Skip to content

Bump the "weekly-dependencies" group with 3 updates across multiple ecosystems - #175

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/weekly_dependencies-88ab821b48
Open

Bump the "weekly-dependencies" group with 3 updates across multiple ecosystems#175
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/weekly_dependencies-88ab821b48

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor

Bumps the weekly-dependencies group in /conformance with 3 updates: mppx, @types/node and tsx.

Updates mppx from 0.8.15 to 0.8.17

Release notes

Sourced from mppx's releases.

mppx@0.8.17

Patch Changes

  • 52d8701: Reject sub-cent amounts via canOffer before issuing 402 challenge on stripe-managed crypto rails. Add metadata parameter to stripe.create() for forwarding key-value pairs to Stripe PaymentIntents.
  • b7ab48e: Changed Tempo relay idempotency keys to use the mpp_ prefix.
Changelog

Sourced from mppx's changelog.

0.8.17

Patch Changes

  • 52d8701: Reject sub-cent amounts via canOffer before issuing 402 challenge on stripe-managed crypto rails. Add metadata parameter to stripe.create() for forwarding key-value pairs to Stripe PaymentIntents.
  • b7ab48e: Changed Tempo relay idempotency keys to use the mpp_ prefix.

0.8.16

Patch Changes

  • c58ee80: Added composable TAP and Web Bot Auth HTTPS-directory profile signers and verifiers with Ed25519 and RSA-PSS SHA-512 support, explicit replay storage, typed verification outcomes, and shared per-attempt signing context.
  • 1d7749a: Added first-class client and server request-attestation configuration to Mppx.create().
  • e2b2a8a: Removed the legacy Tempo session server implementation and server compatibility exports while retaining the v1 client for existing sessions. See the session upgrade guide for migration instructions.
  • 4637603: Aligned published and workspace dependency versions with shared pnpm catalog pins.
  • 4834ef1: Added configurable upstream error recovery hooks to proxy services and preserved request bodies across retries.
  • 00b0063: Fix js-yaml audit vulnerability (CVE-2026-59870) by bumping override to 4.3.1.
  • 81a5c6b: Fix Method.toServer() to pass through onPaymentSuccess from options.
  • f7f8e58: Fixed multi-challenge parsing when quoted parameter values contained the Payment scheme name.
  • 8e370ba: Added structured sponsor budget configuration and support for externally enforced sponsor budgets.
  • 40f430a: Multi-method intent handler: .charge() now works when multiple methods share an intent, internally composing all matching methods into one handler that respects selectOffers.
  • 1272520: Disabled the no-underscore-dangle lint rule.
  • 5ff5cb7: Fixed equality checks between equivalent hex and Tempo-formatted addresses.
  • 71b8884: Add per-method onPaymentSuccess hook to ComposableHooks. Routed through the server event dispatcher for error isolation.
  • 641aa4d: Kept discovery metadata aligned with runtime challenges by preserving composed offers, dispatching nested compositions, and deriving prices from canonical payment requests.
  • cd71f9e: Made attestation verifiers accept the core AtomicStore directly and shared its optimized Store.tryClaim replay primitive with Tempo charges.
  • f3a9369: Updated production dependencies.
  • 3d7ed4b: Removed obsolete compatibility shims for legacy viem Tempo call builders.
  • 47d6df7: Added server- and method-level filtering with immutable snapshots for composed HTTP payment offers across every server method constructor, including Stripe currency minimums.
  • 30f8a12: Added a session-bound WebSocket server helper that reused the configured store and settlement policy, and applied that policy to plain HTTP responses from SSE-enabled methods. Fixed automatic settlement schedules after committed Tempo session SSE and WebSocket charges.
  • 9f0afe0: Added a stable CLI launcher for workspace dependency installation.
  • bdaea3a: Standardized client transports on getChallenges and removed the singular getChallenge hook.
  • 4b3b1c0: Add stripe.create() machine payments API with auto deposit address resolution, PI recording, and unified .charge() handler.
  • fd38304: Added non-mutating credential validation and broadcast hooks to the Tempo session server method.
  • 8f9f8cb: Fixed body-bearing EVM routes to advertise PAYMENT-REQUIRED alongside MPP challenges and accept standard x402 payments when mppx route binding is not required.
Commits
  • fca6f92 chore: version packages (#775)
  • 407cb98 chore(deps-dev): bump the npm-development group across 1 directory with 7 upd...
  • eee27c3 ci: skip changeset check for dependabot (#780)
  • e12928c chore(deps): bump the npm-production group with 8 updates (#778)
  • 205827d chore(deps): bump pnpm/action-setup in the github-actions group (#777)
  • 52d8701 feat(stripe): reject sub-cent amounts before 402 challenge via canOffer (#776)
  • b7ab48e fix(tempo): use mpp relay idempotency prefix (#774)
  • 052ecb7 chore: version packages (#728)
  • af4894f chore: release unreleased changes as patch (#773)
  • 8e370ba feat(tempo): add sponsor budget configuration (#772)
  • Additional commits viewable in compare view

Updates @types/node from 26.1.2 to 26.2.0

Commits

Updates tsx from 4.23.11 to 4.23.12

Release notes

Sourced from tsx's releases.

v4.23.12

4.23.12 (2026-08-10)

Bug Fixes

  • shim import.meta when tokens are split by comments or newlines (#829) (ed9d330), closes #828

This release is also available on:

Commits
  • ed9d330 fix: shim import.meta when tokens are split by comments or newlines (#829)
  • 651f5be test: cover CommonJS TypeScript import.meta paths
  • See full diff in compare view

Bumps the weekly-dependencies group in /conformance/adapters/ruby with 1 update: sorbet-runtime.

Updates sorbet-runtime from 0.6.13412 to 0.6.13426

Release notes

Sourced from sorbet-runtime's releases.

sorbet 0.6.13425.20260811151555-5981ccaa1

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13425', :group => :development
gem 'sorbet-runtime', '0.6.13425'

sorbet 0.6.13424.20260811104750-e05d1b878

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13424', :group => :development
gem 'sorbet-runtime', '0.6.13424'

sorbet 0.6.13423.20260811115228-a352c5412

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13423', :group => :development
gem 'sorbet-runtime', '0.6.13423'

sorbet 0.6.13422.20260811112847-428761da1

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13422', :group => :development
gem 'sorbet-runtime', '0.6.13422'

sorbet 0.6.13421.20260808091639-133a14ab1

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13421', :group => :development
gem 'sorbet-runtime', '0.6.13421'

sorbet 0.6.13420.20260807180717-b90db808d

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13420', :group => :development
gem 'sorbet-runtime', '0.6.13420'

sorbet 0.6.13419.20260807175409-5313dec83

To use Sorbet add this line to your Gemfile:

gem 'sorbet', '0.6.13419', :group => :development
gem 'sorbet-runtime', '0.6.13419'

sorbet 0.6.13418.20260807172916-549db61b5

... (truncated)

Commits

Bumps the weekly-dependencies group in /conformance/adapters/java with 1 update: com.stripe:mpp-java.

Updates com.stripe:mpp-java from 0.1.2 to 0.1.3

Commits
  • 702bc5f Merge pull request #19 from stripe/fix/conformance-ci-deps
  • 44159b8 fix: use uv run for Python scripts in conformance CI
  • 5a52ebd fix: upgrade Node to 22 and install uv for conformance CI
  • bc52e0f Merge pull request #17 from parvahuja/parv/release-0.1.3
  • 8f22ab3 chore: release 0.1.3
  • 8e403af Merge pull request #16 from parvahuja/parv/tempo-relay-support
  • 3477f0b test: clarify verifiable method fixture
  • 9853254 fix: refine relay compatibility
  • 0a7f028 fix: require relay example secret
  • 2639669 refactor: apply relay review cleanups
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the weekly-dependencies group in /conformance with 3 updates: [mppx](https://github.com/wevm/mppx), [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [tsx](https://github.com/privatenumber/tsx).


Updates `mppx` from 0.8.15 to 0.8.17
- [Release notes](https://github.com/wevm/mppx/releases)
- [Changelog](https://github.com/wevm/mppx/blob/main/CHANGELOG.md)
- [Commits](https://github.com/wevm/mppx/compare/mppx@0.8.15...mppx@0.8.17)

Updates `@types/node` from 26.1.2 to 26.2.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `tsx` from 4.23.11 to 4.23.12
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.11...v4.23.12)
chore(deps): bump sorbet-runtime

Bumps the weekly-dependencies group in /conformance/adapters/ruby with 1 update: [sorbet-runtime](https://github.com/sorbet/sorbet).


Updates `sorbet-runtime` from 0.6.13412 to 0.6.13426
- [Release notes](https://github.com/sorbet/sorbet/releases)
- [Commits](https://github.com/sorbet/sorbet/commits)
chore(deps): bump com.stripe:mpp-java

Bumps the weekly-dependencies group in /conformance/adapters/java with 1 update: [com.stripe:mpp-java](https://github.com/stripe/mpp-java).


Updates `com.stripe:mpp-java` from 0.1.2 to 0.1.3
- [Commits](stripe/mpp-java@v0.1.2...v0.1.3)

---
updated-dependencies:
- dependency-name: mppx
  dependency-version: 0.8.17
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: weekly-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: weekly-dependencies
- dependency-name: tsx
  dependency-version: 4.23.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: weekly-dependencies
- dependency-name: sorbet-runtime
  dependency-version: 0.6.13426
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: weekly-dependencies
- dependency-name: com.stripe:mpp-java
  dependency-version: 0.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: weekly-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 17, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedmaven/​org.bouncycastle/​bcprov-jdk18on@​1.8436259010080
Updatednpm/​@​types/​node@​26.1.2 ⏵ 26.2.0100 +110081 +195100
Updatednpm/​tsx@​4.23.11 ⏵ 4.23.121001008194 -1100
Updatednpm/​mppx@​0.8.15 ⏵ 0.8.1799 +18100100 +198 +1100
Updatedgem/​sorbet-runtime@​0.6.13412 ⏵ 0.6.13426100100100100100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: CVE-2026-58062 in maven org.bouncycastle:bcprov-jdk18on

CVE: GHSA-j295-77c3-9frf (CRITICAL)

Affected versions: < 1.85

Patched version: 1.85

From: conformance/adapters/java/gradle.lockfilemaven/org.bouncycastle/bcprov-jdk18on@1.84

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/org.bouncycastle/bcprov-jdk18on@1.84. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: CVE-2026-59650 in maven org.bouncycastle:bcprov-jdk18on

CVE: GHSA-ghgq-7g74-28wp (CRITICAL)

Affected versions: < 1.85

Patched version: 1.85

From: conformance/adapters/java/gradle.lockfilemaven/org.bouncycastle/bcprov-jdk18on@1.84

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/org.bouncycastle/bcprov-jdk18on@1.84. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: CVE-2026-8763 in maven org.bouncycastle:bcprov-jdk18on

CVE: GHSA-9pwp-9qqc-pr26 (CRITICAL)

Affected versions: < 1.85

Patched version: 1.85

From: conformance/adapters/java/gradle.lockfilemaven/org.bouncycastle/bcprov-jdk18on@1.84

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/org.bouncycastle/bcprov-jdk18on@1.84. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants