Fixed sql.identifier(), sql.as() escaping issues. Previously all the values passed to this functions were not properly escaped
causing a possible SQL Injection (CWE-89) vulnerability
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for express-rate-limit since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
@dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
@dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
@dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
@dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.
## 📋 Pull Request Information
**Original PR:** https://github.com/fosrl/pangolin/pull/2754
**Author:** [@dependabot[bot]](https://github.com/apps/dependabot)
**Created:** 3/31/2026
**Status:** ❌ Closed
**Base:** `main` ← **Head:** `dependabot/npm_and_yarn/prod-patch-updates-eac1bff2e9`
---
### 📝 Commits (1)
- [`e4db8c0`](https://github.com/fosrl/pangolin/commit/e4db8c0951871379033fc0f933b7056e4cc47bff) Bump the prod-patch-updates group across 1 directory with 8 updates
### 📊 Changes
**2 files changed** (+128 additions, -131 deletions)
<details>
<summary>View changed files</summary>
📝 `package-lock.json` (+120 -123)
📝 `package.json` (+8 -8)
</details>
### 📄 Description
Bumps the prod-patch-updates group with 8 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [@react-email/components](https://github.com/resend/react-email/tree/HEAD/packages/components) | `1.0.8` | `1.0.10` |
| [@react-email/tailwind](https://github.com/resend/react-email/tree/HEAD/packages/tailwind) | `2.0.5` | `2.0.6` |
| [drizzle-orm](https://github.com/drizzle-team/drizzle-orm) | `0.45.1` | `0.45.2` |
| [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `8.3.0` | `8.3.2` |
| [ioredis](https://github.com/luin/ioredis) | `5.10.0` | `5.10.1` |
| [next-intl](https://github.com/amannn/next-intl) | `4.8.3` | `4.8.4` |
| [posthog-node](https://github.com/PostHog/posthog-js/tree/HEAD/packages/node) | `5.28.0` | `5.28.9` |
| [use-debounce](https://github.com/xnimorz/use-debounce) | `10.1.0` | `10.1.1` |
Updates `@react-email/components` from 1.0.8 to 1.0.10
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/resend/react-email/releases"><code>@react-email/components</code>'s releases</a>.</em></p>
<blockquote>
<h2><code>@react-email/components</code><a href="https://github.com/1"><code>@1</code></a>.0.10</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [444d9df]
<ul>
<li><code>@react-email/tailwind</code><a href="https://github.com/2"><code>@2</code></a>.0.6</li>
</ul>
</li>
</ul>
<h2><code>@react-email/components</code><a href="https://github.com/1"><code>@1</code></a>.0.9</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [493f367]
<ul>
<li><code>@react-email/body</code><a href="https://github.com/0"><code>@0</code></a>.3.0</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/resend/react-email/blob/canary/packages/components/CHANGELOG.md"><code>@react-email/components</code>'s changelog</a>.</em></p>
<blockquote>
<h2>1.0.10</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [444d9df]
<ul>
<li><code>@react-email/tailwind</code><a href="https://github.com/2"><code>@2</code></a>.0.6</li>
</ul>
</li>
</ul>
<h2>1.0.9</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [493f367]
<ul>
<li><code>@react-email/body</code><a href="https://github.com/0"><code>@0</code></a>.3.0</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/resend/react-email/commit/32b0eba91288d24f682639e966fcff64297f35f6"><code>32b0eba</code></a> chore(root): version packages (<a href="https://github.com/resend/react-email/tree/HEAD/packages/components/issues/3073">#3073</a>)</li>
<li><a href="https://github.com/resend/react-email/commit/197d094d127725c52d6625080a4dc631296d33cd"><code>197d094</code></a> chore: version packages (<a href="https://github.com/resend/react-email/tree/HEAD/packages/components/issues/3035">#3035</a>)</li>
<li><a href="https://github.com/resend/react-email/commit/1f27dcd9c38d50927059dba4f2fb7b59cf7c7ddc"><code>1f27dcd</code></a> feat: pnpm catalogs (<a href="https://github.com/resend/react-email/tree/HEAD/packages/components/issues/3014">#3014</a>)</li>
<li><a href="https://github.com/resend/react-email/commit/11aa935196e3da315be4b4e8711f61efeb5c9f75"><code>11aa935</code></a> chore(deps): update dependency tsdown to v0.19.0 (<a href="https://github.com/resend/react-email/tree/HEAD/packages/components/issues/2857">#2857</a>)</li>
<li>See full diff in <a href="https://github.com/resend/react-email/commits/@react-email/components@1.0.10/packages/components">compare view</a></li>
</ul>
</details>
<br />
Updates `@react-email/tailwind` from 2.0.5 to 2.0.6
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/resend/react-email/releases"><code>@react-email/tailwind</code>'s releases</a>.</em></p>
<blockquote>
<h2><code>@react-email/tailwind</code><a href="https://github.com/2"><code>@2</code></a>.0.6</h2>
<h3>Patch Changes</h3>
<ul>
<li>444d9df: allow for any peer version on body, button, code-block, code-inline, container, heading, hr, img, link, preview, text</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/resend/react-email/blob/canary/packages/tailwind/CHANGELOG.md"><code>@react-email/tailwind</code>'s changelog</a>.</em></p>
<blockquote>
<h2>2.0.6</h2>
<h3>Patch Changes</h3>
<ul>
<li>444d9df: allow for any peer version on body, button, code-block, code-inline, container, heading, hr, img, link, preview, text</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/resend/react-email/commit/32b0eba91288d24f682639e966fcff64297f35f6"><code>32b0eba</code></a> chore(root): version packages (<a href="https://github.com/resend/react-email/tree/HEAD/packages/tailwind/issues/3073">#3073</a>)</li>
<li><a href="https://github.com/resend/react-email/commit/444d9df97aa1aaa9954bcc52d20e59a5c2f367fd"><code>444d9df</code></a> fix(tailwind): use caret ranges for internal peer dependencies (<a href="https://github.com/resend/react-email/tree/HEAD/packages/tailwind/issues/3060">#3060</a>)</li>
<li><a href="https://github.com/resend/react-email/commit/1f27dcd9c38d50927059dba4f2fb7b59cf7c7ddc"><code>1f27dcd</code></a> feat: pnpm catalogs (<a href="https://github.com/resend/react-email/tree/HEAD/packages/tailwind/issues/3014">#3014</a>)</li>
<li><a href="https://github.com/resend/react-email/commit/e64cf9ff1f3fb11302c79e199d4446d39ac2ca5c"><code>e64cf9f</code></a> chore: workflow for e2e, only tailwind for now (<a href="https://github.com/resend/react-email/tree/HEAD/packages/tailwind/issues/2998">#2998</a>)</li>
<li><a href="https://github.com/resend/react-email/commit/11aa935196e3da315be4b4e8711f61efeb5c9f75"><code>11aa935</code></a> chore(deps): update dependency tsdown to v0.19.0 (<a href="https://github.com/resend/react-email/tree/HEAD/packages/tailwind/issues/2857">#2857</a>)</li>
<li>See full diff in <a href="https://github.com/resend/react-email/commits/@react-email/tailwind@2.0.6/packages/tailwind">compare view</a></li>
</ul>
</details>
<br />
Updates `drizzle-orm` from 0.45.1 to 0.45.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/drizzle-team/drizzle-orm/releases">drizzle-orm's releases</a>.</em></p>
<blockquote>
<h2>0.45.2</h2>
<ul>
<li>Fixed <code>sql.identifier()</code>, <code>sql.as()</code> escaping issues. Previously all the values passed to this functions were not properly escaped
causing a possible SQL Injection (CWE-89) vulnerability</li>
</ul>
<p>Thanks to <a href="https://github.com/EthanKim88"><code>@EthanKim88</code></a>, <a href="https://github.com/0x90sh"><code>@0x90sh</code></a> and <a href="https://github.com/wgoodall01"><code>@wgoodall01</code></a> for reaching out to us with a reproduction and suggested fix</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/drizzle-team/drizzle-orm/commit/273c78071d4841b497f5144734b38294df7ec64b"><code>273c780</code></a> + 0.45.2 (<a href="https://redirect.github.com/drizzle-team/drizzle-orm/issues/5534">#5534</a>)</li>
<li><a href="https://github.com/drizzle-team/drizzle-orm/commit/4aa6ecfee4b4728dadf6f77f071a149878a3c6c0"><code>4aa6ecf</code></a> Kit updates (<a href="https://redirect.github.com/drizzle-team/drizzle-orm/issues/5490">#5490</a>)</li>
<li><a href="https://github.com/drizzle-team/drizzle-orm/commit/e8e6edfef5ca69c6188d320388ad440265911057"><code>e8e6edf</code></a> feat(drizzle-kit): support d1 via binding (<a href="https://redirect.github.com/drizzle-team/drizzle-orm/issues/5302">#5302</a>)</li>
<li>See full diff in <a href="https://github.com/drizzle-team/drizzle-orm/compare/0.45.1...0.45.2">compare view</a></li>
</ul>
</details>
<br />
Updates `express-rate-limit` from 8.3.0 to 8.3.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/express-rate-limit/express-rate-limit/releases">express-rate-limit's releases</a>.</em></p>
<blockquote>
<h2>v8.3.2</h2>
<p>You can view the changelog <a href="https://express-rate-limit.mintlify.app/reference/changelog">here</a>.</p>
<h2>v8.3.1</h2>
<p>You can view the changelog <a href="https://express-rate-limit.mintlify.app/reference/changelog">here</a>.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/express-rate-limit/express-rate-limit/commit/c4dbb42c1b4891056545e30a9187a64c8bfeb8bc"><code>c4dbb42</code></a> 8.3.2</li>
<li><a href="https://github.com/express-rate-limit/express-rate-limit/commit/8f1cc6639a430d6409e600c8e5434c1bc1e572bf"><code>8f1cc66</code></a> v8.3.2 changelog</li>
<li><a href="https://github.com/express-rate-limit/express-rate-limit/commit/601b87f5d171487ed035ccdfee17ec75f5b22f2d"><code>601b87f</code></a> Fix skipFailedRequests for for connections that close very early (<a href="https://redirect.github.com/express-rate-limit/express-rate-limit/issues/611">#611</a>)</li>
<li><a href="https://github.com/express-rate-limit/express-rate-limit/commit/014c2f32708c0fdb5544834c3e77043e041ae38a"><code>014c2f3</code></a> chore(deps-dev): bump the development-dependencies group with 6 updates (<a href="https://redirect.github.com/express-rate-limit/express-rate-limit/issues/612">#612</a>)</li>
<li><a href="https://github.com/express-rate-limit/express-rate-limit/commit/4e8b18bf972eff2890ed67bd11d8a08a2c6502d5"><code>4e8b18b</code></a> Remove Zuplo sponsorship details from README (<a href="https://redirect.github.com/express-rate-limit/express-rate-limit/issues/613">#613</a>)</li>
<li><a href="https://github.com/express-rate-limit/express-rate-limit/commit/31dab192a3798984b89e78bfacf755f361f29660"><code>31dab19</code></a> test: use numeric range for reset timestamp assertion (<a href="https://redirect.github.com/express-rate-limit/express-rate-limit/issues/610">#610</a>)</li>
<li><a href="https://github.com/express-rate-limit/express-rate-limit/commit/f82ad139611ed69c451f113913f0347ee78d19ec"><code>f82ad13</code></a> chore(deps-dev): bump the development-dependencies group with 2 updates (<a href="https://redirect.github.com/express-rate-limit/express-rate-limit/issues/609">#609</a>)</li>
<li><a href="https://github.com/express-rate-limit/express-rate-limit/commit/fa0b0982049814870faf9d57b7588a0b9acd107f"><code>fa0b098</code></a> docs: fix broken link</li>
<li><a href="https://github.com/express-rate-limit/express-rate-limit/commit/47e5b2952fe697ac0a5f8a6aa86f050f6f2c0ce5"><code>47e5b29</code></a> 8.3.1</li>
<li><a href="https://github.com/express-rate-limit/express-rate-limit/commit/eb61179a49064c7e86f6f8688be742343b1f1b8e"><code>eb61179</code></a> v8.3.1 changelog</li>
<li>Additional commits viewable in <a href="https://github.com/express-rate-limit/express-rate-limit/compare/v8.3.0...v8.3.2">compare view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by [GitHub Actions](<a href="https://www.npmjs.com/~GitHub">https://www.npmjs.com/~GitHub</a> Actions), a new releaser for express-rate-limit since your current version.</p>
</details>
<br />
Updates `ioredis` from 5.10.0 to 5.10.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/luin/ioredis/releases">ioredis's releases</a>.</em></p>
<blockquote>
<h2>v5.10.1</h2>
<h2><a href="https://github.com/luin/ioredis/compare/v5.10.0...v5.10.1">5.10.1</a> (2026-03-19)</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>cluster:</strong> lazily start sharded subscribers (<a href="https://redirect.github.com/luin/ioredis/issues/2090">#2090</a>) (<a href="https://github.com/luin/ioredis/commit/4f167bb9f494f0e8200a20dedd8bbdf1810fcd22">4f167bb</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/redis/ioredis/blob/main/CHANGELOG.md">ioredis's changelog</a>.</em></p>
<blockquote>
<h2><a href="https://github.com/luin/ioredis/compare/v5.10.0...v5.10.1">5.10.1</a> (2026-03-19)</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>cluster:</strong> lazily start sharded subscribers (<a href="https://redirect.github.com/luin/ioredis/issues/2090">#2090</a>) (<a href="https://github.com/luin/ioredis/commit/4f167bb9f494f0e8200a20dedd8bbdf1810fcd22">4f167bb</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/redis/ioredis/commit/9e26f8b384e9f137c31bb080620c69215880df60"><code>9e26f8b</code></a> chore(release): 5.10.1 [skip ci]</li>
<li><a href="https://github.com/redis/ioredis/commit/4f167bb9f494f0e8200a20dedd8bbdf1810fcd22"><code>4f167bb</code></a> fix(cluster): lazily start sharded subscribers (<a href="https://redirect.github.com/luin/ioredis/issues/2090">#2090</a>)</li>
<li>See full diff in <a href="https://github.com/luin/ioredis/compare/v5.10.0...v5.10.1">compare view</a></li>
</ul>
</details>
<br />
Updates `next-intl` from 4.8.3 to 4.8.4
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/amannn/next-intl/releases">next-intl's releases</a>.</em></p>
<blockquote>
<h2>v4.8.4</h2>
<h2>4.8.4 (2026-03-31)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Remove TypeScript peer dependency and update examples to TypeScript v6 (<a href="https://redirect.github.com/amannn/next-intl/issues/2293">#2293</a>) (<a href="https://github.com/amannn/next-intl/commit/5e7bcd743994f8a3ccfd904d7969f4543950cd0a">5e7bcd7</a>) – by <a href="https://github.com/wojtekmaj"><code>@wojtekmaj</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/amannn/next-intl/blob/main/CHANGELOG.md">next-intl's changelog</a>.</em></p>
<blockquote>
<h2>4.8.4 (2026-03-31)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Remove TypeScript peer dependency and update examples to TypeScript v6 (<a href="https://redirect.github.com/amannn/next-intl/issues/2293">#2293</a>) (<a href="https://github.com/amannn/next-intl/commit/5e7bcd743994f8a3ccfd904d7969f4543950cd0a">5e7bcd7</a>) – by <a href="https://github.com/wojtekmaj"><code>@wojtekmaj</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/amannn/next-intl/commit/722785bc2d34f38949b8186c0282af88db38c2a5"><code>722785b</code></a> v4.8.4</li>
<li><a href="https://github.com/amannn/next-intl/commit/5e7bcd743994f8a3ccfd904d7969f4543950cd0a"><code>5e7bcd7</code></a> fix: Remove TypeScript peer dependency and update examples to TypeScript v6 (...</li>
<li><a href="https://github.com/amannn/next-intl/commit/c9d605131259d0533757063822fafb7d3584eca3"><code>c9d6051</code></a> fix: Remove TypeScript peer dependency and update examples to TypeScript v6 (...</li>
<li><a href="https://github.com/amannn/next-intl/commit/5be07b66dfc5842e27decced737ba9b0ab85377f"><code>5be07b6</code></a> fix: Remove TypeScript peer dependency and update examples to TypeScript v6 (...</li>
<li><a href="https://github.com/amannn/next-intl/commit/58326e7df6d2c1ec02673872290b13c5c7daefc2"><code>58326e7</code></a> docs: Fix typos (<a href="https://redirect.github.com/amannn/next-intl/issues/2282">#2282</a>)</li>
<li><a href="https://github.com/amannn/next-intl/commit/ed19787a6d5e106cf98d2c653500548705dd41ee"><code>ed19787</code></a> docs: Fix typos (<a href="https://redirect.github.com/amannn/next-intl/issues/2283">#2283</a>)</li>
<li><a href="https://github.com/amannn/next-intl/commit/db51a73694b9bb6b251bf5a59fb636f98fb24b19"><code>db51a73</code></a> docs: Fix typos in <code>useExtracted</code> blog post (<a href="https://redirect.github.com/amannn/next-intl/issues/2279">#2279</a>)</li>
<li><a href="https://github.com/amannn/next-intl/commit/c0f494caad2d0db86e9ac977ef9854411ccd6d8f"><code>c0f494c</code></a> docs: Update precompilation.mdx</li>
<li><a href="https://github.com/amannn/next-intl/commit/f340ad0cf21f744ebbe382baf2a832d71136ab0d"><code>f340ad0</code></a> docs: Add disclaimer to SWC plugin</li>
<li><a href="https://github.com/amannn/next-intl/commit/a60bd30e049bc1062fbfcd93f8a285be8d12f492"><code>a60bd30</code></a> docs: Remove button arrow</li>
<li>See full diff in <a href="https://github.com/amannn/next-intl/compare/v4.8.3...v4.8.4">compare view</a></li>
</ul>
</details>
<br />
Updates `posthog-node` from 5.28.0 to 5.28.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/PostHog/posthog-js/releases">posthog-node's releases</a>.</em></p>
<blockquote>
<h2>posthog-node@5.28.9</h2>
<h2>5.28.9</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a href="https://github.com/PostHog/posthog-js/commit/a863914bca09643f2aef7ca029b96de9cbfbc24c"><code>a863914</code></a>]:
<ul>
<li><code>@posthog/core</code><a href="https://github.com/1"><code>@1</code></a>.24.4</li>
</ul>
</li>
</ul>
<h2>posthog-node@5.28.8</h2>
<h2>5.28.8</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a href="https://github.com/PostHog/posthog-js/commit/4bdfdbcfe6a5600664a609a6b17c7d7cb72cd20f"><code>4bdfdbc</code></a>]:
<ul>
<li><code>@posthog/core</code><a href="https://github.com/1"><code>@1</code></a>.24.3</li>
</ul>
</li>
</ul>
<h2>posthog-node@5.28.7</h2>
<h2>5.28.7</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a href="https://github.com/PostHog/posthog-js/commit/8d34289f7cf91945223eed4366b11fb187a63a40"><code>8d34289</code></a>]:
<ul>
<li><code>@posthog/core</code><a href="https://github.com/1"><code>@1</code></a>.24.2</li>
</ul>
</li>
</ul>
<h2>posthog-node@5.28.6</h2>
<h2>5.28.6</h2>
<h3>Patch Changes</h3>
<ul>
<li><a href="https://redirect.github.com/PostHog/posthog-js/pull/3282">#3282</a> <a href="https://github.com/PostHog/posthog-js/commit/5784dcaeb71f7e67d9c9df28f116886a573d19df"><code>5784dca</code></a> Thanks <a href="https://github.com/marandaneto"><code>@marandaneto</code></a>! - fix: captureException now uses distinctId from request context
(2026-03-26)</li>
</ul>
<h2>posthog-node@5.28.5</h2>
<h2>5.28.5</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a href="https://github.com/PostHog/posthog-js/commit/314120aa2377b3c8031dd774833fe9082ecdbd39"><code>314120a</code></a>]:
<ul>
<li><code>@posthog/core</code><a href="https://github.com/1"><code>@1</code></a>.24.1</li>
</ul>
</li>
</ul>
<h2>posthog-node@5.28.4</h2>
<h2>5.28.4</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a href="https://github.com/PostHog/posthog-js/commit/9cd23138343e1020811f85853d6016cc985bb24f"><code>9cd2313</code></a>]:
<ul>
<li><code>@posthog/core</code><a href="https://github.com/1"><code>@1</code></a>.24.0</li>
</ul>
</li>
</ul>
<h2>posthog-node@5.28.3</h2>
<h2>5.28.3</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/PostHog/posthog-js/blob/main/packages/node/CHANGELOG.md">posthog-node's changelog</a>.</em></p>
<blockquote>
<h2>5.28.9</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a href="https://github.com/PostHog/posthog-js/commit/a863914bca09643f2aef7ca029b96de9cbfbc24c"><code>a863914</code></a>]:
<ul>
<li><code>@posthog/core</code><a href="https://github.com/1"><code>@1</code></a>.24.4</li>
</ul>
</li>
</ul>
<h2>5.28.8</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a href="https://github.com/PostHog/posthog-js/commit/4bdfdbcfe6a5600664a609a6b17c7d7cb72cd20f"><code>4bdfdbc</code></a>]:
<ul>
<li><code>@posthog/core</code><a href="https://github.com/1"><code>@1</code></a>.24.3</li>
</ul>
</li>
</ul>
<h2>5.28.7</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a href="https://github.com/PostHog/posthog-js/commit/8d34289f7cf91945223eed4366b11fb187a63a40"><code>8d34289</code></a>]:
<ul>
<li><code>@posthog/core</code><a href="https://github.com/1"><code>@1</code></a>.24.2</li>
</ul>
</li>
</ul>
<h2>5.28.6</h2>
<h3>Patch Changes</h3>
<ul>
<li><a href="https://redirect.github.com/PostHog/posthog-js/pull/3282">#3282</a> <a href="https://github.com/PostHog/posthog-js/commit/5784dcaeb71f7e67d9c9df28f116886a573d19df"><code>5784dca</code></a> Thanks <a href="https://github.com/marandaneto"><code>@marandaneto</code></a>! - fix: captureException now uses distinctId from request context
(2026-03-26)</li>
</ul>
<h2>5.28.5</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a href="https://github.com/PostHog/posthog-js/commit/314120aa2377b3c8031dd774833fe9082ecdbd39"><code>314120a</code></a>]:
<ul>
<li><code>@posthog/core</code><a href="https://github.com/1"><code>@1</code></a>.24.1</li>
</ul>
</li>
</ul>
<h2>5.28.4</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a href="https://github.com/PostHog/posthog-js/commit/9cd23138343e1020811f85853d6016cc985bb24f"><code>9cd2313</code></a>]:
<ul>
<li><code>@posthog/core</code><a href="https://github.com/1"><code>@1</code></a>.24.0</li>
</ul>
</li>
</ul>
<h2>5.28.3</h2>
<h3>Patch Changes</h3>
<ul>
<li><a href="https://redirect.github.com/PostHog/posthog-js/pull/3243">#3243</a> <a href="https://github.com/PostHog/posthog-js/commit/697e4237ca945caa33b26f35872951ad0e7530d4"><code>697e423</code></a> Thanks <a href="https://github.com/hpouillot"><code>@hpouillot</code></a>! - fix captureExceptionImmediate return value
(2026-03-18)</li>
</ul>
<h2>5.28.2</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/PostHog/posthog-js/commit/4d6cef416dcd8cedcf224571858729474db2f83f"><code>4d6cef4</code></a> chore: update versions and lockfile [version bump]</li>
<li><a href="https://github.com/PostHog/posthog-js/commit/bec98144c9e131cb84078cfd3f54ef37ac7d96da"><code>bec9814</code></a> chore: update versions and lockfile [version bump]</li>
<li><a href="https://github.com/PostHog/posthog-js/commit/ee9b06a10b38919d716fbc04d096bb516a21a416"><code>ee9b06a</code></a> fix(node): fix flaky nestjs interceptor test (<a href="https://github.com/PostHog/posthog-js/tree/HEAD/packages/node/issues/3293">#3293</a>)</li>
<li><a href="https://github.com/PostHog/posthog-js/commit/287eb9174915cee67aaca24fada285880a505198"><code>287eb91</code></a> chore: update versions and lockfile [version bump]</li>
<li><a href="https://github.com/PostHog/posthog-js/commit/732780989abee5559f6105091911b8e504bf35d7"><code>7327809</code></a> chore: update versions and lockfile [version bump]</li>
<li><a href="https://github.com/PostHog/posthog-js/commit/5784dcaeb71f7e67d9c9df28f116886a573d19df"><code>5784dca</code></a> fix(node): captureException uses distinctId from request context (<a href="https://github.com/PostHog/posthog-js/tree/HEAD/packages/node/issues/3282">#3282</a>)</li>
<li><a href="https://github.com/PostHog/posthog-js/commit/482c85f25c0a52924cfe483bf07b7cf73f38254b"><code>482c85f</code></a> chore: update versions and lockfile [version bump]</li>
<li><a href="https://github.com/PostHog/posthog-js/commit/f4e5889938255921ff739a9c4086885478a2c716"><code>f4e5889</code></a> chore: update versions and lockfile [version bump]</li>
<li><a href="https://github.com/PostHog/posthog-js/commit/52ddf4e349990ad12e3db8b78dcbb5a67bfa972d"><code>52ddf4e</code></a> chore: update versions and lockfile [version bump]</li>
<li><a href="https://github.com/PostHog/posthog-js/commit/697e4237ca945caa33b26f35872951ad0e7530d4"><code>697e423</code></a> fix: make captureExceptionImmediate return the promise (<a href="https://github.com/PostHog/posthog-js/tree/HEAD/packages/node/issues/3243">#3243</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/PostHog/posthog-js/commits/posthog-node@5.28.9/packages/node">compare view</a></li>
</ul>
</details>
<br />
Updates `use-debounce` from 10.1.0 to 10.1.1
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a href="https://github.com/xnimorz/use-debounce/blob/master/CHANGELOG.md">use-debounce's changelog</a>.</em></p>
<blockquote>
<h2>10.1.1</h2>
<ul>
<li>replace global with globalThis which is defined in all possible environments (browser, node, workers) to address <a href="https://redirect.github.com/xnimorz/use-debounce/issues/212">xnimorz/use-debounce#212</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a href="https://github.com/xnimorz/use-debounce/commits">compare view</a></li>
</ul>
</details>
<br />
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions
</details>
---
<sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
📋 Pull Request Information
Original PR: https://github.com/fosrl/pangolin/pull/2754
Author: @dependabot[bot]
Created: 3/31/2026
Status: ❌ Closed
Base:
main← Head:dependabot/npm_and_yarn/prod-patch-updates-eac1bff2e9📝 Commits (1)
e4db8c0Bump the prod-patch-updates group across 1 directory with 8 updates📊 Changes
2 files changed (+128 additions, -131 deletions)
View changed files
📝
package-lock.json(+120 -123)📝
package.json(+8 -8)📄 Description
Bumps the prod-patch-updates group with 8 updates in the / directory:
1.0.81.0.102.0.52.0.60.45.10.45.28.3.08.3.25.10.05.10.14.8.34.8.45.28.05.28.910.1.010.1.1Updates
@react-email/componentsfrom 1.0.8 to 1.0.10Release notes
Sourced from
@react-email/components's releases.Changelog
Sourced from
@react-email/components's changelog.Commits
32b0ebachore(root): version packages (#3073)197d094chore: version packages (#3035)1f27dcdfeat: pnpm catalogs (#3014)11aa935chore(deps): update dependency tsdown to v0.19.0 (#2857)Updates
@react-email/tailwindfrom 2.0.5 to 2.0.6Release notes
Sourced from
@react-email/tailwind's releases.Changelog
Sourced from
@react-email/tailwind's changelog.Commits
32b0ebachore(root): version packages (#3073)444d9dffix(tailwind): use caret ranges for internal peer dependencies (#3060)1f27dcdfeat: pnpm catalogs (#3014)e64cf9fchore: workflow for e2e, only tailwind for now (#2998)11aa935chore(deps): update dependency tsdown to v0.19.0 (#2857)Updates
drizzle-ormfrom 0.45.1 to 0.45.2Release notes
Sourced from drizzle-orm's releases.
Commits
273c780+ 0.45.2 (#5534)4aa6ecfKit updates (#5490)e8e6edffeat(drizzle-kit): support d1 via binding (#5302)Updates
express-rate-limitfrom 8.3.0 to 8.3.2Release notes
Sourced from express-rate-limit's releases.
Commits
c4dbb428.3.28f1cc66v8.3.2 changelog601b87fFix skipFailedRequests for for connections that close very early (#611)014c2f3chore(deps-dev): bump the development-dependencies group with 6 updates (#612)4e8b18bRemove Zuplo sponsorship details from README (#613)31dab19test: use numeric range for reset timestamp assertion (#610)f82ad13chore(deps-dev): bump the development-dependencies group with 2 updates (#609)fa0b098docs: fix broken link47e5b298.3.1eb61179v8.3.1 changelogMaintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for express-rate-limit since your current version.
Updates
ioredisfrom 5.10.0 to 5.10.1Release notes
Sourced from ioredis's releases.
Changelog
Sourced from ioredis's changelog.
Commits
9e26f8bchore(release): 5.10.1 [skip ci]4f167bbfix(cluster): lazily start sharded subscribers (#2090)Updates
next-intlfrom 4.8.3 to 4.8.4Release notes
Sourced from next-intl's releases.
Changelog
Sourced from next-intl's changelog.
Commits
722785bv4.8.45e7bcd7fix: Remove TypeScript peer dependency and update examples to TypeScript v6 (...c9d6051fix: Remove TypeScript peer dependency and update examples to TypeScript v6 (...5be07b6fix: Remove TypeScript peer dependency and update examples to TypeScript v6 (...58326e7docs: Fix typos (#2282)ed19787docs: Fix typos (#2283)db51a73docs: Fix typos inuseExtractedblog post (#2279)c0f494cdocs: Update precompilation.mdxf340ad0docs: Add disclaimer to SWC plugina60bd30docs: Remove button arrowUpdates
posthog-nodefrom 5.28.0 to 5.28.9Release notes
Sourced from posthog-node's releases.
... (truncated)
Changelog
Sourced from posthog-node's changelog.
... (truncated)
Commits
4d6cef4chore: update versions and lockfile [version bump]bec9814chore: update versions and lockfile [version bump]ee9b06afix(node): fix flaky nestjs interceptor test (#3293)287eb91chore: update versions and lockfile [version bump]7327809chore: update versions and lockfile [version bump]5784dcafix(node): captureException uses distinctId from request context (#3282)482c85fchore: update versions and lockfile [version bump]f4e5889chore: update versions and lockfile [version bump]52ddf4echore: update versions and lockfile [version bump]697e423fix: make captureExceptionImmediate return the promise (#3243)Updates
use-debouncefrom 10.1.0 to 10.1.1Changelog
Sourced from use-debounce's changelog.
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.