Skip to content

chore(deps): bump the dependencies group across 1 directory with 20 updates#20

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dependencies-b89b9b5a2e
Closed

chore(deps): bump the dependencies group across 1 directory with 20 updates#20
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dependencies-b89b9b5a2e

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 20, 2026

Bumps the dependencies group with 20 updates in the / directory:

Package From To
@nestjs/common 11.1.18 11.1.19
@nestjs/core 11.1.18 11.1.19
@nestjs/platform-express 11.1.18 11.1.19
@nestjs/swagger 11.2.6 11.3.0
@opentelemetry/auto-instrumentations-node 0.72.0 0.73.0
@opentelemetry/exporter-metrics-otlp-http 0.214.0 0.215.0
@opentelemetry/exporter-trace-otlp-http 0.214.0 0.215.0
@opentelemetry/exporter-trace-otlp-proto 0.214.0 0.215.0
@opentelemetry/resources 2.6.1 2.7.0
@opentelemetry/sdk-metrics 2.6.1 2.7.0
@opentelemetry/sdk-node 0.214.0 0.215.0
axios 1.14.0 1.15.1
dotenv 17.4.1 17.4.2
@nestjs/cli 11.0.18 11.0.21
@nestjs/schematics 11.0.10 11.1.0
eslint 9.39.2 9.39.4
globals 17.4.0 17.5.0
prettier 3.8.1 3.8.3
typedoc 0.28.18 0.28.19
typescript-eslint 8.58.0 8.58.2

Updates @nestjs/common from 11.1.18 to 11.1.19

Release notes

Sourced from @​nestjs/common's releases.

v11.1.19 (2026-04-13)

Bug fixes

Committers: 2

Commits

Updates @nestjs/core from 11.1.18 to 11.1.19

Release notes

Sourced from @​nestjs/core's releases.

v11.1.19 (2026-04-13)

Bug fixes

Committers: 2

Commits

Updates @nestjs/platform-express from 11.1.18 to 11.1.19

Release notes

Sourced from @​nestjs/platform-express's releases.

v11.1.19 (2026-04-13)

Bug fixes

Committers: 2

Commits

Updates @nestjs/swagger from 11.2.6 to 11.3.0

Release notes

Sourced from @​nestjs/swagger's releases.

Release 11.3.0

11.3.0 (2026-04-15)

Bug fixes

Enhancements

Dependencies

Committers: 7

11.2.7

What's Changed

... (truncated)

Commits
  • 0106583 chore(): release v11.3.0
  • 473b26f chore: add rxjs as dev dependency
  • 5b0b014 test: regenerate api-spec
  • 410d6a7 Merge pull request #3826 from Nedunchezhiyan-M/fix/api-response-nullable
  • b1e16e6 Merge pull request #3849 from nestjs/renovate/release-it-20.x
  • 71d9f7a chore(deps): update dependency release-it to v20
  • fa96c15 Merge pull request #3625 from rajasekar33/feat/add-api-level-extensions
  • 672a40d Merge pull request #3449 from leemhoon00/feat-apiheader-example
  • b0f01d5 Merge pull request #3784 from maruthang/fix/nullable-type-field-3274
  • 4063d94 Merge pull request #3774 from SupunGeethanjana/issue/3772
  • Additional commits viewable in compare view

Updates @opentelemetry/auto-instrumentations-node from 0.72.0 to 0.73.0

Release notes

Sourced from @​opentelemetry/auto-instrumentations-node's releases.

auto-instrumentations-node: v0.73.0

0.73.0 (2026-04-17)

Features

  • deps: update deps matching '@opentelemetry/*' (#3479) (8891261)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-amqplib bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-aws-lambda bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-aws-sdk bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-bunyan bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-cassandra-driver bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-connect bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-cucumber bumped from ^0.30.0 to ^0.31.0
      • @​opentelemetry/instrumentation-dataloader bumped from ^0.31.0 to ^0.32.0
      • @​opentelemetry/instrumentation-dns bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-express bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.33.0 to ^0.34.0
      • @​opentelemetry/instrumentation-generic-pool bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-graphql bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-hapi bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-ioredis bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-kafkajs bumped from ^0.23.0 to ^0.24.0
      • @​opentelemetry/instrumentation-knex bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-koa bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-lru-memoizer bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-memcached bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-mongodb bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-mongoose bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-mysql bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-mysql2 bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-nestjs-core bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-net bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-openai bumped from ^0.12.0 to ^0.13.0
      • @​opentelemetry/instrumentation-oracledb bumped from ^0.39.0 to ^0.40.0
      • @​opentelemetry/instrumentation-pg bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-pino bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-redis bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-restify bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-router bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-runtime-node bumped from ^0.27.0 to ^0.28.0
      • @​opentelemetry/instrumentation-socket.io bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-tedious bumped from ^0.33.0 to ^0.34.0
      • @​opentelemetry/instrumentation-undici bumped from ^0.24.0 to ^0.25.0

... (truncated)

Changelog

Sourced from @​opentelemetry/auto-instrumentations-node's changelog.

0.73.0 (2026-04-17)

Features

  • deps: update deps matching '@opentelemetry/*' (#3479) (8891261)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-amqplib bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-aws-lambda bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-aws-sdk bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-bunyan bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-cassandra-driver bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-connect bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-cucumber bumped from ^0.30.0 to ^0.31.0
      • @​opentelemetry/instrumentation-dataloader bumped from ^0.31.0 to ^0.32.0
      • @​opentelemetry/instrumentation-dns bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-express bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.33.0 to ^0.34.0
      • @​opentelemetry/instrumentation-generic-pool bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-graphql bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-hapi bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-ioredis bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-kafkajs bumped from ^0.23.0 to ^0.24.0
      • @​opentelemetry/instrumentation-knex bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-koa bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-lru-memoizer bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-memcached bumped from ^0.57.0 to ^0.58.0
      • @​opentelemetry/instrumentation-mongodb bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-mongoose bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-mysql bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-mysql2 bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-nestjs-core bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-net bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-openai bumped from ^0.12.0 to ^0.13.0
      • @​opentelemetry/instrumentation-oracledb bumped from ^0.39.0 to ^0.40.0
      • @​opentelemetry/instrumentation-pg bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-pino bumped from ^0.60.0 to ^0.61.0
      • @​opentelemetry/instrumentation-redis bumped from ^0.62.0 to ^0.63.0
      • @​opentelemetry/instrumentation-restify bumped from ^0.59.0 to ^0.60.0
      • @​opentelemetry/instrumentation-router bumped from ^0.58.0 to ^0.59.0
      • @​opentelemetry/instrumentation-runtime-node bumped from ^0.27.0 to ^0.28.0
      • @​opentelemetry/instrumentation-socket.io bumped from ^0.61.0 to ^0.62.0
      • @​opentelemetry/instrumentation-tedious bumped from ^0.33.0 to ^0.34.0
      • @​opentelemetry/instrumentation-undici bumped from ^0.24.0 to ^0.25.0
      • @​opentelemetry/instrumentation-winston bumped from ^0.58.0 to ^0.59.0

... (truncated)

Commits

Updates @opentelemetry/exporter-metrics-otlp-http from 0.214.0 to 0.215.0

Release notes

Sourced from @​opentelemetry/exporter-metrics-otlp-http's releases.

experimental/v0.215.0

0.215.0

💥 Breaking Changes

  • feat(sdk-logs)!: add required forceFlush() to LogRecordExporter interface #6356 @​pichlermarc
    • (user-facing): LogRecordExporter interface now requires a forceFlush() method to be implemented. Custom exporters will need to implement this method to continue working with the Logs SDK.
  • feat(api-logs, sdk-logs)!: add Logger#enabled() #6371 @​david-luna

🚀 Features

🐛 Bug Fixes

  • fix(instrumentation-fetch): preserve init overrides when input is a Request object #6421 @​akandic47
  • fix(otlp-exporter-base): limit Node.js HTTP transport response body to 4 MiB #6552 @​kartikgola
  • fix(instrumentation-fetch): avoid unwrapping fetch API when disabling #6575 @​david-luna
  • fix(web-common): add check for possible unsafe json parse #6589 @​maryliag
  • fix(otlp-transformer): add check for possible unsafe json parse #6588 @​maryliag
Commits
  • a0476ee chore: prepare next release (#6603)
  • 6bc69c7 fix(instr-fetch): avoid unwrap fetch API (#6575)
  • 840f3d4 chore: re-arrange misplaced changelog entries (#6604)
  • 2da8d39 feat(configuration): refactoring config loader to print warning message for b...
  • 401af13 fix(deps): update dependency protobufjs to v8 (#6602)
  • 36e2a9a fix(opentelemetry-core): add extra checks on internal merge function for safe...
  • 8ee2a8b fix(web-common): add check for possible unsafe json parse (#6589)
  • f40fd24 fix(otlp-transformer): add check for possible unsafe json parse (#6588)
  • 394eeb0 chore: update changelog script (#6586)
  • 36ce569 feat(sdk-metrics): adds the cardinalitySelector argument to PeriodicExporting...
  • Additional commits viewable in compare view

Updates @opentelemetry/exporter-trace-otlp-http from 0.214.0 to 0.215.0

Release notes

Sourced from @​opentelemetry/exporter-trace-otlp-http's releases.

experimental/v0.215.0

0.215.0

💥 Breaking Changes

  • feat(sdk-logs)!: add required forceFlush() to LogRecordExporter interface #6356 @​pichlermarc
    • (user-facing): LogRecordExporter interface now requires a forceFlush() method to be implemented. Custom exporters will need to implement this method to continue working with the Logs SDK.
  • feat(api-logs, sdk-logs)!: add Logger#enabled() #6371 @​david-luna

🚀 Features

🐛 Bug Fixes

  • fix(instrumentation-fetch): preserve init overrides when input is a Request object #6421 @​akandic47
  • fix(otlp-exporter-base): limit Node.js HTTP transport response body to 4 MiB #6552 @​kartikgola
  • fix(instrumentation-fetch): avoid unwrapping fetch API when disabling #6575 @​david-luna
  • fix(web-common): add check for possible unsafe json parse #6589 @​maryliag
  • fix(otlp-transformer): add check for possible unsafe json parse #6588 @​maryliag
Commits
  • a0476ee chore: prepare next release (#6603)
  • 6bc69c7 fix(instr-fetch): avoid unwrap fetch API (#6575)
  • 840f3d4 chore: re-arrange misplaced changelog entries (#6604)
  • 2da8d39 feat(configuration): refactoring config loader to print warning message for b...
  • 401af13 fix(deps): update dependency protobufjs to v8 (#6602)
  • 36e2a9a fix(opentelemetry-core): add extra checks on internal merge function for safe...
  • 8ee2a8b fix(web-common): add check for possible unsafe json parse (#6589)
  • f40fd24 fix(otlp-transformer): add check for possible unsafe json parse (#6588)
  • 394eeb0 chore: update changelog script (#6586)
  • 36ce569 feat(sdk-metrics): adds the cardinalitySelector argument to PeriodicExporting...
  • Additional commits viewable in compare view

Updates @opentelemetry/exporter-trace-otlp-proto from 0.214.0 to 0.215.0

Release notes

Sourced from @​opentelemetry/exporter-trace-otlp-proto's releases.

experimental/v0.215.0

0.215.0

💥 Breaking Changes

  • feat(sdk-logs)!: add required forceFlush() to LogRecordExporter interface #6356 @​pichlermarc
    • (user-facing): LogRecordExporter interface now requires a forceFlush() method to be implemented. Custom exporters will need to implement this method to continue working with the Logs SDK.
  • feat(api-logs, sdk-logs)!: add Logger#enabled() #6371 @​david-luna

🚀 Features

🐛 Bug Fixes

  • fix(instrumentation-fetch): preserve init overrides when input is a Request object #6421 @​akandic47
  • fix(otlp-exporter-base): limit Node.js HTTP transport response body to 4 MiB #6552 @​kartikgola
  • fix(instrumentation-fetch): avoid unwrapping fetch API when disabling #6575 @​david-luna
  • fix(web-common): add check for possible unsafe json parse #6589 @​maryliag
  • fix(otlp-transformer): add check for possible unsafe json parse #6588 @​maryliag
Commits
  • a0476ee chore: prepare next release (#6603)
  • 6bc69c7 fix(instr-fetch): avoid unwrap fetch API (#6575)
  • 840f3d4 chore: re-arrange misplaced changelog entries (#6604)
  • 2da8d39 feat(configuration): refactoring config loader to print warning message for b...
  • 401af13 fix(deps): update dependency protobufjs to v8 (#6602)
  • 36e2a9a fix(opentelemetry-core): add extra checks on internal merge function for safe...
  • 8ee2a8b fix(web-common): add check for possible unsafe json parse (#6589)
  • f40fd24 fix(otlp-transformer): add check for possible unsafe json parse (#6588)
  • 394eeb0 chore: update changelog script (#6586)
  • 36ce569 feat(sdk-metrics): adds the cardinalitySelector argument to PeriodicExporting...
  • Additional commits viewable in compare view

Updates @opentelemetry/resources from 2.6.1 to 2.7.0

Release notes

Sourced from @​opentelemetry/resources's releases.

v2.7.0

2.7.0

🚀 Features

  • feat(sdk-logs): implement log creation metrics #6433 @​anuraaga
  • feat(sdk-metrics): add the cardinalitySelector argument to PeriodicExportingMetricReaders #6460 @​starzlocker
  • feat(opentelemetry-core): add extra checks on internal merge function for safety #6587 @​maryliag

🐛 Bug Fixes

  • fix(opentelemetry-resources): do not discard OTEL_RESOURCE_ATTRIBUTES when it contains empty kv pairs

🏠 Internal

Changelog

Sourced from @​opentelemetry/resources's changelog.

2.7.0

🚀 Features

  • feat(sdk-logs): implement log creation metrics #6433 @​anuraaga
  • feat(sdk-metrics): add the cardinalitySelector argument to PeriodicExportingMetricReaders #6460 @​starzlocker
  • feat(opentelemetry-core): add extra checks on internal merge function for safety #6587 @​maryliag

🐛 Bug Fixes

  • fix(opentelemetry-resources): do not discard OTEL_RESOURCE_ATTRIBUTES when it contains empty kv pairs

🏠 Internal

Commits
  • a0476ee chore: prepare next release (#6603)
  • 6bc69c7 fix(instr-fetch): avoid unwrap fetch API (#6575)
  • 840f3d4 chore: re-arrange misplaced changelog entries (#6604)
  • 2da8d39 feat(configuration): refactoring config loader to print warning message for b...
  • 401af13 fix(deps): update dependency protobufjs to v8 (#6602)
  • 36e2a9a fix(opentelemetry-core): add extra checks on internal merge function for safe...
  • 8ee2a8b fix(web-common): add check for possible unsafe json parse (#6589)
  • f40fd24 fix(otlp-transformer): add check for possible unsafe json parse (#6588)
  • 394eeb0 chore: update changelog script (#6586)
  • 36ce569 feat(sdk-metrics): adds the cardinalitySelector argument to PeriodicExporting...
  • Additional commits viewable in compare view

Updates @opentelemetry/sdk-metrics from 2.6.1 to 2.7.0

Release notes

Sourced from @​opentelemetry/sdk-metrics's releases.

v2.7.0

2.7.0

🚀 Features

  • feat(sdk-logs): implement log creation metrics #6433 @​anuraaga
  • feat(sdk-metrics): add the cardinalitySelector argument to PeriodicExportingMetricReaders #6460 @​starzlocker
  • feat(opentelemetry-core): add extra checks on internal merge function for safety #6587 @​maryliag

🐛 Bug Fixes

  • fix(opentelemetry-resources): do not discard OTEL_RESOURCE_ATTRIBUTES when it contains empty kv pairs

🏠 Internal

Changelog

Sourced from @​opentelemetry/sdk-metrics's changelog.

2.7.0

🚀 Features

  • feat(sdk-logs): implement log creation metrics #6433 @​anuraaga
  • feat(sdk-metrics): add the cardinalitySelector argument to PeriodicExportingMetricReaders #6460 @​starzlocker
  • feat(opentelemetry-core): add extra checks on internal merge function for safety #6587 @​maryliag

🐛 Bug Fixes

  • fix(opentelemetry-resources): do not discard OTEL_RESOURCE_ATTRIBUTES when it contains empty kv pairs

🏠 Internal

Commits
  • a0476ee chore: prepare next release (#6603)
  • 6bc69c7 fix(instr-fetch): avoid unwrap fetch API (#6575)
  • 840f3d4 chore: re-arrange misplaced changelog entries (#6604)
  • 2da8d39 feat(configuration): refactoring config loader to print warning message for b...
  • 401af13 fix(deps): update dependency protobufjs to v8 (#6602)
  • 36e2a9a fix(opentelemetry-core): add extra checks on internal merge function for safe...
  • 8ee2a8b fix(web-common): add check for possible unsafe json parse (#6589)
  • f40fd24 fix(otlp-transformer): add check for possible unsafe json parse (#6588)
  • 394eeb0 chore: update changelog script (#6586)
  • 36ce569 feat(sdk-metrics): adds the cardinalitySelector argument to PeriodicExporting...
  • Additional commits viewable in compare view

Updates @opentelemetry/sdk-node from 0.214.0 to 0.215.0

Release notes

Sourced from @​opentelemetry/sdk-node's releases.

experimental/v0.215.0

0.215.0

💥 Breaking Changes

  • feat(sdk-logs)!: add required forceFlush() to LogRecordExporter interface #6356 @​pichlermarc
    • (user-facing): LogRecordExporter interface now requires a forceFlush() method to be implemented. Custom exporters will need to implement this method to continue working with the Logs SDK.
  • feat(api-logs, sdk-logs)!: add Logger#enabled() #6371 @​david-luna

🚀 Features

🐛 Bug Fixes

  • fix(instrumentation-fetch): preserve init overrides when input is a Request object #6421 @​akandic47
  • fix(otlp-exporter-base): limit Node.js HTTP transport response body to 4 MiB #6552 @​kartikgola
  • fix(instrumentation-fetch): avoid unwrapping fetch API when disabling #6575 @​david-luna
  • fix(web-common): add check for possible unsafe json parse #6589 @​maryliag
  • fix(otlp-transformer): add check for possible unsafe json parse #6588 @​maryliag
Commits
  • a0476ee chore: prepare next release (#6603)
  • 6bc69c7 fix(instr-fetch): avoid unwrap fetch API (#6575)
  • 840f3d4 chore: re-arrange misplaced changelog entries (#6604)
  • 2da8d39 feat(configuration): refactoring config loader to print warning message for b...
  • 401af13 fix(deps): update dependency protobufjs to v8 (#6602)
  • 36e2a9a fix(opentelemetry-core): add extra checks on internal merge function for safe...
  • 8ee2a8b fix(web-common): add check for possible unsafe json parse (#6589)
  • f40fd24 fix(otlp-transformer): add check for possible unsafe json parse (#6588)
  • 394eeb0 chore: update changelog script (#6586)
  • 36ce569 feat(sdk-metrics): adds the cardinalitySelector argument to PeriodicExporting...
  • Additional commits viewable in compare view

Updates axios from 1.14.0 to 1.15.1

Release notes

Sourced from axios's releases.

v1.15.1

This release ships a coordinated set of security hardening fixes across headers, body/redirect limits, multipart handling, and XSRF/prototype-pollution vectors, alongside a broad sweep of bug fixes, test migrations, and threat-model documentation updates.

🔒 Security Fixes

  • Header Injection Hardening: Tightened validation and sanitisation across request header construction to close the header-injection attack surface. (#10749)
  • CRLF Stripping in Multipart Headers: Correctly strips CR/LF from multipart header values to prevent injection via field names and filenames. (#10758)
  • Prototype Pollution / Auth Bypass: Replaced unsafe in checks with hasOwnProperty to prevent authentication bypass via prototype pollution on config objects, with additional regression tests. (#10761, #10760)
  • withXSRFToken Truthy Bypass: Short-circuits on any truthy non-boolean value, so an ambiguous config no longer silently leaks the XSRF token cross-origin. (#10762)
  • maxBodyLength With Zero Redirects: Enforces maxBodyLength even when maxRedirects is set to 0, closing a bypass path for oversized request bodies. (#10753)
  • Streamed Response maxContentLength Bypass: Applies maxContentLength to streamed responses that previously bypassed the cap. (#10754)
  • Follow-up CVE Completion: Completes an earlier incomplete CVE fix to fully close the regression window. (#10755)

🚀 New Features

  • AI-Based Docs Translations: Initial scaffold for AI-assisted translations of the documentation site. (<...

    Description has been truncated

…pdates

Bumps the dependencies group with 20 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@nestjs/common](https://github.com/nestjs/nest/tree/HEAD/packages/common) | `11.1.18` | `11.1.19` |
| [@nestjs/core](https://github.com/nestjs/nest/tree/HEAD/packages/core) | `11.1.18` | `11.1.19` |
| [@nestjs/platform-express](https://github.com/nestjs/nest/tree/HEAD/packages/platform-express) | `11.1.18` | `11.1.19` |
| [@nestjs/swagger](https://github.com/nestjs/swagger) | `11.2.6` | `11.3.0` |
| [@opentelemetry/auto-instrumentations-node](https://github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/auto-instrumentations-node) | `0.72.0` | `0.73.0` |
| [@opentelemetry/exporter-metrics-otlp-http](https://github.com/open-telemetry/opentelemetry-js) | `0.214.0` | `0.215.0` |
| [@opentelemetry/exporter-trace-otlp-http](https://github.com/open-telemetry/opentelemetry-js) | `0.214.0` | `0.215.0` |
| [@opentelemetry/exporter-trace-otlp-proto](https://github.com/open-telemetry/opentelemetry-js) | `0.214.0` | `0.215.0` |
| [@opentelemetry/resources](https://github.com/open-telemetry/opentelemetry-js) | `2.6.1` | `2.7.0` |
| [@opentelemetry/sdk-metrics](https://github.com/open-telemetry/opentelemetry-js) | `2.6.1` | `2.7.0` |
| [@opentelemetry/sdk-node](https://github.com/open-telemetry/opentelemetry-js) | `0.214.0` | `0.215.0` |
| [axios](https://github.com/axios/axios) | `1.14.0` | `1.15.1` |
| [dotenv](https://github.com/motdotla/dotenv) | `17.4.1` | `17.4.2` |
| [@nestjs/cli](https://github.com/nestjs/nest-cli) | `11.0.18` | `11.0.21` |
| [@nestjs/schematics](https://github.com/nestjs/schematics) | `11.0.10` | `11.1.0` |
| [eslint](https://github.com/eslint/eslint) | `9.39.2` | `9.39.4` |
| [globals](https://github.com/sindresorhus/globals) | `17.4.0` | `17.5.0` |
| [prettier](https://github.com/prettier/prettier) | `3.8.1` | `3.8.3` |
| [typedoc](https://github.com/TypeStrong/TypeDoc) | `0.28.18` | `0.28.19` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.58.0` | `8.58.2` |



Updates `@nestjs/common` from 11.1.18 to 11.1.19
- [Release notes](https://github.com/nestjs/nest/releases)
- [Commits](https://github.com/nestjs/nest/commits/v11.1.19/packages/common)

Updates `@nestjs/core` from 11.1.18 to 11.1.19
- [Release notes](https://github.com/nestjs/nest/releases)
- [Commits](https://github.com/nestjs/nest/commits/v11.1.19/packages/core)

Updates `@nestjs/platform-express` from 11.1.18 to 11.1.19
- [Release notes](https://github.com/nestjs/nest/releases)
- [Commits](https://github.com/nestjs/nest/commits/v11.1.19/packages/platform-express)

Updates `@nestjs/swagger` from 11.2.6 to 11.3.0
- [Release notes](https://github.com/nestjs/swagger/releases)
- [Commits](nestjs/swagger@11.2.6...11.3.0)

Updates `@opentelemetry/auto-instrumentations-node` from 0.72.0 to 0.73.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js-contrib/blob/main/packages/auto-instrumentations-node/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-js-contrib/commits/auto-instrumentations-node-v0.73.0/packages/auto-instrumentations-node)

Updates `@opentelemetry/exporter-metrics-otlp-http` from 0.214.0 to 0.215.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.214.0...experimental/v0.215.0)

Updates `@opentelemetry/exporter-trace-otlp-http` from 0.214.0 to 0.215.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.214.0...experimental/v0.215.0)

Updates `@opentelemetry/exporter-trace-otlp-proto` from 0.214.0 to 0.215.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.214.0...experimental/v0.215.0)

Updates `@opentelemetry/resources` from 2.6.1 to 2.7.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v2.6.1...v2.7.0)

Updates `@opentelemetry/sdk-metrics` from 2.6.1 to 2.7.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v2.6.1...v2.7.0)

Updates `@opentelemetry/sdk-node` from 0.214.0 to 0.215.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.214.0...experimental/v0.215.0)

Updates `axios` from 1.14.0 to 1.15.1
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.14.0...v1.15.1)

Updates `dotenv` from 17.4.1 to 17.4.2
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v17.4.1...v17.4.2)

Updates `@nestjs/cli` from 11.0.18 to 11.0.21
- [Release notes](https://github.com/nestjs/nest-cli/releases)
- [Commits](nestjs/nest-cli@11.0.18...11.0.21)

Updates `@nestjs/schematics` from 11.0.10 to 11.1.0
- [Release notes](https://github.com/nestjs/schematics/releases)
- [Commits](nestjs/schematics@11.0.10...11.1.0)

Updates `eslint` from 9.39.2 to 9.39.4
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v9.39.2...v9.39.4)

Updates `globals` from 17.4.0 to 17.5.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.4.0...v17.5.0)

Updates `prettier` from 3.8.1 to 3.8.3
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.8.1...3.8.3)

Updates `typedoc` from 0.28.18 to 0.28.19
- [Release notes](https://github.com/TypeStrong/TypeDoc/releases)
- [Changelog](https://github.com/TypeStrong/typedoc/blob/master/CHANGELOG.md)
- [Commits](TypeStrong/typedoc@v0.28.18...v0.28.19)

Updates `typescript-eslint` from 8.58.0 to 8.58.2
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.58.2/packages/typescript-eslint)

---
updated-dependencies:
- dependency-name: "@nestjs/common"
  dependency-version: 11.1.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: "@nestjs/core"
  dependency-version: 11.1.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: "@nestjs/platform-express"
  dependency-version: 11.1.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: "@nestjs/swagger"
  dependency-version: 11.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: "@opentelemetry/auto-instrumentations-node"
  dependency-version: 0.73.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: "@opentelemetry/exporter-metrics-otlp-http"
  dependency-version: 0.215.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: "@opentelemetry/exporter-trace-otlp-http"
  dependency-version: 0.215.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: "@opentelemetry/exporter-trace-otlp-proto"
  dependency-version: 0.215.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: "@opentelemetry/resources"
  dependency-version: 2.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: "@opentelemetry/sdk-metrics"
  dependency-version: 2.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: "@opentelemetry/sdk-node"
  dependency-version: 0.215.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: axios
  dependency-version: 1.15.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: dotenv
  dependency-version: 17.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: "@nestjs/cli"
  dependency-version: 11.0.21
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: "@nestjs/schematics"
  dependency-version: 11.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: eslint
  dependency-version: 9.39.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: globals
  dependency-version: 17.5.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: prettier
  dependency-version: 3.8.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: typedoc
  dependency-version: 0.28.19
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: typescript-eslint
  dependency-version: 8.58.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 20, 2026
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 11, 2026

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this May 11, 2026
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/dependencies-b89b9b5a2e branch May 11, 2026 03:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code package

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants