Skip to content

chore(deps-tauri): bump the minor-and-patch group across 1 directory with 6 updates - #100

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/tauri-nextjs-starter/minor-and-patch-51392538d6
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/tauri-nextjs-starter/minor-and-patch-51392538d6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 6 updates in the /tauri-nextjs-starter directory:

Package From To
@tauri-apps/api 2.11.1 2.12.1
radix-ui 1.6.4 1.7.0
shadcn 4.11.0 4.21.3
tailwind-merge 3.6.0 3.7.0
@next/eslint-plugin-next 16.2.10 16.3.8
eslint-config-next 16.2.10 16.3.8

Updates @tauri-apps/api from 2.11.1 to 2.12.1

Release notes

Sourced from @​tauri-apps/api's releases.

@​tauri-apps/api v2.12.1

All found vulnerabilities were already reviewed and decided to be ignored
2 ignored: 2 high

[2.12.1]

Bug Fixes

  • c9a3cb892 (#16166 by @​FabianLars) The macos-private-api feature flag / macOSPrivateAPI tauri.conf.json value is no longer required to use transparency or fullscreen on macOS.
$ pnpm build && cd ./dist && pnpm publish --access public --loglevel debug --no-git-checks
$ rollup -c --configPlugin typescript
�[36m
�[1m./src/app.ts, ./src/core.ts, ./src/dpi.ts, ./src/event.ts, ./src/image.ts, ./src/index.ts, ./src/menu.ts, ./src/mocks.ts, ./src/path.ts, ./src/tray.ts, ./src/webview.ts, ./src/webviewWindow.ts, ./src/window.ts�[22m → �[1m./dist, ./dist�[22m...�[39m
�[32mcreated �[1m./dist, ./dist�[22m in �[1m997ms�[22m�[39m
�[36m
�[1msrc/index.ts�[22m → �[1m../../crates/tauri/scripts/bundle.global.js�[22m...�[39m
�[32mcreated �[1m../../crates/tauri/scripts/bundle.global.js�[22m in �[1m1.5s�[22m�[39m
GET https://run-actions-2-azure-eastus.actions.githubusercontent.com/210//idtoken/dd253aee-436e-8e22-8c02-25aaaa05b17c/69013391-05d6-5397-b35a-e76c0a237b30?api-version=2.0&audience=npm%3Aregistry.npmjs.org 200 336ms
📦 @tauri-apps/api@2.12.1 → https://registry.npmjs.org/
GET https://run-actions-2-azure-eastus.actions.githubusercontent.com/210//idtoken/dd253aee-436e-8e22-8c02-25aaaa05b17c/69013391-05d6-5397-b35a-e76c0a237b30?api-version=2.0&audience=sigstore 200 107ms
Signed provenance statement with source and build information
✅ Published package @tauri-apps/api@2.12.1

@​tauri-apps/api v2.12.0

All found vulnerabilities were already reviewed and decided to be ignored
2 ignored: 2 high

[2.12.0]

... (truncated)

Commits

Updates radix-ui from 1.6.4 to 1.7.0

Changelog

Sourced from radix-ui's changelog.

1.7.0

Dialog

  • Fixed nested, portalled layers being unusable inside a modal layer. A non-modal popover rendered inside a modal Dialog previously broke some user interactions because the modal layer's trapped FocusScope reclaimed focus, and its RemoveScroll only allowed scrolling within the modal content.

Navigation Menu

  • Added a disableToggle prop to NavigationMenu.Sub.
    • true: Clicking the trigger of an already-open submenu item keeps it open. This is the default and matches existing behavior.
    • false: Clicking the trigger of a submenu item toggles it open or closed.
  • Added an activationMode prop to NavigationMenu.Root and NavigationMenu.Sub.
    • "automatic": Hovering or focusing a trigger opens its item, and moving away from the trigger closes it after a short delay. This is the default and matches existing behavior.
    • "manual": Pointer entry and focus never open an item. The item opens when its trigger is clicked.
    • When activationMode is omitted on NavigationMenu.Sub, it inherits the value from the parent NavigationMenu.Root, so setting "manual" on the root also applies to submenus unless a submenu opts back in to "automatic".
  • Fixed a bug where a submenu's defaultValue was reset when an external element was focused before the menu opened.
  • Fixed a bug where NavigationMenu.Viewport discarded its children and rendered the active content in their place. The active content is now rendered inside the consumer's element alongside any children it already had.

Popover

  • Added Popover.Title and Popover.Description parts that provide accessible names and descriptions for popover content.

Scroll Area

  • Added a ScrollArea.Content part so consumers can own the wrapper element implicitly rendered by ScrollArea.Viewport. Pass disableImplicitContentElement to the viewport and render ScrollArea.Content as its child.

    <ScrollArea.Root>
      <ScrollArea.Viewport disableImplicitContentElement>
        <ScrollArea.Content>{children}</ScrollArea.Content>
      </ScrollArea.Viewport>
      <ScrollArea.Scrollbar>
        <ScrollArea.Thumb />
      </ScrollArea.Scrollbar>
    </ScrollArea.Root>

    In the next major release, the viewport will no longer render this element implicitly. We recommend migrating to this API now for a smoother upgrade.

  • Fixed a bug where asChild on ScrollArea.Viewport merged props onto the implicit content element instead of the consumer's element.

Slider

  • Added a preserveThumbOrder prop to Slider that prevents thumbs from crossing over one another. When enabled, each thumb is constrained to the values of its neighbors instead of swapping positions when dragged past them.

Other updates

  • Added support for multiple aria-describedby attributes, so id strings from a component and its child are merged, normalized, and deduplicated instead of one replacing the other.
  • Fixed a bug where internal event handlers were still called on disabled Select.Item elements.
  • Fixed a bug where a paused Toast would not auto-close after its duration changed while the timer was paused.

... (truncated)

Commits

Updates shadcn from 4.11.0 to 4.21.3

Release notes

Sourced from shadcn's releases.

shadcn@4.21.3

Patch Changes

shadcn@4.21.2

Patch Changes

shadcn@4.21.1

Patch Changes

shadcn@4.21.0

Minor Changes

Patch Changes

shadcn@4.20.1

Patch Changes

shadcn@4.20.0

Minor Changes

... (truncated)

Changelog

Sourced from shadcn's changelog.

4.21.3

Patch Changes

4.21.2

Patch Changes

4.21.1

Patch Changes

4.21.0

Minor Changes

Patch Changes

4.20.1

Patch Changes

... (truncated)

Commits
  • d51870f chore(release): version packages (#12152)
  • dba2716 chore(release): version packages (#12141)
  • 95efb5c fix(registry): read components.json and package.json without cosmiconfig (#12...
  • 3b1ae6e fix(registry): skip npm audit and fund when installing dependencies (#12140)
  • 3502dbc chore(release): version packages (#12063)
  • bf6646b feat(registry): extract @​shadcn/registry from shadcn (#12087)
  • a9c1da4 fix(shadcn): apply shimmer reduced motion to variants (#12061)
  • 7bc5604 chore(deps): bump next, astro, postcss, undici, postcss-selector-parser, base...
  • 5c7072d fix(registry): correct logo quoting in directory JSON (#11807)
  • 7c9eaba chore(release): version packages (#11759)
  • Additional commits viewable in compare view

Updates tailwind-merge from 3.6.0 to 3.7.0

Release notes

Sourced from tailwind-merge's releases.

tailwind-merge@3.7.0

New Features

  • Prepare some upcoming changes by @​dcastil in dcastil/tailwind-merge#713
    • Theme getters returned by fromTheme now expose the theme key they read as a themeKey property, so tooling can identify the referenced theme scale without calling the getter.
    • Release tags now include the package name, starting with tailwind-merge@3.7.0.

Bug Fixes

Documentation

Other

Full Changelog: v3.6.0...v3.7.0

Thanks to @​brandonmcconnell, @​manavm1990, @​langy, @​roboflow, @​syntaxfm, @​getsentry, @​codecov, a private sponsor, @​openclaw, @​sourcegraph, @​cesarvcanal, @​CasperKristiansson, @​jbisasky, @​frontendmasters and more via @​thnxdev for sponsoring tailwind-merge! ❤️

Commits
  • 511d68a tailwind-merge@3.7.0
  • 2461127 Release tooling: Pass the namespaced tag prefix and commit message to pnpm's ...
  • 9d41508 add changelog for tailwind-merge@3.7.0
  • c78a80f Configurator: Reuse runtime lookups during pruning
  • 49c317d Monorepo: Fix contributing link and include package coverage
  • 7b565ca Configurator: prune a generated config to a project's used classes (core step)
  • d83e013 Releases: auto-re-pin tag-pinned links on every version bump
  • b71fd41 Docs: pin every in-repo file link to a release tag instead of main
  • ee29441 Docs: point the ThemeObject JSDoc link at the packaged docs location
  • 9521b10 Releases: per-package pipeline with namespaced tags
  • Additional commits viewable in compare view

Updates @next/eslint-plugin-next from 16.2.10 to 16.3.8

Release notes

Sourced from @​next/eslint-plugin-next's releases.

v16.3.8

This release contains security fixes for the following advisories:

High:

Medium:

Low:

v16.3.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • turbo-tasks-backend: fix strongly consistent read hanging on a canceled task (#98931)

Credits

Huge thanks to @​lukesandberg for helping!

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

v16.3.5

The following bug fixes have been backported. It does not include all pending features/changes on canary.

  • next/image: Skip 0-byte entries when initializing disk LRU cache (#98185)
  • next/image: Reject empty images when reading/writing to the disk cache (#98186)
  • Emit whole-app server NFTs when output: 'standalone' is used with an adapter (#98167)
  • Add CSP nonce to script tags of loading and template files (#98403)
  • Fix use cache prerender signal retention (#98448)

v16.3.4

Follow-up release to v16.3.3 re-enabling AVIF Image Optimization (#97949).

The following bug fixes have been backported. It does not include all pending features/changes on canary.

  • testmode: Fix infinite recursion in testmode passthrough fetch (#97691)
  • Fix build error when aliasing typescript to @​typescript/typescript6 (#97997)
  • Fix unset crossOrigin in Turbopack manifests (#97930)

Credits

... (truncated)

Commits

Updates eslint-config-next from 16.2.10 to 16.3.8

Release notes

Sourced from eslint-config-next's releases.

v16.3.8

This release contains security fixes for the following advisories:

High:

Medium:

Low:

v16.3.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • turbo-tasks-backend: fix strongly consistent read hanging on a canceled task (#98931)

Credits

Huge thanks to @​lukesandberg for helping!

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

v16.3.5

The following bug fixes have been backported. It does not include all pending features/changes on canary.

  • next/image: Skip 0-byte entries when initializing disk LRU cache (#98185)
  • next/image: Reject empty images when reading/writing to the disk cache (#98186)
  • Emit whole-app server NFTs when output: 'standalone' is used with an adapter (#98167)
  • Add CSP nonce to script tags of loading and template files (#98403)
  • Fix use cache prerender signal retention (#98448)

v16.3.4

Follow-up release to v16.3.3 re-enabling AVIF Image Optimization (#97949).

The following bug fixes have been backported. It does not include all pending features/changes on canary.

  • testmode: Fix infinite recursion in testmode passthrough fetch (#97691)
  • Fix build error when aliasing typescript to @​typescript/typescript6 (#97997)
  • Fix unset crossOrigin in Turbopack manifests (#97930)

Credits

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…with 6 updates

Bumps the minor-and-patch group with 6 updates in the /tauri-nextjs-starter directory:

| Package | From | To |
| --- | --- | --- |
| [@tauri-apps/api](https://github.com/tauri-apps/tauri) | `2.11.1` | `2.12.1` |
| [radix-ui](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/radix-ui) | `1.6.4` | `1.7.0` |
| [shadcn](https://github.com/shadcn-ui/ui/tree/HEAD/packages/shadcn) | `4.11.0` | `4.21.3` |
| [tailwind-merge](https://github.com/dcastil/tailwind-merge/tree/HEAD/packages/tailwind-merge) | `3.6.0` | `3.7.0` |
| [@next/eslint-plugin-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-plugin-next) | `16.2.10` | `16.3.8` |
| [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.2.10` | `16.3.8` |



Updates `@tauri-apps/api` from 2.11.1 to 2.12.1
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](https://github.com/tauri-apps/tauri/compare/@tauri-apps/api-v2.11.1...@tauri-apps/api-v2.12.1)

Updates `radix-ui` from 1.6.4 to 1.7.0
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/radix-ui/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/radix-ui)

Updates `shadcn` from 4.11.0 to 4.21.3
- [Release notes](https://github.com/shadcn-ui/ui/releases)
- [Changelog](https://github.com/shadcn-ui/ui/blob/main/packages/shadcn/CHANGELOG.md)
- [Commits](https://github.com/shadcn-ui/ui/commits/shadcn@4.21.3/packages/shadcn)

Updates `tailwind-merge` from 3.6.0 to 3.7.0
- [Release notes](https://github.com/dcastil/tailwind-merge/releases)
- [Commits](https://github.com/dcastil/tailwind-merge/commits/tailwind-merge@3.7.0/packages/tailwind-merge)

Updates `@next/eslint-plugin-next` from 16.2.10 to 16.3.8
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.8/packages/eslint-plugin-next)

Updates `eslint-config-next` from 16.2.10 to 16.3.8
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.8/packages/eslint-config-next)

---
updated-dependencies:
- dependency-name: "@tauri-apps/api"
  dependency-version: 2.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: radix-ui
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: shadcn
  dependency-version: 4.21.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: tailwind-merge
  dependency-version: 3.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@next/eslint-plugin-next"
  dependency-version: 16.3.8
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: eslint-config-next
  dependency-version: 16.3.8
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants