Skip to content

build(deps): bump the patch-and-minor group with 4 updates - #545

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/patch-and-minor-b057b1e01a
Open

build(deps): bump the patch-and-minor group with 4 updates#545
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/patch-and-minor-b057b1e01a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the patch-and-minor group with 4 updates: @aws-sdk/client-secrets-manager, @opentelemetry/auto-instrumentations-node, @opentelemetry/sdk-node and lint-staged.

Updates @aws-sdk/client-secrets-manager from 3.1121.0 to 3.1127.0

Release notes

Sourced from @​aws-sdk/client-secrets-manager's releases.

v3.1127.0

3.1127.0(2026-09-04)

New Features
  • client-mediatailor: Elemental MediaTailor now supports two new Monetization Functions lifecycle hooks, Post Ads Response and Pre Manifest Insertion, and a VAST Request function type that calls a VAST or VMAP ad server. This release also adds Yield Optimization with demand from Amazon Publisher Services. (c238a693)
  • client-service-quotas: Service Quotas adds the AdjustableAtLevel property to QuotaContext, indicating whether a quota is adjustable at the account or resource level. (f56bdf2c)
  • client-bedrock: New AWS REVIEW mode as supported data retention mode for Bedrock models (cbd9ea9a)
  • client-ec2: Adds support for ValidateSecurityGroupQuotasForInterface, an API that specifically authorized AWS services use to validate security group rule quotas before creating an elastic network interface. (f51c3b3e)

For list of updated packages, view updated-packages.md in assets-3.1127.0.zip

v3.1126.0

3.1126.0(2026-09-03)

Documentation Changes
  • client-sfn: Updates Step Functions API documentation around CloudTrail, Execution name reuse and sort order of ListExecutions API (8dda8b4b)
  • client-elastic-load-balancing-v2: This release adds support for sending TCP resets for Gateway Load Balancer when a flow's idle timeout expires, or when a target becomes unhealthy or is deregistered. This adds updates the CLI documentation. (a16f1659)
New Features
  • client-socialmessaging: Adding support for WhatsApp Flows with endpoints. (3a3a6205)
  • client-transfer: AWS Transfer Family SFTP Connectors now support specifying an ordered list of AWS Secrets Manager version stages for secret retrieval. This enables seamless credential rotation workflows where external partners may take time to update their systems with new credentials. (e4bf3ecc)
  • client-transcribe: Amazon Transcribe now supports specifying up to 29 PII entity types in the ContentRedaction configuration of a StartTranscriptionJob request, allowing all supported entity types to be redacted in a single batch transcription job. (5fb0b9a5)
  • client-connect: This release enables TagOnCreate for Rule resource on CreateRule API. It also introduces a new field called PreEvaluationFilters to Rule resource, thereby impacting all Create, Update, Describe and Search APIs for Rules (18bb14bc)
  • client-ecs: Adds a critical parameter to the Amazon ECS managed daemon APIs that controls whether a daemon task failure drains the container instance. Non-critical daemon failures no longer drain the instance or block instance registration. (2e6a07d5)
  • client-evs: Amazon EVS now allows users to set, update, and retrieve values for parameters that apply across all EVS Environments in their account at a regional level, such as the VCF License portability core count. (803b694c)
  • client-drs: AWS Elastic Disaster Recovery now includes source server architecture in SourceProperties to identify x86 and ARM64 systems. (20f19e0e)
  • client-bedrock-agentcore: Adds log group name prefix trace source selection, custom or source log group result destinations, and metrics namespace customization (823b2d33)
  • client-bedrock-agentcore-control: AgentCore Identity adds Consent Portal APIs to manage portals that let end users grant OAuth authorization for agents to access resources. AgentCore Evaluation adds trace source selection by log group prefix, custom or source log group result destinations, and metrics namespace customization. (2f826477)
  • client-eks: Deprecate EncryptionConfig resources field. Amazon EKS encrypts all Kubernetes API data with envelope encryption by default for clusters running Kubernetes version 1.28 or higher, so this field no longer affects which resources are encrypted. (c66ca41b)
  • client-guardduty: Adding support for Sequence Activities in GuardDuty Findings (5c12a0eb)
  • lib-transfer-manager: add download directory functionality (#8274) (6e591ee8)

For list of updated packages, view updated-packages.md in assets-3.1126.0.zip

v3.1125.0

3.1125.0(2026-09-02)

New Features
  • client-ec2: This release adds support to retain interruptible Capacity Reservations in an active state when all capacity is reclaimed. (336c7896)
  • client-sagemaker-featurestore-runtime: Amazon SageMaker Feature Store now supports the UpdateRecord API, enabling partial updates to individual feature values in an existing Online Store record without rewriting the entire record. This reduces write payloads and latency for high-frequency feature-level writes . (71920960)

... (truncated)

Changelog

Sourced from @​aws-sdk/client-secrets-manager's changelog.

3.1127.0 (2026-09-04)

Note: Version bump only for package @​aws-sdk/client-secrets-manager

3.1126.0 (2026-09-03)

Note: Version bump only for package @​aws-sdk/client-secrets-manager

3.1125.0 (2026-09-02)

Note: Version bump only for package @​aws-sdk/client-secrets-manager

3.1124.0 (2026-09-01)

Note: Version bump only for package @​aws-sdk/client-secrets-manager

3.1123.0 (2026-08-31)

Note: Version bump only for package @​aws-sdk/client-secrets-manager

3.1122.0 (2026-08-31)

Note: Version bump only for package @​aws-sdk/client-secrets-manager

Commits

Updates @opentelemetry/auto-instrumentations-node from 0.79.0 to 0.80.0

Release notes

Sourced from @​opentelemetry/auto-instrumentations-node's releases.

auto-instrumentations-node: v0.80.0

0.80.0 (2026-08-31)

Features

  • deps: update deps matching '@opentelemetry/*' (#3716) (015582a)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-amqplib bumped from ^0.68.0 to ^0.69.0
      • @​opentelemetry/instrumentation-aws-lambda bumped from ^0.73.0 to ^0.74.0
      • @​opentelemetry/instrumentation-aws-sdk bumped from ^0.76.0 to ^0.77.0
      • @​opentelemetry/instrumentation-bunyan bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-cassandra-driver bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-connect bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-cucumber bumped from ^0.37.0 to ^0.38.0
      • @​opentelemetry/instrumentation-dataloader bumped from ^0.38.0 to ^0.39.0
      • @​opentelemetry/instrumentation-dns bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-express bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.40.0 to ^0.41.0
      • @​opentelemetry/instrumentation-generic-pool bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-graphql bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-hapi bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-host-metrics bumped from ^0.4.0 to ^0.5.0
      • @​opentelemetry/instrumentation-ioredis bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-kafkajs bumped from ^0.30.0 to ^0.31.0
      • @​opentelemetry/instrumentation-knex bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-koa bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-lru-memoizer bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-memcached bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-mongodb bumped from ^0.74.0 to ^0.75.0
      • @​opentelemetry/instrumentation-mongoose bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-mysql bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-mysql2 bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-nestjs-core bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-net bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-openai bumped from ^0.19.0 to ^0.20.0
      • @​opentelemetry/instrumentation-oracledb bumped from ^0.46.0 to ^0.47.0
      • @​opentelemetry/instrumentation-pg bumped from ^0.73.0 to ^0.74.0
      • @​opentelemetry/instrumentation-pino bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-redis bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-restify bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-router bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-runtime-node bumped from ^0.34.0 to ^0.35.0
      • @​opentelemetry/instrumentation-socket.io bumped from ^0.68.0 to ^0.69.0
      • @​opentelemetry/instrumentation-tedious bumped from ^0.40.0 to ^0.41.0

... (truncated)

Changelog

Sourced from @​opentelemetry/auto-instrumentations-node's changelog.

0.80.0 (2026-08-31)

Features

  • deps: update deps matching '@opentelemetry/*' (#3716) (015582a)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​opentelemetry/instrumentation-amqplib bumped from ^0.68.0 to ^0.69.0
      • @​opentelemetry/instrumentation-aws-lambda bumped from ^0.73.0 to ^0.74.0
      • @​opentelemetry/instrumentation-aws-sdk bumped from ^0.76.0 to ^0.77.0
      • @​opentelemetry/instrumentation-bunyan bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-cassandra-driver bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-connect bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-cucumber bumped from ^0.37.0 to ^0.38.0
      • @​opentelemetry/instrumentation-dataloader bumped from ^0.38.0 to ^0.39.0
      • @​opentelemetry/instrumentation-dns bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-express bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-fs bumped from ^0.40.0 to ^0.41.0
      • @​opentelemetry/instrumentation-generic-pool bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-graphql bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-hapi bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-host-metrics bumped from ^0.4.0 to ^0.5.0
      • @​opentelemetry/instrumentation-ioredis bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-kafkajs bumped from ^0.30.0 to ^0.31.0
      • @​opentelemetry/instrumentation-knex bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-koa bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-lru-memoizer bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-memcached bumped from ^0.64.0 to ^0.65.0
      • @​opentelemetry/instrumentation-mongodb bumped from ^0.74.0 to ^0.75.0
      • @​opentelemetry/instrumentation-mongoose bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-mysql bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-mysql2 bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-nestjs-core bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-net bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-openai bumped from ^0.19.0 to ^0.20.0
      • @​opentelemetry/instrumentation-oracledb bumped from ^0.46.0 to ^0.47.0
      • @​opentelemetry/instrumentation-pg bumped from ^0.73.0 to ^0.74.0
      • @​opentelemetry/instrumentation-pino bumped from ^0.67.0 to ^0.68.0
      • @​opentelemetry/instrumentation-redis bumped from ^0.69.0 to ^0.70.0
      • @​opentelemetry/instrumentation-restify bumped from ^0.66.0 to ^0.67.0
      • @​opentelemetry/instrumentation-router bumped from ^0.65.0 to ^0.66.0
      • @​opentelemetry/instrumentation-runtime-node bumped from ^0.34.0 to ^0.35.0
      • @​opentelemetry/instrumentation-socket.io bumped from ^0.68.0 to ^0.69.0
      • @​opentelemetry/instrumentation-tedious bumped from ^0.40.0 to ^0.41.0
      • @​opentelemetry/instrumentation-undici bumped from ^0.31.0 to ^0.32.0

... (truncated)

Commits

Updates @opentelemetry/sdk-node from 0.221.0 to 0.222.0

Release notes

Sourced from @​opentelemetry/sdk-node's releases.

experimental/v0.222.0

0.222.0

💥 Breaking Changes

  • fix(sdk-node)!: fail-fast on Propagator creation from config file #6930 @​trentm
  • fix(sdk-node)!: fail-fast on MeterProvider creation from config file #6954 @​trentm
  • fix(sdk-node)!: fail-fast on TracerProvider creation from config file #6962 @​trentm
  • fix(sdk-node)!: fail-fast on Resource creation from config file #6989 @​trentm
    • This also breaks some usage of startNodeSDK() for environment-based config, i.e. when not using a config file. For example with OTEL_NODE_RESOURCE_DETECTORS=all, it results in an error message and a no-op SDK. (This does not impact users of new NodeSDK() -- the currently recommended mechanism to start an SDK using this package.)

      Could not create OpenTelemetry SDK from configuration, SDK will not be setup: unknown ExperimentalResourceDetector name in configuration: "container"

🚀 Features

🐛 Bug Fixes

  • fix(instrumentation-http): redact sensitive query parameters on incoming (server) spans; add redactedQueryParamsServer config option @​dyladan
  • fix(sdk-node): support headers_list when creating OTLP exporters from declarative configuration #6953 @​JacksonWeber

📚 Documentation

🏠 Internal

  • refactor(sampler-jaeger-remote): remove axios dependency and use fetch to get the sampler configuration from Jaeger API #6963 @​david-luna
Commits
  • 0b72a81 chore: prepare next release (#7044)
  • a9c5338 ci: roll prerelease changelog into one final release changelog (#7045)
  • f41805e chore: prepare next release (#7042)
  • b85eb28 chore(instrumentation-http): fix lint errors (#7039)
  • 3f92530 ci: support pre-releases and major version bumps in release workflow (#7035)
  • 82a5831 docs(otlp-exporter-base): document HTTP exporter options (#6735)
  • e086dec Merge commit from fork
  • 59dac70 chore(deps): update jamesives/github-pages-deploy-action action to v4.9.0 (#7...
  • d0ce753 chore: add @​maryliag to maintainers (#7024)
  • 03469a1 chore(deps): update open-telemetry/shared-workflows action to v0.10.0 (#7032)
  • Additional commits viewable in compare view

Updates lint-staged from 17.4.1 to 17.5.0

Release notes

Sourced from lint-staged's releases.

v17.5.0

Minor Changes

  • #1847 f9063b7 - Lint-staged now refuses to run when files were staged with --intent-to-add, because Git stash doesn't support them. Previously this was an unhandled error.

Patch Changes

  • #1848 d718ccc - Lint-staged now handles color support better in non-TTY streams, and honors the FORCE_COLOR environment variable.

  • #1845 7e5ece8 - Update tinyexec@1.3.1 so that local binaries from node_modules/.bin are resolved starting from the directory of each lint-staged configuration file (in monorepo setups). This behavior was broken in lint-staged@16.3.0 where they were only resolved from the current working directory and up.

  • #1845 eb8a4e3 - Do not try to restore untracked files when using --hide-all and there is no initial commit yet.

Changelog

Sourced from lint-staged's changelog.

17.5.0

Minor Changes

  • #1847 f9063b7 - Lint-staged now refuses to run when files were staged with --intent-to-add, because Git stash doesn't support them. Previously this was an unhandled error.

Patch Changes

  • #1848 d718ccc - Lint-staged now handles color support better in non-TTY streams, and honors the FORCE_COLOR environment variable.

  • #1845 7e5ece8 - Update tinyexec@1.3.1 so that local binaries from node_modules/.bin are resolved starting from the directory of each lint-staged configuration file (in monorepo setups). This behavior was broken in lint-staged@16.3.0 where they were only resolved from the current working directory and up.

  • #1845 eb8a4e3 - Do not try to restore untracked files when using --hide-all and there is no initial commit yet.

Commits
  • dcb59f6 Merge pull request #1846 from lint-staged/changeset-release/main
  • 9c8c6dc chore(changeset): release
  • 586466f Merge pull request #1849 from lint-staged/improve-intent-to-add
  • 45eda5f refactor: improve --intent-to-add detection
  • 26372e3 Merge pull request #1848 from lint-staged/fix-color-detection
  • d718ccc fix: honor FORCE_COLOR/NO_COLOR env variables in non-TTY streams
  • be78a51 Merge pull request #1847 from lint-staged/intent-to-add
  • f9063b7 feat: refuse to run when files were staged with --intent-to-add
  • a767299 Merge pull request #1845 from lint-staged/updates
  • 61ffd25 style: add VS Code extension config
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the patch-and-minor group with 4 updates: [@aws-sdk/client-secrets-manager](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-secrets-manager), [@opentelemetry/auto-instrumentations-node](https://github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/auto-instrumentations-node), [@opentelemetry/sdk-node](https://github.com/open-telemetry/opentelemetry-js) and [lint-staged](https://github.com/lint-staged/lint-staged).


Updates `@aws-sdk/client-secrets-manager` from 3.1121.0 to 3.1127.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-secrets-manager/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1127.0/clients/client-secrets-manager)

Updates `@opentelemetry/auto-instrumentations-node` from 0.79.0 to 0.80.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js-contrib/blob/main/packages/auto-instrumentations-node/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-js-contrib/commits/auto-instrumentations-node-v0.80.0/packages/auto-instrumentations-node)

Updates `@opentelemetry/sdk-node` from 0.221.0 to 0.222.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@experimental/v0.221.0...experimental/v0.222.0)

Updates `lint-staged` from 17.4.1 to 17.5.0
- [Release notes](https://github.com/lint-staged/lint-staged/releases)
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md)
- [Commits](lint-staged/lint-staged@v17.4.1...v17.5.0)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-secrets-manager"
  dependency-version: 3.1127.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: "@opentelemetry/auto-instrumentations-node"
  dependency-version: 0.80.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: "@opentelemetry/sdk-node"
  dependency-version: 0.222.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: lint-staged
  dependency-version: 17.5.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backend dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant