Skip to content

chore(deps): bump the npm-deps group across 1 directory with 6 updates - #89

Merged
mroderick merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-deps-44ebebc0c4
Oct 10, 2026
Merged

mroderick merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-deps-44ebebc0c4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm-deps group with 6 updates in the / directory:

Package From To
@better-auth/oauth-provider 1.7.6 1.7.7
@hono/node-server 2.1.1 2.1.3
better-auth 1.7.6 1.7.7
hono 4.13.9 4.13.12
pg 8.23.0 8.23.1
globals 17.12.0 17.13.0

Updates @better-auth/oauth-provider from 1.7.6 to 1.7.7

Release notes

Sourced from @​better-auth/oauth-provider's releases.

v1.7.7

better-auth

Magic Link upgrade: Upgrade servers sharing verification storage together, request new Magic Links, and restart pending OAuth/SAML sign-ins. No database migration is required. See the critical advisory for affected configurations and custom storage changes.

Bug Fixes

  • Fixed a critical Magic Link account-takeover vulnerability. (#11494)
  • Fixed ID-token sign-in ignoring the social provider’s disableSignUp setting. (#11491)
  • Fixed OAuth Proxy accepting sign-in state as a provider profile. (#11494) Upgrade all OAuth Proxy participants together; see the OAuth Proxy upgrade guidance.
  • Fixed CAPTCHA errors missing the JSON Content-Type header. (#11476)
  • Fixed the active organization failing to refresh after sign-in when a session hook selects the initial organization. (#11375)
  • Fixed rate-limit errors missing the JSON Content-Type header. (#11469)

For detailed changes, see CHANGELOG

@better-auth/oauth-provider

Features

  • Added optional validateRedirectUri validation for trusted deployments with dynamic OAuth redirect URIs. (#8686)
  • Added verifyOAuthQueryParams to verify signed authorization queries before rendering a custom consent page. (#11402)

For detailed changes, see CHANGELOG

@better-auth/drizzle-adapter

Bug Fixes

  • Fixed concurrent PostgreSQL requests exceeding database-backed rate limits. (#11331)

For detailed changes, see CHANGELOG

@better-auth/kysely-adapter

Bug Fixes

  • Fixed consumeOne deleting a record after a concurrent write invalidates its original condition. (#11495)

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@​aryan1306, @​bytaesu, @​gitmotion, @​gustavovalverde, @​lennondotw

Full changelog: v1.7.6...v1.7.7

Changelog

Sourced from @​better-auth/oauth-provider's changelog.

1.7.7

Patch Changes

  • #8686 683ac1d Thanks @​lennondotw! - Add an optional validateRedirectUri callback for trusted deployments with dynamic OAuth redirect URIs. Existing configurations keep their registered URI validation behavior.

  • #11402 b26057e Thanks @​gustavovalverde! - Export verifyOAuthQueryParams from the package root, so an application that renders its own consent page can verify the sig/exp this plugin's signParams puts on the authorization query before it renders anything.

Commits
  • db02f23 chore: release v1.7.7 (#11413)
  • 683ac1d feat(oauth-provider): add validateRedirectUri option for custom redirect vali...
  • b26057e feat(oauth-provider): export verifyOAuthQueryParams for consent pages (#11402)
  • c8aaffa docs: fix Wether and publically typos in comments (#11403)
  • See full diff in compare view

Updates @hono/node-server from 2.1.1 to 2.1.3

Release notes

Sourced from @​hono/node-server's releases.

v2.1.3

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: @hono/node-server/serve-static. Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-rmxm-3fg6-px4f

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in hono v4.13.11.

v2.1.2

What's Changed

Full Changelog: honojs/node-server@v2.1.1...v2.1.2

Commits

Updates better-auth from 1.7.6 to 1.7.7

Release notes

Sourced from better-auth's releases.

v1.7.7

better-auth

Magic Link upgrade: Upgrade servers sharing verification storage together, request new Magic Links, and restart pending OAuth/SAML sign-ins. No database migration is required. See the critical advisory for affected configurations and custom storage changes.

Bug Fixes

  • Fixed a critical Magic Link account-takeover vulnerability. (#11494)
  • Fixed ID-token sign-in ignoring the social provider’s disableSignUp setting. (#11491)
  • Fixed OAuth Proxy accepting sign-in state as a provider profile. (#11494) Upgrade all OAuth Proxy participants together; see the OAuth Proxy upgrade guidance.
  • Fixed CAPTCHA errors missing the JSON Content-Type header. (#11476)
  • Fixed the active organization failing to refresh after sign-in when a session hook selects the initial organization. (#11375)
  • Fixed rate-limit errors missing the JSON Content-Type header. (#11469)

For detailed changes, see CHANGELOG

@better-auth/oauth-provider

Features

  • Added optional validateRedirectUri validation for trusted deployments with dynamic OAuth redirect URIs. (#8686)
  • Added verifyOAuthQueryParams to verify signed authorization queries before rendering a custom consent page. (#11402)

For detailed changes, see CHANGELOG

@better-auth/drizzle-adapter

Bug Fixes

  • Fixed concurrent PostgreSQL requests exceeding database-backed rate limits. (#11331)

For detailed changes, see CHANGELOG

@better-auth/kysely-adapter

Bug Fixes

  • Fixed consumeOne deleting a record after a concurrent write invalidates its original condition. (#11495)

For detailed changes, see CHANGELOG

Contributors

Thanks to everyone who contributed to this release:

@​aryan1306, @​bytaesu, @​gitmotion, @​gustavovalverde, @​lennondotw

Full changelog: v1.7.6...v1.7.7

Changelog

Sourced from better-auth's changelog.

1.7.7

Patch Changes

  • #11476 4186e36 Thanks @​bytaesu! - Return CAPTCHA errors with the correct JSON Content-Type header.

  • #11469 8620aa9 Thanks @​aryan1306! - Return rate limit errors with a JSON Content-Type header.

  • #11491 55cb92e Thanks @​bytaesu! - Respect social provider disableSignUp when signing in with an ID token.

  • #11375 69defbc Thanks @​bytaesu! - Refresh the active organization after sign-in when a session hook selects the initial organization.

  • #11494 ac54bfd Thanks @​gustavovalverde! - Isolate OAuth state cookies and each OAuth Proxy payload with purpose-specific encryption keys. The oAuthProxy options and supported configuration remain unchanged.

    Upgrade all Better Auth nodes that handle the same cookie-backed OAuth or SAML relay-state flow together. Upgrade every OAuth Proxy participant, including production and preview or development deployments, in the same cutover. OAuth sign-in, account-linking, and cookie-backed SAML sign-in flows started before the upgrade must be restarted. Mixed old and new participants cannot exchange existing state or proxy payloads, and there is no fallback to the previous shared key.

  • #11494 ac54bfd Thanks @​gustavovalverde! - Magic Link verification now accepts only records issued for Magic Link. Magic Link records and database-backed OAuth or SAML state use separate verification identifier prefixes. Links and database-backed sign-ins started before the upgrade cannot complete; request new Magic Links and restart those sign-ins. Upgrade servers sharing verification storage together, and update verification.storeIdentifier.overrides rules for these flows to match the new magic-link: and auth-state: prefixes. The link token, callback state, endpoints, and public option types are unchanged.

    Upgrade installed Better Auth adapters, plugins, and integrations released with better-auth alongside it so participating packages use the same release version.

  • Updated dependencies [35d7cd3, 07bdf7e]:

    • @​better-auth/drizzle-adapter@​1.7.7
    • @​better-auth/kysely-adapter@​1.7.7
    • @​better-auth/core@​1.7.7
    • @​better-auth/memory-adapter@​1.7.7
    • @​better-auth/mongo-adapter@​1.7.7
    • @​better-auth/prisma-adapter@​1.7.7
    • @​better-auth/telemetry@​1.7.7
Commits
  • db02f23 chore: release v1.7.7 (#11413)
  • ac54bfd fix(auth): isolate verification records and encryption purposes (#11494)
  • 69defbc fix(organization): refresh active organization after email sign-in (#11375)
  • 55cb92e fix(auth): honor social disableSignUp for ID token sign-in (#11491)
  • 4186e36 fix(captcha): return JSON content type for errors (#11476)
  • 8620aa9 fix(rate-limit): set JSON content type on 429 responses (#11469)
  • See full diff in compare view

Updates hono from 4.13.9 to 4.13.12

Release notes

Sourced from hono's releases.

v4.13.12

What's Changed

  • fix(build): keep internal types private in bundled d.ts and avoid a self-referencing JSX.IntrinsicElements in honojs/hono#5485
  • test(build): type-check the bundled declarations from a consumer project in honojs/hono#5486
  • fix(etag): correctly match mixed-case header name in retainedHeader option in honojs/hono#5475
  • fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap in honojs/hono#5487
  • fix(combine): return a Response from a short-circuiting middleware in some() in honojs/hono#5391
  • chore(deps): upgrade vite-plus to 1.0.0 in honojs/hono#5464

Full Changelog: honojs/hono@v4.13.11...v4.13.12

v4.13.11

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: hono/serve-static and the adapters built on it (hono/bun, hono/deno, hono/cloudflare-workers, @hono/bun, @hono/deno, @hono/cloudflare-workers). Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in @hono/node-server v2.1.3.

v4.13.10

Adapters are now separate packages

The runtime adapters are now published as their own packages: @hono/bun, @hono/deno, @hono/cloudflare-workers, @hono/aws-lambda, @hono/lambda-edge, @hono/netlify, @hono/vercel, and @hono/service-worker. @hono/deno is also on JSR.

hono/<adapter> still works in v4 but is deprecated and will be removed in v5. Migrating is an import change:

- import { serveStatic } from 'hono/bun'
+ import { serveStatic } from '@hono/bun'

hono/cloudflare-pages is deprecated without a replacement package; Cloudflare recommends Workers with static assets.

What's Changed

... (truncated)

Commits
  • 6abd35b 4.13.12
  • 95eb860 chore(deps): upgrade vite-plus to 1.0.0 (#5464)
  • afb2068 fix(combine): return a Response from a short-circuiting middleware in some() ...
  • e5bb206 fix(jsx): add px to numeric gridGap, gridRowGap and gridColumnGap (#5487)
  • c3053cc fix(etag): correctly match mixed-case header name in retainedHeader option (#...
  • c437d75 test(build): type-check the bundled declarations from a consumer project (#5486)
  • be1f749 fix(build): keep internal types private in bundled d.ts and avoid a self-refe...
  • 37ce069 4.13.11
  • 1e1207c test(serve-static): fix the test (#5479)
  • 8b05c77 Merge commit from fork
  • Additional commits viewable in compare view

Updates pg from 8.23.0 to 8.23.1

Changelog

Sourced from pg's changelog.

All major and minor releases are briefly explained below.

For richer information consult the commit log on github with referenced pull requests.

We do not include break-fix version release in this file.

Commits
  • 0980cef Publish
  • 2759b2c fix(pg): run a named statement with an empty text more than once (#3781)
  • 7feb7df fix(pg): expose detail and hint on errors from the native client (#3780)
  • 9683053 fix(pg): do not treat Sync as connection ending (#3772)
  • 4589038 fix: validate server certificate against host when connecting to an IP addres...
  • 9808955 cleanup: Fix typo in comment
  • 2b02f64 fix: avoid mutating query config (#3720)
  • 0cef6af Reject portal based queries in pipeline mode instead of misrouting rows (#3737)
  • 2991480 Deprecate serializing invalid Dates (#3731)
  • c940d7c Fail pipelined queries when the connection dies instead of hanging (#3736)
  • Additional commits viewable in compare view

Updates globals from 17.12.0 to 17.13.0

Release notes

Sourced from globals's releases.

v17.13.0

  • Update globals (2026-10-01) (#354) b007369

sindresorhus/globals@v17.12.0...v17.13.0

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 8, 2026
@till

till commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

@dependabot rebase

Bumps the npm-deps group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@better-auth/oauth-provider](https://github.com/better-auth/better-auth/tree/HEAD/packages/oauth-provider) | `1.7.6` | `1.7.7` |
| [@hono/node-server](https://github.com/honojs/node-server) | `2.1.1` | `2.1.3` |
| [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) | `1.7.6` | `1.7.7` |
| [hono](https://github.com/honojs/hono) | `4.13.9` | `4.13.12` |
| [pg](https://github.com/brianc/node-postgres/tree/HEAD/packages/pg) | `8.23.0` | `8.23.1` |
| [globals](https://github.com/sindresorhus/globals) | `17.12.0` | `17.13.0` |



Updates `@better-auth/oauth-provider` from 1.7.6 to 1.7.7
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/oauth-provider/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.7/packages/oauth-provider)

Updates `@hono/node-server` from 2.1.1 to 2.1.3
- [Release notes](https://github.com/honojs/node-server/releases)
- [Commits](honojs/node-server@v2.1.1...v2.1.3)

Updates `better-auth` from 1.7.6 to 1.7.7
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.7/packages/better-auth)

Updates `hono` from 4.13.9 to 4.13.12
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.9...v4.13.12)

Updates `pg` from 8.23.0 to 8.23.1
- [Changelog](https://github.com/brianc/node-postgres/blob/master/CHANGELOG.md)
- [Commits](https://github.com/brianc/node-postgres/commits/pg@8.23.1/packages/pg)

Updates `globals` from 17.12.0 to 17.13.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.12.0...v17.13.0)

---
updated-dependencies:
- dependency-name: "@better-auth/oauth-provider"
  dependency-version: 1.7.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-deps
- dependency-name: "@hono/node-server"
  dependency-version: 2.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-deps
- dependency-name: better-auth
  dependency-version: 1.7.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-deps
- dependency-name: globals
  dependency-version: 17.13.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-deps
- dependency-name: hono
  dependency-version: 4.13.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-deps
- dependency-name: pg
  dependency-version: 8.23.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump the npm-deps group with 6 updates chore(deps): bump the npm-deps group across 1 directory with 6 updates Oct 8, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-deps-44ebebc0c4 branch from 522c237 to 00a5e0a Compare October 8, 2026 15:19

@mroderick mroderick left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: merge recommended — security-driven

This PR is the fix for critical advisory GHSA-965c-763c-88jm (CVSS 9.1, magic-link account takeover), and it applies to this deployment:

  • Magic Link enabled (src/auth.js) with the default plain storeToken. ✔ affected condition
  • GitHub social provider enabled. ✔ affected condition
  • Database-backed OAuth state (pg Pool, account.skipStateCookieCheck: true, state validated against the verification table). ✔ affected condition

All three affected conditions hold, and production (auth.codebar.io, per docs/architecture.md) has no staging app. The fix (magic-link: / auth-state: purpose-prefix isolation plus a strict verification-record schema) was verified in the shipped 1.7.7 dist and the upstream patch — not the changelog prose.

The lockfile moves all @better-auth/* packages to 1.7.7 together, satisfying the advisory's "upgrade all participants" requirement; this app uses neither OAuth Proxy nor SAML, so the remaining upgrade clauses do not apply.

Confidence: High — validated locally (fresh worktree at the PR head, npm ci, full tap suite: 205/205 passing) plus green CI on the head (test/e2e/smoke). All runtime/cross-service contract rows verified at the line-trace or receiving-test level.

Cutover notes

Pre-upgrade magic links and pending GitHub sign-in states fail once after deploy with a friendly INVALID_TOKEN — restart them. No migrations, no config changes. Single-node Heroku app; brief old/new-dyno overlap may produce transient INVALID_TOKEN noise.

Per-dependency

Package From → To Verdict Basis
better-auth 1.7.6 → 1.7.7 Compatible (required) Advisory fix verified in shipped dist; magic-link/state identifier changes line-traced; no customizations the advisory flags
@better-auth/oauth-provider 1.7.6 → 1.7.7 Compatible Additive validateRedirectUri (opt-in, off here) + verifyOAuthQueryParams export; default redirect-URI validation unchanged (authorize.ts patch)
@hono/node-server 2.1.1 → 2.1.3 Compatible serveStatic % security fix is a no-op here — the app's 6 static assets contain no %
hono 4.13.9 → 4.13.12 Compatible All changed surfaces unused (hono/html-only); JWT/template parsing untouched
pg 8.23.0 → 8.23.1 Compatible Bug fixes in unused edge paths; cert-validation fix moot (ssl rejectUnauthorized: false, never IP-connected)
globals 17.12.0 → 17.13.0 Compatible Dev-only, data-only

Contracts

Planner-side consumption verified from both sides: lib/omniauth/strategies/codebar.rb and AuthServicesController#member_from_github_id consume github_id from raw_info, email/name from userinfo (blank email fails the callback), JWT iss/aud against JWKS — none of the emission paths appear in this diff; the id_token/userinfo round-trips are asserted by test/integration/oauth-flow.test.js and jwt-payload.test.js in the passing suite.

Follow-up (not this PR)

static/auth-client.js currently loads the browser client from esm.sh/better-auth@latest — a version-drift hazard independent of dependency PRs. Draft PR #92 pins it to the server's version; merging #89 first means rebasing #92 with pin 1.7.7.

@mroderick
mroderick merged commit 6acfa64 into main Oct 10, 2026
7 checks passed
@mroderick
mroderick deleted the dependabot/npm_and_yarn/npm-deps-44ebebc0c4 branch October 10, 2026 08:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants