Skip to content

chore(deps): bump the npm group with 2 updates - #10

Merged
arsenstorm merged 2 commits into
mainfrom
dependabot/bun/npm-cb2d8595bc
Aug 21, 2026
Merged

arsenstorm merged 2 commits into
mainfrom
dependabot/bun/npm-cb2d8595bc

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 21, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm group with 2 updates: better-auth and @biomejs/biome.

Updates better-auth from 1.6.30 to 1.7.0

Release notes

Sourced from better-auth's releases.

v1.7.0

Blog post: Better Auth 1.7

better-auth

❗ Breaking Changes

  • Moved database joins out of experimental into the stable advanced.database.joins option (#10359)

    Migration: Replace experimental: { joins: true } with advanced: { database: { joins: true } }. Drizzle and Prisma users should regenerate their schema (npx auth@latest generate) so it includes the required relations.

  • Scoped account identity by trusted issuer, keying accounts on (issuer, accountId) (#10403)

    Migration: Accounts now require Account.issuer. Read provider identity from accountInfo.account.accountId, drop mapping.id from SSO configs, and give the microsoftEntraId helper a concrete tenant GUID. Apply the account-identity backfill in the 1.7 upgrade guide before deploying.

  • Required captcha endpoint entries to match full auth paths, with wildcard support (#10004)

    Migration: Replace partial paths such as /sign-in with explicit wildcards like /sign-in/* or /sign-in/**.

  • Moved the MCP plugin into its own @better-auth/mcp package built on the OAuth provider (#9992)

    Migration: Install @better-auth/mcp and @better-auth/cimd, add the now-required jwt() plugin, and move options nested under oidcConfig to flat mcp({ ... }) options. Rename withMcpAuth to requireMcpAuth and mcpHandler to createMcpProtectedRequestHandler. Regenerate the schema (npx auth migrate): oauthApplication becomes oauthClient, plus new oauthRefreshToken and oauthClientAssertion tables.

  • Added OIDC back-channel logout so ending a session cuts off every connected app's API access (#9304)

    Migration: Introspecting an access token whose session has ended now returns { active: false }, and /oauth2/userinfo rejects it. Clients opt into notifications by registering backchannel_logout_uri. Run the schema migration for the new oauthClient and oauthAccessToken columns.

  • Modeled OAuth protected resources explicitly, with per-resource TTLs, scopes, claims, and signing pins (#9648)

    Migration: validAudiences is removed: move each resource identifier into resources and link restricted clients through oauthClientResource. @better-auth/mcp now requires an explicit resource. Run npx @better-auth/cli generate and apply the migration before deploying.

  • Decoupled SCIM provisioning from the organization plugin (#10390)

    Migration: SCIM configuration, client APIs, database schema, and the Group model are all replaced, and provisioning state cannot migrate in place. Follow the SCIM cutover in the 1.7 upgrade guide, including a full directory reprovision, before resuming traffic.

  • Added OTP-only two-factor enablement with a discriminated enableTwoFactor response (#9057)

    Migration: enableTwoFactor now returns a method field ("otp" or "totp"); narrow on it before reading totpURI and backupCodes. Pass method: "otp" for OTP enrollment, which requires otpOptions.sendOTP.

  • Resolved the auth origin from Host by default when using a dynamic baseURL (#9134)

    Migration: If your proxy exposes the public hostname only through x-forwarded-host, set advanced.trustedProxyHeaders: true. Deployments where the proxy rewrites Host (nginx default, Vercel, Cloudflare, Netlify) are unaffected.

  • Added unique lookup indexes for the device authorization deviceCode and userCode columns (#10059)

    Migration: Resolve duplicate code values before applying the migration. MySQL and SQL Server installations must also convert both columns to bounded strings and clean up values longer than 191 characters.

  • Enforced S256 PKCE in the Electron sign-in flow and hardened custom-scheme origin checks (#9645)

    Migration: Upgrade the @better-auth/electron client and server together and add your app's scheme to trustedOrigins. The code_challenge_method parameter and disableOriginOverride option are removed, and host-bearing custom-scheme entries now match that host exactly.

  • Identified Microsoft Entra accounts by the stable oid claim (#10204)

    Migration: Migrate existing Microsoft account rows created from sub before upgrading. Tokens without a valid oid are rejected.

  • Required a Google client ID before Google One Tap verifies ID tokens (#10036)

    Migration: Configure oneTap({ clientId }) or socialProviders.google.clientId.

  • Removed the deprecated oidcProvider plugin (#10031)

    Migration: Move OIDC authorization-server integrations to @better-auth/oauth-provider.

  • Rewrote the generic OAuth plugin as a first-class social provider with OAuth 2.1 defaults (#9069)

    Migration: Replace signIn.oauth2({ providerId }) with signIn.social({ provider }), oauth2.link() with linkSocial(), and drop genericOAuthClient(). Callbacks move to /api/auth/callback/:id, pkce now defaults to true, and issuer and requireIssuerValidation are removed in favor of OIDC discovery.

  • Separated OAuth device grant ownership into oauthDeviceAuthorization() (#10746)

    Migration: The OAuth integration replaces the optional resource column with oauthClientId and resources, so regenerate and apply the schema. Let pending device codes expire before upgrading from an earlier 1.7 prerelease.

  • Verified provider id_tokens with a single shared verifier (#9828)

    Migration: Custom UpstreamProvider implementations replace the removed verifyIdToken method with an idToken config carrying a JWKS source, issuer, and audience. PayPal client id_token sign-in now returns ID_TOKEN_NOT_SUPPORTED; its redirect flow is unchanged.

Features

  • Added clientAssertion support to the Microsoft Entra ID social provider (#9898)
  • Made the Auth instance directly fetchable (#9431)
  • Added per-provider requireEmailVerification for social sign-in (#9929)
  • Added a user.validateUserInfo gate for rejecting an identity before a user is created or linked (#9864)
  • Added hydrateSession so useSession returns server-fetched data on the first render (#8733)
  • Added compound table indexes to plugin database schemas (#10402)

... (truncated)

Changelog

Sourced from better-auth's changelog.

1.7.0

Minor Changes

  • #8733 4e8e4c7 Thanks @​bytaesu! - Add hydrateSession to seed the client with a server-fetched session so useSession returns data on the first render.

  • #9930 0cbaf81 Thanks @​gustavovalverde! - Anonymous account linking now works after social and generic OAuth sign-in in Expo and other in-app browsers, where the OAuth callback returns without the session cookie. onLinkAccount fires and the anonymous user is migrated; before, it was silently skipped.

    Plugins can now carry server-trusted data across an OAuth redirect with the new addOAuthServerContext API, read back on the callback via getOAuthState().serverContext. Unlike additionalData, it cannot be set from the request body, so it is the right place for values the server must trust.

    For @better-auth/oauth-provider, the post-login authorization query now travels through that server-only channel, so it can no longer be injected through additionalData.

  • #10004 b36c38f Thanks @​bytaesu! - The captcha plugin now requires endpoint entries to match full auth paths unless they use wildcard patterns. This prevents requests like /sign-in//email from bypassing captcha while preserving trailing-slash matches like /sign-in/email/. To protect multiple routes, replace partial paths like /sign-in with explicit wildcards such as /sign-in/* or /sign-in/**.

  • #10746 6782647 Thanks @​gustavovalverde! - OAuth device grants now use oauthDeviceAuthorization() alongside oauthProvider() or mcp(). This single integration replaces both the standalone deviceCodeGrant() plugin and the shared-grant configuration. Standalone Device Authorization no longer accepts or stores RFC 8707 resources, and onDeviceAuthRequest receives only clientId and scope. The OAuth integration rejects resource indicators that are not absolute, fragment-free URIs.

    The OAuth integration replaces the optional resource column with oauthClientId and resources. Regenerate and apply the schema when using it. Before upgrading from an earlier 1.7 prerelease, let pending OAuth device codes expire or delete them because they cannot be exchanged through the new integration.

  • #10402 763a267 Thanks @​gustavovalverde! - Plugin database schemas can now define named or generated table-level indexes across multiple fields. SQL migrations and generated Drizzle or Prisma schemas resolve configured table and column names consistently, while the MongoDB adapter creates the same indexes before the first index-enforcing write.

  • #9766 bf39cbf Thanks @​GautamBytes! - Add a server-only auth.api.consumePhoneNumberOTP API for custom phone OTP flows that need to verify and consume a code without creating or updating users or sessions.

  • #10330 081d3c3 Thanks @​ping-maxwell! - Allow the username plugin's separate displayUsername field to be omitted by setting displayUsername: false on both the server and client plugins.

  • #10059 49b5cf6 Thanks @​GautamBytes! - Device Authorization now creates unique database indexes for deviceCode and userCode, so each generated code must be unique in its column. Existing installations on every adapter must resolve duplicate values before applying the migration. MySQL and SQL Server installations must also convert both columns to bounded strings and clean up values longer than 191 characters before running it.

    Generated codes are limited to 191 characters. Issuance makes up to 3 attempts to overcome unique-key collisions, then returns server_error if it cannot create a unique deviceCode and userCode. Default-generated user codes accept case changes and readability separators during verification, approval, and denial; custom codes outside the default alphabet are matched exactly. The /device limiter allows 5 requests over a window equal to the configured code lifetime, while /device/token polling keeps its separate interval behavior.

  • #9645 e014029 Thanks @​ping-maxwell! - Harden the Electron OAuth flow and tighten custom-scheme trusted-origin matching.

    The Electron sign-in flow now mandates PKCE S256. Plain PKCE is rejected: the code_challenge_method parameter is gone and every authorization code is verified by hashing the verifier with SHA-256. The server no longer trusts an electron-origin header to set the request Origin. The Electron client now sends a real Origin (for example myapp:/), so upgrade the @better-auth/electron client and server together and make sure your app's scheme is in trustedOrigins. The unused disableOriginOverride option is removed.

    Custom-scheme entries in trustedOrigins now match by scheme and authority instead of string prefix. A host-less entry such as myapp:// or exp:// still trusts every host of that scheme, but a host-bearing entry such as myapp://callback matches that host exactly, so it is no longer satisfied by myapp://callback.attacker.tld.

  • #9948 3d04fab Thanks @​yordis! - feat(generic-oauth): add refreshTokenParams config to forward extra params on token refresh

    Multi-tenant OIDC providers (Zitadel multi-org, Auth0 with audience) need to send extra body params on the refresh call to rescope tokens without a full authorization redirect. The generic-oauth plugin now accepts a refreshTokenParams option (object or sync/async function) that is merged into the refresh request body, with grant_type and refresh_token protected from override. The function form receives request metadata for the request that triggered the refresh, so request-scoped data (headers, cookies) is available without out-of-band state like AsyncLocalStorage.

    UpstreamProvider.refreshAccessToken now accepts an optional second ctx argument; the change is backwards compatible because existing implementations that take only refreshToken remain valid. See #7554.

  • #9069 c7d2253 Thanks @​gustavovalverde! - Rewrite the generic OAuth plugin as a first-class social provider with OAuth 2.1 security defaults. Providers now use signIn.social + callback/:id instead of dedicated plugin endpoints, with PKCE required by default (OAuth 2.1), RFC 9207 issuer validation, OIDC auto-discovery with openid scope injection, and typed provider IDs.

    Breaking changes:

    • signIn.oauth2({ providerId }) replaced by signIn.social({ provider })
    • oauth2.link() replaced by linkSocial()
    • Callback URL changed from /api/auth/oauth2/callback/:id to /api/auth/callback/:id
    • genericOAuthClient() removed; generic OAuth providers now use the standard social client APIs
    • pkce defaults to true (was false); set pkce: false for providers that reject PKCE
    • authorizationUrlParams and tokenUrlParams only accept Record<string, string>

... (truncated)

Commits
  • ccd57c2 docs(changelog): align v1.7 release notes with final behavior (#10846)
  • f577ec5 chore: exit pre-release mode for v1.7.0
  • 69258d1 chore: sync main to next
  • bc93b27 chore: release v1.7.0-rc.6 (#10772)
  • 80799e6 chore: sync main to next
  • 3e485bf docs(username): fix displayUsername release notes (#10776)
  • 65fc17c fix(deps): align drizzle-orm peer range with drizzle-adapter (#10501)
  • acbe421 chore: release v1.7.0-rc.5 (#10704)
  • 3ca2c08 fix(device-authorization): enforce RFC device flow requirements (#10752)
  • 6782647 refactor(oauth-provider)!: separate device grant ownership (#10746)
  • Additional commits viewable in compare view

Updates @biomejs/biome from 2.5.8 to 2.5.9

Release notes

Sourced from @​biomejs/biome's releases.

Biome CLI v2.5.9

2.5.9

Patch Changes

  • #11321 41386f3 Thanks @​dyc3! - Fixed #11315: The CSS parser now recovers at declaration boundaries after bogus declarations, allowing subsequent valid declarations to be parsed.

  • #11248 57b197e Thanks @​yanthomasdev! - Expanded the environment variable metadata used by biome rage to include BIOME_BINARY, BIOME_LOG_FILE, and RUST_BACKTRACE as well as reworded explanations for better readability.

  • #11377 a8798ea Thanks @​Netail! - Added a new nursery rule useNamedLayer which disallows anonymous cascade layers.

    @layer {
      a {
        color: red;
      }
    }
  • #11327 6771cf5 Thanks @​dyc3! - The HTML formatter now preserves meaningful blank lines in HTML, including spacing after elements with trailing spaces and blank lines between comment groups.

     <div>
       <!-- first group -->
    +
       <!-- second group -->
     </div>
  • #10312 ba8aa18 Thanks @​dyc3! - Added the nursery rule useTailwindShorthandClasses, which suggests shorter Tailwind utility classes. For example, the rule suggests replacing w-4 h-4 with size-4.

  • #11333 715e0cd Thanks @​kkkhs! - Fixed #11328: lint/nursery/useExpect now recognizes Vitest Browser Mode expect.element() calls as assertions.

  • #11343 9b98211 Thanks @​johncarmack1984! - Fixed #11311: the CSS parser now accepts Tailwind container-query variant names in @variant, such as @xl and @max-xl. These previously produced a parse error and a noUnknownAtRules diagnostic.

    @variant @xl {
      div {
        background: red;
      }
    }
  • #11220 3e8c488 Thanks @​santichausis! - Fixed #9541: noUndeclaredVariables, noUnusedImports, and noUnusedVariables now correctly recognise exported variables and functions declared in one embedded <script> block as usable from a sibling <script> block, in Svelte's <script module>/<script> pair and Vue's non-setup <script> blocks.

    For example, Biome no longer reports greet as undeclared in the following Svelte component:

    <script module>

... (truncated)

Changelog

Sourced from @​biomejs/biome's changelog.

2.5.9

Patch Changes

  • #11321 41386f3 Thanks @​dyc3! - Fixed #11315: The CSS parser now recovers at declaration boundaries after bogus declarations, allowing subsequent valid declarations to be parsed.

  • #11248 57b197e Thanks @​yanthomasdev! - Expanded the environment variable metadata used by biome rage to include BIOME_BINARY, BIOME_LOG_FILE, and RUST_BACKTRACE as well as reworded explanations for better readability.

  • #11377 a8798ea Thanks @​Netail! - Added a new nursery rule useNamedLayer which disallows anonymous cascade layers.

    @layer {
      a {
        color: red;
      }
    }
  • #11327 6771cf5 Thanks @​dyc3! - The HTML formatter now preserves meaningful blank lines in HTML, including spacing after elements with trailing spaces and blank lines between comment groups.

     <div>
       <!-- first group -->
    +
       <!-- second group -->
     </div>
  • #10312 ba8aa18 Thanks @​dyc3! - Added the nursery rule useTailwindShorthandClasses, which suggests shorter Tailwind utility classes. For example, the rule suggests replacing w-4 h-4 with size-4.

  • #11333 715e0cd Thanks @​kkkhs! - Fixed #11328: lint/nursery/useExpect now recognizes Vitest Browser Mode expect.element() calls as assertions.

  • #11343 9b98211 Thanks @​johncarmack1984! - Fixed #11311: the CSS parser now accepts Tailwind container-query variant names in @variant, such as @xl and @max-xl. These previously produced a parse error and a noUnknownAtRules diagnostic.

    @variant @xl {
      div {
        background: red;
      }
    }
  • #11220 3e8c488 Thanks @​santichausis! - Fixed #9541: noUndeclaredVariables, noUnusedImports, and noUnusedVariables now correctly recognise exported variables and functions declared in one embedded <script> block as usable from a sibling <script> block, in Svelte's <script module>/<script> pair and Vue's non-setup <script> blocks.

    For example, Biome no longer reports greet as undeclared in the following Svelte component:

    <script module>
      export function greet() {
        console.log("Hello!");

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the npm group with 2 updates: [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) and [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome).


Updates `better-auth` from 1.6.30 to 1.7.0
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.0/packages/better-auth)

Updates `@biomejs/biome` from 2.5.8 to 2.5.9
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.9/packages/@biomejs/biome)

---
updated-dependencies:
- dependency-name: better-auth
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 21, 2026
@dependabot
dependabot Bot requested a review from arsenstorm as a code owner August 21, 2026 08:46
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 21, 2026
@socket-security

socket-security Bot commented Aug 21, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedbetter-auth@​1.6.30 ⏵ 1.7.0981008596 +1100
Updated@​biomejs/​biome@​2.5.8 ⏵ 2.5.9100100100 +199100

View full report

@arsenstorm
arsenstorm merged commit 8c85443 into main Aug 21, 2026
9 checks passed
@arsenstorm
arsenstorm deleted the dependabot/bun/npm-cb2d8595bc branch August 21, 2026 20:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant