Skip to content

chore(deps): bump the upstash group across 1 directory with 2 updates - #233

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/upstash-b2458ce36d
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/upstash-b2458ce36d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the upstash group with 2 updates in the / directory: @upstash/ratelimit and @upstash/redis.

Updates @upstash/ratelimit from 2.0.8 to 2.2.0

Release notes

Sourced from @​upstash/ratelimit's releases.

v2.2.0

What's Changed

New Contributors

Full Changelog: upstash/ratelimit-js@v2.1.0...v2.2.0

v2.1.0

What's Changed

New Contributors

Full Changelog: upstash/ratelimit-js@v2.0.8...v2.1.0

v2.1.0-rc

What's Changed

Full Changelog: upstash/ratelimit-js@v2.0.8...v2.1.0-rc

Commits
  • fccd840 feat: support decimal values and week unit in duration parser (#158)
  • a955a3c Reject token-bucket requests that exceed the remaining tokens (#156)
  • 8f641c6 fix: avoid negative setTimeout delay in blockUntilReady (#159)
  • 75a956e fix: use last token successfully on cachedFixedWindow cache hits (#157)
  • 7e071b9 feat: run lua scripts with allow-key-locking flag (#154)
  • 89c481b DX-2954: poll npm for the ci version instead of a fixed sleep (#155)
  • 91c0bad chore: add npm bugs and homepage metadata, fix repository URL (#152)
  • f2fc2c7 DX-2861: add sdk telemetry (#153)
  • 5b5448a DX-2479: fix package.version
  • 589cc3e Rename skill from 'ratelimit-ts' to 'upstash-ratelimit-ts'
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​upstash/ratelimit since your current version.


Updates @upstash/redis from 1.38.0 to 1.39.0

Release notes

Sourced from @​upstash/redis's releases.

@​upstash/redis@​1.39.0

Minor Changes

  • 6801501: Add array commands: arset, armset, arget, armget, argetrange, arscan, argrep, ardel, ardelrange, arcount, arlen, arinsert, arring, arlastitems, arnext, arseek, arop and arinfo, available on the client, in pipelines and in transactions.
  • 3f6e286: Support search indexes over Redis streams: redis.search.createIndex({ dataType: "stream", stream: "events", schema }) indexes every entry of the stream as a document keyed by its entry ID. describe() reports dataType: "stream" with the stream key in prefixes.
  • 33658bc: Add vector index support: redis.vector.createIndex() / redis.vector.index() return a VectorIndex with add, get, query, delete, count, info and drop, backed by the new VECTOR.CREATE, VECTOR.ADD, VECTOR.GET, VECTOR.QUERY, VECTOR.DEL, VECTOR.COUNT, VECTOR.INFO and VECTOR.DROP commands.

@​upstash/redis@​1.39.0-canary-20260826110341-795a33599494ef4034259bd4f7d36db70c44f368

Full Changelog: https://github.com/upstash/redis-js/compare/@​upstash/redis@1.38.3...@​upstash/redis@1.39.0-canary-20260826110341-795a33599494ef4034259bd4f7d36db70c44f368

@​upstash/redis@​1.38.4

Patch Changes

  • 7ac8182: Fix read-your-writes sending a stale upstash-sync-token

    A read issued straight after a write travelled with the token from before that write, so the server was under no obligation to serve the write and readYourWrites silently did not hold.

    HttpClient.request() snapshotted the outgoing headers with mergeHeaders(this.headers, ...) and only afterwards wrote the freshest token into this.headers, so the token learned from response N first shipped with request N+2. The assignment now happens before the merge.

    This regressed in 1.34.5. In 1.34.0–1.34.4 the request options held headers: this.headers by reference, so the late write was still picked up before fetch; 1.34.5 introduced per-request header merging, which turned that reference into a copy without moving the assignment.

@​upstash/redis@​1.38.3

Patch Changes

  • f020866: Send an Upstash-Telemetry-Retry header with the retry count on retried requests so retry rates are visible in server-side telemetry
  • 777dc30: Trim telemetry header values before deduplicating so whitespace around existing values does not defeat the dedup check

@​upstash/redis@​1.38.3-canary-20260807072941-777dc30585ae61e5826bb95f5a957e6dea277900

What's Changed

Full Changelog: https://github.com/upstash/redis-js/compare/@​upstash/redis@1.38.2...@​upstash/redis@1.38.3-canary-20260807072941-777dc30585ae61e5826bb95f5a957e6dea277900

@​upstash/redis@​1.38.2

Patch Changes

  • c0f5ad7: Deduplicate telemetry header values so repeated mergeTelemetry calls no longer append the same sdk, platform or runtime tag multiple times

@​upstash/redis@​1.38.1

Patch Changes

... (truncated)

Commits
  • 6b27727 chore: version packages (#1456)
  • 33658bc DX-2963: add vector index commands and redis.vector namespace (#1446)
  • 6801501 DX-3009: add array commands (#1451)
  • 3f6e286 DX-3010: support search indexes over redis streams (#1452)
  • 73fbe1a chore: version packages (#1448)
  • 7ac8182 DX-2995: fix read-your-writes sending a stale upstash-sync-token (#1447)
  • 1bec566 ci: poll npm for the ci version instead of a fixed sleep (#1444)
  • 74da1df chore: version packages (#1443)
  • f020866 DX-2960: send Upstash-Telemetry-Retry header with the attempt number (DX-2960...
  • 777dc30 fix: trim telemetry values before dedup and cover distinct-version case (#1442)
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
unicon Ignored Ignored Preview Oct 3, 2026 6:48pm UTC

Request Review

@github-actions
github-actions Bot enabled auto-merge (squash) October 1, 2026 16:14
@dependabot dependabot Bot changed the title chore(deps): bump the upstash group with 2 updates chore(deps): bump the upstash group across 1 directory with 2 updates Oct 3, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/upstash-b2458ce36d branch from 7495896 to bc62246 Compare October 3, 2026 18:30
Bumps the upstash group with 2 updates in the / directory: [@upstash/ratelimit](https://github.com/upstash/ratelimit-js) and [@upstash/redis](https://github.com/upstash/redis-js).


Updates `@upstash/ratelimit` from 2.0.8 to 2.2.0
- [Release notes](https://github.com/upstash/ratelimit-js/releases)
- [Commits](upstash/ratelimit-js@v2.0.8...v2.2.0)

Updates `@upstash/redis` from 1.38.0 to 1.39.0
- [Release notes](https://github.com/upstash/redis-js/releases)
- [Commits](https://github.com/upstash/redis-js/compare/@upstash/redis@1.38.0...@upstash/redis@1.39.0)

---
updated-dependencies:
- dependency-name: "@upstash/ratelimit"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: upstash
- dependency-name: "@upstash/redis"
  dependency-version: 1.39.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: upstash
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/upstash-b2458ce36d branch from bc62246 to 8fed36e Compare October 3, 2026 18:48

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants