Skip to content

[pull] main from aws-amplify:main - #680

Merged
pull[bot] merged 5 commits into
MLH-Fellowship:mainfrom
aws-amplify:main
Jul 28, 2026
Merged

[pull] main from aws-amplify:main#680
pull[bot] merged 5 commits into
MLH-Fellowship:mainfrom
aws-amplify:main

Conversation

@pull

@pull pull Bot commented Jul 28, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

dependabot Bot and others added 5 commits July 28, 2026 11:49
Bumps [next](https://github.com/vercel/next.js) from 16.2.6 to 16.2.11.
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.2.6...v16.2.11)

---
updated-dependencies:
- dependency-name: next
  dependency-version: 16.2.11
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [linkify-it](https://github.com/markdown-it/linkify-it) from 5.0.1 to 5.0.2.
- [Changelog](https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md)
- [Commits](markdown-it/linkify-it@5.0.1...5.0.2)

---
updated-dependencies:
- dependency-name: linkify-it
  dependency-version: 5.0.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…#14876)

* ci: add retries to e2e install/setup steps to reduce canary flakiness

* ci: warn when staging branch checkout retries are exhausted
* docs: add AGENTS.md and CLAUDE.md for AI agent guidance

* docs: add v5-stable maintenance branch section to AGENTS.md

* docs: fix factual errors in AGENTS.md (Turbo --filter, Node 24, size-limit, pre-commit)

* docs: slim v5-stable section to a pointer — full conventions live on that branch

---------

Co-authored-by: Michael Sober <msober@amazon.com>
) (#14893)

* fix(security): force sharp >=0.35.0 via yarn resolution — resolves https://github.com/aws-amplify/amplify-js/security/dependabot/276

* fix(ci): update dependency-review allowlist for sharp 0.35.x

Bump @img/sharp-libvips-* from 1.2.4 to 1.3.2 and pin
@img/sharp-wasm32 and @img/sharp-win32-* to 0.35.3 to reflect their
new compound LGPL licenses. These are dynamic libraries that do not
ship to customers — used only for next.js image optimization as dev
dependencies.

* fix(ci): use correct purl encoding and drop version pins in allowlist

Switch from %2540 (double-encoded) to %40 (standard purl encoding)
for the @ sign in scoped npm package names, and remove version pins
so the allowlist matches regardless of resolved version. The
dependency-review-action v4.x uses standard purl format.

---------

Co-authored-by: Michael Sober <msober@amazon.com>
@pull pull Bot locked and limited conversation to collaborators Jul 28, 2026
@pull pull Bot added the ⤵️ pull label Jul 28, 2026
@pull
pull Bot merged commit 07f422b into MLH-Fellowship:main Jul 28, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant