chore(deps): update all non-major dependencies#6753
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub. |
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
2526c31 to
d445c97
Compare
commit: |
d445c97 to
09e6253
Compare
09e6253 to
81c59d0
Compare
81c59d0 to
d79aede
Compare
d79aede to
70afa7a
Compare
70afa7a to
c5cbcd4
Compare
c5cbcd4 to
59177ee
Compare
59177ee to
5e70989
Compare
5e70989 to
35b9325
Compare
35b9325 to
314c701
Compare
314c701 to
f443d9b
Compare
f443d9b to
a71f3b6
Compare
a71f3b6 to
8e3e66a
Compare
8e3e66a to
97127eb
Compare
This PR contains the following updates:
^4.0.14→^4.0.20^4.0.19→^4.0.28^2.0.12→^2.0.16^4.0.26→^4.0.37^0.5.0→^0.5.1^1.2.117→^1.2.119^1.2.90→^1.2.91^3.15.0→^3.15.2^1.0.2→^1.0.3^0.22.1→^0.22.2^1.28.3→^1.28.4^1.28.3→^1.28.4^4.3.2→^4.3.3^4.3.2→^4.3.3^3.13.32→^3.13.34^2.1.15→^2.1.16^6.0.7→^6.0.8^7.0.26→^7.0.37^10.7.0→^10.8.0^20.10.6→^20.11.1^6.7.2→^6.7.4^6.2.3→^6.2.711.13.0→11.17.0^3.9.5→^3.9.6^4.3.2→^4.3.3^3.5.39→^3.5.40^3.3.7→^3.3.8^3.3.7→^3.3.8^5.1.0→^5.2.0^3.3.7→^3.3.8Release Notes
vercel/ai (@ai-sdk/anthropic)
v4.0.20Compare Source
Patch Changes
cbdc990: feat (provider/anthropic): support fallbacks 'default' mode, which routes safety classifier refusals to Anthropic's recommended fallback model (adds the server-side-fallback-2026-07-01 beta automatically)cbdc990: feat (provider/anthropic): support mid-conversation tool changes via the toolChanges system message provider option, emitting tool_addition/tool_removal content blocks and the mid-conversation-tool-changes-2026-07-01 betacbdc990: feat (provider/anthropic): add claude-opus-5 model id with frontier-tier capabilities (128k output tokens, structured output, adaptive thinking, xhigh effort, sampling parameter rejection, thinking-disabled only at effort high or below)v4.0.19Compare Source
Patch Changes
01a596a: fix (provider/anthropic): use current-generation capability defaults for unrecognized Claude model IDs while retaining conservative defaults for legacy Claude and non-Claude models.v4.0.18Compare Source
Patch Changes
97de198: Warn when an unknown model uses the default 4096 max output token limit.v4.0.17Compare Source
Patch Changes
b72fc7c: fix(amazon-bedrock): sanitize unsupported JSON Schema constraints in native Anthropic structured output9218ebe: fix(provider/anthropic): warn when parallel tool use is requested with JSON tool structured output02ffdcb]76cb673]v4.0.16Compare Source
Patch Changes
afcf19c: fix(provider/anthropic): preserve web search citations when replaying assistant messagescd06458]v4.0.15Compare Source
Patch Changes
31c7be8]vercel/ai (@ai-sdk/gateway)
v4.0.28Compare Source
Patch Changes
0a7c7f4: chore(provider/gateway): update gateway model settings filesv4.0.27Compare Source
Patch Changes
2112ff1: chore(provider/gateway): update gateway model settings filesv4.0.26Compare Source
Patch Changes
7c16f21: feat(google): addgemini-3.6-flashandgemini-3.5-flash-litemodelsv4.0.25Compare Source
Patch Changes
02ffdcb]76cb673]v4.0.24Compare Source
Patch Changes
cefa3b1: chore(provider/gateway): removehipaaCompliantprovider option8fbb89c: chore(provider/gateway): update gateway model settings filesv4.0.23Compare Source
Patch Changes
cd06458]v4.0.22Compare Source
Patch Changes
341616a: feat: add kimi-k3 model andreasoningEffortprovider option70fc45c: chore(provider/gateway): update gateway model settings filesv4.0.21Compare Source
Patch Changes
7069785: chore(provider/gateway): update gateway model settings files4bf9ac2: feat (provider/gateway): addgateway.experimental_transcription.getTokenfor minting transcription-bound client secretsv4.0.20Compare Source
Patch Changes
4d096f6: chore(provider/gateway): update gateway model settings files31c7be8]vercel/ai (@ai-sdk/mcp)
v2.0.16Compare Source
Patch Changes
02ffdcb]76cb673]v2.0.15Compare Source
Patch Changes
d84ea43: fix(mcp): accept OAuth metadata without code challenge methodscd06458]v2.0.14Compare Source
Patch Changes
48e7e78: Harden MCP Apps handling of server-supplied resource metadata and the host/iframe bridge:_meta.uiand drop malformed or non-string fields.sandbox.allowedPermissionsallowlist.postMessagetarget origin and validate inbound message origins.resources/readtoui://resources and allow onlyhttps/http/mailtoinui/open-link.fingerprintMCPAppResource/detectMCPAppResourceDriftfor pinning and comparing app resources.v2.0.13Compare Source
Patch Changes
31c7be8]vercel/ai (@ai-sdk/vue)
v4.0.37Compare Source
Patch Changes
v4.0.36Compare Source
Patch Changes
7fa85b2]v4.0.35Compare Source
Patch Changes
7f6650b]106ea59]v4.0.34Compare Source
Patch Changes
v4.0.33Compare Source
Patch Changes
02ffdcb]76cb673]e808fa5]33647d7]v4.0.32Compare Source
Patch Changes
6cd7c74]e35bcae]a4eb3f3]v4.0.31Compare Source
Patch Changes
70f18c3]cd06458]v4.0.30Compare Source
Patch Changes
v4.0.29Compare Source
Patch Changes
v4.0.28Compare Source
Patch Changes
0bc8d4f]v4.0.27Compare Source
Patch Changes
ac01b79]31c7be8]2696562]comarkdown/comark (@comark/vue)
v0.5.1: @comark/nuxt v0.5.1Compare Source
0.5.1 (2026-07-14)
nuxt/content (@nuxt/content)
v3.15.2Compare Source
Bug Fixes
v3.15.1Compare Source
Bug Fixes
nuxt/module-builder (@nuxt/module-builder)
v1.0.3Compare Source
👉 Changelog
compare changes
🩹 Fixes
📦 Build
🏡 Chore
resolutions/pnpm.overridestopnpm-workspace.yaml(cfb45fb)afcf2fa)aeb1d38)92eb2af)✅ Tests
809c89f)9412c91)#appornuxt/appin generated declarations (#727)🤖 CI
604d5b3)4442a14)f7be1a6)reproduction(57e7ce9)c3c8e72)d87d217)54c5f13)🎉 New Contributors
❤️ Contributors
nuxt-content/mdc (@nuxtjs/mdc)
v0.22.2Compare Source
compare changes
🩹 Fixes
❤️ Contributors
victorgarciaesgi/regle (@regle/core)
v1.28.4Compare Source
🐞 Bug Fixes
RegleRootgeneric type to support collections #378 - by @victorgarciaesgi in #378 (fcf70)View changes on GitHub
tailwindlabs/tailwindcss (@tailwindcss/postcss)
v4.3.3Compare Source
Fixed
--watch --poll[=ms]in@tailwindcss/cliwhen filesystem events are unreliable or unavailable (#20297)bg-[#fff]andbg-[#FFF]→bg-white) (#20298)iframe:focus-visibleoutline styles (#20292)theme('colors.foo')in JS plugins resolves correctly when both--color-fooand--color-foo-barexist (#20299)shadow-sm/12.5,text-shadow-sm/12.5,drop-shadow-sm/12.5, andinset-shadow-sm/12.5(#20302)[data-foo]divas two selectors instead of one (#20303)@tailwindcss/postcssrebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (#20310)@tailwindcss/browserand Tailwind Play (#20124)oklch(#20314)--spacing(0)is optimized to0pxinstead of0so it remains a<length>when used incalc(…)(#20319)@parcel/watcheronly when needed in@tailwindcss/cli --watchmode, so one-off builds and--watch --pollwork when@parcel/watchercan't be loaded (#20325)system-uiandui-sans-serifso CJK text respects the page'slangattribute on Windows (#20318)@tailwindcss/upgradefrom rewriting ignored files when run from a subdirectory (#20329)@sourcerules pointing to nested files are scanned when later@sourcerules point to files in parent folders (#20335)@tailwindcss/vitefrom triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (#20336)tailwindlabs/tailwindcss (@tailwindcss/vite)
v4.3.3Compare Source
Fixed
--watch --poll[=ms]in@tailwindcss/cliwhen filesystem events are unreliable or unavailable (#20297)bg-[#fff]andbg-[#FFF]→bg-white) (#20298)iframe:focus-visibleoutline styles (#20292)theme('colors.foo')in JS plugins resolves correctly when both--color-fooand--color-foo-barexist (#20299)shadow-sm/12.5,text-shadow-sm/12.5,drop-shadow-sm/12.5, andinset-shadow-sm/12.5(#20302)[data-foo]divas two selectors instead of one (#20303)@tailwindcss/postcssrebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (#20310)@tailwindcss/browserand Tailwind Play (#20124)oklch(#20314)--spacing(0)is optimized to0pxinstead of0so it remains a<length>when used incalc(…)(#20319)@parcel/watcheronly when needed in@tailwindcss/cli --watchmode, so one-off builds and--watch --pollwork when@parcel/watchercan't be loaded (#20325)system-uiandui-sans-serifso CJK text respects the page'slangattribute on Windows (#20318)@tailwindcss/upgradefrom rewriting ignored files when run from a subdirectory (#20329)@sourcerules pointing to nested files are scanned when later@sourcerules point to files in parent folders (#20335)@tailwindcss/vitefrom triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (#20336)TanStack/virtual (@tanstack/vue-virtual)
v3.13.34Compare Source
Patch Changes
7ae32b5]:v3.13.33Compare Source
Patch Changes
1e3b908,7dcfc07]:unjs/unhead (@unhead/vue)
v2.1.16Compare Source
🐞 Bug Fixes
View changes on GitHub
vitejs/vite-plugin-vue (@vitejs/plugin-vue)
v6.0.8Features
Bug Fixes
vercel/ai (ai)
v7.0.37Compare Source
Patch Changes
0a7c7f4]v7.0.36Compare Source
Patch Changes
7fa85b2: fix(ai): use injective serialization for tool approval HMAC payloadThe tool approval signature (
experimental_toolApprovalSecret) built its HMACpayload by joining fields with
\n. Because fields such astoolNameandtoolCallIdcan themselves contain a newline, distinct field tuples couldserialize to identical bytes, allowing a signed approval to verify against a
different tuple. The payload is now serialized with
JSON.stringify(with aversioned domain-separation prefix), which escapes delimiter/control characters
and makes the encoding injective.
Verification remains backwards compatible: a signature in the old format still
verifies, but only when no field contains the
\ndelimiter (the conditionthat made the old format ambiguous), so a pending approval that straddles an
upgrade is not rejected while the collision stays closed.
v7.0.35Compare Source
Patch Changes
7f6650b: Return response piping promises so callers can catch stream read and write errors.106ea59: feat(ai): add per-step first content timeout for streaming generations2112ff1]v7.0.34Compare Source
Patch Changes
7c16f21]v7.0.33Compare Source
Patch Changes
76cb673: fix: detect MP4 audio from its ftyp box during transcriptione808fa5: fix(ai): preserve tool parts when tool call IDs repeat across steps33647d7: Preserve provider options when combining consecutive tool messages.02ffdcb]76cb673]v7.0.32Compare Source
Patch Changes
6cd7c74: fix: correct theonToolCallcallback result documentatione35bcae: Allow UI message chunks to include fields added by newer server versions.a4eb3f3: Propagate abort reasons when generation is cancelled during tool execution.cefa3b1]8fbb89c]v7.0.31Compare Source
Patch Changes
70f18c3: fix(ai): emit denied tool output state for client-rejected approvalscd06458: fix(ai): callonInputStartbeforeonInputAvailableduring non-streaming tool callscd06458]v7.0.30Compare Source
Patch Changes
341616a]70fc45c]v7.0.29Compare Source
Patch Changes
7069785]4bf9ac2]v7.0.28Compare Source
Patch Changes
0bc8d4f: Fix chatonFinishhandling when overlapping requests clear the active response before a resume stream finishes.v7.0.27Compare Source
Patch Changes
ac01b79: Allow validating assistant UI messages with empty parts so persisted errored responses remain loadable.2696562:experimental_streamTranscriberesult promises now resolve without consumingfullStream: accessing any result promise consumes the stream internally. Previouslyawait result.textalone deadlocked on transform backpressure. Because live transcription streams can be unbounded,fullStreamis explicitly single-consumer (no replay buffering): access it once, before any result promise, when both stream parts and final results are needed.31c7be8]4d096f6]eslint/eslint (eslint)
v10.8.0Compare Source
Features
2fee9bbfeat: exportConfigObjectfromeslint/config(#21082) (sethamus)Bug Fixes
6b8d2f7fix: escape reserved characters in rule id inhtmlformatter (#21129) (Francesco Trotta)9091071fix: preventno-unreachable-loopcrash when all loop types are ignored (#21116) (Pixel)e23fafefix: prefer-object-spread add semicolon when adding parenthesis (#21081) (synthex-byte)20b5ad0fix: quadratic-time regex inprefer-template(#21096) (Milos Djermanovic)8b6f6c0fix: apply ignore configs to computed methods in class-methods-use-this (#21094) (Pixel)b2c608cfix: NewExpression with parenthesized callee inpreserve-caught-error(#21083) (Francesco Trotta)Documentation
6ddf858docs: fix broken Specify Parser Options anchor link (#21106) (Minsu)784dfbedocs: Clarifyno-eq-nulldescription (#21120) (Park Harin)7ec733adocs: Fix typos and grammar in glossary (#21095) (Marry (Subin Yang))92bb13fdocs: replace quake link (#21108) (Jung Hyeon Jun)68eb4a5docs: fix broken Specify Globals anchor links in rule pages (#21103) (Minsu)d28f697docs: replace Code Climate CLI links with Qlty CLI links (#21099) (Jung Hyeon Jun)eccc68ddocs: correct --suppressions-location option description (#21093) (Ga eun Lee)c5963f7docs: Update README (GitHub Actions Bot)Chores
4fbf46dtest: pinwebpackversion to 5.108.4 (#21137) (Francesco Trotta)2d063e2chore: update HTTP URLs to HTTPS in JSDoc and comments (#21101) (Bo Hyun Kim)eccbe7btest: add error locations tono-class-assign(#21123) (devoil)e7d1e43ci: bump actions/setup-go from 6 to 7 (#21118) (dependabot[bot])e9d66d0ci: bump actions/setup-node from 6 to 7 (#21119) (dependabot[bot])ee225b6test: Add error location details tono-eq-nullrule (#21117) (Park Harin)044a627chore: update minimatch to ^10.2.5 (#21107) (김채영)fb09aa8chore: update ecosystem plugins (#21115) (ESLint Bot)5abd878test: add error locations tono-proto(#21114) (Gihyeon Jeong / 정기현)9715887test: Add error location details tono-div-regex([#21110Configuration
📅 Schedule: (in timezone Europe/Paris)
* 6-9 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.