chore(deps): update all non-major dependencies#6753
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub. |
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
2526c31 to
d445c97
Compare
commit: |
d445c97 to
09e6253
Compare
09e6253 to
81c59d0
Compare
81c59d0 to
d79aede
Compare
d79aede to
70afa7a
Compare
70afa7a to
c5cbcd4
Compare
c5cbcd4 to
59177ee
Compare
59177ee to
5e70989
Compare
5e70989 to
35b9325
Compare
35b9325 to
314c701
Compare
314c701 to
f443d9b
Compare
f443d9b to
a71f3b6
Compare
This PR contains the following updates:
^4.0.14→^4.0.19^4.0.19→^4.0.28^2.0.12→^2.0.16^4.0.26→^4.0.37^0.5.0→^0.5.1^1.2.117→^1.2.119^1.2.90→^1.2.91^3.15.0→^3.15.2^1.0.2→^1.0.3^0.22.1→^0.22.2^1.28.3→^1.28.4^1.28.3→^1.28.4^4.3.2→^4.3.3^4.3.2→^4.3.3^3.13.32→^3.13.34^2.1.15→^2.1.16^6.0.7→^6.0.8^7.0.26→^7.0.37^20.10.6→^20.11.1^6.7.2→^6.7.4^6.2.3→^6.2.711.13.0→11.17.0^3.9.5→^3.9.6^4.3.2→^4.3.3^3.5.39→^3.5.40^3.3.7→^3.3.8^3.3.7→^3.3.8^5.1.0→^5.2.0^3.3.7→^3.3.8Release Notes
vercel/ai (@ai-sdk/anthropic)
v4.0.19Compare Source
Patch Changes
01a596a: fix (provider/anthropic): use current-generation capability defaults for unrecognized Claude model IDs while retaining conservative defaults for legacy Claude and non-Claude models.v4.0.18Compare Source
Patch Changes
97de198: Warn when an unknown model uses the default 4096 max output token limit.v4.0.17Compare Source
Patch Changes
b72fc7c: fix(amazon-bedrock): sanitize unsupported JSON Schema constraints in native Anthropic structured output9218ebe: fix(provider/anthropic): warn when parallel tool use is requested with JSON tool structured output02ffdcb]76cb673]v4.0.16Compare Source
Patch Changes
afcf19c: fix(provider/anthropic): preserve web search citations when replaying assistant messagescd06458]v4.0.15Compare Source
Patch Changes
31c7be8]vercel/ai (@ai-sdk/gateway)
v4.0.28Compare Source
Patch Changes
0a7c7f4: chore(provider/gateway): update gateway model settings filesv4.0.27Compare Source
Patch Changes
2112ff1: chore(provider/gateway): update gateway model settings filesv4.0.26Compare Source
Patch Changes
7c16f21: feat(google): addgemini-3.6-flashandgemini-3.5-flash-litemodelsv4.0.25Compare Source
Patch Changes
02ffdcb]76cb673]v4.0.24Compare Source
Patch Changes
cefa3b1: chore(provider/gateway): removehipaaCompliantprovider option8fbb89c: chore(provider/gateway): update gateway model settings filesv4.0.23Compare Source
Patch Changes
cd06458]v4.0.22Compare Source
Patch Changes
341616a: feat: add kimi-k3 model andreasoningEffortprovider option70fc45c: chore(provider/gateway): update gateway model settings filesv4.0.21Compare Source
Patch Changes
7069785: chore(provider/gateway): update gateway model settings files4bf9ac2: feat (provider/gateway): addgateway.experimental_transcription.getTokenfor minting transcription-bound client secretsv4.0.20Compare Source
Patch Changes
4d096f6: chore(provider/gateway): update gateway model settings files31c7be8]vercel/ai (@ai-sdk/mcp)
v2.0.16Compare Source
Patch Changes
02ffdcb]76cb673]v2.0.15Compare Source
Patch Changes
d84ea43: fix(mcp): accept OAuth metadata without code challenge methodscd06458]v2.0.14Compare Source
Patch Changes
48e7e78: Harden MCP Apps handling of server-supplied resource metadata and the host/iframe bridge:_meta.uiand drop malformed or non-string fields.sandbox.allowedPermissionsallowlist.postMessagetarget origin and validate inbound message origins.resources/readtoui://resources and allow onlyhttps/http/mailtoinui/open-link.fingerprintMCPAppResource/detectMCPAppResourceDriftfor pinning and comparing app resources.v2.0.13Compare Source
Patch Changes
31c7be8]vercel/ai (@ai-sdk/vue)
v4.0.37Compare Source
Patch Changes
v4.0.36Compare Source
Patch Changes
7fa85b2]v4.0.35Compare Source
Patch Changes
7f6650b]106ea59]v4.0.34Compare Source
Patch Changes
v4.0.33Compare Source
Patch Changes
02ffdcb]76cb673]e808fa5]33647d7]v4.0.32Compare Source
Patch Changes
6cd7c74]e35bcae]a4eb3f3]v4.0.31Compare Source
Patch Changes
70f18c3]cd06458]v4.0.30Compare Source
Patch Changes
v4.0.29Compare Source
Patch Changes
v4.0.28Compare Source
Patch Changes
0bc8d4f]v4.0.27Compare Source
Patch Changes
ac01b79]31c7be8]2696562]comarkdown/comark (@comark/vue)
v0.5.1: @comark/nuxt v0.5.1Compare Source
0.5.1 (2026-07-14)
nuxt/content (@nuxt/content)
v3.15.2Compare Source
Bug Fixes
v3.15.1Compare Source
Bug Fixes
nuxt/module-builder (@nuxt/module-builder)
v1.0.3Compare Source
👉 Changelog
compare changes
🩹 Fixes
📦 Build
🏡 Chore
resolutions/pnpm.overridestopnpm-workspace.yaml(cfb45fb)afcf2fa)aeb1d38)92eb2af)✅ Tests
809c89f)9412c91)#appornuxt/appin generated declarations (#727)🤖 CI
604d5b3)4442a14)f7be1a6)reproduction(57e7ce9)c3c8e72)d87d217)54c5f13)🎉 New Contributors
❤️ Contributors
nuxt-content/mdc (@nuxtjs/mdc)
v0.22.2Compare Source
compare changes
🩹 Fixes
❤️ Contributors
victorgarciaesgi/regle (@regle/core)
v1.28.4Compare Source
🐞 Bug Fixes
RegleRootgeneric type to support collections #378 - by @victorgarciaesgi in #378 (fcf70)View changes on GitHub
tailwindlabs/tailwindcss (@tailwindcss/postcss)
v4.3.3Compare Source
Fixed
--watch --poll[=ms]in@tailwindcss/cliwhen filesystem events are unreliable or unavailable (#20297)bg-[#fff]andbg-[#FFF]→bg-white) (#20298)iframe:focus-visibleoutline styles (#20292)theme('colors.foo')in JS plugins resolves correctly when both--color-fooand--color-foo-barexist (#20299)shadow-sm/12.5,text-shadow-sm/12.5,drop-shadow-sm/12.5, andinset-shadow-sm/12.5(#20302)[data-foo]divas two selectors instead of one (#20303)@tailwindcss/postcssrebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (#20310)@tailwindcss/browserand Tailwind Play (#20124)oklch(#20314)--spacing(0)is optimized to0pxinstead of0so it remains a<length>when used incalc(…)(#20319)@parcel/watcheronly when needed in@tailwindcss/cli --watchmode, so one-off builds and--watch --pollwork when@parcel/watchercan't be loaded (#20325)system-uiandui-sans-serifso CJK text respects the page'slangattribute on Windows (#20318)@tailwindcss/upgradefrom rewriting ignored files when run from a subdirectory (#20329)@sourcerules pointing to nested files are scanned when later@sourcerules point to files in parent folders (#20335)@tailwindcss/vitefrom triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (#20336)tailwindlabs/tailwindcss (@tailwindcss/vite)
v4.3.3Compare Source
Fixed
--watch --poll[=ms]in@tailwindcss/cliwhen filesystem events are unreliable or unavailable (#20297)bg-[#fff]andbg-[#FFF]→bg-white) (#20298)iframe:focus-visibleoutline styles (#20292)theme('colors.foo')in JS plugins resolves correctly when both--color-fooand--color-foo-barexist (#20299)shadow-sm/12.5,text-shadow-sm/12.5,drop-shadow-sm/12.5, andinset-shadow-sm/12.5(#20302)[data-foo]divas two selectors instead of one (#20303)@tailwindcss/postcssrebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (#20310)@tailwindcss/browserand Tailwind Play (#20124)oklch(#20314)--spacing(0)is optimized to0pxinstead of0so it remains a<length>when used incalc(…)(#20319)@parcel/watcheronly when needed in@tailwindcss/cli --watchmode, so one-off builds and--watch --pollwork when@parcel/watchercan't be loaded (#20325)system-uiandui-sans-serifso CJK text respects the page'slangattribute on Windows (#20318)@tailwindcss/upgradefrom rewriting ignored files when run from a subdirectory (#20329)@sourcerules pointing to nested files are scanned when later@sourcerules point to files in parent folders (#20335)@tailwindcss/vitefrom triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (#20336)TanStack/virtual (@tanstack/vue-virtual)
v3.13.34Compare Source
Patch Changes
7ae32b5]:v3.13.33Compare Source
Patch Changes
1e3b908,7dcfc07]:unjs/unhead (@unhead/vue)
v2.1.16Compare Source
🐞 Bug Fixes
View changes on GitHub
vitejs/vite-plugin-vue (@vitejs/plugin-vue)
v6.0.8Features
Bug Fixes
vercel/ai (ai)
v7.0.37Compare Source
Patch Changes
0a7c7f4]v7.0.36Compare Source
Patch Changes
7fa85b2: fix(ai): use injective serialization for tool approval HMAC payloadThe tool approval signature (
experimental_toolApprovalSecret) built its HMACpayload by joining fields with
\n. Because fields such astoolNameandtoolCallIdcan themselves contain a newline, distinct field tuples couldserialize to identical bytes, allowing a signed approval to verify against a
different tuple. The payload is now serialized with
JSON.stringify(with aversioned domain-separation prefix), which escapes delimiter/control characters
and makes the encoding injective.
Verification remains backwards compatible: a signature in the old format still
verifies, but only when no field contains the
\ndelimiter (the conditionthat made the old format ambiguous), so a pending approval that straddles an
upgrade is not rejected while the collision stays closed.
v7.0.35Compare Source
Patch Changes
7f6650b: Return response piping promises so callers can catch stream read and write errors.106ea59: feat(ai): add per-step first content timeout for streaming generations2112ff1]v7.0.34Compare Source
Patch Changes
7c16f21]v7.0.33Compare Source
Patch Changes
76cb673: fix: detect MP4 audio from its ftyp box during transcriptione808fa5: fix(ai): preserve tool parts when tool call IDs repeat across steps33647d7: Preserve provider options when combining consecutive tool messages.02ffdcb]76cb673]v7.0.32Compare Source
Patch Changes
6cd7c74: fix: correct theonToolCallcallback result documentatione35bcae: Allow UI message chunks to include fields added by newer server versions.a4eb3f3: Propagate abort reasons when generation is cancelled during tool execution.cefa3b1]8fbb89c]v7.0.31Compare Source
Patch Changes
70f18c3: fix(ai): emit denied tool output state for client-rejected approvalscd06458: fix(ai): callonInputStartbeforeonInputAvailableduring non-streaming tool callscd06458]v7.0.30Compare Source
Patch Changes
341616a]70fc45c]v7.0.29Compare Source
Patch Changes
7069785]4bf9ac2]v7.0.28Compare Source
Patch Changes
0bc8d4f: Fix chatonFinishhandling when overlapping requests clear the active response before a resume stream finishes.v7.0.27Compare Source
Patch Changes
ac01b79: Allow validating assistant UI messages with empty parts so persisted errored responses remain loadable.2696562:experimental_streamTranscriberesult promises now resolve without consumingfullStream: accessing any result promise consumes the stream internally. Previouslyawait result.textalone deadlocked on transform backpressure. Because live transcription streams can be unbounded,fullStreamis explicitly single-consumer (no replay buffering): access it once, before any result promise, when both stream parts and final results are needed.31c7be8]4d096f6]capricorn86/happy-dom (happy-dom)
v20.11.1Compare Source
v20.11.0Compare Source
🎨 Features
nuxt-modules/og-image (nuxt-og-image)
v6.7.4Compare Source
🐞 Bug Fixes
View changes on GitHub
v6.7.3Compare Source
compare changes
🩹 Fixes
🏡 Chore
❤️ Contributors
harlan-zw/nuxt-schema-org (nuxt-schema-org)
v6.2.7Compare Source
🐞 Bug Fixes
View changes on GitHub
v6.2.6Compare Source
🐞 Bug Fixes
View changes on GitHub
v6.2.5Compare Source
compare changes
🩹 Fixes
❤️ Contributors
v6.2.4Compare Source
compare changes
🏡 Chore
❤️ Contributors
pnpm/pnpm (pnpm)
v11.17.0: pnpm 11.17Compare Source
Minor Changes
Added a new setting,
update.githubActionsServer, for specifying the base URL of the GitHub server that hosts the repositories of the GitHub Actions referenced by the workflow files (for example, a GitHub Enterprise Server). When the setting is not defined, the URL is read from theGITHUB_SERVER_URLenvironment variable, falling back tohttps://github.com. The URL must use thehttps://orhttp://protocol #13220.pnpm outdatedandpnpm updateno longer fail when the refs of a GitHub Action's repository cannot be read (for example, when the action's repository is private or hosted on a different GitHub server). Such actions are now skipped with a warning.Setting
update.githubActionstofalsenow makespnpm outdatedand the interactivepnpm updateskip GitHub Actions dependencies.Patch Changes
The token poll for web-based authentication no longer reads the body of non-OK or still-pending (HTTP 202) responses, and caps the token response body it does read at 64 KiB, so a malicious or compromised registry cannot exhaust memory through the poll pnpm/pnpm#12721.
Fixed
catalog:references in dependencies and overrides failing to resolve when installing through a pnpr server, which errored with "No catalog entry '' was found for catalog 'default'." even though the catalog entry existed. Also fixed a crash on Windows when installing a nested workspace member (e.g.packages/foo) through a pnpr server #13232.Republished every package: the tarballs published by the v11.13.1 through v11.16.0 releases were missing most of their compiled files due to a packing bug #13164.
Revert script ordering change for
pnpm run --sequential /regex/Support the
from-gitargument in thepnpm versioncommand.When the authentication URL cannot be rendered as a QR code (for example when it exceeds the maximum QR data capacity), web-based login now displays the URL alone with a warning instead of aborting authentication pnpm/pnpm#12721.
Platinum Sponsors
✂ Note
PR body was truncated to here.
Configuration
📅 Schedule: (in timezone Europe/Paris)
* 6-9 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.