Skip to content

chore(deps): update npm minor and patch dependencies - #10350

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-minor-patch
Open

chore(deps): update npm minor and patch dependencies#10350
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@anthropic-ai/claude-agent-sdk ^0.3.218^0.3.247 age confidence
@cloudflare/puppeteer (source) ^1.1.0^1.4.0 age confidence
@cloudflare/vitest-pool-workers (source) ^0.18.8^0.22.0 age confidence
@cloudflare/workers-types ^5.20260724.1^5.20260826.1 age confidence
@hono/node-server ^2.0.11^2.1.1 age confidence
@lovable.dev/vite-plugin-dev-server-bridge (source) 1.2.11.3.2 age confidence
@lovable.dev/vite-plugin-hmr-gate (source) 1.1.41.8.1 age confidence
@lovable.dev/vite-tanstack-config (source) 2.7.72.17.1 age confidence
@modelcontextprotocol/sdk (source) 1.29.01.30.0 age confidence
@octokit/core ^7.0.6^7.0.7 age confidence
@posthog/cli (source) 0.9.10.16.0 age confidence
@radix-ui/react-accordion (source) ^1.2.18^1.2.20 age confidence
@radix-ui/react-alert-dialog (source) ^1.1.21^1.1.23 age confidence
@radix-ui/react-aspect-ratio (source) ^1.1.13^1.1.15 age confidence
@radix-ui/react-avatar (source) ^1.2.4^1.2.6 age confidence
@radix-ui/react-checkbox (source) ^1.3.9^1.3.11 age confidence
@radix-ui/react-collapsible (source) ^1.1.18^1.1.20 age confidence
@radix-ui/react-context-menu (source) ^2.3.5^2.3.7 age confidence
@radix-ui/react-dialog (source) ^1.1.21^1.1.23 age confidence
@radix-ui/react-dropdown-menu (source) ^2.1.22^2.1.24 age confidence
@radix-ui/react-hover-card (source) ^1.1.21^1.1.23 age confidence
@radix-ui/react-label (source) ^2.1.13^2.1.15 age confidence
@radix-ui/react-menubar (source) ^1.1.22^1.1.24 age confidence
@radix-ui/react-navigation-menu (source) ^1.2.20^1.2.22 age confidence
@radix-ui/react-popover (source) ^1.1.21^1.1.23 age confidence
@radix-ui/react-progress (source) ^1.1.14^1.1.16 age confidence
@radix-ui/react-radio-group (source) ^1.4.5^1.4.7 age confidence
@radix-ui/react-scroll-area (source) ^1.2.16^1.2.18 age confidence
@radix-ui/react-select (source) ^2.3.5^2.3.7 age confidence
@radix-ui/react-separator (source) ^1.1.13^1.1.15 age confidence
@radix-ui/react-slider (source) ^1.4.5^1.4.7 age confidence
@radix-ui/react-slot (source) ^1.3.1^1.3.3 age confidence
@radix-ui/react-switch (source) ^1.3.5^1.3.7 age confidence
@radix-ui/react-tabs (source) ^1.1.19^1.1.21 age confidence
@radix-ui/react-toggle (source) ^1.1.16^1.1.18 age confidence
@radix-ui/react-toggle-group (source) ^1.1.17^1.1.19 age confidence
@radix-ui/react-tooltip (source) ^1.2.14^1.2.16 age confidence
@scalar/api-reference-react (source) ^0.9.59^0.9.65 age confidence
@sentry/node (source) ^10.67.0^10.71.0 age confidence
@sentry/react (source) ^10.67.0^10.71.0 age confidence
@tanstack/react-query (source) ^5.101.4^5.102.6 age confidence
@tanstack/react-router (source) ^1.170.18^1.170.32 age confidence
@tanstack/react-start (source) ^1.168.32^1.168.49 age confidence
@tanstack/router-plugin (source) ^1.168.23^1.168.35 age confidence
@types/pg (source) ^8.20.0^8.23.1 age confidence
@types/react (source) ^19.2.17^19.2.18 age confidence
@types/react-dom (source) ^19.2.3^19.2.5 age confidence
@types/semver (source) ^7.7.1^7.8.0 age confidence
@vitest/coverage-v8 (source) ^4.1.10^4.1.11 age confidence
agents (source) ^0.19.0^0.21.0 age confidence
esbuild ^0.28.1^0.28.2 age confidence
eslint (source) ^10.8.0^10.9.1 age confidence
eslint-plugin-react-refresh ^0.5.3^0.5.5 age confidence
fumadocs-core ^16.12.1^16.15.2 age confidence
fumadocs-mdx ^15.2.0^15.3.1 age confidence
globals ^17.7.0^17.11.0 age confidence
hono (source) ^4.12.31^4.13.5 age confidence
hono (source) ^4.12.34^4.13.5 age confidence
input-otp (source) ^1.4.2^1.5.0 age confidence
motion ^12.42.2^12.43.0 age confidence
node-addon-api ^8.9.0^8.9.2 age confidence
npm (source) 10.9.810.9.9 age confidence
pg (source) ^8.22.0^8.23.0 age confidence
playwright (source) ^1.61.1^1.62.1 age confidence
posthog-js (source) ^1.409.3^1.421.0 age confidence
posthog-node (source) ^5.46.1^5.51.2 age confidence
react-hook-form (source) ^7.82.0^7.86.0 age confidence
react-resizable-panels (source) ^4.12.2^4.12.3 age confidence
sharp (source, changelog) ^0.35.3^0.35.4 age confidence
sonner (source) ^2.0.7^2.0.8 age confidence
tar ^7.5.21^7.5.22 age confidence
tsx (source) 4.22.54.23.12 age confidence
tsx (source) ^4.23.1^4.23.12 age confidence
turbo (source) ^2.10.6^2.10.12 age confidence
typescript-eslint (source) ^8.65.0^8.68.0 age confidence
vite (source) ^8.1.5^8.2.2 age confidence
vitest (source) ^4.1.10^4.1.11 age confidence
web-tree-sitter (source) ^0.20.8^0.26.13 age confidence
wrangler (source) ^4.115.0^4.126.0 age confidence
wrangler (source) ^4.114.0^4.126.0 age confidence
ws ^8.21.1^8.21.3 age confidence

Dependency PRs must keep npm run test:ci passing. The 97% coverage requirement is enforced as Codecov patch coverage on changed lines (codecov/patch), so dependency-only bumps satisfy it without new tests.

GitHub Actions updates must remain SHA-pinned.

Renovate is the sole dependency and security-update bot for this repo; GitHub Dependabot security updates are disabled to avoid duplicate PRs (e.g. the two hono advisory PRs).


Release Notes

anthropics/claude-agent-sdk-typescript (@​anthropic-ai/claude-agent-sdk)

v0.3.247

Compare Source

  • Added an optional ambient flag to task_started, task_notification and background_tasks_changed task entries so hosts can exclude housekeeping tasks from activity indicators
  • Fixed the permissionMode on per-turn system/init frames reporting the mode at turn start instead of the live mode, so a mode switch right after submitting no longer sends a stale value

v0.3.246

Compare Source

  • Added optional user_message_uuid to error result messages and to the first assistant message or stream_event of each turn, linking a reply or failure to the user message that triggered it
  • Added modelUsage[*].costBasis ('list' | 'managed' | 'unknown') reporting which price table each model's costUSD was computed from
  • Added modelPricing support in the managedSettings option for hosts that set CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST; an admin-managed settings source that sets modelPricing still wins
  • Added perTaskStopAffordance option: when set, interrupt() aborts only the current turn and keeps background agents and workflows running; otherwise (and for one-shot string prompts) they stop

v0.3.245

Compare Source

  • Updated to parity with Claude Code v2.1.245

v0.3.243

  • Added optional queued_turn_count to result messages: the number of queued user sends still pending when the result was produced, so hosts know whether another turn and result will follow
  • Fixed mcp_status reporting a remote MCP server as connected after its connection dropped; it now reports pending while reconnecting, then connected or failed
  • Fixed managed disableAllHooks also disabling hook callbacks registered through the hooks option; they now keep running, matching allowManagedHooksOnly
  • Changed Read tool PDF results: the document block (or page image blocks for pages reads) now arrives inside the tool_result content instead of as a separate user message after it
  • Updated to parity with Claude Code v2.1.243

v0.3.242

  • Updated to parity with Claude Code v2.1.242

v0.3.241

Compare Source

  • Updated to parity with Claude Code v2.1.241

v0.3.240

Compare Source

  • Updated to parity with Claude Code v2.1.240

v0.3.239

Compare Source

  • total_cost_usd / modelUsage.costUSD now include the 1.1× US-only-inference (data residency) multiplier when the response reports inference_geo: "us"
  • A result held back for background subagents in one-shot mode now reports total_cost_usd, duration_api_ms and modelUsage as of its release, not the turn-end snapshot
  • Fixed SYSTEM_PROMPT_DYNAMIC_BOUNDARY in an array systemPrompt being sent to the model as literal text on Bedrock, Vertex, Foundry, and gateway providers
  • A repeated initialize on a running process is now followed by a background_tasks_changed snapshot of the live background tasks, so reconnecting hosts see work that is still running

v0.3.238

Compare Source

  • Added is_backgrounded and spawn_depth to task_started events for subagent tasks (is_backgrounded also on background Bash tasks)
  • Added suppressOriginalPrompt to UserPromptExpansion hook output, matching UserPromptSubmit
  • Added command_lifecycle state refused: a cross-session peer message the session's receive-side policy declines now reports this terminal state instead of producing no lifecycle frames
  • Fixed SDK hook callbacks silently not applying after a host re-sends initialize to an already-running CLI; the response now reports hooks_applied
  • Fixed CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=true not keeping prompt_suggestion messages on when the account is near, but not over, its usage limit
  • Changed vcs_state_changed push events to emit one event per pushed branch

v0.3.237

Compare Source

  • Updated to parity with Claude Code v2.1.237

v0.3.236

Compare Source

  • PostToolUse hooks can return hookSpecificOutput.classifierContext, a short host-asserted note about a tool call's result that the auto mode permission classifier reads alongside that result

v0.3.235

Compare Source

  • Updated to parity with Claude Code v2.1.235

v0.3.234

Compare Source

  • Removed unused bypass_permissions_disabled from ExitReason type; the value was never emitted — TypeScript consumers with an explicit case branch get a compile error on upgrade (runtime unaffected)
  • Updated the ApiKeySource type to include the values system/init actually reports (ANTHROPIC_API_KEY, apiKeyHelper, /login managed key, none)
  • vcs_state_changed events report the directory the shell finished in (an inner cd is reflected)
  • A peer origin injected by the host may declare the sending session's permission class (fromMode) so a same-class message is delivered to a recipient that runs without asking
  • SDKSystemMessage (system/init) gains an optional effort field: the session's applied effort level, or null when none is sent. Set on Remote Control bridge init frames

v0.3.233

Compare Source

  • Notification hooks now fire for pending permission prompts on the SDK path, matching the interactive REPL behavior
  • Todo/task-tracking tools (TaskCreate/TaskGet/TaskUpdate/TaskList, TodoWrite) are no longer in the default tool surface on Opus 4.8, Sonnet 5, Fable 5, Mythos 5, and newer models; name them in the tools option or reference them in allowedTools (or set CLAUDE_CODE_ENABLE_TODO_TOOLS=1) to keep them

v0.3.232

Compare Source

  • Subagent MCP tool_result frames whose result carries _meta now emit tool_use_result as { content, _meta } (matching main-loop frames) instead of a bare value
  • /context result messages now carry a structured context_usage payload (new SDKContextUsage type), so consumers can render the context-usage card without parsing the markdown table
  • vcs_state_changed events now populate the branch field for push operations, sourced from the pushed ref

v0.3.231

Compare Source

  • Updated to parity with Claude Code v2.1.231

v0.3.229

Compare Source

  • Added terminal_slash_commands to the system init message so Remote Control clients can hide terminal-oriented commands
  • Changed conversations whose messages alone exceed the API's 32 MB limit to end the turn with terminal_reason "api_error" instead of "image_error"; StopFailure error_details is "request_body_over_limit: …"

v0.3.228

Compare Source

  • Agent tool results (AgentOutput): usage.output_tokens_details is now carried through

v0.3.227

Compare Source

  • Updated to parity with Claude Code v2.1.227

v0.3.226

Compare Source

  • Updated to parity with Claude Code v2.1.226

v0.3.225

Compare Source

  • Fixed background subagents in headless/SDK sessions never resuming when a background shell command or Monitor they left running completed, so the subagent never saw the result

v0.3.224

Compare Source

  • Added crossSessionInbound and dialogExpiry settings: cross-session messages sent to a session running with bypassed permissions are held for your approval, and messages to other sessions auto-deliver
  • Added subkind: 'peer-send-message' to the task-notification member of SDKMessageOrigin, marking a notification raised by a cross-session SendMessage
  • Added source: 'archive' plugin config variant to Settings, with url and optional sha256, for installing plugins from a zip over HTTPS
  • Added sandbox credential-masking fields to Settings: decode: 'jwt' with maskClaims, extract/onExtractNoMatch on envVars, and awsPairs/sigv4 for AWS SigV4 re-signing
  • Fixed long (>200 char) project paths resolving to another project's session directory under a shared sanitized prefix; session list/get/rename/tag/fork/delete and /resume no longer cross projects

v0.3.223

Compare Source

  • Added resumeDropsTurn option: with resumeSessionAt, declares the turn a truncating resume intends to drop; the CLI refuses the resume if anything else would be discarded
  • Result messages for repeated 529 overload failures now include api_error_status: 529, so SDK consumers can detect overload terminations structurally instead of matching message text
  • Bare headless (-p / SDK query() without canUseTool) now emits system/permission_denied stream events when a tool call is auto-denied
  • Documented usage vs modelUsage on stream-json results: usage is main-loop-only and per-turn; modelUsage is cumulative, covers all query-pipeline calls, and is the field for cost accounting

v0.3.222

Compare Source

  • Fixed query({ sessionStore, resume }) not carrying user settings.json (apiKeyHelper, env, hooks, permissions) into the resumed subprocess

v0.3.221

Compare Source

  • Improved skills option validation: malformed names (delimiters or control characters) and wildcard-form names are rejected with a clear error; use skills: 'all' to enable every skill
  • Fixed external MCP servers passed via the mcpServers option not being connected before the first turn, which caused the model to emit tool calls as literal text

v0.3.220

Compare Source

  • Updated to parity with Claude Code v2.1.220

v0.3.219

Compare Source

  • Added opt-in cancel_queued to the interrupt control request (capability interrupt_cancel_queued_v1): cancels queued and pending-dispatch messages alongside the abort
  • Added fast_mode_disabled_reason to result and init messages so SDK hosts can explain why fast mode is off
  • Added DirectoryAdded lifecycle hook event to the control protocol, fired when a new working directory is registered mid-session
  • Fixed the initialize response reporting fast_mode_state from the spawn-time model after a model switch
  • Added sandbox.network.strictAllowlist to SDK settings types for deterministically denying non-allowlisted hosts in sandboxed commands
  • Added workflowSizeGuideline to SDK settings types for setting the advisory dynamic-workflow size guideline
cloudflare/puppeteer (@​cloudflare/puppeteer)

v1.4.0

Compare Source

v1.3.0

Compare Source

What's Changed

Full Changelog: cloudflare/puppeteer@v1.2.0...v1.3.0

v1.2.0

Compare Source

What's Changed

Full Changelog: cloudflare/puppeteer@v1.1.0...v1.2.0

cloudflare/workers-sdk (@​cloudflare/vitest-pool-workers)

v0.22.0

Compare Source

Minor Changes
  • #​13830 49d4e00 Thanks @​penalosa! - Mocking requests with MSW in Worker tests now requires MSW >= 2.14

    @cloudflare/vitest-pool-workers previously shipped internal shims to make MSW work inside the workerd runtime. MSW 2.14 added that support natively, so those shims have been removed.

    If you mock requests with MSW in your Worker tests, make sure you're on MSW >= 2.14; older versions will no longer intercept requests. You can keep using setupServer() from msw/node, or adopt the official @msw/cloudflare integration via setupNetwork(). See the updated request-mocking example fixture for the recommended pattern.

Patch Changes
  • #​15211 bc5726b Thanks @​nithin42! - Honor access.dev when running Workers with @cloudflare/vitest-pool-workers, so ctx.access.getIdentity() returns the configured identity just as it does with wrangler dev.

  • #​15156 3ddd3ce Thanks @​dario-piotrowicz! - Fix module resolution for relative require() inside CJS deps when the project path contains spaces

    When a project lives under a directory with a space in its name, externalized CommonJS dependencies that use relative require() calls (e.g. require("./lib/impl.js")) would fail with "No such module" because workerd preserves URL encoding in the module name. Encoded module paths are now handled deterministically before CommonJS resolution without altering literal percent sequences.

  • #​15150 2cf3143 Thanks @​kkkhs! - Restore typed inject() keys in cloudflareTest() pool options

    inject() inside cloudflareTest() options again infers the value type from the keys you declare in your Vitest ProvidedContext, and reports misspelled keys. For keys that are only provided at runtime, pass an explicit type argument, e.g. inject<number>("myPort").

  • #​15232 8777180 Thanks [@​vicb](htt

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/Phoenix)

  • Branch creation
    • "before 6am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Aug 10, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
❌ Deployment failed
View logs
loopover-ui dd2e0b4 Aug 29 2026, 06:50 PM

@codecov

codecov Bot commented Aug 10, 2026

Copy link
Copy Markdown

⚠️ JUnit XML file not found

The CLI was unable to find any JUnit XML files to upload.
For more help, visit our troubleshooting guide.

@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 5b9e1bb to 6120b8c Compare August 10, 2026 13:04
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 6120b8c to 2b9cf39 Compare August 10, 2026 17:56
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 2b9cf39 to 0c5024c Compare August 10, 2026 22:16
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 0c5024c to 73830c8 Compare August 11, 2026 01:17
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 73830c8 to 53cdbf8 Compare August 11, 2026 04:50
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 53cdbf8 to 2b3206d Compare August 11, 2026 21:17
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 2b3206d to 7e07ff7 Compare August 12, 2026 05:56
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 7e07ff7 to 6d1860c Compare August 12, 2026 15:17
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 6d1860c to 8246cab Compare August 16, 2026 11:18
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 8246cab to 4bf978f Compare August 16, 2026 12:40
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 4bf978f to c35fbf6 Compare August 16, 2026 17:38
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from c35fbf6 to e67f676 Compare August 16, 2026 20:59
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from e67f676 to 264b992 Compare August 17, 2026 02:56
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 8b4e40a to 5bcb4d4 Compare August 23, 2026 10:34
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 5bcb4d4 to f9bc6f3 Compare August 23, 2026 13:45
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from f9bc6f3 to 7c0adb0 Compare August 23, 2026 21:02
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 7c0adb0 to 3ce9dfc Compare August 24, 2026 03:40
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 3ce9dfc to 79d4646 Compare August 24, 2026 10:00
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 79d4646 to bf45ebf Compare August 25, 2026 17:51
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from bf45ebf to 27819f5 Compare August 26, 2026 00:11
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 27819f5 to 2632feb Compare August 26, 2026 03:47
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch 2 times, most recently from 12f7e58 to e7b6693 Compare August 26, 2026 23:13
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from e7b6693 to 924fe96 Compare August 27, 2026 08:43
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 924fe96 to 3de850f Compare August 27, 2026 17:57
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 3de850f to ec559db Compare August 27, 2026 22:54
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from ec559db to f466077 Compare August 28, 2026 03:41
@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant