chore(deps): update npm minor and patch dependencies - #10350
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): update npm minor and patch dependencies#10350renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ❌ Deployment failed View logs |
loopover-ui | dd2e0b4 | Aug 29 2026, 06:50 PM |
|
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 10, 2026 13:04
5b9e1bb to
6120b8c
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 10, 2026 17:56
6120b8c to
2b9cf39
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 10, 2026 22:16
2b9cf39 to
0c5024c
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 11, 2026 01:17
0c5024c to
73830c8
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 11, 2026 04:50
73830c8 to
53cdbf8
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 11, 2026 21:17
53cdbf8 to
2b3206d
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 12, 2026 05:56
2b3206d to
7e07ff7
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 12, 2026 15:17
7e07ff7 to
6d1860c
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 16, 2026 11:18
6d1860c to
8246cab
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 16, 2026 12:40
8246cab to
4bf978f
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 16, 2026 17:38
4bf978f to
c35fbf6
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 16, 2026 20:59
c35fbf6 to
e67f676
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 17, 2026 02:56
e67f676 to
264b992
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 23, 2026 10:34
8b4e40a to
5bcb4d4
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 23, 2026 13:45
5bcb4d4 to
f9bc6f3
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 23, 2026 21:02
f9bc6f3 to
7c0adb0
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 24, 2026 03:40
7c0adb0 to
3ce9dfc
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 24, 2026 10:00
3ce9dfc to
79d4646
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 25, 2026 17:51
79d4646 to
bf45ebf
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 26, 2026 00:11
bf45ebf to
27819f5
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 26, 2026 03:47
27819f5 to
2632feb
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
2 times, most recently
from
August 26, 2026 23:13
12f7e58 to
e7b6693
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 27, 2026 08:43
e7b6693 to
924fe96
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 27, 2026 17:57
924fe96 to
3de850f
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 27, 2026 22:54
3de850f to
ec559db
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 28, 2026 03:41
ec559db to
f466077
Compare
Contributor
|
Superagent didn't find any vulnerabilities or security issues in this PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.3.218→^0.3.247^1.1.0→^1.4.0^0.18.8→^0.22.0^5.20260724.1→^5.20260826.1^2.0.11→^2.1.11.2.1→1.3.21.1.4→1.8.12.7.7→2.17.11.29.0→1.30.0^7.0.6→^7.0.70.9.1→0.16.0^1.2.18→^1.2.20^1.1.21→^1.1.23^1.1.13→^1.1.15^1.2.4→^1.2.6^1.3.9→^1.3.11^1.1.18→^1.1.20^2.3.5→^2.3.7^1.1.21→^1.1.23^2.1.22→^2.1.24^1.1.21→^1.1.23^2.1.13→^2.1.15^1.1.22→^1.1.24^1.2.20→^1.2.22^1.1.21→^1.1.23^1.1.14→^1.1.16^1.4.5→^1.4.7^1.2.16→^1.2.18^2.3.5→^2.3.7^1.1.13→^1.1.15^1.4.5→^1.4.7^1.3.1→^1.3.3^1.3.5→^1.3.7^1.1.19→^1.1.21^1.1.16→^1.1.18^1.1.17→^1.1.19^1.2.14→^1.2.16^0.9.59→^0.9.65^10.67.0→^10.71.0^10.67.0→^10.71.0^5.101.4→^5.102.6^1.170.18→^1.170.32^1.168.32→^1.168.49^1.168.23→^1.168.35^8.20.0→^8.23.1^19.2.17→^19.2.18^19.2.3→^19.2.5^7.7.1→^7.8.0^4.1.10→^4.1.11^0.19.0→^0.21.0^0.28.1→^0.28.2^10.8.0→^10.9.1^0.5.3→^0.5.5^16.12.1→^16.15.2^15.2.0→^15.3.1^17.7.0→^17.11.0^4.12.31→^4.13.5^4.12.34→^4.13.5^1.4.2→^1.5.0^12.42.2→^12.43.0^8.9.0→^8.9.210.9.8→10.9.9^8.22.0→^8.23.0^1.61.1→^1.62.1^1.409.3→^1.421.0^5.46.1→^5.51.2^7.82.0→^7.86.0^4.12.2→^4.12.3^0.35.3→^0.35.4^2.0.7→^2.0.8^7.5.21→^7.5.224.22.5→4.23.12^4.23.1→^4.23.12^2.10.6→^2.10.12^8.65.0→^8.68.0^8.1.5→^8.2.2^4.1.10→^4.1.11^0.20.8→^0.26.13^4.115.0→^4.126.0^4.114.0→^4.126.0^8.21.1→^8.21.3Dependency PRs must keep
npm run test:cipassing. The 97% coverage requirement is enforced as Codecov patch coverage on changed lines (codecov/patch), so dependency-only bumps satisfy it without new tests.GitHub Actions updates must remain SHA-pinned.
Renovate is the sole dependency and security-update bot for this repo; GitHub Dependabot security updates are disabled to avoid duplicate PRs (e.g. the two hono advisory PRs).
Release Notes
anthropics/claude-agent-sdk-typescript (@anthropic-ai/claude-agent-sdk)
v0.3.247Compare Source
ambientflag totask_started,task_notificationandbackground_tasks_changedtask entries so hosts can exclude housekeeping tasks from activity indicatorspermissionModeon per-turnsystem/initframes reporting the mode at turn start instead of the live mode, so a mode switch right after submitting no longer sends a stale valuev0.3.246Compare Source
user_message_uuidto error result messages and to the first assistant message orstream_eventof each turn, linking a reply or failure to the user message that triggered itmodelUsage[*].costBasis('list' | 'managed' | 'unknown') reporting which price table each model'scostUSDwas computed frommodelPricingsupport in themanagedSettingsoption for hosts that setCLAUDE_CODE_PROVIDER_MANAGED_BY_HOST; an admin-managed settings source that setsmodelPricingstill winsperTaskStopAffordanceoption: when set,interrupt()aborts only the current turn and keeps background agents and workflows running; otherwise (and for one-shot string prompts) they stopv0.3.245Compare Source
v0.3.243queued_turn_countto result messages: the number of queued user sends still pending when the result was produced, so hosts know whether another turn and result will followmcp_statusreporting a remote MCP server as connected after its connection dropped; it now reports pending while reconnecting, then connected or faileddisableAllHooksalso disabling hook callbacks registered through thehooksoption; they now keep running, matchingallowManagedHooksOnlydocumentblock (or pageimageblocks forpagesreads) now arrives inside thetool_resultcontent instead of as a separateusermessage after itv0.3.242v0.3.241Compare Source
v0.3.240Compare Source
v0.3.239Compare Source
total_cost_usd/modelUsage.costUSDnow include the 1.1× US-only-inference (data residency) multiplier when the response reportsinference_geo: "us"total_cost_usd,duration_api_msandmodelUsageas of its release, not the turn-end snapshotSYSTEM_PROMPT_DYNAMIC_BOUNDARYin an arraysystemPromptbeing sent to the model as literal text on Bedrock, Vertex, Foundry, and gateway providersinitializeon a running process is now followed by abackground_tasks_changedsnapshot of the live background tasks, so reconnecting hosts see work that is still runningv0.3.238Compare Source
is_backgroundedandspawn_depthtotask_startedevents for subagent tasks (is_backgroundedalso on background Bash tasks)suppressOriginalPrompttoUserPromptExpansionhook output, matchingUserPromptSubmitcommand_lifecyclestaterefused: a cross-session peer message the session's receive-side policy declines now reports this terminal state instead of producing no lifecycle framesinitializeto an already-running CLI; the response now reportshooks_appliedCLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=truenot keepingprompt_suggestionmessages on when the account is near, but not over, its usage limitvcs_state_changedpush events to emit one event per pushed branchv0.3.237Compare Source
v0.3.236Compare Source
PostToolUsehooks can returnhookSpecificOutput.classifierContext, a short host-asserted note about a tool call's result that the auto mode permission classifier reads alongside that resultv0.3.235Compare Source
v0.3.234Compare Source
bypass_permissions_disabledfromExitReasontype; the value was never emitted — TypeScript consumers with an explicitcasebranch get a compile error on upgrade (runtime unaffected)ApiKeySourcetype to include the valuessystem/initactually reports (ANTHROPIC_API_KEY,apiKeyHelper,/login managed key,none)vcs_state_changedevents report the directory the shell finished in (an innercdis reflected)origininjected by the host may declare the sending session's permission class (fromMode) so a same-class message is delivered to a recipient that runs without askingSDKSystemMessage(system/init) gains an optionaleffortfield: the session's applied effort level, ornullwhen none is sent. Set on Remote Control bridge init framesv0.3.233Compare Source
TaskCreate/TaskGet/TaskUpdate/TaskList,TodoWrite) are no longer in the default tool surface on Opus 4.8, Sonnet 5, Fable 5, Mythos 5, and newer models; name them in thetoolsoption or reference them inallowedTools(or setCLAUDE_CODE_ENABLE_TODO_TOOLS=1) to keep themv0.3.232Compare Source
tool_resultframes whose result carries_metanow emittool_use_resultas{ content, _meta }(matching main-loop frames) instead of a bare value/contextresult messages now carry a structuredcontext_usagepayload (newSDKContextUsagetype), so consumers can render the context-usage card without parsing the markdown tablevcs_state_changedevents now populate thebranchfield for push operations, sourced from the pushed refv0.3.231Compare Source
v0.3.229Compare Source
terminal_slash_commandsto the system init message so Remote Control clients can hide terminal-oriented commandsterminal_reason"api_error"instead of"image_error";StopFailureerror_detailsis"request_body_over_limit: …"v0.3.228Compare Source
AgentOutput):usage.output_tokens_detailsis now carried throughv0.3.227Compare Source
v0.3.226Compare Source
v0.3.225Compare Source
v0.3.224Compare Source
crossSessionInboundanddialogExpirysettings: cross-session messages sent to a session running with bypassed permissions are held for your approval, and messages to other sessions auto-deliversubkind: 'peer-send-message'to thetask-notificationmember ofSDKMessageOrigin, marking a notification raised by a cross-sessionSendMessagesource: 'archive'plugin config variant toSettings, withurland optionalsha256, for installing plugins from a zip over HTTPSSettings:decode: 'jwt'withmaskClaims,extract/onExtractNoMatchonenvVars, andawsPairs/sigv4for AWS SigV4 re-signing/resumeno longer cross projectsv0.3.223Compare Source
resumeDropsTurnoption: withresumeSessionAt, declares the turn a truncating resume intends to drop; the CLI refuses the resume if anything else would be discardedapi_error_status: 529, so SDK consumers can detect overload terminations structurally instead of matching message text-p/ SDKquery()withoutcanUseTool) now emitssystem/permission_deniedstream events when a tool call is auto-deniedusagevsmodelUsageon stream-json results:usageis main-loop-only and per-turn;modelUsageis cumulative, covers all query-pipeline calls, and is the field for cost accountingv0.3.222Compare Source
query({ sessionStore, resume })not carrying usersettings.json(apiKeyHelper,env,hooks,permissions) into the resumed subprocessv0.3.221Compare Source
skillsoption validation: malformed names (delimiters or control characters) and wildcard-form names are rejected with a clear error; useskills: 'all'to enable every skillmcpServersoption not being connected before the first turn, which caused the model to emit tool calls as literal textv0.3.220Compare Source
v0.3.219Compare Source
cancel_queuedto the interrupt control request (capabilityinterrupt_cancel_queued_v1): cancels queued and pending-dispatch messages alongside the abortfast_mode_disabled_reasonto result and init messages so SDK hosts can explain why fast mode is offDirectoryAddedlifecycle hook event to the control protocol, fired when a new working directory is registered mid-sessionfast_mode_statefrom the spawn-time model after a model switchsandbox.network.strictAllowlistto SDK settings types for deterministically denying non-allowlisted hosts in sandboxed commandsworkflowSizeGuidelineto SDK settings types for setting the advisory dynamic-workflow size guidelinecloudflare/puppeteer (@cloudflare/puppeteer)
v1.4.0Compare Source
v1.3.0Compare Source
What's Changed
Full Changelog: cloudflare/puppeteer@v1.2.0...v1.3.0
v1.2.0Compare Source
What's Changed
Full Changelog: cloudflare/puppeteer@v1.1.0...v1.2.0
cloudflare/workers-sdk (@cloudflare/vitest-pool-workers)
v0.22.0Compare Source
Minor Changes
#13830
49d4e00Thanks @penalosa! - Mocking requests with MSW in Worker tests now requires MSW >= 2.14@cloudflare/vitest-pool-workerspreviously shipped internal shims to make MSW work inside the workerd runtime. MSW 2.14 added that support natively, so those shims have been removed.If you mock requests with MSW in your Worker tests, make sure you're on MSW
>= 2.14; older versions will no longer intercept requests. You can keep usingsetupServer()frommsw/node, or adopt the official@msw/cloudflareintegration viasetupNetwork(). See the updatedrequest-mockingexample fixture for the recommended pattern.Patch Changes
#15211
bc5726bThanks @nithin42! - Honoraccess.devwhen running Workers with@cloudflare/vitest-pool-workers, soctx.access.getIdentity()returns the configured identity just as it does withwrangler dev.#15156
3ddd3ceThanks @dario-piotrowicz! - Fix module resolution for relativerequire()inside CJS deps when the project path contains spacesWhen a project lives under a directory with a space in its name, externalized CommonJS dependencies that use relative
require()calls (e.g.require("./lib/impl.js")) would fail with "No such module" becauseworkerdpreserves URL encoding in the module name. Encoded module paths are now handled deterministically before CommonJS resolution without altering literal percent sequences.#15150
2cf3143Thanks @kkkhs! - Restore typedinject()keys incloudflareTest()pool optionsinject()insidecloudflareTest()options again infers the value type from the keys you declare in your VitestProvidedContext, and reports misspelled keys. For keys that are only provided at runtime, pass an explicit type argument, e.g.inject<number>("myPort").#15232
8777180Thanks [@vicb](httConfiguration
📅 Schedule: (in timezone America/Phoenix)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.