Skip to content

build(deps): bump the production-dependencies group across 1 directory with 9 updates - #34

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-e66f585657
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-e66f585657

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 9 updates in the / directory:

Package From To
@anthropic-ai/sdk 0.110.0 0.128.0
inngest 4.12.1 4.21.0
next 16.2.10 16.3.6
react 19.2.7 19.3.0
react-dom 19.2.7 19.3.0
zod 4.4.3 4.6.5
drizzle-orm 0.45.2 0.45.3
cron-parser 5.6.1 5.10.1
fast-xml-parser 5.10.0 5.11.1

Updates @anthropic-ai/sdk from 0.110.0 to 0.128.0

Release notes

Sourced from @​anthropic-ai/sdk's releases.

sdk: v0.128.0

0.128.0 (2026-09-22)

Full Changelog: sdk-v0.127.0...sdk-v0.128.0

Features

  • api: add support for claude-opus-5-5, inline tool definitions and MCP tool-list pinning (beta) (eff2748)

Bug Fixes

  • api: share one evaluated_permission enum across Managed Agents events (0c1cc0f)
  • tools: addTools() takes effect straight away (#773) (1ccdad0)
  • tools: leave reply-only params off the tool runner's compaction request (#769) (8afc336)

Chores

  • docs: add descriptions to the Dreams API reference (ea4ddd1)
  • docs: add descriptions to the User Profiles API reference (ea4ddd1)
  • docs: add memory store descriptions to the Managed Agents API reference (ea4ddd1)
  • docs: improve descriptions in the Dreams API reference (971c54a)
  • docs: simplify the session thread agent type description (ccf71a2)
  • docs: update diagnostics field descriptions on beta messages (c0b8746)
  • internal: add property-based tests for partial JSON parsing (#776) (3ffac09)

sdk: v0.127.0

0.127.0 (2026-09-18)

Full Changelog: sdk-v0.126.0...sdk-v0.127.0

Features

  • api: add group with display_name to rate limits, deprecate group_type (2575d97)
  • tools: add compactBeforeNextTurn() to the tool runner (#682) (9f75ca6)

Bug Fixes

  • BetaMessageStream: stop coercing a null compaction_delta content into "null" (#655) (dbd6845)
  • client: don't retry requests whose body is a stream or iterator (eebc1b9)
  • client: join multiple anthropic-beta values with a comma and no space (#638) (e0cb1ff)
  • client: make pagination exports on the client namespace type-only (5adea1f)
  • internal: drop jest from tsconfig types (60588af)
  • middleware: echo a streamed compaction summary in the fallback continuation (#657) (2e0f004)
  • tools: keep $defs when transformJSONSchema root is a $ref (#687) (57a9f30)

Performance Improvements

... (truncated)

Changelog

Sourced from @​anthropic-ai/sdk's changelog.

0.128.0 (2026-09-22)

Full Changelog: sdk-v0.127.0...sdk-v0.128.0

Features

  • api: add support for claude-opus-5-5, inline tool definitions and MCP tool-list pinning (beta) (eff2748)

Bug Fixes

  • api: share one evaluated_permission enum across Managed Agents events (0c1cc0f)
  • tools: addTools() takes effect straight away (#773) (1ccdad0)
  • tools: leave reply-only params off the tool runner's compaction request (#769) (8afc336)

Chores

  • docs: add descriptions to the Dreams API reference (ea4ddd1)
  • docs: add descriptions to the User Profiles API reference (ea4ddd1)
  • docs: add memory store descriptions to the Managed Agents API reference (ea4ddd1)
  • docs: improve descriptions in the Dreams API reference (971c54a)
  • docs: simplify the session thread agent type description (ccf71a2)
  • docs: update diagnostics field descriptions on beta messages (c0b8746)
  • internal: add property-based tests for partial JSON parsing (#776) (3ffac09)

0.127.0 (2026-09-18)

Full Changelog: sdk-v0.126.0...sdk-v0.127.0

Features

  • api: add group with display_name to rate limits, deprecate group_type (2575d97)
  • tools: add compactBeforeNextTurn() to the tool runner (#682) (9f75ca6)

Bug Fixes

  • BetaMessageStream: stop coercing a null compaction_delta content into "null" (#655) (dbd6845)
  • client: don't retry requests whose body is a stream or iterator (eebc1b9)
  • client: join multiple anthropic-beta values with a comma and no space (#638) (e0cb1ff)
  • client: make pagination exports on the client namespace type-only (5adea1f)
  • internal: drop jest from tsconfig types (60588af)
  • middleware: echo a streamed compaction summary in the fallback continuation (#657) (2e0f004)
  • tools: keep $defs when transformJSONSchema root is a $ref (#687) (57a9f30)

Performance Improvements

  • client: skip formatting request details when debug logging is off (2b29ed2)

... (truncated)

Commits
  • 1926adb Merge pull request #1208 from anthropics/release-please--branches--main--chan...
  • 162c8b1 chore: release main
  • 3ffac09 chore(internal): add property-based tests for partial JSON parsing (#776)
  • e40ce27 test(ecosystem): check that unused imports tree-shake to nothing
  • 1ccdad0 fix(tools): addTools() takes effect straight away (#773)
  • 8afc336 fix(tools): leave reply-only params off the tool runner's compaction request ...
  • eff2748 feat(api): add support for claude-opus-5-5, inline tool definitions and MCP t...
  • 06e5f9b codegen metadata
  • 0c1cc0f fix(api): share one evaluated_permission enum across Managed Agents events
  • c0b8746 chore(docs): update diagnostics field descriptions on beta messages
  • Additional commits viewable in compare view

Updates inngest from 4.12.1 to 4.21.0

Release notes

Sourced from inngest's releases.

inngest@4.21.0

Minor Changes

  • #1725 76015387 Thanks @​jakobevangelista! - Add secrets to sandbox create options as an array of exact workspace secret names, for example secrets: ["OPENAI_API_KEY"]. Save each secret under the environment variable name the application expects. Duplicate names and collisions with literal environment variables are rejected. Names resolve to secret identities at creation, including across create retries. Values are fetched at launch and inherited by commands, managed processes, and snapshots.

Patch Changes

inngest@4.20.0

Minor Changes

inngest@4.19.0

Minor Changes

Patch Changes

inngest@4.18.1

Patch Changes

  • #1686 ca7dff0e Thanks @​jakobevangelista! - Allow sandbox names up to 255 characters, including uppercase ULIDs and human-readable names.

  • #1704 e72b89c7 Thanks @​jacobheric! - Prevent AI metadata tracking from retaining executions after an SDK request ends, including when OpenTelemetry excludes the root span from sampling.

  • #1698 282106a5 Thanks @​Linell! - Fix function-level middleware silently skipped on adapters whose url() drops the query string (AWS Lambda, Redwood, DigitalOcean): resolve fnId the same way execution does

inngest@4.18.0

... (truncated)

Changelog

Sourced from inngest's changelog.

4.21.0

Minor Changes

  • #1725 76015387 Thanks @​jakobevangelista! - Add secrets to sandbox create options as an array of exact workspace secret names, for example secrets: ["OPENAI_API_KEY"]. Save each secret under the environment variable name the application expects. Duplicate names and collisions with literal environment variables are rejected. Names resolve to secret identities at creation, including across create retries. Values are fetched at launch and inherited by commands, managed processes, and snapshots.

Patch Changes

4.20.0

Minor Changes

4.19.0

Minor Changes

Patch Changes

4.18.1

Patch Changes

  • #1686 ca7dff0e Thanks @​jakobevangelista! - Allow sandbox names up to 255 characters, including uppercase ULIDs and human-readable names.

  • #1704 e72b89c7 Thanks @​jacobheric! - Prevent AI metadata tracking from retaining executions after an SDK request ends, including when OpenTelemetry excludes the root span from sampling.

... (truncated)

Commits

Updates next from 16.2.10 to 16.3.6

Release notes

Sourced from next's releases.

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

v16.3.5

The following bug fixes have been backported. It does not include all pending features/changes on canary.

  • next/image: Skip 0-byte entries when initializing disk LRU cache (#98185)
  • next/image: Reject empty images when reading/writing to the disk cache (#98186)
  • Emit whole-app server NFTs when output: 'standalone' is used with an adapter (#98167)
  • Add CSP nonce to script tags of loading and template files (#98403)
  • Fix use cache prerender signal retention (#98448)

v16.3.4

Follow-up release to v16.3.3 re-enabling AVIF Image Optimization (#97949).

The following bug fixes have been backported. It does not include all pending features/changes on canary.

  • testmode: Fix infinite recursion in testmode passthrough fetch (#97691)
  • Fix build error when aliasing typescript to @​typescript/typescript6 (#97997)
  • Fix unset crossOrigin in Turbopack manifests (#97930)

Credits

Huge thanks to @​eps1lon, @​mischnic, and @​timneutkens for helping!

v16.3.3

This release contains security fixes for the following advisories:

Critical:

v16.3.2

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • [backport] Scope app-entry export validation to files inside the app directory (#97357)
  • [backport] Fix catch-all index page being served for every other slug (#97416)
  • [16.3] Turbopack: don't trace embedded WASM loader helpers (#97353) (#97463)
  • [16.3] Turbopack: retain conditions when replacing resolve request keys (#97453)
  • [16.3.x] Fix Turbopack worker chunk loading with asset prefix (#97419)
  • [16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (#97603)

Credits

Huge thanks to @​lubieowoce, @​unstubbable, @​timneutkens, @​mischnic, and @​eps1lon for helping!

... (truncated)

Commits
  • a758ffc v16.3.6
  • 868fad3 [active-lts] Harden next/og SVG serialization
  • 8c81cbb [lts-active] test: remove unsupported deployment ID builder cases (#98821)
  • ca2c75e v16.3.5
  • 14fb290 [backport] Fix use cache prerender signal retention (#98448)
  • 2b1f28d [16.3.x] Add CSP nonce to script tags of loading and template files (#98403)
  • 4b56cee [16.3.x] Backport docs fixes (#98317)
  • 5568a02 [backport] docs: local development: Rewrite docker section, add Windows Dev D...
  • 93249ab [16.3.X] Emit whole-app server NFTs when output: 'standalone' is used with ...
  • 6549fd7 [16.3.x] next/image: reject empty image on read/write to disk cache (#98186)
  • Additional commits viewable in compare view

Updates react from 19.2.7 to 19.3.0

Release notes

Sourced from react's releases.

19.3.0 (September 9, 2026)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.3 release post for more information.

New React Features

New React DOM Features

  • browser(): a new react-dom API that returns a usable which errors during server rendering and resolves in the browser. use(browser()) inside a <Suspense> boundary marks a subtree as browser-only without reporting a recoverable error (@​gnoff: #37143, #37241)
    • Added an onBrowserBailout option to the react-dom/server APIs to observe when a subtree defers to the browser (@​gnoff #37193)

Notable changes

All Changes

React

... (truncated)

Changelog

Sourced from react's changelog.

19.3.0 (September 9, 2026)

New React Features

…y with 9 updates

Bumps the production-dependencies group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) | `0.110.0` | `0.128.0` |
| [inngest](https://github.com/inngest/inngest-js/tree/HEAD/packages/inngest) | `4.12.1` | `4.21.0` |
| [next](https://github.com/vercel/next.js) | `16.2.10` | `16.3.6` |
| [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.7` | `19.3.0` |
| [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.7` | `19.3.0` |
| [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.6.5` |
| [drizzle-orm](https://github.com/drizzle-team/drizzle-orm) | `0.45.2` | `0.45.3` |
| [cron-parser](https://github.com/harrisiirak/cron-parser) | `5.6.1` | `5.10.1` |
| [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) | `5.10.0` | `5.11.1` |



Updates `@anthropic-ai/sdk` from 0.110.0 to 0.128.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.110.0...sdk-v0.128.0)

Updates `inngest` from 4.12.1 to 4.21.0
- [Release notes](https://github.com/inngest/inngest-js/releases)
- [Changelog](https://github.com/inngest/inngest-js/blob/main/packages/inngest/CHANGELOG.md)
- [Commits](https://github.com/inngest/inngest-js/commits/inngest@4.21.0/packages/inngest)

Updates `next` from 16.2.10 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.2.10...v16.3.6)

Updates `react` from 19.2.7 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react)

Updates `react-dom` from 19.2.7 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom)

Updates `zod` from 4.4.3 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.4.3...v4.6.5)

Updates `drizzle-orm` from 0.45.2 to 0.45.3
- [Release notes](https://github.com/drizzle-team/drizzle-orm/releases)
- [Commits](drizzle-team/drizzle-orm@0.45.2...0.45.3)

Updates `cron-parser` from 5.6.1 to 5.10.1
- [Release notes](https://github.com/harrisiirak/cron-parser/releases)
- [Changelog](https://github.com/harrisiirak/cron-parser/blob/master/CHANGELOG.md)
- [Commits](harrisiirak/cron-parser@v5.6.1...v5.10.1)

Updates `fast-xml-parser` from 5.10.0 to 5.11.1
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-parser@v5.10.0...v5.11.1)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.128.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: inngest
  dependency-version: 4.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: next
  dependency-version: 16.3.6
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: react
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: react-dom
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: drizzle-orm
  dependency-version: 0.45.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: cron-parser
  dependency-version: 5.10.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: fast-xml-parser
  dependency-version: 5.11.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 26, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants