fix(deps): update all non-major dependencies - #8
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
18 times, most recently
from
September 27, 2026 10:20
e17fa42 to
d4f6c2f
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
5 times, most recently
from
October 1, 2026 18:07
38ce7dc to
953fd7e
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
October 1, 2026 21:50
953fd7e to
4d420de
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
5 times, most recently
from
October 3, 2026 04:30
aadca16 to
5794674
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
October 3, 2026 09:00
5794674 to
8992ab7
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.0.65→2.0.664.0.126→4.0.1271.2.138→1.2.13926.6.3→26.6.40.24.0→0.26.07.0.126→7.0.1276.10.1→6.10.310.34.5+sha512.a4ee05f2f73658255bd6a89859c065a45c28a57daefae2c893a168ee2b73168c37b91e83e57ea67654ad03f03031746430e8bce38e362e042605fb8abc80192e→10.34.63.3.11→3.3.12Release Notes
vercel/ai (@ai-sdk/mcp)
v2.0.66Compare Source
Patch Changes
3ff0f54: feat(mcp): add AuthorizationServerMismatchError for OAuth authorization server pin mismatchesvercel/ai (@ai-sdk/vue)
v4.0.127Compare Source
Patch Changes
158a718]bb8d33e]284dc11]ba8afe9]cloudflare/agents (agents)
v0.26.0Compare Source
Minor Changes
df9c0efThanks @aron-cf! - Update pi-durable and pi-ai to^1.0.0. See Pi harness docs for details.v0.25.0Compare Source
Minor Changes
c2f7672Thanks @cjol! - Native RPC calls to async Agent and Think methods now start lifecycle initialization first; address Agents by name because raw IDs fromnewUniqueId()andidFromString()now fail their first async RPC. See Lifecycle.Patch Changes
#2390
c55ec80Thanks @threepointone! - Report a failed agent-tool child as failed even when it was evicted before recording the failure. See Agent tools.#2384
f904999Thanks @threepointone! - Fix agent-tool chunks being duplicated or dropped on reconnect, child re-attach, and fiber recovery. See Agent tools.#2364
5e0507eThanks @threepointone! - AddeventDelivery: "terminal"torunAgentToolto forward only lifecycle, progress, and milestone events for a run. See Agent tools.#2448
54f9ca7Thanks @aron-cf! - Add experimentalagents/models/ai-sdk, a provider for Workers AI and AI Gateway over theAIbinding. See Models.#2446
5cf86f8Thanks @aron-cf! - Add experimentalagents/models/pi-ai, a pi-ai provider for Workers AI and AI Gateway over theAIbinding. See Models for pi-ai.#2424
1e54cf1Thanks @aron-cf! - Add experimentalagents/harnesses/pito host pi-durable sessions in a Durable Object. See Pi harness and the runnable example.#2391
d3fe93cThanks @threepointone! - Keep a tool call's input when its approval request arrives before the input finishes streaming (#1872). See Human in the loop.#2369
9b70fdbThanks @ben-reitz! -loadCdpSpecaccepts an optionalsessionIdto read the protocol from an existing Browser Run session. See Browse the web.#2368
ed4f5abThanks @ben-reitz! -connectBrowserSessionthrows aBrowserRenderingErrorwith the HTTP status when Browser Run returns no WebSocket. See Browse the web.#2294
abda4e3Thanks @ben-reitz! - Add Browser Run hostname guardrails, close and activity callbacks, and theCdpConnectionname while retainingCdpSessionas a deprecated alias. See Browse the web.#2372
6e1c346Thanks @ben-reitz! - Add persistent browser tools for AI SDK and TanStack AI, backed by experimental Browser sessions. See Browse the web.#2371
9cddcd3Thanks @ben-reitz! -CdpConnection.send()rejects immediately when its socket is closed instead of waiting for the timeout. See Browse the web.#2379
d49aa82Thanks @ben-reitz! -cdp.spec()andloadCdpSpec()now include command parameters, return types, and type details, so a model can see how to call a CDP method. See Browse the web.#2394
e837967Thanks @threepointone! -useAgentChatloads the new agent's history when the agent address passed touseAgentchanges (#1864, #1874). See Client SDK.#2378
dbf170cThanks @threepointone! -useAgentChatgainsonTurnEnd, and terminal chat frames carry outcomes and user message IDs so clients can settle sends correctly across recovery and reconnects. Replay, tool callbacks, and turn state now remain consistent through terminal delivery; see Chat agents.#2019
d5562e0Thanks @justanotherbyte! - A WebSocket close before the finaldoneframe now putsuseAgentChatin theerrorstate instead of showing a truncated answer as complete (#2013). See Chat agents.#2036
040db5cThanks @justanotherbyte! - Stop storing compaction summaries that clients echo back, and hide duplicates already stored (#1984). See Sessions.#2405
11f87b5Thanks @threepointone! - Context blocks can setwhenChanged: "remind"to send changes as a reminder after the cached prompt instead of rewriting it. See Context.#2399
cbb859bThanks @threepointone! - Sub-agent broadcasts make at most one root call, and none when no client would receive them. See Sub-agents.#2398
d44b67dThanks @threepointone! - Sub-agents no longer sync root-owned host jobs, which could fail a facet's first call after restart. See Sub-agents.#2400
498bc29Thanks @threepointone! - Fix WebSocket connections to sub-agents nested more than one level deep. See Sub-agents.#2344
a91f669Thanks @threepointone! -useAgentChatlets the server snapshot repair a scrambled cross-tab or resumed assistant message instead of keeping it until reload. See Chat agents.#2361
7588509Thanks @threepointone! -useAgentChatcallsonToolCallonly after the stream ends, and only for tool calls still waiting on the client (#2195). See Client tools.#2238
c3a4010Thanks @mattzcarey! - Interfaces can now be used asPropsonAgent,AIChatAgent,Think, and routing helpers. See Routing.#2040
2afe0e0Thanks @AntoniTok! - Keep assistant messages and tool outputs attached to the correct turn when a provider reuses atoolCallId;resolveToolMergeIdis deprecated in favour ofreconcileMessages. See Chat agents.#2402
01d190eThanks @threepointone! -useAgentandAgentClientresolvereadyonly after the agent's state arrives, sostateis no longer brieflyundefined(#2268). See Client SDK.#2039
c658b83Thanks @justanotherbyte! -useAgentChatkeeps messages sent while disconnected when reconnecting, including Think transcripts, instead of erasing them (#1983). See Chat agents.#2322
677c022Thanks @threepointone! - Correct the documented default and unit ofChatRecoveryConfig.maxRecoveryWork. See Chat agents: recovery work units.#2401
218df4aThanks @threepointone! - Clients stop reconnecting after a sub-agent rejects a WebSocket, connection errors report every close that ends reconnection, and terminal rejections use close codes4000 + status(#2118). See Sub-agents.#2348
39361faThanks @threepointone! - Fix text appearing twice when reconnecting during a tool continuation. See Resumable streaming.#2340
3b278b2Thanks @threepointone! -onChatResponsestill fires, withrecovered: true, for a turn persisted just before a Durable Object reset (#2266, #1842). See Think lifecycle hooks.#2363
d72d343Thanks @threepointone! -runFiber()no longer callsonFiberRecovered()for work that already finished (#2305). See Durable execution.#2404
9d125c8Thanks @threepointone! - Addsession.mirror()to keep an in-memory transcript in sync with a session's change feed. See Sessions.#2236
14f7c6aThanks @mattzcarey! - Keep attachment references when a message that already contains attachment pointers is written back, so its media isn't garbage-collected. See Sessions.#2231
040458eThanks @mattzcarey! -updateMessage()detects unchanged messages from a stored content hash, cutting reads on large messages. See Sessions.#2392
4f26402Thanks @threepointone! - Settle approved tool calls that never ran once the conversation moves past them, so later turns don't send unresolved tool calls (#2382). See Human in the loop.#2387
9f70bc8Thanks @threepointone! - Messenger replies hold the thread lock and retain queued follow-ups during slow delivery; typing updates are serialized and settle before reply text arrives. See Think messengers.#2417
9906881Thanks @threepointone! - A regeneration interrupted by a restart now recovers on its own branch. See Multi-chat.#2403
6b5b4a0Thanks @threepointone! - FixuseAgentChatthrowing "Maximum update depth exceeded" during long streamed answers (#2217). See Chat agents.#2366
aaba6cbThanks @ben-reitz! - WithstoreTools: true, oversized tool payloads are recorded with base64 data summarized instead of being dropped. See Observability.#2343
a2f6f94Thanks @threepointone! - Harden transient chat recovery across Think and AI Chat, including retry budgeting, cancellation, terminal error delivery, and recovery after restarts. See theagents/chatrecovery helpers.#2024
310c343Thanks @cjol! -deleteSubAgentnow closes the sub-agent's direct client connections, so late messages can't recreate it (#2003). See Sub-agents.#2339
1edc989Thanks @threepointone! - Truncate older tool results after model conversion sotoModelOutputand provider-executed tools keep valid outputs (#2014). See Sessions.#2272
5dbf6c2Thanks @mattzcarey! -withX402ClientenforcesmaxPaymentValueagainst the payment requirement selected for signing, before signing or retrying the tool call. See Pay from Agents SDK.vercel/ai (ai)
v7.0.127Compare Source
Patch Changes
158a718: feat(ai): select and rank eligible deferred tools via 'search()' callback in tool searchbb8d33e: fix(ai): cancel merged UI message streams when the consumer disconnects284dc11: fix(ai): accept unchanged tool approval inputs created in another JavaScript realmba8afe9: feat(ai): add a configurable maxResults for number of tools returned in tool searchd1bb9e8]nuxt-modules/og-image (nuxt-og-image)
v6.10.3Compare Source
🐞 Bug Fixes
View changes on GitHub
v6.10.2Compare Source
🐞 Bug Fixes
View changes on GitHub
pnpm/pnpm (pnpm)
v10.34.6Compare Source
Patch Changes
e7888e5:pnpm self-updatenow resolves and verifies pnpm through registry, authentication, proxy, and TLS settings from trusted non-project configuration. Project configuration and the default project pnpmfile can no longer redirect the pnpm download or disable engine identity verification.46bc7c9: pnpm no longer tells you to update itself with Corepack or withpnpm add -g:pnpm self-update, or the standalone install script when pnpm is running under Corepack. It used to suggestcorepack use pnpm@<version>, orpnpm add -g pnpm/pnpm add -g @pnpm/exewhen pnpm was not installed by the standalone script — butpnpm add -grefuses to install pnpm and points atpnpm self-updateanyway, and@pnpm/exeis not published for pnpm v12 or newer, where the unscopedpnpmpackage is itself the native executable.pnpm self-updateunder Corepack now points at the standalone install script too, instead of telling you to update pnpm with Corepack.46bc7c9: Updatedadm-zipto v0.6.0, which fixes a memory-exhaustion vulnerability where a crafted ZIP file could make it allocate 4 GB of memory.adm-zipis used to extract the Node.js, Bun, and Deno archives that pnpm downloads on Windows.Updated the embedded Node.js release keys to the current canonical
nodejs/release-keyslist.Updated the embedded npm registry signing keys to the set currently advertised by npm.
702ad5f: Update the embedded Node.js release keys with the new key added to nodejs/release-keys (Stewart X Addison,655F3B5C1FB3FA8D1A0CA6BDE4A7D232B936D2FD).Platinum Sponsors
Gold Sponsors
vuejs/language-tools (vue-tsc)
v3.3.12Compare Source
language-core
@pluginscompiler options (GHSA-vgrw-xjpj-wh8r) - Thanks to @serkodev!defineModel(#6210) - Thanks to @KazariEX!.value(#6181)vueCompilerOptions.pluginsinstead of merging (#6208)vueCompilerOptions.pluginson resolve (#6125) - Thanks to @camonunez!$eventin compound event handlers (#6193) - Thanks to @serkodev!defaultslot name for barev-slot(#6190)component-meta
tsc
typescript-plugin
vscode
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.