chore(deps): update all non-major dependencies - #2366
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub. |
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 3, 2026 20:01
8b00c18 to
8697fd0
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 4, 2026 03:39
8697fd0 to
6309df4
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 4, 2026 08:51
6309df4 to
363b896
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 4, 2026 16:18
363b896 to
aec8bde
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 5, 2026 03:08
aec8bde to
429e597
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 5, 2026 07:05
429e597 to
9c8b91d
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 5, 2026 08:06
9c8b91d to
d163986
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 5, 2026 12:05
d163986 to
a78fbfd
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 5, 2026 14:11
a78fbfd to
0dc735b
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 5, 2026 20:04
0dc735b to
b06f487
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 5, 2026 20:53
b06f487 to
bdd3966
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 6, 2026 03:11
bdd3966 to
93db820
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 6, 2026 07:31
93db820 to
e5006bb
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 6, 2026 12:59
e5006bb to
afdf943
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 6, 2026 19:42
afdf943 to
d9c05b6
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 6, 2026 22:36
d9c05b6 to
ab504f2
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
August 7, 2026 02:40
ab504f2 to
d9d634f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^4.0.37→^4.0.42^2.0.22→^2.0.26^0.5.1→^0.6.0^1.2.11→^1.2.12^1.2.92→^1.2.93^3.4.0→^3.4.1^1.16.0→^1.17.0^1.3.2→^1.3.3^0.18.0→^0.18.1^2.5.5→^2.5.9^7.7.1→^7.8.0^0.6.0→^0.6.1^3.7.6→^3.8.0^3.5.40→^3.5.41^7.0.48→^7.0.54^13.0.2→^13.0.3^0.29.4→^0.30.8^2.23.0→^2.24.0^0.5.29→^0.5.30^6.7.5→^6.7.611.18.0→11.20.0^3.0.446→^3.0.448^4.4.1→^4.4.2^3.5.40→^3.5.41Release Notes
vercel/ai (@ai-sdk/gateway)
v4.0.42Compare Source
Patch Changes
7aeab10: chore(provider/gateway): update gateway model settings files2b60826]v4.0.41Compare Source
Patch Changes
53c326e: chore(provider/gateway): update gateway model settings filesd765f82: Export the Gateway embedding and image model ID types.1bec07d]v4.0.40Compare Source
Patch Changes
160ccdb]v4.0.39Compare Source
Patch Changes
79e133c]v4.0.38Compare Source
Patch Changes
fb6d2f8: chore(provider/gateway): update gateway model settings filesvercel/ai (@ai-sdk/mcp)
v2.0.26Compare Source
Patch Changes
2b60826]v2.0.25Compare Source
Patch Changes
1bec07d]v2.0.24Compare Source
Patch Changes
160ccdb]v2.0.23Compare Source
Patch Changes
79e133c]comarkdown/comark (@comark/nuxt)
v0.6.0: @comark/react v0.6.0Compare Source
nuxt/eslint (@nuxt/eslint)
v1.17.0Compare Source
🚀 Features
🐞 Bug Fixes
View changes on GitHub
nuxt/scripts (@nuxt/scripts)
v1.3.3Compare Source
🐞 Bug Fixes
View changes on GitHub
nuxt-modules/mcp-toolkit (@nuxtjs/mcp-toolkit)
v0.18.1Compare Source
What's Changed
Bug Fixes 🐞
Dependency Updates 📦
Full Changelog: https://github.com/nuxt-modules/mcp-toolkit/compare/@nuxtjs/mcp-toolkit@0.18.0...@nuxtjs/mcp-toolkit@0.18.1
vuejs/core (@vue/compiler-sfc)
v3.5.41Compare Source
Bug Fixes
vercel/ai (ai)
v7.0.54Compare Source
Patch Changes
a6b17a2: AllowToolLoopAgentprepareCallcallbacks to read and override the top-levelreasoningoption.5615eb7: AdddefaultInstructionsMiddlewarefor applying default language model instructions while preserving call-level overrides.36a3ff6: Preserve preceding assistant messages when regenerating a response.v7.0.52Compare Source
Patch Changes
3836a85: Skip re-validating tool input for terminal output-available UI message parts.1bec07d]53c326e]d765f82]v7.0.51Compare Source
Patch Changes
160ccdb]v7.0.50Compare Source
Patch Changes
79e133c: async APIs for generateVideo (poll, webhook)Adds an asynchronous start/status flow to the experimental video model
interface (
VideoModelV4): models may now implementdoStart,doStatus,and
handleWebhookOptioninstead of (or in addition to)doGenerate, andexperimental_generateVideoacceptspollandwebhookoptions toorchestrate completion via polling or webhooks. Polling configuration can use
a custom delay implementation for durable workflow compatibility.
da64b51: feat(code-mode): simplify tool caller configurationUpdated dependencies [
79e133c]v7.0.49Compare Source
Patch Changes
fb6d2f8]WiseLibs/better-sqlite3 (better-sqlite3)
v13.0.3Compare Source
What's Changed
Full Changelog: WiseLibs/better-sqlite3@v13.0.2...v13.0.3
vercel/eve (eve)
v0.30.8Compare Source
Patch Changes
e6f4808: Add a singleeve add linearflow that installs and configures both the Linear Channel and Linear MCP connection.f51f866: Tools can now use async generators to stream preliminary output snapshots. eve publishes local snapshots asaction.partialevents before the finalaction.result, and the default client reducer exposes provisional output withpartial: true.v0.30.7Compare Source
Patch Changes
e5c9191: Add experimental agent messaging behindexperimental.subagentPersistentSessionsinagent.ts. Opted-in agents keep delegated children alive after they answer: each child is owned by a lifecycle handle, settles every turn with an explicit outcome carrying its per-turn token usage, and parks instead of terminating. The parent's subagent tools gain anagentIdparameter to continue a parked child, discoverable from a per-model-call<agents>system injection that lists only parked (resumable) children. An omitted, empty, or unknownagentIdstarts a fresh child; continuing a child that is still starting or working fails withAGENT_BUSY. Without the opt-in, children keep running as one-shot tasks. The subagent tool input schema no longer includes the unuseddescriptionfield.bd21332: Cancelling a turn with running delegated children no longer leaks their handles as permanentlyrunning. The cancellation epilogue now parks each abandoned child as"(cancelled)", so cancelled children stay resumable and later cancellations no longer stall retrying already-dead children.1758161: Add guided GitHub channel setup througheve add channel/github. The flow provisions a Vercel Connect GitHub App, routes verified webhooks, scaffolds the channel, and explains how to install and use the app.56de47b: Show far more of what local traces record ineve traces: span rows carry inline token/cost/tool chips, the header aggregates models, token totals, cost, and errors, and two new flags expose everything else —--verboseexpands every span with all attributes and events, and--jsondumps the full trace machine-readably.v0.30.6Compare Source
Patch Changes
7fa4d36: Accept unmodeledSKILL.mdfrontmatter when importing a skill from another runtime. These fields are no-ops in eve.v0.30.5Compare Source
Patch Changes
5ee18e2: Prevent successful localeve invokecommands from logging a spurious Workflow queue 503 while their temporary development server shuts down.d8fc092: Format registry search results as concise, width-aware entries and limit searches to 10 matches by default. Use--limitto request up to 100 results.557000b: Add skills.sh as a built-in registry, soeve registry search --registry @skills <query>andeve add @skills/<skill>work without project configuration.1953d20: Prevent sandbox abort listeners from accumulating across repeated operations in a turn.7086776: Route session controls and follow-up messages through one durable command inbox shared by stable session IDs and rekeyable channel addresses.v0.30.4Compare Source
Patch Changes
fc87d23: Dev runtime snapshots no longer copy the.workflow-vitesttest cache. Inworkspaces that had run integration tests, this directory was duplicated into
every generation under
.eve/dev-runtime/snapshots— tens of megabytes perrebuild that nothing at dev runtime reads.
v0.30.3Compare Source
Patch Changes
601fb13: Allow just-bash sandboxes to compose a custom filesystem around eve's durable, session-owned workspace.c8bd9c0: Allow declared local subagents to mount extensions under their ownextensions/directory. Contributions, configuration, and overrides are scoped to that subagent and do not extend the root agent.279b5e6: Use compatible POSIX search fallbacks in sandboxes whosergimplementation lacks the options required by eve, and surface command errors instead of reporting them as empty results.c10ca06: Allow dynamic subagents to declare compile-timebuild.externalDependencies, so their authored modules can safely use packages that must remain external before runtime resolution.95b4183: Configure new Linear connectors to receive only Agent Session webhook events, avoiding unrelated default Linear webhook deliveries.95b4183: Add guided Linear Agent channel setup througheve add channel/linear-agent. The flow provisions a Vercel Connect Linear app, routes verified Agent Session events, scaffolds the channel, and explains how to install and use the agent in Linear.v0.30.2Compare Source
Patch Changes
512808c: Allow agents to select Exa or Parallel for the built-inweb_searchtool by exportingwebSearch({ provider })fromagent/tools/web_search.ts. Parallel remains the default for AI Gateway models.v0.30.1Compare Source
Patch Changes
dae6f73: Upload Vercel sandbox workspace seed files in one compressed SDK request instead of one request per file, substantially reducing fresh template build times for large workspaces.v0.30.0Compare Source
Minor Changes
f43b22d:localDev()now grants the synthetic local principal based on the deployment (aneve devorvercel devprocess) instead of the request URL host, so a requestHostheader can no longer obtain local-dev access on a self-hosted server. The previously exportedisLoopbackRequesthelper is removed. The default eve channel now falls back to[vercelOidc(), localDev(), placeholderAuth()], which keeps local dev working and rejects all production traffic.Patch Changes
021dbbf: Add/newas an alias of/clearin the eve dev TUI. It clears model-message history while preserving the current session and its durable resources.136749f: MakeCtrl+Ccooperatively cancel or steer a running turn likeEscin the eve dev TUI. At the idle prompt, the firstCtrl+Cnow shows an exit warning and a second consecutive press exits.13420ab: Allow dynamic subagent resolvers to returndefineRemoteAgent(...). Session and turn selections can now conditionally expose a remote deployment and change its runtime connection settings.ee50ae7: Prevent the dev TUI from duplicating setup panels when an integration setup error includes multiline command output.e1cd7b7: Move eve's internal integration catalog from the Vercel npm scope to@eve/catalog.56651ee: Update eve's bundled Workflow SDK packages to the latest 5.0.0 beta releases, keeping the core runtime and workflow worlds aligned.v0.29.5Compare Source
Patch Changes
c0dc572: Rename the TUI/newcommand to/resetso session reset uses the same name across the client, HTTP, channel, and TUI APIs.3dce30a: Add manual session compaction through custom-channel helpers, the eve HTTP client, and theeve devTUI's/compactcommand. Compaction preserves the session, queues behind an active turn, and does not send synthetic model input.910805e: Make a singleEsccancel the running turn in the eve dev TUI when no message is queued. Queued messages still useEscto steer the oldest message into the next turn.9c51755: Connection search and discovered connection tools now use the samedefineDynamicanddefineToolpipeline as authored tools. Dynamic tool maps now reject entries that omitdefineToolinstead of accepting unsupported raw objects.84aa671: Clarify the dev TUI’s/addflow with consistent integration categories and category-specific browsing labels. MCP connections are now named explicitly, and the flow more clearly explains channels, extensions, and observability integrations.0c28eb7: Allow declared subagents to exportdefineDynamicfromagent.ts. Session and turn resolvers can now return an agent configuration to expose it or nil to omit it from direct and Workflow delegation.f3bb60d: Add manual session-context clearing through custom-channel helpers, the eve HTTP client, and theeve devTUI's/clearcommand. Clearing removes model-message history while preserving the session, agent configuration, durable state, limits, and sandbox.ac7d3c6: Add/cancelto the eve dev TUI. The command cooperatively cancels a running turn from either the live streaming input or the idle prompt while preserving the session and settled context.atinux/nuxt-auth-utils (nuxt-auth-utils)
v0.5.30Compare Source
compare changes
🩹 Fixes
app:suspense:resolvehook (#505)🏡 Chore
❤️ Contributors
nuxt-modules/og-image (nuxt-og-image)
v6.7.6Compare Source
🐞 Bug Fixes
View changes on GitHub
pnpm/pnpm (pnpm)
v11.20.0: pnpm 11.20Compare Source
Minor Changes
Security fix. Affects projects using
namedRegistrieson pnpm 11.1.0–11.19.x. It is semi-breaking for those projects — see "If you use named registries" below.The lockfile recorded no marker for which registry a package came from. Packages were keyed by
name@versionalone, and entry lookup went throughrefToRelative(ref, name), so a dependency you declared against one registry could be satisfied by an entry that was actually resolved from another. When two registries served the same name and version, both collapsed onto a singlepackages:entry and whichever resolved first decided the tarball every consumer got.That is a package-substitution risk: a package you expect from your private registry could be installed from a different registry that publishes the same name and version, and the lockfile recorded nothing that would let you tell.
Packages resolved from a named registry are now recorded under registry-qualified keys (
<name>@<registryName>:<version>, e.g.foo@work:1.0.0), so each registry gets its own entry and the lockfile pins which one a dependency came from.The lockfile format version is unchanged. Registry-qualified keys appear only for packages resolved from a named registry, so a project that does not use
namedRegistriessees no difference, and older pnpm versions keep reading the file.If you use named registries
Your next non-frozen install re-keys those entries, which shows up as a lockfile diff. Commit it — that diff is the fix being applied. Review it: an entry that moves to a registry you did not expect is worth investigating.
Everyone working on the project should be on this version or newer before you do. An older pnpm reads the re-keyed lockfile fine — frozen installs are unaffected — but it does not produce registry-qualified keys itself, so any install that updates the lockfile writes those entries back to the old shape, and the next install on a current pnpm re-qualifies them. The result is a lockfile that flips back and forth, and while it is in the old shape the project is exposed again. Because the lockfile format version is deliberately unchanged, pnpm cannot detect this and warn you about it.
There is no setting to keep the old behavior: the old shape is the vulnerability.
Tarball URLs that follow the standard registry layout are no longer written to the lockfile for named-registry packages; they are recomputed from the
namedRegistriessetting on demand.To use named registries, map your aliases in
pnpm-workspace.yaml:New built-in
npmjs:aliasnpmjs:now resolves tohttps://registry.npmjs.org/with no configuration, alongside the existinggh:alias for GitHub Packages. It pins a dependency to the public registry even whenregistrypoints elsewhere, such as an internal proxy:{ "dependencies": { "left-pad": "npmjs:^1.3.0" } }npm:cannot do this — it is the alias protocol (npm:<name>@<range>) and resolves through whateverregistrypoints at.If you mirror or proxy npmjs, point the alias at your mirror:
Built-in registry URLs are also the prefixes a lockfile's recorded tarball URL is matched against when pnpm verifies a package. Without the override, an entry whose tarball URL is on
registry.npmjs.orgis verified against the public registry rather than your mirror. This only affects lockfiles that record such URLs — a canonical URL for your configured registry is omitted from the lockfile and unaffected — and only when a tarball-URL,minimumReleaseAge, ortrustPolicycheck runs. Overriding the alias is the same escape hatch GHES users already have forgh.Every alias the lockfile references must stay in
namedRegistries: reading an entry whose alias is gone fails withERR_PNPM_MISSING_NAMED_REGISTRYrather than silently falling back to the default registry, since that would fetch a different package. Renaming an alias re-resolves the packages that used it.Named registry aliases that shadow a reserved dependency specifier prefix (
file,link,workspace,runtime,npm,jsr, ...) are now rejected withERR_PNPM_RESERVED_NAMED_REGISTRY_NAMEinstead of being silently shadowed by the corresponding resolver.pnpm licensesandpnpm sbomnow keep the two artifacts apart as well: license records carry the registry alias, and SBOM components carry the purlrepository_urlqualifier.Patch Changes
An empty
http-proxy,https-proxy,proxy, orno-proxyvalue — from the.npmrc,pnpm-workspace.yaml, the CLI, or theHTTP_PROXY/HTTPS_PROXY/PROXY/NO_PROXYenvironment variables — no longer fails the install withERR_PNPM_INVALID_PROXY. Empty settings read as unset, so a shell exportingHTTP_PROXY=disables the proxy, and an emptyproxy=in the.npmrcno longer suppressesHTTPS_PROXY#13533.proxy=falsein the.npmrcorproxy: falseinpnpm-workspace.yamlnow turns proxying off instead of being read as a proxy host namedfalse.falseandnullonhttps-proxy/http-proxy/no-proxyread as unset, and on the command line they are ordinary host names, since a flag carries its value verbatim.The env lockfile no longer pins
@pnpm/exealongsidepnpmwhen the wanted pnpm version is 12 or newer. From v12 the unscopedpnpmpackage is itself the native executable, so@pnpm/exeis not published for it and resolving it would fail. The engine identity check now verifies the native binary through whichever package ships it.lexCompareandnerfDartare now published as@pnpm/text.ordinal-comparatorand@pnpm/config.registry-auth-key. Use these instead of@pnpm/util.lex-comparatorand@pnpm/config.nerf-dart.Fixed the order in which pnpm matches a lockfile's recorded tarball URL against known registry URLs. Two registry URLs of equal length were previously ordered arbitrarily, so which one a tarball URL matched could differ between runs.
Dependency resolution is faster: package metadata is now filtered once per packument instead of once per dependency edge when
minimumReleaseAgeis active, and parsed semver versions and ranges are reused instead of re-parsed on every comparison.Security:
pnpm rebuildnow refuses a lockfile whosepackageskey carries a path traversal in the package name (e.g.../../../escaped@1.0.0), instead of running that package's lifecycle scripts and linking its bins in a directory outside the virtual store. Such a name is rejected withERR_PNPM_INVALID_DEPENDENCY_NAME.Platinum Sponsors
Gold Sponsors
v11.19.0: pnpm 11.19Compare Source
Minor Changes
pnpm loginno longer requires an interactive terminal when the registry supports web-based login: without a TTY it prints the authentication URL (skipping the QR code and the "Press ENTER to open the URL in your browser" prompt) and polls the registry until the browser approval completes. Only the classic username/password login still fails withERR_PNPM_LOGIN_NON_INTERACTIVEin a non-interactive terminal.The
save-prefixsetting now accepts=: newly added dependencies are saved with an explicit=operator (=1.2.3) instead of the setting being silently treated as the default^.Patch Changes
allowBuildsentries can now approve git-hosted packages that pnpm downloads as a tarball, such asgithub:dependencies (which are fetched fromcodeload.github.comrather than cloned), by their repository URL without the resolved commit hash. This matches the hashlessgit+matching already supported for cloned git dependencies. For example:This approves the package whether pnpm clones it or downloads a tarball, so the entry no longer has to be updated every time the pinned commit changes. GitLab and Bitbucket tarball downloads are matched the same way. Approving or denying a specific resolved commit by its full tarball dep path continues to work.
pnpm outdated --include-github-actionsno longer blocks on an interactive git credential prompt when a workflow uses a private action repo.Prevented
minimumReleaseAgefrom replacinglatestwith a SemVer-greater version than the registry tag target #13034.Fixed empty
bundledDependenciesandbundleDependenciesarrays causing nondeterministic lockfile changes. See #13123.The install summary no longer prints
(X is available)when the registry'sdist-tags.latestis still held back by the activeminimumReleaseAgepolicy. The hint only ever names the actual latest tag, so an immature latest suppresses the hint instead of advertising the version pnpm just refused to install #11698.pnpm updatekeeps the explicit=operator of an exact version pin: a dependency saved as=3.5.1now updates to=3.5.2instead of the bare3.5.2. See #13168.Preserve a workspace dependency's
link:entry when a run does not target it — e.g.pnpm update <other-pkg>(with or without--recursive), or a plain install after a root/catalog dependency change — withinjectWorkspacePackages, instead of spuriously rewriting it to a peer-suffixedfile:protocol. See #10433.Workspace dependencies declared with a relative path (e.g.
"foo": "workspace:../foo") are no longer silently dropped from the workspace projects graph, so--filterselection and the topological order of recursive commands take them into account.Platinum Sponsors
<Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.