chore(deps): update npm minor and patch dependencies - #10350
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): update npm minor and patch dependencies#10350renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Contributor
|
Superagent didn't find any vulnerabilities or security issues in this PR. |
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ❌ Deployment failed View logs |
loopover-ui | 5bcb4d4 | Aug 23 2026, 10:37 AM |
|
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 10, 2026 13:04
5b9e1bb to
6120b8c
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 10, 2026 17:56
6120b8c to
2b9cf39
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 10, 2026 22:16
2b9cf39 to
0c5024c
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 11, 2026 01:17
0c5024c to
73830c8
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 11, 2026 04:50
73830c8 to
53cdbf8
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 11, 2026 21:17
53cdbf8 to
2b3206d
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 12, 2026 05:56
2b3206d to
7e07ff7
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 12, 2026 15:17
7e07ff7 to
6d1860c
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 16, 2026 11:18
6d1860c to
8246cab
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 16, 2026 12:40
8246cab to
4bf978f
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 16, 2026 17:38
4bf978f to
c35fbf6
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 16, 2026 20:59
c35fbf6 to
e67f676
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 17, 2026 02:56
e67f676 to
264b992
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 17, 2026 11:04
264b992 to
dbc7abc
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 17, 2026 15:48
dbc7abc to
6915bec
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 22, 2026 11:58
6915bec to
306b030
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 22, 2026 19:03
306b030 to
a9899e7
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 22, 2026 21:09
a9899e7 to
ab8a2fb
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 23, 2026 02:53
ab8a2fb to
a9d04e0
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 23, 2026 06:50
a9d04e0 to
8b4e40a
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 23, 2026 10:34
8b4e40a to
5bcb4d4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.3.218→^0.3.237^1.1.0→^1.4.0^0.18.8→^0.22.0^5.20260724.1→^5.20260820.1^2.0.11→^2.1.11.2.1→1.3.21.1.4→1.8.02.7.7→2.15.11.29.0→1.30.0^7.0.6→^7.0.70.9.1→0.13.0^1.2.18→^1.2.20^1.1.21→^1.1.23^1.1.13→^1.1.15^1.2.4→^1.2.6^1.3.9→^1.3.11^1.1.18→^1.1.20^2.3.5→^2.3.7^1.1.21→^1.1.23^2.1.22→^2.1.24^1.1.21→^1.1.23^2.1.13→^2.1.15^1.1.22→^1.1.24^1.2.20→^1.2.22^1.1.21→^1.1.23^1.1.14→^1.1.16^1.4.5→^1.4.7^1.2.16→^1.2.18^2.3.5→^2.3.7^1.1.13→^1.1.15^1.4.5→^1.4.7^1.3.1→^1.3.3^1.3.5→^1.3.7^1.1.19→^1.1.21^1.1.16→^1.1.18^1.1.17→^1.1.19^1.2.14→^1.2.16^0.9.59→^0.9.63^10.67.0→^10.70.0^10.67.0→^10.70.0^1.170.18→^1.170.31^1.168.32→^1.168.48^1.168.23→^1.168.34^8.20.0→^8.23.1^19.2.17→^19.2.18^19.2.3→^19.2.4^7.7.1→^7.8.0^4.1.10→^4.1.11^0.19.0→^0.21.0^0.28.1→^0.28.2^10.8.0→^10.8.1^0.5.3→^0.5.4^16.12.1→^16.14.5^15.2.0→^15.3.0^17.7.0→^17.11.0^4.12.31→^4.13.3^4.12.34→^4.13.3^1.4.2→^1.5.0^12.42.2→^12.43.0^8.9.0→^8.9.210.9.8→10.9.9^8.22.0→^8.23.0^1.61.1→^1.62.1^1.409.3→^1.418.5^5.46.1→^5.49.1^7.82.0→^7.85.0^4.12.2→^4.12.3^2.0.7→^2.0.8^7.5.21→^7.5.224.22.5→4.23.12^4.23.1→^4.23.12^2.10.6→^2.10.11^8.65.0→^8.67.0^8.1.5→^8.2.2^4.1.10→^4.1.11^0.20.8→^0.26.12^4.115.0→^4.124.0^4.114.0→^4.124.0^8.21.1→^8.21.3Dependency PRs must keep
npm run test:cipassing. The 97% coverage requirement is enforced as Codecov patch coverage on changed lines (codecov/patch), so dependency-only bumps satisfy it without new tests.GitHub Actions updates must remain SHA-pinned.
Renovate is the sole dependency and security-update bot for this repo; GitHub Dependabot security updates are disabled to avoid duplicate PRs (e.g. the two hono advisory PRs).
Release Notes
anthropics/claude-agent-sdk-typescript (@anthropic-ai/claude-agent-sdk)
v0.3.237Compare Source
v0.3.236Compare Source
PostToolUsehooks can returnhookSpecificOutput.classifierContext, a short host-asserted note about a tool call's result that the auto mode permission classifier reads alongside that resultv0.3.235Compare Source
v0.3.234Compare Source
bypass_permissions_disabledfromExitReasontype; the value was never emitted — TypeScript consumers with an explicitcasebranch get a compile error on upgrade (runtime unaffected)ApiKeySourcetype to include the valuessystem/initactually reports (ANTHROPIC_API_KEY,apiKeyHelper,/login managed key,none)vcs_state_changedevents report the directory the shell finished in (an innercdis reflected)origininjected by the host may declare the sending session's permission class (fromMode) so a same-class message is delivered to a recipient that runs without askingSDKSystemMessage(system/init) gains an optionaleffortfield: the session's applied effort level, ornullwhen none is sent. Set on Remote Control bridge init framesv0.3.233Compare Source
TaskCreate/TaskGet/TaskUpdate/TaskList,TodoWrite) are no longer in the default tool surface on Opus 4.8, Sonnet 5, Fable 5, Mythos 5, and newer models; name them in thetoolsoption or reference them inallowedTools(or setCLAUDE_CODE_ENABLE_TODO_TOOLS=1) to keep themv0.3.232Compare Source
tool_resultframes whose result carries_metanow emittool_use_resultas{ content, _meta }(matching main-loop frames) instead of a bare value/contextresult messages now carry a structuredcontext_usagepayload (newSDKContextUsagetype), so consumers can render the context-usage card without parsing the markdown tablevcs_state_changedevents now populate thebranchfield for push operations, sourced from the pushed refv0.3.231Compare Source
v0.3.229Compare Source
terminal_slash_commandsto the system init message so Remote Control clients can hide terminal-oriented commandsterminal_reason"api_error"instead of"image_error";StopFailureerror_detailsis"request_body_over_limit: …"v0.3.228Compare Source
AgentOutput):usage.output_tokens_detailsis now carried throughv0.3.227Compare Source
v0.3.226Compare Source
v0.3.225Compare Source
v0.3.224Compare Source
crossSessionInboundanddialogExpirysettings: cross-session messages sent to a session running with bypassed permissions are held for your approval, and messages to other sessions auto-deliversubkind: 'peer-send-message'to thetask-notificationmember ofSDKMessageOrigin, marking a notification raised by a cross-sessionSendMessagesource: 'archive'plugin config variant toSettings, withurland optionalsha256, for installing plugins from a zip over HTTPSSettings:decode: 'jwt'withmaskClaims,extract/onExtractNoMatchonenvVars, andawsPairs/sigv4for AWS SigV4 re-signing/resumeno longer cross projectsv0.3.223Compare Source
resumeDropsTurnoption: withresumeSessionAt, declares the turn a truncating resume intends to drop; the CLI refuses the resume if anything else would be discardedapi_error_status: 529, so SDK consumers can detect overload terminations structurally instead of matching message text-p/ SDKquery()withoutcanUseTool) now emitssystem/permission_deniedstream events when a tool call is auto-deniedusagevsmodelUsageon stream-json results:usageis main-loop-only and per-turn;modelUsageis cumulative, covers all query-pipeline calls, and is the field for cost accountingv0.3.222Compare Source
query({ sessionStore, resume })not carrying usersettings.json(apiKeyHelper,env,hooks,permissions) into the resumed subprocessv0.3.221Compare Source
skillsoption validation: malformed names (delimiters or control characters) and wildcard-form names are rejected with a clear error; useskills: 'all'to enable every skillmcpServersoption not being connected before the first turn, which caused the model to emit tool calls as literal textv0.3.220Compare Source
v0.3.219Compare Source
cancel_queuedto the interrupt control request (capabilityinterrupt_cancel_queued_v1): cancels queued and pending-dispatch messages alongside the abortfast_mode_disabled_reasonto result and init messages so SDK hosts can explain why fast mode is offDirectoryAddedlifecycle hook event to the control protocol, fired when a new working directory is registered mid-sessionfast_mode_statefrom the spawn-time model after a model switchsandbox.network.strictAllowlistto SDK settings types for deterministically denying non-allowlisted hosts in sandboxed commandsworkflowSizeGuidelineto SDK settings types for setting the advisory dynamic-workflow size guidelinecloudflare/puppeteer (@cloudflare/puppeteer)
v1.4.0Compare Source
v1.3.0Compare Source
What's Changed
Full Changelog: cloudflare/puppeteer@v1.2.0...v1.3.0
v1.2.0Compare Source
What's Changed
Full Changelog: cloudflare/puppeteer@v1.1.0...v1.2.0
cloudflare/workers-sdk (@cloudflare/vitest-pool-workers)
v0.22.0Compare Source
Minor Changes
#13830
49d4e00Thanks @penalosa! - Mocking requests with MSW in Worker tests now requires MSW >= 2.14@cloudflare/vitest-pool-workerspreviously shipped internal shims to make MSW work inside the workerd runtime. MSW 2.14 added that support natively, so those shims have been removed.If you mock requests with MSW in your Worker tests, make sure you're on MSW
>= 2.14; older versions will no longer intercept requests. You can keep usingsetupServer()frommsw/node, or adopt the official@msw/cloudflareintegration viasetupNetwork(). See the updatedrequest-mockingexample fixture for the recommended pattern.Patch Changes
#15211
bc5726bThanks @nithin42! - Honoraccess.devwhen running Workers with@cloudflare/vitest-pool-workers, soctx.access.getIdentity()returns the configured identity just as it does withwrangler dev.#15156
3ddd3ceThanks @dario-piotrowicz! - Fix module resolution for relativerequire()inside CJS deps when the project path contains spacesWhen a project lives under a directory with a space in its name, externalized CommonJS dependencies that use relative
require()calls (e.g.require("./lib/impl.js")) would fail with "No such module" becauseworkerdpreserves URL encoding in the module name. Encoded module paths are now handled deterministically before CommonJS resolution without altering literal percent sequences.#15150
2cf3143Thanks @kkkhs! - Restore typedinject()keys incloudflareTest()pool optionsinject()insidecloudflareTest()options again infers the value type from the keys you declare in your VitestProvidedContext, and reports misspelled keys. For keys that are only provided at runtime, pass an explicit type argument, e.g.inject<number>("myPort").#15232
8777180Thanks @vicb! - Bumpcapnp-esto 0.0.16.#15185
1f79aceThanks @jamesopstad! - Use a fixed default compatibility date rather than the current dateWhen no compatibility date was set, Wrangler, C3 and the Vitest pool all defaulted to the current date.
workerdonly accepts a compatibility date up to 7 days beyond its own release, so whenever aworkerdrelease was delayed the default could get ahead of the runtime that had been installed, and local development would fail to start.The default is now fixed at the release date of the
workerdversion that ships with each release, which leaves a week of headroom and updates asworkerdis upgraded.@cloudflare/vite-pluginpreviously inlined the date at which it was built. It now shares the same default.Updated dependencies [
bc5726b,1277a72,ba54f0d,6529f0c,b7422b0,186339c,4f922dc,4d74b8d,2e0c962,1f79ace,49f73de,7cee278,8777180,265256a,1f79ace,f431166,8fb2b87,75cf407]:v0.21.3Compare Source
Patch Changes
b8fd112,f0f2054,339509d]:v0.21.2Compare Source
Patch Changes
#15123
d0c976cThanks @dependabot! - WidenWorkerPoolOptionsContext.injecttype to avoidProvidedContextmismatchPreviously, calling
inject()insidecloudflareTest()pool options could fail with a type error when your project'sProvidedContextaugmentation wasn't visible to the pool plugin. Theinjectparameter now accepts any string key and is generic (inject<T>(key)), defaulting tounknownwhen no type argument is provided. This lets you opt in to concrete types (e.g.inject<number>("port")) while avoiding the cross-copyProvidedContextmismatch that occurred when pnpm resolved separate virtual-store instances of vitest.#15148
0b82b15Thanks @jamesopstad! - Ignore anodejs_compatcompatibility flag that the compatibility date already enablesworkerd rejects a compatibility flag that its compatibility date enables by default, so a Worker configured with both a compatibility date of
2026-08-04or later andnodejs_compatfailed to start locally with "The compatibility flag nodejs_compat became the default as of 2026-08-04 so does not need to be specified anymore".The redundant
nodejs_compatandnodejs_compat_v2flags are now dropped when starting the runtime, which has no effect on the resulting Worker because the compatibility date enables both anyway.no_nodejs_compatandno_nodejs_compat_v2still switch Node.js compatibility off, and a flag specified alongside its own opt-out is left alone so that workerd still reports those as contradictory.#15123 [
d0c976c](https://redirect.githuConfiguration
📅 Schedule: (in timezone America/Phoenix)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.