Bump the npm_and_yarn group across 3 directories with 9 updates#534
Bump the npm_and_yarn group across 3 directories with 9 updates#534dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the npm_and_yarn group with 2 updates in the / directory: [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) and [express](https://github.com/expressjs/express). Bumps the npm_and_yarn group with 2 updates in the /apis/node directory: [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) and [express](https://github.com/expressjs/express). Bumps the npm_and_yarn group with 1 update in the /packages/proxy directory: [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai). Updates `ai` from 2.2.22 to 5.0.52 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/ai@5.0.52/packages/ai/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/ai@5.0.52/packages/ai) Updates `express` from 4.19.2 to 4.22.0 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/4.22.0/History.md) - [Commits](expressjs/express@4.19.2...4.22.0) Updates `body-parser` from 1.20.2 to 1.20.3 - [Release notes](https://github.com/expressjs/body-parser/releases) - [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md) - [Commits](expressjs/body-parser@1.20.2...1.20.3) Updates `cookie` from 0.6.0 to 0.7.1 - [Release notes](https://github.com/jshttp/cookie/releases) - [Commits](jshttp/cookie@v0.6.0...v0.7.1) Updates `nanoid` from 3.3.6 to 3.3.12 - [Release notes](https://github.com/ai/nanoid/releases) - [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md) - [Commits](ai/nanoid@3.3.6...3.3.12) Updates `path-to-regexp` from 0.1.7 to 0.1.12 - [Release notes](https://github.com/pillarjs/path-to-regexp/releases) - [Changelog](https://github.com/pillarjs/path-to-regexp/blob/master/History.md) - [Commits](pillarjs/path-to-regexp@v0.1.7...v0.1.12) Updates `qs` from 6.11.0 to 6.13.0 - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.11.0...v6.13.0) Updates `send` from 0.18.0 to 0.19.0 - [Release notes](https://github.com/pillarjs/send/releases) - [Changelog](https://github.com/pillarjs/send/blob/master/HISTORY.md) - [Commits](pillarjs/send@0.18.0...0.19.0) Updates `serve-static` from 1.15.0 to 1.16.2 - [Release notes](https://github.com/expressjs/serve-static/releases) - [Changelog](https://github.com/expressjs/serve-static/blob/master/HISTORY.md) - [Commits](expressjs/serve-static@v1.15.0...v1.16.2) Updates `ai` from 2.2.22 to 5.0.52 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/ai@5.0.52/packages/ai/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/ai@5.0.52/packages/ai) Updates `express` from 4.19.2 to 4.22.0 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/4.22.0/History.md) - [Commits](expressjs/express@4.19.2...4.22.0) Updates `ai` from 2.2.37 to 5.0.52 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/ai@5.0.52/packages/ai/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/ai@5.0.52/packages/ai) --- updated-dependencies: - dependency-name: ai dependency-version: 5.0.52 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: express dependency-version: 4.22.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: body-parser dependency-version: 1.20.3 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: cookie dependency-version: 0.7.1 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: nanoid dependency-version: 3.3.12 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: path-to-regexp dependency-version: 0.1.12 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: qs dependency-version: 6.13.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: send dependency-version: 0.19.0 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: serve-static dependency-version: 1.16.2 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: ai dependency-version: 5.0.52 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: express dependency-version: 4.22.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: ai dependency-version: 5.0.52 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 76149a1ce3
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "Codex (@codex) review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "Codex (@codex) address that feedback".
| "@braintrust/proxy": "workspace:*", | ||
| "@supabase/supabase-js": "^2.32.0", | ||
| "ai": "2.2.22", | ||
| "ai": "5.0.52", |
There was a problem hiding this comment.
Do not bump ai before migrating AIStream usage
This workspace still imports AIStream and AIStreamCallbacksAndOptions from ai in apis/node/src/anthropic.ts, but AI SDK v5 removed those legacy stream helpers. With this dependency installed, the node lambda typecheck/bundle will fail on missing exports before the package can build, so this needs to stay on the 2.x line or migrate the Anthropic stream wrapper to the v5 streaming APIs in the same change.
Useful? React with 👍 / 👎.
| "@opentelemetry/resources": "^2.1.0", | ||
| "@opentelemetry/sdk-metrics": "^2.1.0", | ||
| "ai": "2.2.37", | ||
| "ai": "5.0.52", |
There was a problem hiding this comment.
Keep ai compatible with trimStartOfStreamHelper
@braintrust/proxy still imports trimStartOfStreamHelper from ai in packages/proxy/utils/openai.ts, but the AI SDK v5 package no longer exports that helper. Any build of the proxy package (and consumers that bundle it) will fail resolving that import after this dependency bump, so either keep the existing v2 dependency or replace this helper before upgrading.
Useful? React with 👍 / 👎.
Bumps the npm_and_yarn group with 2 updates in the / directory: ai and express.
Bumps the npm_and_yarn group with 2 updates in the /apis/node directory: ai and express.
Bumps the npm_and_yarn group with 1 update in the /packages/proxy directory: ai.
Updates
aifrom 2.2.22 to 5.0.52Changelog
Sourced from ai's changelog.
... (truncated)
Commits
63d5f66Version Packages (#8895)930399bBackport: fix(ai): download files when intermediate file cannot be downloaded...85909a9Backport: chore(ai): update test message (#8875)c56822dBackport: fix(ai): updateuiMessageChunkSchemato satisfy the `UIMessageChu...6bd07dfVersion Packages (#8853)27645bbBackport: ExportparseJsonEventStreamanduiMessageChunkSchemafrom "ai" ...8b7f0d2Version Packages (#8843)9eef198Version Packages (#8831)20bca65Version Packages (#8799)4254096Version Packages (#8753)Maintainer changes
This version was pushed to npm by vercel-release-bot, a new releaser for ai since your current version.
Updates
expressfrom 4.19.2 to 4.22.0Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
Commits
49744ab4.22.0 (#6921)6e97452sec: security patch for CVE-2024-519996a23d34deps: use tilde notation forqs(#6919)8c12cdfdeps: qs@6.14.0 (#6909)7fea74fdeps: use tilde notation for certain dependencies (#6905)dac7a04chore: wider range for query test skip (#6513)997919bci: add node.js 24 to test matrix (#6506)36fb59cfix(ci): reordernpm isteps to fix ci for older node versions (#6336)3a5edfafix(ci): updated github actions ci workflow (#6323)52d9781fix(test): add test for method routes without paths #5955Updates
body-parserfrom 1.20.2 to 1.20.3Release notes
Sourced from body-parser's releases.
Changelog
Sourced from body-parser's changelog.
Commits
17529511.20.339744cfchore: linter (#534)b2695c4Merge commit from forkade0f3fadd scorecard to readme (#531)99a1bd6deps: qs@6.12.3 (#521)9478591fix: pin to node@22.4.183db46aci: fix errors in ci github action for node 8 and 9 (#523)9d4e212chore: add support for OSSF scorecard reporting (#522)Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for body-parser since your current version.
Updates
cookiefrom 0.6.0 to 0.7.1Release notes
Sourced from cookie's releases.
Commits
cf4658f0.7.16a8b8f5Allow leading dot for domain (#174)58015c0Remove more code and perf wins (#172)ab057d60.7.05f02ca8Migrate history to GitHub releasesa5d591cMigrate history to GitHub releases51968f9Skip isNaN9e7ca51perf(parse): cache length, return early (#144)d6f39b0Fix tests for old node6bb701fRemove failing scorecardMaintainer changes
This version was pushed to npm by blakeembrey, a new releaser for cookie since your current version.
Updates
nanoidfrom 3.3.6 to 3.3.12Release notes
Sourced from nanoid's releases.
Changelog
Sourced from nanoid's changelog.
Commits
aa9c399Release 3.3.12 versionb0036edBackport fix to CommonJS version too08a19a4Update test821dfedBackport pool breaking fix609646cFix CI37289ceRelease 3.3.11 version23690b7Fix CIc147962Fix RN supporta83734eMove to manually ESM/CJS dual packagebb12e8aRelease 3.3.10 versionUpdates
path-to-regexpfrom 0.1.7 to 0.1.12Release notes
Sourced from path-to-regexp's releases.
Commits
640e6940.1.12f01c26aMerge commit from fork0c711920.1.118f09549Add error on bad input valuesc827fce0.1.1029b96b4Add backtrack protection to parametersac4c234Update repo url (#314)bdb66350.1.9c4272e4Allow a non-lookahead regex (#312)51a19550.1.8Updates
qsfrom 6.11.0 to 6.13.0Changelog
Sourced from qs's changelog.
... (truncated)
Commits
5cf516cv6.13.08d56df2[New]parse: addstrictDepthoptionc9a6694[Tests] usenpm auditinstead ofaudf90cc35v6.12.31bf9f7a[Fix]parse: properly account forstrictNullHandlingwhenallowEmptyArrays7ebf48b[meta] fix changelog indentationd0dff11v6.12.2f0b8d03[Dev Deps] update@ljharb/eslint-config,object-inspect,tape81835ff[Fix]:parse: parse encoded square bracketsdb47dcc[readme] add CII best practices badgeUpdates
sendfrom 0.18.0 to 0.19.0Release notes
Sourced from send's releases.
Changelog
Sourced from send's changelog.
Commits
9d2db990.19.0ae4f298Merge commit from forkMaintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for send since your current version.
Updates
serve-staticfrom 1.15.0 to 1.16.2Release notes
Sourced from serve-static's releases.
Changelog
Sourced from serve-static's changelog.
Commits
ec9c5ec1.16.2f454d37fix(deps): encodeurl@~2.0.077a82551.16.14263f49fix(deps): send@0.19.048c73971.16.00c11fadMerge commit from forkMaintainer changes
This version was pushed to npm by wesleytodd, a new releaser for serve-static since your current version.
Updates
aifrom 2.2.22 to 5.0.52Changelog
Sourced from ai's changelog.
... (truncated)
Commits
63d5f66Version Packages (#8895)930399bBackport: fix(ai): download files when intermediate file cannot be downloaded...85909a9Backport: chore(ai): update test message (#8875)c56822dBackport: fix(ai): updateuiMessageChunkSchemato satisfy the `UIMessageChu...6bd07dfVersion Packages (#8853)27645bbBackport: ExportparseJsonEventStreamanduiMessageChunkSchemafrom "ai" ...8b7f0d2Version Packages (#8843)9eef198Version Packages (#8831)20bca65Version Packages (#8799)4254096Version Packages (#8753)Maintainer changes
This version was pushed to npm by vercel-release-bot, a new releaser for ai since your current version.
Updates
expressfrom 4.19.2 to 4.22.0Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
Commits
49744ab4.22.0 (#6921)6e97452sec: security patch for CVE-2024-519996a23d34deps: use tilde notation forqs(#6919)8c12cdfdeps: qs@6.14.0 (#6909)7fea74fdeps: use tilde notation for certain dependencies (#6905)dac7a04chore: wider range for query test skip (#6513)997919bci: add node.js 24 to test matrix (#6506)36fb59cfix(ci): reordernpm isteps to fix ci for older node versions (#6336)3a5edfafix(ci): updated github actions ci workflow (#6323)52d9781fix(test): add test for method routes without paths #5955Updates
aifrom 2.2.37 to 5.0.52Changelog
Sourced from ai's changelog.
... (truncated)
Commits
63d5f66Version Packages (#8895)930399bBackport: fix(ai): download files when intermediate file cannot be downloaded...85909a9Backport: chore(ai): update test message (#8875)c56822dBackport: fix(ai): updateuiMessageChunkSchemato satisfy the `UIMessageChu...6bd07dfVersion Packages (#8853)27645bbBackport: ExportparseJsonEventStreamanduiMessageChunkSchemafrom "ai" ...8b7f0d2Version Packages (#8843)9eef198Version Packages (#8831)20bca65Version Packages (#8799)4254096Version Packages (#8753)Maintainer changes
This version was pushed to npm by vercel-release-bot, a new releaser for ai since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill cl...Description has been truncated