chore: update ai-sdk family patches, effect published pins, and zizmor - #150
Conversation
Change-Id: I3a31f5599bf0f69fd31b8ac5cab40c50b07f7754 Signed-off-by: Thomas Kosiewski <tk@coder.com>
|
@codex review |
|
@codex security review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ea70971488
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…th new pins Change-Id: I3da2ee75e99feccb028edaf7fd11aa460113c0ab Signed-off-by: Thomas Kosiewski <tk@coder.com>
|
@codex review |
|
@codex security review |
|
Codex Review: Didn't find any major issues. More of your lovely PRs please. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
Batch dependency update: ai-sdk family patch releases, effect's published-package pins, and the zizmor toolchain pin.
Bumps
ai@ai-sdk/harness@ai-sdk/harness-claude-code@ai-sdk/react@ai-sdk/tuitsx@coder/ai-sdk-provider@coder/ai-sdk-sandbox@ai-sdk/providerzizmorNotes:
@coder/ai-sdk-provider/@coder/ai-sdk-sandboxreleases (exact pins, notworkspace:*), and@coder/ai-sdk-provider@0.4.5pins@ai-sdk/provider: "4.0.9". Effect's own@ai-sdk/providerpin must track the pin inside the published provider release it consumes, otherwise effect's tree splits across two@ai-sdk/providercopies and breaks type identity (this was a codex P2 finding on chore: update ai-sdk family and zod patches #146). The lockfile resolves a single@ai-sdk/provider@4.0.9copy.@ai-sdk/react@4.0.89resolves the same transitive@ai-sdk/mcp@2.0.41already listed inminimumReleaseAgeExclude— no pnpm-workspace.yaml change needed.overrides.zod); no peerDependency ranges touched.mise.lockrefreshed bymise install: all zizmor platform checksums/URLs moved to 1.30.0; mise no longer emits the redundanturl_apilines.actions/checkoutv7.0.1,actions/cachev6.1.0,jdx/mise-actionv4.3.0,amannn/action-semantic-pull-requestv6.1.1 are all already the latest stable releases — no changes.Validation
pnpm check✅ (oxfmt + oxlint + typecheck)pnpm -r build✅pnpm -r test✅pnpm publint✅pnpm attw✅zizmor .github/workflows@ 1.30.0 ✅ — "No findings to report" (8 pre-existing suppressions unchanged)packages/agentvitest run test/e2e— 7/7 passed (plain text, stream deltas, client tool round-trip, single-WS multi-tool turn, transport-event trace, file round-trip, file attach+read)Generated with
mux• Model:anthropic:claude-fable-5• Thinking:xhigh