chore(deps): update npm minor and patch dependencies - #10350
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): update npm minor and patch dependencies#10350renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Contributor
|
Superagent didn't find any vulnerabilities or security issues in this PR. |
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ❌ Deployment failed View logs |
loopover-ui | 4bf978f | Aug 16 2026, 12:42 PM |
|
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 10, 2026 13:04
5b9e1bb to
6120b8c
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 10, 2026 17:56
6120b8c to
2b9cf39
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 10, 2026 22:16
2b9cf39 to
0c5024c
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 11, 2026 01:17
0c5024c to
73830c8
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 11, 2026 04:50
73830c8 to
53cdbf8
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 11, 2026 21:17
53cdbf8 to
2b3206d
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 12, 2026 05:56
2b3206d to
7e07ff7
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 12, 2026 15:17
7e07ff7 to
6d1860c
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 16, 2026 11:18
6d1860c to
8246cab
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 16, 2026 12:40
8246cab to
4bf978f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.3.218→^0.3.231^1.1.0→^1.3.0^0.18.8→^0.21.2^5.20260724.1→^5.20260813.1^2.0.11→^2.1.01.2.1→1.3.11.1.4→1.6.22.7.7→2.13.01.29.0→1.30.0^7.0.6→^7.0.70.9.1→0.11.1^1.2.18→^1.2.20^1.1.21→^1.1.23^1.1.13→^1.1.15^1.2.4→^1.2.6^1.3.9→^1.3.11^1.1.18→^1.1.20^2.3.5→^2.3.7^1.1.21→^1.1.23^2.1.22→^2.1.24^1.1.21→^1.1.23^2.1.13→^2.1.15^1.1.22→^1.1.24^1.2.20→^1.2.22^1.1.21→^1.1.23^1.1.14→^1.1.16^1.4.5→^1.4.7^1.2.16→^1.2.18^2.3.5→^2.3.7^1.1.13→^1.1.15^1.4.5→^1.4.7^1.3.1→^1.3.3^1.3.5→^1.3.7^1.1.19→^1.1.21^1.1.16→^1.1.18^1.1.17→^1.1.19^1.2.14→^1.2.16^0.9.59→^0.9.62^10.67.0→^10.70.0^10.67.0→^10.70.0^1.170.18→^1.170.27^1.168.32→^1.168.44^1.168.23→^1.168.30^8.20.0→^8.21.0^19.2.17→^19.2.18^19.2.3→^19.2.4^7.7.1→^7.8.0^0.19.0→^0.20.1^0.28.1→^0.28.2^10.8.0→^10.8.1^0.5.3→^0.5.4^16.12.1→^16.14.3^15.2.0→^15.2.3^17.7.0→^17.11.0^4.12.31→^4.13.2^4.12.34→^4.13.2^12.42.2→^12.43.0^8.9.0→^8.9.210.9.8→10.9.9^8.22.0→^8.23.0^1.61.1→^1.62.1^1.409.3→^1.416.0^5.46.1→^5.48.2^7.82.0→^7.85.0^2.0.7→^2.0.8^7.5.21→^7.5.224.22.5→4.23.12^4.23.1→^4.23.12^2.10.6→^2.10.9^8.65.0→^8.67.0^8.1.5→^8.2.1^0.20.8→^0.26.12^4.115.0→^4.122.0^4.114.0→^4.122.0^8.21.1→^8.21.3Dependency PRs must keep
npm run test:cipassing. The 97% coverage requirement is enforced as Codecov patch coverage on changed lines (codecov/patch), so dependency-only bumps satisfy it without new tests.GitHub Actions updates must remain SHA-pinned.
Renovate is the sole dependency and security-update bot for this repo; GitHub Dependabot security updates are disabled to avoid duplicate PRs (e.g. the two hono advisory PRs).
Release Notes
anthropics/claude-agent-sdk-typescript (@anthropic-ai/claude-agent-sdk)
v0.3.231Compare Source
v0.3.229Compare Source
terminal_slash_commandsto the system init message so Remote Control clients can hide terminal-oriented commandsterminal_reason"api_error"instead of"image_error";StopFailureerror_detailsis"request_body_over_limit: …"v0.3.228Compare Source
AgentOutput):usage.output_tokens_detailsis now carried throughv0.3.227Compare Source
v0.3.226Compare Source
v0.3.225Compare Source
v0.3.224Compare Source
crossSessionInboundanddialogExpirysettings: cross-session messages sent to a session running with bypassed permissions are held for your approval, and messages to other sessions auto-deliversubkind: 'peer-send-message'to thetask-notificationmember ofSDKMessageOrigin, marking a notification raised by a cross-sessionSendMessagesource: 'archive'plugin config variant toSettings, withurland optionalsha256, for installing plugins from a zip over HTTPSSettings:decode: 'jwt'withmaskClaims,extract/onExtractNoMatchonenvVars, andawsPairs/sigv4for AWS SigV4 re-signing/resumeno longer cross projectsv0.3.223Compare Source
resumeDropsTurnoption: withresumeSessionAt, declares the turn a truncating resume intends to drop; the CLI refuses the resume if anything else would be discardedapi_error_status: 529, so SDK consumers can detect overload terminations structurally instead of matching message text-p/ SDKquery()withoutcanUseTool) now emitssystem/permission_deniedstream events when a tool call is auto-deniedusagevsmodelUsageon stream-json results:usageis main-loop-only and per-turn;modelUsageis cumulative, covers all query-pipeline calls, and is the field for cost accountingv0.3.222Compare Source
query({ sessionStore, resume })not carrying usersettings.json(apiKeyHelper,env,hooks,permissions) into the resumed subprocessv0.3.221Compare Source
skillsoption validation: malformed names (delimiters or control characters) and wildcard-form names are rejected with a clear error; useskills: 'all'to enable every skillmcpServersoption not being connected before the first turn, which caused the model to emit tool calls as literal textv0.3.220Compare Source
v0.3.219Compare Source
cancel_queuedto the interrupt control request (capabilityinterrupt_cancel_queued_v1): cancels queued and pending-dispatch messages alongside the abortfast_mode_disabled_reasonto result and init messages so SDK hosts can explain why fast mode is offDirectoryAddedlifecycle hook event to the control protocol, fired when a new working directory is registered mid-sessionfast_mode_statefrom the spawn-time model after a model switchsandbox.network.strictAllowlistto SDK settings types for deterministically denying non-allowlisted hosts in sandboxed commandsworkflowSizeGuidelineto SDK settings types for setting the advisory dynamic-workflow size guidelinecloudflare/puppeteer (@cloudflare/puppeteer)
v1.3.0Compare Source
What's Changed
Full Changelog: cloudflare/puppeteer@v1.2.0...v1.3.0
v1.2.0Compare Source
What's Changed
Full Changelog: cloudflare/puppeteer@v1.1.0...v1.2.0
cloudflare/workers-sdk (@cloudflare/vitest-pool-workers)
v0.21.2Compare Source
Patch Changes
#15123
d0c976cThanks @dependabot! - WidenWorkerPoolOptionsContext.injecttype to avoidProvidedContextmismatchPreviously, calling
inject()insidecloudflareTest()pool options could fail with a type error when your project'sProvidedContextaugmentation wasn't visible to the pool plugin. Theinjectparameter now accepts any string key and is generic (inject<T>(key)), defaulting tounknownwhen no type argument is provided. This lets you opt in to concrete types (e.g.inject<number>("port")) while avoiding the cross-copyProvidedContextmismatch that occurred when pnpm resolved separate virtual-store instances of vitest.#15148
0b82b15Thanks @jamesopstad! - Ignore anodejs_compatcompatibility flag that the compatibility date already enablesworkerd rejects a compatibility flag that its compatibility date enables by default, so a Worker configured with both a compatibility date of
2026-08-04or later andnodejs_compatfailed to start locally with "The compatibility flag nodejs_compat became the default as of 2026-08-04 so does not need to be specified anymore".The redundant
nodejs_compatandnodejs_compat_v2flags are now dropped when starting the runtime, which has no effect on the resulting Worker because the compatibility date enables both anyway.no_nodejs_compatandno_nodejs_compat_v2still switch Node.js compatibility off, and a flag specified alongside its own opt-out is left alone so that workerd still reports those as contradictory.#15123
d0c976cThanks @dependabot! - Detect Node.js compatibility from the compatibility date, now thatnodejs_compatis enabled by defaultAs of compatibility date
2026-08-04, workerd enables thenodejs_compatandnodejs_compat_v2compatibility flags by default. Previously these tools only treated Node.js compatibility as enabled when one of those flags was listed explicitly, so a Worker on a compatibility date of2026-08-04or later without the flag would get Node.js APIs from the runtime but no Node.js polyfills from the bundler, andprocess.envcould be substituted with an empty object at build time. They now resolve these flags the same way workerd does, and honourno_nodejs_compatto opt out.To keep Node.js compatibility switched off on a newer compatibility date, specify both
no_nodejs_compatandno_nodejs_compat_v2, since each flag has its own default.@cloudflare/vitest-pool-workersneedsnodejs_compat_v2for its own test runner, so it continues to override a project that opts out of it. On a compatibility date that enables the flag anyway, it now drops the opt-out rather than adding the flag back, which workerd would reject — previously this stopped such a project from running any tests at all.wrangler typesalso no longer attributes its@types/nodesuggestion to "thenodejs_compatflag", which it can now make for Workers that do not set the flag at all.#15131
90dd5e5Thanks @vicb! - Bumpcapnp-esto 0.0.15.Also re-generate the types for the latest
.capnpfilesUpdated dependencies [
d0c976c,d0c976c,0b82b15,d0c976c,d0c976c,90dd5e5,3b02915]:v0.21.1Compare Source
Patch Changes
#14882
ab9132dThanks @petebacondarwin! - Report built-in modules that a Worker's compatibility settings don't provide as module errors, instead of crashing workerdPreviously, a Worker whose module graph statically reached a compatibility-gated built-in that wasn't enabled — for example
import "node:child_process"withoutnodejs_compat— took down the runtime with*** Received signal #​11: Segmentation faultbefore any test ran. Vitest reported onlyWorker exited unexpectedly, naming neither the module nor the file that imported it, which made the cause very hard to find. The import didn't even have to be called; being reachable from the entrypoint was enough.The module fallback service answered these specifiers with a redirect to the modules root, but workerd already resolves
node:/cloudflare:/workerd:specifiers there, so the redirect pointed back at the module workerd was in the middle of resolving and it recursed until the stack overflowed. Such a specifier only reaches the fallback service when workerd's own registry has already missed, so it's now reported as not found: workerd raisesNo such module "node:child_process", matching whatwrangler devdoes for the same Worker. The accompanying pool error names the module and points at compatibility flags rather than suggesting you bundle it, which can't help for a module built into the runtime.Updated dependencies [
15cad03,026e058,731b33a,e1b5b4b,5b1b930,6e7d37d,d669088,15cad03,c7aede7,0aa8fa5]:v0.21.0Compare Source
Minor Changes
#14994
2194f88Thanks @emily-shen! - Update the Workers Vitest pool for Miniflare's config-based optionsThe Workers Vitest pool now converts the Miniflare options it creates for test sessions to Miniflare's config-based
workersshape.For the most part, users should not expect to notice any changes.
However, while
miniflare.modulesRulesis preserved for common text and WASM fixture imports, it is not a full replacement for Miniflare's oldmodules: truemodule graph collection and you may notice some differences in behaviour.Patch Changes
6dbd192,2194f88,2194f88,2194f88,2194f88,2194f88,2194f88,2194f88]:v0.20.3Compare Source
Patch Changes
#15013
8cf78c8Thanks @dario-piotrowicz! - Update undici from 7.28.0 to 7.29.0Updated dependencies [
35c87e9,b4f0c97,8cf78c8,a60ff4d,99eb50c,35c87e9]:v0.20.2Compare Source
Patch Changes
20470fa,9c74538,266172b,a88d169,a88d169,daf65f2,a9e5abb]:v0.20.1Compare Source
Patch Changes
cc63aae,f92d1fc,a249591,f92d1fc,f92d1fc,cec9d88,e0bbf55]:v0.20.0Compare Source
Minor Changes
#14586
5a56ddaThanks @emily-shen! - Breaking change: Remove several options from theminiflareoverride optionsThe following options have been removed from the
miniflareoverride options, as they were not intended to be exposed, were not functional,Configuration
📅 Schedule: (in timezone America/Phoenix)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.