Skip to content

chore(deps): update npm minor and patch dependencies - #10350

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-minor-patch
Open

chore(deps): update npm minor and patch dependencies#10350
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@anthropic-ai/claude-agent-sdk ^0.3.218^0.3.231 age confidence
@cloudflare/puppeteer (source) ^1.1.0^1.3.0 age confidence
@cloudflare/vitest-pool-workers (source) ^0.18.8^0.21.2 age confidence
@cloudflare/workers-types ^5.20260724.1^5.20260813.1 age confidence
@hono/node-server ^2.0.11^2.1.0 age confidence
@lovable.dev/vite-plugin-dev-server-bridge (source) 1.2.11.3.1 age confidence
@lovable.dev/vite-plugin-hmr-gate (source) 1.1.41.6.2 age confidence
@lovable.dev/vite-tanstack-config (source) 2.7.72.13.0 age confidence
@modelcontextprotocol/sdk (source) 1.29.01.30.0 age confidence
@octokit/core ^7.0.6^7.0.7 age confidence
@posthog/cli (source) 0.9.10.11.1 age confidence
@radix-ui/react-accordion (source) ^1.2.18^1.2.20 age confidence
@radix-ui/react-alert-dialog (source) ^1.1.21^1.1.23 age confidence
@radix-ui/react-aspect-ratio (source) ^1.1.13^1.1.15 age confidence
@radix-ui/react-avatar (source) ^1.2.4^1.2.6 age confidence
@radix-ui/react-checkbox (source) ^1.3.9^1.3.11 age confidence
@radix-ui/react-collapsible (source) ^1.1.18^1.1.20 age confidence
@radix-ui/react-context-menu (source) ^2.3.5^2.3.7 age confidence
@radix-ui/react-dialog (source) ^1.1.21^1.1.23 age confidence
@radix-ui/react-dropdown-menu (source) ^2.1.22^2.1.24 age confidence
@radix-ui/react-hover-card (source) ^1.1.21^1.1.23 age confidence
@radix-ui/react-label (source) ^2.1.13^2.1.15 age confidence
@radix-ui/react-menubar (source) ^1.1.22^1.1.24 age confidence
@radix-ui/react-navigation-menu (source) ^1.2.20^1.2.22 age confidence
@radix-ui/react-popover (source) ^1.1.21^1.1.23 age confidence
@radix-ui/react-progress (source) ^1.1.14^1.1.16 age confidence
@radix-ui/react-radio-group (source) ^1.4.5^1.4.7 age confidence
@radix-ui/react-scroll-area (source) ^1.2.16^1.2.18 age confidence
@radix-ui/react-select (source) ^2.3.5^2.3.7 age confidence
@radix-ui/react-separator (source) ^1.1.13^1.1.15 age confidence
@radix-ui/react-slider (source) ^1.4.5^1.4.7 age confidence
@radix-ui/react-slot (source) ^1.3.1^1.3.3 age confidence
@radix-ui/react-switch (source) ^1.3.5^1.3.7 age confidence
@radix-ui/react-tabs (source) ^1.1.19^1.1.21 age confidence
@radix-ui/react-toggle (source) ^1.1.16^1.1.18 age confidence
@radix-ui/react-toggle-group (source) ^1.1.17^1.1.19 age confidence
@radix-ui/react-tooltip (source) ^1.2.14^1.2.16 age confidence
@scalar/api-reference-react (source) ^0.9.59^0.9.62 age confidence
@sentry/node (source) ^10.67.0^10.70.0 age confidence
@sentry/react (source) ^10.67.0^10.70.0 age confidence
@tanstack/react-router (source) ^1.170.18^1.170.27 age confidence
@tanstack/react-start (source) ^1.168.32^1.168.44 age confidence
@tanstack/router-plugin (source) ^1.168.23^1.168.30 age confidence
@types/pg (source) ^8.20.0^8.21.0 age confidence
@types/react (source) ^19.2.17^19.2.18 age confidence
@types/react-dom (source) ^19.2.3^19.2.4 age confidence
@types/semver (source) ^7.7.1^7.8.0 age confidence
agents (source) ^0.19.0^0.20.1 age confidence
esbuild ^0.28.1^0.28.2 age confidence
eslint (source) ^10.8.0^10.8.1 age confidence
eslint-plugin-react-refresh ^0.5.3^0.5.4 age confidence
fumadocs-core ^16.12.1^16.14.3 age confidence
fumadocs-mdx ^15.2.0^15.2.3 age confidence
globals ^17.7.0^17.11.0 age confidence
hono (source) ^4.12.31^4.13.2 age confidence
hono (source) ^4.12.34^4.13.2 age confidence
motion ^12.42.2^12.43.0 age confidence
node-addon-api ^8.9.0^8.9.2 age confidence
npm (source) 10.9.810.9.9 age confidence
pg (source) ^8.22.0^8.23.0 age confidence
playwright (source) ^1.61.1^1.62.1 age confidence
posthog-js (source) ^1.409.3^1.416.0 age confidence
posthog-node (source) ^5.46.1^5.48.2 age confidence
react-hook-form (source) ^7.82.0^7.85.0 age confidence
sonner (source) ^2.0.7^2.0.8 age confidence
tar ^7.5.21^7.5.22 age confidence
tsx (source) 4.22.54.23.12 age confidence
tsx (source) ^4.23.1^4.23.12 age confidence
turbo (source) ^2.10.6^2.10.9 age confidence
typescript-eslint (source) ^8.65.0^8.67.0 age confidence
vite (source) ^8.1.5^8.2.1 age confidence
web-tree-sitter (source) ^0.20.8^0.26.12 age confidence
wrangler (source) ^4.115.0^4.122.0 age confidence
wrangler (source) ^4.114.0^4.122.0 age confidence
ws ^8.21.1^8.21.3 age confidence

Dependency PRs must keep npm run test:ci passing. The 97% coverage requirement is enforced as Codecov patch coverage on changed lines (codecov/patch), so dependency-only bumps satisfy it without new tests.

GitHub Actions updates must remain SHA-pinned.

Renovate is the sole dependency and security-update bot for this repo; GitHub Dependabot security updates are disabled to avoid duplicate PRs (e.g. the two hono advisory PRs).


Release Notes

anthropics/claude-agent-sdk-typescript (@​anthropic-ai/claude-agent-sdk)

v0.3.231

Compare Source

  • Updated to parity with Claude Code v2.1.231

v0.3.229

Compare Source

  • Added terminal_slash_commands to the system init message so Remote Control clients can hide terminal-oriented commands
  • Changed conversations whose messages alone exceed the API's 32 MB limit to end the turn with terminal_reason "api_error" instead of "image_error"; StopFailure error_details is "request_body_over_limit: …"

v0.3.228

Compare Source

  • Agent tool results (AgentOutput): usage.output_tokens_details is now carried through

v0.3.227

Compare Source

  • Updated to parity with Claude Code v2.1.227

v0.3.226

Compare Source

  • Updated to parity with Claude Code v2.1.226

v0.3.225

Compare Source

  • Fixed background subagents in headless/SDK sessions never resuming when a background shell command or Monitor they left running completed, so the subagent never saw the result

v0.3.224

Compare Source

  • Added crossSessionInbound and dialogExpiry settings: cross-session messages sent to a session running with bypassed permissions are held for your approval, and messages to other sessions auto-deliver
  • Added subkind: 'peer-send-message' to the task-notification member of SDKMessageOrigin, marking a notification raised by a cross-session SendMessage
  • Added source: 'archive' plugin config variant to Settings, with url and optional sha256, for installing plugins from a zip over HTTPS
  • Added sandbox credential-masking fields to Settings: decode: 'jwt' with maskClaims, extract/onExtractNoMatch on envVars, and awsPairs/sigv4 for AWS SigV4 re-signing
  • Fixed long (>200 char) project paths resolving to another project's session directory under a shared sanitized prefix; session list/get/rename/tag/fork/delete and /resume no longer cross projects

v0.3.223

Compare Source

  • Added resumeDropsTurn option: with resumeSessionAt, declares the turn a truncating resume intends to drop; the CLI refuses the resume if anything else would be discarded
  • Result messages for repeated 529 overload failures now include api_error_status: 529, so SDK consumers can detect overload terminations structurally instead of matching message text
  • Bare headless (-p / SDK query() without canUseTool) now emits system/permission_denied stream events when a tool call is auto-denied
  • Documented usage vs modelUsage on stream-json results: usage is main-loop-only and per-turn; modelUsage is cumulative, covers all query-pipeline calls, and is the field for cost accounting

v0.3.222

Compare Source

  • Fixed query({ sessionStore, resume }) not carrying user settings.json (apiKeyHelper, env, hooks, permissions) into the resumed subprocess

v0.3.221

Compare Source

  • Improved skills option validation: malformed names (delimiters or control characters) and wildcard-form names are rejected with a clear error; use skills: 'all' to enable every skill
  • Fixed external MCP servers passed via the mcpServers option not being connected before the first turn, which caused the model to emit tool calls as literal text

v0.3.220

Compare Source

  • Updated to parity with Claude Code v2.1.220

v0.3.219

Compare Source

  • Added opt-in cancel_queued to the interrupt control request (capability interrupt_cancel_queued_v1): cancels queued and pending-dispatch messages alongside the abort
  • Added fast_mode_disabled_reason to result and init messages so SDK hosts can explain why fast mode is off
  • Added DirectoryAdded lifecycle hook event to the control protocol, fired when a new working directory is registered mid-session
  • Fixed the initialize response reporting fast_mode_state from the spawn-time model after a model switch
  • Added sandbox.network.strictAllowlist to SDK settings types for deterministically denying non-allowlisted hosts in sandboxed commands
  • Added workflowSizeGuideline to SDK settings types for setting the advisory dynamic-workflow size guideline
cloudflare/puppeteer (@​cloudflare/puppeteer)

v1.3.0

Compare Source

What's Changed

Full Changelog: cloudflare/puppeteer@v1.2.0...v1.3.0

v1.2.0

Compare Source

What's Changed

Full Changelog: cloudflare/puppeteer@v1.1.0...v1.2.0

cloudflare/workers-sdk (@​cloudflare/vitest-pool-workers)

v0.21.2

Compare Source

Patch Changes
  • #​15123 d0c976c Thanks @​dependabot! - Widen WorkerPoolOptionsContext.inject type to avoid ProvidedContext mismatch

    Previously, calling inject() inside cloudflareTest() pool options could fail with a type error when your project's ProvidedContext augmentation wasn't visible to the pool plugin. The inject parameter now accepts any string key and is generic (inject<T>(key)), defaulting to unknown when no type argument is provided. This lets you opt in to concrete types (e.g. inject<number>("port")) while avoiding the cross-copy ProvidedContext mismatch that occurred when pnpm resolved separate virtual-store instances of vitest.

  • #​15148 0b82b15 Thanks @​jamesopstad! - Ignore a nodejs_compat compatibility flag that the compatibility date already enables

    workerd rejects a compatibility flag that its compatibility date enables by default, so a Worker configured with both a compatibility date of 2026-08-04 or later and nodejs_compat failed to start locally with "The compatibility flag nodejs_compat became the default as of 2026-08-04 so does not need to be specified anymore".

    The redundant nodejs_compat and nodejs_compat_v2 flags are now dropped when starting the runtime, which has no effect on the resulting Worker because the compatibility date enables both anyway. no_nodejs_compat and no_nodejs_compat_v2 still switch Node.js compatibility off, and a flag specified alongside its own opt-out is left alone so that workerd still reports those as contradictory.

  • #​15123 d0c976c Thanks @​dependabot! - Detect Node.js compatibility from the compatibility date, now that nodejs_compat is enabled by default

    As of compatibility date 2026-08-04, workerd enables the nodejs_compat and nodejs_compat_v2 compatibility flags by default. Previously these tools only treated Node.js compatibility as enabled when one of those flags was listed explicitly, so a Worker on a compatibility date of 2026-08-04 or later without the flag would get Node.js APIs from the runtime but no Node.js polyfills from the bundler, and process.env could be substituted with an empty object at build time. They now resolve these flags the same way workerd does, and honour no_nodejs_compat to opt out.

    To keep Node.js compatibility switched off on a newer compatibility date, specify both no_nodejs_compat and no_nodejs_compat_v2, since each flag has its own default.

    @cloudflare/vitest-pool-workers needs nodejs_compat_v2 for its own test runner, so it continues to override a project that opts out of it. On a compatibility date that enables the flag anyway, it now drops the opt-out rather than adding the flag back, which workerd would reject — previously this stopped such a project from running any tests at all.

    wrangler types also no longer attributes its @types/node suggestion to "the nodejs_compat flag", which it can now make for Workers that do not set the flag at all.

  • #​15131 90dd5e5 Thanks @​vicb! - Bump capnp-es to 0.0.15.

    Also re-generate the types for the latest .capnp files

  • Updated dependencies [d0c976c, d0c976c, 0b82b15, d0c976c, d0c976c, 90dd5e5, 3b02915]:

v0.21.1

Compare Source

Patch Changes
  • #​14882 ab9132d Thanks @​petebacondarwin! - Report built-in modules that a Worker's compatibility settings don't provide as module errors, instead of crashing workerd

    Previously, a Worker whose module graph statically reached a compatibility-gated built-in that wasn't enabled — for example import "node:child_process" without nodejs_compat — took down the runtime with *** Received signal #&#8203;11: Segmentation fault before any test ran. Vitest reported only Worker exited unexpectedly, naming neither the module nor the file that imported it, which made the cause very hard to find. The import didn't even have to be called; being reachable from the entrypoint was enough.

    The module fallback service answered these specifiers with a redirect to the modules root, but workerd already resolves node:/cloudflare:/workerd: specifiers there, so the redirect pointed back at the module workerd was in the middle of resolving and it recursed until the stack overflowed. Such a specifier only reaches the fallback service when workerd's own registry has already missed, so it's now reported as not found: workerd raises No such module "node:child_process", matching what wrangler dev does for the same Worker. The accompanying pool error names the module and points at compatibility flags rather than suggesting you bundle it, which can't help for a module built into the runtime.

  • Updated dependencies [15cad03, 026e058, 731b33a, e1b5b4b, 5b1b930, 6e7d37d, d669088, 15cad03, c7aede7, 0aa8fa5]:

v0.21.0

Compare Source

Minor Changes
  • #​14994 2194f88 Thanks @​emily-shen! - Update the Workers Vitest pool for Miniflare's config-based options

    The Workers Vitest pool now converts the Miniflare options it creates for test sessions to Miniflare's config-based workers shape.

    For the most part, users should not expect to notice any changes.

    However, while miniflare.modulesRules is preserved for common text and WASM fixture imports, it is not a full replacement for Miniflare's old modules: true module graph collection and you may notice some differences in behaviour.

Patch Changes

v0.20.3

Compare Source

Patch Changes

v0.20.2

Compare Source

Patch Changes

v0.20.1

Compare Source

Patch Changes

v0.20.0

Compare Source

Minor Changes
  • #​14586 5a56dda Thanks @​emily-shen! - Breaking change: Remove several options from the miniflare override options

    The following options have been removed from the miniflare override options, as they were not intended to be exposed, were not functional,

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/Phoenix)

  • Branch creation
    • "before 6am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Aug 10, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
❌ Deployment failed
View logs
loopover-ui 4bf978f Aug 16 2026, 12:42 PM

@codecov

codecov Bot commented Aug 10, 2026

Copy link
Copy Markdown

⚠️ JUnit XML file not found

The CLI was unable to find any JUnit XML files to upload.
For more help, visit our troubleshooting guide.

@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 5b9e1bb to 6120b8c Compare August 10, 2026 13:04
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 6120b8c to 2b9cf39 Compare August 10, 2026 17:56
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 2b9cf39 to 0c5024c Compare August 10, 2026 22:16
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 0c5024c to 73830c8 Compare August 11, 2026 01:17
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 73830c8 to 53cdbf8 Compare August 11, 2026 04:50
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 53cdbf8 to 2b3206d Compare August 11, 2026 21:17
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 2b3206d to 7e07ff7 Compare August 12, 2026 05:56
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 7e07ff7 to 6d1860c Compare August 12, 2026 15:17
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 6d1860c to 8246cab Compare August 16, 2026 11:18
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 8246cab to 4bf978f Compare August 16, 2026 12:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant