chore(deps): update npm minor and patch dependencies - #10350
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ❌ Deployment failed View logs |
loopover-ui | 11c5293 | Sep 18 2026, 06:53 AM |
|
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 10, 2026 13:04
5b9e1bb to
6120b8c
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 10, 2026 17:56
6120b8c to
2b9cf39
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 10, 2026 22:16
2b9cf39 to
0c5024c
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 11, 2026 01:17
0c5024c to
73830c8
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 11, 2026 04:50
73830c8 to
53cdbf8
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 11, 2026 21:17
53cdbf8 to
2b3206d
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 12, 2026 05:56
2b3206d to
7e07ff7
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 12, 2026 15:17
7e07ff7 to
6d1860c
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 16, 2026 11:18
6d1860c to
8246cab
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 16, 2026 12:40
8246cab to
4bf978f
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 16, 2026 17:38
4bf978f to
c35fbf6
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 16, 2026 20:59
c35fbf6 to
e67f676
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 17, 2026 02:56
e67f676 to
264b992
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 23, 2026 10:34
8b4e40a to
5bcb4d4
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 23, 2026 13:45
5bcb4d4 to
f9bc6f3
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 23, 2026 21:02
f9bc6f3 to
7c0adb0
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 24, 2026 03:40
7c0adb0 to
3ce9dfc
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 24, 2026 10:00
3ce9dfc to
79d4646
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 25, 2026 17:51
79d4646 to
bf45ebf
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 26, 2026 00:11
bf45ebf to
27819f5
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 26, 2026 03:47
27819f5 to
2632feb
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
2 times, most recently
from
August 26, 2026 23:13
12f7e58 to
e7b6693
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 27, 2026 08:43
e7b6693 to
924fe96
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 27, 2026 17:57
924fe96 to
3de850f
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 27, 2026 22:54
3de850f to
ec559db
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
August 28, 2026 03:41
ec559db to
f466077
Compare
Contributor
|
Superagent didn't find any vulnerabilities or security issues in this PR. |
Contributor
Author
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.3.218→^0.3.272^1.1.0→^1.4.0^0.18.8→^0.22.0^5.20260724.1→^5.20260915.1^2.0.11→^2.1.11.2.1→1.3.21.1.4→1.8.12.7.7→2.22.01.29.0→1.30.0^7.0.6→^7.0.8^0.221.0→^0.222.0^2.10.0→^2.11.0^2.10.0→^2.11.00.9.1→0.18.2^1.2.18→^1.2.20^1.1.21→^1.1.23^1.1.13→^1.1.15^1.2.4→^1.2.6^1.3.9→^1.3.11^1.1.18→^1.1.20^2.3.5→^2.3.7^1.1.21→^1.1.23^2.1.22→^2.1.24^1.1.21→^1.1.23^2.1.13→^2.1.15^1.1.22→^1.1.24^1.2.20→^1.2.22^1.1.21→^1.1.23^1.1.14→^1.1.16^1.4.5→^1.4.7^1.2.16→^1.2.18^2.3.5→^2.3.7^1.1.13→^1.1.15^1.4.5→^1.4.7^1.3.1→^1.3.3^1.3.5→^1.3.7^1.1.19→^1.1.21^1.1.16→^1.1.18^1.1.17→^1.1.19^1.2.14→^1.2.16^0.9.59→^0.9.67^10.67.0→^10.74.0^10.67.0→^10.74.0^5.101.4→^5.102.8^1.170.18→^1.170.36^1.168.32→^1.168.54^1.168.23→^1.168.38^10.4.1→^10.4.2^16.3.2→^16.3.3^22.20.1→^22.20.2^24.13.3→^24.13.4^8.20.0→^8.23.1^19.2.17→^19.3.0^19.2.3→^19.3.0^7.7.1→^7.8.0^4.1.10→^4.1.11^0.6.0→^0.6.1^0.19.0→^0.23.0^0.28.1→^0.28.2^10.8.0→^10.10.0^0.5.3→^0.5.7^16.12.1→^16.15.10^15.2.0→^15.4.0^17.7.0→^17.12.0^1.4.2→^1.5.0^12.42.2→^12.43.0^8.9.0→^8.9.210.9.8→10.9.9^8.22.0→^8.23.0^1.61.1→^1.63.0^1.409.3→^1.433.3^5.46.1→^5.52.2^19.2.8→^19.3.0^19.2.8→^19.3.0^7.82.0→^7.88.0^4.12.2→^4.12.4^2.0.7→^2.0.8^3.6.0→^3.7.0^7.5.21→^7.5.224.22.5→4.23.13^4.23.1→^4.23.13^2.10.6→^2.10.13^8.65.0→^8.70.0^8.1.5→^8.3.0^0.20.8→^0.27.0^4.115.0→^4.131.2^4.114.0→^4.131.2^8.21.1→^8.21.3^2.9.0→^2.9.1^4.4.3→^4.6.5Dependency PRs must keep
npm run test:cipassing. The 97% coverage requirement is enforced as Codecov patch coverage on changed lines (codecov/patch), so dependency-only bumps satisfy it without new tests.GitHub Actions updates must remain SHA-pinned.
Renovate is the sole dependency and security-update bot for this repo; GitHub Dependabot security updates are disabled to avoid duplicate PRs (e.g. the two hono advisory PRs).
Release Notes
anthropics/claude-agent-sdk-typescript (@anthropic-ai/claude-agent-sdk)
v0.3.272Compare Source
v0.3.271Compare Source
omitClaudeMdtoAgentDefinitionin theagentsoption, so a subagent can run without user, project and local CLAUDE.md files; managed policy files still loadlistSessions,getSessionMessagesandgetSessionInfowithdiron Windows not finding sessions for a directory on a mapped network drive or SUBST drivesessionStoreresume losing the global config when it is stored under the legacy.config.jsonname or an OAuth-suffixed file namepersistentfrom theMonitorInputtool typev0.3.270Compare Source
v0.3.269Compare Source
user_message_uuid,user_message_uuidsandresume_reasonto be stamped on a turn's first complete assistant message as well as its first stream event when partial messages are onresult.permission_denialsomitting Read, Edit and Write calls blocked by a path-scoped deny ruletool_use_idontask_started/task_notificationwhen the CLI resumes a background subagent on its own; they now carry the agent's last call idcanUseTooleven whenallowDangerouslySkipPermissionsis set; the flag now only enables switching tobypassPermissionslaterv0.3.268Compare Source
result_indexto result messages: the result's position in delivery order within the run, from 0local_commandto the result message of a turn that ran a slash command without entering the model loop, carrying the command's namehold_on_cache_impactto thereload_pluginscontrol request (Query.reloadPlugins({ holdOnCacheImpact: true })): holds a reload that would invalidate the session's prompt cacheresume_reasonto assistant, stream-event and result messages, set only on the automatic re-run of a turn a host restart interruptedkind(used, free, buffer, deferred) to each category in theget_context_usagecontrol response, matching the/contextresult'scontext_usagerowsdefaultToNoandsuppressAlwaysAllowRulehints tocanUseTooloptions: the prompt should open on its decline option, or offer no persistent "always allow" choicesetModel()to confirm a model id the CLI doesn't know locally with the API the first time a session uses it, instead of refusing it as unrecognizeduser_message_uuidon the automatic re-run of an interrupted turn to name that turn's last user promptinitializesuccess response to always includepending_permission_requests(empty when nothing is pending), so clients can tell that apart from an older CLItools/allowedToolsv0.3.267Compare Source
getCcrEvent(query, message)andgetSseLastSequenceNum(query)to the browser SDK's SSE transport, plusfromSequenceNum,onCatchUpTruncatedandonDeliveryUpdateSSE optionssystemPromptrecording to default on for custom prompts and appends (a mid-session prompt change takes effect at the next compaction); passsnapshot: falseto keep per-request renderingv0.3.266Compare Source
v0.3.265Compare Source
user_message_uuidanduser_message_uuidsto a synthetic turn's first reply and result for a message sent withisSynthetic: trueand auuid, naming the message that started ituser_message_uuidanduser_message_uuidsto the first reply and the result of a turn Claude Code started itself, such as a resume, naming the messages you sent that it picked up mid-turnuser_message_uuidmissing from the success result of a turn that sent no API request, such as a slash commandcwdoption at each new user message; acdmade by the agent now persists across turns, as in the interactive appuser_message_uuidto be set on the first reply after each change of the message a turn is answering, instead of on one reply frame per turnv0.3.263Compare Source
v0.3.261Compare Source
pluginDelivery: 'initialize'to sendpluginsover stdin so the launch command line no longer grows with the plugin count (fixes Windows start failures with many plugins)query()throwing "Object not disposable" in runtimes without a nativeSymbol.dispose, such as Node ≤22vmcontexts (Jest'snodeenvironment, vitestvmThreads/vmForks) and Node <18.18v0.3.260Compare Source
user_message_uuidtothinking_tokenssystem messages, linking thinking progress to the user message that triggered the turnfirst_content_frame_ms,first_stream_post_ms,first_stream_post_ack_msandfirst_stream_post_wall_msfields to the success result message for remote-session latency breakdownsmanagedSettingsdisableAutoMode: "disable"(either spelling) being dropped by the restrictive-only filter instead of turning auto mode off for the spawned sessionrewindFiles()reporting success when no files could be restored (for example when checkpoint backups are missing); it now failserror_max_structured_output_retriesresults to append the last StructuredOutput tool error; validation errors now name the offending key, allowed values, and actual length or countrate_limit_eventto also re-emit during an exceeded window on repeat 429s (about once per 30 seconds per limit window), so stream consumers can refresh stale rate-limit statev0.3.259Compare Source
user_message_uuidsbesideuser_message_uuidon a turn's first reply frame and result: every user message the turn answered, so a reply to several merged messages can be matched to eachpermissionPrompts: 'none'option to auto-deny permission prompts in sessions with nobody to answer them, without disabling auto mode's classifierv0.3.258Compare Source
v0.3.257Compare Source
thinkingTokenstoModelUsage(a subset ofoutputTokens), and fixed result-messageusage.output_tokens_details.thinking_tokensreporting 0 instead of the session's real counttool_use_result.resourceLinkson user messages carrying MCP tool results: theresource_linkblocks the tool returned, so hosts can render returned files without parsing the result textresource_linkstotask_notificationfor an auto-backgrounded MCP tool call that completed, listing the files it returned by reference; join to the call viatool_use_idmcp_reconnectandmcp_toggleacting on a same-named.mcp.json/~/.claude.jsonserver instead of the--mcp-configormcp_set_serversonemcp_toggledisable also removing the tools of a sibling MCP server whose name extends the disabled one's (disablingfoodroppedfoo__bar's tools)mcp_set_serversto also list a server whose connection attempt throws underadded(with afailedrow inmcp_status), not only undererrorstool_progressheartbeat (heartbeat: true) like other long tools; heartbeat frames never clear asubagent_retryindicator@anthropic-ai/claude-agent-sdk/browser) never streaming any messages on engines without nativeSymbol.dispose(Safari/iOS, Firefox ESR, older Chromium)task_notification-pgiving up on a long-running background subagent without actually stopping it, sobackground_tasks_changedkept listing it and events for it arrived after itsstoppednotificationdetailoption toQuery.getContextUsage():'summary'answers from the last response's usage and local estimates without per-category token-count API calls (default'full')v0.3.252Compare Source
v0.3.251Compare Source
v0.3.250Compare Source
v0.3.248Compare Source
timeoutfor SDK-hosted MCP servers (createSdkMcpServer({ timeout })), overridingMCP_TOOL_TIMEOUTfor that server's tool callsv0.3.247Compare Source
ambientflag totask_started,task_notificationandbackground_tasks_changedtask entries so hosts can exclude housekeeping tasks from activity indicatorspermissionModeon per-turnsystem/initframes reporting the mode at turn start instead of the live mode, so a mode switch right after submitting no longer sends a stale valuev0.3.246Compare Source
user_message_uuidto error result messages and to the first assistant message orstream_eventof each turn, linking a reply or failure to the user message that triggered itmodelUsage[*].costBasis('list' | 'managed' | 'unknown') reporting which price table each model'scostUSDwas computed frommodelPricingsupport in themanagedSettingsoption for hosts that setCLAUDE_CODE_PROVIDER_MANAGED_BY_HOST; an admin-managed settings source that setsmodelPricingstill winsperTaskStopAffordanceoption: when set,interrupt()aborts only the current turn and keeps background agents and workflows running; otherwise (and for one-shot string prompts) they stopv0.3.245Compare Source
v0.3.243queued_turn_countto result messages: the number of queued user sends still pending when the result was produced, so hosts know whether another turn and result will followmcp_statusreporting a remote MCP server as connected after its connection dropped; it now reports pending while reconnecting, then connected or faileddisableAllHooksalso disabling hook callbacks registered through thehooksoption; they now keep running, matchingallowManagedHooksOnlydocumentblock (or pageimageblocks forpagesreads) now arrives inside thetool_resultcontent instead of as a separateusermessage after itv0.3.242v0.3.241Compare Source
[
v0.3.240](https://redirect.github.com/anthroConfiguration
📅 Schedule: (in timezone America/Phoenix)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.