Skip to content

chore(deps): update npm minor and patch dependencies - #10350

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-minor-patch
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@anthropic-ai/claude-agent-sdk ^0.3.218^0.3.272 age confidence
@cloudflare/puppeteer (source) ^1.1.0^1.4.0 age confidence
@cloudflare/vitest-pool-workers (source) ^0.18.8^0.22.0 age confidence
@cloudflare/workers-types ^5.20260724.1^5.20260915.1 age confidence
@hono/node-server ^2.0.11^2.1.1 age confidence
@lovable.dev/vite-plugin-dev-server-bridge (source) 1.2.11.3.2 age confidence
@lovable.dev/vite-plugin-hmr-gate (source) 1.1.41.8.1 age confidence
@lovable.dev/vite-tanstack-config (source) 2.7.72.22.0 age confidence
@modelcontextprotocol/sdk (source) 1.29.01.30.0 age confidence
@octokit/core ^7.0.6^7.0.8 age confidence
@opentelemetry/exporter-trace-otlp-http (source) ^0.221.0^0.222.0 age confidence
@opentelemetry/resources (source) ^2.10.0^2.11.0 age confidence
@opentelemetry/sdk-trace-node (source) ^2.10.0^2.11.0 age confidence
@posthog/cli (source) 0.9.10.18.2 age confidence
@radix-ui/react-accordion (source) ^1.2.18^1.2.20 age confidence
@radix-ui/react-alert-dialog (source) ^1.1.21^1.1.23 age confidence
@radix-ui/react-aspect-ratio (source) ^1.1.13^1.1.15 age confidence
@radix-ui/react-avatar (source) ^1.2.4^1.2.6 age confidence
@radix-ui/react-checkbox (source) ^1.3.9^1.3.11 age confidence
@radix-ui/react-collapsible (source) ^1.1.18^1.1.20 age confidence
@radix-ui/react-context-menu (source) ^2.3.5^2.3.7 age confidence
@radix-ui/react-dialog (source) ^1.1.21^1.1.23 age confidence
@radix-ui/react-dropdown-menu (source) ^2.1.22^2.1.24 age confidence
@radix-ui/react-hover-card (source) ^1.1.21^1.1.23 age confidence
@radix-ui/react-label (source) ^2.1.13^2.1.15 age confidence
@radix-ui/react-menubar (source) ^1.1.22^1.1.24 age confidence
@radix-ui/react-navigation-menu (source) ^1.2.20^1.2.22 age confidence
@radix-ui/react-popover (source) ^1.1.21^1.1.23 age confidence
@radix-ui/react-progress (source) ^1.1.14^1.1.16 age confidence
@radix-ui/react-radio-group (source) ^1.4.5^1.4.7 age confidence
@radix-ui/react-scroll-area (source) ^1.2.16^1.2.18 age confidence
@radix-ui/react-select (source) ^2.3.5^2.3.7 age confidence
@radix-ui/react-separator (source) ^1.1.13^1.1.15 age confidence
@radix-ui/react-slider (source) ^1.4.5^1.4.7 age confidence
@radix-ui/react-slot (source) ^1.3.1^1.3.3 age confidence
@radix-ui/react-switch (source) ^1.3.5^1.3.7 age confidence
@radix-ui/react-tabs (source) ^1.1.19^1.1.21 age confidence
@radix-ui/react-toggle (source) ^1.1.16^1.1.18 age confidence
@radix-ui/react-toggle-group (source) ^1.1.17^1.1.19 age confidence
@radix-ui/react-tooltip (source) ^1.2.14^1.2.16 age confidence
@scalar/api-reference-react (source) ^0.9.59^0.9.67 age confidence
@sentry/node (source) ^10.67.0^10.74.0 age confidence
@sentry/react (source) ^10.67.0^10.74.0 age confidence
@tanstack/react-query (source) ^5.101.4^5.102.8 age confidence
@tanstack/react-router (source) ^1.170.18^1.170.36 age confidence
@tanstack/react-start (source) ^1.168.32^1.168.54 age confidence
@tanstack/router-plugin (source) ^1.168.23^1.168.38 age confidence
@testing-library/dom ^10.4.1^10.4.2 age confidence
@testing-library/react ^16.3.2^16.3.3 age confidence
@types/node (source) ^22.20.1^22.20.2 age confidence
@types/node (source) ^24.13.3^24.13.4 age confidence
@types/pg (source) ^8.20.0^8.23.1 age confidence
@types/react (source) ^19.2.17^19.3.0 age confidence
@types/react-dom (source) ^19.2.3^19.3.0 age confidence
@types/semver (source) ^7.7.1^7.8.0 age confidence
@vitest/coverage-v8 (source) ^4.1.10^4.1.11 age confidence
adm-zip ^0.6.0^0.6.1 age confidence
agents (source) ^0.19.0^0.23.0 age confidence
esbuild ^0.28.1^0.28.2 age confidence
eslint (source) ^10.8.0^10.10.0 age confidence
eslint-plugin-react-refresh ^0.5.3^0.5.7 age confidence
fumadocs-core ^16.12.1^16.15.10 age confidence
fumadocs-mdx ^15.2.0^15.4.0 age confidence
globals ^17.7.0^17.12.0 age confidence
input-otp (source) ^1.4.2^1.5.0 age confidence
motion ^12.42.2^12.43.0 age confidence
node-addon-api ^8.9.0^8.9.2 age confidence
npm (source) 10.9.810.9.9 age confidence
pg (source) ^8.22.0^8.23.0 age confidence
playwright (source) ^1.61.1^1.63.0 age confidence
posthog-js (source) ^1.409.3^1.433.3 age confidence
posthog-node (source) ^5.46.1^5.52.2 age confidence
react (source) ^19.2.8^19.3.0 age confidence
react-dom (source) ^19.2.8^19.3.0 age confidence
react-hook-form (source) ^7.82.0^7.88.0 age confidence
react-resizable-panels (source) ^4.12.2^4.12.4 age confidence
sonner (source) ^2.0.7^2.0.8 age confidence
tailwind-merge (source) ^3.6.0^3.7.0 age confidence
tar ^7.5.21^7.5.22 age confidence
tsx (source) 4.22.54.23.13 age confidence
tsx (source) ^4.23.1^4.23.13 age confidence
turbo (source) ^2.10.6^2.10.13 age confidence
typescript-eslint (source) ^8.65.0^8.70.0 age confidence
vite (source) ^8.1.5^8.3.0 age confidence
web-tree-sitter (source) ^0.20.8^0.27.0 age confidence
wrangler (source) ^4.115.0^4.131.2 age confidence
wrangler (source) ^4.114.0^4.131.2 age confidence
ws ^8.21.1^8.21.3 age confidence
yaml (source) ^2.9.0^2.9.1 age confidence
zod (source) ^4.4.3^4.6.5 age confidence

Dependency PRs must keep npm run test:ci passing. The 97% coverage requirement is enforced as Codecov patch coverage on changed lines (codecov/patch), so dependency-only bumps satisfy it without new tests.

GitHub Actions updates must remain SHA-pinned.

Renovate is the sole dependency and security-update bot for this repo; GitHub Dependabot security updates are disabled to avoid duplicate PRs (e.g. the two hono advisory PRs).


Release Notes

anthropics/claude-agent-sdk-typescript (@​anthropic-ai/claude-agent-sdk)

v0.3.272

Compare Source

  • Updated to parity with Claude Code v2.1.272

v0.3.271

Compare Source

  • Added optional omitClaudeMd to AgentDefinition in the agents option, so a subagent can run without user, project and local CLAUDE.md files; managed policy files still load
  • Fixed listSessions, getSessionMessages and getSessionInfo with dir on Windows not finding sessions for a directory on a mapped network drive or SUBST drive
  • Fixed sessionStore resume losing the global config when it is stored under the legacy .config.json name or an OAuth-suffixed file name
  • Removed persistent from the MonitorInput tool type
  • Updated to parity with Claude Code v2.1.271

v0.3.270

Compare Source

  • Updated to parity with Claude Code v2.1.270

v0.3.269

Compare Source

  • Changed user_message_uuid, user_message_uuids and resume_reason to be stamped on a turn's first complete assistant message as well as its first stream event when partial messages are on
  • Fixed result.permission_denials omitting Read, Edit and Write calls blocked by a path-scoped deny rule
  • Fixed interrupts and permission responses being delayed while a host-started MCP server OAuth sign-in waited on a slow authorization server
  • Fixed missing tool_use_id on task_started / task_notification when the CLI resumes a background subagent on its own; they now carry the agent's last call id
  • Changed plan mode to route writes through canUseTool even when allowDangerouslySkipPermissions is set; the flag now only enables switching to bypassPermissions later
  • Updated to parity with Claude Code v2.1.269

v0.3.268

Compare Source

  • Added result_index to result messages: the result's position in delivery order within the run, from 0
  • Added local_command to the result message of a turn that ran a slash command without entering the model loop, carrying the command's name
  • Added hold_on_cache_impact to the reload_plugins control request (Query.reloadPlugins({ holdOnCacheImpact: true })): holds a reload that would invalidate the session's prompt cache
  • Added resume_reason to assistant, stream-event and result messages, set only on the automatic re-run of a turn a host restart interrupted
  • Added kind (used, free, buffer, deferred) to each category in the get_context_usage control response, matching the /context result's context_usage rows
  • Added optional defaultToNo and suppressAlwaysAllowRule hints to canUseTool options: the prompt should open on its decline option, or offer no persistent "always allow" choice
  • Changed setModel() to confirm a model id the CLI doesn't know locally with the API the first time a session uses it, instead of refusing it as unrecognized
  • Changed user_message_uuid on the automatic re-run of an interrupted turn to name that turn's last user prompt
  • Changed the initialize success response to always include pending_permission_requests (empty when nothing is pending), so clients can tell that apart from an older CLI
  • Changed the task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) to be default tools only on Claude 3.x, Opus 4.0–4.7, Sonnet 4.0–4.6 and Haiku 4.5; elsewhere list them in tools/allowedTools
  • Updated to parity with Claude Code v2.1.268

v0.3.267

Compare Source

  • Added getCcrEvent(query, message) and getSseLastSequenceNum(query) to the browser SDK's SSE transport, plus fromSequenceNum, onCatchUpTruncated and onDeliveryUpdate SSE options
  • Changed systemPrompt recording to default on for custom prompts and appends (a mid-session prompt change takes effect at the next compaction); pass snapshot: false to keep per-request rendering
  • Updated to parity with Claude Code v2.1.267

v0.3.266

Compare Source

  • Updated to parity with Claude Code v2.1.266

v0.3.265

Compare Source

  • Added user_message_uuid and user_message_uuids to a synthetic turn's first reply and result for a message sent with isSynthetic: true and a uuid, naming the message that started it
  • Added user_message_uuid and user_message_uuids to the first reply and the result of a turn Claude Code started itself, such as a resume, naming the messages you sent that it picked up mid-turn
  • Fixed user_message_uuid missing from the success result of a turn that sent no API request, such as a slash command
  • Fixed multi-turn sessions resetting the shell working directory to the cwd option at each new user message; a cd made by the agent now persists across turns, as in the interactive app
  • Changed user_message_uuid to be set on the first reply after each change of the message a turn is answering, instead of on one reply frame per turn
  • Updated to parity with Claude Code v2.1.265

v0.3.263

Compare Source

  • Updated to parity with Claude Code v2.1.263

v0.3.261

Compare Source

  • Added pluginDelivery: 'initialize' to send plugins over stdin so the launch command line no longer grows with the plugin count (fixes Windows start failures with many plugins)
  • Fixed query() throwing "Object not disposable" in runtimes without a native Symbol.dispose, such as Node ≤22 vm contexts (Jest's node environment, vitest vmThreads/vmForks) and Node <18.18
  • Updated to parity with Claude Code v2.1.261

v0.3.260

Compare Source

  • Added optional user_message_uuid to thinking_tokens system messages, linking thinking progress to the user message that triggered the turn
  • Added optional first_content_frame_ms, first_stream_post_ms, first_stream_post_ack_ms and first_stream_post_wall_ms fields to the success result message for remote-session latency breakdowns
  • Fixed managedSettings disableAutoMode: "disable" (either spelling) being dropped by the restrictive-only filter instead of turning auto mode off for the spawned session
  • Fixed rewindFiles() reporting success when no files could be restored (for example when checkpoint backups are missing); it now fails
  • Changed error_max_structured_output_retries results to append the last StructuredOutput tool error; validation errors now name the offending key, allowed values, and actual length or count
  • Changed rate_limit_event to also re-emit during an exceeded window on repeat 429s (about once per 30 seconds per limit window), so stream consumers can refresh stale rate-limit state
  • Updated to parity with Claude Code v2.1.260

v0.3.259

Compare Source

  • Added user_message_uuids beside user_message_uuid on a turn's first reply frame and result: every user message the turn answered, so a reply to several merged messages can be matched to each
  • Added permissionPrompts: 'none' option to auto-deny permission prompts in sessions with nobody to answer them, without disabling auto mode's classifier
  • Updated to parity with Claude Code v2.1.259

v0.3.258

Compare Source

  • Updated to parity with Claude Code v2.1.258

v0.3.257

Compare Source

  • Added thinkingTokens to ModelUsage (a subset of outputTokens), and fixed result-message usage.output_tokens_details.thinking_tokens reporting 0 instead of the session's real count
  • Added tool_use_result.resourceLinks on user messages carrying MCP tool results: the resource_link blocks the tool returned, so hosts can render returned files without parsing the result text
  • Added optional resource_links to task_notification for an auto-backgrounded MCP tool call that completed, listing the files it returned by reference; join to the call via tool_use_id
  • Fixed mcp_reconnect and mcp_toggle acting on a same-named .mcp.json / ~/.claude.json server instead of the --mcp-config or mcp_set_servers one
  • Fixed mcp_toggle disable also removing the tools of a sibling MCP server whose name extends the disabled one's (disabling foo dropped foo__bar's tools)
  • Changed mcp_set_servers to also list a server whose connection attempt throws under added (with a failed row in mcp_status), not only under errors
  • Changed Agent tool calls to emit the periodic tool_progress heartbeat (heartbeat: true) like other long tools; heartbeat frames never clear a subagent_retry indicator
  • Fixed the browser SDK bundle (@anthropic-ai/claude-agent-sdk/browser) never streaming any messages on engines without native Symbol.dispose (Safari/iOS, Firefox ESR, older Chromium)
  • Fixed a background Bash task that is still running when a stream-json session ends right after an interrupt (stdin closed) never receiving its final task_notification
  • Fixed -p giving up on a long-running background subagent without actually stopping it, so background_tasks_changed kept listing it and events for it arrived after its stopped notification
  • Added detail option to Query.getContextUsage(): 'summary' answers from the last response's usage and local estimates without per-category token-count API calls (default 'full')
  • Updated to parity with Claude Code v2.1.257

v0.3.252

Compare Source

  • Updated to parity with Claude Code v2.1.252

v0.3.251

Compare Source

  • Updated to parity with Claude Code v2.1.251

v0.3.250

Compare Source

  • Updated to parity with Claude Code v2.1.250

v0.3.248

Compare Source

  • Added a per-server timeout for SDK-hosted MCP servers (createSdkMcpServer({ timeout })), overriding MCP_TOOL_TIMEOUT for that server's tool calls

v0.3.247

Compare Source

  • Added an optional ambient flag to task_started, task_notification and background_tasks_changed task entries so hosts can exclude housekeeping tasks from activity indicators
  • Fixed the permissionMode on per-turn system/init frames reporting the mode at turn start instead of the live mode, so a mode switch right after submitting no longer sends a stale value

v0.3.246

Compare Source

  • Added optional user_message_uuid to error result messages and to the first assistant message or stream_event of each turn, linking a reply or failure to the user message that triggered it
  • Added modelUsage[*].costBasis ('list' | 'managed' | 'unknown') reporting which price table each model's costUSD was computed from
  • Added modelPricing support in the managedSettings option for hosts that set CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST; an admin-managed settings source that sets modelPricing still wins
  • Added perTaskStopAffordance option: when set, interrupt() aborts only the current turn and keeps background agents and workflows running; otherwise (and for one-shot string prompts) they stop

v0.3.245

Compare Source

  • Updated to parity with Claude Code v2.1.245

v0.3.243

  • Added optional queued_turn_count to result messages: the number of queued user sends still pending when the result was produced, so hosts know whether another turn and result will follow
  • Fixed mcp_status reporting a remote MCP server as connected after its connection dropped; it now reports pending while reconnecting, then connected or failed
  • Fixed managed disableAllHooks also disabling hook callbacks registered through the hooks option; they now keep running, matching allowManagedHooksOnly
  • Changed Read tool PDF results: the document block (or page image blocks for pages reads) now arrives inside the tool_result content instead of as a separate user message after it
  • Updated to parity with Claude Code v2.1.243

v0.3.242

  • Updated to parity with Claude Code v2.1.242

v0.3.241

Compare Source

  • Updated to parity with Claude Code v2.1.241

[v0.3.240](https://redirect.github.com/anthro

Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/Phoenix)

  • Branch creation
    • "before 6am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Aug 10, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
❌ Deployment failed
View logs
loopover-ui 11c5293 Sep 18 2026, 06:53 AM

@codecov

codecov Bot commented Aug 10, 2026

Copy link
Copy Markdown

⚠️ JUnit XML file not found

The CLI was unable to find any JUnit XML files to upload.
For more help, visit our troubleshooting guide.

@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 5b9e1bb to 6120b8c Compare August 10, 2026 13:04
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 6120b8c to 2b9cf39 Compare August 10, 2026 17:56
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 2b9cf39 to 0c5024c Compare August 10, 2026 22:16
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 0c5024c to 73830c8 Compare August 11, 2026 01:17
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 73830c8 to 53cdbf8 Compare August 11, 2026 04:50
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 53cdbf8 to 2b3206d Compare August 11, 2026 21:17
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 2b3206d to 7e07ff7 Compare August 12, 2026 05:56
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 7e07ff7 to 6d1860c Compare August 12, 2026 15:17
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 6d1860c to 8246cab Compare August 16, 2026 11:18
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 8246cab to 4bf978f Compare August 16, 2026 12:40
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 4bf978f to c35fbf6 Compare August 16, 2026 17:38
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from c35fbf6 to e67f676 Compare August 16, 2026 20:59
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from e67f676 to 264b992 Compare August 17, 2026 02:56
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 8b4e40a to 5bcb4d4 Compare August 23, 2026 10:34
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 5bcb4d4 to f9bc6f3 Compare August 23, 2026 13:45
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from f9bc6f3 to 7c0adb0 Compare August 23, 2026 21:02
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 7c0adb0 to 3ce9dfc Compare August 24, 2026 03:40
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 3ce9dfc to 79d4646 Compare August 24, 2026 10:00
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 79d4646 to bf45ebf Compare August 25, 2026 17:51
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from bf45ebf to 27819f5 Compare August 26, 2026 00:11
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 27819f5 to 2632feb Compare August 26, 2026 03:47
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch 2 times, most recently from 12f7e58 to e7b6693 Compare August 26, 2026 23:13
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from e7b6693 to 924fe96 Compare August 27, 2026 08:43
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 924fe96 to 3de850f Compare August 27, 2026 17:57
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 3de850f to ec559db Compare August 27, 2026 22:54
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from ec559db to f466077 Compare August 28, 2026 03:41
@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@renovate

renovate Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: package-lock.json
npm error Cannot read properties of null (reading 'edgesOut')
npm error A complete log of this run can be found in: /runner/cache/others/npm/_logs/2026-09-18T06_51_48_345Z-debug-0.log

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant