Skip to content

chore(deps): bump @anthropic-ai/sdk from 0.109.1 to 0.111.0 - #68

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/anthropic-ai/sdk-0.111.0
Closed

chore(deps): bump @anthropic-ai/sdk from 0.109.1 to 0.111.0#68
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/anthropic-ai/sdk-0.111.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 13, 2026

Copy link
Copy Markdown
Contributor

Bumps @anthropic-ai/sdk from 0.109.1 to 0.111.0.

Release notes

Sourced from @​anthropic-ai/sdk's releases.

sdk: v0.111.0

0.111.0 (2026-07-10)

Full Changelog: sdk-v0.110.0...sdk-v0.111.0

Features

  • api: add support for dreaming (77b28a6)
  • tools: gate session tool calls on evaluated_permission; bound idle by server stop_reason (68a6d7b)

Chores

  • docs: small updates to field descriptions (e25b885)
  • docs: update model example (a33f3f0)
  • docs: updates to descriptions and examples (eac4bac)

sdk: v0.110.0

0.110.0 (2026-07-02)

Full Changelog: sdk-v0.109.1...sdk-v0.110.0

Features

  • api: add agent-memory-2026-07-22 beta header (a470e10)
Changelog

Sourced from @​anthropic-ai/sdk's changelog.

0.111.0 (2026-07-10)

Full Changelog: sdk-v0.110.0...sdk-v0.111.0

Features

  • api: add support for dreaming (77b28a6)
  • tools: gate session tool calls on evaluated_permission; bound idle by server stop_reason (68a6d7b)

Chores

  • docs: small updates to field descriptions (e25b885)
  • docs: update model example (a33f3f0)
  • docs: updates to descriptions and examples (eac4bac)

0.110.0 (2026-07-02)

Full Changelog: sdk-v0.109.1...sdk-v0.110.0

Features

  • api: add agent-memory-2026-07-22 beta header (a470e10)
Commits
  • 9e46760 chore: release main
  • 8d461ea feat(api): add support for dreaming
  • 9436e29 codegen metadata
  • 0aec1e7 feat(tools): gate session tool calls on evaluated_permission; bound idle by s...
  • ac2fc67 chore(docs): update model example
  • c8af65d chore(docs): updates to descriptions and examples
  • 2a3a904 codegen metadata
  • 57c56c9 chore(docs): small updates to field descriptions
  • 4f2eb80 chore: release main (#1107)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) from 0.109.1 to 0.111.0.
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.109.1...sdk-v0.111.0)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.111.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 13, 2026
@github-actions

Copy link
Copy Markdown

🛡️ supply-chain-guard Scan Report

Property Value
Target .
Type directory
Time 2026-07-13T02:24:57.371Z
Duration 216ms
Risk Score 14/100 (MEDIUM)

Summary

Scanned 70 of 80 files.

🟡 2 medium | 🔵 2 low

Findings

🟡 [MEDIUM] Workflow requests OIDC id-token:write permission. If combined with unreviewed third-party actions or outbound curl, an attacker can steal the OIDC token to impersonate the workflow's cloud identity.

  • Rule: GHA_OIDC_WRITE_PERM
  • File: .github/workflows/ci.yml:49
  • Match: id-token: write
  • Recommendation: Audit all steps in this workflow when id-token:write is set. Ensure no third-party action or run step can exfiltrate the OIDC token. Scope permissions as narrowly as possible.

🟡 [MEDIUM] Workflow "ci.yml" accesses secrets and has network egress. Verify secrets are not sent to external endpoints.

  • Rule: WORKFLOW_SECRET_TO_UPLOAD_PATH
  • File: .github/workflows/ci.yml
  • Recommendation: Audit this workflow for secret-to-network paths. Minimize secret scoping.

🔵 [LOW] Action "homeofe/supply-chain-guard@v5" uses a version tag instead of a commit SHA. Tags can be force-pushed to point to different commits.

  • Rule: GHA_TAG_NOT_SHA
  • File: .github/workflows/supply-chain-guard.yml:21
  • Match: homeofe/supply-chain-guard@v5
  • Recommendation: Consider pinning this action to a full commit SHA for maximum security. Tags can be moved to point to malicious code.

🔵 [LOW] Action "homeofe/supply-chain-guard@v5" is from third-party owner "homeofe". Third-party actions can be compromised.

  • Rule: GHA_THIRD_PARTY_ACTION
  • File: .github/workflows/supply-chain-guard.yml:21
  • Match: homeofe/supply-chain-guard@v5
  • Recommendation: Pin "homeofe/supply-chain-guard@v5" to a specific commit SHA and audit the action source code before use.

Recommendations

  • Review the listed findings and assess whether they represent legitimate functionality or potential threats.

Generated by supply-chain-guard

@dependabot @github

dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #77.

@dependabot dependabot Bot closed this Jul 20, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/anthropic-ai/sdk-0.111.0 branch July 20, 2026 02:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants