Skip to content

fix(deps): update all non-major dependencies - #57

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

fix(deps): update all non-major dependencies#57
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Apr 18, 2026

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
@ai-sdk/openai (source) 3.0.93.0.90 age confidence dependencies patch
@ai-sdk/valibot (source) 2.0.52.0.42 age confidence dependencies patch
@biomejs/biome (source) 2.3.142.5.6 age confidence devDependencies minor
@cloudflare/vitest-pool-workers (source) ^0.12.0^0.20.0 age confidence devDependencies minor
@cloudflare/workers-types 4.20260113.04.20260702.1 age confidence devDependencies minor
@crxjs/vite-plugin (source) 2.3.02.7.1 age confidence devDependencies minor
@fontsource-variable/inter (source) 5.2.85.3.0 age confidence dependencies minor
@fontsource/geist-mono (source) 5.2.75.3.0 age confidence dependencies minor
@playwright/test (source) 1.57.01.62.1 age confidence devDependencies minor
@radix-ui/react-avatar (source) 1.1.111.2.6 age confidence dependencies minor
@radix-ui/react-checkbox (source) 1.3.31.3.11 age confidence dependencies patch
@radix-ui/react-collapsible (source) 1.1.121.1.20 age confidence dependencies patch
@radix-ui/react-context-menu (source) 2.2.162.3.7 age confidence dependencies minor
@radix-ui/react-dialog (source) 1.1.151.1.23 age confidence dependencies patch
@radix-ui/react-dropdown-menu (source) 2.1.162.1.24 age confidence dependencies patch
@radix-ui/react-label (source) 2.1.82.1.15 age confidence dependencies patch
@radix-ui/react-popover (source) 1.1.151.1.23 age confidence dependencies patch
@radix-ui/react-progress (source) 1.1.81.1.16 age confidence dependencies patch
@radix-ui/react-scroll-area (source) 1.2.101.2.18 age confidence dependencies patch
@radix-ui/react-select (source) 2.2.62.3.7 age confidence dependencies minor
@radix-ui/react-separator (source) 1.1.81.1.15 age confidence dependencies patch
@radix-ui/react-slot (source) 1.2.41.3.3 age confidence dependencies minor
@radix-ui/react-switch (source) 1.2.61.3.7 age confidence dependencies minor
@radix-ui/react-tabs (source) 1.1.131.1.21 age confidence dependencies patch
@radix-ui/react-tooltip (source) 1.2.81.2.16 age confidence dependencies patch
@tailwindcss/vite (source) 4.1.184.3.3 age confidence devDependencies minor
@tanstack/devtools-vite (source) ^0.5.0^0.8.0 age confidence devDependencies minor
@tanstack/react-devtools (source) ^0.9.0^0.10.0 age confidence devDependencies minor
@tanstack/react-form (source) 1.27.71.33.2 age confidence dependencies minor
@tanstack/react-query (source) 5.90.165.101.4 age confidence dependencies minor
@tanstack/react-router (source) 1.156.01.170.18 age confidence dependencies minor
@tanstack/react-router-devtools (source) 1.156.01.167.0 age confidence devDependencies minor
@tanstack/router-plugin (source) 1.156.01.168.23 age confidence devDependencies minor
@testing-library/react 16.3.116.3.2 age confidence devDependencies patch
@types/chrome (source) ^0.1.32^0.2.0 age confidence devDependencies minor
@types/node (source) 25.0.725.9.5 age confidence devDependencies minor
@types/react (source) 19.2.819.2.18 age confidence devDependencies patch
@types/react-dom (source) 19.2.319.2.4 age confidence devDependencies patch
@typescript-eslint/eslint-plugin (source) 8.53.08.65.0 age confidence devDependencies minor
@typescript-eslint/parser (source) 8.53.08.65.0 age confidence devDependencies minor
@uiw/react-heat-map (source) 2.3.32.3.4 age confidence dependencies patch
@valibot/to-json-schema (source) 1.5.01.7.1 age confidence dependencies minor
@vitejs/plugin-react (source) 5.1.25.2.0 age confidence devDependencies minor
ai (source) 6.0.306.0.238 age confidence dependencies patch
ai-gateway-provider (source) 3.0.23.2.0 age confidence dependencies minor
better-auth-cloudflare ^0.2.9^0.3.0 age confidence dependencies minor
date-fns 4.1.04.4.0 age confidence dependencies minor
drizzle-kit (source) 0.31.80.31.10 age confidence devDependencies patch
eslint (source) 9.39.29.39.5 age confidence devDependencies patch
eslint-import-resolver-typescript 4.4.44.4.5 age confidence devDependencies patch
eslint-plugin-boundaries 5.3.15.4.0 age confidence devDependencies minor
filepond (source) 4.32.114.32.12 age confidence dependencies patch
jsdom 28.0.028.1.0 age confidence devDependencies minor
lucide-react (source) ^0.563.0^0.577.0 age confidence dependencies minor
miniflare (source) 4.20260107.04.20260730.0 age confidence pnpm.overrides minor
node (source) 24.13.024.18.1 age confidence volta minor
pnpm (source) 10.28.210.34.5 age confidence packageManager minor
react (source) 19.2.319.2.8 age confidence dependencies patch
react-day-picker (source) 9.13.09.14.0 age confidence dependencies minor
react-dom (source) 19.2.319.2.8 age confidence dependencies patch
recharts 3.6.03.10.1 age confidence dependencies minor
tailwind-merge 3.4.03.6.0 age confidence dependencies minor
tailwindcss (source) 4.1.184.3.3 age confidence devDependencies minor
tsx (source) 4.21.04.23.1 age confidence devDependencies minor
valibot (source) 1.2.01.4.2 age confidence dependencies minor
wrangler (source) 4.59.14.118.0 age confidence devDependencies minor

Release Notes

vercel/ai (@​ai-sdk/openai)

v3.0.90

Compare Source

Patch Changes

v3.0.89

Compare Source

Patch Changes
  • 23632b1: Add blocked domain filters to the OpenAI and Azure Responses API web search tools.

v3.0.88

Compare Source

Patch Changes
  • 8100830: Apply reasoning, service tier, and image defaults to recognizable future OpenAI model family versions.

v3.0.87

Compare Source

Patch Changes
  • 2f11af1: Preserve stored tool search output item IDs from provider metadata.

v3.0.86

Compare Source

Patch Changes

v3.0.85

Compare Source

Patch Changes

v3.0.84

Compare Source

Patch Changes
  • 356918c: feat(provider/openai): add GPT-5.6 reasoning and prompt cache controls

v3.0.83

Compare Source

v3.0.82

Compare Source

v3.0.81

Compare Source

v3.0.80

Compare Source

Patch Changes

v3.0.79

Compare Source

Patch Changes

v3.0.78

Compare Source

Patch Changes
  • 64a701d: Return a helpful error when the Responses stream parser receives Chat Completions chunks.

v3.0.77

Compare Source

Patch Changes

v3.0.76

Compare Source

Patch Changes

v3.0.75

Compare Source

Patch Changes

v3.0.74

Compare Source

Patch Changes
  • 466544d: feat(openai): add orchestration token usage details to Responses API usage

v3.0.73

Compare Source

Patch Changes
  • 1274c07: fix(provider/openai): send client-executed tool calls as full function_call items in the Responses API so they pair with their function_call_output by call_id

v3.0.72

Compare Source

Patch Changes

v3.0.71

Patch Changes

v3.0.69

Compare Source

Patch Changes
  • 9a55f6d: feat(openai): add namespaces for tool definitions

v3.0.68

Compare Source

Patch Changes
  • c65c952: fix(openai): round-trip namespace on function_call input items

    When tool_search dispatches a deferred tool, the resulting function_call carries a namespace field identifying which deferred-tool group the model picked. #14789 preserved this on the read side (providerMetadata.openai.namespace), but the write side still serialized function_call input items without namespace. Multi-step / multi-turn conversations then failed with Missing namespace for function_call '<name>'. ... Round-trip the model's function_call item with its namespace field included.

    convert-to-openai-responses-input.ts now reads namespace from providerOptions.openai.namespace (or providerMetadata.openai.namespace) on tool-call parts and includes it on the serialized function_call item, mirroring how itemId is round-tripped.

v3.0.67

Compare Source

Patch Changes
  • c679fec: feat(provider/azure):web search tool in the Azure OpenAI Responses API.

v3.0.66

Compare Source

Patch Changes
  • c82ab42: feat(openai): forward web_search_call.action.queries from Responses API

v3.0.65

Compare Source

Patch Changes
  • eb52378: fix(openai): skip passing reasoning items when using previous response id

v3.0.64

Compare Source

Patch Changes
  • b7ed8bd: feat(openai): add opt-in pass-through for unsupported file media types

v3.0.63

Compare Source

Patch Changes

v3.0.62

Compare Source

Patch Changes
  • 65edcca: feat: add allowedTools provider option for OpenAI Responses

v3.0.61

Compare Source

Patch Changes
  • b93f9b4: feat(provider/openai): forward imageDetail providerOptions on tool-result image content

v3.0.60

Compare Source

Patch Changes
  • 6dcd8e6: feat(openai): add GPT-5.5 chat model IDs

v3.0.59

Compare Source

Patch Changes
  • 38966ab: fix(openai, openai-compatible): only send null content for assistant messages with tool calls

v3.0.58

Compare Source

Patch Changes
  • 2370948: feat(openai): preserve namespace on function_call output items

v3.0.57

Compare Source

Patch Changes
  • d33e7cc: chore(provider/openai): add type for image model options for type-safe processing

v3.0.55

Compare Source

Patch Changes

v3.0.54

Compare Source

Patch Changes

v3.0.53

Compare Source

Patch Changes
  • 953385d: fix(openai): default undefined tool-call input to empty object before serializing tool arguments

v3.0.52

Compare Source

Patch Changes
  • d42076d: Add AI Gateway hint to provider READMEs

v3.0.51

Compare Source

Patch Changes

v3.0.50

Compare Source

Patch Changes

v3.0.49

Compare Source

Patch Changes
  • bc01093: fix(openai): support file-url parts in tool output content

v3.0.48

Compare Source

Patch Changes
  • 9c548de: Add gpt-5.4-mini, gpt-5.4-mini-2026-03-17, gpt-5.4-nano, and gpt-5.4-nano-2026-03-17 models.

  • bcb04df: fix(openai): preserve raw finish reason for failed responses stream events

    Handle response.failed chunks in Responses API streaming so finishReason.raw is preserved from incomplete_details.reason (e.g. max_output_tokens), and map failed-without-reason cases to unified error instead of other.

v3.0.47

Compare Source

Patch Changes

v3.0.46

Compare Source

Patch Changes
  • 75fc0e7: feat(openai): add new tool search tool

v3.0.45

Compare Source

Patch Changes
  • 023088c: feat(provider/openai): add gpt-5.3-chat-latest

v3.0.44

Compare Source

Patch Changes
  • f4a734a: fix(provider/openai): drop reasoning parts without encrypted content when store: false

v3.0.43

Compare Source

Patch Changes

v3.0.42

Compare Source

Patch Changes
  • 2589004: feat(provider/openai): add GPT-5.4 model support

v3.0.41

Compare Source

Patch Changes

v3.0.40

Compare Source

Patch Changes

v3.0.39

Compare Source

Patch Changes

v3.0.38

Compare Source

Patch Changes
  • 64a8fae: chore: remove obsolete model IDs for Anthropic, Google, OpenAI, xAI

v3.0.37

Compare Source

Patch Changes

v3.0.36

Compare Source

Patch Changes
  • 53bdfa5: fix(openai): allow null/undefined type in streaming tool call deltas

    Azure AI Foundry and Mistral deployed on Azure omit the type field in
    streaming tool_calls deltas. The chat stream parser now accepts a missing
    type field (treating it as "function") instead of throwing
    InvalidResponseDataError: Expected 'function' type.

    Fixes #​12770

v3.0.35

Compare Source

Patch Changes
  • 5e18272: fix(openai): include reasoning parts without itemId when encrypted_content is present

    When providerOptions.openai.itemId is absent on a reasoning content part,
    the converter now uses encrypted_content as a fallback instead of silently
    skipping the part with a warning. The OpenAI Responses API accepts reasoning
    items without an id when encrypted_content is supplied, enabling
    multi-turn reasoning even when item IDs are stripped from provider options.

    Also makes the id field optional on the OpenAIResponsesReasoning type to
    reflect that the API does not require it.

    Fixes #​12853

v3.0.34

Compare Source

Patch Changes
  • 66a374c: Support phase parameter on Responses API message items. The phase field ('commentary' or 'final_answer') is returned by models like gpt-5.3-codex on assistant message output items and must be preserved when sending follow-up requests. The phase value is available in providerMetadata.openai.phase on text parts and is automatically included on assistant messages sent back to the API.

v3.0.33

Compare Source

Patch Changes
  • 624e651: Added missing model IDs to OpenAIChatModelId, OpenAIResponsesModelId, OpenAIImageModelId, OpenAISpeechModelId, OpenAITranscriptionModelId, and OpenAICompletionModelId types for better autocomplete support.

v3.0.32

Compare Source

Patch Changes
  • 0c9395b: feat(provider/openai): add gpt-5.3-codex

[`v3.0.

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@socket-security

socket-security Bot commented Apr 18, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​ai-sdk/​openai@​3.0.9 ⏵ 3.0.9066 -610088 +398100
Updated@​radix-ui/​react-label@​2.1.8 ⏵ 2.1.15100 +110066 +199100
Updated@​radix-ui/​react-separator@​1.1.8 ⏵ 1.1.1570 -291006699 +1100
Updated@​radix-ui/​react-progress@​1.1.8 ⏵ 1.1.16100 +110068 +199100
Updated@​radix-ui/​react-slot@​1.2.3 ⏵ 1.3.3100 +110069 +199100
Updated@​radix-ui/​react-avatar@​1.1.11 ⏵ 1.2.69910069 +199100
Updated@​radix-ui/​react-collapsible@​1.1.12 ⏵ 1.1.2099 +110069 +199100
Updated@​radix-ui/​react-tabs@​1.1.13 ⏵ 1.1.2199 +110070 +199100
Updated@​radix-ui/​react-switch@​1.2.6 ⏵ 1.3.799 +110070 +299100
Updated@​radix-ui/​react-checkbox@​1.3.3 ⏵ 1.3.1199 +110071 +199100
Updated@​radix-ui/​react-dropdown-menu@​2.1.16 ⏵ 2.1.2499 +11007199100
Updated@​radix-ui/​react-popover@​1.1.15 ⏵ 1.1.2399 +11007199100
Updated@​radix-ui/​react-context-menu@​2.2.16 ⏵ 2.3.7100 +11007199100
Updated@​radix-ui/​react-dialog@​1.1.15 ⏵ 1.1.2399 +11007199100
Updated@​tanstack/​react-router-devtools@​1.156.0 ⏵ 1.167.07410071 +194 -5100
Updated@​typescript-eslint/​parser@​8.53.0 ⏵ 8.65.010010072 +198100
Updated@​radix-ui/​react-tooltip@​1.2.8 ⏵ 1.2.169910072 +199100
Updated@​radix-ui/​react-scroll-area@​1.2.10 ⏵ 1.2.1899 +110072 +199100
Updated@​radix-ui/​react-select@​2.2.6 ⏵ 2.3.79910073 +199100
Updated@​types/​react-dom@​19.2.3 ⏵ 19.2.410010075 +184100
Updatedai@​6.0.30 ⏵ 6.0.23875 -2310010099100
Updated@​tanstack/​react-router@​1.156.0 ⏵ 1.170.1875 -31008397 -2100
Updated@​tanstack/​router-plugin@​1.156.0 ⏵ 1.168.2399 +110078 +198100
Updated@​types/​react@​19.2.8 ⏵ 19.2.1810010079 +192100
Updated@​ai-sdk/​valibot@​2.0.5 ⏵ 2.0.4281 +31007998 +1100
Updatedrecharts@​3.6.0 ⏵ 3.10.180 +1100100 +297 +2100
Updated@​typescript-eslint/​eslint-plugin@​8.53.0 ⏵ 8.65.09910080 +198100
Updated@​types/​node@​25.0.7 ⏵ 25.9.5100 +11008195 -1100
Updatedjsdom@​28.0.0 ⏵ 28.1.081 +1100100 +196 +5100
Updatedtsx@​4.21.0 ⏵ 4.23.110010081 +192100
Updateddate-fns@​4.1.0 ⏵ 4.4.0100 +11009283100
Updated@​fontsource-variable/​inter@​5.2.8 ⏵ 5.3.0100100848390
See 25 more rows in the dashboard

View full report

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 20 times, most recently from dcf78d4 to 033a411 Compare April 25, 2026 17:11
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 9 times, most recently from 9f368fc to abc438e Compare April 29, 2026 21:36
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 1a7bad6 to c91c888 Compare May 5, 2026 18:49
@socket-security

socket-security Bot commented May 5, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm eslint-plugin-boundaries is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/eslint-plugin-boundaries@5.4.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/eslint-plugin-boundaries@5.4.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm jsdom is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: packages/web/package.jsonnpm/jsdom@28.1.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/jsdom@28.1.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm rollup is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@crxjs/vite-plugin@2.7.1npm/rollup@2.80.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/rollup@2.80.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 13 times, most recently from c23fdd9 to 166f465 Compare May 11, 2026 22:27
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 13 times, most recently from c386f7b to dc2c62e Compare July 23, 2026 02:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants