deps(deps): bump the npm-all-updates group with 10 updates - #66
deps(deps): bump the npm-all-updates group with 10 updates#66dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the npm-all-updates group with 10 updates: | Package | From | To | | --- | --- | --- | | [@ai-sdk/openai](https://github.com/vercel/ai/tree/HEAD/packages/openai) | `3.0.88` | `3.0.91` | | [@ai-sdk/provider-utils](https://github.com/vercel/ai/tree/HEAD/packages/provider-utils) | `4.0.40` | `4.0.42` | | [@ai-sdk/openai-compatible](https://github.com/vercel/ai/tree/HEAD/packages/openai-compatible) | `2.0.62` | `2.0.64` | | [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) | `2.5.5` | `2.5.7` | | [@rollup/rollup-darwin-arm64](https://github.com/rollup/rollup) | `4.62.3` | `4.62.4` | | [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `6.0.236` | `6.0.246` | | [globals](https://github.com/sindresorhus/globals) | `17.8.0` | `17.9.0` | | [tsx](https://github.com/privatenumber/tsx) | `4.23.1` | `4.23.11` | | [ultracite](https://github.com/haydenbleasel/ultracite) | `7.9.4` | `7.10.1` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.1.5` | `8.2.1` | Updates `@ai-sdk/openai` from 3.0.88 to 3.0.91 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/@ai-sdk/openai@3.0.91/packages/openai/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/openai@3.0.91/packages/openai) Updates `@ai-sdk/provider-utils` from 4.0.40 to 4.0.42 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/@ai-sdk/provider-utils@4.0.42/packages/provider-utils/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/provider-utils@4.0.42/packages/provider-utils) Updates `@ai-sdk/openai-compatible` from 2.0.62 to 2.0.64 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/@ai-sdk/openai-compatible@2.0.64/packages/openai-compatible/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/openai-compatible@2.0.64/packages/openai-compatible) Updates `@biomejs/biome` from 2.5.5 to 2.5.7 - [Release notes](https://github.com/biomejs/biome/releases) - [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md) - [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.7/packages/@biomejs/biome) Updates `@rollup/rollup-darwin-arm64` from 4.62.3 to 4.62.4 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md) - [Commits](rollup/rollup@v4.62.3...v4.62.4) Updates `ai` from 6.0.236 to 6.0.246 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/ai@6.0.246/packages/ai/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/ai@6.0.246/packages/ai) Updates `globals` from 17.8.0 to 17.9.0 - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v17.8.0...v17.9.0) Updates `tsx` from 4.23.1 to 4.23.11 - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](privatenumber/tsx@v4.23.1...v4.23.11) Updates `ultracite` from 7.9.4 to 7.10.1 - [Release notes](https://github.com/haydenbleasel/ultracite/releases) - [Commits](https://github.com/haydenbleasel/ultracite/compare/ultracite@7.9.4...ultracite@7.10.1) Updates `vite` from 8.1.5 to 8.2.1 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.2.1/packages/vite) --- updated-dependencies: - dependency-name: "@ai-sdk/openai" dependency-version: 3.0.91 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-all-updates - dependency-name: "@ai-sdk/provider-utils" dependency-version: 4.0.42 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-all-updates - dependency-name: "@ai-sdk/openai-compatible" dependency-version: 2.0.64 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-all-updates - dependency-name: "@biomejs/biome" dependency-version: 2.5.7 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-all-updates - dependency-name: "@rollup/rollup-darwin-arm64" dependency-version: 4.62.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-all-updates - dependency-name: ai dependency-version: 6.0.246 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-all-updates - dependency-name: globals dependency-version: 17.9.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-all-updates - dependency-name: tsx dependency-version: 4.23.11 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-all-updates - dependency-name: ultracite dependency-version: 7.10.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-all-updates - dependency-name: vite dependency-version: 8.2.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-all-updates ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Superseded by #67. This grouped update cannot be merged as generated: Dependency Review found three high-severity advisories from the introduced |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
## Summary - carry forward the 10 current patch/minor toolchain and AI SDK updates from Dependabot #66 - force `undici` 6.28.0 instead of the newly introduced vulnerable 5.29.0 tree - force `esbuild` 0.28.1 instead of the vulnerable 0.27.7 transitive copy - apply Biome 2.5.7's deterministic formatting changes - add a zero-tolerance `pnpm audit` CI job and remove an unused `pull-requests: write` permission ## Security rationale Dependency Review correctly blocked #66 because it introduced three high-severity Undici advisories (`GHSA-v9p9-hfj2-hcw8`, `GHSA-vrm6-8vpv-qv8q`, and `GHSA-vxpw-j846-p89q`). The override is safe for this Node >=20 project and was exercised by the full runtime/test suite. The esbuild override also removes `GHSA-g7r4-m6w7-qqqr` rather than accepting a low-severity residual. ## Validation - `pnpm install --frozen-lockfile` - `pnpm audit`: **No known vulnerabilities found** - `pnpm verify`: Biome, publication check, TypeScript, full tests, and build passed - `pnpm test -- --coverage`: passed - `pnpm why undici`: only 6.28.0 - lockfile contains neither `undici@5.29.0` nor `esbuild@0.27.7` - actionlint 1.7.12 - Gitleaks 8.30.1: no findings - immutable action reference and diff checks No audit, lint, test, or dependency-review gate is suppressed. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Doeon Kim <215626042+KIM3310@users.noreply.github.com>
Bumps the npm-all-updates group with 10 updates:
3.0.883.0.914.0.404.0.422.0.622.0.642.5.52.5.74.62.34.62.46.0.2366.0.24617.8.017.9.04.23.14.23.117.9.47.10.18.1.58.2.1Updates
@ai-sdk/openaifrom 3.0.88 to 3.0.91Release notes
Sourced from @ai-sdk/openai's releases.
Changelog
Sourced from @ai-sdk/openai's changelog.
Commits
e038ca4Version Packages (#18565)006a2f8Version Packages (#18089)98d8c43Version Packages (#18028)23632b1[v6.0] feat: support blocked domains in OpenAI web search (#18035)Updates
@ai-sdk/provider-utilsfrom 4.0.40 to 4.0.42Release notes
Sourced from @ai-sdk/provider-utils's releases.
Changelog
Sourced from @ai-sdk/provider-utils's changelog.
Commits
e038ca4Version Packages (#18565)ee2bf30[v6.0] fix(provider-utils): preserve Metro compatibility (#18559)006a2f8Version Packages (#18089)9ecdefe[v6] fix(provider-utils): prevent DNS alias SSRF in validated downloads (#18095)Updates
@ai-sdk/openai-compatiblefrom 2.0.62 to 2.0.64Release notes
Sourced from @ai-sdk/openai-compatible's releases.
Changelog
Sourced from @ai-sdk/openai-compatible's changelog.
Commits
e038ca4Version Packages (#18565)006a2f8Version Packages (#18089)Updates
@biomejs/biomefrom 2.5.5 to 2.5.7Release notes
Sourced from @biomejs/biome's releases.
... (truncated)
Changelog
Sourced from @biomejs/biome's changelog.
... (truncated)
Commits
191d051ci: release (#11119)9847e68feat(lint): add noNonScalableViewport rule (#11168)e63354cfeat(lint): add noExtendNative nursery rule (#11136)2fa0a62docs: rework CLI (#11134)e007143feat(lint): add nursery rule noTailwindArbitraryValue (#10094)c171b3bfeat(lint): add ignoreIfStatements option to useNullishCoalescing (#10822)1139f1cci: release (#11022)781d68dfeat(lint/js): addnoRestrictedProperties(#9806)Updates
@rollup/rollup-darwin-arm64from 4.62.3 to 4.62.4Release notes
Sourced from @rollup/rollup-darwin-arm64's releases.
Changelog
Sourced from @rollup/rollup-darwin-arm64's changelog.
Commits
ddc4ffa4.62.486d1710Update audit resolve7beedfaci: fix linux-gnu glibc regression and enforce glibc ≤ 2.28 compatibility (#6...9c2c58ddocs: add llms.txt documentation index for LLMs and agents (#6463)dc69288chore(deps): lock file maintenance (#6466)5ee0821chore(deps): lock file maintenance (#6465)4501389fix(deps): update minor/patch updates (#6464)Updates
aifrom 6.0.236 to 6.0.246Release notes
Sourced from ai's releases.
Changelog
Sourced from ai's changelog.
... (truncated)
Commits
e038ca4Version Packages (#18565)9607861Version Packages (#18557)0de0715[v6.0] fix: prevent incomplete tool calls from blocking follow-up model reque...6b43f42Version Packages (#18491)79e58aa[v6.0] fix: preserve preceding assistant messages when regenerating consecuti...5be723dVersion Packages (#18450)dd5d344[v6.0] fix: prevent aborted tool history from blocking follow-up messages (#1...4dfd1b5Version Packages (#18429)5b4cf0eVersion Packages (#18345)b878ce9Version Packages (#18314)Updates
globalsfrom 17.8.0 to 17.9.0Release notes
Sourced from globals's releases.
Commits
8e7b93517.9.05a958edUpdate globals (2026-08-01) (#348)Updates
tsxfrom 4.23.1 to 4.23.11Release notes
Sourced from tsx's releases.
... (truncated)
Commits
bd3bc64test: cover CommonJS loader source fallback55cbecefix: preserve async ESM require fallback6c5ba85docs: document CommonJS default interopec1bcd5fix: support nyc coverage discovery (#710)b6e5b48docs: clarify CommonJS default imports2f55884fix: map Node test locationsde935d5docs: document Node source-map stack formattingb94f46ffix: support data URLs in tsImportbe1315efix: preserve package subpath resolution5efba41docs: organize transform backend researchUpdates
ultracitefrom 7.9.4 to 7.10.1Release notes
Sourced from ultracite's releases.
Commits
832cb7cVersion Packages (#761)d018b7fSplit the CLI bug-scan changeset into per-fix patch changesets0dce9f8Fix CLI bugs found in code audit36c7b80Move@typescript-eslint/utilsto devDependenciesf943483Version Packages (#756)74e671dAdd video package with the Ultracite 7.10 fix --codex release videoe089510Scope framework-specific react-doctor rules to oxlint/next/js-plugins and oxl...cd0a36cAdd --claude and --codex flags to ultracite fix (#760)477cd6eUpdate ESLint and plugins to latest versions9ec454aUpdate oxlint to 1.76.0 and oxfmt to 0.61.0Updates
vitefrom 8.1.5 to 8.2.1Release notes
Sourced from vite's releases.
Changelog
Sourced from vite's changelog.
... (truncated)
Commits
4216158release: v8.2.1fddf4eafix(server): use a random port when port is 0 (#23158)de041a7fix(css): don't re-run lightningcss visitor during minify (fix #23146) (#23147)15f0307fix(build): make client chunkImportMap work withsharedPlugins: true(#23184)c2155fetest(bundled-dev): enable sourcemap playgrounds (#23080)ef02435docs(build): fix incomplete@defaultfor build.minify (#23177)eac0cc8fix(bundled-dev): inject client script tag before chunk scripts (#23161)23b8a08refactor(bundled-dev): avoid injecting server values in the bundle (#22967)e72036erefactor(bundled-dev): remove rolldown lazy stub module workaround (#23129)14454fdfix(deps): update all non-major dependencies (#23136)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions