Skip to content

chore(deps): bump the npm-minor-patch group across 1 directory with 14 updates - #2956

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-a0269f7bbf
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-a0269f7bbf

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-minor-patch group with 14 updates in the / directory:

Package From To
@comfyorg/sdk 0.1.7 0.4.0
@modelcontextprotocol/sdk 1.30.0 1.30.1
sharp 0.35.3 0.35.4
yaml 2.9.0 2.9.1
zod 4.4.3 4.6.5
tsx 4.23.12 4.23.15
@ai-sdk/anthropic 4.0.41 4.0.63
@ai-sdk/google 4.0.50 4.0.80
@ai-sdk/openai 4.0.46 4.0.75
@anthropic-ai/claude-agent-sdk 0.3.240 0.3.282
@aws-sdk/client-s3 3.1116.0 3.1140.0
@azure/storage-blob 12.33.0 12.34.0
@openai/codex 0.149.0 0.157.0
ai 7.0.77 7.0.114

Updates @comfyorg/sdk from 0.1.7 to 0.4.0

Release notes

Sourced from @​comfyorg/sdk's releases.

v0.4.0 — Router alt-provider controls

Adds the Comfy Router alt-provider controls to models.run, and the disclosure needed to tell an alt-provider run from a native one. Twin of comfy-sdk v0.4.0 (Python).

Added

  • modelProvider, strictMode and fallbackProvider on RunOptions — sent only when set, so a call that names none appends no query at all and is byte-for-byte the request this route always made.
  • servingProvider and droppedParams on RunResult, beside requestId, populated on every path including the queued one.
  • parseDroppedParams, FALLBACK_PROVIDER_HEADER and DROPPED_PARAMS_HEADER exported.

Why the new RunResult fields

With modelProvider, the response is translated back to the model's own native contract — so data is identical whether an alternate or the native provider served the call. X-Comfy-Router-Fallback-Provider is the only disclosure that they differed, and X-Comfy-Router-Dropped-Params the only disclosure that translating the request onto the alternate's schema could not carry a field.

Fixed

  • strict_mode was rendered with a truthiness test, so the string "false" — truthy in JS, and the exact spelling the sibling fallbackProvider option asks for — inverted the flag that decides whether the body is translated or passed through raw. Now an explicit === true.
  • fallbackProvider now accepts boolean | string and normalises the boolean. The server reads any value other than false as fallback ON, so "False", "0", "no" and "off" all type-checked and silently did the opposite.
  • queue_timeout is now in TERMINAL_ERROR_TYPES. It arrives on a 504, which the status >= 500 rule retried, so an admission timeout burned the whole retry budget re-asking the queue that had just said it could not admit the work.

Note for callers

Recovering a lost generation must resend these controls alongside idempotencyKey. A key's identity covers the query, so replaying without them presents the same key under a different query and leaves the generation uncollectable.

v0.3.0

comfy.models gains queued delivery and model discovery, and run no longer destroys a binary generation on the way back.

⚠️ Breaking

Types. RunResult is now a discriminated union: RunJsonResult (kind: "json") and the new RunBinaryResult (kind: "binary", data a Uint8Array, contentType the partner's own media type). A JSON result's runtime shape only gains kind, so existing code keeps running — but types need a narrowing:

const result = await comfy.models.run("bfl/flux-2-pro", { prompt });
if (result.kind === "json") result.data; // your TData again

Runtime. models.run now caps the response body it will buffer at 64 MiB by default, where it was previously unbounded — a larger result raises response_too_large instead of resolving. Nothing in the catalog returns that much today; if yours does, pass maxBytes: <larger> or maxBytes: null.

Added

  • comfy.models.submit / subscribe / handle — queue a request and collect it later, instead of holding one connection open for the whole generation. submit resolves to a RequestHandle with status(), get(), cancel() and async-iterable events(); subscribe is submit + poll + collect in one call. Preview-gated server-side — outside it, 403 not_enabled arrives as routerErrors.NotEnabled. (#133)
  • comfy.models.schema() / comfy.models.list() — ask Router what it runs and what each model takes. schema() sends a held etag as If-None-Match and resolves a 304 as an explicit { unchanged: true }; list() is async-iterable over the whole catalog, with list().page() for callers driving their own pagination. (#138)
  • maxBytes on models.run — per-call control of the cap above (see Breaking). DEFAULT_MAX_RESPONSE_BYTES is exported; null disables it. A breach raises code: "response_too_large" and is deliberately not retried. (#145)
  • routerErrors.errorFromCompletion(body, requestId) — the typed error a completed queued request reports, or null. (#133)

Fixed

  • A binary 200 no longer throws unexpected_response. The ElevenLabs audio models (elevenlabs/eleven_v3, elevenlabs/eleven_sfx_v2) were unusable: their bytes were UTF-8-decoded and JSON.parsed, destroying the generation after the server had run and billed it. run now reads Content-Type before touching the body. (#139)

Changed

... (truncated)

Changelog

Sourced from @​comfyorg/sdk's changelog.

Changelog

All notable changes to @comfyorg/sdk are documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

Entries for 0.1.0 through 0.1.7 were reconstructed from the published GitHub Release notes when this file was introduced; the releases themselves remain the authoritative record for those versions.

[Unreleased]

Added

  • Comfy Router alt-provider controls on comfy.models.run — modelProvider, strictMode and fallbackProvider. Three optional RunOptions fields, sent as the model_provider, strict_mode and fallback_provider query params on the synchronous run route. modelProvider selects an alternate serving provider (e.g. "fal"); strictMode (default false) toggles native ↔ provider translation, and true passes the provider's own raw shape both ways; fallbackProvider accepts "false" to opt out of provider-fallback. Each is sent ONLY when set, so a run that names none of the three is byte-for-byte the request it always was. These are run-route only — the queued submit/subscribe surface does not accept them.
  • Three queue-tier routerErrors classes — Cancelled, QueueTimeout and RequestNotFound — for the cancelled, queue_timeout and request_not_found buckets the vendored Router contract now declares, so a queued failure carrying one of them is a typed catch rather than a bare RouterError.

[0.3.0] - 2026-09-14

Added

  • Queued model delivery — comfy.models.submit, comfy.models.subscribe and comfy.models.handle. comfy.models.run holds one connection open until the generation is finished; submit returns a RequestHandle as soon as the server accepts the request, so a caller who cannot hold a connection for the length of a generation — a web request that has to return now, a worker that submits in one process and collects in another — can collect it later. The handle carries requestId, model, status(), get(), cancel() and an async-iterable events(); get() resolves to the same

... (truncated)

Commits
  • 21454a3 feat: add model_provider / strict_mode / fallback_provider to model run (#150)
  • 83c0c87 docs(changelog): cut 0.3.0, and put two entries back where they belong (#147)
  • 5aeed3a feat(models): cap the response body models.run will buffer (#145)
  • 0a3882c feat(models): add comfy.models.schema() and comfy.models.list() for Router di...
  • f886e03 fix(models): return a Router binary 200 as bytes instead of throwing unexpect...
  • 207d427 feat(models): queue a model request with submit, subscribe and handle (#133)
  • 9bb9ca9 ci: bump Comfy-Org/github-workflows/.github/workflows/cursor-review.yml (#141)
  • f2cc4f5 chore(deps): bump the npm-minor-and-patch group with 2 updates (#142)
  • ac7e49a chore: sync vendored Comfy Router spec from cloud@f42cd6e (#144)
  • 98e0612 chore(deps-dev): bump the npm-minor-and-patch group with 2 updates (#136)
  • Additional commits viewable in compare view

Updates @modelcontextprotocol/sdk from 1.30.0 to 1.30.1

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

1.30.1

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.0...1.30.1

Commits
  • 289ac2c chore: bump version to 1.30.1 (#2848)
  • 12b4256 fix(auth): preserve resource URI without trailing slash (#1968) (#1972)
  • a9f6eb7 [v1.x] fix(server): read HTTP request bodies with a size limit and bound JSON...
  • See full diff in compare view

Updates sharp from 0.35.3 to 0.35.4

Release notes

Sourced from sharp's releases.

v0.35.4

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3

v0.35.4-rc.0

Commits
  • 7f1a0a2 Release v0.35.4
  • f927818 Upgrade to sharp-libvips v1.3.3
  • e802092 Prerelease v0.35.4-rc.0
  • e13eb2f CI: Fix wasm32 build (#4589)
  • a82a0b3 Upgrade to libvips v8.18.6
  • 8044fe4 Bound resize dimensions to coordinate limit
  • 147f859 Docs: changelog entries for #4578 #4584
  • ee5bfb8 Tests: use yauzl directly rather than via extract-zip wrapper
  • 7a77889 Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (#4588)
  • ea5bef2 Improve support for input Streams finishing before output is requested (#4584)
  • Additional commits viewable in compare view

Updates yaml from 2.9.0 to 2.9.1

Release notes

Sourced from yaml's releases.

v2.9.1

  • Limit recursive merge aliases (#685, #713)
  • Simplify line unfolding during quoted string parsing (#714)
Commits

Updates zod from 4.4.3 to 4.6.5

Release notes

Sourced from zod's releases.

v4.6.5

Commits:

  • d2b135cfb7a3582b9eb515756b9166bcb9521f4a docs: add the 4.6.x patch highlights to the 4.6 post
  • f1448f7cee00df9fe1e9ad84a000aa1828cc8bc1 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • de65a5cb39ed22a507fac935788f718fa88d104f docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • 56222cd1532c07bcb91b67df529cab4c0a215330 feat(instanceof): key the .properties() shape off the instance type (#6600)
  • ca0229a404818290e6cdcfefcd7eb2d04bcbb543 Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)"
  • cc4cd4ee9c52fcaa10964e48cc144541e41a5ed9 Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)""
  • 0f3f5ee3ca56c7574bf849e54f79e9a6e02562ee 4.6.5
  • 59bbc03e10c636b9eb3c393dfeb552819774ec21 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump

v4.6.4

A patch on top of 4.6.3.

  • d6bc1e30 feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)
  • ad32d751 perf: z.url() rejects an invalid URL with URL.canParse() instead of a throwing constructor, about 50x faster; fewer allocations on the validation path (#6588)
  • 2bb08717 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • f6e1701a chore(deps): bump next to 15.5.25 and vite to 7.3.6 (#6153)

v4.6.3

A patch on top of 4.6.2.

  • 413cce9a fix(v4): make z.properties() a check again (#6594) — removes the standalone z.properties() schema from 4.6.0; z.instanceof().properties() and .check(...z.properties()) are unchanged
  • 75d63ee1 docs: show only the .properties() method form in the 4.6 post
  • 46da9572 docs: match the error-message examples to what the parsers emit

v4.6.2

A patch on top of 4.6.1.

v4.6.1

A patch on top of 4.6.0.

v4.6.0

Zod 4.6 is now available.

npm install zod@latest

At a glance:

... (truncated)

Commits
  • 59bbc03 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump
  • 0f3f5ee 4.6.5
  • cc4cd4e Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, ref...
  • ca0229a Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed w...
  • 56222cd feat(instanceof): key the .properties() shape off the instance type (#6600)
  • de65a5c docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • f1448f7 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • d2b135c docs: add the 4.6.x patch highlights to the 4.6 post
  • 2bb0871 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • 743aedb 4.6.4
  • Additional commits viewable in compare view

Updates tsx from 4.23.12 to 4.23.15

Release notes

Sourced from tsx's releases.

v4.23.15

4.23.15 (2026-09-20)

Bug Fixes

  • exclude bare builtins from namespace inheritance (38e1588)
  • expose require.cache and require.extensions to tsImport CommonJS modules (2da3407)
  • make namespaced register() overloads portable for declaration emit (562c434)

This release is also available on:

v4.23.14

4.23.14 (2026-09-20)

Bug Fixes

  • restore the CJS bridge namespace for Node 24 require(esm) under tsImport() (#802) (6e5236b)

This release is also available on:

v4.23.13

4.23.13 (2026-08-30)

Bug Fixes

  • cache: bound shared transform cache memory (#835) (28e1f12)

This release is also available on:

Commits
  • ca66105 test: fix drive-less file URLs in ESM resolver fixtures
  • 2da3407 fix: expose require.cache and require.extensions to tsImport CommonJS modules
  • 38e1588 fix: exclude bare builtins from namespace inheritance
  • 562c434 fix: make namespaced register() overloads portable for declaration emit
  • edfb1f0 build: upgrade pkgroll and externalize CJS loader reference
  • 70e7828 test: upgrade tinyspy for disposable API
  • 9ed2022 ci: avoid duplicate release notifications
  • 872e77f refactor: use disposables for cleanup
  • 6e5236b fix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...
  • 28e1f12 fix(cache): bound shared transform cache memory (#835)
  • See full diff in compare view

Updates @ai-sdk/anthropic from 4.0.41 to 4.0.63

Release notes

Sourced from @​ai-sdk/anthropic's releases.

@​ai-sdk/provider-utils@​4.0.55

Patch Changes

  • 3983fea: fix(provider): preserve media types on tool result file URLs and match full MIME types exactly when checking native URL support.
  • Updated dependencies [3983fea]
    • @​ai-sdk/provider@​3.0.18
Changelog

Sourced from @​ai-sdk/anthropic's changelog.

4.0.63

Patch Changes

  • 154221f: feat(anthropic): support on-demand compaction and preserve signed compaction blocks

4.0.62

Patch Changes

  • 771e74b: chore: enable dead code lint rules
  • Updated dependencies [fe07867]
  • Updated dependencies [a4b0940]
  • Updated dependencies [771e74b]
    • @​ai-sdk/provider-utils@​5.0.47

4.0.61

Patch Changes

  • 3733d6e: fix(anthropic): omit empty compaction blocks from replay
  • Updated dependencies [ffb0e76]
    • @​ai-sdk/provider@​4.0.18
    • @​ai-sdk/provider-utils@​5.0.46

4.0.60

Patch Changes

  • 49295bb: feat(anthropic): add Claude Opus 5.5 support

    • add the claude-opus-5-5 model ID to @ai-sdk/anthropic and anthropic/claude-opus-5.5 to @ai-sdk/gateway
    • models that always use adaptive thinking (claude-opus-5-5, claude-fable-5, claude-fable-5-1) no longer receive thinking: { type: 'disabled' } or budget-based thinking; the provider drops the unsupported setting, maps reasoning: 'none' to effort: 'low', and emits a warning
    • models that reject forced tool use (claude-opus-5-5, claude-fable-5-1) fall back to auto tool choice for required and named tool choices, and to native structured outputs when structuredOutputMode: 'jsonTool' is requested, each with a warning
    • add the computerToolset_20260801 computer use tool (computer_toolset_20260801), which is required for computer use on claude-opus-5-5
    • use the documented mid-conversation-output-config-2026-07-01 beta header for per-message effort

4.0.59

Patch Changes

  • f7b7b2a: feat(provider/anthropic): add safeguards provider option and safeguardResults provider metadata (dangerous tool use classifier)

4.0.58

Patch Changes

  • Updated dependencies [2973485]
  • Updated dependencies [a4db5ea]
  • Updated dependencies [2937ea2]

... (truncated)

Commits

Updates @ai-sdk/google from 4.0.50 to 4.0.80

Changelog

Sourced from @​ai-sdk/google's changelog.

4.0.80

Patch Changes

  • 8beac3e: fix(google): serialize JSON Schema references in function responses

4.0.79

Patch Changes

  • fe07867: Fix Google embedMany calls with more than 100 values by keeping per-value multimodal content aligned across automatic batches, including text-only entries. Validate content length before sending requests and validate each batch's provider options after middleware transforms them.

  • 2db5621: fix(google): preserve code execution parts when replaying messages

  • 2693319: Add Gemini 3.8 TTS support with structured speech metadata and per-turn speaker and style controls for prebuilt voices. Preserve native WAV responses without adding a second header, support explicit raw PCM, mu-law, and A-law output, and identify headerless audio formats correctly. Add the Gemini 3.8 speech model IDs to Google and Gateway types.

    Share transcript and custom-voice inspection through the Google provider internal export, and reject empty speech transcripts before sending a request. Default newer and custom model IDs to structured speech while preserving the legacy format for Gemini 2.5 and 3.1.

  • 771e74b: chore: enable dead code lint rules

  • Updated dependencies [fe07867]

  • Updated dependencies [a4b0940]

  • Updated dependencies [771e74b]

    • @​ai-sdk/provider-utils@​5.0.47

4.0.78

Patch Changes

  • ffb0e76: fix(provider): preserve opaque file URI strings for provider serialization
  • Updated dependencies [ffb0e76]
    • @​ai-sdk/provider@​4.0.18
    • @​ai-sdk/provider-utils@​5.0.46

4.0.77

Patch Changes

  • 8dbe0be: fix(google): preserve image candidate finish reasons in provider metadata

4.0.76

Patch Changes

  • Updated dependencies [2973485]
  • Updated dependencies [a4db5ea]
  • Updated dependencies [2937ea2]
    • @​ai-sdk/provider-utils@​5.0.45

4.0.75

Patch Changes

... (truncated)

Commits
  • 3f3a717 Version Packages (#21417)
  • 8beac3e fix(google): serialize JSON Schema references in function responses (#21459)
  • a8961eb docs: refresh model defaults across docs and examples (#21416)
  • 5c830d5 Version Packages (#21370)
  • 2db5621 fix(google): preserve code execution parts when replaying messages (#21402)
  • 2693319 feat(google): support Gemini 3.8 text-to-speech (#21403)
  • fe07867 fix: Google embedMany loses per-value content alignment when batching more th...
  • 771e74b chore: enable dead code lint rules (#21342)
  • 21b2d6c Version Packages (#21300)
  • ffb0e76 fix: Google Vertex percent-encoding literal characters in gs:// object names ...
  • Additional commits viewable in compare view

Updates @ai-sdk/openai from 4.0.46 to 4.0.75

Changelog

Sourced from @​ai-sdk/openai's changelog.

4.0.75

Patch Changes

  • ca31b89: The OpenAI Responses provider now accepts providerOptions.openai.reasoningEffortUpdate on empty system messages and sends each update at its position in the conversation. This lets applications change reasoning effort during a conversation while preserving the prompt prefix for caching.

4.0.74

Patch Changes

  • 4cf5a99: fix(openai): classify Responses stream errors with null codes
  • 771e74b: chore: enable dead code lint rules
  • Updated dependencies [fe07867]
  • Updated dependencies [a4b0940]
  • Updated dependencies [771e74b]
    • @​ai-sdk/provider-utils@​5.0.47

4.0.73

Patch Changes

  • 6d1f881: fix(openai): expose Chat Completions audio transcripts as generated text
  • 618dc11: feat: GPT-6 Sol and Luna model IDs
  • Updated dependencies [ffb0e76]
    • @​ai-sdk/provider@​4.0.18
    • @​ai-sdk/provider-utils@​5.0.46

4.0.72

Patch Changes

  • 411b3f2: fix(openai): strip unsupported regex patterns from JSON schemas
  • e13c32f: fix(openai): include speech provider options in requests

4.0.71

Patch Changes

  • e76a0a3: fix(openai): cancel image edit URL downloads when the request is aborted
  • Updated dependencies [2973485]
  • Updated dependencies [a4db5ea]
  • Updated dependencies [2937ea2]
    • @​ai-sdk/provider-utils@​5.0.45

4.0.70

Patch Changes

  • fd75cee: fix(openai): preserve provider file references in Responses tool results
  • 1f5bb62: fix(openai): send assistant text as Responses easy input messages

... (truncated)

Commits

Updates @anthropic-ai/claude-agent-sdk from 0.3.240 to 0.3.282

Release notes

Sourced from @​anthropic-ai/claude-agent-sdk's releases.

v0.3.282

What's changed

  • Added support for strictKnownMarketplaces and blockedMarketplaces in host-supplied managedSettings: the allowlist applies only where admin policy sets none; the blocklist adds to the admin's
  • Added @anthropic-ai/claude-agent-sdk/core, a smaller entry point for apps that bundle the SDK (query, MCP tool helpers, session mutations, resolveSettings); it uses your installed zod and MCP SDK
  • Added prewarm() and SpareProcess.claim() (alpha): start a Claude Code process before its session is known and bind it to a folder and its per-session options later
  • Fixed readMcpResource() relaying content _meta keys under the CLI-reserved com.anthropic/ prefix; they are now dropped, as for tool results
  • Updated to parity with Claude Code v2.1.282

Update

npm install @anthropic-ai/claude-agent-sdk@0.3.282
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.282
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.282
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.282

v0.3.281

What's changed

  • Added optional trigger, user_message_uuid and timestamp fields to the conversation_reset message so clients can tell what reset the conversation, match a /clear to its message, and show when the reset happened
  • Fixed permission and dialog callbacks still being invoked for requests that arrived after close()
  • Fixed control requests issued after a query closed hanging or leaking, and permission prompts that could not be cancelled after a cancelled request was redelivered
  • Fixed session_state_changed staying at requires_action after an overlapping permission prompt and sandbox network-access prompt were both answered
  • Improved SDK package size and load time: sdk.mjs no longer bundles unused dependencies (1.47 MB → 0.97 MB)
  • Improved startup time for query() sessions with in-process MCP servers (createSdkMcpServer) by running their handshake inside the SDK; initialize may now wait up to 250 ms for them
  • Improved SDK session start-up: the CLI now answers the host's initialize request before starting its background start-up work
  • Changed the Settings type's attribution field to boolean | {...}; TypeScript code that reads attribution.commit from returned settings needs a type narrow
  • Updated to parity with Claude Code v2.1.281

Update

npm install @anthropic-ai/claude-agent-sdk@0.3.281
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.281
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.281
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.281

v0.3.280

What's changed

  • Added optional fireReason to the task-notification SDKMessageOrigin; a local host's declared scheduled-task fire is honored only in a process it started with CLAUDE_CODE_HOST_SCHEDULED_RUN=1

... (truncated)

Changelog

Sourced from @​anthropic-ai/claude-agent-sdk's changelog.

0.3.282

  • Added support for strictKnownMarketplaces and blockedMarketplaces in host-supplied managedSettings: the allowlist applies only where admin policy sets none; the blocklist adds to the admin's
  • Added @anthropic-ai/claude-agent-sdk/core, a smaller entry point for apps that bundle the SDK (query, MCP tool helpers, session mutations, resolveSettings); it uses your installed zod and MCP SDK
  • Added prewarm() and SpareProcess.claim() (alpha): start a Claude Code process before its session is known and bind it to a folder and its per-session options later
  • Fixed readMcpResource() relaying content _meta keys under the CLI-reserved com.anthropic/ prefix; they are now dropped, as for tool results
  • Updated to parity with Claude Code v2.1.282

0.3.281

  • Added optional trigger, user_message_uuid and timestamp fields to the conversation_reset message so clients can tell what reset the conversation, match a /clear to its message, and show when the reset happened
  • Fixed permission and dialog callbacks still being invoked for requests that arrived after close()
  • Fixed control requests issued after a query closed hanging or leaking, and permission prompts that could not be cancelled after a cancelled request was redelivered
  • Fixed session_state_changed staying at requires_action after an overlapping permission prompt and sandbox network-access prompt were both answered
  • Improved SDK package size and load time: sdk.mjs no longer bundles unused dependencies (1.47 MB → 0.97 MB)
  • Improved startup time for query() sessions with in-process MCP servers (createSdkMcpServer) by running their handshake inside the SDK; initialize may now wait up to 250 ms for them
  • Improved SDK session start-up: the CLI now answers the host's initialize request before starting its background start-up work
  • Changed the Settings type's attribution field to boolean | {...}; TypeScript code that reads attribution.commit from returned settings needs a type narrow
  • Updated to parity with Claude Code v2.1.281

0.3.280

  • Added optional fireReason to the task-notification SDKMessageOrigin; a local host's declared scheduled-task fire is honored only in a process it started with CLAUDE_CODE_HOST_SCHEDULED_RUN=1
  • Added verbatimPrompts option: prompts are delivered as written — no @path expansion, no slash-command dispatch and, on current CLIs, no ambient attachments with the prompt (Claude Code 2.1.248+)
  • Added _meta to mcpServerStatus() tool entries, carrying a tool's MCP Apps ui metadata so a host can find its ui:// resource
  • Added readMcpResource() (alpha) to read an MCP Apps ui:// resource from an MCP server that Claude Code connected
  • Improved askSideQuestion(): asked while a turn is running, it now sees that turn (its prompt, replies and finished tool results so far) instead of only the last completed turn
  • Improved unattended retry (CLAUDE_CODE_RETRY_WATCHDOG): a usage-limit wait emits rate_limit_event (rejected, resetsAt) as it begins; api_retry heartbeats continue while sub-agent work waits
  • Changed session_state_changed events (CLAUDE_CODE_EMIT_SESSION_STATE_EVENTS=1) to report requires_action while an MCP elicitation waits on the user, as for permission prompts
  • Changed headless sessions to cancel an MCP server's pending form question when the tool call that drew it ends
  • Updated to parity with Claude Code v2.1.280

0.3.279

  • Updated to parity with Claude Code v2.1.279

0.3.278

  • Updated to parity with Claude Code v2.1.278

0.3.277

  • Added an optional builtin field to SlashCommand, set when a command is built into Claude Code
  • Added pasted_content to SDKUserMessage: text the user pasted rather than typed, appended after the typed prompt
  • Added optional remote-session latency fields (first_text_post_ms, first_text_post_wall_ms, first_stream_post_queue_wait_ms, first_stream_post_queued_behind) to the success result message
  • Added 'userSettings' as an updateSettings() source, accepting only effortLevel, which is saved for the session's current model as /effort saves it
  • Fixed a resumed or forked session's total_cost_usd, modelUsage and get_usage totals starting at zero instead of continuing from the earlier turns (maxBudgetUsd is unchanged)
  • Changed SDKUsageReport usage rows to always carry severity and is_active: the report relays only rows from a live server reply, and none while the usage fetch is failing
  • Updated to parity with Claude Code v2.1.277

... (truncated)

Commits

Updates @aws-sdk/client-s3 from 3.1116.0 to 3.1140.0

Release notes

Sourced from @​aws-sdk/client-s3's releases.

v3.1140.0

3.1140.0(2026-09-24)

Documentation Changes
  • client-route53resolver: Documentation updates for Route 53 Resolver. Clarifies which Outpost Resolver operations apply to first-generation AWS Outposts and that Resolver is managed automatically on second-generation Outposts. Adds Local Network Interface subnet compatibility notes for Resolver endpoints. (b4432aba)
  • client-iot: Fixed ListV2LoggingLevels and DeleteV2LoggingLevel documentation to include all supported target-types (4dcf76d5)
New Features
  • clients: update client endpoints as of 2026-09-24 (29a8566c)
  • client-eventbridgev2: Introducing Amazon EventBridge enhanced Custom event bus, a new shareable event bus for organizational-scale event-driven applications feature ordered delivery, deduplication, open ev...

    Description has been truncated

…4 updates

---
updated-dependencies:
- dependency-name: "@comfyorg/sdk"
  dependency-version: 0.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.30.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: sharp
  dependency-version: 0.35.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: yaml
  dependency-version: 2.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@ai-sdk/anthropic"
  dependency-version: 4.0.63
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@ai-sdk/google"
  dependency-version: 4.0.80
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@ai-sdk/openai"
  dependency-version: 4.0.75
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@anthropic-ai/claude-agent-sdk"
  dependency-version: 0.3.282
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@aws-sdk/client-s3"
  dependency-version: 3.1140.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@azure/storage-blob"
  dependency-version: 12.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@openai/codex"
  dependency-version: 0.157.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: ai
  dependency-version: 7.0.114
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 28, 2026
@artokun

artokun commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Limited maintenance audit — October 1, 2026.

Scope: this refresh changes fourteen dependencies and the SDK/model runtime together. The limited-maintenance release does not include a broad dependency refresh; no demonstrated vulnerability or critical blocker requires this bundle.

Closing this PR does not close or mark the underlying bug as fixed. Conflicts and age were not used as quality criteria. Automatic issue reporting remains disabled.

@artokun artokun closed this Oct 1, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/npm-minor-patch-a0269f7bbf branch October 1, 2026 18:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant