Update Routine updates - #25
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
6 times, most recently
from
June 4, 2026 16:35
24826b0 to
98013c1
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
4 times, most recently
from
June 9, 2026 00:59
da1af68 to
a3a98f1
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
5 times, most recently
from
June 18, 2026 19:03
20b05ad to
2145f05
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
5 times, most recently
from
June 27, 2026 02:25
251900b to
61bcead
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
8 times, most recently
from
July 3, 2026 02:47
b0835cd to
2eb89f4
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
2 times, most recently
from
July 9, 2026 08:30
cfa2a24 to
f7629eb
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
6 times, most recently
from
July 16, 2026 15:57
7852e08 to
3da314f
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
5 times, most recently
from
July 23, 2026 18:11
f197d26 to
294de3b
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
5 times, most recently
from
July 30, 2026 16:56
b8e1655 to
ec522a9
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
7 times, most recently
from
August 7, 2026 01:28
4ca08b2 to
6d6bdc7
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
4 times, most recently
from
August 14, 2026 22:55
d12fd26 to
c799f62
Compare
renovate
Bot
force-pushed
the
renovate/routine-updates
branch
from
August 15, 2026 14:02
c799f62 to
958c122
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.3.1→3.3.69.39.1→9.39.50.15.15→0.17.4^0.8.0→^0.8.0 || ^0.24.00.8.3→0.24.90.2.10→0.15.1320.19.41→20.19.4319.2.6→19.2.1819.2.3→19.2.45.1.1→5.2.0de0fac2→d23441a93cb6ef→fbc6f391.39.1→1.43.01.44.00.0.38→0.0.559.39.1→9.39.57.0.1→7.1.10.4.24→0.5.417.5.0→17.11.03.6.2→3.9.6v2.1.2→v2.2.019.2.0→19.2.819.2.0→19.2.88.47.0→8.67.07.3.5→7.3.64.1.0→4.1.10v0.5.6→v0.6.1v0.6.2Release Notes
eslint/eslintrc (@eslint/eslintrc)
v3.3.6Compare Source
Bug Fixes
js-yamlto 4.3.0 to address security vulnerability (#235) (0c5de74)v3.3.5Compare Source
Bug Fixes
v3.3.4Compare Source
Bug Fixes
ajvto6.14.0to address security vulnerabilities (#221) (9139140)minimatchto3.1.3to address security vulnerabilities (#224) (30339d0)v3.3.3Compare Source
Bug Fixes
eslint/eslint (@eslint/js)
v9.39.5Compare Source
Bug Fixes
253be16fix: handle unavailable require cache (backport of #20812 to v9.x) (#21065) (Eric)Documentation
74930eddocs: switch build to Node.js 24 (#20894) (Milos Djermanovic)eaec8bbdocs: Add ESLint v9.x EOL notice (#20828) (Milos Djermanovic)Chores
458205fchore: update@eslint/eslintrcand@eslint/jsfor v9.39.5 (#21077) (Francesco Trotta)202117bchore: package.json update for @eslint/js release (Jenkins)d9eb6edtest: disable warning forvm.constants.USE_MAIN_CONTEXT_DEFAULT_LOADER(#21074) (Francesco Trotta)7b431a7chore: overridere2dependency for@metascraper/helpers(#21068) (Milos Djermanovic)daf7791chore: pin fflate@0.8.2 (#20895) (Milos Djermanovic)daee8baci: use pnpm ineslint-flat-config-utilstype integration test (#20829) (Milos Djermanovic)116d4beci: unpin Node.js 25.x in CI (#20619) (Copilot)v9.39.4Compare Source
Bug Fixes
f18f6c8fix: update dependency minimatch to ^3.1.5 (#20564) (Milos Djermanovic)a3c868ffix: update dependency @eslint/eslintrc to ^3.3.4 (#20554) (Milos Djermanovic)234d005fix: minimatch security vulnerability patch for v9.x (#20549) (Andrej Beles)b1b37eefix: updateajvto6.14.0to address security vulnerabilities (#20538) (루밀LuMir)Documentation
4675152docs: add deprecation notice partial (#20520) (Milos Djermanovic)Chores
b8b4eb1chore: update dependencies for ESLint v9.39.4 (#20596) (Francesco Trotta)71b2f6bchore: package.json update for @eslint/js release (Jenkins)1d16c2fci: pin Node.js 25.6.1 (#20563) (Milos Djermanovic)v9.39.3Compare Source
Bug Fixes
791bf8dfix: restore TypeScript 4.0 compatibility in types (#20504) (sethamus)Chores
8594a43chore: upgrade @eslint/js@9.39.3 (#20529) (Milos Djermanovic)9ceef92chore: package.json update for @eslint/js release (Jenkins)af498c6chore: ignore/docs/v9.xin link checker (#20453) (Milos Djermanovic)v9.39.2Compare Source
Bug Fixes
5705833fix: warn wheneslint-envconfiguration comments are found (#20381) (sethamus)Build Related
506f154build: add .scss files entry to knip (#20391) (Milos Djermanovic)Chores
7ca0af7chore: upgrade to@eslint/js@9.39.2(#20394) (Francesco Trotta)c43ce24chore: package.json update for @eslint/js release (Jenkins)4c9858eci: addv9.x-devbranch (#20382) (Milos Djermanovic)tursodatabase/libsql-client-ts (@libsql/client)
v0.17.4Compare Source
v0.17.3Compare Source
v0.17.2Compare Source
v0.17.1Compare Source
v0.17.0Compare Source
mastra-ai/mastra (@mastra/core)
v0.24.9Compare Source
v0.24.8Compare Source
v0.24.7Compare Source
v0.24.6: 2025-11-27Compare Source
Highlights
Stream nested execution context from Workflows and Networks to your UI
Agent responses now stream live through workflows and networks, with complete execution metadata flowing to your UI.
In workflows, pipe agent streams directly through steps:
In networks, each step now tracks properly—unique IDs, iteration counts, task info, and agent handoffs all flow through with correct sequencing. No more duplicated steps or missing metadata.
Both surface text chunks, tool calls, and results as they happen, so users see progress in real time instead of waiting for the full response.
AI-SDK voice models are now supported
CompositeVoicenow accepts AI SDK voice models directly—use OpenAI for transcription, ElevenLabs for speech, or any combination you want.Works with OpenAI, ElevenLabs, Groq, Deepgram, LMNT, Hume, and more. AI SDK models are automatically wrapped, so you can swap providers without changing your code.
Changelog
@mastra/ai-sdk
Support streaming agent text chunks from workflow-step-output
Adds support for streaming text and tool call chunks from agents running inside workflows via the workflow-step-output event. When you pipe an agent's stream into a workflow step's writer, the text chunks, tool calls, and other streaming events are automatically included in the workflow stream and converted to UI messages.
Features:
includeTextStreamPartsoption toWorkflowStreamToAISDKTransformer(defaults totrue)isMastraTextStreamChunktype guard to identify Mastra chunks with text streaming datatext-start,text-delta,text-endtool-call,tool-resulttransformers.test.tsworkflowRoute()Example:
When served via
workflowRoute(), the UI receives incremental text updates as the agent generates its response, providing a smooth streaming experience. (#10568)Fix chat route to use agent ID instead of agent name for resolution. The
/chat/:agentIdendpoint now correctly resolves agents by their ID property (e.g.,weather-agent) instead of requiring the camelCase variable name (e.g.,weatherAgent). This fixes issue #10469 where URLs like/chat/weather-agentwould return 404 errors. (#10565)Fixes propagation of custom data chunks from nested workflows in branches to the root stream when using
toAISdkV5Streamwith{from: 'workflow'}.Previously, when a nested workflow within a branch used
writer.custom()to write data-* chunks, those chunks were wrapped inworkflow-step-outputevents and not extracted, causing them to be dropped from the root stream.Changes:
workflow-step-outputchunks intransformWorkflow()to extract and propagate data-* chunksWhen a
workflow-step-outputchunk contains a data-* chunk in itspayload.output, the transformer now extracts it and returns it directly to the root streamAdded comprehensive test coverage for nested workflows with branches and custom data propagation
This ensures that custom data chunks written via
writer.custom()in nested workflows (especially those within branches) are properly propagated to the root stream, allowing consumers to receive progress updates, metrics, and other custom data from nested workflow steps. (#10447)Fix network data step formatting in AI SDK stream transformation
Previously, network execution steps were not being tracked correctly in the AI SDK stream transformation. Steps were being duplicated rather than updated, and critical metadata like step IDs, iterations, and task information was missing or incorrectly structured.
Changes:
AgentNetworkToAISDKTransformerto properly maintain step state throughout execution lifecycleSteps are now identified by unique IDs and updated in place rather than creating duplicates
Added proper iteration and task metadata to each step in the network execution flow
Fixed agent, workflow, and tool execution events to correctly populate step data
Updated network stream event types to include
networkId,workflowId, and consistentrunIdtrackingAdded test coverage for network custom data chunks with comprehensive validation
This ensures the AI SDK correctly represents the full execution flow of agent networks with accurate step sequencing and metadata. (#10432)
[0.x] Make workflowRoute includeTextStreamParts option default to false (#10574)
Add support for tool-call-approval and tool-call-suspended events in chatRoute (#10205)
Backports the
messageMetadataandonErrorsupport from PR #10313 to the 0.x branch, adding these features totoAISdkFormatfunction.messageMetadataparameter totoAISdkFormatoptionsstartandfinishchunks when providedAdded
onErrorparameter totoAISdkFormatoptionssafeParseErrorObjectutility when not providedAdded
safeParseErrorObjectutility function for error parsingUpdated
AgentStreamToAISDKTransformerto accept and usemessageMetadataandonErrorUpdated JSDoc documentation with parameter descriptions and usage examples
Added comprehensive test suite for
messageMetadatafunctionality (6 test cases)Fixed existing test file to use
toAISdkFormatinstead of removedtoAISdkV5StreamNew tests verify:
messageMetadatais called with correct part structureMetadata is included in start and finish chunks
Proper handling when
messageMetadatais not provided or returns null/undefinedFunction is called for each relevant part in the stream
Uses
UIMessageStreamOptions<UIMessage>['messageMetadata']andUIMessageStreamOptions<UIMessage>['onError']types from AI SDK v5 for full type compatibilityBackport of: #10313 (#10314)
Fixed workflow routes to properly receive request context from middleware. This aligns the behavior of
workflowRoutewithchatRoute, ensuring that context set in middleware is consistently forwarded to workflows.When both middleware and request body provide a request context, the middleware value now takes precedence, and a warning is emitted to help identify potential conflicts.
See #10427 (#10427)
@mastra/astra
@mastra/auth-clerk
@mastra/chroma
@mastra/clickhouse
@mastra/cloudflare
@mastra/cloudflare-d1
@mastra/core
Fix base64 encoded images with threads - issue #10480
Fixed "Invalid URL" error when using base64 encoded images (without
data:prefix) in agent calls with threads and resources. Raw base64 strings are now automatically converted to proper data URIs before being processed.Changes:
Updated
attachments-to-parts.tsto detect and convert raw base64 strings to data URIsFixed
MessageListimage processing to handle raw base64 in two locations:aiV4CoreMessageToV1PromptMessagemastraDBMessageToAIV4UIMessageAdded comprehensive tests for base64 images, data URIs, and HTTP URLs with threads
Breaking Change: None - this is a bug fix that maintains backward compatibility while adding support for raw base64 strings. (#10483)
SimpleAuth and improved CloudAuth (#10569)
Fixed OpenAI schema compatibility when using
agent.generate()oragent.stream()withstructuredOutput.Changes
.optional()fields are converted to.nullable()with a transform that convertsnull→undefined, preserving optional semantics while satisfying OpenAI's strict mode requirements.nullable()fields remain unchanged.optional()fields at any nesting level (objects, arrays, unions, etc.)Example
(#10454)
deleteVectors, deleteFilter when upserting, updateVector filter (#10244) (#10244)
Fix generateTitle model type to accept AI SDK LanguageModelV2
Updated the
generateTitle.modelconfig option to acceptMastraModelConfiginstead ofMastraLanguageModel. This allows users to pass raw AI SDKLanguageModelV2models (e.g.,anthropic.languageModel('claude-3-5-haiku-20241022')) directly without type errors.Previously, passing a standard
LanguageModelV2would fail becauseMastraLanguageModelV2has differentdoGenerate/doStreamreturn types. NowMastraModelConfigis used consistently across:memory/types.ts-generateTitle.modelconfigagent.ts-genTitle,generateTitleFromUserMessage,resolveTitleGenerationConfigagent-legacy.ts-AgentLegacyCapabilitiesinterface (#10567)Fix message metadata not persisting when using simple message format. Previously, custom metadata passed in messages (e.g.,
{role: 'user', content: 'text', metadata: {userId: '123'}}) was not being saved to the database. This occurred because the CoreMessage conversion path didn't preserve metadata fields.Now metadata is properly preserved for all message input formats:
Simple CoreMessage format:
{role, content, metadata}Full UIMessage format:
{role, content, parts, metadata}AI SDK v5 ModelMessage format with metadata
Fixes #8556 (#10488)
feat: Composite auth implementation (#10359)
Fix requireApproval property being ignored for tools passed via toolsets, clientTools, and memoryTools parameters. The requireApproval flag now correctly propagates through all tool conversion paths, ensuring tools requiring approval will properly request user approval before execution. (#10562)
Fix Azure Foundry rate limit handling for -1 values (#10409)
Fix model headers not being passed through gateway system
Previously, custom headers specified in
MastraModelConfigwere not being passed through the gateway system to model providers. This affected:OpenRouter (preventing activity tracking with
HTTP-RefererandX-Title)Custom providers using custom URLs (headers not passed to
createOpenAICompatible)Custom gateway implementations (headers not available in
resolveLanguageModel)Now headers are correctly passed through the entire gateway system:
Base
MastraModelGatewayinterface updated to accept headersModelRouterLanguageModelpasses headers from config to all gatewaysOpenRouter receives headers for activity tracking
Custom URL providers receive headers via
createOpenAICompatibleCustom gateways can access headers in their
resolveLanguageModelimplementationExample usage:
Fixes #9760
(#10564)
fix(agent): persist messages before tool suspension
Fixes issues where thread and messages were not saved before suspension when tools require approval or call suspend() during execution. This caused conversation history to be lost if users refreshed during tool approval or suspension.
Backend changes (@mastra/core):
Add assistant messages to messageList immediately after LLM execution
Flush messages synchronously before suspension to persist state
Create thread if it doesn't exist before flushing
Add metadata helpers to persist and remove tool approval state
Pass saveQueueManager and memory context through workflow for immediate persistence
Frontend changes (@mastra/react):
Extract runId from pending approvals to enable resumption after refresh
Convert
pendingToolApprovals(DB format) torequireApprovalMetadata(runtime format)Handle both
dynamic-toolandtool-{NAME}part types for approval stateChange runId from hardcoded
agentIdto uniqueuuid()UI changes (@mastra/playground-ui):
Handle tool calls awaiting approval in message initialization
Convert approval metadata format when loading initial messages
Fixes #9745, #9906 (#10369)
Fix race condition in parallel tool stream writes
Introduces a write queue to ToolStream to serialize access to the underlying stream, preventing writer locked errors (#10463)
Remove unneeded console warning when flushing messages and no threadId or saveQueueManager is found. (#10369)
Fixes GPT-5 reasoning which was failing on subsequent tool calls with the error:
(#10489)
Add optional includeRawChunks parameter to agent execution options,
allowing users to include raw chunks in stream output where supported
by the model provider. (#10456)
When
mastra devruns, multiple processes can write toprovider-registry.jsonconcurrently (auto-refresh, syncGateways, syncGlobalCacheToLocal). This causes file corruption where the end of the JSON appears twice, making it unparseable.The fix uses atomic writes via the write-to-temp-then-rename pattern. Instead of:
fs.rename()is atomic on POSIX systems when both paths are on the same filesystem, so concurrent writes will each complete fully rather than interleaving. (#10529)Ensures that data chunks written via
writer.custom()always bubble up directly to the top-level stream, even when nested in sub-agents. This allows tools to emit custom progress updates, metrics, and other data that can be consumed at any level of the agent hierarchy.Added bubbling logic in sub-agent execution: When sub-agents execute, data chunks (chunks with type starting with
data-) are detected and written viawriter.custom()instead ofwriter.write(), ensuring they bubble up directly without being wrapped intool-outputchunks.Added comprehensive tests:
Test for
writer.custom()with direct tool executionTest for
writer.custom()with sub-agent tools (nested execution)Test for mixed usage of
writer.write()andwriter.custom()in the same toolWhen a sub-agent's tool uses
writer.custom()to write data chunks, those chunks appear in the sub-agent's stream. The parent agent's execution logic now detects these chunks and useswriter.custom()to bubble them up directly, preserving their structure and making them accessible at the top level.This ensures that:
Data chunks bubble up correctly through nested agent hierarchies
Regular chunks continue to be wrapped in
tool-outputas expected (#10309)Adds ability to create custom
MastraModelGateway's that can be added to theMastraclass instance under thegatewaysproperty. Giving you typescript autocompletion in any model picker string.(#10535)
Support AI SDK voice models
Mastra now supports AI SDK's transcription and speech models directly in
CompositeVoice, enabling seamless integration with a wide range of voice providers through the AI SDK ecosystem. This allows you to use models from OpenAI, ElevenLabs, Groq, Deepgram, LMNT, Hume, and many more for both speech-to-text (transcription) and text-to-speech capabilities.AI SDK models are automatically wrapped when passed to
CompositeVoice, so you can mix and match AI SDK models with existing Mastra voice providers for maximum flexibility.Usage Example
Fixes #9947 (#10558)
Fix network data step formatting in AI SDK stream transformation
Previously, network execution steps were not being tracked correctly in the AI SDK stream transformation. Steps were being duplicated rather than updated, and critical metadata like step IDs, iterations, and task information was missing or incorrectly structured.
Changes:
AgentNetworkToAISDKTransformerto properly maintain step state throughout execution lifecycleSteps are now identified by unique IDs and updated in place rather than creating duplicates
Added proper iteration and task metadata to each step in the network execution flow
Fixed agent, workflow, and tool execution events to correctly populate step data
Updated network stream event types to include
networkId,workflowId, and consistentrunIdtrackingAdded test coverage for network custom data chunks with comprehensive validation
This ensures the AI SDK correctly represents the full execution flow of agent networks with accurate step sequencing and metadata. (#10432)
Fix generating provider-registry.json (#10535)
Fix message-list conversion issues when persisting messages before tool suspension: filter internal metadata fields (
__originalContent) from UI messages, keep reasoning field empty for consistent cache keys during message deduplication, and only include providerMetadata on parts when defined. (#10552)Fix agent.generate() to use model's doGenerate method instead of doStream
When calling
agent.generate(), the model'sdoGeneratemethod is now correctly invoked instead of always usingdoStream. This aligns the non-streaming generation path with the intended behavior where providers can implement optimized non-streaming responses. (#10572)@mastra/couchbase
@mastra/deployer
@mastra/deployer-cloud
@mastra/dynamodb
@mastra/inngest
@mastra/lance
@mastra/libsql
@mastra/mcp
@mastra/mcp-docs-server
@mastra/mongodb
@mastra/mssql
@mastra/opensearch
@mastra/pg
Configuration
📅 Schedule: (in timezone America/Los_Angeles)
* * * * 1-5)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.