Skip to content

chore(deps): update npm minor and patch dependencies#9209

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-minor-patch
Closed

chore(deps): update npm minor and patch dependencies#9209
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@anthropic-ai/claude-agent-sdk ^0.3.205^0.3.218 age confidence
@cloudflare/vitest-pool-workers (source) ^0.18.0^0.18.8 age confidence
@cloudflare/workers-types ^5.20260721.1^5.20260724.1 age confidence
@eslint/js (source) ^9.39.4^9.39.5 age confidence
@hono/node-server ^2.0.0^2.0.11 age confidence
@hono/node-server ^2.0.8^2.0.11 age confidence
@lovable.dev/vite-plugin-dev-server-bridge (source) 1.0.31.2.1 age confidence
@lovable.dev/vite-plugin-hmr-gate (source) 1.1.21.1.4 age confidence
@lovable.dev/vite-tanstack-config (source) 2.6.52.7.7 age confidence
@opentelemetry/exporter-trace-otlp-http (source) ^0.220.0^0.221.0 age confidence
@opentelemetry/resources (source) ^2.9.0^2.10.0 age confidence
@opentelemetry/sdk-trace-node (source) ^2.9.0^2.10.0 age confidence
@radix-ui/react-accordion (source) ^1.2.15^1.2.18 age confidence
@radix-ui/react-alert-dialog (source) ^1.1.18^1.1.21 age confidence
@radix-ui/react-aspect-ratio (source) ^1.1.11^1.1.13 age confidence
@radix-ui/react-avatar (source) ^1.2.1^1.2.4 age confidence
@radix-ui/react-checkbox (source) ^1.3.6^1.3.9 age confidence
@radix-ui/react-collapsible (source) ^1.1.15^1.1.18 age confidence
@radix-ui/react-context-menu (source) ^2.3.2^2.3.5 age confidence
@radix-ui/react-dialog (source) ^1.1.18^1.1.21 age confidence
@radix-ui/react-dropdown-menu (source) ^2.1.19^2.1.22 age confidence
@radix-ui/react-hover-card (source) ^1.1.18^1.1.21 age confidence
@radix-ui/react-label (source) ^2.1.11^2.1.13 age confidence
@radix-ui/react-menubar (source) ^1.1.19^1.1.22 age confidence
@radix-ui/react-navigation-menu (source) ^1.2.17^1.2.20 age confidence
@radix-ui/react-popover (source) ^1.1.18^1.1.21 age confidence
@radix-ui/react-progress (source) ^1.1.11^1.1.14 age confidence
@radix-ui/react-radio-group (source) ^1.4.2^1.4.5 age confidence
@radix-ui/react-scroll-area (source) ^1.2.13^1.2.16 age confidence
@radix-ui/react-select (source) ^2.3.2^2.3.5 age confidence
@radix-ui/react-separator (source) ^1.1.11^1.1.13 age confidence
@radix-ui/react-slider (source) ^1.4.2^1.4.5 age confidence
@radix-ui/react-slot (source) ^1.3.0^1.3.1 age confidence
@radix-ui/react-switch (source) ^1.3.2^1.3.5 age confidence
@radix-ui/react-tabs (source) ^1.1.16^1.1.19 age confidence
@radix-ui/react-toggle (source) ^1.1.13^1.1.16 age confidence
@radix-ui/react-toggle-group (source) ^1.1.14^1.1.17 age confidence
@radix-ui/react-tooltip (source) ^1.2.11^1.2.14 age confidence
@scalar/api-reference-react (source) ^0.9.55^0.9.59 age confidence
@sentry/node (source) ^10.63.0^10.67.0 age confidence
@sentry/react (source) ^10.63.0^10.67.0 age confidence
@tailwindcss/vite (source) ^4.3.2^4.3.3 age confidence
@tanstack/react-query (source) ^5.101.2^5.101.4 age confidence
@tanstack/react-router (source) ^1.170.17^1.170.18 age confidence
@tanstack/react-start (source) ^1.168.27^1.168.32 age confidence
@tanstack/router-plugin (source) ^1.168.19^1.168.23 age confidence
@types/node (source) ^22.20.0^22.20.1 age confidence
@types/node (source) ^22.20.0^22.20.1 age confidence
@types/node (source) ^24.13.2^24.13.3 age confidence
@types/react (source) ^19.2.7^19.2.17 age confidence
@vitejs/plugin-react (source) ^5.1.4^5.2.0 age confidence
@vitest/coverage-v8 (source) ^4.1.9^4.1.10 age confidence
agents (source) ^0.17.3^0.19.0 age confidence
eslint (source) ^9.39.4^9.39.5 age confidence
eslint-plugin-prettier ^5.5.5^5.5.6 age confidence
eslint-plugin-react-hooks (source) ^7.0.1^7.1.1 age confidence
eslint-plugin-react-refresh ^0.5.2^0.5.3 age confidence
fumadocs-core ^16.11.4^16.12.1 age confidence
fumadocs-mdx ^15.1.1^15.2.0 age confidence
globals ^17.4.0^17.7.0 age confidence
hono (source) ^4.12.27^4.12.31 age confidence
hono (source) ^4.12.27^4.12.31 age confidence
postcss (source) ^8.5.18^8.5.22 age confidence
posthog-node (source) ^5.44.0^5.46.1 age confidence
posthog-node (source) ^5.44.0^5.46.1 age confidence
prettier (source) 3.9.43.9.6 age confidence
prettier (source) ^3.9.4^3.9.6 age confidence
prettier (source) ^3.8.1^3.9.6 age confidence
react (source) ^19.2.7^19.2.8 age confidence
react-dom (source) ^19.2.7^19.2.8 age confidence
react-hook-form (source) ^7.80.0^7.82.0 age confidence
react-resizable-panels (source) ^4.12.0^4.12.2 age confidence
semver ^7.8.4^7.8.5 age confidence
sharp (source, changelog) ^0.35.0^0.35.3 age confidence
tailwindcss (source) ^4.3.2^4.3.3 age confidence
tsx (source) ^4.22.5^4.23.1 age confidence
turbo (source) ^2.10.5^2.10.6 age confidence
typescript-eslint (source) ^8.62.1^8.65.0 age confidence
typescript-eslint (source) ^8.56.1^8.65.0 age confidence
vite (source) ^8.1.3^8.1.5 age confidence
vitest (source) ^4.1.9^4.1.10 age confidence
web-tree-sitter (source) ^0.20.8^0.26.11 age confidence
wrangler (source) ^4.107.0^4.114.0 age confidence
wrangler (source) ^4.107.0^4.114.0 age confidence
wrangler (source) ^4.112.0^4.114.0 age confidence
ws ^8.21.0^8.21.1 age confidence

Dependency PRs must keep npm run test:ci passing. The 97% coverage requirement is enforced as Codecov patch coverage on changed lines (codecov/patch), so dependency-only bumps satisfy it without new tests.

GitHub Actions updates must remain SHA-pinned.

Renovate is the sole dependency and security-update bot for this repo; GitHub Dependabot security updates are disabled to avoid duplicate PRs (e.g. the two hono advisory PRs).


Release Notes

anthropics/claude-agent-sdk-typescript (@​anthropic-ai/claude-agent-sdk)

v0.3.218

Compare Source

  • SkillToolOutput now reports background: true when a forked skill was dispatched as a detached background agent
  • Fixed the result event's api_error_status reporting null for rate-limit and overloaded errors delivered mid-stream; it now reports 429/529
  • Added canonicalModel and provider to each modelUsage entry in result messages so downstream billing can look up the correct rate table for costUSD

v0.3.217

Compare Source

  • Changed subagents to no longer spawn nested subagents by default (depth cap lowered from 5 to 1); set CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH to allow deeper nesting
  • Added a cap on concurrently-running subagents (default 20, override with CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS)
  • Fixed Remote Control sessions not re-sending pending permission prompts to clients that connect after the prompt appeared

v0.3.216

Compare Source

  • Added optional skippedLinks count to rewindFiles responses for paths the rewind safety guards refused to restore or delete
  • Added tool_result_meta sidecar to user messages (non_execution_kind, user_feedback) so consumers can classify denied, interrupted, or cancelled tool calls without string-matching result prose
  • Added optional user_message_uuid and request_sent_wall_ms fields to the success result message for cross-host request-latency correlation

v0.3.215

Compare Source

  • Updated to parity with Claude Code v2.1.215

v0.3.214

  • set_permission_mode now rejects unrecognized permission modes with an error instead of silently adopting them; the 'manual' alias is accepted at every ingress
  • Added optional subkind: 'scheduled-trigger' to the task-notification member of SDKMessageOrigin, marking deliveries that are the fired prompt of a user-configured scheduled task
  • applyFlagSettings({effortLevel}) now accepts 'max' in its TypeScript type (runtime already supported it)
  • Assistant messages truncated by interrupt() now carry aborted: true, so consumers can distinguish a mid-stream partial from a completed message
  • Added optional subagent_type and subagent_retry fields to tool_progress messages so clients can show a subagent waiting out an API rate-limit retry
  • The system/init message's plugins entries and the reload_plugins response now include each plugin's manifest version
  • SessionStart hooks now report source "fork" instead of "resume" when the session begins as a fork

v0.3.213

  • Updated to parity with Claude Code v2.1.213

v0.3.212

Compare Source

  • Fixed dash-leading resumeSessionAt and sessionId values being passed to the CLI as separate argv tokens; both now use equals-form (--flag=value)
  • Agent tool output now includes the resolved model when a mid-turn model swap changed the subagent's model

v0.3.211

Compare Source

  • Fixed --replay-user-messages with --include-partial-messages emitting the turn-start user replay after the first content block instead of before the turn's content events
  • Added SDKAssistantMessage.timestamp (ISO-8601) to the live stream, matching SDKUserMessage; older emitters omit it, consumers should fall back to receive time
  • Added rate-limit message prefix buckets (USAGE_LIMIT_ERROR_PREFIXES and siblings) as @alpha exports for classifying rate-limit messages without hand-mirrored lists
  • Improved process-exit errors to include the CLI's stderr output, so a failed child reports its actual cause instead of only an exit code

v0.3.210

Compare Source

  • Added timedOutAfterMs to BashToolOutput, set when a command is auto-backgrounded on timeout

v0.3.209

Compare Source

  • Updated to parity with Claude Code v2.1.209

v0.3.208

Compare Source

  • Fixed a caller abort during a pending SDK hook callback being converted into hook success, which let PreToolUse-gated tools execute after the abort
  • Fixed a per-query resource leak in the SDK's process tracking when spawning the CLI fails (nonexistent or inaccessible executable path)
  • Fixed an SDK UserPromptSubmit hook callback exceeding its timeout killing the entire query with an empty error; it now blocks the prompt with a clear timeout message and the session continues
  • Fixed extraArgs values that look like flags (e.g. resume: '--version') being parsed as their own CLI flags; dash-leading values are now bound with equals-form argv
  • Fixed an abort-listener leak: streaming queries sharing one AbortController no longer accumulate abort listeners on its signal after each completed query
  • Fixed createSdkMcpServer docs pointing at a nonexistent env var; the MCP tool-call timeout knob is MCP_TOOL_TIMEOUT
  • Fixed an uncaught exception when writing to stdin after the Claude Code subprocess has exited

v0.3.207

Compare Source

  • Fixed canUseTool returning {behavior: 'allow'} without updatedInput being rejected as a deny with a raw ZodError message; the tool now runs with the original input per the documented contract
  • The Agent tool's structured result now has a published SDK type (AgentToolCompletedOutput) that matches the emitted object exactly

v0.3.206

Compare Source

  • Added command_lifecycle frames to stream-json and SDK sessions, reporting each uuid-stamped message's terminal state (queued/started/completed/cancelled/discarded); zero-API results no longer report stale duration_api_ms
cloudflare/workers-sdk (@​cloudflare/vitest-pool-workers)

v0.18.8

Compare Source

Patch Changes

v0.18.7

Compare Source

Patch Changes
  • #​14713 de34449 Thanks @​allocsys! - Fix a non-ASCII path failure during the Miniflare WebSocket handshake: the MF-Vitest-Worker-Data header embedded the raw process.cwd() value, which threw a Latin-1/ASCII header encoding error when the workspace path contained non-ASCII characters (e.g. CJK characters) on Windows. The value is now percent-encoded on write and decoded on read, matching the fix applied to the module fallback redirect response.

  • #​14713 de34449 Thanks @​allocsys! - Fix a runtime start-up failure ("No such module "cloudflare:test-internal"") when the project workspace path contains non-ASCII characters (e.g. CJK characters) on Windows. The module fallback service's redirect response set the target file path directly as an HTTP Location header value, but headers are restricted to the Latin-1/ASCII byte range, so any non-ASCII byte in the path caused header construction to throw. Such paths are now percent-encoded (and tagged with a sentinel prefix) before being used as a header value, and decoded again only for the values we encoded, so the round-trip is unambiguous and a workspace path containing a literal % is left untouched instead of being mis-decoded.

  • #​14739 5eac99e Thanks @​Ankcorn! - Support testing Streaming Tail Workers in Vitest Pool Workers.

  • #​14763 538e867 Thanks @​gianghungtien! - Treat webSocketMessage(), webSocketClose() and webSocketError() as optional Durable Object handlers

    The pool wraps each Durable Object class and installs a prototype method for every default handler before user code is loaded, so workerd always sees a handler and always dispatches. When the wrapped class didn't actually define one, the wrapper threw <ClassName> exported by <path> does not define a `webSocketClose()` method, even though deployed Workers silently ignore these events for classes that omit them. A hibernatable Durable Object defining only webSocketMessage() would log an uncaught TypeError on every close.

    These three handlers now no-op when absent, matching deployed behaviour. alarm() is unchanged and still reports a missing handler, since workerd rejects setAlarm() up front on a class without one.

  • Updated dependencies [42af66d, a0a091b, f03b108, deae171, 0df3d43, d83a476, 4e92e32, d1d6945, 4815711, a0c8bb1, a50f73a, 2b390d7, c82d96b, 34430b3, f75ae5d]:

    • miniflare@​4.20260721.0
    • wrangler@​4.113.0

v0.18.6

Compare Source

Patch Changes

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/Phoenix)

  • Branch creation
    • "before 6am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jul 27, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
❌ Deployment failed
View logs
loopover-ui 45e85bf Jul 27 2026, 08:09 AM

@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from ce387c6 to c5d561a Compare July 27, 2026 07:08
@codecov

codecov Bot commented Jul 27, 2026

Copy link
Copy Markdown

⚠️ JUnit XML file not found

The CLI was unable to find any JUnit XML files to upload.
For more help, visit our troubleshooting guide.

@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from c5d561a to 712bd87 Compare July 27, 2026 07:12
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 712bd87 to c460cf8 Compare July 27, 2026 07:24
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from c460cf8 to 089445d Compare July 27, 2026 07:35
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 089445d to 49b1867 Compare July 27, 2026 07:59
@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from 49b1867 to 45e85bf Compare July 27, 2026 08:06
@JSONbored JSONbored closed this Jul 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant