chore(deps): update npm minor and patch dependencies#9209
Closed
renovate[bot] wants to merge 1 commit into
Closed
Conversation
JSONbored
approved these changes
Jul 27, 2026
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ❌ Deployment failed View logs |
loopover-ui | 45e85bf | Jul 27 2026, 08:09 AM |
Contributor
|
Superagent didn't find any vulnerabilities or security issues in this PR. |
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
July 27, 2026 07:08
ce387c6 to
c5d561a
Compare
|
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
July 27, 2026 07:12
c5d561a to
712bd87
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
July 27, 2026 07:24
712bd87 to
c460cf8
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
July 27, 2026 07:35
c460cf8 to
089445d
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
July 27, 2026 07:59
089445d to
49b1867
Compare
renovate
Bot
force-pushed
the
renovate/npm-minor-patch
branch
from
July 27, 2026 08:06
49b1867 to
45e85bf
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.3.205→^0.3.218^0.18.0→^0.18.8^5.20260721.1→^5.20260724.1^9.39.4→^9.39.5^2.0.0→^2.0.11^2.0.8→^2.0.111.0.3→1.2.11.1.2→1.1.42.6.5→2.7.7^0.220.0→^0.221.0^2.9.0→^2.10.0^2.9.0→^2.10.0^1.2.15→^1.2.18^1.1.18→^1.1.21^1.1.11→^1.1.13^1.2.1→^1.2.4^1.3.6→^1.3.9^1.1.15→^1.1.18^2.3.2→^2.3.5^1.1.18→^1.1.21^2.1.19→^2.1.22^1.1.18→^1.1.21^2.1.11→^2.1.13^1.1.19→^1.1.22^1.2.17→^1.2.20^1.1.18→^1.1.21^1.1.11→^1.1.14^1.4.2→^1.4.5^1.2.13→^1.2.16^2.3.2→^2.3.5^1.1.11→^1.1.13^1.4.2→^1.4.5^1.3.0→^1.3.1^1.3.2→^1.3.5^1.1.16→^1.1.19^1.1.13→^1.1.16^1.1.14→^1.1.17^1.2.11→^1.2.14^0.9.55→^0.9.59^10.63.0→^10.67.0^10.63.0→^10.67.0^4.3.2→^4.3.3^5.101.2→^5.101.4^1.170.17→^1.170.18^1.168.27→^1.168.32^1.168.19→^1.168.23^22.20.0→^22.20.1^22.20.0→^22.20.1^24.13.2→^24.13.3^19.2.7→^19.2.17^5.1.4→^5.2.0^4.1.9→^4.1.10^0.17.3→^0.19.0^9.39.4→^9.39.5^5.5.5→^5.5.6^7.0.1→^7.1.1^0.5.2→^0.5.3^16.11.4→^16.12.1^15.1.1→^15.2.0^17.4.0→^17.7.0^4.12.27→^4.12.31^4.12.27→^4.12.31^8.5.18→^8.5.22^5.44.0→^5.46.1^5.44.0→^5.46.13.9.4→3.9.6^3.9.4→^3.9.6^3.8.1→^3.9.6^19.2.7→^19.2.8^19.2.7→^19.2.8^7.80.0→^7.82.0^4.12.0→^4.12.2^7.8.4→^7.8.5^0.35.0→^0.35.3^4.3.2→^4.3.3^4.22.5→^4.23.1^2.10.5→^2.10.6^8.62.1→^8.65.0^8.56.1→^8.65.0^8.1.3→^8.1.5^4.1.9→^4.1.10^0.20.8→^0.26.11^4.107.0→^4.114.0^4.107.0→^4.114.0^4.112.0→^4.114.0^8.21.0→^8.21.1Dependency PRs must keep
npm run test:cipassing. The 97% coverage requirement is enforced as Codecov patch coverage on changed lines (codecov/patch), so dependency-only bumps satisfy it without new tests.GitHub Actions updates must remain SHA-pinned.
Renovate is the sole dependency and security-update bot for this repo; GitHub Dependabot security updates are disabled to avoid duplicate PRs (e.g. the two hono advisory PRs).
Release Notes
anthropics/claude-agent-sdk-typescript (@anthropic-ai/claude-agent-sdk)
v0.3.218Compare Source
SkillToolOutputnow reportsbackground: truewhen a forked skill was dispatched as a detached background agentapi_error_statusreporting null for rate-limit and overloaded errors delivered mid-stream; it now reports 429/529canonicalModelandproviderto eachmodelUsageentry in result messages so downstream billing can look up the correct rate table forcostUSDv0.3.217Compare Source
CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTHto allow deeper nestingCLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS)v0.3.216Compare Source
skippedLinkscount torewindFilesresponses for paths the rewind safety guards refused to restore or deletetool_result_metasidecar to user messages (non_execution_kind,user_feedback) so consumers can classify denied, interrupted, or cancelled tool calls without string-matching result proseuser_message_uuidandrequest_sent_wall_msfields to the success result message for cross-host request-latency correlationv0.3.215Compare Source
v0.3.214set_permission_modenow rejects unrecognized permission modes with an error instead of silently adopting them; the'manual'alias is accepted at every ingresssubkind: 'scheduled-trigger'to thetask-notificationmember ofSDKMessageOrigin, marking deliveries that are the fired prompt of a user-configured scheduled taskapplyFlagSettings({effortLevel})now accepts'max'in its TypeScript type (runtime already supported it)interrupt()now carryaborted: true, so consumers can distinguish a mid-stream partial from a completed messagesubagent_typeandsubagent_retryfields totool_progressmessages so clients can show a subagent waiting out an API rate-limit retrysystem/initmessage'spluginsentries and thereload_pluginsresponse now include each plugin's manifestversion"fork"instead of"resume"when the session begins as a forkv0.3.213v0.3.212Compare Source
resumeSessionAtandsessionIdvalues being passed to the CLI as separate argv tokens; both now use equals-form (--flag=value)v0.3.211Compare Source
--replay-user-messageswith--include-partial-messagesemitting the turn-start user replay after the first content block instead of before the turn's content eventsSDKAssistantMessage.timestamp(ISO-8601) to the live stream, matchingSDKUserMessage; older emitters omit it, consumers should fall back to receive timeUSAGE_LIMIT_ERROR_PREFIXESand siblings) as@alphaexports for classifying rate-limit messages without hand-mirrored listsv0.3.210Compare Source
timedOutAfterMstoBashToolOutput, set when a command is auto-backgrounded on timeoutv0.3.209Compare Source
v0.3.208Compare Source
UserPromptSubmithook callback exceeding its timeout killing the entire query with an empty error; it now blocks the prompt with a clear timeout message and the session continuesextraArgsvalues that look like flags (e.g.resume: '--version') being parsed as their own CLI flags; dash-leading values are now bound with equals-form argvAbortControllerno longer accumulateabortlisteners on its signal after each completed querycreateSdkMcpServerdocs pointing at a nonexistent env var; the MCP tool-call timeout knob isMCP_TOOL_TIMEOUTv0.3.207Compare Source
canUseToolreturning{behavior: 'allow'}withoutupdatedInputbeing rejected as a deny with a raw ZodError message; the tool now runs with the original input per the documented contractAgentToolCompletedOutput) that matches the emitted object exactlyv0.3.206Compare Source
command_lifecycleframes to stream-json and SDK sessions, reporting each uuid-stamped message's terminal state (queued/started/completed/cancelled/discarded); zero-API results no longer report staleduration_api_mscloudflare/workers-sdk (@cloudflare/vitest-pool-workers)
v0.18.8Compare Source
Patch Changes
#14793
7b3fea6Thanks @trafgals! - Prevent worker disposal errors from failing otherwise successful test runsErrors raised while disposing test Workers are now logged for diagnostics rather than overriding the test result. Set
NODE_DEBUG=vitest-pool-workersto view these errors.Updated dependencies [
246ce92,c38a2c3,8416b33,c079ba3,4683ff8,95b026e,02232f3,c4bacec,f8a8c2c,3203b5d]:v0.18.7Compare Source
Patch Changes
#14713
de34449Thanks @allocsys! - Fix a non-ASCII path failure during the Miniflare WebSocket handshake: theMF-Vitest-Worker-Dataheader embedded the rawprocess.cwd()value, which threw a Latin-1/ASCII header encoding error when the workspace path contained non-ASCII characters (e.g. CJK characters) on Windows. The value is now percent-encoded on write and decoded on read, matching the fix applied to the module fallback redirect response.#14713
de34449Thanks @allocsys! - Fix a runtime start-up failure ("No such module "cloudflare:test-internal"") when the project workspace path contains non-ASCII characters (e.g. CJK characters) on Windows. The module fallback service's redirect response set the target file path directly as an HTTPLocationheader value, but headers are restricted to the Latin-1/ASCII byte range, so any non-ASCII byte in the path caused header construction to throw. Such paths are now percent-encoded (and tagged with a sentinel prefix) before being used as a header value, and decoded again only for the values we encoded, so the round-trip is unambiguous and a workspace path containing a literal%is left untouched instead of being mis-decoded.#14739
5eac99eThanks @Ankcorn! - Support testing Streaming Tail Workers in Vitest Pool Workers.#14763
538e867Thanks @gianghungtien! - TreatwebSocketMessage(),webSocketClose()andwebSocketError()as optional Durable Object handlersThe pool wraps each Durable Object class and installs a prototype method for every default handler before user code is loaded, so
workerdalways sees a handler and always dispatches. When the wrapped class didn't actually define one, the wrapper threw<ClassName> exported by <path> does not define a `webSocketClose()` method, even though deployed Workers silently ignore these events for classes that omit them. A hibernatable Durable Object defining onlywebSocketMessage()would log an uncaughtTypeErroron every close.These three handlers now no-op when absent, matching deployed behaviour.
alarm()is unchanged and still reports a missing handler, sinceworkerdrejectssetAlarm()up front on a class without one.Updated dependencies [
42af66d,a0a091b,f03b108,deae171,0df3d43,d83a476,4e92e32,d1d6945,4815711,a0c8bb1,a50f73a,2b390d7,c82d96b,34430b3,f75ae5d]:v0.18.6Compare Source
Patch Changes
#14678
4e62bbaThanks @apeacock1991! - Fix test runs hanging after a Durable Object logs and rejectsblockConcurrencyWhile()Console messages emitted from another Durable Object are now buffered until execution returns to the test runner, avoiding I/O that cannot complete after the object's input gate breaks.
Updated dependencies [
34e696d,d39ae01,3de70df,c79504f,9f04a7e,9f04a7e,cb30df3,cb6c3f9,c7dbe1a,3f3afbb,e6fbc4e,4e1a7a7, [9f04a7e](https://redirect.giConfiguration
📅 Schedule: (in timezone America/Phoenix)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.