Commit Graph

330 Commits

Author SHA1 Message Date
jkomyno 994b2f2fff Merge branch next into chore/changesets-v3-migration 2026-08-25 01:44:03 +02:00
dependabot[bot] 96d6c87705 fix(deps): bump the npm-production group across 1 directory with 26 updates (#4231)
Bumps the npm-production group with 26 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
|
[@anthropic-ai/claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-typescript)
| `0.3.233` | `0.3.239` |
|
[@mastra/mcp](https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp)
| `1.16.0` | `1.17.1` |
| [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `6.0.256` |
`6.0.263` |
|
[@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript)
| `0.117.1` | `0.120.0` |
| [@google/genai](https://github.com/googleapis/js-genai) | `2.17.1` |
`2.18.0` |
| [@langchain/core](https://github.com/langchain-ai/langchainjs) |
`1.2.8` | `1.2.9` |
|
[@langchain/langgraph](https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core)
| `1.4.10` | `1.4.12` |
| [@langchain/openai](https://github.com/langchain-ai/langchainjs) |
`1.5.8` | `1.5.10` |
| [langchain](https://github.com/langchain-ai/langchainjs) | `1.5.9` |
`1.5.10` |
| [@openai/agents](https://github.com/openai/openai-agents-js) |
`0.16.0` | `0.17.0` |
| [@langchain/anthropic](https://github.com/langchain-ai/langchainjs) |
`1.5.6` | `1.5.8` |
| [@langchain/mcp-adapters](https://github.com/langchain-ai/langchainjs)
| `1.1.3` | `1.1.4` |
|
[@agentclientprotocol/sdk](https://github.com/agentclientprotocol/typescript-sdk)
| `1.3.0` | `1.4.0` |
| [typebox](https://github.com/sinclairzx81/typebox) | `1.3.14` |
`1.3.16` |
| [@ai-sdk/mcp](https://github.com/vercel/ai/tree/HEAD/packages/mcp) |
`2.0.32` | `2.0.34` |
|
[@ai-sdk/openai](https://github.com/vercel/ai/tree/HEAD/packages/openai)
| `4.0.42` | `4.0.45` |
|
[@cloudflare/vitest-pool-workers](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vitest-pool-workers)
| `0.21.3` | `0.22.0` |
| [@cloudflare/workers-types](https://github.com/cloudflare/workerd) |
`5.20260815.1` | `5.20260821.1` |
|
[@mastra/core](https://github.com/mastra-ai/mastra/tree/HEAD/packages/core)
| `1.52.1` | `1.61.0` |
|
[@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk)
| `1.26.0` | `1.30.0` |
|
[@types/bun](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/bun)
| `1.3.14` | `1.4.0` |
|
[@vitest/ui](https://github.com/vitest-dev/vitest/tree/HEAD/packages/ui)
| `4.1.10` | `4.1.11` |
| [pnpm](https://github.com/pnpm/pnpm/tree/HEAD/pnpm11/pnpm) | `11.21.0`
| `11.22.0` |
|
[publint](https://github.com/publint/publint/tree/HEAD/packages/publint)
| `0.3.23` | `0.3.24` |
|
[vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest)
| `4.1.10` | `4.1.11` |
|
[wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler)
| `4.123.0` | `4.125.0` |


Updates `@anthropic-ai/claude-agent-sdk` from 0.3.233 to 0.3.239
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/claude-agent-sdk-typescript/releases">@​anthropic-ai/claude-agent-sdk's
releases</a>.</em></p>
<blockquote>
<h2>v0.3.239</h2>
<h2>What's changed</h2>
<ul>
<li><code>total_cost_usd</code> / <code>modelUsage.costUSD</code> now
include the 1.1× US-only-inference (data residency) multiplier when the
response reports <code>inference_geo: &quot;us&quot;</code></li>
<li>A result held back for background subagents in one-shot mode now
reports <code>total_cost_usd</code>, <code>duration_api_ms</code> and
<code>modelUsage</code> as of its release, not the turn-end
snapshot</li>
<li>Fixed <code>SYSTEM_PROMPT_DYNAMIC_BOUNDARY</code> in an array
<code>systemPrompt</code> being sent to the model as literal text on
Bedrock, Vertex, Foundry, and gateway providers</li>
<li>A repeated <code>initialize</code> on a running process is now
followed by a <code>background_tasks_changed</code> snapshot of the live
background tasks, so reconnecting hosts see work that is still
running</li>
</ul>
<h2>Update</h2>
<pre lang="sh"><code>npm install @anthropic-ai/claude-agent-sdk@0.3.239
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.239
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.239
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.239
</code></pre>
<h2>v0.3.238</h2>
<h2>What's changed</h2>
<ul>
<li>Added <code>is_backgrounded</code> and <code>spawn_depth</code> to
<code>task_started</code> events for subagent tasks
(<code>is_backgrounded</code> also on background Bash tasks)</li>
<li>Added <code>suppressOriginalPrompt</code> to
<code>UserPromptExpansion</code> hook output, matching
<code>UserPromptSubmit</code></li>
<li>Added <code>command_lifecycle</code> state <code>refused</code>: a
cross-session peer message the session's receive-side policy declines
now reports this terminal state instead of producing no lifecycle
frames</li>
<li>Fixed SDK hook callbacks silently not applying after a host re-sends
<code>initialize</code> to an already-running CLI; the response now
reports <code>hooks_applied</code></li>
<li>Fixed <code>CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=true</code> not
keeping <code>prompt_suggestion</code> messages on when the account is
near, but not over, its usage limit</li>
<li>Changed <code>vcs_state_changed</code> push events to emit one event
per pushed branch</li>
</ul>
<h2>Update</h2>
<pre lang="sh"><code>npm install @anthropic-ai/claude-agent-sdk@0.3.238
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.238
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.238
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.238
</code></pre>
<h2>v0.3.237</h2>
<h2>What's changed</h2>
<ul>
<li>Updated to parity with Claude Code v2.1.237</li>
</ul>
<h2>Update</h2>
<pre lang="sh"><code>&lt;/tr&gt;&lt;/table&gt; 
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/claude-agent-sdk-typescript/blob/main/CHANGELOG.md">@​anthropic-ai/claude-agent-sdk's
changelog</a>.</em></p>
<blockquote>
<h2>0.3.239</h2>
<ul>
<li><code>total_cost_usd</code> / <code>modelUsage.costUSD</code> now
include the 1.1× US-only-inference (data residency) multiplier when the
response reports <code>inference_geo: &quot;us&quot;</code></li>
<li>A result held back for background subagents in one-shot mode now
reports <code>total_cost_usd</code>, <code>duration_api_ms</code> and
<code>modelUsage</code> as of its release, not the turn-end
snapshot</li>
<li>Fixed <code>SYSTEM_PROMPT_DYNAMIC_BOUNDARY</code> in an array
<code>systemPrompt</code> being sent to the model as literal text on
Bedrock, Vertex, Foundry, and gateway providers</li>
<li>A repeated <code>initialize</code> on a running process is now
followed by a <code>background_tasks_changed</code> snapshot of the live
background tasks, so reconnecting hosts see work that is still
running</li>
</ul>
<h2>0.3.238</h2>
<ul>
<li>Added <code>is_backgrounded</code> and <code>spawn_depth</code> to
<code>task_started</code> events for subagent tasks
(<code>is_backgrounded</code> also on background Bash tasks)</li>
<li>Added <code>suppressOriginalPrompt</code> to
<code>UserPromptExpansion</code> hook output, matching
<code>UserPromptSubmit</code></li>
<li>Added <code>command_lifecycle</code> state <code>refused</code>: a
cross-session peer message the session's receive-side policy declines
now reports this terminal state instead of producing no lifecycle
frames</li>
<li>Fixed SDK hook callbacks silently not applying after a host re-sends
<code>initialize</code> to an already-running CLI; the response now
reports <code>hooks_applied</code></li>
<li>Fixed <code>CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=true</code> not
keeping <code>prompt_suggestion</code> messages on when the account is
near, but not over, its usage limit</li>
<li>Changed <code>vcs_state_changed</code> push events to emit one event
per pushed branch</li>
</ul>
<h2>0.3.237</h2>
<ul>
<li>Updated to parity with Claude Code v2.1.237</li>
</ul>
<h2>0.3.236</h2>
<ul>
<li><code>PostToolUse</code> hooks can return
<code>hookSpecificOutput.classifierContext</code>, a short host-asserted
note about a tool call's result that the auto mode permission classifier
reads alongside that result</li>
</ul>
<h2>0.3.235</h2>
<ul>
<li>Updated to parity with Claude Code v2.1.235</li>
</ul>
<h2>0.3.234</h2>
<ul>
<li>Removed unused <code>bypass_permissions_disabled</code> from
<code>ExitReason</code> type; the value was never emitted — TypeScript
consumers with an explicit <code>case</code> branch get a compile error
on upgrade (runtime unaffected)</li>
<li>Updated the <code>ApiKeySource</code> type to include the values
<code>system/init</code> actually reports
(<code>ANTHROPIC_API_KEY</code>, <code>apiKeyHelper</code>, <code>/login
managed key</code>, <code>none</code>)</li>
<li><code>vcs_state_changed</code> events report the directory the shell
finished in (an inner <code>cd</code> is reflected)</li>
<li>A peer <code>origin</code> injected by the host may declare the
sending session's permission class (<code>fromMode</code>) so a
same-class message is delivered to a recipient that runs without
asking</li>
<li><code>SDKSystemMessage</code>
(<code>system</code>/<code>init</code>) gains an optional
<code>effort</code> field: the session's applied effort level, or
<code>null</code> when none is sent. Set on Remote Control bridge init
frames</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/ae7e3dd656244b67e8634c33b3137775ae5a3fcd"><code>ae7e3dd</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/c4fdbe3a4309f7165a4c3bee179c155d0422ff4c"><code>c4fdbe3</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/591a180a197a73ce90042a6f97a7c59c100d2c3a"><code>591a180</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/d933c997f2282179582d97c562b4d3451e74c0ee"><code>d933c99</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/076593f6db4357c3a050a5ed19c39ba1217eab3a"><code>076593f</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/a616205d6cb7c2f5907120f660f6391310918369"><code>a616205</code></a>
chore: Update CHANGELOG.md</li>
<li>See full diff in <a
href="https://github.com/anthropics/claude-agent-sdk-typescript/compare/v0.3.233...v0.3.239">compare
view</a></li>
</ul>
</details>
<br />

Updates `@mastra/mcp` from 1.16.0 to 1.17.1
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/mastra-ai/mastra/blob/main/packages/mcp/CHANGELOG.md">@​mastra/mcp's
changelog</a>.</em></p>
<blockquote>
<h2>1.17.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>Fixed MCP tool listing when a tool has no input schema. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/21861">#21861</a>)</p>
</li>
<li>
<p>Fixed <code>Cannot find package '@modelcontextprotocol/sdk'</code>
when importing <code>@mastra/mcp</code> in projects that skip automatic
peer installation (e.g. npm with <code>--legacy-peer-deps</code>), by
declaring the MCP SDK v1 peer required by
<code>@modelcontextprotocol/ext-apps</code> as a direct dependency. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/21999">#21999</a>)</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/mastra-ai/mastra/commit/88d14cac008582a618fecc3d5c7fd3bdf4f6ddc3"><code>88d14ca</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/480e491588bd6a7a1c9ee4407590ad625dd33952"><code>480e491</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/9267e9b3d9c2fcf16936050495a787054c2431ab"><code>9267e9b</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/acc3471de5f3fde8027ee4e355af292b2bc1bc30"><code>acc3471</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/b6a771ef23d203ddb348efca8065eff65def8191"><code>b6a771e</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/9267e9b3d9c2fcf16936050495a787054c2431ab"><code>9267e9b</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/3bb88ddf07fb98f3cd16d3bff94e51cd3b45d011"><code>3bb88dd</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/d23e75d57cc7cf5b9bfdbee896bf5a6a2484fed7"><code>d23e75d</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/c8faa4e1cfebaec56b65e754e90b9fe46d153359"><code>c8faa4e</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/d378d7511f71309ed61a8f6b93cd0361dc6cb70f"><code>d378d75</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/26d40160ff7f7d8bf95fee2039a52cbc83863533"><code>26d4016</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/7c60df5c7872343fbac5c3e5b1175c8076a5abfd"><code>7c60df5</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/9267e9b3d9c2fcf16936050495a787054c2431ab"><code>9267e9b</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/f2031a47445e8f67a89ba1309036816f97ab7a65"><code>f2031a4</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/9267e9b3d9c2fcf16936050495a787054c2431ab"><code>9267e9b</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/cad42082e6aa1776168a94914f523334be45d929"><code>cad4208</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/8e529d4ac754efef04b225841349e0da9edf89a6"><code>8e529d4</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/57c51035a2a36e3df3c4f32f46bb789a66ed5946"><code>57c5103</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/038b7b405cb4ac25ab3f3031334111b1f87ac112"><code>038b7b4</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/4132d61f8367077120ee9e6420d3224dffd93c93"><code>4132d61</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/d378d7511f71309ed61a8f6b93cd0361dc6cb70f"><code>d378d75</code></a>]:</p>
<ul>
<li><code>@​mastra/core</code><a
href="https://github.com/1"><code>@​1</code></a>.61.0</li>
</ul>
</li>
</ul>
<h2>1.17.1-alpha.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>Fixed <code>Cannot find package '@modelcontextprotocol/sdk'</code>
when importing <code>@mastra/mcp</code> in projects that skip automatic
peer installation (e.g. npm with <code>--legacy-peer-deps</code>), by
declaring the MCP SDK v1 peer required by
<code>@modelcontextprotocol/ext-apps</code> as a direct dependency. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/21999">#21999</a>)</p>
</li>
<li>
<p>Updated dependencies:</p>
<ul>
<li><code>@​mastra/core</code><a
href="https://github.com/1"><code>@​1</code></a>.61.0-alpha.4</li>
</ul>
</li>
</ul>
<h2>1.17.1-alpha.0</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>Fixed MCP tool listing when a tool has no input schema. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/21861">#21861</a>)</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/mastra-ai/mastra/commit/88d14cac008582a618fecc3d5c7fd3bdf4f6ddc3"><code>88d14ca</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/84a5b699f84d6bae0a34efe5a970d891090b9f41"><code>84a5b69</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/038b7b405cb4ac25ab3f3031334111b1f87ac112"><code>038b7b4</code></a>,
<a
href="https://github.com/mastra-ai/mastra/commit/4132d61f8367077120ee9e6420d3224dffd93c93"><code>4132d61</code></a>]:</p>
<ul>
<li><code>@​mastra/core</code><a
href="https://github.com/1"><code>@​1</code></a>.60.1-alpha.0</li>
</ul>
</li>
</ul>
<h2>1.17.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>
<p>MCP tools served over HTTP now see the authenticated caller. When an
MCP server runs behind a Mastra server with <code>server.auth</code>
configured, the resolved user is bridged into
<code>extra.authInfo</code> automatically, on both the streamable HTTP
and SSE transports. Previously <code>extra.authInfo</code> was always
undefined because the request handed to the MCP transport was rebuilt
without the auth data. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/21689">#21689</a>)</p>
<p><strong>Custom verification</strong></p>
<p>If your own middleware verifies the caller, build the auth info
yourself with the new <code>server.mcpOptions.setRequestAuth</code>
hook:</p>
<pre lang="ts"><code>export const mastra = new Mastra({
  mcpServers: { myServer },
  server: {
    middleware: [verifyBearerToken],
    mcpOptions: {
      setRequestAuth: (req, requestContext) =&gt; {
        const payload = requestContext.get('bearerPayload');
req.auth = { token: payload.token, clientId: payload.sub, scopes:
payload.scope.split(' ') };
      },
    },
</code></pre>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/mastra-ai/mastra/commit/ce66f918f0e27984772b524220e87be0e69cebe3"><code>ce66f91</code></a>
chore: version - exit prerelease mode</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/cc6549590e54065c70721a2b4af025c91550792b"><code>cc65495</code></a>
chore: version packages (alpha) (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/22001">#22001</a>)</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/1d41dd06a001c6fee3aab1cdf1ec759f2070df3e"><code>1d41dd0</code></a>
fix(mcp): declare <code>@​modelcontextprotocol/sdk</code> v1 as a direct
dependency (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/21999">#21999</a>)</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/8c6990aefc426c68a63560328bef4033f9ae8f77"><code>8c6990a</code></a>
chore: version packages</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/64cd7ac22c2c7a6e6b533a4b3a9ede432700f1fb"><code>64cd7ac</code></a>
fix(mcp): list tools without input schemas (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/21861">#21861</a>)</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/c23d44525cb59f271fca8978bbaae05b7b6b3b9e"><code>c23d445</code></a>
chore: version - exit prerelease mode</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/86bde188a70540ebe849bd8a77594d88ffb77e2f"><code>86bde18</code></a>
chore: version packages (alpha) (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/21734">#21734</a>)</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/39ba1b9ce256a9a910a16f125cc6a59588185bfe"><code>39ba1b9</code></a>
feat(mcp): elicitation on the 2026-07-28 protocol leg via multi
round-trip re...</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/0f53aeb119158bd9f83bd8ef667f1f675740e8f0"><code>0f53aeb</code></a>
feat(mcp): opt-in MCP protocol revision 2026-07-28 behind a
protocolVersion f...</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/9f626699ac4422352721b2a3ca95ed5543763294"><code>9f62669</code></a>
chore: version packages (alpha) (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/21597">#21597</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/mastra-ai/mastra/commits/@mastra/mcp@1.17.1/packages/mcp">compare
view</a></li>
</ul>
</details>
<br />

Updates `ai` from 6.0.256 to 6.0.263
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/ai/blob/ai@6.0.263/packages/ai/CHANGELOG.md">ai's
changelog</a>.</em></p>
<blockquote>
<h2>6.0.263</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [1e70580]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.179</li>
</ul>
</li>
</ul>
<h2>6.0.262</h2>
<h3>Patch Changes</h3>
<ul>
<li>30526e9: Prevent exceptions in streaming <code>onChunk</code> and
<code>onError</code> callbacks from terminating the stream or masking
provider errors.</li>
<li>Updated dependencies [7de3226]</li>
<li>Updated dependencies [504da15]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.178</li>
</ul>
</li>
</ul>
<h2>6.0.261</h2>
<h3>Patch Changes</h3>
<ul>
<li>f1afbf9: Fix array-backed language model mocks to return configured
results in order from the first call.</li>
</ul>
<h2>6.0.260</h2>
<h3>Patch Changes</h3>
<ul>
<li>98c656f: fix: reject <code>streamObject</code> result promises and
report failed completion when the provider stream errors</li>
<li>b253d52: Filter preliminary tool outputs when
<code>ignoreIncompleteToolCalls</code> is enabled.</li>
<li>9e15cb4: Prevent automatic tool execution when a model call ends
with an unsafe finish reason.</li>
</ul>
<h2>6.0.259</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [def7999]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.177</li>
</ul>
</li>
</ul>
<h2>6.0.258</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [96304fc]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.176</li>
</ul>
</li>
</ul>
<h2>6.0.257</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [000b243]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.175</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vercel/ai/commit/23e4c50cf56b0a9fca260098b731b1f730fd6254"><code>23e4c50</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19261">#19261</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/b55c2a9941725e0723a0abb0dc26a00baddab59b"><code>b55c2a9</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19212">#19212</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/30526e9ec8265181756c24ac6e8ff41b17d4366f"><code>30526e9</code></a>
[v6.0] fix: contain streaming callback exceptions without interrupting
consum...</li>
<li><a
href="https://github.com/vercel/ai/commit/d3f6cc9591a5482656decf88ee5cd08cdfaddc58"><code>d3f6cc9</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19191">#19191</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/f1afbf981dc66ea4ca290d778232b96640b6c14a"><code>f1afbf9</code></a>
[v6.0] fix: return array-backed mock language model results in
configured ord...</li>
<li><a
href="https://github.com/vercel/ai/commit/bb5526fc0b981bcb2c95accde20bf93b1b317de2"><code>bb5526f</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19131">#19131</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/9e15cb48a5f82f8e241ed71ad28918341ae5b16a"><code>9e15cb4</code></a>
[v6.0] fix: automatic tools executing after unsafe model finish reasons
(<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19120">#19120</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/b253d5245e9cd29a59811d1a18677c63c9a77f93"><code>b253d52</code></a>
[v6.0] fix: omit preliminary tool outputs when ignoring incomplete tool
calls...</li>
<li><a
href="https://github.com/vercel/ai/commit/98c656f768f0ae3a887b4251340f397d878ce5de"><code>98c656f</code></a>
[v6.0] fix: settle streamObject results and report provider stream
failures w...</li>
<li><a
href="https://github.com/vercel/ai/commit/815515120857394d2a3d3979a399f2cf4380a80f"><code>8155151</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/19079">#19079</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vercel/ai/commits/ai@6.0.263/packages/ai">compare
view</a></li>
</ul>
</details>
<br />

Updates `@anthropic-ai/sdk` from 0.117.1 to 0.120.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/anthropic-sdk-typescript/releases">@​anthropic-ai/sdk's
releases</a>.</em></p>
<blockquote>
<h2>sdk: v0.120.0</h2>
<h2>0.120.0 (2026-08-19)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.119.0...sdk-v0.120.0">sdk-v0.119.0...sdk-v0.120.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> managed agents web search config and self
hosted sandbox memory (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ba8ec50ffe31e10781971a942d54289439307424">ba8ec50</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>internal:</strong> use a single pnpm workspace lockfile (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/359">#359</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/3c32145d2bc4d53888c6c6857c9af216eec95fb9">3c32145</a>)</li>
</ul>
<h2>sdk: v0.119.0</h2>
<h2>0.119.0 (2026-08-19)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.118.0...sdk-v0.119.0">sdk-v0.118.0...sdk-v0.119.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> Files and Skills APIs are now GA; add computer
use and browser use toolsets (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ab41aa32b92a7964b35beb42a6be5b0bec1dd735">ab41aa3</a>)</li>
</ul>
<h2>sdk: v0.118.0</h2>
<h2>0.118.0 (2026-08-18)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.117.1...sdk-v0.118.0">sdk-v0.117.1...sdk-v0.118.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> additions to files and memory stores (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/fdc03790dc3e7fb0352298382f8a9603e92e19c2">fdc0379</a>)</li>
<li><strong>api:</strong> updates to skill, files, and user profiles (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/671e6b187f475b5a7a797adbbe5b908bd74d3935">671e6b1</a>)</li>
<li><strong>client:</strong> add helpers for accessing the workspace ID
in response headers (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/28aa5afe3284bcdc2cc35264f6f4d8dd762e186f">28aa5af</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>api:</strong> remove unsupported mid_conv_system content
block (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ae6ca9403125b5a0effb22c9d9c65804a99a80bd">ae6ca94</a>)</li>
<li><strong>session-runner:</strong> retry tool-result sends for at
least the lease TTL (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/339">#339</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/7dc632557bfea8475aab8345e27469f02faa6a5a">7dc6325</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>internal:</strong> bump zod to 4.4.3 (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/334">#334</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/faa5b7b841a31967ee4679423c22802d4e70c79f">faa5b7b</a>)</li>
<li><strong>internal:</strong> remove leftover prism references (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/a163b960ce982ffb2827a0e95a5ae05a1120aa51">a163b96</a>)</li>
<li>stop shipping the v0.50 migration guide and migrate CLI (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/53992d708ba024c25adabc864fe0268cc065865d">53992d7</a>)</li>
</ul>
<h3>Documentation</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md">@​anthropic-ai/sdk's
changelog</a>.</em></p>
<blockquote>
<h2>0.120.0 (2026-08-19)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.119.0...sdk-v0.120.0">sdk-v0.119.0...sdk-v0.120.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> managed agents web search config and self
hosted sandbox memory (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ba8ec50ffe31e10781971a942d54289439307424">ba8ec50</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>internal:</strong> use a single pnpm workspace lockfile (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/359">#359</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/3c32145d2bc4d53888c6c6857c9af216eec95fb9">3c32145</a>)</li>
</ul>
<h2>0.119.0 (2026-08-19)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.118.0...sdk-v0.119.0">sdk-v0.118.0...sdk-v0.119.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> Files and Skills APIs are now GA; add computer
use and browser use toolsets (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ab41aa32b92a7964b35beb42a6be5b0bec1dd735">ab41aa3</a>)</li>
</ul>
<h2>0.118.0 (2026-08-18)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.117.1...sdk-v0.118.0">sdk-v0.117.1...sdk-v0.118.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> additions to files and memory stores (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/fdc03790dc3e7fb0352298382f8a9603e92e19c2">fdc0379</a>)</li>
<li><strong>api:</strong> updates to skill, files, and user profiles (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/671e6b187f475b5a7a797adbbe5b908bd74d3935">671e6b1</a>)</li>
<li><strong>client:</strong> add helpers for accessing the workspace ID
in response headers (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/28aa5afe3284bcdc2cc35264f6f4d8dd762e186f">28aa5af</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>api:</strong> remove unsupported mid_conv_system content
block (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ae6ca9403125b5a0effb22c9d9c65804a99a80bd">ae6ca94</a>)</li>
<li><strong>session-runner:</strong> retry tool-result sends for at
least the lease TTL (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/339">#339</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/7dc632557bfea8475aab8345e27469f02faa6a5a">7dc6325</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>internal:</strong> bump zod to 4.4.3 (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/334">#334</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/faa5b7b841a31967ee4679423c22802d4e70c79f">faa5b7b</a>)</li>
<li><strong>internal:</strong> remove leftover prism references (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/a163b960ce982ffb2827a0e95a5ae05a1120aa51">a163b96</a>)</li>
<li>stop shipping the v0.50 migration guide and migrate CLI (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/53992d708ba024c25adabc864fe0268cc065865d">53992d7</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li><strong>tools:</strong> warn that blocking tool bodies stall the
worker heartbeat (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/299">#299</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/908fdb5d9de8809190bdcf9d14a8319e80d8f31c">908fdb5</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/bfa9197f0182084941052be9752c948638421601"><code>bfa9197</code></a>
chore: release main</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/bc167f3c8fe36137c5594a3776e9677d493e6618"><code>bc167f3</code></a>
feat(api): managed agents web search config and self hosted sandbox
memory</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/83fd8981a7b11321257027c817755305cc0a4b59"><code>83fd898</code></a>
chore(internal): use a single pnpm workspace lockfile (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/359">#359</a>)</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/7fe6dd50d509bb68eb0981ad1f7ad046984b426e"><code>7fe6dd5</code></a>
remove internal ticket references from changelog- <a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/360">#360</a></li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/c67e4e2d2329d25ba057f5e60c6dec3b2f33ba97"><code>c67e4e2</code></a>
chore: release main</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/50fc0dba920417d641734f4abef51627c4785380"><code>50fc0db</code></a>
feat(api): Files and Skills APIs are now GA; add computer use and
browser use...</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/18ea26d324911c3236f2ce762dd0c87f04d038d3"><code>18ea26d</code></a>
chore: release main</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/6ed9ddd8924924d20ff4610b83668754629f9478"><code>6ed9ddd</code></a>
feat(api): updates to skill, files, and user profiles</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/91921f5f0410a8caa638a85b0d38a8102d7e3c91"><code>91921f5</code></a>
fix(session-runner): retry tool-result sends for at least the lease TTL
(<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/339">#339</a>)</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/142adcc2b864940a72464e41b63cc5733f38187b"><code>142adcc</code></a>
docs(tools): warn that blocking tool bodies stall the worker heartbeat
(<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/299">#299</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.117.1...sdk-v0.120.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `@google/genai` from 2.17.1 to 2.18.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/googleapis/js-genai/releases">@​google/genai's
releases</a>.</em></p>
<blockquote>
<h2>v2.18.0</h2>
<h2><a
href="https://github.com/googleapis/js-genai/compare/v2.17.1...v2.18.0">2.18.0</a>
(2026-08-19)</h2>
<h3>Features</h3>
<ul>
<li>Add <code>mode</code> enum (<code>VERBATIM</code>,
<code>SMART</code>) to <code>AudioTranscriptionConfig</code> and
<code>TranscriptionConfig</code>. (<a
href="https://github.com/googleapis/js-genai/commit/4c5208baa923cecea897b7b4fdc9de5e49555709">4c5208b</a>)</li>
<li>Add enable_data_retention to ToolParallelAiSearch, Add step_count to
ReinforcementTuningHyperParameters, Add BidiGenerateContentSetup (<a
href="https://github.com/googleapis/js-genai/commit/f52c20858c1bf6c7892192bc41cfc027d30b57ab">f52c208</a>)</li>
<li>Add IDLE state to live connection status enum and mark
REQUIRES_ACTION as deprecated. (<a
href="https://github.com/googleapis/js-genai/commit/2f110f23372cf2ea52452fe57ddf3a4e30833857">2f110f2</a>)</li>
<li>add video resolution and extension task parameters (<a
href="https://github.com/googleapis/js-genai/commit/39b2a2dea4c5ff75c1754581b213b9d480504e7d">39b2a2d</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>fix examples (<a
href="https://github.com/googleapis/js-genai/commit/3f631be857d0faec43012c2510ce17caea5bffe8">3f631be</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/googleapis/js-genai/blob/main/CHANGELOG.md">@​google/genai's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/googleapis/js-genai/compare/v2.17.1...v2.18.0">2.18.0</a>
(2026-08-19)</h2>
<h3>Features</h3>
<ul>
<li>Add <code>mode</code> enum (<code>VERBATIM</code>,
<code>SMART</code>) to <code>AudioTranscriptionConfig</code> and
<code>TranscriptionConfig</code>. (<a
href="https://github.com/googleapis/js-genai/commit/4c5208baa923cecea897b7b4fdc9de5e49555709">4c5208b</a>)</li>
<li>Add enable_data_retention to ToolParallelAiSearch, Add step_count to
ReinforcementTuningHyperParameters, Add BidiGenerateContentSetup (<a
href="https://github.com/googleapis/js-genai/commit/f52c20858c1bf6c7892192bc41cfc027d30b57ab">f52c208</a>)</li>
<li>Add IDLE state to live connection status enum and mark
REQUIRES_ACTION as deprecated. (<a
href="https://github.com/googleapis/js-genai/commit/2f110f23372cf2ea52452fe57ddf3a4e30833857">2f110f2</a>)</li>
<li>add video resolution and extension task parameters (<a
href="https://github.com/googleapis/js-genai/commit/39b2a2dea4c5ff75c1754581b213b9d480504e7d">39b2a2d</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>fix examples (<a
href="https://github.com/googleapis/js-genai/commit/3f631be857d0faec43012c2510ce17caea5bffe8">3f631be</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/googleapis/js-genai/commit/128781fdfec5d33f24d8305d90964f3b75b0774f"><code>128781f</code></a>
chore(main): release 2.18.0 (<a
href="https://redirect.github.com/googleapis/js-genai/issues/1856">#1856</a>)</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/67f4cf7c48059de776d2841a5cf5129361a97c49"><code>67f4cf7</code></a>
chore: Internal Changes</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/2f110f23372cf2ea52452fe57ddf3a4e30833857"><code>2f110f2</code></a>
feat: Add IDLE state to live connection status enum and mark
REQUIRES_ACTION ...</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/3f631be857d0faec43012c2510ce17caea5bffe8"><code>3f631be</code></a>
fix: fix examples</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/4c5208baa923cecea897b7b4fdc9de5e49555709"><code>4c5208b</code></a>
feat: Add <code>mode</code> enum (<code>VERBATIM</code>,
<code>SMART</code>) to <code>AudioTranscriptionConfig</code> and...</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/f52c20858c1bf6c7892192bc41cfc027d30b57ab"><code>f52c208</code></a>
feat: Add enable_data_retention to ToolParallelAiSearch, Add step_count
to Re...</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/39b2a2dea4c5ff75c1754581b213b9d480504e7d"><code>39b2a2d</code></a>
feat: add video resolution and extension task parameters</li>
<li>See full diff in <a
href="https://github.com/googleapis/js-genai/compare/v2.17.1...v2.18.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/core` from 1.2.8 to 1.2.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">@​langchain/core's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.2.9</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11402">#11402</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/43e439698fa7794c10ab8d7355d4433e058e4d62"><code>43e4396</code></a>
Thanks <a
href="https://github.com/thushanth-bengre-langchain"><code>@​thushanth-bengre-langchain</code></a>!
- Fix ChatVertexAI/ChatGoogle content blocks: include
<code>tool_call</code> blocks from <code>message.tool_calls</code> and
skip spurious empty <code>text</code> blocks in
<code>contentBlocks</code>.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/e493ed653d734e31a8d051f78ab29b067f530e4b"><code>e493ed6</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11393">#11393</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/83848481ea27502c4221a01b4c55a87f1fa7c472"><code>8384848</code></a>
fix(google-common): release endpoint routing fix as patch (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11413">#11413</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/8cfff4dced1327fc87893a86dfc63c553403aec0"><code>8cfff4d</code></a>
feat(google): add gateway support for genai (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11405">#11405</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/7df258c0af8362fede14d42bb982597a56f41b78"><code>7df258c</code></a>
chore(langchain): update langgraph deps (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11412">#11412</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/3ceef4baadfaec8f0b1e43191b9363cfcc04187f"><code>3ceef4b</code></a>
fix(anthropic): round-trip tool search server-tool result blocks (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11407">#11407</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/fe8eec1915cc5580b8e7a2f3d4f68fe5e577d641"><code>fe8eec1</code></a>
fix(openai): drop Gemini functionCall content blocks in Chat Completions
mess...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/0e7c7654c8bd84b80fe9a2495ab2703355ff8c1e"><code>0e7c765</code></a>
fix(google-genai): throw ContentBlockedError when Gemini candidate has
no con...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/5c9fdf2f0339deb92db84eaa838cf35c7dcdb027"><code>5c9fdf2</code></a>
fix(openai): retain cache_write_tokens, update to v7 sdk (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11399">#11399</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/5ff9179e25f594d7cd21e176fdadd953190375c5"><code>5ff9179</code></a>
fix(google-genai): guard streaming chunks when candidate has no content
(<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10742">#10742</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/43e439698fa7794c10ab8d7355d4433e058e4d62"><code>43e4396</code></a>
fix(core): include tool_call blocks and skip empty text blocks in
ChatVertexA...</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchainjs/compare/@langchain/core@1.2.8...@langchain/core@1.2.9">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/langgraph` from 1.4.10 to 1.4.12
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langgraphjs/releases">@​langchain/langgraph's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/langgraph</code><a
href="https://github.com/1"><code>@​1</code></a>.4.12</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langgraphjs/pull/2714">#2714</a>
<a
href="https://github.com/langchain-ai/langgraphjs/commit/a2a59ec6f8fdd93d4520d86fceab8a234dacf978"><code>a2a59ec</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
Update checkpoint integrations to require the patched checkpoint
serializer release.</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/langchain-ai/langgraphjs/commit/a2a59ec6f8fdd93d4520d86fceab8a234dacf978"><code>a2a59ec</code></a>]:</p>
<ul>
<li><code>@​langchain/langgraph-checkpoint</code><a
href="https://github.com/1"><code>@​1</code></a>.1.5</li>
</ul>
</li>
</ul>
<h2><code>@​langchain/langgraph</code><a
href="https://github.com/1"><code>@​1</code></a>.4.11</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langgraphjs/pull/2706">#2706</a>
<a
href="https://github.com/langchain-ai/langgraphjs/commit/eaa5472fa480fad2671659d1c9ed0686a55d42bd"><code>eaa5472</code></a>
Thanks <a
href="https://github.com/zduric-langchain"><code>@​zduric-langchain</code></a>!
- fix(langgraph): dedupe merged callback handlers by identity</p>
<p><code>mergeCallbacks</code> concatenated <code>handlers</code> and
<code>inheritableHandlers</code> while
deduping <code>tags</code>, so a handler inherited by both the ambient
and the explicit
config picked up an extra registration at every graph boundary. With
tracing
on, a nested <code>streamMode: &quot;messages&quot;</code> run delivered
every token twice.</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/langchain-ai/langgraphjs/commit/3ce9f8d11dd64b1d091a25162603c49e6f4a426f"><code>3ce9f8d</code></a>,
<a
href="https://github.com/langchain-ai/langgraphjs/commit/51b42020f7c730a15193aa907056881e3d961924"><code>51b4202</code></a>,
<a
href="https://github.com/langchain-ai/langgraphjs/commit/a86f813954e010fbf30711c37baa5c53444613d5"><code>a86f813</code></a>]:</p>
<ul>
<li><code>@​langchain/langgraph-sdk</code><a
href="https://github.com/1"><code>@​1</code></a>.9.30</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langgraphjs/blob/main/libs/langgraph-core/CHANGELOG.md">@​langchain/langgraph's
changelog</a>.</em></p>
<blockquote>
<h2>1.4.12</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langgraphjs/pull/2714">#2714</a>
<a
href="https://github.com/langchain-ai/langgraphjs/commit/a2a59ec6f8fdd93d4520d86fceab8a234dacf978"><code>a2a59ec</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
Update checkpoint integrations to require the patched checkpoint
serializer release.</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/langchain-ai/langgraphjs/commit/a2a59ec6f8fdd93d4520d86fceab8a234dacf978"><code>a2a59ec</code></a>]:</p>
<ul>
<li><code>@​langchain/langgraph-checkpoint</code><a
href="https://github.com/1"><code>@​1</code></a>.1.5</li>
</ul>
</li>
</ul>
<h2>1.4.11</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langgraphjs/pull/2706">#2706</a>
<a
href="https://github.com/langchain-ai/langgraphjs/commit/eaa5472fa480fad2671659d1c9ed0686a55d42bd"><code>eaa5472</code></a>
Thanks <a
href="https://github.com/zduric-langchain"><code>@​zduric-langchain</code></a>!
- fix(langgraph): dedupe merged callback handlers by identity</p>
<p><code>mergeCallbacks</code> concatenated <code>handlers</code> and
<code>inheritableHandlers</code> while
deduping <code>tags</code>, so a handler inherited by both the ambient
and the explicit
config picked up an extra registration at every graph boundary. With
tracing
on, a nested <code>streamMode: &quot;messages&quot;</code> run delivered
every token twice.</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/langchain-ai/langgraphjs/commit/3ce9f8d11dd64b1d091a25162603c49e6f4a426f"><code>3ce9f8d</code></a>,
<a
href="https://github.com/langchain-ai/langgraphjs/commit/51b42020f7c730a15193aa907056881e3d961924"><code>51b4202</code></a>,
<a
href="https://github.com/langchain-ai/langgraphjs/commit/a86f813954e010fbf30711c37baa5c53444613d5"><code>a86f813</code></a>]:</p>
<ul>
<li><code>@​langchain/langgraph-sdk</code><a
href="https://github.com/1"><code>@​1</code></a>.9.30</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langgraphjs/commit/6530ba9b4c577c560422d9c9de18914e67411d9d"><code>6530ba9</code></a>
chore: version packages (<a
href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2715">#2715</a>)</li>
<li><a
href="https://github.com/langchain-ai/langgraphjs/commit/c3b27a997c682a64f65904b2a97a5ee4d6e741b0"><code>c3b27a9</code></a>
fix(checkpoint): narrow re-constructable types in JsonPlusSerializer (<a
href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2709">#2709</a>)</li>
<li><a
href="https://github.com/langchain-ai/langgraphjs/commit/659d628d196f6b1ba7aa46b30293c31ff5715cf4"><code>659d628</code></a>
chore: version packages (<a
href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2704">#2704</a>)</li>
<li><a
href="https://github.com/langchain-ai/langgraphjs/commit/eaa5472fa480fad2671659d1c9ed0686a55d42bd"><code>eaa5472</code></a>
fix(langgraph): dedupe merged callback handlers by identity (<a
href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2706">#2706</a>)</li>
<li>See full diff in <a
href="https://github.com/langchain-ai/langgraphjs/commits/@langchain/langgraph@1.4.12/libs/langgraph-core">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/openai` from 1.5.8 to 1.5.10
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">@​langchain/openai's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/openai</code><a
href="https://github.com/1"><code>@​1</code></a>.5.10</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11419">#11419</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/c26c87e41bccd01111e170c32ba1e5eec94ba3a6"><code>c26c87e</code></a>
Thanks <a href="https://github.com/chiliec"><code>@​chiliec</code></a>!
- fix(openai): send content null (not []) for tool-call-only v1
assistant messages</li>
</ul>
<h2><code>@​langchain/openai</code><a
href="https://github.com/1"><code>@​1</code></a>.5.9</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11399">#11399</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/5c9fdf2f0339deb92db84eaa838cf35c7dcdb027"><code>5c9fdf2</code></a>
Thanks <a
href="https://github.com/gethin-langchain"><code>@​gethin-langchain</code></a>!
- update to v7 openai sdk</p>
</li>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11403">#11403</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/fe8eec1915cc5580b8e7a2f3d4f68fe5e577d641"><code>fe8eec1</code></a>
Thanks <a
href="https://github.com/thushanth-bengre-langchain"><code>@​thushanth-bengre-langchain</code></a>!
- Drop Gemini-native <code>functionCall</code> content blocks (already
carried in <code>tool_calls</code>) when converting messages to Chat
Completions API params, fixing requests that fail when a
<code>ChatGoogleGenerativeAI</code> message is passed to
<code>ChatOpenAI</code> (e.g. a cross-provider handoff in
LangGraph).</p>
</li>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11399">#11399</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/5c9fdf2f0339deb92db84eaa838cf35c7dcdb027"><code>5c9fdf2</code></a>
Thanks <a
href="https://github.com/gethin-langchain"><code>@​gethin-langchain</code></a>!
- Map OpenAI's <code>cache_write_tokens</code> to
<code>cache_creation</code> in
<code>usage_metadata.input_token_details</code>, mirroring the existing
<code>cached_tokens</code> -&gt; <code>cache_read</code> mapping across
the Chat Completions and Responses APIs. Previously, prompt cache-write
token counts were silently dropped.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/d5264a180b2dd121d5fba54e9272d34352875d7b"><code>d5264a1</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11427">#11427</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/c26c87e41bccd01111e170c32ba1e5eec94ba3a6"><code>c26c87e</code></a>
fix(openai): send content null (not []) for tool-call-only v1 assistant
messa...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/041a75581666a7fd551e6df62226dcf873be50cc"><code>041a755</code></a>
fix(anthropic): preserve generic tool_search_tool_result blocks (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11421">#11421</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/e493ed653d734e31a8d051f78ab29b067f530e4b"><code>e493ed6</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11393">#11393</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/83848481ea27502c4221a01b4c55a87f1fa7c472"><code>8384848</code></a>
fix(google-common): release endpoint routing fix as patch (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11413">#11413</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/8cfff4dced1327fc87893a86dfc63c553403aec0"><code>8cfff4d</code></a>
feat(google): add gateway support for genai (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11405">#11405</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/7df258c0af8362fede14d42bb982597a56f41b78"><code>7df258c</code></a>
chore(langchain): update langgraph deps (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11412">#11412</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/3ceef4baadfaec8f0b1e43191b9363cfcc04187f"><code>3ceef4b</code></a>
fix(anthropic): round-trip tool search server-tool result blocks (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11407">#11407</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/fe8eec1915cc5580b8e7a2f3d4f68fe5e577d641"><code>fe8eec1</code></a>
fix(openai): drop Gemini functionCall content blocks in Chat Completions
mess...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/0e7c7654c8bd84b80fe9a2495ab2703355ff8c1e"><code>0e7c765</code></a>
fix(google-genai): throw ContentBlockedError when Gemini candidate has
no con...</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchainjs/compare/@langchain/openai@1.5.8...@langchain/openai@1.5.10">compare
view</a></li>
</ul>
</details>
<br />

Updates `langchain` from 1.5.9 to 1.5.10
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">langchain's
releases</a>.</em></p>
<blockquote>
<h2>langchain@1.5.10</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11412">#11412</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/7df258c0af8362fede14d42bb982597a56f41b78"><code>7df258c</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
chore(langgraph): update langgraph deps to track serialization fix</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/e493ed653d734e31a8d051f78ab29b067f530e4b"><code>e493ed6</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11393">#11393</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/83848481ea27502c4221a01b4c55a87f1fa7c472"><code>8384848</code></a>
fix(google-common): release endpoint routing fix as patch (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11413">#11413</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/8cfff4dced1327fc87893a86dfc63c553403aec0"><code>8cfff4d</code></a>
feat(google): add gateway support for genai (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11405">#11405</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/7df258c0af8362fede14d42bb982597a56f41b78"><code>7df258c</code></a>
chore(langchain): update langgraph deps (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11412">#11412</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/3ceef4baadfaec8f0b1e43191b9363cfcc04187f"><code>3ceef4b</code></a>
fix(anthropic): round-trip tool search server-tool result blocks (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11407">#11407</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/fe8eec1915cc5580b8e7a2f3d4f68fe5e577d641"><code>fe8eec1</code></a>
fix(openai): drop Gemini functionCall content blocks in Chat Completions
mess...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/0e7c7654c8bd84b80fe9a2495ab2703355ff8c1e"><code>0e7c765</code></a>
fix(google-genai): throw ContentBlockedError when Gemini candidate has
no con...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/5c9fdf2f0339deb92db84eaa838cf35c7dcdb027"><code>5c9fdf2</code></a>
fix(openai): retain cache_write_tokens, update to v7 sdk (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11399">#11399</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/5ff9179e25f594d7cd21e176fdadd953190375c5"><code>5ff9179</code></a>
fix(google-genai): guard streaming chunks when candidate has no content
(<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10742">#10742</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/43e439698fa7794c10ab8d7355d4433e058e4d62"><code>43e4396</code></a>
fix(core): include tool_call blocks and skip empty text blocks in
ChatVertexA...</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchainjs/compare/langchain@1.5.9...langchain@1.5.10">compare
view</a></li>
</ul>
</details>
<br />

Updates `@openai/agents` from 0.16.0 to 0.17.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/openai/openai-agents-js/releases">@​openai/agents's
releases</a>.</em></p>
<blockquote>
<h2>v0.17.0</h2>
<h2>Key Changes</h2>
<h3>Output-guardrail replay safety</h3>
<p>Serialized output-bearing approval checkpoints now fail closed with
<code>UserError</code> when the SDK cannot prove which response owns a
pending terminal tool output. Continue with the live
<code>RunState</code> when possible, or start a new run from safe input
instead of replaying ambiguous serialized items. When an output
guardrail rejects a completed function-tool result used as final output,
the SDK replaces rejected content in SDK-owned replay surfaces with
<code>Output withheld by an output guardrail.</code>, sanitizes current
guardrail metadata, and preserves earlier accepted history. This does
not undo external tool side effects or erase application-owned
copies.</p>
<h3>Complete guardrail batch results</h3>
<p>Guardrails started in the same batch now settle before the runner
surfaces a tripwire or execution failure. Completed sibling results
remain available in run state while further run processing is
halted.</p>
<h3>Explicit OpenAI client configuration</h3>
<p><code>OpenAIProvider</code> now rejects <code>organization</code> or
<code>project</code> when <code>openAIClient</code> is also supplied
because provider-level values cannot modify an already-created client.
Configure these values when constructing the <code>OpenAI</code> client,
then pass that client through <code>openAIClient</code>.</p>
<h2>What's Changed</h2>
<ul>
<li>fix(core): redact blocked tool outputs and aliases from replay state
by <a href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1712">openai/openai-agents-js#1712</a></li>
<li>fix(openai): reject ignored explicit-client options by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1718">openai/openai-agents-js#1718</a></li>
</ul>
<h3>Documentation &amp; Other Changes</h3>
<ul>
<li>docs: v01.6.1 release by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1696">openai/openai-agents-js#1696</a></li>
<li>docs: fix access token typo in connectors example by <a
href="https://github.com/Chair403"><code>@​Chair403</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1716">openai/openai-agents-js#1716</a></li>
<li>fix: keep Codex verification for development sandboxed by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1707">openai/openai-agents-js#1707</a></li>
<li>chore: update versions by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1717">openai/openai-agents-js#1717</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/Chair403"><code>@​Chair403</code></a>
made their first contribution in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1716">openai/openai-agents-js#1716</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/openai/openai-agents-js/compare/v0.16.1...v0.17.0">https://github.com/openai/openai-agents-js/compare/v0.16.1...v0.17.0</a></p>
<h2>v0.16.1</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(core): add model call timeouts by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1679">openai/openai-agents-js#1679</a></li>
<li>feat(sandbox): add run-scoped sandbox working directories by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1683">openai/openai-agents-js#1683</a></li>
<li>feat(sandbox): allow Docker sandboxes to disable networking by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1695">openai/openai-agents-js#1695</a></li>
<li>feat(extensions): add Modal sandbox resource options by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1693">openai/openai-agents-js#1693</a></li>
<li>fix(core): honor exact call approval decisions by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1694">openai/openai-agents-js#1694</a></li>
<li>fix(sandbox): validate view_image raster content by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1704">openai/openai-agents-js#1704</a></li>
<li>fix(sandbox): validate dynamic compaction ratios by <a
href="https://github.com/sylvesterkaczmarek"><code>@​sylvesterkaczmarek</code></a>
in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1691">openai/openai-agents-js#1691</a></li>
<li>fix(sandbox): trace effective run-scoped sandbox paths by <a
href="https://github.com/sylvesterkaczmarek"><code>@​sylvesterkaczmarek</code></a>
in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1697">openai/openai-agents-js#1697</a></li>
</ul>
<h3>Documentation &amp; Other Changes</h3>
<ul>
<li>docs: prepare v0.16.0 release documentation by <a
href="https://github.com/seratch"><code>@​seratch</code></a> in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1646">openai/openai-agents-js#1646</a></li>
<li>docs: document Agent.clone list property sharing by <a
href="https://github.com/thegoodengineer"><code>@​thegoodengineer</code></a>
in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1705">openai/openai-agents-js#1705</a></li>
<li>chore: update versions by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/openai/openai-agents-js/pull/1688">openai/openai-agents-js#1688</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/openai/openai-agents-js/commit/0319b657e64e0c132629fe9ed4d524f7cde93445"><code>0319b65</code></a>
chore: update versions (<a
href="https://redirect.github.com/openai/openai-agents-js/issues/1717">#1717</a>)</li>
<li><a
href="https://github.com/openai/openai-agents-js/commit/d80736ace3c8ac32c41ba2b353a3e64ed31354b3"><code>d80736a</code></a>
fix(openai): reject ignored explicit-client options (<a
href="https://redirect.github.com/openai/openai-agents-js/issues/1718">#1718</a>)</li>
<li><a
href="https://github.com/openai/openai-agents-js/commit/b9ecb03ede8845fd8e2da74667242b7d2cf3d7c3"><code>b9ecb03</code></a>
docs: fix access token typo in connectors example (<a
href="https://redirect.github.com/openai/openai-agents-js/issues/1716">#1716</a>)</li>
<li><a
href="https://github.com/openai/openai-agents-js/commit/33fe55c62e5a0535766f8adbac63430593b7acd9"><code>33fe55c</code></a>
fix(core): redact blocked tool outputs and aliases from replay state (<a
href="https://redirect.github.com/openai/openai-agents-js/issues/1712">#1712</a>)</li>
<li><a
href="https://github.com/openai/openai-agents-js/commit/2d68a10f8c1593f37a8e291e7bce00634ba3e5dd"><code>2d68a10</code></a>
test: remove flaky example process-group test</li>
<li><a
href="https://github.com/openai/openai-agents-js/commit/dcbb1e7ba9bcf5ce50052a2a8d287c94d1d84daf"><code>dcbb1e7</code></a>
chore: move example and integration runners out of skills</li>
<li><a href="https://github.com/openai/openai-agents-js/commit/272...

_Description has been truncated_

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: jkomyno <alberto@composio.dev>
2026-08-25 01:38:21 +02:00
jkomyno e4189aeb57 chore(release): migrate to Changesets v3 2026-08-25 01:01:10 +02:00
dependabot[bot] 303ad9b7eb fix(deps): keep undici on v7 for native fetch compatibility (#4195)
## Summary

- retain Undici 7 in @composio/core and @composio/slim
- ignore future Undici semver-major Dependabot updates until supported
Node runtimes use the compatible dispatcher protocol
- preserve the real-socket DNS-pinning regression coverage

## Why

Undici 8 dispatchers require the new request handler API, while the
built-in fetch implementation in supported Node 22, 24, and 25 releases
dispatches through the legacy API. Passing the SDK pinned Undici 8 Agent
to native fetch fails with UND_ERR_INVALID_ARG: invalid onRequestStart
method, breaking SSRF-safe URL fetches.

## Verification

- pnpm --filter @composio/core exec vitest run
test/utils/pinnedDispatcher.node.test.ts
- pnpm --filter @composio/core test
- pnpm --filter @composio/core typecheck
- pnpm test

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: jkomyno <alberto@composio.dev>
2026-08-24 21:12:57 +02:00
Alberto Schiabel 64406ff359 chore(cli): bump Bun to 1.4.0 and replace tar with Bun.Archive (#4183)
Bumps the mise-pinned Bun toolchain from 1.3.10 to 1.4.0 and replaces
the one CLI dependency that a Bun 1.4 built-in can verifiably take over.

## Binary size: Linux shrinks a lot, macOS grows a little

Measured per target, byte counts from `build:binary:all` on a
darwin-arm64 host.

| Target | Before (1.3.10) | After runtime (1.4.0) | After full | Δ
total | Δ % |
|---|---:|---:|---:|---:|---:|
| `composio-darwin-aarch64` | 80,850,704 (77.1 MiB) | 83,790,962 (79.9
MiB) | 83,790,962 (79.9 MiB) | +2,940,258 (+2.8 MiB) | +3.6% |
| `composio-darwin-x64` | 85,710,240 (81.7 MiB) | 90,430,880 (86.2 MiB)
| 90,430,880 (86.2 MiB) | +4,720,640 (+4.5 MiB) | +5.5% |
| `composio-linux-x64` | 123,666,298 (117.9 MiB) | 102,270,152 (97.5
MiB) | 102,270,152 (97.5 MiB) | -21,396,146 (-20.4 MiB) | -17.3% |
| `composio-linux-aarch64` | 121,153,270 (115.5 MiB) | 102,221,816 (97.5
MiB) | 102,221,816 (97.5 MiB) | -18,931,454 (-18.1 MiB) | -15.6% |

**Attribution — read this before quoting the numbers.** Every byte of
movement above comes from the **Bun runtime bump**, not from dependency
removal. The "after runtime" and "after full" columns are
byte-identical: the only dependency dropped here is `tar`, a
devDependency used by one build script that never reaches the binary.
Its size contribution is exactly **0 bytes**. (The identical columns
also confirm the compiled build is reproducible across runs.)

Linux users — the large majority of installs — get a ~18-20 MiB smaller
binary. macOS grows 2.8-4.5 MiB. This matches the direction upstream
reports for the standalone Bun binary.

## What changed

- `mise.toml` pins `bun = "1.4.0"`; `mise.lock` regenerated with the
exact platform list `ts.audit` uses.
- `scripts/_acp-adapters.ts` extracts npm tarballs with `Bun.Archive`
instead of the `tar` package.
- `tar` dropped from `@composio/cli` devDependencies (plus
`@isaacs/fs-minipass`, `chownr`, `minizlib`, `yallist` from the
lockfile).

## Verified negative results

These are the two adjacent candidates a reviewer would expect to see
replaced. Both were probed against a real Bun 1.4.0 binary and both fail
— recorded here so nobody re-derives the dead ends:

- **`extract-zip` stays.** `Bun.Archive` cannot read zip: `new
Bun.Archive(zipBytes)` throws `Unrecognized archive format`, and
`ArchiveOptions.compress` accepts only `"gzip"`. Still used at three
call sites.
- **`semver` stays.** `Object.keys(Bun.semver)` returns exactly
`["satisfies", "order"]`. The CLI also needs `valid`, `prerelease`,
`compare`, `gt`, and `lt`. `valid` and `prerelease` have no equivalent,
so a partial migration would only add a second semver dialect.

## `json5` → `Bun.JSON5` was attempted and backed out

`parse-json.ts` is covered by the CLI's Vitest suite, which runs on
**Node**, where the `Bun` global does not exist — `Bun.JSON5.parse`
throws `ReferenceError` under test. The suite cannot move to the Bun
runtime (88 of 122 files fail there on unrelated zod resolution errors),
and `bun test` for a single file would conflict with the repo's
`@effect/vitest` lint rule.

The swap itself is sound — `Bun.JSON5.parse` matched the `json5` package
on all nine contract cases against a real 1.4.0 binary, including
`SyntaxError` on malformed input. It is the test harness, not the
parser, that blocks it. Deferred rather than shipped with weakened
coverage.

For sizing the follow-up: `--metafile-md` puts `json5` at **28,045 bytes
(0.1%)** of the JS bundle, imported only by `src/utils/parse-json.ts` —
roughly 0.03% of a compiled binary. Worth doing for dependency-surface
reasons, not for size.

## Verification

- All four release targets cross-compile on Bun 1.4.0.
- `mise lock --platform linux-x64,linux-arm64,macos-arm64,macos-x64`
then `git diff --exit-code mise.lock` is clean, replayed in a CI-like
environment.
- `pnpm typecheck` clean; CLI suite green (122 files, 1248 passed, 1
skipped).
- `Bun.Archive` adapter build against the live npm registry produces
codex-acp binaries **byte-identical** (SHA-256) to the `tar`-produced
ones, at the same `package/bin/<name>` paths, executable after `chmod`,
extracted concurrently. A truncated tarball throws `ReadError` rather
than silently yielding an empty directory.
- Runtime smoke on the 1.4.0 binary: `composio version`, `composio
--help`, and the `composio run` companion-module spawn path (reports
`process.version` v26.3.0 — no Node 26 stream regression). `extract-zip`
verified working under the new runtime.

### Not run locally

`pnpm test:e2e:cli` needs Docker, which was unavailable on this machine.
CI covers it. Worth a look at that job: the e2e image is version-keyed
and has served a stale Bun binary from a cached layer before, so confirm
the container reports 1.4.0.

## Notes

- `@types/bun` is deliberately not bumped: `Bun.JSON5` and `Bun.Archive`
are already declared in the installed `bun-types@1.3.14`, no
`@types/bun` 1.4.x exists yet, and `minimumReleaseAge` would block a
fresh pin anyway.
- No changeset: `@composio/cli` is in `.changeset/config.json`'s
`ignore` list and no published package is touched.
- `mise lock` locally adds a stray `[[tools.node]] 24.19.0` block
sourced from the developer's global mise config. It was stripped; the
committed lock is stable under the audit gate's exact command.
2026-08-20 20:02:44 +02:00
Alberto Schiabel d544006a25 fix(sdk): pin the validated address when fetching URLs (SSRF DNS rebinding) (#4172)
Fixes #4151.

## The problem

Both SDKs validated a URL by resolving its hostname, and then handed the
*hostname* to the HTTP client, which resolved it again when it opened
the socket. Two lookups, two answers: a short-TTL record under an
attacker's control answers publicly for the check and with
`169.254.169.254`, `127.0.0.1`, or RFC 1918 space for the connect. The
guard passes and the connection lands inside the network — classic
TOCTOU DNS rebinding, documented in both modules until now as a known
residual.

```mermaid
sequenceDiagram
    participant SDK
    participant DNS as Attacker DNS
    participant Meta as 169.254.169.254
    Note over SDK,Meta: before
    SDK->>DNS: resolve evil.example.com (validate)
    DNS-->>SDK: 93.184.216.34 — passes the guard
    SDK->>DNS: resolve evil.example.com (connect)
    DNS-->>SDK: 169.254.169.254
    SDK->>Meta: GET /latest/meta-data/…
    Meta-->>SDK: credentials
```

## The fix

Resolve once, validate every answer, then connect to the address that
was validated. There is no second lookup left to rebind.

- **Python** — `safe_get` / `safe_request` mount a transport adapter
that swaps the connect target for the duration of the socket connect
only. The `Host` header and TLS SNI keep the hostname, so certificate
verification is unchanged; rewriting `conn._dns_host` for the whole
connection would have sent `Host: <ip>` and offered the IP as SNI,
failing against every real origin. Every fetch call site now goes
through those two helpers, so no `requests.get` sits next to a bare
check any more:
- `_files.py::_fetch_file_from_url`,
`_files.py::FileDownloadable.download`
  - `tool_router_session_files.py::_fetch_url_bytes`
  - `safe_request`, per redirect hop
- **TypeScript** — `assertSafeFetchTarget` returns the validated address
and `ssrfSafeFetch` hands `fetch` a dispatcher pinned to it, re-pinned
per redirect hop. The dispatcher goes to the runtime's own `fetch`, so
callers that stub `globalThis.fetch` keep working. The pinned `lookup`
answers both shapes Node calls it with — the address *list* it uses for
Happy Eyeballs, and the single `(address, family)` it uses when
`autoSelectFamily` is off — since answering in the wrong shape is
rejected as an invalid address.
- A fail-closed peer assertion runs on the Python side before a byte is
written to the socket — redundant while pinning works, and a tripwire if
a urllib3 upgrade ever breaks it.
- `workerd` is unchanged: it already fails closed for user-supplied
URLs.

Redirect *validation* already existed in both SDKs (`safe_request` /
`ssrfSafeFetch`); what was missing was re-pinning each hop.

## Tests

The existing suites could not express this bug: they mock both the
resolver and the HTTP client, so check and use are the same mock. The
new tests use real sockets.

- `python/tests/test_url_safety_pinning.py` — two loopback servers and a
resolver that answers the first lookup with one endpoint and every later
one with another, which is what a short-TTL rebinding record does.
Asserts the rebound endpoint receives **zero** connections, and that
`Host` still carries the hostname. Both tests fail on `next` and pass
here.
- `ts/packages/core/test/utils/pinnedDispatcher.node.test.ts` — a real
server plus a hostname under `.invalid`, which RFC 2606 guarantees never
resolves. A request that arrives proves the connect used the pinned
address and never consulted DNS. The third case shows the contrast:
unpinned, the same fetch cannot resolve at all.
- `ssrfGuard.test.ts` gains assertions that each hop is pinned to that
hop's own validated address.
- `pinnedDispatcher.node.test.ts` also pins with
`setDefaultAutoSelectFamily(false)`, which is the branch Node takes for
the single-address callback.

## Notes

- Supersedes #4157, which diagnosed this correctly. Its post-response
peer check turned out not to hold: with an HTTP/1.0 or `Connection:
close` server, urllib3 detaches the socket (`conn.sock is None`) while
`r.content` still returns the full body, so the check fails open exactly
where exfiltration succeeds. That is why the assertion here runs at
connect time instead.
- The Python package now declares `urllib3>=2` directly. `url_safety`
imports it for `NameResolutionError`, which only exists from 2.0, and
the pinning adapter reaches into 2.x connection internals; `requests`
alone allows 1.x, where `import composio` would have failed outright.
- `@composio/core` gains an `undici` dependency, pinned to `^7`: undici
8 dispatchers are rejected by the `fetch` in every Node version this
package supports (22/24/25, verified). The real-socket test runs on the
full CI matrix, so a future incompatibility fails loudly instead of
silently un-pinning.
- `undici` is imported on first pinned request rather than at module
load: importing it installs a process-wide global dispatcher, which
would have handed the host application's own unrelated `fetch` calls
this package's undici merely because it imported `@composio/core`.
- Residuals, now documented in the modules:
- Requests routed through an environment proxy keep the pre-flight check
only. The proxy resolves the hostname itself and the SDK cannot see or
pin that resolution.
- A process that does perform a pinned fetch still ends up on this
package's `Agent` if nothing had claimed the global dispatcher slot yet.
undici defines that slot non-configurable, so it cannot be handed back —
assigning `undefined` leaves the runtime's own `fetch` asserting on a
missing dispatcher.
2026-08-20 13:34:37 +02:00
dependabot[bot] 389902f0ac chore(deps): bump the npm-production group across 1 directory with 25 updates (#4160)
Bumps the npm-production group with 25 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
|
[@anthropic-ai/claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-typescript)
| `0.3.221` | `0.3.233` |
|
[@mastra/mcp](https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp)
| `1.15.0` | `1.16.0` |
| [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `6.0.241` |
`6.0.256` |
|
[@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript)
| `0.115.0` | `0.117.1` |
| [@google/genai](https://github.com/googleapis/js-genai) | `2.15.0` |
`2.17.1` |
| [@langchain/core](https://github.com/langchain-ai/langchainjs) |
`1.2.4` | `1.2.8` |
|
[@langchain/langgraph](https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core)
| `1.4.9` | `1.4.10` |
| [@langchain/openai](https://github.com/langchain-ai/langchainjs) |
`1.5.5` | `1.5.8` |
| [langchain](https://github.com/langchain-ai/langchainjs) | `1.5.4` |
`1.5.9` |
| [@openai/agents](https://github.com/openai/openai-agents-js) |
`0.14.2` | `0.16.0` |
| [@langchain/anthropic](https://github.com/langchain-ai/langchainjs) |
`1.5.2` | `1.5.6` |
| [open](https://github.com/sindresorhus/open) | `11.0.0` | `11.0.1` |
| [typebox](https://github.com/sinclairzx81/typebox) | `1.3.10` |
`1.3.14` |
|
[@mastra/schema-compat](https://github.com/mastra-ai/mastra/tree/HEAD/packages/schema-compat)
| `1.3.4` | `1.3.7` |
| [@ai-sdk/mcp](https://github.com/vercel/ai/tree/HEAD/packages/mcp) |
`2.0.24` | `2.0.32` |
|
[@ai-sdk/openai](https://github.com/vercel/ai/tree/HEAD/packages/openai)
| `4.0.29` | `4.0.42` |
|
[@cloudflare/vitest-pool-workers](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vitest-pool-workers)
| `0.20.1` | `0.21.3` |
| [@cloudflare/workers-types](https://github.com/cloudflare/workerd) |
`5.20260804.1` | `5.20260815.1` |
|
[@effect/language-service](https://github.com/Effect-TS/language-service)
| `0.87.1` | `0.87.2` |
|
[@mastra/core](https://github.com/mastra-ai/mastra/tree/HEAD/packages/core)
| `1.52.1` | `1.59.0` |
|
[@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk)
| `1.26.0` | `1.30.0` |
| [hono](https://github.com/honojs/hono) | `4.13.1` | `4.13.2` |
| [pnpm](https://github.com/pnpm/pnpm/tree/HEAD/pnpm11/pnpm) | `11.20.0`
| `11.21.0` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.5` | `4.23.12` |
|
[wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler)
| `4.118.0` | `4.123.0` |


Updates `@anthropic-ai/claude-agent-sdk` from 0.3.221 to 0.3.233
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/claude-agent-sdk-typescript/releases">@​anthropic-ai/claude-agent-sdk's
releases</a>.</em></p>
<blockquote>
<h2>v0.3.233</h2>
<h2>What's changed</h2>
<ul>
<li>Notification hooks now fire for pending permission prompts on the
SDK path, matching the interactive REPL behavior</li>
<li>Todo/task-tracking tools
(<code>TaskCreate</code>/<code>TaskGet</code>/<code>TaskUpdate</code>/<code>TaskList</code>,
<code>TodoWrite</code>) are no longer in the default tool surface on
Opus 4.8, Sonnet 5, Fable 5, Mythos 5, and newer models; name them in
the <code>tools</code> option or reference them in
<code>allowedTools</code> (or set
<code>CLAUDE_CODE_ENABLE_TODO_TOOLS=1</code>) to keep them</li>
</ul>
<h2>Update</h2>
<pre lang="sh"><code>npm install @anthropic-ai/claude-agent-sdk@0.3.233
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.233
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.233
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.233
</code></pre>
<h2>v0.3.232</h2>
<h2>What's changed</h2>
<ul>
<li>Subagent MCP <code>tool_result</code> frames whose result carries
<code>_meta</code> now emit <code>tool_use_result</code> as <code>{
content, _meta }</code> (matching main-loop frames) instead of a bare
value</li>
<li><code>/context</code> result messages now carry a structured
<code>context_usage</code> payload (new <code>SDKContextUsage</code>
type), so consumers can render the context-usage card without parsing
the markdown table</li>
<li><code>vcs_state_changed</code> events now populate the
<code>branch</code> field for push operations, sourced from the pushed
ref</li>
</ul>
<h2>Update</h2>
<pre lang="sh"><code>npm install @anthropic-ai/claude-agent-sdk@0.3.232
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.232
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.232
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.232
</code></pre>
<h2>v0.3.231</h2>
<h2>What's changed</h2>
<ul>
<li>Updated to parity with Claude Code v2.1.231</li>
</ul>
<h2>Update</h2>
<pre lang="sh"><code>npm install @anthropic-ai/claude-agent-sdk@0.3.231
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.231
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.231
&lt;/tr&gt;&lt;/table&gt; 
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/claude-agent-sdk-typescript/blob/main/CHANGELOG.md">@​anthropic-ai/claude-agent-sdk's
changelog</a>.</em></p>
<blockquote>
<h2>0.3.233</h2>
<ul>
<li>Notification hooks now fire for pending permission prompts on the
SDK path, matching the interactive REPL behavior</li>
<li>Todo/task-tracking tools
(<code>TaskCreate</code>/<code>TaskGet</code>/<code>TaskUpdate</code>/<code>TaskList</code>,
<code>TodoWrite</code>) are no longer in the default tool surface on
Opus 4.8, Sonnet 5, Fable 5, Mythos 5, and newer models; name them in
the <code>tools</code> option or reference them in
<code>allowedTools</code> (or set
<code>CLAUDE_CODE_ENABLE_TODO_TOOLS=1</code>) to keep them</li>
</ul>
<h2>0.3.232</h2>
<ul>
<li>Subagent MCP <code>tool_result</code> frames whose result carries
<code>_meta</code> now emit <code>tool_use_result</code> as <code>{
content, _meta }</code> (matching main-loop frames) instead of a bare
value</li>
<li><code>/context</code> result messages now carry a structured
<code>context_usage</code> payload (new <code>SDKContextUsage</code>
type), so consumers can render the context-usage card without parsing
the markdown table</li>
<li><code>vcs_state_changed</code> events now populate the
<code>branch</code> field for push operations, sourced from the pushed
ref</li>
</ul>
<h2>0.3.231</h2>
<ul>
<li>Updated to parity with Claude Code v2.1.231</li>
</ul>
<h2>0.3.230</h2>
<ul>
<li>Updated to parity with Claude Code v2.1.230</li>
</ul>
<h2>0.3.229</h2>
<ul>
<li>Added <code>terminal_slash_commands</code> to the system init
message so Remote Control clients can hide terminal-oriented
commands</li>
<li>Changed conversations whose messages alone exceed the API's 32 MB
limit to end the turn with <code>terminal_reason</code>
<code>&quot;api_error&quot;</code> instead of
<code>&quot;image_error&quot;</code>; <code>StopFailure</code>
<code>error_details</code> is <code>&quot;request_body_over_limit:
…&quot;</code></li>
</ul>
<h2>0.3.228</h2>
<ul>
<li>Agent tool results (<code>AgentOutput</code>):
<code>usage.output_tokens_details</code> is now carried through</li>
</ul>
<h2>0.3.227</h2>
<ul>
<li>Updated to parity with Claude Code v2.1.227</li>
</ul>
<h2>0.3.226</h2>
<ul>
<li>Updated to parity with Claude Code v2.1.226</li>
</ul>
<h2>0.3.225</h2>
<ul>
<li>Fixed background subagents in headless/SDK sessions never resuming
when a background shell command or Monitor they left running completed,
so the subagent never saw the result</li>
</ul>
<h2>0.3.224</h2>
<ul>
<li>Added <code>crossSessionInbound</code> and <code>dialogExpiry</code>
settings: cross-session messages sent to a session running with bypassed
permissions are held for your approval, and messages to other sessions
auto-deliver</li>
<li>Added <code>subkind: 'peer-send-message'</code> to the
<code>task-notification</code> member of <code>SDKMessageOrigin</code>,
marking a notification raised by a cross-session
<code>SendMessage</code></li>
<li>Added <code>source: 'archive'</code> plugin config variant to
<code>Settings</code>, with <code>url</code> and optional
<code>sha256</code>, for installing plugins from a zip over HTTPS</li>
<li>Added sandbox credential-masking fields to <code>Settings</code>:
<code>decode: 'jwt'</code> with <code>maskClaims</code>,
<code>extract</code>/<code>onExtractNoMatch</code> on
<code>envVars</code>, and <code>awsPairs</code>/<code>sigv4</code> for
AWS SigV4 re-signing</li>
<li>Fixed long (&gt;200 char) project paths resolving to another
project's session directory under a shared sanitized prefix; session
list/get/rename/tag/fork/delete and <code>/resume</code> no longer cross
projects</li>
</ul>
<h2>0.3.223</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/73a28abad0d5015568404ecfe0d9cad3ed479fe3"><code>73a28ab</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/8716a39f83dd7506e6421199caface603d4941ab"><code>8716a39</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/b5321a4b65ec1b034fea19f684e2d8db728875da"><code>b5321a4</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/71dfabbc343457793684e21d3085bb7a5f8c3f46"><code>71dfabb</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/0a2639d6b561af90342d4a98c93f9cc807d0e5ce"><code>0a2639d</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/22847067d63ef74234a0542a302cc3608de5e837"><code>2284706</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/d13c50c54d591cb2355672c8259fbb6e159687f9"><code>d13c50c</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/4cae4b76341d9a17a2e30915cbd84a79aba1b305"><code>4cae4b7</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/86e3e9464ea31b62b94de39412d70ff2b8b5f97b"><code>86e3e94</code></a>
chore: Update CHANGELOG.md</li>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/064793e6da11fbaf00509ef1ab66f374fb379cbc"><code>064793e</code></a>
chore: Update CHANGELOG.md</li>
<li>Additional commits viewable in <a
href="https://github.com/anthropics/claude-agent-sdk-typescript/compare/v0.3.221...v0.3.233">compare
view</a></li>
</ul>
</details>
<br />

Updates `@mastra/mcp` from 1.15.0 to 1.16.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/mastra-ai/mastra/releases">@​mastra/mcp's
releases</a>.</em></p>
<blockquote>
<h2>Mar 25, 2026</h2>
<h2>Highlights</h2>
<h3>Smarter Model Selection for Observational Memory</h3>
<p><code>@mastra/memory</code> now lets you route observer and reflector
calls to different models based on input size using
<code>ModelByInputTokens</code>. Short inputs can go to a fast, cheap
model while longer ones get sent to a more capable one -- all configured
declaratively with token thresholds. Tracing shows which model was
selected and why.</p>
<h3>MongoDB Support for Datasets and Experiments</h3>
<p><code>@mastra/mongodb</code> now stores versioned datasets with full
item history and time-travel queries, plus experiment results and CRUD.
If you're already using <code>MongoDBStore</code>, this works
automatically with no extra setup.</p>
<h3>Okta Auth and RBAC</h3>
<p>New <code>@mastra/auth-okta</code> package brings SSO authentication
and role-based access control via Okta. Map Okta groups to Mastra
permissions, verify JWTs against Okta's JWKS endpoint, and manage
sessions -- or pair Okta RBAC with a different auth provider like Auth0
or Clerk.</p>
<h3>Breaking Changes</h3>
<ul>
<li>None called out in this changelog.</li>
</ul>
<h2>Changelog</h2>
<h3><a
href="https://github.com/mastra-ai/mastra/blob/@mastra/core@1.16.0//private/var/folders/d4/mn8gvlx91cz80s_9c4gjr12r0000gn/T/mastra-mastra-ai-mastra-_mastra_core_1.16.0/packages/core/CHANGELOG.md">@​mastra/core@1.16.0</a></h3>
<h4>Minor Changes</h4>
<ul>
<li>
<p>Added dataset-agent association and experiment status tracking for
the Evaluate workflow. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/14470">#14470</a>)</p>
<ul>
<li><strong>Dataset targeting</strong>: Added <code>targetType</code>
and <code>targetIds</code> fields to datasets, enabling association with
agents, scorers, or workflows. Datasets can now be linked to multiple
entities.</li>
<li><strong>Experiment status</strong>: Added <code>status</code> field
to experiment results (<code>'needs-review'</code>,
<code>'reviewed'</code>, <code>'complete'</code>) for review queue
workflow.</li>
<li><strong>Dataset experiment routes</strong>: Added API endpoints for
triggering experiments from a dataset with configurable target type and
target ID.</li>
<li><strong>LLM data generation</strong>: Added endpoint for generating
dataset items using an LLM with configurable count and prompt.</li>
<li><strong>Failure analysis</strong>: Added endpoint for clustering
experiment failures and proposing tags using LLM analysis.</li>
</ul>
</li>
<li>
<p>Added agent version support for experiments. When triggering an
experiment, you can now pass an <code>agentVersion</code> parameter to
pin which agent version to use. The agent version is stored with the
experiment and returned in experiment responses. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/14562">#14562</a>)</p>
<pre lang="ts"><code>const client = new MastraClient();
<p>await client.triggerDatasetExperiment({
datasetId: &quot;my-dataset&quot;,
targetType: &quot;agent&quot;,
targetId: &quot;my-agent&quot;,
version: 3, // pin to dataset version 3
agentVersion: &quot;ver_abc123&quot; // pin to a specific agent version
});
</code></pre></p>
</li>
<li>
<p>Added tool suspension handling to the Harness. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/14611">#14611</a>)</p>
<p>When a tool calls <code>suspend()</code> during execution, the
harness now emits a <code>tool_suspended</code> event, reports
<code>agent_end</code> with reason <code>'suspended'</code>, and exposes
<code>respondToToolSuspension()</code> to resume execution with
user-provided data.</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/mastra-ai/mastra/blob/main/packages/mcp/CHANGELOG.md">@​mastra/mcp's
changelog</a>.</em></p>
<blockquote>
<h2>1.16.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>
<p>Updated the MCP client and server to run on the MCP 2.0 packages.
Request context, authentication, logging, and progress behavior are
unchanged, so tools that read <code>context.mcp.extra.authInfo</code>,
send progress, or use elicitation keep working as before. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/18683">#18683</a>)</p>
<p>Tool schemas advertised over MCP no longer declare a draft-07
<code>$schema</code> dialect. The MCP 2.0 default validator rejects that
dialect, which previously made tools with output schemas fail on the
client.</p>
<p><strong>If you pass a custom schema validator</strong></p>
<p>The optional <code>jsonSchemaValidator</code> option now takes its
validator from the MCP packages. Update the import path:</p>
<pre lang="ts"><code>// Before
import { CfWorkerJsonSchemaValidator } from
'@modelcontextprotocol/sdk/validation/cfworker';
<p>// After
import { CfWorkerJsonSchemaValidator } from
'<code>@​modelcontextprotocol/client/</code>validators/cf-worker';</p>
<p>const mcp = new MCPClient({
servers: {
weather: { url: new URL('<a
href="https://example.com/mcp">https://example.com/mcp</a>'),
jsonSchemaValidator: new CfWorkerJsonSchemaValidator() },
},
});
</code></pre></p>
<p><strong>If you import MCP protocol types directly</strong></p>
<p>Types re-exported by <code>@mastra/mcp</code> (such as
<code>ToolAnnotations</code>, <code>LoggingLevel</code>, and the OAuth
helpers) are unchanged and need no edits. Only imports that reached past
<code>@mastra/mcp</code> into <code>@modelcontextprotocol/sdk</code>
need repointing to <code>@modelcontextprotocol/client</code> or
<code>@modelcontextprotocol/server</code>.</p>
</li>
<li>
<p>Add opt-in security hardening options to the MCP client. Both options
are opt-in; default behavior is unchanged. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/20868">#20868</a>)</p>
<ul>
<li><code>allowedHosts</code> on HTTP server configs restricts which
hosts the client's HTTP requests may target, covering the initial
connection, the SSE fallback, and OAuth discovery. On the default fetch
path redirect hops are blocked before they are sent; with a custom
<code>fetch</code>, the final response URL is validated after the
request runs, so custom fetch implementations must enforce redirect
policy themselves when preventing outbound contact is required.</li>
<li><code>inheritDefaultEnv: false</code> on stdio server configs stops
the subprocess from inheriting the SDK's default environment variables;
only the entries you list in <code>env</code> are passed.</li>
</ul>
<pre lang="typescript"><code>const mcp = new MCPClient({
  servers: {
    weather: {
      url: new URL('https://weather.example/mcp'),
      allowedHosts: ['weather.example'],
    },
    local: {
      command: 'npx',
      args: ['tsx', 'stdio-server.ts'],
      inheritDefaultEnv: false,
      env: { WEATHER_API_KEY: process.env.WEATHER_API_KEY! },
    },
  },
});
</code></pre>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/mastra-ai/mastra/commit/387c6b7f5a76e34bc3e2a1ec34cd5893abf4dcf4"><code>387c6b7</code></a>
chore: version - exit prerelease mode</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/361c421ca280e3fe6955ae91625931416bf4a731"><code>361c421</code></a>
chore: version packages</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/1b1dd7bc0e59b7a8bfabd09a3eec1ccd95b4c2f3"><code>1b1dd7b</code></a>
Cache MCP tool definitions and rebuild tools without reconnecting at
startup ...</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/ac0a3b8bcd5777b803b6b6aba2b6b60026919adc"><code>ac0a3b8</code></a>
chore: version packages (alpha) (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/20769">#20769</a>)</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/9ba12470c77f1c03642d720ce67e517e878f666e"><code>9ba1247</code></a>
fix(mcp): send MCP content text to the model via toModelOutput (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/20176">#20176</a>)</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/289f4ce16e3293370440172132c52ee787cbc09f"><code>289f4ce</code></a>
fix(core,mcp): coerce sub-agent maxSteps and prevent spurious MCP
reconnects ...</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/8e23a0b207f34b84bd28f3bf554c6931d8025b97"><code>8e23a0b</code></a>
chore: version packages</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/e7a5da4ef8e4dd452d2f232961b4e682a85ffe43"><code>e7a5da4</code></a>
feat: MCP v2 (draft) (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/18683">#18683</a>)</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/c71e3077e69eae3f25aa628e3778f153a9d6ab36"><code>c71e307</code></a>
feat(mcp): opt-in allowedHosts URL policy and inheritDefaultEnv stdio
isolati...</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/03348e6bea7d4b44edb3298e286506afdbcc04f0"><code>03348e6</code></a>
chore(deps): update security updates [security] (major) (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/mcp/issues/19265">#19265</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/mastra-ai/mastra/commits/@mastra/mcp@1.16.0/packages/mcp">compare
view</a></li>
</ul>
</details>
<br />

Updates `ai` from 6.0.241 to 6.0.256
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/vercel/ai/releases">ai's
releases</a>.</em></p>
<blockquote>
<h2>ai@6.0.256</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [31205a4]
<ul>
<li><code>@​ai-sdk/provider-utils</code><a
href="https://github.com/4"><code>@​4</code></a>.0.46</li>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.174</li>
</ul>
</li>
</ul>
<h2>ai@6.0.255</h2>
<h3>Patch Changes</h3>
<ul>
<li>35a94b0: Keep chat status submitted until response content begins
streaming.</li>
<li>93d24c6: Avoid repeatedly cloning accumulated text in
<code>readUIMessageStream</code> while
preserving independent snapshots for mutable nested values.</li>
<li>1bd1caf: Fix declaration emit for exported values that infer an
<code>Output</code> type.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/ai/blob/ai@6.0.256/packages/ai/CHANGELOG.md">ai's
changelog</a>.</em></p>
<blockquote>
<h2>6.0.256</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [31205a4]
<ul>
<li><code>@​ai-sdk/provider-utils</code><a
href="https://github.com/4"><code>@​4</code></a>.0.46</li>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.174</li>
</ul>
</li>
</ul>
<h2>6.0.255</h2>
<h3>Patch Changes</h3>
<ul>
<li>35a94b0: Keep chat status submitted until response content begins
streaming.</li>
<li>93d24c6: Avoid repeatedly cloning accumulated text in
<code>readUIMessageStream</code> while
preserving independent snapshots for mutable nested values.</li>
<li>1bd1caf: Fix declaration emit for exported values that infer an
<code>Output</code> type.</li>
</ul>
<h2>6.0.254</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [71e94ad]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.173</li>
</ul>
</li>
</ul>
<h2>6.0.253</h2>
<h3>Patch Changes</h3>
<ul>
<li>d91d30b: Preserve reasoning block IDs from UI message streams on
reasoning UI parts.</li>
<li>Updated dependencies [0ec239b]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.172</li>
</ul>
</li>
</ul>
<h2>6.0.252</h2>
<h3>Patch Changes</h3>
<ul>
<li>2f96d3f: Allow providers without reranking model support to satisfy
the <code>Provider</code> type.</li>
<li>afb1965: Propagate errors thrown by the Chat <code>onFinish</code>
callback to the initiating request.</li>
<li>Updated dependencies [18b0965]</li>
<li>Updated dependencies [451d2c3]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.171</li>
</ul>
</li>
</ul>
<h2>6.0.251</h2>
<h3>Patch Changes</h3>
<ul>
<li>d13c2e9: Respect ToolLoopAgent timeouts configured in agent
settings.</li>
</ul>
<h2>6.0.250</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vercel/ai/commit/85464f4e2026d9fc0274424c0171a25742836411"><code>85464f4</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/18920">#18920</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/4b050c0884f1f3c8f66867e8a91e3c5d70f8ac20"><code>4b050c0</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/18865">#18865</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/1bd1caf15fd87dd74c2c2e4af70800b3107b9af0"><code>1bd1caf</code></a>
[v6.0] fix: declaration emit failure for exported utilities using Prompt
and ...</li>
<li><a
href="https://github.com/vercel/ai/commit/93d24c6d8b664f4bb218d2e725eae3a9d6115f05"><code>93d24c6</code></a>
[v6.0] fix: prevent quadratic readUIMessageStream allocation without
weakenin...</li>
<li><a
href="https://github.com/vercel/ai/commit/9190ea8c3766862cb4bf6262a0061a4c3b8e6c2a"><code>9190ea8</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/18855">#18855</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/35a94b09b323a9b30a7f2c3974e15f00092881a0"><code>35a94b0</code></a>
[v6.0] fix: keep chat submitted until response content starts streaming
(<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/18861">#18861</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/f8cf14d13c66794cac9be6b024c20e1e316cbf9a"><code>f8cf14d</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/18786">#18786</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/d91d30b0151c52120a6d791a47c4bfd1da4a4065"><code>d91d30b</code></a>
[v6.0] fix: reasoning UI message parts lose their SSE block IDs (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/18753">#18753</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/1b0361cdd052701c9b043cd2bc87ab3035d4929d"><code>1b0361c</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/18745">#18745</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/afb19653c29338697ee7e3697752ebbe96bd62b5"><code>afb1965</code></a>
[v6.0] fix: propagate errors thrown by Chat onFinish callbacks (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/18736">#18736</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vercel/ai/commits/ai@6.0.256/packages/ai">compare
view</a></li>
</ul>
</details>
<br />

Updates `@anthropic-ai/sdk` from 0.115.0 to 0.117.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/anthropic-sdk-typescript/releases">@​anthropic-ai/sdk's
releases</a>.</em></p>
<blockquote>
<h2>sdk: v0.117.1</h2>
<h2>0.117.1 (2026-08-13)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.117.0...sdk-v0.117.1">sdk-v0.117.0...sdk-v0.117.1</a></p>
<h3>Chores</h3>
<ul>
<li><strong>ci:</strong> allow manually re-publishing a package to npm
from the release workflow (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/af60c1f980557368fb10c3701d8dc8a1fa75d70e">af60c1f</a>)</li>
<li><strong>internal:</strong> tag uploaded preview builds with the
branch name (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/295">#295</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/228f44ee4848e6a26be27d26093635e2dba783ea">228f44e</a>)</li>
</ul>
<h2>sdk: v0.117.0</h2>
<h2>0.117.0 (2026-08-13)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.116.0...sdk-v0.117.0">sdk-v0.116.0...sdk-v0.117.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add output_behavior to dream creation (create
a new memory store or update the input store in place) (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/6a5bd0f34d214759f97d485e46b09203fff3ea99">6a5bd0f</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>build:</strong> include dotfiles when flattening dist during
git installs (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/917dbbb40070dbd1f861b16fcf297720d96f691b">917dbbb</a>)</li>
<li><strong>client:</strong> add models (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/a7bfbb1b31e9d1dffe9a83b90ec1d0dabf5c36db">a7bfbb1</a>)</li>
<li><strong>messages:</strong> honor per-request timeout in the
non-streaming long-request check (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/272">#272</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/0fdd8a8feb5d16fbb943490a2b1e8ecf915596d6">0fdd8a8</a>)</li>
<li><strong>streaming:</strong> apply all message_delta fields when
accumulating streamed messages (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/289">#289</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/7b82659d70201ae3edab846f1693366db7e62ce3">7b82659</a>)</li>
<li><strong>tool-runner:</strong> forward the response container id to
the next request (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/271">#271</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5bdee4a8ddd83e2f1c71daa429345b3b0fea4602">5bdee4a</a>)</li>
<li><strong>tools:</strong> align path resolution, skill-archive
members, and heartbeat bounds with the other SDKs (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/264">#264</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5fbc729c82ec3967c9f76428d0f733b5fa61ddd5">5fbc729</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>ci:</strong> run breaking-change detection as a ci.yml job
on every push (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/c34c1d53f3227b3978621590e67f5a33f5cad107">c34c1d5</a>)</li>
<li><strong>internal:</strong> switch from yarn to pnpm (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/f4eeea09648620d35517513814ffdc3bd3080801">f4eeea0</a>)</li>
<li><strong>tools:</strong> escape backslashes in skill archive
exclusion patterns (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/311">#311</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/67ede1c665883b7785af3240c749601d7ca19255">67ede1c</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li><strong>api:</strong> clarify that user profile name is optional for
resold profiles (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/1b6fed5868bd16dd92120440d373da22084be237">1b6fed5</a>)</li>
</ul>
<h2>sdk: v0.116.0</h2>
<h2>0.116.0 (2026-08-07)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.115.0...sdk-v0.116.0">sdk-v0.115.0...sdk-v0.116.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add
<code>mid-conversation-tool-changes-2026-07-01</code> beta (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/70e04f689baa233e7cb2fed6bb807562f5595928">70e04f6</a>)</li>
<li><strong>api:</strong> add support for session budgets, advisor tool,
pinned inference location and skills auto-loading from GitHub (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/1336a4a90387a7005f6211b6df5e2b247f4cb6b3">1336a4a</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md">@​anthropic-ai/sdk's
changelog</a>.</em></p>
<blockquote>
<h2>0.117.1 (2026-08-13)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.117.0...sdk-v0.117.1">sdk-v0.117.0...sdk-v0.117.1</a></p>
<h3>Chores</h3>
<ul>
<li><strong>ci:</strong> allow manually re-publishing a package to npm
from the release workflow (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/af60c1f980557368fb10c3701d8dc8a1fa75d70e">af60c1f</a>)</li>
<li><strong>internal:</strong> tag uploaded preview builds with the
branch name (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/295">#295</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/228f44ee4848e6a26be27d26093635e2dba783ea">228f44e</a>)</li>
</ul>
<h2>0.117.0 (2026-08-13)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.116.0...sdk-v0.117.0">sdk-v0.116.0...sdk-v0.117.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add output_behavior to dream creation (create
a new memory store or update the input store in place) (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/6a5bd0f34d214759f97d485e46b09203fff3ea99">6a5bd0f</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>build:</strong> include dotfiles when flattening dist during
git installs (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/917dbbb40070dbd1f861b16fcf297720d96f691b">917dbbb</a>)</li>
<li><strong>client:</strong> add models (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/a7bfbb1b31e9d1dffe9a83b90ec1d0dabf5c36db">a7bfbb1</a>)</li>
<li><strong>messages:</strong> honor per-request timeout in the
non-streaming long-request check (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/272">#272</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/0fdd8a8feb5d16fbb943490a2b1e8ecf915596d6">0fdd8a8</a>)</li>
<li><strong>streaming:</strong> apply all message_delta fields when
accumulating streamed messages (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/289">#289</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/7b82659d70201ae3edab846f1693366db7e62ce3">7b82659</a>)</li>
<li><strong>tool-runner:</strong> forward the response container id to
the next request (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/271">#271</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5bdee4a8ddd83e2f1c71daa429345b3b0fea4602">5bdee4a</a>)</li>
<li><strong>tools:</strong> align path resolution, skill-archive
members, and heartbeat bounds with the other SDKs (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/264">#264</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5fbc729c82ec3967c9f76428d0f733b5fa61ddd5">5fbc729</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>ci:</strong> run breaking-change detection as a ci.yml job
on every push (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/c34c1d53f3227b3978621590e67f5a33f5cad107">c34c1d5</a>)</li>
<li><strong>internal:</strong> switch from yarn to pnpm (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/f4eeea09648620d35517513814ffdc3bd3080801">f4eeea0</a>)</li>
<li><strong>tools:</strong> escape backslashes in skill archive
exclusion patterns (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/311">#311</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/67ede1c665883b7785af3240c749601d7ca19255">67ede1c</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li><strong>api:</strong> clarify that user profile name is optional for
resold profiles (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/1b6fed5868bd16dd92120440d373da22084be237">1b6fed5</a>)</li>
</ul>
<h2>0.116.0 (2026-08-07)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.115.0...sdk-v0.116.0">sdk-v0.115.0...sdk-v0.116.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add
<code>mid-conversation-tool-changes-2026-07-01</code> beta (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/70e04f689baa233e7cb2fed6bb807562f5595928">70e04f6</a>)</li>
<li><strong>api:</strong> add support for session budgets, advisor tool,
pinned inference location and skills auto-loading from GitHub (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/1336a4a90387a7005f6211b6df5e2b247f4cb6b3">1336a4a</a>)</li>
<li><strong>tools:</strong> make bash timeout and abort errors matchable
by class (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/259">#259</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/201b12e8acd69d7ab7068fe078f7988ab23897d2">201b12e</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/64a1e8e285bbcc4cef2b15ebcadccd8e5f6987ff"><code>64a1e8e</code></a>
chore: release main</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/0281a291359489284c116d1adea6d13aa7a94b6d"><code>0281a29</code></a>
chore(ci): allow manually re-publishing a package to npm from the
release wor...</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/f3e060b568a09556fea9288b688e1191f28f0935"><code>f3e060b</code></a>
chore(internal): tag uploaded preview builds with the branch name (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/295">#295</a>)</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/6fcfb2c3fce958e59750df3e4a8fda969c5ff171"><code>6fcfb2c</code></a>
chore: release main</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/1a1af331442d9e9fc4ba172d87e4bc46a48255b1"><code>1a1af33</code></a>
codegen metadata</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/d6b8f40ffe75a80a53b1464b8cce05b54ecac40d"><code>d6b8f40</code></a>
chore: release main</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5edda861559d809092bead9617a1073324a64585"><code>5edda86</code></a>
chore(tools): escape backslashes in skill archive exclusion patterns (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/311">#311</a>)</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/07cf28ce9d07da7d7c2b96d064d7a370d261c5bc"><code>07cf28c</code></a>
chore(internal): switch from yarn to pnpm</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/a751543f5e0ba2096cc49821c351f8b3a82216ab"><code>a751543</code></a>
docs(api): clarify that user profile name is optional for resold
profiles</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/0c74ed0372883d85378e5f85526d072e12d1997b"><code>0c74ed0</code></a>
fix(build): include dotfiles when flattening dist during git
installs</li>
<li>Additional commits viewable in <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.115.0...sdk-v0.117.1">compare
view</a></li>
</ul>
</details>
<br />

Updates `@google/genai` from 2.15.0 to 2.17.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/googleapis/js-genai/releases">@​google/genai's
releases</a>.</em></p>
<blockquote>
<h2>v2.17.1</h2>
<h2><a
href="https://github.com/googleapis/js-genai/compare/v2.17.0...v2.17.1">2.17.1</a>
(2026-08-13)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Add gemini-3.7-flash (<a
href="https://github.com/googleapis/js-genai/commit/c495e82719486d90561eeb7dc476b9fbaa26077b">c495e82</a>)</li>
</ul>
<h2>v2.17.0</h2>
<h2><a
href="https://github.com/googleapis/js-genai/compare/v2.16.0...v2.17.0">2.17.0</a>
(2026-08-12)</h2>
<h3>Features</h3>
<ul>
<li>Add interaction_status to LiveServerContent (<a
href="https://github.com/googleapis/js-genai/commit/4489991a7c40b22dff75348748048b0b14ac687e">4489991</a>)</li>
<li><strong>api:</strong> make the deferred service tier publicly
available on Vertex (<a
href="https://github.com/googleapis/js-genai/commit/9dafee9cd0f6089221bce5269dbd53fe7fa69806">9dafee9</a>)</li>
<li>Make speech_config a structured object. (<a
href="https://github.com/googleapis/js-genai/commit/9c9066594a57bda7ee417d79f8ef15c8ed0b333d">9c90665</a>)</li>
</ul>
<h2>v2.16.0</h2>
<h2><a
href="https://github.com/googleapis/js-genai/compare/v2.15.0...v2.16.0">2.16.0</a>
(2026-08-06)</h2>
<h3>Features</h3>
<ul>
<li>Add the Gemini Robotics ER 2 Preview model (<a
href="https://github.com/googleapis/js-genai/commit/5647cedfcf3fc5f862b01fb908d6aae267d8bb91">5647ced</a>)</li>
<li>Add TOO_MANY_TOOL_CALLS to FinishReason enum. (<a
href="https://github.com/googleapis/js-genai/commit/a7fa5683bc86a3edce347f6259fca8face0df3a4">a7fa568</a>)</li>
<li>Add top-level errors array to Interaction resource (iAPI) (<a
href="https://github.com/googleapis/js-genai/commit/b9dfd814a16ae985685ebcf5cb99a82625167142">b9dfd81</a>)</li>
<li>Make HttpOptions.timeout a per-attempt deadline in the JS GenAI SDK.
(<a
href="https://github.com/googleapis/js-genai/commit/8268806b3090834870ca6b901bdf289415425bac">8268806</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Add propertyOrdering auto-population for ResponseSchema and
ResponseJsonSchema for Dotnet SDK (<a
href="https://github.com/googleapis/js-genai/commit/e26542fc58f832e0b88affab5c266fd0c469d01c">e26542f</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/googleapis/js-genai/blob/main/CHANGELOG.md">@​google/genai's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/googleapis/js-genai/compare/v2.17.0...v2.17.1">2.17.1</a>
(2026-08-13)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Add gemini-3.7-flash (<a
href="https://github.com/googleapis/js-genai/commit/c495e82719486d90561eeb7dc476b9fbaa26077b">c495e82</a>)</li>
</ul>
<h2><a
href="https://github.com/googleapis/js-genai/compare/v2.16.0...v2.17.0">2.17.0</a>
(2026-08-12)</h2>
<h3>Features</h3>
<ul>
<li>Add interaction_status to LiveServerContent (<a
href="https://github.com/googleapis/js-genai/commit/4489991a7c40b22dff75348748048b0b14ac687e">4489991</a>)</li>
<li><strong>api:</strong> make the deferred service tier publicly
available on Vertex (<a
href="https://github.com/googleapis/js-genai/commit/9dafee9cd0f6089221bce5269dbd53fe7fa69806">9dafee9</a>)</li>
<li>Make speech_config a structured object. (<a
href="https://github.com/googleapis/js-genai/commit/9c9066594a57bda7ee417d79f8ef15c8ed0b333d">9c90665</a>)</li>
</ul>
<h2><a
href="https://github.com/googleapis/js-genai/compare/v2.15.0...v2.16.0">2.16.0</a>
(2026-08-06)</h2>
<h3>Features</h3>
<ul>
<li>Add the Gemini Robotics ER 2 Preview model (<a
href="https://github.com/googleapis/js-genai/commit/5647cedfcf3fc5f862b01fb908d6aae267d8bb91">5647ced</a>)</li>
<li>Add TOO_MANY_TOOL_CALLS to FinishReason enum. (<a
href="https://github.com/googleapis/js-genai/commit/a7fa5683bc86a3edce347f6259fca8face0df3a4">a7fa568</a>)</li>
<li>Add top-level errors array to Interaction resource (iAPI) (<a
href="https://github.com/googleapis/js-genai/commit/b9dfd814a16ae985685ebcf5cb99a82625167142">b9dfd81</a>)</li>
<li>Make HttpOptions.timeout a per-attempt deadline in the JS GenAI SDK.
(<a
href="https://github.com/googleapis/js-genai/commit/8268806b3090834870ca6b901bdf289415425bac">8268806</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Add propertyOrdering auto-population for ResponseSchema and
ResponseJsonSchema for Dotnet SDK (<a
href="https://github.com/googleapis/js-genai/commit/e26542fc58f832e0b88affab5c266fd0c469d01c">e26542f</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/googleapis/js-genai/commit/7736083c6d062ef423a378aecef154aab6def8a2"><code>7736083</code></a>
chore(main): release 2.17.1 (<a
href="https://redirect.github.com/googleapis/js-genai/issues/1853">#1853</a>)</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/c495e82719486d90561eeb7dc476b9fbaa26077b"><code>c495e82</code></a>
fix: Add gemini 3.7</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/dec2d3cbbc3c3928520d5c22fbbb2333b00b4ac9"><code>dec2d3c</code></a>
chore: Update GCS references to Cloud Storage in descriptions</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/0e80b4275655ed21cf1c390772da3e22b2a5a1db"><code>0e80b42</code></a>
Copybara import of the project:</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/4d15a7b78f5fceae4dca09f343c065e18f42b282"><code>4d15a7b</code></a>
chore: remove deprecated Turn types</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/49153845ff8968dff7403ce01ebd24e261403cda"><code>4915384</code></a>
chore(main): release 2.17.0 (<a
href="https://redirect.github.com/googleapis/js-genai/issues/1833">#1833</a>)</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/9c9066594a57bda7ee417d79f8ef15c8ed0b333d"><code>9c90665</code></a>
feat: Make speech_config a structured object.</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/b98223e26e043c40f41369d9c5eb84a5c776f85c"><code>b98223e</code></a>
No public description</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/4489991a7c40b22dff75348748048b0b14ac687e"><code>4489991</code></a>
feat: Add interaction_status to LiveServerContent</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/9dafee9cd0f6089221bce5269dbd53fe7fa69806"><code>9dafee9</code></a>
feat(api): make the deferred service tier publicly available on
Vertex</li>
<li>Additional commits viewable in <a
href="https://github.com/googleapis/js-genai/compare/v2.15.0...v2.17.1">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/core` from 1.2.4 to 1.2.8
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">@​langchain/core's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.2.8</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11369">#11369</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/d6ad9735640a6c729f81ef79361acc5e83c526f1"><code>d6ad973</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
fix(langchain): use unified endpoint for gateway</p>
</li>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11342">#11342</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/3b0e4c48a31811031a460c4d95519a7c1163dc41"><code>3b0e4c4</code></a>
Thanks <a
href="https://github.com/thushanth-bengre-langchain"><code>@​thushanth-bengre-langchain</code></a>!
- feat(core): mark errors as retryable or not, and stop retrying the
ones that aren't</p>
<p>Retry middleware retried every failure up to <code>maxRetries</code>,
including deterministic ones like a bad API key or an unknown model.
Retries also nest, so a single such failure could cost dozens of API
calls.</p>
<p><code>@langchain/core/errors</code> adds <code>stampRetryable(error,
retryable)</code> and <code>getRetryable(error)</code>. Marking an error
leaves its class and shape untouched, so a provider SDK error can be
classified without breaking <code>instanceof</code>.
<code>getRetryable</code> returns <code>undefined</code> for errors
nobody classified, and both are exported so tool authors can mark their
own failures.</p>
<p><code>modelRetryMiddleware</code> and
<code>toolRetryMiddleware</code> now respect the mark by default, and
retries stop as soon as one is found rather than each layer spending its
own budget. Aborted calls, context overflow, and oversized payloads are
marked non-retryable out of the box.
Models accept a per-call <code>maxRetries</code> so a surrounding retry
loop can take over.</p>
<p><strong>Behavior change:</strong> errors marked non-retryable now
fail on the first attempt. Unclassified errors — including any from
third-party integrations or custom tools — retry exactly as before. Pass
<code>retryOn: () =&gt; true</code> to restore the old default. A custom
<code>onFailedAttempt</code> replaces the built-in handler and opts out
of marking.</p>
</li>
</ul>
<h2><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.2.7</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11366">#11366</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/c068bbf8c113132bf16ac7a8add44e486a147b41"><code>c068bbf</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
fix(core,langchain): patch and release core, update peer
dependencies</li>
</ul>
<h2><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.2.6</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11344">#11344</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/f08e0c6d50156accf95a36469a3e107a5598a3a0"><code>f08e0c6</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
fix: apply [Symbol.hasInstance] method to all comparable properties
using .isInstance()</p>
<p>We have some internal schemas that rely on
<code>z.instanceof()</code>. This uses a strict <code>instanceof</code>
check which can conflict if there are multiple versions of core
installed. This overrides the <a
href="https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Symbol/hasInstance">Symbol.hasInstance</a>
method to use the same logic as <code>.isInstance()</code> to compare
objects at runtime.</p>
</li>
</ul>
<h2><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.2.5</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11305">#11305</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/e654022e291b8dae54504ac2d1a3232332406723"><code>e654022</code></a>
Thanks <a
href="https://github.com/jacoblee93"><code>@​jacoblee93</code></a>! -
Add LangSmith Gateway environment configuration to OpenAI, Anthropic,
and Fireworks chat models.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11295">#11295</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/1a1b347d18bc68e842df8badffc987493c81d70a"><code>1a1b347</code></a>
Thanks <a
href="https://github.com/vladislav-nechakhin"><code>@​vladislav-nechakhin</code></a>!
- fix(core): pass the mustache escape override per render call</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/d0c905ddcc2471d0c89a2f1520d96782253ba5c3"><code>d0c905d</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11370">#11370</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/8ba1fd996ff9efe93e5cb75afa946204c00528a4"><code>8ba1fd9</code></a>
fix(aws): classify Bedrock stream-idle timeouts, cover pre-response hang
(<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11">#11</a>...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/3b0e4c48a31811031a460c4d95519a7c1163dc41"><code>3b0e4c4</code></a>
feat(core): mark errors as retryable or not, and stop retrying the ones
that ...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/d6ad9735640a6c729f81ef79361acc5e83c526f1"><code>d6ad973</code></a>
fix(langchain): use unified endpoint for gateway (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11369">#11369</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/3fedf7f1934a592b71da866bd16af886b4e0c00d"><code>3fedf7f</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11367">#11367</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/c068bbf8c113132bf16ac7a8add44e486a147b41"><code>c068bbf</code></a>
fix(core,langchain): patch and release core, update peer dependencies
(<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11366">#11366</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/242b986afd9b257ddbedd5d0dcc84f197289faef"><code>242b986</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11361">#11361</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/2d1f7449c95a554d429535abae0115b4f578bbac"><code>2d1f744</code></a>
chore(langchain): add missing changeset (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11363">#11363</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/f401396a21285d49804f1dc7e4e2fa2396d5317f"><code>f401396</code></a>
feat(langchain): add langsmith gateway to initChatModel (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11362">#11362</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/d36ec6a6f4b1c474b0d9f9cb6037ff37f54183bf"><code>d36ec6a</code></a>
fix(anthropic): preserve gateway cost on the native stream path (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11359">#11359</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchainjs/compare/@langchain/core@1.2.4...@langchain/core@1.2.8">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/langgraph` from 1.4.9 to 1.4.10
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langgraphjs/releases">@​langchain/langgraph's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/langgraph</code><a
href="https://github.com/1"><code>@​1</code></a>.4.10</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langgraphjs/pull/2690">#2690</a>
<a
href="https://github.com/langchain-ai/langgraphjs/commit/00f68a1b002d820b95129bcdaf387d2678ead6f0"><code>00f68a1</code></a>
Thanks <a
href="https://github.com/saad-supports-langchain"><code>@​saad-supports-langchain</code></a>!
- fix(langgraph): keep <code>context</code> values out of tracer-derived
metadata</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langgraphjs/blob/main/libs/langgraph-core/CHANGELOG.md">@​langchain/langgraph's
changelog</a>.</em></p>
<blockquote>
<h2>1.4.10</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langgraphjs/pull/2690">#2690</a>
<a
href="https://github.com/langchain-ai/langgraphjs/commit/00f68a1b002d820b95129bcdaf387d2678ead6f0"><code>00f68a1</code></a>
Thanks <a
href="https://github.com/saad-supports-langchain"><code>@​saad-supports-langchain</code></a>!
- fix(langgraph): keep <code>context</code> values out of tracer-derived
metadata</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langgraphjs/commit/f6b41bf4861322e380e02f746285496e84b0f96b"><code>f6b41bf</code></a>
chore: version packages (<a
href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2698">#2698</a>)</li>
<li><a
href="https://github.com/langchain-ai/langgraphjs/commit/00f68a1b002d820b95129bcdaf387d2678ead6f0"><code>00f68a1</code></a>
fix(langgraph): keep context values out of tracer-derived metadata (<a
href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2690">#2690</a>)</li>
<li><a
href="https://github.com/langchain-ai/langgraphjs/commit/6ac60da74f6b9e29d20b111a7947ac3060f1d2dd"><code>6ac60da</code></a>
chore(deps): bump the langchain group across 1 directory with 5 updates
(<a
href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2651">#2651</a>)</li>
<li>See full diff in <a
href="https://github.com/langchain-ai/langgraphjs/commits/@langchain/langgraph@1.4.10/libs/langgraph-core">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/openai` from 1.5.5 to 1.5.8
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">@​langchain/openai's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/openai</code><a
href="https://github.com/1"><code>@​1</code></a>.5.8</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11342">#11342</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/3b0e4c48a31811031a460c4d95519a7c1163dc41"><code>3b0e4c4</code></a>
Thanks <a
href="https://github.com/thushanth-bengre-langchain"><code>@​thushanth-bengre-langchain</code></a>!
- feat(openai): mark OpenAI provider errors as retryable or not</p>
<p>Builds on <code>stampRetryable</code> in <code>@langchain/core</code>
so the retry middleware can tell a transient failure from a
deterministic one. Timeouts and rate limits are marked retryable;
aborts, context overflow, invalid tool results, bad credentials, and
unknown models non-retryable. Anything else stays unmarked and retries
as before.</p>
<p>Also forwards a per-call <code>maxRetries</code> to the retry loop,
so a surrounding retry loop such as <code>modelRetryMiddleware</code>
can take over instead of the two multiplying against each other.</p>
<p>Errors keep their original class, so <code>instanceof</code> against
the <code>openai</code> SDK error types is unaffected.</p>
</li>
</ul>
<h2><code>@​langchain/openai</code><a
href="https://github.com/1"><code>@​1</code></a>.5.7</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11347">#11347</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/3fe4c43ce3399ebf2391ed612d78fedcd3ea5ec6"><code>3fe4c43</code></a>
Thanks <a
href="https://github.com/talarari"><code>@​talarari</code></a>! -
fix(openai): include <code>usage</code> in
<code>response_metadata</code> when <code>system_fingerprint</code> is
absent</li>
</ul>
<h2><code>@​langchain/openai</code><a
href="https://github.com/1"><code>@​1</code></a>.5.6</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11305">#11305</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/e654022e291b8dae54504ac2d1a3232332406723"><code>e654022</code></a>
Thanks <a
href="https://github.com/jacoblee93"><code>@​jacoblee93</code></a>! -
Add LangSmith Gateway environment configuration to OpenAI, Anthropic,
and Fireworks chat models.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/d0c905ddcc2471d0c89a2f1520d96782253ba5c3"><code>d0c905d</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11370">#11370</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/8ba1fd996ff9efe93e5cb75afa946204c00528a4"><code>8ba1fd9</code></a>
fix(aws): classify Bedrock stream-idle timeouts, cover pre-response hang
(<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11">#11</a>...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/3b0e4c48a31811031a460c4d95519a7c1163dc41"><code>3b0e4c4</code></a>
feat(core): mark errors as retryable or not, and stop retrying the ones
that ...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/d6ad9735640a6c729f81ef79361acc5e83c526f1"><code>d6ad973</code></a>
fix(langchain): use unified endpoint for gateway (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11369">#11369</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/3fedf7f1934a592b71da866bd16af886b4e0c00d"><code>3fedf7f</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11367">#11367</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/c068bbf8c113132bf16ac7a8add44e486a147b41"><code>c068bbf</code></a>
fix(core,langchain): patch and release core, update peer dependencies
(<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11366">#11366</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/242b986afd9b257ddbedd5d0dcc84f197289faef"><code>242b986</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11361">#11361</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/2d1f7449c95a554d429535abae0115b4f578bbac"><code>2d1f744</code></a>
chore(langchain): add missing changeset (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11363">#11363</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/f401396a21285d49804f1dc7e4e2fa2396d5317f"><code>f401396</code></a>
feat(langchain): add langsmith gateway to initChatModel (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11362">#11362</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/d36ec6a6f4b1c474b0d9f9cb6037ff37f54183bf"><code>d36ec6a</code></a>
fix(anthropic): preserve gateway cost on the native stream path (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11359">#11359</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchainjs/compare/@langchain/openai@1.5.5...@langchain/openai@1.5.8">compare
view</a></li>
</ul>
</details>
<br />

Updates `langchain` from 1.5.4 to 1.5.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">langchain's
releases</a>.</em></p>
<blockquote>
<h2>langchain@1.5.9</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11369">#11369</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/d6ad9735640a6c729f81ef79361acc5e83c526f1"><code>d6ad973</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
fix(langchain): use unified endpoint for gateway</p>
</li>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11342">#11342</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/3b0e4c48a31811031a460c4d95519a7c1163dc41"><code>3b0e4c4</code></a>
Thanks <a
href="https://github.com/thushanth-bengre-langchain"><code>@​thushanth-bengre-langchain</code></a>!
- feat(core): mark errors as retryable or not, and stop retrying the
ones that aren't</p>
<p>Retry middleware retried every failure up to <code>maxRetries</code>,
including deterministic ones like a bad API key or an unknown model.
Retries also nest, so a single such failure could cost dozens of API
calls.</p>
<p><code>@langchain/core/errors</code> adds <code>stampRetryable(error,
retryable)</code> and <code>getRetryable(error)</code>. Marking an error
leaves its class and shape untouched, so a provider SDK error can be
classified without breaking <code>instanceof</code>.
<code>getRetryable</code> returns <code>undefined</code> for errors
nobody classified, and both are exported so tool authors can mark their
own failures.</p>
<p><code>modelRetryMiddleware</code> and
<code>toolRetryMiddleware</code> now respect the mark by default, and
retries stop as soon as one is found rather than each layer spending its
own budget. Aborted calls, context overflow, and oversized payloads are
marked non-retryable out of the box.
Models accept a per-call <code>maxRetries</code> so a surrounding retry
loop can take over.</p>
<p><strong>Behavior change:</strong> errors marked non-retryable now
fail on the first attempt. Unclassified errors — including any from
third-party integrations or custom tools — retry exactly as before. Pass
<code>retryOn: () =&gt; true</code> to restore the old default. A custom
<code>onFailedAttempt</code> replaces the built-in handler and opts out
of marking.</p>
</li>
</ul>
<h2>langchain@1.5.8</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11366">#11366</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/c068bbf8c113132bf16ac7a8add44e486a147b41"><code>c068bbf</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
fix(core,langchain): patch and release core, update peer
dependencies</li>
</ul>
<h2>langchain@1.5.7</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11363">#11363</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/2d1f7449c95a554d429535abae0115b4f578bbac"><code>2d1f744</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
feat(langchain): add langsmith gateway to initChatModel- <a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11362">#11362</a></li>
</ul>
<h2>langchain@1.5.6</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11331">#11331</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/18765b002c3819bc4dc42123a293cab27a35ce4f"><code>18765b0</code></a>
Thanks <a
href="https://github.com/thushanth-bengre-langchain"><code>@​thushanth-bengre-langchain</code></a>!
- fix(langchain): exclude middleware-internal model calls from the
message projection</p>
<p>Bookkeeping model calls made by <code>summarizationMiddleware</code>
and <code>toolEmulatorMiddleware</code> no longer appear in
<code>run.messages</code> or <code>stream({ streamMode:
&quot;messages&quot; })</code>, and the summary
<code>summarizationMiddleware</code> writes back to state is no longer
projected as a new message. These calls remain observable via
<code>streamEvents({ version: &quot;v2&quot; })</code>, identified by
<code>lc_source</code>.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11344">#11344</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/f08e0c6d50156accf95a36469a3e107...

_Description has been truncated_

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: jkomyno <alberto@composio.dev>
2026-08-18 13:51:57 +02:00
Alberto Schiabel 09f76b1c9f refactor(cli): eliminate raw environment access (#4134)
This PR:
- routes Composio-prefixed runtime configuration through `APP_CONFIG`
and normalizes unprefixed host values through `HOST_CONFIG` in
`app-config.ts`
- removes `loadOptionalAppConfig`-style fallback loading so optional
strings, booleans, and CLI flag precedence resolve at the configuration
boundary
- removes every executable `process.env` reference from CLI source;
child commands inherit the ambient environment through
`@effect/platform` and receive explicit normalized overrides
- preserves arbitrary `CODEX_*`, `CLAUDE_*`, and `OPENCLAW_*` detection
through Effect config enumeration without exposing the raw environment
map
- propagates telemetry debug state through worker arguments instead of
mutating the process environment
- replaces removable filesystem, OS, subprocess, and error-handling
exceptions with Effect services and typed control flow
- documents supported and internal CLI environment variables, including
their `user_data.json` and `config.json` mappings
- reduces registered CLI lint boundaries from 45 to 4; the retained
entries are the detached-spawn, Node OS, synchronous preload filesystem,
and MD5 checksum implementations
- verifies the result with 1,201 passing CLI tests (1 skipped), strict
Oxlint, boundary validation, root typechecking across 19 packages, the
CLI build, and real `composio run` child-process checks
2026-08-18 12:54:26 +02:00
dependabot[bot] c0c511bb4b chore(deps-dev): bump the npm-development group with 7 updates (#4133)
Bumps the npm-development group with 7 updates:

| Package | From | To |
| --- | --- | --- |
|
[@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
| `26.1.2` | `26.2.0` |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) |
`1.77.0` | `1.78.0` |
|
[oxlint-plugin-eslint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint)
| `1.77.0` | `1.78.0` |
| [turbo](https://github.com/vercel/turborepo) | `2.10.8` | `2.10.9` |
|
[chrome-devtools-mcp](https://github.com/ChromeDevTools/chrome-devtools-mcp)
| `1.6.0` | `1.7.0` |
|
[@earendil-works/pi-coding-agent](https://github.com/earendil-works/pi/tree/HEAD/packages/coding-agent)
| `0.83.0` | `0.84.1` |
| [eve](https://github.com/vercel/eve/tree/HEAD/packages/eve) | `0.29.5`
| `0.31.3` |

Updates `@types/node` from 26.1.2 to 26.2.0
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node">compare
view</a></li>
</ul>
</details>
<br />

Updates `oxlint` from 1.77.0 to 1.78.0
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md">oxlint's
changelog</a>.</em></p>
<blockquote>
<h2>[1.78.0] - 2026-08-10</h2>
<h3>🚀 Features</h3>
<ul>
<li>ccb8fe8 linter/jsdoc: Implement <code>no-blank-blocks</code> rule
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25207">#25207</a>)
(Mikhail Baev)</li>
<li>d4a897c linter/eslint: Implement <code>one-var</code> rule (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/24470">#24470</a>)
(Cole Ellison)</li>
<li>5ab9340 linter/jsx-a11y/anchor-has-content: Add options to match
eslint (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/24571">#24571</a>)
(Cole Ellison)</li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>9573937 linter/typescript: Validate <code>ban-ts-comment</code>
description_format (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25320">#25320</a>)
(Mikhail Baev)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/oxc-project/oxc/commit/c42d6397eab5b2d5bb2bd6746c57bc2a9cad21bd"><code>c42d639</code></a>
release(apps): oxlint v1.78.0 &amp;&amp; oxfmt v0.63.0 (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25473">#25473</a>)</li>
<li><a
href="https://github.com/oxc-project/oxc/commit/ccb8fe89db08123ff2b86d7fb2f39d0dd6c33df7"><code>ccb8fe8</code></a>
feat(linter/jsdoc): implement <code>no-blank-blocks</code> rule (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25207">#25207</a>)</li>
<li><a
href="https://github.com/oxc-project/oxc/commit/9573937df3cc01f29e1c65bc018ce378ec947e0e"><code>9573937</code></a>
fix(linter/typescript): validate <code>ban-ts-comment</code>
description_format (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25320">#25320</a>)</li>
<li><a
href="https://github.com/oxc-project/oxc/commit/d4a897ce2290bf853720b4fbf371304bfea2c980"><code>d4a897c</code></a>
feat(linter/eslint): implement <code>one-var</code> rule (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/24470">#24470</a>)</li>
<li><a
href="https://github.com/oxc-project/oxc/commit/5ab9340637eff80539bca89a494e162e94569358"><code>5ab9340</code></a>
feat(linter/jsx-a11y/anchor-has-content): add options to match eslint
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/24571">#24571</a>)</li>
<li>See full diff in <a
href="https://github.com/oxc-project/oxc/commits/oxlint_v1.78.0/npm/oxlint">compare
view</a></li>
</ul>
</details>
<br />

Updates `oxlint-plugin-eslint` from 1.77.0 to 1.78.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/oxc-project/oxc/releases">oxlint-plugin-eslint's
releases</a>.</em></p>
<blockquote>
<h2>oxlint v1.78.0 &amp; oxfmt v0.63.0</h2>
<h2>Table of Contents</h2>
<ul>
<li><a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/blob/HEAD/#oxlint-v1.78.0">Oxlint
v1.78.0</a></li>
<li><a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/blob/HEAD/#oxfmt-v0.63.0">Oxfmt
v0.63.0</a></li>
</ul>
<h2>Oxlint v1.78.0</h2>
<h3>🚀 Features</h3>
<ul>
<li>ccb8fe8 linter/jsdoc: Implement <code>no-blank-blocks</code> rule
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25207">#25207</a>)
(Mikhail Baev)</li>
<li>d4a897c linter/eslint: Implement <code>one-var</code> rule (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/24470">#24470</a>)
(Cole Ellison)</li>
<li>5ab9340 linter/jsx-a11y/anchor-has-content: Add options to match
eslint (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/24571">#24571</a>)
(Cole Ellison)</li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>b746e00 linter/eslint/no-implicit-coercion: Preserve template
coercion whitespace (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25470">#25470</a>)
(camc314)</li>
<li>a92c541 linter: Preserve source text for JS plugin ignore fixes (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25280">#25280</a>)
(Norcleeh)</li>
<li>675c840 linter/eslint/prefer-promise-reject-errors: Handle
parenthesized calls (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25378">#25378</a>)
(camc314)</li>
<li>1703739 linter/unicorn/new-for-builtins: Ignore optional chains (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25411">#25411</a>)
(tanakalucky)</li>
<li>95ece63 linter/unicorn/prefer-code-point: Downgrade the auto-fix to
dangerous (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25412">#25412</a>)
(leemr)</li>
<li>c451a0e linter/vitest: Validate
<code>consistent-test-filename</code> regex patterns (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25408">#25408</a>)
(Mikhail Baev)</li>
<li>937825c react_compiler: Disable exhaustive memo validation by
default (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25417">#25417</a>)
(Boshen)</li>
<li>f0f7dae linter/eslint/no-unused-vars: Report invalid regex options
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25380">#25380</a>)
(Cameron)</li>
<li>44e73fd linter/unicorn/prefer-array-flat: Fix
<code>concat.apply</code> suggestions (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25373">#25373</a>)
(Cameron)</li>
<li>6846a9a linter/react/rules-of-hooks: Detect constructor callbacks
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25377">#25377</a>)
(camc314)</li>
<li>b247a9d linter/unicorn/new-for-builtins: Support
<code>Float16Array</code> (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25382">#25382</a>)
(tanakalucky)</li>
<li>19109cd linter/unicorn/error-message: Support
<code>SuppressedError</code> messages (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25375">#25375</a>)
(camc314)</li>
<li>9c13f5e linter: Assert token lookup invariants (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25368">#25368</a>)
(camc314)</li>
<li>bc35f83 linter/eslint/no-unused-vars: Bound catch parameter lookup
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25367">#25367</a>)
(camc314)</li>
<li>c159fb9 linter/unicorn/switch-case-braces: Bound token lookup (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25363">#25363</a>)
(camc314)</li>
<li>03b2eb2 linter/unicorn/no-static-only-class: Bound token lookup (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25361">#25361</a>)
(camc314)</li>
<li>0afc59e linter/unicorn/empty-brace-spaces: Bound token lookup (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25353">#25353</a>)
(camc314)</li>
<li>2963d98 linter/eslint/no-unreachable-loop: Do not report loops whose
body has a finally block (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25335">#25335</a>)
(Todor Andonov)</li>
<li>589e5fb linter/eslint/no-param-reassign: Validate
<code>ignorePropertyModificationsForRegex</code> property (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25346">#25346</a>)
(Mikhail Baev)</li>
<li>aae5d8b linter/eslint/no-throw-literal: False positive on variable
declared without initializer (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25275">#25275</a>)
(cjnoname)</li>
<li>6b1c479 oxlint: Normalize customized rule names (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25316">#25316</a>)
(camc314)</li>
<li>d494eb5 linter/unicorn/consistent-existence-index-check: Bound token
lookup (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25325">#25325</a>)
(camc314)</li>
<li>4266037 linter/typescript/prefer-namespace-keyword: Bound token
lookup (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25322">#25322</a>)
(camc314)</li>
<li>4745b4e linter/typescript/no-namespace: Bound token lookup (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25321">#25321</a>)
(camc314)</li>
<li>648a481 linter/eslint/one-var: Avoid joining exported declarations
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25314">#25314</a>)
(camc314)</li>
<li>9573937 linter/typescript: Validate <code>ban-ts-comment</code>
description_format (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25320">#25320</a>)
(Mikhail Baev)</li>
<li>ebf7d18 linter/typescript/consistent-type-definitions: Bound token
lookup (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25281">#25281</a>)
(camc314)</li>
<li>1501ccf linter/typescript/consistent-generic-constructors: Bound
token lookup (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25258">#25258</a>)
(camc314)</li>
</ul>
<h3>⚡ Performance</h3>
<ul>
<li>8f784f3 linter: Reduce rule config dispatch size (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25461">#25461</a>)
(Boshen)</li>
<li>2de4ec2 linter: Reduce visitor code size (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25441">#25441</a>)
(Boshen)</li>
<li>6fb7f47 linter/unicorn/prefer-export-from: Narrow
<code>ExportFromDeclaration</code> lookup (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25381">#25381</a>)
(camc314)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/oxc-project/oxc/commit/c42d6397eab5b2d5bb2bd6746c57bc2a9cad21bd"><code>c42d639</code></a>
release(apps): oxlint v1.78.0 &amp;&amp; oxfmt v0.63.0 (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25473">#25473</a>)</li>
<li>See full diff in <a
href="https://github.com/oxc-project/oxc/commits/apps_v1.78.0/npm/oxlint-plugin-eslint">compare
view</a></li>
</ul>
</details>
<br />

Updates `turbo` from 2.10.8 to 2.10.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/turborepo/releases">turbo's
releases</a>.</em></p>
<blockquote>
<h2>Turborepo v2.10.9</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<h3>Changelog</h3>
<ul>
<li>chore: Release Turborepo 2.10.8 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/13626">vercel/turborepo#13626</a></li>
<li>perf: Walk literal-prefix tree globs without wax compilation by <a
href="https://github.com/charpeni"><code>@​charpeni</code></a> in <a
href="https://redirect.github.com/vercel/turborepo/pull/13522">vercel/turborepo#13522</a></li>
<li>fix: Accept semver ranges in devEngines.packageManager.version by <a
href="https://github.com/bangseongbeom"><code>@​bangseongbeom</code></a>
in <a
href="https://redirect.github.com/vercel/turborepo/pull/13623">vercel/turborepo#13623</a></li>
<li>docs: Explain affected package invalidation reasons by <a
href="https://github.com/ghoullier"><code>@​ghoullier</code></a> in <a
href="https://redirect.github.com/vercel/turborepo/pull/13594">vercel/turborepo#13594</a></li>
<li>perf(lockfiles): Borrow field-name scalars in the pnpm fast parser
by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13648">vercel/turborepo#13648</a></li>
<li>perf(repository): Avoid discarded alias allocation in Relationship
by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13650">vercel/turborepo#13650</a></li>
<li>perf(lockfiles): Drop redundant human_name clone for pnpm v7/v9 by
<a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a>
in <a
href="https://redirect.github.com/vercel/turborepo/pull/13649">vercel/turborepo#13649</a></li>
<li>perf: Index workspace nodes by name in project_relationships by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13647">vercel/turborepo#13647</a></li>
<li>perf: Share resolution identity lists across identical workspace
closures by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13641">vercel/turborepo#13641</a></li>
<li>docs: Fix duplicated word in runtime dependencies guide summary by
<a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a>
in <a
href="https://redirect.github.com/vercel/turborepo/pull/13630">vercel/turborepo#13630</a></li>
<li>refactor: Remove turborepo-lsp dependency on turborepo-lib by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13631">vercel/turborepo#13631</a></li>
<li>perf: Index Bun nested lockfile entries by name for fallback
resolution by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13633">vercel/turborepo#13633</a></li>
<li>perf: Memoize framework inference per package during task hashing by
<a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a>
in <a
href="https://redirect.github.com/vercel/turborepo/pull/13634">vercel/turborepo#13634</a></li>
<li>perf: Avoid materializing transient declarations in
external_dependencies by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13646">vercel/turborepo#13646</a></li>
<li>perf: Enable shared closure DP for npm and yarn1 lockfiles by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13635">vercel/turborepo#13635</a></li>
<li>perf: Parse pnpm explicit-key entries in the lockfile fast path by
<a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a>
in <a
href="https://redirect.github.com/vercel/turborepo/pull/13640">vercel/turborepo#13640</a></li>
<li>perf: Parallelize resolution fingerprint hashing by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13642">vercel/turborepo#13642</a></li>
<li>perf: Build resolution identity lists in parallel by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13643">vercel/turborepo#13643</a></li>
<li>perf: Intern resolution identities as Arc&lt;str&gt; across closures
by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13645">vercel/turborepo#13645</a></li>
<li>fix: Compose affected tasks with package filters by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13656">vercel/turborepo#13656</a></li>
<li>docs: Explain worktree cache path isolation by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13657">vercel/turborepo#13657</a></li>
<li>fix: Upgrade brace-expansion to 5.0.9 by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13658">vercel/turborepo#13658</a></li>
<li>docs: Correct verified inaccuracies in the Turborepo Agent Skill by
<a href="https://github.com/charpeni"><code>@​charpeni</code></a> in <a
href="https://redirect.github.com/vercel/turborepo/pull/13644">vercel/turborepo#13644</a></li>
<li>chore: Update Next.js to 16.3.0 by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13659">vercel/turborepo#13659</a></li>
<li>fix: Don't use <code>eprintln!</code> in the panic hook by <a
href="https://github.com/molofsky"><code>@​molofsky</code></a> in <a
href="https://redirect.github.com/vercel/turborepo/pull/13637">vercel/turborepo#13637</a></li>
<li>fix: Invalidate only when Git ignore sources change by <a
href="https://github.com/smasato"><code>@​smasato</code></a> in <a
href="https://redirect.github.com/vercel/turborepo/pull/13632">vercel/turborepo#13632</a></li>
<li>docs: Update Geistdocs to 1.19.4 by <a
href="https://github.com/christopherkindl"><code>@​christopherkindl</code></a>
in <a
href="https://redirect.github.com/vercel/turborepo/pull/13680">vercel/turborepo#13680</a></li>
<li>docs: Exclude Turborepo from its own OSS products menu by <a
href="https://github.com/christopherkindl"><code>@​christopherkindl</code></a>
in <a
href="https://redirect.github.com/vercel/turborepo/pull/13681">vercel/turborepo#13681</a></li>
<li>docs: Use the geistdocs Turborepo logo in the navbar by <a
href="https://github.com/christopherkindl"><code>@​christopherkindl</code></a>
in <a
href="https://redirect.github.com/vercel/turborepo/pull/13682">vercel/turborepo#13682</a></li>
<li>docs: Update redirected vercel.com/nextjs.org links to current
targets by <a
href="https://github.com/molebox"><code>@​molebox</code></a> in <a
href="https://redirect.github.com/vercel/turborepo/pull/13685">vercel/turborepo#13685</a></li>
<li>refactor: Generalize native command arguments by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13664">vercel/turborepo#13664</a></li>
<li>refactor: Move native contracts to tasks by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13665">vercel/turborepo#13665</a></li>
<li>docs: Fix loadTransformers reference in turbo-codemod README by <a
href="https://github.com/latent-9"><code>@​latent-9</code></a> in <a
href="https://redirect.github.com/vercel/turborepo/pull/13683">vercel/turborepo#13683</a></li>
<li>refactor: Model native task execution explicitly by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13666">vercel/turborepo#13666</a></li>
<li>feat: Compose aggregate native task dependencies by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13667">vercel/turborepo#13667</a></li>
<li>fix: Respect aggregate task overrides by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13668">vercel/turborepo#13668</a></li>
<li>test: Stabilize watch task inputs regression test by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13686">vercel/turborepo#13686</a></li>
<li>feat: Parse Python quality tool declarations by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13669">vercel/turborepo#13669</a></li>
<li>feat: Resolve Python quality plans by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13670">vercel/turborepo#13670</a></li>
<li>refactor: Extract uv native task specs by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13671">vercel/turborepo#13671</a></li>
<li>feat: Synthesize Python quality tasks by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13672">vercel/turborepo#13672</a></li>
<li>test: Cover Python quality task commands by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13673">vercel/turborepo#13673</a></li>
<li>feat: Hash Python quality task inputs by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13674">vercel/turborepo#13674</a></li>
<li>test: Cover Python quality task graph by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13675">vercel/turborepo#13675</a></li>
<li>chore: Release Turborepo 2.10.9-canary.1 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/13687">vercel/turborepo#13687</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vercel/turborepo/commit/33237d4be13d7b74768c2cf3353b19cfa8d1af7c"><code>33237d4</code></a>
publish 2.10.9 to registry</li>
<li><a
href="https://github.com/vercel/turborepo/commit/3b0e57f1289b2a6b3d6dd402bce928469d3b25fa"><code>3b0e57f</code></a>
fix: Prevent Windows process cleanup PID reuse (<a
href="https://redirect.github.com/vercel/turborepo/issues/13695">#13695</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/efe4e1bdf665f2950cf89d7968907de36c2f0737"><code>efe4e1b</code></a>
fix: Prune Bun wildcard workspace dev dependencies (<a
href="https://redirect.github.com/vercel/turborepo/issues/13694">#13694</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/a98e5cde97796088c6107684a64a40a967cd1ef0"><code>a98e5cd</code></a>
docs: Document dependency-driven Python tasks (<a
href="https://redirect.github.com/vercel/turborepo/issues/13676">#13676</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/c09a92f526b6dca9ea0243922f680803779759cd"><code>c09a92f</code></a>
chore: Release Turborepo 2.10.9-canary.1 (<a
href="https://redirect.github.com/vercel/turborepo/issues/13687">#13687</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/09bd548dddbff2a29086bdef7cb07b02d5e5458a"><code>09bd548</code></a>
test: Cover Python quality task graph (<a
href="https://redirect.github.com/vercel/turborepo/issues/13675">#13675</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/3584a5fb8edac9efc826fdea57e92088505fc76a"><code>3584a5f</code></a>
feat: Hash Python quality task inputs (<a
href="https://redirect.github.com/vercel/turborepo/issues/13674">#13674</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/0d43ff3cbf5ac8873c646a84b2fd7ae53097e08d"><code>0d43ff3</code></a>
test: Cover Python quality task commands (<a
href="https://redirect.github.com/vercel/turborepo/issues/13673">#13673</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/94708adc6bc19b41805741cc5a15ac5467a481cf"><code>94708ad</code></a>
feat: Synthesize Python quality tasks (<a
href="https://redirect.github.com/vercel/turborepo/issues/13672">#13672</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/e14f04ec6c2dc2791b0a3beb32df7515b31b3d4b"><code>e14f04e</code></a>
refactor: Extract uv native task specs (<a
href="https://redirect.github.com/vercel/turborepo/issues/13671">#13671</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vercel/turborepo/compare/v2.10.8...v2.10.9">compare
view</a></li>
</ul>
</details>
<br />

Updates `chrome-devtools-mcp` from 1.6.0 to 1.7.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/releases">chrome-devtools-mcp's
releases</a>.</em></p>
<blockquote>
<h2>chrome-devtools-mcp: v1.7.0</h2>
<h2><a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/compare/chrome-devtools-mcp-v1.6.0...chrome-devtools-mcp-v1.7.0">1.7.0</a>
(2026-08-10)</h2>
<h3>🎉 Features</h3>
<ul>
<li>add a utility function to check for localhost. (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2454">#2454</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/c5ebf9e2023ec37c77d2ee355a345249ac91d192">c5ebf9e</a>)</li>
<li>Add get_heapsnapshot_object_details MCP tool (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2374">#2374</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/8432cb97a2a18f48afcb542f27dd88d7e5a11f36">8432cb9</a>)</li>
<li>Emit native contexts in snapshot summary (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2375">#2375</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/f78a911dc0ce843b08549560d0357712d3b18609">f78a911</a>)</li>
<li>Filter heap snapshot objects by native context (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2377">#2377</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/76fd2424984827802867672fcc8d0e0036f4a3af">76fd242</a>)</li>
<li><strong>telemetry:</strong> log devtools data. (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2460">#2460</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/df2c753006ce77cdc8df8c7715d0b5c6675560d4">df2c753</a>)</li>
<li><strong>telemetry:</strong> log is_devtools_open with each tool
call. (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2445">#2445</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/6f60eabf59dd197bcad244846ea5bbdd2e172286">6f60eab</a>)</li>
<li><strong>telemetry:</strong> report whether tool call is made on
localhost. (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2455">#2455</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/6398b7e9a4ee91e50a1f1fd31aee45b0a80b14e4">6398b7e</a>)</li>
<li>update lighthouse to 13.4.1 (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2398">#2398</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/745ffe7132f8de97cba58b10e6501427fe254cfc">745ffe7</a>)</li>
</ul>
<h3>🛠️ Fixes</h3>
<ul>
<li>bound per-navigation network request retention (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2435">#2435</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/b08c73c8d8887813fdf358e81a43925b84ef10e4">b08c73c</a>)</li>
<li><strong>cli:</strong> validate session ids (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2475">#2475</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/5ca9121d1805ba11215ddc36d6fb18d40403c1fc">5ca9121</a>)</li>
<li><strong>cli:</strong> warn about version mismatch between cli and
daemon (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2461">#2461</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/3afc44dac95757fcaa94e0e9296594bdf2ec97d1">3afc44d</a>)</li>
<li><strong>daemon:</strong> preserve hyphenated browser flags in arg
serialization and lazy daemon startup (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2405">#2405</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/d79f3ba24f3c38f7391ea7c9d886f9f7f404743c">d79f3ba</a>)</li>
<li>dispose heap snapshot workers on context teardown (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2428">#2428</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/f245c760570680fd808c8c034d138cf4a5c699e0">f245c76</a>)</li>
<li>do not throw synchronously when a CDP session is gone (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2466">#2466</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/ba4fe3eaa4c20e4e32ef6af3b78b4d9d9bbdc1d2">ba4fe3e</a>)</li>
<li>don't throw if Dialog was handled (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2437">#2437</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/574c3207ac5376f104960c5ba425dc4a2e0e3232">574c320</a>)</li>
<li>downscale viewport screenshots when no viewport is emulated (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2380">#2380</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/39c4140f119307bf9b4253ab368512a3aab6ebfc">39c4140</a>)</li>
<li>improve daemon lifecycle (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2360">#2360</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/3ee6a2710029f3718792da634c048bf4de90eaa6">3ee6a27</a>)</li>
<li>improve file writing (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2447">#2447</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/1da4bb06e2e598ec9cab9158e8d818aa8a344dc4">1da4bb0</a>)</li>
<li>include the tab id in <code>get_tab_id</code>'s text response (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2381">#2381</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/dcbaf495183a34d9bb0e3d9e8f3e566de6b425f8">dcbaf49</a>)</li>
<li><strong>memory:</strong> dispose the heap-snapshot worker when
loading fails (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2449">#2449</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/744738deaaa93e931628b8c42a38a317d0ae3c93">744738d</a>)</li>
<li><strong>performance:</strong> reset trace-running flag when
start_trace setup fails (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2420">#2420</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/40240c033f8ef91596b16e1b5b53974b385f8b5d">40240c0</a>)</li>
<li>regression after the <a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2443">#2443</a>
(<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2462">#2462</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/4c80ce46f3a456cbbc379a569506bcf44fc2bc48">4c80ce4</a>)</li>
<li>rename maxRetainedSize column (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2402">#2402</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/75c7048c80033d1826352f5f4464427e4235a526">75c7048</a>)</li>
<li><strong>screenshot:</strong> dispose element handle after
take_screenshot (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2422">#2422</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/fffb40e58bd5f7ff7e7110f07238b93d56f390ec">fffb40e</a>)</li>
<li>toggle lazy loading for source maps. (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2486">#2486</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/8028bfe3abaecb67422530d05327c5ec72c53753">8028bfe</a>)</li>
<li><strong>wait:</strong> avoid 180s mutex stall when a dialog opens
during an action (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2427">#2427</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/b4e8f74ae5da327a5968c4836d9f5450a3bc2532">b4e8f74</a>)</li>
</ul>
<h3>📄 Documentation</h3>
<ul>
<li>Add devin cli install instruction to README (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2361">#2361</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/45262c0a5ca433e4d9d5700e3c1e006ac41f45f5">45262c0</a>)</li>
<li>correct the user data directory documentation (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2473">#2473</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/5ddbffd0f364ecd073f4d42a56109950b1421a57">5ddbffd</a>)</li>
<li><strong>skills:</strong> update memory leak debugging skill to use
native MCP tools (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2436">#2436</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/99bd90a7881bea5161d4e6b5ab6da26c2a9a3721">99bd90a</a>)</li>
<li>Update Chrome requirement for categoryExperimentalWebmcp (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2163">#2163</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/354458e23ffd2d1aaaaf1486abb6eb793394797d">354458e</a>)</li>
<li>update security.md (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2362">#2362</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/5012b077997618edeb2291d39d17553280f5b2a6">5012b07</a>)</li>
</ul>
<h3>🏗️ Refactor</h3>
<ul>
<li>clean up McpResponse.handle (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2392">#2392</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/348975d808aa0bb1f8a7795df36aa3ff738d6d42">348975d</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/blob/main/CHANGELOG.md">chrome-devtools-mcp's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/compare/chrome-devtools-mcp-v1.6.0...chrome-devtools-mcp-v1.7.0">1.7.0</a>
(2026-08-10)</h2>
<h3>🎉 Features</h3>
<ul>
<li>add a utility function to check for localhost. (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2454">#2454</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/c5ebf9e2023ec37c77d2ee355a345249ac91d192">c5ebf9e</a>)</li>
<li>Add get_heapsnapshot_object_details MCP tool (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2374">#2374</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/8432cb97a2a18f48afcb542f27dd88d7e5a11f36">8432cb9</a>)</li>
<li>Emit native contexts in snapshot summary (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2375">#2375</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/f78a911dc0ce843b08549560d0357712d3b18609">f78a911</a>)</li>
<li>Filter heap snapshot objects by native context (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2377">#2377</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/76fd2424984827802867672fcc8d0e0036f4a3af">76fd242</a>)</li>
<li><strong>telemetry:</strong> log devtools data. (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2460">#2460</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/df2c753006ce77cdc8df8c7715d0b5c6675560d4">df2c753</a>)</li>
<li><strong>telemetry:</strong> log is_devtools_open with each tool
call. (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2445">#2445</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/6f60eabf59dd197bcad244846ea5bbdd2e172286">6f60eab</a>)</li>
<li><strong>telemetry:</strong> report whether tool call is made on
localhost. (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2455">#2455</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/6398b7e9a4ee91e50a1f1fd31aee45b0a80b14e4">6398b7e</a>)</li>
<li>update lighthouse to 13.4.1 (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2398">#2398</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/745ffe7132f8de97cba58b10e6501427fe254cfc">745ffe7</a>)</li>
</ul>
<h3>🛠️ Fixes</h3>
<ul>
<li>bound per-navigation network request retention (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2435">#2435</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/b08c73c8d8887813fdf358e81a43925b84ef10e4">b08c73c</a>)</li>
<li><strong>cli:</strong> validate session ids (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2475">#2475</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/5ca9121d1805ba11215ddc36d6fb18d40403c1fc">5ca9121</a>)</li>
<li><strong>cli:</strong> warn about version mismatch between cli and
daemon (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2461">#2461</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/3afc44dac95757fcaa94e0e9296594bdf2ec97d1">3afc44d</a>)</li>
<li><strong>daemon:</strong> preserve hyphenated browser flags in arg
serialization and lazy daemon startup (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2405">#2405</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/d79f3ba24f3c38f7391ea7c9d886f9f7f404743c">d79f3ba</a>)</li>
<li>dispose heap snapshot workers on context teardown (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2428">#2428</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/f245c760570680fd808c8c034d138cf4a5c699e0">f245c76</a>)</li>
<li>do not throw synchronously when a CDP session is gone (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2466">#2466</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/ba4fe3eaa4c20e4e32ef6af3b78b4d9d9bbdc1d2">ba4fe3e</a>)</li>
<li>don't throw if Dialog was handled (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2437">#2437</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/574c3207ac5376f104960c5ba425dc4a2e0e3232">574c320</a>)</li>
<li>downscale viewport screenshots when no viewport is emulated (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2380">#2380</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/39c4140f119307bf9b4253ab368512a3aab6ebfc">39c4140</a>)</li>
<li>improve daemon lifecycle (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2360">#2360</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/3ee6a2710029f3718792da634c048bf4de90eaa6">3ee6a27</a>)</li>
<li>improve file writing (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2447">#2447</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/1da4bb06e2e598ec9cab9158e8d818aa8a344dc4">1da4bb0</a>)</li>
<li>include the tab id in <code>get_tab_id</code>'s text response (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2381">#2381</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/dcbaf495183a34d9bb0e3d9e8f3e566de6b425f8">dcbaf49</a>)</li>
<li><strong>memory:</strong> dispose the heap-snapshot worker when
loading fails (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2449">#2449</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/744738deaaa93e931628b8c42a38a317d0ae3c93">744738d</a>)</li>
<li><strong>performance:</strong> reset trace-running flag when
start_trace setup fails (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2420">#2420</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/40240c033f8ef91596b16e1b5b53974b385f8b5d">40240c0</a>)</li>
<li>regression after the <a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2443">#2443</a>
(<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2462">#2462</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/4c80ce46f3a456cbbc379a569506bcf44fc2bc48">4c80ce4</a>)</li>
<li>rename maxRetainedSize column (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2402">#2402</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/75c7048c80033d1826352f5f4464427e4235a526">75c7048</a>)</li>
<li><strong>screenshot:</strong> dispose element handle after
take_screenshot (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2422">#2422</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/fffb40e58bd5f7ff7e7110f07238b93d56f390ec">fffb40e</a>)</li>
<li>toggle lazy loading for source maps. (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2486">#2486</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/8028bfe3abaecb67422530d05327c5ec72c53753">8028bfe</a>)</li>
<li><strong>wait:</strong> avoid 180s mutex stall when a dialog opens
during an action (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2427">#2427</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/b4e8f74ae5da327a5968c4836d9f5450a3bc2532">b4e8f74</a>)</li>
</ul>
<h3>📄 Documentation</h3>
<ul>
<li>Add devin cli install instruction to README (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2361">#2361</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/45262c0a5ca433e4d9d5700e3c1e006ac41f45f5">45262c0</a>)</li>
<li>correct the user data directory documentation (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2473">#2473</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/5ddbffd0f364ecd073f4d42a56109950b1421a57">5ddbffd</a>)</li>
<li><strong>skills:</strong> update memory leak debugging skill to use
native MCP tools (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2436">#2436</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/99bd90a7881bea5161d4e6b5ab6da26c2a9a3721">99bd90a</a>)</li>
<li>Update Chrome requirement for categoryExperimentalWebmcp (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2163">#2163</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/354458e23ffd2d1aaaaf1486abb6eb793394797d">354458e</a>)</li>
<li>update security.md (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2362">#2362</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/5012b077997618edeb2291d39d17553280f5b2a6">5012b07</a>)</li>
</ul>
<h3>🏗️ Refactor</h3>
<ul>
<li>clean up McpResponse.handle (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2392">#2392</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/348975d808aa0bb1f8a7795df36aa3ff738d6d42">348975d</a>)</li>
<li>introduce Explicit resouce managent (using) (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2443">#2443</a>)
(<a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/5b25370c9cd779032c3c9dc9880eca7031c73005">5b25370</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/774d78f5eef5e610407a0c92fa6ec5ed74b027e8"><code>774d78f</code></a>
chore(main): release chrome-devtools-mcp 1.7.0 (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2363">#2363</a>)</li>
<li><a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/5ddbffd0f364ecd073f4d42a56109950b1421a57"><code>5ddbffd</code></a>
docs: correct the user data directory documentation (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2473">#2473</a>)</li>
<li><a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/8028bfe3abaecb67422530d05327c5ec72c53753"><code>8028bfe</code></a>
fix: toggle lazy loading for source maps. (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2486">#2486</a>)</li>
<li><a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/d1e4d711aa520c67df045a2f805380e9b3307abd"><code>d1e4d71</code></a>
chore(deps): bump sigstore/cosign-installer from 4.1.0 to 4.1.2 in the
all gr...</li>
<li><a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/744738deaaa93e931628b8c42a38a317d0ae3c93"><code>744738d</code></a>
fix(memory): dispose the heap-snapshot worker when loading fails (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2449">#2449</a>)</li>
<li><a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/ca66d0f321a57473ae400fa5e82842d4bbffe210"><code>ca66d0f</code></a>
chore(dev-deps): bump devtools-frontend (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2498">#2498</a>)</li>
<li><a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/2f375c7e592d15ee9d0e1d665a4600a8b20879d0"><code>2f375c7</code></a>
chore: fix Explicit resource management polyfill (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2496">#2496</a>)</li>
<li><a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/830f78b8ce19f8ee1e1d8c4d812bd9d6e4f48c2f"><code>830f78b</code></a>
chore: re-use connection adapter and dispose devtools unvierse (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2465">#2465</a>)</li>
<li><a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/4c96dca1f19711a80308bd0d608fb8d40e29d152"><code>4c96dca</code></a>
ci: add main branch (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2497">#2497</a>)</li>
<li><a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/commit/71d897b27e7936c1a8911d053e19d92ec2c46655"><code>71d897b</code></a>
chore: add a new profiler scenario for get_console_messages. (<a
href="https://redirect.github.com/ChromeDevTools/chrome-devtools-mcp/issues/2491">#2491</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/ChromeDevTools/chrome-devtools-mcp/compare/chrome-devtools-mcp-v1.6.0...chrome-devtools-mcp-v1.7.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `@earendil-works/pi-coding-agent` from 0.83.0 to 0.84.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/earendil-works/pi/releases">@​earendil-works/pi-coding-agent's
releases</a>.</em></p>
<blockquote>
<h2>v0.84.1</h2>
<h3>New Features</h3>
<ul>
<li><strong>Qwen Token Plan Individual</strong> — Use the built-in
provider for models documented for Individual subscriptions. See <a
href="https://github.com/earendil-works/pi/blob/v0.84.1/packages/coding-agent/docs/providers.md#api-keys">API
Keys</a>.</li>
<li><strong>Authentication readiness checks</strong> — Use <code>pi auth
check</code> to verify provider or model credentials, optionally
emitting the resolved credential.</li>
<li><strong>Improved fullscreen interaction</strong> — Select words and
paragraphs with multiple clicks and configure half-page transcript
scrolling. See <a
href="https://github.com/earendil-works/pi/blob/v0.84.1/packages/coding-agent/docs/keybindings.md#tui-fullscreen-viewport">TUI
Fullscreen Viewport</a>.</li>
<li><strong>Terminating blocked tool calls</strong> — Extension
<code>tool_call</code> handlers can stop all-terminating batches without
another model call. See <a
href="https://github.com/earendil-works/pi/blob/v0.84.1/packages/coding-agent/docs/extensions.md#tool-events">Tool
Events</a>.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added Qwen Token Plan Individual as a built-in provider with its
documented subscription model catalog and the shared international
<code>QWEN_TOKEN_PLAN_API_KEY</code>. See <a
href="https://github.com/earendil-works/pi/blob/v0.84.1/packages/coding-agent/docs/providers.md#api-keys">API
Keys</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7659">#7659</a>
by <a
href="https://github.com/arasovic"><code>@​arasovic</code></a>).</li>
<li>Added <code>pi auth check</code> provider/model auth preflight with
optional credential output (<a
href="https://redirect.github.com/earendil-works/pi/issues/7152">#7152</a>).</li>
<li>Added <code>terminate</code> support to blocked extension
<code>tool_call</code> events so all-terminating batches can skip the
automatic follow-up model call. See <a
href="https://github.com/earendil-works/pi/blob/v0.84.1/packages/coding-agent/docs/extensions.md#tool-events">Tool
Events</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7715">#7715</a>
by <a href="https://github.com/muyiyr"><code>@​muyiyr</code></a>).</li>
<li>Added inherited double-click word and whitespace selection,
granularity-aware drag selection, and triple-click paragraph selection
in fullscreen mode (<a
href="https://redirect.github.com/earendil-works/pi/issues/7725">#7725</a>,
<a
href="https://redirect.github.com/earendil-works/pi/pull/7733">#7733</a>
by <a href="https://github.com/volsa"><code>@​volsa</code></a>).</li>
<li>Added inherited unbound half-page transcript scrolling actions for
fullscreen mode. See <a
href="https://github.com/earendil-works/pi/blob/v0.84.1/packages/coding-agent/docs/keybindings.md#tui-fullscreen-viewport">TUI
Fullscreen Viewport</a> (<a
href="https://redirect.github.com/earendil-works/pi/issues/7735">#7735</a>).</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Softened the bash tool's <code>PI_*</code> environment guideline in
an attempt to reduce unnecessary inspection commands (<a
href="https://redirect.github.com/earendil-works/pi/issues/7128">#7128</a>).</li>
<li>Reduced worst-case automatic terminal theme detection delay from 200
ms to 100 ms by probing color-scheme and background support
concurrently.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed Bun standalone binaries crashing on startup when the cwd
contains a <code>bunfig.toml</code> with <code>preload</code> by
compiling with <code>--no-compile-autoload-bunfig</code> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7685">#7685</a>
by <a
href="https://github.com/geril07"><code>@​geril07</code></a>).</li>
<li>Fixed extension TUI method wrappers recursing indefinitely when
delegating to the original method (<a
href="https://redirect.github.com/earendil-works/pi/issues/7731">#7731</a>).</li>
<li>Fixed right-click not pasting clipboard text in fullscreen mode on
Windows.</li>
<li>Fixed inherited <code>Agent.reset()</code> clearing transcript and
runtime state during active runs; it now rejects until the agent is idle
(<a
href="https://redirect.github.com/earendil-works/pi/pull/7717">#7717</a>
by <a
href="https://github.com/wesleyzhangwq"><code>@​wesleyzhangwq</code></a>).</li>
<li>Fixed inherited LaTeX relation, multiplication, and named-operator
spacing, and matrix composition with stacked fractions, operator limits,
and adjacent matrices.</li>
<li>Reduced inherited fullscreen mouse event volume under tmux, Zellij,
and GNU Screen by using button-motion tracking instead of all-motion
tracking.</li>
</ul>
<h2>v0.84.0</h2>
<h3>New Features</h3>
<ul>
<li><strong>Fullscreen TUI mode</strong> — Switch between regular and
fullscreen modes at runtime, with a sticky editor and footer,
independently scrollable transcript, and draggable scrollbars. See <a
href="https://github.com/earendil-works/pi/blob/v0.84.0/packages/coding-agent/docs/settings.md#ui--display">UI
&amp; Display</a>.</li>
<li><strong>Mermaid and LaTeX rendering</strong> — Render Mermaid
diagrams and terminal-friendly Unicode math in interactive transcripts.
See <a
href="https://github.com/earendil-works/pi/blob/v0.84.0/packages/coding-agent/docs/settings.md#markdown">Markdown
settings</a> and <a
href="https://github.com/earendil-works/pi/blob/v0.84.0/packages/tui/README.md#markdown">TUI
Markdown</a>.</li>
<li><strong>Per-directory context overrides</strong> — Use
<code>AGENTS.override.md</code> to replace context files for a specific
directory. See <a
href="https://github.com/earendil-works/pi/blob/v0.84.0/packages/coding-agent/docs/usage.md#context-files">Context
Files</a>.</li>
<li><strong>Advanced custom model sampling</strong> — Configure
arbitrary OpenAI-compatible <code>samplingParams</code> and opt-in vLLM
<code>thinking_token_budget</code> values. See <a
href="https://github.com/earendil-works/pi/blob/v0.84.0/packages/coding-agent/docs/models.md#sampling-parameters">Sampling
Parameters</a>.</li>
<li><strong>Baseten provider</strong> — Use built-in Baseten
authentication and model support. See <a
href="https://github.com/earendil-works/pi/blob/v0.84.0/packages/coding-agent/docs/providers.md#api-keys">API
Keys</a>.</li>
</ul>
<h3>Breaking Changes</h3>
<ul>
<li>
<p>Renamed the inherited pi-ai <code>ModelsStreamTransforms</code>
interface to <code>ModelsRequestTransforms</code> because its header
transformation now applies to all authenticated provider requests.</p>
</li>
<li>
<p>Changed JSON and RPC <code>message_update</code> events to emit only
<code>assistantMessageEvent</code> deltas, removing the cumulative
<code>message</code> and <code>assistantMessageEvent.partial</code>
fields that caused quadratic output growth. Clients that need partial
messages must assemble deltas between <code>message_start</code> and
<code>message_end</code>; the latter remains authoritative (<a
href="https://redirect.github.com/earendil-works/pi/issues/7290">#7290</a>).</p>
</li>
<li>
<p><code>ModelRegistry.getApiKeyAndHeaders()</code> now returns
<code>ProviderHeaders</code> with <code>string | null</code> values and
preserves <code>null</code> header-deletion markers. Extensions that
inspect returned headers must handle <code>null</code>; extensions
forwarding them to pi-ai streams should pass them through unchanged.
This prevents placeholder OpenAI credentials from being sent through
Cloudflare AI Gateway (<a
href="https://redirect.github.com/earendil-works/pi/issues/7030">#7030</a>).</p>
</li>
<li>
<p>Changed <code>ModelRegistry.refresh()</code> to accept
<code>ModelsRefreshOptions</code> and return
<code>ModelsRefreshResult</code> instead of discarding cancellation and
provider errors.</p>
</li>
<li>
<p>Changed <code>ModelRuntime.setRuntimeApiKey()</code> to accept auth
cancellation options rather than catalog refresh options. Call
<code>refresh({ providers: [providerId], signal })</code> separately
when remote freshness is required.</p>
</li>
<li>
<p>Required config-form extension OAuth <code>refreshToken(credentials,
signal)</code> callbacks to accept and honor a concrete abort
signal.</p>
</li>
<li>
<p>Replaced dynamic provider refresh context store access with the
read-only <code>context.stored</code> snapshot and generation-checked
<code>context.publish()</code> transaction.</p>
<p><strong>Providers built with <code>createProvider({ fetchModels
})</code>:</strong> no catalog-publication migration is required. Before
and after, return the fetched models and register the resulting
provider; <code>createProvider()</code> owns restoration, persistence,
and in-memory publication.</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/CHANGELOG.md">@​earendil-works/pi-coding-agent's
changelog</a>.</em></p>
<blockquote>
<h2>[0.84.1] - 2026-08-07</h2>
<h3>New Features</h3>
<ul>
<li><strong>Qwen Token Plan Individual</strong> — Use the built-in
provider for models documented for Individual subscriptions. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/providers.md#api-keys">API
Keys</a>.</li>
<li><strong>Authentication readiness checks</strong> — Use <code>pi auth
check</code> to verify provider or model credentials, optionally
emitting the resolved credential.</li>
<li><strong>Improved fullscreen interaction</strong> — Select words and
paragraphs with multiple clicks and configure half-page transcript
scrolling. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/keybindings.md#tui-fullscreen-viewport">TUI
Fullscreen Viewport</a>.</li>
<li><strong>Terminating blocked tool calls</strong> — Extension
<code>tool_call</code> handlers can stop all-terminating batches without
another model call. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/extensions.md#tool-events">Tool
Events</a>.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added Qwen Token Plan Individual as a built-in provider with its
documented subscription model catalog and the shared international
<code>QWEN_TOKEN_PLAN_API_KEY</code>. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/providers.md#api-keys">API
Keys</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7659">#7659</a>
by <a
href="https://github.com/arasovic"><code>@​arasovic</code></a>).</li>
<li>Added <code>pi auth check</code> provider/model auth preflight with
optional credential output (<a
href="https://redirect.github.com/earendil-works/pi/issues/7152">#7152</a>).</li>
<li>Added <code>terminate</code> support to blocked extension
<code>tool_call</code> events so all-terminating batches can skip the
automatic follow-up model call. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/extensions.md#tool-events">Tool
Events</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7715">#7715</a>
by <a href="https://github.com/muyiyr"><code>@​muyiyr</code></a>).</li>
<li>Added inherited double-click word and whitespace selection,
granularity-aware drag selection, and triple-click paragraph selection
in fullscreen mode (<a
href="https://redirect.github.com/earendil-works/pi/issues/7725">#7725</a>,
<a
href="https://redirect.github.com/earendil-works/pi/pull/7733">#7733</a>
by <a href="https://github.com/volsa"><code>@​volsa</code></a>).</li>
<li>Added inherited unbound half-page transcript scrolling actions for
fullscreen mode. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/keybindings.md#tui-fullscreen-viewport">TUI
Fullscreen Viewport</a> (<a
href="https://redirect.github.com/earendil-works/pi/issues/7735">#7735</a>).</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Softened the bash tool's <code>PI_*</code> environment guideline in
an attempt to reduce unnecessary inspection commands (<a
href="https://redirect.github.com/earendil-works/pi/issues/7128">#7128</a>).</li>
<li>Reduced worst-case automatic terminal theme detection delay from 200
ms to 100 ms by probing color-scheme and background support
concurrently.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed Bun standalone binaries crashing on startup when the cwd
contains a <code>bunfig.toml</code> with <code>preload</code> by
compiling with <code>--no-compile-autoload-bunfig</code> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7685">#7685</a>
by <a
href="https://github.com/geril07"><code>@​geril07</code></a>).</li>
<li>Fixed extension TUI method wrappers recursing indefinitely when
delegating to the original method (<a
href="https://redirect.github.com/earendil-works/pi/issues/7731">#7731</a>).</li>
<li>Fixed right-click not pasting clipboard text in fullscreen mode on
Windows.</li>
<li>Fixed inherited <code>Agent.reset()</code> clearing transcript and
runtime state during active runs; it now rejects until the agent is idle
(<a
href="https://redirect.github.com/earendil-works/pi/pull/7717">#7717</a>
by <a
href="https://github.com/wesleyzhangwq"><code>@​wesleyzhangwq</code></a>).</li>
<li>Fixed inherited LaTeX relation, multiplication, and named-operator
spacing, and matrix composition with stacked fractions, operator limits,
and adjacent matrices.</li>
<li>Reduced inherited fullscreen mouse event volume under tmux, Zellij,
and GNU Screen by using button-motion tracking instead of all-motion
tracking.</li>
</ul>
<h2>[0.84.0] - 2026-08-06</h2>
<h3>New Features</h3>
<ul>
<li><strong>Fullscreen TUI mode</strong> — Switch between regular and
fullscreen modes at runtime, with a sticky editor and footer,
independently scrollable transcript, and draggable scrollbars. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/settings.md#ui-display">UI
&amp; Display</a>.</li>
<li><strong>Mermaid and LaTeX rendering</strong> — Render Mermaid
diagrams and terminal-friendly Unicode math in interactive transcripts.
See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/settings.md#markdown">Markdown
settings</a> and <a
href="https://github.com/earendil-works/pi/blob/main/packages/tui/README.md#markdown">TUI
Markdown</a>.</li>
<li><strong>Per-directory context overrides</strong> — Use
<code>AGENTS.override.md</code> to replace context files for a specific
directory. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/usage.md#context-files">Context
Files</a>.</li>
<li><strong>Advanced custom model sampling</strong> — Configure
arbitrary OpenAI-compatible <code>samplingParams</code> and opt-in vLLM
<code>thinking_token_budget</code> values. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/models.md#sampling-parameters">Sampling
Parameters</a>.</li>
<li><strong>Baseten provider</strong> — Use built-in Baseten
authentication and model support. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/providers.md#api-keys">API
Keys</a>.</li>
</ul>
<h3>Breaking Changes</h3>
<ul>
<li>Renamed the inherited pi-ai <code>ModelsStreamTransforms</code>
interface to <code>ModelsRequestTransforms</code> because its header
transformation now applies to all authenticated provider requests.</li>
<li>Changed JSON and RPC <code>message_update</code> events to emit only
<code>assistantMessageEvent</code> deltas, removing the cumulative
<code>message</code> and <code>assistantMessageEvent.partial</code>
fields that caused quadratic output growth. Clients that need partial
messages must assemble deltas between <code>message_start</code> and
<code>message_end</code>; the latter remains authoritative (<a
href="https://redirect.github.com/earendil-works/pi/issues/7290">#7290</a>).</li>
<li><code>ModelRegistry.getApiKeyAndHeaders()</code> now returns
<code>ProviderHeaders</code> with <code>string | null</code> values and
preserves <code>null</code> header-deletion markers. Extensions that
inspect returned headers must handle <code>null</code>; extensions
forwarding them to pi-ai streams should pass them through unchanged.
This prevents placeholder OpenAI credentials from being sent through
Cloudflare AI Gateway (<a
href="https://redirect.github.com/earendil-works/pi/issues/7030">#7030</a>).</li>
<li>Changed <code>ModelRegistry.refresh()</code> to accept
<code>ModelsRefreshOptions</code> and return
<code>ModelsRefreshResult</code> instead of discarding cancellation and
provider errors.</li>
<li>Changed <code>ModelRuntime.setRuntimeApiKey()</code> to accept auth
cancellation options rather than catalog refresh options. Call
<code>refresh({ providers: [providerId], signal })</code> separately
when remote freshness is required.</li>
<li>Required config-form extension OAuth <code>refreshToken(credentials,
signal)</code> callbacks to accept and honor a concrete abort
signal.</li>
<li>Replaced dynamic provider refresh context store access with the
read-only <code>context.stored</code> snapshot and generation-checked
<code>context.publish()</code> transac...

_Description has been truncated_

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-17 18:57:12 +02:00
Alberto Schiabel 8086ef02cb fix(examples): align Python and TypeScript examples with current backend (#4107)
## Summary

- Repairs runnable TypeScript and Python examples for current backend
requirements, including authenticated MCP endpoints, current transports,
valid tool identifiers, provider limits, and resource uniqueness.
- Replaces placeholder resource IDs with explicit `COMPOSIO_EXAMPLES_*`
configuration and makes failed examples exit loudly.
- Adds `scripts/examples-provision.mjs` as an idempotent provisioning
check for a disposable examples project.

## Scope

- This PR no longer changes the Python SDK runtime or generated-client
dependency.
- Python remains pinned to the published `composio-client==1.43.0` in
`pyproject.toml`, `setup.py`, and `uv.lock`.
- The owned 2.x client integration is deferred until that client
completes its release guarantees and is explicitly published.
- The scheduled live workflow and manifest remain deferred until their
runner is tracked.

## Verification

- `make chk`
- `make tst` (`927 passed, 33 skipped`)
- Hosted checks rerun against commit `12691aca7`.
2026-08-11 19:45:58 +02:00
jkomyno 6c08f17637 test(json-schema): share one corpus loader across the SDK test suites
The loader was copied into four packages, identical but for one path constant.
Core now owns it and the Zod, Effect, and CLI suites re-export it.

It also read its fixture with node:fs, which pulled @types/node into the Zod and
Effect test typechecks for the first time and broke them against the Node 26 line
the workspace was pinned to. That had been worked around by centralizing
@types/node on a Node 24 catalog entry across ten manifests. resolveJsonModule is
already enabled in every consumer, so a static JSON import removes the node:fs
dependency and the whole detour with it: the catalog entry, the pnpm override, the
per-package types fields, and 171 lines of lockfile churn are all reverted.
2026-08-08 00:22:29 +05:30
jkomyno 8d4bb3bf7e chore: merge next into json schema conversion fix 2026-08-07 18:44:34 +05:30
dependabot[bot] 0c4c5a360a chore(deps): bump the npm-production group across 1 directory with 17 updates (#4090)
Bumps the npm-production group with 17 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
|
[@anthropic-ai/claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-typescript)
| `0.3.220` | `0.3.221` |
| [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `6.0.235` |
`6.0.241` |
| [@google/genai](https://github.com/googleapis/js-genai) | `2.13.0` |
`2.15.0` |
| [@langchain/core](https://github.com/langchain-ai/langchainjs) |
`1.2.3` | `1.2.4` |
|
[@langchain/langgraph](https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core)
| `1.4.8` | `1.4.9` |
| [typebox](https://github.com/sinclairzx81/typebox) | `1.3.9` |
`1.3.10` |
| [@ai-sdk/mcp](https://github.com/vercel/ai/tree/HEAD/packages/mcp) |
`2.0.22` | `2.0.24` |
|
[@ai-sdk/openai](https://github.com/vercel/ai/tree/HEAD/packages/openai)
| `4.0.27` | `4.0.29` |
|
[@cloudflare/vitest-pool-workers](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vitest-pool-workers)
| `0.18.8` | `0.20.1` |
| [@cloudflare/workers-types](https://github.com/cloudflare/workerd) |
`5.20260801.1` | `5.20260804.1` |
|
[@mastra/core](https://github.com/mastra-ai/mastra/tree/HEAD/packages/core)
| `1.52.1` | `1.55.0` |
|
[@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk)
| `1.26.0` | `1.30.0` |
| [hono](https://github.com/honojs/hono) | `4.12.31` | `4.13.0` |
| [pnpm](https://github.com/pnpm/pnpm/tree/HEAD/pnpm11/pnpm) | `11.17.0`
| `11.20.0` |
|
[publint](https://github.com/publint/publint/tree/HEAD/packages/publint)
| `0.3.22` | `0.3.23` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.1` | `4.23.5` |
|
[wrangler](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/wrangler)
| `4.114.0` | `4.118.0` |


Updates `@anthropic-ai/claude-agent-sdk` from 0.3.220 to 0.3.221
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/claude-agent-sdk-typescript/releases">@​anthropic-ai/claude-agent-sdk's
releases</a>.</em></p>
<blockquote>
<h2>v0.3.221</h2>
<h2>What's changed</h2>
<ul>
<li>Improved <code>skills</code> option validation: malformed names
(delimiters or control characters) and wildcard-form names are rejected
with a clear error; use <code>skills: 'all'</code> to enable every
skill</li>
<li>Fixed external MCP servers passed via the <code>mcpServers</code>
option not being connected before the first turn, which caused the model
to emit tool calls as literal text</li>
</ul>
<h2>Update</h2>
<pre lang="sh"><code>npm install @anthropic-ai/claude-agent-sdk@0.3.221
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.221
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.221
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.221
</code></pre>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/claude-agent-sdk-typescript/blob/main/CHANGELOG.md">@​anthropic-ai/claude-agent-sdk's
changelog</a>.</em></p>
<blockquote>
<h2>0.3.221</h2>
<ul>
<li>Improved <code>skills</code> option validation: malformed names
(delimiters or control characters) and wildcard-form names are rejected
with a clear error; use <code>skills: 'all'</code> to enable every
skill</li>
<li>Fixed external MCP servers passed via the <code>mcpServers</code>
option not being connected before the first turn, which caused the model
to emit tool calls as literal text</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/anthropics/claude-agent-sdk-typescript/commit/31fbbfd403b3289933abc297e66cec775301e15e"><code>31fbbfd</code></a>
chore: Update CHANGELOG.md</li>
<li>See full diff in <a
href="https://github.com/anthropics/claude-agent-sdk-typescript/compare/v0.3.220...v0.3.221">compare
view</a></li>
</ul>
</details>
<br />

Updates `ai` from 6.0.235 to 6.0.241
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/ai/blob/ai@6.0.241/packages/ai/CHANGELOG.md">ai's
changelog</a>.</em></p>
<blockquote>
<h2>6.0.241</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [7e50c52]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.163</li>
</ul>
</li>
</ul>
<h2>6.0.240</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [b28367e]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.162</li>
</ul>
</li>
</ul>
<h2>6.0.239</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [d3d9e0b]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.161</li>
</ul>
</li>
</ul>
<h2>6.0.238</h2>
<h3>Patch Changes</h3>
<ul>
<li>9ecdefe: Prevent validated downloads on Node.js from reaching
private or internal services through DNS aliases or DNS rebinding by
validating and pinning every resolved address at connection time.</li>
<li>26d10c0: support overriding model call settings for individual
<code>prepareStep</code> invocations</li>
<li>7767170: Preserve provider metadata from empty text deltas in
<code>streamText</code>.</li>
<li>Updated dependencies [9ecdefe]</li>
<li>Updated dependencies [87fb433]
<ul>
<li><code>@​ai-sdk/provider-utils</code><a
href="https://github.com/4"><code>@​4</code></a>.0.41</li>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.160</li>
</ul>
</li>
</ul>
<h2>6.0.237</h2>
<h3>Patch Changes</h3>
<ul>
<li>f6020d7: Avoid synthesizing client tool errors for invalid
provider-executed tool calls.</li>
<li>Updated dependencies [de438f5]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.159</li>
</ul>
</li>
</ul>
<h2>6.0.236</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [8418710]
<ul>
<li><code>@​ai-sdk/gateway</code><a
href="https://github.com/3"><code>@​3</code></a>.0.158</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vercel/ai/commit/5b4cf0ef925c6dfac12167e9e986e2e2e796e68e"><code>5b4cf0e</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/18345">#18345</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/b878ce998fbe53bb27d8124b59c94cb9c109899b"><code>b878ce9</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/18314">#18314</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/fbb507af0398516dc4db212a6dcdfff48744a4fd"><code>fbb507a</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/18280">#18280</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/6e37b23980716390f878881f0e39a878295d1dd4"><code>6e37b23</code></a>
v6.0: docs: document GenerateTextResult.output getter errors (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/18252">#18252</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/006a2f87a3ca3409973d1a11ed21002b37d38c74"><code>006a2f8</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/18089">#18089</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/2deee5b27ec31ba38a2e2b20966fe1a868b5f117"><code>2deee5b</code></a>
v6.0: docs: clarify generateText text aggregation and empty-string
behavior (...</li>
<li><a
href="https://github.com/vercel/ai/commit/26d10c0b30ca68d5c7b618b8d54b06ae01930a68"><code>26d10c0</code></a>
[v6.0] feat: support per-step model call setting overrides in
prepareStep (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/1">#1</a>...</li>
<li><a
href="https://github.com/vercel/ai/commit/9ecdefe4eb4db14c76bcc7c04813663d2012fb8e"><code>9ecdefe</code></a>
[v6] fix(provider-utils): prevent DNS alias SSRF in validated downloads
(<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/18095">#18095</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/776717089720a00a29a7b72b86f7bdc54ea8c0bd"><code>7767170</code></a>
[v6.0] fix: preserve provider metadata from empty streamText text deltas
(<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/18">#18</a>...</li>
<li><a
href="https://github.com/vercel/ai/commit/98d8c433aa6a0d3ec05c201e0355f876c6349c47"><code>98d8c43</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/ai/issues/18028">#18028</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vercel/ai/commits/ai@6.0.241/packages/ai">compare
view</a></li>
</ul>
</details>
<br />

Updates `@google/genai` from 2.13.0 to 2.15.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/googleapis/js-genai/releases">@​google/genai's
releases</a>.</em></p>
<blockquote>
<h2>v2.15.0</h2>
<h2><a
href="https://github.com/googleapis/js-genai/compare/v2.14.0...v2.15.0">2.15.0</a>
(2026-07-30)</h2>
<h3>Features</h3>
<ul>
<li>add environment resource (<a
href="https://github.com/googleapis/js-genai/commit/2c911befbf839fc250a296783cbedbd3b668a9f7">2c911be</a>)</li>
<li>Support GoogleMaps Tool grounding_types places and routing (<a
href="https://github.com/googleapis/js-genai/commit/52655c192848942d2d866c3b256de27c94583f78">52655c1</a>)</li>
<li>Support per-request retryOptions in the JS GenAI SDK API Client (<a
href="https://github.com/googleapis/js-genai/commit/124b606bc5be0d5e70673dc28e16e739c9a25d7c">124b606</a>)</li>
<li>Wire environment service into genai sdk (<a
href="https://github.com/googleapis/js-genai/commit/70d79389536821f1323ae5016f63ee95afa6b48a">70d7938</a>)</li>
</ul>
<h2>v2.14.0</h2>
<h2><a
href="https://github.com/googleapis/js-genai/compare/v2.13.0...v2.14.0">2.14.0</a>
(2026-07-28)</h2>
<h3>Features</h3>
<ul>
<li>[GenerateContentConfig] Add
GenerationConfig.audio_transcription_config and
Part.audio_transcription. (<a
href="https://github.com/googleapis/js-genai/commit/4b2e67aebbb713321c095ccad34618f2a98fdd7d">4b2e67a</a>)</li>
<li>Add flat <code>language_codes</code> field to
<code>AudioTranscriptionConfig</code>. (<a
href="https://github.com/googleapis/js-genai/commit/cc808ebcbe76beb8e54fd5ca24ac358643104853">cc808eb</a>)</li>
<li>Allow api key + proj/location for enterprise mode (<a
href="https://github.com/googleapis/js-genai/commit/9c0540a26694e6a2896a433e43d1bac963af10e5">9c0540a</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>add deprecation warnings to Imagen generate_images, edit_images,
generate_videos (if using prompt/text/image args),
LiveConnectConfig.GenerationConfig which will be removed in the next
major version (<a
href="https://github.com/googleapis/js-genai/commit/bb6610199a76f7a99e28ed77974e6a3af21a52b1">bb66101</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/googleapis/js-genai/blob/main/CHANGELOG.md">@​google/genai's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/googleapis/js-genai/compare/v2.14.0...v2.15.0">2.15.0</a>
(2026-07-30)</h2>
<h3>Features</h3>
<ul>
<li>add environment resource (<a
href="https://github.com/googleapis/js-genai/commit/2c911befbf839fc250a296783cbedbd3b668a9f7">2c911be</a>)</li>
<li>Support GoogleMaps Tool grounding_types places and routing (<a
href="https://github.com/googleapis/js-genai/commit/52655c192848942d2d866c3b256de27c94583f78">52655c1</a>)</li>
<li>Support per-request retryOptions in the JS GenAI SDK API Client (<a
href="https://github.com/googleapis/js-genai/commit/124b606bc5be0d5e70673dc28e16e739c9a25d7c">124b606</a>)</li>
<li>Wire environment service into genai sdk (<a
href="https://github.com/googleapis/js-genai/commit/70d79389536821f1323ae5016f63ee95afa6b48a">70d7938</a>)</li>
</ul>
<h2><a
href="https://github.com/googleapis/js-genai/compare/v2.13.0...v2.14.0">2.14.0</a>
(2026-07-28)</h2>
<h3>Features</h3>
<ul>
<li>[GenerateContentConfig] Add
GenerationConfig.audio_transcription_config and
Part.audio_transcription. (<a
href="https://github.com/googleapis/js-genai/commit/4b2e67aebbb713321c095ccad34618f2a98fdd7d">4b2e67a</a>)</li>
<li>Add flat <code>language_codes</code> field to
<code>AudioTranscriptionConfig</code>. (<a
href="https://github.com/googleapis/js-genai/commit/cc808ebcbe76beb8e54fd5ca24ac358643104853">cc808eb</a>)</li>
<li>Allow api key + proj/location for enterprise mode (<a
href="https://github.com/googleapis/js-genai/commit/9c0540a26694e6a2896a433e43d1bac963af10e5">9c0540a</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>add deprecation warnings to Imagen generate_images, edit_images,
generate_videos (if using prompt/text/image args),
LiveConnectConfig.GenerationConfig which will be removed in the next
major version (<a
href="https://github.com/googleapis/js-genai/commit/bb6610199a76f7a99e28ed77974e6a3af21a52b1">bb66101</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/googleapis/js-genai/commit/a76a3eab126e5b7c6a46f6c43795ec3cc65b5488"><code>a76a3ea</code></a>
chore(main): release 2.15.0 (<a
href="https://redirect.github.com/googleapis/js-genai/issues/1815">#1815</a>)</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/124b606bc5be0d5e70673dc28e16e739c9a25d7c"><code>124b606</code></a>
feat: Support per-request retryOptions in the JS GenAI SDK API
Client</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/52655c192848942d2d866c3b256de27c94583f78"><code>52655c1</code></a>
feat: Support GoogleMaps Tool grounding_types places and routing</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/70d79389536821f1323ae5016f63ee95afa6b48a"><code>70d7938</code></a>
feat: Wire environment service into genai sdk</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/2c911befbf839fc250a296783cbedbd3b668a9f7"><code>2c911be</code></a>
feat: add environment resource</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/1895d5793954cb62e3ab4d90aab2f636b4285497"><code>1895d57</code></a>
docs: Communicate on upcoming updates in the next major version</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/ebeba1cda039d43e821d519afb8ce1d0dc9d0f74"><code>ebeba1c</code></a>
chore(main): release 2.14.0 (<a
href="https://redirect.github.com/googleapis/js-genai/issues/1799">#1799</a>)</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/cc808ebcbe76beb8e54fd5ca24ac358643104853"><code>cc808eb</code></a>
feat: Add flat <code>language_codes</code> field to
<code>AudioTranscriptionConfig</code>.</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/9c0540a26694e6a2896a433e43d1bac963af10e5"><code>9c0540a</code></a>
feat: Allow api key + proj/location for enterprise mode</li>
<li><a
href="https://github.com/googleapis/js-genai/commit/d221cf34c94ad558ab22d59e3163b60122d72948"><code>d221cf3</code></a>
chore: internal update</li>
<li>Additional commits viewable in <a
href="https://github.com/googleapis/js-genai/compare/v2.13.0...v2.15.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/core` from 1.2.3 to 1.2.4
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">@​langchain/core's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.2.4</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11190">#11190</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/9654bde694af4e78080a76a0b39d7edd35683449"><code>9654bde</code></a>
Thanks <a
href="https://github.com/pawel-twardziak"><code>@​pawel-twardziak</code></a>!
- Coalesce nested LangChain tracer callbacks that share run
bookkeeping.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/11153">#11153</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/84ce6d65ef0ab2c556d5a5a3b5651b5cf3d73303"><code>84ce6d6</code></a>
Thanks <a
href="https://github.com/parveshsaini"><code>@​parveshsaini</code></a>!
- fix(core): bind splitText when trimMessages receives a TextSplitter
instance</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/f6dbb882d1d4a591d69020145b6a871fe7801b35"><code>f6dbb88</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11268">#11268</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/9654bde694af4e78080a76a0b39d7edd35683449"><code>9654bde</code></a>
fix(core): coalesce duplicate tracer copies sharing run state (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11190">#11190</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/84ce6d65ef0ab2c556d5a5a3b5651b5cf3d73303"><code>84ce6d6</code></a>
fix(core): bind splitText when trimMessages receives a TextSplitter
instance ...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/710d74f3fc0ff98d5088c8e0c86752829cfaaa2c"><code>710d74f</code></a>
fix: resolve open Dependabot alerts (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11259">#11259</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/5226cddb0d0b31d33bb78fc51230e4283cd6cc64"><code>5226cdd</code></a>
chore(deps-dev): bump <code>@​hono/node-server</code> from 2.0.4 to
2.0.10 in /libs/langcha...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/d829cb490112454b3cf8718a526f28450ff37062"><code>d829cb4</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11204">#11204</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/c8bd4c4a6dbde07fb24deb5870c02dc29c51ab53"><code>c8bd4c4</code></a>
feat(anthropic): add Claude Opus 5 support (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11255">#11255</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/741f380ae54afd2e920495b3042ea6346865836a"><code>741f380</code></a>
chore(deps): bump <code>@​hono/node-server</code> from 2.0.4 to 2.0.10
(<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11244">#11244</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/5103cee12ae0e3e56038f0c20edda5159b252daa"><code>5103cee</code></a>
chore(deps): bump js-yaml from 5.1.0 to 5.2.2 (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11256">#11256</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/db29a6a8060d9d8998f5fb566368e3bad5b32a5b"><code>db29a6a</code></a>
chore(deps): bump axios from 1.16.1 to 1.18.0 (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/11228">#11228</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchainjs/compare/@langchain/core@1.2.3...@langchain/core@1.2.4">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/langgraph` from 1.4.8 to 1.4.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langgraphjs/releases">@​langchain/langgraph's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/langgraph</code><a
href="https://github.com/1"><code>@​1</code></a>.4.9</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langgraphjs/pull/2653">#2653</a>
<a
href="https://github.com/langchain-ai/langgraphjs/commit/7880055ac7303483e424380cdd52f54cd094e311"><code>7880055</code></a>
Thanks <a
href="https://github.com/christian-bromann"><code>@​christian-bromann</code></a>!
- fix(langgraph): checkpoint Topic as a flat values list</p>
<p>Match Python Topic checkpoints so Host JS graphs no longer put
<code>__pregel_tasks: [[], []]</code> through the Python checkpointer.
Keep reading legacy <code>[seen, values]</code> checkpoints for restore
compatibility.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langgraphjs/blob/main/libs/langgraph-core/CHANGELOG.md">@​langchain/langgraph's
changelog</a>.</em></p>
<blockquote>
<h2>1.4.9</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langgraphjs/pull/2653">#2653</a>
<a
href="https://github.com/langchain-ai/langgraphjs/commit/7880055ac7303483e424380cdd52f54cd094e311"><code>7880055</code></a>
Thanks <a
href="https://github.com/christian-bromann"><code>@​christian-bromann</code></a>!
- fix(langgraph): checkpoint Topic as a flat values list</p>
<p>Match Python Topic checkpoints so Host JS graphs no longer put
<code>__pregel_tasks: [[], []]</code> through the Python checkpointer.
Keep reading legacy <code>[seen, values]</code> checkpoints for restore
compatibility.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langgraphjs/commit/5f9915234a5dca861ef01180fde28e52f42c6e15"><code>5f99152</code></a>
chore: version packages (<a
href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2655">#2655</a>)</li>
<li><a
href="https://github.com/langchain-ai/langgraphjs/commit/7880055ac7303483e424380cdd52f54cd094e311"><code>7880055</code></a>
fix(langgraph): checkpoint Topic as a flat values list (<a
href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2653">#2653</a>)</li>
<li><a
href="https://github.com/langchain-ai/langgraphjs/commit/cac6d3106599b5c9ecff8c00d99a7e78571c5202"><code>cac6d31</code></a>
chore(deps): bump the vite-vitest group across 1 directory with 6
updates (<a
href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2">#2</a>...</li>
<li><a
href="https://github.com/langchain-ai/langgraphjs/commit/fa9892117d56398ce0f02f1a73bafb807a61ce2e"><code>fa98921</code></a>
chore(deps-dev): bump <code>@​vitest/browser</code> from 4.1.9 to 4.1.10
(<a
href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2624">#2624</a>)</li>
<li><a
href="https://github.com/langchain-ai/langgraphjs/commit/cdffd18d192eaa87375bc2d45b343418af8bd024"><code>cdffd18</code></a>
chore(deps): bump the langchain group across 1 directory with 6 updates
(<a
href="https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core/issues/2616">#2616</a>)</li>
<li>See full diff in <a
href="https://github.com/langchain-ai/langgraphjs/commits/@langchain/langgraph@1.4.9/libs/langgraph-core">compare
view</a></li>
</ul>
</details>
<br />

Updates `typebox` from 1.3.9 to 1.3.10
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/sinclairzx81/typebox/commit/221a1de804f08471600ebd4dc8a4460340797d56"><code>221a1de</code></a>
Version 1.3.10 (<a
href="https://redirect.github.com/sinclairzx81/typebox/issues/1662">#1662</a>)</li>
<li><a
href="https://github.com/sinclairzx81/typebox/commit/4992c53f930a675d78acdf5d61a1a12e64e8037a"><code>4992c53</code></a>
Specification</li>
<li>See full diff in <a
href="https://github.com/sinclairzx81/typebox/compare/1.3.9...1.3.10">compare
view</a></li>
</ul>
</details>
<br />

Updates `@ai-sdk/mcp` from 2.0.22 to 2.0.24
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/ai/blob/main/packages/mcp/CHANGELOG.md">@​ai-sdk/mcp's
changelog</a>.</em></p>
<blockquote>
<h2>2.0.24</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [160ccdb]
<ul>
<li><code>@​ai-sdk/provider-utils</code><a
href="https://github.com/5"><code>@​5</code></a>.0.20</li>
</ul>
</li>
</ul>
<h2>2.0.23</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [79e133c]
<ul>
<li><code>@​ai-sdk/provider</code><a
href="https://github.com/4"><code>@​4</code></a>.0.5</li>
<li><code>@​ai-sdk/provider-utils</code><a
href="https://github.com/5"><code>@​5</code></a>.0.19</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vercel/ai/commit/22095f409fdf70dc858546fe26b1cf92f12f87f1"><code>22095f4</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/mcp/issues/18381">#18381</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/9df82a8bc70f569ae0fbb701a81fd6209ec2a2b7"><code>9df82a8</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/mcp/issues/18368">#18368</a>)</li>
<li>See full diff in <a
href="https://github.com/vercel/ai/commits/@ai-sdk/mcp@2.0.24/packages/mcp">compare
view</a></li>
</ul>
</details>
<br />

Updates `@ai-sdk/openai` from 4.0.27 to 4.0.29
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/ai/blob/main/packages/openai/CHANGELOG.md">@​ai-sdk/openai's
changelog</a>.</em></p>
<blockquote>
<h2>4.0.29</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [160ccdb]
<ul>
<li><code>@​ai-sdk/provider-utils</code><a
href="https://github.com/5"><code>@​5</code></a>.0.20</li>
</ul>
</li>
</ul>
<h2>4.0.28</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [79e133c]
<ul>
<li><code>@​ai-sdk/provider</code><a
href="https://github.com/4"><code>@​4</code></a>.0.5</li>
<li><code>@​ai-sdk/provider-utils</code><a
href="https://github.com/5"><code>@​5</code></a>.0.19</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vercel/ai/commit/22095f409fdf70dc858546fe26b1cf92f12f87f1"><code>22095f4</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/openai/issues/18381">#18381</a>)</li>
<li><a
href="https://github.com/vercel/ai/commit/9df82a8bc70f569ae0fbb701a81fd6209ec2a2b7"><code>9df82a8</code></a>
Version Packages (<a
href="https://github.com/vercel/ai/tree/HEAD/packages/openai/issues/18368">#18368</a>)</li>
<li>See full diff in <a
href="https://github.com/vercel/ai/commits/@ai-sdk/openai@4.0.29/packages/openai">compare
view</a></li>
</ul>
</details>
<br />

Updates `@cloudflare/vitest-pool-workers` from 0.18.8 to 0.20.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/cloudflare/workers-sdk/releases">@​cloudflare/vitest-pool-workers's
releases</a>.</em></p>
<blockquote>
<h2><code>@​cloudflare/vitest-pool-workers</code><a
href="https://github.com/0"><code>@​0</code></a>.20.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a
href="https://github.com/cloudflare/workers-sdk/commit/cc63aae658c39ae33169c6dc89f2e6ec1071fc53"><code>cc63aae</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/f92d1fc1316ba4e5f7e308c79943cb9e34b308c2"><code>f92d1fc</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/a249591473321cc2fb88a7b62a8c2b8663ebd4ef"><code>a249591</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/f92d1fc1316ba4e5f7e308c79943cb9e34b308c2"><code>f92d1fc</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/f92d1fc1316ba4e5f7e308c79943cb9e34b308c2"><code>f92d1fc</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/cec9d8875d3f103acc813724ded980867bd25ed7"><code>cec9d88</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/e0bbf55fdce5239a88c78a4350d3287f52d77964"><code>e0bbf55</code></a>]:
<ul>
<li>wrangler@4.118.0</li>
</ul>
</li>
</ul>
<h2><code>@​cloudflare/vitest-pool-workers</code><a
href="https://github.com/0"><code>@​0</code></a>.20.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/cloudflare/workers-sdk/pull/14586">#14586</a>
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>
Thanks <a
href="https://github.com/emily-shen"><code>@​emily-shen</code></a>! -
Breaking change: Remove several options from the <code>miniflare</code>
override options</p>
<p>The following options have been removed from the
<code>miniflare</code> override options, as they were not intended to be
exposed, were not functional, or have been superseded by other
options:</p>
<ul>
<li><code>wrappedBindings</code></li>
<li><code>cacheWarnUsage</code></li>
<li><code>fetchMock</code>: you should use <code>outboundService</code>
instead</li>
<li><code>containerEngine</code>: containers were not supported in
vitest-pool-workers. Consider using <a
href="https://developers.cloudflare.com/workers/testing/test-harness/"><code>createTestHarness()</code></a>
instead if you want to test against actual containers.</li>
</ul>
<p>Additionally, <code>cache</code> has been deprecated and renamed to
<code>cacheAPI</code>, but <code>cache</code> remains functional.</p>
</li>
</ul>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/cloudflare/workers-sdk/pull/14586">#14586</a>
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>
Thanks <a
href="https://github.com/emily-shen"><code>@​emily-shen</code></a>! -
Preserve the deprecated Miniflare <code>cache</code> option</p>
<p>Vitest configurations using <code>cache</code> continue to work after
the internal Miniflare v5 upgrade. The option is translated to
<code>cacheAPI</code>; new configurations should use
<code>cacheAPI</code> directly.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/cloudflare/workers-sdk/pull/14586">#14586</a>
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>
Thanks <a
href="https://github.com/emily-shen"><code>@​emily-shen</code></a>! -
Stop enabling Miniflare's removed <code>unsafeStickyBlobs</code>
option</p>
<p>The pool no longer sets the <code>unsafeStickyBlobs</code> Miniflare
option, which has been removed. This option was only needed for the
Durable Object isolated storage feature that was dropped in 0.13.0, so
there is no change in behaviour.</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>]:</p>
<ul>
<li><a
href="mailto:miniflare@5.20260730.0-alpha">miniflare@5.20260730.0-alpha</a></li>
<li>wrangler@4.117.0</li>
</ul>
</li>
</ul>
<h2><code>@​cloudflare/vitest-pool-workers</code><a
href="https://github.com/0"><code>@​0</code></a>.19.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a
href="https://github.com/cloudflare/workers-sdk/commit/01d7020806dd523158cf9f26a4575365117f5381"><code>01d7020</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/beec0fbc9d3adec24bc42e31a21fe7f82badb543"><code>beec0fb</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/48f0c6cbbc50dfac02e2d76554c181ced233a792"><code>48f0c6c</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/8049ca451c9561e8b72f3eeeb7916a8712f06133"><code>8049ca4</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/d7f38c311e8cd0f29f56a25250da45f62b20f8ca"><code>d7f38c3</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/1394867d1dc357d9bddabf8c16aede47d052fb18"><code>1394867</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/cc5447865022ebc602258cfbeb79953181a62ae0"><code>cc54478</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5c25cfe4e03e0d3d42ddab57adc3274d6f6a1a30"><code>5c25cfe</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/b21eac24878f060296915f198fae910268c465ef"><code>b21eac2</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/bb09f1bd77a194520db3e61d733996f4bbe4bad8"><code>bb09f1b</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/1f61001e5f7a807db7856f5d89e0b26e12a0d0a0"><code>1f61001</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/01d7020806dd523158cf9f26a4575365117f5381"><code>01d7020</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/e31ab0f40c5310babd8b493490c0e1ca677e9a8c"><code>e31ab0f</code></a>]:
<ul>
<li>miniflare@4.20260730.0</li>
<li>wrangler@4.116.0</li>
</ul>
</li>
</ul>
<h2><code>@​cloudflare/vitest-pool-workers</code><a
href="https://github.com/0"><code>@​0</code></a>.19.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/cloudflare/workers-sdk/pull/14879">#14879</a>
<a
href="https://github.com/cloudflare/workers-sdk/commit/e6480e3c26e849034e9e511a2fd1216257975656"><code>e6480e3</code></a>
Thanks <a
href="https://github.com/dmmulroy"><code>@​dmmulroy</code></a>! - Add a
<code>verbose</code> option to <code>cloudflareTest()</code> and
<code>cloudflarePool()</code> configuration</p>
<p>Set <code>verbose: false</code> to suppress verbose workerd runtime
logs, such as caught Durable Object RPC errors. The option defaults to
<code>true</code> to preserve existing output.</p>
</li>
</ul>
<h3>Patch Changes</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/cloudflare/workers-sdk/blob/main/packages/vitest-pool-workers/CHANGELOG.md">@​cloudflare/vitest-pool-workers's
changelog</a>.</em></p>
<blockquote>
<h2>0.20.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a
href="https://github.com/cloudflare/workers-sdk/commit/cc63aae658c39ae33169c6dc89f2e6ec1071fc53"><code>cc63aae</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/f92d1fc1316ba4e5f7e308c79943cb9e34b308c2"><code>f92d1fc</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/a249591473321cc2fb88a7b62a8c2b8663ebd4ef"><code>a249591</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/f92d1fc1316ba4e5f7e308c79943cb9e34b308c2"><code>f92d1fc</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/f92d1fc1316ba4e5f7e308c79943cb9e34b308c2"><code>f92d1fc</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/cec9d8875d3f103acc813724ded980867bd25ed7"><code>cec9d88</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/e0bbf55fdce5239a88c78a4350d3287f52d77964"><code>e0bbf55</code></a>]:
<ul>
<li>wrangler@4.118.0</li>
</ul>
</li>
</ul>
<h2>0.20.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/cloudflare/workers-sdk/pull/14586">#14586</a>
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>
Thanks <a
href="https://github.com/emily-shen"><code>@​emily-shen</code></a>! -
Breaking change: Remove several options from the <code>miniflare</code>
override options</p>
<p>The following options have been removed from the
<code>miniflare</code> override options, as they were not intended to be
exposed, were not functional, or have been superseded by other
options:</p>
<ul>
<li><code>wrappedBindings</code></li>
<li><code>cacheWarnUsage</code></li>
<li><code>fetchMock</code>: you should use <code>outboundService</code>
instead</li>
<li><code>containerEngine</code>: containers were not supported in
vitest-pool-workers. Consider using <a
href="https://developers.cloudflare.com/workers/testing/test-harness/"><code>createTestHarness()</code></a>
instead if you want to test against actual containers.</li>
</ul>
<p>Additionally, <code>cache</code> has been deprecated and renamed to
<code>cacheAPI</code>, but <code>cache</code> remains functional.</p>
</li>
</ul>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/cloudflare/workers-sdk/pull/14586">#14586</a>
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>
Thanks <a
href="https://github.com/emily-shen"><code>@​emily-shen</code></a>! -
Preserve the deprecated Miniflare <code>cache</code> option</p>
<p>Vitest configurations using <code>cache</code> continue to work after
the internal Miniflare v5 upgrade. The option is translated to
<code>cacheAPI</code>; new configurations should use
<code>cacheAPI</code> directly.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/cloudflare/workers-sdk/pull/14586">#14586</a>
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>
Thanks <a
href="https://github.com/emily-shen"><code>@​emily-shen</code></a>! -
Stop enabling Miniflare's removed <code>unsafeStickyBlobs</code>
option</p>
<p>The pool no longer sets the <code>unsafeStickyBlobs</code> Miniflare
option, which has been removed. This option was only needed for the
Durable Object isolated storage feature that was dropped in 0.13.0, so
there is no change in behaviour.</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>]:</p>
<ul>
<li><a
href="mailto:miniflare@5.20260730.0-alpha">miniflare@5.20260730.0-alpha</a></li>
<li>wrangler@4.117.0</li>
</ul>
</li>
</ul>
<h2>0.19.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a
href="https://github.com/cloudflare/workers-sdk/commit/01d7020806dd523158cf9f26a4575365117f5381"><code>01d7020</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/beec0fbc9d3adec24bc42e31a21fe7f82badb543"><code>beec0fb</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/48f0c6cbbc50dfac02e2d76554c181ced233a792"><code>48f0c6c</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/8049ca451c9561e8b72f3eeeb7916a8712f06133"><code>8049ca4</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/d7f38c311e8cd0f29f56a25250da45f62b20f8ca"><code>d7f38c3</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/1394867d1dc357d9bddabf8c16aede47d052fb18"><code>1394867</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/cc5447865022ebc602258cfbeb79953181a62ae0"><code>cc54478</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/5c25cfe4e03e0d3d42ddab57adc3274d6f6a1a30"><code>5c25cfe</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/b21eac24878f060296915f198fae910268c465ef"><code>b21eac2</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/bb09f1bd77a194520db3e61d733996f4bbe4bad8"><code>bb09f1b</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/1f61001e5f7a807db7856f5d89e0b26e12a0d0a0"><code>1f61001</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/01d7020806dd523158cf9f26a4575365117f5381"><code>01d7020</code></a>,
<a
href="https://github.com/cloudflare/workers-sdk/commit/e31ab0f40c5310babd8b493490c0e1ca677e9a8c"><code>e31ab0f</code></a>]:
<ul>
<li>miniflare@4.20260730.0</li>
<li>wrangler@4.116.0</li>
</ul>
</li>
</ul>
<h2>0.19.0</h2>
<h3>Minor Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/cloudflare/workers-sdk/pull/14879">#14879</a>
<a
href="https://github.com/cloudflare/workers-sdk/commit/e6480e3c26e849034e9e511a2fd1216257975656"><code>e6480e3</code></a>
Thanks <a
href="https://github.com/dmmulroy"><code>@​dmmulroy</code></a>! - Add a
<code>verbose</code> option to <code>cloudflareTest()</code> and
<code>cloudflarePool()</code> configuration</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/cloudflare/workers-sdk/commit/95d9b12f2c707f254b66b446e0bd9fd6b8b7d96d"><code>95d9b12</code></a>
Version Packages (<a
href="https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vitest-pool-workers/issues/14946">#14946</a>)</li>
<li><a
href="https://github.com/cloudflare/workers-sdk/commit/83a37e3ef05d6930f29df904978e7f6eacde2203"><code>83a37e3</code></a>
docs: point vitest-pool-workers BUILD section at the tsdown config (<a
href="https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vitest-pool-workers/issues/14940">#14940</a>)</li>
<li><a
href="https://github.com/cloudflare/workers-sdk/commit/fcb5402346b2424008c7a0d0612ee8ba2f65bf3e"><code>fcb5402</code></a>
Version Packages (<a
href="https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vitest-pool-workers/issues/14939">#14939</a>)</li>
<li><a
href="https://github.com/cloudflare/workers-sdk/commit/5a56ddaf8548fe79787482506b3d5e0233c329c6"><code>5a56dda</code></a>
Miniflare v5 alpha (<a
href="https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vitest-pool-workers/issues/14586">#14586</a>)</li>
<li><a
href="https://github.com/cloudflare/workers-sdk/commit/96fd16f0e06e82eb99001c70e4935e992e69cb87"><code>96fd16f</code></a>
Version Packages (<a
href="https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vitest-pool-workers/issues/14898">#14898</a>)</li>
<li><a
href="https://github.com/cloudflare/workers-sdk/commit/760a85b6fac60b0a73298c99df54ae0058653c76"><code>760a85b</code></a>
Version Packages (<a
href="https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vitest-pool-workers/issues/14824">#14824</a>)</li>
<li><a
href="https://github.com/cloudflare/workers-sdk/commit/e6480e3c26e849034e9e511a2fd1216257975656"><code>e6480e3</code></a>
[vitest-pool-workers] Make workerd verbose logging configurable (<a
href="https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vitest-pool-workers/issues/14879">#14879</a>)</li>
<li><a
href="https://github.com/cloudflare/workers-sdk/commit/edc203e42a10a52f8d2af305fecd2fed4807274e"><code>edc203e</code></a>
[vitest-pool-workers] Ignore workerd's ungraceful TLS disconnect
exception lo...</li>
<li>See full diff in <a
href="https://github.com/cloudflare/workers-sdk/commits/@cloudflare/vitest-pool-workers@0.20.1/packages/vitest-pool-workers">compare
view</a></li>
</ul>
</details>
<br />

Updates `@cloudflare/workers-types` from 5.20260801.1 to 5.20260804.1
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/cloudflare/workerd/commits">compare
view</a></li>
</ul>
</details>
<br />

Updates `@mastra/core` from 1.52.1 to 1.55.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/mastra-ai/mastra/releases">@​mastra/core's
releases</a>.</em></p>
<blockquote>
<h2>July 30, 2026</h2>
<h2>Highlights</h2>
<h3>In-process Code Mode execution (no workspace sandbox required)</h3>
<p>Code Mode transports can now declare <code>requiresSandbox:
false</code>, letting <code>createCodeMode()</code> run without a
workspace sandbox for in-process execution boundaries. This enables
secure in-process runtimes like V8 isolates and exports
<code>sanitizeToolId</code> so transports can share consistent
<code>external_*</code> naming.</p>
<h3>New <code>@mastra/isolated-vm</code> package for V8-isolated Code
Mode</h3>
<p>Introduces <code>@mastra/isolated-vm</code> with
<code>IsolatedVmCodeModeTransport</code>, running model-authored
programs inside an in-process V8 isolate with no
filesystem/network/process access (only bridged <code>external_*</code>
tools). Note: requires <code>isolated-vm</code> native addon and Node
20+ hosts must start with <code>--no-node-snapshot</code>.</p>
<h3>Built-in provider-native Web Search tool</h3>
<p><code>@mastra/core</code> adds <code>webSearchTool</code>, a
first-party web search tool that resolves to provider-native search when
supported by the configured model/provider, simplifying “current info”
agent setups.</p>
<h3>Stored agent drafts via <code>autoPublish</code> (Server + JS
SDK)</h3>
<p>Both <code>@mastra/server</code> and <code>@mastra/client-js</code>
add <code>autoPublish</code> to stored agent creation so you can create
an initial unpublished draft for review before publishing (existing
calls still publish immediately by default).</p>
<h3>New Factory channel identity domain + channels integration slot</h3>
<p><code>@mastra/factory</code> adds a <code>channel-identity</code>
storage domain to link chat-platform senders to Factory users, plus a
<code>channels()</code> integration slot to attach an
<code>AgentControllerChannels</code> during <code>prepare()</code> so
inbound platform messages can drive the same agents as the web UI.</p>
<h3>Breaking Changes</h3>
<ul>
<li><code>ChannelHandler</code> context parameter is now required: the
4th parameter is <code>ctx: ChannelHandlerContext</code> (non-optional).
Code that <em>calls</em> a <code>ChannelHandler</code>-typed function
with only three args must be updated to pass <code>ctx</code>.</li>
</ul>
<h2>Changelog</h2>
<h3><a
href="https://github.com/mastra-ai/mastra/blob/@mastra/core@1.55.0/packages/core/CHANGELOG.md">@​mastra/core@1.55.0</a></h3>
<h4>Minor Changes</h4>
<ul>
<li>
<p>Added support for Code Mode transports that provide their own
execution boundary. A transport can now declare <code>requiresSandbox:
false</code> and <code>createCodeMode()</code> will run it without a
workspace sandbox, which enables in-process transports such as
<code>IsolatedVmCodeModeTransport</code> from
<code>@mastra/isolated-vm</code>: (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/20359">#20359</a>)</p>
<pre lang="typescript"><code>import { createCodeMode } from
'@mastra/core/tools';
import { IsolatedVmCodeModeTransport } from '@mastra/isolated-vm';
<p>// No sandbox needed — the V8 isolate is the execution boundary
const { tool, instructions } = createCodeMode({ tools }, new
IsolatedVmCodeModeTransport());
</code></pre></p>
<p>Also fixed the generated Code Mode instructions to describe isolation
accurately instead of always claiming the program runs fully sandboxed,
since the actual boundary depends on the configured sandbox and
transport. The <code>sanitizeToolId</code> helper used for
<code>external_*</code> naming is now exported from
<code>@mastra/core/tools</code> so transports can reuse it instead of
duplicating it.</p>
</li>
<li>
<p>Added retry callbacks for stream error policies and ensured explicit
matcher policies override provider retry metadata. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/19724">#19724</a>)</p>
</li>
<li>
<p>Channel handlers can now contribute to the request context of the run
they start. (<a
href="https://redirect.github.com/mastra-ai/mastra/pull/20060">#20060</a>)</p>
<p><code>ChannelHandlerContext</code> gains a
<code>requestContext</code> field holding the
<code>RequestContext</code> for the run the inbound message is about to
start. It is constructed fresh for every message, and a handler may
write to it before calling <code>defaultHandler</code>. Core then adds
its own channel and render-context entries and dispatches with the same
instance, so anything the handler wrote reaches the run.</p>
<pre lang="ts"><code>import { AgentControllerChannels } from
'@mastra/core/channels';
<p>const channels = new AgentControllerChannels({
adapters,
handlers: {
</code></pre></p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/mastra-ai/mastra/commit/bccb45d579ae7a914b9c03733f919127952c2300"><code>bccb45d</code></a>
chore: version - exit prerelease mode</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/469696312ac4c618bc8475b0c5ed7949b8a3455e"><code>4696963</code></a>
fix(core): persist delegation prompt exactly once in sub-agent threads
(<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/core/issues/20174">#20174</a>)</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/6b861234d6728e50c7b424d504024b468d6db2b8"><code>6b86123</code></a>
chore: version packages (alpha) (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/core/issues/20419">#20419</a>)</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/723aa5437106bdb708ae03c0ef6b77aa11291e73"><code>723aa54</code></a>
feat(factory): stricter review agent — weigh existing comments,
calibrated ve...</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/ef8a7ceb6d663723e5e09aa6ebabc716665325af"><code>ef8a7ce</code></a>
chore: version packages (alpha) (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/core/issues/20358">#20358</a>)</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/07f5b4ba9d608d88865030732e580298296adf99"><code>07f5b4b</code></a>
fix(core): avoid serializing result comparisons (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/core/issues/20340">#20340</a>)</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/9c16d7b20f02b5bfd1152861a69fd6694c26f4b3"><code>9c16d7b</code></a>
chore: regenerate providers and docs [skip ci]</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/55c9e248c27c1d72b5bb7e94ea6b8a3999eee49f"><code>55c9e24</code></a>
Run Slack messages as the sender's Mastra tenant (<a
href="https://github.com/mastra-ai/mastra/tree/HEAD/packages/core/issues/20060">#20060</a>)</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/cfb2899d510252f39ddf46fb75c35c11fb4a36f4"><code>cfb2899</code></a>
chore: version packages</li>
<li><a
href="https://github.com/mastra-ai/mastra/commit/ba369f2a0aaf998da0d6aa033d26f64f96bef8ac"><code>ba369f2</code></a>
feat(isolated-vm): add IsolatedVmCodeModeTransport for in-process Code
Mode i...</li>
<li>Additional commits viewable in <a
href="https://github.com/mastra-ai/mastra/commits/@mastra/core@1.55.0/packages/core">compare
view</a></li>
</ul>
</details>
<br />

Updates `@modelcontextprotocol/sdk` from 1.26.0 to 1.30.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/modelcontextprotocol/typescript-sdk/releases">@​modelcontextprotocol/sdk's
releases</a>.</em></p>
<blockquote>
<h2>1.30.0</h2>
<h2>What's Changed</h2>
<ul>
<li>fix(server): prioritize zod issues and format them by <a
href="https://github.com/mozmo15"><code>@​mozmo15</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1503">modelcontextprotocol/typescript-sdk#1503</a></li>
<li>chore(ci): switch publish to OIDC trusted publishing by <a
href="https://github.com/felixweinberger"><code>@​felixweinberger</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1839">modelcontextprotocol/typescript-sdk#1839</a></li>
<li>Add end-to-end test suite by <a
href="https://github.com/felixweinberger"><code>@​felixweinberger</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2167">modelcontextprotocol/typescript-sdk#2167</a></li>
<li>v1 stdio buffer limit by <a
href="https://github.com/KKonstantinov"><code>@​KKonstantinov</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2239">modelcontextprotocol/typescript-sdk#2239</a></li>
<li>fix: support Zod 3.25 method literals by <a
href="https://github.com/mattzcarey"><code>@​mattzcarey</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2368">modelcontextprotocol/typescript-sdk#2368</a></li>
<li>Validate Content-Type by parsed media type instead of substring
match (v1.x) by <a
href="https://github.com/felixweinberger"><code>@​felixweinberger</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2444">modelcontextprotocol/typescript-sdk#2444</a></li>
<li>fix: send SSE keep-alive comment frames from Streamable HTTP server
transport (v1.x) by <a
href="https://github.com/mattzcarey"><code>@​mattzcarey</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2538">modelcontextprotocol/typescript-sdk#2538</a></li>
<li>fix(deps): widen <code>@​hono/node-server</code> past
GHSA-frvp-7c67-39w9 by <a
href="https://github.com/arimu1"><code>@​arimu1</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2549">modelcontextprotocol/typescript-sdk#2549</a></li>
<li>Fix SSE keep-alive timer lifecycle in Streamable HTTP server
transport (v1.x) by <a
href="https://github.com/felixweinberger"><code>@​felixweinberger</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2547">modelcontextprotocol/typescript-sdk#2547</a></li>
<li>chore: bump version to 1.30.0 by <a
href="https://github.com/felixweinberger"><code>@​felixweinberger</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2563">modelcontextprotocol/typescript-sdk#2563</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/mozmo15"><code>@​mozmo15</code></a> made
their first contribution in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1503">modelcontextprotocol/typescript-sdk#1503</a></li>
<li><a href="https://github.com/arimu1"><code>@​arimu1</code></a> made
their first contribution in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/2549">modelcontextprotocol/typescript-sdk#2549</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.29.0...1.30.0">https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.29.0...1.30.0</a></p>
<h2>v1.29.0</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: treat v1.x as primary branch for npm latest tag (backport <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1577">#1577</a>)
by <a
href="https://github.com/felixweinberger"><code>@​felixweinberger</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1749">modelcontextprotocol/typescript-sdk#1749</a></li>
<li>[v1.x] fix: disallow null (infinite) requested TTL by <a
href="https://github.com/LucaButBoring"><code>@​LucaButBoring</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1339">modelcontextprotocol/typescript-sdk#1339</a></li>
<li>[v1.x] fix: add missing size field to ResourceSchema by <a
href="https://github.com/olaservo"><code>@​olaservo</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1575">modelcontextprotocol/typescript-sdk#1575</a></li>
<li>Add typings exports by <a
href="https://github.com/tdraier"><code>@​tdraier</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1623">modelcontextprotocol/typescript-sdk#1623</a></li>
<li>v1.x npm audit fix by <a
href="https://github.com/KKonstantinov"><code>@​KKonstantinov</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1780">modelcontextprotocol/typescript-sdk#1780</a></li>
<li>v1.x <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/1623">#1623</a>
follow up -add missing types to package.json by <a
href="https://github.com/KKonstantinov"><code>@​KKonstantinov</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1773">modelcontextprotocol/typescript-sdk#1773</a></li>
<li>[v1.x backport] Allow servers / clients to advertise extensions in
the capability object by <a
href="https://github.com/localden"><code>@​localden</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1811">modelcontextprotocol/typescript-sdk#1811</a></li>
<li>fix(stdio): always set windowsHide on Windows, not just in Electron
by <a href="https://github.com/jnMetaCode"><code>@​jnMetaCode</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1640">modelcontextprotocol/typescript-sdk#1640</a></li>
<li>chore: bump version to 1.29.0 by <a
href="https://github.com/felixweinberger"><code>@​felixweinberger</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1820">modelcontextprotocol/typescript-sdk#1820</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/tdraier"><code>@​tdraier</code></a> made
their first contribution in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1623">modelcontextprotocol/typescript-sdk#1623</a></li>
<li><a
href="https://github.com/jnMetaCode"><code>@​jnMetaCode</code></a> made
their first contribution in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1640">modelcontextprotocol/typescript-sdk#1640</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.28.0...v1.29.0">https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.28.0...v1.29.0</a></p>
<h2>v1.28.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat: use scopes_supported from resource metadata by default (fixes
<a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/580">#580</a>)
by <a href="https://github.com/antogyn"><code>@​antogyn</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/757">modelcontextprotocol/typescript-sdk#757</a></li>
<li>[v1.x backport] Default to client_secret_basic when server omits
token_endpoint_auth_methods_supported by <a
href="https://github.com/pcarleton"><code>@​pcarleton</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1611">modelcontextprotocol/typescript-sdk#1611</a></li>
<li>fix: reject plain JSON Schema objects passed as inputSchema by <a
href="https://github.com/tiluckdave"><code>@​tiluckdave</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1596">modelcontextprotocol/typescript-sdk#1596</a></li>
<li>fix: clear _timeoutInfo in _onclose() and scope .finally() abort
controller cleanup by <a
href="https://github.com/pcarleton"><code>@​pcarleton</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1462">modelcontextprotocol/typescript-sdk#1462</a></li>
<li>fix(server/auth): RFC 8252 loopback port relaxation by <a
href="https://github.com/poteat"><code>@​poteat</code></a> in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1738">modelcontextprotocol/typescript-sdk#1738</a></li>
<li>chore: bump version to 1.28.0 by <a
href="https://github.com/felixweinberger"><code>@​felixweinberger</code></a>
in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1746">modelcontextprotocol/typescript-sdk#1746</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/antogyn"><code>@​antogyn</code></a> made
their first contribution in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/757">modelcontextprotocol/typescript-sdk#757</a></li>
<li><a
href="https://github.com/tiluckdave"><code>@​tiluckdave</code></a> made
their first contribution in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1596">modelcontextprotocol/typescript-sdk#1596</a></li>
<li><a href="https://github.com/poteat"><code>@​poteat</code></a> made
their first contribution in <a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/pull/1738">modelcontextprotocol/typescript-sdk#1738</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/2d889f2b329e46680ec9bdd565de4616c497825a"><code>2d889f2</code></a>
chore: bump version to 1.30.0 (<a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/2563">#2563</a>)</li>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/e3f3daa12cc2603919939b72136ce9d9e800b868"><code>e3f3daa</code></a>
Fix SSE keep-alive timer lifecycle in Streamable HTTP server transport
(v1.x)...</li>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/bb5a718cbf90796bacbf62218b359196d210426b"><code>bb5a718</code></a>
fix(deps): widen <code>@​hono/node-server</code> past
GHSA-frvp-7c67-39w9 (<a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/2549">#2549</a>)</li>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/1dad2634ce5799fb386283d14291d1b4935a9a52"><code>1dad263</code></a>
fix: send SSE keep-alive comment frames from Streamable HTTP server
transport...</li>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/69749aa5081ddfe675d36da8d96c7e27d83742b8"><code>69749aa</code></a>
Validate Content-Type by parsed media type instead of substring match
(v1.x) ...</li>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/369513df7b0e9d8a979c86f68ba1930e0d5f27f0"><code>369513d</code></a>
fix: support Zod 3.25 method literals (<a
href="https://redirect.github.com/modelcontextprotocol/typescript-sdk/issues/2368">#2368</a>)</li>
<li><a
href="https://github.com/modelcontextprotocol/typescript-sdk/commit/e7ee57c2f33b8290a78a3cefa27ab635fe67fbff"><code>e7ee57c</code></a>
v1 stdio buffer limit (<a
href="https://redirect.github.com/modelcontextprotocol...

_Description has been truncated_

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com>
2026-08-07 18:41:15 +05:30
dependabot[bot] 2cab683f0e chore(deps-dev): bump the npm-development group with 6 updates (#4091)
Bumps the npm-development group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [lint-staged](https://github.com/lint-staged/lint-staged) | `17.2.0` |
`17.3.0` |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) |
`1.76.0` | `1.77.0` |
|
[oxlint-plugin-eslint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint)
| `1.76.0` | `1.77.0` |
|
[@types/semver](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/semver)
| `7.7.1` | `7.8.0` |
|
[@earendil-works/pi-coding-agent](https://github.com/earendil-works/pi/tree/HEAD/packages/coding-agent)
| `0.82.1` | `0.83.0` |
| [eve](https://github.com/vercel/eve/tree/HEAD/packages/eve) |
`0.27.13` | `0.29.5` |

Updates `lint-staged` from 17.2.0 to 17.3.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lint-staged/lint-staged/releases">lint-staged's
releases</a>.</em></p>
<blockquote>
<h2>v17.3.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/lint-staged/lint-staged/pull/1825">#1825</a>
<a
href="https://github.com/lint-staged/lint-staged/commit/16b3f74850e5d2811b5fbaea6c136733a71ad3e4"><code>16b3f74</code></a>
- It is now possible to run multiple tasks in parallel for a single glob
by configuring it with an array of tasks (which run sequentially), and
then placing another array inside it (where the tasks will run in
parallel). The following demonstrates the order tasks will start in:</p>
<pre lang="json"><code>{
&quot;*.ts&quot;: [&quot;first&quot;, &quot;second&quot;,
[&quot;third&quot;, &quot;third&quot;], &quot;fourth&quot;]
}
</code></pre>
<p>As a concrete example, <em>lint-staged</em>'s own configuration
is:</p>
<pre lang="js"><code>/** @type {import('./lib/index.js').Configuration}
*/
export default {
  &quot;*&quot;: [
    [
      &quot;oxfmt --check --no-error-on-unmatched-pattern&quot;,
      &quot;oxlint --no-error-on-unmatched-pattern&quot;,
    ],
  ],
  &quot;*.ts&quot;: () =&gt; &quot;tsc&quot;,
};
</code></pre>
<p>which means:</p>
<ol>
<li>for all staged files, run the two commands in parallel with staged
filenames appended, for example:
<ul>
<li><code>oxfmt --check --no-error-on-unmatched-pattern
lib/index.js</code></li>
<li><code>oxlint --no-error-on-unmatched-pattern
lib/index.js</code></li>
</ul>
</li>
<li>additionally, if any <code>*.ts</code> files are staged, run
<code>tsc</code> without appending any arguments</li>
<li>The two sets of commands also run in parallel</li>
</ol>
</li>
</ul>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/lint-staged/lint-staged/pull/1829">#1829</a>
<a
href="https://github.com/lint-staged/lint-staged/commit/15f7e5314b4afe4702808d978758b22d42437f43"><code>15f7e53</code></a>
- During an in-progress merge, files that are unchanged from the branch
being merged are now skipped. Technically, files are only included if
there are staged changes against both <code>HEAD</code> and
<code>MERGE_HEAD</code>.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md">lint-staged's
changelog</a>.</em></p>
<blockquote>
<h2>17.3.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/lint-staged/lint-staged/pull/1825">#1825</a>
<a
href="https://github.com/lint-staged/lint-staged/commit/16b3f74850e5d2811b5fbaea6c136733a71ad3e4"><code>16b3f74</code></a>
- It is now possible to run multiple tasks in parallel for a single glob
by configuring it with an array of tasks (which run sequentially), and
then placing another array inside it (where the tasks will run in
parallel). The following demonstrates the order tasks will start in:</p>
<pre lang="json"><code>{
&quot;*.ts&quot;: [&quot;first&quot;, &quot;second&quot;,
[&quot;third&quot;, &quot;third&quot;], &quot;fourth&quot;]
}
</code></pre>
<p>As a concrete example, <em>lint-staged</em>'s own configuration
is:</p>
<pre lang="js"><code>/** @type {import('./lib/index.js').Configuration}
*/
export default {
  &quot;*&quot;: [
    [
      &quot;oxfmt --check --no-error-on-unmatched-pattern&quot;,
      &quot;oxlint --no-error-on-unmatched-pattern&quot;,
    ],
  ],
  &quot;*.ts&quot;: () =&gt; &quot;tsc&quot;,
};
</code></pre>
<p>which means:</p>
<ol>
<li>for all staged files, run the two commands in parallel with staged
filenames appended, for example:
<ul>
<li><code>oxfmt --check --no-error-on-unmatched-pattern
lib/index.js</code></li>
<li><code>oxlint --no-error-on-unmatched-pattern
lib/index.js</code></li>
</ul>
</li>
<li>additionally, if any <code>*.ts</code> files are staged, run
<code>tsc</code> without appending any arguments</li>
<li>The two sets of commands also run in parallel</li>
</ol>
</li>
</ul>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/lint-staged/lint-staged/pull/1829">#1829</a>
<a
href="https://github.com/lint-staged/lint-staged/commit/15f7e5314b4afe4702808d978758b22d42437f43"><code>15f7e53</code></a>
- During an in-progress merge, files that are unchanged from the branch
being merged are now skipped. Technically, files are only included if
there are staged changes against both <code>HEAD</code> and
<code>MERGE_HEAD</code>.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/lint-staged/lint-staged/commit/d15344350d914f5ce24df2c85f3ffebb9b387f3b"><code>d153443</code></a>
Merge pull request <a
href="https://redirect.github.com/lint-staged/lint-staged/issues/1828">#1828</a>
from lint-staged/changeset-release/main</li>
<li><a
href="https://github.com/lint-staged/lint-staged/commit/5162c149bbfa09b8a5ad4d37c647d63946568ca8"><code>5162c14</code></a>
chore(changeset): release</li>
<li><a
href="https://github.com/lint-staged/lint-staged/commit/a4db9a4c32f108d1397436752be7e9dda956baa2"><code>a4db9a4</code></a>
Merge pull request <a
href="https://redirect.github.com/lint-staged/lint-staged/issues/1831">#1831</a>
from lint-staged/linter-updates</li>
<li><a
href="https://github.com/lint-staged/lint-staged/commit/ea96cab0109ab44a5b2562927b890648ee32b4cc"><code>ea96cab</code></a>
style: enable oxlint &quot;suspicious&quot; category</li>
<li><a
href="https://github.com/lint-staged/lint-staged/commit/2fae00778cea0c99da9bcb8bad4718dce08ea04e"><code>2fae007</code></a>
style: add <code>@e18e/eslint-plugin</code></li>
<li><a
href="https://github.com/lint-staged/lint-staged/commit/2280c38a09ff4ca4db60320b5879e0029527afaa"><code>2280c38</code></a>
Merge pull request <a
href="https://redirect.github.com/lint-staged/lint-staged/issues/1829">#1829</a>
from lint-staged/fix-merge-conflict-files</li>
<li><a
href="https://github.com/lint-staged/lint-staged/commit/1453ae6ae0e05275d714ad0cad7cd090885f504d"><code>1453ae6</code></a>
test: relax assertion so that it passes in worktree</li>
<li><a
href="https://github.com/lint-staged/lint-staged/commit/15f7e5314b4afe4702808d978758b22d42437f43"><code>15f7e53</code></a>
fix: lint only files changed against HEAD and MERGE_HEAD, during a
merge</li>
<li><a
href="https://github.com/lint-staged/lint-staged/commit/dedfc31007aed50e1c9c5591a11085cb485ba41c"><code>dedfc31</code></a>
Merge pull request <a
href="https://redirect.github.com/lint-staged/lint-staged/issues/1825">#1825</a>
from lint-staged/parallel-tasks-inside-sequence</li>
<li><a
href="https://github.com/lint-staged/lint-staged/commit/286e25cef9fde2fb6e77d2312fd91ac99020d69d"><code>286e25c</code></a>
feat: allow running parallel tasks by nesting arrays</li>
<li>Additional commits viewable in <a
href="https://github.com/lint-staged/lint-staged/compare/v17.2.0...v17.3.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `oxlint` from 1.76.0 to 1.77.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/oxc-project/oxc/releases">oxlint's
releases</a>.</em></p>
<blockquote>
<h2>oxlint v1.27.0 &amp;&amp; oxfmt v0.12.0</h2>
<h1>Oxlint v1.27.0</h1>
<h3>🚀 Features</h3>
<ul>
<li>222a8f0 linter/plugins: Implement
<code>SourceCode#isSpaceBetween</code> (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15498">#15498</a>)
(overlookmotel)</li>
<li>2f9735d linter/plugins: Implement
<code>context.languageOptions</code> (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15486">#15486</a>)
(overlookmotel)</li>
<li>bc731ff linter/plugins: Stub out all <code>Context</code> APIs (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15479">#15479</a>)
(overlookmotel)</li>
<li>5822cb4 linter/plugins: Add <code>extend</code> method to
<code>FILE_CONTEXT</code> (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15477">#15477</a>)
(overlookmotel)</li>
<li>7b1e6f3 apps: Add pure rust binaries and release to github (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15469">#15469</a>)
(Boshen)</li>
<li>2a89b43 linter: Introduce debug assertions after fixes to assert
validity (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15389">#15389</a>)
(camc314)</li>
<li>ad3c45a editor: Add <code>oxc.path.node</code> option (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15040">#15040</a>)
(Sysix)</li>
</ul>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>6f3cd77 linter/no-var: Incorrect warning for blocks (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15504">#15504</a>)
(Hamir Mahal)</li>
<li>6957fb9 linter/plugins: Do not allow access to
<code>Context#id</code> in <code>createOnce</code> (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15489">#15489</a>)
(overlookmotel)</li>
<li>7409630 linter/plugins: Allow access to <code>cwd</code> in
<code>createOnce</code> in ESLint interop mode (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15488">#15488</a>)
(overlookmotel)</li>
<li>732205e parser: Reject <code>using</code> / <code>await using</code>
in a switch <code>case</code> / <code>default</code> clause (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15225">#15225</a>)
(sapphi-red)</li>
<li>a17ca32 linter/plugins: Replace <code>Context</code> class (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15448">#15448</a>)
(overlookmotel)</li>
<li>ecf2f7b language_server: Fail gracefully when tsgolint executable
not found (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15436">#15436</a>)
(camc314)</li>
<li>3c8d3a7 lang-server: Improve logging in failure case for tsgolint
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15299">#15299</a>)
(camc314)</li>
<li>ef71410 linter: Use jsx if source type is JS in fix debug assertion
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15434">#15434</a>)
(camc314)</li>
<li>e32bbf6 linter/no-var: Handle TypeScript declare keyword in fixer
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15426">#15426</a>)
(camc314)</li>
<li>6565dbe linter/switch-case-braces: Skip comments when searching for
<code>:</code> token (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15425">#15425</a>)
(camc314)</li>
<li>85bd19a linter/prefer-class-fields: Insert value after type
annotation in fixer (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15423">#15423</a>)
(camc314)</li>
<li>fde753e linter/plugins: Block access to
<code>context.settings</code> in <code>createOnce</code> (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15394">#15394</a>)
(overlookmotel)</li>
<li>ddd9f9f linter/forward-ref-uses-ref: Dont suggest removing wrapper
in invalid positions (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15388">#15388</a>)
(camc314)</li>
<li>dac2a9c linter/no-template-curly-in-string: Remove fixer (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15387">#15387</a>)
(camc314)</li>
<li>989b8e3 linter/no-var: Only fix to <code>const</code> if the var has
an initializer (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15385">#15385</a>)
(camc314)</li>
<li>cc403f5 linter/plugins: Return empty object for unimplemented
parserServices (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15364">#15364</a>)
(magic-akari)</li>
</ul>
<h3>⚡ Performance</h3>
<ul>
<li>25d577e language_server: Start tools in parallel (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15500">#15500</a>)
(Sysix)</li>
<li>3c57291 linter/plugins: Optimize loops (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15449">#15449</a>)
(overlookmotel)</li>
<li>3166233 linter/plugins: Remove <code>Arc</code>s (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15431">#15431</a>)
(overlookmotel)</li>
<li>9de1322 linter/plugins: Lazily deserialize settings JSON (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15395">#15395</a>)
(overlookmotel)</li>
<li>3049ec2 linter/plugins: Optimize <code>deepFreezeSettings</code> (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15392">#15392</a>)
(overlookmotel)</li>
<li>444ebfd linter/plugins: Use single object for
<code>parserServices</code> (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15378">#15378</a>)
(overlookmotel)</li>
</ul>
<h3>📚 Documentation</h3>
<ul>
<li>97d2104 linter: Update comment in lint.rs about default value for
tsconfig path (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15530">#15530</a>)
(Connor Shea)</li>
<li>2c6bd9e linter: Always refer as &quot;ES2015&quot; instead of
&quot;ES6&quot; (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15411">#15411</a>)
(sapphi-red)</li>
<li>a0c5203 linter/import/named: Update &quot;ES7&quot; comment in
examples (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15410">#15410</a>)
(sapphi-red)</li>
<li>3dc24b5 linter,minifier: Always refer as &quot;ES Modules&quot;
instead of &quot;ES6 Modules&quot; (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15409">#15409</a>)
(sapphi-red)</li>
<li>2ad77fb linter/no-this-before-super: Correct &quot;Why is this
bad?&quot; section (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15408">#15408</a>)
(sapphi-red)</li>
<li>57f0ce1 linter: Add backquotes where appropriate (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/15407">#15407</a>)
(sapphi-red)</li>
</ul>
<h1>Oxfmt v0.12.0</h1>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md">oxlint's
changelog</a>.</em></p>
<blockquote>
<h2>[1.77.0] - 2026-08-03</h2>
<h3>🐛 Bug Fixes</h3>
<ul>
<li>5c0fa61 linter/eslint/no-warning-comments: Unify config structs and
remove manual options docs (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25151">#25151</a>)
(Mikhail Baev)</li>
</ul>
<h3>📚 Documentation</h3>
<ul>
<li>9dc7756 linter/typescript/no-unnecessary-condition: Clarify options
(<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25110">#25110</a>)
(camc314)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/oxc-project/oxc/commit/9a423f2f485b79c2353c49442c0c7f60f900261d"><code>9a423f2</code></a>
release(apps): oxlint v1.77.0 &amp;&amp; oxfmt v0.62.0 (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25251">#25251</a>)</li>
<li><a
href="https://github.com/oxc-project/oxc/commit/5c0fa61ddbd098fea5101dff356dc9b67adbee95"><code>5c0fa61</code></a>
fix(linter/eslint/no-warning-comments): unify config structs and remove
manua...</li>
<li><a
href="https://github.com/oxc-project/oxc/commit/9dc77567291db6ebd0641284f80bf50163c6a257"><code>9dc7756</code></a>
docs(linter/typescript/no-unnecessary-condition): clarify options (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint/issues/25110">#25110</a>)</li>
<li>See full diff in <a
href="https://github.com/oxc-project/oxc/commits/oxlint_v1.77.0/npm/oxlint">compare
view</a></li>
</ul>
</details>
<br />

Updates `oxlint-plugin-eslint` from 1.76.0 to 1.77.0
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/oxc-project/oxc/commit/9a423f2f485b79c2353c49442c0c7f60f900261d"><code>9a423f2</code></a>
release(apps): oxlint v1.77.0 &amp;&amp; oxfmt v0.62.0 (<a
href="https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugin-eslint/issues/25251">#25251</a>)</li>
<li>See full diff in <a
href="https://github.com/oxc-project/oxc/commits/apps_v1.77.0/npm/oxlint-plugin-eslint">compare
view</a></li>
</ul>
</details>
<br />

Updates `@types/semver` from 7.7.1 to 7.8.0
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/semver">compare
view</a></li>
</ul>
</details>
<br />

Updates `@earendil-works/pi-coding-agent` from 0.82.1 to 0.83.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/earendil-works/pi/releases">@​earendil-works/pi-coding-agent's
releases</a>.</em></p>
<blockquote>
<h2>v0.83.0</h2>
<h3>New Features</h3>
<ul>
<li><strong>Credential export for external clients</strong> — <code>pi
auth print-api-key</code> and <code>pi auth print-bearer-token</code>
export configured credentials with automatic OAuth refresh and
minimum-validity enforcement.</li>
<li><strong>Headless OpenRouter sign-in</strong> — Complete
<code>/login</code> over SSH by pasting the redirect URL or
authorization code when the loopback callback is unavailable. See <a
href="https://github.com/earendil-works/pi/blob/v0.83.0/packages/coding-agent/docs/providers.md#openrouter">OpenRouter</a>.</li>
<li><strong>Claude Opus 5 on GitHub Copilot</strong> — Use Claude Opus 5
through GitHub Copilot with adaptive thinking and a 1M context window.
See <a
href="https://github.com/earendil-works/pi/blob/v0.83.0/packages/coding-agent/docs/providers.md#github-copilot">GitHub
Copilot</a>.</li>
</ul>
<h3>Breaking Changes</h3>
<ul>
<li>Upgraded bundled TypeBox aliases to 1.3.7, removing deprecated APIs
including <code>Type.Base</code>, <code>Type.Awaited</code>,
<code>Type.Promise</code>, <code>Type.AsyncIterator</code>,
<code>Type.Iterator</code>, <code>Type.Options</code>, and
<code>Value.Mutate</code>, while fixing compiled validation of nullable
array tool arguments. Extensions using removed APIs must migrate to
supported TypeBox APIs. See <a
href="https://github.com/earendil-works/pi/blob/v0.83.0/packages/coding-agent/docs/packages.md#dependencies">Package
Dependencies</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7243">#7243</a>
by <a
href="https://github.com/petrroll"><code>@​petrroll</code></a>).</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added <code>pi auth print-api-key</code> and <code>pi auth
print-bearer-token</code> commands for exporting configured credentials
to external clients, including automatic OAuth refresh and configurable
minimum token validity (<a
href="https://redirect.github.com/earendil-works/pi/pull/7168">#7168</a>).</li>
<li>Exposed the session's resolved model scope as
<code>ctx.scopedModels</code> to extensions. See <a
href="https://github.com/earendil-works/pi/blob/v0.83.0/packages/coding-agent/docs/extensions.md#ctxmodelregistry--ctxmodel--ctxthinkinglevel--ctxscopedmodels">Extension
Context</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7191">#7191</a>
by <a href="https://github.com/pungggi"><code>@​pungggi</code></a>, <a
href="https://redirect.github.com/earendil-works/pi/pull/7215">#7215</a>).</li>
<li>Added inherited per-request <code>fetch</code> injection for
supported text and image provider transports.</li>
<li>Added the inherited <code>&quot;pending&quot;</code> stop reason for
partial streaming messages. See <a
href="https://github.com/earendil-works/pi/blob/v0.83.0/packages/coding-agent/docs/custom-provider.md#stream-pattern">Custom
Provider Stream Pattern</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7151">#7151</a>
by <a
href="https://github.com/lucasmeijer"><code>@​lucasmeijer</code></a>).</li>
<li>Added inherited raw provider stop reasons across Google, Anthropic,
Amazon Bedrock, Mistral, and OpenAI streams; unmapped terminal reasons
now surface as provider errors instead of successful stops (<a
href="https://redirect.github.com/earendil-works/pi/pull/7272">#7272</a>).</li>
<li>Added manual redirect URL and authorization-code entry to OpenRouter
login for remote and headless environments. See <a
href="https://github.com/earendil-works/pi/blob/v0.83.0/packages/coding-agent/docs/providers.md#openrouter">OpenRouter</a>
(<a
href="https://redirect.github.com/earendil-works/pi/pull/7114">#7114</a>
by <a
href="https://github.com/rgarcia"><code>@​rgarcia</code></a>).</li>
<li>Added inherited Claude Opus 5 support for GitHub Copilot with
adaptive thinking and a 1M context window. See <a
href="https://github.com/earendil-works/pi/blob/v0.83.0/packages/coding-agent/docs/providers.md#github-copilot">GitHub
Copilot</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7158">#7158</a>
by <a
href="https://github.com/jay-aye-see-kay"><code>@​jay-aye-see-kay</code></a>).</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed inherited OAuth credential resolution to refresh tokens with
less than five minutes of validity remaining instead of waiting until
expiration (<a
href="https://redirect.github.com/earendil-works/pi/pull/7168">#7168</a>).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Added a status line when the tool output expansion is toggled (<a
href="https://redirect.github.com/earendil-works/pi/issues/7180">#7180</a>).</li>
<li>Fixed file-backed <code>SYSTEM.md</code> and
<code>APPEND_SYSTEM.md</code> prompts being omitted from the interactive
startup context listing. See <a
href="https://github.com/earendil-works/pi/blob/v0.83.0/packages/coding-agent/docs/usage.md#system-prompt-files">System
Prompt Files</a> (<a
href="https://redirect.github.com/earendil-works/pi/issues/7096">#7096</a>).</li>
<li>Fixed context files loading twice when a linked Git worktree is
nested under its main repository. See <a
href="https://github.com/earendil-works/pi/blob/v0.83.0/packages/coding-agent/docs/usage.md#context-files">Context
Files</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7221">#7221</a>
by <a
href="https://github.com/arajkumar"><code>@​arajkumar</code></a>).</li>
<li>Fixed llama.cpp streamed responses reporting zero token usage and
leaving session context accounting empty. See <a
href="https://github.com/earendil-works/pi/blob/v0.83.0/packages/coding-agent/docs/llama-cpp.md">llama.cpp</a>
(<a
href="https://redirect.github.com/earendil-works/pi/pull/7258">#7258</a>
by <a
href="https://github.com/SteveImmanuel"><code>@​SteveImmanuel</code></a>).</li>
<li>Fixed session replacement and committed tree navigation during an
active response to abort and persist the outgoing turn instead of
leaving dangling tool calls. See <a
href="https://github.com/earendil-works/pi/blob/v0.83.0/packages/coding-agent/docs/usage.md#sessions">Sessions</a>
(<a
href="https://redirect.github.com/earendil-works/pi/pull/7022">#7022</a>
by <a
href="https://github.com/tmustier"><code>@​tmustier</code></a>).</li>
<li>Fixed failed Git package installs leaving partial directories that
blocked clean retries. See <a
href="https://github.com/earendil-works/pi/blob/v0.83.0/packages/coding-agent/docs/packages.md#install-and-manage">Install
and Manage</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7210">#7210</a>
by <a
href="https://github.com/haoqixu"><code>@​haoqixu</code></a>).</li>
<li>Fixed the <code>/model</code> selector retaining a stale selection
while filtering instead of highlighting the top match (<a
href="https://redirect.github.com/earendil-works/pi/pull/7211">#7211</a>
by <a
href="https://github.com/christianbasch"><code>@​christianbasch</code></a>).</li>
<li>Fixed direct RPC bash commands bypassing extension
<code>user_bash</code> handlers. See <a
href="https://github.com/earendil-works/pi/blob/v0.83.0/packages/coding-agent/docs/extensions.md#user-bash-events">User
Bash Events</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7214">#7214</a>).</li>
<li>Fixed skills, prompts, and themes losing package source metadata
after extensions reload resources. See <a
href="https://github.com/earendil-works/pi/blob/v0.83.0/packages/coding-agent/docs/extensions.md#resource-events">Resource
Events</a> (<a
href="https://redirect.github.com/earendil-works/pi/issues/6968">#6968</a>).</li>
<li>Fixed cancellation of concurrently running user bash commands so
every active command is aborted (<a
href="https://redirect.github.com/earendil-works/pi/pull/7103">#7103</a>
by <a
href="https://github.com/yzhg1983"><code>@​yzhg1983</code></a>).</li>
<li>Fixed duplicate messages appearing when extensions switch sessions
during interactive startup (<a
href="https://redirect.github.com/earendil-works/pi/pull/7110">#7110</a>
by <a
href="https://github.com/yzhg1983"><code>@​yzhg1983</code></a>).</li>
<li>Fixed inherited Qwen Token Plan reasoning models to send their
service-specific thinking controls and supported reasoning-effort levels
(<a
href="https://redirect.github.com/earendil-works/pi/issues/6951">#6951</a>,
<a
href="https://redirect.github.com/earendil-works/pi/issues/6998">#6998</a>).</li>
<li>Fixed inherited Z.AI output limits being sent through an unsupported
parameter. See <a
href="https://github.com/earendil-works/pi/blob/v0.83.0/packages/coding-agent/docs/providers.md">Providers</a>
(<a
href="https://redirect.github.com/earendil-works/pi/pull/7174">#7174</a>
by <a
href="https://github.com/HyeokjaeLee"><code>@​HyeokjaeLee</code></a>).</li>
<li>Fixed explicitly configured Amazon Bedrock profiles being overridden
by ambient AWS access keys. See <a
href="https://github.com/earendil-works/pi/blob/v0.83.0/packages/coding-agent/docs/providers.md#amazon-bedrock">Amazon
Bedrock</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7176">#7176</a>
by <a
href="https://github.com/christianbasch"><code>@​christianbasch</code></a>).</li>
<li>Fixed inherited image fallback paths overflowing narrow terminals,
shortened home-directory paths, and made absolute paths clickable when
terminal hyperlinks are available (<a
href="https://redirect.github.com/earendil-works/pi/pull/7262">#7262</a>).</li>
<li>Fixed inherited OpenAI-compatible tool calls losing their function
arguments when malformed deltas also contain an empty
<code>custom</code> object (<a
href="https://redirect.github.com/earendil-works/pi/pull/7288">#7288</a>
by <a
href="https://github.com/sunnyyoung"><code>@​sunnyyoung</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/CHANGELOG.md">@​earendil-works/pi-coding-agent's
changelog</a>.</em></p>
<blockquote>
<h2>[0.83.0] - 2026-07-29</h2>
<h3>New Features</h3>
<ul>
<li><strong>Credential export for external clients</strong> — <code>pi
auth print-api-key</code> and <code>pi auth print-bearer-token</code>
export configured credentials with automatic OAuth refresh and
minimum-validity enforcement.</li>
<li><strong>Headless OpenRouter sign-in</strong> — Complete
<code>/login</code> over SSH by pasting the redirect URL or
authorization code when the loopback callback is unavailable. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/providers.md#openrouter">OpenRouter</a>.</li>
<li><strong>Claude Opus 5 on GitHub Copilot</strong> — Use Claude Opus 5
through GitHub Copilot with adaptive thinking and a 1M context window.
See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/providers.md#github-copilot">GitHub
Copilot</a>.</li>
</ul>
<h3>Breaking Changes</h3>
<ul>
<li>Upgraded bundled TypeBox aliases to 1.3.7, removing deprecated APIs
including <code>Type.Base</code>, <code>Type.Awaited</code>,
<code>Type.Promise</code>, <code>Type.AsyncIterator</code>,
<code>Type.Iterator</code>, <code>Type.Options</code>, and
<code>Value.Mutate</code>, while fixing compiled validation of nullable
array tool arguments. Extensions using removed APIs must migrate to
supported TypeBox APIs. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/packages.md#dependencies">Package
Dependencies</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7243">#7243</a>
by <a
href="https://github.com/petrroll"><code>@​petrroll</code></a>).</li>
</ul>
<h3>Added</h3>
<ul>
<li>Added <code>pi auth print-api-key</code> and <code>pi auth
print-bearer-token</code> commands for exporting configured credentials
to external clients, including automatic OAuth refresh and configurable
minimum token validity (<a
href="https://redirect.github.com/earendil-works/pi/pull/7168">#7168</a>).</li>
<li>Exposed the session's resolved model scope as
<code>ctx.scopedModels</code> to extensions. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/extensions.md#ctxmodelregistry--ctxmodel--ctxthinkinglevel--ctxscopedmodels">Extension
Context</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7191">#7191</a>
by <a href="https://github.com/pungggi"><code>@​pungggi</code></a>, <a
href="https://redirect.github.com/earendil-works/pi/pull/7215">#7215</a>).</li>
<li>Added inherited per-request <code>fetch</code> injection for
supported text and image provider transports.</li>
<li>Added the inherited <code>&quot;pending&quot;</code> stop reason for
partial streaming messages. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/custom-provider.md#stream-pattern">Custom
Provider Stream Pattern</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7151">#7151</a>
by <a
href="https://github.com/lucasmeijer"><code>@​lucasmeijer</code></a>).</li>
<li>Added inherited raw provider stop reasons across Google, Anthropic,
Amazon Bedrock, Mistral, and OpenAI streams; unmapped terminal reasons
now surface as provider errors instead of successful stops (<a
href="https://redirect.github.com/earendil-works/pi/pull/7272">#7272</a>).</li>
<li>Added manual redirect URL and authorization-code entry to OpenRouter
login for remote and headless environments. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/providers.md#openrouter">OpenRouter</a>
(<a
href="https://redirect.github.com/earendil-works/pi/pull/7114">#7114</a>
by <a
href="https://github.com/rgarcia"><code>@​rgarcia</code></a>).</li>
<li>Added inherited Claude Opus 5 support for GitHub Copilot with
adaptive thinking and a 1M context window. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/providers.md#github-copilot">GitHub
Copilot</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7158">#7158</a>
by <a
href="https://github.com/jay-aye-see-kay"><code>@​jay-aye-see-kay</code></a>).</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed inherited OAuth credential resolution to refresh tokens with
less than five minutes of validity remaining instead of waiting until
expiration (<a
href="https://redirect.github.com/earendil-works/pi/pull/7168">#7168</a>).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Added a status line when the tool output expansion is toggled (<a
href="https://redirect.github.com/earendil-works/pi/issues/7180">#7180</a>).</li>
<li>Fixed file-backed <code>SYSTEM.md</code> and
<code>APPEND_SYSTEM.md</code> prompts being omitted from the interactive
startup context listing. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/usage.md#system-prompt-files">System
Prompt Files</a> (<a
href="https://redirect.github.com/earendil-works/pi/issues/7096">#7096</a>).</li>
<li>Fixed context files loading twice when a linked Git worktree is
nested under its main repository. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/usage.md#context-files">Context
Files</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7221">#7221</a>
by <a
href="https://github.com/arajkumar"><code>@​arajkumar</code></a>).</li>
<li>Fixed llama.cpp streamed responses reporting zero token usage and
leaving session context accounting empty. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/llama-cpp.md">llama.cpp</a>
(<a
href="https://redirect.github.com/earendil-works/pi/pull/7258">#7258</a>
by <a
href="https://github.com/SteveImmanuel"><code>@​SteveImmanuel</code></a>).</li>
<li>Fixed session replacement and committed tree navigation during an
active response to abort and persist the outgoing turn instead of
leaving dangling tool calls. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/usage.md#sessions">Sessions</a>
(<a
href="https://redirect.github.com/earendil-works/pi/pull/7022">#7022</a>
by <a
href="https://github.com/tmustier"><code>@​tmustier</code></a>).</li>
<li>Fixed failed Git package installs leaving partial directories that
blocked clean retries. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/packages.md#install-and-manage">Install
and Manage</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7210">#7210</a>
by <a
href="https://github.com/haoqixu"><code>@​haoqixu</code></a>).</li>
<li>Fixed the <code>/model</code> selector retaining a stale selection
while filtering instead of highlighting the top match (<a
href="https://redirect.github.com/earendil-works/pi/pull/7211">#7211</a>
by <a
href="https://github.com/christianbasch"><code>@​christianbasch</code></a>).</li>
<li>Fixed direct RPC bash commands bypassing extension
<code>user_bash</code> handlers. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/extensions.md#user-bash-events">User
Bash Events</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7214">#7214</a>).</li>
<li>Fixed skills, prompts, and themes losing package source metadata
after extensions reload resources. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/extensions.md#resource-events">Resource
Events</a> (<a
href="https://redirect.github.com/earendil-works/pi/issues/6968">#6968</a>).</li>
<li>Fixed cancellation of concurrently running user bash commands so
every active command is aborted (<a
href="https://redirect.github.com/earendil-works/pi/pull/7103">#7103</a>
by <a
href="https://github.com/yzhg1983"><code>@​yzhg1983</code></a>).</li>
<li>Fixed duplicate messages appearing when extensions switch sessions
during interactive startup (<a
href="https://redirect.github.com/earendil-works/pi/pull/7110">#7110</a>
by <a
href="https://github.com/yzhg1983"><code>@​yzhg1983</code></a>).</li>
<li>Fixed inherited Qwen Token Plan reasoning models to send their
service-specific thinking controls and supported reasoning-effort levels
(<a
href="https://redirect.github.com/earendil-works/pi/issues/6951">#6951</a>,
<a
href="https://redirect.github.com/earendil-works/pi/issues/6998">#6998</a>).</li>
<li>Fixed inherited Z.AI output limits being sent through an unsupported
parameter. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/providers.md">Providers</a>
(<a
href="https://redirect.github.com/earendil-works/pi/pull/7174">#7174</a>
by <a
href="https://github.com/HyeokjaeLee"><code>@​HyeokjaeLee</code></a>).</li>
<li>Fixed explicitly configured Amazon Bedrock profiles being overridden
by ambient AWS access keys. See <a
href="https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/providers.md#amazon-bedrock">Amazon
Bedrock</a> (<a
href="https://redirect.github.com/earendil-works/pi/pull/7176">#7176</a>
by <a
href="https://github.com/christianbasch"><code>@​christianbasch</code></a>).</li>
<li>Fixed inherited image fallback paths overflowing narrow terminals,
shortened home-directory paths, and made absolute paths clickable when
terminal hyperlinks are available (<a
href="https://redirect.github.com/earendil-works/pi/pull/7262">#7262</a>).</li>
<li>Fixed inherited OpenAI-compatible tool calls losing their function
arguments when malformed deltas also contain an empty
<code>custom</code> object (<a
href="https://redirect.github.com/earendil-works/pi/pull/7288">#7288</a>
by <a
href="https://github.com/sunnyyoung"><code>@​sunnyyoung</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/earendil-works/pi/commit/845d6ff1f6643aba440341cce877ce1c43ebbc39"><code>845d6ff</code></a>
Release v0.83.0</li>
<li><a
href="https://github.com/earendil-works/pi/commit/f0499a63ff5563ff041c689f680ecbf01436a5e2"><code>f0499a6</code></a>
docs: audit changelogs since v0.82.1</li>
<li><a
href="https://github.com/earendil-works/pi/commit/bff5ab71743b442efa234dbed369e0a96da791f3"><code>bff5ab7</code></a>
fix(coding-agent): show system prompt files in startup context (<a
href="https://github.com/earendil-works/pi/tree/HEAD/packages/coding-agent/issues/7266">#7266</a>)</li>
<li><a
href="https://github.com/earendil-works/pi/commit/cced6a21da273b26ee4a23a803680614bbe8dd1e"><code>cced6a2</code></a>
fix(coding-agent): stop loading AGENTS.md twice in nested git worktrees
(<a
href="https://github.com/earendil-works/pi/tree/HEAD/packages/coding-agent/issues/7221">#7221</a>)</li>
<li><a
href="https://github.com/earendil-works/pi/commit/f9476a61e557bfdce2fbf3ffeaad0988fe47c184"><code>f9476a6</code></a>
fix(ai): update TypeBox nullable array validation (<a
href="https://github.com/earendil-works/pi/tree/HEAD/packages/coding-agent/issues/7243">#7243</a>)</li>
<li><a
href="https://github.com/earendil-works/pi/commit/0c32e83a352a4284133b2544f730a23814948ac3"><code>0c32e83</code></a>
fix(coding-agent): enable streaming usage for llama.cpp provider (<a
href="https://github.com/earendil-works/pi/tree/HEAD/packages/coding-agent/issues/7258">#7258</a>)</li>
<li><a
href="https://github.com/earendil-works/pi/commit/47ca25fcd8535b80710fad5be758f1f2cf81443c"><code>47ca25f</code></a>
Revert &quot;fix(coding-agent): build-check-test (<a
href="https://github.com/earendil-works/pi/tree/HEAD/packages/coding-agent/issues/7206">#7206</a>)&quot;</li>
<li><a
href="https://github.com/earendil-works/pi/commit/0d008b746892ad33d3fe15c0c4bc86a14369e0e8"><code>0d008b7</code></a>
fix(coding-agent): show tool expansion status</li>
<li><a
href="https://github.com/earendil-works/pi/commit/f14519551682cd0fddac2e4b4e8b1f333667e94c"><code>f145195</code></a>
fix(coding-agent): build-check-test (<a
href="https://github.com/earendil-works/pi/tree/HEAD/packages/coding-agent/issues/7206">#7206</a>)</li>
<li><a
href="https://github.com/earendil-works/pi/commit/cefa40ed8f8dbcd6ffd67b5e7a0eaa75a5050d1a"><code>cefa40e</code></a>
***WIP it's a PoC *** fix(coding-agent): guard tree navigation during
respons...</li>
<li>Additional commits viewable in <a
href="https://github.com/earendil-works/pi/commits/v0.83.0/packages/coding-agent">compare
view</a></li>
</ul>
</details>
<br />

Updates `eve` from 0.27.13 to 0.29.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/eve/releases">eve's
releases</a>.</em></p>
<blockquote>
<h2>eve@0.29.5</h2>
<h3>Patch Changes</h3>
<ul>
<li>c0dc572: Rename the TUI <code>/new</code> command to
<code>/reset</code> so session reset uses the same name across the
client, HTTP, channel, and TUI APIs.</li>
<li>3dce30a: Add manual session compaction through custom-channel
helpers, the eve HTTP client, and the <code>eve dev</code> TUI's
<code>/compact</code> command. Compaction preserves the session, queues
behind an active turn, and does not send synthetic model input.</li>
<li>910805e: Make a single <code>Esc</code> cancel the running turn in
the eve dev TUI when no message is queued. Queued messages still use
<code>Esc</code> to steer the oldest message into the next turn.</li>
<li>9c51755: Connection search and discovered connection tools now use
the same <code>defineDynamic</code> and <code>defineTool</code> pipeline
as authored tools. Dynamic tool maps now reject entries that omit
<code>defineTool</code> instead of accepting unsupported raw
objects.</li>
<li>84aa671: Clarify the dev TUI’s <code>/add</code> flow with
consistent integration categories and category-specific browsing labels.
MCP connections are now named explicitly, and the flow more clearly
explains channels, extensions, and observability integrations.</li>
<li>0c28eb7: Allow declared subagents to export
<code>defineDynamic</code> from <code>agent.ts</code>. Session and turn
resolvers can now return an agent configuration to expose it or nil to
omit it from direct and Workflow delegation.</li>
<li>f3bb60d: Add manual session-context clearing through custom-channel
helpers, the eve HTTP client, and the <code>eve dev</code> TUI's
<code>/clear</code> command. Clearing removes model-message history
while preserving the session, agent configuration, durable state,
limits, and sandbox.</li>
<li>ac7d3c6: Add <code>/cancel</code> to the eve dev TUI. The command
cooperatively cancels a running turn from either the live streaming
input or the idle prompt while preserving the session and settled
context.</li>
</ul>
<h2>eve@0.29.4</h2>
<h3>Patch Changes</h3>
<ul>
<li>e90a8c2: Launch local or deployed eve applications as stable ACP v1
agents with <code>eve acp [url]</code>, including streamed messages,
tool activity, human input, cancellation, concurrent sessions, and
verified Vercel authentication.</li>
<li>cec672d: Add guided Discord setup through <code>eve add
channel/discord</code>, including Vercel Connect provisioning, trigger
attachment, interactions endpoint configuration, slash-command
registration, and channel scaffolding.</li>
<li>ed328e7: Render registry item titles with their exact
registry-provided casing by loading manifests for each page of catalog
results.</li>
<li>c875a67: Update the generated <code>AGENTS.md</code> to direct
coding agents to the eve registry for discovering and installing
integrations.</li>
<li>5153b13: Add JSON output to <code>eve registry list</code> and
<code>eve registry search</code> for scripts that inspect registry
catalogs.</li>
<li>155d46a: Connection registry items now configure their Vercel
Connect connector during <code>eve add</code>, and registry setup
commands close their IPC channel after reporting an outcome so
<code>/add</code> returns instead of remaining stuck.</li>
<li>6f3daca: Add <code>ClientSession.snapshot()</code> for reading a
finite, cursor-consistent session event prefix that can hydrate
server-rendered applications.</li>
<li>67bfc76: Resolve sandbox skill roots and seed-file paths through the
same <code>$HOME</code> resolver the file tools use, so the skills
location is spelled once instead of twice.</li>
<li>a5acde8: Ensure exiting the dev TUI shuts down its owned server and
any surviving workflow processes before the CLI exits. Persisted
workflow messages now reach the ready worker during restart instead of
being rejected while the file watcher starts.</li>
<li>731464f: Give the local trace spool's on-disk layout a single owner:
the shared trace reader now exposes the listing and segment-read
primitives that <code>eve traces</code> and the <code>/traces</code>
viewer both use, and payload formatting is shared between the detail
panel and the conversation view.</li>
<li>f7ba3b3: Derive the <code>/traces</code> conversation viewer's line
geometry from one prefix-sum helper so scroll, click, and wheel math
cannot disagree, and reset the view through a single factory when the
viewed trace changes.</li>
<li>3f4bb9c: The <code>/traces</code> viewer now follows your terminal's
colors instead of forcing a hardcoded black/grey truecolor palette. It
probes the terminal's default background (OSC 11) and derives its card
surfaces from your own theme — subtly elevated bands on dark and light
backgrounds alike, with red bands for failures, and card titles that
invert to black on light backgrounds so they stay legible. Terminals
that don't answer the probe get a clean gutter-rail rendering drawn
entirely with the shared TUI theme.</li>
<li>f5d0533: Derive the dev TUI's slash-command suggestion window from
the command registry instead of a hand-maintained constant, and collapse
the duplicated cursor step in the terminal line-wrap loop.</li>
</ul>
<h2>eve@0.29.3</h2>
<h3>Patch Changes</h3>
<ul>
<li>22bfa02: Add guided Photon setup through <code>eve add
channel/photon-imessage</code>, including project creation, phone
registration, Vercel Connect or portable credentials, and channel
scaffolding.</li>
<li>0c0de19: Add an opt-in experimental steering policy to Chat SDK
sends that cancels an active turn before delivering its replacement
message.</li>
<li>b00a79d: Add <code>photonIMessageChannel</code>, a first-class
Photon iMessage channel with lazy credentials, Vercel OIDC webhook
verification, and automatic eve session routing.</li>
<li>495e93b: Resolve leading <code>$HOME</code> paths in the built-in
<code>read_file</code>, <code>write_file</code>, <code>glob</code>, and
<code>grep</code> tools so agents can directly access packaged skill
references advertised in their prompt.</li>
<li>bf01952: Local trace spans now capture model and tool payloads: the
system prompt, prompt messages, and response text/reasoning/tool calls
on model spans, and call arguments/results on tool spans, each capped at
32 KB with provider transport metadata stripped. Set
<code>EVE_TRACES_CONTENT=off</code> to keep payloads out of the
spool.</li>
<li>680db59: Provider-executed tool calls (like a gateway's
<code>web_search</code>) now show up in local traces: their calls and
results are captured on the model span and the <code>/traces</code>
viewer renders them as tool cards, with oversized outputs truncated to
stay valid JSON.</li>
<li>7ab6d8a: Terminal text wrapping in the dev TUI is now linear-time,
so views rendering large single-line payloads (long tool results, big
JSON) no longer stall on every repaint.</li>
<li>52cee9c: Consolidate the three Vercel CLI subprocess runners onto
one shared lifecycle. A <code>vercel</code> lookup killed by a signal
(for example Ctrl-C during setup) now reports a cancellation failure
instead of resolving as a success with truncated output.</li>
<li>7703448: The local trace spool reader behind <code>eve traces</code>
moved into a shared internal module; command behavior is unchanged.</li>
<li>2d87acb: Subagent turn spans now record the dispatch that created
them —
<code>agent.parent.session.id</code>, <code>agent.parent.turn.id</code>,
<code>agent.parent.call_id</code>, and
<code>agent.subagent.name</code> — so a parent turn that fans out to
several children can
be attributed to the exact tool call behind each one.</li>
<li>3c846bc: The <code>/traces</code> viewer supports drag-to-select:
dragging with the mouse highlights text and releasing copies it to the
clipboard (OSC 52 with tmux passthrough, plus the platform clipboard
command) with a confirmation toast. Clicks now act on release so drags
never toggle cards, and Esc cancels an in-flight selection.</li>
<li>3645c6e: The <code>/traces</code> viewer frame breathes: padding
rows around the title and above the footer hints, the copy toast floats
top-right as a small surface with a left edge bar, and the scroll wheel
scrolls the attributes drawer when the pointer is over it.</li>
<li>8858403: The local tracing subsystem (spool writer/reader,
retention, the zero-config local OTel runtime, and agent span capture)
moved from <code>src/harness</code> into its own
<code>src/tracing</code> module; no behavior change.</li>
<li>9adb455: Adds a <code>/traces</code> command to the dev TUI: a
full-screen live viewer over the local trace spool that re-tells each
trace as a chat-style conversation — system prompt, user and assistant
messages, and tool calls render as expandable cards (arrow keys or mouse
click to expand/collapse), with a right-side metadata drawer. Subagent
turns are badged with their dispatch lineage
(<code>subagent:&lt;name&gt;</code>), and the viewer opens on the trace
containing the current session — including windowed sessions and
subagent children recorded into a parent's trace. Expanded cards scroll
line-by-line so content taller than the viewport is fully readable.
Model spans with errors, token usage, or tool calls (but no text) now
appear as cards instead of disappearing. Terminal escape sequences in
trace payloads are stripped at render time. Tool-call arguments and
results are captured without stripping domain-level
<code>providerOptions</code>/<code>providerMetadata</code> keys. A
single prompt message over 32 KiB is truncated at the text level so the
serialized JSON stays parseable. Local spans capture system prompt,
prompt messages, responses, reasoning, and tool arguments/results
(<code>EVE_TRACES_CONTENT=off</code> to disable); long conversations
truncate oldest messages first with an omission marker.</li>
<li>275271d: Subagent runs now record into the trace of the session that
dispatched them instead of a disconnected trace of their own, and
<code>eve traces</code> resolves either session id to it. Local traces
also open a real <code>agent.session</code> root span rather than a
synthesized parent, so an authored OTel sampler's root rule decides
whether a session is sampled, and a session long enough to outgrow one
trace rolls into numbered windows that <code>eve traces
&lt;session-id&gt;</code> lists oldest first. Rows whose lifetime
outlives the worker that opened them — <code>agent.session</code> and
<code>agent.turn</code> — now show the extent of their descendants
instead of <code>0ms</code>.</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/eve/blob/main/packages/eve/CHANGELOG.md">eve's
changelog</a>.</em></p>
<blockquote>
<h2>0.29.5</h2>
<h3>Patch Changes</h3>
<ul>
<li>c0dc572: Rename the TUI <code>/new</code> command to
<code>/reset</code> so session reset uses the same name across the
client, HTTP, channel, and TUI APIs.</li>
<li>3dce30a: Add manual session compaction through custom-channel
helpers, the eve HTTP client, and the <code>eve dev</code> TUI's
<code>/compact</code> command. Compaction preserves the session, queues
behind an active turn, and does not send synthetic model input.</li>
<li>910805e: Make a single <code>Esc</code> cancel the running turn in
the eve dev TUI when no message is queued. Queued messages still use
<code>Esc</code> to steer the oldest message into the next turn.</li>
<li>9c51755: Connection search and discovered connection tools now use
the same <code>defineDynamic</code> and <code>defineTool</code> pipeline
as authored tools. Dynamic tool maps now reject entries that omit
<code>defineTool</code> instead of accepting unsupported raw
objects.</li>
<li>84aa671: Clarify the dev TUI’s <code>/add</code> flow with
consistent integration categories and category-specific browsing labels.
MCP connections are now named explicitly, and the flow more clearly
explains channels, extensions, and observability integrations.</li>
<li>0c28eb7: Allow declared subagents to export
<code>defineDynamic</code> from <code>agent.ts</code>. Session and turn
resolvers can now return an agent configuration to expose it or nil to
omit it from direct and Workflow delegation.</li>
<li>f3bb60d: Add manual session-context clearing through custom-channel
helpers, the eve HTTP client, and the <code>eve dev</code> TUI's
<code>/clear</code> command. Clearing removes model-message history
while preserving the session, agent configuration, durable state,
limits, and sandbox.</li>
<li>ac7d3c6: Add <code>/cancel</code> to the eve dev TUI. The command
cooperatively cancels a running turn from either the live streaming
input or the idle prompt while preserving the session and settled
context.</li>
</ul>
<h2>0.29.4</h2>
<h3>Patch Changes</h3>
<ul>
<li>e90a8c2: Launch local or deployed eve applications as stable ACP v1
agents with <code>eve acp [url]</code>, including streamed messages,
tool activity, human input, cancellation, concurrent sessions, and
verified Vercel authentication.</li>
<li>cec672d: Add guided Discord setup through <code>eve add
channel/discord</code>, including Vercel Connect provisioning, trigger
attachment, interactions endpoint configuration, slash-command
registration, and channel scaffolding.</li>
<li>ed328e7: Render registry item titles with their exact
registry-provided casing by loading manifests for each page of catalog
results.</li>
<li>c875a67: Update the generated <code>AGENTS.md</code> to direct
coding agents to the eve registry for discovering and installing
integrations.</li>
<li>5153b13: Add JSON output to <code>eve registry list</code> and
<code>eve registry search</code> for scripts that inspect registry
catalogs.</li>
<li>155d46a: Connection registry items now configure their Vercel
Connect connector during <code>eve add</code>, and registry setup
commands close their IPC channel after reporting an outcome so
<code>/add</code> returns instead of remaining stuck.</li>
<li>6f3daca: Add <code>ClientSession.snapshot()</code> for reading a
finite, cursor-consistent session event prefix that can hydrate
server-rendered applications.</li>
<li>67bfc76: Resolve sandbox skill roots and seed-file paths through the
same <code>$HOME</code> resolver the file tools use, so the skills
location is spelled once instead of twice.</li>
<li>a5acde8: Ensure exiting the dev TUI shuts down its owned server and
any surviving workflow processes before the CLI exits. Persisted
workflow messages now reach the ready worker during restart instead of
being rejected while the file watcher starts.</li>
<li>731464f: Give the local trace spool's on-disk layout a single owner:
the shared trace reader now exposes the listing and segment-read
primitives that <code>eve traces</code> and the <code>/traces</code>
viewer both use, and payload formatting is shared between the detail
panel and the conversation view.</li>
<li>f7ba3b3: Derive the <code>/traces</code> conversation viewer's line
geometry from one prefix-sum helper so scroll, click, and wheel math
cannot disagree, and reset the view through a single factory when the
viewed trace changes.</li>
<li>3f4bb9c: The <code>/traces</code> viewer now follows your terminal's
colors instead of forcing a hardcoded black/grey truecolor palette. It
probes the terminal's default background (OSC 11) and derives its card
surfaces from your own theme — subtly elevated bands on dark and light
backgrounds alike, with red bands for failures, and card titles that
invert to black on light backgrounds so they stay legible. Terminals
that don't answer the probe get a clean gutter-rail rendering drawn
entirely with the shared TUI theme.</li>
<li>f5d0533: Derive the dev TUI's slash-command suggestion window from
the command registry instead of a hand-maintained constant, and collapse
the duplicated cursor step in the terminal line-wrap loop.</li>
</ul>
<h2>0.29.3</h2>
<h3>Patch Changes</h3>
<ul>
<li>22bfa02: Add guided Photon setup through <code>eve add
channel/photon-imessage</code>, including project creation, phone
registration, Vercel Connect or portable credentials, and channel
scaffolding.</li>
<li>0c0de19: Add an opt-in experimental steering policy to Chat SDK
sends that cancels an active turn before delivering its replacement
message.</li>
<li>b00a79d: Add <code>photonIMessageChannel</code>, a first-class
Photon iMessage channel with lazy credentials, Vercel OIDC webhook
verification, and automatic eve session routing.</li>
<li>495e93b: Resolve leading <code>$HOME</code> paths in the built-in
<code>read_file</code>, <code>write_file</code>, <code>glob</code>, and
<code>grep</code> tools so agents can directly access packaged skill
references advertised in their prompt.</li>
<li>bf01952: Local trace spans now capture model and tool payloads: the
system prompt, prompt messages, and response text/reasoning/tool calls
on model spans, and call arguments/results on tool spans, each capped at
32 KB with provider transport metadata stripped. Set
<code>EVE_TRACES_CONTENT=off</code> to keep payloads out of the
spool.</li>
<li>680db59: Provider-executed tool calls (like a gateway's
<code>web_search</code>) now show up in local traces: their calls and
results are captured on the model span and the <code>/traces</code>
viewer renders them as tool cards, with oversized outputs truncated to
stay valid JSON.</li>
<li>7ab6d8a: Terminal text wrapping in the dev TUI is now linear-time,
so views rendering large single-line payloads (long tool results, big
JSON) no longer stall on every repaint.</li>
<li>52cee9c: Consolidate the three Vercel CLI subprocess runners onto
one shared lifecycle. A <code>vercel</code> lookup killed by a signal
(for example Ctrl-C during setup) now reports a cancellation failure
instead of resolving as a success with truncated output.</li>
<li>7703448: The local trace spool reader behind <code>eve traces</code>
moved into a shared internal module; command behavior is unchanged.</li>
<li>2d87acb: Subagent turn spans now record the dispatch that created
them —
<code>agent.parent.session.id</code>, <code>agent.parent.turn.id</code>,
<code>agent.parent.call_id</code>, and
<code>agent.subagent.name</code> — so a parent turn that fans out to
several children can
be attributed to the exact tool call behind each one.</li>
<li>3c846bc: The <code>/traces</code> viewer supports drag-to-select:
dragging with the mouse highlights text and releasing copies it to the
clipboard (OSC 52 with tmux passthrough, plus the platform clipboard
command) with a confirmation toast. Clicks now act on release so drags
never toggle cards, and Esc cancels an in-flight selection.</li>
<li>3645c6e: The <code>/traces</code> viewer frame breathes: padding
rows around the title and above the footer hints, the copy toast floats
top-right as a small surface with a left edge bar, and the scroll wheel
scrolls the attributes drawer when the pointer is over it.</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vercel/eve/commit/8988139097d1e1a1f1aca9b2828e63408848fccf"><code>8988139</code></a>
Version Packages (<a
href="https://github.com/vercel/eve/tree/HEAD/packages/eve/issues/1497">#1497</a>)</li>
<li><a
href="https://github.com/vercel/eve/commit/c0dc57240ec850b0f73075f0e3cc900c6e07640a"><code>c0dc572</code></a>
feat(tui): rename /new command to /reset (<a
href="https://github.com/vercel/eve/tree/HEAD/packages/eve/issues/1513">#1513</a>)</li>
<li><a
href="https://github.com/vercel/eve/commit/910805e8a825a34ba90c0a22a59dc1d787967976"><code>910805e</code></a>
feat(tui): cancel with one Esc press (<a
href="https://github.com/vercel/eve/tree/HEAD/packages/eve/issues/1514">#1514</a>)</li>
<li><a
href="https://github.com/vercel/eve/commit/ac7d3c66f8c43ce1008d88cedd5254bfec1301e1"><code>ac7d3c6</code></a>
feat(tui): add /cancel command (<a
href="https://github.com/vercel/eve/tree/HEAD/packages/eve/issues/1512">#1512</a>)</li>
<li><a
href="https://github.com/vercel/eve/commit/f3bb60dd53fa56e955c6ea71cbf72533cfe618e1"><code>f3bb60d</code></a>
feat: add manual session context clearing (<a
href="https://github.com/vercel/eve/tree/HEAD/packages/eve/issues/1511">#1511</a>)</li>
<li><a
href="https://github.com/vercel/eve/commit/3dce30a18d24644d85b6120d79eaf4d304beaf4b"><code>3dce30a</code></a>
feat: add manual session compaction (<a
href="https://github.com/vercel/eve/tree/HEAD/packages/eve/issues/1508">#1508</a>)</li>
<li><a
href="https://github.com/vercel/eve/commit/9c517555e870231af00df799523bffd9fc00df71"><code>9c51755</code></a>
refactor(eve): use public dynamic definitions for connection tools (<a
href="https://github.com/vercel/eve/tree/HEAD/packages/eve/issues/1505">#1505</a>)</li>
<li><a
href="https://github.com/vercel/eve/commit/0c28eb7e886c1a69ee20a5229682509d5413e140"><code>0c28eb7</code></a>
feat(eve): support dynamic subagents (<a
href="https://github.com/vercel/eve/tree/HEAD/packages/eve/issues/1485">#1485</a>)</li>
<li><a
href="https://github.com/vercel/eve/commit/84aa6715dbf6b6d696b7f567744711f4526b183f"><code>84aa671</code></a>
fix(eve): clarify add flow categories (<a
href="https://github.com/vercel/eve/tree/HEAD/packages/eve/issues/1494">#1494</a>)</li>
<li><a
href="https://github.com/vercel/eve/commit/ab86523b3e07f05f415c9c784232b3875b17b16f"><code>ab86523</code></a>
feat(eve): agent-handle lifecycle contracts (three-phase handles, turn
outcom...</li>
<li>Additional commits viewable in <a
href="https://github.com/vercel/eve/commits/eve@0.29.5/packages/eve">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-07 16:53:51 +05:30
jkomyno ac6bbabd31 fix(claude-agent-sdk): register complete tool schemas
The provider registered tools through jsonSchemaToZodShape, which returns only
the per-property map. Root-level constraints -- `additionalProperties`, boolean
or schema-valued, and `patternProperties` -- are structurally unrepresentable in
a raw shape, so they were dropped before the Claude Agent SDK ever saw them:
free-form object arguments lost their content, and an unknown key was silently
stripped from tool input rather than rejected.

Registering the complete object schema fixes both. A tool with no input
parameters keeps its closed root explicitly, since a bare `properties: {}` is
now an open object.

Proven at the real SDK boundary rather than against a mocked `tool()`: the new
suite drives createSdkMcpServer over an in-memory MCP transport and asserts on
the advertised inputSchema and on real tools/call results.
2026-08-06 21:59:12 +05:30
jkomyno 46ee10eb78 chore(deps): catalog @types/node on the Node 24 line
Every workspace package now takes @types/node from the catalog instead of
pinning its own major, and an override pulls the transitive copies onto the
same line -- @types/ws and @types/yauzl depend on `@types/node: *`, so
vite/vitest peer-resolved 26 for packages that declare nothing themselves.

Node 26 is not a safe target yet. This also removes the one-off ^24.13.3
devDependency the schema-conversion corpus loaders had added to
@composio/json-schema-to-effect-schema, which was the only package in the
repository typing against a different major.
2026-08-06 21:44:41 +05:30
jkomyno 2e2e71f2b1 chore(json-schema-to-effect-schema): type the corpus loaders against Node 24
The corpus loaders read their fixture copy with `node:fs`, so both test
tsconfigs now declare `types: ["node"]` — the dependency alone was not enough,
as `@composio/json-schema-to-zod` already had it and still failed to resolve the
builtins. `@types/node` is pinned to the 24.x line that `mise.toml` pins the
runtime to.
2026-08-06 20:47:23 +05:30
jkomyno 3c4c025aff fix(deps): patch undici audit vulnerability 2026-08-05 21:40:13 +05:30
jkomyno 86cc3cc399 chore: merge next into dependabot remediation 2026-08-05 21:29:53 +05:30
jkomyno 9a6d59326f Merge branch 'next' into feat/installer-auto-shell-default
Keeps this branch's fixture-driven managed-block reconciler
(reconcileManagedPathBlock, pinned byte-for-byte against install.sh's awk
rewrite by test/managed-block-fixtures) and drops next's narrower
replaceManagedPathBlock/applyFileChanges pair, which it supersedes.

Adopts from next: the narrowed unsafe-path character set on both the TS and
sh sides, the removal of the $PATH-reachability write skip, the hedged
no-shell PATH message, and the COMPOSIO_BIN_DIR command documentation.
2026-08-05 19:12:05 +05:30
jkomyno aaa3830f35 Merge remote-tracking branch 'origin/next' into feat/mise-style-installer-rollout 2026-08-05 17:42:58 +05:30
jkomyno fdb366d090 Merge branch 'feat/cli-install-shell-flag' into feat/mise-style-installer-rollout
# Conflicts:
#	install.sh
#	test/install-sh-release-resolution.test.sh
#	ts/packages/cli/test/__utils__/services/test-layer.ts
#	ts/packages/cli/test/src/commands/install.cmd.test.ts
2026-08-04 20:02:22 +05:30
dependabot[bot] 02c7af88ae chore(deps): bump hono from 4.12.31 to 4.12.34 in the npm-security group across 1 directory (#4051)
Bumps the npm-security group with 1 update in the / directory:
[hono](https://github.com/honojs/hono).

Updates `hono` from 4.12.31 to 4.12.34
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/honojs/hono/releases">hono's
releases</a>.</em></p>
<blockquote>
<h2>v4.12.34</h2>
<h2>Security fixes</h2>
<p>This release includes fixes for the following security issues:</p>
<h3><code>memo()</code> retains SSR output across requests, leading to
cross-user data disclosure</h3>
<p>Affects: <code>hono/jsx</code> (server-side rendering). Fixes
<code>memo()</code> reusing a retained render result across requests
when props compare equal, where a component reading request-scoped
values from ambient context — <code>useContext()</code>,
<code>useRequestContext()</code>, or <code>getContext()</code> — could
serve HTML rendered for another user's request, disclosing account data
or request-scoped secrets such as CSRF tokens. GHSA-f23p-vx2j-j53r</p>
<h3>ReDoS in CORS middleware via
<code>Access-Control-Request-Headers</code></h3>
<p>Affects: <code>hono/cors</code>. Fixes a whitespace-tolerant regular
expression with quadratic backtracking used to parse the
<code>Access-Control-Request-Headers</code> preflight header when
<code>allowHeaders</code> is not configured (the default), where a
single preflight request carrying a long whitespace run could consume
seconds of CPU and stall request processing. GHSA-8j4g-w8fx-2239</p>
<h3>Algorithmic complexity DoS in Language Middleware</h3>
<p>Affects: <code>hono/language</code>. Fixes quadratic string
processing in language-tag normalization, where a crafted language tag
with a large number of hyphen-separated subtags — supplied via a query
parameter, cookie, or <code>Accept-Language</code> header — could cause
excessive CPU consumption and block the event loop.
GHSA-54fx-42gc-7vw4</p>
<h3>Proxy Helper does not remove response headers listed in the
<code>Connection</code> header</h3>
<p>Affects: <code>hono/proxy</code>. Fixes <code>proxy()</code>
forwarding response headers that the origin's <code>Connection</code>
header designates as connection-scoped, where headers intended only for
the immediate peer — per RFC 9110 Section 7.6.1 — could be exposed to
clients, disclosing connection-scoped or internal metadata.
GHSA-79qm-7rj5-m7r9</p>
<hr />
<p>Users who use <code>hono/jsx</code> for server-side rendering,
<code>hono/cors</code>, <code>hono/language</code>, or
<code>hono/proxy</code> are strongly encouraged to upgrade to this
version.</p>
<h2>v4.12.33</h2>
<h2>What's Changed</h2>
<ul>
<li>fix(cookie): relax name validation when parsing Cookie header in <a
href="https://redirect.github.com/honojs/hono/pull/5164">honojs/hono#5164</a></li>
<li>chore: bump <code>@hono/node-server</code> in <a
href="https://redirect.github.com/honojs/hono/pull/5167">honojs/hono#5167</a></li>
<li>fix(jsx): handle useSyncExternalStore subscription and snapshot
changes in <a
href="https://redirect.github.com/honojs/hono/pull/5166">honojs/hono#5166</a></li>
<li>chore: remove undici in favor of global fetch in <a
href="https://redirect.github.com/honojs/hono/pull/5168">honojs/hono#5168</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/honojs/hono/compare/v4.12.32...v4.12.33">https://github.com/honojs/hono/compare/v4.12.32...v4.12.33</a></p>
<h2>v4.12.32</h2>
<h2>What's Changed</h2>
<ul>
<li>ci: enable reports for type &amp; bundle size check in <a
href="https://redirect.github.com/honojs/hono/pull/5148">honojs/hono#5148</a></li>
<li>fix(aws-lambda): add jwt and lambda authorizer types for API Gateway
v2 in <a
href="https://redirect.github.com/honojs/hono/pull/5142">honojs/hono#5142</a></li>
<li>fix(sse): emit empty id field to reset Last-Event-ID in <a
href="https://redirect.github.com/honojs/hono/pull/5138">honojs/hono#5138</a></li>
<li>test(cloudflare-workers): add coverage for onClose, onError, send,
and close in Cloudflare Workers websocket adapter in <a
href="https://redirect.github.com/honojs/hono/pull/5145">honojs/hono#5145</a></li>
<li>fix: use <code>Object.create(null)</code> when parsing query,
headers, and params in <a
href="https://redirect.github.com/honojs/hono/pull/5161">honojs/hono#5161</a></li>
<li>fix(secure-headers): keep CSP callbacks scoped to their header in <a
href="https://redirect.github.com/honojs/hono/pull/5147">honojs/hono#5147</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/honojs/hono/compare/v4.12.31...v4.12.32">https://github.com/honojs/hono/compare/v4.12.31...v4.12.32</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/honojs/hono/commit/734755ace341607628219ea1dd8ca17f01bf1a5c"><code>734755a</code></a>
4.12.34</li>
<li><a
href="https://github.com/honojs/hono/commit/9839ff32a349bf088b6ddfa604010879dd2d3a05"><code>9839ff3</code></a>
chore: update <code>bun.lock</code> (<a
href="https://redirect.github.com/honojs/hono/issues/5182">#5182</a>)</li>
<li><a
href="https://github.com/honojs/hono/commit/0c45036d6b0ddf42ab2fa44639dc8710825d5c0f"><code>0c45036</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/honojs/hono/commit/720b566290793d4358bf39843adcb7cf4da4548f"><code>720b566</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/honojs/hono/commit/f70e2c31684387b3231cc38512a31df6ca76a1c7"><code>f70e2c3</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/honojs/hono/commit/93fc250d8b4df58ea542cb945171de8013d5e6d5"><code>93fc250</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/honojs/hono/commit/51db3131d5e97076327edaa0afdb60ebb77c264f"><code>51db313</code></a>
4.12.33</li>
<li><a
href="https://github.com/honojs/hono/commit/aed146364d5c48a8336b8c82fedfabebf8063d07"><code>aed1463</code></a>
chore: remove undici in favor of global fetch (<a
href="https://redirect.github.com/honojs/hono/issues/5168">#5168</a>)</li>
<li><a
href="https://github.com/honojs/hono/commit/224d2f5cbf2b4bc2ebb7482d0592149a8d9f0574"><code>224d2f5</code></a>
fix(jsx): handle useSyncExternalStore subscription and snapshot changes
(<a
href="https://redirect.github.com/honojs/hono/issues/5166">#5166</a>)</li>
<li><a
href="https://github.com/honojs/hono/commit/df653cea0450657977887d56a5188368387456c8"><code>df653ce</code></a>
chore: bump <code>@hono/node-server</code> (<a
href="https://redirect.github.com/honojs/hono/issues/5167">#5167</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/honojs/hono/compare/v4.12.31...v4.12.34">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=hono&package-manager=npm_and_yarn&previous-version=4.12.31&new-version=4.12.34)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/ComposioHQ/composio/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-04 19:20:31 +05:30
Alberto Schiabel f7a4503bbe fix(deps): clear high-severity TypeScript audit findings (#4050)
This PR:
- follows up on the failed TypeScript audit in
https://github.com/ComposioHQ/composio/pull/4048
- adds patched transitive floors for `fast-uri`, `ip-address`, and
`brace-expansion`
- refreshes `pnpm-lock.yaml` to resolve 3.1.5, 10.4.0, and 5.0.9
respectively
- clears all high-severity findings from `pnpm audit --prod
--audit-level=high`; one low and one moderate advisory remain below the
gate
- verifies the affected CLI dependency graph with a frozen install,
package build, and 1,072 passing tests (1 skipped)
2026-08-04 17:23:05 +05:30
jkomyno 611f4e648a fix(deps): restore Workers-compatible Mastra 2026-08-03 18:05:04 +05:30
jkomyno 7198144863 fix(e2e): restore runtime compatibility coverage 2026-08-03 18:04:45 +05:30
jkomyno e5c9adabc8 chore(deps): migrate OpenAI runtime to v7 2026-08-03 17:05:23 +05:30
jkomyno a8d7401b73 test(openai): cover v6 and v7 consumers 2026-08-03 17:05:20 +05:30
jkomyno 4ceaede87a chore(deps): refresh runtime support dependencies 2026-08-03 17:05:20 +05:30
jkomyno d1c2e12e33 chore(deps): refresh agent framework dependencies 2026-08-03 17:05:16 +05:30
jkomyno 32fdddd197 chore(deps): align AI SDK dependencies 2026-08-03 17:04:44 +05:30
jkomyno a59a409204 chore(cli): align Effect dependencies 2026-08-03 17:04:44 +05:30
jkomyno a850f2c1c1 chore(deps-dev): refresh development tooling 2026-08-03 17:04:43 +05:30
Alberto Schiabel 51056129ee fix(core): detect filesystem case sensitivity for uploads (#4036)
This PR:
- fixes #4024
- supersedes #4025 with target-filesystem detection instead of
unconditional case folding
- uses `is-fs-case-sensitive` on the nearest existing directory so mixed
mounts and case-sensitive filesystem configurations are handled
correctly
- preserves exact matching on case-sensitive filesystems and falls back
to conservative case-insensitive matching when detection fails
- keeps Node-only detection behind `#platform` and mirrors its runtime
dependency in `@composio/slim`, preserving the workerd-safe bundle and
Slim import
- adds focused Node, workerd, and matcher regressions plus an
`@composio/core` patch changeset
- verifies 1,044 core tests, five CLI upload tests, the Slim
build/import smoke, typecheck, build, ATTW, publint, lint, formatting,
frozen install, and changeset validation
2026-08-03 16:32:40 +05:30
jkomyno cf9223879e test(cli): cover upgrading a running binary 2026-08-01 19:17:31 +05:30
jkomyno dadd2f4471 test(cli): add hermetic installer e2e coverage 2026-08-01 16:15:24 +05:30
Kshitij Jhunjhunwala fc9745040a feat(cli): make headless composio login agent-friendly (PRDE-1138) (#3945)
## What

Closes the PRDE-1138 gap: an unattended agent hitting plain `composio
login` in a pipe dead-ended at browser OAuth. Now the default headless
path either completes unattended or tells the agent exactly what to run
— without ever auto-creating an account for a human.

- **Offer**: non-interactive login instructions gain a second hint —
"For unattended agents: run `composio login --agent`" — alongside the
existing URL + `composio login --poll` flow.
- **Perform (reuse only)**: when `~/.composio/agent.json` already holds
a READY agent identity, plain headless `composio login` completes
unattended by reusing it. New `getStoredReadyAgent` in
`services/agents.ts` is the reuse-only counterpart of
`getOrSignupReadyAgent` — it never falls back to signup.
- **Guardrail** (the design constraint from the ticket): account
creation stays exclusively behind the explicit `composio login --agent`
/ `composio signup` commands. A human piping `composio login` with no
stored agent identity gets the same URL instructions as before and no
account. Asserted at both unit and E2E level (`/api/signup` is never
called on the default path).
- `install.sh --agent` login now sets
`COMPOSIO_CLI_INVOCATION_ORIGIN=installer` for analytics attribution.
- Root `.dockerignore`: host `node_modules` (pnpm store symlinks that
break outside the host) no longer enter the e2e image build context;
without this, e2e images cannot build from a checkout that has run `pnpm
install`.

## Verification

- `pnpm typecheck` green; `@composio/cli` suite green — 1001 passed, 1
skipped; `validate:boundaries` clean.
- New Docker E2E suite `ts/e2e-tests/cli/agent-signin` (10/10) against a
mock `agents.composio.dev` (`COMPOSIO_AGENTS_BASE_URL`): unattended
nothing→authenticated (`login --agent` then `whoami` in one container),
headless-human guardrail (instructions printed, zero signup calls),
stored-identity reuse (login completes + whoami reports `account_type:
agent`). No real accounts are created.

## Notes

- No VHS recordings: the visible change is piped-mode text output, which
VHS interactive recordings don't demonstrate.
- No changeset by design (`@composio/cli` is Changesets-ignored);
human-facing note added to `ts/packages/cli/CHANGELOG.md` under 0.3.0.
2026-07-28 13:48:28 -07:00
Alberto Schiabel 2b9571b17f fix(core): resolve typedoc against the TS6 compiler API (#3972)
This PR:
- restores TypeDoc generation after
https://github.com/ComposioHQ/composio/pull/3966 by resolving
`@composio/core`'s TypeScript dev dependency from `catalog:ts6`
- keeps core typechecking on the root TypeScript 7 compiler while
TypeDoc receives the TS6 compiler API
- documents the additional compiler-API consumer in the shared
TypeScript catalog
- commits the regenerated `session-files.mdx` output that could not be
produced while the workflow was broken
- verifies `generate:docs`, `typecheck`, and `build` for
`@composio/core`
2026-07-28 21:03:06 +05:30
Kshitij Jhunjhunwala fc1460995b feat(cli): make headless composio login agent-friendly (PRDE-1138)
Teach non-interactive login to reuse an existing READY agent identity without creating one implicitly. Preserve explicit --no-browser and --no-wait contracts, and branch on TerminalUI.canPrompt so piping stdout alone remains interactive.

Add unattended guidance, installer analytics attribution, and focused unit and Docker E2E coverage. Exclude host node_modules from Docker build contexts.
2026-07-28 20:13:57 +05:30
Alberto Schiabel f233e46937 chore(repo): migrate eslint to oxlint and typecheck to TypeScript 7 (#3966)
This PR:

- replaces ESLint with oxlint across the pnpm workspace and the
Bun-based docs site, porting the rules to `.oxlintrc.json` /
`docs/.oxlintrc.json` with behavior parity (restricted-syntax selectors
kept via `oxlint-plugin-eslint`)
- migrates typecheck to TypeScript 7 (`typescript@^7.0.2` catalog) and
keeps a TS6 pin for JS compiler API consumers via a named `ts6` pnpm
catalog (`ts/scripts/validate-examples.ts`, the `@composio/cli` generate
pipeline). The CLI's `typescript` dependency rebinds only the
compiler-API import — its typecheck still runs the root TS7 `tsc`, since
the alias package only ships a `tsc6` bin (documented in
`ts/packages/cli/AGENTS.md`)
- removes the `paths` mappings that pointed `@composio/core` (and, in
`experimental`, `@composio/json-schema-to-zod` plus core-internal
`#`-imports) at sibling `src` directories: under TS7, tsdown's
tsgo-based dts step emitted stray `.d.ts` files next to those
out-of-root sources on every dependent package build. Workspace deps now
resolve through their built dist types, which turbo's `dependsOn:
^build` already guarantees exist — and which the deep-path exports
(`@composio/core/*`) always used anyway
- renames the cli boundary tooling `eslint-boundaries*` →
`lint-boundaries*` and hardens the scanner to reject `oxlint-disable`
spellings so the disable manifest cannot be bypassed
- rewrites inline `eslint-disable` comments to oxlint rule names
(comment-only; no runtime changes), and adds **one new** declared
boundary: `tool-file-uploads.ts` needs `no-restricted-imports` disabled
for `node:crypto` (MD5 for the presigned-upload checksum is not in Web
Crypto), because oxlint also catches dynamic `await import()` where
ESLint did not. The manifest grows 46 → 47 deliberately
- updates CI path filters, `turbo.jsonc` lint inputs, and the docs
typescript-check workflow (renamed to "Docs - Lint and TypeScript
Validation" since it now lints too); drops `eslint`,
`typescript-eslint`, `eslint-config-next`, and `globals` from the
dependency graphs
- ships no changeset: I built `@composio/core` and `@composio/anthropic`
on this branch and on the pre-migration base and diffed the emitted
`dist/**/*.d.mts`. The provider output is byte-identical. Core's output
is **semantically identical but not byte-identical**: TS7 changes quote
style (`"x"` → `'x'`), object-property and union-member ordering in
inferred types, and picks equivalent shorter re-export alias paths for
five signatures (e.g. `OpenAI.Beta.Threads.Runs.Run` →
`OpenAI.Beta.Threads.Run` — verified both names alias the same type in
the shipped typings). Chunk-name hashes shift as a consequence. No type
gains, losses, or shape changes; `attw` and `publint` pass on the TS7
build

## Context

First of a three-PR split of #3958. The type-safety refactors are
stacked on this branch and merge after it:

- docs: https://github.com/ComposioHQ/composio/pull/3967
- `@composio/core`: https://github.com/ComposioHQ/composio/pull/3968
2026-07-28 19:16:57 +05:30
Alberto Schiabel 503b50ab02 chore(deps): refresh SDK, Python, and CI dependencies (#3955)
This PR:

- splits https://github.com/ComposioHQ/composio/pull/3953 in two: this
PR carries every dependency and GitHub Actions bump **except** the docs
site, which follows in a stacked PR
- consolidates and supersedes Dependabot PRs #3915, #3916, and #3934
through #3942
- adopts TypeScript 7.0.2 for primary compilation while retaining the
`@typescript/typescript6` API lane that TypeScript-ESLint still
requires, following the upstream side-by-side guidance
- refreshes Python core and provider dependencies, lockfiles, and the
Ruff 0.16 lint configuration
- updates every GitHub Action with a verified newer official release,
including majors, while retaining immutable commit SHA pins and
migrating setup-uv cache pruning
- deletes four per-package `eslint.config.mjs` shims: under ESLint 10
the default per-file config lookup re-anchors the root config's globs
into each package, so `pnpm lint` stayed green while the CLI's
try/catch, `process.env` and node-builtin bans went unenforced
- bounds and documents the new `brace-expansion` and `@hono/node-server`
security overrides, raising the `@hono/node-server` floor to 2.0.10 to
clear GHSA-9mqv-5hh9-4cgg
- preserves intentional compatibility fixtures and lanes for AI SDK 6,
Zod 3, TypeScript 5.8, Mastra AI SDK 5, and Python provider constraints

## Context

The docs site is a separate Bun workspace with its own `bun.lock` and is
not a pnpm workspace member, so the two halves share no lockfile and no
build. Splitting them keeps the Fumadocs 11 migration (a breaking API
change with real refactoring) reviewable on its own, independently of
the mechanical version bumps here.

The `brace-expansion` override deliberately spans majors:
GHSA-mh99-v99m-4gvg (HIGH) is published as a single `<=5.0.7` range with
no 1.x or 2.x backport, so narrowing it to the 5.x line puts
`brace-expansion` 2.1.2 back under `core>minimatch>brace-expansion` and
`pnpm audit --prod --audit-level=high` exits 1. Verified both ways; the
trade-off it buys is recorded inline in `pnpm-workspace.yaml`.

Verified on this branch standalone: `pnpm install --frozen-lockfile`,
`pnpm lint`, `pnpm typecheck`, `pnpm build:packages`, `pnpm test` (963
tests, 26/26 tasks), and `pnpm audit --prod --audit-level=high`.
2026-07-27 17:57:29 +05:30
Alberto Schiabel 332cb71214 fix(ci): clear dependency audit and cli test failures on next (#3898)
This PR:

- bumps the transitive `brace-expansion` resolution to 2.1.2
([GHSA-3jxr-9vmj-r5cp](https://github.com/advisories/GHSA-3jxr-9vmj-r5cp),
high)
- adds a scoped `js-yaml` override to `>=4.3.0 <5`
([GHSA-52cp-r559-cp3m](https://github.com/advisories/GHSA-52cp-r559-cp3m),
high) — `@redocly/openapi-core@1.34.x` (via `openapi-typescript`)
exact-pins vulnerable 4.2.0, so a lockfile bump alone cannot reach the
patched version
- bumps the existing `protobufjs` override 7.6.3 → 7.6.5
([GHSA-j3f2-48v5-ccww](https://github.com/advisories/GHSA-j3f2-48v5-ccww),
moderate)
- leaves the low `@ai-sdk/provider-utils` advisory as-is: the advertised
patched version 3.0.98 is not published on npm and `@mastra/core`
exact-pins 3.0.25
- aligns `analytics.dispatch.test.ts` mocks with the `spawnDetached`
contract from https://github.com/ComposioHQ/composio/pull/3880
(`once('spawn')`/`once('error')` with unref-after-confirmation); the
test added in https://github.com/ComposioHQ/composio/pull/3881 still
asserted the old fire-and-forget `.on('error')` shape

Verified locally: `pnpm audit --prod --audit-level=high` exits 0 (1 low
remaining), `pnpm install --frozen-lockfile` passes, and the full
`@composio/cli` suite passes (934 tests).

<!-- codesmith:footer -->
---
<a
href="https://app.blacksmith.sh/ComposioHQ/codesmith/composio/pr/3898"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img
alt="View with Codesmith"
src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a>
<a
href="https://backend.blacksmith.sh/track/enable-autofix?expires=1787212096&installation_model_id=428187&pr_number=3898&repository=ComposioHQ%2Fcomposio&return_to=https%3A%2F%2Fgithub.com%2FComposioHQ%2Fcomposio%2Fpull%2F3898&signature=9d7662095d47fa89940855b0abb67f014a807b522b81ea780b62f6326dc0e807"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"><source
media="(prefers-color-scheme: light)"
srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-light.svg"><img
alt="Autofix with Codesmith"
src="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"></picture></a>
<sup>Need help on this PR? Tag <code>/codesmith</code> with what you
need. Autofix is disabled.</sup>

<!-- codesmith:autofix:disabled -->
<!-- /codesmith:footer -->
2026-07-21 12:09:07 +04:00
Alberto Schiabel 6d5465acd3 refactor(cli): seal the CommandDescriptor seam and drop zod for Schema (#3882)
This PR:
- activates the descriptor-seam rule group:
`commands/command-introspection.ts` becomes the only module allowed to
import `CommandDescriptor`/`Usage` from `@effect/cli` — the redesign
seam the Effect CLI v4 migration will reimplement
- routes root command assembly, preflight parsing, help routing, and
value-option collection through the seam helpers instead of descriptor
walks
- replaces the Zod-backed tool-input adapter with an internal
`@composio/json-schema-to-effect-schema` compiler backed by the
eval-free `@cfworker/json-schema` interpreter
- normalizes the OpenAPI and Composio extensions accepted by the
previous validator, while preserving typed `ToolInputValidationError`
failures, field paths, multi-error reporting, and typo suggestions
- extends the descriptor and Zod boundaries to reject static imports,
dynamic `import()`, and `require()` bypasses
- adds compiler parity tests plus CLI regression coverage for multiple
simultaneous field and unknown-key failures
- introspection tests pin that the helpers yield identical descriptors
and usage strings

---

**Stack** (re-slice of https://github.com/ComposioHQ/composio/pull/3859;
each PR targets its parent and auto-retargets to `next` as parents
merge):

1. https://github.com/ComposioHQ/composio/pull/3877 — guidelines + inert
rule groups
2. https://github.com/ComposioHQ/composio/pull/3878 — `new Function()`
eval security fix
3. https://github.com/ComposioHQ/composio/pull/3879 — behavioral fix
pack
4. https://github.com/ComposioHQ/composio/pull/3880 — platform-imports
rule + migration
5. https://github.com/ComposioHQ/composio/pull/3881 — terminal-streams
rule + TerminalUI boundary
6. https://github.com/ComposioHQ/composio/pull/3882 — descriptor seam +
Zod→Schema ← **this PR**
7. https://github.com/ComposioHQ/composio/pull/3883 — test-tree lint +
deterministic suites
8. https://github.com/ComposioHQ/composio/pull/3884 — typed error
boundaries + v4 seams
9. https://github.com/ComposioHQ/composio/pull/3885 — try/catch+env ban
+ boundary ratchet

On stacked bases CI runs lint/build and the CLI Docker e2e job; unit
tests and typecheck are verified locally per PR and re-verified by full
CI when each PR is retargeted to `next`.
2026-07-21 11:25:58 +04:00
Alberto Schiabel 2dc9ef34d0 fix(cli): remove new Function() eval from JSON-ish input parsing (#3878)
This PR:
- removes an in-process arbitrary-code-execution surface:
`parse-json-ish.ts` fell back to `Function("return (…)")()` for any
`tools execute --data`, `listen --params`, or `proxy` body value that
failed JSON and comment-JSON parsing — the CLI is agent-facing and
`--data` also accepts `@file` and stdin, so crafted or prompt-injected
input reached the eval
- lands the parser in its final consolidated shape:
`src/utils/parse-json.ts` parses JSON5 (unquoted keys, single quotes,
trailing commas, comments) without evaluating anything and returns
`Either` with a typed `JsonParsingError`
- consolidates the `effect-errors` read-json duplicates onto the same
parser and swaps `comment-json` for `json5` (the stack's only lockfile
change)
- pins code-execution probes in unit tests (`new Date()`, computed
expressions, `globalThis` writes are rejected, never evaluated)
- intentional narrowing: JS expressions such as `1+1` that only worked
because of the eval now fail with a parse error; proxy bodies that are
not JSON5 records fall back to the raw string
---

**Stack** (re-slice of https://github.com/ComposioHQ/composio/pull/3859;
each PR targets its parent and auto-retargets to `next` as parents
merge):

1. https://github.com/ComposioHQ/composio/pull/3877 — guidelines + inert
rule groups
2. https://github.com/ComposioHQ/composio/pull/3878 — `new Function()`
eval security fix ← **this PR**
3. https://github.com/ComposioHQ/composio/pull/3879 — behavioral fix
pack
4. https://github.com/ComposioHQ/composio/pull/3880 — platform-imports
rule + migration
5. https://github.com/ComposioHQ/composio/pull/3881 — terminal-streams
rule + TerminalUI boundary
6. https://github.com/ComposioHQ/composio/pull/3882 — descriptor seam +
zod→Schema
7. https://github.com/ComposioHQ/composio/pull/3883 — test-tree lint +
deterministic suites
8. https://github.com/ComposioHQ/composio/pull/3884 — typed error
boundaries + v4 seams
9. https://github.com/ComposioHQ/composio/pull/3885 — try/catch+env ban
+ boundary ratchet

On stacked bases CI runs lint/build and the CLI Docker e2e job; unit
tests and typecheck are verified locally per PR and re-verified by full
CI when each PR is retargeted to `next`.
2026-07-21 11:14:55 +04:00
Alberto Schiabel 9498679c26 fix(release): guard and document CLI releases (#3895)
This PR:
- removes the stale `@composio/cli` changeset that wedges
`changesets/action` and preserves its release note in the CLI changelog
- adds `validate:changesets` before the TypeScript release action and
covers ignored-package changesets in the release regression suite
- makes the guard read changeset files directly so it also works in
shallow and detached CI checkouts
- refreshes `mise.lock` after the pinned Python standalone artifacts
moved to the 20260718 build
- adds the repo-local `cli-release` skill with beta, stable-promotion,
verification, and failure-recovery procedures
- replaces the contradictory "stable via changeset" contributor guidance
with the tested-beta promotion path
- extends skill taxonomy, routing probes, and PR path filters so the
guard cannot silently drift

## Regression coverage

The validator test creates a changeset fixture outside a Git repository,
verifies that an ignored CLI package is rejected, then verifies that a
normal package changeset passes. This reproduces the shallow-checkout
failure without relying on a local `next` ref.

## Verification

- `pnpm validate:agent-skills`
- `pnpm validate:skill-routing`
- `pnpm validate:changesets`
- `pnpm test:release-workflow`
- `pnpm lint`
- `pnpm install --frozen-lockfile`
- all 24 TypeScript package test tasks
- skill-creator `quick_validate.py`
- Prettier check
- `git diff --check`
- manual beta release
[`@composio/cli@0.2.33-beta.294`](https://github.com/ComposioHQ/composio/releases/tag/%40composio/cli%400.2.33-beta.294):
33/33 release and installation jobs passed
2026-07-20 23:17:03 +04:00
Kshitij Jhunjhunwala d583e7ef6f fix(cli): harden plugin setup installation 2026-07-13 15:19:38 -07:00
dependabot[bot] 09aab1d19f chore(deps-dev): bump the npm-development group across 1 directory with 3 updates (#3795)
Bumps the npm-development group with 3 updates in the / directory:
[turbo](https://github.com/vercel/turborepo),
[typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint)
and [typedoc](https://github.com/TypeStrong/TypeDoc).

Updates `turbo` from 2.10.2 to 2.10.4
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/turborepo/releases">turbo's
releases</a>.</em></p>
<blockquote>
<h2>Turborepo v2.10.4</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<h3>Changelog</h3>
<ul>
<li>release(turborepo): 2.10.3 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/13222">vercel/turborepo#13222</a></li>
<li>ci: Retry Windows nextest aborts from transient 0xc0000142 spawn
failures by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13240">vercel/turborepo#13240</a></li>
<li>perf: Use mimalloc as the global allocator by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13237">vercel/turborepo#13237</a></li>
<li>perf: Parse yarn v1 lockfiles in a single pass by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13241">vercel/turborepo#13241</a></li>
<li>ci: Fix cache outputs for Eve app by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13243">vercel/turborepo#13243</a></li>
<li>perf: Stop materializing spans for the disabled daemon log layer by
<a href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a>
in <a
href="https://redirect.github.com/vercel/turborepo/pull/13244">vercel/turborepo#13244</a></li>
<li>fix: Keep ancestor-scoped bun dependencies resolvable after prune
renames by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13236">vercel/turborepo#13236</a></li>
<li>perf: Overlap external dependency hashing with package file hashing
by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13234">vercel/turborepo#13234</a></li>
<li>perf: Build tracked repo index concurrently with package graph by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13232">vercel/turborepo#13232</a></li>
<li>perf: Release tokio runtime at exit so background DNS lookups never
stall the user by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13231">vercel/turborepo#13231</a></li>
<li>perf: Overhaul pnpm lockfile parsing and dependency closure
computation by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13228">vercel/turborepo#13228</a></li>
<li>feat: Add futureFlags.experimentalCargoWorkspaces flag (no-op) by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13227">vercel/turborepo#13227</a></li>
<li>feat: Introduce toolchain provider abstraction by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13235">vercel/turborepo#13235</a></li>
<li>perf: Parse Berry lockfiles in a single pass by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13242">vercel/turborepo#13242</a></li>
<li>fix: Apply input exclusion globs to the filesystem walk by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13224">vercel/turborepo#13224</a></li>
<li>fix: Stop root-directory packages from claiming every file in change
mapping by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13225">vercel/turborepo#13225</a></li>
<li>chore: Rename turborepo-repository napi package to
<code>@​turbo/repository</code> by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13226">vercel/turborepo#13226</a></li>
<li>perf: Hash git blobs with hardware-accelerated SHA-1 by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13245">vercel/turborepo#13245</a></li>
<li>release(turborepo): 2.10.4-canary.1 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/13247">vercel/turborepo#13247</a></li>
<li>feat: Discover Cargo crates as packages by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13248">vercel/turborepo#13248</a></li>
<li>perf: Reuse per-package external dependency hashes in run summaries
by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13249">vercel/turborepo#13249</a></li>
<li>perf: Stat workspace turbo.json files concurrently during discovery
by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13251">vercel/turborepo#13251</a></li>
<li>chore: Add tracing spans to workspace discovery and globwalk phases
by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13252">vercel/turborepo#13252</a></li>
<li>fix: Avoid non-reentrant libc calls in concurrent shutdown process
scans by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13256">vercel/turborepo#13256</a></li>
<li>perf: Memoize resolved task definitions during engine construction
by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13257">vercel/turborepo#13257</a></li>
<li>perf: Compute transitive closures and external dependency hashes
concurrently with run setup by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13250">vercel/turborepo#13250</a></li>
<li>perf: Probe microfrontends configs in parallel by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13262">vercel/turborepo#13262</a></li>
<li>feat: Execute Cargo crate tasks via cargo by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13261">vercel/turborepo#13261</a></li>
<li>perf: Pre-size engine task collections by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13265">vercel/turborepo#13265</a></li>
<li>feat: Expose resolved experimentalCI task configuration in
<code>turbo query</code> by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13264">vercel/turborepo#13264</a></li>
<li>feat: Derive input and output globs for Cargo tasks by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13263">vercel/turborepo#13263</a></li>
<li>perf: Parse large pnpm lockfile sections in parallel by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13266">vercel/turborepo#13266</a></li>
<li>feat: Hash Cargo external dependencies per-crate by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13267">vercel/turborepo#13267</a></li>
<li>ci: Install pnpm 10 in musl containers for Library Release by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13269">vercel/turborepo#13269</a></li>
<li>ci: Force pnpm overwrite in Library Release musl containers by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13270">vercel/turborepo#13270</a></li>
<li>perf: Defer the untracked-scan barrier to first file-hash use by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13268">vercel/turborepo#13268</a></li>
<li>ci: Fetch API-created commit before updating local ref by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13271">vercel/turborepo#13271</a></li>
<li>release(library): 0.0.1-canary.22 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/13272">vercel/turborepo#13272</a></li>
<li>perf: Remove lock and dispatch overhead from task hash
precomputation by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13273">vercel/turborepo#13273</a></li>
<li>fix: Fall back to lockfile detection in
<code>@​turbo/repository</code> when package manager is undeclared by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13275">vercel/turborepo#13275</a></li>
<li>test: Add end-to-end coverage for Cargo workspaces by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13274">vercel/turborepo#13274</a></li>
<li>release(library): 0.0.1-canary.23 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/13276">vercel/turborepo#13276</a></li>
<li>release(turborepo): 2.10.4-canary.2 by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/vercel/turborepo/pull/13278">vercel/turborepo#13278</a></li>
<li>fix: Collapse nested package-manager fallback conditional by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13279">vercel/turborepo#13279</a></li>
<li>feat: Make turbo watch Cargo-aware by <a
href="https://github.com/anthonyshew"><code>@​anthonyshew</code></a> in
<a
href="https://redirect.github.com/vercel/turborepo/pull/13280">vercel/turborepo#13280</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vercel/turborepo/commit/1506a114e377dd7e1e8e7a7863c42adf94a9f776"><code>1506a11</code></a>
publish 2.10.4 to registry</li>
<li><a
href="https://github.com/vercel/turborepo/commit/11a68c705274cc7a408776b576ce7a9e14d6e6df"><code>11a68c7</code></a>
fix: Stop flagging relative imports that resolve into node_modules in
boundar...</li>
<li><a
href="https://github.com/vercel/turborepo/commit/947b4784cd1b254e62b663bbdb22891a849b7442"><code>947b478</code></a>
fix: Raise the open-file soft limit at startup (<a
href="https://redirect.github.com/vercel/turborepo/issues/13282">#13282</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/ddc584d788349fc3668e280286f540feee4eb6b9"><code>ddc584d</code></a>
feat: Make turbo prune Cargo-aware (<a
href="https://redirect.github.com/vercel/turborepo/issues/13281">#13281</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/ff0d50822314c5b388d9b4daa9c6159387752d95"><code>ff0d508</code></a>
perf: Skip dependency-closure assembly for toolchains that derive
nothing (<a
href="https://redirect.github.com/vercel/turborepo/issues/1">#1</a>...</li>
<li><a
href="https://github.com/vercel/turborepo/commit/39d623e1323ef50e06be0a103082ae29cc545779"><code>39d623e</code></a>
feat: Make turbo watch Cargo-aware (<a
href="https://redirect.github.com/vercel/turborepo/issues/13280">#13280</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/af01fdfeb5efe07a7b6843a0b8f5033b59ebbb2c"><code>af01fdf</code></a>
fix: Collapse nested package-manager fallback conditional (<a
href="https://redirect.github.com/vercel/turborepo/issues/13279">#13279</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/7e02f94f647cb4d527a438313dc4adbe3e8c0df3"><code>7e02f94</code></a>
release(turborepo): 2.10.4-canary.2 (<a
href="https://redirect.github.com/vercel/turborepo/issues/13278">#13278</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/8e3a59fdb6c71ad24fbbb363db52f88eb9a89116"><code>8e3a59f</code></a>
release(library): 0.0.1-canary.23 (<a
href="https://redirect.github.com/vercel/turborepo/issues/13276">#13276</a>)</li>
<li><a
href="https://github.com/vercel/turborepo/commit/ce18f0a79eb49e9a22c7e6cfa491777c24ed746a"><code>ce18f0a</code></a>
test: Add end-to-end coverage for Cargo workspaces (<a
href="https://redirect.github.com/vercel/turborepo/issues/13274">#13274</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vercel/turborepo/compare/v2.10.2...v2.10.4">compare
view</a></li>
</ul>
</details>
<br />

Updates `typescript-eslint` from 8.62.1 to 8.63.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/typescript-eslint/typescript-eslint/releases">typescript-eslint's
releases</a>.</em></p>
<blockquote>
<h2>v8.63.0</h2>
<h2>8.63.0 (2026-07-06)</h2>
<h3>🚀 Features</h3>
<ul>
<li><strong>eslint-plugin:</strong> [no-misused-promises] detect async
usage of a sync dispose usage (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12426">#12426</a>)</li>
</ul>
<h3>🩹 Fixes</h3>
<ul>
<li><strong>eslint-plugin:</strong> [method-signature-style] suggest
converting readonly function properties instead of emitting invalid
syntax (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12447">#12447</a>,
<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/issues/12446">#12446</a>)</li>
<li><strong>eslint-plugin:</strong> [no-unnecessary-type-assertion]
handle optional-chained calls to overloaded functions (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12491">#12491</a>,
<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/issues/12485">#12485</a>)</li>
<li><strong>eslint-plugin:</strong> [no-base-to-string] don't flag a
shadowed String() call (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12492">#12492</a>)</li>
<li><strong>scope-manager:</strong> export ClassStaticBlockScope (<a
href="https://redirect.github.com/typescript-eslint/typescript-eslint/pull/12460">#12460</a>)</li>
</ul>
<h3>❤️ Thank You</h3>
<ul>
<li>Evyatar Daud <a
href="https://github.com/StyleShit"><code>@​StyleShit</code></a></li>
<li>Kristjan <a
href="https://github.com/KristjanTammekivi"><code>@​KristjanTammekivi</code></a></li>
<li>Michael Naumov <a
href="https://github.com/mnaoumov"><code>@​mnaoumov</code></a></li>
<li>Serhii Leniv <a
href="https://github.com/Serhii-Leniv"><code>@​Serhii-Leniv</code></a></li>
<li>송재욱</li>
</ul>
<p>See <a
href="https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.63.0">GitHub
Releases</a> for more information.</p>
<p>You can read about our <a
href="https://typescript-eslint.io/users/versioning">versioning
strategy</a> and <a
href="https://typescript-eslint.io/users/releases">releases</a> on our
website.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md">typescript-eslint's
changelog</a>.</em></p>
<blockquote>
<h2>8.63.0 (2026-07-06)</h2>
<p>This was a version bump only for typescript-eslint to align it with
other projects, there were no code changes.</p>
<p>See <a
href="https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.63.0">GitHub
Releases</a> for more information.</p>
<p>You can read about our <a
href="https://typescript-eslint.io/users/versioning">versioning
strategy</a> and <a
href="https://typescript-eslint.io/users/releases">releases</a> on our
website.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/typescript-eslint/typescript-eslint/commit/290cf6cdcc5ffb00c5b8f3e1e0e9f2fd8cc96374"><code>290cf6c</code></a>
chore(release): publish 8.63.0</li>
<li>See full diff in <a
href="https://github.com/typescript-eslint/typescript-eslint/commits/v8.63.0/packages/typescript-eslint">compare
view</a></li>
</ul>
</details>
<br />

Updates `typedoc` from 0.28.19 to 0.28.20
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/TypeStrong/TypeDoc/releases">typedoc's
releases</a>.</em></p>
<blockquote>
<h2>v0.28.20</h2>
<h3>Features</h3>
<ul>
<li>Group/category section headings (<code>&lt;h2&gt;</code>) in the
default theme now include an <code>id</code> attribute so they can be
linked to via fragment identifiers (e.g.
<code>modules.html#classes</code>), <a
href="https://redirect.github.com/TypeStrong/TypeDoc/issues/3029">#3029</a>.</li>
<li>Added a <code>@reexport</code> modifier tag to have TypeDoc convert
variable/type references as a re-export instead of a new symbol, <a
href="https://redirect.github.com/TypeStrong/TypeDoc/issues/3096">#3096</a>.</li>
<li>API: Introduced <code>generateOutputsBegin</code> and
<code>generateOutputsEnd</code> events on <code>Application</code> for
plugin use.</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>When <code>--emit none</code> is used, TypeDoc will now report
warnings about missing relative paths previously reported when
rendering, <a
href="https://redirect.github.com/TypeStrong/TypeDoc/issues/3078">#3078</a>.</li>
<li>Improved performance via asynchronously performing git and file
write operations, more performant JSX rendering, and source code
bundling, <a
href="https://redirect.github.com/TypeStrong/TypeDoc/issues/3103">#3103</a>.</li>
<li>A <code>@hidden</code> tag on a constructor parameter-property will
now only hide the property, not both the property and the parameter, <a
href="https://redirect.github.com/TypeStrong/TypeDoc/issues/3111">#3111</a>.</li>
<li>Custom <code>@group</code> and <code>@category</code> titles with
the same sort weight are now ordered consistently with the
<code>alphabetical</code> reflection sort, <a
href="https://redirect.github.com/TypeStrong/TypeDoc/issues/3120">#3120</a>.</li>
</ul>
<h3>Thanks!</h3>
<ul>
<li><a
href="https://github.com/greymoth-jp"><code>@​greymoth-jp</code></a></li>
<li><a
href="https://github.com/jonathanhefner"><code>@​jonathanhefner</code></a></li>
<li><a
href="https://github.com/kcastellino"><code>@​kcastellino</code></a></li>
<li><a href="https://github.com/Metbcy"><code>@​Metbcy</code></a></li>
<li><a
href="https://github.com/StoneCypher"><code>@​StoneCypher</code></a></li>
<li><a
href="https://github.com/wotan-allfather"><code>@​wotan-allfather</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/TypeStrong/typedoc/blob/master/CHANGELOG.md">typedoc's
changelog</a>.</em></p>
<blockquote>
<h2>v0.28.20 (2026-07-05)</h2>
<h3>Features</h3>
<ul>
<li>Group/category section headings (<code>&lt;h2&gt;</code>) in the
default theme now include an <code>id</code> attribute so they can be
linked to via fragment identifiers (e.g.
<code>modules.html#classes</code>), <a
href="https://redirect.github.com/TypeStrong/TypeDoc/issues/3029">#3029</a>.</li>
<li>Added a <code>@reexport</code> modifier tag to have TypeDoc convert
variable/type references as a re-export instead of a new symbol, <a
href="https://redirect.github.com/TypeStrong/TypeDoc/issues/3096">#3096</a>.</li>
<li>API: Introduced <code>generateOutputsBegin</code> and
<code>generateOutputsEnd</code> events on <code>Application</code> for
plugin use.</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>When <code>--emit none</code> is used, TypeDoc will now report
warnings about missing relative paths previously reported when
rendering, <a
href="https://redirect.github.com/TypeStrong/TypeDoc/issues/3078">#3078</a>.</li>
<li>Improved performance via asynchronously performing git and file
write operations, more performant JSX rendering, and source code
bundling, <a
href="https://redirect.github.com/TypeStrong/TypeDoc/issues/3103">#3103</a>.</li>
<li>A <code>@hidden</code> tag on a constructor parameter-property will
now only hide the property, not both the property and the parameter, <a
href="https://redirect.github.com/TypeStrong/TypeDoc/issues/3111">#3111</a>.</li>
<li>Custom <code>@group</code> and <code>@category</code> titles with
the same sort weight are now ordered consistently with the
<code>alphabetical</code> reflection sort, <a
href="https://redirect.github.com/TypeStrong/TypeDoc/issues/3120">#3120</a>.</li>
</ul>
<h3>Thanks!</h3>
<ul>
<li><a
href="https://github.com/greymoth-jp"><code>@​greymoth-jp</code></a></li>
<li><a
href="https://github.com/jonathanhefner"><code>@​jonathanhefner</code></a></li>
<li><a
href="https://github.com/kcastellino"><code>@​kcastellino</code></a></li>
<li><a href="https://github.com/Metbcy"><code>@​Metbcy</code></a></li>
<li><a
href="https://github.com/StoneCypher"><code>@​StoneCypher</code></a></li>
<li><a
href="https://github.com/wotan-allfather"><code>@​wotan-allfather</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/TypeStrong/typedoc/commit/34d843be0953fc81de0fde14bea8db72d0bbccc6"><code>34d843b</code></a>
Update changelog for release</li>
<li><a
href="https://github.com/TypeStrong/typedoc/commit/fbd4a254952c171b9ba7ebbe96c5151e844743be"><code>fbd4a25</code></a>
Bump version to 0.28.20</li>
<li><a
href="https://github.com/TypeStrong/typedoc/commit/93ba157000e4a632bfbf32a0b6f00f8ae57c7c99"><code>93ba157</code></a>
Update dependencies in example</li>
<li><a
href="https://github.com/TypeStrong/typedoc/commit/e8c5df8844edca9800dfc62cee9115ef0fba59ea"><code>e8c5df8</code></a>
Remove unnecessary files from distribution</li>
<li><a
href="https://github.com/TypeStrong/typedoc/commit/392b0dd50a428ea0c732c38c6c263e74cb6200b1"><code>392b0dd</code></a>
Update dependencies</li>
<li><a
href="https://github.com/TypeStrong/typedoc/commit/8510dd48c7778f419f4605146f1a733af27993fa"><code>8510dd4</code></a>
Add missing entries in changelog before release</li>
<li><a
href="https://github.com/TypeStrong/typedoc/commit/51dc0521890924269f06e08972c6453299f63cb5"><code>51dc052</code></a>
Update change log for 0.28.20 release</li>
<li><a
href="https://github.com/TypeStrong/typedoc/commit/72f20cd87b4ef30aae97b68fcbb42ca19cebdc22"><code>72f20cd</code></a>
Merge branch 'fix-locale-sort-group-category-titles' into dev</li>
<li><a
href="https://github.com/TypeStrong/typedoc/commit/623f2c0bd35b5e89cc79fb5783dac01c6f2530e9"><code>623f2c0</code></a>
Fix failing test, accept slightly slower build for now</li>
<li><a
href="https://github.com/TypeStrong/typedoc/commit/c8bdf14cab0c22dd415b6872cc647c6cf81f917c"><code>c8bdf14</code></a>
Minor config tweak to improve dev build time</li>
<li>Additional commits viewable in <a
href="https://github.com/TypeStrong/TypeDoc/compare/v0.28.19...v0.28.20">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-13 13:54:29 +04:00
dependabot[bot] 4baacbeb77 chore(deps): bump the npm-production group across 1 directory with 7 updates (#3799)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: jkomyno <alberto@composio.dev>
2026-07-10 19:06:45 +04:00
Alberto Schiabel b07fcada3f feat(experimental): add Eve provider and iMessage example (#3800)
This PR:

- supersedes https://github.com/ComposioHQ/composio/pull/3642 and
credits @shamsharoon for the original Eve provider and iMessage work
- rebases the integration onto the current `next` branch and resolves
its lockfile conflicts
- publishes an isolated `@composio/experimental/eve` entry with the
correct Eve 0.12+ peer contract
- adds recoverable per-session discovery, native Eve context
propagation, and durable approval policies for direct and batched side
effects
- centralizes circular-safe auth-link extraction across Eve and Pi and
replaces dense conditional expressions with named control flow
- hardens the iMessage example against `osascript` option injection,
unsafe trigger scoping, and third-party prompt injection
- preserves completed local-tool results when a mixed local/remote batch
loses its remote transport
- consolidates the example documentation onto shared components,
documents direct model-provider credentials, and clarifies that the
browsable source is not yet a standalone fixture
- verifies the change with 999 core tests, 32 experimental tests,
package builds/typechecks, packed peer-isolation smokes, and a
production docs build

---------

Co-authored-by: shams haroon <144290365+shamsharoon@users.noreply.github.com>
Co-authored-by: shams haroon <shamsharoon7@gmail.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: shams haroon <shams@composio.dev>
2026-07-10 16:57:11 +04:00
Alberto Schiabel 30ba4d2930 feat(openai): add executable provider example (#3798)
This PR:

- builds on top of https://github.com/ComposioHQ/composio/pull/3790
- makes the OpenAI example executable in direct-tools, Tool Router,
smoke, and Cloudflare Workers modes
- keeps direct and Tool Router agents in separate files so each
execution model is explicit and readable
- requires a successful Composio tool execution before either agent can
accept a final model response
- adds OpenAI to the nightly staging matrix without weakening the
existing Mastra coverage
- updates two stale experimental OpenAI usages so the complete example
package typechecks against current SDK APIs

## Testing

- `pnpm --filter openai-example run typecheck`
- `pnpm --filter openai-example run lint` (0 errors; 4 pre-existing
warnings)
- `pnpm --filter openai-example run smoke` (staging: 5 direct tools and
6 Tool Router tools)
- `pnpm --filter openai-example run cf:dry-run`
- `pnpm run typecheck`
- `./node_modules/.bin/eslint ts/packages --ext .ts,.tsx`
- `pnpm run typecheck:examples`
- `pnpm run lint:examples`
- `pnpm exec turbo cf:dry-run --filter='./ts/examples/*'`
- [branch
nightly](https://github.com/ComposioHQ/composio/actions/runs/29079263571):
OpenAI and Mastra both passed smoke, direct-tools, and Tool Router
against staging

## Post-deploy validation

- dispatch `ts.examples-nightly.yml` on `next` after merge and confirm
both matrix legs stay green
- healthy runs finish within the 20-minute job budget and log successful
tool-backed responses for both agent modes
- revert this PR if the OpenAI leg blocks the nightly; examples
maintainers own the first post-merge run and the next 06:00 UTC schedule

---

[![Compound
Engineering](https://img.shields.io/badge/Built_with-Compound_Engineering-6366f1)](https://github.com/EveryInc/compound-engineering-plugin)
![Codex](https://img.shields.io/badge/GPT--5-000000)
2026-07-10 13:41:59 +04:00