chore(deps): update all non-major dependencies#2270
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
4d6a0f5 to
e1386fd
Compare
e1386fd to
41c64a9
Compare
41c64a9 to
f2c50da
Compare
f2c50da to
967b104
Compare
967b104 to
0040817
Compare
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
0040817 to
8a4c09d
Compare
8a4c09d to
6ef1f01
Compare
6ef1f01 to
5dde234
Compare
5dde234 to
96a205f
Compare
96a205f to
3dcfa2a
Compare
86ef0a6 to
18c268a
Compare
18c268a to
7f08945
Compare
7f08945 to
dfe60ec
Compare
dfe60ec to
3bfb98d
Compare
3bfb98d to
56500bb
Compare
56500bb to
2c57c45
Compare
2c57c45 to
76696ea
Compare
76696ea to
a731d38
Compare
a731d38 to
aaa32fe
Compare
aaa32fe to
05024bf
Compare
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
This PR contains the following updates:
^3.0.81→^3.0.84^1.0.45→^1.0.50^3.0.193→^3.0.204^0.3.1→^0.4.0^1.2.111→^1.2.112^1.2.26→^1.2.28^1.2.84→^1.2.86^1.2.53→^1.2.57^1.15.2→^1.16.0^1.1.2→^1.1.3^1.1.1→^1.2.1^4.8.1→^4.8.2^1.6.0→^1.8.5^0.2.0→^0.3.0^3.6.1→^3.7.1^3.5.35→^3.5.38^2.4.10→^2.4.11^6.0.193→^6.0.204^12.10.0→^12.10.1^10.4.1→^10.5.0^2.18.1→^2.19.1^20.9.0→^20.10.3^2.2.1→^2.3.0^6.5.1→^6.6.0^6.0.4→^6.2.111.5.0→11.6.0^2.5.128→^2.5.130^4.1.0→^4.2.0^4.1.7→^4.1.8^3.5.35→^3.5.38^3.3.3→^3.3.5Release Notes
vercel/ai (@ai-sdk/anthropic)
v3.0.84Patch Changes
bfa5864]f42aa79]v3.0.82Compare Source
Patch Changes
2a91a17: feat(provider/anthropic): add support forclaude-fable-5and thefallbacksAPI parametervercel/ai (@ai-sdk/mcp)
v1.0.49Patch Changes
3e8d9ba: fix(mcp): lock first sse endpoint received via event4fa7354: fix(mcp): prevent prototype-named tools from bypassing theschemasallowlistWhen using
client.tools({ schemas })to expose only an explicitly allowedsubset of an MCP server's tools, the allowlist check used the
inoperator,which also matches inherited
Object.prototypeproperties. A server-advertisedtool named
constructor,toString,__proto__, etc. would pass the checkeven though the developer never defined it in
schemas, and was then exposed tothe model and executable. The check now uses
Object.hasOwn, so onlyexplicitly defined tools are returned.
Updated dependencies [
bfa5864]Updated dependencies [
f42aa79]v1.0.47Compare Source
Patch Changes
bf1d6bd: fix(mcp): prevent mcp oauth credential exfiltration during rediscoveryv1.0.46Compare Source
Patch Changes
1f817db: fix(mcp): await addClientAuthentication in token exchange and refreshvercel/ai (@ai-sdk/vue)
v3.0.203Patch Changes
bfa5864]f42aa79]5291f7e]b4b575a]v3.0.201Compare Source
Patch Changes
0c8c0ed]v3.0.200Compare Source
Patch Changes
14098e7]2cabe9c]v3.0.199Compare Source
Patch Changes
49d9364]v3.0.198Compare Source
Patch Changes
v3.0.197Compare Source
Patch Changes
v3.0.196Compare Source
Patch Changes
v3.0.195Compare Source
Patch Changes
v3.0.194Compare Source
Patch Changes
comarkdown/comark (@comark/nuxt)
v0.4.0: @comark/svelte v0.4.0Compare Source
Bug Fixes
nuxt/eslint (@nuxt/eslint)
v1.16.0Compare Source
🚀 Features
View changes on GitHub
nuxt/hints (@nuxt/hints)
v1.1.3Compare Source
🩹 Fixes
❤️ Contributors
nuxt/scripts (@nuxt/scripts)
v1.2.1Compare Source
🐞 Bug Fixes
View changes on GitHub
v1.2.0Compare Source
🚀 Features
🐞 Bug Fixes
View changes on GitHub
nuxt/ui (@nuxt/ui)
v4.8.2Compare Source
Bug Fixes
nameattribute (#6539) (f8186e2)localeprop (#6546) (ed2f955)kane50613/takumi (@takumi-rs/core)
v1.8.5Compare Source
Patch Changes
v1.8.4Compare Source
Patch Changes
v1.8.3Compare Source
Patch Changes
bfc6e55: Join rayon's worker threads on N-API teardown to fix a Windows crash (0xC0000005) when Node exits after rendering (#763)v1.8.2Compare Source
Patch Changes
v1.8.1Compare Source
Patch Changes
v1.8.0Compare Source
Minor Changes
ae2c9aa: Built with nightly Rust toolchain withpanic=immediate-abortto reduce binary sizePatch Changes
v1.7.0Compare Source
Patch Changes
b908a4d]4748c22]42d0d03]80e29da]vercel/vercel (@vercel/functions)
v3.7.1Compare Source
Patch Changes
a7f1f7c: Makewsan optional peer dependencyv3.7.0Compare Source
Minor Changes
3f3ef14: Addexperimental_upgradeWebSocket()APIv3.6.3Compare Source
Patch Changes
01cf6c2]v3.6.2Compare Source
Patch Changes
fddeb55]vuejs/core (@vue/compiler-sfc)
v3.5.38Compare Source
v3.5.37Compare Source
v3.5.36Compare Source
Bug Fixes
once: true(#14902) (450a8a8)vuejs/test-utils (@vue/test-utils)
v2.4.11Compare Source
compare changes
🩹 Fixes
setData()correctly for components using bothsetup()anddata()(#2846)GlobalMountOptionstype (#2851)event.codeonkeydown/keyup(#2850)❤️ Contributors
vercel/ai (ai)
v6.0.204Compare Source
v6.0.203Compare Source
Patch Changes
f42aa79: fix: harden download URL SSRF guard against hostname and redirect bypassesvalidateDownloadUrland the file download helpers (downloadBlob,download) could be bypassed in several ways when handling untrusted URLs:localhost.,myhost.local.) skipped the localhost/.localblocklist.::127.0.0.1), IPv4-translated (::ffff:0:127.0.0.1), and NAT64 (64:ff9b::127.0.0.1, including the64:ff9b:1::/48local-use prefix) — were not decoded and checked against the private IPv4 ranges.fetchhad already followed them, so the request to a redirect target (e.g. an internal/metadata address) had already been issued before the check ran.100.64.0.0/10, used by some cloud providers for internal traffic), benchmarking (198.18.0.0/15), IETF protocol assignments (192.0.0.0/24), the reserved240.0.0.0/4block (including the255.255.255.255broadcast address), and IPv6 site-local (fec0::/10) and multicast (ff00::/8).The validator now strips trailing dots before the hostname checks and fully expands IPv6 addresses to detect embedded private IPv4 targets. The download helpers now follow redirects manually (
redirect: 'manual'), re-validating each hop before requesting it, so an unsafe redirect target is never fetched. When a redirect cannot be inspected because the runtime returns an opaque response, the helpers fail closed (reject the redirect) on the server; only in a real browser — where SSRF is not reachable (fetch is constrained by CORS and cannot reach a server's internal network or cloud-metadata endpoints) — is the redirect followed natively so legitimate redirected downloads keep working.5291f7e: Harden stream text processing and middleware against prototype pollution from stream part IDs.b4b575a: fix: redact server error details from UI message streams by defaultstreamText(...).toUIMessageStream()andcreateUIMessageStreamdefaulted theironErrorcallback togetErrorMessage, which serializes the raw error (error.toString()/JSON.stringify(error)) into the client-facing{ type: 'error', errorText }chunk — and also intotool-output-errorparts. The documented default was() => 'An error occurred.', so applications relying on the documented behavior were unknowingly streaming server exception details (internal hostnames, paths, provider request data, validation inputs) to end users.The default
onErrornow returns the documented generic'An error occurred.'. Raw error details are only emitted when the developer explicitly supplies anonErrorhandler. This also redactstool-output-errorand invalid-tool-input error text by default; pass anonErrorto surface richer messages.Updated dependencies [
bfa5864]Updated dependencies [
f42aa79]v6.0.202Compare Source
Patch Changes
942f2f8: fix(security): re-validate tool approvals from client message history before executionThe approval-replay path in
generateText/streamTextreconstructed approved tool calls from the client-supplied messages array and executed them without re-validating input against the tool's schema or re-checking that the tool actually requires approval. A client could forge an assistant message with a pre-approved tool-call part and have the server execute a tool with attacker-chosen arguments.The replay path now verifies the HMAC signature (when
experimental_toolApprovalSecretis configured), re-validates tool-call input against the tool's input schema, and re-resolves whether the tool requires approval before execution.Updated dependencies [
942f2f8]v6.0.201Compare Source
Patch Changes
0c8c0ed: fix(ai): return schema-transformed elements in array output modePreviously final array output validation checked each element against the schema but returned the raw model output. Array output now returns the validated values so Zod transforms, coercions, defaults, and pipes are applied consistently with object output.
v6.0.200Compare Source
Patch Changes
14098e7: fix(ai): rejectstreamTextresult promises withNoOutputGeneratedErrorwhen the model stream ends without producing any output. Previously such streams resolved with an empty step. Incomplete streams with partial output still resolve with the partial result.2cabe9c: Harden UI message stream processing against prototype pollution from chunk IDs.v6.0.199Compare Source
Patch Changes
49d9364: fix(ai): add approval guard for denied tool outputs3851e29]2a91a17]v6.0.198Compare Source
Patch Changes
ff16d3b]v6.0.197Compare Source
v6.0.196Compare Source
Patch Changes
286b7a2]v6.0.195Compare Source
v6.0.194Compare Source
WiseLibs/better-sqlite3 (better-sqlite3)
v12.10.1Compare Source
What's Changed
Full Changelog: WiseLibs/better-sqlite3@v12.10.0...v12.10.1
eslint/eslint (eslint)
v10.5.0Compare Source
HugoRCD/evlog (evlog)
v2.19.1Compare Source
What's Changed
Bug Fixes 🐞
Dependency Updates 📦
New Contributors
Full Changelog: https://github.com/HugoRCD/evlog/compare/evlog@2.19.0...evlog@2.19.1
v2.19.0Compare Source
What's Changed
Features 🚀
Bug Fixes 🐞
Continuous Integration 🔄
New Contributors
Full Changelog: https://github.com/HugoRCD/evlog/compare/evlog@2.18.1...evlog@2.19.0
capricorn86/happy-dom (happy-dom)
v20.10.3Compare Source
v20.10.2Compare Source
👷♂️ Patch fixes
v20.10.1Compare Source
v20.10.0Compare Source
motiondivision/motion-vue (motion-v)
v2.3.0Compare Source
🚀 Features
🐞 Bug Fixes
View changes on GitHub
nuxt-modules/og-image (nuxt-og-image)
v6.6.0Compare Source
🚀 Features
🐞 Bug Fixes
View changes on GitHub
v6.5.3Compare Source
🐞 Bug Fixes
"when inlining<style>rules intostyleattr - by @danielroe in #629 (c6cd3)<template>bounds - by @danielroe in #628 (607fd)View changes on GitHub
v6.5.2Compare Source
🐞 Bug Fixes
View changes on GitHub
harlan-zw/nuxt-schema-org (nuxt-schema-org)
v6.2.1Compare Source
No significant changes
View changes on GitHub
v6.2.0Compare Source
🚀 Features
🐞 Bug Fixes
@unhead/schema-orgmajors, drop npm-alias dep - by @harlan-zw in #126 (9c376)View changes on GitHub
v6.1.3[Compare Source](https://r
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.