Skip to content

build(deps-dev): bump the minor-and-patch group with 16 updates - #154

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/minor-and-patch-fd76356a24
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/minor-and-patch-fd76356a24

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown

Bumps the minor-and-patch group with 16 updates:

Package From To
@ai-sdk/anthropic 4.0.22 4.0.71
@anthropic-ai/claude-agent-sdk 0.3.220 0.3.289
@langchain/core 1.2.3 1.2.14
@langchain/langgraph 1.4.8 1.4.19
@mastra/core 1.53.0 1.74.0
@modelcontextprotocol/sdk 1.29.0 1.32.1
@openai/agents 0.13.5 0.18.0
@types/bun 1.4.0 1.4.2
ai 7.0.38 7.0.127
bullmq 5.79.3 5.81.5
elysia 1.4.29 1.4.30
fast-check 4.9.0 4.10.2
oxfmt 0.64.0 0.72.0
oxlint 1.79.0 1.87.0
oxlint-tsgolint 7.0.2001 7.0.2003
zod 4.4.3 4.6.5

Updates @ai-sdk/anthropic from 4.0.22 to 4.0.71

Changelog

Sourced from @​ai-sdk/anthropic's changelog.

4.0.71

Patch Changes

  • c35458e: fix(anthropic): preserve invalid toolset calls

4.0.70

Patch Changes

  • Updated dependencies [8c65988]
  • Updated dependencies [527a163]
    • @​ai-sdk/provider@​4.0.21
    • @​ai-sdk/provider-utils@​5.0.53

4.0.69

Patch Changes

  • ede5b89: chore: migrate package builds from tsup to tsdown
  • a587f55: fix(anthropic): preserve server-side fallback boundaries when replaying assistant messages
  • Updated dependencies [ede5b89]
    • @​ai-sdk/provider@​4.0.20
    • @​ai-sdk/provider-utils@​5.0.52

4.0.68

Patch Changes

  • c2511c1: fix: use standards-compliant User-Agent header
  • Updated dependencies [c2511c1]
    • @​ai-sdk/provider-utils@​5.0.51

4.0.67

Patch Changes

  • e361d39: feat(anthropic): add Claude Sonnet 5.5 support

    • add the claude-sonnet-5-5 model ID to @ai-sdk/anthropic and @ai-sdk/google-vertex, anthropic.claude-sonnet-5-5 and us.anthropic.claude-sonnet-5-5 to @ai-sdk/amazon-bedrock, and anthropic/claude-sonnet-5.5 to @ai-sdk/gateway
    • add the between_tools thinking type (thinking: { type: 'between_tools' }), the lowest thinking setting on claude-sonnet-5-5; xhigh and max effort are lowered to high with a warning because the API rejects them with between_tools
    • claude-sonnet-5-5 rejects disabled thinking: thinking: { type: 'disabled' } is replaced with between_tools thinking (with a warning), reasoning: 'none' maps to between_tools thinking, and budget-based thinking is converted to adaptive thinking
    • claude-sonnet-5-5 rejects forced tool use: required and named tool choices fall back to auto, and structuredOutputMode: 'jsonTool' falls back to native structured outputs, each with a warning
  • 8373a22: Normalize dangling programmatic tool caller references in conversation history after pruning. Before a subsequent user message, omit caller metadata whose source code execution call is missing and emit a warning, preserving the retained tool calls and results. Keep caller metadata unchanged for active tool continuations.

4.0.66

Patch Changes

... (truncated)

Commits

Updates @anthropic-ai/claude-agent-sdk from 0.3.220 to 0.3.289

Release notes

Sourced from @​anthropic-ai/claude-agent-sdk's releases.

v0.3.289

What's changed

  • Updated to parity with Claude Code v2.1.289

Update

npm install @anthropic-ai/claude-agent-sdk@0.3.289
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.289
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.289
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.289

v0.3.288

What's changed

  • Updated to parity with Claude Code v2.1.288

Update

npm install @anthropic-ai/claude-agent-sdk@0.3.288
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.288
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.288
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.288

v0.3.287

What's changed

  • Added optional remote-session latency fields (first_text_post_queue_wait_ms, first_text_post_queued_behind) to the success result message
  • Fixed includePartialMessages streams sending a cut-short reply's message_stop late or never, so apps could show the reply as still in progress
  • Fixed the error for a revoked claude.ai login, which now reads "Failed to authenticate: OAuth token revoked" instead of a generic or "does not have access" message
  • Fixed a tool call to an in-process MCP server being left waiting after toggleMcpServer() disabled the server or setMcpServers() removed it
  • Fixed commands_changed arriving before init, or twice, at session start: the initialize response now includes commands registered at startup
  • Changed tool_use_result for a WebFetch or WebSearch call that steps aside for a priority "now" message to { detachedToolCall: true }; the result follows in a later turn
  • Changed tool_use_result for MCP tools: structuredContent over 1,048,576 JSON characters is left off and structuredContentOmitted: true set, except for SDK-server and MCP Apps tools
  • Updated to parity with Claude Code v2.1.287

Update

npm install @anthropic-ai/claude-agent-sdk@0.3.287
</tr></table> 

... (truncated)

Changelog

Sourced from @​anthropic-ai/claude-agent-sdk's changelog.

0.3.289

  • Updated to parity with Claude Code v2.1.289

0.3.288

  • Updated to parity with Claude Code v2.1.288

0.3.287

  • Added optional remote-session latency fields (first_text_post_queue_wait_ms, first_text_post_queued_behind) to the success result message
  • Fixed includePartialMessages streams sending a cut-short reply's message_stop late or never, so apps could show the reply as still in progress
  • Fixed the error for a revoked claude.ai login, which now reads "Failed to authenticate: OAuth token revoked" instead of a generic or "does not have access" message
  • Fixed a tool call to an in-process MCP server being left waiting after toggleMcpServer() disabled the server or setMcpServers() removed it
  • Fixed commands_changed arriving before init, or twice, at session start: the initialize response now includes commands registered at startup
  • Changed tool_use_result for a WebFetch or WebSearch call that steps aside for a priority "now" message to { detachedToolCall: true }; the result follows in a later turn
  • Changed tool_use_result for MCP tools: structuredContent over 1,048,576 JSON characters is left off and structuredContentOmitted: true set, except for SDK-server and MCP Apps tools
  • Updated to parity with Claude Code v2.1.287

0.3.286

  • Added the initialize response field sdk_mcp_manifests_parked and the system/init capabilities sdk_mcp_manifests and sdk_mcp_tools_list_changed
  • Fixed foreground subagents sometimes not receiving the task-tracking tools listed in tools or allowedTools
  • Fixed an SDK MCP server listing no tools when one tool's schema cannot be converted to JSON Schema; that tool is now left out with a warning naming it
  • Fixed toggleMcpServer() not disconnecting, and failing to re-enable, an in-process MCP server created with createSdkMcpServer(), except one named claude-in-chrome
  • Changed a person's priority now message to move running shell commands, agents and MCP calls to the background and join the running turn instead of stopping it
  • Changed the TypeScript Agent SDK to leave an omitted permissionMode to Claude Code, so a settings defaultMode now applies and, on third-party providers or with telemetry off, the session starts in auto mode like claude -p; pass permissionMode: 'default' for manual approvals
  • Updated to parity with Claude Code v2.1.286

0.3.285

  • Added an optional read.title (the artifact's stored title) to the Artifact tool's structured read result
  • Added provider_not_allowed to startup_failure_reason and allowedProviders to the Settings type
  • Fixed sessions with CLAUDE_CODE_FORK_SUBAGENT=1: a subagent's own Agent call now runs in the foreground, so the subagent gets the child's result
  • Fixed getSessionMessages() leaving out a message sent while Claude was working when the process stopped before the reply, or when another prompt followed it with no reply in between
  • Fixed toggleMcpServer(name, false) leaving the connection open for a server that had not yet connected when the session started, or whose config was edited after it connected
  • Fixed rewind_conversation leaving a backgrounded MCP tool call running after the message that started it was removed
  • Changed Bash/PowerShell timeout to bound a run_in_background command (was ignored; default 30 min, max 2 h); the stopped task notification for a stop at that limit says why
  • Changed getSubagentMessages() to also return the messages a subagent read while it ran, such as a message sent to it; offset and limit count these rows
  • Updated to parity with Claude Code v2.1.285

0.3.284

  • Added a renamed skill's directory name to its SlashCommand aliases when the name is plain and Claude Code ships no command by that name
  • Added applied.ultracodeAvailable and applied.ultracodeRequested to getSettings(): whether this session can run Ultracode, and whether it is requested, independent of whether it is in effect
  • Fixed forkSession() copies reading back the wrong history when cut at a progress row or fork briefing after a rewind, or when the session was compacted with some messages kept
  • Fixed getSessionMessages() leaving out messages from other agents, sessions and channels that the CLI transcript shows
  • Fixed { decision: 'block' } returned by Elicitation and ElicitationResult hook callbacks being ignored; it now declines the MCP elicitation
  • Fixed query() closing stdin before a follow-up turn woken by a finished background agent, which failed that turn's hooks, canUseTool and SDK MCP calls with "Stream closed"
  • Changed the first turn to still wait up to 2s for connecting MCP servers named in allowedTools or by an mcp_tool hook, even with CLAUDE_CODE_MCP_STARTUP_WAIT_MS set to 0

... (truncated)

Commits
  • 16cf0a7 chore: Update CHANGELOG.md
  • 36836f0 chore: Update CHANGELOG.md
  • 9d8cb9c chore: Update CHANGELOG.md
  • 0e21ebb chore: Update CHANGELOG.md
  • 28c70e2 ci: security hardening for the GitHub Actions workflow that calls Claude (#483)
  • 49ac970 chore: Update CHANGELOG.md
  • 41cad2a chore: Update CHANGELOG.md
  • fc99cf7 ci: pin the model for issue triage (#480)
  • 9e1902d chore: Update CHANGELOG.md
  • 9e477a1 chore: Update CHANGELOG.md
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​anthropic-ai/claude-agent-sdk since your current version.


Updates @langchain/core from 1.2.3 to 1.2.14

Release notes

Sourced from @​langchain/core's releases.

@​langchain/core@​1.2.14

Patch Changes

  • #11771 bbed273 Thanks @​thushanth-bengre-langchain! - Add fileMimeTypes to ModelProfile so models can advertise the MIME types they accept as generic file inputs. OpenAI Responses API models now report the file types input_file supports; Chat Completions profiles are unchanged.

@​langchain/core@​1.2.13

Patch Changes

  • #11714 a83dfb1 Thanks @​ccurme! - Abbreviate long tool-call IDs when formatting chat messages as strings, keeping original messages unchanged.

@​langchain/core@​1.2.12

Patch Changes

@​langchain/core@​1.2.11

Patch Changes

  • #11603 fec9cd8 Thanks @​thushanth-bengre-langchain! - fix(core): build streaming llmOutput.tokenUsage from the fully-accumulated chunk instead of whichever individual chunk's usage_metadata arrived last

    Affects both core streaming paths — .stream()/.streamEvents() (_streamIterator) and .invoke()/.generate() when a streaming-preferring callback is attached (_generateWithCache's hasStreamingHandler branch). Previously, llmOutput.tokenUsage was overwritten by each chunk in turn, so only the last chunk carrying usage_metadata won — correct for providers that emit one cumulative total on a final chunk, but wrong for providers (e.g. @langchain/google, @langchain/anthropic) that emit usage_metadata as a per-chunk delta across multiple chunks, where the values must be summed.

    Note for provider authors: this assumes each streamed chunk's usage_metadata is either a per-chunk delta or appears only on a single final chunk. A provider that instead repeats a cumulative total on every chunk will now see it summed (and inflated) in llmOutput.tokenUsage, matching the existing behavior of the correctly-working message.usage_metadata field.

    Also fixes @langchain/google's invoke({streaming: true}) path (no streaming-preferring callback attached), where llmOutput was never populated at all.

  • #11590 ffebdc2 Thanks @​thushanth-bengre-langchain! - Fix OpenAI Responses API replay under Zero Data Retention when a response contains more than one reasoning item, for both v0 and v1. In v0, the default replay path now reuses response_metadata.output directly, preserving every reasoning item's id/encrypted_content in original order. In v1, AIMessage.contentBlocks (outputVersion: "v1") is fixed the same way. additional_kwargs.reasoning is unchanged.

@​langchain/core@​1.2.10

Patch Changes

Commits
  • 417ddcf chore: version packages (#11749)
  • bbed273 feat(openai): report Responses API file MIME types in model profile (#11771)
  • 56a7f0b chore(mcp-adapters): release adapter v2 (#11767)
  • 51b3b7b refactor(mcp-adapters): drop config guards that only served 1.x upgrades (#11...
  • ab0181f feat(mcp-adapters)!: prefix tool names with the server name by default, and r...
  • 347bc0b fix(mcp-adapters): stop cancelled discovery before acquiring another server (...
  • ba4e7a2 fix(mcp-adapters): return MCP tool errors as error ToolMessages (#11758)
  • 17b6bba fix(langchain): preserve graph interrupts through tool retries (#11649)
  • 13283cd feat(mcp-adapters): accept token AuthProviders and keep auth failures retryab...
  • 7a02156 feat(mcp-adapters): langgraph elicitation by default (#11716)
  • Additional commits viewable in compare view

Updates @langchain/langgraph from 1.4.8 to 1.4.19

Release notes

Sourced from @​langchain/langgraph's releases.

@​langchain/langgraph@​1.4.19

Patch Changes

  • #2906 9876bf0 Thanks @​eliornl! - read a subgraph's DeltaChannel with the checkpointer the parent resolved, instead of hydrating it empty; hydrating a written DeltaChannel without a checkpointer or config now throws instead of returning an empty value; state methods resolve the checkpointer the way a run does, so a checkpointer: false graph no longer writes state with a checkpointer lent through the config and has no task state in getState, and a checkpointer: true graph used as a root rejects state methods with the run's error; getState, getStateHistory and updateState use a checkpointer: true subgraph's namespace as its run stores it, so reads find its state and updates are no longer lost; resuming from a subgraph checkpoint returned by getState(config, { subgraphs: true }) now applies the resume value instead of re-firing the interrupt
  • Updated dependencies [cca4806, 7343768]:
    • @​langchain/langgraph-sdk@​1.12.1

@​langchain/langgraph@​1.4.18

Patch Changes

  • Updated dependencies [7a12289]:
    • @​langchain/langgraph-sdk@​1.12.0

@​langchain/langgraph@​1.4.18-rc.0

Patch Changes

  • Updated dependencies [7a12289]:
    • @​langchain/langgraph-sdk@​1.12.0-rc.0

@​langchain/langgraph@​1.4.17

Patch Changes

  • #2861 7639085 Thanks @​casparb! - Add GraphCallbackHandler with typed handleInterrupt and handleResume events through normal callback configuration, matching Python graph lifecycle behavior. Lifecycle callbacks are awaited before terminal chain callbacks and work independently of stream mode.

@​langchain/langgraph@​1.4.16

Patch Changes

  • #2824 e75f6a0 Thanks @​eliornl! - feat(langgraph): add responseSchema option to interrupt()

    interrupt(value, { responseSchema }) lets a graph declare the shape of the value it expects on resume. A Zod schema validates the resume value and the parsed result is what interrupt() returns; a raw JSON Schema object is passed through as-is. The schema is surfaced on Interrupt.response_schema so clients such as Studio can render a typed form instead of a free-form JSON editor. Omitting the option keeps today's behavior.

  • Updated dependencies [e75f6a0]:

    • @​langchain/langgraph-sdk@​1.11.1

@​langchain/langgraph@​1.4.15

Patch Changes

  • #2794 83a4b62 Thanks @​hntrl! - feat(langgraph): add per-node tracePolicy input/output processors and omitPayload

    Transform the payloads recorded on a node's own trace run while retaining its span and timing. Processors receive raw values and fall back to the original payload if they throw. Graph state, root runs, and child runs remain unchanged when processors do not mutate their arguments.

    Matches Python's callback-level behavior: transforms also affect chain events and message streaming, so omitting outputs can suppress messages returned directly by nodes and omitting inputs can affect message deduplication.

  • Updated dependencies [3234c69, 3234c69, 11a4535, 2fab6fd, 4fc118f, db4bdad, 55fa26b]:

    • @​langchain/langgraph-sdk@​1.11.0

@​langchain/langgraph@​1.4.15-rc.0

... (truncated)

Changelog

Sourced from @​langchain/langgraph's changelog.

1.4.19

Patch Changes

  • #2906 9876bf0 Thanks @​eliornl! - read a subgraph's DeltaChannel with the checkpointer the parent resolved, instead of hydrating it empty; hydrating a written DeltaChannel without a checkpointer or config now throws instead of returning an empty value; state methods resolve the checkpointer the way a run does, so a checkpointer: false graph no longer writes state with a checkpointer lent through the config and has no task state in getState, and a checkpointer: true graph used as a root rejects state methods with the run's error; getState, getStateHistory and updateState use a checkpointer: true subgraph's namespace as its run stores it, so reads find its state and updates are no longer lost; resuming from a subgraph checkpoint returned by getState(config, { subgraphs: true }) now applies the resume value instead of re-firing the interrupt
  • Updated dependencies [cca4806, 7343768]:
    • @​langchain/langgraph-sdk@​1.12.1

1.4.18

Patch Changes

  • Updated dependencies [7a12289]:
    • @​langchain/langgraph-sdk@​1.12.0

1.4.18-rc.0

Patch Changes

  • Updated dependencies [7a12289]:
    • @​langchain/langgraph-sdk@​1.12.0-rc.0

1.4.17

Patch Changes

  • #2861 7639085 Thanks @​casparb! - Add GraphCallbackHandler with typed handleInterrupt and handleResume events through normal callback configuration, matching Python graph lifecycle behavior. Lifecycle callbacks are awaited before terminal chain callbacks and work independently of stream mode.

1.4.16

Patch Changes

  • #2824 e75f6a0 Thanks @​eliornl! - feat(langgraph): add responseSchema option to interrupt()

    interrupt(value, { responseSchema }) lets a graph declare the shape of the value it expects on resume. A Zod schema validates the resume value and the parsed result is what interrupt() returns; a raw JSON Schema object is passed through as-is. The schema is surfaced on Interrupt.response_schema so clients such as Studio can render a typed form instead of a free-form JSON editor. Omitting the option keeps today's behavior.

  • Updated dependencies [e75f6a0]:

    • @​langchain/langgraph-sdk@​1.11.1

1.4.15

Patch Changes

  • #2794 83a4b62 Thanks @​hntrl! - feat(langgraph): add per-node tracePolicy input/output processors and omitPayload

    Transform the payloads recorded on a node's own trace run while retaining its span and timing. Processors receive raw values and fall back to the original payload if they throw. Graph state, root runs, and child runs remain unchanged when processors do not mutate their arguments.

... (truncated)

Commits
  • 1cee82d chore: version packages (#2890)
  • 9143976 chore(deps): bump the langchain group across 1 directory with 7 updates (#2933)
  • 537f7eb chore(deps): bump the react group across 1 directory with 6 updates (#2937)
  • 9876bf0 fix(langgraph): hydrate subgraph delta channels with the resolved checkpointe...
  • ec8cb37 chore: version packages (#2870)
  • 285ed3d chore: version packages (rc) (#2868)
  • 3dd35b6 chore: version packages (#2862)
  • 7639085 feat(langgraph): add graph lifecycle callbacks (#2861)
  • ec67d5d chore: version packages (#2852)
  • e75f6a0 feat(langgraph): add responseSchema option to interrupt() (#2824)
  • Additional commits viewable in compare view

Updates @mastra/core from 1.53.0 to 1.74.0

Release notes

Sourced from @​mastra/core's releases.

October 1, 2026

Highlights

Tool Context Can Read the Full Conversation (agent.getMessages())

Tools now have access to the current conversation state via context.agent.getMessages() in both standard and durable agent loops, including remembered messages and in-run responses—enabling richer, context-aware tool behavior without changing the existing input-only messages field.

Observational Memory History Search (Filtering, Ordering, Record Lookup)

getObservationalMemoryHistory gained group filtering (groupId), explicit ordering (sortDirection), and direct lookup by recordId, with adapter capability signaling via supportsObservationalMemoryHistorySearch (notably affecting multiple DB adapters; Convex requires a server function redeploy for the new filters to apply).

Memory Recall Can Page Through Observation Groups Around Search Hits

Recall now supports paging “before/after” from a matched groupId, including groups condensed by reflection and buffered-but-not-yet-activated groups—improving investigation workflows without requiring re-indexing, alongside clearer, chronologically ordered search results and better first-turn retrieval guidance.

Playground UI: New Accessible Form Field Primitives (Field, Fieldset, Form, SearchInput)

A new set of form-building components standardizes label/description/error wiring without manual id/htmlFor, improving accessibility and consistency; includes new Form and SearchInput, plus deprecations of the older *FieldBlock approach to move toward a single, safer pattern.

Breaking Changes

  • @mastra/playground-ui: anchorTraceId removed from ThreadViewByTrace, TraceThreadPanel, and ThreadTrace; ThreadTrace.LoadMoreSentinel removed. Use pageSize and onLoadOlder on ThreadTrace to control pagination/loading older turns.

Changelog

@​mastra/core@1.74.0

Minor Changes

  • Added agent.getMessages() to tool execution context in standard and durable agent loops. Tools can read the current conversation, including remembered messages and in-run responses, without changing the existing input-only messages field. (#25525)

    execute: async (input, context) => {
      const messages = context?.agent?.getMessages?.() ?? [];
      return { messageCount: messages.length };
    };

    The getter reflects message-list removals, but not transient transforms applied only to the provider prompt. Treat returned messages as read-only.

  • Added group filtering and generation ordering to observational memory history. For example, getObservationalMemoryHistory(threadId, resourceId, 1, { groupId, sortDirection: "ASC" }) finds the earliest retained record containing a group in active observations or persisted buffered chunks. Adapters advertise support through supportsObservationalMemoryHistorySearch. Pass recordId to read one record by ID; it only matches records for the requested thread or resource. (#25525)

    Convex users need to redeploy their Mastra server functions for these filters to apply.

    Also in: @​mastra/convex@​1.7.0, @​mastra/libsql@​1.25.0, @​mastra/mongodb@​1.21.0, @​mastra/mysql@​0.12.0, @​mastra/oracledb@​0.5.0, @​mastra/pg@​1.29.0

Patch Changes

  • Update provider registry and model documentation with latest models and providers (ac54c46)

  • Fixed chat channel agents ignoring mentions of their current display name after being renamed. For example, a Slack app renamed from acme-bot to helper now responds to @helper in channels, instead of only recognising its original username. The bot's current profile name is looked up once through the adapter and exposed as botDisplayName on the channel context. (#25652)

  • Raise transitive security dependency floors (dompurify, js-yaml, @​ai-sdk/provider-utils) and bump nested/template deps (nodemailer, fastify, hono, ajv) for the 2026-10-01 Vanta remediation pass. (#25694)

@​mastra/factory@0.19.1

Patch Changes

... (truncated)

Commits
  • b21e46e chore: version - exit prerelease mode
  • a86dc42 feat(memory): make recalled observations navigable (#25525)
  • 486d3b7 chore: version packages (alpha) (#25684)
  • a354bdc chore: version packages
  • 580c22b fix(core): recognise a chat bot's current display name in channel mentions (#...
  • ac54c46 chore: regenerate providers and docs [skip ci]
  • 8b35a6c chore: version - exit prerelease mode
  • 30c6251 chore: regenerate providers and docs [skip ci]
  • de967f0 chore: version packages
  • fab9ba1 fix(core): don't replay aborted runs to replacement thread subscriptions (#25...
  • Additional commits viewable in compare view

Updates @modelcontextprotocol/sdk from 1.29.0 to 1.32.1

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

1.32.1

What's Changed

Full Changelog: modelcontextprotocol/typescript-sdk@1.32.0...1.32.1

1.32.0

Upgrade notes

  • Redirects: the HTTP client transports now follow a redirect only when it stays on the same origin (same scheme, host and port; http to https on the same host is allowed). A deployment whose endpoint redirects to another host or port either configures the final URL or sets redirectPolicy: 'follow' on StreamableHTTPClientTransport or SSEClientTransport. In browsers, a redirected request fails unless that option is set.
  • New options, both off unless you set them: maxToolInputElements on McpServer limits the number of array elements and object members in a tool call's arguments. expectedResource on requireBearerAuth accepts only tokens issued for this server (the token's audience).

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.31.0...1.32.0

1.31.0

Upgrade notes

  • Stored OAuth tokens and client information now include an issuer field. Storage that rejects unknown fields needs to allow it.
  • Pass expectedIssuer when constructing ClientCredentialsProvider, PrivateKeyJwtProvider or StaticPrivateKeyJwtProvider. Constructing them without it is deprecated.

What's Changed

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.1...1.31.0

1.30.1

What's Changed

New Contributors

... (truncated)

Commits
  • ff07b00 chore: bump version to 1.32.1 (#2954)
  • 8a74d50 [v1.x] docs: point the README at v2 and say what v1.x supports (#2942)
  • a8cf503 [v1.x] docs: state the principles in CLAUDE.md (#2939)
  • 32549b0 chore: bump version to 1.32.0 (#2935)
  • 588d51d [v1.x] test(e2e): cover tools/call and prompts/get without arguments (#2931)
  • 5a0724d [v1.x] feat(auth): add expectedResource to requireBearerAuth (#2930)
  • 0ca0b62 [v1.x] fix(server): accept tools/call and prompts/get requests that omit argu...
  • fd26801 [v1.x] feat(server): add maxToolInputElements option to limit the number of e...
  • 727075b [v1.x] fix(tasks): keep tasks of the in-memory task store within the session ...
  • 0ff6377 [v1.x] examples: close idle sessions and cap the session map (#2914)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​modelcontextprotocol/sdk since your current version.


Updates @openai/agents from 0.13.5 to 0.18.0

Commits
  • 71abeaa chore: update versions (#1859)
  • 064fcb2 fix: harden UnixLocal file I/O and route Docker file APIs through containers ...
  • 19d0b5f fix(core): avoid redundant final computer screenshots (#1827)
  • a0f48ff fix: preserve sandbox workdirs for shell command lists (#1862)
  • a3a9215 feat: support the image generation tool action option (#1861)
  • f3bfca2 fix(realtime): preserve agent_end response ownership (#1858)
  • b665b0e fix: recover deferred tools during response continuation (#1856)
  • 78b67df chore: update versions (#1852)
  • 83f3240 chore: remove private packges from changeset targets
  • 8d1f019 fix: preserve model settings for GPT-5 and newer models (#1850)
  • Additional commits viewable in compare view

Updates @types/bun from 1.4.0 to 1.4.2

Commits

Updates ai from 7.0.38 to 7.0.127

Changelog

Sourced from ai's changelog.

7.0.127

Patch Changes

  • 158a718: feat(ai): select and rank eligible deferred tools via 'search()' callback in tool search
  • bb8d33e: fix(ai): cancel merged UI message streams when the consumer disconnects
  • 284dc11: fix(ai): accept unchanged tool approval inputs created in another JavaScript realm
  • ba8afe9: feat(ai): add a configurable maxResults for number of tools returned in tool search
  • Updated dependencies [d1bb9e8]
    • @​ai-sdk/gateway@​4.0.103

7.0.126

Patch Changes

  • 4f3d236: fix: clear tool approvals when addToolOutput runs

7.0.125

Patch Changes

  • ff3dcef: feat(ai): add convertDataPart to agent UI stream helpers

7.0.124

Patch Changes

  • 8c65988: feat(ai): ...

    Description has been truncated

Bumps the minor-and-patch group with 16 updates:

| Package | From | To |
| --- | --- | --- |
| [@ai-sdk/anthropic](https://github.com/vercel/ai/tree/HEAD/packages/anthropic) | `4.0.22` | `4.0.71` |
| [@anthropic-ai/claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-typescript) | `0.3.220` | `0.3.289` |
| [@langchain/core](https://github.com/langchain-ai/langchainjs) | `1.2.3` | `1.2.14` |
| [@langchain/langgraph](https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core) | `1.4.8` | `1.4.19` |
| [@mastra/core](https://github.com/mastra-ai/mastra/tree/HEAD/packages/core) | `1.53.0` | `1.74.0` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.29.0` | `1.32.1` |
| [@openai/agents](https://github.com/openai/openai-agents-js) | `0.13.5` | `0.18.0` |
| [@types/bun](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/bun) | `1.4.0` | `1.4.2` |
| [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `7.0.38` | `7.0.127` |
| [bullmq](https://github.com/taskforcesh/bullmq) | `5.79.3` | `5.81.5` |
| [elysia](https://github.com/elysiajs/elysia) | `1.4.29` | `1.4.30` |
| [fast-check](https://github.com/dubzzz/fast-check/tree/HEAD/packages/fast-check) | `4.9.0` | `4.10.2` |
| [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.64.0` | `0.72.0` |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.79.0` | `1.87.0` |
| [oxlint-tsgolint](https://github.com/oxc-project/tsgolint) | `7.0.2001` | `7.0.2003` |
| [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.6.5` |


Updates `@ai-sdk/anthropic` from 4.0.22 to 4.0.71
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/packages/anthropic/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/@ai-sdk/anthropic@4.0.71/packages/anthropic)

Updates `@anthropic-ai/claude-agent-sdk` from 0.3.220 to 0.3.289
- [Release notes](https://github.com/anthropics/claude-agent-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/claude-agent-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/claude-agent-sdk-typescript@v0.3.220...v0.3.289)

Updates `@langchain/core` from 1.2.3 to 1.2.14
- [Release notes](https://github.com/langchain-ai/langchainjs/releases)
- [Commits](https://github.com/langchain-ai/langchainjs/compare/@langchain/core@1.2.3...@langchain/core@1.2.14)

Updates `@langchain/langgraph` from 1.4.8 to 1.4.19
- [Release notes](https://github.com/langchain-ai/langgraphjs/releases)
- [Changelog](https://github.com/langchain-ai/langgraphjs/blob/main/libs/langgraph-core/CHANGELOG.md)
- [Commits](https://github.com/langchain-ai/langgraphjs/commits/@langchain/langgraph@1.4.19/libs/langgraph-core)

Updates `@mastra/core` from 1.53.0 to 1.74.0
- [Release notes](https://github.com/mastra-ai/mastra/releases)
- [Changelog](https://github.com/mastra-ai/mastra/blob/main/docs/CHANGELOG.md)
- [Commits](https://github.com/mastra-ai/mastra/commits/@mastra/core@1.74.0/packages/core)

Updates `@modelcontextprotocol/sdk` from 1.29.0 to 1.32.1
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@v1.29.0...1.32.1)

Updates `@openai/agents` from 0.13.5 to 0.18.0
- [Release notes](https://github.com/openai/openai-agents-js/releases)
- [Commits](openai/openai-agents-js@v0.13.5...v0.18.0)

Updates `@types/bun` from 1.4.0 to 1.4.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/bun)

Updates `ai` from 7.0.38 to 7.0.127
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/packages/ai/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/ai@7.0.127/packages/ai)

Updates `bullmq` from 5.79.3 to 5.81.5
- [Release notes](https://github.com/taskforcesh/bullmq/releases)
- [Commits](taskforcesh/bullmq@v5.79.3...v5.81.5)

Updates `elysia` from 1.4.29 to 1.4.30
- [Release notes](https://github.com/elysiajs/elysia/releases)
- [Changelog](https://github.com/elysiajs/elysia/blob/main/CHANGELOG.md)
- [Commits](elysiajs/elysia@1.4.29...1.4.30)

Updates `fast-check` from 4.9.0 to 4.10.2
- [Release notes](https://github.com/dubzzz/fast-check/releases)
- [Changelog](https://github.com/dubzzz/fast-check/blob/main/packages/fast-check/CHANGELOG.md)
- [Commits](https://github.com/dubzzz/fast-check/commits/v4.10.2/packages/fast-check)

Updates `oxfmt` from 0.64.0 to 0.72.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.72.0/npm/oxfmt)

Updates `oxlint` from 1.79.0 to 1.87.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.87.0/npm/oxlint)

Updates `oxlint-tsgolint` from 7.0.2001 to 7.0.2003
- [Release notes](https://github.com/oxc-project/tsgolint/releases)
- [Commits](oxc-project/tsgolint@v7.0.2001...v7.0.2003)

Updates `zod` from 4.4.3 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.4.3...v4.6.5)

---
updated-dependencies:
- dependency-name: "@ai-sdk/anthropic"
  dependency-version: 4.0.71
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@anthropic-ai/claude-agent-sdk"
  dependency-version: 0.3.289
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@langchain/core"
  dependency-version: 1.2.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@langchain/langgraph"
  dependency-version: 1.4.19
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@mastra/core"
  dependency-version: 1.74.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.32.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@openai/agents"
  dependency-version: 0.18.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@types/bun"
  dependency-version: 1.4.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: ai
  dependency-version: 7.0.127
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: bullmq
  dependency-version: 5.81.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: elysia
  dependency-version: 1.4.30
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: fast-check
  dependency-version: 4.10.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: oxfmt
  dependency-version: 0.72.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: oxlint
  dependency-version: 1.87.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: oxlint-tsgolint
  dependency-version: 7.0.2003
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 8, 2026
@dependabot
dependabot Bot requested a review from egeominotti as a code owner October 8, 2026 14:41
@dependabot dependabot Bot added the javascript Pull requests that update javascript code label Oct 8, 2026
@vercel

vercel Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Oct 8, 2026 2:48pm UTC

@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: a7885da2-8a5e-47db-bd5b-cfe4d968f0ad

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@egeominotti egeominotti closed this Oct 8, 2026
@egeominotti
egeominotti deleted the dependabot/bun/minor-and-patch-fd76356a24 branch October 8, 2026 15:35
@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

This branch was successfully deployed

1 active deployment
Preview — 760bb0b2 Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant