fix(deps): update all non-major dependencies - #119
Closed
renovate[bot] wants to merge 1 commit into
Closed
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 2, 2026 14:50
e9c74cd to
603e19e
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 2, 2026 17:18
603e19e to
f6fca5c
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 2, 2026 21:57
f6fca5c to
7862edc
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 3, 2026 01:03
7862edc to
f145af9
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 3, 2026 04:57
f145af9 to
dfffa75
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 3, 2026 21:56
dfffa75 to
368afd0
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 4, 2026 01:51
368afd0 to
b4b40d1
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 4, 2026 10:35
b4b40d1 to
8996532
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 4, 2026 21:26
8996532 to
4ef246e
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 5, 2026 01:03
4ef246e to
be8539a
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 5, 2026 04:50
be8539a to
e94cc10
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 5, 2026 19:44
e94cc10 to
633c46d
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 5, 2026 23:57
633c46d to
8655aa9
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 6, 2026 00:41
8655aa9 to
2407f4c
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 10, 2026 20:40
7be769a to
b61f9e6
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 11, 2026 18:10
b61f9e6 to
b70c649
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 11, 2026 20:48
b70c649 to
3dcafe2
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 12, 2026 13:50
3dcafe2 to
158462e
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 12, 2026 21:42
158462e to
2cb8203
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 13, 2026 10:51
2cb8203 to
aa92a23
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 13, 2026 22:36
aa92a23 to
18c57fc
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 16, 2026 14:17
18c57fc to
700db4e
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 16, 2026 21:48
700db4e to
d75b722
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 17, 2026 01:21
d75b722 to
e056928
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 17, 2026 09:23
e056928 to
e2fcddc
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 17, 2026 12:35
e2fcddc to
7c18a42
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 17, 2026 21:08
7c18a42 to
e892507
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 18, 2026 01:39
e892507 to
1085560
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
from
March 18, 2026 16:53
1085560 to
6b43672
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.0.11→4.0.164.0.30→4.0.340.41.1→0.41.23.1085.0→3.1090.03.1085.0→3.1090.04.3.2→4.3.37.0.28→7.0.3110.5.3→10.5.41.0.0-beta.4→1.0.0-beta.80.38.49→0.38.5011.1.11→11.1.155.0.0-beta.30→5.0.0-beta.314.3.2→4.3.34.110.0→4.112.0Release Notes
vercel/ai (@ai-sdk/openai)
v4.0.16Compare Source
Patch Changes
75f86f4: fix(provider/openai, provider/open-responses): throw a descriptive error when the Responses API returns a 200 with nooutputA successful (200) Responses body missing the
outputarray previously threw an opaqueoutput is not iterableTypeError fromdoGenerate. Both providers now surface a clearAPICallError("Responses API returned no output …"), including the incomplete-details reason (and status, for open-responses) when present. When the body includes aresponse.error, its message is surfaced first so upstream error details aren't masked by the generic fallback. This makes malformed/incomplete upstream responses actionable instead of a cryptic crash.Updated dependencies [
cd06458]v4.0.15Compare Source
Patch Changes
0063c2d: Add the client-executed OpenAI Responses API computer tool with batched actions and screenshot outputs.v4.0.14Compare Source
Patch Changes
31c7be8]v4.0.13Compare Source
Patch Changes
7805e4a: Fix realtime transcription auth header handling: per-callauthorizationheaders now override configuration headers regardless of header-key casing (last case-variant wins), and theBearerscheme is matched case-insensitively.cd12954: Reject empty OpenAI, Anthropic, and Replicate base URLs with a helpful AI SDKinvalid argument error.
4be62c1]7805e4a]cd12954]vercel/ai (@ai-sdk/react)
v4.0.34Compare Source
Patch Changes
70f18c3]cd06458]d84ea43]v4.0.33Compare Source
Patch Changes
v4.0.32Compare Source
Patch Changes
v4.0.31Compare Source
Patch Changes
48e7e78: Harden MCP Apps handling of server-supplied resource metadata and the host/iframe bridge:_meta.uiand drop malformed or non-string fields.sandbox.allowedPermissionsallowlist.postMessagetarget origin and validate inbound message origins.resources/readtoui://resources and allow onlyhttps/http/mailtoinui/open-link.fingerprintMCPAppResource/detectMCPAppResourceDriftfor pinning and comparing app resources.Updated dependencies [
48e7e78]nextauthjs/next-auth (@auth/core)
v0.41.2Compare Source
Bugfixes
Other
aws/aws-sdk-js-v3 (@aws-sdk/client-s3)
v3.1090.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1089.0Compare Source
3.1089.0(2026-07-16)
Chores
Documentation Changes
New Features
Bug Fixes
Tests
For list of updated packages, view updated-packages.md in assets-3.1089.0.zip
v3.1088.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1087.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
v3.1086.0Compare Source
Note: Version bump only for package @aws-sdk/client-s3
aws/aws-sdk-js-v3 (@aws-sdk/s3-request-presigner)
v3.1090.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1089.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1088.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1087.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
v3.1086.0Compare Source
Note: Version bump only for package @aws-sdk/s3-request-presigner
tailwindlabs/tailwindcss (@tailwindcss/postcss)
v4.3.3Compare Source
Fixed
--watch --poll[=ms]in@tailwindcss/cliwhen filesystem events are unreliable or unavailable (#20297)bg-[#fff]andbg-[#FFF]→bg-white) (#20298)iframe:focus-visibleoutline styles (#20292)theme('colors.foo')in JS plugins resolves correctly when both--color-fooand--color-foo-barexist (#20299)shadow-sm/12.5,text-shadow-sm/12.5,drop-shadow-sm/12.5, andinset-shadow-sm/12.5(#20302)[data-foo]divas two selectors instead of one (#20303)@tailwindcss/postcssrebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (#20310)@tailwindcss/browserand Tailwind Play (#20124)oklch(#20314)--spacing(0)is optimized to0pxinstead of0so it remains a<length>when used incalc(…)(#20319)@parcel/watcheronly when needed in@tailwindcss/cli --watchmode, so one-off builds and--watch --pollwork when@parcel/watchercan't be loaded (#20325)system-uiandui-sans-serifso CJK text respects the page'slangattribute on Windows (#20318)@tailwindcss/upgradefrom rewriting ignored files when run from a subdirectory (#20329)@sourcerules pointing to nested files are scanned when later@sourcerules point to files in parent folders (#20335)@tailwindcss/vitefrom triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (#20336)vercel/ai (ai)
v7.0.31Compare Source
Patch Changes
70f18c3: fix(ai): emit denied tool output state for client-rejected approvalscd06458: fix(ai): callonInputStartbeforeonInputAvailableduring non-streaming tool callscd06458]v7.0.30Compare Source
Patch Changes
341616a]70fc45c]v7.0.29Compare Source
Patch Changes
7069785]4bf9ac2]postcss/autoprefixer (autoprefixer)
v10.5.4Compare Source
discordjs/discord-api-types (discord-api-types)
v0.38.50Compare Source
Features
is_spoiler(#1700) (0e09f22)immerjs/immer (immer)
v11.1.15Compare Source
Bug Fixes
v11.1.14Compare Source
Bug Fixes
v11.1.13Compare Source
Bug Fixes
v11.1.12Compare Source
Bug Fixes
tailwindlabs/tailwindcss (tailwindcss)
v4.3.3Compare Source
Fixed
--watch --poll[=ms]in@tailwindcss/cliwhen filesystem events are unreliable or unavailable (#20297)bg-[#fff]andbg-[#FFF]→bg-white) (#20298)iframe:focus-visibleoutline styles (#20292)theme('colors.foo')in JS plugins resolves correctly when both--color-fooand--color-foo-barexist (#20299)shadow-sm/12.5,text-shadow-sm/12.5,drop-shadow-sm/12.5, andinset-shadow-sm/12.5(#20302)[data-foo]divas two selectors instead of one (#20303)@tailwindcss/postcssrebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (#20310)@tailwindcss/browserand Tailwind Play (#20124)oklch(#20314)--spacing(0)is optimized to0pxinstead of0so it remains a<length>when used incalc(…)(#20319)@parcel/watcheronly when needed in@tailwindcss/cli --watchmode, so one-off builds and--watch --pollwork when@parcel/watchercan't be loaded (#20325)system-uiandui-sans-serifso CJK text respects the page'slangattribute on Windows (#20318)@tailwindcss/upgradefrom rewriting ignored files when run from a subdirectory (#20329)@sourcerules pointing to nested files are scanned when later@sourcerules point to files in parent folders (#20335)@tailwindcss/vitefrom triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (#20336)cloudflare/workers-sdk (wrangler)
v4.112.0Compare Source
Minor Changes
#14470
3de70dfThanks @DiogoSantoss! - Add a top-leveladdressesfield to Wrangler configuration for Email RoutingYou can now declare the inbound email addresses handled by your Worker directly in
wrangler.json:{ "name": "my-worker", "main": "src/index.ts", "compatibility_date": "2026-05-21", "addresses": ["support@example.com", "*@​example.com"] }#14706
cb6c3f9Thanks @edmundhung! - Add Durable Object storage access tocreateTestHarness()You can now execute SQL against a SQLite-backed Durable Object to seed or assert the storage state.
#14562
9f04a7eThanks @martijnwalraven! - Emit a typedruntimeErrorevent on theunstable_startWorkerDevEnv for uncaught Worker exceptionsUncaught Worker exceptions were only source-mapped and printed, so programmatic consumers had to scrape terminal output to observe them. The DevEnv now re-emits a
RuntimeErrorEvent(likereloadComplete) carrying the exception text and source-mapped stack — fed from Miniflare's pretty-error seam via the newhandleUncaughtErroroption for exceptions the runtime catches, and from the inspector for those it does not.Patch Changes
#14682
d39ae01Thanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#14725
c79504fThanks @edmundhung! - Support containers increateTestHarness()Workers configured with containers can now be tested using
createTestHarness(). The harness builds configured images and makes container-backed Durable Objects available during integration tests.#14696
c7dbe1aThanks @martijnwalraven! - Typeunstable_startWorker,DevEnv.startWorker, andConfigController.set/patchagainstWranglerStartDevWorkerInput, so the wrangler-specificdev.structuredLogsHandlerfield the runtime already honors is expressible through the public API. Previously the public signatures took the baseStartDevWorkerInput, and callers passing the handler needed a cast while internal callers (the test harness) routed the wider type around the signature.#14494
4e1a7a7Thanks @petebacondarwin! - Register a workers.dev subdomain before uploading a new WorkerDeploying a Worker for the first time on an account that has no workers.dev subdomain failed with an opaque API error raised by the upload request itself (code 10063, "You need a workers.dev subdomain in order to proceed"). Wrangler now checks for a workers.dev subdomain before uploading a brand-new Worker that publishes to workers.dev and prompts you to register one, so you get a clear, actionable message instead of a cryptic API failure. The check is skipped for deploys that don't target workers.dev (routes-only deploys, or
workers_dev: false) and for existing Workers, since their account already has a subdomain.Updated dependencies [
34e696d,d39ae01,9f04a7e,9f04a7e,cb30df3,cb6c3f9,3f3afbb,e6fbc4e]:v4.111.0Compare Source
Minor Changes
#14602
7692a61Thanks @edmundhung! - Add Durable Object eviction support tocreateTestHarnessYou can now gracefully evict a running Durable Object by class name or binding name to verify how it recovers after its instance is torn down:
#14620
899c297Thanks @penalosa! - Remove support for service environments and thelegacy_envconfiguration fieldService environments have been removed. Wrangler now always deploys each environment as its own Worker named
<name>-<environment>, which matches the behaviour of the previous default (legacy_env = true). The--legacy-envCLI flag has been removed, and thelegacy_envconfiguration field is no longer supported — including it in your configuration file will now raise an error.Because
legacy_env = truewas already the default, removing the field will not change how your Worker is deployed. If you were relying on service environments (legacy_env = false), each environment will now be deployed as a standalone Worker instead of as an environment of a single Worker. See https://developers.cloudflare.com/workers/wrangler/environments/ for more information.#14652
317ce1fThanks @jamesopstad! - Append Workers runtime types to the generated types under--x-new-config, with a newdev.types.includeRuntimeoptionWhen running
wrangler dev --x-new-config, the runtime types generated from your compatibility date and flags are now appended toworker-configuration.d.ts, alongside the types inferred fromcloudflare.config.ts. This is controlled by a newdev.types.includeRuntimeoption inwrangler.config.ts, which defaults totrue.This applies to the experimental new config path only and does not change type generation for existing
wrangler.jsonc/wrangler.tomlprojects.Patch Changes
#14627
ed33326Thanks @tpmmorris! - Add convenient logging for worker emails in the project directory. In addition to the system's temp directory, logs for emails sent by workers are also written to a local temp directory defined by the calling process, e.g for an simple text email sent via Wrangler this is.wrangler/tmp/email/<session>/email-text/<message-uuid>.txt(and related files) in the project root. Callers of Miniflare can control this location via the newdefaultProjectTmpPathoption, which Wrangler and Vite plugin now set automatically.#14642
018574bThanks @dependabot! - Update dependencies of "miniflare", "wrangler"The following dependency versions have been updated:
#14588
eb99ab1Thanks @emily-shen! - fix: Respect auth profiles when using remote bindings in the Vite pluginAuth profiles (configured via
wrangler auth createandwrangler auth activate) were previously being ignored when using remote bindings with the Vite plugin. This is now fixed.Note that the profile directory is resolved based on the Vite project root.
#14658
cdf3148Thanks @ATKasem! - Fixwrangler devcorrupting external hostnames in proxied response headersWhen a Worker was run with
routesconfigured,wrangler dev's proxy rewrote the host inside URL-valued headers (such asLocation) using a boundary-less substring replace. Any host that merely contained the route host as a substring was corrupted — e.g. with anexample.comroute, aLocation: https://books.example.com/read/ch01header becamehttps://books.127.0.0.1:8788/read/ch01, andhttps://myexample.com/pathbecamehttps://my127.0.0.1:8788/path.The proxy now only rewrites absolute URLs whose host is exactly the proxied host, swapping the scheme and host together (which also fixes a related case where an
https:scheme survived on a plain-HTTP dev address). Unrelated hosts and subdomains pass through untouched.#14601
3015320Thanks @MattieTK! - Improve the agent-facing--forceguidance for Pages-to-Workers delegationWhen an AI agent opts out of the Pages-to-Workers delegation by passing
--forcetowrangler pages deployorwrangler pages project create, Wrangler now prints a notice at the end of a successful command explaining that--forceonly needs to be passed once: the project then exists, so subsequent commands are no longer delegated and do not need the flag.#14569
9da77acThanks @dario-piotrowicz! - Suggest similar commands when a typo is detectedWhen an unknown command or subcommand is entered, wrangler now suggests the closest matching command if one exists within a reasonable edit distance. For example, running
wrangler whoamiowill displayDid you mean "wrangler whoami"?, and runningwrangler kv namespasewill displayDid you mean "wrangler kv namespace"?.Updated dependencies [
7692a61,ed33326,018574b,7692a61]:Configuration
📅 Schedule: (in timezone Asia/Singapore)
* 0-3 1 * *)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.