chore(deps): update dependency ai to v7.0.107 - #50
Merged
Merged
Conversation
renovate
Bot
force-pushed
the
renovate/ai-7.x-lockfile
branch
from
September 20, 2026 14:43
86f8742 to
fbc34b5
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
7.0.101→7.0.107Release Notes
vercel/ai (ai)
v7.0.107Compare Source
Patch Changes
79681c4: fix(ai): preserve provider file and skill upload APIs in wrapProvider98c7275: fix(ai): preserve query parameters in chat reconnect URLsa105059: fix(workflow): support deferred tool discovery in WorkflowAgent31532f3: fix(ai): prevent preliminary tool outputs from completing chatse61cbd8: fix(ai): preserve raw speech audio format metadata8ade040: fix(ai): pass tool-specific context to input callbacks970a01e: fix(ai): enforce polling timeouts for in-flight video status requests85539c5: fix(ai): preserve multiple Set-Cookie headers in Node stream responses611d301: fix(ai): prevent duplicate content types in chat transport requestsc415657: fix(ai): decode base64 text data URLs using their declared charset2973485]a4db5ea]2937ea2]v7.0.106Compare Source
Patch Changes
4775577: fix(ai): preserve provider metadata when simulating text streams6696728: fix(ai): report the prepareStep model in streamed step results09516a1: fix(ai): prevent unhandled rejections when UI message stream reading stops early1aef01e: fix(ai): preserve prototype-named properties in serialized tool outputs9c1ea74: fix(ai): close telemetry spans when provider response streams fail107343a: fix(ai): use the prepareStep-selected model for streamed response metadata fallbacks03c3e33: fix(ai): preserve tool calls required by retained pending approvals5d42ebd: fix(ai): skip input available callbacks for invalid streamed tool calls4a67783: fix(ai): cancel prompt attachment downloads when model calls are aborted or time out1058ed5: fix(ai): strip streamed JSON fences before arbitrary trailing whitespace84f5d1b: fix(ai): stream null and empty string JSON partial outputs2d53a5d: fix(ai): prevent onEnd after aborting a multi-step text stream2a5ed55: fix(ai): stream structured output from the final tool-loop step4fdf51e]0455398]v7.0.105Compare Source
Patch Changes
6982e9d: Resolve evaluation model IDs through AI Gateway when no default provider is configured, including string aliases in custom providers.6982e9d]6982e9d]v7.0.104Compare Source
Patch Changes
a7dd893: Add experimental evaluation model aliases and registry resolution.customProvideracceptsevaluationModels, registries exposeevaluationModel, andexperimental_evaluateaccepts string IDs when an evaluation-capable default provider is explicitly configured. Evaluation never implicitly falls back to Gateway. Model-resolution errors now identifyevaluationModelwhile stable provider contracts remain unchanged.227f3b0: fix(ai): report abnormal realtime WebSocket close diagnostics throughonError3456e2c: feat(ai): support tool search with direct tool callingc4e76de: feat(ai): add native tool search tool215b25e]d4d96bf]a7dd893]3456e2c]c4e76de]v7.0.103Compare Source
Patch Changes
91c2128: feat(ai): add mid conversation tool discovery/updates for code-mode25a0447: feat(ai): deprecate rawInput in output-error UI message parts2cd80b3: Keep default Node.js downloads protected by DNS validation and connection pinning when frameworks or instrumentation wrap global fetch before or after the SDK loads.123d71f: Addexperimental_evaluateand the isolated experimental v4 evaluation model specification for Choice, Score, and Boolean questions against shared state. Includes typed answers, optional Choice/Score distributions, required Boolean probabilities, validation, retries, cancellation, andExperimental_EvaluationUnsupportedQuestionTypeErrorfor unsupported questions.91c2128]0c9ab5a]2cd80b3]d06bb2a]123d71f]2fa5e0e]2cce7da]v7.0.102Compare Source
Patch Changes
5c0054d: Add optional browser-direct WebRTC for experimental client-delegated Live conversations alongside the existing WebSocket path. Exchange SDP through an application endpoint withapi.session, configure server-owned data-channel permissions, and preserve committed React session ownership. Capture follows the selected sender track, borrowed tracks remain caller-owned, and disconnect recovery and finalization stay bounded. Applications continue to handle client delegation and submit context; Live session updates and Responses delegation remain unsupported.Serialize microphone sender changes and close the peer if detachment fails, without stopping borrowed tracks. Validate nonempty SDP setup answers with a bounded response body, and document the same-origin broker authentication contract.
39535af: Add experimental OpenAI Live provider support through the unifiedopenai.experimental_realtimefactory for server WebSocket sessions with client delegation. Applications own their agents and tools, receive continuous audio/transcript events and delegation metadata, and return context through validated channels. Support immutable startup options, microphone mute controls, graceful session close, and cumulative voice usage. Responses delegation and Live session updates reject before sending.Route known Live model IDs to Live, allow an OpenAI-specific
apioverride for early-access models, and preserve legacy Realtime defaults for unknown IDs. Token minting follows the same selection rules and rejects Live before requesting unsupported credentials. Extend the realtime v4 specification with optional server WebSocket configuration, per-connection raw-event parsers, and model-wide startup/finalization capabilities. This provider layer supplies connection settings and protocol mapping for server adapters; browser lifecycle and UI integration belong to the core runtime and framework hooks.Preserve Realtime client event IDs for session updates and audio appends, and correlate server errors with the originating client event.
8b92ba9: fix(ai): settle automatically denied tool calls in UI streams4b306c2: Report abnormal realtime WebSocket close codes and reasons through the session error path.4b306c2: Add the client-delegation-first realtime WebSocket runtime with session lifecycle, exact final duration, bounded event queues and command acknowledgement tracking, transcripts, context append, and reversible capture. Continuous sessions support PCM16 audio-chunk playback over an application relay with a recoverable live-edge buffer policy. Legacy turn-based WebSockets retain queued playback and frontend tool handling.Remove the deferred managed Responses coordinator, autoContinueTools option, backend usage state, and Live tool-result aliases. Continuous text and delegation handling belong to the application; sendTextMessage and addToolOutput reject continuous sessions. Server-confirmed provider delegation and turn-based audio-delta on the continuous profile fail explicitly. maxPlaybackBufferSeconds is supported only for continuous PCM sessions.
Fence callbacks, startup publications, tool results, and teardown by connection attempt. Validate token setup before opening a client-secret socket, require explicit relay transport mode, and include WebSocket URL, protocol values, and runtime timeouts/buffer settings in React session configuration keys.
Retain immediate local capture for explicit legacy preconnect streams, including owned-track cleanup and capture continuity through asynchronous setup. Signal transport closing before draining accepted terminal events, share reentrant close settlement, and cancel stale readiness and deadlines. Enforce 128 KiB frame and combined buffered-send budgets only for Live continuous sessions, using actual encoded wire bytes; oversized manual operations remain recoverable while startup and automatic audio failures close the session. Legacy startup, text, tool output, and audio retain their pre-Live behavior without these byte caps. Live pending-audio overflow drains accepted terminal usage within the existing one-second drain window. Validate final provider-transformed WebSocket URL syntax without removing native authentication query parameters.
Updated dependencies [
5c0054d]Updated dependencies [
39535af]Configuration
📅 Schedule: (in timezone Europe/Rome)
* 0-6 * * 6,0)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.