chore(deps): update npm minor and patch dependencies - #10288
chore(deps): update npm minor and patch dependencies#10288renovate[bot] wants to merge 1 commit into
Conversation
|
Superagent didn't find any vulnerabilities or security issues in this PR. |
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ❌ Deployment failed View logs |
loopover-ui | 60975ff | Aug 03 2026, 01:19 PM |
| "version": "4.20260722.0", | ||
| "resolved": "https://registry.npmjs.org/miniflare/-/miniflare-4.20260722.0.tgz", | ||
| "integrity": "sha512-LW6ABMhCx/yIEFBLC/DO4yAhdm2T/G7jp7pr5T2kj895+CCIaHZqpMXdW9O6YE48LcYcCJChwWc8aEs1vpbTXw==", | ||
| "version": "4.20260730.0", |
There was a problem hiding this comment.
P1: miniflare@4.20260730.0 has 15 supply-chain risks
Superagent correlated 15 risks for this dependency. Top signal: Detects download-and-execute patterns: fetching a remote file then executing it. Location: package/dist/src/index.j…
Review miniflare@4.20260730.0 before merging. Remove or replace it if this behavior is unexpected.
AI prompt
Check if this security scanner issue is valid. If so, understand the root cause and fix it. If appropriate, update or add tests. Keep the change focused and preserve intended behavior.
<file name="control-plane/package-lock.json">
<violation number="1" location="control-plane/package-lock.json:1899">
<priority>P1</priority>
<title>miniflare@4.20260730.0 has 15 supply-chain risks</title>
<evidence>Superagent correlated 15 risks for this dependency. Top signal: Detects download-and-execute patterns: fetching a remote file then executing it. Location: package/dist/src/index.js. Rules: threat-process-download-exec. Rules: capability-filesystem-read, capability-process-spawn, threat-filesystem-read, threat-network-outbound-shady-links, threat-process-download-exec, threat-process-spawn-silent, threat-runtime-obfuscation, threat-runtime-obfuscation-base64exec
Dependency path: control-plane/package-lock.json → miniflare</evidence>
<recommendation>Review miniflare@4.20260730.0 before merging. Remove or replace it if this behavior is unexpected.</recommendation>
</violation>
</file>
| "prettier": "3.9.6", | ||
| "typescript": "^5.9.3", | ||
| "wrangler": "^4.114.0" | ||
| "wrangler": "^4.116.0" |
There was a problem hiding this comment.
P1: wrangler@4.116.0 has 21 supply-chain risks
Superagent correlated 21 risks for this dependency. Top signal: Detects suspicious autostart persistence mechanisms. Location: package/wrangler-dist/cli.js. Rules: threat-filesyst…
Review wrangler@4.116.0 before merging. Remove or replace it if this behavior is unexpected.
AI prompt
Check if this security scanner issue is valid. If so, understand the root cause and fix it. If appropriate, update or add tests. Keep the change focused and preserve intended behavior.
<file name="control-plane/package-lock.json">
<violation number="1" location="control-plane/package-lock.json:21">
<priority>P1</priority>
<title>wrangler@4.116.0 has 21 supply-chain risks</title>
<evidence>Superagent correlated 21 risks for this dependency. Top signal: Detects suspicious autostart persistence mechanisms. Location: package/wrangler-dist/cli.js. Rules: threat-filesystem-autostart. Rules: capability-filesystem-read, capability-network-lolbas, capability-process-spawn, threat-filesystem-autostart, threat-filesystem-read, threat-network-exfiltration, threat-network-outbound-shady-links, threat-process-download-exec, threat-process-spawn-silent, threat-runtime-environment-read, threat-runtime-obfuscation, threat-runtime-obfuscation-base64exec, threat-runtime-obfuscation-steganography
Dependency path: control-plane/package-lock.json → wrangler</evidence>
<recommendation>Review wrangler@4.116.0 before merging. Remove or replace it if this behavior is unexpected.</recommendation>
</violation>
</file>
Superagent Supply Chain ScanSuperagent flagged 15 dependencies introduced by this pull request. High risk:
|
|
f7a4c68 to
60975ff
Compare
This PR contains the following updates:
^0.3.218→^0.3.220^1.1.0→^1.2.0^0.18.8→^0.20.0^5.20260724.1→^5.20260731.1^2.0.11→^2.0.121.1.4→1.3.22.7.7→2.8.31.29.0→1.30.00.9.1→0.9.4^1.2.18→^1.2.20^1.1.21→^1.1.23^1.1.13→^1.1.15^1.2.4→^1.2.6^1.3.9→^1.3.11^1.1.18→^1.1.20^2.3.5→^2.3.7^1.1.21→^1.1.23^2.1.22→^2.1.24^1.1.21→^1.1.23^2.1.13→^2.1.15^1.1.22→^1.1.24^1.2.20→^1.2.22^1.1.21→^1.1.23^1.1.14→^1.1.16^1.4.5→^1.4.7^1.2.16→^1.2.18^2.3.5→^2.3.7^1.1.13→^1.1.15^1.4.5→^1.4.7^1.3.1→^1.3.3^1.3.5→^1.3.7^1.1.19→^1.1.21^1.1.16→^1.1.18^1.1.17→^1.1.19^1.2.14→^1.2.16^0.9.59→^0.9.60^10.67.0→^10.69.0^10.67.0→^10.69.0^1.168.32→^1.168.34^19.2.17→^19.2.18^19.2.3→^19.2.4^0.19.0→^0.20.1^3.1.4→^3.1.5^16.12.1→^16.14.0^15.2.0→^15.2.1^17.7.0→^17.8.0^4.12.31→^4.12.33^12.42.2→^12.43.010.9.8→10.9.9^1.61.1→^1.62.1^8.5.22→^8.5.25^1.409.3→^1.409.4^5.46.1→^5.47.2^7.82.0→^7.83.0^7.5.21→^7.5.224.22.5→4.23.1^2.10.6→^2.10.7^8.1.5→^8.2.0^0.20.8→^0.26.11^4.115.0→^4.117.0^4.114.0→^4.117.0Dependency PRs must keep
npm run test:cipassing. The 97% coverage requirement is enforced as Codecov patch coverage on changed lines (codecov/patch), so dependency-only bumps satisfy it without new tests.GitHub Actions updates must remain SHA-pinned.
Renovate is the sole dependency and security-update bot for this repo; GitHub Dependabot security updates are disabled to avoid duplicate PRs (e.g. the two hono advisory PRs).
Release Notes
anthropics/claude-agent-sdk-typescript (@anthropic-ai/claude-agent-sdk)
v0.3.220Compare Source
v0.3.219Compare Source
cancel_queuedto the interrupt control request (capabilityinterrupt_cancel_queued_v1): cancels queued and pending-dispatch messages alongside the abortfast_mode_disabled_reasonto result and init messages so SDK hosts can explain why fast mode is offDirectoryAddedlifecycle hook event to the control protocol, fired when a new working directory is registered mid-sessionfast_mode_statefrom the spawn-time model after a model switchsandbox.network.strictAllowlistto SDK settings types for deterministically denying non-allowlisted hosts in sandboxed commandsworkflowSizeGuidelineto SDK settings types for setting the advisory dynamic-workflow size guidelinecloudflare/puppeteer (@cloudflare/puppeteer)
v1.2.0Compare Source
What's Changed
Full Changelog: cloudflare/puppeteer@v1.1.0...v1.2.0
cloudflare/workers-sdk (@cloudflare/vitest-pool-workers)
v0.20.0Compare Source
Minor Changes
#14586
5a56ddaThanks @emily-shen! - Breaking change: Remove several options from theminiflareoverride optionsThe following options have been removed from the
miniflareoverride options, as they were not intended to be exposed, were not functional, or have been superseded by other options:wrappedBindingscacheWarnUsagefetchMock: you should useoutboundServiceinsteadcontainerEngine: containers were not supported in vitest-pool-workers. Consider usingcreateTestHarness()instead if you want to test against actual containers.Additionally,
cachehas been deprecated and renamed tocacheAPI, butcacheremains functional.Patch Changes
#14586
5a56ddaThanks @emily-shen! - Preserve the deprecated MiniflarecacheoptionVitest configurations using
cachecontinue to work after the internal Miniflare v5 upgrade. The option is translated tocacheAPI; new configurations should usecacheAPIdirectly.#14586
5a56ddaThanks @emily-shen! - Stop enabling Miniflare's removedunsafeStickyBlobsoptionThe pool no longer sets the
unsafeStickyBlobsMiniflare option, which has been removed. This option was only needed for the Durable Object isolated storage feature that was dropped in 0.13.0, so there is no change in behaviour.Updated dependencies [
5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda,5a56dda]:v0.19.1Compare Source
Patch Changes
01d7020,beec0fb,48f0c6c,8049ca4,d7f38c3,1394867,cc54478,5c25cfe,b21eac2,bb09f1b,1f61001,01d7020,e31ab0f]:v0.19.0Compare Source
Minor Changes
#14879
e6480e3Thanks @dmmulroy! - Add averboseoption tocloudflareTest()andcloudflarePool()configurationSet
verbose: falseto suppress verbose workerd runtime logs, such as caught Durable Object RPC errors. The option defaults totrueto preserve existing output.Patch Changes
#14821
edc203eThanks @mishushakov! - Ignore workerd'sdisconnected: peer disconnected without gracefully ending TLS sessionexception logsWhen tests make real
fetch()calls to external TLS endpoints, servers and load balancers routinely close idle keepalive connections without sending a TLSclose_notify. No request fails — the connection is idle — but workerd logs akj/compat/tls.c++exception with a full stack trace each time, flooding otherwise green test runs. This is the TLS sibling of thedisconnected: ...messages already in the ignore list, so filter it the same way.Updated dependencies [
773ead4,773ead4,09b8a44,4dfb96e,1035f74,e426cb9,3a22ae5,465c0fb,465c0fb,e8b3a9d,552bcfc,b737676,6e0bf6e]:cloudflare/workerd (@cloudflare/workers-types)
v5.20260731.1Compare Source
v5.20260730.1Compare Source
v5.20260729.1Compare Source
v5.20260728.1Compare Source
v5.20260727.1Compare Source
v5.20260726.1Compare Source
honojs/node-server (@hono/node-server)
v2.0.12Compare Source
What's Changed
Full Changelog: honojs/node-server@v2.0.11...v2.0.12
lovablelabs/lovable (@lovable.dev/vite-tanstack-config)
v2.7.0Compare Source
modelcontextprotocol/typescript-sdk (@modelcontextprotocol/sdk)
v1.30.0Compare Source
radix-ui/primitives (@radix-ui/react-accordion)
v1.2.20@radix-ui/react-collapsible@1.1.20,@radix-ui/react-collection@1.1.15,@radix-ui/react-compose-refs@1.1.5,@radix-ui/react-context@1.2.2,@radix-ui/react-direction@1.1.4,@radix-ui/react-id@1.1.4,@radix-ui/react-primitive@2.1.10,@radix-ui/react-use-controllable-state@1.2.6v1.2.19@radix-ui/react-collection@1.1.14,@radix-ui/react-primitive@2.1.9,@radix-ui/react-collapsible@1.1.19radix-ui/primitives (@radix-ui/react-alert-dialog)
v1.1.23@radix-ui/react-compose-refs@1.1.5,@radix-ui/react-context@1.2.2,@radix-ui/react-dialog@1.1.23,@radix-ui/react-primitive@2.1.10v1.1.22@radix-ui/react-dialog@1.1.22,@radix-ui/react-primitive@2.1.9radix-ui/primitives (@radix-ui/react-aspect-ratio)
v1.1.15@radix-ui/react-primitive@2.1.10v1.1.14@radix-ui/react-primitive@2.1.9radix-ui/primitives (@radix-ui/react-avatar)
v1.2.6@radix-ui/react-context@1.2.2,@radix-ui/react-primitive@2.1.10,@radix-ui/react-use-callback-ref@1.1.4,@radix-ui/react-use-is-hydrated@0.1.3,@radix-ui/react-use-layout-effect@1.1.4v1.2.5@radix-ui/react-primitive@2.1.9radix-ui/primitives (@radix-ui/react-checkbox)
v1.3.11@radix-ui/react-compose-refs@1.1.5,@radix-ui/react-context@1.2.2,@radix-ui/react-presence@1.1.10,@radix-ui/react-primitive@2.1.10,@radix-ui/react-use-controllable-state@1.2.6,@radix-ui/react-use-size@1.1.4v1.3.10@radix-ui/react-primitive@2.1.9radix-ui/primitives (@radix-ui/react-collapsible)
v1.1.20@radix-ui/react-compose-refs@1.1.5,@radix-ui/react-context@1.2.2,@radix-ui/react-id@1.1.4,@radix-ui/react-presence@1.1.10,@radix-ui/react-primitive@2.1.10,@radix-ui/react-use-controllable-state@1.2.6,@radix-ui/react-use-layout-effect@1.1.4v1.1.19@radix-ui/react-primitive@2.1.9radix-ui/primitives (@radix-ui/react-context-menu)
v2.3.7@radix-ui/react-context@1.2.2,@radix-ui/react-menu@2.1.24,@radix-ui/react-primitive@2.1.10,@radix-ui/react-use-controllable-state@1.2.6v2.3.6@radix-ui/react-menu@2.1.23,@radix-ui/react-primitive@2.1.9radix-ui/primitives (@radix-ui/react-dialog)
v1.1.23@radix-ui/react-compose-refs@1.1.5,@radix-ui/react-context@1.2.2,@radix-ui/react-dismissable-layer@1.1.19,@radix-ui/react-focus-guards@1.1.6,@radix-ui/react-focus-scope@1.1.16,@radix-ui/react-id@1.1.4,@radix-ui/react-portal@1.1.17,@radix-ui/react-presence@1.1.10,@radix-ui/react-primitive@2.1.10,@radix-ui/react-slot@1.3.3,@radix-ui/react-use-controllable-state@1.2.6,@radix-ui/react-use-layout-effect@1.1.4v1.1.22@radix-ui/react-slot@1.3.2,@radix-ui/react-primitive@2.1.9,@radix-ui/react-dismissable-layer@1.1.18,@radix-ui/react-focus-scope@1.1.15,@radix-ui/react-portal@1.1.16radix-ui/primitives (@radix-ui/react-dropdown-menu)
v2.1.24@radix-ui/react-compose-refs@1.1.5,@radix-ui/react-context@1.2.2,@radix-ui/react-id@1.1.4,@radix-ui/react-menu@2.1.24,@radix-ui/react-primitive@2.1.10,@radix-ui/react-use-controllable-state@1.2.6v2.1.23@radix-ui/react-menu@2.1.23,@radix-ui/react-primitive@2.1.9radix-ui/primitives (@radix-ui/react-hover-card)
v1.1.23@radix-ui/react-compose-refs@1.1.5,@radix-ui/react-context@1.2.2,@radix-ui/react-dismissable-layer@1.1.19,@radix-ui/react-popper@1.3.7,@radix-ui/react-portal@1.1.17,@radix-ui/react-presence@1.1.10,@radix-ui/react-primitive@2.1.10,@radix-ui/react-use-controllable-state@1.2.6v1.1.22@radix-ui/react-primitive@2.1.9,@radix-ui/react-dismissable-layer@1.1.18,@radix-ui/react-focus-scope@1.1.15,@radix-ui/react-popper@1.3.6,@radix-ui/react-portal@1.1.16radix-ui/primitives (@radix-ui/react-label)
v2.1.15@radix-ui/react-primitive@2.1.10v2.1.14@radix-ui/react-primitive@2.1.9radix-ui/primitives (@radix-ui/react-menubar)
v1.1.24@radix-ui/react-collection@1.1.15,@radix-ui/react-compose-refs@1.1.5,@radix-ui/react-context@1.2.2,@radix-ui/react-direction@1.1.4,@radix-ui/react-id@1.1.4,@radix-ui/react-menu@2.1.24,@radix-ui/react-primitive@2.1.10,@radix-ui/react-roving-focus@1.1.19,@radix-ui/react-use-controllable-state@1.2.6v1.1.23@radix-ui/react-collection@1.1.14,@radix-ui/react-menu@2.1.23,@radix-ui/react-primitive@2.1.9,@radix-ui/react-roving-focus@1.1.18radix-ui/primitives (@radix-ui/react-navigation-menu)
v1.2.22@radix-ui/react-collection@1.1.15,@radix-ui/react-compose-refs@1.1.5,@radix-ui/react-context@1.2.2,@radix-ui/react-direction@1.1.4,@radix-ui/react-dismissable-layer@1.1.19,@radix-ui/react-id@1.1.4,@radix-ui/react-presence@1.1.10,@radix-ui/react-primitive@2.1.10,@radix-ui/react-use-callback-ref@1.1.4,@radix-ui/react-use-controllable-state@1.2.6,@radix-ui/react-use-layout-effect@1.1.4,@radix-ui/react-use-previous@1.1.4,@radix-ui/react-visually-hidden@1.2.11v1.2.21@radix-ui/react-collection@1.1.14,@radix-ui/react-primitive@2.1.9,@radix-ui/react-dismissable-layer@1.1.18,@radix-ui/react-visually-hidden@1.2.10radix-ui/primitives (@radix-ui/react-popover)
v1.1.23@radix-ui/react-compose-refs@1.1.5,@radix-ui/react-context@1.2.2,@radix-ui/react-dismissable-layer@1.1.19,@radix-ui/react-focus-guards@1.1.6,@radix-ui/react-focus-scope@1.1.16,@radix-ui/react-id@1.1.4,@radix-ui/react-popper@1.3.7,@radix-ui/react-portal@1.1.17,@radix-ui/react-presence@1.1.10,@radix-ui/react-primitive@2.1.10,@radix-ui/react-slot@1.3.3,@radix-ui/react-use-controllable-state@1.2.6v1.1.22@radix-ui/react-slot@1.3.2,@radix-ui/react-primitive@2.1.9,@radix-ui/react-dismissable-layer@1.1.18,@radix-ui/react-focus-scope@1.1.15,@radix-ui/react-popper@1.3.6,@radix-ui/react-portal@1.1.16radix-ui/primitives (@radix-ui/react-progress)
v1.1.16@radix-ui/react-context@1.2.2,@radix-ui/react-primitive@2.1.10v1.1.15@radix-ui/react-primitive@2.1.9radix-ui/primitives (@radix-ui/react-radio-group)
v1.4.7@radix-ui/react-compose-refs@1.1.5,@radix-ui/react-context@1.2.2,@radix-ui/react-direction@1.1.4,@radix-ui/react-presence@1.1.10,@radix-ui/react-primitive@2.1.10,@radix-ui/react-roving-focus@1.1.19,@radix-ui/react-use-controllable-state@1.2.6,@radix-ui/react-use-size@1.1.4v1.4.6@radix-ui/react-primitive@2.1.9,@radix-ui/react-roving-focus@1.1.18radix-ui/primitives (@radix-ui/react-scroll-area)
v1.2.18@radix-ui/react-compose-refs@1.1.5,@radix-ui/react-context@1.2.2,@radix-ui/react-direction@1.1.4Configuration
📅 Schedule: (in timezone America/Phoenix)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.