Skip to content

chore(deps): update npm minor and patch dependencies - #10288

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-minor-patch
Open

chore(deps): update npm minor and patch dependencies#10288
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@anthropic-ai/claude-agent-sdk ^0.3.218^0.3.220 age confidence
@cloudflare/puppeteer (source) ^1.1.0^1.2.0 age confidence
@cloudflare/vitest-pool-workers (source) ^0.18.8^0.20.0 age confidence
@cloudflare/workers-types ^5.20260724.1^5.20260731.1 age confidence
@hono/node-server ^2.0.11^2.0.12 age confidence
@lovable.dev/vite-plugin-hmr-gate (source) 1.1.41.3.2 age confidence
@lovable.dev/vite-tanstack-config (source) 2.7.72.8.3 age confidence
@modelcontextprotocol/sdk (source) 1.29.01.30.0 age confidence
@posthog/cli (source) 0.9.10.9.4 age confidence
@radix-ui/react-accordion (source) ^1.2.18^1.2.20 age confidence
@radix-ui/react-alert-dialog (source) ^1.1.21^1.1.23 age confidence
@radix-ui/react-aspect-ratio (source) ^1.1.13^1.1.15 age confidence
@radix-ui/react-avatar (source) ^1.2.4^1.2.6 age confidence
@radix-ui/react-checkbox (source) ^1.3.9^1.3.11 age confidence
@radix-ui/react-collapsible (source) ^1.1.18^1.1.20 age confidence
@radix-ui/react-context-menu (source) ^2.3.5^2.3.7 age confidence
@radix-ui/react-dialog (source) ^1.1.21^1.1.23 age confidence
@radix-ui/react-dropdown-menu (source) ^2.1.22^2.1.24 age confidence
@radix-ui/react-hover-card (source) ^1.1.21^1.1.23 age confidence
@radix-ui/react-label (source) ^2.1.13^2.1.15 age confidence
@radix-ui/react-menubar (source) ^1.1.22^1.1.24 age confidence
@radix-ui/react-navigation-menu (source) ^1.2.20^1.2.22 age confidence
@radix-ui/react-popover (source) ^1.1.21^1.1.23 age confidence
@radix-ui/react-progress (source) ^1.1.14^1.1.16 age confidence
@radix-ui/react-radio-group (source) ^1.4.5^1.4.7 age confidence
@radix-ui/react-scroll-area (source) ^1.2.16^1.2.18 age confidence
@radix-ui/react-select (source) ^2.3.5^2.3.7 age confidence
@radix-ui/react-separator (source) ^1.1.13^1.1.15 age confidence
@radix-ui/react-slider (source) ^1.4.5^1.4.7 age confidence
@radix-ui/react-slot (source) ^1.3.1^1.3.3 age confidence
@radix-ui/react-switch (source) ^1.3.5^1.3.7 age confidence
@radix-ui/react-tabs (source) ^1.1.19^1.1.21 age confidence
@radix-ui/react-toggle (source) ^1.1.16^1.1.18 age confidence
@radix-ui/react-toggle-group (source) ^1.1.17^1.1.19 age confidence
@radix-ui/react-tooltip (source) ^1.2.14^1.2.16 age confidence
@scalar/api-reference-react (source) ^0.9.59^0.9.60 age confidence
@sentry/node (source) ^10.67.0^10.69.0 age confidence
@sentry/react (source) ^10.67.0^10.69.0 age confidence
@tanstack/react-start (source) ^1.168.32^1.168.34 age confidence
@types/react (source) ^19.2.17^19.2.18 age confidence
@types/react-dom (source) ^19.2.3^19.2.4 age confidence
agents (source) ^0.19.0^0.20.1 age confidence
fast-uri ^3.1.4^3.1.5 age confidence
fumadocs-core ^16.12.1^16.14.0 age confidence
fumadocs-mdx ^15.2.0^15.2.1 age confidence
globals ^17.7.0^17.8.0 age confidence
hono (source) ^4.12.31^4.12.33 age confidence
motion ^12.42.2^12.43.0 age confidence
npm (source) 10.9.810.9.9 age confidence
playwright (source) ^1.61.1^1.62.1 age confidence
postcss (source) ^8.5.22^8.5.25 age confidence
posthog-js (source) ^1.409.3^1.409.4 age confidence
posthog-node (source) ^5.46.1^5.47.2 age confidence
react-hook-form (source) ^7.82.0^7.83.0 age confidence
tar ^7.5.21^7.5.22 age confidence
tsx (source) 4.22.54.23.1 age confidence
turbo (source) ^2.10.6^2.10.7 age confidence
vite (source) ^8.1.5^8.2.0 age confidence
web-tree-sitter (source) ^0.20.8^0.26.11 age confidence
wrangler (source) ^4.115.0^4.117.0 age confidence
wrangler (source) ^4.114.0^4.117.0 age confidence

Dependency PRs must keep npm run test:ci passing. The 97% coverage requirement is enforced as Codecov patch coverage on changed lines (codecov/patch), so dependency-only bumps satisfy it without new tests.

GitHub Actions updates must remain SHA-pinned.

Renovate is the sole dependency and security-update bot for this repo; GitHub Dependabot security updates are disabled to avoid duplicate PRs (e.g. the two hono advisory PRs).


Release Notes

anthropics/claude-agent-sdk-typescript (@​anthropic-ai/claude-agent-sdk)

v0.3.220

Compare Source

  • Updated to parity with Claude Code v2.1.220

v0.3.219

Compare Source

  • Added opt-in cancel_queued to the interrupt control request (capability interrupt_cancel_queued_v1): cancels queued and pending-dispatch messages alongside the abort
  • Added fast_mode_disabled_reason to result and init messages so SDK hosts can explain why fast mode is off
  • Added DirectoryAdded lifecycle hook event to the control protocol, fired when a new working directory is registered mid-session
  • Fixed the initialize response reporting fast_mode_state from the spawn-time model after a model switch
  • Added sandbox.network.strictAllowlist to SDK settings types for deterministically denying non-allowlisted hosts in sandboxed commands
  • Added workflowSizeGuideline to SDK settings types for setting the advisory dynamic-workflow size guideline
cloudflare/puppeteer (@​cloudflare/puppeteer)

v1.2.0

Compare Source

What's Changed

Full Changelog: cloudflare/puppeteer@v1.1.0...v1.2.0

cloudflare/workers-sdk (@​cloudflare/vitest-pool-workers)

v0.20.0

Compare Source

Minor Changes
  • #​14586 5a56dda Thanks @​emily-shen! - Breaking change: Remove several options from the miniflare override options

    The following options have been removed from the miniflare override options, as they were not intended to be exposed, were not functional, or have been superseded by other options:

    • wrappedBindings
    • cacheWarnUsage
    • fetchMock: you should use outboundService instead
    • containerEngine: containers were not supported in vitest-pool-workers. Consider using createTestHarness() instead if you want to test against actual containers.

    Additionally, cache has been deprecated and renamed to cacheAPI, but cache remains functional.

Patch Changes

v0.19.1

Compare Source

Patch Changes

v0.19.0

Compare Source

Minor Changes
  • #​14879 e6480e3 Thanks @​dmmulroy! - Add a verbose option to cloudflareTest() and cloudflarePool() configuration

    Set verbose: false to suppress verbose workerd runtime logs, such as caught Durable Object RPC errors. The option defaults to true to preserve existing output.

Patch Changes
  • #​14821 edc203e Thanks @​mishushakov! - Ignore workerd's disconnected: peer disconnected without gracefully ending TLS session exception logs

    When tests make real fetch() calls to external TLS endpoints, servers and load balancers routinely close idle keepalive connections without sending a TLS close_notify. No request fails — the connection is idle — but workerd logs a kj/compat/tls.c++ exception with a full stack trace each time, flooding otherwise green test runs. This is the TLS sibling of the disconnected: ... messages already in the ignore list, so filter it the same way.

  • Updated dependencies [773ead4, 773ead4, 09b8a44, 4dfb96e, 1035f74, e426cb9, 3a22ae5, 465c0fb, 465c0fb, e8b3a9d, 552bcfc, b737676, 6e0bf6e]:

    • wrangler@​4.115.0
    • miniflare@​4.20260722.1
cloudflare/workerd (@​cloudflare/workers-types)

v5.20260731.1

Compare Source

v5.20260730.1

Compare Source

v5.20260729.1

Compare Source

v5.20260728.1

Compare Source

v5.20260727.1

Compare Source

v5.20260726.1

Compare Source

honojs/node-server (@​hono/node-server)

v2.0.12

Compare Source

What's Changed

Full Changelog: honojs/node-server@v2.0.11...v2.0.12

lovablelabs/lovable (@​lovable.dev/vite-tanstack-config)

v2.7.0

Compare Source

modelcontextprotocol/typescript-sdk (@​modelcontextprotocol/sdk)

v1.30.0

Compare Source

radix-ui/primitives (@​radix-ui/react-accordion)

v1.2.20

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-collapsible@1.1.20, @radix-ui/react-collection@1.1.15, @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-direction@1.1.4, @radix-ui/react-id@1.1.4, @radix-ui/react-primitive@2.1.10, @radix-ui/react-use-controllable-state@1.2.6

v1.2.19

  • Updated dependencies: @radix-ui/react-collection@1.1.14, @radix-ui/react-primitive@2.1.9, @radix-ui/react-collapsible@1.1.19
radix-ui/primitives (@​radix-ui/react-alert-dialog)

v1.1.23

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-dialog@1.1.23, @radix-ui/react-primitive@2.1.10

v1.1.22

  • Updated dependencies: @radix-ui/react-dialog@1.1.22, @radix-ui/react-primitive@2.1.9
radix-ui/primitives (@​radix-ui/react-aspect-ratio)

v1.1.15

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-primitive@2.1.10

v1.1.14

  • Updated dependencies: @radix-ui/react-primitive@2.1.9
radix-ui/primitives (@​radix-ui/react-avatar)

v1.2.6

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-context@1.2.2, @radix-ui/react-primitive@2.1.10, @radix-ui/react-use-callback-ref@1.1.4, @radix-ui/react-use-is-hydrated@0.1.3, @radix-ui/react-use-layout-effect@1.1.4

v1.2.5

  • Updated dependencies: @radix-ui/react-primitive@2.1.9
radix-ui/primitives (@​radix-ui/react-checkbox)

v1.3.11

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-presence@1.1.10, @radix-ui/react-primitive@2.1.10, @radix-ui/react-use-controllable-state@1.2.6, @radix-ui/react-use-size@1.1.4

v1.3.10

  • Updated dependencies: @radix-ui/react-primitive@2.1.9
radix-ui/primitives (@​radix-ui/react-collapsible)

v1.1.20

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-id@1.1.4, @radix-ui/react-presence@1.1.10, @radix-ui/react-primitive@2.1.10, @radix-ui/react-use-controllable-state@1.2.6, @radix-ui/react-use-layout-effect@1.1.4

v1.1.19

  • Updated dependencies: @radix-ui/react-primitive@2.1.9
radix-ui/primitives (@​radix-ui/react-context-menu)

v2.3.7

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-context@1.2.2, @radix-ui/react-menu@2.1.24, @radix-ui/react-primitive@2.1.10, @radix-ui/react-use-controllable-state@1.2.6

v2.3.6

  • Updated dependencies: @radix-ui/react-menu@2.1.23, @radix-ui/react-primitive@2.1.9
radix-ui/primitives (@​radix-ui/react-dialog)

v1.1.23

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-dismissable-layer@1.1.19, @radix-ui/react-focus-guards@1.1.6, @radix-ui/react-focus-scope@1.1.16, @radix-ui/react-id@1.1.4, @radix-ui/react-portal@1.1.17, @radix-ui/react-presence@1.1.10, @radix-ui/react-primitive@2.1.10, @radix-ui/react-slot@1.3.3, @radix-ui/react-use-controllable-state@1.2.6, @radix-ui/react-use-layout-effect@1.1.4

v1.1.22

  • Updated dependencies: @radix-ui/react-slot@1.3.2, @radix-ui/react-primitive@2.1.9, @radix-ui/react-dismissable-layer@1.1.18, @radix-ui/react-focus-scope@1.1.15, @radix-ui/react-portal@1.1.16
radix-ui/primitives (@​radix-ui/react-dropdown-menu)

v2.1.24

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-id@1.1.4, @radix-ui/react-menu@2.1.24, @radix-ui/react-primitive@2.1.10, @radix-ui/react-use-controllable-state@1.2.6

v2.1.23

  • Updated dependencies: @radix-ui/react-menu@2.1.23, @radix-ui/react-primitive@2.1.9
radix-ui/primitives (@​radix-ui/react-hover-card)

v1.1.23

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-dismissable-layer@1.1.19, @radix-ui/react-popper@1.3.7, @radix-ui/react-portal@1.1.17, @radix-ui/react-presence@1.1.10, @radix-ui/react-primitive@2.1.10, @radix-ui/react-use-controllable-state@1.2.6

v1.1.22

  • Updated dependencies: @radix-ui/react-primitive@2.1.9, @radix-ui/react-dismissable-layer@1.1.18, @radix-ui/react-focus-scope@1.1.15, @radix-ui/react-popper@1.3.6, @radix-ui/react-portal@1.1.16
radix-ui/primitives (@​radix-ui/react-label)

v2.1.15

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-primitive@2.1.10

v2.1.14

  • Updated dependencies: @radix-ui/react-primitive@2.1.9
radix-ui/primitives (@​radix-ui/react-menubar)

v1.1.24

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-collection@1.1.15, @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-direction@1.1.4, @radix-ui/react-id@1.1.4, @radix-ui/react-menu@2.1.24, @radix-ui/react-primitive@2.1.10, @radix-ui/react-roving-focus@1.1.19, @radix-ui/react-use-controllable-state@1.2.6

v1.1.23

  • Updated dependencies: @radix-ui/react-collection@1.1.14, @radix-ui/react-menu@2.1.23, @radix-ui/react-primitive@2.1.9, @radix-ui/react-roving-focus@1.1.18
radix-ui/primitives (@​radix-ui/react-navigation-menu)

v1.2.22

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-collection@1.1.15, @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-direction@1.1.4, @radix-ui/react-dismissable-layer@1.1.19, @radix-ui/react-id@1.1.4, @radix-ui/react-presence@1.1.10, @radix-ui/react-primitive@2.1.10, @radix-ui/react-use-callback-ref@1.1.4, @radix-ui/react-use-controllable-state@1.2.6, @radix-ui/react-use-layout-effect@1.1.4, @radix-ui/react-use-previous@1.1.4, @radix-ui/react-visually-hidden@1.2.11

v1.2.21

  • Updated dependencies: @radix-ui/react-collection@1.1.14, @radix-ui/react-primitive@2.1.9, @radix-ui/react-dismissable-layer@1.1.18, @radix-ui/react-visually-hidden@1.2.10
radix-ui/primitives (@​radix-ui/react-popover)

v1.1.23

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-dismissable-layer@1.1.19, @radix-ui/react-focus-guards@1.1.6, @radix-ui/react-focus-scope@1.1.16, @radix-ui/react-id@1.1.4, @radix-ui/react-popper@1.3.7, @radix-ui/react-portal@1.1.17, @radix-ui/react-presence@1.1.10, @radix-ui/react-primitive@2.1.10, @radix-ui/react-slot@1.3.3, @radix-ui/react-use-controllable-state@1.2.6

v1.1.22

  • Updated dependencies: @radix-ui/react-slot@1.3.2, @radix-ui/react-primitive@2.1.9, @radix-ui/react-dismissable-layer@1.1.18, @radix-ui/react-focus-scope@1.1.15, @radix-ui/react-popper@1.3.6, @radix-ui/react-portal@1.1.16
radix-ui/primitives (@​radix-ui/react-progress)

v1.1.16

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-context@1.2.2, @radix-ui/react-primitive@2.1.10

v1.1.15

  • Updated dependencies: @radix-ui/react-primitive@2.1.9
radix-ui/primitives (@​radix-ui/react-radio-group)

v1.4.7

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-direction@1.1.4, @radix-ui/react-presence@1.1.10, @radix-ui/react-primitive@2.1.10, @radix-ui/react-roving-focus@1.1.19, @radix-ui/react-use-controllable-state@1.2.6, @radix-ui/react-use-size@1.1.4

v1.4.6

  • Updated dependencies: @radix-ui/react-primitive@2.1.9, @radix-ui/react-roving-focus@1.1.18
radix-ui/primitives (@​radix-ui/react-scroll-area)

v1.2.18

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-direction@1.1.4

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/Phoenix)

  • Branch creation
    • "before 6am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Aug 3, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
❌ Deployment failed
View logs
loopover-ui 60975ff Aug 03 2026, 01:19 PM

@superagent-security superagent-security Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Superagent found 14 supply chain issue(s)

Comment thread control-plane/package-lock.json Outdated
"version": "4.20260722.0",
"resolved": "https://registry.npmjs.org/miniflare/-/miniflare-4.20260722.0.tgz",
"integrity": "sha512-LW6ABMhCx/yIEFBLC/DO4yAhdm2T/G7jp7pr5T2kj895+CCIaHZqpMXdW9O6YE48LcYcCJChwWc8aEs1vpbTXw==",
"version": "4.20260730.0",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: miniflare@4.20260730.0 has 15 supply-chain risks

Superagent correlated 15 risks for this dependency. Top signal: Detects download-and-execute patterns: fetching a remote file then executing it. Location: package/dist/src/index.j…

Review miniflare@4.20260730.0 before merging. Remove or replace it if this behavior is unexpected.

AI prompt
Check if this security scanner issue is valid. If so, understand the root cause and fix it. If appropriate, update or add tests. Keep the change focused and preserve intended behavior.

<file name="control-plane/package-lock.json">
<violation number="1" location="control-plane/package-lock.json:1899">
<priority>P1</priority>
<title>miniflare@4.20260730.0 has 15 supply-chain risks</title>
<evidence>Superagent correlated 15 risks for this dependency. Top signal: Detects download-and-execute patterns: fetching a remote file then executing it. Location: package/dist/src/index.js. Rules: threat-process-download-exec. Rules: capability-filesystem-read, capability-process-spawn, threat-filesystem-read, threat-network-outbound-shady-links, threat-process-download-exec, threat-process-spawn-silent, threat-runtime-obfuscation, threat-runtime-obfuscation-base64exec

Dependency path: control-plane/package-lock.json → miniflare</evidence>
<recommendation>Review miniflare@4.20260730.0 before merging. Remove or replace it if this behavior is unexpected.</recommendation>
</violation>
</file>

Comment thread control-plane/package-lock.json Outdated
"prettier": "3.9.6",
"typescript": "^5.9.3",
"wrangler": "^4.114.0"
"wrangler": "^4.116.0"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: wrangler@4.116.0 has 21 supply-chain risks

Superagent correlated 21 risks for this dependency. Top signal: Detects suspicious autostart persistence mechanisms. Location: package/wrangler-dist/cli.js. Rules: threat-filesyst…

Review wrangler@4.116.0 before merging. Remove or replace it if this behavior is unexpected.

AI prompt
Check if this security scanner issue is valid. If so, understand the root cause and fix it. If appropriate, update or add tests. Keep the change focused and preserve intended behavior.

<file name="control-plane/package-lock.json">
<violation number="1" location="control-plane/package-lock.json:21">
<priority>P1</priority>
<title>wrangler@4.116.0 has 21 supply-chain risks</title>
<evidence>Superagent correlated 21 risks for this dependency. Top signal: Detects suspicious autostart persistence mechanisms. Location: package/wrangler-dist/cli.js. Rules: threat-filesystem-autostart. Rules: capability-filesystem-read, capability-network-lolbas, capability-process-spawn, threat-filesystem-autostart, threat-filesystem-read, threat-network-exfiltration, threat-network-outbound-shady-links, threat-process-download-exec, threat-process-spawn-silent, threat-runtime-environment-read, threat-runtime-obfuscation, threat-runtime-obfuscation-base64exec, threat-runtime-obfuscation-steganography

Dependency path: control-plane/package-lock.json → wrangler</evidence>
<recommendation>Review wrangler@4.116.0 before merging. Remove or replace it if this behavior is unexpected.</recommendation>
</violation>
</file>

@superagent-security

superagent-security Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Superagent Supply Chain Scan

Superagent flagged 15 dependencies introduced by this pull request.

High risk: @anthropic-ai/claude-agent-sdk@0.3.220

  • Change: upgraded from 0.3.218 to 0.3.220
  • Dependency path: package-lock.json → @anthropic-ai/claude-agent-sdk
  • Correlated risks: 10
  • Why flagged: Detects suspicious autostart persistence mechanisms. Location: package/bridge.mjs. Rules: threat-filesystem-autostart
  • Risk score: 9.4

High risk: @posthog/cli@0.9.4

  • Change: upgraded from 0.9.1 to 0.9.4
  • Dependency path: package-lock.json → @posthog/cli
  • Correlated risks: 16
  • Why flagged: Detects download-and-execute patterns: fetching a remote file then executing it. Location: package/lib/posthog-api-cli.mjs. Rules: threat-process-download-exec
  • Risk score: 9.4

High risk: @scalar/api-reference@1.64.0

  • Change: upgraded from 1.63.0 to 1.64.0
  • Dependency path: package-lock.json → @scalar/api-reference
  • Correlated risks: 5
  • Why flagged: Detects download-and-execute patterns: fetching a remote file then executing it. Location: package/dist/browser/chunks/vendor-CBP43oHJ.js. Rules: threat-process-download-exec
  • Risk score: 8.8

12 additional actionable issues are shown in the check details.

View Superagent Supply Chain Scan

@codecov

codecov Bot commented Aug 3, 2026

Copy link
Copy Markdown

⚠️ JUnit XML file not found

The CLI was unable to find any JUnit XML files to upload.
For more help, visit our troubleshooting guide.

@renovate
renovate Bot force-pushed the renovate/npm-minor-patch branch from f7a4c68 to 60975ff Compare August 3, 2026 13:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant