chore(deps): bump the patches group across 1 directory with 24 updates#3025
chore(deps): bump the patches group across 1 directory with 24 updates#3025dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the patches group with 24 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@ai-sdk/mcp](https://github.com/vercel/ai/tree/HEAD/packages/mcp) | `1.0.35` | `1.0.43` | | [@ai-sdk/openai-compatible](https://github.com/vercel/ai/tree/HEAD/packages/openai-compatible) | `2.0.41` | `2.0.47` | | [@ai-sdk/react](https://github.com/vercel/ai/tree/HEAD/packages/react) | `3.0.155` | `3.0.192` | | [@headlessui/react](https://github.com/tailwindlabs/headlessui/tree/HEAD/packages/@headlessui-react) | `2.2.0` | `2.2.10` | | [@opentelemetry/api](https://github.com/open-telemetry/opentelemetry-js) | `1.9.0` | `1.9.1` | | [@radix-ui/react-accordion](https://github.com/radix-ui/primitives) | `1.2.3` | `1.2.12` | | [@radix-ui/react-avatar](https://github.com/radix-ui/primitives) | `1.1.3` | `1.1.11` | | [@radix-ui/react-collapsible](https://github.com/radix-ui/primitives) | `1.1.11` | `1.1.12` | | [@radix-ui/react-dialog](https://github.com/radix-ui/primitives) | `1.1.6` | `1.1.15` | | [@radix-ui/react-dropdown-menu](https://github.com/radix-ui/primitives) | `2.1.6` | `2.1.16` | | [@radix-ui/react-hover-card](https://github.com/radix-ui/primitives) | `1.1.6` | `1.1.15` | | [@radix-ui/react-label](https://github.com/radix-ui/primitives) | `2.1.2` | `2.1.8` | | [@radix-ui/react-scroll-area](https://github.com/radix-ui/primitives) | `1.2.9` | `1.2.10` | | [@radix-ui/react-select](https://github.com/radix-ui/primitives) | `2.2.5` | `2.2.6` | | [@radix-ui/react-separator](https://github.com/radix-ui/primitives) | `1.1.2` | `1.1.8` | | [@radix-ui/react-tabs](https://github.com/radix-ui/primitives) | `1.1.3` | `1.1.13` | | [@react-three/fiber](https://github.com/pmndrs/react-three-fiber) | `9.6.0` | `9.6.1` | | [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `6.0.153` | `6.0.190` | | [jsonwebtoken](https://github.com/auth0/node-jsonwebtoken) | `9.0.2` | `9.0.3` | | [langfuse](https://github.com/langfuse/langfuse-js/tree/HEAD/langfuse) | `3.38.4` | `3.38.20` | | [livekit-server-sdk](https://github.com/livekit/node-sdks/tree/HEAD/packages/livekit-server-sdk) | `2.15.0` | `2.15.3` | | [nanoid](https://github.com/ai/nanoid) | `5.1.5` | `5.1.11` | | [openai-edge](https://github.com/dan-kwiat/openai-edge) | `1.2.2` | `1.2.3` | | [use-stick-to-bottom](https://github.com/stackblitz/use-stick-to-bottom) | `1.1.1` | `1.1.4` | Updates `@ai-sdk/mcp` from 1.0.35 to 1.0.43 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/@ai-sdk/mcp@1.0.43/packages/mcp/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/mcp@1.0.43/packages/mcp) Updates `@ai-sdk/openai-compatible` from 2.0.41 to 2.0.47 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/@ai-sdk/openai-compatible@2.0.47/packages/openai-compatible/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/openai-compatible@2.0.47/packages/openai-compatible) Updates `@ai-sdk/react` from 3.0.155 to 3.0.192 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/@ai-sdk/react@3.0.192/packages/react/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/react@3.0.192/packages/react) Updates `@headlessui/react` from 2.2.0 to 2.2.10 - [Release notes](https://github.com/tailwindlabs/headlessui/releases) - [Changelog](https://github.com/tailwindlabs/headlessui/blob/main/packages/@headlessui-react/CHANGELOG.md) - [Commits](https://github.com/tailwindlabs/headlessui/commits/@headlessui/react@v2.2.10/packages/@headlessui-react) Updates `@opentelemetry/api` from 1.9.0 to 1.9.1 - [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-js@v1.9.0...v1.9.1) Updates `@radix-ui/react-accordion` from 1.2.3 to 1.2.12 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-avatar` from 1.1.3 to 1.1.11 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-collapsible` from 1.1.11 to 1.1.12 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-dialog` from 1.1.6 to 1.1.15 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-dropdown-menu` from 2.1.6 to 2.1.16 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-hover-card` from 1.1.6 to 1.1.15 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-label` from 2.1.2 to 2.1.8 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-scroll-area` from 1.2.9 to 1.2.10 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-select` from 2.2.5 to 2.2.6 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-separator` from 1.1.2 to 1.1.8 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-tabs` from 1.1.3 to 1.1.13 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@react-three/fiber` from 9.6.0 to 9.6.1 - [Release notes](https://github.com/pmndrs/react-three-fiber/releases) - [Commits](pmndrs/react-three-fiber@v9.6.0...v9.6.1) Updates `ai` from 6.0.153 to 6.0.190 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/ai@6.0.190/packages/ai/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/ai@6.0.190/packages/ai) Updates `jsonwebtoken` from 9.0.2 to 9.0.3 - [Changelog](https://github.com/auth0/node-jsonwebtoken/blob/master/CHANGELOG.md) - [Commits](auth0/node-jsonwebtoken@v9.0.2...v9.0.3) Updates `langfuse` from 3.38.4 to 3.38.20 - [Release notes](https://github.com/langfuse/langfuse-js/releases) - [Commits](https://github.com/langfuse/langfuse-js/commits/v3.38.20/langfuse) Updates `livekit-server-sdk` from 2.15.0 to 2.15.3 - [Release notes](https://github.com/livekit/node-sdks/releases) - [Changelog](https://github.com/livekit/node-sdks/blob/main/packages/livekit-server-sdk/CHANGELOG.md) - [Commits](https://github.com/livekit/node-sdks/commits/livekit-server-sdk@2.15.3/packages/livekit-server-sdk) Updates `nanoid` from 5.1.5 to 5.1.11 - [Release notes](https://github.com/ai/nanoid/releases) - [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md) - [Commits](ai/nanoid@5.1.5...5.1.11) Updates `openai-edge` from 1.2.2 to 1.2.3 - [Commits](https://github.com/dan-kwiat/openai-edge/commits) Updates `use-stick-to-bottom` from 1.1.1 to 1.1.4 - [Changelog](https://github.com/stackblitz-labs/use-stick-to-bottom/blob/main/CHANGELOG.md) - [Commits](https://github.com/stackblitz/use-stick-to-bottom/commits) --- updated-dependencies: - dependency-name: "@ai-sdk/mcp" dependency-version: 1.0.43 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@ai-sdk/openai-compatible" dependency-version: 2.0.47 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@ai-sdk/react" dependency-version: 3.0.192 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@headlessui/react" dependency-version: 2.2.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@opentelemetry/api" dependency-version: 1.9.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-accordion" dependency-version: 1.2.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-avatar" dependency-version: 1.1.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-collapsible" dependency-version: 1.1.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-dialog" dependency-version: 1.1.15 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-dropdown-menu" dependency-version: 2.1.16 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-hover-card" dependency-version: 1.1.15 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-label" dependency-version: 2.1.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-scroll-area" dependency-version: 1.2.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-select" dependency-version: 2.2.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-separator" dependency-version: 1.1.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-tabs" dependency-version: 1.1.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@react-three/fiber" dependency-version: 9.6.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: ai dependency-version: 6.0.190 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: jsonwebtoken dependency-version: 9.0.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: langfuse dependency-version: 3.38.20 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: livekit-server-sdk dependency-version: 2.15.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: nanoid dependency-version: 5.1.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: openai-edge dependency-version: 1.2.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: use-stick-to-bottom dependency-version: 1.1.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
LGTM - dependabot patch bumps for the docs site.
Extended reasoning...
Overview
This is a Dependabot grouped PR bumping 24 dependencies to patch versions in package.json and updating pnpm-lock.yaml accordingly. All bumps are patch-level (e.g., 1.0.35 → 1.0.43, 2.2.0 → 2.2.10, 1.9.0 → 1.9.1) — no major or minor jumps that would imply breaking changes per semver. The PR is labeled auto-merge and dependencies.
Security risks
The changes are limited to dependency version bumps. Notable security-positive bumps include @ai-sdk/mcp (which fixed prototype pollution via secureJsonParse in 1.0.38) and jsonwebtoken 9.0.2 → 9.0.3 (bumps jws transitively). No code-path changes are introduced by this PR itself.
Level of scrutiny
Low. This is the langfuse-docs documentation site (not the production Langfuse app), and all updates are patch versions from trusted ecosystems (Vercel AI SDK, Radix UI, OpenTelemetry, Headless UI, etc.). Patch versions are expected to be backwards-compatible, and any regressions would surface in the Vercel preview build that runs against this PR.
Other factors
The bug hunting system reported no bugs. The preview deployment was already running at the time of review. This is exactly the kind of routine grouped patch update that Dependabot is designed for, and approval here is appropriate.
Bumps the patches group with 24 updates in the / directory:
1.0.351.0.432.0.412.0.473.0.1553.0.1922.2.02.2.101.9.01.9.11.2.31.2.121.1.31.1.111.1.111.1.121.1.61.1.152.1.62.1.161.1.61.1.152.1.22.1.81.2.91.2.102.2.52.2.61.1.21.1.81.1.31.1.139.6.09.6.16.0.1536.0.1909.0.29.0.33.38.43.38.202.15.02.15.35.1.55.1.111.2.21.2.31.1.11.1.4Updates
@ai-sdk/mcpfrom 1.0.35 to 1.0.43Changelog
Sourced from @ai-sdk/mcp's changelog.
... (truncated)
Commits
0075589Version Packages (#15529)e2b923fBackport: fix(mcp): deduplicate auth refresh on http transport (#15528)5e287d0Backport: chore: add readme for@ai-sdk/mcp(#15450)8ccd431Version Packages (#15168)725f2edBackport: feat(mcp): expose server instructions to be accessible through clie...7281592Backport: fix(mcp): use negotiated protocol version in transport request head...e3ccdb5Version Packages (#15094)f591416Backport: feat(ai): add toolMetadata for tool specific metdata (#15053)74a7a20Version Packages (#15012)0084974Backport: feat(mcp): deprecate name and use clientName for MCPClient (#15003)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@ai-sdk/mcpsince your current version.Updates
@ai-sdk/openai-compatiblefrom 2.0.41 to 2.0.47Changelog
Sourced from @ai-sdk/openai-compatible's changelog.
Commits
e3ccdb5Version Packages (#15094)a1dddccVersion Packages (#14954)38966abbackport v6: fix(openai, openai-compatible): only send null content for assis...3def720Version Packages (#14908)6043d24Backport: feat(vertex): add grok models to vertex provider (#14902)8a46a3cVersion Packages (#14875)8e650abVersion Packages (#14824)a727da4backport of chore: ensure consistent import handling and avoid import duplica...77a4e05Version Packages (#14802)a7f3c72Re-enable v6 releases (#14799)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@ai-sdk/openai-compatiblesince your current version.Updates
@ai-sdk/reactfrom 3.0.155 to 3.0.192Changelog
Sourced from @ai-sdk/react's changelog.
... (truncated)
Commits
1a3ec6dVersion Packages (#15513)bde7d0fVersion Packages (#15494)93ad540Version Packages (#15489)a15eda9Version Packages (#15473)e33b836Version Packages (#15440)4a98945Version Packages (#15406)f8d3003Version Packages (#15356)2e7664bVersion Packages (#15315)c76ce9cVersion Packages (#15257)c0e4fefVersion Packages (#15251)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@ai-sdk/reactsince your current version.Updates
@headlessui/reactfrom 2.2.0 to 2.2.10Release notes
Sourced from @headlessui/react's releases.
... (truncated)
Changelog
Sourced from @headlessui/react's changelog.
... (truncated)
Commits
d13526d2.2.10 -@headlessui/reactb0dcd8fHandle props on Fragment error due toSymbol(react.lazy)(#3873)7baca70Don’t render\<Portal>s while hydrating (#3825)5ef7395AddRefProptoprops(#3823)589ea902.2.9 -@headlessui/reactbba75c7update changelogca536edupdate changelog49e9e8edo not serialize React components into form fields2a647a7Ensure refs are forwarded when freezing data (#3390)da2fa94Freeze values as soon as possible (#3802)Updates
@opentelemetry/apifrom 1.9.0 to 1.9.1Release notes
Sourced from @opentelemetry/api's releases.
Changelog
Sourced from @opentelemetry/api's changelog.
Commits
279458eRelease 1.9.1 / 0.35.1 (#3573)4978743fix(http): remove outgoing headers normalization (#3557)d1f9594chore(deps): update dependency rimraf to v4 (#3532)e0abcc0fix: remove JSON syntax error and regenerate tsconfig files (#3566)a90c558fix(sdk-node): register instrumentations early (#3502)5b070b8fix: include TraceState in trace exports (#3569)dcb09b7chore(deps): update dependency gh-pages to v5 (#3571)3bc93a9feat: exponential histogram - part 1 - mapping functions (#3504)3670071fix: avoid grpc types dependency (#3551)b5ef0e4chore: fix proto generation (#3567)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@opentelemetry/apisince your current version.Updates
@radix-ui/react-accordionfrom 1.2.3 to 1.2.12Commits
Updates
@radix-ui/react-avatarfrom 1.1.3 to 1.1.11Commits
Updates
@radix-ui/react-collapsiblefrom 1.1.11 to 1.1.12Commits
Updates
@radix-ui/react-dialogfrom 1.1.6 to 1.1.15Commits
Updates
@radix-ui/react-dropdown-menufrom 2.1.6 to 2.1.16Commits
Updates
@radix-ui/react-hover-cardfrom 1.1.6 to 1.1.15Commits
Updates
@radix-ui/react-labelfrom 2.1.2 to 2.1.8Commits
Updates
@radix-ui/react-scroll-areafrom 1.2.9 to 1.2.10Commits
Updates
@radix-ui/react-selectfrom 2.2.5 to 2.2.6Commits
Updates
@radix-ui/react-separatorfrom 1.1.2 to 1.1.8Commits
Updates
@radix-ui/react-tabsfrom 1.1.3 to 1.1.13Commits
Updates
@react-three/fiberfrom 9.6.0 to 9.6.1Release notes
Sourced from @react-three/fiber's releases.
Commits
2a52874RELEASING: Releasing 1 package(s)b645741docs(changeset): fix: Seamlessly transfer interactivity state when swapping i...119668ffix: Seamlessly transfer interactivity state when swapping instances (#3744)943a37eMerge pull request #3738 from pmndrs:chore/simplify-shadermaterial-demo1be9504chore: Add uniform piercing test4df10c0chore: Simplify ShaderMaterial demo47d30bachore: Move ShaderMaterial uniform notes to objects out of pitfallsUpdates
aifrom 6.0.153 to 6.0.190Changelog
Sourced from ai's changelog.
... (truncated)
Commits
1a3ec6dVersion Packages (#15513)bde7d0fVersion Packages (#15494)356c3cfBackport: fix(ai): make input optional on input-streaming UIMessagePart varia...93ad540Version Packages (#15489)c98715aBackport: [tool-loop-agent] adding support for messages with system role with...a15eda9Version Packages (#15473)917e487Backport CI speed improvements to release-v6.0 (#15455)e33b836Version Packages (#15440)4a98945Version Packages (#15406)f8d3003Version Packages (#15356)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for ai since your current version.
Updates
jsonwebtokenfrom 9.0.2 to 9.0.3Changelog
Sourced from jsonwebtoken's changelog.
Commits
ed59e76chore: bump jws to 4.0.1 (#1007)Updates
langfusefrom 3.38.4 to 3.38.20Commits
88f742av3.38.20be826fdv3.38.19401ff11v3.38.18e0ca44bv3.38.1779350d2v3.38.1634bd9c4v3.38.15249a8eav3.38.144ebe6fbv3.38.13d50023bv3.38.123339402v3.38.11Updates
livekit-server-sdkfrom 2.15.0 to 2.15.3Release notes
Sourced from livekit-server-sdk's releases.
Changelog
Sourced from livekit-server-sdk's changelog.
Commits
4885d82Version Packages (#658)6609ca9Add canManageAgentSession to VideoGrant (#661)05e6f18feat: add support for SimulateScenario (#659)f93752dfeat: update agent dispatch and connector client (#657)0ed1835Version Packages (#646)75824e5add ringingTimeput field to SIP inbound create api (#645)a5cac5aVersion Packages (#610)b3fcd70Exposing optional TransferSipParticipant.ringingTimeout (#627)bcce97bAdd bun runtime tests (#607)e094320add e2e tests (#591)Updates
nanoidfrom 5.1.5 to 5.1.11Release notes
Sourced from nanoid's releases.
Changelog
Sourced from nanoid's changelog.
Commits
5423cf5Release 5.1.11 version2183894Backport 3.3.12 changelog7087969Limit ID even more013517bTemporary add pnpm-workspace.yaml to npm ignore5db09eeRelease 5.1.10 versionbe7901aFix random pool break974f73bStructure tests with describe() instead of prefixfe3e7ecUpdate dependencies043a7c1Move to pnpm 11e52d946Release 5.1.9 versionUpdates
openai-edgefrom 1.2.2 to 1.2.3Commits
Updates
use-stick-to-bottomfrom 1.1.1 to 1.1.4Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions