chore(deps): bump the prod-deps group across 1 directory with 10 updates#34
chore(deps): bump the prod-deps group across 1 directory with 10 updates#34dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the prod-deps group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@ai-sdk/react](https://github.com/vercel/ai/tree/HEAD/packages/react) | `3.0.170` | `3.0.185` | | [@openrouter/ai-sdk-provider](https://github.com/OpenRouterTeam/ai-sdk-provider) | `2.8.0` | `2.9.0` | | [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `6.0.168` | `6.0.183` | | [fumadocs-core](https://github.com/fuma-nama/fumadocs) | `16.8.0` | `16.8.11` | | [fumadocs-ui](https://github.com/fuma-nama/fumadocs) | `16.8.0` | `16.8.11` | | [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.8.0` | `1.16.0` | | [react](https://github.com/facebook/react/tree/HEAD/packages/react) | `19.2.5` | `19.2.6` | | [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) | `19.2.5` | `19.2.6` | | [tailwind-merge](https://github.com/dcastil/tailwind-merge) | `3.5.0` | `3.6.0` | | [zod](https://github.com/colinhacks/zod) | `4.3.6` | `4.4.3` | Updates `@ai-sdk/react` from 3.0.170 to 3.0.185 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/@ai-sdk/react@3.0.185/packages/react/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/react@3.0.185/packages/react) Updates `@openrouter/ai-sdk-provider` from 2.8.0 to 2.9.0 - [Release notes](https://github.com/OpenRouterTeam/ai-sdk-provider/releases) - [Changelog](https://github.com/OpenRouterTeam/ai-sdk-provider/blob/main/CHANGELOG.md) - [Commits](OpenRouterTeam/ai-sdk-provider@2.8.0...2.9.0) Updates `ai` from 6.0.168 to 6.0.183 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/ai@6.0.183/packages/ai/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/ai@6.0.183/packages/ai) Updates `fumadocs-core` from 16.8.0 to 16.8.11 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/commits/fumadocs-core@16.8.11) Updates `fumadocs-ui` from 16.8.0 to 16.8.11 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/commits/fumadocs-ui@16.8.11) Updates `lucide-react` from 1.8.0 to 1.16.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.16.0/packages/lucide-react) Updates `react` from 19.2.5 to 19.2.6 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.6/packages/react) Updates `react-dom` from 19.2.5 to 19.2.6 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.6/packages/react-dom) Updates `tailwind-merge` from 3.5.0 to 3.6.0 - [Release notes](https://github.com/dcastil/tailwind-merge/releases) - [Commits](dcastil/tailwind-merge@v3.5.0...v3.6.0) Updates `zod` from 4.3.6 to 4.4.3 - [Release notes](https://github.com/colinhacks/zod/releases) - [Commits](colinhacks/zod@v4.3.6...v4.4.3) --- updated-dependencies: - dependency-name: "@ai-sdk/react" dependency-version: 3.0.185 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: "@openrouter/ai-sdk-provider" dependency-version: 2.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-deps - dependency-name: ai dependency-version: 6.0.183 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: fumadocs-core dependency-version: 16.8.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: fumadocs-ui dependency-version: 16.8.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: lucide-react dependency-version: 1.16.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-deps - dependency-name: react dependency-version: 19.2.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: react-dom dependency-version: 19.2.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: tailwind-merge dependency-version: 3.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-deps - dependency-name: zod dependency-version: 4.4.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-deps ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
Mogplex PR Review
Status: Attention needed
This is a Dependabot-generated dependency bump PR updating 10 production dependencies. All packages are from well-known, legitimate maintainers with no CVE concerns. The PR is largely safe to merge, but one notable lockfile-only change (a new postcss override) is not reflected in package.json and deserves attention before merging. All other changes are routine patch/minor bumps.
2 findings were added inline.
| autoInstallPeers: true | ||
| excludeLinksFromLockfile: false | ||
|
|
||
| overrides: |
There was a problem hiding this comment.
Warning: postcss override added to lockfile but not to package.json
The lockfile adds a new global override:
overrides:
postcss@<8.5.10: '>=8.5.10'This override pins any transitive dependency on old postcss versions to >=8.5.10, which is consistent with CVE-style vulnerability patching. However, package.json has no corresponding pnpm.overrides block. This means the override is present in the committed lockfile but will not be reproducible if someone regenerates the lockfile from scratch using pnpm install. Any engineer who runs pnpm install --frozen-lockfile=false (or deletes and regenerates the lockfile) will lose this security fix silently.
Suggestion: Add the override explicitly to package.json:
"pnpm": {
"overrides": {
"postcss@<8.5.10": ">=8.5.10"
}
}This ensures the override is durable and auditable regardless of how the lockfile is regenerated.
| "zod": "^4.3.6" | ||
| "zod": "^4.4.3" | ||
| }, | ||
| "devDependencies": { |
There was a problem hiding this comment.
Warning: zod 4.4.x contains potentially breaking strictness changes — validate before merging
The zod bump from 4.3.6 to 4.4.3 is described in the zod changelog as a "minor release with a wide set of correctness and soundness fixes" that includes "potentially breaking bug fixes" — specifically, Zod 4.4.0 makes some validations stricter. The ai SDK changelog for 6.0.181 even notes a fix that was required due to Zod 4.4+ treating missing z.unknown() keys as a validation failure (previously they were implicitly optional).
Although the SDK authors patched for this in ai@6.0.181 (included in this PR), any custom Zod schemas in the application itself may behave differently after this bump. Confirm that all application-level Zod schemas (especially those handling AI message parsing or optional/absent keys) have been tested or reviewed for compatibility with Zod 4.4.x strictness changes.
Bumps the prod-deps group with 10 updates in the / directory:
3.0.1703.0.1852.8.02.9.06.0.1686.0.18316.8.016.8.1116.8.016.8.111.8.01.16.019.2.519.2.619.2.519.2.63.5.03.6.04.3.64.4.3Updates
@ai-sdk/reactfrom 3.0.170 to 3.0.185Release notes
Sourced from @ai-sdk/react's releases.
Changelog
Sourced from @ai-sdk/react's changelog.
... (truncated)
Commits
2e7664bVersion Packages (#15315)c76ce9cVersion Packages (#15257)c0e4fefVersion Packages (#15251)43e5359Version Packages (#15221)e2f1bcaVersion Packages (#15216)d37fb1fVersion Packages (#15202)e70aab9Version Packages (#15138)e3ccdb5Version Packages (#15094)3015153Version Packages (#14960)0129eb6Version Packages (#14912)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@ai-sdk/reactsince your current version.Updates
@openrouter/ai-sdk-providerfrom 2.8.0 to 2.9.0Release notes
Sourced from @openrouter/ai-sdk-provider's releases.
Changelog
Sourced from @openrouter/ai-sdk-provider's changelog.
... (truncated)
Commits
5cef3c5Version Packages (#490)bb2d4cbfix: stop emitting duplicate tool-call events on trailing-whitespace deltas (...82e8014fix: allow opting out of response_format strict mode (#483) (#486)bf664b1fix: allow query strings and fragments in image URL regex (#484) (#485)310ba3dVersion Packages (#488)4588197fix: preserve empty reasoning_details arrays in multi-turn conversations (#487)Updates
aifrom 6.0.168 to 6.0.183Release notes
Sourced from ai's releases.
Changelog
Sourced from ai's changelog.
... (truncated)
Commits
2e7664bVersion Packages (#15315)7baadccchore: diverge test assertions based on node version (#15326)5427555chore: fix flaky tests diverging on different node versions (#15296)c76ce9cVersion Packages (#15257)c0e4fefVersion Packages (#15251)e76a29aBackport: fix(ai): download tool-result file URLs (#15246)538974aBackport: fix(ai): Fix validateUIMessages with Zod 4.4 (#15247)43e5359Version Packages (#15221)57ec10fBackport: fix hero url (#15225)253bd5aBackport: fix(gateway): enable retry support for gateway errors (#15220)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for ai since your current version.
Updates
fumadocs-corefrom 16.8.0 to 16.8.11Release notes
Sourced from fumadocs-core's releases.
Commits
Updates
fumadocs-uifrom 16.8.0 to 16.8.11Release notes
Sourced from fumadocs-ui's releases.
... (truncated)
Commits
Updates
lucide-reactfrom 1.8.0 to 1.16.0Release notes
Sourced from lucide-react's releases.
... (truncated)
Commits
07c885efix(docs): fix zephyr-cloud URL in readmes50d8af5docs(readme): Update readme files (#4320)653e44bfeat(packages): use .mjs for ESM bundles (#4285)Updates
reactfrom 19.2.5 to 19.2.6Release notes
Sourced from react's releases.
Commits
eaf3e95Version 19.2.6Updates
react-domfrom 19.2.5 to 19.2.6Release notes
Sourced from react-dom's releases.
Commits
eaf3e95Version 19.2.6Updates
tailwind-mergefrom 3.5.0 to 3.6.0Release notes
Sourced from tailwind-merge's releases.
Commits
d54f7e5v3.6.0638871aUpdate README to add info about Tailwind CSS v4.3 support39fc7b5Revert "v3.6.0"bd8390fv3.6.0802877cadd v3.6.0 changeloga35fedaMerge pull request #665 from dcastil/renovate/rollup-plugin-babel-7.x940389cMerge pull request #667 from dcastil/renovate/release-drafter-release-drafter...005af6dpin to specific version5816cedimplement breaking changes17041e1Merge pull request #676 from dcastil/dependabot/npm_and_yarn/babel/plugin-tra...Updates
zodfrom 4.3.6 to 4.4.3Release notes
Sourced from zod's releases.
... (truncated)
Commits
1fb56a5docs: document release procedure in AGENTS.mdf3c9ec04.4.3c2be4f8fix(v4): generalize optin/fallback to transform; restore preprocess on absent...1cab693fix(v4): restore catch handling for absent object keys (#5937) (#5939)b8dffe9docs: remove Numeric and Speakeasy (2+ missed monthly cycles)9195250docs: remove Mintlify from bronze sponsors (churned)2c70332docs: normalize bronze sponsor logos to github avatar pattern7391be8docs: prune lapsed silver/bronze sponsors and add active ones2aeec83docs: prune lapsed gold sponsors and rebalance logo sizing4c2fa95docs: use Zernio primary wordmark for gold sponsor logoMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for zod since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsNeed help on this PR? Tag
@codesmithwith what you need.