Update all dependencies - #136
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/all
branch
9 times, most recently
from
April 6, 2026 17:28
b372a82 to
6ac13be
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
11 times, most recently
from
April 13, 2026 20:36
3312ab9 to
ffa128f
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
9 times, most recently
from
April 20, 2026 09:17
d324026 to
3848913
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
from
April 25, 2026 02:03
3848913 to
a4c55b6
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
5 times, most recently
from
May 10, 2026 13:48
a68d722 to
c242ad3
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
7 times, most recently
from
May 18, 2026 18:15
3c08811 to
c1f2f20
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
3 times, most recently
from
May 23, 2026 02:03
e708df1 to
a5e0c60
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
5 times, most recently
from
June 3, 2026 22:00
413c393 to
24ffa19
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
5 times, most recently
from
June 11, 2026 00:44
6ec398c to
9c07beb
Compare
renovate
Bot
force-pushed
the
renovate/all
branch
4 times, most recently
from
June 15, 2026 23:50
ac3a9ba to
a09ae19
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.11.1→2.11.30.13.8→0.13.11^5.0.0→^7.0.010.4.22→10.6.11.3.4→1.4.216.0.7→16.3.61.5.1→1.7.2^5.2.0→^7.0.016.1.0→16.1.13.4.0→3.7.05.9.3→7.0.24.1.13→4.6.5Release Notes
nextauthjs/next-auth (@auth/prisma-adapter)
v2.11.3Compare Source
Other
8a933f9)v2.11.2Compare Source
Other
67f2b16)t3-oss/t3-env (@t3-oss/env-nextjs)
v0.13.11Compare Source
Patch Changes
6937086]:v0.13.10Compare Source
Patch Changes
a778bf3]:v0.13.9Compare Source
Patch Changes
5987d5a]:vercel/ai (ai)
v7.0.113Compare Source
Patch Changes
dcdb011: fix(ai): route completed streamed tool input callbacks to repaired tools8f72832: fix(ai): preserve video models from legacy fallback providersfe07867: Fix GoogleembedManycalls with more than 100 values by keeping per-value multimodal content aligned across automatic batches, including text-only entries. Validate content length before sending requests and validate each batch's provider options after middleware transforms them.b74c0cb: fix(ai): resume tool approvals from earlier messagesa4b0940: fix(ai): execute manually approved tool inputs produced by schema transformsPreserve approved inputs during revalidation and reject histories whose reconstructed schema output differs, including signed approvals with missing original input. Validate transformed UI tool inputs against the reconstructed output before returning them as static tool parts.
2693319: Add Gemini 3.8 TTS support with structured speech metadata and per-turn speaker and style controls for prebuilt voices. Preserve native WAV responses without adding a second header, support explicit raw PCM, mu-law, and A-law output, and identify headerless audio formats correctly. Add the Gemini 3.8 speech model IDs to Google and Gateway types.Share transcript and custom-voice inspection through the Google provider internal export, and reject empty speech transcripts before sending a request. Default newer and custom model IDs to structured speech while preserving the legacy format for Gemini 2.5 and 3.1.
c93ee90: fix(ai): preserve message history for direct transport stream callbacks771e74b: chore: enable dead code lint rulesUpdated dependencies [
fe07867]Updated dependencies [
a4b0940]Updated dependencies [
2693319]Updated dependencies [
b73f2f9]Updated dependencies [
771e74b]v7.0.112Compare Source
Patch Changes
9a98fd9: fix(ai): prune reasoning file parts when removing reasoninga0553d6: feat(ai): report consumer cancellation in UI message stream end callbacksffb0e76: fix(provider): preserve opaque file URI strings for provider serializationfde0d66: fix(ai): preserve parsed metadata and data values when validating UI messagesed5a1d7]ffb0e76]618dc11]v7.0.111Compare Source
Patch Changes
31d24ce: feat: add telemetry support toexperimental_evaluatea65bfd9: fix(ai): securely download URL-backed language model file outputs so generated files expose actual base64 and byte content and UI streams contain valid data URLs. Propagate cancellation to batch file downloads.v7.0.110Compare Source
Patch Changes
49295bb]v7.0.109Compare Source
Patch Changes
0343bb1: fix(ai): keep replacement completion requests loading and cancellable when an earlier request settles2b105fa: fix(ai): preserve overlapping text blocks in reasoning extraction streams125f493: fix(harness): forward validatedtoolsContextto host-executed tools in alignment withToolLoopAgentv7.0.108Compare Source
Patch Changes
3f6852a: fix(ai): prevent direct execution of tools governed by tool callers6317504: fix(ai): stop pending tool-call repairs when generation is cancelled3cb2dcd: fix(ai): preserve file data when adapting v3 language modelsccf98e7: fix(ai): preventstreamTextfrom executing tool calls that violate tool choice20dd00a]7cf7cee]c42576a]d85dcf5]fd9b3f3]v7.0.107Compare Source
Patch Changes
79681c4: fix(ai): preserve provider file and skill upload APIs in wrapProvider98c7275: fix(ai): preserve query parameters in chat reconnect URLsa105059: fix(workflow): support deferred tool discovery in WorkflowAgent31532f3: fix(ai): prevent preliminary tool outputs from completing chatse61cbd8: fix(ai): preserve raw speech audio format metadata8ade040: fix(ai): pass tool-specific context to input callbacks970a01e: fix(ai): enforce polling timeouts for in-flight video status requests85539c5: fix(ai): preserve multiple Set-Cookie headers in Node stream responses611d301: fix(ai): prevent duplicate content types in chat transport requestsc415657: fix(ai): decode base64 text data URLs using their declared charset2973485]a4db5ea]2937ea2]v7.0.106Compare Source
Patch Changes
4775577: fix(ai): preserve provider metadata when simulating text streams6696728: fix(ai): report the prepareStep model in streamed step results09516a1: fix(ai): prevent unhandled rejections when UI message stream reading stops early1aef01e: fix(ai): preserve prototype-named properties in serialized tool outputs9c1ea74: fix(ai): close telemetry spans when provider response streams fail107343a: fix(ai): use the prepareStep-selected model for streamed response metadata fallbacks03c3e33: fix(ai): preserve tool calls required by retained pending approvals5d42ebd: fix(ai): skip input available callbacks for invalid streamed tool calls4a67783: fix(ai): cancel prompt attachment downloads when model calls are aborted or time out1058ed5: fix(ai): strip streamed JSON fences before arbitrary trailing whitespace84f5d1b: fix(ai): stream null and empty string JSON partial outputs2d53a5d: fix(ai): prevent onEnd after aborting a multi-step text stream2a5ed55: fix(ai): stream structured output from the final tool-loop step4fdf51e]0455398]v7.0.105Compare Source
Patch Changes
6982e9d: Resolve evaluation model IDs through AI Gateway when no default provider is configured, including string aliases in custom providers.6982e9d]6982e9d]v7.0.104Compare Source
Patch Changes
a7dd893: Add experimental evaluation model aliases and registry resolution.customProvideracceptsevaluationModels, registries exposeevaluationModel, andexperimental_evaluateaccepts string IDs when an evaluation-capable default provider is explicitly configured. Evaluation never implicitly falls back to Gateway. Model-resolution errors now identifyevaluationModelwhile stable provider contracts remain unchanged.227f3b0: fix(ai): report abnormal realtime WebSocket close diagnostics throughonError3456e2c: feat(ai): support tool search with direct tool callingc4e76de: feat(ai): add native tool search tool215b25e]d4d96bf]a7dd893]3456e2c]c4e76de]v7.0.103Compare Source
Patch Changes
91c2128: feat(ai): add mid conversation tool discovery/updates for code-mode25a0447: feat(ai): deprecate rawInput in output-error UI message parts2cd80b3: Keep default Node.js downloads protected by DNS validation and connection pinning when frameworks or instrumentation wrap global fetch before or after the SDK loads.123d71f: Addexperimental_evaluateand the isolated experimental v4 evaluation model specification for Choice, Score, and Boolean questions against shared state. Includes typed answers, optional Choice/Score distributions, required Boolean probabilities, validation, retries, cancellation, andExperimental_EvaluationUnsupportedQuestionTypeErrorfor unsupported questions.91c2128]0c9ab5a]2cd80b3]d06bb2a]123d71f]2fa5e0e]2cce7da]v7.0.102Compare Source
Patch Changes
5c0054d: Add optional browser-direct WebRTC for experimental client-delegated Live conversations alongside the existing WebSocket path. Exchange SDP through an application endpoint withapi.session, configure server-owned data-channel permissions, and preserve committed React session ownership. Capture follows the selected sender track, borrowed tracks remain caller-owned, and disconnect recovery and finalization stay bounded. Applications continue to handle client delegation and submit context; Live session updates and Responses delegation remain unsupported.Serialize microphone sender changes and close the peer if detachment fails, without stopping borrowed tracks. Validate nonempty SDP setup answers with a bounded response body, and document the same-origin broker authentication contract.
39535af: Add experimental OpenAI Live provider support through the unifiedopenai.experimental_realtimefactory for server WebSocket sessions with client delegation. Applications own their agents and tools, receive continuous audio/transcript events and delegation metadata, and return context through validated channels. Support immutable startup options, microphone mute controls, graceful session close, and cumulative voice usage. Responses delegation and Live session updates reject before sending.Route known Live model IDs to Live, allow an OpenAI-specific
apioverride for early-access models, and preserve legacy Realtime defaults for unknown IDs. Token minting follows the same selection rules and rejects Live before requesting unsupported credentials. Extend the realtime v4 specification with optional server WebSocket configuration, per-connection raw-event parsers, and model-wide startup/finalization capabilities. This provider layer supplies connection settings and protocol mapping for server adapters; browser lifecycle and UI integration belong to the core runtime and framework hooks.Preserve Realtime client event IDs for session updates and audio appends, and correlate server errors with the originating client event.
8b92ba9: fix(ai): settle automatically denied tool calls in UI streams4b306c2: Report abnormal realtime WebSocket close codes and reasons through the session error path.4b306c2: Add the client-delegation-first realtime WebSocket runtime with session lifecycle, exact final duration, bounded event queues and command acknowledgement tracking, transcripts, context append, and reversible capture. Continuous sessions support PCM16 audio-chunk playback over an application relay with a recoverable live-edge buffer policy. Legacy turn-based WebSockets retain queued playback and frontend tool handling.Remove the deferred managed Responses coordinator, autoContinueTools option, backend usage state, and Live tool-result aliases. Continuous text and delegation handling belong to the application; sendTextMessage and addToolOutput reject continuous sessions. Server-confirmed provider delegation and turn-based audio-delta on the continuous profile fail explicitly. maxPlaybackBufferSeconds is supported only for continuous PCM sessions.
Fence callbacks, startup publications, tool results, and teardown by connection attempt. Validate token setup before opening a client-secret socket, require explicit relay transport mode, and include WebSocket URL, protocol values, and runtime timeouts/buffer settings in React session configuration keys.
Retain immediate local capture for explicit legacy preconnect streams, including owned-track cleanup and capture continuity through asynchronous setup. Signal transport closing before draining accepted terminal events, share reentrant close settlement, and cancel stale readiness and deadlines. Enforce 128 KiB frame and combined buffered-send budgets only for Live continuous sessions, using actual encoded wire bytes; oversized manual operations remain recoverable while startup and automatic audio failures close the session. Legacy startup, text, tool output, and audio retain their pre-Live behavior without these byte caps. Live pending-audio overflow drains accepted terminal usage within the existing one-second drain window. Validate final provider-transformed WebSocket URL syntax without removing native authentication query parameters.
Updated dependencies [
5c0054d]Updated dependencies [
39535af]v7.0.101Compare Source
Patch Changes
6aa7c54: fix(ai): serialize tool output JSON valuesv7.0.100Compare Source
Patch Changes
6431635: feat(ai): expose typed AI SDK errors for UI transport and completion failures23a0fff]v7.0.99Compare Source
Patch Changes
615ac89: feat(ai): use InvalidArgumentError for utility input validation7f76d83]v7.0.98Compare Source
Patch Changes
5ec21a6: fix: reject unsupported batch request typesdb59d78: feat(ai): add runtime context attribution to embed, embedMany and rerank7469a3b: feat: support image generation requests in batchesf87bf07: fix(ai): reject invalid reranking provider indicesbc5cb7a: fix(ai): accept inferred tools invalidateUIMessagesa5f449a: feat(ai): add a stable UI message type and type guard for tool output errors5ec21a6]7469a3b]dbd83a3]813bb36]c43e4b7]03f4e59]v7.0.97Compare Source
Patch Changes
ef3bac4: Observe video webhook receiver rejections before generation starts to prevent unhandled rejections during or after a failed start. Preserve start error precedence and assimilate custom receivers only once.9942196: feat: add batch cancel and list APIs9942196]v7.0.96Compare Source
Patch Changes
912fb01: feat: add batch cancel and list APIsc595e6e: fix(ai): callatobwithout a receiver for Cloudflare Workers compatibility912fb01]aa4cc14]f102e41]v7.0.95Compare Source
Patch Changes
27f6d7a: fix(ai): reject embedding model responses that contain no embeddingsv7.0.94Compare Source
Patch Changes
a4ba394: feat: support per-request models in batch36b3364: fix(ai): enforce tool choices in streamText45099da: Retry unclassified empty image results, preserve retry-attempt accounting, add provider-independent result retryability classification, and mark Google and Google Vertex prompt blocks as terminal.a4ba394]e9bf5e3]45099da]56c004c]9e1d1b2]a495511]v7.0.93Compare Source
Patch Changes
df6c009: fix(ai): use new message ID when replacing a message insendMessage6ee74a3: fix(ai): preserve tool part titles when validating UI messagesf13d371: fix(ai): preserve provider metadata when converting failed tool callsd4485fe: feat(ai): support minItems and maxItems in array outputs4f201cc: chore(ai): formally include already supportedonLanguageModelCallStartandonLanguageModelCallEndinToolLoopAgentSettingstype8cdb2a7: fix(ai): decode text data URLs in Node.js0f2281e: fix(ai): reject embedding responses whose count does not match the input valuesfc8e8ac: fix(ai): preserve image call diagnostics when no image is generatedee8391e: fix(ai): support abort signals when the global AbortSignal is not a constructor3cfc1fc]v7.0.92Compare Source
Patch Changes
a51cc94: fix(ai): preserve provider metadata from empty smooth stream deltasd1904d3: fix(ai): surface fallback errors for empty HTTP response bodies84e5a79: fix(ai): skipsmoothStreamdelays while the document is hiddena8e8ad0: fix(ai): expose call ID and abort reason in streamText onAbort callbacksa7e324b]v7.0.91Compare Source
Patch Changes
802af1e: Add configurable recovery for provider errors received afterstreamTextresponse streaming begins. Explicitly configuringstreamRetriesenables isolated retry attempts, including one bounded callback-directed recovery throughStreamTextOnErrorRetryCallbackwithstreamRetries: 0; recovered results and metadata reflect only the successful attempt, while the existingStreamTextOnErrorCallbackcontract and logging-only observer behavior remain compatible.5484f27]36eb7ee]622fa7f]v7.0.90Compare Source
Patch Changes
4d25a08]6bcc0f8]v7.0.89Compare Source
Patch Changes
5190b67: feat(provider): extend the FilesV4 interface with optionalgetFileMetadata,downloadFile(streaming), anddeleteFileoperations, plusabortSignal/headerscall options and a{ type: 'stream' }upload data variant; upload results now exposebyteSize,createdAt, andexpiresAt(also surfaced by the coreuploadFile()helper, which now forwardsabortSignal/headers); addpostMultipartStreamToApi(streaming multipart uploads with deterministic part ordering and failure-path stream teardown),deleteFromApi, andcreateBinaryStreamResponseHandlerto provider-utils5190b67]v7.0.88Compare Source
Patch Changes
8b6b756: fix(ai): prevent generateText from accepting responses that violate required tool choicese07b577: feat: add tool calling support to batchv7.0.87Compare Source
Patch Changes
850d863: fix(ai): preserve approval descriptors in UI message streamsv7.0.86Compare Source
Patch Changes
11109ae: feat(ai): support signed tool approvals in WorkflowAgent1329d5a]v7.0.85Compare Source
Patch Changes
55a9981: Ensure canonical hashes preserve undefined array element positions.dd32de2: fix(ai): sum Gateway image-generation costs across split requestsaa45741: fix(provider/anthropic): preserve native message batch request counts in provider metadata and support the full language-model option surface in batch requestscc29073: feat(ai): expose individual image generation callsd2507af]aa45741]v7.0.84Compare Source
Patch Changes
6669d69: Expose parsed structured output instreamTextend callbacks.a6463ca: fix(ai): allow tool approval secrets in ToolLoopAgent settings and prepareCalle604532: fix(ai): handle stateful and empty-match regular expressions in smoothStream805bbfc]90192f1]v7.0.83Compare Source
Patch Changes
8dd86a9: Validate persisted typed tool calls against current input and output schemas.Schema-incompatible empty or error inputs and terminal history from unavailable
tools remain loadable as dynamic tool parts instead of exposing unvalidated
values under current static tool types.
fda13b3: Allow chats to continue automatically after tool approval denials reach theoutput-deniedstate.957146c: add operation-level outcomes to UI message stream end callbacksce6849a: fix(ai): handle stitchable stream cancellation before an inner stream is registeredv7.0.82Compare Source
Patch Changes
3e125ba: Allow manual tool approval statuses to include a reason and preserve it acrosscore, model, and UI approval requests. OPA
requires-approvaldecisions nowsurface their reason to human approvers. UI request chunks serialize the
optional
reason, while UI messages retain it asapproval.requestReasonseparately from an approver's response
reason.0e7994c]3e125ba]v7.0.79Compare Source
Patch Changes
b251584: Preserve active text and reasoning parts when another merged UI message stream finishes a step, and align workflow stream normalization with the explicit part end chunks.591d25b: feat: add batch completion webhooks.experimental_startTextBatchaccepts awebhookUrl, and the gateway provider registers it through the batchcallbackUrlcontract and exports typed async-job metadata. Direct Anthropic and OpenAI batch providers return an unsupported warning when the option is provided.9de0baf: Parse structured generateText output when providers omit finishReason but return text.591d25b]v7.0.78Compare Source
Patch Changes
96970bb: Continue approvedgenerateText,streamText, andWorkflowAgentturns with a model-visible tool error when revalidated tool input is invalid.e12e068]v7.0.77Patch Changes
b74971f]a371615]v7.0.76Patch Changes
c6d57f3: fix(ai): prevent duplicate text and reasoning part ids677a707: fix(ai): allow nullish metadata schemas for UI messages with branded IDsv7.0.74Patch Changes
5941bd6]9a4337d]v7.0.73Patch Changes
f607a12]v7.0.71Patch Changes
9a37469: Prevent exceptions in streamingonChunkandonErrorcallbacks from terminating the stream or masking provider errors.936719b]v7.0.70Patch Changes
9566914: Stop multi-step text generation for client tool approval even when a provider-executed tool has a deferred result.b181020: fix: rejectstreamObjectresult promises and report failed completion when the provider stream errors7054073: Filter preliminary tool outputs whenignoreIncompleteToolCallsis enabled.a828527: Prevent automatic tool execution when a model call ends with an unsafe finish reason.d3cc3fe: Clear partial UI message parts when a WorkflowAgent model-call step is retried.e6087c9]v7.0.69Patch Changes
1f7a464]v7.0.68Patch Changes
257632b]v7.0.67Patch Changes
a0b1ffc]v7.0.66Compare Source
Patch Changes
0782259: Keep chat status submitted until response content begins streaming.2fd1214: Fix declaration emit for exported values that infer anOutputtype.v7.0.65Compare Source
Patch Changes
dc8caae: Avoid repeatedly cloning accumulated text inreadUIMessageStreamwhilepreserving independent snapshots for mutable nested values.
72ec74f: Preserve root-level JSON Schema definitions when wrapping array output schemas.c5b0515: Propagate errors thrown by the ChatonFinishcallback to the initiating request.16650e9]v7.0.64Compare Source
Patch Changes
ea75787]b20de9e]v7.0.63Compare Source
Patch Changes
d0a5807: Preserve reasoning block IDs from UI message streams on reasoning UI parts.dcf33e8: Allow providers without reranking model support to be assigned toProvider.a4d386d]v7.0.62Patch Changes
e0bcf52: feat(ui): add typed custom bodies to Completion APIsv7.0.61Patch Changes
326054b: PreventresumeStreamfrom copying the previous assistant message into the resumed response.975bb28: Cancel messages that are still being prepared when a chat is stopped.7fbfc6d]v7.0.60Patch Changes
79c52ef: AlignToolLoopAgentprepareCalltypes with the settings available and honored at runtime.3cc1bb6]v7.0.59Compare Source
Patch Changes
401a4ba](https://redirect.github.cConfiguration
📅 Schedule: (in timezone Asia/Manila)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.