chore(deps): bump the patches group across 1 directory with 27 updates#2930
chore(deps): bump the patches group across 1 directory with 27 updates#2930dependabot[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
LGTM, dependabot patch-level dependency bumps.
Extended reasoning...
Overview
This PR is a Dependabot grouped patch-level update bumping 27 dependencies in package.json and the corresponding pnpm-lock.yaml. All bumps stay within the same minor version (e.g., @ai-sdk/mcp 1.0.35→1.0.39, @headlessui/react 2.2.0→2.2.10, tailwindcss 4.2.0→4.2.4, jsonwebtoken 9.0.2→9.0.3, etc.). No application code is modified.
Security risks
Patch releases are unlikely to introduce breaking changes, and several of the included patches are themselves security fixes (e.g., @ai-sdk/mcp prototype-pollution fix via secureJsonParse, jsonwebtoken jws bump). This is the langfuse-docs repository, not the core Langfuse production code, so the blast radius is limited to the marketing/docs site.
Level of scrutiny
Low. Dependabot patch-grouped bumps within a docs repo are mechanical and well-suited for shadow approval. The Vercel preview build will catch any incidental compatibility issues before deploy.
Other factors
No bugs were reported by the bug-hunting system, no outstanding reviewer comments exist, and the only timeline entry is the Vercel preview bot.
Bumps the patches group with 27 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@ai-sdk/mcp](https://github.com/vercel/ai/tree/HEAD/packages/mcp) | `1.0.35` | `1.0.41` | | [@ai-sdk/openai-compatible](https://github.com/vercel/ai/tree/HEAD/packages/openai-compatible) | `2.0.41` | `2.0.47` | | [@ai-sdk/react](https://github.com/vercel/ai/tree/HEAD/packages/react) | `3.0.155` | `3.0.178` | | [@headlessui/react](https://github.com/tailwindlabs/headlessui/tree/HEAD/packages/@headlessui-react) | `2.2.0` | `2.2.10` | | [@opentelemetry/api](https://github.com/open-telemetry/opentelemetry-js) | `1.9.0` | `1.9.1` | | [@radix-ui/react-accordion](https://github.com/radix-ui/primitives) | `1.2.3` | `1.2.12` | | [@radix-ui/react-avatar](https://github.com/radix-ui/primitives) | `1.1.3` | `1.1.11` | | [@radix-ui/react-collapsible](https://github.com/radix-ui/primitives) | `1.1.11` | `1.1.12` | | [@radix-ui/react-dialog](https://github.com/radix-ui/primitives) | `1.1.6` | `1.1.15` | | [@radix-ui/react-dropdown-menu](https://github.com/radix-ui/primitives) | `2.1.6` | `2.1.16` | | [@radix-ui/react-hover-card](https://github.com/radix-ui/primitives) | `1.1.6` | `1.1.15` | | [@radix-ui/react-label](https://github.com/radix-ui/primitives) | `2.1.2` | `2.1.8` | | [@radix-ui/react-scroll-area](https://github.com/radix-ui/primitives) | `1.2.9` | `1.2.10` | | [@radix-ui/react-select](https://github.com/radix-ui/primitives) | `2.2.5` | `2.2.6` | | [@radix-ui/react-separator](https://github.com/radix-ui/primitives) | `1.1.2` | `1.1.8` | | [@radix-ui/react-tabs](https://github.com/radix-ui/primitives) | `1.1.3` | `1.1.13` | | [@react-three/fiber](https://github.com/pmndrs/react-three-fiber) | `9.6.0` | `9.6.1` | | [@tailwindcss/postcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss) | `4.2.0` | `4.2.4` | | [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `6.0.153` | `6.0.176` | | [jsonwebtoken](https://github.com/auth0/node-jsonwebtoken) | `9.0.2` | `9.0.3` | | [katex](https://github.com/KaTeX/KaTeX) | `0.16.22` | `0.16.45` | | [langfuse](https://github.com/langfuse/langfuse-js/tree/HEAD/langfuse) | `3.38.4` | `3.38.20` | | [livekit-server-sdk](https://github.com/livekit/node-sdks/tree/HEAD/packages/livekit-server-sdk) | `2.15.0` | `2.15.2` | | [nanoid](https://github.com/ai/nanoid) | `5.1.5` | `5.1.11` | | [openai-edge](https://github.com/dan-kwiat/openai-edge) | `1.2.2` | `1.2.3` | | [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) | `4.2.0` | `4.2.4` | | [use-stick-to-bottom](https://github.com/stackblitz/use-stick-to-bottom) | `1.1.1` | `1.1.4` | Updates `@ai-sdk/mcp` from 1.0.35 to 1.0.41 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/@ai-sdk/mcp@1.0.41/packages/mcp/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/mcp@1.0.41/packages/mcp) Updates `@ai-sdk/openai-compatible` from 2.0.41 to 2.0.47 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/@ai-sdk/openai-compatible@2.0.47/packages/openai-compatible/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/openai-compatible@2.0.47/packages/openai-compatible) Updates `@ai-sdk/react` from 3.0.155 to 3.0.178 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/@ai-sdk/react@3.0.178/packages/react/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/react@3.0.178/packages/react) Updates `@headlessui/react` from 2.2.0 to 2.2.10 - [Release notes](https://github.com/tailwindlabs/headlessui/releases) - [Changelog](https://github.com/tailwindlabs/headlessui/blob/main/packages/@headlessui-react/CHANGELOG.md) - [Commits](https://github.com/tailwindlabs/headlessui/commits/@headlessui/react@v2.2.10/packages/@headlessui-react) Updates `@opentelemetry/api` from 1.9.0 to 1.9.1 - [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-js@v1.9.0...v1.9.1) Updates `@radix-ui/react-accordion` from 1.2.3 to 1.2.12 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-avatar` from 1.1.3 to 1.1.11 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-collapsible` from 1.1.11 to 1.1.12 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-dialog` from 1.1.6 to 1.1.15 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-dropdown-menu` from 2.1.6 to 2.1.16 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-hover-card` from 1.1.6 to 1.1.15 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-label` from 2.1.2 to 2.1.8 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-scroll-area` from 1.2.9 to 1.2.10 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-select` from 2.2.5 to 2.2.6 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-separator` from 1.1.2 to 1.1.8 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@radix-ui/react-tabs` from 1.1.3 to 1.1.13 - [Changelog](https://github.com/radix-ui/primitives/blob/main/release-process.md) - [Commits](https://github.com/radix-ui/primitives/commits) Updates `@react-three/fiber` from 9.6.0 to 9.6.1 - [Release notes](https://github.com/pmndrs/react-three-fiber/releases) - [Commits](pmndrs/react-three-fiber@v9.6.0...v9.6.1) Updates `@tailwindcss/postcss` from 4.2.0 to 4.2.4 - [Release notes](https://github.com/tailwindlabs/tailwindcss/releases) - [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.2.4/packages/@tailwindcss-postcss) Updates `ai` from 6.0.153 to 6.0.176 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/ai@6.0.176/packages/ai/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/ai@6.0.176/packages/ai) Updates `jsonwebtoken` from 9.0.2 to 9.0.3 - [Changelog](https://github.com/auth0/node-jsonwebtoken/blob/master/CHANGELOG.md) - [Commits](auth0/node-jsonwebtoken@v9.0.2...v9.0.3) Updates `katex` from 0.16.22 to 0.16.45 - [Release notes](https://github.com/KaTeX/KaTeX/releases) - [Changelog](https://github.com/KaTeX/KaTeX/blob/main/CHANGELOG.md) - [Commits](KaTeX/KaTeX@v0.16.22...v0.16.45) Updates `langfuse` from 3.38.4 to 3.38.20 - [Release notes](https://github.com/langfuse/langfuse-js/releases) - [Commits](https://github.com/langfuse/langfuse-js/commits/v3.38.20/langfuse) Updates `livekit-server-sdk` from 2.15.0 to 2.15.2 - [Release notes](https://github.com/livekit/node-sdks/releases) - [Changelog](https://github.com/livekit/node-sdks/blob/main/packages/livekit-server-sdk/CHANGELOG.md) - [Commits](https://github.com/livekit/node-sdks/commits/livekit-server-sdk@2.15.2/packages/livekit-server-sdk) Updates `nanoid` from 5.1.5 to 5.1.11 - [Release notes](https://github.com/ai/nanoid/releases) - [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md) - [Commits](ai/nanoid@5.1.5...5.1.11) Updates `openai-edge` from 1.2.2 to 1.2.3 - [Commits](https://github.com/dan-kwiat/openai-edge/commits) Updates `tailwindcss` from 4.2.0 to 4.2.4 - [Release notes](https://github.com/tailwindlabs/tailwindcss/releases) - [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.2.4/packages/tailwindcss) Updates `use-stick-to-bottom` from 1.1.1 to 1.1.4 - [Changelog](https://github.com/stackblitz-labs/use-stick-to-bottom/blob/main/CHANGELOG.md) - [Commits](https://github.com/stackblitz/use-stick-to-bottom/commits) --- updated-dependencies: - dependency-name: "@ai-sdk/mcp" dependency-version: 1.0.39 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@ai-sdk/openai-compatible" dependency-version: 2.0.46 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@ai-sdk/react" dependency-version: 3.0.177 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@headlessui/react" dependency-version: 2.2.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@opentelemetry/api" dependency-version: 1.9.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-accordion" dependency-version: 1.2.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-avatar" dependency-version: 1.1.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-collapsible" dependency-version: 1.1.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-dialog" dependency-version: 1.1.15 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-dropdown-menu" dependency-version: 2.1.16 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-hover-card" dependency-version: 1.1.15 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-label" dependency-version: 2.1.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-scroll-area" dependency-version: 1.2.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-select" dependency-version: 2.2.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-separator" dependency-version: 1.1.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@radix-ui/react-tabs" dependency-version: 1.1.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@react-three/fiber" dependency-version: 9.6.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: "@tailwindcss/postcss" dependency-version: 4.2.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: ai dependency-version: 6.0.175 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: jsonwebtoken dependency-version: 9.0.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: katex dependency-version: 0.16.45 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: langfuse dependency-version: 3.38.20 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: livekit-server-sdk dependency-version: 2.15.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: nanoid dependency-version: 5.1.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: openai-edge dependency-version: 1.2.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: tailwindcss dependency-version: 4.2.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches - dependency-name: use-stick-to-bottom dependency-version: 1.1.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patches ... Signed-off-by: dependabot[bot] <support@github.com>
641903c to
41d6126
Compare
Bumps the patches group with 27 updates in the / directory:
1.0.351.0.412.0.412.0.473.0.1553.0.1782.2.02.2.101.9.01.9.11.2.31.2.121.1.31.1.111.1.111.1.121.1.61.1.152.1.62.1.161.1.61.1.152.1.22.1.81.2.91.2.102.2.52.2.61.1.21.1.81.1.31.1.139.6.09.6.14.2.04.2.46.0.1536.0.1769.0.29.0.30.16.220.16.453.38.43.38.202.15.02.15.25.1.55.1.111.2.21.2.34.2.04.2.41.1.11.1.4Updates
@ai-sdk/mcpfrom 1.0.35 to 1.0.41Changelog
Sourced from @ai-sdk/mcp's changelog.
Commits
e3ccdb5Version Packages (#15094)f591416Backport: feat(ai): add toolMetadata for tool specific metdata (#15053)74a7a20Version Packages (#15012)0084974Backport: feat(mcp): deprecate name and use clientName for MCPClient (#15003)221a984Backport: fix(@ai-sdk/mcp): add resource_link content type to CallToolResultS...8a46a3cVersion Packages (#14875)7beadf0Backport: feat(mcp): propagate the server name through dynamic tool parts (#1...8e650abVersion Packages (#14824)a727da4backport of chore: ensure consistent import handling and avoid import duplica...5fee301backport v6: fix(mcp): prevent prototype pollution by using secureJsonParse (...Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@ai-sdk/mcpsince your current version.Updates
@ai-sdk/openai-compatiblefrom 2.0.41 to 2.0.47Changelog
Sourced from @ai-sdk/openai-compatible's changelog.
Commits
e3ccdb5Version Packages (#15094)a1dddccVersion Packages (#14954)38966abbackport v6: fix(openai, openai-compatible): only send null content for assis...3def720Version Packages (#14908)6043d24Backport: feat(vertex): add grok models to vertex provider (#14902)8a46a3cVersion Packages (#14875)8e650abVersion Packages (#14824)a727da4backport of chore: ensure consistent import handling and avoid import duplica...77a4e05Version Packages (#14802)a7f3c72Re-enable v6 releases (#14799)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@ai-sdk/openai-compatiblesince your current version.Updates
@ai-sdk/reactfrom 3.0.155 to 3.0.178Changelog
Sourced from @ai-sdk/react's changelog.
... (truncated)
Commits
e3ccdb5Version Packages (#15094)3015153Version Packages (#14960)0129eb6Version Packages (#14912)8a46a3cVersion Packages (#14875)29c80ecVersion Packages (#14868)8e650abVersion Packages (#14824)a727da4backport of chore: ensure consistent import handling and avoid import duplica...7ab1e18Version Packages (#14815)77a4e05Version Packages (#14802)a7f3c72Re-enable v6 releases (#14799)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@ai-sdk/reactsince your current version.Updates
@headlessui/reactfrom 2.2.0 to 2.2.10Release notes
Sourced from @headlessui/react's releases.
... (truncated)
Changelog
Sourced from @headlessui/react's changelog.
... (truncated)
Commits
d13526d2.2.10 -@headlessui/reactb0dcd8fHandle props on Fragment error due toSymbol(react.lazy)(#3873)7baca70Don’t render\<Portal>s while hydrating (#3825)5ef7395AddRefProptoprops(#3823)589ea902.2.9 -@headlessui/reactbba75c7update changelogca536edupdate changelog49e9e8edo not serialize React components into form fields2a647a7Ensure refs are forwarded when freezing data (#3390)da2fa94Freeze values as soon as possible (#3802)Updates
@opentelemetry/apifrom 1.9.0 to 1.9.1Release notes
Sourced from @opentelemetry/api's releases.
Changelog
Sourced from @opentelemetry/api's changelog.
Commits
279458eRelease 1.9.1 / 0.35.1 (#3573)4978743fix(http): remove outgoing headers normalization (#3557)d1f9594chore(deps): update dependency rimraf to v4 (#3532)e0abcc0fix: remove JSON syntax error and regenerate tsconfig files (#3566)a90c558fix(sdk-node): register instrumentations early (#3502)5b070b8fix: include TraceState in trace exports (#3569)dcb09b7chore(deps): update dependency gh-pages to v5 (#3571)3bc93a9feat: exponential histogram - part 1 - mapping functions (#3504)3670071fix: avoid grpc types dependency (#3551)b5ef0e4chore: fix proto generation (#3567)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@opentelemetry/apisince your current version.Updates
@radix-ui/react-accordionfrom 1.2.3 to 1.2.12Commits
Updates
@radix-ui/react-avatarfrom 1.1.3 to 1.1.11Commits
Updates
@radix-ui/react-collapsiblefrom 1.1.11 to 1.1.12Commits
Updates
@radix-ui/react-dialogfrom 1.1.6 to 1.1.15Commits
Updates
@radix-ui/react-dropdown-menufrom 2.1.6 to 2.1.16Commits
Updates
@radix-ui/react-hover-cardfrom 1.1.6 to 1.1.15Commits
Updates
@radix-ui/react-labelfrom 2.1.2 to 2.1.8Commits
Updates
@radix-ui/react-scroll-areafrom 1.2.9 to 1.2.10Commits
Updates
@radix-ui/react-selectfrom 2.2.5 to 2.2.6Commits
Updates
@radix-ui/react-separatorfrom 1.1.2 to 1.1.8Commits
Updates
@radix-ui/react-tabsfrom 1.1.3 to 1.1.13Commits
Updates
@react-three/fiberfrom 9.6.0 to 9.6.1Release notes
Sourced from @react-three/fiber's releases.
Commits
2a52874RELEASING: Releasing 1 package(s)b645741docs(changeset): fix: Seamlessly transfer interactivity state when swapping i...119668ffix: Seamlessly transfer interactivity state when swapping instances (#3744)943a37eMerge pull request #3738 from pmndrs:chore/simplify-shadermaterial-demo1be9504chore: Add uniform piercing test4df10c0chore: Simplify ShaderMaterial demo47d30bachore: Move ShaderMaterial uniform notes to objects out of pitfallsUpdates
@tailwindcss/postcssfrom 4.2.0 to 4.2.4Release notes
Sourced from @tailwindcss/postcss's releases.
Changelog
Sourced from @tailwindcss/postcss's changelog.
... (truncated)
Commits
69ad7cc4.2.4 (#19948)685c19eFix issue around resolving paths in@tailwindcss/vite(#19947)2e3fa494.2.3 (#19944)4527123docs(postcss): remove duplicated optimize example from README (#19938)aad6017docs/fix-lightning-css-typo-postcss-readme (#19913)d596b0c4.2.2 (#19821)faa5e88Cleanup inconsistencies related to (regex) escapes (#19804)1dce64e4.2.1 (#19714)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@tailwindcss/postcsssince your current version.Updates
aifrom 6.0.153 to 6.0.176Changelog
Sourced from ai's changelog.
... (truncated)
Commits
e3ccdb5Version Packages (#15094)f591416Backport: feat(ai): add toolMetadata for tool specific metdata (#15053)0084974Backport: feat(mcp): deprecate name and use clientName for MCPClient (#15003)3015153Version Packages (#14960)0129eb6Version Packages (#14912)8a46a3cVersion Packages (#14875)7beadf0Backport: feat(mcp): propagate the server name through dynamic tool parts (#1...29c80ecVersion Packages (#14868)8e650abVersion Packages (#14824)