chore(deps): update all non-major dependencies#1825
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
PR Summary
|
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
21 times, most recently
from
April 6, 2026 13:01
59d69a1 to
e22be0f
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
6 times, most recently
from
April 7, 2026 14:35
ab302d9 to
88f9fa8
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
17 times, most recently
from
April 20, 2026 09:07
5787c43 to
141c929
Compare
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
5 times, most recently
from
April 22, 2026 10:33
81d7e9e to
0ff655b
Compare
@stacksjs/actions
@stacksjs/ai
@stacksjs/alias
@stacksjs/analytics
@stacksjs/api
@stacksjs/arrays
@stacksjs/auth
@stacksjs/browser
@stacksjs/browser-extension
@stacksjs/buddy
@stacksjs/build
@stacksjs/cache
@stacksjs/calendar-api
@stacksjs/charts
@stacksjs/chat
@stacksjs/cli
@stacksjs/cloud
@stacksjs/cms
@stacksjs/collections
@stacksjs/commerce
@stacksjs/composables
@stacksjs/config
@stacksjs/cron
@stacksjs/database
@stacksjs/datetime
@stacksjs/defaults
@stacksjs/desktop
@stacksjs/dns
@stacksjs/docs
@stacksjs/email
@stacksjs/enums
@stacksjs/env
@stacksjs/error-handling
@stacksjs/events
@stacksjs/faker
@stacksjs/feature-flags
@stacksjs/git
@stacksjs/github
@stacksjs/health
@stacksjs/http
@stacksjs/i18n
@stacksjs/lint
@stacksjs/logging
@stacksjs/newsletter
@stacksjs/notifications
@stacksjs/objects
@stacksjs/orm
@stacksjs/path
@stacksjs/payments
@stacksjs/push
@stacksjs/query-builder
@stacksjs/queue
@stacksjs/realtime
@stacksjs/registry
@stacksjs/repl
@stacksjs/router
@stacksjs/scheduler
@stacksjs/search-engine
@stacksjs/security
@stacksjs/server
@stacksjs/shell
@stacksjs/skills
@stacksjs/slug
@stacksjs/sms
@stacksjs/socials
@stacksjs/storage
@stacksjs/strings
@stacksjs/testing
@stacksjs/tinker
@stacksjs/tunnel
@stacksjs/types
@stacksjs/ui
@stacksjs/utils
@stacksjs/validation
@stacksjs/whois
commit: |
renovate
Bot
force-pushed
the
renovate/all-minor-patch
branch
6 times, most recently
from
April 23, 2026 16:46
9f467f0 to
c57f981
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.2.79→^0.3.216^0.2.79→^0.3.216^0.2.6→^0.2.10^0.1.0→^0.1.2^0.1.12→^0.1.13^0.3.24→^0.3.28^0.1.10→^0.1.11^0.11.29→^0.11.30^0.13.0→^0.13.13^0.13.2→^0.13.13^0.1.9→^0.1.11^0.5.0→^0.5.2^9.10.0→^9.12.0^9.10.0→^9.12.0^0.2.0→^0.2.3^0.2.0→^0.2.3^1.3.11→^1.3.14^3.7.2-12→^3.9.2^0.4.0→^0.4.1^0.15.11→^0.15.15^0.3.2→^0.3.51.3.10→1.3.141.3.11→1.3.141.3.11→1.3.14>=4.0.0→>=4.7.1^0.1.1→^0.1.3^0.10.11→^0.10.28^0.4.2→^0.4.4^0.1.0→^0.1.2^0.2.1→^0.2.5^1.109.5→^1.129.1Release Notes
anthropics/claude-agent-sdk-typescript (@anthropic-ai/claude-agent-sdk)
v0.3.216Compare Source
skippedLinkscount torewindFilesresponses for paths the rewind safety guards refused to restore or deletetool_result_metasidecar to user messages (non_execution_kind,user_feedback) so consumers can classify denied, interrupted, or cancelled tool calls without string-matching result proseuser_message_uuidandrequest_sent_wall_msfields to the success result message for cross-host request-latency correlationv0.3.215Compare Source
v0.3.214set_permission_modenow rejects unrecognized permission modes with an error instead of silently adopting them; the'manual'alias is accepted at every ingresssubkind: 'scheduled-trigger'to thetask-notificationmember ofSDKMessageOrigin, marking deliveries that are the fired prompt of a user-configured scheduled taskapplyFlagSettings({effortLevel})now accepts'max'in its TypeScript type (runtime already supported it)interrupt()now carryaborted: true, so consumers can distinguish a mid-stream partial from a completed messagesubagent_typeandsubagent_retryfields totool_progressmessages so clients can show a subagent waiting out an API rate-limit retrysystem/initmessage'spluginsentries and thereload_pluginsresponse now include each plugin's manifestversion"fork"instead of"resume"when the session begins as a forkv0.3.213v0.3.212Compare Source
resumeSessionAtandsessionIdvalues being passed to the CLI as separate argv tokens; both now use equals-form (--flag=value)v0.3.211Compare Source
--replay-user-messageswith--include-partial-messagesemitting the turn-start user replay after the first content block instead of before the turn's content eventsSDKAssistantMessage.timestamp(ISO-8601) to the live stream, matchingSDKUserMessage; older emitters omit it, consumers should fall back to receive timeUSAGE_LIMIT_ERROR_PREFIXESand siblings) as@alphaexports for classifying rate-limit messages without hand-mirrored listsv0.3.210Compare Source
timedOutAfterMstoBashToolOutput, set when a command is auto-backgrounded on timeoutv0.3.209Compare Source
v0.3.208Compare Source
UserPromptSubmithook callback exceeding its timeout killing the entire query with an empty error; it now blocks the prompt with a clear timeout message and the session continuesextraArgsvalues that look like flags (e.g.resume: '--version') being parsed as their own CLI flags; dash-leading values are now bound with equals-form argvAbortControllerno longer accumulateabortlisteners on its signal after each completed querycreateSdkMcpServerdocs pointing at a nonexistent env var; the MCP tool-call timeout knob isMCP_TOOL_TIMEOUTv0.3.207Compare Source
canUseToolreturning{behavior: 'allow'}withoutupdatedInputbeing rejected as a deny with a raw ZodError message; the tool now runs with the original input per the documented contractAgentToolCompletedOutput) that matches the emitted object exactlyv0.3.206Compare Source
command_lifecycleframes to stream-json and SDK sessions, reporting each uuid-stamped message's terminal state (queued/started/completed/cancelled/discarded); zero-API results no longer report staleduration_api_msv0.3.205Compare Source
still_queued(UUIDs of queued async messages that will still run),Query.interrupt()returns the typed receipt, andsystem/initadvertises aninterrupt_receipt_v1capability for feature detectionnameandbodyfields to peer-message session events, exposing the sender display name and decoded message bodyv0.3.204Compare Source
terminal_reasonvaluestool_deferred_unavailable(deferred tool resume found the tool gone — previously anis_errorresult with no reason, read as a clean completion by lifecycle sweeps) andturn_setup_failed(the turn-input builder threw before the turn started). Both classify as dead turns, so commands consumed by them reportcommand_lifecyclestatecancelledcancelled— on remote transports that acknowledged them as processed, silently dropping messages nobody cancelled)terminal_reasonvaluesapi_error,malformed_tool_use_exhausted,budget_exhausted, andstructured_output_retry_exhausted. Turns that die on an exhausted-API-retry or malformed-tool-use give-up previously reportedcompleted; budget and structured-output exhaustion results previously omittedterminal_reason. Commands consumed by such turns now reportcommand_lifecyclestatecancelledinstead ofcompleted(dup-over-loss)v0.3.203Compare Source
background_tasks_changedsystem message with the full set of live background tasks on every membership change, so consumers can track background activity as a level instead of pairingtask_started/task_notificationedgessdk.d.tswith unresolved type references that broke consumer typechecking withskipLibCheckdisabledv0.3.202Compare Source
parent_agent_idfield to subagent session messages for building depth-2+ agent trees from disk-persisted metadataapply_flag_settingswith a non-object settings value crashing the session instead of returning a control errorv0.3.201Compare Source
v0.3.200Compare Source
'manual'as an accepted alias for the'default'permission mode in SDK inputsonSetPermissionModecallback not firing for SDK-hosted Remote Control sessionsset_modelcontrol request accepting unrecognized model strings; invalid models are now rejected before latchingv0.3.199Compare Source
requestIdtocanUseToolcallback options for correlating out-of-band permission responses, and support for returningnullto suppress the SDK's automatic control responseblockedfield toworkflow_agentprogress events indicating when an agent was blocked by the auto-mode safety classifiermode:"mask"and per-credentialinjectHoststosandbox.credentialssettings types for injecting masked credentials into sandboxed commandsv0.3.198Compare Source
canUseToolis configured alongsideallowedToolsorbypassPermissions, which shadow the callbackrequest_timeout_msoption tomcp_set_serverscontrol requestSDKUserMessage.isSyntheticnot being mapped toisMetaon ingestion, which could cause synthetic messages to be treated as real user messagesv0.3.197Compare Source
v0.3.196Compare Source
prompt_idfield to hook input payloads for correlating hook events with OpenTelemetry prompt-level eventstool_resultdeliveries in long-running sessionsv0.3.195Compare Source
Query.reinitialize()to re-send the initialize control request and redeliver pending permission/dialog prompts after a transport gapcommands_changedevent not being emitted for synced skills when the skill list resolves before the change-detector subscribesv0.3.193Compare Source
promptSuggestionsoption to Browser SDKquery()to opt the remote CLI into emitting follow-up suggestionsv0.3.191Compare Source
old_sourcefield toNotebookEdittool results forreplaceanddeleteoperations, enabling inline diffsseven_day_overage_includedtoSDKRateLimitInfo.rateLimitTypefor per-model weekly usage limitsmodel_scopedarray to usage response for per-model weekly limit windows with utilization and reset timessettingSourcesincludes user/project settingsv0.3.190Compare Source
v0.3.187Compare Source
sandbox.credentialsto SDK settings types for configuring credential file and environment variable denial in sandboxed commandsv0.3.186Compare Source
agent_idfield tocan_use_toolcontrol requests — background agents now forward permission prompts tocanUseToolinstead of auto-denying, and stdin stays open while background tasks are runningReadMcpResourceDirTooltool type to SDK schemas — MCP resource directory listing is now a dedicated tool instead of a fallback insideReadMcpResourceToolrewind_conversationcontrol request for rewinding a conversation to a previous point with durable resume anchor supportv0.3.185Compare Source
v0.3.183v0.3.182v0.3.181Compare Source
errorCode,canUserPurchaseCredits, andhasChargeableSavedPaymentMethodfields toSDKRateLimitInfofor detecting credits-required rate limitstool_use_meta.icon_urlto assistant messages, populated from MCP server directory metadatafile_attachmentsfrom inbound user messagesv0.3.179Compare Source
tool_use_metasidecar to assistant messages with display-friendly names for tool calls, so SDK consumers can render human-readable labels instead of raw wire names-pmode exiting before a completed background agent's notification was delivered, causing interim text to ship as the final resultv0.3.178Compare Source
options.pathToClaudeCodeExecutablesafetyCheck,asyncAgent), enabling SDK consumers to programmatically match denial causesUserPromptSubmithook block feedback not being emitted to the SDK event stream — consumers can now see why a prompt was blocked by a hook instead of a silent hangworker_shutting_downsystem message on graceful exit so remote clients can show why the session endedmcp__server,mcp__server__*) indisallowedToolsbeing silently ignored — they now correctly remove all tools from the named serverv0.3.177Compare Source
v0.3.176Compare Source
resultmessages being dropped when multiple turns complete while a background agent or workflow is runningv0.3.175Compare Source
v0.3.174Compare Source
system/model_fallbackmessage for all fallback triggers —overloaded,server_error, andlast_resortin addition tomodel_not_foundandpermission_denied— and the message'striggerfield gained theserver_errorandlast_resortvaluesv0.3.173Compare Source
v0.3.172Compare Source
pluginsoption now acceptsskipMcpDiscovery: trueper plugin, so a host that manages a plugin's MCP connections itself can load skills/hooks from the plugin path without the engine re-reading its.mcp.json/ add tests) being silently dropped instead of treated as a plain promptv0.3.170Compare Source
v0.3.169Compare Source
usage_EXPERIMENTAL_MAY_CHANGE_DO_NOT_RELY_ON_THIS_API_YET()method onQueryreturning structured session cost, plan rate-limit, and local usage-behaviors datasseoption (SSEOptions) toBrowserQueryOptionsas an alternative towebsocket, for browser SDK consumers who prefer Server-Sent Eventsv0.3.168Compare Source
v0.3.167Compare Source
v0.3.166Compare Source
mcp_set_serverscontrol requestv0.3.165Compare Source
v0.3.163Compare Source
stop_taskcontrol requests now return success when the target task is already gone (not_foundornot_running), so SDK clients can reliably prune stale task chipsclaude-in-chrome) viasetMcpServerswhen the CLI was launched without themadditionalContextinhookSpecificOutput, enabling non-error feedback that continues the turnv0.3.162Compare Source
stop_reason: "refusal"andstop_detailson the assistant message and in session transcripts, so SDK consumers can detect refusals without text-matching the error contentfind/grepsearch in Bash, matching the interactive CLI, instead of always registering the dedicated Grep/Glob tools. To keep the dedicated tools (e.g. to intercept searches viacanUseToolor hooks), name them in thetoolsoption or reference them inallowedToolsv0.3.161Compare Source
initializecontrol request is now idempotent: a secondinitializereturns the same success payload instead of anAlready initializederror.ControlResponsegains an optionalpending_permission_requestsfield, mirroringControlErrorResponseapplyFlagSettingsnow live-appliesagentchanges: switching the active agent (or passingnullto reset) takes effect on the next turn in a running sessionv0.3.160Compare Source
resultmessage instead of hanging the calling processv0.3.159Compare Source
v0.3.158Compare Source
v0.3.157Compare Source
v0.3.156Compare Source
v0.3.154Compare Source
v0.3.153Compare Source
v0.3.152Compare Source
SessionStarthooks can now returnreloadSkills: trueto trigger a skill re-scan, and set the session title viahookSpecificOutput.sessionTitleMessageDisplayhook event that lets hooks transform or hide assistant message text as it is displayedv0.3.150Compare Source
v0.3.149Compare Source
options.envdroppingCLAUDE_AGENT_SDK_VERSION(used forUser-Agentand telemetry) when a custom environment is supplied, and corrected theOptions.envdocs to state that the value replaces the subprocess environment rather than merging withprocess.envv0.3.148Compare Source
v0.3.147Compare Source
v0.3.146Compare Source
v0.3.145Compare Source
v0.3.144Compare Source
StopFailurehooks now reporterror: 'model_not_found'when the selected model doesn't exist or isn't available, instead of the generic'invalid_request'. Theapi_error_statusfield on result messages is now documented.@anthropic-ai/claude-agent-sdk/extractexport forbun build --compileconsumers: import the platform native binary withwith { type: 'file' }, callextractFromBunfs(binPath)to copy it out of the compiled executable's virtual filesystem, and pass the result tooptions.pathToClaudeCodeExecutablev0.3.143Compare Source
@anthropic-ai/sdkand@modelcontextprotocol/sdkare nowpeerDependenciesinstead ofdependencies. Runtime is unaffected (both are bundled); npm/bun/pnpm auto-install them. yarn classic users should add them explicitly for full TypeScript type resolutionv0.3.142Compare Source
unstable_v2_createSession,unstable_v2_resumeSession,unstable_v2_prompt,SDKSession,SDKSessionOptions), deprecated since 0.2.133. Usequery()— pass anAsyncIterable<SDKUserMessage>for multi-turn, oroptions.resumeto continue a session.status: "pending"ininituntil ready. SetMCP_CONNECTION_NONBLOCKING=0to restore the old behavior of waiting up to 5s before the first query, or mark a serveralwaysLoad: trueto require it in turn 1.TaskCreate/TaskUpdate/TaskGet/TaskList) instead ofTodoWrite, deprecated since 0.2.136. Tool consumers should accumulate by task ID instead of replacing a snapshot list.request_id,subagent_type, andtask_descriptionon SDK message types and task system events--sdk-urlsessions now exit non-zero with a stderr diagnostic when the remote transport closes permanently (401/403/404 or WS permanent close), instead of silently exiting 0v0.2.141Compare Source
TaskCreateInput,TaskCreateOutput,TaskGetInput,TaskGetOutput,TaskUpdateInput,TaskUpdateOutput,TaskListInput, andTaskListOutputtypes are now exported from@anthropic-ai/claude-agent-sdk/sdk-toolsand included in theToolInputSchemas/ToolOutputSchemasunions@anthropic-ai/sdkdependency to ^0.93.0v0.2.140Compare Source
v0.2.139Compare Source
v0.2.138Compare Source
v0.2.137Compare Source
v0.2.136Compare Source
resolveSettings()(alpha) to inspect effective merged settings without spawning the Claude CLI; reads MDM (plist/HKLM/HKCU) for parity with CLI startupTodoWritetool — future versions will switch to Task tools (TaskCreate,TaskGet,TaskUpdate,TaskList)v0.2.133Compare Source
unstable_v2_createSession/unstable_v2_resumeSession/unstable_v2_prompt) — usequery()instead'Skill'inallowedTools— use theskillsoption insteadv0.2.132Compare Source
applyFlagSettings()in the TypeScript Agent SDK reference and added support fornullon top-level keys to clear flag-settings overridesv0.2.131Compare Source
v0.2.129Compare Source
v0.2.128Compare Source
v0.2.126originto result messages (SDKResultSuccess/SDKResultError) — forwards the triggering message'sSDKMessageOriginso consumers can distinguish user-prompted results fromtask-notificationfollowupsv0.2.124v0.2.123[Compare Sourc
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.