Skip to content

build(deps): bump the production-dependencies group with 9 updates - #150

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-b4a905f8c5
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-b4a905f8c5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 9 updates:

Package From To
@ai-sdk/google 4.0.78 4.0.86
@ai-sdk/openai 4.0.73 4.0.82
@ai-sdk/otel 1.0.112 1.0.123
@better-auth/infra 0.4.10 0.4.13
ai 7.0.112 7.0.123
better-auth 1.7.5 1.7.6
dompurify 3.4.15 3.4.16
katex 0.18.7 0.18.9
lucide-react 1.47.0 1.49.0

Updates @ai-sdk/google from 4.0.78 to 4.0.86

Changelog

Sourced from @​ai-sdk/google's changelog.

4.0.86

Patch Changes

  • ede5b89: chore: migrate package builds from tsup to tsdown
  • Updated dependencies [ede5b89]
    • @​ai-sdk/provider@​4.0.20
    • @​ai-sdk/provider-utils@​5.0.52

4.0.85

Patch Changes

  • c2511c1: fix: use standards-compliant User-Agent header
  • Updated dependencies [c2511c1]
    • @​ai-sdk/provider-utils@​5.0.51

4.0.84

Patch Changes

  • d0290cf: fix(google): preserve realtime user utterances with independent IDs and cumulative transcripts, honor text-free transcription completion markers, and advance response IDs after interruption

4.0.83

Patch Changes

  • 32cf2f6: fix(google): send the default Gemini Live thinkingLevel when thinkingConfig sets neither thinkingLevel nor thinkingBudget, and stop overwriting a raw generationConfig.thinkingConfig

  • 525efc5: feat(provider): advertise image model file and mask input support

    Use confirmed model IDs for capability declarations so unrecognized model names remain unknown. Include Together AI FLUX.2 Pro and Flex single-image editing, and allow asynchronous capability lookups and middleware overrides to resolve to unknown.

    Advertise QuiverAI Arrow 2 and Arrow 2 Telos file-input support, and mark Together AI Gemini image inputs unsupported by the current single-image request mapping.

  • Updated dependencies [e3605f6]

  • Updated dependencies [525efc5]

    • @​ai-sdk/provider-utils@​5.0.50
    • @​ai-sdk/provider@​4.0.19

4.0.82

Patch Changes

  • bc49f78: fix(google): forward supported Vertex tool result URLs as function response file data
  • Updated dependencies [af9597b]
  • Updated dependencies [bc49f78]

... (truncated)

Commits

Updates @ai-sdk/openai from 4.0.73 to 4.0.82

Changelog

Sourced from @​ai-sdk/openai's changelog.

4.0.82

Patch Changes

  • 040033b: feat(openai): add GPT-6.1 Sol model support
  • ede5b89: chore: migrate package builds from tsup to tsdown
  • Updated dependencies [ede5b89]
    • @​ai-sdk/provider@​4.0.20
    • @​ai-sdk/provider-utils@​5.0.52

4.0.81

Patch Changes

  • 4e94782: fix(openai): rewrite recursive Zod schemas that use allOf wrappers

4.0.80

Patch Changes

  • c2511c1: fix: use standards-compliant User-Agent header
  • Updated dependencies [c2511c1]
    • @​ai-sdk/provider-utils@​5.0.51

4.0.79

Patch Changes

  • e3605f6: Fix streamed tool calls with missing, blank, or repeated IDs.

  • 525efc5: feat(provider): advertise image model file and mask input support

    Use confirmed model IDs for capability declarations so unrecognized model names remain unknown. Include Together AI FLUX.2 Pro and Flex single-image editing, and allow asynchronous capability lookups and middleware overrides to resolve to unknown.

    Advertise QuiverAI Arrow 2 and Arrow 2 Telos file-input support, and mark Together AI Gemini image inputs unsupported by the current single-image request mapping.

  • Updated dependencies [e3605f6]

  • Updated dependencies [525efc5]

    • @​ai-sdk/provider-utils@​5.0.50
    • @​ai-sdk/provider@​4.0.19

4.0.78

Patch Changes

  • 94d5d6d: Support reasoningEffortUpdate: 'none' for GPT-6 Sol and Luna in request-level options and positioned system messages. Validate update efforts against the model's supported efforts, warning and omitting unsupported request-level updates and rejecting unsupported historical updates.

... (truncated)

Commits

Updates @ai-sdk/otel from 1.0.112 to 1.0.123

Changelog

Sourced from @​ai-sdk/otel's changelog.

1.0.123

Patch Changes

  • ede5b89: chore: migrate package builds from tsup to tsdown
  • Updated dependencies [05cdac6]
  • Updated dependencies [4514fc1]
  • Updated dependencies [ede5b89]
  • Updated dependencies [2a625cf]
  • Updated dependencies [50a26d5]
    • ai@7.0.123
    • @​ai-sdk/provider@​4.0.20

1.0.122

Patch Changes

  • Updated dependencies [f3575f8]
  • Updated dependencies [27ab8d4]
    • ai@7.0.122

1.0.121

Patch Changes

  • Updated dependencies [c5e90bb]
  • Updated dependencies [868c475]
  • Updated dependencies [119536f]
  • Updated dependencies [9941f32]
    • ai@7.0.121

1.0.120

Patch Changes

  • Updated dependencies [b032d70]
  • Updated dependencies [e21b98b]
    • ai@7.0.120

1.0.119

Patch Changes

  • Updated dependencies [33e94ba]
  • Updated dependencies [34d869e]
  • Updated dependencies [def4df8]
  • Updated dependencies [525efc5]
    • ai@7.0.119
    • @​ai-sdk/provider@​4.0.19

... (truncated)

Commits

Updates @better-auth/infra from 0.4.10 to 0.4.13

Commits

Updates ai from 7.0.112 to 7.0.123

Release notes

Sourced from ai's releases.

ai@7.0.123

Patch Changes

  • 05cdac6: fix(ai): keep idle UI message streams open with optional SSE heartbeats
  • 4514fc1: fix(ai): prune all tool content when retaining zero trailing messages
  • ede5b89: chore: migrate package builds from tsup to tsdown
  • 2a625cf: fix(ai): preserve partial reasoning tags when streamed text parts end
  • 50a26d5: fix(ai): ignore pending tool approvals superseded by user messages
  • Updated dependencies [040033b]
  • Updated dependencies [ede5b89]
    • @​ai-sdk/gateway@​4.0.101
    • @​ai-sdk/provider@​4.0.20
    • @​ai-sdk/provider-utils@​5.0.52
Changelog

Sourced from ai's changelog.

7.0.123

Patch Changes

  • 05cdac6: fix(ai): keep idle UI message streams open with optional SSE heartbeats
  • 4514fc1: fix(ai): prune all tool content when retaining zero trailing messages
  • ede5b89: chore: migrate package builds from tsup to tsdown
  • 2a625cf: fix(ai): preserve partial reasoning tags when streamed text parts end
  • 50a26d5: fix(ai): ignore pending tool approvals superseded by user messages
  • Updated dependencies [040033b]
  • Updated dependencies [ede5b89]
    • @​ai-sdk/gateway@​4.0.101
    • @​ai-sdk/provider@​4.0.20
    • @​ai-sdk/provider-utils@​5.0.52

7.0.122

Patch Changes

  • f3575f8: Clarify that provider-executed tool execution errors bypass the UI stream's onError callback to preserve provider error data and harness runtime messages. Stream errors and invalid tool calls still use the callback. Runtime behavior is unchanged.
  • 27ab8d4: Encode chat IDs in default stream reconnection URLs so slashes, query delimiters, and fragments stay within the ID. Reject standalone . and .. IDs before fetching. Custom URLs returned by prepareReconnectToStreamRequest remain unchanged.
  • Updated dependencies [870f509]
  • Updated dependencies [a75f1fd]
    • @​ai-sdk/gateway@​4.0.100

7.0.121

Patch Changes

  • c5e90bb: fix(ai): preserve hydrated partial static tool input across stream resumptions
  • 868c475: Preserve prototype-named tools, providers, and provider metadata as own properties without changing lookup object prototypes. Prevent inherited names from resolving as registered providers or causing image metadata aggregation to fail.
  • 119536f: Preserve provider metadata on corresponding smoothStream chunks without carrying it into subsequent metadata-free deltas.
  • 9941f32: Prevent automatic chat resumption when completed tool output is followed by terminal text without a completed stream state, while preserving resumption after completed model text.
  • Updated dependencies [dbddb5b]
  • Updated dependencies [c2511c1]
    • @​ai-sdk/gateway@​4.0.99
    • @​ai-sdk/provider-utils@​5.0.51

7.0.120

Patch Changes

  • b032d70: fix(ai): preserve tool metadata from tool output chunks
  • e21b98b: fix(ai): continue active UI message parts when resuming after a disconnect
  • Updated dependencies [e361d39]
    • @​ai-sdk/gateway@​4.0.98

7.0.119

Patch Changes

... (truncated)

Commits
  • 161a7fd Version Packages (#21718)
  • 4514fc1 fix: prune tool content when retaining zero trailing messages (#21732)
  • 2a625cf fix: preserve streamed text ending with a partial reasoning tag (#21726)
  • 05cdac6 fix: idle UI message streams failing to flush promptly or remain open behind ...
  • ede5b89 chore: move from tsup to tsdown (#21642)
  • 50a26d5 fix: prevent follow-up user messages from failing while tool approval is pend...
  • 9125dbf test(ai): cover persisted aborted tool history (#21575)
  • 69cc80b Version Packages (#21666)
  • 1040e97 Version Packages (#21638)
  • f3575f8 docs(ai): explain provider-executed tool error masking exception (#21650)
  • Additional commits viewable in compare view

Updates better-auth from 1.7.5 to 1.7.6

Release notes

Sourced from better-auth's releases.

v1.7.6

better-auth

Features

  • Added support for a bannedUserMessage function that receives the banned user, allowing sign-in errors to include details such as the ban reason. (#11325)
  • Added Vercel BotID as a captcha provider for protected authentication routes. (#11016)

Bug Fixes

  • Passwords over maxPasswordLength are now rejected with PASSWORD_TOO_LONG before hashing or verification. (#11324)
  • Fixed React hydration mismatches when session or plugin auth queries resolve before streamed components hydrate. (#11316)
  • Prevented older auth-query responses from overwriting newer results when requests overlap. (#11376)
  • Fixed model identity when a custom model name matches another schema key. (#11333)
  • Fixed schema validation for Cloudflare D1 when the Kysely dialect cannot introspect the database. (#11366)
  • Fixed social account linking through the OAuth Proxy plugin. (#11268)

For detailed changes, see CHANGELOG

@better-auth/kysely-adapter

Bug Fixes

  • Fixed model identity when a custom model name matches another schema key. (#11333)
  • Fixed schema validation for SQLite-generated primary keys, including INTEGER PRIMARY KEY columns without AUTOINCREMENT. (#11374)
  • Fixed schema validation for Cloudflare D1 when the Kysely dialect cannot introspect the database. (#11366)

For detailed changes, see CHANGELOG

@better-auth/prisma-adapter

Bug Fixes

  • Fixed model identity when a custom model name matches another schema key. (#11333)
  • Fixed schema validation for capitalized custom Prisma model names. (#11319)

For detailed changes, see CHANGELOG

@better-auth/core

Bug Fixes

  • Fixed model identity when a custom model name matches another schema key. (#11333)

For detailed changes, see CHANGELOG

@better-auth/drizzle-adapter

Bug Fixes

... (truncated)

Changelog

Sourced from better-auth's changelog.

1.7.6

Patch Changes

  • #11325 af88385 Thanks @​Wadiou! - Admin plugin bannedUserMessage can now be a function that receives the banned user, so sign-in errors can include details such as the ban reason.

  • #11268 2fa501c Thanks @​bytaesu! - Support linking social accounts through the OAuth Proxy plugin.

  • #11366 d41e2ca Thanks @​bytaesu! - Use targeted PRAGMA queries when a Kysely dialect cannot introspect Cloudflare D1.

  • #11016 3d0efa3 Thanks @​davbrito! - Support Vercel BotID checks on protected authentication routes in Vercel-hosted applications.

  • #11333 631ac29 Thanks @​bytaesu! - Preserve logical model identity when a custom model name matches another schema key.

  • #11324 8853419 Thanks @​XXMOHAMED012! - Passwords longer than maxPasswordLength are now rejected with PASSWORD_TOO_LONG before hashing on sign-in (email, username, phone number), verify-password, change-password (currentPassword), delete-user, the two-factor endpoints that take a password, and admin create-user, matching what sign-up and password reset already did.

  • #11316 2ee1545 Thanks @​Smidge! - Fix React hydration mismatches when a session or plugin auth query resolves before a streamed component hydrates. Preserve the server-rendered pending state during hydration, then update to the current client state without changing ordinary or computed plugin stores.

  • #11376 fc45d08 Thanks @​bytaesu! - Prevent older auth-query responses from replacing newer results when requests overlap.

  • Updated dependencies [41b7dc1, d41e2ca, 631ac29, 2b13e01]:

    • @​better-auth/prisma-adapter@​1.7.6
    • @​better-auth/kysely-adapter@​1.7.6
    • @​better-auth/core@​1.7.6
    • @​better-auth/drizzle-adapter@​1.7.6
    • @​better-auth/memory-adapter@​1.7.6
    • @​better-auth/mongo-adapter@​1.7.6
    • @​better-auth/telemetry@​1.7.6
Commits
  • 229a02a chore: release v1.7.6 (#11322)
  • dcaa5a7 feat(cli): add check command for schema validation (#11314)
  • fc45d08 fix(client): prevent stale query overwrites (#11376)
  • 8853419 fix: enforce maxPasswordLength before hashing on password verification endpoi...
  • 2fa501c fix(oauth-proxy): support social account linking (#11268)
  • 3d0efa3 feat(captcha): add Vercel BotID provider (#11016)
  • af88385 feat(admin): allow bannedUserMessage to be a function of the banned user (#11...
  • 2ee1545 fix(client): preserve auth query snapshots during hydration (#11316)
  • 0362d62 test(oauth): cover stateless implicit linking across instances (#11298)
  • See full diff in compare view

Updates dompurify from 3.4.15 to 3.4.16

Release notes

Sourced from dompurify's releases.

DOMPurify 3.4.16

  • Fixed a problem with IN_PLACE node removal when working with hooks, thanks @​manus-pi
  • Fixed a problem with IN_PLACE sanitization and raw-text roots, thanks @​h-t-m
  • Fixed a problem with ESM default exports landing in CommonJS declarations, thanks @​ssi02014
  • Migrated from rollup to rolldown because performance, thanks @​ssi02014
  • Bumped several dependencies where possible
Commits

Updates katex from 0.18.7 to 0.18.9

Release notes

Sourced from katex's releases.

v0.18.9

0.18.9 (2026-09-23)

Features

v0.18.8

0.18.8 (2026-09-23)

Bug Fixes

Changelog

Sourced from katex's changelog.

0.18.9 (2026-09-23)

Features

0.18.8 (2026-09-23)

Bug Fixes

Commits
  • 71a7bc0 chore(release): 0.18.9 [ci skip]
  • aafa187 feat(types): add contrib module declarations (#4250)
  • e749fd1 chore(release): 0.18.8 [ci skip]
  • ddfcc29 fix(array): preserve trailing rows in align (#4283)
  • 96e751c chore(deps): bump github/codeql-action from 4.38.0 to 4.38.1 (#4292)
  • 726c2d4 chore(deps): bump github/codeql-action from 4.37.9 to 4.38.0 (#4287)
  • f71045d chore(deps): update dependency js-yaml to v4.3.2 [security] (#4286)
  • See full diff in compare view

Updates lucide-react from 1.47.0 to 1.49.0

Release notes

Sourced from lucide-react's releases.

Version 1.49.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.48.0...1.49.0

Version 1.48.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.47.0...1.48.0

Commits
  • e042fec fix(packages): declare @types/react as an optional peer dependency (#4892)
  • f06ac67 chore(typchecking): More typecheck jobs for all packages (#4885)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the production-dependencies group with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [@ai-sdk/google](https://github.com/vercel/ai/tree/HEAD/packages/google) | `4.0.78` | `4.0.86` |
| [@ai-sdk/openai](https://github.com/vercel/ai/tree/HEAD/packages/openai) | `4.0.73` | `4.0.82` |
| [@ai-sdk/otel](https://github.com/vercel/ai/tree/HEAD/packages/otel) | `1.0.112` | `1.0.123` |
| [@better-auth/infra](https://github.com/better-auth/infrastructure/tree/HEAD/packages/infra) | `0.4.10` | `0.4.13` |
| [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `7.0.112` | `7.0.123` |
| [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) | `1.7.5` | `1.7.6` |
| [dompurify](https://github.com/cure53/DOMPurify) | `3.4.15` | `3.4.16` |
| [katex](https://github.com/KaTeX/KaTeX) | `0.18.7` | `0.18.9` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.47.0` | `1.49.0` |


Updates `@ai-sdk/google` from 4.0.78 to 4.0.86
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/packages/google/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/@ai-sdk/google@4.0.86/packages/google)

Updates `@ai-sdk/openai` from 4.0.73 to 4.0.82
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/packages/openai/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/@ai-sdk/openai@4.0.82/packages/openai)

Updates `@ai-sdk/otel` from 1.0.112 to 1.0.123
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/packages/otel/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/@ai-sdk/otel@1.0.123/packages/otel)

Updates `@better-auth/infra` from 0.4.10 to 0.4.13
- [Commits](https://github.com/better-auth/infrastructure/commits/HEAD/packages/infra)

Updates `ai` from 7.0.112 to 7.0.123
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/packages/ai/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/ai@7.0.123/packages/ai)

Updates `better-auth` from 1.7.5 to 1.7.6
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.6/packages/better-auth)

Updates `dompurify` from 3.4.15 to 3.4.16
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.15...3.4.16)

Updates `katex` from 0.18.7 to 0.18.9
- [Release notes](https://github.com/KaTeX/KaTeX/releases)
- [Changelog](https://github.com/KaTeX/KaTeX/blob/main/CHANGELOG.md)
- [Commits](KaTeX/KaTeX@v0.18.7...v0.18.9)

Updates `lucide-react` from 1.47.0 to 1.49.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.49.0/packages/lucide-react)

---
updated-dependencies:
- dependency-name: "@ai-sdk/google"
  dependency-version: 4.0.86
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@ai-sdk/openai"
  dependency-version: 4.0.82
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@ai-sdk/otel"
  dependency-version: 1.0.123
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@better-auth/infra"
  dependency-version: 0.4.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: ai
  dependency-version: 7.0.123
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: better-auth
  dependency-version: 1.7.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: dompurify
  dependency-version: 3.4.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: katex
  dependency-version: 0.18.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: lucide-react
  dependency-version: 1.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 3, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants