fix(deps): update all non-major dependencies (patch) - #2786
shunkakinoki wants to merge 1 commit into
Conversation
|
Warning This organization's free trial has ended, so Indent couldn't start this review. Manage billing to resume reviews on this repository. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 SummarySummary by CodeRabbit
WalkthroughThe pull request updates JavaScript dependency ranges in ChangesDependency Updates
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Other Merge Risk: ⚪ Minimal · up to This change updates dependency versions without an evidenced merge-blocking production impact and is ready to merge with normal checks. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks each version line Comment |
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes: This PR updates all non-major dependencies to their next patch/minor versions (as indicated by the title fix(deps): update all non-major dependencies (patch)). Changes are limited to 3 files:
package.json/bun.lock— 11 dependency version bumps (@anthropic-ai/claude-code,@oh-my-pi/pi-coding-agent,@oh-my-pi/pi-natives,@upstash/context7-mcp)pyproject.toml—graphifyy>=0.9.56 → >=0.9.57
All updates are within the same major version and include legitimate bug fixes and minor improvements per their release notes. No behavioral code changes or breaking changes are introduced.
openrouter/openrouter/free | 𝕏
a65c687 to
601a089
Compare
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes: Since the prior pullfrog review at a65c687, the following dependency updates were made across 3 files:
@anthropic-ai/claude-code+ platform variants:^2.1.267 → ^2.1.268@biomejs/biome:^2.5.12 → ^2.5.13@oh-my-pi/pi-coding-agent+@oh-my-pi/pi-natives:^18.1.16 → ^18.1.17@traces-sh/traces:^0.6.27 → ^0.6.28mcp-remote:^0.8.6 → ^0.8.7graphifyy:>=0.9.57 → >=0.9.58- New dependencies added:
@deepseek-ai/dsh,@earendil-works/pi-coding-agent,@sentry/cli,mistral-vibe,nvitop,ruff,serena-agent,transformers,vllm
All updates are within the same major version and include legitimate bug fixes and minor improvements per their release notes. No behavioral code changes or breaking changes are introduced.
openrouter/openrouter/free | 𝕏
601a089 to
7b7ab48
Compare
There was a problem hiding this comment.
Reviewed changes
- Updated @anthropic-ai/claude-code from ^2.1.266 to ^2.1.269 (multiple platforms)
- Updated @biomejs/biome from ^2.5.12 to ^2.5.13 (Linux variants)
- Updated @oh-my-pi/pi-coding-agent and @oh-my-pi/pi-natives from ^18.1.15 to ^18.1.18 (multiple platforms)
- Updated @posthog/cli from ^0.18.1 to ^0.18.2
- Updated @pulumi/pulumi to ^3.261.0
- Updated @railway/cli from ^5.49.6
- Updated @redwoodjs/agent-ci from ^0.18.1
- Updated @openai/codex from ^0.153.4
- Updated @pkieltyka/gitgenie from ^0.1.2
- Updated @MCP-Remote from ^0.8.5 to ^0.8.7
- Updated @mcporter from ^0.13.10 to ^0.13.12
- Updated @openclaw from ^2026.9.3 to ^2026.9.4
- Updated @oxfmt from ^0.67.0
- Updated @oxlint from ^1.82.0
- Updated @pinchtab from ^0.15.2
- Updated @traces-sh/traces from ^0.6.27 to ^0.6.28
- Updated @upstash/context7-mcp from ^4.0.6 to ^4.0.7
All changes are patch-level dependency updates that maintain backward compatibility while incorporating security patches and bug fixes.
openrouter/openrouter/free | 𝕏
2d7cb2c to
0465035
Compare
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes:
- Updated non-major dependencies across 3 files (
package.json,pyproject.toml) with patch-level version bumps - Added new dependencies:
@deepseek-ai/dsh,@earendil-works/pi-coding-agent,@sentry/cli,mistral-vibe,nvitop,serena-agent,transformers,vllm - All changes are within the same major version (patch/minor bumps) and do not introduce behavioral code changes
- Previous Pullfrog reviews (4) all approved with "No issues found"
Summary:
The PR performs standard dependency maintenance by updating non-major dependencies to their latest patch versions and adding a few new utility dependencies. No functional code changes are introduced.
openrouter/openrouter/free | 𝕏
0465035 to
e43c44e
Compare
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes: Since the prior pullfrog review at 0465035b (review #5273877783), this force-push updated non-major dependencies across 3 files with the following additional version bumps:
@anthropic-ai/claude-code+ all platform variants:^2.1.269 → ^2.1.273(lockfile resolves to2.1.280)@oh-my-pi/pi-coding-agent+@oh-my-pi/pi-natives:^18.1.18 → ^18.1.22(lockfile@oh-my-pi/*family18.1.20 → 18.2.10)@mcporter:^0.13.12 → ^0.13.13,@traces-sh/traces:^0.6.28 → ^0.6.29graphifyy:>=0.9.58 → >=0.9.62turbo:^2.10.13 → ^2.11.3(lockfile2.10.12 → 2.11.3)cline:^3.0.61 → ^3.0.62(lockfile3.0.61 → 3.0.64, internal@cline/*packages0.0.82 → 0.0.85)- Lockfile-only bumps:
@biomejs/biome2.5.13 → 2.5.14,@posthog/cli0.18.2 → 0.18.3 zodtransitive bumps in@cline/core,@cline/llms,@cline/shared:4.5.4 → 4.6.5- New lockfile entries:
@langfuse/otel/@langfuse/core,@langfuse/tracing/@langfuse/core,@langfuse/vercel-ai-sdk/@langfuse/coreat@langfuse/core@5.11.0;axe-core@4.13.0added as@oh-my-pi/pi-coding-agentdependency
All updates remain within declared semver ranges (patch/minor within the same major version). No behavioral code changes are introduced. All 5 prior pullfrog reviews approved with "No issues found."
openrouter/openrouter/free | 𝕏
e43c44e to
26f3030
Compare
There was a problem hiding this comment.
Reviewed changes
This PR updates non-major dependencies to their latest patch versions across multiple files. All changes are within the same major version ranges and represent safe, backward-compatible updates. No behavioral code changes are introduced.
Summary of updated packages:
@anthropic-ai/claude-code+ platform variants:^2.1.266 → ^2.1.274@biomejs/biome:^2.5.12 → ^2.5.14@oh-my-pi/pi-coding-agent+@oh-my-pi/pi-natives:^18.1.15 → ^18.1.22@posthog/cli:^0.18.1 → ^0.18.5@pulumi/pulumi:^3.261.0@railway/cli:^5.49.6@redwoodjs/agent-ci:^0.18.1@openai/codex:^0.153.4@pkieltyka/gitgenie:^0.1.2@mcporter:^0.13.10 → ^0.13.13@traces-sh/traces:^0.6.27 → ^0.6.29@upstash/context7-mcp:^4.0.6 → ^4.0.7graphifyy:>=0.9.56 → >=0.9.63ruff:>=0.16.6 → >=0.16.8turbo:^2.10.12 → ^2.11.3cline:^3.0.61 → ^3.0.64@github/copilot:^1.0.83 → ^1.0.88@higgsfield/cli:^1.1.24 → ^1.1.26vite-plus:^0.3.1 → ^0.3.2mcp-remote:^0.8.5 → ^0.8.7
All prior reviews (5) have approved with "No issues found". The changes are patch-level dependency updates that maintain backward compatibility.
openrouter/openrouter/free | 𝕏

This PR contains the following updates:
^2.1.266→^2.1.274^2.1.266→^2.1.274^2.1.266→^2.1.274^2.1.266→^2.1.274^2.1.266→^2.1.274^2.1.266→^2.1.274^2.1.266→^2.1.274^2.1.266→^2.1.274^2.1.266→^2.1.274^2.5.12→^2.5.14^1.0.83→^1.0.85^1.1.24→^1.1.25^18.1.15→^18.1.22^18.1.15→^18.1.22^0.18.1→^0.18.3^0.6.27→^0.6.29^4.0.6→^4.0.7^3.0.61→^3.0.62>=0.9.56→>=0.9.63^0.8.5→^0.8.7^0.13.10→^0.13.13>=0.16.6→>=0.16.8^2.10.12→^2.10.13^0.3.1→^0.3.2Release Notes
anthropics/claude-code (@anthropic-ai/claude-code)
v2.1.274Compare Source
CLAUDE_CODE_MCP_STARTUP_WAIT_MSto bound how long the first non-interactive turn waits for connecting MCP servers (0= don't wait)effortattribute to theclaude_code.llm_requestOpenTelemetry trace span, matching theapi_requesteventclaude_code.managed_settings_resolvedOTel event: managed-settings sources and policy helper state; redacted settings and digests withOTEL_LOG_MANAGED_SETTINGS=1store.connect_timeout_secondsto the Claude apps gateway config to lengthen the Postgres connect timeout (default 5 seconds), and improved the boot error when the database is unreachable to point tostore.postgres_urland the configured timeoutenduser.sub, the IdP subject, to the telemetry Claude Desktop and Cowork send through a Claude apps gateway/rewindhint) ends the loophttpthat only speak legacy HTTP+SSE failing to connect when they answer the first request with 422 or another 4xx errortimeoutwas setlistChanged/mcpre-authentication/goal) ending with "Prompt is too long" instead of compacting when the context overflowed again after a reactive compaction/goalbeing lost when resuming (--continue/--resume) a session that had compactedclaude agentslosing--model,--effort,--permission-mode,--allow-dangerously-skip-permissionsand--agentafter an auto-update relaunchmodel: "opus"on Bedrock, Vertex or Foundry leaving the session's model when its id has no recognizable model family (unlessANTHROPIC_DEFAULT_OPUS_MODELis set)file://URIclaude -p --resumestarted withCLAUDE_CODE_RESUME_INTERRUPTED_TURNnot reporting background tasks the previous process left unfinished/usage-creditsinstead of CLI flags that cannot be used there/schedulesaving a routine's prompt without its message role when Claude writes the routine in the shape that listing routines returns/statusnot showing theapiKeyHelperfailure that its own error banner told you to check/fast onin non-interactive sessions reporting on and then turning off under an organization's managed fast mode policy; it now says the organization has disabled it~/.claude--strict-mcp-configwith an empty--mcp-configholding the first non-interactive turn for up toMCP_TIMEOUTon incidental MCP serversCLAUDE_GATEWAY_DRAIN_TIMEOUT_MS)installed_plugins.jsonbeing rewritten on nearly every start-up when plugin policy comes from remote managed settings, which made Claude Desktop reload every open session's pluginsbin/directories changed$schemainhooks/hooks.jsonshowing an "unknown key" notice${VAR}placeholders in MCP configs.zipbeing served from a stale extraction after several overlapping reloads--input-format stream-jsonsessions: the first turn no longer waits up to 2s for still-connecting MCP servers whose tools tool search defers; they arrive on a later turnOTEL_LOG_RAW_API_BODIES=file:<dir>output: a newindex.jsonlandrequest_body_id/message.idevent attributes link each response to its request file and transcript message/loginnow explains the refusal, and the gateway log says which limit was hit and which setting to changeMCP_SDK_GENERATION=v1orMCP_PROTOCOL_NEGOTIATION=legacy)/code-reviewto use leaner inline review prompts for every model that has no tuned settings of its own, instead of spawning many review subagents"type": "sdk"MCP entries in.mcp.json, settings, plugins and agent files to be skipped with a warning: only an SDK host application can register in-process serversgit lfs pullin the checkout fetches them/statusGitHub line to read "Cloud sessions", and/web-setup,/ultrareview, and teleport messages to say "cloud session" instead of "Claude Code on the web"claudeCode.lockEditorGroupssetting to stop Claude from locking the editor groups it opens in/btwside question asked in a new conversation's first seconds occasionally showing another session's side-question historyCLAUDE_CONFIG_DIRchanged in the Environment Variables setting~/.claude/settings.jsonunparseable or dropping a setting$XDG_CONFIG_HOME/git/ignorewhenXDG_CONFIG_HOMEis an absolute pathmailto:prefix; they now show as the plain, clickable addressv2.1.273Compare Source
x-claude-code-request-class,x-claude-code-agent-type,x-claude-code-prev-tool-durations,x-claude-code-compactionandx-claude-code-context-compactedrequest headers for LLM gateways; opt in withCLAUDE_CODE_GATEWAY_HINT_HEADERS=1/mcpclaude --remote-controlor/remote-controlfrom the Claude app; the fork runs as a background session on your computerpermissions.blockReadsOutsideWorkingDirectories, and a subshell hiding a dangerousrmin bypass modeallowManagedMcpServersOnly,deniedMcpServersanddisableClaudeAiConnectorsset via MDM ormanaged-settings.jsonbeing ignored when server-managed settings are also present/login; the message now names the credential to refresh or points to your gateway administrator/login,/upgrade, and/extra-usagediscarding earlier thinking from the conversation, which forced a full prompt-cache rewrite on the next request.git/info/excludeafter the repository's.gitdirectory was removed or moved away!typed at the start while already in shell mode, so negated commands like! grep …can be typedpermissions.blockReadsOutsideWorkingDirectories: a memory directory chosen by a repository's settings is no longer loaded into the prompt, recalled, indexed, or used by memory extraction/tuirefusing to restart because of an agent-team teammate that had already finished its work and was no longer shown in the agents panel.claude/scheduled_tasks.jsonwas copied into another folder, such as a new worktree--output-format stream-jsonoutput dropping a subagent's remaining messages and final report after it is moved to the background mid-run (e.g. byCLAUDE_AUTO_BACKGROUND_TASKS)/install-github-appreporting a SAML single sign-on block as "admin permissions required"eval,env -C); commands liketime -p make buildprompt again instead of being denied/autofix-pr: whengh pr viewfails it now shows gh's own error (sign-in, SAML, rate limit) instead of a generic exit-code line/autofix-prto say why GitHub webhook delivery couldn't be set up for the PR (for example, no linked GitHub account) instead of a generic warning/web-setuperrors: a refused GitHub token now lists the likely reasons and the fix, and a connection failure names a configured proxy or TLS certificate problemNODE_EXTRA_CA_CERTSfor an untrusted corporate CA/login/mcp)CLAUDE_CODE_AUTO_MODE_SERVER=1to use the platform's server-side classifierOTEL_LOG_TOOL_DETAILS=1to also include real agent, skill, plugin and MCP server names on cost and token metrics/bugand/feedbackreports to include only model-behavior params (model, system prompt, tools) from the last API request, omitting request metadata andCLAUDE_CODE_EXTRA_BODYfields/bug//feedbackopening a report form, for organizations that have product feedback disabled4294967" banner appearing after completed turns on Windows--add-dir/ultrareview --postso a retry after a GitHub error posts the findings comment exactly once instead of never or twice; the comment now names the reviewed commitv2.1.272Compare Source
v2.1.271Compare Source
/fasttyped in the session applies where your organization allows it/configpanel in fullscreen mode: the wheel scrolls the settings list, a click on a setting's value changes it, and the row under the pointer is highlightedclaude self-hosted-runner --drain-marker-file <path>: when that file exists at a SIGTERM drain, the runner reports its exit to the server as a host drain (telemetry only)allowed_domainsto Bash, PowerShell and Monitor in auto mode with sandboxing: the hosts a command needs are reviewed with it and opened for it alone; other hosts are refusedomitClaudeMdto agent frontmatter and--agentsJSON, letting custom and plugin subagents run without user, project and local CLAUDE.md files; managed policy files still load--accept-command <sha256>toclaude plugin installandclaude plugin updateto accept exactly the command a previous--jsonrun displayed, instead of-ymultiplierabove 1, up to 10, in themodelPricingmanaged setting and the Claude apps gatewaypricingblock, for marked-up internal chargeback rates/desktop, which offers to download the appmanaged-mcp.jsonthat can't be read or parsed being ignored: it now keeps exclusive MCP control (user, project and plugin servers don't load) and warns at startupANTHROPIC_UNIX_SOCKET; they are again treated like other custom gateways, including for Remote Control/fast offanswering "Fast mode unavailable" instead of turning fast mode off when the organization has fast mode disabledCLAUDE_CODE_SKIP_FAST_MODE_ORG_CHECKre-sending fast requests every turn after the API rejected fast mode; the rejection now stands and its reason is shownCLAUDE_CODE_RETRY_WATCHDOGfailing the turn on a usage-credits limit, or retrying an overload at fast speed, instead of falling back to standard speedfmt,columnand similar commands read when it follows an option the checker doesn't recognizegrep -v dir/* file)cd+gitchain skipping the prompt underpermissions.blockReadsOutsideWorkingDirectoriesin bypass and auto mode.git/config.lockbreakinggit checkout -b,git push -uandgit configfor the rest of a session after a sandboxed command failed to start (Linux)claude -psessions whose tools all come from MCP servers failing with "At least one tool must have defer_loading=false"text/plainlist_changednotifications in a tight loopmcp__server__toolname/mcpsent from Remote Control failing while the transcript view is openSendMessageresults no longer imply it was read/modelwarning about losing the conversation cache when switching back to the model the conversation actually ran on/reload-skillsreporting a skill count that disagreed with the slash menu after/cd/resumeand/continueshowing only 1-2 sessions in fullscreen mode on short terminals/resumeand/teleportkeeping the previous conversation's file-read tracking, so Claude could edit files the resumed conversation had never read--resumedropping the 1M context window ([1m]) when the resumed session's model family differs from the configured default model/artifactsdisappearing from the session after--resumeclaude --bg,claude agents) not watching the artifacts they publish for republishes made elsewhere--host-config-snapshot disk|memorycleanupPeriodDaysnow move to the recoverable trash at the next launch/add-dirpath input: the left and right arrow keys now move the cursor, and Enter adds only the typed path instead of also adding the highlighted completion!to the end of what you typed (!foocame out asfoo!)/hooksmenu crashing when a hook matcher is named after an inherited object property such as__proto__orconstructor^[[?1;2c) appearing at the shell prompt or in an editor when Claude Code exits, is suspended, or opens an editor right after startingclaude mcp serve: a running tool call now sends a progress update every 30 seconds, so clients show it is still running and idle timeouts don't abort a long command that prints nothingalwaysLoadMCP server that finishes connecting mid-conversation is usable on the next turn without a tool-search round trip/mobileto show a single QR code for claude.ai/mobile, which opens the right app store for your phone!shell commands follow default-mode permission rules instead of the classifier; a command no rule decides runs as a reviewed tool call-pruns) and notify Claude to re-arm, replacing the no-timeoutpersistentoption[⧉ …]pill that wraps with the text instead of squeezing multi-line prompts; delete it with Backspace to leave the selection outclaude-apiskill to enableeager_input_streamingon streaming custom tools, and to start deliverable-shaped Managed Agents work withuser.define_outcomeCLAUDE_CONFIG_DIRchanged in theenvironmentVariablessettingv2.1.270Compare Source
v2.1.269Compare Source
claude plugin eval: run a plugin's eval suite against Claude Code and get scored, reproducible results (JSON + HTML report); seeclaude plugin eval --help/output-style [name]to list and switch output styles, including over Remote Control and in cloud and other headless sessionsbashEditDiffEnabled)OTEL_METRICS_INCLUDE_REPOSITORYto tag OpenTelemetry metrics and events withvcs.*repository attributes; commit events getvcs.ref.head.*withOTEL_LOG_TOOL_DETAILSCLAUDE_CODE_GATEWAY_MODEL_DISCOVERY_TIMEOUT_MSto extend the LLM gateway/v1/modelsdiscovery timeout (default 3s)/focusfor a view with just your prompt, a one-line work summary, and the responseCLAUDE_CODE_WORKFLOW_MAX_CONCURRENT_AGENTS(1–256) to raise the Workflow tool's per-run concurrent agent limit for inference-bound fan-outsCLAUDE_CODE_BG_TASKS_REPORT_RUNNING=0to restore the old behavior)^[[?1;2c) appearing as stray text at startup in some terminals!applying beyond the settings source that wrote it; such a rule now applies only within its own source, and a bare!negation is ignoredheadersHelperconsent prompts showing a URL path that could be misread as a different host[redacted URL]in place of a relative Windows path with a folder name that starts with@/forkreceipt, each under a second apart, never backgrounding the sessiConfiguration
📅 Schedule: (in timezone UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.