Skip to content

chore(deps): bump the minor-and-patch group with 4 updates - #85

Merged
Max Golovanov (maxgolov) merged 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-36a8ef9f69
Sep 14, 2026
Merged

Max Golovanov (maxgolov) merged 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-36a8ef9f69

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 4 updates: zod, @ai-sdk/azure, @types/node and ai.

Updates zod from 4.5.4 to 4.6.2

Release notes

Sourced from zod's releases.

v4.6.2

A patch on top of 4.6.1.

v4.6.1

A patch on top of 4.6.0.

v4.6.0

Zod 4.6 is now available.

npm install zod@latest

At a glance:

  • .validate() — checks input validity without building a result (up to 35x faster than .safeParse().success on a compiled schema)
  • z.instanceof().properties() — validates properties of an instance
  • fromJSONSchema() — enforces six validation keywords it used to ignore
  • z.iban() — electronic-format IBAN plus mod-97 checksum
  • z.withParser() — installs a parser generated elsewhere, for environments without new Function
  • Faster CommonJS — drops the getter on every export (~3x faster z.validate() under require)
  • Memory retention in recursive schemas — releases the parsed input, fixing a 4.5 out-of-memory regression
  • @zod/mini — Zod Mini as a standalone package, versioned in lockstep with zod since 4.5

.validate()

Standalone boolean validation, in Zod, Zod Mini, and Zod Core. It answers "is this input valid?" without constructing a ZodError, which makes rejection cheap. The return type is a guard on the schema's input type.

z.validate(z.string(), "hi"); // true
z.validate(z.string(), 42);   // false

It is a method on Zod Classic schemas too. (#6547)

const Player = z.object({
  username: z.string(),
  xp: z.number(),
});
</tr></table>

... (truncated)

Commits
  • e359f73 4.6.2
  • 9446b5c fix: preserve undefined prefault outputs and object keys (#6587)
  • 0c483c5 docs: Zod 4.6 announcement post (#6546)
  • a00c3f3 docs: use Trigger.dev's brand-kit lockups for the platinum card
  • 62311eb 4.6.1
  • 2efa8b8 ci: give the npm wait a real budget and drop the back-publish path (#6583)
  • b12aa52 fix: preserve unique tags with defaulted discriminators (#6582)
  • dd9c36f fix(v4): defer recursive object index inference (#6580)
  • 574d480 fix(locales): clarify Tajik discriminator value message
  • c532d76 test(locales): cover Tajik error branches
  • Additional commits viewable in compare view

Updates @ai-sdk/azure from 4.0.63 to 4.0.68

Release notes

Sourced from @​ai-sdk/azure's releases.

@​ai-sdk/openai@​4.0.66

Patch Changes

  • 5ec21a6: fix: reject unsupported batch request types
  • 7469a3b: feat: support image generation requests in batches
  • 0de8886: fix(openai): allow providers to disable web search source includes
  • d5e3024: fix(openai): remove propertyNames from JSON Schema
  • Updated dependencies [5ec21a6]
  • Updated dependencies [7469a3b]
  • Updated dependencies [813bb36]
  • Updated dependencies [c43e4b7]
    • @​ai-sdk/provider@​4.0.14
    • @​ai-sdk/provider-utils@​5.0.40
Changelog

Sourced from @​ai-sdk/azure's changelog.

4.0.68

Patch Changes

  • Updated dependencies [9942196]
  • Updated dependencies [9942196]
    • @​ai-sdk/provider@​4.0.13
    • @​ai-sdk/openai@​4.0.65
    • @​ai-sdk/deepseek@​3.0.42
    • @​ai-sdk/provider-utils@​5.0.39

4.0.67

Patch Changes

  • Updated dependencies [912fb01]
  • Updated dependencies [ccb8952]
    • @​ai-sdk/provider@​4.0.12
    • @​ai-sdk/openai@​4.0.64
    • @​ai-sdk/deepseek@​3.0.41
    • @​ai-sdk/provider-utils@​5.0.38

4.0.66

Patch Changes

  • 85db433: Include explicit message item types in Azure AI Foundry Responses requests.
  • Updated dependencies [85db433]
  • Updated dependencies [5fb2a64]
  • Updated dependencies [e105b2b]
  • Updated dependencies [45f2b6a]
    • @​ai-sdk/openai@​4.0.63

4.0.65

Patch Changes

  • Updated dependencies [8487955]
    • @​ai-sdk/openai@​4.0.62

4.0.64

Patch Changes

  • Updated dependencies [a4ba394]
  • Updated dependencies [45099da]
  • Updated dependencies [4a09793]
  • Updated dependencies [9e1d1b2]
  • Updated dependencies [a495511]
  • Updated dependencies [685ed8c]

... (truncated)

Commits

Updates @types/node from 26.4.1 to 26.5.1

Commits

Updates ai from 7.0.93 to 7.0.97

Changelog

Sourced from ai's changelog.

7.0.97

Patch Changes

  • ef3bac4: Observe video webhook receiver rejections before generation starts to prevent unhandled rejections during or after a failed start. Preserve start error precedence and assimilate custom receivers only once.
  • 9942196: feat: add batch cancel and list APIs
  • Updated dependencies [9942196]
    • @​ai-sdk/provider@​4.0.13
    • @​ai-sdk/gateway@​4.0.78
    • @​ai-sdk/provider-utils@​5.0.39

7.0.96

Patch Changes

  • 912fb01: feat: add batch cancel and list APIs
  • c595e6e: fix(ai): call atob without a receiver for Cloudflare Workers compatibility
  • Updated dependencies [912fb01]
  • Updated dependencies [aa4cc14]
  • Updated dependencies [f102e41]
    • @​ai-sdk/provider@​4.0.12
    • @​ai-sdk/gateway@​4.0.77
    • @​ai-sdk/provider-utils@​5.0.38

7.0.95

Patch Changes

  • 27f6d7a: fix(ai): reject embedding model responses that contain no embeddings

7.0.94

Patch Changes

  • a4ba394: feat: support per-request models in batch
  • 36b3364: fix(ai): enforce tool choices in streamText
  • 45099da: Retry unclassified empty image results, preserve retry-attempt accounting, add provider-independent result retryability classification, and mark Google and Google Vertex prompt blocks as terminal.
  • Updated dependencies [a4ba394]
  • Updated dependencies [e9bf5e3]
  • Updated dependencies [45099da]
  • Updated dependencies [56c004c]
  • Updated dependencies [9e1d1b2]
  • Updated dependencies [a495511]
    • @​ai-sdk/provider@​4.0.11
    • @​ai-sdk/gateway@​4.0.76
    • @​ai-sdk/provider-utils@​5.0.37
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-and-patch group with 4 updates: [zod](https://github.com/colinhacks/zod), [@ai-sdk/azure](https://github.com/vercel/ai/tree/HEAD/packages/azure), [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai).


Updates `zod` from 4.5.4 to 4.6.2
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.5.4...v4.6.2)

Updates `@ai-sdk/azure` from 4.0.63 to 4.0.68
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/packages/azure/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/@ai-sdk/azure@4.0.68/packages/azure)

Updates `@types/node` from 26.4.1 to 26.5.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `ai` from 7.0.93 to 7.0.97
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/packages/ai/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/ai@7.0.97/packages/ai)

---
updated-dependencies:
- dependency-name: zod
  dependency-version: 4.6.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@ai-sdk/azure"
  dependency-version: 4.0.68
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 26.5.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: ai
  dependency-version: 7.0.97
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 14, 2026
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 14, 2026
@github-actions

Copy link
Copy Markdown

⚠️ Deprecation Warning: The deny-licenses option is deprecated for possible removal in the next major release. For more information, see issue 997.

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/@ai-sdk/azure 4.0.68 UnknownUnknown
npm/@ai-sdk/deepseek 3.0.42 UnknownUnknown
npm/@ai-sdk/gateway 4.0.78 UnknownUnknown
npm/@ai-sdk/openai 4.0.65 UnknownUnknown
npm/@ai-sdk/provider 4.0.13 UnknownUnknown
npm/@ai-sdk/provider-utils 5.0.39 UnknownUnknown
npm/@types/node 26.5.1 🟢 6.5
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Packaging⚠️ -1packaging workflow not detected
Code-Review🟢 8Found 26/30 approved changesets -- score normalized to 8
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 10security policy file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 9license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing⚠️ 0project is not fuzzed
npm/ai 7.0.97 UnknownUnknown
npm/undici-types 8.9.0 🟢 7.8
Details
CheckScoreReason
Code-Review🟢 5Found 15/26 approved changesets -- score normalized to 5
Dependency-Update-Tool🟢 10update tool detected
Maintained🟢 1030 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
Security-Policy🟢 10security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 8binaries present in source code
License🟢 10license file detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 6dependency not pinned by hash detected -- score normalized to 6
Signed-Releases⚠️ -1no releases found
Vulnerabilities🟢 64 existing vulnerabilities detected
SAST🟢 10SAST tool is run on all commits
Packaging🟢 10packaging workflow detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Fuzzing🟢 10project is fuzzed
CI-Tests🟢 1019 out of 19 merged PRs checked by a CI test -- score normalized to 10
Contributors🟢 10project has 63 contributing companies or organizations
npm/zod 4.6.2 🟢 5.4
Details
CheckScoreReason
Security-Policy🟢 10security policy file detected
Code-Review⚠️ 0Found 1/28 approved changesets -- score normalized to 0
Maintained🟢 1030 commit(s) and 24 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 5dependency not pinned by hash detected -- score normalized to 5
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • package-lock.json

@maxgolov
Max Golovanov (maxgolov) merged commit 3acf586 into main Sep 14, 2026
9 checks passed
@maxgolov
Max Golovanov (maxgolov) deleted the dependabot/npm_and_yarn/minor-and-patch-36a8ef9f69 branch September 14, 2026 04:14
Max Golovanov (maxgolov) added a commit that referenced this pull request Sep 14, 2026
…dk/azure)

Lockfile regenerated on public npm (ai 7.0.99, zod 4.6.5, @types/node 26.5.1, @ai-sdk/azure 4.0.70), keeping sharp>=0.35.4 override + transformers/coverage-v8. Validated by CI build+unit tests; avoids downgrading main on merge. NOTE: this device's CFS proxy still lags these versions, so local npm ci needs the proxy to catch up; build/tests run on the already-installed modules.
Max Golovanov (maxgolov) added a commit that referenced this pull request Sep 15, 2026
…s, deps) (#89)

* feat(advisories): add date-range filtering for published/updated

- Add parseDateFilter + filterByDateRange to LocalRepositoryDataSource: single day (YYYY-MM-DD) and inclusive range (YYYY-MM-DD..YYYY-MM-DD) with validation for malformed/reversed ranges and array inputs

- Replace naive '>=' comparison that only supported open-ended dates

- Improve list_advisories schema descriptions (date format, examples, defaults)

- Add 14 unit tests covering parse/filter edge cases

Cleanly re-applies the feature from #25 onto current main (post-#76); supersedes that stale branch.

* fix(datasource): map ecosystem enum to OSV names so filtering works (#78)

list_advisories/search ecosystem filter used exact string match against OSV data, so only 'npm' matched; composer/pip/maven/rust/etc. silently returned 0.

- Add ECOSYSTEM_ALIASES (GitHub enum -> OSV name) + case-insensitive ecosystemMatches()

- Apply at both filter sites (listAdvisories + filterResults/search)

- Add unit tests for all 12 ecosystems; make e2e assertions real regression guards (drop vacuous length>0 guard, use ecosystemMatches instead of fragile [0]===name)

Fixes #78

* fix(datasource): normalize CWE filter input (#80)

cwes filter did options.cwes.includes(cwe.cwe_id) i.e. checked if bare input like '89' contains 'CWE-89' - always false. Documented bare-number form never matched.

- Add normalizeCwe() + cweFilterMatches(): accept bare (89) or prefixed (CWE-89), comma-separated and/or array, case-insensitive; match if any requested CWE is present

- Add unit tests (test/unit/cwe-filter.test.ts)

Fixes #80

* fix(tools): derive local API URL from ADVISORY_API_PORT (#81)

The MCP tools read ADVISORY_API_BASE (hardcoded :18005) while the server binds ADVISORY_API_PORT, so a custom API port broke every tool with 'fetch failed', and two servers collided on 18005 (serving each other's data - the source of the E2E flakiness).

- Derive base URL from ADVISORY_API_HOST/PORT; keep ADVISORY_API_BASE as override

- CI E2E now runs on a non-default API port (18055) to guard against regressions

Fixes #81

* chore(mcp): default advisory server to ADVISORY_API_PORT=18025

Distinct from the test defaults (18005/18006) so the dev MCP server and the test suite can run simultaneously without colliding. Relies on the tool port fix in this PR.

* feat(local): reviewed/unreviewed tier filter + web_app_only (session prototype)

* proto(semantic): local hybrid search (embeddings + BM25 + RRF + temporal rerank)

Local-only, advisory-specific prototype on branch proto/semantic-search. No external engine/service.

- Local ONNX embeddings via @huggingface/transformers (MiniLM 384-dim), offline (reuse a cached model dir)

- Compact Okapi BM25 with identifier-preserving tokenizer

- RRF fusion + field-aware rerank (exact GHSA/CVE/package/CWE/phrase boosts)

- Temporal-aware rerank: parse a period from the query, run recall on the residual text, boost by publish-date proximity (in-window 1.0, exp decay half-life 45d)

- File-backed index (embeddings.bin/bm25.json/docs.json/meta.json), CLI build+query. Not wired into MCP tools yet.

* proto(semantic): expose semantic_search MCP tool

Registers semantic_search in createAdvisoryServer (stdio + HTTP): hybrid local search with optional web_app_only/severity/ecosystem/cwes post-filters and temporal reranking. Returns build instructions if the index is absent.

* docs(semantic): design note on weekly index redistribution (git-lfs, CI feasibility)

Covers what/why to redistribute, git-lfs channel, cross-platform/ABI portability (LE + model pinning), and GitHub Actions scheduling feasibility (full rebuild ~borderline in 30m; incremental = seconds).

* docs(semantic): detailed design — tool, measured timing, git-lfs distribution, weekly refresh, sparse checkout

Covers the semantic_search tool + pipeline, empirical build/size numbers (35k in ~22m local; index ~96MB), git-lfs on a dedicated semantic-index branch, weekly scheduled refresh, and sparse-checkout/partial-clone recipes to avoid clone bloat.

* test(semantic): unit tests + coverage checks + hygiene

- 82 unit tests across bm25, temporal, document, store (save/load round-trip incl. embeddings byte-exactness), and hybrid (RRF + field/temporal rerank via injected query embedding — no model needed)

- Add @vitest/coverage-v8 + test:coverage script; per-file coverage thresholds for the deterministic semantic modules

- Hygiene: store index dir resolved at runtime (indexDir()) not import time; hybridSearch accepts an injectable query embedding for tests; drop unused import

* ci: run unit tests with coverage (enforces semantic thresholds)

* fix(deps): keep package.json in sync with lockfile (feed-available versions)

* docs: add AGENTS.md and refresh stale docs (hygiene)

- Add root AGENTS.md: build/bootstrap/run/test contract for agents (generic, no internal infra)

- CONTRIBUTING: Node 20+, branch from main (no dev branch), unit-test command

- README: correct advisory counts (~370K/~35K), CI Node matrix 20.x/22.x, main-only triggers, drop stale CI notes

* docs+chore: trim README, gate integration tests, tidy semantic docs

- Move raw REST/MCP JSON-RPC recipes to docs/http-api.md and orchestrator/rate-limit examples to docs/integration.md; README 428->341 lines (M2)

- Scope 'npm test' to unit; add test:all; skip Azure integration suite via describe.skipIf when AZURE_OPENAI_ENDPOINT unset (M3)

- src/semantic/README.md: scope to how-to-run and link canonical docs/semantic-search-design.md; fix stale 'not wired in' note (M4)

* fix(deps): force sharp>=0.35.4 to clear transitive advisories

@huggingface/transformers pins a vulnerable sharp ^0.34.1; add an overrides entry (sharp>=0.35.4) to resolve GHSA-rgj7-g3m4-5g8c (libheif) and GHSA-f88m-g3jw-g9cj (libvips). npm audit: 0 vulnerabilities. Rationale documented in src/semantic/embeddings.ts (our usage is text-only).

* chore(deps): resolve to main's #85 versions (ai/zod/@types/node/@ai-sdk/azure)

Lockfile regenerated on public npm (ai 7.0.99, zod 4.6.5, @types/node 26.5.1, @ai-sdk/azure 4.0.70), keeping sharp>=0.35.4 override + transformers/coverage-v8. Validated by CI build+unit tests; avoids downgrading main on merge. NOTE: this device's CFS proxy still lags these versions, so local npm ci needs the proxy to catch up; build/tests run on the already-installed modules.

* ci(semantic): weekly index refresh -> rolling Release asset

Adds .github/workflows/semantic-index.yml: weekly (cron 0 6 * * 1) + manual rebuild of the reviewed-tier index, published as the rolling 'semantic-index-latest' Release asset (~100 MB/week). Release (not LFS-to-main) because main is protected; keeps the blob off clones. Docs updated with consumer steps.

* ci(semantic): manual maintainer-gated index build -> artifact (no schedule/release yet)

workflow_dispatch only; authorize job restricts to admin/maintain; uploads .semantic-index as a downloadable artifact (contents: read, no repo write, no Release). Weekly schedule + distribution deferred and documented. Addresses: run on demand, download as artifact without releasing, and maintainer-only trigger.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant