chore(deps): bump the minor-and-patch group with 4 updates - #85
Merged
Max Golovanov (maxgolov) merged 1 commit intoSep 14, 2026
Merged
Max Golovanov (maxgolov) merged 1 commit into
Max Golovanov (maxgolov) merged 1 commit into
Conversation
Bumps the minor-and-patch group with 4 updates: [zod](https://github.com/colinhacks/zod), [@ai-sdk/azure](https://github.com/vercel/ai/tree/HEAD/packages/azure), [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai). Updates `zod` from 4.5.4 to 4.6.2 - [Release notes](https://github.com/colinhacks/zod/releases) - [Commits](colinhacks/zod@v4.5.4...v4.6.2) Updates `@ai-sdk/azure` from 4.0.63 to 4.0.68 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/main/packages/azure/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/azure@4.0.68/packages/azure) Updates `@types/node` from 26.4.1 to 26.5.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `ai` from 7.0.93 to 7.0.97 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/main/packages/ai/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/ai@7.0.97/packages/ai) --- updated-dependencies: - dependency-name: zod dependency-version: 4.6.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@ai-sdk/azure" dependency-version: 4.0.68 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@types/node" dependency-version: 26.5.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: ai dependency-version: 7.0.97 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
requested a review
from Max Golovanov (maxgolov)
as a code owner
September 14, 2026 03:25
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
Max Golovanov (maxgolov)
deleted the
dependabot/npm_and_yarn/minor-and-patch-36a8ef9f69
branch
September 14, 2026 04:14
Max Golovanov (maxgolov)
added a commit
that referenced
this pull request
Sep 14, 2026
…dk/azure) Lockfile regenerated on public npm (ai 7.0.99, zod 4.6.5, @types/node 26.5.1, @ai-sdk/azure 4.0.70), keeping sharp>=0.35.4 override + transformers/coverage-v8. Validated by CI build+unit tests; avoids downgrading main on merge. NOTE: this device's CFS proxy still lags these versions, so local npm ci needs the proxy to catch up; build/tests run on the already-installed modules.
Max Golovanov (maxgolov)
added a commit
that referenced
this pull request
Sep 15, 2026
…s, deps) (#89) * feat(advisories): add date-range filtering for published/updated - Add parseDateFilter + filterByDateRange to LocalRepositoryDataSource: single day (YYYY-MM-DD) and inclusive range (YYYY-MM-DD..YYYY-MM-DD) with validation for malformed/reversed ranges and array inputs - Replace naive '>=' comparison that only supported open-ended dates - Improve list_advisories schema descriptions (date format, examples, defaults) - Add 14 unit tests covering parse/filter edge cases Cleanly re-applies the feature from #25 onto current main (post-#76); supersedes that stale branch. * fix(datasource): map ecosystem enum to OSV names so filtering works (#78) list_advisories/search ecosystem filter used exact string match against OSV data, so only 'npm' matched; composer/pip/maven/rust/etc. silently returned 0. - Add ECOSYSTEM_ALIASES (GitHub enum -> OSV name) + case-insensitive ecosystemMatches() - Apply at both filter sites (listAdvisories + filterResults/search) - Add unit tests for all 12 ecosystems; make e2e assertions real regression guards (drop vacuous length>0 guard, use ecosystemMatches instead of fragile [0]===name) Fixes #78 * fix(datasource): normalize CWE filter input (#80) cwes filter did options.cwes.includes(cwe.cwe_id) i.e. checked if bare input like '89' contains 'CWE-89' - always false. Documented bare-number form never matched. - Add normalizeCwe() + cweFilterMatches(): accept bare (89) or prefixed (CWE-89), comma-separated and/or array, case-insensitive; match if any requested CWE is present - Add unit tests (test/unit/cwe-filter.test.ts) Fixes #80 * fix(tools): derive local API URL from ADVISORY_API_PORT (#81) The MCP tools read ADVISORY_API_BASE (hardcoded :18005) while the server binds ADVISORY_API_PORT, so a custom API port broke every tool with 'fetch failed', and two servers collided on 18005 (serving each other's data - the source of the E2E flakiness). - Derive base URL from ADVISORY_API_HOST/PORT; keep ADVISORY_API_BASE as override - CI E2E now runs on a non-default API port (18055) to guard against regressions Fixes #81 * chore(mcp): default advisory server to ADVISORY_API_PORT=18025 Distinct from the test defaults (18005/18006) so the dev MCP server and the test suite can run simultaneously without colliding. Relies on the tool port fix in this PR. * feat(local): reviewed/unreviewed tier filter + web_app_only (session prototype) * proto(semantic): local hybrid search (embeddings + BM25 + RRF + temporal rerank) Local-only, advisory-specific prototype on branch proto/semantic-search. No external engine/service. - Local ONNX embeddings via @huggingface/transformers (MiniLM 384-dim), offline (reuse a cached model dir) - Compact Okapi BM25 with identifier-preserving tokenizer - RRF fusion + field-aware rerank (exact GHSA/CVE/package/CWE/phrase boosts) - Temporal-aware rerank: parse a period from the query, run recall on the residual text, boost by publish-date proximity (in-window 1.0, exp decay half-life 45d) - File-backed index (embeddings.bin/bm25.json/docs.json/meta.json), CLI build+query. Not wired into MCP tools yet. * proto(semantic): expose semantic_search MCP tool Registers semantic_search in createAdvisoryServer (stdio + HTTP): hybrid local search with optional web_app_only/severity/ecosystem/cwes post-filters and temporal reranking. Returns build instructions if the index is absent. * docs(semantic): design note on weekly index redistribution (git-lfs, CI feasibility) Covers what/why to redistribute, git-lfs channel, cross-platform/ABI portability (LE + model pinning), and GitHub Actions scheduling feasibility (full rebuild ~borderline in 30m; incremental = seconds). * docs(semantic): detailed design — tool, measured timing, git-lfs distribution, weekly refresh, sparse checkout Covers the semantic_search tool + pipeline, empirical build/size numbers (35k in ~22m local; index ~96MB), git-lfs on a dedicated semantic-index branch, weekly scheduled refresh, and sparse-checkout/partial-clone recipes to avoid clone bloat. * test(semantic): unit tests + coverage checks + hygiene - 82 unit tests across bm25, temporal, document, store (save/load round-trip incl. embeddings byte-exactness), and hybrid (RRF + field/temporal rerank via injected query embedding — no model needed) - Add @vitest/coverage-v8 + test:coverage script; per-file coverage thresholds for the deterministic semantic modules - Hygiene: store index dir resolved at runtime (indexDir()) not import time; hybridSearch accepts an injectable query embedding for tests; drop unused import * ci: run unit tests with coverage (enforces semantic thresholds) * fix(deps): keep package.json in sync with lockfile (feed-available versions) * docs: add AGENTS.md and refresh stale docs (hygiene) - Add root AGENTS.md: build/bootstrap/run/test contract for agents (generic, no internal infra) - CONTRIBUTING: Node 20+, branch from main (no dev branch), unit-test command - README: correct advisory counts (~370K/~35K), CI Node matrix 20.x/22.x, main-only triggers, drop stale CI notes * docs+chore: trim README, gate integration tests, tidy semantic docs - Move raw REST/MCP JSON-RPC recipes to docs/http-api.md and orchestrator/rate-limit examples to docs/integration.md; README 428->341 lines (M2) - Scope 'npm test' to unit; add test:all; skip Azure integration suite via describe.skipIf when AZURE_OPENAI_ENDPOINT unset (M3) - src/semantic/README.md: scope to how-to-run and link canonical docs/semantic-search-design.md; fix stale 'not wired in' note (M4) * fix(deps): force sharp>=0.35.4 to clear transitive advisories @huggingface/transformers pins a vulnerable sharp ^0.34.1; add an overrides entry (sharp>=0.35.4) to resolve GHSA-rgj7-g3m4-5g8c (libheif) and GHSA-f88m-g3jw-g9cj (libvips). npm audit: 0 vulnerabilities. Rationale documented in src/semantic/embeddings.ts (our usage is text-only). * chore(deps): resolve to main's #85 versions (ai/zod/@types/node/@ai-sdk/azure) Lockfile regenerated on public npm (ai 7.0.99, zod 4.6.5, @types/node 26.5.1, @ai-sdk/azure 4.0.70), keeping sharp>=0.35.4 override + transformers/coverage-v8. Validated by CI build+unit tests; avoids downgrading main on merge. NOTE: this device's CFS proxy still lags these versions, so local npm ci needs the proxy to catch up; build/tests run on the already-installed modules. * ci(semantic): weekly index refresh -> rolling Release asset Adds .github/workflows/semantic-index.yml: weekly (cron 0 6 * * 1) + manual rebuild of the reviewed-tier index, published as the rolling 'semantic-index-latest' Release asset (~100 MB/week). Release (not LFS-to-main) because main is protected; keeps the blob off clones. Docs updated with consumer steps. * ci(semantic): manual maintainer-gated index build -> artifact (no schedule/release yet) workflow_dispatch only; authorize job restricts to admin/maintain; uploads .semantic-index as a downloadable artifact (contents: read, no repo write, no Release). Weekly schedule + distribution deferred and documented. Addresses: run on demand, download as artifact without releasing, and maintainer-only trigger.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the minor-and-patch group with 4 updates: zod, @ai-sdk/azure, @types/node and ai.
Updates
zodfrom 4.5.4 to 4.6.2Release notes
Sourced from zod's releases.
... (truncated)
Commits
e359f734.6.29446b5cfix: preserve undefined prefault outputs and object keys (#6587)0c483c5docs: Zod 4.6 announcement post (#6546)a00c3f3docs: use Trigger.dev's brand-kit lockups for the platinum card62311eb4.6.12efa8b8ci: give the npm wait a real budget and drop the back-publish path (#6583)b12aa52fix: preserve unique tags with defaulted discriminators (#6582)dd9c36ffix(v4): defer recursive object index inference (#6580)574d480fix(locales): clarify Tajik discriminator value messagec532d76test(locales): cover Tajik error branchesUpdates
@ai-sdk/azurefrom 4.0.63 to 4.0.68Release notes
Sourced from @ai-sdk/azure's releases.
Changelog
Sourced from @ai-sdk/azure's changelog.
... (truncated)
Commits
e9795abVersion Packages (#20555)65eb52bVersion Packages (#20524)b7670d9Version Packages (#20486)85db433fix(azure): include explicit message types for Foundry Responses (#20487)db450a2Version Packages (#20476)b3b74c8Version Packages (#20455)Updates
@types/nodefrom 26.4.1 to 26.5.1Commits
Updates
aifrom 7.0.93 to 7.0.97Changelog
Sourced from ai's changelog.
Commits
e9795abVersion Packages (#20555)ef3bac4fix: forward video callback URLs for caller-managed receivers (#20561)65eb52bVersion Packages (#20524)912fb01feat: add batch cancel and list APIs (#20543)c595e6efix(ai): call atob without a receiver (#20541)b7670d9Version Packages (#20486)27f6d7afix: reject empty embedding model responses instead of returning undefined (#...b3b74c8Version Packages (#20455)45099dafix: generateImage maxRetries skips transient empty image results (#20170)a4ba394feat: support per-request models in batch (#20138)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions