Skip to content

Bump the npm_and_yarn group across 8 directories with 8 updates - #63

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-37aff0ec63
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-37aff0ec63

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps the npm_and_yarn group with 4 updates in the / directory: @anthropic-ai/sdk, undici, braces and ip-address.
Bumps the npm_and_yarn group with 1 update in the /build/npm/gyp directory: ip-address.
Bumps the npm_and_yarn group with 5 updates in the /extensions/copilot directory:

Package From To
@anthropic-ai/sdk 0.82.0 0.91.1
undici 7.29.0 7.30.0
uuid 8.3.2 removed
ip-address 10.5.0 10.7.2
@opentelemetry/core 1.30.1 2.11.0

Bumps the npm_and_yarn group with 2 updates in the /extensions/copilot/chat-lib directory: undici and @opentelemetry/core.
Bumps the npm_and_yarn group with 1 update in the /extensions/copilot/test/simulation/fixtures/generate/issue-6163 directory: esbuild.
Bumps the npm_and_yarn group with 2 updates in the /remote directory: undici and ip-address.
Bumps the npm_and_yarn group with 1 update in the /test/mcp directory: ip-address.
Bumps the npm_and_yarn group with 1 update in the /test/sanity directory: diff.

Updates @anthropic-ai/sdk from 0.82.0 to 0.129.0

Release notes

Sourced from @​anthropic-ai/sdk's releases.

sdk: v0.129.0

0.129.0 (2026-09-28)

Full Changelog: sdk-v0.128.0...sdk-v0.129.0

Features

  • api: add between_tools thinking type (ab51075)
  • api: add claude-sonnet-5-5 (4e77366)
  • api: add ClientToolUnion type for client-executed tools (2c1d2d7)
  • api: add include_inherited and source to workspace rate limits (66e925e)
  • api: add typed event type values to the Managed Agents events list filter (8ac4a26)
  • api: cache diagnostics GA — diagnostics on Message / MessageCreateParams (5ba5f29)
  • tools: optionally start tool calls while the reply streams (083969b)

Bug Fixes

  • client: also send X-Stainless-Timeout for client-level timeouts (b84783b)
  • client: send upload filenames as given, with no placeholder (f9d3e98)
  • helpers: degrade between_tools thinking to disabled on fallback hops (#841) (edbbf05)
  • internal: let bundlers drop unused classes with more than ten private-member assignments (67c7adb)
  • streaming: show every complete array item and hold back unfinished numbers in partial tool input (#781) (5806588)

Performance Improvements

  • streaming: drop the redundant iterSSEChunks layer (0357f81)
  • streaming: take each string token as one slice in the partial JSON tokenizer (#255) (cdfb1e5)

Chores

  • api: deprecate the betas param on GA models and completions methods (5c74e45)
  • api: list the known model ids first in the Model types (9452822)
  • ci: choose the CI runner by repository (33db1ec)
  • docs: clarify that stream: true returns the raw event stream (4286c22)
  • docs: make Managed Agents actor descriptions resource-neutral (15733f9)
  • docs: restore the research-preview notice on the Dream type (b32f8ba)
  • internal: move old constants around (0cd8edf)
  • tests: add diagnostics to the parser test's Message fixtures (eb5ca58)
  • tools: remove client-side compaction control (#802) (9c3e8a5)

Documentation

  • api: prefer each field's own description over its shared type's (5193478)
  • expand CLAUDE.md into a full contributor guide (98d2ddb)

sdk: v0.128.0

... (truncated)

Changelog

Sourced from @​anthropic-ai/sdk's changelog.

0.129.0 (2026-09-28)

Full Changelog: sdk-v0.128.0...sdk-v0.129.0

Features

  • api: add between_tools thinking type (ab51075)
  • api: add claude-sonnet-5-5 (4e77366)
  • api: add ClientToolUnion type for client-executed tools (2c1d2d7)
  • api: add include_inherited and source to workspace rate limits (66e925e)
  • api: add typed event type values to the Managed Agents events list filter (8ac4a26)
  • api: cache diagnostics GA — diagnostics on Message / MessageCreateParams (5ba5f29)
  • tools: optionally start tool calls while the reply streams (083969b)

Bug Fixes

  • client: also send X-Stainless-Timeout for client-level timeouts (b84783b)
  • client: send upload filenames as given, with no placeholder (f9d3e98)
  • helpers: degrade between_tools thinking to disabled on fallback hops (#841) (edbbf05)
  • internal: let bundlers drop unused classes with more than ten private-member assignments (67c7adb)
  • streaming: show every complete array item and hold back unfinished numbers in partial tool input (#781) (5806588)

Performance Improvements

  • streaming: drop the redundant iterSSEChunks layer (0357f81)
  • streaming: take each string token as one slice in the partial JSON tokenizer (#255) (cdfb1e5)

Chores

  • api: deprecate the betas param on GA models and completions methods (5c74e45)
  • api: list the known model ids first in the Model types (9452822)
  • ci: choose the CI runner by repository (33db1ec)
  • docs: clarify that stream: true returns the raw event stream (4286c22)
  • docs: make Managed Agents actor descriptions resource-neutral (15733f9)
  • docs: restore the research-preview notice on the Dream type (b32f8ba)
  • internal: move old constants around (0cd8edf)
  • tests: add diagnostics to the parser test's Message fixtures (eb5ca58)
  • tools: remove client-side compaction control (#802) (9c3e8a5)

Documentation

  • api: prefer each field's own description over its shared type's (5193478)
  • expand CLAUDE.md into a full contributor guide (98d2ddb)

0.128.0 (2026-09-22)

... (truncated)

Commits
  • bf20586 Merge pull request #1218 from anthropics/release-please--branches--main--chan...
  • da41a5a chore: release main
  • 3a79b93 codegen metadata
  • 4e77366 feat(api): add claude-sonnet-5-5
  • 2c1d2d7 feat(api): add ClientToolUnion type for client-executed tools
  • f9d3e98 fix(client): send upload filenames as given, with no placeholder
  • 8ac4a26 feat(api): add typed event type values to the Managed Agents events list filter
  • 083969b feat(tools): optionally start tool calls while the reply streams
  • 9505bf3 codegen metadata
  • b84783b fix(client): also send X-Stainless-Timeout for client-level timeouts
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​anthropic-ai/sdk since your current version.


Updates undici from 7.29.0 to 7.30.0

Release notes

Sourced from undici's releases.

v7.30.0

What's Changed

Full Changelog: nodejs/undici@v7.29.1...v7.30.0

v7.29.1

⚠️ Security fixes

High severity

  • GHSA-w293-vg96-wgc3: BalancedPool could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves connect and legacy tls options when creating upstreams. Fixed by f690157d.
  • GHSA-rfgv-xxqx-mfg5: a WebSocket server could select a subprotocol when none was requested, causing an uncaught TypeError that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 6615e017.

Medium severity

  • GHSA-3wwx-pv8p-q78v: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by 63cf698b.
  • GHSA-rx4f-c7p8-82vq: an unclean WebSocketStream close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by 1858656e.
  • GHSA-2jfj-6hjv-fm6j: shared caches could store and replay responses containing Set-Cookie, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by b6c5a002.
  • GHSA-3xpg-4rpp-hhhm: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable maxSize. Fixed by 2c7d7e12.
  • GHSA-pmjh-fq2x-6v4x: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by 3c672659.

Low severity

  • GHSA-8436-99hf-9mmv: cache interceptors could store and replay responses to unsafe HTTP methods such as POST or DELETE. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by b61d9432.
  • GHSA-2gqq-gqf2-x968: the dump interceptor could treat an oversized chunked response as successfully truncated when no Content-Length was present. Undici now enforces maxSize against received bytes and aborts oversized responses. Fixed by 21693f40.
  • GHSA-r53p-7pc4-xj5r: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates Content-Range against the original response framing before resuming. Fixed by cd8af90b.

What's Changed

Full Changelog: nodejs/undici@v7.29.0...v7.29.1

Commits

Updates braces from 2.3.2 to 3.0.3

Changelog

Sourced from braces's changelog.

Release history

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog and this project adheres to Semantic Versioning.

  • Changelogs are for humans, not machines.
  • There should be an entry for every single version.
  • The same types of changes should be grouped.
  • Versions and sections should be linkable.
  • The latest version comes first.
  • The release date of each versions is displayed.
  • Mention whether you follow Semantic Versioning.

Changelog entries are classified using the following labels (from keep-a-changelog):

  • Added for new features.
  • Changed for changes in existing functionality.
  • Deprecated for soon-to-be removed features.
  • Removed for now removed features.
  • Fixed for any bug fixes.
  • Security in case of vulnerabilities.

[3.0.0] - 2018-04-08

v3.0 is a complete refactor, resulting in a faster, smaller codebase, with fewer deps, and a more accurate parser and compiler.

Breaking Changes

  • The undocumented .makeRe method was removed
  • Require Node.js >= 8.3

Non-breaking changes

  • Caching was removed
Commits

Updates ip-address from 10.5.0 to 10.7.2

Release notes

Sourced from ip-address's releases.

v10.7.2

What's Changed

Full Changelog: beaugunderson/ip-address@v10.7.1...v10.7.2

v10.7.1

What's Changed

Full Changelog: beaugunderson/ip-address@v10.7.0...v10.7.1

v10.7.0

What's Changed

Full Changelog: beaugunderson/ip-address@v10.6.0...v10.7.0

v10.6.0

What's Changed

Full Changelog: beaugunderson/ip-address@v10.5.1...v10.6.0

v10.5.1

Full Changelog: beaugunderson/ip-address@v10.5.0...v10.5.1

Commits
  • 974b48d 10.7.2
  • 4dfe8e5 Accept an arpa suffix in any case and without the root dot in fromArpa (#227)
  • f0c25df 10.7.1
  • 8b34a21 Merge commit from fork
  • 13b6155 Merge commit from fork
  • 469ead1 Reject an address longer than the family allows before parsing it
  • 1343629 Report an address of the other family as not contained
  • 4c2184a Bump js-yaml and brace-expansion in the lockfile (#226)
  • 2b7cab5 10.7.0
  • 87fae23 Add offset() and nextNetwork(), accept prefix-length ip6.arpa names, correct ...
  • Additional commits viewable in compare view

Updates ip-address from 10.5.0 to 10.7.2

Release notes

Sourced from ip-address's releases.

v10.7.2

What's Changed

Full Changelog: beaugunderson/ip-address@v10.7.1...v10.7.2

v10.7.1

What's Changed

Full Changelog: beaugunderson/ip-address@v10.7.0...v10.7.1

v10.7.0

What's Changed

Full Changelog: beaugunderson/ip-address@v10.6.0...v10.7.0

v10.6.0

What's Changed

Full Changelog: beaugunderson/ip-address@v10.5.1...v10.6.0

v10.5.1

Full Changelog: beaugunderson/ip-address@v10.5.0...v10.5.1

Commits
  • 974b48d 10.7.2
  • 4dfe8e5 Accept an arpa suffix in any case and without the root dot in fromArpa (#227)
  • f0c25df 10.7.1
  • 8b34a21 Merge commit from fork
  • 13b6155 Merge commit from fork
  • 469ead1 Reject an address longer than the family allows before parsing it
  • 1343629 Report an address of the other family as not contained
  • 4c2184a Bump js-yaml and brace-expansion in the lockfile (#226)
  • 2b7cab5 10.7.0
  • 87fae23 Add offset() and nextNetwork(), accept prefix-length ip6.arpa names, correct ...
  • Additional commits viewable in compare view

Updates @anthropic-ai/sdk from 0.82.0 to 0.91.1

Release notes

Sourced from @​anthropic-ai/sdk's releases.

sdk: v0.129.0

0.129.0 (2026-09-28)

Full Changelog: sdk-v0.128.0...sdk-v0.129.0

Features

  • api: add between_tools thinking type (ab51075)
  • api: add claude-sonnet-5-5 (4e77366)
  • api: add ClientToolUnion type for client-executed tools (2c1d2d7)
  • api: add include_inherited and source to workspace rate limits (66e925e)
  • api: add typed event type values to the Managed Agents events list filter (8ac4a26)
  • api: cache diagnostics GA — diagnostics on Message / MessageCreateParams (5ba5f29)
  • tools: optionally start tool calls while the reply streams (083969b)

Bug Fixes

  • client: also send X-Stainless-Timeout for client-level timeouts (b84783b)
  • client: send upload filenames as given, with no placeholder (f9d3e98)
  • helpers: degrade between_tools thinking to disabled on fallback hops (#841) (edbbf05)
  • internal: let bundlers drop unused classes with more than ten private-member assignments (67c7adb)
  • streaming: show every complete array item and hold back unfinished numbers in partial tool input (#781) (5806588)

Performance Improvements

  • streaming: drop the redundant iterSSEChunks layer (0357f81)
  • streaming: take each string token as one slice in the partial JSON tokenizer (#255) (cdfb1e5)

Chores

  • api: deprecate the betas param on GA models and completions methods (5c74e45)
  • api: list the known model ids first in the Model types (9452822)
  • ci: choose the CI runner by repository (33db1ec)
  • docs: clarify that stream: true returns the raw event stream (4286c22)
  • docs: make Managed Agents actor descriptions resource-neutral (15733f9)
  • docs: restore the research-preview notice on the Dream type (b32f8ba)
  • internal: move old constants around (0cd8edf)
  • tests: add diagnostics to the parser test's Message fixtures (eb5ca58)
  • tools: remove client-side compaction control (#802) (9c3e8a5)

Documentation

  • api: prefer each field's own description over its shared type's (5193478)
  • expand CLAUDE.md into a full contributor guide (98d2ddb)

sdk: v0.128.0

... (truncated)

Changelog

Sourced from @​anthropic-ai/sdk's changelog.

0.129.0 (2026-09-28)

Full Changelog: sdk-v0.128.0...sdk-v0.129.0

Features

  • api: add between_tools thinking type (ab51075)
  • api: add claude-sonnet-5-5 (4e77366)
  • api: add ClientToolUnion type for client-executed tools (2c1d2d7)
  • api: add include_inherited and source to workspace rate limits (66e925e)
  • api: add typed event type values to the Managed Agents events list filter (8ac4a26)
  • api: cache diagnostics GA — diagnostics on Message / MessageCreateParams (5ba5f29)
  • tools: optionally start tool calls while the reply streams (083969b)

Bug Fixes

  • client: also send X-Stainless-Timeout for client-level timeouts (b84783b)
  • client: send upload filenames as given, with no placeholder (f9d3e98)
  • helpers: degrade between_tools thinking to disabled on fallback hops (#841) (edbbf05)
  • internal: let bundlers drop unused classes with more than ten private-member assignments (67c7adb)
  • streaming: show every complete array item and hold back unfinished numbers in partial tool input (#781) (5806588)

Performance Improvements

  • streaming: drop the redundant iterSSEChunks layer (0357f81)
  • streaming: take each string token as one slice in the partial JSON tokenizer (#255) (cdfb1e5)

Chores

  • api: deprecate the betas param on GA models and completions methods (5c74e45)
  • api: list the known model ids first in the Model types (9452822)
  • ci: choose the CI runner by repository (33db1ec)
  • docs: clarify that stream: true returns the raw event stream (4286c22)
  • docs: make Managed Agents actor descriptions resource-neutral (15733f9)
  • docs: restore the research-preview notice on the Dream type (b32f8ba)
  • internal: move old constants around (0cd8edf)
  • tests: add diagnostics to the parser test's Message fixtures (eb5ca58)
  • tools: remove client-side compaction control (#802) (9c3e8a5)

Documentation

  • api: prefer each field's own description over its shared type's (5193478)
  • expand CLAUDE.md into a full contributor guide (98d2ddb)

0.128.0 (2026-09-22)

... (truncated)

Commits
  • bf20586 Merge pull request #1218 from anthropics/release-please--branches--main--chan...
  • da41a5a chore: release main
  • 3a79b93 codegen metadata
  • 4e77366 feat(api): add claude-sonnet-5-5
  • 2c1d2d7 feat(api): add ClientToolUnion type for client-executed tools
  • f9d3e98 fix(client): send upload filenames as given, with no placeholder
  • 8ac4a26 feat(api): add typed event type values to the Managed Agents events list filter
  • 083969b feat(tools): optionally start tool calls while the reply streams
  • 9505bf3 codegen metadata
  • b84783b fix(client): also send X-Stainless-Timeout for client-level timeouts
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​anthropic-ai/sdk since your current version.


Updates undici from 7.29.0 to 7.30.0

Release notes

Sourced from undici's releases.

v7.30.0

What's Changed

Full Changelog: nodejs/undici@v7.29.1...v7.30.0

v7.29.1

⚠️ Security fixes

High severity

  • GHSA-w293-vg96-wgc3: BalancedPool could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves connect and legacy tls options when creating upstreams. Fixed by f690157d.
  • GHSA-rfgv-xxqx-mfg5: a WebSocket server could select a subprotocol when none was requested, causing an uncaught TypeError that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 6615e017.

Medium severity

  • GHSA-3wwx-pv8p-q78v: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by 63cf698b.
  • GHSA-rx4f-c7p8-82vq: an unclean WebSocketStream close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by 1858656e.
  • GHSA-2jfj-6hjv-fm6j: shared caches could store and replay responses containing Set-Cookie, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by b6c5a002.
  • GHSA-3xpg-4rpp-hhhm: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable maxSize. Fixed by 2c7d7e12.
  • GHSA-pmjh-fq2x-6v4x: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by 3c672659.

Low severity

  • GHSA-8436-99hf-9mmv: cache interceptors could store and replay responses to unsafe HTTP methods such as POST or DELETE. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by b61d9432.
  • GHSA-2gqq-gqf2-x968: the dump interceptor could treat an oversized chunked response as successfully truncated when no Content-Length was present. Undici now enforces maxSize against received bytes and aborts oversized responses. Fixed by 21693f40.
  • GHSA-r53p-7pc4-xj5r: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates Content-Range against the original response framing before resuming. Fixed by cd8af90b.

What's Changed

Full Changelog: nodejs/undici@v7.29.0...v7.29.1

Commits

Bumps the npm_and_yarn group with 4 updates in the / directory: [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript), [undici](https://github.com/nodejs/undici), [braces](https://github.com/micromatch/braces) and [ip-address](https://github.com/beaugunderson/ip-address).
Bumps the npm_and_yarn group with 1 update in the /build/npm/gyp directory: [ip-address](https://github.com/beaugunderson/ip-address).
Bumps the npm_and_yarn group with 5 updates in the /extensions/copilot directory:

| Package | From | To |
| --- | --- | --- |
| [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) | `0.82.0` | `0.91.1` |
| [undici](https://github.com/nodejs/undici) | `7.29.0` | `7.30.0` |
| [uuid](https://github.com/uuidjs/uuid) | `8.3.2` | `removed` |
| [ip-address](https://github.com/beaugunderson/ip-address) | `10.5.0` | `10.7.2` |
| [@opentelemetry/core](https://github.com/open-telemetry/opentelemetry-js) | `1.30.1` | `2.11.0` |

Bumps the npm_and_yarn group with 2 updates in the /extensions/copilot/chat-lib directory: [undici](https://github.com/nodejs/undici) and [@opentelemetry/core](https://github.com/open-telemetry/opentelemetry-js).
Bumps the npm_and_yarn group with 1 update in the /extensions/copilot/test/simulation/fixtures/generate/issue-6163 directory: [esbuild](https://github.com/evanw/esbuild).
Bumps the npm_and_yarn group with 2 updates in the /remote directory: [undici](https://github.com/nodejs/undici) and [ip-address](https://github.com/beaugunderson/ip-address).
Bumps the npm_and_yarn group with 1 update in the /test/mcp directory: [ip-address](https://github.com/beaugunderson/ip-address).
Bumps the npm_and_yarn group with 1 update in the /test/sanity directory: [diff](https://github.com/kpdecker/jsdiff).


Updates `@anthropic-ai/sdk` from 0.82.0 to 0.129.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.82.0...sdk-v0.129.0)

Updates `undici` from 7.29.0 to 7.30.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.29.0...v7.30.0)

Updates `braces` from 2.3.2 to 3.0.3
- [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md)
- [Commits](https://github.com/micromatch/braces/commits/3.0.3)

Updates `ip-address` from 10.5.0 to 10.7.2
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](beaugunderson/ip-address@v10.5.0...v10.7.2)

Updates `ip-address` from 10.5.0 to 10.7.2
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](beaugunderson/ip-address@v10.5.0...v10.7.2)

Updates `@anthropic-ai/sdk` from 0.82.0 to 0.91.1
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.82.0...sdk-v0.129.0)

Updates `undici` from 7.29.0 to 7.30.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.29.0...v7.30.0)

Removes `uuid`

Updates `ip-address` from 10.5.0 to 10.7.2
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](beaugunderson/ip-address@v10.5.0...v10.7.2)

Updates `@opentelemetry/core` from 1.30.1 to 2.11.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v1.30.1...v2.11.0)

Updates `undici` from 7.29.0 to 7.29.1
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.29.0...v7.30.0)

Updates `@opentelemetry/core` from 1.30.1 to 2.11.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-js/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-js@v1.30.1...v2.11.0)

Updates `esbuild` from 0.21.5 to 0.28.2
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2024.md)
- [Commits](evanw/esbuild@v0.21.5...v0.28.2)

Updates `undici` from 7.29.0 to 7.30.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.29.0...v7.30.0)

Updates `ip-address` from 10.4.0 to 10.7.2
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](beaugunderson/ip-address@v10.5.0...v10.7.2)

Updates `ip-address` from 10.4.0 to 10.7.2
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](beaugunderson/ip-address@v10.5.0...v10.7.2)

Updates `diff` from 7.0.0 to 9.0.0
- [Changelog](https://github.com/kpdecker/jsdiff/blob/master/release-notes.md)
- [Commits](kpdecker/jsdiff@7.0.0...v9.0.0)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.129.0
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: undici
  dependency-version: 7.30.0
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: braces
  dependency-version: 3.0.3
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: ip-address
  dependency-version: 10.7.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: ip-address
  dependency-version: 10.7.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.91.1
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: undici
  dependency-version: 7.30.0
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: uuid
  dependency-version:
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: ip-address
  dependency-version: 10.7.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: "@opentelemetry/core"
  dependency-version: 2.11.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: undici
  dependency-version: 7.29.1
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: "@opentelemetry/core"
  dependency-version: 2.11.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: esbuild
  dependency-version: 0.28.2
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: undici
  dependency-version: 7.30.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: ip-address
  dependency-version: 10.7.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: ip-address
  dependency-version: 10.7.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: diff
  dependency-version: 9.0.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@Taxperia

Copy link
Copy Markdown
Owner

Closed as stale/superseded by bb6734b. This branch is based on c99d4ce and would revert validated dependency and telemetry API fixes; its Gulp 5/Mocha 12 major upgrades require separate compatibility work.

@Taxperia Taxperia closed this Sep 29, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/npm_and_yarn-37aff0ec63 branch September 29, 2026 14:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant