chore(deps): bump the prod-deps group across 1 directory with 11 updates#45
chore(deps): bump the prod-deps group across 1 directory with 11 updates#45dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the prod-deps group with 11 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@ai-sdk/react](https://github.com/vercel/ai/tree/HEAD/packages/react) | `3.0.170` | `3.0.187` | | [@openrouter/ai-sdk-provider](https://github.com/OpenRouterTeam/ai-sdk-provider) | `2.8.0` | `2.9.0` | | [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `6.0.168` | `6.0.185` | | [framer-motion](https://github.com/motiondivision/motion) | `12.38.0` | `12.39.0` | | [fumadocs-core](https://github.com/fuma-nama/fumadocs) | `16.8.0` | `16.8.11` | | [fumadocs-ui](https://github.com/fuma-nama/fumadocs) | `16.8.0` | `16.8.11` | | [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.8.0` | `1.16.0` | | [react](https://github.com/facebook/react/tree/HEAD/packages/react) | `19.2.5` | `19.2.6` | | [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) | `19.2.5` | `19.2.6` | | [tailwind-merge](https://github.com/dcastil/tailwind-merge) | `3.5.0` | `3.6.0` | | [zod](https://github.com/colinhacks/zod) | `4.3.6` | `4.4.3` | Updates `@ai-sdk/react` from 3.0.170 to 3.0.187 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/@ai-sdk/react@3.0.187/packages/react/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/@ai-sdk/react@3.0.187/packages/react) Updates `@openrouter/ai-sdk-provider` from 2.8.0 to 2.9.0 - [Release notes](https://github.com/OpenRouterTeam/ai-sdk-provider/releases) - [Changelog](https://github.com/OpenRouterTeam/ai-sdk-provider/blob/main/CHANGELOG.md) - [Commits](OpenRouterTeam/ai-sdk-provider@2.8.0...2.9.0) Updates `ai` from 6.0.168 to 6.0.185 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/ai@6.0.185/packages/ai/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/ai@6.0.185/packages/ai) Updates `framer-motion` from 12.38.0 to 12.39.0 - [Changelog](https://github.com/motiondivision/motion/blob/main/CHANGELOG.md) - [Commits](motiondivision/motion@v12.38.0...v12.39.0) Updates `fumadocs-core` from 16.8.0 to 16.8.11 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/commits/fumadocs-core@16.8.11) Updates `fumadocs-ui` from 16.8.0 to 16.8.11 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/commits/fumadocs-ui@16.8.11) Updates `lucide-react` from 1.8.0 to 1.16.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.16.0/packages/lucide-react) Updates `react` from 19.2.5 to 19.2.6 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.6/packages/react) Updates `react-dom` from 19.2.5 to 19.2.6 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.6/packages/react-dom) Updates `tailwind-merge` from 3.5.0 to 3.6.0 - [Release notes](https://github.com/dcastil/tailwind-merge/releases) - [Commits](dcastil/tailwind-merge@v3.5.0...v3.6.0) Updates `zod` from 4.3.6 to 4.4.3 - [Release notes](https://github.com/colinhacks/zod/releases) - [Commits](colinhacks/zod@v4.3.6...v4.4.3) --- updated-dependencies: - dependency-name: "@ai-sdk/react" dependency-version: 3.0.187 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: "@openrouter/ai-sdk-provider" dependency-version: 2.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-deps - dependency-name: ai dependency-version: 6.0.185 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: framer-motion dependency-version: 12.39.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-deps - dependency-name: fumadocs-core dependency-version: 16.8.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: fumadocs-ui dependency-version: 16.8.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: lucide-react dependency-version: 1.16.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-deps - dependency-name: react dependency-version: 19.2.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: react-dom dependency-version: 19.2.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: tailwind-merge dependency-version: 3.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-deps - dependency-name: zod dependency-version: 4.4.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-deps ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
Mogplex PR Review
Status: Attention needed
This is a standard Dependabot batch dependency bump across 11 production packages. All updates are patch or minor versions from well-known, reputable maintainers. Notably, the lockfile introduces two security overrides for brace-expansion (ReDoS) and postcss (ReDoS / CVE-2025-27789) to remediate vulnerable transitive dependency versions — this is a positive security improvement. The zod upgrade (4.3.6 → 4.4.3) contains a "potentially breaking" 4.4.0 release that altered strictness for some validation patterns, which is worth flagging even though the PR itself is auto-generated. No custom code changes are present. The PR is safe to merge after verifying CI passes.
Warnings
- zod 4.4.x contains potentially breaking strictness changes (package.json)
Thezodupgrade from 4.3.6 to 4.4.3 passes through the 4.4.0 release, which its own changelog marks as containing "Potentially breaking bug fixes": it generalizes opt-in/fallback to transforms, restorespreprocesson absent keys, and restorescatchhandling for absent object keys. These changes intentionally make Zod stricter in edge cases. If the codebase defines Zod schemas with.catch(),.preprocess(), or relies on absent-key coercion behaviour, runtime validation could silently change. Additionally, theai@6.0.181changelog explicitly mentions a fix forvalidateUIMessagesthat was needed because Zod 4.4+ treats missingz.unknown()keys as validation failures — indicating the Vercel AI SDK is already aware of this breaking shift.
Recommendation: Verify all Zod schemas used for request/response validation still behave as expected (especially any that use .catch(), .default(), or .preprocess()), and check that any persisted AI message threads continue to load without AI_TypeValidationError.
Suggestions
- Security overrides for brace-expansion and postcss are only in pnpm-lock.yaml, not package.json (pnpm-lock.yaml)
The lockfile addsoverridesforbrace-expansion@>=5.0.0 <5.0.6andpostcss@<8.5.10to force safe versions of vulnerable transitive dependencies. However, these overrides do not appear inpackage.json'spnpm.overrides(oroverrides) field — they exist only in the lockfile. In a pnpm workspace this is unusual: overrides defined only in the lockfile may be lost if the lockfile is regenerated without the correspondingpackage.jsonentry, leaving the project re-exposed to the vulnerability.
Recommendation: Add the same overrides explicitly to package.json under a pnpm.overrides block (for pnpm) to ensure they survive a lockfile regeneration:
"pnpm": {
"overrides": {
"brace-expansion@>=5.0.0 <5.0.6": ">=5.0.6",
"postcss@<8.5.10": ">=8.5.10"
}
}
Bumps the prod-deps group with 11 updates in the / directory:
3.0.1703.0.1872.8.02.9.06.0.1686.0.18512.38.012.39.016.8.016.8.1116.8.016.8.111.8.01.16.019.2.519.2.619.2.519.2.63.5.03.6.04.3.64.4.3Updates
@ai-sdk/reactfrom 3.0.170 to 3.0.187Release notes
Sourced from @ai-sdk/react's releases.
Changelog
Sourced from @ai-sdk/react's changelog.
... (truncated)
Commits
4a98945Version Packages (#15406)f8d3003Version Packages (#15356)2e7664bVersion Packages (#15315)c76ce9cVersion Packages (#15257)c0e4fefVersion Packages (#15251)43e5359Version Packages (#15221)e2f1bcaVersion Packages (#15216)d37fb1fVersion Packages (#15202)e70aab9Version Packages (#15138)e3ccdb5Version Packages (#15094)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@ai-sdk/reactsince your current version.Updates
@openrouter/ai-sdk-providerfrom 2.8.0 to 2.9.0Release notes
Sourced from @openrouter/ai-sdk-provider's releases.
Changelog
Sourced from @openrouter/ai-sdk-provider's changelog.
... (truncated)
Commits
5cef3c5Version Packages (#490)bb2d4cbfix: stop emitting duplicate tool-call events on trailing-whitespace deltas (...82e8014fix: allow opting out of response_format strict mode (#483) (#486)bf664b1fix: allow query strings and fragments in image URL regex (#484) (#485)310ba3dVersion Packages (#488)4588197fix: preserve empty reasoning_details arrays in multi-turn conversations (#487)Updates
aifrom 6.0.168 to 6.0.185Release notes
Sourced from ai's releases.
Changelog
Sourced from ai's changelog.
... (truncated)
Commits
4a98945Version Packages (#15406)f8d3003Version Packages (#15356)40fc5e4Backport: fix(ai): default missing embedding warnings (#15354)2e7664bVersion Packages (#15315)7baadccchore: diverge test assertions based on node version (#15326)5427555chore: fix flaky tests diverging on different node versions (#15296)c76ce9cVersion Packages (#15257)c0e4fefVersion Packages (#15251)e76a29aBackport: fix(ai): download tool-result file URLs (#15246)538974aBackport: fix(ai): Fix validateUIMessages with Zod 4.4 (#15247)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for ai since your current version.
Updates
framer-motionfrom 12.38.0 to 12.39.0Changelog
Sourced from framer-motion's changelog.
Commits
b607391v12.39.0cd53178Updating changelogbd07642Merge pull request #3716 from motiondivision/worktree-fix-issue-33153f053b6Merge branch 'main' into worktree-fix-issue-3315f434c42Merge pull request #3718 from motiondivision/dependabot/npm_and_yarn/next-15....5973dfbMerge pull request #3722 from motiondivision/worktree-fix-issue-2829cfccb03fix(drag): Refresh root scroll before measuring ref constraints16aa417Updating changelog5d627a4Merge pull request #3720 from motiondivision/worktree-fix-issue-283163cf0d0Merge pull request #3721 from motiondivision/worktree-fix-issue-2833Updates
fumadocs-corefrom 16.8.0 to 16.8.11Release notes
Sourced from fumadocs-core's releases.
Commits
Updates
fumadocs-uifrom 16.8.0 to 16.8.11Release notes
Sourced from fumadocs-ui's releases.
... (truncated)
Commits
Updates
lucide-reactfrom 1.8.0 to 1.16.0Release notes
Sourced from lucide-react's releases.
... (truncated)
Commits
07c885efix(docs): fix zephyr-cloud URL in readmes50d8af5docs(readme): Update readme files (#4320)653e44bfeat(packages): use .mjs for ESM bundles (#4285)Updates
reactfrom 19.2.5 to 19.2.6Release notes
Sourced from react's releases.
Commits
eaf3e95Version 19.2.6Updates
react-domfrom 19.2.5 to 19.2.6Release notes
Sourced from react-dom's releases.
Commits
eaf3e95Version 19.2.6Updates
tailwind-mergefrom 3.5.0 to 3.6.0Release notes
Sourced from tailwind-merge's releases.
Commits
d54f7e5v3.6.0638871aUpdate README to add info about Tailwind CSS v4.3 support39fc7b5Revert "v3.6.0"bd8390fv3.6.0802877cadd v3.6.0 changeloga35fedaMerge pull request #665 from dcastil/renovate/rollup-plugin-babel-7.x940389cMerge pull request #667 from dcastil/renovate/release-drafter-release-drafter...005af6dpin to specific version5816cedimplement breaking changes17041e1Merge pull request #676 from dcastil/dependabot/npm_and_yarn/babel/plugin-tra...Updates
zodfrom 4.3.6 to 4.4.3Release notes
Sourced from zod's releases.
... (truncated)
Commits
1fb56a5docs: document release procedure in AGENTS.mdf3c9ec04.4.3c2be4f8fix(v4): generalize optin/fallback to transform; restore preprocess on absent...1cab693fix(v4): restore catch handling for absent object keys (#5937) (#5939)b8dffe9docs: remove Numeric and Speakeasy (2+ missed monthly cycles)9195250docs: remove Mintlify from bronze sponsors (churned)2c70332docs: normalize bronze sponsor logos to github avatar pattern7391be8docs: prune lapsed silver/bronze sponsors and add active ones2aeec83docs: prune lapsed gold sponsors and rebalance logo sizing4c2fa95docs: use Zernio primary wordmark for gold sponsor logoMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for zod since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsNeed help on this PR? Tag
@codesmithwith what you need.