Skip to content

deps(node): bump the node-production-minor-and-patch group across 1 directory with 21 updates - #387

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/node-production-minor-and-patch-3478fa5cf2
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/node-production-minor-and-patch-3478fa5cf2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the node-production-minor-and-patch group with 21 updates in the / directory:

Package From To
@modelcontextprotocol/sdk 1.30.0 1.30.1
yaml 2.9.0 2.9.1
zod 4.4.3 4.6.5
@ai-sdk/react 4.0.43 4.0.117
@lobehub/icons-static-svg 1.94.0 1.95.1
@tanstack/react-query 5.101.4 5.103.2
@tanstack/react-router 1.170.18 1.170.39
ai 7.0.40 7.0.114
lucide-react 1.27.0 1.48.0
react-error-boundary 6.1.2 6.1.6
sonner 2.0.7 2.0.8
streamdown 2.5.0 2.6.0
tailwind-merge 3.6.0 3.7.0
zustand 5.0.14 5.0.15
@scalar/openapi-upgrader 0.2.11 0.3.1
cnfast 0.1.0 0.2.0
fumadocs-core 16.14.0 16.15.14
fumadocs-mdx 15.2.1 15.4.4
next 16.2.12 16.3.6
shiki 4.3.1 4.4.3
keycloakify 11.15.14 11.16.0

Updates @modelcontextprotocol/sdk from 1.30.0 to 1.30.1

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

1.30.1

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.0...1.30.1

Commits
  • 289ac2c chore: bump version to 1.30.1 (#2848)
  • 12b4256 fix(auth): preserve resource URI without trailing slash (#1968) (#1972)
  • a9f6eb7 [v1.x] fix(server): read HTTP request bodies with a size limit and bound JSON...
  • See full diff in compare view

Updates yaml from 2.9.0 to 2.9.1

Release notes

Sourced from yaml's releases.

v2.9.1

  • Limit recursive merge aliases (#685, #713)
  • Simplify line unfolding during quoted string parsing (#714)
Commits

Updates zod from 4.4.3 to 4.6.5

Release notes

Sourced from zod's releases.

v4.6.5

Commits:

  • d2b135cfb7a3582b9eb515756b9166bcb9521f4a docs: add the 4.6.x patch highlights to the 4.6 post
  • f1448f7cee00df9fe1e9ad84a000aa1828cc8bc1 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • de65a5cb39ed22a507fac935788f718fa88d104f docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • 56222cd1532c07bcb91b67df529cab4c0a215330 feat(instanceof): key the .properties() shape off the instance type (#6600)
  • ca0229a404818290e6cdcfefcd7eb2d04bcbb543 Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)"
  • cc4cd4ee9c52fcaa10964e48cc144541e41a5ed9 Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)""
  • 0f3f5ee3ca56c7574bf849e54f79e9a6e02562ee 4.6.5
  • 59bbc03e10c636b9eb3c393dfeb552819774ec21 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump

v4.6.4

A patch on top of 4.6.3.

  • d6bc1e30 feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)
  • ad32d751 perf: z.url() rejects an invalid URL with URL.canParse() instead of a throwing constructor, about 50x faster; fewer allocations on the validation path (#6588)
  • 2bb08717 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • f6e1701a chore(deps): bump next to 15.5.25 and vite to 7.3.6 (#6153)

v4.6.3

A patch on top of 4.6.2.

  • 413cce9a fix(v4): make z.properties() a check again (#6594) — removes the standalone z.properties() schema from 4.6.0; z.instanceof().properties() and .check(...z.properties()) are unchanged
  • 75d63ee1 docs: show only the .properties() method form in the 4.6 post
  • 46da9572 docs: match the error-message examples to what the parsers emit

v4.6.2

A patch on top of 4.6.1.

v4.6.1

A patch on top of 4.6.0.

v4.6.0

Zod 4.6 is now available.

npm install zod@latest

At a glance:

... (truncated)

Commits
  • 59bbc03 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump
  • 0f3f5ee 4.6.5
  • cc4cd4e Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, ref...
  • ca0229a Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed w...
  • 56222cd feat(instanceof): key the .properties() shape off the instance type (#6600)
  • de65a5c docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • f1448f7 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • d2b135c docs: add the 4.6.x patch highlights to the 4.6 post
  • 2bb0871 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • 743aedb 4.6.4
  • Additional commits viewable in compare view

Updates @ai-sdk/react from 4.0.43 to 4.0.117

Changelog

Sourced from @​ai-sdk/react's changelog.

4.0.117

Patch Changes

  • Updated dependencies [b5679a7]
  • Updated dependencies [1ffd453]
  • Updated dependencies [ca31b89]
    • ai@7.0.114
    • @​ai-sdk/mcp@​2.0.58

4.0.116

Patch Changes

  • Updated dependencies [dcdb011]
  • Updated dependencies [8f72832]
  • Updated dependencies [fe07867]
  • Updated dependencies [b74c0cb]
  • Updated dependencies [a4b0940]
  • Updated dependencies [2693319]
  • Updated dependencies [c93ee90]
  • Updated dependencies [771e74b]
    • ai@7.0.113
    • @​ai-sdk/provider-utils@​5.0.47
    • @​ai-sdk/mcp@​2.0.57

4.0.115

Patch Changes

  • Updated dependencies [9a98fd9]
  • Updated dependencies [a0553d6]
  • Updated dependencies [ffb0e76]
  • Updated dependencies [fde0d66]
    • ai@7.0.112
    • @​ai-sdk/provider@​4.0.18
    • @​ai-sdk/mcp@​2.0.56
    • @​ai-sdk/provider-utils@​5.0.46

4.0.114

Patch Changes

  • Updated dependencies [31d24ce]
  • Updated dependencies [a65bfd9]
    • ai@7.0.111

4.0.113

Patch Changes

... (truncated)

Commits

Updates @lobehub/icons-static-svg from 1.94.0 to 1.95.1

Release notes

Sourced from @​lobehub/icons-static-svg's releases.

@​lobehub/icons-static-svg@​1.95.1

Version 1.95.1

Released on 2026-09-21

💄 Styles

  • misc: Update static.

Styles

Changelog

Sourced from @​lobehub/icons-static-svg's changelog.

Changelog

Version 5.21.0

Released on 2026-09-23

✨ Features

  • misc: Map Composer models to the Cursor icon.

What's improved

  • misc: Map Composer models to the Cursor icon (f0183a2)

Version 5.20.0

Released on 2026-09-23

✨ Features

  • auto: Auto build static icons.
  • misc: Redesign the docs home and show guide pages in the sidebar.

What's improved

  • auto: Auto build static icons (2e25cec)
  • misc: Redesign the docs home and show guide pages in the sidebar (8196bab)

... (truncated)

Commits
  • 49a2130 🔖 chore(release): @​lobehub/icons-static-svg@​1.95.1 [skip ci]
  • 0f1017c 🔖 chore(release): @​lobehub/icons-static-png@​1.97.1 [skip ci]
  • 4f54580 🔖 chore(release): @​lobehub/icons-static-avatar@​1.15.0 [skip ci]
  • 10ef92e 🔖 chore(release): @​lobehub/icons-rn@​2.14.0 [skip ci]
  • 2e25cec ✨ feat(auto): Auto build static icons
  • 2c3b3c8 🔖 chore(release): v5.19.3 [skip ci]
  • ad84f0c 🐛 fix: use github.token for semantic-release
  • b434565 🔖 chore(release): v5.19.2 [skip ci]
  • bded67e 💄 style: update workflow
  • e3c0b05 🔖 chore(release): v5.19.1 [skip ci]
  • Additional commits viewable in compare view

Updates @tanstack/react-query from 5.101.4 to 5.103.2

Release notes

Sourced from @​tanstack/react-query's releases.

@​tanstack/react-query-devtools@​5.103.2

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-devtools@​5.103.2
    • @​tanstack/react-query@​5.103.2

@​tanstack/react-query-next-experimental@​5.103.2

Patch Changes

  • Updated dependencies []:
    • @​tanstack/react-query@​5.103.2

@​tanstack/react-query-persist-client@​5.103.2

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-persist-client-core@​5.103.2
    • @​tanstack/react-query@​5.103.2

@​tanstack/react-query@​5.103.2

Patch Changes

  • Updated dependencies [8a28904]:
    • @​tanstack/query-core@​5.103.2
Changelog

Sourced from @​tanstack/react-query's changelog.

5.103.2

Patch Changes

  • Updated dependencies [8a28904]:
    • @​tanstack/query-core@​5.103.2

5.103.1

Patch Changes

5.103.0

Patch Changes

5.102.8

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-core@​5.102.8

5.102.7

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-core@​5.102.7

5.102.6

Patch Changes

  • #11305 ac2b612 - fix(react-query): throw falsy errors from useQueries and useSuspenseQueries to the error boundary

  • Updated dependencies []:

    • @​tanstack/query-core@​5.102.6

5.102.5

Patch Changes

  • Updated dependencies [578e5c2]:
    • @​tanstack/query-core@​5.102.5

... (truncated)

Commits
  • e0f6c55 ci: Version Packages (#11525)
  • c08f576 ci: Version Packages (#11511)
  • 19ccf27 ci: Version Packages (#11339)
  • 2da46cd chore(*): use eslint description syntax for grandfathered 'no-restricted-synt...
  • 58ad3e2 fix: isolate TypeScript test output (#11503)
  • d63afc7 Simplifed query methods/internal tests new lint (#11347)
  • 23fbdc3 test({react,preact,solid,angular}-query): remove 'fromGenericOptionsQueryFn' ...
  • 50680b9 test({react,preact,solid,svelte}-query,angular-query-experimental): rename 'm...
  • 0b326b6 test({react,preact}-query/useMutation): add tests for 'MutationFunctionContex...
  • a1119e5 ref(hydration): remove outdated dehydratedAt fallback (#11436)
  • Additional commits viewable in compare view

Updates @tanstack/react-router from 1.170.18 to 1.170.39

Release notes

Sourced from @​tanstack/react-router's releases.

@​tanstack/react-router@​1.170.39

Patch Changes

  • #8435 73bfc15 - Avoid hydration-triggered rerenders for links that do not compare URL hashes while preserving hash-sensitive active state and ClientOnly behavior.

@​tanstack/react-router@​1.170.38

Patch Changes

@​tanstack/react-router@​1.170.37

Patch Changes

  • #8418 e561fa1 - deepEqual now takes its flags as positional arguments — deepEqual(a, b, partial?, explicitUndefined?) — instead of an options object. The router's hot callers (Link option stabilization and active-state checks, matchRoute) no longer allocate an options object per comparison, and the comparator reads two booleans instead of a polymorphic object. explicitUndefined replaces ignoreUndefined: false. deepEqual is an internal helper; it stays exported for compatibility of two-argument calls.

  • #8419 a1c8d1a - resolvePath (internal helper) now takes positional arguments — resolvePath(base, to, trailingSlash?, cache?) — so buildLocation and matchRoute no longer allocate an options object per path resolution.

  • #8204 cbbfbe3 - Stream large deferred SSR hydration payloads through a backpressure-aware router transport, fail known setup errors before response creation, and close cancelled or expired transforms safely.

    Start now cancels discarded middleware and HEAD response bodies, including plain streams and derived branches.

    Server-function raw streams share one ordered response. Arbitrary or sequential consumption can require potentially unbounded buffering of unread data on the client. Cancelling one raw stream discards it locally, while aborting the whole call cancels the response and server work. Consume streams concurrently, cancel unused streams promptly, or use separate calls when independent backpressure is required. A raw stream that exceeds its unread-byte limit now fails alone; sibling streams and the JSON result keep flowing.

    The JSON wire shape of a RawStream server-function argument changed. Clients and servers must run matching versions for requests that pass a RawStream.

    The frame-protocol constants (FRAME_TYPE_*, MAX_FRAME_PAYLOAD_SIZE, MAX_FRAMED_STREAMS) moved from the @tanstack/start-client-core root to the @tanstack/start-client-core/client-rpc subpath.

    Router requests whose Accept header allows neither text/html nor */* now receive 406 Not Acceptable instead of 500.

    Framework adapters share the body <Scripts> composition (getSsrBodyScriptParts, composeSsrBodyScripts) and the eager HTML response wrapper (renderSsrHtmlResponse) from @tanstack/router-core.

    Solid SSR now emits one document type and renders late lazy errors through route boundaries. A Solid <Await> without a fallback no longer holds the streamed shell; it renders inside the nearest <Suspense> boundary like React and Vue, and now renders falsy resolved values.

    Static server functions decode cached RawStream values with the client deserializer plugins.

    SSR Query integrations now keep request cleanup and stream ownership aligned with the router lifecycle.

  • #8420 8e164d2 - useLinkProps no longer calls through an internal wrapper. The host element Link renders on is an @internal overload parameter that is stripped from the published declarations, so the public useLinkProps(options, forwardedRef?) signature is unchanged.

  • Updated dependencies [bc80866, e561fa1, cbbfbe3, a1c8d1a, cbbfbe3, a0b2ad9, 1ca361b]:

    • @​tanstack/router-core@​1.171.31
Changelog

Sourced from @​tanstack/react-router's changelog.

1.170.39

Patch Changes

  • #8435 73bfc15 - Avoid hydration-triggered rerenders for links that do not compare URL hashes while preserving hash-sensitive active state and ClientOnly behavior.

1.170.38

Patch Changes

1.170.37

Patch Changes

  • #8418 e561fa1 - deepEqual now takes its flags as positional arguments — deepEqual(a, b, partial?, explicitUndefined?) — instead of an options object. The router's hot callers (Link option stabilization and active-state checks, matchRoute) no longer allocate an options object per comparison, and the comparator reads two booleans instead of a polymorphic object. explicitUndefined replaces ignoreUndefined: false. deepEqual is an internal helper; it stays exported for compatibility of two-argument calls.

  • #8419 a1c8d1a - resolvePath (internal helper) now takes positional arguments — resolvePath(base, to, trailingSlash?, cache?) — so buildLocation and matchRoute no longer allocate an options object per path resolution.

  • #8204 cbbfbe3 - Stream large deferred SSR hydration payloads through a backpressure-aware router transport, fail known setup errors before response creation, and close cancelled or expired transforms safely.

    Start now cancels discarded middleware and HEAD response bodies, including plain streams and derived branches.

    Server-function raw streams share one ordered response. Arbitrary or sequential consumption can require potentially unbounded buffering of unread data on the client. Cancelling one raw stream discards it locally, while aborting the whole call cancels the response and server work. Consume streams concurrently, cancel unused streams promptly, or use separate calls when independent backpressure is required. A raw stream that exceeds its unread-byte limit now fails alone; sibling streams and the JSON result keep flowing.

    The JSON wire shape of a RawStream server-function argument changed. Clients and servers must run matching versions for requests that pass a RawStream.

    The frame-protocol constants (FRAME_TYPE_*, MAX_FRAME_PAYLOAD_SIZE, MAX_FRAMED_STREAMS) moved from the @tanstack/start-client-core root to the @tanstack/start-client-core/client-rpc subpath.

    Router requests whose Accept header allows neither text/html nor */* now receive 406 Not Acceptable instead of 500.

    Framework adapters share the body <Scripts> composition (getSsrBodyScriptParts, composeSsrBodyScripts) and the eager HTML response wrapper (renderSsrHtmlResponse) from @tanstack/router-core.

    Solid SSR now emits one document type and renders late lazy errors through route boundaries. A Solid <Await> without a fallback no longer holds the streamed shell; it renders inside the nearest <Suspense> boundary like React and Vue, and now renders falsy resolved values.

    Static server functions decode cached RawStream values with the client deserializer plugins.

    SSR Query integrations now keep request cleanup and stream ownership aligned with the router lifecycle.

  • #8420 8e164d2 - useLinkProps no longer calls through an internal wrapper. The host element Link renders on is an @internal overload parameter that is stripped from the published declarations, so the public useLinkProps(options, forwardedRef?) signature is unchanged.

  • Updated dependencies [bc80866, e561fa1, cbbfbe3, a1c8d1a, cbbfbe3, a0b2ad9, 1ca361b]:

    • @​tanstack/router-core@​1.171.31

1.170.36

Patch Changes

... (truncated)

Commits

Updates ai from 7.0.40 to 7.0.114

Changelog

Sourced from ai's changelog.

7.0.114

Patch Changes

  • b5679a7: fix(ai): filter tracing-channel context with telemetry allowlists
  • ca31b89: Clarify in the prompt validation code that allowSystemInMessages permits all system messages, including instruction text.
  • Updated dependencies [124b6ef]
    • @​ai-sdk/gateway@​4.0.92

7.0.113

Patch Changes

  • dcdb011: fix(ai): route completed streamed tool input callbacks to repaired tools

  • 8f72832: fix(ai): preserve video models from legacy fallback providers

  • fe07867: Fix Google embedMany calls with more than 100 values by keeping per-value multimodal content aligned across automatic batches, including text-only entries. Validate content length before sending requests and validate each batch's provider options after middleware transforms them.

  • b74c0cb: fix(ai): resume tool approvals from earlier messages

  • a4b0940: fix(ai): execute manually approved tool inputs produced by schema transforms

    Preserve approved inputs during revalidation and reject histories whose reconstructed schema output differs, including signed approvals with missing original input. Validate transformed UI tool inputs against the reconstructed output before returning them as static tool parts.

  • 2693319: Add Gemini 3.8 TTS support with structured speech metadata and per-turn speaker and style controls for prebuilt voices. Preserve native WAV responses without adding a second header, support explicit raw PCM, mu-law, and A-law output, and identify headerless audio formats correctly. Add the Gemini 3.8 speech model IDs to Google and Gateway types.

    Share transcript and custom-voice inspection through the Google provider internal export, and reject empty speech transcripts before sending a request. Default newer and custom model IDs to structured speech while preserving the legacy format for Gemini 2.5 and 3.1.

  • c93ee90: fix(ai): preserve message history for direct transport stream callbacks

  • 771e74b: chore: enable dead code lint rules

  • Updated dependencies [fe07867]

  • Updated dependencies [a4b0940]

  • Updated dependencies [2693319]

  • Updated dependencies [b73f2f9]

  • Updated dependencies [771e74b]

    • @​ai-sdk/provider-utils@​5.0.47
    • @​ai-sdk/gateway@​4.0.91

7.0.112

Patch Changes

  • 9a98fd9: fix(ai): prune reasoning file parts when removing reasoning
  • a0553d6: feat(ai): report consumer cancellation in UI message stream end callbacks
  • ffb0e76: fix(provider): preserve opaque file URI strings for provider serialization
  • fde0d66: fix(ai): preserve parsed metadata and data values when validating UI messages
  • Updated dependencies [ed5a1d7]
  • Updated dependencies [ffb0e76]
  • Updated dependencies [618dc11]
    • @​ai-sdk/gateway@​4.0.90
    • @​ai-sdk/provider@​4.0.18
    • @​ai-sdk/provider-utils@​5.0.46

... (truncated)

Commits
  • 3f3a717 Version Packages (#21417)
  • d23443d chore: bump generateText bundle size limit to 280kb (#21460)
  • b5679a7 fix: prevent tracing-channel telemetry from exposing context excluded by tele...
  • ca31b89 feat(openai): support message-level reasoning effort updates (#21418)
  • a8961eb docs: refresh model defaults across docs and examples (#21416)
  • 154221f feat: add Anthropic on-demand compaction with signed block round-tripping (#2...
  • 5c830d5 Version Packages (#21370)
  • dcdb011 fix: route the wrong onInputAvailable callback and context after streamed too...
  • 2693319 feat(google): support Gemini 3.8 text-to-speech (#21403)
  • a4b0940 fix: manual tool approvals reject or mutate transformed inputs across model a...
  • Additional commits viewable in compare view

Updates lucide-react from 1.27.0 to 1.48.0

Release notes

Sourced from lucide-react's releases.

Version 1.48.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.47.0...1.48.0

Version 1.47.0

What's Changed

New Contributors

... (truncated)

Commits
  • f06ac67 chore(typchecking): More typecheck jobs for all packages (#4885)
  • 94e4cb9 chore(dependencies): Update dependencies (#4806)
  • 99d25bd feat(packages): extract icon build logic into @lucide/shared (#4409)
  • 75b5516 chore(dev): upgrade ESLint to latest compatible stack (v10) (

…irectory with 21 updates

Bumps the node-production-minor-and-patch group with 21 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.30.0` | `1.30.1` |
| [yaml](https://github.com/eemeli/yaml) | `2.9.0` | `2.9.1` |
| [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.6.5` |
| [@ai-sdk/react](https://github.com/vercel/ai/tree/HEAD/packages/react) | `4.0.43` | `4.0.117` |
| [@lobehub/icons-static-svg](https://github.com/lobehub/lobe-icons) | `1.94.0` | `1.95.1` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.101.4` | `5.103.2` |
| [@tanstack/react-router](https://github.com/TanStack/router/tree/HEAD/packages/react-router) | `1.170.18` | `1.170.39` |
| [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `7.0.40` | `7.0.114` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.27.0` | `1.48.0` |
| [react-error-boundary](https://github.com/bvaughn/react-error-boundary) | `6.1.2` | `6.1.6` |
| [sonner](https://github.com/emilkowalski/sonner) | `2.0.7` | `2.0.8` |
| [streamdown](https://github.com/vercel/streamdown/tree/HEAD/packages/streamdown) | `2.5.0` | `2.6.0` |
| [tailwind-merge](https://github.com/dcastil/tailwind-merge/tree/HEAD/packages/tailwind-merge) | `3.6.0` | `3.7.0` |
| [zustand](https://github.com/pmndrs/zustand) | `5.0.14` | `5.0.15` |
| [@scalar/openapi-upgrader](https://github.com/scalar/scalar/tree/HEAD/packages/openapi-upgrader) | `0.2.11` | `0.3.1` |
| [cnfast](https://github.com/aidenybai/cnfast/tree/HEAD/packages/cnfast) | `0.1.0` | `0.2.0` |
| [fumadocs-core](https://github.com/fuma-nama/fumadocs) | `16.14.0` | `16.15.14` |
| [fumadocs-mdx](https://github.com/fuma-nama/fumadocs) | `15.2.1` | `15.4.4` |
| [next](https://github.com/vercel/next.js) | `16.2.12` | `16.3.6` |
| [shiki](https://github.com/shikijs/shiki/tree/HEAD/packages/shiki) | `4.3.1` | `4.4.3` |
| [keycloakify](https://github.com/keycloakify/keycloakify) | `11.15.14` | `11.16.0` |



Updates `@modelcontextprotocol/sdk` from 1.30.0 to 1.30.1
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@1.30.0...1.30.1)

Updates `yaml` from 2.9.0 to 2.9.1
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.9.0...v2.9.1)

Updates `zod` from 4.4.3 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.4.3...v4.6.5)

Updates `@ai-sdk/react` from 4.0.43 to 4.0.117
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/packages/react/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/@ai-sdk/react@4.0.117/packages/react)

Updates `@lobehub/icons-static-svg` from 1.94.0 to 1.95.1
- [Release notes](https://github.com/lobehub/lobe-icons/releases)
- [Changelog](https://github.com/lobehub/lobe-icons/blob/master/CHANGELOG.md)
- [Commits](https://github.com/lobehub/lobe-icons/compare/@lobehub/icons-static-svg@1.94.0...@lobehub/icons-static-svg@1.95.1)

Updates `@tanstack/react-query` from 5.101.4 to 5.103.2
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.103.2/packages/react-query)

Updates `@tanstack/react-router` from 1.170.18 to 1.170.39
- [Release notes](https://github.com/TanStack/router/releases)
- [Changelog](https://github.com/TanStack/router/blob/main/packages/react-router/CHANGELOG.md)
- [Commits](https://github.com/TanStack/router/commits/@tanstack/react-router@1.170.39/packages/react-router)

Updates `ai` from 7.0.40 to 7.0.114
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/packages/ai/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/ai@7.0.114/packages/ai)

Updates `lucide-react` from 1.27.0 to 1.48.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.48.0/packages/lucide-react)

Updates `react-error-boundary` from 6.1.2 to 6.1.6
- [Release notes](https://github.com/bvaughn/react-error-boundary/releases)
- [Commits](bvaughn/react-error-boundary@6.1.2...6.1.6)

Updates `sonner` from 2.0.7 to 2.0.8
- [Release notes](https://github.com/emilkowalski/sonner/releases)
- [Commits](emilkowalski/sonner@v2.0.7...v2.0.8)

Updates `streamdown` from 2.5.0 to 2.6.0
- [Release notes](https://github.com/vercel/streamdown/releases)
- [Changelog](https://github.com/vercel/streamdown/blob/main/packages/streamdown/CHANGELOG.md)
- [Commits](https://github.com/vercel/streamdown/commits/streamdown@2.6.0/packages/streamdown)

Updates `tailwind-merge` from 3.6.0 to 3.7.0
- [Release notes](https://github.com/dcastil/tailwind-merge/releases)
- [Commits](https://github.com/dcastil/tailwind-merge/commits/tailwind-merge@3.7.0/packages/tailwind-merge)

Updates `zustand` from 5.0.14 to 5.0.15
- [Release notes](https://github.com/pmndrs/zustand/releases)
- [Commits](pmndrs/zustand@v5.0.14...v5.0.15)

Updates `@scalar/openapi-upgrader` from 0.2.11 to 0.3.1
- [Release notes](https://github.com/scalar/scalar/releases)
- [Changelog](https://github.com/scalar/scalar/blob/main/packages/openapi-upgrader/CHANGELOG.md)
- [Commits](https://github.com/scalar/scalar/commits/HEAD/packages/openapi-upgrader)

Updates `cnfast` from 0.1.0 to 0.2.0
- [Release notes](https://github.com/aidenybai/cnfast/releases)
- [Changelog](https://github.com/aidenybai/cnfast/blob/main/packages/cnfast/CHANGELOG.md)
- [Commits](https://github.com/aidenybai/cnfast/commits/cnfast@0.2.0/packages/cnfast)

Updates `fumadocs-core` from 16.14.0 to 16.15.14
- [Release notes](https://github.com/fuma-nama/fumadocs/releases)
- [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs@16.14.0...fumadocs@16.15.14)

Updates `fumadocs-mdx` from 15.2.1 to 15.4.4
- [Release notes](https://github.com/fuma-nama/fumadocs/releases)
- [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs-mdx@15.2.1...fumadocs-mdx@15.4.4)

Updates `next` from 16.2.12 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.2.12...v16.3.6)

Updates `shiki` from 4.3.1 to 4.4.3
- [Release notes](https://github.com/shikijs/shiki/releases)
- [Commits](https://github.com/shikijs/shiki/commits/v4.4.3/packages/shiki)

Updates `keycloakify` from 11.15.14 to 11.16.0
- [Release notes](https://github.com/keycloakify/keycloakify/releases)
- [Commits](keycloakify/keycloakify@v11.15.14...v11.16.0)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.30.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: node-production-minor-and-patch
- dependency-name: yaml
  dependency-version: 2.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: node-production-minor-and-patch
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: node-production-minor-and-patch
- dependency-name: "@ai-sdk/react"
  dependency-version: 4.0.117
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: node-production-minor-and-patch
- dependency-name: "@lobehub/icons-static-svg"
  dependency-version: 1.95.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: node-production-minor-and-patch
- dependency-name: "@tanstack/react-query"
  dependency-version: 5.103.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: node-production-minor-and-patch
- dependency-name: "@tanstack/react-router"
  dependency-version: 1.170.39
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: node-production-minor-and-patch
- dependency-name: ai
  dependency-version: 7.0.114
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: node-production-minor-and-patch
- dependency-name: lucide-react
  dependency-version: 1.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: node-production-minor-and-patch
- dependency-name: react-error-boundary
  dependency-version: 6.1.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: node-production-minor-and-patch
- dependency-name: sonner
  dependency-version: 2.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: node-production-minor-and-patch
- dependency-name: streamdown
  dependency-version: 2.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: node-production-minor-and-patch
- dependency-name: tailwind-merge
  dependency-version: 3.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: node-production-minor-and-patch
- dependency-name: zustand
  dependency-version: 5.0.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: node-production-minor-and-patch
- dependency-name: "@scalar/openapi-upgrader"
  dependency-version: 0.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: node-production-minor-and-patch
- dependency-name: cnfast
  dependency-version: 0.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: node-production-minor-and-patch
- dependency-name: fumadocs-core
  dependency-version: 16.15.14
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: node-production-minor-and-patch
- dependency-name: fumadocs-mdx
  dependency-version: 15.4.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: node-production-minor-and-patch
- dependency-name: next
  dependency-version: 16.3.6
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: node-production-minor-and-patch
- dependency-name: shiki
  dependency-version: 4.4.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: node-production-minor-and-patch
- dependency-name: keycloakify
  dependency-version: 11.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: node-production-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Tegami

This repository uses Tegami to manage releases. When your changes affect published packages, add a changelog file under .tegami/ before merging.

Create a changelog → · Changelog format

Release preview

Package Bump Version
orgmemory minor 0.5.0 → 0.6.0

This PR does not add changelog files. Pending changelogs from other branches are included in the preview above.

Run pnpm run tegami locally to create a changelog interactively.

Managed by Tegami.

@dependabot @github

dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 4, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/node-production-minor-and-patch-3478fa5cf2 branch October 4, 2026 21:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants