Skip to content

chore(deps): bump qs from 6.15.2 to 6.16.0 - #69

Open
dependabot[bot] wants to merge 403 commits into
mainfrom
dependabot/npm_and_yarn/qs-6.16.0
Open

dependabot[bot] wants to merge 403 commits into
mainfrom
dependabot/npm_and_yarn/qs-6.16.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Contributor

Bumps qs from 6.15.2 to 6.16.0.

Changelog

Sourced from qs's changelog.

6.16.0

  • [New] stringify: add a depth option to bound recursion depth (default Infinity)
  • [Fix] stringify: serialize Date values when a filter is provided
  • [Fix] parse: enforce arrayLimit on comma groups under []= when throwOnLimitExceeded is set
  • [Fix] parse: flatten a collection appended to an overflowed array (#571)
  • [Fix] utils: isBuffer: do not invoke a non-callable constructor.isBuffer
  • [Fix] stringify: do not let allowEmptyArrays skip cycle detection (or drop own keys) on an empty array with own properties
  • [Fix] stringify: encode dots in a top-level key with a primitive value when encodeDotInKeys is set (#562)
  • [Docs] threat model: clarify stringify deep-nesting DoS is caller-bounded
  • [Docs] clarify arrayLimit is a representation threshold, not an element-count cap
  • [Tests] parse: remove a test that pinned []= comma groups escaping arrayLimit
  • [Tests] stringify: pin current encodeDotInKeys separator-dot behavior
  • [Dev Deps] update @ljharb/eslint-config, eslint
  • [Dev Deps] update eslint, evalmd

6.15.3

  • [Fix] parse: enforce throwOnLimitExceeded for cumulative array growth via combine/merge
  • [Fix] utils: respect encoding of surrogate pairs across chunks (#559)
  • [Robustness] parse: throw the arrayLimit error before splitting oversized comma values
  • [Robustness] utils.merge / utils.assign: avoid invoking __proto__ setter when copying own properties
  • [Robustness] utils: enforce arrayLimit consistently across merge's array paths
  • [Perf] utils: make compact O(n) via a side-channel visited-set instead of Array.indexOf
  • [Deps] update side-channel
  • [Dev Deps] update eslint, mock-property, tape
  • [Tests] parse: characterize current lenient handling of unbalanced bracket keys (#558)
Commits
  • bb9379e v6.16.0
  • 62fd254 [Fix] stringify: serialize Date values when a filter is provided
  • 8859c37 [Fix] parse: enforce arrayLimit on comma groups under []= when `throwOn...
  • 8079adc [Tests] parse: remove a test that pinned []= comma groups escaping `array...
  • d56f48c [Fix] parse: flatten a collection appended to an overflowed array
  • e83d321 [Fix] utils: isBuffer: do not invoke a non-callable constructor.isBuffer
  • 7e87a07 [Dev Deps] update @ljharb/eslint-config, eslint
  • 9a76af2 [Dev Deps] update eslint, evalmd
  • 3a890d4 [Dev Deps] update eslint, evalmd
  • b433a9b [Fix] stringify: do not let allowEmptyArrays skip cycle detection (or dro...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

vilaca and others added 30 commits May 9, 2026 19:07
…-correct

The corrector helps on a narrow band of failures (typo paths, obvious
arg-shape errors) but on broader categories — Edit's "found N times" and
Read's ENOENT — it works against itself: it rewrites the call from an
8000-char truncated file slice with no fs access, often producing
syntactically different but semantically identical args (the ci.yml
session showed an absolute→relative no-op rewrite that re-failed
identically) or fabricated context lines (the eslint-disable session
fabricated a preceding line that didn't exist next to any match).

The main model has strictly more context (full conversation, prior tool
results, full file content). Its self-recovery on ENOENT (list the dir,
re-read) and on "must be unique" (replace_all=true or add context) is
already first-class. The corrector's only real edge — running on the
weak tier — only pays off when its hit rate is high; the recent samples
suggest it's break-even at best.

Flipping the default to off; users who want it can pass --auto-correct
or toggle via /correct on. Programmatic and TUI defaults follow.
…ault

A repo-root Grep with include_content=true could overflow the 10 MiB
execFile buffer because matches in dist/, dist-test/, and c8 coverage
HTML (which embeds source snippets) compound on top of legit src
matches. The whole call died with "stdout maxBuffer length exceeded"
even though our own MAX_RESULT_LINES=1000 cap would have trimmed the
result to 1000 lines anyway — the cap fired AFTER the buffer.

- Replace execFile with a streaming spawn helper that walks chunks,
  counts newlines, and SIGTERMs the child once we cross
  MAX_RESULT_LINES + 50 slack. The 10 MiB cap is gone; output is
  line-bounded instead. Trims back to the last full newline so the
  downstream filter still sees clean line-oriented data.
- Capture up to 64 KiB of stderr for diagnostics on exit code >= 2.
- Default-exclude dist, dist-test, coverage, and *.tsbuildinfo for
  both rg and grep, alongside the existing node_modules and .git.

Regression test writes a 60 MiB file (12k matches × 5 KiB) and
confirms a cleanly truncated 1001-line result instead of a buffer
overflow.
…ging

Move non-chat-model filtering into each provider's listModels() (the
natural home — providers know their catalog conventions) and emit a
single diagnostic log entry per call listing what was dropped and why.
Drops land in ~/.factory/provider-events.jsonl with action
'list-models-filter', so questions like "why isn't gpt-4o-audio-preview
in my list?" answer themselves from the log.

Replaces the picker's central hardcoded scoring table with tier-based
sort (provider-supplied via existing getCapabilities().modelTier) plus
numeric-descending name tiebreaker so newer versions float above older.

Also fixes interlocking picker bugs: render-time 'hidden' filter that
desynced from selection index, and bypassed prepareModels in the
validation-success and preloaded-models paths. Cache provider
instances by name+keyId so multiple keys for the same provider don't
overwrite each other.
…x variants

OpenAI's /v1/models ships only {id, created, object, owned_by} — every
other capability is inferred from the model id. Six separate startsWith
chains across estimateModelTier, estimateContextWindow, estimateMaxOutput,
isReasoningModel, supportsToolsByName, supportsVisionByName, and
buildModelWarning are replaced by one OPENAI_FAMILIES table with a
longest-prefix-wins lookup. Adding a new flagship is now one row instead
of edits in six functions.

Adds a codingSpecialist? capability flag detected via generic
codex|coder substring match (covers OpenAI's gpt-5-codex line, Qwen's
qwen3-coder, and any future coding-specialist family without per-provider
edits). The picker treats it as a sort-key bump within tier so codex
variants float above generic flagships of the same generation.

buildPickerInfo() extracted to a shared module so Session.tsx and
menu.tsx no longer duplicate the capability-lookup logic.

Documents the picker pipeline, per-provider catalog signals, and what to
update when OpenAI ships a new flagship in docs/picker-internals.md.
When a model id matches a family row in OPENAI_FAMILIES (e.g. `gpt-5`
matches `gpt-5.1-codex-mini`), the row's explicit `tier: 'strong'`
short-circuits before the generic mini/nano regex can fire. The row is
meant to encode the family default, not its mini variants — so
`gpt-5.1-codex-mini` ended up at strong tier and surfaced above
`gpt-5.1-codex` and `gpt-5-codex` in the picker.

Apply the mini/nano demotion on top of `strong` rows. Explicit `medium`
and `weak` rows are left untouched since they already account for being
a mini.
Follow-up to 4ee42a3, which tracked provider in model-change rows but
left three gaps:

- Session.tsx (mid-session picker) and menu.tsx (startup picker) both
  built RecentPair[] from RecentSession but stripped keyId. The picker
  itself already passes pair.keyId to onCommit, and swapProvider already
  accepts a keyId — only the wiring at the source was missing.
  Selecting a recent now resumes against the same saved key the session
  used, instead of falling through to the provider's default key.

- StartupSelection lacked a keyId field, so picker-driven startup
  selections (anything other than the last-session fast-path) lost the
  keyId before it reached resolveProvider. Threaded through.

- The key-rotation event handler updated refs.activeKeyId in memory but
  didn't write a model-change row, so rollupSessionLines kept the
  original keyId from session-start. After tier-1 rotation,
  getLastSessionSelection / getRecentSessions surfaced a stale keyId
  (often the one that just rate-limited). Logging a same-model
  model-change with the new keyId lets rollup track it; rollup already
  handles entry.to === entry.from since the only check is against the
  STARTUP placeholder.

Tests:
- session-log: same-model model-change updates rollup keyId.
- event-handler: key-rotation calls logModelChange(model, model, newKey)
  and tolerates refs===null.
- event-handler: tuple-rotation calls
  logModelChange(fromModel, toModel, activeKeyId, toProvider) — was not
  covered before.
OpenAI's codex family (gpt-5-codex, gpt-5.1-codex, gpt-5.3-codex,
gpt-5.1-codex-mini) is served only on /v1/responses; the chat-
completions endpoint returns 404 "This is not a chat model". Adds a
Responses-API transport path inside OpenAIProvider, gated on a
`/codex/i` substring check — same pattern the picker uses for
codingSpecialist, so dotted minors route without one row per variant.
Other providers that share the chat-completions plumbing are
untouched.

The Responses API uses a different request shape (`input` instead of
`messages`, flat tool definitions, `max_output_tokens`, `instructions`
hoisted from the first system message) and a different SSE event
protocol (output_item.added, output_text.delta,
function_call_arguments.delta/done, completed). New modules:

- responses-messages.ts: body + input/tool mappers
- responses-tool-calls.ts: accumulator keyed by output_index
- responses-usage.ts: usage extractor including reasoning_tokens
- responses-stream.ts: streaming + non-streaming transport

Adds `reasoningTokens` to TokenUsage so codex's hidden-reasoning
output bill is surfaced separately from the visible answer.

`previous_response_id` chain tracking (cost optimization that lets
codex reuse server-side reasoning across turns) is deferred to a
follow-up — it needs agent-loop wiring for compaction/clear/swap/abort
invalidation and ships better on its own.
Pasted blocks were clipped at the first newline because Enter submitted
mid-paste. Switch the session prompt to multiline mode: capture pastes
via usePaste, allow Alt+Enter to insert a literal newline, and render
the buffer as a vertical row stack so the cursor highlight stays correct.
…rompt

- Quote Grep/Glob pattern args in tool-call summaries so values
  containing spaces or metacharacters are unambiguous. Driven by a
  small QUOTE_PRIMARY_ARG set keyed off TOOL_NAMES.

- Collapse the empty-success tool-result render into a single green
  "    ◌ <body>" row (continuation lines hang at 6-space indent)
  instead of the previous two-line yellow ○ header + dim body. Drops
  the matching TODO that asked for this consolidation.

- Render the "Allow X?" permission prompt with a blank line above and
  paddingLeft=4 so it aligns with tool args / tool-result lines and
  visually belongs to the preceding tool-call panel.
Codex generates 5–15k hidden reasoning tokens per turn, billed at
o-series output rates. Without `previous_response_id` the model
re-derives reasoning from scratch every turn — on a 10-turn agentic
flow that's a real money difference.

Wires through OpenAI's stored-response chain. The provider now sends
`store: true` on every /v1/responses call, captures `response.id`
from the terminal chunk, and surfaces it on `ChatChunk.responseId`.
The agent loop holds the pointer in `RunRefs.responsesChain` (TUI) or
a closure-state ref (headless) and feeds it back via
`ChatOptions.responsesChain` on the next call. The body builder slices
input to `messages[messageCount:]` and adds `previous_response_id` so
the server reuses prior reasoning instead of re-running it.

The chain shape carries `provider`, `model`, and `keyId` for use-site
validation: a stale pointer left over from a missed reset path is
silently dropped rather than corrupting the next call. Reset paths:

- /clear (use-agent-loop.clearConversation)
- /provider, /model swap (swap.ts)
- Tier-1 key rotation (onActiveKeyChange in run-loop)
- Tier-2 (provider, model) rotation (run-agent finalProvider/finalModel)
- Compaction (new `compacted: true` flag on CompactionDecision)
- Aborted turn (run-agent before partial-content addAssistant)

Privacy note: `store: true` means OpenAI retains responses ~30 days.
Documented in the responses-messages comment block; users who don't
want this should pick a non-codex model.

callModel's signature gained one parameter beyond the lint cap, so
trailing args (`signal`, `rotation`, `chatOptions`) collapsed into a
single `extras` options bag. Updated existing call sites in tests.
…eamble

Codex and gpt-5 stall into deferential narration when reasoning is off and
the system prompt lacks an explicit persistence directive — observed in a
real session where seven consecutive turns produced text-only continuations
after the user typed "ok"/"go". Both gaps are flagged by OpenAI's GPT-5
troubleshooting cookbook.

- Plumb ChatOptions.reasoningEffort into the Responses API path; default to
  'medium' for codex variants, 'low' for other reasoning models, none for
  non-reasoning models. Caller overrides win.
- Add a per-provider agentic persistence block to buildSystemPrompt; emitted
  only when provider=openai. Anthropic is already action-biased and would
  be made worse by it.

Refs:
  https://developers.openai.com/cookbook/examples/gpt-5/gpt-5_troubleshooting_guide
  https://platform.openai.com/docs/guides/reasoning
…inish_reason plumbing

Closes a real latent bug and rounds out the cross-provider terminal-reason
surface introduced alongside the codex/gpt-5 changes.

Bug fixes
- Chain bookkeeping was asymmetric: buildResponsesBody dropped the inbound
  chain pointer when store=false, but the provider still surfaced the
  response id, so the agent layer captured an unreferenceable id and the
  next call sent `previous_response_id: <X>` for an unstored response →
  silent 404. Fix at the wire boundary: streamOpenAiResponses and
  sendOpenAiResponses now suppress responseId when body.store === false
  via a shared isChainable() helper. chainRef can no longer hold a poisoned
  id regardless of how options thread.
- recoverViaNonStream dropped doneReason when falling back from an SSE
  failure to chatNoStream. SSE-fail-then-recover paths now propagate
  doneReason so output-cap-reached / output-blocked still fire on
  truncations and refusals seen via the recovery channel.

New event: output-blocked
- Distinct from the natural turn-complete: provider classifier blocked the
  response or the model refused. Carries a `reason` string so the renderer
  can choose the notice text. Wired in headless (stderr warning) and TUI
  (danger-level notice).
- run-agent dispatches on `content_filter` (OpenAI) and `refusal`
  (Anthropic 4.x). Mapping table is documented in both the event-type
  JSDoc and the inline comment at the dispatch site so a future provider
  contributor knows where to extend.

Anthropic stop_reason mapping (was unwired, now real)
- src/providers/anthropic.ts maps native stop_reason to the agent layer's
  cross-provider doneReason vocabulary:
    max_tokens → 'length'  (output-cap-reached now fires for Anthropic)
    refusal    → 'refusal' (output-blocked fires when Claude declines)
    natural stops (end_turn, stop_sequence, tool_use, pause_turn) → unset
  Streaming reads delta.stop_reason from message_delta events; non-stream
  reads response.stop_reason. Both paths covered.

Parallel tool calls flip
- supportsParallelToolCalls() is now /^o\d/i instead of isReasoningModel().
  gpt-5 and codex are reasoning models too but they support parallel tool
  calls — the GPT-5 cookbook explicitly recommends parallelization for
  read-only tool batches. Effect: OpenAI request bodies for gpt-5 and codex
  now include `parallel_tool_calls: true` where they previously had it
  stripped. Anyone diffing wire-format snapshots in CI needs to update.
  Inline comment now spells out the rationale.

Doc fixes
- responses-messages.ts:toResponsesInput comment said "first contiguous
  system messages collapse"; the code only ever hoists index 0, so a
  second contiguous system at index 1 falls through to inline. Comment
  now matches reality.
- responses-messages.ts:toResponsesTools comment now describes the strict
  parameter and notes the closed-form-schema requirement.
- responses-messages.ts:buildResponsesBody comment explains store/chain
  incompatibility.
- types.ts:ChatChunk.done documents the multi-emit shape (the OpenAI chat
  stream yields a first done with usage/doneReason then a second with
  finalized tool_calls — consumers must iterate to generator end).
- docs/providers.md corrects the OpenAI row: parallel_tool_calls is now
  dropped only for o-series, codex routes through /v1/responses with
  per-model reasoning.effort defaults.

Tests (+6 unit, +1 file)
- agent-output-blocked.test.ts: orchestration-level coverage for
  content_filter/refusal → output-blocked, plus negative cases (natural
  stops don't fire, length triggers output-cap-reached not output-blocked).
- responses-stream.test.ts: terminal chunk omits responseId when
  body.store=false; counter-test confirms it surfaces when store defaults.
- openai-provider.test.ts: same suppression on the chat-completions/
  responses non-stream path; preservation when default; finish_reason
  forwarding for length truncation; dotted-codex capability normalization;
  store=false + tool_strict=true wire-shape.
- responses-helpers.test.ts: chain pointer is dropped when store=false
  (input-side regression for the bug above); strict tool flag passes
  through.
- agent-helpers.ts: MockResponse gains optional doneReason; existing tests
  unaffected (usage only attached when the test sets it).

Not user-facing (intentional, deferred exposure)
- ChatOptions.responsesStore and ChatOptions.toolStrict are set only by
  tests today. Establishing the wire-format surface now; CLI/config wiring
  deferred until there's a use case (toolStrict needs a tool-schema audit
  before enabling broadly; responsesStore needs per-provider config + a
  cost-warning UI for the chain-cost change).
New per-call ChatOptions for the OpenAI provider: promptCacheKey,
serviceTier, seed, safetyIdentifier, metadata, truncationAuto,
responseFormat, reasoningSummary. Wired through both the chat-completions
and Responses request builders via shared applyCommonOpenAiOptions +
buildJsonSchemaFormat helpers.

store=false path: FACTORY_OPENAI_RESPONSES_STORE env override; request
side now sends include: ["reasoning.encrypted_content"]. Capture/replay
half remains TODO'd in responses-stream.ts.

Auto-strict tool calling: isStrictCompatible() schema validator gates
function.strict per-tool. Chat path opts in only when toolStrict=true
(safer for OpenAI-compat backends); Responses path always emits strict
as it's OpenAI-only.

SSE plumbing: dedicated SseIdleTimeoutError + OpenAiSseIdleAbortReason
classes replace fragile error.message string matching. Shared
stream-common.ts dedupes openAiSseIdleTimeoutMs and
createLinkedAbortController between stream.ts and responses-stream.ts.

Tests: sse-test-helpers.ts consolidates withSseServer / withFailingServer
/ withHangingSseServer factories used by both transport test files;
~160 LOC of duplication removed. Added 7 isStrictCompatible cases and
updated the toResponsesTools strict-gating test for the new behavior.
82/82 OpenAI tests pass.

Docs: documented FACTORY_OPENAI_SSE_IDLE_TIMEOUT_MS and
FACTORY_OPENAI_RESPONSES_STORE in docs/configuration.md; added a note
in docs/troubleshooting.md explaining the new 504 idle-timeout surface.

Inline TODO comments mark the remaining P0/P1/P2 parity work
(model-aware idle timeout, request-level cap, Retry-After honor,
x-request-id propagation, stream_options.include_usage, encrypted
reasoning capture/replay, vision content, responsesStore config wiring).
…up (#1)

Bumps the dev-minor group with 1 update: [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip).


Updates `knip` from 6.12.1 to 6.12.2
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.12.2/packages/knip)

---
updated-dependencies:
- dependency-name: knip
  dependency-version: 6.12.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot Bot and others added 25 commits July 3, 2026 11:31
Bumps [ws](https://github.com/websockets/ws) from 8.20.1 to 8.21.0.
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.20.1...8.21.0)

---
updated-dependencies:
- dependency-name: ws
  dependency-version: 8.21.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [hono](https://github.com/honojs/hono) from 4.12.23 to 4.12.26.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.12.23...v4.12.26)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.12.26
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…tes (#32)

Bumps the prod-minor group with 4 updates in the / directory: [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript), [@huggingface/inference](https://github.com/huggingface/huggingface.js), [google-auth-library](https://github.com/googleapis/google-cloud-node/tree/HEAD/core/packages/google-auth-library-nodejs) and [ink](https://github.com/vadimdemedes/ink).


Updates `@anthropic-ai/sdk` from 0.104.1 to 0.110.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.104.1...sdk-v0.110.0)

Updates `@huggingface/inference` from 4.13.18 to 4.13.22
- [Release notes](https://github.com/huggingface/huggingface.js/releases)
- [Commits](huggingface/huggingface.js@inference-v4.13.18...inference-v4.13.22)

Updates `google-auth-library` from 10.7.0 to 10.9.0
- [Release notes](https://github.com/googleapis/google-cloud-node/releases)
- [Changelog](https://github.com/googleapis/google-cloud-node/blob/main/core/packages/google-auth-library-nodejs/CHANGELOG.md)
- [Commits](https://github.com/googleapis/google-cloud-node/commits/google-auth-library-v10.9.0/core/packages/google-auth-library-nodejs)

Updates `ink` from 7.0.6 to 7.1.0
- [Release notes](https://github.com/vadimdemedes/ink/releases)
- [Commits](vadimdemedes/ink@v7.0.6...v7.1.0)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.106.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor
- dependency-name: "@huggingface/inference"
  dependency-version: 4.13.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-minor
- dependency-name: google-auth-library
  dependency-version: 10.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor
- dependency-name: ink
  dependency-version: 7.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.15 to 8.5.25.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.15...8.5.25)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.25
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [hono](https://github.com/honojs/hono) from 4.12.26 to 4.13.0.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.12.26...v4.13.0)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.13.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.2.0 to 10.4.0.
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](beaugunderson/ip-address@v10.2.0...v10.4.0)

---
updated-dependencies:
- dependency-name: ip-address
  dependency-version: 10.4.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…tes (#49)

Bumps the prod-minor group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) | `0.110.0` | `0.115.0` |
| [@huggingface/inference](https://github.com/huggingface/huggingface.js) | `4.13.22` | `4.13.23` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.29.0` | `1.30.0` |
| [ink](https://github.com/vadimdemedes/ink) | `7.1.0` | `7.1.1` |
| [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.7` | `19.2.8` |



Updates `@anthropic-ai/sdk` from 0.110.0 to 0.115.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.110.0...sdk-v0.115.0)

Updates `@huggingface/inference` from 4.13.22 to 4.13.23
- [Release notes](https://github.com/huggingface/huggingface.js/releases)
- [Commits](huggingface/huggingface.js@inference-v4.13.22...inference-v4.13.23)

Updates `@modelcontextprotocol/sdk` from 1.29.0 to 1.30.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@v1.29.0...1.30.0)

Updates `ink` from 7.1.0 to 7.1.1
- [Release notes](https://github.com/vadimdemedes/ink/releases)
- [Commits](vadimdemedes/ink@v7.1.0...v7.1.1)

Updates `react` from 19.2.7 to 19.2.8
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.2.8/packages/react)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.115.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor
- dependency-name: "@huggingface/inference"
  dependency-version: 4.13.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-minor
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.30.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor
- dependency-name: ink
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-minor
- dependency-name: react
  dependency-version: 19.2.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.6 to 5.0.9.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.6...v5.0.9)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 5.0.9
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 3.1.5.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.2...v3.1.5)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [body-parser](https://github.com/expressjs/body-parser) from 2.2.2 to 2.3.0.
- [Release notes](https://github.com/expressjs/body-parser/releases)
- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md)
- [Commits](expressjs/body-parser@v2.2.2...v2.3.0)

---
updated-dependencies:
- dependency-name: body-parser
  dependency-version: 2.3.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [hono](https://github.com/honojs/hono) from 4.13.0 to 4.13.1.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.0...v4.13.1)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.13.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@hono/node-server](https://github.com/honojs/node-server) from 1.19.14 to 2.1.0.
- [Release notes](https://github.com/honojs/node-server/releases)
- [Commits](honojs/node-server@v1.19.14...v2.1.0)

---
updated-dependencies:
- dependency-name: "@hono/node-server"
  dependency-version: 2.1.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…pdates (#35)

Bumps the dev-minor group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `22.19.21` | `22.20.1` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.61.0` | `8.66.0` |
| [archunit](https://github.com/LukasNiessen/ArchUnitTS) | `2.3.0` | `2.4.0` |
| [eslint](https://github.com/eslint/eslint) | `10.5.0` | `10.8.0` |
| [eslint-plugin-sonarjs](https://github.com/SonarSource/SonarJS) | `4.0.3` | `4.2.0` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.16.1` | `6.31.0` |
| [prettier](https://github.com/prettier/prettier) | `3.8.4` | `3.9.6` |
| [tsx](https://github.com/privatenumber/tsx) | `4.22.4` | `4.23.5` |



Updates `@types/node` from 22.19.21 to 22.20.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@typescript-eslint/eslint-plugin` from 8.61.0 to 8.66.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.66.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.61.0 to 8.66.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.66.0/packages/parser)

Updates `archunit` from 2.3.0 to 2.4.0
- [Release notes](https://github.com/LukasNiessen/ArchUnitTS/releases)
- [Changelog](https://github.com/LukasNiessen/ArchUnitTS/blob/main/CHANGELOG.md)
- [Commits](LukasNiessen/ArchUnitTS@v2.3.0...v2.4.0)

Updates `eslint` from 10.5.0 to 10.8.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.5.0...v10.8.0)

Updates `eslint-plugin-sonarjs` from 4.0.3 to 4.2.0
- [Release notes](https://github.com/SonarSource/SonarJS/releases)
- [Changelog](https://github.com/SonarSource/SonarJS/blob/master/docs/RELEASE.md)
- [Commits](https://github.com/SonarSource/SonarJS/commits)

Updates `knip` from 6.16.1 to 6.31.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.31.0/packages/knip)

Updates `prettier` from 3.8.4 to 3.9.6
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.8.4...3.9.6)

Updates `tsx` from 4.22.4 to 4.23.5
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.22.4...v4.23.5)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 22.20.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.62.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.62.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: archunit
  dependency-version: 2.3.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-minor
- dependency-name: eslint
  dependency-version: 10.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: eslint-plugin-sonarjs
  dependency-version: 4.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: knip
  dependency-version: 6.24.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: prettier
  dependency-version: 3.9.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: tsx
  dependency-version: 4.23.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Collapse short union types onto single lines per prettier 3.9's
formatting; fixes the advisory format-check CI job.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
Bumps [c8](https://github.com/bcoe/c8) from 11.0.0 to 12.0.0.
- [Release notes](https://github.com/bcoe/c8/releases)
- [Changelog](https://github.com/bcoe/c8/blob/main/CHANGELOG.md)
- [Commits](bcoe/c8@v11.0.0...v12.0.0)

---
updated-dependencies:
- dependency-name: c8
  dependency-version: 12.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [chalk](https://github.com/chalk/chalk) from 5.6.2 to 6.0.0.
- [Release notes](https://github.com/chalk/chalk/releases)
- [Commits](chalk/chalk@v5.6.2...v6.0.0)

---
updated-dependencies:
- dependency-name: chalk
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@lydell/node-pty](https://github.com/lydell/node-pty) from 1.2.0-beta.12 to 1.2.0-beta.14.
- [Release notes](https://github.com/lydell/node-pty/releases)
- [Commits](lydell/node-pty@v1.2.0-beta.12...v1.2.0-beta.14)

---
updated-dependencies:
- dependency-name: "@lydell/node-pty"
  dependency-version: 1.2.0-beta.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [google-auth-library](https://github.com/googleapis/google-cloud-node/tree/HEAD/core/packages/google-auth-library-nodejs) from 10.9.0 to 11.0.0.
- [Release notes](https://github.com/googleapis/google-cloud-node/releases)
- [Changelog](https://github.com/googleapis/google-cloud-node/blob/main/core/packages/google-auth-library-nodejs/CHANGELOG.md)
- [Commits](https://github.com/googleapis/google-cloud-node/commits/google-auth-library-v11.0.0/core/packages/google-auth-library-nodejs)

---
updated-dependencies:
- dependency-name: google-auth-library
  dependency-version: 11.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the prod-minor group with 1 update: [@huggingface/inference](https://github.com/huggingface/huggingface.js).


Updates `@huggingface/inference` from 4.13.23 to 4.13.25
- [Release notes](https://github.com/huggingface/huggingface.js/releases)
- [Commits](huggingface/huggingface.js@inference-v4.13.23...inference-v4.13.25)

---
updated-dependencies:
- dependency-name: "@huggingface/inference"
  dependency-version: 4.13.25
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the dev-minor group with 2 updates: [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) and [tsx](https://github.com/privatenumber/tsx).


Updates `knip` from 6.31.0 to 6.32.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.32.0/packages/knip)

Updates `tsx` from 4.23.5 to 4.23.10
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.5...v4.23.10)

---
updated-dependencies:
- dependency-name: knip
  dependency-version: 6.32.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: tsx
  dependency-version: 4.23.10
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the dev-minor group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.66.0` | `8.67.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.66.0` | `8.67.0` |
| [eslint](https://github.com/eslint/eslint) | `10.8.0` | `10.8.1` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.32.0` | `6.32.2` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.10` | `4.23.12` |


Updates `@typescript-eslint/eslint-plugin` from 8.66.0 to 8.67.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.67.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.66.0 to 8.67.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.67.0/packages/parser)

Updates `eslint` from 10.8.0 to 10.8.1
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.8.0...v10.8.1)

Updates `knip` from 6.32.0 to 6.32.2
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.32.2/packages/knip)

Updates `tsx` from 4.23.10 to 4.23.12
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.10...v4.23.12)

---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.67.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.67.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: eslint
  dependency-version: 10.8.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-minor
- dependency-name: knip
  dependency-version: 6.32.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-minor
- dependency-name: tsx
  dependency-version: 4.23.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the prod-minor group with 3 updates: [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript), [@huggingface/inference](https://github.com/huggingface/huggingface.js) and [google-auth-library](https://github.com/googleapis/google-cloud-node/tree/HEAD/core/packages/google-auth-library-nodejs).


Updates `@anthropic-ai/sdk` from 0.115.0 to 0.117.1
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.115.0...sdk-v0.117.1)

Updates `@huggingface/inference` from 4.13.25 to 4.13.26
- [Release notes](https://github.com/huggingface/huggingface.js/releases)
- [Commits](huggingface/huggingface.js@inference-v4.13.25...inference-v4.13.26)

Updates `google-auth-library` from 11.0.0 to 11.0.2
- [Release notes](https://github.com/googleapis/google-cloud-node/releases)
- [Changelog](https://github.com/googleapis/google-cloud-node/blob/main/core/packages/google-auth-library-nodejs/CHANGELOG.md)
- [Commits](https://github.com/googleapis/google-cloud-node/commits/google-auth-library-v11.0.2/core/packages/google-auth-library-nodejs)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.117.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor
- dependency-name: "@huggingface/inference"
  dependency-version: 4.13.26
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-minor
- dependency-name: google-auth-library
  dependency-version: 11.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@lydell/node-pty](https://github.com/lydell/node-pty) from 1.2.0-beta.14 to 1.2.0-beta.15.
- [Release notes](https://github.com/lydell/node-pty/releases)
- [Commits](lydell/node-pty@v1.2.0-beta.14...v1.2.0-beta.15)

---
updated-dependencies:
- dependency-name: "@lydell/node-pty"
  dependency-version: 1.2.0-beta.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the prod-minor group with 2 updates: [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) and [@huggingface/inference](https://github.com/huggingface/huggingface.js).


Updates `@anthropic-ai/sdk` from 0.117.1 to 0.120.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.117.1...sdk-v0.120.0)

Updates `@huggingface/inference` from 4.13.26 to 4.13.28
- [Release notes](https://github.com/huggingface/huggingface.js/releases)
- [Commits](huggingface/huggingface.js@inference-v4.13.26...inference-v4.13.28)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.120.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor
- dependency-name: "@huggingface/inference"
  dependency-version: 4.13.28
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [qs](https://github.com/ljharb/qs) from 6.15.2 to 6.16.0.
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.15.2...v6.16.0)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.16.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 3, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant