Skip to content

chore(deps): bump hono from 4.13.1 to 4.13.7 - #71

Open
dependabot[bot] wants to merge 403 commits into
mainfrom
dependabot/npm_and_yarn/hono-4.13.7
Open

dependabot[bot] wants to merge 403 commits into
mainfrom
dependabot/npm_and_yarn/hono-4.13.7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 10, 2026

Copy link
Copy Markdown
Contributor

Bumps hono from 4.13.1 to 4.13.7.

Release notes

Sourced from hono's releases.

v4.13.7

Security fixes

This release includes a fix for the following security issue:

hono/jsx renders plain strings unescaped in boundary components, leading to XSS

Affects: Suspense, ErrorBoundary, and Context.Provider in hono/jsx, and renderToString() / renderToReadableStream() in hono/jsx/dom/server. Fixes missing HTML escaping for a plain string placed directly as a child or fallback of these components, or as the root value of the server rendering functions, so untrusted strings could be emitted as markup. GHSA-hxh3-vqpv-xpqv


Users who render untrusted strings inside Suspense, ErrorBoundary, or Context.Provider, or pass them directly to hono/jsx/dom/server, are strongly encouraged to upgrade to this version.

v4.13.6

What's Changed

Full Changelog: honojs/hono@v4.13.5...v4.13.6

v4.13.5

Security fixes

This release includes fixes for the following security issues:

Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

Affects: Cache Middleware and applications behind a proxy, WAF, or logging layer that inspects query strings. Fixes query parsing that did not stop at the URL fragment, so a ? after a # was treated as the start of a query string and the application could read parameters that the other component never saw. GHSA-crvj-82cr-hjcx

Incomplete fix for CVE-2026-39408: toSSG() still writes files outside the output directory

Affects: toSSG() for Static Site Generation. Fixes a path normalization gap where consecutive parent-directory segments in ssgParams values were not fully collapsed, bypassing the containment check added in 4.12.12. GHSA-gqvv-2mrq-wpjv

Unbounded dot-notation nesting in parseBody() can cause memory exhaustion

Affects: parseBody() when dot-notation parsing is enabled. Fixes unbounded expansion of dot-separated field names, where a small request body could allocate a disproportionately large object graph and concurrent requests could exhaust the heap. GHSA-g6gw-c38x-mqfc


Users who use Cache Middleware, deploy behind a proxy or WAF that inspects query strings, use Static Site Generation, or use parseBody({ dot: true }) are strongly encouraged to upgrade to this version.

v4.13.4

What's Changed

  • fix(request): handle params on unmatched requests in honojs/hono#5268
  • fix(jsx/dom): execute previous ref cleanup when ref prop changes on re-render in honojs/hono#5264
  • fix(reg-exp-router): associate wildcard middleware with matching routes in honojs/hono#5266
  • perf(router): share null object creation in honojs/hono#5267

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

vilaca and others added 30 commits May 9, 2026 19:07
…-correct

The corrector helps on a narrow band of failures (typo paths, obvious
arg-shape errors) but on broader categories — Edit's "found N times" and
Read's ENOENT — it works against itself: it rewrites the call from an
8000-char truncated file slice with no fs access, often producing
syntactically different but semantically identical args (the ci.yml
session showed an absolute→relative no-op rewrite that re-failed
identically) or fabricated context lines (the eslint-disable session
fabricated a preceding line that didn't exist next to any match).

The main model has strictly more context (full conversation, prior tool
results, full file content). Its self-recovery on ENOENT (list the dir,
re-read) and on "must be unique" (replace_all=true or add context) is
already first-class. The corrector's only real edge — running on the
weak tier — only pays off when its hit rate is high; the recent samples
suggest it's break-even at best.

Flipping the default to off; users who want it can pass --auto-correct
or toggle via /correct on. Programmatic and TUI defaults follow.
…ault

A repo-root Grep with include_content=true could overflow the 10 MiB
execFile buffer because matches in dist/, dist-test/, and c8 coverage
HTML (which embeds source snippets) compound on top of legit src
matches. The whole call died with "stdout maxBuffer length exceeded"
even though our own MAX_RESULT_LINES=1000 cap would have trimmed the
result to 1000 lines anyway — the cap fired AFTER the buffer.

- Replace execFile with a streaming spawn helper that walks chunks,
  counts newlines, and SIGTERMs the child once we cross
  MAX_RESULT_LINES + 50 slack. The 10 MiB cap is gone; output is
  line-bounded instead. Trims back to the last full newline so the
  downstream filter still sees clean line-oriented data.
- Capture up to 64 KiB of stderr for diagnostics on exit code >= 2.
- Default-exclude dist, dist-test, coverage, and *.tsbuildinfo for
  both rg and grep, alongside the existing node_modules and .git.

Regression test writes a 60 MiB file (12k matches × 5 KiB) and
confirms a cleanly truncated 1001-line result instead of a buffer
overflow.
…ging

Move non-chat-model filtering into each provider's listModels() (the
natural home — providers know their catalog conventions) and emit a
single diagnostic log entry per call listing what was dropped and why.
Drops land in ~/.factory/provider-events.jsonl with action
'list-models-filter', so questions like "why isn't gpt-4o-audio-preview
in my list?" answer themselves from the log.

Replaces the picker's central hardcoded scoring table with tier-based
sort (provider-supplied via existing getCapabilities().modelTier) plus
numeric-descending name tiebreaker so newer versions float above older.

Also fixes interlocking picker bugs: render-time 'hidden' filter that
desynced from selection index, and bypassed prepareModels in the
validation-success and preloaded-models paths. Cache provider
instances by name+keyId so multiple keys for the same provider don't
overwrite each other.
…x variants

OpenAI's /v1/models ships only {id, created, object, owned_by} — every
other capability is inferred from the model id. Six separate startsWith
chains across estimateModelTier, estimateContextWindow, estimateMaxOutput,
isReasoningModel, supportsToolsByName, supportsVisionByName, and
buildModelWarning are replaced by one OPENAI_FAMILIES table with a
longest-prefix-wins lookup. Adding a new flagship is now one row instead
of edits in six functions.

Adds a codingSpecialist? capability flag detected via generic
codex|coder substring match (covers OpenAI's gpt-5-codex line, Qwen's
qwen3-coder, and any future coding-specialist family without per-provider
edits). The picker treats it as a sort-key bump within tier so codex
variants float above generic flagships of the same generation.

buildPickerInfo() extracted to a shared module so Session.tsx and
menu.tsx no longer duplicate the capability-lookup logic.

Documents the picker pipeline, per-provider catalog signals, and what to
update when OpenAI ships a new flagship in docs/picker-internals.md.
When a model id matches a family row in OPENAI_FAMILIES (e.g. `gpt-5`
matches `gpt-5.1-codex-mini`), the row's explicit `tier: 'strong'`
short-circuits before the generic mini/nano regex can fire. The row is
meant to encode the family default, not its mini variants — so
`gpt-5.1-codex-mini` ended up at strong tier and surfaced above
`gpt-5.1-codex` and `gpt-5-codex` in the picker.

Apply the mini/nano demotion on top of `strong` rows. Explicit `medium`
and `weak` rows are left untouched since they already account for being
a mini.
Follow-up to 4ee42a3, which tracked provider in model-change rows but
left three gaps:

- Session.tsx (mid-session picker) and menu.tsx (startup picker) both
  built RecentPair[] from RecentSession but stripped keyId. The picker
  itself already passes pair.keyId to onCommit, and swapProvider already
  accepts a keyId — only the wiring at the source was missing.
  Selecting a recent now resumes against the same saved key the session
  used, instead of falling through to the provider's default key.

- StartupSelection lacked a keyId field, so picker-driven startup
  selections (anything other than the last-session fast-path) lost the
  keyId before it reached resolveProvider. Threaded through.

- The key-rotation event handler updated refs.activeKeyId in memory but
  didn't write a model-change row, so rollupSessionLines kept the
  original keyId from session-start. After tier-1 rotation,
  getLastSessionSelection / getRecentSessions surfaced a stale keyId
  (often the one that just rate-limited). Logging a same-model
  model-change with the new keyId lets rollup track it; rollup already
  handles entry.to === entry.from since the only check is against the
  STARTUP placeholder.

Tests:
- session-log: same-model model-change updates rollup keyId.
- event-handler: key-rotation calls logModelChange(model, model, newKey)
  and tolerates refs===null.
- event-handler: tuple-rotation calls
  logModelChange(fromModel, toModel, activeKeyId, toProvider) — was not
  covered before.
OpenAI's codex family (gpt-5-codex, gpt-5.1-codex, gpt-5.3-codex,
gpt-5.1-codex-mini) is served only on /v1/responses; the chat-
completions endpoint returns 404 "This is not a chat model". Adds a
Responses-API transport path inside OpenAIProvider, gated on a
`/codex/i` substring check — same pattern the picker uses for
codingSpecialist, so dotted minors route without one row per variant.
Other providers that share the chat-completions plumbing are
untouched.

The Responses API uses a different request shape (`input` instead of
`messages`, flat tool definitions, `max_output_tokens`, `instructions`
hoisted from the first system message) and a different SSE event
protocol (output_item.added, output_text.delta,
function_call_arguments.delta/done, completed). New modules:

- responses-messages.ts: body + input/tool mappers
- responses-tool-calls.ts: accumulator keyed by output_index
- responses-usage.ts: usage extractor including reasoning_tokens
- responses-stream.ts: streaming + non-streaming transport

Adds `reasoningTokens` to TokenUsage so codex's hidden-reasoning
output bill is surfaced separately from the visible answer.

`previous_response_id` chain tracking (cost optimization that lets
codex reuse server-side reasoning across turns) is deferred to a
follow-up — it needs agent-loop wiring for compaction/clear/swap/abort
invalidation and ships better on its own.
Pasted blocks were clipped at the first newline because Enter submitted
mid-paste. Switch the session prompt to multiline mode: capture pastes
via usePaste, allow Alt+Enter to insert a literal newline, and render
the buffer as a vertical row stack so the cursor highlight stays correct.
…rompt

- Quote Grep/Glob pattern args in tool-call summaries so values
  containing spaces or metacharacters are unambiguous. Driven by a
  small QUOTE_PRIMARY_ARG set keyed off TOOL_NAMES.

- Collapse the empty-success tool-result render into a single green
  "    ◌ <body>" row (continuation lines hang at 6-space indent)
  instead of the previous two-line yellow ○ header + dim body. Drops
  the matching TODO that asked for this consolidation.

- Render the "Allow X?" permission prompt with a blank line above and
  paddingLeft=4 so it aligns with tool args / tool-result lines and
  visually belongs to the preceding tool-call panel.
Codex generates 5–15k hidden reasoning tokens per turn, billed at
o-series output rates. Without `previous_response_id` the model
re-derives reasoning from scratch every turn — on a 10-turn agentic
flow that's a real money difference.

Wires through OpenAI's stored-response chain. The provider now sends
`store: true` on every /v1/responses call, captures `response.id`
from the terminal chunk, and surfaces it on `ChatChunk.responseId`.
The agent loop holds the pointer in `RunRefs.responsesChain` (TUI) or
a closure-state ref (headless) and feeds it back via
`ChatOptions.responsesChain` on the next call. The body builder slices
input to `messages[messageCount:]` and adds `previous_response_id` so
the server reuses prior reasoning instead of re-running it.

The chain shape carries `provider`, `model`, and `keyId` for use-site
validation: a stale pointer left over from a missed reset path is
silently dropped rather than corrupting the next call. Reset paths:

- /clear (use-agent-loop.clearConversation)
- /provider, /model swap (swap.ts)
- Tier-1 key rotation (onActiveKeyChange in run-loop)
- Tier-2 (provider, model) rotation (run-agent finalProvider/finalModel)
- Compaction (new `compacted: true` flag on CompactionDecision)
- Aborted turn (run-agent before partial-content addAssistant)

Privacy note: `store: true` means OpenAI retains responses ~30 days.
Documented in the responses-messages comment block; users who don't
want this should pick a non-codex model.

callModel's signature gained one parameter beyond the lint cap, so
trailing args (`signal`, `rotation`, `chatOptions`) collapsed into a
single `extras` options bag. Updated existing call sites in tests.
…eamble

Codex and gpt-5 stall into deferential narration when reasoning is off and
the system prompt lacks an explicit persistence directive — observed in a
real session where seven consecutive turns produced text-only continuations
after the user typed "ok"/"go". Both gaps are flagged by OpenAI's GPT-5
troubleshooting cookbook.

- Plumb ChatOptions.reasoningEffort into the Responses API path; default to
  'medium' for codex variants, 'low' for other reasoning models, none for
  non-reasoning models. Caller overrides win.
- Add a per-provider agentic persistence block to buildSystemPrompt; emitted
  only when provider=openai. Anthropic is already action-biased and would
  be made worse by it.

Refs:
  https://developers.openai.com/cookbook/examples/gpt-5/gpt-5_troubleshooting_guide
  https://platform.openai.com/docs/guides/reasoning
…inish_reason plumbing

Closes a real latent bug and rounds out the cross-provider terminal-reason
surface introduced alongside the codex/gpt-5 changes.

Bug fixes
- Chain bookkeeping was asymmetric: buildResponsesBody dropped the inbound
  chain pointer when store=false, but the provider still surfaced the
  response id, so the agent layer captured an unreferenceable id and the
  next call sent `previous_response_id: <X>` for an unstored response →
  silent 404. Fix at the wire boundary: streamOpenAiResponses and
  sendOpenAiResponses now suppress responseId when body.store === false
  via a shared isChainable() helper. chainRef can no longer hold a poisoned
  id regardless of how options thread.
- recoverViaNonStream dropped doneReason when falling back from an SSE
  failure to chatNoStream. SSE-fail-then-recover paths now propagate
  doneReason so output-cap-reached / output-blocked still fire on
  truncations and refusals seen via the recovery channel.

New event: output-blocked
- Distinct from the natural turn-complete: provider classifier blocked the
  response or the model refused. Carries a `reason` string so the renderer
  can choose the notice text. Wired in headless (stderr warning) and TUI
  (danger-level notice).
- run-agent dispatches on `content_filter` (OpenAI) and `refusal`
  (Anthropic 4.x). Mapping table is documented in both the event-type
  JSDoc and the inline comment at the dispatch site so a future provider
  contributor knows where to extend.

Anthropic stop_reason mapping (was unwired, now real)
- src/providers/anthropic.ts maps native stop_reason to the agent layer's
  cross-provider doneReason vocabulary:
    max_tokens → 'length'  (output-cap-reached now fires for Anthropic)
    refusal    → 'refusal' (output-blocked fires when Claude declines)
    natural stops (end_turn, stop_sequence, tool_use, pause_turn) → unset
  Streaming reads delta.stop_reason from message_delta events; non-stream
  reads response.stop_reason. Both paths covered.

Parallel tool calls flip
- supportsParallelToolCalls() is now /^o\d/i instead of isReasoningModel().
  gpt-5 and codex are reasoning models too but they support parallel tool
  calls — the GPT-5 cookbook explicitly recommends parallelization for
  read-only tool batches. Effect: OpenAI request bodies for gpt-5 and codex
  now include `parallel_tool_calls: true` where they previously had it
  stripped. Anyone diffing wire-format snapshots in CI needs to update.
  Inline comment now spells out the rationale.

Doc fixes
- responses-messages.ts:toResponsesInput comment said "first contiguous
  system messages collapse"; the code only ever hoists index 0, so a
  second contiguous system at index 1 falls through to inline. Comment
  now matches reality.
- responses-messages.ts:toResponsesTools comment now describes the strict
  parameter and notes the closed-form-schema requirement.
- responses-messages.ts:buildResponsesBody comment explains store/chain
  incompatibility.
- types.ts:ChatChunk.done documents the multi-emit shape (the OpenAI chat
  stream yields a first done with usage/doneReason then a second with
  finalized tool_calls — consumers must iterate to generator end).
- docs/providers.md corrects the OpenAI row: parallel_tool_calls is now
  dropped only for o-series, codex routes through /v1/responses with
  per-model reasoning.effort defaults.

Tests (+6 unit, +1 file)
- agent-output-blocked.test.ts: orchestration-level coverage for
  content_filter/refusal → output-blocked, plus negative cases (natural
  stops don't fire, length triggers output-cap-reached not output-blocked).
- responses-stream.test.ts: terminal chunk omits responseId when
  body.store=false; counter-test confirms it surfaces when store defaults.
- openai-provider.test.ts: same suppression on the chat-completions/
  responses non-stream path; preservation when default; finish_reason
  forwarding for length truncation; dotted-codex capability normalization;
  store=false + tool_strict=true wire-shape.
- responses-helpers.test.ts: chain pointer is dropped when store=false
  (input-side regression for the bug above); strict tool flag passes
  through.
- agent-helpers.ts: MockResponse gains optional doneReason; existing tests
  unaffected (usage only attached when the test sets it).

Not user-facing (intentional, deferred exposure)
- ChatOptions.responsesStore and ChatOptions.toolStrict are set only by
  tests today. Establishing the wire-format surface now; CLI/config wiring
  deferred until there's a use case (toolStrict needs a tool-schema audit
  before enabling broadly; responsesStore needs per-provider config + a
  cost-warning UI for the chain-cost change).
New per-call ChatOptions for the OpenAI provider: promptCacheKey,
serviceTier, seed, safetyIdentifier, metadata, truncationAuto,
responseFormat, reasoningSummary. Wired through both the chat-completions
and Responses request builders via shared applyCommonOpenAiOptions +
buildJsonSchemaFormat helpers.

store=false path: FACTORY_OPENAI_RESPONSES_STORE env override; request
side now sends include: ["reasoning.encrypted_content"]. Capture/replay
half remains TODO'd in responses-stream.ts.

Auto-strict tool calling: isStrictCompatible() schema validator gates
function.strict per-tool. Chat path opts in only when toolStrict=true
(safer for OpenAI-compat backends); Responses path always emits strict
as it's OpenAI-only.

SSE plumbing: dedicated SseIdleTimeoutError + OpenAiSseIdleAbortReason
classes replace fragile error.message string matching. Shared
stream-common.ts dedupes openAiSseIdleTimeoutMs and
createLinkedAbortController between stream.ts and responses-stream.ts.

Tests: sse-test-helpers.ts consolidates withSseServer / withFailingServer
/ withHangingSseServer factories used by both transport test files;
~160 LOC of duplication removed. Added 7 isStrictCompatible cases and
updated the toResponsesTools strict-gating test for the new behavior.
82/82 OpenAI tests pass.

Docs: documented FACTORY_OPENAI_SSE_IDLE_TIMEOUT_MS and
FACTORY_OPENAI_RESPONSES_STORE in docs/configuration.md; added a note
in docs/troubleshooting.md explaining the new 504 idle-timeout surface.

Inline TODO comments mark the remaining P0/P1/P2 parity work
(model-aware idle timeout, request-level cap, Retry-After honor,
x-request-id propagation, stream_options.include_usage, encrypted
reasoning capture/replay, vision content, responsesStore config wiring).
…up (#1)

Bumps the dev-minor group with 1 update: [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip).


Updates `knip` from 6.12.1 to 6.12.2
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.12.2/packages/knip)

---
updated-dependencies:
- dependency-name: knip
  dependency-version: 6.12.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dependabot Bot and others added 24 commits July 3, 2026 11:32
Bumps [hono](https://github.com/honojs/hono) from 4.12.23 to 4.12.26.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.12.23...v4.12.26)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.12.26
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…tes (#32)

Bumps the prod-minor group with 4 updates in the / directory: [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript), [@huggingface/inference](https://github.com/huggingface/huggingface.js), [google-auth-library](https://github.com/googleapis/google-cloud-node/tree/HEAD/core/packages/google-auth-library-nodejs) and [ink](https://github.com/vadimdemedes/ink).


Updates `@anthropic-ai/sdk` from 0.104.1 to 0.110.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.104.1...sdk-v0.110.0)

Updates `@huggingface/inference` from 4.13.18 to 4.13.22
- [Release notes](https://github.com/huggingface/huggingface.js/releases)
- [Commits](huggingface/huggingface.js@inference-v4.13.18...inference-v4.13.22)

Updates `google-auth-library` from 10.7.0 to 10.9.0
- [Release notes](https://github.com/googleapis/google-cloud-node/releases)
- [Changelog](https://github.com/googleapis/google-cloud-node/blob/main/core/packages/google-auth-library-nodejs/CHANGELOG.md)
- [Commits](https://github.com/googleapis/google-cloud-node/commits/google-auth-library-v10.9.0/core/packages/google-auth-library-nodejs)

Updates `ink` from 7.0.6 to 7.1.0
- [Release notes](https://github.com/vadimdemedes/ink/releases)
- [Commits](vadimdemedes/ink@v7.0.6...v7.1.0)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.106.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor
- dependency-name: "@huggingface/inference"
  dependency-version: 4.13.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-minor
- dependency-name: google-auth-library
  dependency-version: 10.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor
- dependency-name: ink
  dependency-version: 7.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.15 to 8.5.25.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.15...8.5.25)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.25
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [hono](https://github.com/honojs/hono) from 4.12.26 to 4.13.0.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.12.26...v4.13.0)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.13.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.2.0 to 10.4.0.
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](beaugunderson/ip-address@v10.2.0...v10.4.0)

---
updated-dependencies:
- dependency-name: ip-address
  dependency-version: 10.4.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…tes (#49)

Bumps the prod-minor group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) | `0.110.0` | `0.115.0` |
| [@huggingface/inference](https://github.com/huggingface/huggingface.js) | `4.13.22` | `4.13.23` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.29.0` | `1.30.0` |
| [ink](https://github.com/vadimdemedes/ink) | `7.1.0` | `7.1.1` |
| [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.7` | `19.2.8` |



Updates `@anthropic-ai/sdk` from 0.110.0 to 0.115.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.110.0...sdk-v0.115.0)

Updates `@huggingface/inference` from 4.13.22 to 4.13.23
- [Release notes](https://github.com/huggingface/huggingface.js/releases)
- [Commits](huggingface/huggingface.js@inference-v4.13.22...inference-v4.13.23)

Updates `@modelcontextprotocol/sdk` from 1.29.0 to 1.30.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@v1.29.0...1.30.0)

Updates `ink` from 7.1.0 to 7.1.1
- [Release notes](https://github.com/vadimdemedes/ink/releases)
- [Commits](vadimdemedes/ink@v7.1.0...v7.1.1)

Updates `react` from 19.2.7 to 19.2.8
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.2.8/packages/react)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.115.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor
- dependency-name: "@huggingface/inference"
  dependency-version: 4.13.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-minor
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.30.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor
- dependency-name: ink
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-minor
- dependency-name: react
  dependency-version: 19.2.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.6 to 5.0.9.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.6...v5.0.9)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 5.0.9
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 3.1.5.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.2...v3.1.5)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [body-parser](https://github.com/expressjs/body-parser) from 2.2.2 to 2.3.0.
- [Release notes](https://github.com/expressjs/body-parser/releases)
- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md)
- [Commits](expressjs/body-parser@v2.2.2...v2.3.0)

---
updated-dependencies:
- dependency-name: body-parser
  dependency-version: 2.3.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [hono](https://github.com/honojs/hono) from 4.13.0 to 4.13.1.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.0...v4.13.1)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.13.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@hono/node-server](https://github.com/honojs/node-server) from 1.19.14 to 2.1.0.
- [Release notes](https://github.com/honojs/node-server/releases)
- [Commits](honojs/node-server@v1.19.14...v2.1.0)

---
updated-dependencies:
- dependency-name: "@hono/node-server"
  dependency-version: 2.1.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…pdates (#35)

Bumps the dev-minor group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `22.19.21` | `22.20.1` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.61.0` | `8.66.0` |
| [archunit](https://github.com/LukasNiessen/ArchUnitTS) | `2.3.0` | `2.4.0` |
| [eslint](https://github.com/eslint/eslint) | `10.5.0` | `10.8.0` |
| [eslint-plugin-sonarjs](https://github.com/SonarSource/SonarJS) | `4.0.3` | `4.2.0` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.16.1` | `6.31.0` |
| [prettier](https://github.com/prettier/prettier) | `3.8.4` | `3.9.6` |
| [tsx](https://github.com/privatenumber/tsx) | `4.22.4` | `4.23.5` |



Updates `@types/node` from 22.19.21 to 22.20.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@typescript-eslint/eslint-plugin` from 8.61.0 to 8.66.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.66.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.61.0 to 8.66.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.66.0/packages/parser)

Updates `archunit` from 2.3.0 to 2.4.0
- [Release notes](https://github.com/LukasNiessen/ArchUnitTS/releases)
- [Changelog](https://github.com/LukasNiessen/ArchUnitTS/blob/main/CHANGELOG.md)
- [Commits](LukasNiessen/ArchUnitTS@v2.3.0...v2.4.0)

Updates `eslint` from 10.5.0 to 10.8.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.5.0...v10.8.0)

Updates `eslint-plugin-sonarjs` from 4.0.3 to 4.2.0
- [Release notes](https://github.com/SonarSource/SonarJS/releases)
- [Changelog](https://github.com/SonarSource/SonarJS/blob/master/docs/RELEASE.md)
- [Commits](https://github.com/SonarSource/SonarJS/commits)

Updates `knip` from 6.16.1 to 6.31.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.31.0/packages/knip)

Updates `prettier` from 3.8.4 to 3.9.6
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.8.4...3.9.6)

Updates `tsx` from 4.22.4 to 4.23.5
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.22.4...v4.23.5)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 22.20.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.62.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.62.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: archunit
  dependency-version: 2.3.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-minor
- dependency-name: eslint
  dependency-version: 10.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: eslint-plugin-sonarjs
  dependency-version: 4.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: knip
  dependency-version: 6.24.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: prettier
  dependency-version: 3.9.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: tsx
  dependency-version: 4.23.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Collapse short union types onto single lines per prettier 3.9's
formatting; fixes the advisory format-check CI job.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
Bumps [c8](https://github.com/bcoe/c8) from 11.0.0 to 12.0.0.
- [Release notes](https://github.com/bcoe/c8/releases)
- [Changelog](https://github.com/bcoe/c8/blob/main/CHANGELOG.md)
- [Commits](bcoe/c8@v11.0.0...v12.0.0)

---
updated-dependencies:
- dependency-name: c8
  dependency-version: 12.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [chalk](https://github.com/chalk/chalk) from 5.6.2 to 6.0.0.
- [Release notes](https://github.com/chalk/chalk/releases)
- [Commits](chalk/chalk@v5.6.2...v6.0.0)

---
updated-dependencies:
- dependency-name: chalk
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@lydell/node-pty](https://github.com/lydell/node-pty) from 1.2.0-beta.12 to 1.2.0-beta.14.
- [Release notes](https://github.com/lydell/node-pty/releases)
- [Commits](lydell/node-pty@v1.2.0-beta.12...v1.2.0-beta.14)

---
updated-dependencies:
- dependency-name: "@lydell/node-pty"
  dependency-version: 1.2.0-beta.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [google-auth-library](https://github.com/googleapis/google-cloud-node/tree/HEAD/core/packages/google-auth-library-nodejs) from 10.9.0 to 11.0.0.
- [Release notes](https://github.com/googleapis/google-cloud-node/releases)
- [Changelog](https://github.com/googleapis/google-cloud-node/blob/main/core/packages/google-auth-library-nodejs/CHANGELOG.md)
- [Commits](https://github.com/googleapis/google-cloud-node/commits/google-auth-library-v11.0.0/core/packages/google-auth-library-nodejs)

---
updated-dependencies:
- dependency-name: google-auth-library
  dependency-version: 11.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the prod-minor group with 1 update: [@huggingface/inference](https://github.com/huggingface/huggingface.js).


Updates `@huggingface/inference` from 4.13.23 to 4.13.25
- [Release notes](https://github.com/huggingface/huggingface.js/releases)
- [Commits](huggingface/huggingface.js@inference-v4.13.23...inference-v4.13.25)

---
updated-dependencies:
- dependency-name: "@huggingface/inference"
  dependency-version: 4.13.25
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the dev-minor group with 2 updates: [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) and [tsx](https://github.com/privatenumber/tsx).


Updates `knip` from 6.31.0 to 6.32.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.32.0/packages/knip)

Updates `tsx` from 4.23.5 to 4.23.10
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.5...v4.23.10)

---
updated-dependencies:
- dependency-name: knip
  dependency-version: 6.32.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: tsx
  dependency-version: 4.23.10
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the dev-minor group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.66.0` | `8.67.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.66.0` | `8.67.0` |
| [eslint](https://github.com/eslint/eslint) | `10.8.0` | `10.8.1` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.32.0` | `6.32.2` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.10` | `4.23.12` |


Updates `@typescript-eslint/eslint-plugin` from 8.66.0 to 8.67.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.67.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.66.0 to 8.67.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.67.0/packages/parser)

Updates `eslint` from 10.8.0 to 10.8.1
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.8.0...v10.8.1)

Updates `knip` from 6.32.0 to 6.32.2
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.32.2/packages/knip)

Updates `tsx` from 4.23.10 to 4.23.12
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.10...v4.23.12)

---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.67.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.67.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-minor
- dependency-name: eslint
  dependency-version: 10.8.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-minor
- dependency-name: knip
  dependency-version: 6.32.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-minor
- dependency-name: tsx
  dependency-version: 4.23.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the prod-minor group with 3 updates: [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript), [@huggingface/inference](https://github.com/huggingface/huggingface.js) and [google-auth-library](https://github.com/googleapis/google-cloud-node/tree/HEAD/core/packages/google-auth-library-nodejs).


Updates `@anthropic-ai/sdk` from 0.115.0 to 0.117.1
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.115.0...sdk-v0.117.1)

Updates `@huggingface/inference` from 4.13.25 to 4.13.26
- [Release notes](https://github.com/huggingface/huggingface.js/releases)
- [Commits](huggingface/huggingface.js@inference-v4.13.25...inference-v4.13.26)

Updates `google-auth-library` from 11.0.0 to 11.0.2
- [Release notes](https://github.com/googleapis/google-cloud-node/releases)
- [Changelog](https://github.com/googleapis/google-cloud-node/blob/main/core/packages/google-auth-library-nodejs/CHANGELOG.md)
- [Commits](https://github.com/googleapis/google-cloud-node/commits/google-auth-library-v11.0.2/core/packages/google-auth-library-nodejs)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.117.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor
- dependency-name: "@huggingface/inference"
  dependency-version: 4.13.26
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-minor
- dependency-name: google-auth-library
  dependency-version: 11.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@lydell/node-pty](https://github.com/lydell/node-pty) from 1.2.0-beta.14 to 1.2.0-beta.15.
- [Release notes](https://github.com/lydell/node-pty/releases)
- [Commits](lydell/node-pty@v1.2.0-beta.14...v1.2.0-beta.15)

---
updated-dependencies:
- dependency-name: "@lydell/node-pty"
  dependency-version: 1.2.0-beta.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the prod-minor group with 2 updates: [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) and [@huggingface/inference](https://github.com/huggingface/huggingface.js).


Updates `@anthropic-ai/sdk` from 0.117.1 to 0.120.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.117.1...sdk-v0.120.0)

Updates `@huggingface/inference` from 4.13.26 to 4.13.28
- [Release notes](https://github.com/huggingface/huggingface.js/releases)
- [Commits](huggingface/huggingface.js@inference-v4.13.26...inference-v4.13.28)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.120.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-minor
- dependency-name: "@huggingface/inference"
  dependency-version: 4.13.28
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [hono](https://github.com/honojs/hono) from 4.13.1 to 4.13.7.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.13.1...v4.13.7)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.13.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 10, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

A newer version of hono exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant