chore(deps): bump the prod-deps group across 1 directory with 14 updates#49
Merged
charlesrhoward merged 1 commit intoJun 12, 2026
Merged
Conversation
Bumps the prod-deps group with 14 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@ai-sdk/react](https://github.com/vercel/ai/tree/HEAD/packages/react) | `3.0.170` | `3.0.206` | | [@openrouter/ai-sdk-provider](https://github.com/OpenRouterTeam/ai-sdk-provider) | `2.8.0` | `2.9.1` | | [@radix-ui/react-presence](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/presence) | `1.1.5` | `1.1.6` | | [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `6.0.168` | `6.0.204` | | [framer-motion](https://github.com/motiondivision/motion) | `12.38.0` | `12.40.0` | | [fumadocs-core](https://github.com/fuma-nama/fumadocs) | `16.8.0` | `16.10.2` | | [fumadocs-ui](https://github.com/fuma-nama/fumadocs) | `16.8.0` | `16.10.2` | | [geist](https://github.com/vercel/geist-font/tree/HEAD/packages/next) | `1.7.0` | `1.7.2` | | [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.8.0` | `1.18.0` | | [next](https://github.com/vercel/next.js) | `16.2.6` | `16.2.9` | | [react](https://github.com/facebook/react/tree/HEAD/packages/react) | `19.2.5` | `19.2.7` | | [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) | `19.2.5` | `19.2.7` | | [tailwind-merge](https://github.com/dcastil/tailwind-merge) | `3.5.0` | `3.6.0` | | [zod](https://github.com/colinhacks/zod) | `4.3.6` | `4.4.3` | Updates `@ai-sdk/react` from 3.0.170 to 3.0.206 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/main/packages/react/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/HEAD/packages/react) Updates `@openrouter/ai-sdk-provider` from 2.8.0 to 2.9.1 - [Release notes](https://github.com/OpenRouterTeam/ai-sdk-provider/releases) - [Changelog](https://github.com/OpenRouterTeam/ai-sdk-provider/blob/main/CHANGELOG.md) - [Commits](OpenRouterTeam/ai-sdk-provider@2.8.0...2.9.1) Updates `@radix-ui/react-presence` from 1.1.5 to 1.1.6 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/presence/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/presence) Updates `ai` from 6.0.168 to 6.0.204 - [Release notes](https://github.com/vercel/ai/releases) - [Changelog](https://github.com/vercel/ai/blob/[email protected]/packages/ai/CHANGELOG.md) - [Commits](https://github.com/vercel/ai/commits/[email protected]/packages/ai) Updates `framer-motion` from 12.38.0 to 12.40.0 - [Changelog](https://github.com/motiondivision/motion/blob/main/CHANGELOG.md) - [Commits](motiondivision/motion@v12.38.0...v12.40.0) Updates `fumadocs-core` from 16.8.0 to 16.10.2 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/commits/[email protected]) Updates `fumadocs-ui` from 16.8.0 to 16.10.2 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/commits/[email protected]) Updates `geist` from 1.7.0 to 1.7.2 - [Release notes](https://github.com/vercel/geist-font/releases) - [Changelog](https://github.com/vercel/geist-font/blob/main/packages/next/CHANGELOG.md) - [Commits](https://github.com/vercel/geist-font/commits/v1.7.2/packages/next) Updates `lucide-react` from 1.8.0 to 1.18.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.18.0/packages/lucide-react) Updates `next` from 16.2.6 to 16.2.9 - [Release notes](https://github.com/vercel/next.js/releases) - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js) - [Commits](vercel/next.js@v16.2.6...v16.2.9) Updates `react` from 19.2.5 to 19.2.7 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.7/packages/react) Updates `react-dom` from 19.2.5 to 19.2.7 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.7/packages/react-dom) Updates `tailwind-merge` from 3.5.0 to 3.6.0 - [Release notes](https://github.com/dcastil/tailwind-merge/releases) - [Commits](dcastil/tailwind-merge@v3.5.0...v3.6.0) Updates `zod` from 4.3.6 to 4.4.3 - [Release notes](https://github.com/colinhacks/zod/releases) - [Commits](colinhacks/zod@v4.3.6...v4.4.3) --- updated-dependencies: - dependency-name: "@ai-sdk/react" dependency-version: 3.0.206 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: "@openrouter/ai-sdk-provider" dependency-version: 2.9.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-deps - dependency-name: "@radix-ui/react-presence" dependency-version: 1.1.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: ai dependency-version: 6.0.204 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: framer-motion dependency-version: 12.40.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-deps - dependency-name: fumadocs-core dependency-version: 16.10.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-deps - dependency-name: fumadocs-ui dependency-version: 16.10.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-deps - dependency-name: geist dependency-version: 1.7.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: lucide-react dependency-version: 1.18.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-deps - dependency-name: next dependency-version: 16.2.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: react dependency-version: 19.2.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: react-dom dependency-version: 19.2.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-deps - dependency-name: tailwind-merge dependency-version: 3.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-deps - dependency-name: zod dependency-version: 4.4.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-deps ... Signed-off-by: dependabot[bot] <[email protected]>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
Mogplex PR Review
Status: Attention needed
Automated Dependabot PR bumping 14 production dependencies. The ai SDK update (6.0.168→6.0.204) includes 3 critical security fixes (SSRF bypass, tool approval forgery, server error detail leakage) making this an important update. Two items need attention: (1) eslint-config-next is pinned at 16.2.6 while next is updated to 16.2.9 — these should match; (2) fumadocs-ui 16.10.2 changes the default TOC variant, which may alter the site's visual appearance.
Warnings
- eslint-config-next version mismatch with next (package.json)
Thenextdependency is updated to16.2.9buteslint-config-nextremains pinned at16.2.6. The Next.js docs recommend keeping these versions in sync:eslint-config-nextshould match thenextversion to ensure lint rules align with the framework's current behavior. This mismatch could produce false-positive or false-negative lint results. - fumadocs-ui 16.10.2 changes default TOC variant (package.json)
Thefumadocs-uichangelog for 16.10.2 states: "The 'clerk' TOC variant will revert to the original Clerk-like style, the redesigned TOC (the one you see on official docs) will be the new default." This means the site's table of contents appearance may change visually after this update. Verify the TOC still looks correct after upgrading, and if the project explicitly uses the default variant, consider whether the new default is acceptable or if an explicit variant prop is needed.
Suggestions
- ai SDK 6.0.204 includes important security fixes — verify no behavior changes (package.json)
Theaipackage update from 6.0.168 to 6.0.204 includes: (1) SSRF guard hardening for download URLs, (2) tool approval replay forgery fix, (3) default redaction of server error details in UI message streams. Item #3 is a behavior change —streamText().toUIMessageStream()now returns generic 'An error occurred.' instead of raw error details by default. If the app relies on rich error messages in the UI stream, an explicitonErrorhandler must now be provided. Verify this doesn't break any error display UX.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the prod-deps group with 14 updates in the / directory:
3.0.1703.0.2062.8.02.9.11.1.51.1.66.0.1686.0.20412.38.012.40.016.8.016.10.216.8.016.10.21.7.01.7.21.8.01.18.016.2.616.2.919.2.519.2.719.2.519.2.73.5.03.6.04.3.64.4.3Updates
@ai-sdk/reactfrom 3.0.170 to 3.0.206Release notes
Sourced from @ai-sdk/react's releases.
Commits
Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@ai-sdk/reactsince your current version.Updates
@openrouter/ai-sdk-providerfrom 2.8.0 to 2.9.1Release notes
Sourced from @openrouter/ai-sdk-provider's releases.
Changelog
Sourced from @openrouter/ai-sdk-provider's changelog.
... (truncated)
Commits
07a98d6Version Packages (#507)e9cff3afix: send null content for tool-only assistant messages (#506)5cef3c5Version Packages (#490)bb2d4cbfix: stop emitting duplicate tool-call events on trailing-whitespace deltas (...82e8014fix: allow opting out of response_format strict mode (#483) (#486)bf664b1fix: allow query strings and fragments in image URL regex (#484) (#485)310ba3dVersion Packages (#488)4588197fix: preserve empty reasoning_details arrays in multi-turn conversations (#487)Updates
@radix-ui/react-presencefrom 1.1.5 to 1.1.6Changelog
Sourced from @radix-ui/react-presence's changelog.
Commits
Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@radix-ui/react-presencesince your current version.Updates
aifrom 6.0.168 to 6.0.204Release notes
Sourced from ai's releases.
Changelog
Sourced from ai's changelog.
... (truncated)
Commits
63b3f60Version Packages (#16086)bae9babVersion Packages (#16026)b4b575aBackport: fix(ai): redact server error details from UI message streams by def...f42aa79Backport: fix(provider-utils,ai): harden download SSRF guard against hostname...5291f7eBackport: fix: Harden stream text processing and middleware against prototype...9ef2c3cVersion Packages (#15998)942f2f8Backport: fix(security): harden tool approval replay path against client-forg...dca8c38Version Packages (#15992)0c8c0edBackport: fix(ai): return schema-transformed elements in array output mode (#...a340536Version Packages (#15965)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for ai since your current version.
Updates
framer-motionfrom 12.38.0 to 12.40.0Changelog
Sourced from framer-motion's changelog.
Commits
38ebb94v12.40.0b1f766cLatestbca5544Merge pull request #3699 from motiondivision/lochie/arcs-injectablef1a96cfarc(): rename amp/rotate, expose MotionPath, fix explicit cw/ccwb4aaba0pathRotation: non-destructive orientToPath rotation channel8604ef3Make arcs injectable viatransition.path = arc()f90fe29addorientToPath9ebe999fix: testbc2107eRevert "no should"6eeb92dno shouldUpdates
fumadocs-corefrom 16.8.0 to 16.10.2Release notes
Sourced from fumadocs-core's releases.
... (truncated)
Commits
Updates
fumadocs-uifrom 16.8.0 to 16.10.2Release notes
Sourced from fumadocs-ui's releases.
... (truncated)
Commits
Updates
geistfrom 1.7.0 to 1.7.2Changelog
Sourced from geist's changelog.
Commits
31b2359Version Packages (#230)a4195aeGeist Pixel on Google Fonts (#229)8b8b75ffix(release): sync package.json version and unignore packages/**/package.json...88309a4Version Packages (#223)6af2e7fci: harden release workflow (#222)c8ed578chore: add changeset for [email protected] (Mono liga regression fix) (#221)a0a06a3make build855f609Fix broken link in README.mdMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for geist since your current version.
Updates
lucide-reactfrom 1.8.0 to 1.18.0Release notes
Sourced from lucide-react's releases.
... (truncated)
Commits
07c885efix(docs): fix zephyr-cloud URL in readmes50d8af5docs(readme): Update readme files (#4320)653e44bfeat(packages): use .mjs for ESM bundles (#4285)Updates
nextfrom 16.2.6 to 16.2.9Release notes
Sourced from next's releases.
Commits
f37fad9v16.2.9d9aaaed[cd] Allow tagging semver-lower releases as@latestif@latestpo… (#94627)6f16804v16.2.80dbc1d5[16.2.x][cd] Ensure release can be triggered on old branches (#94598)90e3c81[16.2.x] Align Actions dependencies with Canary (#94339)83f402c[16.2.x][cd] Stop fetching all tags when searching parent tag (#94334)411c455v16.2.7c63224f[backport] feat(turbopack): add LocalPathOrProjectPath PostCSS config resolut...63115c7[16.2.x] Don't dropFormDataentries (#94240)aef22fd[backport] Propagate adapter preferred regions (#94200)Updates
reactfrom 19.2.5 to 19.2.7Release notes
Sourced from react's releases.
Commits
6117d7cVersion 19.2.7 (#36591)eaf3e95Version 19.2.6Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for react since your current version.
Updates
react-domfrom 19.2.5 to 19.2.7Release notes
Sourced from react-dom's releases.
Commits
6117d7cVersion 19.2.7 (#36591)eaf3e95Version 19.2.6Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for react-dom since your current version.
Updates
tailwind-mergefrom 3.5.0 to 3.6.0Release notes
Sourced from tailwind-merge's releases.
Commits
d54f7e5v3.6.0638871aUpdate README to add info about Tailwind CSS v4.3 support39fc7b5Revert "v3.6.0"bd8390fv3.6.0802877cadd v3.6.0 changeloga35fedaMerge pull request #665 from dcastil/renovate/rollup-plugin-babel-7.x940389cMerge pull request #667 from dcastil/renovate/release-drafter-release-drafter...005af6dpin to specific version5816cedimplement breaking changes17041e1Merge pull request #676 from dcastil/dependabot/npm_and_yarn/babel/plugin-tra...Updates
zodfrom 4.3.6 to 4.4.3Release notes
Sourced from zod's releases.