Skip to content

fix(deps): update compatible workspace dependencies - #1991

Merged
jbeckwith-oai merged 7 commits into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-d530ca161b
Oct 1, 2026
Merged

jbeckwith-oai merged 7 commits into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-d530ca161b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Updates compatible workspace dependencies and adds a patch changeset for all five changed SDK packages. Preserves main’s coordinated Expo 57 migration and dependency removals.

Retains OpenAI 7.2.0, MCP client 2.0.0, SDK Zod 4.3.5, starlight-typedoc 0.22.0, and sandbox provider versions within existing peer ranges. Keeps the MCP example at 1.30.0 and regenerates the lockfile from current main. A fresh install passes the existing strict extensions declaration check, including eventsource-parser/stream, without changing module resolution or skipLibCheck.

Validation at 0fd0446: two independent compatibility and supply-chain reviews passed; all current-head CI passed (Node 22/24, coverage, Windows, docs, changesets, and security). Node 24 ran all 7,496 tests successfully. Local validation passed 299 focused tests, all builds/types/declarations/lint/format, changeset validation, and the 5,025-page docs build. The local full suite had eight host-only failures from injected proxy stderr or inaccessible Docker; passing current-head CI covers those paths.

Reviewed manifest/lockfile consistency, retained-version integrity, provider compatibility, install hooks, and preserved release-age/build controls. Requested maintainer dependency/security review in the root sdk-reviews channel. All prior inline findings have fix explanations and are resolved. Approved and merged after current-head CI passed.

---
updated-dependencies:
- dependency-name: "@changesets/cli"
  dependency-version: 3.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: prettier
  dependency-version: 3.9.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: typescript-eslint
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: verdaccio
  dependency-version: 6.10.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: vitest
  dependency-version: 5.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: openai
  dependency-version: 7.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@modelcontextprotocol/client"
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@blaxel/core"
  dependency-version: 0.3.22
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@daytonaio/sdk"
  dependency-version: 0.216.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@e2b/code-interpreter"
  dependency-version: 2.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@openai/codex-sdk"
  dependency-version: 0.156.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@runloop/api-client"
  dependency-version: 1.32.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: e2b
  dependency-version: 2.51.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: modal
  dependency-version: 0.10.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: next
  dependency-version: 16.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: react
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@types/react"
  dependency-version: 19.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: react-dom
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@types/react-dom"
  dependency-version: 19.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@types/react"
  dependency-version: 19.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@types/react-dom"
  dependency-version: 19.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@valibot/to-json-schema"
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: valibot
  dependency-version: 1.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.30.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@tanstack/react-query"
  dependency-version: 5.103.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: tailwind-merge
  dependency-version: 3.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tailwindcss/postcss"
  dependency-version: 4.3.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: tailwindcss
  dependency-version: 4.3.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tailwindcss/vite"
  dependency-version: 4.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: react-native
  dependency-version: 0.87.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@fastify/websocket"
  dependency-version: 11.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: fastify
  dependency-version: 5.12.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@astrojs/mdx"
  dependency-version: 8.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@astrojs/starlight"
  dependency-version: 0.42.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: astro
  dependency-version: 7.3.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: starlight-llms-txt
  dependency-version: 0.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: starlight-typedoc
  dependency-version: 0.23.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: typedoc
  dependency-version: 0.28.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: typedoc-plugin-markdown
  dependency-version: 4.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@astrojs/markdown-remark"
  dependency-version: 7.3.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: typedoc-plugin-frontmatter
  dependency-version: 1.3.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team as a code owner October 1, 2026 09:56
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 1, 2026
@changeset-bot

changeset-bot Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 0fd0446

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 5 packages
Name Type
@openai/agents Patch
@openai/agents-core Patch
@openai/agents-openai Patch
@openai/agents-realtime Patch
@openai/agents-extensions Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1dcecc9a53

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread examples/realtime-react-native/package.json Outdated
Comment thread packages/agents-extensions/package.json Outdated
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T18:31:13.178356Z 0fd0446 New commits
🔒 Security Review ✅ Completed 2026-10-01T18:32:49.939325Z 0fd0446 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@jbeckwith-oai jbeckwith-oai changed the title fix(deps): bump the npm-minor-patch group with 44 updates fix(deps): update compatible workspace dependencies Oct 1, 2026

@dpiet-oai dpiet-oai left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current head has three verified blocking dependency regressions. Exact-head CI reproduces each failure; see the inline findings for the smallest fixes.

Comment thread packages/agents-core/package.json Outdated
Comment thread packages/agents-core/package.json Outdated
Comment thread docs/package.json Outdated

@markstuart-oai markstuart-oai left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed all 32 changed files at f450b7b0, including manifest/lockfile consistency, provider peers, Expo alignment, and the preserved install/security controls. The earlier Expo and provider-peer findings are resolved, and I found no structural or file-size regression.

Three compatibility issues remain: the Zod update breaks saved run-state restoration, MCP 2.1 breaks the existing emitted-declaration check, and TypeDoc 0.23 rejects the current docs output layout. Details and exact-head hosted evidence are inline; I am leaving feedback without approval.

Validation: source-only review plus hosted CI logs. Coverage reports 29 failing and 7,467 passing tests; Node 24 distribution checking and docs build fail as described. Changeset validation and CodeQL passed; Node 22 was cancelled. No local installs, tests, builds or remote workloads were run. Dependency review covered the manifests, lock changes, peers and configured install controls, not a complete audit of upstream package source or provenance.

Comment thread packages/agents-core/package.json Outdated
Comment thread packages/agents-core/package.json Outdated
Comment thread docs/package.json Outdated

@jbeckwith-oai jbeckwith-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The known OpenAI/Modal compilation, provider peer-range, Expo alignment, Zod state-restoration, docs-plugin, and changeset problems have been repaired and pushed. Both original inline findings were replied to and resolved. The current revision still fails the required extensions declaration check: @ai-sdk/provider-utils imports eventsource-parser/stream, whose types do not resolve under the existing moduleResolution setting (TS7016). A baseline-parser lockfile experiment and fresh install did not correct it, so the experiment was discarded. Keep this group unmerged until declaration compatibility is addressed or the remaining update is split into smaller passing changes; do not relax the check merely to merge.

Copy link
Copy Markdown
Contributor

Confirmed on current-head CI at eb045ae: the Node 24 declaration step fails with TS7016 for eventsource-parser/stream in @ai-sdk/provider-utils (job 110482091981). This matches local verification, so it is not solely a macOS/sandbox problem. The other compatibility repairs remain pushed. After repeated dependency-compatibility findings and the narrower version-retention attempt, this group is held for a deliberate declaration-compatibility fix or split; the failing check has not been disabled.

@markstuart-oai markstuart-oai left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed all 31 changed files at eb045ae9, including the repairs since my previous review, manifest/lockfile consistency, provider peers and install/security controls.

The lockfile again selects MCP 2.0.0, SDK Zod 4.3.5 and starlight-typedoc 0.22.0. The current-head docs build passes, and core/openai/realtime/agents pass their declaration checks. Expo and provider peer alignment remain intact. No new structural or file-size regression found.

One declaration-compatibility blocker remains in extensions: the selected eventsource-parser package no longer supplies the legacy subpath type mapping used by the existing check. The inline comment includes the verified package-level cause and hosted failure. I am leaving feedback without approval.

Validation was source-only, with current-head hosted CI and integrity-verified published parser/provider-utils declarations. Node 24 fails as described; Node 22 was cancelled; coverage was still running. Changeset validation, Windows and CodeQL passed. No local installs, tests, builds or remote workloads were run; this was not a complete audit of every upstream dependency. These rollbacks preserve the current locked versions, rather than establishing permanent upper bounds in the existing ranges.

Comment thread pnpm-lock.yaml Outdated

@markstuart-oai markstuart-oai left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the complete 30-file diff at 0fd0446, including the previous compatibility findings, manifests, complete lockfile, provider peers, and install-policy boundaries. No remaining actionable findings.

The repaired graph preserves baseline MCP, SDK Zod, TypeDoc, and Expo selections. Parser dependency edges now match current main, and both Node 22 and 24.3 have passed the original strict generated-declaration check. The manifest/lockfile pairs are consistent; retained package versions preserve their integrity records, and release-age, build allowlist, overrides, and patch controls are unchanged. The five-package patch changeset covers the SDK manifest updates.

Validation: source-only review. Exact-head Node 24 tests, documentation build, Windows sandbox checks, CodeQL, and changeset validation passed. Node 22 and coverage were still running at the final check. No local installs, builds, or tests were run. This was a focused dependency-change review, not a complete audit of every upstream release or native binary.

@jbeckwith-oai jbeckwith-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed complete dependency/manifests/lockfile changes at 0fd0446 with independent compatibility and supply-chain reviews. Current main is integrated, the coordinated Expo 57 upgrade and dependency removals are preserved, and incompatible dependency migrations are excluded. A fresh install and the original strict declaration checks pass, including the prior eventsource-parser/stream failure. All current-head CI is green: Node 22/24, coverage, Windows, docs, changesets and security. Node 24 ran all 7,496 tests successfully; local 299 focused tests and the 5,025-page docs build also passed. Prior inline findings have fix explanations and are resolved. Approved on the maintainer's behalf as requested.

@jbeckwith-oai
jbeckwith-oai merged commit 7efc536 into main Oct 1, 2026
18 checks passed
@jbeckwith-oai
jbeckwith-oai deleted the dependabot/npm_and_yarn/npm-minor-patch-d530ca161b branch October 1, 2026 18:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation javascript Pull requests that update javascript code package:agents-core package:agents-extensions package:agents-openai package:agents-realtime project

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants