Skip to content

deps: bump the provider-sdks group across 2 directories with 5 updates - #1573

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/apps/ade-cli/provider-sdks-756bd372f1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/apps/ade-cli/provider-sdks-756bd372f1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the provider-sdks group with 5 updates in the /apps/ade-cli directory:

Package From To
@anthropic-ai/claude-agent-sdk 0.3.293 0.3.296
@cursor/sdk 1.0.36 1.0.37
@openai/codex 0.161.0 0.162.1
@opencode/cli 2.0.24 2.0.26
@opencode/client 2.0.24 2.0.26

Bumps the provider-sdks group with 5 updates in the /apps/desktop directory:

Package From To
@anthropic-ai/claude-agent-sdk 0.3.293 0.3.296
@cursor/sdk 1.0.36 1.0.37
@openai/codex 0.161.0 0.162.1
@opencode/cli 2.0.24 2.0.26
@opencode/client 2.0.24 2.0.26

Updates @anthropic-ai/claude-agent-sdk from 0.3.293 to 0.3.296

Release notes

Sourced from @​anthropic-ai/claude-agent-sdk's releases.

v0.3.296

What's changed

  • Added claude_code_version to the initialize control response so clients know the CLI version before the first turn
  • Added autoCompactWindow to AgentDefinition, so a subagent can auto-compact earlier than the main conversation's window
  • Fixed the sandbox option discarding an inline settings.sandbox block: the two now merge, the option's values win, and deny and credential lists from both sides are combined
  • Changed the default limit on MCP tool descriptions sent up front and on MCP server instructions, in-process SDK servers included, from 2,048 to 4,096 characters
  • Changed permission answers that arrive after a restart to be parsed like live ones: over 4,096 updatedPermissions entries count as a denial, and a malformed list is ignored as a whole
  • Updated to parity with Claude Code v2.1.296

Update

npm install @anthropic-ai/claude-agent-sdk@0.3.296
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.296
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.296
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.296

v0.3.295

What's changed

  • Added overageEnabled to SDKRateLimitInfo: on usage-limit warnings, whether the account has extra usage turned on
  • Fixed an MCP server added with mcp_set_servers sometimes keeping an outdated tool list when another server in the same request connected later
  • Fixed assistant text blocks losing their citations in streamed responses
  • Fixed Claude being told "disabled by the user" about an in-process MCP server that was switched off with toggleMcpServer()
  • Fixed rate_limit_event with status allowed_warning omitting overageStatus, overageResetsAt and overageDisabledReason, which allowed and rejected events already carry
  • Changed MCP tool descriptions the model loads through tool search, including those from in-process SDK servers, to be cut at 16,384 characters instead of 2,048
  • Changed a permission answer whose updatedPermissions holds over 4,096 updates, rules and directories to count as a denial
  • Changed tool_result_meta[].non_execution_kind to be absent when a mod withheld the result of a tool that ran without error; it was permission-rule
  • Changed pasted_content on user messages to be ignored when it holds over 1,000 entries and blocks in all
  • Changed how the SDK passes option values to Claude Code: the values of its named options are now sent in the same argument as their flag (--flag=value)
  • Changed tool_use_result for MCP Apps tools: structuredContent or _meta over 8,388,608 JSON characters is left off, and _meta.ui with no ui:// resource no longer lifts the ordinary caps
  • Changed tool_use_result for MCP tools: when a long result is saved to a file, or cut because it could not be, the text kept past 500,000 characters is dropped, with a note of how much
  • Changed tool_use_result for MCP tools: a result _meta over 1,048,576 JSON characters is left off, except for SDK-server tools; so is text blocks' _meta that totals over 65,536
  • Updated to parity with Claude Code v2.1.295

Update

npm install @anthropic-ai/claude-agent-sdk@0.3.295
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.295
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.295
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.295
</tr></table> 

... (truncated)

Changelog

Sourced from @​anthropic-ai/claude-agent-sdk's changelog.

0.3.296

  • Added claude_code_version to the initialize control response so clients know the CLI version before the first turn
  • Added autoCompactWindow to AgentDefinition, so a subagent can auto-compact earlier than the main conversation's window
  • Fixed the sandbox option discarding an inline settings.sandbox block: the two now merge, the option's values win, and deny and credential lists from both sides are combined
  • Changed the default limit on MCP tool descriptions sent up front and on MCP server instructions, in-process SDK servers included, from 2,048 to 4,096 characters
  • Changed permission answers that arrive after a restart to be parsed like live ones: over 4,096 updatedPermissions entries count as a denial, and a malformed list is ignored as a whole
  • Updated to parity with Claude Code v2.1.296

0.3.295

  • Added overageEnabled to SDKRateLimitInfo: on usage-limit warnings, whether the account has extra usage turned on
  • Fixed an MCP server added with mcp_set_servers sometimes keeping an outdated tool list when another server in the same request connected later
  • Fixed assistant text blocks losing their citations in streamed responses
  • Fixed Claude being told "disabled by the user" about an in-process MCP server that was switched off with toggleMcpServer()
  • Fixed rate_limit_event with status allowed_warning omitting overageStatus, overageResetsAt and overageDisabledReason, which allowed and rejected events already carry
  • Changed MCP tool descriptions the model loads through tool search, including those from in-process SDK servers, to be cut at 16,384 characters instead of 2,048
  • Changed a permission answer whose updatedPermissions holds over 4,096 updates, rules and directories to count as a denial
  • Changed tool_result_meta[].non_execution_kind to be absent when a mod withheld the result of a tool that ran without error; it was permission-rule
  • Changed pasted_content on user messages to be ignored when it holds over 1,000 entries and blocks in all
  • Changed how the SDK passes option values to Claude Code: the values of its named options are now sent in the same argument as their flag (--flag=value)
  • Changed tool_use_result for MCP Apps tools: structuredContent or _meta over 8,388,608 JSON characters is left off, and _meta.ui with no ui:// resource no longer lifts the ordinary caps
  • Changed tool_use_result for MCP tools: when a long result is saved to a file, or cut because it could not be, the text kept past 500,000 characters is dropped, with a note of how much
  • Changed tool_use_result for MCP tools: a result _meta over 1,048,576 JSON characters is left off, except for SDK-server tools; so is text blocks' _meta that totals over 65,536
  • Updated to parity with Claude Code v2.1.295

0.3.294

  • Updated to parity with Claude Code v2.1.294
Commits

Updates @cursor/sdk from 1.0.36 to 1.0.37

Commits

Updates @openai/codex from 0.161.0 to 0.162.1
Updates @opencode/cli from 2.0.24 to 2.0.26

Commits
  • 9b4ec57 release: v2.0.26
  • 5e73d5c feat(core): add Google Cloud credential setup for Vertex (#53798)
  • 38c955e fix(tui): keep low verbosity summaries in place when toggled (#52357)
  • 0bd95d0 docs(www): remove Fledge Alpha Free from Console models (#53985)
  • 7522502 feat(release): lead V2 release notes with highlights (#53969)
  • 7de2e68 fix(tui): keep the home footer off the hint row in short terminals (#53891)
  • 56ab743 fix(core): batch tree diff selections on every platform (#53956)
  • d445615 feat(release): write reviewed V2 release notes to CHANGELOG.md (#53964)
  • 6dfb413 docs: add Step 5 Free to V2 (#53897)
  • 19fb891 fix(cli): serve remote access on a random unguessable subdomain (#53962)
  • Additional commits viewable in compare view

Updates @opencode/client from 2.0.24 to 2.0.26

Commits
  • 9b4ec57 release: v2.0.26
  • 62e087f sync release versions for v2.0.25 [skip ci]
  • 434f7b2 fix(app): derive waiting steer presentation from execution state (#53880)
  • 613ef8b feat(core): enforce managed integration and tool policies (#53775)
  • 70c6c8c feat(integration): add declarative external connection method (#53672)
  • 369aad3 feat(core): add external credential references (#53624)
  • 59e5953 fix(schema): expose effort-update and thinking-binding overrides on model com...
  • 50ae4bd chore: remove unused dependencies from V2 packages (#53482)
  • cabb5d0 fix(core): migrate the v1 thinking block-binding opt-out (#52327)
  • 2bddf58 refactor(client): share the registered service decision between clients (#53241)
  • Additional commits viewable in compare view

Updates @anthropic-ai/claude-agent-sdk from 0.3.293 to 0.3.296

Release notes

Sourced from @​anthropic-ai/claude-agent-sdk's releases.

v0.3.296

What's changed

  • Added claude_code_version to the initialize control response so clients know the CLI version before the first turn
  • Added autoCompactWindow to AgentDefinition, so a subagent can auto-compact earlier than the main conversation's window
  • Fixed the sandbox option discarding an inline settings.sandbox block: the two now merge, the option's values win, and deny and credential lists from both sides are combined
  • Changed the default limit on MCP tool descriptions sent up front and on MCP server instructions, in-process SDK servers included, from 2,048 to 4,096 characters
  • Changed permission answers that arrive after a restart to be parsed like live ones: over 4,096 updatedPermissions entries count as a denial, and a malformed list is ignored as a whole
  • Updated to parity with Claude Code v2.1.296

Update

npm install @anthropic-ai/claude-agent-sdk@0.3.296
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.296
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.296
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.296

v0.3.295

What's changed

  • Added overageEnabled to SDKRateLimitInfo: on usage-limit warnings, whether the account has extra usage turned on
  • Fixed an MCP server added with mcp_set_servers sometimes keeping an outdated tool list when another server in the same request connected later
  • Fixed assistant text blocks losing their citations in streamed responses
  • Fixed Claude being told "disabled by the user" about an in-process MCP server that was switched off with toggleMcpServer()
  • Fixed rate_limit_event with status allowed_warning omitting overageStatus, overageResetsAt and overageDisabledReason, which allowed and rejected events already carry
  • Changed MCP tool descriptions the model loads through tool search, including those from in-process SDK servers, to be cut at 16,384 characters instead of 2,048
  • Changed a permission answer whose updatedPermissions holds over 4,096 updates, rules and directories to count as a denial
  • Changed tool_result_meta[].non_execution_kind to be absent when a mod withheld the result of a tool that ran without error; it was permission-rule
  • Changed pasted_content on user messages to be ignored when it holds over 1,000 entries and blocks in all
  • Changed how the SDK passes option values to Claude Code: the values of its named options are now sent in the same argument as their flag (--flag=value)
  • Changed tool_use_result for MCP Apps tools: structuredContent or _meta over 8,388,608 JSON characters is left off, and _meta.ui with no ui:// resource no longer lifts the ordinary caps
  • Changed tool_use_result for MCP tools: when a long result is saved to a file, or cut because it could not be, the text kept past 500,000 characters is dropped, with a note of how much
  • Changed tool_use_result for MCP tools: a result _meta over 1,048,576 JSON characters is left off, except for SDK-server tools; so is text blocks' _meta that totals over 65,536
  • Updated to parity with Claude Code v2.1.295

Update

npm install @anthropic-ai/claude-agent-sdk@0.3.295
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.295
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.295
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.295
</tr></table> 

... (truncated)

Changelog

Sourced from @​anthropic-ai/claude-agent-sdk's changelog.

0.3.296

  • Added claude_code_version to the initialize control response so clients know the CLI version before the first turn
  • Added autoCompactWindow to AgentDefinition, so a subagent can auto-compact earlier than the main conversation's window
  • Fixed the sandbox option discarding an inline settings.sandbox block: the two now merge, the option's values win, and deny and credential lists from both sides are combined
  • Changed the default limit on MCP tool descriptions sent up front and on MCP server instructions, in-process SDK servers included, from 2,048 to 4,096 characters
  • Changed permission answers that arrive after a restart to be parsed like live ones: over 4,096 updatedPermissions entries count as a denial, and a malformed list is ignored as a whole
  • Updated to parity with Claude Code v2.1.296

0.3.295

  • Added overageEnabled to SDKRateLimitInfo: on usage-limit warnings, whether the account has extra usage turned on
  • Fixed an MCP server added with mcp_set_servers sometimes keeping an outdated tool list when another server in the same request connected later
  • Fixed assistant text blocks losing their citations in streamed responses
  • Fixed Claude being told "disabled by the user" about an in-process MCP server that was switched off with toggleMcpServer()
  • Fixed rate_limit_event with status allowed_warning omitting overageStatus, overageResetsAt and overageDisabledReason, which allowed and rejected events already carry
  • Changed MCP tool descriptions the model loads through tool search, including those from in-process SDK servers, to be cut at 16,384 characters instead of 2,048
  • Changed a permission answer whose updatedPermissions holds over 4,096 updates, rules and directories to count as a denial
  • Changed tool_result_meta[].non_execution_kind to be absent when a mod withheld the result of a tool that ran without error; it was permission-rule
  • Changed pasted_content on user messages to be ignored when it holds over 1,000 entries and blocks in all
  • Changed how the SDK passes option values to Claude Code: the values of its named options are now sent in the same argument as their flag (--flag=value)
  • Changed tool_use_result for MCP Apps tools: structuredContent or _meta over 8,388,608 JSON characters is left off, and _meta.ui with no ui:// resource no longer lifts the ordinary caps
  • Changed tool_use_result for MCP tools: when a long result is saved to a file, or cut because it could not be, the text kept past 500,000 characters is dropped, with a note of how much
  • Changed tool_use_result for MCP tools: a result _meta over 1,048,576 JSON characters is left off, except for SDK-server tools; so is text blocks' _meta that totals over 65,536
  • Updated to parity with Claude Code v2.1.295

0.3.294

  • Updated to parity with Claude Code v2.1.294
Commits

Updates @cursor/sdk from 1.0.36 to 1.0.37

Commits

Updates @openai/codex from 0.161.0 to 0.162.1
Updates @opencode/cli from 2.0.24 to 2.0.26

Commits
  • 9b4ec57 release: v2.0.26
  • 5e73d5c feat(core): add Google Cloud credential setup for Vertex (#53798)
  • 38c955e fix(tui): keep low verbosity summaries in place when toggled (#52357)
  • 0bd95d0 docs(www): remove Fledge Alpha Free from Console models (#53985)
  • 7522502 feat(release): lead V2 release notes with highlights (#53969)
  • 7de2e68 fix(tui): keep the home footer off the hint row in short terminals (#53891)
  • 56ab743 fix(core): batch tree diff selections on every platform (#53956)
  • d445615 feat(release): write reviewed V2 release notes to CHANGELOG.md (#53964)
  • 6dfb413 docs: add Step 5 Free to V2 (#53897)
  • 19fb891 fix(cli): serve remote access on a random unguessable subdomain (#53962)
  • Additional commits viewable in compare view

Updates @opencode/client from 2.0.24 to 2.0.26

Commits
  • 9b4ec57 release: v2.0.26
  • 62e087f sync release versions for v2.0.25 [skip ci]
  • 434f7b2 fix(app): derive waiting steer presentation from execution state (#53880)
  • 613ef8b feat(core): enforce managed integration and tool policies (#53775)
  • 70c6c8c feat(integration): add declarative external connection method (#53672)
  • 369aad3 feat(core): add external credential references (#53624)
  • 59e5953 fix(schema): expose effort-update and thinking-binding overrides on model com...
  • 50ae4bd chore: remove unused dependencies from V2 packages (#53482)
  • cabb5d0 fix(core): migrate the v1 thinking block-binding opt-out (#52327)
  • 2bddf58 refactor(client): share the registered service decision between clients (#53241)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

---
updated-dependencies:
- dependency-name: "@anthropic-ai/claude-agent-sdk"
  dependency-version: 0.3.296
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: provider-sdks
- dependency-name: "@cursor/sdk"
  dependency-version: 1.0.37
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: provider-sdks
- dependency-name: "@openai/codex"
  dependency-version: 0.162.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: provider-sdks
- dependency-name: "@opencode/cli"
  dependency-version: 2.0.26
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: provider-sdks
- dependency-name: "@opencode/client"
  dependency-version: 2.0.26
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: provider-sdks
- dependency-name: "@anthropic-ai/claude-agent-sdk"
  dependency-version: 0.3.296
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: provider-sdks
- dependency-name: "@cursor/sdk"
  dependency-version: 1.0.37
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: provider-sdks
- dependency-name: "@openai/codex"
  dependency-version: 0.162.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: provider-sdks
- dependency-name: "@opencode/cli"
  dependency-version: 2.0.26
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: provider-sdks
- dependency-name: "@opencode/client"
  dependency-version: 2.0.26
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: provider-sdks
...

Signed-off-by: dependabot[bot] <support@github.com>
@vercel

vercel Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
ade Ignored Ignored Preview Oct 10, 2026 1:13am UTC

@dependabot
dependabot Bot requested a review from arul28 as a code owner October 10, 2026 01:13
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 10, 2026
@greptile-apps

greptile-apps Bot commented Oct 10, 2026

Copy link
Copy Markdown

PR author is in the excluded authors list.

@coderabbitai

coderabbitai Bot commented Oct 10, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: arul28/ADE/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 377d3a35-0234-431a-a0e1-e5f3ea883af4

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dependabot @github

dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

The group that created this PR has been removed from your configuration.

@dependabot dependabot Bot closed this Oct 10, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/apps/ade-cli/provider-sdks-756bd372f1 branch October 10, 2026 20:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants