Skip to content

chore(deps): bump the npm-production group across 1 directory with 4 updates - #140

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-production-d0b7c4a852
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-production-d0b7c4a852

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm-production group with 4 updates in the / directory: @anthropic-ai/claude-agent-sdk, js-yaml, react and smol-toml.

Updates @anthropic-ai/claude-agent-sdk from 0.3.250 to 0.3.282

Release notes

Sourced from @​anthropic-ai/claude-agent-sdk's releases.

v0.3.282

What's changed

  • Added support for strictKnownMarketplaces and blockedMarketplaces in host-supplied managedSettings: the allowlist applies only where admin policy sets none; the blocklist adds to the admin's
  • Added @anthropic-ai/claude-agent-sdk/core, a smaller entry point for apps that bundle the SDK (query, MCP tool helpers, session mutations, resolveSettings); it uses your installed zod and MCP SDK
  • Added prewarm() and SpareProcess.claim() (alpha): start a Claude Code process before its session is known and bind it to a folder and its per-session options later
  • Fixed readMcpResource() relaying content _meta keys under the CLI-reserved com.anthropic/ prefix; they are now dropped, as for tool results
  • Updated to parity with Claude Code v2.1.282

Update

npm install @anthropic-ai/claude-agent-sdk@0.3.282
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.282
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.282
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.282

v0.3.281

What's changed

  • Added optional trigger, user_message_uuid and timestamp fields to the conversation_reset message so clients can tell what reset the conversation, match a /clear to its message, and show when the reset happened
  • Fixed permission and dialog callbacks still being invoked for requests that arrived after close()
  • Fixed control requests issued after a query closed hanging or leaking, and permission prompts that could not be cancelled after a cancelled request was redelivered
  • Fixed session_state_changed staying at requires_action after an overlapping permission prompt and sandbox network-access prompt were both answered
  • Improved SDK package size and load time: sdk.mjs no longer bundles unused dependencies (1.47 MB → 0.97 MB)
  • Improved startup time for query() sessions with in-process MCP servers (createSdkMcpServer) by running their handshake inside the SDK; initialize may now wait up to 250 ms for them
  • Improved SDK session start-up: the CLI now answers the host's initialize request before starting its background start-up work
  • Changed the Settings type's attribution field to boolean | {...}; TypeScript code that reads attribution.commit from returned settings needs a type narrow
  • Updated to parity with Claude Code v2.1.281

Update

npm install @anthropic-ai/claude-agent-sdk@0.3.281
# or
yarn add @anthropic-ai/claude-agent-sdk@0.3.281
# or
pnpm add @anthropic-ai/claude-agent-sdk@0.3.281
# or
bun add @anthropic-ai/claude-agent-sdk@0.3.281

v0.3.280

What's changed

  • Added optional fireReason to the task-notification SDKMessageOrigin; a local host's declared scheduled-task fire is honored only in a process it started with CLAUDE_CODE_HOST_SCHEDULED_RUN=1

... (truncated)

Changelog

Sourced from @​anthropic-ai/claude-agent-sdk's changelog.

0.3.282

  • Added support for strictKnownMarketplaces and blockedMarketplaces in host-supplied managedSettings: the allowlist applies only where admin policy sets none; the blocklist adds to the admin's
  • Added @anthropic-ai/claude-agent-sdk/core, a smaller entry point for apps that bundle the SDK (query, MCP tool helpers, session mutations, resolveSettings); it uses your installed zod and MCP SDK
  • Added prewarm() and SpareProcess.claim() (alpha): start a Claude Code process before its session is known and bind it to a folder and its per-session options later
  • Fixed readMcpResource() relaying content _meta keys under the CLI-reserved com.anthropic/ prefix; they are now dropped, as for tool results
  • Updated to parity with Claude Code v2.1.282

0.3.281

  • Added optional trigger, user_message_uuid and timestamp fields to the conversation_reset message so clients can tell what reset the conversation, match a /clear to its message, and show when the reset happened
  • Fixed permission and dialog callbacks still being invoked for requests that arrived after close()
  • Fixed control requests issued after a query closed hanging or leaking, and permission prompts that could not be cancelled after a cancelled request was redelivered
  • Fixed session_state_changed staying at requires_action after an overlapping permission prompt and sandbox network-access prompt were both answered
  • Improved SDK package size and load time: sdk.mjs no longer bundles unused dependencies (1.47 MB → 0.97 MB)
  • Improved startup time for query() sessions with in-process MCP servers (createSdkMcpServer) by running their handshake inside the SDK; initialize may now wait up to 250 ms for them
  • Improved SDK session start-up: the CLI now answers the host's initialize request before starting its background start-up work
  • Changed the Settings type's attribution field to boolean | {...}; TypeScript code that reads attribution.commit from returned settings needs a type narrow
  • Updated to parity with Claude Code v2.1.281

0.3.280

  • Added optional fireReason to the task-notification SDKMessageOrigin; a local host's declared scheduled-task fire is honored only in a process it started with CLAUDE_CODE_HOST_SCHEDULED_RUN=1
  • Added verbatimPrompts option: prompts are delivered as written — no @path expansion, no slash-command dispatch and, on current CLIs, no ambient attachments with the prompt (Claude Code 2.1.248+)
  • Added _meta to mcpServerStatus() tool entries, carrying a tool's MCP Apps ui metadata so a host can find its ui:// resource
  • Added readMcpResource() (alpha) to read an MCP Apps ui:// resource from an MCP server that Claude Code connected
  • Improved askSideQuestion(): asked while a turn is running, it now sees that turn (its prompt, replies and finished tool results so far) instead of only the last completed turn
  • Improved unattended retry (CLAUDE_CODE_RETRY_WATCHDOG): a usage-limit wait emits rate_limit_event (rejected, resetsAt) as it begins; api_retry heartbeats continue while sub-agent work waits
  • Changed session_state_changed events (CLAUDE_CODE_EMIT_SESSION_STATE_EVENTS=1) to report requires_action while an MCP elicitation waits on the user, as for permission prompts
  • Changed headless sessions to cancel an MCP server's pending form question when the tool call that drew it ends
  • Updated to parity with Claude Code v2.1.280

0.3.279

  • Updated to parity with Claude Code v2.1.279

0.3.278

  • Updated to parity with Claude Code v2.1.278

0.3.277

  • Added an optional builtin field to SlashCommand, set when a command is built into Claude Code
  • Added pasted_content to SDKUserMessage: text the user pasted rather than typed, appended after the typed prompt
  • Added optional remote-session latency fields (first_text_post_ms, first_text_post_wall_ms, first_stream_post_queue_wait_ms, first_stream_post_queued_behind) to the success result message
  • Added 'userSettings' as an updateSettings() source, accepting only effortLevel, which is saved for the session's current model as /effort saves it
  • Fixed a resumed or forked session's total_cost_usd, modelUsage and get_usage totals starting at zero instead of continuing from the earlier turns (maxBudgetUsd is unchanged)
  • Changed SDKUsageReport usage rows to always carry severity and is_active: the report relays only rows from a live server reply, and none while the usage fetch is failing
  • Updated to parity with Claude Code v2.1.277

... (truncated)

Commits

Updates js-yaml from 5.4.1 to 5.4.2

Changelog

Sourced from js-yaml's changelog.

[5.4.2] - 2026-09-13

Fixed

  • forceQuotes no longer quotes non-string scalars, #798.
Commits

Updates react from 19.2.8 to 19.3.0

Release notes

Sourced from react's releases.

19.3.0 (September 9, 2026)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.3 release post for more information.

New React Features

New React DOM Features

  • browser(): a new react-dom API that returns a usable which errors during server rendering and resolves in the browser. use(browser()) inside a <Suspense> boundary marks a subtree as browser-only without reporting a recoverable error (@​gnoff: #37143, #37241)
    • Added an onBrowserBailout option to the react-dom/server APIs to observe when a subtree defers to the browser (@​gnoff #37193)

Notable changes

All Changes

React

... (truncated)

Changelog

Sourced from react's changelog.

19.3.0 (September 9, 2026)

New React Features

New React DOM Features

  • browser(): a new react-dom API that returns a usable which errors during server rendering and resolves in the browser. use(browser()) inside a <Suspense> boundary marks a subtree as browser-only without reporting a recoverable error (@​gnoff: #37143, #37241)
    • Added an onBrowserBailout option to the react-dom/server APIs to observe when a subtree defers to the browser (@​gnoff #37193)

Notable changes

All Changes

React

... (truncated)

Commits

Updates smol-toml from 1.8.0 to 1.9.0

Release notes

Sourced from smol-toml's releases.

v1.9.0

Huge update!!! This is most likely the largest update the library received since its release, with lots of new features and improvements.

Performance improvements

Significant parts of the internal parse logic have been rewritten, improving performance by 1.5x-2x. The library was already comfortably ahead of the others, but it is now faster than ever, sitting at 4x faster parse performance than the closest maintained implementation.

Problematic code paths have also been replaced by safer implementations, solving potential DoS vectors. See GHSA-r4xh-jqrq-34v2.

Note: the objects returned by the library now have a null prototype. This is a transparent change for 99.9% of users, and is one of the most significant contributors to the major performance gains in this version.

Full Temporal support

Version 1.8.0 brought support for Temporal in stringify; now the library is also able to emit Temporal objects instead of its own ad-hoc TomlDate object. It is not enabled by default, but it will become the default in v2. Enable by setting useLegacyDate: false in the parser's options.

Better Temporal support in stringify

Temporal support has been improved since it released: Temporal objects that cannot be represented (such as Temporal.PlainMonthDay) now throw an error (instead of silently emitting a bogus object).

A new option has been added to stringify to disallow Temporal objects that cannot be fully represented in TOML. This includes ZonedDateTime objects with a IANA timezone attached instead of a plain offset, and dates with a specific calendar value set. Enable by setting strictTemporal: true in the options.

Handling of unsafe keys

Since its release the library has been protected against prototype pollution attacks, setting properties like __proto__ using safe mechanisms that do not trigger prototype pollution. However, while the returned objects are safe on their own, they may become problematic if used carelessly.

Inspired by secure-json-parse, the library now offers a way to either drop unsafe properties from the returned object, or to throw an error and reject documents altogether. By default, these potentially unsafe keys are preserved and returned.

Miscellaneous updates

  • Unicode BOM is now gracefully accepted and ignored.
  • Table array headers are now properly checked again. Reported in #65.
  • Closed certain gaps where invalid whitespace would be accepted. Reported in #61.
  • Bogus local date and local time values with a UTC offset are no longer accepted.
  • Certain error messages are more accurate and handle errors at line boundaries better.
  • The default export of the lib is now formally deprecated; use a import * instead. Proposed in #50.
  • On Node 20+, strings that contain lone surrogates are now normalised to well-formed strings.
  • On Node 20+, keys that contain lone surrogates are now rejected.

Full Changelog: squirrelchat/smol-toml@v1.8.0...v1.9.0

Commits
  • 6f9739a fix: gate [is|to]WellFormed (Node 18 compat)
  • a73ca32 fix: no Temporal with toml-test when Node < 26
  • 7727890 chore: version bump
  • 641903d chore: rewrite README.md
  • 2df14c5 fix(types): make it work if Temporal doesn't exist
  • 3eaa44e chore: update benchmark harness
  • cd3ba60 feat: safety option for dangerous properties
  • 6746a7f perf: refactor TomlDate to avoid regex path
  • 16fa64f chore: move benchmarks and test harness under 0BSD
  • bbd14b1 fix: correct sign for single-char numbers
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…updates

Bumps the npm-production group with 4 updates in the / directory: [@anthropic-ai/claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-typescript), [js-yaml](https://github.com/nodeca/js-yaml), [react](https://github.com/react/react/tree/HEAD/packages/react) and [smol-toml](https://github.com/squirrelchat/smol-toml).


Updates `@anthropic-ai/claude-agent-sdk` from 0.3.250 to 0.3.282
- [Release notes](https://github.com/anthropics/claude-agent-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/claude-agent-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/claude-agent-sdk-typescript@v0.3.250...v0.3.282)

Updates `js-yaml` from 5.4.1 to 5.4.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@5.4.1...5.4.2)

Updates `react` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react)

Updates `smol-toml` from 1.8.0 to 1.9.0
- [Release notes](https://github.com/squirrelchat/smol-toml/releases)
- [Commits](squirrelchat/smol-toml@v1.8.0...v1.9.0)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/claude-agent-sdk"
  dependency-version: 0.3.282
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-production
- dependency-name: js-yaml
  dependency-version: 5.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-production
- dependency-name: react
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
- dependency-name: smol-toml
  dependency-version: 1.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants