JD Davis
34a5517562
chore: release 0.36.5 ( #3214 )
...
🤖 I have created a release *beep* *boop*
---
##
[0.36.5](https://github.com/headroomlabs-ai/headroom/compare/v0.36.4...v0.36.5 )
(2026-08-22)
### Bug Fixes
* **codex:** detect ChatGPT auth from id_token claims so wrap/init emit
requires_openai_auth
([#3212 ](https://github.com/headroomlabs-ai/headroom/issues/3212 ))
([2f81fa5 ](2f81fa5931 ))
* **doctor:** report project-scoped Claude routing instead of a false
negative
([#3213 ](https://github.com/headroomlabs-ai/headroom/issues/3213 ))
([8f3e33a ](8f3e33a00e ))
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-22 16:22:48 -07:00
JD Davis
91186b40d8
chore: release 0.36.4 ( #3189 )
...
🤖 I have created a release *beep* *boop*
---
##
[0.36.4](https://github.com/headroomlabs-ai/headroom/compare/v0.36.3...v0.36.4 )
(2026-08-22)
### Bug Fixes
* **dashboard:** pin MIME types for the vendored static assets
([#3193 ](https://github.com/headroomlabs-ai/headroom/issues/3193 ))
([b485768 ](b4857685ff ))
* **proxy/responses:** keep the Codex additional_tools carrier on the
wire ([#3194 ](https://github.com/headroomlabs-ai/headroom/issues/3194 ))
([1617f83 ](1617f839a1 ))
* **security:** validate caller-supplied upstreams on every resolution
path ([#3195 ](https://github.com/headroomlabs-ai/headroom/issues/3195 ))
([3e3c409 ](3e3c409436 ))
* skip cross-turn dedup pointers on OpenAI chat streaming
([#3191 ](https://github.com/headroomlabs-ai/headroom/issues/3191 ))
([9c30b62 ](9c30b62962 ))
* **wrap:** make the Serena pre-index stall budget configurable
([#3183 ](https://github.com/headroomlabs-ai/headroom/issues/3183 ))
([202c189 ](202c1895e1 ))
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-21 23:29:15 -07:00
JD Davis
87e71dd100
chore: release 0.36.3 ( #3188 )
...
🤖 I have created a release *beep* *boop*
---
##
[0.36.3](https://github.com/headroomlabs-ai/headroom/compare/v0.36.2...v0.36.3 )
(2026-08-21)
### Bug Fixes
* **proxy/responses:** lift Codex >= 0.149.0 additional_tools into
top-level tools
([#3186 ](https://github.com/headroomlabs-ai/headroom/issues/3186 ))
([25ca580 ](25ca580825 ))
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-21 14:57:44 -07:00
JD Davis
5e0ce242e9
chore: release 0.36.2 ( #3157 )
...
🤖 I have created a release *beep* *boop*
---
##
[0.36.2](https://github.com/headroomlabs-ai/headroom/compare/v0.36.1...v0.36.2 )
(2026-08-21)
### Bug Fixes
* **copilot:** bind the minted token to the integration ID we forward
([#3164 ](https://github.com/headroomlabs-ai/headroom/issues/3164 ))
([397803a ](397803a942 ))
* **kompress:** accept ccr_original on the remote compressor
([#3162 ](https://github.com/headroomlabs-ai/headroom/issues/3162 ))
([45cb1b9 ](45cb1b9c48 ))
* **proxy:** count output tokens from the stream's text, not its wire
size ([#3163 ](https://github.com/headroomlabs-ai/headroom/issues/3163 ))
([4006964 ](4006964a03 ))
### Dependencies
* bump ai from 6.0.138 to 7.0.59 in /sdk/typescript
([#2281 ](https://github.com/headroomlabs-ai/headroom/issues/2281 ))
([0891062 ](08910624fb ))
* bump ai from 6.0.149 to 7.0.59 in /docs
([#2277 ](https://github.com/headroomlabs-ai/headroom/issues/2277 ))
([f7e5d37 ](f7e5d37f52 ))
* bump md-5 from 0.10.6 to 0.11.0
([#3146 ](https://github.com/headroomlabs-ai/headroom/issues/3146 ))
([c6dd823 ](c6dd823384 ))
* bump ruff from 0.16.2 to 0.16.3 in the pip-minor-patch group
([#3143 ](https://github.com/headroomlabs-ai/headroom/issues/3143 ))
([c8db13d ](c8db13d5ad ))
* bump the cargo-minor-patch group with 8 updates
([#3145 ](https://github.com/headroomlabs-ai/headroom/issues/3145 ))
([9c14e3a ](9c14e3aa95 ))
* bump tiktoken-rs from 0.11.0 to 0.12.0
([#3147 ](https://github.com/headroomlabs-ai/headroom/issues/3147 ))
([a307c11 ](a307c11109 ))
* bump tokenizers from 0.22.2 to 0.23.1
([#3149 ](https://github.com/headroomlabs-ai/headroom/issues/3149 ))
([6e2e10f ](6e2e10f67a ))
* bump typescript from 5.9.3 to 7.0.2 in /plugins/openclaw
([#2279 ](https://github.com/headroomlabs-ai/headroom/issues/2279 ))
([85774fc ](85774fcb70 ))
* bump typescript from 5.9.3 to 7.0.2 in /plugins/opencode
([#2280 ](https://github.com/headroomlabs-ai/headroom/issues/2280 ))
([a382137 ](a382137844 ))
* update mcp requirement from <2.0.0,>=1.28.1 to
>=1.28.1,<3.0.0
([#3144 ](https://github.com/headroomlabs-ai/headroom/issues/3144 ))
([6928d19 ](6928d1932c ))
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-20 23:09:18 -07:00
dependabot[bot]
a382137844
deps: bump typescript from 5.9.3 to 7.0.2 in /plugins/opencode ( #2280 )
...
Bumps [typescript](https://github.com/microsoft/TypeScript ) from 5.9.3
to 7.0.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/microsoft/TypeScript/releases ">typescript's
releases</a>.</em></p>
<blockquote>
<h2>TypeScript 6.0.3</h2>
<p>For release notes, check out the <a
href="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/ ">release
announcement blog post</a>.</p>
<ul>
<li><a
href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&q=milestone%3A%22TypeScript+6.0.0%22 ">fixed
issues query for TypeScript 6.0.0 (Beta)</a>.</li>
<li><a
href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&q=milestone%3A%22TypeScript+6.0.1%22 ">fixed
issues query for TypeScript 6.0.1 (RC)</a>.</li>
<li><a
href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&q=milestone%3A%22TypeScript+6.0.2%22 ">fixed
issues query for TypeScript 6.0.2 (Stable)</a>.</li>
<li><a
href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&q=milestone%3A%22TypeScript+6.0.3%22 ">fixed
issues query for TypeScript 6.0.3 (Stable)</a>.</li>
</ul>
<p>Downloads are available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/typescript ">npm</a></li>
</ul>
<h2>TypeScript 6.0</h2>
<p>For release notes, check out the <a
href="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/ ">release
announcement blog post</a>.</p>
<ul>
<li><a
href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&q=milestone%3A%22TypeScript+6.0.0%22 ">fixed
issues query for TypeScript 6.0.0 (Beta)</a>.</li>
<li><a
href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&q=milestone%3A%22TypeScript+6.0.1%22 ">fixed
issues query for TypeScript 6.0.1 (RC)</a>.</li>
<li><a
href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&q=milestone%3A%22TypeScript+6.0.2%22 ">fixed
issues query for TypeScript 6.0.2 (Stable)</a>.</li>
</ul>
<p>Downloads are available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/typescript ">npm</a></li>
</ul>
<h2>TypeScript 6.0.1 RC</h2>
<p>For release notes, check out the <a
href="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0-rc/ ">release
announcement blog post</a>.</p>
<ul>
<li><a
href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&q=milestone%3A%22TypeScript+6.0.0%22 ">fixed
issues query for TypeScript 6.0.0 (Beta)</a>.</li>
<li><a
href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&q=milestone%3A%22TypeScript+6.0.1%22 ">fixed
issues query for TypeScript 6.0.1 (RC)</a>.</li>
</ul>
<p>Downloads are available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/typescript ">npm</a></li>
</ul>
<h2>TypeScript 6.0 Beta</h2>
<p>For release notes, check out the <a
href="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0-beta/ ">release
announcement</a>.</p>
<ul>
<li><a
href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&q=milestone%3A%22TypeScript+6.0.0%22+is%3Aclosed+ ">fixed
issues query for Typescript 6.0.0 (Beta)</a>.</li>
</ul>
<p>Downloads are available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/typescript ">npm</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/microsoft/TypeScript/commits ">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~microsoft1es ">microsoft1es</a>, a new
releaser for typescript since your current version.</p>
</details>
<br />
> **Note**
> Automatic rebases have been disabled on this pull request as it has
been open for over 30 days.
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: JerrettDavis <mxjerrett@gmail.com>
2026-08-20 22:12:03 -05:00
JD Davis
37faf2f247
chore: release 0.36.1 ( #3152 )
...
## Description
Release 0.36.1, generated by Release Please, containing the security
fixes from #2207 (WEB-01–07). This updates the changelog and keeps
Python, TypeScript SDK, plugin package, marketplace, server, and release
metadata versions aligned at 0.36.1.
## Type of Change
- [x] Release / version metadata
## Changes Made
- Updated the release manifest and generated changelog for 0.36.1.
- Synchronized `pyproject.toml`, TypeScript SDK, OpenClaw, OpenCode,
agent-hook plugin, marketplace, server, and release metadata versions.
- Included the 0.36.1 changelog entry for the security assessment fixes
merged in #2207 .
## Testing
- [x] CI and release validation pass
### Test Output
All current required checks are complete and passing, including version
sync, package builds, wheel smoke imports, security scans, Python test
shards, native wrapper checks, and devcontainer validation.
## Real Behavior Proof
- Environment: GitHub Actions release and CI workflows for commit
`52c0a0c61dce0af81af3ff73a34efe8b451501cb`.
- Observed result: all generated version-bearing files report 0.36.1;
build and smoke-import jobs produced and validated the release
artifacts.
- Not exercised: publishing jobs are intentionally skipped for a pull
request and run only after the release receives final human approval and
is merged.
## Runtime Rollout Safety
- Rollout-managed features: none; this PR packages already-merged
behavior.
- Stable/default behavior changed: no additional runtime behavior beyond
the included, already-reviewed security fixes.
- Kill switch / disable path: not applicable to generated release
metadata.
- Qualification impact: release artifact construction and smoke-import
validation are green.
- Rollback path: do not merge the release PR, or revert the release
commit before publishing.
## Review Readiness
- [x] I have performed a self-review
- [x] This PR is ready for human review
## Release Notes
### Bug Fixes
- **security:** address u9up assessment findings (WEB-01–07) (#2207 )
This PR was generated with Release Please and then its description was
expanded to document review and qualification evidence. It still
requires final human review; no publishing or merge has been performed.
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-20 17:20:18 -07:00
JD Davis
b88b9078d8
chore: release 0.36.0 ( #3067 )
...
🤖 I have created a release *beep* *boop*
---
##
[0.36.0](https://github.com/headroomlabs-ai/headroom/compare/v0.35.0...v0.36.0 )
(2026-08-20)
### Features
* add deterministic runtime rollout controls
([#1490 ](https://github.com/headroomlabs-ai/headroom/issues/1490 ))
([3077ac8 ](3077ac81e8 ))
* **proxy:** let extensions report cost savings and their own latency
([#3051 ](https://github.com/headroomlabs-ai/headroom/issues/3051 ))
([f9807fd ](f9807fd69e ))
* **proxy:** unify savings attribution across stats, perf, metrics, and
dashboard
([1b0b0b8 ](1b0b0b89a4 )),
closes [#2976 ](https://github.com/headroomlabs-ai/headroom/issues/2976 )
* **wrap/claude:** make the --1m fallback model configurable via
HEADROOM_1M_MODEL
([#2983 ](https://github.com/headroomlabs-ai/headroom/issues/2983 ))
([2a84725 ](2a8472525d ))
### Bug Fixes
* **anthropic:** honor the [1m] 1M-context tier, and price it correctly
([#3073 ](https://github.com/headroomlabs-ai/headroom/issues/3073 ))
([6d2254d ](6d2254dfb5 ))
* **ccr:** make --no-ccr disable server-side response handling too
([#3101 ](https://github.com/headroomlabs-ai/headroom/issues/3101 ))
([131b119 ](131b119c05 )),
closes [#3082 ](https://github.com/headroomlabs-ai/headroom/issues/3082 )
* **ccr:** make StreamingCCRHandler work on OpenAI streams
([#3069 ](https://github.com/headroomlabs-ai/headroom/issues/3069 ))
([7ef736f ](7ef736fb1a ))
* **ccr:** only buffer a stream when a marker is actually redeemable
([#3092 ](https://github.com/headroomlabs-ai/headroom/issues/3092 ))
([c502087 ](c502087db7 ))
* **ccr:** re-inject headroom_retrieve when history references it on the
sessionless path
([942af56 ](942af56f11 ))
* **ccr:** relay a successful upstream turn when post-processing fails
([#3094 ](https://github.com/headroomlabs-ai/headroom/issues/3094 ))
([0ec73fa ](0ec73faa28 ))
* **ccr:** send Accept: application/json on a buffered stream:false turn
([#3102 ](https://github.com/headroomlabs-ai/headroom/issues/3102 ))
([139c7cb ](139c7cbdde )),
closes [#3078 ](https://github.com/headroomlabs-ai/headroom/issues/3078 )
* **ccr:** verify a scanned marker's hash before advertising it
([#2908 ](https://github.com/headroomlabs-ai/headroom/issues/2908 ))
([41dab2d ](41dab2d099 ))
* **ci:** prevent native detector from hanging test shards
([#2996 ](https://github.com/headroomlabs-ai/headroom/issues/2996 ))
([a708c05 ](a708c0571e ))
* **ci:** scope the release credential and stop persisting it to disk
([#3062 ](https://github.com/headroomlabs-ai/headroom/issues/3062 ))
([ac8646a ](ac8646aa3c ))
* **ci:** unjam release and Docker publishing
([#2958 ](https://github.com/headroomlabs-ai/headroom/issues/2958 ))
([e269afb ](e269afb935 ))
* **claude:** reject conflicting auth before proxy startup
([#2993 ](https://github.com/headroomlabs-ai/headroom/issues/2993 ))
([2d88e31 ](2d88e31a40 ))
* **cli/install:** resolve the deployment profile instead of dead-ending
on default
([#2832 ](https://github.com/headroomlabs-ai/headroom/issues/2832 ))
([8252619 ](82526191a1 ))
* **cli:** stop the macOS malloc re-exec replacing an embedder's process
([#3064 ](https://github.com/headroomlabs-ai/headroom/issues/3064 ))
([96c25f5 ](96c25f5181 ))
* **copilot:** route VS Code inline completions to Copilot, not OpenAI
([#3077 ](https://github.com/headroomlabs-ai/headroom/issues/3077 ))
([204e751 ](204e751d2f ))
* **copilot:** send VS Code inline completions to the host that serves
them ([#3112 ](https://github.com/headroomlabs-ai/headroom/issues/3112 ))
([b77d612 ](b77d612913 ))
* **deps:** bump datasets past PYSEC-2026-3716
([#3136 ](https://github.com/headroomlabs-ai/headroom/issues/3136 ))
([df6ff6b ](df6ff6bd5b ))
* **deps:** clear the two Rust advisories and make cargo audit blocking
([#3121 ](https://github.com/headroomlabs-ai/headroom/issues/3121 ))
([93c474e ](93c474e84b ))
* **deps:** raise the GitPython floor to 3.1.58 to clear 9 open
advisories
([#3120 ](https://github.com/headroomlabs-ai/headroom/issues/3120 ))
([8156d4d ](8156d4dc3a ))
* **docker:** publish compose ports on loopback only
([#3061 ](https://github.com/headroomlabs-ai/headroom/issues/3061 ))
([481e0b8 ](481e0b83d5 ))
* **docker:** ship Bedrock auth and current registry
([#2982 ](https://github.com/headroomlabs-ai/headroom/issues/2982 ))
([eafdf11 ](eafdf11a2c ))
* **doctor:** surface that Claude Desktop agent sessions bypass the
proxy ([#2987 ](https://github.com/headroomlabs-ai/headroom/issues/2987 ))
([be5b26d ](be5b26d807 ))
* **install:** consolidate Windows fallback and cleanup safety
([#2980 ](https://github.com/headroomlabs-ai/headroom/issues/2980 ))
([ddd2a25 ](ddd2a259ec ))
* **install:** honor HEADROOM_PORT in install apply and deploy
([#3085 ](https://github.com/headroomlabs-ai/headroom/issues/3085 ))
([58f28dc ](58f28dc7a6 ))
* **install:** stop the PowerShell installer leaking temp dirs into the
real user PATH
([#2985 ](https://github.com/headroomlabs-ai/headroom/issues/2985 ))
([ddd9f76 ](ddd9f76729 ))
* **learn:** include stdout in CLI failure messages, not just stderr
([#3080 ](https://github.com/headroomlabs-ai/headroom/issues/3080 ))
([c5563d3 ](c5563d3a7d ))
* **mcp:** restore SDK v1 compatibility cap
([#2978 ](https://github.com/headroomlabs-ai/headroom/issues/2978 ))
([6077e5a ](6077e5a149 ))
* **memory:** sanitize entity_refs to prevent dict-shaped entries
crashing search
([#2951 ](https://github.com/headroomlabs-ai/headroom/issues/2951 ))
([2d1e96b ](2d1e96b85c ))
* **onnx:** enforce Rust API-24 runtime compatibility
([#2979 ](https://github.com/headroomlabs-ai/headroom/issues/2979 ))
([a3fe5cb ](a3fe5cb65b ))
* **openclaw-plugin:** circuit breaker + per-request timeout for proxy
resilience
([#639 ](https://github.com/headroomlabs-ai/headroom/issues/639 ))
([6576ef6 ](6576ef639c ))
* **opencode:** send x-headroom-project header on all proxied requests
([#2868 ](https://github.com/headroomlabs-ai/headroom/issues/2868 ))
([eeb038b ](eeb038bc0c ))
* **policy:** price net-cost mutations with the 1h cache-write tier
([#2780 ](https://github.com/headroomlabs-ai/headroom/issues/2780 ))
([ef7e07e ](ef7e07e0f5 ))
* **providers:** don't crash on a non-object HEADROOM_MODEL_LIMITS /
models.json
([#3089 ](https://github.com/headroomlabs-ai/headroom/issues/3089 ))
([3ed8f76 ](3ed8f76019 ))
* **proxy/anthropic:** don't buffer a CCR stream when passthrough
discards the stream flip
([#2953 ](https://github.com/headroomlabs-ai/headroom/issues/2953 ))
([f1c34d3 ](f1c34d336c ))
* **proxy/anthropic:** don't replay recorded prefix over live history
([#3026 ](https://github.com/headroomlabs-ai/headroom/issues/3026 ))
([#3052 ](https://github.com/headroomlabs-ai/headroom/issues/3052 ))
([c16be9b ](c16be9bbbe ))
* **proxy/anthropic:** repair headroom_retrieve history references the
tools array cannot support
([#2876 ](https://github.com/headroomlabs-ai/headroom/issues/2876 ))
([7de3573 ](7de35739c6 ))
* **proxy/anthropic:** stop answering a non-streaming turn with an event
stream
([#3142 ](https://github.com/headroomlabs-ai/headroom/issues/3142 ))
([0e26fb8 ](0e26fb80de ))
* **proxy/cache:** strip cache_control from messages in the semantic
cache key
([#3086 ](https://github.com/headroomlabs-ai/headroom/issues/3086 ))
([2cae0f8 ](2cae0f8eaf ))
* **proxy/gemini:** guard CCR continuation usage against present-null
counts
([#3035 ](https://github.com/headroomlabs-ai/headroom/issues/3035 ))
([a01897c ](a01897c791 ))
* **proxy/openai:** propagate provider usage on the Responses
WS->HTTP fallback
([#2988 ](https://github.com/headroomlabs-ai/headroom/issues/2988 ))
([536c949 ](536c949a69 ))
* **proxy:** adapt 200 SSE upstream replies on buffered /v1/responses
instead of 502
([#2622 ](https://github.com/headroomlabs-ai/headroom/issues/2622 ))
([d76fce0 ](d76fce04a3 ))
* **proxy:** align signed-thinking wire accounting
([#3015 ](https://github.com/headroomlabs-ai/headroom/issues/3015 ))
([b3f4436 ](b3f443636d ))
* **proxy:** complete stateless Responses and buffered CCR lifecycle
([#2997 ](https://github.com/headroomlabs-ai/headroom/issues/2997 ))
([8a1d38b ](8a1d38bc5d ))
* **proxy:** guard feedback endpoints and add CSRF checks to loopback
writes
([#3060 ](https://github.com/headroomlabs-ai/headroom/issues/3060 ))
([a6ab359 ](a6ab359a5d ))
* **proxy:** keep prefixed core tools resident
([#3046 ](https://github.com/headroomlabs-ai/headroom/issues/3046 ))
([2f4d001 ](2f4d001c9f ))
* **proxy:** preserve Codex WebSocket model attribution
([#3029 ](https://github.com/headroomlabs-ai/headroom/issues/3029 ))
([a06a51e ](a06a51eca6 ))
* **proxy:** relocate stray system-role messages to the top-level system
param ([#765 ](https://github.com/headroomlabs-ai/headroom/issues/765 ))
([#1357 ](https://github.com/headroomlabs-ai/headroom/issues/1357 ))
([9fde127 ](9fde127534 ))
* **proxy:** restore the buffered-CCR heartbeat behind a grace window
([#3091 ](https://github.com/headroomlabs-ai/headroom/issues/3091 ))
([a29d201 ](a29d2015e5 ))
* **proxy:** scope the signed-thinking lock to blocks that actually
changed
([#3124 ](https://github.com/headroomlabs-ai/headroom/issues/3124 ))
([17522fb ](17522fb0a1 ))
* **proxy:** stop a lone surrogate turning a thinking body into a 500
([#3134 ](https://github.com/headroomlabs-ai/headroom/issues/3134 ))
([284ff31 ](284ff31947 ))
* **proxy:** stop cached responses replaying the producing turn's wire
framing
([#3024 ](https://github.com/headroomlabs-ai/headroom/issues/3024 ))
([9d37059 ](9d370592b0 ))
* **proxy:** stop operator secrets following a client-chosen upstream
([#3122 ](https://github.com/headroomlabs-ai/headroom/issues/3122 ))
([05f5ef4 ](05f5ef47cb ))
* **proxy:** tune macOS libmalloc and trim allocator pages so long-lived
RSS stays bounded
([#2879 ](https://github.com/headroomlabs-ai/headroom/issues/2879 ))
([6d87825 ](6d87825f62 ))
* **reporting:** show net vs gross savings, real skip thresholds, and
the effective profile
([#3123 ](https://github.com/headroomlabs-ai/headroom/issues/3123 ))
([250ede2 ](250ede2f7f ))
* tool_search_tool_regex deferred and falsely resolved on
direct-Anthropic path
([#2971 ](https://github.com/headroomlabs-ai/headroom/issues/2971 ))
([8ea87e7 ](8ea87e7804 ))
* **vscode:** persist compatible Claude modes and route Copilot CAPI
([#2986 ](https://github.com/headroomlabs-ai/headroom/issues/2986 ))
([1aa701a ](1aa701adaa ))
* **wrap:** set xAI upstream for grok-build proxy
([#2772 ](https://github.com/headroomlabs-ai/headroom/issues/2772 ))
([c831081 ](c8310819a4 ))
* **wrap:** stop the Serena pre-index stalling the launch path for 300s
([#2945 ](https://github.com/headroomlabs-ai/headroom/issues/2945 ))
([6147883 ](6147883d5e ))
* **wrap:** verify proxy deps before mutating Codex config
([#1628 ](https://github.com/headroomlabs-ai/headroom/issues/1628 ))
([b7f342c ](b7f342c153 ))
### Performance Improvements
* **perf:** skip rotated logs outside the requested window
([#3081 ](https://github.com/headroomlabs-ai/headroom/issues/3081 ))
([6c9f41e ](6c9f41e08c ))
### Dependencies
* bump axum from 0.7.9 to 0.8.9
([#2966 ](https://github.com/headroomlabs-ai/headroom/issues/2966 ))
([5731be7 ](5731be7e68 ))
* bump criterion from 0.5.1 to 0.8.2
([#2965 ](https://github.com/headroomlabs-ai/headroom/issues/2965 ))
([b30f339 ](b30f339d69 ))
* bump ruff from 0.15.22 to 0.16.2 in the pip-minor-patch group across 1
directory
([#2962 ](https://github.com/headroomlabs-ai/headroom/issues/2962 ))
([ff17961 ](ff17961cd7 ))
* bump sha2 from 0.10.9 to 0.11.0
([#2288 ](https://github.com/headroomlabs-ai/headroom/issues/2288 ))
([322425c ](322425c43b ))
* bump the cargo-minor-patch group across 1 directory with 4 updates
([#2964 ](https://github.com/headroomlabs-ai/headroom/issues/2964 ))
([888a9f4 ](888a9f4e14 ))
* bump tokio-tungstenite from 0.24.0 to 0.30.0
([#2967 ](https://github.com/headroomlabs-ai/headroom/issues/2967 ))
([bbe9013 ](bbe901319d ))
* update mcp requirement from <2.0.0,>=1.28.1 to
>=1.28.1,<3.0.0
([#2963 ](https://github.com/headroomlabs-ai/headroom/issues/2963 ))
([d6fb536 ](d6fb5365f6 ))
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-19 21:14:59 -07:00
Tejas Chopra
93f2d7a2da
chore: release main ( #2792 )
...
🤖 I have created a release *beep* *boop*
---
<details><summary>0.35.0</summary>
##
[0.35.0](https://github.com/headroomlabs-ai/headroom/compare/v0.34.0...v0.35.0 )
(2026-08-12)
### Features
* **beacon:** allowlist the routing summary key
([#2818 ](https://github.com/headroomlabs-ai/headroom/issues/2818 ))
([7940c05 ](7940c05ebf ))
* **beacon:** hourly R2 compaction, per-strategy savings, and a stack
that reports
([#2853 ](https://github.com/headroomlabs-ai/headroom/issues/2853 ))
([e0870ef ](e0870ef931 ))
* **cli,pricing:** add CLI extension seam and prompt-cache TTL pricing
([#2802 ](https://github.com/headroomlabs-ai/headroom/issues/2802 ))
([6ec3e34 ](6ec3e3478a ))
### Bug Fixes
* **anthropic:** strip first-party tool search on custom upstreams
([#2539 ](https://github.com/headroomlabs-ai/headroom/issues/2539 ))
([7f6950b ](7f6950be34 ))
* **backends/anyllm:** convert Anthropic tools and tool_choice to OpenAI
shape
([0d6866b ](0d6866b91a ))
* **backends/anyllm:** stream tool_use blocks and map finish_reason on
the streaming path
([e4904e2 ](e4904e23a6 ))
* **backends/litellm:** None-guard core token counts in OpenAI usage
block ([#2324 ](https://github.com/headroomlabs-ai/headroom/issues/2324 ))
([12f9f58 ](12f9f58cb3 ))
* **beacon:** report all-layers savings, not context-compression only
([#2796 ](https://github.com/headroomlabs-ai/headroom/issues/2796 ))
([e9a24f3 ](e9a24f3ec1 ))
* **beacon:** split session failures by status code
([#2815 ](https://github.com/headroomlabs-ai/headroom/issues/2815 ))
([2954e37 ](2954e37048 ))
* **cache:** bound compression cache bookkeeping
([0ae948c ](0ae948c151 ))
* **cache:** enforce Anthropic's 1h-before-5m cache_control ordering
before forwarding
([#2941 ](https://github.com/headroomlabs-ai/headroom/issues/2941 ))
([3752458 ](3752458022 ))
* **cache:** mirror client cache_control positions instead of
single-marker consolidation
([def3d76 ](def3d76e5a ))
* **cache:** stabilize Anthropic block-growing lineages
([#2917 ](https://github.com/headroomlabs-ai/headroom/issues/2917 ))
([1a04c95 ](1a04c957f5 ))
* **ccr:** avoid injecting tool on chat streaming
([d0c1f5b ](d0c1f5b8ad ))
* **ccr:** preserve exact SQLite TTL boundary
([#2669 ](https://github.com/headroomlabs-ai/headroom/issues/2669 ))
([d0a86d4 ](d0a86d409f ))
* **ccr:** report embedded hashes from compress endpoint
([#717 ](https://github.com/headroomlabs-ai/headroom/issues/717 ))
([685ebe4 ](685ebe457d ))
* **ccr:** resolve <<ccr:...>> markers inline when no
retrieve-tool path exists
([#2512 ](https://github.com/headroomlabs-ai/headroom/issues/2512 ))
([ce8ce83 ](ce8ce8313f ))
* **ccr:** tolerate null/malformed OpenAI data in response handling
([#2467 ](https://github.com/headroomlabs-ai/headroom/issues/2467 ))
([e583e08 ](e583e082d8 ))
* **ci:** publish latest from the root Docker manifest
([#2252 ](https://github.com/headroomlabs-ai/headroom/issues/2252 ))
([5568d73 ](5568d738af ))
* **claude:** stop forcing tool search on Foundry
([#2477 ](https://github.com/headroomlabs-ai/headroom/issues/2477 ))
([7981396 ](798139608c ))
* **cli/update:** let install ownership win over bare /.dockerenv so
venv installs self-update
([#2830 ](https://github.com/headroomlabs-ai/headroom/issues/2830 ))
([7092b53 ](7092b53c46 ))
* **codex:** route alpha search through the Codex backend
([#2538 ](https://github.com/headroomlabs-ai/headroom/issues/2538 ))
([a540eb2 ](a540eb2c61 ))
* **content-router:** protect custom-tag blocks before mixed-content
section split
([d7bc1e2 ](d7bc1e275f ))
* **deps:** bump h2 to 4.4.1 for CVE-2026-71554
([#2839 ](https://github.com/headroomlabs-ai/headroom/issues/2839 ))
([564e0a8 ](564e0a8d0f ))
* **deps:** enforce audited transitive dependency floors
([#2791 ](https://github.com/headroomlabs-ai/headroom/issues/2791 ))
([64e2039 ](64e203931b ))
* **doctor:** flag `ollama launch claude` proxy bypass instead of
misdirecting
([#2566 ](https://github.com/headroomlabs-ai/headroom/issues/2566 ))
([7f24d69 ](7f24d695ee ))
* emit SSE ping before message_start on Bedrock streaming path (issue
[#902 ](https://github.com/headroomlabs-ai/headroom/issues/902 ))
([#1080 ](https://github.com/headroomlabs-ai/headroom/issues/1080 ))
([4dab254 ](4dab254d52 ))
* **gemini:** resolve native CCR retrieval calls
([#2253 ](https://github.com/headroomlabs-ai/headroom/issues/2253 ))
([2483f57 ](2483f57002 ))
* **health:** label kompress as degraded/optional when not yet loaded
([#2865 ](https://github.com/headroomlabs-ai/headroom/issues/2865 ))
([8949371 ](89493714d2 ))
* **image:** decouple routing types from trained_router so importing the
compressor doesn't import torch
([#2513 ](https://github.com/headroomlabs-ai/headroom/issues/2513 ))
([#2537 ](https://github.com/headroomlabs-ai/headroom/issues/2537 ))
([d7cf981 ](d7cf981093 ))
* **install/windows:** register persistent-task from S4U hidden XML
([#2453 ](https://github.com/headroomlabs-ai/headroom/issues/2453 ))
([#2459 ](https://github.com/headroomlabs-ai/headroom/issues/2459 ))
([1edaeb8 ](1edaeb8b76 ))
* **install:** don't crash the PowerShell installer when $PROFILE is
unset ([#2469 ](https://github.com/headroomlabs-ai/headroom/issues/2469 ))
([fc5c4e2 ](fc5c4e239c ))
* **install:** trust Docker bridge for dashboard metadata
([e044139 ](e044139001 ))
* **install:** use --userns=keep-id under Podman so bind-mount writes
don't fail
([#2846 ](https://github.com/headroomlabs-ai/headroom/issues/2846 ))
([3488f8d ](3488f8d4b5 ))
* **learn/gemini:** stop double-counting session tokens
([#2230 ](https://github.com/headroomlabs-ai/headroom/issues/2230 ))
([29d8a5e ](29d8a5e563 ))
* **learn/grok:** detect a Windows absolute project path
([#2283 ](https://github.com/headroomlabs-ai/headroom/issues/2283 ))
([e240df2 ](e240df2b69 ))
* **learn:** stop classifying a successful exit code 0 as an error
([#2289 ](https://github.com/headroomlabs-ai/headroom/issues/2289 ))
([a24fe7d ](a24fe7dcbf ))
* **litellm:** add async_post_call_success_hook to HeadroomCallback
([#1322 ](https://github.com/headroomlabs-ai/headroom/issues/1322 ))
([3107994 ](3107994aed ))
* **litellm:** don't forward a caller key the target cannot accept
([#2883 ](https://github.com/headroomlabs-ai/headroom/issues/2883 ))
([2f2950a ](2f2950a626 ))
* **memory:** bound the TrafficLearner pending-pattern accumulator
(memory leak)
([#2579 ](https://github.com/headroomlabs-ai/headroom/issues/2579 ))
([1f5feff ](1f5fefffd3 ))
* **memory:** close DirectMem0 resources
([6596182 ](65961827cf ))
* **memory:** close MCP backend on shutdown
([4bd8ecd ](4bd8ecd1e3 ))
* **memory:** don't crash inline memory extraction on a non-object
<memory> block
([#2470 ](https://github.com/headroomlabs-ai/headroom/issues/2470 ))
([e00c6ff ](e00c6ff81c ))
* **memory:** keep vector metadata in sync
([#2295 ](https://github.com/headroomlabs-ai/headroom/issues/2295 ))
([c471800 ](c471800e8e ))
* **memory:** make explicit-project and user store keys
collision-resistant
([#2231 ](https://github.com/headroomlabs-ai/headroom/issues/2231 ))
([f840d5f ](f840d5f2fe ))
* **memory:** skip <system-reminder> blocks when building the
retrieval query
([#2195 ](https://github.com/headroomlabs-ai/headroom/issues/2195 ))
([#2541 ](https://github.com/headroomlabs-ai/headroom/issues/2541 ))
([4e5a67a ](4e5a67a342 ))
* **memory:** sync FTS5 and vector indexes on CLI
delete/edit/prune/purge
([fd4628d ](fd4628d821 ))
* **oauth2:** make repository lint checks pass
([c85abf7 ](c85abf7a87 ))
* **observability:** aggregate tool savings in OTEL
([#2936 ](https://github.com/headroomlabs-ai/headroom/issues/2936 ))
([941c25d ](941c25d31e ))
* **onnx:** stop ONNX thread pools from spinning idle cores
([#2495 ](https://github.com/headroomlabs-ai/headroom/issues/2495 ))
([#2540 ](https://github.com/headroomlabs-ai/headroom/issues/2540 ))
([5c561bd ](5c561bd913 ))
* **openai:** skip Responses tool-search deferral for clients that
cannot execute it
([#2696 ](https://github.com/headroomlabs-ai/headroom/issues/2696 ))
([54ea28d ](54ea28d983 ))
* **opencode:** ship the transport hook-shim so wheel installs route
Node child traffic
([702dbc5 ](702dbc5902 ))
* **providers/anthropic:** don't crash token estimation on null
tool_calls
([#2472 ](https://github.com/headroomlabs-ai/headroom/issues/2472 ))
([08466f3 ](08466f3cae ))
* **providers/openai:** bound tiktoken vocab loads with the guarded
loader
([#2554 ](https://github.com/headroomlabs-ai/headroom/issues/2554 ))
([0805e8e ](0805e8e410 ))
* **proxy/anthropic:** inject headroom_retrieve whenever a CCR marker is
present, not only for new markers
([#2848 ](https://github.com/headroomlabs-ai/headroom/issues/2848 ))
([3808f60 ](3808f60ca6 ))
* **proxy/anthropic:** None-guard usage token counts on the direct
buffered path
([#2434 ](https://github.com/headroomlabs-ai/headroom/issues/2434 ))
([2b5ee7c ](2b5ee7cde8 ))
* **proxy/anthropic:** run tool-search history repair after turn hooks
([c6f9948 ](c6f99482e1 ))
* **proxy/batch:** don't crash an OpenAI batch on a valid-JSON
non-object line
([#2316 ](https://github.com/headroomlabs-ai/headroom/issues/2316 ))
([1f2c681 ](1f2c681c0b ))
* **proxy/bedrock:** report uncached input tokens from backend usage,
not the live-zone count
([#2318 ](https://github.com/headroomlabs-ai/headroom/issues/2318 ))
([c19e412 ](c19e412b33 ))
* **proxy/gemini:** keep streaming-parity baseline so eligible_pct can't
exceed 100
([#2824 ](https://github.com/headroomlabs-ai/headroom/issues/2824 ))
([b97c7c6 ](b97c7c6e99 ))
* **proxy/metrics:** cap client-supplied model label cardinality
([#2480 ](https://github.com/headroomlabs-ai/headroom/issues/2480 ))
([e24a7e6 ](e24a7e66b9 ))
* **proxy/metrics:** escape label values in the Prometheus export
([#2463 ](https://github.com/headroomlabs-ai/headroom/issues/2463 ))
([6a53861 ](6a53861063 ))
* **proxy/openai:** don't crash the Responses memory tool loops on null
arguments
([#2273 ](https://github.com/headroomlabs-ai/headroom/issues/2273 ))
([a30db2c ](a30db2cae4 ))
* **proxy/openai:** feed Codex WS traffic into the traffic learner
([#2334 ](https://github.com/headroomlabs-ai/headroom/issues/2334 ))
([f669149 ](f669149769 ))
* **proxy/openai:** run response hooks on Responses, and bill their
re-drives
([#2872 ](https://github.com/headroomlabs-ai/headroom/issues/2872 ))
([675d13f ](675d13f08d ))
* **proxy:** allow settings routes for trusted gateway/dashboard clients
([#2491 ](https://github.com/headroomlabs-ai/headroom/issues/2491 ))
([a5b0a8f ](a5b0a8f4cc ))
* **proxy:** cache litellm model resolution to stop repeated Provider
List spam
([99f07e7 ](99f07e7bbd ))
* **proxy:** cancel periodic TOIN task on shutdown
([739fdef ](739fdef423 ))
* **proxy:** close the upstream stream when a streaming body is never
consumed
([0951663 ](0951663562 ))
* **proxy:** compress cache-mode cold starts and tag prefix-mismatch
passthrough
([#2365 ](https://github.com/headroomlabs-ai/headroom/issues/2365 ))
([aaeba0a ](aaeba0a319 ))
* **proxy:** emit request log timestamps in UTC
([620028f ](620028fa18 ))
* **proxy:** enable tool search by default and repair poisoned
transcripts
([#2807 ](https://github.com/headroomlabs-ai/headroom/issues/2807 ))
([0237cbf ](0237cbffbb ))
* **proxy:** gate mid-turn message coalescing to Claude Code clients
([#1643 ](https://github.com/headroomlabs-ai/headroom/issues/1643 ))
([a4bd2e6 ](a4bd2e62a5 ))
* **proxy:** give each Codex /v1/responses WS turn a unique request_id
([#2164 ](https://github.com/headroomlabs-ai/headroom/issues/2164 ))
([d02df10 ](d02df10758 ))
* **proxy:** graceful shutdown and reliable Ctrl+C exit
([#621 ](https://github.com/headroomlabs-ai/headroom/issues/621 ))
([17cdb18 ](17cdb185bc ))
* **proxy:** guard telemetry and TOIN endpoints
([cde1513 ](cde1513c91 ))
* **proxy:** include tool_search_deferral savings in the savings ledger
([12149f7 ](12149f7446 ))
* **proxy:** pass through cross-region prefixed Bedrock model IDs
directly
([#2330 ](https://github.com/headroomlabs-ai/headroom/issues/2330 ))
([64cb46e ](64cb46e24b ))
* **proxy:** port session-sticky beta headers to the Rust proxy
([#2381 ](https://github.com/headroomlabs-ai/headroom/issues/2381 ))
([f6398a6 ](f6398a6476 ))
* **proxy:** preserve merged session and quarantine contracts
([#2943 ](https://github.com/headroomlabs-ai/headroom/issues/2943 ))
([039cd24 ](039cd2431a ))
* **proxy:** preserve signed Anthropic thinking blocks on outbound
re-serialize
([#2254 ](https://github.com/headroomlabs-ai/headroom/issues/2254 ))
([dc163bc ](dc163bcd1c ))
* **proxy:** stop discarding compressed Codex WS later-frame payloads
([#2823 ](https://github.com/headroomlabs-ai/headroom/issues/2823 ))
([4ec416d ](4ec416df88 ))
* **proxy:** time-cap the compression timeout-debt quarantine
([#2360 ](https://github.com/headroomlabs-ai/headroom/issues/2360 ))
([#2412 ](https://github.com/headroomlabs-ai/headroom/issues/2412 ))
([c5a08d2 ](c5a08d22e0 ))
* **proxy:** unwrap Hermes tool_call bridge in tool name map
([#2717 ](https://github.com/headroomlabs-ai/headroom/issues/2717 ))
([a97b824 ](a97b82413b ))
* publish headroom-opencode in release workflow
([#2372 ](https://github.com/headroomlabs-ai/headroom/issues/2372 ))
([7859154 ](78591545ce ))
* **settings:** accept documented HEADROOM_* env names as settings keys
([#2833 ](https://github.com/headroomlabs-ai/headroom/issues/2833 ))
([de9e052 ](de9e0523da ))
* **subscription:** dedup transcript usage by message id
([#2340 ](https://github.com/headroomlabs-ai/headroom/issues/2340 ) token
inflation)
([#2408 ](https://github.com/headroomlabs-ai/headroom/issues/2408 ))
([74275b7 ](74275b7c3e ))
* **toin:** bound private query and pattern retention
([8cd1380 ](8cd138039e ))
* **tokenizer:** coerce non-string tool_call fields before counting
([#2801 ](https://github.com/headroomlabs-ai/headroom/issues/2801 ))
([b6f9877 ](b6f9877c78 ))
* **tokenizer:** price CJK in the Rust fixed-ratio estimator (Python
parity)
([#2260 ](https://github.com/headroomlabs-ai/headroom/issues/2260 ))
([6840153 ](6840153473 ))
* **transforms/adaptive-sizer:** honor max_k on small-input fast path
([#2319 ](https://github.com/headroomlabs-ai/headroom/issues/2319 ))
([8a90523 ](8a90523209 ))
* **transforms/smart_crusher:** don't crash on a tool call with a null
function
([#2232 ](https://github.com/headroomlabs-ai/headroom/issues/2232 ))
([3bb02f8 ](3bb02f8f75 ))
* Vertex model pricing shows $0.00 for versioned model names and
vertex:anthropic provider
([#2517 ](https://github.com/headroomlabs-ai/headroom/issues/2517 ))
([eb5b5e4 ](eb5b5e4198 ))
* **wrap/claude:** keep --1m effective when an explicit --model is
passed through
([c093bf1 ](c093bf11eb ))
* **wrap/opencode:** verify the opencode binary before mutating config
([ae38486 ](ae384862a4 ))
* **wrap/serena:** install Serena from the serena-agent PyPI wheel, not
the git source
([d7b25ae ](d7b25ae3bb ))
* **wrap:** honor Copilot OAuth wire-api override and model default
([#2387 ](https://github.com/headroomlabs-ai/headroom/issues/2387 ))
([1db6d88 ](1db6d88ab4 ))
* **wrap:** serialize shared proxy startup
([#2946 ](https://github.com/headroomlabs-ai/headroom/issues/2946 ))
([e540d64 ](e540d64feb ))
* **wrap:** stop the launch cwd from shadowing the installed package in
the proxy subprocess
([#2843 ](https://github.com/headroomlabs-ai/headroom/issues/2843 ))
([c49be26 ](c49be269a1 ))
### Performance Improvements
* cut hot-path latency 27% (token-count memo, startup preloads, JSON
scan memo)
([#2838 ](https://github.com/headroomlabs-ai/headroom/issues/2838 ))
([53af90d ](53af90d68c ))
* **proxy:** bound upstream calls and hot-path costs
([#2852 ](https://github.com/headroomlabs-ai/headroom/issues/2852 ))
([f624d3a ](f624d3a00a ))
* **subscription:** skip transcripts older than the window in
compute_window_tokens
([#2861 ](https://github.com/headroomlabs-ai/headroom/issues/2861 ))
([91d6bf3 ](91d6bf33cd ))
### Dependencies
* bump brace-expansion from 5.0.7 to 5.0.9 in /docs
([#2751 ](https://github.com/headroomlabs-ai/headroom/issues/2751 ))
([56ee57b ](56ee57be98 ))
* bump bytesize from 1.3.3 to 2.4.2
([#2286 ](https://github.com/headroomlabs-ai/headroom/issues/2286 ))
([6448545 ](6448545a7f ))
* bump hf-hub from 0.4.3 to 0.5.0
([#2285 ](https://github.com/headroomlabs-ai/headroom/issues/2285 ))
([4925bf6 ](4925bf6a82 ))
* bump next from 16.2.10 to 16.3.0 in /docs
([#2750 ](https://github.com/headroomlabs-ai/headroom/issues/2750 ))
([0fd0b99 ](0fd0b996a4 ))
* bump postcss from 8.5.19 to 8.5.25 in /plugins/openclaw
([#2749 ](https://github.com/headroomlabs-ai/headroom/issues/2749 ))
([cd60ee9 ](cd60ee9ae8 ))
* bump postcss from 8.5.19 to 8.5.25 in /plugins/opencode
([#2748 ](https://github.com/headroomlabs-ai/headroom/issues/2748 ))
([ff4e016 ](ff4e0167bb ))
* bump postcss from 8.5.19 to 8.5.25 in /sdk/typescript
([#2747 ](https://github.com/headroomlabs-ai/headroom/issues/2747 ))
([267c2bd ](267c2bdcb5 ))
* bump postcss from 8.5.19 to 8.5.26 in /docs
([#2881 ](https://github.com/headroomlabs-ai/headroom/issues/2881 ))
([e6e5826 ](e6e5826423 ))
* bump ruff from 0.15.17 to 0.15.22 in the pip-minor-patch group
([#2501 ](https://github.com/headroomlabs-ai/headroom/issues/2501 ))
([ecf130d ](ecf130d3ac ))
* bump rusqlite from 0.32.1 to 0.40.1
([#2287 ](https://github.com/headroomlabs-ai/headroom/issues/2287 ))
([522faa1 ](522faa1a59 ))
* bump the cargo-minor-patch group across 1 directory with 22 updates
([#2916 ](https://github.com/headroomlabs-ai/headroom/issues/2916 ))
([148d860 ](148d8605e2 ))
</details>
---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please ). See
[documentation](https://github.com/googleapis/release-please#release-please ).
---------
Co-authored-by: JD Davis <mxjerrett@gmail.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-08-12 19:02:51 -05:00
Rod Boev
78591545ce
fix: publish headroom-opencode in release workflow ( #2372 )
...
## Description
`headroom-opencode` is documented as an npm package, but the release
workflow never published it, so installs failed with a registry 404 even
though the plugin source already lived under `plugins/opencode`. This
wires the existing package into the npm release path, keeps its version
synced with root releases, and adds release guards for the new package.
Closes #76 .
## Type of Change
- [x] Bug fix (non-breaking change that fixes an issue)
- [ ] New feature (non-breaking change that adds functionality)
- [ ] Breaking change (fix or feature that would cause existing
functionality to change)
- [x] Documentation update
- [ ] Performance improvement
- [ ] Code refactoring (no functional changes)
## Changes Made
- added `headroom-opencode` to the npm release workflow, including
release-version stamping and `headroom-ai` dependency rewrite before
publish
- added `plugins/opencode/package.json` to release-please and local
version-sync guards
- synced the source opencode package version to the current release line
and documented the new npm package in the release docs
- added focused release workflow and version-sync tests for the opencode
package
- aligned the two failing dashboard Playwright tests with the current
Session/Lifetime split and `/stats-lifetime` fixture contract
## Testing
- [x] Unit tests pass (`uv run pytest scripts/tests/test_version_sync.py
-q`, `uv run pytest tests/test_release_workflows.py -q -k
'publish_npm_rewrites_opencode_dependency_after_version_and_before_publish
or opencode_source_dependency_matches_lockfile_registry_range or
release_please_manifest_config_consistency'`)
- [x] Unit tests pass (`uv run pytest
tests/test_dashboard_cache_lifetime_playwright.py
tests/test_dashboard_cache_ttl_playwright.py -q`)
- [x] Linting passes (`uv run ruff check scripts/verify-versions.py
scripts/version-sync.py scripts/tests/test_version_sync.py
tests/test_release_workflows.py`)
- [ ] Type checking passes (`uv run mypy headroom`)
- [x] New tests added for new functionality when applicable
- [x] Manual testing performed
### Test Output
```text
$ uv run pytest scripts/tests/test_version_sync.py -q
8 passed, 1 warning in 0.51s
$ uv run pytest tests/test_release_workflows.py -q -k 'publish_npm_rewrites_opencode_dependency_after_version_and_before_publish or opencode_source_dependency_matches_lockfile_registry_range or release_please_manifest_config_consistency'
2 passed, 38 deselected, 1 warning in 0.07s
$ uv run pytest tests/test_dashboard_cache_lifetime_playwright.py tests/test_dashboard_cache_ttl_playwright.py -q
4 passed, 1 warning in 4.04s
$ uv run ruff check scripts/verify-versions.py scripts/version-sync.py scripts/tests/test_version_sync.py tests/test_release_workflows.py
All checks passed!
$ npm ci && npm run build (plugins/opencode)
Build success; dist/index.js, dist/entry.opencode.js, and DTS outputs emitted
```
## Real Behavior Proof
- Environment: Windows, Python 3.11.15, Node v24.15.0, npm 11.16.0
- Exact command / steps: inspected `.github/workflows/release.yml`,
updated the npm publish path for `plugins/opencode`, aligned the two
failing dashboard Playwright tests with the current Session/Lifetime
split, then ran the focused pytest commands above plus `npm ci && npm
run build` in `plugins/opencode`
- Observed result: the release workflow now versions and publishes
`headroom-opencode`, release-please and version-sync track
`plugins/opencode/package.json`, the dashboard tests now fetch durable
cache and setup-url data from the Lifetime view, and the opencode
package still builds locally from source
- Not tested: GitHub Package Registry publish
## Review Readiness
- [x] I have performed a self-review
- [x] This PR is ready for human review
## Checklist
- [x] My code follows the project's style guidelines
- [x] I have performed a self-review of my code
- [x] I have commented my code, particularly in hard-to-understand areas
- [x] I have made corresponding changes to the documentation
- [x] My changes generate no new warnings
- [x] I have added tests that prove my fix is effective or that my
feature works
- [x] New and existing unit tests pass locally with my changes
- [x] I have updated the CHANGELOG.md if applicable
## Additional Notes
`CHANGELOG.md` is unchanged because release-please owns changelog
generation here.
---------
Co-authored-by: JD Davis <mxjerrett@gmail.com>
2026-08-11 23:56:40 -05:00
gglucass
f54f04f5bf
feat(opencode): ship the transport plugin in pip installs ( #2601 )
...
## Description
The OpenCode transport plugin - the piece that gives `wrap opencode`
all-provider routing by tagging each request with `x-headroom-base-url`
- only exists in repo checkouts today. `headroom_opencode_plugin_path()`
resolves `plugins/opencode/dist/entry.opencode.js`, which pip wheels do
not ship, so every pip install silently degrades to the two-provider
(anthropic/openai) baseURL fallback. The function's own docstring
documents the gap ("a pip-only install that does not ship `plugins/`").
Shipping the existing build output is not enough: the regular tsup build
leaves `headroom-ai` and `@opencode-ai/plugin` as bare external imports,
which only resolve next to the checkout's `node_modules`. Copied into
site-packages, the file fails to load. This PR ships a self-contained
bundle inside the wheel instead.
Closes #
## Type of Change
- [ ] Bug fix (non-breaking change that fixes an issue)
- [x] New feature (non-breaking change that adds functionality)
- [ ] Breaking change (fix or feature that would cause existing
functionality to change)
- [ ] Documentation update
- [ ] Performance improvement
- [ ] Code refactoring (no functional changes)
## Changes Made
- `plugins/opencode/tsup.standalone.config.ts` + `npm run
build:standalone`: a second build of the loader entry with `noExternal:
[/.*/]` and `splitting: false` - a single self-contained file whose only
imports are node builtins.
- `headroom/providers/opencode/_dist/entry.opencode.js`: the committed
standalone bundle (452 KB). It sits inside the package directory, so
maturin's `python-source = "."` packaging picks it up into the wheel
with no build-system changes.
- `headroom_opencode_plugin_path()`: falls back to the packaged bundle.
Precedence otherwise unchanged: `HEADROOM_OPENCODE_PLUGIN_PATH` env
override, then a repo-checkout build (fresher during development), then
the packaged bundle.
- CI (`opencode-plugin.yml`): rebuilds the standalone bundle and fails
the run if the committed artifact drifted from source, with a one-line
fix instruction; workflow path triggers extended to
`headroom/providers/opencode/_dist/**`.
- `tests/test_providers_opencode_plugin_path.py`: packaged bundle exists
and is self-contained (no bare npm imports), env override wins, fallback
resolution order.
## Testing
- [x] Unit tests pass (`pytest`)
- [x] Linting passes (`ruff check .`)
- [x] Type checking passes (`mypy headroom`)
- [x] New tests added for new functionality
- [x] Manual testing performed
### Test Output
```text
$ uv run --frozen --extra dev pytest tests/test_providers_opencode_plugin_path.py \
tests/test_providers_opencode_config.py tests/test_providers_opencode_install.py
============================== 49 passed in 0.31s ==============================
$ uvx ruff check headroom/providers/opencode/runtime.py tests/test_providers_opencode_plugin_path.py
All checks passed!
$ uvx ruff format --check headroom/providers/opencode/runtime.py tests/test_providers_opencode_plugin_path.py
2 files already formatted
$ uv run --frozen --extra dev mypy headroom/providers/opencode/runtime.py
Success: no issues found in 1 source file
$ cd plugins/opencode && npm run build:standalone
ESM dist-standalone/entry.opencode.js 452.28 KB
ESM Build success in 28ms
```
## Real Behavior Proof
- Environment: macOS 15 (arm64), opencode 1.18.5 (Homebrew), node 22 /
npm 10, isolated `XDG_*` dirs so no real user config was touched.
- Exact command / steps:
1. `npm run build:standalone` in `plugins/opencode`.
2. Started a local header-logging HTTP listener on `127.0.0.1:9977`
(stands in for the proxy; logs method, path, headers, returns 401).
3. Registered the standalone bundle by absolute path in a scratch
`opencode.json` (`"plugin":
["<abs>/dist-standalone/entry.opencode.js"]`) with a `google` provider
entry and a fake API key. Note: the bundle's directory has **no**
`node_modules` - this is exactly the site-packages situation.
4. `HEADROOM_PROXY_URL=http://127.0.0.1:9977 opencode run -m
google/gemini-2.5-flash "say hi"`.
- Observed result: the listener received `POST
/v1beta/models/gemini-2.5-flash:streamGenerateContent?alt=sse` with
`User-Agent: opencode/1.18.5 ...` - i.e. the plugin loaded standalone
and rerouted a provider that the baseURL fallback cannot cover (native
Gemini wire format) to the proxy URL from `HEADROOM_PROXY_URL`.
- Not tested: Windows path resolution (pure `pathlib`, no platform
branches); wheel-build byte-determinism of the tsup output across OSes
(the CI drift check will surface it on the first divergent build).
## Review Readiness
- [x] I have performed a self-review
- [x] This PR is ready for human review
## Checklist
- [x] My code follows the project's style guidelines
- [x] I have performed a self-review of my code
- [x] I have commented my code, particularly in hard-to-understand areas
- [ ] I have made corresponding changes to the documentation
- [x] My changes generate no new warnings
- [x] I have added tests that prove my fix is effective or that my
feature works
- [x] New and existing unit tests pass locally with my changes
- [x] I did **not** edit `CHANGELOG.md` — it is generated by
release-please from my Conventional Commit PR title (a CI guard enforces
this)
## Screenshots (if applicable)
Not applicable - CLI/packaging change.
## Additional Notes
- Documentation checklist item: unchecked because the only doc surface I
found is the `headroom_opencode_plugin_path()` docstring, which this PR
rewrites to describe the three-step resolution order. Happy to add a
line to `docs/content/docs/` if there is a preferred page.
- A committed build artifact is not free: the CI drift check keeps it
honest, and the byte-compare relies on tsup/esbuild determinism under
`npm ci` (pinned lockfile). If you'd rather avoid the committed artifact
entirely, the alternative is publishing `headroom-opencode` to npm (its
`package.json` is publish-ready) and registering the plugin by package
name - happy to rework in that direction; the wheel-bundled path has the
advantage of version-locking the plugin to the backend it ships with.
- Downstream motivation: Headroom Desktop manages a long-lived shared
proxy (no `wrap` launcher) and wants to register this plugin from the
installed wheel path so OpenCode users get all-provider routing there
too.
🤖 Generated with [Claude Code](https://claude.com/claude-code )
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-27 06:40:43 -07:00
dependabot[bot]
961866ba7c
deps: bump the npm-minor-patch group across 3 directories with 7 updates ( #2276 )
...
Bumps the npm-minor-patch group with 6 updates in the /docs directory:
| Package | From | To |
| --- | --- | --- |
| [fumadocs-core](https://github.com/fuma-nama/fumadocs ) | `16.11.1` |
`16.11.5` |
| [fumadocs-mdx](https://github.com/fuma-nama/fumadocs ) | `15.1.0` |
`15.2.0` |
| [fumadocs-ui](https://github.com/fuma-nama/fumadocs ) | `16.11.1` |
`16.11.5` |
|
[@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript )
| `0.106.0` | `0.111.0` |
| [openai](https://github.com/openai/openai-node ) | `6.33.0` | `6.47.0`
|
| [postcss](https://github.com/postcss/postcss ) | `8.5.16` | `8.5.19` |
Bumps the npm-minor-patch group with 1 update in the /plugins/opencode
directory: @opencode-ai/plugin.
Bumps the npm-minor-patch group with 1 update in the /sdk/typescript
directory:
[@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript ).
Updates `fumadocs-core` from 16.11.1 to 16.11.5
<details>
<summary>Commits</summary>
<ul>
<li><a
href="52af6cf292 "><code>52af6cf</code></a>
Merge pull request <a
href="https://redirect.github.com/fuma-nama/fumadocs/issues/3416 ">#3416</a>
from fuma-nama/tegami/version-packages</li>
<li><a
href="efc9d18402 "><code>efc9d18</code></a>
chore(mdx): bake passthroughs into runtime module</li>
<li><a
href="368a92e3a2 "><code>368a92e</code></a>
feat(mdx): macro collection-level last modified time</li>
<li><a
href="13dfdbc224 "><code>13dfdbc</code></a>
feat(mdx): no longer require include for macros</li>
<li><a
href="63623320b5 "><code>6362332</code></a>
test macro API on vite</li>
<li><a
href="126a74d995 "><code>126a74d</code></a>
fix(ui): fix accessibility of sidebar components</li>
<li><a
href="430254caab "><code>430254c</code></a>
fix(mdx): fix file check</li>
<li><a
href="1862822aa5 "><code>1862822</code></a>
feat(mdx): redesign macro infrastructure</li>
<li><a
href="d3710a9614 "><code>d3710a9</code></a>
fix(openapi): fix invalid generated request</li>
<li><a
href="ba78b0177b "><code>ba78b01</code></a>
fix(ui): correct prop types</li>
<li>Additional commits viewable in <a
href="https://github.com/fuma-nama/fumadocs/compare/fumadocs@16.11.1...fumadocs@16.11.5 ">compare
view</a></li>
</ul>
</details>
<br />
Updates `fumadocs-mdx` from 15.1.0 to 15.2.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/fuma-nama/fumadocs/releases ">fumadocs-mdx's
releases</a>.</em></p>
<blockquote>
<h2>fumadocs-mdx@15.2.0</h2>
<h3>Support Macro API</h3>
<p>Use <code>fumadocs-mdx/macro</code> to define collections, and enable
the macro-style API from bundler plugin (e.g. <code>createMDX</code>)
using the <code>include</code> option.</p>
<h2>fumadocs-mdx@15.1.1</h2>
<h3>Migrate from <code>js-yaml</code> to <code>yaml</code></h3>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="52af6cf292 "><code>52af6cf</code></a>
Merge pull request <a
href="https://redirect.github.com/fuma-nama/fumadocs/issues/3416 ">#3416</a>
from fuma-nama/tegami/version-packages</li>
<li><a
href="efc9d18402 "><code>efc9d18</code></a>
chore(mdx): bake passthroughs into runtime module</li>
<li><a
href="368a92e3a2 "><code>368a92e</code></a>
feat(mdx): macro collection-level last modified time</li>
<li><a
href="13dfdbc224 "><code>13dfdbc</code></a>
feat(mdx): no longer require include for macros</li>
<li><a
href="63623320b5 "><code>6362332</code></a>
test macro API on vite</li>
<li><a
href="126a74d995 "><code>126a74d</code></a>
fix(ui): fix accessibility of sidebar components</li>
<li><a
href="430254caab "><code>430254c</code></a>
fix(mdx): fix file check</li>
<li><a
href="1862822aa5 "><code>1862822</code></a>
feat(mdx): redesign macro infrastructure</li>
<li><a
href="d3710a9614 "><code>d3710a9</code></a>
fix(openapi): fix invalid generated request</li>
<li><a
href="ba78b0177b "><code>ba78b01</code></a>
fix(ui): correct prop types</li>
<li>Additional commits viewable in <a
href="https://github.com/fuma-nama/fumadocs/compare/fumadocs-mdx@15.1.0...fumadocs-mdx@15.2.0 ">compare
view</a></li>
</ul>
</details>
<br />
Updates `fumadocs-ui` from 16.11.1 to 16.11.5
<details>
<summary>Commits</summary>
<ul>
<li><a
href="52af6cf292 "><code>52af6cf</code></a>
Merge pull request <a
href="https://redirect.github.com/fuma-nama/fumadocs/issues/3416 ">#3416</a>
from fuma-nama/tegami/version-packages</li>
<li><a
href="efc9d18402 "><code>efc9d18</code></a>
chore(mdx): bake passthroughs into runtime module</li>
<li><a
href="368a92e3a2 "><code>368a92e</code></a>
feat(mdx): macro collection-level last modified time</li>
<li><a
href="13dfdbc224 "><code>13dfdbc</code></a>
feat(mdx): no longer require include for macros</li>
<li><a
href="63623320b5 "><code>6362332</code></a>
test macro API on vite</li>
<li><a
href="126a74d995 "><code>126a74d</code></a>
fix(ui): fix accessibility of sidebar components</li>
<li><a
href="430254caab "><code>430254c</code></a>
fix(mdx): fix file check</li>
<li><a
href="1862822aa5 "><code>1862822</code></a>
feat(mdx): redesign macro infrastructure</li>
<li><a
href="d3710a9614 "><code>d3710a9</code></a>
fix(openapi): fix invalid generated request</li>
<li><a
href="ba78b0177b "><code>ba78b01</code></a>
fix(ui): correct prop types</li>
<li>Additional commits viewable in <a
href="https://github.com/fuma-nama/fumadocs/compare/fumadocs@16.11.1...fumadocs@16.11.5 ">compare
view</a></li>
</ul>
</details>
<br />
Updates `@anthropic-ai/sdk` from 0.106.0 to 0.111.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/anthropic-sdk-typescript/releases ">@anthropic-ai/sdk's
releases</a>.</em></p>
<blockquote>
<h2>sdk: v0.111.0</h2>
<h2>0.111.0 (2026-07-10)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.110.0...sdk-v0.111.0 ">sdk-v0.110.0...sdk-v0.111.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add support for dreaming (<a
href="77b28a6472 ">77b28a6</a>)</li>
<li><strong>tools:</strong> gate session tool calls on
evaluated_permission; bound idle by server stop_reason (<a
href="68a6d7b92a ">68a6d7b</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>docs:</strong> small updates to field descriptions (<a
href="e25b885eac ">e25b885</a>)</li>
<li><strong>docs:</strong> update model example (<a
href="a33f3f0b7c ">a33f3f0</a>)</li>
<li><strong>docs:</strong> updates to descriptions and examples (<a
href="eac4bace32 ">eac4bac</a>)</li>
</ul>
<h2>sdk: v0.110.0</h2>
<h2>0.110.0 (2026-07-02)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.109.1...sdk-v0.110.0 ">sdk-v0.109.1...sdk-v0.110.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add agent-memory-2026-07-22 beta header (<a
href="a470e10aaa ">a470e10</a>)</li>
</ul>
<h2>sdk: v0.109.1</h2>
<h2>0.109.1 (2026-07-01)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.109.0...sdk-v0.109.1 ">sdk-v0.109.0...sdk-v0.109.1</a></p>
<h3>Chores</h3>
<ul>
<li><strong>api:</strong> remove some nonfunctional types from the SDKs
(<a
href="cc4dd4e257 ">cc4dd4e</a>)</li>
</ul>
<h2>sdk: v0.109.0</h2>
<h2>0.109.0 (2026-06-30)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.108.0...sdk-v0.109.0 ">sdk-v0.108.0...sdk-v0.109.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add support for Managed Agents event delta
streaming, agent overrides, reverse pagination, vault credential
injection scoping, and agent and deployment webhook events (<a
href="7f3211b488 ">7f3211b</a>)</li>
</ul>
<h2>sdk: v0.108.0</h2>
<h2>0.108.0 (2026-06-30)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.107.0...sdk-v0.108.0 ">sdk-v0.107.0...sdk-v0.108.0</a></p>
<h3>Features</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md ">@anthropic-ai/sdk's
changelog</a>.</em></p>
<blockquote>
<h2>0.111.0 (2026-07-10)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.110.0...sdk-v0.111.0 ">sdk-v0.110.0...sdk-v0.111.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add support for dreaming (<a
href="77b28a6472 ">77b28a6</a>)</li>
<li><strong>tools:</strong> gate session tool calls on
evaluated_permission; bound idle by server stop_reason (<a
href="68a6d7b92a ">68a6d7b</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>docs:</strong> small updates to field descriptions (<a
href="e25b885eac ">e25b885</a>)</li>
<li><strong>docs:</strong> update model example (<a
href="a33f3f0b7c ">a33f3f0</a>)</li>
<li><strong>docs:</strong> updates to descriptions and examples (<a
href="eac4bace32 ">eac4bac</a>)</li>
</ul>
<h2>0.110.0 (2026-07-02)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.109.1...sdk-v0.110.0 ">sdk-v0.109.1...sdk-v0.110.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add agent-memory-2026-07-22 beta header (<a
href="a470e10aaa ">a470e10</a>)</li>
</ul>
<h2>0.109.1 (2026-07-01)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.109.0...sdk-v0.109.1 ">sdk-v0.109.0...sdk-v0.109.1</a></p>
<h3>Chores</h3>
<ul>
<li><strong>api:</strong> remove some nonfunctional types from the SDKs
(<a
href="cc4dd4e257 ">cc4dd4e</a>)</li>
</ul>
<h2>0.109.0 (2026-06-30)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.108.0...sdk-v0.109.0 ">sdk-v0.108.0...sdk-v0.109.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add support for Managed Agents event delta
streaming, agent overrides, reverse pagination, vault credential
injection scoping, and agent and deployment webhook events (<a
href="7f3211b488 ">7f3211b</a>)</li>
</ul>
<h2>0.108.0 (2026-06-30)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.107.0...sdk-v0.108.0 ">sdk-v0.107.0...sdk-v0.108.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add support for claude-sonnet-5 (<a
href="4588db01ec ">4588db0</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="9e46760688 "><code>9e46760</code></a>
chore: release main</li>
<li><a
href="8d461ea962 "><code>8d461ea</code></a>
feat(api): add support for dreaming</li>
<li><a
href="9436e29159 "><code>9436e29</code></a>
codegen metadata</li>
<li><a
href="0aec1e748b "><code>0aec1e7</code></a>
feat(tools): gate session tool calls on evaluated_permission; bound idle
by s...</li>
<li><a
href="ac2fc6779d "><code>ac2fc67</code></a>
chore(docs): update model example</li>
<li><a
href="c8af65d6af "><code>c8af65d</code></a>
chore(docs): updates to descriptions and examples</li>
<li><a
href="2a3a9042ab "><code>2a3a904</code></a>
codegen metadata</li>
<li><a
href="57c56c9172 "><code>57c56c9</code></a>
chore(docs): small updates to field descriptions</li>
<li><a
href="4f2eb80719 "><code>4f2eb80</code></a>
chore: release main (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/1107 ">#1107</a>)</li>
<li><a
href="96d1a991b6 "><code>96d1a99</code></a>
chore: release main (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/1106 ">#1106</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.106.0...sdk-v0.111.0 ">compare
view</a></li>
</ul>
</details>
<br />
Updates `openai` from 6.33.0 to 6.47.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/openai/openai-node/releases ">openai's
releases</a>.</em></p>
<blockquote>
<h2>v6.47.0</h2>
<h2>6.47.0 (2026-07-14)</h2>
<p>Full Changelog: <a
href="https://github.com/openai/openai-node/compare/v6.46.0...v6.47.0 ">v6.46.0...v6.47.0</a></p>
<h3>Features</h3>
<ul>
<li>add async event iterators (<a
href="https://redirect.github.com/openai/openai-node/issues/1977 ">#1977</a>)
(<a
href="2ece8aa848 ">2ece8aa</a>)</li>
<li>add fromReadableStream to ResponseStream (<a
href="https://redirect.github.com/openai/openai-node/issues/1987 ">#1987</a>)
(<a
href="5984f442e0 ">5984f44</a>)</li>
<li><strong>api:</strong> add owner_project_access to APIKeyListParams
(<a
href="7bfce973a1 ">7bfce97</a>)</li>
<li>pass context to runTools callbacks (<a
href="https://redirect.github.com/openai/openai-node/issues/1973 ">#1973</a>)
(<a
href="a6f01e53de ">a6f01e5</a>)</li>
<li>support streaming file uploads (<a
href="https://redirect.github.com/openai/openai-node/issues/1970 ">#1970</a>)
(<a
href="a86f1fde30 ">a86f1fd</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>assistants:</strong> preserve readable stream deltas (<a
href="https://redirect.github.com/openai/openai-node/issues/1994 ">#1994</a>)
(<a
href="1cdc0196b4 ">1cdc019</a>)</li>
<li>avoid deep Deno Zod types (<a
href="https://redirect.github.com/openai/openai-node/issues/1980 ">#1980</a>)
(<a
href="ae17127eff ">ae17127</a>),
closes <a
href="https://redirect.github.com/openai/openai-node/issues/984 ">#984</a></li>
<li><strong>ci:</strong> bump <code>@arethetypeswrong/cli</code> to
^0.18.0 and run CI workflows on Node 24 (<a
href="baa0b2ad90 ">baa0b2a</a>)</li>
<li>emit stream finalization errors (<a
href="https://redirect.github.com/openai/openai-node/issues/1972 ">#1972</a>)
(<a
href="9555b71ab8 ">9555b71</a>)</li>
<li>handle Azure filter stream chunks (<a
href="https://redirect.github.com/openai/openai-node/issues/1982 ">#1982</a>)
(<a
href="c1c5c28267 ">c1c5c28</a>),
closes <a
href="https://redirect.github.com/openai/openai-node/issues/1015 ">#1015</a></li>
<li><strong>zod:</strong> support zod v4 mini schemas (<a
href="https://redirect.github.com/openai/openai-node/issues/1985 ">#1985</a>)
(<a
href="2df10fc19a ">2df10fc</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>clarify strict Zod function schemas (<a
href="https://redirect.github.com/openai/openai-node/issues/1988 ">#1988</a>)
(<a
href="373b08ac3b ">373b08a</a>)</li>
</ul>
<h2>v6.46.0</h2>
<h2>6.46.0 (2026-07-09)</h2>
<p>Full Changelog: <a
href="https://github.com/openai/openai-node/compare/v6.45.0...v6.46.0 ">v6.45.0...v6.46.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> gpt-5.6-sol updates (<a
href="6c397d5d28 ">6c397d5</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>assistants:</strong> place array delta entries by index
instead of appending (<a
href="https://redirect.github.com/openai/openai-node/issues/1963 ">#1963</a>)
(<a
href="0e18d30a31 ">0e18d30</a>)</li>
<li><strong>runner:</strong> normalize missing tool call IDs (<a
href="https://redirect.github.com/openai/openai-node/issues/1958 ">#1958</a>)
(<a
href="6371623aad ">6371623</a>)</li>
<li>upgrade next to 15.5.16 in examples (<a
href="https://redirect.github.com/openai/openai-node/issues/1967 ">#1967</a>)
(<a
href="95b54e5894 ">95b54e5</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>add Azure Assistants example (<a
href="https://redirect.github.com/openai/openai-node/issues/1975 ">#1975</a>)
(<a
href="90a72e5345 ">90a72e5</a>),
closes <a
href="https://redirect.github.com/openai/openai-node/issues/701 ">#701</a></li>
<li>document assistant stream failures (<a
href="https://redirect.github.com/openai/openai-node/issues/1979 ">#1979</a>)
(<a
href="d93fbe5bc5 ">d93fbe5</a>),
closes <a
href="https://redirect.github.com/openai/openai-node/issues/959 ">#959</a></li>
<li>document file search result limits (<a
href="https://redirect.github.com/openai/openai-node/issues/1981 ">#1981</a>)
(<a
href="e9dc283dce ">e9dc283</a>),
closes <a
href="https://redirect.github.com/openai/openai-node/issues/1004 ">#1004</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/openai/openai-node/blob/main/CHANGELOG.md ">openai's
changelog</a>.</em></p>
<blockquote>
<h2>6.47.0 (2026-07-14)</h2>
<p>Full Changelog: <a
href="https://github.com/openai/openai-node/compare/v6.46.0...v6.47.0 ">v6.46.0...v6.47.0</a></p>
<h3>Features</h3>
<ul>
<li>add async event iterators (<a
href="https://redirect.github.com/openai/openai-node/issues/1977 ">#1977</a>)
(<a
href="2ece8aa848 ">2ece8aa</a>)</li>
<li>add fromReadableStream to ResponseStream (<a
href="https://redirect.github.com/openai/openai-node/issues/1987 ">#1987</a>)
(<a
href="5984f442e0 ">5984f44</a>)</li>
<li><strong>api:</strong> add owner_project_access to APIKeyListParams
(<a
href="7bfce973a1 ">7bfce97</a>)</li>
<li>pass context to runTools callbacks (<a
href="https://redirect.github.com/openai/openai-node/issues/1973 ">#1973</a>)
(<a
href="a6f01e53de ">a6f01e5</a>)</li>
<li>support streaming file uploads (<a
href="https://redirect.github.com/openai/openai-node/issues/1970 ">#1970</a>)
(<a
href="a86f1fde30 ">a86f1fd</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>assistants:</strong> preserve readable stream deltas (<a
href="https://redirect.github.com/openai/openai-node/issues/1994 ">#1994</a>)
(<a
href="1cdc0196b4 ">1cdc019</a>)</li>
<li>avoid deep Deno Zod types (<a
href="https://redirect.github.com/openai/openai-node/issues/1980 ">#1980</a>)
(<a
href="ae17127eff ">ae17127</a>),
closes <a
href="https://redirect.github.com/openai/openai-node/issues/984 ">#984</a></li>
<li><strong>ci:</strong> bump <code>@arethetypeswrong/cli</code> to
^0.18.0 and run CI workflows on Node 24 (<a
href="baa0b2ad90 ">baa0b2a</a>)</li>
<li>emit stream finalization errors (<a
href="https://redirect.github.com/openai/openai-node/issues/1972 ">#1972</a>)
(<a
href="9555b71ab8 ">9555b71</a>)</li>
<li>handle Azure filter stream chunks (<a
href="https://redirect.github.com/openai/openai-node/issues/1982 ">#1982</a>)
(<a
href="c1c5c28267 ">c1c5c28</a>),
closes <a
href="https://redirect.github.com/openai/openai-node/issues/1015 ">#1015</a></li>
<li><strong>zod:</strong> support zod v4 mini schemas (<a
href="https://redirect.github.com/openai/openai-node/issues/1985 ">#1985</a>)
(<a
href="2df10fc19a ">2df10fc</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>clarify strict Zod function schemas (<a
href="https://redirect.github.com/openai/openai-node/issues/1988 ">#1988</a>)
(<a
href="373b08ac3b ">373b08a</a>)</li>
</ul>
<h2>6.46.0 (2026-07-09)</h2>
<p>Full Changelog: <a
href="https://github.com/openai/openai-node/compare/v6.45.0...v6.46.0 ">v6.45.0...v6.46.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> gpt-5.6-sol updates (<a
href="6c397d5d28 ">6c397d5</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>assistants:</strong> place array delta entries by index
instead of appending (<a
href="https://redirect.github.com/openai/openai-node/issues/1963 ">#1963</a>)
(<a
href="0e18d30a31 ">0e18d30</a>)</li>
<li><strong>runner:</strong> normalize missing tool call IDs (<a
href="https://redirect.github.com/openai/openai-node/issues/1958 ">#1958</a>)
(<a
href="6371623aad ">6371623</a>)</li>
<li>upgrade next to 15.5.16 in examples (<a
href="https://redirect.github.com/openai/openai-node/issues/1967 ">#1967</a>)
(<a
href="95b54e5894 ">95b54e5</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li>add Azure Assistants example (<a
href="https://redirect.github.com/openai/openai-node/issues/1975 ">#1975</a>)
(<a
href="90a72e5345 ">90a72e5</a>),
closes <a
href="https://redirect.github.com/openai/openai-node/issues/701 ">#701</a></li>
<li>document assistant stream failures (<a
href="https://redirect.github.com/openai/openai-node/issues/1979 ">#1979</a>)
(<a
href="d93fbe5bc5 ">d93fbe5</a>),
closes <a
href="https://redirect.github.com/openai/openai-node/issues/959 ">#959</a></li>
<li>document file search result limits (<a
href="https://redirect.github.com/openai/openai-node/issues/1981 ">#1981</a>)
(<a
href="e9dc283dce ">e9dc283</a>),
closes <a
href="https://redirect.github.com/openai/openai-node/issues/1004 ">#1004</a></li>
</ul>
<h2>6.45.0 (2026-06-24)</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="6255405380 "><code>6255405</code></a>
release: 6.47.0 (<a
href="https://redirect.github.com/openai/openai-node/issues/1989 ">#1989</a>)</li>
<li><a
href="1cdc0196b4 "><code>1cdc019</code></a>
fix(assistants): preserve readable stream deltas (<a
href="https://redirect.github.com/openai/openai-node/issues/1994 ">#1994</a>)</li>
<li><a
href="ec2f57fd0d "><code>ec2f57f</code></a>
Preserve snapshots when resuming response streams (<a
href="https://redirect.github.com/openai/openai-node/issues/1984 ">#1984</a>)</li>
<li><a
href="2df10fc19a "><code>2df10fc</code></a>
fix(zod): support zod v4 mini schemas (<a
href="https://redirect.github.com/openai/openai-node/issues/1985 ">#1985</a>)</li>
<li><a
href="ebb649811d "><code>ebb6498</code></a>
Fix runTools readable stream round trip tool results (<a
href="https://redirect.github.com/openai/openai-node/issues/1986 ">#1986</a>)</li>
<li><a
href="5984f442e0 "><code>5984f44</code></a>
feat: add fromReadableStream to ResponseStream (<a
href="https://redirect.github.com/openai/openai-node/issues/1987 ">#1987</a>)</li>
<li><a
href="373b08ac3b "><code>373b08a</code></a>
docs: clarify strict Zod function schemas (<a
href="https://redirect.github.com/openai/openai-node/issues/1988 ">#1988</a>)</li>
<li><a
href="a6f01e53de "><code>a6f01e5</code></a>
feat: pass context to runTools callbacks (<a
href="https://redirect.github.com/openai/openai-node/issues/1973 ">#1973</a>)</li>
<li><a
href="53e580efb6 "><code>53e580e</code></a>
test: serialize Steady-backed Jest runs (<a
href="https://redirect.github.com/openai/openai-node/issues/1976 ">#1976</a>)</li>
<li><a
href="a86f1fde30 "><code>a86f1fd</code></a>
feat: support streaming file uploads (<a
href="https://redirect.github.com/openai/openai-node/issues/1970 ">#1970</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/openai/openai-node/compare/v6.33.0...v6.47.0 ">compare
view</a></li>
</ul>
</details>
<br />
Updates `postcss` from 8.5.16 to 8.5.19
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/postcss/releases ">postcss's
releases</a>.</em></p>
<blockquote>
<h2>8.5.19</h2>
<ul>
<li>Fixed cleaning <code>before</code> for new nodes inserted to
<code>Root</code> (by <a
href="https://github.com/MahinAnowar "><code>@MahinAnowar</code></a>).</li>
</ul>
<h2>8.5.18</h2>
<ul>
<li>Restricted loading previous source maps file to the
<code>opts.from</code> folder for security reasons (use <code>unsafeMap:
true</code> to disable the check).</li>
</ul>
<h2>8.5.17</h2>
<ul>
<li>Fixed <code>Maximum call stack size exceeded</code> error.</li>
<li>Fixed Prototype hijacking for <code>postcss.fromJSON()</code>.</li>
<li>Fixed <code>Input#origin()</code> for unmapped end position (by <a
href="https://github.com/chatman-media "><code>@chatman-media</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/postcss/blob/main/CHANGELOG.md ">postcss's
changelog</a>.</em></p>
<blockquote>
<h2>8.5.19</h2>
<ul>
<li>Fixed cleaning <code>before</code> for new nodes inserted to
<code>Root</code> (by <a
href="https://github.com/MahinAnowar "><code>@MahinAnowar</code></a>).</li>
</ul>
<h2>8.5.18</h2>
<ul>
<li>Restricted loading previous source maps file to the
<code>opts.from</code> folder for security reasons (use <code>unsafeMap:
true</code> to disable the check).</li>
</ul>
<h2>8.5.17</h2>
<ul>
<li>Fixed <code>Maximum call stack size exceeded</code> error.</li>
<li>Fixed Prototype hijacking for <code>postcss.fromJSON()</code>.</li>
<li>Fixed <code>Input#origin()</code> for unmapped end position (by <a
href="https://github.com/chatman-media "><code>@chatman-media</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="9543b22769 "><code>9543b22</code></a>
Release 8.5.19 version</li>
<li><a
href="3d13bf9360 "><code>3d13bf9</code></a>
Fix CI on Windows too</li>
<li><a
href="00d0dd2322 "><code>00d0dd2</code></a>
Keep explicitly set raws.before when inserting nodes into root (<a
href="https://redirect.github.com/postcss/postcss/issues/2111 ">#2111</a>)</li>
<li><a
href="7a05b33e7a "><code>7a05b33</code></a>
Temporary fix CI</li>
<li><a
href="4c0d194c13 "><code>4c0d194</code></a>
Release 8.5.18 version</li>
<li><a
href="92b4e7891e "><code>92b4e78</code></a>
Update dependencies</li>
<li><a
href="95663d3eb7 "><code>95663d3</code></a>
Limit where source map can be loaded for security reasons</li>
<li><a
href="74e25ae9f4 "><code>74e25ae</code></a>
Release 8.5.17 version</li>
<li><a
href="d1518afd5a "><code>d1518af</code></a>
Fix Maximum call stack size exceeded error</li>
<li><a
href="2421312ffe "><code>2421312</code></a>
Fix linter</li>
<li>Additional commits viewable in <a
href="https://github.com/postcss/postcss/compare/8.5.16...8.5.19 ">compare
view</a></li>
</ul>
</details>
<br />
Updates `@opencode-ai/plugin` from 1.17.16 to 1.18.2
Updates `@anthropic-ai/sdk` from 0.110.0 to 0.111.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/anthropic-sdk-typescript/releases ">@anthropic-ai/sdk's
releases</a>.</em></p>
<blockquote>
<h2>sdk: v0.111.0</h2>
<h2>0.111.0 (2026-07-10)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.110.0...sdk-v0.111.0 ">sdk-v0.110.0...sdk-v0.111.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add support for dreaming (<a
href="77b28a6472 ">77b28a6</a>)</li>
<li><strong>tools:</strong> gate session tool calls on
evaluated_permission; bound idle by server stop_reason (<a
href="68a6d7b92a ">68a6d7b</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>docs:</strong> small updates to field descriptions (<a
href="e25b885eac ">e25b885</a>)</li>
<li><strong>docs:</strong> update model example (<a
href="a33f3f0b7c ">a33f3f0</a>)</li>
<li><strong>docs:</strong> updates to descriptions and examples (<a
href="eac4bace32 ">eac4bac</a>)</li>
</ul>
<h2>sdk: v0.110.0</h2>
<h2>0.110.0 (2026-07-02)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.109.1...sdk-v0.110.0 ">sdk-v0.109.1...sdk-v0.110.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add agent-memory-2026-07-22 beta header (<a
href="a470e10aaa ">a470e10</a>)</li>
</ul>
<h2>sdk: v0.109.1</h2>
<h2>0.109.1 (2026-07-01)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.109.0...sdk-v0.109.1 ">sdk-v0.109.0...sdk-v0.109.1</a></p>
<h3>Chores</h3>
<ul>
<li><strong>api:</strong> remove some nonfunctional types from the SDKs
(<a
href="cc4dd4e257 ">cc4dd4e</a>)</li>
</ul>
<h2>sdk: v0.109.0</h2>
<h2>0.109.0 (2026-06-30)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.108.0...sdk-v0.109.0 ">sdk-v0.108.0...sdk-v0.109.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add support for Managed Agents event delta
streaming, agent overrides, reverse pagination, vault credential
injection scoping, and agent and deployment webhook events (<a
href="7f3211b488 ">7f3211b</a>)</li>
</ul>
<h2>sdk: v0.108.0</h2>
<h2>0.108.0 (2026-06-30)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.107.0...sdk-v0.108.0 ">sdk-v0.107.0...sdk-v0.108.0</a></p>
<h3>Features</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md ">@anthropic-ai/sdk's
changelog</a>.</em></p>
<blockquote>
<h2>0.111.0 (2026-07-10)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.110.0...sdk-v0.111.0 ">sdk-v0.110.0...sdk-v0.111.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add support for dreaming (<a
href="77b28a6472 ">77b28a6</a>)</li>
<li><strong>tools:</strong> gate session tool calls on
evaluated_permission; bound idle by server stop_reason (<a
href="68a6d7b92a ">68a6d7b</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>docs:</strong> small updates to field descriptions (<a
href="e25b885eac ">e25b885</a>)</li>
<li><strong>docs:</strong> update model example (<a
href="a33f3f0b7c ">a33f3f0</a>)</li>
<li><strong>docs:</strong> updates to descriptions and examples (<a
href="eac4bace32 ">eac4bac</a>)</li>
</ul>
<h2>0.110.0 (2026-07-02)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.109.1...sdk-v0.110.0 ">sdk-v0.109.1...sdk-v0.110.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add agent-memory-2026-07-22 beta header (<a
href="a470e10aaa ">a470e10</a>)</li>
</ul>
<h2>0.109.1 (2026-07-01)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.109.0...sdk-v0.109.1 ">sdk-v0.109.0...sdk-v0.109.1</a></p>
<h3>Chores</h3>
<ul>
<li><strong>api:</strong> remove some nonfunctional types from the SDKs
(<a
href="cc4dd4e257 ">cc4dd4e</a>)</li>
</ul>
<h2>0.109.0 (2026-06-30)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.108.0...sdk-v0.109.0 ">sdk-v0.108.0...sdk-v0.109.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add support for Managed Agents event delta
streaming, agent overrides, reverse pagination, vault credential
injection scoping, and agent and deployment webhook events (<a
href="7f3211b488 ">7f3211b</a>)</li>
</ul>
<h2>0.108.0 (2026-06-30)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.107.0...sdk-v0.108.0 ">sdk-v0.107.0...sdk-v0.108.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add support for claude-sonnet-5 (<a
href="4588db01ec ">4588db0</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="9e46760688 "><code>9e46760</code></a>
chore: release main</li>
<li><a
href="8d461ea962 "><code>8d461ea</code></a>
feat(api): add support for dreaming</li>
<li><a
href="9436e29159 "><code>9436e29</code></a>
codegen metadata</li>
<li><a
href="0aec1e748b "><code>0aec1e7</code></a>
feat(tools): gate session tool calls on evaluated_permission; bound idle
by s...</li>
<li><a
href="ac2fc6779d "><code>ac2fc67</code></a>
chore(docs): update model example</li>
<li><a
href="c8af65d6af "><code>c8af65d</code></a>
chore(docs): updates to descriptions and examples</li>
<li><a
href="2a3a9042ab "><code>2a3a904</code></a>
codegen metadata</li>
<li><a
href="57c56c9172 "><code>57c56c9</code></a>
chore(docs): small updates to field descriptions</li>
<li><a
href="4f2eb80719 "><code>4f2eb80</code></a>
chore: release main (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/1107 ">#1107</a>)</li>
<li><a
href="96d1a991b6 "><code>96d1a99</code></a>
chore: release main (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/1106 ">#1106</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.106.0...sdk-v0.111.0 ">compare
view</a></li>
</ul>
</details>
<br />
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 11:21:14 -05:00
JD Davis
ea3d5a86b7
fix(deps): clear Dependabot lockfile alerts ( #2175 )
...
## Description
Clears the current dependency/security-audit blockers that are making
unrelated PRs red:
- `transformers 5.3.0` / `CVE-2026-5241`, fixed by requiring
`transformers>=5.5.0` in the locked optional dependency set.
- `sqlitedict <=2.1.0` via the optional `benchmark` extra's
`lm-eval[api]` dependency. There is no patched `sqlitedict` release, so
this PR removes the published/locked `benchmark` extra instead of
shipping a known-vulnerable transitive dependency.
- `esbuild >=0.27.3,<0.28.1` in the OpenCode plugin lockfile, fixed by
forcing `esbuild@0.28.1` through the OpenCode npm override and
regenerated lockfile.
The benchmark code still invokes `python -m lm_eval`; researchers who
need that harness should install `lm-eval[api]` in their benchmark
environment until its transitive vulnerability has a patched release.
## Type of Change
- [x] Bug fix (non-breaking change that fixes an issue)
- [ ] New feature (non-breaking change that adds functionality)
- [ ] Breaking change (fix or feature that would cause existing
functionality to change)
- [ ] Documentation update
- [ ] Performance improvement
- [ ] Code refactoring (no functional changes)
## Changes Made
- `pyproject.toml`: remove the `benchmark` optional extra, document
external `lm-eval[api]` installation guidance, and require
`transformers>=5.5.0`.
- `uv.lock`: regenerate without the `benchmark` extra, removing
`lm-eval` and `sqlitedict` lock entries and locking the patched
transformers floor.
- `plugins/opencode/package.json`: add an `overrides` entry for
`esbuild@0.28.1`.
- `plugins/opencode/package-lock.json`: regenerate the OpenCode lockfile
with `esbuild@0.28.1`.
## Testing
- [x] Unit tests pass (`pytest`)
- [x] Linting passes (`ruff check .`)
- [ ] Type checking passes (`mypy headroom`)
- [ ] New tests added for new functionality
- [x] Manual testing performed
### Test Output
```text
uv lock --check
rg -n -F 'sqlitedict' uv.lock # no matches
rg -n -F 'name = "lm-eval"' uv.lock # no matches
rg -n -F "extra == 'benchmark'" uv.lock # no matches
rg -n -F '0.27.7' plugins/opencode/package-lock.json plugins/opencode/package.json # no matches
npm ls esbuild --package-lock-only
npm audit --package-lock-only # found 0 vulnerabilities
git diff --check
```
Previous GitHub checks were green. After merging current `main`, fresh
GitHub checks are running again; local targeted validation still passes.
## Real Behavior Proof
- Environment: Windows 11, Python 3.13.3, uv, npm in `plugins/opencode`,
Dependabot/pip-audit alert metadata from the failing PR jobs.
- Exact command / steps: inspected the regenerated Python and npm
lockfiles with `rg`, checked the uv lock with `uv lock --check`, checked
OpenCode's dependency tree with `npm ls esbuild --package-lock-only`,
and ran `npm audit --package-lock-only`.
- Observed result: `uv.lock` no longer contains `sqlitedict`, `lm-eval`,
or a `benchmark` extra marker; `transformers` resolves at the patched
`>=5.5.0` floor; OpenCode's lock resolves `esbuild@0.28.1`; `npm audit
--package-lock-only` reports 0 vulnerabilities; GitHub `Dependency audit
(pip-audit)` passes.
- Not tested: running the external `lm-eval` harness after installing it
separately.
## Review Readiness
- [x] I have performed a self-review
- [x] This PR is ready for human review
## Checklist
- [x] My code follows the project's style guidelines
- [x] I have performed a self-review of my code
- [ ] I have commented my code, particularly in hard-to-understand areas
- [x] I have made corresponding changes to the documentation
- [x] My changes generate no new warnings
- [ ] I have added tests that prove my fix is effective or that my
feature works
- [x] New and existing unit tests pass locally with my changes
- [x] I have updated the CHANGELOG.md if applicable
## Screenshots (if applicable)
N/A - dependency and lockfile security fix.
## Additional Notes
The `benchmark` extra can be restored once the upstream `lm-eval[api]`
dependency chain stops pulling a vulnerable `sqlitedict` release.
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-07-14 20:40:28 -07:00
dependabot[bot]
87151952ee
deps: bump @types/node from 22.20.0 to 26.1.1 in /plugins/opencode ( #1688 )
...
Bumps
[@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node )
from 22.20.0 to 26.1.1.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node ">compare
view</a></li>
</ul>
</details>
<br />
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-09 17:02:04 -05:00
dependabot[bot]
8872bbc6a2
deps: bump the npm-minor-patch group across 4 directories with 18 updates ( #1907 )
...
Bumps the npm-minor-patch group with 12 updates in the /docs directory:
| Package | From | To |
| --- | --- | --- |
| [fumadocs-core](https://github.com/fuma-nama/fumadocs ) | `16.10.3` |
`16.11.1` |
| [fumadocs-mdx](https://github.com/fuma-nama/fumadocs ) | `15.0.12` |
`15.1.0` |
| [fumadocs-twoslash](https://github.com/fuma-nama/fumadocs ) | `3.1.15`
| `3.3.0` |
| [fumadocs-ui](https://github.com/fuma-nama/fumadocs ) | `16.10.3` |
`16.11.1` |
| [next](https://github.com/vercel/next.js ) | `16.2.6` | `16.2.10` |
| [react](https://github.com/facebook/react/tree/HEAD/packages/react ) |
`19.2.4` | `19.2.7` |
|
[@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react )
| `19.2.14` | `19.2.17` |
|
[react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom )
| `19.2.4` | `19.2.7` |
| [recharts](https://github.com/recharts/recharts ) | `3.8.1` | `3.9.2` |
|
[@tailwindcss/postcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss )
| `4.2.2` | `4.3.2` |
|
[@types/mdx](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/mdx )
| `2.0.13` | `2.0.14` |
| [postcss](https://github.com/postcss/postcss ) | `8.5.15` | `8.5.16` |
Bumps the npm-minor-patch group with 1 update in the /plugins/openclaw
directory:
[vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest ).
Bumps the npm-minor-patch group with 2 updates in the /plugins/opencode
directory:
[vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest )
and @opencode-ai/plugin.
Bumps the npm-minor-patch group with 3 updates in the /sdk/typescript
directory:
[vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest ),
[@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript )
and [dotenv](https://github.com/motdotla/dotenv ).
Updates `fumadocs-core` from 16.10.3 to 16.11.1
<details>
<summary>Commits</summary>
<ul>
<li><a
href="ab09f500cb "><code>ab09f50</code></a>
Version Packages (<a
href="https://redirect.github.com/fuma-nama/fumadocs/issues/3405 ">#3405</a>)</li>
<li><a
href="889a296d06 "><code>889a296</code></a>
docs: update stale content</li>
<li><a
href="a5c081d0c6 "><code>a5c081d</code></a>
fix: UI inconsistencies</li>
<li><a
href="9a269030df "><code>9a26903</code></a>
Version Packages</li>
<li><a
href="3e33f4362f "><code>3e33f43</code></a>
perf(satteri): reduce clones</li>
<li><a
href="3597c9d1e6 "><code>3597c9d</code></a>
perf(satteri): persist results</li>
<li><a
href="0f389cf3de "><code>0f389cf</code></a>
feat(satteri): decouple imports/exports from <code>compile()</code></li>
<li><a
href="4611f97d49 "><code>4611f97</code></a>
feat(satteri): full rehype-toc functionality</li>
<li><a
href="d095300760 "><code>d095300</code></a>
fix(satteri): workaround common issues</li>
<li><a
href="0297e25477 "><code>0297e25</code></a>
configure pretrust</li>
<li>Additional commits viewable in <a
href="https://github.com/fuma-nama/fumadocs/compare/fumadocs-core@16.10.3...fumadocs@16.11.1 ">compare
view</a></li>
</ul>
</details>
<br />
Updates `fumadocs-mdx` from 15.0.12 to 15.1.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/fuma-nama/fumadocs/releases ">fumadocs-mdx's
releases</a>.</em></p>
<blockquote>
<h2>fumadocs-mdx@15.1.0</h2>
<h3>Default to Base UI</h3>
<p>Internal packages & templates now use Base UI rather than Radix
UI.</p>
<h2>fumadocs-mdx@15.0.13</h2>
<h3>Require <code>collection</code> query param at regex matching</h3>
<p>Instead of passing through all JSON/YAML files, the meta loader now
requires <code>collection</code> query param to be triggered.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="9a269030df "><code>9a26903</code></a>
Version Packages</li>
<li><a
href="3e33f4362f "><code>3e33f43</code></a>
perf(satteri): reduce clones</li>
<li><a
href="3597c9d1e6 "><code>3597c9d</code></a>
perf(satteri): persist results</li>
<li><a
href="0f389cf3de "><code>0f389cf</code></a>
feat(satteri): decouple imports/exports from <code>compile()</code></li>
<li><a
href="4611f97d49 "><code>4611f97</code></a>
feat(satteri): full rehype-toc functionality</li>
<li><a
href="d095300760 "><code>d095300</code></a>
fix(satteri): workaround common issues</li>
<li><a
href="0297e25477 "><code>0297e25</code></a>
configure pretrust</li>
<li><a
href="02c242b0da "><code>02c242b</code></a>
chore(satteri): clean code</li>
<li><a
href="3d80b8b242 "><code>3d80b8b</code></a>
fix(mdx): ensure satteri integration is optional</li>
<li><a
href="0ec19af868 "><code>0ec19af</code></a>
feat(satteri): more tests & move remark-include</li>
<li>Additional commits viewable in <a
href="https://github.com/fuma-nama/fumadocs/compare/fumadocs-mdx@15.0.12...fumadocs-mdx@15.1.0 ">compare
view</a></li>
</ul>
</details>
<br />
Updates `fumadocs-twoslash` from 3.1.15 to 3.3.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/fuma-nama/fumadocs/releases ">fumadocs-twoslash's
releases</a>.</em></p>
<blockquote>
<h2>fumadocs-twoslash@3.3.0</h2>
<h3>Default to Base UI</h3>
<p>Internal packages & templates now use Base UI rather than Radix
UI.</p>
<h2>fumadocs-twoslash@3.2.1</h2>
<h3>Migrate to <code>cnfast</code></h3>
<p>Drop <code>tailwind-merge</code>.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="9a269030df "><code>9a26903</code></a>
Version Packages</li>
<li><a
href="3e33f4362f "><code>3e33f43</code></a>
perf(satteri): reduce clones</li>
<li><a
href="3597c9d1e6 "><code>3597c9d</code></a>
perf(satteri): persist results</li>
<li><a
href="0f389cf3de "><code>0f389cf</code></a>
feat(satteri): decouple imports/exports from <code>compile()</code></li>
<li><a
href="4611f97d49 "><code>4611f97</code></a>
feat(satteri): full rehype-toc functionality</li>
<li><a
href="d095300760 "><code>d095300</code></a>
fix(satteri): workaround common issues</li>
<li><a
href="0297e25477 "><code>0297e25</code></a>
configure pretrust</li>
<li><a
href="02c242b0da "><code>02c242b</code></a>
chore(satteri): clean code</li>
<li><a
href="3d80b8b242 "><code>3d80b8b</code></a>
fix(mdx): ensure satteri integration is optional</li>
<li><a
href="0ec19af868 "><code>0ec19af</code></a>
feat(satteri): more tests & move remark-include</li>
<li>Additional commits viewable in <a
href="https://github.com/fuma-nama/fumadocs/compare/fumadocs-twoslash@3.1.15...fumadocs-twoslash@3.3.0 ">compare
view</a></li>
</ul>
</details>
<br />
Updates `fumadocs-ui` from 16.10.3 to 16.11.1
<details>
<summary>Commits</summary>
<ul>
<li><a
href="ab09f500cb "><code>ab09f50</code></a>
Version Packages (<a
href="https://redirect.github.com/fuma-nama/fumadocs/issues/3405 ">#3405</a>)</li>
<li><a
href="889a296d06 "><code>889a296</code></a>
docs: update stale content</li>
<li><a
href="a5c081d0c6 "><code>a5c081d</code></a>
fix: UI inconsistencies</li>
<li><a
href="9a269030df "><code>9a26903</code></a>
Version Packages</li>
<li><a
href="3e33f4362f "><code>3e33f43</code></a>
perf(satteri): reduce clones</li>
<li><a
href="3597c9d1e6 "><code>3597c9d</code></a>
perf(satteri): persist results</li>
<li><a
href="0f389cf3de "><code>0f389cf</code></a>
feat(satteri): decouple imports/exports from <code>compile()</code></li>
<li><a
href="4611f97d49 "><code>4611f97</code></a>
feat(satteri): full rehype-toc functionality</li>
<li><a
href="d095300760 "><code>d095300</code></a>
fix(satteri): workaround common issues</li>
<li><a
href="0297e25477 "><code>0297e25</code></a>
configure pretrust</li>
<li>Additional commits viewable in <a
href="https://github.com/fuma-nama/fumadocs/compare/fumadocs-ui@16.10.3...fumadocs@16.11.1 ">compare
view</a></li>
</ul>
</details>
<br />
Updates `lucide-react` from 1.20.0 to 1.23.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lucide-icons/lucide/releases ">lucide-react's
releases</a>.</em></p>
<blockquote>
<h2>Version 1.23.0</h2>
<h2>What's Changed</h2>
<ul>
<li>fix(docs): prevent scrollbar layout shift on icons page by <a
href="https://github.com/g30r93g "><code>@g30r93g</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4500 ">lucide-icons/lucide#4500</a></li>
<li>chore(docs): Remove certificates banner by <a
href="https://github.com/ericfennis "><code>@ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4504 ">lucide-icons/lucide#4504</a></li>
<li>ci(repo-journal.yml): GH copilot repo summary by <a
href="https://github.com/ericfennis "><code>@ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4505 ">lucide-icons/lucide#4505</a></li>
<li>ci(repo-journal.yml): Small fix in the workflow by <a
href="https://github.com/ericfennis "><code>@ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4508 ">lucide-icons/lucide#4508</a></li>
<li>ci(repo-journal.yml): Switch to token by <a
href="https://github.com/ericfennis "><code>@ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4509 ">lucide-icons/lucide#4509</a></li>
<li>feat(icons): added <code>paper-bag</code> icon by <a
href="https://github.com/dkast "><code>@dkast</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4023 ">lucide-icons/lucide#4023</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/g30r93g "><code>@g30r93g</code></a> made
their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4500 ">lucide-icons/lucide#4500</a></li>
<li><a href="https://github.com/dkast "><code>@dkast</code></a> made
their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4023 ">lucide-icons/lucide#4023</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/lucide-icons/lucide/compare/1.22.0...1.23.0 ">https://github.com/lucide-icons/lucide/compare/1.22.0...1.23.0 </a></p>
<h2>Version 1.22.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(icons): add 6 database variant icons by <a
href="https://github.com/Barakudum "><code>@Barakudum</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4336 ">lucide-icons/lucide#4336</a></li>
<li>ci(release.yml): Remove concurrency field to prevent release mess by
<a href="https://github.com/ericfennis "><code>@ericfennis</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4485 ">lucide-icons/lucide#4485</a></li>
<li>fix(docs): fix color input clipping by <a
href="https://github.com/Hsiii "><code>@Hsiii</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4488 ">lucide-icons/lucide#4488</a></li>
<li>docs(site): add Deno to installation instructions by <a
href="https://github.com/bartlomieju "><code>@bartlomieju</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4486 ">lucide-icons/lucide#4486</a></li>
<li>chore(deps): bump esbuild from 0.25.12 to 0.28.1 by <a
href="https://github.com/dependabot "><code>@dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4459 ">lucide-icons/lucide#4459</a></li>
<li>fix(docs): prevent private analytics token from blocking local dev
by <a href="https://github.com/Hsiii "><code>@Hsiii</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4481 ">lucide-icons/lucide#4481</a></li>
<li>docs(installation.md): Remove outdate next tag in installation by <a
href="https://github.com/ericfennis "><code>@ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4495 ">lucide-icons/lucide#4495</a></li>
<li>fix(lucide-react-native): Fix context provider export by <a
href="https://github.com/ericfennis "><code>@ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4497 ">lucide-icons/lucide#4497</a></li>
<li>fix(astro): add Astro v7 compatibility by <a
href="https://github.com/iseraph-dev "><code>@iseraph-dev</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4491 ">lucide-icons/lucide#4491</a></li>
<li>fix(icons): changed <code>carrot</code> icon by <a
href="https://github.com/jguddas "><code>@jguddas</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4010 ">lucide-icons/lucide#4010</a></li>
<li>fix(icons): changed <code>ungroup</code> icon by <a
href="https://github.com/jguddas "><code>@jguddas</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3969 ">lucide-icons/lucide#3969</a></li>
<li>feat(icons): added <code>phi</code> icon also used as
<code>golden-ratio</code> by <a
href="https://github.com/whoisBugsbunny "><code>@whoisBugsbunny</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4218 ">lucide-icons/lucide#4218</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/bartlomieju "><code>@bartlomieju</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4486 ">lucide-icons/lucide#4486</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/lucide-icons/lucide/compare/1.21.0...1.22.0 ">https://github.com/lucide-icons/lucide/compare/1.21.0...1.22.0 </a></p>
<h2>Version 1.21.0</h2>
<h2>What's Changed</h2>
<ul>
<li>ci(release.yml): Remove new-version in release flow by <a
href="https://github.com/ericfennis "><code>@ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4478 ">lucide-icons/lucide#4478</a></li>
<li>ci(release.yml): Fix workflow and remove <code>version</code>
scripts in package scripts by <a
href="https://github.com/ericfennis "><code>@ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4479 ">lucide-icons/lucide#4479</a></li>
<li>fix(docs): rename navigation category label by <a
href="https://github.com/Hsiii "><code>@Hsiii</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4483 ">lucide-icons/lucide#4483</a></li>
<li>feat(icons): added <code>broken-bone</code> icon by <a
href="https://github.com/Patolord "><code>@Patolord</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4131 ">lucide-icons/lucide#4131</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/Hsiii "><code>@Hsiii</code></a> made
their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4483 ">lucide-icons/lucide#4483</a></li>
<li><a href="https://github.com/Patolord "><code>@Patolord</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4131 ">lucide-icons/lucide#4131</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/lucide-icons/lucide/compare/1.20.0...1.21.0 ">https://github.com/lucide-icons/lucide/compare/1.20.0...1.21.0 </a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="5ff536e139 "><code>5ff536e</code></a>
ci(release.yml): Fix workflow and remove <code>version</code> scripts in
package scripts...</li>
<li>See full diff in <a
href="https://github.com/lucide-icons/lucide/commits/1.23.0/packages/lucide-react ">compare
view</a></li>
</ul>
</details>
<br />
Updates `next` from 16.2.6 to 16.2.10
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/next.js/releases ">next's
releases</a>.</em></p>
<blockquote>
<h2>v16.2.10</h2>
<p>Contains no changes except publishing <code>@next/swc-wasm-web</code>
which was accidentally not published since 16.2.4.</p>
<h2>v16.2.9</h2>
<p>Empty release to ensure <code>next@latest</code> points at a stable
release. Next.js only allows publishing with Trusted Publishing enabled.
In order to fix NPM dist-tags, we have to release a new version.
Updating dist-tags is not possible with Trusted Publishing.</p>
<h2>v16.2.8</h2>
<p>Release with no changes in an attempt to fix <code>next@latest</code>
pointing at a prerelease version.</p>
<h2>v16.2.7</h2>
<blockquote>
<p>[!NOTE]
This release is backporting bug fixes. It does <strong>not</strong>
include all pending features/changes on canary.</p>
</blockquote>
<h3>Core Changes</h3>
<ul>
<li>Backport documentation fixes for v16.2 (<a
href="https://redirect.github.com/vercel/next.js/issues/93804 ">#93804</a>)</li>
<li>[backport] Patch <code>playwright-core</code> to resolve
<code>_finishedPromise</code> on <code>requestFailed</code> (<a
href="https://redirect.github.com/vercel/next.js/issues/93920 ">#93920</a>)</li>
<li>[backport] Fix dev mode hydration failure when page is served from
HTTP cache (<a
href="https://redirect.github.com/vercel/next.js/issues/93492 ">#93492</a>)</li>
<li>[backport] Fix catch-all <code>router.query</code> corruption with
<code>basePath</code> + <code>rewrites</code> (<a
href="https://redirect.github.com/vercel/next.js/issues/93917 ">#93917</a>)</li>
<li>[backport] Encode non-ASCII characters in cache tags at construction
(<a
href="https://redirect.github.com/vercel/next.js/issues/93918 ">#93918</a>)</li>
<li>[backport] Fix server action forwarding loop with middleware
rewrites (<a
href="https://redirect.github.com/vercel/next.js/issues/93919 ">#93919</a>)</li>
<li>[backport] Turbopack: switch from base40 to base38 hash encoding (<a
href="https://redirect.github.com/vercel/next.js/issues/93932 ">#93932</a>)</li>
<li>[ci] Disable hanging node 24 typescript tests on 16.2 backport
branch (<a
href="https://redirect.github.com/vercel/next.js/issues/94164 ">#94164</a>)</li>
<li>[backport] Fix "type: module" in project dir when using
standalone or adapters (<a
href="https://redirect.github.com/vercel/next.js/issues/94050 ">#94050</a>)</li>
<li>[backport] Propagate adapter preferred regions (<a
href="https://redirect.github.com/vercel/next.js/issues/94200 ">#94200</a>)</li>
<li>[16.2.x] Don't drop <code>FormData</code> entries (<a
href="https://redirect.github.com/vercel/next.js/issues/94240 ">#94240</a>)</li>
<li>[backport] feat(turbopack): add LocalPathOrProjectPath PostCSS
config resolution (<a
href="https://redirect.github.com/vercel/next.js/issues/94284 ">#94284</a>)</li>
</ul>
<h3>Credits</h3>
<p>Huge thanks to <a
href="https://github.com/eps1lon "><code>@eps1lon</code></a>, <a
href="https://github.com/icyJoseph "><code>@icyJoseph</code></a>, <a
href="https://github.com/unstubbable "><code>@unstubbable</code></a>, <a
href="https://github.com/mischnic "><code>@mischnic</code></a>, <a
href="https://github.com/bgw "><code>@bgw</code></a>, <a
href="https://github.com/timneutkens "><code>@timneutkens</code></a>,
and <a
href="https://github.com/lukesandberg "><code>@lukesandberg</code></a>
for helping!</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="9dadfd693c "><code>9dadfd6</code></a>
v16.2.10</li>
<li><a
href="534d9c144c "><code>534d9c1</code></a>
[16.2.x] Release pipeline updates (<a
href="https://redirect.github.com/vercel/next.js/issues/95160 ">#95160</a>)</li>
<li><a
href="98941fc427 "><code>98941fc</code></a>
backport: docs fixes 16.2.x (<a
href="https://redirect.github.com/vercel/next.js/issues/94935 ">#94935</a>)</li>
<li><a
href="6e1a94de7c "><code>6e1a94d</code></a>
[16.2.x][ci]: fix release script to not strip newlines (<a
href="https://redirect.github.com/vercel/next.js/issues/94640 ">#94640</a>)</li>
<li><a
href="f37fad9405 "><code>f37fad9</code></a>
v16.2.9</li>
<li><a
href="d9aaaedfd8 "><code>d9aaaed</code></a>
[cd] Allow tagging semver-lower releases as <code>@latest</code> if
<code>@latest</code> po… (<a
href="https://redirect.github.com/vercel/next.js/issues/94627 ">#94627</a>)</li>
<li><a
href="6f1680448c "><code>6f16804</code></a>
v16.2.8</li>
<li><a
href="0dbc1d5c86 "><code>0dbc1d5</code></a>
[16.2.x][cd] Ensure release can be triggered on old branches (<a
href="https://redirect.github.com/vercel/next.js/issues/94598 ">#94598</a>)</li>
<li><a
href="90e3c811e7 "><code>90e3c81</code></a>
[16.2.x] Align Actions dependencies with Canary (<a
href="https://redirect.github.com/vercel/next.js/issues/94339 ">#94339</a>)</li>
<li><a
href="83f402c69d "><code>83f402c</code></a>
[16.2.x][cd] Stop fetching all tags when searching parent tag (<a
href="https://redirect.github.com/vercel/next.js/issues/94334 ">#94334</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vercel/next.js/compare/v16.2.6...v16.2.10 ">compare
view</a></li>
</ul>
</details>
<br />
Updates `react` from 19.2.4 to 19.2.7
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/facebook/react/releases ">react's
releases</a>.</em></p>
<blockquote>
<h2>19.2.7 (June 1st, 2026)</h2>
<h2>React Server Components</h2>
<ul>
<li>Fixed missing <code>FormData</code> entries in Server Actions which
regressed in 19.2.6
(<a
href="https://redirect.github.com/facebook/react/pull/36566 ">#36566</a>
by <a
href="https://github.com/unstubbable "><code>@unstubbable</code></a>)</li>
</ul>
<h2>19.2.6 (May 6th, 2026)</h2>
<h2>React Server Components</h2>
<ul>
<li>Type hardening and performance improvements
(<a
href="https://redirect.github.com/facebook/react/pull/36425 ">#36425</a>
by <a href="https://github.com/eps1lon "><code>@eps1lon</code></a> and
<a
href="https://github.com/unstubbable "><code>@unstubbable</code></a>)</li>
</ul>
<h2>19.2.5 (April 8th, 2026)</h2>
<h2>React Server Components</h2>
<ul>
<li>Add more cycle protections (<a
href="https://redirect.github.com/facebook/react/pull/36236 ">#36236</a>
by <a href="https://github.com/eps1lon "><code>@eps1lon</code></a> and
<a
href="https://github.com/unstubbable "><code>@unstubbable</code></a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/react/react/blob/main/CHANGELOG.md ">react's
changelog</a>.</em></p>
<blockquote>
<h2>19.2.7 (June 1, 2026)</h2>
<h3>React Server Components</h3>
<ul>
<li>Fixed missing <code>FormData</code> entries in Server Actions which
regressed in 19.2.6 (<a
href="https://github.com/unstubbable "><code>@unstubbable</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36566 ">#36566</a>)</li>
</ul>
<h2>19.2.6 (May 6, 2026)</h2>
<h3>React Server Components</h3>
<ul>
<li>Type hardening and performance improvements (<a
href="https://github.com/eps1lon "><code>@eps1lon</code></a>, <a
href="https://github.com/unstubbable "><code>@unstubbable</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36425 ">#36425</a>)</li>
</ul>
<h2>19.2.5 (March 18, 2026)</h2>
<h3>React Server Components</h3>
<ul>
<li>Add more cycle protections (<a
href="https://github.com/eps1lon "><code>@eps1lon</code></a>, <a
href="https://github.com/unstubbable "><code>@unstubbable</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36236 ">#36236</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="6117d7cca4 "><code>6117d7c</code></a>
Version 19.2.7 (<a
href="https://github.com/facebook/react/tree/HEAD/packages/react/issues/36591 ">#36591</a>)</li>
<li><a
href="eaf3e95ca9 "><code>eaf3e95</code></a>
Version 19.2.6</li>
<li><a
href="23f4f9f30d "><code>23f4f9f</code></a>
19.2.5</li>
<li>See full diff in <a
href="https://github.com/facebook/react/commits/v19.2.7/packages/react ">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions ">GitHub Actions</a>, a new
releaser for react since your current version.</p>
</details>
<br />
Updates `@types/react` from 19.2.14 to 19.2.17
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react ">compare
view</a></li>
</ul>
</details>
<br />
Updates `react-dom` from 19.2.4 to 19.2.7
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/facebook/react/releases ">react-dom's
releases</a>.</em></p>
<blockquote>
<h2>19.2.7 (June 1st, 2026)</h2>
<h2>React Server Components</h2>
<ul>
<li>Fixed missing <code>FormData</code> entries in Server Actions which
regressed in 19.2.6
(<a
href="https://redirect.github.com/facebook/react/pull/36566 ">#36566</a>
by <a
href="https://github.com/unstubbable "><code>@unstubbable</code></a>)</li>
</ul>
<h2>19.2.6 (May 6th, 2026)</h2>
<h2>React Server Components</h2>
<ul>
<li>Type hardening and performance improvements
(<a
href="https://redirect.github.com/facebook/react/pull/36425 ">#36425</a>
by <a href="https://github.com/eps1lon "><code>@eps1lon</code></a> and
<a
href="https://github.com/unstubbable "><code>@unstubbable</code></a>)</li>
</ul>
<h2>19.2.5 (April 8th, 2026)</h2>
<h2>React Server Components</h2>
<ul>
<li>Add more cycle protections (<a
href="https://redirect.github.com/facebook/react/pull/36236 ">#36236</a>
by <a href="https://github.com/eps1lon "><code>@eps1lon</code></a> and
<a
href="https://github.com/unstubbable "><code>@unstubbable</code></a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/react/react/blob/main/CHANGELOG.md ">react-dom's
changelog</a>.</em></p>
<blockquote>
<h2>19.2.7 (June 1, 2026)</h2>
<h3>React Server Components</h3>
<ul>
<li>Fixed missing <code>FormData</code> entries in Server Actions which
regressed in 19.2.6 (<a
href="https://github.com/unstubbable "><code>@unstubbable</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36566 ">#36566</a>)</li>
</ul>
<h2>19.2.6 (May 6, 2026)</h2>
<h3>React Server Components</h3>
<ul>
<li>Type hardening and performance improvements (<a
href="https://github.com/eps1lon "><code>@eps1lon</code></a>, <a
href="https://github.com/unstubbable "><code>@unstubbable</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36425 ">#36425</a>)</li>
</ul>
<h2>19.2.5 (March 18, 2026)</h2>
<h3>React Server Components</h3>
<ul>
<li>Add more cycle protections (<a
href="https://github.com/eps1lon "><code>@eps1lon</code></a>, <a
href="https://github.com/unstubbable "><code>@unstubbable</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36236 ">#36236</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="6117d7cca4 "><code>6117d7c</code></a>
Version 19.2.7 (<a
href="https://github.com/facebook/react/tree/HEAD/packages/react-dom/issues/36591 ">#36591</a>)</li>
<li><a
href="eaf3e95ca9 "><code>eaf3e95</code></a>
Version 19.2.6</li>
<li><a
href="23f4f9f30d "><code>23f4f9f</code></a>
19.2.5</li>
<li>See full diff in <a
href="https://github.com/facebook/react/commits/v19.2.7/packages/react-dom ">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions ">GitHub Actions</a>, a new
releaser for react-dom since your current version.</p>
</details>
<br />
Updates `recharts` from 3.8.1 to 3.9.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/recharts/recharts/releases ">recharts's
releases</a>.</em></p>
<blockquote>
<h2>v3.9.2</h2>
<h2>What's Changed</h2>
<ul>
<li>docs: clarify custom labels and ticks need SVG elements by <a
href="https://github.com/ishaanlabs-gg "><code>@ishaanlabs-gg</code></a>
in <a
href="https://redirect.github.com/recharts/recharts/pull/7524 ">recharts/recharts#7524</a></li>
<li>chore(deps): bump immer from 11.1.8 to 11.1.9 by <a
href="https://github.com/dependabot "><code>@dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/recharts/recharts/pull/7526 ">recharts/recharts#7526</a></li>
<li>fix(Sankey): avoid exponential depth traversal on dense graphs by <a
href="https://github.com/dm-gthb "><code>@dm-gthb</code></a> in <a
href="https://redirect.github.com/recharts/recharts/pull/7479 ">recharts/recharts#7479</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/ishaanlabs-gg "><code>@ishaanlabs-gg</code></a>
made their first contribution in <a
href="https://redirect.github.com/recharts/recharts/pull/7524 ">recharts/recharts#7524</a></li>
<li><a href="https://github.com/dm-gthb "><code>@dm-gthb</code></a> made
their first contribution in <a
href="https://redirect.github.com/recharts/recharts/pull/7479 ">recharts/recharts#7479</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/recharts/recharts/compare/v3.9.1...v3.9.2 ">https://github.com/recharts/recharts/compare/v3.9.1...v3.9.2 </a></p>
<h2>v3.9.1</h2>
<h2>What's Changed</h2>
<ul>
<li>perf: optimize ScatterChart hover by reducing re-renders from O(n)
to O(1) by <a href="https://github.com/roy7 "><code>@roy7</code></a> in
<a
href="https://redirect.github.com/recharts/recharts/pull/7133 ">recharts/recharts#7133</a></li>
<li>fix(YAxis): render explicit ticks when a non-literal domain can't
resolve on empty data (<a
href="https://redirect.github.com/recharts/recharts/issues/7362 ">#7362</a>)
by <a href="https://github.com/nlenepveu "><code>@nlenepveu</code></a>
in <a
href="https://redirect.github.com/recharts/recharts/pull/7393 ">recharts/recharts#7393</a></li>
<li>fix: avoid Sankey nodes overlapping skipped-depth links by <a
href="https://github.com/pupuking723 "><code>@pupuking723</code></a> in
<a
href="https://redirect.github.com/recharts/recharts/pull/7471 ">recharts/recharts#7471</a></li>
<li>Add stacked bar chart with horizontal threshold line example by <a
href="https://github.com/nijuse "><code>@nijuse</code></a> in <a
href="https://redirect.github.com/recharts/recharts/pull/7495 ">recharts/recharts#7495</a></li>
<li>fix(DefaultLegendContent): omit empty value from legend icon
aria-label by <a
href="https://github.com/greymoth-jp "><code>@greymoth-jp</code></a> in
<a
href="https://redirect.github.com/recharts/recharts/pull/7501 ">recharts/recharts#7501</a></li>
<li>chore(deps): bump immer from 10.2.0 to 11.1.8 by <a
href="https://github.com/dependabot "><code>@dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/recharts/recharts/pull/7452 ">recharts/recharts#7452</a></li>
<li>fix(getNiceTickValues): remove trailing duplicate tick when
allowDecimals=false by <a
href="https://github.com/JSap0914 "><code>@JSap0914</code></a> in <a
href="https://redirect.github.com/recharts/recharts/pull/7482 ">recharts/recharts#7482</a></li>
<li>Fix/per graphical item formatter prop by <a
href="https://github.com/shreedharbhat98 "><code>@shreedharbhat98</code></a>
in <a
href="https://redirect.github.com/recharts/recharts/pull/7287 ">recharts/recharts#7287</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/pupuking723 "><code>@pupuking723</code></a>
made their first contribution in <a
href="https://redirect.github.com/recharts/recharts/pull/7471 ">recharts/recharts#7471</a></li>
<li><a href="https://github.com/nijuse "><code>@nijuse</code></a> made
their first contribution in <a
href="https://redirect.github.com/recharts/recharts/pull/7495 ">recharts/recharts#7495</a></li>
<li><a
href="https://github.com/greymoth-jp "><code>@greymoth-jp</code></a>
made their first contribution in <a
href="https://redirect.github.com/recharts/recharts/pull/7501 ">recharts/recharts#7501</a></li>
<li><a href="https://github.com/JSap0914 "><code>@JSap0914</code></a>
made their first contribution in <a
href="https://redirect.github.com/recharts/recharts/pull/7482 ">recharts/recharts#7482</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/recharts/recharts/compare/v3.9.0...v3.9.1 ">https://github.com/recharts/recharts/compare/v3.9.0...v3.9.1 </a></p>
<h2>v3.9.0</h2>
<h2>What's Changed</h2>
<h3>Animations</h3>
<p>3.9 comes with new animations! There are several bug fixes and what's
best, all animations are now fully customizable.</p>
<p>See the animations guide on <a
href="https://recharts.github.io/en-US/guide/animations/ ">https://recharts.github.io/en-US/guide/animations/ </a></p>
<ul>
<li>Animation guide by <a
href="https://github.com/PavelVanecek "><code>@PavelVanecek</code></a>
in <a
href="https://redirect.github.com/recharts/recharts/pull/7179 ">recharts/recharts#7179</a></li>
<li>Animation tests by <a
href="https://github.com/PavelVanecek "><code>@PavelVanecek</code></a>
in <a
href="https://redirect.github.com/recharts/recharts/pull/7255 ">recharts/recharts#7255</a></li>
<li>New animation props by <a
href="https://github.com/PavelVanecek "><code>@PavelVanecek</code></a>
in <a
href="https://redirect.github.com/recharts/recharts/pull/7215 ">recharts/recharts#7215</a></li>
<li>test: cover legacy animation length changes by <a
href="https://github.com/PavelVanecek "><code>@PavelVanecek</code></a>
in <a
href="https://redirect.github.com/recharts/recharts/pull/7283 ">recharts/recharts#7283</a></li>
<li>test: add sparse animation path tests for Line component by <a
href="https://github.com/PavelVanecek "><code>@PavelVanecek</code></a>
in <a
href="https://redirect.github.com/recharts/recharts/pull/7295 ">recharts/recharts#7295</a></li>
<li>Export and document interpolate function by <a
href="https://github.com/PavelVanecek "><code>@PavelVanecek</code></a>
in <a
href="https://redirect.github.com/recharts/recharts/pull/7293 ">recharts/recharts#7293</a></li>
<li>test: enhance line animation tests for ComposedChart and responsive
by <a
href="https://github.com/PavelVanecek "><code>@PavelVanecek</code></a>
in <a
href="https://redirect.github.com/recharts/recharts/pull/7289 ">recharts/recharts#7289</a></li>
<li>Manual animations on website by <a
href="https://github.com/PavelVanecek "><code>@PavelVanecek</code></a>
in <a
href="https://redirect.github.com/recharts/recharts/pull/7483 ">recharts/recharts#7483</a></li>
<li>Add new example where chart animates by scroll by <a
href="https://github.com/PavelVanecek "><code>@PavelVanecek</code></a>
in <a
href="https://redirect.github.com/recharts/recharts/pull/7484 ">recharts/recharts#7484</a></li>
<li>fix: preserve single-value line dash gaps during animation by <a
href="https://github.com/puneetdixit200 "><code>@puneetdixit200</code></a>
in <a
href="https://redirect.github.com/recharts/recharts/pull/7405 ">recharts/recharts#7405</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="b3451050c0 "><code>b345105</code></a>
3.9.2</li>
<li><a
href="f27779c048 "><code>f27779c</code></a>
npm i</li>
<li><a
href="85f9369f40 "><code>85f9369</code></a>
chore(deps-dev): bump prettier from 3.8.4 to 3.9.4 (<a
href="https://redirect.github.com/recharts/recharts/issues/7520 ">#7520</a>)</li>
<li><a
href="52a2a896cf "><code>52a2a89</code></a>
fix(Sankey): avoid exponential depth traversal on dense graphs (<a
href="https://redirect.github.com/recharts/recharts/issues/7479 ">#7479</a>)</li>
<li><a
href="8a056c1018 "><code>8a056c1</code></a>
chore(deps-dev): bump rollup from 4.61.1 to 4.62.2 (<a
href="https://redirect.github.com/recharts/recharts/issues/7527 ">#7527</a>)</li>
<li><a
href="2af6ec6f0f "><code>2af6ec6</code></a>
chore(deps): bump immer from 11.1.8 to 11.1.9 (<a
href="https://redirect.github.com/recharts/recharts/issues/7526 ">#7526</a>)</li>
<li><a
href="6f10d53cf6 "><code>6f10d53</code></a>
docs: clarify custom labels and ticks need SVG elements (<a
href="https://redirect.github.com/recharts/recharts/issues/7524 ">#7524</a>)</li>
<li><a
href="c04f1a7678 "><code>c04f1a7</code></a>
chore(deps-dev): bump lint-staged from 17.0.7 to 17.0.8 (<a
href="https://redirect.github.com/recharts/recharts/issues/7521 ">#7521</a>)</li>
<li><a
href="69c7a9630a "><code>69c7a96</code></a>
chore(deps-dev): bump glob from 11.1.0 to 13.0.6 (<a
href="https://redirect.github.com/recharts/recharts/issues/7522 ">#7522</a>)</li>
<li><a
href="6efaf16a1a "><code>6efaf16</code></a>
chore(deps): bump es-toolkit from 1.47.0 to 1.49.0 (<a
href="https://redirect.github.com/recharts/recharts/issues/7515 ">#7515</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/recharts/recharts/compare/v3.8.1...v3.9.2 ">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions ">GitHub Actions</a>, a new
releaser for recharts since your current version.</p>
</details>
<details>
<summary>Install script changes</summary>
<p>This version modifies <code>prepare</code> script that runs during
installation. Review the package contents before updating.</p>
</details>
<br />
Updates `@tailwindcss/postcss` from 4.2.2 to 4.3.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/tailwindlabs/tailwindcss/releases ">@tailwindcss/postcss's
releases</a>.</em></p>
<blockquote>
<h2>v4.3.2</h2>
<h3>Fixed</h3>
<ul>
<li>Support bare spacing values for <code>auto-rows-*</code> and
<code>auto-cols-*</code> utilities (e.g. <code>auto-rows-12</code> and
<code>auto-cols-16</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20229 ">#20229</a>)</li>
<li>Prevent <code>@tailwindcss/cli</code> in <code>--watch</code> mode
from crashing on Windows when <code>@source</code> points to a directory
that doesn't exist (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20242 ">#20242</a>)</li>
<li>Prevent <code>@tailwindcss/vite</code> from crashing in Deno v2.8.x
when <code>context.parentURL</code> is not a valid URL (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20245 ">#20245</a>)</li>
<li>Ensure <code>@tailwindcss/cli</code> in <code>--watch</code> mode
rebuilds when the input CSS file changes in an ignored directory (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20246 ">#20246</a>)</li>
<li>Allow <code>@variant</code> rules used in <code>addBase(…)</code> to
use custom variants defined later (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20247 ">#20247</a>)</li>
<li>Prevent <code>@tailwindcss/vite</code> from crashing during HMR when
scanned files or directories are deleted (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20259 ">#20259</a>)</li>
<li>Generate <code>font-size</code> instead of <code>color</code>
declarations for <code>text-[--spacing(…)]</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20260 ">#20260</a>)</li>
<li>Prevent <code>@source</code> patterns from scanning unrelated
sibling files and folders (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20263 ">#20263</a>)</li>
<li>Extract class candidates adjacent to Template Toolkit delimiters
like <code>%]…[%</code> in <code>.tt</code>, <code>.tt2</code>, and
<code>.tx</code> files (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20269 ">#20269</a>)</li>
<li>Extract class candidates from conditional Maud syntax like
<code>p.text-black[condition]</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20269 ">#20269</a>)</li>
<li>Prevent <code>@position-try</code> rules from triggering unknown
at-rule warnings when optimizing CSS (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20277 ">#20277</a>)</li>
<li>Support class suggestions for named opacity modifiers from
<code>--opacity</code> theme values (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20287 ">#20287</a>)</li>
<li>Prevent type errors in <code>@tailwindcss/postcss</code> when used
with newer PostCSS patch releases (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20289 ">#20289</a>)</li>
</ul>
<h2>v4.3.1</h2>
<h3>Added</h3>
<ul>
<li>Add <code>--silent</code> option to suppress output in
<code>@tailwindcss/cli</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20100 ">#20100</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Remove deprecation warnings by using
<code>Module#registerHooks</code> instead of
<code>Module#register</code> on Node 26+ (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20028 ">#20028</a>)</li>
<li>Canonicalization: don't crash when plugin utilities throw for
unsupported values (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20052 ">#20052</a>)</li>
<li>Allow <code>@apply</code> to be used with CSS mixins (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19427 ">#19427</a>)</li>
<li>Ensure <code>not-*</code> correctly negates <code>@container</code>
queries, including <code>style(…)</code> queries (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20059 ">#20059</a>)</li>
<li>Ensure <code>drop-shadow-*</code> color utilities work with custom
shadow values containing <code>calc(…)</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20080 ">#20080</a>)</li>
<li>Fix 'Sourcemap is likely to be incorrect' warnings when using
<code>@tailwindcss/vite</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20103 ">#20103</a>)</li>
<li>Ensure <code>@tailwindcss/webpack</code> can be installed in Rspack
projects without requiring <code>webpack</code> as a peer dependency (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20027 ">#20027</a>)</li>
<li>Canonicalization: don't suggest invalid <code>calc(…)</code>
expressions (e.g. <code>px-[calc(1rem+0px)]</code> →
<code>px-[calc(1rem+0)]</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20127 ">#20127</a>)</li>
<li>Canonicalization: avoid suggesting large spacing-scale values for
arbitrary lengths (e.g. <code>left-[99999px]</code> →
<code>left-[99999px]</code>, not <code>left-24999.75</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20130 ">#20130</a>)</li>
<li>Ensure <code>@tailwindcss/cli</code> in <code>--watch</code> mode
recovers when a tracked dependency is deleted and restored (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20137 ">#20137</a>)</li>
<li>Ensure standalone <code>@tailwindcss/cli</code> binaries are ignored
when scanning for class candidates (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20139 ">#20139</a>)</li>
<li>Ensure class candidates are extracted from Twig
<code>addClass(…)</code> and <code>removeClass(…)</code> calls (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20198 ">#20198</a>)</li>
<li>Don't crash in the Ruby or Vue preprocessors when scanning files
containing invalid UTF-8 bytes (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19588 ">#19588</a>)</li>
<li>Allow <code>@variant</code> to be used inside <code>addBase</code>
(<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19480 ">#19480</a>)</li>
<li>Ensure <code>@source</code> globs with symlinks are preserved (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20203 ">#20203</a>)</li>
<li>Ensure later <code>@source</code> rules can re-include files
excluded by earlier <code>@source not</code> rules (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20203 ">#20203</a>)</li>
<li>Upgrade: don't migrate empty class rules to invalid
<code>@utility</code> rules (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20205 ">#20205</a>)</li>
<li>Ensure transitions between <code>inset-shadow-none</code> and other
inset shadows work correctly (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20208 ">#20208</a>)</li>
<li>Ensure explicitly referenced <code>@source</code> directories are
scanned even when ignored by git (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20214 ">#20214</a>)</li>
<li>Ensure <code>@source</code> globs ending in <code>**/*</code>
preserve dynamic path segments to avoid scanning too many files (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20217 ">#20217</a>)</li>
<li>Canonicalization: don't fold <code>calc(…)</code> divisions when the
result would require high precision (e.g.
<code>w-[calc(100%/3.5)]</code> → <code>w-[calc(100%/3.5)]</code>, not
<code>w-[28.571428571428573%]</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20221 ">#20221</a>)</li>
<li>Serve ESM type declarations to ESM importers of
<code>@tailwindcss/postcss</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20228 ">#20228</a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Generate <code>0</code> instead of <code>calc(var(--spacing) *
0)</code> for spacing utilities like <code>m-0</code> and
<code>left-0</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20196 ">#20196</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md ">@tailwindcss/postcss's
changelog</a>.</em></p>
<blockquote>
<h2>[4.3.2] - 2026-06-26</h2>
<h3>Fixed</h3>
<ul>
<li>Support bare spacing values for <code>auto-rows-*</code> and
<code>auto-cols-*</code> utilities (e.g. <code>auto-rows-12</code> and
<code>auto-cols-16</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20229 ">#20229</a>)</li>
<li>Prevent <code>@tailwindcss/cli</code> in <code>--watch</code> mode
from crashing on Windows when <code>@source</code> points to a directory
that doesn't exist (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20242 ">#20242</a>)</li>
<li>Prevent <code>@tailwindcss/vite</code> from crashing in Deno v2.8.x
when <code>context.parentURL</code> is not a valid URL (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20245 ">#20245</a>)</li>
<li>Ensure <code>@tailwindcss/cli</code> in <code>--watch</code> mode
rebuilds when the input CSS file changes in an ignored directory (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20246 ">#20246</a>)</li>
<li>Allow <code>@variant</code> rules used in <code>addBase(…)</code> to
use custom variants defined later (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20247 ">#20247</a>)</li>
<li>Prevent <code>@tailwindcss/vite</code> from crashing during HMR when
scanned files or directories are deleted (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20259 ">#20259</a>)</li>
<li>Generate <code>font-size</code> instead of <code>color</code>
declarations for <code>text-[--spacing(…)]</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20260 ">#20260</a>)</li>
<li>Prevent <code>@source</code> patterns from scanning unrelated
sibling files and folders (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20263 ">#20263</a>)</li>
<li>Extract class candidates adjacent to Template Toolkit delimiters
like <code>%]…[%</code> in <code>.tt</code>, <code>.tt2</code>, and
<code>.tx</code> files (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20269 ">#20269</a>)</li>
<li>Extract class candidates from conditional Maud syntax like
<code>p.text-black[condition]</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20269 ">#20269</a>)</li>
<li>Prevent <code>@position-try</code> rules from triggering unknown
at-rule warnings when optimizing CSS (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20277 ">#20277</a>)</li>
<li>Support class suggestions for named opacity modifiers from
<code>--opacity</code> theme values (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20287 ">#20287</a>)</li>
<li>Prevent type errors in <code>@tailwindcss/postcss</code> when used
with newer PostCSS patch releases (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20289 ">#20289</a>)</li>
</ul>
<h2>[4.3.1] - 2026-06-12</h2>
<h3>Added</h3>
<ul>
<li>Add <code>--silent</code> option to suppress output in
<code>@tailwindcss/cli</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20100 ">#20100</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Remove deprecation warnings by using
<code>Module#registerHooks</code> instead of
<code>Module#register</code> on Node 26+ (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20028 ">#20028</a>)</li>
<li>Canonicalization: don't crash when plugin utilities throw for
unsupported values (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20052 ">#20052</a>)</li>
<li>Allow <code>@apply</code> to be used with CSS mixins (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19427 ">#19427</a>)</li>
<li>Ensure <code>not-*</code> correctly negates <code>@container</code>
queries, including <code>style(…)</code> queries (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20059 ">#20059</a>)</li>
<li>Ensure <code>drop-shadow-*</code> color utilities work with custom
shadow values containing <code>calc(…)</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20080 ">#20080</a>)</li>
<li>Fix 'Sourcemap is likely to be incorrect' warnings when using
<code>@tailwindcss/vite</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20103 ">#20103</a>)</li>
<li>Ensure <code>@tailwindcss/webpack</code> can be installed in Rspack
projects without requiring <code>webpack</code> as a peer dependency (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20027 ">#20027</a>)</li>
<li>Canonicalization: don't suggest invalid <code>calc(…)</code>
expressions (e.g. <code>px-[calc(1rem+0px)]</code> →
<code>px-[calc(1rem+0)]</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20127 ">#20127</a>)</li>
<li>Canonicalization: avoid suggesting large spacing-scale values for
arbitrary lengths (e.g. <code>left-[99999px]</code> →
<code>left-[99999px]</code>, not <code>left-24999.75</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20130 ">#20130</a>)</li>
<li>Ensure <code>@tailwindcss/cli</code> in <code>--watch</code> mode
recovers when a tracked dependency is deleted and restored (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20137 ">#20137</a>)</li>
<li>Ensure standalone <code>@tailwindcss/cli</code> binaries are ignored
when scanning for class candidates (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20139 ">#20139</a>)</li>
<li>Ensure class candidates are extracted from Twig
<code>addClass(…)</code> and <code>removeClass(…)</code> calls (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20198 ">#20198</a>)</li>
<li>Don't crash in the Ruby or Vue preprocessors when scanning files
containing invalid UTF-8 bytes (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19588 ">#19588</a>)</li>
<li>Allow <code>@variant</code> to be used inside <code>addBase</code>
(<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19480 ">#19480</a>)</li>
<li>Ensure <code>@source</code> globs with symlinks are preserved (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20203 ">#20203</a>)</li>
<li>Ensure later <code>@source</code> rules can re-include files
excluded by earlier <code>@source not</code> rules (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20203 ">#20203</a>)</li>
<li>Upgrade: don't migrate empty class rules to invalid
<code>@utility</code> rules (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20205 ">#20205</a>)</li>
<li>Ensure transitions between <code>inset-shadow-none</code> and other
inset shadows work correctly (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20208 ">#20208</a>)</li>
<li>Ensure explicitly referenced <code>@source</code> directories are
scanned even when ignored by git (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20214 ">#20214</a>)</li>
<li>Ensure <code>@source</code> globs ending in <code>**/*</code>
preserve dynamic path segments to avoid scanning too many files (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20217 ">#20217</a>)</li>
<li>Canonicalization: don't fold <code>calc(…)</code> divisions when the
result would require high precision (e.g.
<code>w-[calc(100%/3.5)]</code> → <code>w-[calc(100%/3.5)]</code>, not
<code>w-[28.571428571428573%]</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20221 ">#20221</a>)</li>
<li>Serve ESM type declarations to ESM importers of
<code>@tailwindcss/postcss</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20228 ">#20228</a>)</li>
</ul>
<h3>Changed</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="056a155072 "><code>056a155</code></a>
4.3.2 (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss/issues/20281 ">#20281</a>)</li>
<li><a
href="8a14a71010 "><code>8a14a71</code></a>
4.3.1 (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss/issues/20226 ">#20226</a>)</li>
<li><a
href="522288ca08 "><code>522288c</code></a>
Serve ESM type declarations to ESM importers of
<code>@tailwindcss/postcss</code> (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss/issues/20228 ">#20228</a>)</li>
<li><a
href="8dcdb66e8a "><code>8dcdb66</code></a>
Bump dependencies (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss/issues/20095 ">#20095</a>)</li>
<li><a
href="588bd7371f "><code>588bd73</code></a>
4.3.0 (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss/issues/20023 ">#20023</a>)</li>
<li><a
href="12eb5ae7b6 "><code>12eb5ae</code></a>
Cleanup noisy test output (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss/issues/20015 ">#20015</a>)</li>
<li><a
href="4255671c5f "><code>4255671</code></a>
Improve snapshot tests (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss/issues/20013 ">#20013</a>)</li>
<li><a
href="52f94c74bb "><code>52f94c7</code></a>
Improve codebase quality (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss/issues/19999 ">#19999</a>)</li>
<li><a
href="d194d4c3e6 "><code>d194d4c</code></a>
docs: fix various typos in comments and documentation (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss/issues/19878 ">#19878</a>)</li>
<li><a
href="bfb5732b0b "><code>bfb5732</code></a>
Fall back to the plugin <code>base</code> when PostCSS has no
<code>from</code> option (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss/issues/19980 ">#19980</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/tailwindlabs/tailwindcss/commits/v4.3.2/packages/@tailwindcss-postcss ">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions ">GitHub Actions</a>, a new
releaser for <code>@tailwindcss/postcss</code> since your current
version.</p>
</details>
<br />
Updates `@types/mdx` from 2.0.13 to 2.0.14
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/mdx ">compare
view</a></li>
</ul>
</details>
<br />
Updates `@types/react` from 19.2.14 to 19.2.17
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react ">compare
view</a></li>
</ul>
</details>
<br />
Updates `postcss` from 8.5.15 to 8.5.16
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/postcss/releases ">postcss's
releases</a>.</em></p>
<blockquote>
<h2>8.5.16</h2>
<ul>
<li>Fixed <code>Input#origin()</code> position (by <a
href="https://github.com/mizdra "><code>@mizdra</code></a>).</li>
<li>Fixed <code>raws</code> after rehydrating a JSON AST (by <a
href="https://github.com/sarathfrancis90 "><code>@sarathfrancis90</code></a>).</li>
<li>Fixed putting parent-less node in <code>nodes</code> of new node (by
<a
href="https://github.com/MahinAnowar "><code>@MahinAnowar</code></a>).</li>
<li>Fixed computing <code>offset</code> in <code>positionBy()</code> (by
<a
href="https://github.com/greymoth-jp "><code>@greymoth-jp</code></a>).</li>
<li>Fixed <code>rangeBy()</code> on <code>index: 0</code> (by <a
href="https://github.com/sarathfrancis90 "><code>@sarathfrancis90</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/postcss/blob/main/CHANGELOG.md ">postcss's
changelog</a>.</em></p>
<blockquote>
<h2>8.5.16</h2>
<ul>
<li>Fixed <code>Input#origin()</code> position (by <a
href="https://github.com/mizdra "><code>@mizdra</code></a>).</li>
<li>Fixed <code>raws</code> after rehydrating a JSON AST (by <a
href="https://github.com/sarathfrancis90 "><code>@sarathfrancis90</code></a>).</li>
<li>Fixed putting parent-less node in <code>nodes</code> of new node (by
<a
href="https://github.com/MahinAnowar "><code>@MahinAnowar</code></a>).</li>
<li>Fixed computing <code>offset</code> in <code>positionBy()</code> (by
<a
href="https://github.com/greymoth-jp "><code>@greymoth-jp</code></a>).</li>
<li>Fixed <code>rangeBy()</code> on <code>index: 0</code> (by <a
href="https://github.com/sarathfrancis90 "><code>@sarathfrancis90</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="92ccc93ff1 "><code>92ccc93</code></a>
Release 8.5.16 version</li>
<li><a
href="818bdd6043 "><code>818bdd6</code></a>
Update formatting</li>
<li><a
href="46e451068e "><code>46e4510</code></a>
Fix <code>Input#origin()</code> returning incorrect position (<a
href="https://redirect.github.com/postcss/postcss/issues/2036 ">#2036</a>)</li>
<li><a
href="34942ce76c "><code>34942ce</code></a>
Fix tests</li>
<li><a
href="d4feed6453 "><code>d4feed6</code></a>
Don't clone root-less child nodes in container constructor (<a
href="https://redirect.github.com/postcss/postcss/issues/2097 ">#2097</a>)</li>
<li><a
href="da323fc8d3 "><code>da323fc</code></a>
Revert version update to fix old Node.js on CI</li>
<li><a
href="8863369194 "><code>8863369</code></a>
Update dependencies</li>
<li><a
href="3828982213 "><code>3828982</code></a>
Preserve node raws when rehydrating a JSON AST (<a
href="https://redirect.github.com/postcss/postcss/issues/2100 ">#2100</a>)</li>
<li><a
href="d1e80b8303 "><code>d1e80b8</code></a>
Fix Node#rangeBy() ignoring index 0 (<a
href="https://redirect.github.com/postcss/postcss/issues/2091 ">#2091</a>)</li>
<li><a
href="b91e4a6390 "><code>b91e4a6</code></a>
Fix Node.js 26 tests</li>
<li>Additional commits viewable in <a
href="https://github.com/postcss/postcss/compare/8.5.15...8.5.16 ">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a href="https://www.npm ...
_Description has been truncated_
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-09 09:38:37 -04:00
Rudimar Ronsoni
b4571cc346
feat: headroom wrap opencode / unwrap opencode CLI ( #1105 )
...
## Summary
This PR implements transparent `headroom wrap opencode` support without
asking users to edit OpenCode provider URLs, choose an extra CLI flag,
or maintain a static provider list.
The wrapper now lives at the runtime transport boundary: OpenCode keeps
its user/provider config, while Headroom intercepts outbound provider
traffic in-process and routes it through the local Headroom proxy.
## What changed
### Transparent OpenCode wrapping
- `headroom wrap opencode` injects the `headroom-opencode` plugin
through `OPENCODE_CONFIG_CONTENT`.
- Existing OpenCode provider URLs are preserved. We do not rewrite user
config URLs to point at Headroom.
- Existing `OPENAI_BASE_URL` and `ANTHROPIC_BASE_URL` env vars are
preserved.
- Local OpenCode traffic, localhost traffic, and Headroom proxy traffic
bypass the shim to avoid loops.
### Runtime transport interception
- Added an OpenCode plugin transport shim that wraps:
- `globalThis.fetch`
- `http.request` / `http.get`
- `https.request` / `https.get`
- External provider calls are routed to the local Headroom proxy.
- The original upstream origin is passed through `x-headroom-base-url`,
so the proxy can forward to the real provider without changing OpenCode
config.
- External `http2.connect` is blocked loudly instead of allowing direct
provider traffic to leak outside Headroom.
### Live provider additions
Provider coverage is no longer based on a static config scan. Because
routing happens at outbound request time, providers added mid-session
are routed through Headroom automatically as long as they use the
covered Node transport paths.
### Subagent and child-process coverage
- The parent OpenCode plugin sets a packaged Node preload shim through
`NODE_OPTIONS=--import=.../hook-shim/handler.js`.
- The transport shim patches `child_process.spawn`, `exec`, `execFile`,
and `fork` so child Node processes receive the Headroom preload even
when OpenCode passes a custom `env`.
- The child-process shim fails closed if it loads without
`HEADROOM_OPENCODE_TRANSPORT_PROXY_URL`.
- This closes the subagent leak path where a child Node process could
otherwise start without Headroom transport interception.
## Why this goes beyond PR #1089
PR #1089 improves OpenCode provider registration, but it still focuses
on provider config shape. This PR moves the enforcement boundary to
runtime transport interception.
This PR goes further because:
- No provider URL rewriting is required.
- New providers added mid-session are covered automatically.
- Subagents and child Node processes inherit the Headroom transport
shim.
- Direct external HTTP/2 paths fail loudly instead of leaking.
- The wrap remains transparent to the user's OpenCode provider config.
- The wrapper is fail-closed for unsupported child-process preload
state.
## Additional robustness fixes
While validating the change in Docker, the full Python suite exposed
unrelated Linux/container robustness issues. These are fixed in this PR
so the suite is green:
- Binary cache handling now treats cache paths under a non-writable
existing parent as unavailable, including when tests run as root in
Docker.
- `release_version.py` honors `MANUAL_VER` before git calls so direct
script execution works outside a `.git` checkout.
- Test logger isolation now resets relevant Headroom child loggers so
proxy logging setup cannot poison later `caplog` tests.
- The scanner missing-path test now uses a guaranteed missing `tmp_path`
child instead of relying on `/nonexistent/path`.
## Validation
All implementation validation was run inside Docker.
- Full Python suite from a fresh Docker copy: `6605 passed, 523
skipped`.
- Ruff on changed Python/OpenCode paths: passed.
- OpenCode plugin typecheck: passed.
- OpenCode plugin tests: `9 passed`.
- OpenCode plugin build: passed.
- Hook shim preload smoke test: passed.
## Notes
This PR intentionally does not add a CLI option. `headroom wrap
opencode` means full wrap. Either Headroom wraps OpenCode transparently,
or the path fails loudly instead of silently leaking provider traffic.
---------
Co-authored-by: Rudimar Ronsoni <6081613+rudironsoni@users.noreply.github.com>
2026-06-22 11:07:12 -05:00