Skip to content

chore(deps): bump the prod-deps group with 7 updates - #140

Merged
charlesrhoward merged 2 commits into
mainfrom
dependabot/npm_and_yarn/prod-deps-c6b7896214
Sep 29, 2026
Merged

charlesrhoward merged 2 commits into
mainfrom
dependabot/npm_and_yarn/prod-deps-c6b7896214

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the prod-deps group with 7 updates:

Package From To
@ai-sdk/react 4.0.110 4.0.116
@openrouter/ai-sdk-provider 3.0.0 3.1.0
ai 7.0.107 7.0.113
fumadocs-core 16.15.11 16.15.13
fumadocs-mdx 15.4.1 15.4.3
fumadocs-ui 16.15.11 16.15.13
next 16.3.5 16.3.6

Updates @ai-sdk/react from 4.0.110 to 4.0.116

Changelog

Sourced from @​ai-sdk/react's changelog.

4.0.116

Patch Changes

  • Updated dependencies [dcdb011]
  • Updated dependencies [8f72832]
  • Updated dependencies [fe07867]
  • Updated dependencies [b74c0cb]
  • Updated dependencies [a4b0940]
  • Updated dependencies [2693319]
  • Updated dependencies [c93ee90]
  • Updated dependencies [771e74b]
    • ai@7.0.113
    • @​ai-sdk/provider-utils@​5.0.47
    • @​ai-sdk/mcp@​2.0.57

4.0.115

Patch Changes

  • Updated dependencies [9a98fd9]
  • Updated dependencies [a0553d6]
  • Updated dependencies [ffb0e76]
  • Updated dependencies [fde0d66]
    • ai@7.0.112
    • @​ai-sdk/provider@​4.0.18
    • @​ai-sdk/mcp@​2.0.56
    • @​ai-sdk/provider-utils@​5.0.46

4.0.114

Patch Changes

  • Updated dependencies [31d24ce]
  • Updated dependencies [a65bfd9]
    • ai@7.0.111

4.0.113

Patch Changes

  • ai@7.0.110

4.0.112

Patch Changes

  • 7976437: fix(react): prevent stale throttled completion updates from overwriting a newer request
  • 0343bb1: fix(ai): keep replacement completion requests loading and cancellable when an earlier request settles
  • Updated dependencies [0343bb1]

... (truncated)

Commits

Updates @openrouter/ai-sdk-provider from 3.0.0 to 3.1.0

Release notes

Sourced from @​openrouter/ai-sdk-provider's releases.

3.1.0

What's Changed

New Contributors

Full Changelog: OpenRouterTeam/ai-sdk-provider@3.0.0...3.1.0

Changelog

Sourced from @​openrouter/ai-sdk-provider's changelog.

3.1.0

Minor Changes

  • #562 4020201 Thanks @​robert-j-y! - Add openrouter.evaluationModel() backed by the OpenRouter Decisions API (/api/alpha/decisions), so experimental_evaluate from ai@7.0.103+ runs boolean, choice, and score questions through OpenRouter. Probabilities are mapped onto the AI SDK answer shapes with the API's two-decimal rounding declared on the result, and per-answer confidence, score legends, and cost are exposed under providerMetadata.openrouter. Model settings accept user, provider, session_id, trace, and extraBody; call-level providerOptions.openrouter is validated and merged into the request body without being able to override model, state, or questions. A new decisionsBaseURL provider setting configures the Decisions endpoint for proxies whose baseURL does not end in /v1. The ai peer dependency range is unchanged; only evaluationModel() requires ai@7.0.103+.

Patch Changes

Commits

Updates ai from 7.0.107 to 7.0.113

Changelog

Sourced from ai's changelog.

7.0.113

Patch Changes

  • dcdb011: fix(ai): route completed streamed tool input callbacks to repaired tools

  • 8f72832: fix(ai): preserve video models from legacy fallback providers

  • fe07867: Fix Google embedMany calls with more than 100 values by keeping per-value multimodal content aligned across automatic batches, including text-only entries. Validate content length before sending requests and validate each batch's provider options after middleware transforms them.

  • b74c0cb: fix(ai): resume tool approvals from earlier messages

  • a4b0940: fix(ai): execute manually approved tool inputs produced by schema transforms

    Preserve approved inputs during revalidation and reject histories whose reconstructed schema output differs, including signed approvals with missing original input. Validate transformed UI tool inputs against the reconstructed output before returning them as static tool parts.

  • 2693319: Add Gemini 3.8 TTS support with structured speech metadata and per-turn speaker and style controls for prebuilt voices. Preserve native WAV responses without adding a second header, support explicit raw PCM, mu-law, and A-law output, and identify headerless audio formats correctly. Add the Gemini 3.8 speech model IDs to Google and Gateway types.

    Share transcript and custom-voice inspection through the Google provider internal export, and reject empty speech transcripts before sending a request. Default newer and custom model IDs to structured speech while preserving the legacy format for Gemini 2.5 and 3.1.

  • c93ee90: fix(ai): preserve message history for direct transport stream callbacks

  • 771e74b: chore: enable dead code lint rules

  • Updated dependencies [fe07867]

  • Updated dependencies [a4b0940]

  • Updated dependencies [2693319]

  • Updated dependencies [b73f2f9]

  • Updated dependencies [771e74b]

    • @​ai-sdk/provider-utils@​5.0.47
    • @​ai-sdk/gateway@​4.0.91

7.0.112

Patch Changes

  • 9a98fd9: fix(ai): prune reasoning file parts when removing reasoning
  • a0553d6: feat(ai): report consumer cancellation in UI message stream end callbacks
  • ffb0e76: fix(provider): preserve opaque file URI strings for provider serialization
  • fde0d66: fix(ai): preserve parsed metadata and data values when validating UI messages
  • Updated dependencies [ed5a1d7]
  • Updated dependencies [ffb0e76]
  • Updated dependencies [618dc11]
    • @​ai-sdk/gateway@​4.0.90
    • @​ai-sdk/provider@​4.0.18
    • @​ai-sdk/provider-utils@​5.0.46

7.0.111

Patch Changes

  • 31d24ce: feat: add telemetry support to experimental_evaluate
  • a65bfd9: fix(ai): securely download URL-backed language model file outputs so generated files expose actual base64 and byte content and UI streams contain valid data URLs. Propagate cancellation to batch file downloads.

7.0.110

... (truncated)

Commits
  • 5c830d5 Version Packages (#21370)
  • dcdb011 fix: route the wrong onInputAvailable callback and context after streamed too...
  • 2693319 feat(google): support Gemini 3.8 text-to-speech (#21403)
  • a4b0940 fix: manual tool approvals reject or mutate transformed inputs across model a...
  • fe07867 fix: Google embedMany loses per-value content alignment when batching more th...
  • c93ee90 fix: allow DirectChatTransport tool-approval continuations with onEnd callbac...
  • 771e74b chore: enable dead code lint rules (#21342)
  • b74c0cb fix: support approving, resuming, and retrying tool approvals from earlier me...
  • 8f72832 fix: preserve v3 video models in custom-provider fallbacks (#21119)
  • 21b2d6c Version Packages (#21300)
  • Additional commits viewable in compare view

Updates fumadocs-core from 16.15.11 to 16.15.13

Release notes

Sourced from fumadocs-core's releases.

fumadocs@16.15.13

  • @​fumadocs/base-ui@​16.15.13
  • fumadocs-core@16.15.13
  • fumadocs-ui@16.15.13

Keep the collapsed sidebar's controls off the page title

With the sidebar collapsed, the docs layout floats the reopen and search buttons in a fixed pill at the top-left of the page and starts the article at the same row. Wherever the article is not centered with room to spare, every viewport below about 1280px, the pill covered the page title. The article now leaves room for the pill while the sidebar is collapsed.

AI page actions name the page by the URL the reader is on

The "Open in ..." prompts built the page URL from the router pathname and the origin. Next's usePathname() omits a configured basePath, so a site mounted under one sent assistants a URL that did not exist.

The prompt now uses the reader's current URL, without query and hash, and falls back to the pathname during server rendering. A new pageUrl prop on ViewOptionsPopover sets a canonical URL instead.

Optimize Performance

Use useSyncExternalStore() from React.

Keep TOC step numbers after an HTML re-parse

remarkSteps marks each step heading with a numeric data-fd-step, and the TOC plugin only read it as a number. A later rehype-raw pass re-parses the tree from HTML, so the property came back as the canonical dataFdStep string and every step number silently vanished from the table of contents.

rehypeToc now accepts both shapes, so pipelines that render raw HTML in Markdown keep their numbered TOC.

fumadocs@16.15.12

  • @​fumadocs/base-ui@​16.15.12
  • fumadocs-core@16.15.12
  • fumadocs-ui@16.15.12

Fix filterElement being ignored by remarkLLMs

remarkLLMs wrote its own filterElement over yours, so the option did nothing:

remarkLLMs({
  // never ran
  filterElement: (node) => node.name !== 'Callout',
});

Your function now runs for every node except mdxjsEsm, which stays excluded either way.

Fumadocs MDX passes this option through postprocess.includeProcessedMarkdown.

Commits
  • b2cf491 Version Packages (#3574)
  • 8322703 fix(ui): keep the collapsed sidebar's controls off the page title (#3573)
  • 8f880bd fix(ui): name the page by the reader's URL in the AI page actions (#3572)
  • 0782a5a perf(ui): use useSyncExternalStore
  • 20ae70f fix(core): keep TOC step numbers when rehype-raw re-parses the tree (#3571)
  • e150548 Version Packages (#3569)
  • 5db5f36 Merge pull request #3568 from fuma-nama/chore/fuma-cli-0.3
  • 55ad14d docs: workaround upstream issues
  • 3763aff Merge pull request #3564 from fuma-nama/tegami/version-packages
  • 19100e9 refactor(cli): rename registry
  • Additional commits viewable in compare view

Updates fumadocs-mdx from 15.4.1 to 15.4.3

Release notes

Sourced from fumadocs-mdx's releases.

fumadocs-mdx@15.4.3

Fix experimentalBuildCache bloating frontmatter-only imports

With a warm build cache, ?only=frontmatter imports were served the fully compiled page from cache instead of the frontmatter module, so every page was bundled two more times. The cache now only applies to full compilations.

fumadocs-mdx@15.4.2

Fix the _mdast export with removePosition

// fumadocs-mdx collection config
postprocess: {
  includeMDAST: { removePosition: true },
},

This exported _mdast with no value, and getMDAST() then reported that includeMDAST was disabled. removePosition strips positions in place and returns nothing, so JSON.stringify received undefined.

The tree is now cloned, stripped, and serialized from the clone.

Fix SOURCEMAP_BROKEN warnings on Vite

With build.sourcemap enabled, Vite warned once per content and meta file because the loaders returned no source map. They now return an empty map when nothing is generated.

Source maps for MDX stay opt-in, pass SourceMapGenerator from source-map to MDX options:

import { SourceMapGenerator } from 'source-map';
export default defineConfig({
mdxOptions: {
SourceMapGenerator,
},
});

Commits

Updates fumadocs-ui from 16.15.11 to 16.15.13

Release notes

Sourced from fumadocs-ui's releases.

fumadocs@16.15.13

  • @​fumadocs/base-ui@​16.15.13
  • fumadocs-core@16.15.13
  • fumadocs-ui@16.15.13

Keep the collapsed sidebar's controls off the page title

With the sidebar collapsed, the docs layout floats the reopen and search buttons in a fixed pill at the top-left of the page and starts the article at the same row. Wherever the article is not centered with room to spare, every viewport below about 1280px, the pill covered the page title. The article now leaves room for the pill while the sidebar is collapsed.

AI page actions name the page by the URL the reader is on

The "Open in ..." prompts built the page URL from the router pathname and the origin. Next's usePathname() omits a configured basePath, so a site mounted under one sent assistants a URL that did not exist.

The prompt now uses the reader's current URL, without query and hash, and falls back to the pathname during server rendering. A new pageUrl prop on ViewOptionsPopover sets a canonical URL instead.

Optimize Performance

Use useSyncExternalStore() from React.

Keep TOC step numbers after an HTML re-parse

remarkSteps marks each step heading with a numeric data-fd-step, and the TOC plugin only read it as a number. A later rehype-raw pass re-parses the tree from HTML, so the property came back as the canonical dataFdStep string and every step number silently vanished from the table of contents.

rehypeToc now accepts both shapes, so pipelines that render raw HTML in Markdown keep their numbered TOC.

fumadocs@16.15.12

  • @​fumadocs/base-ui@​16.15.12
  • fumadocs-core@16.15.12
  • fumadocs-ui@16.15.12

Fix filterElement being ignored by remarkLLMs

remarkLLMs wrote its own filterElement over yours, so the option did nothing:

remarkLLMs({
  // never ran
  filterElement: (node) => node.name !== 'Callout',
});

Your function now runs for every node except mdxjsEsm, which stays excluded either way.

Fumadocs MDX passes this option through postprocess.includeProcessedMarkdown.

Commits
  • b2cf491 Version Packages (#3574)
  • 8322703 fix(ui): keep the collapsed sidebar's controls off the page title (#3573)
  • 8f880bd fix(ui): name the page by the reader's URL in the AI page actions (#3572)
  • 0782a5a perf(ui): use useSyncExternalStore
  • 20ae70f fix(core): keep TOC step numbers when rehype-raw re-parses the tree (#3571)
  • e150548 Version Packages (#3569)
  • 5db5f36 Merge pull request #3568 from fuma-nama/chore/fuma-cli-0.3
  • 55ad14d docs: workaround upstream issues
  • 3763aff Merge pull request #3564 from fuma-nama/tegami/version-packages
  • 19100e9 refactor(cli): rename registry
  • Additional commits viewable in compare view

Updates next from 16.3.5 to 16.3.6

Release notes

Sourced from next's releases.

v16.3.6

This release contains a security fix for GHSA-vcvr-r3jv-pc5j: Remote Code Execution in next/og ImageResponse

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Bumps the prod-deps group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [@ai-sdk/react](https://github.com/vercel/ai/tree/HEAD/packages/react) | `4.0.110` | `4.0.116` |
| [@openrouter/ai-sdk-provider](https://github.com/OpenRouterTeam/ai-sdk-provider) | `3.0.0` | `3.1.0` |
| [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `7.0.107` | `7.0.113` |
| [fumadocs-core](https://github.com/fuma-nama/fumadocs) | `16.15.11` | `16.15.13` |
| [fumadocs-mdx](https://github.com/fuma-nama/fumadocs) | `15.4.1` | `15.4.3` |
| [fumadocs-ui](https://github.com/fuma-nama/fumadocs) | `16.15.11` | `16.15.13` |
| [next](https://github.com/vercel/next.js) | `16.3.5` | `16.3.6` |


Updates `@ai-sdk/react` from 4.0.110 to 4.0.116
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/packages/react/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/@ai-sdk/react@4.0.116/packages/react)

Updates `@openrouter/ai-sdk-provider` from 3.0.0 to 3.1.0
- [Release notes](https://github.com/OpenRouterTeam/ai-sdk-provider/releases)
- [Changelog](https://github.com/OpenRouterTeam/ai-sdk-provider/blob/main/CHANGELOG.md)
- [Commits](OpenRouterTeam/ai-sdk-provider@3.0.0...3.1.0)

Updates `ai` from 7.0.107 to 7.0.113
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/packages/ai/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/ai@7.0.113/packages/ai)

Updates `fumadocs-core` from 16.15.11 to 16.15.13
- [Release notes](https://github.com/fuma-nama/fumadocs/releases)
- [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs@16.15.11...fumadocs@16.15.13)

Updates `fumadocs-mdx` from 15.4.1 to 15.4.3
- [Release notes](https://github.com/fuma-nama/fumadocs/releases)
- [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs-mdx@15.4.1...fumadocs-mdx@15.4.3)

Updates `fumadocs-ui` from 16.15.11 to 16.15.13
- [Release notes](https://github.com/fuma-nama/fumadocs/releases)
- [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs@16.15.11...fumadocs@16.15.13)

Updates `next` from 16.3.5 to 16.3.6
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.3.5...v16.3.6)

---
updated-dependencies:
- dependency-name: "@ai-sdk/react"
  dependency-version: 4.0.116
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: "@openrouter/ai-sdk-provider"
  dependency-version: 3.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: ai
  dependency-version: 7.0.113
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: fumadocs-core
  dependency-version: 16.15.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: fumadocs-mdx
  dependency-version: 15.4.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: fumadocs-ui
  dependency-version: 16.15.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: next
  dependency-version: 16.3.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 27, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 27, 2026
@vercel

vercel Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
mogplex-docs Ready Ready Preview Sep 29, 2026 8:48pm UTC

Request Review

@charlesrhoward
charlesrhoward enabled auto-merge (squash) September 29, 2026 20:48
@charlesrhoward
charlesrhoward merged commit 555dfb8 into main Sep 29, 2026
7 checks passed
@charlesrhoward
charlesrhoward deleted the dependabot/npm_and_yarn/prod-deps-c6b7896214 branch September 29, 2026 20:48

This branch was successfully deployed

1 active deployment
Preview — 2f170244 Deployed Sep 29, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant