deps: bump the production group with 5 updates - #8
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the production group with 5 updates: | Package | From | To | | --- | --- | --- | | [@aws-sdk/client-bedrock-runtime](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-bedrock-runtime) | `3.1111.0` | `3.1112.0` | | [jose](https://github.com/panva/jose) | `6.2.8` | `6.2.9` | | [next-intl](https://github.com/amannn/next-intl) | `4.13.6` | `4.13.7` | | [onnxruntime-node](https://github.com/Microsoft/onnxruntime) | `1.24.3` | `1.27.0` | | [@atjsh/llmlingua-2](https://github.com/atjsh/llmlingua-2-js) | `2.0.5` | `3.0.0` | Updates `@aws-sdk/client-bedrock-runtime` from 3.1111.0 to 3.1112.0 - [Release notes](https://github.com/aws/aws-sdk-js-v3/releases) - [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-bedrock-runtime/CHANGELOG.md) - [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1112.0/clients/client-bedrock-runtime) Updates `jose` from 6.2.8 to 6.2.9 - [Release notes](https://github.com/panva/jose/releases) - [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md) - [Commits](panva/jose@v6.2.8...v6.2.9) Updates `next-intl` from 4.13.6 to 4.13.7 - [Release notes](https://github.com/amannn/next-intl/releases) - [Changelog](https://github.com/amannn/next-intl/blob/main/CHANGELOG.md) - [Commits](amannn/next-intl@v4.13.6...v4.13.7) Updates `onnxruntime-node` from 1.24.3 to 1.27.0 - [Release notes](https://github.com/Microsoft/onnxruntime/releases) - [Changelog](https://github.com/microsoft/onnxruntime/blob/main/docs/ReleaseNotesWorkflow.md) - [Commits](microsoft/onnxruntime@v1.24.3...v1.27.0) Updates `@atjsh/llmlingua-2` from 2.0.5 to 3.0.0 - [Release notes](https://github.com/atjsh/llmlingua-2-js/releases) - [Commits](atjsh/llmlingua-2-js@2.0.5...3.0.0) --- updated-dependencies: - dependency-name: "@aws-sdk/client-bedrock-runtime" dependency-version: 3.1112.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production - dependency-name: jose dependency-version: 6.2.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production - dependency-name: next-intl dependency-version: 4.13.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production - dependency-name: onnxruntime-node dependency-version: 1.27.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production - dependency-name: "@atjsh/llmlingua-2" dependency-version: 3.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: production ... Signed-off-by: dependabot[bot] <support@github.com>
Author
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
dependabot
Bot
deleted the
dependabot/npm_and_yarn/production-3a052d7eb3
branch
August 21, 2026 12:07
jonlwheat2-gif
pushed a commit
that referenced
this pull request
Aug 23, 2026
diegosouzapw#11190) * feat(api): structured ?format=json for the self-service usage endpoint GET /api/usage/om-usage already let any key read its own usage — personal daily/weekly USD limits and the provider quota snapshot — but only as text/plain, which a UI cannot parse safely. OmniCopilot issue #8 asks exactly for this surface. Adds ?format=json, returning the ApiKeyUsageLimitStatus + UsageSnapshot the text is rendered from. Text and JSON share the same collectors (collectUsageSnapshots, getApiKeyUsageLimitStatus), so the two can never disagree about a number. The response is a discriminated union: a key without allowUsageCommand (403) or an invalid key (401) returns { allowed:false, error:{message} }, distinct from allowed:true with empty sections — the state a panel must render as "nothing learned yet", not a refusal. Text form unchanged; without ?format the contract is untouched. The endpoint was previously missing from API_REFERENCE.md; it now has a section documenting both forms, the allowUsageCommand gate, and the self-service auth model (caller's own key, not requireManagementAuth). Regression guards in tests/unit/usage-command-json-format.test.ts (4 tests: json shape, text default preserved, structured 403, sanitized 401 with no stack trace). Existing internal-usage-command suite still 12/12. * chore(changelog): correct the fragment to the real PR number (diegosouzapw#11190) --------- Co-authored-by: Xiangzhe <bakryun0718@proton.me>
jonlwheat2-gif
pushed a commit
that referenced
this pull request
Aug 23, 2026
…-usage json (diegosouzapw#11192) * feat(api): structured ?format=json for the self-service usage endpoint GET /api/usage/om-usage already let any key read its own usage — personal daily/weekly USD limits and the provider quota snapshot — but only as text/plain, which a UI cannot parse safely. OmniCopilot issue #8 asks exactly for this surface. Adds ?format=json, returning the ApiKeyUsageLimitStatus + UsageSnapshot the text is rendered from. Text and JSON share the same collectors (collectUsageSnapshots, getApiKeyUsageLimitStatus), so the two can never disagree about a number. The response is a discriminated union: a key without allowUsageCommand (403) or an invalid key (401) returns { allowed:false, error:{message} }, distinct from allowed:true with empty sections — the state a panel must render as "nothing learned yet", not a refusal. Text form unchanged; without ?format the contract is untouched. The endpoint was previously missing from API_REFERENCE.md; it now has a section documenting both forms, the allowUsageCommand gate, and the self-service auth model (caller's own key, not requireManagementAuth). Regression guards in tests/unit/usage-command-json-format.test.ts (4 tests: json shape, text default preserved, structured 403, sanitized 401 with no stack trace). Existing internal-usage-command suite still 12/12. * chore(changelog): correct the fragment to the real PR number (diegosouzapw#11190) * feat(api): return every connection's snapshot under providers[] in om-usage json Closes diegosouzapw#11191. buildUsageCommandJson picked a single snapshot via selectUsageSnapshot, so a panel could only ever show one provider. The collector already had them all — the single-pick is a presentation choice for a terminal. The JSON form now also returns the full UsageSnapshot[] alongside the selected provider, so a UI can render Codex / Claude / OpenCode side by side. The text form is untouched. --------- Co-authored-by: Xiangzhe <bakryun0718@proton.me>
jonlwheat2-gif
pushed a commit
that referenced
this pull request
Aug 23, 2026
…pw#11279) Validated on the combined 8-PR board + the branch itself: vertex-anthropic-models 4/4 (new — pushed to your branch as a fix-in-place commit per Hard Rule #8, covering the parser's global/project-scoped resource names, malformed-input handling, and the claude-* → targetFormat heuristic on vertex/vertex-partner), 88/88 across the board's focused suites, typecheck:core clean, gates within baseline. Anthropic partner models on Vertex AI now discover dynamically via the Model Garden publisher endpoint and route through the Claude translator even for models outside the static registry. Thank you @maci0!
jonlwheat2-gif
pushed a commit
that referenced
this pull request
Sep 17, 2026
…e leak (diegosouzapw#13679) (diegosouzapw#13911) PR E of the diegosouzapw#13679 insecure-defaults umbrella (items #6, #7; item #8 analyzed as by-design, no change). The published Docker image and fly.toml shipped without REQUIRE_API_KEY set, so a bare `docker run` (README/QUICK-START one-liners, no --env-file) or a `fly deploy` combined "keyless" with "world-reachable" for the anonymous /v1 LLM proxy. docker-compose.yml already mitigates this via loopback-only binding (diegosouzapw#12568) and correctly keeps following the operator's own .env, so it is untouched. The npm/CLI local-first REQUIRE_API_KEY=false default in featureFlagDefinitions.ts is also untouched per the owner's decision. /api/free-tier/summary ships an unconditional Access-Control-Allow-Origin: "*" and always included the operator's own local usedThisMonth/remaining usage regardless of auth — a low-severity info leak to any reachable origin. Both fields are now withheld from unauthenticated callers while the intentionally public catalog data stays served to everyone. The gemini-SSE (openai-to-gemini-sse.ts) sub-finding needed no code change: /v1beta/models/*:streamGenerateContent is already classified CLIENT_API and fronted by clientApiPolicy through src/proxy.ts before the translator ever runs, and its CORS-header echo was already hardened fail-closed by diegosouzapw#12573. REQUIRE_API_KEY=true (this PR's container/Fly default) closes the dependency that finding cited. Added a locking regression test confirming this chain. Regression tests: - tests/unit/issue-13679-container-posture-require-api-key.test.ts - tests/unit/issue-13679-free-tier-summary-usage-leak.test.ts - tests/unit/issue-13679-gemini-sse-requires-api-key.test.ts (confirmation) Refs diegosouzapw#13679
jonlwheat2-gif
pushed a commit
that referenced
this pull request
Sep 18, 2026
diegosouzapw#12038) * feat(chat-admission): add settings store for admission tunables * fix(chat-admission): extract parseEnvNumber to reduce cyclomatic complexity * fix(chat-admission): repair settings store write path and add coverage The settings store could not persist anything: `updateChatAdmissionSettings` targeted an `updated_at` column that `key_value` does not have (the schema is namespace/key/value — src/lib/db/core.ts), so every write threw `table key_value has no column named updated_at`. Also fixes, found while adding the tests: - `getChatAdmissionSettingsSource` returned a partial map (only the keys whose layer differed from the default) and dropped the unset keys entirely, so a dashboard reading it could not render a complete row. - env parsing used `parseFloat` for the shed ratio, so `"0.5x"` was silently accepted as 0.5 while `chatBodyAdmission.ts` rejects that same input — both paths now share one per-field predicate table. - DB reads validated `typeof === "number"` but not integrality/range, so a hand-edited row could serve `2.5` or `-1` to the admission controller. - writes persisted unvalidated input. - malformed, non-object, and partial rows are now tolerated per field. Adds tests/unit/db-chat-admission-settings.test.ts (17 cases) covering CRUD round-trips, namespace isolation, reset, env parsing/validation boundaries, env-over-DB precedence, provenance, normalization on write, and malformed-row tolerance, per Hard Rule #8. Verification: eslint clean; `npm run typecheck:core` clean; the new suite plus the two sibling settings suites pass 63/63; check-complexity-ratchets reports complexityNewCode=0; check-db-rules OK; check-env-doc-sync OK (all three vars are already documented in .env.example). --------- Co-authored-by: oyi77 <oyi77@users.noreply.github.com>
jonlwheat2-gif
pushed a commit
that referenced
this pull request
Sep 18, 2026
* fix(windows): hide supervised server console * fix(windows): port icon.ico fix from diegosouzapw#13991 and add regression tests Adds a source-pattern test asserting the supervised server spawn() passes windowsHide: true (Hard Rule #8 gap noted in review), and ports the icon.ico-on-win32 fix from diegosouzapw#13991 (credit @prabhtheone) with its own regression test, so both real fixes ship without diegosouzapw#13991's unrelated comment purge. Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com> --------- Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the production group with 5 updates:
3.1111.03.1112.06.2.86.2.94.13.64.13.71.24.31.27.02.0.53.0.0Updates
@aws-sdk/client-bedrock-runtimefrom 3.1111.0 to 3.1112.0Release notes
Sourced from @aws-sdk/client-bedrock-runtime's releases.
Changelog
Sourced from @aws-sdk/client-bedrock-runtime's changelog.
Commits
cb4ae76Publish v3.1112.0Updates
josefrom 6.2.8 to 6.2.9Release notes
Sourced from jose's releases.
Changelog
Sourced from jose's changelog.
Commits
f3a3c78chore(release): 6.2.933bf832fix(types): undeprecate PBES2 p2c parameter6ed19a6fix: reject a JWE whose generated Key Management Parameters collide944840dci: use shared release workflows05bccf2chore: bump packagesf7392d1test: account for workerd nodejs_compat flag default changes4e944beci: drop the wait-for-npm machinery4285b6fchore(deps-dev): bump undicicb114ecchore: cleanup after releaseUpdates
next-intlfrom 4.13.6 to 4.13.7Release notes
Sourced from next-intl's releases.
Changelog
Sourced from next-intl's changelog.
Commits
4e5d46bv4.13.7a37d8aafix: Pin@swc/coreto a range that is compatible with the extractor plugin ...Updates
onnxruntime-nodefrom 1.24.3 to 1.27.0Release notes
Sourced from onnxruntime-node's releases.
... (truncated)
Commits
8f0278c[CUDA] Optimize QMoE SoftmaxTopK router for small-batch decode (#29026)66916b0fix: NodeJS pkging stage needs to use CFS (#29007)af99e19Disable OrtEp::ort_version_supported sanity check to work around EPs that don...6fc112f1.27.0 - cherry pick 2 (#28900)8f5403c1.27.0 - cherry pick 1 (#28817)0b451f5Switch NPM publishing to consume from CUDA 13 pipeline (#28773) (#28792)a8baf5cSkip SetupDi device discovery if Win32k system calls are disabled (#28535)5c34495fix(quantization): validate bias scale in QDQ Conv → QLinearConv fusion (#28229)8da5e91Use abseil for readable POSIX stack traces in debug builds (#28405)8fcb725feat(quantization): add opset-21 block_size attribute to QDQ (#28522)Maintainer changes
This version was pushed to npm by erscor_msft, a new releaser for onnxruntime-node since your current version.
Updates
@atjsh/llmlingua-2from 2.0.5 to 3.0.0Release notes
Sourced from @atjsh/llmlingua-2's releases.
... (truncated)
Commits
70f5ff0feat: update demo's package dependencydbcfae1Merge pull request #32 from atjsh/fix(tests): getProviderCredentials now returns allExpired sentinel (#9985) #24-v4bda2acd3.0.06fe7ce2chore: remove temporary Transformers.js v4 verificationd5418f0feat: migrate to Transformers.js v4Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions