Skip to content

build(deps): bump the minor-and-patch group across 1 directory with 3 updates - #1625

Open
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/dev/minor-and-patch-4c3e55582a
Open

build(deps): bump the minor-and-patch group across 1 directory with 3 updates#1625
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/dev/minor-and-patch-4c3e55582a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 3 updates in the / directory: @assistant-ui/react, @aws-sdk/lib-storage and next.

Updates @assistant-ui/react from 0.14.29 to 0.15.18

Release notes

Sourced from @​assistant-ui/react's releases.

@​assistant-ui/react@​0.15.18

Patch Changes

@​assistant-ui/react@​0.15.17

Patch Changes

... (truncated)

Changelog

Sourced from @​assistant-ui/react's changelog.

0.15.18

Patch Changes

0.15.17

Patch Changes

... (truncated)

Commits
  • d511ff4 chore: update versions (#6482)
  • 39c99b5 fix(react): keep trigger callbacks commit-safe (#6762)
  • 8cc962e feat: let a tool approval request describe itself and report its outcome (#6723)
  • 0f3140d refactor(react): extract a shared model-context snapshot hook (#6714)
  • 6194f3e fix(react): refresh model context mentions and honor explicit tool categories...
  • a83be6b fix(react): accept spec-shaped MCP App messages (#6710)
  • 21cbb78 refactor(react): collapse the three trigger-item query predicates onto one he...
  • 05e3e6d chore: update dependencies (#6639)
  • 79c1465 fix(react): prevent MCP Apps from loading through stale hosts (#6640)
  • 98b7213 feat(react): resolve MCP App renderer options per part (#6629)
  • Additional commits viewable in compare view

Updates @aws-sdk/lib-storage from 3.1096.0 to 3.1126.0

Release notes

Sourced from @​aws-sdk/lib-storage's releases.

v3.1126.0

3.1126.0(2026-09-03)

Documentation Changes
  • client-sfn: Updates Step Functions API documentation around CloudTrail, Execution name reuse and sort order of ListExecutions API (8dda8b4b)
  • client-elastic-load-balancing-v2: This release adds support for sending TCP resets for Gateway Load Balancer when a flow's idle timeout expires, or when a target becomes unhealthy or is deregistered. This adds updates the CLI documentation. (a16f1659)
New Features
  • client-socialmessaging: Adding support for WhatsApp Flows with endpoints. (3a3a6205)
  • client-transfer: AWS Transfer Family SFTP Connectors now support specifying an ordered list of AWS Secrets Manager version stages for secret retrieval. This enables seamless credential rotation workflows where external partners may take time to update their systems with new credentials. (e4bf3ecc)
  • client-transcribe: Amazon Transcribe now supports specifying up to 29 PII entity types in the ContentRedaction configuration of a StartTranscriptionJob request, allowing all supported entity types to be redacted in a single batch transcription job. (5fb0b9a5)
  • client-connect: This release enables TagOnCreate for Rule resource on CreateRule API. It also introduces a new field called PreEvaluationFilters to Rule resource, thereby impacting all Create, Update, Describe and Search APIs for Rules (18bb14bc)
  • client-ecs: Adds a critical parameter to the Amazon ECS managed daemon APIs that controls whether a daemon task failure drains the container instance. Non-critical daemon failures no longer drain the instance or block instance registration. (2e6a07d5)
  • client-evs: Amazon EVS now allows users to set, update, and retrieve values for parameters that apply across all EVS Environments in their account at a regional level, such as the VCF License portability core count. (803b694c)
  • client-drs: AWS Elastic Disaster Recovery now includes source server architecture in SourceProperties to identify x86 and ARM64 systems. (20f19e0e)
  • client-bedrock-agentcore: Adds log group name prefix trace source selection, custom or source log group result destinations, and metrics namespace customization (823b2d33)
  • client-bedrock-agentcore-control: AgentCore Identity adds Consent Portal APIs to manage portals that let end users grant OAuth authorization for agents to access resources. AgentCore Evaluation adds trace source selection by log group prefix, custom or source log group result destinations, and metrics namespace customization. (2f826477)
  • client-eks: Deprecate EncryptionConfig resources field. Amazon EKS encrypts all Kubernetes API data with envelope encryption by default for clusters running Kubernetes version 1.28 or higher, so this field no longer affects which resources are encrypted. (c66ca41b)
  • client-guardduty: Adding support for Sequence Activities in GuardDuty Findings (5c12a0eb)
  • lib-transfer-manager: add download directory functionality (#8274) (6e591ee8)

For list of updated packages, view updated-packages.md in assets-3.1126.0.zip

v3.1125.0

3.1125.0(2026-09-02)

New Features
  • client-ec2: This release adds support to retain interruptible Capacity Reservations in an active state when all capacity is reclaimed. (336c7896)
  • client-sagemaker-featurestore-runtime: Amazon SageMaker Feature Store now supports the UpdateRecord API, enabling partial updates to individual feature values in an existing Online Store record without rewriting the entire record. This reduces write payloads and latency for high-frequency feature-level writes . (71920960)
  • client-sagemaker: Amazon SageMaker Feature Store now supports the Standard V2 online store type, which enables feature-level writes to feature groups. You can select Standard V2 when creating a feature group, and update the storage type of an existing feature group via UpdateFeatureGroup. (5287db7f)
  • client-odb: Adds the ListFlexComponents API for listing the flex components available for a given DB system shape. (551174bf)
  • client-mgn: AWS Transform for migrations adds a second network migration option - apply your source security posture to existing VPCs. Upload a source network file with firewall rules, tag the in-scope VPCs, and AWS Transform matches source subnets to them by CIDR and generates the security groups. (822144b2)
  • client-mwaa: Enabled customers to clear optional S3 paths (plugins, requirements, and startup script) for their Amazon MWAA environments by accepting empty strings for the associated fields in UpdateEnvironment requests. (9fa2e0c1)
  • client-bedrock-agentcore: Batch evaluation now supports up to 10 CloudWatch log groups per CloudWatchLogsSource (cebd3179)
  • client-medialive: AWS Elemental MediaLive now supports AB forensic video watermarking (d48e9e15)
  • client-appintegrations: This release adds a force parameter to DeleteApplication and a ConflictException to UpdateApplication, letting customers delete applications with existing associations in one call and get a clear error when an update conflicts with the application's current state. (62b7304c)
Bug Fixes
  • cloudfront-signer: preserve plus in query strings when signing URLs (#8283) (dd76a0dd)

... (truncated)

Changelog

Sourced from @​aws-sdk/lib-storage's changelog.

3.1126.0 (2026-09-03)

Note: Version bump only for package @​aws-sdk/lib-storage

3.1125.0 (2026-09-02)

Note: Version bump only for package @​aws-sdk/lib-storage

3.1124.0 (2026-09-01)

Note: Version bump only for package @​aws-sdk/lib-storage

3.1123.0 (2026-08-31)

Note: Version bump only for package @​aws-sdk/lib-storage

3.1122.0 (2026-08-31)

Note: Version bump only for package @​aws-sdk/lib-storage

3.1121.0 (2026-08-28)

Note: Version bump only for package @​aws-sdk/lib-storage

3.1120.0 (2026-08-27)

... (truncated)

Commits

Updates next from 16.2.12 to 16.3.4

Release notes

Sourced from next's releases.

v16.3.4

Follow-up release to v16.3.3 re-enabling AVIF Image Optimization (#97949).

The following bug fixes have been backported. It does not include all pending features/changes on canary.

  • testmode: Fix infinite recursion in testmode passthrough fetch (#97691)
  • Fix build error when aliasing typescript to @​typescript/typescript6 (#97997)
  • Fix unset crossOrigin in Turbopack manifests (#97930)

Credits

Huge thanks to @​eps1lon, @​mischnic, and @​timneutkens for helping!

v16.3.3

This release contains security fixes for the following advisories:

Critical:

v16.3.2

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • [backport] Scope app-entry export validation to files inside the app directory (#97357)
  • [backport] Fix catch-all index page being served for every other slug (#97416)
  • [16.3] Turbopack: don't trace embedded WASM loader helpers (#97353) (#97463)
  • [16.3] Turbopack: retain conditions when replacing resolve request keys (#97453)
  • [16.3.x] Fix Turbopack worker chunk loading with asset prefix (#97419)
  • [16.3.x] Authenticate Turborepo remote caching with OIDC instead of a static PAT (#97603)

Credits

Huge thanks to @​lubieowoce, @​unstubbable, @​timneutkens, @​mischnic, and @​eps1lon for helping!

v16.3.1

What's Changed

... (truncated)

Commits
  • 299180d v16.3.4
  • 12e173d [16.3.x] Re-enable AVIF image optimization and require sharp 0.35.4 (#97949)
  • 5d9022e [backport] Fix unset crossOrigin in Turbopack manifests (#97930)
  • d8f4560 [16.3.x] Fix build error when aliasing typescript to @​typescript/typescript6 ...
  • 656aebf [16.3] testmode: Fix infinite recursion in testmode passthrough fetch (#97691)
  • f37c1d6 [16.3.x] ci: remove pull_request_stats workflow (#97975)
  • a9a1cb7 v16.3.3
  • 968b9fc [16.3.x] Fix ISR misses with backslashes in segments when deployed on Windows
  • 3a15b4a [16.3.x] [next/image]: disable avif image optimization
  • 7378b51 Backport/docs fixes 16.3 (#97649)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 10, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8b4460b69b

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread package.json Outdated
"@ai-sdk/openai": "~3.0.74",
"@ai-sdk/react": "~3.0.210",
"@assistant-ui/react": "^0.14.23",
"@assistant-ui/react": "^0.15.8",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Regenerate the root Bun lockfile

In CI and container builds, this dependency bump leaves bun.lock out of sync: the lockfile still records @assistant-ui/react at ^0.14.23/0.14.23, @aws-sdk/lib-storage at 3.1096.0, and next at 16.2.12, while .github/workflows/ci.yml:36-37 and Dockerfile:15-21 both install with bun install --frozen-lockfile. With these package.json changes alone, the frozen install cannot use the committed lockfile for the new versions and fails during dependency installation, so CI/builds are blocked until the root bun.lock is updated in the same commit.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Member

🤖 pr-fix routine: blocked — cannot regenerate the lockfile in this environment

Diagnosis (confirmed, not a guess):

Four checks fail — Test, Lint, and Type Check, Validate CDK Infrastructure, Unified Content PostgreSQL Lifecycle, and Auth Edge Production Artifact. All four die on the same step, bun install --frozen-lockfile:

error: lockfile had changes, but lockfile is frozen
note: try re-running without --frozen-lockfile and commit the updated lockfile

This PR modifies only package.json (3 bumps) and does not touch bun.lock, which still pins all three old versions:

Package package.json (this PR) bun.lock (unchanged)
next 16.3.0 16.2.12
@assistant-ui/react ^0.15.8 0.14.23
@aws-sdk/lib-storage 3.1105.0 3.1096.0

So bun install --frozen-lockfile is correctly refusing. CI on dev at this PR's exact base commit (e39c3f5) is green, so this is PR-caused, not a pre-existing base-branch failure.

The fix is one commandbun install at the repo root, then commit the updated bun.lock. I could not run it: registry.npmjs.org is not in this session's egress allowlist (403 on all three packages), and a lockfile entry requires the package's real sha512 integrity hash from the registry. I will not fabricate one.

Systemic root cause — this is the 10th open PR blocked the same way.

.github/dependabot.yml still declares package-ecosystem: "npm" for both / and /infra. This repo has no package-lock.json or yarn.lock — it uses bun.lock. Dependabot's npm ecosystem edits package.json only and cannot update bun.lock, so every Dependabot JS PR desyncs the lockfile and fails --frozen-lockfile.

Currently blocked on this exact cause: #1566, #1567, #1570, #1571, #1572, #1573, #1574, #1575, #1576, and this one. (#1561 and #1563 are stuck for unrelated reasons; #1562, #1564, #1597 are green and just awaiting review.)

This was already reported on #1566 on Aug 4 and the config is unchanged, so I'm escalating rather than repeating it per-PR. Two options for a human:

  1. Per-PR: run bun install on each branch and push the lockfile.
  2. Once, permanently: switch .github/dependabot.yml to package-ecosystem: "bun" for both directories so Dependabot maintains bun.lock itself. I deliberately did not make this change — it reshapes every future dependency PR, it would not fix this PR (dependabot config only takes effect for newly-created PRs after it merges to the default branch), and I can't validate it from here. That should be your call.

A third option, if you want this routine to fix these itself: add registry.npmjs.org to the routine environment's network egress allowlist, and I can regenerate lockfiles directly on future fires.

The routine will not pick this PR up again until someone removes the pr-fix-stuck label.


Generated by Claude Code

@krishagel krishagel added the pr-fix-stuck pr-fix routine gave up — human attention needed label Aug 10, 2026 — with Claude
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/dev/minor-and-patch-4c3e55582a branch 2 times, most recently from ad50f68 to 65833bf Compare August 24, 2026 17:05
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/dev/minor-and-patch-4c3e55582a branch from 65833bf to 90c18dc Compare August 31, 2026 17:06
… updates

Bumps the minor-and-patch group with 3 updates in the / directory: [@assistant-ui/react](https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react), [@aws-sdk/lib-storage](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/lib/lib-storage) and [next](https://github.com/vercel/next.js).


Updates `@assistant-ui/react` from 0.14.29 to 0.15.18
- [Release notes](https://github.com/assistant-ui/assistant-ui/releases)
- [Changelog](https://github.com/assistant-ui/assistant-ui/blob/main/packages/react/CHANGELOG.md)
- [Commits](https://github.com/assistant-ui/assistant-ui/commits/@assistant-ui/react@0.15.18/packages/react)

Updates `@aws-sdk/lib-storage` from 3.1096.0 to 3.1126.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/lib/lib-storage/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1126.0/lib/lib-storage)

Updates `next` from 16.2.12 to 16.3.4
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.2.12...v16.3.4)

---
updated-dependencies:
- dependency-name: "@assistant-ui/react"
  dependency-version: 0.15.8
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@aws-sdk/lib-storage"
  dependency-version: 3.1105.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: next
  dependency-version: 16.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/dev/minor-and-patch-4c3e55582a branch from 90c18dc to 55ef709 Compare September 7, 2026 17:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code pr-fix-stuck pr-fix routine gave up — human attention needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant