Skip to content

build(deps): bump the playbook-node group in /playbook/node with 11 updates - #21

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/playbook/node/playbook-node-6dbd352f81
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/playbook/node/playbook-node-6dbd352f81

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown

Bumps the playbook-node group in /playbook/node with 11 updates:

Package From To
@ai-sdk/anthropic 4.0.46 4.0.65
@browserbasehq/sdk 2.19.0 2.21.0
@browserbasehq/stagehand 4.0.2 4.1.0
boxen 8.0.1 9.0.0
chalk 5.6.2 6.0.1
dotenv 16.6.1 18.0.4
zod 4.4.3 4.6.5
ai 7.0.86 7.0.118
playwright-core 1.62.1 1.63.0
open 11.0.2 11.0.4
jszip 3.10.1 3.10.2

Updates @ai-sdk/anthropic from 4.0.46 to 4.0.65

Release notes

Sourced from @​ai-sdk/anthropic's releases.

@​ai-sdk/provider-utils@​4.0.57

Patch Changes

  • a9cea74: Keep default Node.js downloads protected by DNS validation and connection pinning when frameworks or instrumentation wrap global fetch before or after the SDK loads.
  • a9cea74: fix(mcp): prevent SSRF in OAuth metadata discovery
  • a9cea74: fix(provider-utils): make lazy Undici import visible to deployment tracers
Changelog

Sourced from @​ai-sdk/anthropic's changelog.

4.0.65

Patch Changes

  • Updated dependencies [af9597b]
  • Updated dependencies [bc49f78]
    • @​ai-sdk/provider-utils@​5.0.49

4.0.64

Patch Changes

  • 67f8000: Preserve effort updates on empty system messages at the beginning of a conversation, including consecutive updates.
  • Updated dependencies [be877ff]
    • @​ai-sdk/provider-utils@​5.0.48

4.0.63

Patch Changes

  • 154221f: feat(anthropic): support on-demand compaction and preserve signed compaction blocks

4.0.62

Patch Changes

  • 771e74b: chore: enable dead code lint rules
  • Updated dependencies [fe07867]
  • Updated dependencies [a4b0940]
  • Updated dependencies [771e74b]
    • @​ai-sdk/provider-utils@​5.0.47

4.0.61

Patch Changes

  • 3733d6e: fix(anthropic): omit empty compaction blocks from replay
  • Updated dependencies [ffb0e76]
    • @​ai-sdk/provider@​4.0.18
    • @​ai-sdk/provider-utils@​5.0.46

4.0.60

Patch Changes

  • 49295bb: feat(anthropic): add Claude Opus 5.5 support

    • add the claude-opus-5-5 model ID to @ai-sdk/anthropic and anthropic/claude-opus-5.5 to @ai-sdk/gateway
    • models that always use adaptive thinking (claude-opus-5-5, claude-fable-5, claude-fable-5-1) no longer receive thinking: { type: 'disabled' } or budget-based thinking; the provider drops the unsupported setting, maps reasoning: 'none' to effort: 'low', and emits a warning
    • models that reject forced tool use (claude-opus-5-5, claude-fable-5-1) fall back to auto tool choice for required and named tool choices, and to native structured outputs when structuredOutputMode: 'jsonTool' is requested, each with a warning

... (truncated)

Commits

Updates @browserbasehq/sdk from 2.19.0 to 2.21.0

Release notes

Sourced from @​browserbasehq/sdk's releases.

v2.21.0

2.21.0 (2026-09-24)

Features

  • Add secrets SDK generation (f22482a)

v2.20.0

2.20.0 (2026-09-09)

Features

  • api: declare the webhooks resource (d57781b)

Chores

  • api: reset webhooks before release re-land (bf7ad1e)

v2.19.1

2.19.1 (2026-09-03)

Chores

Changelog

Sourced from @​browserbasehq/sdk's changelog.

2.21.0 (2026-09-24)

Features

  • Add secrets SDK generation (f22482a)

2.20.0 (2026-09-09)

Features

  • api: declare the webhooks resource (d57781b)

Chores

  • api: reset webhooks before release re-land (bf7ad1e)

2.19.1 (2026-09-03)

Chores

Commits
  • adef824 release: 2.21.0 (#221)
  • 86b5179 Build SDK
  • e8e4409 [AP-2931] docs(agents): pausing and resuming runs (#12265)
  • f22482a feat: Add secrets SDK generation
  • cdcef9d [AP-3006] Expose secrets operations in SDK spec (#12281)
  • 629718d [CB-0000] fix(api): align downloads pagination schema and defaults (#11957)
  • fe805b8 release: 2.20.0 (#220)
  • 272f02f test(webhooks): use the configured HTTP response shim (#8)
  • d57781b feat(api): declare the webhooks resource
  • bf7ad1e chore(api): reset webhooks before release re-land
  • Additional commits viewable in compare view

Updates @browserbasehq/stagehand from 4.0.2 to 4.1.0

Changelog

Sourced from @​browserbasehq/stagehand's changelog.

TypeScript SDK 4.1.0

Minor Changes

  • #2828 e2c8946 Thanks @​miguelg719! - Expose Browserbase Search and Fetch through the Stagehand browserbase facade in TypeScript, Python, and Go.

Patch Changes

Python SDK 4.1.0

Minor Changes

  • #2828 e2c8946 Thanks @​miguelg719! - Expose Browserbase Search and Fetch through the Stagehand browserbase facade in TypeScript, Python, and Go.

Patch Changes

Extension Runtime 1.0.2

Patch Changes

... (truncated)

Commits
  • cd7b230 Release Stagehand packages (#2798)
  • e825c77 test: cross-version compatibility check against the last published extension ...
  • 67a4668 [fix]: fail fast on incompatible Stagehand runtime instead of polling to time...
  • 5beaca7 test: make runtime compatibility fixtures resilient to protocol bumps (#2908)
  • 50146e4 [feat]: add support for WebMCP tool invokation in iframes (#2878)
  • e2c8946 feat(sdk): expose Browserbase search and fetch (#2828)
  • d2d9169 [fix]: close parity gaps across SDKs for local browser launching (#2864)
  • 8df637a [chore]: fix ts package boundaries (#2865)
  • a144e1b [refactor]: replace chrome-launcher with handrolled local browser launcher ...
  • 6555e81 [fix]: align browser.close and context.close semantics (#2827)
  • Additional commits viewable in compare view

Updates boxen from 8.0.1 to 9.0.0

Release notes

Sourced from boxen's releases.

v9.0.0

Breaking

  • Require Node.js 22 0aead27

Improvements

  • Add maxWidth option 5932ef4
  • Add footer option e719cec
  • Add titleColor option c0f18e7
  • Add borderBackgroundColor option (#100) 1373d4f
  • Lots of bug fixes

sindresorhus/boxen@v8.0.1...v9.0.0

Commits
  • a809729 9.0.0
  • 2e901c1 Measure a label with the corners it is drawn between
  • 6d377fb More tests
  • 427ac21 Give the box the height it is given when the text does not fit
  • 94db7a5 Write a border character the way a label is written
  • 804e1e7 Keep a styling escape whole when a backspace is applied
  • 9f8fabd Draw a padding and a margin as a whole number of columns
  • 986a49b Do not take columns for a margin that is not drawn
  • 2bc26cd Measure the border in columns
  • 7ed8da2 Read the height of the terminal from LINES
  • Additional commits viewable in compare view

Updates chalk from 5.6.2 to 6.0.1

Release notes

Sourced from chalk's releases.

v6.0.1

  • Fix inconsistent coercion of two arguments 9c93a04

chalk/chalk@v6.0.0...v6.0.1

v6.0.0

Breaking

  • Require Node.js 22 8a94e0e

Improvements

  • Add underline styles and underline colors (#689) 4c304dd
  • Improve performance 5729845 fa5cff2

Fixes

  • Treat a numeric FORCE_COLOR as an exact level (#688) e912931
  • Downsample ansi256() and bgAnsi256() to 16 colors at level 1 (#687) ff549c5

chalk/chalk@v5.6.2...v6.0.0

Commits

Updates dotenv from 16.6.1 to 18.0.4

Changelog

Sourced from dotenv's changelog.

18.0.4 (2026-09-25)

Changed

  • import dotenv/config should default quiet: true (#1063)

18.0.3 (2026-09-22)

Changed

  • Patch DOTENV_QUIET setting when inside .env file (#1059)

18.0.2 (2026-09-21)

Changed

  • Patch additional edge cases for the fast parser (#1056)

18.0.1 (2026-09-18)

Changed

  • Handle file urls in config logging (#1054)

18.0.0 (2026-09-17)

Added

  • NEW: Dotenv now has a CLI. (#1022)
$ dotenv run -- node index.js
◇ injected env (2) from .env
Hello Dotenv
  • NEW: Dotenv now has a fast parser thanks to @​homanp of superagent.sh. Pass config({ fast: true }), flag --fast, or set DOTENV_FAST=true to opt-in to ~2x faster character-scanner parser. (#1010)
$ dotenv run --fast -- node index.js
◇ injected env (2) from .env
Hello Dotenv

faster than Node native parseEnv!

Changed

  • Injecting message sent to stderr rather than stdout and tips removed (#1037)

... (truncated)

Commits

Updates zod from 4.4.3 to 4.6.5

Release notes

Sourced from zod's releases.

v4.6.5

Commits:

  • d2b135cfb7a3582b9eb515756b9166bcb9521f4a docs: add the 4.6.x patch highlights to the 4.6 post
  • f1448f7cee00df9fe1e9ad84a000aa1828cc8bc1 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • de65a5cb39ed22a507fac935788f718fa88d104f docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • 56222cd1532c07bcb91b67df529cab4c0a215330 feat(instanceof): key the .properties() shape off the instance type (#6600)
  • ca0229a404818290e6cdcfefcd7eb2d04bcbb543 Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)"
  • cc4cd4ee9c52fcaa10964e48cc144541e41a5ed9 Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)""
  • 0f3f5ee3ca56c7574bf849e54f79e9a6e02562ee 4.6.5
  • 59bbc03e10c636b9eb3c393dfeb552819774ec21 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump

v4.6.4

A patch on top of 4.6.3.

  • d6bc1e30 feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)
  • ad32d751 perf: z.url() rejects an invalid URL with URL.canParse() instead of a throwing constructor, about 50x faster; fewer allocations on the validation path (#6588)
  • 2bb08717 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • f6e1701a chore(deps): bump next to 15.5.25 and vite to 7.3.6 (#6153)

v4.6.3

A patch on top of 4.6.2.

  • 413cce9a fix(v4): make z.properties() a check again (#6594) — removes the standalone z.properties() schema from 4.6.0; z.instanceof().properties() and .check(...z.properties()) are unchanged
  • 75d63ee1 docs: show only the .properties() method form in the 4.6 post
  • 46da9572 docs: match the error-message examples to what the parsers emit

v4.6.2

A patch on top of 4.6.1.

v4.6.1

A patch on top of 4.6.0.

v4.6.0

Zod 4.6 is now available.

npm install zod@latest

At a glance:

... (truncated)

Commits
  • 59bbc03 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump
  • 0f3f5ee 4.6.5
  • cc4cd4e Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, ref...
  • ca0229a Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed w...
  • 56222cd feat(instanceof): key the .properties() shape off the instance type (#6600)
  • de65a5c docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • f1448f7 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • d2b135c docs: add the 4.6.x patch highlights to the 4.6 post
  • 2bb0871 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • 743aedb 4.6.4
  • Additional commits viewable in compare view

Updates ai from 7.0.86 to 7.0.118

Changelog

Sourced from ai's changelog.

7.0.118

Patch Changes

  • Updated dependencies [e6a7996]
  • Updated dependencies [e19f0fc]
    • @​ai-sdk/gateway@​4.0.96

7.0.117

Patch Changes

  • Updated dependencies [b67b1b7]
    • @​ai-sdk/gateway@​4.0.95

7.0.116

Patch Changes

  • af9597b: Compile packages for ES2022 runtime target
  • bc49f78: Preserve original opaque URI strings in tagged file URLs during prompt conversion. Match explicit supported URL MIME types exactly so unsupported subtypes are not forwarded to providers.
  • Updated dependencies [af9597b]
  • Updated dependencies [bc49f78]
    • @​ai-sdk/provider-utils@​5.0.49
    • @​ai-sdk/gateway@​4.0.94

7.0.115

Patch Changes

  • be877ff: Use the new fetchUntrustedUrl helper for SDK downloads, preserving the existing user-agent header and URL validation while enforcing first-hop credential isolation.
  • Updated dependencies [80b9100]
  • Updated dependencies [d3cc6ae]
  • Updated dependencies [be877ff]
    • @​ai-sdk/gateway@​4.0.93
    • @​ai-sdk/provider-utils@​5.0.48

7.0.114

Patch Changes

  • b5679a7: fix(ai): filter tracing-channel context with telemetry allowlists
  • ca31b89: Clarify in the prompt validation code that allowSystemInMessages permits all system messages, including instruction text.
  • Updated dependencies [124b6ef]
    • @​ai-sdk/gateway@​4.0.92

7.0.113

Patch Changes

... (truncated)

Commits

Updates playwright-core from 1.62.1 to 1.63.0

Release notes

Sourced from playwright-core's releases.

v1.63.0

🔒 Test locks

Tests that access a shared resource — an external service, a global account setting — can now declare a named lock. Tests that share a lock name never run concurrently, across files, workers and projects, while everything else keeps running in parallel:

test('update user settings', { lock: 'user-settings' }, async ({ page }) => {
  // never runs at the same time as other tests holding 'user-settings'
});

A test can hold multiple locks, and test.describe() accepts a lock for the whole group. Learn more about test locks.

🪟 Locate across frames

page.frameLocator() and frame.frameLocator() called without a selector search in any frame of the subtree, so you no longer need to locate the iframe first:

// Finds the button in any frame on the page.
await page.frameLocator().getByRole('button').click();

The rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it matches elements in several frames.

👁️ Visible-only locators

New locator.visible() returns a locator that matches only visible elements. It is the recommended replacement for the :visible CSS pseudo-class:

await page.locator('button').visible().click();

🧾 Step params and subtitles

Steps now carry structured data for reporters. Playwright API steps report the target locator and call arguments, and test.step() accepts subtitle and params options for your own steps:

await test.step('Login', async () => {
  // ...
}, { subtitle: 'as admin', params: { user: 'admin' } });

Reporters receive them via testStep.subtitle and testStep.params. For Playwright API

... (truncated)

Commits
  • 1b025d7 chore: mark v1.63.0 (#42569)
  • 0b9956d cherry-pick(#42568): docs(test): mark test.step subtitle option as since v1.63
  • 13dbf10 cherry-pick(#42552): docs: release notes for v1.63
  • e93b64e cherry-pick(#42566): feat(test): add subtitle option to test.step (#42567)
  • 2b7a5f2 test: response.body() for content-encoding:identity (#42537)
  • 648a67c fix(mcp): create parent directories for explicitly named files (#42540)
  • 7894f56 docs(mcp): clarify how tool file names are resolved (#42538)
  • 52900a1 devops: restore npm publishing from GitHub Actions (#42550)
  • 8c47f59 docs(csharp): fix nonexistent method names in guide examples (#42507)
  • bd6e552 chore(video): emit frames with real timestamps, drop frame number quantizatio...
  • Additional commits viewable in compare view

Updates open from 11.0.2 to 11.0.4

Release notes

Sourced from open's releases.

v11.0.4

  • Fix browser/browserPrivate not detecting Safari or Brave as the default browser 6ae6196

sindresorhus/open@v11.0.3...v11.0.4

v11.0.3

  • Fix Windows launches being killed when the parent process exits 734b821

sindresorhus/open@v11.0.2...v11.0.3

Commits
  • 4151110 11.0.4
  • 6ae6196 Fix browser/browserPrivate not detecting Safari or Brave as the default b...
  • 81deafb 11.0.3
  • 734b821 Fix Windows launches being killed when the parent process exits
  • See full diff in compare view

Updates jszip from 3.10.1 to 3.10.2

Changelog

Sourced from jszip's changelog.

v3.10.2 2026-09-09

  • Fix cross-realm binary type detection in getTypeOf. Fixes #759 (see #578)
  • Add missing types for JSZip.defaults. Fixes #690 (see #927)
  • Fix Blob support in Node.js 18 and up. Fixes #941 (see #955)
Commits
Maintainer changes

This version was pushed to npm by jkoops, a new releaser for jszip since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the playbook-node group in /playbook/node with 11 updates:

| Package | From | To |
| --- | --- | --- |
| [@ai-sdk/anthropic](https://github.com/vercel/ai/tree/HEAD/packages/anthropic) | `4.0.46` | `4.0.65` |
| [@browserbasehq/sdk](https://github.com/browserbase/sdk-node) | `2.19.0` | `2.21.0` |
| [@browserbasehq/stagehand](https://github.com/browserbase/stagehand/tree/HEAD/packages/sdk-ts) | `4.0.2` | `4.1.0` |
| [boxen](https://github.com/sindresorhus/boxen) | `8.0.1` | `9.0.0` |
| [chalk](https://github.com/chalk/chalk) | `5.6.2` | `6.0.1` |
| [dotenv](https://github.com/motdotla/dotenv) | `16.6.1` | `18.0.4` |
| [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.6.5` |
| [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai) | `7.0.86` | `7.0.118` |
| [playwright-core](https://github.com/microsoft/playwright) | `1.62.1` | `1.63.0` |
| [open](https://github.com/sindresorhus/open) | `11.0.2` | `11.0.4` |
| [jszip](https://github.com/Stuk/jszip) | `3.10.1` | `3.10.2` |


Updates `@ai-sdk/anthropic` from 4.0.46 to 4.0.65
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/packages/anthropic/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/@ai-sdk/anthropic@4.0.65/packages/anthropic)

Updates `@browserbasehq/sdk` from 2.19.0 to 2.21.0
- [Release notes](https://github.com/browserbase/sdk-node/releases)
- [Changelog](https://github.com/browserbase/sdk-node/blob/main/CHANGELOG.md)
- [Commits](browserbase/sdk-node@v2.19.0...v2.21.0)

Updates `@browserbasehq/stagehand` from 4.0.2 to 4.1.0
- [Release notes](https://github.com/browserbase/stagehand/releases)
- [Changelog](https://github.com/browserbase/stagehand/blob/main/CHANGELOG.md)
- [Commits](https://github.com/browserbase/stagehand/commits/@browserbasehq/stagehand@4.1.0/packages/sdk-ts)

Updates `boxen` from 8.0.1 to 9.0.0
- [Release notes](https://github.com/sindresorhus/boxen/releases)
- [Commits](sindresorhus/boxen@v8.0.1...v9.0.0)

Updates `chalk` from 5.6.2 to 6.0.1
- [Release notes](https://github.com/chalk/chalk/releases)
- [Commits](chalk/chalk@v5.6.2...v6.0.1)

Updates `dotenv` from 16.6.1 to 18.0.4
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v16.6.1...v18.0.4)

Updates `zod` from 4.4.3 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.4.3...v4.6.5)

Updates `ai` from 7.0.86 to 7.0.118
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/packages/ai/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/ai@7.0.118/packages/ai)

Updates `playwright-core` from 1.62.1 to 1.63.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.62.1...v1.63.0)

Updates `open` from 11.0.2 to 11.0.4
- [Release notes](https://github.com/sindresorhus/open/releases)
- [Commits](sindresorhus/open@v11.0.2...v11.0.4)

Updates `jszip` from 3.10.1 to 3.10.2
- [Changelog](https://github.com/Stuk/jszip/blob/main/CHANGES.md)
- [Commits](Stuk/jszip@v3.10.1...v3.10.2)

---
updated-dependencies:
- dependency-name: "@ai-sdk/anthropic"
  dependency-version: 4.0.65
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: playbook-node
- dependency-name: "@browserbasehq/sdk"
  dependency-version: 2.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: playbook-node
- dependency-name: "@browserbasehq/stagehand"
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: playbook-node
- dependency-name: boxen
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: playbook-node
- dependency-name: chalk
  dependency-version: 6.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: playbook-node
- dependency-name: dotenv
  dependency-version: 18.0.4
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: playbook-node
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: playbook-node
- dependency-name: ai
  dependency-version: 7.0.118
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: playbook-node
- dependency-name: playwright-core
  dependency-version: 1.63.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: playbook-node
- dependency-name: open
  dependency-version: 11.0.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: playbook-node
- dependency-name: jszip
  dependency-version: 3.10.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: playbook-node
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 1, 2026
@dependabot
dependabot Bot requested review from a team as code owners October 1, 2026 05:58
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 1, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​boxen@​9.0.010010010080100
Addednpm/​chalk@​6.0.110010010087100
Addednpm/​@​ai-sdk/​anthropic@​4.0.65931008898100
Addednpm/​ai@​7.0.1189910010099100
Addednpm/​@​browserbasehq/​stagehand@​4.1.0100100100100100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants