Skip to content

chore(deps): bump @ai-sdk/provider-utils, @ai-sdk/amazon-bedrock and ai in /samples/mastra-extended/app - #698

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/samples/mastra-extended/app/multi-858b19bc51
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/samples/mastra-extended/app/multi-858b19bc51

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @ai-sdk/provider-utils to 4.0.57 and updates ancestor dependencies @ai-sdk/provider-utils, @ai-sdk/amazon-bedrock and ai. These dependencies need to be updated together.

Updates @ai-sdk/provider-utils from 2.2.8 to 4.0.57

Release notes

Sourced from @​ai-sdk/provider-utils's releases.

@​ai-sdk/provider-utils@​4.0.57

Patch Changes

  • a9cea74: Keep default Node.js downloads protected by DNS validation and connection pinning when frameworks or instrumentation wrap global fetch before or after the SDK loads.
  • a9cea74: fix(mcp): prevent SSRF in OAuth metadata discovery
  • a9cea74: fix(provider-utils): make lazy Undici import visible to deployment tracers

@​ai-sdk/provider-utils@​3.0.41

Patch Changes

  • 2b1c2df: Keep default Node.js downloads protected by DNS validation and connection pinning when frameworks or instrumentation wrap global fetch before or after the SDK loads.
  • 2b1c2df: fix(mcp): prevent SSRF in OAuth metadata discovery
  • 2b1c2df: fix(provider-utils): make lazy Undici import visible to deployment tracers
Changelog

Sourced from @​ai-sdk/provider-utils's changelog.

4.0.57

Patch Changes

  • a9cea74: Keep default Node.js downloads protected by DNS validation and connection pinning when frameworks or instrumentation wrap global fetch before or after the SDK loads.
  • a9cea74: fix(mcp): prevent SSRF in OAuth metadata discovery
  • a9cea74: fix(provider-utils): make lazy Undici import visible to deployment tracers

4.0.56

Patch Changes

  • 29dc427: fix(provider-utils): preserve streamed tool calls with unreliable IDs and indices

4.0.55

Patch Changes

  • 3983fea: fix(provider): preserve media types on tool result file URLs and match full MIME types exactly when checking native URL support.
  • Updated dependencies [3983fea]
    • @​ai-sdk/provider@​3.0.18

4.0.54

Patch Changes

  • 069a945: Fix Google embedMany calls with more than 100 values by keeping per-value multimodal content aligned across automatic batches, including text-only entries. Validate content length before sending requests and validate each batch's provider options after middleware transforms them.

  • d1a36d2: fix(ai): execute manually approved tool inputs produced by schema transforms

    Preserve approved inputs during revalidation and reject histories whose reconstructed schema output differs, including signed approvals with missing original input. Validate transformed UI tool inputs against the reconstructed output before returning them as static tool parts.

  • f7f36d2: chore: enable dead code lint rules

4.0.53

Patch Changes

  • Updated dependencies [da2e17b]
    • @​ai-sdk/provider@​3.0.17

4.0.52

Patch Changes

  • 82e18b0: fix(provider-utils): avoid excessive memory usage when base64 encoding byte arrays

4.0.51

Patch Changes

... (truncated)

Commits
  • 8dde272 Version Packages (#21848)
  • a9cea74 Backport: fix(mcp, provider-utils): DNS-pinned MCP OAuth fetches under wrappe...
  • fc81a9e Version Packages (#21573)
  • 29dc427 [v6.0] fix: preserve streamed tool calls when gateway IDs or indices are unre...
  • 5da12f6 Version Packages (#21513)
  • 3983fea [v6.0] fix: forward Google Vertex GCS tool-result files as function response ...
  • ba213ad Version Packages (#21368)
  • d1a36d2 [v6.0] fix: manual tool approvals reject or mutate transformed inputs across ...
  • 069a945 [v6.0] fix: preserve Google embedMany content alignment across automatic batc...
  • f7f36d2 [v6] chore: enable dead code lint rules (#21395)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​ai-sdk/provider-utils since your current version.


Updates @ai-sdk/amazon-bedrock from 4.0.92 to 4.0.190

Release notes

Sourced from @​ai-sdk/amazon-bedrock's releases.

@​ai-sdk/react@​4.0.129

Patch Changes

  • Updated dependencies [4f3d236]
    • ai@7.0.126

@​ai-sdk/react@​4.0.127

Patch Changes

  • Updated dependencies [8c65988]
  • Updated dependencies [527a163]
    • ai@7.0.124
    • @​ai-sdk/provider@​4.0.21
    • @​ai-sdk/provider-utils@​5.0.53
    • @​ai-sdk/mcp@​2.0.64

@​ai-sdk/react@​4.0.126

Patch Changes

  • 193d284: fix(react): deduplicate automatic stream resumption for shared Chat instances
  • ede5b89: chore: migrate package builds from tsup to tsdown
  • Updated dependencies [05cdac6]
  • Updated dependencies [4514fc1]
  • Updated dependencies [ede5b89]
  • Updated dependencies [2a625cf]
  • Updated dependencies [50a26d5]
    • ai@7.0.123
    • @​ai-sdk/mcp@​2.0.63
    • @​ai-sdk/provider@​4.0.20
    • @​ai-sdk/provider-utils@​5.0.52

@​ai-sdk/vue@​4.0.126

Patch Changes

  • Updated dependencies [4f3d236]
    • ai@7.0.126

@​ai-sdk/vue@​4.0.124

Patch Changes

  • Updated dependencies [8c65988]
  • Updated dependencies [527a163]
    • ai@7.0.124
    • @​ai-sdk/provider-utils@​5.0.53

@​ai-sdk/vue@​4.0.123

Patch Changes

  • ede5b89: chore: migrate package builds from tsup to tsdown
  • Updated dependencies [05cdac6]

... (truncated)

Changelog

Sourced from @​ai-sdk/amazon-bedrock's changelog.

4.0.190

Patch Changes

  • Updated dependencies [f56545c]
    • @​ai-sdk/openai@​3.0.123

4.0.189

Patch Changes

  • Updated dependencies [d5c12b2]
    • @​ai-sdk/anthropic@​3.0.127

4.0.188

Patch Changes

  • Updated dependencies [a9cea74]
  • Updated dependencies [a9cea74]
  • Updated dependencies [a9cea74]
    • @​ai-sdk/provider-utils@​4.0.57
    • @​ai-sdk/anthropic@​3.0.126
    • @​ai-sdk/openai@​3.0.122

4.0.187

Patch Changes

  • Updated dependencies [4972874]
    • @​ai-sdk/openai@​3.0.121

4.0.186

Patch Changes

  • 358683e: feat(anthropic): add Claude Sonnet 5.5 support

    • add the claude-sonnet-5-5 model ID to @ai-sdk/anthropic and @ai-sdk/google-vertex, anthropic.claude-sonnet-5-5 and us.anthropic.claude-sonnet-5-5 to @ai-sdk/amazon-bedrock, and anthropic/claude-sonnet-5.5 to @ai-sdk/gateway
    • add the between_tools thinking type (thinking: { type: 'between_tools' }), the lowest thinking setting on claude-sonnet-5-5; xhigh and max effort are lowered to high with a warning because the API rejects them with between_tools
    • claude-sonnet-5-5 rejects disabled thinking: thinking: { type: 'disabled' } is replaced with between_tools thinking (with a warning), and budget-based thinking is converted to adaptive thinking
    • claude-sonnet-5-5 rejects forced tool use: required and named tool choices fall back to auto, and structuredOutputMode: 'jsonTool' falls back to native structured outputs, each with a warning
  • Updated dependencies [358683e]

  • Updated dependencies [eeabdce]

    • @​ai-sdk/anthropic@​3.0.125

4.0.185

Patch Changes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​ai-sdk/amazon-bedrock since your current version.


Updates ai from 6.0.149 to 6.0.299

Release notes

Sourced from ai's releases.

ai@6.0.299

Patch Changes

  • Updated dependencies [a2749a2]
    • @​ai-sdk/gateway@​3.0.208

ai@6.0.298

Patch Changes

  • a9cea74: Keep default Node.js downloads protected by DNS validation and connection pinning when frameworks or instrumentation wrap global fetch before or after the SDK loads.
  • Updated dependencies [a9cea74]
  • Updated dependencies [a9cea74]
  • Updated dependencies [a9cea74]
    • @​ai-sdk/provider-utils@​4.0.57
    • @​ai-sdk/gateway@​3.0.207

ai@6.0.297

Patch Changes

  • 8349396: fix(ai): preserve hydrated partial static tool input across stream resumptions
  • ab0b94b: fix(ai): keep idle UI message streams open with optional SSE heartbeats
  • ce660b0: Clarify that provider-executed tool execution errors bypass the UI stream's onError callback to preserve provider error data. Stream errors and invalid tool calls still use the callback. Runtime behavior is unchanged.
  • 850d4d5: Encode chat IDs in default stream reconnection URLs so slashes, query delimiters, and fragments stay within the ID. Reject standalone . and .. IDs before fetching. Custom URLs returned by prepareReconnectToStreamRequest remain unchanged.
  • cdc5b56: Preserve prototype-named tools, providers, and provider metadata as own properties without changing lookup object prototypes. Prevent inherited names from resolving as registered providers or causing image metadata aggregation to fail.
  • d4203d2: Prevent automatic chat resumption when completed tool output is followed by terminal text without a completed stream state, while preserving resumption after completed model text.
  • Updated dependencies [4972874]
  • Updated dependencies [03e5a25]
    • @​ai-sdk/gateway@​3.0.206
Changelog

Sourced from ai's changelog.

6.0.299

Patch Changes

  • Updated dependencies [a2749a2]
    • @​ai-sdk/gateway@​3.0.208

6.0.298

Patch Changes

  • a9cea74: Keep default Node.js downloads protected by DNS validation and connection pinning when frameworks or instrumentation wrap global fetch before or after the SDK loads.
  • Updated dependencies [a9cea74]
  • Updated dependencies [a9cea74]
  • Updated dependencies [a9cea74]
    • @​ai-sdk/provider-utils@​4.0.57
    • @​ai-sdk/gateway@​3.0.207

6.0.297

Patch Changes

  • 8349396: fix(ai): preserve hydrated partial static tool input across stream resumptions
  • ab0b94b: fix(ai): keep idle UI message streams open with optional SSE heartbeats
  • ce660b0: Clarify that provider-executed tool execution errors bypass the UI stream's onError callback to preserve provider error data. Stream errors and invalid tool calls still use the callback. Runtime behavior is unchanged.
  • 850d4d5: Encode chat IDs in default stream reconnection URLs so slashes, query delimiters, and fragments stay within the ID. Reject standalone . and .. IDs before fetching. Custom URLs returned by prepareReconnectToStreamRequest remain unchanged.
  • cdc5b56: Preserve prototype-named tools, providers, and provider metadata as own properties without changing lookup object prototypes. Prevent inherited names from resolving as registered providers or causing image metadata aggregation to fail.
  • d4203d2: Prevent automatic chat resumption when completed tool output is followed by terminal text without a completed stream state, while preserving resumption after completed model text.
  • Updated dependencies [4972874]
  • Updated dependencies [03e5a25]
    • @​ai-sdk/gateway@​3.0.206

6.0.296

Patch Changes

  • 0741da8: fix(ai): allow agent UI streams to use original messages as input
  • a63fa9b: fix(ai): preserve tool metadata from tool output chunks
  • a61bea9: Preserve provider metadata on corresponding smoothStream chunks without carrying it into subsequent metadata-free deltas.

6.0.295

Patch Changes

  • 0b38b6b: fix(ai): continue active UI message parts when resuming after a disconnect
  • Updated dependencies [358683e]
    • @​ai-sdk/gateway@​3.0.205

6.0.294

... (truncated)

Commits
  • def2c64 Version Packages (#21852)
  • 8dde272 Version Packages (#21848)
  • a9cea74 Backport: fix(mcp, provider-utils): DNS-pinned MCP OAuth fetches under wrappe...
  • 76a2575 Version Packages (#21670)
  • c937f88 [v6] chore(ai): raise bundle size limit to 630 KB (#21802)
  • ab0b94b [v6.0] fix: idle UI message streams failing to flush promptly or remain open ...
  • 8349396 [v6.0] fix: resume hydrated partial static tool calls without losing streamin...
  • ce660b0 docs(ai): document provider tool error exception in v6 (#21663)
  • cdc5b56 fix(ai,mcp): backport prototype-safe maps to v6 (#21658)
  • 850d4d5 fix(ai): backport reconnect chat ID encoding to v6 (#21661)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for ai since your current version.


Samples Checklist

✅ All good!

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 8, 2026
@dependabot
dependabot Bot deployed to deploy-changed-samples September 8, 2026 16:19 Active
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/samples/mastra-extended/app/multi-858b19bc51 branch 3 times, most recently from 30f4b42 to 2a3c2e8 Compare September 8, 2026 23:17
@dependabot
dependabot Bot deployed to deploy-changed-samples September 8, 2026 23:17 Active
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/samples/mastra-extended/app/multi-858b19bc51 branch from 2a3c2e8 to 57916a1 Compare September 24, 2026 18:50
@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 7ba8a06d-07a8-4e12-884a-c388d9ae3274

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@dependabot
dependabot Bot deployed to deploy-changed-samples September 24, 2026 18:50 Active
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/samples/mastra-extended/app/multi-858b19bc51 branch from 57916a1 to 5939a94 Compare September 28, 2026 22:52
@dependabot
dependabot Bot deployed to deploy-changed-samples September 28, 2026 22:53 Active
Bumps [@ai-sdk/provider-utils](https://github.com/vercel/ai/tree/HEAD/packages/provider-utils) to 4.0.57 and updates ancestor dependencies [@ai-sdk/provider-utils](https://github.com/vercel/ai/tree/HEAD/packages/provider-utils), [@ai-sdk/amazon-bedrock](https://github.com/vercel/ai/tree/HEAD/packages/amazon-bedrock) and [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai). These dependencies need to be updated together.


Updates `@ai-sdk/provider-utils` from 2.2.8 to 4.0.57
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/@ai-sdk/provider-utils@4.0.57/packages/provider-utils/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/@ai-sdk/provider-utils@4.0.57/packages/provider-utils)

Updates `@ai-sdk/amazon-bedrock` from 4.0.92 to 4.0.190
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/@ai-sdk/amazon-bedrock@4.0.190/packages/amazon-bedrock/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/@ai-sdk/amazon-bedrock@4.0.190/packages/amazon-bedrock)

Updates `ai` from 6.0.149 to 6.0.299
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/ai@6.0.299/packages/ai/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/ai@6.0.299/packages/ai)

---
updated-dependencies:
- dependency-name: "@ai-sdk/amazon-bedrock"
  dependency-version: 4.0.172
  dependency-type: direct:production
- dependency-name: "@ai-sdk/provider-utils"
  dependency-version: 4.0.50
  dependency-type: indirect
- dependency-name: ai
  dependency-version: 6.0.277
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/samples/mastra-extended/app/multi-858b19bc51 branch from 5939a94 to 3891fec Compare October 1, 2026 02:37
@dependabot
dependabot Bot deployed to deploy-changed-samples October 1, 2026 02:37 Active

This branch was successfully deployed

1 active deployment
deploy-changed-samples — 3891fec1 Deployed Oct 1, 2026 by dependabot[bot] via deploy_changed_samples #846
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants