Skip to content

chore(deps)(deps): bump @ai-sdk/provider-utils, @ai-sdk/groq, @ai-sdk/react and ai - #259

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-c243fa15e4
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-c243fa15e4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @ai-sdk/provider-utils to 4.0.56 and updates ancestor dependencies @ai-sdk/provider-utils, @ai-sdk/groq, @ai-sdk/react and ai. These dependencies need to be updated together.

Updates @ai-sdk/provider-utils from 4.0.30 to 4.0.56

Release notes

Sourced from @​ai-sdk/provider-utils's releases.

@​ai-sdk/provider-utils@​4.0.56

Patch Changes

  • 29dc427: fix(provider-utils): preserve streamed tool calls with unreliable IDs and indices
Changelog

Sourced from @​ai-sdk/provider-utils's changelog.

4.0.56

Patch Changes

  • 29dc427: fix(provider-utils): preserve streamed tool calls with unreliable IDs and indices

4.0.55

Patch Changes

  • 3983fea: fix(provider): preserve media types on tool result file URLs and match full MIME types exactly when checking native URL support.
  • Updated dependencies [3983fea]
    • @​ai-sdk/provider@​3.0.18

4.0.54

Patch Changes

  • 069a945: Fix Google embedMany calls with more than 100 values by keeping per-value multimodal content aligned across automatic batches, including text-only entries. Validate content length before sending requests and validate each batch's provider options after middleware transforms them.

  • d1a36d2: fix(ai): execute manually approved tool inputs produced by schema transforms

    Preserve approved inputs during revalidation and reject histories whose reconstructed schema output differs, including signed approvals with missing original input. Validate transformed UI tool inputs against the reconstructed output before returning them as static tool parts.

  • f7f36d2: chore: enable dead code lint rules

4.0.53

Patch Changes

  • Updated dependencies [da2e17b]
    • @​ai-sdk/provider@​3.0.17

4.0.52

Patch Changes

  • 82e18b0: fix(provider-utils): avoid excessive memory usage when base64 encoding byte arrays

4.0.51

Patch Changes

  • Updated dependencies [1a4dbb1]
    • @​ai-sdk/provider@​3.0.16

4.0.50

Patch Changes

  • cc23556: Mark transient network errors that occur while reading successful response bodies as retryable.

... (truncated)

Commits
  • fc81a9e Version Packages (#21573)
  • 29dc427 [v6.0] fix: preserve streamed tool calls when gateway IDs or indices are unre...
  • 5da12f6 Version Packages (#21513)
  • 3983fea [v6.0] fix: forward Google Vertex GCS tool-result files as function response ...
  • ba213ad Version Packages (#21368)
  • d1a36d2 [v6.0] fix: manual tool approvals reject or mutate transformed inputs across ...
  • 069a945 [v6.0] fix: preserve Google embedMany content alignment across automatic batc...
  • f7f36d2 [v6] chore: enable dead code lint rules (#21395)
  • 82d20f8 Version Packages (#21308)
  • 5d69aa4 Version Packages (#21168)
  • Additional commits viewable in compare view

Updates @ai-sdk/groq from 3.0.42 to 3.0.71

Release notes

Sourced from @​ai-sdk/groq's releases.

@​ai-sdk/togetherai@​3.0.60

Patch Changes

  • c2511c1: fix: use standards-compliant User-Agent header
  • Updated dependencies [c2511c1]
    • @​ai-sdk/openai-compatible@​3.0.59
    • @​ai-sdk/provider-utils@​5.0.51

@​ai-sdk/togetherai@​3.0.59

Patch Changes

  • 525efc5: feat(provider): advertise image model file and mask input support

    Use confirmed model IDs for capability declarations so unrecognized model names remain unknown. Include Together AI FLUX.2 Pro and Flex single-image editing, and allow asynchronous capability lookups and middleware overrides to resolve to unknown.

    Advertise QuiverAI Arrow 2 and Arrow 2 Telos file-input support, and mark Together AI Gemini image inputs unsupported by the current single-image request mapping.

  • Updated dependencies [e3605f6]

  • Updated dependencies [525efc5]

    • @​ai-sdk/provider-utils@​5.0.50
    • @​ai-sdk/openai-compatible@​3.0.58
    • @​ai-sdk/provider@​4.0.19

@​ai-sdk/replicate@​3.0.52

Patch Changes

  • c2511c1: fix: use standards-compliant User-Agent header
  • Updated dependencies [c2511c1]
    • @​ai-sdk/provider-utils@​5.0.51

@​ai-sdk/replicate@​3.0.51

Patch Changes

  • 525efc5: feat(provider): advertise image model file and mask input support

    Use confirmed model IDs for capability declarations so unrecognized model names remain unknown. Include Together AI FLUX.2 Pro and Flex single-image editing, and allow asynchronous capability lookups and middleware overrides to resolve to unknown.

    Advertise QuiverAI Arrow 2 and Arrow 2 Telos file-input support, and mark Together AI Gemini image inputs unsupported by the current single-image request mapping.

  • Updated dependencies [e3605f6]

  • Updated dependencies [525efc5]

    • @​ai-sdk/provider-utils@​5.0.50

... (truncated)

Changelog

Sourced from @​ai-sdk/groq's changelog.

3.0.71

Patch Changes

  • Updated dependencies [29dc427]
    • @​ai-sdk/provider-utils@​4.0.56

3.0.70

Patch Changes

  • Updated dependencies [3983fea]
    • @​ai-sdk/provider@​3.0.18
    • @​ai-sdk/provider-utils@​4.0.55

3.0.69

Patch Changes

  • f7f36d2: chore: enable dead code lint rules
  • Updated dependencies [069a945]
  • Updated dependencies [d1a36d2]
  • Updated dependencies [f7f36d2]
    • @​ai-sdk/provider-utils@​4.0.54

3.0.68

Patch Changes

  • Updated dependencies [da2e17b]
    • @​ai-sdk/provider@​3.0.17
    • @​ai-sdk/provider-utils@​4.0.53

3.0.67

Patch Changes

  • Updated dependencies [82e18b0]
    • @​ai-sdk/provider-utils@​4.0.52

3.0.66

Patch Changes

  • 4bd2599: fix(deepseek): preserve reasoning streams across empty tool-call deltas

3.0.65

Patch Changes

... (truncated)

Commits

Updates @ai-sdk/react from 3.0.210 to 3.0.299

Release notes

Sourced from @​ai-sdk/react's releases.

@​ai-sdk/react@​3.0.299

Patch Changes

  • Updated dependencies [0741da8]
  • Updated dependencies [a63fa9b]
  • Updated dependencies [a61bea9]
    • ai@6.0.296

@​ai-sdk/react@​3.0.298

Patch Changes

  • Updated dependencies [0b38b6b]
    • ai@6.0.295

@​ai-sdk/react@​3.0.297

Patch Changes

  • Updated dependencies [16a04d7]
  • Updated dependencies [29dc427]
    • ai@6.0.294
    • @​ai-sdk/provider-utils@​4.0.56
Changelog

Sourced from @​ai-sdk/react's changelog.

3.0.299

Patch Changes

  • Updated dependencies [0741da8]
  • Updated dependencies [a63fa9b]
  • Updated dependencies [a61bea9]
    • ai@6.0.296

3.0.298

Patch Changes

  • Updated dependencies [0b38b6b]
    • ai@6.0.295

3.0.297

Patch Changes

  • Updated dependencies [16a04d7]
  • Updated dependencies [29dc427]
    • ai@6.0.294
    • @​ai-sdk/provider-utils@​4.0.56

3.0.296

Patch Changes

  • Updated dependencies [3983fea]
    • ai@6.0.293
    • @​ai-sdk/provider-utils@​4.0.55

3.0.295

Patch Changes

  • ai@6.0.292

3.0.294

Patch Changes

  • ai@6.0.291

3.0.293

Patch Changes

  • da8b37a: fix(react): preserve active useObject cancellation state during overlapping requests

... (truncated)

Commits

Updates ai from 6.0.208 to 6.0.296

Release notes

Sourced from ai's releases.

ai@6.0.296

Patch Changes

  • 0741da8: fix(ai): allow agent UI streams to use original messages as input
  • a63fa9b: fix(ai): preserve tool metadata from tool output chunks
  • a61bea9: Preserve provider metadata on corresponding smoothStream chunks without carrying it into subsequent metadata-free deltas.

ai@6.0.295

Patch Changes

  • 0b38b6b: fix(ai): continue active UI message parts when resuming after a disconnect
  • Updated dependencies [358683e]
    • @​ai-sdk/gateway@​3.0.205

ai@6.0.294

Patch Changes

  • 16a04d7: fix(ai): cancel response streams when clients disconnect
  • Updated dependencies [29dc427]
    • @​ai-sdk/provider-utils@​4.0.56
    • @​ai-sdk/gateway@​3.0.204
Changelog

Sourced from ai's changelog.

6.0.296

Patch Changes

  • 0741da8: fix(ai): allow agent UI streams to use original messages as input
  • a63fa9b: fix(ai): preserve tool metadata from tool output chunks
  • a61bea9: Preserve provider metadata on corresponding smoothStream chunks without carrying it into subsequent metadata-free deltas.

6.0.295

Patch Changes

  • 0b38b6b: fix(ai): continue active UI message parts when resuming after a disconnect
  • Updated dependencies [358683e]
    • @​ai-sdk/gateway@​3.0.205

6.0.294

Patch Changes

  • 16a04d7: fix(ai): cancel response streams when clients disconnect
  • Updated dependencies [29dc427]
    • @​ai-sdk/provider-utils@​4.0.56
    • @​ai-sdk/gateway@​3.0.204

6.0.293

Patch Changes

  • 3983fea: fix(provider): preserve media types on tool result file URLs and match full MIME types exactly when checking native URL support.
  • Updated dependencies [3983fea]
    • @​ai-sdk/provider@​3.0.18
    • @​ai-sdk/provider-utils@​4.0.55
    • @​ai-sdk/gateway@​3.0.203

6.0.292

Patch Changes

  • Updated dependencies [2cf7cb4]
  • Updated dependencies [af4a3e4]
    • @​ai-sdk/gateway@​3.0.202

6.0.291

Patch Changes

  • Updated dependencies [1915a6f]
    • @​ai-sdk/gateway@​3.0.201

... (truncated)

Commits
  • d4f6c23 Version Packages (#21641)
  • a61bea9 [v6.0] fix: preserve smoothStream provider metadata without loss or cross-del...
  • a63fa9b [v6.0] fix: preserve tool metadata from tool output chunks in UI message stre...
  • 0741da8 [v6.0] fix: allow agent UI streams to run persistence flows with only origina...
  • e1b3faa Version Packages (#21630)
  • 0b38b6b [v6.0] fix: resumeStream fails to continue active UI message parts after a di...
  • fc81a9e Version Packages (#21573)
  • 16a04d7 [v6.0] fix: settle response stream pipes and cancel their sources after clien...
  • 5da12f6 Version Packages (#21513)
  • 3983fea [v6.0] fix: forward Google Vertex GCS tool-result files as function response ...
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Dependency updates and maintenance javascript Pull requests that update javascript code patch Patch-level change labels Sep 8, 2026
@github-actions

github-actions Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/@ai-sdk/gateway 3.0.205 UnknownUnknown
npm/@ai-sdk/groq 3.0.71 UnknownUnknown
npm/@ai-sdk/provider 3.0.18 UnknownUnknown
npm/@ai-sdk/provider-utils 4.0.56 UnknownUnknown
npm/@ai-sdk/react 3.0.299 UnknownUnknown
npm/ai 6.0.296 UnknownUnknown
npm/undici 6.29.0 🟢 8.1
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 12 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Dependency-Update-Tool🟢 10update tool detected
Code-Review🟢 10all changesets reviewed
Security-Policy🟢 10security policy file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 8binaries present in source code
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 6dependency not pinned by hash detected -- score normalized to 6
SAST🟢 9SAST tool detected but not run on all commits
Vulnerabilities🟢 64 existing vulnerabilities detected
License🟢 10license file detected
Packaging🟢 10packaging workflow detected
Fuzzing🟢 10project is fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
CI-Tests🟢 1030 out of 30 merged PRs checked by a CI test -- score normalized to 10
Contributors🟢 10project has 58 contributing companies or organizations

Scanned Files

  • package-lock.json

…/react and ai

Bumps [@ai-sdk/provider-utils](https://github.com/vercel/ai/tree/HEAD/packages/provider-utils) to 4.0.56 and updates ancestor dependencies [@ai-sdk/provider-utils](https://github.com/vercel/ai/tree/HEAD/packages/provider-utils), [@ai-sdk/groq](https://github.com/vercel/ai/tree/HEAD/packages/groq), [@ai-sdk/react](https://github.com/vercel/ai/tree/HEAD/packages/react) and [ai](https://github.com/vercel/ai/tree/HEAD/packages/ai). These dependencies need to be updated together.


Updates `@ai-sdk/provider-utils` from 4.0.30 to 4.0.56
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/@ai-sdk/provider-utils@4.0.56/packages/provider-utils/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/@ai-sdk/provider-utils@4.0.56/packages/provider-utils)

Updates `@ai-sdk/groq` from 3.0.42 to 3.0.71
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/@ai-sdk/groq@3.0.71/packages/groq/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/@ai-sdk/groq@3.0.71/packages/groq)

Updates `@ai-sdk/react` from 3.0.210 to 3.0.299
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/@ai-sdk/react@3.0.299/packages/react/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/@ai-sdk/react@3.0.299/packages/react)

Updates `ai` from 6.0.208 to 6.0.296
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/ai@6.0.296/packages/ai/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/ai@6.0.296/packages/ai)

---
updated-dependencies:
- dependency-name: "@ai-sdk/groq"
  dependency-version: 3.0.64
  dependency-type: direct:production
- dependency-name: "@ai-sdk/provider-utils"
  dependency-version: 4.0.50
  dependency-type: indirect
- dependency-name: "@ai-sdk/react"
  dependency-version: 3.0.280
  dependency-type: direct:production
- dependency-name: ai
  dependency-version: 6.0.277
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-c243fa15e4 branch from 97d7c60 to bba36ae Compare September 29, 2026 08:01
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: f6d75e30-fd60-4f6e-93e1-e4f2922bf55e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates and maintenance javascript Pull requests that update javascript code patch Patch-level change

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant