Skip to content

chore(deps): bump the production group across 1 directory with 15 updates - #41

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-5d0421e8f6
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-5d0421e8f6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown

Bumps the production group with 15 updates in the / directory:

Package From To
@modelcontextprotocol/server 2.0.0 2.2.0
@tanstack/react-router 1.170.32 1.170.41
@tanstack/react-start 1.168.49 1.168.60
cn 0.2.5 0.4.0
lucide-react 1.41.0 1.49.0
react 19.2.8 19.3.0
react-dom 19.2.8 19.3.0
@ff-labs/fff-bun 0.10.6 0.11.0
@huggingface/transformers 4.2.0 4.3.0
@oxlint/plugins 1.81.0 1.86.0
@types/bun 1.4.0 1.4.2
@types/node 26.4.1 26.6.4
oxfmt 0.66.0 0.71.0
oxlint 1.81.0 1.86.0
zod 4.5.4 4.6.5

Updates @modelcontextprotocol/server from 2.0.0 to 2.2.0

Release notes

Sourced from @​modelcontextprotocol/server's releases.

@​modelcontextprotocol/server-legacy@​2.2.0

Patch Changes

  • Updated dependencies [edd12e2]:
    • @​modelcontextprotocol/core@​2.2.0

@​modelcontextprotocol/server@​2.2.0

Patch Changes

  • #2885 9dd722f Thanks @​claude! - Sending a notification on a closed connection no longer produces a briefly unhandled promise rejection (seen as unhandledrejection on Cloudflare Workers) in addition to the returned rejection.

  • #2778 e3fb9ed Thanks @​vjymisal0! - Fix a stack overflow in createMcpHandler when the factory returns the same server instance for more than one request. Returning a fresh instance per request is still required.

  • #2651 c55efa6 Thanks @​sushantkumar23! - createMcpHandler now ends a subscriptions/listen stream right after the acknowledgement when it honored none of the requested notification types, instead of holding the stream open with nothing to deliver. The client receives the acknowledgement and then the resultType: "complete" result. Streams that honor at least one type are unchanged.

  • Updated dependencies [edd12e2]:

    • @​modelcontextprotocol/core@​2.2.0

@​modelcontextprotocol/server-legacy@​2.1.0

Patch Changes

  • Updated dependencies [dcc0102]:
    • @​modelcontextprotocol/core@​2.1.0

@​modelcontextprotocol/server@​2.1.0

Minor Changes

  • #1624 6032170 Thanks @​SamMorrowDrums! - Add request-time OAuth scope challenges for tools, resources, resource templates, and prompts. Each primitive's scopeChallenge callback receives the parsed request and verified authentication info, then either continues or returns the exact scope set for an insufficient_scope response. requireScopes provides a small helper for static all-of checks.

    createMcpHandler and Streamable HTTP transports return HTTP 403 with an insufficient_scope challenge before handler execution or SSE setup. The preflight is active whenever a registered primitive carries a scopeChallenge callback — there is no handler- or transport-level configuration. The challenge's WWW-Authenticate header is built by the same formatter as the bearer-auth 401/403 answers, and its resource_metadata parameter is derived from the verified AuthInfo: requireBearerAuth / verifyBearerToken now stamp their configured resourceMetadataUrl onto the AuthInfo they return (new optional AuthInfo.resourceMetadataUrl field), with a fallback to the well-known location for an HTTP(S) RFC 8707 resource identifier; the parameter is omitted when neither is available.

Patch Changes

  • #2726 6fa4227 Thanks @​LuckTerence! - SdkError and SdkHttpError accept standard ErrorOptions as an optional fourth constructor argument and forward it to Error, so a wrapped error is reachable through the standard Error.cause chain. Version-negotiation probe failures (SdkErrorCode.EraNegotiationFailed) now use it: the underlying TypeError: fetch failed and the DNS or socket error beneath it surface via error.cause, so pino, Sentry, and util.inspect render ENOTFOUND / ECONNREFUSED / ETIMEDOUT instead of stopping at the SdkError (#2657). The previous error.data.cause slot is still populated for compatibility but is deprecated and slated for removal; read error.cause instead.

  • #2654 03842cd Thanks @​pshah19! - Treat request id 0 as a real id. Two guards tested a RequestId for truthiness, so the legal JSON-RPC ids 0 and '' were read as absent. Id 0 is not a corner case: the outbound request counter is zero-based, so it is the first id every peer assigns, which on the server→client leg is the first sampling/createMessage, elicitation/create, or roots/list a server sends.

... (truncated)

Commits
  • dd22ba2 Version Packages (#2849)
  • c55efa6 fix(server): close a listen stream that has honored nothing (#2651)
  • edd12e2 fix(client): deprecate omitting expectedIssuer and apply the SEP-2352 issuer ...
  • ef39308 fix(client): follow nextCursor until it is absent; stop on a repeated page (#...
  • 9dd722f fix(core): await the notification send so a failed send is never briefly unha...
  • e780e13 fix(client): preserve _meta on input_required results (#2862)
  • a4ae2f9 docs(client): correct the registerClient deprecation citation to spec PR #285...
  • efebf5b docs(client): correct token endpoint TLS citation (#2768)
  • d992df7 chore: remove CODEOWNERS patterns that match nothing on main (#2884)
  • c0f7aec fix(client): inline jose types in the CommonJS declaration file (#2883)
  • Additional commits viewable in compare view

Updates @tanstack/react-router from 1.170.32 to 1.170.41

Release notes

Sourced from @​tanstack/react-router's releases.

@​tanstack/react-router@​1.170.41

Patch Changes

  • #8529 60b8ad1 - Compose only enabled route boundaries instead of rendering inactive wrapper components.

  • #8568 614bc27 - Update TanStack Store to 0.11.2 to prevent unrelated atom reads inside subscription observers from triggering extra notifications.

  • #8530 ff66a03 - Consolidate the root match context provider while preserving match context in the root shell.

  • #8522 863c8a7 - Reuse Link href classification and active/inactive results across location updates while preserving live history href formatting.

  • Updated dependencies [d521abd]:

    • @​tanstack/router-core@​1.171.34

@​tanstack/react-router@​1.170.40

Patch Changes

  • #8436 f5ffd38 - Skip unused Link preload cleanup when preloading is disabled and ignore queued viewport notifications after their effect has been cleaned up.

  • Updated dependencies [488d046, 0c1b5e3, 3cdd1af]:

    • @​tanstack/router-core@​1.171.33

@​tanstack/react-router@​1.170.39

Patch Changes

  • #8435 73bfc15 - Avoid hydration-triggered rerenders for links that do not compare URL hashes while preserving hash-sensitive active state and ClientOnly behavior.
Changelog

Sourced from @​tanstack/react-router's changelog.

1.170.41

Patch Changes

  • #8529 60b8ad1 - Compose only enabled route boundaries instead of rendering inactive wrapper components.

  • #8568 614bc27 - Update TanStack Store to 0.11.2 to prevent unrelated atom reads inside subscription observers from triggering extra notifications.

  • #8530 ff66a03 - Consolidate the root match context provider while preserving match context in the root shell.

  • #8522 863c8a7 - Reuse Link href classification and active/inactive results across location updates while preserving live history href formatting.

  • Updated dependencies [d521abd]:

    • @​tanstack/router-core@​1.171.34

1.170.40

Patch Changes

  • #8436 f5ffd38 - Skip unused Link preload cleanup when preloading is disabled and ignore queued viewport notifications after their effect has been cleaned up.

  • Updated dependencies [488d046, 0c1b5e3, 3cdd1af]:

    • @​tanstack/router-core@​1.171.33

1.170.39

Patch Changes

  • #8435 73bfc15 - Avoid hydration-triggered rerenders for links that do not compare URL hashes while preserving hash-sensitive active state and ClientOnly behavior.

1.170.38

Patch Changes

1.170.37

Patch Changes

  • #8418 e561fa1 - deepEqual now takes its flags as positional arguments — deepEqual(a, b, partial?, explicitUndefined?) — instead of an options object. The router's hot callers (Link option stabilization and active-state checks, matchRoute) no longer allocate an options object per comparison, and the comparator reads two booleans instead of a polymorphic object. explicitUndefined replaces ignoreUndefined: false. deepEqual is an internal helper; it stays exported for compatibility of two-argument calls.

  • #8419 a1c8d1a - resolvePath (internal helper) now takes positional arguments — resolvePath(base, to, trailingSlash?, cache?) — so buildLocation and matchRoute no longer allocate an options object per path resolution.

  • #8204 cbbfbe3 - Stream large deferred SSR hydration payloads through a backpressure-aware router transport, fail known setup errors before response creation, and close cancelled or expired transforms safely.

    Start now cancels discarded middleware and HEAD response bodies, including plain streams and derived branches.

    Server-function raw streams share one ordered response. Arbitrary or sequential consumption can require potentially unbounded buffering of unread data on the client. Cancelling one raw stream discards it locally, while aborting the whole call cancels the response and server work. Consume streams concurrently, cancel unused streams promptly, or use separate calls when independent backpressure is required. A raw stream that exceeds its unread-byte limit now fails alone; sibling streams and the JSON result keep flowing.

... (truncated)

Commits
  • 57e126e ci: Version Packages (#8531)
  • 614bc27 chore(deps): update TanStack Store to 0.11.2 (#8568)
  • 60b8ad1 perf(react-router): omit inactive route wrapper components (#8529)
  • 863c8a7 perf(react-router): reuse link selector results (#8522)
  • ff66a03 perf(react-router): consolidate root match provider (CodSpeed experiment) (#8...
  • f0e751d ci: Version Packages (#8497)
  • 763ac8b test(react-router): regression for #2072 router context invalidation (#8499)
  • f5ffd38 perf(router): skip unused link preload cleanup across adapters (#8436)
  • ddad69a ci: Version Packages (#8486)
  • 73bfc15 perf(react-router): avoid redundant link hydration updates (#8435)
  • Additional commits viewable in compare view

Updates @tanstack/react-start from 1.168.49 to 1.168.60

Release notes

Sourced from @​tanstack/react-start's releases.

@​tanstack/react-start@​1.168.60

Patch Changes

@​tanstack/react-start@​1.168.59

Patch Changes

  • Updated dependencies [f5ffd38, 488d046, e81845f, 76a7c0b]:
    • @​tanstack/react-router@​1.170.40
    • @​tanstack/start-client-core@​1.170.33
    • @​tanstack/start-server-core@​1.169.38
    • @​tanstack/start-plugin-core@​1.171.48
    • @​tanstack/react-start-client@​1.168.38
    • @​tanstack/react-start-rsc@​0.1.58
    • @​tanstack/react-start-server@​1.167.45

@​tanstack/react-start@​1.168.58

Patch Changes

  • Updated dependencies [73bfc15]:
    • @​tanstack/react-router@​1.170.39
    • @​tanstack/react-start-client@​1.168.37
    • @​tanstack/react-start-rsc@​0.1.57
    • @​tanstack/react-start-server@​1.167.44

@​tanstack/react-start@​1.168.57

Patch Changes

  • Updated dependencies [222300b]:
    • @​tanstack/start-plugin-core@​1.171.47
    • @​tanstack/react-start-rsc@​0.1.56
Changelog

Sourced from @​tanstack/react-start's changelog.

1.168.60

Patch Changes

1.168.59

Patch Changes

  • Updated dependencies [f5ffd38, 488d046, e81845f, 76a7c0b]:
    • @​tanstack/react-router@​1.170.40
    • @​tanstack/start-client-core@​1.170.33
    • @​tanstack/start-server-core@​1.169.38
    • @​tanstack/start-plugin-core@​1.171.48
    • @​tanstack/react-start-client@​1.168.38
    • @​tanstack/react-start-rsc@​0.1.58
    • @​tanstack/react-start-server@​1.167.45

1.168.58

Patch Changes

  • Updated dependencies [73bfc15]:
    • @​tanstack/react-router@​1.170.39
    • @​tanstack/react-start-client@​1.168.37
    • @​tanstack/react-start-rsc@​0.1.57
    • @​tanstack/react-start-server@​1.167.44

1.168.57

Patch Changes

  • Updated dependencies [222300b]:
    • @​tanstack/start-plugin-core@​1.171.47
    • @​tanstack/react-start-rsc@​0.1.56

1.168.56

Patch Changes

  • Updated dependencies []:
    • @​tanstack/react-router@​1.170.38

... (truncated)

Commits

Updates cn from 0.2.5 to 0.4.0

Release notes

Sourced from cn's releases.

cn@0.4.0

Minor Changes

  • #153 2691a38 Thanks @​shadcn! - cn build and the plugins now register the theme scales declared in your Tailwind CSS.

cn@0.3.3

Patch Changes

  • #152 00daa7e Thanks @​shadcn! - Calls with an interpolated argument, such as cn(base, "translate-x-[" + x + "px]"), no longer thrash the argument cache. 2,213 → 80 ns per call on that shape; stable arguments are unchanged.

  • #150 6f5ccfa Thanks @​shadcn! - cn build -o *.ts output now typechecks under noUncheckedIndexedAccess and the rest of the @tsconfig/strictest flags. The .mjs output is unchanged.

cn@0.3.2

Patch Changes

  • #147 e703bfe Thanks @​shadcn! - Custom animate-* classes are no longer merged, matching tailwind-merge. Only the default theme animations (spin, ping, pulse, bounce), animate-none, and arbitrary values share the animate group, so plugin classes such as animate-in, animate-once, and animate-duration-500 are never dropped.

cn@0.3.1

Patch Changes

  • #144 19a9a66 Thanks @​shadcn! - Axis utilities now override the logical sides they cover, matching tailwind-merge 3.7.0. px-2 replaces ps-* and pe-*, py-2 replaces pbs-* and pbe-*, and the same applies to mx/my, inset-x/inset-y, border-x/border-y widths and colors, and scroll-mx/scroll-my/scroll-px/scroll-py.

cn@0.3.0

Minor Changes

  • #137 9a9c9b5 Thanks @​shadcn! - Add cn/build, the library behind cn build. The CLI now parses arguments and prints; scanning, subsetting, compiling, and writing run in build(options) so build scripts and bundler plugins can call it directly.

  • #139 829b6e1 Thanks @​shadcn! - Add cn/vite and cn/next.

cn@0.2.6

Patch Changes

  • #74 947e624 Thanks @​shadcn! - Fix merging for custom animations, containment, legacy gradients, and missing Tailwind v4 utilities.
Changelog

Sourced from cn's changelog.

0.4.0

Minor Changes

  • #153 2691a38 Thanks @​shadcn! - cn build and the plugins now register the theme scales declared in your Tailwind CSS.

0.3.3

Patch Changes

  • #152 00daa7e Thanks @​shadcn! - Calls with an interpolated argument, such as cn(base, "translate-x-[" + x + "px]"), no longer thrash the argument cache. 2,213 → 80 ns per call on that shape; stable arguments are unchanged.

  • #150 6f5ccfa Thanks @​shadcn! - cn build -o *.ts output now typechecks under noUncheckedIndexedAccess and the rest of the @tsconfig/strictest flags. The .mjs output is unchanged.

0.3.2

Patch Changes

  • #147 e703bfe Thanks @​shadcn! - Custom animate-* classes are no longer merged, matching tailwind-merge. Only the default theme animations (spin, ping, pulse, bounce), animate-none, and arbitrary values share the animate group, so plugin classes such as animate-in, animate-once, and animate-duration-500 are never dropped.

0.3.1

Patch Changes

  • #144 19a9a66 Thanks @​shadcn! - Axis utilities now override the logical sides they cover, matching tailwind-merge 3.7.0. px-2 replaces ps-* and pe-*, py-2 replaces pbs-* and pbe-*, and the same applies to mx/my, inset-x/inset-y, border-x/border-y widths and colors, and scroll-mx/scroll-my/scroll-px/scroll-py.

0.3.0

Minor Changes

  • #137 9a9c9b5 Thanks @​shadcn! - Add cn/build, the library behind cn build. The CLI now parses arguments and prints; scanning, subsetting, compiling, and writing run in build(options) so build scripts and bundler plugins can call it directly.

  • #139 829b6e1 Thanks @​shadcn! - Add cn/vite and cn/next.

0.2.6

Patch Changes

  • #74 947e624 Thanks @​shadcn! - Fix merging for custom animations, containment, legacy gradients, and missing Tailwind v4 utilities.
Commits
  • 84db832 chore(release): version packages (#154)
  • 2691a38 feat(build): register theme scales from the Tailwind CSS entry (#153)
  • acfba70 chore(release): version packages (#151)
  • 00daa7e fix(engine): stop the arg cache thrashing on interpolated arguments (#152)
  • 6f5ccfa fix(build): typecheck .ts output under noUncheckedIndexedAccess (#150)
  • 210353b chore(release): version packages (#148)
  • e703bfe fix(config): stop merging custom animate classes (#147)
  • 8f12110 chore(release): version packages (#145)
  • 19a9a66 fix(config): override logical sides with axis utilities (#144)
  • 398d55a chore(release): version packages (#138)
  • Additional commits viewable in compare view

Updates lucide-react from 1.41.0 to 1.49.0

Release notes

Sourced from lucide-react's releases.

Version 1.49.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.48.0...1.49.0

Version 1.48.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.47.0...1.48.0

Version 1.47.0

What's Changed

... (truncated)

Commits
  • e042fec fix(packages): declare @types/react as an optional peer dependency (#4892)
  • f06ac67 chore(typchecking): More typecheck jobs for all packages (#4885)
  • 94e4cb9 chore(dependencies): Update dependencies (#4806)
  • 99d25bd feat(packages): extract icon build logic into @lucide/shared (#4409)
  • See full diff in compare view

Updates react from 19.2.8 to 19.3.0

Release notes

Sourced from react's releases.

19.3.0 (September 9, 2026)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.3 release post for more information.

New React Features

…ates

Bumps the production group with 15 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@modelcontextprotocol/server](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.2.0` |
| [@tanstack/react-router](https://github.com/TanStack/router/tree/HEAD/packages/react-router) | `1.170.32` | `1.170.41` |
| [@tanstack/react-start](https://github.com/TanStack/router/tree/HEAD/packages/react-start) | `1.168.49` | `1.168.60` |
| [cn](https://github.com/shadcn-ui/cn/tree/HEAD/packages/cn) | `0.2.5` | `0.4.0` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.41.0` | `1.49.0` |
| [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.8` | `19.3.0` |
| [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.8` | `19.3.0` |
| [@ff-labs/fff-bun](https://github.com/dmtrKovalenko/fff/tree/HEAD/packages/fff) | `0.10.6` | `0.11.0` |
| [@huggingface/transformers](https://github.com/huggingface/transformers.js) | `4.2.0` | `4.3.0` |
| [@oxlint/plugins](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint-plugins) | `1.81.0` | `1.86.0` |
| [@types/bun](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/bun) | `1.4.0` | `1.4.2` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.4.1` | `26.6.4` |
| [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.66.0` | `0.71.0` |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.81.0` | `1.86.0` |
| [zod](https://github.com/colinhacks/zod) | `4.5.4` | `4.6.5` |



Updates `@modelcontextprotocol/server` from 2.0.0 to 2.2.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/server@2.0.0...@modelcontextprotocol/server@2.2.0)

Updates `@tanstack/react-router` from 1.170.32 to 1.170.41
- [Release notes](https://github.com/TanStack/router/releases)
- [Changelog](https://github.com/TanStack/router/blob/main/packages/react-router/CHANGELOG.md)
- [Commits](https://github.com/TanStack/router/commits/@tanstack/react-router@1.170.41/packages/react-router)

Updates `@tanstack/react-start` from 1.168.49 to 1.168.60
- [Release notes](https://github.com/TanStack/router/releases)
- [Changelog](https://github.com/TanStack/router/blob/main/packages/react-start/CHANGELOG.md)
- [Commits](https://github.com/TanStack/router/commits/@tanstack/react-start@1.168.60/packages/react-start)

Updates `cn` from 0.2.5 to 0.4.0
- [Release notes](https://github.com/shadcn-ui/cn/releases)
- [Changelog](https://github.com/shadcn-ui/cn/blob/main/packages/cn/CHANGELOG.md)
- [Commits](https://github.com/shadcn-ui/cn/commits/cn@0.4.0/packages/cn)

Updates `lucide-react` from 1.41.0 to 1.49.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.49.0/packages/lucide-react)

Updates `react` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react)

Updates `react-dom` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom)

Updates `@ff-labs/fff-bun` from 0.10.6 to 0.11.0
- [Release notes](https://github.com/dmtrKovalenko/fff/releases)
- [Commits](https://github.com/dmtrKovalenko/fff/commits/v0.11.0/packages/fff)

Updates `@huggingface/transformers` from 4.2.0 to 4.3.0
- [Release notes](https://github.com/huggingface/transformers.js/releases)
- [Commits](huggingface/transformers.js@4.2.0...4.3.0)

Updates `@oxlint/plugins` from 1.81.0 to 1.86.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.86.0/npm/oxlint-plugins)

Updates `@types/bun` from 1.4.0 to 1.4.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/bun)

Updates `@types/node` from 26.4.1 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `oxfmt` from 0.66.0 to 0.71.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.71.0/npm/oxfmt)

Updates `oxlint` from 1.81.0 to 1.86.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.86.0/npm/oxlint)

Updates `zod` from 4.5.4 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.5.4...v4.6.5)

---
updated-dependencies:
- dependency-name: "@modelcontextprotocol/server"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: "@tanstack/react-router"
  dependency-version: 1.170.41
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: "@tanstack/react-start"
  dependency-version: 1.168.60
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: cn
  dependency-version: 0.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: lucide-react
  dependency-version: 1.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: react
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: react-dom
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: "@ff-labs/fff-bun"
  dependency-version: 0.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: "@huggingface/transformers"
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: "@oxlint/plugins"
  dependency-version: 1.86.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: "@types/bun"
  dependency-version: 1.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: oxfmt
  dependency-version: 0.71.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: oxlint
  dependency-version: 1.86.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 04f3879f-3253-4def-93f2-3f58f949d0e0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Benchmark comparison

main 294ff73 → PR 363be17.

7 measured rounds per revision; one discarded warm-up round. Medians ± median absolute deviation; lower is better.

Operation main PR Change Assessment
Full index (4,096 messages) 135.978 ± 7.384 ms 176.253 ± 18.240 ms 29.6% Within noise
Index unchanged files 16.323 ± 0.269 ms 16.210 ± 0.197 ms -0.7% Within noise
Index one appended session 22.440 ± 0.746 ms 22.273 ± 0.298 ms -0.7% Within noise
Index unchanged (8 sessions) 3.720 ± 0.242 ms 3.834 ± 0.044 ms 3.1% Within noise
Index unchanged (128 sessions) 39.693 ± 0.170 ms 40.371 ± 0.712 ms 1.7% Within noise
Index unchanged (2,048 sessions) 579.960 ± 3.093 ms 580.704 ± 6.375 ms 0.1% Within noise
Native grep: initialization + first query 65.990 ± 0.250 ms 66.185 ± 0.446 ms 0.3% Within noise
Native grep: warm query 8.455 ± 0.201 ms 8.341 ± 0.124 ms -1.3% Within noise
Native grep: no match 0.143 ± 0.003 ms 0.119 ± 0.004 ms -17.1% Faster
Streaming grep: plain 7.678 ± 0.145 ms 7.496 ± 0.072 ms -2.4% Within noise
Streaming grep: regex 7.412 ± 0.121 ms 7.546 ± 0.134 ms 1.8% Within noise
Streaming grep: fuzzy 7.612 ± 0.159 ms 7.588 ± 0.197 ms -0.3% Within noise
Streaming grep: no match 14.299 ± 0.397 ms 14.306 ± 0.170 ms 0.0% Within noise
FTS: open index 5.703 ± 0.004 ms 5.776 ± 0.039 ms 1.3% Within noise
FTS: reopen index per query 6.858 ± 0.052 ms 6.883 ± 0.121 ms 0.4% Within noise
Semantic build: fake engine (4,097 messages) 359.543 ± 15.011 ms 350.539 ± 10.352 ms -2.5% Within noise
Vector search: SQLite 7.263 ± 0.457 ms 6.425 ± 0.311 ms -11.5% Within noise
Vector search: SQLite, selective filter 1.791 ± 0.029 ms 2.363 ± 0.116 ms 31.9% Slower
Vector search: SQLite, selective filter (16,384 vectors) 1.965 ± 0.319 ms 2.120 ± 0.077 ms 7.9% Within noise
Vector search: cosine, selective filter 0.641 ± 0.024 ms 0.553 ± 0.062 ms -13.7% Within noise
Rank fusion (2 × 100 hits) 0.034 ± 0.004 ms 0.034 ± 0.003 ms 2.1% Within noise

A change is flagged only when it exceeds 10% and three times the larger median absolute deviation. This is a noise heuristic, not a statistical significance test. Timing changes are informational. New correctness failures and execution errors fail the job; identical assertion failures in every main and PR round remain visible without blocking the PR.

Runtime: Bun 1.4.0, linux x64, AMD EPYC 9V74 80-Core Processor. Same runner, serial execution, alternating revision order. Suite: f7f0a0530c34.

Fixtures: 32 sessions × 128 messages (~2 MiB), unchanged incremental-index proxies at 8/128/2,048 one-message sessions, 4,096 vectors × 384 dimensions, and a 16,384-vector selective-filter case. Native cold includes finder initialization; filesystem caches are not flushed. Vector retrieval excludes model loading and embedding generation.
Vector retrieval remains exact: SQL predicates reduce the distance input set and LIMIT bounds materialized results, but scalar distance still scans every filtered vector. Approximate vec0/ANN retrieval is deferred pending separate maintainer approval.

Tail latency (p95 of round averages)
Operation main p95 PR p95
Full index (4,096 messages) 230.885 ms 240.610 ms
Index unchanged files 17.103 ms 16.851 ms
Index one appended session 331.590 ms 116.082 ms
Index unchanged (8 sessions) 4.067 ms 3.902 ms
Index unchanged (128 sessions) 40.892 ms 41.677 ms
Index unchanged (2,048 sessions) 583.053 ms 593.686 ms
Native grep: initialization + first query 66.274 ms 67.188 ms
Native grep: warm query 8.773 ms 8.591 ms
Native grep: no match 0.148 ms 0.134 ms
Streaming grep: plain 7.867 ms 7.731 ms
Streaming grep: regex 7.594 ms 7.685 ms
Streaming grep: fuzzy 7.886 ms 8.031 ms
Streaming grep: no match 15.209 ms 15.162 ms
FTS: open index 5.749 ms 5.814 ms
FTS: reopen index per query 7.032 ms 7.170 ms
Semantic build: fake engine (4,097 messages) 554.687 ms 578.099 ms
Vector search: SQLite 8.512 ms 7.114 ms
Vector search: SQLite, selective filter 1.880 ms 3.216 ms
Vector search: SQLite, selective filter (16,384 vectors) 2.303 ms 2.424 ms
Vector search: cosine, selective filter 0.787 ms 0.709 ms
Rank fusion (2 × 100 hits) 0.038 ms 0.039 ms

Raw samples and per-case failures are available in the workflow artifact.

Workflow run and raw results

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants