Skip to content

chore: bump ai sdk family, ws, and @types/node - #261

Merged
ThomasK33 merged 1 commit into
mainfrom
deps-batch-sep28
Sep 28, 2026
Merged

ThomasK33 merged 1 commit into
mainfrom
deps-batch-sep28

Conversation

@ThomasK33

Copy link
Copy Markdown
Member

Summary

Refresh the AI SDK family, ws, and @types/node to the newest versions that met the strict 24-hour npm publish-age rule at the bump. Only five package manifests and the pnpm lockfile change.

  • npm publish timestamps fetched at 2026-09-28T06:25:22Z; manifests bumped immediately afterwards. All 8 added lockfile versions were ≥24.29 hours old at the lockfile audit (2026-09-28T06:26:40Z). The AI SDK releases were published 2026-09-27T06:08–06:09Z, so each was checked to the second.
  • @ai-sdk/provider stays 4.0.18 everywhere (one version in the lockfile; it is still the latest published 4.x), matching the published @coder/ai-sdk-provider 0.4.24 and @coder/ai-sdk-agent 0.12.2 that packages/effect consumes. @ai-sdk/anthropic 4.0.65, @ai-sdk/openai-compatible 3.0.57, and @ai-sdk/provider-utils 5.0.49 are already the latest on their majors.
  • Transitive @ai-sdk/gateway moves 4.0.94 → 4.0.96 (from ai 7.0.118). @ai-sdk/mcp stays 2.0.60, the latest 2.x.
  • Effect's published Coder pins, effect and @effect/ai are unchanged.
  • No published peer ranges, engine floors, source, tests, examples, READMEs, changelogs, toolchain files, pnpm-workspace.yaml, or GitHub Action pins change.

Runtime dependency ranges (published packages)

Package dependencies change devDependencies change
@coder/ai-sdk-agent ws ^8.21.3 → ^8.22.0 ai, @ai-sdk/react, @types/node
@coder/ai-sdk-sandbox ws ^8.21.3 → ^8.22.0 @ai-sdk/harness, @ai-sdk/harness-claude-code, @ai-sdk/tui, @types/node
@coder/ai-sdk-provider none ai, @types/node

The private packages change too: @coder/release-please-ai (ai in dependencies, @types/node) and @coder/ai-sdk-effect (dev only: ai, @ai-sdk/harness, @types/node).

ws 8.22.0 review

ws 8.22.0 adds a protocols constructor option and fixes close(): invalid arguments no longer move the socket to CLOSING before the error is thrown. I read the full published diff (lib/websocket.js only). Neither change affects our code (verified against source):

  • packages/agent/src/coder/ws.ts constructs new WebSocket(url, { headers }) with no protocols key, so the subprotocol list is still empty. Every close() call passes the valid code 1000. The stream, replay, and redial invariants are untouched.
  • packages/sandbox/src/native-relay.ts does not use protocols. Its only close(code, reason) call is inside try { … } catch { terminate() }. terminate() works from OPEN as well as CLOSING, so the new behaviour on invalid arguments still ends in a terminated socket.

Versions

Package Old New Scope
ai 7.0.116 7.0.118 Dev dependency (agent, provider, effect); dependency of private release-please-ai
@ai-sdk/harness 1.0.126 1.0.128 Dev dependency (sandbox, effect)
@ai-sdk/harness-claude-code 1.0.130 1.0.132 Dev dependency (sandbox)
@ai-sdk/react 4.0.119 4.0.121 Dev dependency (exact pin, agent)
@ai-sdk/tui 1.0.117 1.0.119 Dev dependency (sandbox)
ws 8.21.3 8.22.0 Runtime dependency (agent, sandbox)
@types/node 26.6.2 26.6.3 Dev dependency
@ai-sdk/gateway 4.0.94 4.0.96 Transitive (from ai 7.0.118)
Adopted version npm published at (UTC)
ai@7.0.118 2026-09-27T06:08:49.678Z
@ai-sdk/harness@1.0.128 2026-09-27T06:09:18.414Z
@ai-sdk/harness-claude-code@1.0.132 2026-09-27T06:09:19.085Z
@ai-sdk/react@4.0.121 2026-09-27T06:09:29.740Z
@ai-sdk/tui@1.0.119 2026-09-27T06:09:33.119Z
@ai-sdk/gateway@4.0.96 2026-09-27T06:09:19.296Z
ws@8.22.0 2026-09-26T15:00:57.748Z
@types/node@26.6.3 2026-09-25T22:06:16.779Z

Deferred: younger than 24 hours at the bump

None. Each adopted version is the newest published on its tracked major line.

Out of scope and unchanged: TypeScript 7 (tracking issue #99), pnpm 12 (tracking issue #176), Node/mise toolchain, GitHub Actions, published peer ranges, and the engines.node floors. Recheck at the next daily dependency sweep.

Validation

All gates ran with an explicit PATH to the mise Node; node --version inside pnpm exec and every pnpm -r exec workspace reported v26.10.0.

Gate Final local result
Age-guarded install (temporary minimumReleaseAge: 1440, exclusions only for the unchanged @coder/* pins) and pnpm dedupe Passed; temporary pnpm-workspace.yaml edit restored, not committed
Frozen-lockfile reinstall, empty store and cache (repository config) Passed; lockfile unchanged
Every added lockfile package age Passed, 8 package versions; minimum age 24.29 h at audit
pnpm check Passed: formatting, lint, typecheck
pnpm -r build Passed
pnpm -r test 678 passed across 32 test files
pnpm publint Passed
pnpm attw Passed
coder whoami Authenticated with ambient credentials on dogfood.cdr.dev (v2.37.3-devel+4851c7b60c)
cd packages/agent && npx vitest run test/e2e 7/7 passed, final dependency graph, 42.24 s (first run), including the single-WebSocket multi-step turn test
cd packages/effect && npx vitest run test/e2e 2/2 passed, final dependency graph, 9.10 s (first run)

Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high

Refresh the AI SDK family, ws, and @types/node to the newest versions
that are at least 24 hours old on npm. @ai-sdk/provider stays 4.0.18.

- ai 7.0.116 -> 7.0.118
- @ai-sdk/harness 1.0.126 -> 1.0.128
- @ai-sdk/harness-claude-code 1.0.130 -> 1.0.132
- @ai-sdk/react 4.0.119 -> 4.0.121 (exact pin)
- @ai-sdk/tui 1.0.117 -> 1.0.119
- ws ^8.21.3 -> ^8.22.0 (runtime dependency of agent and sandbox)
- @types/node 26.6.2 -> 26.6.3
- transitive @ai-sdk/gateway 4.0.94 -> 4.0.96

Signed-off-by: Thomas Kosiewski <tk@coder.com>

---
_Generated with [`xum`](https://github.com/coder/xum) • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_

Change-Id: I2f3cd2d2f021cad5f1e391558eaf92966f92c86b
@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@ThomasK33

Copy link
Copy Markdown
Member Author

@codex security review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T06:31:55.785263Z 9e91d01 Manual request
🔒 Security Review ✅ Completed 2026-09-28T06:34:46.158763Z 9e91d01 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Delightful!

Reviewed commit: 9e91d01a41

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review

Security review completed. No security issues were found in this pull request.

Reviewed commit: 9e91d01a41

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@ThomasK33
ThomasK33 added this pull request to the merge queue Sep 28, 2026
Merged via the queue into main with commit 1ba0e0e Sep 28, 2026
6 checks passed
@ThomasK33
ThomasK33 deleted the deps-batch-sep28 branch September 28, 2026 06:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant