Skip to content

build(deps): bump the npm_and_yarn group across 6 directories with 6 updates - #62

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-ee47cf3b44
Open

build(deps): bump the npm_and_yarn group across 6 directories with 6 updates#62
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-ee47cf3b44

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 19, 2026

Copy link
Copy Markdown

Bumps the npm_and_yarn group with 3 updates in the / directory: @anthropic-ai/sdk, @github/copilot and braces.
Bumps the npm_and_yarn group with 1 update in the /build/npm/gyp directory: ip-address.
Bumps the npm_and_yarn group with 1 update in the /build/rspack directory: webpack-dev-server.
Bumps the npm_and_yarn group with 1 update in the /extensions/copilot directory: @anthropic-ai/sdk.
Bumps the npm_and_yarn group with 1 update in the /extensions/copilot/test/simulation/fixtures/generate/issue-6163 directory: esbuild.
Bumps the npm_and_yarn group with 1 update in the /remote directory: @github/copilot.

Updates @anthropic-ai/sdk from 0.82.0 to 0.97.1

Release notes

Sourced from @​anthropic-ai/sdk's releases.

sdk: v0.97.1

0.97.1 (2026-05-19)

Full Changelog: sdk-v0.97.0...sdk-v0.97.1

Bug Fixes

  • runner: skip tool calls SessionToolRunner does not own (9987379)

sdk: v0.97.0

0.97.0 (2026-05-19)

Full Changelog: sdk-v0.96.0...sdk-v0.97.0

Features

  • client: Add support for self-hosted sandboxes in CMA with sandbox helpers (659a343)

Bug Fixes

  • typescript: upgrade tsc-multi so that it works with Node 26 (623f71c)

Chores

  • tests: remove redundant File import (cf821fc)

sdk: v0.96.0

0.96.0 (2026-05-13)

Full Changelog: sdk-v0.95.2...sdk-v0.96.0

Features

  • api: Add BetaManagedAgentsSearchResultBlock types (08f02f3)
  • api: Add support for cache diagnostics beta (eafbd6d)

Bug Fixes

  • zod: ensure only zod/v4 types are used (#992) (9e08bcc)

Chores

sdk: v0.95.2

0.95.2 (2026-05-11)

... (truncated)

Changelog

Sourced from @​anthropic-ai/sdk's changelog.

0.97.1 (2026-05-19)

Full Changelog: sdk-v0.97.0...sdk-v0.97.1

Bug Fixes

  • runner: skip tool calls SessionToolRunner does not own (9987379)

0.97.0 (2026-05-19)

Full Changelog: sdk-v0.96.0...sdk-v0.97.0

Features

  • client: Add support for self-hosted sandboxes in CMA with sandbox helpers (659a343)

Bug Fixes

  • typescript: upgrade tsc-multi so that it works with Node 26 (623f71c)

Chores

  • tests: remove redundant File import (cf821fc)

0.96.0 (2026-05-13)

Full Changelog: sdk-v0.95.2...sdk-v0.96.0

Features

  • api: Add BetaManagedAgentsSearchResultBlock types (08f02f3)
  • api: Add support for cache diagnostics beta (eafbd6d)

Bug Fixes

  • zod: ensure only zod/v4 types are used (#992) (9e08bcc)

Chores

0.95.2 (2026-05-11)

Full Changelog: sdk-v0.95.1...sdk-v0.95.2

0.95.1 (2026-05-07)

... (truncated)

Commits
  • ac9ece3 chore: release main
  • 1987147 fix(runner): skip tool calls SessionToolRunner does not own
  • 409ff0e chore: release main (#1052)
  • a53f60d chore: release main
  • d1b8d04 feat(api): Add support for cache diagnostics beta
  • 8e43bf8 chore(api): spec updates
  • 697e4d5 codegen metadata
  • cd5801c feat(api): Add BetaManagedAgentsSearchResultBlock types
  • dce6bc7 ci: pin GitHub Actions to commit SHAs
  • 4eee523 fix(zod): ensure only zod/v4 types are used (#992)
  • Additional commits viewable in compare view

Updates @github/copilot from 1.0.39 to 1.0.50

Release notes

Sourced from @​github/copilot's releases.

1.0.49

2026-05-18

  • postToolUse hook additionalContext is now injected as a system message for the model instead of being silently discarded
  • Mouse clicks in the prompt correctly position cursor when input contains wide characters (CJK, emoji)
  • Add /chronicle search subcommand to search all session content by keyword or topic
  • /user switch reuses the fetched user list and shows a loading spinner on first open
  • MCP servers using static OAuth clients correctly persist registration for token refreshes
  • Add support for running the CLI on Alpine Linux (musl libc)
  • Add /exit print option to print the session to the terminal before exiting
  • Add /rubber-duck command to get an independent critique of the agent's current work
  • Add /session id subcommand to display the current session ID and copy it to the clipboard
  • Add auth.redirectPort config option for MCP servers to pin the OAuth callback to a fixed port
  • Add /memory on|off|show slash command to enable, disable, or view memory status (persistent)
  • Add copilot plugin update --all to update all installed plugins at once
  • Add /rubber-duck command to invoke the rubber duck agent for an independent critique (experimental)
  • Input prompt collapses to a single line when empty and grows naturally as you type
  • File diffs are correctly reported to ACP clients for all edit tool types
  • Repo hooks in .github/hooks/ now load in prompt mode (-p) when the folder is already trusted
  • Fix extra line in timeline entries
  • Box drawing and block characters render correctly on Windows terminals not using UTF-8 code page
  • MCP server configurations with no args field are now accepted and treated as an empty args list
  • Document attachment paths are included in context so the agent can reference pasted file paths, including Windows Copy as path inputs
  • MCP stdio servers now display type as 'stdio' instead of 'local' for consistency
  • Progress bar indicator now displays correctly in tmux sessions
  • Experimental slash commands are now annotated with "(experimental)" in the help dialog and command picker
  • Auto-update downloads the smaller platform-specific package instead of the universal one when available
  • Auto-link GitHub issue and PR references (owner/repo#number) in assistant responses
  • Prompt mode (-p) automatically loads workspace MCP sources when the current folder is already trusted
  • Experimental: /mcp search command to search and install MCP servers from registry
  • Experimental: Tool search with deferred loading for MCP and external tools
  • Add "None" reasoning effort option to disable model reasoning in the reasoning effort picker
  • Add COPILOT_PLUGIN_DIR_ONLY environment variable to disable automatic plugin discovery, enabling deterministic plugin sets when using --plugin-dir
  • Copying text from the scroll view joins soft-wrapped lines without extra newlines or indentation
  • Cursor positioning in input fields works correctly with wide characters (CJK, emoji)
  • Hooks (preToolUse, postToolUse, subagentStart, subagentStop) now fire correctly for sub-agent tool calls
  • Plugins loaded via --plugin-dir now correctly register their agents as available task(agent_type=...) subagents in prompt mode
  • Memory storage correctly limits available scopes when no repository context is present
  • --plugin-dir and --additional-mcp-config now work in --server / --headless mode
  • Content-filtered model responses now display an explanation instead of a blank assistant turn
  • PromptFrame UI now renders inside tmux when the outer terminal is ghostty, WezTerm, or kitty (detected via tmux list-clients).
  • MCP OAuth token lookups are correctly scoped to the active session
  • Memory permission prompts now name who can see a stored memory: user scope or the specific owner/repo for repository scope. Timeline entries also show the scope ((for user) / (shared with repository collaborators)).
  • Reduce PowerShell syntax errors on Windows by avoiding && chaining instructions when using legacy PowerShell 5.x

1.0.49-6

Pre-release 1.0.49-6

1.0.49-1

Improved

... (truncated)

Changelog

Sourced from @​github/copilot's changelog.

1.0.49 - 2026-05-18

  • postToolUse hook additionalContext is now injected as a system message for the model instead of being silently discarded
  • Mouse clicks in the prompt correctly position cursor when input contains wide characters (CJK, emoji)
  • Add /chronicle search subcommand to search all session content by keyword or topic
  • /user switch reuses the fetched user list and shows a loading spinner on first open
  • MCP servers using static OAuth clients correctly persist registration for token refreshes
  • Add support for running the CLI on Alpine Linux (musl libc)
  • Add /exit print option to print the session to the terminal before exiting
  • Add /rubber-duck command to get an independent critique of the agent's current work
  • Add /session id subcommand to display the current session ID and copy it to the clipboard
  • Add auth.redirectPort config option for MCP servers to pin the OAuth callback to a fixed port
  • Add /memory on|off|show slash command to enable, disable, or view memory status (persistent)
  • Add copilot plugin update --all to update all installed plugins at once
  • Add /rubber-duck command to invoke the rubber duck agent for an independent critique (experimental)
  • Input prompt collapses to a single line when empty and grows naturally as you type
  • File diffs are correctly reported to ACP clients for all edit tool types
  • Repo hooks in .github/hooks/ now load in prompt mode (-p) when the folder is already trusted
  • Fix extra line in timeline entries
  • Box drawing and block characters render correctly on Windows terminals not using UTF-8 code page
  • MCP server configurations with no args field are now accepted and treated as an empty args list
  • Document attachment paths are included in context so the agent can reference pasted file paths, including Windows Copy as path inputs
  • MCP stdio servers now display type as 'stdio' instead of 'local' for consistency
  • Progress bar indicator now displays correctly in tmux sessions
  • Experimental slash commands are now annotated with "(experimental)" in the help dialog and command picker
  • Auto-update downloads the smaller platform-specific package instead of the universal one when available
  • Auto-link GitHub issue and PR references (owner/repo#number) in assistant responses
  • Prompt mode (-p) automatically loads workspace MCP sources when the current folder is already trusted
  • Experimental: /mcp search command to search and install MCP servers from registry
  • Experimental: Tool search with deferred loading for MCP and external tools
  • Add "None" reasoning effort option to disable model reasoning in the reasoning effort picker
  • Add COPILOT_PLUGIN_DIR_ONLY environment variable to disable automatic plugin discovery, enabling deterministic plugin sets when using --plugin-dir
  • Copying text from the scroll view joins soft-wrapped lines without extra newlines or indentation
  • Cursor positioning in input fields works correctly with wide characters (CJK, emoji)
  • Hooks (preToolUse, postToolUse, subagentStart, subagentStop) now fire correctly for sub-agent tool calls
  • Plugins loaded via --plugin-dir now correctly register their agents as available task(agent_type=...) subagents in prompt mode
  • Memory storage correctly limits available scopes when no repository context is present
  • --plugin-dir and --additional-mcp-config now work in --server / --headless mode
  • Content-filtered model responses now display an explanation instead of a blank assistant turn
  • PromptFrame UI now renders inside tmux when the outer terminal is ghostty, WezTerm, or kitty (detected via tmux list-clients).
  • MCP OAuth token lookups are correctly scoped to the active session
  • Memory permission prompts now name who can see a stored memory: user scope or the specific owner/repo for repository scope. Timeline entries also show the scope ((for user) / (shared with repository collaborators)).
  • Reduce PowerShell syntax errors on Windows by avoiding && chaining instructions when using legacy PowerShell 5.x

1.0.48 - 2026-05-14

  • Model picker displays actual token prices instead of dot indicators for token-based billing users
  • Instruction files with unquoted glob patterns in applyTo frontmatter (e.g. applyTo: */.ts) are now applied correctly
  • Input text with CJK characters or emoji renders without blank gaps between lines
  • /context shows correct token limits for all models instead of always showing 128k

... (truncated)

Commits

Updates braces from 2.3.2 to 3.0.3

Changelog

Sourced from braces's changelog.

Release history

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog and this project adheres to Semantic Versioning.

  • Changelogs are for humans, not machines.
  • There should be an entry for every single version.
  • The same types of changes should be grouped.
  • Versions and sections should be linkable.
  • The latest version comes first.
  • The release date of each versions is displayed.
  • Mention whether you follow Semantic Versioning.

Changelog entries are classified using the following labels (from keep-a-changelog):

  • Added for new features.
  • Changed for changes in existing functionality.
  • Deprecated for soon-to-be removed features.
  • Removed for now removed features.
  • Fixed for any bug fixes.
  • Security in case of vulnerabilities.

[3.0.0] - 2018-04-08

v3.0 is a complete refactor, resulting in a faster, smaller codebase, with fewer deps, and a more accurate parser and compiler.

Breaking Changes

  • The undocumented .makeRe method was removed
  • Require Node.js >= 8.3

Non-breaking changes

  • Caching was removed
Commits

Updates braces from 2.3.2 to 3.0.3

Changelog

Sourced from braces's changelog.

Release history

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog and this project adheres to Semantic Versioning.

  • Changelogs are for humans, not machines.
  • There should be an entry for every single version.
  • The same types of changes should be grouped.
  • Versions and sections should be linkable.
  • The latest version comes first.
  • The release date of each versions is displayed.
  • Mention whether you follow Semantic Versioning.

Changelog entries are classified using the following labels (from keep-a-changelog):

  • Added for new features.
  • Changed for changes in existing functionality.
  • Deprecated for soon-to-be removed features.
  • Removed for now removed features.
  • Fixed for any bug fixes.
  • Security in case of vulnerabilities.

[3.0.0] - 2018-04-08

v3.0 is a complete refactor, resulting in a faster, smaller codebase, with fewer deps, and a more accurate parser and compiler.

Breaking Changes

  • The undocumented .makeRe method was removed
  • Require Node.js >= 8.3

Non-breaking changes

  • Caching was removed
Commits

Updates @anthropic-ai/sdk from 0.82.0 to 0.97.1

Release notes

Sourced from @​anthropic-ai/sdk's releases.

sdk: v0.97.1

0.97.1 (2026-05-19)

Full Changelog: sdk-v0.97.0...sdk-v0.97.1

Bug Fixes

  • runner: skip tool calls SessionToolRunner does not own (9987379)

sdk: v0.97.0

0.97.0 (2026-05-19)

Full Changelog: sdk-v0.96.0...sdk-v0.97.0

Features

  • client: Add support for self-hosted sandboxes in CMA with sandbox helpers (659a343)

Bug Fixes

  • typescript: upgrade tsc-multi so that it works with Node 26 (623f71c)

Chores

  • tests: remove redundant File import (cf821fc)

sdk: v0.96.0

0.96.0 (2026-05-13)

Full Changelog: sdk-v0.95.2...sdk-v0.96.0

Features

  • api: Add BetaManagedAgentsSearchResultBlock types (08f02f3)
  • api: Add support for cache diagnostics beta (eafbd6d)

Bug Fixes

  • zod: ensure only zod/v4 types are used (#992) (9e08bcc)

Chores

sdk: v0.95.2

0.95.2 (2026-05-11)

... (truncated)

Changelog

Sourced from @​anthropic-ai/sdk's changelog.

0.97.1 (2026-05-19)

Full Changelog: sdk-v0.97.0...sdk-v0.97.1

Bug Fixes

  • runner: skip tool calls SessionToolRunner does not own (9987379)

0.97.0 (2026-05-19)

Full Changelog: sdk-v0.96.0...sdk-v0.97.0

Features

  • client: Add support for self-hosted sandboxes in CMA with sandbox helpers (659a343)

Bug Fixes

  • typescript: upgrade tsc-multi so that it works with Node 26 (623f71c)

Chores

  • tests: remove redundant File import (cf821fc)

0.96.0 (2026-05-13)

Full Changelog: sdk-v0.95.2...sdk-v0.96.0

Features

  • api: Add BetaManagedAgentsSearchResultBlock types (08f02f3)
  • api: Add support for cache diagnostics beta (eafbd6d)

Bug Fixes

  • zod: ensure only zod/v4 types are used (#992) (9e08bcc)

Chores

0.95.2 (2026-05-11)

Full Changelog: sdk-v0.95.1...sdk-v0.95.2

0.95.1 (2026-05-07)

... (truncated)

Commits
  • ac9ece3 chore: release main
  • 1987147 fix(runner): skip tool calls SessionToolRunner does not own
  • 409ff0e chore: release main (#1052)
  • a53f60d chore: release main
  • d1b8d04 feat(api): Add support for cache diagnostics beta
  • 8e43bf8 chore(api): spec updates
  • 697e4d5 codegen metadata
  • cd5801c feat(api): Add BetaManagedAgentsSearchResultBlock types
  • dce6bc7 ci: pin GitHub Actions to commit SHAs
  • 4eee523 fix(zod): ensure only zod/v4 types are used (#992)
  • Additional commits viewable in compare view

Updates @github/copilot from 1.0.39 to 1.0.50

Release notes

Sourced from @​github/copilot's releases.

1.0.49

2026-05-18

  • postToolUse hook additionalContext is now injected as a system message for the model instead of being silently discarded
  • Mouse clicks in the prompt correctly position cursor when input contains wide characters (CJK, emoji)
  • Add /chronicle search subcommand to search all session content by keyword or topic
  • /user switch reuses the fetched user list and shows a loading spinner on first open
  • MCP servers using static OAuth clients correctly persist registration for token refreshes
  • Add support for running the CLI on Alpine Linux (musl libc)
  • Add /exit print option to print the session to the terminal before exiting
  • Add /rubber-duck command to get an independent critique of the agent's current work
  • Add /session id subcommand to display the current session ID and copy it to the clipboard
  • Add auth.redirectPort config option for MCP servers to pin the OAuth callback to a fixed port
  • Add /memory on|off|show slash command to enable, disable, or view memory status (persistent)
  • Add copilot plugin update --all to update all installed plugins at once
  • Add /rubber-duck command to invoke the rubber duck agent for an independent critique (experimental)
  • Input prompt collapses to a single line when empty and grows naturally as you type
  • File diffs are correctly reported to ACP clients for all edit tool types
  • Repo hooks in .github/hooks/ now load in prompt mode (-p) when the folder is already trusted
  • Fix extra line in timeline entries
  • Box drawing and block characters render correctly on Windows terminals not using UTF-8 code page
  • MCP server configurations with no args field are now accepted and treated as an empty args list
  • Document attachment paths are included in context so the agent can reference pasted file paths, including Windows Copy as path inputs
  • MCP stdio servers now display type as 'stdio' instead of 'local' for consistency
  • Progress bar indicator now displays correctly in tmux sessions
  • Experimental slash commands are now annotated with "(experimental)" in the help dialog and command picker
  • Auto-update downloads the smaller platform-specific package instead of the universal one when available
  • Auto-link GitHub issue and PR references (owner/repo#number) in assistant responses
  • Prompt mode (-p) automatically loads workspace MCP sources when the current folder is already trusted
  • Experimental: /mcp search command to search and install MCP servers from registry
  • Experimental: Tool search with deferred loading for MCP and external tools
  • Add "None" reasoning effort option to disable model reasoning in the reasoning effort picker
  • Add COPILOT_PLUGIN_DIR_ONLY environment variable to disable automatic plugin discovery, enabling deterministic plugin sets when using --plugin-dir
  • Copying text from the scroll view joins soft-wrapped lines without extra newlines or indentation
  • Cursor positioning in input fields works correctly with wide characters (CJK, emoji)
  • Hooks (preToolUse, postToolUse, subagentStart, subagentStop) now fire correctly for sub-agent tool calls
  • Plugins loaded via --plugin-dir now correctly register their agents as available task(agent_type=...) subagents in prompt mode
  • Memory storage correctly limits available scopes when no repository context is present
  • --plugin-dir and --additional-mcp-config now work in --server / --headless mode
  • Content-filtered model responses now display an explanation instead of a blank assistant turn
  • PromptFrame UI now renders inside tmux when the outer terminal is ghostty, WezTerm, or kitty (detected via tmux list-clients).
  • MCP OAuth token lookups are correctly scoped to the active session
  • Memory permission prompts now name who can see a stored memory: user scope or the specific owner/repo for repository scope. Timeline entries also show the scope ((for user) / (shared with repository collaborators)).
  • Reduce PowerShell syntax errors on Windows by avoiding && chaining instructions when using legacy PowerShell 5.x

1.0.49-6

Pre-release 1.0.49-6

1.0.49-1

Improved

... (truncated)

Changelog

Sourced from @​github/copilot's changelog.

1.0.49 - 2026-05-18

  • postToolUse hook additionalContext is now injected as a system message for the model instead of being silently discarded
  • Mouse clicks in the prompt correctly position cursor when input contains wide characters (CJK, emoji)
  • Add /chronicle search subcommand to search all session content by keyword or topic
  • /user switch reuses the fetched user list and shows a loading spinner on first open
  • MCP servers using static OAuth clients correctly persist registration for token refreshes
  • Add support for running the CLI on Alpine Linux (musl libc)
  • Add /exit print option to print the session to the terminal before exiting
  • Add /rubber-duck command to get an independent critique of the agent's current work
  • Add /session id subcommand to display the current session ID and copy it to the clipboard
  • Add auth.redirectPort config option for MCP servers to pin the OAuth callback to a fixed port
  • Add /memory on|off|show slash command to enable, disable, or view memory status (persistent)
  • Add copilot plugin update --all to update all installed plugins at once
  • Add /rubber-duck command to invoke the rubber duck agent for an independent critique (experimental)
  • Input prompt collapses to a single line when empty and grows naturally as you type
  • File diffs are correctly reported to ACP clients for all edit tool types
  • Repo hooks in .github/hooks/ now load in prompt mode (-p) when the folder is already trusted
  • Fix extra line in timeline entries
  • Box drawing and block characters render correctly on Windows terminals not using UTF-8 code page
  • MCP server configurations with no args field are now accepted and treated as an empty args list
  • Document attachment paths are included in context so the agent can reference pasted file paths, including Windows Copy as path inputs
  • MCP stdio servers now display type as 'stdio' instead of 'local' for consistency
  • Progress bar indicator now displays correctly in tmux sessions
  • Experimental slash commands are now annotated with "(experimental)" in the help dialog and command picker
  • Auto-update downloads the smaller platform-specific package instead of the universal one when available
  • Auto-link GitHub issue and PR references (owner/repo#number) in assistant responses
  • Prompt mode (-p) automatically loads workspace MCP sources when the current folder is already trusted
  • Experimental: /mcp search command to search and install MCP servers from registry
  • Experimental: Tool search with deferred loading for MCP and external tools
  • Add "None" reasoning effort option to disable model reasoning in the reasoning effort picker
  • Add COPILOT_PLUGIN_DIR_ONLY environment variable to disable automatic plugin discovery, enabling deterministic plugin sets when using --plugin-dir
  • Copying text from the scroll view joins soft-wrapped lines without extra newlines or indentation
  • Cursor positioning in input fields works correctly with wide characters (CJK, emoji)
  • Hooks (preToolUse, postToolUse, subagentStart, subagentStop) now fire correctly for sub-agent tool calls
  • Plugins loaded via --plugin-dir now correctly register their agents as available task(agent_type=...) subagents in prompt mode
  • Memory storage correctly limits available scopes when no repository context is present
  • --plugin-dir and --additional-mcp-config now work in --server / --headless mode
  • Content-filtered model responses now display an explanation instead of a blank assistant turn
  • PromptFrame UI now renders inside tmux when the outer terminal is ghostty, WezTerm, or kitty (detected via tmux list-clients).
  • MCP OAuth token lookups are correctly scoped to the active session
  • Memory permission prompts now name who can see a stored memory: user scope or the specific owner/repo for repository scope. Timeline entries also show the scope ((for user) / (shared with repository collaborators)).
  • Reduce PowerShell syntax errors on Windows by avoiding && chaining instructions when using legacy PowerShell 5.x

1.0.48 - 2026-05-14

  • Model picker displays actual token prices instead of dot indicators for token-based billing users
  • Instruction files with unquoted glob patterns in applyTo frontmatter (e.g. applyTo: */.ts) are now applied correctly
  • Input text with CJK characters or emoji renders without blank gaps between lines
  • /context shows correct token limits for all models instead of always showing 128k

... (truncated)

Commits

Updates braces from 2.3.2 to 3.0.3

Changelog

Sourced from braces's changelog.

Release history

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog and this project adheres to Semantic Versioning.

  • Changelogs are for humans, not machines.
  • There should be an entry for every single version.
  • The same types of changes should be grouped.
  • Versions and sections should be linkable.
  • The latest version comes first.
  • The release date of each versions is displayed.
  • Mention whether you follow Semantic Versioning.

Changelog entries are classified using the following labels (from keep-a-changelog):

  • Added for new features.
  • Changed for changes in existing functionality.
  • Deprecated for soon-to-be removed features.
  • Removed for now removed features.
  • Fixed for any bug fixes.
  • Security in case of vulnerabilities.

[3.0.0] - 2018-04-08

v3.0 is a complete refactor, resulting in a faster, smaller codebase, with fewer deps, and a more accurate parser and compiler.

Breaking Changes

  • The undocumented .makeRe method was removed
  • Require Node.js >= 8.3

Non-breaking changes

  • Caching was removed
Commits

Updates @github/copilot from 1.0.39 to 1.0.50

Release notes

Sourced from @​github/copilot's releases.

1.0.49

2026-05-18

  • postToolUse hook additionalContext is now injected as a system message for the model instead of being silently discarded
  • Mouse clicks in the prompt correctly position cursor when input contains wide characters (CJK, emoji)
  • Add /chronicle search subcommand to search all session content by keyword or topic
  • /user switch reuses the fetched user list and shows a loading spinner on first open
  • MCP servers using static OAuth clients correctly persist registration for token refreshes
  • Add support for running the CLI on Alpine Linux (musl libc)
  • Add /exit print option to print the session to the terminal before exiting
  • Add /rubber-duck command to get an independent critique of the agent's current work
  • Add /session id subcommand to display the current session ID and copy it to the clipboard
  • Add auth.redirectPort config option for MCP servers to pin the OAuth callback to a fixed port
  • Add /memory on|off|show slash command to enable, disable, or view memory status (persistent)
  • Add copilot plugin update --all to update all installed plugins at once
  • Add /rubber-duck command to invoke the rubber duck agent for an independent critique (experimental)
  • Input prompt collapses to a single line when empty and grows naturally as you type
  • File diffs are correctly reported to ACP clients for all edit tool types
  • Repo hooks in .github/hooks/ now load in prompt mode (-p) when the folder is already trusted
  • Fix extra line in timeline entries
  • Box drawing and block characters render correctly on Windows terminals not using UTF-8 code page
  • MCP server configurations with no args field are now accepted and treated as an empty args list
  • Document attachment paths are included in context so the agent can reference pasted file paths, including Windows Copy as path inputs
  • MCP stdio servers now display type as 'stdio' instead of 'local' for consistency
  • Progress bar indicator now displays correctly in tmux sessions
  • Experimental slash commands are now annotated with "(experimental)" in the help dialog and command picker
  • Auto-update downloads the smaller platform-specific package instead of the universal one when available
  • Auto-link GitHub issue and PR references (owner/repo#number) in assistant responses
  • Prompt mode (-p) automatically loads workspace MCP sources when the current folder is already trusted
  • Experimental: /mcp search command to search and install MCP servers from registry
  • Experimental: Tool search with deferred loading for MCP and external tools
  • Add "None" reasoning effort option to disable model reasoning in the reasoning effort picker
  • Add COPILOT_PLUGIN_DIR_ONLY environment variable to disable automatic plugin discovery, enabling deterministic plugin sets when using --plugin-dir
  • Copying text from the scroll view joins soft-wrapped lines without extra newlines or indentation
  • Cursor positioning in input fields works correctly with wide characters (CJK, emoji)
  • Hooks (preToolUse, postToolUse, subagentStart, subagentStop) now fire correctly for sub-agent tool calls
  • Plugins loaded via --plugin-dir now correctly register their agents as available task(agent_type=...) subagents in prompt mode
  • Memory storage correctly limits available scopes when no repository context is present
  • --plugin-dir and --additional-mcp-config now work in --server / --headless mode
  • Content-filtered model responses now display an explanation instead of a blank assistant turn
  • PromptFrame UI now renders inside tmux when the outer terminal is ghostty, WezTerm, or kitty (detected via tmux list-clients).
  • MCP OAuth token lookups are correctly scoped to the active session
  • Memory permission prompts now name who can see a stored memory: user scope or the specific owner/repo for repository scope. Timeline entries also show the scope ((for user) / (shared with repository collaborators)).
  • Reduce PowerShell syntax errors on Windows by avoiding && chaining instructions when using legacy PowerShell 5.x

1.0.49-6

Pre-release 1.0.49-6

1.0.49-1

Improved

... (truncated)

Changelog

Sourced from @​github/copilot's changelog.

1.0.49 - 2026-05-18

  • postToolUse hook additionalContext is now injected as a system message for the model instead of being silently discarded
  • Mouse clicks in the prompt correctly position cursor when input contains wide characters (CJK, emoji)
  • Add /chronicle search subcommand to search all session content by keyword or topic
  • /user switch reuses the fetched user list and shows a loading spinner on first open
  • MCP servers using static OAuth clients correctly persist registration for token refreshes
  • Add support for running the CLI on Alpine Linux (musl libc)
  • Add /exit print option to print the session to the terminal before exiting
  • Add /rubber-duck command to get an independent critique of the agent's current work
  • Add /session id subcommand to display the current session ID and copy it to the clipboard
  • Add auth.redirectPort config option for MCP servers to pin the OAuth callback to a fixed port
  • Add /memory on|off|show slash command to enable, disable, or view memory status (persistent)
  • Add copilot plugin update --all to update all installed plugins at once
  • Add /rubber-duck command to invoke the rubber duck agent for an independent critique (experimental)
  • Input prompt collapses to a single line when empty and grows naturally as you type
  • File diffs are correctly reported to ACP clients for all edit tool types
  • Repo hooks in .github/hooks/ now load in prompt mode (-p) when the folder is already trusted
  • Fix extra line in timeline entries
  • Box drawing and block characters render correctly on Windows terminals not using UTF-8 code page
  • MCP server configurations with no args field are now accepted and treated as an empty args list
  • Document attachment paths are included in context so the agent can reference pasted file paths, including Windows Copy as path inputs
  • MCP stdio servers now display type as 'stdio' instead of 'local' for consistency
  • Progress bar indicator now displays correctly in tmux sessions
  • Experimental slash commands are now annotated with "(experimental)" in the help dialog and command picker
  • Auto-update downloads the smaller platform-specific package instead of the universal one when available
  • Auto-link GitHub issue and PR references (owner/repo#number) in assistant responses
  • Prompt mode (-p) automatically loads workspace MCP sources when the current folder is already trusted
  • Experimental: /mcp search command to search and install MCP servers from registry
  • Experimental: Tool search with deferred loading for MCP and external tools
  • Add "None" reasoning effort option to disable model reasoning in the reasoning effort picker
  • Add COPILOT_PLUGIN_DIR_ONLY environment variable to disable automatic plugin discovery, enabling deterministic plugin sets when using --plugin-dir
  • Copying text from the scroll view joins soft-wrapped lines without extra newlines or indentation
  • Cursor positioning in input fields works correctly with wide characters (CJK, emoji)
  • Hooks (preToolUse, postToolUse, subagentStart, subagentStop) now fire correctly for sub-agent tool calls
  • Plugins loaded via --plugin-dir now correctly register their agents as available task(agent_type=...) subagents in prompt mode
  • Memory storage correctly limits available scopes when no repository context is present
  • --plugin-dir and --additional-mcp-config now work in --server / --headless mode
  • Content-filtered model responses now display an explanation instead of a blank assistant turn
  • PromptFrame UI now renders inside tmux when the outer terminal is ghostty, WezTerm, or kitty (detected via tmux list-clients).
  • MCP OAuth token lookups are correctly scoped to the active session
  • Memory permission prompts now name who can see a stored memory: user scope or the specific owner/repo for repository scope. Timeline entries also show the scope ((for user) / (shared with repository collaborators)).
  • Reduce PowerShell syntax errors on Windows by avoiding && chaining instructions when using legacy PowerShell 5.x

1.0.48 - 2026-05-14

  • Model picker displays actual token prices instead of dot indicators for token-based billing users
  • Instruction files with unquoted glob patterns in applyTo frontmatter (e.g. applyTo: */.ts) are now applied correctly
  • Input text with CJK characters or emoji renders without blank gaps between lines
  • /context shows correct token limits for all models instead of always showing 128k

... (truncated)

Commits

Updates ip-address from 9.0.5 to 10.2.0

Commits

Updates ip-address from 9.0.5 to 10.2.0

Commits

Updates ip-address from 9.0.5 to 10.2.0

Commits

Updates ip-address from 9.0.5 to 10.2.0

Commits

Removes webpack-dev-server

Updates @anthropic-ai/sdk from 0.82.0 to 0.97.1

Release notes

Sourced from @​anthropic-ai/sdk's releases.

sdk: v0.97.1

0.97.1 (2026-05-19)

Full Changelog: sdk-v0.97.0...sdk-v0.97.1

Bug Fixes

  • runner: skip tool calls SessionToolRunner does not own (9987379)

sdk: v0.97.0

0.97.0 (2026-05-19)

Full Changelog: sdk-v0.96.0...sdk-v0.97.0

Features

  • client: Add support for self-hosted sandboxes in CMA with sandbox helpers (659a343)

Bug Fixes

  • typescript: upgrade tsc-multi so that it works with Node 26 (623f71c)

Chores

  • tests: remove redundant File import (cf821fc)

sdk: v0.96.0

0.96.0 (2026-05-13)

Full Changelog: sdk-v0.95.2...sdk-v0.96.0

Features

  • api: Add BetaManagedAgentsSearchResultBlock types (08f02f3)
  • api: Add support for cache diagnostics beta (eafbd6d)

Bug Fixes

  • zod: ensure only zod/v4 types are used (#992) (9e08bcc)

Chores

sdk: v0.95.2

0.95.2 (2026-05-11)

... (truncated)

Changelog

Sourced from @​anthropic-ai/sdk's changelog.

0.97.1 (2026-05-19)

Full Changelog: sdk-v0.97.0...sdk-v0.97.1

Bug Fixes

  • runner: skip tool calls SessionToolRunner does not own (9987379)

0.97.0 (2026-05-19)

Full Changelog: sdk-v0.96.0...sdk-v0.97.0

Features

  • client: Add support for self-hosted sandboxes in CMA with sandbox helpers (659a343)

Bug Fixes

  • typescript: upgrade tsc-multi so that it works with Node 26 (623f71c)

Chores

  • tests: remove redundant File import (cf821fc)

0.96.0 (2026-05-13)

Full Changelog: sdk-v0.95.2...sdk-v0.96.0

Features

  • api: Add BetaManagedAgentsSearchResultBlock types (08f02f3)
  • api: Add support for cache diagnostics beta (eafbd6d)

Bug Fixes

  • zod: ensure only zod/v4 types are used (#992) (9e08bcc)

Chores

0.95.2 (2026-05-11)

Full Changelog: sdk-v0.95.1...sdk-v0.95.2

0.95.1 (2026-05-07)

... (truncated)

Commits
  • ac9ece3 chore: release main
  • 1987147 fix(runner): skip tool calls SessionToolRunner does not own
  • 409ff0e chore: release main (#1052)
  • a53f60d chore: release main
  • d1b8d04 feat(api): Add support for cache diagnostics beta
  • 8e43bf8 chore(api): spec updates
  • 697e4d5 codegen metadata
  • cd5801c feat(api): Add BetaManagedAgentsSearchResultBlock types
  • dce6bc7 ci: pin GitHub Actions to commit SHAs
  • 4eee523 fix(zod): ensure only zod/v4 types are used (#992)
  • Additional commits viewable in compare view

Updates @anthropic-ai/sdk from 0.82.0 to 0.97.1

Release notes

Sourced from @​anthropic-ai/sdk's releases.

sdk: v0.97.1

0.97.1 (2026-05-19)

Full Changelog: sdk-v0.97.0...sdk-v0.97.1

Bug Fixes

  • runner: skip tool calls SessionToolRunner does not own (9987379)

sdk: v0.97.0

0.97.0 (2026-05-19)

Full Changelog: sdk-v0.96.0...sdk-v0.97.0

Features

  • client: Add support for self-hosted sandboxes in CMA with sandbox helpers (659a343)

Bug Fixes

  • typescript: upgrade tsc-multi so that it works with Node 26 (623f71c)

Chores

  • tests: remove redundant File import (cf821fc)

sdk: v0.96.0

0.96.0 (2026-05-13)

Full Changelog: sdk-v0.95.2...sdk-v0.96.0

Features

  • api: Add BetaManagedAgentsSearchResultBlock types (08f02f3)
  • api: Add support for cache diagnostics beta (eafbd6d)

Bug Fixes

  • zod: ensure only zod/v4 types are used (#992) (9e08bcc)

Chores

  • api:Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 19, 2026
…updates

Bumps the npm_and_yarn group with 3 updates in the / directory: [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript), [@github/copilot](https://github.com/github/copilot-cli) and [braces](https://github.com/micromatch/braces).
Bumps the npm_and_yarn group with 1 update in the /build/npm/gyp directory: [ip-address](https://github.com/beaugunderson/ip-address).
Bumps the npm_and_yarn group with 1 update in the /build/rspack directory: [webpack-dev-server](https://github.com/webpack/webpack-dev-server).
Bumps the npm_and_yarn group with 1 update in the /extensions/copilot directory: [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript).
Bumps the npm_and_yarn group with 1 update in the /extensions/copilot/test/simulation/fixtures/generate/issue-6163 directory: [esbuild](https://github.com/evanw/esbuild).
Bumps the npm_and_yarn group with 1 update in the /remote directory: [@github/copilot](https://github.com/github/copilot-cli).


Updates `@anthropic-ai/sdk` from 0.82.0 to 0.97.1
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.82.0...sdk-v0.97.1)

Updates `@github/copilot` from 1.0.39 to 1.0.50
- [Release notes](https://github.com/github/copilot-cli/releases)
- [Changelog](https://github.com/github/copilot-cli/blob/main/changelog.md)
- [Commits](https://github.com/github/copilot-cli/commits)

Updates `braces` from 2.3.2 to 3.0.3
- [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md)
- [Commits](https://github.com/micromatch/braces/commits/3.0.3)

Updates `braces` from 2.3.2 to 3.0.3
- [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md)
- [Commits](https://github.com/micromatch/braces/commits/3.0.3)

Updates `@anthropic-ai/sdk` from 0.82.0 to 0.97.1
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.82.0...sdk-v0.97.1)

Updates `@github/copilot` from 1.0.39 to 1.0.50
- [Release notes](https://github.com/github/copilot-cli/releases)
- [Changelog](https://github.com/github/copilot-cli/blob/main/changelog.md)
- [Commits](https://github.com/github/copilot-cli/commits)

Updates `braces` from 2.3.2 to 3.0.3
- [Changelog](https://github.com/micromatch/braces/blob/master/CHANGELOG.md)
- [Commits](https://github.com/micromatch/braces/commits/3.0.3)

Updates `@github/copilot` from 1.0.39 to 1.0.50
- [Release notes](https://github.com/github/copilot-cli/releases)
- [Changelog](https://github.com/github/copilot-cli/blob/main/changelog.md)
- [Commits](https://github.com/github/copilot-cli/commits)

Updates `ip-address` from 9.0.5 to 10.2.0
- [Commits](https://github.com/beaugunderson/ip-address/commits)

Updates `ip-address` from 9.0.5 to 10.2.0
- [Commits](https://github.com/beaugunderson/ip-address/commits)

Updates `ip-address` from 9.0.5 to 10.2.0
- [Commits](https://github.com/beaugunderson/ip-address/commits)

Updates `ip-address` from 9.0.5 to 10.2.0
- [Commits](https://github.com/beaugunderson/ip-address/commits)

Removes `webpack-dev-server`

Updates `@anthropic-ai/sdk` from 0.82.0 to 0.97.1
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.82.0...sdk-v0.97.1)

Updates `@anthropic-ai/sdk` from 0.82.0 to 0.97.1
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.82.0...sdk-v0.97.1)

Updates `esbuild` from 0.21.5 to 0.28.0
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2024.md)
- [Commits](evanw/esbuild@v0.21.5...v0.28.0)

Updates `@github/copilot` from 1.0.39 to 1.0.50
- [Release notes](https://github.com/github/copilot-cli/releases)
- [Changelog](https://github.com/github/copilot-cli/blob/main/changelog.md)
- [Commits](https://github.com/github/copilot-cli/commits)

Updates `@github/copilot` from 1.0.39 to 1.0.50
- [Release notes](https://github.com/github/copilot-cli/releases)
- [Changelog](https://github.com/github/copilot-cli/blob/main/changelog.md)
- [Commits](https://github.com/github/copilot-cli/commits)

Updates `@github/copilot` from 1.0.39 to 1.0.50
- [Release notes](https://github.com/github/copilot-cli/releases)
- [Changelog](https://github.com/github/copilot-cli/blob/main/changelog.md)
- [Commits](https://github.com/github/copilot-cli/commits)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.97.1
  dependency-type: direct:production
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.97.1
  dependency-type: direct:production
- dependency-name: "@github/copilot"
  dependency-version: 1.0.50
  dependency-type: direct:production
- dependency-name: "@github/copilot"
  dependency-version: 1.0.50
  dependency-type: direct:production
- dependency-name: braces
  dependency-version: 3.0.3
  dependency-type: indirect
- dependency-name: esbuild
  dependency-version: 0.28.0
  dependency-type: direct:production
- dependency-name: ip-address
  dependency-version: 10.2.0
  dependency-type: indirect
- dependency-name: webpack-dev-server
  dependency-version:
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump the npm_and_yarn group across 6 directories with 6 updates build(deps): bump the npm_and_yarn group across 6 directories with 6 updates May 20, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm_and_yarn-ee47cf3b44 branch from 283bcc2 to 0568812 Compare May 20, 2026 09:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants