Skip to content

build(deps): bump @ai-sdk/react from 3.0.201 to 4.0.34#253

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/ai-sdk/react-3.0.210
Open

build(deps): bump @ai-sdk/react from 3.0.201 to 4.0.34#253
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/ai-sdk/react-3.0.210

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 29, 2026

Copy link
Copy Markdown
Contributor

Bumps @ai-sdk/react from 3.0.201 to 4.0.34.

Release notes

Sourced from @​ai-sdk/react's releases.

@​ai-sdk/react@​3.0.237

Patch Changes

  • ai@6.0.235
Changelog

Sourced from @​ai-sdk/react's changelog.

4.0.34

Patch Changes

  • Updated dependencies [70f18c3]
  • Updated dependencies [cd06458]
  • Updated dependencies [d84ea43]
    • ai@7.0.31
    • @​ai-sdk/provider-utils@​5.0.11
    • @​ai-sdk/mcp@​2.0.15

4.0.33

Patch Changes

  • ai@7.0.30

4.0.32

Patch Changes

  • ai@7.0.29

4.0.31

Patch Changes

  • 48e7e78: Harden MCP Apps handling of server-supplied resource metadata and the host/iframe bridge:

    • Runtime-validate _meta.ui and drop malformed or non-string fields.
    • Gate iframe permissions deny-by-default via a new sandbox.allowedPermissions allowlist.
    • Derive a concrete postMessage target origin and validate inbound message origins.
    • Validate inbound bridge params: limit resources/read to ui:// resources and allow only https/http/mailto in ui/open-link.
    • Add fingerprintMCPAppResource / detectMCPAppResourceDrift for pinning and comparing app resources.
  • Updated dependencies [48e7e78]

    • @​ai-sdk/mcp@​2.0.14

4.0.30

Patch Changes

  • Updated dependencies [0bc8d4f]
    • ai@7.0.28

4.0.29

Patch Changes

  • 519c72b: fix (react/mcp-apps): sanitize server-supplied CSP domains in getMCPAppCSP so values cannot inject extra directives, sources, or policies into the generated Content-Security-Policy

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 29, 2026
@dependabot
dependabot Bot requested a review from qnbs as a code owner June 29, 2026 23:51
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 29, 2026
@vercel

vercel Bot commented Jun 29, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
worldscript-studio Ready Ready Preview, Comment Jul 26, 2026 5:49pm

@deepsource-io

deepsource-io Bot commented Jun 29, 2026

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 79aace8...b2bf186 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Docker Jun 29, 2026 11:51p.m. Review ↗
JavaScript Jun 29, 2026 11:51p.m. Review ↗
CSS Jun 29, 2026 11:51p.m. Review ↗
Rust Jun 29, 2026 11:51p.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@socket-security

socket-security Bot commented Jun 29, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​@​ai-sdk/​react@​4.0.34991007598100

View full report

@codeant-ai

codeant-ai Bot commented Jul 26, 2026

Copy link
Copy Markdown

🏁 CodeAnt Quality Gate Results

Commit: 29715328
Scan Time: 2026-07-26 17:44:33 UTC

✅ Overall Status: PASSED

Quality Gate Details

Quality Gate Status Details
Secrets ✅ PASSED 0 secrets found
Duplicate Code ✅ PASSED 0.0% duplicated
SAST ✅ PASSED No security issues
Bugs ✅ PASSED Rating S: No bugs
IAC ✅ PASSED Rating S: No issues

View Full Results

Bumps [@ai-sdk/react](https://github.com/vercel/ai/tree/HEAD/packages/react) from 3.0.201 to 4.0.34.
- [Release notes](https://github.com/vercel/ai/releases)
- [Changelog](https://github.com/vercel/ai/blob/main/packages/react/CHANGELOG.md)
- [Commits](https://github.com/vercel/ai/commits/@ai-sdk/react@4.0.34/packages/react)

---
updated-dependencies:
- dependency-name: "@ai-sdk/react"
  dependency-version: 3.0.210
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps): bump @ai-sdk/react from 3.0.201 to 3.0.210 build(deps): bump @ai-sdk/react from 3.0.201 to 4.0.34 Jul 26, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/ai-sdk/react-3.0.210 branch from b2bf186 to 2971532 Compare July 26, 2026 17:43
@codecov

codecov Bot commented Jul 26, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants