chore: bump ai sdk family, oxc tooling, and tsx - #224
Conversation
Update only patch/minor versions published at least 24 hours before the bump. Signed-off-by: Thomas Kosiewski <tk@coder.com> --- _Generated with [`xum`](https://github.com/coder/xum) • Model: `coder:openai/gpt-6-astra` • Thinking: `high`_ Change-Id: If29e6769e17343d8d68965d74373793ad4dd7492
|
@codex review |
|
@codex security review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Didn't find any major issues. More of your lovely PRs please. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security ReviewSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
Readiness record for
Newer dependency releases remain listed in the PR body for the next daily batch. Node 26.10.0 stays outside this dependency-only change. Generated with |
|
Merged through the merge queue at 2026-09-23T02:59:21Z as
Generated with |
Summary
Complete the fixed daily dependency batch. No runtime, test, peer-dependency, CI, or mise changes.
@ai-sdk/gateway@ai-sdk/harness-claude-code@ai-sdk/harness@ai-sdk/mcp@ai-sdk/react@ai-sdk/tui@oxlint/pluginsaioxfmtoxlinttsx@ai-sdk/providerremains 4.0.17 everywhere.@ai-sdk/anthropicremains 4.0.58. The Effect bridge's Coder pins and all peer dependencies are unchanged. Gateway and MCP changes are transitive, within their existing ranges; oxc platform bindings move with their parent packages.Publish-age gate and deferred versions
npm view <package> time --jsonwas rechecked at 2026-09-23T02:39:22.393538+00:00. All 49 adopted lockfile versions, including platform bindings, were at least 24 hours old. Newer releases remain outside this fixed batch even if they age past 24 hours during review.Deferred versions and npm publish timestamps
aiaiai@ai-sdk/harness@ai-sdk/harness@ai-sdk/harness@ai-sdk/harness-claude-code@ai-sdk/harness-claude-code@ai-sdk/harness-claude-code@ai-sdk/react@ai-sdk/react@ai-sdk/react@ai-sdk/tui@ai-sdk/tui@ai-sdk/tui@ai-sdk/gateway@ai-sdk/anthropic@ai-sdk/anthropicnodeNode stays 26.9.0 in mise; Node 26.10.0 is out of scope. The Node timestamp above is the npm package timestamp, not the upstream release-announcement timestamp.
Validation
mise installandpnpm install --frozen-lockfile: passed with Node 26.9.0 / pnpm 11.27.0.pnpm format: passed. No formatter churn.pnpm check: passed. Zero oxlint warnings or errors; no lint fixes.pnpm -r build: passed.pnpm -r test: 640 passed (agent 369, Effect 45, provider 22, release tooling 13, sandbox 191).pnpm publintandpnpm attw: passed for provider and sandbox.coder whoami: passed using ambient deployment credentials.cd packages/agent && npx vitest run test/e2e: 7/7 passed on attempt 1, 25.27 seconds. The single-WebSocket multi-tool test passed (7.609 seconds). No second attempt or control checkout was needed.Hands-on evidence
The attached terminal screenshot shows the passing live suite. The WebM is a recording of that same actual run, exported with accelerated timing (idle gaps compressed), not a second test run. Credentials were not printed. Raw logs and capture are preserved under the task's private
~/w43b-scratch/evidence directory.Merge gate
Require CI
Requiredgreen, both Codex review loops clean for the exact head, zero unresolved threads, and a fresh thread audit after roughly six minutes of settled review summaries. Merge only through the queue.Generated with
xum• Model:coder:openai/gpt-6-astra• Thinking:highlive-1.webm