Skip to content

chore(deps): Bump the runtime-minor-patch group across 1 directory with 6 updates - #55

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/runtime-minor-patch-27d63e9a83
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/runtime-minor-patch-27d63e9a83

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown

Bumps the runtime-minor-patch group with 6 updates in the / directory:

Package From To
@huggingface/transformers 4.2.0 4.3.0
@isomorphic-git/lightning-fs 4.6.3 4.8.0
@langchain/core 1.2.3 1.2.11
@langchain/langgraph 1.4.8 1.4.15
isomorphic-git 1.38.10 1.42.2
zod 4.4.3 4.6.5

Updates @huggingface/transformers from 4.2.0 to 4.3.0

Release notes

Sourced from @​huggingface/transformers's releases.

4.3.0

🚀 Transformers.js v4.3 — Structured Output, New Models, WebGPU upgrade, Documentation Overhaul

This release adds structured output, three new model architectures, WebGPU support for Safari 26+, and a documentation overhaul. We also upgraded ONNX Runtime to the latest version.

What's new?

Structured output

Constrain generation to a JSON schema, JSON object, or regular expression with the experimental, dependency-free @huggingface/transformers-structured-output package in huggingface/transformers.js#1758.

For example, classify customer feedback into a fixed set of sentiments and topics:

import { pipeline, TextStreamer } from "@huggingface/transformers";
import { StructuredOutputProcessor } from "@huggingface/transformers-structured-output";
// Create the pipeline first so its tokenizer is available.
const generator = await pipeline(
"text-generation",
"onnx-community/LFM2.5-350M-ONNX",
{ dtype: "q4f16", device: "webgpu" },
);
const processor = new StructuredOutputProcessor(generator.tokenizer, {
type: "json_schema",
json_schema: {
type: "object",
properties: {
sentiment: { enum: ["positive", "negative", "neutral"] },
topic: { enum: ["price", "quality", "delivery", "other"] },
},
required: ["sentiment", "topic"],
additionalProperties: false,
},
});
const messages = [
{
role: "user",
content: "Classify this feedback: The product is way too expensive.",
},
];
const output = await generator(messages, {
max_new_tokens: 512,
do_sample: false,
streamer: new TextStreamer(generator.tokenizer, {
skip_prompt: true,
skip_special_tokens: true,
</tr></table>

... (truncated)

Commits

Updates @isomorphic-git/lightning-fs from 4.6.3 to 4.8.0

Release notes

Sourced from @​isomorphic-git/lightning-fs's releases.

v4.8.0

4.8.0 (2026-09-15)

Features

v4.7.0

4.7.0 (2026-07-25)

Features

Commits

Updates @langchain/core from 1.2.3 to 1.2.11

Release notes

Sourced from @​langchain/core's releases.

@​langchain/core@​1.2.11

Patch Changes

  • #11603 fec9cd8 Thanks @​thushanth-bengre-langchain! - fix(core): build streaming llmOutput.tokenUsage from the fully-accumulated chunk instead of whichever individual chunk's usage_metadata arrived last

    Affects both core streaming paths — .stream()/.streamEvents() (_streamIterator) and .invoke()/.generate() when a streaming-preferring callback is attached (_generateWithCache's hasStreamingHandler branch). Previously, llmOutput.tokenUsage was overwritten by each chunk in turn, so only the last chunk carrying usage_metadata won — correct for providers that emit one cumulative total on a final chunk, but wrong for providers (e.g. @langchain/google, @langchain/anthropic) that emit usage_metadata as a per-chunk delta across multiple chunks, where the values must be summed.

    Note for provider authors: this assumes each streamed chunk's usage_metadata is either a per-chunk delta or appears only on a single final chunk. A provider that instead repeats a cumulative total on every chunk will now see it summed (and inflated) in llmOutput.tokenUsage, matching the existing behavior of the correctly-working message.usage_metadata field.

    Also fixes @langchain/google's invoke({streaming: true}) path (no streaming-preferring callback attached), where llmOutput was never populated at all.

  • #11590 ffebdc2 Thanks @​thushanth-bengre-langchain! - Fix OpenAI Responses API replay under Zero Data Retention when a response contains more than one reasoning item, for both v0 and v1. In v0, the default replay path now reuses response_metadata.output directly, preserving every reasoning item's id/encrypted_content in original order. In v1, AIMessage.contentBlocks (outputVersion: "v1") is fixed the same way. additional_kwargs.reasoning is unchanged.

@​langchain/core@​1.2.10

Patch Changes

@​langchain/core@​1.2.9

Patch Changes

@​langchain/core@​1.2.8

Patch Changes

  • #11369 d6ad973 Thanks @​hntrl! - fix(langchain): use unified endpoint for gateway

  • #11342 3b0e4c4 Thanks @​thushanth-bengre-langchain! - feat(core): mark errors as retryable or not, and stop retrying the ones that aren't

    Retry middleware retried every failure up to maxRetries, including deterministic ones like a bad API key or an unknown model. Retries also nest, so a single such failure could cost dozens of API calls.

    @langchain/core/errors adds stampRetryable(error, retryable) and getRetryable(error). Marking an error leaves its class and shape untouched, so a provider SDK error can be classified without breaking instanceof. getRetryable returns undefined for errors nobody classified, and both are exported so tool authors can mark their own failures.

    modelRetryMiddleware and toolRetryMiddleware now respect the mark by default, and retries stop as soon as one is found rather than each layer spending its own budget. Aborted calls, context overflow, and oversized payloads are marked non-retryable out of the box. Models accept a per-call maxRetries so a surrounding retry loop can take over.

    Behavior change: errors marked non-retryable now fail on the first attempt. Unclassified errors — including any from third-party integrations or custom tools — retry exactly as before. Pass retryOn: () => true to restore the old default. A custom onFailedAttempt replaces the built-in handler and opts out of marking.

@​langchain/core@​1.2.7

Patch Changes

Commits
  • 778566e chore: version packages (#11607)
  • 18b71af feat(google-genai): add outputDimensionality parameter to GoogleGenerativeAIE...
  • 35368db fix(google): surface groundingMetadata/citationMetadata on streaming path (#1...
  • 78b2923 fix(google): preserve tool call id and thoughtSignature in native streaming (...
  • ffebdc2 fix(openai): correctly handle multiple reasoning items in v1 content blocks (...
  • c9ae847 fix(google): set includeServerSideToolInvocations when mixing tools (#11611)
  • bc88b75 fix(google): route Vertex multi-region endpoints (#11433)
  • fec9cd8 fix(core): build streaming llmOutput.tokenUsage from accumulated usage (#11603)
  • 194a063 fix(google): allowlist JSON Schema keywords for Gemini schemas (#11606)
  • b0a0d3f fix(deps): upgrade Vitest to address GHSA-82fw-gwwq-j7x9 (#11599)
  • Additional commits viewable in compare view

Updates @langchain/langgraph from 1.4.8 to 1.4.15

Release notes

Sourced from @​langchain/langgraph's releases.

@​langchain/langgraph@​1.4.15

Patch Changes

  • #2794 83a4b62 Thanks @​hntrl! - feat(langgraph): add per-node tracePolicy input/output processors and omitPayload

    Transform the payloads recorded on a node's own trace run while retaining its span and timing. Processors receive raw values and fall back to the original payload if they throw. Graph state, root runs, and child runs remain unchanged when processors do not mutate their arguments.

    Matches Python's callback-level behavior: transforms also affect chain events and message streaming, so omitting outputs can suppress messages returned directly by nodes and omitting inputs can affect message deduplication.

  • Updated dependencies [3234c69, 3234c69, 11a4535, 2fab6fd, 4fc118f, db4bdad, 55fa26b]:

    • @​langchain/langgraph-sdk@​1.11.0

@​langchain/langgraph@​1.4.15-rc.0

Patch Changes

  • #2794 83a4b62 Thanks @​hntrl! - feat(langgraph): add per-node tracePolicy input/output processors and omitPayload

    Transform the payloads recorded on a node's own trace run while retaining its span and timing. Processors receive raw values and fall back to the original payload if they throw. Graph state, root runs, and child runs remain unchanged when processors do not mutate their arguments.

  • Updated dependencies [2fab6fd]:

    • @​langchain/langgraph-sdk@​1.10.3-rc.0

@​langchain/langgraph@​1.4.14

Patch Changes

  • #2747 fix(langgraph): pushMessage emits on the streamEvents v3 messages channel
  • Updated dependencies: @​langchain/langgraph-sdk

@​langchain/langgraph@​1.4.13

Patch Changes

@​langchain/langgraph@​1.4.12

Patch Changes

  • #2714 a2a59ec Thanks @​hntrl! - Update checkpoint integrations to require the patched checkpoint serializer release.

  • Updated dependencies [a2a59ec]:

    • @​langchain/langgraph-checkpoint@​1.1.5

@​langchain/langgraph@​1.4.11

Patch Changes

  • #2706 eaa5472 Thanks @​zduric-langchain! - fix(langgraph): dedupe merged callback handlers by identity

    mergeCallbacks concatenated handlers and inheritableHandlers while deduping tags, so a handler inherited by both the ambient and the explicit config picked up an extra registration at every graph boundary. With tracing on, a nested streamMode: "messages" run delivered every token twice.

... (truncated)

Changelog

Sourced from @​langchain/langgraph's changelog.

1.4.15

Patch Changes

  • #2794 83a4b62 Thanks @​hntrl! - feat(langgraph): add per-node tracePolicy input/output processors and omitPayload

    Transform the payloads recorded on a node's own trace run while retaining its span and timing. Processors receive raw values and fall back to the original payload if they throw. Graph state, root runs, and child runs remain unchanged when processors do not mutate their arguments.

    Matches Python's callback-level behavior: transforms also affect chain events and message streaming, so omitting outputs can suppress messages returned directly by nodes and omitting inputs can affect message deduplication.

  • Updated dependencies [3234c69, 3234c69, 11a4535, 2fab6fd, 4fc118f, db4bdad, 55fa26b]:

    • @​langchain/langgraph-sdk@​1.11.0

1.4.15-rc.0

Patch Changes

  • #2794 83a4b62 Thanks @​hntrl! - feat(langgraph): add per-node tracePolicy input/output processors and omitPayload

    Transform the payloads recorded on a node's own trace run while retaining its span and timing. Processors receive raw values and fall back to the original payload if they throw. Graph state, root runs, and child runs remain unchanged when processors do not mutate their arguments.

  • Updated dependencies [2fab6fd]:

    • @​langchain/langgraph-sdk@​1.10.3-rc.0

1.4.14

Patch Changes

  • #2747 5ce7f42 Thanks @​t3s7r! - fix(langgraph): pushMessage emits on the streamEvents v3 messages channel

  • Updated dependencies [dd287b4]:

    • @​langchain/langgraph-sdk@​1.10.1

1.4.13

Patch Changes

1.4.12

Patch Changes

  • #2714 a2a59ec Thanks @​hntrl! - Update checkpoint integrations to require the patched checkpoint serializer release.

  • Updated dependencies [a2a59ec]:

    • @​langchain/langgraph-checkpoint@​1.1.5

1.4.11

... (truncated)

Commits

Updates isomorphic-git from 1.38.10 to 1.42.2

Release notes

Sourced from isomorphic-git's releases.

v1.42.2

1.42.2 (2026-09-11)

Bug Fixes

v1.42.1

1.42.1 (2026-09-11)

Bug Fixes

  • restore PushRejectedError when pushing against advanced remote (#2429) (14764ae), closes #2421

v1.42.0

1.42.0 (2026-09-10)

Features

Bug Fixes

v1.41.9

1.41.9 (2026-08-23)

Bug Fixes

  • match filepaths on path component boundaries (#2416) (89d641a)

v1.41.8

1.41.8 (2026-08-21)

Bug Fixes

  • throw when TREE is given a ref that cannot be resolved (#2407) (fe987eb)

v1.41.7

1.41.7 (2026-08-19)

Bug Fixes

... (truncated)

Commits

Updates zod from 4.4.3 to 4.6.5

Release notes

Sourced from zod's releases.

v4.6.5

Commits:

  • d2b135cfb7a3582b9eb515756b9166bcb9521f4a docs: add the 4.6.x patch highlights to the 4.6 post
  • f1448f7cee00df9fe1e9ad84a000aa1828cc8bc1 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • de65a5cb39ed22a507fac935788f718fa88d104f docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • 56222cd1532c07bcb91b67df529cab4c0a215330 feat(instanceof): key the .properties() shape off the instance type (#6600)
  • ca0229a404818290e6cdcfefcd7eb2d04bcbb543 Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)"
  • cc4cd4ee9c52fcaa10964e48cc144541e41a5ed9 Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)""
  • 0f3f5ee3ca56c7574bf849e54f79e9a6e02562ee 4.6.5
  • 59bbc03e10c636b9eb3c393dfeb552819774ec21 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump

v4.6.4

A patch on top of 4.6.3.

  • d6bc1e30 feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)
  • ad32d751 perf: z.url() rejects an invalid URL with URL.canParse() instead of a throwing constructor, about 50x faster; fewer allocations on the validation path (#6588)
  • 2bb08717 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • f6e1701a chore(deps): bump next to 15.5.25 and vite to 7.3.6 (#6153)

v4.6.3

A patch on top of 4.6.2.

  • 413cce9a fix(v4): make z.properties() a check again (#6594) — removes the standalone z.properties() schema from 4.6.0; z.instanceof().properties() and .check(...z.properties()) are unchanged
  • 75d63ee1 docs: show only the .properties() method form in the 4.6 post
  • 46da9572 docs: match the error-message examples to what the parsers emit

v4.6.2

A patch on top of 4.6.1.

v4.6.1

A patch on top of 4.6.0.

v4.6.0

Zod 4.6 is now available.

npm install zod@latest

At a glance:

... (truncated)

Commits
  • 59bbc03 chore: re-pin the integration peers to the workspace zod after the 4.6.5 bump
  • 0f3f5ee 4.6.5
  • cc4cd4e Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, ref...
  • ca0229a Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed w...
  • 56222cd feat(instanceof): key the .properties() shape off the instance type (#6600)
  • de65a5c docs: lead the properties section with the check and add a Zod Mini tab (#6598)
  • f1448f7 docs: fold the 4.6.x patch highlights into the 4.6 post's own sections
  • d2b135c docs: add the 4.6.x patch highlights to the 4.6 post
  • 2bb0871 chore: re-pin the integration peers to the workspace zod after the 4.6.4 bump
  • 743aedb 4.6.4
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…th 6 updates

Bumps the runtime-minor-patch group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@huggingface/transformers](https://github.com/huggingface/transformers.js) | `4.2.0` | `4.3.0` |
| [@isomorphic-git/lightning-fs](https://github.com/isomorphic-git/lightning-fs) | `4.6.3` | `4.8.0` |
| [@langchain/core](https://github.com/langchain-ai/langchainjs) | `1.2.3` | `1.2.11` |
| [@langchain/langgraph](https://github.com/langchain-ai/langgraphjs/tree/HEAD/libs/langgraph-core) | `1.4.8` | `1.4.15` |
| [isomorphic-git](https://github.com/isomorphic-git/isomorphic-git) | `1.38.10` | `1.42.2` |
| [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.6.5` |



Updates `@huggingface/transformers` from 4.2.0 to 4.3.0
- [Release notes](https://github.com/huggingface/transformers.js/releases)
- [Commits](huggingface/transformers.js@4.2.0...4.3.0)

Updates `@isomorphic-git/lightning-fs` from 4.6.3 to 4.8.0
- [Release notes](https://github.com/isomorphic-git/lightning-fs/releases)
- [Commits](isomorphic-git/lightning-fs@v4.6.3...v4.8.0)

Updates `@langchain/core` from 1.2.3 to 1.2.11
- [Release notes](https://github.com/langchain-ai/langchainjs/releases)
- [Commits](https://github.com/langchain-ai/langchainjs/compare/@langchain/core@1.2.3...@langchain/core@1.2.11)

Updates `@langchain/langgraph` from 1.4.8 to 1.4.15
- [Release notes](https://github.com/langchain-ai/langgraphjs/releases)
- [Changelog](https://github.com/langchain-ai/langgraphjs/blob/main/libs/langgraph-core/CHANGELOG.md)
- [Commits](https://github.com/langchain-ai/langgraphjs/commits/@langchain/langgraph@1.4.15/libs/langgraph-core)

Updates `isomorphic-git` from 1.38.10 to 1.42.2
- [Release notes](https://github.com/isomorphic-git/isomorphic-git/releases)
- [Commits](isomorphic-git/isomorphic-git@v1.38.10...v1.42.2)

Updates `zod` from 4.4.3 to 4.6.5
- [Release notes](https://github.com/colinhacks/zod/releases)
- [Commits](colinhacks/zod@v4.4.3...v4.6.5)

---
updated-dependencies:
- dependency-name: "@huggingface/transformers"
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: runtime-minor-patch
- dependency-name: "@isomorphic-git/lightning-fs"
  dependency-version: 4.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: runtime-minor-patch
- dependency-name: "@langchain/core"
  dependency-version: 1.2.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: runtime-minor-patch
- dependency-name: "@langchain/langgraph"
  dependency-version: 1.4.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: runtime-minor-patch
- dependency-name: isomorphic-git
  dependency-version: 1.42.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: runtime-minor-patch
- dependency-name: zod
  dependency-version: 4.6.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: runtime-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants