Skip to content

chore(deps): bump the third-party group across 1 directory with 4 updates - #919

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/sdk/typescript/third-party-b400b64251
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/sdk/typescript/third-party-b400b64251

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the third-party group with 4 updates in the /sdk/typescript directory: @agentclientprotocol/claude-agent-acp, @agentclientprotocol/sdk, @bex-co/muse-code-acp and @types/node.

Updates @agentclientprotocol/claude-agent-acp from 0.70.0 to 0.84.0

Release notes

Sourced from @​agentclientprotocol/claude-agent-acp's releases.

v0.84.0

0.84.0 (2026-09-28)

Features

v0.83.0

0.83.0 (2026-09-28)

Features

  • deps: Bump @​anthropic-ai/claude-agent-sdk to 0.3.283 (#1186) (49858b5)

v0.82.0

0.82.0 (2026-09-28)

Features

  • AIR tool call contract, exact git patches, plan file, and fixes for every client (#1153) (875d75f)

Bug Fixes

  • use ACP auth errors without access updates (#1179) (e6681d2)

v0.81.2

0.81.2 (2026-09-24)

Bug Fixes

  • announce resumed subagent generations when they start (#1173) (b495e55)
  • continue clear-context plans approved in a background followup (#1170) (a2c362c)

v0.81.1

0.81.1 (2026-09-23)

Bug Fixes

  • gate login result text on error state (#1103) (6e97e07)
  • honor permissions.disableBypassPermissionsMode (#1165) (281e47e)
  • include model on usage updates (#1032) (da11f1f)
  • keep the agent starting when the managed-policy tier cannot be read (#1146) (58c5db1)
  • mark informational chunks with metadata (#1055) (bd059c1)
  • offer bypass alongside auto in plan approval (#1164) (43c27e9)

... (truncated)

Changelog

Sourced from @​agentclientprotocol/claude-agent-acp's changelog.

0.84.0 (2026-09-28)

Features

0.83.0 (2026-09-28)

Features

  • deps: Bump @​anthropic-ai/claude-agent-sdk to 0.3.283 (#1186) (49858b5)

0.82.0 (2026-09-28)

Features

  • AIR tool call contract, exact git patches, plan file, and fixes for every client (#1153) (875d75f)

Bug Fixes

  • use ACP auth errors without access updates (#1179) (e6681d2)

0.81.2 (2026-09-24)

Bug Fixes

  • announce resumed subagent generations when they start (#1173) (b495e55)
  • continue clear-context plans approved in a background followup (#1170) (a2c362c)

0.81.1 (2026-09-23)

Bug Fixes

  • gate login result text on error state (#1103) (6e97e07)
  • honor permissions.disableBypassPermissionsMode (#1165) (281e47e)
  • include model on usage updates (#1032) (da11f1f)
  • keep the agent starting when the managed-policy tier cannot be read (#1146) (58c5db1)
  • mark informational chunks with metadata (#1055) (bd059c1)
  • offer bypass alongside auto in plan approval (#1164) (43c27e9)
  • preserve context usage when quota is exhausted (#1132) (39062b6)
  • preserve native Vertex endpoint defaults (#1104) (29a4e98)
  • publish effective mode after plan approval (#1163) (a2f4239)
  • recreate resumed sessions when any session option changes (#1097) (df38ccc)
  • render Write tool calls that use path/file_text aliases (#1161) (90cde4b)

... (truncated)

Commits

Updates @agentclientprotocol/sdk from 1.4.0 to 1.5.1

Release notes

Sourced from @​agentclientprotocol/sdk's releases.

v1.5.1

1.5.1 (2026-09-28)

Bug Fixes

  • bound incoming transport message sizes (#259) (69fda37)
  • bound per-connection memory in AcpServer (#261) (4356253)

v1.5.0

1.5.0 (2026-09-21)

Features

  • update schemas to v1.22.0 and v2.0.0-alpha.4 (#253) (a9f08bd)
  • update schemas to v1.23.0 and v2.0.0-alpha.5 (#255) (f7941e7)
Changelog

Sourced from @​agentclientprotocol/sdk's changelog.

1.5.1 (2026-09-28)

Bug Fixes

  • bound incoming transport message sizes (#259) (69fda37)
  • bound per-connection memory in AcpServer (#261) (4356253)

1.5.0 (2026-09-21)

Features

  • update schemas to v1.22.0 and v2.0.0-alpha.4 (#253) (a9f08bd)
  • update schemas to v1.23.0 and v2.0.0-alpha.5 (#255) (f7941e7)
Commits
  • c77d9bd chore(main): release 1.5.1 (#260)
  • b6cf568 chore(deps): bump the minor group with 40 updates (#262)
  • 4356253 fix: bound per-connection memory in AcpServer (#261)
  • 69fda37 fix: bound incoming transport message sizes (#259)
  • f1ba3a9 chore(main): release 1.5.0 (#254)
  • 20daeb7 chore(deps): bump crate-ci/typos from 1.50.1 to 1.50.2 (#256)
  • 2aadf1c chore(deps): bump the minor group with 11 updates (#257)
  • d031138 chore(deps-dev): bump markdown-it from 14.3.1 to 14.3.2 (#258)
  • f7941e7 feat: update schemas to v1.23.0 and v2.0.0-alpha.5 (#255)
  • a9f08bd feat: update schemas to v1.22.0 and v2.0.0-alpha.4 (#253)
  • Additional commits viewable in compare view

Updates @bex-co/muse-code-acp from 0.6.0 to 0.7.0

Changelog

Sourced from @​bex-co/muse-code-acp's changelog.

0.7.0 (2026-09-25)

Features

  • Read an explicit gateway endpoint from MUSE_CODE_ACP_GATEWAY_URL and MUSE_CODE_ACP_GATEWAY_KEY, so a client that configures the agent's environment can route a session without negotiating muse/provider. Both variables are required together, the same URL validation, guards and session binding apply, and a client-supplied muse/provider still wins. SDK backend only.

Fixes

  • Report legacy :auto-review sessions that the host refuses to read (Muse 1.3.0-R3401.1, resume_refused_class_c) with the same actionable message as a refused resume, so session/load no longer surfaces the raw host refusal. Detection uses the structured refusal detail as well as the older message form.
  • Advertise workflow cancel on Muse 1.3.0 as well as 1.2.1, after verifying public workflow/cancel against a real observed run on 1.3.0-R3401.1. Other hosts still show workflow cards without cancel.

Dependencies

  • Bump @muse-code/sdk from 0.1.1 to 1.3.0. The SDK now reroutes onApproval when approval/updated advances a multi-stage requirement ([upstream #10](meta-models/muse-code-sdk#10)); the adapter already decides approvals from the fold, so behavior is unchanged. The three newly folded view events (session/nameChanged, session/reasoningEffortChanged, session/modelRouteUnserved) are classified as ignored.

Compatibility and upgrading

The adapter now depends on @muse-code/sdk@1.3.0. No ACP IDs, config options or approval behavior change; approvals are still decided from the fold, so the SDK's new multi-stage routing is not relied on.

On Muse 1.3.0-R3401.1, a legacy muse exec session saved with :auto-review now fails at session/load rather than at the next prompt, because that host refuses to read it. The message and remedy are the same: continue it in Muse with reviewer support, or start a new ACP session. This is a host behavior change; the pinned 1.1.1 baseline is unchanged.

0.6.1 (2026-09-16)

Fixes

  • Name modes, models and reasoning efforts for the narrow chips clients render them in, keeping muse's own vocabulary: SDK default reads as "On request" after muse --approval-mode on-request, bypassApprovals as "Auto-approve", rejectApprovals as "Reject prompts" because known-safe tools may still run, and exec yolo as "No approval, no sandbox" — muse --yolo disables both, and the name keeps the pair that muse's own safety section states together. Effort tiers are capitalized, and a model shows its provider only when that distinguishes two catalog entries.
  • Correct a stale live-test version gate that pinned the legacy :auto-review resume limitation to 1.2.1-R2847.1, so 1.3.0-R3057.1 was expected to continue successfully. Affected builds stay enumerated, which is how 1.3.0 was caught still reproducing the rejection rather than fixing it. Adapter behavior is unchanged; only the test expectation and its documentation moved.

Compatibility and upgrading

Display names only: mode IDs, config option IDs, model choices and effort values are unchanged, so stored selections and automated clients keying on IDs are unaffected. A client that matches on the previous display strings should key on the ID instead.

The legacy :auto-review resume limitation is now confirmed on 1.3.0-R3057.1 as well as 1.2.1-R2847.1. This is an observation about the Muse host, not a regression in this adapter, and the pinned 1.1.1 baseline is unchanged.

Commits
  • e0cce00 chore: release 0.7.0
  • 47e6f60 chore: bump @​muse-code/sdk to 1.3.0 and adapt to Muse 1.3.0-R3401.1
  • b72d01a feat: route a session through an environment gateway
  • 9349855 chore: release 0.6.1
  • 4860db9 fix: align mode and model display names with the muse CLI
  • c34fec2 docs: record delegated-worker reassessment and file upstream issue
  • See full diff in compare view

Updates @types/node from 26.6.2 to 26.6.3

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…ates

Bumps the third-party group with 4 updates in the /sdk/typescript directory: [@agentclientprotocol/claude-agent-acp](https://github.com/agentclientprotocol/claude-agent-acp), [@agentclientprotocol/sdk](https://github.com/agentclientprotocol/typescript-sdk), [@bex-co/muse-code-acp](https://github.com/bex-co/muse-code-acp) and [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node).


Updates `@agentclientprotocol/claude-agent-acp` from 0.70.0 to 0.84.0
- [Release notes](https://github.com/agentclientprotocol/claude-agent-acp/releases)
- [Changelog](https://github.com/agentclientprotocol/claude-agent-acp/blob/main/CHANGELOG.md)
- [Commits](agentclientprotocol/claude-agent-acp@v0.70.0...v0.84.0)

Updates `@agentclientprotocol/sdk` from 1.4.0 to 1.5.1
- [Release notes](https://github.com/agentclientprotocol/typescript-sdk/releases)
- [Changelog](https://github.com/agentclientprotocol/typescript-sdk/blob/main/CHANGELOG.md)
- [Commits](agentclientprotocol/typescript-sdk@v1.4.0...v1.5.1)

Updates `@bex-co/muse-code-acp` from 0.6.0 to 0.7.0
- [Release notes](https://github.com/bex-co/muse-code-acp/releases)
- [Changelog](https://github.com/bex-co/muse-code-acp/blob/main/CHANGELOG.md)
- [Commits](bex-co/muse-code-acp@v0.6.0...v0.7.0)

Updates `@types/node` from 26.6.2 to 26.6.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@agentclientprotocol/claude-agent-acp"
  dependency-version: 0.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: third-party
- dependency-name: "@agentclientprotocol/sdk"
  dependency-version: 1.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: third-party
- dependency-name: "@bex-co/muse-code-acp"
  dependency-version: 0.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: third-party
- dependency-name: "@types/node"
  dependency-version: 26.6.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: third-party
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants