chore(deps): update dependency ai to v5.0.153#1056
Open
renovate[bot] wants to merge 1 commit intomainfrom
Open
chore(deps): update dependency ai to v5.0.153#1056renovate[bot] wants to merge 1 commit intomainfrom
renovate[bot] wants to merge 1 commit intomainfrom
Conversation
a4cce57 to
6c4b687
Compare
0921fe1 to
fca7cd2
Compare
fca7cd2 to
4e4683a
Compare
4e4683a to
92052c2
Compare
92052c2 to
55d4ca1
Compare
98fdd1f to
269da45
Compare
269da45 to
d79b69b
Compare
d79b69b to
a7149ec
Compare
a7149ec to
76741d0
Compare
76741d0 to
44c23e6
Compare
44c23e6 to
8131481
Compare
8131481 to
da3dfaf
Compare
da3dfaf to
86a5402
Compare
86a5402 to
ab09852
Compare
ab09852 to
b62752f
Compare
b62752f to
6fe4117
Compare
6fe4117 to
9430120
Compare
9430120 to
3835c42
Compare
3835c42 to
8882b98
Compare
8882b98 to
ca5536c
Compare
ca5536c to
a42f847
Compare
a42f847 to
7dc6341
Compare
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
7dc6341 to
352c2b0
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.0.117→5.0.153Release Notes
vercel/ai (ai)
v5.0.153Compare Source
Patch Changes
c59a31c: Remove custom User-Agent header from HttpChatTransport to fix CORS preflight failures in Safari and Firefoxv5.0.152Compare Source
Patch Changes
a608d48]c5790b1]v5.0.151Compare Source
Patch Changes
f54cb63]v5.0.150Compare Source
Patch Changes
ee7582f]v5.0.149Compare Source
Patch Changes
c66afc5: fix(security): validate redirect targets in download functions to prevent SSRF bypassdownloadnow validates the final URL after following HTTP redirects, preventing attackers from bypassing SSRF protections via open redirects to internal/private addresses.v5.0.148Compare Source
Patch Changes
392dc94]v5.0.147Compare Source
Patch Changes
7a57a71]v5.0.146Compare Source
Patch Changes
6a2f01b: Add URL validation todownloadto prevent blind SSRF attacks. Private/internal IP addresses, localhost, and non-HTTP protocols are now rejected before fetching.6a2f01b]17d64e3]v5.0.145Compare Source
Patch Changes
201bb12]v5.0.144Compare Source
Patch Changes
c4a324b]v5.0.143Compare Source
Patch Changes
4fa740a]v5.0.142Compare Source
Patch Changes
8ea21c1]v5.0.141Compare Source
Patch Changes
4db4318]v5.0.140Compare Source
Patch Changes
3749ed6]v5.0.139Compare Source
Patch Changes
9212b2d]v5.0.138Compare Source
Patch Changes
42815ac]v5.0.137Compare Source
Patch Changes
5e921ed]v5.0.136Compare Source
Patch Changes
9baf5ea]v5.0.135Compare Source
Patch Changes
fe42fd3]8b5473c]v5.0.134Compare Source
Patch Changes
9545c46]v5.0.133Compare Source
Patch Changes
b4ac032]v5.0.132Compare Source
Patch Changes
8aac221]v5.0.131Compare Source
Patch Changes
3f04ffe]v5.0.130Compare Source
Patch Changes
20565b8: security: prevent unbounded memory growth in download functionsThe
download()anddownloadBlob()functions now enforce a default 2 GiB size limit when downloading from user-provided URLs. Downloads that exceed this limit are aborted with aDownloadErrorinstead of consuming unbounded memory and crashing the process. TheabortSignalparameter is now passed through tofetch()in all download call sites.Added
downloadoption totranscribe()andexperimental_generateVideo()for providing a custom download function. Use the newcreateDownload({ maxBytes })factory to configure download size limits.Updated dependencies [
20565b8]v5.0.129Patch Changes
a207442]v5.0.128Patch Changes
7e6c81a]v5.0.127Patch Changes
db2e810]v5.0.126Compare Source
Patch Changes
beba89c]v5.0.125Compare Source
Patch Changes
8d8fdd2]v5.0.124Compare Source
Patch Changes
fad90dd]8479fe8]0d3fc21]53e891c]v5.0.123Compare Source
Patch Changes
5253b83]v5.0.122Compare Source
Patch Changes
9158228]v5.0.121Compare Source
Patch Changes
74676fa]v5.0.120Compare Source
Patch Changes
655377e]v5.0.119Compare Source
Patch Changes
f6b46d2]v5.0.118Compare Source
Patch Changes
42bad72:https://ai-sdk.dev->https://v5.ai-sdk.devConfiguration
📅 Schedule: Branch creation - At 12:00 AM through 04:59 AM and 10:00 PM through 11:59 PM, Monday through Friday ( * 0-4,22-23 * * 1-5 ), Only on Sunday and Saturday ( * * * * 0,6 ) (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.