Commit Graph

2873 Commits

Author SHA1 Message Date
dependabot[bot] c79cf7f813 chore(deps): bump the angular group across 1 directory with 9 updates (#2365)
Bumps the angular group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
|
[@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common)
| `21.2.7` | `21.2.11` |
|
[@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler)
| `21.2.7` | `21.2.11` |
|
[@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core)
| `21.2.7` | `21.2.11` |
|
[@angular/forms](https://github.com/angular/angular/tree/HEAD/packages/forms)
| `21.2.7` | `21.2.11` |
|
[@angular/platform-browser](https://github.com/angular/angular/tree/HEAD/packages/platform-browser)
| `21.2.7` | `21.2.11` |
|
[@angular/router](https://github.com/angular/angular/tree/HEAD/packages/router)
| `21.2.7` | `21.2.11` |
| [@angular/build](https://github.com/angular/angular-cli) | `21.2.6` |
`21.2.9` |
| [@angular/cli](https://github.com/angular/angular-cli) | `21.2.6` |
`21.2.9` |
|
[@angular/compiler-cli](https://github.com/angular/angular/tree/HEAD/packages/compiler-cli)
| `21.2.7` | `21.2.11` |


Updates `@angular/common` from 21.2.7 to 21.2.11
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/angular/angular/releases">@​angular/common's
releases</a>.</em></p>
<blockquote>
<h2>21.2.11</h2>
<h3>common</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/10ad3c06923453ae0ec06b06e664ce05900a4ff6"><img
src="https://img.shields.io/badge/10ad3c0692-fix-green" alt="fix -
10ad3c0692" /></a></td>
<td>prevent focus from scrollToAnchor</td>
</tr>
</tbody>
</table>
<h3>compiler</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/4f5d8a2c0b5e38d4debc4293945270cea4a9590d"><img
src="https://img.shields.io/badge/4f5d8a2c0b-fix-green" alt="fix -
4f5d8a2c0b" /></a></td>
<td>let declaration span not including end character</td>
</tr>
</tbody>
</table>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/a40e2cebc878965c3e21bfb61658f3f80cbd2ebf"><img
src="https://img.shields.io/badge/a40e2cebc8-fix-green" alt="fix -
a40e2cebc8" /></a></td>
<td>fix ordering of view queries metadata in JIT mode</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/885a1a1d9757adfa8766d9b369c848a277438c31"><img
src="https://img.shields.io/badge/885a1a1d97-fix-green" alt="fix -
885a1a1d97" /></a></td>
<td>guard against non-object events and avoid listener wrapper identity
mismatch</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/7a64aff9b59999077ea915486a7fa0b97a286659"><img
src="https://img.shields.io/badge/7a64aff9b5-fix-green" alt="fix -
7a64aff9b5" /></a></td>
<td>prevent event replay double-invocation when element hydrates before
app stability</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/be1f80a253b8ee27ed7d8de2287d6895c4821909"><img
src="https://img.shields.io/badge/be1f80a253-fix-green" alt="fix -
be1f80a253" /></a></td>
<td>ensure origin has a trailing slash when parsing url</td>
</tr>
</tbody>
</table>
<h2>21.2.10</h2>
<h3>docs</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/0d5ee9ae1ba4b7acd8f27a059a778f0b4bd8a5bd"><img
src="https://img.shields.io/badge/0d5ee9ae1b-fix-green" alt="fix -
0d5ee9ae1b" /></a></td>
<td>link formatting in &quot;Animating your Application with
CSS&quot;</td>
</tr>
</tbody>
</table>
<h3>migrations</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/5533ab4f56f574bc9365cf0573c4a34a3ab5aaf1"><img
src="https://img.shields.io/badge/5533ab4f56-fix-green" alt="fix -
5533ab4f56" /></a></td>
<td>fix NgClass leaving trailing comma after removal</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/580212c995751c4bf4ce8a49df4167498743e0ea"><img
src="https://img.shields.io/badge/580212c995-fix-green" alt="fix -
580212c995" /></a></td>
<td>restore internal URL on popstate when <code>browserUrl</code> is
used</td>
</tr>
</tbody>
</table>
<h2>21.2.9</h2>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/f603d4714fa184aad34a6f7f9ea4e79c8af3afac"><img
src="https://img.shields.io/badge/f603d4714f-fix-green" alt="fix -
f603d4714f" /></a></td>
<td>escape forward slashes in transfer state to prevent crawler
indexing</td>
</tr>
</tbody>
</table>
<h3>http</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/540536c386f2c735a700c2c9e2697a88dcb3d4ec"><img
src="https://img.shields.io/badge/540536c386-fix-green" alt="fix -
540536c386" /></a></td>
<td>add CSP nonce support to JsonpClientBackend</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/63a857b874172766451aa75ed3347ba50f0ee229"><img
src="https://img.shields.io/badge/63a857b874-fix-green" alt="fix -
63a857b874" /></a></td>
<td>Don't on Passthru outside of reactive context</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/e0b5078cf2ebe79a6de85e9123148ae948b3d81d"><img
src="https://img.shields.io/badge/e0b5078cf2-fix-green" alt="fix -
e0b5078cf2" /></a></td>
<td>prevent SSRF bypasses via protocol-relative and backslash URLs</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<p>| Commit | Description |</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/angular/angular/blob/main/CHANGELOG.md">@​angular/common's
changelog</a>.</em></p>
<blockquote>
<h1>21.2.11 (2026-04-29)</h1>
<h3>common</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/10ad3c06923453ae0ec06b06e664ce05900a4ff6">10ad3c0692</a></td>
<td>fix</td>
<td>prevent focus from scrollToAnchor</td>
</tr>
</tbody>
</table>
<h3>compiler</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/4f5d8a2c0b5e38d4debc4293945270cea4a9590d">4f5d8a2c0b</a></td>
<td>fix</td>
<td>let declaration span not including end character</td>
</tr>
</tbody>
</table>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/a40e2cebc878965c3e21bfb61658f3f80cbd2ebf">a40e2cebc8</a></td>
<td>fix</td>
<td>fix ordering of view queries metadata in JIT mode</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/885a1a1d9757adfa8766d9b369c848a277438c31">885a1a1d97</a></td>
<td>fix</td>
<td>guard against non-object events and avoid listener wrapper identity
mismatch</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/7a64aff9b59999077ea915486a7fa0b97a286659">7a64aff9b5</a></td>
<td>fix</td>
<td>prevent event replay double-invocation when element hydrates before
app stability</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/be1f80a253b8ee27ed7d8de2287d6895c4821909">be1f80a253</a></td>
<td>fix</td>
<td>ensure origin has a trailing slash when parsing url</td>
</tr>
</tbody>
</table>
<!-- raw HTML omitted -->
<p><!-- raw HTML omitted --><!-- raw HTML omitted --></p>
<h1>22.0.0-next.9 (2026-04-22)</h1>
<h2>Breaking Changes</h2>
<h3>router</h3>
<ul>
<li>
<p>paramsInheritanceStrategy now defaults to 'always'</p>
<p>The default value of paramsInheritanceStrategy has been changed from
'emptyOnly' to 'always'. This means that route parameters are inherited
from all parent routes by default. To restore the previous behavior, set
paramsInheritanceStrategy to 'emptyOnly' in your router
configuration.</p>
</li>
</ul>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/8f3d0b9d97424e058eb7bce57d80833fb68dec4a">8f3d0b9d97</a></td>
<td>feat</td>
<td>introduce <code>@Service</code> decorator</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/9f479ae9641a5c928f8eeab9c7846245002b3eff">9f479ae964</a></td>
<td>feat</td>
<td>Update Testability to use PendingTasks for stability indicator</td>
</tr>
</tbody>
</table>
<h3>docs</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/b24b4cb699c325fc2ce40681724341baaabf277b">b24b4cb699</a></td>
<td>fix</td>
<td>link formatting in &quot;Animating your Application with
CSS&quot;</td>
</tr>
</tbody>
</table>
<h3>migrations</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/b395173cf206b8c04c5ab74298e640c9086d0bac">b395173cf2</a></td>
<td>fix</td>
<td>fix NgClass leaving trailing comma after removal</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/6eff4395467de51a46656d79d957b448b32dde0c">6eff439546</a></td>
<td>fix</td>
<td>restore internal URL on popstate when <code>browserUrl</code> is
used</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/17d10f7a9921429d0192df6925d20d7236425c9a">17d10f7a99</a></td>
<td>fix</td>
<td>set default paramsInheritanceStrategy to 'always'</td>
</tr>
</tbody>
</table>
<!-- raw HTML omitted -->
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/angular/angular/commit/42d57c35781fb65fc4d44df59b6a85287664216a"><code>42d57c3</code></a>
refactor(common): fix viewport tests</li>
<li><a
href="https://github.com/angular/angular/commit/10ad3c06923453ae0ec06b06e664ce05900a4ff6"><code>10ad3c0</code></a>
fix(common): prevent focus from scrollToAnchor</li>
<li><a
href="https://github.com/angular/angular/commit/540536c386f2c735a700c2c9e2697a88dcb3d4ec"><code>540536c</code></a>
fix(http): add CSP nonce support to JsonpClientBackend</li>
<li><a
href="https://github.com/angular/angular/commit/8102331f82c808ca2256ba51a1d83803a61beabb"><code>8102331</code></a>
test(http): disable XSRF and mock location in HttpClient tests to avoid
Domin...</li>
<li>See full diff in <a
href="https://github.com/angular/angular/commits/v21.2.11/packages/common">compare
view</a></li>
</ul>
</details>
<br />

Updates `@angular/compiler` from 21.2.7 to 21.2.11
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/angular/angular/releases">@​angular/compiler's
releases</a>.</em></p>
<blockquote>
<h2>21.2.11</h2>
<h3>common</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/10ad3c06923453ae0ec06b06e664ce05900a4ff6"><img
src="https://img.shields.io/badge/10ad3c0692-fix-green" alt="fix -
10ad3c0692" /></a></td>
<td>prevent focus from scrollToAnchor</td>
</tr>
</tbody>
</table>
<h3>compiler</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/4f5d8a2c0b5e38d4debc4293945270cea4a9590d"><img
src="https://img.shields.io/badge/4f5d8a2c0b-fix-green" alt="fix -
4f5d8a2c0b" /></a></td>
<td>let declaration span not including end character</td>
</tr>
</tbody>
</table>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/a40e2cebc878965c3e21bfb61658f3f80cbd2ebf"><img
src="https://img.shields.io/badge/a40e2cebc8-fix-green" alt="fix -
a40e2cebc8" /></a></td>
<td>fix ordering of view queries metadata in JIT mode</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/885a1a1d9757adfa8766d9b369c848a277438c31"><img
src="https://img.shields.io/badge/885a1a1d97-fix-green" alt="fix -
885a1a1d97" /></a></td>
<td>guard against non-object events and avoid listener wrapper identity
mismatch</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/7a64aff9b59999077ea915486a7fa0b97a286659"><img
src="https://img.shields.io/badge/7a64aff9b5-fix-green" alt="fix -
7a64aff9b5" /></a></td>
<td>prevent event replay double-invocation when element hydrates before
app stability</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/be1f80a253b8ee27ed7d8de2287d6895c4821909"><img
src="https://img.shields.io/badge/be1f80a253-fix-green" alt="fix -
be1f80a253" /></a></td>
<td>ensure origin has a trailing slash when parsing url</td>
</tr>
</tbody>
</table>
<h2>21.2.10</h2>
<h3>docs</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/0d5ee9ae1ba4b7acd8f27a059a778f0b4bd8a5bd"><img
src="https://img.shields.io/badge/0d5ee9ae1b-fix-green" alt="fix -
0d5ee9ae1b" /></a></td>
<td>link formatting in &quot;Animating your Application with
CSS&quot;</td>
</tr>
</tbody>
</table>
<h3>migrations</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/5533ab4f56f574bc9365cf0573c4a34a3ab5aaf1"><img
src="https://img.shields.io/badge/5533ab4f56-fix-green" alt="fix -
5533ab4f56" /></a></td>
<td>fix NgClass leaving trailing comma after removal</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/580212c995751c4bf4ce8a49df4167498743e0ea"><img
src="https://img.shields.io/badge/580212c995-fix-green" alt="fix -
580212c995" /></a></td>
<td>restore internal URL on popstate when <code>browserUrl</code> is
used</td>
</tr>
</tbody>
</table>
<h2>21.2.9</h2>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/f603d4714fa184aad34a6f7f9ea4e79c8af3afac"><img
src="https://img.shields.io/badge/f603d4714f-fix-green" alt="fix -
f603d4714f" /></a></td>
<td>escape forward slashes in transfer state to prevent crawler
indexing</td>
</tr>
</tbody>
</table>
<h3>http</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/540536c386f2c735a700c2c9e2697a88dcb3d4ec"><img
src="https://img.shields.io/badge/540536c386-fix-green" alt="fix -
540536c386" /></a></td>
<td>add CSP nonce support to JsonpClientBackend</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/63a857b874172766451aa75ed3347ba50f0ee229"><img
src="https://img.shields.io/badge/63a857b874-fix-green" alt="fix -
63a857b874" /></a></td>
<td>Don't on Passthru outside of reactive context</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/e0b5078cf2ebe79a6de85e9123148ae948b3d81d"><img
src="https://img.shields.io/badge/e0b5078cf2-fix-green" alt="fix -
e0b5078cf2" /></a></td>
<td>prevent SSRF bypasses via protocol-relative and backslash URLs</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<p>| Commit | Description |</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/angular/angular/blob/main/CHANGELOG.md">@​angular/compiler's
changelog</a>.</em></p>
<blockquote>
<h1>21.2.11 (2026-04-29)</h1>
<h3>common</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/10ad3c06923453ae0ec06b06e664ce05900a4ff6">10ad3c0692</a></td>
<td>fix</td>
<td>prevent focus from scrollToAnchor</td>
</tr>
</tbody>
</table>
<h3>compiler</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/4f5d8a2c0b5e38d4debc4293945270cea4a9590d">4f5d8a2c0b</a></td>
<td>fix</td>
<td>let declaration span not including end character</td>
</tr>
</tbody>
</table>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/a40e2cebc878965c3e21bfb61658f3f80cbd2ebf">a40e2cebc8</a></td>
<td>fix</td>
<td>fix ordering of view queries metadata in JIT mode</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/885a1a1d9757adfa8766d9b369c848a277438c31">885a1a1d97</a></td>
<td>fix</td>
<td>guard against non-object events and avoid listener wrapper identity
mismatch</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/7a64aff9b59999077ea915486a7fa0b97a286659">7a64aff9b5</a></td>
<td>fix</td>
<td>prevent event replay double-invocation when element hydrates before
app stability</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/be1f80a253b8ee27ed7d8de2287d6895c4821909">be1f80a253</a></td>
<td>fix</td>
<td>ensure origin has a trailing slash when parsing url</td>
</tr>
</tbody>
</table>
<!-- raw HTML omitted -->
<p><!-- raw HTML omitted --><!-- raw HTML omitted --></p>
<h1>22.0.0-next.9 (2026-04-22)</h1>
<h2>Breaking Changes</h2>
<h3>router</h3>
<ul>
<li>
<p>paramsInheritanceStrategy now defaults to 'always'</p>
<p>The default value of paramsInheritanceStrategy has been changed from
'emptyOnly' to 'always'. This means that route parameters are inherited
from all parent routes by default. To restore the previous behavior, set
paramsInheritanceStrategy to 'emptyOnly' in your router
configuration.</p>
</li>
</ul>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/8f3d0b9d97424e058eb7bce57d80833fb68dec4a">8f3d0b9d97</a></td>
<td>feat</td>
<td>introduce <code>@Service</code> decorator</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/9f479ae9641a5c928f8eeab9c7846245002b3eff">9f479ae964</a></td>
<td>feat</td>
<td>Update Testability to use PendingTasks for stability indicator</td>
</tr>
</tbody>
</table>
<h3>docs</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/b24b4cb699c325fc2ce40681724341baaabf277b">b24b4cb699</a></td>
<td>fix</td>
<td>link formatting in &quot;Animating your Application with
CSS&quot;</td>
</tr>
</tbody>
</table>
<h3>migrations</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/b395173cf206b8c04c5ab74298e640c9086d0bac">b395173cf2</a></td>
<td>fix</td>
<td>fix NgClass leaving trailing comma after removal</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/6eff4395467de51a46656d79d957b448b32dde0c">6eff439546</a></td>
<td>fix</td>
<td>restore internal URL on popstate when <code>browserUrl</code> is
used</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/17d10f7a9921429d0192df6925d20d7236425c9a">17d10f7a99</a></td>
<td>fix</td>
<td>set default paramsInheritanceStrategy to 'always'</td>
</tr>
</tbody>
</table>
<!-- raw HTML omitted -->
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/angular/angular/commit/4f5d8a2c0b5e38d4debc4293945270cea4a9590d"><code>4f5d8a2</code></a>
fix(compiler): let declaration span not including end character</li>
<li><a
href="https://github.com/angular/angular/commit/a4f312060cdf745e4fb0b15eda24ee2b4df0440c"><code>a4f3120</code></a>
refactor(compiler): require a reference in DirectiveMeta</li>
<li><a
href="https://github.com/angular/angular/commit/de533fe49181ee7409fd0b0ae4c0391a1e220ee6"><code>de533fe</code></a>
refactor(compiler-cli): move ClassPropertyMapping into compiler</li>
<li><a
href="https://github.com/angular/angular/commit/ea1e34c4ddf404cde8d5c4ba0ba762bb0b9edbf8"><code>ea1e34c</code></a>
refactor(compiler): move matchSource into base metadata</li>
<li><a
href="https://github.com/angular/angular/commit/e40d378f3e3e7e57a45c8fbd9565ee06a3a6a13f"><code>e40d378</code></a>
fix(compiler): handle nested brackets in host object bindings</li>
<li>See full diff in <a
href="https://github.com/angular/angular/commits/v21.2.11/packages/compiler">compare
view</a></li>
</ul>
</details>
<br />

Updates `@angular/core` from 21.2.7 to 21.2.11
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/angular/angular/releases">@​angular/core's
releases</a>.</em></p>
<blockquote>
<h2>21.2.11</h2>
<h3>common</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/10ad3c06923453ae0ec06b06e664ce05900a4ff6"><img
src="https://img.shields.io/badge/10ad3c0692-fix-green" alt="fix -
10ad3c0692" /></a></td>
<td>prevent focus from scrollToAnchor</td>
</tr>
</tbody>
</table>
<h3>compiler</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/4f5d8a2c0b5e38d4debc4293945270cea4a9590d"><img
src="https://img.shields.io/badge/4f5d8a2c0b-fix-green" alt="fix -
4f5d8a2c0b" /></a></td>
<td>let declaration span not including end character</td>
</tr>
</tbody>
</table>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/a40e2cebc878965c3e21bfb61658f3f80cbd2ebf"><img
src="https://img.shields.io/badge/a40e2cebc8-fix-green" alt="fix -
a40e2cebc8" /></a></td>
<td>fix ordering of view queries metadata in JIT mode</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/885a1a1d9757adfa8766d9b369c848a277438c31"><img
src="https://img.shields.io/badge/885a1a1d97-fix-green" alt="fix -
885a1a1d97" /></a></td>
<td>guard against non-object events and avoid listener wrapper identity
mismatch</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/7a64aff9b59999077ea915486a7fa0b97a286659"><img
src="https://img.shields.io/badge/7a64aff9b5-fix-green" alt="fix -
7a64aff9b5" /></a></td>
<td>prevent event replay double-invocation when element hydrates before
app stability</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/be1f80a253b8ee27ed7d8de2287d6895c4821909"><img
src="https://img.shields.io/badge/be1f80a253-fix-green" alt="fix -
be1f80a253" /></a></td>
<td>ensure origin has a trailing slash when parsing url</td>
</tr>
</tbody>
</table>
<h2>21.2.10</h2>
<h3>docs</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/0d5ee9ae1ba4b7acd8f27a059a778f0b4bd8a5bd"><img
src="https://img.shields.io/badge/0d5ee9ae1b-fix-green" alt="fix -
0d5ee9ae1b" /></a></td>
<td>link formatting in &quot;Animating your Application with
CSS&quot;</td>
</tr>
</tbody>
</table>
<h3>migrations</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/5533ab4f56f574bc9365cf0573c4a34a3ab5aaf1"><img
src="https://img.shields.io/badge/5533ab4f56-fix-green" alt="fix -
5533ab4f56" /></a></td>
<td>fix NgClass leaving trailing comma after removal</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/580212c995751c4bf4ce8a49df4167498743e0ea"><img
src="https://img.shields.io/badge/580212c995-fix-green" alt="fix -
580212c995" /></a></td>
<td>restore internal URL on popstate when <code>browserUrl</code> is
used</td>
</tr>
</tbody>
</table>
<h2>21.2.9</h2>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/f603d4714fa184aad34a6f7f9ea4e79c8af3afac"><img
src="https://img.shields.io/badge/f603d4714f-fix-green" alt="fix -
f603d4714f" /></a></td>
<td>escape forward slashes in transfer state to prevent crawler
indexing</td>
</tr>
</tbody>
</table>
<h3>http</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/540536c386f2c735a700c2c9e2697a88dcb3d4ec"><img
src="https://img.shields.io/badge/540536c386-fix-green" alt="fix -
540536c386" /></a></td>
<td>add CSP nonce support to JsonpClientBackend</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/63a857b874172766451aa75ed3347ba50f0ee229"><img
src="https://img.shields.io/badge/63a857b874-fix-green" alt="fix -
63a857b874" /></a></td>
<td>Don't on Passthru outside of reactive context</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/e0b5078cf2ebe79a6de85e9123148ae948b3d81d"><img
src="https://img.shields.io/badge/e0b5078cf2-fix-green" alt="fix -
e0b5078cf2" /></a></td>
<td>prevent SSRF bypasses via protocol-relative and backslash URLs</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<p>| Commit | Description |</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/angular/angular/blob/main/CHANGELOG.md">@​angular/core's
changelog</a>.</em></p>
<blockquote>
<h1>21.2.11 (2026-04-29)</h1>
<h3>common</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/10ad3c06923453ae0ec06b06e664ce05900a4ff6">10ad3c0692</a></td>
<td>fix</td>
<td>prevent focus from scrollToAnchor</td>
</tr>
</tbody>
</table>
<h3>compiler</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/4f5d8a2c0b5e38d4debc4293945270cea4a9590d">4f5d8a2c0b</a></td>
<td>fix</td>
<td>let declaration span not including end character</td>
</tr>
</tbody>
</table>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/a40e2cebc878965c3e21bfb61658f3f80cbd2ebf">a40e2cebc8</a></td>
<td>fix</td>
<td>fix ordering of view queries metadata in JIT mode</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/885a1a1d9757adfa8766d9b369c848a277438c31">885a1a1d97</a></td>
<td>fix</td>
<td>guard against non-object events and avoid listener wrapper identity
mismatch</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/7a64aff9b59999077ea915486a7fa0b97a286659">7a64aff9b5</a></td>
<td>fix</td>
<td>prevent event replay double-invocation when element hydrates before
app stability</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/be1f80a253b8ee27ed7d8de2287d6895c4821909">be1f80a253</a></td>
<td>fix</td>
<td>ensure origin has a trailing slash when parsing url</td>
</tr>
</tbody>
</table>
<!-- raw HTML omitted -->
<p><!-- raw HTML omitted --><!-- raw HTML omitted --></p>
<h1>22.0.0-next.9 (2026-04-22)</h1>
<h2>Breaking Changes</h2>
<h3>router</h3>
<ul>
<li>
<p>paramsInheritanceStrategy now defaults to 'always'</p>
<p>The default value of paramsInheritanceStrategy has been changed from
'emptyOnly' to 'always'. This means that route parameters are inherited
from all parent routes by default. To restore the previous behavior, set
paramsInheritanceStrategy to 'emptyOnly' in your router
configuration.</p>
</li>
</ul>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/8f3d0b9d97424e058eb7bce57d80833fb68dec4a">8f3d0b9d97</a></td>
<td>feat</td>
<td>introduce <code>@Service</code> decorator</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/9f479ae9641a5c928f8eeab9c7846245002b3eff">9f479ae964</a></td>
<td>feat</td>
<td>Update Testability to use PendingTasks for stability indicator</td>
</tr>
</tbody>
</table>
<h3>docs</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/b24b4cb699c325fc2ce40681724341baaabf277b">b24b4cb699</a></td>
<td>fix</td>
<td>link formatting in &quot;Animating your Application with
CSS&quot;</td>
</tr>
</tbody>
</table>
<h3>migrations</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/b395173cf206b8c04c5ab74298e640c9086d0bac">b395173cf2</a></td>
<td>fix</td>
<td>fix NgClass leaving trailing comma after removal</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/6eff4395467de51a46656d79d957b448b32dde0c">6eff439546</a></td>
<td>fix</td>
<td>restore internal URL on popstate when <code>browserUrl</code> is
used</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/17d10f7a9921429d0192df6925d20d7236425c9a">17d10f7a99</a></td>
<td>fix</td>
<td>set default paramsInheritanceStrategy to 'always'</td>
</tr>
</tbody>
</table>
<!-- raw HTML omitted -->
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/angular/angular/commit/4900e453e1a2e9351ad2672a804d876ff5a62968"><code>4900e45</code></a>
build: update cross-repo angular dependencies</li>
<li><a
href="https://github.com/angular/angular/commit/a40e2cebc878965c3e21bfb61658f3f80cbd2ebf"><code>a40e2ce</code></a>
fix(core): fix ordering of view queries metadata in JIT mode</li>
<li><a
href="https://github.com/angular/angular/commit/9bcbf376413632590ef1fb1cebe68d049d9bd45b"><code>9bcbf37</code></a>
refactor(core): fix bundling symbol test</li>
<li><a
href="https://github.com/angular/angular/commit/885a1a1d9757adfa8766d9b369c848a277438c31"><code>885a1a1</code></a>
fix(core): guard against non-object events and avoid listener wrapper
identit...</li>
<li><a
href="https://github.com/angular/angular/commit/7a64aff9b59999077ea915486a7fa0b97a286659"><code>7a64aff</code></a>
fix(core): prevent event replay double-invocation when element hydrates
befor...</li>
<li><a
href="https://github.com/angular/angular/commit/750af5b12325277e04a345aaa74256bd8a1fbf26"><code>750af5b</code></a>
build: update cross-repo angular dependencies to v21.2.8</li>
<li><a
href="https://github.com/angular/angular/commit/5533ab4f56f574bc9365cf0573c4a34a3ab5aaf1"><code>5533ab4</code></a>
fix(migrations): fix NgClass leaving trailing comma after removal</li>
<li><a
href="https://github.com/angular/angular/commit/2b9954fd3dab124bfd88a49fc46f77271831c778"><code>2b9954f</code></a>
fix(migrations): fix NgClass leaving trailing comma after removal</li>
<li><a
href="https://github.com/angular/angular/commit/c9215b353975163c1d2b67d2fffe499ae82ceeef"><code>c9215b3</code></a>
Revert &quot;refactor(core): complete removal of deprecated
<code>createNgModuleRef</code> al...</li>
<li><a
href="https://github.com/angular/angular/commit/d88d6ed69e05decd2957e1235615926f49fb35c6"><code>d88d6ed</code></a>
refactor(core): complete removal of deprecated
<code>createNgModuleRef</code> alias</li>
<li>Additional commits viewable in <a
href="https://github.com/angular/angular/commits/v21.2.11/packages/core">compare
view</a></li>
</ul>
</details>
<br />

Updates `@angular/forms` from 21.2.7 to 21.2.11
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/angular/angular/releases">@​angular/forms's
releases</a>.</em></p>
<blockquote>
<h2>21.2.11</h2>
<h3>common</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/10ad3c06923453ae0ec06b06e664ce05900a4ff6"><img
src="https://img.shields.io/badge/10ad3c0692-fix-green" alt="fix -
10ad3c0692" /></a></td>
<td>prevent focus from scrollToAnchor</td>
</tr>
</tbody>
</table>
<h3>compiler</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/4f5d8a2c0b5e38d4debc4293945270cea4a9590d"><img
src="https://img.shields.io/badge/4f5d8a2c0b-fix-green" alt="fix -
4f5d8a2c0b" /></a></td>
<td>let declaration span not including end character</td>
</tr>
</tbody>
</table>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/a40e2cebc878965c3e21bfb61658f3f80cbd2ebf"><img
src="https://img.shields.io/badge/a40e2cebc8-fix-green" alt="fix -
a40e2cebc8" /></a></td>
<td>fix ordering of view queries metadata in JIT mode</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/885a1a1d9757adfa8766d9b369c848a277438c31"><img
src="https://img.shields.io/badge/885a1a1d97-fix-green" alt="fix -
885a1a1d97" /></a></td>
<td>guard against non-object events and avoid listener wrapper identity
mismatch</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/7a64aff9b59999077ea915486a7fa0b97a286659"><img
src="https://img.shields.io/badge/7a64aff9b5-fix-green" alt="fix -
7a64aff9b5" /></a></td>
<td>prevent event replay double-invocation when element hydrates before
app stability</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/be1f80a253b8ee27ed7d8de2287d6895c4821909"><img
src="https://img.shields.io/badge/be1f80a253-fix-green" alt="fix -
be1f80a253" /></a></td>
<td>ensure origin has a trailing slash when parsing url</td>
</tr>
</tbody>
</table>
<h2>21.2.10</h2>
<h3>docs</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/0d5ee9ae1ba4b7acd8f27a059a778f0b4bd8a5bd"><img
src="https://img.shields.io/badge/0d5ee9ae1b-fix-green" alt="fix -
0d5ee9ae1b" /></a></td>
<td>link formatting in &quot;Animating your Application with
CSS&quot;</td>
</tr>
</tbody>
</table>
<h3>migrations</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/5533ab4f56f574bc9365cf0573c4a34a3ab5aaf1"><img
src="https://img.shields.io/badge/5533ab4f56-fix-green" alt="fix -
5533ab4f56" /></a></td>
<td>fix NgClass leaving trailing comma after removal</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/580212c995751c4bf4ce8a49df4167498743e0ea"><img
src="https://img.shields.io/badge/580212c995-fix-green" alt="fix -
580212c995" /></a></td>
<td>restore internal URL on popstate when <code>browserUrl</code> is
used</td>
</tr>
</tbody>
</table>
<h2>21.2.9</h2>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/f603d4714fa184aad34a6f7f9ea4e79c8af3afac"><img
src="https://img.shields.io/badge/f603d4714f-fix-green" alt="fix -
f603d4714f" /></a></td>
<td>escape forward slashes in transfer state to prevent crawler
indexing</td>
</tr>
</tbody>
</table>
<h3>http</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/540536c386f2c735a700c2c9e2697a88dcb3d4ec"><img
src="https://img.shields.io/badge/540536c386-fix-green" alt="fix -
540536c386" /></a></td>
<td>add CSP nonce support to JsonpClientBackend</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/63a857b874172766451aa75ed3347ba50f0ee229"><img
src="https://img.shields.io/badge/63a857b874-fix-green" alt="fix -
63a857b874" /></a></td>
<td>Don't on Passthru outside of reactive context</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/e0b5078cf2ebe79a6de85e9123148ae948b3d81d"><img
src="https://img.shields.io/badge/e0b5078cf2-fix-green" alt="fix -
e0b5078cf2" /></a></td>
<td>prevent SSRF bypasses via protocol-relative and backslash URLs</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<p>| Commit | Description |</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/angular/angular/blob/main/CHANGELOG.md">@​angular/forms's
changelog</a>.</em></p>
<blockquote>
<h1>21.2.11 (2026-04-29)</h1>
<h3>common</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/10ad3c06923453ae0ec06b06e664ce05900a4ff6">10ad3c0692</a></td>
<td>fix</td>
<td>prevent focus from scrollToAnchor</td>
</tr>
</tbody>
</table>
<h3>compiler</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/4f5d8a2c0b5e38d4debc4293945270cea4a9590d">4f5d8a2c0b</a></td>
<td>fix</td>
<td>let declaration span not including end character</td>
</tr>
</tbody>
</table>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/a40e2cebc878965c3e21bfb61658f3f80cbd2ebf">a40e2cebc8</a></td>
<td>fix</td>
<td>fix ordering of view queries metadata in JIT mode</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/885a1a1d9757adfa8766d9b369c848a277438c31">885a1a1d97</a></td>
<td>fix</td>
<td>guard against non-object events and avoid listener wrapper identity
mismatch</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/7a64aff9b59999077ea915486a7fa0b97a286659">7a64aff9b5</a></td>
<td>fix</td>
<td>prevent event replay double-invocation when element hydrates before
app stability</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/be1f80a253b8ee27ed7d8de2287d6895c4821909">be1f80a253</a></td>
<td>fix</td>
<td>ensure origin has a trailing slash when parsing url</td>
</tr>
</tbody>
</table>
<!-- raw HTML omitted -->
<p><!-- raw HTML omitted --><!-- raw HTML omitted --></p>
<h1>22.0.0-next.9 (2026-04-22)</h1>
<h2>Breaking Changes</h2>
<h3>router</h3>
<ul>
<li>
<p>paramsInheritanceStrategy now defaults to 'always'</p>
<p>The default value of paramsInheritanceStrategy has been changed from
'emptyOnly' to 'always'. This means that route parameters are inherited
from all parent routes by default. To restore the previous behavior, set
paramsInheritanceStrategy to 'emptyOnly' in your router
configuration.</p>
</li>
</ul>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/8f3d0b9d97424e058eb7bce57d80833fb68dec4a">8f3d0b9d97</a></td>
<td>feat</td>
<td>introduce <code>@Service</code> decorator</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/9f479ae9641a5c928f8eeab9c7846245002b3eff">9f479ae964</a></td>
<td>feat</td>
<td>Update Testability to use PendingTasks for stability indicator</td>
</tr>
</tbody>
</table>
<h3>docs</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/b24b4cb699c325fc2ce40681724341baaabf277b">b24b4cb699</a></td>
<td>fix</td>
<td>link formatting in &quot;Animating your Application with
CSS&quot;</td>
</tr>
</tbody>
</table>
<h3>migrations</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/b395173cf206b8c04c5ab74298e640c9086d0bac">b395173cf2</a></td>
<td>fix</td>
<td>fix NgClass leaving trailing comma after removal</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/6eff4395467de51a46656d79d957b448b32dde0c">6eff439546</a></td>
<td>fix</td>
<td>restore internal URL on popstate when <code>browserUrl</code> is
used</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/17d10f7a9921429d0192df6925d20d7236425c9a">17d10f7a99</a></td>
<td>fix</td>
<td>set default paramsInheritanceStrategy to 'always'</td>
</tr>
</tbody>
</table>
<!-- raw HTML omitted -->
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/angular/angular/commit/600da64ba4df4b73ee00ab1b13f490a7de436ff6"><code>600da64</code></a>
docs(forms): add NG01902 error reference and link to docs</li>
<li><a
href="https://github.com/angular/angular/commit/dc9581469fe552faf45984362508d7e05adb5930"><code>dc95814</code></a>
docs: add documentation for NG1002</li>
<li><a
href="https://github.com/angular/angular/commit/b0dc2fbfcb909c558c7dcff89c2fe47c89878991"><code>b0dc2fb</code></a>
docs(forms): clarify disabled FormArray value behavior</li>
<li>See full diff in <a
href="https://github.com/angular/angular/commits/v21.2.11/packages/forms">compare
view</a></li>
</ul>
</details>
<br />

Updates `@angular/platform-browser` from 21.2.7 to 21.2.11
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/angular/angular/releases">@​angular/platform-browser's
releases</a>.</em></p>
<blockquote>
<h2>21.2.11</h2>
<h3>common</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/10ad3c06923453ae0ec06b06e664ce05900a4ff6"><img
src="https://img.shields.io/badge/10ad3c0692-fix-green" alt="fix -
10ad3c0692" /></a></td>
<td>prevent focus from scrollToAnchor</td>
</tr>
</tbody>
</table>
<h3>compiler</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/4f5d8a2c0b5e38d4debc4293945270cea4a9590d"><img
src="https://img.shields.io/badge/4f5d8a2c0b-fix-green" alt="fix -
4f5d8a2c0b" /></a></td>
<td>let declaration span not including end character</td>
</tr>
</tbody>
</table>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/a40e2cebc878965c3e21bfb61658f3f80cbd2ebf"><img
src="https://img.shields.io/badge/a40e2cebc8-fix-green" alt="fix -
a40e2cebc8" /></a></td>
<td>fix ordering of view queries metadata in JIT mode</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/885a1a1d9757adfa8766d9b369c848a277438c31"><img
src="https://img.shields.io/badge/885a1a1d97-fix-green" alt="fix -
885a1a1d97" /></a></td>
<td>guard against non-object events and avoid listener wrapper identity
mismatch</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/7a64aff9b59999077ea915486a7fa0b97a286659"><img
src="https://img.shields.io/badge/7a64aff9b5-fix-green" alt="fix -
7a64aff9b5" /></a></td>
<td>prevent event replay double-invocation when element hydrates before
app stability</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/be1f80a253b8ee27ed7d8de2287d6895c4821909"><img
src="https://img.shields.io/badge/be1f80a253-fix-green" alt="fix -
be1f80a253" /></a></td>
<td>ensure origin has a trailing slash when parsing url</td>
</tr>
</tbody>
</table>
<h2>21.2.10</h2>
<h3>docs</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/0d5ee9ae1ba4b7acd8f27a059a778f0b4bd8a5bd"><img
src="https://img.shields.io/badge/0d5ee9ae1b-fix-green" alt="fix -
0d5ee9ae1b" /></a></td>
<td>link formatting in &quot;Animating your Application with
CSS&quot;</td>
</tr>
</tbody>
</table>
<h3>migrations</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/5533ab4f56f574bc9365cf0573c4a34a3ab5aaf1"><img
src="https://img.shields.io/badge/5533ab4f56-fix-green" alt="fix -
5533ab4f56" /></a></td>
<td>fix NgClass leaving trailing comma after removal</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/580212c995751c4bf4ce8a49df4167498743e0ea"><img
src="https://img.shields.io/badge/580212c995-fix-green" alt="fix -
580212c995" /></a></td>
<td>restore internal URL on popstate when <code>browserUrl</code> is
used</td>
</tr>
</tbody>
</table>
<h2>21.2.9</h2>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/f603d4714fa184aad34a6f7f9ea4e79c8af3afac"><img
src="https://img.shields.io/badge/f603d4714f-fix-green" alt="fix -
f603d4714f" /></a></td>
<td>escape forward slashes in transfer state to prevent crawler
indexing</td>
</tr>
</tbody>
</table>
<h3>http</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/540536c386f2c735a700c2c9e2697a88dcb3d4ec"><img
src="https://img.shields.io/badge/540536c386-fix-green" alt="fix -
540536c386" /></a></td>
<td>add CSP nonce support to JsonpClientBackend</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/63a857b874172766451aa75ed3347ba50f0ee229"><img
src="https://img.shields.io/badge/63a857b874-fix-green" alt="fix -
63a857b874" /></a></td>
<td>Don't on Passthru outside of reactive context</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/e0b5078cf2ebe79a6de85e9123148ae948b3d81d"><img
src="https://img.shields.io/badge/e0b5078cf2-fix-green" alt="fix -
e0b5078cf2" /></a></td>
<td>prevent SSRF bypasses via protocol-relative and backslash URLs</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<p>| Commit | Description |</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/angular/angular/blob/main/CHANGELOG.md">@​angular/platform-browser's
changelog</a>.</em></p>
<blockquote>
<h1>21.2.11 (2026-04-29)</h1>
<h3>common</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/10ad3c06923453ae0ec06b06e664ce05900a4ff6">10ad3c0692</a></td>
<td>fix</td>
<td>prevent focus from scrollToAnchor</td>
</tr>
</tbody>
</table>
<h3>compiler</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/4f5d8a2c0b5e38d4debc4293945270cea4a9590d">4f5d8a2c0b</a></td>
<td>fix</td>
<td>let declaration span not including end character</td>
</tr>
</tbody>
</table>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/a40e2cebc878965c3e21bfb61658f3f80cbd2ebf">a40e2cebc8</a></td>
<td>fix</td>
<td>fix ordering of view queries metadata in JIT mode</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/885a1a1d9757adfa8766d9b369c848a277438c31">885a1a1d97</a></td>
<td>fix</td>
<td>guard against non-object events and avoid listener wrapper identity
mismatch</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/7a64aff9b59999077ea915486a7fa0b97a286659">7a64aff9b5</a></td>
<td>fix</td>
<td>prevent event replay double-invocation when element hydrates before
app stability</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/be1f80a253b8ee27ed7d8de2287d6895c4821909">be1f80a253</a></td>
<td>fix</td>
<td>ensure origin has a trailing slash when parsing url</td>
</tr>
</tbody>
</table>
<!-- raw HTML omitted -->
<p><!-- raw HTML omitted --><!-- raw HTML omitted --></p>
<h1>22.0.0-next.9 (2026-04-22)</h1>
<h2>Breaking Changes</h2>
<h3>router</h3>
<ul>
<li>
<p>paramsInheritanceStrategy now defaults to 'always'</p>
<p>The default value of paramsInheritanceStrategy has been changed from
'emptyOnly' to 'always'. This means that route parameters are inherited
from all parent routes by default. To restore the previous behavior, set
paramsInheritanceStrategy to 'emptyOnly' in your router
configuration.</p>
</li>
</ul>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/8f3d0b9d97424e058eb7bce57d80833fb68dec4a">8f3d0b9d97</a></td>
<td>feat</td>
<td>introduce <code>@Service</code> decorator</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/9f479ae9641a5c928f8eeab9c7846245002b3eff">9f479ae964</a></td>
<td>feat</td>
<td>Update Testability to use PendingTasks for stability indicator</td>
</tr>
</tbody>
</table>
<h3>docs</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/b24b4cb699c325fc2ce40681724341baaabf277b">b24b4cb699</a></td>
<td>fix</td>
<td>link formatting in &quot;Animating your Application with
CSS&quot;</td>
</tr>
</tbody>
</table>
<h3>migrations</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/b395173cf206b8c04c5ab74298e640c9086d0bac">b395173cf2</a></td>
<td>fix</td>
<td>fix NgClass leaving trailing comma after removal</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/6eff4395467de51a46656d79d957b448b32dde0c">6eff439546</a></td>
<td>fix</td>
<td>restore internal URL on popstate when <code>browserUrl</code> is
used</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/17d10f7a9921429d0192df6925d20d7236425c9a">17d10f7a99</a></td>
<td>fix</td>
<td>set default paramsInheritanceStrategy to 'always'</td>
</tr>
</tbody>
</table>
<!-- raw HTML omitted -->
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/angular/angular/commits/v21.2.11/packages/platform-browser">compare
view</a></li>
</ul>
</details>
<br />

Updates `@angular/router` from 21.2.7 to 21.2.11
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/angular/angular/releases">@​angular/router's
releases</a>.</em></p>
<blockquote>
<h2>21.2.11</h2>
<h3>common</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/10ad3c06923453ae0ec06b06e664ce05900a4ff6"><img
src="https://img.shields.io/badge/10ad3c0692-fix-green" alt="fix -
10ad3c0692" /></a></td>
<td>prevent focus from scrollToAnchor</td>
</tr>
</tbody>
</table>
<h3>compiler</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/4f5d8a2c0b5e38d4debc4293945270cea4a9590d"><img
src="https://img.shields.io/badge/4f5d8a2c0b-fix-green" alt="fix -
4f5d8a2c0b" /></a></td>
<td>let declaration span not including end character</td>
</tr>
</tbody>
</table>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/a40e2cebc878965c3e21bfb61658f3f80cbd2ebf"><img
src="https://img.shields.io/badge/a40e2cebc8-fix-green" alt="fix -
a40e2cebc8" /></a></td>
<td>fix ordering of view queries metadata in JIT mode</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/885a1a1d9757adfa8766d9b369c848a277438c31"><img
src="https://img.shields.io/badge/885a1a1d97-fix-green" alt="fix -
885a1a1d97" /></a></td>
<td>guard against non-object events and avoid listener wrapper identity
mismatch</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/7a64aff9b59999077ea915486a7fa0b97a286659"><img
src="https://img.shields.io/badge/7a64aff9b5-fix-green" alt="fix -
7a64aff9b5" /></a></td>
<td>prevent event replay double-invocation when element hydrates before
app stability</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/be1f80a253b8ee27ed7d8de2287d6895c4821909"><img
src="https://img.shields.io/badge/be1f80a253-fix-green" alt="fix -
be1f80a253" /></a></td>
<td>ensure origin has a trailing slash when parsing url</td>
</tr>
</tbody>
</table>
<h2>21.2.10</h2>
<h3>docs</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/0d5ee9ae1ba4b7acd8f27a059a778f0b4bd8a5bd"><img
src="https://img.shields.io/badge/0d5ee9ae1b-fix-green" alt="fix -
0d5ee9ae1b" /></a></td>
<td>link formatting in &quot;Animating your Application with
CSS&quot;</td>
</tr>
</tbody>
</table>
<h3>migrations</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/5533ab4f56f574bc9365cf0573c4a34a3ab5aaf1"><img
src="https://img.shields.io/badge/5533ab4f56-fix-green" alt="fix -
5533ab4f56" /></a></td>
<td>fix NgClass leaving trailing comma after removal</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/580212c995751c4bf4ce8a49df4167498743e0ea"><img
src="https://img.shields.io/badge/580212c995-fix-green" alt="fix -
580212c995" /></a></td>
<td>restore internal URL on popstate when <code>browserUrl</code> is
used</td>
</tr>
</tbody>
</table>
<h2>21.2.9</h2>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/f603d4714fa184aad34a6f7f9ea4e79c8af3afac"><img
src="https://img.shields.io/badge/f603d4714f-fix-green" alt="fix -
f603d4714f" /></a></td>
<td>escape forward slashes in transfer state to prevent crawler
indexing</td>
</tr>
</tbody>
</table>
<h3>http</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/540536c386f2c735a700c2c9e2697a88dcb3d4ec"><img
src="https://img.shields.io/badge/540536c386-fix-green" alt="fix -
540536c386" /></a></td>
<td>add CSP nonce support to JsonpClientBackend</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/63a857b874172766451aa75ed3347ba50f0ee229"><img
src="https://img.shields.io/badge/63a857b874-fix-green" alt="fix -
63a857b874" /></a></td>
<td>Don't on Passthru outside of reactive context</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/e0b5078cf2ebe79a6de85e9123148ae948b3d81d"><img
src="https://img.shields.io/badge/e0b5078cf2-fix-green" alt="fix -
e0b5078cf2" /></a></td>
<td>prevent SSRF bypasses via protocol-relative and backslash URLs</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<p>| Commit | Description |</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/angular/angular/blob/main/CHANGELOG.md">@​angular/router's
changelog</a>.</em></p>
<blockquote>
<h1>21.2.11 (2026-04-29)</h1>
<h3>common</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/10ad3c06923453ae0ec06b06e664ce05900a4ff6">10ad3c0692</a></td>
<td>fix</td>
<td>prevent focus from scrollToAnchor</td>
</tr>
</tbody>
</table>
<h3>compiler</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/4f5d8a2c0b5e38d4debc4293945270cea4a9590d">4f5d8a2c0b</a></td>
<td>fix</td>
<td>let declaration span not including end character</td>
</tr>
</tbody>
</table>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/a40e2cebc878965c3e21bfb61658f3f80cbd2ebf">a40e2cebc8</a></td>
<td>fix</td>
<td>fix ordering of view queries metadata in JIT mode</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/885a1a1d9757adfa8766d9b369c848a277438c31">885a1a1d97</a></td>
<td>fix</td>
<td>guard against non-object events and avoid listener wrapper identity
mismatch</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/7a64aff9b59999077ea915486a7fa0b97a286659">7a64aff9b5</a></td>
<td>fix</td>
<td>prevent event replay double-invocation when element hydrates before
app stability</td>
</tr>
</tbody>
</table>
<h3>platform-server</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/be1f80a253b8ee27ed7d8de2287d6895c4821909">be1f80a253</a></td>
<td>fix</td>
<td>ensure origin has a trailing slash when parsing url</td>
</tr>
</tbody>
</table>
<!-- raw HTML omitted -->
<p><!-- raw HTML omitted --><!-- raw HTML omitted --></p>
<h1>22.0.0-next.9 (2026-04-22)</h1>
<h2>Breaking Changes</h2>
<h3>router</h3>
<ul>
<li>
<p>paramsInheritanceStrategy now defaults to 'always'</p>
<p>The default value of paramsInheritanceStrategy has been changed from
'emptyOnly' to 'always'. This means that route parameters are inherited
from all parent routes by default. To restore the previous behavior, set
paramsInheritanceStrategy to 'emptyOnly' in your router
configuration.</p>
</li>
</ul>
<h3>core</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/8f3d0b9d97424e058eb7bce57d80833fb68dec4a">8f3d0b9d97</a></td>
<td>feat</td>
<td>introduce <code>@Service</code> decorator</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/9f479ae9641a5c928f8eeab9c7846245002b3eff">9f479ae964</a></td>
<td>feat</td>
<td>Update Testability to use PendingTasks for stability indicator</td>
</tr>
</tbody>
</table>
<h3>docs</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/b24b4cb699c325fc2ce40681724341baaabf277b">b24b4cb699</a></td>
<td>fix</td>
<td>link formatting in &quot;Animating your Application with
CSS&quot;</td>
</tr>
</tbody>
</table>
<h3>migrations</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/b395173cf206b8c04c5ab74298e640c9086d0bac">b395173cf2</a></td>
<td>fix</td>
<td>fix NgClass leaving trailing comma after removal</td>
</tr>
</tbody>
</table>
<h3>router</h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Type</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular/commit/6eff4395467de51a46656d79d957b448b32dde0c">6eff439546</a></td>
<td>fix</td>
<td>restore internal URL on popstate when <code>browserUrl</code> is
used</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular/commit/17d10f7a9921429d0192df6925d20d7236425c9a">17d10f7a99</a></td>
<td>fix</td>
<td>set default paramsInheritanceStrategy to 'always'</td>
</tr>
</tbody>
</table>
<!-- raw HTML omitted -->
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/angular/angular/commit/fbe080f829a677610d6bc8ab68af5f4e969f8422"><code>fbe080f</code></a>
docs(router): Fix method name for retrieving stored handles</li>
<li><a
href="https://github.com/angular/angular/commit/1be52ad880933139852ca785a5bf19098d8d6594"><code>1be52ad</code></a>
docs: Align Router API docs with inject based DI</li>
<li><a
href="https://github.com/angular/angular/commit/fa4eff36cb288c4d16aa96bfeedaefdd211f74c2"><code>fa4eff3</code></a>
docs(docs-infra): Validate case-sensitive API symbol links in
<code>@link</code></li>
<li><a
href="https://github.com/angular/angular/commit/580212c995751c4bf4ce8a49df4167498743e0ea"><code>580212c</code></a>
fix(router): restore internal URL on popstate when
<code>browserUrl</code> is used</li>
<li><a
href="https://github.com/angular/angular/commit/684e9fd53daacb9e910f42d98c6017f9e5cb4180"><code>684e9fd</code></a>
fix(router): normalize multiple leading slashes in URL parser</li>
<li>See full diff in <a
href="https://github.com/angular/angular/commits/v21.2.11/packages/router">compare
view</a></li>
</ul>
</details>
<br />

Updates `@angular/build` from 21.2.6 to 21.2.9
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/angular/angular-cli/releases">@​angular/build's
releases</a>.</em></p>
<blockquote>
<h2>21.2.9</h2>
<h3><code>@​schematics/angular</code></h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular-cli/commit/e7abeb5c74024daf125070c9b4f7f8d2426bab66"><img
src="https://img.shields.io/badge/e7abeb5c7-fix-green" alt="fix -
e7abeb5c7" /></a></td>
<td>add missing imports for focus and skip APIs in
refactor-jasmine-vitest</td>
</tr>
</tbody>
</table>
<h3><code>@​angular/cli</code></h3>
<table>
<thead>
<tr>
<th>Commit</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><a
href="https://github.com/angular/angular-cli/commit/233deef01288c6aa39a048d6bd66a1f09595dc15"><img
src="https://img.shields.io/badge/233deef01-fix-green" alt="fix -
233deef01" /></a></td>
<td>fix broken img ref in ai-tutor</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular-cli/commit/7cea9885c64a747b391b74e6434cdf005c843766"><img
src="https://img.shields.io/badge/7cea9885c-fix-green" alt="fix -
7cea9885c" /></a></td>
<td>introduce initial package manager workspace awareness</td>
</tr>
<tr>
<td><a
href="https://github.com/angular/angular-cli/commit/5b1a5b7434323eb383df1f53c389fe9dc948a785"><img
src="https://img.s...

_Description has been truncated_

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-05 22:13:16 -07:00
dependabot[bot] 58c3de24f7 chore(deps-dev): bump the svelte group across 1 directory with 3 updates (#2368)
Bumps the svelte group with 3 updates in the / directory:
[@sveltejs/vite-plugin-svelte](https://github.com/sveltejs/vite-plugin-svelte/tree/HEAD/packages/vite-plugin-svelte),
[svelte](https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte)
and
[vitest-browser-svelte](https://github.com/vitest-community/vitest-browser-svelte).

Updates `@sveltejs/vite-plugin-svelte` from 7.0.0 to 7.1.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/sveltejs/vite-plugin-svelte/releases">@​sveltejs/vite-plugin-svelte's
releases</a>.</em></p>
<blockquote>
<h2><code>@​sveltejs/vite-plugin-svelte</code><a
href="https://github.com/7"><code>@​7</code></a>.1.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>fix: pass <code>typescript.onlyRemoveTypeImports</code> to
<code>transformWithOxc</code> in <code>vitePreprocess</code> so that
value imports are not dropped when they are only referenced in Svelte
template markup (<a
href="https://redirect.github.com/sveltejs/vite-plugin-svelte/pull/1326">#1326</a>)</p>
</li>
<li>
<p>fix: correctly resolve compiled CSS for optimised Svelte dependencies
on the server (<a
href="https://redirect.github.com/sveltejs/vite-plugin-svelte/pull/1336">#1336</a>)</p>
</li>
</ul>
<h2><code>@​sveltejs/vite-plugin-svelte</code><a
href="https://github.com/7"><code>@​7</code></a>.1.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>feat: enable optimizer for server environments during dev (<a
href="https://redirect.github.com/sveltejs/vite-plugin-svelte/pull/1328">#1328</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/sveltejs/vite-plugin-svelte/blob/main/packages/vite-plugin-svelte/CHANGELOG.md">@​sveltejs/vite-plugin-svelte's
changelog</a>.</em></p>
<blockquote>
<h2>7.1.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>fix: pass <code>typescript.onlyRemoveTypeImports</code> to
<code>transformWithOxc</code> in <code>vitePreprocess</code> so that
value imports are not dropped when they are only referenced in Svelte
template markup (<a
href="https://redirect.github.com/sveltejs/vite-plugin-svelte/pull/1326">#1326</a>)</p>
</li>
<li>
<p>fix: correctly resolve compiled CSS for optimised Svelte dependencies
on the server (<a
href="https://redirect.github.com/sveltejs/vite-plugin-svelte/pull/1336">#1336</a>)</p>
</li>
</ul>
<h2>7.1.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>feat: enable optimizer for server environments during dev (<a
href="https://redirect.github.com/sveltejs/vite-plugin-svelte/pull/1328">#1328</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/sveltejs/vite-plugin-svelte/commit/508d91bbdd495d62bc99fef26b9323977c20d5a9"><code>508d91b</code></a>
Version Packages (<a
href="https://github.com/sveltejs/vite-plugin-svelte/tree/HEAD/packages/vite-plugin-svelte/issues/1339">#1339</a>)</li>
<li><a
href="https://github.com/sveltejs/vite-plugin-svelte/commit/990e58cc9062a8d9b258d9248223e5cbd53935a1"><code>990e58c</code></a>
fix: correctly resolve Svelte CSS on the server during development (<a
href="https://github.com/sveltejs/vite-plugin-svelte/tree/HEAD/packages/vite-plugin-svelte/issues/1336">#1336</a>)</li>
<li><a
href="https://github.com/sveltejs/vite-plugin-svelte/commit/d5458a9c5122cb81fbf2a03c4a825124eb1a0f0d"><code>d5458a9</code></a>
fix: restore value imports stripped by oxc in script preprocessing (<a
href="https://github.com/sveltejs/vite-plugin-svelte/tree/HEAD/packages/vite-plugin-svelte/issues/1326">#1326</a>)</li>
<li><a
href="https://github.com/sveltejs/vite-plugin-svelte/commit/1c851266cb22f269156406a7c5e094aa8cdf475d"><code>1c85126</code></a>
Version Packages (<a
href="https://github.com/sveltejs/vite-plugin-svelte/tree/HEAD/packages/vite-plugin-svelte/issues/1331">#1331</a>)</li>
<li><a
href="https://github.com/sveltejs/vite-plugin-svelte/commit/1a4d225148d17af1dbab447dc9202b82e2bc1663"><code>1a4d225</code></a>
feat: enable optimizer for server environments during dev (<a
href="https://github.com/sveltejs/vite-plugin-svelte/tree/HEAD/packages/vite-plugin-svelte/issues/1328">#1328</a>)</li>
<li><a
href="https://github.com/sveltejs/vite-plugin-svelte/commit/d91be5f6dd2dff5806432e113c362e49aa19e356"><code>d91be5f</code></a>
fix: use correct pnpm catalog syntax</li>
<li><a
href="https://github.com/sveltejs/vite-plugin-svelte/commit/4d3afb492087e94581be7fc77f63b379b3a1c4e2"><code>4d3afb4</code></a>
chore: fix audit CI (<a
href="https://github.com/sveltejs/vite-plugin-svelte/tree/HEAD/packages/vite-plugin-svelte/issues/1327">#1327</a>)</li>
<li><a
href="https://github.com/sveltejs/vite-plugin-svelte/commit/8b3687bc2bf90ca81faadf42c8d9d2738851b968"><code>8b3687b</code></a>
use modern JSDoc imports (<a
href="https://github.com/sveltejs/vite-plugin-svelte/tree/HEAD/packages/vite-plugin-svelte/issues/1309">#1309</a>)</li>
<li>See full diff in <a
href="https://github.com/sveltejs/vite-plugin-svelte/commits/@sveltejs/vite-plugin-svelte@7.1.1/packages/vite-plugin-svelte">compare
view</a></li>
</ul>
</details>
<br />

Updates `svelte` from 5.55.1 to 5.55.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/sveltejs/svelte/releases">svelte's
releases</a>.</em></p>
<blockquote>
<h2>svelte@5.55.5</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>fix: don't mark deriveds while an effect is updating (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18124">#18124</a>)</p>
</li>
<li>
<p>fix: do not dispatch introstart event with animation of animate
directive (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18122">#18122</a>)</p>
</li>
</ul>
<h2>svelte@5.55.4</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>fix: never mark a child effect root as inert (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18111">#18111</a>)</p>
</li>
<li>
<p>fix: reset context after waiting on blockers of <code>@const</code>
expressions (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18100">#18100</a>)</p>
</li>
<li>
<p>fix: keep flushing new eager effects (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18102">#18102</a>)</p>
</li>
</ul>
<h2>svelte@5.55.3</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>fix: ensure proper HMR updates for dynamic components (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18079">#18079</a>)</p>
</li>
<li>
<p>fix: correctly calculate <code>@const</code> blockers (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18039">#18039</a>)</p>
</li>
<li>
<p>fix: freeze deriveds once their containing effects are destroyed (<a
href="https://redirect.github.com/sveltejs/svelte/pull/17921">#17921</a>)</p>
</li>
<li>
<p>fix: defer error boundary rendering in forks (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18076">#18076</a>)</p>
</li>
<li>
<p>fix: avoid false positives for reactivity loss warning (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18088">#18088</a>)</p>
</li>
</ul>
<h2>svelte@5.55.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>fix: invalidate <code>@const</code> tags based on visible references
in legacy mode (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18041">#18041</a>)</p>
</li>
<li>
<p>fix: handle parens in template expressions more robustly (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18075">#18075</a>)</p>
</li>
<li>
<p>fix: disallow <code>--</code> in <code>idPrefix</code> (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18038">#18038</a>)</p>
</li>
<li>
<p>fix: correct types for <code>ontoggle</code> on
<code>&lt;details&gt;</code> elements (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18063">#18063</a>)</p>
</li>
<li>
<p>fix: don't override <code>$destroy/set/on</code> instance methods in
dev mode (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18034">#18034</a>)</p>
</li>
<li>
<p>fix: unskip branches of earlier batches after commit (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18048">#18048</a>)</p>
</li>
<li>
<p>fix: never set derived.v inside fork (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18037">#18037</a>)</p>
</li>
<li>
<p>fix: skip rebase logic in non-async mode (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18040">#18040</a>)</p>
</li>
<li>
<p>fix: don't reset status of uninitialized deriveds (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18054">#18054</a>)</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/sveltejs/svelte/blob/main/packages/svelte/CHANGELOG.md">svelte's
changelog</a>.</em></p>
<blockquote>
<h2>5.55.5</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>fix: don't mark deriveds while an effect is updating (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18124">#18124</a>)</p>
</li>
<li>
<p>fix: do not dispatch introstart event with animation of animate
directive (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18122">#18122</a>)</p>
</li>
</ul>
<h2>5.55.4</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>fix: never mark a child effect root as inert (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18111">#18111</a>)</p>
</li>
<li>
<p>fix: reset context after waiting on blockers of <code>@const</code>
expressions (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18100">#18100</a>)</p>
</li>
<li>
<p>fix: keep flushing new eager effects (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18102">#18102</a>)</p>
</li>
</ul>
<h2>5.55.3</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>fix: ensure proper HMR updates for dynamic components (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18079">#18079</a>)</p>
</li>
<li>
<p>fix: correctly calculate <code>@const</code> blockers (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18039">#18039</a>)</p>
</li>
<li>
<p>fix: freeze deriveds once their containing effects are destroyed (<a
href="https://redirect.github.com/sveltejs/svelte/pull/17921">#17921</a>)</p>
</li>
<li>
<p>fix: defer error boundary rendering in forks (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18076">#18076</a>)</p>
</li>
<li>
<p>fix: avoid false positives for reactivity loss warning (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18088">#18088</a>)</p>
</li>
</ul>
<h2>5.55.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>fix: invalidate <code>@const</code> tags based on visible references
in legacy mode (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18041">#18041</a>)</p>
</li>
<li>
<p>fix: handle parens in template expressions more robustly (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18075">#18075</a>)</p>
</li>
<li>
<p>fix: disallow <code>--</code> in <code>idPrefix</code> (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18038">#18038</a>)</p>
</li>
<li>
<p>fix: correct types for <code>ontoggle</code> on
<code>&lt;details&gt;</code> elements (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18063">#18063</a>)</p>
</li>
<li>
<p>fix: don't override <code>$destroy/set/on</code> instance methods in
dev mode (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18034">#18034</a>)</p>
</li>
<li>
<p>fix: unskip branches of earlier batches after commit (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18048">#18048</a>)</p>
</li>
<li>
<p>fix: never set derived.v inside fork (<a
href="https://redirect.github.com/sveltejs/svelte/pull/18037">#18037</a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/sveltejs/svelte/commit/b771df346444d486243882099d2a36f88e32dde0"><code>b771df3</code></a>
Version Packages (<a
href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18125">#18125</a>)</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/8e7319063aa609cca2cbf8cdf1958e5392dd2fa0"><code>8e73190</code></a>
fix: don't mark deriveds while an effect is updating (<a
href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18124">#18124</a>)</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/51736e576d86cc8879211632e3969730c513236b"><code>51736e5</code></a>
fix: do not dispatch transition event with animation (<a
href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18122">#18122</a>)</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/7fddfbdbbde8813ee107d56f70f5ea6c3d3abbc3"><code>7fddfbd</code></a>
Version Packages (<a
href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18105">#18105</a>)</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/671fc2ea11b56f050f37f7e03564fb070bc8abea"><code>671fc2e</code></a>
fix: never mark a child effect root as inert (<a
href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18111">#18111</a>)</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/0ed8c282f96960f52eaf077ffbe6e53c181b3774"><code>0ed8c28</code></a>
fix: reset context after waiting on blockers of <code>@const</code>
expressions (<a
href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18100">#18100</a>)</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/273f1a85a4dbe2937f2d97afa2511e828eb8ebba"><code>273f1a8</code></a>
fix: keep flushing new eager effects (<a
href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18102">#18102</a>)</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/4a50e8ea3b7db1d8cd752b825032e4ce2878524b"><code>4a50e8e</code></a>
Version Packages (<a
href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18085">#18085</a>)</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/15588f5fbfe736f65e189e56047ee08678f5509f"><code>15588f5</code></a>
fix: avoid false positives for reactivity loss warning (<a
href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/18088">#18088</a>)</li>
<li><a
href="https://github.com/sveltejs/svelte/commit/0e9e76f29262b5f64ac7a5d4db37ec83c9181634"><code>0e9e76f</code></a>
fix: freeze deriveds once their containing effects are destroyed (<a
href="https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte/issues/17921">#17921</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/sveltejs/svelte/commits/svelte@5.55.5/packages/svelte">compare
view</a></li>
</ul>
</details>
<br />

Updates `vitest-browser-svelte` from 2.1.0 to 2.1.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vitest-community/vitest-browser-svelte/releases">vitest-browser-svelte's
releases</a>.</em></p>
<blockquote>
<h2>v2.1.1</h2>
<h3>   🐞 Bug Fixes</h3>
<ul>
<li>Move <code>@playwright/test</code> out of dependencies  -  by <a
href="https://github.com/ocavue"><code>@​ocavue</code></a> in <a
href="https://redirect.github.com/vitest-community/vitest-browser-svelte/issues/26">vitest-community/vitest-browser-svelte#26</a>
<a
href="https://github.com/vitest-community/vitest-browser-svelte/commit/ff94b22"><!--
raw HTML omitted -->(ff94b)<!-- raw HTML omitted --></a></li>
</ul>
<h5>    <a
href="https://github.com/vitest-community/vitest-browser-svelte/compare/v2.1.0...v2.1.1">View
changes on GitHub</a></h5>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vitest-community/vitest-browser-svelte/commit/092253b3ee80af3de6ac708199d6e7b1bb3f2dc4"><code>092253b</code></a>
chore: release v2.1.1</li>
<li><a
href="https://github.com/vitest-community/vitest-browser-svelte/commit/ff94b225d11b40cdfad6da1fd12044d7de842e41"><code>ff94b22</code></a>
fix: move <code>@playwright/test</code> out of dependencies (<a
href="https://redirect.github.com/vitest-community/vitest-browser-svelte/issues/26">#26</a>)</li>
<li>See full diff in <a
href="https://github.com/vitest-community/vitest-browser-svelte/compare/v2.1.0...v2.1.1">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-05 22:12:42 -07:00
dependabot[bot] c17ee878d4 chore(deps): bump the vue group across 1 directory with 2 updates (#2361)
Bumps the vue group with 2 updates in the / directory:
[vue](https://github.com/vuejs/core) and
[@vitejs/plugin-vue](https://github.com/vitejs/vite-plugin-vue/tree/HEAD/packages/plugin-vue).

Updates `vue` from 3.5.31 to 3.5.33
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vuejs/core/releases">vue's
releases</a>.</em></p>
<blockquote>
<h2>v3.5.33</h2>
<p>For stable releases, please refer to <a
href="https://github.com/vuejs/core/blob/main/CHANGELOG.md">CHANGELOG.md</a>
for details.
For pre-releases, please refer to <a
href="https://github.com/vuejs/core/blob/minor/CHANGELOG.md">CHANGELOG.md</a>
of the <code>minor</code> branch.</p>
<h2>v3.5.32</h2>
<p>For stable releases, please refer to <a
href="https://github.com/vuejs/core/blob/main/CHANGELOG.md">CHANGELOG.md</a>
for details.
For pre-releases, please refer to <a
href="https://github.com/vuejs/core/blob/minor/CHANGELOG.md">CHANGELOG.md</a>
of the <code>minor</code> branch.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vuejs/core/blob/main/CHANGELOG.md">vue's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/vuejs/core/compare/v3.5.32...v3.5.33">3.5.33</a>
(2026-04-22)</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>compiler-sfc:</strong> handle nested :deep in selector
pseudos (<a
href="https://redirect.github.com/vuejs/core/issues/14725">#14725</a>)
(<a
href="https://github.com/vuejs/core/commit/bb9d265d8dcdde2af824fc01b24f9a7b3169f5fa">bb9d265</a>),
closes <a
href="https://redirect.github.com/vuejs/core/issues/14724">#14724</a></li>
<li><strong>reactivity:</strong> unlink effect scopes on out-of-order
off (<a
href="https://redirect.github.com/vuejs/core/issues/14734">#14734</a>)
(<a
href="https://github.com/vuejs/core/commit/e7659beafc5407e892fa70f3f4ade80263b0905d">e7659be</a>),
closes <a
href="https://redirect.github.com/vuejs/core/issues/14733">#14733</a></li>
<li><strong>runtime-dom:</strong> preserve textarea resize dimensions
(<a
href="https://redirect.github.com/vuejs/core/issues/14747">#14747</a>)
(<a
href="https://github.com/vuejs/core/commit/11fb2fd4a246e40f6f350701dfea73ec525b4f59">11fb2fd</a>),
closes <a
href="https://redirect.github.com/vuejs/core/issues/14741">#14741</a></li>
<li><strong>teleport:</strong> don't move teleport children if not
mounted (<a
href="https://redirect.github.com/vuejs/core/issues/14702">#14702</a>)
(<a
href="https://github.com/vuejs/core/commit/6a61f4452ba1a31fc929cadf8abe3337ac4d3a46">6a61f44</a>),
closes <a
href="https://redirect.github.com/vuejs/core/issues/14701">#14701</a></li>
<li><strong>transition:</strong> preserve placeholder for conditional
explicit default slots (<a
href="https://redirect.github.com/vuejs/core/issues/14748">#14748</a>)
(<a
href="https://github.com/vuejs/core/commit/45990cecf4604b2f39c571ab6aefa49d362af36a">45990ce</a>),
closes <a
href="https://redirect.github.com/vuejs/core/issues/14727">#14727</a></li>
</ul>
<h2><a
href="https://github.com/vuejs/core/compare/v3.5.31...v3.5.32">3.5.32</a>
(2026-04-03)</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>runtime-core:</strong> prevent currentInstance leak into
sibling render during async setup re-entry (<a
href="https://redirect.github.com/vuejs/core/issues/14668">#14668</a>)
(<a
href="https://github.com/vuejs/core/commit/f1663535a163057788d3285dec54a245c3efb3ad">f166353</a>),
closes <a
href="https://redirect.github.com/vuejs/core/issues/14667">#14667</a></li>
<li><strong>teleport:</strong> handle updates before deferred mount (<a
href="https://redirect.github.com/vuejs/core/issues/14642">#14642</a>)
(<a
href="https://github.com/vuejs/core/commit/32b44f19f67aa30899817a7e79a4510f3b52970a">32b44f1</a>),
closes <a
href="https://redirect.github.com/vuejs/core/issues/14640">#14640</a></li>
<li><strong>types:</strong> allow customRef to have different
getter/setter types (<a
href="https://redirect.github.com/vuejs/core/issues/14639">#14639</a>)
(<a
href="https://github.com/vuejs/core/commit/e20ddb00188e9935884930046fa572eab7c9dcba">e20ddb0</a>)</li>
<li><strong>types:</strong> use private branding for shallowReactive (<a
href="https://redirect.github.com/vuejs/core/issues/14641">#14641</a>)
(<a
href="https://github.com/vuejs/core/commit/302c47a4994bc8b47b8a2af6693d8cb6bbd4b06b">302c47a</a>),
closes <a
href="https://redirect.github.com/vuejs/core/issues/14638">#14638</a> <a
href="https://redirect.github.com/vuejs/core/issues/14493">#14493</a></li>
</ul>
<h3>Reverts</h3>
<ul>
<li>Revert &quot;fix(server-renderer): cleanup component effect scopes
after SSR render&quot; (<a
href="https://redirect.github.com/vuejs/core/issues/14674">#14674</a>)
(<a
href="https://github.com/vuejs/core/commit/219d83bd305ce6fc052941acaaf02e7bc70616a4">219d83b</a>),
closes <a
href="https://redirect.github.com/vuejs/core/issues/14674">#14674</a> <a
href="https://redirect.github.com/vuejs/core/issues/14669">#14669</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vuejs/core/commit/3310eea4ececff0379ea657e633e3c18b0f647eb"><code>3310eea</code></a>
release: v3.5.33</li>
<li><a
href="https://github.com/vuejs/core/commit/bb9d265d8dcdde2af824fc01b24f9a7b3169f5fa"><code>bb9d265</code></a>
fix(compiler-sfc): handle nested :deep in selector pseudos (<a
href="https://redirect.github.com/vuejs/core/issues/14725">#14725</a>)</li>
<li><a
href="https://github.com/vuejs/core/commit/60402cd4771be1b758cae759d27ffa6c01428364"><code>60402cd</code></a>
Revert &quot;chore(deps): update pnpm/action-setup action to v6&quot;
(<a
href="https://redirect.github.com/vuejs/core/issues/14749">#14749</a>)</li>
<li><a
href="https://github.com/vuejs/core/commit/11fb2fd4a246e40f6f350701dfea73ec525b4f59"><code>11fb2fd</code></a>
fix(runtime-dom): preserve textarea resize dimensions (<a
href="https://redirect.github.com/vuejs/core/issues/14747">#14747</a>)</li>
<li><a
href="https://github.com/vuejs/core/commit/974e2d21b75c677e835656b8743b44c4eb285ca8"><code>974e2d2</code></a>
chore(deps): update test (<a
href="https://redirect.github.com/vuejs/core/issues/14713">#14713</a>)</li>
<li><a
href="https://github.com/vuejs/core/commit/45990cecf4604b2f39c571ab6aefa49d362af36a"><code>45990ce</code></a>
fix(transition): preserve placeholder for conditional explicit default
slots ...</li>
<li><a
href="https://github.com/vuejs/core/commit/6a61f4452ba1a31fc929cadf8abe3337ac4d3a46"><code>6a61f44</code></a>
fix(teleport): don't move teleport children if not mounted (<a
href="https://redirect.github.com/vuejs/core/issues/14702">#14702</a>)</li>
<li><a
href="https://github.com/vuejs/core/commit/e7659beafc5407e892fa70f3f4ade80263b0905d"><code>e7659be</code></a>
fix(reactivity): unlink effect scopes on out-of-order off (<a
href="https://redirect.github.com/vuejs/core/issues/14734">#14734</a>)</li>
<li><a
href="https://github.com/vuejs/core/commit/268115dc49fe8aa9a2a6c820a7b91eba6ca68208"><code>268115d</code></a>
chore: update pnpm config (<a
href="https://redirect.github.com/vuejs/core/issues/14694">#14694</a>)</li>
<li><a
href="https://github.com/vuejs/core/commit/24f26f41af5aea64b5054ec57066679a4d71aff4"><code>24f26f4</code></a>
chore(deps): update pnpm/action-setup action to v6 (<a
href="https://redirect.github.com/vuejs/core/issues/14716">#14716</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/vuejs/core/compare/v3.5.31...v3.5.33">compare
view</a></li>
</ul>
</details>
<br />

Updates `@vitejs/plugin-vue` from 6.0.5 to 6.0.6
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vitejs/vite-plugin-vue/releases">@​vitejs/plugin-vue's
releases</a>.</em></p>
<blockquote>
<h2>plugin-vue@6.0.6</h2>
<p>Please refer to <a
href="https://github.com/vitejs/vite-plugin-vue/blob/plugin-vue@6.0.6/packages/plugin-vue/CHANGELOG.md">CHANGELOG.md</a>
for details.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vitejs/vite-plugin-vue/blob/main/packages/plugin-vue/CHANGELOG.md">@​vitejs/plugin-vue's
changelog</a>.</em></p>
<blockquote>
<h2><!-- raw HTML omitted --><a
href="https://github.com/vitejs/vite-plugin-vue/compare/plugin-vue@6.0.5...plugin-vue@6.0.6">6.0.6</a>
(2026-04-13)<!-- raw HTML omitted --></h2>
<h3>Features</h3>
<ul>
<li><strong>plugin-vue:</strong> propagate multiRoot for template-only
vapor components (<a
href="https://redirect.github.com/vitejs/vite-plugin-vue/issues/745">#745</a>)
(<a
href="https://github.com/vitejs/vite-plugin-vue/commit/9e07ae94d0ca2e40cf0c2aac6a3d355a445a5e2d">9e07ae9</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> update all non-major dependencies (<a
href="https://redirect.github.com/vitejs/vite-plugin-vue/issues/738">#738</a>)
(<a
href="https://github.com/vitejs/vite-plugin-vue/commit/050c9962660e7bb189fe8e03f0fa4cbd0b5ba766">050c996</a>)</li>
</ul>
<h3>Miscellaneous Chores</h3>
<ul>
<li><strong>deps:</strong> update dependency rollup to ^4.59.0 (<a
href="https://redirect.github.com/vitejs/vite-plugin-vue/issues/749">#749</a>)
(<a
href="https://github.com/vitejs/vite-plugin-vue/commit/a0e1ef83bd841c22c3fddc62189b545ec7c71729">a0e1ef8</a>)</li>
<li>remove unused deps (<a
href="https://redirect.github.com/vitejs/vite-plugin-vue/issues/760">#760</a>)
(<a
href="https://github.com/vitejs/vite-plugin-vue/commit/6d834d82614ec76eb7618a2b015b6e8b0664f096">6d834d8</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vitejs/vite-plugin-vue/commit/51dbf4b494ef3e8b87febdb285d3c15b8a9c5490"><code>51dbf4b</code></a>
release: plugin-vue@6.0.6</li>
<li><a
href="https://github.com/vitejs/vite-plugin-vue/commit/9e07ae94d0ca2e40cf0c2aac6a3d355a445a5e2d"><code>9e07ae9</code></a>
feat(plugin-vue): propagate multiRoot for template-only vapor components
(<a
href="https://github.com/vitejs/vite-plugin-vue/tree/HEAD/packages/plugin-vue/issues/745">#745</a>)</li>
<li><a
href="https://github.com/vitejs/vite-plugin-vue/commit/050c9962660e7bb189fe8e03f0fa4cbd0b5ba766"><code>050c996</code></a>
fix(deps): update all non-major dependencies (<a
href="https://github.com/vitejs/vite-plugin-vue/tree/HEAD/packages/plugin-vue/issues/738">#738</a>)</li>
<li><a
href="https://github.com/vitejs/vite-plugin-vue/commit/6d834d82614ec76eb7618a2b015b6e8b0664f096"><code>6d834d8</code></a>
chore: remove unused deps (<a
href="https://github.com/vitejs/vite-plugin-vue/tree/HEAD/packages/plugin-vue/issues/760">#760</a>)</li>
<li><a
href="https://github.com/vitejs/vite-plugin-vue/commit/a0e1ef83bd841c22c3fddc62189b545ec7c71729"><code>a0e1ef8</code></a>
chore(deps): update dependency rollup to ^4.59.0 (<a
href="https://github.com/vitejs/vite-plugin-vue/tree/HEAD/packages/plugin-vue/issues/749">#749</a>)</li>
<li>See full diff in <a
href="https://github.com/vitejs/vite-plugin-vue/commits/plugin-vue@6.0.6/packages/plugin-vue">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-05 21:54:16 -07:00
Naomi Pentrel eea2e429c8 docs: update README.md (#2369) @langchain/angular@1.0.1 @langchain/vue@1.0.1 2026-05-05 17:58:49 +02:00
github-actions[bot] 69a7c01313 chore: version packages (#2367)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-api@1.2.1

### Patch Changes

- [#2366](https://github.com/langchain-ai/langgraphjs/pull/2366)
[`2bb66bf`](https://github.com/langchain-ai/langgraphjs/commit/2bb66bf816a8b18b2968ed885ef2df15f684cb4e)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): update endpoints

-   Updated dependencies \[]:
    -   @langchain/langgraph-ui@1.2.1

## @langchain/langgraph-cli@1.2.1

### Patch Changes

- Updated dependencies
\[[`2bb66bf`](https://github.com/langchain-ai/langgraphjs/commit/2bb66bf816a8b18b2968ed885ef2df15f684cb4e)]:
    -   @langchain/langgraph-api@1.2.1

## @langchain/langgraph-sdk@1.9.1

### Patch Changes

- [#2366](https://github.com/langchain-ai/langgraphjs/pull/2366)
[`2bb66bf`](https://github.com/langchain-ai/langgraphjs/commit/2bb66bf816a8b18b2968ed885ef2df15f684cb4e)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): update endpoints

## @langchain/angular@1.0.1

### Patch Changes

- Updated dependencies
\[[`2bb66bf`](https://github.com/langchain-ai/langgraphjs/commit/2bb66bf816a8b18b2968ed885ef2df15f684cb4e)]:
    -   @langchain/langgraph-sdk@1.9.1

## @langchain/react@1.0.1

### Patch Changes

- Updated dependencies
\[[`2bb66bf`](https://github.com/langchain-ai/langgraphjs/commit/2bb66bf816a8b18b2968ed885ef2df15f684cb4e)]:
    -   @langchain/langgraph-sdk@1.9.1

## @langchain/svelte@1.0.1

### Patch Changes

- Updated dependencies
\[[`2bb66bf`](https://github.com/langchain-ai/langgraphjs/commit/2bb66bf816a8b18b2968ed885ef2df15f684cb4e)]:
    -   @langchain/langgraph-sdk@1.9.1

## @langchain/vue@1.0.1

### Patch Changes

- Updated dependencies
\[[`2bb66bf`](https://github.com/langchain-ai/langgraphjs/commit/2bb66bf816a8b18b2968ed885ef2df15f684cb4e)]:
    -   @langchain/langgraph-sdk@1.9.1

## @langchain/langgraph-ui@1.2.1



## @example/ai-elements@0.1.16

### Patch Changes

-   Updated dependencies \[]:
    -   @langchain/react@1.0.1

## @examples/assistant-ui-claude@0.1.16

### Patch Changes

-   Updated dependencies \[]:
    -   @langchain/react@1.0.1

## @examples/ui-angular@0.0.26

### Patch Changes

- Updated dependencies
\[[`2bb66bf`](https://github.com/langchain-ai/langgraphjs/commit/2bb66bf816a8b18b2968ed885ef2df15f684cb4e)]:
    -   @langchain/langgraph-sdk@1.9.1
    -   @langchain/angular@1.0.1

## @examples/ui-multimodal@0.0.2

### Patch Changes

-   Updated dependencies \[]:
    -   @langchain/react@1.0.1

## @examples/ui-react@0.0.2

### Patch Changes

- Updated dependencies
\[[`2bb66bf`](https://github.com/langchain-ai/langgraphjs/commit/2bb66bf816a8b18b2968ed885ef2df15f684cb4e)]:
    -   @langchain/langgraph-sdk@1.9.1
    -   @langchain/react@1.0.1

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-05-05 01:58:31 -07:00
Christian Bromann 2bb66bf816 fix(sdk): update endpoints (#2366)
Aligning with latest Python changes updating endpoints to be:

POST /threads/{thread_id}/stream/events — SSE event stream
POST /threads/{thread_id}/commands — JSON command
WS /threads/{thread_id}/stream/events

for new streaming features.
2026-05-05 01:54:42 -07:00
github-actions[bot] 1f11df2668 chore: version packages (#2364)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/angular@1.0.0

### Major Changes

- [#2314](https://github.com/langchain-ai/langgraphjs/pull/2314)
[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb)
Thanks [@christian-bromann](https://github.com/christian-bromann)! - Add
the Angular event streaming integration.

Angular applications can now build on the shared event streaming runtime
with
    `useStream`, `injectStream`, `StreamService`, `provideStream`,
`provideStreamDefaults`, `injectProjection`, and selector helpers for
messages,
values, tool calls, custom channels, extensions, media, message
metadata, and
submission queues. The integration supports thread switching, run
submission,
reattachment, interrupts, WebSocket and SSE/custom transports, headless
tools,
    subgraphs, subagents, and typed event projections.

    This release also adds Angular-specific media helpers, including
`injectMediaUrl` and selectors for audio, images, video, and files. The
package
now exports the shared stream, media, transport, headless-tool, and type
    inference types needed to compose strongly typed streaming UIs.

The documentation has been refreshed with guides for dependency
injection,
`injectStream`, selectors, transports, custom transports, interrupts,
submission queues, headless tools, subagents/subgraphs, type safety,
testing,
    and migration from the previous SDK surface.

### Patch Changes

- Updated dependencies
\[[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb),
[`d1e2fda`](https://github.com/langchain-ai/langgraphjs/commit/d1e2fda1b1165e122362780a62ab8d2ebff9f9b9)]:
    -   @langchain/langgraph-sdk@1.9.0

## @langchain/react@1.0.0

### Major Changes

- [#2314](https://github.com/langchain-ai/langgraphjs/pull/2314)
[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb)
Thanks [@christian-bromann](https://github.com/christian-bromann)! - Add
the React event streaming integration.

React applications can now use the shared event streaming runtime
through
`useStream`, `useProjection`, `useSuspenseStream`, `StreamProvider`, and
focused selector hooks for messages, values, tool calls, custom
channels,
extensions, media, message metadata, and submission queues. The new
integration
    supports thread-scoped runs, reattachment, interrupts, WebSocket and
SSE/custom transports, headless tools, subgraphs, subagents, typed
stream
    extensions, and strongly typed state/tool-call inference.

This release also adds media helpers for streaming UI experiences,
including
`useMediaURL`, `useAudioPlayer`, and `useVideoPlayer`, plus selectors
for
audio, images, video, and files. Shared transport, media, protocol
event,
message metadata, and discovery types are exported from the package so
React
components can compose richer streaming interfaces without deep imports.

    The package documentation and tests have been expanded around custom
transports, selectors, interrupts, multimodal streaming, suspense,
submission
queues, headless tools, subagents, type safety, and migration from the
previous
    streaming API.

### Patch Changes

- Updated dependencies
\[[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb),
[`d1e2fda`](https://github.com/langchain-ai/langgraphjs/commit/d1e2fda1b1165e122362780a62ab8d2ebff9f9b9)]:
    -   @langchain/langgraph-sdk@1.9.0

## @langchain/svelte@1.0.0

### Major Changes

- [#2314](https://github.com/langchain-ai/langgraphjs/pull/2314)
[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb)
Thanks [@christian-bromann](https://github.com/christian-bromann)! - Add
the Svelte event streaming integration.

Svelte applications can now use the shared event streaming runtime
through
`useStream`, `useProjection`, context helpers, and selector runes for
messages,
values, tool calls, custom channels, extensions, media, message
metadata, and
submission queues. The integration supports thread-scoped runs,
reattachment,
interrupts, WebSocket and SSE/custom transports, headless tools,
subgraphs,
subagents, typed stream extensions, and strongly typed state/tool-call
    inference.

This release also adds Svelte media helpers, including `useMediaURL`,
`useAudioPlayer`, and `useVideoPlayer`, plus selectors for audio,
images,
video, and files. Shared transport, media, protocol event, message
metadata,
and discovery types are exported from the package so Svelte components
can
    compose streaming interfaces without deep imports.

The package now includes focused documentation and tests for context,
custom
    transports, selectors, interrupts, hydration, submission queues,
subscriptions, headless tools, subagents, type safety, and migration
from the
    previous streaming API.

### Patch Changes

- Updated dependencies
\[[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb),
[`d1e2fda`](https://github.com/langchain-ai/langgraphjs/commit/d1e2fda1b1165e122362780a62ab8d2ebff9f9b9)]:
    -   @langchain/langgraph-sdk@1.9.0

## @langchain/vue@1.0.0

### Major Changes

- [#2314](https://github.com/langchain-ai/langgraphjs/pull/2314)
[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb)
Thanks [@christian-bromann](https://github.com/christian-bromann)! - Add
the Vue event streaming integration.

Vue applications can now use the shared event streaming runtime through
`useStream`, `useProjection`, `provideStream`, `useStreamContext`, and
selector composables for messages, values, tool calls, custom channels,
extensions, media, message metadata, and submission queues. The
integration
    supports thread-scoped runs, reattachment, interrupts, WebSocket and
SSE/custom transports, headless tools, subgraphs, subagents, typed
stream
    extensions, and strongly typed state/tool-call inference.

    This release also adds Vue media helpers, including `useMediaURL`,
`useAudioPlayer`, and `useVideoPlayer`, plus selectors for audio,
images,
video, and files. Shared transport, media, protocol event, message
metadata,
and discovery types are exported from the package so Vue components can
build
    rich streaming UIs without deep imports.

The package documentation and tests now cover API usage, custom
transports,
forking, interrupts, multimodal streaming, selectors, shared streams,
subagents, suspense, submission queues, transports, type safety, and
migration
    from the previous streaming API.

### Patch Changes

- Updated dependencies
\[[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb),
[`d1e2fda`](https://github.com/langchain-ai/langgraphjs/commit/d1e2fda1b1165e122362780a62ab8d2ebff9f9b9)]:
    -   @langchain/langgraph-sdk@1.9.0

## @langchain/langgraph-api@1.2.0

### Minor Changes

- [#2314](https://github.com/langchain-ai/langgraphjs/pull/2314)
[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb)
Thanks [@christian-bromann](https://github.com/christian-bromann)! - Add
the thread-scoped event streaming protocol used by the new SDK streaming
    clients.

This release adds protocol routes for WebSocket and SSE/HTTP streaming,
including thread-local command handling, filtered subscriptions, event
replay,
state inspection, checkpoint listing/forking, interrupt input, agent
tree
queries, and run start/resume commands. Stream events are normalized
into the
canonical protocol shape with ordered sequence IDs so clients can safely
dedupe, resume subscriptions, and coordinate multiple projections from
the same
    run.

The experimental embed server now supports the same protocol flow, so
embedded
graphs can serve the new SDK transports without standing up a separate
LangGraph API deployment. The server also gains protocol session tests
and
fixture graphs covering deep agents, interrupts, subgraphs, and SDK
transport
    behavior.

### Patch Changes

-   Updated dependencies \[]:
    -   @langchain/langgraph-ui@1.2.0

## @langchain/langgraph@1.3.0

### Minor Changes

- [#2314](https://github.com/langchain-ai/langgraphjs/pull/2314)
[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb)
Thanks [@christian-bromann](https://github.com/christian-bromann)! - Add
the in-process event streaming runtime behind `streamEvents`.

LangGraph now exposes the core primitives for event-based streaming,
including
`StreamChannel`, `StreamMux`, `GraphRunStream`, `SubgraphRunStream`,
native
stream transformers, and protocol event conversion utilities. These APIs
let
graphs emit ordered protocol events, derive additional projections,
expose
custom stream channels, and bridge in-process runs to remote SDK
clients.

The runtime includes built-in transformers for messages, values,
lifecycle
    events, and subgraph discovery. It also adds support for transformer
registration during graph execution, forwarding remote `StreamChannel`
output,
subgraph-aware event routing, event log multiplexing, and
checkpoint-aware
    values streams.

This release also expands test coverage across Pregel streaming, event
    conversion, stream muxing, stream channels, run streams, lifecycle
transformers, subgraph transformers, and type-level streaming behavior.

### Patch Changes

- Updated dependencies
\[[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb),
[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb),
[`d1e2fda`](https://github.com/langchain-ai/langgraphjs/commit/d1e2fda1b1165e122362780a62ab8d2ebff9f9b9)]:
    -   @langchain/langgraph-checkpoint@1.0.2
    -   @langchain/langgraph-sdk@1.9.0

## @langchain/langgraph-sdk@1.9.0

### Minor Changes

- [#2314](https://github.com/langchain-ai/langgraphjs/pull/2314)
[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb)
Thanks [@christian-bromann](https://github.com/christian-bromann)! - Add
the framework-agnostic event streaming SDK.

    The SDK now includes a thread-focused streaming client built around
`ThreadStream`, `SubscriptionHandle`, message assembly, media assembly,
typed
stream extensions, and pluggable protocol transports. Applications can
stream
over SSE or WebSocket, provide custom agent-server adapters, subscribe
to
values/messages/tools/custom/lifecycle/checkpoint channels, inspect and
fork
state, respond to interrupts, and replay or dedupe ordered event
streams.

This release also adds the reusable stream runtime used by the React,
Vue,
    Svelte, and Angular packages: `StreamController`, `StreamStore`,
`ChannelRegistry`, projection factories, subagent/subgraph discovery,
submission queue coordination, message metadata tracking, root message
projection, media projections, and helper types for agent/deep-agent
state and
    tool-call inference.

The client package has been reorganized into focused modules for
assistants,
threads, runs, store, protocol streaming, transports, media, messages,
and UI
helpers. New SDK documentation covers configuration, assistants,
threads, runs,
store, streaming, transports, extensions, interrupts, messages, media,
    subagents, and subgraphs.

### Patch Changes

- [#2363](https://github.com/langchain-ai/langgraphjs/pull/2363)
[`d1e2fda`](https://github.com/langchain-ai/langgraphjs/commit/d1e2fda1b1165e122362780a62ab8d2ebff9f9b9)
Thanks [@cwlbraa](https://github.com/cwlbraa)! - Add a `returnMinimal`
option to `threads.update`.

## @langchain/langgraph-checkpoint@1.0.2

### Patch Changes

- [#2314](https://github.com/langchain-ai/langgraphjs/pull/2314)
[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
Improve `MemorySaver` diagnostics when checkpoint writes are missing a
      `thread_id`.

The in-memory checkpointer now explains why `configurable.thread_id` is
required and includes a concrete `graph.stream(..., { configurable: {
    thread_id } })` example in the error message. This makes the new
thread-oriented event streaming flows easier to debug when an
application
      forgets to provide durable thread configuration.

## @langchain/langgraph-cli@1.2.0

### Patch Changes

- Updated dependencies
\[[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb)]:
    -   @langchain/langgraph-api@1.2.0

## @langchain/langgraph-ui@1.2.0



## @example/ai-elements@0.1.15

### Patch Changes

- Updated dependencies
\[[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb),
[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb)]:
    -   @langchain/langgraph@1.3.0
    -   @langchain/react@1.0.0

## @examples/assistant-ui-claude@0.1.15

### Patch Changes

- Updated dependencies
\[[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb),
[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb)]:
    -   @langchain/langgraph@1.3.0
    -   @langchain/react@1.0.0

## @examples/ui-angular@0.0.25

### Patch Changes

- Updated dependencies
\[[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb),
[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb),
[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb),
[`d1e2fda`](https://github.com/langchain-ai/langgraphjs/commit/d1e2fda1b1165e122362780a62ab8d2ebff9f9b9)]:
    -   @langchain/langgraph@1.3.0
    -   @langchain/langgraph-sdk@1.9.0
    -   @langchain/angular@1.0.0

## @examples/ui-multimodal@0.0.1

### Patch Changes

- Updated dependencies
\[[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb),
[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb)]:
    -   @langchain/langgraph@1.3.0
    -   @langchain/react@1.0.0

## @examples/ui-react@0.0.1

### Patch Changes

- Updated dependencies
\[[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb),
[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb),
[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb),
[`d1e2fda`](https://github.com/langchain-ai/langgraphjs/commit/d1e2fda1b1165e122362780a62ab8d2ebff9f9b9)]:
    -   @langchain/langgraph@1.3.0
    -   @langchain/langgraph-sdk@1.9.0
    -   @langchain/react@1.0.0

## langgraph@1.0.32

### Patch Changes

- Updated dependencies
\[[`085a07f`](https://github.com/langchain-ai/langgraphjs/commit/085a07f569b6d7d79728eb7eb6eb3a0c67fcdefb)]:
    -   @langchain/langgraph@1.3.0

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Hunter Lovell <hunter@hntrl.io>
@langchain/angular@1.0.0 @langchain/langgraph-api@1.2.0 @langchain/langgraph-cli@1.2.0 @langchain/react@1.0.0 @langchain/vue@1.0.0
2026-05-05 00:41:45 -07:00
Christian Bromann 085a07f569 feat(core): event based streaming (#2314)
All stream v2 changes consolidated.

---------

Co-authored-by: Hunter Lovell <hunter@hntrl.io>
2026-05-05 00:13:12 -07:00
dependabot[bot] fe09385cb1 chore(deps): bump the langchain group across 1 directory with 9 updates (#2358)
Bumps the langchain group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@langchain/anthropic](https://github.com/langchain-ai/langchainjs) |
`1.3.26` | `1.3.28` |
| [@langchain/core](https://github.com/langchain-ai/langchainjs) |
`1.1.40` | `1.1.43` |
| [langchain](https://github.com/langchain-ai/langchainjs) | `1.3.0` |
`1.3.5` |
| [@langchain/openai](https://github.com/langchain-ai/langchainjs) |
`1.4.1` | `1.4.5` |
| [@langchain/groq](https://github.com/langchain-ai/langchainjs) |
`1.1.5` | `1.2.0` |
| [@langchain/mistralai](https://github.com/langchain-ai/langchainjs) |
`1.0.7` | `1.0.8` |
| [@langchain/ollama](https://github.com/langchain-ai/langchainjs) |
`1.2.6` | `1.2.7` |
| [@langchain/classic](https://github.com/langchain-ai/langchainjs) |
`1.0.27` | `1.0.32` |
| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.5.20`
| `0.6.0` |


Updates `@langchain/anthropic` from 1.3.26 to 1.3.28
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">@​langchain/anthropic's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/anthropic</code><a
href="https://github.com/1"><code>@​1</code></a>.3.27</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/10726">#10726</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/ad153c185b6cf813d4b7695740d9a4453d2cb63f"><code>ad153c1</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
feat(anthropic): add Claude Opus 4.7 compatibility updates</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/langchain-ai/langchainjs/commit/589f29ce844eb252c2d5e6b0f8d26de37763a0d7"><code>589f29c</code></a>,
<a
href="https://github.com/langchain-ai/langchainjs/commit/2e9e6969e248a53ede0659a41d0ac8dbaf291ab4"><code>2e9e696</code></a>]:</p>
<ul>
<li><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.1.41</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/langchain-ai/langchainjs/commits">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/core` from 1.1.40 to 1.1.43
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">@​langchain/core's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.1.41</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/10733">#10733</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/589f29ce844eb252c2d5e6b0f8d26de37763a0d7"><code>589f29c</code></a>
Thanks <a
href="https://github.com/jacoblee93"><code>@​jacoblee93</code></a>! -
fix(core): Update inheritance behavior for tracer metadata for special
keys</p>
</li>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/10711">#10711</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/2e9e6969e248a53ede0659a41d0ac8dbaf291ab4"><code>2e9e696</code></a>
Thanks <a
href="https://github.com/jacoblee93"><code>@​jacoblee93</code></a>! -
feat(core): Add chat model and llm invocation params to traced
metadata</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/langchain-ai/langchainjs/commits">compare
view</a></li>
</ul>
</details>
<br />

Updates `langchain` from 1.3.0 to 1.3.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">langchain's
releases</a>.</em></p>
<blockquote>
<h2>langchain@1.3.4</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/10713">#10713</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/49ac9e7404e5a9269b9ac047711ee96dd928b231"><code>49ac9e7</code></a>
Thanks <a
href="https://github.com/jacoblee93"><code>@​jacoblee93</code></a>! -
feat(langchain): Adds ls_agent_type to create agent runs as tracing
metadata</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/langchain-ai/langchainjs/commit/589f29ce844eb252c2d5e6b0f8d26de37763a0d7"><code>589f29c</code></a>,
<a
href="https://github.com/langchain-ai/langchainjs/commit/2e9e6969e248a53ede0659a41d0ac8dbaf291ab4"><code>2e9e696</code></a>]:</p>
<ul>
<li><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.1.41</li>
</ul>
</li>
</ul>
<h2>langchain@1.3.3</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/9386">#9386</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/71e53f1c07bc60e2c2304b10f0edd3c85c62b192"><code>71e53f1</code></a>
Thanks <a
href="https://github.com/Josh-Engle"><code>@​Josh-Engle</code></a>! -
Prevent local file corruption when using <code>LocalFileStore</code></p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/langchain-ai/langchainjs/commit/d3e080995bb267bf3797067ab53c96bc2a6c8e3f"><code>d3e0809</code></a>]:</p>
<ul>
<li><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.1.40</li>
</ul>
</li>
</ul>
<h2>langchain@1.3.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/10693">#10693</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/5a6e0ab6617587f3aed19d07bf3ed91994dcdac8"><code>5a6e0ab</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
fix(agents): derive middleware hook state from invocation state</p>
<p>Prevents middleware state from leaking across threads by deriving
middleware hook input state from the current invocation state instead of
cross-node cached state.</p>
</li>
</ul>
<h2>langchain@1.3.1</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/10673">#10673</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/f0693657b7e5bdbf888a46d04e68431e446c7bc0"><code>f069365</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
bump langgraph dependency to 1.2.8</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/6845a1ef129450cd6e75bb8a8e7390a416ab3d9c"><code>6845a1e</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10690">#10690</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/5a6e0ab6617587f3aed19d07bf3ed91994dcdac8"><code>5a6e0ab</code></a>
fix(agents): derive middleware hook state from invocation state (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10693">#10693</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/607696e8143ad30faeebb800028e244a11d46638"><code>607696e</code></a>
chore(ci): add label-gated publish-preview workflow (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10696">#10696</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/1f8b2c0b863645da45114d8756dc5b66fcb43c98"><code>1f8b2c0</code></a>
chore(ci): add label-gated publish-preview workflow (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10695">#10695</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/2ff51cf0688e45d5d237b2b435334b5fd987afa9"><code>2ff51cf</code></a>
fix(aws): normalize Bedrock Converse object errors for tracing (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10688">#10688</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/4a91db32a80a1b9da3bea4f6333eff63980b28b4"><code>4a91db3</code></a>
chore(deps): bump langsmith from 0.5.9 to 0.5.18 (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10687">#10687</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/312d60536da66827791e9b0f4a9d5d9091439183"><code>312d605</code></a>
chore(deps): bump axios from 1.13.6 to 1.15.0 (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10686">#10686</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/3e071bb44ec9c80a0eb964eff089434f4edd78b2"><code>3e071bb</code></a>
chore: remove suppressed CodeQL query filter and deduplicate
paths-ignore (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/1">#1</a>...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/e5b6e1c8568115cdda53eccafbdcd23537f554c5"><code>e5b6e1c</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10682">#10682</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/2301260ae90ead5c5f725c8dae1487b6722607e2"><code>2301260</code></a>
fix(openai): add index to streaming reasoning content blocks for proper
chunk...</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchainjs/compare/langchain@1.3.0...@langchain/aws@1.3.5">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/openai` from 1.4.1 to 1.4.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">@​langchain/openai's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/openai</code><a
href="https://github.com/1"><code>@​1</code></a>.4.4</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/10681">#10681</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/2301260ae90ead5c5f725c8dae1487b6722607e2"><code>2301260</code></a>
Thanks <a href="https://github.com/hntrl"><code>@​hntrl</code></a>! -
fix(openai): add index to streaming reasoning content blocks for proper
chunk merging</li>
</ul>
<h2><code>@​langchain/openai</code><a
href="https://github.com/1"><code>@​1</code></a>.4.3</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/10670">#10670</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/6b8ef6c95e061af47af206926598c983d878f72a"><code>6b8ef6c</code></a>
Thanks <a
href="https://github.com/christian-bromann"><code>@​christian-bromann</code></a>!
- fix(openai): preserve plain string responses content</li>
</ul>
<h2><code>@​langchain/openai</code><a
href="https://github.com/1"><code>@​1</code></a>.4.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/10614">#10614</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/d6bf4fc91b2c2eb931bf3bc7606b1817632bc8c1"><code>d6bf4fc</code></a>
Thanks <a
href="https://github.com/colifran"><code>@​colifran</code></a>! -
feat(openai): imput placeholder filenames for openai file inputs</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/langchain-ai/langchainjs/commit/d3d0922c24afcd3006fb94dcadd3ebe08fbf2383"><code>d3d0922</code></a>]:</p>
<ul>
<li><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.1.39</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/langchain-ai/langchainjs/commits">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/groq` from 1.1.5 to 1.2.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">@​langchain/groq's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/groq</code><a
href="https://github.com/1"><code>@​1</code></a>.2.0</h2>
<h3>Minor Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/10603">#10603</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/66effb028baf5c923501801c989c7377efb8b77a"><code>66effb0</code></a>
Thanks <a
href="https://github.com/apps/dependabot"><code>@​dependabot</code></a>!
- chore(deps): bump groq-sdk from 0.37.0 to 1.1.2</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/daece6df71e0095c7a354270667a0b851a8cee4d"><code>daece6d</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10560">#10560</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/9781bff525bffdd3b6a75adfa8a30fdb4bfc505e"><code>9781bff</code></a>
fix(google): align ChatGoogle mediaResolution with Gemini scalar type
(<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10550">#10550</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/3bd85c17869e95d5d1a67c5fccc0c4cab2646616"><code>3bd85c1</code></a>
feat(langchain): add ChatGoogle support to initChatModel (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10654">#10654</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/d3d0922c24afcd3006fb94dcadd3ebe08fbf2383"><code>d3d0922</code></a>
feat(core): support for headless tools (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10430">#10430</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/793bc69a8af8198de9d157c21070871660e6bb13"><code>793bc69</code></a>
feat(aws): impute file name for document content blocks#963 (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10658">#10658</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/d6bf4fc91b2c2eb931bf3bc7606b1817632bc8c1"><code>d6bf4fc</code></a>
feat(openai): impute placeholder filenames for openai file inputs (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10614">#10614</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/0a7a7298b719f579854e41adddb04f17dc82640b"><code>0a7a729</code></a>
fix(examples): update dependencies (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10651">#10651</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/6f8dafcb9deee169473eadaae6416ad255277a5b"><code>6f8dafc</code></a>
Bump vitest (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/10649">#10649</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/e89cfd29f36e0b2fee20a7443e6c30c88039d735"><code>e89cfd2</code></a>
chore(deps): bump <code>@​cloudflare/workers-types</code> from
4.20260207.0 to 4.20260402.1...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/0de2c14d38716d9c66c546e18a490c5bfda75134"><code>0de2c14</code></a>
chore(deps): bump <code>@​aws-sdk/client-bedrock-agent-runtime</code>
from 3.1006.0 to 3.10...</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchainjs/compare/@langchain/groq@1.1.5...@langchain/groq@1.2.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/mistralai` from 1.0.7 to 1.0.8
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">@​langchain/mistralai's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/neo4j</code><a
href="https://github.com/0"><code>@​0</code></a>.1.3</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a
href="https://github.com/langchain-ai/langchainjs/commit/d3e080995bb267bf3797067ab53c96bc2a6c8e3f"><code>d3e0809</code></a>,
<a
href="https://github.com/langchain-ai/langchainjs/commit/71e53f1c07bc60e2c2304b10f0edd3c85c62b192"><code>71e53f1</code></a>]:
<ul>
<li><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.1.40</li>
<li><code>@​langchain/classic</code><a
href="https://github.com/1"><code>@​1</code></a>.0.31</li>
</ul>
</li>
</ul>
<h2><code>@​langchain/neo4j</code><a
href="https://github.com/0"><code>@​0</code></a>.1.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies []:
<ul>
<li><code>@​langchain/classic</code><a
href="https://github.com/1"><code>@​1</code></a>.0.30</li>
</ul>
</li>
</ul>
<h2><code>@​langchain/neo4j</code><a
href="https://github.com/0"><code>@​0</code></a>.1.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies []:
<ul>
<li><code>@​langchain/classic</code><a
href="https://github.com/1"><code>@​1</code></a>.0.29</li>
</ul>
</li>
</ul>
<h2><code>@​langchain/neo4j</code><a
href="https://github.com/0"><code>@​0</code></a>.1.0</h2>
<h3>Minor Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/10590">#10590</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/ed8cda659c893219d853a402f0fcd46e06cf7c28"><code>ed8cda6</code></a>
Thanks <a
href="https://github.com/christian-bromann"><code>@​christian-bromann</code></a>!
- feat: scaffold <code>@​langchain/neo4j</code> provider package</li>
</ul>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a
href="https://github.com/langchain-ai/langchainjs/commit/d7a98cda1a5d9bf9b93b503fc54374f1aaf1a37e"><code>d7a98cd</code></a>,
<a
href="https://github.com/langchain-ai/langchainjs/commit/884c2d3d1b2c49225d73ddec2235ad174db36f86"><code>884c2d3</code></a>,
<a
href="https://github.com/langchain-ai/langchainjs/commit/0fb6fa40dcd3a09a4fb91f36c9f2ca869552961e"><code>0fb6fa4</code></a>,
<a
href="https://github.com/langchain-ai/langchainjs/commit/d3d0922c24afcd3006fb94dcadd3ebe08fbf2383"><code>d3d0922</code></a>]:
<ul>
<li><code>@​langchain/classic</code><a
href="https://github.com/1"><code>@​1</code></a>.0.28</li>
<li><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.1.39</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/7ea8874715f76c17d3ec3d2ff0503dd12abbc5e9"><code>7ea8874</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9716">#9716</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/5707c3edc6a4d43934da0d3e7b9666b2fc144440"><code>5707c3e</code></a>
docs(internal): add AGENTS.md file (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9742">#9742</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/8ef152555a945c95322f28209957b69605c04c91"><code>8ef1525</code></a>
feat(google-common): support thinkingLevel parameter for Gemini models
(<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9738">#9738</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/c28d24a8770f6d0e543cde116b0e38b3baf21301"><code>c28d24a</code></a>
fix(core): use getBufferString for message summarization (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9739">#9739</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/f6974516b041ed12befd26e1a4cbe457865a2780"><code>f697451</code></a>
fix(langchain): keep tool call / AIMessage pairings when summarizing (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9740">#9740</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/536c7ddacd6c7f80d2edf18ab9caeeab71827ccd"><code>536c7dd</code></a>
fix(langchain): default strict to true in providerStrategy for OpenAI
compati...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/75b3b90c5fa62cbbfa678dfb01f031caed4488ef"><code>75b3b90</code></a>
fix(openai): pass runManager to _streamResponseChunks in responses API
(<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9737">#9737</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/13c9d5bfa3acac7ffb37642e9a50d84dc9004e88"><code>13c9d5b</code></a>
fix(openai): pass through provider-native content in ToolMessage without
stri...</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/5cfbedf064ffdc960cb2e5a97e37d7a5900560de"><code>5cfbedf</code></a>
fix(langchain): support callbacks property in stream (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9728">#9728</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/9ac29de3d3f70c75933913d94ad9a47c6ce39c1d"><code>9ac29de</code></a>
fix(langchain-aws): add support for Amazon Nova embedding models (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9701">#9701</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchainjs/compare/@langchain/mistralai@1.0.7...@langchain/classic@1.0.8">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/ollama` from 1.2.6 to 1.2.7
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">@​langchain/ollama's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/neo4j</code><a
href="https://github.com/0"><code>@​0</code></a>.1.3</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a
href="https://github.com/langchain-ai/langchainjs/commit/d3e080995bb267bf3797067ab53c96bc2a6c8e3f"><code>d3e0809</code></a>,
<a
href="https://github.com/langchain-ai/langchainjs/commit/71e53f1c07bc60e2c2304b10f0edd3c85c62b192"><code>71e53f1</code></a>]:
<ul>
<li><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.1.40</li>
<li><code>@​langchain/classic</code><a
href="https://github.com/1"><code>@​1</code></a>.0.31</li>
</ul>
</li>
</ul>
<h2><code>@​langchain/neo4j</code><a
href="https://github.com/0"><code>@​0</code></a>.1.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies []:
<ul>
<li><code>@​langchain/classic</code><a
href="https://github.com/1"><code>@​1</code></a>.0.30</li>
</ul>
</li>
</ul>
<h2><code>@​langchain/neo4j</code><a
href="https://github.com/0"><code>@​0</code></a>.1.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies []:
<ul>
<li><code>@​langchain/classic</code><a
href="https://github.com/1"><code>@​1</code></a>.0.29</li>
</ul>
</li>
</ul>
<h2><code>@​langchain/neo4j</code><a
href="https://github.com/0"><code>@​0</code></a>.1.0</h2>
<h3>Minor Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/10590">#10590</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/ed8cda659c893219d853a402f0fcd46e06cf7c28"><code>ed8cda6</code></a>
Thanks <a
href="https://github.com/christian-bromann"><code>@​christian-bromann</code></a>!
- feat: scaffold <code>@​langchain/neo4j</code> provider package</li>
</ul>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a
href="https://github.com/langchain-ai/langchainjs/commit/d7a98cda1a5d9bf9b93b503fc54374f1aaf1a37e"><code>d7a98cd</code></a>,
<a
href="https://github.com/langchain-ai/langchainjs/commit/884c2d3d1b2c49225d73ddec2235ad174db36f86"><code>884c2d3</code></a>,
<a
href="https://github.com/langchain-ai/langchainjs/commit/0fb6fa40dcd3a09a4fb91f36c9f2ca869552961e"><code>0fb6fa4</code></a>,
<a
href="https://github.com/langchain-ai/langchainjs/commit/d3d0922c24afcd3006fb94dcadd3ebe08fbf2383"><code>d3d0922</code></a>]:
<ul>
<li><code>@​langchain/classic</code><a
href="https://github.com/1"><code>@​1</code></a>.0.28</li>
<li><code>@​langchain/core</code><a
href="https://github.com/1"><code>@​1</code></a>.1.39</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/bd72d8eb8bde1b2282c9ec88f2ebadd0747dc7b7"><code>bd72d8e</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9762">#9762</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/578574906bdbd9cfce95e34030c1a3d97e63d1c1"><code>5785749</code></a>
fix(internal): fix changeset config (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9768">#9768</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/ddd72b8122e9dc68242b8467292bbee62e1dda2e"><code>ddd72b8</code></a>
chore(standard-tests): move standard-tests into ./internal (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9755">#9755</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/739d4e88cc78b8f578ab019b526c97d63d9c2144"><code>739d4e8</code></a>
Feat/xai responses implementation (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9718">#9718</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/e0360d9bdc0e7725d59625902bcfc98c39931e2a"><code>e0360d9</code></a>
fix(langchain): ensure models only make on write_todo call at a time (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9761">#9761</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/8619adb81f16977b3ab8d4607ad5c30f79c41e3d"><code>8619adb</code></a>
fix: add properties to check valid props (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9757">#9757</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/23be5afd59b5f4806edef11937ce5e2ba300f7ee"><code>23be5af</code></a>
feat(langchain): consolidate type generics in bags (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9517">#9517</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/85820be04995b4047a798ec44da6077cd1908d7a"><code>85820be</code></a>
chore: version packages (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9754">#9754</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/a46a24983fd0fea649d950725a2673b3c435275f"><code>a46a249</code></a>
fix(core): allow shared object references in serialization (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9753">#9753</a>)</li>
<li><a
href="https://github.com/langchain-ai/langchainjs/commit/3c8ba0d97f1c08e8f8c67ffddff5d57daba46f85"><code>3c8ba0d</code></a>
chore(internal): Turborepo improvements (<a
href="https://redirect.github.com/langchain-ai/langchainjs/issues/9744">#9744</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/langchain-ai/langchainjs/compare/@langchain/ollama@1.2.6...langchain@1.2.7">compare
view</a></li>
</ul>
</details>
<br />

Updates `@langchain/classic` from 1.0.27 to 1.0.32
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langchainjs/releases">@​langchain/classic's
releases</a>.</em></p>
<blockquote>
<h2><code>@​langchain/classic</code><a
href="https://github.com/1"><code>@​1</code></a>.0.31</h2>
<h3>Patch Changes</h3>
<ul>
<li><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/9386">#9386</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/71e53f1c07bc60e2c2304b10f0edd3c85c62b192"><code>71e53f1</code></a>
Thanks <a
href="https://github.com/Josh-Engle"><code>@​Josh-Engle</code></a>! -
Prevent local file corruption when using
<code>LocalFileStore</code></li>
</ul>
<h2><code>@​langchain/classic</code><a
href="https://github.com/1"><code>@​1</code></a>.0.30</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a
href="https://github.com/langchain-ai/langchainjs/commit/2301260ae90ead5c5f725c8dae1487b6722607e2"><code>2301260</code></a>]:
<ul>
<li><code>@​langchain/openai</code><a
href="https://github.com/1"><code>@​1</code></a>.4.4</li>
</ul>
</li>
</ul>
<h2><code>@​langchain/classic</code><a
href="https://github.com/1"><code>@​1</code></a>.0.29</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a
href="https://github.com/langchain-ai/langchainjs/commit/6b8ef6c95e061af47af206926598c983d878f72a"><code>6b8ef6c</code></a>]:
<ul>
<li><code>@​langchain/openai</code><a
href="https://github.com/1"><code>@​1</code></a>.4.3</li>
</ul>
</li>
</ul>
<h2><code>@​langchain/classic</code><a
href="https://github.com/1"><code>@​1</code></a>.0.28</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/10591">#10591</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/d7a98cda1a5d9bf9b93b503fc54374f1aaf1a37e"><code>d7a98cd</code></a>
Thanks <a
href="https://github.com/christian-bromann"><code>@​christian-bromann</code></a>!
- feat: add <code>@​langchain/perplexity</code> standalone provider
package</p>
</li>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/10594">#10594</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/884c2d3d1b2c49225d73ddec2235ad174db36f86"><code>884c2d3</code></a>
Thanks <a
href="https://github.com/christian-bromann"><code>@​christian-bromann</code></a>!
- feat(fireworks): extract standalone provider package</p>
</li>
<li>
<p><a
href="https://redirect.github.com/langchain-ai/langchainjs/pull/10593">#10593</a>
<a
href="https://github.com/langchain-ai/langchainjs/commit/0fb6fa40dcd3a09a4fb91f36c9f2ca869552961e"><code>0fb6fa4</code></a>
Thanks <a
href="https://github.com/christian-bromann"><code>@​christian-bromann</code></a>!
- feat(together-ai): migrate Together AI into provider package</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/langchain-ai/langchainjs/commit/d6bf4fc91b2c2eb931bf3bc7606b1817632bc8c1"><code>d6bf4fc</code></a>]:</p>
<ul>
<li><code>@​langchain/openai</code><a
href="https://github.com/1"><code>@​1</code></a>.4.2</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/langchain-ai/langchainjs/commits">compare
view</a></li>
</ul>
</details>
<br />

Updates `langsmith` from 0.5.20 to 0.6.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/langchain-ai/langsmith-sdk/releases">langsmith's
releases</a>.</em></p>
<blockquote>
<h2>v0.6.0</h2>
<h2>What's Changed</h2>
<ul>
<li>chore(js): bump JS to 0.4.3 by <a
href="https://github.com/dqbd"><code>@​dqbd</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/2253">langchain-ai/langsmith-sdk#2253</a></li>
<li>Revert &quot;feat: add js prompt caching&quot; by <a
href="https://github.com/angus-langchain"><code>@​angus-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/2258">langchain-ai/langsmith-sdk#2258</a></li>
<li>Revert &quot;feat: Replace UUID5 with deterministic UUID7 for
replicas&quot; by <a
href="https://github.com/angus-langchain"><code>@​angus-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/2257">langchain-ai/langsmith-sdk#2257</a></li>
<li>release(js): bump to 0.4.4 by <a
href="https://github.com/dqbd"><code>@​dqbd</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/2259">langchain-ai/langsmith-sdk#2259</a></li>
<li>feat: add prompt cache back and setup environment tests by <a
href="https://github.com/langchain-infra"><code>@​langchain-infra</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/2260">langchain-ai/langsmith-sdk#2260</a></li>
<li>feat(python): Bump pydantic to v2 by <a
href="https://github.com/angus-langchain"><code>@​angus-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/2248">langchain-ai/langsmith-sdk#2248</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.5.2...v0.6.0">https://github.com/langchain-ai/langsmith-sdk/compare/v0.5.2...v0.6.0</a></p>
<h2>v0.6.0rc0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(js): Add support for tracing AI SDK 6 by <a
href="https://github.com/jacoblee93"><code>@​jacoblee93</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/2237">langchain-ai/langsmith-sdk#2237</a></li>
<li>fix(js): Remove default Jestlike timeout by <a
href="https://github.com/jacoblee93"><code>@​jacoblee93</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/2243">langchain-ai/langsmith-sdk#2243</a></li>
<li>feat(js): Add support for tracing tool loop agent by <a
href="https://github.com/jacoblee93"><code>@​jacoblee93</code></a> in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/2244">langchain-ai/langsmith-sdk#2244</a></li>
<li>feat: Replace UUID5 with deterministic UUID7 for replicas by <a
href="https://github.com/angus-langchain"><code>@​angus-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/2249">langchain-ai/langsmith-sdk#2249</a></li>
<li>feat: add prompt caching to python sdk by <a
href="https://github.com/langchain-infra"><code>@​langchain-infra</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/2246">langchain-ai/langsmith-sdk#2246</a></li>
<li>feat: add js prompt caching by <a
href="https://github.com/langchain-infra"><code>@​langchain-infra</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/2251">langchain-ai/langsmith-sdk#2251</a></li>
<li>fix(claude): correctly parse llm and tool inputs in claude agent sdk
by <a
href="https://github.com/angus-langchain"><code>@​angus-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/2255">langchain-ai/langsmith-sdk#2255</a></li>
<li>bump(python): 0.5.2 by <a
href="https://github.com/angus-langchain"><code>@​angus-langchain</code></a>
in <a
href="https://redirect.github.com/langchain-ai/langsmith-sdk/pull/2256">langchain-ai/langsmith-sdk#2256</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/langchain-ai/langsmith-sdk/compare/v0.5.1...v0.6.0rc0">https://github.com/langchain-ai/langsmith-sdk/compare/v0.5.1...v0.6.0rc0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/langchain-ai/langsmith-sdk/commits/v0.6.0">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-04 22:42:09 -07:00
dependabot[bot] 2435ff6ab3 chore(deps): bump pnpm/action-setup from 5.0.0 to 6.0.4 (#2357)
Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from
5.0.0 to 6.0.4.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pnpm/action-setup/releases">pnpm/action-setup's
releases</a>.</em></p>
<blockquote>
<h2>v6.0.4</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: use npm co-located with the action node binary by <a
href="https://github.com/benquarmby"><code>@​benquarmby</code></a> in <a
href="https://redirect.github.com/pnpm/action-setup/pull/239">pnpm/action-setup#239</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/benquarmby"><code>@​benquarmby</code></a> made
their first contribution in <a
href="https://redirect.github.com/pnpm/action-setup/pull/239">pnpm/action-setup#239</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/pnpm/action-setup/compare/v6.0.3...v6.0.4">https://github.com/pnpm/action-setup/compare/v6.0.3...v6.0.4</a></p>
<h2>v6.0.3</h2>
<p>Updated pnpm to v11.0.0-rc.5</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/pnpm/action-setup/compare/v6.0.2...v6.0.3">https://github.com/pnpm/action-setup/compare/v6.0.2...v6.0.3</a></p>
<h2>v6.0.2</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: pnpm self-update binary shadowed by bootstrap on PATH by <a
href="https://github.com/oniani1"><code>@​oniani1</code></a> in <a
href="https://redirect.github.com/pnpm/action-setup/pull/230">pnpm/action-setup#230</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/oniani1"><code>@​oniani1</code></a> made
their first contribution in <a
href="https://redirect.github.com/pnpm/action-setup/pull/230">pnpm/action-setup#230</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/pnpm/action-setup/compare/v6.0.1...v6.0.2">https://github.com/pnpm/action-setup/compare/v6.0.1...v6.0.2</a></p>
<h2>v6.0.1</h2>
<p>Update pnpm to v11.0.0-rc.2. <code>pnpm-lock.yaml</code> will not be
saved with two documents unless the <code>packageManager</code> is set
via <code>devEngines.packageManager</code>. Related issue: <a
href="https://redirect.github.com/pnpm/action-setup/issues/228">pnpm/action-setup#228</a></p>
<h2>v6.0.0</h2>
<p>Added support for pnpm <a
href="https://github.com/pnpm/pnpm/releases/tag/v11.0.0-rc.0">v11</a>.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pnpm/action-setup/commit/26f6d4f2c533a43e6b5da0b4a5dd983f98f7b49a"><code>26f6d4f</code></a>
fix: use npm co-located with the action node binary (<a
href="https://redirect.github.com/pnpm/action-setup/issues/239">#239</a>)</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/903f9c1a6ebcba6cf41d87230be49611ac97822e"><code>903f9c1</code></a>
fix: update pnpm to 11.0.0-rc.5</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/bdf0af2a9d539c0fd91f655344d2934bfd5a2cdd"><code>bdf0af2</code></a>
test: add strict version-match jobs to reproduce <a
href="https://redirect.github.com/pnpm/action-setup/issues/225">#225</a>
/ <a
href="https://redirect.github.com/pnpm/action-setup/issues/227">#227</a></li>
<li><a
href="https://github.com/pnpm/action-setup/commit/71c92474e7e4f5bca283fb17ef80fba9cdb2b4b1"><code>71c9247</code></a>
fix: pnpm self-update binary shadowed by bootstrap on PATH (<a
href="https://redirect.github.com/pnpm/action-setup/issues/230">#230</a>)</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/078e9d416474b29c0c387560859308974f7e9c53"><code>078e9d4</code></a>
fix: update pnpm to 11.0.0-rc.2</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/08c4be7e2e672a47d11bd04269e27e5f3e8529cb"><code>08c4be7</code></a>
docs(README): update action-setup version</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/579891461a117d7c030d0430bbc772562374d9e1"><code>5798914</code></a>
chore: update .gitignore</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/ddffd667542d33325b6f1d9bda9cfcc7861fc400"><code>ddffd66</code></a>
fix: remove accidentally committed file</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/b43f991918ce53332dce4c15c32ae14261d12d65"><code>b43f991</code></a>
fix: update pnpm to 11.0.0-rc.0</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/3852509c9e55070b5aac70d0500b8772d13ed4e6"><code>3852509</code></a>
README.md: bring versions up-to-date (<a
href="https://redirect.github.com/pnpm/action-setup/issues/222">#222</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/pnpm/action-setup/compare/fc06bc1257f339d1d5d8b3a19a8cae5388b55320...26f6d4f2c533a43e6b5da0b4a5dd983f98f7b49a">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=pnpm/action-setup&package-manager=github_actions&previous-version=5.0.0&new-version=6.0.4)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-04 22:41:58 -07:00
dependabot[bot] 34d848c806 chore(deps): bump actions/upload-pages-artifact from 4.0.0 to 5.0.0 (#2356)
Bumps
[actions/upload-pages-artifact](https://github.com/actions/upload-pages-artifact)
from 4.0.0 to 5.0.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/upload-pages-artifact/releases">actions/upload-pages-artifact's
releases</a>.</em></p>
<blockquote>
<h2>v5.0.0</h2>
<h1>Changelog</h1>
<ul>
<li>Update upload-artifact action to version 7 <a
href="https://github.com/Tom-van-Woudenberg"><code>@​Tom-van-Woudenberg</code></a>
(<a
href="https://redirect.github.com/actions/upload-pages-artifact/issues/139">#139</a>)</li>
<li>feat: add <code>include-hidden-files</code> input <a
href="https://github.com/jonchurch"><code>@​jonchurch</code></a> (<a
href="https://redirect.github.com/actions/upload-pages-artifact/issues/137">#137</a>)</li>
</ul>
<p>See details of <a
href="https://github.com/actions/upload-pages-artifact/compare/v4.0.0...v4.0.1">all
code changes</a> since previous release.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/upload-pages-artifact/commit/fc324d3547104276b827a68afc52ff2a11cc49c9"><code>fc324d3</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/upload-pages-artifact/issues/139">#139</a>
from Tom-van-Woudenberg/patch-1</li>
<li><a
href="https://github.com/actions/upload-pages-artifact/commit/fe9d4b7d84090e1d8d9c53a0236f810d4e00d2c3"><code>fe9d4b7</code></a>
Merge branch 'main' into patch-1</li>
<li><a
href="https://github.com/actions/upload-pages-artifact/commit/0ca16172ca884f0a37117fed41734f29784cc980"><code>0ca1617</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/upload-pages-artifact/issues/137">#137</a>
from jonchurch/include-hidden-files</li>
<li><a
href="https://github.com/actions/upload-pages-artifact/commit/57f0e8492b437b7818227931fef2faa1a379839b"><code>57f0e84</code></a>
Update action.yml</li>
<li><a
href="https://github.com/actions/upload-pages-artifact/commit/4a90348b2933470dc78cec55534259872a6d3c0d"><code>4a90348</code></a>
v7 --&gt; hash</li>
<li><a
href="https://github.com/actions/upload-pages-artifact/commit/56f665a6f297fa95f8d735b314187fb2d7764569"><code>56f665a</code></a>
Update upload-artifact action to version 7</li>
<li><a
href="https://github.com/actions/upload-pages-artifact/commit/f7615f5917213b24245d49ba96693d0f5375a414"><code>f7615f5</code></a>
Add <code>include-hidden-files</code> input</li>
<li>See full diff in <a
href="https://github.com/actions/upload-pages-artifact/compare/7b1f4a764d45c48632c6b24a0339c27f5614fb0b...fc324d3547104276b827a68afc52ff2a11cc49c9">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/upload-pages-artifact&package-manager=github_actions&previous-version=4.0.0&new-version=5.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-04 22:41:48 -07:00
dependabot[bot] 4f810a2ce7 chore(deps): bump the minor-and-patch group with 2 updates (#2355)
Bumps the minor-and-patch group with 2 updates:
[actions/setup-node](https://github.com/actions/setup-node) and
[actions/upload-artifact](https://github.com/actions/upload-artifact).

Updates `actions/setup-node` from 6.3.0 to 6.4.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/setup-node/releases">actions/setup-node's
releases</a>.</em></p>
<blockquote>
<h2>v6.4.0</h2>
<h2>What's Changed</h2>
<h3>Dependency updates:</h3>
<ul>
<li>Upgrade <a
href="https://github.com/actions"><code>@​actions</code></a>
dependencies by <a
href="https://github.com/Copilot"><code>@​Copilot</code></a> in <a
href="https://redirect.github.com/actions/setup-node/pull/1525">actions/setup-node#1525</a></li>
<li>Update Node.js versions in versions.yml and bump package to v6.4.0
by <a
href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
in <a
href="https://redirect.github.com/actions/setup-node/pull/1533">actions/setup-node#1533</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/Copilot"><code>@​Copilot</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/setup-node/pull/1525">actions/setup-node#1525</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-node/compare/v6...v6.4.0">https://github.com/actions/setup-node/compare/v6...v6.4.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/setup-node/commit/48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e"><code>48b55a0</code></a>
Update Node.js versions in versions.yml and bump package to v6.4.0 (<a
href="https://redirect.github.com/actions/setup-node/issues/1533">#1533</a>)</li>
<li><a
href="https://github.com/actions/setup-node/commit/ab72c7e7eba0eaa11f8cab0f5679243900c2cac9"><code>ab72c7e</code></a>
Upgrade <a href="https://github.com/actions"><code>@​actions</code></a>
dependencies (<a
href="https://redirect.github.com/actions/setup-node/issues/1525">#1525</a>)</li>
<li>See full diff in <a
href="https://github.com/actions/setup-node/compare/53b83947a5a98c8d113130e565377fae1a50d02f...48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e">compare
view</a></li>
</ul>
</details>
<br />

Updates `actions/upload-artifact` from 7.0.0 to 7.0.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/upload-artifact/releases">actions/upload-artifact's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.1</h2>
<h2>What's Changed</h2>
<ul>
<li>Update the readme with direct upload details by <a
href="https://github.com/danwkennedy"><code>@​danwkennedy</code></a> in
<a
href="https://redirect.github.com/actions/upload-artifact/pull/795">actions/upload-artifact#795</a></li>
<li>Readme: bump all the example versions to v7 by <a
href="https://github.com/danwkennedy"><code>@​danwkennedy</code></a> in
<a
href="https://redirect.github.com/actions/upload-artifact/pull/796">actions/upload-artifact#796</a></li>
<li>Include changes in typespec/ts-http-runtime 0.3.5 by <a
href="https://github.com/yacaovsnc"><code>@​yacaovsnc</code></a> in <a
href="https://redirect.github.com/actions/upload-artifact/pull/797">actions/upload-artifact#797</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/upload-artifact/compare/v7...v7.0.1">https://github.com/actions/upload-artifact/compare/v7...v7.0.1</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/upload-artifact/commit/043fb46d1a93c77aae656e7c1c64a875d1fc6a0a"><code>043fb46</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/upload-artifact/issues/797">#797</a>
from actions/yacaovsnc/update-dependency</li>
<li><a
href="https://github.com/actions/upload-artifact/commit/634250c1388765ea7ed0f053e636f1f399000b94"><code>634250c</code></a>
Include changes in typespec/ts-http-runtime 0.3.5</li>
<li><a
href="https://github.com/actions/upload-artifact/commit/e454baaac2be505c9450e11b8f3215c6fc023ce8"><code>e454baa</code></a>
Readme: bump all the example versions to v7 (<a
href="https://redirect.github.com/actions/upload-artifact/issues/796">#796</a>)</li>
<li><a
href="https://github.com/actions/upload-artifact/commit/74fad66b98a6d799dc004d3353ccd0e6f6b2530e"><code>74fad66</code></a>
Update the readme with direct upload details (<a
href="https://redirect.github.com/actions/upload-artifact/issues/795">#795</a>)</li>
<li>See full diff in <a
href="https://github.com/actions/upload-artifact/compare/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-04 22:41:40 -07:00
Connor Braa d1e2fda1b1 feat(sdk): add returnMinimal to threads update (#2363)
Adds a first-class `returnMinimal` option to JS SDK `threads.update`.
When enabled, the SDK sends `Prefer: return=minimal` and resolves with
`undefined` for the 204 response. Includes a patch changeset and focused
fetch test coverage.
2026-05-04 15:46:03 -07:00
github-actions[bot] 740ce21852 chore: version packages (#2362)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/angular@0.4.7

### Patch Changes

- [#2354](https://github.com/langchain-ai/langgraphjs/pull/2354)
[`733d28e`](https://github.com/langchain-ai/langgraphjs/commit/733d28ea637135876375fa005a8d8a5605a692e6)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): pin framework SDKs to langgraph-sdk version

## @langchain/react@0.3.5

### Patch Changes

- [#2354](https://github.com/langchain-ai/langgraphjs/pull/2354)
[`733d28e`](https://github.com/langchain-ai/langgraphjs/commit/733d28ea637135876375fa005a8d8a5605a692e6)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): pin framework SDKs to langgraph-sdk version

## @langchain/svelte@0.4.7

### Patch Changes

- [#2354](https://github.com/langchain-ai/langgraphjs/pull/2354)
[`733d28e`](https://github.com/langchain-ai/langgraphjs/commit/733d28ea637135876375fa005a8d8a5605a692e6)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): pin framework SDKs to langgraph-sdk version

## @langchain/vue@0.4.7

### Patch Changes

- [#2354](https://github.com/langchain-ai/langgraphjs/pull/2354)
[`733d28e`](https://github.com/langchain-ai/langgraphjs/commit/733d28ea637135876375fa005a8d8a5605a692e6)
Thanks [@christian-bromann](https://github.com/christian-bromann)! -
fix(sdk): pin framework SDKs to langgraph-sdk version

## @example/ai-elements@0.1.14

### Patch Changes

- Updated dependencies
\[[`733d28e`](https://github.com/langchain-ai/langgraphjs/commit/733d28ea637135876375fa005a8d8a5605a692e6)]:
    -   @langchain/react@0.3.5

## @examples/assistant-ui-claude@0.1.14

### Patch Changes

- Updated dependencies
\[[`733d28e`](https://github.com/langchain-ai/langgraphjs/commit/733d28ea637135876375fa005a8d8a5605a692e6)]:
    -   @langchain/react@0.3.5

## @examples/ui-angular@0.0.24

### Patch Changes

- Updated dependencies
\[[`733d28e`](https://github.com/langchain-ai/langgraphjs/commit/733d28ea637135876375fa005a8d8a5605a692e6)]:
    -   @langchain/angular@0.4.7

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@0.4.7 @langchain/react@0.3.5 @langchain/svelte@0.4.7 @langchain/vue@0.4.7
2026-05-01 17:30:18 -07:00
Christian Bromann 733d28ea63 fix(sdk): pin framework SDKs to langgraph-sdk version (#2354)
As a safe guard for the upcoming major release of the framework SDK
packages we pin the 0.x packages to whatever the latest langgraph-sdk
was at the time.
2026-05-01 16:58:06 -07:00
open-swe[bot] 122f649556 chore: update x handle to langchain oss (#2348)
## Description
Updates the LangGraph.js docs social link to point at the new LangChain
OSS X handle. I checked the requested README and pyproject targets; this
repo has no pyproject files or libs/partners READMEs with matching X
handle references.

## Test Plan
- [ ] Confirm docs social icon opens the @langchain_oss X profile

_Opened collaboratively by Mason Daugherty and open-swe._

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Mason Daugherty <61371264+mdrxy@users.noreply.github.com>
2026-04-29 14:03:14 -04:00
github-actions[bot] 1b66d654dd chore: version packages (#2347)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-sdk@1.8.10

### Patch Changes

- [#2340](https://github.com/langchain-ai/langgraphjs/pull/2340)
[`6bab458`](https://github.com/langchain-ai/langgraphjs/commit/6bab458d4a03ce2d7b2708488b92226899eb94d4)
Thanks [@cwlbraa](https://github.com/cwlbraa)! - Respect
`fetchStateHistory` when restoring subagent history.

## @langchain/angular@0.4.6

### Patch Changes

- [#2340](https://github.com/langchain-ai/langgraphjs/pull/2340)
[`6bab458`](https://github.com/langchain-ai/langgraphjs/commit/6bab458d4a03ce2d7b2708488b92226899eb94d4)
Thanks [@cwlbraa](https://github.com/cwlbraa)! - Respect
`fetchStateHistory` when restoring subagent history.

- Updated dependencies
\[[`6bab458`](https://github.com/langchain-ai/langgraphjs/commit/6bab458d4a03ce2d7b2708488b92226899eb94d4)]:
    -   @langchain/langgraph-sdk@1.8.10

## @langchain/react@0.3.4

### Patch Changes

- [#2340](https://github.com/langchain-ai/langgraphjs/pull/2340)
[`6bab458`](https://github.com/langchain-ai/langgraphjs/commit/6bab458d4a03ce2d7b2708488b92226899eb94d4)
Thanks [@cwlbraa](https://github.com/cwlbraa)! - Respect
`fetchStateHistory` when restoring subagent history.

- Updated dependencies
\[[`6bab458`](https://github.com/langchain-ai/langgraphjs/commit/6bab458d4a03ce2d7b2708488b92226899eb94d4)]:
    -   @langchain/langgraph-sdk@1.8.10

## @langchain/svelte@0.4.6

### Patch Changes

- [#2340](https://github.com/langchain-ai/langgraphjs/pull/2340)
[`6bab458`](https://github.com/langchain-ai/langgraphjs/commit/6bab458d4a03ce2d7b2708488b92226899eb94d4)
Thanks [@cwlbraa](https://github.com/cwlbraa)! - Respect
`fetchStateHistory` when restoring subagent history.

- Updated dependencies
\[[`6bab458`](https://github.com/langchain-ai/langgraphjs/commit/6bab458d4a03ce2d7b2708488b92226899eb94d4)]:
    -   @langchain/langgraph-sdk@1.8.10

## @langchain/vue@0.4.6

### Patch Changes

- [#2340](https://github.com/langchain-ai/langgraphjs/pull/2340)
[`6bab458`](https://github.com/langchain-ai/langgraphjs/commit/6bab458d4a03ce2d7b2708488b92226899eb94d4)
Thanks [@cwlbraa](https://github.com/cwlbraa)! - Respect
`fetchStateHistory` when restoring subagent history.

- Updated dependencies
\[[`6bab458`](https://github.com/langchain-ai/langgraphjs/commit/6bab458d4a03ce2d7b2708488b92226899eb94d4)]:
    -   @langchain/langgraph-sdk@1.8.10

## @example/ai-elements@0.1.13

### Patch Changes

- Updated dependencies
\[[`6bab458`](https://github.com/langchain-ai/langgraphjs/commit/6bab458d4a03ce2d7b2708488b92226899eb94d4)]:
    -   @langchain/react@0.3.4

## @examples/assistant-ui-claude@0.1.13

### Patch Changes

- Updated dependencies
\[[`6bab458`](https://github.com/langchain-ai/langgraphjs/commit/6bab458d4a03ce2d7b2708488b92226899eb94d4)]:
    -   @langchain/react@0.3.4

## @examples/ui-angular@0.0.23

### Patch Changes

- Updated dependencies
\[[`6bab458`](https://github.com/langchain-ai/langgraphjs/commit/6bab458d4a03ce2d7b2708488b92226899eb94d4)]:
    -   @langchain/langgraph-sdk@1.8.10
    -   @langchain/angular@0.4.6

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@0.4.6 @langchain/langgraph-sdk@1.8.10 @langchain/react@0.3.4 @langchain/svelte@0.4.6 @langchain/vue@0.4.6
2026-04-29 09:34:18 -07:00
Connor Braa 6bab458d4a fix(sdk): respect fetchStateHistory for subagent history (#2340)
## Summary

- skip eager subagent history restoration when `fetchStateHistory` is
`false`
- reuse numeric `fetchStateHistory` limits for subagent namespace
discovery
- add orchestrator regression coverage for both cases

## Context

- Slack thread:
https://langchain.slack.com/archives/C09BAECNA14/p1776755205756119
- [Agent Builder
trace](https://langchain-us.datadoghq.com/apm/entity/service%3Aagent_builder_prod?dependencyMap.showNetworkMetrics=false&fromUser=false&graphType=flamegraph&groupMapByOperation=null&historicalData=true&panels=qson%3A%28data%3A%28activePanelKey%3Atrace%2Cresource%3A%28resourceName%3APOST%2520%252Fthreads%252F%257Bthread_id%257D%252Fhistory%2CresourceID%3A2bfaa153eac24153%2CoperationName%3Astarlette.request%29%2Ctrace%3A%28traceID%3A69ef784f000000001773743cf39a72b5%2CspanID%3A8969752200629810217%2ChasSearchOrFacetActions%3A%21f%29%29%2Cversion%3A%210%29&resources=qson%3A%28data%3A%28visible%3A%21t%2Chits%3A%28selected%3Arate%2CgroupBy%3A%5Bresource_name%5D%29%2Cerrors%3A%28selected%3Atotal%2CgroupBy%3A%5Bresource_name%5D%29%2Clatency%3A%28selected%3Ap95%2CgroupBy%3A%5Bresource_name%5D%29%2CtopN%3Aall%29%2Cversion%3A%211%29&shouldShowLegend=true&spanID=8969752200629810217&spanKind=server&spanViewType=logs&summary=qson%3A%28data%3A%28visible%3A%21t%2Cchanges%3A%28%29%2Cerrors%3A%28selected%3Acount%2CgroupBy%3A%5B%5D%29%2Chits%3A%28selected%3Arate%2CgroupBy%3A%5B%5D%29%2Clatency%3A%28selected%3Alatency%2Cslot%3A%28agg%3A95%29%2Cdistribution%3A%28isLogScale%3A%21f%29%2CshowTraceOutliers%3A%21t%2CgroupBy%3A%5B%5D%2Coperation%3Astarlette.request%29%2Csublayer%3A%28slot%3A%28layers%3AserviceAndInferred%29%2Cselected%3Apercentage%29%2ClagMetrics%3A%28selectedMetric%3A%21s%2CselectedGroupBy%3A%21s%29%29%2Cversion%3A%211%29&timeHint=1777301587169&trace=AwAAAZ3PbgThpE93_wAAABhBWjNQYmdkWUFBQ2ZVVkFJVExwS3lYTVgAAAAkMTE5ZGNmODctODg4Ny00ZTY5LThlN2MtNGEzOWU2ZTE3ZjY0AAUrsg&traceID=69ef784f000000001773743cf39a72b5&traceQuery=&start=1777062982891&end=1777322182891&paused=false)

## Test Plan

- `corepack pnpm exec vitest run src/ui/orchestrator.test.ts
--typecheck.enabled=false` from `libs/sdk`
- `corepack pnpm run lint -- libs/sdk-react/src/stream.lgp.tsx
libs/sdk/src/react/stream.lgp.tsx libs/sdk/src/ui/orchestrator.ts
libs/sdk/src/ui/manager.ts libs/sdk/src/ui/orchestrator.test.ts`
- `corepack pnpm run format:check -- libs/sdk-react/src/stream.lgp.tsx
libs/sdk/src/react/stream.lgp.tsx libs/sdk/src/ui/orchestrator.ts
libs/sdk/src/ui/manager.ts libs/sdk/src/ui/orchestrator.test.ts
.changeset/tame-subagent-history.md`
2026-04-29 08:53:30 -07:00
github-actions[bot] 0120a78d58 chore: version packages (#2343)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph-checkpoint-mongodb@1.3.0

### Minor Changes

- [#2326](https://github.com/langchain-ai/langgraphjs/pull/2326)
[`36916ed`](https://github.com/langchain-ai/langgraphjs/commit/36916ed86e63eb07249a68ecf0508e3b986ba587)
Thanks [@tadjik1](https://github.com/tadjik1)! - feat: add MongoDBStore
for long-term memory

New `MongoDBStore` class for persisting data across threads and sessions
— user preferences, learned facts, agent memory, and more.

- Store and retrieve JSON documents organized by hierarchical namespaces
    -   Search with field-based filtering and comparison operators
- Vector similarity search with manual embedding (bring your own
embedding model) or auto embedding (MongoDB generates embeddings via
Voyage AI)
    -   Automatic document expiration via configurable TTL

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Hunter Lovell <hunter@hntrl.io>
@langchain/langgraph-checkpoint-mongodb@1.3.0
2026-04-28 16:37:19 -07:00
Sergey Zelenov 36916ed86e feat(langgraph-checkpoint-mongodb): add MongoDBStore for long-term memory with manual and auto embedding (#2326)
## Summary

Adds `MongoDBStore` - a `BaseStore` implementation backed by MongoDB for
long-term cross-thread memory. While the existing `MongoDBSaver`
persists graph execution state within a single thread (checkpoints),
`MongoDBStore` enables agents to store and retrieve data across threads
and sessions - user preferences, learned facts, agent instructions, and
more.

Fixes [NODE-7497](https://jira.mongodb.org/browse/NODE-7497)

Built on top of the initial implementation by @PavelSafronov and
@RaschidJFR (PR #2320). Their work provided the foundation for the
store, auto embedding integration, and Docker test setup.

## Review notes

This PR is organized into two self-contained commits that can be
reviewed independently:

1. **[`add MongoDBStore with core CRUD and field-based
search`](https://github.com/langchain-ai/langgraphjs/commit/1415f7f6c7df0338644444feffa14f8123e2f0a8)**
- the store itself with all non-embedding functionality, namespace
prefix matching, matchConditions, tests
2. **[`add manual and auto embedding
support`](https://github.com/langchain-ai/langgraphjs/pull/2326/changes/7bc2ecd80840b1bd291d7dfcdc012a704b614040)**
- adds vector search on top of the first commit, including IndexConfig,
embedding logic in put/search, vector search index creation, tests

## What's included

### Core store (commit 1)
- `MongoDBStore` extending `BaseStore` with Put, Get, Delete, Search,
and ListNamespaces operations
- Hierarchical namespace organization with unique `(namespace, key)`
index
- Field-based search with comparison operators (`$eq`, `$ne`, `$gt`,
`$gte`, `$lt`, `$lte`)
- Namespace prefix matching in search using dot-notation array indexing
- ListNamespaces with `matchConditions` support (prefix, suffix, and
wildcard filtering)
- TTL support via MongoDB TTL index with optional refresh-on-read
- Factory method `fromConnString` for convenient setup
- Refactors existing `MongoDBSaver` into separate `checkpoint.ts` file

### Embedding support (commit 2)
Two modes for vector similarity search via MongoDB `$vectorSearch`, both
requiring `indexConfig`:

**Manual embedding** - app provides an `EmbeddingsInterface`:
  - Store computes vectors on put via `embedDocuments()`
- Search computes query vector via `embedQuery()` and uses `queryVector`
in `$vectorSearch`

**Auto embedding** - no `EmbeddingsInterface` needed:
  - Store writes plain text to the embedding field
- MongoDB generates embeddings server-side via Voyage AI (requires
`model` in `indexConfig`)
  - Search sends query text via `query.text` in `$vectorSearch`
  - Requires MongoDB 8.2+ with auto embedding support

---------

Co-authored-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com>
2026-04-28 14:48:27 -07:00
John Kennedy 7f3320cda8 fix: patch 6 medium-severity security alerts (#2333)
## Security Alert Patch (medium-tier follow-up)

Follow-up to #2329, which patched the critical+high tier. This PR
resolves the remaining **6 medium-severity Dependabot alerts** via
`pnpm.overrides` plus one published-path constraint bump. All fixes are
patch/minor bumps within the current major — no breaking changes.

### Packages Updated

| Package | Old Constraint | New Constraint | Strategy | Scope | CVEs
Resolved |

|---------|---------------|----------------|----------|-------|---------------|
| `axios` | `>=1.13.5` (override) | `>=1.15.0` (override); resolved
1.13.6 → **1.15.1** | C (override) | dev-only (via `@langchain/scripts`
devDep) | CVE-2025-62718 (SSRF via NO_PROXY bypass), CVE-2026-40175
(cloud metadata exfiltration) |
| `dompurify` | (transitive, resolved 3.3.3) | `>=3.4.0` (new override);
resolved **3.4.0** | C (override) | dev-only (private
`@example/ai-elements` via mermaid) | GHSA-39q2-94rc-95cp (ADD_TAGS
bypasses FORBID_TAGS) |
| `follow-redirects` | (transitive, resolved 1.15.11) | `>=1.16.0` (new
override); resolved **1.16.0** | C (override) | dev-only (via
`@langchain/scripts` devDep) | GHSA-r4q5-vmmm-2653 (auth header leak on
cross-domain redirect) |
| `langsmith` (published path) | `langsmith: >=0.3.33 <1.0.0` in
`libs/langgraph-api/package.json` | `>=0.5.19 <1.0.0` | **A (manifest
bump)** | **published** — direct dep of `@langchain/langgraph-api` |
CVE-2026-40190 (prototype pollution), GHSA-rr7j-v2q5-chgv (streaming
redaction bypass) |
| `langsmith` (dev chains) | (transitive 0.4.12, 0.5.16 resolved via
`@langchain/classic`, `langchain@1.3.0`) | `langsmith@<0.5.19: >=0.5.19
<1` (new override) | C (override) | dev-only | same as above (flushes
vulnerable transitive copies) |

*Strategy C overrides follow the existing repo pattern — axios, qs,
undici, minimatch, brace-expansion, protobufjs, basic-ftp, vite, and
defu are already overridden the same way.*

### Published-path rationale

`@langchain/langgraph-api` exercises `langsmith` at runtime for tracing
and streaming, which touches the affected internal code paths (lodash
`set()` prototype-pollution guard, token-event redaction). Therefore the
fix is Strategy A (raise the published lower bound) rather than
A-lockfile — this protects end users who pin `@langchain/langgraph-api`.
The lockfile already resolved `langsmith@0.5.20` before this change, so
installs are unchanged at HEAD; the bump is a downstream-safety
constraint tightening.

### Deferred (not fixed in this PR)

- **`protobufjs@6.11.5`** (CRITICAL, CVE-2026-41242) — reached via
`@xenova/transformers@2.17.2` in `libs/langgraph-core` devDeps +
examples. `@xenova/transformers` is abandoned; the successor is
`@huggingface/transformers@3`. Forcing a 6.x → 7.x override would cross
a breaking API boundary. **Upstream issue — requires a manual migration,
tracked separately.** (See #2329 body for full context.)
- **`elliptic@6.6.1`** (LOW, GHSA-848j-6mx2-7j84) —
`first_patched_version` is `null`; upstream has not released a fix.
Defer until a patched version ships.

### CVE Details

- **CVE-2025-62718** / GHSA-3p68-rc4w-qgx5 — Axios NO_PROXY Hostname
Normalization Bypass Leads to SSRF —
https://github.com/advisories/GHSA-3p68-rc4w-qgx5
- **CVE-2026-40175** / GHSA-fvcv-3m26-pcqx — Axios Unrestricted Cloud
Metadata Exfiltration via Header Injection Chain —
https://github.com/advisories/GHSA-fvcv-3m26-pcqx
- **GHSA-39q2-94rc-95cp** — DOMPurify `ADD_TAGS` bypasses `FORBID_TAGS`
via short-circuit evaluation —
https://github.com/advisories/GHSA-39q2-94rc-95cp
- **GHSA-r4q5-vmmm-2653** — follow-redirects leaks custom authentication
headers to cross-domain redirect targets —
https://github.com/advisories/GHSA-r4q5-vmmm-2653
- **CVE-2026-40190** / GHSA-fw9q-39r9-c252 — LangSmith prototype
pollution via incomplete `__proto__` guard in internal lodash `set()` —
https://github.com/advisories/GHSA-fw9q-39r9-c252
- **GHSA-rr7j-v2q5-chgv** — LangSmith streaming token events bypass
output redaction — https://github.com/advisories/GHSA-rr7j-v2q5-chgv

### Linear Tickets

Linear ticket lookup returned no matches for the resolved CVEs/GHSAs. No
ticket IDs included in the title.

### Verification

- [x] Lockfile regenerated via `pnpm install --lockfile-only`
- [x] `pnpm lint` (oxlint) — 0 warnings, 0 errors
- [x] `pnpm format:check` (oxfmt) — clean
- [x] `pnpm audit --prod` — **No known vulnerabilities found**
- [x] `pnpm typecheck` on `libs/langgraph-api` — clean
- [x] No staged secrets (`gitleaks git --staged`)

🤖 Submitted by langster-patch

Co-authored-by: John Kennedy <jkennedyvz@users.noreply.github.com>
2026-04-22 09:26:44 -07:00
John Kennedy 076f7f81f0 fix: patch 7 security alerts (critical + high severity) (#2329)
## Security Alert Patch

Resolves **7 Dependabot security alerts** in the critical + high
severity tier via `pnpm.overrides` in the root `package.json`. All fixes
are patch/minor bumps within the current major — no breaking changes.

### Packages Updated

| Package | Old Constraint | New Constraint | Strategy | Scope | CVEs
Resolved |

|---------|---------------|----------------|----------|-------|---------------|
| `protobufjs` | (transitive, resolved 7.5.4) | `>=7.5.5 <8` | C
(override) | dev-only (testcontainers chain + `@xenova/transformers`
devDeps) | CVE-2026-41242 |
| `basic-ftp` | (transitive, resolved 5.2.0) | `>=5.3.0 <6` | C
(override) | effectively dev-only (reached only via `@vitest/browser` —
an optional peerDep of vitest — through webdriverio→proxy-agent) |
GHSA-rp42-5vxx-qpwr, GHSA-6v7q-wjvx-w8wg, CVE-2026-39983 |
| `vite` (7.x only) | (transitive via vitest peer, resolved 7.3.1) |
`>=7.3.2` | C (override, scoped to vite@7) | effectively dev-only (vite
is a peerDependency of vitest — end users supply their own vite) |
CVE-2026-39363, CVE-2026-39364 |
| `defu` | (transitive, resolved 6.1.4) | `>=6.1.5 <7` | C (override) |
dev-only (`internal/build` via tsdown) | CVE-2026-35209 |

*Strategy C (pnpm.overrides) follows the existing pattern in this repo —
axios, qs, undici, minimatch, brace-expansion, etc. are already
overridden the same way.*

### Side-effect Fixes

Bumping `vite@7` to 7.3.2 also resolves one **medium** alert that wasn't
in the primary batch:

- CVE-2026-39365 / GHSA-4w7w-66w2-5vf9 — vite Path Traversal in
Optimized Deps `.map` Handling

### Upstream / Design Issues (NOT fixed in this PR)

- **`protobufjs@6.11.x`** persists in the dependency graph via
`@xenova/transformers@2.17.2` (`libs/langgraph-core` devDep + 9 example
apps). `@xenova/transformers` is abandoned and rebranded as
`@huggingface/transformers@3`; a migration would be a separate manual
dev-only upgrade. The 6.x line is in devDependencies only and does not
ship to published package consumers. Dependabot may continue to flag the
6.x range because the advisory's `vulnerable_range` is `< 7.5.5`.

- **Published-path caveat for `basic-ftp` and `vite`:** Both transit
through `@langchain/langgraph-checkpoint-validation`'s
`dependencies.vitest`. However, `vite` is declared as a
**peerDependency** of vitest (end users supply their own), and
`basic-ftp` reaches end users only through `@vitest/browser` — an
**optional peerDependency** that users must explicitly opt into.
Overrides in this PR protect local dev and CI; end users of
`@langchain/langgraph-checkpoint-validation` are not exposed unless they
independently install and configure the browser-testing chain.

### Deferred (medium + low tier)

Per security-alert-patch policy, only the highest active severity tier
was patched in this PR. The following remain open and would be addressed
in a follow-up batch:

- 6 medium: axios ×2 (SSRF + cloud-metadata exfil — existing `axios:
>=1.13.5` override doesn't cover 1.15.0), dompurify, langsmith ×2,
follow-redirects
- 1 low: elliptic (no `first_patched_version` published — upstream has
not released a fix)

### Verification

- [x] Lockfile regenerated via `pnpm install --lockfile-only`
- [x] `pnpm lint` (oxlint) — 0 warnings, 0 errors
- [x] `pnpm format:check` (oxfmt) — clean
- [x] `pnpm audit --prod` — 0 critical, 0 high remaining (3 moderates =
the deferred medium alerts)
- [x] No staged secrets (gitleaks)

### Linear Tickets

Linear ticket lookup skipped — CLI not authenticated in this
environment. No ticket IDs included in title.

🤖 Submitted by langster-patch

Co-authored-by: John Kennedy <jkennedyvz@users.noreply.github.com>
2026-04-20 21:47:08 -07:00
dependabot[bot] 786fe03646 chore(deps): bump vite from 7.3.2 to 8.0.5 (#2322) 2026-04-20 20:07:04 -07:00
github-actions[bot] aba243a403 chore: version packages (#2313)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## @langchain/langgraph@1.2.9

### Patch Changes

- [#2315](https://github.com/langchain-ai/langgraphjs/pull/2315)
[`9102d52`](https://github.com/langchain-ai/langgraphjs/commit/9102d526c858a4cdbe9b47dcdd062b93da93e49f)
Thanks [@hntrl](https://github.com/hntrl)! - propagate tracer metadata
defaults from configurable

- [#2311](https://github.com/langchain-ai/langgraphjs/pull/2311)
[`b7c196b`](https://github.com/langchain-ai/langgraphjs/commit/b7c196b2142fb888dfcd9ceb1dfb4365d803c8b6)
Thanks [@open-swe](https://github.com/apps/open-swe)! - fix: export
missing types for typescript 6.0 declaration file compatibility

- Updated dependencies
\[[`458d66b`](https://github.com/langchain-ai/langgraphjs/commit/458d66bf665468854abb8133594d4d4f966054ed)]:
    -   @langchain/langgraph-sdk@1.8.9

## @langchain/langgraph-sdk@1.8.9

### Patch Changes

- [#2302](https://github.com/langchain-ai/langgraphjs/pull/2302)
[`458d66b`](https://github.com/langchain-ai/langgraphjs/commit/458d66bf665468854abb8133594d4d4f966054ed)
Thanks [@AdrianSajjan](https://github.com/AdrianSajjan)! - fix(sdk):
preserve messages on interrupt values events

    Add a regression test for interrupt-only `values` payloads to ensure
previously streamed messages are not overwritten when `__interrupt__` is
emitted.

## @example/ai-elements@0.1.12

### Patch Changes

- Updated dependencies
\[[`9102d52`](https://github.com/langchain-ai/langgraphjs/commit/9102d526c858a4cdbe9b47dcdd062b93da93e49f),
[`b7c196b`](https://github.com/langchain-ai/langgraphjs/commit/b7c196b2142fb888dfcd9ceb1dfb4365d803c8b6)]:
    -   @langchain/langgraph@1.2.9

## @examples/assistant-ui-claude@0.1.12

### Patch Changes

- Updated dependencies
\[[`9102d52`](https://github.com/langchain-ai/langgraphjs/commit/9102d526c858a4cdbe9b47dcdd062b93da93e49f),
[`b7c196b`](https://github.com/langchain-ai/langgraphjs/commit/b7c196b2142fb888dfcd9ceb1dfb4365d803c8b6)]:
    -   @langchain/langgraph@1.2.9

## @examples/ui-angular@0.0.22

### Patch Changes

- Updated dependencies
\[[`458d66b`](https://github.com/langchain-ai/langgraphjs/commit/458d66bf665468854abb8133594d4d4f966054ed),
[`9102d52`](https://github.com/langchain-ai/langgraphjs/commit/9102d526c858a4cdbe9b47dcdd062b93da93e49f),
[`b7c196b`](https://github.com/langchain-ai/langgraphjs/commit/b7c196b2142fb888dfcd9ceb1dfb4365d803c8b6)]:
    -   @langchain/langgraph-sdk@1.8.9
    -   @langchain/langgraph@1.2.9

## langgraph@1.0.31

### Patch Changes

- Updated dependencies
\[[`9102d52`](https://github.com/langchain-ai/langgraphjs/commit/9102d526c858a4cdbe9b47dcdd062b93da93e49f),
[`b7c196b`](https://github.com/langchain-ai/langgraphjs/commit/b7c196b2142fb888dfcd9ceb1dfb4365d803c8b6)]:
    -   @langchain/langgraph@1.2.9

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Hunter Lovell <hunter@hntrl.io>
@langchain/langgraph-sdk@1.8.9 @langchain/langgraph@1.2.9
2026-04-16 07:07:37 +00:00
dependabot[bot] ac9947f64d chore(deps): bump langsmith from 0.5.19 to 0.5.20 (#2323)
Bumps [langsmith](https://github.com/langchain-ai/langsmith-sdk) from
0.5.19 to 0.5.20.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/langchain-ai/langsmith-sdk/commits">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=langsmith&package-manager=npm_and_yarn&previous-version=0.5.19&new-version=0.5.20)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraphjs/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-16 03:45:01 +00:00
dependabot[bot] a9db0172df chore(deps): bump hono from 4.12.12 to 4.12.14 (#2321)
Bumps [hono](https://github.com/honojs/hono) from 4.12.12 to 4.12.14.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/honojs/hono/releases">hono's
releases</a>.</em></p>
<blockquote>
<h2>v4.12.14</h2>
<h2>Security fixes</h2>
<p>This release includes fixes for the following security issues:</p>
<h3>Improper handling of JSX attribute names in hono/jsx SSR</h3>
<p>Affects: hono/jsx. Fixes missing validation of JSX attribute names
during server-side rendering, which could allow malformed attribute keys
to corrupt the generated HTML output and inject unintended attributes or
elements. GHSA-458j-xx4x-4375</p>
<h2>Other changes</h2>
<ul>
<li>fix(aws-lambda): handle invalid header names in request processing
(<a
href="https://redirect.github.com/honojs/hono/issues/4883">#4883</a>)
fa2c74fe</li>
</ul>
<h2>v4.12.13</h2>
<h2>What's Changed</h2>
<ul>
<li>fix(types): infer response type from last handler in app.on
9-/10-handler overloads by <a
href="https://github.com/T4ko0522"><code>@​T4ko0522</code></a> in <a
href="https://redirect.github.com/honojs/hono/pull/4865">honojs/hono#4865</a></li>
<li>feat(trailing-slash): add <code>skip</code> option by <a
href="https://github.com/yusukebe"><code>@​yusukebe</code></a> in <a
href="https://redirect.github.com/honojs/hono/pull/4862">honojs/hono#4862</a></li>
<li>feat(cache): add <code>onCacheNotAvailable</code> option by <a
href="https://github.com/yusukebe"><code>@​yusukebe</code></a> in <a
href="https://redirect.github.com/honojs/hono/pull/4876">honojs/hono#4876</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/T4ko0522"><code>@​T4ko0522</code></a>
made their first contribution in <a
href="https://redirect.github.com/honojs/hono/pull/4865">honojs/hono#4865</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/honojs/hono/compare/v4.12.12...v4.12.13">https://github.com/honojs/hono/compare/v4.12.12...v4.12.13</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/honojs/hono/commit/cf2d2b7edcf07adef2db7614557f4d7f9e2be7ba"><code>cf2d2b7</code></a>
4.12.14</li>
<li><a
href="https://github.com/honojs/hono/commit/66daa2edef8965544c04fcad82c596ab2acdb5ee"><code>66daa2e</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/honojs/hono/commit/fa2c74fe5c3ce996d025d9d97bf5670c207bb82e"><code>fa2c74f</code></a>
fix(aws-lambda): handle invalid header names in request processing (<a
href="https://redirect.github.com/honojs/hono/issues/4883">#4883</a>)</li>
<li><a
href="https://github.com/honojs/hono/commit/3779927c17201dc6bfd20697f0e1ec65407da779"><code>3779927</code></a>
4.12.13</li>
<li><a
href="https://github.com/honojs/hono/commit/faa6c46a1aa3a8b792b29e20fc93bcd6d2a4d720"><code>faa6c46</code></a>
feat(cache): add <code>onCacheNotAvailable</code> option (<a
href="https://redirect.github.com/honojs/hono/issues/4876">#4876</a>)</li>
<li><a
href="https://github.com/honojs/hono/commit/f23e97b7f300bcb8571ae864010b8f7cdb5d0d5d"><code>f23e97b</code></a>
feat(trailing-slash): add <code>skip</code> option (<a
href="https://redirect.github.com/honojs/hono/issues/4862">#4862</a>)</li>
<li><a
href="https://github.com/honojs/hono/commit/1aa32fb91e7bc1366811d80ebcce61ec0d0c68cb"><code>1aa32fb</code></a>
fix(types): infer response type from last handler in app.on 9- and
10-handler...</li>
<li>See full diff in <a
href="https://github.com/honojs/hono/compare/v4.12.12...v4.12.14">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=hono&package-manager=npm_and_yarn&previous-version=4.12.12&new-version=4.12.14)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraphjs/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 19:45:00 -07:00
Hunter Lovell 9102d526c8 fix(langgraph): propagate tracer metadata defaults from configurable (#2315)
## Summary

This updates Pregel callback manager initialization to pass
`tracerInheritableMetadata` defaults derived from `config.configurable`,
and narrows `ensureLangGraphConfig` metadata mirroring to the
allowlisted LangGraph identifiers used in stream/runtime metadata.

## Changes

### `@langchain/langgraph` (`libs/langgraph-core`)

- Updated Pregel callback manager setup to configure core callbacks with
`tracerInheritableMetadata` based on configurable primitive values,
excluding internal and secret-like keys.
- Hoisted tracing default logic into `_getTracingMetadataDefaults` and
`_excludeAsMetadata` for parity with the Python implementation shape.
- Restricted `ensureLangGraphConfig` configurable-to-metadata
propagation to the identifier allowlist:
  - `thread_id`
  - `checkpoint_id`
  - `checkpoint_ns`
  - `task_id`
  - `run_id`
  - `assistant_id`
  - `graph_id`
- Updated config tests to assert the narrowed metadata propagation
behavior.
2026-04-15 18:48:41 -07:00
dependabot[bot] 7da383a8e6 chore(deps-dev): bump vite from 7.3.1 to 7.3.2 (#2297)
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite)
from 7.3.1 to 7.3.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vitejs/vite/releases">vite's
releases</a>.</em></p>
<blockquote>
<h2>v7.3.2</h2>
<p>Please refer to <a
href="https://github.com/vitejs/vite/blob/v7.3.2/packages/vite/CHANGELOG.md">CHANGELOG.md</a>
for details.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vitejs/vite/blob/v7.3.2/packages/vite/CHANGELOG.md">vite's
changelog</a>.</em></p>
<blockquote>
<h2><!-- raw HTML omitted --><a
href="https://github.com/vitejs/vite/compare/v7.3.1...v7.3.2">7.3.2</a>
(2026-04-06)<!-- raw HTML omitted --></h2>
<h3>Bug Fixes</h3>
<ul>
<li>avoid path traversal with optimize deps sourcemap handler (<a
href="https://redirect.github.com/vitejs/vite/issues/22161">#22161</a>)
(<a
href="https://github.com/vitejs/vite/commit/09d8c903bde12fee2710314d3b42bc789c686df7">09d8c90</a>)</li>
<li>backport <a
href="https://redirect.github.com/vitejs/vite/issues/22159">#22159</a>,
apply server.fs check to env transport (<a
href="https://redirect.github.com/vitejs/vite/issues/22162">#22162</a>)
(<a
href="https://github.com/vitejs/vite/commit/19db0f29c3a3ac4e64cc95c270716c77fd223ad1">19db0f2</a>)</li>
<li>check <code>server.fs</code> after stripping query as well (<a
href="https://redirect.github.com/vitejs/vite/issues/22160">#22160</a>)
(<a
href="https://github.com/vitejs/vite/commit/f8103cc946f137a54e395fe3f5d08e8209231ed6">f8103cc</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vitejs/vite/commit/cc383e07b66d4c5a9768fcb570e0af812cb8d999"><code>cc383e0</code></a>
release: v7.3.2</li>
<li><a
href="https://github.com/vitejs/vite/commit/09d8c903bde12fee2710314d3b42bc789c686df7"><code>09d8c90</code></a>
fix: avoid path traversal with optimize deps sourcemap handler (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22161">#22161</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/f8103cc946f137a54e395fe3f5d08e8209231ed6"><code>f8103cc</code></a>
fix: check <code>server.fs</code> after stripping query as well (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22160">#22160</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/19db0f29c3a3ac4e64cc95c270716c77fd223ad1"><code>19db0f2</code></a>
fix: backport <a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22159">#22159</a>,
apply server.fs check to env transport (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22162">#22162</a>)</li>
<li>See full diff in <a
href="https://github.com/vitejs/vite/commits/v7.3.2/packages/vite">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-16 01:43:26 +00:00
dependabot[bot] 5a0d0d0155 chore(deps): bump langsmith from 0.5.18 to 0.5.19 (#2319)
Bumps [langsmith](https://github.com/langchain-ai/langsmith-sdk) from
0.5.18 to 0.5.19.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/langchain-ai/langsmith-sdk/commits">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=langsmith&package-manager=npm_and_yarn&previous-version=0.5.18&new-version=0.5.19)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraphjs/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-14 16:51:50 -07:00
Hunter Lovell e3ff7735eb ci: add PR title lint workflow (#2318)
## Summary
Adds pull request title linting to enforce Conventional Commit style
titles in this repository.

## Changes
- Add .github/workflows/pr_lint.yml
- Reject empty scopes in PR titles (for example, fix(): ...)
- Validate title format via amannn/action-semantic-pull-request
- Allow langgraphjs package/area scopes and ignore label override
2026-04-14 14:24:40 -07:00
Adrian Sajjan 458d66bf66 Prevent values from getting overrwritten on interrupt event (#2302)
Issue:

In multi-agent sustem with handoffs like this example:
https://docs.langchain.com/oss/python/langchain/multi-agent/handoffs#multiple-agent-subgraphs,
if we trigger an interrupt from an agent within a swarm workflow, the
interrupt is propagated and sent twice, the last interrupt contains
values from the main graphs state, which is always going to be behind
the state of the agent from where interrupt is triggered. So,
temporarily, the message data becomes empty, it gets refilled when
interrupt is resumed

Fixes:

Do not update values when interrupt is recieved, just update the
interrupt in the state with the latest __interrupt data.

---------

Co-authored-by: Hunter Lovell <hunter@hntrl.io>
2026-04-14 12:54:08 -07:00
open-swe[bot] b7c196b214 fix: export missing types for typescript 6.0 declaration file compatibility (#2311)
## Description
TypeScript 6.0 requires that any type emitted to a declaration file is
reachable via the package's `exports` field. Several types used in
`StateGraph`'s public API (class extends clause, constructor overloads,
method signatures) were not exported from the package entrypoints,
causing TS6 consumers to fail when exporting `StateGraph` instances from
their own packages.

Adds exports for: `ToStateDefinition`, `StateGraphNodeSpec`, `NodeSpec`,
`AddNodeOptions`, `StateGraphAddNodeOptions`,
`StateGraphArgsWithStateSchema`, `StateGraphArgsWithInputOutputSchemas`,
`CachePolicy`, `AnyStateSchema`, `StateSchemaFieldToChannel`,
`StateSchemaFieldsToStateDefinition`.

## Test Plan
- [ ] Verify a TS6 project can export a `StateGraph` instance without
declaration file errors
- [ ] Build passes with `pnpm build`

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Christian Bromann <git@bromann.dev>
2026-04-13 10:28:29 -07:00
dependabot[bot] aa2cfc8bf7 chore(deps): bump langsmith from 0.5.16 to 0.5.18 (#2307)
Bumps [langsmith](https://github.com/langchain-ai/langsmith-sdk) from
0.5.16 to 0.5.18.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/langchain-ai/langsmith-sdk/commits">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=langsmith&package-manager=npm_and_yarn&previous-version=0.5.16&new-version=0.5.18)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraphjs/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-10 13:58:27 -07:00
dependabot[bot] af76eb76f4 chore(deps): bump vite from 7.3.1 to 7.3.2 in /internal/environment_tests/test-exports-vite in the npm_and_yarn group across 1 directory (#2299)
Bumps the npm_and_yarn group with 1 update in the
/internal/environment_tests/test-exports-vite directory:
[vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite).

Updates `vite` from 7.3.1 to 7.3.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vitejs/vite/releases">vite's
releases</a>.</em></p>
<blockquote>
<h2>v7.3.2</h2>
<p>Please refer to <a
href="https://github.com/vitejs/vite/blob/v7.3.2/packages/vite/CHANGELOG.md">CHANGELOG.md</a>
for details.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vitejs/vite/blob/v7.3.2/packages/vite/CHANGELOG.md">vite's
changelog</a>.</em></p>
<blockquote>
<h2><!-- raw HTML omitted --><a
href="https://github.com/vitejs/vite/compare/v7.3.1...v7.3.2">7.3.2</a>
(2026-04-06)<!-- raw HTML omitted --></h2>
<h3>Bug Fixes</h3>
<ul>
<li>avoid path traversal with optimize deps sourcemap handler (<a
href="https://redirect.github.com/vitejs/vite/issues/22161">#22161</a>)
(<a
href="https://github.com/vitejs/vite/commit/09d8c903bde12fee2710314d3b42bc789c686df7">09d8c90</a>)</li>
<li>backport <a
href="https://redirect.github.com/vitejs/vite/issues/22159">#22159</a>,
apply server.fs check to env transport (<a
href="https://redirect.github.com/vitejs/vite/issues/22162">#22162</a>)
(<a
href="https://github.com/vitejs/vite/commit/19db0f29c3a3ac4e64cc95c270716c77fd223ad1">19db0f2</a>)</li>
<li>check <code>server.fs</code> after stripping query as well (<a
href="https://redirect.github.com/vitejs/vite/issues/22160">#22160</a>)
(<a
href="https://github.com/vitejs/vite/commit/f8103cc946f137a54e395fe3f5d08e8209231ed6">f8103cc</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vitejs/vite/commit/cc383e07b66d4c5a9768fcb570e0af812cb8d999"><code>cc383e0</code></a>
release: v7.3.2</li>
<li><a
href="https://github.com/vitejs/vite/commit/09d8c903bde12fee2710314d3b42bc789c686df7"><code>09d8c90</code></a>
fix: avoid path traversal with optimize deps sourcemap handler (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22161">#22161</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/f8103cc946f137a54e395fe3f5d08e8209231ed6"><code>f8103cc</code></a>
fix: check <code>server.fs</code> after stripping query as well (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22160">#22160</a>)</li>
<li><a
href="https://github.com/vitejs/vite/commit/19db0f29c3a3ac4e64cc95c270716c77fd223ad1"><code>19db0f2</code></a>
fix: backport <a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22159">#22159</a>,
apply server.fs check to env transport (<a
href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/22162">#22162</a>)</li>
<li>See full diff in <a
href="https://github.com/vitejs/vite/commits/v7.3.2/packages/vite">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=vite&package-manager=npm_and_yarn&previous-version=7.3.1&new-version=7.3.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/langchain-ai/langgraphjs/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 23:06:51 -07:00
dependabot[bot] 9c1e3278fe chore(deps): bump @hono/node-server from 1.19.11 to 1.19.13 (#2300)
Bumps [@hono/node-server](https://github.com/honojs/node-server) from
1.19.11 to 1.19.13.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/honojs/node-server/releases"><code>@​hono/node-server</code>'s
releases</a>.</em></p>
<blockquote>
<h2>v1.19.13</h2>
<h2>Security Fix</h2>
<p>Fixed an issue in Serve Static Middleware where inconsistent handling
of repeated slashes (<code>//</code>) between the router and static file
resolution could allow middleware to be bypassed. Users of Serve Static
Middleware are encouraged to upgrade to this version.</p>
<p>See GHSA-92pp-h63x-v22m for details.</p>
<h2>v1.19.12</h2>
<h2>What's Changed</h2>
<ul>
<li>chore: ignore claude setting by <a
href="https://github.com/yusukebe"><code>@​yusukebe</code></a> in <a
href="https://redirect.github.com/honojs/node-server/pull/314">honojs/node-server#314</a></li>
<li>fix: request draining for early 413 responses by <a
href="https://github.com/usualoma"><code>@​usualoma</code></a> in <a
href="https://redirect.github.com/honojs/node-server/pull/329">honojs/node-server#329</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/honojs/node-server/compare/v1.19.11...v1.19.12">https://github.com/honojs/node-server/compare/v1.19.11...v1.19.12</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/honojs/node-server/commit/fd64e659a34ec661fd9ccda00d1b9dff88dfaf90"><code>fd64e65</code></a>
1.19.13</li>
<li><a
href="https://github.com/honojs/node-server/commit/025c30f55d589ddbe6048b151d77e904f67a8cc2"><code>025c30f</code></a>
Merge commit from fork</li>
<li><a
href="https://github.com/honojs/node-server/commit/6cdb5a724952f3df5748e435637792068ebea6d9"><code>6cdb5a7</code></a>
1.19.12</li>
<li><a
href="https://github.com/honojs/node-server/commit/70250f780ec99d2ddc0dd8275a42f8e091e06e94"><code>70250f7</code></a>
fix: request draining for early 413 responses (<a
href="https://redirect.github.com/honojs/node-server/issues/329">#329</a>)</li>
<li><a
href="https://github.com/honojs/node-server/commit/cfc08b330a1f2e0a2d8cc7797cde389465b5f4fb"><code>cfc08b3</code></a>
chore: ignore claude setting (<a
href="https://redirect.github.com/honojs/node-server/issues/314">#314</a>)</li>
<li>See full diff in <a
href="https://github.com/honojs/node-server/compare/v1.19.11...v1.19.13">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 17:27:00 -07:00
dependabot[bot] 96a92c01a6 chore(deps): bump hono from 4.12.7 to 4.12.12 (#2301)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-08 14:34:47 -07:00
github-actions[bot] 9e9807523f chore: version packages (#2294)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Hunter Lovell <hunter@hntrl.io>
@langchain/langgraph@1.2.8
2026-04-07 08:14:22 -07:00
open-swe[bot] e42c2c8836 feat: enhance runtime with executionInfo and serverInfo (#2275)
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Sydney Runkle <54324534+sydney-runkle@users.noreply.github.com>
Co-authored-by: Hunter Lovell <hunter@hntrl.io>
Co-authored-by: Hunter Lovell <40191806+hntrl@users.noreply.github.com>
2026-04-05 21:15:56 -07:00
github-actions[bot] 2a5b85bf55 chore: version packages (#2293)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@0.4.5 @langchain/langgraph-sdk@1.8.8 @langchain/react@0.3.3 @langchain/svelte@0.4.5 @langchain/vue@0.4.5
2026-04-05 18:28:15 -07:00
Christian Bromann d74ef958ba chore(sdk): strengthen framework browser stream tests (#2289) 2026-04-05 18:22:58 -07:00
Christian Bromann 33293c7f3f fix(sdk): buffer subagent messages instead of dropping them (#2292) 2026-04-05 18:22:36 -07:00
github-actions[bot] 89fed91da2 chore: version packages (#2291)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@0.4.4 @langchain/svelte@0.4.4 @langchain/vue@0.4.4
2026-04-05 17:41:29 -07:00
Christian Bromann 4cddca61ce fix(vue): actually make it reactive (#2290) 2026-04-05 17:36:19 -07:00
github-actions[bot] 3a81396657 chore: version packages (#2288)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@0.4.3 @langchain/svelte@0.4.3 @langchain/vue@0.4.3
2026-04-05 16:29:22 -07:00
Christian Bromann 591d2dc70e fix(sdk): subagent stream reactivity (#2287) 2026-04-05 16:25:53 -07:00
github-actions[bot] 29f071d826 chore: version packages (#2286)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@0.4.2 @langchain/langgraph-sdk@1.8.7 @langchain/react@0.3.2 @langchain/svelte@0.4.2 @langchain/vue@0.4.2
2026-04-03 23:09:53 -07:00
Christian Bromann a5dfdb61c7 fix(sdk): detect interrupt for Python agents (#2285) 2026-04-03 23:06:34 -07:00
github-actions[bot] 7176861f72 chore: version packages (#2284)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@0.4.1 @langchain/langgraph-sdk@1.8.6 @langchain/react@0.3.1 @langchain/svelte@0.4.1 @langchain/vue@0.4.1
2026-04-03 22:29:39 -07:00
Christian Bromann b4a841c4b3 fix(sdk): bump all packages 2026-04-03 22:26:13 -07:00
github-actions[bot] ed1107df54 chore: version packages (#2283)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@langchain/angular@0.4.0 @langchain/langgraph@1.2.7 @langchain/react@0.3.0 @langchain/svelte@0.4.0 @langchain/vue@0.4.0
2026-04-03 22:14:06 -07:00