Skip to content

chore(deps): lock file maintenance#1707

Merged
shunkakinoki merged 1 commit intomainfrom
renovate/lock-file-maintenance
May 8, 2026
Merged

chore(deps): lock file maintenance#1707
shunkakinoki merged 1 commit intomainfrom
renovate/lock-file-maintenance

Conversation

@shunkakinoki
Copy link
Copy Markdown
Owner

@shunkakinoki shunkakinoki commented May 8, 2026

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.


Summary by cubic

Refresh lock files (bun.lock, flake.lock) to pick up current dependency versions and Nix inputs. No application code changes.

  • Dependencies
    • Bumped @noble/curves to 1.9.7 and @opentelemetry/api to 1.9.1; cleaned up a few alias entries.
    • Updated Nix inputs to newer nixpkgs-nightly and NUR revisions.

Written for commit 85aa4b6. Summary will update on new commits.

@shunkakinoki shunkakinoki enabled auto-merge (squash) May 8, 2026 04:06
@indent
Copy link
Copy Markdown
Contributor

indent Bot commented May 8, 2026

PR Summary

Routine Renovate lockFileMaintenance refresh of bun.lock and flake.lock. No package.json or flake.nix declarations are touched, and no package versions or integrity hashes for retained entries are altered, so there is no resolution or supply-chain delta beyond the rolling Nix inputs.

  • bun.lock: prunes redundant hoisted nested entries (mostly duplicate @opentelemetry/.../api-logs/@opentelemetry/api@1.9.1 hoists and several openclaw/@mariozechner/.../@aws-sdk/client-bedrock-runtime + @aws-sdk/token-providers@3.1045.0 entries); net +9/-69 lines, deletions only.
  • flake.lock: bumps the two rolling inputs nixpkgs-nightly (75fd6ff…b1c9fea…) and NUR (8186143…93212c6…), ~3.7-hour delta on the same upstream sources, with narHash updated accordingly.

Issues

1 potential issue found:

  • The root tar entry in bun.lock moved from 7.5.15 to 7.5.13 because Bun deduplicated to openclaw's exact pin (tar: "7.5.13"); confirm any non-openclaw consumer hoisting the root tar is OK with the 2-patch rollback, otherwise bump openclaw's tar pin so dedup goes the other direction. → Autofix

CI Checks

Waiting for CI checks...


⚡ Autofix All Issues

@mesa-dot-dev
Copy link
Copy Markdown

mesa-dot-dev Bot commented May 8, 2026

You do not have enough credits to review this pull request. Please purchase more credits to continue.

@coderabbitai
Copy link
Copy Markdown

coderabbitai Bot commented May 8, 2026

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (2)
  • bun.lock is excluded by !**/*.lock
  • flake.lock is excluded by !**/*.lock

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 11ebda47-60e8-4f5d-bea3-898294473927

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch renovate/lock-file-maintenance

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@mesa-dot-dev
Copy link
Copy Markdown

mesa-dot-dev Bot commented May 8, 2026

Mesa Description

TL;DR

Refreshed all lock files to use the latest dependency versions.

What changed?

All lock files were refreshed. Specific file changes are not available.

Description generated by Mesa. Update settings

Copy link
Copy Markdown
Contributor

@cubic-dev-ai cubic-dev-ai Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates dependency lockfiles, specifically bun.lock and flake.lock, including updates to OpenTelemetry, Noble curves, and Nix flake inputs. Feedback highlights several concerns: the removal of @aws-sdk/client-bedrock-runtime from certain dependency paths may break AWS Bedrock integration, the tar package was unexpectedly downgraded, and a version mismatch for @opentelemetry/api was introduced, which could lead to telemetry data conflicts.

Comment thread bun.lock

"@mariozechner/pi-ai/@anthropic-ai/sdk": ["@anthropic-ai/sdk@0.91.1", "", { "dependencies": { "json-schema-to-ts": "^3.1.1" }, "peerDependencies": { "zod": "^3.25.0 || ^4.0.0" }, "optionalPeers": ["zod"], "bin": { "anthropic-ai-sdk": "bin/cli" } }, "sha512-LAmu761tSN9r66ixvmciswUj/ZC+1Q4iAfpedTfSVLeswRwnY3n2Nb6Tsk+cLPP28aLOPWeMgIuTuCcMC6W/iw=="],

"@mariozechner/pi-ai/@aws-sdk/client-bedrock-runtime": ["@aws-sdk/client-bedrock-runtime@3.1045.0", "", { "dependencies": { "@aws-crypto/sha256-browser": "5.2.0", "@aws-crypto/sha256-js": "5.2.0", "@aws-sdk/core": "^3.974.8", "@aws-sdk/credential-provider-node": "^3.972.39", "@aws-sdk/eventstream-handler-node": "^3.972.14", "@aws-sdk/middleware-eventstream": "^3.972.10", "@aws-sdk/middleware-host-header": "^3.972.10", "@aws-sdk/middleware-logger": "^3.972.10", "@aws-sdk/middleware-recursion-detection": "^3.972.11", "@aws-sdk/middleware-user-agent": "^3.972.38", "@aws-sdk/middleware-websocket": "^3.972.16", "@aws-sdk/region-config-resolver": "^3.972.13", "@aws-sdk/token-providers": "3.1045.0", "@aws-sdk/types": "^3.973.8", "@aws-sdk/util-endpoints": "^3.996.8", "@aws-sdk/util-user-agent-browser": "^3.972.10", "@aws-sdk/util-user-agent-node": "^3.973.24", "@smithy/config-resolver": "^4.4.17", "@smithy/core": "^3.23.17", "@smithy/eventstream-serde-browser": "^4.2.14", "@smithy/eventstream-serde-config-resolver": "^4.3.14", "@smithy/eventstream-serde-node": "^4.2.14", "@smithy/fetch-http-handler": "^5.3.17", "@smithy/hash-node": "^4.2.14", "@smithy/invalid-dependency": "^4.2.14", "@smithy/middleware-content-length": "^4.2.14", "@smithy/middleware-endpoint": "^4.4.32", "@smithy/middleware-retry": "^4.5.7", "@smithy/middleware-serde": "^4.2.20", "@smithy/middleware-stack": "^4.2.14", "@smithy/node-config-provider": "^4.3.14", "@smithy/node-http-handler": "^4.6.1", "@smithy/protocol-http": "^5.3.14", "@smithy/smithy-client": "^4.12.13", "@smithy/types": "^4.14.1", "@smithy/url-parser": "^4.2.14", "@smithy/util-base64": "^4.3.2", "@smithy/util-body-length-browser": "^4.2.2", "@smithy/util-body-length-node": "^4.2.3", "@smithy/util-defaults-mode-browser": "^4.3.49", "@smithy/util-defaults-mode-node": "^4.2.54", "@smithy/util-endpoints": "^3.4.2", "@smithy/util-middleware": "^4.2.14", "@smithy/util-retry": "^4.3.6", "@smithy/util-stream": "^4.5.25", "@smithy/util-utf8": "^4.2.2", "tslib": "^2.6.2" } }, "sha512-aPC6gAz9uKRiwfnKB7peTs6yD0FpSzmVnSkx0f2QtJfosFM6J6KtBvR1lMKby050K4C4PAyEScwA5YTsGfTcGA=="],
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The removal of @aws-sdk/client-bedrock-runtime from the dependency tree of @mariozechner/pi-ai and others is a significant change that will break any code relying on AWS Bedrock. This appears to be an unintended side effect of the lockfile refresh, as the parent package versions have not changed.

Comment thread bun.lock
"tapable": ["tapable@2.3.3", "", {}, "sha512-uxc/zpqFg6x7C8vOE7lh6Lbda8eEL9zmVm/PLeTPBRhh1xCgdWaQ+J1CUieGpIfm2HdtsUpRv+HshiasBMcc6A=="],

"tar": ["tar@7.5.15", "", { "dependencies": { "@isaacs/fs-minipass": "^4.0.0", "chownr": "^3.0.0", "minipass": "^7.1.2", "minizlib": "^3.1.0", "yallist": "^5.0.0" } }, "sha512-dzGK0boVlC4W5QFuQN1EFSl3bIDYsk7Tj40U6eIBnK2k/8ml7TZ5agbI5j5+qnoVcAA+rNtBml8SEiLxZpNqRQ=="],
"tar": ["tar@7.5.13", "", { "dependencies": { "@isaacs/fs-minipass": "^4.0.0", "chownr": "^3.0.0", "minipass": "^7.1.2", "minizlib": "^3.1.0", "yallist": "^5.0.0" } }, "sha512-tOG/7GyXpFevhXVh8jOPJrmtRpOTsYqUIkVdVooZYJS/z8WhfQUX8RJILmeuJNinGAMSu1veBr4asSHFt5/hng=="],
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The tar package has been downgraded from 7.5.15 to 7.5.13. This is a regression in dependency freshness. While it may have been done for deduplication, aligning on the newer version is preferred to ensure the latest fixes are included.

Comment thread bun.lock

"ai/@ai-sdk/provider-utils": ["@ai-sdk/provider-utils@4.0.19", "", { "dependencies": { "@ai-sdk/provider": "3.0.8", "@standard-schema/spec": "^1.1.0", "eventsource-parser": "^3.0.6" }, "peerDependencies": { "zod": "^3.25.76 || ^4.1.8" } }, "sha512-3eG55CrSWCu2SXlqq2QCsFjo3+E7+Gmg7i/oRVoSZzIodTuDSfLb3MRje67xE9RFea73Zao7Lm4mADIfUETKGg=="],

"ai/@opentelemetry/api": ["@opentelemetry/api@1.9.0", "", {}, "sha512-3giAOQvZiH5F9bMlMiv8+GSPMeqg0dbaeo58/0SlA9sxSqZhnUtxzX9/2FzyhS9sWQf5S0GJE0AKBrFqjpeYcg=="],
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

This entry introduces @opentelemetry/api@1.9.0 for the ai package, creating a version mismatch with the root @opentelemetry/api@1.9.1. Multiple versions of the OpenTelemetry API can conflict over global state registration, which often leads to telemetry data loss. Deduplicating this to a single version is recommended.

Comment thread bun.lock
"tapable": ["tapable@2.3.3", "", {}, "sha512-uxc/zpqFg6x7C8vOE7lh6Lbda8eEL9zmVm/PLeTPBRhh1xCgdWaQ+J1CUieGpIfm2HdtsUpRv+HshiasBMcc6A=="],

"tar": ["tar@7.5.15", "", { "dependencies": { "@isaacs/fs-minipass": "^4.0.0", "chownr": "^3.0.0", "minipass": "^7.1.2", "minizlib": "^3.1.0", "yallist": "^5.0.0" } }, "sha512-dzGK0boVlC4W5QFuQN1EFSl3bIDYsk7Tj40U6eIBnK2k/8ml7TZ5agbI5j5+qnoVcAA+rNtBml8SEiLxZpNqRQ=="],
"tar": ["tar@7.5.13", "", { "dependencies": { "@isaacs/fs-minipass": "^4.0.0", "chownr": "^3.0.0", "minipass": "^7.1.2", "minizlib": "^3.1.0", "yallist": "^5.0.0" } }, "sha512-tOG/7GyXpFevhXVh8jOPJrmtRpOTsYqUIkVdVooZYJS/z8WhfQUX8RJILmeuJNinGAMSu1veBr4asSHFt5/hng=="],
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Root tar resolved version downgraded 7.5.15 → 7.5.13. The pre-PR lockfile had two tar entries: root tar@7.5.15 and openclaw/tar@7.5.13 (openclaw pins tar: "7.5.13" exactly — see line 2849). This PR's deduplication dropped the nested entry and converged the root onto 7.5.13, so any non-openclaw consumer that hoists the root tar silently moved two patch versions back. Low impact since openclaw is the dominant consumer here, but if you want to keep the root on the newer release, the proper fix is to bump openclaw's pinned tar version upstream so Bun dedups to the higher version instead.

@shunkakinoki shunkakinoki merged commit 3c407cb into main May 8, 2026
41 of 42 checks passed
@shunkakinoki shunkakinoki deleted the renovate/lock-file-maintenance branch May 8, 2026 05:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants