Skip to content

chore(deps): bump the third-party group across 3 directories with 2 updates - #1042

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/plugins/codex-security/mcp-app/third-party-2a61720c8a
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/plugins/codex-security/mcp-app/third-party-2a61720c8a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the third-party group with 1 update in the /plugins/codex-security/mcp-app directory: @types/node.
Bumps the third-party group with 1 update in the /plugins/codex-security/skills/triage-finding/evals directory: promptfoo.
Bumps the third-party group with 1 update in the /sdk/typescript directory: @types/node.

Updates @types/node from 26.6.1 to 26.6.2

Commits

Updates @types/node from 26.6.1 to 26.6.2

Commits

Updates promptfoo from 0.123.0 to 0.123.1

Release notes

Sourced from promptfoo's releases.

0.123.1

0.123.1 (2026-09-18)

Features

  • bedrock: refresh auth across HTTP adapters (#10123) (9d3f063)
  • providers: add Gemini 3.8 and Vertex Live (#10956) (1417f22)
  • providers: add GPT-Live voice sessions (#10891) (316a334)
  • providers: add OpenAI Agents API (#10892) (ad3bee3)
  • providers: add portable HTTP config schemas (#10968) (fcd0604)
  • providers: add portable MCP config schemas (#10965) (f5ccb3c)
  • providers: support Ollama 0.34 features and refresh model docs (#10964) (ac01a4f)
  • providers: surface Ollama thinking output and finish reason (#10954) (27d4c22)
  • providers: update Gemini tools and media support (#10172) (627bdd0)

Bug Fixes

  • assertions: bound embedded tool call parsing (#10877) (78202a3)
  • assertions: bound tool-call parser state (#10887) (15290b4)
  • assertions: default RAG assertion thresholds to 0.5 (#10202) (4831b60), closes #9910 #9848
  • assertions: invert score along with pass for search-rubric (#10103) (26e8f2f)
  • assertions: never invert grader failures on not-classifier and not-search-rubric (#10904) (e049702)
  • assertions: reject malformed webhook results (#10955) (fc57736)
  • assertions: reject non-string search rubrics (#10934) (7bbb79e)
  • auth: harden custom header requests (#10524) (5325084)
  • cli: handle large values during result export (#10884) (be798f4)
  • cli: preserve in-memory results for extensions (#10885) (60483d9)
  • code-scan: extractValidLineRanges off-by-one on trailing newline (#10107) (2cbabdb)
  • config: preserve discovery in paths containing quotes (#10549) (d9b3927)
  • db: preserve shared blobs after persistence errors (#10897) (3b353fb)
  • deps: update dependency @​anthropic-ai/sdk to v0.123.0 (#10901) (14f7c06)
  • deps: update dependency @​anthropic-ai/sdk to v0.124.0 (#10940) (29a15d1)
  • deps: update engine.io to v6.6.10 (#10915) (e54a968)
  • deps: update opentelemetry (#10886) (280bc5e)
  • deps: update type definitions (#10924) (01c6397)
  • drain database writes and preserve provider options (#10911) (32bfa9e)
  • eval: keep concurrent derived metrics consistent (#10873) (2a3a3bd)
  • eval: preserve audio grading results and order (#10822) (395d21e)
  • eval: preserve cloud UUID config semantics (#7732) (8544fed)
  • fetch: decode URL credentials and match Authorization case-insensitively (#10909) (b8aa6ff)
  • fetch: treat credit_balance_exhausted as a hard quota error (#10881) (7f21bb2)
  • honor SDK options and load AVIF/TIFF images (#10902) (15bba21)
  • integrations: honor --env-file and config env for Helicone key and Langfuse base URL (#10942) (8bd9f37)
  • integrations: read Langfuse env at fetch time (#10937) (033080c)
  • integrations: share Langfuse prompt fetches and surface real SDK load errors (#10943) (379ecd0)
  • matchers: tag context-faithfulness grader failures (#9907) (77bc3ba)
  • matchers: tag RAG grader failures so inverse assertions cannot pass (#10494) (b3d21d2)
  • mcp: accept fine-tuned model identifiers (#10847) (9442129)

... (truncated)

Changelog

Sourced from promptfoo's changelog.

0.123.1 (2026-09-18)

Features

  • bedrock: refresh auth across HTTP adapters (#10123) (9d3f063)
  • providers: add Gemini 3.8 and Vertex Live (#10956) (1417f22)
  • providers: add GPT-Live voice sessions (#10891) (316a334)
  • providers: add OpenAI Agents API (#10892) (ad3bee3)
  • providers: add portable HTTP config schemas (#10968) (fcd0604)
  • providers: add portable MCP config schemas (#10965) (f5ccb3c)
  • providers: support Ollama 0.34 features and refresh model docs (#10964) (ac01a4f)
  • providers: surface Ollama thinking output and finish reason (#10954) (27d4c22)
  • providers: update Gemini tools and media support (#10172) (627bdd0)

Bug Fixes

  • assertions: bound embedded tool call parsing (#10877) (78202a3)
  • assertions: bound tool-call parser state (#10887) (15290b4)
  • assertions: default RAG assertion thresholds to 0.5 (#10202) (4831b60), closes #9910 #9848
  • assertions: invert score along with pass for search-rubric (#10103) (26e8f2f)
  • assertions: never invert grader failures on not-classifier and not-search-rubric (#10904) (e049702)
  • assertions: reject malformed webhook results (#10955) (fc57736)
  • assertions: reject non-string search rubrics (#10934) (7bbb79e)
  • auth: harden custom header requests (#10524) (5325084)
  • cli: handle large values during result export (#10884) (be798f4)
  • cli: preserve in-memory results for extensions (#10885) (60483d9)
  • code-scan: extractValidLineRanges off-by-one on trailing newline (#10107) (2cbabdb)
  • config: preserve discovery in paths containing quotes (#10549) (d9b3927)
  • db: preserve shared blobs after persistence errors (#10897) (3b353fb)
  • deps: update dependency @​anthropic-ai/sdk to v0.123.0 (#10901) (14f7c06)
  • deps: update dependency @​anthropic-ai/sdk to v0.124.0 (#10940) (29a15d1)
  • deps: update engine.io to v6.6.10 (#10915) (e54a968)
  • deps: update opentelemetry (#10886) (280bc5e)
  • deps: update type definitions (#10924) (01c6397)
  • drain database writes and preserve provider options (#10911) (32bfa9e)
  • eval: keep concurrent derived metrics consistent (#10873) (2a3a3bd)
  • eval: preserve audio grading results and order (#10822) (395d21e)
  • eval: preserve cloud UUID config semantics (#7732) (8544fed)
  • fetch: decode URL credentials and match Authorization case-insensitively (#10909) (b8aa6ff)
  • fetch: treat credit_balance_exhausted as a hard quota error (#10881) (7f21bb2)
  • honor SDK options and load AVIF/TIFF images (#10902) (15bba21)
  • integrations: honor --env-file and config env for Helicone key and Langfuse base URL (#10942) (8bd9f37)
  • integrations: read Langfuse env at fetch time (#10937) (033080c)
  • integrations: share Langfuse prompt fetches and surface real SDK load errors (#10943) (379ecd0)
  • matchers: tag context-faithfulness grader failures (#9907) (77bc3ba)
  • matchers: tag RAG grader failures so inverse assertions cannot pass (#10494) (b3d21d2)
  • mcp: accept fine-tuned model identifiers (#10847) (9442129)
  • opencode: capture skill calls from full session history (#10011) (290973d)
  • prompts: CSV rows collapse to duplicate labels/IDs when basePrompt.label is set (#10102) (25963c3)
  • providers: align ElevenLabs requests and audio inputs (#10736) (de12341)

... (truncated)

Commits
  • 34f74d3 chore(main): release 0.123.1 (#10879)
  • 9d3f063 feat(bedrock): refresh auth across HTTP adapters (#10123)
  • 5325084 fix(auth): harden custom header requests (#10524)
  • f385d96 fix(providers): isolate Agents endpoint credentials (#10951)
  • ba0eeb4 fix(providers): preserve patterned OpenCode skill history (#10971)
  • 288e26c chore(deps): update dependency oxc-parser to ^0.149.0 (#10975)
  • fc57736 fix(assertions): reject malformed webhook results (#10955)
  • 52ce503 chore(deps): bump the npm_and_yarn group across 1 directory with 2 updates (#...
  • 1417f22 feat(providers): add Gemini 3.8 and Vertex Live (#10956)
  • 08e91da fix(redteam): preserve strategy grading context (#10969)
  • Additional commits viewable in compare view

Updates @types/node from 26.6.1 to 26.6.2

Commits

Updates @types/node from 26.6.1 to 26.6.2

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 26, 2026
…pdates

Bumps the third-party group with 1 update in the /plugins/codex-security/mcp-app directory: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node).
Bumps the third-party group with 1 update in the /plugins/codex-security/skills/triage-finding/evals directory: [promptfoo](https://github.com/promptfoo/promptfoo).
Bumps the third-party group with 1 update in the /sdk/typescript directory: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node).


Updates `@types/node` from 26.6.1 to 26.6.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@types/node` from 26.6.1 to 26.6.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `promptfoo` from 0.123.0 to 0.123.1
- [Release notes](https://github.com/promptfoo/promptfoo/releases)
- [Changelog](https://github.com/promptfoo/promptfoo/blob/main/CHANGELOG.md)
- [Commits](promptfoo/promptfoo@0.123.0...0.123.1)

Updates `@types/node` from 26.6.1 to 26.6.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@types/node` from 26.6.1 to 26.6.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.6.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: third-party
- dependency-name: "@types/node"
  dependency-version: 26.6.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: third-party
- dependency-name: promptfoo
  dependency-version: 0.123.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: third-party
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/plugins/codex-security/mcp-app/third-party-2a61720c8a branch from 99e70fd to cf4657d Compare September 26, 2026 09:44

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants