Skip to content

chore(deps): bump @connectrpc/connect-node from 2.1.2 to 2.2.0 - #124

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/connectrpc/connect-node-2.2.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/connectrpc/connect-node-2.2.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @connectrpc/connect-node from 2.1.2 to 2.2.0.

Release notes

Sourced from @​connectrpc/connect-node's releases.

v2.2.0

What's Changed

[!IMPORTANT]

This release adds a security-related feature for servers: the request gate is a function that runs after the request headers are available. Throwing a ConnectError in the gate rejects a request before messages are read, decompressed, or parsed. Use this option to reject unauthenticated requests instead of interceptors. See the documentation for details.

We also recommend that you configure a message size limit for your server, see the readMaxBytes option.

New Contributors

Full Changelog: connectrpc/connect-es@v2.1.2...v2.2.0

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​connectrpc/connect-node since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 16, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/connectrpc/connect-node-2.2.0 branch from 421592a to 19df4b6 Compare September 29, 2026 15:41
Bumps [@connectrpc/connect-node](https://github.com/connectrpc/connect-es/tree/HEAD/packages/connect-node) from 2.1.2 to 2.2.0.
- [Release notes](https://github.com/connectrpc/connect-es/releases)
- [Commits](https://github.com/connectrpc/connect-es/commits/v2.2.0/packages/connect-node)

---
updated-dependencies:
- dependency-name: "@connectrpc/connect-node"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@justin-carper

Copy link
Copy Markdown
Collaborator

Superseded by #132, which includes this bump (at newer versions where available), clears npm audit, and passed the full CI matrix. Closing so Dependabot does not keep rebasing it.

@dependabot @github

dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/connectrpc/connect-node-2.2.0 branch September 29, 2026 17:35
justin-carper added a commit that referenced this pull request Sep 30, 2026
… param docs (#132)

* chore: consolidate dependency updates, clear npm audit, fix per-model param docs

Dependencies (supersedes #122, #124, #125):
- @connectrpc/connect-node 2.1.2 -> 2.2.0
- @cursor/sdk 1.0.31 -> 1.0.32
- @opencode-ai/plugin + sdk -> 1.18.33 (one sdk copy)
- @ai-sdk/provider 3.0.15 -> 3.0.18, @types/node -> 26.6.3, vitest -> 5.0.2
- overrides: undici ^6.28.1 (GHSA-3wwx-pv8p-q78v), new toml ^4.2.0
  (GHSA-82x6-q7mm-w9cf); npm audit reports 0 vulnerabilities
- @ai-sdk/provider v4 and TypeScript 7 stay blocked per dependabot.yml

Docs (#119): Cursor model param ids are per model, so `thinking` on a
model without that param (e.g. grok-4.6, which takes `effort`) is ignored.
Correct the README examples and the delegate/cloud-agent `thinking`
tool-arg descriptions. Comment-only changes in src/provider; no logic change.

* fix: point v2 install at @next, list model params in refresh tool, fix fallback param

- README (#126): the opencode v2 install snippet used @latest, which is
  0.9.0 (v1-only build, no { id, setup } default export) and reproduces
  "Plugin must export a default definition" on opencode 2.x. Point it at
  @next until 0.10.0 is promoted, with a note.
- cursor_refresh_models (#119): append each model's param ids and accepted
  values, e.g. `grok-4.6 [effort=low|medium|high|xhigh, fast=false|true]`,
  so users can tell effort from reasoning_effort. Add a test.
- fallback catalog: composer-2.5 exposes `fast`, not `thinking`; the stale
  entry produced a bogus `thinking` variant on the keyless path.
- CHANGELOG: limit the connect-node note to verified facts (nothing in the
  repo imports it; @cursor/sdk nests its own 1.7.0) and record the above.

* docs: give opencode v2 users the right plugin cache path

The troubleshooting entry and the manual-install snippet only described the
opencode v1 cache layout (~/.cache/opencode/packages/...). opencode v2 caches
plugin installs under ~/.cache/opencode/npm/<spec>/, so anyone following the
README on v2 cleared the wrong directory (#126). Cover both layouts, point v2
users at `opencode plugin update`, and note that an @latest install of 0.9.x
has no v2 entrypoint.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant