Skip to content

chore(deps): update dependency @ai-sdk/openai to v2.0.102#1068

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/ai-sdk-openai-2.x
Open

chore(deps): update dependency @ai-sdk/openai to v2.0.102#1068
renovate[bot] wants to merge 1 commit intomainfrom
renovate/ai-sdk-openai-2.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Feb 13, 2026

This PR contains the following updates:

Package Type Update Change OpenSSF
@ai-sdk/openai (source) dependencies patch 2.0.892.0.102 OpenSSF Scorecard

Release Notes

vercel/ai (@​ai-sdk/openai)

v2.0.102

Compare Source

Patch Changes

v2.0.101

Compare Source

Patch Changes
  • 316517c: Add gpt-5.4-mini, gpt-5.4-mini-2026-03-17, gpt-5.4-nano, and gpt-5.4-nano-2026-03-17 models.

v2.0.100

Compare Source

Patch Changes
  • 216151a: fix(provider/openai): drop reasoning parts without encrypted content when store: false

v2.0.99

Patch Changes
  • Updated dependencies [15cfac8]
    • ai@​5.0.99

v2.0.98

Patch Changes
  • 392dc94: feat(provider/openai): add GPT-5.4 model support

v2.0.97

Patch Changes

v2.0.96

Compare Source

Patch Changes
  • e867b5c: Support phase parameter on Responses API message items. The phase field ('commentary' or 'final_answer') is returned by models like gpt-5.3-codex on assistant message output items and must be preserved when sending follow-up requests. The phase value is available in providerMetadata.openai.phase on text parts and is automatically included on assistant messages sent back to the API.

v2.0.95

Compare Source

Patch Changes
  • b08351e: fix(openai): allow null/undefined type in streaming tool call deltas

    Azure AI Foundry and Mistral deployed on Azure omit the type field in
    streaming tool_calls deltas. The chat stream parser now accepts a missing
    type field (treating it as "function") instead of throwing
    InvalidResponseDataError: Expected 'function' type.

    Fixes #​12770

v2.0.94

Compare Source

Patch Changes
  • 42815ac: feat(provider/openai): add gpt-5.3-codex

v2.0.93

Compare Source

Patch Changes
  • fa64d70: fix(openai): change web search tool action to be optional

v2.0.92

Compare Source

Patch Changes
  • c680a01: fix(openai): add changeset and tests for per-image usage metadata

v2.0.91

Compare Source

Patch Changes
  • 6a0adb7: feat: differentiate text vs image input tokens

v2.0.90

Compare Source

Patch Changes

Configuration

📅 Schedule: Branch creation - At 12:00 AM through 04:59 AM and 10:00 PM through 11:59 PM, Monday through Friday ( * 0-4,22-23 * * 1-5 ), Only on Sunday and Saturday ( * * * * 0,6 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Dependency updates label Feb 13, 2026
@renovate renovate bot enabled auto-merge (squash) February 13, 2026 03:39
@renovate renovate bot added the dependencies Dependency updates label Feb 13, 2026
Copy link
Copy Markdown

@cubic-dev-ai cubic-dev-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

@renovate renovate bot force-pushed the renovate/ai-sdk-openai-2.x branch from 5a31b10 to 22649b7 Compare February 14, 2026 02:46
@renovate renovate bot changed the title chore(deps): update dependency @ai-sdk/openai to v2.0.90 chore(deps): update dependency @ai-sdk/openai to v2.0.91 Feb 14, 2026
@renovate renovate bot force-pushed the renovate/ai-sdk-openai-2.x branch from 22649b7 to c02402a Compare February 21, 2026 02:12
@renovate renovate bot changed the title chore(deps): update dependency @ai-sdk/openai to v2.0.91 chore(deps): update dependency @ai-sdk/openai to v2.0.92 Feb 21, 2026
@renovate renovate bot force-pushed the renovate/ai-sdk-openai-2.x branch from c02402a to 037627a Compare February 24, 2026 03:44
@renovate renovate bot changed the title chore(deps): update dependency @ai-sdk/openai to v2.0.92 chore(deps): update dependency @ai-sdk/openai to v2.0.93 Feb 24, 2026
@renovate renovate bot force-pushed the renovate/ai-sdk-openai-2.x branch from 037627a to 9305ef9 Compare February 24, 2026 23:53
@renovate renovate bot changed the title chore(deps): update dependency @ai-sdk/openai to v2.0.93 chore(deps): update dependency @ai-sdk/openai to v2.0.94 Feb 24, 2026
@renovate renovate bot force-pushed the renovate/ai-sdk-openai-2.x branch from 9305ef9 to 63f27c7 Compare February 26, 2026 22:56
@renovate renovate bot changed the title chore(deps): update dependency @ai-sdk/openai to v2.0.94 chore(deps): update dependency @ai-sdk/openai to v2.0.95 Feb 26, 2026
@renovate renovate bot force-pushed the renovate/ai-sdk-openai-2.x branch from 63f27c7 to a8580db Compare March 8, 2026 09:49
@renovate renovate bot changed the title chore(deps): update dependency @ai-sdk/openai to v2.0.95 chore(deps): update dependency @ai-sdk/openai to v2.0.98 Mar 8, 2026
@renovate renovate bot force-pushed the renovate/ai-sdk-openai-2.x branch from a8580db to 8b04948 Compare March 9, 2026 20:08
@renovate renovate bot changed the title chore(deps): update dependency @ai-sdk/openai to v2.0.98 chore(deps): update dependency @ai-sdk/openai to v2.0.99 Mar 9, 2026
@renovate renovate bot force-pushed the renovate/ai-sdk-openai-2.x branch from 8b04948 to 637fc6e Compare March 18, 2026 02:00
@renovate renovate bot changed the title chore(deps): update dependency @ai-sdk/openai to v2.0.99 chore(deps): update dependency @ai-sdk/openai to v2.0.100 Mar 18, 2026
@renovate renovate bot force-pushed the renovate/ai-sdk-openai-2.x branch from 637fc6e to 68c5f48 Compare March 23, 2026 19:29
@renovate renovate bot changed the title chore(deps): update dependency @ai-sdk/openai to v2.0.100 chore(deps): update dependency @ai-sdk/openai to v2.0.101 Mar 23, 2026
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate bot force-pushed the renovate/ai-sdk-openai-2.x branch from 68c5f48 to dd008ef Compare April 2, 2026 22:38
@renovate renovate bot changed the title chore(deps): update dependency @ai-sdk/openai to v2.0.101 chore(deps): update dependency @ai-sdk/openai to v2.0.102 Apr 2, 2026
@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​ai-sdk/​openai@​2.0.89 ⏵ 2.0.102100 +2910085 +198 +1100

View full report

@socket-security
Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
License policy violation: npm @img/sharp-libvips-darwin-arm64 under LGPL-3.0-or-later

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (npm metadata)

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (package/package.json)

From: ?npm/next@16.1.1npm/@img/sharp-libvips-darwin-arm64@1.2.4

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@img/sharp-libvips-darwin-arm64@1.2.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm @img/sharp-libvips-darwin-x64 under LGPL-3.0-or-later

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (npm metadata)

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (package/package.json)

From: ?npm/next@16.1.1npm/@img/sharp-libvips-darwin-x64@1.2.4

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@img/sharp-libvips-darwin-x64@1.2.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm @img/sharp-libvips-linux-arm under LGPL-3.0-or-later

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (npm metadata)

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (package/package.json)

From: ?npm/next@16.1.1npm/@img/sharp-libvips-linux-arm@1.2.4

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@img/sharp-libvips-linux-arm@1.2.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm @img/sharp-libvips-linux-arm64 under LGPL-3.0-or-later

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (npm metadata)

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (package/package.json)

From: ?npm/next@16.1.1npm/@img/sharp-libvips-linux-arm64@1.2.4

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@img/sharp-libvips-linux-arm64@1.2.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm @img/sharp-libvips-linux-ppc64 under LGPL-3.0-or-later

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (npm metadata)

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (package/package.json)

From: ?npm/next@16.1.1npm/@img/sharp-libvips-linux-ppc64@1.2.4

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@img/sharp-libvips-linux-ppc64@1.2.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm @img/sharp-libvips-linux-riscv64 under LGPL-3.0-or-later

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (npm metadata)

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (package/package.json)

From: ?npm/next@16.1.1npm/@img/sharp-libvips-linux-riscv64@1.2.4

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@img/sharp-libvips-linux-riscv64@1.2.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm @img/sharp-libvips-linux-s390x under LGPL-3.0-or-later

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (npm metadata)

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (package/package.json)

From: ?npm/next@16.1.1npm/@img/sharp-libvips-linux-s390x@1.2.4

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@img/sharp-libvips-linux-s390x@1.2.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm @img/sharp-libvips-linux-x64 under LGPL-3.0-or-later

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (npm metadata)

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (package/package.json)

From: ?npm/next@16.1.1npm/@img/sharp-libvips-linux-x64@1.2.4

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@img/sharp-libvips-linux-x64@1.2.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm @img/sharp-libvips-linuxmusl-arm64 under LGPL-3.0-or-later

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (npm metadata)

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (package/package.json)

From: ?npm/next@16.1.1npm/@img/sharp-libvips-linuxmusl-arm64@1.2.4

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@img/sharp-libvips-linuxmusl-arm64@1.2.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm @img/sharp-libvips-linuxmusl-x64 under LGPL-3.0-or-later

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (npm metadata)

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (package/package.json)

From: ?npm/next@16.1.1npm/@img/sharp-libvips-linuxmusl-x64@1.2.4

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@img/sharp-libvips-linuxmusl-x64@1.2.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm @img/sharp-win32-arm64 under LGPL-3.0-or-later

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (npm metadata)

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (package/package.json)

From: ?npm/next@16.1.1npm/@img/sharp-win32-arm64@0.34.5

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@img/sharp-win32-arm64@0.34.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm @img/sharp-win32-ia32 under LGPL-3.0-or-later

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (npm metadata)

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (package/package.json)

From: ?npm/next@16.1.1npm/@img/sharp-win32-ia32@0.34.5

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@img/sharp-win32-ia32@0.34.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm @img/sharp-win32-x64 under LGPL-3.0-or-later

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (npm metadata)

License: LGPL-3.0-or-later - the applicable license policy does not allow this license (4) (package/package.json)

From: ?npm/next@16.1.1npm/@img/sharp-win32-x64@0.34.5

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@img/sharp-win32-x64@0.34.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm vscode-jsonrpc under LGPL-2.1-or-later

License: LGPL-2.1-or-later - the applicable license policy does not allow this license (4) (package/thirdpartynotices.txt)

From: ?npm/vscode-jsonrpc@8.2.0

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/vscode-jsonrpc@8.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm vscode-languageserver-types under LGPL-2.1-or-later

License: LGPL-2.1-or-later - the applicable license policy does not allow this license (4) (package/thirdpartynotices.txt)

From: ?npm/vscode-languageserver-types@3.17.5

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/vscode-languageserver-types@3.17.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants