build(deps-dev): Bump @anthropic-ai/sdk from 0.112.4 to 0.115.0 - #605
Conversation
Bumps [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) from 0.112.4 to 0.115.0. - [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases) - [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md) - [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.112.4...sdk-v0.115.0) --- updated-dependencies: - dependency-name: "@anthropic-ai/sdk" dependency-version: 0.115.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
hermes-exosphere
left a comment
There was a problem hiding this comment.
✅ Auto-approved: all 10 CI checks passing. Ready to merge.
|
Automated code review started - full review. Results will be posted here. |
|
⏳ Automated code review in progress — running full test suite... |
🔍 Automated Code Review📋 Executive SummaryDependabot bump of 📊 Change Architecturegraph TD
A["package.json<br/>@anthropic-ai/sdk: ^0.112.4 → ^0.115.0"] -->|"bun lockfile update"| B["bun.lock<br/>hash-only diff"]
A -->|"no code changes required"| C["scripts/translate-docs/translator.ts<br/>consumer: messages.stream() API"]
A -->|"no code changes required"| D["tests mock factory unchanged"]
style A fill:#87CEEB
style C fill:#90EE90
style D fill:#90EE90
Legend: 🟢 New | 🔵 Modified | 🟡 Breaking Change Risk 🔴 Breaking Changes✅ No breaking changes detected. The SDK diff (0.112.4 → 0.115.0) adds:
None of these affect the existing
|
| Check | Status |
|---|---|
| build | ✅ SUCCESS |
| test (default) | ✅ SUCCESS |
| test (log-debug, debug) | ✅ SUCCESS |
| test (hook-log-file, 1) | ✅ SUCCESS |
| test-e2e | ✅ SUCCESS |
| quality (lint) | ✅ SUCCESS |
| docs | ✅ SUCCESS |
| OSV-Scanner | ✅ SUCCESS |
| Socket Security | ✅ SUCCESS |
PR is MERGEABLE.
🔗 Issue Linkage
👥 Human Review Feedback
- socket-security[bot]: Reviewed dependency changes, no blocking alerts raised
- hermes-exosphere: Prior review-started notice posted
No human review comments on this PR.
💡 Suggestions
None. This is a textbook clean Dependabot bump.
🏆 Verdict
VERDICT: APPROVED
Automated code review · 2026-07-28 03:11:00 UTC
hermes-exosphere
left a comment
There was a problem hiding this comment.
Automated review: Approved. ✅
- What: Dependabot bump of @anthropic-ai/sdk 0.112.4 → 0.115.0
- Why: 4 upstream releases — features (claude-opus-5 model, tool_change events, model_context_window_exceeded stop reason), chores, and an abort-listener memory leak fix
- Risk: None — API surface used (messages.stream API) is backward compatible; only package.json and bun.lock changed; all 9 CI checks pass; PR is mergeable
- Verdict: APPROVED
hermes-exosphere
left a comment
There was a problem hiding this comment.
Automated review: Approved. ✅
Bumps @anthropic-ai/sdk from 0.112.4 to 0.115.0.
Release notes
Sourced from @anthropic-ai/sdk's releases.
Changelog
Sourced from @anthropic-ai/sdk's changelog.
Commits
3b45cd3chore: release mainf298e9afeat(api): add claude-opus-5 modelce8e54bfix(client): release abort listeners when requests settle (#1129)2d314b4chore: release main3d051dffeat(api): add new stop reason 'model_context_window_exceeded'4414d47chore: release main1ec5566feat(api): add support for Managed Agents model effort, initial session event...c58a55bchore: release main2fb7da5chore(api): add support for new refusal categoryd6ffc3cchore(internal): codegen related updateDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)