Dependency maintenance on top of v0.9.8. No functional changes — no runtime
code was touched, and every bump is verified against the full suite.
Security
- Bump transitive
brace-expansion(2.1.2 -> 2.1.4, 5.0.8 -> 5.0.9) andhono(4.13.2 -> 4.13.7) (3017be1) — two advisoriesnpm auditflagged that Dependabot had not alerted on. Neither is reachable in production:brace-expansioncomes in throughvite-plugin-pwaas build-time tooling, and every Praktor MCP server usesStdioServerTransport, so Hono's affected HTTP paths never run. Both projects now report 0 vulnerabilities.
Dependencies
- Bump
moby/moby/api1.55.0 -> 1.56.0,moby/moby/client0.5.1 -> 0.6.0, andgolang.org/x/crypto0.55.0 -> 0.57.0 (c258989) - Bump
vitest4.1.11 -> 5.0.0 in ui and agent-runner (3cb730f) - Refresh in-range npm dependencies:
@testing-library/react,@types/react-dom,@types/node(9334708)
This clears the dependency backlog completely — go list -u reports no direct
updates and npm outdated is empty in both projects.