Skip to content

build(deps): bump openai from 7.7.0 to 7.9.0 in the npm-production-minor-patch group - #331

Merged
cursor[bot] merged 1 commit into
masterfrom
dependabot/npm_and_yarn/npm-production-minor-patch-baabab3f91
Sep 10, 2026
Merged

build(deps): bump openai from 7.7.0 to 7.9.0 in the npm-production-minor-patch group#331
cursor[bot] merged 1 commit into
masterfrom
dependabot/npm_and_yarn/npm-production-minor-patch-baabab3f91

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-production-minor-patch group with 1 update: openai.

Updates openai from 7.7.0 to 7.9.0

Release notes

Sourced from openai's releases.

v7.9.0

7.9.0 (2026-09-02)

Features

  • api: update usage APIs and documentation (#2565) (4908505)

Bug Fixes

  • api: prevent Responses WebSockets from following redirects (#2513) (0a4fb1b)
  • load CommonJS under browser export conditions (#2507) (222f3d7)
  • restore monthly Node version review (#2553) (15dc890)
  • support Jest 28 CommonJS package imports (#2511) (eea2292)

Chores

  • deps-dev: bump browserslist to 4.28.7 across ecosystem tests (#2554) (a408e0b)
  • raise custom-code budget to 4,000 lines (#2562) (82c5b2d)

v7.8.0

7.8.0 (2026-08-27)

Features

  • api: add compute_units to Responses and Chat Completions usage (#2505) (f9b1313)
  • api: add default WebSocket User-Agent and audit log events (#2504) (9b2f089)

Bug Fixes

  • auth: clamp the workload-identity refresh buffer to the token lifetime (#2490) (76b73a9)
  • auth: secure first-class X.509 workload credentials (#2479) (1b36c19)
  • deps: harden dependency and release boundaries (#2484) (b21ff45)
  • events: settle WebSocket waiters when listeners throw (#2491) (b5a13a7)
  • restore native browser ESM imports (#2495) (c8cab1e)
  • uploads: detect multipart bodies from own properties only (#2492) (559ffc8)
Changelog

Sourced from openai's changelog.

7.9.0 (2026-09-02)

Features

  • api: update usage APIs and documentation (#2565) (4908505)

Bug Fixes

  • api: prevent Responses WebSockets from following redirects (#2513) (0a4fb1b)
  • load CommonJS under browser export conditions (#2507) (222f3d7)
  • restore monthly Node version review (#2553) (15dc890)
  • support Jest 28 CommonJS package imports (#2511) (eea2292)

Chores

  • deps-dev: bump browserslist to 4.28.7 across ecosystem tests (#2554) (a408e0b)
  • raise custom-code budget to 4,000 lines (#2562) (82c5b2d)

7.8.0 (2026-08-27)

Features

  • api: add compute_units to Responses and Chat Completions usage (#2505) (f9b1313)
  • api: add default WebSocket User-Agent and audit log events (#2504) (9b2f089)

Bug Fixes

  • auth: clamp the workload-identity refresh buffer to the token lifetime (#2490) (76b73a9)
  • auth: secure first-class X.509 workload credentials (#2479) (1b36c19)
  • deps: harden dependency and release boundaries (#2484) (b21ff45)
  • events: settle WebSocket waiters when listeners throw (#2491) (b5a13a7)
  • restore native browser ESM imports (#2495) (c8cab1e)
  • uploads: detect multipart bodies from own properties only (#2492) (559ffc8)
Commits
  • 3cf755e release: 7.9.0 (#2510)
  • 4908505 feat(api): update usage APIs and documentation (#2565)
  • 82c5b2d chore: raise custom-code budget to 4,000 lines (#2562)
  • a408e0b chore(deps-dev): bump browserslist to 4.28.7 across ecosystem tests (#2554)
  • 15dc890 fix: restore monthly Node version review (#2553)
  • eea2292 fix: support Jest 28 CommonJS package imports (#2511)
  • 0a4fb1b fix(api): prevent Responses WebSockets from following redirects (#2513)
  • 222f3d7 fix: load CommonJS under browser export conditions (#2507)
  • 31fae53 release: 7.8.0 (#2493)
  • f9b1313 feat(api): add compute_units to Responses and Chat Completions usage (#2505)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the npm-production-minor-patch group with 1 update: [openai](https://github.com/openai/openai-node).


Updates `openai` from 7.7.0 to 7.9.0
- [Release notes](https://github.com/openai/openai-node/releases)
- [Changelog](https://github.com/openai/openai-node/blob/main/CHANGELOG.md)
- [Commits](openai/openai-node@v7.7.0...v7.9.0)

---
updated-dependencies:
- dependency-name: openai
  dependency-version: 7.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-production-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 10, 2026
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 10, 2026

Copy link
Copy Markdown

Deploying podnotes with  Cloudflare Pages  Cloudflare Pages

Latest commit: 4d86a6a
Status: ✅  Deploy successful!
Preview URL: https://dfaa6058.podnotes.pages.dev
Branch Preview URL: https://dependabot-npm-and-yarn-npm-sabo.podnotes.pages.dev

View logs

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 10, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependabot production bump of openai from 7.7.0 to 7.9.0. Diff is package.json + package-lock.json only.

Plugin surface. PodNotes constructs new OpenAI({ apiKey, dangerouslyAllowBrowser: true }) and calls audio.transcriptions.create for whisper-1 and gpt-4o-transcribe-diarize (with AbortSignal). It does not use Responses, WebSockets, Chat Completions usage fields, or X.509 / workload-identity auth.

Changelog (7.8.0 + 7.9.0). Additive usage/docs fields, optional ws peer floor ^8.21.0, and fixes for browser ESM/CJS export conditions, multipart own-property detection, and unused auth/WebSocket paths. No breaking change on the transcription + browser-client surface this plugin uses. The browser-export fixes are more likely to help Obsidian's Electron import of the bundled SDK than to regress it.

Gates.

  • npm ci on Node 22.22.2 succeeded and did not rewrite the lockfile (openai@7.9.0).
  • lint, format:check, typecheck, build, svelte-check, and Vitest 1152/1152 passed.
  • GitHub Test and Cloudflare Pages are green.
  • npm audit --omit=dev is clean. Remaining highs (js-yaml, sharp via wrangler) are pre-existing dev-only and are not in this diff.

openai is already bundled into main.js; this title is build(deps): and will cut a plugin patch, which matches the last openai bump.

No regressions found. Approving and squash-merging.

Open in Web View Automation 

Sent by Cursor Automation: Dependabot PRs

@cursor
cursor Bot merged commit 875c9b8 into master Sep 10, 2026
4 checks passed
@cursor
cursor Bot deleted the dependabot/npm_and_yarn/npm-production-minor-patch-baabab3f91 branch September 10, 2026 12:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants