chore: consolidate dependency updates, clear npm audit, fix per-model param docs - #132
Merged
Merged
Conversation
… param docs Dependencies (supersedes #122, #124, #125): - @connectrpc/connect-node 2.1.2 -> 2.2.0 - @cursor/sdk 1.0.31 -> 1.0.32 - @opencode-ai/plugin + sdk -> 1.18.33 (one sdk copy) - @ai-sdk/provider 3.0.15 -> 3.0.18, @types/node -> 26.6.3, vitest -> 5.0.2 - overrides: undici ^6.28.1 (GHSA-3wwx-pv8p-q78v), new toml ^4.2.0 (GHSA-82x6-q7mm-w9cf); npm audit reports 0 vulnerabilities - @ai-sdk/provider v4 and TypeScript 7 stay blocked per dependabot.yml Docs (#119): Cursor model param ids are per model, so `thinking` on a model without that param (e.g. grok-4.6, which takes `effort`) is ignored. Correct the README examples and the delegate/cloud-agent `thinking` tool-arg descriptions. Comment-only changes in src/provider; no logic change.
This was referenced Sep 29, 2026
…x fallback param - README (#126): the opencode v2 install snippet used @latest, which is 0.9.0 (v1-only build, no { id, setup } default export) and reproduces "Plugin must export a default definition" on opencode 2.x. Point it at @next until 0.10.0 is promoted, with a note. - cursor_refresh_models (#119): append each model's param ids and accepted values, e.g. `grok-4.6 [effort=low|medium|high|xhigh, fast=false|true]`, so users can tell effort from reasoning_effort. Add a test. - fallback catalog: composer-2.5 exposes `fast`, not `thinking`; the stale entry produced a bogus `thinking` variant on the keyless path. - CHANGELOG: limit the connect-node note to verified facts (nothing in the repo imports it; @cursor/sdk nests its own 1.7.0) and record the above.
The troubleshooting entry and the manual-install snippet only described the opencode v1 cache layout (~/.cache/opencode/packages/...). opencode v2 caches plugin installs under ~/.cache/opencode/npm/<spec>/, so anyone following the README on v2 cleared the wrong directory (#126). Cover both layouts, point v2 users at `opencode plugin update`, and note that an @latest install of 0.9.x has no v2 entrypoint.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Supersedes Dependabot PRs #122, #124 and #125 with one verified update, clears
npm audit, and fixes the misleading docs behind #119.Dependencies
@connectrpc/connect-node2.1.2 → 2.2.0 (runtime dep of@cursor/sdk; not imported by the plugin)@cursor/sdk1.0.31 → 1.0.32@opencode-ai/plugin+@opencode-ai/sdk→ 1.18.33 (newer than the 1.18.30/31 in chore(deps): bump @opencode-ai/plugin from 1.18.25 to 1.18.30 in the opencode-ai group #122/chore(deps-dev): bump the dev-dependencies group across 1 directory with 4 updates #125; one sdk copy in the tree)@ai-sdk/provider3.0.15 → 3.0.18,@types/node→ 26.6.3,vitest→ 5.0.2npm audit: 2 findings → 0undicioverride^6.28.1(resolves 6.29.0, GHSA-3wwx-pv8p-q78v)tomloverride^4.2.0(resolves 4.3.0, GHSA-82x6-q7mm-w9cf; viaeffectunder@opencode-ai/plugin, whose declared range^4.1.1covers it).github/dependabot.yml:@ai-sdk/providerv4, TypeScript 7.Docs (#119)
Cursor model param ids are per model.
grok-4.6exposeseffort, notthinking, so a configuredthinkingparam is sent and ignored, and Cursor uses its default (high). That last step is inferred from the report, not proven from code.paramsexample, added a per-model param note, reworded thecursor_delegate/cursor_cloud_agentthinkingrows.src/plugin/cursor-tools.ts: the twothinkingdescribe()strings the model sees.src/provider/{controls,delegate,cloud-agent,index}.ts.Verification
npm cifrom scratch,npm run typecheck,npm run build: passnpm test: 42 files / 642 tests pass (same as baseline on main)npm audit: 0 vulnerabilitiesbash scripts/integration-test.shagainst a real opencode 1.18.33: plugin loads, lists Cursor models,limit.inputsentinel intact, delegation tools registerresolvedURL is registry.npmjs.orgCloses nothing automatically; #119 and #126 need replies (see notes).