Repository navigation
chore(deps-dev): bump the dev-dependencies group across 1 directory with 12 updates - #390
dependabot[bot] wants to merge 1 commit into
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
…ith 12 updates Bumps the dev-dependencies group with 12 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@commitlint/cli](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/cli) | `21.1.0` | `21.2.1` | | [@commitlint/config-conventional](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/config-conventional) | `21.1.0` | `21.2.0` | | [@semantic-release/github](https://github.com/semantic-release/github) | `12.0.8` | `12.0.9` | | [prettier](https://github.com/prettier/prettier) | `3.9.4` | `3.9.6` | | [semantic-release](https://github.com/semantic-release/semantic-release) | `25.0.5` | `25.0.8` | | [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.62.0` | `8.65.0` | | [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.62.0` | `8.65.0` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.1.0` | `8.1.5` | | [@docusaurus/module-type-aliases](https://github.com/facebook/docusaurus/tree/HEAD/packages/docusaurus-module-type-aliases) | `3.10.1` | `3.10.2` | | [@docusaurus/types](https://github.com/facebook/docusaurus/tree/HEAD/packages/docusaurus-types) | `3.10.1` | `3.10.2` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.0.1` | `26.1.1` | | [wait-on](https://github.com/jeffbski/wait-on) | `9.0.10` | `9.1.0` | Updates `@commitlint/cli` from 21.1.0 to 21.2.1 - [Release notes](https://github.com/conventional-changelog/commitlint/releases) - [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/cli/CHANGELOG.md) - [Commits](https://github.com/conventional-changelog/commitlint/commits/v21.2.1/@commitlint/cli) Updates `@commitlint/config-conventional` from 21.1.0 to 21.2.0 - [Release notes](https://github.com/conventional-changelog/commitlint/releases) - [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/config-conventional/CHANGELOG.md) - [Commits](https://github.com/conventional-changelog/commitlint/commits/v21.2.0/@commitlint/config-conventional) Updates `@semantic-release/github` from 12.0.8 to 12.0.9 - [Release notes](https://github.com/semantic-release/github/releases) - [Commits](semantic-release/github@v12.0.8...v12.0.9) Updates `prettier` from 3.9.4 to 3.9.6 - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](prettier/prettier@3.9.4...3.9.6) Updates `semantic-release` from 25.0.5 to 25.0.8 - [Release notes](https://github.com/semantic-release/semantic-release/releases) - [Commits](semantic-release/semantic-release@v25.0.5...v25.0.8) Updates `@typescript-eslint/eslint-plugin` from 8.62.0 to 8.65.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/eslint-plugin) Updates `@typescript-eslint/parser` from 8.62.0 to 8.65.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/parser) Updates `vite` from 8.1.0 to 8.1.5 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.1.5/packages/vite) Updates `@docusaurus/module-type-aliases` from 3.10.1 to 3.10.2 - [Release notes](https://github.com/facebook/docusaurus/releases) - [Changelog](https://github.com/facebook/docusaurus/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/docusaurus/commits/v3.10.2/packages/docusaurus-module-type-aliases) Updates `@docusaurus/types` from 3.10.1 to 3.10.2 - [Release notes](https://github.com/facebook/docusaurus/releases) - [Changelog](https://github.com/facebook/docusaurus/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/docusaurus/commits/v3.10.2/packages/docusaurus-types) Updates `@types/node` from 26.0.1 to 26.1.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `wait-on` from 9.0.10 to 9.1.0 - [Release notes](https://github.com/jeffbski/wait-on/releases) - [Commits](jeffbski/wait-on@v9.0.10...v9.1.0) --- updated-dependencies: - dependency-name: "@commitlint/cli" dependency-version: 21.2.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: "@commitlint/config-conventional" dependency-version: 21.2.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: "@docusaurus/module-type-aliases" dependency-version: 3.10.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: "@docusaurus/types" dependency-version: 3.10.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: "@semantic-release/github" dependency-version: 12.0.9 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: "@types/node" dependency-version: 26.1.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: "@typescript-eslint/eslint-plugin" dependency-version: 8.65.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: "@typescript-eslint/parser" dependency-version: 8.65.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: prettier dependency-version: 3.9.6 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: semantic-release dependency-version: 25.0.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: vite dependency-version: 8.1.5 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: wait-on dependency-version: 9.1.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
5bf280a to
528936f
Compare
|
Closing as superseded by #393 (merged as Generated by Claude Code |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
…oth CLIs (#447) * chore(deps): consolidate dependabot updates, pin patched minimatch and yaml Consolidates #427, #428, #431, #432 and #440 into one PR so the shared pnpm-lock.yaml is regenerated once instead of forcing dependabot to rebase six branches serially. Same approach as #393 for #388/#390. docusaurus-plugin-llms 0.5.x pins its own dependencies exactly rather than by range, which dragged minimatch back to 9.0.3 (three high ReDoS advisories) and yaml to 2.8.1, failing both `pnpm audit --audit-level=high` and Dependency Review on #440. Two scoped overrides restore the patched versions; the rest of that group was already clean. @semantic-release/changelog 7 and @semantic-release/git 11 are the same CJS-to-ESM wave and are taken together. Every option the release configs actually pass (changelogFile, assets, message) is unchanged, and both declare a semantic-release peer of >=20.1.0, satisfied by ^25.0.8. @testing-library/jest-dom 7 removes no matchers; the new required peer @testing-library/dom is already resolved at 10.4.1 via @testing-library/react. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * feat(create-bestax): require Node 22 and take chalk 6 chalk 6 drops support for Node below 22. The API surface this package uses is unchanged — every call site is a default import using .red/.yellow/.green and friends — so no calling code changes. Raising engines.node to >=22 brings the manifest in line with what the docs have claimed all along: the installation guide already states "Node.js: 22.0.0 or higher (the current LTS baseline)". The version guard in src/index.ts moves ahead of every import and stops using chalk. Import declarations are hoisted and evaluated before any statement in the module, and chalk 6 itself requires Node >= 22 — so a static import would fail to load on exactly the runtimes the guard exists to catch, replacing a clear message with an opaque loader error. ./cli.js is now imported dynamically for the same reason. BREAKING CHANGE: create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * feat(bestax-migrate): require Node 22 and take chalk 6 chalk 6 drops support for Node below 22. The API surface this package uses is unchanged, so no calling code changes. The version guard in src/index.ts moves ahead of every import and no longer depends on anything: import declarations are hoisted and evaluated before any statement in the module, and chalk 6 itself requires Node >= 22, so a static import would fail to load on exactly the runtimes the guard exists to catch. ./cli.js is now imported dynamically for the same reason. @babel/parser deliberately stays on 7.x. Babel 8 removes the `deprecatedImportAssert` plugin with no replacement, and this package parses the legacy `import x from 'y' assert { type: 'json' }` form on purpose — a codemod that migrates older codebases must not crash on the syntax those codebases still contain. There is a regression test for it ("parses the legacy import-assert syntax"), which Babel 8 fails outright. jscodeshift 17 bundles its own Babel 7 regardless, so staying on 7 also keeps a single parser in the tree rather than two. BREAKING CHANGE: bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
Bumps the dev-dependencies group with 12 updates in the / directory:
21.1.021.2.121.1.021.2.012.0.812.0.93.9.43.9.625.0.525.0.88.62.08.65.08.62.08.65.08.1.08.1.53.10.13.10.23.10.13.10.226.0.126.1.19.0.109.1.0Updates
@commitlint/clifrom 21.1.0 to 21.2.1Release notes
Sourced from @commitlint/cli's releases.
Changelog
Sourced from @commitlint/cli's changelog.
Commits
6e20041v21.2.11b4e5bcv21.2.0fdb566ffeat(resolve-extends): resolve pure-ESM presets (conventional-changelog v7/v9...Updates
@commitlint/config-conventionalfrom 21.1.0 to 21.2.0Release notes
Sourced from @commitlint/config-conventional's releases.
Changelog
Sourced from @commitlint/config-conventional's changelog.
Commits
1b4e5bcv21.2.0fdb566ffeat(resolve-extends): resolve pure-ESM presets (conventional-changelog v7/v9...Updates
@semantic-release/githubfrom 12.0.8 to 12.0.9Release notes
Sourced from @semantic-release/github's releases.
Commits
28e3741fix(publish): handle content-length header properly for asset uploads (#1260)241f966fix(asset-upload): stop settingcontent-lengthheader manually40973e3fix(local-undici): always use the locally installed undici instead of the nod...8879ae4chore(deps): update dependency prettier to v3.9.1 (#1259)bf720e2chore(deps): update dependency prettier to v3.9.0 (#1258)b34e0ecchore(deps): update dependency prettier to v3.8.5 (#1257)b445fa0chore(deps): update dependency ls-engines to v0.10.1 (#1256)4ca0ef4chore(deps): lock file maintenance (#1255)bb9fdb3chore(deps): update dependency undici to v7.28.0 [security] (#1254)059c6ceci(action): update actions/checkout action to v7 (#1252)Updates
prettierfrom 3.9.4 to 3.9.6Release notes
Sourced from prettier's releases.
Changelog
Sourced from prettier's changelog.
... (truncated)
Commits
8f0c950Release 3.9.6e910764Update changelogec3f1c7Update typescript-eslint to v8.65.0 (#19675)73d2efcUpdate Yuku parser to v0.7.0 (#19664)dd5e24ePreserve quotes forTSMethodSignaturenodes namednew(#19621)c03ab4eUpdate dependency eslint-plugin-unicorn to v72 (#19633)b74dd53Update Yuku parser to v0.6.5 (#19654)f1b594eUpdate dependency eslint-plugin-simple-import-sort to v14 (#19655)0d9dfb6Update Yuku parser to v0.6.4 (#19650)3bbb815Removetypescript-onlydirectory (#19636)Updates
semantic-releasefrom 25.0.5 to 25.0.8Release notes
Sourced from semantic-release's releases.
Commits
1bfdc52fix: mask sensitive environment variables and improve commit handling (#4252)0a60004fix: handle potential null values in commit message and gitTags trimmingf121540fix: prevent template evaluation syntax in branch expansion and tag formatting973d763fix(hide-sensitive): mask key/auth/webhook env vars474e5a3ci(action): update github/codeql-action action to v4.37.1 (#4254)fc9382cdocs: fix issue template links (#4251)e34c52dci(action): update actions/setup-node action to v7 (#4250)8020ec6ci(action): update actions/setup-node action to v6.5.0 (#4249)956baf4chore(deps): update npm to v12.0.1 (#4247)c46dbdafix: argument Injection via repositoryUrl in package.json (#4245)Updates
@typescript-eslint/eslint-pluginfrom 8.62.0 to 8.65.0Release notes
Sourced from @typescript-eslint/eslint-plugin's releases.
... (truncated)
Changelog
Sourced from @typescript-eslint/eslint-plugin's changelog.
... (truncated)
Commits
63ba81bchore(release): publish 8.65.0aa602bdfix(eslint-plugin): [no-unnecessary-parameter-property-assignment] don't flag...1e90d67feat(eslint-plugin): [no-shadow] specialized error on enum declaration and me...b32fb34docs: fix broken code samples in no-extraneous-class and prefer-function-type...eaf4576feat: add warning when TS 7 is detected (#12529)18c01c7feat(eslint-plugin): [no-restricted-imports] deprecate extension rule (#12527)96e8fe2fix(eslint-plugin): [unbound-method] report unbound methods accessed via memb...0d06406chore: add attw validation to repo (#12437)9d9973bfix(eslint-plugin): [prefer-string-starts-ends-with] handle escaped $ ending ...c2386e4chore(deps): update dependency prettier to v3.9.5 (#12486)Updates
@typescript-eslint/parserfrom 8.62.0 to 8.65.0Release notes
Sourced from @typescript-eslint/parser's releases.
... (truncated)
Changelog
Sourced from @typescript-eslint/parser's changelog.
Commits
63ba81bchore(release): publish 8.65.0eaf4576feat: add warning when TS 7 is detected (#12529)d8f1044feat(parser): add onUnsupportedTypeScriptVersion option to error on unsupport...0d06406chore: add attw validation to repo (#12437)c2386e4chore(deps): update dependency prettier to v3.9.5 (#12486)414d9abchore(release): publish 8.64.0290cf6cchore(release): publish 8.63.03ea32f4chore(release): publish 8.62.1Updates
vitefrom 8.1.0 to 8.1.5Release notes
Sourced from vite's releases.
Changelog
Sourced from vite's changelog.
... (truncated)
Commits
5e7fe12release: v8.1.56c08c39fix(optimizer): respect importer module format for dynamic import interop wit...5a72b87fix(client): overlay error message format align rolldown (#22869)f8b38e3fix(module-runner): don't crash stack-trace source mapping when globalThis.Bu...8100320fix(bundled-dev): avoid duplicatedbuildEnd(#22931)c88c236docs(build): fix incorrect@defaultfor build.cssMinify (#22948)b59a73ffix(ssr): scope switch-case declarations to the switch, not the function (#22...fef682dfix(deps): update all non-major dependencies (#22921)3c345e4fix(deps): update rolldown-related dependencies (#22922)369ed60docs(build): fix incorrect@defaultfor build.lib.formats (#22911)Updates
@docusaurus/module-type-aliasesfrom 3.10.1 to 3.10.2Release notes
Sourced from @docusaurus/module-type-aliases's releases.
Changelog
Sourced from @docusaurus/module-type-aliases's changelog.
Commits
f37f903v3.10.2Updates
@docusaurus/typesfrom 3.10.1 to 3.10.2Release notes
Sourced from @docusaurus/types's releases.