Skip to content

chore(deps,middleware)(deps-dev): bump the dev-tooling group in /middleware with 3 updates - #487

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/middleware/dev-tooling-31a23caf07
Closed

chore(deps,middleware)(deps-dev): bump the dev-tooling group in /middleware with 3 updates#487
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/middleware/dev-tooling-31a23caf07

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 13, 2026

Copy link
Copy Markdown
Contributor

Bumps the dev-tooling group in /middleware with 3 updates: prettier, tsx and vitest.

Updates prettier from 3.9.4 to 3.9.5

Release notes

Sourced from prettier's releases.

3.9.5

🔗 Changelog

Changelog

Sourced from prettier's changelog.

3.9.5

diff

Markdown: Cap ordered list mark at 999,999,999 (#19351 by @​tats-u)

CommonMark parsers only support ordered list item numbers up to 999,999,999.

With this change, Prettier now caps the ordered list item number at 999,999,999 to ensure that the output is correctly parsed as an ordered list by CommonMark parsers. Numbers larger than 999,999,999 are not parsed as list item numbers and are left unchanged in the output:

<!-- Input -->
999999998. text
999999998. text
999999998. text
999999998. text
1234567890123456789012) text
<!-- Prettier 3.9.4 -->
999999998. text
999999999. text
1000000000. text
1000000001. text
1234567890123456789012) text
<!-- Prettier 3.9.5 -->
999999998. text
999999999. text
999999999. text
999999999. text
1234567890123456789012) text

Markdown: Avoid corrupting empty link with title (#19487 by @​andersk)

Do not remove <> from an inline link or image with an empty URL and a title, as this removal would change its interpretation.

<!-- Input -->
[link](https://github.com/prettier/prettier/blob/main/<> "title")
<!-- Prettier 3.9.4 -->
[link](https://github.com/prettier/prettier/blob/main/ "title")
<!-- Prettier 3.9.5 -->
</tr></table>

... (truncated)

Commits

Updates tsx from 4.23.0 to 4.23.1

Release notes

Sourced from tsx's releases.

v4.23.1

4.23.1 (2026-07-13)

Bug Fixes

  • support tsImport after global preload (8d4ffc2)
  • watch: avoid clearing piped output (95d0672)
  • watch: treat script and dependency paths literally (79fddde)

Performance Improvements

  • index transform cache lazily (e818ad6)
  • load esbuild lazily in CLI (d067938)
  • map Node TypeScript formats directly (cdcc623)
  • use sync module hooks on Node v22.22.3+ (f8992f1)

This release is also available on:

Commits
  • 79fddde fix(watch): treat script and dependency paths literally
  • e818ad6 perf: index transform cache lazily
  • cdcc623 perf: map Node TypeScript formats directly
  • d067938 perf: load esbuild lazily in CLI
  • 95d0672 fix(watch): avoid clearing piped output
  • 6fd4607 docs: add per-page metadata
  • f4176d8 docs: generate sitemap
  • 8d4ffc2 fix: support tsImport after global preload
  • f0e89b2 docs: document Node's public type-stripping API vs internal loader path
  • f8992f1 perf: use sync module hooks on Node v22.22.3+
  • See full diff in compare view

Updates vitest from 4.1.9 to 4.1.10

Release notes

Sourced from vitest's releases.

v4.1.10

   🐞 Bug Fixes

    View changes on GitHub
Commits
  • db616d2 chore: release v4.1.10 (#10718)
  • bae52b5 fix(vm): fix external module resolve error with deps optimizer query for enco...
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dev-tooling group in /middleware with 3 updates: [prettier](https://github.com/prettier/prettier), [tsx](https://github.com/privatenumber/tsx) and [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).


Updates `prettier` from 3.9.4 to 3.9.5
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.4...3.9.5)

Updates `tsx` from 4.23.0 to 4.23.1
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.0...v4.23.1)

Updates `vitest` from 4.1.9 to 4.1.10
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/vitest)

---
updated-dependencies:
- dependency-name: prettier
  dependency-version: 3.9.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-tooling
- dependency-name: tsx
  dependency-version: 4.23.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-tooling
- dependency-name: vitest
  dependency-version: 4.1.10
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-tooling
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 13, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: deps, middleware. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Weegy added a commit that referenced this pull request Jul 26, 2026
* chore(middleware): bump dependencies (dependabot batch 2026-07-26)

openai 6.42.0 -> 6.46.0 (#492)
@anthropic-ai/sdk 0.110.0 -> 0.111.0 (#491)
sharp 0.33.5 -> 0.35.3 (#490)
ws 8.18.0/8.21.0 -> 8.21.1, bonjour-service 1.4.2 -> 1.4.3 (#502)
prettier 3.9.4 -> 3.9.5, tsx 4.23.0 -> 4.23.1, vitest 4.1.8/4.1.9 -> 4.1.10 (#487)

* chore(web-ui): bump dependencies (dependabot batch 2026-07-26)

@tailwindcss/postcss 4.3.2 -> 4.3.3, @types/node 22.20.0 -> 22.20.1,
eslint 9.39.4 -> 9.39.5, vitest 4.1.9 -> 4.1.10 (#503)
@xyflow/react 12.11.1 -> 12.11.2, next-intl 4.13.1 -> 4.13.2 (#493)
@vitejs/plugin-react 5.2.0 -> 6.0.3 -- major bump, CI-validated build/typecheck/lint/vitest (#494)
cytoscape 3.33.4 -> 3.34.0 (#250, stale PR reapplied onto fresh main)

* chore(ci): bump actions/setup-node v4 -> v7, actions/setup-python v6 -> v7

actions/setup-node@v7 across ci.yml, auto-release.yml, desktop-apps.yml, release.yml (#500)
actions/setup-python@v7 in desktop-apps.yml (#501)

* chore(deps): ignore typescript major bumps (dependabot batch 2026-07-26)

PR #495 (typescript 5.9.3 -> 7.0.2, the Go-native tsgo rewrite) fails
web-ui build + typecheck + vitest CI outright. Excluded from this batch;
add an ignore rule for typescript semver-major so dependabot stops
reopening it weekly until the ecosystem catches up.

* fix(ci): upgrade npm before audit step to dodge retired quick-audit endpoint

Both 'audit (high+critical block)' checks on this PR (middleware, web-ui)
fail with a 400 'Invalid package tree' from npm's registry -- reproduces
identically against a pristine, unmodified main checkout (confirmed via
fresh npm ci + npm audit), and main's last green CI run was 2026-07-20.
Not caused by this batch's dependency bumps: npm's registry is retiring
the legacy 'quick audit' endpoint npm 10.x calls, and now hard-rejects it.
A current npm CLI uses the newer bulk-advisory endpoint instead.

* fix(ci): degrade audit gate gracefully on upstream npm registry outage

The npm@latest bump alone didn't fix it: every npm CLI I tested (10.9.8,
11.0.0, 11.16.0, 11.18.0, latest/12.0.1) fails against npm's registry
right now -- 10.x's retiring 'quick audit' endpoint 400s outright, and
11.x/12.x's newer bulk-advisory endpoint fails to gzip-decode its own
response. This is a registry-side outage, confirmed reproducible even
against a pristine main checkout, not something fixable by picking an
npm version.

npm's own error handler prints the literal string 'audit endpoint
returned an error' whenever the HTTP call itself fails, distinct from a
genuine vulnerabilities-found failure. Detect that string and treat it
as non-blocking (::warning:: + exit 0) so this gate degrades gracefully
during an outage instead of wedging every PR in the repo; real
high/critical findings still hard-fail as before.
@dependabot @github

dependabot Bot commented on behalf of github Jul 26, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 26, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/middleware/dev-tooling-31a23caf07 branch July 26, 2026 08:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants