Skip to content

chore(deps)(deps-dev): bump @types/node from 20.19.39 to 25.6.0 - #29

Merged
pathosDev merged 1 commit into
mainfrom
dependabot/npm_and_yarn/types/node-25.6.0
Apr 27, 2026
Merged

pathosDev merged 1 commit into
mainfrom
dependabot/npm_and_yarn/types/node-25.6.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 27, 2026

Copy link
Copy Markdown
Contributor

Bumps @types/node from 20.19.39 to 25.6.0.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 20.19.39 to 25.6.0.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 25.6.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Apr 27, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@pathosDev
pathosDev merged commit 54d71fc into main Apr 27, 2026
1 of 3 checks passed
@pathosDev
pathosDev deleted the dependabot/npm_and_yarn/types/node-25.6.0 branch April 27, 2026 14:37
pathosDev added a commit that referenced this pull request May 14, 2026
…ode-25.6.0

chore(deps)(deps-dev): bump @types/node from 20.19.39 to 25.6.0
pathosDev added a commit that referenced this pull request Sep 20, 2026
…t writes its lockfile

The repository tracks thirteen package.json manifests and `.github/dependabot.yml`
watched one of them — the root, through the `npm` ecosystem, which has no code
for `bun.lock` at all (`npm_and_yarn/` in dependabot-core does not mention it)
and therefore ran manifest-only.  A caret range already admits every minor and
patch, so an in-range release changed nothing that updater could see: the
`npm-minor-and-patch` group configured since `b5464448` opened no PR in five
months, and every root PR Dependabot did open (thirteen, #29 to #908, all
majors) edited `package.json` alone and went red on every frozen install until
`bun.lock` was regenerated by hand (#817).  The other twelve manifests got
security updates only — Dependabot opens those from the dependency graph
regardless of this file, which is what the `npm_and_yarn group across N
directories` PRs are — and were kept current by hand (#1520).  #779 is what the
blind spot cost: all nineteen high advisories in the runtime closure were fixed
inside the declared ranges, exactly the updates that never surfaced.

The ecosystem now follows the lockfile CI installs from:

- `package-ecosystem: "bun"` for the five Bun-installed manifests — `/`,
  `/docs`, `/devtools-ui`, `/benchmarks/comparison`,
  `/tests/integration/brokers`.  Its updater runs `bun install <dep>@<version>
  --save-text-lockfile` and commits the result, so a PR arrives green on
  `--frozen-lockfile` and in-range updates surface as the grouped daily PR.
  One entry per directory, deliberately not a `directories:` list: a grouped
  update across directories is a single PR, and the DevTools UI half of it is
  red by construction — `bun run check:ui` hashes `devtools-ui/package.json`
  into the embedded bundle's `source-hash`, so a bump there needs `bun run
  build:ui` in the same merge, like any change under `devtools-ui/` — which
  must not hold a root or docs bump hostage.  Neither updater reads
  `peerDependencies` (`DEPENDENCY_TYPES` in both parsers), so no peer floor
  moves as a side effect.
- `package-ecosystem: "npm"` with a `directories:` list for the eight example
  frontends, because `examples.yml` builds them with `npm ci` from
  `package-lock.json`.  The `bun.lock` each also carries is #1402's open
  decision; until then the dry-run leg there goes red on the directories a PR
  touches, naming the lockfile to sync.  A minor-and-patch group spans the
  eight (one PR a day, not eight) and a `group-by: dependency-name` group
  lands a major in both halves of a chat/voice pair at once.

The Dependabot bun updater bundles Bun 1.3.14 and, since
dependabot/dependabot-core#15896, refuses a `lockfileVersion` above 1 with
`DependencyFileNotSupported` — no PRs, no silent downgrade;
dependabot/dependabot-core#16071 raises the ceiling and is still open.  Bun 1.4
stamps a fresh lockfile 2 but preserves an existing 1 on every re-save, so the
four lockfiles born under 1.3 are fine and `devtools-ui/bun.lock`, born under
1.4.0 as a 2 (`65548aa9`), is restamped to 1.  The content is identical (v2
only added parse-time strictness), and measured rather than assumed: under
1.4.2 a frozen install of the restamped file succeeds (352 packages) and an
unfrozen one — what `ui:install` runs — reports no changes, both leaving the
file byte-identical.

`tests/unit/ci/WorkflowHygiene.test.ts`, which already parses this file, now
lists every tracked package.json from the git index and asserts that each is
named by exactly one `bun`/`npm` entry, that the entry's ecosystem is `npm`
iff a `package-lock.json` sits beside the manifest, that every directory an
entry names holds a manifest, and that every `bun.lock` a `bun` entry watches
carries a stamp the updater reads.  Each assertion was checked to fail on the
mutation it exists for: an entry removed, an ecosystem crossed, a directory
that does not exist, a directory named twice, the lockfile restamped to 2.

Also: commit prefixes are `chore` + Dependabot's own scope, so messages read
`chore(deps): …` / `chore(deps-dev): …` — the two scopes AGENTS.md lists —
instead of the doubled `chore(deps)(deps-dev): …` the old prefix produced; and
the header no longer says PRs open against `main` (they target `develop`).

Closes #1596

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant