chore(deps): bump the npm group across 1 directory with 11 updates - #477
Closed
dependabot[bot] wants to merge 1 commit into
Closed
chore(deps): bump the npm group across 1 directory with 11 updates#477dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Collaborator
|
#484 limits every Dependabot group to Note for whoever handles the rebuilt pair: @dependabot recreate |
Bumps the npm group with 11 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@tauri-apps/api](https://github.com/tauri-apps/tauri) | `2.10.1` | `2.11.1` | | [@tauri-apps/plugin-dialog](https://github.com/tauri-apps/plugins-workspace) | `2.6.0` | `2.7.2` | | [@tauri-apps/plugin-opener](https://github.com/tauri-apps/plugins-workspace) | `2.5.3` | `2.5.4` | | [katex](https://github.com/KaTeX/KaTeX) | `0.16.47` | `0.18.1` | | [monaco-editor](https://github.com/microsoft/monaco-editor) | `0.55.1` | `0.56.0` | | [@sveltejs/vite-plugin-svelte](https://github.com/sveltejs/vite-plugin-svelte/tree/HEAD/packages/vite-plugin-svelte) | `5.1.1` | `7.2.0` | | [@tauri-apps/cli](https://github.com/tauri-apps/tauri) | `2.9.6` | `2.11.4` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `24.13.3` | `26.1.2` | | [tsx](https://github.com/privatenumber/tsx) | `4.22.4` | `4.23.5` | | [typescript](https://github.com/microsoft/TypeScript) | `5.6.3` | `7.0.2` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `6.4.3` | `8.2.0` | Updates `@tauri-apps/api` from 2.10.1 to 2.11.1 - [Release notes](https://github.com/tauri-apps/tauri/releases) - [Commits](https://github.com/tauri-apps/tauri/compare/@tauri-apps/api-v2.10.1...@tauri-apps/api-v2.11.1) Updates `@tauri-apps/plugin-dialog` from 2.6.0 to 2.7.2 - [Release notes](https://github.com/tauri-apps/plugins-workspace/releases) - [Commits](tauri-apps/plugins-workspace@log-v2.6.0...dialog-v2.7.2) Updates `@tauri-apps/plugin-opener` from 2.5.3 to 2.5.4 - [Release notes](https://github.com/tauri-apps/plugins-workspace/releases) - [Commits](tauri-apps/plugins-workspace@http-v2.5.3...http-v2.5.4) Updates `katex` from 0.16.47 to 0.18.1 - [Release notes](https://github.com/KaTeX/KaTeX/releases) - [Changelog](https://github.com/KaTeX/KaTeX/blob/main/CHANGELOG.md) - [Commits](KaTeX/KaTeX@v0.16.47...v0.18.1) Updates `monaco-editor` from 0.55.1 to 0.56.0 - [Release notes](https://github.com/microsoft/monaco-editor/releases) - [Changelog](https://github.com/microsoft/monaco-editor/blob/main/CHANGELOG.md) - [Commits](microsoft/monaco-editor@v0.55.1...v0.56.0) Updates `@sveltejs/vite-plugin-svelte` from 5.1.1 to 7.2.0 - [Release notes](https://github.com/sveltejs/vite-plugin-svelte/releases) - [Changelog](https://github.com/sveltejs/vite-plugin-svelte/blob/main/packages/vite-plugin-svelte/CHANGELOG.md) - [Commits](https://github.com/sveltejs/vite-plugin-svelte/commits/@sveltejs/vite-plugin-svelte@7.2.0/packages/vite-plugin-svelte) Updates `@tauri-apps/cli` from 2.9.6 to 2.11.4 - [Release notes](https://github.com/tauri-apps/tauri/releases) - [Commits](https://github.com/tauri-apps/tauri/compare/@tauri-apps/cli-v2.9.6...@tauri-apps/cli-v2.11.4) Updates `@types/node` from 24.13.3 to 26.1.2 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `tsx` from 4.22.4 to 4.23.5 - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](privatenumber/tsx@v4.22.4...v4.23.5) Updates `typescript` from 5.6.3 to 7.0.2 - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) Updates `vite` from 6.4.3 to 8.2.0 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/create-vite@8.2.0/packages/vite) --- updated-dependencies: - dependency-name: "@sveltejs/vite-plugin-svelte" dependency-version: 7.2.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm - dependency-name: "@tauri-apps/api" dependency-version: 2.11.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm - dependency-name: "@tauri-apps/cli" dependency-version: 2.11.4 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm - dependency-name: "@tauri-apps/plugin-dialog" dependency-version: 2.7.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm - dependency-name: "@tauri-apps/plugin-opener" dependency-version: 2.5.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm - dependency-name: "@types/node" dependency-version: 26.1.2 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm - dependency-name: katex dependency-version: 0.18.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm - dependency-name: monaco-editor dependency-version: 0.56.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm - dependency-name: tsx dependency-version: 4.23.5 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm - dependency-name: vite dependency-version: 8.2.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/npm-3d17b8893e
branch
from
August 6, 2026 02:47
02f29ca to
4b0834e
Compare
PathGao
added a commit
that referenced
this pull request
Aug 6, 2026
…#484) #472 gave each ecosystem one grouped pull request a month with `patterns: ['*']` and no `update-types` filter. The first run showed what that grouping actually covers: | PR | contents | crossed | |------|-----------|-----------------------------------------------------| | #476 | 4 actions | major tags v4 -> v7, merged | | #477 | 11 npm | TypeScript 5.6 -> 7.0, Vite 6 -> 8 | | #478 | 17 crates | tauri-plugin-prevent-default 2 -> 5, notify 6 -> 8 | Nothing failed. Dependabot's schema check accepts the config, and the result is a `chore(deps)` title wrapped around a toolchain migration -- a diff whose per-dependency changelogs are the review, presented as a batch that cannot be split, bisected, or reverted per dependency. So each group now takes `update-types: [minor, patch]`. Majors fall outside every group and arrive one pull request per dependency, each carrying its own changelog. That is the documented shape: "Example: Individual pull requests for major updates and grouped for minor/patch updates" in GitHub's guide to optimizing pull request creation, whose stated result is "All major updates will continue to be raised as individual pull requests." `update-types` alone does not suppress anything. The next example in the same guide, the one titled "no pull requests for major updates", starts from this exact group and reaches that outcome by *adding* an `ignore` condition on `version-update:semver-major`. That condition is deliberately not written here: an `ignore` is a permanent, repo-invisible mute, and the point of this change is to make majors visible one at a time, not to stop hearing about them. `open-pull-requests-limit` goes 2 -> 4 because the shape of a run changed. Two was sized for "one grouped pull request, plus headroom for a stale one". With majors opening individually the file now holds one grouped pull request plus n majors, and a limit of 2 leaves room for exactly one of them. One caveat, which is in the config comment because it is invisible from the config: on a run where a grouped pull request is already open, Dependabot marks every dependency matching the group's `patterns` as handled before it consults `update-types`, so that run opens no individual major pull requests at all. They appear on the first run after the grouped pull request is merged or closed. Majors are deferred by an unreviewed batch, not dropped by it. Separately, and recorded in the config comment because nothing else in the repository says it: `tauri build` fails when a Tauri plugin's crate and npm halves disagree on major *or minor*, and Dependabot puts those two halves in two different pull requests. #478 is red on Linux and macOS for exactly that -- `tauri-plugin-dialog (v2.7.2) : @tauri-apps/plugin-dialog (v2.6.0)`, the npm half sitting in #477. That coupling is not a semver problem and this change does not fix it; the pair has to be merged as a pair. The github-actions comment is corrected while it is being rewritten: it claimed all five actions are tracked by major tag. Four are; `dtolnay/rust-toolchain@stable` carries no version for Dependabot to compare. scripts/dependabotConfig.test.ts locks the four properties this file has that a reader cannot see: no group lists or admits `major`, every group stays `applies-to: version-updates` so a security advisory never waits for the monthly batch, the `interval` matches the cadence the header comment promises, and the limit stays above the point where the queue becomes invisible. Each was verified to fail by breaking the property it claims to protect. `ecosystemBlocks()` asserts it found blocks, because every check is a `for` over its result and a `for` over an empty list passes. Measured: an extra space in each `- package-ecosystem:` line left four of the five checks green. Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Contributor
Author
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
This was referenced Aug 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm group with 11 updates in the / directory:
2.10.12.11.12.6.02.7.22.5.32.5.40.16.470.18.10.55.10.56.05.1.17.2.02.9.62.11.424.13.326.1.24.22.44.23.55.6.37.0.26.4.38.2.0Updates
@tauri-apps/apifrom 2.10.1 to 2.11.1Release notes
Sourced from @tauri-apps/api's releases.
... (truncated)
Commits
6f6ab12apply version updates (#15409)728c8d4fix(cli): skip building bundles when usingtauri android run(#15473)e25f45crefactor: remove impl clone on inner menus (#15553)fbcf1b0chore(deps): update dependency eslint-plugin-security to v4.0.1 (#15545)828f710fix(cli): respect src/bin required-features (fix: #15325) (#15427)ed8fd41chore(cli): lesser verboseureq_protolog (#15552)50b0237fix(android): escape special characters instrings.xml(#15549)800223ddocs: fix some missing and wrong docs (#15548)5075c81fix: checkis_maximizableininternal_toggle_maximize(#15550)532c22achore(deps-dev): bump vite from 8.0.5 to 8.0.16 (#15547)Updates
@tauri-apps/plugin-dialogfrom 2.6.0 to 2.7.2Release notes
Sourced from @tauri-apps/plugin-dialog's releases.
... (truncated)
Commits
03afae6publish new versions (#3500)57ac986chore(deps): update dependency@tauri-apps/clito v2.11.4 (#3463)2ed6d6cfix(store):StoreOptions.defaultsshould not be required (#3499)cdfd462chore(example): setcolor-cheme(#3493)d6e0b6bchore(example): clean up and migrate to ts partially (#3492)40ae0a7enhance(dialog): useMaterialAlertDialogBuilder(#3491)edc52eachore(deps): bump create-pull-request to v8 (#3489)a0d949dchore(deps): update pnpm to v11 (#3487)13c63afchore: fix clippy (#3488)cad301fpublish new versions (#3447)Updates
@tauri-apps/plugin-openerfrom 2.5.3 to 2.5.4Release notes
Sourced from @tauri-apps/plugin-opener's releases.
... (truncated)
Commits
e7a68fapublish new versions (#3068)b5550a3chore: temp delete updater changefile93426f8fix: fix docsrs builds4ee61e0Revert "chore: temp delete updater changefile"Updates
katexfrom 0.16.47 to 0.18.1Release notes
Sourced from katex's releases.
Changelog
Sourced from katex's changelog.
Commits
cdf479fchore(release): 0.18.1 [ci skip]87a2b30fix(htmlData): allow escaped commas in \htmlData (#4236)2318066chore(deps): bump codecov/codecov-action from 6 to 7 (#4227)3b5b6a0chore(deps): bump actions/checkout from 6 to 7 (#4232)4e9d31achore(deps): update dependency js-yaml to v4.2.0 [security] (#4244)b7ca8f0chore(deps): update dependency webpack-dev-server to v5.2.5 [security] (#4242)bf1a59fchore: use pixel diff as fallback for byte-to-byte (#4245)4d9d0aechore(release): 0.18.0 [ci skip]6f5c44ffeat: prefix css classes (#4229)2c6143arefactor: remove direct hasOwnProperty call (#4230)Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
monaco-editorfrom 0.55.1 to 0.56.0Release notes
Sourced from monaco-editor's releases.
... (truncated)
Changelog
Sourced from monaco-editor's changelog.
Commits
13f0c87Bump websocket-driver from 0.7.4 to 0.7.5 in /website (#5392)b5f23a3Merge pull request #5396 from microsoft/hediet/b/release-0.56.09d053abImprove Monaco Editor 0.56.0 changelog0ba33d0Release Monaco Editor 0.56.06d961b1Bump websocket-driver from 0.7.4 to 0.7.5 in /samples (#5385)d8c9ff0Removes leftover debugger statements. (#5379)59285abfixes pipeline (#5376)aaf58dbBump webpack-dev-server from 5.2.4 to 5.2.5 in /samples (#5374)d8ac38eBump webpack-dev-server from 5.2.4 to 5.2.5 in /website (#5373)874af57Bump undici from 7.24.7 to 7.28.0 (#5371)Updates
@sveltejs/vite-plugin-sveltefrom 5.1.1 to 7.2.0Release notes
Sourced from @sveltejs/vite-plugin-svelte's releases.
... (truncated)
Changelog
Sourced from @sveltejs/vite-plugin-svelte's changelog.
... (truncated)
Commits
02981fdVersion Packages (#1371)4158aa2feat: context menu with component stack (#1370)c867a3aVersion Packages (#1368)dbdb255fix: inspector rtl host styles (#1324)694bc95chore(deps): update dependency typescript to v6 (#1315)9281816chore(deps): update all non-major dependencies (#1365)02d370dVersion Packages (#1361)3b581deRevert "feat: support.svelte.mjsand.svelte.mtsfiles" (#1366)5545e1afeat: support.svelte.mjsand.svelte.mtsfiles (#1293)2cb977efix(inspector): activate under Vite+ by matching its client module path (#1355)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@sveltejs/vite-plugin-sveltesince your current version.Updates
@tauri-apps/clifrom 2.9.6 to 2.11.4Release notes
Sourced from @tauri-apps/cli's releases.
... (truncated)
Commits
8909f22apply version updates (#15598)67ffa19fix(bundler): make .desktop and .DirIcon relative symlinks (#15596)c5c8b2bdocs(readme): desktop platforms -> operating systems, closes #1558980d437ffix(#15580): bump memmap2 (#15587)469ecc8test: regenerate stale macOS acl snapshot for has_app_acl (#15576)5be0cb8fix(ci): change strip to debuginfo for cloudflare worker (#15574)4bbd497chore(deps): bump cloudflare worker versions (#15573)5712549chore(deps): update dependency rollup to v4.62.0 (#15551)c8faedfci: test on node 20,22 instead of node 18,203641e26refactor: simplify menu code (#15559)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@tauri-apps/clisince your current version.Updates
@types/nodefrom 24.13.3 to 26.1.2Commits
Updates
tsxfrom 4.22.4 to 4.23.5Release notes
Sourced from tsx's releases.
... (truncated)
Commits
c55004dtest: remove legacy PTY retrye368161chore(deps): update pty-spawn to 1.1.18d39496ci: validate GitHub Actions workflows6fe724etest: clean up timed-out PTY attemptse0a0536ci: skip unused Windows Node cache6d6dd84ci: remove broken lock automation3c1d051fix: detect the Node inspector enabled via NODE_OPTIONS40380a4ci: lock down the release toolchainf217b6bci: restrict releases to public repository2afc7bbfix(cli): allow async process.once() signal handlers to finish (#827)Updates
typescriptfrom 5.6.3 to 7.0.2Release notes
Sourced from typescript's releases.
... (truncated)
Commits
Maintainer changes
This version was pushed to npm by microsoft1es, a new releaser for typescript since your current version.
Updates
vitefrom 6.4.3 to 8.2.0Release notes
Sourced from vite's releases.
... (truncated)
Changelog
Sourced from vite's changelog.