chore(deps): bump the minor-and-patch group across 1 directory with 9 updates#129
Closed
dependabot[bot] wants to merge 1 commit into
Closed
chore(deps): bump the minor-and-patch group across 1 directory with 9 updates#129dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
… updates Bumps the minor-and-patch group with 9 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@octokit/graphql](https://github.com/octokit/graphql.js) | `9.0.1` | `9.0.3` | | [apollo3-cache-persist](https://github.com/apollographql/apollo-cache-persist) | `0.14.1` | `0.15.0` | | [chalk](https://github.com/chalk/chalk) | `5.6.0` | `5.6.2` | | [dotenv](https://github.com/motdotla/dotenv) | `17.2.1` | `17.4.2` | | [fuse.js](https://github.com/krisk/Fuse) | `7.4.1` | `7.4.2` | | [react](https://github.com/facebook/react/tree/HEAD/packages/react) | `19.1.1` | `19.2.7` | | [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react) | `19.1.12` | `19.2.17` | | [tsup](https://github.com/egoist/tsup) | `8.5.0` | `8.5.1` | | [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.0` | `4.1.9` | Updates `@octokit/graphql` from 9.0.1 to 9.0.3 - [Release notes](https://github.com/octokit/graphql.js/releases) - [Commits](octokit/graphql.js@v9.0.1...v9.0.3) Updates `apollo3-cache-persist` from 0.14.1 to 0.15.0 - [Release notes](https://github.com/apollographql/apollo-cache-persist/releases) - [Changelog](https://github.com/apollographql/apollo-cache-persist/blob/master/CHANGELOG.md) - [Commits](apollographql/apollo-cache-persist@0.14.1...0.15.0) Updates `chalk` from 5.6.0 to 5.6.2 - [Release notes](https://github.com/chalk/chalk/releases) - [Commits](chalk/chalk@v5.6.0...v5.6.2) Updates `dotenv` from 17.2.1 to 17.4.2 - [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md) - [Commits](motdotla/dotenv@v17.2.1...v17.4.2) Updates `fuse.js` from 7.4.1 to 7.4.2 - [Release notes](https://github.com/krisk/Fuse/releases) - [Changelog](https://github.com/krisk/Fuse/blob/main/CHANGELOG.md) - [Commits](krisk/Fuse@v7.4.1...v7.4.2) Updates `react` from 19.1.1 to 19.2.7 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.7/packages/react) Updates `@types/react` from 19.1.12 to 19.2.17 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react) Updates `@types/react` from 19.1.12 to 19.2.17 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react) Updates `tsup` from 8.5.0 to 8.5.1 - [Release notes](https://github.com/egoist/tsup/releases) - [Commits](egoist/tsup@v8.5.0...v8.5.1) Updates `vitest` from 4.1.0 to 4.1.9 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.9/packages/vitest) --- updated-dependencies: - dependency-name: "@octokit/graphql" dependency-version: 9.0.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: apollo3-cache-persist dependency-version: 0.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: chalk dependency-version: 5.6.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: dotenv dependency-version: 17.4.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: fuse.js dependency-version: 7.4.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: react dependency-version: 19.2.7 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@types/react" dependency-version: 19.2.17 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@types/react" dependency-version: 19.2.17 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: tsup dependency-version: 8.5.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: vitest dependency-version: 4.1.9 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
This was referenced Jun 18, 2026
Owner
|
Superseded by #131, which consolidates all open Dependabot updates into a single PR. Closing in favour of that. |
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
wiiiimm
added a commit
that referenced
this pull request
Jun 18, 2026
…r title] (#131) * chore(deps): consolidate open dependabot updates (GMC-45) Combine all 13 open Dependabot PRs (#116–#129) into a single update. npm group (#129): @octokit/graphql 9.0.3, apollo3-cache-persist 0.15.0, chalk 5.6.2, dotenv 17.4.2, fuse.js 7.4.2, react 19.2.7, @types/react 19.2.17, tsup 8.5.1, vitest 4.1.9. npm majors: typescript 6.0.3 (#128), @vitest/coverage-v8 4.1.8 (#127), semantic-release 25.0.5 (#126), ink-testing-library 4.0.0 (#125), env-paths 4.0.0 (#124), @types/node 25.9.2 (#123), open 11.0.0 (#122). GitHub Actions: setup-node v6 (#120), checkout v6 (#119), github-script v9 (#118), download-artifact v8 (#117), cache v5 (#116). Verified: typecheck (TS 6), build, and full test suite (456/456) all pass. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ci: bump release workflow to Node 22 for semantic-release 25 (GMC-45) semantic-release 25 requires Node ^22.14.0 || >=24.10.0; the release workflow still set up Node 20, which would fail `npx semantic-release` on the next push to main. Bump all setup-node steps to Node 22 (LTS). Flagged by Cursor Bugbot (High) and Codex (P1) on PR #131. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * chore: raise Node floor to >=20 for env-paths 4 and open 11 (GMC-45) env-paths@4 and open@11 both declare engines.node ">=20", but the package still advertised ">=18", letting Node 18-19 users install a build that breaks at startup (env-paths) and on browser open (open). Align engines.node and the setup docs to >=20. Node 18 is already EOL. Flagged by Cursor Bugbot (Medium) on PR #131. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * build: migrate to @yao-pkg/pkg and target node20 binaries (GMC-45) vercel/pkg (pkg@5.8.1) is archived and only ships base binaries up to Node 18, so release binaries embedded a Node 18 runtime — incompatible with env-paths 4 / open 11 (Node 20+) after raising the engine floor. Switch to the maintained @yao-pkg/pkg fork and build node20 targets in both the build:binaries script and the release workflow. The packager needs Node 22 to run, which the release jobs already use. Flagged by Cursor Bugbot (High) on PR #131. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * docs: note build:binaries requires Node 22+ for @yao-pkg/pkg (GMC-45) The CLI runtime engine stays at Node >=20, but @yao-pkg/pkg requires Node >=22 to run. Document this in the Packaging section so contributors on Node 20/21 know the binary build needs a newer Node, rather than raising engines.node and wrongly forcing end users onto Node 22. Addresses CodeRabbit engine-mismatch note on PR #131. The companion "Invalid Windows pkg target" finding is a false positive: pkg-fetch's toFancyPlatform aliases "windows" -> "win" during target parsing. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the minor-and-patch group with 9 updates in the / directory:
9.0.19.0.30.14.10.15.05.6.05.6.217.2.117.4.27.4.17.4.219.1.119.2.719.1.1219.2.178.5.08.5.14.1.04.1.9Updates
@octokit/graphqlfrom 9.0.1 to 9.0.3Release notes
Sourced from @octokit/graphql's releases.
Commits
d5acce5fix(deps): update dependency@octokit/typesto v16 (#676)db5b8fcbuild(deps): lock file maintenance (#670)6d34f9fci(action): update github/codeql-action action to v4 (#671)be6febachore(deps): update dependency@types/nodeto v24 (#675)59bbbbcci(action): update peter-evans/create-or-update-comment action to v5 (#668)9014228ci(action): update actions/setup-node action to v6 (#672)2e9c447chore(deps): update dependency prettier to v3.6.2 (#661)e31cf11ci(action): update actions/setup-node action to v5 (#663)9989422build(deps): lock file maintenance (#667)ea07437ci(action): update actions/checkout action to v5 (#662)Updates
apollo3-cache-persistfrom 0.14.1 to 0.15.0Release notes
Sourced from apollo3-cache-persist's releases.
Changelog
Sourced from apollo3-cache-persist's changelog.
Commits
719048dchore(deps): update secops orb to v2.0.763b12fcchore: release 0.15.09b170b0chore(examples): update web example dependencies and yarne39c2aachore(deps): update dev dependenciesb8a2217chore: ignore .idea366d155chore: migrate to latest yarnac4797efix: persist cache on garbage collection2a9e3e9feat: add semgrep jobcbf1b19update secops orbbe23e25Add gitleaks scan to CIUpdates
chalkfrom 5.6.0 to 5.6.2Release notes
Sourced from chalk's releases.
Commits
51557785.6.2Updates
dotenvfrom 17.2.1 to 17.4.2Changelog
Sourced from dotenv's changelog.
... (truncated)
Commits
f116f7017.4.23a81612fix visual order of faq13f55a8Merge branch 'skill'4bbbf73reorganize faqc3da64bMerge pull request #1009 from motdotla/skill6f743b1update sourcefc2c624update skill972315bTighten up skill2795fcereorganize faqd5495d4adjust skillUpdates
fuse.jsfrom 7.4.1 to 7.4.2Release notes
Sourced from fuse.js's releases.
Changelog
Sourced from fuse.js's changelog.
Commits
9e63058chore(release): 7.4.233f5d29fix(types): emit CommonJS declarations (.d.cts) for node16/nodenext (#780)7c6af4ebuild: replace rollup/babel/terser build with tsdown50f6b24chore(deps): pin fast-uri to ^3.1.2 via overrides9e6ec22chore(build): exit non-zero when a build step failsff51f6bchore: source docs version from package.json, not npm view08b77d9chore: bump doc versions to 7.4.1Updates
reactfrom 19.1.1 to 19.2.7Release notes
Sourced from react's releases.
... (truncated)
Changelog
Sourced from react's changelog.
... (truncated)
Commits
6117d7cVersion 19.2.7 (#36591)eaf3e95Version 19.2.623f4f9f19.2.590ab3f8Version 19.2.4612e371Version 19.2.3b910fc1Version 19.2.2053df4eVersion 19.2.15667a41Bump next prerelease version numbers (#34639)8bb7241Bump useEffectEvent to Canary (#34610)e3c9656Ensure Performance Track are Clamped and Don't overlap (#34509)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for react since your current version.
Updates
@types/reactfrom 19.1.12 to 19.2.17Commits
Updates
@types/reactfrom 19.1.12 to 19.2.17Commits
Updates
tsupfrom 8.5.0 to 8.5.1Release notes
Sourced from tsup's releases.
Commits
1ecb6a5chore: release v8.5.1e92ba64chore: upgrade esbuildfb8ae7dfix: update esbuild to fix sourcemap source issue (#1316)db7cfaachore: upgrade pnpmdf7360bfix: add script tag validation (#1314)65e8547chore: bumpsource-mapto 0.7.6 (#1358)f127e57ci: switch to trusted publisher8b6907dchore: add maintenance info in README (#1332)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for tsup since your current version.
Updates
vitestfrom 4.1.0 to 4.1.9Release notes
Sourced from vitest's releases.
... (truncated)
Commits
a7a61e7chore: release v4.1.9 (#10598)934b0f5fix(pool): prevent test run hang on worker crash (#10543) [backport to v4] (#...7fb2965fix(browser): wait for orchestrator readiness before resolving browser sessio...a518019fix: fiximportOriginalwith optimizer and query import [backport to v4] (#...e61f2ddchore: release v4.1.8e4067b3fix(browser): disable clientcdpAPI whenallowWrite/allowExec: false[ba...a09d472chore: release v4.1.7a8fd24cchore: release v4.1.618af98cfix(browser): simplify orchestrator otel carrier (#10285)3188260feat(browser): provide project reference inToMatchScreenshotResolvePath(#...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions