chore(deps): bump the npm_and_yarn group across 2 directories with 2 updates#119
chore(deps): bump the npm_and_yarn group across 2 directories with 2 updates#119dependabot[bot] wants to merge 1 commit into
Conversation
…updates Bumps the npm_and_yarn group with 2 updates in the / directory: [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) and [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro). Bumps the npm_and_yarn group with 1 update in the /apps/docs directory: [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro). Updates `vitest` from 3.2.6 to 4.1.8 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.8/packages/vitest) Updates `astro` from 5.18.2 to 6.4.2 - [Release notes](https://github.com/withastro/astro/releases) - [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md) - [Commits](https://github.com/withastro/astro/commits/astro@6.4.2/packages/astro) Updates `astro` from 5.18.2 to 6.4.2 - [Release notes](https://github.com/withastro/astro/releases) - [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md) - [Commits](https://github.com/withastro/astro/commits/astro@6.4.2/packages/astro) --- updated-dependencies: - dependency-name: vitest dependency-version: 4.1.8 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: astro dependency-version: 6.4.2 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: astro dependency-version: 6.4.2 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
|
Audit note (scheduled routine): this PR has been red for 12 days and the underlying upgrade is already tracked, so nothing here is mergeable as a drive-by.
Recommendation (matches the close-out plan documented in #115):
Happy to file the vitest tracking issue if you want — say the word. Generated by Claude Code |
|
Filed the vitest 3 → 4 tracking issue as #120 so the major bump doesn't keep getting re-proposed alongside Astro. Both blockers (#115 Astro 6, #120 Vitest 4) are now captured. Next step to close this PR out cleanly per the documented plan: That tells Dependabot to stop re-proposing the Astro 6 and Vitest 4 majors on this group while #115 and #120 stay open as the real tracking surfaces. Security and minor bumps within Generated by Claude Code |
|
Closing per the plan documented in #120 (Vitest 4) and #115 (Astro 6). Both upgrades are tracked in dedicated migration issues; neither can ride along as a drive-by bump. Resume bumping within v3 / v5 in the meantime. ·@·d·ependabot i·gnore t·his major version Generated by Claude Code |
|
Closing per the migration trackers — both upgrades are blocked on upstream work and can't ride along with a Dependabot drive-by:
Issuing the ignore-major commands #120 / #115 recommend so Dependabot keeps bumping within the current major: @dependabot ignore vitest major version Generated by Claude Code — scheduled audit routine Generated by Claude Code |
|
Closing per the migration trackers — both bumps in this group are real majors that need their own plan, not a drive-by:
Both tracker issues explicitly say to ignore the major bump here until they're actionable. Stopping the v4/v6 majors so the group can resume bumping within v3/v5. @dependabot ignore vitest major version Generated by Claude Code |
Bumps the npm_and_yarn group with 2 updates in the / directory: vitest and astro.
Bumps the npm_and_yarn group with 1 update in the /apps/docs directory: astro.
Updates
vitestfrom 3.2.6 to 4.1.8Release notes
Sourced from vitest's releases.
... (truncated)
Commits
e61f2ddchore: release v4.1.8e4067b3fix(browser): disable clientcdpAPI whenallowWrite/allowExec: false[ba...a09d472chore: release v4.1.7a8fd24cchore: release v4.1.618af98cfix(browser): simplify orchestrator otel carrier (#10285)3188260feat(browser): provide project reference inToMatchScreenshotResolvePath(#...e399846chore: release v4.1.57dc6d54Revert "fix: respect diff config options in soft assertions (#8696)"9787dedfix: respect diff config options in soft assertions (#8696)325463afix(ast-collect): recognize _vi_import prefix in static test discovery (#10...Updates
astrofrom 5.18.2 to 6.4.2Release notes
Sourced from astro's releases.
... (truncated)
Changelog
Sourced from astro's changelog.
... (truncated)
Commits
b82137b[ci] release (#16885)c8625e2[ci] formatb94bcfdfix(config): Keep legacy plugins data on the config (#16889)b9f6bb9Fix SSR dynamic routes blocked by prerendered dynamic routes (#16878)3b75dc6[ci] release (#16884)eeb064cfix(mdx): Restore MDX rehype plugin entrypoint (#16883)c7157e6[ci] release (#16870)f387eba[ci] formate0e26dbResolve X-Forwarded-* headers inside FetchState (#16811)8153f8d[ci] formatUpdates
astrofrom 5.18.2 to 6.4.2Release notes
Sourced from astro's releases.
... (truncated)
Changelog
Sourced from astro's changelog.
... (truncated)
Commits
b82137b[ci] release (#16885)c8625e2[ci] formatb94bcfdfix(config): Keep legacy plugins data on the config (#16889)b9f6bb9Fix SSR dynamic routes blocked by prerendered dynamic routes (#16878)3b75dc6[ci] release (#16884)eeb064cfix(mdx): Restore MDX rehype plugin entrypoint (#16883)c7157e6[ci] release (#16870)f387eba[ci] formate0e26dbResolve X-Forwarded-* headers inside FetchState (#16811)8153f8d[ci] formatDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.