Skip to content

Bump brace-expansion, @rollup/plugin-commonjs and shx - #99

Merged
onyb merged 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-bef33f638f
Aug 3, 2026
Merged

Bump brace-expansion, @rollup/plugin-commonjs and shx#99
onyb merged 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-bef33f638f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 29, 2026

Copy link
Copy Markdown
Contributor

Removes brace-expansion. It's no longer used after updating ancestor dependencies brace-expansion, @rollup/plugin-commonjs and shx. These dependencies need to be updated together.

Removes brace-expansion

Updates @rollup/plugin-commonjs from 22.0.2 to 29.0.3

Changelog

Sourced from @​rollup/plugin-commonjs's changelog.

v29.0.3

2026-05-29

Bugfixes

v29.0.2

2026-03-06

Bugfixes

  • commonjs: conditional exports (#1952)

v29.0.1

2026-03-05

Bugfixes

  • commonjs: correctly replaces shorthand "global" property in object (#1957)

v29.0.0

2025-10-30

Breaking Changes

  • feat!: revert #1909 and add requireNodeBuiltins option (#1937)

v28.0.9

2025-10-24

Bugfixes

  • fix: handle node: builtins with strictRequires: auto (#1930)

v28.0.8

2025-10-16

Bugfixes

  • fix: guard moduleSideEffects for wrapped externals (#1914)

v28.0.7

... (truncated)

Commits
  • 1e4025b chore(release): commonjs v29.0.3
  • 08a5b17 fix(commonjs): make #1868 es5-compatible (#1981)
  • 5800bf3 chore(repo): test migration to vitest. phase 4 (#1978)
  • 2de0d62 chore(release): commonjs v29.0.2
  • ab65325 fix(commonjs): conditional exports (#1952)
  • 7d22981 chore(repo): add rollup-plugin keyword in package.json (#1955)
  • a79ae55 chore(release): commonjs v29.0.1
  • bb41cfd chore(release): commonjs v29.0.1
  • 14ae186 fix(commonjs): correctly replaces shorthand "global" property in object (#1957)
  • c8e78c8 chore(release): commonjs v29.0.0
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​rollup/plugin-commonjs since your current version.


Updates shx from 0.3.4 to 0.4.0

Release notes

Sourced from shx's releases.

v0.4.0

✨ Highlighted changes

  • This is based on ShellJS v0.9! This means we bumped the minimum node version to >= v18.
  • Small bash compatibility change to shx sed. Now if you invoke shx sed -i, this will not print any output to stdout (this is for consistency with unix sed). Using shx sed without the -i flag will still print to stdout as before.

What's Changed

New Contributors

Full Changelog: shelljs/shx@v0.3.4...v0.4.0

Commits
  • 8886c3e 0.4.0
  • e8db3bc refactor: code cleanup for the --negate flag
  • 6184003 Adding a global --negate flag (#189)
  • b3d5b80 fix: add back ShellJS version in --version
  • 5106c6b chore: update dependencies
  • e8bb9f8 chore: drop some dependencies and simplify
  • 3bb21d9 chore: drop non-LTS node versions
  • b70e666 chore: update shelljs and drop old node support
  • f8b0b37 doc: Fix typo in README
  • 03c2964 chore(dependencies): update js-yaml
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Removes [brace-expansion](https://github.com/juliangruber/brace-expansion). It's no longer used after updating ancestor dependencies [brace-expansion](https://github.com/juliangruber/brace-expansion), [@rollup/plugin-commonjs](https://github.com/rollup/plugins/tree/HEAD/packages/commonjs) and [shx](https://github.com/shelljs/shx). These dependencies need to be updated together.


Removes `brace-expansion`

Updates `@rollup/plugin-commonjs` from 22.0.2 to 29.0.3
- [Changelog](https://github.com/rollup/plugins/blob/master/packages/commonjs/CHANGELOG.md)
- [Commits](https://github.com/rollup/plugins/commits/commonjs-v29.0.3/packages/commonjs)

Updates `shx` from 0.3.4 to 0.4.0
- [Release notes](https://github.com/shelljs/shx/releases)
- [Changelog](https://github.com/shelljs/shx/blob/main/CHANGELOG.md)
- [Commits](shelljs/shx@v0.3.4...v0.4.0)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version:
  dependency-type: indirect
- dependency-name: "@rollup/plugin-commonjs"
  dependency-version: 29.0.3
  dependency-type: direct:development
- dependency-name: shx
  dependency-version: 0.4.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 29, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner July 29, 2026 12:26
@github-actions github-actions Bot added P2 security for security issue reporting labels Jul 29, 2026
@onyb
onyb merged commit 6c7c19c into master Aug 3, 2026
7 checks passed
@onyb
onyb deleted the dependabot/npm_and_yarn/multi-bef33f638f branch August 3, 2026 19:10
onyb added a commit that referenced this pull request Aug 4, 2026
CI verified almost nothing about its own output. The IIFE bundle shipped to
npm was only checked with `test -s`, and the package smoke test asserted
`typeof initialize === 'function'` without ever calling it. Reviewing the
plugin-commonjs 22->29 bump in #99 meant verifying the bundle by hand,
because nothing in CI could have caught a regression in it.

Add a zero-dependency suite (node:test / node:assert / node:vm) that runs the
real artifacts:

- behavior: drives the full wallet surface -- connect, events, signMessage,
  signTransaction single and batch, signAndSendTransaction, the error paths,
  disconnect -- through lib/esm, lib/cjs and the IIFE bundle, then requires all
  three to agree. Cross-target equality is what catches a bundler change that
  silently diverges the bundle from the tsc output. Covers
  VersionedTransaction.deserialize and bs58.decode, the CJS-interop paths a
  bundler regression actually breaks.

- registration: registerWallet swallows every error it hits, so a failed
  registration is indistinguishable from a successful one at the call site.
  Assert on the observable effect (exactly one wallet registered) instead.

- bundle: reject a commonjsRequire shim, which plugin-commonjs emits for
  unresolvable requires and which throws at runtime; assert the bundle stays
  unmangled, since rollup.config.js runs terser with mangle and compress off
  to keep the artifact auditable and nothing enforced that; validate the
  sourcemap. Size is logged, not gated -- this project has explicitly traded
  size for auditability, so a byte budget would enforce a goal it does not
  have and would block routine dependency bumps.

- package: assert every declared entry point reaches the tarball, that no
  development files leak into it, and that lib/cjs/package.json still pins
  "commonjs".

Also fix engines.node, which claimed >=16 while @solana/web3.js ->
@solana/codecs-numbers had already moved the real runtime floor to >=20.18.0.
The new drift check compares the declared floor against every non-dev package
in the lockfile, so this cannot silently rot again.

Run the suite on node 20/22/24 in PR CI, and before publish -- previously a
broken bundle could be published on the strength of `test -s` alone.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code P2 security for security issue reporting

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant