chore(deps-dev): Bump the npm group across 1 directory with 3 updates - #103
Conversation
Bumps the npm group with 3 updates in the / directory: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node), [typescript](https://github.com/microsoft/TypeScript) and [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). Updates `@types/node` from 26.1.1 to 26.1.2 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `typescript` from 6.0.3 to 7.0.2 - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) Updates `vite` from 8.1.5 to 8.2.0 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/create-vite@8.2.0/packages/vite) --- updated-dependencies: - dependency-name: "@types/node" dependency-version: 26.1.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm - dependency-name: vite dependency-version: 8.2.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Beyond the flagged @typescript-eslint/typescript@7.0.2 peer mismatch, I also checked whether eslint-plugin-sonarjs's own TypeScript resolution is affected by this bump: it still resolves ts-api-utils/typescript independently at 6.0.3 (pnpm-lock.yaml:3100-3101), unaffected by and unrelated to the version bump, so it doesn't compound the reported issue.
Extended reasoning...
Verified via the lockfile that eslint-plugin-sonarjs@4.2.0 keeps its own private, unaffected resolution of typescript@6.0.3 through ts-api-utils@2.5.0(typescript@6.0.3) (pnpm-lock.yaml lines 3100-3101, 3838), separate from the workspace's bumped typescript@7.0.2. This is expected pnpm peer-resolution behavior (sonarjs doesn't peer on the hoisted typescript version) and does not introduce any additional risk beyond the inline finding.
…nt compatibility Dependabot's npm group bump also proposed typescript 6.0.3 -> 7.0.2, but typescript-eslint does not yet support TS 7.0 (lint fails hard). Applying only the compatible @types/node and vite bumps from this group; typescript stays pinned to the latest supported 6.x release.
|
@claude review |
|
| Experiment | Status | Actions |
|---|---|---|
| Uppercase (ts) — e2e-matrix (beta) | ✅ Pass | View GitHub Action Run · View in Langfuse |
| Uppercase (ts) — e2e-matrix (alpha) | ✅ Pass | View GitHub Action Run · View in Langfuse |
| Uppercase (py) | ✅ Pass | View GitHub Action Run · View in Langfuse |
| Uppercase (ts) | ✅ Pass | View GitHub Action Run · View in Langfuse |
| Mixed dir (node) | ✅ Pass | View GitHub Action Run · View in Langfuse |
| Mixed dir (python) | ✅ Pass | View GitHub Action Run · View in Langfuse |
| Regression fixture | ❌ Regression | View GitHub Action Run · View in Langfuse |
Details
There was a problem hiding this comment.
LGTM — dev-dependency-only bump (types/vite patch/minor), no bugs found.
What was reviewed: confirmed the diff only touches @types/node (26.1.1→26.1.2) and vite (8.1.5→8.2.0) plus their transitive lockfile entries (nanoid, postcss, rolldown, oxc-project types, rolldown platform bindings) — no application code changed. Checked the previously flagged typescript 6→7 bump against @typescript-eslint's peer range: that concern doesn't apply here, since the diff leaves the typescript devDependency unchanged at ^6.0.3 (the PR description's dependabot template lists it, but the actual patch does not touch it).
Extended reasoning...
Overview
This PR is a dependabot devDependency bump touching only package.json and pnpm-lock.yaml. The effective changes are: @types/node 26.1.1 → 26.1.2 (patch) and vite 8.1.5 → 8.2.0 (minor), plus their transitively-updated lockfile entries (nanoid, postcss, rolldown, @oxc-project/types, @rolldown/binding-* platform packages, @emnapi/*). No source files under src/, scripts/, or CI config are touched.
Security risks
None identified. These are build/type-tooling and dev-server dependencies used only in the local/CI dev workflow (typechecking types, Vite dev/build), not shipped in the action's runtime path. No auth, crypto, or permission-related code is touched.
Level of scrutiny
Low. This is a mechanical, dependabot-generated patch/minor bump with no application logic changes. A prior automated review run flagged a peer-dependency conflict from a typescript 6→7 major bump, but re-checking the current diff shows the typescript devDependency specifier is unchanged at ^6.0.3 — that finding does not apply to what's actually in this diff (likely stale relative to an earlier version of the PR, or a mismatch with the dependabot description template which lists all group members regardless of whether each was ultimately included).
Other factors
The bug hunting system found no issues in this run. The lockfile diff is internally consistent (importer specifiers match resolved versions, peer-dependency-relevant packages like @typescript-eslint/* remain pinned against typescript@6.0.3). No outstanding unaddressed reviewer comments beyond the now-inapplicable prior flag.
Bumps the npm group with 3 updates in the / directory: @types/node, typescript and vite.
Updates
@types/nodefrom 26.1.1 to 26.1.2Commits
Updates
typescriptfrom 6.0.3 to 7.0.2Commits
Maintainer changes
This version was pushed to npm by microsoft1es, a new releaser for typescript since your current version.
Updates
vitefrom 8.1.5 to 8.2.0Release notes
Sourced from vite's releases.
Changelog
Sourced from vite's changelog.
... (truncated)
Commits
24a611frelease: v7.2.42d66b7bfix: revert "perf(deps): replace debug with obug (#21107)"a668014release: v7.2.3acfe939perf(deps): replace debug with obug (#21107)4f8171efix(deps): update all non-major dependencies (#21128)5029720chore(deps): update rolldown-related dependencies (#21127)5909efdfix: allow multiplebindCLIShortcutscalls with shortcut merging (#21103)39a0a15chore(deps): update rolldown-related dependencies (#21095)6a34ac3fix(deps): update all non-major dependencies (#21096)02ceaecchore(deps): update dependency@rollup/plugin-commonjsto v29 (#21099)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions