Skip to content

chore(deps-dev): bump the development-dependencies group across 1 directory with 4 updates - #118

Merged
kschlt merged 2 commits into
mainfrom
dependabot/npm_and_yarn/development-dependencies-f89e61a578
Oct 4, 2026
Merged

kschlt merged 2 commits into
mainfrom
dependabot/npm_and_yarn/development-dependencies-f89e61a578

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the development-dependencies group with 4 updates in the / directory: @biomejs/biome, @types/node, tsx and vitest.

Updates @biomejs/biome from 2.5.14 to 2.5.15

Release notes

Sourced from @​biomejs/biome's releases.

Biome CLI v2.5.15

2.5.15

Patch Changes

  • #10634 b436ba0 Thanks @​subaru-hello! - Added the new nursery rule noReactObjectTypeAsDefaultProp, which disallows array, object, and function values as default props in React components.

    For example, the following snippet triggers the rule.

    function Component({ items = [] }) {
      return items;
    }
  • #11956 faa8b37 Thanks @​dyc3! - Added the nursery rule noSvelteExportLet, which disallows declaring Svelte component props with the legacy export let syntax. Use the $props() rune instead.

    <script>
      export let name;
    </script>
  • #10816 1b9479e Thanks @​Th3S4mur41! - Added a new nursery rule useLogicalProperties that enforces the use of logical properties in CSS, promoting better internationalization and accessibility practices. The rule supports a direction option with "ltr" as the default and "rtl" as the alternative. This is a first rule covering parts of #9034

    {
      "linter": {
        "rules": {
          "nursery": {
            "useLogicalProperties": {
              "level": "warn",
              "options": {
                "direction": "rtl"
              }
            }
          }
        }
      }
    }
  • #11960 1fdb5c2 Thanks @​dyc3! - Added the nursery rule useSvelteKitRuneImports, which reports imports from the deprecated $app/stores module and suggests $app/state instead.

    import { page } from "$app/stores";

... (truncated)

Changelog

Sourced from @​biomejs/biome's changelog.

2.5.15

Patch Changes

  • #10634 b436ba0 Thanks @​subaru-hello! - Added the new nursery rule noReactObjectTypeAsDefaultProp, which disallows array, object, and function values as default props in React components.

    For example, the following snippet triggers the rule.

    function Component({ items = [] }) {
      return items;
    }
  • #11956 faa8b37 Thanks @​dyc3! - Added the nursery rule noSvelteExportLet, which disallows declaring Svelte component props with the legacy export let syntax. Use the $props() rune instead.

    <script>
      export let name;
    </script>
  • #10816 1b9479e Thanks @​Th3S4mur41! - Added a new nursery rule useLogicalProperties that enforces the use of logical properties in CSS, promoting better internationalization and accessibility practices. The rule supports a direction option with "ltr" as the default and "rtl" as the alternative. This is a first rule covering parts of #9034

    {
      "linter": {
        "rules": {
          "nursery": {
            "useLogicalProperties": {
              "level": "warn",
              "options": {
                "direction": "rtl"
              }
            }
          }
        }
      }
    }
  • #11960 1fdb5c2 Thanks @​dyc3! - Added the nursery rule useSvelteKitRuneImports, which reports imports from the deprecated $app/stores module and suggests $app/state instead.

    import { page } from "$app/stores";
  • #11723 3b429d1 Thanks @​m1handr! - Fixed #11656: noAstroSetHtmlDirective now correctly reports set:html directives inside Astro template expressions.

... (truncated)

Commits

Updates @types/node from 26.6.2 to 26.6.3

Commits

Updates tsx from 4.23.13 to 4.23.15

Release notes

Sourced from tsx's releases.

v4.23.15

4.23.15 (2026-09-20)

Bug Fixes

  • exclude bare builtins from namespace inheritance (38e1588)
  • expose require.cache and require.extensions to tsImport CommonJS modules (2da3407)
  • make namespaced register() overloads portable for declaration emit (562c434)

This release is also available on:

v4.23.14

4.23.14 (2026-09-20)

Bug Fixes

  • restore the CJS bridge namespace for Node 24 require(esm) under tsImport() (#802) (6e5236b)

This release is also available on:

Commits
  • ca66105 test: fix drive-less file URLs in ESM resolver fixtures
  • 2da3407 fix: expose require.cache and require.extensions to tsImport CommonJS modules
  • 38e1588 fix: exclude bare builtins from namespace inheritance
  • 562c434 fix: make namespaced register() overloads portable for declaration emit
  • edfb1f0 build: upgrade pkgroll and externalize CJS loader reference
  • 70e7828 test: upgrade tinyspy for disposable API
  • 9ed2022 ci: avoid duplicate release notifications
  • 872e77f refactor: use disposables for cleanup
  • 6e5236b fix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...
  • See full diff in compare view

Updates vitest from 5.0.1 to 5.0.3

Release notes

Sourced from vitest's releases.

v5.0.3

   🐞 Bug Fixes

    View changes on GitHub

v5.0.2

   🐞 Bug Fixes

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…ectory with 4 updates

Bumps the development-dependencies group with 4 updates in the / directory: [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome), [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node), [tsx](https://github.com/privatenumber/tsx) and [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).


Updates `@biomejs/biome` from 2.5.14 to 2.5.15
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.15/packages/@biomejs/biome)

Updates `@types/node` from 26.6.2 to 26.6.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `tsx` from 4.23.13 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.13...v4.23.15)

Updates `vitest` from 5.0.1 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

---
updated-dependencies:
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.6.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 4, 2026

kschlt commented Oct 4, 2026

Copy link
Copy Markdown
Owner

PR Review Verdict

Result: BLOCK

Deterministic: Measured on head 8520d49 — tree 0d04ace. main at 2afb042 is an ancestor, so the head is the merge result; this branch replaced #114, which dependabot closed when main moved, and it carries @biomejs/biome as a fourth update. npm ci installs what the PR declares: @biomejs/biome 2.5.15, @types/node 26.6.3, tsx 4.23.15, vitest 5.0.3, with hono 4.13.9 and undici 8.11.2 already on main from #115. The gate is red, with the same single failure #114 had: npm run quality exits 1, tsc --noEmit clean, biome ci . clean over 204 files, and the suite 1378 passed / 1 failed at protections/the-major-plants-still-describe-this-tree, reporting the same two @types/node plant anchors. Everything else here is measured inert. The biome move is a declaration catching up to what was already installed: ^2.3.0 resolved to 2.5.14 on main, so the bump changes the installed linter by one patch, and I compared its output on both trees — 111 findings on each, zero lines different in either direction. The subject is 90 characters, which puts the merge title at 97, three short of the limit. — Tree: 0d04acea3b7833c522eeefba105a913884fdbb02 — Head: 8520d49

Acceptance Criteria

  • [met] The four declared bumps are the ones installed, and no production dependency moves — Evidence: the versions read back from the lockfile after npm ci; hono and undici are at main's values, untouched by this branch — proof: the whole gate, which is the only proof a dependency bump has
  • [met] The linter bump changes nothing the linter says about this tree — Evidence: biome ci . on main's tree under 2.5.14 and on this tree under 2.5.15 report the same 111 findings, compared line by line with nothing unique to either. A linter bump that silently gained a rule is the hazard here, and this one did not
  • [not met] The gate is green — Evidence: exit 1, one failure, the same two stale plant anchors chore(deps-dev): bump the development-dependencies group with 3 updates #114 found. See the finding
  • [met] The head needs no merge — Evidence: main is an ancestor, so what I measured is what would land
  • [not verifiable] That the new test runner behaves identically for a reason the suite cannot see — Evidence: vitest moves 5.0.1 to 5.0.3, so the suite reporting this is the bumped runner reporting on itself. 1378 of 1379 pass and the one failure is explained by a version string rather than by the runner; CI re-runs the same runner independently

Findings

  • [blocking][reproduced] The same guard anchored to @types/node's exact declared version, on the branch that replaced chore(deps-dev): bump the development-dependencies group with 3 updates #114. tests/protections/majors.ts holds two node-26 plants whose find text is the literal "@types/node": "^26.6.2"; this branch writes ^26.6.3, so the guard reports both as rotten — find-absent: node-26 › package.json › the declared @types/node major drifts above the runtime and … the @types/node caret range is gone, so its major cannot be read. I measured two closures on chore(deps-dev): bump the development-dependencies group with 3 updates #114's tree and both turn the majors suite green at 15 of 15: replacing the anchors with ^26.6.3, which buys exactly one bump, and anchoring on the major rather than the patch (find: '"@types/node": "^26', replacing the 26), which still matches exactly once and which no future patch bump can break. The second is the one worth having. The guard is right and the anchor's shape is the defect, and the fix is not this branch's: dependabot rebases and force-pushes, so a repair carried here would not survive — it belongs on main as its own small change, after which this branch goes green on a branch update. The full reasoning is in the verdict on chore(deps-dev): bump the development-dependencies group with 3 updates #114 and is recorded as an input in the state repository.
  • [advisory][reproduced] biome.json still declares schema 2.3.0, biome says so on every run, and the gate does not care. Biome prints Expected: 2.5.15, Found: 2.3.0 against the $schema line and recommends biome migrate, and it reports a deprecated key at biome.json:21. Both are pre-existing on main and both are warnings: biome ci . exits 0 with them in the tree, so what holds the configuration current is a reader noticing the output of a green run. That is the same measurement as test(protections): read src/ through one type-checked program #112's noTsIgnore, one file over. Out of scope for a dependency branch and named rather than asked for, but the bump widens the gap it reports, so this is the moment it is visible.

Not Checked

  • The behaviour of the individual upstream patches. A bump's proof is the gate.
  • Whether the gate is green with the plant anchors repaired. I measured the majors suite green under both closures on chore(deps-dev): bump the development-dependencies group with 3 updates #114's tree, which carries the same @types/node bump, and no test depends on majors.ts; I did not re-run the whole gate with a fix in place, because the fix is not mine to write.
  • Whether a version newer than these four exists by now. Dependabot's schedule decides that, and bumping past what the PR declares would make the measurement not match the PR.
  • The 1378 passing tests one at a time.

Routed

  • The plant anchors in tests/protections/majors.ts have to stop naming a patch version, which blocks this branch and every future @types/node bump. — Landing zone: tests/protections/majors.ts, as its own small change on main; written up as .aos/input/2026-10-04-a-plant-anchored-to-a-patch-version-makes-every-bump-of-it-red.md, which is pre-gate and not yet an item. — Filing: outstanding

Generated by Claude Code

kschlt commented Oct 4, 2026

Copy link
Copy Markdown
Owner

PR Review Verdict

Result: PASS

Deterministic: Round two, delta-scoped: did the one blocking finding's closure hold, and did anything new appear at blocking severity. Measured on head ecd354a — tree 4ffa17c. That head is GitHub's merge of main d5c2888 into the Dependabot branch, so the head is the merge result and there is nothing left to merge; all 22 check runs are green on it. The blocker is closed, and closed on this tree rather than on the one that fixed it. Round one blocked at 8520d49 for exactly one failing test — protections/the-major-plants-still-describe-this-tree > every plant's text is still in its subject, exactly once, which reported both @types/node plants as find-absent because their anchors named the literal ^26.6.2 this pull request moves to ^26.6.3. #119 re-anchored them on the major and is now in this head through main. In a fresh worktree, npm ci first, npm run quality exits 0 against a real PostgreSQL 16 under Node 26.10.0: tsc --noEmit clean, biome ci . over 204 files with 5 warnings and 106 infos and no errors — byte-identical counts to main's own tree — and 94 files, 1379 passed / 4 skipped, which is main's number exactly. The lockfile merge was checked the only way that counts: npm ci after the merge validates the lock against package.json and exits 0, and all four declared bumps are the installed versions — @biomejs/biome 2.5.15, @types/node 26.6.3, tsx 4.23.15, vitest 5.0.3. The expensive half was run here too, on the declaration that caused the block: npm run majors -- node-26 is 10 killed, 0 survived, 0 inconclusive, 0 refused with ^26.6.3 declared, both @types/node mutations reported at every place that pins a Node version pins the same major. Subjects are 84 and 90 characters; the merge subject is Merge branch 'main' into dependabot/…, which the commits check exempts as a standard merge, and the merge title will land at 97. — Tree: 4ffa17cbe5fe0424a95dedc2e5b24a932a906edf — Head: ecd354a

Acceptance Criteria

  • [met] The one blocking finding is closed — Evidence: the test that failed at 8520d49 passes here, and it passes because the anchors moved rather than because the declaration did: "@types/node": "^26 matches ^26.6.3 exactly once. The gate is 1379 passed with no failures, against 1378 passed / 1 failed in round one — proof: protections/the-major-plants-still-describe-this-tree > every plant's text is still in its subject, exactly once
  • [met] The closure holds on this tree, not only on the tree that shipped it — Evidence: npm run majors -- node-26 run here, with ^26.6.3 as the declared range, kills all ten plants and names the resolved assertion for each. That is the question fix(majors): anchor the @types/node plants on the major, not the patch #119 could not answer about itself: it measured ^26.6.3 as a plant, this measures it as the tree's actual declaration
  • [met] Nothing new at blocking severity in the delta — Evidence: the delta over round one is the merge commit and nothing else; package.json and package-lock.json are the only files this branch touches, and the test counts, tsc result and biome diagnostic counts are identical to main's. The four bumps are development tooling only — no production dependency moved
  • [met] The lockfile is internally consistent after the merge — Evidence: npm ci exits 0 on the merged tree, which is the check that fails when a merged lock no longer satisfies package.json, and each of the four declared ranges resolves to the version it declares. A green suite over a stale node_modules would have said nothing about this
  • [met] The merge will not poison the commits check — Evidence: 84 and 90 characters, both under the 100-character limit the check reads over the whole origin/main..HEAD range, and the merge subject matches the standard-merge exemption. The merge title at 97 characters is inside the limit, with three to spare

Findings

  • [advisory][reasoned] This round's green says nothing about the two bumps whose libraries a guard walks, because neither moved far enough to matter. biome and vitest are both walked or driven by this repository's protections, and a guard that walks a library inherits its version — the shape that made the zod 4 bump dangerous. Here biome was already resolving to 2.5.14 under the old ^2.3.0 caret, so the declaration bump to ^2.5.15 moves the installed version by one patch, and vitest moves 5.0.1 to 5.0.3. Both are patches, and typescript — the one the source-parsing guards actually reflect over — is untouched at ^5.7.0. So the usual demand, prove the walkers still recognise something after the bump, is not owed here. Naming it because the next grouped bump may well carry a minor or a major of one of these, and then it is owed.

Not Checked

  • Each bumped package's own changelog. A development-dependency bump's proof is the gate, and the gate is green on the merge result with every declared version installed; reading four changelogs would not add a measurement.
  • Whether the 27 packages the lockfile moved transitively include anything that reaches production code. package.json's dependencies block is untouched, and the four moved names are all in devDependencies, which is as far as I took it.
  • The 1379 tests outside the one that blocked round one. The gate ran them green here and on main, at identical counts; I did not reason about them individually.
  • Anything about @types/pg, typescript and yaml, which this group left alone.

Routed

none


Generated by Claude Code

@kschlt
kschlt merged commit 59c4b13 into main Oct 4, 2026
22 checks passed
@kschlt
kschlt deleted the dependabot/npm_and_yarn/development-dependencies-f89e61a578 branch October 4, 2026 15:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant