Skip to content

chore(deps-dev): bump @stryker-mutator/core from 9.6.1 to 10.0.0 - #506

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/stryker-mutator/core-10.0.0
Closed

chore(deps-dev): bump @stryker-mutator/core from 9.6.1 to 10.0.0#506
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/stryker-mutator/core-10.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps @stryker-mutator/core from 9.6.1 to 10.0.0.

Release notes

Sourced from @​stryker-mutator/core's releases.

v10.0.0

10.0.0 (2026-08-14)

Bug Fixes

  • deps: update babel monorepo to v7.29.7 (#6068) (c10cb94)
  • deps: update dependency ajv to v8.20.0 (#5992) (0ead8ce)
  • deps: update dependency angular-html-parser to ~10.10.0 (#6069) (82f4e1f)
  • deps: update dependency angular-html-parser to ~10.11.0 (#6132) (81706f0)
  • deps: update dependency angular-html-parser to ~10.6.0 (#5962) (4a47b39)
  • deps: update dependency semver to v7.8.5 (#6075) (f66c2fc)
  • deps: update dependency weapon-regex to v2 (#6077) (b357f40)
  • deps: update mutation-testing-elements monorepo to v3.8.0 (#6095) (d62fd75)
  • deps: update mutation-testing-elements monorepo to v3.8.4 (#6118) (29ede69)
  • instrumenter: parse svelte template expressions as TS when file uses lang="ts" (#6024) (e81abcc)
  • mocha-runner: prefer project-mocha over bundled mocha (#6138) (e602725), closes #6127
  • vitest-runner: fix noisy vitest options & setup file warnings (#6098) (58c4b85)

Features

BREAKING CHANGES

  • node: Node.js 20 is no longer supported, please use Node.js 22 or higher.
Changelog

Sourced from @​stryker-mutator/core's changelog.

10.0.0 (2026-08-14)

Bug Fixes

  • deps: update dependency ajv to v8.20.0 (#5992) (0ead8ce)
  • deps: update mutation-testing-elements monorepo to v3.8.0 (#6095) (d62fd75)
  • deps: update mutation-testing-elements monorepo to v3.8.4 (#6118) (29ede69)

Features

  • babel: update babel to major version 8 (#6104) (291b7ea)
  • core: save partial incremental report on unexpected exit (#5986) (d091b1a)
  • empty-expression-mutator (#6012) (cc08738), closes #5765
  • node: drop support for Node.js 20, require Node.js 22 or higher (#6002) (425cb9f)

BREAKING CHANGES

  • node: Node.js 20 is no longer supported, please use Node.js 22 or higher.
Commits
  • cb3bd8f v10.0.0
  • aadfdc9 chore(deps): update typescript-eslint monorepo to v8.67.0 (#5984)
  • 51b9fa5 chore(deps): update dependency @​types/node to v24.13.3 (#6122)
  • 29ede69 fix(deps): update mutation-testing-elements monorepo to v3.8.4 (#6118)
  • 291b7ea feat(babel): update babel to major version 8 (#6104)
  • d62fd75 fix(deps): update mutation-testing-elements monorepo to v3.8.0 (#6095)
  • cc08738 feat: empty-expression-mutator (#6012)
  • 5deb03e chore(deps): update dependency @​types/node to v24.13.2 (#6058)
  • 0ead8ce fix(deps): update dependency ajv to v8.20.0 (#5992)
  • 6201b38 chore(deps): update dependency @​types/node to v24.12.4 (#6015)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@stryker-mutator/core](https://github.com/stryker-mutator/stryker-js/tree/HEAD/packages/core) from 9.6.1 to 10.0.0.
- [Release notes](https://github.com/stryker-mutator/stryker-js/releases)
- [Changelog](https://github.com/stryker-mutator/stryker-js/blob/master/packages/core/CHANGELOG.md)
- [Commits](https://github.com/stryker-mutator/stryker-js/commits/v10.0.0/packages/core)

---
updated-dependencies:
- dependency-name: "@stryker-mutator/core"
  dependency-version: 10.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 17, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 17, 2026 13:25
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 17, 2026
@clawsweeper

clawsweeper Bot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

@clawsweeper clawsweeper Bot added merge-risk: 🚨 compatibility 🚨 Merging this PR could break existing users, config, migrations, defaults, or upgrades. P2 Normal priority bug or improvement with limited blast radius. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. labels Aug 17, 2026
@clawsweeper

clawsweeper Bot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Codex review: found issues before merge. Reviewed August 17, 2026, 9:28 AM ET / 13:28 UTC.

ClawSweeper review

What this changes

This PR updates the development-only mutation-testing engine from version 9.6.1 to 10.0.0 and refreshes its resolved dependency graph.

Merge readiness

⚠️ Ready for maintainer review - 4 items remain

Keep open: the Stryker 10 resolution brings in Babel 8, whose declared Node support excludes part of acpx’s documented Node 22.13+ range; resolve that compatibility choice before merging.

Priority: P2
Reviewed head: dad95c7dfdd5bbf4ad1ea4e8f190cdb5d382dc62
Owner decision: Required. See Decision needed.

Review scores

Measure Result What it means
Overall readiness 🦐 gold shrimp (3/6) The update is focused, but the unresolved supported-Node mismatch prevents a merge-ready rating.
Proof confidence 🌊 off-meta tidepool Not applicable: This Dependabot development-tool update is exempt from contributor real-behavior proof; compatibility validation remains necessary before merge.
Patch quality 🦐 gold shrimp (3/6) 1 actionable review finding remain.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: This Dependabot development-tool update is exempt from contributor real-behavior proof; compatibility validation remains necessary before merge.
Evidence reviewed 6 items Mutation command uses the updated dependency: The repository invokes stryker run, so this direct development dependency is executed by the mutation-test workflow.
Declared runtime support conflicts with the resolved toolchain: acpx declares Node >=22.13.0, but the new lockfile resolves Babel 8 packages requiring ^22.18.0 or >=24.11.0.
Babel 8 is on Stryker’s active execution path: The Stryker 10 instrumenter depends directly on Babel core, generator, parser, and TypeScript preset packages.
Findings 1 actionable finding [P1] Preserve the supported Node 22.13–22.17 range
Security None None.

How this fits together

acpx runs Stryker as its mutation-testing tool during development and CI. The package manifest and pnpm lockfile select the toolchain that pnpm run mutate executes.

flowchart LR
  A[Developer or CI] --> B[Package manifest]
  B --> C[pnpm lockfile]
  C --> D[Stryker mutation tool]
  D --> E[Babel instrumenter]
  E --> F[Mutation test result]
Loading

Decision needed

Question Recommendation
Should acpx retain Node 22.13 as its supported development baseline, or intentionally raise the baseline to accommodate the Babel 8 toolchain required by Stryker 10? Retain the Node 22.13 baseline: Use a Stryker version and lockfile resolution whose complete dependency graph supports Node 22.13, then validate the mutation command there.

Why: The current manifest and repository policy promise Node >=22.13, while the newly locked transitive toolchain excludes part of that range; changing that promise is a maintainer compatibility-policy choice.

Before merge

  • Preserve the supported Node 22.13–22.17 range (P1) - pnpm run mutate executes Stryker, whose new instrumenter resolves Babel 8. The lockfile declares Babel 8 requires Node ^22.18.0 || >=24.11.0, while this repository declares >=22.13.0; developers on the documented 22.13–22.17 range would receive an unsupported toolchain. Retain a compatible Stryker resolution or intentionally raise and validate the project’s Node baseline before merging.
  • Resolve merge risk (P1) - Merging would leave developers using the documented Node 22.13–22.17 range with a mutation-test dependency graph outside its declared supported runtime range.
  • Complete next step (P2) - A maintainer must choose whether to preserve Node 22.13 developer support or raise it before this major toolchain upgrade proceeds.

Findings

  • [P1] Preserve the supported Node 22.13–22.17 range — package.json:90
Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Dependency surface 2 files affected; 1 manifest line changed and 801 lockfile lines refreshed A one-line major tool update materially replaces its transitive execution graph.
Node compatibility gap project >=22.13.0; locked Babel 8 ^22.18.0 || >=24.11.0 The resolved instrumenter no longer covers the repository’s stated minimum Node version.

Merge-risk options

Maintainer options:

  1. Preserve the documented Node baseline (recommended)
    Keep Node 22.13 support by selecting a compatible Stryker dependency graph and prove pnpm run mutate at that minimum before merge.
  2. Accept a newer Node baseline
    Raise the declared support floor only after a maintainer explicitly accepts the developer and CI compatibility change.

Technical review

Best possible solution:

Keep the documented Node 22.13 baseline by using a Stryker resolution compatible with it, or deliberately raise the project’s supported Node floor and validate clean install and mutation runs at the new minimum.

Do we have a high-confidence way to reproduce the issue?

Unclear: source proves the Node-engine contract mismatch, but confirming the exact install or runtime failure requires a clean run on Node 22.13–22.17.

Is this the best way to solve the issue?

No. The update is reasonable, but this resolution is not the best path while acpx promises Node >=22.13; preserve that support or make a deliberate, validated runtime-policy change.

Full review comments:

  • [P1] Preserve the supported Node 22.13–22.17 range — package.json:90
    pnpm run mutate executes Stryker, whose new instrumenter resolves Babel 8. The lockfile declares Babel 8 requires Node ^22.18.0 || >=24.11.0, while this repository declares >=22.13.0; developers on the documented 22.13–22.17 range would receive an unsupported toolchain. Retain a compatible Stryker resolution or intentionally raise and validate the project’s Node baseline before merging.
    Confidence: 0.95

Overall correctness: patch is incorrect
Overall confidence: 0.95

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning high; reviewed against 026544cd7550.

Labels

Label changes:

  • add P2: This is a bounded compatibility problem in development and CI tooling, not a shipped runtime outage.
  • add merge-risk: 🚨 compatibility: The new direct development-tool graph excludes part of the repository’s documented Node 22 support range.
  • add rating: 🦐 gold shrimp: Overall readiness is 🦐 gold shrimp; proof is 🌊 off-meta tidepool and patch quality is 🦐 gold shrimp.
  • add status: ⏳ waiting on author: ClawSweeper has contributor-facing work open and is waiting for author action. Not applicable: This Dependabot development-tool update is exempt from contributor real-behavior proof; compatibility validation remains necessary before merge.

Label justifications:

  • P2: This is a bounded compatibility problem in development and CI tooling, not a shipped runtime outage.
  • merge-risk: 🚨 compatibility: The new direct development-tool graph excludes part of the repository’s documented Node 22 support range.
  • rating: 🦐 gold shrimp: Overall readiness is 🦐 gold shrimp; proof is 🌊 off-meta tidepool and patch quality is 🦐 gold shrimp.
  • status: ⏳ waiting on author: ClawSweeper has contributor-facing work open and is waiting for author action. Not applicable: This Dependabot development-tool update is exempt from contributor real-behavior proof; compatibility validation remains necessary before merge.

Evidence

What I checked:

  • Mutation command uses the updated dependency: The repository invokes stryker run, so this direct development dependency is executed by the mutation-test workflow. (package.json:62, dad95c7dfdd5)
  • Declared runtime support conflicts with the resolved toolchain: acpx declares Node >=22.13.0, but the new lockfile resolves Babel 8 packages requiring ^22.18.0 or >=24.11.0. (pnpm-lock.yaml:125, dad95c7dfdd5)
  • Babel 8 is on Stryker’s active execution path: The Stryker 10 instrumenter depends directly on Babel core, generator, parser, and TypeScript preset packages. (pnpm-lock.yaml:3760, dad95c7dfdd5)
  • CI does not cover the documented minimum patch release: The mutation job selects Node 22 with check-latest, so it validates the current Node 22 release rather than the documented 22.13 minimum. (.github/workflows/ci.yml:115, dad95c7dfdd5)
  • Feature-history provenance: The available local history identifies the current main parent as commit 026544c; shallow/promisor history did not expose an earlier specific owner for the mutation-tool configuration. (package.json:90, 026544cd7550)
  • Structured review attempt: The repository autoreview helper could not construct a safe commit bundle because the shallow checkout treated the commit as a 4.2 MB root diff; the focused source review above used the exact two-file PR diff instead. (dad95c7dfdd5)

Likely related people:

  • Peter Steinberger: Current main is based on Peter Steinberger’s latest commit; the available history did not reveal a more specific owner for the mutation-tool configuration. (role: recent repository contributor; confidence: low; commits: 026544cd7550; files: package.json, .github/workflows/ci.yml, pnpm-lock.yaml)

Rank-up moves

Optional improvements that raise the rating; they are not merge blockers.

  • Choose whether to preserve Node 22.13 support or raise the project baseline.
  • Validate pnpm install --frozen-lockfile and pnpm run mutate at the selected minimum Node version.

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@steipete

Copy link
Copy Markdown
Contributor

Superseded by #515, which lands the dependency refresh as one coherent branch (avoids lockfile cascades) with build + smoke proof.

@steipete steipete closed this Aug 23, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 23, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/stryker-mutator/core-10.0.0 branch August 23, 2026 16:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code merge-risk: 🚨 compatibility 🚨 Merging this PR could break existing users, config, migrations, defaults, or upgrades. P2 Normal priority bug or improvement with limited blast radius. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant