Skip to content

deps: update tree-sitter-language-pack requirement from <1.14,>=1.13.3 to >=1.13.3,<1.15 - #101

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/tree-sitter-language-pack-gte-1.13.3-and-lt-1.15
Open

deps: update tree-sitter-language-pack requirement from <1.14,>=1.13.3 to >=1.13.3,<1.15#101
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/tree-sitter-language-pack-gte-1.13.3-and-lt-1.15

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown

Updates the requirements on tree-sitter-language-pack to permit the latest version.

Release notes

Sourced from tree-sitter-language-pack's releases.

v1.14.0

Added

  • Add 65 tree-sitter grammars, raising coverage from 306 to 371. New languages include Slint, MoonBit, Aiken, Koka, Koto, Unison, Leo, Motoko, Eiffel, Picat, Cython, Ballerina, SAS, D2, Vala, and Fluent, alongside DSL/schema/query grammars (YANG, FlatBuffers, Avro, Cypher, SpiceDB, Kusto, PostgreSQL, T-SQL, WDL, SysML, and the Salesforce SOQL/SOSL/debug-log family), templating grammars (HAML, Slim, Vento, rsHTML), and systems/config grammars (m68k, scfg, kitty, jjdescription, bpftrace, strace, SystemTap, TRACE32). Seven permissively-licensed but unmaintained grammars are vendored in-repo (ABNF, PlantUML, Promela, Reason, Wolfram, XQuery, Yul), and just is re-sourced to the canonical casey/tree-sitter-just.
  • Detect kitty (kitty.conf), rsHTML (.rs.html), and dotenv (.env) files by name.
  • The core library emits tracing spans and events always-on across parsing, grammar loading, and download operations, making observability a first-class product surface. tracing is now a non-optional dependency (near-zero cost without a subscriber). Levels follow the shared contract: INFO for coarse state changes (download/init/prefetch/clean, network bundle fetch), DEBUG for per-call flow (process, get_language, grammar shared-library loads). Span names and field keys are part of the public API.

Changed

  • The ts-pack CLI installs a tracing subscriber for every command (previously only the MCP server did), so RUST_LOG surfaces library diagnostics on stderr for all subcommands; machine- readable result output on stdout is unchanged. tracing/tracing-subscriber are no longer gated behind the mcp feature.
  • Raw println!/eprintln!/print!/eprint!/dbg! are denied in production code across the workspace (clippy print_stdout/print_stderr/dbg_macro); tracing is the sole diagnostic surface. The ts-pack CLI's command results and prompts remain its stdout/stderr output contract (opted in crate-wide), while the MCP command's diagnostics continue through tracing.
  • Regenerate all language bindings on alef 0.49.0.
Changelog

Sourced from tree-sitter-language-pack's changelog.

[1.14.0] - 2026-08-01

Added

  • Add 65 tree-sitter grammars, raising coverage from 306 to 371. New languages include Slint, MoonBit, Aiken, Koka, Koto, Unison, Leo, Motoko, Eiffel, Picat, Cython, Ballerina, SAS, D2, Vala, and Fluent, alongside DSL/schema/query grammars (YANG, FlatBuffers, Avro, Cypher, SpiceDB, Kusto, PostgreSQL, T-SQL, WDL, SysML, and the Salesforce SOQL/SOSL/debug-log family), templating grammars (HAML, Slim, Vento, rsHTML), and systems/config grammars (m68k, scfg, kitty, jjdescription, bpftrace, strace, SystemTap, TRACE32). Seven permissively-licensed but unmaintained grammars are vendored in-repo (ABNF, PlantUML, Promela, Reason, Wolfram, XQuery, Yul), and just is re-sourced to the canonical casey/tree-sitter-just.
  • Detect kitty (kitty.conf), rsHTML (.rs.html), and dotenv (.env) files by name.
  • The core library emits tracing spans and events always-on across parsing, grammar loading, and download operations, making observability a first-class product surface. tracing is now a non-optional dependency (near-zero cost without a subscriber). Levels follow the shared contract: INFO for coarse state changes (download/init/prefetch/clean, network bundle fetch), DEBUG for per-call flow (process, get_language, grammar shared-library loads). Span names and field keys are part of the public API.

Changed

  • The ts-pack CLI installs a tracing subscriber for every command (previously only the MCP server did), so RUST_LOG surfaces library diagnostics on stderr for all subcommands; machine- readable result output on stdout is unchanged. tracing/tracing-subscriber are no longer gated behind the mcp feature.
  • Raw println!/eprintln!/print!/eprint!/dbg! are denied in production code across the workspace (clippy print_stdout/print_stderr/dbg_macro); tracing is the sole diagnostic surface. The ts-pack CLI's command results and prompts remain its stdout/stderr output contract (opted in crate-wide), while the MCP command's diagnostics continue through tracing.
  • Regenerate all language bindings on alef 0.49.0.

[1.13.5] - 2026-07-27

Changed

  • Regenerate all language bindings on alef 0.48.4, which fixes the Java publish (lowered the Maven enforcer floor) and the C# publish (generates runtime.json.template so runtime.json can be rendered before the NuGet pack).
  • Update grammar revisions to latest upstream (gnuplot, javadoc, scala, tmux).
  • Upgrade Rust dependencies to their latest incompatible versions (base64 0.22 -> 0.23).

Fixed

  • ci: render runtime.json from its template before packing the NuGet package so C# runtime metadata is published correctly.

[1.13.4] - 2026-07-26

Changed

... (truncated)

Commits
  • 1706d6b chore(swift): update Package.swift with checksum for v1.14.0
  • a2867fa fix(e2e/php): sync composer.lock to the guzzle ^7.0 constraint
  • 62df374 fix(ci): unblock plugin, swift, and validate jobs
  • 1040d0d fix(build): link macro-based external scanners under static linking
  • 9af9509 chore(release): 1.14.0
  • 3717251 chore: regenerate bindings, docs, and e2e for 371 languages
  • aed41a3 feat(grammars): add 65 tree-sitter grammars (306 → 371)
  • c94acf6 docs: mention cargo binstall as a CLI install option
  • 1c78520 ci: name CLI assets by target triple and verify cargo-binstall
  • e0781d6 feat(cli): add cargo-binstall metadata
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [tree-sitter-language-pack](https://github.com/xberg-io/tree-sitter-language-pack) to permit the latest version.
- [Release notes](https://github.com/xberg-io/tree-sitter-language-pack/releases)
- [Changelog](https://github.com/xberg-io/tree-sitter-language-pack/blob/main/CHANGELOG.md)
- [Commits](xberg-io/tree-sitter-language-pack@v1.13.3...v1.14.0)

---
updated-dependencies:
- dependency-name: tree-sitter-language-pack
  dependency-version: 1.14.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 10, 2026
@dependabot
dependabot Bot requested a review from Cranot as a code owner August 10, 2026 10:35
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 10, 2026
@github-actions

Copy link
Copy Markdown

roam-code Analysis

Mode: incremental (changed-only) — base 0f86518b8f59a9c9b8e0017d4987228184162c7f, 1 changed+dependent files

Health Score: 76/100 FAIR

health: Fair codebase (76/100) — 66 critical, 0 warnings, focus: god_components
pr-risk: Moderate risk (30/100) — review recommended (risk_level medium) (driver: test_coverage_low)

Health Metrics

Metric Value
Health Score 76/100
Tangle Ratio 0.7%
Propagation Cost 0.0404
Total Issues 66

PR Risk

Metric Value
Risk Score 30/100

Quality Gate: PASSED

Gate expression: health_score>=50

SARIF Upload

Metric Value
Category roam-code-self-analysis/self-analysis/py3.12
Results Uploaded 116
Full analysis output

health

{
  "_meta": {
    "cache_ttl_s": 300,
    "cacheable": true,
    "index_age_s": 5,
    "index_status": {
      "dirty_files": 0,
      "fresh": false,
      "head_commit": "db23d8b9be48",
      "hint": "index latest commit 24b837452ad9 != HEAD db23d8b9be48 — git-derived metrics (commits, churn, co-change, weather) may be stale. Run `roam index --force`.",
      "indexed_commit": "24b837452ad9"
    },
    "latency_ms": null,
    "response_tokens": 6878,
    "roam_version": "14.0.0",
    "timestamp": "2026-08-10T10:38:59Z"
  },
  "actionable_count": 18,
  "actionable_cycles": 1,
  "agent_contract": {
    "confidence": null,
    "facts": [
      "Fair codebase (76/100) — 66 critical, 0 warnings, focus: god_components",
      "health score 76",
      "tangle ratio 0.7",
      "0.0404 propagation cost findings",
      "issue count 66"
    ],
    "next_commands": [
      "roam debt",
      "roam trends --days 30"
    ],
    "risks": []
  },
  "algebraic_connectivity": null,
  "algebraic_connectivity_available": false,
  "bottleneck_thresholds": {
    "list_limit": 15,
    "p70": 38562.7,
    "p90": 177188.4,
    "population": 3341,
    "utility_multiplier": 1.5
  },
  "category_severity": {
    "bottlenecks": {
      "critical": 15,
      "info": 0,
      "warning": 0
    },
    "cycles": {
      "critical": 1,
      "info": 0,
      "warning": 0
    },
    "god_components": {
      "critical": 50,
      "info": 0,
      "warning": 0
    },
    "layer_violations": {
      "critical": 0,
      "info": 0,
      "warning": 0
    }
  },
  "command": "health",
  "cycles_actionable": 1,
  "cycles_total": 51,
  "framework_filtered": 0,
  "god_component_thresholds": {
    "list_limit": 50,
    "min_degree": 20,
    "population": 616
  },
  "health_score": 76,
  "ignored_cycles": 50,
  "imported_coverable_lines": 0,
  "imported_coverage_files": 0,
  "imported_coverage_pct": null,
  "imported_covered_lines": 0,
  "index_status": {
    "dirty_files": 0,
    "fresh": false,
    "head_commit": "db23d8b9be48",
    "hint": "index latest commit 24b837452ad9 != HEAD db23d8b9be48 — git-derived metrics (commits, churn, co-change, weather) may be stale. Run `roam index --force`.",
    "indexed_commit": "24b837452ad9"
  },
  "issue_count": 66,
  "list_counts": {
    "bottlenecks": 15,
    "cycle_break_suggestions": 1,
    "cycles": 51,
    "god_components": 50,
    "layer_violations": 0,
    "next_steps": 2,
    "score_breakdown": 5
  },
  "project": "roam-code",
  "propagation_cost": 0.0404,
  "schema": "roam-envelope-v1",
  "schema_version": "1.2.0",
  "severity": {
    "critical": 66,
    "info": 50,
    "warning": 0
  },
  "summary": {
    "actionable_cycles": 1,
    "algebraic_connectivity": null,
    "algebraic_connectivity_available": false,
    "category_severity": {
      "bottlenecks": {
        "critical": 15,
        "info": 0,
        "warning": 0
      },
      "cycles": {
        "critical": 1,
        "info": 0,
        "warning": 0
      },
      "god_components": {
        "critical": 50,
        "info": 0,
        "warning": 0
      },
      "layer_violations": {
        "critical": 0,
        "info": 0,
        "warning": 0
      }
    },
    "cycles_actionable": 1,
    "cycles_definition": "Cycle counts derived from `roam.graph.cycles.find_cycles(G, min_size=2)` on the symbol graph. `cycles_total` = all SCCs of size >= 2; `cycles_actionable` = SCCs spanning >=2 files AND no test files (same-file and test-only cycles are informational). Run `roam health` for the per-cycle breakdown.",
    "cycles_total": 51,
    "detail_available": true,
    "god_components": 50,
    "god_components_definition": "God components: symbols where `(in_degree + out_degree) > 20` from the `graph_metrics` table, with utility-aware severity bands (standard >50=CRITICAL >30=WARNING; utility >150=CRITICAL >90=WARNING). Run `roam health` for the per-symbol breakdown. Legacy aliases: `god_objects` (fingerprint), `god_classes` (rules).",
    "health_score": 76,
    "health_score_definition": "weighted geometric mean (0-100) of 5 sigmoid health factors: tangle_ratio, god_components, bottlenecks, layer_violations, file_health (+coverage if available); computed by roam.quality.health_score.compute_health_score, shared verbatim with the `snapshots` writer so `roam health --baseline` compares like with like.",
    "ignored_cycles": 50,
    "imported_coverage_files": 0,
    "imported_coverage_pct": null,
    "issue_count": 66,
    "partial_success": true,
    "preserved_list_truncations": {},
    "propagation_cost": 0.0404,
    "severity": {
      "critical": 66,
      "info": 50,
      "warning": 0
    },
    "tangle_ratio": 0.7,
    "tangle_ratio_definition": "percent of symbols inside non-trivial SCCs (size >= 2), counting ALL such SCCs, not just actionable ones; higher = more cyclic coupling. `roam fingerprint` reports the identical measurement as a fraction (percent / 100).",
    "total_cycles": 51,
    "truncated": true,
    "truncation_reason": "detail_mode",
    "verdict": "Fair codebase (76/100) — 66 critical, 0 warnings, focus: god_components",
    "warnings_out": [
      "health_algebraic_connectivity_warning:RuntimeWarning:algebraic_connectivity compute failed (ModuleNotFoundError): No module named 'numpy'; returning 0.0 sentinel — value is NOT a legitimate disconnected-graph reading",
      "health_god_components_list_capped:showing_top_50_of_616",
      "health_bottlenecks_list_capped:showing_top_15_of_3341"
    ]
  },
  "tangle_ratio": 0.7,
  "total_cycles": 51,
  "utility_count": 32,
  "version": "14.0.0",
  "warnings_out": [
    "health_algebraic_connectivity_warning:RuntimeWarning:algebraic_connectivity compute failed (ModuleNotFoundError): No module named 'numpy'; returning 0.0 sentinel — value is NOT a legitimate disconnected-graph reading",
    "health_god_components_list_capped:showing_top_50_of_616",
    "health_bottlenecks_list_capped:showing_top_15_of_3341"
  ]
}

pr-risk

{
  "_meta": {
    "cache_ttl_s": 60,
    "cacheable": true,
    "index_age_s": 7,
    "index_status": {
      "dirty_files": 0,
      "fresh": false,
      "head_commit": "db23d8b9be48",
      "hint": "index latest commit 24b837452ad9 != HEAD db23d8b9be48 — git-derived metrics (commits, churn, co-change, weather) may be stale. Run `roam index --force`.",
      "indexed_commit": "24b837452ad9"
    },
    "latency_ms": null,
    "response_tokens": 872,
    "roam_version": "14.0.0",
    "timestamp": "2026-08-10T10:39:01Z"
  },
  "actor": null,
  "agent_contract": {
    "confidence": null,
    "facts": [
      "Moderate risk (30/100) — review recommended (risk_level medium) (driver: test_coverage_low)",
      "risk score 30",
      "2 risk rank findings",
      "1 changed files",
      "1 lines added"
    ],
    "next_commands": [],
    "risks": [
      "pr-risk: moderate (30/100) on 0f86518b8f59a9c9b8e0017d4987228184162c7f..HEAD — driver: test_coverage_low"
    ]
  },
  "author": null,
  "blast_radius_pct": 0,
  "bus_factor_risk": 0,
  "change_shape": "mixed",
  "changed_files": 1,
  "closest_historical_pattern": null,
  "closest_similarity": 0,
  "cluster_spread": 0,
  "clusters_touched": 0,
  "command": "pr-risk",
  "coupling_score": 0,
  "dead_code": [],
  "dead_exports": 0,
  "familiarity": {
    "avg_familiarity": 1,
    "files": [],
    "files_assessed": 0
  },
  "findings": [
    {
      "claim": "pr-risk: moderate (30/100) on 0f86518b8f59a9c9b8e0017d4987228184162c7f..HEAD — driver: test_coverage_low",
      "confidence": "heuristic",
      "evidence": {
        "actor": null,
        "author": null,
        "blast_radius_pct": 0,
        "bus_factor_risk": 0,
        "changed_files_count": 1,
        "commit_range": "0f86518b8f59a9c9b8e0017d4987228184162c7f..HEAD",
        "coupling_score": 0,
        "created_at_epoch": 1786358341,
        "diff_id": "f18c14e9ff0a",
        "familiarity_risk": 0,
        "file_list": [
          "pyproject.toml"
        ],
        "hotspot_score": 0,
        "label": "0f86518b8f59a9c9b8e0017d4987228184162c7f..HEAD",
        "lines_added": 1,
        "lines_removed": 1,
        "minor_risk": 0,
        "novelty_score": 0,
        "reductive_change": false,
        "risk_level": "moderate",
        "risk_score": 30,
        "staged": false,
        "test_coverage_pct": 0,
        "top_driver": "test_coverage_low"
      },
      "finding_id_str": "pr-risk:composite-risk-score:f18c14e9ff0a",
      "kind": "pr-risk:composite-risk-score",
      "severity": "medium",
      "source_detector": "pr-risk",
      "source_version": "1.0.0",
      "subject_id": null,
      "subject_kind": "commit"
    }
  ],
  "hotspot_score": 0,
  "label": "0f86518b8f59a9c9b8e0017d4987228184162c7f..HEAD",
  "layer_spread": 0,
  "layers_touched": 0,
  "lines_added": 1,
  "lines_removed": 1,
  "minor_risk": {
    "files": [],
    "files_assessed": 0,
    "minor_files": 0
  },
  "novelty_score": 0,
  "per_file": [
    {
      "blast": 0,
      "churn": 642,
      "is_test": false,
      "lines_added": 1,
      "lines_removed": 1,
      "path": "pyproject.toml",
      "symbols": 0
    }
  ],
  "project": "roam-code",
  "reductive_change": false,
  "reductive_discount_applied": false,
  "risk_level": "moderate",
  "risk_level_canonical": "medium",
  "risk_rank": 2,
  "risk_score": 30,
  "schema": "roam-envelope-v1",
  "schema_version": "1.2.0",
  "suggested_reviewers": [
    {
      "actor": "Cranot",
      "author": "Cranot",
      "lines": 448
    },
    {
      "actor": "t",
      "author": "t",
      "lines": 15
    },
    {
      "actor": "dependabot[bot]",
      "author": "dependabot[bot]",
      "lines": 1
    }
  ],
  "summary": {
    "change_shape": "mixed",
    "changed_files": 1,
    "findings_count": 1,
    "lines_added": 1,
    "lines_removed": 1,
    "partial_success": false,
    "risk_level": "moderate",
    "risk_level_canonical": "medium",
    "risk_rank": 2,
    "risk_score": 30,
    "score_classification": "classified",
    "verdict": "Moderate risk (30/100) — review recommended (risk_level medium) (driver: test_coverage_low)"
  },
  "test_coverage_pct": 0,
  "total_clusters": 11313,
  "total_layers": 45,
  "version": "14.0.0",
  "warnings_out": []
}

roam-code analysis | Commands: health pr-risk

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants