Skip to content

chore(deps-dev): bump the development-dependencies group across 1 directory with 5 updates - #73

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/development-dependencies-8705a9f0b6
Closed

chore(deps-dev): bump the development-dependencies group across 1 directory with 5 updates#73
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/development-dependencies-8705a9f0b6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 29, 2026

Copy link
Copy Markdown
Contributor

Bumps the development-dependencies group with 5 updates in the / directory:

Package From To
@ast-grep/cli 0.44.1 0.45.1
dependency-cruiser 17.4.3 18.1.1
js-yaml 4.3.1 5.2.3
typescript 6.0.3 7.0.2
@types/node 25.9.5 26.2.0

Updates @ast-grep/cli from 0.44.1 to 0.45.1

Release notes

Sourced from @​ast-grep/cli's releases.

0.45.1

0.45.0

Changelog

Sourced from @​ast-grep/cli's changelog.

0.45.1

0.45.0

23 July 2026

Commits
  • dc3d655 0.45.1
  • 2ac18ca chore: bump deps
  • fa147e1 fix: match root metavariables against comments (#2868)
  • 20d880a feat(outline): add C# multiline member signatures (#2861)
  • 96c6792 chore(deps): update rust crate ignore to v0.4.32 (#2864)
  • cffbe33 chore(deps): update dependency oxlint to v1.77.0 (#2865)
  • ff97c38 chore(deps): update dependency typescript to v7 (#2833)
  • eaf94ff chore(deps): update astral-sh/setup-uv action to v9 (#2839)
  • d5c9d01 chore(deps): update dependency smol-toml to v1.7.1 (#2848)
  • c1f1af9 chore(deps): update dependency @​napi-rs/cli to v3.8.2 (#2854)
  • Additional commits viewable in compare view

Updates dependency-cruiser from 17.4.3 to 18.1.1

Release notes

Sourced from dependency-cruiser's releases.

v18.1.1

👷 maintenance

  • 1ee565bb/ 942cf969 build(npm): updates external dependencies
  • f0061d15 fix: removes all unused catch parameters
  • cbe062ae/ c0250f8d chore(tools): uses node permission model
  • 01c47439 fix(build): re-adds esbuild to the devDependencies
  • e57d9fc2 chore: replaces eslint with oxlint (#1074)

v18.1.0

✨ new functionality

  • 65c432cc feat: adds environment inconsistency checks (#1070) dependency-cruiser now also warns at runtime if it detects typescript is needed, but (a usable version of the) typescript compiler isn't present (+ the same for babel and swc). It already did so on --init. Thanks @​kbarendrecht for the suggestion!
  • 6bb22b6f feat(report/error-html): makes the table heads sticky

TypeScript 7 support: typescript@7.1.0 is expected to ship with a public API - so that's the first version in the TypeScript 7 (formerly tsgo) version range dependency-cruiser will be able to support.

👷 maintenance

  • f04f2fad build(npm): updates external dependencies

v18.0.0

🚨 breaking changes

  • 40f42e96 chore!: drops support for nodejs 20 and 25 BREAKING (#1060)

This is because we follow the Node.js release cycle who dropped support for version 20 and 25 (a while ago already).

🐛 fixes

  • a25fe7f7 fix(graph-utl): makes the summary more deterministic (#1066) - thanks @​Sebastian-G for raising the issue and providing the first feedback!

👷 maintenance

  • 92d6a1f9/ ee3dc3a9/ c9974443 build(npm): updates external dependencies
  • 0d8becbe refactor(config-utl): only imports json5 when it's used (#1062)
  • 793bd4d4 chore(ci): updates known violations
  • 41911765 chore: updates copilot instructions

v18.0.0-beta-2

🐛 fixes

  • 15e84477/ 878511d3 fix(graph-utl): makes the summary more deterministic (thanks to @​Sebastian-G for raising the well-documented issue!)

👷 maintenacne

  • ee3dc3a9/ 92d6a1f9 build(npm): updates external dependencies and refreshes package lock
  • 0d8becbe refactor(config-utl): only imports json5 when it's used (#1062)

... (truncated)

Commits
  • da355e4 18.1.1
  • c0250f8 chore(tools): makes the tools work again on node 22
  • 942cf96 build(npm): updates external dependencies
  • cbe062a chore(tools): uses node permission model
  • 01c4743 fix(build): re-adds esbuild to the devDependencies
  • e57d9fc chore: replaces eslint with oxlint (#1074)
  • f0061d1 fix: removes all unused catch parameters
  • 1ee565b build(npm): updates external dependencies
  • 26dffc0 18.1.0
  • f04f2fa build(npm): updates external dependencies
  • Additional commits viewable in compare view

Updates js-yaml from 4.3.1 to 5.2.3

Changelog

Sourced from js-yaml's changelog.

[5.2.3] - 2026-08-01

Fixed

  • Prevent prototype fallback when resolving tags and mapping entries, #782.
  • Resolve !!timestamp years 0000-0099 correctly, #775.
  • Preserve implicit null mapping values before document markers and reject unpaired mapping event streams, #784.
  • Preserve folded scalar values with tab-indented lines when round-tripping a parsed AST through present(); dump() and loading are unaffected, #780.

[5.2.2] - 2026-07-24

Fixed

  • Quote flow scalars where a colon precedes a flow indicator, #773.

Security

  • Avoid exponential parsing time for nested flow sequence pairs.

[5.2.1] - 2026-07-02

Fixed

  • Add Map support to !!omap (should work when realMapTag used)

Security

  • Remove quadratic complexity from !!omap addItem. Regression from v5 (usually not critical, because YAML11_SCHEMA is not default anymore).

4.3.0, 3.15.0 - 2026-06-27

Security

  • Backported maxTotalMergeKeys option.

[5.2.0] - 2026-06-26

Added

  • Added maxTotalMergeKeys (10000) loader option to limit the total number of keys processed by YAML merge (<<) across one load() / loadAll() call.
  • Added maxAliases (-1) loader option to limit the number of YAML aliases per document.

Removed

  • maxMergeSeqLength replaced with maxTotalMergeKeys for limiting YAML merge processing.

Fixed

  • Round-trip of integers with exponential form (>= 1e21)

[5.1.0] - 2026-06-23

... (truncated)

Commits
  • 6740445 5.2.3 released
  • 94e766d Update changelog
  • c3bd7ca Polish previous commit, #780
  • 00209b6 presenter: treat a tab-indented line in a folded scalar as more-indented (#780)
  • 40fcb4f Fix missing mapping values before document markers and reject unpaired mappin...
  • 49280f3 Fix !!timestamp resolution for years 0000-0099, #775
  • 355dc96 fix: prevent prototype fallback in tag and harden object lookups, #782 (than...
  • d524f83 docs: add contributing guidelines
  • 3c29559 5.2.2 released
  • 3e5240f parser: avoid reparsing flow sequence pair keys
  • Additional commits viewable in compare view

Updates typescript from 6.0.3 to 7.0.2

Commits
Maintainer changes

This version was pushed to npm by microsoft1es, a new releaser for typescript since your current version.


Updates @types/node from 25.9.5 to 26.2.0

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 29, 2026
@dependabot
dependabot Bot requested a review from heimanba as a code owner July 29, 2026 12:25
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 29, 2026
…ectory with 5 updates

Bumps the development-dependencies group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@ast-grep/cli](https://github.com/ast-grep/ast-grep) | `0.44.1` | `0.45.1` |
| [dependency-cruiser](https://github.com/sverweij/dependency-cruiser) | `17.4.3` | `18.1.1` |
| [js-yaml](https://github.com/nodeca/js-yaml) | `4.3.1` | `5.2.3` |
| [typescript](https://github.com/microsoft/TypeScript) | `6.0.3` | `7.0.2` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `25.9.5` | `26.2.0` |



Updates `@ast-grep/cli` from 0.44.1 to 0.45.1
- [Release notes](https://github.com/ast-grep/ast-grep/releases)
- [Changelog](https://github.com/ast-grep/ast-grep/blob/main/CHANGELOG.md)
- [Commits](ast-grep/ast-grep@0.44.1...0.45.1)

Updates `dependency-cruiser` from 17.4.3 to 18.1.1
- [Release notes](https://github.com/sverweij/dependency-cruiser/releases)
- [Changelog](https://github.com/sverweij/dependency-cruiser/blob/main/CHANGELOG.md)
- [Commits](sverweij/dependency-cruiser@v17.4.3...v18.1.1)

Updates `js-yaml` from 4.3.1 to 5.2.3
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.3.1...5.2.3)

Updates `typescript` from 6.0.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/commits)

Updates `@types/node` from 25.9.5 to 26.2.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@ast-grep/cli"
  dependency-version: 0.45.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.1.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: development-dependencies
- dependency-name: dependency-cruiser
  dependency-version: 18.1.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: development-dependencies
- dependency-name: js-yaml
  dependency-version: 5.2.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: development-dependencies
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: development-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps-dev): bump the development-dependencies group with 5 updates chore(deps-dev): bump the development-dependencies group across 1 directory with 5 updates Aug 12, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/development-dependencies-8705a9f0b6 branch from 6c0148d to d4f8d09 Compare August 12, 2026 03:25
@heimanba

Copy link
Copy Markdown
Contributor

Closing because this combines multiple ecosystem-wide semver-major upgrades without updating bun.lock. The branch cannot pass frozen-lockfile installation, and the TypeScript, Node types, architecture tooling, and YAML upgrades should be reviewed independently.

@heimanba heimanba closed this Aug 12, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 12, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/development-dependencies-8705a9f0b6 branch August 12, 2026 03:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant