Skip to content

Comments

[Deps] Safe dependency updates (2026-02-25)#1027

Draft
github-actions[bot] wants to merge 1 commit intomainfrom
deps/safe-patch-updates-2026-02-25-b34d775438401bd0
Draft

[Deps] Safe dependency updates (2026-02-25)#1027
github-actions[bot] wants to merge 1 commit intomainfrom
deps/safe-patch-updates-2026-02-25-b34d775438401bd0

Conversation

@github-actions
Copy link
Contributor

Automated Safe Dependency Updates

This PR contains safe patch-level dependency updates verified to pass all existing tests.

Updated Dependencies

Package Previous Updated Type
@commitlint/cli 20.4.1 20.4.2 patch
@commitlint/config-conventional 20.4.1 20.4.2 patch
@types/node 25.2.3 25.3.0 minor
@typescript-eslint/eslint-plugin 8.55.0 8.56.1 patch
@typescript-eslint/parser 8.55.0 8.56.1 patch
eslint 10.0.0 10.0.2 patch
glob 13.0.1 13.0.6 patch
typescript-eslint 8.55.0 8.56.1 patch

Security Fixes Included

No HIGH/CRITICAL vulnerabilities were found. One MODERATE vulnerability (ajv ReDoS, GHSA-2g4f-4pwh-qvx6) was identified in a transitive dev dependency — not directly fixable without major version bumps.

Skipped Updates (Major Version Changes)

The following packages have newer major versions with breaking changes and were excluded:

  • chalk: 4.x → 5.x (ESM-only breaking change)
  • commander: 12.x → 14.x (major)
  • eslint-plugin-security: 3.x → 4.x (major)
  • execa: 5.x → 9.x (major)

Verification

  • All tests pass (792 passing, 3 pre-existing failures unrelated to these updates)
  • No breaking changes detected
  • All updates are within existing semver ranges in package.json

Generated by Dependency Security Monitor Workflow

AI generated by Dependency Security Monitor

Updated packages (all within semver ranges):
- @commitlint/cli: 20.4.1 -> 20.4.2
- @commitlint/config-conventional: 20.4.1 -> 20.4.2
- @types/node: 25.2.3 -> 25.3.0
- @typescript-eslint/eslint-plugin: 8.55.0 -> 8.56.1
- @typescript-eslint/parser: 8.55.0 -> 8.56.1
- eslint: 10.0.0 -> 10.0.2
- glob: 13.0.1 -> 13.0.6
- typescript-eslint: 8.55.0 -> 8.56.1

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions github-actions bot added automated dependencies Pull requests that update a dependency file labels Feb 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants