Skip to content

chore(deps-dev): bump the tooling-minor-patch group across 1 directory with 6 updates - #363

Merged
hetaoBackend merged 1 commit into
mainfrom
dependabot/npm_and_yarn/tooling-minor-patch-989e67a36b
Oct 4, 2026
Merged

hetaoBackend merged 1 commit into
mainfrom
dependabot/npm_and_yarn/tooling-minor-patch-989e67a36b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the tooling-minor-patch group with 6 updates in the / directory:

Package From To
prettier 3.9.6 3.9.9
tsx 4.23.13 4.23.15
eslint-plugin-prettier 5.5.5 5.5.6
dependency-cruiser 18.3.1 18.4.0
jscpd 5.2.1 5.3.3
knip 6.35.1 6.38.0

Updates prettier from 3.9.6 to 3.9.9

Release notes

Sourced from prettier's releases.

3.9.9

  • Markdown: Fix text with $ been incorrectly parsed as math syntax (#20140 by @​fisker)

🔗 Changelog

3.9.8

  • Markdown: Don't let Liquid objects interrupt paragraphs (#20087 by @​seiyab)

🔗 Changelog

3.9.7

  • Support Angular 22.2
  • Fix regressions in v3.9

🔗 Changelog

Changelog

Sourced from prettier's changelog.

3.9.9

diff

Markdown: Fix text with $ been incorrectly parsed as math syntax (#20140 by @​fisker)

<!-- Input -->
**Uses $FOO** from `a.sh` and `b.sh`, plus `$BAR` from `c.sh`, before anything else runs here.
<!-- Prettier 3.9.8 -->
Uses $FOO from a.sh and b.sh, plus $BARfromc.sh, before anything else runs here.
<!-- Prettier 3.9.9 -->
Uses $FOO from a.sh and b.sh, plus $BAR from c.sh, before anything else runs here.

3.9.8

diff

Markdown: Don't let Liquid objects interrupt paragraphs (#20087 by @​seiyab)

<!-- Input -->
If `module` is not a [`WebAssembly.Module`](https://github.com/prettier/prettier/blob/main/en-US/docs/WebAssembly/Reference/JavaScript_interface/Module) object instance, a
{{jsxref("TypeError")}} is thrown.
<!-- Prettier 3.9.7 -->
If module is not a WebAssembly.Module object instance, a
{{jsxref("TypeError")}} is thrown.
<!-- Prettier 3.9.8 -->
If module is not a WebAssembly.Module object instance, a
{{jsxref("TypeError")}} is thrown.

3.9.7

diff

Markdown: Prevent indentation drift in list-item code blocks (#19647, #19990 by @​Austin1serb, @​giaBaoJS)

<!-- Input -->
- [x] short first line.
</tr></table> 

... (truncated)

Commits

Updates tsx from 4.23.13 to 4.23.15

Release notes

Sourced from tsx's releases.

v4.23.15

4.23.15 (2026-09-20)

Bug Fixes

  • exclude bare builtins from namespace inheritance (38e1588)
  • expose require.cache and require.extensions to tsImport CommonJS modules (2da3407)
  • make namespaced register() overloads portable for declaration emit (562c434)

This release is also available on:

v4.23.14

4.23.14 (2026-09-20)

Bug Fixes

  • restore the CJS bridge namespace for Node 24 require(esm) under tsImport() (#802) (6e5236b)

This release is also available on:

Commits
  • ca66105 test: fix drive-less file URLs in ESM resolver fixtures
  • 2da3407 fix: expose require.cache and require.extensions to tsImport CommonJS modules
  • 38e1588 fix: exclude bare builtins from namespace inheritance
  • 562c434 fix: make namespaced register() overloads portable for declaration emit
  • edfb1f0 build: upgrade pkgroll and externalize CJS loader reference
  • 70e7828 test: upgrade tinyspy for disposable API
  • 9ed2022 ci: avoid duplicate release notifications
  • 872e77f refactor: use disposables for cleanup
  • 6e5236b fix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...
  • See full diff in compare view

Updates eslint-plugin-prettier from 5.5.5 to 5.5.6

Release notes

Sourced from eslint-plugin-prettier's releases.

v5.5.6

Patch Changes

Changelog

Sourced from eslint-plugin-prettier's changelog.

5.5.6

Patch Changes

Commits

Updates dependency-cruiser from 18.3.1 to 18.4.0

Release notes

Sourced from dependency-cruiser's releases.

v18.4.0

✨ features

To improve visibility of the state of the baseline (.dependency-cruiser-known-violations.json)...

  • ...the err, err-html and markdown reporters now show the number of stale entries in the baseline. (c617e580/ e9ad4ce6/ be91a27c/ 993ac9df)
  • ... the err, null, azure-devops and teamcity reporters can exit with a non-zero exit code when the baseline contains stale entries (set baseline.staleEntriesSeverity to error to enable).
    (#1100 / 0dbd7610)
  • ... the new baseline-mode 'format' sorts the baseline so future diffs are easier to read after manual edits. (077d4431/ 3e465ea1)

Thanks to @​yunusdim and @​BPScott for the raising the issues and providing the suggestions and feedback that birthed these 🙇.

📖 documentation

  • e41450b9 doc(cli): adds note to --baseline that severities are ignored on comparison

👷 maintenance

  • 9f402bbb/ ab42c712 chore(npm): updates all external devDependencies
  • c9d8fb5d chore(npm): adds upem policy to prevent accidents when @​types/node publishes a super-old version as 'latest'
Commits
  • 7c22858 18.4.0
  • 9f402bb chore(npm): updates all external devDependencies
  • 993ac9d feat(report/markdown): adds baseline stale count (#1101)
  • c9d8fb5 chore(npm): adds upem policy to prevent accidents when @​types/node publishes ...
  • 0dbd761 feat: adds option to make stale entries in the baseline a non-zero-exit-code ...
  • be91a27 feat(report/err-html): adds baseline stale count and table (#1099)
  • e9ad4ce feat(report/err): adds stale baseline count (#1098)
  • c617e58 feat(analyze): adds baseline stats to the summary (#1097)
  • 3e465ea feat(baseline): renames baseline-mode 'view' to 'format' & sorts the baseline...
  • 077d443 feat(baseline): adds dry-run ('view') mode (#1096)
  • Additional commits viewable in compare view

Updates jscpd from 5.2.1 to 5.3.3

Release notes

Sourced from jscpd's releases.

Release v5.3.3

New Features

  • Semantic clones, experimental: --semantic. The token passes match runs of tokens, so they miss two functions that do the same job with different code. Such a function may be renamed and restructured, or written in another language, like a validation rule that a Rust backend enforces and a Svelte frontend repeats (Type-4 clones). --semantic (config key semantic) embeds every function with a code embedding model and reports the pairs whose vectors point the same way as clones of kind semantic.
    • jscpd embeds the functions of JavaScript, TypeScript, JSX, TSX, Vue, Svelte, Astro, Python, Rust, Go, Java, Kotlin, C#, C, C++, PHP, Ruby, Scala and Swift files that clear --min-tokens and --min-lines. It embeds each function's code without comments, starting at the name the function is declared under.
    • Two functions pair only if they are in different files, neither calls the other, and the clones already found do not cover both. Each must be the other's closest match among the functions of its language; a function that is only close to the best match needs a higher similarity. The cosine must reach --semantic-threshold for a pair across languages, or --semantic-same-threshold for a pair within one language (0.4125 and 0.6375 with the default model), and it must stand at least 3 standard deviations above each function's background. --semantic-scope same keeps the pairs within one language, and --semantic-scope cross keeps the pairs across languages.
    • The default model, CodeRankEmbed (MIT), runs inside jscpd on the CPU once jscpd --semantic-download has fetched it (548 MB, pinned by revision and SHA-256), and a scan makes no network call. In a comparison of nine open models, it found more known clones than jina-embeddings-v2-base-code at the same precision, and reviewers judged more of its pairs to be duplicates. jscpd also runs jina-embeddings-v2-base-code, which is faster: jscpd --semantic-download jina-embeddings-v2-base-code fetches it (324 MB), and --semantic-model jina-embeddings-v2-base-code scans with it.
    • --semantic-url sends the functions to an OpenAI-compatible embeddings API instead, such as Ollama, llama.cpp, text-embeddings-inference or a hosted API. jscpd reads the API key only from JSCPD_SEMANTIC_API_KEY, and sends it only to a URL given on the command line or to a server on this machine. A config file can neither hold a key nor send code to another host on its own.
    • jscpd caches the vectors, so a repeat run embeds only the functions whose code changed. Each set of scanned paths has its own cache file. Once the vectors of changed and deleted functions make up more than a quarter of that file, the next run that embeds something rewrites it without them. --semantic-rebuild-cache embeds everything again and replaces the file at once.
    • Each model scores similarity on its own scale, so each model gets its own thresholds. jscpd --semantic-models lists the nine models jscpd has calibrated, with their thresholds, licenses and where they run. --semantic-model takes any of them by the name in that list (CodeRankEmbed), by Hugging Face id or by Ollama name, and the thresholds follow the model. The rule for groups of copies has two more settings, tuned with jina-embeddings-v2-base-code: a near-best margin of 0.05 and a floor of 0.8. jscpd scales both for every other model by the model's gap between its two thresholds, which gives 0.075 and 0.7125 for CodeRankEmbed. Qwen3-Embedding-0.6B and jina-code-embeddings-0.5b expect an instruction before the text, and jscpd puts the one they were calibrated with before every function; the config key prefix replaces it. A model that jscpd has not calibrated gets 0.6 and 0.75, and the run warns about it.
    • The console prints Clone found (rust, semantic ~0.78), -r ai prints [~0.78 semantic], JSON carries "kind": "semantic" and similarity, and SARIF uses the rule jscpd/semantic-code. --kind semantic keeps only these clones. The code lives in a new crate, cpd-semantic, and a run without --semantic works as before.
    • fixtures/semantic-demo is a runnable example: a Rust API and a SvelteKit frontend with 8 rules written on both sides and 2 features written twice in one language. (#1101, #1103, #1105, #1108, #1110)

Bug Fixes

  • A scan path inside another scanned its files twice. With jscpd . src, or a config file that lists src next to src/generated, jscpd walked every file under the inner path once for each path and reported each of those files as a clone of itself. --semantic embedded their functions twice and paired each one with itself. Version 4 read those files once, and so does jscpd now, as it already did with --follow-symlinks. See fixtures/nested-paths-demo. (#1106)

  • Svelte components lost two kinds of use to --dead-code. Svelte reads a store as $name, in the script and in the markup, and that is often the only use that import { page } from '$app/stores' gets, so --dead-code reported the import as unused with 100% confidence. It also reported a name as an unused symbol when the markup read it only inside the ${…} of a template literal, as in href={(p) => `/?${base}&page=${p}`}, because the markup scan skipped template literals the way it skips plain strings. $name now counts as a read of name (runes such as $state and $props, and $$props, do not), and jscpd reads the placeholders of a template literal as code in every component format. On two SvelteKit apps, sshx and the RealWorld example, the six and three findings of basta 0.3.0 were all of these two kinds, and neither app has a finding now. See fixtures/dead-code-demo. (#1102)

  • Positions in files with Windows line endings drifted. The generic tokenizer, which reads Python, Go, Java, C# and most other formats, moved one byte forward per line where a CRLF line ends in two bytes, so every position was short by the number of lines above it. The position values in the JSON report were off, and an --ignore-pattern match removed tokens a byte behind per line, which changed the token counts of the clones around it. Files with CRLF endings now report true byte offsets, and where a pattern applies, their clones can count different tokens than before. Files with LF endings are unaffected. See fixtures/crlf-demo. (#1101)

Dependencies

  • paste is gone from the build. The crate is unmaintained (RUSTSEC-2024-0436), and candle's matrix kernels, pulp and tokenizers still depend on it. The workspace now patches it with a small local crate that hands its one macro to pastey, its maintained successor, so cargo audit and cargo deny pass without an ignore for the advisory. The patch goes away once those crates release their switch to pastey. sha2 moved to 0.11, and every other dependency to its latest compatible release. (#1107, #1109)
  • oxc moved to 0.151 and ruff to 0.0.15, each as one family of crates (#1098), and clap to 4.6.7 (#1097).

Deprecations

  • --min-duplicated-lines never did anything, and now says so. Since the first 5.x release, the docs described it as a minimum percentage of duplication to report, but no code ever read it: a scan with --min-duplicated-lines 100 found the same clones as one without it. jscpd now hides the flag from --help and prints a warning when it is passed, and a later release will remove it. The flag is still accepted, so a script that passes it keeps working. To fail a run on too much duplication, use --threshold; to set the smallest clone worth reporting, use --min-lines or --min-tokens. (#1100)

Published Packages

  • basta@0.3.0 on crates.io
  • cpd-core@0.1.19 on crates.io
  • cpd-finder@0.1.19 on crates.io
  • cpd-reporter@0.1.20 on crates.io
  • cpd-tokenizer@0.1.18 on crates.io
  • cpd@5.3.3 on npm
  • jscpd@5.3.3 on npm
  • jscpd-darwin-arm64@5.3.3 on npm
  • jscpd-darwin-x64@5.3.3 on npm
  • jscpd-linux-x64-gnu@5.3.3 on npm
  • jscpd-linux-arm64-gnu@5.3.3 on npm
  • jscpd-linux-x64-musl@5.3.3 on npm
  • jscpd-linux-arm64-musl@5.3.3 on npm
  • jscpd-windows-x64-msvc@5.3.3 on npm
  • jscpd-windows-arm64-msvc@5.3.3 on npm
  • jscpd==5.3.3 on PyPI

... (truncated)

Commits

Updates knip from 6.35.1 to 6.38.0

Release notes

Sourced from knip's releases.

Release 6.38.0

  • Include co-authors in docs contributor list (0c334100df59d89a512ad598ec50e7f62f6da0c3)
  • Filter bots and agents from docs contributors (617f70d8179c6b8668ca41fe5df77ced5e2b37c0)
  • Update Eve plugin conventions (#2049) (260dbb91a85f3a3bc2727e8f255d73df3737552c) - thanks @​matchai!
  • Add args example to that doc page (50b271b98fc930a05a3b045a2f691486f9f06528)
  • Add Turborepo plugin (#2055) (e49d3db05f1d69ce7db3efcb8467a4af63c27379) - thanks @​changbaebang!
  • Support import-x/* settings in ESLint plugin (#2050) (1a34cf82a3d6a1202717ef910bedba55838e9dd9) - thanks @​bytedoe!
  • Resolve file option in Mocha configuration files (#2051) (9b5c5f60468c8a92a3e74adca5c0931f008677af) - thanks @​giaBaoJS!
  • Support oxlint extends (#2054) (a149a98219bb14b15f446fc5f8c4f815e28b2183) - thanks @​matthewnitschke-wk!
  • Fix import.meta handling in built-in compilers (#2059) (8b0c85076bf3dce15ef5f3c0c4e58bfefdf59ded) - thanks @​vdavid!
  • Fix tag hints for enum and namespace members (#2061) (8a8805e48945863248429d18b7f6c4e4b7dc9ebd) - thanks @​devYRPauli!
  • Flag unused member tags in tagged enums and namespaces (584e53ff3e0846fbfe04fa5b5bfefe2420576a34)
  • feat: resolve MDX content mapper remarkPlugins (#2060) (34dbccf25359f9e9fefe9d0be6ef2ec0252223cc) - thanks @​gioboa!
  • Refactor and separate concerns w/ new typescript-content-mapper plugin (11e94509bd0f350d747facf4003fc5b248d1b02d)
  • Resolve mdx content mapper providerImportSource (7b5825117f97f2f87b7141509a254f88d0957cf7)
  • Fix config → entry in plop plugin (25a380c9e1165b76583d69b48b5fa7cdf5db0ae2)

Release 6.37.0

  • fix(graphql-codegen): mark near-operation-file outputs as entries, not the documents directory (#2048) (06a68fcf99a90e559daeb0b8fb2d24e173124774) - thanks @​RobHannay!
  • fix: enable JSX in the config loader (#1959) (5b21dc9192f773613d1c5db8edf35f0a68820268) - thanks @​addielaruee!
  • Match binaries only to their actual dependency providers (c5bdb69ccbcb7e1056233f346d0ada3495d1013d)
  • Preserve executable references across package manager commands (54af171638db22f5d903faae05c37c2ea6adc869)
  • Correct binary provider metadata in Relay fixtures (e67dfcb96d055c27be9c8601e077656855bb632b)
  • Separate shell binary expectations from reporting exemptions (resolve #2022) (c1d7d75a3529d9faff7f4c0df11dd0ca1bdfb149)
  • Respect npx no-install flags before the executable (4237010c9a834eb8b04f4a528c76d10a5c38ee98)
  • Update dependencies (038ea179f7d6bf7ca43bc5daf553a68b13a9067c)
  • Remove npm auth check now that's in release-it (4aaf77c58004ac64063a1982b98e53107c2ebe93)
  • Fix --format name resolution in the ESLint plugin (#2046) (1269e98bb700384811fadc124d69ea720832037e) - thanks @​bytedoe!

Release 6.36.0

  • Add @​tailwindcss/webpack as Tailwind plugin enabler (#2027) (b5ac0cf734dda3c6c6c51c817981dfc558b7c582) - thanks @​igas!
  • Fix Next.js Turbopack loader dependencies (23419b4edfd48796dd484fa880e1bad49a043d2e)
  • Explain ambiguous star exports in traces (#2025) (3c2c1a53f9c2b7ff3057a4e46761791979e0b09c) - thanks @​gioboa!
  • Fix eslintrc parserOptions.parser handling in ESLint plugin (#2028) (c79463cec81d09518eda325ec00e6f12327dea8d) - thanks @​bytedoe!
  • fix(compilers): require word boundary around import keyword (#2029) (68bbe51c39b564022b63942bc83cb570778cca00) - thanks @​thanadolps!
  • fix: recover from corrupt cache file (#2034) (30ff7568c84e0a6731ca634a52314228d23d1a2b) - thanks @​gioboa!
  • fix: fix trailing comma on dependency removal (#2033) (adfaf4f78878b6d55b0939a92d70a1fbb0ae1240) - thanks @​gioboa!
  • Document built-in compiler scope (a05e155276dad4ead16992580d17572cebf045e7)
  • Add babel, khan and oxc to projects and optimize svgs (1c26560b98bc3109e93d15761d02f089213bfb6c)
  • Add section to test preview packages & extension (d911c18385f0aa41f53653a2a15cc90a1e0251b8)
  • Fix shared info/exclude handling in linked Git worktrees (#2037) (c1f18d5a7d25fc5a614747bbcbd62d043457eb48) - thanks @​kenfdev!
  • Shard Node specs on Windows and enable Bun test parallelism (66e966b6edec4460b40b05847fefa9f90ee69068)
  • Add Varlock plugin support (#2000) (e4fbf46acff08e78370e72b142e795bd81f28561) - thanks @​Joehoel!
  • Apply NODE_OPTIONS inputs to package manager binaries (#2038) (c8df8a28e9a19484efe7097f984abc0c6556aff5) - thanks @​giaBaoJS!
  • Handle array form of import/resolver setting in ESLint plugin (#2041) (a80d386a80fdafc89c610d4887ec82184ac178db) - thanks @​bytedoe!
  • fix(node): add valueless Node CLI flags to boolean options (#2042) (4c6768501f7115a894d7ece9e5c32090b684cc6f) - thanks @​shoutoutuoadi325!
  • fix(typedoc): accept string form of plugin and theme options (#2043) (ce387b05c8f136546e860ec73e29557563c63afa) - thanks @​giaBaoJS!
  • Add textlint plugin (#2039) (532dab595fc9a910e320418dc0390222fb2d7478) - thanks @​anandghegde!
  • fix: Correctly resolve Vitest setupFiles from nested configs (#2040) (84a494334e125d229dc865893b21d69d0d201e85) - thanks @​CruseCtrl!
  • Add n8n to projects (3f756a7e70c4164d57a7dbbd58f3604afe4043e2)

... (truncated)

Commits
  • c0e42f8 Release knip@6.38.0
  • 25a380c Fix config → entry in plop plugin
  • 7b58251 Resolve mdx content mapper providerImportSource
  • 11e9450 Refactor and separate concerns w/ new typescript-content-mapper plugin
  • 34dbccf feat: resolve MDX content mapper remarkPlugins (#2060)
  • 584e53f Flag unused member tags in tagged enums and namespaces
  • 8a8805e Fix tag hints for enum and namespace members (#2061)
  • 8b0c850 Fix import.meta handling in built-in compilers (#2059)
  • a149a98 Support oxlint extends (#2054)
  • 9b5c5f6 Resolve file option in Mocha configuration files (#2051)
  • Additional commits viewable in compare view


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 25, 2026
@dependabot
dependabot Bot requested a review from hetaoBackend as a code owner September 25, 2026 12:27
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 25, 2026
…y with 6 updates

Bumps the tooling-minor-patch group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.9` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.13` | `4.23.15` |
| [eslint-plugin-prettier](https://github.com/prettier/eslint-plugin-prettier) | `5.5.5` | `5.5.6` |
| [dependency-cruiser](https://github.com/sverweij/dependency-cruiser) | `18.3.1` | `18.4.0` |
| [jscpd](https://github.com/kucherenko/jscpd/tree/HEAD/rust/jscpd) | `5.2.1` | `5.3.3` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.35.1` | `6.38.0` |



Updates `prettier` from 3.9.6 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.6...3.9.9)

Updates `tsx` from 4.23.13 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.13...v4.23.15)

Updates `eslint-plugin-prettier` from 5.5.5 to 5.5.6
- [Release notes](https://github.com/prettier/eslint-plugin-prettier/releases)
- [Changelog](https://github.com/prettier/eslint-plugin-prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/eslint-plugin-prettier@v5.5.5...v5.5.6)

Updates `dependency-cruiser` from 18.3.1 to 18.4.0
- [Release notes](https://github.com/sverweij/dependency-cruiser/releases)
- [Changelog](https://github.com/sverweij/dependency-cruiser/blob/main/CHANGELOG.md)
- [Commits](sverweij/dependency-cruiser@v18.3.1...v18.4.0)

Updates `jscpd` from 5.2.1 to 5.3.3
- [Release notes](https://github.com/kucherenko/jscpd/releases)
- [Commits](https://github.com/kucherenko/jscpd/commits/v5.3.3/rust/jscpd)

Updates `knip` from 6.35.1 to 6.38.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.38.0/packages/knip)

---
updated-dependencies:
- dependency-name: dependency-cruiser
  dependency-version: 18.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: tooling-minor-patch
- dependency-name: eslint-plugin-prettier
  dependency-version: 5.5.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: tooling-minor-patch
- dependency-name: jscpd
  dependency-version: 5.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: tooling-minor-patch
- dependency-name: knip
  dependency-version: 6.37.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: tooling-minor-patch
- dependency-name: prettier
  dependency-version: 3.9.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: tooling-minor-patch
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: tooling-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps-dev): bump the tooling-minor-patch group with 6 updates chore(deps-dev): bump the tooling-minor-patch group across 1 directory with 6 updates Oct 2, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/tooling-minor-patch-989e67a36b branch from 085df3a to c5521b9 Compare October 2, 2026 12:28
@hetaoBackend
hetaoBackend merged commit 7ea1c8c into main Oct 4, 2026
20 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/tooling-minor-patch-989e67a36b branch October 4, 2026 11:56
tournierjc pushed a commit to tournierjc/kinetick-code that referenced this pull request Oct 4, 2026
…I#363 (prettier 3.9.9, tsx 4.23.15, eslint-plugin-prettier 5.5.6, knip 6.38)
tournierjc added a commit to tournierjc/kinetick-code that referenced this pull request Oct 4, 2026
…iniMax-AI#428 timeouts de requête modèle, MiniMax-AI#363 bumps deps) (#111)

* fix: remove forced branching from bash guidance (MiniMax-AI#358)

Co-authored-by: minimax <adhere@minimaxi.com>

* feat: sync reviewed 0.5.5 runtime improvements (MiniMax-AI#367)

Preserve public privacy defaults and distribution boundaries while porting compaction, Bash timeout, memory output and update-proxy improvements. Record selective provenance without advancing the full source baseline.

Assisted-by: codex-cli reason:public-source-sync-0.5.5

* docs: publish feedback and private security contact channels (MiniMax-AI#360)

* docs: publish feedback and private security contact channels

* docs: correct MiniMax Agent X contact link

* fix(tui): distinguish Bash recaps and import models during onboarding (MiniMax-AI#369)

* fix: measure token speed over model generation time (MiniMax-AI#373)

* chore: bump version to 0.5.6 (MiniMax-AI#374)

* feat(config): add M3.1 Flash Preview to the fallback catalog (MiniMax-AI#375)

Include context window and effort controls in the first-run catalog while preserving existing managed snapshots.

Docs-Impact: Existing model selection workflow is unchanged.

Assisted-by: codex-cli reason:m31-flash-fallback-sync

* chore: bump version to 0.5.7 (MiniMax-AI#377)

* chore: bump version to 0.5.7

* test: drain stderr before nonzero Bash fixture exit

* fix(tui): display hook system messages without adding model context (MiniMax-AI#376)

* fix(tui): anchor restored sessions above inherited terminal history (MiniMax-AI#378)

* fix(tui): keep slow terminal output off the input loop (MiniMax-AI#379)

* chore: bump version to 0.5.8 (MiniMax-AI#380)

* feat: cascade explicit session stops to owned background work (MiniMax-AI#381)

Port the reviewed shared runtime behavior while retaining standalone composition. Keep conversation leave separate from explicit stop, suppress canceled task delivery, and track append activations through teardown.


Assisted-by: codex-cli reason:selective-runtime-port
Docs-Impact: document stop and session-leave behavior in docs/tui-capabilities.md

Co-authored-by: chenhao <chenhao@minimaxi.com>

* fix: query structured Windows source volume properties (MiniMax-AI#383)

* feat(examples): add Pocket Pet demo and refresh README onboarding (MiniMax-AI#385)

* feat(examples): add reproducible Pocket Pet demo and refresh onboarding

* feat(examples): polish Pocket Pet interaction and demo

* fix(tui): dismiss stale terminal errors when a new turn starts (MiniMax-AI#388)

* fix(tui): preserve native scrollback during automatic updates (MiniMax-AI#389)

* fix(tui): preserve native scrollback during projection updates

* fix(tui): isolate transient overlays from native scrollback

* fix(tui): stabilize native history and diff overlay frames (MiniMax-AI#390)

* fix(tui): prevent idle transcript replay and diff overlay frames

* fix(tui): retain prompt identity and deferred main-buffer geometry

* test: pin the srt-macos probe PATH and scale the BYOK serial timeout budget (MiniMax-AI#397)

* test(sandbox): pin the probe PATH instead of inheriting the ambient one

The real sandbox-exec probes resolve their command through PATH, so
inheriting the caller's let any wrapper ahead of /bin decide what `rm`
means. On a machine that has run the agent, that is the recoverable-delete
shim MCode installs into agent shells: `rm` resolves to the shim, the shim
execs mavis-trash, the sandbox denies that trash move as a write outside
the policy under test, and a correct allow-probe exits 1. The suite then
reports a sandbox regression where the sandbox behaved correctly.

Pin all three probe environments to the system binaries the probes
actually use, matching the wrapper-argument test above them. This also
drops the unguarded `process.env.PATH` in wrapProfile, which had no
fallback and could hand a real sandbox spawn an undefined PATH.

Fixes MiniMax-AI#394.

* test(byok): scale the serial BYOK budget by platform

The first case is 30+ serial CLI spawns, each booting the whole runtime,
so its wall-clock cost tracks machine speed rather than the transport it
asserts. The flat 90s budget only held with roughly 1.5x headroom on an
idle machine, so a parallel build, a laptop under load, or a shared CI
runner turned a passing transport into a `testTimeoutFailure` that named a
product failure no assertion had actually observed.

Budget it the way smoke.test.mjs already budgets runtime startup: a base
allowance plus a Windows multiplier for slower process spawn. The test is
not slowed down by a larger ceiling; it only stops failing for reasons
unrelated to what it checks.

Fixes MiniMax-AI#395.

* feat: sync MiniMax Code 0.5.9 runtime and TUI changes (MiniMax-AI#398)

TUI
- Report active root-session background tasks as `background=N` in the
  `[V]` build-mode status line. Bash still owned by its foreground tool
  call is excluded, and the count holds at 1 after a turn settles until a
  fresh task list arrives. The documented minimum width is now 102 columns.

Runtime
- The MiniMax API-key route now shares the official model catalog with the
  managed route; the first-run catalog moves to `minimax-model-catalog.ts`
  with unchanged model definitions.
- Apply byte limits to large media and accumulated history for BYOK requests.
- Send the M3 thinking toggle as a thinking setting rather than a generic
  reasoning effort.
- Allow edit and rewind after an interrupt that left only a background
  reminder in canonical history.
- Read less data when listing session files and navigating long histories.
- Measure token output rate from the time events are observed.
- Add `worktreeRefreshBeforeCreate` (default on) to fetch the selected
  upstream before creating a worktree, and exclude nested roots from fork
  worktree fingerprints.
- Add Ghostty to the external editor catalog.
- Enable the Codex OAuth model settings entry by default.

Prompts
- Cron guidance now lives only in tool definitions; the legacy feature
  template is empty. Memory edits use the `memory` tool's `edit` operation.
- Clarify multimodal tool discovery in the mcode-tools reminder.

* chore: release MiniMax Code 0.5.9 (MiniMax-AI#399)

* Revert MiniMax-AI#390 and MiniMax-AI#389 to restore TUI scrollback baseline (MiniMax-AI#396)

* Revert "fix(tui): stabilize native history and diff overlay frames (MiniMax-AI#390)"

This reverts commit 1e136bf.

* Revert "fix(tui): preserve native scrollback during automatic updates (MiniMax-AI#389)"

This reverts commit 9b9c07b.

* fix(tui): sync 0.5.10 prompt and run recovery fixes (MiniMax-AI#410)

* chore: release MiniMax Code 0.5.10 (MiniMax-AI#411)

* fix: include hidden thinking in TPS timing (MiniMax-AI#413)

* fix: include hidden thinking in TPS timing

* docs: note thinking_start in first token timing comment

* test(windows): allow the NTFS source check to exceed the default timeout

---------

Co-authored-by: hetaoBackend <hetao7@pku.edu.cn>

* fix: omit empty tools from OpenAI compaction requests (MiniMax-AI#199)

* fix: omit empty tools on OpenAI compaction requests

* fix: negotiate missing tools with bounded compatibility recovery

* fix: simplify empty tools handling to omit absent definitions

* fix(tui): keep regular-mode history stable during live runs (MiniMax-AI#416)

Regular mode wrote rows into native scrollback as soon as they scrolled
off screen. When such a row later changed (a parallel tool finishing, a
streamed table widening, a list turning loose, a turn growing past the
projection fold, the welcome status badge flipping, or a stopped prompt
gaining its cancelled marker), the renderer cleared scrollback and
replayed the whole session from the welcome logo.

Only final rows now reach native history:

- The transcript reports how many leading rows later updates cannot
  change, including the committed blocks of a streaming Markdown reply.
- The chat layout keeps rows that may still change within one screen
  above the footer, showing their latest rows under a one-line notice
  when they do not fit.
- The regular-mode projection only appends; established turns are not
  re-folded or dropped.
- The welcome banner above a conversation is static; account notices
  that need action appear above the Composer.
- Stopping a run no longer marks its delivered prompt as cancelled; the
  marker stays reserved for prompts returned to the Composer.

To keep long sessions responsive, the transcript drops final rows far
above the screen and the engine rebases its retained state
(takeDiscardedRows) instead of rewriting history.

* feat: sync and release MiniMax Code 0.6.0 (MiniMax-AI#421)

Port the reviewed 0.6.0 runtime and TUI behavior into the standalone
distribution and bump the release version to 0.6.0.

- Allow /retry inside a /btw side conversation to resend its last message.
- Default to MiniMax-M3.1-Flash-Preview when no model has been selected.
- After an accepted Goal completion, keep the Turn open for one final reply
  that summarizes the result and deliverables; blocked proposals still end
  the Turn.
- Do not retry provider safety refusals, including on BYOK, and classify
  them as content_filter; keep Anthropic refusal details in the error.
- Retry TLS record verification failures before output like other
  transient network errors.
- Keep a post-compaction reminder at the tail of a continuation instead of
  aborting the provider call and recompacting on every retry.

* feat: sync and release MiniMax Code 0.6.1 (MiniMax-AI#422)

Allow /doctor and /feedback in a /btw side conversation so a failed side
response can be diagnosed or reported without leaving it. Neither command
mutates the parent or side Session. /quit stays blocked in the side view,
because leaving from there aborts only the side Turn and skips side
Session cleanup.

Bump the root and TUI source versions to 0.6.1.

* fix(tui): keep side-session Esc and main run timer consistent (MiniMax-AI#423)

In a /btw side conversation, an empty Escape no longer arms the
double-Escape /edit shortcut or shows its "Press Esc again to edit"
hint, since /edit is unavailable in side conversations. Escape still
interrupts a live side response.

Switching between the side and main views re-adopted the main Session's
live Turn at the switch time, which reset the Running/Loading timer and
shortened the settled Turn duration. A Turn start ledger now records the
earliest observed start (submission, session.start events including
hidden Sessions, and adoption), and both re-adoption and the activity
line use it.

Bump the root and TUI source versions to 0.6.2.

* chore(deps-dev): bump the tooling-minor-patch group across 1 directory with 6 updates (MiniMax-AI#363)

Bumps the tooling-minor-patch group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.9` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.13` | `4.23.15` |
| [eslint-plugin-prettier](https://github.com/prettier/eslint-plugin-prettier) | `5.5.5` | `5.5.6` |
| [dependency-cruiser](https://github.com/sverweij/dependency-cruiser) | `18.3.1` | `18.4.0` |
| [jscpd](https://github.com/kucherenko/jscpd/tree/HEAD/rust/jscpd) | `5.2.1` | `5.3.3` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.35.1` | `6.38.0` |



Updates `prettier` from 3.9.6 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.6...3.9.9)

Updates `tsx` from 4.23.13 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.13...v4.23.15)

Updates `eslint-plugin-prettier` from 5.5.5 to 5.5.6
- [Release notes](https://github.com/prettier/eslint-plugin-prettier/releases)
- [Changelog](https://github.com/prettier/eslint-plugin-prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/eslint-plugin-prettier@v5.5.5...v5.5.6)

Updates `dependency-cruiser` from 18.3.1 to 18.4.0
- [Release notes](https://github.com/sverweij/dependency-cruiser/releases)
- [Changelog](https://github.com/sverweij/dependency-cruiser/blob/main/CHANGELOG.md)
- [Commits](sverweij/dependency-cruiser@v18.3.1...v18.4.0)

Updates `jscpd` from 5.2.1 to 5.3.3
- [Release notes](https://github.com/kucherenko/jscpd/releases)
- [Commits](https://github.com/kucherenko/jscpd/commits/v5.3.3/rust/jscpd)

Updates `knip` from 6.35.1 to 6.38.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.38.0/packages/knip)

---
updated-dependencies:
- dependency-name: dependency-cruiser
  dependency-version: 18.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: tooling-minor-patch
- dependency-name: eslint-plugin-prettier
  dependency-version: 5.5.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: tooling-minor-patch
- dependency-name: jscpd
  dependency-version: 5.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: tooling-minor-patch
- dependency-name: knip
  dependency-version: 6.37.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: tooling-minor-patch
- dependency-name: prettier
  dependency-version: 3.9.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: tooling-minor-patch
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: tooling-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(agent-core): bound hung model requests with first-event and idle timeouts (MiniMax-AI#428)

* fix: bound hung model requests so the retry path runs (MiniMax-AI#425)

A provider that accepts a request but never sends a response held the
turn for the transport default (undici headers timeout, ~300 s) before
the existing retry path ran. During that window the TUI showed Loading,
queued follow-ups, and /retry and /goal clear appeared to do nothing.

- agent-core: wrap every physical model request (each withLLMRetry
  attempt, agent and compaction scopes) in a stream watchdog. No first
  event within 120 s, or no event for 300 s after the first, aborts the
  attempt and ends the stream with a retryable "LLM request timed out"
  error (stopReason "error", not "aborted"), so BYOK and managed
  providers retry it. Caller aborts pass through unchanged. Bounds are
  configurable via LLMModelConfig.firstEventTimeoutMs /
  streamIdleTimeoutMs or MCODE_LLM_FIRST_EVENT_TIMEOUT_MS /
  MCODE_LLM_STREAM_IDLE_TIMEOUT_MS (0 disables).
- tui: /retry during a live run now says "Stop the running turn before
  using /retry." instead of "There is no failed response to retry";
  /goal clear and /goal pause during a live run say the current response
  keeps running and that Esc interrupts it.
- Tests: never-responding fake provider and real HTTP server that
  accepts but never answers; the attempt fails within the bound, retries
  and recovers, a fully hung turn fails and the next turn on the same
  runner completes. Document the bounds in docs/tui-capabilities.md.

* fix: keep prior first-response wait and stop reading abandoned streams (MiniMax-AI#425)

Review follow-up for the model request timeouts:

- Default the first-event bound to 300 s, matching undici's headers
  timeout that was the effective previous wait, so no request that used
  to succeed now times out. The idle bound stays at 300 s.
- Timeout errors name the setting that fired
  (MCODE_LLM_FIRST_EVENT_TIMEOUT_MS or MCODE_LLM_STREAM_IDLE_TIMEOUT_MS,
  or the host's per-model firstEventTimeoutMs/streamIdleTimeoutMs).
- When a bound fires, the wrapper stops waiting on the inner stream even
  if the provider ignores the abort: the pending read races a stop
  signal, and the inner iterator is released without being awaited.

Refs MiniMax-AI#425

---------

Co-authored-by: Tao He <hetaoBackend@users.noreply.github.com>

* fix(tui): defer rebuild after output-driven layout shrink (MiniMax-AI#429)

* fix(tui): keep scrolled-up readers in place on output-driven redraws (MiniMax-AI#426)

The regular-mode history reconstruction (L034) clears scrollback with
ED 3 and replays the document. xterm.js keeps its scrolled state while
the scrollback is rebuilt, so a reader who had scrolled up was moved to
line 0 whenever a resize settled (for example a fit addon reacting to a
layout change) or a transient layout shrank while a reply streamed.

Output-driven reconstructions now wait for the next user input, when
terminals scroll back to the bottom:

- TuiBase reports key and paste input through a protected onUserInput()
  hook; focus, size, mode and kitty-flag reports and key releases do not
  count.
- A settled resize replays history only if input arrived after the
  resize notification; otherwise it finishes as an in-place viewport
  redraw and the replay is deferred.
- A shrink in an unknown or changed layout pads like L038 unless input
  arrived within the last second (input-driven closes still restore
  rows immediately), and the replay is deferred.
- The next input after the deferral, or stop(), runs the deferred
  replay, so native history ends up exact and unique as before.

Changed historical text and size changes without a resize notification
still reconstruct immediately. Recorded as L047 in LOCAL_CHANGES.

* fix(tui): limit scroll preservation to output-driven layout shrink (MiniMax-AI#426)

Review follow-up:

- Resize again replays history as soon as it settles, as on main. The
  resize deferral is split out until the reporter's fit/resize behaviour
  is known; only the output-driven layout-shrink deferral remains (pad
  with blank rows, reconstruct on the next user input, immediately
  within one second of input).
- User input detection splits each chunk into control sequences instead
  of matching the whole chunk. Cursor position reports, OSC/DCS/APC
  strings and SGR mouse reports join focus, window, device and mode
  reports and key releases as non-input, and a key or paste that shares
  a chunk with reports still counts.
- Tests cover a tailing reader when output ends and the task list
  collapses, recent input reconstructing immediately, resize keeping its
  replay, each report kind, report-only and mixed chunks, and the replay
  before stop. L047 is updated accordingly.

Refs MiniMax-AI#426

---------

Co-authored-by: Tao He <hetaoBackend@users.noreply.github.com>

* fix(engine): replay main takeDiscardedRows rebase on tui-main-screen + types union seam

* chore(inventory): register upstream MiniMax-AI#428 timeout sources

* fix(deps): align dev-dep manifests with upstream lock after MiniMax-AI#363 (prettier 3.9.9, tsx 4.23.15, eslint-plugin-prettier 5.5.6, knip 6.38)

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: AdhereZ <85055734+AdhereZ@users.noreply.github.com>
Co-authored-by: minimax <adhere@minimaxi.com>
Co-authored-by: DanielWalnut <45447813+hetaoBackend@users.noreply.github.com>
Co-authored-by: AmsZuidas <254873068+amszuidas@users.noreply.github.com>
Co-authored-by: chenhao <chenhao@minimaxi.com>
Co-authored-by: SaladDay <1203511142@qq.com>
Co-authored-by: hetaoBackend <hetao7@pku.edu.cn>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Tao He <hetaoBackend@users.noreply.github.com>
Co-authored-by: hermes-agent <hermes-agent@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant