Skip to content

chore(deps): combine dependency updates - #16

Merged
ThomasK33 merged 1 commit into
mainfrom
deps/combined-update
Sep 24, 2026
Merged

ThomasK33 merged 1 commit into
mainfrom
deps/combined-update

Conversation

@ThomasK33

Copy link
Copy Markdown
Member

Combines every open Dependabot update into one lockfile refresh, and also applies the other in-range updates that npm outdated reported.

Supersedes #5, #6, #9, #10, #11, #13, #14.

What changed

  • package-lock.json was regenerated with npm update (Node 25.9.0, npm 11.12.1). It was not edited by hand.
  • package.json is unchanged. Every new version fits the existing semver ranges.
  • No source changes were needed.

Dependabot targets

PR Package Old Dependabot target This PR
#14 vitest / @vitest/mocker 4.1.5 4.1.11 4.1.11
#14, #6 vite 8.0.10 8.2.2 (#14), 8.0.16 (#6) 8.3.0
#14, #6 rolldown 1.0.0-rc.17 1.2.8 1.2.10
#13 nanoid 3.3.11 3.3.18 3.3.19
#11 undici 6.25.0 6.28.0 6.28.1
#10 postcss 8.5.10 8.5.25 8.5.28
#9 tar 7.5.13 7.5.22 7.5.22
#5 esbuild 0.27.7 0.28.1 0.28.2
#5 tsx 4.21.0 4.22.4 4.23.15

Other direct dependencies (in range)

Package Old New
@types/node 25.6.0 25.9.8
node-addon-api 8.7.0 8.9.2
node-gyp 12.3.0 12.4.0
All other transitive changes
Package Old New
@jridgewell/sourcemap-codec 1.5.5 1.6.0
@oxc-project/types 0.127.0 0.151.0
@rolldown/pluginutils 1.0.0-rc.17 1.0.1
@rolldown/binding-* 1.0.0-rc.17 1.2.10
@esbuild/* 0.27.7 0.28.2
@types/estree 1.0.8 1.0.9
@vitest/expect, pretty-format, runner, snapshot, spy, utils 4.1.5 4.1.11
es-module-lexer 2.0.0 2.3.2
expect-type 1.3.0 1.4.0
lightningcss (+ platform packages) 1.32.0 1.33.0
node-abi 3.89.0 3.96.0
obug 2.1.1 2.2.1
picomatch 4.0.4 4.0.7
semver 7.7.4 7.8.5
std-env 4.1.0 4.2.0
tar-fs 2.1.4 2.1.5
tinyexec 1.1.1 1.3.1
tinyglobby 0.2.16 0.2.17
tinyrainbow 3.1.0 3.1.1
undici-types 7.19.2 7.24.6
Removed: @emnapi/core, @emnapi/runtime, @emnapi/wasi-threads, @napi-rs/wasm-runtime, @tybys/wasm-util, tslib, get-tsconfig, resolve-pkg-maps — —

Skipped major bumps

  • typescript 5.9.3 → 7.0.2: major (the TypeScript 7 native compiler). Not proposed by Dependabot.
  • @types/node 25.x → 26.x: major, and the repo pins Node 25.9 in mise.toml. Not proposed by Dependabot.

Validation

Run locally on Linux x64 with the mise.toml toolchain (Node 25.9.0, Zig 0.15.2), matching mise run ci:

  1. npm ci ✅
  2. npm run build:libghostty ✅
  3. npm run build:native (node-gyp) ✅
  4. npm run build ✅
  5. npm run typecheck ✅
  6. npm test: 2 files, 6 tests ✅
  7. npm run smoke ✅
  8. Extra: npm run build:prebuild && npm run verify:prebuilds && npm pack --dry-run ✅

The repo has no lint script.

npm audit: before, 8 (1 critical, 4 high, 2 moderate, 1 low); after, 0.


Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high

Supersedes #5, #6, #9, #10, #11, #13, #14.

Regenerated package-lock.json with npm update (Node 25.9 / npm 11.12.1);
package.json ranges are unchanged.

Change-Id: I1efe77936fd9185efb48fee9acbfddcc55fccbcd
Signed-off-by: Thomas Kosiewski <tk@coder.com>
@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@ThomasK33

Copy link
Copy Markdown
Member Author

@codex security review

@ThomasK33

ThomasK33 commented Sep 24, 2026 •

Copy link
Copy Markdown
Member Author

Validation evidence for head da9ae13.

  1. I recorded the full local gate run with vhs at head da9ae13 (Node 25.9.0, Zig 0.15.2). The order matches mise run ci: npm ci, build:libghostty, build:native, build, typecheck, test, smoke, then npm audit.
  2. npm audit signatures: all 92 packages have verified registry signatures; 37 also have verified attestations.
  3. An independent fresh-context review (a Codex substitute, because @codex review and @codex security review got no response here) recommended ready with tracked follow-ups, with no blockers. It confirmed:
    • Every Dependabot target is met or exceeded.
    • Every lockfile entry resolves from registry.npmjs.org and has a sha512 integrity hash.
    • The only new package is the optional @rolldown/binding-android-arm-eabi.
    • No install scripts changed.
    • All versions still support Node 20.19.
  4. Follow-up from that review: some versions are only 1–5 days old (for example rolldown 1.2.10). The repo has no release-age cooldown policy. Adding one is tracked as a separate follow-up.

Tests and typecheck:
vitest: 2 files, 6 tests passed

Smoke and audit:
smoke snapshot summary and npm audit: 0 vulnerabilities

Recording:

gates.mp4

Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant