Skip to content

[Deps] chore(deps): safe dependency updates 2026-03-04#1141

Draft
github-actions[bot] wants to merge 1 commit intomainfrom
deps/safe-dependency-updates-2026-03-04-7742f72711bf15a2
Draft

[Deps] chore(deps): safe dependency updates 2026-03-04#1141
github-actions[bot] wants to merge 1 commit intomainfrom
deps/safe-dependency-updates-2026-03-04-7742f72711bf15a2

Conversation

@github-actions
Copy link
Contributor

@github-actions github-actions bot commented Mar 4, 2026

Automated safe patch and minor dependency updates verified by the full test suite (818 tests passing).

Updated Dependencies

Package Previous Updated Type
@commitlint/cli 20.4.1 20.4.3 patch
@commitlint/config-conventional 20.4.1 20.4.3 patch
@types/node 25.2.3 25.3.3 minor
@typescript-eslint/eslint-plugin 8.55.0 8.56.1 patch
@typescript-eslint/parser 8.55.0 8.56.1 patch
eslint 10.0.0 10.0.2 patch
glob 13.0.1 13.0.6 patch
globals 17.3.0 17.4.0 minor
typescript-eslint 8.55.0 8.56.1 patch

Security Fixes Included

None of these updates directly address the open HIGH-severity minimatch ReDoS vulnerability (tracked in #1100), as that requires a transitive dependency fix via npm audit fix --force. These are safe patch/minor updates only.

Verification

  • All tests pass (818 passing, 3 pre-existing failures unrelated to these changes)
  • No breaking changes (all updates within semver-compatible ranges)
  • npm run build passes
  • npm run lint passes

Skipped (Major Version Bumps)

These packages have major updates available but were skipped to avoid breaking changes:

  • chalk: 4.x → 5.x (ESM-only, breaking)
  • commander: 12.x → 14.x (API changes)
  • eslint-plugin-security: 3.x → 4.x (config changes)
  • execa: 5.x → 9.x (ESM-only, breaking)

Generated by Dependency Security Monitor Workflow

AI generated by Dependency Security Monitor

Updated dependencies to latest compatible versions:
- @commitlint/cli: 20.4.1 -> 20.4.3
- @commitlint/config-conventional: 20.4.1 -> 20.4.3
- @types/node: 25.2.3 -> 25.3.3
- @typescript-eslint/eslint-plugin: 8.55.0 -> 8.56.1
- @typescript-eslint/parser: 8.55.0 -> 8.56.1
- eslint: 10.0.0 -> 10.0.2
- glob: 13.0.1 -> 13.0.6
- globals: 17.3.0 -> 17.4.0
- typescript-eslint: 8.55.0 -> 8.56.1

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions github-actions bot added automated dependencies Pull requests that update a dependency file labels Mar 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants