Skip to content

chore(deps-dev): bump the npm-dependencies group with 35 updates#210

Open
dependabot[bot] wants to merge 5 commits into
masterfrom
dependabot/npm_and_yarn/npm-dependencies-eb6bc349ce
Open

chore(deps-dev): bump the npm-dependencies group with 35 updates#210
dependabot[bot] wants to merge 5 commits into
masterfrom
dependabot/npm_and_yarn/npm-dependencies-eb6bc349ce

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Jun 4, 2026

Bumps the npm-dependencies group with 35 updates:

Package From To
@apidevtools/json-schema-ref-parser 11.9.3 15.3.5
@bazel/bazelisk 1.26.0 1.28.1
@bazel/ibazel 0.25.0 0.28.0
@redocly/cli 1.34.0 2.31.6
@semantic-release/exec 6.0.3 7.1.0
@semantic-release/npm 9.0.2 13.1.5
@types/node 17.0.45 25.9.1
@types/unist 2.0.11 3.0.3
axios 0.27.2 1.17.0
dir-compare 4.2.0 5.0.0
glob 8.1.0 13.0.6
js-yaml 4.1.1 4.2.0
jsonpath-plus 6.0.1 10.4.0
mdast-util-from-markdown 0.8.5 2.0.3
mdast-util-gfm 0.1.2 3.1.0
micromark-extension-gfm 0.3.3 3.0.0
openapi-examples-validator 6.0.3 7.1.0
openapi-to-postmanv2 5.7.0 6.0.1
postman-code-generators 1.14.2 2.1.1
postman-collection 4.5.0 5.3.0
prettier 2.8.8 3.8.3
query-string 7.1.3 9.4.0
remark-gfm 1.0.0 4.0.1
remark-html 13.0.2 16.0.1
remark-parse 9.0.0 11.0.0
remark-stringify 9.0.1 11.0.0
rimraf 6.1.2 6.1.3
slugify 1.6.6 1.6.9
tar 6.2.1 7.5.16
tar-stream 3.1.7 3.2.0
tmp 0.2.5 0.2.7
typescript 5.6.2 6.0.3
unified 9.2.2 11.0.5
yaml 2.8.2 2.9.0
yargs 17.7.2 18.0.0

Updates @apidevtools/json-schema-ref-parser from 11.9.3 to 15.3.5

Release notes

Sourced from @​apidevtools/json-schema-ref-parser's releases.

v15.3.5

15.3.5 (2026-03-30)

Bug Fixes

  • edge: fix some edge cases and add more tests (df7967e)

v15.3.4

15.3.4 (2026-03-27)

Reverts

  • Revert "fix: support 2020-12 anchors and ref siblings" (f26d8c7)

v15.3.3

15.3.3 (2026-03-26)

Bug Fixes

v15.3.2

15.3.2 (2026-03-23)

Bug Fixes

v15.3.1

15.3.1 (2026-02-28)

Bug Fixes

v15.3.0

15.3.0 (2026-02-28)

Bug Fixes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​apidevtools/json-schema-ref-parser since your current version.


Updates @bazel/bazelisk from 1.26.0 to 1.28.1

Release notes

Sourced from @​bazel/bazelisk's releases.

v1.28.1

Bazelisk v1.28.1 comes with a bug fix:

Bug Fixes & Improvements (Go)

We’d like to thank our amazing contributor @​valco1994!

v1.28.0

Bazelisk v1.28.0 comes with a new feature and several improvements:

New Features (Go)

Bug Fixes & Improvements (Go)

Bug Fixes & Improvements (JavaScript)

We’d like to thank our amazing contributors @​cerisier, @​chrisirhc, @​hagl, @​jmmv, @​jwnimmer-tri, @​jylenhof, @​oxidase and @​valco1994!

v1.27.0

Bazelisk v1.27.0 comes with a few improvements:

New Features (Go)

  • Bazelisk now offers the bazelisk completion bash/fish command to print shell completion scripts for the current Bazel version (bazelbuild/bazelisk#706).

Bug Fixes & Improvements (Go)

We’d like to thank our amazing contributors @​chenrui333, @​fmeum, @​jln-ho, @​kolloch and @​thii!

Commits
  • 1e6aaf1 Fix wrappers issues in Bazelisk 1.28.0 on Windows (#762)
  • 166e156 Report a proper exit code when Bazel is terminated by signal and use exec o...
  • b1bce1b Upgrade bazel_dep dependencies and .bazelversion (#752)
  • c10812c Improve error when completion is not supported (#747)
  • d502081 docs(installation): add mise alternative method installation (#739)
  • 239f342 Correctly detect rolling release in rare edge case (#745)
  • 1fe6057 Bump golang.org/x/term from 0.36.0 to 0.37.0 (#740)
  • 49f0b12 Properly handle powershell and batch wrappers (#732)
  • ffde42c Change completion script name from 'gh' to 'bazel' (#733)
  • 6dde358 Add BAZELISK_BASE_URL regression test (#734)
  • Additional commits viewable in compare view

Updates @bazel/ibazel from 0.25.0 to 0.28.0

Updates @redocly/cli from 1.34.0 to 2.31.6

Release notes

Sourced from @​redocly/cli's releases.

@​redocly/cli@​2.31.6

Patch Changes

  • Fixed lint --format=checkstyle to produce a single combined XML document when multiple APIs are passed to the command, instead of concatenated per-file documents.
  • Updated redoc to v2.5.3, styled-components to v6.4.2, and react to v19.2.7.
  • Updated @​redocly/openapi-core to v2.31.6.

@​redocly/cli@​2.31.5

Patch Changes

  • Updated the no-unused-components rule to validate unused security schemes.

  • Pinned the official Docker image base to node:24-alpine.

  • Fixed the remove-unused-components decorator to remove unused security schemes.

    Warning: The bundler may now remove more unused components than before.

  • Updated @​redocly/openapi-core to v2.31.5.

@​redocly/cli@​2.31.4

Patch Changes

  • Updated @​redocly/openapi-core to v2.31.4.

@​redocly/cli@​2.31.3

Patch Changes

  • Fixed an issue where the Respect command did not honor the HTTP_PROXY, HTTPS_PROXY, and NO_PROXY environment variables when loading remote source descriptions or resolving external $refs. Proxy settings are consistently applied during reference resolution as well.
  • Updated @​redocly/openapi-core to v2.31.3.

@​redocly/cli@​2.31.2

Patch Changes

  • Fixed the remove-unused-components decorator to remove unused components containing allOf keyword.

    Warning: The bundler may now remove more unused components than before.

  • Fixed the no-unused-components rule to highlight unused schemas containing allOf keyword.

  • Updated @​redocly/openapi-core to v2.31.2.

@​redocly/cli@​2.31.1

Patch Changes

  • Updated @​redocly/openapi-core to v2.31.1.

@​redocly/cli@​2.31.0

Patch Changes

... (truncated)

Commits
  • 7a26299 chore: 🔖 release new versions (#2847)
  • 7b5e572 chore(cli): update redoc to v2.5.3 (#2842)
  • 296e029 fix(cli): lint with multiple api files results in invalid output (#2744)
  • d7e0b7a chore: add e2e tests for security propagation during join (#2827)
  • 1146d8b chore(deps): bump vitest and @​vitest/coverage-istanbul to v4.1.8 (#2846)
  • 0b51bad chore: improve performance benchmark (#2816)
  • 7d01f5d chore: add reference links for common build-in rules (#2839)
  • a87dc62 chore: 🔖 release new versions (#2840)
  • 8ac6790 fix: pin specific nodejs version in dockerfile (#2841)
  • ba8ac4c fix(core): validate/remove unused securitySchemes and securityDefinitions cor...
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​redocly/cli since your current version.


Updates @semantic-release/exec from 6.0.3 to 7.1.0

Release notes

Sourced from @​semantic-release/exec's releases.

v7.1.0

7.1.0 (2025-05-09)

Features

  • error: print more useful error for non-process failure (#449) (a285bc5)

v7.0.3

7.0.3 (2025-02-03)

Bug Fixes

  • deps: update dependency execa to v9 (643e2eb)

v7.0.2

7.0.2 (2025-02-01)

Bug Fixes

  • deps: update dependency @​semantic-release/error to v4 (#353) (471f963)

v7.0.1

7.0.1 (2025-02-01)

Bug Fixes

  • deps: update dependency parse-json to v8 (#394) (080440f)

v7.0.0

7.0.0 (2025-01-31)

Features

BREAKING CHANGES

  • the minimum required version of semantic-release to use @semantic-release/exec is now v24.1.0; the warn logger method/function is now available to use in plugin

  • @semantic-release/exec is now a native ES Module. It has named exports for each plugin hook (verifyConditions, analyzeCommits, verifyRelease, generateNotes, prepare, publish, addChannel, success, fail)

... (truncated)

Commits
  • a285bc5 feat(error): print more useful error for non-process failure (#449)
  • aa1a2bc chore(deps): lock file maintenance (#451)
  • b0dc7ab chore(deps): update dependency ava to v6.3.0 (#450)
  • 93bf408 chore(deps): lock file maintenance (#448)
  • 0e70c6f chore(deps): lock file maintenance (#446)
  • e643dc3 ci(action): update actions/setup-node action to v4.4.0 (#445)
  • a08859e chore(deps): lock file maintenance (#444)
  • da1754e chore(deps): lock file maintenance (#443)
  • 72668cc chore(deps): lock file maintenance (#442)
  • 3c6a8a9 chore(deps): update dependency sinon to v20 (#441)
  • Additional commits viewable in compare view

Updates @semantic-release/npm from 9.0.2 to 13.1.5

Release notes

Sourced from @​semantic-release/npm's releases.

v13.1.5

13.1.5 (2026-03-01)

Bug Fixes

  • deps: update dependency normalize-url to v9 (#1095) (daec492)

v13.1.4

13.1.4 (2026-02-06)

Bug Fixes

  • deps: update dependency @​actions/core to v3 (#1085) (17abfe1)

v13.1.3

13.1.3 (2025-12-12)

Bug Fixes

  • deps: update dependency @​actions/core to v2 (#1055) (fa4a3ab)

v13.1.2

13.1.2 (2025-11-14)

Bug Fixes

v13.1.1

13.1.1 (2025-10-19)

Bug Fixes

  • publish-dry-run: temporarily remove the addition of dry-running the publish step (30bd176)

v13.1.0

13.1.0 (2025-10-19)

Features

  • trusted-publishing: verify auth, considering OIDC vs tokens from various registries (e3319f1), closes #958
  • trusted-publishing: refine the messages for related errors (316ce21), closes #958
  • trusted-publishing: make request to verify if OIDC token exchange can succeed (c80ecb0), closes #958
  • trusted-publishing: pass id-token as bearer header for github actions (d83b727), closes #958
  • trusted-publishing: pass id-token as bearer header for gitlab pipelines (6d1c3cf), closes #958

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​semantic-release/npm since your current version.


Updates @types/node from 17.0.45 to 25.9.1

Commits

Updates @types/unist from 2.0.11 to 3.0.3

Commits

Updates axios from 0.27.2 to 1.17.0

Release notes

Sourced from axios's releases.

v1.17.0 — June 1, 2026

This release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regressions.

🔒 Security Fixes

  • Config Hardening: Guarded socketPath, params, and paramsSerializer reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (#10901, #10922)
  • Release Publishing: Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance. (#10926)

🚀 New Features

  • HTTP Compression: Added Node HTTP adapter support for zstd response decompression, with transitional.advertiseZstdAcceptEncoding controlling whether zstd is advertised in Accept-Encoding. (#6792, #10920)

🐛 Bug Fixes

  • Authentication Handling: Restored Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and aligned the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth. (#10929, #10896)
  • Proxy TLS: Preserved user httpsAgent TLS options when tunneling HTTPS requests through HTTP CONNECT proxies. (#10957)
  • React Native FormData: Cleared default Content-Type for React Native FormData so multipart boundaries can be generated correctly. (#10898)
  • Headers: Silently skipped empty or whitespace-only header names instead of throwing, matching parsed-header behavior and avoiding React Native response crashes. (#10875)
  • Request Data Merging: Preserved enumerable symbol keys when cloning plain request data through axios merge logic. (#10812)
  • Bundler Compatibility: Converted resolveConfig from an arrow default export to a named function export to avoid webpack and Babel transform interop failures. (#10891)
  • Types: Corrected AxiosHeaders.toJSON() return types and updated CommonJS isCancel typings to narrow to CanceledError<T>. (#10956, #10952)
  • Build Tooling: Avoided emitting a null Authorization header from the GitHub build helper when GITHUB_TOKEN is unset. (#10931)

🔧 Maintenance & Chores

  • HTTP/2 Internals: Extracted Http2Sessions into its own helper module and added direct unit coverage for session pooling, timeout, and cleanup behavior. (#10861)
  • Package Publishing: Reduced published package size by switching to a files allowlist and dropping unneeded unminified bundle source maps. (#10939)
  • CI and Release Automation: Added bundle-size reporting, moved reports to the job summary, fixed bundle-size comparison coverage, added Node 26 to the matrix, pinned npm for staged publishing, and prepared the 1.17.0 release. (#10907, #10911, #10916, #10927, #10935, #10983)
  • Developer Workflow: Added a dev container and iterated on OpenSpec workflow files before removing them from the release branch. (#10925, #10914, #10958)
  • Documentation and Policy: Updated disclosure, contributor, collaboration, threat-model, advanced docs, README badges, release notes, moderator configuration, and project metadata. (#10890, #10889, #10921, #10945, #10905, #10933, #10915, #10887, #10955)
  • Dependencies: Bumped Babel tooling, Commitlint, ESLint, Rollup, Globals, Vitest, Playwright, fs-extra, qs, docs dependencies, and GitHub Actions dependencies including actions/dependency-review-action and zizmorcore/zizmor-action. (#10871, #10879, #10918, #10919, #10934, #10947, #10954, #10960)

🌟 New Contributors

We are thrilled to welcome our new contributors. Thank you for helping improve axios:

Full Changelog

... (truncated)

Changelog

Sourced from axios's changelog.

v1.17.0 — June 1, 2026

This release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regressions.

🔒 Security Fixes

  • Config Hardening: Guarded socketPath, params, and paramsSerializer reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (#10901, #10922)
  • Release Publishing: Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance. (#10926)

🚀 New Features

  • HTTP Compression: Added Node HTTP adapter support for zstd response decompression, with transitional.advertiseZstdAcceptEncoding controlling whether zstd is advertised in Accept-Encoding. (#6792, #10920)

🐛 Bug Fixes

  • Authentication Handling: Restored Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and aligned the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth. (#10929, #10896)
  • Proxy TLS: Preserved user httpsAgent TLS options when tunneling HTTPS requests through HTTP CONNECT proxies. (#10957)
  • React Native FormData: Cleared default Content-Type for React Native FormData so multipart boundaries can be generated correctly. (#10898)
  • Headers: Silently skipped empty or whitespace-only header names instead of throwing, matching parsed-header behavior and avoiding React Native response crashes. (#10875)
  • Request Data Merging: Preserved enumerable symbol keys when cloning plain request data through axios merge logic. (#10812)
  • Bundler Compatibility: Converted resolveConfig from an arrow default export to a named function export to avoid webpack and Babel transform interop failures. (#10891)
  • Types: Corrected AxiosHeaders.toJSON() return types and updated CommonJS isCancel typings to narrow to CanceledError<T>. (#10956, #10952)
  • Build Tooling: Avoided emitting a null Authorization header from the GitHub build helper when GITHUB_TOKEN is unset. (#10931)

🔧 Maintenance & Chores

  • HTTP/2 Internals: Extracted Http2Sessions into its own helper module and added direct unit coverage for session pooling, timeout, and cleanup behavior. (#10861)
  • Package Publishing: Reduced published package size by switching to a files allowlist and dropping unneeded unminified bundle source maps. (#10939)
  • CI and Release Automation: Added bundle-size reporting, moved reports to the job summary, fixed bundle-size comparison coverage, added Node 26 to the matrix, pinned npm for staged publishing, and prepared the 1.17.0 release. (#10907, #10911, #10916, #10927, #10935, #10983)
  • Developer Workflow: Added a dev container and iterated on OpenSpec workflow files before removing them from the release branch. (#10925, #10914, #10958)
  • Documentation and Policy: Updated disclosure, contributor, collaboration, threat-model, advanced docs, README badges, release notes, moderator configuration, and project metadata. (#10890, #10889, #10921, #10945, #10905, #10933, #10915, #10887, #10955)
  • Dependencies: Bumped Babel tooling, Commitlint, ESLint, Rollup, Globals, Vitest, Playwright, fs-extra, qs, docs dependencies, and GitHub Actions dependencies including actions/dependency-review-action and zizmorcore/zizmor-action. (#10871, #10879, #10918, #10919, #10934, #10947, #10954, #10960)

🌟 New Contributors

We are thrilled to welcome our new contributors. Thank you for helping improve axios:

Full Changelog

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for axios since your current version.

Install script changes

This version adds prepare script that runs during installation. Review the package contents before updating.


Updates dir-compare from 4.2.0 to 5.0.0

Release notes

Sourced from dir-compare's releases.

v5.0.0

Breaking changes: * skipSubdirs option has slightly different behavior. More details in #77

Commits

Updates glob from 8.1.0 to 13.0.6

Changelog

Sourced from glob's changelog.

changeglob

13

  • Move the CLI program out to a separate package, glob-bin. Install that if you'd like to continue using glob from the command line.

12

  • Remove the unsafe --shell option. The --shell option is now ONLY supported on known shells where the behavior can be implemented safely.

11.1

GHSA-5j98-mcp5-4vw2

  • Add the --shell option for the command line, with a warning that this is unsafe. (It will be removed in v12.)
  • Add the --cmd-arg/-g as a way to safely add positional arguments to the command provided to the CLI tool.
  • Detect commands with space or quote characters on known shells, and pass positional arguments to them safely, avoiding shell:true execution.

11.0

  • Drop support for node before v20

10.4

  • Add includeChildMatches: false option
  • Export the Ignore class

10.3

  • Add --default -p flag to provide a default pattern
  • exclude symbolic links to directories when follow and nodir are both set

10.2

  • Add glob cli

10.1

  • Return '.' instead of the empty string '' when the current working directory is returned as a match.
  • Add posix: true option to return / delimited paths, even on

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by isaacs, a new releaser for glob since your current version.

Install script changes

This version adds prepare script that runs during installation. Review the package contents before updating.


Updates js-yaml from 4.1.1 to 4.2.0

Changelog

Sourced from js-yaml's changelog.

[4.2.0] - 2026-06-01

Added

  • Added docs/safety.md with notes about processing untrusted YAML.
  • Added maxDepth (100) loader option. Not a problem, but gives a better exception instead of RangeError on stack overflow.
  • Added maxMergeSeqLength (20) loader option. Not a problem after merge fix, but an additional restriction for safety.
  • Added sourcemaps to dist/ builds.

Changed

  • Stop resolving numbers with underscores as numeric scalars, #627.
  • Switched dev toolchains to Vite / neostandard.
  • Updated demo.
  • Reorganized tests.
  • dist/ files are no longer kept in the repository.

Fixed

  • Fix parsing of properties on the first implicit block mapping key, #62.
  • Fix trailing whitespace handling when folding flow scalar lines, #307.
  • Reject top-level block scalars without content indentation, #280...

    Description has been truncated

Bumps the npm-dependencies group with 35 updates:

| Package | From | To |
| --- | --- | --- |
| [@apidevtools/json-schema-ref-parser](https://github.com/APIDevTools/json-schema-ref-parser) | `11.9.3` | `15.3.5` |
| [@bazel/bazelisk](https://github.com/bazelbuild/bazelisk) | `1.26.0` | `1.28.1` |
| @bazel/ibazel | `0.25.0` | `0.28.0` |
| [@redocly/cli](https://github.com/Redocly/redocly-cli) | `1.34.0` | `2.31.6` |
| [@semantic-release/exec](https://github.com/semantic-release/exec) | `6.0.3` | `7.1.0` |
| [@semantic-release/npm](https://github.com/semantic-release/npm) | `9.0.2` | `13.1.5` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `17.0.45` | `25.9.1` |
| [@types/unist](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/unist) | `2.0.11` | `3.0.3` |
| [axios](https://github.com/axios/axios) | `0.27.2` | `1.17.0` |
| [dir-compare](https://github.com/gliviu/dir-compare) | `4.2.0` | `5.0.0` |
| [glob](https://github.com/isaacs/node-glob) | `8.1.0` | `13.0.6` |
| [js-yaml](https://github.com/nodeca/js-yaml) | `4.1.1` | `4.2.0` |
| [jsonpath-plus](https://github.com/s3u/JSONPath) | `6.0.1` | `10.4.0` |
| [mdast-util-from-markdown](https://github.com/syntax-tree/mdast-util-from-markdown) | `0.8.5` | `2.0.3` |
| [mdast-util-gfm](https://github.com/syntax-tree/mdast-util-gfm) | `0.1.2` | `3.1.0` |
| [micromark-extension-gfm](https://github.com/micromark/micromark-extension-gfm) | `0.3.3` | `3.0.0` |
| [openapi-examples-validator](https://github.com/codekie/openapi-examples-validator) | `6.0.3` | `7.1.0` |
| [openapi-to-postmanv2](https://github.com/postmanlabs/openapi-to-postman) | `5.7.0` | `6.0.1` |
| [postman-code-generators](https://github.com/postmanlabs/code-generators) | `1.14.2` | `2.1.1` |
| [postman-collection](https://github.com/postmanlabs/postman-collection) | `4.5.0` | `5.3.0` |
| [prettier](https://github.com/prettier/prettier) | `2.8.8` | `3.8.3` |
| [query-string](https://github.com/sindresorhus/query-string) | `7.1.3` | `9.4.0` |
| [remark-gfm](https://github.com/remarkjs/remark-gfm) | `1.0.0` | `4.0.1` |
| [remark-html](https://github.com/remarkjs/remark-html) | `13.0.2` | `16.0.1` |
| [remark-parse](https://github.com/remarkjs/remark) | `9.0.0` | `11.0.0` |
| [remark-stringify](https://github.com/remarkjs/remark) | `9.0.1` | `11.0.0` |
| [rimraf](https://github.com/isaacs/rimraf) | `6.1.2` | `6.1.3` |
| [slugify](https://github.com/simov/slugify) | `1.6.6` | `1.6.9` |
| [tar](https://github.com/isaacs/node-tar) | `6.2.1` | `7.5.16` |
| [tar-stream](https://github.com/mafintosh/tar-stream) | `3.1.7` | `3.2.0` |
| [tmp](https://github.com/raszi/node-tmp) | `0.2.5` | `0.2.7` |
| [typescript](https://github.com/microsoft/TypeScript) | `5.6.2` | `6.0.3` |
| [unified](https://github.com/unifiedjs/unified) | `9.2.2` | `11.0.5` |
| [yaml](https://github.com/eemeli/yaml) | `2.8.2` | `2.9.0` |
| [yargs](https://github.com/yargs/yargs) | `17.7.2` | `18.0.0` |


Updates `@apidevtools/json-schema-ref-parser` from 11.9.3 to 15.3.5
- [Release notes](https://github.com/APIDevTools/json-schema-ref-parser/releases)
- [Commits](APIDevTools/json-schema-ref-parser@v11.9.3...v15.3.5)

Updates `@bazel/bazelisk` from 1.26.0 to 1.28.1
- [Release notes](https://github.com/bazelbuild/bazelisk/releases)
- [Commits](bazelbuild/bazelisk@v1.26.0...v1.28.1)

Updates `@bazel/ibazel` from 0.25.0 to 0.28.0

Updates `@redocly/cli` from 1.34.0 to 2.31.6
- [Release notes](https://github.com/Redocly/redocly-cli/releases)
- [Commits](https://github.com/Redocly/redocly-cli/compare/@redocly/cli@1.34.0...@redocly/cli@2.31.6)

Updates `@semantic-release/exec` from 6.0.3 to 7.1.0
- [Release notes](https://github.com/semantic-release/exec/releases)
- [Commits](semantic-release/exec@v6.0.3...v7.1.0)

Updates `@semantic-release/npm` from 9.0.2 to 13.1.5
- [Release notes](https://github.com/semantic-release/npm/releases)
- [Commits](semantic-release/npm@v9.0.2...v13.1.5)

Updates `@types/node` from 17.0.45 to 25.9.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@types/unist` from 2.0.11 to 3.0.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/unist)

Updates `axios` from 0.27.2 to 1.17.0
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v0.27.2...v1.17.0)

Updates `dir-compare` from 4.2.0 to 5.0.0
- [Release notes](https://github.com/gliviu/dir-compare/releases)
- [Commits](gliviu/dir-compare@v4.2.0...v5.0.0)

Updates `glob` from 8.1.0 to 13.0.6
- [Changelog](https://github.com/isaacs/node-glob/blob/main/changelog.md)
- [Commits](isaacs/node-glob@v8.1.0...v13.0.6)

Updates `js-yaml` from 4.1.1 to 4.2.0
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](https://github.com/nodeca/js-yaml/commits)

Updates `jsonpath-plus` from 6.0.1 to 10.4.0
- [Release notes](https://github.com/s3u/JSONPath/releases)
- [Changelog](https://github.com/JSONPath-Plus/JSONPath/blob/main/CHANGES.md)
- [Commits](JSONPath-Plus/JSONPath@v6.0.1...v10.4.0)

Updates `mdast-util-from-markdown` from 0.8.5 to 2.0.3
- [Release notes](https://github.com/syntax-tree/mdast-util-from-markdown/releases)
- [Commits](syntax-tree/mdast-util-from-markdown@0.8.5...2.0.3)

Updates `mdast-util-gfm` from 0.1.2 to 3.1.0
- [Release notes](https://github.com/syntax-tree/mdast-util-gfm/releases)
- [Commits](syntax-tree/mdast-util-gfm@0.1.2...3.1.0)

Updates `micromark-extension-gfm` from 0.3.3 to 3.0.0
- [Release notes](https://github.com/micromark/micromark-extension-gfm/releases)
- [Commits](micromark/micromark-extension-gfm@0.3.3...3.0.0)

Updates `openapi-examples-validator` from 6.0.3 to 7.1.0
- [Changelog](https://github.com/codekie/openapi-examples-validator/blob/main/CHANGELOG.md)
- [Commits](codekie/openapi-examples-validator@v6.0.3...v7.1.0)

Updates `openapi-to-postmanv2` from 5.7.0 to 6.0.1
- [Release notes](https://github.com/postmanlabs/openapi-to-postman/releases)
- [Changelog](https://github.com/postmanlabs/openapi-to-postman/blob/develop/CHANGELOG.md)
- [Commits](postmanlabs/openapi-to-postman@v5.7.0...v6.0.1)

Updates `postman-code-generators` from 1.14.2 to 2.1.1
- [Release notes](https://github.com/postmanlabs/code-generators/releases)
- [Changelog](https://github.com/postmanlabs/postman-code-generators/blob/develop/CHANGELOG.md)
- [Commits](postmanlabs/postman-code-generators@v1.14.2...v2.1.1)

Updates `postman-collection` from 4.5.0 to 5.3.0
- [Release notes](https://github.com/postmanlabs/postman-collection/releases)
- [Changelog](https://github.com/postmanlabs/postman-collection/blob/develop/CHANGELOG.yaml)
- [Commits](postmanlabs/postman-collection@v4.5.0...v5.3.0)

Updates `prettier` from 2.8.8 to 3.8.3
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@2.8.8...3.8.3)

Updates `query-string` from 7.1.3 to 9.4.0
- [Release notes](https://github.com/sindresorhus/query-string/releases)
- [Commits](sindresorhus/query-string@v7.1.3...v9.4.0)

Updates `remark-gfm` from 1.0.0 to 4.0.1
- [Release notes](https://github.com/remarkjs/remark-gfm/releases)
- [Commits](remarkjs/remark-gfm@1.0.0...4.0.1)

Updates `remark-html` from 13.0.2 to 16.0.1
- [Release notes](https://github.com/remarkjs/remark-html/releases)
- [Commits](remarkjs/remark-html@13.0.2...16.0.1)

Updates `remark-parse` from 9.0.0 to 11.0.0
- [Release notes](https://github.com/remarkjs/remark/releases)
- [Changelog](https://github.com/remarkjs/remark/blob/main/changelog.md)
- [Commits](https://github.com/remarkjs/remark/compare/remark-parse@9.0.0...remark-parse@11.0.0)

Updates `remark-stringify` from 9.0.1 to 11.0.0
- [Release notes](https://github.com/remarkjs/remark/releases)
- [Changelog](https://github.com/remarkjs/remark/blob/main/changelog.md)
- [Commits](https://github.com/remarkjs/remark/compare/remark-stringify@9.0.1...remark-stringify@11.0.0)

Updates `rimraf` from 6.1.2 to 6.1.3
- [Changelog](https://github.com/isaacs/rimraf/blob/main/CHANGELOG.md)
- [Commits](isaacs/rimraf@v6.1.2...v6.1.3)

Updates `slugify` from 1.6.6 to 1.6.9
- [Changelog](https://github.com/simov/slugify/blob/master/CHANGELOG.md)
- [Commits](https://github.com/simov/slugify/commits)

Updates `tar` from 6.2.1 to 7.5.16
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v6.2.1...v7.5.16)

Updates `tar-stream` from 3.1.7 to 3.2.0
- [Commits](mafintosh/tar-stream@v3.1.7...v3.2.0)

Updates `tmp` from 0.2.5 to 0.2.7
- [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md)
- [Commits](raszi/node-tmp@v0.2.5...v0.2.7)

Updates `typescript` from 5.6.2 to 6.0.3
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v5.6.2...v6.0.3)

Updates `unified` from 9.2.2 to 11.0.5
- [Release notes](https://github.com/unifiedjs/unified/releases)
- [Changelog](https://github.com/unifiedjs/unified/blob/main/changelog.md)
- [Commits](unifiedjs/unified@9.2.2...11.0.5)

Updates `yaml` from 2.8.2 to 2.9.0
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.8.2...v2.9.0)

Updates `yargs` from 17.7.2 to 18.0.0
- [Release notes](https://github.com/yargs/yargs/releases)
- [Changelog](https://github.com/yargs/yargs/blob/main/CHANGELOG.md)
- [Commits](yargs/yargs@v17.7.2...v18.0.0)

---
updated-dependencies:
- dependency-name: "@apidevtools/json-schema-ref-parser"
  dependency-version: 15.3.5
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: "@bazel/bazelisk"
  dependency-version: 1.28.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: "@bazel/ibazel"
  dependency-version: 0.28.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: "@redocly/cli"
  dependency-version: 2.31.6
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: "@semantic-release/exec"
  dependency-version: 7.1.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: "@semantic-release/npm"
  dependency-version: 13.1.5
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: "@types/node"
  dependency-version: 25.9.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: "@types/unist"
  dependency-version: 3.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: axios
  dependency-version: 1.17.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: dir-compare
  dependency-version: 5.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: glob
  dependency-version: 13.0.6
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: js-yaml
  dependency-version: 4.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: jsonpath-plus
  dependency-version: 10.4.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: mdast-util-from-markdown
  dependency-version: 2.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: mdast-util-gfm
  dependency-version: 3.1.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: micromark-extension-gfm
  dependency-version: 3.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: openapi-examples-validator
  dependency-version: 7.1.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: openapi-to-postmanv2
  dependency-version: 6.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: postman-code-generators
  dependency-version: 2.1.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: postman-collection
  dependency-version: 5.3.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: prettier
  dependency-version: 3.8.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: query-string
  dependency-version: 9.4.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: remark-gfm
  dependency-version: 4.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: remark-html
  dependency-version: 16.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: remark-parse
  dependency-version: 11.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: remark-stringify
  dependency-version: 11.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: rimraf
  dependency-version: 6.1.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-dependencies
- dependency-name: slugify
  dependency-version: 1.6.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-dependencies
- dependency-name: tar
  dependency-version: 7.5.16
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: tar-stream
  dependency-version: 3.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: tmp
  dependency-version: 0.2.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-dependencies
- dependency-name: typescript
  dependency-version: 6.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: unified
  dependency-version: 11.0.5
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
- dependency-name: yaml
  dependency-version: 2.9.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-dependencies
- dependency-name: yargs
  dependency-version: 18.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: npm-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 4, 2026
Copy link
Copy Markdown

@claude claude Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This repository is configured for manual code reviews. Comment @claude review to trigger a review and subscribe this PR to future pushes, or @claude review once for a one-time review.

Tip: disable this comment in your organization's Code Review settings.

cmillett and others added 4 commits June 5, 2026 11:35
Checkpoint 1 — TypeScript compilation green under the upgraded stack.
Generator runtime fixes (json-schema-ref-parser path resolution, postman
snippets) follow in subsequent checkpoints.

Bazel toolchain:
- aspect_rules_ts 3.5.1 -> 3.8.10 (mirror list includes TypeScript 6.0.3,
  so the hermetic fetch keeps working without a ts_integrity override)
- aspect_rules_js 2.3.2 -> 2.9.2 + Node 18 -> 22.14 (EOL bump; also enables
  require() of the now ESM-only remark/unified toolchain)

TypeScript 6:
- tsconfig types: ["node"] — TS6 dropped automatic @types inclusion

Library API migrations:
- remark/unified/mdast/micromark: named imports + gfm()/gfmFromMarkdown()
- @types/unist deduped to v3 via pnpm.overrides (mdast-builder pins v2 and
  conflicts with the unist@3 used by the upgraded remark stack)
- glob 8 -> 13: named import + promise API (async main)
- prettier 2 -> 3: await the now-async format()
- postman-collection 4 -> 5: RequestBodyDefinition/RequestDefinition, array
  form of addQueryParams
- yargs 17 -> 18: singleton options() export removed; use yargs(argv).options()

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Checkpoint 2 — `bazel build //:outputs` passes.

redocly v2 no longer inlines $refs inside example values, so the bundled spec
keeps "../../responses|requests/*.yml" refs that json-schema-ref-parser must
resolve. Two fixes in the bundle macro + dereference step:

- redocly_cli.bzl: add the spec sources (all_srcs) as inputs to the
  dereference action so the referenced response/request files are present.
- dereference.ts: resolve the example refs against a base that mirrors the
  original specification/paths/<group>/<file>.yml depth, so "../../responses"
  lands under specification/. Output keeps #/components refs with examples
  inlined, matching the previous pipeline output.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Checkpoint 3 — 19/21 tests pass; the 2 remaining are stale committed
artifacts from redocly v2's output changes (see PR notes), pending a
content decision.

- tar 6 -> 7: dropped its default export; use `import * as tar`
  (rules/schema-in-index.ts, rules/dist-is-updated.ts).
- openapi-examples-validator 7 requires js-yaml at runtime without declaring
  it; provide //:node_modules/js-yaml to the validate_examples target.
- redocly v2 config: `spec` rule renamed to `struct` (raw config). Its
  stricter `recommended` set is downgraded for `no-invalid-schema-examples`
  and `no-empty-servers` to preserve prior behavior (flagged for follow-up).
- regenerate .aspect/bazelrc/* presets (newer aspect_bazel_lib via rules_js).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Checkpoint 4 — `bazel test //...` fully green (21/21).

redocly v2's remove-unused-components prunes 3 schemas (Destinations, Origins,
Units) that are unreferenced in every bundle (v1 left them in). Their source
files therefore had no generated docs, failing schema-in-index. They are
provably dead (0 refs across the source tree and both bundles), so:

- delete specification/schemas/{Destinations,Origins,Units}.yml + _index.yml
  entries.
- regenerate the committed dist/ and specification/parameters/_index.yml to
  match the v2 pipeline output. The only spec content change is the removal of
  those 3 unused schema definitions; examples remain inlined and #/components
  refs are preserved.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant