Skip to content

chore(deps-dev): bump rollup from 2.60.0 to 3.29.5 - #925

Merged
appletreeisyellow merged 1 commit into
masterfrom
dependabot/npm_and_yarn/rollup-3.29.5
Sep 24, 2024
Merged

chore(deps-dev): bump rollup from 2.60.0 to 3.29.5#925
appletreeisyellow merged 1 commit into
masterfrom
dependabot/npm_and_yarn/rollup-3.29.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2024

Copy link
Copy Markdown
Contributor

Bumps rollup from 2.60.0 to 3.29.5.

Release notes

Sourced from rollup's releases.

v3.29.4

3.29.4

2023-09-28

Bug Fixes

  • Fix static analysis when an exported function uses callbacks (#5158)

Pull Requests

v3.29.3

3.29.3

2023-09-24

Bug Fixes

  • Fix a bug where code was wrongly tree-shaken after mutating function parameters (#5153)

Pull Requests

  • #5145: docs: improve the docs repl appearance in the light mode (@​TrickyPi)
  • #5148: chore(deps): update dependency @​vue/eslint-config-typescript to v12 (@​renovate[bot])
  • #5149: chore(deps): lock file maintenance minor/patch updates (@​renovate[bot])
  • #5153: Fully deoptimize first level path when deoptimizing nested parameter paths (@​lukastaegert)

v3.29.2

3.29.2

2023-09-15

Bug Fixes

  • Export TreeshakingPreset type (#5131)

Pull Requests

v3.29.1

3.29.1

2023-09-10

Bug Fixes

... (truncated)

Changelog

Sourced from rollup's changelog.

rollup changelog

4.22.4

2024-09-21

Bug Fixes

  • Fix a vulnerability in generated code that affects IIFE, UMD and CJS bundles when run in a browser context (#5671)

Pull Requests

4.22.3

2024-09-21

Bug Fixes

  • Ensure that mutations in modules without side effects are observed while properly handling transitive dependencies (#5669)

Pull Requests

4.22.2

2024-09-20

Bug Fixes

  • Revert fix for side effect free modules until other issues are investigated (#5667)

Pull Requests

4.22.1

2024-09-20

Bug Fixes

  • Revert #5644 "stable chunk hashes" while issues are being investigated

Pull Requests

... (truncated)

Commits
  • dfd233d 3.29.5
  • 2ef77c0 Fix DOM Clobbering CVE
  • a6448b9 3.29.4
  • 4e92d60 Deoptimize all parameters when losing track of a function (#5158)
  • 801ffd1 3.29.3
  • 353e462 Fully deoptimize first level path when deoptimizing nested parameter paths (#...
  • a1a89e7 chore(deps): update dependency @​vue/eslint-config-typescript to v12 (#5148)
  • cc14f70 chore(deps): lock file maintenance minor/patch updates (#5149)
  • 1e8355b docs: improve the docs repl appearance in the light mode (#5145)
  • 5950fc8 Adapt branches in REPL workflow
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [rollup](https://github.com/rollup/rollup) from 2.60.0 to 3.29.5.
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md)
- [Commits](rollup/rollup@v2.60.0...v3.29.5)

---
updated-dependencies:
- dependency-name: rollup
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested review from a team and mavarius as code owners September 24, 2024 08:43
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 24, 2024
@appletreeisyellow
appletreeisyellow merged commit 22d8536 into master Sep 24, 2024
@appletreeisyellow
appletreeisyellow deleted the dependabot/npm_and_yarn/rollup-3.29.5 branch September 24, 2024 13:50
jdstrand added a commit that referenced this pull request Aug 31, 2026
rollup 3 loads rollup.config.js as an ES module. rollup 2 transpiled it
to CommonJS first. The config uses require(), so rollup 3 fails with
"require is not defined in ES module scope" and the build never starts.

rollup moved from 2.60.0 to 3.29.5 in #925 and nothing detected this,
because no CI step built the package.

Moving forward instead is not possible today. @wessberg/rollup-plugin-ts
1.1.73 does not support the rollup 3 plugin API, and its successor
rollup-plugin-ts 3.4.5 depends on browserslist-generator, which uses the
removed `assert { type: ... }` import syntax that Node 22 and Node 24
both reject. A forward fix requires upgrading TypeScript off 3.8.3.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
jdstrand added a commit that referenced this pull request Sep 4, 2026
* chore(deps-dev): bump @babel/core from 7.16.0 to 7.29.6

Bumps [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) from 7.16.0 to 7.29.6.
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.29.6/packages/babel-core)

---
updated-dependencies:
- dependency-name: "@babel/core"
  dependency-version: 7.29.6
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix(build): pin rollup to ^2.60.0

rollup 3 loads rollup.config.js as an ES module. rollup 2 transpiled it
to CommonJS first. The config uses require(), so rollup 3 fails with
"require is not defined in ES module scope" and the build never starts.

rollup moved from 2.60.0 to 3.29.5 in #925 and nothing detected this,
because no CI step built the package.

Moving forward instead is not possible today. @wessberg/rollup-plugin-ts
1.1.73 does not support the rollup 3 plugin API, and its successor
rollup-plugin-ts 3.4.5 depends on browserslist-generator, which uses the
removed `assert { type: ... }` import syntax that Node 22 and Node 24
both reject. A forward fix requires upgrading TypeScript off 3.8.3.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(build): drop unused webpack devDependency

Nothing in this repo imports webpack. The build is rollup, and Storybook
resolves its own nested webpack 4.46.0, which is the version Storybook
6.3 expects. The hoisted webpack 5.94.0 served nothing.

It also broke the build. tsconfig typeRoots includes every @types/*
package as a global type, which pulls in webpack 5's bundled types.d.ts.
TypeScript 3.8.3 cannot parse it and fails with "Property or signature
expected" at types.d.ts:1894. webpack 4 ships no types.d.ts, so removing
the direct dependency clears the error at its source.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* chore(build): read package.json without require in rollup config

rollup.config.js mixed ES module imports with a CommonJS require. Read
the file with fs instead, so the config is valid ES module syntax.

No behaviour change under rollup 2. This stops the same failure
recurring if rollup 3 is attempted again.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* chore(ci): update to cimg/node:24.20

* chore(ci): run yarn build

CI ran yarn ci, which is test, lint and typecheck. It never ran the
rollup build, so nothing verified the artifact this package publishes.

The build was broken from 2024-09-24 until the earlier commits in this
branch. Two dependency bumps caused it and neither was detected, because
no CI step built the package.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* chore: pass --openssl-legacy-provider to storybook (for webpack v4)

webpack v4 uses MD4 which is removed from openssl 3. node 24 uses
openssl 3, so pass NODE_OPTIONS=--openssl-legacy-provider to storybook
until we can upgrade.

* chore(ci): add build-storybook

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Jamie Strandboge <jamie@influxdata.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant