Skip to content

build(deps): bump ghcr.io/devcontainers/features/node from 1.7.1 to 2.0.0#11784

Merged
sk593 merged 3 commits intomainfrom
dependabot/devcontainers/ghcr.io/devcontainers/features/node-2.0.0
May 4, 2026
Merged

build(deps): bump ghcr.io/devcontainers/features/node from 1.7.1 to 2.0.0#11784
sk593 merged 3 commits intomainfrom
dependabot/devcontainers/ghcr.io/devcontainers/features/node-2.0.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 30, 2026

Bumps ghcr.io/devcontainers/features/node from 1.7.1 to 2.0.0.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps ghcr.io/devcontainers/features/node from 1.7.1 to 2.0.0.

---
updated-dependencies:
- dependency-name: ghcr.io/devcontainers/features/node
  dependency-version: 2.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file devcontainers_package_manager Pull requests that update devcontainers_package_manager code labels Apr 30, 2026
Copilot AI review requested due to automatic review settings April 30, 2026 03:13
@dependabot dependabot Bot requested review from a team as code owners April 30, 2026 03:13
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file devcontainers_package_manager Pull requests that update devcontainers_package_manager code labels Apr 30, 2026
@dependabot dependabot Bot review requested due to automatic review settings April 30, 2026 03:13
@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 30, 2026

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

Copilot AI review requested due to automatic review settings May 4, 2026 16:48
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the devcontainer Node feature dependency to the new major version (ghcr.io/devcontainers/features/node from :1 / 1.7.1 to :2 / 2.0.0) to keep the contributor devcontainer environment up to date.

Changes:

  • Bump the Node devcontainer feature reference from ghcr.io/devcontainers/features/node:1 to ghcr.io/devcontainers/features/node:2.
  • Update the devcontainer lockfile entry to 2.0.0 with the corresponding new image digest.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
.devcontainer/devcontainer.json Updates the Node feature major version from :1 to :2 while keeping Node configured at version 24.
.devcontainer/devcontainer-lock.json Updates the locked Node feature version/digest to 2.0.0 to match the devcontainer feature bump.

@sk593 sk593 merged commit f1bcb28 into main May 4, 2026
45 checks passed
@sk593 sk593 deleted the dependabot/devcontainers/ghcr.io/devcontainers/features/node-2.0.0 branch May 4, 2026 18:46
sylvainsf added a commit that referenced this pull request May 4, 2026
The dependabot bump in #11784 wrote the JSON without a trailing newline,
which fails prettier's format check on every PR that gets merged with
main. Reformatted via 'make format-write'.
sk593 pushed a commit that referenced this pull request May 4, 2026
The dependabot bump in #11784 wrote the JSON without a trailing newline,
which fails prettier's format check on every PR that gets merged with
main. Reformatted via 'make format-write'.
sk593 added a commit that referenced this pull request May 4, 2026
….0.0 (#11784)

Bumps ghcr.io/devcontainers/features/node from 1.7.1 to 2.0.0.

[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ghcr.io/devcontainers/features/node&package-manager=devcontainers&previous-version=1.7.1&new-version=2.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Shruthi Kumar <shruthikumar@microsoft.com>
Signed-off-by: sk593 <shruthikumar@microsoft.com>
sk593 pushed a commit that referenced this pull request May 4, 2026
The dependabot bump in #11784 wrote the JSON without a trailing newline,
which fails prettier's format check on every PR that gets merged with
main. Reformatted via 'make format-write'.

Signed-off-by: sk593 <shruthikumar@microsoft.com>
sk593 pushed a commit that referenced this pull request May 4, 2026
The dependabot bump in #11784 wrote the JSON without a trailing newline,
which fails prettier's format check on every PR that gets merged with
main. Reformatted via 'make format-write'.
sk593 pushed a commit that referenced this pull request May 4, 2026
The dependabot bump in #11784 wrote the JSON without a trailing newline,
which fails prettier's format check on every PR that gets merged with
main. Reformatted via 'make format-write'.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file devcontainers_package_manager Pull requests that update devcontainers_package_manager code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants