build(deps): bump commander from 13.1.0 to 14.0.3#13
Closed
dependabot[bot] wants to merge 1 commit into
Closed
Conversation
Bumps [commander](https://github.com/tj/commander.js) from 13.1.0 to 14.0.3. - [Release notes](https://github.com/tj/commander.js/releases) - [Changelog](https://github.com/tj/commander.js/blob/master/CHANGELOG.md) - [Commits](tj/commander.js@v13.1.0...v14.0.3) --- updated-dependencies: - dependency-name: commander dependency-version: 14.0.3 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
efea878 to
9759825
Compare
7 tasks
Owner
|
Superseded by #18 (bulk dep bump). |
Author
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
theagenticguy
added a commit
that referenced
this pull request
Apr 23, 2026
## Summary Sweep of every outdated direct dependency in the workspace, bringing each one to its latest version — except for two intentional holds (TypeScript 6, Zod 4) that need their own migration PRs. ## What's bumped **Safe minors + patches** (no behavior changes on our surface): | Package | From | To | |---|---|---| | `@biomejs/biome` | 2.4.0 | 2.4.12 | | `fast-xml-parser` | 5.7.0 | 5.7.1 | | `piscina` | 5.1.3 | 5.1.4 | | `envinfo` | 7.14.0 | 7.21.0 | | `lru-cache` | 11.2.2 | 11.3.5 | **Safe majors** (no source-level breakage; verified via full build + test matrix): | Package | From | To | |---|---|---| | `@apidevtools/swagger-parser` | 10.1.1 | 12.1.0 | | `@commitlint/cli` | 19.6.1 | 20.5.0 | | `@commitlint/config-conventional` | 19.6.0 | 20.5.0 | | `@types/node` | 20.14.0 | 22.19.17 (Node 22 LTS) | | `commander` | 13.1.0 | 14.0.3 | | `listr2` | 9.0.4 | 10.2.1 | | `write-file-atomic` | 6.0.0 | 7.0.1 | **Deliberately deferred** (need real migration work; track in follow-up PRs): - `typescript` 5.9.3 → 6.x — many workspace deps peer-declare `typescript@^5`; the jump needs a compatibility sweep first. - `zod` 3 → 4 — breaking changes (`.merge()` → `.extend()`, stricter coercion, different result shape) that touch the MCP + SARIF schema layers. ## License allowlist update `lru-cache` switched its declared license from `ISC` → `BlueOak-1.0.0` at 11.3.x. BlueOak-1.0.0 is an OSI-approved permissive license (explicitly designed as an MIT/ISC-class modernization with no ShareAlike / attribution friction). Added `BlueOak-1.0.0` and `0BSD` to the CI license allowlist (`.github/workflows/ci.yml`, `mise.toml`) to match what's actually in the SBOM today. `SECURITY.md` + `CONTRIBUTING.md` updated to mirror. ## Supply chain - `osv-scanner` — 0 issues on the refreshed 705-package lockfile. - `SBOM.cdx.json` regenerated from the new lockfile. - `THIRD_PARTY_LICENSES.md` regenerated (705 components). ## Drive-by fix `packages/cli/src/commands/setup.test.ts` asserted the bundled plugin manifest version was `2.0.0` (stale from the pre-launch internal versioning). Updated to `0.1.0` to match the launch version and unblock `pnpm -r test`. ## Closes Should supersede these open Dependabot PRs (will auto-close on next scan): #6, #7, #8, #9, #10, #11, #12, #13, #14, #15. ## Test plan - [x] `pnpm install` resolves cleanly - [x] `pnpm -r build` — all workspaces green - [x] `pnpm -r exec tsc --noEmit` — 0 type errors - [x] `pnpm -r test` — 1 stale-assertion fixed, remainder green - [x] `bash scripts/check-banned-strings.sh` — PASS - [x] `osv-scanner scan source --lockfile=pnpm-lock.yaml` — 0 issues - [x] `license-checker-rseidelsohn --onlyAllow '...'` — 0 violations
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps commander from 13.1.0 to 14.0.3.
Release notes
Sourced from commander's releases.
Changelog
Sourced from commander's changelog.
... (truncated)
Commits
824736414.0.3e281fe3Update docs for 14.0.3 (#2474)7357ddaSeparate out a more detailed release policy document (#2462)b6e2e3aBump eslint from 9.39.1 to 9.39.2 (#2470)d6f63a7Bump ts-jest from 29.4.5 to 29.4.6 (#2467)2a9768aBump prettier from 3.6.2 to 3.7.4 (#2466)9211918docs(README): Tweak formatting, punctuation for clarity (#2465)4208a96Bump typescript-eslint from 8.46.2 to 8.48.0 (#2458)03308ceBump eslint-plugin-jest from 29.0.1 to 29.2.1 (#2457)4d2db1fBump globals from 16.4.0 to 16.5.0 (#2456)