Skip to content

build(deps): consolidate 12 dependabot bumps#51

Merged
theagenticguy merged 2 commits into
mainfrom
chore/deps-consolidate
Apr 30, 2026
Merged

build(deps): consolidate 12 dependabot bumps#51
theagenticguy merged 2 commits into
mainfrom
chore/deps-consolidate

Conversation

@theagenticguy
Copy link
Copy Markdown
Owner

@theagenticguy theagenticguy commented Apr 30, 2026

Summary

Consolidates all 12 open dependabot PRs into a single branch so they can land together with one CI cycle.

npm deps

GitHub Actions

Drive-by fixes

  • Bump biome.json $schema URL to 2.4.13 to match the new CLI version.
  • Drop a stale local-only ignore line that was tripping the banned-strings guardrail (added in b848c2f) and blocking every local commit via lefthook.

Test plan

  • pnpm install — no peer warnings introduced beyond those already present on main
  • pnpm run build — all 15 packages build
  • pnpm run typecheck — clean
  • pnpm -r test — 1627 pass, 0 fail across all packages
  • lefthook pre-commit (biome + banned-strings) passes

Does NOT touch the pnpm.onlyBuiltDependencies list — verified by diff, because prior sessions saw pnpm approve-builds destructively rewrite it.

npm deps:
- @aws-sdk/client-bedrock-runtime 3.1035.0 → 3.1040.0 (#50)
- @commitlint/cli 20.5.0 → 20.5.3 (#49)
- fast-xml-parser 5.7.1 → 5.7.2 (#48)
- sharp ^0.34.1 → ^0.34.5 (#47)
- astro ^6.1.9 → ^6.2.1 (#46)
- ts-morph ^25.0.1 → ^28.0.0 (#45)
- @bufbuild/protobuf 2.11.0 → 2.12.0 (#44)
- ajv 8.18.0 → 8.20.0 (#43)
- typescript-tooling group: @biomejs/biome 2.4.12 → 2.4.13, @types/node 24.12.2 → 25.6.0 (#42)

github actions:
- actions/cache v4 → v5 (#41)
- googleapis/release-please-action v4 → v5 (#40)
- actions/github-script v7 → v9 (#39)

Drive-by fixes:
- Bump biome.json \$schema to 2.4.13 to match the new CLI.
- Remove .gitnexus from .gitignore — it was tripping the banned-strings
  guardrail (added in b848c2f) and blocking every commit via lefthook.

Verified: pnpm install, pnpm build, pnpm typecheck, pnpm -r test all pass.
derive.test.ts and context.ts had format errors that were already failing
CI on main before this branch started. Fix here so the consolidated deps
PR can go green.
@theagenticguy theagenticguy merged commit 283c2be into main Apr 30, 2026
19 checks passed
@theagenticguy theagenticguy deleted the chore/deps-consolidate branch April 30, 2026 23:05
theagenticguy added a commit that referenced this pull request May 1, 2026
## Summary

Consolidates all 12 open dependabot PRs into a single branch so they can
land together with one CI cycle.

### npm deps
- `@aws-sdk/client-bedrock-runtime` 3.1035.0 → 3.1040.0 — closes #50
- `@commitlint/cli` 20.5.0 → 20.5.3 — closes #49
- `fast-xml-parser` 5.7.1 → 5.7.2 — closes #48
- `sharp` ^0.34.1 → ^0.34.5 — closes #47
- `astro` ^6.1.9 → ^6.2.1 — closes #46
- `ts-morph` ^25.0.1 → ^28.0.0 — closes #45
- `@bufbuild/protobuf` 2.11.0 → 2.12.0 — closes #44
- `ajv` 8.18.0 → 8.20.0 — closes #43
- typescript-tooling group (`@biomejs/biome` 2.4.12 → 2.4.13,
`@types/node` 24.12.2 → 25.6.0) — closes #42

### GitHub Actions
- `actions/cache` v4 → v5 — closes #41
- `googleapis/release-please-action` v4 → v5 — closes #40
- `actions/github-script` v7 → v9 — closes #39

### Drive-by fixes
- Bump `biome.json` `$schema` URL to 2.4.13 to match the new CLI
version.

## Test plan
- [x] `pnpm install` — no peer warnings introduced beyond those already
present on main
- [x] `pnpm run build` — all 15 packages build
- [x] `pnpm run typecheck` — clean
- [x] `pnpm -r test` — 1627 pass, 0 fail across all packages
- [x] lefthook pre-commit (biome + banned-strings) passes

Does NOT touch the `pnpm.onlyBuiltDependencies` list — verified by diff,
because prior sessions saw `pnpm approve-builds` destructively rewrite
it.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant