Skip to content

build(deps-dev): bump @commitlint/config-conventional from 20.5.0 to 20.5.3#60

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/commitlint/config-conventional-20.5.3
Closed

build(deps-dev): bump @commitlint/config-conventional from 20.5.0 to 20.5.3#60
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/commitlint/config-conventional-20.5.3

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github May 4, 2026

Bumps @commitlint/config-conventional from 20.5.0 to 20.5.3.

Release notes

Sourced from @​commitlint/config-conventional's releases.

v20.5.3

20.5.3 (2026-04-30)

Refactor

Docs

New Contributors

Full Changelog: conventional-changelog/commitlint@v20.5.2...v20.5.3

v20.5.2

20.5.2 (2026-04-25)

Just minor dep updates before the next breaking change

Chore & Docs

New Contributors

Full Changelog: conventional-changelog/commitlint@v20.5.1...v20.5.2

v20.5.1

20.5.1 (2026-03-31)

Bug Fixes

Reverts

... (truncated)

Changelog

Sourced from @​commitlint/config-conventional's changelog.

20.5.3 (2026-04-30)

Note: Version bump only for package @​commitlint/config-conventional

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 4, 2026
Bumps [@commitlint/config-conventional](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/config-conventional) from 20.5.0 to 20.5.3.
- [Release notes](https://github.com/conventional-changelog/commitlint/releases)
- [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/config-conventional/CHANGELOG.md)
- [Commits](https://github.com/conventional-changelog/commitlint/commits/v20.5.3/@commitlint/config-conventional)

---
updated-dependencies:
- dependency-name: "@commitlint/config-conventional"
  dependency-version: 20.5.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/commitlint/config-conventional-20.5.3 branch from 86d1860 to 98b50c4 Compare May 6, 2026 03:34
@dependabot @github
Copy link
Copy Markdown
Author

dependabot Bot commented on behalf of github May 8, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/commitlint/config-conventional-20.5.3 branch May 8, 2026 13:32
theagenticguy added a commit that referenced this pull request May 10, 2026
## Summary

One PR that takes in all 10 open Dependabot bumps so pnpm-lock only has
to resolve once. All versions match the Dependabot PRs exactly. Bumps
are drops-in — no code changes needed.

### Closes

- Closes #67 — `@aws-sdk/client-sagemaker-runtime` 3.1035.0 → 3.1043.0
(`packages/embedder`)
- Closes #66 — `fast-xml-parser` 5.7.2 → 5.7.3 (`packages/ingestion`)
- Closes #65 — `@aws-sdk/client-bedrock-runtime` 3.1040.0 → 3.1043.0
(`packages/ingestion`, `summarizer`, `wiki`)
- Closes #63 — `lru-cache` 11.3.5 → 11.3.6 (`packages/mcp`)
- Closes #62 — `yaml` 2.8.3 → 2.8.4 (`packages/frameworks`, `sarif`,
`cli`, `policy`)
- Closes #60 — `@commitlint/config-conventional` 20.5.0 → 20.5.3 (root
devDep)
- Closes #59 — `zod` 4.3.6 → 4.4.3 (`packages/frameworks`, `mcp`,
`sarif`, `policy`, `summarizer`)
- Closes #57 — `snyk-nodejs-lockfile-parser` 2.7.0 → 2.7.1
(`packages/ingestion`)
- Closes #56 — `onnxruntime-node` 1.24.3 → 1.25.1 (`packages/embedder`)
- Closes #55 — `@biomejs/biome` 2.4.13 → 2.4.14 (root devDep)

Mise pins (`node = "22"`, `pnpm = "10.33.2"`, `python = "3.12"`, `uv =
"latest"`) left alone — none of the Dependabot PRs touch them and a pnpm
10→11 jump would be a major change out of scope.

## Test plan

- [x] `pnpm install` resolves cleanly, lockfile regenerates without
workarounds
- [x] `pnpm -r clean && pnpm -r build` succeeds (all workspace packages
build)
- [x] `pnpm -r exec tsc --noEmit` passes (14 stale-`dist` errors in
`packages/search` were pre-existing on main before a fresh build and
clear after)
- [x] `pnpm -r test` passes (225 CLI tests + 150 MCP tests + rest; the 2
earlier MCP failures were stale `dist/tools/pack-codebase.test.js`
leftovers from a prior branch's build and disappeared after `pnpm -r
clean`)
- [x] `pnpm run lint` passes (biome 2.4.14 surfaces 6 warnings / 1 info
on existing test code, non-blocking)
- [x] `pnpm run banned-strings` passes
- [x] `lefthook` pre-commit + commit-msg + pre-push hooks all green

## Notes

- Root `pnpm.onlyBuiltDependencies` was **not** touched by this change —
preserved `onnxruntime-node`, `@duckdb/node-api`, tree-sitter natives,
etc. exactly as they were.
- The `fast-xml-parser@<5.7.0: 5.7.1` override is still in
`package.json` for transitive resolution of older versions — left
intact.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants