Skip to content

build(deps): bump write-file-atomic from 6.0.0 to 7.0.1#8

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/write-file-atomic-7.0.1
Closed

build(deps): bump write-file-atomic from 6.0.0 to 7.0.1#8
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/write-file-atomic-7.0.1

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github Apr 22, 2026

Bumps write-file-atomic from 6.0.0 to 7.0.1.

Release notes

Sourced from write-file-atomic's releases.

v7.0.1

7.0.1 (2026-02-26)

Bug Fixes

Dependencies

Chores

v7.0.0

7.0.0 (2025-10-22)

⚠️ BREAKING CHANGES

  • write-file-atomic now supports node ^20.17.0 || >=22.9.0

Bug Fixes

Chores

Changelog

Sourced from write-file-atomic's changelog.

7.0.1 (2026-02-26)

Bug Fixes

Dependencies

Chores

7.0.0 (2025-10-22)

⚠️ BREAKING CHANGES

  • write-file-atomic now supports node ^20.17.0 || >=22.9.0

Bug Fixes

Chores

Commits
  • f54fa15 chore: release 7.0.1 (#230)
  • 727e92c deps: remove imurmurhash
  • da246ef fix: use node:crypto instead of imurmurhash
  • 0c819a3 chore: bump @​npmcli/template-oss from 4.28.0 to 4.28.1 (#223)
  • d6ad0c2 chore: bump @​npmcli/template-oss from 4.27.1 to 4.28.0 (#222)
  • 4785863 chore: bump @​npmcli/eslint-config from 5.1.0 to 6.0.0 (#221)
  • 2d6070a chore: release 7.0.0 (#220)
  • 05b67bd fix!: align to npm 11 node engine range (#219)
  • 602f2ad chore: bump @​npmcli/template-oss from 4.26.0 to 4.27.1 (#218)
  • 1cb18b0 chore: bump @​npmcli/template-oss from 4.25.1 to 4.26.0 (#217)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for write-file-atomic since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 22, 2026
Bumps [write-file-atomic](https://github.com/npm/write-file-atomic) from 6.0.0 to 7.0.1.
- [Release notes](https://github.com/npm/write-file-atomic/releases)
- [Changelog](https://github.com/npm/write-file-atomic/blob/main/CHANGELOG.md)
- [Commits](npm/write-file-atomic@v6.0.0...v7.0.1)

---
updated-dependencies:
- dependency-name: write-file-atomic
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/write-file-atomic-7.0.1 branch from 77c4a7a to 1bd5257 Compare April 23, 2026 00:07
@theagenticguy
Copy link
Copy Markdown
Owner

Superseded by #18 (bulk dep bump).

@dependabot @github
Copy link
Copy Markdown
Author

dependabot Bot commented on behalf of github Apr 23, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@theagenticguy theagenticguy deleted the dependabot/npm_and_yarn/write-file-atomic-7.0.1 branch April 23, 2026 00:10
theagenticguy added a commit that referenced this pull request Apr 23, 2026
## Summary

Sweep of every outdated direct dependency in the workspace, bringing
each one to its latest version — except for two intentional holds
(TypeScript 6, Zod 4) that need their own migration PRs.

## What's bumped

**Safe minors + patches** (no behavior changes on our surface):

| Package | From | To |
|---|---|---|
| `@biomejs/biome` | 2.4.0 | 2.4.12 |
| `fast-xml-parser` | 5.7.0 | 5.7.1 |
| `piscina` | 5.1.3 | 5.1.4 |
| `envinfo` | 7.14.0 | 7.21.0 |
| `lru-cache` | 11.2.2 | 11.3.5 |

**Safe majors** (no source-level breakage; verified via full build +
test matrix):

| Package | From | To |
|---|---|---|
| `@apidevtools/swagger-parser` | 10.1.1 | 12.1.0 |
| `@commitlint/cli` | 19.6.1 | 20.5.0 |
| `@commitlint/config-conventional` | 19.6.0 | 20.5.0 |
| `@types/node` | 20.14.0 | 22.19.17 (Node 22 LTS) |
| `commander` | 13.1.0 | 14.0.3 |
| `listr2` | 9.0.4 | 10.2.1 |
| `write-file-atomic` | 6.0.0 | 7.0.1 |

**Deliberately deferred** (need real migration work; track in follow-up
PRs):

- `typescript` 5.9.3 → 6.x — many workspace deps peer-declare
`typescript@^5`; the jump needs a compatibility sweep first.
- `zod` 3 → 4 — breaking changes (`.merge()` → `.extend()`, stricter
coercion, different result shape) that touch the MCP + SARIF schema
layers.

## License allowlist update

`lru-cache` switched its declared license from `ISC` → `BlueOak-1.0.0`
at 11.3.x. BlueOak-1.0.0 is an OSI-approved permissive license
(explicitly designed as an MIT/ISC-class modernization with no
ShareAlike / attribution friction).

Added `BlueOak-1.0.0` and `0BSD` to the CI license allowlist
(`.github/workflows/ci.yml`, `mise.toml`) to match what's actually in
the SBOM today. `SECURITY.md` + `CONTRIBUTING.md` updated to mirror.

## Supply chain

- `osv-scanner` — 0 issues on the refreshed 705-package lockfile.
- `SBOM.cdx.json` regenerated from the new lockfile.
- `THIRD_PARTY_LICENSES.md` regenerated (705 components).

## Drive-by fix

`packages/cli/src/commands/setup.test.ts` asserted the bundled plugin
manifest version was `2.0.0` (stale from the pre-launch internal
versioning). Updated to `0.1.0` to match the launch version and unblock
`pnpm -r test`.

## Closes

Should supersede these open Dependabot PRs (will auto-close on next
scan): #6, #7, #8, #9, #10, #11, #12, #13, #14, #15.

## Test plan

- [x] `pnpm install` resolves cleanly
- [x] `pnpm -r build` — all workspaces green
- [x] `pnpm -r exec tsc --noEmit` — 0 type errors
- [x] `pnpm -r test` — 1 stale-assertion fixed, remainder green
- [x] `bash scripts/check-banned-strings.sh` — PASS
- [x] `osv-scanner scan source --lockfile=pnpm-lock.yaml` — 0 issues
- [x] `license-checker-rseidelsohn --onlyAllow '...'` — 0 violations
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant