Skip to content

Bump the development-dependencies group with 9 updates - #49

Merged
bluwy merged 1 commit into
mainfrom
dependabot/npm_and_yarn/development-dependencies-eba1dacb65
Oct 1, 2026
Merged

bluwy merged 1 commit into
mainfrom
dependabot/npm_and_yarn/development-dependencies-eba1dacb65

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the development-dependencies group with 9 updates:

Package From To
@changesets/changelog-github 1.0.0 1.0.1
@changesets/cli 3.0.1 3.0.3
@types/node 26.3.0 26.6.2
fs-fixture 2.14.0 2.16.0
oxfmt 0.65.0 0.70.0
tsdown 0.22.14 0.23.0
@biomejs/biome 2.5.10 2.5.14
dprint 0.56.1 0.57.4
prettier 3.9.6 3.9.9

Updates @changesets/changelog-github from 1.0.0 to 1.0.1

Release notes

Sourced from @​changesets/changelog-github's releases.

@​changesets/changelog-github@​1.0.1

Patch Changes

  • Updated dependencies [4d7b4fb]:
    • @​changesets/get-github-info@​1.0.1
Changelog

Sourced from @​changesets/changelog-github's changelog.

1.0.1

Patch Changes

  • Updated dependencies [4d7b4fb]:
    • @​changesets/get-github-info@​1.0.1
Commits

Updates @changesets/cli from 3.0.1 to 3.0.3

Release notes

Sourced from @​changesets/cli's releases.

@​changesets/cli@​3.0.3

Patch Changes

  • #2297 3f163da Thanks @​Andarist! - Fixed semver ranges (such as >=1.0.0 <2.0.0) getting cut off (>=2.0.0) when updating internal dependencies.

  • #2276 ca9d110 Thanks @​Andarist! - Fixed pnpm 10 compatibility with npm 12 when reading registry information, packing, and publishing packages.

  • Updated dependencies [3f163da, bfe9050, e522996]:

    • @​changesets/apply-release-plan@​8.1.1
    • @​changesets/config@​4.0.1

@​changesets/cli@​3.0.2

Patch Changes

Changelog

Sourced from @​changesets/cli's changelog.

3.0.3

Patch Changes

  • #2297 3f163da Thanks @​Andarist! - Fixed semver ranges (such as >=1.0.0 <2.0.0) getting cut off (>=2.0.0) when updating internal dependencies.

  • #2276 ca9d110 Thanks @​Andarist! - Fixed pnpm 10 compatibility with npm 12 when reading registry information, packing, and publishing packages.

  • Updated dependencies [3f163da, bfe9050, e522996]:

    • @​changesets/apply-release-plan@​8.1.1
    • @​changesets/config@​4.0.1

3.0.2

Patch Changes

Commits

Updates @types/node from 26.3.0 to 26.6.2

Commits

Updates fs-fixture from 2.14.0 to 2.16.0

Release notes

Sourced from fs-fixture's releases.

v2.16.0

2.16.0 (2026-09-03)

Features

  • read fixture root by default (121f1b9)

v2.15.0

2.15.0 (2026-08-31)

Features

  • add fixture initializer functions (fd5c6fb)
Commits
  • 121f1b9 feat: read fixture root by default
  • 827e62b build: upgrade lint and type tooling
  • 55ac41a build: upgrade package tooling
  • 1625195 test: upgrade manten and vfs
  • fd5c6fb feat: add fixture initializer functions
  • 5ceb1f8 chore: upgrade skills-npm to v1.2.0
  • 12362e6 ci: restrict release workflow to public org
  • See full diff in compare view

Updates oxfmt from 0.65.0 to 0.70.0

Release notes

Sourced from oxfmt's releases.

oxfmt v0.70.0

🚀 Features

  • 415b742 oxlint,oxfmt: Do not discover nested config in Vite+ mode (#26763) (leaysgur)
Commits

Updates tsdown from 0.22.14 to 0.23.0

Release notes

Sourced from tsdown's releases.

v0.23.0

   🧭 Migration Guide

Most users can upgrade directly. Before upgrading, run one final build with tsdown@0.22.14 and resolve all deprecation warnings.

  • config:
    • bundle: false → unbundle: true; bundle: true can be removed
    • outExtension → outExtensions
    • publicDir / --public-dir → copy / --copy
    • removeNodeProtocol: true → nodeProtocol: 'strip'
    • injectStyle → css.inject
  • deps:
    • inlineOnly / deps.onlyAllowBundle → deps.onlyBundle
    • skipNodeModulesBundle: true → deps.neverBundle: true
    • resolveDepSubpath now defaults to false; set it to true to preserve the previous behavior
  • dts:
    • rolldown-plugin-dts was upgraded from 0.27.13 to 0.28.5
    • dts.oxc: true → dts.generator: 'oxc'
    • dts.tsgo: true → dts.generator: 'tsgo'; oxc and tsgo objects now only configure their respective generators
    • dts.volarPlugins → dts.customLanguages; rename each language's create hook to createVolarPlugins
    • Custom languages, including vue, now throw when combined with an incompatible generator
    • dts.cjsReexport was removed; dual-format builds now generate CJS declarations in a separate pass
  • attw:
    • The default profile changed from strict to esm-only; set profile: 'strict' to preserve the previous checks
  • programmatic API:
    • build() now returns { bundles, watch }; replace const bundles = await build() with const { bundles } = await build()
  • requirements:
    • Node.js 25 is no longer supported; use ^22.18.0, ^24.11.0, or >=26.0.0
    • rolldown-plugin-dts now requires Rolldown 1.2.x
    • Legacy types and typesVersions fallbacks were removed; use TypeScript's bundler, node16, or nodenext module resolution

   🚨 Breaking Changes

   🚀 Features

... (truncated)

Commits

Updates @biomejs/biome from 2.5.10 to 2.5.14

Release notes

Sourced from @​biomejs/biome's releases.

Biome CLI v2.5.14

2.5.14

Patch Changes

  • #9022 0d49e24 Thanks @​dyc3! - Added the nursery rule noReturnInFinally. This rule disallows return statements in Promise.prototype.finally() callbacks, including inside nested blocks and conditional branches. Returns in nested functions are ignored by the rule.

    // Invalid: return in finally callback
    Promise.resolve(1).finally(() => { return 2 })
    // Valid: no return in finally callback
    Promise.resolve(1).finally(() => { console.log(2) })

    Returning a value from a Promise.prototype.finally() callback does not replace the original promise's fulfillment value, which can be confusing. Returned promises and thenables are awaited, and their rejection rejects the resulting promise.

  • #11754 71eaa0d Thanks @​griff-rees! - Added the nursery rule noSvelteAtDebugTags, which disallows Svelte's {@debug} tag.

    <!-- Invalid: leftover debugging tag -->
    {@debug user}

    The {@debug} tag is a debugging aid and should be removed once you no longer need it, as it should not remain in production code. The rule provides a safe fix that removes the tag.

  • #11725 5eb5f09 Thanks @​m1handr! - Added the nursery rule useValidTestTitle, which enforces valid titles for unit test cases and suites.

  • #11735 9bd70c7 Thanks @​ematipico! - Fixed #8471: source.fixAll.biome ignored formatter.formatWithErrors. It now applies safe fixes without formatting files that have parse errors when the option is disabled.

  • #11715 f05a3c3 Thanks @​ematipico! - Fixed #7771: Grit plugins that use sequential no longer panic when Biome processes files.

  • #11766 c2542c6 Thanks @​dyc3! - Fixed validation of readonly and accessor modifiers: combining them in either order now reports that they cannot be used together.

  • #11461 22e9966 Thanks @​FoundDream! - Fixed #11423: Multiline template interpolations now preserve the indentation of their closing brace when the source indentation is not a multiple of tabWidth.

     const value = `
          ${
            condition
              ? "yes"
              : "no"
    -}
    +     }
     `;
  • #11766 c2542c6 Thanks @​dyc3! - Fixed #11763: TypeScript class members using override accessor, such as override accessor value = 1, now parse correctly. The reversed order, accessor override, now reports that override must precede accessor.

... (truncated)

Changelog

Sourced from @​biomejs/biome's changelog.

2.5.14

Patch Changes

  • #9022 0d49e24 Thanks @​dyc3! - Added the nursery rule noReturnInFinally. This rule disallows return statements in Promise.prototype.finally() callbacks, including inside nested blocks and conditional branches. Returns in nested functions are ignored by the rule.

    // Invalid: return in finally callback
    Promise.resolve(1).finally(() => { return 2 })
    // Valid: no return in finally callback
    Promise.resolve(1).finally(() => { console.log(2) })

    Returning a value from a Promise.prototype.finally() callback does not replace the original promise's fulfillment value, which can be confusing. Returned promises and thenables are awaited, and their rejection rejects the resulting promise.

  • #11754 71eaa0d Thanks @​griff-rees! - Added the nursery rule noSvelteAtDebugTags, which disallows Svelte's {@debug} tag.

    <!-- Invalid: leftover debugging tag -->
    {@debug user}

    The {@debug} tag is a debugging aid and should be removed once you no longer need it, as it should not remain in production code. The rule provides a safe fix that removes the tag.

  • #11725 5eb5f09 Thanks @​m1handr! - Added the nursery rule useValidTestTitle, which enforces valid titles for unit test cases and suites.

  • #11735 9bd70c7 Thanks @​ematipico! - Fixed #8471: source.fixAll.biome ignored formatter.formatWithErrors. It now applies safe fixes without formatting files that have parse errors when the option is disabled.

  • #11715 f05a3c3 Thanks @​ematipico! - Fixed #7771: Grit plugins that use sequential no longer panic when Biome processes files.

  • #11766 c2542c6 Thanks @​dyc3! - Fixed validation of readonly and accessor modifiers: combining them in either order now reports that they cannot be used together.

  • #11461 22e9966 Thanks @​FoundDream! - Fixed #11423: Multiline template interpolations now preserve the indentation of their closing brace when the source indentation is not a multiple of tabWidth.

     const value = `
          ${
            condition
              ? "yes"
              : "no"
    -}
    +     }
     `;
  • #11766 c2542c6 Thanks @​dyc3! - Fixed #11763: TypeScript class members using override accessor, such as override accessor value = 1, now parse correctly. The reversed order, accessor override, now reports that override must precede accessor.

  • #11790 17d0ff0 Thanks @​ematipico! - Fixed #10248: noUselessFragments now allows fragments with props in Astro files, such as <Fragment slot="name">{text}</Fragment> inside template expressions.

... (truncated)

Commits

Updates dprint from 0.56.1 to 0.57.4

Release notes

Sourced from dprint's releases.

0.57.4

Changes

  • fix: include wasmtime's precompile compatibility hash in the plugin cache key (#1245)

Install

Run dprint upgrade or see https://dprint.dev/install/

Verification

These artifacts have build provenance attestations. Verify a download with the GitHub CLI:

gh attestation verify dprint-x86_64-unknown-linux-gnu.zip --repo dprint/dprint

Checksums

Artifact SHA-256 Checksum
dprint-x86_64-apple-darwin.zip 8978bd5d9a564ec19472545fb853da9ec468e024e75d39c3a9df9fd5750ecdfd
dprint-aarch64-apple-darwin.zip f9e752812791f258e89ff88a7affd05c793b0db3d929718651eae7df5f19eb2e
dprint-x86_64-pc-windows-msvc.zip 1038af32fade7a79f9c3a690d9546bb17be13dd7b4568a3684692fdcb0a52a1d
dprint-x86_64-pc-windows-msvc-installer.exe a6f89e60c7c63b3cf29fbb8c8ab8b4f9821b94bcbac6f76f35ef5b47932e2d51
dprint-aarch64-pc-windows-msvc.zip 72fb7d97861533b5a611ffd176229bdb8673edd24203bd967d1cece803d6b31d
dprint-x86_64-unknown-linux-gnu.zip 1d26357d8bc66898d4ecc7dafca3d2971cfe222ba487228bd2ce5c3b3a309c33
dprint-x86_64-unknown-linux-musl.zip 03f3e8002f9d952bf53325fc8853686d2e8808b9e5b652b215600ba147e73a5c
dprint-aarch64-unknown-linux-gnu.zip ff961314e7c1ca6a02eaada0e37920a37c668fbc09fd85838c2aced41a4bc0e4
dprint-aarch64-unknown-linux-musl.zip e1b713806f7f7b94072ba2b069aa19ac28f475dbb1fbc5b672d3030a2ab001ee
dprint-riscv64gc-unknown-linux-gnu.zip 04a90c94c0b22d165088ff680644225910125b99731348a82fd7bf2926b9edee
dprint-loongarch64-unknown-linux-gnu.zip e69a55aa4b242a1870b2a1e39ba03239950ea956a4fab886dc6580c41c29644a
dprint-loongarch64-unknown-linux-musl.zip 2ff5a32f8d2f641cb252636c79972e59db0a7a40f11699cbbddd76cbb063a31c
dprint-powerpc64le-unknown-linux-gnu.zip 5232a896fb1b957c9cbf589d4581077f1ea8d22cdcb20284d399a37b0d26ca77
dprint-powerpc64le-unknown-linux-musl.zip a7e1cba0b951bce0355e18f9045fe461244b6c022e5bd2a2061616aa14530880
dprint-aarch64-linux-android.zip 5e23986c4fc715bc12d80fc4580f786def8c1a2a770aa1615dd06991acd83456
dprint-x86_64-linux-android.zip 4a6a286a21970cb1db63840d0e2b04fd2d6bc793614d5b0069384fa266a0cef6

0.57.3

Changes

  • fix: only rewrite the incremental file when new file hashes were seen (#1244)

Install

Run dprint upgrade or see https://dprint.dev/install/

... (truncated)

Commits
  • abd996b 0.57.4
  • ea61629 fix: include wasmtime's precompile compatibility hash in the plugin cache key...
  • fcc19bc 0.57.3
  • f5a4777 fix: only rewrite the incremental file when new file hashes were seen (#1244)
  • c4875ba 0.57.2
  • f381e44 fix: output paths relative to the cwd in dprint incremental-state (#1243)
  • a7cbd8c 0.57.1
  • 4f8ecc6 fix: scan hidden directories with dprint init (#1240)
  • f2528a1 feat: accept --minimum-release-age as an alias of `--minimum-dependency-age...
  • 03f2e9c fix: recommend --minimum-dependency-age=0 when an older version is selected...
  • Additional commits viewable in compare view

Updates prettier from 3.9.6 to 3.9.9

Release notes

Sourced from prettier's releases.

3.9.9

  • Markdown: Fix text with $ been incorrectly parsed as math syntax (#20140 by @​fisker)

🔗 Changelog

3.9.8

  • Markdown: Don't let Liquid objects interrupt paragraphs (#20087 by @​seiyab)

🔗 Changelog

3.9.7

  • Support Angular 22.2
  • Fix regressions in v3.9

🔗 Changelog

Changelog

Sourced from prettier's changelog.

3.9.9

diff

Markdown: Fix text with $ been incorrectly parsed as math syntax (#20140 by @​fisker)

<!-- Input -->
**Uses $FOO** from `a.sh` and `b.sh`, plus `$BAR` from `c.sh`, before anything else runs here.
<!-- Prettier 3.9.8 -->
Uses $FOO from a.sh and b.sh, plus $BARfromc.sh, before anything else runs here.
<!-- Prettier 3.9.9 -->
Uses $FOO from a.sh and b.sh, plus $BAR from c.sh, before anything else runs here.

3.9.8

diff

Markdown: Don't let Liquid objects interrupt paragraphs (#20087 by @​seiyab)

<!-- Input -->
If `module` is not a [`WebAssembly.Module`](https://github.com/prettier/prettier/blob/main/en-US/docs/WebAssembly/Reference/JavaScript_interface/Module) object instance, a
{{jsxref("TypeError")}} is thrown.
<!-- Prettier 3.9.7 -->
If module is not a WebAssembly.Module object instance, a
{{jsxref("TypeError")}} is thrown.
<!-- Prettier 3.9.8 -->
If module is not a WebAssembly.Module object instance, a
{{jsxref("TypeError")}} is thrown.

3.9.7

diff

Markdown: Prevent indentation drift in list-item code blocks (#19647, #19990 by @​Austin1serb, @​giaBaoJS)

<!-- Input -->
- [x] short first line.
</tr></table> 

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the development-dependencies group with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [@changesets/changelog-github](https://github.com/changesets/changesets/tree/HEAD/packages/changelog-github) | `1.0.0` | `1.0.1` |
| [@changesets/cli](https://github.com/changesets/changesets/tree/HEAD/packages/cli) | `3.0.1` | `3.0.3` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.3.0` | `26.6.2` |
| [fs-fixture](https://github.com/privatenumber/fs-fixture) | `2.14.0` | `2.16.0` |
| [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.65.0` | `0.70.0` |
| [tsdown](https://github.com/rolldown/tsdown) | `0.22.14` | `0.23.0` |
| [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) | `2.5.10` | `2.5.14` |
| [dprint](https://github.com/dprint/dprint) | `0.56.1` | `0.57.4` |
| [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.9` |


Updates `@changesets/changelog-github` from 1.0.0 to 1.0.1
- [Release notes](https://github.com/changesets/changesets/releases)
- [Changelog](https://github.com/changesets/changesets/blob/main/packages/changelog-github/CHANGELOG.md)
- [Commits](https://github.com/changesets/changesets/commits/@changesets/changelog-github@1.0.1/packages/changelog-github)

Updates `@changesets/cli` from 3.0.1 to 3.0.3
- [Release notes](https://github.com/changesets/changesets/releases)
- [Changelog](https://github.com/changesets/changesets/blob/main/packages/cli/CHANGELOG.md)
- [Commits](https://github.com/changesets/changesets/commits/@changesets/cli@3.0.3/packages/cli)

Updates `@types/node` from 26.3.0 to 26.6.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `fs-fixture` from 2.14.0 to 2.16.0
- [Release notes](https://github.com/privatenumber/fs-fixture/releases)
- [Commits](privatenumber/fs-fixture@v2.14.0...v2.16.0)

Updates `oxfmt` from 0.65.0 to 0.70.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.70.0/npm/oxfmt)

Updates `tsdown` from 0.22.14 to 0.23.0
- [Release notes](https://github.com/rolldown/tsdown/releases)
- [Commits](rolldown/tsdown@v0.22.14...v0.23.0)

Updates `@biomejs/biome` from 2.5.10 to 2.5.14
- [Release notes](https://github.com/biomejs/biome/releases)
- [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md)
- [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.14/packages/@biomejs/biome)

Updates `dprint` from 0.56.1 to 0.57.4
- [Release notes](https://github.com/dprint/dprint/releases)
- [Commits](dprint/dprint@0.56.1...0.57.4)

Updates `prettier` from 3.9.6 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.6...3.9.9)

---
updated-dependencies:
- dependency-name: "@changesets/changelog-github"
  dependency-version: 1.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: "@changesets/cli"
  dependency-version: 3.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.6.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: fs-fixture
  dependency-version: 2.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: oxfmt
  dependency-version: 0.70.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: tsdown
  dependency-version: 0.23.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: "@biomejs/biome"
  dependency-version: 2.5.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: dprint
  dependency-version: 0.57.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: prettier
  dependency-version: 3.9.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 1, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updateddprint@​0.56.1 ⏵ 0.57.4911007095 +2100
Updated@​changesets/​cli@​3.0.1 ⏵ 3.0.399 +110074 +195 -1100
Updated@​types/​node@​26.3.0 ⏵ 26.6.2100 +110081 +196100
Updatedoxfmt@​0.65.0 ⏵ 0.70.086 +110088 +196 +1100
Updatedtsdown@​0.22.14 ⏵ 0.23.09810088 +196 +1100
Updatedfs-fixture@​2.14.0 ⏵ 2.16.094 +910097 +192 +3100
Updated@​changesets/​changelog-github@​1.0.0 ⏵ 1.0.11001009595 +2100
Updatedprettier@​3.9.6 ⏵ 3.9.99810097 +199100
Updated@​biomejs/​biome@​2.5.10 ⏵ 2.5.14100 +1100100 +198 -1100

View full report

@bluwy
bluwy added this pull request to the merge queue Oct 1, 2026
Merged via the queue into main with commit 1c0744c Oct 1, 2026
8 checks passed
@bluwy
bluwy deleted the dependabot/npm_and_yarn/development-dependencies-eba1dacb65 branch October 1, 2026 10:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant