Skip to content

chore(deps): rolling dependency update - #8

Open
socket-pr-bot[bot] wants to merge 1 commit into
mainfrom
weekly-update
Open

socket-pr-bot[bot] wants to merge 1 commit into
mainfrom
weekly-update

Conversation

@socket-pr-bot

@socket-pr-bot socket-pr-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown

Rolling dependency update

One long-lived PR, rebuilt from main on every run so it stays
mergeable. Each run appends its dependency delta below, newest first.

2026-09-21 — run · 5 updated
package from to
@anthropic-ai/claude-code 2.1.220 2.1.270
fast-check 4.9.0 4.10.0
rolldown-plugin-dts 0.28.4 0.28.5
vite 8.2.2 8.3.0
yaml 2.9.0 2.9.1
commits
  • chore(deps): apply weekly update fixes
2026-09-20 — run · 5 updated
package from to
@anthropic-ai/claude-code 2.1.220 2.1.270
fast-check 4.9.0 4.10.0
rolldown-plugin-dts 0.28.4 0.28.5
vite 8.2.2 8.3.0
yaml 2.9.0 2.9.1
commits
  • chore(deps): apply weekly update fixes
2026-09-19 — run · 5 updated
package from to
@anthropic-ai/claude-code 2.1.220 2.1.269
fast-check 4.9.0 4.10.0
rolldown-plugin-dts 0.28.4 0.28.5
vite 8.2.2 8.3.0
yaml 2.9.0 2.9.1
commits
  • chore(deps): apply weekly update fixes
2026-09-18 — run · 4 updated
package from to
@anthropic-ai/claude-code 2.1.220 2.1.268
fast-check 4.9.0 4.10.0
rolldown-plugin-dts 0.28.4 0.28.5
vite 8.2.2 8.3.0
commits
  • chore(deps): apply weekly update fixes

Note

Low Risk
Tooling and lockfile-only changes with semver-minor bumps; no application runtime or security-sensitive logic is modified.

Overview
This rolling dependency update bumps the fleet Node pin to 26.8.2 and refreshes the pnpm lockfile (including pinning the workspace pnpm binary to 12.4.1).

Catalog / direct bumps in pnpm-workspace.yaml: @anthropic-ai/claude-code (2.1.220 → 2.1.268), vite (8.2.2 → 8.3.0), fast-check (4.9.0 → 4.10.0), and rolldown-plugin-dts (0.28.4 → 0.28.5). The lockfile also picks up aligned override and transitive updates (e.g. magic-string 1.3.1, sharp 0.35.4, protobufjs 7.6.6, picomatch 4.0.7, content-type 2.1.0).

package.json devEngines now declares both npm and pnpm as allowed package managers (each with onFail: "error"), instead of only pnpm.

Reviewed by Cursor Bugbot for commit 7622c01. Configure here.

@socket-pr-bot socket-pr-bot Bot added automation Automated maintenance dependencies Dependency updates labels Sep 18, 2026
@socket-security-staging

socket-security-staging Bot commented Sep 18, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​fast-check@​4.9.0 ⏵ 4.10.0100 +110010090100
Updatednpm/​yaml@​2.9.0 ⏵ 2.9.1100 +110010092 +6100
Updatednpm/​magic-string@​1.2.3 ⏵ 1.3.1100100100 +197 +1100

View full report

@socket-security

socket-security Bot commented Sep 18, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​yaml@​2.9.0 ⏵ 2.9.1100 +110010090100
Updatednpm/​fast-check@​4.9.0 ⏵ 4.10.0100 +1100100 +190 -2100
Updatednpm/​magic-string@​1.2.3 ⏵ 1.3.1100100100 +197 +1100

View full report

@socket-pr-bot
socket-pr-bot Bot force-pushed the weekly-update branch 3 times, most recently from 8edcc32 to b1747d5 Compare September 21, 2026 08:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automation Automated maintenance dependencies Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants