Skip to content

chore(deps-dev): bump cspell from 10.3.0 to 10.3.6 - #678

Open
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/cspell-10.3.3
Open

dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/npm_and_yarn/cspell-10.3.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Bumps cspell from 10.3.0 to 10.3.6.

Release notes

Sourced from cspell's releases.

v10.3.6

Fixes

fix: Report unknown CSpell directives again (#9319)

Summary

cspell lint reports unknown in-document directives again, such as cspell:bad-dir, when --validate-directives or validateDirectives: true in the config asks for them. Since 9.1.0 they were found but never shown or counted.

  • --validate-directives and --no-validate-directives override the config setting.
  • An unknown directive counts as an issue, so cspell lint exits with an error, as it did before 9.1.0.
  • The JSON reporter, @cspell/cspell-json-reporter, includes them in its output again.
  • The default reporter and the JSON reporter now ask to receive directive issues. Other reporters still only get them if they ask for them.
  • The command-line flag is now applied as a setting, like --report, so it controls what is shown as well as what is checked.

fix(cspell-io): Keep redirected requests under the private root (#9329)

Summary

createRedirectProvider in cspell-io now only serves requests that map to a location under its private root. A request that would resolve outside the private root is refused with VFSErrorUnsupportedRequest, the same error as a request outside the public root.

  • Refused: a path that starts with a separator (/, \, %2F, %5C) right after the public root.
  • Now served from inside the private root: file names that look like a URL scheme or a drive, such as a:b.txt or C|. They used to resolve to a different URL.

cspell itself does not use createRedirectProvider. This affects projects that use cspell-io directly.

  • The part of the URL after the public root is resolved as a relative path under the private root, and the result is checked to be under the private root: same protocol, same host, and the same path prefix.
  • Results coming back from the private file system are checked the same way before they are shown under the public root.
  • The change is in commit 25359026e1.

... (truncated)

Changelog

Sourced from cspell's changelog.

v10.3.6 (2026-09-29)

Fixes

fix: Report unknown CSpell directives again (#9319)

Summary

cspell lint reports unknown in-document directives again, such as cspell:bad-dir, when --validate-directives or validateDirectives: true in the config asks for them. Since 9.1.0 they were found but never shown or counted.

  • --validate-directives and --no-validate-directives override the config setting.
  • An unknown directive counts as an issue, so cspell lint exits with an error, as it did before 9.1.0.
  • The JSON reporter, @cspell/cspell-json-reporter, includes them in its output again.
  • The default reporter and the JSON reporter now ask to receive directive issues. Other reporters still only get them if they ask for them.
  • The command-line flag is now applied as a setting, like --report, so it controls what is shown as well as what is checked.

fix(cspell-io): Keep redirected requests under the private root (#9329)

Summary

createRedirectProvider in cspell-io now only serves requests that map to a location under its private root. A request that would resolve outside the private root is refused with VFSErrorUnsupportedRequest, the same error as a request outside the public root.

  • Refused: a path that starts with a separator (/, \, %2F, %5C) right after the public root.
  • Now served from inside the private root: file names that look like a URL scheme or a drive, such as a:b.txt or C|. They used to resolve to a different URL.

cspell itself does not use createRedirectProvider. This affects projects that use cspell-io directly.

  • The part of the URL after the public root is resolved as a relative path under the private root, and the result is checked to be under the private root: same protocol, same host, and the same path prefix.
  • Results coming back from the private file system are checked the same way before they are shown under the public root.
  • The change is in commit 25359026e1.

... (truncated)

Commits
  • 8559198 v10.3.6
  • 72e1be3 chore: Prepare Release v10.3.6 (auto-deploy) (#9305)
  • e230ca0 test: Give time-limited RPC and worker tests room on slow runners (#9330)
  • 8eae6b6 fix: Report unknown CSpell directives again (#9319)
  • a5f5111 fix: Don't reuse cached results made with different command-line options (#9318)
  • 2f897be fix: --show-perf-summary shows where all of the run's time goes (#9307)
  • fe37b7b chore: Label per package, and bugs links to its open issues (#9309)
  • f37a244 v10.3.5
  • b36374c chore: Prepare Release v10.3.5 (auto-deploy) (#9277)
  • 93e55c0 fix(cspell-lib): shouldCheckDocument honors the forceCheck option (#9303)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 22, 2026
@dependabot dependabot Bot changed the title chore(deps-dev): bump cspell from 10.3.0 to 10.3.3 chore(deps-dev): bump cspell from 10.3.0 to 10.3.6 Oct 3, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/cspell-10.3.3 branch 2 times, most recently from d261d87 to 089b6cb Compare October 3, 2026 09:50
@dependabot dependabot Bot changed the title chore(deps-dev): bump cspell from 10.3.0 to 10.3.6 bump cspell from 10.3.0 to 10.3.6 Oct 3, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/cspell-10.3.3 branch from 089b6cb to a50cef1 Compare October 3, 2026 21:52
@dependabot dependabot Bot changed the title bump cspell from 10.3.0 to 10.3.6 chore(deps-dev): bump cspell from 10.3.0 to 10.3.6 Oct 3, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/cspell-10.3.3 branch 4 times, most recently from 8267b88 to 40ed6e7 Compare October 6, 2026 21:57
Bumps [cspell](https://github.com/streetsidesoftware/cspell/tree/HEAD/packages/cspell) from 10.3.0 to 10.3.6.
- [Release notes](https://github.com/streetsidesoftware/cspell/releases)
- [Changelog](https://github.com/streetsidesoftware/cspell/blob/main/packages/cspell/CHANGELOG.md)
- [Commits](https://github.com/streetsidesoftware/cspell/commits/v10.3.6/packages/cspell)

---
updated-dependencies:
- dependency-name: cspell
  dependency-version: 10.3.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/cspell-10.3.3 branch from 40ed6e7 to dc2e391 Compare October 7, 2026 08:34

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants