Skip to content

chore(deps): rolling dependency update - #235

Open
socket-pr-bot[bot] wants to merge 1 commit into
mainfrom
weekly-update
Open

socket-pr-bot[bot] wants to merge 1 commit into
mainfrom
weekly-update

Conversation

@socket-pr-bot

@socket-pr-bot socket-pr-bot Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Rolling dependency update

One long-lived PR, rebuilt from main on every run so it stays
mergeable. Each run appends its dependency delta below, newest first.

2026-09-29 — run · 32 updated
package from to
@babel/parser 7.29.8 7.29.9
@inquirer/checkbox 5.2.2 5.2.5
@inquirer/confirm 6.2.0 6.3.2
@inquirer/input 5.1.3 5.1.6
@inquirer/password 5.1.2 5.2.2
@inquirer/search 4.3.0 4.3.3
@inquirer/select 5.2.2 5.2.5
@mdn/browser-compat-data 8.1.1 8.1.2
@perryts/perry 0.5.1220 0.5.1520
@sigstore/protobuf-specs 0.5.1 0.5.2
@types/node 26.5.1 26.6.2
@vitest/coverage-v8 5.0.0 5.0.1
@vitest/ui 5.0.0 5.0.1
ast-v8-to-istanbul 1.0.6 1.0.7
ata-validator 1.27.0 1.27.1
fallow 3.27.0 3.28.0
fast-check 4.10.0 4.10.2
get-east-asian-width 1.6.0 1.7.0
globals 17.11.0 17.12.0
libnpmpack 9.1.12 9.1.13
magic-string 1.3.1 1.4.1
markdownlint-cli2 0.23.2 0.23.3
oxlint-tsgolint 7.0.2001 7.0.2002
p-map 7.0.6 7.0.8
regjsparser 0.13.2 0.13.3
typebox 1.3.30 1.3.34
typescript 7.1.0-dev.20260913.1 7.1.0-dev.20260921.1
vite 8.2.2 8.3.0
vitest 5.0.0 5.0.1
webpack 5.109.2 5.111.1
yaml 2.9.0 2.9.1
zod 4.4.3 4.6.5
commits
  • chore(deps): apply weekly update fixes

Note

Medium Risk
Wide dev/CI toolchain and validation-library bumps (Vite, Vitest, Zod, Webpack) can affect builds and tests; removing the Vitest patch assumes upstream 5.0.1 covers prior fleet coverage behavior.

Overview
This rolling update refreshes fleet-wide catalog pins and matching pnpm overrides in pnpm-workspace.yaml for 32 packages, keeping the monorepo on a single resolved tree.

Notable toolchain moves include Vitest and @vitest/* 5.0.0 → 5.0.1, Vite 8.2.2 → 8.3.0, a newer TypeScript 7.1 dev build, webpack 5.111.1, and zod 4.6.5. Several override-only bumps align transitives with those pins (e.g. magic-string 1.4.1, postcss 8.5.28, hono 4.13.8, js-yaml / lru-cache), and brace-expansion overrides are corrected to 5.0.12 so they match the catalog and patch key.

The patchedDependencies entry for vitest@5.0.0 is dropped as part of the Vitest bump (no replacement pin is added in this diff).

Reviewed by Cursor Bugbot for commit 6e16c13. Configure here.

@socket-pr-bot socket-pr-bot Bot added automation dependencies Pull requests that update a dependency file labels Sep 29, 2026
@socket-security

Copy link
Copy Markdown

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Priority Alert  (click "▶" to expand/collapse) Action
Low priority
Obfuscated code: npm @perryts/perry-win32-x64 is 78.0% likely obfuscated

Confidence: 0.78

Location: Package overview

From: pnpm-lock.yaml → npm/@perryts/perry@0.5.1520 → npm/@perryts/perry-win32-x64@0.5.1520

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@perryts/perry-win32-x64@0.5.1520. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Obfuscated code: npm @perryts/perry-win32-x64 is 78.0% likely obfuscated

Confidence: 0.78

Location: Package overview

From: pnpm-lock.yaml → npm/@perryts/perry@0.5.1520 → npm/@perryts/perry-win32-x64@0.5.1520

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@perryts/perry-win32-x64@0.5.1520. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn

View full report

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix prepared a fix for the issue found in the latest run.

  • ✅ Fixed: Vitest patch dropped after version bump
    • Restored the vitest@5.0.1 patchedDependencies entry and lockfile patch hash so install applies patches/fleet/vitest@5.0.1.patch.

Create PR

Or push these changes by commenting:

@cursor push f3a6f4d0b2
Preview (f3a6f4d0b2)
diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml
--- a/pnpm-lock.yaml
+++ b/pnpm-lock.yaml
@@ -558,6 +558,7 @@
   node-gyp@12.4.0: 140ba43d43d74f7d3577feb3f8a6efad544dbb0059784102b144a0e2daa437f9
   pony-cause@2.1.11: 39b2eb2567818b7c60126d03e252dbbabd8738082fca850582300d45b0a8cfb8
   run-local-ci@0.18.1: a335253820e963c2659ec1b08ee143e865eb39ec80ca7d313fff50c33e157d99
+  vitest@5.0.1: 065993cceebda16dedb4662626ed60c0aeb40f02240c8d0e540b4dc6d9674df2
 
 importers:
 
@@ -880,7 +881,7 @@
         version: 6.0.2
       vitest:
         specifier: 'catalog:'
-        version: 5.0.1(@types/node@26.6.2)(@vitest/coverage-v8@5.0.1)(@vitest/ui@5.0.1)(vite@8.3.0(@types/node@26.6.2)(esbuild@0.28.2)(jiti@2.7.0)(terser@5.48.0)(yaml@2.9.1))
+        version: 5.0.1(patch_hash=065993cceebda16dedb4662626ed60c0aeb40f02240c8d0e540b4dc6d9674df2)(@types/node@26.6.2)(@vitest/coverage-v8@5.0.1)(@vitest/ui@5.0.1)(vite@8.3.0(@types/node@26.6.2)(esbuild@0.28.2)(jiti@2.7.0)(terser@5.48.0)(yaml@2.9.1))
       vitiate:
         specifier: 'catalog:'
         version: 0.3.1(typescript@7.1.0-dev.20260921.1)(vite@8.3.0(@types/node@26.6.2)(esbuild@0.28.2)(jiti@2.7.0)(terser@5.48.0)(yaml@2.9.1))(vitest@5.0.1)
@@ -9506,7 +9507,7 @@
       obug: 2.1.4
       std-env: 4.2.0
       tinyrainbow: 3.1.1
-      vitest: 5.0.1(@types/node@26.6.2)(@vitest/coverage-v8@5.0.1)(@vitest/ui@5.0.1)(vite@8.3.0(@types/node@26.6.2)(esbuild@0.28.2)(jiti@2.7.0)(terser@5.48.0)(yaml@2.9.1))
+      vitest: 5.0.1(patch_hash=065993cceebda16dedb4662626ed60c0aeb40f02240c8d0e540b4dc6d9674df2)(@types/node@26.6.2)(@vitest/coverage-v8@5.0.1)(@vitest/ui@5.0.1)(vite@8.3.0(@types/node@26.6.2)(esbuild@0.28.2)(jiti@2.7.0)(terser@5.48.0)(yaml@2.9.1))
 
   '@vitest/istanbul-lib-coverage@1.0.1': {}
 
@@ -9537,7 +9538,7 @@
       pathe: 2.0.3
       sirv: 3.0.2
       tinyrainbow: 3.1.1
-      vitest: 5.0.1(@types/node@26.6.2)(@vitest/coverage-v8@5.0.1)(@vitest/ui@5.0.1)(vite@8.3.0(@types/node@26.6.2)(esbuild@0.28.2)(jiti@2.7.0)(terser@5.48.0)(yaml@2.9.1))
+      vitest: 5.0.1(patch_hash=065993cceebda16dedb4662626ed60c0aeb40f02240c8d0e540b4dc6d9674df2)(@types/node@26.6.2)(@vitest/coverage-v8@5.0.1)(@vitest/ui@5.0.1)(vite@8.3.0(@types/node@26.6.2)(esbuild@0.28.2)(jiti@2.7.0)(terser@5.48.0)(yaml@2.9.1))
 
   '@vitest/utils@5.0.1':
     dependencies:
@@ -9558,7 +9559,7 @@
       magic-string: 1.4.1
       valibot: 1.4.2(typescript@7.1.0-dev.20260921.1)
       vite: 8.3.0(@types/node@26.6.2)(esbuild@0.28.2)(jiti@2.7.0)(terser@5.48.0)(yaml@2.9.1)
-      vitest: 5.0.1(@types/node@26.6.2)(@vitest/coverage-v8@5.0.1)(@vitest/ui@5.0.1)(vite@8.3.0(@types/node@26.6.2)(esbuild@0.28.2)(jiti@2.7.0)(terser@5.48.0)(yaml@2.9.1))
+      vitest: 5.0.1(patch_hash=065993cceebda16dedb4662626ed60c0aeb40f02240c8d0e540b4dc6d9674df2)(@types/node@26.6.2)(@vitest/coverage-v8@5.0.1)(@vitest/ui@5.0.1)(vite@8.3.0(@types/node@26.6.2)(esbuild@0.28.2)(jiti@2.7.0)(terser@5.48.0)(yaml@2.9.1))
     transitivePeerDependencies:
       - '@swc/helpers'
       - typescript
@@ -12099,7 +12100,7 @@
       terser: 5.48.0
       yaml: 2.9.1
 
-  vitest@5.0.1(@types/node@26.6.2)(@vitest/coverage-v8@5.0.1)(@vitest/ui@5.0.1)(vite@8.3.0(@types/node@26.6.2)(esbuild@0.28.2)(jiti@2.7.0)(terser@5.48.0)(yaml@2.9.1)):
+  vitest@5.0.1(patch_hash=065993cceebda16dedb4662626ed60c0aeb40f02240c8d0e540b4dc6d9674df2)(@types/node@26.6.2)(@vitest/coverage-v8@5.0.1)(@vitest/ui@5.0.1)(vite@8.3.0(@types/node@26.6.2)(esbuild@0.28.2)(jiti@2.7.0)(terser@5.48.0)(yaml@2.9.1)):
     dependencies:
       '@types/chai': 5.2.3
       '@vitest/mocker': 5.0.1(vite@8.3.0(@types/node@26.6.2)(esbuild@0.28.2)(jiti@2.7.0)(terser@5.48.0)(yaml@2.9.1))

diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml
--- a/pnpm-workspace.yaml
+++ b/pnpm-workspace.yaml
@@ -588,6 +588,7 @@
   # This preserves membership and bounds matcher memory for fleet coverage.
   # CPU-profiled forks use the configured teardown deadline to flush profiles.
   # Ordinary forks retain the upstream 500 ms termination grace.
+  vitest@5.0.1: patches/fleet/vitest@5.0.1.patch
   # Indirects the `node-gyp/bin/node-gyp.js` require.resolve so the rolldown
   # bundle doesn't statically inline node-gyp; consumer: pacote → run-script
   # in the bundled dist tree.

You can send follow-ups to the cloud agent here.

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 6e16c13. Configure here.

Comment thread pnpm-workspace.yaml
# This preserves membership and bounds matcher memory for fleet coverage.
# CPU-profiled forks use the configured teardown deadline to flush profiles.
# Ordinary forks retain the upstream 500 ms termination grace.
vitest@5.0.0: patches/fleet/vitest@5.0.0.patch

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Vitest patch dropped after version bump

High Severity

Bumping vitest to 5.0.1 removed the patchedDependencies entry. patches/fleet/vitest@5.0.1.patch is present and still applies exclude-first coverage matching plus the CPU-prof teardownTimeout SIGKILL override, but the lockfile installs unpatched vitest@5.0.1. Coverage membership and profiled-fork teardown therefore revert to upstream.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 6e16c13. Configure here.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automation dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants