Skip to content

Bump Platform.Bible extension deps to clear Dependabot alerts#2324

Closed
myieye wants to merge 1 commit into
developfrom
chore/platform-bible-security-bumps
Closed

Bump Platform.Bible extension deps to clear Dependabot alerts#2324
myieye wants to merge 1 commit into
developfrom
chore/platform-bible-security-bumps

Conversation

@myieye

@myieye myieye commented Jun 1, 2026

Copy link
Copy Markdown
Collaborator

Just some security bumps.

Split out of #2315 so that PR is purely the pnpm/CI/.NET bumps and this is the npm workspace.

webpack 5.97→5.104, postcss 8.5.3→8.5.10, glob 10.4→10.5, copy-webpack-plugin 12→14 (clears serialize-javascript), plus a single tmp override (old zip-build→inquirer@8 chain). npm install regenerated the lockfile.

🤖 Generated with Claude Code

webpack 5.97→5.104, postcss 8.5.3→8.5.10, glob 10.4→10.5, copy-webpack-plugin
12→14 (clears serialize-javascript), and a single npm override for tmp
(old zip-build→inquirer@8 chain). npm install regenerated package-lock.

Split out of #2315 to keep that PR's pnpm/CI bumps separate from this npm
workspace.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Jun 1, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Updates npm development dependencies in platform.bible-extension/package.json, bumping copy-webpack-plugin (14.0.0), glob (10.5.0), postcss (8.5.10), and webpack (5.104.1), with formatting adjustments to volta and overrides sections.

Changes

Dependency Updates

Layer / File(s) Summary
Development dependency upgrades
platform.bible-extension/package.json
copy-webpack-plugin, glob, postcss, and webpack devDependencies are updated to newer versions; volta and overrides blocks are reformatted while preserving Node version and tmp override values.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

Suggested labels

📙 Platform.Bible, 🟩 Low

Suggested reviewers

  • jasonleenaylor

Poem

🐰 A rabbit hops through package.json's trail,
Webpack and tools get versions that prevail!
From twelve to fourteen, and minor bumps too,
Formatting flourishes make the manifest new!
Build faster, build better—hop on through! 🚀

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately describes the main change: bumping Platform.Bible extension npm dependencies to resolve Dependabot security alerts.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description check ✅ Passed The PR description clearly explains the purpose of the changes: security bumps for npm dependencies with specific version updates and rationale for splitting from another PR.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/platform-bible-security-bumps

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@imnasnainaec

Copy link
Copy Markdown
Collaborator

This pr is subsumed in #2333, where I update the extension from the template and regenerate package-lock.json.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants