Skip to content

fix(deps): update all non-major dependencies - #2131

Open
renovate[bot] wants to merge 2 commits into
mainfrom
renovate/all-minor-patch
Open

fix(deps): update all non-major dependencies#2131
renovate[bot] wants to merge 2 commits into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
@aws-sdk/client-s3 (source) 3.1096.03.1101.0 age confidence dependencies minor 3.1106.0 (+4)
@aws-sdk/lib-storage (source) 3.1096.03.1101.0 age confidence dependencies minor 3.1106.0 (+4)
@harperfast/skills (source) 1.11.11.12.0 age confidence dependencies minor 1.12.1
@types/lodash (source) 4.17.244.17.25 age confidence devDependencies patch
@typescript-eslint/parser (source) 8.65.08.66.0 age confidence devDependencies minor 8.67.0
axios (source) 1.18.11.19.0 age confidence devDependencies minor
cbor-x 1.6.41.6.5 age confidence dependencies patch
docker/login-action v4.5.1v4.6.0 age confidence action minor
fastify (source) 5.10.05.11.2 age confidence dependencies minor 5.11.3
globals 17.8.017.9.0 age confidence devDependencies minor
jsonata (source) 1.8.81.8.9 age confidence dependencies patch
mocha (source) 11.7.611.8.0 age confidence devDependencies minor
node (source) 24.18.124.19.0 age confidence minor
node 24.18.024.18.1 age confidence uses-with patch 24.19.0
openai 6.45.06.49.0 age confidence devDependencies minor
oxlint (source) 1.76.01.77.0 age confidence devDependencies minor 1.78.0
tsx (source) 4.23.14.23.5 age confidence devDependencies patch 4.23.12 (+6)
typescript-eslint (source) 8.65.08.66.0 age confidence devDependencies minor 8.67.0

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

aws/aws-sdk-js-v3 (@​aws-sdk/client-s3)

v3.1101.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1100.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1099.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1098.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

v3.1097.0

Compare Source

Note: Version bump only for package @​aws-sdk/client-s3

aws/aws-sdk-js-v3 (@​aws-sdk/lib-storage)

v3.1101.0

Compare Source

Note: Version bump only for package @​aws-sdk/lib-storage

v3.1100.0

Compare Source

Note: Version bump only for package @​aws-sdk/lib-storage

v3.1099.0

Compare Source

Note: Version bump only for package @​aws-sdk/lib-storage

v3.1098.0

Compare Source

Note: Version bump only for package @​aws-sdk/lib-storage

v3.1097.0

Compare Source

Note: Version bump only for package @​aws-sdk/lib-storage

HarperFast/skills (@​harperfast/skills)

v1.12.0

Compare Source

Features
  • harper-best-practices: add delegating-to-the-built-in-agent rule (0c6b9d7), closes harper#626
typescript-eslint/typescript-eslint (@​typescript-eslint/parser)

v8.66.0

Compare Source

This was a version bump only for parser to align it with other projects, there were no code changes.

See GitHub Releases for more information.

You can read about our versioning strategy and releases on our website.

axios/axios (axios)

v1.19.0

Compare Source

This release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.

kriszyp/cbor-x (cbor-x)

v1.6.5

Compare Source

docker/login-action (docker/login-action)

v4.6.0

Compare Source

v4.5.2

Compare Source

fastify/fastify (fastify)

v5.11.2

Compare Source

v5.11.1

Compare Source

What's Changed

New Contributors

Full Changelog: fastify/fastify@v5.11.0...v5.11.1

v5.11.0

Compare Source

What's Changed

New Contributors

Full Changelog: fastify/fastify@v5.10.0...v5.11.0

sindresorhus/globals (globals)

v17.9.0

Compare Source

jsonata-js/jsonata (jsonata)

v1.8.9: 1.8.9 Security Release

Compare Source

  • Backport $toMillis security fixes to v1 (PR #​825)
mochajs/mocha (mocha)

v11.8.0

Compare Source

nodejs/node (node)

v24.19.0: 2026-08-03, Version 24.19.0 'Krypton' (LTS), @​aduh95

Compare Source

Notable Changes
  • [d08872b530] - (SEMVER-MINOR) buffer: implement blob.textStream() (Matthew Aitken) #​64036
  • [35222948be] - (SEMVER-MINOR) deps: update OpenSSL build config to support compression (Tim Perry) #​62217
  • [d6ab039f24] - (SEMVER-MINOR) doc: update blockList stability status to release candidate (alphaleadership) #​63050
  • [1da05fb79d] - doc: mark stream.compose stable (Matteo Collina) #​62562
  • [3c1636dabf] - (SEMVER-MINOR) esm: add --experimental-import-text flag (Efe) #​62300
  • [e323e877be] - (SEMVER-MINOR) fs: support caller-supplied readFile() buffers (Matteo Collina) #​63634
  • [c1248c9544] - (SEMVER-MINOR) http: add httpValidation option to configure header value validation (RajeshKumar11) #​61597
  • [a534b65815] - (SEMVER-MINOR) net: support TCP_KEEPINTVL and TCP_KEEPCNT in setKeepAlive (Guy Bedford) #​63825
  • [a23cdec683] - (SEMVER-MINOR) perf_hooks: sample delay per event loop iteration (Pablo Erhard) #​62935
  • [7428b57a37] - (SEMVER-MINOR) src: allow empty --experimental-config-file (Marco Ippolito) #​61610
  • [e57597173c] - (SEMVER-MINOR) stream: expose ReadableStreamTee (Matteo Collina) #​64195
  • [5396235993] - (SEMVER-MINOR) tls: report negotiated TLS groups (Filip Skokan) #​64119
  • [5e901b5cd9] - (SEMVER-MINOR) tls: add certificateCompression option (Tim Perry) #​62217
Commits

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • "before 9am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Human-Review-Need: 4 @ 0bd60a6

@socket-security

socket-security Bot commented Aug 10, 2026

Copy link
Copy Markdown

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 2f6fa11 to 64d8079 Compare August 10, 2026 15:58
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 64d8079 to d190965 Compare August 10, 2026 18:43
Co-Authored-By: GPT-5 Codex <noreply@openai.com>
@kriszyp

kriszyp commented Aug 10, 2026

Copy link
Copy Markdown
Member

I traced the Node 26 failure to a timing-sensitive assertion in getRecordCount.test.js, not to an incompatibility in the dependency updates. The test had assumed its 500 ms default budget would always finish a 30-row scan; on that CI worker it correctly took the timeout path and consulted the key count. This update gives that assertion an explicit 60 s within-budget limit.

The dependency bump remains intact. Build, the resources unit suite, and the RocksDB CBOR serialization integration test pass locally.

This push is intentionally human-authored on the Renovate branch, so Renovate will no longer automatically rebase this PR.

— GPT-5 Codex

@renovate

renovate Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@dawsontoth dawsontoth left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved — clean audit, and the two things worth a second look both check out

Lockfile audit (base main vs head 0bd60a64): 64 top-level version changes, 0 major crossings, 0 removals, 2 additions (fastify/node_modules/fast-json-stringify/node_modules/fast-uri@4.1.2, harper/node_modules/cbor-x@1.6.4 — both nested re-pins, not new surface). Bulk is @aws-sdk/@smithy patches, the @oxlint/binding-* platform set 1.76.0 → 1.77.0, and @typescript-eslint 8.65.0 → 8.66.0. Real movers: fastify 5.10.0 → 5.11.2, openai 6.45.0 → 6.49.0, axios 1.18.1 → 1.19.0, cbor-x 1.6.4 → 1.6.5, jsonata 1.8.8 → 1.8.9, mocha 11.7.6 → 11.8.0, tsx 4.23.1 → 4.23.5, @harperfast/skills 1.11.1 → 1.12.0.

axios 1.19.0 is safe here, which is worth stating because the same bump is a hard blocker in studio — 1.19 changed get<T,R,D> to get<T,R,D,P>, and studio's TypedAxios overrides break on the arity shift. harper is unaffected: axios appears in exactly two places, and neither is production type surface — the unitTests/apiTests/*.mjs suites (untyped .mjs) and two comments in utility/logging/harper_logger.ts about axios stashing credentials on error objects. npm run typecheck and npm run build both pass.

docker/login-action v4.5.1 → v4.6.0 — both digests verified genuine against upstream:

v4.5.1 -> abd2ef45e78c5afb21d64d4ca52ee8550d9572c7   (matches main)
v4.6.0 -> dbcb813823bdd20940b903addbd779551569679f   (matches this PR)

Local verification (Node 24.17.0): npm ci clean, npm run build (tsc) clean, npm run typecheck clean, npm run lint:required clean. I could not get the full test:unit:main suite to complete on this machine — it hangs on a worker handshake (No listener registered for worker message type process-group-worker-ready) and the subset run hits TLS/port environment issues, the same reason harper's integration suite can't run locally here. So for test evidence I'm leaning on CI, which is unusually thorough on this repo and entirely green: 41 checks including Build Harper (Node 24 and Windows) and Integration Tests 1–6 across Bun, Node 24, Windows, and uWS HTTP.

One inconsistency, non-blocking: .nvmrc and .node-version both go to 24.19.0, but .github/workflows/npm-package-app-e2e.yml:108 hardcodes node-version: 24.18.1 (Renovate bumped it separately from 24.18.0). That workflow pins Node inline instead of reading .nvmrc, so it now lags the repo's declared version. Harmless today; worth switching to node-version-file: .nvmrc so it stops drifting.

@dawsontoth

Copy link
Copy Markdown
Contributor

Following up on my approval with the local test results that finished after I posted — the approval stands, and I can now back the test claim with data rather than deferring to CI.

Correcting my own review: I said I was leaning on CI "including Build Harper and Integration Tests" and didn't mention the most relevant jobs — this repo does gate unit tests, via Unit Test (Node.js v22 / v24 / v26) running npm run test:unit:all. All three are green on this PR. I'd truncated the check list when I looked.

The local run did surface one failing test, and it's pre-existing — not from these bumps:

extractApplication directory swap
  ✗ atomically restores the previous tree when preparation fails under a live writer
    Error: ENOTEMPTY: directory not empty, rename '…/.deploy-aside/web/93569-…' -> '…/web'
      at async rollbackExtractedDirectory (dist/components/Application.js:738:17)
      at async Object.rollback (dist/components/Application.js:694:13)
      at async Context.<anonymous> (unitTests/components/extractApplicationSwap.test.js:130:4)

It's flaky, and worse on main than on this branch — same file, same command, five runs each on macOS/Node 24.17.0:

tree result
this PR (0bd60a64) 4 clean runs, 1 failure (8 passing otherwise)
main (eb702ee5, rebuilt with the same deps) 1 clean run, 4 failures

So it's a pre-existing race in the rollback path, and nothing in this PR's dependency set (aws-sdk/smithy patches, oxlint bindings, typescript-eslint, fastify, openai, axios) plausibly touches extractApplication. It doesn't fire in CI, which fits an ENOTEMPTY-on-rename race behaving differently on APFS than on the Linux runners.

Filing it separately — it's in a rollback path, which is exactly where you don't want a race, and it makes the unit suite unreliable for anyone developing on a Mac. Nothing blocking for this PR.

@kriszyp kriszyp left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Dispatch codex review (verdict COMMENTS).

🤖 Reviewed with Codex

Comment thread package-lock.json
"version": "3.977.4",
"resolved": "https://registry.npmjs.org/@aws-sdk/core/-/core-3.977.4.tgz",
"integrity": "sha512-CEkcQlMOQJCvul60U7wdAOACjtdgFWDsfJI+6wUOGdhGNV2lGbuJpi/R50QLpFG3Tp+sQxa/RmzC3X7KHbhuTA==",
"deprecated": "Deprecated due to Document number parsing bug in JSON, see\n https://github.com/aws/aws-sdk-js-v3/issues/8246. Newer version available.",

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@aws-sdk/core@3.977.4 is newly introduced here, and AWS explicitly deprecated this exact release for a JSON Document number-parsing defect; the lock metadata also says a newer release is available. Because Harper turns this lockfile into the shrinkwrap shipped to customers, a JSON-protocol AWS client sharing this core can deserialize Document numeric values incorrectly. Please refresh the aligned @aws-sdk/client-s3/@aws-sdk/lib-storage set until it resolves a non-deprecated core, or leave the AWS bump out of this batch.

— KrAIs (OpenAI Codex)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants