chore(deps): bump 15 of 19 npm-vueapp deps, hold typescript 7 - #281
chore(deps): bump 15 of 19 npm-vueapp deps, hold typescript 7#281dependabot[bot] wants to merge 2 commits into
Conversation
Bumps the npm-vueapp group in /VueApp with 19 updates: | Package | From | To | | --- | --- | --- | | [pinia](https://github.com/vuejs/pinia) | `3.0.4` | `4.0.2` | | [vue](https://github.com/vuejs/core) | `3.5.38` | `3.5.40` | | [vue-chartjs](https://github.com/apertureless/vue-chartjs) | `5.3.3` | `5.3.4` | | [vue-router](https://github.com/vuejs/router) | `5.1.0` | `5.2.0` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `24.13.2` | `26.1.1` | | [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.62.0` | `8.65.0` | | [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.62.0` | `8.65.0` | | [@vitejs/plugin-vue](https://github.com/vitejs/vite-plugin-vue/tree/HEAD/packages/plugin-vue) | `6.0.7` | `6.0.8` | | [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `4.1.9` | `4.1.10` | | [eslint](https://github.com/eslint/eslint) | `10.5.0` | `10.8.0` | | [eslint-plugin-harlanzw](https://github.com/harlan-zw/eslint-plugin-harlanzw) | `0.17.0` | `0.17.1` | | [eslint-plugin-vue](https://github.com/vuejs/eslint-plugin-vue) | `10.9.2` | `10.10.0` | | [happy-dom](https://github.com/capricorn86/happy-dom) | `20.10.6` | `20.11.1` | | [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.56.0` | `0.60.0` | | [oxlint-tsgolint](https://github.com/oxc-project/tsgolint) | `0.23.0` | `0.25.0` | | [typescript](https://github.com/microsoft/TypeScript) | `6.0.3` | `7.0.2` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.1.4` | `8.1.5` | | [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.9` | `4.1.10` | | [vue-tsc](https://github.com/vuejs/language-tools/tree/HEAD/packages/tsc) | `3.3.5` | `3.3.8` | Updates `pinia` from 3.0.4 to 4.0.2 - [Release notes](https://github.com/vuejs/pinia/releases) - [Commits](vuejs/pinia@v3.0.4...v4.0.2) Updates `vue` from 3.5.38 to 3.5.40 - [Release notes](https://github.com/vuejs/core/releases) - [Changelog](https://github.com/vuejs/core/blob/main/CHANGELOG.md) - [Commits](vuejs/core@v3.5.38...v3.5.40) Updates `vue-chartjs` from 5.3.3 to 5.3.4 - [Release notes](https://github.com/apertureless/vue-chartjs/releases) - [Changelog](https://github.com/apertureless/vue-chartjs/blob/main/CHANGELOG.md) - [Commits](apertureless/vue-chartjs@v5.3.3...v5.3.4) Updates `vue-router` from 5.1.0 to 5.2.0 - [Release notes](https://github.com/vuejs/router/releases) - [Commits](vuejs/router@v5.1.0...v5.2.0) Updates `@types/node` from 24.13.2 to 26.1.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `@typescript-eslint/eslint-plugin` from 8.62.0 to 8.65.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/eslint-plugin) Updates `@typescript-eslint/parser` from 8.62.0 to 8.65.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.65.0/packages/parser) Updates `@vitejs/plugin-vue` from 6.0.7 to 6.0.8 - [Release notes](https://github.com/vitejs/vite-plugin-vue/releases) - [Changelog](https://github.com/vitejs/vite-plugin-vue/blob/main/packages/plugin-vue/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite-plugin-vue/commits/plugin-vue@6.0.8/packages/plugin-vue) Updates `@vitest/coverage-v8` from 4.1.9 to 4.1.10 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/coverage-v8) Updates `eslint` from 10.5.0 to 10.8.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.5.0...v10.8.0) Updates `eslint-plugin-harlanzw` from 0.17.0 to 0.17.1 - [Release notes](https://github.com/harlan-zw/eslint-plugin-harlanzw/releases) - [Commits](harlan-zw/eslint-plugin-harlanzw@v0.17.0...v0.17.1) Updates `eslint-plugin-vue` from 10.9.2 to 10.10.0 - [Release notes](https://github.com/vuejs/eslint-plugin-vue/releases) - [Changelog](https://github.com/vuejs/eslint-plugin-vue/blob/master/CHANGELOG.md) - [Commits](vuejs/eslint-plugin-vue@v10.9.2...v10.10.0) Updates `happy-dom` from 20.10.6 to 20.11.1 - [Release notes](https://github.com/capricorn86/happy-dom/releases) - [Commits](capricorn86/happy-dom@v20.10.6...v20.11.1) Updates `oxfmt` from 0.56.0 to 0.60.0 - [Release notes](https://github.com/oxc-project/oxc/releases) - [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md) - [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.60.0/npm/oxfmt) Updates `oxlint-tsgolint` from 0.23.0 to 0.25.0 - [Release notes](https://github.com/oxc-project/tsgolint/releases) - [Commits](oxc-project/tsgolint@v0.23.0...v0.25.0) Updates `typescript` from 6.0.3 to 7.0.2 - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) Updates `vite` from 8.1.4 to 8.1.5 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.1.5/packages/vite) Updates `vitest` from 4.1.9 to 4.1.10 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/vitest) Updates `vue-tsc` from 3.3.5 to 3.3.8 - [Release notes](https://github.com/vuejs/language-tools/releases) - [Changelog](https://github.com/vuejs/language-tools/blob/master/CHANGELOG.md) - [Commits](https://github.com/vuejs/language-tools/commits/v3.3.8/packages/tsc) --- updated-dependencies: - dependency-name: pinia dependency-version: 4.0.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-vueapp - dependency-name: vue dependency-version: 3.5.40 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-vueapp - dependency-name: vue-chartjs dependency-version: 5.3.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-vueapp - dependency-name: vue-router dependency-version: 5.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-vueapp - dependency-name: "@types/node" dependency-version: 26.1.1 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-vueapp - dependency-name: "@typescript-eslint/eslint-plugin" dependency-version: 8.65.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-vueapp - dependency-name: "@typescript-eslint/parser" dependency-version: 8.65.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-vueapp - dependency-name: "@vitejs/plugin-vue" dependency-version: 6.0.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-vueapp - dependency-name: "@vitest/coverage-v8" dependency-version: 4.1.10 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-vueapp - dependency-name: eslint dependency-version: 10.8.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-vueapp - dependency-name: eslint-plugin-harlanzw dependency-version: 0.17.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-vueapp - dependency-name: eslint-plugin-vue dependency-version: 10.10.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-vueapp - dependency-name: happy-dom dependency-version: 20.11.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-vueapp - dependency-name: oxfmt dependency-version: 0.60.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-vueapp - dependency-name: oxlint-tsgolint dependency-version: 0.25.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-vueapp - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-vueapp - dependency-name: vite dependency-version: 8.1.5 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-vueapp - dependency-name: vitest dependency-version: 4.1.10 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-vueapp - dependency-name: vue-tsc dependency-version: 3.3.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-vueapp ... Signed-off-by: dependabot[bot] <support@github.com>
6e2093b to
a10d90a
Compare
Bundle ReportChanges will increase total bundle size by 415 bytes (0.02%) ⬆️. This is within the configured threshold ✅ Detailed changes
Affected Assets, Files, and Routes:view changes for bundle: viper-frontend-esmAssets Changed:
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #281 +/- ##
=======================================
Coverage 50.09% 50.09%
=======================================
Files 998 998
Lines 58370 58370
Branches 5858 5858
=======================================
Hits 29239 29239
Misses 28228 28228
Partials 903 903
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. |
There was a problem hiding this comment.
Pull request overview
Updates the VueApp’s npm dependencies (mostly Dependabot-proposed), while intentionally holding back TypeScript 7 and @types/node major bumps to preserve install correctness against the Node 24 runtime. Also aligns the VueApp manifest with upstream peer dependency requirements introduced by newer Pinia/Vue Router.
Changes:
- Bump Vue/Vite/Vitest/ESLint ecosystem packages in
VueAppand refresh the lockfile accordingly. - Add explicit
@vue/devtools-apidependency required as a non-optional peer by Pinia 4. - Configure Dependabot to ignore
@types/nodesemver-major updates for/VueApp.
Reviewed changes
Copilot reviewed 2 out of 3 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| VueApp/package.json | Updates direct deps/devDeps for the VueApp (incl. adding @vue/devtools-api, bumping core toolchain packages). |
| VueApp/package-lock.json | Regenerates lockfile to reflect updated dependency graph and removed unused packages. |
| .github/dependabot.yml | Adds an ignore rule preventing @types/node major bumps for the VueApp group. |
- typescript 7.0.2 ships only a native binary launcher in lib/, dropping the compiler JS API; typescript-eslint caps its peer at <6.1.0 and npm ci fails ERESOLVE, so hold at ^6.0.3 until upstream supports it - @types/node majors track Node majors, so stay on 24.x to match engines.node 24.16.0, CI node-version 24, and @tsconfig/node24 - oxfmt and oxlint-tsgolint were never used from VueApp: lint-any.js and lint-staged-ts.js spawn them with cwd projectRoot, and .oxlintrc.json exists only at the repo root - declare @vue/devtools-api, now a required non-optional peer of pinia 4 rather than a transitive dependency as it was under pinia 3 - raise @typescript-eslint/parser to ^8.65.0 to match the peer range the bumped eslint-plugin declares; ^8.56.0 admitted versions that cannot satisfy it
a10d90a to
51d5448
Compare
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 2 out of 3 changed files in this pull request and generated no new comments.
Suppressed comments (1)
VueApp/package.json:65
typescriptis declared as^6.0.3, but the updated@typescript-eslint/*toolchain declares a peer constraint oftypescript >=4.8.4 <6.1.0(seeVueApp/package-lock.json). Keeping a caret range here allows npm/Dependabot to pick a future6.1.x(or higher) release that would immediately break installs with an ERESOLVE peer conflict. Consider tightening the range to stay within the peer cap until typescript-eslint expands support.
"typescript": "^6.0.3",
Review outcome
Dependabot proposed 19 updates. Of those, 15 land as proposed, 2 are held back, and 2 are dropped because the packages themselves were dead weight in this manifest. Plus one dependency correctness fix. Rebased onto latest
main.Held back
typescript7.0.2^6.0.3(unchanged)npm cioutright@types/node26.1.1^24.13.3typescript 7.0.2
TypeScript 7 is the native Go compiler, and the npm package no longer ships the compiler JS API. Its entire
lib/is now:The package drops from 23 MB to 2.38 MB plus 20 platform-specific native binaries, and
tsserveris gone frombin. Any programmatic consumer of the API breaks: typescript-eslint,ts-api-utils, and@volar/typescriptbehindvue-tsc --build.So
@typescript-eslint/*correctly caps its peer attypescript@">=4.8.4 <6.1.0", andnpm cifails before a single test runs:That is the actual CI failure on this PR's earlier run (Frontend Tests failed in 8s, Fallow regression in 16s).
No published typescript-eslint accepts TS 7, including
8.66.0and every8.66.1-alpha.*canary. Forcing it with--legacy-peer-depsor an override would swap a fast install failure for a silently broken linter and type-checker. TypeScript 7 needs its own PR once upstream ships support.@types/node 26.1.1
@types/nodemajors track Node majors, so 26.x describes APIs the runtime does not have. Everything here is pinned to Node 24:engines.nodeandvoltaat24.16.0,node-version: 24across all five CI jobs, and@tsconfig/node24.Per the Node release schedule, v24 is Active LTS until 2026-10-20 and supported to 2028-04-30, while v26 is Current and does not reach LTS until 2026-10-28.
The concrete risk is not tidiness:
@types/node@26pullsundici-types@~8.3.0, while Node 24 ships undici 7. That typesfetch,Headers,Response, andFormDataper undici 8, so type-check passes and the runtime throws. Bumped within the 24 line instead (24.13.2to24.13.3)..github/dependabot.ymlnow ignores@types/nodemajors for/VueAppso this does not recur monthly. Remove that when the runtime moves.Also in this branch
@vue/devtools-api^8.2.1. pinia 4 moved it fromdependenciesto a required, non-optional peer. npm auto-installs it so nothing breaks today, but it was an undeclared implicit dependency of the app bundle.oxfmtandoxlint-tsgolintfrom VueApp. They were never used from here.scripts/lint-any.jsspawnsnpx oxfmtwithcwd: projectRoot,scripts/lint-staged-ts.jsrunsoxlintfromprojectRoot(passing--type-aware --tsconfig=VueApp/tsconfig.json),.oxlintrc.jsonexists only at the repo root, no VueApp script invokes them, and no CI job runs them. Verified after removal thatnpx oxfmtandnpx oxlintstill resolve from root. This also removes the version skew against chore(deps-dev): bump the npm-root group with 8 updates #280, which moves root to oxfmt0.60.0and oxlint-tsgolint7.0.2001.Net effect on the lockfile is 580 insertions against 1009 deletions, since dropping the dead deps removes 19
@oxfmt/*and 6@oxlint-tsgolint/*platform binaries, and holding TypeScript at 6 keeps 20@typescript/typescript-*natives out.Supply chain review
All 19 direct updates plus 113 changed or added lockfile entries were checked.
eslint@10.8.0at 11 days..npmrcmin-release-age=7and the Dependabotcooldownalready enforce this.npm auditreports 3 pre-existing issues (brace-expansion,postcss,undici). I auditedmain's lockfile separately and it reports the identical 3, so this PR neither introduces nor fixes any. OSV batch query across all 113 new package versions returned zero hits.hasInstallScriptisfsevents@2.3.3, darwin-only and pre-existing.typescriptandeslinthave none, which is normal for both.vuejs/pinia.nostics@1.2.0, a new transitive from pinia 4 and vue-router 5.2, isvercel-labs/nostics, MIT, maintained bydanielroe,posva, andantfu.posvaauthors both dependents, so it is first-party. Not a typosquat.createPinia,defineStore, andstoreToRefs, all stable across the major.Verification
npm installnpm run test:frontendvue-tsc --build --forcenpm run verify:buildnpm run lintOriginal Dependabot report
Bumps the npm-vueapp group in /VueApp with 19 updates:
3.0.44.0.23.5.383.5.405.3.35.3.45.1.05.2.024.13.226.1.18.62.08.65.08.62.08.65.06.0.76.0.84.1.94.1.1010.5.010.8.00.17.00.17.110.9.210.10.020.10.620.11.10.56.00.60.00.23.00.25.06.0.37.0.28.1.48.1.54.1.94.1.103.3.53.3.8Dependabot's per-package release notes were trimmed here. That section had already hit GitHub's body length limit and self-truncated, and prepending this review would have overflowed it. Release notes for every package above are reachable from its link.