Bump the all-dependencies group across 1 directory with 13 updates - #600
Closed
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the all-dependencies group with 12 updates in the /samples/AspireWithJavaScript/AspireJavaScript.Vue directory: | Package | From | To | | --- | --- | --- | | [vue](https://github.com/vuejs/core) | `3.4.33` | `3.5.13` | | [@rushstack/eslint-patch](https://github.com/microsoft/rushstack/tree/HEAD/eslint/eslint-patch) | `1.10.3` | `1.10.4` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `20.14.11` | `22.10.1` | | [@vitejs/plugin-vue](https://github.com/vitejs/vite-plugin-vue/tree/HEAD/packages/plugin-vue) | `5.0.5` | `5.2.1` | | [@vue/eslint-config-prettier](https://github.com/vuejs/eslint-config-prettier) | `9.0.0` | `10.1.0` | | [@vue/eslint-config-typescript](https://github.com/vuejs/eslint-config-typescript) | `13.0.0` | `14.1.4` | | [@vue/tsconfig](https://github.com/vuejs/tsconfig) | `0.5.1` | `0.7.0` | | [npm-run-all2](https://github.com/bcomnes/npm-run-all2) | `6.2.2` | `7.0.1` | | [prettier](https://github.com/prettier/prettier) | `3.3.3` | `3.4.1` | | [typescript](https://github.com/microsoft/TypeScript) | `5.5.3` | `5.7.2` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `5.3.4` | `6.0.2` | | [vue-tsc](https://github.com/vuejs/language-tools/tree/HEAD/packages/tsc) | `2.0.26` | `2.1.10` | Updates `vue` from 3.4.33 to 3.5.13 - [Release notes](https://github.com/vuejs/core/releases) - [Changelog](https://github.com/vuejs/core/blob/main/CHANGELOG.md) - [Commits](vuejs/core@v3.4.33...v3.5.13) Updates `@rushstack/eslint-patch` from 1.10.3 to 1.10.4 - [Changelog](https://github.com/microsoft/rushstack/blob/main/eslint/eslint-patch/CHANGELOG.md) - [Commits](https://github.com/microsoft/rushstack/commits/@rushstack/eslint-patch_v1.10.4/eslint/eslint-patch) Updates `@types/node` from 20.14.11 to 22.10.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `@vitejs/plugin-vue` from 5.0.5 to 5.2.1 - [Release notes](https://github.com/vitejs/vite-plugin-vue/releases) - [Changelog](https://github.com/vitejs/vite-plugin-vue/blob/main/packages/plugin-vue/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite-plugin-vue/commits/plugin-vue@5.2.1/packages/plugin-vue) Updates `@vue/eslint-config-prettier` from 9.0.0 to 10.1.0 - [Release notes](https://github.com/vuejs/eslint-config-prettier/releases) - [Changelog](https://github.com/vuejs/eslint-config-prettier/blob/main/CHANGELOG.md) - [Commits](vuejs/eslint-config-prettier@v9.0.0...v10.1.0) Updates `@vue/eslint-config-typescript` from 13.0.0 to 14.1.4 - [Release notes](https://github.com/vuejs/eslint-config-typescript/releases) - [Commits](vuejs/eslint-config-typescript@v13.0.0...v14.1.4) Updates `@vue/tsconfig` from 0.5.1 to 0.7.0 - [Release notes](https://github.com/vuejs/tsconfig/releases) - [Commits](vuejs/tsconfig@v0.5.1...v0.7.0) Updates `eslint-plugin-vue` from 9.27.0 to 9.32.0 - [Release notes](https://github.com/vuejs/eslint-plugin-vue/releases) - [Commits](vuejs/eslint-plugin-vue@v9.27.0...v9.32.0) Updates `npm-run-all2` from 6.2.2 to 7.0.1 - [Release notes](https://github.com/bcomnes/npm-run-all2/releases) - [Changelog](https://github.com/bcomnes/npm-run-all2/blob/master/CHANGELOG.md) - [Commits](bcomnes/npm-run-all2@v6.2.2...v7.0.1) Updates `prettier` from 3.3.3 to 3.4.1 - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](prettier/prettier@3.3.3...3.4.1) Updates `typescript` from 5.5.3 to 5.7.2 - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Changelog](https://github.com/microsoft/TypeScript/blob/main/azure-pipelines.release.yml) - [Commits](microsoft/TypeScript@v5.5.3...v5.7.2) Updates `vite` from 5.3.4 to 6.0.2 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v6.0.2/packages/vite) Updates `vue-tsc` from 2.0.26 to 2.1.10 - [Release notes](https://github.com/vuejs/language-tools/releases) - [Changelog](https://github.com/vuejs/language-tools/blob/master/CHANGELOG.md) - [Commits](https://github.com/vuejs/language-tools/commits/v2.1.10/packages/tsc) --- updated-dependencies: - dependency-name: vue dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-dependencies - dependency-name: "@rushstack/eslint-patch" dependency-type: direct:development update-type: version-update:semver-patch dependency-group: all-dependencies - dependency-name: "@types/node" dependency-type: direct:development update-type: version-update:semver-major dependency-group: all-dependencies - dependency-name: "@vitejs/plugin-vue" dependency-type: direct:development update-type: version-update:semver-minor dependency-group: all-dependencies - dependency-name: "@vue/eslint-config-prettier" dependency-type: direct:development update-type: version-update:semver-major dependency-group: all-dependencies - dependency-name: "@vue/eslint-config-typescript" dependency-type: direct:development update-type: version-update:semver-major dependency-group: all-dependencies - dependency-name: "@vue/tsconfig" dependency-type: direct:development update-type: version-update:semver-minor dependency-group: all-dependencies - dependency-name: eslint-plugin-vue dependency-type: direct:development update-type: version-update:semver-minor dependency-group: all-dependencies - dependency-name: npm-run-all2 dependency-type: direct:development update-type: version-update:semver-major dependency-group: all-dependencies - dependency-name: prettier dependency-type: direct:development update-type: version-update:semver-minor dependency-group: all-dependencies - dependency-name: typescript dependency-type: direct:development update-type: version-update:semver-minor dependency-group: all-dependencies - dependency-name: vite dependency-type: direct:development update-type: version-update:semver-major dependency-group: all-dependencies - dependency-name: vue-tsc dependency-type: direct:development update-type: version-update:semver-minor dependency-group: all-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
|
Superseded by #615. |
dependabot
Bot
deleted the
dependabot/npm_and_yarn/samples/AspireWithJavaScript/AspireJavaScript.Vue/all-dependencies-39f55e9854
branch
December 9, 2024 07:00
David Pine (IEvangelist)
pushed a commit
that referenced
this pull request
Jul 30, 2026
…rity patches The angular-tooling group bump (main #1848) set typescript ~7.0.2, which violates @angular-devkit/build-angular@22's peer requirement (typescript >=6.0 <6.1). This breaks `npm ci` for the Angular sample (run via AppHost .WithNpm(installCommand: "ci")) and has left main red. Revert typescript to ~6.0.3 to restore a resolvable dependency tree. Reset this sample's package.json/package-lock.json to the upstream/main baseline and apply three surgical leaf patches: - typescript 7.0.2 -> 6.0.3 (drops 20 orphaned @typescript/typescript-* platform pkgs) - postcss 8.5.10 -> 8.5.18 (GHSA-r28c-9q8g-f849 #630, GHSA-6g55-p6wh-862q #629) - js-yaml 4.2.0 -> 4.3.0 (GHSA-52cp-r559-cp3m #601) Remaining Angular alerts (fast-uri #624, webpack-dev-server #604/#603/#563, @hono/node-server #617, brace-expansion #600) are deferred to a follow-up once CI is verified green. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
David Pine (IEvangelist)
pushed a commit
that referenced
this pull request
Jul 30, 2026
Angular sample lockfile-only leaf swaps (no override cascade): - fast-uri 3.1.3 -> 3.1.4 (alert #624, high) - brace-expansion 1.1.15 -> 1.1.16 (alert #600, high) Both satisfy parent ranges (ajv; minimatch requires ^1.1.7). Integrity cross-verified via canonical npmjs SHA-1 shasum. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
David Pine (IEvangelist)
pushed a commit
that referenced
this pull request
Jul 31, 2026
…rity patches The angular-tooling group bump (main #1848) set typescript ~7.0.2, which violates @angular-devkit/build-angular@22's peer requirement (typescript >=6.0 <6.1). This breaks `npm ci` for the Angular sample (run via AppHost .WithNpm(installCommand: "ci")) and has left main red. Revert typescript to ~6.0.3 to restore a resolvable dependency tree. Reset this sample's package.json/package-lock.json to the upstream/main baseline and apply three surgical leaf patches: - typescript 7.0.2 -> 6.0.3 (drops 20 orphaned @typescript/typescript-* platform pkgs) - postcss 8.5.10 -> 8.5.18 (GHSA-r28c-9q8g-f849 #630, GHSA-6g55-p6wh-862q #629) - js-yaml 4.2.0 -> 4.3.0 (GHSA-52cp-r559-cp3m #601) Remaining Angular alerts (fast-uri #624, webpack-dev-server #604/#603/#563, @hono/node-server #617, brace-expansion #600) are deferred to a follow-up once CI is verified green. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
David Pine (IEvangelist)
pushed a commit
that referenced
this pull request
Jul 31, 2026
Angular sample lockfile-only leaf swaps (no override cascade): - fast-uri 3.1.3 -> 3.1.4 (alert #624, high) - brace-expansion 1.1.15 -> 1.1.16 (alert #600, high) Both satisfy parent ranges (ajv; minimatch requires ^1.1.7). Integrity cross-verified via canonical npmjs SHA-1 shasum. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
David Pine (IEvangelist)
pushed a commit
that referenced
this pull request
Aug 3, 2026
…rity patches The angular-tooling group bump (main #1848) set typescript ~7.0.2, which violates @angular-devkit/build-angular@22's peer requirement (typescript >=6.0 <6.1). This breaks `npm ci` for the Angular sample (run via AppHost .WithNpm(installCommand: "ci")) and has left main red. Revert typescript to ~6.0.3 to restore a resolvable dependency tree. Reset this sample's package.json/package-lock.json to the upstream/main baseline and apply three surgical leaf patches: - typescript 7.0.2 -> 6.0.3 (drops 20 orphaned @typescript/typescript-* platform pkgs) - postcss 8.5.10 -> 8.5.18 (GHSA-r28c-9q8g-f849 #630, GHSA-6g55-p6wh-862q #629) - js-yaml 4.2.0 -> 4.3.0 (GHSA-52cp-r559-cp3m #601) Remaining Angular alerts (fast-uri #624, webpack-dev-server #604/#603/#563, @hono/node-server #617, brace-expansion #600) are deferred to a follow-up once CI is verified green. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
David Pine (IEvangelist)
pushed a commit
that referenced
this pull request
Aug 3, 2026
Angular sample lockfile-only leaf swaps (no override cascade): - fast-uri 3.1.3 -> 3.1.4 (alert #624, high) - brace-expansion 1.1.15 -> 1.1.16 (alert #600, high) Both satisfy parent ranges (ajv; minimatch requires ^1.1.7). Integrity cross-verified via canonical npmjs SHA-1 shasum. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
David Pine (IEvangelist)
pushed a commit
that referenced
this pull request
Aug 6, 2026
…postcss, fast-uri, js-yaml) Clears 27 Dependabot alerts via minimal, lockfile-only patch bumps (registry.npmjs.org, sha512): - brace-expansion 5.0.5->5.0.7 (9 samples) and 1.1.15->1.1.16 (Angular): #590,#592-#600 (HIGH ReDoS) - postcss ->8.5.23 (Angular, Vite, Vue, aspire-with-node, rag-svelte, vite-csharp, vite-react): #629,#630,#647,#649,#651,#659,#660,#695,#704,#706,#709,#715,#716,#717 - fast-uri 3.1.3->3.1.4 (Angular, React): #624,#626 (HIGH) - js-yaml 4.2.0->4.3.0 (Angular): #601 (HIGH) Same-major patch bumps only; dependency trees unchanged. Deferred (see PR body): fast-uri 3.1.5, webpack-dev-server, esbuild, @babel/core, @hono/node-server, body-parser, protobufjs. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
David Pine (IEvangelist)
pushed a commit
that referenced
this pull request
Aug 8, 2026
…postcss, fast-uri, js-yaml) Clears 27 Dependabot alerts via minimal, lockfile-only patch bumps (registry.npmjs.org, sha512): - brace-expansion 5.0.5->5.0.7 (9 samples) and 1.1.15->1.1.16 (Angular): #590,#592-#600 (HIGH ReDoS) - postcss ->8.5.23 (Angular, Vite, Vue, aspire-with-node, rag-svelte, vite-csharp, vite-react): #629,#630,#647,#649,#651,#659,#660,#695,#704,#706,#709,#715,#716,#717 - fast-uri 3.1.3->3.1.4 (Angular, React): #624,#626 (HIGH) - js-yaml 4.2.0->4.3.0 (Angular): #601 (HIGH) Same-major patch bumps only; dependency trees unchanged. Deferred (see PR body): fast-uri 3.1.5, webpack-dev-server, esbuild, @babel/core, @hono/node-server, body-parser, protobufjs. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the all-dependencies group with 12 updates in the /samples/AspireWithJavaScript/AspireJavaScript.Vue directory:
3.4.333.5.131.10.31.10.420.14.1122.10.15.0.55.2.19.0.010.1.013.0.014.1.40.5.10.7.06.2.27.0.13.3.33.4.15.5.35.7.25.3.46.0.22.0.262.1.10Updates
vuefrom 3.4.33 to 3.5.13Release notes
Sourced from vue's releases.
... (truncated)
Changelog
Sourced from vue's changelog.
... (truncated)
Commits
6eb29d3release: v3.5.134f8d807fix(ssr): handle initial selected state for select with v-model + v-for optio...983eb50fix(templateRef): set ref on cached async component which wrapped in KeepAliv...da7ad5efix(ssr): avoid updating subtree of async component if it is resolved (#12363)1f75d4efix(ssr): ensure v-text updates correctly with custom directives in SSR outpu...4b479dbfix(transition): reflow before leave-active class after leave-from (#12288)a20a4cbfix(hydration): the component vnode's el should be updated when a mismatch oc...352bc88fix(custom-element): avoid triggering mutationObserver when relecting props10ab8c0chore(playground): reset version when opening local playground from reproductiond637bd6perf(reactivity): do not track inner key `__v_skip`` (#11690)Updates
@rushstack/eslint-patchfrom 1.10.3 to 1.10.4Changelog
Sourced from
@rushstack/eslint-patch's changelog.Commits
2154c68Bump versions [skip ci]daaa6e5Update changelogs [skip ci]c07320dInclude CHANGELOG.md in published releases again (#4851)660d44bBump decoupled local dependencies.44b7912Merge pull request #4747 from iclanton/stricter-types5a185aaTurn on some stricter compiler options.f210738Bump cyclics.7d87045prettier -w .9b2973dBump cyclic dependencies.Updates
@types/nodefrom 20.14.11 to 22.10.1Commits
Updates
@vitejs/plugin-vuefrom 5.0.5 to 5.2.1Release notes
Sourced from
@vitejs/plugin-vue's releases.Changelog
Sourced from
@vitejs/plugin-vue's changelog.... (truncated)
Commits
d156ad7release: plugin-vue@5.2.14288652chore: add vite 6 peer dep (#481)b2df95echore(deps): update dependency rollup to ^4.27.2 (#476)378aea3chore: fix lint7edc3d9release: plugin-vue@5.2.07a1fc4cfeat: add a feature option to support custom component id generator (#461)7d081ccrelease: plugin-vue@5.1.591210ccchore(deps): update dependency rollup to ^4.25.0 (#472)e432bcbfix(deps): update all non-major dependencies (#439)62b17f3fix(hmr): should reload if relies file changed after re-render (#471)Updates
@vue/eslint-config-prettierfrom 9.0.0 to 10.1.0Release notes
Sourced from
@vue/eslint-config-prettier's releases.Commits
a1c8b5310.1.0c75ff34feat: generate .d.ts files on publishing8784cfbdocs: fix typo0eaa1ea10.0.0d693afadocs: improve description3637e3910.0.0-rc.3fd79ecefix: the recommended config is from the plugin847691e10.0.0-rc.23e9409afix: forgot to prepend the path with a dot321cc3710.0.0-rc.1Updates
@vue/eslint-config-typescriptfrom 13.0.0 to 14.1.4Release notes
Sourced from
@vue/eslint-config-typescript's releases.... (truncated)
Commits
e95da4714.1.4bb462ccworkflow: add automated release with provenance1fc321cfix: escape glob-like paths to ensure correct overrides4e1fe36chore(deps): update all non-major dependencies (#103)53e61edchore(deps): update all non-major dependencies (#99)b9d22ddchore(deps): update dependency typescript to ~5.6.3 (#100)1ed4b98chore: Configure Renovate (#97)d7b6c2eci: skip cypress binary download as we don't need it in linting89e08a5chore: ⬆️ Upgraded typescript-eslint dependencies (#96)3f8bf2e14.1.3Updates
@vue/tsconfigfrom 0.5.1 to 0.7.0Release notes
Sourced from
@vue/tsconfig's releases.Commits
37994ed0.7.0cee76cffeat(lib)!: disableskipLibCheckin library tsconfig, closes #5ab390830.6.01b9a763workflow: add release automation with provenancead9bd77fix: require vue 3.3 as peer dependency590d74cfix: add peer dep to typescript v5.x in package.json. (#20)e1ef309chore: renamebundlertoBundlerfor consistency6355fabfeat: setmoduleDetectiontoforce27fa57bfeat: enable allowImportingTsExtensions480cd96fix: typo (#28)Updates
eslint-plugin-vuefrom 9.27.0 to 9.32.0Release notes
Sourced from eslint-plugin-vue's releases.
... (truncated)
Commits
4cbcad69.32.0dc06535docs: add example config with typescript-eslint and Prettier (#2522)618f49cfix(require-explicit-slots): add support for type references (#2617)a270df8feat: add slot-name-casing rule (#2620)fdfffd6fix(prefer-use-template-ref): only check root-level variables (#2612)39b353aChore: workaround for ESLint Stylistic issue (#2623)bed816bfeat: addrestricted-component-namesrule (#2611)9ddf3e5feat: addignoreTagsoption (#2609)bea53c0feat(no-v-text-v-html-on-component): add ignore namespace option (#2610)86a8138feat(no-duplicate-attr-inheritance): ignore multi root (#2598)Updates
npm-run-all2from 6.2.2 to 7.0.1Release notes
Sourced from npm-run-all2's releases.
Changelog
Sourced from npm-run-all2's changelog.
Commits
43bfd547.0.1b2e849bRevert engine range bump back to Node 181a2f0a17.0.0b300a1fMerge remote-tracking branch 'origin/dependabot/npm_and_yarn/minimatch-10.0.1'4be26c5Merge remote-tracking branch 'origin/dependabot/npm_and_yarn/which-5.0.0'3f28b19Merge pull request #158 from bcomnes/fix-undefined-throwb0f342ePrevent a throw when looking up undefined resultsc661ffcMerge pull request #156 from bcomnes/rm-rf-rimrafb667e23Upgrade: Bump which from 3.0.1 to 5.0.0c989293Upgrade: Bump minimatch from 9.0.5 to 10.0.1Updates
prettierfrom 3.3.3 to 3.4.1Release notes
Sourced from prettier's releases.
Changelog
Sourced from prettier's changelog.
Commits
37fd177Release 3.4.11fb6297Update ts-api-utils to v1.4.2 (#16888)f6fccadRemove unnecessary parentheses around assignment inv-on(#16887)