Add npm to Dependabot and update dependencies - #58
Merged
Merged
Conversation
Group minor and patch updates into one monthly PR with a 7-day cooldown, matching the github-actions entry. Majors arrive as separate PRs so each can be migrated on its own. Use the increase-if-necessary versioning strategy so updates that fit the existing range change only package-lock.json. The default strategy raises every range, including @types/vscode past engines.vscode, and vsce refuses to package when the @types/vscode range exceeds engines.vscode (see #57). CI doesn't run vsce, so that would first fail at publish time.
Run npm update, which moves every package to the newest version its range allows, including transitive dependencies. No ranges in package.json change. Notable direct updates: - @types/node 25.5.0 -> 25.9.8 - @types/vscode 1.110.0 -> 1.138.0 - @typescript-eslint/* 8.57.2 -> 8.71.0 - eslint 10.1.0 -> 10.11.0 - jest 30.3.0 -> 30.5.2, ts-jest 29.4.6 -> 29.4.14 - prettier 3.8.1 -> 3.9.9 - ts-loader 9.5.4 -> 9.6.2 - webpack 5.105.4 -> 5.111.1, webpack-cli 7.0.2 -> 7.2.3 webpack 5.111 replaces terser-webpack-plugin with webpack's own minimizer-webpack-plugin, and jest-haste-map 30.5 adds @parcel/watcher.
TypeScript 7 is out, but typescript-eslint supports only >=4.8.4 <6.1.0, so pin ~6.0.3, the latest release it supports. TypeScript 6 changes two defaults that matter here: - types defaults to [], so the declarations in @types/node and @types/jest (setTimeout, describe, and built-in modules like path and fs) are no longer loaded implicitly. List both. @types/vscode and @types/js-yaml still resolve through their imports. - strict defaults to true. Set it explicitly in place of the narrower strictNullChecks. It reports only catch variables typed as unknown, at the two catch blocks that read .message. Add an errorMessage() helper: for the Error and stderr-string rejections those blocks see, it logs the same text as before.
js-yaml 5 ships its own type declarations, so drop @types/js-yaml. The namespace import and yaml.load() call keep working unchanged. Its load() now defaults to the YAML 1.2 core schema, which no longer resolves `<<` merge keys. A team config that inherits slack.room_for_humans through `<<: *defaults` would lose its Slack action, so load team configs with CORE_SCHEMA plus mergeTag, the migration guide's way to restore v4's merge handling. The other v5 changes don't affect this call: load() now throws on empty input, and getSlackChannel() already returns undefined when load() throws.
CI's Node 24.21 ships npm 11.19.0, whose npm ci rejected the lockfile written by npm 11.6.1 as out of sync: it was missing top-level @emnapi/core and @emnapi/runtime. They are optional peers of @napi-rs/wasm-runtime, part of unrs-resolver's WebAssembly fallback, so nothing failed locally. npm install under 11.19.0 adds those two entries. The other changes are peer flags that 11.19.0 records differently. No other package versions change, and both npm 11.6.1 and 11.19.0 now accept the lockfile in npm ci.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Brings over the Dependabot and dependency work done in rubyatscale/packwerk-vscode (#27 to #35 there). There are five commits, which can be reviewed separately.
npmecosystem to.github/dependabot.yml, using the same block as packwerk-vscode. Minor and patch updates come as one monthly grouped PR, majors come as separate PRs, and all updates have a 7-day cooldown.versioning-strategy: increase-if-necessary. By default, Dependabot raises every range inpackage.json, which would move@types/vscodeto^1.138.0, aboveengines.vscode.vscerefuses to package that combination (Raise the minimum VS Code version to 1.110 #57), and CI doesn't runvsce, so it would first fail at publish time.increase-if-necessary, updates that fit the current range change onlypackage-lock.json.npm updatechanges the lockfile only; no ranges change. That includes@types/vscode1.110.0 → 1.138.0, typescript-eslint 8.57 → 8.71, ESLint 10.1 → 10.11, Jest 30.3 → 30.5, Prettier 3.8 → 3.9, webpack 5.105 → 5.111 and webpack-cli 7.0 → 7.2. It also movesfast-urifrom 3.1.7 to 3.1.8, which clears the one moderate advisorynpm auditreports onmain.~6.0.3. TypeScript 7 is out, but typescript-eslint supports only<6.1.0. TypeScript 6 changes two defaults that affect this repo:typesnow defaults to[], sotsconfig.jsonlistsnodeandjest.strictnow defaults totrue. It replaces the narrowerstrictNullChecks, and its only new errors are the twocatchblocks that read.message. A smallerrorMessage()helper handles them and logs the same text as before.@types/js-yamlis removed.load()now defaults to the YAML 1.2 core schema, which doesn't resolve<<merge keys. A team config that inheritsslack.room_for_humansthrough<<: *defaultswould lose its Slack button. Team configs are now loaded withCORE_SCHEMA.withTags(mergeTag), the migration guide's way to restore v4 behavior..vsixfrom 20 KB to 24.6 KB.npm ci. CI's Node 24.21 ships npm 11.19.0, which rejected the lockfile my local npm 11.6.1 wrote as out of sync: it was missing top-level@emnapi/coreand@emnapi/runtime, optional peers used byunrs-resolver's WebAssembly fallback. Runningnpm installunder 11.19.0 adds them and changes somepeerflags. No other versions change, and both npm versions now accept the lockfile.Not updated, as requested:
@types/node26 (it stays on 25.x, now 25.9.8) and TypeScript 7.Worth deciding separately
@types/vscodevsengines.vscode: the installed types are now 1.138.0, whileengines.vscodeis^1.110.0. That reopens the gap Raise the minimum VS Code version to 1.110 #57 closed: the compiler won't catch use of APIs newer than 1.110. The range is unchanged, sovscestill packages, and the new Dependabot group would make the same lockfile bump next month anyway. To keep them matched, either ignore@types/vscodeupdates in Dependabot and bump it together withengines.vscode, or raiseengines.vscode.npm run lintalready fails onmain:.prettierrcsetssingleQuote: true, and Prettier also applies it to YAML. It flags the double quotes in.github/dependabot.yml,.github/workflows/codeql.ymland.github/workflows/zizmor.yml, with both Prettier 3.8.1 and 3.9.9. CI doesn't run lint. The new Dependabot block follows the file's existing double-quote style.Test plan
npm ciunder both npm 11.6.1 and 11.19.0 (the version CI uses), thennpm run build:prod,npm tandnpx vsce package. The package has 7 files and is 24.61 KB.tsc --noEmitand ESLint (type-aware, viatsconfig.eslint.json) pass. Prettier passes on the changed source and config files.dist/extension.jswith a stubbedvscodeAPI and a fake workspace containingbin/codeownershipand a team YAML that uses<<: *defaults. The status bar, info message and actions matchedmain's bundle in three cases: success, a failingbin/codeownership, and output on stderr. As a control, a build withoutmergeTaglost the Slack action.npm audit: 0 vulnerabilities (mainhas 1 moderate,fast-uri).Errorwith an empty message logging""instead of"Error". Fixed in the TypeScript commit.