From b990606bac1bc07c03f20db703ced19e47b18f7e Mon Sep 17 00:00:00 2001 From: Peter Steinberger Date: Tue, 29 Sep 2026 20:40:13 -0700 Subject: [PATCH] build(deps): refresh review tooling and security scanners Update Vitest and V8 coverage to 5.0.2, pnpm to 11.28.0, CodeQL to 4.38.2, and the TruffleHog action and scanner to 3.97.9. Preserve the Node 22 runtime floor and document pnpm 11 development requirements. Incorporates dependency updates from #228 and #229. Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/codeql.yml | 4 +- .github/workflows/crabbox-hydrate.yml | 2 +- .github/workflows/secret-scan.yml | 4 +- AGENTS.md | 2 +- CHANGELOG.md | 1 + README.md | 2 +- package.json | 2 +- pnpm-lock.yaml | 73 +++++++++++---------------- 8 files changed, 39 insertions(+), 51 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 6c6d36a..5d5e9bd 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -66,13 +66,13 @@ jobs: - name: Initialize CodeQL if: ${{ github.event_name != 'workflow_dispatch' || inputs.profile == 'all' || inputs.profile == matrix.category }} - uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 + uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: languages: ${{ matrix.language }} config-file: ${{ matrix.config_file }} - name: Analyze if: ${{ github.event_name != 'workflow_dispatch' || inputs.profile == 'all' || inputs.profile == matrix.category }} - uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1 + uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2 with: category: "/codeql/${{ matrix.category }}" diff --git a/.github/workflows/crabbox-hydrate.yml b/.github/workflows/crabbox-hydrate.yml index d5e8a81..08123ef 100644 --- a/.github/workflows/crabbox-hydrate.yml +++ b/.github/workflows/crabbox-hydrate.yml @@ -44,7 +44,7 @@ jobs: - uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 with: - version: 11.27.1 + version: 11.28.0 - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/secret-scan.yml b/.github/workflows/secret-scan.yml index 5137a1b..d73582f 100644 --- a/.github/workflows/secret-scan.yml +++ b/.github/workflows/secret-scan.yml @@ -47,10 +47,10 @@ jobs: echo "head=$head" >> "$GITHUB_OUTPUT" - name: Scan with TruffleHog - uses: trufflesecurity/trufflehog@f714bf454f350590f4a24c3ddb1aef02c35bf5b6 # v3.97.5 + uses: trufflesecurity/trufflehog@4dd8831c5f12599465d4d45c3c447b4018a34c85 # v3.97.9 with: path: ./ base: ${{ steps.scan-range.outputs.base }} head: ${{ steps.scan-range.outputs.head }} - version: "3.97.5" + version: "3.97.9" extra_args: --only-verified --debug diff --git a/AGENTS.md b/AGENTS.md index 87e8eef..6faf78d 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -10,7 +10,7 @@ User documentation is in `docs/`; the static website assets are in `website/`. ## Build, Test, and Development Commands -Use pnpm with Node 22.x (22.12+), 24.x, or 26+ for Vitest 5 development. The published +Use pnpm with Node 22.x (22.13+), 24.x, or 26+ for pnpm 11 and Vitest 5 development. The published CLI continues to support Node 22 or newer. Keep `@types/node` on the Node 22 major to typecheck against that runtime floor. diff --git a/CHANGELOG.md b/CHANGELOG.md index db27b6b..1c2f75a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,7 @@ ## 0.8.2 - Unreleased +- Updated Vitest and V8 coverage to 5.0.2, pnpm to 11.28.0, CodeQL to 4.38.2, and both the TruffleHog action and scanner to 3.97.9, thanks @dependabot[bot]. - Fixed non-Git patch audits to retain symlink edits and literal backslashes in Unix filenames without reading linked targets. - Fixed diff-scoped review, CI, and revalidation to include both paths of committed renames, preventing features mapped to the old path from being silently skipped. diff --git a/README.md b/README.md index b95e3e9..e5d50b8 100644 --- a/README.md +++ b/README.md @@ -97,7 +97,7 @@ pnpm build pnpm pack:smoke ``` -Use Node.js 22.x (22.12+), 24.x, or 26+ and the pnpm version declared in `package.json` +Use Node.js 22.x (22.13+), 24.x, or 26+ and the pnpm version declared in `package.json` for development with Vitest 5. CI tests Node.js 22, 24, and 26; the published CLI continues to support Node.js 22 or newer. `pnpm test:coverage` runs the full suite with V8 coverage, prints a text report, and writes JSON summary and HTML reports diff --git a/package.json b/package.json index d016957..c7a713f 100644 --- a/package.json +++ b/package.json @@ -52,5 +52,5 @@ "engines": { "node": ">=22" }, - "packageManager": "pnpm@11.27.1+sha512.a81d4c21b9b09a4b0aebf90ef5e527d4262bdda322d26082978cb549023ac6d9cafc98b19fffaa5c71db438a65f70224edb78d7311187861ff96480d1cdca23c" + "packageManager": "pnpm@11.28.0+sha512.8ed239371de82244b6cccf9e2023c18ea8439961f2ec3fe898913b9f7ee2e76ca0a45717580aca3c7997c135f6d4f5de4524cbeee1a2ccac430c03d134e2a48c" } diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 22bbdeb..083760b 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -30,7 +30,7 @@ importers: version: 4.1.4 '@vitest/coverage-v8': specifier: ^5.0.1 - version: 5.0.1(vitest@5.0.1) + version: 5.0.2(vitest@5.0.2) oxfmt: specifier: ^0.70.0 version: 0.70.0 @@ -42,7 +42,7 @@ importers: version: 7.0.2 vitest: specifier: ^5.0.1 - version: 5.0.1(@types/node@22.20.4)(@vitest/coverage-v8@5.0.1)(vite@8.3.0(@types/node@22.20.4)) + version: 5.0.2(@types/node@22.20.4)(@vitest/coverage-v8@5.0.2)(vite@8.3.0(@types/node@22.20.4)) packages: @@ -561,11 +561,11 @@ packages: cpu: [x64] os: [win32] - '@vitest/coverage-v8@5.0.1': - resolution: {integrity: sha512-FRC8ACiudC3dI6MTplzRSYWHDRnIv2IPfbzs4FdoJNsMal/35sWV8hwIfV8ZcqzSPy+uXHeMVONt9CEqtOU17w==} + '@vitest/coverage-v8@5.0.2': + resolution: {integrity: sha512-3ffHBEi8DOOBLwIGBhOBZbRfYFYWjMUuxZicONdhuFEFEG5AVsMOSrVeuROskqnqpbOmEJwxM2eTVZ9N3a1t+A==} peerDependencies: - '@vitest/browser': 5.0.1 - vitest: 5.0.1 + '@vitest/browser': 5.0.2 + vitest: 5.0.2 peerDependenciesMeta: '@vitest/browser': optional: true @@ -578,8 +578,8 @@ packages: resolution: {integrity: sha512-1EOLRfsTMnyAr3+kEAsP4o9dhaDlGPpD7H5iLBBeq//YpNB1VIahkPhB+eRp9N2Dkfw8oySROjE3yf9XDeaIkQ==} engines: {node: '>=22'} - '@vitest/mocker@5.0.1': - resolution: {integrity: sha512-6K1DoBNAPGvuOcSsGA4D6x+5zEEff/KmOOP3uetT2TrGpVfI+HRHRnJJfKi5ib/g1vx8IYHQD8s0pbJz8WQI7Q==} + '@vitest/mocker@5.0.2': + resolution: {integrity: sha512-Z5FS00Q1SJHkB35xATsmWGdQ5WA1/0MV3CDjqyv7GavHv1OfOj145MNfHOlHk7QLes21dKFDHr8EO2zvL+9WGA==} peerDependencies: msw: ^2.4.9 vite: ^8.3.0 @@ -589,8 +589,8 @@ packages: vite: optional: true - '@vitest/spy@5.0.1': - resolution: {integrity: sha512-rbto/mF/SGERxEgYOek7Xm6B9b+y+mVoo+f4b2LymYO8zM1b7uB5nHuhVMTP2hxdzgxvGiZYGxGIaMvL5y180Q==} + '@vitest/spy@5.0.2': + resolution: {integrity: sha512-Ijc7T1nT9efNb5LxvjaBrEqw3f/QwUv5EE0nKqZxgqsaV/FxAAZ8baGylA8X/Z2oS4Lp+K74Jr6dTJsDKxJDeg==} assertion-error@2.0.1: resolution: {integrity: sha512-Izi8RQcffqCeNVgFigKli1ssklIbpHnCYc6AknXGYoB6grJqyeby7jv12JUQgmTAnIDnbck1uxksT4dzN3PWBA==} @@ -775,9 +775,6 @@ packages: engines: {node: ^20.19.0 || >=22.12.0} hasBin: true - siginfo@2.0.0: - resolution: {integrity: sha512-ybx0WO1/8bSBLEWXZvEd7gMW3Sn3JFlW3TvX1nREbDLRNQNaeNN8WK0meBwPdAaOI7TtRRRJn/Es1zhrrCHu7g==} - signal-exit@3.0.7: resolution: {integrity: sha512-wnD2ZE+l+SPC/uoS0vXeE9L1+0wuaMqKlfz9AMUo38JsyLSBWSFcHR1Rri62LZc12vLr1gb3jl7iwQhgwpAbGQ==} @@ -785,9 +782,6 @@ packages: resolution: {integrity: sha512-UXWMKhLOwVKb728IUtQPXxfYU+usdybtUrK/8uGE8CQMvrhOpwvzDBwj0QhSL7MQc7vIsISBG8VQ8+IDQxpfQA==} engines: {node: '>=0.10.0'} - stackback@0.0.2: - resolution: {integrity: sha512-1XMJE5fQo1jGH6Y/7ebnwPOBEkIEnT4QF32d5R1+VXdXveM0IBMJt8zfaxX1P3QhVwrYe+576+jkANtSS2mBbw==} - std-env@4.2.0: resolution: {integrity: sha512-oCUKSupKTHX53EyjDtuZQ64pjLJ6yYCtpmEw0goYxtjG9KpbRe8KAsl2tBUGU9DyMcJ0RwJ8GqJAFzMXcXW1Rw==} @@ -862,20 +856,20 @@ packages: yaml: optional: true - vitest@5.0.1: - resolution: {integrity: sha512-iA95lQbKEkvrtTkdAgnWbXfbipWiiWe/hDl2P5tMi6WFwD76G0NxXAGp/M9EOcYupeGJRr6wppMc7CoA41TQjg==} + vitest@5.0.2: + resolution: {integrity: sha512-7MQrx9pDv5aHiUcovIb/70Ys3tgtkUVgCtledvKdCmEO+/1Dicq5ZqoSxOW034m03oqC+oHOKui2dM6qtMLoJg==} engines: {node: ^22.12.0 || ^24.0.0 || >=26.0.0} hasBin: true peerDependencies: '@edge-runtime/vm': '*' '@opentelemetry/api': ^1.9.0 '@types/node': ^22.0.0 || >=24.0.0 - '@vitest/browser-playwright': 5.0.1 - '@vitest/browser-preview': 5.0.1 + '@vitest/browser-playwright': 5.0.2 + '@vitest/browser-preview': 5.0.2 '@vitest/browser-webdriverio': ^5.0.0-beta.5 || >=5.0.0 - '@vitest/coverage-istanbul': 5.0.1 - '@vitest/coverage-v8': 5.0.1 - '@vitest/ui': 5.0.1 + '@vitest/coverage-istanbul': 5.0.2 + '@vitest/coverage-v8': 5.0.2 + '@vitest/ui': 5.0.2 happy-dom: '*' jsdom: '*' vite: ^8.3.0 @@ -903,9 +897,9 @@ packages: jsdom: optional: true - why-is-node-running@2.3.0: - resolution: {integrity: sha512-hUrmaWBdVDcxvYqnyh09zunKzROWjbZTiNy8dBEjkS7ehEDQibXJ7XvlmtbwuTclUiIyN+CyXQD4Vmko8fNm8w==} - engines: {node: '>=8'} + why-is-node-running@3.2.2: + resolution: {integrity: sha512-NKUzAelcoCXhXL4dJzKIwXeR8iEVqsA0Lq6Vnd0UXvgaKbzVo4ZTHROF2Jidrv+SgxOQ03fMinnNhzZATxOD3A==} + engines: {node: '>=20.11'} hasBin: true zod@4.6.5: @@ -1179,7 +1173,7 @@ snapshots: '@typescript/typescript-win32-x64@7.0.2': optional: true - '@vitest/coverage-v8@5.0.1(vitest@5.0.1)': + '@vitest/coverage-v8@5.0.2(vitest@5.0.2)': dependencies: '@bcoe/v8-coverage': 1.0.2 '@vitest/istanbul-lib-coverage': 1.0.1 @@ -1189,7 +1183,7 @@ snapshots: obug: 2.2.1 std-env: 4.2.0 tinyrainbow: 3.1.1 - vitest: 5.0.1(@types/node@22.20.4)(@vitest/coverage-v8@5.0.1)(vite@8.3.0(@types/node@22.20.4)) + vitest: 5.0.2(@types/node@22.20.4)(@vitest/coverage-v8@5.0.2)(vite@8.3.0(@types/node@22.20.4)) '@vitest/istanbul-lib-coverage@1.0.1': {} @@ -1197,16 +1191,16 @@ snapshots: dependencies: '@vitest/istanbul-lib-coverage': 1.0.1 - '@vitest/mocker@5.0.1(vite@8.3.0(@types/node@22.20.4))': + '@vitest/mocker@5.0.2(vite@8.3.0(@types/node@22.20.4))': dependencies: '@jridgewell/trace-mapping': 0.3.31 - '@vitest/spy': 5.0.1 + '@vitest/spy': 5.0.2 estree-walker: 3.0.3 magic-string: 1.4.1 optionalDependencies: vite: 8.3.0(@types/node@22.20.4) - '@vitest/spy@5.0.1': {} + '@vitest/spy@5.0.2': {} assertion-error@2.0.1: {} @@ -1387,14 +1381,10 @@ snapshots: '@rolldown/binding-win32-arm64-msvc': 1.2.8 '@rolldown/binding-win32-x64-msvc': 1.2.8 - siginfo@2.0.0: {} - signal-exit@3.0.7: {} source-map-js@1.2.1: {} - stackback@0.0.2: {} - std-env@4.2.0: {} tinybench@6.1.4: {} @@ -1446,10 +1436,10 @@ snapshots: '@types/node': 22.20.4 fsevents: 2.3.3 - vitest@5.0.1(@types/node@22.20.4)(@vitest/coverage-v8@5.0.1)(vite@8.3.0(@types/node@22.20.4)): + vitest@5.0.2(@types/node@22.20.4)(@vitest/coverage-v8@5.0.2)(vite@8.3.0(@types/node@22.20.4)): dependencies: '@types/chai': 5.2.3 - '@vitest/mocker': 5.0.1(vite@8.3.0(@types/node@22.20.4)) + '@vitest/mocker': 5.0.2(vite@8.3.0(@types/node@22.20.4)) chai: 6.2.2 es-module-lexer: 2.3.2 expect-type: 1.4.0 @@ -1461,16 +1451,13 @@ snapshots: tinyexec: 1.3.0 tinyglobby: 0.2.17 vite: 8.3.0(@types/node@22.20.4) - why-is-node-running: 2.3.0 + why-is-node-running: 3.2.2 optionalDependencies: '@types/node': 22.20.4 - '@vitest/coverage-v8': 5.0.1(vitest@5.0.1) + '@vitest/coverage-v8': 5.0.2(vitest@5.0.2) transitivePeerDependencies: - msw - why-is-node-running@2.3.0: - dependencies: - siginfo: 2.0.0 - stackback: 0.0.2 + why-is-node-running@3.2.2: {} zod@4.6.5: {}