Skip to content

fix: upgrade deps - #140

Merged
9romise merged 6 commits into
mainfrom
upgrade
Jul 21, 2026
Merged

fix: upgrade deps#140
9romise merged 6 commits into
mainfrom
upgrade

Conversation

@9romise

@9romise 9romise commented Jul 17, 2026

Copy link
Copy Markdown
Member

No description provided.

@socket-security

socket-security Bot commented Jul 17, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @emnapi/runtime is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/vite@8.1.5npm/@emnapi/runtime@1.11.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@emnapi/runtime@1.11.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm eslint-plugin-jsdoc is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@vida0905/eslint-config@2.13.0npm/eslint-plugin-jsdoc@63.2.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/eslint-plugin-jsdoc@63.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm yargs is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/msw@2.15.0npm/yargs@17.7.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/yargs@17.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@coderabbitai

coderabbitai Bot commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: f7d68862-860c-4f7d-b97f-be2510c8d00d

📥 Commits

Reviewing files that changed from the base of the PR and between 2055fcd and 67d3dff.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (2)
  • package.json
  • pnpm-workspace.yaml

📝 Walkthrough

Walkthrough

Updates the workspace to pnpm 11.15.1, refreshes dependency catalogs and package-level pins, and replaces the native TypeScript preview setup with typescript and typescript7. Type checking now uses tsc, the VS Code bundling allowlist includes @typescript/typescript6, and diagnostic code-action matching obtains message text through Diagnostic.getMessageString.

Possibly related PRs

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning No pull request description was provided, so it does not describe the dependency upgrade changeset. Add a brief description of the dependency and config updates made in this PR.
✅ Passed checks (2 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch upgrade

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install timed out. The project may have too many dependencies for the sandbox.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@9romise
9romise marked this pull request as draft July 21, 2026 14:31
@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown

⚠️ Dependency Count

This PR adds 42 new dependencies (476 → 518), which exceeds the threshold of 10.

📊 Dependency Size Changes

Note

🎉 This PR removes 7.5 MB of dependencies.

📦 Package 📏 Size
@typescript/native-preview-linux-x64@7.0.0-dev.20260421.2 -28.6 MB
@typescript/typescript-linux-x64@7.0.2 27.9 MB
@rolldown/binding-linux-x64-gnu@1.0.1 -21.5 MB
typescript@5.9.3 → typescript@7.0.2 -21.1 MB
@rolldown/binding-linux-x64-gnu@1.1.5 19.1 MB
@rolldown/binding-linux-x64-gnu@1.2.0 19 MB
@babel/types@7.29.7 2.8 MB
@babel/types@7.29.0 -2.8 MB
@babel/types@8.0.0-rc.5 -2.3 MB
@emnapi/core@1.11.1 2 MB
@emnapi/core@1.11.2 2 MB
@babel/parser@7.29.7 2 MB
@babel/parser@7.29.3 -2 MB
@babel/parser@8.0.0-rc.5 -2 MB
@babel/parser@8.0.0-rc.4 -2 MB
@emnapi/core@1.10.0 -2 MB
eslint-plugin-unicorn@64.0.0 → eslint-plugin-unicorn@68.0.0 1.4 MB
jsdoc-type-pratt-parser@7.1.1 -1.1 MB
caniuse-lite@1.0.30001793 → caniuse-lite@1.0.30001806 -874.9 kB
rolldown@1.2.0 793.1 kB
rolldown@1.1.5 785.9 kB
rolldown@1.0.1 -765.1 kB
@yuku-parser/binding-linux-x64-gnu@0.7.0 712.3 kB
graphql@16.14.0 → graphql@16.14.2 677.8 kB
@babel/generator@8.0.0-rc.5 -478.5 kB
msw@2.14.6 → msw@2.15.0 453.4 kB
@emnapi/runtime@1.11.2 433.6 kB
@emnapi/runtime@1.11.1 433.5 kB
@emnapi/runtime@1.10.0 -433.5 kB
comment-parser@1.4.7 399.1 kB
comment-parser@1.4.6 -396 kB
comment-parser@1.4.5 -379.3 kB
@yuku-codegen/binding-linux-x64-gnu@0.7.0 345.4 kB
regexp-tree@0.1.27 -313.7 kB
tldts@7.0.30 → tldts@7.4.9 -207.2 kB
@es-joy/jsdoccomment@0.88.0 154.3 kB
@es-joy/jsdoccomment@0.86.0 -149.1 kB
@es-joy/jsdoccomment@0.84.0 -148.9 kB
brace-expansion@2.1.2 146.8 kB
@jridgewell/trace-mapping@0.3.31 -146.7 kB
tldts-core@7.0.30 → tldts-core@7.4.9 132.5 kB
@typescript-eslint/rule-tester@8.59.4 -121.4 kB
@clack/prompts@1.4.0 → @clack/prompts@1.7.0 -111.5 kB
@eslint/plugin-kit@0.7.2 109.8 kB
@eslint/plugin-kit@0.7.1 -108.2 kB
@eslint/plugin-kit@0.6.1 -108.2 kB
yuku-codegen@0.7.0 102.2 kB
@jridgewell/gen-mapping@0.3.13 -93.8 kB
vue-eslint-parser@10.4.0 → vue-eslint-parser@10.4.1 80.9 kB
yuku-ast@0.7.0 80.8 kB
verkit@0.1.2 78.4 kB
@clack/core@1.3.1 → @clack/core@1.4.3 -74.1 kB
es-module-lexer@2.1.0 → es-module-lexer@2.3.1 71.3 kB
eslint-plugin-jsdoc@62.9.0 → eslint-plugin-jsdoc@63.2.0 -67.5 kB
@antfu/eslint-config@8.3.0 → @antfu/eslint-config@9.1.0 64.9 kB
lodash.merge@4.6.2 -54.1 kB
@jridgewell/resolve-uri@3.1.2 -53.2 kB
@types/node@25.9.0 → @types/node@26.1.1 53 kB
yuku-parser@0.7.0 52.9 kB
ast-kit@3.0.0-beta.1 -51.5 kB
brace-expansion@5.0.7 50.7 kB
@vue/compiler-sfc@3.5.34 → @vue/compiler-sfc@3.5.40 49.6 kB
@babel/helper-validator-identifier@7.29.7 48.8 kB
@babel/helper-validator-identifier@7.28.5 -48.8 kB
@babel/helper-validator-identifier@8.0.0-rc.5 -48.7 kB
vite@8.0.13 → vite@8.1.5 48.2 kB
brace-expansion@5.0.6 -47.6 kB
enhanced-resolve@5.21.4 → enhanced-resolve@5.24.3 47.4 kB
eslint-plugin-vue@10.9.1 → eslint-plugin-vue@10.10.0 46.6 kB
@yuku-toolchain/types@0.7.0 46.4 kB
@oxc-project/types@0.139.0 44.6 kB
@oxc-project/types@0.140.0 44.6 kB
@oxc-project/types@0.130.0 -44.5 kB
@e18e/eslint-plugin@0.4.1 → @e18e/eslint-plugin@0.5.1 39.3 kB
vscode-languageserver-types@3.17.5 → vscode-languageserver-types@3.18.0 37.8 kB
@babel/helper-string-parser@8.0.0-rc.5 -34.3 kB
@babel/helper-string-parser@7.29.7 31.8 kB
@babel/helper-string-parser@7.27.1 -31.8 kB
@types/hast@3.0.4 → @types/hast@3.0.5 25.6 kB
yargs@17.7.2 → yargs@17.7.3 25 kB
postcss-selector-parser@7.1.1 → postcss-selector-parser@7.1.4 24.9 kB
birpc@4.0.0 -23.5 kB
ocache@0.1.4 → ocache@0.2.0 22.3 kB
type-fest@5.6.0 → type-fest@5.8.0 18.5 kB
node-releases@2.0.44 → node-releases@2.0.51 18.4 kB
expect-type@1.3.0 → expect-type@1.4.0 18.3 kB
@vida0905/eslint-config@2.12.0 → @vida0905/eslint-config@2.13.0 17.1 kB
vscode-jsonrpc@8.2.0 → vscode-jsonrpc@9.0.1 16.8 kB
@vitest/eslint-plugin@1.6.17 → @vitest/eslint-plugin@1.6.23 15.4 kB
module-replacements@3.0.0-beta.8 → module-replacements@3.0.0 14.4 kB
@typescript/native-preview@7.0.0-dev.20260421.2 -14.2 kB
eslint@10.4.0 → eslint@10.7.0 13.5 kB
eslint-plugin-de-morgan@2.1.2 → eslint-plugin-de-morgan@2.1.3 12.8 kB
tinyexec@1.1.2 → tinyexec@1.2.4 -12.5 kB
@tybys/wasm-util@0.10.2 → @tybys/wasm-util@0.10.3 12.1 kB
brace-expansion@2.1.0 -11.7 kB
@typescript-eslint/eslint-plugin@8.59.4 → @typescript-eslint/eslint-plugin@8.64.0 11.6 kB
@typescript/typescript6@6.0.2 10.5 kB
postcss@8.5.14 → postcss@8.5.20 10.2 kB
eslint-plugin-perfectionist@5.9.0 → eslint-plugin-perfectionist@5.10.0 10.1 kB
detect-indent@7.0.2 9.9 kB
tsdown@0.22.0 → tsdown@0.22.12 8.5 kB
nanoid@3.3.12 → nanoid@3.3.16 -8.5 kB
eslint-plugin-n@18.0.1 → eslint-plugin-n@18.2.2 8.4 kB
fast-wrap-ansi@0.2.0 → fast-wrap-ansi@0.2.2 -8.3 kB
lightningcss-linux-x64-gnu@1.32.0 → lightningcss-linux-x64-gnu@1.33.0 -8.2 kB
rolldown-plugin-dts@0.25.1 → rolldown-plugin-dts@0.27.12 7.6 kB
@types/jsesc@2.5.1 -7.5 kB
@napi-rs/wasm-runtime@1.1.4 → @napi-rs/wasm-runtime@1.1.6 7.2 kB
@eslint/markdown@8.0.1 → @eslint/markdown@8.0.3 6.9 kB
obug@2.1.1 → obug@2.1.4 6 kB
eslint-plugin-regexp@3.1.0 → eslint-plugin-regexp@3.1.1 -5.4 kB
electron-to-chromium@1.5.357 → electron-to-chromium@1.5.393 5.4 kB
acorn@8.16.0 → acorn@8.17.0 4.4 kB
tough-cookie@6.0.1 → tough-cookie@6.0.2 4.3 kB
eslint-plugin-yml@3.3.2 → eslint-plugin-yml@3.6.0 4.3 kB
@typescript-eslint/typescript-estree@8.59.4 → @typescript-eslint/typescript-estree@8.64.0 4.2 kB
lightningcss@1.32.0 → lightningcss@1.33.0 3.3 kB
@pkgr/core@0.2.9 → @pkgr/core@0.3.6 3.1 kB
@vue/compiler-core@3.5.34 → @vue/compiler-core@3.5.40 2.7 kB
package-manager-detector@1.6.0 → package-manager-detector@1.7.0 2.6 kB
@emnapi/wasi-threads@1.2.1 → @emnapi/wasi-threads@1.2.2 -2.6 kB
@vue/compiler-dom@3.5.34 → @vue/compiler-dom@3.5.40 2.5 kB
baseline-browser-mapping@2.10.31 → baseline-browser-mapping@2.10.43 2.2 kB
undici-types@7.24.6 → undici-types@8.3.0 1.9 kB
@typescript-eslint/types@8.59.4 → @typescript-eslint/types@8.64.0 1.6 kB
picomatch@4.0.4 → picomatch@4.0.5 1.6 kB
@inquirer/core@11.1.10 → @inquirer/core@11.2.1 1.3 kB
globals@17.6.0 → globals@17.7.0 1.2 kB
exsolve@1.0.8 → exsolve@1.1.0 -1.1 kB
eslint-plugin-jsonc@3.1.2 → eslint-plugin-jsonc@3.3.0 -1.1 kB
ignore@7.0.5 → ignore@7.0.6 1 kB
semver@7.8.0 → semver@7.8.5 1 kB
yaml-eslint-parser@2.0.0 → yaml-eslint-parser@2.1.0 904 B
vitest@4.1.6 → vitest@4.1.10 891 B
tinyglobby@0.2.16 → tinyglobby@0.2.17 615 B
@vitest/mocker@4.1.6 → @vitest/mocker@4.1.10 504 B
eslint-plugin-command@3.5.2 → eslint-plugin-command@3.5.3 474 B
@typescript-eslint/utils@8.59.4 → @typescript-eslint/utils@8.64.0 453 B
object-deep-merge@2.0.0 → object-deep-merge@2.0.1 443 B
@vue/shared@3.5.34 → @vue/shared@3.5.40 243 B
@typescript-eslint/scope-manager@8.59.4 → @typescript-eslint/scope-manager@8.64.0 190 B
ansis@4.3.0 → ansis@4.3.1 -157 B
@typescript-eslint/tsconfig-utils@8.59.4 → @typescript-eslint/tsconfig-utils@8.64.0 113 B
@typescript-eslint/parser@8.59.4 → @typescript-eslint/parser@8.64.0 110 B
@vitest/runner@4.1.6 → @vitest/runner@4.1.10 99 B
set-cookie-parser@3.1.0 → set-cookie-parser@3.1.2 91 B
@typescript-eslint/type-utils@8.59.4 → @typescript-eslint/type-utils@8.64.0 90 B
@typescript-eslint/visitor-keys@8.59.4 → @typescript-eslint/visitor-keys@8.64.0 90 B
@typescript-eslint/project-service@8.59.4 → @typescript-eslint/project-service@8.64.0 90 B
std-env@4.1.0 → std-env@4.2.0 -84 B
xml-name-validator@4.0.0 → xml-name-validator@5.0.0 29 B
@eslint-community/eslint-plugin-eslint-comments@4.7.1 → @eslint-community/eslint-plugin-eslint-comments@4.7.2 25 B
@inquirer/confirm@6.0.13 → @inquirer/confirm@6.1.1 -13 B
builtin-modules@5.2.0 → builtin-modules@5.3.0 13 B
@inquirer/type@4.0.5 → @inquirer/type@4.0.7 -11 B
@inquirer/ansi@2.0.5 → @inquirer/ansi@2.0.7 -11 B
@inquirer/figures@2.0.5 → @inquirer/figures@2.0.7 -11 B
@vitest/expect@4.1.6 → @vitest/expect@4.1.10 4 B
eslint-plugin-toml@1.3.1 → eslint-plugin-toml@1.4.0 -3 B
@vitest/snapshot@4.1.6 → @vitest/snapshot@4.1.10 3 B
@vitest/utils@4.1.6 → @vitest/utils@4.1.10 2 B
@vitest/spy@4.1.6 → @vitest/spy@4.1.10 1 B
@vitest/pretty-format@4.1.6 → @vitest/pretty-format@4.1.10 1 B
browserslist@4.28.2 → browserslist@4.28.6 -1 B
typescript@@typescript/typescript6@6.0.2 Unknown
typescript7@typescript@7.0.2 Unknown
eslint-plugin-pnpm@1.6.0 → eslint-plugin-pnpm@1.6.1 0 B
local-pkg@1.1.2 → local-pkg@1.2.1 0 B
@typescript/old@typescript@6.0.3 Unknown
@vue/compiler-ssr@3.5.34 → @vue/compiler-ssr@3.5.40 0 B
synckit@0.11.12 → synckit@0.11.13 0 B
pnpm-workspace-yaml@1.6.0 → pnpm-workspace-yaml@1.6.1 0 B
regjsparser@0.13.1 → regjsparser@0.13.2 0 B
escape-string-regexp@1.0.5 Unknown
clean-regexp@1.0.0 Unknown

Total size change: -7.5 MB

⚠️ Package Size Increase

📦 Package 📏 Base Size 📏 Source Size 📈 Size Change
npmx-language-server 237.9 kB 237.9 kB +1 B

@9romise
9romise marked this pull request as ready for review July 21, 2026 16:10
@9romise
9romise added this pull request to the merge queue Jul 21, 2026
Merged via the queue into main with commit af651e4 Jul 21, 2026
18 checks passed
@9romise
9romise deleted the upgrade branch July 21, 2026 16:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant