Skip to content

chore(deps-dev): bump the development group with 4 updates - #141

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/development-6c92528911
Closed

chore(deps-dev): bump the development group with 4 updates#141
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/development-6c92528911

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the development group with 4 updates: @types/node, @types/pg, eslint-config-next and tsx.

Updates @types/node from 26.1.2 to 26.2.0

Commits

Updates @types/pg from 8.20.2 to 8.21.0

Commits

Updates eslint-config-next from 15.5.22 to 15.5.23

Release notes

Sourced from eslint-config-next's releases.

v15.5.23

What's Changed

Full Changelog: vercel/next.js@v15.5.22...v15.5.23

Commits

Updates tsx from 4.23.1 to 4.23.11

Release notes

Sourced from tsx's releases.

v4.23.11

4.23.11 (2026-08-07)

Bug Fixes

  • preserve async ESM require fallback (55cbece)

This release is also available on:

v4.23.10

4.23.10 (2026-08-07)

Bug Fixes


This release is also available on:

v4.23.9

4.23.9 (2026-08-06)

Bug Fixes

  • map Node test locations (2f55884)
  • support data URLs in tsImport (b94f46f)

This release is also available on:

v4.23.8

4.23.8 (2026-08-05)

Bug Fixes

  • preserve package subpath resolution (be1315e)
  • preserve typeless ESM dependency exports (70dfc5e)

This release is also available on:

... (truncated)

Commits
  • bd3bc64 test: cover CommonJS loader source fallback
  • 55cbece fix: preserve async ESM require fallback
  • 6c5ba85 docs: document CommonJS default interop
  • ec1bcd5 fix: support nyc coverage discovery (#710)
  • b6e5b48 docs: clarify CommonJS default imports
  • 2f55884 fix: map Node test locations
  • de935d5 docs: document Node source-map stack formatting
  • b94f46f fix: support data URLs in tsImport
  • be1315e fix: preserve package subpath resolution
  • 5efba41 docs: organize transform backend research
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the development group with 4 updates: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node), [@types/pg](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/pg), [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) and [tsx](https://github.com/privatenumber/tsx).


Updates `@types/node` from 26.1.2 to 26.2.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@types/pg` from 8.20.2 to 8.21.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/pg)

Updates `eslint-config-next` from 15.5.22 to 15.5.23
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v15.5.23/packages/eslint-config-next)

Updates `tsx` from 4.23.1 to 4.23.11
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.1...v4.23.11)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development
- dependency-name: "@types/pg"
  dependency-version: 8.21.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development
- dependency-name: eslint-config-next
  dependency-version: 15.5.23
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
- dependency-name: tsx
  dependency-version: 4.23.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 10, 2026
@dependabot
dependabot Bot requested a review from WhiteMuush as a code owner August 10, 2026 22:37
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 10, 2026
@WhiteMuush

Copy link
Copy Markdown
Owner

Superseded by #142.

This pull request targets main, which is 64 commits behind develop, the integration branch. Retargeting was not possible: the lockfile conflicts with develop (next-auth removed, better-auth added). The bumps have been redone against the develop tree in #142, where every gate passes, including the Dependency audit job that was red here.

The one bump left out is @tanstack/react-table 8 to 9, a breaking major that needs a migration of EmployeeTable.tsx, tracked in its own issue.

@WhiteMuush WhiteMuush closed this Aug 11, 2026
@WhiteMuush
WhiteMuush deleted the dependabot/npm_and_yarn/development-6c92528911 branch August 11, 2026 12:48
@dependabot @github

dependabot Bot commented on behalf of github Aug 11, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

WhiteMuush added a commit that referenced this pull request Aug 11, 2026
…142)

* chore(deps): port the august bumps to develop and fix the audit gate

Dependabot opened #139, #140 and #141 against main, which is 64 commits
behind develop. Their lockfiles conflict with develop (next-auth removed,
better-auth added), so the bumps are redone here against the develop tree.

Ported:
- github/codeql-action 4.37.4 to 4.37.6
- @aws-sdk/client-identitystore, @base-ui/react, lucide-react, next 16.3.0
- @types/node, @types/pg, eslint-config-next, tsx

Left out: @tanstack/react-table 8 to 9. It is a breaking major that renames
the row model factories (getCoreRowModel to createCoreRowModel) and needs a
migration of EmployeeTable.tsx. Tracked separately.

The Dependency audit job was already failing on develop before these PRs,
on two high advisories reaching us through transitives:
- js-yaml 4.3.0 via @eslint/eslintrc (GHSA-5p4m-2wfm-xmqj)
- nanoid 3.3.16 via postcss (GHSA-2v37-7h3g-55p8)
Both are pinned through overrides, so npm audit --audit-level=high is clean.

* chore(next): opt out of the AGENTS.md rewrite added in next 16.3

Next 16.3 ships an `agentRules` option, on by default, that makes `next dev`
append a Next-authored block to AGENTS.md on every run. Two problems here:
the block contains a non-ASCII character, which the pre-push ASCII gate
rejects, and the working tree goes dirty on each dev start.

AGENTS.md is ours, so the option is turned off.

* fix(test): stop the RBAC integration suite from sharing the seeded admin (#144)

require-permission.itest.ts reassigned the shared admin account to Viewer,
then restored Administrator at the end. That only holds if suites run one at
a time. Vitest runs test files in parallel against the same database, so any
suite reading the admin's role inside that window sees the read-only Viewer
set instead.

This is what broke Integration (DB) on the deps branch: roles/route.itest.ts
reported the admin missing exactly the ten non-read permissions of the SOC
Analyst preset, which is the Viewer set. Forcing the admin to Viewer and
running that suite reproduces the CI output character for character.

The suite now seeds its own company and asserts on that company's Viewer
role. It never touched the admin user for its assertions anyway, the
reassignment was dead weight that only created the race.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant