Skip to content

chore(deps-dev): bump @ast-grep/cli from 0.43.0 to 0.44.1#118

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/ast-grep/cli-0.44.1
Closed

chore(deps-dev): bump @ast-grep/cli from 0.43.0 to 0.44.1#118
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/ast-grep/cli-0.44.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 17, 2026

Copy link
Copy Markdown

Bumps @ast-grep/cli from 0.43.0 to 0.44.1.

Release notes

Sourced from @​ast-grep/cli's releases.

0.44.1

0.44.0

... (truncated)

Changelog

Sourced from @​ast-grep/cli's changelog.

0.44.1

0.44.0

21 June 2026

... (truncated)

Commits
  • 26f7845 0.44.1
  • de129f2 chore(deps): update rust crate napi to v3.10.3 (#2786)
  • 6859948 chore(deps): update rust crate napi-derive to v3.5.9 (#2785)
  • b50dd49 chore(deps): update dependency oxlint to v1.72.0 (#2780)
  • c16babe chore(deps): update rust crate terminal-light to v1.9.0 (#2781)
  • 6bcb735 chore(deps): update rust crate clap_complete to v4.6.7 (#2783)
  • 0708018 chore(deps): update rust crate ignore to v0.4.27 (#2784)
  • fe3607e fix(cli): bound outline file queue (#2787)
  • ba4047f chore(deps): update rust crate clap_complete to v4.6.6 (#2782)
  • 50d1510 chore(deps): update dependency @​ast-grep/napi to v0.44.0 (#2764)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 17, 2026
Bumps [@ast-grep/cli](https://github.com/ast-grep/ast-grep) from 0.43.0 to 0.44.1.
- [Release notes](https://github.com/ast-grep/ast-grep/releases)
- [Changelog](https://github.com/ast-grep/ast-grep/blob/main/CHANGELOG.md)
- [Commits](ast-grep/ast-grep@0.43.0...0.44.1)

---
updated-dependencies:
- dependency-name: "@ast-grep/cli"
  dependency-version: 0.44.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/ast-grep/cli-0.44.1 branch from ca91a4a to e98b3c5 Compare July 17, 2026 20:20
agjs added a commit that referenced this pull request Jul 20, 2026
* chore(deps): consolidate the 14 open dependabot bumps

Single PR superseding the open dependabot PRs:
- fast-check 3.23.2 → 4.9.0 (packages/core) — full suite green on v4 (#93/#99)
- astro 7.0.9 → 7.1.3 (root + apps/docs) — clears GHSA-4g3v-8h47-v7g6 (#158/#162)
- @astrojs/react 5.0.6 → 6.0.1 (#114), @astrojs/sitemap 3.7.2 → 3.7.3 (#116)
- astro-mermaid 2.0.1 → 2.1.0 (#119)
- tailwindcss + @tailwindcss/vite 4.3.2 → 4.3.3 (#115/#117)
- wrangler 4.110.0/4.111.0 → 4.112.0 (#161), @ast-grep/cli 0.43.0 → 0.44.1 (#118)

Validated: typecheck + lint + full suite (2820) green. Docs build + osv run by CI.
NOTE: the transitive brace-expansion CVE (not a dependabot PR) is separate and may
still need an override; GH Actions bumps (#160 checkout, #112 lychee) are workflow
YAML, follow-up.

* fix(deps): pin brace-expansion to patched 5.0.7 (CVE-2026-13149)

New high-severity ReDoS advisory CVE-2026-13149 / GHSA-3jxr-9vmj-r5cp (published
~2026-07-20 21:00) affects brace-expansion <1.1.16 / <2.1.2 / <5.0.7. The lockfile
had 1.1.15 and 5.0.6 (transitive via eslint→minimatch/glob — a real runtime dep of
the published package, so it is FIXED, not ignored). Override forces all instances
to 5.0.7 (patched; API is a single stable expand() fn across majors). typecheck +
lint (uses minimatch/glob) + full suite green.

* fix(deps): pin js-yaml to patched 4.3.0 (GHSA-52cp-r559-cp3m)

The astro/tooling bumps pulled js-yaml 4.2.0 (High ReDoS, GHSA-52cp-r559-cp3m,
fixed 4.3.0). Transitive, 4.x only (no 3.x consumers) → override to 4.3.0.
osv-scanner local run: 'No issues found', exit 0. typecheck + lint + full suite green.
@agjs

agjs commented Jul 20, 2026

Copy link
Copy Markdown
Owner

Superseded by #164 (consolidated dependabot bumps), merged to main.

@agjs agjs closed this Jul 20, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/ast-grep/cli-0.44.1 branch July 20, 2026 22:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant