build(deps): bump diff and mocha in /eng - #2402
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [diff](https://github.com/kpdecker/jsdiff) to 9.0.0 and updates ancestor dependency [mocha](https://github.com/mochajs/mocha). These dependencies need to be updated together. Updates `diff` from 7.0.0 to 9.0.0 - [Changelog](https://github.com/kpdecker/jsdiff/blob/master/release-notes.md) - [Commits](kpdecker/jsdiff@7.0.0...v9.0.0) Updates `mocha` from 11.7.6 to 12.0.3 - [Release notes](https://github.com/mochajs/mocha/releases) - [Changelog](https://github.com/mochajs/mocha/blob/main/CHANGELOG.md) - [Commits](mochajs/mocha@v11.7.6...v12.0.3) --- updated-dependencies: - dependency-name: diff dependency-version: 9.0.0 dependency-type: indirect - dependency-name: mocha dependency-version: 12.0.3 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The package’s Node engine range includes versions unsupported by Mocha 12.
Review effort: Balanced
Findings: 1
What changed in this PR
Updates the engineering package’s test dependencies.
Changes:
- Upgrades Mocha from 11.7.6 to 12.0.3.
- Updates transitive
diffand related dependencies.
| File | Description |
|---|---|
eng/package.json |
Updates Mocha. |
eng/package-lock.json |
Refreshes the resolved dependency tree. |
Files not reviewed (1)
- eng/package-lock.json: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| "chai-as-promised": "^8.0.2", | ||
| "eslint": "^10.7.0", | ||
| "mocha": "^11.7.6", | ||
| "mocha": "^12.0.3", |
Brandon Waterloo [MSFT] (bwateratmsft)
left a comment
There was a problem hiding this comment.
🤖 This update has not reached the required package age of 168 hours (7 full days).
| Package | Version | Published (UTC) | Eligible (UTC) | Notes |
|---|---|---|---|---|
mocha |
12.0.3 |
2026-10-01T04:37:57Z | 2026-10-08T04:37:57Z | direct dependency |
The whole update becomes eligible at 2026-10-08T04:37:57Z.
Please wait until the eligibility time before approval.
|
Unacceptable. Major bumps are way out of Dependabot's scope here. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |

Bumps diff to 9.0.0 and updates ancestor dependency mocha. These dependencies need to be updated together.
Updates
difffrom 7.0.0 to 9.0.0Changelog
Sourced from diff's changelog.
... (truncated)
Commits
ed13acaUpdate version in package.json and in release notes (#683)7a49317Bump dependencies again (#682)afe5aecAdd Git support, and otherwise variously improve & fix parsePatch (and other ...2e46779Fix a typo (#679)dd2f9948.0.4 release (#678)3cc4384Update docs on releasing to reflect migration to yarn berry (#677)6fc2aa6yarn up '*' && yarn up -R '**' (#676)af7393ayarn up '*' && yarn up -R '**' (#670)4b5d180Fix another bug in diffWords's "intlSegmenter" mode (#667)10da50cyarn up '*' && yarn up -R '**' (#666)Updates
mochafrom 11.7.6 to 12.0.3Release notes
Sourced from mocha's releases.
... (truncated)
Changelog
Sourced from mocha's changelog.
... (truncated)
Commits
51a0cc5chore(main): release 12.0.3 (#6353)1227939fix: support--Xone-char aliases (#6391)bb2e69adocs: refresh help output, fix stale links (#6357)921c161fix: keep watching when the last test file is removed (#6355)3382fddtest: add --import=tsx integration test (#6356)a68344ffix: show require() error on unsupported directory import (#6354)d59467atest: touch a new file without stamping it afterwards (#6349)70db1c7chore(main): release 12.0.2 (#6300)571110ffix: give CLI reporter-option precedence over config file (#6331)a652ff5fix: use find-up-simple to workaround ERR_PACKAGE_PATH_NOT_EXPORTED (#6342)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.