Skip to content

Update development dependencies (supersedes Dependabot PRs) - #85

Merged
JosephMaynard merged 2 commits into
masterfrom
codex/update-dependencies
Jul 10, 2026
Merged

JosephMaynard merged 2 commits into
masterfrom
codex/update-dependencies

Conversation

@JosephMaynard

@JosephMaynard JosephMaynard commented Jul 10, 2026 •

Copy link
Copy Markdown
Owner

Updates all dev dependencies in one pass, superseding the four open Dependabot PRs:

Why not just merge #84: TypeScript 7 breaks ts-node (TypeError: Cannot read properties of undefined (reading 'fileExists') in ts-node's config loading), which the build scripts used. This branch replaces ts-node with tsx in the build/dev scripts, which is why CI fails on #84 but passes here.

Also updates the scorecard-action version comment and test expectations.

Verified locally: npm run build and npm run test:unit (153/153) pass.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Improvements

    • Updated development and build commands to use tsx for faster, streamlined TypeScript execution.
    • Refreshed the embedded dependency report interface assets.
  • Bug Fixes

    • Updated the security scorecard workflow to use the latest pinned Scorecard action release.
  • Documentation

    • Updated development instructions to reflect the new tsx command.

@coderabbitai

coderabbitai Bot commented Jul 10, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 439587bb-c9fb-4885-ac3c-90783e335e81

📥 Commits

Reviewing files that changed from the base of the PR and between 8f0fa48 and 27f30e0.

⛔ Files ignored due to path filters (6)
  • dist/cli.js is excluded by !**/dist/**
  • dist/report-assets.js is excluded by !**/dist/**
  • dist/runners/lockfileParsers.js is excluded by !**/dist/**
  • dist/runners/maintenanceSignals.js is excluded by !**/dist/**
  • package-lock.json is excluded by !**/package-lock.json
  • report-ui/dist/report.iife.js is excluded by !**/dist/**
📒 Files selected for processing (5)
  • .github/workflows/scorecard.yml
  • README.md
  • package.json
  • src/cli.test.ts
  • src/report-assets.ts

📝 Walkthrough

Walkthrough

The PR migrates TypeScript execution from ts-node to tsx, updates related dependencies and CLI tests, regenerates embedded report JavaScript, and repins the OpenSSF Scorecard action to v2.4.3.

Changes

Tooling and report generation

Layer / File(s) Summary
tsx execution migration
package.json, README.md, src/cli.test.ts
Build, development, documentation, and CLI test commands now use tsx; ts-node is removed and selected dependencies are upgraded.
Embedded report bundle refresh
src/report-assets.ts
The embedded dependency-radar report JavaScript is replaced with regenerated minified output.

Scorecard workflow update

Layer / File(s) Summary
Pinned Scorecard action
.github/workflows/scorecard.yml
The workflow updates its pinned OpenSSF Scorecard action from v2.4.0 to v2.4.3.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title matches the main purpose of the PR: bundling development dependency updates and superseding Dependabot updates.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/update-dependencies

Comment @coderabbitai help to get the list of available commands.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant