Repository navigation
deps: bump the npm-deps group across 1 directory with 3 updates - #574
Merged
Merged
Conversation
Bumps the npm-deps group with 3 updates in the / directory: [tsx](https://github.com/privatenumber/tsx), [sharp](https://github.com/lovell/sharp) and [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node). Updates `tsx` from 4.23.12 to 4.23.13 - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](privatenumber/tsx@v4.23.12...v4.23.13) Updates `sharp` from 0.35.3 to 0.35.4 - [Release notes](https://github.com/lovell/sharp/releases) - [Commits](lovell/sharp@v0.35.3...v0.35.4) Updates `@types/node` from 24.13.3 to 26.4.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) --- updated-dependencies: - dependency-name: tsx dependency-version: 4.23.13 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-deps - dependency-name: sharp dependency-version: 0.35.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-deps - dependency-name: "@types/node" dependency-version: 26.4.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-deps ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
EricAndrechek
approved these changes
Sep 9, 2026
EricAndrechek
deleted the
dependabot/npm_and_yarn/npm-deps-56e289a66a
branch
September 9, 2026 12:56
EricAndrechek
added a commit
that referenced
this pull request
Sep 9, 2026
## Summary Replaces Dependabot's #571 (`astro` 7.1.6 → 7.2.8), whose generated lockfile cannot be installed under this repo's supply-chain policy. Bumps to **astro 7.2.10** with a lockfile resolved by pnpm itself, so it satisfies `minimumReleaseAge`. Supersedes #571 — once `main` carries astro 7.2.10, Dependabot closes that PR itself (its 7.2.8 target is already satisfied). No manual close needed. ## Why #571 could not be rebased `pnpm install --frozen-lockfile` — the install every Node-touching CI job runs — rejected #571's lockfile outright: ``` ✗ Lockfile failed supply-chain policy check (1126 entries in 2.1s) [ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION] 21 lockfile entries failed verification: @clack/core@1.5.0 was published at 2026-09-07T20:12:19.000Z, within the minimumReleaseAge cutoff rolldown@1.2.7 ... postcss@8.5.28 ... tinyexec@1.3.1 ... undici@8.10.2 ... ``` That one `pnpm-install` target — reached via `make verify` (Lint), `make build-docs` → check-docs (Docs build), `make test-ts` (Unit tests), `make test-e2e` → build-ts (E2E tests), and invoked directly by the workflow (Coverage) — failed all five at once, printing no reason for any of them (#578). Integration tests, the one suite that never installs, stayed green on the same lockfile. `@dependabot rebase` / `recreate` cannot fix it: Dependabot resolves with a resolver that does not read `minimumReleaseAge` from `pnpm-workspace.yaml`, so it regenerates the same violating tree. This is #441. Note `astro@7.2.8` itself was **not** the problem — published 2026-08-26, 14 days old and well past the 7-day cooldown. All 21 violations were transitive: `rolldown@1.2.7` plus its 15 platform bindings (09-02), `postcss@8.5.28` / `tinyexec@1.3.1` (09-03), `undici@8.10.2` (09-04), `@clack/core` + `@clack/prompts` (09-07). A Dependabot `cooldown:` setting would not have prevented it, since that gates only the direct dependency. ## What this does instead Bump the manifest and let pnpm resolve. Its resolver *does* honor `minimumReleaseAge`, so it backs off to age-eligible versions on its own: ``` docs/package.json: "astro": "^7.1.1" -> "^7.2.10" pnpm install ``` Resolves `astro@7.2.10` (published 2026-08-31, already past cooldown) with `rolldown@1.2.2`, `postcss@8.5.25`, `undici@8.10.1`, `vite@8.2.0`. One further manifest change rides along, surfaced by pre-push review: - **Declare `@astrojs/markdown-remark` `^7.3.0`.** astro 7.1.6 pinned it to exactly 7.2.2 (an *optional* peer even then, so an unmet one is dropped silently rather than erroring); 7.2.10 widens the range to `^7.3.0`, which the tree's 7.2.2 — a hard dep of `@astrojs/mdx` — doesn't satisfy, so pnpm dropped it from astro's peer set. That's load-bearing: `docs/astro.config.mjs` sets `markdown.remarkPlugins`/`rehypePlugins`, and astro's `coerceLegacyMarkdownPlugins()` does `await import("@astrojs/markdown-remark")` and **throws** if it can't resolve. It only worked via pnpm's hoisted fallback copy — an undeclared edge a narrower `hoist-pattern`, or a starlight/mdx bump dropping that dependency, would break. A `sharp` bump to `^0.35.4` was also part of this branch originally (astro 7.2.8 raised its own optional sharp floor, and the stale 0.35.3 pin had stopped sharing a copy with astro). That change reached `main` first via #574, so it no longer appears in this diff — and #572, the dedicated sharp PR, was superseded by #574 and is already closed. ## Synced with main `origin/main` advanced while this was in review (#570 go-deps, #573 actions-deps, #574 npm-deps all merged). `origin/main` is merged in here — never rebased, per §Branch Maintenance. `pnpm-lock.yaml` conflicted. Resolved by taking main's post-#574 lockfile (`git checkout --theirs pnpm-lock.yaml`) and re-running a targeted `pnpm install` against the merged manifests, rather than hand-merging conflicting YAML. That is deliberate: a lockfile's peer-suffixed keys encode a whole resolution graph, and hand-merging them yields a tree that installs but matches neither side's actual resolution. Re-resolving lets pnpm rebuild the graph under policy. The result keeps both sides intact — #574's catalog `@types/node@26.4.1` and `tsx@4.23.13` are preserved, alongside this branch's `astro@7.2.10` and `@astrojs/markdown-remark@7.3.0`. Net diff vs `main` is now `docs/package.json` (2 lines) plus 281+/136− in `pnpm-lock.yaml`, with zero downgrades. One package drops out entirely — `@rollup/pluginutils@5.4.0`, correct because astro 7.2.x drops its `rollup` optional peer. ## Verification - `pnpm install --frozen-lockfile` — clean, no policy violation (this is what #571 failed), and leaves the lockfile byte-identical. Every entry in the resulting tree is past the 7-day cooldown; the newest is `@types/node@26.4.1` at 7d 17h. - `make build-docs` — 22 pages, all internal links valid, mermaid patched, 68 diagram PNGs rendered. - `make ci` — green on the merged tree. ## Related - #571 — the Dependabot PR this replaces. - #441 — the underlying Dependabot/pnpm cooldown mismatch. [Commented there](#441 (comment)) with the updated failure mode: the repo pinned pnpm 11.1.3 until #490 moved it to 11.21.0, which *does* enforce the policy under `--frozen-lockfile` — so this now fails loudly in CI rather than merging silently as #441 originally described. - #578 — filed from this PR's review: `pnpm-install`'s `--reporter=silent` swallowed the diagnostic entirely, which is why five red jobs stated no reason. - #572 — superseded by #574 (identical sharp bump); closed. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01CbyVditEujZabgu3R11VAm Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm-deps group with 3 updates in the / directory: tsx, sharp and @types/node.
Updates
tsxfrom 4.23.12 to 4.23.13Release notes
Sourced from tsx's releases.
Commits
28e1f12fix(cache): bound shared transform cache memory (#835)Updates
sharpfrom 0.35.3 to 0.35.4Release notes
Sourced from sharp's releases.
Commits
7f1a0a2Release v0.35.4f927818Upgrade to sharp-libvips v1.3.3e802092Prerelease v0.35.4-rc.0e13eb2fCI: Fix wasm32 build (#4589)a82a0b3Upgrade to libvips v8.18.68044fe4Bound resize dimensions to coordinate limit147f859Docs: changelog entries for #4578 #4584ee5bfb8Tests: use yauzl directly rather than via extract-zip wrapper7a77889Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (#4588)ea5bef2Improve support for input Streams finishing before output is requested (#4584)Updates
@types/nodefrom 24.13.3 to 26.4.1Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions