Skip to content

[CSR-0] chore: Bump typescript from 5.9.3 to 7.0.2 - #414

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/typescript-7.0.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/typescript-7.0.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Bumps typescript from 5.9.3 to 7.0.2.

Release notes

Sourced from typescript's releases.

TypeScript 7.0.2

https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/

This tag was originally released at: https://github.com/microsoft/typescript-go/releases/tag/typescript%2Fv7.0.2

TypeScript 6.0.3

For release notes, check out the release announcement blog post.

Downloads are available on:

TypeScript 6.0

For release notes, check out the release announcement blog post.

Downloads are available on:

TypeScript 6.0.1 RC

For release notes, check out the release announcement blog post.

Downloads are available on:

TypeScript 6.0 Beta

For release notes, check out the release announcement.

Downloads are available on:

Commits
  • 1e4744d Merge branch 'main' into ts7-release
  • a5a219cmicrosoft/typescript-go#4558
  • ecfe30d Update status localization
  • 5de25b5 Hide executable name in TypeScript status
  • d7ce74a Show bundled TypeScript version for packaged servers
  • 29be66a Correct TS 7 release version to 7.0.2
  • ed2bd1b Merge branch 'main' into ts7-release
  • 8873075 Bump the github-actions group across 1 directory with 3 updates (microsoft/ty...
  • 9427131 Set up stable / nightly extension split, other prep (microsoft/typescript-go#...
  • d4eaca5microsoft/typescript-go#4549
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by microsoft1es, a new releaser for typescript since your current version.


Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.9.3 to 7.0.2.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v5.9.3...v7.0.2)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 31, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 31, 2026

Copy link
Copy Markdown
Contributor Author

Assignees

The following users could not be added as assignees: ynahmany. Either the username does not exist or it does not have the correct permissions to be added as an assignee.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the javascript Pull requests that update javascript code label Aug 31, 2026

Copy link
Copy Markdown
Contributor

Security triage: Tier B — needs a decision. This is a major compiler bump, not a routine dependency refresh.

What and why — typescript 5.9.3 → 7.0.2 across packages/cmd and packages/jest. This closes no security finding. npm audit on this repo reports @humanfs/node (moderate, <0.16.8), vitest / @vitest/mocker (moderate, ≤4.1.10) and esbuild (low, 0.27.3–0.28.0); none of them is TypeScript. There is no Vanta finding for this repo due inside the next 30 days, so nothing here is on a compliance clock — this can take the time it deserves.

Exposure — development: typescript is in the devDependencies of both packages. But "development scope" understates it. This compiler produces the published @currents/cmd and @currents/jest build output, so a behaviour change lands in what users install even though the dependency itself does not ship.

Why Tier B — a major bump is Tier B on its own under this rubric, and never taken to close an alert. Three further things in the diff are worth naming:

  • It adds 20 new @typescript/typescript-* platform packages (aix-ppc64, darwin-arm64, linux-x64, win32-x64, …) as optional dependencies. TypeScript 7 is the native port, so the toolchain gains a per-platform binary where 5.9 was pure JavaScript. That changes what a CI runner and a publish job download and execute.
  • It flips "peer": true onto the root node_modules/typescript stanza while the workspace copies move to 7.0.2 — so the repo ends up resolving more than one TypeScript. Worth confirming that is intended and that ts-jest (^29.4.12, which declares a TypeScript peer range) is satisfied by what it actually gets.
  • It edits two manifests and strips "peer": true from ~25 @esbuild/* stanzas, the same unrelated lockfile churn carried by the other Dependabot PRs opened here on 2026-08-31.

Breaking-change check — TypeScript 7 is a major release with real behaviour differences from the 5.x line, not a version-number formality. I did not find a changelog section that makes this safe to take unattended, which is itself the finding: a compiler major wants a human reading the migration notes against this codebase, not a rubric.

CI coverage — lint, types-matrix and unit-test all run on every PR to main with no paths filter. types-matrix is the one that matters here, since it is what would actually exercise a new compiler.

Verification — I read the diff and resolved the dependency scope from both manifests. I did not run this repo's scripts against this branch; for a compiler major that verification belongs with whoever decides to take it.

What a human should still check — whether the project wants TypeScript 7 at all yet, and if so, that it lands deliberately across all workspaces at once rather than through three separate Dependabot PRs. #416 and #417 move the same dependency in packages/cmd and packages/jest; taking one without the others leaves the repo straddling two compiler majors.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants