Skip to content

chore(deps-dev): bump the dev-dependencies group with 10 updates - #624

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dev-dependencies-6fec8ed1f2
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dev-dependencies-6fec8ed1f2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the dev-dependencies group with 10 updates:

Package From To
@commitlint/cli 21.2.2 21.2.3
@commitlint/config-conventional 21.2.2 21.2.3
@microsoft/api-extractor 7.59.1 7.59.2
@vitest/browser-webdriverio 4.1.11 5.0.0
@vitest/coverage-v8 4.1.11 5.0.2
fast-check 4.10.1 4.10.2
jscpd 5.2.1 5.3.2
knip 6.36.0 6.38.0
vite-plus 0.3.2 1.0.0
webdriverio 9.31.9 9.32.0

Updates @commitlint/cli from 21.2.2 to 21.2.3

Release notes

Sourced from @​commitlint/cli's releases.

v21.2.3

21.2.3 (2026-09-19)

Bug Fixes

Refactor

Chore, ci, build, etc.

New Contributors

Full Changelog: conventional-changelog/commitlint@v21.2.2...v21.2.3

Changelog

Sourced from @​commitlint/cli's changelog.

21.2.3 (2026-09-19)

Bug Fixes

  • lint: trim trailing whitespace off the message handed to ignore matchers (#4960) (a6f279b)
Commits
  • 95d4056 v21.2.3
  • a6f279b fix(lint): trim trailing whitespace off the message handed to ignore matchers...
  • See full diff in compare view

Updates @commitlint/config-conventional from 21.2.2 to 21.2.3

Release notes

Sourced from @​commitlint/config-conventional's releases.

v21.2.3

21.2.3 (2026-09-19)

Bug Fixes

Refactor

Chore, ci, build, etc.

New Contributors

Full Changelog: conventional-changelog/commitlint@v21.2.2...v21.2.3

Changelog

Sourced from @​commitlint/config-conventional's changelog.

21.2.3 (2026-09-19)

Bug Fixes

  • rules: report the case that matched in case rule failure messages (#4962) (9f5f7bc)
Commits

Updates @microsoft/api-extractor from 7.59.1 to 7.59.2

Changelog

Sourced from @​microsoft/api-extractor's changelog.

7.59.2

Tue, 22 Sep 2026 17:35:41 GMT

Patches

  • Update the @microsoft/tsdoc dependency to ~0.17.0 and the @microsoft/tsdoc-config dependency to ~0.18.2.
Commits

Updates @vitest/browser-webdriverio from 4.1.11 to 5.0.0

Release notes

Sourced from @​vitest/browser-webdriverio's releases.

v5.0.0

   🚀 Features

    View changes on GitHub

v5.0.0-rc.1

No significant changes

    View changes on GitHub

v5.0.0-beta.6

   🐞 Bug Fixes

    View changes on GitHub
Commits

Updates @vitest/coverage-v8 from 4.1.11 to 5.0.2

Release notes

Sourced from @​vitest/coverage-v8's releases.

v5.0.2

   🐞 Bug Fixes

    View changes on GitHub

v5.0.1

   🚀 Features

   🐞 Bug Fixes

... (truncated)

Commits

Updates fast-check from 4.10.1 to 4.10.2

Release notes

Sourced from fast-check's releases.

v4.10.2

Fix interrupt plugin (throwing) [Code][Diff]

Fixes

  • (PR#7333) Bug: Plugin interruptAfterTimeLimit crashes
Changelog

Sourced from fast-check's changelog.

4.10.2

Fix interrupt plugin (throwing) [Code][Diff]

Fixes

  • (PR#7333) Bug: Plugin interruptAfterTimeLimit crashes
Commits

Updates jscpd from 5.2.1 to 5.3.2

Release notes

Sourced from jscpd's releases.

Release v5.3.2

New Features

  • Rust dead code, read from the compiler. jscpd does not parse Rust, and does not need to. Every cargo build already prints lines like function reprint is never used, with real name resolution, trait dispatch and macro expansion behind them. The dead-code run now reads that output, from the JSON of cargo check (or build, clippy, test --no-run), and reports it next to everything else, through the same categories, reporters and --min-confidence, at 100% confidence.
    • basta takes --rust-diagnostics <file>, or - for a pipe: cargo check --all-targets --message-format=json | basta . --rust-diagnostics -.
    • jscpd takes the same flag for --dead-code, --dashboard and --health, so a Rust project gets its health badge from the check it already runs: cargo check --all-targets --message-format=json | jscpd . --health --rust-diagnostics - --reporters badge. The dead-code section of the config file takes the file as rustDiagnostics.
    • Neither tool runs cargo itself, because that would execute the project's build scripts and procedural macros.
    • The compiler's span covers only the name, so the item's real size is read from the source. An item that --all-targets reports twice is counted once. A diagnostic inside a macro expansion, or for a crate outside the scanned paths, is left out.
    • A finding from a test target is handled like a test file in any other language: reported only with --include-tests, at 85%.
    • In a workspace, cargo writes paths relative to the workspace root, and they are resolved as such. A relative manifest_path in a hand-edited or copied file is resolved from where the file lives.
    • The compiler never reports a pub item of a library, and it has no notion of an unused file, so jscpd reports neither for Rust.
    • The dashboard's dead-code heading no longer names three languages, and a project with no language the run could read says so in its health score.
    • See fixtures/dead-code-demo. (#1089)

Bug Fixes

  • Text around an embedded code block was counted as code. A ts block in a markdown file, a <script> in a single-file component: jscpd scans these under the embedded language's own format, and the block keeps the line numbers of the file it lives in. The statistics read those numbers as if the block ran the whole way, which put the markdown prose and the component templates into the embedded language's line counts — both the total and the duplicated lines. On a repository with about 3600 markdown files the typescript row said 51.30% of lines were duplicated where the same code, scanned with -f typescript, said 3.37%. Neither number was a typo and both came from the same run.

    An embedded source now counts the lines its blocks occupy, and a clone counts the block lines it covers rather than everything its fragment reaches across. The two percentage columns agree again, which is the quickest way to check a run: they measure the same duplication, so when the line column sits far below the token column it is counting text that holds no code. Ordinary files are counted exactly as before. See fixtures/embedded-stats-demo. (#1091, closes #1090)

  • Every clone was one line short. Duplicated lines came from end - start, so a clone covering lines 10 through 19 counted nine — while the console printed 10 lines for it, from its own arithmetic. Line counts are inclusive now, and the header and the table come from one place. Expect duplicated-line totals to rise by about one line per clone, and percentages with them. (#1091)

Other

Published Packages

  • basta@0.3.0 on crates.io
  • cpd-core@0.1.18 on crates.io
  • cpd-finder@0.1.18 on crates.io
  • cpd-reporter@0.1.19 on crates.io
  • cpd-tokenizer@0.1.17 on crates.io
  • jscpd@5.3.2 on crates.io
  • cpd@5.3.2 on npm
  • jscpd@5.3.2 on npm
  • jscpd-darwin-arm64@5.3.2 on npm
  • jscpd-darwin-x64@5.3.2 on npm
  • jscpd-linux-x64-gnu@5.3.2 on npm
  • jscpd-linux-arm64-gnu@5.3.2 on npm
  • jscpd-linux-x64-musl@5.3.2 on npm
  • jscpd-linux-arm64-musl@5.3.2 on npm
  • jscpd-windows-x64-msvc@5.3.2 on npm
  • jscpd-windows-arm64-msvc@5.3.2 on npm
  • jscpd==5.3.2 on PyPI

Verify

... (truncated)

Commits

Updates knip from 6.36.0 to 6.38.0

Release notes

Sourced from knip's releases.

Release 6.38.0

  • Include co-authors in docs contributor list (0c334100df59d89a512ad598ec50e7f62f6da0c3)
  • Filter bots and agents from docs contributors (617f70d8179c6b8668ca41fe5df77ced5e2b37c0)
  • Update Eve plugin conventions (#2049) (260dbb91a85f3a3bc2727e8f255d73df3737552c) - thanks @​matchai!
  • Add args example to that doc page (50b271b98fc930a05a3b045a2f691486f9f06528)
  • Add Turborepo plugin (#2055) (e49d3db05f1d69ce7db3efcb8467a4af63c27379) - thanks @​changbaebang!
  • Support import-x/* settings in ESLint plugin (#2050) (1a34cf82a3d6a1202717ef910bedba55838e9dd9) - thanks @​bytedoe!
  • Resolve file option in Mocha configuration files (#2051) (9b5c5f60468c8a92a3e74adca5c0931f008677af) - thanks @​giaBaoJS!
  • Support oxlint extends (#2054) (a149a98219bb14b15f446fc5f8c4f815e28b2183) - thanks @​matthewnitschke-wk!
  • Fix import.meta handling in built-in compilers (#2059) (8b0c85076bf3dce15ef5f3c0c4e58bfefdf59ded) - thanks @​vdavid!
  • Fix tag hints for enum and namespace members (#2061) (8a8805e48945863248429d18b7f6c4e4b7dc9ebd) - thanks @​devYRPauli!
  • Flag unused member tags in tagged enums and namespaces (584e53ff3e0846fbfe04fa5b5bfefe2420576a34)
  • feat: resolve MDX content mapper remarkPlugins (#2060) (34dbccf25359f9e9fefe9d0be6ef2ec0252223cc) - thanks @​gioboa!
  • Refactor and separate concerns w/ new typescript-content-mapper plugin (11e94509bd0f350d747facf4003fc5b248d1b02d)
  • Resolve mdx content mapper providerImportSource (7b5825117f97f2f87b7141509a254f88d0957cf7)
  • Fix config → entry in plop plugin (25a380c9e1165b76583d69b48b5fa7cdf5db0ae2)

Release 6.37.0

  • fix(graphql-codegen): mark near-operation-file outputs as entries, not the documents directory (#2048) (06a68fcf99a90e559daeb0b8fb2d24e173124774) - thanks @​RobHannay!
  • fix: enable JSX in the config loader (#1959) (5b21dc9192f773613d1c5db8edf35f0a68820268) - thanks @​addielaruee!
  • Match binaries only to their actual dependency providers (c5bdb69ccbcb7e1056233f346d0ada3495d1013d)
  • Preserve executable references across package manager commands (54af171638db22f5d903faae05c37c2ea6adc869)
  • Correct binary provider metadata in Relay fixtures (e67dfcb96d055c27be9c8601e077656855bb632b)
  • Separate shell binary expectations from reporting exemptions (resolve #2022) (c1d7d75a3529d9faff7f4c0df11dd0ca1bdfb149)
  • Respect npx no-install flags before the executable (4237010c9a834eb8b04f4a528c76d10a5c38ee98)
  • Update dependencies (038ea179f7d6bf7ca43bc5daf553a68b13a9067c)
  • Remove npm auth check now that's in release-it (4aaf77c58004ac64063a1982b98e53107c2ebe93)
  • Fix --format name resolution in the ESLint plugin (#2046) (1269e98bb700384811fadc124d69ea720832037e) - thanks @​bytedoe!
Commits
  • c0e42f8 Release knip@6.38.0
  • 25a380c Fix config → entry in plop plugin
  • 7b58251 Resolve mdx content mapper providerImportSource
  • 11e9450 Refactor and separate concerns w/ new typescript-content-mapper plugin
  • 34dbccf feat: resolve MDX content mapper remarkPlugins (#2060)
  • 584e53f Flag unused member tags in tagged enums and namespaces
  • 8a8805e Fix tag hints for enum and namespace members (#2061)
  • 8b0c850 Fix import.meta handling in built-in compilers (#2059)
  • a149a98 Support oxlint extends (#2054)
  • 9b5c5f6 Resolve file option in Mocha configuration files (#2051)
  • Additional commits viewable in compare view

Updates vite-plus from 0.3.2 to 1.0.0

Release notes

Sourced from vite-plus's releases.

vite-plus v1.0.0: Vite+ 1.0 is stable

Vite+ 1.0 is stable (announcement). This release promotes v1.0.0-rc.1 to stable with no code changes.

Notable changes since v0.3.3

v1.0.0 includes everything from the two release candidates below. See each release's notes for the full list of changes.

  • v1.0.0-rc.0: vp test moves to vitest@5.0.1, and the CLI now requires Node.js ^22.18.0 || ^24.11.0 || >=26.0.0. vp staged has new Node.js and Git minimums. Standalone installs and vp upgrade verify release provenance.
  • v1.0.0-rc.1: task cache settings in run.tasks move under cache. vp lint and vp fmt run from a package directory now use the same config as your editor.

Projects on v1.0.0-rc.1 need no changes. Projects on v1.0.0-rc.0 whose tasks set env, untrackedEnv, input, or output should run vp migrate to move those settings under cache. For a Vite+ 0.3 project, follow Upgrade from Vite+ 0.3 to 1.0 and run vp migrate before you update the project's dependencies.

Bundled Versions

Tool Version Source
vite 8.3.1 39ddf7c
rolldown 1.2.11 8df4219
tsdown 0.23.0 npm
vitest 5.0.1 npm
oxlint 1.85.0 npm
oxlint-tsgolint 7.0.2003 npm
oxfmt 0.70.0 npm

Upgrade

vp upgrade

Full Changelog: voidzero-dev/vite-plus@v1.0.0-rc.1...v1.0.0

Published Packages

  • @voidzero-dev/vite-plus-core@1.0.0
  • vite-plus@1.0.0

Installation

macOS/Linux:

curl -fsSL https://vite.plus | bash

Windows:

irm https://vite.plus/ps1 | iex

... (truncated)

Commits
  • fc287d7 release: v1.0.0: Vite+ 1.0 is stable (#2839)
  • a9d81a4 release: v1.0.0-rc.1: task cache settings move under cache (#2818)
  • 9f6e158 fix(cli): use native config discovery for lint and fmt (#2807)
  • 4897b10 fix(cli): expose Vitest 5 options in test help (#2809)
  • 688fe4a feat(migrate): move task cache settings under cache (#2814)
  • 70185af chore: bump vite-task to 7d69d65 (#2813)
  • d29792f feat(deps): upgrade upstream dependencies (#2805)
  • 6abe93a fix(config): type async tool options contextually (#2803)
  • 173e734 release: v1.0.0-rc.0: Vitest 5 migration and npm provenance checks (#2780)
  • 1e16526 fix(create): inline generator dependencies without catalog support (#2720)
  • Additional commits viewable in compare view

Updates webdriverio from 9.31.9 to 9.32.0

Release notes

Sourced from webdriverio's releases.

v9.32.0 (2026-09-20)

🚀 New Feature

  • wdio-cli, wdio-runner, wdio-types, wdio-utils
  • webdriverio
  • create-wdio

🐛 Bug Fix

... (truncated)

Changelog

Sourced from webdriverio's changelog.

v9.32.0 (2026-09-20)

🚀 New Feature

  • wdio-cli, wdio-runner, wdio-types, wdio-utils
  • webdriverio
  • create-wdio

🐛 Bug Fix

  • webdriverio
    • #15632 fix(webdriverio): make addLocatorStrategy work on multi-remote browsers (@​nikolas-sapa)
    • #15637 fix(webdriverio): keep a valid top-level context on switchTo...

      Description has been truncated

Bumps the dev-dependencies group with 10 updates:

| Package | From | To |
| --- | --- | --- |
| [@commitlint/cli](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/cli) | `21.2.2` | `21.2.3` |
| [@commitlint/config-conventional](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/config-conventional) | `21.2.2` | `21.2.3` |
| [@microsoft/api-extractor](https://github.com/microsoft/rushstack/tree/HEAD/apps/api-extractor) | `7.59.1` | `7.59.2` |
| [@vitest/browser-webdriverio](https://github.com/vitest-community/vitest-webdriverio) | `4.1.11` | `5.0.0` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `4.1.11` | `5.0.2` |
| [fast-check](https://github.com/dubzzz/fast-check/tree/HEAD/packages/fast-check) | `4.10.1` | `4.10.2` |
| [jscpd](https://github.com/kucherenko/jscpd/tree/HEAD/rust/jscpd) | `5.2.1` | `5.3.2` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.36.0` | `6.38.0` |
| [vite-plus](https://github.com/voidzero-dev/vite-plus/tree/HEAD/packages/cli) | `0.3.2` | `1.0.0` |
| [webdriverio](https://github.com/webdriverio/webdriverio/tree/HEAD/packages/webdriverio) | `9.31.9` | `9.32.0` |


Updates `@commitlint/cli` from 21.2.2 to 21.2.3
- [Release notes](https://github.com/conventional-changelog/commitlint/releases)
- [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/cli/CHANGELOG.md)
- [Commits](https://github.com/conventional-changelog/commitlint/commits/v21.2.3/@commitlint/cli)

Updates `@commitlint/config-conventional` from 21.2.2 to 21.2.3
- [Release notes](https://github.com/conventional-changelog/commitlint/releases)
- [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/config-conventional/CHANGELOG.md)
- [Commits](https://github.com/conventional-changelog/commitlint/commits/v21.2.3/@commitlint/config-conventional)

Updates `@microsoft/api-extractor` from 7.59.1 to 7.59.2
- [Changelog](https://github.com/microsoft/rushstack/blob/main/apps/api-extractor/CHANGELOG.md)
- [Commits](https://github.com/microsoft/rushstack/commits/HEAD/apps/api-extractor)

Updates `@vitest/browser-webdriverio` from 4.1.11 to 5.0.0
- [Release notes](https://github.com/vitest-community/vitest-webdriverio/releases)
- [Commits](https://github.com/vitest-community/vitest-webdriverio/commits/v5.0.0)

Updates `@vitest/coverage-v8` from 4.1.11 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/coverage-v8)

Updates `fast-check` from 4.10.1 to 4.10.2
- [Release notes](https://github.com/dubzzz/fast-check/releases)
- [Changelog](https://github.com/dubzzz/fast-check/blob/main/packages/fast-check/CHANGELOG.md)
- [Commits](https://github.com/dubzzz/fast-check/commits/v4.10.2/packages/fast-check)

Updates `jscpd` from 5.2.1 to 5.3.2
- [Release notes](https://github.com/kucherenko/jscpd/releases)
- [Commits](https://github.com/kucherenko/jscpd/commits/v5.3.2/rust/jscpd)

Updates `knip` from 6.36.0 to 6.38.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.38.0/packages/knip)

Updates `vite-plus` from 0.3.2 to 1.0.0
- [Release notes](https://github.com/voidzero-dev/vite-plus/releases)
- [Commits](https://github.com/voidzero-dev/vite-plus/commits/v1.0.0/packages/cli)

Updates `webdriverio` from 9.31.9 to 9.32.0
- [Release notes](https://github.com/webdriverio/webdriverio/releases)
- [Changelog](https://github.com/webdriverio/webdriverio/blob/main/CHANGELOG.md)
- [Commits](https://github.com/webdriverio/webdriverio/commits/v9.32.0/packages/webdriverio)

---
updated-dependencies:
- dependency-name: "@commitlint/cli"
  dependency-version: 21.2.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: "@commitlint/config-conventional"
  dependency-version: 21.2.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: "@microsoft/api-extractor"
  dependency-version: 7.59.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: "@vitest/browser-webdriverio"
  dependency-version: 5.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
- dependency-name: fast-check
  dependency-version: 4.10.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: jscpd
  dependency-version: 5.3.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: knip
  dependency-version: 6.38.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: vite-plus
  dependency-version: 1.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
- dependency-name: webdriverio
  dependency-version: 9.32.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
@dependabot
dependabot Bot requested a review from hyanmandian as a code owner October 5, 2026 12:05
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
@vercel

vercel Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
brazilian-utils Ready Ready Preview Oct 5, 2026 12:05pm UTC

@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 7bca6174-e029-44e3-b44c-30a12acd5300

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dependabot @github

dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/dev-dependencies-6fec8ed1f2 branch October 6, 2026 22:20

This branch was successfully deployed

1 active deployment
Preview — e214dfd8 Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant