Skip to content

release: v2.1.3 - bump the patch group across 1 directory with 2 updates - #112

Merged
cldmv-bot[bot] merged 11 commits into
masterfrom
next
Oct 3, 2026
Merged

cldmv-bot[bot] merged 11 commits into
masterfrom
next

Conversation

@cldmv-bot

@cldmv-bot cldmv-bot Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

@cldmv/fix-headers v2.1.3 Changelog

Release Date: October 2026
Release Type: Patch
Branch: release/2.1.3


Overview

Version 2.1.3 is a CI and tooling release with no runtime change. The ✅ Required PR Check mirror job in ci.yml no longer satisfies the branch ruleset while it is skipped, which closes a window in which an in-repo pull request could be merged before its tests had finished. Four development dependencies move to their current releases through the lockfile; ignore, the only runtime dependency, is unchanged.

No source file changes, so dist/, bin/ and the fixHeaders API are the same as in v2.1.2. The two patch releases before this one, v2.1.1 (a header-only file ends with the header instead of trailing margin lines; esbuild 0.28.2) and v2.1.2 (the repository adopts the shared CLDMV fix-headers config and stamps uniform file headers), shipped without a changelog file; their notes are on their GitHub Releases.


🔧 CI & tooling

The skipped PR-run mirror no longer satisfies ✅ Required PR Check (#111)

An in-repo feature PR gets two ci.yml runs on the same commit: a push run on the head branch and a pull_request run. The pull_request run skips the required-check job, because the push run owns the status on that SHA, but a skipped job still posts a check run under its name, and GitHub treats a skipped required check as satisfied. The push run's real mirror is only created once ci finishes, so for the whole test window the only ✅ Required PR Check on the head SHA was the skipped one: the ruleset read green, and a PR with auto-merge enabled could merge while its tests were still running, or over a red result.

The job's name: is now an expression. On every path that actually runs (push events, fork PRs, and the next and hotfixes release PRs) it evaluates to ✅ Required PR Check; on the skipped path it does not carry the required name, so the check stays pending until the push run reports. The condition in the name is written out to match the job's if: exactly. Synced from the CLDMV/.github template change in CLDMV/.github#346.

📚 Documentation

  • NEW: docs/changelog/v2/v2.1.3.md — this changelog.
  • README What's New: v2.1.3 is the new Latest, and the v2.1.1 and v2.1.2 releases, which shipped without a README entry, are listed under Recent Releases.

🔧 Dependencies

Development dependencies only; each PR moves the resolved versions in package-lock.json and leaves the package.json ranges unchanged.

  • @cldmv/eslint-plugin-jsonv 1.0.10 → 1.0.13 and @cldmv/jsonv 1.0.9 → 1.1.1 (#109).
  • @cldmv/prettier-plugin-jsonv 1.0.6 → 1.1.0 and @cldmv/vitest-runner 1.4.2 → 1.5.1 (#114). The prettier plugin's 1.1.0 fixes lossy .jsonv formatting (identifier keys printed as [object Object], comments dropped); this repository has no .jsonv files, so the bump only keeps the lint and format toolchain current.
  • ignore, the only runtime dependency, is unchanged.

Upgrade notes

  • No breaking changes: drop-in for v2.1.2. No runtime code changed and no option was added or removed.
👥 Contributors

coverage

Metric Coverage
Statements 100.0%
Branches 100.0%
Functions 100.0%
Lines 100.0%

Avg: 100.0% · 7d71608 · Node lts/*

Co-authored-by: Shinrai Shinrai@users.noreply.github.com

Shinrai and others added 3 commits October 2, 2026 13:56
On an in-repo feature PR, the `pull_request` run skips the
`required-check` job because the push run owns the status. A skipped job
still posts a check run under its name, and GitHub treats a skipped
required check as satisfied. The push run's mirror is only created once
`ci` finishes, so for the whole test window the only `✅ Required PR
Check` on the head SHA was the skipped one, and the PR could merge while
tests were still running.

Give the job a conditional name so the skipped path posts under a
different name and the required check stays pending until the push run
reports. Synced from CLDMV/.github#346.
…111)

## 🚀 What's Changed

### 💥 Breaking Changes
_No breaking changes_

### ✨ Features
_No new features_

### 🐛 Bug Fixes
_No bug fixes_

### 📦 Dependencies
_No dependency updates_

### 🔧 Other Changes
- ci: stop the skipped PR-run mirror from satisfying Required PR Check
(4b62b78)



<details>
<summary>👥 Contributors</summary>

- @Shinrai

</details>
@cldmv-bot cldmv-bot Bot added ! release → master v4 flow: persistent next → master release PR (carries the next feature release) release Marks a pull request as a pending release — merge to publish a new version semver: patch This release contains only backwards-compatible bug fixes type: ci Changes to CI workflows, actions, or build pipelines type: config Changes to repository or project configuration files type: dependencies Relates to dependency updates, version bumps, or package management labels Oct 2, 2026
@cldmv-bot

cldmv-bot Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor Author

🔒 Dependency Review

  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses
  • ✅ 0 denied package(s)
  • ✅ 0 package(s) with OpenSSF Scorecard score < 3

Full job summary

@cldmv-bot

cldmv-bot Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

📦 Bundle size unchanged

File Raw Δ Raw Gzipped Δ Gzipped
bin/fix-headers.mjs 49.3 kB — 16.5 kB —
dist/index.cjs 1.1 kB — 692 B —
dist/index.mjs 40.5 kB — 13.7 kB —
Total 91.0 kB ±0 B 30.8 kB ±0 B

📊 Generated by bundle-size. Brotli sizes also measured but omitted from the table for brevity.

dependabot Bot and others added 2 commits October 2, 2026 21:39
Bumps the patch group with 2 updates in the / directory: [@cldmv/eslint-plugin-jsonv](https://github.com/CLDMV/jsonv-eslint-plugin-jsonv) and [@cldmv/jsonv](https://github.com/CLDMV/jsonv).


Updates `@cldmv/eslint-plugin-jsonv` from 1.0.10 to 1.0.13
- [Release notes](https://github.com/CLDMV/jsonv-eslint-plugin-jsonv/releases)
- [Commits](CLDMV/jsonv-eslint-plugin-jsonv@v1.0.10...v1.0.13)

Updates `@cldmv/jsonv` from 1.0.9 to 1.1.1
- [Release notes](https://github.com/CLDMV/jsonv/releases)
- [Changelog](https://github.com/CLDMV/jsonv/blob/master/CHANGELOG.md)
- [Commits](CLDMV/jsonv@v1.0.9...v1.1.1)

---
updated-dependencies:
- dependency-name: "@cldmv/eslint-plugin-jsonv"
  dependency-version: 1.0.13
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch
- dependency-name: "@cldmv/jsonv"
  dependency-version: 1.1.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps the patch group with 2 updates in the / directory:
[@cldmv/eslint-plugin-jsonv](https://github.com/CLDMV/jsonv-eslint-plugin-jsonv)
and [@cldmv/jsonv](https://github.com/CLDMV/jsonv).

Updates `@cldmv/eslint-plugin-jsonv` from 1.0.10 to 1.0.13
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/CLDMV/jsonv-eslint-plugin-jsonv/releases">@​cldmv/eslint-plugin-jsonv's
releases</a>.</em></p>
<blockquote>
<h2>v1.0.13</h2>
<p>release: v1.0.13 - publish real types for the plugin, language and
AST</p>
<h1><code>@​cldmv/eslint-plugin-jsonv</code> v1.0.13 Changelog</h1>
<p><strong>Release Date</strong>: September 2026
<strong>Release Type</strong>: Patch
<strong>Branch</strong>: <code>release/1.0.13</code></p>
<hr />
<h2>Overview</h2>
<p>Version 1.0.13 makes the plugin's published types real.
<code>dist/index.d.mts</code> used to declare the default export as a
bare <code>Object</code>; it now types the plugin, the
<code>jsonv/jsonv</code> language, <code>JsonvSourceCode</code>, and
every AST node against <code>@eslint/core</code>'s generics, and the
JSDoc that generates those declarations is now type-checked in CI. The
release also closes a gap the new types surfaced:
<code>engines.node</code> and a missing <code>eslint</code> peer range
now match what the plugin's runtime dependencies actually require.
Alongside that, the plugin accepts three more <code>@cldmv/jsonv</code>
language options, and the repository adopts the CLDMV lint/format
tooling.</p>
<p>No configuration changes are required to pick this up — existing
<code>eslint.config.mjs</code> files, rules, and
<code>languageOptions</code> keep working unchanged.</p>
<hr />
<h2>🐛 Bug Fixes</h2>
<h3>Published types describe a real ESLint plugin (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/30">#30</a>,
fixes <a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/28">#28</a>)</h3>
<p><code>dist/index.d.mts</code> declared <code>const plugin:
Object</code>, so a TypeScript (or <code>// @ts-check</code>) config got
no type for <code>plugin.configs.recommended</code>,
<code>plugin.languages.jsonv</code>, or <code>languageOptions</code>,
and nothing for a rule author to use for the AST node types the language
exposes. The JSDoc in <code>index.mjs</code> is now typed against
<code>@eslint/core</code>'s <code>Language</code>,
<code>TextSourceCode</code>, <code>OkParseResult</code>, and
<code>Plugin</code> generics, the way <code>@eslint/json</code> types
its JSON language, and <code>tsconfig.types.json</code> now type-checks
it (<code>checkJs: true</code>) instead of only emitting from it. The
package exports typedefs for every AST node (<code>JsonvProgram</code>,
<code>JsonvObjectExpression</code>, <code>JsonvProperty</code>,
<code>JsonvLiteral</code>, <code>JsonvIdentifier</code>,
<code>JsonvMemberExpression</code>, <code>JsonvTemplateLiteral</code>,
<code>JsonvTemplateElement</code>), for
<code>JsonvLanguageOptions</code>, and for a rule's visitor
(<code>JsonvRuleDefinition</code>, <code>JsonvRuleVisitor</code>), plus
the <code>JsonvSourceCode</code> class itself, and
<code>JsonvSourceCode</code> is now a named export alongside the default
plugin. A new <code>test:types</code> script compiles a type-level
consumer test against the built declarations the way an
<code>eslint.config.mts</code> would, and <code>build:ci</code> runs
it.</p>
<h3>The declared Node floor and ESLint range match what the plugin needs
(<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/37">#37</a>,
fixes <a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/32">#32</a>)</h3>
<p><code>engines.node</code> still said <code>&gt;=18.0.0</code>, but
the runtime dependencies added for real types —
<code>@eslint/core</code> and <code>@eslint/plugin-kit</code> — both
require <code>^20.19.0 || ^22.13.0 || &gt;=24</code>, and so does ESLint
10 itself. Installing on Node 18 could fail or warn while
<code>engines</code> claimed support. <code>engines.node</code> now
states that real floor, and a new <code>eslint</code> peer dependency
(<code>^9.13.0 || ^10.0.0</code>) tells consumers which ESLint versions
the plugin's <code>languages</code> API needs — <code>^9.13.0</code> is
the first release with <code>defaultLanguageOptions</code> support for
plugin languages.</p>
<h3><code>mode</code>, <code>strictOctal</code>, and
<code>allowInternalReferences</code> language options (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/39">#39</a>,
fixes <a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/34">#34</a>)</h3>
<p>The README documented a <code>mode</code> option, and the plugin
rejected it (<code>Unknown language option &quot;mode&quot;</code>)
because it was never actually forwarded to the parser. <code>mode</code>
(<code>&quot;jsonv&quot;</code>, <code>&quot;json5&quot;</code>, or
<code>&quot;json&quot;</code>, default <code>&quot;jsonv&quot;</code>),
<code>strictOctal</code> (boolean, default <code>false</code>), and
<code>allowInternalReferences</code> (boolean, default
<code>true</code>) are now accepted, validated, and passed through to
both <code>parseWithOptions()</code> and <code>parseToAst()</code>,
matching <code>@cldmv/jsonv</code>'s own <code>ParseOptions</code>.
<code>reviver</code>, <code>preserveComments</code>, and
<code>tolerant</code> stay unsupported, and
<code>validateLanguageOptions</code> now names the reason when one of
those three is set instead of reporting it as merely unknown. The
README's <strong>Configuration Options</strong> table documents all five
options with their defaults, and a new test extracts the README's own
<code>languageOptions</code> examples and runs them through
<code>validateLanguageOptions</code> and a live <code>Linter</code>, so
the docs and the code can't drift apart again.</p>
<h2>🔧 CI &amp; tooling</h2>
<ul>
<li>The CLDMV eslint + prettier config, <code>lint</code> /
<code>lint:fix</code> / <code>format</code> / <code>format:check</code>
scripts, and the <code>.githooks</code> pre-commit hook are added, and
the existing sources and README are reformatted repo-wide (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/38">#38</a>,
fixes <a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/33">#33</a>).</li>
<li><code>release-merge</code> is re-armed on every check-producing
workflow, instead of only the ones that existed when it was first wired
(<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/40">#40</a>).</li>
<li>The v4 workflows are synced with the <code>CLDMV/.github</code>
v4.29.2 templates (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/42">#42</a>).</li>
<li>The bundle-size workflow is added, and the
<code>release-merge</code> required-workflow list is restored to the
full set (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/43">#43</a>).</li>
</ul>
<h2>📚 Documentation</h2>
<ul>
<li><strong>NEW:</strong> <a
href="https://github.com/CLDMV/jsonv-eslint-plugin-jsonv/blob/HEAD/v1.0.13.md">docs/changelog/v1/v1.0.13.md</a>
— this changelog.</li>
<li>README <strong>Installation</strong> now states the Node and ESLint
requirements (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/37">#37</a>).</li>
<li>README <strong>Configuration Options</strong> documents
<code>mode</code>, <code>strictOctal</code>, and
<code>allowInternalReferences</code> alongside <code>year</code> and
<code>strictBigInt</code> (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/39">#39</a>).</li>
</ul>
<h2>🔧 Dependencies</h2>
<ul>
<li><strong>NEW</strong> runtime dependency: <code>@eslint/core</code>
<code>^1.2.1</code>, which provides the <code>Language</code>,
<code>TextSourceCode</code>, and <code>Plugin</code> types the published
declarations are built against (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/30">#30</a>).</li>
<li><strong>NEW</strong> dev dependency: <code>@types/node</code>
<code>^26.6.3</code>, needed by the type-checked JSDoc (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/30">#30</a>).</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/CLDMV/jsonv-eslint-plugin-jsonv/commit/2ce4e13d4b9ffeb4e0d86388f0b00604bed56672"><code>2ce4e13</code></a>
release: v1.0.13 - publish real types for the plugin, language and
AST</li>
<li><a
href="https://github.com/CLDMV/jsonv-eslint-plugin-jsonv/commit/2686e4f7bfde1ba8d73080836e15b1d5887a1767"><code>2686e4f</code></a>
release: v1.0.12 - build a real ESLint AST from the jsonv parser</li>
<li><a
href="https://github.com/CLDMV/jsonv-eslint-plugin-jsonv/commit/55c0ec8df0925543aa2bbb6f59bbc849363ade69"><code>55c0ec8</code></a>
release: v1.0.11 - validate language options and clean up the
language…</li>
<li>See full diff in <a
href="https://github.com/CLDMV/jsonv-eslint-plugin-jsonv/compare/v1.0.10...v1.0.13">compare
view</a></li>
</ul>
</details>
<details>
<summary>Install script changes</summary>
<p>This version adds <code>prepare</code> script that runs during
installation. Review the package contents before updating.</p>
</details>
<br />

Updates `@cldmv/jsonv` from 1.0.9 to 1.1.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/CLDMV/jsonv/releases">@​cldmv/jsonv's
releases</a>.</em></p>
<blockquote>
<h2>v1.1.1</h2>
<p>release: v1.1.1 - include the closing } in template middle/tail
tokens…</p>
<h1><code>@​cldmv/jsonv</code> v1.1.1 Changelog</h1>
<p><strong>Release Date</strong>: September 2026
<strong>Release Type</strong>: Patch
<strong>Branch</strong>: <code>release/1.1.1</code></p>
<hr />
<h2>Overview</h2>
<p>Version 1.1.1 is a correctness patch on top of v1.1.0's AST/token
work. Exercising the new <code>parseToAst()</code> output and the
<code>tolerant</code> option surfaced nine bugs across parse-mode
enforcement, tolerant-mode error reporting, reference resolution, and
template-literal lexing — all fixed here, each with regression tests.
Three ESLint tooling dependencies are also bumped, and CI's
release-merge gate is re-armed against every check-producing
workflow.</p>
<p>No public API changes. All v1.1.0 configuration and usage is fully
compatible.</p>
<hr />
<h2>🐛 Bug Fixes</h2>
<h3><code>mode: &quot;json&quot;</code> and <code>mode:
&quot;json5&quot;</code> now enforce their feature sets (<a
href="https://redirect.github.com/CLDMV/jsonv/issues/65">#65</a>)</h3>
<p><code>ParseOptions.mode</code> was documented to restrict
<code>&quot;json&quot;</code> to RFC 8259 JSON and
<code>&quot;json5&quot;</code> to JSON5 1.0, but only the comment check
was ever wired up — both modes silently accepted the full set of jsonv
extensions (unquoted keys, single quotes, trailing commas, hex,
<code>Infinity</code>/<code>NaN</code>, and, in
<code>&quot;json5&quot;</code>, even internal references and templates).
Both modes now reject every feature outside their spec with a positioned
<code>JsonvSyntaxError</code> naming the feature and the mode, covering
every year entry point and <code>parseToAst()</code>. Fixes <a
href="https://redirect.github.com/CLDMV/jsonv/issues/52">#52</a>.</p>
<h3>Tolerant mode reports collected syntax errors instead of a
misleading reference error (<a
href="https://redirect.github.com/CLDMV/jsonv/issues/64">#64</a>)</h3>
<p>With <code>tolerant: true</code>, <code>parseWithOptions</code>
collected syntax errors and then evaluated the partial result anyway, so
a document with real syntax errors surfaced an unrelated
<code>JsonvReferenceError</code> (&quot;Unresolved reference: b&quot;)
instead of the errors that were actually collected. When any syntax
errors are collected, <code>parseWithOptions</code> now throws a single
<code>JsonvAggregateSyntaxError</code> — its own
<code>line</code>/<code>column</code>/<code>offset</code>/<code>code</code>
are the first error's, its message summarizes the first error plus the
total count, and <code>errors</code> holds every collected error in
source order. The document is not evaluated. Fixes <a
href="https://redirect.github.com/CLDMV/jsonv/issues/59">#59</a>.</p>
<h3>Forward-reference chains of any length now resolve (<a
href="https://redirect.github.com/CLDMV/jsonv/issues/66">#66</a>)</h3>
<p>Internal references resolved in a fixed number of passes, so an
acyclic forward-reference chain longer than the pass limit (five or more
keys) failed with a spurious &quot;Unresolved reference&quot; error even
though nothing was circular. References now resolve by dependency order
— recursively resolving a reference as soon as its target has a concrete
value — instead of a fixed pass count, so chains of any depth, through
member expressions and templates, resolve correctly. True cycles and
self-references still throw, pointing at the reference that closes the
cycle. Fixes <a
href="https://redirect.github.com/CLDMV/jsonv/issues/54">#54</a>.</p>
<h3><code>parseToAst</code> collects lexer errors instead of throwing
(<a
href="https://redirect.github.com/CLDMV/jsonv/issues/62">#62</a>)</h3>
<p><code>parseToAst()</code> returns <code>{ program, comments, tokens,
errors }</code> and collected parser errors in <code>errors</code>, but
lexer errors (unterminated templates/strings, invalid escapes,
year-gated literals) were thrown instead — forcing callers to handle two
separate error paths, and hiding every other error in
<code>tolerant</code> mode behind the first lexical failure. Lexer
errors are now collected into <code>errors</code> alongside parser
errors, with the tokens lexed up to the error and a partial program
returned. Fixes <a
href="https://redirect.github.com/CLDMV/jsonv/issues/51">#51</a>.</p>
<h3>Template interpolations balance braces; object/array literals inside
<code>${}</code> are rejected clearly (<a
href="https://redirect.github.com/CLDMV/jsonv/issues/57">#57</a>)</h3>
<p>While inside a template interpolation, the lexer treated the
<em>first</em> <code>}</code> as the end of the interpolation, so an
interpolated expression containing its own braces — an object literal,
for example — broke parsing with a misleading &quot;Expected ',' or
'}'&quot; error pointing at the wrong brace. The lexer now tracks brace
depth per interpolation the way a JS lexer tracks a stack of
template/brace contexts, so only the balancing <code>}</code> ends the
interpolation; an object or array literal directly inside
<code>${}</code> is then explicitly rejected with a clear, correctly
positioned error instead of a confusing one. Fixes <a
href="https://redirect.github.com/CLDMV/jsonv/issues/50">#50</a>.</p>
<h3>Nested templates inside an interpolation now evaluate (<a
href="https://redirect.github.com/CLDMV/jsonv/issues/53">#53</a>)</h3>
<p>A template literal nested inside another template's interpolation
(<code>`a${ `b${a}c` }d`</code>) parsed with correct tokens and spans
but threw <code>JsonvReferenceError: Unresolved reference:
\&lt;template&gt;</code> on evaluation — reference resolution treated
the inner <code>TemplateLiteral</code> node as a named reference instead
of evaluating it. Nested templates now evaluate like any other
interpolated expression, at any nesting depth, including when
referencing another key or appearing inside a forward reference. Fixes
<a href="https://redirect.github.com/CLDMV/jsonv/issues/49">#49</a>.</p>
<h3>Template middle/tail tokens and quasis now include the closing
<code>}</code> (<a
href="https://redirect.github.com/CLDMV/jsonv/issues/48">#48</a>)</h3>
<p>In <code>parseToAst()</code> output, the <code>TemplateHead</code>
token and its quasi included the opening <code>${</code>, but the
<code>}</code> that closes an interpolation belonged to no token and no
quasi — so the following
<code>TemplateMiddle</code>/<code>TemplateTail</code> segment started
one character too late, leaving a one-character gap in the token stream.
Tokens now tile the template source with no gaps, matching
ESTree/Babel/Espree conventions: a tail/middle token and its quasi start
at the closing <code>}</code>. This shifts
<code>@cldmv/eslint-plugin-jsonv</code>'s <code>TemplateElement</code>
ranges by one character; that plugin should be re-checked against this
release. Fixes <a
href="https://redirect.github.com/CLDMV/jsonv/issues/47">#47</a>.</p>
<h3>CR and CRLF in template literals normalize to LF (<a
href="https://redirect.github.com/CLDMV/jsonv/issues/56">#56</a>)</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/CLDMV/jsonv/commit/cbee3ca9b5e192f4aeb126851183a6ce266cb540"><code>cbee3ca</code></a>
release: v1.1.1 - include the closing } in template middle/tail
tokens…</li>
<li><a
href="https://github.com/CLDMV/jsonv/commit/5bfa55bc9dbcd188d991db38a6565e1b3d853760"><code>5bfa55b</code></a>
release: v1.1.0 - return comments and tokens, positioned keys and…</li>
<li><a
href="https://github.com/CLDMV/jsonv/commit/4448b47bfbf3f088d0ce7ead0004f6a7c3f0103a"><code>4448b47</code></a>
release: v1.0.10 - expose line, column and offset on parse errors</li>
<li>See full diff in <a
href="https://github.com/CLDMV/jsonv/compare/v1.0.9...v1.1.1">compare
view</a></li>
</ul>
</details>
<br />
@cldmv-bot cldmv-bot Bot changed the title release: v2.1.3 - stop the skipped PR-run mirror from satisfying… release: v2.1.3 - bump the patch group across 1 directory with 2 updates Oct 2, 2026
dependabot Bot and others added 2 commits October 2, 2026 21:44
Bumps the minor group with 2 updates in the / directory: [@cldmv/prettier-plugin-jsonv](https://github.com/CLDMV/jsonv-prettier-plugin-jsonv) and [@cldmv/vitest-runner](https://github.com/CLDMV/vitest-runner).


Updates `@cldmv/prettier-plugin-jsonv` from 1.0.6 to 1.1.0
- [Release notes](https://github.com/CLDMV/jsonv-prettier-plugin-jsonv/releases)
- [Commits](CLDMV/jsonv-prettier-plugin-jsonv@v1.0.6...v1.1)

Updates `@cldmv/vitest-runner` from 1.4.2 to 1.5.1
- [Release notes](https://github.com/CLDMV/vitest-runner/releases)
- [Commits](CLDMV/vitest-runner@v1.4.2...v1.5.1)

---
updated-dependencies:
- dependency-name: "@cldmv/prettier-plugin-jsonv"
  dependency-version: 1.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor
- dependency-name: "@cldmv/vitest-runner"
  dependency-version: 1.5.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps the minor group with 2 updates in the / directory:
[@cldmv/prettier-plugin-jsonv](https://github.com/CLDMV/jsonv-prettier-plugin-jsonv)
and [@cldmv/vitest-runner](https://github.com/CLDMV/vitest-runner).

Updates `@cldmv/prettier-plugin-jsonv` from 1.0.6 to 1.1.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/CLDMV/jsonv-prettier-plugin-jsonv/releases">@​cldmv/prettier-plugin-jsonv's
releases</a>.</em></p>
<blockquote>
<h2>v1.1.0</h2>
<p>release: v1.1.0 - honour prettier's trailingComma option</p>
<h1><code>@​cldmv/prettier-plugin-jsonv</code> v1.1.0 Changelog</h1>
<p><strong>Release Date</strong>: September 2026
<strong>Release Type</strong>: Minor
<strong>Branch</strong>: <code>release/1.1.0</code></p>
<hr />
<h2>Overview</h2>
<p>A critical correctness fix plus a new formatting option. Every
published version through v1.0.6 — the printer's key- and
literal-handling code was unchanged since the v1.0.0 initial release —
could silently corrupt a <code>.jsonv</code> file on format: unquoted
(identifier) keys were printed as the literal string <code>&quot;[object
Object]&quot;</code>, collapsing every key in an object to the same
name; every comment, line and block, was dropped; and numbers were
printed from their evaluated value rather than their source text, so
numeric separators and non-decimal forms were rewritten
(<code>1_000_000</code> → <code>1000000</code>, <code>0b1111_0000</code>
→ <code>240</code>, <code>0xFF</code> → <code>255</code>). Because every
repo on the canonical CLDMV lint/format config registers this plugin for
<code>*.jsonv</code>, and the v4 post-merge lint-format job runs
<code>npm run format</code> on <code>next</code> and commits the result,
any repo with <code>.jsonv</code> files was one merge away from having
them corrupted; a scan of CLDMV's own checkouts at the time the bug was
reported found none yet corrupted.</p>
<p>The printer is rewritten around <a
href="https://github.com/CLDMV/jsonv"><code>@cldmv/jsonv</code></a>
1.1.0's <code>parseToAst()</code>, which returns a positioned AST
carrying <code>raw</code> text on every literal and identifier key, plus
the full comment and token list. Printing is now lossless: keys,
strings, numbers and BigInts are printed from their source text rather
than their evaluated value, and every comment is attached through
Prettier's own comment API so it prints exactly once, in place. Only
layout — indentation, line breaks, blank-line runs between entries, and
spacing inside template interpolations — is normalized, along with
unquoting a quoted key whose content is a plain identifier with no
escapes.</p>
<p>The published types are also fixed: the plugin now ships a real,
type-checked <code>JsonvPlugin</code> declaration instead of a loosely
typed one. On top of the fixes, the plugin now honours Prettier's
<code>trailingComma</code> option for object and array literals,
matching Prettier's default behavior for JavaScript instead of silently
ignoring the setting.</p>
<hr />
<h2>🐛 Bug Fixes</h2>
<h3>Print jsonv losslessly from the source AST (<a
href="https://redirect.github.com/CLDMV/jsonv-prettier-plugin-jsonv/pull/26">#26</a>,
fixes <a
href="https://redirect.github.com/CLDMV/jsonv-prettier-plugin-jsonv/issues/25">#25</a>)</h3>
<ul>
<li><strong>Keys</strong>: an unquoted (identifier) key is printed from
its name, not stringified from the key node — fixing the
<code>&quot;[object Object]&quot;</code> corruption. A quoted key is
printed verbatim, including its quote character, <em>unless</em> its
content is a plain identifier with no escapes, in which case it is
unquoted (<code>&quot;host&quot;</code> → <code>host</code>); every
other quoted key — one with a space, an escape, a leading digit, or
content that reads as a reserved word — is kept exactly as written. This
replaces the previous behavior of normalizing every quoted key's quote
character to match the <code>singleQuote</code> option.</li>
<li><strong>Numbers and BigInts</strong>: printed from their source
text, not their evaluated value — numeric separators, binary/octal/hex
literals and their casing, and BigInt's <code>n</code> suffix all
survive formatting unchanged.</li>
<li><strong>Comments</strong>: every line and block comment is attached
to the AST and printed, including comments in previously-unsupported
positions (between a key and its value, inside a member-expression,
inside a template interpolation). A line comment's spacing after
<code>//</code> is now taken from the source when the comment doesn't
start with a letter or digit (a divider like <code>//---</code> is kept
as written); a comment that does start with a letter or digit is still
normalized to a single space after <code>//</code>.</li>
<li><strong>Blank lines</strong>: at most one blank line between
object/array entries is now preserved when the source had one.
Previously every blank line between entries was removed, corruption bug
or not.</li>
<li><strong>Templates</strong>: interpolated template literals are now
sliced verbatim from the source text between their delimiters, rather
than rebuilt from the parser's quasi nodes.</li>
</ul>
<p>Round-trip tests were added covering every jsonv feature (identifier,
numeric and quoted keys; every number form; comments in every position;
templates; internal references; trailing commas) across the full
<code>@cldmv/jsonv</code> fixture corpus, asserting that parsing the
formatted output reproduces the original value, that comments survive,
and that formatting is idempotent (<code>format(format(x)) ===
format(x)</code>).</p>
<h3>Publish a typed plugin and type-check the JSDoc (<a
href="https://redirect.github.com/CLDMV/jsonv-prettier-plugin-jsonv/pull/32">#32</a>,
fixes <a
href="https://redirect.github.com/CLDMV/jsonv-prettier-plugin-jsonv/issues/5">#5</a>)</h3>
<p>The published declarations previously typed the plugin only as a
generic Prettier <code>Plugin</code>, with no detail about its parser,
printer or options. The JSDoc in <code>src/index.mjs</code> is now
complete and type-checked, and the generated <code>.d.mts</code> exports
a real <code>JsonvPlugin</code> type (parser, printer, language and
option definitions) alongside <code>JsonvOptions</code>,
<code>JsonvParserOptions</code>, <code>JsonvNode</code>,
<code>JsonvProgram</code>, <code>JsonvComment</code> and
<code>JsonvYear</code>. The plugin satisfies Prettier's own
<code>Plugin</code> type directly, and it is exported both as the
default export and by name. A new <code>test:types</code> check compiles
a consumer file against the published types and now runs as part of
<code>build:ci</code>.</p>
<h2>✨ Features</h2>
<h3>Honour prettier's trailingComma option (<a
href="https://redirect.github.com/CLDMV/jsonv-prettier-plugin-jsonv/pull/31">#31</a>,
fixes <a
href="https://redirect.github.com/CLDMV/jsonv-prettier-plugin-jsonv/issues/27">#27</a>)</h3>
<p>The printer previously never added a trailing comma and ignored
Prettier's <code>trailingComma</code> option entirely, even though
Prettier 3 defaults to <code>&quot;all&quot;</code> and jsonv allows
trailing commas in every year. It now follows Prettier's own JavaScript
behavior for object and array literals:</p>
<ul>
<li><code>&quot;all&quot;</code> (Prettier's default) and
<code>&quot;es5&quot;</code> add a comma after the last entry of every
object or array that breaks across lines. A non-empty object or array is
always printed one entry per line, so only an empty one (<code>{
}</code>, <code>[]</code>) stays on a single line, and it never gets a
comma.</li>
<li><code>&quot;none&quot;</code> never adds one.</li>
</ul>
<p>A trailing comma already in the source is not kept as written — the
option normalizes it, adding or removing the comma after the last entry
— and the change stays lossless: the parsed value never changes, and a
comment next to the last entry stays in place (<code>a: 1, //
note</code> keeps the comment after the comma; <code>a: 1 /* note
*/,</code> keeps it before). Round-trip and idempotency tests cover
every <code>trailingComma</code> value across the jsonv fixture corpus,
plus every comment placement around a document's last entry.</p>
<h2>🔧 CI &amp; tooling</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/CLDMV/jsonv-prettier-plugin-jsonv/commit/0a57039e1ec617c2121ad1d1767fae68d4a24102"><code>0a57039</code></a>
release: v1.1.0 - honour prettier's trailingComma option</li>
<li>See full diff in <a
href="https://github.com/CLDMV/jsonv-prettier-plugin-jsonv/compare/v1.0.6...v1.1">compare
view</a></li>
</ul>
</details>
<details>
<summary>Install script changes</summary>
<p>This version adds <code>prepare</code> script that runs during
installation. Review the package contents before updating.</p>
</details>
<br />

Updates `@cldmv/vitest-runner` from 1.4.2 to 1.5.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/CLDMV/vitest-runner/releases">@​cldmv/vitest-runner's
releases</a>.</em></p>
<blockquote>
<h2>v1.5.1</h2>
<p>release: v1.5.1 - backfill the missing v1.5.0 changelog</p>
<h1>vitest-runner v1.5.1 Changelog</h1>
<p><strong>Release Date</strong>: September 2026
<strong>Release Type</strong>: Patch
<strong>Branch</strong>: <code>release/1.5.1</code></p>
<hr />
<h2>Overview</h2>
<p>A documentation-only release: v1.5.0 shipped through the automated
release-merge gate before its changelog and README <code>What's
New</code> update had landed on <code>next</code>, so it released with
the raw auto-generated PR-title dump instead of curated notes. This
backfills v1.5.0's changelog and promotes the README. No code
changes.</p>
<hr />
<h2>📚 Documentation</h2>
<h3>Backfilled the missing v1.5.0 changelog</h3>
<p><a
href="https://github.com/CLDMV/vitest-runner/blob/HEAD/v1.5.0.md"><code>docs/changelog/v1/v1.5.0.md</code></a>
— the curated release notes for the <code>exclude</code> option (<a
href="https://redirect.github.com/CLDMV/vitest-runner/issues/57">#57</a>,
<a
href="https://redirect.github.com/CLDMV/vitest-runner/issues/58">#58</a>)
that v1.5.0 shipped without. The README <code>✨ What's New</code> block
is promoted to match.</p>
<hr />
<h2>Upgrade notes</h2>
<p>No breaking changes — drop-in for v1.5.0. No runtime code
changed.</p>
<hr />
<!-- raw HTML omitted -->
<p><img
src="https://img.shields.io/badge/coverage-99.8%25-brightgreen?style=for-the-badge&amp;logo=vitest&amp;logoColor=white"
alt="coverage" /></p>
<table>
<thead>
<tr>
<th>Metric</th>
<th>Coverage</th>
</tr>
</thead>
<tbody>
<tr>
<td>Statements</td>
<td>99.6%</td>
</tr>
<tr>
<td>Branches</td>
<td>100.0%</td>
</tr>
<tr>
<td>Functions</td>
<td>100.0%</td>
</tr>
<tr>
<td>Lines</td>
<td>99.6%</td>
</tr>
</tbody>
</table>
<p><em>Avg: <strong>99.8%</strong> · <code>d915e7d</code> · Node
lts/</em>*</p>
<!-- raw HTML omitted -->
<!-- raw HTML omitted -->
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/CLDMV/vitest-runner/commit/7aedb329940cb04cfc3556c8f76933b537fba9b1"><code>7aedb32</code></a>
release: v1.5.1 - backfill the missing v1.5.0 changelog</li>
<li><a
href="https://github.com/CLDMV/vitest-runner/commit/9e0f31c874d52b275609b9553a285e137e2e9231"><code>9e0f31c</code></a>
release: v1.5.0 - add an exclude option for test discovery</li>
<li><a
href="https://github.com/CLDMV/vitest-runner/commit/1241f7f114fe84a95e96f9b244cec2ad1f26d1ea"><code>1241f7f</code></a>
release: v1.4.4 - drop the tsup-availability guard in prepack (<a
href="https://redirect.github.com/CLDMV/vitest-runner/issues/41">#41</a>)</li>
<li><a
href="https://github.com/CLDMV/vitest-runner/commit/fade67fac72309674ff9a7767eb3df8b8c5c2056"><code>fade67f</code></a>
release: v1.4.3 - enable minification for the tsup build</li>
<li>See full diff in <a
href="https://github.com/CLDMV/vitest-runner/compare/v1.4.2...v1.5.1">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>
Shinrai
Shinrai previously approved these changes Oct 2, 2026
Shinrai and others added 3 commits October 2, 2026 16:14
The Required PR Check mirror job was skipped on the `pull_request` run of
an in-repo feature PR, with a conditional name keeping the skipped check
off `✅ Required PR Check`. GitHub never evaluates a skipped job's
`name:`, so every in-repo PR showed the raw expression as a check name.

The job now uses `if: always()` and never skips, so its name is always
evaluated. On the in-repo PR path it lands on
`⏭️ Required PR Check (reported by the push run)` and passes as a no-op;
the push run still posts `✅ Required PR Check`. Every path that posts
the required name keeps `needs: ci`, so that check still only exists
once the full test matrix for the SHA has finished.

Synced from CLDMV/.github#351 (CLDMV/.github#350).
Add docs/changelog/v2/v2.1.3.md, covering the Required PR Check mirror
rename (#111) and the lockfile moves of four development dependencies
(#109, #114), so the next -> master release PR and the GitHub Release
carry curated notes instead of the auto-generated PR-title dump.

Promote the README What's New block: v2.1.3 is the new Latest, and
Recent Releases now lists v2.1.2, v2.1.1, v2.1.0 and v2.0.0. v2.1.1 and
v2.1.2 shipped without a README entry and have no changelog file, so
they link to their GitHub Releases.
@cldmv-bot cldmv-bot Bot added the type: documentation Relates to docs, README updates, guides, or inline code comments label Oct 3, 2026
@cldmv-bot
cldmv-bot Bot merged commit 22815e6 into master Oct 3, 2026
41 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

! release → master v4 flow: persistent next → master release PR (carries the next feature release) release Marks a pull request as a pending release — merge to publish a new version semver: patch This release contains only backwards-compatible bug fixes type: ci Changes to CI workflows, actions, or build pipelines type: config Changes to repository or project configuration files type: dependencies Relates to dependency updates, version bumps, or package management type: documentation Relates to docs, README updates, guides, or inline code comments

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant