Conversation
Bumps the patch group with 1 update: [@cldmv/fix-headers](https://github.com/CLDMV/fix-headers). Updates `@cldmv/fix-headers` from 1.3.9 to 1.3.11 - [Release notes](https://github.com/CLDMV/fix-headers/releases) - [Commits](CLDMV/fix-headers@v1.3.9...v1.3.11) --- updated-dependencies: - dependency-name: "@cldmv/fix-headers" dependency-version: 1.3.11 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: patch ... Signed-off-by: dependabot[bot] <support@github.com>
…#28) Bumps the patch group with 1 update: [@cldmv/fix-headers](https://github.com/CLDMV/fix-headers). Updates `@cldmv/fix-headers` from 1.3.9 to 1.3.11 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/CLDMV/fix-headers/releases">@cldmv/fix-headers's releases</a>.</em></p> <blockquote> <h2>v1.3.11</h2> <p>release: v1.3.11 - pass BOT_NAME/BOT_EMAIL to v4 release/feature-PR… (<a href="https://redirect.github.com/CLDMV/fix-headers/issues/37">#37</a>)</p> <!-- raw HTML omitted --> <ul> <li><a href="https://github.com/Shinrai"><code>@Shinrai</code></a></li> </ul> <!-- raw HTML omitted --> <h2>v1.3.10</h2> <p>release: v1.3.10 - give fallback-path tests a workspace with no project… (<a href="https://redirect.github.com/CLDMV/fix-headers/issues/30">#30</a>)</p> <!-- raw HTML omitted --> <ul> <li><a href="https://github.com/Shinrai"><code>@Shinrai</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/CLDMV/fix-headers/commit/2162ab875bee60029879c05557e5f05bc93ae9d5"><code>2162ab8</code></a> release: v1.3.11 - pass BOT_NAME/BOT_EMAIL to v4 release/feature-PR… (<a href="https://redirect.github.com/CLDMV/fix-headers/issues/37">#37</a>)</li> <li><a href="https://github.com/CLDMV/fix-headers/commit/0c602e09651fd609191659fd39279bea995a6e59"><code>0c602e0</code></a> release: v1.3.10 - give fallback-path tests a workspace with no project… (<a href="https://redirect.github.com/CLDMV/fix-headers/issues/30">#30</a>)</li> <li>See full diff in <a href="https://github.com/CLDMV/fix-headers/compare/v1.3.9...v1.3.11">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details>
Contributor
Author
🔒 Dependency Review
|
vitest@5.0.0's published engines.node is "^22.12.0 || ^24.0.0 || >=26.0.0" (checked via npm view) — it won't run below Node 22.12. 26 is the next even-major LTS-track ceiling. package.json's engines.node stays at >=16.12.0 (deliberately kept low for downstream consumers).
vitest and @vitest/coverage-v8 peer each other exactly, so opening separate PRs for each breaks npm ci with an ERESOLVE the moment one bumps without the other. Group them so future bumps land together in one PR.
@eslint/js peers eslint with a major-locked range ("^10.0.0"), and
@cldmv/prettier-plugin-jsonv peers prettier the same way ("^3.0.0")
-- both verified via npm view, not memory. Neither is broken today,
but a future major bump would hit the same npm ci ERESOLVE class the
vitest + @vitest/coverage-v8 split just did. Group them proactively.
Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.10 to 5.0.0. - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.0/packages/vitest) --- updated-dependencies: - dependency-name: vitest dependency-version: 5.0.0 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
@vitest/coverage-v8 peers vitest with a major-locked range, so Dependabot's separate vitest-only bump (this branch) broke npm ci with an ERESOLVE until coverage-v8 moved too. `@dependabot recreate` does not re-group an already-opened single-package PR against a newly added dependabot.yml group -- it just refreshes that PR's own single-package update, so this had to be applied by hand.
Shinrai
approved these changes
Sep 13, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🚀 What's Changed
💥 Breaking Changes
No breaking changes
✨ Features
No new features
🐛 Bug Fixes
No bug fixes
📦 Dependencies
deps: bump vitest from 4.1.10 to 5.0.0 #29
deps: bump @cldmv/fix-headers from 1.3.9 to 1.3.11 in the patch group #28
🔧 Other Changes
👥 Contributors
Avg: 87.1% ·
51a8279· Node lts/*