Skip to content

build(deps): Bump commander from 12.1.0 to 14.0.3 - #5

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/commander-14.0.3
Feb 23, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/commander-14.0.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Feb 23, 2026 •

Copy link
Copy Markdown
Contributor

Bumps commander from 12.1.0 to 14.0.3.

Release notes

Sourced from commander's releases.

v14.0.3

Added

  • Release Policy document (#2462)

Changes

  • old major versions now supported for 12 months instead of just previous major version, to give predictable end-of-life date (#2462)
  • clarify typing for deprecated callback parameter to .outputHelp() (#2427)
  • simple readability improvements to README (#2465)

v14.0.2

Changed

  • improve negative number auto-detection test (#2428)
  • update (dev) dependencies

v14.0.1

Fixed

  • broken markdown link in README (#2369)

Changed

  • improve code readability by using optional chaining (#2394)
  • use more idiomatic code with object spread instead of Object.assign() (#2395)
  • improve code readability using string.endsWith() instead of string.slice() (#2396)
  • refactor .parseOptions() to process args array in-place (#2409)
  • change private variadic support routines from ._concatValue() to ._collectValue() (change code from array.concat() to array.push()) (#2410)
  • update (dev) dependencies

v14.0.0

Added

  • support for groups of options and commands in the help using low-level .helpGroup() on Option and Command, and higher -level .optionsGroup() and .commandsGroup() which can be used in chaining way to specify group title for following option s/commands (#2328)
  • support for unescaped negative numbers as option-arguments and command-arguments (#2339)
  • TypeScript: add parseArg property to Argument class (#2359)

Fixed

  • remove bogus leading space in help when option has default value but not a description (#2348)
  • .configureOutput() now makes copy of settings instead of modifying in-place, fixing side-effects (#2350)

Changed

  • Breaking: Commander 14 requires Node.js v20 or higher
  • internal refactor of Help class adding .formatItemList() and .groupItems() methods (#2328)

... (truncated)

Changelog

Sourced from commander's changelog.

[14.0.3] (2026-01-31)

Added

  • Release Policy document (#2462)

Changes

  • old major versions now supported for 12 months instead of just previous major version, to give predictable end-of-life date (#2462)
  • clarify typing for deprecated callback parameter to .outputHelp() (#2427)
  • simple readability improvements to README (#2465)

[14.0.2] (2025-10-25)

Changed

  • improve negative number auto-detection test (#2428)
  • update (dev) dependencies

[14.0.1] (2025-09-12)

Fixed

  • broken markdown link in README (#2369)

Changed

  • improve code readability by using optional chaining (#2394)
  • use more idiomatic code with object spread instead of Object.assign() (#2395)
  • improve code readability using string.endsWith() instead of string.slice() (#2396)
  • refactor .parseOptions() to process args array in-place (#2409)
  • change private variadic support routines from ._concatValue() to ._collectValue() (change code from array.concat() to array.push()) (#2410)
  • update (dev) dependencies

[14.0.0] (2025-05-18)

Added

  • support for groups of options and commands in the help using low-level .helpGroup() on Option and Command, and higher-level .optionsGroup() and .commandsGroup() which can be used in chaining way to specify group title for following options/commands (#2328)
  • support for unescaped negative numbers as option-arguments and command-arguments (#2339)
  • TypeScript: add parseArg property to Argument class (#2359)

Fixed

  • remove bogus leading space in help when option has default value but not a description (#2348)
  • .configureOutput() now makes copy of settings instead of modifying in-place, fixing side-effects (#2350)

Changed

  • Breaking: Commander 14 requires Node.js v20 or higher

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Feb 23, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/commander-14.0.3 branch 2 times, most recently from d509f51 to 9f7be76 Compare February 23, 2026 15:05
@rishitank

Copy link
Copy Markdown
Owner

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/commander-14.0.3 branch from 9f7be76 to 41bcea8 Compare February 23, 2026 15:26
@dependabot
dependabot Bot requested a review from rishitank as a code owner February 23, 2026 15:26
@github-actions
github-actions Bot enabled auto-merge (squash) February 23, 2026 15:27
@rishitank

Copy link
Copy Markdown
Owner

@dependabot rebase

1 similar comment
@rishitank

Copy link
Copy Markdown
Owner

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/commander-14.0.3 branch 2 times, most recently from 34c1c80 to 19b20cc Compare February 23, 2026 15:37
@rishitank

Copy link
Copy Markdown
Owner

@dependabot rebase

Bumps [commander](https://github.com/tj/commander.js) from 12.1.0 to 14.0.3.
- [Release notes](https://github.com/tj/commander.js/releases)
- [Changelog](https://github.com/tj/commander.js/blob/master/CHANGELOG.md)
- [Commits](tj/commander.js@v12.1.0...v14.0.3)

---
updated-dependencies:
- dependency-name: commander
  dependency-version: 14.0.3
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/commander-14.0.3 branch from 19b20cc to c3620c3 Compare February 23, 2026 15:41
@github-actions
github-actions Bot merged commit e912786 into main Feb 23, 2026
9 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/commander-14.0.3 branch February 23, 2026 15:43
@github-actions github-actions Bot mentioned this pull request Feb 23, 2026
rishitank added a commit that referenced this pull request Sep 25, 2026
FileIndexer:
- canonicalise the root with realpath and require every file's realpath
  to stay under it (rejects ../ traversal, absolute paths elsewhere,
  sibling-prefix dirs, and symlinks - file or directory - that escape)
- open-then-fstat instead of stat-then-open (O_NOFOLLOW | O_NONBLOCK),
  and cap the bytes actually read at 1 MB, so the checked file is the
  file read
- readFile() now takes the root it must stay inside

LocalContextAdapter remembers the roots passed to indexDirectory() and
indexFiles() only reads files under one of them, so only content the
user chose to index can reach search results and inference prompts.

GitTracker writes .holocron-last-sha with mode 0600.

Also drops an unused import in the benchmark runner.

Resolves CodeQL js/path-injection (#1-#5), js/file-system-race (#18,
#19), js/insecure-temporary-file (#9, with the test change in the next
commit) and js/unused-local-variable (#24).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0171XyyqTUH64gAi1AcerwjN
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant