chore(deps): bump the dependencies group with 9 updates#230
Conversation
Bumps the dependencies group with 9 updates: | Package | From | To | | --- | --- | --- | | [@earendil-works/pi-ai](https://github.com/earendil-works/pi-mono/tree/HEAD/packages/ai) | `0.75.3` | `0.75.5` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `24.12.4` | `25.9.1` | | [@typescript/native-preview](https://github.com/microsoft/typescript-go) | `7.0.0-dev.20260519.1` | `7.0.0-dev.20260526.1` | | [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.51.0` | `0.52.0` | | [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.66.0` | `1.67.0` | | [es-toolkit](https://github.com/toss/es-toolkit) | `1.46.1` | `1.47.0` | | [@zag-js/checkbox](https://github.com/chakra-ui/zag) | `1.40.0` | `1.41.1` | | [@zag-js/select](https://github.com/chakra-ui/zag) | `1.40.0` | `1.41.1` | | [markdown-it](https://github.com/markdown-it/markdown-it) | `14.1.1` | `14.2.0` | Updates `@earendil-works/pi-ai` from 0.75.3 to 0.75.5 - [Release notes](https://github.com/earendil-works/pi-mono/releases) - [Changelog](https://github.com/earendil-works/pi/blob/main/packages/ai/CHANGELOG.md) - [Commits](https://github.com/earendil-works/pi-mono/commits/v0.75.5/packages/ai) Updates `@types/node` from 24.12.4 to 25.9.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `@typescript/native-preview` from 7.0.0-dev.20260519.1 to 7.0.0-dev.20260526.1 - [Changelog](https://github.com/microsoft/typescript-go/blob/main/CHANGES.md) - [Commits](https://github.com/microsoft/typescript-go/commits) Updates `oxfmt` from 0.51.0 to 0.52.0 - [Release notes](https://github.com/oxc-project/oxc/releases) - [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md) - [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.52.0/npm/oxfmt) Updates `oxlint` from 1.66.0 to 1.67.0 - [Release notes](https://github.com/oxc-project/oxc/releases) - [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md) - [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.67.0/npm/oxlint) Updates `es-toolkit` from 1.46.1 to 1.47.0 - [Release notes](https://github.com/toss/es-toolkit/releases) - [Changelog](https://github.com/toss/es-toolkit/blob/main/CHANGELOG.md) - [Commits](toss/es-toolkit@v1.46.1...v1.47.0) Updates `@zag-js/checkbox` from 1.40.0 to 1.41.1 - [Release notes](https://github.com/chakra-ui/zag/releases) - [Changelog](https://github.com/chakra-ui/zag/blob/main/CHANGELOG.md) - [Commits](https://github.com/chakra-ui/zag/compare/@zag-js/checkbox@1.40.0...@zag-js/checkbox@1.41.1) Updates `@zag-js/select` from 1.40.0 to 1.41.1 - [Release notes](https://github.com/chakra-ui/zag/releases) - [Changelog](https://github.com/chakra-ui/zag/blob/main/CHANGELOG.md) - [Commits](https://github.com/chakra-ui/zag/compare/@zag-js/select@1.40.0...@zag-js/select@1.41.1) Updates `markdown-it` from 14.1.1 to 14.2.0 - [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md) - [Commits](markdown-it/markdown-it@14.1.1...14.2.0) --- updated-dependencies: - dependency-name: "@earendil-works/pi-ai" dependency-version: 0.75.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: "@types/node" dependency-version: 25.9.1 dependency-type: direct:development update-type: version-update:semver-major dependency-group: dependencies - dependency-name: "@typescript/native-preview" dependency-version: 7.0.0-dev.20260526.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: oxfmt dependency-version: 0.52.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: oxlint dependency-version: 1.67.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: es-toolkit dependency-version: 1.47.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: "@zag-js/checkbox" dependency-version: 1.41.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: "@zag-js/select" dependency-version: 1.41.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: markdown-it dependency-version: 14.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
|
Codex review: needs changes before merge. Reviewed May 27, 2026, 3:30 AM ET / 07:30 UTC. Summary Reproducibility: yes. for the PR defect from source inspection: the PR head lockfile resolves checkbox/select to 1.41.1 while the patched Preact adapter stays 1.40.0. I did not run install or tests because this review is read-only. Review metrics: 2 noteworthy metrics.
Merge readiness Overall follows the weaker of proof and patch quality, so missing proof can cap an otherwise strong patch. Rank-up moves:
Risk before merge
Maintainer options:
Copy recommended automerge instructionNext step before merge Security Review findings
Review detailsBest possible solution: Land a regenerated dependency update that keeps Zag checkbox/select/preact and the patchedDependency entry on one compatible release, while preserving the Node 24 support guard unless the runtime floor is intentionally raised. Do we have a high-confidence way to reproduce the issue? Yes for the PR defect from source inspection: the PR head lockfile resolves checkbox/select to 1.41.1 while the patched Preact adapter stays 1.40.0. I did not run install or tests because this review is read-only. Is this the best way to solve the issue? No; the dependency update should keep the Zag packages on a single compatible version or update the patched adapter and patch together before merge. Full review comments:
Overall correctness: patch is incorrect AGENTS.md: found and applied where relevant. Codex review notes: model gpt-5.5, reasoning high; reviewed against 043def5f6442. Label changesLabel justifications:
Evidence reviewedAcceptance criteria:
What I checked:
Likely related people:
What the crustacean ranks mean
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics. How this review workflow works
|
Bumps the dependencies group with 9 updates:
0.75.30.75.524.12.425.9.17.0.0-dev.20260519.17.0.0-dev.20260526.10.51.00.52.01.66.01.67.01.46.11.47.01.40.01.41.11.40.01.41.114.1.114.2.0Updates
@earendil-works/pi-aifrom 0.75.3 to 0.75.5Release notes
Sourced from @earendil-works/pi-ai's releases.
... (truncated)
Changelog
Sourced from @earendil-works/pi-ai's changelog.
Commits
83a227aUpdate release instructions and generated modelsea2b70dRelease v0.75.5b9566fcAudit unreleased changelog entriesd80bcc3test(ai): avoid hardcoded Fireworks router id9b62f1fFix Anthropic eager tool input compat testd801d88Support adaptive thinking for Anthropic-compatible aliases7002c68fix(ai): declare Bedrock Smithy HTTP handler dependencyc841a6cClean up OAuth device-code callbacks11e868bMerge pull request #4788 from earendil-works/refactor-device-code-login1a2a536chore: update PR prompt templateUpdates
@types/nodefrom 24.12.4 to 25.9.1Commits
Updates
@typescript/native-previewfrom 7.0.0-dev.20260519.1 to 7.0.0-dev.20260526.1Commits
Updates
oxfmtfrom 0.51.0 to 0.52.0Changelog
Sourced from oxfmt's changelog.
... (truncated)
Commits
68b455drelease(apps): oxlint v1.67.0 && oxfmt v0.52.0 (#22735)16b8058feat(oxfmt): Supportvite-plus/resolveConfigfor vite.config.ts (#22454)Updates
oxlintfrom 1.66.0 to 1.67.0Release notes
Sourced from oxlint's releases.
... (truncated)
Changelog
Sourced from oxlint's changelog.
Commits
68b455drelease(apps): oxlint v1.67.0 && oxfmt v0.52.0 (#22735)b84941efeat(linter/vue): implement no-expose-after-await rule (#22675)98b98c1feat(linter/vue): implement no-computed-properties-in-data rule (#22674)2d4c919feat(oxlint): Supportvite-plus/resolveConfigfor vite.config.ts (#22456)2a60012feat(linter/vue): implement require-render-return rule (#22613)9f227fdfeat(linter/vue): implement no-deprecated-props-default-this rule (#21892)87f065efeat(linter/vue): implement return-in-emits-validator rule (#21935)ea0380cfeat(linter/unicorn): implementimport-stylerule (#22173)dde40fefeat(linter/vue): implement no-watch-after-await rule (#22006)a735eb0feat(linter/vue): implement valid-next-tick rule (#22531)Updates
es-toolkitfrom 1.46.1 to 1.47.0Release notes
Sourced from es-toolkit's releases.
Changelog
Sourced from es-toolkit's changelog.
Commits
9f35cf9v1.47.0b73e0bcdocs[playground]: add link to playground editor title (#1735)a6d40dfdocs[server]: add localized server docs (#1733)ecbdd36docs[playground]: separate playground page layout (#1732)52ac49cdocs(compat): align method chaining guidance across locales (#1731)c011690fix(docs): fix issues in playground page (#1727)03ca6eafix(uniqWith): match lodash comparator argument order in compat (#1729)8a978e3build(deps): bump dahlia/submark (#1730)6d3ca81docs: introduce flavor switcher and co-locate compat under /compat/ (#1699)970ae85fix: add alt text to VitePress logo (#1722)Updates
@zag-js/checkboxfrom 1.40.0 to 1.41.1Release notes
Sourced from @zag-js/checkbox's releases.
Changelog
Sourced from @zag-js/checkbox's changelog.
... (truncated)
Commits
1109315Version Packages (#3146)2e3867dfix(drawer): measure content that mounts lazily behind a Presence wrapper (#3...f61de29fix: drawer transitionsb39524crefactor: pointer outside handling9056a6achore(deps): update all non-major dependencies (#3140)ea4cbb0chore: remove unused dependencies05a7779chore: update dialog examplesf531192ci: add fallback tag push to release workflowc6cdf7bVersion Packages (#3077)56090cechore: update dependencies and migrate to pnpm v11Updates
@zag-js/selectfrom 1.40.0 to 1.41.1Release notes
Sourced from @zag-js/select's releases.
Changelog
Sourced from @zag-js/select's changelog.
... (truncated)
Commits
1109315Version Packages (#3146)2e3867dfix(drawer): measure content that mounts lazily behind a Presence wrapper (#3...f61de29fix: drawer transitionsb39524crefactor: pointer outside handling9056a6achore(deps): update all non-major dependencies (#3140)ea4cbb0chore: remove unused dependencies05a7779chore: update dialog examplesf531192ci: add fallback tag push to release workflowc6cdf7bVersion Packages (#3077)56090cechore: update dependencies and migrate to pnpm v11Updates
markdown-itfrom 14.1.1 to 14.2.0Changelog
Sourced from markdown-it's changelog.
Commits
829797a14.2.0 released9ce2087Fix smartquotes perfomance02e73b8linkify-it bump68cfb8cfix: don't end HTML comment blocks on a blank line (#1155)1083137Readme cleanup97c7ca2Update funding infoc471b55Changelog update7769621isPunctChar => isPunctCharCodeaa2aa70fix: always reset parentType in lheading rule (#1131)59955f2Polish PRs #1072, #1074Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions