Skip to content

build(deps): upgrade every dependency to its latest release - #139

Merged
Mearman merged 3 commits into
mainfrom
chore/upgrade-dependencies
Oct 3, 2026
Merged

Mearman merged 3 commits into
mainfrom
chore/upgrade-dependencies

Conversation

@Mearman

@Mearman Mearman commented Oct 3, 2026

Copy link
Copy Markdown
Member

Every dependency is at its latest release and pnpm outdated reports nothing. The majors that needed work: vitest 5 cannot call an arrow function as a constructor, so class mocks use function implementations and a small helper (src/test-support, excluded from the published build) copies a test double onto the constructed instance in place of the casts that were there. TypeScript 7 ships no importable compiler API: ESLint could not even load eslint.config.ts under it. typescript is therefore aliased to Microsoft's @typescript/typescript6 compatibility package for typescript-eslint, typedoc and knip, and the native compiler is installed as @typescript/native so tsc builds and type-checks with the 7.0 binary; this is the setup documented in the TypeScript 7 announcement. Removing the alias once typescript-eslint supports 7.1 is tracked in #135. The vitest 5 upgrade also fixes the coverage run, which crashed on main inside a transitive glob dependency after the audit's brace-expansion override.

…rows

A newer vitest cannot call an arrow function as a constructor and types
a class mock's implementation as either a constructable or a this-typed
function returning nothing. Mocks of classes now use function
implementations, and a small helper copies a test double's members onto
the constructed instance, which replaces the casts that pretended a
double was a full instance. The helper lives outside the published
build.
TypeScript 7 ships no importable compiler API, so typescript-eslint,
typedoc and knip cannot load it. typescript is aliased to Microsoft's
typescript6 compatibility package for them and the native compiler is
installed beside it, so tsc builds and type-checks with the native
binary.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-10-03T08:24:17.985739Z 9661d36 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Vitest now sets an environment variable whose config value is undefined
to the string undefined, and turbo's strict environment mode withholds
the CI matrix variables, so on Linux the helper read the case
sensitivity as the string undefined and reported a case-insensitive
filesystem. The config forwards only variables that are set, and the
test task declares them to turbo so the per-OS settings reach the tests
and take part in the cache key.
@Mearman

Mearman commented Oct 3, 2026

Copy link
Copy Markdown
Member Author

@codex security review

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review

Security review completed. No security issues were found in this pull request.

Reviewed commit: 9661d36fc2

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@Mearman
Mearman merged commit 3a458bd into main Oct 3, 2026
22 checks passed
@Mearman
Mearman deleted the chore/upgrade-dependencies branch October 3, 2026 08:24
@Mearman

Mearman commented Oct 3, 2026

Copy link
Copy Markdown
Member Author

🎉 This PR is included in version 1.41.4 🎉

The release is available on:

Installation

npm install -g markmv@1.41.4

Security & Supply Chain

✅ OIDC Trusted Publishing: published from CI with no long-lived npm token
✅ SBOM: Software Bill of Materials included in release
✅ NPM Provenance: Published with npm provenance attestations

Test Coverage

This release includes comprehensive test coverage reports. View coverage details in the release assets.

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant