chore(deps): bump github/codeql-action from 4.37.4 to 4.37.8 - #33
chore(deps): bump github/codeql-action from 4.37.4 to 4.37.8#33dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.37.4 to 4.37.8. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v4.37.4...v4.37.8) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.37.8 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Superseded by #34, which bundles this bump together with the other open dependabot PRs and fixes the CI failure caused by TS7's removal of |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
…script, codeql-action (#34) Bundles the 4 currently-open dependabot PRs (#30-#33) into one tested change rather than merging them separately: - vitest 4.1.10 -> 4.1.11 - @types/node 25.9.1 -> 26.2.0 - typescript 6.0.3 -> 7.0.2 - github/codeql-action 4.37.4 -> 4.37.8 (workflow-only) The typescript bump (#32) was failing CI (lint + test 22.x) because TS 7 removed the `node10` moduleResolution value outright (TS5108). tsconfig.cjs.json used `"moduleResolution": "node10"` for the CJS build with `"ignoreDeprecations": "6.0"` silencing the prior deprecation warning -- TS7 doesn't accept the ignoreDeprecations escape hatch for a removed option, it's just a hard error now. Switched to `"moduleResolution": "Bundler"`, which is TS's own default for a CommonJS module target when the base config's `module` isn't node16/node18/nodenext (base tsconfig.json uses Node16 for the ESM build), so this restores the previous effective resolution behavior rather than changing it. The other three bumps had no code-visible impact; build, full test suite, and npm audit all pass unchanged. Found and left alone (pre-existing, not caused by this bump, not blocking): dist/cjs/*.js has no dist/cjs/package.json declaring `"type": "commonjs"`, so under the root package.json's `"type": "module"`, a plain `require()` against dist/cjs/index.js fails -- confirmed this reproduces identically on typescript@6.0.3 before this bump. Worth its own fix; not touched here since it's orthogonal to a dependency-version PR. Co-authored-by: safenestdev <safenestdev@users.noreply.github.com>
Bumps github/codeql-action from 4.37.4 to 4.37.8.
Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
Commits
db488ddMerge pull request #4102 from github/update-v4.37.8-9ee088e131845f5bUpdate changelog for v4.37.89ee088eMerge pull request #4080 from github/henrymercer/studious-giggle1aef003Address review feedback on overlay disk flags508b83bMerge main into overlay minimum disk feature branchd97b342Merge pull request #4098 from github/mbg/permission-error-as-configuration-error47fa622MakeEACCESaConfigurationError45693ccRefactorENOSPCcheck intoisDiskConfigurationErrorfunctionc2fd8f5Merge pull request #4081 from github/mario-campos/version-cache-to-diskc56f48eLog unexpected conditions during caching CLI outputDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)