Skip to content

build(deps-dev): bump commit-and-tag-version from 13.1.0 to 13.1.2 - #2200

Merged
carlos-alm merged 2 commits into
mainfrom
dependabot/npm_and_yarn/commit-and-tag-version-13.1.2
Aug 2, 2026
Merged

build(deps-dev): bump commit-and-tag-version from 13.1.0 to 13.1.2#2200
carlos-alm merged 2 commits into
mainfrom
dependabot/npm_and_yarn/commit-and-tag-version-13.1.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 1, 2026

Copy link
Copy Markdown
Contributor

Bumps commit-and-tag-version from 13.1.0 to 13.1.2.

Release notes

Sourced from commit-and-tag-version's releases.

v13.1.2

13.1.2 (2026-07-28)

Bug Fixes

v13.1.1

13.1.1 (2026-07-28)

Bug Fixes

  • Fix issue where prereleases were calculated from the wrong base (fixes #310) (1261803)
Changelog

Sourced from commit-and-tag-version's changelog.

13.1.2 (2026-07-28)

Bug Fixes

13.1.1 (2026-07-28)

Bug Fixes

  • Fix issue where prereleases were calculated from the wrong base (fixes #310) (1261803)
Commits
  • 12204b8 chore(master): release 13.1.2 (#319)
  • 8b968bc fix(yaml): preserve long scalar lines (#313)
  • efc14c1 docs: recommend branch-based prerelease workflow (#312)
  • 0debe39 chore(master): release 13.1.1 (#318)
  • 8aa1098 chore: Run audit fix
  • 080bec7 build(deps-dev): bump eslint-plugin-n from 17.21.3 to 18.2.2 (#316)
  • cf60c59 build(deps): bump figures from 3.2.0 to 6.1.0 (#315)
  • 1261803 fix: Fix issue where prereleases were calculated from the wrong base (fixes #...
  • ef5a889 build(deps): bump yaml from 2.8.4 to 2.9.0 (#314)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [commit-and-tag-version](https://github.com/absolute-version/commit-and-tag-version) from 13.1.0 to 13.1.2.
- [Release notes](https://github.com/absolute-version/commit-and-tag-version/releases)
- [Changelog](https://github.com/absolute-version/commit-and-tag-version/blob/master/CHANGELOG.md)
- [Commits](absolute-version/commit-and-tag-version@v13.1.0...v13.1.2)

---
updated-dependencies:
- dependency-name: commit-and-tag-version
  dependency-version: 13.1.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 1, 2026
@carlos-alm

Copy link
Copy Markdown
Contributor

@greptileai

@greptile-apps

greptile-apps Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR updates the development-only commit-and-tag-version lockfile entry from 13.1.0 to 13.1.2.

  • Updates the package tarball URL and integrity hash.
  • Updates its resolved yaml dependency from 2.8.4 to 2.9.0.
  • Contains no application-code changes.

Confidence Score: 5/5

The PR appears safe to merge because it only applies a consistent patch-level development dependency update with no identified runtime or build failure.

The changed lockfile entries align the release tool with its updated yaml dependency, while the reported vulnerable packages are unchanged and do not create PR-caused failures.

Important Files Changed

Filename Overview
package-lock.json Consistently updates commit-and-tag-version and its yaml dependency; no actionable regression was identified.

Reviews (1): Last reviewed commit: "build(deps-dev): bump commit-and-tag-ver..." | Re-trigger Greptile

@carlos-alm
carlos-alm merged commit 0f01214 into main Aug 2, 2026
12 checks passed
@carlos-alm
carlos-alm deleted the dependabot/npm_and_yarn/commit-and-tag-version-13.1.2 branch August 2, 2026 03:21
@github-actions github-actions Bot locked and limited conversation to collaborators Aug 2, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant