Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Nov 26, 2025

Bumps style-dictionary from 4.3.0 to 5.1.1.

Release notes

Sourced from style-dictionary's releases.

v5.1.1

Patch Changes

  • 65745da: Fix outputReferences for tokens with 'value' in their name. Previously, references to tokens like object_type.value_chain were incorrectly resolved because the code removed the first occurrence of .value instead of only the trailing suffix.

v5.1.0

Minor Changes

  • 97a209a: Add new size/compose/{sp,dp} transforms

Patch Changes

  • dbcdae3: Fix fontName parsing to handle double quotes
  • c47600d: Export expand DTCGTypesMap for extension use cases.

v5.0.4

Patch Changes

  • 7a238af: Fix an issue with token collisions being way to eager about complaining when values that are identical are "colliding". This cuts collision warnings by 75% or more.

v5.0.3

Patch Changes

  • 3d070f5: Move patch-package to devDependencies and run in prepare instead of postinstall, so it only runs when npm installing locally and not for consumers.
  • 71614da: Wrap structuredClone in loadFile in a try catch, in case we have a JS/TS config file with dynamic content.

v5.0.2

Patch Changes

  • 8e413a2: Fix vulnerable dependencies, patch-package and its transitive tmp dependency in particular.
  • 9f84a81: Remove node-sass from create-react-app example, dart-sass is used now usually.
  • da19c8f: Small patch to allow no-destination "files" to not cause errors when using clean methods.

v5.0.1

Patch Changes

  • 463b456: Simplify internal cleanFile(s) utils, fix a bug that would still attempt to unlink non-existent files in verbosity "silent" mode.
  • 8f7c522: Fix loadFile to deep clone ES module exports to avoid unintended mutations

v5.0.0

Major Changes

  • 02300b1: No longer allow references to non-token leaf nodes. References only work when referencing a Design Token (its value). Non-token nodes will also not make it to the output, because they are filtered out during the flattening process to tokenMap and tokenArray. Remove allowing references with .value suffix.
  • f19a0cb: BREAKING: no longer possible to pass options to change the reference syntax {ref.foo}. The opening, closing and separator characters are now set to be aligned with the DTCG spec.
  • 02300b1: BREAKING: minimum NodeJS version required is now v22.0.0 (LTS, at time of writing this). This is to support Set.prototype.union which we utilize in our token reference resolution utility, and it's important to use the cheaper built-in versus doing a union manually.

Minor Changes

... (truncated)

Changelog

Sourced from style-dictionary's changelog.

5.1.1

Patch Changes

  • 65745da: Fix outputReferences for tokens with 'value' in their name. Previously, references to tokens like object_type.value_chain were incorrectly resolved because the code removed the first occurrence of .value instead of only the trailing suffix.

5.1.0

Minor Changes

  • 97a209a: Add new size/compose/{sp,dp} transforms

Patch Changes

  • dbcdae3: Fix fontName parsing to handle double quotes
  • c47600d: Export expand DTCGTypesMap for extension use cases.

5.0.4

Patch Changes

  • 7a238af: Fix an issue with token collisions being way to eager about complaining when values that are identical are "colliding". This cuts collision warnings by 75% or more.

5.0.3

Patch Changes

  • 3d070f5: Move patch-package to devDependencies and run in prepare instead of postinstall, so it only runs when npm installing locally and not for consumers.
  • 71614da: Wrap structuredClone in loadFile in a try catch, in case we have a JS/TS config file with dynamic content.

5.0.2

Patch Changes

  • 8e413a2: Fix vulnerable dependencies, patch-package and its transitive tmp dependency in particular.
  • 9f84a81: Remove node-sass from create-react-app example, dart-sass is used now usually.
  • da19c8f: Small patch to allow no-destination "files" to not cause errors when using clean methods.

5.0.1

Patch Changes

  • 463b456: Simplify internal cleanFile(s) utils, fix a bug that would still attempt to unlink non-existent files in verbosity "silent" mode.
  • 8f7c522: Fix loadFile to deep clone ES module exports to avoid unintended mutations

5.0.0

Major Changes

  • 02300b1: No longer allow references to non-token leaf nodes. References only work when referencing a Design Token (its value).

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [style-dictionary](https://github.com/amzn/style-dictionary) from 4.3.0 to 5.1.1.
- [Release notes](https://github.com/amzn/style-dictionary/releases)
- [Changelog](https://github.com/style-dictionary/style-dictionary/blob/main/CHANGELOG.md)
- [Commits](style-dictionary/style-dictionary@v4.3.0...v5.1.1)

---
updated-dependencies:
- dependency-name: style-dictionary
  dependency-version: 5.1.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Nov 26, 2025
@dependabot dependabot bot requested a review from a team as a code owner November 26, 2025 15:00
@dependabot dependabot bot requested a review from alizedebray November 26, 2025 15:00
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Nov 26, 2025
@changeset-bot
Copy link

changeset-bot bot commented Nov 26, 2025

⚠️ No Changeset found

Latest commit: e617f66

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@swisspost-bot
Copy link
Contributor

swisspost-bot commented Nov 26, 2025

Related Previews

@oliverschuerch oliverschuerch requested review from oliverschuerch and removed request for alizedebray December 8, 2025 14:41
@socket-security
Copy link

socket-security bot commented Dec 8, 2025

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​tokens-studio/​sd-transforms@​1.3.0 ⏵ 2.0.299 +1100100 +191100

View full report

@sonarqubecloud
Copy link

sonarqubecloud bot commented Dec 8, 2025

@oliverschuerch oliverschuerch merged commit 874136e into main Dec 8, 2025
13 checks passed
@oliverschuerch oliverschuerch deleted the dependabot/npm_and_yarn/style-dictionary-5.1.1 branch December 8, 2025 16:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants