Skip to content

Bump the node group with 3 updates - #1

Closed
dependabot[bot] wants to merge 9 commits into
masterfrom
dependabot/npm_and_yarn/node-a8cb9b4362
Closed

dependabot[bot] wants to merge 9 commits into
masterfrom
dependabot/npm_and_yarn/node-a8cb9b4362

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 10, 2026

Copy link
Copy Markdown

Bumps the node group with 3 updates: @vitest/coverage-v8, tsdown and vitest.

Updates @vitest/coverage-v8 from 4.1.11 to 5.0.0

Release notes

Sourced from @​vitest/coverage-v8's releases.

v5.0.0

Vitest 5 is officially out! This release focuses on performance and brings a lot of new features while fixing long-standing bugs. See our blog post for the official announcement.

   🚨 Breaking Changes

... (truncated)

Commits

Updates tsdown from 0.22.14 to 0.23.0

Release notes

Sourced from tsdown's releases.

v0.23.0

   🧭 Migration Guide

Most users can upgrade directly. Before upgrading, run one final build with tsdown@0.22.14 and resolve all deprecation warnings.

  • config:
    • bundle: false → unbundle: true; bundle: true can be removed
    • outExtension → outExtensions
    • publicDir / --public-dir → copy / --copy
    • removeNodeProtocol: true → nodeProtocol: 'strip'
    • injectStyle → css.inject
  • deps:
    • inlineOnly / deps.onlyAllowBundle → deps.onlyBundle
    • skipNodeModulesBundle: true → deps.neverBundle: true
    • resolveDepSubpath now defaults to false; set it to true to preserve the previous behavior
  • dts:
    • rolldown-plugin-dts was upgraded from 0.27.13 to 0.28.5
    • dts.oxc: true → dts.generator: 'oxc'
    • dts.tsgo: true → dts.generator: 'tsgo'; oxc and tsgo objects now only configure their respective generators
    • dts.volarPlugins → dts.customLanguages; rename each language's create hook to createVolarPlugins
    • Custom languages, including vue, now throw when combined with an incompatible generator
    • dts.cjsReexport was removed; dual-format builds now generate CJS declarations in a separate pass
  • attw:
    • The default profile changed from strict to esm-only; set profile: 'strict' to preserve the previous checks
  • programmatic API:
    • build() now returns { bundles, watch }; replace const bundles = await build() with const { bundles } = await build()
  • requirements:
    • Node.js 25 is no longer supported; use ^22.18.0, ^24.11.0, or >=26.0.0
    • rolldown-plugin-dts now requires Rolldown 1.2.x
    • Legacy types and typesVersions fallbacks were removed; use TypeScript's bundler, node16, or nodenext module resolution

   🚨 Breaking Changes

   🚀 Features

... (truncated)

Commits

Updates vitest from 4.1.11 to 5.0.0

Release notes

Sourced from vitest's releases.

v5.0.0

Vitest 5 is officially out! This release focuses on performance and brings a lot of new features while fixing long-standing bugs. See our blog post for the official announcement.

   🚨 Breaking Changes

... (truncated)

Commits
  • f441c6f chore: release v5.0.0 (#11130)
  • d46a747 fix: treat test.describe as a suite during static collection (#11128)
  • 584cf30 fix: add a warning if inline project has duplicate plugins due to unexpected ...
  • f08ce4b fix: apply queued mocks from doMock() in queue order (fixes #10706) (#11127)
  • 897f51f chore: release v5.0.0-rc.4 (#11107)
  • 1339b06 chore(deps): update all non-major dependencies (#11104)
  • 51e9494 feat!: parse files statically in vitest list by default (#11088)
  • 2122ffd fix: propagate --maxWorkers to projects (#11102)
  • dc10f5f fix(browser): report the action error when a task times out (#11101)
  • d4fe198 feat: promote clearCache out of experimental (#11086)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

leonardocustodio and others added 9 commits September 9, 2026 17:19
Imported from paritytech/bcts (packages are extracted one per repository) and
restructured to match BlockchainCommons/bc-dcbor-ts: self-contained tsconfig
and ESLint config, no turbo, no workspace protocol, @BlockchainCommons scope,
API surface snapshots, and Blockchain Commons governance documents.
Commit the api/ surface snapshots and seed the coverage floors from the first
measured run of this repository outside the monorepo.
Commit the api/ surface snapshots and seed the coverage floors from the first
measured run of this repository outside the monorepo.
Commit the api/ surface snapshots and seed the coverage floors from the first
measured run of this repository outside the monorepo.
Assert the contract the exports map promises: every declared entry point exists
as .mjs, .cjs, .d.mts and .d.cts, the ESM root entry loads, and the CJS entry
exposes the same public names.
…tors, differential, Rust harness

- tests/baseline/dcbor-parse-baseline.mjs built from the unmodified tree
  with dcbor-compat, known-values, tags and uniform-resources inlined
  (the build ignores the package's tsdown config so `neverBundle` cannot
  keep siblings external; a tests/baseline/entry.ts exposes the inlined
  compat tags store so the differential registers the same names).
- Sources and tests ported to canonical dcbor (taggedValue, CborDate,
  diagnostic subpath), known-values (getGlobalKnownValuesStore().byName,
  toCbor) and uniform-resources (UR.parse, type.name, cbor); dcbor-compat
  dropped from dependencies. The differential proves the port
  byte-identical over 876 golden vectors and ~14k generated recipes.
- Recipes: parse / partial / composeArray / composeMap → hex or
  `throw:Variant[(Token)]@start-end`; hand corpus of 290 sources from both
  implementations' suites plus edges; grammar generator up to depth 4 with
  truncation and single-character corruptions; properties (diagnostic
  round trip, compose = parse, prefix length).
- Rust harness (dcbor-parse 0.11.1 by path, bc-tags 0.12): 823 match, 53
  expected divergences (S1/S2 error spans and lexer-level variants on
  rejected input, D2 `Unit` in containers, P1–P3 pending fixes), 0
  mismatch; RUST_DIVERGENCES.md written. ADRs 0001–0003; bench.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G2xPbsuQ149Gams41qu7vS
- The lexer matches sticky regular expressions at the current position
  instead of slicing the remaining source for every attempt, so a long
  document lexes in linear time. Same tokens, same spans: the differential
  is clean.
- bench (baseline bundle vs dist): 49 kB document 0.39×, one item 0.55×,
  rejection 0.46× (the port to canonical dcbor accounts for about half).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G2xPbsuQ149Gams41qu7vS
- parseDcbor / parseDcborPrefix ({ value, length }) / composeDcborArray /
  composeDcborMap throw DcborParseError and DcborComposeError (code
  unions, typed details, fullMessage(source), cause); try… forms return
  { ok, value } | { ok, error }. options { tags, knownValues } choose the
  registries. Lexer, Token and token move to the /lexer subpath;
  Lexer.next() throws. The old result objects, helpers and factories gone.
- Fixes towards the reference (tombstones T1–T3, vectors and snapshot
  regenerated): exact fractional seconds via CborDate.fromYmdHms with
  nanoseconds, leap seconds accepted, keyword runs unrecognised as a
  whole. Rust harness: 831 match, 45 expected (D2, S1, S2), 0 mismatch.
- Coverage 91/85/95/92, floors raised to 88/82/92/90; size root 47 kB
  (limit 57), /lexer 12 kB (limit 15); API snapshots for both entries;
  MIGRATION, CHANGELOG, README, RUST_DIVERGENCES updated.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G2xPbsuQ149Gams41qu7vS
Bumps the node group with 3 updates: [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8), [tsdown](https://github.com/rolldown/tsdown) and [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).


Updates `@vitest/coverage-v8` from 4.1.11 to 5.0.0
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.0/packages/coverage-v8)

Updates `tsdown` from 0.22.14 to 0.23.0
- [Release notes](https://github.com/rolldown/tsdown/releases)
- [Commits](rolldown/tsdown@v0.22.14...v0.23.0)

Updates `vitest` from 4.1.11 to 5.0.0
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.0/packages/vitest)

---
updated-dependencies:
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: node
- dependency-name: tsdown
  dependency-version: 0.23.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: node
- dependency-name: vitest
  dependency-version: 5.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: node
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 10, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot @github

dependabot Bot commented on behalf of github Sep 10, 2026

Copy link
Copy Markdown
Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/node-a8cb9b4362 branch September 10, 2026 12:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant