fix(deps-dev): bump tsx from 4.23.1 to 4.23.5 - #206
Conversation
Bumps [tsx](https://github.com/privatenumber/tsx) from 4.23.1 to 4.23.5. - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](privatenumber/tsx@v4.23.1...v4.23.5) --- updated-dependencies: - dependency-name: tsx dependency-version: 4.23.5 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
athena-omt
left a comment
There was a problem hiding this comment.
Athena governance review — APPROVE
Pinned to exact head 67f9e520c0ee3cc57924f46b9df8686699aeb02d (single Dependabot commit directly on origin/main 748a413c; branch fresh, mergeable, REVIEW_REQUIRED).
Change: fix(deps-dev): bump tsx from 4.23.1 to 4.23.5 — dev-dependency only.
- Files:
package.json,pnpm-lock.yaml(2 files, +139/−128); no source, workflow, or script changes. - Lockfile delta is the tsx bump plus routine peer/transitive refresh (rollup platform packages 4.62.3→4.62.4, nanoid, postcss).
Supply chain: lockfile integrity for tsx@4.23.5 (sha512-rw55FUaq…) matches the npm registry record exactly. Upstream release notes: bug-fix-only patch (4.23.2–4.23.5).
Local verification at exact head (node OMT-NAS, gh identity athena-omt):
pnpm install --frozen-lockfile→ exit 0pnpm lint(tsc --noEmit) → exit 0pnpm test→ 54 files / 324 tests passed, exit 0
CI at head: all required checks pass (CI Gate, Fast Checks, CodeQL/codeql, dependency-review, osv/osv-scanner, Validate Secrets, contracts, test); skipped jobs are path-filtered smoke callers, expected for a lockfile-only change.
Authorship preserved (Dependabot PR; no merge performed). Governance review only — merge decision remains with JT/human maintainers.
Bumps tsx from 4.23.1 to 4.23.5.
Release notes
Sourced from tsx's releases.
Commits
c55004dtest: remove legacy PTY retrye368161chore(deps): update pty-spawn to 1.1.18d39496ci: validate GitHub Actions workflows6fe724etest: clean up timed-out PTY attemptse0a0536ci: skip unused Windows Node cache6d6dd84ci: remove broken lock automation3c1d051fix: detect the Node inspector enabled via NODE_OPTIONS40380a4ci: lock down the release toolchainf217b6bci: restrict releases to public repository2afc7bbfix(cli): allow async process.once() signal handlers to finish (#827)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)