Skip to content

chore: bump tsx from 4.23.13 to 4.23.15 - #72

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/tsx-4.23.15
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/tsx-4.23.15

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps tsx from 4.23.13 to 4.23.15.

Release notes

Sourced from tsx's releases.

v4.23.15

4.23.15 (2026-09-20)

Bug Fixes

  • exclude bare builtins from namespace inheritance (38e1588)
  • expose require.cache and require.extensions to tsImport CommonJS modules (2da3407)
  • make namespaced register() overloads portable for declaration emit (562c434)

This release is also available on:

v4.23.14

4.23.14 (2026-09-20)

Bug Fixes

  • restore the CJS bridge namespace for Node 24 require(esm) under tsImport() (#802) (6e5236b)

This release is also available on:

Commits
  • ca66105 test: fix drive-less file URLs in ESM resolver fixtures
  • 2da3407 fix: expose require.cache and require.extensions to tsImport CommonJS modules
  • 38e1588 fix: exclude bare builtins from namespace inheritance
  • 562c434 fix: make namespaced register() overloads portable for declaration emit
  • edfb1f0 build: upgrade pkgroll and externalize CJS loader reference
  • 70e7828 test: upgrade tinyspy for disposable API
  • 9ed2022 ci: avoid duplicate release notifications
  • 872e77f refactor: use disposables for cleanup
  • 6e5236b fix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [tsx](https://github.com/privatenumber/tsx) from 4.23.13 to 4.23.15.
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.13...v4.23.15)

---
updated-dependencies:
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@claude

claude Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Claude finished @dependabot[bot]'s task in 1m 8s —— View job


Dependency review: tsx 4.23.13 → 4.23.15

  • Read the diff and package.json
  • Check how tsx is used in the repo
  • Assess release notes vs. actual usage
  • Verify scope of the lockfile change

Verdict: safe to merge. Patch bump, dev-only, no transitive changes, and none of the fixed code paths are ones this repo touches.


1. What changed

Patch bump within the same major/minor line (4.23.13 → 4.23.15), so no semver-breaking surface. package.json already declares "tsx": "^4.19.0" (package.json:46) and is untouched — only the resolved pin in the lockfile moved.

The diff is three lines in one lockfile entry (version, resolved, integrity) with no change to esbuild, get-tsconfig, or any other transitive dependency, and no new/removed packages. That's the minimal shape you want from a dependency bump — nothing to scrutinise beyond the version itself.

2. Release notes vs. this codebase

All four upstream fixes across 4.23.14 and 4.23.15 are in tsx's programmatic API:

Fix API affected
restore CJS bridge namespace for Node 24 require(esm) (#802) tsImport()
expose require.cache / require.extensions to CJS modules tsImport()
exclude bare builtins from namespace inheritance register()
make namespaced register() overloads portable for declaration emit register() types

This repo uses tsx exclusively as a CLI, in exactly one place:

  • package.json:20 — "generate-catalog": "tsx scripts/generate-catalog.ts"
  • invoked by .github/workflows/update-catalog.yml:33 (npm run generate-catalog)

scripts/generate-catalog.ts imports only node:fs/node:path/node:url plus two local .ts modules via .js specifiers (resolve-refs.js, format-json.js) — no tsImport, no register, no tsx/esm hooks anywhere in the repo. So the blast radius of this bump is effectively zero; the 4.23.14 Node 24 fix is doubly irrelevant since update-catalog.yml:27 pins Node 22.

3. Node floor

engines.node is >=22 (package.json:13), consistent with @types/node ^22.0.0, the CI matrix low end (ci.yml:20 → ['22', '24']), and update-catalog.yml:27. tsx 4.x requires Node ≥18, so the floor is unaffected and nothing in the drift-prone set needs to move alongside this.

4. Risks and follow-up

No concrete risks identified. The one behaviour this bump could plausibly disturb is catalog generation, and that is already covered end-to-end: the weekly update-catalog.yml run executes the script against the live OpenAPI spec, and test/catalog.test.ts asserts invariants over the committed output. Merging on green CI plus the next scheduled catalog run is sufficient verification — no extra tests worth adding for a patch bump of a dev-only CLI.

One note on verification limits: I could not run npm ci / npm test locally in this environment (install not permitted, no node_modules present), so my assessment is static — based on the lockfile diff, the usage sites, and the upstream release notes. The build, both Node matrix legs, and the .mcpb smoke test in ci.yml are the actual gate here; please treat a green CI run as the confirmation I couldn't produce.


· branch

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants