chore: bump tsx from 4.23.13 to 4.23.15 - #72
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [tsx](https://github.com/privatenumber/tsx) from 4.23.13 to 4.23.15. - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](privatenumber/tsx@v4.23.13...v4.23.15) --- updated-dependencies: - dependency-name: tsx dependency-version: 4.23.15 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
Claude finished @dependabot[bot]'s task in 1m 8s —— View job Dependency review:
|
| Fix | API affected |
|---|---|
restore CJS bridge namespace for Node 24 require(esm) (#802) |
tsImport() |
expose require.cache / require.extensions to CJS modules |
tsImport() |
| exclude bare builtins from namespace inheritance | register() |
make namespaced register() overloads portable for declaration emit |
register() types |
This repo uses tsx exclusively as a CLI, in exactly one place:
package.json:20—"generate-catalog": "tsx scripts/generate-catalog.ts"- invoked by
.github/workflows/update-catalog.yml:33(npm run generate-catalog)
scripts/generate-catalog.ts imports only node:fs/node:path/node:url plus two local .ts modules via .js specifiers (resolve-refs.js, format-json.js) — no tsImport, no register, no tsx/esm hooks anywhere in the repo. So the blast radius of this bump is effectively zero; the 4.23.14 Node 24 fix is doubly irrelevant since update-catalog.yml:27 pins Node 22.
3. Node floor
engines.node is >=22 (package.json:13), consistent with @types/node ^22.0.0, the CI matrix low end (ci.yml:20 → ['22', '24']), and update-catalog.yml:27. tsx 4.x requires Node ≥18, so the floor is unaffected and nothing in the drift-prone set needs to move alongside this.
4. Risks and follow-up
No concrete risks identified. The one behaviour this bump could plausibly disturb is catalog generation, and that is already covered end-to-end: the weekly update-catalog.yml run executes the script against the live OpenAPI spec, and test/catalog.test.ts asserts invariants over the committed output. Merging on green CI plus the next scheduled catalog run is sufficient verification — no extra tests worth adding for a patch bump of a dev-only CLI.
One note on verification limits: I could not run npm ci / npm test locally in this environment (install not permitted, no node_modules present), so my assessment is static — based on the lockfile diff, the usage sites, and the upstream release notes. The build, both Node matrix legs, and the .mcpb smoke test in ci.yml are the actual gate here; please treat a green CI run as the confirmation I couldn't produce.
· branch
Bumps tsx from 4.23.13 to 4.23.15.
Release notes
Sourced from tsx's releases.
Commits
ca66105test: fix drive-less file URLs in ESM resolver fixtures2da3407fix: expose require.cache and require.extensions to tsImport CommonJS modules38e1588fix: exclude bare builtins from namespace inheritance562c434fix: make namespaced register() overloads portable for declaration emitedfb1f0build: upgrade pkgroll and externalize CJS loader reference70e7828test: upgrade tinyspy for disposable API9ed2022ci: avoid duplicate release notifications872e77frefactor: use disposables for cleanup6e5236bfix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)