Skip to content

[TASK] Keep the dependencies current - #3

Merged
benjaminkott merged 2 commits into
mainfrom
task/keep-dependencies-current
Sep 19, 2026
Merged

benjaminkott merged 2 commits into
mainfrom
task/keep-dependencies-current

Conversation

@benjaminkott

Copy link
Copy Markdown
Owner

Description

Two commits:

  1. Update the dependencies — everything within range to current (playwright 1.63, yaml 2.9.1, zod 4.6, …), TypeScript to 7 (the native compiler; builds, typechecks and passes the suite unchanged), actions/setup-node to v7. @types/node stays on 24 on purpose: the types describe the Node the tool targets, the current LTS, and move when that target does.
  2. Let Dependabot keep them current — one pull request a week per ecosystem, npm grouped, @types/node majors ignored. The runner stays on ubuntu-latest so it moves on its own too; the CI run is what says whether a move held. Both written down in MAINTAINERS.md.

Type of change

  • Bugfix
  • Task
  • Feature
  • Documentation

Related issues

How to validate

  1. CI on this pull request is green under TypeScript 7 and setup-node v7
  2. After the merge, Dependabot's first run shows up under Insights → Dependency graph → Dependabot

AI assistance

  • Agent and version: Claude Code
  • Model and effort/reasoning level: Claude Opus 5, default effort
  • Share written by the agent: all of it
  • Reviewed and understood before pushing: yes

Checklist

  • Targets main
  • Commits are signed off (git commit -s) — appreciated, not
    required
  • Commit subjects follow [BUGFIX|TASK|FEATURE] Subject
  • npm run typecheck passes
  • npm test passes
  • A bugfix comes with a test that fails without it — appreciated,
    not required
  • The JSON schema still matches the parser if the config format
    changed
  • README updated if the change is user facing

Everything to what is current: playwright 1.63, yaml 2.9.1, zod 4.6 and
the rest of the lockfile within their ranges, TypeScript to 7 -- the
native compiler, which builds, typechecks and passes the suite as it
is -- and actions/setup-node to v7.

@types/node stays on 24 on purpose. The types describe the Node the
tool targets, which is the current LTS, and a newer major would let
code compile against APIs that Node 24 does not have. It moves when
the target does.

Signed-off-by: Benjamin Kott <benjamin.kott@outlook.com>
The dependencies were as current as the last time somebody looked,
which on a small project is the last release. Dependabot now opens one
pull request a week per ecosystem: the npm updates grouped into one
change with one CI run to trust, the GitHub Actions on their own.

@types/node is held to the major of the Node the tool targets, and the
workflows stay on ubuntu-latest so the runner moves on its own as well.
Both are said in MAINTAINERS.md, beside how a release is cut.

Signed-off-by: Benjamin Kott <benjamin.kott@outlook.com>
@benjaminkott
benjaminkott merged commit 35a2ac8 into main Sep 19, 2026
1 check passed
@benjaminkott
benjaminkott deleted the task/keep-dependencies-current branch September 19, 2026 21:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant