chore(deps): rolling dependency update - #231
socket-pr-bot[bot] wants to merge 1 commit into
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
1269f1f to
d4bc16f
Compare
d4bc16f to
0231bfa
Compare
Rolling dependency update
One long-lived PR, rebuilt from
mainon every run so it staysmergeable. Each run appends its dependency delta below, newest first.
2026-09-20 — run · 15 updated
@inquirer/checkbox@inquirer/confirm@inquirer/input@inquirer/password@inquirer/search@inquirer/select@perryts/perryfast-checkglobalslibnpmpackp-mapvitewebpackyamlzodcommits
2026-09-19 — run · 15 updated
@inquirer/checkbox@inquirer/confirm@inquirer/input@inquirer/password@inquirer/search@inquirer/select@perryts/perryfast-checkglobalslibnpmpackp-mapvitewebpackyamlzodcommits
2026-09-18 — run · 14 updated
@inquirer/checkbox@inquirer/confirm@inquirer/input@inquirer/password@inquirer/search@inquirer/select@perryts/perryfast-checkglobalslibnpmpackp-mapvitewebpackzodcommits
Note
Low Risk
Routine pin and lockfile refresh across dev/build tooling; the zod and vite bumps are the widest blast radius but stay in test/agent tooling rather than production runtime paths.
Overview
This is the rolling weekly dependency refresh: catalog pins and
pnpm-lock.yamlmove forward together with a small runtime/toolchain bump.Toolchain & external tools: Node is bumped to 26.8.2 in
.node-version. The pinned GitHub CLI inexternal-tools.jsongoes 2.99.0 → 2.100.0 (new per-platform assets and integrity hashes); the temporarysoakBypassforghis removed, indicating that version is now treated as past soak.Notable catalog / override bumps (also reflected in
pnpm-workspace.yaml):vite8.2.2 → 8.3.0,webpack5.109.2 → 5.110.3,zod4.4.3 → 4.6.2,@perryts/perry0.5.1220 → 0.5.1520, refreshed@inquirer/*prompts, plus smaller bumps (fast-check,globals,libnpmpack,p-map,magic-string,hono,js-yaml,postcss,qs, and related transitives). The lockfile also adjusts pnpm’s packaged exe pin (12.4.2 → 12.4.1) and refreshes@perryts/perryoptional platform binaries (e.g. win32-arm64 added, some musl variants dropped).Build/test impact: Vitest/Vitiate and MCP-related packages now resolve against Vite 8.3 and Zod 4.6; webpack’s minimizer plugin chain updates (including svgo in the webpack minimizer graph).
Reviewed by Cursor Bugbot for commit 1269f1f. Configure here.