Skip to content

chore(deps): rolling dependency update - #13

Open
socket-pr-bot[bot] wants to merge 1 commit into
mainfrom
weekly-update
Open

socket-pr-bot[bot] wants to merge 1 commit into
mainfrom
weekly-update

Conversation

@socket-pr-bot

@socket-pr-bot socket-pr-bot Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Rolling dependency update

One long-lived PR, rebuilt from main on every run so it stays
mergeable. Each run appends its dependency delta below, newest first.

2026-10-10 — run · 7 updated
package from to
@anthropic-ai/claude-code 2.1.251 2.1.288
@modelcontextprotocol/client 2.2.0 2.3.0
portless 0.15.6 0.15.7
shell-quote 1.11.0 1.12.0
typescript 7.1.0-dev.20261001.1 7.1.0-dev.20261003.1
vite 8.3.1 8.3.2
yaml 2.9.0 2.9.1
commits
  • chore(deps): apply weekly update fixes
2026-10-09 — run · no dependency changes

No dependency ranges changed in this run.

commits
  • chore(deps): apply weekly update fixes
2026-09-25 — run · 2 updated
package from to
@anthropic-ai/claude-code 2.1.251 2.1.276
yaml 2.9.0 2.9.1
commits
  • chore(deps): apply weekly update fixes

Note

Low Risk
Routine semver-compatible dependency pins and lockfile churn; the devEngines shape change only affects local/CI package-manager validation, not runtime behavior.

Overview
This rolling update bumps fleet catalog pins for @anthropic-ai/claude-code (2.1.251 → 2.1.276), yaml (2.9.0 → 2.9.1), and the transitive markdown-it override (14.3.1 → 14.3.2), with pnpm-lock.yaml refreshed so Vitest/Vite and related packages resolve the new yaml revision.

package.json also changes devEngines.packageManager from a single pnpm entry to an array that lists both npm and pnpm with the same version ranges already declared under engines, so installs can be enforced for either manager with onFail: "error".

Reviewed by Cursor Bugbot for commit 7b629b4. Configure here.

@socket-pr-bot socket-pr-bot Bot added automation Automated maintenance dependencies Dependency updates labels Sep 25, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​modelcontextprotocol/​client@​2.2.0 ⏵ 2.3.093 +110084 +196 +1100
Updatednpm/​typescript@​7.1.0-dev.20261001.1 ⏵ 7.1.0-dev.20261003.1100 +110089 +110090
Updatednpm/​shell-quote@​1.11.0 ⏵ 1.12.0100 +110010092100
Updatednpm/​portless@​0.15.6 ⏵ 0.15.799 +2100100 +195 -1100

View full report

@socket-security-staging

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​modelcontextprotocol/​client@​2.2.0 ⏵ 2.3.093 +110084 +197100
Updatednpm/​typescript@​7.1.0-dev.20261001.1 ⏵ 7.1.0-dev.20261003.1100 +110089 +1100100
Updatednpm/​shell-quote@​1.11.0 ⏵ 1.12.0100 +110010092100
Updatednpm/​portless@​0.15.6 ⏵ 0.15.799 +2100100 +194 -1100

View full report

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automation Automated maintenance dependencies Dependency updates

Development

Successfully merging this pull request may close these issues.

0 participants