Skip to content

chore: bump @types/node from 22.20.4 to 22.20.5 - #74

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/types/node-22.20.5
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/types/node-22.20.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps @types/node from 22.20.4 to 22.20.5.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 22.20.4 to 22.20.5.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 22.20.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
@claude

claude Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Claude finished @dependabot[bot]'s task in 52s —— View job


Dependency review: @types/node 22.20.4 → 22.20.5

  • Read the PR diff
  • Check the Node floor in package.json engines
  • Verify the bump stays within the pinned major
  • Build and test — not run (see caveat below)

Verdict: safe to merge, pending green CI.

What changed

Lockfile only (package-lock.json, +3/-3): one version/resolved/integrity triple for node_modules/@types/node. package.json is untouched — the declared range stays ^22.0.0.

Semver and the Node floor

Patch bump within 22.x, so no major, and the Dependabot ignore rule for @types/node majors is intact. It also still matches the floor declared across the repo, which is consistently 22 everywhere it's mirrored:

Location Value
package.json engines.node >=22
manifest.json compatibility.runtimes.node >=22.0.0
README.md Requirements Node.js ≥ 22
ci.yml matrix low end '22'
update-catalog.yml '22'

Per CLAUDE.md, @types/node tracks the floor rather than the newest release — staying on 22.x is exactly right. DefinitelyTyped patch releases for a Node major are definition refinements only; they don't introduce APIs from a newer runtime.

Risk notes

  • Single resolved copy in the lockfile (package-lock.json:850). The other @types/node mentions (lines 2691, 2783) are optional peer ranges from the vite/vitest tree — ^20.19.0 || >=22.12.0 and ^20.0.0 || ^22.0.0 || >=24.0.0 — both satisfied by 22.20.5, so no duplicate install or peer conflict.
  • tsconfig.json has skipLibCheck: true and types: ["node"], so the only exposure is the handful of Node globals this codebase actually touches (process.env in src/config.ts, stdio transport in src/index.ts). strict: true is unchanged.
  • Worst realistic case for a DT patch is a tightened signature surfacing a new tsc error. ci.yml builds and tests on Node 22 and 24, which covers it.

Caveat

I couldn't run npm ci / npm run build / npm test locally — the install step wasn't in my allowed tools, and node_modules isn't present in this checkout. The analysis above is static. CI runs the build and the full Vitest suite on both matrix entries, so treat a green ci.yml as the verification here. (To let me verify locally on future dependency PRs, add Bash(npm ci), Bash(npm run build), and Bash(npm test) to --allowedTools.)
· branch

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants