Skip to content

chore: bump the npm-patch-minor group with 8 updates - #87

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-patch-minor-ed715577fa
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-patch-minor-ed715577fa

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-patch-minor group with 8 updates:

Package From To
@putdotio/design 3.0.0 3.4.0
@putdotio/rokit 2.4.6 2.4.7
@putdotio/vref 2.0.0 2.1.1
@rokucommunity/bslint 0.8.44 0.8.46
@types/node 26.1.2 26.6.4
brighterscript 0.73.0 0.73.5
brighterscript-formatter 1.8.1 1.8.3
oxfmt 0.70.0 0.71.0

Updates @putdotio/design from 3.0.0 to 3.4.0

Release notes

Sourced from @​putdotio/design's releases.

v3.4.0

3.4.0 (2026-10-03)

Features

  • preview: add the phone welcome screen for iOS and Android (#69) (4be2a03)

v3.3.0

3.3.0 (2026-09-05)

Features

  • apple: reconcile tier-2 SwiftUI contract (#48) (5128cbd)

v3.2.2

3.2.2 (2026-09-04)

Performance Improvements

  • gallery: defer offscreen preview browsing contexts (#52) (9ecab50)

v3.2.1

3.2.1 (2026-08-30)

Bug Fixes

  • auth: center Tier-1 card headers (#50) (dc25e33)

v3.2.0

3.2.0 (2026-08-30)

Features

  • auth: reconcile the Tier-1 design contract (#49) (eeb69f2)

v3.1.0

3.1.0 (2026-08-29)

Features

  • expand platform and form design coverage (15a3201)
Commits
  • ac31770 chore(release): 3.4.0 [skip ci]
  • 4be2a03 feat(preview): add the phone welcome screen for iOS and Android (#69)
  • c398530 docs: use the org-wide security policy (#68)
  • 28f4e03 docs: tighten the design guide and distribution notes (#63)
  • 286c5c4 docs: trim guides and link canonical sources (#62)
  • c8142ff chore: move to Node 24.21.0 (#61)
  • 40fc5a3 chore: move to pnpm 12.4.2 (#60)
  • a3413ad docs: link the foundations preview to DESIGN.md on GitHub
  • 75e4099 docs: link platform tier definitions to the public Binding Tiers section (#57)
  • a244e4e docs: drop em-dash phrasing from guides
  • Additional commits viewable in compare view

Updates @putdotio/rokit from 2.4.6 to 2.4.7

Release notes

Sourced from @​putdotio/rokit's releases.

v2.4.7

2.4.7 (2026-09-05)

Bug Fixes

  • screenshot: validate images before saving capture proof (#70) (4dae889)
Commits
  • 888b8fe chore(release): 2.4.7 [skip ci]
  • 4dae889 fix(screenshot): validate images before saving capture proof (#70)
  • e6975b2 docs: route Effect guide, add decision boundary and done criteria
  • See full diff in compare view

Updates @putdotio/vref from 2.0.0 to 2.1.1

Release notes

Sourced from @​putdotio/vref's releases.

v2.1.1

2.1.1 (2026-09-30)

Bug Fixes

  • check wildcard-bind Hosts, serve stable snapshots, and catch NFD orphans (#62) (92090a4)

v2.1.0

2.1.0 (2026-09-19)

Features

  • add manifest update and screenshot remove (#48) (5bb7c1f)
Commits
  • 18a3c49 chore(vref): release 2.1.1 [skip ci]
  • 92090a4 fix: check wildcard-bind Hosts, serve stable snapshots, and catch NFD orphans...
  • d0c3aff chore(deps): keep Vitest on the version Vite+ bundles
  • 3411322 chore: bump effect from 4.0.0-rc.115 to 4.0.0-rc.117 (#54)
  • 5bc126b chore: bump @​uinaf/skillcheck in the npm-major group across 1 directory (#60)
  • f223814 chore: bump the npm-patch-minor group across 1 directory with 4 updates (#59)
  • 31d3b8c chore(deps): upgrade Vite+ to 1.0.0 and Vitest to 5.0.1 (#58)
  • b228865 docs: point agents at describe and fix the --manifest command list (#57)
  • be74c89 docs: point to .node-version instead of restating it (#56)
  • 5999a46 chore: move to Node 24.21.0 (#55)
  • Additional commits viewable in compare view

Updates @rokucommunity/bslint from 0.8.44 to 0.8.46

Release notes

Sourced from @​rokucommunity/bslint's releases.

0.8.46

Added

  • Add sorted-imports rule (#202)

Changed

  • Security enhancements (#203)
  • upgrade to brighterscript@0.73.3. Notable changes since 0.73.1:
    • Security enhancements (#1796)
    • Better error message for wrong-cased XML tags (#1793)
    • Add isTerminal and previousInChain getters to AstNode (#1788)
    • Fix nested curly braces in template strings (#1539)
    • Recognize regex literals after ${ and , (#1789)
    • Infer node type from findAncestor type-guard matchers (#1787)
    • Reduce per-Token lexer allocation to cut GC pressure while editing (#1712)

0.8.45

Changed

  • Security enhancements (#196, #198)
  • upgrade to brighterscript@0.73.1. Notable changes since 0.72.5:
    • Report mismatched XML element pairs (#1746)
    • Add warning for function names that exceed the truncation limit (#1777)
    • Validate eval/rsg_version against firmware lifecycle (#1698)
    • Remove more prod deps: (drop array-flat-polyfill/readline, consolidate minimatch into micromatch) (#1737)

Fixed

  • fix: restrict CreateObject component usage detection (#197)
Changelog

Sourced from @​rokucommunity/bslint's changelog.

0.8.46 - 2026-09-09

Added

  • Add sorted-imports rule (#202)

Changed

  • Security enhancements (#203)
  • upgrade to brighterscript@0.73.3. Notable changes since 0.73.1:
    • Security enhancements (#1796)
    • Better error message for wrong-cased XML tags (#1793)
    • Add isTerminal and previousInChain getters to AstNode (#1788)
    • Fix nested curly braces in template strings (#1539)
    • Recognize regex literals after ${ and , (#1789)
    • Infer node type from findAncestor type-guard matchers (#1787)
    • Reduce per-Token lexer allocation to cut GC pressure while editing (#1712)

0.8.45 - 2026-09-02

Changed

  • Security enhancements (#196, #198)
  • upgrade to brighterscript@0.73.1. Notable changes since 0.72.5:
    • Report mismatched XML element pairs (#1746)
    • Add warning for function names that exceed the truncation limit (#1777)
    • Validate eval/rsg_version against firmware lifecycle (#1698)
    • Remove more prod deps: (drop array-flat-polyfill/readline, consolidate minimatch into micromatch) (#1737)

Fixed

  • fix: restrict CreateObject component usage detection (#197)
Commits

Updates @types/node from 26.1.2 to 26.6.4

Commits

Updates brighterscript from 0.73.0 to 0.73.5

Release notes

Sourced from brighterscript's releases.

0.73.5

Fixed

  • Fix crash stripping sourceMappingURL comment from non-transpiled files (#1821)

0.73.4

Changed

  • Tolerate older BrsTranspileState in continue back-transpile (#1812)
  • Security enhancements (#1804, #1805)
  • Locate the super() call when injecting field initializers (#1803)

0.73.3

Changed

  • Modifies default max worker thread logic to be only as much as memory allows (#1798)
  • Security enhancements (#1796)

0.73.2

Added

  • Add isTerminal and previousInChain getters to AstNode (#1788)
  • Add generic go-to-definition for file path strings in BRS/BS/XML files (#1648)
  • Transpile continue down for firmware below 11.5 (#489)

Changed

  • Better error message for wrong-cased XML tags (#1793)
  • Infer node type from findAncestor type-guard matchers (#1787)
  • Enable @​typescript-eslint/no-unsafe-argument (#1785)
  • Reduce per-Token lexer allocation to cut GC pressure while editing (#1712)

Fixed

  • Avoid emitting a duplicate sourceMappingURL comment (#1786)
  • Recognize regex literals after ${ and , (#1789)
  • Fix duplicate and crashing "find all references" results (#1791)
  • Fix nested curly braces in template strings (#1539)

0.73.1

Added

  • Add and completions in xml interfaces (#1748)
  • Add warning for function names that exceed the truncation limit (#1777)
  • Add SceneGraph XML element and attribute completions (#1741)
  • Report mismatched XML element pairs (#1746)

Changed

  • Security enhancements ((#1773, #1775, #1782)
  • Keep synthesized Tokens on the lexer's hidden class (#1781)
  • Cap LSP worker thread pool to fix memory scaling with project count (#1776)
  • upgrade to @​rokucommunity/logger@0.4.2. Notable changes since 0.4.0:
    • Security enhancements (#38, #39)
    • Serialize Error.cause (recursively) when logging (#33)
  • upgrade to roku-deploy@3.18.4. Notable changes since 3.17.6:
    • Migrate networking library from postman-request to needle (#282)

Fixed

  • Fix compile break against roku-deploy 3.18 (#1752)
Changelog

Sourced from brighterscript's changelog.

0.73.5 - 2026-09-15

Fixed

  • Fix crash stripping sourceMappingURL comment from non-transpiled files (#1821)

0.73.4 - 2026-09-11

Changed

  • Tolerate older BrsTranspileState in continue back-transpile (#1812)
  • Security enhancements (#1804, #1805)
  • Locate the super() call when injecting field initializers (#1803)

0.73.3 - 2026-09-09

Changed

  • Modifies default max worker thread logic to be only as much as memory allows (#1798)
  • Security enhancements (#1796)

0.73.2 - 2026-09-08

Added

  • Add isTerminal and previousInChain getters to AstNode (#1788)
  • Add generic go-to-definition for file path strings in BRS/BS/XML files (#1648)
  • Transpile continue down for firmware below 11.5 (#489)

Changed

  • Better error message for wrong-cased XML tags (#1793)
  • Infer node type from findAncestor type-guard matchers (#1787)
  • Enable @​typescript-eslint/no-unsafe-argument (#1785)
  • Reduce per-Token lexer allocation to cut GC pressure while editing (#1712)

Fixed

  • Avoid emitting a duplicate sourceMappingURL comment (#1786)
  • Recognize regex literals after ${ and , (#1789)
  • Fix duplicate and crashing "find all references" results (#1791)
  • Fix nested curly braces in template strings (#1539)

0.73.1 - 2026-09-02

Added

  • Add and completions in xml interfaces (#1748)
  • Add warning for function names that exceed the truncation limit (#1777)
  • Add SceneGraph XML element and attribute completions (#1741)
  • Report mismatched XML element pairs (#1746)

Changed

... (truncated)

Commits

Updates brighterscript-formatter from 1.8.1 to 1.8.3

Release notes

Sourced from brighterscript-formatter's releases.

1.8.3

Changed

  • Security enhancements (#157)
  • upgrade to brighterscript@0.73.3. Notable changes since 0.73.1:
    • Security enhancements (#1796)
    • Add isTerminal and previousInChain getters to AstNode (#1788)
    • Fix nested curly braces in template strings (#1539)
    • Recognize regex literals after ${ and , (#1789)
    • Reduce per-Token lexer allocation to cut GC pressure while editing (#1712)

1.8.2

Changed

Changelog

Sourced from brighterscript-formatter's changelog.

1.8.3 - 2026-09-09

Changed

  • Security enhancements (#157)
  • upgrade to brighterscript@0.73.3. Notable changes since 0.73.1:
    • Security enhancements (#1796)
    • Add isTerminal and previousInChain getters to AstNode (#1788)
    • Fix nested curly braces in template strings (#1539)
    • Recognize regex literals after ${ and , (#1789)
    • Reduce per-Token lexer allocation to cut GC pressure while editing (#1712)

1.8.2 - 2026-09-02

Changed

Commits

Updates oxfmt from 0.70.0 to 0.71.0

Release notes

Sourced from oxfmt's releases.

oxfmt v0.71.0

🚀 Features

  • e0b1f9f oxfmt: Bump bundled Prettier version to 3.9.9 (#27002) (leaysgur)
  • 342527d oxfmt: Bump bundled Prettier version to 3.9.8 (#26999) (leaysgur)

🐛 Bug Fixes

  • eeba1db formatter: Skip test-call layout when arguments have comments (#27119) (leaysgur)
  • 1f7b8ad oxfmt: Allow repeated CLI calls in the same process (#27051) (Liang)
  • 7bcb807 formatter_markdown: Keep blank line between HTML and nested list (#27112) (leaysgur)
  • 10b10c5 formatter: Keep comments around = on their side and line (#27041) (leaysgur)
  • 9aad365 formatter: Keep comments deferred before an assignment operator (#26997) (waltu)
  • 8fbddb1 formatter/jsdoc: More alignment with original plugin (#27039) (leaysgur)
  • 50be18e formatter: Keep trailing spaces on normal block comments (#27037) (leaysgur)
  • 56d1880 formatter: Nestle adjacent block comments (#27036) (leaysgur)
  • 3be5d94 formatter: Treat /*** comments as JSDoc (#27035) (leaysgur)
  • cd45f71 formatter: Keep trailing double spaces on JSDoc lines (#26861) (John Costa)
  • fd695f4 formatter_markdown: Fix more mismatches found in ecosystem-ci repos (#27003) (leaysgur)
  • 4e77d59 formatter_markdown: Keep a math span after a kept line break from opening a block (#27001) (leaysgur)
  • 584b8b0 formatter_markdown: Keep a shape line after a multi-line inline node or link title (#27000) (leaysgur)
  • b939645 formatter_markdown: Keep a line break before an inline liquid tag under preserve (#26998) (leaysgur)
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the npm-patch-minor group with 8 updates:

| Package | From | To |
| --- | --- | --- |
| [@putdotio/design](https://github.com/putdotio/putio-design) | `3.0.0` | `3.4.0` |
| [@putdotio/rokit](https://github.com/putdotio/rokit) | `2.4.6` | `2.4.7` |
| [@putdotio/vref](https://github.com/putdotio/vref) | `2.0.0` | `2.1.1` |
| [@rokucommunity/bslint](https://github.com/rokucommunity/bslint) | `0.8.44` | `0.8.46` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.2` | `26.6.4` |
| [brighterscript](https://github.com/rokucommunity/brighterscript) | `0.73.0` | `0.73.5` |
| [brighterscript-formatter](https://github.com/rokucommunity/brighterscript-formatter) | `1.8.1` | `1.8.3` |
| [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.70.0` | `0.71.0` |


Updates `@putdotio/design` from 3.0.0 to 3.4.0
- [Release notes](https://github.com/putdotio/putio-design/releases)
- [Commits](putdotio/putio-design@v3.0.0...v3.4.0)

Updates `@putdotio/rokit` from 2.4.6 to 2.4.7
- [Release notes](https://github.com/putdotio/rokit/releases)
- [Commits](putdotio/rokit@v2.4.6...v2.4.7)

Updates `@putdotio/vref` from 2.0.0 to 2.1.1
- [Release notes](https://github.com/putdotio/vref/releases)
- [Commits](putdotio/vref@v2.0.0...v2.1.1)

Updates `@rokucommunity/bslint` from 0.8.44 to 0.8.46
- [Release notes](https://github.com/rokucommunity/bslint/releases)
- [Changelog](https://github.com/rokucommunity/bslint/blob/master/CHANGELOG.md)
- [Commits](rokucommunity/bslint@v0.8.44...v0.8.46)

Updates `@types/node` from 26.1.2 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `brighterscript` from 0.73.0 to 0.73.5
- [Release notes](https://github.com/rokucommunity/brighterscript/releases)
- [Changelog](https://github.com/rokucommunity/brighterscript/blob/master/CHANGELOG.md)
- [Commits](rokucommunity/brighterscript@v0.73.0...v0.73.5)

Updates `brighterscript-formatter` from 1.8.1 to 1.8.3
- [Release notes](https://github.com/rokucommunity/brighterscript-formatter/releases)
- [Changelog](https://github.com/rokucommunity/brighterscript-formatter/blob/master/CHANGELOG.md)
- [Commits](rokucommunity/brighterscript-formatter@v1.8.1...v1.8.3)

Updates `oxfmt` from 0.70.0 to 0.71.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.71.0/npm/oxfmt)

---
updated-dependencies:
- dependency-name: "@putdotio/design"
  dependency-version: 3.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-patch-minor
- dependency-name: "@putdotio/rokit"
  dependency-version: 2.4.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-patch-minor
- dependency-name: "@putdotio/vref"
  dependency-version: 2.1.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-patch-minor
- dependency-name: "@rokucommunity/bslint"
  dependency-version: 0.8.46
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-patch-minor
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-patch-minor
- dependency-name: brighterscript
  dependency-version: 0.73.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-patch-minor
- dependency-name: brighterscript-formatter
  dependency-version: 1.8.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-patch-minor
- dependency-name: oxfmt
  dependency-version: 0.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-patch-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
@altaywtf

Copy link
Copy Markdown
Member

Superseded by Renovate.

@altaywtf altaywtf closed this Oct 10, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@altaywtf
altaywtf deleted the dependabot/npm_and_yarn/npm-patch-minor-ed715577fa branch October 10, 2026 07:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant