2.5.0 Dependency Updates #293
No reviewers
Labels
No labels
blocked
duplicate
needs
approval
needs
criteria
needs
estimate
needs
tests
question
step
doing
step
review
step
testing
step
todo
step
uat
type
admin
type
alert
type
bug
type
change
type
defect
type
dependencies
type
epic
type
idea
type
incident
type
investigation
type
spike
type
story
won't fix
No milestone
No project
No assignees
2 participants
Due date
No due date set.
Dependencies
No dependencies set
Reference
RabbitLabs/random-bunny!293
Loading…
Reference in a new issue
No description provided.
Delete branch "feature/268-2-5-0-dependencies"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
#268
WIP: 2.5.0 Dependency Updatesto 2.5.0 Dependency UpdatesApproved — the 2.5.0 dependency audit looks good to merge.
Summary: Within-range bumps across runtime and dev deps (commander, htmlparser2, eslint/typescript-eslint stack, jest, typescript, @yao-pkg/pkg, etc.) with an expanded
resolutionstable pinning transitive packages with known advisories (lodash, tar/tmp, minimatch, ajv, glob, js-yaml, and others). CI workflows consistently move from Node 20.x to 22.x, matching the pipeline fix noted on #268.What looks good:
Non-blocking: Consider adding an
engines.nodefield inpackage.jsonif you want local dev environments to match the Node 22 CI target.Closes review for #268.
New commits pushed, approval review dismissed automatically according to repository settings
Approved — follow-up re-review at HEAD
6cd6668.The new commit adds
"engines": { "node": ">=22 && <=24" }topackage.json, which addresses the non-blocking suggestion from my prior review and aligns local dev expectations with the Node 22 CI workflows. No other changes since approval.Summary: The 2.5.0 dependency audit remains solid — within-range bumps, expanded
resolutionspins for transitive advisories, lockfile regeneration, and CI on Node 22. The dependency-audit Cursor skill and overview doc are a nice addition for future releases.Looks good to merge.