Skip to content

deps: bump globals from 17.12.0 to 17.13.0 in the minor group - #19

Merged
cldmv-bot[bot] merged 1 commit into
nextfrom
dependabot/npm_and_yarn/next/minor-a35d97b24e
Oct 4, 2026
Merged

cldmv-bot[bot] merged 1 commit into
nextfrom
dependabot/npm_and_yarn/next/minor-a35d97b24e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown

Bumps the minor group with 1 update: globals.

Updates globals from 17.12.0 to 17.13.0

Release notes

Sourced from globals's releases.

v17.13.0

  • Update globals (2026-10-01) (#354) b007369

sindresorhus/globals@v17.12.0...v17.13.0

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor group with 1 update: [globals](https://github.com/sindresorhus/globals).


Updates `globals` from 17.12.0 to 17.13.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.12.0...v17.13.0)

---
updated-dependencies:
- dependency-name: globals
  dependency-version: 17.13.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 4, 2026

@cldmv-bot cldmv-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved by CLDMV-bot: minor bump from 17.12.0 to 17.13.0.

@cldmv-bot
cldmv-bot Bot enabled auto-merge October 4, 2026 06:35
@cldmv-bot cldmv-bot Bot added the type: dependencies Relates to dependency updates, version bumps, or package management label Oct 4, 2026
@cldmv-bot
cldmv-bot Bot merged commit 335fbc2 into next Oct 4, 2026
30 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/next/minor-a35d97b24e branch October 4, 2026 06:36
cldmv-bot Bot added a commit that referenced this pull request Oct 4, 2026
# @cldmv/configs v1.2.4 Changelog

**Release Date**: October 2026
**Release Type**: Patch
**Branch**: `release/1.2.4`

---

## Overview

The shared `fix-headers.json` stops forcing `@Last modified by`. Until now every fix-headers run in an extending repository stamped whoever ran it as the last modifier of every file it touched, even when the only change was a header rewrite such as a new date format. With `forceLastModifiedAuthorUpdate` set to `false` and fix-headers 2.2.0, `@Last modified by` now records the last person who actually edited a file's content, while `@Last modified time` still moves whenever fix-headers rewrites a header.

Together with `forceAuthorUpdate: false`, which shipped in v1.2.3, the shared config no longer rewrites anyone's authorship: `@Author` keeps the file's creator, and `@Last modified by` follows real edits. Extending repositories should upgrade to `@cldmv/fix-headers` 2.2.0 or later alongside this release.

---

## 🐛 Bug Fixes

### `@Last modified by` follows real edits ([#20](#20))

`forceLastModifiedAuthorUpdate` was `true`, so every run rewrote `@Last modified by` to the identity running fix-headers (the name on their signing key, or `git config user.name` without one) on every file it changed. A contributor who ran `npm run fix:headers` therefore became the last modifier of every restamped file, even files they never opened ([#15](#15)).

The option is now `false`. From fix-headers 2.2.0 ([CLDMV/fix-headers#128](CLDMV/fix-headers#128)) the field changes only when a file's content, everything outside the header, differs from the last commit, or when the file is new:

| What changed in a file                                              | `@Last modified time` | `@Last modified by`            | `@Author` |
| ------------------------------------------------------------------- | --------------------- | ------------------------------ | --------- |
| Nothing                                                             | unchanged             | unchanged                      | unchanged |
| Only the header (date format, epoch, `@Date`, spacing, filename, …) | updated               | unchanged                      | unchanged |
| Content edited, or a new file                                       | updated               | the person running fix-headers | unchanged |

On fix-headers releases before 2.2.0 the same setting keeps the existing `@Last modified by` on every run, real edits included, so the upgrade matters.

## 🔧 Dependencies

- `@cldmv/fix-headers` `^2.1.4` → `^2.2.0` ([#20](#20)), dev-only. The repository's own header pass ran under 2.2.0 and changed no files.
- `vitest` and `@vitest/coverage-v8` `^5.0.2` → `^5.0.3`, and `globals` `^17.12.0` → `^17.13.0` ([#21](#21)), dev-only. The coverage and globals bumps first merged as [#18](#18) and [#19](#19), two minutes after the v1.2.3 release, and were lost when `next` was reset after that release ([CLDMV/.github#360](CLDMV/.github#360)). #21 re-applies them, together with the vitest bump from [#17](#17).

## 📚 Documentation

- **NEW:** [docs/changelog/v1/v1.2.4.md](./v1.2.4.md) — this changelog.
- README: the `fix-headers.json` table and notes explain both author settings, and the requirements now name fix-headers 2.2.0 as the version the author rules need.
- [v1.2.3](./v1.2.3.md) changelog corrected: that release also shipped `forceAuthorUpdate: false`, which its notes left out.

---

## Upgrade notes

- **Upgrade `@cldmv/fix-headers` to 2.2.0 or later** in every repository that extends this config. On older fix-headers, `@Last modified by` would no longer update even when a file is edited.
- The first fix-headers run after upgrading leaves existing `@Last modified by` values alone and only changes them on files whose content was edited since the last commit. No repository-wide restamp of authors.



<details>
<summary>👥 Contributors</summary>

- @Shinrai

</details>

---

<!-- coverage-start -->

![coverage](https://img.shields.io/badge/coverage-100.0%25-brightgreen?style=for-the-badge&logo=vitest&logoColor=white)

| Metric | Coverage |
|--------|----------|
| Statements | 100.0% |
| Branches   | 100.0% |
| Functions  | 100.0% |
| Lines      | 100.0% |

*Avg: **100.0%** · `117287f` · Node lts/**

<!-- coverage-end -->

<!-- co-authors -->

Co-authored-by: Shinrai <Shinrai@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code type: dependencies Relates to dependency updates, version bumps, or package management

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants