Skip to content

release: v1.1.2 - bump the patch group across 1 directory with 2 updates - #48

Merged
cldmv-bot[bot] merged 13 commits into
masterfrom
next
Oct 2, 2026
Merged

cldmv-bot[bot] merged 13 commits into
masterfrom
next

Conversation

@cldmv-bot

@cldmv-bot cldmv-bot Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

🚀 What's Changed

💥 Breaking Changes

No breaking changes

✨ Features

No new features

🐛 Bug Fixes

No bug fixes

📦 Dependencies

🔧 Other Changes

👥 Contributors

coverage

Metric Coverage
Statements 100.0%
Branches 100.0%
Functions 100.0%
Lines 100.0%

Avg: 100.0% · d57c1fd · Node lts/*

Co-authored-by: Shinrai Shinrai@users.noreply.github.com

dependabot Bot and others added 12 commits September 28, 2026 20:08
Bumps the patch group with 2 updates in the / directory: [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) and [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest).


Updates `@vitest/coverage-v8` from 5.0.1 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/coverage-v8)

Updates `vitest` from 5.0.1 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/vitest)

---
updated-dependencies:
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch
- dependency-name: vitest
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch
...

Signed-off-by: dependabot[bot] <support@github.com>
On an in-repo feature PR, the `pull_request` run skips the
`required-check` job because the push run owns the status. A skipped job
still posts a check run under its name, and GitHub treats a skipped
required check as satisfied. The push run's mirror is only created once
`ci` finishes, so for the whole test window the only `✅ Required PR
Check` on the head SHA was the skipped one, and the PR could merge while
tests were still running.

Give the job a conditional name so the skipped path posts under a
different name and the required check stays pending until the push run
reports. Synced from CLDMV/.github#346.
…45)

## 🚀 What's Changed

### 💥 Breaking Changes
_No breaking changes_

### ✨ Features
_No new features_

### 🐛 Bug Fixes
_No bug fixes_

### 📦 Dependencies
_No dependency updates_

### 🔧 Other Changes
- ci: stop the skipped PR-run mirror from satisfying Required PR Check
(9f50a18)



<details>
<summary>👥 Contributors</summary>

- @Shinrai

</details>
…le headers (#44)

## 🚀 What's Changed

### 💥 Breaking Changes
_No breaking changes_

### ✨ Features
_No new features_

### 🐛 Bug Fixes
_No bug fixes_

### 📦 Dependencies
_No dependency updates_

### 🔧 Other Changes
- chore: adopt the shared CLDMV fix-headers config and stamp uniform
file headers (eb97633)



<details>
<summary>👥 Contributors</summary>

- @Shinrai

</details>
Bumps the patch group with 2 updates: [@cldmv/eslint-plugin-jsonv](https://github.com/CLDMV/jsonv-eslint-plugin-jsonv) and [@cldmv/jsonv](https://github.com/CLDMV/jsonv).


Updates `@cldmv/eslint-plugin-jsonv` from 1.0.12 to 1.0.13
- [Release notes](https://github.com/CLDMV/jsonv-eslint-plugin-jsonv/releases)
- [Commits](CLDMV/jsonv-eslint-plugin-jsonv@v1.0.12...v1.0.13)

Updates `@cldmv/jsonv` from 1.1.0 to 1.1.1
- [Release notes](https://github.com/CLDMV/jsonv/releases)
- [Changelog](https://github.com/CLDMV/jsonv/blob/master/CHANGELOG.md)
- [Commits](CLDMV/jsonv@v1.1...v1.1.1)

---
updated-dependencies:
- dependency-name: "@cldmv/eslint-plugin-jsonv"
  dependency-version: 1.0.13
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch
- dependency-name: "@cldmv/jsonv"
  dependency-version: 1.1.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps the minor group with 1 update: [@cldmv/vitest-runner](https://github.com/CLDMV/vitest-runner).


Updates `@cldmv/vitest-runner` from 1.2.0 to 1.5.1
- [Release notes](https://github.com/CLDMV/vitest-runner/releases)
- [Commits](CLDMV/vitest-runner@v1.2.0...v1.5.1)

---
updated-dependencies:
- dependency-name: "@cldmv/vitest-runner"
  dependency-version: 1.5.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps the patch group with 2 updates:
[@cldmv/eslint-plugin-jsonv](https://github.com/CLDMV/jsonv-eslint-plugin-jsonv)
and [@cldmv/jsonv](https://github.com/CLDMV/jsonv).

Updates `@cldmv/eslint-plugin-jsonv` from 1.0.12 to 1.0.13
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/CLDMV/jsonv-eslint-plugin-jsonv/releases">@​cldmv/eslint-plugin-jsonv's
releases</a>.</em></p>
<blockquote>
<h2>v1.0.13</h2>
<p>release: v1.0.13 - publish real types for the plugin, language and
AST</p>
<h1><code>@​cldmv/eslint-plugin-jsonv</code> v1.0.13 Changelog</h1>
<p><strong>Release Date</strong>: September 2026
<strong>Release Type</strong>: Patch
<strong>Branch</strong>: <code>release/1.0.13</code></p>
<hr />
<h2>Overview</h2>
<p>Version 1.0.13 makes the plugin's published types real.
<code>dist/index.d.mts</code> used to declare the default export as a
bare <code>Object</code>; it now types the plugin, the
<code>jsonv/jsonv</code> language, <code>JsonvSourceCode</code>, and
every AST node against <code>@eslint/core</code>'s generics, and the
JSDoc that generates those declarations is now type-checked in CI. The
release also closes a gap the new types surfaced:
<code>engines.node</code> and a missing <code>eslint</code> peer range
now match what the plugin's runtime dependencies actually require.
Alongside that, the plugin accepts three more <code>@cldmv/jsonv</code>
language options, and the repository adopts the CLDMV lint/format
tooling.</p>
<p>No configuration changes are required to pick this up — existing
<code>eslint.config.mjs</code> files, rules, and
<code>languageOptions</code> keep working unchanged.</p>
<hr />
<h2>🐛 Bug Fixes</h2>
<h3>Published types describe a real ESLint plugin (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/30">#30</a>,
fixes <a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/28">#28</a>)</h3>
<p><code>dist/index.d.mts</code> declared <code>const plugin:
Object</code>, so a TypeScript (or <code>// @ts-check</code>) config got
no type for <code>plugin.configs.recommended</code>,
<code>plugin.languages.jsonv</code>, or <code>languageOptions</code>,
and nothing for a rule author to use for the AST node types the language
exposes. The JSDoc in <code>index.mjs</code> is now typed against
<code>@eslint/core</code>'s <code>Language</code>,
<code>TextSourceCode</code>, <code>OkParseResult</code>, and
<code>Plugin</code> generics, the way <code>@eslint/json</code> types
its JSON language, and <code>tsconfig.types.json</code> now type-checks
it (<code>checkJs: true</code>) instead of only emitting from it. The
package exports typedefs for every AST node (<code>JsonvProgram</code>,
<code>JsonvObjectExpression</code>, <code>JsonvProperty</code>,
<code>JsonvLiteral</code>, <code>JsonvIdentifier</code>,
<code>JsonvMemberExpression</code>, <code>JsonvTemplateLiteral</code>,
<code>JsonvTemplateElement</code>), for
<code>JsonvLanguageOptions</code>, and for a rule's visitor
(<code>JsonvRuleDefinition</code>, <code>JsonvRuleVisitor</code>), plus
the <code>JsonvSourceCode</code> class itself, and
<code>JsonvSourceCode</code> is now a named export alongside the default
plugin. A new <code>test:types</code> script compiles a type-level
consumer test against the built declarations the way an
<code>eslint.config.mts</code> would, and <code>build:ci</code> runs
it.</p>
<h3>The declared Node floor and ESLint range match what the plugin needs
(<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/37">#37</a>,
fixes <a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/32">#32</a>)</h3>
<p><code>engines.node</code> still said <code>&gt;=18.0.0</code>, but
the runtime dependencies added for real types —
<code>@eslint/core</code> and <code>@eslint/plugin-kit</code> — both
require <code>^20.19.0 || ^22.13.0 || &gt;=24</code>, and so does ESLint
10 itself. Installing on Node 18 could fail or warn while
<code>engines</code> claimed support. <code>engines.node</code> now
states that real floor, and a new <code>eslint</code> peer dependency
(<code>^9.13.0 || ^10.0.0</code>) tells consumers which ESLint versions
the plugin's <code>languages</code> API needs — <code>^9.13.0</code> is
the first release with <code>defaultLanguageOptions</code> support for
plugin languages.</p>
<h3><code>mode</code>, <code>strictOctal</code>, and
<code>allowInternalReferences</code> language options (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/39">#39</a>,
fixes <a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/34">#34</a>)</h3>
<p>The README documented a <code>mode</code> option, and the plugin
rejected it (<code>Unknown language option &quot;mode&quot;</code>)
because it was never actually forwarded to the parser. <code>mode</code>
(<code>&quot;jsonv&quot;</code>, <code>&quot;json5&quot;</code>, or
<code>&quot;json&quot;</code>, default <code>&quot;jsonv&quot;</code>),
<code>strictOctal</code> (boolean, default <code>false</code>), and
<code>allowInternalReferences</code> (boolean, default
<code>true</code>) are now accepted, validated, and passed through to
both <code>parseWithOptions()</code> and <code>parseToAst()</code>,
matching <code>@cldmv/jsonv</code>'s own <code>ParseOptions</code>.
<code>reviver</code>, <code>preserveComments</code>, and
<code>tolerant</code> stay unsupported, and
<code>validateLanguageOptions</code> now names the reason when one of
those three is set instead of reporting it as merely unknown. The
README's <strong>Configuration Options</strong> table documents all five
options with their defaults, and a new test extracts the README's own
<code>languageOptions</code> examples and runs them through
<code>validateLanguageOptions</code> and a live <code>Linter</code>, so
the docs and the code can't drift apart again.</p>
<h2>🔧 CI &amp; tooling</h2>
<ul>
<li>The CLDMV eslint + prettier config, <code>lint</code> /
<code>lint:fix</code> / <code>format</code> / <code>format:check</code>
scripts, and the <code>.githooks</code> pre-commit hook are added, and
the existing sources and README are reformatted repo-wide (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/38">#38</a>,
fixes <a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/33">#33</a>).</li>
<li><code>release-merge</code> is re-armed on every check-producing
workflow, instead of only the ones that existed when it was first wired
(<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/40">#40</a>).</li>
<li>The v4 workflows are synced with the <code>CLDMV/.github</code>
v4.29.2 templates (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/42">#42</a>).</li>
<li>The bundle-size workflow is added, and the
<code>release-merge</code> required-workflow list is restored to the
full set (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/43">#43</a>).</li>
</ul>
<h2>📚 Documentation</h2>
<ul>
<li><strong>NEW:</strong> <a
href="https://github.com/CLDMV/jsonv-eslint-plugin-jsonv/blob/HEAD/v1.0.13.md">docs/changelog/v1/v1.0.13.md</a>
— this changelog.</li>
<li>README <strong>Installation</strong> now states the Node and ESLint
requirements (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/37">#37</a>).</li>
<li>README <strong>Configuration Options</strong> documents
<code>mode</code>, <code>strictOctal</code>, and
<code>allowInternalReferences</code> alongside <code>year</code> and
<code>strictBigInt</code> (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/39">#39</a>).</li>
</ul>
<h2>🔧 Dependencies</h2>
<ul>
<li><strong>NEW</strong> runtime dependency: <code>@eslint/core</code>
<code>^1.2.1</code>, which provides the <code>Language</code>,
<code>TextSourceCode</code>, and <code>Plugin</code> types the published
declarations are built against (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/30">#30</a>).</li>
<li><strong>NEW</strong> dev dependency: <code>@types/node</code>
<code>^26.6.3</code>, needed by the type-checked JSDoc (<a
href="https://redirect.github.com/CLDMV/jsonv-eslint-plugin-jsonv/issues/30">#30</a>).</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/CLDMV/jsonv-eslint-plugin-jsonv/commit/2ce4e13d4b9ffeb4e0d86388f0b00604bed56672"><code>2ce4e13</code></a>
release: v1.0.13 - publish real types for the plugin, language and
AST</li>
<li>See full diff in <a
href="https://github.com/CLDMV/jsonv-eslint-plugin-jsonv/compare/v1.0.12...v1.0.13">compare
view</a></li>
</ul>
</details>
<details>
<summary>Install script changes</summary>
<p>This version adds <code>prepare</code> script that runs during
installation. Review the package contents before updating.</p>
</details>
<br />

Updates `@cldmv/jsonv` from 1.1.0 to 1.1.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/CLDMV/jsonv/releases">@​cldmv/jsonv's
releases</a>.</em></p>
<blockquote>
<h2>v1.1.1</h2>
<p>release: v1.1.1 - include the closing } in template middle/tail
tokens…</p>
<h1><code>@​cldmv/jsonv</code> v1.1.1 Changelog</h1>
<p><strong>Release Date</strong>: September 2026
<strong>Release Type</strong>: Patch
<strong>Branch</strong>: <code>release/1.1.1</code></p>
<hr />
<h2>Overview</h2>
<p>Version 1.1.1 is a correctness patch on top of v1.1.0's AST/token
work. Exercising the new <code>parseToAst()</code> output and the
<code>tolerant</code> option surfaced nine bugs across parse-mode
enforcement, tolerant-mode error reporting, reference resolution, and
template-literal lexing — all fixed here, each with regression tests.
Three ESLint tooling dependencies are also bumped, and CI's
release-merge gate is re-armed against every check-producing
workflow.</p>
<p>No public API changes. All v1.1.0 configuration and usage is fully
compatible.</p>
<hr />
<h2>🐛 Bug Fixes</h2>
<h3><code>mode: &quot;json&quot;</code> and <code>mode:
&quot;json5&quot;</code> now enforce their feature sets (<a
href="https://redirect.github.com/CLDMV/jsonv/issues/65">#65</a>)</h3>
<p><code>ParseOptions.mode</code> was documented to restrict
<code>&quot;json&quot;</code> to RFC 8259 JSON and
<code>&quot;json5&quot;</code> to JSON5 1.0, but only the comment check
was ever wired up — both modes silently accepted the full set of jsonv
extensions (unquoted keys, single quotes, trailing commas, hex,
<code>Infinity</code>/<code>NaN</code>, and, in
<code>&quot;json5&quot;</code>, even internal references and templates).
Both modes now reject every feature outside their spec with a positioned
<code>JsonvSyntaxError</code> naming the feature and the mode, covering
every year entry point and <code>parseToAst()</code>. Fixes <a
href="https://redirect.github.com/CLDMV/jsonv/issues/52">#52</a>.</p>
<h3>Tolerant mode reports collected syntax errors instead of a
misleading reference error (<a
href="https://redirect.github.com/CLDMV/jsonv/issues/64">#64</a>)</h3>
<p>With <code>tolerant: true</code>, <code>parseWithOptions</code>
collected syntax errors and then evaluated the partial result anyway, so
a document with real syntax errors surfaced an unrelated
<code>JsonvReferenceError</code> (&quot;Unresolved reference: b&quot;)
instead of the errors that were actually collected. When any syntax
errors are collected, <code>parseWithOptions</code> now throws a single
<code>JsonvAggregateSyntaxError</code> — its own
<code>line</code>/<code>column</code>/<code>offset</code>/<code>code</code>
are the first error's, its message summarizes the first error plus the
total count, and <code>errors</code> holds every collected error in
source order. The document is not evaluated. Fixes <a
href="https://redirect.github.com/CLDMV/jsonv/issues/59">#59</a>.</p>
<h3>Forward-reference chains of any length now resolve (<a
href="https://redirect.github.com/CLDMV/jsonv/issues/66">#66</a>)</h3>
<p>Internal references resolved in a fixed number of passes, so an
acyclic forward-reference chain longer than the pass limit (five or more
keys) failed with a spurious &quot;Unresolved reference&quot; error even
though nothing was circular. References now resolve by dependency order
— recursively resolving a reference as soon as its target has a concrete
value — instead of a fixed pass count, so chains of any depth, through
member expressions and templates, resolve correctly. True cycles and
self-references still throw, pointing at the reference that closes the
cycle. Fixes <a
href="https://redirect.github.com/CLDMV/jsonv/issues/54">#54</a>.</p>
<h3><code>parseToAst</code> collects lexer errors instead of throwing
(<a
href="https://redirect.github.com/CLDMV/jsonv/issues/62">#62</a>)</h3>
<p><code>parseToAst()</code> returns <code>{ program, comments, tokens,
errors }</code> and collected parser errors in <code>errors</code>, but
lexer errors (unterminated templates/strings, invalid escapes,
year-gated literals) were thrown instead — forcing callers to handle two
separate error paths, and hiding every other error in
<code>tolerant</code> mode behind the first lexical failure. Lexer
errors are now collected into <code>errors</code> alongside parser
errors, with the tokens lexed up to the error and a partial program
returned. Fixes <a
href="https://redirect.github.com/CLDMV/jsonv/issues/51">#51</a>.</p>
<h3>Template interpolations balance braces; object/array literals inside
<code>${}</code> are rejected clearly (<a
href="https://redirect.github.com/CLDMV/jsonv/issues/57">#57</a>)</h3>
<p>While inside a template interpolation, the lexer treated the
<em>first</em> <code>}</code> as the end of the interpolation, so an
interpolated expression containing its own braces — an object literal,
for example — broke parsing with a misleading &quot;Expected ',' or
'}'&quot; error pointing at the wrong brace. The lexer now tracks brace
depth per interpolation the way a JS lexer tracks a stack of
template/brace contexts, so only the balancing <code>}</code> ends the
interpolation; an object or array literal directly inside
<code>${}</code> is then explicitly rejected with a clear, correctly
positioned error instead of a confusing one. Fixes <a
href="https://redirect.github.com/CLDMV/jsonv/issues/50">#50</a>.</p>
<h3>Nested templates inside an interpolation now evaluate (<a
href="https://redirect.github.com/CLDMV/jsonv/issues/53">#53</a>)</h3>
<p>A template literal nested inside another template's interpolation
(<code>`a${ `b${a}c` }d`</code>) parsed with correct tokens and spans
but threw <code>JsonvReferenceError: Unresolved reference:
\&lt;template&gt;</code> on evaluation — reference resolution treated
the inner <code>TemplateLiteral</code> node as a named reference instead
of evaluating it. Nested templates now evaluate like any other
interpolated expression, at any nesting depth, including when
referencing another key or appearing inside a forward reference. Fixes
<a href="https://redirect.github.com/CLDMV/jsonv/issues/49">#49</a>.</p>
<h3>Template middle/tail tokens and quasis now include the closing
<code>}</code> (<a
href="https://redirect.github.com/CLDMV/jsonv/issues/48">#48</a>)</h3>
<p>In <code>parseToAst()</code> output, the <code>TemplateHead</code>
token and its quasi included the opening <code>${</code>, but the
<code>}</code> that closes an interpolation belonged to no token and no
quasi — so the following
<code>TemplateMiddle</code>/<code>TemplateTail</code> segment started
one character too late, leaving a one-character gap in the token stream.
Tokens now tile the template source with no gaps, matching
ESTree/Babel/Espree conventions: a tail/middle token and its quasi start
at the closing <code>}</code>. This shifts
<code>@cldmv/eslint-plugin-jsonv</code>'s <code>TemplateElement</code>
ranges by one character; that plugin should be re-checked against this
release. Fixes <a
href="https://redirect.github.com/CLDMV/jsonv/issues/47">#47</a>.</p>
<h3>CR and CRLF in template literals normalize to LF (<a
href="https://redirect.github.com/CLDMV/jsonv/issues/56">#56</a>)</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/CLDMV/jsonv/compare/v1.1...v1.1.1">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>
@cldmv-bot cldmv-bot Bot added ! release → master v4 flow: persistent next → master release PR (carries the next feature release) release Marks a pull request as a pending release — merge to publish a new version semver: patch This release contains only backwards-compatible bug fixes type: dependencies Relates to dependency updates, version bumps, or package management labels Oct 2, 2026
@cldmv-bot

cldmv-bot Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor Author

🔒 Dependency Review

  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses
  • ✅ 0 denied package(s)
  • ✅ 0 package(s) with OpenSSF Scorecard score < 3

Full job summary

@cldmv-bot

cldmv-bot Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

📦 Bundle size unchanged

File Raw Δ Raw Gzipped Δ Gzipped
dist/index.mjs 6.1 kB — 2.2 kB —
types/dist/index.d.mts 5.0 kB — 1.4 kB —
types/dist/index.d.mts.map 1.1 kB — 467 B —
Total 12.3 kB ±0 B 4.1 kB ±0 B

📊 Generated by bundle-size. Brotli sizes also measured but omitted from the table for brevity.

#47)

Bumps the minor group with 1 update:
[@cldmv/vitest-runner](https://github.com/CLDMV/vitest-runner).

Updates `@cldmv/vitest-runner` from 1.2.0 to 1.5.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/CLDMV/vitest-runner/releases">@​cldmv/vitest-runner's
releases</a>.</em></p>
<blockquote>
<h2>v1.5.1</h2>
<p>release: v1.5.1 - backfill the missing v1.5.0 changelog</p>
<h1>vitest-runner v1.5.1 Changelog</h1>
<p><strong>Release Date</strong>: September 2026
<strong>Release Type</strong>: Patch
<strong>Branch</strong>: <code>release/1.5.1</code></p>
<hr />
<h2>Overview</h2>
<p>A documentation-only release: v1.5.0 shipped through the automated
release-merge gate before its changelog and README <code>What's
New</code> update had landed on <code>next</code>, so it released with
the raw auto-generated PR-title dump instead of curated notes. This
backfills v1.5.0's changelog and promotes the README. No code
changes.</p>
<hr />
<h2>📚 Documentation</h2>
<h3>Backfilled the missing v1.5.0 changelog</h3>
<p><a
href="https://github.com/CLDMV/vitest-runner/blob/HEAD/v1.5.0.md"><code>docs/changelog/v1/v1.5.0.md</code></a>
— the curated release notes for the <code>exclude</code> option (<a
href="https://redirect.github.com/CLDMV/vitest-runner/issues/57">#57</a>,
<a
href="https://redirect.github.com/CLDMV/vitest-runner/issues/58">#58</a>)
that v1.5.0 shipped without. The README <code>✨ What's New</code> block
is promoted to match.</p>
<hr />
<h2>Upgrade notes</h2>
<p>No breaking changes — drop-in for v1.5.0. No runtime code
changed.</p>
<hr />
<!-- raw HTML omitted -->
<p><img
src="https://img.shields.io/badge/coverage-99.8%25-brightgreen?style=for-the-badge&amp;logo=vitest&amp;logoColor=white"
alt="coverage" /></p>
<table>
<thead>
<tr>
<th>Metric</th>
<th>Coverage</th>
</tr>
</thead>
<tbody>
<tr>
<td>Statements</td>
<td>99.6%</td>
</tr>
<tr>
<td>Branches</td>
<td>100.0%</td>
</tr>
<tr>
<td>Functions</td>
<td>100.0%</td>
</tr>
<tr>
<td>Lines</td>
<td>99.6%</td>
</tr>
</tbody>
</table>
<p><em>Avg: <strong>99.8%</strong> · <code>d915e7d</code> · Node
lts/</em>*</p>
<!-- raw HTML omitted -->
<!-- raw HTML omitted -->
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/CLDMV/vitest-runner/commit/7aedb329940cb04cfc3556c8f76933b537fba9b1"><code>7aedb32</code></a>
release: v1.5.1 - backfill the missing v1.5.0 changelog</li>
<li><a
href="https://github.com/CLDMV/vitest-runner/commit/9e0f31c874d52b275609b9553a285e137e2e9231"><code>9e0f31c</code></a>
release: v1.5.0 - add an exclude option for test discovery</li>
<li><a
href="https://github.com/CLDMV/vitest-runner/commit/1241f7f114fe84a95e96f9b244cec2ad1f26d1ea"><code>1241f7f</code></a>
release: v1.4.4 - drop the tsup-availability guard in prepack (<a
href="https://redirect.github.com/CLDMV/vitest-runner/issues/41">#41</a>)</li>
<li><a
href="https://github.com/CLDMV/vitest-runner/commit/fade67fac72309674ff9a7767eb3df8b8c5c2056"><code>fade67f</code></a>
release: v1.4.3 - enable minification for the tsup build</li>
<li><a
href="https://github.com/CLDMV/vitest-runner/commit/0685350706a08efdb0fbfc9ffd51ca25fceb4a25"><code>0685350</code></a>
release: v1.4.2 - add missing repository/bugs/homepage fields to…</li>
<li><a
href="https://github.com/CLDMV/vitest-runner/commit/ee919b60c3892fa4c1442e9f5e9904b1c5896891"><code>ee919b6</code></a>
release: v1.4.1 - README npm badges reference the unscoped package
name</li>
<li><a
href="https://github.com/CLDMV/vitest-runner/commit/57542fe3dee92ca3d79040bcfc4be457f3bf8783"><code>57542fe</code></a>
release: v1.4.0 - bundle a real dist/ build with tsup, generate the CJS…
(<a
href="https://redirect.github.com/CLDMV/vitest-runner/issues/22">#22</a>)</li>
<li><a
href="https://github.com/CLDMV/vitest-runner/commit/cf7dcbdfd307c0c20118d4128f3ddbd90c4bb4f2"><code>cf7dcbd</code></a>
release: v1.3.3 - bump the npm_and_yarn group across 1 directory with 2…
(<a
href="https://redirect.github.com/CLDMV/vitest-runner/issues/19">#19</a>)</li>
<li><a
href="https://github.com/CLDMV/vitest-runner/commit/bf402bd9094c0a530fddb9f8fa19a5c9fff707f6"><code>bf402bd</code></a>
build(deps-dev): bump the npm_and_yarn group across 1 directory with 2
update...</li>
<li><a
href="https://github.com/CLDMV/vitest-runner/commit/c36611fca40c30335973bb0aaad37b76d70829fe"><code>c36611f</code></a>
Merge branch 'hotfixes' into hotfix-redirect/pr-8</li>
<li>Additional commits viewable in <a
href="https://github.com/CLDMV/vitest-runner/compare/v1.2.0...v1.5.1">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for <code>@​cldmv/vitest-runner</code> since your current
version.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@cldmv/vitest-runner&package-manager=npm_and_yarn&previous-version=1.2.0&new-version=1.5.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>
@cldmv-bot
cldmv-bot Bot merged commit 56b0087 into master Oct 2, 2026
46 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

! release → master v4 flow: persistent next → master release PR (carries the next feature release) release Marks a pull request as a pending release — merge to publish a new version semver: patch This release contains only backwards-compatible bug fixes type: dependencies Relates to dependency updates, version bumps, or package management

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant