Skip to content

release: v1.5.2 - bump @types/node from 25.3.0 to 26.6.3 - #66

Merged
cldmv-bot[bot] merged 11 commits into
masterfrom
next
Oct 3, 2026
Merged

cldmv-bot[bot] merged 11 commits into
masterfrom
next

Conversation

@cldmv-bot

@cldmv-bot cldmv-bot Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

🚀 What's Changed

💥 Breaking Changes

No breaking changes

✨ Features

No new features

🐛 Bug Fixes

No bug fixes

📦 Dependencies

🔧 Other Changes

👥 Contributors

coverage

Metric Coverage
Statements 99.6%
Branches 100.0%
Functions 100.0%
Lines 99.6%

Avg: 99.8% · 03965dd · Node lts/*

Co-authored-by: Shinrai Shinrai@users.noreply.github.com

dependabot Bot and others added 5 commits September 30, 2026 16:54
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 25.3.0 to 26.6.3.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.6.3
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
On an in-repo feature PR, the `pull_request` run skips the
`required-check` job because the push run owns the status. A skipped job
still posts a check run under its name, and GitHub treats a skipped
required check as satisfied. The push run's mirror is only created once
`ci` finishes, so for the whole test window the only `✅ Required PR
Check` on the head SHA was the skipped one, and the PR could merge while
tests were still running.

Give the job a conditional name so the skipped path posts under a
different name and the required check stays pending until the push run
reports. Synced from CLDMV/.github#346.
…65)

## 🚀 What's Changed

### 💥 Breaking Changes
_No breaking changes_

### ✨ Features
_No new features_

### 🐛 Bug Fixes
_No bug fixes_

### 📦 Dependencies
_No dependency updates_

### 🔧 Other Changes
- ci: stop the skipped PR-run mirror from satisfying Required PR Check
(aa8b1f1)



<details>
<summary>👥 Contributors</summary>

- @Shinrai

</details>
Bumps
[@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
from 25.3.0 to 26.6.3.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@types/node&package-manager=npm_and_yarn&previous-version=25.3.0&new-version=26.6.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>
@cldmv-bot cldmv-bot Bot added ! release → master v4 flow: persistent next → master release PR (carries the next feature release) release Marks a pull request as a pending release — merge to publish a new version semver: patch This release contains only backwards-compatible bug fixes type: ci Changes to CI workflows, actions, or build pipelines type: config Changes to repository or project configuration files type: dependencies Relates to dependency updates, version bumps, or package management labels Oct 2, 2026
@cldmv-bot

cldmv-bot Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor Author

🔒 Dependency Review

  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses
  • ✅ 0 denied package(s)
  • ✅ 0 package(s) with OpenSSF Scorecard score < 3

Full job summary

@cldmv-bot

cldmv-bot Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Bundle size increased

File Raw Δ Raw Gzipped Δ Gzipped
bin/vitest-runner.mjs 31.6 kB — 11.0 kB —
dist/index.cjs 1.3 kB +456 B (+50.0%) ⚠️ 782 B +249 B
dist/index.mjs 25.7 kB — 9.1 kB —
Total 58.6 kB +456 B 20.8 kB +249 B

📊 Generated by bundle-size. Brotli sizes also measured but omitted from the table for brevity.

dependabot Bot and others added 5 commits October 2, 2026 21:41
Bumps [chalk](https://github.com/chalk/chalk) from 5.6.2 to 6.0.1.
- [Release notes](https://github.com/chalk/chalk/releases)
- [Commits](chalk/chalk@v5.6.2...v6.0.1)

---
updated-dependencies:
- dependency-name: chalk
  dependency-version: 6.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
The Required PR Check mirror job was skipped on the `pull_request` run of
an in-repo feature PR, with a conditional name keeping the skipped check
off `✅ Required PR Check`. GitHub never evaluates a skipped job's
`name:`, so every in-repo PR showed the raw expression as a check name.

The job now uses `if: always()` and never skips, so its name is always
evaluated. On the in-repo PR path it lands on
`⏭️ Required PR Check (reported by the push run)` and passes as a no-op;
the push run still posts `✅ Required PR Check`. Every path that posts
the required name keeps `needs: ci`, so that check still only exists
once the full test matrix for the SHA has finished.

Synced from CLDMV/.github#351 (CLDMV/.github#350).
@cldmv-bot cldmv-bot Bot added area: core Touches core library / runtime source code area: tests Touches test files, fixtures, or test infrastructure labels Oct 3, 2026
@cldmv-bot
cldmv-bot Bot merged commit fed1e56 into master Oct 3, 2026
46 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: core Touches core library / runtime source code area: tests Touches test files, fixtures, or test infrastructure ! release → master v4 flow: persistent next → master release PR (carries the next feature release) release Marks a pull request as a pending release — merge to publish a new version semver: patch This release contains only backwards-compatible bug fixes type: ci Changes to CI workflows, actions, or build pipelines type: config Changes to repository or project configuration files type: dependencies Relates to dependency updates, version bumps, or package management

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant