Skip to content

refactor: Bump config from 4.4.1 to 5.0.1 - #611

Draft
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/config-5.0.1
Draft

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/config-5.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Bumps config from 4.4.1 to 5.0.1.

Release notes

Sourced from config's releases.

v5.0.1

What's Changed

  • Fix issue with async defers calls not being replaced in the config data.

New Contributors

Full Changelog: node-config/node-config@v5.0.0...v5.0.1

v5.0.0

The 5.0 release contains ESM support, removes some deprecations, strengthens some immutability constraints in a few call paths, and fixes some incorrect filename matches for files that only contain the NODE_ENV value but don't start with it.

What's Changed

New Contributors

Full Changelog: node-config/node-config@v4.4.1...v5.0.0

v5.0.0-alpha.2

What's Changed

  • fix: prevent setEnv from clobbering envConfig when merging NODE_CONFIG
  • .iced files are never loaded, and support has been removed.
  • Load.scan() now returns the configuration data that was loaded, simplifying the calling convention for setModuleDefaults()
  • TOML regression in 4.4.1 fixed in mainline

Breaking Changes

  • Scanning of the config directory no longer loads files that contain the NODE_ENV value as a substring of the file name instead of the prefix. Ex: "prod-server1.js" versus "preprod.json" for NODE_ENV=prod

New Contributors

Full Changelog: node-config/node-config@v5.0.0-alpha.1...v5.0.0-alpha.2

v5.0.0-alpha.1

What's Changed

  • Fixed TS type list in README
  • Fixed version tag issue

Full Changelog: node-config/node-config@v5.0.0-alpha.0...v5.0.0-alpha.1

... (truncated)

Commits
  • f89ef8b 5.0.1
  • 8114c25 Merge pull request #926 from MMShep97/fix-resolve-async-configs
  • 08edfa0 Merge pull request #928 from jdmarshall/workflowMain
  • 9705d75 Fix workflow for PRs.
  • 77b8752 Merge pull request #927 from jdmarshall/main
  • 1cd86a7 Remove method signature change
  • a06d897 Fix resolveAsyncConfigs leaving promises in the exported config
  • fbb28f8 Release 5.0.0
  • b4dfbd2 Merge pull request #923 from jdmarshall/supplyChain44
  • 3a4851b Merge pull request #922 from jdmarshall/supplyChain
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Bot label; pull requests that updates a dependency file javascript Pull requests that update javascript code labels Sep 23, 2026
@coderabbitai

coderabbitai Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 704de9e5-cf69-4e55-bb0d-53e19072a90c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.77%. Comparing base (d6f6d2a) to head (b5378cf).

Additional details and impacted files
@@           Coverage Diff           @@
##           master     #611   +/-   ##
=======================================
  Coverage   97.77%   97.77%           
=======================================
  Files           2        2           
  Lines         225      225           
=======================================
  Hits          220      220           
  Misses          5        5           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/config-5.0.1 branch 2 times, most recently from f796f8d to a520f91 Compare September 26, 2026 01:24
@mtrezza

mtrezza commented Sep 26, 2026

Copy link
Copy Markdown
Member

Cannot merge: config@5.0.1 requires Node >=20.19.0 but engines.node specifies >=20.18.0 <21.0.0 || >=22.12.0 <23.0.0 || >=24.11.0 <25.0.0.

config@5 declares engines.node >= 20.11.0, but since config@5.0.0 (ESM conversion, node-config/node-config#889) its CommonJS entry point lib/config.js is module.exports = require('./config.mjs').default, which needs require(esm) support. That is only available without a flag from Node 20.19.0 / 22.12.0.

config is loaded by spec/test.spec.js on every CI test job, and the Parse Server 8, Node.js 20 job (Node 20.18.0) fails with SyntaxError: Cannot use import statement outside a module when it loads config/lib/config.mjs. The same job passes on master. The newest version without this requirement is 4.4.2. Converting to draft until the minimum supported Node.js version is raised to 20.19.0.

@mtrezza
mtrezza marked this pull request as draft September 26, 2026 01:27
Bumps [config](https://github.com/node-config/node-config) from 4.4.1 to 5.0.1.
- [Release notes](https://github.com/node-config/node-config/releases)
- [Changelog](https://github.com/node-config/node-config/blob/main/History.md)
- [Commits](node-config/node-config@v4.4.1...v5.0.1)

---
updated-dependencies:
- dependency-name: config
  dependency-version: 5.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/config-5.0.1 branch from a520f91 to b5378cf Compare September 26, 2026 01:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Bot label; pull requests that updates a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant