Skip to content

build(deps-dev): bump the contract-tooling group across 1 directory with 4 updates - #4

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/contract-tooling-2502b2d398
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/contract-tooling-2502b2d398

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 3, 2026 •

Copy link
Copy Markdown

Bumps the contract-tooling group with 4 updates in the / directory: @redocly/cli, ajv, prettier and yaml.

Updates @redocly/cli from 2.2.1 to 2.54.2

Release notes

Sourced from @​redocly/cli's releases.

@​redocly/cli@​2.54.2

Patch Changes

  • Updated @​redocly/openapi-core to v2.54.2.
  • Updated @​redocly/reunite-integration to v2.54.2.

@​redocly/cli@​2.53.3

Patch Changes

  • Fixed respect so a same-workflow goto no longer cleared $steps outputs from steps that already ran. Previously, this broke $steps expressions in the target step.
  • Updated @​redocly/respect-core to v2.53.3.

@​redocly/cli@​2.53.2

Patch Changes

  • Added start and end line and column positions to each problem location in the --format=json lint output.
  • Updated @​redocly/openapi-core to v2.53.2.

@​redocly/cli@​2.53.1

Patch Changes

  • Added a deprecation warning to the build-docs command about the upcoming switch to Redoc 3.

@​redocly/cli@​2.53.0

Minor Changes

  • Added a disallowDefault option to the operation-2xx-response rule, which requires an explicit 2xx response when enabled. There is no change in current behavior.

Patch Changes

  • Updated @​redocly/openapi-core to v2.53.0.

@​redocly/cli@​2.52.1

Patch Changes

  • Updated redoc to the 2.5.4 version to fix accessibility problems in the HTML produced by build-docs. Added the lang attribute to the default build-docs template.

@​redocly/cli@​2.52.0

Minor Changes

  • Added agent skills for AI coding assistants: redocly-cli for everyday CLI usage, redocly-lint-rules for writing configurable rules and custom plugins. Install them with npx skills add https://redocly.com.
  • Added an experimental inspect-node-types command to navigate the Redocly's node type tree of an API description. inspect-node-types helps pick the correct subject types for a configurable rule or the correct visitor for a custom plugin.
  • Added a strategy option to the component-name-unique rule, matching the --component-names-strategy option of the bundle command.
  • Added an experimental introspect-mcp command that analyzes a running MCP server and records its tools, prompts, resources, and capabilities. introspect-mcp records its findings in the x-mcp extension of an OpenAPI description.

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​redocly/cli since your current version.


Updates ajv from 8.17.1 to 8.20.0

Release notes

Sourced from ajv's releases.

v8.20.0

What's Changed

Full Changelog: ajv-validator/ajv@v8.19.0...v8.20.0

v8.19.0

What's Changed

Full Changelog: ajv-validator/ajv@v8.18.0...v8.19.0

v8.18.0

What's Changed

New Contributors

Full Changelog: ajv-validator/ajv@v8.17.1...v8.18.0

Commits

Updates prettier from 3.6.2 to 3.9.9

Release notes

Sourced from prettier's releases.

3.9.9

  • Markdown: Fix text with $ been incorrectly parsed as math syntax (#20140 by @​fisker)

🔗 Changelog

3.9.8

  • Markdown: Don't let Liquid objects interrupt paragraphs (#20087 by @​seiyab)

🔗 Changelog

3.9.7

  • Support Angular 22.2
  • Fix regressions in v3.9

🔗 Changelog

3.9.6

What's Changed

🔗 Changelog

3.9.5

🔗 Changelog

3.9.4

  • Angular: Format @content(name) -> @content (name) to align with other block syntax (#19499 by @​fisker)

🔗 Changelog

3.9.3

🔗 Changelog

3.9.1

🔗 Changelog

3.9.0

diff

... (truncated)

Changelog

Sourced from prettier's changelog.

3.9.9

diff

Markdown: Fix text with $ been incorrectly parsed as math syntax (#20140 by @​fisker)

<!-- Input -->
**Uses $FOO** from `a.sh` and `b.sh`, plus `$BAR` from `c.sh`, before anything else runs here.
<!-- Prettier 3.9.8 -->
Uses $FOO from a.sh and b.sh, plus $BARfromc.sh, before anything else runs here.
<!-- Prettier 3.9.9 -->
Uses $FOO from a.sh and b.sh, plus $BAR from c.sh, before anything else runs here.

3.9.8

diff

Markdown: Don't let Liquid objects interrupt paragraphs (#20087 by @​seiyab)

<!-- Input -->
If `module` is not a [`WebAssembly.Module`](https://github.com/prettier/prettier/blob/main/en-US/docs/WebAssembly/Reference/JavaScript_interface/Module) object instance, a
{{jsxref("TypeError")}} is thrown.
<!-- Prettier 3.9.7 -->
If module is not a WebAssembly.Module object instance, a
{{jsxref("TypeError")}} is thrown.
<!-- Prettier 3.9.8 -->
If module is not a WebAssembly.Module object instance, a
{{jsxref("TypeError")}} is thrown.

3.9.7

diff

Markdown: Prevent indentation drift in list-item code blocks (#19647, #19990 by @​Austin1serb, @​giaBaoJS)

<!-- Input -->
- [x] short first line.
</tr></table> 

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for prettier since your current version.


Updates yaml from 2.8.1 to 2.9.1

Release notes

Sourced from yaml's releases.

v2.9.1

  • Limit recursive merge aliases (#685, #713)
  • Simplify line unfolding during quoted string parsing (#714)

v2.9.0

The changes here are really only patches, but I'm releasing this as a minor version to note a small change to the documentation of parseDocument() and parseAllDocuments(): I've removed the claim that they'll "never throw".

It remains the case that practically all non-malicious inputs will be handled without emitting an error, but there is a decent chance that code paths remain where e.g. a RangeError due to call stack exhaustion can be triggered by malicious inputs. Up to now, I've considered these as security vulnerabilities, and in fact it's the only category of error for which yaml CVEs have been issued so far.

Starting from this release, I'll be considering such errors as bugs, but not vulnerabilities. I do welcome people and/or LLMs looking for them, but please report them as normal issues rather than suspected security vulnerabilities. This also applies to previously undiscovered bugs in earlier releases.

  • fix: Avoid calling Array.prototype.push.apply() with large source array
  • fix(lexer): Avoid recursive calls that may exhaust the call stack

v2.8.4

  • Disable alias resolution with maxAliasCount:0 (#677)
  • Handle invalid unicode escapes (e1a1a77)
  • Apply minFractionDigits only to decimal strings (#676)

v2.8.3

  • Add trailingComma ToString option for multiline flow formatting (#670)
  • Catch stack overflow during node composition (1e84ebb)

v2.8.2

  • Serialize -0 as -0 (#638)
  • Do not double newlines for empty map values (#642)
Commits
  • 1440ecd 2.9.1
  • c699bc5 fix: Simplify line unfolding during quoted string parsing (#714)
  • d11ce77 fix: Limit recursive merge aliases (#713)
  • c5f49f4 chore: Update docs-slate
  • ddb21b0 2.9.0
  • 167365b docs: Clarify that not all errors can be avoided
  • 6eca2a7 fix: Avoid calling Array.prototype.push.apply() with large source array
  • 0543cd5 fix(lexer): Avoid recursive calls that may exhaust the call stack
  • ccdf743 2.8.4
  • f625789 fix: Disable alias resolution with maxAliasCount:0 (#677)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 3, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 3, 2026 03:08
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 3, 2026
@dependabot dependabot Bot changed the title build(deps-dev): bump the contract-tooling group with 4 updates build(deps-dev): bump the contract-tooling group across 1 directory with 4 updates Sep 5, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/contract-tooling-2502b2d398 branch 3 times, most recently from 8cfcae4 to 31db994 Compare September 11, 2026 06:41
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/contract-tooling-2502b2d398 branch 3 times, most recently from 19d7b05 to d0d5fda Compare September 14, 2026 14:23
…ith 4 updates

Bumps the contract-tooling group with 4 updates in the / directory: [@redocly/cli](https://github.com/Redocly/redocly-cli), [ajv](https://github.com/ajv-validator/ajv), [prettier](https://github.com/prettier/prettier) and [yaml](https://github.com/eemeli/yaml).


Updates `@redocly/cli` from 2.2.1 to 2.54.2
- [Release notes](https://github.com/Redocly/redocly-cli/releases)
- [Commits](https://github.com/Redocly/redocly-cli/compare/@redocly/cli@2.2.1...@redocly/cli@2.54.2)

Updates `ajv` from 8.17.1 to 8.20.0
- [Release notes](https://github.com/ajv-validator/ajv/releases)
- [Commits](ajv-validator/ajv@v8.17.1...v8.20.0)

Updates `prettier` from 3.6.2 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.6.2...3.9.9)

Updates `yaml` from 2.8.1 to 2.9.1
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.8.1...v2.9.1)

---
updated-dependencies:
- dependency-name: "@redocly/cli"
  dependency-version: 2.49.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: contract-tooling
- dependency-name: ajv
  dependency-version: 8.20.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: contract-tooling
- dependency-name: prettier
  dependency-version: 3.9.6
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: contract-tooling
- dependency-name: yaml
  dependency-version: 2.9.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: contract-tooling
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/contract-tooling-2502b2d398 branch from d0d5fda to e7ee1ca Compare September 27, 2026 14:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants