Skip to content

build(deps-dev): bump the development-minor-and-patch group with 2 updates - #190

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/development-minor-and-patch-b705bc7931
Open

build(deps-dev): bump the development-minor-and-patch group with 2 updates#190
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/development-minor-and-patch-b705bc7931

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor

Bumps the development-minor-and-patch group with 2 updates: oxfmt and oxlint.

Updates oxfmt from 0.62.0 to 0.63.0

Changelog

Sourced from oxfmt's changelog.

Changelog

All notable changes to this package will be documented in this file.

The format is based on Keep a Changelog.

Commits
  • c42d639 release(apps): oxlint v1.78.0 && oxfmt v0.63.0 (#25473)
  • 00f490d refactor(oxfmt,formatter): split sortImports validation and use type enum (...
  • See full diff in compare view

Updates oxlint from 1.77.0 to 1.78.0

Changelog

Sourced from oxlint's changelog.

[1.78.0] - 2026-08-10

🚀 Features

  • ccb8fe8 linter/jsdoc: Implement no-blank-blocks rule (#25207) (Mikhail Baev)
  • d4a897c linter/eslint: Implement one-var rule (#24470) (Cole Ellison)
  • 5ab9340 linter/jsx-a11y/anchor-has-content: Add options to match eslint (#24571) (Cole Ellison)

🐛 Bug Fixes

  • 9573937 linter/typescript: Validate ban-ts-comment description_format (#25320) (Mikhail Baev)
Commits
  • c42d639 release(apps): oxlint v1.78.0 && oxfmt v0.63.0 (#25473)
  • ccb8fe8 feat(linter/jsdoc): implement no-blank-blocks rule (#25207)
  • 9573937 fix(linter/typescript): validate ban-ts-comment description_format (#25320)
  • d4a897c feat(linter/eslint): implement one-var rule (#24470)
  • 5ab9340 feat(linter/jsx-a11y/anchor-has-content): add options to match eslint (#24571)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…dates

Bumps the development-minor-and-patch group with 2 updates: [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) and [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint).


Updates `oxfmt` from 0.62.0 to 0.63.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.63.0/npm/oxfmt)

Updates `oxlint` from 1.77.0 to 1.78.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.78.0/npm/oxlint)

---
updated-dependencies:
- dependency-name: oxfmt
  dependency-version: 0.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-minor-and-patch
- dependency-name: oxlint
  dependency-version: 1.78.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 17, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 17, 2026 18:27
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 17, 2026
@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Aug 17, 2026
@clawsweeper

clawsweeper Bot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Codex review: needs maintainer review before merge. Reviewed August 17, 2026, 2:32 PM ET / 18:32 UTC.

ClawSweeper review

What this changes

Updates Oxfmt from 0.62.0 to 0.63.0 and refreshes the pnpm-resolved Oxlint version from 1.77.0 to 1.78.0 with their platform bindings.

Merge readiness

⚠️ Ready for maintainer review - 1 item remains

This clean Dependabot update remains necessary: current main still uses the older formatter and linter resolutions, while the PR’s focused package and lockfile update passed all reported checks.

Priority: P3
Reviewed head: 192e87b0c5739ea0076ba2989b890d7121760812

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A narrow, expected dependency update with all reported validation checks passing.
Proof confidence 🌊 off-meta tidepool Not applicable: This Dependabot maintenance PR is exempt from contributor real-behavior proof; successful repository CI covers the changed development tooling.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: This Dependabot maintenance PR is exempt from contributor real-behavior proof; successful repository CI covers the changed development tooling.
Evidence reviewed 6 items Current main does not contain the update: Current main declares oxfmt ^0.62.0 and oxlint ^1.77.0, so the requested development-tool update is still needed.
Tools are used by repository checks: The project directly invokes oxlint for linting and oxfmt for format checking.
Focused resolved update: The branch changes one manifest declaration and the matching lockfile resolutions and integrity metadata.
Findings None None.
Security None None.

How this fits together

clawpatch invokes Oxfmt and Oxlint through package scripts for local development and CI. package.json declares the tools and pnpm-lock.yaml pins their installed binaries and optional platform bindings.

flowchart LR
  A[Developer or CI] --> B[pnpm scripts]
  B --> C[Oxfmt and Oxlint]
  C --> D[Format and lint checks]
  E[Package manifest] --> F[pnpm lockfile]
  F --> C
  D --> G[Build validation]
Loading

Before merge

  • Complete next step (P2) - No repair lane is needed: the branch is clean, narrowly scoped, and ready for ordinary dependency-update merge handling.
Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Dependency surface 2 files; 1 manifest line; lockfile +162/-162 The lockfile churn is the expected platform-binding refresh for two direct development tools.

Technical review

Best possible solution:

Merge the narrow, validated development-tool update so local and CI checks resolve the newer Oxc releases.

Do we have a high-confidence way to reproduce the issue?

Not applicable: this is dependency maintenance, not a reported runtime bug; the relevant toolchain checks completed successfully on the PR.

Is this the best way to solve the issue?

Yes: updating the direct development-tool declaration and pnpm resolutions is the narrow supported path, and current main does not yet contain it.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning high; reviewed against 36b5c739e0f9.

Labels

Label changes:

  • add P3: This is a routine minor development-tool update with successful validation and no reported user-facing regression.
  • add rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • add status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: This Dependabot maintenance PR is exempt from contributor real-behavior proof; successful repository CI covers the changed development tooling.

Label justifications:

  • P3: This is a routine minor development-tool update with successful validation and no reported user-facing regression.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: This Dependabot maintenance PR is exempt from contributor real-behavior proof; successful repository CI covers the changed development tooling.

Evidence

What I checked:

  • Current main does not contain the update: Current main declares oxfmt ^0.62.0 and oxlint ^1.77.0, so the requested development-tool update is still needed. (package.json:44, 36b5c739e0f9)
  • Tools are used by repository checks: The project directly invokes oxlint for linting and oxfmt for format checking. (package.json:24, 192e87b0c573)
  • Focused resolved update: The branch changes one manifest declaration and the matching lockfile resolutions and integrity metadata. (pnpm-lock.yaml:29, 192e87b0c573)
  • Validation coverage: CI installs with the frozen lockfile, then runs typecheck, lint, format checking, tests, build, and package smoke validation; all reported PR checks succeeded. (.github/workflows/ci.yml:22, 192e87b0c573)
  • Dependency review is configured: The repository runs dependency review for package.json and pnpm-lock.yaml changes; the reported dependency-review check passed. (.github/workflows/dependency-review.yml:3, 192e87b0c573)
  • Recent package history: Peter Steinberger authored the recent package and lockfile maintenance commits, including prior toolchain refreshes. (package.json:41, 439d9e42b891)

Likely related people:

  • Peter Steinberger: Authored the recent dependency and toolchain refreshes affecting the manifest and lockfile. (role: recent package and toolchain contributor; confidence: high; commits: c19979fa0225, ab5ded8beeb5, 439d9e42b891; files: package.json, pnpm-lock.yaml)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants