deps: bump the dependencies group across 1 directory with 18 updates - #82
dependabot[bot] wants to merge 1 commit into
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
3efa2e7 to
85050a2
Compare
85050a2 to
f5b9256
Compare
Bumps the dependencies group with 18 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@effect/platform](https://github.com/Effect-TS/effect/tree/HEAD/packages/platform) | `0.95.0` | `0.97.2` | | [@google-cloud/storage](https://github.com/googleapis/google-cloud-node/tree/HEAD/handwritten/storage) | `7.19.0` | `8.1.0` | | [@openrouter/sdk](https://github.com/OpenRouterTeam/typescript-sdk) | `1.2.113` | `1.2.123` | | [chrono-node](https://github.com/wanasit/chrono) | `2.9.0` | `2.10.1` | | [csv-parse](https://github.com/adaltas/node-csv/tree/HEAD/packages/csv-parse) | `5.6.0` | `7.0.2` | | [effect](https://github.com/Effect-TS/effect/tree/HEAD/packages/effect) | `3.20.0` | `3.22.2` | | [hyparquet](https://github.com/hyparam/hyparquet) | `1.26.1` | `1.30.1` | | [hyparquet-writer](https://github.com/hyparam/hyparquet-writer) | `0.16.1` | `0.16.9` | | [modal](https://github.com/modal-labs/modal-client) | `0.8.0` | `0.10.1` | | [smol-toml](https://github.com/squirrelchat/smol-toml) | `1.6.1` | `1.8.0` | | [yaml](https://github.com/eemeli/yaml) | `2.8.3` | `2.9.1` | | [zod](https://github.com/colinhacks/zod) | `4.4.3` | `4.6.5` | | [@effect/tsgo](https://github.com/Effect-TS/tsgo/tree/HEAD/_packages/tsgo) | `0.31.0` | `0.45.0` | | [@types/bun](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/bun) | `1.3.14` | `1.4.2` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `24.10.0` | `26.5.1` | | [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.62.0` | `0.68.0` | | [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.77.0` | `1.83.0` | | [ultracite](https://github.com/haydenbleasel/ultracite) | `7.10.1` | `7.12.0` | Updates `@effect/platform` from 0.95.0 to 0.97.2 - [Release notes](https://github.com/Effect-TS/effect/releases) - [Changelog](https://github.com/Effect-TS/effect/blob/@effect/platform@0.97.2/packages/platform/CHANGELOG.md) - [Commits](https://github.com/Effect-TS/effect/commits/@effect/platform@0.97.2/packages/platform) Updates `@google-cloud/storage` from 7.19.0 to 8.1.0 - [Release notes](https://github.com/googleapis/google-cloud-node/releases) - [Changelog](https://github.com/googleapis/google-cloud-node/blob/main/handwritten/storage/CHANGELOG.md) - [Commits](https://github.com/googleapis/google-cloud-node/commits/admin-v8.1.0/handwritten/storage) Updates `@openrouter/sdk` from 1.2.113 to 1.2.123 - [Release notes](https://github.com/OpenRouterTeam/typescript-sdk/releases) - [Changelog](https://github.com/OpenRouterTeam/typescript-sdk/blob/main/RELEASES.md) - [Commits](OpenRouterTeam/typescript-sdk@v1.2.113...v1.2.123) Updates `chrono-node` from 2.9.0 to 2.10.1 - [Release notes](https://github.com/wanasit/chrono/releases) - [Commits](wanasit/chrono@v2.9.0...v2.10.1) Updates `csv-parse` from 5.6.0 to 7.0.2 - [Changelog](https://github.com/adaltas/node-csv/blob/master/packages/csv-parse/CHANGELOG.md) - [Commits](https://github.com/adaltas/node-csv/commits/csv-parse@7.0.2/packages/csv-parse) Updates `effect` from 3.20.0 to 3.22.2 - [Release notes](https://github.com/Effect-TS/effect/releases) - [Changelog](https://github.com/Effect-TS/effect/blob/effect@3.22.2/packages/effect/CHANGELOG.md) - [Commits](https://github.com/Effect-TS/effect/commits/effect@3.22.2/packages/effect) Updates `hyparquet` from 1.26.1 to 1.30.1 - [Changelog](https://github.com/hyparam/hyparquet/blob/master/CHANGELOG.md) - [Commits](hyparam/hyparquet@v1.26.1...v1.30.1) Updates `hyparquet-writer` from 0.16.1 to 0.16.9 - [Changelog](https://github.com/hyparam/hyparquet-writer/blob/master/CHANGELOG.md) - [Commits](hyparam/hyparquet-writer@v0.16.1...v0.16.9) Updates `modal` from 0.8.0 to 0.10.1 - [Changelog](https://github.com/modal-labs/modal-client/blob/main/CHANGELOG_DEV.md) - [Commits](modal-labs/modal-client@go/v0.8.0...go/v0.10.1) Updates `smol-toml` from 1.6.1 to 1.8.0 - [Release notes](https://github.com/squirrelchat/smol-toml/releases) - [Commits](squirrelchat/smol-toml@v1.6.1...v1.8.0) Updates `yaml` from 2.8.3 to 2.9.1 - [Release notes](https://github.com/eemeli/yaml/releases) - [Commits](eemeli/yaml@v2.8.3...v2.9.1) Updates `zod` from 4.4.3 to 4.6.5 - [Release notes](https://github.com/colinhacks/zod/releases) - [Commits](colinhacks/zod@v4.4.3...v4.6.5) Updates `@effect/tsgo` from 0.31.0 to 0.45.0 - [Release notes](https://github.com/Effect-TS/tsgo/releases) - [Changelog](https://github.com/Effect-TS/tsgo/blob/main/_packages/tsgo/CHANGELOG.md) - [Commits](https://github.com/Effect-TS/tsgo/commits/@effect/tsgo@0.45.0/_packages/tsgo) Updates `@types/bun` from 1.3.14 to 1.4.2 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/bun) Updates `@types/node` from 24.10.0 to 26.5.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `oxfmt` from 0.62.0 to 0.68.0 - [Release notes](https://github.com/oxc-project/oxc/releases) - [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md) - [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.68.0/npm/oxfmt) Updates `oxlint` from 1.77.0 to 1.83.0 - [Release notes](https://github.com/oxc-project/oxc/releases) - [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md) - [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.83.0/npm/oxlint) Updates `ultracite` from 7.10.1 to 7.12.0 - [Release notes](https://github.com/haydenbleasel/ultracite/releases) - [Commits](https://github.com/haydenbleasel/ultracite/compare/ultracite@7.10.1...ultracite@7.12.0) --- updated-dependencies: - dependency-name: "@effect/platform" dependency-version: 0.97.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: "@effect/tsgo" dependency-version: 0.41.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: "@google-cloud/storage" dependency-version: 8.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: "@openrouter/sdk" dependency-version: 1.2.108 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: "@types/bun" dependency-version: 1.4.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: "@types/node" dependency-version: 26.5.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: dependencies - dependency-name: chrono-node dependency-version: 2.10.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: csv-parse dependency-version: 7.0.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: effect dependency-version: 3.22.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: hyparquet dependency-version: 1.30.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: hyparquet-writer dependency-version: 0.16.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: modal dependency-version: 0.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: oxfmt dependency-version: 0.67.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: oxlint dependency-version: 1.82.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: smol-toml dependency-version: 1.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: ultracite dependency-version: 7.11.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: yaml dependency-version: 2.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: zod dependency-version: 4.5.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
f5b9256 to
8fcee82
Compare
There was a problem hiding this comment.
Perry's Review
Verdict: 🔴 Request Changes — CI regression from oxlint 1.83.0
Dependabot group bump with 18 dependency updates across the lockfile. Most bumps are routine. The oxlint 1.77.0 → 1.83.0 bump breaks CI.
🔴 Blocker: oxlint 1.83.0 breaks CI (19 new lint errors)
The new oxlint version flags the repo's const+type declaration-merging pattern as "X is already defined":
export const RewardType = { Db: "DB", ... } as const;
export type RewardType = ValueOf<typeof RewardType>; // ← flagged as "already defined"CI fails at the Lint step, producing 19 errors across 11 source files. Because CI fails at lint, the Typecheck, Test, and Build steps never execute.
| Source file | Symbols flagged |
|---|---|
| tau3-bench-banking/types.ts | RewardType, ToolRequestor |
| harness/core.ts | MessageRole, ScoreValue |
| internal/enums.ts | WebFetchEngine |
| harness/constants.ts | ImageDetail, VideoProcessingMode |
| draco/schemas.ts | GenerationStatus, VerdictValue, JudgeRunStatus, DracoToolType, ShellEngine, DracoExperimentType, JudgeReasoningEffort |
| tau-bench-airline/types.ts | RewardType, ToolRequestor |
| tau-bench-airline/solver.ts | Role |
| ifstruct/schema.ts | OutputFormat |
| tau3-bench-banking/solver.ts | Role |
Fix: Either revert the oxlint bump to 1.77.0 in this PR (and handle the upgrade separately with the necessary source fixes or rule config), or fix the 19 errors now by addressing the new no-redeclare rule.
✅ Major version bumps verified compatible
@google-cloud/storage7→8: The only breaking change in v8 is a Node 22 minimum (this repo uses Bun). The repo importsRETRYABLE_ERR_FN_DEFAULTandStorage— both are still exported in v8.1.0 (verified against the v8 source on GitHub).csv-parse5→7: The ./sync export map is identical in v5 and v7. The repo only usesparsefrom csv-parse/sync, which is unchanged.modal0.8→0.10: The repo importsApp,SandboxCreateParams, andModalClient— all still exported in v0.10.1 (verified against the v0.10.1 type declarations).
The remaining 14 bumps are minor/patch versions with no API surface changes affecting this repo.
🟡 Risk assessment
Risk: 🟡 Medium
| Dimension | Severity | Risk | Reasoning |
|---|---|---|---|
| Implementation risk | 🟨🟨 | Medium | CI is broken by the oxlint bump; the codebase itself is unchanged. |
| Premise risk | 🟩 | Low | Routine dependency bumps; the framing is correct. |
| Estimated impact | 🟩 | Low | No runtime changes; a blocked CI is the only consequence. |
| Risk Factor | Severity | Risk | Reasoning |
|---|---|---|---|
| Reversibility | 🟩 | Low | Lockfile/package.json revert is trivial. |
| Detectability | 🟩 | Low | CI failure is immediately visible. |
| Blast radius | 🟩 | Low | No runtime impact — CI only. |
| Data integrity | 🟩 | Low | No persisted state touched. |
| Financial exposure | 🟩 | Low | No billing/payment code affected. |
| Security and privacy exposure | 🟩 | Low | No auth/credential code affected. |
| Propagation | 🟩 | Low | No downstream consumers of the lint config. |
| Availability | 🟩 | Low | No serving path affected. |
| Recovery cost | 🟩 | Low | Revert the oxlint version line. |
| Time to correct | 🟩 | Low | One-line revert or rule config. |
Recommendation
Split the oxlint bump out of this PR. Merge the other 17 dependency bumps (all verified safe), then handle the oxlint 1.77→1.83 upgrade in a separate PR that also fixes the 19 no-redeclare errors (either by configuring the rule or adjusting the source pattern).
Estimated impact: Low — the PR is a dependency bump with no runtime changes; the only consequence of merging as-is would be a broken CI pipeline that blocks future merges until the lint errors are resolved.
| "oxfmt": "0.62.0", | ||
| "oxlint": "1.77.0", | ||
| "oxfmt": "0.68.0", | ||
| "oxlint": "1.83.0", |
There was a problem hiding this comment.
🔴 Blocker — CI regression. Bumping oxlint from 1.77.0 to 1.83.0 introduces a no-redeclare rule that flags the repo's const X = {...} as const; export type X = ValueOf<typeof X> pattern as 'X' is already defined. This produces 19 errors across 11 source files and fails CI at the Lint step — Typecheck, Test, and Build never run.
Fix: Revert this line to "oxlint": "1.77.0" and handle the oxlint upgrade in a separate PR that also addresses the 19 lint errors (either via an oxlint config override for this pattern, or by renaming the type aliases). The other 17 dependency bumps in this PR are verified safe to merge.
Bumps the dependencies group with 18 updates in the / directory:
0.95.00.97.27.19.08.1.01.2.1131.2.1232.9.02.10.15.6.07.0.23.20.03.22.21.26.11.30.10.16.10.16.90.8.00.10.11.6.11.8.02.8.32.9.14.4.34.6.50.31.00.45.01.3.141.4.224.10.026.5.10.62.00.68.01.77.01.83.07.10.17.12.0Updates
@effect/platformfrom 0.95.0 to 0.97.2Release notes
Sourced from @effect/platform's releases.
Changelog
Sourced from @effect/platform's changelog.
... (truncated)
Commits
6985be0Version Packages (v3) (#6809)2e471d9fix(platform): preserve multipart limit failures (#7998)417e0faVersion Packages (v3) (#6466)284b021Fix KeyValueStore file backend docs (#6776)4b03605Harden file-backed key-value store keys on v3 (#6774)5859b37Harden v3 cookie attribute validation (#6765)8ee801dFix HTML escaping in API docs (#6756)e5dfd78Add extendEnv option to Command.env (#6652)8a405fdupdate multipasta (#6311)e670e0fVersion Packages (#6323)Updates
@google-cloud/storagefrom 7.19.0 to 8.1.0Release notes
Sourced from @google-cloud/storage's releases.
... (truncated)
Changelog
Sourced from @google-cloud/storage's changelog.
... (truncated)
Commits
Updates
@openrouter/sdkfrom 1.2.113 to 1.2.123Release notes
Sourced from @openrouter/sdk's releases.
... (truncated)
Changelog
Sourced from @openrouter/sdk's changelog.
... (truncated)
Commits
05098eachore: 🐝 Update SDK - Generate (spec change merged) 1.2.123 (#999)8a3747cchore: update OpenAPI spec from monorepo (#998)da3ec60chore: 🐝 Update SDK - Generate (spec change merged) 1.2.122 (#997)bdc465bchore: update OpenAPI spec from monorepo (#996)53b95f6chore: 🐝 Update SDK - Generate (spec change merged) 1.2.121 (#995)6e95ba0chore: update OpenAPI spec from monorepo (#994)a76a1c5chore: 🐝 Update SDK - Generate (spec change merged) 1.2.120 (#993)3f80a66chore: update OpenAPI spec from monorepo (#992)9e07731chore: 🐝 Update SDK - Generate (spec change merged) 1.2.119 (#990)1f8ab8bchore: update OpenAPI spec from monorepo (#989)Updates
chrono-nodefrom 2.9.0 to 2.10.1Release notes
Sourced from chrono-node's releases.
Commits
82c0e5b2.10.1f15d1a8fix(en): support all 2-digit years in month name little endian parser (fixes ...eeef954docs(it): list Italian as fully supported in READMEa0ac654feat(it): support relative times, timezone offsets, and improve Italian langu...41ee4e8fix(fr): support standard month name abbreviations and accented variants (iss...c4c26852.10.05b13e0aMerge pull request #650 from elinathan/fix/dst-system-timezone-dependencedc63e17build(npm): remove redundant .npmignore668509fbuild(npm): whitelist dist and src directories for publishing1ec7e232.9.2Updates
csv-parsefrom 5.6.0 to 7.0.2Changelog
Sourced from csv-parse's changelog.
... (truncated)
Commits
288c9c6chore(release): publish2ad6c07refactor(csv-parse): rename group_columns_by_name testseb4d148fix(csv-parse): prototype replacement reachable via columns (#497)1d4ed3bperf(csv-parse): avoid unnecessary allocation in ResizeableBuffer.toString (#...6e0d5a3chore(release): publishabfe4debuild: latest dependenciesa5ef896docs(csv-parse): fix changelog message from previous version230af8efix(csv-parse): ship stream cjs export (#490)3d71f0bchore(release): publish2ba4897build: use ts nodenextMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for csv-parse since your current version.
Updates
effectfrom 3.20.0 to 3.22.2Release notes
Sourced from effect's releases.
Changelog
Sourced from effect's changelog.
... (truncated)
Commits
6985be0Version Packages (v3) (#6809)7c6e1e5Fix use of Schema.NonEmptyArrayEnsure with strings (#7170)291d5a9fix(effect): TMap.remove/removeAll clears entire bucket on hash collision (#6...417e0faVersion Packages (v3) (#6466)fcabf08Fix Config redaction errors on v3 (#6762)3cc3c6eUse linear matcher for string template literals (#6761)735d81bFix Stream.asyncPush bounded termination (#6669)ab2af6dFix zero-capacity Mailbox rendezvous (#6673)3d390f2Suppress unhandled logs from timeout fibers (#6507)7ccbd9cClarify GenericTag key documentation (#6443)Updates
hyparquetfrom 1.26.1 to 1.30.1Changelog
Sourced from hyparquet's changelog.
Commits
252af4bPublish v1.30.1ea07519Fix $not filters on dot-notation paths (#177)f013402Publish v1.30.06673b17Add opt-in physical row index symbol to object rows (#176)a90371fPublish v1.29.2bed29f6Add default exports to thepackage.json(#174)4196fb2Publish v1.29.10620905Defer parquet scan column planning (#173)eb6eb73Publish v1.29.043226acAdd lazy physical parquet scans (#172)Updates
hyparquet-writerfrom 0.16.1 to 0.16.9Changelog
Sourced from hyparquet-writer's changelog.
Commits
f30ace7Publish v0.16.9e44065eFix INT32 DECIMAL statistics encoding (#43)7104e0bImprove built-in Snappy compression window (#42)60d6d3bPublish v0.16.86d68e39Accept a bigint for DECIMAL values and statistics (#39)e281d79Reuse variant scratch writers (#41)98036cbPublish v0.16.78bf25b3Fix ByteWriter capacity checks (#40)ef95875Publish v0.16.6b16dd50Keep large dictionaries that win, decoupled from pageSize (#36)Updates
modalfrom 0.8.0 to 0.10.1Commits
3b4ed40Release v0.10.1 of the JS / Go SDKs (#58439)9a37902[Proto] Return helpful hint when Cls is passed to FunctionGet (#58038)5ce9823[CLI] modal server logs and modal function logs (#56981)f321b87Add OAuth private-key JWT authentication to the JS SDK (#58126)8b61508Add OAuth private-key JWT authentication to the Go SDK (#57861)78d3314Add FunctionGetFlashAuthToken RPC to api.proto (#57751)5f257c4Remove legacy Sandbox filesystem API from the Python client (#57485)a24a6c2Make_AuthTokenManageraccept a custom token fetcher (#58134)789ce05Add environment setting to block unauthenticated resources (#57986)6cc41e6Run static_types_test.py under Bazel instead of skipping it (#57697)Updates
smol-tomlfrom 1.6.1 to 1.8.0Release notes
Sourced from smol-toml's releases.
CommitsDescription has been truncated