Skip to content

chore(deps): bump the development-dependencies group across 1 directory with 6 updates - #69

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/development-dependencies-cb08aeef60
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/development-dependencies-cb08aeef60

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the development-dependencies group with 6 updates in the / directory:

Package From To
eslint-plugin-sonarjs 4.2.1 4.2.2
knip 6.37.0 6.39.0
lefthook 2.1.14 2.1.16
oxfmt 0.68.0 0.71.0
oxlint 1.83.0 1.86.0
ultracite 7.12.0 7.12.2

Updates eslint-plugin-sonarjs from 4.2.1 to 4.2.2

Commits

Updates knip from 6.37.0 to 6.39.0

Release notes

Sourced from knip's releases.

Release 6.39.0

  • Add Railway plugin (#2026) (6da55767eb419701dd32f93789a00e8bdc915276) - thanks @​jonahsnider!
  • Update query snapshot (8877d3cf35943e17a617e1197fa46c5a43342479)
  • Fix excluded tags on entry re-exports (#2062) (b22e27543cb8dd4ba7ec97c70ccfd06bc8f16614) - thanks @​devYRPauli!
  • Update rolldown snapshot (3a45c806e1c1b7ceb078903652c8631566400096)
  • Skip synthetic self-imports in Vue and Nuxt auto-import compilers (#2067) (d912d807e41f140bbc79bafce6882b3c05dec6ff) - thanks @​bytedoe!
  • fix(angular): keep other projects' inputs when one has no architect (#2064) (af3f42e9772e9937fd71b7557d3b54aee1db339a) - thanks @​Cayan!
  • fix(vite): resolve nested HTML entry points in multi-page apps (#1988) (4648aefe56e7bac521bb6f17189473b46f8ff00f) - thanks @​DreamLongYT!
  • Improve Rstest plugin support (#2068) (add87992e9dfe2f3c22e4c6ba7fa257d7f0151cf) - thanks @​fi3ework!
  • Handle profiles, formatters and require paths in Cucumber plugin (#2065) (2ad39fcf02e067b4bdfc06a658bf4bf5abeea764) - thanks @​giaBaoJS!
  • fix(playwright): resolve globalSetup/globalTeardown from config dir (#2076) (7060bb968339680d694275413aba2833e4521ed9) - thanks @​alokn!
  • fix: read entry export tags under the re-exported names (#2069) (1698683df95a96b3515795eb664aacf030042d7b) - thanks @​devYRPauli!

Release 6.38.0

  • Include co-authors in docs contributor list (0c334100df59d89a512ad598ec50e7f62f6da0c3)
  • Filter bots and agents from docs contributors (617f70d8179c6b8668ca41fe5df77ced5e2b37c0)
  • Update Eve plugin conventions (#2049) (260dbb91a85f3a3bc2727e8f255d73df3737552c) - thanks @​matchai!
  • Add args example to that doc page (50b271b98fc930a05a3b045a2f691486f9f06528)
  • Add Turborepo plugin (#2055) (e49d3db05f1d69ce7db3efcb8467a4af63c27379) - thanks @​changbaebang!
  • Support import-x/* settings in ESLint plugin (#2050) (1a34cf82a3d6a1202717ef910bedba55838e9dd9) - thanks @​bytedoe!
  • Resolve file option in Mocha configuration files (#2051) (9b5c5f60468c8a92a3e74adca5c0931f008677af) - thanks @​giaBaoJS!
  • Support oxlint extends (#2054) (a149a98219bb14b15f446fc5f8c4f815e28b2183) - thanks @​matthewnitschke-wk!
  • Fix import.meta handling in built-in compilers (#2059) (8b0c85076bf3dce15ef5f3c0c4e58bfefdf59ded) - thanks @​vdavid!
  • Fix tag hints for enum and namespace members (#2061) (8a8805e48945863248429d18b7f6c4e4b7dc9ebd) - thanks @​devYRPauli!
  • Flag unused member tags in tagged enums and namespaces (584e53ff3e0846fbfe04fa5b5bfefe2420576a34)
  • feat: resolve MDX content mapper remarkPlugins (#2060) (34dbccf25359f9e9fefe9d0be6ef2ec0252223cc) - thanks @​gioboa!
  • Refactor and separate concerns w/ new typescript-content-mapper plugin (11e94509bd0f350d747facf4003fc5b248d1b02d)
  • Resolve mdx content mapper providerImportSource (7b5825117f97f2f87b7141509a254f88d0957cf7)
  • Fix config → entry in plop plugin (25a380c9e1165b76583d69b48b5fa7cdf5db0ae2)
Commits
  • ed30e5b Release knip@6.39.0
  • 1698683 fix: read entry export tags under the re-exported names (#2069)
  • 7060bb9 fix(playwright): resolve globalSetup/globalTeardown from config dir (#2076)
  • 2ad39fc Handle profiles, formatters and require paths in Cucumber plugin (#2065)
  • add8799 Improve Rstest plugin support (#2068)
  • 4648aef fix(vite): resolve nested HTML entry points in multi-page apps (#1988)
  • af3f42e fix(angular): keep other projects' inputs when one has no architect (#2064)
  • d912d80 Skip synthetic self-imports in Vue and Nuxt auto-import compilers (#2067)
  • b22e275 Fix excluded tags on entry re-exports (#2062)
  • 6da5576 Add Railway plugin (#2026)
  • Additional commits viewable in compare view

Updates lefthook from 2.1.14 to 2.1.16

Release notes

Sourced from lefthook's releases.

v2.1.16

Changelog

  • 3ee04318fd06d56a70cc9c90dc8385b19918f520 ci: refactor publishing scripts (#1559)
  • 91407e537b2fa36539506963a33e582dca394798 deps: bump mod and text deps to resolve CVEs (#1560)
  • be6f0ae8793533449cb9a07a253fa9a381e82206 fix: preserve unrelated unstaged changes on conflict (#1483)
  • cf4ef1e19baf0581871f69b40914d64c94ff19d7 fix: test staging fixed files with partially staged

v2.1.15

Changelog

  • 2388dde2b31dc9a782e967764046b41b404cece9 feat: propagate forced colors to hook commands via CLICOLOR_FORCE (#1547)
  • 49260b57c2a56bc4d65d09395458bb3ce3c63311 fix(lfs): do not pipe stdin into post-checkout git-lfs hook (#1523)
  • 38bc1c6cef3192a36002d0dcc37973416249c07e fix: quote paths in the generated hook shim (#1509)
  • 0892f5f256ebe162485492af5ca14c2ced45586f fix: remove color blending (#1558)
  • f1de41cd5cd6a6c5e0179c65e00d5ed6d90078c2 fix: resolve push-files fallback against the remote-tracking ref (#1485)
  • 07ce565bcc73465bc18fb36561b935ee2a53eab6 fix: sanitize slashes in remote ref when building the checkout dir name (#1486)
  • c465ca8ef4fc9ee0695aa4a9530fc404ed838b7a test(cmd): regression for valid fish shell completion output (#1527)
Changelog

Sourced from lefthook's changelog.

2.1.16

2.1.15

Commits
  • 433e6b9 2.1.16: preserve unrelated unstaged changes on conflicts after autofixes
  • cf4ef1e fix: test staging fixed files with partially staged
  • be6f0ae fix: preserve unrelated unstaged changes on conflict (#1483)
  • 91407e5 deps: bump mod and text deps to resolve CVEs (#1560)
  • 3ee0431 ci: refactor publishing scripts (#1559)
  • d050364 2.1.15: small fixes to output and LFS
  • 49260b5 fix(lfs): do not pipe stdin into post-checkout git-lfs hook (#1523)
  • 0892f5f fix: remove color blending (#1558)
  • f1de41c fix: resolve push-files fallback against the remote-tracking ref (#1485)
  • c465ca8 test(cmd): regression for valid fish shell completion output (#1527)
  • Additional commits viewable in compare view

Updates oxfmt from 0.68.0 to 0.71.0

Release notes

Sourced from oxfmt's releases.

oxfmt v0.71.0

🚀 Features

  • e0b1f9f oxfmt: Bump bundled Prettier version to 3.9.9 (#27002) (leaysgur)
  • 342527d oxfmt: Bump bundled Prettier version to 3.9.8 (#26999) (leaysgur)

🐛 Bug Fixes

  • eeba1db formatter: Skip test-call layout when arguments have comments (#27119) (leaysgur)
  • 1f7b8ad oxfmt: Allow repeated CLI calls in the same process (#27051) (Liang)
  • 7bcb807 formatter_markdown: Keep blank line between HTML and nested list (#27112) (leaysgur)
  • 10b10c5 formatter: Keep comments around = on their side and line (#27041) (leaysgur)
  • 9aad365 formatter: Keep comments deferred before an assignment operator (#26997) (waltu)
  • 8fbddb1 formatter/jsdoc: More alignment with original plugin (#27039) (leaysgur)
  • 50be18e formatter: Keep trailing spaces on normal block comments (#27037) (leaysgur)
  • 56d1880 formatter: Nestle adjacent block comments (#27036) (leaysgur)
  • 3be5d94 formatter: Treat /*** comments as JSDoc (#27035) (leaysgur)
  • cd45f71 formatter: Keep trailing double spaces on JSDoc lines (#26861) (John Costa)
  • fd695f4 formatter_markdown: Fix more mismatches found in ecosystem-ci repos (#27003) (leaysgur)
  • 4e77d59 formatter_markdown: Keep a math span after a kept line break from opening a block (#27001) (leaysgur)
  • 584b8b0 formatter_markdown: Keep a shape line after a multi-line inline node or link title (#27000) (leaysgur)
  • b939645 formatter_markdown: Keep a line break before an inline liquid tag under preserve (#26998) (leaysgur)

oxfmt v0.70.0

🚀 Features

  • 415b742 oxlint,oxfmt: Do not discover nested config in Vite+ mode (#26763) (leaysgur)
Commits

Updates oxlint from 1.83.0 to 1.86.0

Release notes

Sourced from oxlint's releases.

oxlint v1.86.0

🚀 Features

  • 9d80eed linter/react/only-export-components: Support allowCompoundComponents (#27117) (Kuroda Kayn)
  • e05b155 linter: Add typescript/no-generated-empty-object-type (#26958) (camc314)

🐛 Bug Fixes

  • 8306aa4 linter/typescript/no-unnecessary-parameter-property-assignment: Account for parameter property reassignment (#26955) (camc314)
  • 42dfbb5 linter/eslint/one-var: Keep declare when splitting declarations (#27081) (Cheolhee Lee)
  • 2ba7e33 linter/eslint/require-await: Count await using as an await (#27080) (Cheolhee Lee)
  • 611e4ed linter/plugins: Include executing selectors in JS plugin rule timings (#27111) (overlookmotel)
  • 2cac66f react-compiler: Handle recursive function expressions (#26796) (Brennan Butler)
  • e996e6c react-compiler: Treat zero-argument new Date as impure (#26894) (Boshen)
  • 571cfa3 oxlint: Skip type-aware lint rules in type-check-only mode (#27076) (camc314)
  • d0b2462 oxlint: Skip undefined children in CFG walker (#27075) (camc314)
  • 5186328 parser: Handle HTML comment values (#22933) (Boshen)
  • 0b630e8 linter/typescript/unified-signatures: Align rule with upstream (#26956) (camc314)
  • ebb22f1 linter/node/no-exports-assign: Change category from style to suspicious (#26555) (Bartok)
  • cce28a0 linter/import/no-duplicates: Distinguish import attributes (#26936) (camc314)
  • feb733b linter/unicorn/prefer-spread: Stop checking string split calls (#26935) (camc314)
  • 929e154 linter/eslint/no-unused-vars: Honor ignore patterns inside array rest bindings (#26923) (camc314)
  • 5bdb9b8 linter/eslint/no-unused-vars: Recognize consumed update expressions (#26782) (camc314)
  • 5c05bef linter/eslint/prefer-const: Ignore embedded assignments (#26920) (camc314)

⚡ Performance

  • ded4c29 linter/eslint/no-unused-vars: Skip sequence checks when absent (#26921) (camc314)

oxlint v1.85.0

🚀 Features

  • 415b742 oxlint,oxfmt: Do not discover nested config in Vite+ mode (#26763) (leaysgur)
Changelog

Sourced from oxlint's changelog.

[1.86.0] - 2026-09-28

🚀 Features

  • 9d80eed linter/react/only-export-components: Support allowCompoundComponents (#27117) (Kuroda Kayn)
  • e05b155 linter: Add typescript/no-generated-empty-object-type (#26958) (camc314)

[1.82.0] - 2026-09-07

🚀 Features

  • 6a0e19c linter/eslint/no-unmodified-loop-condition: Support checkConditionalExpressions option (#26249) (camc314)

[1.81.0] - 2026-08-31

📚 Documentation

  • d5be037 linter/typescript/switch-exhaustiveness-check: Clarify default case comment pattern (#26100) (camc314)

[1.79.0] - 2026-08-18

💥 BREAKING CHANGES

  • 8c4552d linter: [BREAKING] Split react/react-compiler into per-category rules (#25500) (Boshen)

🐛 Bug Fixes

  • 228e8e0 linter: Resolve inactive React compiler rules (#25830) (Boshen)
  • aa49d86 linter: Allow spread rule options in config types (#25675) (ch3rry)
  • 36f8451 linter/eslint/no-eval: Align indirect default with ESLint (#25656) (camc314)
  • beb724d linter/eslint/no-unused-vars: Report bare underscore parameters (#25663) (camc314)
  • 4004c10 linter/eslint/no-irregular-whitespace: Check comments by default (#25660) (camc314)
  • 285820e linter/no-large-snapshots: Precompile and document allowed snapshot matchers (#25611) (Mikhail Baev)
  • 4df5835 linter: Allow capitalized built-in calls (#25516) (Boshen)

[1.78.0] - 2026-08-10

🚀 Features

  • ccb8fe8 linter/jsdoc: Implement no-blank-blocks rule (#25207) (Mikhail Baev)
  • d4a897c linter/eslint: Implement one-var rule (#24470) (Cole Ellison)
  • 5ab9340 linter/jsx-a11y/anchor-has-content: Add options to match eslint (#24571) (Cole Ellison)

🐛 Bug Fixes

  • 9573937 linter/typescript: Validate ban-ts-comment description_format (#25320) (Mikhail Baev)

[1.77.0] - 2026-08-03

🐛 Bug Fixes

... (truncated)

Commits
  • 2ae2939 release(apps): oxlint v1.86.0 && oxfmt v0.71.0 (#27132)
  • 9d80eed feat(linter/react/only-export-components): support allowCompoundComponents ...
  • e05b155 feat(linter): add typescript/no-generated-empty-object-type (#26958)
  • 88a0096 chore(oxlint): require tsgolint 7.0.2003 (#27021)
  • 288d8cc release(apps): oxlint v1.85.0 && oxfmt v0.70.0 (#26903)
  • f02a64a release(apps): oxlint v1.84.0 && oxfmt v0.69.0 (#26874)
  • See full diff in compare view

Updates ultracite from 7.12.0 to 7.12.2

Release notes

Sourced from ultracite's releases.

ultracite@7.12.2

Patch Changes

  • 0f192a7: ultracite init no longer wipes an existing Biome config it can't read. Previously a biome.json or biome.jsonc with a syntax error, or a nested monorepo config with "extends": "//", was treated as empty and replaced with just the Ultracite extends, losing every other setting. Now:

    • A config with a syntax error is left unchanged, with a warning asking you to fix it and re-run init.
    • A nested config that extends the root config ("extends": "//") is left unchanged, since the Ultracite presets belong in the root config.
    • A string extends is turned into a list that also includes the Ultracite presets.
    • Updates edit the file in place, so comments and formatting in biome.jsonc are preserved.

    ultracite doctor and the check/fix resolution check now follow a nested config that extends "//" to the root config, instead of warning that the nested config doesn't extend ultracite/biome/core.

  • c68ba48: ultracite check and ultracite fix handle their arguments and missing tools more reliably:

    • check now treats explicit files the way fix does. Oxlint only gets files it can lint, Prettier runs with --ignore-unknown, and oxfmt with --no-error-on-unmatched-pattern. Before, ultracite check README.md or ultracite check Dockerfile src/index.ts failed even though nothing was wrong.
    • Linter flags that take a value keep it, even when the value looks like a file: --tsconfig tsconfig.json, -c .oxlintrc.json, --config-path biome.json, --only lint/suspicious/noDebugger, --since origin/main and similar. Before, the value was treated as a lint target, so ultracite fix --tsconfig tsconfig.json skipped Oxlint entirely and only formatted tsconfig.json. Ultracite's own --claude, --codex, --hook and --unsafe never take a value, so the next argument is always a target.
    • ultracite fix --unsafe with the ESLint toolchain no longer fails with ESLint's "Invalid option '--unsafe'". ESLint has no unsafe fixes, so the flag is dropped with a warning.
    • A linter that isn't installed is reported with a plain message instead of a stack trace. The other tools still run first. Stylelint is optional in the ESLint toolchain, as ultracite doctor already said, so a project without it now skips CSS linting with a warning instead of failing. "No linter configuration found" is also printed without a stack trace.
    • Linters installed in the project's node_modules/.bin are found even when Ultracite isn't run through a package manager script, npx or bunx, for example ./node_modules/.bin/ultracite check.
  • f61f393: ultracite init now looks for existing ESLint, Prettier and Stylelint configs in the same order the tools do, so when a project has more than one, init updates the one the tool actually loads. For example, Prettier reads .prettierrc.json before prettier.config.mjs, and ESLint reads eslint.config.js before eslint.config.mjs. Before, init could update a config the tool ignored and leave the active one in place. Stylelint's .stylelintrc.ts and stylelint.config.ts are now recognised too.

  • 242cd2a: ultracite init now updates an existing .vscode/settings.json or .zed/settings.json in place, so your comments and formatting are kept. Before, the file was re-serialised as plain JSON, which stripped every comment. A settings file with a syntax error is now left unchanged with a warning. Before, it was rewritten with whatever part the parser could recover, which dropped the rest.

    For the ESLint toolchain, init now also installs the Prettier VS Code extension (esbenp.prettier-vscode), since the settings it writes make Prettier the default formatter. Before, only the ESLint extension was installed, so format-on-save did nothing until you added Prettier yourself.

  • c273393: ultracite init now checks every flag value before it changes anything in the project. An unknown value for --linter, --pm, --frameworks, --editors, --agents, --hooks, --integrations or --js-plugins stops init with a message listing the valid values. Previously a misspelled --linter (for example --linter Biome) deleted every existing Biome, ESLint, Prettier, Stylelint, Oxlint and oxfmt config file and then crashed.

    When --linter is not passed and init runs without prompts (because of --quiet, CI, or flags such as --agents or --pm), it now keeps the linter the project is already set up with and only falls back to Oxlint when there is none. Running ultracite init --agents universal on a Biome project no longer migrates it to Oxlint. The interactive linter prompt also preselects the detected linter.

  • 3cb2e71: Clearer wording in the CLI:

    • ultracite init --help now lists the valid values for --pm, --linter, --frameworks, --hooks and --integrations, and explains what --type-aware does for Biome and for Oxlint.
    • The agent rules file says "Oxlint + Oxfmt will catch most mechanical issues automatically" instead of "Oxlint + Oxfmt's linter will catch…".
    • init and upgrade say "Using pnpm (detected from the project)" instead of "Detected lockfile", since the package manager can also come from packageManager.
    • ultracite doctor spells "unrecognized" consistently, formats commands as code, and describes warnings as "Some checks have warnings" instead of "optional improvements".
  • 6ae8be8: The ESLint nestjs preset imports @darraghor/eslint-plugin-nestjs-typed, but ultracite init --linter eslint --frameworks nestjs never installed it, so ESLint failed to load the config with "Cannot find package". init now installs the plugin with the preset, and ultracite upgrade installs the plugins of every framework preset your eslint.config.* imports, so existing NestJS projects pick it up on their next upgrade.

  • a8e83bb: ultracite init now migrates an existing .oxlintrc.json, .oxfmtrc.json or .oxfmtrc.jsonc when it sets up Oxlint. Oxlint and oxfmt refuse to load any config when a JSON config sits next to oxlint.config.ts or oxfmt.config.ts, and init used to write the TS configs beside the JSON ones, so ultracite check and ultracite fix stopped working. Init now moves the JSON config's settings into the TS config and deletes the JSON file:

    • rules, overrides, env, plugins and other options become properties of the generated config.
    • ignorePatterns, settings and jsPlugins are added to the ones Ultracite generates instead of replacing them.
    • Ultracite extends entries become presets. Other extends paths can't be referenced from a TS config, so init names them in a warning.

    A JSON config that doesn't parse is left in place, and neither file is written.

    Re-running ultracite init also keeps what you added to oxlint.config.ts and oxfmt.config.ts: custom rules, overrides, ignorePatterns, settings and other properties, extra extends entries, your own imports and statements, and comments are carried over while the Ultracite parts are regenerated. Before, both files were regenerated from scratch. A config that doesn't parse is now left unchanged with a warning instead of being overwritten.

    ultracite doctor now fails when a JSON config and a TS config for Oxlint or oxfmt sit side by side, and suggests running init to migrate a lone .oxfmtrc.json.

  • 981ef2f: ultracite init --linter oxlint no longer adds "type": "module" to package.json. That field changes how Node loads every .js file in the package, so CommonJS files such as a next.config.js, postcss.config.js or jest.config.js using module.exports stopped working after init.

    Instead, init writes the Oxlint and oxfmt configs as oxlint.config.mts and oxfmt.config.mts when the package isn't an ES module package (no "type" or "type": "commonjs"). A .mts file always loads as an ES module, with no MODULE_TYPELESS_PACKAGE_JSON warning on every run, and it works under "type": "commonjs". ES module packages ("type": "module") still get oxlint.config.ts and oxfmt.config.ts.

    Re-running init updates an existing config under the name it already has. The one exception is a .ts config in a "type": "commonjs" package, which Node can't load: init renames it to .mts and says so. ultracite doctor, linter detection and the stale-config cleanup all recognise the .mts names. doctor fails a .ts config in a CommonJS package, and fails when a .ts and an .mts config sit side by side.

    Requires oxfmt >= 0.59.0, the first release that finds oxfmt.config.mts on its own.

... (truncated)

Commits
  • e948def Version Packages (#823)
  • 84838a2 Note that adding hooks later keeps the project's linter
  • 987468a Document --unsafe per toolchain and the new check, doctor and upgrade behavior
  • 857e799 Describe how init updates existing configs in the migration guides
  • 9eb8cbf Document init's linter detection, flag checks and quiet output
  • 9c30c15 Raise the oxlint peer range to the first release that loads the presets
  • 44d6997 Create agent and hook directories only after the path guard
  • 3cb2e71 Tidy CLI help and messages
  • f61f393 Look for ESLint, Prettier and Stylelint configs in the tools' own order
  • 923667b Respect tsconfig strictNullChecks settings, including inherited ones
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Polylane reviews this pull request when you ask:

Review with Polylane


Summary by cubic

Bumps six development dependencies to their latest patch and minor releases, updating package.json and bun.lock. The oxlint bump to 1.86.0 raises its oxlint-tsgolint peer requirement to >=7.0.2003, and ultracite 7.12.2 changes init, check, and fix CLI behavior while requiring the oxfmt and oxlint versions included in this PR.

Written for commit c5b3d34. Summary will update on new commits.

Review in cubic

…ry with 6 updates

Bumps the development-dependencies group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [eslint-plugin-sonarjs](https://github.com/SonarSource/SonarJS) | `4.2.1` | `4.2.2` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.37.0` | `6.39.0` |
| [lefthook](https://github.com/evilmartians/lefthook) | `2.1.14` | `2.1.16` |
| [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.68.0` | `0.71.0` |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.83.0` | `1.86.0` |
| [ultracite](https://github.com/haydenbleasel/ultracite) | `7.12.0` | `7.12.2` |



Updates `eslint-plugin-sonarjs` from 4.2.1 to 4.2.2
- [Release notes](https://github.com/SonarSource/SonarJS/releases)
- [Changelog](https://github.com/SonarSource/SonarJS/blob/master/docs/RELEASE.md)
- [Commits](https://github.com/SonarSource/SonarJS/commits)

Updates `knip` from 6.37.0 to 6.39.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.39.0/packages/knip)

Updates `lefthook` from 2.1.14 to 2.1.16
- [Release notes](https://github.com/evilmartians/lefthook/releases)
- [Changelog](https://github.com/evilmartians/lefthook/blob/master/CHANGELOG.md)
- [Commits](evilmartians/lefthook@v2.1.14...v2.1.16)

Updates `oxfmt` from 0.68.0 to 0.71.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.71.0/npm/oxfmt)

Updates `oxlint` from 1.83.0 to 1.86.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.86.0/npm/oxlint)

Updates `ultracite` from 7.12.0 to 7.12.2
- [Release notes](https://github.com/haydenbleasel/ultracite/releases)
- [Commits](https://github.com/haydenbleasel/ultracite/compare/ultracite@7.12.0...ultracite@7.12.2)

---
updated-dependencies:
- dependency-name: eslint-plugin-sonarjs
  dependency-version: 4.2.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: knip
  dependency-version: 6.39.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: lefthook
  dependency-version: 2.1.16
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: oxfmt
  dependency-version: 0.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: oxlint
  dependency-version: 1.86.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: ultracite
  dependency-version: 7.12.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 5, 2026
@changeset-bot

changeset-bot Bot commented Oct 5, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: c5b3d34

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 429f2774-7f1f-4b86-9a5b-9fba89a6d1af

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 5, 2026

Copy link
Copy Markdown

Open in StackBlitz

bun add https://pkg.pr.new/@mynameistito/codex-usage@c5b3d34

commit: c5b3d34

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedeslint-plugin-sonarjs@​4.2.1 ⏵ 4.2.299 +1100100 +195 +770
Updatedoxfmt@​0.68.0 ⏵ 0.71.094 +810088 +196 +1100
Updatedoxlint@​1.83.0 ⏵ 1.86.099 +110091 +196100
Updatedlefthook@​2.1.14 ⏵ 2.1.169210010095 +1100
Updatedknip@​6.37.0 ⏵ 6.39.099 +110095 +195 -1100
Updatedultracite@​7.12.0 ⏵ 7.12.29810097 +196100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants