chore(deps-dev): bump the development group with 2 updates - #77
chore(deps-dev): bump the development group with 2 updates#77dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the development group with 2 updates: [@napi-rs/cli](https://github.com/napi-rs/napi-rs) and [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node). Updates `@napi-rs/cli` from 3.7.4 to 3.8.0 - [Release notes](https://github.com/napi-rs/napi-rs/releases) - [Commits](https://github.com/napi-rs/napi-rs/compare/@napi-rs/cli@3.7.4...@napi-rs/cli@3.8.0) Updates `@types/node` from 26.1.1 to 26.1.2 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) --- updated-dependencies: - dependency-name: "@napi-rs/cli" dependency-version: 3.8.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: development - dependency-name: "@types/node" dependency-version: 26.1.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: development ... Signed-off-by: dependabot[bot] <support@github.com>
|
Codex review: needs maintainer review before merge. Reviewed August 1, 2026, 8:15 PM ET / August 2, 2026, 00:15 UTC. ClawSweeper reviewWhat this changesUpdates the development-only N-API native-build CLI from 3.7.4 to 3.8.0 and refreshes the resolved Merge readiness⛔ Blocked until real behavior proof is added - 4 items remain Keep this PR open for validation before merge. Current Priority: P3 Review scores
Verification
How this fits togetherThe development dependency set supplies TypeScript tooling and the N-API CLI that builds this package’s native bindings. CI and release prebuilds install the frozen pnpm lockfile before using that CLI to validate the package and produce platform artifacts. flowchart LR
A[Locked development dependencies] --> B[Frozen pnpm install]
B --> C[Node validation]
B --> D[N-API build CLI]
D --> E[Native platform bindings]
C --> F[Package validation]
E --> G[Release artifacts]
Decision needed
Why: The changed tool builds release artifacts, but the available failed-check status has no diagnostic output, so it is not safe to attribute or dismiss the Windows failure automatically. Before merge
Agent review detailsSecurityNone. Review metrics
Merge-risk optionsMaintainer options:
Technical reviewBest possible solution: Retrieve or rerun the Node 24 Windows failure on this exact head, then merge the narrow dependency update only if the frozen install and Do we have a high-confidence way to reproduce the issue? No. The failed Node 24 Windows status is concrete, but its job log was unavailable during this read-only review, so there is no high-confidence path to reproduce or attribute the failure locally. Is this the best way to solve the issue? Unclear. The dependency update is narrowly scoped and follows the repository’s lockfile workflow, but resolving the Windows validation result is necessary before treating it as a safe upgrade. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning high; reviewed against ab933820c089. LabelsLabel justifications:
EvidenceWhat I checked:
Likely related people:
Rank-up movesOptional improvements that raise the rating; they are not merge blockers.
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (13 earlier review cycles; latest 8 shown)
|
|
Disposition: CLOSE as superseded by #79. The Windows/Node 24 failure on this exact head was not caused by the dependency update: it was a one-off #79 carries the dependency work forward with No Dependabot branch revision is requested; this generated update is cleanly superseded. |
|
Closing as superseded by #79, which landed the newer dependency set with a complete npm, Rust, native-build, packaged-consumer, and cross-platform CI proof. Full disposition and original-head analysis: #77 (comment) |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Bumps the development group with 2 updates: @napi-rs/cli and @types/node.
Updates
@napi-rs/clifrom 3.7.4 to 3.8.0Commits
9da8723chore(release): publish8d22196chore(deps): update dependency oxc-parser to ^0.142.0 (#3422)abc30fbbuild(deps): bump postcss from 8.5.17 to 8.5.23 (#3421)5542139build(deps): bump fast-xml-parser from 5.9.3 to 5.10.1 (#3418)dc4ee8cbuild(deps): bump fast-uri from 3.1.3 to 3.1.4 (#3419)050d985feat(async-runtime): drain-linger surface + lock-free scheduler internals (#3...e0b8708chore(deps): update dependency oxc-parser to ^0.141.0 (#3417)fc84940chore(deps): update actions/setup-node action to v7 (#3413)ee598dbbuild(deps): bump protobufjs from 7.6.4 to 7.6.5 (#3410)e707edechore(deps): update actions/setup-node action to v7 (#3412)Updates
@types/nodefrom 26.1.1 to 26.1.2Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions