Skip to content

chore(deps): bump the dependencies group across 1 directory with 4 updates - #5755

Merged
alexander-akait merged 1 commit into
mainfrom
dependabot/npm_and_yarn/dependencies-aa7e836124
Oct 1, 2026
Merged

alexander-akait merged 1 commit into
mainfrom
dependabot/npm_and_yarn/dependencies-aa7e836124

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 4 updates in the / directory: ws, @types/node, cspell and lint-staged.

Updates ws from 8.21.3 to 8.22.0

Release notes

Sourced from ws's releases.

8.22.0

Features

  • Introduced the protocols option (8b918b01).

Bug fixes

  • Calling websocket.close() with invalid arguments no longer transitions the state to WebSocket.CLOSING (#2337).
Commits
  • 297202c [dist] 8.22.0
  • 8b918b0 [feature] Introduce the protocols option
  • 73e03eb [ci] Update actions/setup-node action to v7
  • d9b8954 [fix] Change the ready state after validating the arguments (#2337)
  • See full diff in compare view

Updates @types/node from 26.6.2 to 26.6.3

Commits

Updates cspell from 10.3.4 to 10.3.5

Release notes

Sourced from cspell's releases.

v10.3.5

Fixes

fix(cspell-lib): shouldCheckDocument honors the forceCheck option (#9303)

Summary

For users of the cspell-lib API:

  • shouldCheckDocument now honors forceCheck. It returns shouldCheck: true for a document excluded by ignorePaths, or disabled by overrides or languageSettings. Before, the option was accepted but ignored. DocumentValidator already worked this way.
  • SpellCheckFileOptions now declares forceCheck, so it can be passed to spellCheckDocument and spellCheckFile with type checking.

fix: --force-check checks the listed files even when ignorePaths or files would skip them (#9300)

Summary

--force-check now checks every file given with --file or --file-list, as its help says. Before, some of those files were still skipped:

  • files matched by ignorePaths in the config;
  • files that don't match the files setting in the config.

Using globs on the command line together with --force-check is now an error, the same as globs with --file:

error: mixing globs and --force-check is not supported

Before, cspell lint --file-list list.txt "**/*.md" --force-check was accepted. To filter a file list by glob, leave out --force-check.


fix: files globs starting with ** no longer skip --file and --file-list files in a project under a dot folder (#9299)

Summary

When a project was under a folder whose name starts with a dot, such as ~/.local/src/my-project or a git worktree in .claude/worktrees/, files given with --file or --file-list could be skipped without any warning. CSpell then reported Files checked: 0 and exited with success.

This happened when the listed files were filtered by a glob starting with **:

... (truncated)

Changelog

Sourced from cspell's changelog.

v10.3.5 (2026-09-27)

Fixes

fix(cspell-lib): shouldCheckDocument honors the forceCheck option (#9303)

Summary

For users of the cspell-lib API:

  • shouldCheckDocument now honors forceCheck. It returns shouldCheck: true for a document excluded by ignorePaths, or disabled by overrides or languageSettings. Before, the option was accepted but ignored. DocumentValidator already worked this way.
  • SpellCheckFileOptions now declares forceCheck, so it can be passed to spellCheckDocument and spellCheckFile with type checking.

fix: --force-check checks the listed files even when ignorePaths or files would skip them (#9300)

Summary

--force-check now checks every file given with --file or --file-list, as its help says. Before, some of those files were still skipped:

  • files matched by ignorePaths in the config;
  • files that don't match the files setting in the config.

Using globs on the command line together with --force-check is now an error, the same as globs with --file:

error: mixing globs and --force-check is not supported

Before, cspell lint --file-list list.txt "**/*.md" --force-check was accepted. To filter a file list by glob, leave out --force-check.


fix: files globs starting with ** no longer skip --file and --file-list files in a project under a dot folder (#9299)

Summary

... (truncated)

Commits
  • f37a244 v10.3.5
  • b36374c chore: Prepare Release v10.3.5 (auto-deploy) (#9277)
  • 93e55c0 fix(cspell-lib): shouldCheckDocument honors the forceCheck option (#9303)
  • 17e31b3 fix: --force-check checks the listed files even when ignorePaths or `file...
  • 5deeffb fix: files globs starting with ** no longer skip --file and `--file-lis...
  • See full diff in compare view

Updates lint-staged from 17.5.1 to 17.6.0

Release notes

Sourced from lint-staged's releases.

v17.6.0

Minor Changes

  • #1850 938d3f4 - Task functions like { title, task } can now use a logger function log() to emit output while the task runs. By default, the output will only be visible if the task fails, unless the --verbose option was used. Additionally, when the task rejects, the error will be shown in the output.

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*': {
    title: 'Fail if PDF files are committed',
    task: async (filepaths, { log }) => {
    const pdfFiles = filepaths.filter((f) => f.toLowerCase().endsWith('.pdf'))
    if (pdfFiles.length > 0) {
    log('PDF files should not be committed: %s', pdfFiles)
    throw new Error('Failed')
    }
    },
    },
    })

  • #1854 30562bc - lint-staged now stages changes to all tracked files modified by tasks, including files that weren’t originally staged or didn’t match the configured globs. This can happen when your task has side-effects, or it's a function that ignores the staged files like () => "prettier --write .".

    If you have unstaged changes in a file and the task also edits that file, your unstaged changes will be staged too. Use --hide-unstaged to hide your changes while tasks run.

Patch Changes

  • #1860 4296532 - The assignment of staged files to lint-staged configuration files (when using multiple, for example in a monorepo) has been rewritten to be more efficient. As a reminder, each staged file is assigned to exactly one configuration (the closest one), even if that config doesn't match the file in its globs.

  • #1861 c45f28a - Fix running parallel tasks for a single glob, when tasks are created by a function. Nesting one level of arrays inside an array of tasks will result in the inner tasks running in parallel. This behavior should now be consistent when creating tasks using functions. In the following example eslint and prettier will run in parallel (for all files, when any JS files are staged):

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*.js': () => [['eslint --max-warnings=0 .', 'prettier --list-different .']],
    })

  • #1859 f0ea69d - Various performance improvements from skipping redundant internal Git calls.

  • #1856 69d7d17 - Partially staged changes are hidden in a uniquely-named patch file to avoid multiple invocations of lint-staged overwriting it. This makes it safer to run lint-staged in multiple worktrees at the same time.

Changelog

Sourced from lint-staged's changelog.

17.6.0

Minor Changes

  • #1850 938d3f4 - Task functions like { title, task } can now use a logger function log() to emit output while the task runs. By default, the output will only be visible if the task fails, unless the --verbose option was used. Additionally, when the task rejects, the error will be shown in the output.

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*': {
    title: 'Fail if PDF files are committed',
    task: async (filepaths, { log }) => {
    const pdfFiles = filepaths.filter((f) => f.toLowerCase().endsWith('.pdf'))
    if (pdfFiles.length > 0) {
    log('PDF files should not be committed: %s', pdfFiles)
    throw new Error('Failed')
    }
    },
    },
    })

  • #1854 30562bc - lint-staged now stages changes to all tracked files modified by tasks, including files that weren’t originally staged or didn’t match the configured globs. This can happen when your task has side-effects, or it's a function that ignores the staged files like () => "prettier --write .".

    If you have unstaged changes in a file and the task also edits that file, your unstaged changes will be staged too. Use --hide-unstaged to hide your changes while tasks run.

Patch Changes

  • #1860 4296532 - The assignment of staged files to lint-staged configuration files (when using multiple, for example in a monorepo) has been rewritten to be more efficient. As a reminder, each staged file is assigned to exactly one configuration (the closest one), even if that config doesn't match the file in its globs.

  • #1861 c45f28a - Fix running parallel tasks for a single glob, when tasks are created by a function. Nesting one level of arrays inside an array of tasks will result in the inner tasks running in parallel. This behavior should now be consistent when creating tasks using functions. In the following example eslint and prettier will run in parallel (for all files, when any JS files are staged):

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*.js': () => [['eslint --max-warnings=0 .', 'prettier --list-different .']],
    })

  • #1859 f0ea69d - Various performance improvements from skipping redundant internal Git calls.

  • #1856 69d7d17 - Partially staged changes are hidden in a uniquely-named patch file to avoid multiple invocations of lint-staged overwriting it. This makes it safer to run lint-staged in multiple worktrees at the same time.

Commits
  • 48f9f4e Merge pull request #1857 from lint-staged/changeset-release/main
  • 16b2e21 chore(changeset): release
  • 195f156 docs: improve changeset
  • 0ba6261 fix: create hidden directory only when required
  • 66ac2de docs: fixes to changesets
  • 80af8d7 Merge pull request #1863 from lint-staged/fix-issues
  • e433488 fix: handle task editing a symlinked file to a regular file, and --fail-on-ch...
  • e5019b3 fix: handle trailing newlines when detecting changed files
  • 74efec8 ci: run Cygwin and MSYS2 tests on Node.js 26
  • 655b7dc fix: use TypeScript types instead of JSDoc
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…dates

Bumps the dependencies group with 4 updates in the / directory: [ws](https://github.com/websockets/ws), [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node), [cspell](https://github.com/streetsidesoftware/cspell/tree/HEAD/packages/cspell) and [lint-staged](https://github.com/lint-staged/lint-staged).


Updates `ws` from 8.21.3 to 8.22.0
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.21.3...8.22.0)

Updates `@types/node` from 26.6.2 to 26.6.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `cspell` from 10.3.4 to 10.3.5
- [Release notes](https://github.com/streetsidesoftware/cspell/releases)
- [Changelog](https://github.com/streetsidesoftware/cspell/blob/main/packages/cspell/CHANGELOG.md)
- [Commits](https://github.com/streetsidesoftware/cspell/commits/v10.3.5/packages/cspell)

Updates `lint-staged` from 17.5.1 to 17.6.0
- [Release notes](https://github.com/lint-staged/lint-staged/releases)
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md)
- [Commits](lint-staged/lint-staged@v17.5.1...v17.6.0)

---
updated-dependencies:
- dependency-name: ws
  dependency-version: 8.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: "@types/node"
  dependency-version: 26.6.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: cspell
  dependency-version: 10.3.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: lint-staged
  dependency-version: 17.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 1, 2026
@changeset-bot

changeset-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 32f0324

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​types/​node@​26.6.2 ⏵ 26.6.31001008196100
Updatedws@​8.21.3 ⏵ 8.22.09910010093100
Updatedlint-staged@​17.5.1 ⏵ 17.6.0100 +110010095 -1100
Updatedcspell@​10.3.4 ⏵ 10.3.598 +110010096 +1100

View full report

@alexander-akait
alexander-akait merged commit 6a11ab1 into main Oct 1, 2026
15 checks passed
@alexander-akait
alexander-akait deleted the dependabot/npm_and_yarn/dependencies-aa7e836124 branch October 1, 2026 08:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant