build(deps): bump the dependencies group with 10 updates#230
Conversation
Bumps the dependencies group with 10 updates: | Package | From | To | | --- | --- | --- | | [@google/genai](https://github.com/googleapis/js-genai) | `2.6.0` | `2.7.0` | | [commander](https://github.com/tj/commander.js) | `14.0.3` | `15.0.0` | | [inquirer](https://github.com/SBoudrias/Inquirer.js) | `13.4.3` | `14.0.1` | | [openai](https://github.com/openai/openai-node) | `6.39.0` | `6.39.1` | | [@typescript/native-preview](https://github.com/microsoft/typescript-go) | `7.0.0-dev.20260523.1` | `7.0.0-dev.20260527.2` | | [devtools-protocol](https://github.com/ChromeDevTools/devtools-protocol) | `0.0.1634055` | `0.0.1638241` | | [es-toolkit](https://github.com/toss/es-toolkit) | `1.46.1` | `1.47.0` | | [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.51.0` | `0.52.0` | | [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.66.0` | `1.67.0` | | [puppeteer-core](https://github.com/puppeteer/puppeteer) | `25.0.4` | `25.1.0` | Updates `@google/genai` from 2.6.0 to 2.7.0 - [Release notes](https://github.com/googleapis/js-genai/releases) - [Changelog](https://github.com/googleapis/js-genai/blob/main/CHANGELOG.md) - [Commits](googleapis/js-genai@v2.6.0...v2.7.0) Updates `commander` from 14.0.3 to 15.0.0 - [Release notes](https://github.com/tj/commander.js/releases) - [Changelog](https://github.com/tj/commander.js/blob/master/CHANGELOG.md) - [Commits](tj/commander.js@v14.0.3...v15.0.0) Updates `inquirer` from 13.4.3 to 14.0.1 - [Release notes](https://github.com/SBoudrias/Inquirer.js/releases) - [Commits](https://github.com/SBoudrias/Inquirer.js/compare/inquirer@13.4.3...inquirer@14.0.1) Updates `openai` from 6.39.0 to 6.39.1 - [Release notes](https://github.com/openai/openai-node/releases) - [Changelog](https://github.com/openai/openai-node/blob/master/CHANGELOG.md) - [Commits](openai/openai-node@v6.39.0...v6.39.1) Updates `@typescript/native-preview` from 7.0.0-dev.20260523.1 to 7.0.0-dev.20260527.2 - [Changelog](https://github.com/microsoft/typescript-go/blob/main/CHANGES.md) - [Commits](https://github.com/microsoft/typescript-go/commits) Updates `devtools-protocol` from 0.0.1634055 to 0.0.1638241 - [Commits](ChromeDevTools/devtools-protocol@v0.0.1634055...v0.0.1638241) Updates `es-toolkit` from 1.46.1 to 1.47.0 - [Release notes](https://github.com/toss/es-toolkit/releases) - [Changelog](https://github.com/toss/es-toolkit/blob/main/CHANGELOG.md) - [Commits](toss/es-toolkit@v1.46.1...v1.47.0) Updates `oxfmt` from 0.51.0 to 0.52.0 - [Release notes](https://github.com/oxc-project/oxc/releases) - [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md) - [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.52.0/npm/oxfmt) Updates `oxlint` from 1.66.0 to 1.67.0 - [Release notes](https://github.com/oxc-project/oxc/releases) - [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md) - [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.67.0/npm/oxlint) Updates `puppeteer-core` from 25.0.4 to 25.1.0 - [Release notes](https://github.com/puppeteer/puppeteer/releases) - [Changelog](https://github.com/puppeteer/puppeteer/blob/main/CHANGELOG.md) - [Commits](puppeteer/puppeteer@puppeteer-core-v25.0.4...puppeteer-core-v25.1.0) --- updated-dependencies: - dependency-name: "@google/genai" dependency-version: 2.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: commander dependency-version: 15.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: inquirer dependency-version: 14.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies - dependency-name: openai dependency-version: 6.39.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: "@typescript/native-preview" dependency-version: 7.0.0-dev.20260527.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: devtools-protocol dependency-version: 0.0.1638241 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: es-toolkit dependency-version: 1.47.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: oxfmt dependency-version: 0.52.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: oxlint dependency-version: 1.67.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: puppeteer-core dependency-version: 25.1.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
|
Codex review: needs maintainer review before merge. Reviewed May 29, 2026, 7:04 PM ET / 23:04 UTC. Summary Reproducibility: not applicable. this is dependency maintenance, not a reported runtime bug. Source inspection identifies the affected CLI, TUI, provider, tooling, and browser paths to validate. Review metrics: 3 noteworthy metrics.
Merge readiness Overall follows the weaker of proof and patch quality, so missing proof can cap an otherwise strong patch. Rank-up moves:
Risk before merge
Maintainer options:
Next step before merge
Security Review detailsBest possible solution: Land the grouped dependency bump only after focused CLI/help/doctor, TUI, install/build/check, and browser smoke evidence; split commander or inquirer out if either major upgrade needs investigation. Do we have a high-confidence way to reproduce the issue? Not applicable: this is dependency maintenance, not a reported runtime bug. Source inspection identifies the affected CLI, TUI, provider, tooling, and browser paths to validate. Is this the best way to solve the issue? Unclear until validation: the dependency refresh is a reasonable maintenance path, but grouping semver-major commander and inquirer with browser/tooling updates is safest only with focused smoke evidence or a split if behavior changes. AGENTS.md: found and applied where relevant. Codex review notes: model gpt-5.5, reasoning high; reviewed against 6019a199e44c. Label changesLabel changes:
Label justifications:
Evidence reviewedWhat I checked:
Likely related people:
What the crustacean ranks mean
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics. How this review workflow works
|
Bumps the dependencies group with 10 updates:
2.6.02.7.014.0.315.0.013.4.314.0.16.39.06.39.17.0.0-dev.20260523.17.0.0-dev.20260527.20.0.16340550.0.16382411.46.11.47.00.51.00.52.01.66.01.67.025.0.425.1.0Updates
@google/genaifrom 2.6.0 to 2.7.0Release notes
Sourced from @google/genai's releases.
Changelog
Sourced from @google/genai's changelog.
Commits
2821346chore(main): release 2.7.0 (#1630)54a692bfeat: additional computer_use field support for vertex.d75582afeat: Add Skill Registry ListSkills and DeleteSkill to SDK3cc830efeat(interaction-api): Allow "text/csv" as a supported document mime type for...58c8c7efeat(interaction-api): Enable BigQuery tool in Deep Research config.b25d22fchore: Internal cleanup418cc35feat: Support Reinforcement Tuning in GenAI SDKUpdates
commanderfrom 14.0.3 to 15.0.0Release notes
Sourced from commander's releases.
... (truncated)
Changelog
Sourced from commander's changelog.
Commits
ba6d13dFix release dates in changelog (#2523)a752ed9Pin GitHub actions with hash (#2521)74d5dfeDrop EOL node 20 from test matrix, and add node 26 (#2520)6df9b68Update details for 15.0.0 release (#2519)01ce5d0Remove jest esm examples (#2517)d785d8bUpdate dependencies (#2518)9098b48Update dependencies (#2506)373f660Use node:util stripVTControlCharacters instead of own code (#2486)987f289Use simple match in test (to avoid warning about expensive regex) (#2485)0ea3bb3Update dependecies and lint (#2489)Updates
inquirerfrom 13.4.3 to 14.0.1Release notes
Sourced from inquirer's releases.
Commits
b43359dchore: Publish new release24ecae2chore: fix yarn.lockb078d97fix: validate package engine compatibility3a49f9fchore(deps-dev): Bump oxfmt in the formatting group (#2143)9cc492fchore(deps): Bump fast-wrap-ansi from 0.2.0 to 0.2.2 (#2146)feb7edfchore(deps-dev): Bump@types/nodein the types group (#2145)a05eb68chore(deps-dev): Bump the build group with 3 updates (#2144)f6ddfcechore(deps-dev): Bump the linting group with 3 updates (#2142)5ca6d11chore: Publish new release2520349feat(@inquirer/core): support keybindings env defaultsUpdates
openaifrom 6.39.0 to 6.39.1Release notes
Sourced from openai's releases.
Changelog
Sourced from openai's changelog.
Commits
6c11a74release: 6.39.1a91a7aafix: Improve undici dispatcher mismatch guidance (#1898)13520f4chore(internal): codegen related updatea22dd6bMerge pull request #1867 from openai/docs/readme-gpt-5.500e1d1aUpdate README models to gpt-5.5 and gpt-realtime-2Updates
@typescript/native-previewfrom 7.0.0-dev.20260523.1 to 7.0.0-dev.20260527.2Commits
Updates
devtools-protocolfrom 0.0.1634055 to 0.0.1638241Commits
2f5c261Roll protocol to r1638241c2ef27fRoll protocol to r16374857919a58Roll protocol to r1636713b6b27f6Roll protocol to r1635485Updates
es-toolkitfrom 1.46.1 to 1.47.0Release notes
Sourced from es-toolkit's releases.
Changelog
Sourced from es-toolkit's changelog.
Commits
9f35cf9v1.47.0b73e0bcdocs[playground]: add link to playground editor title (#1735)a6d40dfdocs[server]: add localized server docs (#1733)ecbdd36docs[playground]: separate playground page layout (#1732)52ac49cdocs(compat): align method chaining guidance across locales (#1731)c011690fix(docs): fix issues in playground page (#1727)03ca6eafix(uniqWith): match lodash comparator argument order in compat (#1729)8a978e3build(deps): bump dahlia/submark (#1730)6d3ca81docs: introduce flavor switcher and co-locate compat under /compat/ (#1699)970ae85fix: add alt text to VitePress logo (#1722)Updates
oxfmtfrom 0.51.0 to 0.52.0Changelog
Sourced from oxfmt's changelog.
... (truncated)
Commits
68b455drelease(apps): oxlint v1.67.0 && oxfmt v0.52.0 (#22735)16b8058feat(oxfmt): Supportvite-plus/resolveConfigfor vite.config.ts (#22454)Updates
oxlintfrom 1.66.0 to 1.67.0Release notes
Sourced from oxlint's releases.
... (truncated)
Changelog
Sourced from oxlint's changelog.
Commits
68b455drelease(apps): oxlint v1.67.0 && oxfmt v0.52.0 (#22735)b84941efeat(linter/vue): implement no-expose-after-await rule (#22675)98b98c1feat(linter/vue): implement no-computed-properties-in-data rule (#22674)2d4c919feat(oxlint): Supportvite-plus/resolveConfigfor vite.config.ts (#22456)2a60012feat(linter/vue): implement require-render-return rule (#22613)9f227fdfeat(linter/vue): implement no-deprecated-props-default-this rule (#21892)87f065efeat(linter/vue): implement return-in-emits-validator rule (#21935)ea0380cfeat(linter/unicorn): implementimport-stylerule (#22173)dde40fefeat(linter/vue): implement no-watch-after-await rule (#22006)a735eb0feat(linter/vue): implement valid-next-tick rule (#22531)Updates
puppeteer-corefrom 25.0.4 to 25.1.0Release notes
Sourced from puppeteer-core's releases.
Changelog
Sourced from puppeteer-core's changelog.
Commits
ede6669chore: release main (#15056)7bc09e7chore(deps): bump the all group with 5 updates (#15052)8c81170chore(deps): bump the all group in /website with 3 updates (#15051)09eced5chore: update lock53b9fdachore(deps): bump the dependencies group with 2 updates (#15049)d842411chore(deps): bump node from050bf2bto8530f76in /docker in the all grou...1d2a569docs: document read-only Docker directories (#15048)ab0171dfix: support concurrency in progress bars (#15045)51db32afix: improve progress bar and install (#15042)d32384bchore(deps): bump qs and express in /website (#15040)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions