chore(deps): bump inquirer from 13.3.0 to 13.3.2#304
chore(deps): bump inquirer from 13.3.0 to 13.3.2#304dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps [inquirer](https://github.com/SBoudrias/Inquirer.js) from 13.3.0 to 13.3.2. - [Release notes](https://github.com/SBoudrias/Inquirer.js/releases) - [Commits](https://github.com/SBoudrias/Inquirer.js/compare/inquirer@13.3.0...inquirer@13.3.2) --- updated-dependencies: - dependency-name: inquirer dependency-version: 13.3.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits. |
✔️ Bundle Size Analysis
Bundle breakdown |
There was a problem hiding this comment.
LGTM — straightforward Dependabot patch bump of inquirer (13.3.0 → 13.3.2), lock file only.
Extended reasoning...
Overview
This is an automated Dependabot PR that bumps inquirer from 13.3.0 to 13.3.2. The only file changed is pnpm-lock.yaml. The upstream release notes indicate 13.3.1 was a dependency bump and 13.3.2 fixed a broken release process — purely maintenance changes.
Security risks
None. This is a patch version bump of a CLI prompting library with no security-sensitive surface. The lock file changes are all consistent version bumps of @inquirer/* sub-packages and an incidental @sourcegraph/amp transitive dependency update.
Level of scrutiny
Minimal scrutiny required. This is a lock-file-only patch bump generated by Dependabot for a non-security-critical dev dependency. No source code, configuration, or CI pipelines are modified.
Other factors
No outstanding reviewer comments. No bugs found. The PR is fully mechanical with no design decisions involved. The package.json specifier (^13.2.2) already permitted this range, so no semver policy change is needed.
Bumps inquirer from 13.3.0 to 13.3.2.
Release notes
Sourced from inquirer's releases.
Commits
b218fccchore: Publish new releaseb6aabedfix: set prepublish script1ce0319chore: Publish new release62a1b2dMerge pull request #2031 from SBoudrias/sboudrias/debug-xterm-80g09fcc6cchore(@inquirer/testing): fix formatting56bdf30fix(@inquirer/testing): resolve xterm CJS named export error under native Nod...58d3bf0chore(deps): Bump brace-expansion from 1.1.11 to 1.1.12 (#2029)f9a3adbMerge pull request #2026 from SBoudrias/emdash/semver-315264f5dachore(setup-packages): simplify coerce using tryParseRangefeab678chore(setup-packages): replace semver with std-semverDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)