build(deps): bump lru-cache from 11.2.2 to 11.3.5#14
Closed
dependabot[bot] wants to merge 1 commit into
Closed
Conversation
Bumps [lru-cache](https://github.com/isaacs/node-lru-cache) from 11.2.2 to 11.3.5. - [Changelog](https://github.com/isaacs/node-lru-cache/blob/main/CHANGELOG.md) - [Commits](isaacs/node-lru-cache@v11.2.2...v11.3.5) --- updated-dependencies: - dependency-name: lru-cache dependency-version: 11.3.5 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
4ea7a61 to
226bb60
Compare
7 tasks
Owner
|
Superseded by #18 (bulk dep bump). |
Contributor
Author
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
theagenticguy
added a commit
that referenced
this pull request
Apr 23, 2026
## Summary Sweep of every outdated direct dependency in the workspace, bringing each one to its latest version — except for two intentional holds (TypeScript 6, Zod 4) that need their own migration PRs. ## What's bumped **Safe minors + patches** (no behavior changes on our surface): | Package | From | To | |---|---|---| | `@biomejs/biome` | 2.4.0 | 2.4.12 | | `fast-xml-parser` | 5.7.0 | 5.7.1 | | `piscina` | 5.1.3 | 5.1.4 | | `envinfo` | 7.14.0 | 7.21.0 | | `lru-cache` | 11.2.2 | 11.3.5 | **Safe majors** (no source-level breakage; verified via full build + test matrix): | Package | From | To | |---|---|---| | `@apidevtools/swagger-parser` | 10.1.1 | 12.1.0 | | `@commitlint/cli` | 19.6.1 | 20.5.0 | | `@commitlint/config-conventional` | 19.6.0 | 20.5.0 | | `@types/node` | 20.14.0 | 22.19.17 (Node 22 LTS) | | `commander` | 13.1.0 | 14.0.3 | | `listr2` | 9.0.4 | 10.2.1 | | `write-file-atomic` | 6.0.0 | 7.0.1 | **Deliberately deferred** (need real migration work; track in follow-up PRs): - `typescript` 5.9.3 → 6.x — many workspace deps peer-declare `typescript@^5`; the jump needs a compatibility sweep first. - `zod` 3 → 4 — breaking changes (`.merge()` → `.extend()`, stricter coercion, different result shape) that touch the MCP + SARIF schema layers. ## License allowlist update `lru-cache` switched its declared license from `ISC` → `BlueOak-1.0.0` at 11.3.x. BlueOak-1.0.0 is an OSI-approved permissive license (explicitly designed as an MIT/ISC-class modernization with no ShareAlike / attribution friction). Added `BlueOak-1.0.0` and `0BSD` to the CI license allowlist (`.github/workflows/ci.yml`, `mise.toml`) to match what's actually in the SBOM today. `SECURITY.md` + `CONTRIBUTING.md` updated to mirror. ## Supply chain - `osv-scanner` — 0 issues on the refreshed 705-package lockfile. - `SBOM.cdx.json` regenerated from the new lockfile. - `THIRD_PARTY_LICENSES.md` regenerated (705 components). ## Drive-by fix `packages/cli/src/commands/setup.test.ts` asserted the bundled plugin manifest version was `2.0.0` (stale from the pre-launch internal versioning). Updated to `0.1.0` to match the launch version and unblock `pnpm -r test`. ## Closes Should supersede these open Dependabot PRs (will auto-close on next scan): #6, #7, #8, #9, #10, #11, #12, #13, #14, #15. ## Test plan - [x] `pnpm install` resolves cleanly - [x] `pnpm -r build` — all workspaces green - [x] `pnpm -r exec tsc --noEmit` — 0 type errors - [x] `pnpm -r test` — 1 stale-assertion fixed, remainder green - [x] `bash scripts/check-banned-strings.sh` — PASS - [x] `osv-scanner scan source --lockfile=pnpm-lock.yaml` — 0 issues - [x] `license-checker-rseidelsohn --onlyAllow '...'` — 0 violations
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps lru-cache from 11.2.2 to 11.3.5.
Changelog
Sourced from lru-cache's changelog.
... (truncated)
Commits
ad1060711.3.5697314eminify browser export1723a9511.3.443b7583add browser esm export condition to not even try to load diagnostics channele9ae122comment typo6de4a00correct comment (it's not about TLA)21db42b11.3.328e4dacRemove TLA, feature is DOA :(36204ccremove unnecessary unused internal exportb08aa7atest to ensure TLA is not in use in nodeInstall script changes
This version modifies
preparescript that runs during installation. Review the package contents before updating.