Skip to content

build(deps-dev): bump the tooling-minor-patch group with 2 updates - #144

Merged
hetaoBackend merged 2 commits into
mainfrom
dependabot/npm_and_yarn/tooling-minor-patch-b847abed45
Sep 18, 2026
Merged

hetaoBackend merged 2 commits into
mainfrom
dependabot/npm_and_yarn/tooling-minor-patch-b847abed45

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 18, 2026

Copy link
Copy Markdown
Contributor

Bumps the tooling-minor-patch group with 2 updates: dependency-cruiser and jscpd.

Updates dependency-cruiser from 18.2.0 to 18.3.1

Release notes

Sourced from dependency-cruiser's releases.

v18.3.1

🐛 fixes

  • aed44794 fix(extract/swc): finds the swc Visitor when bun hands over the default export (#1093) - thanks @​kurovskyiii for raising the issue and providing the fix in the pull request.

👷 maintenance

  • 0b873f48 chore(npm): updates all external devDependencies

v18.3.0

✨ features

  • Updates to the 'baseline' feature
    • feat: makes it possible to update the baseline "shrink-only", so violations that are fixed get removed, but no new ones are added (#1088/ #1091/ #1085)
    • feat(cli): exposes the baseline feature as a regular --baseline option (with same functionality as depcruise-baseline command) (#1084)
    • feat(baseline): when the baseline is updated show how many are new, same or removed (#1079)
    • Thanks to @​yunusdim for the idea(s) to introduce these features.
  • Improvements to processing with the 'swc' compiler
    • ee229c36 feat(extract/swc): adds support for parsing tsx/jsx (#1086) thanks @​JPBuildsRoot for the issue & initial code that led to this feature
    • 2aa2e34e feat(extract/swc): adds support recognizing type-only imports (#1087) thanks @​JPBuildsRoot for raising the issue that led to this feature

👷 maintenance

  • ed21436e/ ceb7d676 build(npm): updates external dependencies
  • 1f28f44a perf(utl): initializes severity translation table only once
  • 88c7cf9e docs: standardizes the command name for running the command to dependency-cruiser (#1083)
  • 9a8a3dd1 chore(doc): marks depcruise-baseline command as deprecated in favor of dependency-cruiser --baseline (#1090)
  • 400553d9 chore(report): takes x-dot-webpage out of experimental and names it dot-webpage (#1089)
Commits
  • 62c78b6 18.3.1
  • 0b873f4 chore(npm): updates all external devDependencies
  • aed4479 fix(extract/swc): finds the swc Visitor when bun hands over the default expor...
  • 5e067a0 18.3.0
  • ceb7d67 build(npm): updates external dependencies
  • 66d9d5c feat(cli): replaces --baseline-shrink-only option with --baseline-mode option...
  • 9a8a3dd chore(doc): marks depcruise-baseline command as deprecated in favor of depend...
  • 400553d chore(report): takes x-dot-webpage out of experimental and names it dot-webpa...
  • 786431a feat(cli): adds --baseline-shrink-only option (#1088)
  • 2aa2e34 feat(extract/swc): adds support recognizing type-only imports (#1087)
  • Additional commits viewable in compare view

Updates jscpd from 5.2.0 to 5.2.1

Release notes

Sourced from jscpd's releases.

Release v5.2.1

New Features

  • --history: duplication trend over git historyjscpd src --history v5.0.0..HEAD scans every commit in the range in a detached worktree and prints a bar chart, a per-commit table with the change between points, the overall trend and how far --threshold could be tightened without failing the build. --history-since, --history-every N and --history-limit N narrow the range; the JSON reporter carries the points under a history key and the GitHub Action takes a history input. (#1002, #1050, #1052)
  • Exit codes you can gate on, and --fail-on-empty — an unknown --format, a scan path that does not exist and a reporter that cannot write its file now print an error and exit 1 instead of passing with an empty report. --fail-on-empty (config key failOnEmpty, action input fail-on-empty) turns "analyzed no files" into a failure, so a mistyped path or an over-broad ignore cannot look like a clean run. (#1047, #1049)
  • PyPI: pip install jscpd — the release now publishes eight platform wheels built from the same prebuilt binaries as the npm and GitHub Release artifacts, so pip install jscpd and uvx jscpd get the Rust engine with no Python code and no Node.js runtime involved. The repository-hosted pre-commit hook installs from PyPI instead of npm, which removes Node.js from the pre-commit path. (#1037, #1039)

Bug Fixes

  • An open clone could be stretched past the file it started in — while growing a clone the detector accepted a continuation from any stored occurrence of the next window, so a third file that shared the same text but continued differently could extend a fragment beyond what its own file contains. The clone was then dropped or reported with mismatched ends (fixtures/haxe reported file1.hx [1:1 - 62:76] against file2.hx [1:1 - 62:2]). The match now asks first whether the clone's own anchor continues, and starts a new clone when it does not, so N-way copies no longer lose pairs. (#1033, #1034)
  • The XML report could be rejected by every parser — a clone containing a byte XML 1.0 cannot represent (an ANSI escape, a form feed) was written verbatim, and xmllint refused the file with PCDATA invalid Char value 27; ]]> inside a fragment closed the CDATA section early, and attribute values were escaped twice. Such characters are now replaced with U+FFFD, ]]> is split across two CDATA sections, and paths are escaped once. (#375, #1055)
  • --follow-symlinks renamed and double-counted linked files — a file reached through a symlink was reported by its resolved real path, which could be an absolute path outside the scan root, so the report and --ignore disagreed about its name; a file reachable through two paths counted as two sources, and a file symlink next to its target was reported as a clone of itself. Files now keep the path they were found at, and each real file is scanned once. (#1059, #1060)

Other

  • Symlinks are skipped by default in v5 — v4 followed them unless --noSymlinks was set; v5 needs --follow-symlinks (config key followSymlinks, and a v4 noSymlinks: false still maps to following). This was true in every 5.x release but undocumented, and it silently drops a corpus mounted through a symlink. Now in the README and the migration table. (#1059)
  • CITATION.cff and a Citation section — GitHub's "Cite this repository" button and a BibTeX entry for the papers that use jscpd as their detector. The version and release date are kept in step by sync-version.mjs. (#1051)
  • Docs: jscpd is language-aware — the README and the Rust docs now say that detection runs on language tokens, per-format comment and string syntax with the oxc parser for JavaScript/TypeScript, rather than on raw text. (#1048)
  • Agent skills know about clone kinds, the summary and their noise — the bundled jscpd and dry-refactoring skills (npx skills add kucherenko/jscpd) document --summary, the Type-2 and Type-3 flags with their kind suffixes, and warn that normalized passes surface look-alike code, with conservative defaults and a triage step before refactoring. (#1056, #1057)
  • console-full prints the --history block like console does, and the test scaffolding behind the CLI, MCP, reporter and finder suites was deduplicated. (#1053)
  • CI: the npm platform-package gate polls against a 5-minute deadline instead of a fixed sleep, so a slow registry no longer fails a release that would have succeeded. (#1032)

Dependencies

  • Bump askama from 0.16.0 to 0.16.1 in /rust (#1045)
  • Bump taiki-e/install-action from 2.87.3 to 2.87.8 in /.github/workflows (#1046)

Thank You ❤️

  • @​mnahkies for correcting the ignore examples in the README — --ignore-pattern has no short flag and a bare node_modules does not match, since globs are matched against the whole path (#1038)

Published Packages

  • cpd-core@0.1.13 on crates.io
  • cpd-finder@0.1.16 on crates.io
  • cpd-reporter@0.1.14 on crates.io
  • cpd-tokenizer@0.1.15 on crates.io
  • jscpd@5.2.1 on crates.io
  • cpd@5.2.1 on npm
  • jscpd@5.2.1 on npm
  • jscpd-darwin-arm64@5.2.1 on npm
  • jscpd-darwin-x64@5.2.1 on npm
  • jscpd-linux-x64-gnu@5.2.1 on npm
  • jscpd-linux-arm64-gnu@5.2.1 on npm
  • jscpd-linux-x64-musl@5.2.1 on npm
  • jscpd-linux-arm64-musl@5.2.1 on npm
  • jscpd-windows-x64-msvc@5.2.1 on npm
  • jscpd-windows-arm64-msvc@5.2.1 on npm
  • jscpd==5.2.1 on PyPI

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the tooling-minor-patch group with 2 updates: [dependency-cruiser](https://github.com/sverweij/dependency-cruiser) and [jscpd](https://github.com/kucherenko/jscpd/tree/HEAD/rust/jscpd).


Updates `dependency-cruiser` from 18.2.0 to 18.3.1
- [Release notes](https://github.com/sverweij/dependency-cruiser/releases)
- [Changelog](https://github.com/sverweij/dependency-cruiser/blob/main/CHANGELOG.md)
- [Commits](sverweij/dependency-cruiser@v18.2.0...v18.3.1)

Updates `jscpd` from 5.2.0 to 5.2.1
- [Release notes](https://github.com/kucherenko/jscpd/releases)
- [Commits](https://github.com/kucherenko/jscpd/commits/v5.2.1/rust/jscpd)

---
updated-dependencies:
- dependency-name: dependency-cruiser
  dependency-version: 18.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: tooling-minor-patch
- dependency-name: jscpd
  dependency-version: 5.2.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: tooling-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 18, 2026
@dependabot
dependabot Bot requested a review from hetaoBackend as a code owner September 18, 2026 11:31
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 18, 2026

@hetaoBackend hetaoBackend left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the dependency and lockfile changes. Source verification passed on Linux, macOS, and Windows with Node 24, including the full Linux typecheck. Release audit, including the Node 22 build and source/distribution scans, also passed. No blocking findings.

@hetaoBackend
hetaoBackend merged commit 17b8ded into main Sep 18, 2026
8 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/tooling-minor-patch-b847abed45 branch September 18, 2026 13:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant