Skip to content

chore(deps-dev): bump the dependencies group with 4 updates - #682

Merged
webpack[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/dependencies-21a72d97ba
Oct 5, 2026
Merged

webpack[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/dependencies-21a72d97ba

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 4 updates: cspell, eslint-config-webpack, lint-staged and memfs.

Updates cspell from 10.3.4 to 10.3.6

Release notes

Sourced from cspell's releases.

v10.3.6

Fixes

fix: Report unknown CSpell directives again (#9319)

Summary

cspell lint reports unknown in-document directives again, such as cspell:bad-dir, when --validate-directives or validateDirectives: true in the config asks for them. Since 9.1.0 they were found but never shown or counted.

  • --validate-directives and --no-validate-directives override the config setting.
  • An unknown directive counts as an issue, so cspell lint exits with an error, as it did before 9.1.0.
  • The JSON reporter, @cspell/cspell-json-reporter, includes them in its output again.
  • The default reporter and the JSON reporter now ask to receive directive issues. Other reporters still only get them if they ask for them.
  • The command-line flag is now applied as a setting, like --report, so it controls what is shown as well as what is checked.

fix(cspell-io): Keep redirected requests under the private root (#9329)

Summary

createRedirectProvider in cspell-io now only serves requests that map to a location under its private root. A request that would resolve outside the private root is refused with VFSErrorUnsupportedRequest, the same error as a request outside the public root.

  • Refused: a path that starts with a separator (/, \, %2F, %5C) right after the public root.
  • Now served from inside the private root: file names that look like a URL scheme or a drive, such as a:b.txt or C|. They used to resolve to a different URL.

cspell itself does not use createRedirectProvider. This affects projects that use cspell-io directly.

  • The part of the URL after the public root is resolved as a relative path under the private root, and the result is checked to be under the private root: same protocol, same host, and the same path prefix.
  • Results coming back from the private file system are checked the same way before they are shown under the public root.
  • The change is in commit 25359026e1.

... (truncated)

Changelog

Sourced from cspell's changelog.

v10.3.6 (2026-09-29)

Fixes

fix: Report unknown CSpell directives again (#9319)

Summary

cspell lint reports unknown in-document directives again, such as cspell:bad-dir, when --validate-directives or validateDirectives: true in the config asks for them. Since 9.1.0 they were found but never shown or counted.

  • --validate-directives and --no-validate-directives override the config setting.
  • An unknown directive counts as an issue, so cspell lint exits with an error, as it did before 9.1.0.
  • The JSON reporter, @cspell/cspell-json-reporter, includes them in its output again.
  • The default reporter and the JSON reporter now ask to receive directive issues. Other reporters still only get them if they ask for them.
  • The command-line flag is now applied as a setting, like --report, so it controls what is shown as well as what is checked.

fix(cspell-io): Keep redirected requests under the private root (#9329)

Summary

createRedirectProvider in cspell-io now only serves requests that map to a location under its private root. A request that would resolve outside the private root is refused with VFSErrorUnsupportedRequest, the same error as a request outside the public root.

  • Refused: a path that starts with a separator (/, \, %2F, %5C) right after the public root.
  • Now served from inside the private root: file names that look like a URL scheme or a drive, such as a:b.txt or C|. They used to resolve to a different URL.

cspell itself does not use createRedirectProvider. This affects projects that use cspell-io directly.

  • The part of the URL after the public root is resolved as a relative path under the private root, and the result is checked to be under the private root: same protocol, same host, and the same path prefix.
  • Results coming back from the private file system are checked the same way before they are shown under the public root.
  • The change is in commit 25359026e1.

... (truncated)

Commits
  • 8559198 v10.3.6
  • 72e1be3 chore: Prepare Release v10.3.6 (auto-deploy) (#9305)
  • e230ca0 test: Give time-limited RPC and worker tests room on slow runners (#9330)
  • 8eae6b6 fix: Report unknown CSpell directives again (#9319)
  • a5f5111 fix: Don't reuse cached results made with different command-line options (#9318)
  • 2f897be fix: --show-perf-summary shows where all of the run's time goes (#9307)
  • fe37b7b chore: Label per package, and bugs links to its open issues (#9309)
  • f37a244 v10.3.5
  • b36374c chore: Prepare Release v10.3.5 (auto-deploy) (#9277)
  • 93e55c0 fix(cspell-lib): shouldCheckDocument honors the forceCheck option (#9303)
  • Additional commits viewable in compare view

Updates eslint-config-webpack from 4.14.0 to 4.15.0

Release notes

Sourced from eslint-config-webpack's releases.

v4.15.0

Minor Changes

  • Move prettier/prettier out of the recommended configs into the opt-in stylistic/prettier config; run Prettier on its own instead. (by @​alexander-akait in #212)

Patch Changes

  • Turn off jsdoc rules that TypeScript already reports: require-param-type, require-param-name, require-property-name and implements-on-classes. (by @​alexander-akait in #211)

  • Turn off jsdoc/require-next-type, jsdoc/require-throws-type and jsdoc/require-yields-type. (by @​alexander-akait in #210)

  • Check jsdoc/no-restricted-syntax with one combined selector, so it lints faster. (by @​alexander-akait in #208)

Changelog

Sourced from eslint-config-webpack's changelog.

4.15.0

Minor Changes

  • Move prettier/prettier out of the recommended configs into the opt-in stylistic/prettier config; run Prettier on its own instead. (by @​alexander-akait in #212)

Patch Changes

  • Turn off jsdoc rules that TypeScript already reports: require-param-type, require-param-name, require-property-name and implements-on-classes. (by @​alexander-akait in #211)

  • Turn off jsdoc/require-next-type, jsdoc/require-throws-type and jsdoc/require-yields-type. (by @​alexander-akait in #210)

  • Check jsdoc/no-restricted-syntax with one combined selector, so it lints faster. (by @​alexander-akait in #208)

Commits
  • a67ea3a chore(release): new release (#209)
  • 8e7805c feat(stylistic): move prettier/prettier into an opt-in stylistic/prettier con...
  • 8464b5f perf(jsdoc): turn off require-param-type and explain the disabled type rules ...
  • a7db55d fix(jsdoc): turn off require-next-type, require-throws-type and require-yield...
  • dff9d5e perf(jsdoc): check no-restricted-syntax with one combined selector (#208)
  • 16a18a9 chore(deps): bump codecov/codecov-action in the dependencies group (#206)
  • 397f027 chore(deps): bump the dependencies group across 1 directory with 2 updates (#...
  • See full diff in compare view

Updates lint-staged from 17.5.1 to 17.6.0

Release notes

Sourced from lint-staged's releases.

v17.6.0

Minor Changes

  • #1850 938d3f4 - Task functions like { title, task } can now use a logger function log() to emit output while the task runs. By default, the output will only be visible if the task fails, unless the --verbose option was used. Additionally, when the task rejects, the error will be shown in the output.

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*': {
    title: 'Fail if PDF files are committed',
    task: async (filepaths, { log }) => {
    const pdfFiles = filepaths.filter((f) => f.toLowerCase().endsWith('.pdf'))
    if (pdfFiles.length > 0) {
    log('PDF files should not be committed: %s', pdfFiles)
    throw new Error('Failed')
    }
    },
    },
    })

  • #1854 30562bc - lint-staged now stages changes to all tracked files modified by tasks, including files that weren’t originally staged or didn’t match the configured globs. This can happen when your task has side-effects, or it's a function that ignores the staged files like () => "prettier --write .".

    If you have unstaged changes in a file and the task also edits that file, your unstaged changes will be staged too. Use --hide-unstaged to hide your changes while tasks run.

Patch Changes

  • #1860 4296532 - The assignment of staged files to lint-staged configuration files (when using multiple, for example in a monorepo) has been rewritten to be more efficient. As a reminder, each staged file is assigned to exactly one configuration (the closest one), even if that config doesn't match the file in its globs.

  • #1861 c45f28a - Fix running parallel tasks for a single glob, when tasks are created by a function. Nesting one level of arrays inside an array of tasks will result in the inner tasks running in parallel. This behavior should now be consistent when creating tasks using functions. In the following example eslint and prettier will run in parallel (for all files, when any JS files are staged):

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*.js': () => [['eslint --max-warnings=0 .', 'prettier --list-different .']],
    })

  • #1859 f0ea69d - Various performance improvements from skipping redundant internal Git calls.

  • #1856 69d7d17 - Partially staged changes are hidden in a uniquely-named patch file to avoid multiple invocations of lint-staged overwriting it. This makes it safer to run lint-staged in multiple worktrees at the same time.

Changelog

Sourced from lint-staged's changelog.

17.6.0

Minor Changes

  • #1850 938d3f4 - Task functions like { title, task } can now use a logger function log() to emit output while the task runs. By default, the output will only be visible if the task fails, unless the --verbose option was used. Additionally, when the task rejects, the error will be shown in the output.

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*': {
    title: 'Fail if PDF files are committed',
    task: async (filepaths, { log }) => {
    const pdfFiles = filepaths.filter((f) => f.toLowerCase().endsWith('.pdf'))
    if (pdfFiles.length > 0) {
    log('PDF files should not be committed: %s', pdfFiles)
    throw new Error('Failed')
    }
    },
    },
    })

  • #1854 30562bc - lint-staged now stages changes to all tracked files modified by tasks, including files that weren’t originally staged or didn’t match the configured globs. This can happen when your task has side-effects, or it's a function that ignores the staged files like () => "prettier --write .".

    If you have unstaged changes in a file and the task also edits that file, your unstaged changes will be staged too. Use --hide-unstaged to hide your changes while tasks run.

Patch Changes

  • #1860 4296532 - The assignment of staged files to lint-staged configuration files (when using multiple, for example in a monorepo) has been rewritten to be more efficient. As a reminder, each staged file is assigned to exactly one configuration (the closest one), even if that config doesn't match the file in its globs.

  • #1861 c45f28a - Fix running parallel tasks for a single glob, when tasks are created by a function. Nesting one level of arrays inside an array of tasks will result in the inner tasks running in parallel. This behavior should now be consistent when creating tasks using functions. In the following example eslint and prettier will run in parallel (for all files, when any JS files are staged):

    import { defineConfig } from 'lint-staged/config'
    export default defineConfig({
    '*.js': () => [['eslint --max-warnings=0 .', 'prettier --list-different .']],
    })

  • #1859 f0ea69d - Various performance improvements from skipping redundant internal Git calls.

  • #1856 69d7d17 - Partially staged changes are hidden in a uniquely-named patch file to avoid multiple invocations of lint-staged overwriting it. This makes it safer to run lint-staged in multiple worktrees at the same time.

Commits
  • 48f9f4e Merge pull request #1857 from lint-staged/changeset-release/main
  • 16b2e21 chore(changeset): release
  • 195f156 docs: improve changeset
  • 0ba6261 fix: create hidden directory only when required
  • 66ac2de docs: fixes to changesets
  • 80af8d7 Merge pull request #1863 from lint-staged/fix-issues
  • e433488 fix: handle task editing a symlinked file to a regular file, and --fail-on-ch...
  • e5019b3 fix: handle trailing newlines when detecting changed files
  • 74efec8 ci: run Cygwin and MSYS2 tests on Node.js 26
  • 655b7dc fix: use TypeScript types instead of JSDoc
  • Additional commits viewable in compare view

Updates memfs from 4.79.0 to 4.80.0

Release notes

Sourced from memfs's releases.

Release v4.80.0

What's Changed

New Contributors

Full Changelog: streamich/memfs@v4.79.0...v4.80.0

Commits
  • adae41a chore: release v4.80.0
  • d9cfa18 Merge pull request #1298 from Firatakti/codex/fsa-sync-timeout
  • fe75fbc feat: allow configuring the synchronous FSA worker timeout
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dependencies group with 4 updates: [cspell](https://github.com/streetsidesoftware/cspell/tree/HEAD/packages/cspell), [eslint-config-webpack](https://github.com/webpack/eslint-config-webpack), [lint-staged](https://github.com/lint-staged/lint-staged) and [memfs](https://github.com/streamich/memfs).


Updates `cspell` from 10.3.4 to 10.3.6
- [Release notes](https://github.com/streetsidesoftware/cspell/releases)
- [Changelog](https://github.com/streetsidesoftware/cspell/blob/main/packages/cspell/CHANGELOG.md)
- [Commits](https://github.com/streetsidesoftware/cspell/commits/v10.3.6/packages/cspell)

Updates `eslint-config-webpack` from 4.14.0 to 4.15.0
- [Release notes](https://github.com/webpack/eslint-config-webpack/releases)
- [Changelog](https://github.com/webpack/eslint-config-webpack/blob/main/CHANGELOG.md)
- [Commits](webpack/eslint-config-webpack@v4.14.0...v4.15.0)

Updates `lint-staged` from 17.5.1 to 17.6.0
- [Release notes](https://github.com/lint-staged/lint-staged/releases)
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md)
- [Commits](lint-staged/lint-staged@v17.5.1...v17.6.0)

Updates `memfs` from 4.79.0 to 4.80.0
- [Release notes](https://github.com/streamich/memfs/releases)
- [Changelog](https://github.com/streamich/memfs/blob/master/CHANGELOG.md)
- [Commits](streamich/memfs@v4.79.0...v4.80.0)

---
updated-dependencies:
- dependency-name: cspell
  dependency-version: 10.3.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: eslint-config-webpack
  dependency-version: 4.15.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: lint-staged
  dependency-version: 17.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: memfs
  dependency-version: 4.80.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 5, 2026
@changeset-bot

changeset-bot Bot commented Oct 5, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 6bffbd0

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@webpack
webpack Bot enabled auto-merge (squash) October 5, 2026 06:53
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedmemfs@​4.79.0 ⏵ 4.80.0991009396 +1100
Updatedeslint-config-webpack@​4.14.0 ⏵ 4.15.095 +410010099 +1100
Updatedlint-staged@​17.5.1 ⏵ 17.6.0100 +110010095 -1100
Updatedcspell@​10.3.4 ⏵ 10.3.698 +110010096 +1100

View full report

@webpack
webpack Bot merged commit 98e0668 into main Oct 5, 2026
37 checks passed
@webpack
webpack Bot deleted the dependabot/npm_and_yarn/dependencies-21a72d97ba branch October 5, 2026 06:55
@codspeed

codspeed Bot commented Oct 5, 2026

Copy link
Copy Markdown

Merging this PR will regress 1 benchmark

⚠️ Different runtime environments detected

Some benchmarks with significant performance changes were compared across different runtime environments,
which may affect the accuracy of the results.

Open the report in CodSpeed to investigate

⚡ 2 improved benchmarks
❌ 1 regressed benchmark
✅ 139 untouched benchmarks

Warning

Please fix the performance issues or acknowledge them on CodSpeed.

Performance Changes

Mode Benchmark BASE HEAD Efficiency
❌ Memory deep-package-subpath: pkg/a/b/c requests (warm) 2.2 KB 3.5 KB -36.95%
⚡ Memory alias-wildcard-scan: 100+1 wildcard + 1 exact 2.7 KB 1.5 KB +88.11%
⚡ Memory array-alias: @ -> [preferred, fallback] (warm) 3.6 KB 2.2 KB +64.75%

Tip

Investigate this regression by commenting @codspeedbot fix this regression on this PR, or directly use the CodSpeed MCP with your agent.


Comparing dependabot/npm_and_yarn/dependencies-21a72d97ba (6bffbd0) with main (c65e40a)

Open in CodSpeed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants