Skip to content

build(deps-dev): bump typescript from 5.9.3 to 7.0.2 - #32

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/typescript-7.0.2
Open

build(deps-dev): bump typescript from 5.9.3 to 7.0.2#32
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/typescript-7.0.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 9, 2026

Copy link
Copy Markdown
Contributor

Bumps typescript from 5.9.3 to 7.0.2.

Release notes

Sourced from typescript's releases.

TypeScript 6.0.3

For release notes, check out the release announcement blog post.

Downloads are available on:

TypeScript 6.0

For release notes, check out the release announcement blog post.

Downloads are available on:

TypeScript 6.0 Beta

For release notes, check out the release announcement.

Downloads are available on:

Commits
Maintainer changes

This version was pushed to npm by microsoft1es, a new releaser for typescript since your current version.



Note

Medium Risk
Major compiler upgrade (5→7) may introduce new type-check failures in CI without changing runtime behavior; scope is limited to dev tooling in two packages.

Overview
Bumps the TypeScript dev dependency from ^5.7.0 (lockfile 5.9.3) to ^7.0.2 in governance-sdk and governance-sdk-platform, with package-lock.json updated to match.

The lockfile reflects TypeScript 7’s packaging: many optional @typescript/typescript-* platform packages and a raised Node engine (>=16.20.0); the published typescript bin list in the lock now only includes tsc (no tsserver entry). No application source changes—only compile/lint (tsc, tsc --noEmit) tooling.

Reviewed by Cursor Bugbot for commit a2bdadf. Bugbot is set up for automated code reviews on this repo. Configure here.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 9, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/typescript-7.0.2 branch 2 times, most recently from 42b2bb3 to 0a43c21 Compare July 20, 2026 11:56
Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.9.3 to 7.0.2.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/commits)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/typescript-7.0.2 branch from 0a43c21 to a2bdadf Compare July 23, 2026 08:47
lua-stefan-kruger added a commit that referenced this pull request Sep 3, 2026
Resolves Dependabot alert #32 for @humanfs/node <0.16.8 in the nested
examples/demo-app/package-lock.json. Adds an explicit ^0.16.8 floor to
examples/demo-app devDependencies and regenerates the nested lock.

Tail-collapse: also bumps nanoid 3.3.16 -> 3.3.18 (floor ^3.3.18) found
below floor in the same lock. browserslist/js-yaml/postcss already at or
above floor; qs/fast-uri/@xmldom/xmldom not present.

Co-authored-by: lua-stefan-kruger <security-bot@lua.ai>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants