Skip to content

chore(deps-dev): bump the dev-dependencies group with 19 updates - #94

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dev-dependencies-846b0e532d
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dev-dependencies-846b0e532d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown

Bumps the dev-dependencies group with 19 updates:

Package From To
@arethetypeswrong/cli 0.18.4 0.18.5
@changesets/cli 2.31.0 3.0.3
@cosyte/eslint-config 0.0.3 0.1.0
@cosyte/prettier-config 0.0.2 0.1.0
@cosyte/test-utils 0.0.2 0.1.0
@cosyte/tsconfig 0.0.2 0.1.0
@cosyte/tsup-config 0.0.1 0.1.0
@cosyte/vitest-config 0.0.2 0.1.0
@types/node 22.20.0 26.6.4
@vitest/coverage-v8 4.1.4 5.0.3
eslint 10.5.0 10.12.0
fast-check 3.23.2 4.10.2
prettier 3.8.3 3.9.9
selfsigned 2.4.1 5.5.0
simple-git-hooks 2.13.0 2.14.0
tsx 4.21.0 4.23.15
typescript 5.9.3 7.0.2
vite 7.3.6 8.3.3
vitest 4.1.4 5.0.3

Updates @arethetypeswrong/cli from 0.18.4 to 0.18.5

Changelog

Sourced from @​arethetypeswrong/cli's changelog.

0.18.5

Patch Changes

  • Updated dependencies [c4be7e8]
    • @​arethetypeswrong/core@​0.18.5
Commits

Updates @changesets/cli from 2.31.0 to 3.0.3

Release notes

Sourced from @​changesets/cli's releases.

@​changesets/cli@​3.0.3

Patch Changes

  • #2297 3f163da Thanks @​Andarist! - Fixed semver ranges (such as >=1.0.0 <2.0.0) getting cut off (>=2.0.0) when updating internal dependencies.

  • #2276 ca9d110 Thanks @​Andarist! - Fixed pnpm 10 compatibility with npm 12 when reading registry information, packing, and publishing packages.

  • Updated dependencies [3f163da, bfe9050, e522996]:

    • @​changesets/apply-release-plan@​8.1.1
    • @​changesets/config@​4.0.1

@​changesets/cli@​3.0.2

Patch Changes

@​changesets/cli@​3.0.1

Patch Changes

@​changesets/cli@​3.0.0

Major Changes

  • #2128 7113c01 Thanks @​Andarist! - Renamed the changeset tag command to changeset git-tag.

  • #2074 3599e47 Thanks @​bluwy! - Set supported package manager versions in "engines" field, including npm >=10.9.0, pnpm >=10.0.0, and yarn >=4.5.2.

  • #1860 92b1c1b Thanks @​mixelburg! - changeset version now exits with code 1 when there are no unreleased changesets, instead of silently exiting with code 0.

    This makes it easier to detect when a version step is a no-op — for example, to prevent accidentally publishing packages with incorrect version tags when using --snapshot mode.

  • #1482 df424a4 Thanks @​Andarist! - Bumped supported Node versions to ^22.11 || ^24 || >=26

  • #1994 062530b Thanks @​bluwy! - The prettier option in .changeset/config.json has been removed in favor of format. format supports "auto", "prettier", "oxfmt", "deno", and "dprint", and false disables formatting. If you previously used prettier: false, migrate to format: false or remove the option to use automatic formatter detection.

  • #2190 96b65ee Thanks @​bluwy! - Move versioned prerelease changesets to .changeset/pre/ folder instead of accumulating in the root and tracking the versioned changeset ids in the .changeset/pre.json file. Existing pre.json will auto-migrate to this new structure on the next run of changeset version or when calling changeset status.

    This change allows easier management of versioned prerelease changesets (for the final stable release) and current queued changesets (for the next prerelease). Changesets in .changeset/pre/ can be edited or deleted depending if it's still relevant for the final stable release of a package. There's no need to synchronize the changeset ids in pre.json if certain changesets are deleted.

  • #2145 f5887ff Thanks @​Andarist! - Removed Yarn Classic support

  • #2097 8c88f6a Thanks @​Andarist! - Packages with only prerelease versions published will now be published with the prerelease tag in the prerelease mode if the target registry doesn't auto-assign latest tag. npm registry itself does that and such packages will continue to be released with latest tag (and not with the configured prerelease tag).

  • #1879 c76b232 Thanks @​beeequeue! - Removed warning messages about using v1 configs. They will now be silently ignored.

... (truncated)

Changelog

Sourced from @​changesets/cli's changelog.

3.0.3

Patch Changes

  • #2297 3f163da Thanks @​Andarist! - Fixed semver ranges (such as >=1.0.0 <2.0.0) getting cut off (>=2.0.0) when updating internal dependencies.

  • #2276 ca9d110 Thanks @​Andarist! - Fixed pnpm 10 compatibility with npm 12 when reading registry information, packing, and publishing packages.

  • Updated dependencies [3f163da, bfe9050, e522996]:

    • @​changesets/apply-release-plan@​8.1.1
    • @​changesets/config@​4.0.1

3.0.2

Patch Changes

3.0.1

Patch Changes

3.0.0

Major Changes

  • #2128 7113c01 Thanks @​Andarist! - Renamed the changeset tag command to changeset git-tag.

  • #2074 3599e47 Thanks @​bluwy! - Set supported package manager versions in "engines" field, including npm >=10.9.0, pnpm >=10.0.0, and yarn >=4.5.2.

  • #1860 92b1c1b Thanks @​mixelburg! - changeset version now exits with code 1 when there are no unreleased changesets, instead of silently exiting with code 0.

    This makes it easier to detect when a version step is a no-op — for example, to prevent accidentally publishing packages with incorrect version tags when using --snapshot mode.

  • #1482 df424a4 Thanks @​Andarist! - Bumped supported Node versions to ^22.11 || ^24 || >=26

  • #1994 062530b Thanks @​bluwy! - The prettier option in .changeset/config.json has been removed in favor of format. format supports "auto", "prettier", "oxfmt", "deno", and "dprint", and false disables formatting. If you previously used prettier: false, migrate to format: false or remove the option to use automatic formatter detection.

  • #2190 96b65ee Thanks @​bluwy! - Move versioned prerelease changesets to .changeset/pre/ folder instead of accumulating in the root and tracking the versioned changeset ids in the .changeset/pre.json file. Existing pre.json will auto-migrate to this new structure on the next run of changeset version or when calling changeset status.

    This change allows easier management of versioned prerelease changesets (for the final stable release) and current queued changesets (for the next prerelease). Changesets in .changeset/pre/ can be edited or deleted depending if it's still relevant for the final stable release of a package. There's no need to synchronize the changeset ids in pre.json if certain changesets are deleted.

  • #2145 f5887ff Thanks @​Andarist! - Removed Yarn Classic support

... (truncated)

Commits

Updates @cosyte/eslint-config from 0.0.3 to 0.1.0

Release notes

Sourced from @​cosyte/eslint-config's releases.

@​cosyte/eslint-config@​0.1.0

Every published README now documents every entry point its exports map declares and says what a consumer may override, under headings every package spells the same way. A new root check, test/package-docs.test.ts, grades all of it and fails when a package falls short.

Why all eight packages are versioned for a documentation change: a README ships inside the npm tarball and is what the package page renders, so it is a consumer-visible surface. No API, type, signature or default changed in any of them, and no runtime file was touched.

What was actually missing before this. Three published entry points were documented nowhere: @cosyte/script-utils/phi-scan, @cosyte/test-utils/perf and @cosyte/vitest-config/snippets each had prose about the package and nothing that said the subpath existed. No README told a consumer which of the things it enforces can be turned off, and no documented example was executed by anything.

This check grades what the sections say about the published interface; scripts/readme-check.mjs grades the house shape. The two share one vocabulary rather than each demanding its own: ## Install, ## Usage and the ## License line that closes every file are the house gate's, and ## Entry points and ## Overrides are the two this one adds.

The check derives its package set from pnpm-workspace.yaml and skips anything marked private, so a package added later joins the graded set with no edit to the check. Entry points come from each exports map for the same reason, and so does the one exemption: @cosyte/tsconfig and @cosyte/prettier-config are excused from carrying an executable example because every one of their export targets is a JSON file a tool reads, which is asked of the manifest rather than written down as a list of two names. They are not excused a copyable one: every published package's ## Usage section has to carry a fenced block, and a section that answers how to consume the package in prose alone is named with the package and the topic. A heading with nothing under it is named the same way, because a topic is what its section says.

Nine usage examples are now executed on every pnpm test through @cosyte/vitest-config/snippets, against this repo's own sources rather than the published versions. A documented call whose output no longer matches the code fails the run, naming the README file and the line of the offending block. Which blocks those are is decided by where they sit, not by who remembered a tag: the example in a package's ## Usage section is the one a consumer copies, so an untagged TypeScript or JavaScript block there is refused by file and line. Script blocks elsewhere in a README stay illustrative, being anti-examples, fragments, and integrations written against packages this repository does not contain.

@cosyte/eslint-config@0.1.0 is the first release on the settled-surface version line. No rule, option, peer range, or behaviour change: the flat config and its guardrails are byte-identical to 0.0.6. What moves is the version policy the package states about itself. Its bundled changelog now records the 0.1.0 line and points at ADR 0002 for the reasoning, and the 0.0.6 content it was still heading as unreleased is dated to the release that shipped it. Its bundled README now states that line in its ## Status section, in place of the ladder sentence it carried.

Install

npm install @cosyte/eslint-config@0.1.0

npm: https://www.npmjs.com/package/@​cosyte/eslint-config/v/0.1.0

@​cosyte/eslint-config@​0.0.6

The bundled CHANGELOG.md no longer heads already-shipped content [Unreleased].

Every section now carries the version it shipped in, dated from that release's tag, so a reader of the published tarball can tell which release a given entry belongs to. Previously the newest entries sat under [Unreleased] in the file that shipped, which meant each release republished the previous release's notes under a heading saying they had not shipped yet.

Nothing else in the tarball changes: no rule, setting, compiler option, build option, or runner behaviour is different in any of the six packages.

Install

npm install @cosyte/eslint-config@0.0.6

npm: https://www.npmjs.com/package/@​cosyte/eslint-config/v/0.0.6

@​cosyte/eslint-config@​0.0.5

Changed

... (truncated)

Changelog

Sourced from @​cosyte/eslint-config's changelog.

[0.1.0] - Unreleased

Changed

  • The package leaves the pre-alpha version ladder for the 0.1.x line. No rule, option, peer range, or behaviour change: the flat config and its guardrails are byte-identical to 0.0.6. What moves is the version policy this package states about itself, and the reasoning is in ADR 0002. A consumer pinned at ^0.0.6 does not resolve this release and has to widen its range once.
  • The README.md in the tarball now opens its ## Status section on the settled-line sentence instead of the pre-alpha ladder one, so the policy text a consumer reads agrees with the version printed beside it. scripts/readme-check.mjs grades that sentence against the release line the pending changesets resolve to.
  • The 0.0.6 section below was relabelled: its content had shipped and was still sitting under [Unreleased], which is the same defect the note above describes, recurring one release after it was written down. That relabelling changes only the CHANGELOG.md inside the published tarball.

[0.0.6] - 2026-08-04

Changed

  • The sections below were relabelled: content that had already shipped was still sitting under [Unreleased], so each release republished it. Every section now carries the version it shipped in. No rule, option, or behaviour change; the CHANGELOG.md inside the published tarball is the only thing that differs.

[0.0.5] - 2026-07-31

Changed

  • Documentation and source comments no longer use em dashes, in line with the Cosyte brand voice. No rule, option, or behaviour change.

[0.0.4] - 2026-06-26

Added

  • Application mode: cosyte(rootDir, { library: false }) drops the JSDoc + @example gate and no-console while keeping every type-safety rule (no any, no unjustified casts, exhaustiveness, strict imports). Libraries (the default, library: true) are unchanged. This makes applications, like the pathways engine, first-class consumers of the one shared config instead of forking it: an app has no published API surface to document and legitimately logs.
Commits
  • 254ca68 Version Packages (#111)
  • 4dc4061 S0200-config-release-prep-1: prepare the eight published packages for a singl...
  • beb59b2 S0198-config-docs-1: grade every published README's interface, on the house s...
  • 7867f9f S0197: bring all nine READMEs to the house skeleton, and gate the shape (#90)
  • 3766366 Version Packages (#46)
  • 89cc33f fix(release): close the three ways this repo's releases lied about themselves...
  • 89d5d06 Version Packages (#39)
  • 1f35b93 feat(brand): sweep every em dash and land the no-emdash gate in the same comm...
  • 2e13eeb docs(config): date test-utils 0.0.1 + eslint-config 0.0.4 (2026-06-26)
  • 71c1267 Version Packages (#2)
  • Additional commits viewable in compare view

Updates @cosyte/prettier-config from 0.0.2 to 0.1.0

Release notes

Sourced from @​cosyte/prettier-config's releases.

@​cosyte/prettier-config@​0.1.0

Every published README now documents every entry point its exports map declares and says what a consumer may override, under headings every package spells the same way. A new root check, test/package-docs.test.ts, grades all of it and fails when a package falls short.

Why all eight packages are versioned for a documentation change: a README ships inside the npm tarball and is what the package page renders, so it is a consumer-visible surface. No API, type, signature or default changed in any of them, and no runtime file was touched.

What was actually missing before this. Three published entry points were documented nowhere: @cosyte/script-utils/phi-scan, @cosyte/test-utils/perf and @cosyte/vitest-config/snippets each had prose about the package and nothing that said the subpath existed. No README told a consumer which of the things it enforces can be turned off, and no documented example was executed by anything.

This check grades what the sections say about the published interface; scripts/readme-check.mjs grades the house shape. The two share one vocabulary rather than each demanding its own: ## Install, ## Usage and the ## License line that closes every file are the house gate's, and ## Entry points and ## Overrides are the two this one adds.

The check derives its package set from pnpm-workspace.yaml and skips anything marked private, so a package added later joins the graded set with no edit to the check. Entry points come from each exports map for the same reason, and so does the one exemption: @cosyte/tsconfig and @cosyte/prettier-config are excused from carrying an executable example because every one of their export targets is a JSON file a tool reads, which is asked of the manifest rather than written down as a list of two names. They are not excused a copyable one: every published package's ## Usage section has to carry a fenced block, and a section that answers how to consume the package in prose alone is named with the package and the topic. A heading with nothing under it is named the same way, because a topic is what its section says.

Nine usage examples are now executed on every pnpm test through @cosyte/vitest-config/snippets, against this repo's own sources rather than the published versions. A documented call whose output no longer matches the code fails the run, naming the README file and the line of the offending block. Which blocks those are is decided by where they sit, not by who remembered a tag: the example in a package's ## Usage section is the one a consumer copies, so an untagged TypeScript or JavaScript block there is refused by file and line. Script blocks elsewhere in a README stay illustrative, being anti-examples, fragments, and integrations written against packages this repository does not contain.

@cosyte/prettier-config@0.1.0 is the first release on the settled-surface version line. No setting change: the shared Prettier settings and their overrides are byte-identical to 0.0.4. Its bundled changelog now records the 0.1.0 line and points at ADR 0002 for the reasoning, and the 0.0.4 content it was still heading as unreleased is dated to the release that shipped it. Its bundled README now states that line in its ## Status section, in place of the ladder sentence it carried.

Install

npm install @cosyte/prettier-config@0.1.0

npm: https://www.npmjs.com/package/@​cosyte/prettier-config/v/0.1.0

@​cosyte/prettier-config@​0.0.4

The bundled CHANGELOG.md no longer heads already-shipped content [Unreleased].

Every section now carries the version it shipped in, dated from that release's tag, so a reader of the published tarball can tell which release a given entry belongs to. Previously the newest entries sat under [Unreleased] in the file that shipped, which meant each release republished the previous release's notes under a heading saying they had not shipped yet.

Nothing else in the tarball changes: no rule, setting, compiler option, build option, or runner behaviour is different in any of the six packages.

Install

npm install @cosyte/prettier-config@0.0.4

npm: https://www.npmjs.com/package/@​cosyte/prettier-config/v/0.0.4

@​cosyte/prettier-config@​0.0.3

Changed

Documentation was repunctuated to drop em dashes, in line with the cosyte brand voice.

... (truncated)

Changelog

Sourced from @​cosyte/prettier-config's changelog.

[0.1.0] - Unreleased

Changed

  • The package leaves the pre-alpha version ladder for the 0.1.x line. No setting change: the shared Prettier settings and their overrides are byte-identical to 0.0.4. What moves is the version policy this package states about itself, and the reasoning is in ADR 0002. A consumer pinned at ^0.0.4 does not resolve this release and has to widen its range once.
  • The README.md in the tarball now opens its ## Status section on the settled-line sentence instead of the pre-alpha ladder one, so the policy text a consumer reads agrees with the version printed beside it. scripts/readme-check.mjs grades that sentence against the release line the pending changesets resolve to.
  • The 0.0.4 section below was relabelled: its content had shipped and was still sitting under [Unreleased], which is the same defect the note above describes, recurring one release after it was written down. That relabelling changes only the CHANGELOG.md inside the published tarball.

[0.0.4] - 2026-08-04

Changed

  • The sections below were relabelled: content that had already shipped was still sitting under [Unreleased], so each release republished it. Every section now carries the version it shipped in. No setting change; the CHANGELOG.md inside the published tarball is the only thing that differs.

[0.0.3] - 2026-07-31

Changed

  • Documentation no longer uses em dashes, in line with the Cosyte brand voice. No setting change.
Commits
  • 254ca68 Version Packages (#111)
  • 4dc4061 S0200-config-release-prep-1: prepare the eight published packages for a singl...
  • beb59b2 S0198-config-docs-1: grade every published README's interface, on the house s...
  • 7867f9f S0197: bring all nine READMEs to the house skeleton, and gate the shape (#90)
  • 3766366 Version Packages (#46)
  • 89cc33f fix(release): close the three ways this repo's releases lied about themselves...
  • 89d5d06 Version Packages (#39)
  • 1f35b93 feat(brand): sweep every em dash and land the no-emdash gate in the same comm...
  • 133d856 docs(config): date the published CHANGELOG entries (2026-06-25 batch)
  • See full diff in compare view

Updates @cosyte/test-utils from 0.0.2 to 0.1.0

Release notes

Sourced from @​cosyte/test-utils's releases.

@​cosyte/test-utils@​0.1.0

Every published README now documents every entry point its exports map declares and says what a consumer may override, under headings every package spells the same way. A new root check, test/package-docs.test.ts, grades all of it and fails when a package falls short.

Why all eight packages are versioned for a documentation change: a README ships inside the npm tarball and is what the package page renders, so it is a consumer-visible surface. No API, type, signature or default changed in any of them, and no runtime file was touched.

What was actually missing before this. Three published entry points were documented nowhere: @cosyte/script-utils/phi-scan, @cosyte/test-utils/perf and @cosyte/vitest-config/snippets each had prose about the package and nothing that said the subpath existed. No README told a consumer which of the things it enforces can be turned off, and no documented example was executed by anything.

This check grades what the sections say about the published interface; scripts/readme-check.mjs grades the house shape. The two share one vocabulary rather than each demanding its own: ## Install, ## Usage and the ## License line that closes every file are the house gate's, and ## Entry points and ## Overrides are the two this one adds.

The check derives its package set from pnpm-workspace.yaml and skips anything marked private, so a package added later joins the graded set with no edit to the check. Entry points come from each exports map for the same reason, and so does the one exemption: @cosyte/tsconfig and @cosyte/prettier-config are excused from carrying an executable example because every one of their export targets is a JSON file a tool reads, which is asked of the manifest rather than written down as a list of two names. They are not excused a copyable one: every published package's ## Usage section has to carry a fenced block, and a section that answers how to consume the package in prose alone is named with the package and the topic. A heading with nothing under it is named the same way, because a topic is what its section says.

Nine usage examples are now executed on every pnpm test through @cosyte/vitest-config/snippets, against this repo's own sources rather than the published versions. A documented call whose output no longer matches the code fails the run, naming the README file and the line of the offending block. Which blocks those are is decided by where they sit, not by who remembered a tag: the example in a package's ## Usage section is the one a consumer copies, so an untagged TypeScript or JavaScript block there is refused by file and line. Script blocks elsewhere in a README stay illustrative, being anti-examples, fragments, and integrations written against packages this repository does not contain.

@cosyte/test-utils@0.1.0 is the first release on the settled-surface version line. No runner, API, or type change: the conformance runners, the scaling gate on the ./perf subpath and the frozen PERF_CONTRACT constants are byte-identical to 0.0.4. Its bundled changelog now records the 0.1.0 line and points at ADR 0002 for the reasoning, and the two releases' worth of content it was still heading as unreleased are dated to the releases that shipped them: the scaling gate to 0.0.4 and the changelog relabelling to 0.0.3. Its bundled README now states that line in its ## Status section, in place of the ladder sentence it carried.

Install

npm install @cosyte/test-utils@0.1.0

npm: https://www.npmjs.com/package/@​cosyte/test-utils/v/0.1.0

@​cosyte/test-utils@​0.0.4

PERF-P2: add @cosyte/test-utils/perf, the throughput scaling gate.

A new subpath export, and a sixth runner family alongside the conformance runners on the root entry. It exists so every @cosyte/* package can prove, in its own CI and without bespoke code, that it has not silently acquired an algorithmic-complexity regression. Zero dependencies, hand-rolled on node:perf_hooks.

  • scalingGate(options): takes a workload generator and a parse function (never a file path, which is what keeps PHI out of the benchmark path by construction), does time-budgeted warmup with a stability rule, sampling, and sink accumulation, then asserts RATIO_FLOOR ≤ min(scaled)/min(base) ≤ RATIO_CEILING on two axes.
  • Both axes, and size-scaling is not optional. count scales the number of inputs at fixed length; size scales each input's length at fixed count. An O(n²)-in-length tokenizer is invisible to the count axis by construction: at fixed message size a quadratic parser still scores ≈4 there , so there is no way to ask for one axis.
  • assertScalingGateFires(options, injection): the per-package self-check, and the load-bearing half. The ceiling of 8 sits between a constant (the worst false alarm across 3,200 clean ratios, 6.649) and a non-constant: the weakest real O(n²) signal climbs 4.69 → 8.09 → 8.84 → 10.68 as the base fixture grows 125 → 250 → 500 → 1000 segments. At the smallest, a genuine quadratic is inside the noise and the gate reads green while broken. The self-check takes the **same options

... (truncated)

Changelog

Sourced from @​cosyte/test-utils's changelog.

[0.1.0] - Unreleased

Changed

  • The package leaves the pre-alpha version ladder for the 0.1.x line. No runner, API, or type change: the conformance runners, the scaling gate on the ./perf subpath and the frozen PERF_CONTRACT constants are byte-identical to 0.0.4. What moves is the version policy this package states about itself, and the reasoning is in ADR 0002. A consumer pinned at ^0.0.4 does not resolve this release and has to widen its range once.
  • The README.md in the tarball now opens its ## Status section on the settled-line sentence instead of the pre-alpha ladder one, so the policy text a consumer reads agrees with the version printed beside it. scripts/readme-check.mjs grades that sentence against the release line the pending changesets resolve to.
  • The 0.0.4 and 0.0.3 sections below were relabelled: both had shipped and both were still sitting under [Unreleased], which is the same defect the note above describes, recurring twice after it was written down. This is the package where the gap was widest, at two releases. That relabelling changes only the CHANGELOG.md inside the published tarball.

[0.0.4] - 2026-08-06

Added

  • @cosyte/test-utils/perf: the throughput scaling gate (PERF-P2). A new subpath export, a sixth runner family alongside the conformance runners. It exists so every @cosyte/* package can prove, in its own CI and without bespoke code, that it has not silently acquired an algorithmic-complexity regression. Zero dependencies, hand-rolled on node:perf_hooks, that question is closed (founder, 2026-07-25) and the reasons are in ADR 0001. New exports:
    • scalingGate(options): takes a workload generator and a parse function, does time-budgeted warmup, sampling and sink accumulation, and asserts RATIO_FLOOR ≤ min(scaled)/min(base) ≤ RATIO_CEILING on two axes.
    • assertScalingGateFires(options, injection): the per-package self-check.
    • PERF_CONTRACT: the frozen constants, readable and deliberately not overridable.
    • perfSink: the accumulator the measured loop sums into.
  • Both axes, and size-scaling is not optional. count scales the number of inputs at fixed length; size scales each input's length at fixed count. An O(n²)-in-length tokenizer is invisible to the count axis by construction: at fixed message size a quadratic parser still scores ≈4 there, so there is no way to ask for one axis.
  • The self-check, which is the load-bearing half. The ceiling of 8 is derived from a constant (the worst false alarm across 3,200 clean ratios, 6.649) and a non-constant (the weakest real O(n²) signal, which climbs 4.69 → 8.09 → 8.84 → 10.68 as the base fixture grows 125 → 250 → 500 → 1000 segments). Below about 250 base segments a genuine quadratic sits inside the noise and the gate reads green while broken. assertScalingGateFires takes the same options object the real gate is given, so "run the self-check at the sizes your real gate uses" is structural rather than a thing you remember to do, and it fails the build when the fixture is too small.
  • The fail-safe: typed, loud skips. phase-too-short (base min under MIN_PHASE_MS) and warmup-unstable (never reached steady state) write the full diagnostic to stderr and return status: "skipped". A measurement never reports a confident wrong answer, and a skip is not a pass. Both bounds are hard failures: the ceiling catches the complexity regression, the floor catches the two phases having received the same workload. The floor deliberately does not claim

... (truncated)

Commits
  • 254ca68 Version Packages (#111)
  • a3a935c S0333-attw-probe-consolidation: one attw probe body, consumed rather than cop...
  • 4dc4061 S0200-config-release-prep-1: prepare the eight published packages for a singl...
  • beb59b2 S0198-config-docs-1: grade every published README's interface, on the house s...
  • 7867f9f S0197: bring all nine READMEs to the house skeleton, and gate the shape (#90)
  • 382a23c fix(attw): read the SEE LICENSE IN form of license, the field no disclosure n...
  • 776ebfe fix(attw): grade the manifest pnpm WOULD PUBLISH, as a fourth net (CONFIG-SCA...
  • 260c765 fix(attw): read man, unpkg and jsdelivr, and name what is still unread (CONFI...
  • dfb7010 fix(attw): read every field that declares a file, not just exports (CONFIG-SC...
  • 7471907 fix(attw): check the DECLARED paths are in the tarball, not just some .d.ts (...
  • Additional commits viewable in compare view

Updates @cosyte/tsconfig from 0.0.2 to 0.1.0

Release notes

Sourced from @​cosyte/tsconfig's releases.

@​cosyte/tsconfig@​0.1.0

Every published README now documents every entry point its exports map declares and says what a consumer may override, under headings every package spells the same way. A new root check, test/package-docs.test.ts, grades all of it and fails when a package falls short.

Why all eight packages are versioned for a documentation change: a README ships inside the npm tarball and is what the package page renders, so it is a consumer-visible surface. No API, type, signature or default changed in any of them, and no runtime file was touched.

What was actually missing before this. Three published entry points were documented nowhere: @cosyte/script-utils/phi-scan, @cosyte/test-utils/perf and @cosyte/vitest-config/snippets each had prose about the package and nothing that said the subpath existed. No README told a consumer which of the things it enforces can be turned off, and no documented example was executed by anything.

This check grades what the sections say about the published interface; scripts/readme-check.mjs grades the house shape. The two share one vocabulary rather than each demanding its own: ## Install, ## Usage and the ## License line that closes every file are the house gate's, and ## Entry points and ## Overrides are the two this one adds.

The check derives its package set from pnpm-workspace.yaml and skips anything marked private, so a package added later joins the graded set with no edit to the check. Entry points come from each exports map for the same reason, and so does the one exemption: @cosyte/tsconfig and @cosyte/prettier-config are excused from carrying an executable example because every one of their export targets is a JSON file a tool reads, which is asked of the manifest rather than written down as a list of two names. They are not excused a copyable one: every published package's ## Usage section has to carry a fenced block, and a section that answers how to consume the package in prose alone is named with the package and the topic. A heading with nothing under it is named the same way, because a topic is what its section says.

Nine usage examples are now executed on every pnpm test through @cosyte/vitest-config/snippets, against this repo's own sources rather than the published versions. A documented call whose output no longer matches the code fails the run, naming the README file and the line of the offending block. Which blocks those are is decided by where they sit, not by who remembered a tag: the example in a package's ## Usage section is the one a consumer copies, so an untagged TypeScript or JavaScript block there is refused by file and line. Script blocks elsewhere in a README stay illustrative, being anti-examples, fragments, and integrations written against packages this repository does not contain.

@cosyte/tsconfig@0.1.0 is the first release on the settled-surface version line. No compiler-option change: base.json and library.json are byte-identical to 0.0.4. Its bundled changelog now records the 0.1.0 line and points at ADR 0002 for the reasoning, and the 0.0.4 content it was still heading as unreleased is dated to the release that shipped it. Its bundled README now states that line in its ## Status section, in place of the ladder sentence it carried.

Install

npm install @cosyte/tsconfig@0.1.0

npm: https://www.npmjs.com/package/@​cosyte/tsconfig/v/0.1.0

@​cosyte/tsconfig@​0.0.4

The bundled CHANGELOG.md no longer heads already-shipped content [Unreleased].

Every section now carries the version it shipped in, dated from that release's tag, so a reader of the published tarball can tell which release a given entry belongs to. Previously the newest entries sat under [Unreleased] in the file that shipped, which meant each release republished the previous release's notes under a heading saying they had not shipped yet.

Nothing else in the tarball changes: no rule, setting, compiler option, build option, or runner behaviour is different in any of the six packages.

Install

npm install @cosyte/tsconfig@0.0.4

npm: https://www.npmjs.com/package/@​cosyte/tsconfig/v/0.0.4

@​cosyte/tsconfig@​0.0.3

Changed

Documentation was repunctuated to drop em dashes, in line with the cosyte brand voice.

... (truncated)

Changelog

Sourced from @​cosyte/tsconfig's changelog.

[0.1.0] - Unreleased

Changed

  • The package leaves the pre-alpha version ladder for the 0.1.x line. No compiler-option change: base.json and library.json are byte-identical to 0.0.4. What moves is the version policy this package states about itself, and the reasoning is in ADR 0002. A consumer pinned at ^0.0.4 does not resolve this release and has to widen its range once.
  • The README.md in the tarball now opens its ## Status section on the settled-line sentence instead of the pre-alpha ladder one, so the policy text a consumer reads agrees with the version printed beside it. scripts/readme-check.mjs grades that sentence against the release line the pending changesets resolve to.
  • The 0.0.4 section below was relabelled: its content had shipped and was still sitting under [Unreleased], which is the same defect the note above describes, recurring one release after it was written down. That relabelling changes only the CHANGELOG.md inside the published tarball.

[0.0.4] - 2026-08-04

Changed

  • The sections below were relabelled: content that had already shipped was still sitting under [Unreleased], so each release republished it. Every section now carries the version it shipped in. No compiler-option change; the CHANGELOG.md inside the published tarball is the only thing that differs.

[0.0.3] - 2026-07-31

Changed

  • Documentation no longer uses em dashes, in line with the Cosyte brand voice. No compiler-option change.
Commits
  • 254ca68 Version Packages (#111)
  • 4dc4061 S0200-config-release-prep-1: prepare the eight published packages for a singl...
  • beb59b2 S0198-config-docs-1: grade every published README's interface, on the house s...
  • 7867f9f S0197: bring all nine READMEs to the house skeleton, and gate the shape (#90)
  • 3766366 Version Packages (#46)
  • 89cc33f fix(release): close the three ways this repo's releases lied about themselves...
  • 89d5d06 Version Packages (#39)
  • 1f35b93 feat(brand): sweep every em dash and land the no-emdash gate in the same comm...

Bumps the dev-dependencies group with 19 updates:

| Package | From | To |
| --- | --- | --- |
| [@arethetypeswrong/cli](https://github.com/arethetypeswrong/arethetypeswrong.github.io/tree/HEAD/packages/cli) | `0.18.4` | `0.18.5` |
| [@changesets/cli](https://github.com/changesets/changesets/tree/HEAD/packages/cli) | `2.31.0` | `3.0.3` |
| [@cosyte/eslint-config](https://github.com/cosyte/config/tree/HEAD/packages/eslint-config) | `0.0.3` | `0.1.0` |
| [@cosyte/prettier-config](https://github.com/cosyte/config/tree/HEAD/packages/prettier-config) | `0.0.2` | `0.1.0` |
| [@cosyte/test-utils](https://github.com/cosyte/config/tree/HEAD/packages/test-utils) | `0.0.2` | `0.1.0` |
| [@cosyte/tsconfig](https://github.com/cosyte/config/tree/HEAD/packages/tsconfig) | `0.0.2` | `0.1.0` |
| [@cosyte/tsup-config](https://github.com/cosyte/config/tree/HEAD/packages/tsup-config) | `0.0.1` | `0.1.0` |
| [@cosyte/vitest-config](https://github.com/cosyte/config/tree/HEAD/packages/vitest-config) | `0.0.2` | `0.1.0` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `22.20.0` | `26.6.4` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `4.1.4` | `5.0.3` |
| [eslint](https://github.com/eslint/eslint) | `10.5.0` | `10.12.0` |
| [fast-check](https://github.com/dubzzz/fast-check/tree/HEAD/packages/fast-check) | `3.23.2` | `4.10.2` |
| [prettier](https://github.com/prettier/prettier) | `3.8.3` | `3.9.9` |
| [selfsigned](https://github.com/jfromaniello/selfsigned) | `2.4.1` | `5.5.0` |
| [simple-git-hooks](https://github.com/toplenboren/simple-git-hooks) | `2.13.0` | `2.14.0` |
| [tsx](https://github.com/privatenumber/tsx) | `4.21.0` | `4.23.15` |
| [typescript](https://github.com/microsoft/TypeScript) | `5.9.3` | `7.0.2` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `7.3.6` | `8.3.3` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.4` | `5.0.3` |


Updates `@arethetypeswrong/cli` from 0.18.4 to 0.18.5
- [Release notes](https://github.com/arethetypeswrong/arethetypeswrong.github.io/releases)
- [Changelog](https://github.com/arethetypeswrong/arethetypeswrong.github.io/blob/main/packages/cli/CHANGELOG.md)
- [Commits](https://github.com/arethetypeswrong/arethetypeswrong.github.io/commits/HEAD/packages/cli)

Updates `@changesets/cli` from 2.31.0 to 3.0.3
- [Release notes](https://github.com/changesets/changesets/releases)
- [Changelog](https://github.com/changesets/changesets/blob/main/packages/cli/CHANGELOG.md)
- [Commits](https://github.com/changesets/changesets/commits/@changesets/cli@3.0.3/packages/cli)

Updates `@cosyte/eslint-config` from 0.0.3 to 0.1.0
- [Release notes](https://github.com/cosyte/config/releases)
- [Changelog](https://github.com/cosyte/config/blob/main/packages/eslint-config/CHANGELOG.md)
- [Commits](https://github.com/cosyte/config/commits/@cosyte/eslint-config@0.1.0/packages/eslint-config)

Updates `@cosyte/prettier-config` from 0.0.2 to 0.1.0
- [Release notes](https://github.com/cosyte/config/releases)
- [Changelog](https://github.com/cosyte/config/blob/main/packages/prettier-config/CHANGELOG.md)
- [Commits](https://github.com/cosyte/config/commits/@cosyte/prettier-config@0.1.0/packages/prettier-config)

Updates `@cosyte/test-utils` from 0.0.2 to 0.1.0
- [Release notes](https://github.com/cosyte/config/releases)
- [Changelog](https://github.com/cosyte/config/blob/main/packages/test-utils/CHANGELOG.md)
- [Commits](https://github.com/cosyte/config/commits/@cosyte/test-utils@0.1.0/packages/test-utils)

Updates `@cosyte/tsconfig` from 0.0.2 to 0.1.0
- [Release notes](https://github.com/cosyte/config/releases)
- [Changelog](https://github.com/cosyte/config/blob/main/packages/tsconfig/CHANGELOG.md)
- [Commits](https://github.com/cosyte/config/commits/@cosyte/tsconfig@0.1.0/packages/tsconfig)

Updates `@cosyte/tsup-config` from 0.0.1 to 0.1.0
- [Release notes](https://github.com/cosyte/config/releases)
- [Changelog](https://github.com/cosyte/config/blob/main/packages/tsup-config/CHANGELOG.md)
- [Commits](https://github.com/cosyte/config/commits/@cosyte/tsup-config@0.1.0/packages/tsup-config)

Updates `@cosyte/vitest-config` from 0.0.2 to 0.1.0
- [Release notes](https://github.com/cosyte/config/releases)
- [Changelog](https://github.com/cosyte/config/blob/main/packages/vitest-config/CHANGELOG.md)
- [Commits](https://github.com/cosyte/config/commits/@cosyte/vitest-config@0.1.0/packages/vitest-config)

Updates `@types/node` from 22.20.0 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@vitest/coverage-v8` from 4.1.4 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/coverage-v8)

Updates `eslint` from 10.5.0 to 10.12.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.5.0...v10.12.0)

Updates `fast-check` from 3.23.2 to 4.10.2
- [Release notes](https://github.com/dubzzz/fast-check/releases)
- [Changelog](https://github.com/dubzzz/fast-check/blob/main/packages/fast-check/CHANGELOG.md)
- [Commits](https://github.com/dubzzz/fast-check/commits/v4.10.2/packages/fast-check)

Updates `prettier` from 3.8.3 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.8.3...3.9.9)

Updates `selfsigned` from 2.4.1 to 5.5.0
- [Changelog](https://github.com/jfromaniello/selfsigned/blob/master/CHANGELOG.md)
- [Commits](jfromaniello/selfsigned@v2.4.1...v5.5.0)

Updates `simple-git-hooks` from 2.13.0 to 2.14.0
- [Release notes](https://github.com/toplenboren/simple-git-hooks/releases)
- [Changelog](https://github.com/toplenboren/simple-git-hooks/blob/master/CHANGELOG.md)
- [Commits](toplenboren/simple-git-hooks@2.13.0...2.14.0)

Updates `tsx` from 4.21.0 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.21.0...v4.23.15)

Updates `typescript` from 5.9.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v5.9.3...v7.0.2)

Updates `vite` from 7.3.6 to 8.3.3
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.3/packages/vite)

Updates `vitest` from 4.1.4 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

---
updated-dependencies:
- dependency-name: "@arethetypeswrong/cli"
  dependency-version: 0.18.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: "@changesets/cli"
  dependency-version: 3.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
- dependency-name: "@cosyte/eslint-config"
  dependency-version: 0.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: "@cosyte/prettier-config"
  dependency-version: 0.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: "@cosyte/test-utils"
  dependency-version: 0.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: "@cosyte/tsconfig"
  dependency-version: 0.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: "@cosyte/tsup-config"
  dependency-version: 0.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: "@cosyte/vitest-config"
  dependency-version: 0.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
- dependency-name: eslint
  dependency-version: 10.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: fast-check
  dependency-version: 4.10.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
- dependency-name: prettier
  dependency-version: 3.9.9
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: selfsigned
  dependency-version: 5.5.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
- dependency-name: simple-git-hooks
  dependency-version: 2.14.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
- dependency-name: vite
  dependency-version: 8.3.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from NSchatz as a code owner October 9, 2026 05:56
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 9, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants