build(deps-dev): bump n8n-workflow from 1.120.7 to 2.16.0 - #137
build(deps-dev): bump n8n-workflow from 1.120.7 to 2.16.0#137dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [n8n-workflow](https://github.com/n8n-io/n8n) from 1.120.7 to 2.16.0. - [Release notes](https://github.com/n8n-io/n8n/releases) - [Commits](https://github.com/n8n-io/n8n/commits/n8n@2.16.0) --- updated-dependencies: - dependency-name: n8n-workflow dependency-version: 2.16.0 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
Held (not merged): |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
…ed majors (#140) Closes out the second Dependabot triage wave. ## 1. Align `vitest` across the workspace `packages/sdk` pinned `vitest ^1.2.2` while `apps/api` and `apps/worker` were on `^2.0.0`. **That split is itself a PR generator** — it's why Dependabot kept proposing a separate sdk-only bump (#134, `1.6.1 → 4.1.10`) that could never merge cleanly and would have left the workspace split three ways. Aligning sdk to `^2.0.0` means one vitest major governs everything (and matches the `^2` pin on `@vitest/coverage-v8`). Drops **249 lines** of duplicate vitest-1 tree from the lockfile; sdk tests stay green (17/17). ## 2. Three more `ignore` rules for migration-gated majors | dep | why it can't be a drop-in bump | |-----|-------------------------------| | `next` | Next 15+ **requires React 19**, which is already ignored for the same reason — the admin crosses both majors together or not at all (#138 closed) | | `vitest` | must move in lockstep with `@vitest/coverage-v8` **and** every workspace package → one deliberate PR, never per-package (#134 closed) | | `n8n-workflow` | 2.x is a new n8n node-API major; the published `n8n-nodes-multiwa` must be reconciled against it and re-published (#137 closed) | ## Verification - All 5 workspace packages build ✓ · `api`/`worker`/`admin` typecheck ✓ - **api 324/324** · **worker 34/34** · **sdk 17/17** ✓ - Lockfile still **air-gap safe** (0 `ssh://` refs) - `dependabot.yml` parses; 13 migration-gated majors now ignored ## This wave's triage **Merged (4):** #135 `@fastify/multipart` 10 · #136 `@types/nodemailer` 8 (aligned all 3 packages) · **#139 `@fastify/static` 10.1.2 — SECURITY FIX** · this PR **Closed with reasons (3):** #134 vitest (workspace split) · #137 n8n-workflow 2.x · #138 next 14→16 >⚠️ **#139 was a real vulnerability:** `@fastify/static@8.3.0` was affected by [GHSA-8pvw-jcv7-9cmj](GHSA-8pvw-jcv7-9cmj) — *Authorization Bypass via Non-Canonical URL Paths* (MODERATE, affects `<= 10.1.1`). First patched version is exactly `10.1.2`, so the major bump was the only remedy. Now on `10.1.2`.
Bumps n8n-workflow from 1.120.7 to 2.16.0.
Release notes
Sourced from n8n-workflow's releases.
... (truncated)
Commits
Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for n8n-workflow since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)