Skip to content

chore(deps): bump the npm-minor-patch group across 1 directory with 3 updates - #1259

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/server/mcp/npm-minor-patch-20e45feb72
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/server/mcp/npm-minor-patch-20e45feb72

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 12, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-minor-patch group with 3 updates in the /server/mcp directory: ws, @yao-pkg/pkg and esbuild.

Updates ws from 8.21.1 to 8.21.3

Release notes

Sourced from ws's releases.

8.21.3

Bug fixes

  • The server now correctly rejects permessage-deflate offers if the incoming client_max_window_bits parameter value is smaller than its configured clientMaxWindowBits (e97a20ea).

8.21.2

Bug fixes

  • Fixed a test for CITGM (2eb3be0b).
Commits
  • c791e70 [dist] 8.21.3
  • e97a20e [fix] Reject offers with client_max_window_bits below config
  • 787ebf2 [dist] 8.21.2
  • b4d62eb Revert "[ci] Trust Coveralls Homebrew tap"
  • e4bb883 [security] Use GitHub PVR as main reporting channel
  • 2eb3be0 [test] Skip test on Node.js versions where it does not apply
  • See full diff in compare view

Updates @yao-pkg/pkg from 6.21.0 to 6.22.0

Release notes

Sourced from @​yao-pkg/pkg's releases.

Release 6.22.0

6.22.0 (2026-07-30)

Features

  • bump fetch 3.6.5 with nodejs 22.23.2, 24.18.1, 26.5.1 (#291) (e1a96ae)

Bug Fixes

  • prelude: throw instead of crashing on Intl.Segmenter with small-icu (#290) (cbc7629)

Chores

  • ci: use node 24.x for release, drop npm upgrade step (c1e10f5)
Changelog

Sourced from @​yao-pkg/pkg's changelog.

6.22.0 (2026-07-30)

Features

  • bump fetch 3.6.5 with nodejs 22.23.2, 24.18.1, 26.5.1 (#291) (e1a96ae)

Bug Fixes

  • prelude: throw instead of crashing on Intl.Segmenter with small-icu (#290) (cbc7629)

Chores

  • ci: use node 24.x for release, drop npm upgrade step (c1e10f5)
Commits
  • 8d3d7af Release 6.22.0
  • c1e10f5 chore(ci): use node 24.x for release, drop npm upgrade step
  • e1a96ae feat: bump fetch 3.6.5 with nodejs 22.23.2, 24.18.1, 26.5.1 (#291)
  • cbc7629 fix(prelude): throw instead of crashing on Intl.Segmenter with small-icu (#290)
  • See full diff in compare view

Updates esbuild from 0.28.1 to 0.28.2

Release notes

Sourced from esbuild's releases.

v0.28.2

  • Fix tree shaking bug due to TypeScript import alias (#4507)

    This release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific import assignment and looks something like this:

    import Base from './dep.js';
    import Alias = Base.SomeType;
  • Fix CSS minification bug involving & (#4497)

    This release fixes a bug where esbuild's CSS minifier incorrectly removed a & when it was unsafe to do so. Here is an example:

    /* Original code */
    .a .b {
      & .b:not(& .c) {
        color: red;
      }
    }
    /* Old output (with --minify) */
    .a .b{.b:not(& .c){color:red}}
    /* New output (with --minify) */
    .a .b{& .b:not(& .c){color:red}}

    This should match <span class="a"><span class="b"><span class="b">yes</span></span></span> but not <span class="a"><span class="b">no</span></span>. The old output incorrectly matched both.

  • Avoid overwriting input files without --allow-overwrite (#4484)

    For example: esbuild input.js --outfile=input.js tells esbuild to overwrite input.js with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.

    This release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless --allow-overwrite is explicitly present. This is done by not writing out any files when a build error is encountered.

  • Fix incorrect code generated when using top-level await (#4498)

    Previously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing async on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an async module wrapper.

  • Fix a minification bug with lowered logical assignment operators (#4508)

    This release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:

    // Original code
    function foo() {
      let x
      bar(x ||= {})

... (truncated)

Changelog

Sourced from esbuild's changelog.

0.28.2

  • Fix tree shaking bug due to TypeScript import alias (#4507)

    This release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific import assignment and looks something like this:

    import Base from './dep.js';
    import Alias = Base.SomeType;
  • Fix CSS minification bug involving & (#4497)

    This release fixes a bug where esbuild's CSS minifier incorrectly removed a & when it was unsafe to do so. Here is an example:

    /* Original code */
    .a .b {
      & .b:not(& .c) {
        color: red;
      }
    }
    /* Old output (with --minify) */
    .a .b{.b:not(& .c){color:red}}
    /* New output (with --minify) */
    .a .b{& .b:not(& .c){color:red}}

    This should match <span class="a"><span class="b"><span class="b">yes</span></span></span> but not <span class="a"><span class="b">no</span></span>. The old output incorrectly matched both.

  • Avoid overwriting input files without --allow-overwrite (#4484)

    For example: esbuild input.js --outfile=input.js tells esbuild to overwrite input.js with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.

    This release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless --allow-overwrite is explicitly present. This is done by not writing out any files when a build error is encountered.

  • Fix incorrect code generated when using top-level await (#4498)

    Previously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing async on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an async module wrapper.

  • Fix a minification bug with lowered logical assignment operators (#4508)

    This release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:

    // Original code
    function foo() {
      let x

... (truncated)

Commits
  • 609683d publish 0.28.2 to npm
  • 11b1fe4 add to release notes
  • ab50d91 css: fix green/blue channel swap in oklch gamut mapping (#4488)
  • 04627b6 fix #4498: async TLA checks need a worklist
  • 5c15177 disable gopls in the go folder
  • fc2ee9b css: adjust parser to allow --foo: {...}
  • 209db54 release notes for css nesting bugfix
  • c625d31 fix #4497: preserve nested ampersands during minification (#4500)
  • 34474e2 better isolation of current part in js parser
  • 07f6e8c fix #4507: import assignment tree-shaking bug
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

… updates

Bumps the npm-minor-patch group with 3 updates in the /server/mcp directory: [ws](https://github.com/websockets/ws), [@yao-pkg/pkg](https://github.com/yao-pkg/pkg) and [esbuild](https://github.com/evanw/esbuild).


Updates `ws` from 8.21.1 to 8.21.3
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.21.1...8.21.3)

Updates `@yao-pkg/pkg` from 6.21.0 to 6.22.0
- [Release notes](https://github.com/yao-pkg/pkg/releases)
- [Changelog](https://github.com/yao-pkg/pkg/blob/main/CHANGELOG.md)
- [Commits](yao-pkg/pkg@v6.21.0...v6.22.0)

Updates `esbuild` from 0.28.1 to 0.28.2
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md)
- [Commits](evanw/esbuild@v0.28.1...v0.28.2)

---
updated-dependencies:
- dependency-name: ws
  dependency-version: 8.21.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@yao-pkg/pkg"
  dependency-version: 6.22.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: esbuild
  dependency-version: 0.28.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 12, 2026
@xiaolai

xiaolai commented Aug 13, 2026

Copy link
Copy Markdown
Owner

Closing — this PR could not have merged, and the cause is a Dependabot config defect rather than anything wrong with the bumps themselves.

server/mcp is a pnpm workspace member (pnpm-workspace.yaml), so it has no lockfile of its own; the root pnpm-lock.yaml is the only one that resolves it. The /server/mcp entry in .github/dependabot.yml could only rewrite server/mcp/package.json, never the root lockfile — so every job here failed at install:

ERR_PNPM_OUTDATED_LOCKFILE  Cannot install with "frozen-lockfile" because
pnpm-lock.yaml is not up to date with <ROOT>/server/mcp/package.json

Five earlier PRs from the same two entries were closed for the same reason: #1239, #1237, #1189, #1167, #1166.

The bumps are not lost. #1261 — opened by the root / entry, which resolves the whole workspace — carries the byte-identical change to server/mcp/package.json (ws ^8.21.3, @yao-pkg/pkg ^6.22.0, esbuild ^0.28.2) together with the root lockfile, and is green. It is merging as part of #1262.

#1262 also deletes the /server/mcp and /server/content entries so this class of PR stops being generated.

@xiaolai xiaolai closed this Aug 13, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 13, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/server/mcp/npm-minor-patch-20e45feb72 branch August 13, 2026 09:40
bet4it pushed a commit to bet4it/vmark that referenced this pull request Aug 19, 2026
server/mcp and server/content are pnpm workspace members, so they have no
lockfile of their own — the root pnpm-lock.yaml is the only one that
resolves them. The per-directory Dependabot entries for those two could
only ever rewrite a member package.json, never the root lockfile, so every
PR they opened was born failing pnpm install --frozen-lockfile with
ERR_PNPM_OUTDATED_LOCKFILE. Six were opened; five were closed unmerged
(xiaolai#1259, xiaolai#1239, xiaolai#1237, xiaolai#1189, xiaolai#1167, xiaolai#1166).

Delete both entries. The root "/" entry already covers the whole workspace:
xiaolai#1261 updated package.json, pnpm-lock.yaml, server/content/package.json and
server/mcp/package.json in one consistent PR, carrying byte-identical (and
in two cases newer) bumps to the ones that could not merge. The @types/node
major-version ignore moves with it and applies workspace-wide.

Also resync website/pnpm-lock.yaml with website/package.json. website is
deliberately outside the pnpm workspace and keeps its own lockfile, but
Dependabot updates only its package.json — so its bumps land a manifest the
lockfile does not match. That drift is silent rather than red because
deploy-website.yml installs without --frozen-lockfile, and it has already
required two manual repair commits (bfc7d24, c5486c5). Verified here by
installing with --frozen-lockfile and running a full vitepress build.

The gap itself is recorded in dependabot.yml rather than fixed, because
closing it is a choice between moving website into the workspace and adding
a drift gate.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant