Skip to content

chore(deps-dev): bump the dev-dependencies group with 2 updates#700

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dev-dependencies-3a38b5836c
Closed

chore(deps-dev): bump the dev-dependencies group with 2 updates#700
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/dev-dependencies-3a38b5836c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 19, 2026

Copy link
Copy Markdown
Contributor

Bumps the dev-dependencies group with 2 updates: js-yaml and @clerk/backend.

Updates js-yaml from 4.2.0 to 4.3.0

Changelog

Sourced from js-yaml's changelog.

4.3.0, 3.15.0 - 2026-06-27

Security

  • Backported maxTotalMergeKeys option.

[5.2.0] - 2026-06-26

Added

  • Added maxTotalMergeKeys (10000) loader option to limit the total number of keys processed by YAML merge (<<) across one load() / loadAll() call.
  • Added maxAliases (-1) loader option to limit the number of YAML aliases per document.

Removed

  • maxMergeSeqLength replaced with maxTotalMergeKeys for limiting YAML merge processing.

Fixed

  • Round-trip of integers with exponential form (>= 1e21)

[5.1.0] - 2026-06-23

Added

  • Collection tags can finalize an incrementally populated carrier into a different result value.

Changed

  • [breaking] quoteStyle now selects the preferred quote style; use the restored forceQuotes option to force quoting non-key strings.

[5.0.0] - 2026-06-20

Added

  • Added named exports for schemas, tags, parser events and AST utilities.
  • Reworked JSON_SCHEMA and CORE_SCHEMA with spec-compliant scalar resolution rules, and added YAML11_SCHEMA.
  • Added realMapTag for lossless mappings with non-string and complex keys. Object-based mappings now reject complex keys instead of stringifying them.
  • Added dump() transform option for changing the generated AST before rendering.
  • Added dump() options seqInlineFirst, flowBracketPadding, flowSkipCommaSpace, flowSkipColonSpace, quoteFlowKeys, quoteStyle and tagBeforeAnchor.
  • Added formal data layers (events and AST) for modular data pipelines.
    • Added low-level parser (to events), presenter and visitor APIs.
  • Added the YAML Test Suite to the test set.

Changed

  • See the migration guide for upgrade notes.
  • Rewritten in TypeScript and reorganized the public API around flat named exports.

... (truncated)

Commits
  • 33d05b5 4.3.0 released
  • 663bfab Drop demo publish, to not override new v5 one.
  • 1cb8c7b Add v4-legacy tag for publish
  • 02f27af Restore umd builds back to es5
  • 8be84ed Fix es5 compatibility
  • 59423c6 Replace maxMergeSeqLength option with maxTotalMergeKeys (more robust). Ba...
  • 6842ef6 doc polish
  • See full diff in compare view

Updates @clerk/backend from 3.11.3 to 3.11.4

Release notes

Sourced from @​clerk/backend's releases.

@​clerk/backend@​3.11.4

Patch Changes

  • Clarify in the M2MToken, APIKey, and IdPOAuthAccessToken JSDoc that the timestamp properties (expiration, lastUsedAt, createdAt, and updatedAt) are Unix timestamps in milliseconds (not seconds). (#9122) by @​SarahSoutoul
Changelog

Sourced from @​clerk/backend's changelog.

3.11.4

Patch Changes

  • Clarify in the M2MToken, APIKey, and IdPOAuthAccessToken JSDoc that the timestamp properties (expiration, lastUsedAt, createdAt, and updatedAt) are Unix timestamps in milliseconds (not seconds). (#9122) by @​SarahSoutoul
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dev-dependencies group with 2 updates: [js-yaml](https://github.com/nodeca/js-yaml) and [@clerk/backend](https://github.com/clerk/javascript/tree/HEAD/packages/backend).


Updates `js-yaml` from 4.2.0 to 4.3.0
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.2.0...4.3.0)

Updates `@clerk/backend` from 3.11.3 to 3.11.4
- [Release notes](https://github.com/clerk/javascript/releases)
- [Changelog](https://github.com/clerk/javascript/blob/main/packages/backend/CHANGELOG.md)
- [Commits](https://github.com/clerk/javascript/commits/@clerk/backend@3.11.4/packages/backend)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: "@clerk/backend"
  dependency-version: 3.11.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 19, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jul 19, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: supply-chain. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from a team as a code owner July 19, 2026 22:06
@changeset-bot

changeset-bot Bot commented Jul 19, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 00017a2

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@dependabot @github

dependabot Bot commented on behalf of github Jul 24, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 24, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/dev-dependencies-3a38b5836c branch July 24, 2026 07:03
@auxesis

auxesis commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Claude's analysis of why @dependabot closed this PR:

Short answer

Dependabot's closing message was accurate. Neither of the two updates in PR #700 could change any file, so the group had nothing left in it and Dependabot closed the pull request. There are two separate reasons, one per dependency.

Reason 1: the js-yaml update could never change anything

PR #700 said it was raising js-yaml from 4.2.0 to 4.3.0. It could not do that, for two reasons at once:

  1. The version requirement was already updated. The root package.json:43 already asks for "js-yaml": "^4.3.0". That change landed on 2026-07-12 in PR chore(deps-dev): bump the dev-dependencies group across 1 directory with 6 updates #611 (commit 1a24ca17). There was nothing left for Dependabot to edit in the manifest.
  2. An override forces the installed version back down. pnpm-workspace.yaml:75 contains 'js-yaml@>=4.0.0 <5': '4.2.0'. This tells pnpm to install exactly 4.2.0 for any js-yaml version in the 4.x range, no matter what any package.json asks for. I confirmed this by running pnpm install --lockfile-only on a clean copy of main: the lock file still records js-yaml 4.2.0 even though the manifest asks for ^4.3.0.

You can see this in the pull request itself. gh pr diff 700 contains no js-yaml lines at all. The only real change is @clerk/backend, plus an unrelated shell-quote line in the lock file. The pull request description claimed the js-yaml update, but the commit never contained it.

Dependabot reads the version recorded in the lock file (4.2.0) as the current version, and it does not read pnpm's override settings. So it will keep proposing 4.3.0, and the change will keep disappearing when pnpm rewrites the lock file. The same thing happened to PR #730, which claimed to move js-yaml to 5.2.1: it merged at 06:58 UTC today, and main's lock file still records 4.2.0.

Reason 2: the @clerk/backend update could not be resolved

What happened on 2026-07-24, in UTC:

Time Event
06:58:41 PR #730 merged (js-yaml)
06:59:55 PR #774 merged, moving next from 15.5.20 to 15.5.21
07:01:44 PR #702 merged (GitHub Actions)
07:03:47 Dependabot closed PR #700

pnpm-workspace.yaml sets minimumReleaseAge: 10080, which is 7 days in minutes. This tells pnpm to refuse any package version published less than 7 days ago. next@15.5.21 requires @next/swc-win32-arm64-msvc@15.5.21, which was published on 2026-07-22 — two days ago. So any attempt to work out a fresh set of package versions now stops with this error:

ERR_PNPM_NO_MATURE_MATCHING_VERSION  Version 15.5.21 (released 2 days ago) of @next/swc-win32-arm64-msvc does not meet the minimumReleaseAge constraint

I checked this in both directions:

  • Raising @clerk/backend to 3.11.7 (the newest version old enough to pass Dependabot's own 7-day waiting period) on current main produces the error above.
  • Making the exact same change one commit earlier, at 16d40e17, where next is still 15.5.20, finishes in one second and correctly records @clerk/backend@3.11.7 in the lock file.

So when Dependabot tried to rebuild the lock file for the @clerk/backend update, the attempt failed and produced no change either.

The wording of the closing message supports this

Dependabot uses different wording depending on why it closes a grouped pull request. Earlier pull requests #631, #645, #680 and #525 were closed with "updatable in another way", which means a replacement pull request was coming. PR #700 was closed with "no longer updatable", which means the group came out empty when Dependabot recalculated it. That matches what I found: there are currently no open Dependabot pull requests on the repository, and no replacement for #700 was opened.

What this means for the repository

  • All npm updates from Dependabot are blocked right now. They will stay blocked until @next/swc-win32-arm64-msvc@15.5.21 is 7 days old, which is around 2026-07-29. The next scheduled Dependabot run is Monday 2026-07-27 at 08:00 Sydney time, and it will fail the same way.
  • To unblock it sooner, add next or @next/swc-* to minimumReleaseAgeExclude in pnpm-workspace.yaml. Otherwise, no action is needed and updates will resume on their own after 2026-07-29.
  • The js-yaml override should be raised to 4.3.0. Its own comment says 4.3.0 was pinned out because it was too new at the time; it was published on 2026-06-27 and passed the 7-day mark on 2026-07-04, so that reason no longer applies. The comment also asks you to re-run changeset status and changeset version after changing this pin, because a past js-yaml upgrade broke changesets. Until the override is raised, Dependabot will keep opening js-yaml pull requests that change nothing.
  • Worth noting separately: PR chore(deps): bump js-yaml from 4.2.0 to 5.2.1 #730 was merged but had no effect. main's lock file still records js-yaml 4.2.0, not the 5.2.1 the pull request title promised.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant