Skip to content

chore(deps): roll up 12 dependabot bumps - #126

Closed
twangodev wants to merge 25 commits into
mainfrom
chore/deps-rollup
Closed

chore(deps): roll up 12 dependabot bumps#126
twangodev wants to merge 25 commits into
mainfrom
chore/deps-rollup

Conversation

@twangodev

@twangodev twangodev commented Aug 5, 2026

Copy link
Copy Markdown
Owner

Octopus roll-up of the 12 open dependabot PRs that are safe to merge. None touch the platform version, since-build, or anything else affecting the minimum supported IDE version.

Merged head commits of:

Excluded: #119 (kotlin.plugin.serialization 2.4.10) — requires a coordinated Kotlin 2.4 upgrade, build fails standalone.

ui/package-lock.json was regenerated after merging so it is consistent with the merged package.json (typescript 7.0.2 + its platform binaries).

The red checks on the individual PRs were investigated: IU-2026.2 verify failures are a pre-existing EAP compile issue unrelated to these bumps; the failures on #116/#117 were a GitHub Actions outage on 2026-07-13.

Summary by CodeRabbit

  • Chores
    • Updated build, testing, release, and code-scanning tooling to newer versions.
    • Refreshed development tooling used for IntelliJ platform integration, verification, code coverage, and UI development.
    • Improved consistency and reliability across automated project workflows.

dependabot Bot and others added 25 commits July 8, 2026 13:06
Bumps [@sveltejs/vite-plugin-svelte](https://github.com/sveltejs/vite-plugin-svelte/tree/HEAD/packages/vite-plugin-svelte) from 7.1.4 to 7.2.0.
- [Release notes](https://github.com/sveltejs/vite-plugin-svelte/releases)
- [Changelog](https://github.com/sveltejs/vite-plugin-svelte/blob/main/packages/vite-plugin-svelte/CHANGELOG.md)
- [Commits](https://github.com/sveltejs/vite-plugin-svelte/commits/@sveltejs/vite-plugin-svelte@7.2.0/packages/vite-plugin-svelte)

---
updated-dependencies:
- dependency-name: "@sveltejs/vite-plugin-svelte"
  dependency-version: 7.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 26.1.0 to 26.1.1.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.1.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [typescript](https://github.com/microsoft/TypeScript) from 6.0.3 to 7.0.2.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](https://github.com/microsoft/TypeScript/commits)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [shadcn-svelte](https://github.com/huntabyte/shadcn-svelte/tree/HEAD/packages/cli) from 1.3.0 to 1.4.0.
- [Release notes](https://github.com/huntabyte/shadcn-svelte/releases)
- [Changelog](https://github.com/huntabyte/shadcn-svelte/blob/main/packages/cli/CHANGELOG.md)
- [Commits](https://github.com/huntabyte/shadcn-svelte/commits/shadcn-svelte@1.4.0/packages/cli)

---
updated-dependencies:
- dependency-name: shadcn-svelte
  dependency-version: 1.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.1.3 to 8.1.4.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.1.4/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 8.1.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps org.jetbrains.intellij.platform.settings from 2.17.0 to 2.18.1.

---
updated-dependencies:
- dependency-name: org.jetbrains.intellij.platform.settings
  dependency-version: 2.18.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps org.jetbrains.intellij.platform from 2.17.0 to 2.18.1.

---
updated-dependencies:
- dependency-name: org.jetbrains.intellij.platform
  dependency-version: 2.18.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.jetbrains.kotlinx.kover](https://github.com/Kotlin/kotlinx-kover) from 0.9.7 to 0.9.9.
- [Release notes](https://github.com/Kotlin/kotlinx-kover/releases)
- [Changelog](https://github.com/Kotlin/kotlinx-kover/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Kotlin/kotlinx-kover/commits)

---
updated-dependencies:
- dependency-name: org.jetbrains.kotlinx.kover
  dependency-version: 0.9.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.jetbrains.intellij.plugins:verifier-cli](https://github.com/JetBrains/intellij-plugin-verifier) from 1.408 to 1.409.
- [Release notes](https://github.com/JetBrains/intellij-plugin-verifier/releases)
- [Changelog](https://github.com/JetBrains/intellij-plugin-verifier/blob/master/CHANGELOG.md)
- [Commits](JetBrains/intellij-plugin-verifier@1.408...1.409)

---
updated-dependencies:
- dependency-name: org.jetbrains.intellij.plugins:verifier-cli
  dependency-version: '1.409'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [JetBrains/qodana-action](https://github.com/jetbrains/qodana-action) from 2026.1.3 to 2026.2.0.
- [Release notes](https://github.com/jetbrains/qodana-action/releases)
- [Commits](JetBrains/qodana-action@v2026.1.3...v2026.2.0)

---
updated-dependencies:
- dependency-name: JetBrains/qodana-action
  dependency-version: 2026.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4 to 4.37.4.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v4...v4.37.4)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.37.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [gradle/actions](https://github.com/gradle/actions) from 5 to 6.2.0.
- [Release notes](https://github.com/gradle/actions/releases)
- [Commits](gradle/actions@v5...v6.2.0)

---
updated-dependencies:
- dependency-name: gradle/actions
  dependency-version: 6.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…/codeql-action-4.37.4' into worktree-deps-rollup
…ins/qodana-action-2026.2.0' into worktree-deps-rollup
…intellij.plugins-verifier-cli-1.409' into worktree-deps-rollup
…kotlinx.kover-0.9.9' into worktree-deps-rollup
…intellij.platform-2.18.1' into worktree-deps-rollup
…intellij.platform.settings-2.18.1' into worktree-deps-rollup
…cript-7.0.2' into worktree-deps-rollup

# Conflicts:
#	ui/package-lock.json
#	ui/package.json
…ejs/vite-plugin-svelte-7.2.0' into worktree-deps-rollup
Copilot AI lite review requested due to automatic review settings August 5, 2026 21:22
@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Changes

Dependency and tooling updates

Layer / File(s) Summary
CI action version updates
.github/workflows/build.yml, .github/workflows/codeql.yml, .github/workflows/release.yml
Updated Gradle setup, CodeQL, Qodana, and release workflow action versions.
Gradle tooling version updates
gradle/libs.versions.toml, settings.gradle.kts
Updated plugin verifier, IntelliJ Platform, Kover, and IntelliJ Platform settings versions.
UI development dependency updates
ui/package.json
Updated Svelte, Node.js types, shadcn-svelte, TypeScript, and Vite versions.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers: copilot

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Linked Issues check ❓ Inconclusive The listed dependency upgrades match the linked issues, but the required package-lock.json update is excluded from review. Review ui/package-lock.json to verify that it matches the updated ui/package.json; the file was excluded by the !**/package-lock.json path filter.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies a dependency roll-up that matches the pull request changes.
Out of Scope Changes check ✅ Passed The reviewed changes are limited to the dependency and tooling upgrades described in the linked issues.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/deps-rollup

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@socket-security

Copy link
Copy Markdown

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: maven org.bouncycastle:bcprov-jdk18on is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?maven/org.jetbrains.intellij.plugins/verifier-cli@1.409maven/org.bouncycastle/bcprov-jdk18on@1.85

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/org.bouncycastle/bcprov-jdk18on@1.85. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Rolls up multiple Dependabot dependency bumps across the Gradle build (IntelliJ Platform + tooling), the UI toolchain (Vite/Svelte/TypeScript ecosystem), and GitHub Actions workflows to keep CI and build tooling up to date without changing the minimum supported IDE/platform version.

Changes:

  • Bump UI dev dependencies (TypeScript, Vite, shadcn-svelte, @types/node, @sveltejs/vite-plugin-svelte) and regenerate package-lock.json.
  • Bump Gradle toolchain versions (IntelliJ Platform Gradle plugin + settings plugin, Kover, Plugin Verifier).
  • Update GitHub Actions workflow action versions (Gradle setup, CodeQL, Qodana).

Reviewed changes

Copilot reviewed 6 out of 7 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
ui/package.json Updates UI devDependency versions (TypeScript/Vite/Svelte tooling).
ui/package-lock.json Regenerated lockfile to reflect updated UI dependency graph (incl. new platform optional deps).
settings.gradle.kts Bumps org.jetbrains.intellij.platform.settings plugin version.
gradle/libs.versions.toml Bumps IntelliJ Platform Gradle plugin, Kover, and verifier-cli versions.
.github/workflows/release.yml Updates Gradle setup action version used during release publishing.
.github/workflows/codeql.yml Pins CodeQL init/analyze actions to the bumped patch version.
.github/workflows/build.yml Updates Gradle setup, CodeQL upload-sarif, and Qodana action versions in CI.
Files not reviewed (1)
  • ui/package-lock.json: Generated file

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread ui/package.json
Comment on lines +20 to 24
"@sveltejs/vite-plugin-svelte": "^7.2.0",
"@tailwindcss/vite": "^4.3.2",
"@tsconfig/svelte": "^5.0.8",
"@types/node": "^26.1.0",
"@types/node": "^26.1.1",
"bits-ui": "^2.18.1",

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@ui/package.json`:
- Around line 28-33: Add the required TypeScript 7 integration for the
svelte-check command, using the documented `@typescript/native` TypeScript 7 alias
or --tsgo/@typescript/native-preview setup while retaining TypeScript 6 for
Svelte tooling. Update the relevant package.json dependencies and check script
so plain svelte-check runs successfully with the existing tsconfig.app.json.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 9e4440c3-a7ef-4d37-9c42-8d3bca073e05

📥 Commits

Reviewing files that changed from the base of the PR and between 3c937c0 and fa973c9.

⛔ Files ignored due to path filters (1)
  • ui/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (6)
  • .github/workflows/build.yml
  • .github/workflows/codeql.yml
  • .github/workflows/release.yml
  • gradle/libs.versions.toml
  • settings.gradle.kts
  • ui/package.json

Comment thread ui/package.json
Comment on lines 28 to +33
"svelte-check": "^4.7.2",
"tailwind-merge": "^3.6.0",
"tailwind-variants": "^3.2.2",
"tailwindcss": "^4.3.2",
"tw-animate-css": "^1.4.0",
"typescript": "~6.0.3",
"vite": "^8.1.3",
"typescript": "~7.0.2",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

python - <<'PY'
import json
from pathlib import Path

package = json.loads(Path("ui/package.json").read_text())
print("scripts:", json.dumps(package.get("scripts", {}), indent=2))
print("relevant dependencies:", json.dumps({
    k: v for k, v in package.get("devDependencies", {}).items()
    if k in {"svelte-check", "typescript", "`@typescript/native`", "`@typescript/native-preview`"}
}, indent=2))
PY

rg -n '"(svelte-check|typescript|`@typescript/native`|`@typescript/native-preview`)|--tsgo' \
  ui/package.json ui/package-lock.json

Repository: twangodev/jetplay

Length of output: 953


🌐 Web query:

svelte-check 4.7.2 README TypeScript 7 tsgo @typescript/native-preview TypeScript 6 TypeScript 7

💡 Result:

The current state of TypeScript 7 and its relationship with svelte-check is as follows: Svelte-check 4.7.2 (released July 7, 2026) includes updates regarding the experimental --tsgo flag, which allows users to leverage the native TypeScript compiler port (the foundation of TypeScript 7) [1][2]. The --tsgo flag in svelte-check relies on the @typescript/native-preview package [3][4]. This package was used to distribute preview builds of the native TypeScript compiler (often referred to as tsgo) during the transition from TypeScript 6.0 to TypeScript 7.0 [5][6][7]. As of the release of TypeScript 7.0, the stable version is distributed under the official typescript package, and the tsgo binary has been transitioned to be available as the standard tsc command [6][8][4]. However, ecosystem tools like svelte-check that rely on deep integration with the TypeScript compiler's programmatic API face compatibility challenges [9]. Because TypeScript 7 initially lacked a stable programmatic API, these tools often require TypeScript 6.0 for internal operations, even when experimenting with TypeScript 7 features via --tsgo or similar mechanisms [9]. In summary: - svelte-check 4.7.2 provides experimental support for the native compiler (tsgo) through the --tsgo flag [10][1]. - This functionality is intended to allow testing the performance improvements of the new compiler architecture [6][4]. - Users should be aware that full programmatic integration of TypeScript 7 into tools like svelte-check is an ongoing effort, and users may still require a TypeScript 6.0 environment for stable type-checking operations within these tools [9].

Citations:


🌐 Web query:

Svelte language tools README svelte-check TypeScript 7 @typescript/native-preview @typescript/native``

💡 Result:

As of August 5, 2026, svelte-check does not natively support TypeScript 7 due to fundamental incompatibilities with TypeScript 7's architecture and programmatic API [1]. While TypeScript 7 is stable, Svelte tooling—including svelte-check and svelte2tsx—requires TypeScript 6.0 for core language service operations [1]. To use TypeScript 7 within a project that also requires Svelte tooling, maintainers recommend a dual-version setup using npm aliases [2]. This allows you to keep TypeScript 6 for Svelte's requirements while experimenting with or running TypeScript 7 for other parts of your build [2][1]. Recommended setup: npm install --save-dev typescript@~6 @typescript/native@npm:typescript@7 [2] For type-checking specifically, svelte-check provides experimental flags to leverage TypeScript's "Go" (native) implementation, which is often used in conjunction with TypeScript 7 workflows [3][2][4]. Key flags for svelte-check: --tsgo: Uses TypeScript's native Go implementation [5][3]. This requires the @typescript/native-preview package to be installed [5][2]. Note that this approach has specific limitations similar to the --incremental flag, such as difficulties handling files outside the root directory of your tsconfig.json [5][3]. --tsgo-experimental-api: An alternative flag that avoids some of the limitations of --tsgo by not caching virtual code, though it is slightly slower and considered experimental [6][4]. These flags are intended for testing and experimentation as the Svelte and TypeScript teams continue to work toward full compatibility [7][6][1]. In typical environments, you should continue to rely on a stable TypeScript 6.0 dependency for your primary Svelte development workflow to avoid crashes and integration errors [1][8].

Citations:


Add the required TypeScript 7 support for svelte-check.

check runs plain svelte-check --tsconfig ./tsconfig.app.json, but svelte-check 4.7.2 needs both TypeScript 6 for Svelte tooling and TypeScript 7 support for the project TypeScript version. Add @typescript/native@npm:typescript@7 or use the documented --tsgo/@typescript/native-preview setup, or keep TypeScript 6 as the compiler until the TypeScript 7 integration is in place.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ui/package.json` around lines 28 - 33, Add the required TypeScript 7
integration for the svelte-check command, using the documented
`@typescript/native` TypeScript 7 alias or --tsgo/@typescript/native-preview setup
while retaining TypeScript 6 for Svelte tooling. Update the relevant
package.json dependencies and check script so plain svelte-check runs
successfully with the existing tsconfig.app.json.

@twangodev

Copy link
Copy Markdown
Owner Author

Superseded by a rebuilt roll-up without the typescript 7 bump: svelte-check 4.7.2 crashes against typescript@7 (TS 7 no longer ships the JS API svelte-check consumes), and CI does not run npm run check, so the green checks on #111 never exercised it. New PR carries the remaining 11 bumps.

@twangodev twangodev closed this Aug 5, 2026
@twangodev
twangodev deleted the chore/deps-rollup branch August 5, 2026 21:32
@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Qodana for JVM

It seems all right 👌

No new problems were found according to the checks applied

💡 Qodana analysis was run in the pull request mode: only the changed files were checked

View the detailed Qodana report

To be able to view the detailed Qodana report, you can either:

To get *.log files or any other Qodana artifacts, run the action with upload-result option set to true,
so that the action will upload the files as the job artifacts:

      - name: 'Qodana Scan'
        uses: JetBrains/qodana-action@v2026.2.0
        with:
          upload-result: true
Contact Qodana team

Contact us at qodana-support@jetbrains.com

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants