chore(deps): roll up 12 dependabot bumps - #126
Conversation
Bumps [@sveltejs/vite-plugin-svelte](https://github.com/sveltejs/vite-plugin-svelte/tree/HEAD/packages/vite-plugin-svelte) from 7.1.4 to 7.2.0. - [Release notes](https://github.com/sveltejs/vite-plugin-svelte/releases) - [Changelog](https://github.com/sveltejs/vite-plugin-svelte/blob/main/packages/vite-plugin-svelte/CHANGELOG.md) - [Commits](https://github.com/sveltejs/vite-plugin-svelte/commits/@sveltejs/vite-plugin-svelte@7.2.0/packages/vite-plugin-svelte) --- updated-dependencies: - dependency-name: "@sveltejs/vite-plugin-svelte" dependency-version: 7.2.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 26.1.0 to 26.1.1. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) --- updated-dependencies: - dependency-name: "@types/node" dependency-version: 26.1.1 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [typescript](https://github.com/microsoft/TypeScript) from 6.0.3 to 7.0.2. - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) --- updated-dependencies: - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [shadcn-svelte](https://github.com/huntabyte/shadcn-svelte/tree/HEAD/packages/cli) from 1.3.0 to 1.4.0. - [Release notes](https://github.com/huntabyte/shadcn-svelte/releases) - [Changelog](https://github.com/huntabyte/shadcn-svelte/blob/main/packages/cli/CHANGELOG.md) - [Commits](https://github.com/huntabyte/shadcn-svelte/commits/shadcn-svelte@1.4.0/packages/cli) --- updated-dependencies: - dependency-name: shadcn-svelte dependency-version: 1.4.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.1.3 to 8.1.4. - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.1.4/packages/vite) --- updated-dependencies: - dependency-name: vite dependency-version: 8.1.4 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps org.jetbrains.intellij.platform.settings from 2.17.0 to 2.18.1. --- updated-dependencies: - dependency-name: org.jetbrains.intellij.platform.settings dependency-version: 2.18.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps org.jetbrains.intellij.platform from 2.17.0 to 2.18.1. --- updated-dependencies: - dependency-name: org.jetbrains.intellij.platform dependency-version: 2.18.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.jetbrains.kotlinx.kover](https://github.com/Kotlin/kotlinx-kover) from 0.9.7 to 0.9.9. - [Release notes](https://github.com/Kotlin/kotlinx-kover/releases) - [Changelog](https://github.com/Kotlin/kotlinx-kover/blob/main/CHANGELOG.md) - [Commits](https://github.com/Kotlin/kotlinx-kover/commits) --- updated-dependencies: - dependency-name: org.jetbrains.kotlinx.kover dependency-version: 0.9.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.jetbrains.intellij.plugins:verifier-cli](https://github.com/JetBrains/intellij-plugin-verifier) from 1.408 to 1.409. - [Release notes](https://github.com/JetBrains/intellij-plugin-verifier/releases) - [Changelog](https://github.com/JetBrains/intellij-plugin-verifier/blob/master/CHANGELOG.md) - [Commits](JetBrains/intellij-plugin-verifier@1.408...1.409) --- updated-dependencies: - dependency-name: org.jetbrains.intellij.plugins:verifier-cli dependency-version: '1.409' dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [JetBrains/qodana-action](https://github.com/jetbrains/qodana-action) from 2026.1.3 to 2026.2.0. - [Release notes](https://github.com/jetbrains/qodana-action/releases) - [Commits](JetBrains/qodana-action@v2026.1.3...v2026.2.0) --- updated-dependencies: - dependency-name: JetBrains/qodana-action dependency-version: 2026.2.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4 to 4.37.4. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v4...v4.37.4) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.37.4 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [gradle/actions](https://github.com/gradle/actions) from 5 to 6.2.0. - [Release notes](https://github.com/gradle/actions/releases) - [Commits](gradle/actions@v5...v6.2.0) --- updated-dependencies: - dependency-name: gradle/actions dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…/actions-6.2.0' into worktree-deps-rollup
…/codeql-action-4.37.4' into worktree-deps-rollup
…ins/qodana-action-2026.2.0' into worktree-deps-rollup
…intellij.plugins-verifier-cli-1.409' into worktree-deps-rollup
…kotlinx.kover-0.9.9' into worktree-deps-rollup
…intellij.platform-2.18.1' into worktree-deps-rollup
…intellij.platform.settings-2.18.1' into worktree-deps-rollup
…8.1.4' into worktree-deps-rollup
…n-svelte-1.4.0' into worktree-deps-rollup
…cript-7.0.2' into worktree-deps-rollup # Conflicts: # ui/package-lock.json # ui/package.json
…/node-26.1.1' into worktree-deps-rollup
…ejs/vite-plugin-svelte-7.2.0' into worktree-deps-rollup
📝 WalkthroughWalkthroughChangesDependency and tooling updates
Estimated code review effort: 2 (Simple) | ~10 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
There was a problem hiding this comment.
Pull request overview
Rolls up multiple Dependabot dependency bumps across the Gradle build (IntelliJ Platform + tooling), the UI toolchain (Vite/Svelte/TypeScript ecosystem), and GitHub Actions workflows to keep CI and build tooling up to date without changing the minimum supported IDE/platform version.
Changes:
- Bump UI dev dependencies (TypeScript, Vite, shadcn-svelte, @types/node, @sveltejs/vite-plugin-svelte) and regenerate
package-lock.json. - Bump Gradle toolchain versions (IntelliJ Platform Gradle plugin + settings plugin, Kover, Plugin Verifier).
- Update GitHub Actions workflow action versions (Gradle setup, CodeQL, Qodana).
Reviewed changes
Copilot reviewed 6 out of 7 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
| ui/package.json | Updates UI devDependency versions (TypeScript/Vite/Svelte tooling). |
| ui/package-lock.json | Regenerated lockfile to reflect updated UI dependency graph (incl. new platform optional deps). |
| settings.gradle.kts | Bumps org.jetbrains.intellij.platform.settings plugin version. |
| gradle/libs.versions.toml | Bumps IntelliJ Platform Gradle plugin, Kover, and verifier-cli versions. |
| .github/workflows/release.yml | Updates Gradle setup action version used during release publishing. |
| .github/workflows/codeql.yml | Pins CodeQL init/analyze actions to the bumped patch version. |
| .github/workflows/build.yml | Updates Gradle setup, CodeQL upload-sarif, and Qodana action versions in CI. |
Files not reviewed (1)
- ui/package-lock.json: Generated file
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| "@sveltejs/vite-plugin-svelte": "^7.2.0", | ||
| "@tailwindcss/vite": "^4.3.2", | ||
| "@tsconfig/svelte": "^5.0.8", | ||
| "@types/node": "^26.1.0", | ||
| "@types/node": "^26.1.1", | ||
| "bits-ui": "^2.18.1", |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@ui/package.json`:
- Around line 28-33: Add the required TypeScript 7 integration for the
svelte-check command, using the documented `@typescript/native` TypeScript 7 alias
or --tsgo/@typescript/native-preview setup while retaining TypeScript 6 for
Svelte tooling. Update the relevant package.json dependencies and check script
so plain svelte-check runs successfully with the existing tsconfig.app.json.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 9e4440c3-a7ef-4d37-9c42-8d3bca073e05
⛔ Files ignored due to path filters (1)
ui/package-lock.jsonis excluded by!**/package-lock.json
📒 Files selected for processing (6)
.github/workflows/build.yml.github/workflows/codeql.yml.github/workflows/release.ymlgradle/libs.versions.tomlsettings.gradle.ktsui/package.json
| "svelte-check": "^4.7.2", | ||
| "tailwind-merge": "^3.6.0", | ||
| "tailwind-variants": "^3.2.2", | ||
| "tailwindcss": "^4.3.2", | ||
| "tw-animate-css": "^1.4.0", | ||
| "typescript": "~6.0.3", | ||
| "vite": "^8.1.3", | ||
| "typescript": "~7.0.2", |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
python - <<'PY'
import json
from pathlib import Path
package = json.loads(Path("ui/package.json").read_text())
print("scripts:", json.dumps(package.get("scripts", {}), indent=2))
print("relevant dependencies:", json.dumps({
k: v for k, v in package.get("devDependencies", {}).items()
if k in {"svelte-check", "typescript", "`@typescript/native`", "`@typescript/native-preview`"}
}, indent=2))
PY
rg -n '"(svelte-check|typescript|`@typescript/native`|`@typescript/native-preview`)|--tsgo' \
ui/package.json ui/package-lock.jsonRepository: twangodev/jetplay
Length of output: 953
🌐 Web query:
svelte-check 4.7.2 README TypeScript 7 tsgo @typescript/native-preview TypeScript 6 TypeScript 7
💡 Result:
The current state of TypeScript 7 and its relationship with svelte-check is as follows: Svelte-check 4.7.2 (released July 7, 2026) includes updates regarding the experimental --tsgo flag, which allows users to leverage the native TypeScript compiler port (the foundation of TypeScript 7) [1][2]. The --tsgo flag in svelte-check relies on the @typescript/native-preview package [3][4]. This package was used to distribute preview builds of the native TypeScript compiler (often referred to as tsgo) during the transition from TypeScript 6.0 to TypeScript 7.0 [5][6][7]. As of the release of TypeScript 7.0, the stable version is distributed under the official typescript package, and the tsgo binary has been transitioned to be available as the standard tsc command [6][8][4]. However, ecosystem tools like svelte-check that rely on deep integration with the TypeScript compiler's programmatic API face compatibility challenges [9]. Because TypeScript 7 initially lacked a stable programmatic API, these tools often require TypeScript 6.0 for internal operations, even when experimenting with TypeScript 7 features via --tsgo or similar mechanisms [9]. In summary: - svelte-check 4.7.2 provides experimental support for the native compiler (tsgo) through the --tsgo flag [10][1]. - This functionality is intended to allow testing the performance improvements of the new compiler architecture [6][4]. - Users should be aware that full programmatic integration of TypeScript 7 into tools like svelte-check is an ongoing effort, and users may still require a TypeScript 6.0 environment for stable type-checking operations within these tools [9].
Citations:
- 1: https://github.com/sveltejs/language-tools/releases/tag/svelte-check@4.7.2
- 2: https://github.com/sveltejs/language-tools/blob/master/packages/svelte-check/CHANGELOG.md
- 3: https://www.npmjs.com/package/svelte-check
- 4: https://github.com/microsoft/typescript-go?tab=readme-ov-file
- 5: https://www.npmjs.com/package/@typescript/native-preview
- 6: https://devblogs.microsoft.com/typescript/announcing-typescript-7-0-rc/
- 7: https://devblogs.microsoft.com/typescript/announcing-typescript-native-previews/
- 8: https://devblogs.microsoft.com/typescript/announcing-typescript-7-0-beta/
- 9: Typescript 7 crashes svelte2tsx and svelte-check sveltejs/language-tools#3063
- 10: https://github.com/sveltejs/language-tools/blob/master/packages/svelte-check/README.md
🌐 Web query:
Svelte language tools README svelte-check TypeScript 7 @typescript/native-preview @typescript/native``
💡 Result:
As of August 5, 2026, svelte-check does not natively support TypeScript 7 due to fundamental incompatibilities with TypeScript 7's architecture and programmatic API [1]. While TypeScript 7 is stable, Svelte tooling—including svelte-check and svelte2tsx—requires TypeScript 6.0 for core language service operations [1]. To use TypeScript 7 within a project that also requires Svelte tooling, maintainers recommend a dual-version setup using npm aliases [2]. This allows you to keep TypeScript 6 for Svelte's requirements while experimenting with or running TypeScript 7 for other parts of your build [2][1]. Recommended setup: npm install --save-dev typescript@~6 @typescript/native@npm:typescript@7 [2] For type-checking specifically, svelte-check provides experimental flags to leverage TypeScript's "Go" (native) implementation, which is often used in conjunction with TypeScript 7 workflows [3][2][4]. Key flags for svelte-check: --tsgo: Uses TypeScript's native Go implementation [5][3]. This requires the @typescript/native-preview package to be installed [5][2]. Note that this approach has specific limitations similar to the --incremental flag, such as difficulties handling files outside the root directory of your tsconfig.json [5][3]. --tsgo-experimental-api: An alternative flag that avoids some of the limitations of --tsgo by not caching virtual code, though it is slightly slower and considered experimental [6][4]. These flags are intended for testing and experimentation as the Svelte and TypeScript teams continue to work toward full compatibility [7][6][1]. In typical environments, you should continue to rely on a stable TypeScript 6.0 dependency for your primary Svelte development workflow to avoid crashes and integration errors [1][8].
Citations:
- 1: Typescript 7 crashes svelte2tsx and svelte-check sveltejs/language-tools#3063
- 2: https://www.npmjs.com/package/svelte-check
- 3: feat: svelte-check
--incremental/--tsgosveltejs/language-tools#2932 - 4: TypeScript Go support (at least in CLI) sveltejs/language-tools#2733
- 5: https://github.com/sveltejs/language-tools/blob/master/packages/svelte-check/README.md
- 6: feat: svelte-check tsgo support with experimental api sveltejs/language-tools#3036
- 7: https://www.npmjs.com/package/@typescript/native-preview
- 8: svelte-check crashes under TypeScript 7 — blocks TS 7 upgrade philoserf/obsidian-periodic-notes#157
Add the required TypeScript 7 support for svelte-check.
check runs plain svelte-check --tsconfig ./tsconfig.app.json, but svelte-check 4.7.2 needs both TypeScript 6 for Svelte tooling and TypeScript 7 support for the project TypeScript version. Add @typescript/native@npm:typescript@7 or use the documented --tsgo/@typescript/native-preview setup, or keep TypeScript 6 as the compiler until the TypeScript 7 integration is in place.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@ui/package.json` around lines 28 - 33, Add the required TypeScript 7
integration for the svelte-check command, using the documented
`@typescript/native` TypeScript 7 alias or --tsgo/@typescript/native-preview setup
while retaining TypeScript 6 for Svelte tooling. Update the relevant
package.json dependencies and check script so plain svelte-check runs
successfully with the existing tsconfig.app.json.
|
Superseded by a rebuilt roll-up without the typescript 7 bump: svelte-check 4.7.2 crashes against typescript@7 (TS 7 no longer ships the JS API svelte-check consumes), and CI does not run |
Qodana for JVMIt seems all right 👌 No new problems were found according to the checks applied 💡 Qodana analysis was run in the pull request mode: only the changed files were checked View the detailed Qodana reportTo be able to view the detailed Qodana report, you can either:
To get - name: 'Qodana Scan'
uses: JetBrains/qodana-action@v2026.2.0
with:
upload-result: trueContact Qodana teamContact us at qodana-support@jetbrains.com
|
Octopus roll-up of the 12 open dependabot PRs that are safe to merge. None touch the platform version, since-build, or anything else affecting the minimum supported IDE version.
Merged head commits of:
Excluded: #119 (kotlin.plugin.serialization 2.4.10) — requires a coordinated Kotlin 2.4 upgrade, build fails standalone.
ui/package-lock.json was regenerated after merging so it is consistent with the merged package.json (typescript 7.0.2 + its platform binaries).
The red checks on the individual PRs were investigated: IU-2026.2 verify failures are a pre-existing EAP compile issue unrelated to these bumps; the failures on #116/#117 were a GitHub Actions outage on 2026-07-13.
Summary by CodeRabbit