chore(deps): roll up 11 dependabot bumps - #127
Conversation
Bumps [@sveltejs/vite-plugin-svelte](https://github.com/sveltejs/vite-plugin-svelte/tree/HEAD/packages/vite-plugin-svelte) from 7.1.4 to 7.2.0. - [Release notes](https://github.com/sveltejs/vite-plugin-svelte/releases) - [Changelog](https://github.com/sveltejs/vite-plugin-svelte/blob/main/packages/vite-plugin-svelte/CHANGELOG.md) - [Commits](https://github.com/sveltejs/vite-plugin-svelte/commits/@sveltejs/vite-plugin-svelte@7.2.0/packages/vite-plugin-svelte) --- updated-dependencies: - dependency-name: "@sveltejs/vite-plugin-svelte" dependency-version: 7.2.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 26.1.0 to 26.1.1. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) --- updated-dependencies: - dependency-name: "@types/node" dependency-version: 26.1.1 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [shadcn-svelte](https://github.com/huntabyte/shadcn-svelte/tree/HEAD/packages/cli) from 1.3.0 to 1.4.0. - [Release notes](https://github.com/huntabyte/shadcn-svelte/releases) - [Changelog](https://github.com/huntabyte/shadcn-svelte/blob/main/packages/cli/CHANGELOG.md) - [Commits](https://github.com/huntabyte/shadcn-svelte/commits/shadcn-svelte@1.4.0/packages/cli) --- updated-dependencies: - dependency-name: shadcn-svelte dependency-version: 1.4.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.1.3 to 8.1.4. - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.1.4/packages/vite) --- updated-dependencies: - dependency-name: vite dependency-version: 8.1.4 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps org.jetbrains.intellij.platform.settings from 2.17.0 to 2.18.1. --- updated-dependencies: - dependency-name: org.jetbrains.intellij.platform.settings dependency-version: 2.18.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps org.jetbrains.intellij.platform from 2.17.0 to 2.18.1. --- updated-dependencies: - dependency-name: org.jetbrains.intellij.platform dependency-version: 2.18.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.jetbrains.kotlinx.kover](https://github.com/Kotlin/kotlinx-kover) from 0.9.7 to 0.9.9. - [Release notes](https://github.com/Kotlin/kotlinx-kover/releases) - [Changelog](https://github.com/Kotlin/kotlinx-kover/blob/main/CHANGELOG.md) - [Commits](https://github.com/Kotlin/kotlinx-kover/commits) --- updated-dependencies: - dependency-name: org.jetbrains.kotlinx.kover dependency-version: 0.9.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.jetbrains.intellij.plugins:verifier-cli](https://github.com/JetBrains/intellij-plugin-verifier) from 1.408 to 1.409. - [Release notes](https://github.com/JetBrains/intellij-plugin-verifier/releases) - [Changelog](https://github.com/JetBrains/intellij-plugin-verifier/blob/master/CHANGELOG.md) - [Commits](JetBrains/intellij-plugin-verifier@1.408...1.409) --- updated-dependencies: - dependency-name: org.jetbrains.intellij.plugins:verifier-cli dependency-version: '1.409' dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [JetBrains/qodana-action](https://github.com/jetbrains/qodana-action) from 2026.1.3 to 2026.2.0. - [Release notes](https://github.com/jetbrains/qodana-action/releases) - [Commits](JetBrains/qodana-action@v2026.1.3...v2026.2.0) --- updated-dependencies: - dependency-name: JetBrains/qodana-action dependency-version: 2026.2.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4 to 4.37.4. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v4...v4.37.4) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.37.4 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [gradle/actions](https://github.com/gradle/actions) from 5 to 6.2.0. - [Release notes](https://github.com/gradle/actions/releases) - [Commits](gradle/actions@v5...v6.2.0) --- updated-dependencies: - dependency-name: gradle/actions dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…/actions-6.2.0' into worktree-deps-rollup
…/codeql-action-4.37.4' into worktree-deps-rollup
…ins/qodana-action-2026.2.0' into worktree-deps-rollup
…intellij.plugins-verifier-cli-1.409' into worktree-deps-rollup
…kotlinx.kover-0.9.9' into worktree-deps-rollup
…intellij.platform-2.18.1' into worktree-deps-rollup
…intellij.platform.settings-2.18.1' into worktree-deps-rollup
…8.1.4' into worktree-deps-rollup
…n-svelte-1.4.0' into worktree-deps-rollup
…/node-26.1.1' into worktree-deps-rollup
…ejs/vite-plugin-svelte-7.2.0' into worktree-deps-rollup
|
Warning Review limit reached
Next review available in: 49 minutes You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (6)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
There was a problem hiding this comment.
Pull request overview
Roll-up of multiple Dependabot updates across the UI toolchain, Gradle/IntelliJ Platform build tooling, and GitHub Actions workflows, keeping the plugin’s minimum supported IDE version unchanged.
Changes:
- Bump UI dev dependencies (Vite,
@sveltejs/vite-plugin-svelte,shadcn-svelte,@types/node) and refreshpackage-lock.jsonaccordingly. - Update Gradle/IntelliJ Platform-related versions (IntelliJ Platform Gradle plugins, Plugin Verifier, Kover).
- Update GitHub Actions workflow action versions (Gradle setup, CodeQL action, Qodana action).
Reviewed changes
Copilot reviewed 6 out of 7 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
ui/package.json |
Updates UI dev dependency versions for the frontend build/check tooling. |
ui/package-lock.json |
Regenerates lockfile to reflect updated UI dependency graph. |
settings.gradle.kts |
Bumps org.jetbrains.intellij.platform.settings plugin version. |
gradle/libs.versions.toml |
Bumps IntelliJ Platform Gradle plugin, Plugin Verifier, and Kover versions. |
.github/workflows/release.yml |
Updates Gradle setup action version used during release publishing. |
.github/workflows/codeql.yml |
Pins CodeQL init/analyze action to the newer v4.37.4 release. |
.github/workflows/build.yml |
Updates Gradle setup action, CodeQL SARIF upload action, and Qodana action versions used in CI. |
Files not reviewed (1)
- ui/package-lock.json: Generated file
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Qodana for JVMIt seems all right 👌 No new problems were found according to the checks applied 💡 Qodana analysis was run in the pull request mode: only the changed files were checked View the detailed Qodana reportTo be able to view the detailed Qodana report, you can either:
To get - name: 'Qodana Scan'
uses: JetBrains/qodana-action@v2026.2.0
with:
upload-result: trueContact Qodana teamContact us at qodana-support@jetbrains.com
|
Octopus roll-up of the open dependabot PRs that are safe to merge. None touch the platform version, since-build, or anything else affecting the minimum supported IDE version. Supersedes #126.
Merged head commits of:
Excluded:
TypeError: Cannot read properties of undefined (reading 'useCaseSensitiveFileNames')) because TS 7's native compiler no longer ships the JS API svelte-check consumes. CI never runsnpm run check, so chore(deps-dev): bump typescript from 6.0.3 to 7.0.2 in /ui #111's green checks did not cover this. Needs svelte-check support for TS 7 first.Verified locally:
./gradlew helpresolves with the 2.18.1 plugin pair,npm ciis lockfile-consistent, andnpm run checkoutput is identical to main (2 pre-existing App.svelte errors, no new diagnostics).Red checks on the individual dependabot PRs were investigated: IU-2026.2 verify failures are a pre-existing EAP compile issue unrelated to these bumps; failures on #116/#117 were a GitHub Actions outage on 2026-07-13.