Skip to content

chore(deps): roll up 11 dependabot bumps - #127

Merged
twangodev merged 22 commits into
mainfrom
chore/deps-rollup-v2
Aug 5, 2026
Merged

chore(deps): roll up 11 dependabot bumps#127
twangodev merged 22 commits into
mainfrom
chore/deps-rollup-v2

Conversation

@twangodev

Copy link
Copy Markdown
Owner

Octopus roll-up of the open dependabot PRs that are safe to merge. None touch the platform version, since-build, or anything else affecting the minimum supported IDE version. Supersedes #126.

Merged head commits of:

Excluded:

Verified locally: ./gradlew help resolves with the 2.18.1 plugin pair, npm ci is lockfile-consistent, and npm run check output is identical to main (2 pre-existing App.svelte errors, no new diagnostics).

Red checks on the individual dependabot PRs were investigated: IU-2026.2 verify failures are a pre-existing EAP compile issue unrelated to these bumps; failures on #116/#117 were a GitHub Actions outage on 2026-07-13.

dependabot Bot and others added 22 commits July 8, 2026 13:06
Bumps [@sveltejs/vite-plugin-svelte](https://github.com/sveltejs/vite-plugin-svelte/tree/HEAD/packages/vite-plugin-svelte) from 7.1.4 to 7.2.0.
- [Release notes](https://github.com/sveltejs/vite-plugin-svelte/releases)
- [Changelog](https://github.com/sveltejs/vite-plugin-svelte/blob/main/packages/vite-plugin-svelte/CHANGELOG.md)
- [Commits](https://github.com/sveltejs/vite-plugin-svelte/commits/@sveltejs/vite-plugin-svelte@7.2.0/packages/vite-plugin-svelte)

---
updated-dependencies:
- dependency-name: "@sveltejs/vite-plugin-svelte"
  dependency-version: 7.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 26.1.0 to 26.1.1.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.1.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [shadcn-svelte](https://github.com/huntabyte/shadcn-svelte/tree/HEAD/packages/cli) from 1.3.0 to 1.4.0.
- [Release notes](https://github.com/huntabyte/shadcn-svelte/releases)
- [Changelog](https://github.com/huntabyte/shadcn-svelte/blob/main/packages/cli/CHANGELOG.md)
- [Commits](https://github.com/huntabyte/shadcn-svelte/commits/shadcn-svelte@1.4.0/packages/cli)

---
updated-dependencies:
- dependency-name: shadcn-svelte
  dependency-version: 1.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.1.3 to 8.1.4.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.1.4/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 8.1.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps org.jetbrains.intellij.platform.settings from 2.17.0 to 2.18.1.

---
updated-dependencies:
- dependency-name: org.jetbrains.intellij.platform.settings
  dependency-version: 2.18.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps org.jetbrains.intellij.platform from 2.17.0 to 2.18.1.

---
updated-dependencies:
- dependency-name: org.jetbrains.intellij.platform
  dependency-version: 2.18.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.jetbrains.kotlinx.kover](https://github.com/Kotlin/kotlinx-kover) from 0.9.7 to 0.9.9.
- [Release notes](https://github.com/Kotlin/kotlinx-kover/releases)
- [Changelog](https://github.com/Kotlin/kotlinx-kover/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Kotlin/kotlinx-kover/commits)

---
updated-dependencies:
- dependency-name: org.jetbrains.kotlinx.kover
  dependency-version: 0.9.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.jetbrains.intellij.plugins:verifier-cli](https://github.com/JetBrains/intellij-plugin-verifier) from 1.408 to 1.409.
- [Release notes](https://github.com/JetBrains/intellij-plugin-verifier/releases)
- [Changelog](https://github.com/JetBrains/intellij-plugin-verifier/blob/master/CHANGELOG.md)
- [Commits](JetBrains/intellij-plugin-verifier@1.408...1.409)

---
updated-dependencies:
- dependency-name: org.jetbrains.intellij.plugins:verifier-cli
  dependency-version: '1.409'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [JetBrains/qodana-action](https://github.com/jetbrains/qodana-action) from 2026.1.3 to 2026.2.0.
- [Release notes](https://github.com/jetbrains/qodana-action/releases)
- [Commits](JetBrains/qodana-action@v2026.1.3...v2026.2.0)

---
updated-dependencies:
- dependency-name: JetBrains/qodana-action
  dependency-version: 2026.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4 to 4.37.4.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v4...v4.37.4)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.37.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [gradle/actions](https://github.com/gradle/actions) from 5 to 6.2.0.
- [Release notes](https://github.com/gradle/actions/releases)
- [Commits](gradle/actions@v5...v6.2.0)

---
updated-dependencies:
- dependency-name: gradle/actions
  dependency-version: 6.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…/codeql-action-4.37.4' into worktree-deps-rollup
…ins/qodana-action-2026.2.0' into worktree-deps-rollup
…intellij.plugins-verifier-cli-1.409' into worktree-deps-rollup
…kotlinx.kover-0.9.9' into worktree-deps-rollup
…intellij.platform-2.18.1' into worktree-deps-rollup
…intellij.platform.settings-2.18.1' into worktree-deps-rollup
…ejs/vite-plugin-svelte-7.2.0' into worktree-deps-rollup
Copilot AI lite review requested due to automatic review settings August 5, 2026 21:32
@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@twangodev, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 49 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 12548b57-9a31-4430-8206-309d0a256b6e

📥 Commits

Reviewing files that changed from the base of the PR and between 3c937c0 and 1e41843.

⛔ Files ignored due to path filters (1)
  • ui/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (6)
  • .github/workflows/build.yml
  • .github/workflows/codeql.yml
  • .github/workflows/release.yml
  • gradle/libs.versions.toml
  • settings.gradle.kts
  • ui/package.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedmaven/​org.jetbrains.intellij.plugins/​verifier-cli@​1.408 ⏵ 1.40936 -1810090100100
Updatednpm/​@​types/​node@​26.1.0 ⏵ 26.1.110010081 +195 -1100
Updatednpm/​@​sveltejs/​vite-plugin-svelte@​7.1.4 ⏵ 7.2.0100 +110081 +195 -1100
Updatednpm/​vite@​8.1.3 ⏵ 8.1.499 +110082 +198 +1100
Updatednpm/​shadcn-svelte@​1.3.0 ⏵ 1.4.09110085 +193 +3100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: maven org.bouncycastle:bcprov-jdk18on is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?maven/org.jetbrains.intellij.plugins/verifier-cli@1.409maven/org.bouncycastle/bcprov-jdk18on@1.85

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/org.bouncycastle/bcprov-jdk18on@1.85. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Roll-up of multiple Dependabot updates across the UI toolchain, Gradle/IntelliJ Platform build tooling, and GitHub Actions workflows, keeping the plugin’s minimum supported IDE version unchanged.

Changes:

  • Bump UI dev dependencies (Vite, @sveltejs/vite-plugin-svelte, shadcn-svelte, @types/node) and refresh package-lock.json accordingly.
  • Update Gradle/IntelliJ Platform-related versions (IntelliJ Platform Gradle plugins, Plugin Verifier, Kover).
  • Update GitHub Actions workflow action versions (Gradle setup, CodeQL action, Qodana action).

Reviewed changes

Copilot reviewed 6 out of 7 changed files in this pull request and generated no comments.

Show a summary per file
File Description
ui/package.json Updates UI dev dependency versions for the frontend build/check tooling.
ui/package-lock.json Regenerates lockfile to reflect updated UI dependency graph.
settings.gradle.kts Bumps org.jetbrains.intellij.platform.settings plugin version.
gradle/libs.versions.toml Bumps IntelliJ Platform Gradle plugin, Plugin Verifier, and Kover versions.
.github/workflows/release.yml Updates Gradle setup action version used during release publishing.
.github/workflows/codeql.yml Pins CodeQL init/analyze action to the newer v4.37.4 release.
.github/workflows/build.yml Updates Gradle setup action, CodeQL SARIF upload action, and Qodana action versions used in CI.
Files not reviewed (1)
  • ui/package-lock.json: Generated file

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Qodana for JVM

It seems all right 👌

No new problems were found according to the checks applied

💡 Qodana analysis was run in the pull request mode: only the changed files were checked

View the detailed Qodana report

To be able to view the detailed Qodana report, you can either:

To get *.log files or any other Qodana artifacts, run the action with upload-result option set to true,
so that the action will upload the files as the job artifacts:

      - name: 'Qodana Scan'
        uses: JetBrains/qodana-action@v2026.2.0
        with:
          upload-result: true
Contact Qodana team

Contact us at qodana-support@jetbrains.com

@twangodev
twangodev merged commit 9c3d639 into main Aug 5, 2026
17 checks passed
@twangodev
twangodev deleted the chore/deps-rollup-v2 branch August 5, 2026 21:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants