Skip to content

chore(deps): bump the minor-production-deps group with 4 updates - #1536

Open
dependabot[bot] wants to merge 1 commit into
nextfrom
dependabot/npm_and_yarn/minor-production-deps-6cc3995d72
Open

dependabot[bot] wants to merge 1 commit into
nextfrom
dependabot/npm_and_yarn/minor-production-deps-6cc3995d72

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-production-deps group with 4 updates: ignore, js-yaml, oas and oas-normalize.

Updates ignore from 7.0.6 to 7.0.10

Release notes

Sourced from ignore's releases.

7.0.8

PATCH Brings pattern matching closer to git:

  • PATCH A backslash now makes the next character a literal, exactly as git does: \* matches a literal * rather than acting as a wildcard, \? matches a literal ?, and \d, \b, \/ and the like are the plain characters instead of regular-expression escapes.
  • PATCH Only a trailing run of spaces is stripped from a pattern — never tabs or other whitespace — and a line of only tabs is treated as a pattern rather than a blank line, matching git.

An upgrade is recommended for all dependents.

Commits
  • 3a12e09 bump version 9.0.10
  • 58ae427 Merge pull request #168 from MFA-G/fix/wildcard-partial-separator
  • e341595 fix: let a wildcard reach past a partial match of what follows it
  • 821765e #166: bump version 7.0.9
  • e00d35e Merge pull request #167 from bentbrain/fix-bom-blank-line
  • 9b6481f fix(ignore): reject BOM-only blank lines before compilation
  • 20b802a bump version 7.0.8
  • 0414358 build: require 100% coverage of index.js as an explicit gate
  • 968aee6 compat: check compatibility by running old versions' test suites
  • 8e46220 build: run the compatibility gate as part of npm test
  • Additional commits viewable in compare view

Updates js-yaml from 5.4.1 to 5.4.2

Changelog

Sourced from js-yaml's changelog.

[5.4.2] - 2026-09-13

Fixed

  • forceQuotes no longer quotes non-string scalars, #798.
Commits

Updates oas from 38.5.0 to 38.6.0

Changelog

Sourced from oas's changelog.

38.6.0

Minor Changes

  • 42a653e: Add support for the apply-endpoint-order ReadMe extension (x-readme.apply-endpoint-order) for opting in to ordering API operation pages from their API definition.

Patch Changes

  • 8e9fb56: Preserve discriminator children discovered through allOf inheritance and their dependencies when reducing or pruning OpenAPI definitions.

38.5.3

Patch Changes

  • bb7a31d: Resolve property examples and defaults from the most specific JSON pointer first, so a nested property no longer picks up the value of a shallower property that shares its name.

38.5.2

Patch Changes

  • 4180d7c: Populate property examples from a schema-level examples array of objects
  • 2a7dfeb: Retain Path Item $ref targets reached through #/paths and #/webhooks operation pointers, and keep security schemes whose names require JSON Pointer escaping, so reduce no longer emits dangling references.
    • @​readme/openapi-parser@​9.0.0

38.5.1

Patch Changes

  • f9c2553: Resolve Path Item $refs when scoping analyzeOperation() / analyzeWebhookOperation() so components.pathItems operations no longer throw "operation not found".
  • 9e0fe7d: Fix analyzer() gating the webhooks query on xmlSchemas, so requesting webhook analysis actually returns webhook results.
  • 164d208: Resolve Path Item $refs when matching URLs to operations and when collecting common parameters so components.pathItems and webhook Path Items no longer drop methods or parameters.
  • b440535: Retain Path Items and webhooks targeted by #/paths and #/webhooks $refs — including whole-item and path-level parameter pointers — so reduce/prune no longer emit dangling references. Field-level pointers also keep sibling container $ref targets.
  • Updated dependencies [21732a2]
  • Updated dependencies [3f27c3e]
  • Updated dependencies [e3f4494]
  • Updated dependencies [fcfb099]
    • @​readme/openapi-parser@​8.0.2
Commits

Updates oas-normalize from 18.0.0 to 18.0.2

Release notes

Sourced from oas-normalize's releases.

18.0.2

What's Changed

Full Changelog: readmeio/oas@18.0.1...18.0.2

18.0.1

What's Changed

Full Changelog: readmeio/oas@18.0.0...18.0.1

Changelog

Sourced from oas-normalize's changelog.

18.0.2

Patch Changes

  • @​readme/openapi-parser@​9.0.0

18.0.1

Patch Changes

  • 3a39803: chore(deps): bump js-yaml from 4.3.1 to 5.4.1
  • Updated dependencies [21732a2]
  • Updated dependencies [3f27c3e]
  • Updated dependencies [e3f4494]
  • Updated dependencies [fcfb099]
    • @​readme/openapi-parser@​8.0.2
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-production-deps group with 4 updates: [ignore](https://github.com/kaelzhang/node-ignore), [js-yaml](https://github.com/nodeca/js-yaml), [oas](https://github.com/readmeio/oas/tree/HEAD/packages/oas) and [oas-normalize](https://github.com/readmeio/oas/tree/HEAD/packages/oas-normalize).


Updates `ignore` from 7.0.6 to 7.0.10
- [Release notes](https://github.com/kaelzhang/node-ignore/releases)
- [Commits](kaelzhang/node-ignore@7.0.6...7.0.10)

Updates `js-yaml` from 5.4.1 to 5.4.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@5.4.1...5.4.2)

Updates `oas` from 38.5.0 to 38.6.0
- [Release notes](https://github.com/readmeio/oas/releases)
- [Changelog](https://github.com/readmeio/oas/blob/main/packages/oas/CHANGELOG.md)
- [Commits](https://github.com/readmeio/oas/commits/oas@38.6.0/packages/oas)

Updates `oas-normalize` from 18.0.0 to 18.0.2
- [Release notes](https://github.com/readmeio/oas/releases)
- [Changelog](https://github.com/readmeio/oas/blob/main/packages/oas-normalize/CHANGELOG.md)
- [Commits](https://github.com/readmeio/oas/commits/18.0.2/packages/oas-normalize)

---
updated-dependencies:
- dependency-name: ignore
  dependency-version: 7.0.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-production-deps
- dependency-name: js-yaml
  dependency-version: 5.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-production-deps
- dependency-name: oas
  dependency-version: 38.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-production-deps
- dependency-name: oas-normalize
  dependency-version: 18.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-production-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 1, 2026
@dependabot
dependabot Bot requested a review from erunion as a code owner October 1, 2026 03:44
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants