Skip to content

chore(deps): bump the all-deps group across 1 directory with 7 updates#673

Closed
dependabot[bot] wants to merge 4 commits intomainfrom
dependabot/npm_and_yarn/templates/quickstart/all-deps-b3e2cd3519
Closed

chore(deps): bump the all-deps group across 1 directory with 7 updates#673
dependabot[bot] wants to merge 4 commits intomainfrom
dependabot/npm_and_yarn/templates/quickstart/all-deps-b3e2cd3519

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Apr 9, 2026

Manual fix: audit GHSA suppression

Dependabot's dependency bumps introduced 3 transitive vulnerabilities via @typespec/compiler's dependency tree. These are unfixable on our end — only the TypeSpec team can update their pinned versions of picomatch and yaml.

3 GHSAs suppressed — full details including severity, dependency paths, and remediation TODOs are documented in AUDIT_EXCEPTIONS.md.


Original Dependabot description

Bumps the all-deps group with 7 updates in the /templates/quickstart directory:

Package From To
@typespec/compiler 1.8.0 1.11.0
@typespec/http 1.8.0 1.11.0
@typespec/json-schema 1.8.0 1.11.0
@typespec/openapi3 1.8.0 1.11.0
@typespec/openapi 1.8.0 1.11.0
@typespec/rest 0.75.0 0.81.0
@typespec/versioning 0.75.0 0.81.0

@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Apr 9, 2026
@github-actions github-actions bot added the typescript Issue or PR related to TypeScript tooling label Apr 9, 2026
@bryan-thompsoncodes
Copy link
Copy Markdown
Collaborator

@dependabot rebase

Bumps the all-deps group in /templates/quickstart with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [@typespec/compiler](https://github.com/microsoft/typespec) | `1.8.0` | `1.11.0` |
| [@typespec/http](https://github.com/microsoft/typespec) | `1.8.0` | `1.11.0` |
| [@typespec/json-schema](https://github.com/microsoft/typespec) | `1.8.0` | `1.11.0` |
| [@typespec/openapi3](https://github.com/microsoft/typespec) | `1.8.0` | `1.11.0` |
| [@typespec/openapi](https://github.com/microsoft/typespec) | `1.8.0` | `1.11.0` |
| [@typespec/rest](https://github.com/microsoft/typespec) | `0.75.0` | `0.81.0` |
| [@typespec/versioning](https://github.com/microsoft/typespec) | `0.75.0` | `0.81.0` |


Updates `@typespec/compiler` from 1.8.0 to 1.11.0
- [Release notes](https://github.com/microsoft/typespec/releases)
- [Commits](https://github.com/microsoft/typespec/compare/typespec-stable@1.8.0...typespec-stable@1.11.0)

Updates `@typespec/http` from 1.8.0 to 1.11.0
- [Release notes](https://github.com/microsoft/typespec/releases)
- [Commits](https://github.com/microsoft/typespec/compare/typespec-stable@1.8.0...typespec-stable@1.11.0)

Updates `@typespec/json-schema` from 1.8.0 to 1.11.0
- [Release notes](https://github.com/microsoft/typespec/releases)
- [Commits](https://github.com/microsoft/typespec/compare/typespec-stable@1.8.0...typespec-stable@1.11.0)

Updates `@typespec/openapi3` from 1.8.0 to 1.11.0
- [Release notes](https://github.com/microsoft/typespec/releases)
- [Commits](https://github.com/microsoft/typespec/compare/typespec-stable@1.8.0...typespec-stable@1.11.0)

Updates `@typespec/openapi` from 1.8.0 to 1.11.0
- [Release notes](https://github.com/microsoft/typespec/releases)
- [Commits](https://github.com/microsoft/typespec/compare/typespec-stable@1.8.0...typespec-stable@1.11.0)

Updates `@typespec/rest` from 0.75.0 to 0.81.0
- [Release notes](https://github.com/microsoft/typespec/releases)
- [Commits](https://github.com/microsoft/typespec/compare/@typespec/rest@0.75.0...@typespec/rest@0.81.0)

Updates `@typespec/versioning` from 0.75.0 to 0.81.0
- [Release notes](https://github.com/microsoft/typespec/releases)
- [Commits](https://github.com/microsoft/typespec/compare/@typespec/versioning@0.75.0...@typespec/versioning@0.81.0)

---
updated-dependencies:
- dependency-name: "@typespec/compiler"
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-deps
- dependency-name: "@typespec/http"
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-deps
- dependency-name: "@typespec/json-schema"
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-deps
- dependency-name: "@typespec/openapi3"
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-deps
- dependency-name: "@typespec/openapi"
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-deps
- dependency-name: "@typespec/rest"
  dependency-version: 0.81.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-deps
- dependency-name: "@typespec/versioning"
  dependency-version: 0.81.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot changed the title chore(deps): bump the all-deps group in /templates/quickstart with 7 updates chore(deps): bump the all-deps group across 1 directory with 7 updates Apr 9, 2026
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/templates/quickstart/all-deps-b3e2cd3519 branch from 0a87824 to 55ddd96 Compare April 9, 2026 19:41
@bryan-thompsoncodes
Copy link
Copy Markdown
Collaborator

Closing — Dependabot entries for templates/ removed in #703. Templates and examples are now manually maintained.

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot bot commented on behalf of github Apr 10, 2026

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot dependabot bot deleted the dependabot/npm_and_yarn/templates/quickstart/all-deps-b3e2cd3519 branch April 10, 2026 20:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file typescript Issue or PR related to TypeScript tooling

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant