Skip to content
This repository was archived by the owner on Dec 22, 2024. It is now read-only.

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 9, 2024

Bumps svelte-check from 3.8.5 to 4.1.1.

Release notes

Sourced from svelte-check's releases.

svelte-check-4.1.1

  • fix: support each without as (#2615)

svelte-check-4.1.0

  • fix: don't move appended content from previous node while hoisting interface (#2596)
  • fix: ensure hoisted interfaces are moved after hoisted imports (#2597)
  • fix: preserve bind:... mapping on elements for better source maps
  • feat: prepare for some upcoming features of Svelte 5

svelte-check-4.0.9

  • fix: detect shadowed variables/types during type hoisting (#2590)

svelte-check-4.0.8

  • fix: fall back to any instead of unknown for untyped $props (#2582)
  • fix: robustify and fix file writing (#2584)
  • fix: hoist types related to $props rune if possible (#2571)

svelte-check-4.0.7

  • fix: $props: infer types for $bindable, infer function type from arrow function

svelte-check-4.0.6

  • chore: autotype const load = ... declarations (#2540)
  • chore: provide component instance type in Svelte 5 (#2553)
  • chore: support typescript 5.6 (#2545)
  • fix: infer object and array shapes from fallback types (#2562)

svelte-check-4.0.5

  • fix: include named exports in svelte 5 type (#2528)

svelte-check-4.0.4

  • fix: relax component constructor type (#2524)

svelte-check-4.0.3

  • breaking(svelte5): only generate function component shape in runes mode (#2517). This means you can no longer just do Component in type positions. Instead you need to prepend it with typeof. Here's how you do it:
    • ...when typing a component instance: Before: let x: Component. After: let x: ReturnType<typeof Component>
    • ...when typing a component constructor/function: Before let x: typeof Component. After let x: typeof Component (no change)
  • fix: revert additional two-way-binding checks as they were causing bugs (#2508)
  • fix: include files indirectly belonging to a project into correct project (#2488)
  • fix: check project files update more aggressively before assigning service (#2518)
  • chore: upgrade to chokidar 4 (#2502)

svelte-check-4.0.2

  • fix: ensure components typed through Svelte 5's Component interface get proper intellisense

svelte-check-4.0.1

  • fix: remove ancient process augmentation from internal d.ts file

svelte-check-4.0.0

  • chore: bump magic-string (#2476)
  • chore: switch from fast-glob to fdir (#2433)

... (truncated)

Commits
  • 02db54d fix: support each without as (#2615)
  • 131f78a fix: make sure snapshots are shared per ProjectService (#2614)
  • 89cc22b fix: ensure imports without semicolon doesn't break intellisense (#2610)
  • fda35fe chore: update tests
  • 0bf5836 chore: pin TS to 5.6 for now
  • 10820f9 fix: ensure organize imports doesn't mess with generated $$Component type
  • cda5c86 fix: preserve bind:... mapping on elements for better source maps
  • be44125 feat: support bind:value={get, set}
  • 695c660 chore: bump prettier-plugin-svelte
  • 9a5a6af feat: hoist snippets to module context if possible (#2601)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [svelte-check](https://github.com/sveltejs/language-tools) from 3.8.5 to 4.1.1.
- [Release notes](https://github.com/sveltejs/language-tools/releases)
- [Commits](sveltejs/language-tools@svelte-check-3.8.5...svelte-check-4.1.1)

---
updated-dependencies:
- dependency-name: svelte-check
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Dec 9, 2024
@vercel
Copy link

vercel bot commented Dec 9, 2024

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
capy-life ❌ Failed (Inspect) Dec 9, 2024 5:45pm

@socket-security
Copy link

Report is too large to display inline.
View full report↗︎

Next steps

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore pypi/h2@4.1.0
  • @SocketSecurity ignore pypi/hpack@4.0.0
  • @SocketSecurity ignore pypi/hyperframe@6.0.1
  • @SocketSecurity ignore pypi/bump2version@1.0.1
  • @SocketSecurity ignore pypi/asttokens@2.4.1
  • @SocketSecurity ignore pypi/executing@2.0.1
  • @SocketSecurity ignore pypi/beautifulsoup4@4.12.3
  • @SocketSecurity ignore pypi/gprof2dot@2024.6.6
  • @SocketSecurity ignore pypi/ipykernel@6.29.5
  • @SocketSecurity ignore pypi/jsonschema@4.23.0
  • @SocketSecurity ignore pypi/exceptiongroup@1.2.2
  • @SocketSecurity ignore pypi/incremental@24.7.2
  • @SocketSecurity ignore pypi/cython@3.0.11
  • @SocketSecurity ignore pypi/furo@2024.8.6
  • @SocketSecurity ignore pypi/lxml@5.3.0
  • @SocketSecurity ignore pypi/keyring@25.4.1
  • @SocketSecurity ignore pypi/gcovr@8.2
  • @SocketSecurity ignore pypi/blurb@1.3.0
  • @SocketSecurity ignore pypi/argcomplete@3.5.2

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant