Skip to content

build(deps): bump the vue group across 1 directory with 2 updates - #2203

Merged
akurtakov merged 1 commit into
masterfrom
dependabot/npm_and_yarn/org.eclipse.wildwebdeveloper/vue-2914de7251
Sep 10, 2026
Merged

build(deps): bump the vue group across 1 directory with 2 updates#2203
akurtakov merged 1 commit into
masterfrom
dependabot/npm_and_yarn/org.eclipse.wildwebdeveloper/vue-2914de7251

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Bumps the vue group with 2 updates in the /org.eclipse.wildwebdeveloper directory: @vue/language-server and @vue/typescript-plugin.

Updates @vue/language-server from 3.3.10 to 3.3.11

Release notes

Sourced from @​vue/language-server's releases.

v3.3.11

language-core

  • fix: generate full fragment props for type checking (#6155) - Thanks to @​serkodev!

language-service

  • fix: invalidate tag and prop casing detection after template changes (#6172) - Thanks to @​serkodev!
  • refactor: make name casing detection reactive (#6173) - Thanks to @​KazariEX!

component-meta

  • fix: invalidate module resolution caches when deleting files (#6163) - Thanks to @​serkodev!

tsc

  • fix: make extension retry errors serializable across IPC (#6162) - Thanks to @​KazariEX!

vscode

Our Sponsors ❤️

... (truncated)

Changelog

Sourced from @​vue/language-server's changelog.

3.3.11 (2026-08-21)

language-core

  • fix: generate full fragment props for type checking (#6155) - Thanks to @​serkodev!

language-service

  • fix: invalidate tag and prop casing detection after template changes (#6172) - Thanks to @​serkodev!
  • refactor: make name casing detection reactive (#6173) - Thanks to @​KazariEX!

component-meta

  • fix: invalidate module resolution caches when deleting files (#6163) - Thanks to @​serkodev!

tsc

  • fix: make extension retry errors serializable across IPC (#6162) - Thanks to @​KazariEX!

vscode

Commits

Updates @vue/typescript-plugin from 3.3.10 to 3.3.11

Release notes

Sourced from @​vue/typescript-plugin's releases.

v3.3.11

language-core

  • fix: generate full fragment props for type checking (#6155) - Thanks to @​serkodev!

language-service

  • fix: invalidate tag and prop casing detection after template changes (#6172) - Thanks to @​serkodev!
  • refactor: make name casing detection reactive (#6173) - Thanks to @​KazariEX!

component-meta

  • fix: invalidate module resolution caches when deleting files (#6163) - Thanks to @​serkodev!

tsc

  • fix: make extension retry errors serializable across IPC (#6162) - Thanks to @​KazariEX!

vscode

Our Sponsors ❤️

... (truncated)

Changelog

Sourced from @​vue/typescript-plugin's changelog.

3.3.11 (2026-08-21)

language-core

  • fix: generate full fragment props for type checking (#6155) - Thanks to @​serkodev!

language-service

  • fix: invalidate tag and prop casing detection after template changes (#6172) - Thanks to @​serkodev!
  • refactor: make name casing detection reactive (#6173) - Thanks to @​KazariEX!

component-meta

  • fix: invalidate module resolution caches when deleting files (#6163) - Thanks to @​serkodev!

tsc

  • fix: make extension retry errors serializable across IPC (#6162) - Thanks to @​KazariEX!

vscode

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 24, 2026
@github-actions

Copy link
Copy Markdown

⚠️ NPM dependency license review required

The following NPM dependencies have licenses that are not yet vetted and require a review before they can be used:

  • npm/npmjs/-/sass/1.103.1 (license: unknown, source: clearlydefined)

No review request could be created automatically (this happens for fork pull requests, where the GitLab token is unavailable). A committer can submit the review requests by commenting /request-license-review on this pull request. These dependencies must be approved before this change can be merged.

@akurtakov

Copy link
Copy Markdown
Contributor

/request-license-review

@github-actions

Copy link
Copy Markdown

/request-license-review

✔️ All licenses already successfully vetted.

Workflow run (with attached summary files):
https://github.com/eclipse-wildwebdeveloper/wildwebdeveloper/actions/runs/32748279857

@github-actions

Copy link
Copy Markdown

⚠️ NPM dependency license review required

The following NPM dependencies have licenses that are not yet vetted and require a review before they can be used:

  • npm/npmjs/-/sass/1.103.1 (license: unknown, source: clearlydefined) — review request

A review request has been submitted to the Eclipse IP team for each dependency listed above (see the linked issues). These dependencies must be approved before this change can be merged.

@github-actions

Copy link
Copy Markdown

⚠️ NPM dependency license review required

The following NPM dependencies have licenses that are not yet vetted and require a review before they can be used:

  • npm/npmjs/-/vscode-uri/3.2.0 (license: unknown, source: clearlydefined)

No review request could be created automatically (this happens for fork pull requests, where the GitLab token is unavailable). A committer can submit the review requests by commenting /request-license-review on this pull request. These dependencies must be approved before this change can be merged.

@vrubezhny

Copy link
Copy Markdown
Contributor

/request-license-review

@github-actions

Copy link
Copy Markdown

/request-license-review

✔️ All licenses already successfully vetted.

Workflow run (with attached summary files):
https://github.com/eclipse-wildwebdeveloper/wildwebdeveloper/actions/runs/32797202268

@github-actions

Copy link
Copy Markdown

⚠️ NPM dependency license review required

The following NPM dependencies have licenses that are not yet vetted and require a review before they can be used:

  • npm/npmjs/-/vscode-uri/3.2.0 (license: unknown, source: clearlydefined) — review request

A review request has been submitted to the Eclipse IP team for each dependency listed above (see the linked issues). These dependencies must be approved before this change can be merged.

@dependabot dependabot Bot changed the title build(deps): bump the vue group in /org.eclipse.wildwebdeveloper with 2 updates build(deps): bump the vue group across 1 directory with 2 updates Aug 25, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/org.eclipse.wildwebdeveloper/vue-2914de7251 branch 2 times, most recently from 69808e4 to 596282f Compare August 28, 2026 14:13
@github-actions

Copy link
Copy Markdown

⚠️ NPM dependency license review required

The following NPM dependencies have licenses that are not yet vetted and require a review before they can be used:

  • npm/npmjs/-/fastq/1.20.2 (license: unknown, source: clearlydefined)
  • npm/npmjs/-/vscode-uri/3.2.0 (license: MIT AND (LicenseRef-scancode-proprietary-license AND MIT), source: #30482)

No review request could be created automatically (this happens for fork pull requests, where the GitLab token is unavailable). A committer can submit the review requests by commenting /request-license-review on this pull request. These dependencies must be approved before this change can be merged.

@github-actions

Copy link
Copy Markdown

⚠️ NPM dependency license review required

The following NPM dependencies have licenses that are not yet vetted and require a review before they can be used:

  • npm/npmjs/-/vscode-uri/3.2.0 (license: MIT AND (LicenseRef-scancode-proprietary-license AND MIT), source: #30482)

No review request could be created automatically (this happens for fork pull requests, where the GitLab token is unavailable). A committer can submit the review requests by commenting /request-license-review on this pull request. These dependencies must be approved before this change can be merged.

@akurtakov

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/org.eclipse.wildwebdeveloper/vue-2914de7251 branch from 596282f to 4ca8c65 Compare September 1, 2026 09:49
@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown

⚠️ NPM dependency license review required

The following NPM dependencies have licenses that are not yet vetted and require a review before they can be used:

  • npm/npmjs/-/vscode-uri/3.2.0 (license: MIT AND (LicenseRef-scancode-proprietary-license AND MIT), source: #30482)

No review request could be created automatically (this happens for fork pull requests, where the GitLab token is unavailable). A committer can submit the review requests by commenting /request-license-review on this pull request. These dependencies must be approved before this change can be merged.

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

⚠️ NPM dependency license review required

The following NPM dependencies have licenses that are not yet vetted and require a review before they can be used:

  • npm/npmjs/-/sass/1.104.0 (license: unknown, source: clearlydefined)
  • npm/npmjs/-/vscode-uri/3.2.0 (license: MIT AND (LicenseRef-scancode-proprietary-license AND MIT), source: #30482)

No review request could be created automatically (this happens for fork pull requests, where the GitLab token is unavailable). A committer can submit the review requests by commenting /request-license-review on this pull request. These dependencies must be approved before this change can be merged.

@akurtakov

Copy link
Copy Markdown
Contributor

/request-license-review

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

/request-license-review

✔️ All licenses already successfully vetted.

Workflow run (with attached summary files):
https://github.com/eclipse-wildwebdeveloper/wildwebdeveloper/actions/runs/34089277019

@akurtakov

Copy link
Copy Markdown
Contributor

/request-license-review

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

/request-license-review

✔️ All licenses already successfully vetted.

Workflow run (with attached summary files):
https://github.com/eclipse-wildwebdeveloper/wildwebdeveloper/actions/runs/34089705053

@sebthom

sebthom commented Sep 9, 2026

Copy link
Copy Markdown
Member

@dependabot recreate

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/org.eclipse.wildwebdeveloper/vue-2914de7251 branch from 4ca8c65 to 42590b9 Compare September 9, 2026 19:24
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown

⚠️ NPM dependency license review required

The following NPM dependencies have licenses that are not yet vetted and require a review before they can be used:

  • npm/npmjs/-/vscode-uri/3.2.0 (license: MIT AND (LicenseRef-scancode-proprietary-license AND MIT), source: #30482)

No review request could be created automatically (this happens for fork pull requests, where the GitLab token is unavailable). A committer can submit the review requests by commenting /request-license-review on this pull request. These dependencies must be approved before this change can be merged.

@sebthom

sebthom commented Sep 9, 2026

Copy link
Copy Markdown
Member

@akurtakov this issue is btw. one of the reason why I was voting for checking in the package.json lock file. This unvetted dependency is now breaking all unrelated PRs. It is a transitive dependency of the language server itself and probably got updated under the hood without us updating the language server dependencies. this dependency is no included in each binary build - no matter if we merge new PRs. this would not have happened with a versioned package.json lock file.

Bumps the vue group with 2 updates in the /org.eclipse.wildwebdeveloper directory: [@vue/language-server](https://github.com/vuejs/language-tools/tree/HEAD/packages/language-server) and [@vue/typescript-plugin](https://github.com/vuejs/language-tools/tree/HEAD/packages/typescript-plugin).


Updates `@vue/language-server` from 3.3.10 to 3.3.11
- [Release notes](https://github.com/vuejs/language-tools/releases)
- [Changelog](https://github.com/vuejs/language-tools/blob/master/CHANGELOG.md)
- [Commits](https://github.com/vuejs/language-tools/commits/v3.3.11/packages/language-server)

Updates `@vue/typescript-plugin` from 3.3.10 to 3.3.11
- [Release notes](https://github.com/vuejs/language-tools/releases)
- [Changelog](https://github.com/vuejs/language-tools/blob/master/CHANGELOG.md)
- [Commits](https://github.com/vuejs/language-tools/commits/v3.3.11/packages/typescript-plugin)

---
updated-dependencies:
- dependency-name: "@vue/language-server"
  dependency-version: 3.3.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: vue
- dependency-name: "@vue/typescript-plugin"
  dependency-version: 3.3.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: vue
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/org.eclipse.wildwebdeveloper/vue-2914de7251 branch from 42590b9 to 7639b85 Compare September 9, 2026 19:48
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown

⚠️ NPM dependency license review required

The following NPM dependencies have licenses that are not yet vetted and require a review before they can be used:

  • npm/npmjs/-/vscode-uri/3.2.0 (license: MIT AND (LicenseRef-scancode-proprietary-license AND MIT), source: #30482)

No review request could be created automatically (this happens for fork pull requests, where the GitLab token is unavailable). A committer can submit the review requests by commenting /request-license-review on this pull request. These dependencies must be approved before this change can be merged.

@akurtakov

Copy link
Copy Markdown
Contributor

Wouldn't package lock also contain the vscode-uri update and thus prevent updates?

@akurtakov

Copy link
Copy Markdown
Contributor

For the reference https://gitlab.eclipse.org/eclipsefdn/emo-team/iplab/-/work_items/30482 is now fixed.

@akurtakov
akurtakov merged commit 664e608 into master Sep 10, 2026
12 of 13 checks passed
@akurtakov
akurtakov deleted the dependabot/npm_and_yarn/org.eclipse.wildwebdeveloper/vue-2914de7251 branch September 10, 2026 04:52
@sebthom

sebthom commented Sep 10, 2026

Copy link
Copy Markdown
Member

Wouldn't package lock also contain the vscode-uri update and thus prevent updates?

no because it does not change transitive dependencies on unrelated PRs.

@akurtakov

Copy link
Copy Markdown
Contributor

How/when will transitive dependencies be updated in this case? Wouldn't we end up using combinations that majority of people will no longer get as npm will not produce it for them?

@sebthom

sebthom commented Sep 10, 2026

Copy link
Copy Markdown
Member

transitive dependencies should be updated in a controlled way not potentially change on each build randomly. the NPM ecosystem is very volatile and other than in Maven transitive dependencies actually change without direct dependencies not being touched. if have a PR that updates a markdown dependency it is from my view inacceptable that the build can fail because deep down in the dependency hierarchy of another unrelated dependency a transitive dependency was updated on npmjs. thats why lockfiles lock the complete dependency tree. and thats why they are commited to git everywhere else except in this project.

@akurtakov

Copy link
Copy Markdown
Contributor

What is the proposal for a "controlled way of updating transitive dependencies" in automated way?

@akurtakov

Copy link
Copy Markdown
Contributor

Don't get me wrong - I would welcome your proposal as long as it doesn't lead to shipping older than what most people get combinations and/or more manual work.

@sebthom

sebthom commented Sep 10, 2026

Copy link
Copy Markdown
Member

my proposal is to check in the lock file and update everything including transitive dependencies through dependabot PRs. nothing changes really compared to now except only the PRs will fail that try to bump an unvetted dependency.

@akurtakov

Copy link
Copy Markdown
Contributor

Would you please setup in your fork and show dependabot actually updating transitive deps in lockfiles? Just so we are sure it actually works. I assume we should see PRs for each transitive dependency? As that would probably increase the number of PRs significantly it would probably need auto merge setup for dependabot PRs for which all validations succeed.

@sebthom

sebthom commented Sep 10, 2026

Copy link
Copy Markdown
Member

Honestly, this still feels again a bit like a ridiculous discussion. npm lockfiles are git committed and versioned. I don't think we need a proof of concept that it works and if so how. Usually you don't want transitive dependencies to update randomly, the only good reason is security and that is already covered by dependabot https://github.blog/changelog/2022-09-07-dependabot-unlocks-transitive-dependencies-for-npm-projects/ but again, this needs the lockfiles to be git committed. Even the official package.json documentation documents it: https://docs.npmjs.com/cli/v11/configuring-npm/package-lock-json I feel the only reason the file was not commited from the beginning in this repo is lack of knowledge of the NPM eco system.

@akurtakov

akurtakov commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

I have never claimed good knowledge of NPM ! But you would better fill your knowledge on the history of the project before doing more claims :) . Lock files have been committed initially and they have been removed as that allowed us to have less manual work to keep all the dependencies uptodate e.g. #222 .
So do you have a setup which will update transitive dependencies without vulnerabilities against them automatically to whatever people will get when they do npm install ? Relying on the minimum versions being properly set everywhere is a problem which I am not eager to chase.

@sebthom

sebthom commented Sep 10, 2026

Copy link
Copy Markdown
Member

That decision may have been somewhat justified seven years ago but it even then introduced the real risk of publishing releases with unvetted transitive dependencies which kinda turns the whole Eclipse IP/license check ceremony ad absurdum. Also seven years ago there was no dependabot and github workflows for this repo.

In the Maven eco system it is very unlikely if you specify a dependency in pom.xml that a transitive dependency will change. this is not the case in npm where often Version ranges are specified and where semantic versioning is often not followed despite versions looking like semantic versions.

I'll see what I can do.

@akurtakov

Copy link
Copy Markdown
Contributor

In the Maven eco system it is very unlikely if you specify a dependency in pom.xml that a transitive dependency will change. this is not the case in npm where often Version ranges are specified and where semantic versioning is often not followed despite versions looking like semantic versions.

^^ Exactly these "looks to be correct" but no one verifies them version ranges is why I insist on automatic uncovering and opening PRs instead of sticking to smth to uncover at runtime it no longer works.

I'll see what I can do.

Thanks, much appreciated!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants