Skip to content

chore(deps-dev): bump @changesets/cli from 3.0.1 to 3.0.3 in the npm-minor-patch group across 1 directory - #1267

Merged
frahlg merged 2 commits into
masterfrom
dependabot/npm_and_yarn/npm-minor-patch-9b46e5f5fb
Sep 23, 2026
Merged

frahlg merged 2 commits into
masterfrom
dependabot/npm_and_yarn/npm-minor-patch-9b46e5f5fb

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm-minor-patch group with 1 update in the / directory: @changesets/cli.

Updates @changesets/cli from 3.0.1 to 3.0.3

Release notes

Sourced from @​changesets/cli's releases.

@​changesets/cli@​3.0.3

Patch Changes

  • #2297 3f163da Thanks @​Andarist! - Fixed semver ranges (such as >=1.0.0 <2.0.0) getting cut off (>=2.0.0) when updating internal dependencies.

  • #2276 ca9d110 Thanks @​Andarist! - Fixed pnpm 10 compatibility with npm 12 when reading registry information, packing, and publishing packages.

  • Updated dependencies [3f163da, bfe9050, e522996]:

    • @​changesets/apply-release-plan@​8.1.1
    • @​changesets/config@​4.0.1

@​changesets/cli@​3.0.2

Patch Changes

Changelog

Sourced from @​changesets/cli's changelog.

3.0.3

Patch Changes

  • #2297 3f163da Thanks @​Andarist! - Fixed semver ranges (such as >=1.0.0 <2.0.0) getting cut off (>=2.0.0) when updating internal dependencies.

  • #2276 ca9d110 Thanks @​Andarist! - Fixed pnpm 10 compatibility with npm 12 when reading registry information, packing, and publishing packages.

  • Updated dependencies [3f163da, bfe9050, e522996]:

    • @​changesets/apply-release-plan@​8.1.1
    • @​changesets/config@​4.0.1

3.0.2

Patch Changes

Commits

@dependabot dependabot Bot added dependencies Dependency updates no-changeset PR intentionally exempt from the changeset requirement (dev tooling / non-shipping) labels Sep 14, 2026
@dependabot dependabot Bot changed the title chore(deps-dev): bump @changesets/cli from 3.0.1 to 3.0.2 in the npm-minor-patch group chore(deps-dev): bump @changesets/cli from 3.0.1 to 3.0.2 in the npm-minor-patch group across 1 directory Sep 14, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-minor-patch-9b46e5f5fb branch 2 times, most recently from 0275a17 to 42d016a Compare September 14, 2026 17:48

@miravoss26 miravoss26 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependabot bump: @changesets/cli 3.0.1 → 3.0.2 (dev dependency), plus its transitive lockfile entries (apply-release-plan, git, read).

  • Dev-only tooling, no runtime code touched, no new attack surface.
  • Lockfile integrity hashes present and consistent with the version bump.

Safe to merge from my read.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-minor-patch-9b46e5f5fb branch from 42d016a to f1b1f58 Compare September 17, 2026 16:59

@miravoss26 miravoss26 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Straight patch dependency bump (@changesets/cli 3.0.1 → 3.0.2, transitive @changesets/* patch bumps), package-lock.json + package.json only. No source touched, no new deps beyond the transitive changesets patches, nothing security-relevant. Safe to merge from my read.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-minor-patch-9b46e5f5fb branch 3 times, most recently from 4a0d185 to ed3b8c0 Compare September 18, 2026 10:53

@miravoss26 miravoss26 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependabot patch bump: @changesets/cli 3.0.1 → 3.0.2 (npm-minor-patch group), devDependency only. package.json range and package-lock.json are consistent with the bump; changelog is a small patch (pre-exit review message + transitive apply-release-plan/git/read bumps) — no behavior change to shipped code.

Security: no secrets, no new dependencies, no runtime/network surface touched — build-tooling only.

CI green across the board (relevant checks SUCCESS, others correctly SKIPPED for a deps-only diff). Safe to merge from my read.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-minor-patch-9b46e5f5fb branch 2 times, most recently from 4d483d9 to 1639f9d Compare September 20, 2026 15:07

@miravoss26 miravoss26 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependabot patch bump: @changesets/cli 3.0.1 → 3.0.2 (dev dependency only, plus its transitive @changesets/* bumps in the lockfile).

Correctness: package.json/package-lock.json only, no source changes. Upstream changelog is patch-level (pre-exit review message, dependency bumps) — nothing behavior-affecting for this repo's build.

Security: dev-only tooling, no runtime surface, no new top-level deps. All CI checks green (brand-cleanup, changeset-check, hygiene, test suite).

Safe to merge from my read.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-minor-patch-9b46e5f5fb branch from 1639f9d to ec55857 Compare September 20, 2026 15:50

@miravoss26 miravoss26 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependabot dev-dependency patch bump: @changesets/cli 3.0.1 → 3.0.2 (pulls transitive patch bumps on @changesets/apply-release-plan, git, read). package.json + lockfile only.

  • No prod code touched, dev-only tooling.
  • No secrets, no new network destinations, no authz surface.
  • CI green across the board.

Safe to merge from my read.

Bumps the npm-minor-patch group with 1 update in the / directory: [@changesets/cli](https://github.com/changesets/changesets/tree/HEAD/packages/cli).


Updates `@changesets/cli` from 3.0.1 to 3.0.3
- [Release notes](https://github.com/changesets/changesets/releases)
- [Changelog](https://github.com/changesets/changesets/blob/main/packages/cli/CHANGELOG.md)
- [Commits](https://github.com/changesets/changesets/commits/@changesets/cli@3.0.3/packages/cli)

---
updated-dependencies:
- dependency-name: "@changesets/cli"
  dependency-version: 3.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps-dev): bump @changesets/cli from 3.0.1 to 3.0.2 in the npm-minor-patch group across 1 directory chore(deps-dev): bump @changesets/cli from 3.0.1 to 3.0.3 in the npm-minor-patch group across 1 directory Sep 22, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-minor-patch-9b46e5f5fb branch from ec55857 to 24bff73 Compare September 22, 2026 17:27
@frahlg
frahlg merged commit 8ef4c79 into master Sep 23, 2026
13 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/npm-minor-patch-9b46e5f5fb branch September 23, 2026 09:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates no-changeset PR intentionally exempt from the changeset requirement (dev tooling / non-shipping)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants