chore(deps): bump @types/node from 26.6.2 to 26.6.3 in /clients/typescript - #5427
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 26.6.2 to 26.6.3. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) --- updated-dependencies: - dependency-name: "@types/node" dependency-version: 26.6.3 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
REST API breakage checks (OpenAPI) — ✅ PASSEDResult: ✅ PASSED |
all-hands-bot
left a comment
There was a problem hiding this comment.
This review was posted by an AI agent (OpenHands).
Summary
Dependabot bumps @types/node from 26.6.2 to 26.6.3 in clients/typescript/package-lock.json (+3/-3: version, resolved, integrity). The diff itself is correct and complete:
- The
resolvedURL andintegrity(sha512-dsqMQQoeTLqu9wynDD00q573mNzso3IdQOAfHRJqLCcmCFPoGo9A1bDpUcv/9tnKpErQWv9uKeGfl37EIS02Yg==) match the npm registry metadata for 26.6.3 exactly. - 26.6.3 stays within the declared
^26.1.0devDependency range, and its only dependency (undici-types ~8.9.0) is already resolved at 8.9.0, so no transitive change is pulled in. - The package is dev-only and the client is browser-targeted, so there is no production runtime impact.
Verification performed
- Scope: in scope -
clients/typescript/owns the TypeScript client and its lockfile, and.github/dependabot.ymlconfigures the npm ecosystem for that directory. - Local checks on exact head
d3dc563:npm ci,npm run lint(0 errors),npm run build, andnpm run test:coverage(23 files, 347 tests) all pass. - Current-head CI: all required checks pass, including
TypeScript client CI,TypeScript client integration tests,TypeScript client endpoint audit,Run tests,Pre-commit checks, andReview Thread Gate. - No linked issues, no existing review threads, and no prior review comments on this PR.
Supply-chain checkpoint (repository guidance)
.agents/skills/custom-codereview-guide.md (Dependency updates) requires inspecting the changed distribution's package-index upload time and not approving an artifact uploaded less than seven days ago, instead stating the package, version, and upload time and asking a maintainer whether to wait or override the guardrail. This artifact is still inside that window:
- Package:
@types/node - Version:
26.6.3 - npm upload time: 2026-09-25T22:06:16Z
- Age at review: ~6.3 days
The code change has no defect; this hold is about artifact age only. Note the asymmetry that produced the same hold on the previous @types/node bump (PR #5301): .github/dependabot.yml sets cooldown.default-days: 7 for the uv ecosystem but sets no cooldown for the npm ecosystem (/clients/typescript), so npm bumps bypass the seven-day freshness window the repository applies to its Python workspace via pyproject.toml tool.uv.exclude-newer = "7 days".
A maintainer should decide whether to wait until the artifact clears seven days, merge now with an explicit override, or add a matching cooldown to the npm Dependabot entry so future npm bumps are held automatically.
🔄 CHANGES REQUESTED
Bumps @types/node from 26.6.2 to 26.6.3.
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)🐳 Agent Server images for this PR — GHCR package, pull/run commands, and all pushed tags (click to expand)
• GHCR package: https://github.com/OpenHands/agent-sdk/pkgs/container/agent-server
Variants & Base Images
eclipse-temurin:17-jdkpython-node-runtimepython-node-runtimepython-node-runtimegolang:1.21-bookwormPull (multi-arch manifest)
# Each variant is a multi-arch manifest supporting both amd64 and arm64 docker pull ghcr.io/openhands/agent-server:d3dc563-pythonRun
All tags pushed for this build
About Multi-Architecture Support
d3dc563-python) is a multi-arch manifest supporting both amd64 and arm64d3dc563-python-amd64) are also available if needed