Skip to content

chore(deps): bump @changesets/cli to 3.0.1 - #905

Open
shigechika wants to merge 1 commit into
googleworkspace:mainfrom
shigechika:fix/changesets-cli-3-private-package-npm-vulns
Open

chore(deps): bump @changesets/cli to 3.0.1#905
shigechika wants to merge 1 commit into
googleworkspace:mainfrom
shigechika:fix/changesets-cli-3-private-package-npm-vulns

Conversation

@shigechika

Copy link
Copy Markdown

js-yaml (3.14.2, 4.1.1) and picomatch (2.3.1) are transitive devDependencies of @changesets/cli 2.29.8, flagged by Dependabot. Bumping to 3.0.1 drops all three from the tree.

v3 also stopped versioning "private": true packages by default. Added privatePackages.version: true to .changeset/config.json so changeset version keeps working — verified changeset status correctly reports the pending bump after this change.

…aml/picomatch alerts

js-yaml (3.14.2, 4.1.1) and picomatch (2.3.1) are transitive
devDependencies pulled in by @changesets/cli 2.29.8's own dependency
tree (via @changesets/parse, @manypkg/get-packages, @changesets/git).
Bumping to 3.0.1 drops all three from the tree: @changesets/parse
switched from js-yaml to yaml, @manypkg/get-packages 3.x no longer
depends on read-yaml-file, and @changesets/git 4.x depends on
picomatch@^4 directly.

v3 also changed default behavior for "private": true packages:
`changeset version` now silently no-ops for them unless
`privatePackages.version` is explicitly enabled in
.changeset/config.json. Verified locally with an isolated worktree
A/B test: without this option, `changeset version` reports "All
files have been updated" but makes zero changes; with it, it
correctly bumps the version and consumes pending changesets. Since
this repo's root package is "private": true, that option is added
here so `changeset version` (invoked by scripts/version-sync.sh, used
by changesets/action) keeps working.
@changeset-bot

changeset-bot Bot commented Aug 22, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: d70fcfb

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@googleworkspace/cli Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant