Skip to content

deps(deps-dev): bump typescript from 5.9.3 to 6.0.3#8

Open
dependabot[bot] wants to merge 61 commits into
mainfrom
dependabot/npm_and_yarn/typescript-6.0.3
Open

deps(deps-dev): bump typescript from 5.9.3 to 6.0.3#8
dependabot[bot] wants to merge 61 commits into
mainfrom
dependabot/npm_and_yarn/typescript-6.0.3

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github Apr 18, 2026

Bumps typescript from 5.9.3 to 6.0.3.

Release notes

Sourced from typescript's releases.

TypeScript 6.0.3

For release notes, check out the release announcement blog post.

Downloads are available on:

TypeScript 6.0

For release notes, check out the release announcement blog post.

Downloads are available on:

TypeScript 6.0 Beta

For release notes, check out the release announcement.

Downloads are available on:

Commits
  • 050880c Bump version to 6.0.3 and LKG
  • eeae9dd 🤖 Pick PR #63401 (Also check package name validity in...) into release-6.0 (#...
  • ad1c695 🤖 Pick PR #63368 (Harden ATA package name filtering) into release-6.0 (#63372)
  • 0725fb4 🤖 Pick PR #63310 (Mark class property initializers as...) into release-6.0 (#...
  • 607a22a Bump version to 6.0.2 and LKG
  • 9e72ab7 🤖 Pick PR #63239 (Fix missing lib files in reused pro...) into release-6.0 (#...
  • 35ff23d 🤖 Pick PR #63163 (Port anyFunctionType subtype fix an...) into release-6.0 (#...
  • e175b69 Bump version to 6.0.1-rc and LKG
  • af4caac Update LKG
  • 8efd7e8 Merge remote-tracking branch 'origin/main' into release-6.0
  • Additional commits viewable in compare view

…ipeline state management

- Updated UI components to display activity and pipeline status.
- Introduced new hooks and IPC methods for better integration with the atomization process.
- Refactored related code for improved clarity and maintainability.
… backend

- Add wizard_logic.rs: advance_wizard_step, save_wizard_draft, mark_wizard_stale,
  validate_describe_input, validate_project_config, validate_launch_readiness,
  get_default_config, add/update/remove/reorder/get_stories commands
- Add wizard_state.rs: WizardStepState with advance/mark_stale/clear_stale
- Add validation.rs: validate_config, validate_describe, validate_launch_readiness
  with unit tests; ConfigLimits and ConfigDefaultsResponse
- Add stories_crud.rs: full CRUD over prd.json (add, update, remove, reorder, get)
- Add notification_filter.rs: should_emit_verification_failed, build_notification
- Add plan_engine/filters.rs: noise filtering for plan stream output
- Add wizard-logic.ts: IPC bindings for all new Tauri commands
- Remove draft-payload.ts: draft construction moved to save_wizard_draft (Rust)
- Remove plan-stream-filters.ts: filtering moved to plan_engine/filters.rs (Rust)
- Remove wizard store mutations for stories: all writes go through backend
- Replace hardcoded DEFAULT_CONFIG with PLACEHOLDER_CONFIG; config loaded from
  get_default_config on Configure mount
- Wire all new commands in invoke.rs
Standardize linting and formatting across frontend and Rust so Biome, TypeScript, rustfmt, and clippy run clean in strict mode through hooks and CI.
Align rule coverage with artifact and vertical-slice contracts while splitting guidance into focused files to reduce implementation ambiguity.
…g failure

Make AppHandle generic over R: Runtime across the test call chain so
MockRuntime tests compile. Add tauri test feature as dev-dependency,
supply missing StartLoopArgs fields, annotate closure parameter types,
and skip updater artifact creation in CI builds.
Move SystemReadiness to its alphabetically correct position.
…izer prompts

Fix activity, contract, invoke, and plan engine test fixtures so the
full suite passes green. Upgrade atomize templates with richer context
and clearer instructions for chunk, merge, stories, and summarize stages.
…xa token

Introduce a product focused README with GitHub Flavored Markdown, a short
contributing guide and the MIT license so the project is ready for open
source. Ignore OpenSpec generated agent folders and replace the hardcoded
Exa MCP bearer token with an environment variable reference.
Keep the Cursor MCP configuration outside version control so API keys live
only in shell environment variables on the developer machine.
Keep the Cursor agent definitions outside version control because they
are workstation specific and may contain absolute paths.
Prepare the repository for open source release by adding the community
health files that GitHub looks for and by storing the automation that
will finish the lockdown when the repo becomes public.

Adds:
  * SECURITY.md with a reporting policy and scope.
  * .github/CODEOWNERS so future pull requests route to the maintainer.
  * .github/dependabot.yml with weekly updates for cargo, npm, and
    github-actions grouped by patch and minor bumps.
  * .github/ISSUE_TEMPLATE with a config that forces structured forms
    plus bug and feature request templates.
  * scripts/setup-github-security.sh that applies branch rulesets,
    secret scanning, push protection, CodeQL default setup, private
    vulnerability reporting, and SHA pinning for Actions as soon as the
    repository goes public or is upgraded to GitHub Pro.
The initial version of the script required status checks that did not
exist in .github/workflows/test.yml. Point the ruleset at the real job
names so the protection becomes effective as soon as the repository
goes public.

Required checks: typecheck, lint, rust-tests.
The build matrix stays out of the required list because the four
platform combinations are not needed to accept a pull request.
@dependabot @github
Copy link
Copy Markdown
Author

dependabot Bot commented on behalf of github Apr 18, 2026

Labels

The following labels could not be found: dependencies, javascript. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

GitHub now enforces sha_pinning_required for this repository, so every
uses reference in the workflows needs to point at a full 40 character
commit hash instead of a moving tag. The comments next to each hash
keep the semver visible for humans and let Dependabot bump the pin
when a new release ships.

Also drops required_signatures from the main ruleset script because
the maintainer signs commits through GitHub and does not run local
GPG or SSH signing. The rule can come back once signing keys are set
up and the signing workflow is documented.
@taberoajorge
Copy link
Copy Markdown
Owner

@dependabot rebase

Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.9.3 to 6.0.3.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v5.9.3...v6.0.3)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 6.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/typescript-6.0.3 branch from 5dfc1e7 to e429e96 Compare April 18, 2026 16:06
@dependabot dependabot Bot requested a review from taberoajorge as a code owner April 18, 2026 16:06
@taberoajorge taberoajorge force-pushed the dependabot/npm_and_yarn/typescript-6.0.3 branch from e429e96 to 5754ee1 Compare April 20, 2026 02:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant