Skip to content

Bump semver and @wordpress/scripts - #7

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-18d1dcfc72
Open

Bump semver and @wordpress/scripts#7
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-18d1dcfc72

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Feb 5, 2026

Copy link
Copy Markdown

Bumps semver to 5.7.2 and updates ancestor dependency @wordpress/scripts. These dependencies need to be updated together.

Updates semver from 5.7.1 to 5.7.2

Release notes

Sourced from semver's releases.

v5.7.2

5.7.2 (2023-07-10)

Bug Fixes

Changelog

Sourced from semver's changelog.

5.7.2 (2023-07-10)

Bug Fixes

5.7

  • Add minVersion method

5.6

  • Move boolean loose param to an options object, with backwards-compatibility protection.
  • Add ability to opt out of special prerelease version handling with the includePrerelease option flag.

5.5

  • Add version coercion capabilities

5.4

  • Add intersection checking

5.3

  • Add minSatisfying method

5.2

  • Add prerelease(v) that returns prerelease components

5.1

  • Add Backus-Naur for ranges
  • Remove excessively cute inspection methods

5.0

  • Remove AMD/Browserified build artifacts
  • Fix ltr and gtr when using the * range
  • Fix for range * with a prerelease identifier
Commits
Maintainer changes

This version was pushed to npm by lukekarrys, a new releaser for semver since your current version.


Updates @wordpress/scripts from 12.1.1 to 12.6.1

Changelog

Sourced from @​wordpress/scripts's changelog.

12.6.1 (2021-01-05)

Bug Fixes

  • Fix multiple build (build command) runtimes conflicting when using globals (#27985).

12.6.0 (2020-12-17)

Enhancements

Internal

  • The bundled ignore-emit-webpack-plugin dependency has been updated from requiring 2.0.3 to requiring ^2.0.6.

12.5.0 (2020-10-30)

Enhancements

  • Ignore /vendor folder when searching for files to lint or format.

Bug Fixes

  • Temporary pin ignore-emit-webpack-plugin to the version 2.0.3 to fix a known issue with version 2.0.4 (GitHub issue).

12.1.0 (2020-07-07)

Enhancements

  • Update webpack configuration to preserve translator comments in minified output.

Bug Fixes

  • Allow the CSS, SVG, and Sass loaders to process files from node_modules directory.
  • Improve the way licenses are validated with check-licenses by falling back to license files verification when the entry in package.json doesn't contain an allowed match (#23550).
  • Fix build script error when importing style.css files (#23710).
  • Exclude node_modules from source map processing in start script (#23711).

12.0.0-rc.0 (2020-06-24)

Breaking Changes

  • The bundled stylelint dependency has been updated from requiring ^9.10.1 to requiring ^13.6.0.
  • The bundled stylelint-config-wordpress dependency has been updated from requiring ^13.1.0 to requiring ^17.0.0.

Bug Fixes

... (truncated)

Commits
  • defb705 chore(release): publish
  • ef16ad4 Update changelog files
  • 88f3b9a Merge changes published in the Gutenberg plugin "release/9.7" branch
  • f8ba578 chore(release): publish
  • 6fe224a Update changelog files
  • b55817f Merge changes published in the Gutenberg plugin "release/9.6" branch
  • 148085f chore(release): publish
  • 9eb374e Update changelog files
  • 4a40304 Scripts: Fix error in ignore-emit-webpack-plugin (#26591)
  • e9d684e Scripts: Teach all the tools to skip vendor folder (#26450)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [semver](https://github.com/npm/node-semver) to 5.7.2 and updates ancestor dependency [@wordpress/scripts](https://github.com/WordPress/gutenberg/tree/HEAD/packages/scripts). These dependencies need to be updated together.


Updates `semver` from 5.7.1 to 5.7.2
- [Release notes](https://github.com/npm/node-semver/releases)
- [Changelog](https://github.com/npm/node-semver/blob/v5.7.2/CHANGELOG.md)
- [Commits](npm/node-semver@v5.7.1...v5.7.2)

Updates `@wordpress/scripts` from 12.1.1 to 12.6.1
- [Release notes](https://github.com/WordPress/gutenberg/releases)
- [Changelog](https://github.com/WordPress/gutenberg/blob/trunk/packages/scripts/CHANGELOG.md)
- [Commits](https://github.com/WordPress/gutenberg/commits/@wordpress/scripts@12.6.1/packages/scripts)

---
updated-dependencies:
- dependency-name: semver
  dependency-version: 5.7.2
  dependency-type: indirect
- dependency-name: "@wordpress/scripts"
  dependency-version: 12.6.1
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Feb 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants