Skip to content

Conversation

@justlevine
Copy link
Contributor

What

This PR reapplies and further updates the outdated NPM and Composer deps.

Breaking updates that don't have security implications we're obviously left out.

Also updates dependabot.yml with a sensible configuration. cc @iamimmanuelraj

Why

Prerelease cleanup

Related Issue(s):

How

Testing Instructions

Screenshots

Additional Info

Checklist

  • I have read the Contribution Guidelines.
  • I have read the Development Guidelines.
  • My code is tested to the best of my abilities.
  • My code passes all lints (ESLint etc.).
  • My code has detailed inline documentation.
  • I have updated the project documentation as needed.

@justlevine justlevine requested review from Copilot and up1512001 and removed request for Copilot January 25, 2026 18:35
Copilot AI review requested due to automatic review settings January 25, 2026 18:46
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates NPM and Composer dependencies as part of prerelease cleanup, while also introducing a more structured Dependabot configuration to manage future dependency updates more sensibly.

Changes:

  • Updated multiple WordPress packages and development dependencies in package.json to latest minor/patch versions
  • Updated PHP development dependencies (PHPStan, PHPUnit, and related packages) to latest versions in composer.lock
  • Restructured dependabot.yml from daily updates across 8 ecosystems to weekly updates for 3 relevant ecosystems (Composer, NPM, GitHub Actions) with grouping strategies

Reviewed changes

Copilot reviewed 3 out of 5 changed files in this pull request and generated 4 comments.

File Description
package.json Updates WordPress packages and development tools to latest minor/patch versions
composer.json Downgrades plugin-check from 1.8.0 to 1.6.0
composer.lock Reflects composer.json changes and updates development dependencies with future timestamps
.github/dependabot.yml Restructures configuration with invalid fields (cooldown, directories) and grouping strategies

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@justlevine justlevine mentioned this pull request Jan 25, 2026
6 tasks
@justlevine
Copy link
Contributor Author

Obviated by #42

@justlevine justlevine closed this Jan 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants