Skip to content

Bump zx and @companion-module/tools#36

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-ed5b04a2f5
Open

Bump zx and @companion-module/tools#36
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-ed5b04a2f5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Nov 21, 2025

Copy link
Copy Markdown
Contributor

Bumps zx to 8.8.5 and updates ancestor dependency @companion-module/tools. These dependencies need to be updated together.

Updates zx from 7.1.1 to 8.8.5

Release notes

Sourced from zx's releases.

8.8.5 — Temporary Reservoir

This release fixes the issue, when zx flushes external node_modules on linking #1348 #1349 #1355

Also globby@15.0.0 arrives here.

8.8.4 — Flange Coupling

It's time. This release updates zx internals to make the ps API and related methods ProcessPromise.kill(), kill() work on Windows systems without wmic. #1344 webpod/ps#15

  1. WMIC will be missing in Windows 11 25H2 (kernel >= 26000)
  2. The windows-latest label in GitHub Actions will migrate from Windows Server 2022 to Windows Server 2025 beginning September 2, 2025 and finishing by September 30, 2025.

https://github.blog/changelog/2025-07-31-github-actions-new-apis-and-windows-latest-migration-notice/#windows-latest-image-label-migration

8.8.3 — Sealing Gasket

Continues #1339 to prevent injections via Proxy input or custom toString() manipulations.

8.8.2 — Leaking Valve

Fixes potential cmd injection via kill() method for Windows platform. #1337 #1339. Affects the versions range 8.7.1...8.8.1.

8.8.1 — Turbo Flush

We keep improving the projects internal infra to bring more stability, safety and performance for artifacts.

Featfixes

  • Applied flags filtration for CLI-driven deps install #1308
  • Added kill() event logging #1312
  • Set SIGTERM as kill() fallback signal #1313
  • Allowed stdio() arg be an array #1311
const p = $({halt: true})`cmd`
p.stdio([stream, 'ignore', 'pipe'])

Enhancements

8.8.0 — Pressure Tested

This release enhances the coherence between the ProcessPromise and the Streams API, eliminating the need for certain script-level workarounds.

✨ New Features

unpipe() — Selectively stop piping

You can now call .unpipe() to stop data transfer from a source to a destination without closing any of the pair. #1302

</tr></table> 

... (truncated)

Commits

Updates @companion-module/tools from 0.5.1 to 2.4.2

Release notes

Sourced from @​companion-module/tools's releases.

v2.4.2

2.4.2 (2025-10-18)

Bug Fixes

  • prune some unnecessary native prebuilt binaries from packages (f943056)

v2.4.1

2.4.1 (2025-09-28)

Bug Fixes

  • update release-please and provenance generation (15a5393)

v2.4.0

2.4.0 (2025-09-04)

Features

v2.3.0

2.3.0 (2025-04-12)

Features

  • Allow additional rules to be provided to the eslint config generator (#48) (6fb9125)

v2.2.3

2.2.3 (2025-04-12)

Bug Fixes

  • sanitise output filename (cb07027)

v2.2.2

2.2.2 (2025-03-09)

Bug Fixes

  • package always being created with old filename (412014c)

v2.2.1

2.2.1 (2025-03-06)

... (truncated)

Changelog

Sourced from @​companion-module/tools's changelog.

2.4.2 (2025-10-18)

Bug Fixes

  • prune some unnecessary native prebuilt binaries from packages (f943056)

2.4.1 (2025-09-28)

Bug Fixes

  • update release-please and provenance generation (15a5393)

2.4.0 (2025-09-04)

Features

2.3.0 (2025-04-12)

Features

  • Allow additional rules to be provided to the eslint config generator (#48) (6fb9125)

2.2.3 (2025-04-12)

Bug Fixes

  • sanitise output filename (cb07027)

2.2.2 (2025-03-09)

Bug Fixes

  • package always being created with old filename (412014c)

2.2.1 (2025-03-06)

Bug Fixes

  • incorrect isPrerelease capitalisation (b3399d3)

2.2.0 (2025-03-06)

... (truncated)

Commits
  • 8974412 chore(main): release 2.4.2 (#70)
  • 3f548f4 chore(deps): bump actions/download-artifact from 4 to 5 (#69)
  • f943056 fix: prune some unnecessary native prebuilt binaries from packages
  • 1143627 chore(main): release 2.4.1 (#68)
  • 5f0ff50 chore: add release-please config file
  • 92a5489 chore: fix publish script
  • 1e6c3e5 chore: remove test invocation
  • 15a5393 fix: update release-please and provenance generation
  • f51e6dc chore: update dependencies
  • 7b28d60 chore(main): release 2.4.0 (#65)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for @​companion-module/tools since your current version.


You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [zx](https://github.com/google/zx) to 8.8.5 and updates ancestor dependency [@companion-module/tools](https://github.com/bitfocus/companion-module-tools). These dependencies need to be updated together.


Updates `zx` from 7.1.1 to 8.8.5
- [Release notes](https://github.com/google/zx/releases)
- [Commits](google/zx@7.1.1...8.8.5)

Updates `@companion-module/tools` from 0.5.1 to 2.4.2
- [Release notes](https://github.com/bitfocus/companion-module-tools/releases)
- [Changelog](https://github.com/bitfocus/companion-module-tools/blob/main/CHANGELOG.md)
- [Commits](bitfocus/companion-module-tools@v0.5.1...v2.4.2)

---
updated-dependencies:
- dependency-name: zx
  dependency-version: 8.8.5
  dependency-type: indirect
- dependency-name: "@companion-module/tools"
  dependency-version: 2.4.2
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Nov 21, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants