Skip to content

Bump npm-check-updates from 22.2.9 to 23.0.0 - #767

Merged
mrz1836 merged 1 commit into
masterfrom
dependabot/npm_and_yarn/master/npm-check-updates-23.0.0
Jul 27, 2026
Merged

Bump npm-check-updates from 22.2.9 to 23.0.0#767
mrz1836 merged 1 commit into
masterfrom
dependabot/npm_and_yarn/master/npm-check-updates-23.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor

Bumps npm-check-updates from 22.2.9 to 23.0.0.

Release notes

Sourced from npm-check-updates's releases.

v23.0.0

⚠️ Breaking changes & migration

1. Node.js 22+ required (#1844) The minimum supported Node.js is now 22. Supported versions: ^22.22.2 || ^24.15.0 || >=26.0.0 (and npm >=10).

  • Migration: Upgrade Node before installing. On older Node, stay on v22.x.

2. Pure ESM package — CJS build dropped, default export is now callable (#1916, #1894) The package is now pure ESM (no more CommonJS build), and the default export is now callable directly. ncu.run() and ncu.defineConfig() still work as namespaced properties.

  • Migration (ESM):
    // before
    import * as ncu from 'npm-check-updates'
    const upgraded = await ncu.run({ /* ... */ })
    // after
    import ncu from 'npm-check-updates'
    const upgraded = await ncu({ /* ... */ }) // ncu.run({...}) also still works
  • Migration (CommonJS): Still usable via Node's native require() of ESM (Node 22+), but the import shape changed:
    // before
    const ncu = require('npm-check-updates')
    // after
    const { default: ncu } = require('npm-check-updates')
    ncu({ /* ... */ }).then(upgraded => console.log(upgraded))

3. filterVersion / rejectVersion no longer accept a predicate function. Use filter / reject instead. (#1933) These options now accept only a string, wildcard, glob, comma/space-delimited list, or /regex/. (CLI usage is unchanged — the CLI never supported functions.)

  • Migration: If you passed a function to filterVersion/rejectVersion in .ncurc.js or via the module API, move it to filter / reject instead. Those receive the package name and the parsed current version, so they can match on both:
    // before
    filterVersion: (name, semver) => !(name.startsWith('@myorg/') && +semver[0].major > 5)
    // after
    filter:        (name, semver) => !(name.startsWith('@myorg/') && +semver[0].major > 5)

4. Output is now grouped by default (#1937) --format now defaults to ["group"], so upgrades are grouped by major / minor / patch out of the box. This is a better default for most users.

  • Migration: To get the old flat output, use:
    ncu --format no-group
    The new no- prefix removes a value from the default list instead of replacing the whole list, so --format no-group,time disables grouping while adding publish times.

5. --target semver now respects explicit upper bounds (#1920) An explicit upper bound in a range is now preserved and never exceeded, e.g. ^9.5.0 <10^9.7.0 <10 (previously the bound could be overrun). This can change which versions are selected for ranges with explicit upper bounds.

✨ Other improvements

  • Native TypeScript loading (#1888), lazy-loaded npm-registry-fetch for faster startup (#1898), and reduced dependencies for a lighter install.

... (truncated)

Commits
  • 2417fe3 23.0.0
  • 61b8818 Update deps (#1948)
  • 548c6e3 Merge pull request #1943 from raineorshine/xmr/test-doctor
  • d31677a test/doctor: run fixtures from a temp copy instead of mutating tracked files
  • 31c7e85 Fix and clean up skipped tests (#1941)
  • c7c968f Merge pull request #1935 from raineorshine/xmr/fix-regex
  • e42e613 Update dependencies (#1940)
  • 5c7b422 Add regression test for single-character override keys that are not '.'
  • 8d0d4be Move override tests into upgradePackageData.test.ts
  • 21b8f53 Use jsonc-parser for packageManager and JSON catalog upgrades
  • Additional commits viewable in compare view

@dependabot dependabot Bot added the update General updates label Jul 27, 2026
@mergify

mergify Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

⚠️ @mrz1836: this is a major version bump and requires your attention

Bumps [npm-check-updates](https://github.com/raineorshine/npm-check-updates) from 22.2.9 to 23.0.0.
- [Release notes](https://github.com/raineorshine/npm-check-updates/releases)
- [Changelog](https://github.com/raineorshine/npm-check-updates/blob/main/CHANGELOG.md)
- [Commits](raineorshine/npm-check-updates@v22.2.9...v23.0.0)

---
updated-dependencies:
- dependency-name: npm-check-updates
  dependency-version: 23.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/master/npm-check-updates-23.0.0 branch from 58ea453 to b932be9 Compare July 27, 2026 10:08
@mergify

mergify Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

⚠️ @mrz1836: this is a major version bump and requires your attention

@mrz1836
mrz1836 merged commit 9ba6f20 into master Jul 27, 2026
4 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/master/npm-check-updates-23.0.0 branch July 27, 2026 13:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

update General updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant