Skip to content

Bump semver, @shopify/app and @shopify/cli in /sample-apps/bundles-cart-transform#652

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/sample-apps/bundles-cart-transform/multi-149e046bb5
Open

Bump semver, @shopify/app and @shopify/cli in /sample-apps/bundles-cart-transform#652
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/sample-apps/bundles-cart-transform/multi-149e046bb5

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 5, 2026

Bumps semver to 7.5.4 and updates ancestor dependencies semver, @shopify/app and @shopify/cli. These dependencies need to be updated together.

Updates semver from 7.3.6 to 7.5.4

Release notes

Sourced from semver's releases.

v7.5.4

7.5.4 (2023-07-07)

Bug Fixes

v7.5.3

7.5.3 (2023-06-22)

Bug Fixes

Documentation

v7.5.2

7.5.2 (2023-06-15)

Bug Fixes

v7.5.1

7.5.1 (2023-05-12)

Bug Fixes

v7.5.0

7.5.0 (2023-04-17)

Features

Bug Fixes

v7.4.0

7.4.0 (2023-04-10)

... (truncated)

Changelog

Sourced from semver's changelog.

7.5.4 (2023-07-07)

Bug Fixes

7.5.3 (2023-06-22)

Bug Fixes

Documentation

7.5.2 (2023-06-15)

Bug Fixes

7.5.1 (2023-05-12)

Bug Fixes

7.5.0 (2023-04-17)

Features

Bug Fixes

7.4.0 (2023-04-10)

Features

... (truncated)

Commits
  • 36cd334 chore: release 7.5.4
  • 8456d87 chore: postinstall for dependabot template-oss PR
  • dde1f00 chore: postinstall for dependabot template-oss PR
  • dffcd1b chore: bump @​npmcli/template-oss from 4.16.0 to 4.17.0
  • d619f66 chore: postinstall for dependabot template-oss PR
  • 3bc4247 chore: bump @​npmcli/template-oss from 4.15.1 to 4.16.0
  • cc6fde2 fix: trim each range set before parsing
  • 99d8287 fix: correctly parse long build ids as valid (#583)
  • 4f0f6b1 chore: fix arguments in whitespace test (#574)
  • 6bd1a37 chore: remove duplicate test in semver class (#575)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by npm-cli-ops, a new releaser for semver since your current version.


Updates @shopify/app from 3.41.1 to 3.58.2

Commits
  • b489891 Merge pull request #3655 from Shopify/changeset-release/stable/3.58
  • a4ab7e5 Version Packages
  • f41ab02 [3.58] Fix shopify theme push issue when password flag is provided
  • 3139346 Merge pull request #3641 from Shopify/changeset-release/stable/3.58
  • 7955f71 Version Packages
  • e03cb9c Merge pull request #3648 from Shopify/move-link-uses-api-client-config-as-fal...
  • 5b70eee Added changeset
  • 6b8a253 Revert changes to ShopifyDevelopersClient
  • b86899d Added unit tests
  • 7c2e424 Every API client config field is optional
  • Additional commits viewable in compare view

Updates @shopify/cli from 3.41.1 to 3.90.0

Release notes

Sourced from @​shopify/cli's releases.

@​shopify/cli-kit@​3.76.0

Minor Changes

  • 4a3895c: Use GraphQL for theme creation

Patch Changes

  • 38e8d7b: Hide serialized_script fields in verbose logs
  • b1ed29d: Fix binary files being corrupted on theme pull
  • 6449aa6: Fetch notifications in background

@​shopify/cli@​3.76.0

Minor Changes

  • fd32347: Add multi-environment infrastructure and allow multiple environment usage in theme list command

Patch Changes

  • c72ce71: Update to cli-hydrogen 9.0.6
  • 5ad63a4: Update to cli-hydrogen 9.0.7
  • e9b8582: Upgrade cli-hydrogen to 9.0.8 for 2025.1.2
Changelog

Sourced from @​shopify/cli's changelog.

3.90.0

3.89.0

3.88.0

3.87.0

3.86.0

Minor Changes

  • a657b4b: Add --allow-live flag to theme dev to allow development on live themes without confirmation

Patch Changes

  • e81c29c: Remove POLARIS_UNIFIED flag

3.85.0

Minor Changes

  • b855ec1: Allow theme push and share commands to be called with multiple environments
  • 809d355: Display warning when multiple environment flags are provided to profile, metafields pull, open, dev, or console theme commands
  • 6497461: Add auth login command with multi-session support
  • f8df96b: Allow theme pull command to be called with multiple environments

Patch Changes

  • 4d377e8: Remove leftover references to CLI2 from theme commands

3.84.0

Minor Changes

  • 1f4fd78: Allow multi-environment theme commands to accept flags from CLI
  • 9b872dc: Update fetched AI instructions
  • b382a89: Prompt for confirmation before running multi-environment theme commands that allow --force flag
  • 281b50b: Allow theme rename command to be run with multiple environments
  • a12a7cc: Allow commands run with multiple environments to require "one of" a list of flags

Patch Changes

  • 1161f7a: Update docs for 'ignore' and 'only' flags for theme push/pull

3.83.0

Minor Changes

  • 521fb07: Add new theme duplicate command to duplicate store themes

... (truncated)

Commits
  • 4698acc Version Packages
  • b105cfd refresh manifests
  • 05a210b Version Packages
  • 68279b0 Recommend --allow-updates and improve errors on CI/CD
  • b19f3fc Add --allow-updates and --allow-delete flags to deploy and release
  • 2465390 Update React types to 18.3.12 and fix TypeScript compatibility
  • 7297a1f Merge pull request #6734 from Shopify/execute_commands_remove_query_stdin_sup...
  • a28e8f4 Merge pull request #6733 from Shopify/app_execute_query_file
  • aee9944 Merge pull request #6732 from Shopify/app_execute_variable_file
  • f594242 Merge pull request #6706 from Shopify/add-shopify-app-bulk-cancel-command
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for @​shopify/cli since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [semver](https://github.com/npm/node-semver) to 7.5.4 and updates ancestor dependencies [semver](https://github.com/npm/node-semver), [@shopify/app](https://github.com/Shopify/cli) and [@shopify/cli](https://github.com/Shopify/cli/tree/HEAD/packages/cli). These dependencies need to be updated together.


Updates `semver` from 7.3.6 to 7.5.4
- [Release notes](https://github.com/npm/node-semver/releases)
- [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md)
- [Commits](npm/node-semver@v7.3.6...v7.5.4)

Updates `@shopify/app` from 3.41.1 to 3.58.2
- [Release notes](https://github.com/Shopify/cli/releases)
- [Commits](Shopify/cli@3.41.1...3.58.2)

Updates `@shopify/cli` from 3.41.1 to 3.90.0
- [Release notes](https://github.com/Shopify/cli/releases)
- [Changelog](https://github.com/Shopify/cli/blob/main/packages/cli/CHANGELOG.md)
- [Commits](https://github.com/Shopify/cli/commits/3.90.0/packages/cli)

---
updated-dependencies:
- dependency-name: semver
  dependency-version: 7.5.4
  dependency-type: indirect
- dependency-name: "@shopify/app"
  dependency-version: 3.58.2
  dependency-type: direct:production
- dependency-name: "@shopify/cli"
  dependency-version: 3.90.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Feb 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants