Skip to content

deps(dev): bump cspell from 9.8.0 to 10.3.6 - #3972

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/cspell-10.3.6
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/cspell-10.3.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps cspell from 9.8.0 to 10.3.6.

Release notes

Sourced from cspell's releases.

v10.3.6

Fixes

fix: Report unknown CSpell directives again (#9319)

Summary

cspell lint reports unknown in-document directives again, such as cspell:bad-dir, when --validate-directives or validateDirectives: true in the config asks for them. Since 9.1.0 they were found but never shown or counted.

  • --validate-directives and --no-validate-directives override the config setting.
  • An unknown directive counts as an issue, so cspell lint exits with an error, as it did before 9.1.0.
  • The JSON reporter, @cspell/cspell-json-reporter, includes them in its output again.
  • The default reporter and the JSON reporter now ask to receive directive issues. Other reporters still only get them if they ask for them.
  • The command-line flag is now applied as a setting, like --report, so it controls what is shown as well as what is checked.

fix(cspell-io): Keep redirected requests under the private root (#9329)

Summary

createRedirectProvider in cspell-io now only serves requests that map to a location under its private root. A request that would resolve outside the private root is refused with VFSErrorUnsupportedRequest, the same error as a request outside the public root.

  • Refused: a path that starts with a separator (/, \, %2F, %5C) right after the public root.
  • Now served from inside the private root: file names that look like a URL scheme or a drive, such as a:b.txt or C|. They used to resolve to a different URL.

cspell itself does not use createRedirectProvider. This affects projects that use cspell-io directly.

  • The part of the URL after the public root is resolved as a relative path under the private root, and the result is checked to be under the private root: same protocol, same host, and the same path prefix.
  • Results coming back from the private file system are checked the same way before they are shown under the public root.
  • The change is in commit 25359026e1.

... (truncated)

Changelog

Sourced from cspell's changelog.

v10.3.6 (2026-09-29)

Fixes

fix: Report unknown CSpell directives again (#9319)

Summary

cspell lint reports unknown in-document directives again, such as cspell:bad-dir, when --validate-directives or validateDirectives: true in the config asks for them. Since 9.1.0 they were found but never shown or counted.

  • --validate-directives and --no-validate-directives override the config setting.
  • An unknown directive counts as an issue, so cspell lint exits with an error, as it did before 9.1.0.
  • The JSON reporter, @cspell/cspell-json-reporter, includes them in its output again.
  • The default reporter and the JSON reporter now ask to receive directive issues. Other reporters still only get them if they ask for them.
  • The command-line flag is now applied as a setting, like --report, so it controls what is shown as well as what is checked.

fix(cspell-io): Keep redirected requests under the private root (#9329)

Summary

createRedirectProvider in cspell-io now only serves requests that map to a location under its private root. A request that would resolve outside the private root is refused with VFSErrorUnsupportedRequest, the same error as a request outside the public root.

  • Refused: a path that starts with a separator (/, \, %2F, %5C) right after the public root.
  • Now served from inside the private root: file names that look like a URL scheme or a drive, such as a:b.txt or C|. They used to resolve to a different URL.

cspell itself does not use createRedirectProvider. This affects projects that use cspell-io directly.

  • The part of the URL after the public root is resolved as a relative path under the private root, and the result is checked to be under the private root: same protocol, same host, and the same path prefix.
  • Results coming back from the private file system are checked the same way before they are shown under the public root.
  • The change is in commit 25359026e1.

... (truncated)

Commits
  • 8559198 v10.3.6
  • 72e1be3 chore: Prepare Release v10.3.6 (auto-deploy) (#9305)
  • e230ca0 test: Give time-limited RPC and worker tests room on slow runners (#9330)
  • 8eae6b6 fix: Report unknown CSpell directives again (#9319)
  • a5f5111 fix: Don't reuse cached results made with different command-line options (#9318)
  • 2f897be fix: --show-perf-summary shows where all of the run's time goes (#9307)
  • fe37b7b chore: Label per package, and bugs links to its open issues (#9309)
  • f37a244 v10.3.5
  • b36374c chore: Prepare Release v10.3.5 (auto-deploy) (#9277)
  • 93e55c0 fix(cspell-lib): shouldCheckDocument honors the forceCheck option (#9303)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for cspell since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [cspell](https://github.com/streetsidesoftware/cspell/tree/HEAD/packages/cspell) from 9.8.0 to 10.3.6.
- [Release notes](https://github.com/streetsidesoftware/cspell/releases)
- [Changelog](https://github.com/streetsidesoftware/cspell/blob/main/packages/cspell/CHANGELOG.md)
- [Commits](https://github.com/streetsidesoftware/cspell/commits/v10.3.6/packages/cspell)

---
updated-dependencies:
- dependency-name: cspell
  dependency-version: 10.3.6
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 4, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 4, 2026 19:04
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 4, 2026
@github-actions github-actions Bot added the size/XS Extra small PR (code churn < 10) label Oct 4, 2026

This branch was successfully deployed

No deployments
AcceptanceTests — 4be2b228 Deployed Oct 4, 2026 by dependabot[bot] via integration (20.x, ubuntu-latest) #9396
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code size/XS Extra small PR (code churn < 10)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants