Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 23, 2025

Bumps eslint-plugin-yml from 1.18.0 to 1.19.0.

Release notes

Sourced from eslint-plugin-yml's releases.

v1.19.0

Minor Changes

  • #482 2dd3bca Thanks @​ota-meshi! - feat(sort-keys): improve to calculate the minimum edit distance for sorting and report the optimal sorting direction

  • #482 2dd3bca Thanks @​ota-meshi! - feat(sort-sequence-values): improve to calculate the minimum edit distance for sorting and report the optimal sorting direction

Changelog

Sourced from eslint-plugin-yml's changelog.

1.19.0

Minor Changes

  • #482 2dd3bca Thanks @​ota-meshi! - feat(sort-keys): improve to calculate the minimum edit distance for sorting and report the optimal sorting direction

  • #482 2dd3bca Thanks @​ota-meshi! - feat(sort-sequence-values): improve to calculate the minimum edit distance for sorting and report the optimal sorting direction

Commits
  • 76e635a Version Packages (#484)
  • 5191220 fix: wrong import paths
  • 62e4315 Update package.json
  • 2dd3bca feat(sort-keys): improve to calculate the minimum edit distance for sorting a...
  • b332c3d chore: repo maintenance
  • 988e028 use instant preview
  • 3ed61f5 chore(deps): update actions/stale action to v10 (#469)
  • 8b97e96 chore(deps): update typescript-eslint monorepo to ~8.45.0 (#481)
  • 9d16b78 chore(deps): update npm to v11.6.1 (#480)
  • f9aa306 chore(deps): update dependency eslint-plugin-jsdoc to v60 (#478)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for eslint-plugin-yml since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [eslint-plugin-yml](https://github.com/ota-meshi/eslint-plugin-yml) from 1.18.0 to 1.19.0.
- [Release notes](https://github.com/ota-meshi/eslint-plugin-yml/releases)
- [Changelog](https://github.com/ota-meshi/eslint-plugin-yml/blob/master/CHANGELOG.md)
- [Commits](ota-meshi/eslint-plugin-yml@v1.18.0...v1.19.0)

---
updated-dependencies:
- dependency-name: eslint-plugin-yml
  dependency-version: 1.19.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependencies Changes to the project's dependencies label Oct 23, 2025
@fossabot
Copy link

fossabot bot commented Oct 23, 2025

fossabot is Thinking

@fossabot
Copy link

fossabot bot commented Oct 23, 2025

✓ Safe to upgrade

I recommend merging this upgrade because this is a minor version update that only improves the internal sorting algorithms for the sort-keys and sort-sequence-values rules. The project has both of these rules explicitly disabled in the ESLint configuration, so the algorithm improvements will have no impact on the codebase. The upgrade is purely a dependency update with no breaking changes, configuration changes required, or functional impact on the YAML linting currently enforced across the GitHub Actions workflows and configuration files.

What we checked

  • eslint-plugin-yml upgraded from 1.18.0 to 1.19.0 as a devDependency [1]
  • yml/sort-keys rule is explicitly disabled, so improved sorting algorithm in v1.19.0 has no effect [2]
  • yml/sort-sequence-values rule is explicitly disabled, so improved sorting algorithm in v1.19.0 has no effect [3]
  • Plugin imported and used in ESLint flat config for YAML file linting [4]
  • v1.19.0 released October 2nd with improved sorting algorithms for sort-keys and sort-sequence-values rules (calculating minimum edit distance for optimal sorting direction) [5]

Dependency Usage

The eslint-plugin-yml dependency is integrated into the project's code quality infrastructure to enforce consistent YAML formatting and validation rules across GitHub Actions workflows and configuration files. This plugin enables automated linting of multiple YAML files in the .github/workflows directory and config directory, ensuring adherence to formatting standards like double quotes, block mapping style, proper indentation, and preventing common YAML errors. The plugin follows a centralized ESLint configuration pattern where all linting rules are consolidated in a single configuration file that orchestrates multiple specialized ESLint plugins for different file types.

This code is importing the eslint-plugin-yml package to enable YAML linting rules within an ESLint configuration file.

Other Usages (1)

These usages were analyzed but no breaking changes were detected:

eslint-plugin-yml

Changes

The eslint-plugin-yml package was updated with an enhancement to the sort-keys rule that now calculates minimum edit distance for sorting and reports the optimal sorting direction, improving linting accuracy for YAML key ordering.

  • #482 2dd3bca Thanks @​ota-meshi! - feat(sort-keys): improve to calculate the minimum edit distance for sorting and report the optimal sorting direction (v1.19.0, changelog)
References (5)

[1]: eslint-plugin-yml upgraded from 1.18.0 to 1.19.0 as a devDependency

"eslint-plugin-yml": "1.19.0",

[2]: yml/sort-keys rule is explicitly disabled, so improved sorting algorithm in v1.19.0 has no effect

"yml/sort-keys": ["off"],

[3]: yml/sort-sequence-values rule is explicitly disabled, so improved sorting algorithm in v1.19.0 has no effect

"yml/sort-sequence-values": ["off"],

[4]: Plugin imported and used in ESLint flat config for YAML file linting

import yml from "eslint-plugin-yml";

[5]: v1.19.0 released October 2nd with improved sorting algorithms for sort-keys and sort-sequence-values rules (calculating minimum edit distance for optimal sorting direction) (source link)


fossabot analyzed this PR using static analysis and dependency research.

@deepsource-io
Copy link

deepsource-io bot commented Oct 23, 2025

Here's the code health analysis summary for commits 65bc4f5..7a1196e. View details on DeepSource ↗.

Analysis Summary

AnalyzerStatusSummaryLink
DeepSource JavaScript LogoJavaScript✅ SuccessView Check ↗

💡 If you’re a repository administrator, you can configure the quality gates from the settings.

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Oct 23, 2025

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot bot deleted the dependabot/npm_and_yarn/eslint-plugin-yml-1.19.0 branch October 23, 2025 17:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Changes to the project's dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant