Skip to content

chore(deps-dev): bump turbo from 2.9.7 to 2.9.14 in the npm_and_yarn group across 1 directory#450

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-ed42d8a014
Closed

chore(deps-dev): bump turbo from 2.9.7 to 2.9.14 in the npm_and_yarn group across 1 directory#450
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-ed42d8a014

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github May 23, 2026

Bumps the npm_and_yarn group with 1 update in the / directory: turbo.

Updates turbo from 2.9.7 to 2.9.14

Release notes

Sourced from turbo's releases.

Turborepo v2.9.14

[!NOTE] This release contains important security fixes.

High:

Low:

What's Changed

Changelog

New Contributors

Full Changelog: vercel/turborepo@v2.9.12...v2.9.14

Turborepo v2.9.13-canary.1

What's Changed

Changelog

... (truncated)

Commits


Note

Low Risk
Dev-only dependency and lockfile churn with no runtime code changes; the turbo upgrade includes upstream security patches worth taking.

Overview
Bumps the root devDependency turbo from 2.9.7 to 2.9.14 in package.json and refreshes pnpm-lock.yaml. No application or library source changes—only how the monorepo runs turbo for dev, build, test, and typecheck.

The lockfile also picks up transitive updates pulled in with the new resolution (e.g. esbuild 0.27.7, rollup 4.60.4, ajv 6.15.0, and related platform packages). 2.9.14 includes Turborepo security fixes (notably VS Code extension command injection); those matter if you use the extension or remote auth, less so for CLI-only CI/local builds.

Reviewed by Cursor Bugbot for commit 2efdd28. Bugbot is set up for automated code reviews on this repo. Configure here.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 23, 2026
@vercel
Copy link
Copy Markdown

vercel Bot commented May 23, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
react-doctor-website Ready Ready Preview, Comment May 23, 2026 9:18am

Bumps the npm_and_yarn group with 1 update in the / directory: [turbo](https://github.com/vercel/turborepo).


Updates `turbo` from 2.9.7 to 2.9.14
- [Release notes](https://github.com/vercel/turborepo/releases)
- [Changelog](https://github.com/vercel/turborepo/blob/main/RELEASE.md)
- [Commits](vercel/turborepo@v2.9.7...v2.9.14)

---
updated-dependencies:
- dependency-name: turbo
  dependency-version: 2.9.14
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/npm_and_yarn-ed42d8a014 branch from b49b1b4 to 2efdd28 Compare May 24, 2026 23:33
@aidenybai aidenybai closed this May 25, 2026
@dependabot @github
Copy link
Copy Markdown
Author

dependabot Bot commented on behalf of github May 25, 2026

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/npm_and_yarn-ed42d8a014 branch May 25, 2026 01:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant