Skip to content

Bump import-module-string from 2.0.3 to 3.0.0 - #254

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/import-module-string-3.0.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/import-module-string-3.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps import-module-string from 2.0.3 to 3.0.0.

Release notes

Sourced from import-module-string's releases.

import-module-string v3.0.0

Breaking

  • Node minimum bump to 22.18
  • Adds exports map to package.json (no more wild west deep imports)

Features and Fixes

  • Adds TypeScript types
  • Fixes issue with implicit exports picking up non-top-level globals. Related 11ty/buildawesome#4354
  • Was missing a license file 🫣

Size watch: No dependency count changes but this release did grow in file size due to TypeScript types. Full Changelog: zachleat/import-module-string@v2.0.3...v3.0.0

Commits
  • 3bd41a7 v3.0.0
  • ff25c1a Implicit export was detecting more than top level globals. See https://github...
  • fccf85a Fix audits
  • 92bf0e7 Merge pull request #9 from zachleat/dependabot/github_actions/dot-github/work...
  • 230b83d Merge pull request #10 from zachleat/dependabot/github_actions/dot-github/wor...
  • f312bc7 Upgrade dev deps (major bumps)
  • d465bf1 Upgrade deps
  • c4c67e1 Prepare for v3.0.0
  • eabc6da Adds typescript types, bump Node minimum to 22+
  • 09afbec Bump actions/checkout from 6.0.2 to 7.0.1 in /.github/workflows
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [import-module-string](https://github.com/zachleat/import-module-string) from 2.0.3 to 3.0.0.
- [Release notes](https://github.com/zachleat/import-module-string/releases)
- [Commits](zachleat/import-module-string@v2.0.3...v3.0.0)

---
updated-dependencies:
- dependency-name: import-module-string
  dependency-version: 3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Development

Successfully merging this pull request may close these issues.

0 participants