Skip to content

chore(deps): bump the npm_and_yarn group with 2 updates#159

Merged
akiojin merged 1 commit into
developfrom
dependabot/npm_and_yarn/develop/npm_and_yarn-acda4d4975
Apr 7, 2026
Merged

chore(deps): bump the npm_and_yarn group with 2 updates#159
akiojin merged 1 commit into
developfrom
dependabot/npm_and_yarn/develop/npm_and_yarn-acda4d4975

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 6, 2026

Bumps the npm_and_yarn group with 2 updates: @google/gemini-cli and @openai/codex.

Updates @google/gemini-cli from 0.34.0 to 0.36.0

Release notes

Sourced from @​google/gemini-cli's releases.

Release v0.36.0

What's Changed

... (truncated)

Commits
  • 8b1e649 chore(release): v0.36.0
  • b6d9970 chore(release): v0.36.0-preview.8
  • 201c74c fix(config): disable JIT context loading by default (#24364)
  • b7d2aea ink 6.6.3 (#24372)
  • 071076a chore(release): v0.36.0-preview.7
  • 425d64a fix(chore): resolve typescript errors resulting from cherry-picks
  • c63350c fix broken tests (#24279)
  • 55a5ed6 fix(cli): resolve missing F12 logs via global console store (#24235)
  • 7e0ac00 feat(cli): show Flash Lite Preview model regardless of user tier (#23904)
  • bbd8483 feat(core,ui): Add experiment-gated support for gemini flash 3.1 lite (#23794)
  • Additional commits viewable in compare view

Updates @openai/codex from 0.116.0 to 0.118.0

Release notes

Sourced from @​openai/codex's releases.

0.118.0

New Features

  • Windows sandbox runs can now enforce proxy-only networking with OS-level egress rules, instead of relying on environment variables alone. (#12220)
  • App-server clients can now start ChatGPT sign-in with a device code flow, which helps when browser callback login is unreliable or unavailable. (#15525)
  • codex exec now supports the prompt-plus-stdin workflow, so you can pipe input and still pass a separate prompt on the command line. (#15917)
  • Custom model providers can now fetch and refresh short-lived bearer tokens dynamically, instead of being limited to static credentials from config or environment variables. (#16286, #16287, #16288)

Bug Fixes

  • Project-local .codex files are now protected even on first creation, closing a gap where the initial write could bypass normal approval checks. (#15067)
  • Linux sandbox launches are more reliable because Codex once again finds a trusted system bwrap on normal multi-entry PATHs. (#15791, #15973)
  • The app-server-backed TUI regained several missing workflows: hook notifications replay correctly, /copy and /resume <name> work again, /agent no longer shows stale threads, and the skills picker scrolls past the first page. (#16013, #16021, #16050, #16014, #16109, #16110)
  • MCP startup is more robust: local servers get a longer startup window, and failed handshakes surface warnings in the TUI again instead of looking like clean startups. (#16080, #16041)
  • On Windows, apply_patch is less likely to fail because it no longer adds redundant writable roots that could trigger unnecessary ACL churn. (#16030)

Changelog

Full Changelog: openai/codex@rust-v0.117.0...rust-v0.118.0

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the npm_and_yarn group with 2 updates: [@google/gemini-cli](https://github.com/google-gemini/gemini-cli) and [@openai/codex](https://github.com/openai/codex/tree/HEAD/codex-cli).


Updates `@google/gemini-cli` from 0.34.0 to 0.36.0
- [Release notes](https://github.com/google-gemini/gemini-cli/releases)
- [Changelog](https://github.com/google-gemini/gemini-cli/blob/main/docs/releases.md)
- [Commits](google-gemini/gemini-cli@v0.34.0...v0.36.0)

Updates `@openai/codex` from 0.116.0 to 0.118.0
- [Release notes](https://github.com/openai/codex/releases)
- [Commits](https://github.com/openai/codex/commits/rust-v0.118.0/codex-cli)

---
updated-dependencies:
- dependency-name: "@google/gemini-cli"
  dependency-version: 0.36.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm_and_yarn
- dependency-name: "@openai/codex"
  dependency-version: 0.118.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 6, 2026

Labels

The following labels could not be found: npm. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Apr 6, 2026
@akiojin akiojin merged commit fc2b207 into develop Apr 7, 2026
8 checks passed
@akiojin akiojin deleted the dependabot/npm_and_yarn/develop/npm_and_yarn-acda4d4975 branch April 7, 2026 04:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant