Skip to content

chore(deps-dev): bump turbo from 2.5.6 to 2.9.14 - #332

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/turbo-2.9.14
Open

chore(deps-dev): bump turbo from 2.5.6 to 2.9.14#332
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/turbo-2.9.14

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 28, 2026

Copy link
Copy Markdown
Contributor

Bumps turbo from 2.5.6 to 2.9.14.

Release notes

Sourced from turbo's releases.

Turborepo v2.9.14

[!NOTE] This release contains important security fixes.

High:

Low:

What's Changed

Changelog

New Contributors

Full Changelog: vercel/turborepo@v2.9.12...v2.9.14

Turborepo v2.9.13-canary.1

What's Changed

Changelog

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for turbo since your current version.



Note

Medium Risk
Low runtime risk for the published packages, but the lockfile also changes resolved Next versions for latest example apps and upgrades the monorepo task runner used in CI.

Overview
Bumps the root turbo devDependency from ^2.5.4 to ^2.9.14 (lockfile resolves 2.9.18), aligning monorepo scripts (build, test, lint, etc.) with a newer Turborepo release that includes security fixes noted in the release notes.

The pnpm-lock.yaml refresh also drops older turbo 2.5.6 / 2.9.12 entries, updates eslint-plugin-turbo’s linked turbo peer to 2.9.18, and—because several telemetry examples pin next: latest—moves their resolved Next from 16.3.0-canary.41 to stable 16.2.9 (including matching @next/* SWC packages and a postcss version change on those installs). A minor nanoid@3.3.12 entry appears for an optional postcss@8.5.10 path.

Reviewed by Cursor Bugbot for commit 7a394c8. Bugbot is set up for automated code reviews on this repo. Configure here.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 28, 2026
@pkg-pr-new

pkg-pr-new Bot commented May 28, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/axiom@332

commit: 7a394c8

@dependabot @github

dependabot Bot commented on behalf of github Jun 8, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

Bumps [turbo](https://github.com/vercel/turborepo) from 2.5.6 to 2.9.14.
- [Release notes](https://github.com/vercel/turborepo/releases)
- [Changelog](https://github.com/vercel/turborepo/blob/main/RELEASE.md)
- [Commits](vercel/turborepo@v2.5.6...v2.9.14)

---
updated-dependencies:
- dependency-name: turbo
  dependency-version: 2.9.14
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/turbo-2.9.14 branch from c430eca to 7a394c8 Compare June 12, 2026 09:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants