dependabot[bot] opened a new pull request, #492: URL: https://github.com/apache/arrow-js/pull/492
Bumps [rollup](https://github.com/rollup/rollup) from 4.59.0 to 4.63.5. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/rollup/rollup/releases">rollup's releases</a>.</em></p> <blockquote> <h2>v4.63.5</h2> <h2>4.63.5</h2> <p><em>2026-09-24</em></p> <h3>Bug Fixes</h3> <ul> <li>Fix an issue where watch mode would hang instead of terminating when closing via Ctrl+C (<a href="https://redirect.github.com/rollup/rollup/issues/6521">#6521</a>)</li> <li>Avoid starting overlapping watch mode runs when plugins invalidate files at the wrong time (<a href="https://redirect.github.com/rollup/rollup/issues/6526">#6526</a>)</li> <li>Fix many edge cases where watch mode events were not properly emitted to listeners, especially when errors occur (<a href="https://redirect.github.com/rollup/rollup/issues/6526">#6526</a>)</li> </ul> <h3>Pull Requests</h3> <ul> <li><a href="https://redirect.github.com/rollup/rollup/pull/6520">#6520</a>: Lock file maintenance (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot], <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6521">#6521</a>: Terminate watch mode via natural process exit when possible (<a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6523">#6523</a>: Protect cc pin against renovate lock file maintenance (<a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6525">#6525</a>: docs: fix typos 'interations' and 'coresponding' (<a href="https://github.com/haimingZZ"><code>@haimingZZ</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6526">#6526</a>: fix(watch): prevent overlapping runs and other run lifecycle bugs (<a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> </ul> <h2>v4.63.4</h2> <h2>4.63.4</h2> <p><em>2026-09-19</em></p> <h3>Bug Fixes</h3> <ul> <li>Ensure meta information of the cached module is exposed in <code>shouldTransformCachedModule</code> (<a href="https://redirect.github.com/rollup/rollup/issues/6442">#6442</a>)</li> <li>Do not create invalid code if import attribute values contain special characters (<a href="https://redirect.github.com/rollup/rollup/issues/6502">#6502</a>)</li> </ul> <h3>Pull Requests</h3> <ul> <li><a href="https://redirect.github.com/rollup/rollup/pull/6429">#6429</a>: ci: collect Rust coverage from JS tests in dedicated job (<a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6442">#6442</a>: fix: expose cached module meta during cache checks (<a href="https://github.com/ychampion"><code>@ychampion</code></a>, <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6496">#6496</a>: docs: name the parameter runHook actually takes (<a href="https://github.com/darkdi"><code>@darkdi</code></a>, <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6502">#6502</a>: Escape quotes and backslashes in import attribute values (<a href="https://github.com/dylanpulver"><code>@dylanpulver</code></a>, <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6517">#6517</a>: Improve agent instructions (<a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6518">#6518</a>: fix(deps): update minor/patch updates (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6519">#6519</a>: Request Copilot code review via workflow (<a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> </ul> <h2>v4.63.3</h2> <h2>4.63.3</h2> <p><em>2026-09-14</em></p> <h3>Bug Fixes</h3> <ul> <li>Make sure that the internal shims for basename and extname in the browser build fully match NodeJS (<a href="https://redirect.github.com/rollup/rollup/issues/6473">#6473</a>)</li> <li>Always report and recover from failures on invalidation in watch mode (<a href="https://redirect.github.com/rollup/rollup/issues/6506">#6506</a>)</li> <li>Respect windows line terminators when tree-shaking in situations where line-breaks need to be removed to prevent automatic semicolon insertion (<a href="https://redirect.github.com/rollup/rollup/issues/6514">#6514</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/rollup/rollup/blob/master/CHANGELOG.md">rollup's changelog</a>.</em></p> <blockquote> <h2>4.63.5</h2> <p><em>2026-09-24</em></p> <h3>Bug Fixes</h3> <ul> <li>Fix an issue where watch mode would hang instead of terminating when closing via Ctrl+C (<a href="https://redirect.github.com/rollup/rollup/issues/6521">#6521</a>)</li> <li>Avoid starting overlapping watch mode runs when plugins invalidate files at the wrong time (<a href="https://redirect.github.com/rollup/rollup/issues/6526">#6526</a>)</li> <li>Fix many edge cases where watch mode events were not properly emitted to listeners, especially when errors occur (<a href="https://redirect.github.com/rollup/rollup/issues/6526">#6526</a>)</li> </ul> <h3>Pull Requests</h3> <ul> <li><a href="https://redirect.github.com/rollup/rollup/pull/6520">#6520</a>: Lock file maintenance (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot], <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6521">#6521</a>: Terminate watch mode via natural process exit when possible (<a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6523">#6523</a>: Protect cc pin against renovate lock file maintenance (<a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6525">#6525</a>: docs: fix typos 'interations' and 'coresponding' (<a href="https://github.com/haimingZZ"><code>@haimingZZ</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6526">#6526</a>: fix(watch): prevent overlapping runs and other run lifecycle bugs (<a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> </ul> <h2>4.63.4</h2> <p><em>2026-09-19</em></p> <h3>Bug Fixes</h3> <ul> <li>Ensure meta information of the cached module is exposed in <code>shouldTransformCachedModule</code> (<a href="https://redirect.github.com/rollup/rollup/issues/6442">#6442</a>)</li> <li>Do not create invalid code if import attribute values contain special characters (<a href="https://redirect.github.com/rollup/rollup/issues/6502">#6502</a>)</li> </ul> <h3>Pull Requests</h3> <ul> <li><a href="https://redirect.github.com/rollup/rollup/pull/6429">#6429</a>: ci: collect Rust coverage from JS tests in dedicated job (<a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6442">#6442</a>: fix: expose cached module meta during cache checks (<a href="https://github.com/ychampion"><code>@ychampion</code></a>, <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6496">#6496</a>: docs: name the parameter runHook actually takes (<a href="https://github.com/darkdi"><code>@darkdi</code></a>, <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6502">#6502</a>: Escape quotes and backslashes in import attribute values (<a href="https://github.com/dylanpulver"><code>@dylanpulver</code></a>, <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6517">#6517</a>: Improve agent instructions (<a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6518">#6518</a>: fix(deps): update minor/patch updates (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6519">#6519</a>: Request Copilot code review via workflow (<a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> </ul> <h2>4.63.3</h2> <p><em>2026-09-14</em></p> <h3>Bug Fixes</h3> <ul> <li>Make sure that the internal shims for basename and extname in the browser build fully match NodeJS (<a href="https://redirect.github.com/rollup/rollup/issues/6473">#6473</a>)</li> <li>Always report and recover from failures on invalidation in watch mode (<a href="https://redirect.github.com/rollup/rollup/issues/6506">#6506</a>)</li> <li>Respect windows line terminators when tree-shaking in situations where line-breaks need to be removed to prevent automatic semicolon insertion (<a href="https://redirect.github.com/rollup/rollup/issues/6514">#6514</a>)</li> </ul> <h3>Pull Requests</h3> <ul> <li><a href="https://redirect.github.com/rollup/rollup/pull/6473">#6473</a>: fix(browser): match node's basename and extname (<a href="https://github.com/luantaraschi"><code>@luantaraschi</code></a>, <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/rollup/rollup/commit/3722484c33c58b3ab0cbbfcca09b8f267d420329"><code>3722484</code></a> 4.63.5</li> <li><a href="https://github.com/rollup/rollup/commit/9156d5b509b6b27676d34430ca9be6eb82a34f86"><code>9156d5b</code></a> fix(watch): prevent overlapping runs and other run lifecycle bugs (<a href="https://redirect.github.com/rollup/rollup/issues/6526">#6526</a>)</li> <li><a href="https://github.com/rollup/rollup/commit/87fbbf6b3f8c55c81f1f07673957ebd70bc57c07"><code>87fbbf6</code></a> Protect cc pin against renovate lock file maintenance (<a href="https://redirect.github.com/rollup/rollup/issues/6523">#6523</a>)</li> <li><a href="https://github.com/rollup/rollup/commit/30f0442482c0ab2b37e7e7af3bdd04e6bb292c48"><code>30f0442</code></a> docs: fix typos 'interations' and 'coresponding' (<a href="https://redirect.github.com/rollup/rollup/issues/6525">#6525</a>)</li> <li><a href="https://github.com/rollup/rollup/commit/b54c4c2af5762e846109f1b1f09d5a944486498a"><code>b54c4c2</code></a> Lock file maintenance (<a href="https://redirect.github.com/rollup/rollup/issues/6520">#6520</a>)</li> <li><a href="https://github.com/rollup/rollup/commit/c28de6fa616ff6525802996a6b480b57d1e7b0e1"><code>c28de6f</code></a> Terminate watch mode via natural process exit when possible (<a href="https://redirect.github.com/rollup/rollup/issues/6521">#6521</a>)</li> <li><a href="https://github.com/rollup/rollup/commit/ba78d5752a1e1ff4ff4af3a8bffab7691d822f7d"><code>ba78d57</code></a> 4.63.4</li> <li><a href="https://github.com/rollup/rollup/commit/67c3379f61a105839e26afdf519f2f65a0a2e248"><code>67c3379</code></a> Escape quotes and backslashes in import attribute values (<a href="https://redirect.github.com/rollup/rollup/issues/6502">#6502</a>)</li> <li><a href="https://github.com/rollup/rollup/commit/35f6053b8b655befc57f8db79006e8cd47312699"><code>35f6053</code></a> fix: expose cached module meta during cache checks (<a href="https://redirect.github.com/rollup/rollup/issues/6442">#6442</a>)</li> <li><a href="https://github.com/rollup/rollup/commit/b7ae5e20fa60caa4e4d73d32200991104c5e9616"><code>b7ae5e2</code></a> Request Copilot code review via workflow (<a href="https://redirect.github.com/rollup/rollup/issues/6519">#6519</a>)</li> <li>Additional commits viewable in <a href="https://github.com/rollup/rollup/compare/v4.59.0...v4.63.5">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
