Repository navigation
chore(deps): merge main into Dev_new_gui to unblock the release sync (#13654) - #13655
Conversation
chore(sync): promote Dev_new_gui to main — 601 commits since 2026-07-17
…updates (#13515) Bumps the npm_and_yarn group with 1 update in the /.mcp directory: [ip-address](https://github.com/beaugunderson/ip-address). Bumps the npm_and_yarn group with 1 update in the /autobot-frontend directory: [undici](https://github.com/nodejs/undici). Bumps the npm_and_yarn group with 2 updates in the /autobot-infrastructure/shared/mcp/tools/mcp-autobot-tracker directory: [ip-address](https://github.com/beaugunderson/ip-address) and [mongoose](https://github.com/Automattic/mongoose). Bumps the npm_and_yarn group with 1 update in the /autobot-infrastructure/shared/mcp/tools/mcp-structured-thinking directory: [ip-address](https://github.com/beaugunderson/ip-address). Updates `ip-address` from 10.2.0 to 10.4.0 - [Release notes](https://github.com/beaugunderson/ip-address/releases) - [Commits](beaugunderson/ip-address@v10.2.0...v10.4.0) Updates `ip-address` from 10.2.0 to 10.4.0 - [Release notes](https://github.com/beaugunderson/ip-address/releases) - [Commits](beaugunderson/ip-address@v10.2.0...v10.4.0) Updates `ip-address` from 10.2.0 to 10.4.0 - [Release notes](https://github.com/beaugunderson/ip-address/releases) - [Commits](beaugunderson/ip-address@v10.2.0...v10.4.0) Updates `undici` from 7.28.0 to 7.29.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.28.0...v7.29.0) Updates `undici` from 7.28.0 to 7.29.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.28.0...v7.29.0) Updates `ip-address` from 10.2.0 to 10.4.0 - [Release notes](https://github.com/beaugunderson/ip-address/releases) - [Commits](beaugunderson/ip-address@v10.2.0...v10.4.0) Updates `ip-address` from 10.2.0 to 10.4.0 - [Release notes](https://github.com/beaugunderson/ip-address/releases) - [Commits](beaugunderson/ip-address@v10.2.0...v10.4.0) Updates `mongoose` from 8.23.1 to 8.24.2 - [Release notes](https://github.com/Automattic/mongoose/releases) - [Changelog](https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md) - [Commits](Automattic/mongoose@8.23.1...8.24.2) Updates `ip-address` from 10.2.0 to 10.4.0 - [Release notes](https://github.com/beaugunderson/ip-address/releases) - [Commits](beaugunderson/ip-address@v10.2.0...v10.4.0) Updates `ip-address` from 10.2.0 to 10.4.0 - [Release notes](https://github.com/beaugunderson/ip-address/releases) - [Commits](beaugunderson/ip-address@v10.2.0...v10.4.0) Updates `ip-address` from 10.2.0 to 10.4.0 - [Release notes](https://github.com/beaugunderson/ip-address/releases) - [Commits](beaugunderson/ip-address@v10.2.0...v10.4.0) Updates `ip-address` from 10.2.0 to 10.4.0 - [Release notes](https://github.com/beaugunderson/ip-address/releases) - [Commits](beaugunderson/ip-address@v10.2.0...v10.4.0) --- updated-dependencies: - dependency-name: ip-address dependency-version: 10.4.0 dependency-type: indirect - dependency-name: ip-address dependency-version: 10.4.0 dependency-type: indirect - dependency-name: ip-address dependency-version: 10.4.0 dependency-type: indirect - dependency-name: mongoose dependency-version: 8.24.2 dependency-type: indirect - dependency-name: undici dependency-version: 7.29.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Martins Veiss <martins.veiss@gmail.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…13523) Bumps the pip group with 1 update in the / directory: [cryptography](https://github.com/pyca/cryptography). Bumps the pip group with 1 update in the /requirements-ci directory: [cryptography](https://github.com/pyca/cryptography). Updates `cryptography` from 49.0.0 to 50.0.0 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@49.0.0...50.0.0) Updates `cryptography` from 49.0.0 to 50.0.0 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@49.0.0...50.0.0) Updates `cryptography` from 49.0.0 to 50.0.0 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@49.0.0...50.0.0) Updates `cryptography` from 49.0.0 to 50.0.0 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@49.0.0...50.0.0) --- updated-dependencies: - dependency-name: cryptography dependency-version: 50.0.0 dependency-type: direct:production - dependency-name: cryptography dependency-version: 50.0.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…updates (#13524) Bumps the npm_and_yarn group with 2 updates in the /.mcp directory: [fast-uri](https://github.com/fastify/fast-uri) and [hono](https://github.com/honojs/hono). Bumps the npm_and_yarn group with 1 update in the /autobot-frontend directory: [postcss](https://github.com/postcss/postcss). Bumps the npm_and_yarn group with 2 updates in the /autobot-infrastructure/shared/mcp/tools/mcp-autobot-tracker directory: [fast-uri](https://github.com/fastify/fast-uri) and [hono](https://github.com/honojs/hono). Bumps the npm_and_yarn group with 2 updates in the /autobot-infrastructure/shared/mcp/tools/mcp-structured-thinking directory: [fast-uri](https://github.com/fastify/fast-uri) and [hono](https://github.com/honojs/hono). Updates `fast-uri` from 3.1.4 to 3.1.5 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.4...v3.1.5) Updates `hono` from 4.12.31 to 4.13.0 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.31...v4.13.0) Updates `fast-uri` from 3.1.4 to 3.1.5 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.4...v3.1.5) Updates `hono` from 4.12.31 to 4.13.0 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.31...v4.13.0) Updates `fast-uri` from 3.1.4 to 3.1.5 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.4...v3.1.5) Updates `hono` from 4.12.31 to 4.13.0 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.31...v4.13.0) Updates `postcss` from 8.5.19 to 8.5.25 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.19...8.5.25) Updates `postcss` from 8.5.19 to 8.5.25 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.19...8.5.25) Updates `fast-uri` from 3.1.4 to 3.1.5 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.4...v3.1.5) Updates `hono` from 4.12.31 to 4.13.0 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.31...v4.13.0) Updates `fast-uri` from 3.1.4 to 3.1.5 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.4...v3.1.5) Updates `hono` from 4.12.31 to 4.13.0 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.31...v4.13.0) Updates `fast-uri` from 3.1.4 to 3.1.5 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.4...v3.1.5) Updates `hono` from 4.12.31 to 4.13.0 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.31...v4.13.0) Updates `fast-uri` from 3.1.4 to 3.1.5 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.4...v3.1.5) Updates `hono` from 4.12.31 to 4.13.0 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.31...v4.13.0) Updates `fast-uri` from 3.1.4 to 3.1.5 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.4...v3.1.5) Updates `hono` from 4.12.31 to 4.13.0 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.31...v4.13.0) Updates `fast-uri` from 3.1.4 to 3.1.5 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.4...v3.1.5) Updates `hono` from 4.12.31 to 4.13.0 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.31...v4.13.0) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.5 dependency-type: indirect - dependency-name: fast-uri dependency-version: 3.1.5 dependency-type: indirect - dependency-name: fast-uri dependency-version: 3.1.5 dependency-type: indirect - dependency-name: hono dependency-version: 4.13.0 dependency-type: indirect - dependency-name: hono dependency-version: 4.13.0 dependency-type: indirect - dependency-name: hono dependency-version: 4.13.0 dependency-type: indirect - dependency-name: postcss dependency-version: 8.5.25 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…13654) main carried 4 commits Dev_new_gui lacked (#13515, #13523, #13524 plus a merge), so `Sync Dev_new_gui -> main` refused to run. Dependabot targets the repository default branch, which is main, while every other PR targets Dev_new_gui. Resolution: keep Dev_new_gui's side throughout -- it leads on all 28 differing direct npm dependencies and on autobot-slm-backend/requirements.txt -- while accepting the genuine security upgrades main held in transitive lock entries: cryptography 49.0.0 -> 50.0.0 fast-uri 3.1.4 -> 3.1.5 hono 4.12.31 -> 4.13.0 undici 8.9.0 -> 8.10.0 nanoid 3.3.16 -> 3.3.17 Verified: no package in any package-lock.json is left behind main's version. Dev_new_gui's PyJWT[crypto] line from #13411 is preserved.
Blocked — this approach cannot pass a required check
The check scans every commit the PR adds: while IFS= read -r sha; do ... done < <(git rev-list "${BASE_SHA}..${HEAD_SHA}")
pattern='^[[:space:]]*Co-authored-by:|Generated with \[?Claude|noreply@paperclip'Merging A merge commit's whole purpose here is to put those commits in the ancestry, so the conflict is structural: the thing that unblocks the sync is the thing the check rejects. I have marked this draft rather than trying to force it through. The check's own suggested remedy — Options, all needing a decisionA. Scope the trailers check to commits authored for the PR. e.g. B. Drop the merge entirely. Land the five security bumps on C. Rewrite Not affectedThe dependency analysis in this PR stands regardless of which option is chosen. |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Unblocking this — the failure is the trailers guard, not the diff
The guard cannot distinguish that from a human co-authorship claim, so a sync carrying dependabot commits can never pass — which means security fixes strand on #13726 narrows the guard to skip bot-authored commits — scoped to the author, not the trailer text, so a human commit carrying Once #13726 lands, this needs an update-from-base and a re-run; no changes to the sync itself. The remaining Deliberately not done: rewriting the three commits to strip trailers. That would rewrite dependabot's authorship on security bumps and break SHA parity with |
Important
Merge this with a merge commit, not squash. The whole point is to make
mainan ancestor ofDev_new_gui. Squashing discards the second parent, andSync Dev_new_gui → mainwill refuse exactly as it does today.Thinking Path
Sync Dev_new_gui → mainfailed on dispatch:mainis 194 commits behind and 4 ahead. The four are dependabot merges #13515, #13523, #13524 plus a merge commit. Dependabot opens against the repository default branch —main— while every other PR targetsDev_new_gui, so dependency updates land where nobody develops and the sync jams.My first read was that main's bumps were entirely superseded, because
Dev_new_guileads on all 28 differing direct dependencies inautobot-frontend/package.jsonandautobot-slm-frontend/package.json, and onautobot-slm-backend/requirements.txt(fastapi>=0.141.1vs0.140.1).That was wrong, and worth stating plainly: the dependabot security bumps were in transitive lock entries, not direct dependencies. Comparing
package-lock.jsonrather thanpackage.jsonshowed main genuinely ahead on four packages, pluscryptography.What Changed
A real merge of
origin/mainintoDev_new_gui. Conflicts inautobot-frontend/package.json,autobot-frontend/package-lock.json,requirements-ci/security.txt, all resolved toDev_new_gui's side, then main's genuine upgrades applied on top:cryptographyfast-urihonoundicinanoidnanoidis the one that needed care: it lives inautobot-frontend/package-lock.json, which I had resolved with--ours. That silently discarded the bump. It is restored here by copying main'sversion/resolved/integritytriple.Dev_new_gui'sPyJWT[crypto]>=2.8.0line from #13411 is preserved — main does not have it.Verification
The decisive check, across every
package-lock.jsonin the repository:Merge commit has two parents, so
mainbecomes an ancestor:Direct-dependency comparison that produced the initial (incorrect) read, kept here because it is still true and still relevant —
Dev_new_guileads on all 28:After this
The sync is unblocked once. Dependabot will target
mainagain on its next security update and the divergence returns. #13654 lists the three options — pointing dependabot atDev_new_gui, changing the default branch, or scheduling the sync — and notes that changing the default branch would also fix the misleading "20 vulnerabilities on the default branch" banner, at the cost of alteringCloses #Nbehaviour this project already works around.Model Used
Opus 5
Closes #13654