Repository navigation
chore(deps): carry dependabot's npm security bumps onto Dev_new_gui (hono 4.13.7 and transitive; supersedes #16171) - #16408
Conversation
…-chromium, hono, joi, node-releases, @redocly/openapi-core in autobot-frontend, mcp-structured-thinking, mcp-autobot-tracker, libs/autobot-sdk-ts (supersedes #16171) Applies the subset of dependabot commit 7dc04e3 that was still behind origin/Dev_new_gui, per lockfile node (version/resolved/integrity only): - autobot-frontend: @redocly/openapi-core 1.34.18->1.34.20, baseline-browser-mapping 2.11.20->2.11.21, browserslist 4.28.7->4.28.9, electron-to-chromium 1.5.419->1.5.426, joi 18.2.3->18.2.8, node-releases 2.0.54->2.0.55 - mcp-structured-thinking: baseline-browser-mapping 2.11.20->2.11.21, browserslist 4.28.8->4.28.9, electron-to-chromium 1.5.420->1.5.426, hono 4.13.0->4.13.7, node-releases 2.0.54->2.0.55 - mcp-autobot-tracker: hono 4.13.0->4.13.7 - libs/autobot-sdk-ts: baseline-browser-mapping 2.11.20->2.11.21, browserslist 4.28.7->4.28.9, electron-to-chromium 1.5.419->1.5.426, node-releases 2.0.54->2.0.55 autobot-slm-frontend already had fast-uri 3.1.7 (dependabot's target); no change. fast-uri, qs, js-yaml, caniuse-lite, es-object-atoms, hasown, side-channel(-list), update-browserslist-db were already at or above dependabot's target in every directory and were skipped. package.json overrides (js-yaml, qs) were already at the bumped constraint in every directory that has one.
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
… and openapi-core bumps (#16171)
|
CI red: Fix: add a line the check accepts, e.g.: That satisfies the linkage textually without implying #16171 needed fixing as an issue. |
|
Content review: approve. Pure lockfile bump (hono 4.13.0→4.13.7 + transitive deps across 4 package-lock.json files), no source changes. closingIssuesReferences=[] matches body (Refs #16171 only, no Closes). Ready. |
Refs #16171 (dependabot's original npm security bump, superseded by this PR and closed).
Supersedes #16171 (dependabot's security update, which targets
main; PRs here targetDev_new_gui).Single-issue rationale: this carries one dependabot security update onto the branch PRs actually target. Its scope is exactly that update's lockfiles.
Thinking Path
Dependabot security updates always target the default branch (
main), whatevertarget-branchsays, so #16171 couldn't ride theDev_new_guitrains. Each package dependabot bumped was compared withDev_new_gui's lockfile, and only those still behind were brought up.What Changed
.mcp:hono4.13.0 → 4.13.7 (GHSA-hxh3-vqpv-xpqv, GHSA-crvj-82cr-hjcx, GHSA-gqvv-2mrq-wpjv, GHSA-g6gw-c38x-mqfc).fast-uriandqswere already fixed onDev_new_gui.mcp-structured-thinkingandmcp-autobot-trackergethono4.13.0 → 4.13.7, plus dependabot's transitive bumps (browserslist,electron-to-chromium,node-releasesandbaseline-browser-mapping).autobot-frontendgetsjoi18.2.3 → 18.2.8,@redocly/openapi-core1.34.18 → 1.34.20, and the same transitive bumps.libs/autobot-sdk-tsgets the same transitive bumps.autobot-slm-frontendwas already at target, so it's unchanged.7dc04e3a3. Nothing was hand-computed or installed.Verification
Dev_new_gui, dependabot, and applied or skipped; it's in the implementation report.npm installwas run locally, and CI'snpm ciplus the audit gates are the real check..github/workflows/security.ymlis untouched: chore(deps): bump the npm_and_yarn group across 6 directories with 7 updates #16171's allowance edit belonged tomain.Model Used
Claude Opus 5 as coordinator; devops-engineer subagents on Sonnet.
🤖 Generated with Claude Code