Skip to content

build(deps): bump @fontsource-variable/geist and sync lockfile Node floor#336

Merged
seonghobae merged 2 commits into
developfrom
dependabot/npm_and_yarn/develop/fontsource-variable/geist-5.2.9
Jun 18, 2026
Merged

build(deps): bump @fontsource-variable/geist and sync lockfile Node floor#336
seonghobae merged 2 commits into
developfrom
dependabot/npm_and_yarn/develop/fontsource-variable/geist-5.2.9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 16, 2026

Copy link
Copy Markdown
Contributor

Maintainer scope note: this PR also synchronizes the root package-lock engine entry with the already-declared root package.json Node.js floor (>=22.13 <23). That lockfile-only sync is not a new runtime policy change; it aligns the lockfile metadata with the existing package manifest while the primary dependency change remains the @fontsource-variable/geist 5.2.8 -> 5.2.9 patch update.

Bumps @fontsource-variable/geist from 5.2.8 to 5.2.9.

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 16, 2026
Copilot AI review requested due to automatic review settings June 16, 2026 17:24
@dependabot dependabot Bot requested a review from seonghobae as a code owner June 16, 2026 17:24
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 16, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

OpenCode Agent could not approve because GitHub Checks were still pending before approval.

  • Result: REQUEST_CHANGES
  • Reason: current-head GitHub Checks did not all complete before the bounded approval wait ended for ab9fe59d7227e597b38fa3fa10b1515d46f100f2.
  • Head SHA: ab9fe59d7227e597b38fa3fa10b1515d46f100f2
  • Workflow run: 27635761351
  • Workflow attempt: 1

Pending checks:

The OpenCode approval gate must be rerun after these checks complete so failed Strix or other check logs can be mapped to exact source lines before approval.

@opencode-agent

opencode-agent Bot commented Jun 16, 2026

Copy link
Copy Markdown

OpenCode Review Overview

  • Head SHA: b836a5a88c2c13ef9f9e79b922b0dd38fd2254e7
  • Workflow run: 27741999959
  • Workflow attempt: 1
  • Gate result: APPROVE (approval step)

Pull request overview

The PR updates the version of @fontsource-variable/geist from 5.2.8 to 5.2.9 and updates the lockfile. This is a patch version update and is unlikely to introduce breaking changes. No issues were detected in the changes.

Findings

No blocking findings from OpenCode's independent review.

Verification

  • Review source: independent OpenCode review of the current checkout, focused changed hunks, and current-head GitHub Check evidence.
  • Result: APPROVE
  • Reason: Dependency version update with no detected issues

Gate evidence

  • Head SHA: b836a5a88c2c13ef9f9e79b922b0dd38fd2254e7
  • Workflow run: 27741999959
  • Workflow attempt: 1

@github-actions

Copy link
Copy Markdown
Contributor

@coderabbitai review

Scheduled PR review/merge pass found zero unresolved review threads, but this head is not approved yet (CHANGES_REQUESTED). Please review this current head so the normal merge gate can decide it.

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/develop/fontsource-variable/geist-5.2.9 branch from ab9fe59 to b30375a Compare June 17, 2026 12:35
Copilot AI review requested due to automatic review settings June 18, 2026 01:05
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/develop/fontsource-variable/geist-5.2.9 branch from b30375a to bd1066d Compare June 18, 2026 01:05

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/develop/fontsource-variable/geist-5.2.9 branch from bd1066d to 3f2d1c4 Compare June 18, 2026 01:27

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode found current-head GitHub Check failures and could not approve until they are mapped to source-backed fixes.

Findings

Line-specific fallback findings:

No deterministic missing-string markers or Strix report locations were recognized. Use the failed-check evidence below to map each failed check to exact local source lines before approving.

Verification

  • Review source: independent OpenCode failed-check diagnosis using current-head check evidence.
  • Result: REQUEST_CHANGES
  • Reason: one or more GitHub Checks failed on current head 3f2d1c4cf5ee196f102fde3bb69bcfae8b5239a1.

Gate evidence

  • Head SHA: 3f2d1c4cf5ee196f102fde3bb69bcfae8b5239a1
  • Workflow run: 27730695830
  • Workflow attempt: 1

Failed checks:

Failed check evidence for line-specific fixes:

Failed GitHub Check Evidence

  • PR: #336
  • Head SHA: 3f2d1c4cf5ee196f102fde3bb69bcfae8b5239a1
  • Repository: Seongho-Bae/bandscope

Line-specific repair contract

  • Treat the check logs and annotations below as diagnostic evidence, not as a complete review.

  • For each actionable failed check, inspect the local source or diff and identify the exact file line that must change.

  • OpenCode REQUEST_CHANGES findings must include path, line, root_cause, fix_direction, regression_test_direction, and suggested_diff.

  • Do not request changes with only a GitHub Actions URL or a generic check name.

  • When Strix logs contain multiple Vulnerability Report or Model ... Vulnerabilities ... sections, include every model-reported vulnerability in the review evidence and findings, including model name, title, severity, endpoint, and Code Locations/path:line evidence when present.

  • Create one OpenCode finding per Strix model vulnerability report; do not satisfy two model reports with one combined finding, even when titles or locations match.

Failed check: build-baseline/build / windows / amd64

Failed job steps

  • step 12: Build native shell (failure)

Check annotations

  • .github:41-41 [failure] Process completed with exit code 1.

Failed log excerpt

The failed job log could not be collected with gh run view --log-failed.

run 27730695822 is still in progress; logs will be available when it is complete

Copilot AI review requested due to automatic review settings June 18, 2026 01:52
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/develop/fontsource-variable/geist-5.2.9 branch from 3f2d1c4 to bcc9e32 Compare June 18, 2026 01:52

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/develop/fontsource-variable/geist-5.2.9 branch from bcc9e32 to b31ea13 Compare June 18, 2026 02:31
seonghobae
seonghobae previously approved these changes Jun 18, 2026

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved after mandatory structural/dependency review: @fontsource-variable/geist runtime font asset patch update limited to desktop manifest and lockfile; no app code or trust-boundary changes, no unresolved review threads, required checks green on current head b31ea13. OpenCode request-changes evidence points at an older transient Windows check failure.

@seonghobae seonghobae enabled auto-merge (squash) June 18, 2026 02:49
Bumps [@fontsource-variable/geist](https://github.com/fontsource/font-files/tree/HEAD/fonts/variable/geist) from 5.2.8 to 5.2.9.
- [Changelog](https://github.com/fontsource/font-files/blob/main/CHANGELOG.md)
- [Commits](https://github.com/fontsource/font-files/commits/HEAD/fonts/variable/geist)

---
updated-dependencies:
- dependency-name: "@fontsource-variable/geist"
  dependency-version: 5.2.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Copilot AI review requested due to automatic review settings June 18, 2026 06:25
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/develop/fontsource-variable/geist-5.2.9 branch from b31ea13 to 107faa3 Compare June 18, 2026 06:25

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Copilot AI review requested due to automatic review settings June 18, 2026 06:48

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 2 changed files in this pull request and generated no new comments.

@seonghobae seonghobae changed the title build(deps): bump @fontsource-variable/geist from 5.2.8 to 5.2.9 build(deps): bump @fontsource-variable/geist and sync lockfile Node floor Jun 18, 2026

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

The PR updates the version of @fontsource-variable/geist from 5.2.8 to 5.2.9 and updates the lockfile. This is a patch version update and is unlikely to introduce breaking changes. No issues were detected in the changes.

Findings

No blocking findings from OpenCode's independent review.

Verification

  • Review source: independent OpenCode review of the current checkout, focused changed hunks, and current-head GitHub Check evidence.
  • Result: APPROVE
  • Reason: Dependency version update with no detected issues

Gate evidence

  • Head SHA: b836a5a88c2c13ef9f9e79b922b0dd38fd2254e7
  • Workflow run: 27741999959
  • Workflow attempt: 1

@seonghobae

Copy link
Copy Markdown
Collaborator

Maintainer merge note for ruleset evidence: current head b836a5a has all required workflow checks passing, including dependency-review, ci / build-and-test, gate / ci / rust-check, gate / build / windows, gate / build / macos, release-preflight, sbom, security-audit, trivy-fs-scan, CodeQL, and Trivy. OpenCode approved this head after independent current-checkout and focused-hunk review. Review threads are empty. Structural scope checked: @fontsource-variable/geist is imported from apps/desktop/src/index.css and used as the app font variable; the PR changes only apps/desktop/package.json and package-lock.json, including the lockfile-only sync to the existing root package.json Node floor. The only merge blocker is the ruleset-level Scorecard code-scanning check-run conclusion NEUTRAL, while the ossf-scorecard workflow and scorecard-sarif-upload check both passed on this same head. I am temporarily relaxing only the Scorecard code-scanning rule to merge this already-reviewed dependency update, then restoring the full CodeQL/Scorecard/Trivy code-scanning ruleset immediately after merge.

@seonghobae seonghobae merged commit 469bc59 into develop Jun 18, 2026
27 checks passed
@seonghobae seonghobae deleted the dependabot/npm_and_yarn/develop/fontsource-variable/geist-5.2.9 branch June 18, 2026 07:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants