security: lockfile-only dependency bumps - #1
Open
neocody wants to merge 1 commit into
Open
Conversation
npm audit fix --package-lock-only in each manifest directory carrying open Dependabot alerts. No package.json ranges changed.
neocody
commented
Sep 13, 2026
neocody
left a comment
Owner
Author
There was a problem hiding this comment.
Verdict: nothing reviewable - every changed file is generated or vendored (lockfiles, build output, snapshots, planning docs), so no model review was run and pr-shepherd will not merge this.
Automated notice posted by pr-shepherd, which reviews every open PR once per head (Cody, 2026-09-12) -- this is not a signal that the PR looked stuck.
escalated: needs a human-approved session (reason: title mentions 'security')
Advice: a human-owned session should confirm the change is intended and merge it on green CI.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Lockfile-only dependency bumps generated by the mission console.
Manifest directories updated:
npm audit fix --package-lock-onlywas run in each directory that had open Dependabot alerts, including nested manifests that a root-level fix does not reach. Nopackage.jsonversion ranges were changed, so this cannot pull in a semver-major.Review CI before merging.