Skip to content

security: lockfile-only dependency bumps - #1

Open
neocody wants to merge 1 commit into
mainfrom
security/dependabot-nested-lockfile-bumps
Open

security: lockfile-only dependency bumps#1
neocody wants to merge 1 commit into
mainfrom
security/dependabot-nested-lockfile-bumps

Conversation

@neocody

@neocody neocody commented Aug 18, 2026

Copy link
Copy Markdown
Owner

Lockfile-only dependency bumps generated by the mission console.

Manifest directories updated:

npm audit fix --package-lock-only was run in each directory that had open Dependabot alerts, including nested manifests that a root-level fix does not reach. No package.json version ranges were changed, so this cannot pull in a semver-major.

Review CI before merging.

npm audit fix --package-lock-only in each manifest directory carrying open Dependabot alerts. No package.json ranges changed.

@neocody neocody left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: nothing reviewable - every changed file is generated or vendored (lockfiles, build output, snapshots, planning docs), so no model review was run and pr-shepherd will not merge this.

Automated notice posted by pr-shepherd, which reviews every open PR once per head (Cody, 2026-09-12) -- this is not a signal that the PR looked stuck.

escalated: needs a human-approved session (reason: title mentions 'security')

Advice: a human-owned session should confirm the change is intended and merge it on green CI.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant