Skip to content

chore(deps-dev): bump @unbrained/pm-cli from 2026.9.26 to 2026.10.1 - #129

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.9.30
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.9.30

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @unbrained/pm-cli from 2026.9.26 to 2026.10.1.

Release notes

Sourced from @​unbrained/pm-cli's releases.

v2026.10.1

@​unbrained/pm-cli 2026.10.1

Source range: v2026.9.30...v2026.10.1

Changelog

Fixed

  • Control native effort in the history/activity provenance fixture (pm-6jvz55)
  • GH-1351: leaf get advertises empty children as omitted (pm-x8jdt8)
  • GH-1349: Bun 1.3.5 merge installer accepts a transient launcher (pm-aaxq4n)

Security

  • Scorecard alert 29: patch new brace-expansion recursion and rewrite denial-of-service advisories (pm-cbzvgn)

PM Tracker Evidence

Closed pm items in release window: 4 By type: Issue=4 By status: closed=4

Selected release-related tracker items:

  • No release-tagged pm items found in the selected window.

v2026.9.30

@​unbrained/pm-cli 2026.9.30

Source range: v2026.9.29...v2026.9.30

Changelog

Fixed

  • Registry install acceptance loses subprocess timeout and signal evidence and labels every failure as registry availability (pm-q7c36n)
  • Bun merge-driver installation disagrees with strict health (pm-vks66s)
  • Expose host-bound audited workspace settings mutation to extension commands (pm-wtqltn)
  • Full-item stdin JSON update silently ignores edited notes (pm-2589e6)

PM Tracker Evidence

Closed pm items in release window: 4 By type: Issue=4 By status: closed=4

Selected release-related tracker items:

  • No release-tagged pm items found in the selected window.

v2026.9.29

... (truncated)

Changelog

Sourced from @​unbrained/pm-cli's changelog.

2026.10.1 - 2026-10-01

Fixed

  • Control native effort in the history/activity provenance fixture (pm-6jvz55)
  • GH-1351: leaf get advertises empty children as omitted (pm-x8jdt8)
  • GH-1349: Bun 1.3.5 merge installer accepts a transient launcher (pm-aaxq4n)

Security

  • Scorecard alert 29: patch new brace-expansion recursion and rewrite denial-of-service advisories (pm-cbzvgn)

2026.9.30 - 2026-09-30

Fixed

  • Registry install acceptance loses subprocess timeout and signal evidence and labels every failure as registry availability (pm-q7c36n)
  • Bun merge-driver installation disagrees with strict health (pm-vks66s)
  • Expose host-bound audited workspace settings mutation to extension commands (pm-wtqltn)
  • Full-item stdin JSON update silently ignores edited notes (pm-2589e6)

2026.9.29 - 2026-09-29

Fixed

  • GH-1340: pm duplicates treats UTF-8 prose as a 0.99 issue-code match (pm-1ieq24)
  • Persist revised linked evidence notes while preserving idempotent retries (pm-zqxlfs)
  • Bound Plan mutation receipts while preserving full inspection (pm-hqy7lr)

Deprecated

  • Alias-usage counters: measure deprecated-spelling hits so grammar-freeze removals are evidence-based (pm-0mox)
  • Extension activation attributes canonical full-list projection to deprecated --full (pm-8uwigr)

Other

  • Replay each history state once: reuse the previous entry's digest as the next before-hash, stop at the first matching hash epoch, and drop the second document clone (pm-hen0t6)

2026.9.28 - 2026-09-28

Fixed

  • Allow self-isolating linked package tests without inherited PM_PATH (pm-t05d8d)
  • Preserve every tracker merge fence during nested init and detect lost active mappings (pm-kynkl8)
  • GH-1325: history diff cursor drops newest rows and strands the final page (pm-c3aiik)
  • Windows nightly merge-receipt classification test exceeds 60-second budget (pm-v0600g)
  • GH-1327: Windows nightly static inventory unreadable-source assertion fails (pm-ft90q2)
  • GH-1326: Windows nightly bundled-package init test exceeds 30 seconds (pm-kvhnb5)
  • MCP detached task completion coverage can miss cleanup under hosted shards (pm-tm6h9x)
  • Full coverage refusal-closure retry test exceeds its four-minute budget under suite contention (pm-mrrci4)

... (truncated)

Commits
  • 89b4aa8 chore(release): cut 2026.10.1
  • 1e7ecc1 fix: stabilize Bun merge, context reads and dependency security (#1353)
  • 344aa7b chore(release): cut 2026.9.30
  • d56cae9 Merge pull request #1350 from unbraind/fix/release-origin-and-install-diagnos...
  • d28153f fix(release): keep dispatcher timing separate from native cron
  • dc9b60e fix(release): recognize Bun registry 404 diagnostics
  • 1d2443f fix(release): preserve exact-tag recovery and complete redaction
  • 1a4ab2f fix(release): preserve install failure evidence and attribute daily dispatches
  • bbfa428 Audit extension settings and item JSON updates; repair Bun merge drivers (#1348)
  • db52e3f chore(release): cut 2026.9.29
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 4, 2026
@greptile-apps

greptile-apps Bot commented Oct 4, 2026

Copy link
Copy Markdown

PR author is in the excluded authors list.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 70eab7b3-fa73-4353-94a6-9d4b471fb8df

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dependabot dependabot Bot changed the title chore(deps-dev): bump @unbrained/pm-cli from 2026.9.23 to 2026.9.30 chore(deps-dev): bump @unbrained/pm-cli from 2026.9.26 to 2026.10.1 Oct 4, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/unbrained/pm-cli-2026.9.30 branch from f2b62aa to a4cb7cb Compare October 4, 2026 08:26
Bumps [@unbrained/pm-cli](https://github.com/unbraind/pm-cli) from 2026.9.26 to 2026.10.1.
- [Release notes](https://github.com/unbraind/pm-cli/releases)
- [Changelog](https://github.com/unbraind/pm-cli/blob/main/CHANGELOG.md)
- [Commits](unbraind/pm-cli@v2026.9.26...v2026.10.1)

---
updated-dependencies:
- dependency-name: "@unbrained/pm-cli"
  dependency-version: 2026.9.30
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Superseded by #131, which carries this update together with the PM CLI 2026.10.4 certification.

unbraind added a commit that referenced this pull request Oct 4, 2026
…cy updates (#131)

* Certify pm-beads on PM CLI 2026.10.4 and consolidate pending dependency updates

Pin @unbrained/pm-cli to 2026.10.4 (supersedes Dependabot #129, which
proposed 2026.10.1) and pm-ops to 2026.10.4 (supersedes #127, which proposed
2026.9.29), bump the @types/node lockfile to 26.6.4 (newer than #126), and
pin the codeql-action SHAs to 2892aa5e (#125). pm-changelog stays 2026.9.25
(latest npm). Both npm audit and npm audit --omit=dev are clean; no open
Dependabot security alerts.

Re-copy scripts/prepare-merge-driver.ts byte-identical from the pm-ops
2026.10.4 template: its presence probe now fails closed when a lookup path
is unreadable (EACCES/EPERM/ENOTDIR/ELOOP) instead of treating an uncertain
probe as an omit-dev install (pm-ops #136). Add the matching fail-closed
regression so the launcher keeps full coverage.

Track the 2026.10.4 certification round in pm-beads-8h18 (pm-github managed
extension installed at 2026.10.4 with a clean read-only sync dry-run).

* Pin the complete certification toolchain and record fresh real-tracker acceptance

* Record review handoff and release certification ownership

---------

Co-authored-by: SteveBot <1153461+unbraind@users.noreply.github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Looks like @unbrained/pm-cli is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 4, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/unbrained/pm-cli-2026.9.30 branch October 4, 2026 11:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant