Skip to content

chore(deps-dev): bump @unbrained/pm-cli from 2026.9.29 to 2026.10.1 - #138

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.10.1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.10.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @unbrained/pm-cli from 2026.9.29 to 2026.10.1.

Release notes

Sourced from @​unbrained/pm-cli's releases.

v2026.10.1

@​unbrained/pm-cli 2026.10.1

Source range: v2026.9.30...v2026.10.1

Changelog

Fixed

  • Control native effort in the history/activity provenance fixture (pm-6jvz55)
  • GH-1351: leaf get advertises empty children as omitted (pm-x8jdt8)
  • GH-1349: Bun 1.3.5 merge installer accepts a transient launcher (pm-aaxq4n)

Security

  • Scorecard alert 29: patch new brace-expansion recursion and rewrite denial-of-service advisories (pm-cbzvgn)

PM Tracker Evidence

Closed pm items in release window: 4 By type: Issue=4 By status: closed=4

Selected release-related tracker items:

  • No release-tagged pm items found in the selected window.

v2026.9.30

@​unbrained/pm-cli 2026.9.30

Source range: v2026.9.29...v2026.9.30

Changelog

Fixed

  • Registry install acceptance loses subprocess timeout and signal evidence and labels every failure as registry availability (pm-q7c36n)
  • Bun merge-driver installation disagrees with strict health (pm-vks66s)
  • Expose host-bound audited workspace settings mutation to extension commands (pm-wtqltn)
  • Full-item stdin JSON update silently ignores edited notes (pm-2589e6)

PM Tracker Evidence

Closed pm items in release window: 4 By type: Issue=4 By status: closed=4

Selected release-related tracker items:

  • No release-tagged pm items found in the selected window.
Changelog

Sourced from @​unbrained/pm-cli's changelog.

2026.10.1 - 2026-10-01

Fixed

  • Control native effort in the history/activity provenance fixture (pm-6jvz55)
  • GH-1351: leaf get advertises empty children as omitted (pm-x8jdt8)
  • GH-1349: Bun 1.3.5 merge installer accepts a transient launcher (pm-aaxq4n)

Security

  • Scorecard alert 29: patch new brace-expansion recursion and rewrite denial-of-service advisories (pm-cbzvgn)

2026.9.30 - 2026-09-30

Fixed

  • Registry install acceptance loses subprocess timeout and signal evidence and labels every failure as registry availability (pm-q7c36n)
  • Bun merge-driver installation disagrees with strict health (pm-vks66s)
  • Expose host-bound audited workspace settings mutation to extension commands (pm-wtqltn)
  • Full-item stdin JSON update silently ignores edited notes (pm-2589e6)
Commits
  • 89b4aa8 chore(release): cut 2026.10.1
  • 1e7ecc1 fix: stabilize Bun merge, context reads and dependency security (#1353)
  • 344aa7b chore(release): cut 2026.9.30
  • d56cae9 Merge pull request #1350 from unbraind/fix/release-origin-and-install-diagnos...
  • d28153f fix(release): keep dispatcher timing separate from native cron
  • dc9b60e fix(release): recognize Bun registry 404 diagnostics
  • 1d2443f fix(release): preserve exact-tag recovery and complete redaction
  • 1a4ab2f fix(release): preserve install failure evidence and attribute daily dispatches
  • bbfa428 Audit extension settings and item JSON updates; repair Bun merge drivers (#1348)
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 4, 2026
@greptile-apps

greptile-apps Bot commented Oct 4, 2026

Copy link
Copy Markdown

PR author is in the excluded authors list.

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 71d6c071-f515-4557-896b-47eceabfc470

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dependabot dependabot Bot changed the title chore(deps-dev): bump @unbrained/pm-cli from 2026.9.27 to 2026.10.1 chore(deps-dev): bump @unbrained/pm-cli from 2026.9.28 to 2026.10.1 Oct 4, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/unbrained/pm-cli-2026.10.1 branch from 9554aad to 11459ca Compare October 4, 2026 08:21
@dependabot dependabot Bot changed the title chore(deps-dev): bump @unbrained/pm-cli from 2026.9.28 to 2026.10.1 chore(deps-dev): bump @unbrained/pm-cli from 2026.9.29 to 2026.10.1 Oct 4, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/unbrained/pm-cli-2026.10.1 branch from 11459ca to 65cd925 Compare October 4, 2026 08:35
Bumps [@unbrained/pm-cli](https://github.com/unbraind/pm-cli) from 2026.9.29 to 2026.10.1.
- [Release notes](https://github.com/unbraind/pm-cli/releases)
- [Changelog](https://github.com/unbraind/pm-cli/blob/main/CHANGELOG.md)
- [Commits](unbraind/pm-cli@v2026.9.29...v2026.10.1)

---
updated-dependencies:
- dependency-name: "@unbrained/pm-cli"
  dependency-version: 2026.10.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@unbraind

unbraind commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Superseded by #142, which carries this update together with the PM CLI 2026.10.4 certification.

unbraind added a commit that referenced this pull request Oct 4, 2026
… updates

Pin @unbrained/pm-cli to 2026.10.4 (supersedes Dependabot #138), bump
@babel/eslint-parser to 8.0.6 (#126), jscpd to 5.4.0 (#139), @types/node
lockfile to 26.6.4 (newer than #137), and pin the codeql-action SHAs to
2892aa5e (#127). Fix Dependabot security alert #3 by resolving
brace-expansion to 5.0.12; npm audit --omit=dev is clean.

jscpd 5.4.0 sums overlapping clone spans into duplicatedLines, which the
fail-closed jscpd-5 report validation rejected as impossible counts at the
one-token completeness floor. parseJscpdReport now validates each clone span
against the scanned total and duplicatedLines against the sum of reported
clone spans, keeping the gate fail-closed while adopting the new accounting.

Track the certification in ops-hiee (pm-github managed extension installed at
2026.9.26 with a clean read-only sync dry-run preview).
unbraind added a commit that referenced this pull request Oct 4, 2026
… updates (#142)

* Certify pm-ops on PM CLI 2026.10.4 and consolidate pending dependency updates

Pin @unbrained/pm-cli to 2026.10.4 (supersedes Dependabot #138), bump
@babel/eslint-parser to 8.0.6 (#126), jscpd to 5.4.0 (#139), @types/node
lockfile to 26.6.4 (newer than #137), and pin the codeql-action SHAs to
2892aa5e (#127). Fix Dependabot security alert #3 by resolving
brace-expansion to 5.0.12; npm audit --omit=dev is clean.

jscpd 5.4.0 sums overlapping clone spans into duplicatedLines, which the
fail-closed jscpd-5 report validation rejected as impossible counts at the
one-token completeness floor. parseJscpdReport now validates each clone span
against the scanned total and duplicatedLines against the sum of reported
clone spans, keeping the gate fail-closed while adopting the new accounting.

Track the certification in ops-hiee (pm-github managed extension installed at
2026.9.26 with a clean read-only sync dry-run preview).

* Keep the search evaluation file eligible for tracking

* Record review handoff and release certification ownership

---------

Co-authored-by: SteveBot <1153461+unbraind@users.noreply.github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Looks like @unbrained/pm-cli is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 4, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/unbrained/pm-cli-2026.10.1 branch October 4, 2026 12:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant