Repository navigation
fix(deps): clear the devalue advisories and catch up on dependencies - #45
Merged
Merged
Conversation
`bun audit --production` exits 1 on devalue 5.9.2, which astro 7.3.4 pulls transitively through its `^5.8.1` range, for GHSA-j22f-vq7h-c4qm, GHSA-mcm9-63f2-9j32, GHSA-x5rw-q4pp-hg5g (high) and three lower advisories. 5.9.4 is inside that range, so a lockfile refresh clears it without an override. The refresh also corrects the stale `packages/collector` version the lockfile still carried at 0.4.0.
Dependabot cannot land the bump itself: it cannot rewrite the bun.lock v3 lockfile (dependabot-core#16071), so its own pull request stays red.
oxlint runs clean at 1.86.0 under the ultracite anti-slop preset, so no rule needed disabling. Same reason as the commitlint bump: Dependabot cannot write the bun.lock v3 lockfile (dependabot-core#16071).
The context file still described the linter at the version the bump replaced.
`wrangler deploy --dry-run` and the wrangler types check pass at 4.147.0, and the miniflare undici override still resolves. Same reason as the other bumps: Dependabot cannot write the bun.lock v3 lockfile (dependabot-core#16071).
The reviewed golden moves with it: the negative fixture that mutates the SHA still proves an unreviewed commit fails, and the appended-second-deploy-step fixture now carries the reviewed SHA so the extra step is the only reason it can be rejected. v4.0.0..v4.1.3 holds two changes beyond release plumbing: - v4.1.0 (minor, PR #450, 9500699 plus fixups, 429a99d, d3cfe74) adds Workers Previews. That branch is only entered when the command starts with preview and takes no argument, so it is unreachable for the "deploy" command this workflow passes; it adds the preview-url, preview-deployment-url, preview-name, preview-id and preview-deployment-id outputs. - v4.1.0 (patch, PR #418, 789ac84) logs wrangler's stderr before rethrowing when a command fails, instead of surfacing only the generic exec failure. That only changes failure diagnostics, and GitHub masks secrets in logs. Everything else is release plumbing: Changesets and immutable-release ordering, floating-tag verification, a Prettier catch-up, v3-to-v4 doc references, action.yml descriptions and the compiled dist/index.mjs.
This was referenced Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Clears the
devalueadvisories that makebun run audit:productionfail onmainand lands the dependency bumps Dependabot cannot. Verified on30169d918d14c8f3d26c373381492fab271b1063.Why main is red
bun audit --productionexits 1 ondevalue@5.9.2, pulled transitively byastro@7.3.4 > devalue:Nothing changed in this repo; new advisories were published against
<=5.9.2, so every CI rerun went red.Bumps
devalueastro@commitlint/config-conventionaloxlintwranglerapps/workercloudflare/wrangler-actionebbaa15(v4.0.0)953926a(v4.1.3).github/workflows/ci.ymlastro@7.3.4declaresdevalue: ^5.8.1and 5.9.4 is inside that range, sobun update devalueresolves it and the audit goes clean without a rootoverridesentry. The lockfile refresh also corrects a stale field it already carried:packages/collector.versionwas pinned at0.4.0whilepackage.jsonsaid0.5.0.bun pm ls --all | grep devalueis nowdevalue@5.9.4.Dependabot could not land any of these: it cannot rewrite the
bun.lockv3 lockfile (dependabot-core#16071), so its pull requests stay stale. They are untouched by this PR.oxlint1.86.0 runs clean under the ultracite anti-slop preset, so no rule was disabled.wrangler-action review: v4.0.0
ebbaa15-> v4.1.3953926aTwo changes beyond release plumbing.
9500699plus fixups,429a99d,d3cfe74) adds Workers Previews. The branch is only entered whencommandstarts withpreviewand takes no argument, so it is unreachable for thecommand: deploythis workflow passes. It adds thepreview-url,preview-deployment-url,preview-name,preview-idandpreview-deployment-idoutputs, plus a GitHub Deployment and job summary for previews.789ac84) logs wrangler's stderr before rethrowing when a command fails, instead of surfacing only the generic exec failure. This does touch the deploy step, but only when it fails, and only its diagnostics.Everything else is release plumbing: Changesets and immutable-release ordering (
7e340a9,876f5b5,ecefb49,d7fd981,5fa9855, the Version Packages commits), floating-tag verification, a Prettier catch-up, v3-to-v4 doc references,action.ymldescriptions and the compileddist/index.mjs.Reviewed and approved before pinning.
The golden in
scripts/ci-deploy-jobs.test.tsmoves with the pin. The negative fixture that flips the last hex character of the SHA still proves an unreviewed commit fails, and the appended-second-deploy-step fixture now carries the reviewed SHA so the extra step is the only reason it can be rejected. Mutation-probed: reverting the golden constant to another SHA turns the suite red.Gates
All run on
30169d918d14c8f3d26c373381492fab271b1063, in CI's order.bun install --frozen-lockfileChecked 544 installs across 702 packages (no changes)printf '%s' '<PR title>' | bunx commitlintbun run formatChecked 96 files in 32ms. No fixes applied.bun run lint:slopbun run check-types30 files,0 errors, 0 warnings, 0 hints; collectorExited with code 0bun run test16 files, 212 tests passed; collector12 files, 140 tests passedbun run test:dependency-policy68 pass, 0 fail, 316 expect() callsbun run test:package1 file, 1 test passedbun run audit:productionNo vulnerabilities found (checked 408 packages)- exit 0bun run buildComplete!- exit 0Commits
No merge, no auto-merge.