Skip to content

Lock file maintenance - #302

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/lock-file-maintenance
Sep 4, 2026
Merged

Lock file maintenance#302
renovate[bot] merged 1 commit into
mainfrom
renovate/lock-file-maintenance

Conversation

@renovate

@renovate renovate Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge September 4, 2026 20:54
@renovate
renovate Bot added this pull request to the merge queue Sep 4, 2026
Merged via the queue into main with commit efa032b Sep 4, 2026
3 checks passed
@renovate
renovate Bot deleted the renovate/lock-file-maintenance branch September 4, 2026 20:57
dunningdan added a commit that referenced this pull request Sep 7, 2026
#302 cleared 42 of 51 Dependabot alerts by refreshing yarn.lock, but 9
survive because re-resolution provably cannot reach them - their parents
either pin an exact version or cap below the patched release:

  minimatch             parent pins 9.0.3 exactly      -> 9.0.9
  yaml                  parent pins 2.8.1 exactly      -> 2.9.0
  serialize-javascript  parent caps at ^6.0.0          -> 7.1.1
  uuid                  parent caps at ^8.3.2          -> 11.1.1
  qs                    parent caps at ~6.15.1         -> 6.16.0

yarn resolutions are the only lever here, following the existing `got`
entry. This clears 9 of the 11 currently open alerts.

qs is the newest of these: GHSA for it was published Sep 2 and GitHub
raised alerts #197/#198 three minutes after #302 merged, against the
freshly refreshed lockfile. `~6.15.1` excludes 6.16.0, so no future
lockFileMaintenance pass would have fixed it either.

Remaining open after this: #186/#187 image-size, which has no patched
version published upstream. Reached via @docusaurus/mdx-loader at build
time only; tracked for risk acceptance rather than code change.

Verified on Node 24.20.0: yarn build passes (59 documents) and the dev
server serves HTTP 200, which exercises sockjs -> uuid@11, the one bump
here that crosses major versions and that a production build would not
otherwise cover.

Also refreshes the lockFileMaintenance description - it still told the
reader to restore a weekly schedule, which is no longer the intent. No
behavior change; schedule stays "at any time".

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants