Lock file maintenance (main) - #3370
red-hat-konflux[bot] wants to merge 1 commit into
Conversation
|
🤖 Finished Review · ✅ Success · Started 4:49 AM UTC · Completed 4:58 AM UTC |
Codecov Report✅ All modified and coverable lines are covered by tests.
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
|
Looks good to me Previous runLooks good to me Previous run (2)Looks good to me Previous run (3)Looks good to me Previous run (4)Looks good to me Previous run (5)Looks good to me Previous run (6)ReviewFindingsInfo
Previous run (7)ReviewFindingsInfo
Previous run (8)Looks good to me Previous run (9)Looks good to me Previous run (10)Looks good to me Previous run (11)Looks good to me Previous run (12)Looks good to me Previous run (13)Looks good to me Previous run (14)Looks good to me Previous run (15)Looks good to me Previous run (16)Looks good to me Previous run (17)Looks good to me Previous run (18)Looks good to me Previous run (19)Looks good to me Previous run (20)Looks good to me Previous run (21)Looks good to me Previous run (22)Looks good to me Previous run (23)Review — ApproveLock file maintenance — 4 transitive dependency version bumps in
Supply chain verification
This PR contains two beneficial security updates. The "Possible security concern" label reflects that dependency updates warrant scrutiny — the review confirms these changes are safe and recommended. Previous run (24)Review — ApprovePR: #3370 — Lock file maintenance npm dependencies (main) SummaryAutomated lock file maintenance bumping four transitive npm dependencies to their latest versions:
Review dimensions
VerdictClean lock file maintenance. All dependency bumps are valid within their semver constraints, no structural changes to the dependency graph, and no security concerns. Safe to merge. Previous run (25)Review — ApprovePR: #3370 — Lock file maintenance npm dependencies (main) SummaryAutomated lockfile maintenance refreshing 4 transitive npm dependencies of
Security Assessment
Dimensional Coverage
This lockfile maintenance PR is safe to merge. The Previous run (26)Looks good to me Labels: Lock file maintenance PR updating npm dependencies fits the 'dependencies' label. Previous run (27)ReviewFindingsHigh
Low
Labels: PR contains a dependency version bump that requires manual verification for supply chain integrity |
976122f to
4cf619c
Compare
|
🤖 Finished Review · ✅ Success · Started 2:22 AM UTC · Completed 2:29 AM UTC |
4cf619c to
86252df
Compare
|
🤖 Finished Review · ✅ Success · Started 4:46 AM UTC · Completed 4:54 AM UTC |
86252df to
873507f
Compare
|
🤖 Finished Review · ✅ Success · Started 4:44 AM UTC · Completed 4:50 AM UTC |
873507f to
ec5a10d
Compare
|
🤖 Finished Review · ✅ Success · Started 2:17 AM UTC · Completed 2:23 AM UTC |
7567888 to
5351093
Compare
5351093 to
8520f95
Compare
928e680 to
5748476
Compare
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
5748476 to
ddf01ce
Compare
|
🤖 Review · Commit: |
Superseded by updated review
Superseded by updated review
This PR contains the following updates:
🔧 This Pull Request updates lock files to use the latest dependency versions.
Configuration
📅 Schedule: (UTC)
* 0-4 * * *)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.