Skip to content

deps: bump flatted from 3.3.3 to 3.4.2 - #59

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/flatted-3.4.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/flatted-3.4.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 21, 2026

Copy link
Copy Markdown
Contributor

Bumps flatted from 3.3.3 to 3.4.2.

Commits
  • 3bf0909 3.4.2
  • 885ddcc fix CWE-1321
  • 0bdba70 added flatted-view to the benchmark
  • 2a02dce 3.4.1
  • fba4e8f Merge pull request #89 from WebReflection/python-fix
  • 5fe8648 added "when in Rome" also a test for PHP
  • 53517ad some minor improvement
  • b3e2a0c Fixing recursion issue in Python too
  • c4b46db Add SECURITY.md for security policy and reporting
  • f86d071 Create dependabot.yml for version updates
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [flatted](https://github.com/WebReflection/flatted) from 3.3.3 to 3.4.2.
- [Commits](WebReflection/flatted@v3.3.3...v3.4.2)

---
updated-dependencies:
- dependency-name: flatted
  dependency-version: 3.4.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Mar 21, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@robotlearning123

Copy link
Copy Markdown
Member

Backlog-loop verification: checks/tests green except pre-existing base failures (delta: Failing checks at head vs base: head = 8 SUCCESS + 1 FAILURE (claude-review); base-equivalent = same single failure (claude-review FAILURE on PRs #61–#66, base=ce7da5b151) — identical, PR not worse. Local execution (head fe69f87 vs base ce7da5b, each in its own /tmp worktree): tests 57 pass / 0 fail at BOTH; typecheck=0 lint=0 format:check=0 test=0 at BOTH; npm ci exit 0 at BOTH; git status --porcelain = 0 entries at BOTH. npm audit: base = 19 vulns (1 low, 8 moderate, 10 high, 0 critical) incl. flatted high; head = 18 vulns (1 low, 8 moderate, 9 high, 0 critical) — the PR removes exactly 1 high (flatted, CWE-1321). PR strictly improves the baseline.). Independent review: APPROVE.

INDEPENDENT GROK REVIEW OF PR #59 — VERDICT: APPROVE (no findings). Reviewer model grok-4.7-build-fast (headless), writer was devin/dependabot — writer != reviewer satisfied.

RAW REVIEWER OUTPUT (verbatim, /tmp/loop-grok-pr59-review.log, 329 bytes, exit=0):
"VERDICT: APPROVE

No findings."
(Preceded in stdout by grok's progress notes: "Reviewing PR #59 against origin/main. The change is a Dependabot bump of indirect flatted 3.3.3 → 3.4.2; I'll read the lockfile diff and how the package is used.")

PINNED REF (three independent sources agree): refs/pull/59/head = fe69f87 (git ls-remote origin, gh pr view 59 headRefOid, local FETCH_HEAD after git fetch origin refs/pull/59/head). Head branch dependabot/npm_and_yarn/flatted-3.4.2, base main, state OPEN, REVIEW_REQUIRED, mergeable MERGEABLE.

WHAT THE PR CHANGES (my own read, git diff origin/main...HEAD, merge-base = ce7da5b = origin/main tip, branch has exactly 1 commit fe69f87): package-lock.json only, +6/-13 over 1 file. Content: flatted 3.3.3→3.4.2 (version/resolved/integrity, 3 lines), lockfile root "version" 0.1.0→0.2.0 (both occurrences; package.json is already 0.2.0 on BOTH sides, so the lock was stale), and peer-flag churn = 8 "peer": true removals + 1 addition (hono). flatted is a dev-only transitive: node_modules/flat-cache requires "flatted": "^3.2.9"; grok's install resolved chain eslint@9.39.2 → file-entry-cache@8.0.0 → flat-cache@4.0.1 → flatted@3.4.2.

REVIEW HAD POWER (grok actually executed, session 01a0cd3e-c3c9-7911-a6a3-1799a521f9cf, 1 turn, 13 model calls, 1,063,905 tokens; evidence = grok's terminal call logs under ~/.grok/sessions/%2Ftmp%2Floop-wt-agent-next_agent-ready-pr59/):

  • read the real diff against origin/main (not the description) and HEAD/commit log;
  • npm view flatted for 3.4.2 vs 3.3.3 dist.integrity/tarball from the live registry;
  • performed a real lockfile install in a scratch copy (/tmp/flatted-ci-pr59): "added 326 packages in 1s", installed flatted = 3.4.2, npm ls flatted resolved cleanly (no ERESOLVE/peer conflict);
  • checked upstream tags/commits after 3.4.2 (v3.4.3, v3.4.4 exist; later fixes are unrelated);
  • attributed the non-flatted churn by regenerating main's lock with npm 10.9.4 and matching the identical version+peer key deltas — i.e. judge-call "lockfile-regeneration artifact, not a hand edit".

MY INDEPENDENT SPOT-CHECKS (execution, not agreement-by-association): lockfile integrity for flatted@3.4.2 sha512-PjDse7RzhcPkIJwy5t7KPWQSZ9cAbzQXcafsetQoD7sOJRQlGikNbx7yZp2OotDnJyrDcbyRq3Ttb18iYOqkxA== matches npm view flatted@3.4.2 dist.integrity exactly; churn counts confirmed (grep -c: 8 removals / 1 addition of peer:true); gh-reported PR file count (+6/-13, package-lock.json only) matches my computed diff exactly, confirming local origin/main == reviewer base.

SCOPE-CREEP NOTE (labeled, not a grok finding): the diff is wider than "bump flatted" — it also carries the version-sync and npm peer-flag churn above. Grok judged this not worth a finding; I record it as an unverified-but-plausible cosmetic artifact (plausible because grok reproduced the same deltas from an npm-10.9.4 regeneration of main and package.json is 0.2.0 on both sides). No test was added — none is applicable to a lockfile-only dev-transitive bump; the honest oracle for this class is the lockfile installing, which grok ran. claude-review is noted broken repo-wide (baseline-delta), so no CI signal was available — CI status was NOT used as evidence here.

DEVIATIONS (conservative option taken each time): (1) step 1 assumed /tmp/loop-wt-agent-next_agent-ready-pr59 existed — it did not, so I created it fresh per the safety contract: git worktree add --detach <path> fe69f87 from fetched origin, then fetched inside it; (2) replaced the unsubstituted template placeholder "head PR-head" in the reviewer prompt with the real head ref+SHA; (3) replaced literal git diff with git diff origin/main...HEAD in the prompt — a bare git diff in a clean worktree is empty and would have produced a blind review of nothing.
NOT DONE (out of the STEPS scope, conservative): no PR comment, no label, no merge, no approve, no branch write. PR #59 is dependabot-headed (foreign head) and was review-only, as required.
CLEANUP RECEIPTS: /tmp/flatted-ci-pr59 (134M reviewer node_modules scratch, created by my grok run, no process referencing it — verified with ps before deletion) removed; git -C /home/robot/workspace/agent-next/agent-ready worktree remove /tmp/loop-wt-agent-next_agent-ready-pr59 --force exit=0; git worktree list now shows exactly the 3 pre-existing worktrees (none mine); git status --porcelain in the repo main tree is empty; git branch --list 'loop/*' = 0 and no new refs were created (detached worktree, PR ref fetched to FETCH_HEAD only). Other lanes' /tmp/loop-wt-* (pr46, backend-pr1, media-pr4) were left untouched.
Retained: /tmp/loop-grok-pr59-review.log as the raw 329-byte reviewer capture; grok's full session transcript persists under ~/.grok/sessions/%2Ftmp%2Floop-wt-agent-next_agent-ready-pr59/.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant