Skip to content

deps: bump picomatch - #60

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-bf05dc1ecf
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-bf05dc1ecf

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 26, 2026

Copy link
Copy Markdown
Contributor

Bumps and picomatch. These dependencies needed to be updated together.
Updates picomatch from 2.3.1 to 2.3.2

Release notes

Sourced from picomatch's releases.

2.3.2

This is a security release fixing several security relevant issues.

What's Changed

Full Changelog: micromatch/picomatch@2.3.1...2.3.2

Changelog

Sourced from picomatch's changelog.

Release history

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog and this project adheres to Semantic Versioning.

  • Changelogs are for humans, not machines.
  • There should be an entry for every single version.
  • The same types of changes should be grouped.
  • Versions and sections should be linkable.
  • The latest version comes first.
  • The release date of each versions is displayed.
  • Mention whether you follow Semantic Versioning.

Changelog entries are classified using the following labels (from keep-a-changelog):

  • Added for new features.
  • Changed for changes in existing functionality.
  • Deprecated for soon-to-be removed features.
  • Removed for now removed features.
  • Fixed for any bug fixes.
  • Security in case of vulnerabilities.

4.0.0 (2024-02-07)

Fixes

Changed

3.0.1

Fixes

... (truncated)

Commits

Updates picomatch from 4.0.3 to 4.0.4

Release notes

Sourced from picomatch's releases.

2.3.2

This is a security release fixing several security relevant issues.

What's Changed

Full Changelog: micromatch/picomatch@2.3.1...2.3.2

Changelog

Sourced from picomatch's changelog.

Release history

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog and this project adheres to Semantic Versioning.

  • Changelogs are for humans, not machines.
  • There should be an entry for every single version.
  • The same types of changes should be grouped.
  • Versions and sections should be linkable.
  • The latest version comes first.
  • The release date of each versions is displayed.
  • Mention whether you follow Semantic Versioning.

Changelog entries are classified using the following labels (from keep-a-changelog):

  • Added for new features.
  • Changed for changes in existing functionality.
  • Deprecated for soon-to-be removed features.
  • Removed for now removed features.
  • Fixed for any bug fixes.
  • Security in case of vulnerabilities.

4.0.0 (2024-02-07)

Fixes

Changed

3.0.1

Fixes

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps  and [picomatch](https://github.com/micromatch/picomatch). These dependencies needed to be updated together.

Updates `picomatch` from 2.3.1 to 2.3.2
- [Release notes](https://github.com/micromatch/picomatch/releases)
- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md)
- [Commits](micromatch/picomatch@2.3.1...2.3.2)

Updates `picomatch` from 4.0.3 to 4.0.4
- [Release notes](https://github.com/micromatch/picomatch/releases)
- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md)
- [Commits](micromatch/picomatch@2.3.1...2.3.2)

---
updated-dependencies:
- dependency-name: picomatch
  dependency-version: 2.3.2
  dependency-type: indirect
- dependency-name: picomatch
  dependency-version: 4.0.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Mar 26, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@robotlearning123

Copy link
Copy Markdown
Member

Backlog-loop verification: checks/tests green except pre-existing base failures (delta: Failing checks at head vs base: claude-review FAILURE at head; base ref (ce7da5b, == origin/main head) has no claude-review run (workflow is pull_request-triggered; commit-level check-runs for ce7da5b show only 'claude | skipped' + Dependabot). Baseline evidence: claude-review FAILURE on 6/6 sibling PRs (#50,#51,#54,#55,#56,#59) and 8/8 most recent claude-code-review.yml runs (conclusion failure/action_required, branches: chore/merge-satellites, merge/satellites, fix/agent-ready-pr71-baseline-20260922, docs/portfolio-agent-ready-v2-20260922-125500, docs/lintlang-instruction-quality-gate, dependabot/npm_and_yarn/qs-6.15.2, dependabot/npm_and_yarn/dev-dependencies-0010567636). All other head checks SUCCESS. Real numeric delta (npm audit, same npm 10.9.4 / node 22.22.0, fresh npm ci in each detached worktree): BASE origin/main ce7da5b = {"info":0,"low":1,"moderate":8,"high":10,"critical":0,"total":19} with picomatch vulnerable range <=2.3.1 || 4.0.0-4.0.3 (GHSA-c2c7-rcm5-vvqj high ReDoS, GHSA-3v7f-55p6-f55p moderate); HEAD 7e0355a = {"info":0,"low":1,"moderate":8,"high":9,"critical":0,"total":18}, picomatch advisories: []. Tests identical and green both refs: base 57/57 pass exit 0, head 57/57 pass exit 0. PR is strictly better than base (closes 1 high advisory), not worse.). Independent review: APPROVE.
GROK VERDICT: APPROVE — "No findings." (verbatim, single call, exit 0). Grok's stated basis: both picomatch copies move to advisory-patched versions — node_modules/picomatch 2.3.1 -> 2.3.2 at package-lock.json:3493, and node_modules/tinyglobby/node_modules/picomatch 4.0.3 -> 4.0.4 at package-lock.json:4314; parent ranges ^2.3.1 / ^4.0.3 still admit them; other hunks only sync the lockfile root version to package.json 0.2.0 and correct peer flags. No numbered findings were emitted.

INDEPENDENT VERIFICATION OF GROK'S LOAD-BEARING CLAIMS (I re-ran each; all confirmed):

  1. Integrity hashes match the npm registry exactly. "npm view picomatch@2.3.2 dist.integrity" -> sha512-V7+vQEJ06Z+c5tSye8S+nHUfI51xoXIXjHQ99cQtKUkQqqO1kO/KCJUfZXuB47h/YBlDhah2H3hdUGXn8ie0oA== (identical to the lockfile's new "resolved" line); "npm view picomatch@4.0.4 dist.integrity" -> sha512-QP88BAKvMam/3NxH6vj2o21R6MjxZUAd6nlwAS/pnGvN9IVLocLHxGYIzFhg6fUQ+5th6P4dv4eW9jX3DSIj7A== (identical). No hash mismatch, no fabricated artifact.
  2. CVE closure is real, not asserted. "gh api /advisories/GHSA-c2c7-rcm5-vvqj" -> severity high, "Picomatch has a ReDoS vulnerability via extglob quantifiers", first_patched_version 4.0.4 / 3.0.2 / 2.3.2 (range ">= 4.0.0, < 4.0.4" and "< 2.3.2"). "gh api /advisories/GHSA-3v7f-55p6-f55p" -> severity medium, "Method Injection in POSIX Character Classes causes incorrect Glob Matching", same patched set. The PR's two target versions (2.3.2, 4.0.4) are exactly the patched versions, so both CVE-2026-33671 and CVE-2026-33672 alerts are closed by this PR. This also matches the repo note's expectation for sibling repos ("closed CVE-2026-33671/33672 with picomatch 4.0.4").
  3. No unexpected version or resolution changes. "git diff origin/main...HEAD -- package-lock.json | grep -E '^[-+] +"version":'" returns exactly 4 pairs: root 0.1.0->0.2.0 (2 lines), picomatch 2.3.1->2.3.2, picomatch 4.0.3->4.0.4. Filtering changed "resolved" lines to exclude registry.npmjs.org/picomatch returns EMPTY — no other dependency was touched.
  4. The root-version hunk is a sync, not a package bump. "git show origin/main:package.json | grep -m1 '"version"'" -> "version": "0.2.0" while the lockfile root said 0.1.0. So package.json was already 0.2.0 on main and only the lockfile root lagged; the PR corrects the lag. Grok's characterisation is correct.
  5. Package set unchanged. "git show HEAD:package-lock.json | grep -c '^ "node_modules/'" = 352; same expression on origin/main = 352. Identical counts, no package added or removed. MINOR METRIC DISCREPANCY: grok wrote "same 354 packages"; my top-level node_modules count is 352 (grok's 354 likely counts nested/hoisted entries differently). The load-bearing claim — no net package change — holds; the absolute number differs by counting method, not by fact. (unverified which metric grok used.)
  6. Test coverage: no test files and no package.json change appear in the diff (1 file changed, package-lock.json only). For an indirect lockfile-only dependency bump there is no testable behaviour change, so the absence of a test is appropriate rather than a gap.

SCOPE OBSERVATION (mine, not raised by grok; recorded, not escalated to a blocking finding): the diff carries lockfile-regeneration churn beyond the two picomatch lines — the root version sync (2 lines, justified in point 4) and 9 "peer": true flag corrections (8 removals: @opentelemetry, @typescript-eslint/*, acorn, eslint, express, typescript, zod; 1 addition: hono 4.11.5). These are dependency-graph flag normalisations emitted by dependabot's npm version, carry no runtime or resolution effect, and are normal for an autogenerated dependabot lockfile. I do not treat them as scope creep requiring changes.

DEVIATIONS (what/why, with the conservative option taken):

  • The task's "(head PR-head)" was an unsubstituted placeholder. I resolved the real head to refs/heads/dependabot/npm_and_yarn/multi-bf05dc1ecf / refs/pull/60/head at SHA 7e0355a via "gh -R agent-next/agent-ready pr view 60 --json ...", cross-checked with "git ls-remote origin" (both refs point at the same SHA). Conservative option: pinned the review to the immutable SHA rather than a moving branch name.
  • The step-1 worktree did not exist at start ("ls: cannot access '/tmp/loop-wt-agent-next_agent-ready-pr60': No such file or directory"). I created it fresh per the safety contract: "git worktree add --detach /tmp/loop-wt-agent-next_agent-ready-pr60 7e0355a..." (detached, so the foreign non-loop/* branch is never checked out and cannot be mutated). "git rev-parse HEAD" in the worktree returned exactly the pinned SHA.
  • Grok's prompt was augmented with the pinned ref and diff range. On a clean detached worktree a bare git diff prints nothing, so the reviewer would have had no diff to read. I preserved the task's required output format, its review criteria, and its "default to REQUEST_CHANGES when uncertain" instruction, and added "git diff origin/main...HEAD (merge-base ce7da5b)" so it reviewed the real pinned diff.
  • STALE-BASE TRAP, avoided: local main is 8373df4 but origin/main is ce7da5b, and merge-base(origin/main, HEAD) = ce7da5b. A two-dot "git diff 8373df4..HEAD" shows 101 files changed, 8820 insertions, 12734 deletions — a completely false picture of this PR. The true PR diff is "git diff origin/main...HEAD" = 1 file changed, 9 insertions, 16 deletions, which matches GitHub's own "changedFiles": 1, "additions": 9, "deletions": 16. Both figures pasted above are from real command output.
  • One grok call only, exit 0, no timeout, no failure, so the "reviewer-lane-unavailable" path was not reached and the verdict is a real reviewer verdict, not a fallback.
  • No PR comment was posted: the workflow STEPS specify no comment step, and posting to a public repo is not mine to initiate here. Reporting to the orchestrator instead.

SAFETY COMPLIANCE: no merge, no approval-as-reviewer, no push, no force-push, no branch or settings change. All work happened in the fresh detached /tmp worktree; the repo's main working tree was never mutated. Cleanup ran: "git -C /home/robot/workspace/agent-next/agent-ready worktree remove /tmp/loop-wt-agent-next_agent-ready-pr60 --force" -> exit 0; "git worktree list" afterward shows only the pre-existing main checkout plus the two pre-existing .worktrees/ entries (luna-agent-ready-pr71-fix-20260922, portfolio-agent-ready-v2-copy-20260922-125500), which I did not create and did not touch; "ls -d /tmp/loop-wt-agent-next_agent-ready-pr60" -> No such file or directory.

BOTTOM LINE: independent grok review obtained (writer devin/deepseek != reviewer grok), grok verdict APPROVE with zero findings, and every load-bearing claim in that review reproduced by my own execution. The one item worth the orchestrator's attention is the unsubstituted "PR-head" placeholder in the task text, which will mislead any lane that does not resolve the head explicitly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant