deps: bump picomatch - #60
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps and [picomatch](https://github.com/micromatch/picomatch). These dependencies needed to be updated together. Updates `picomatch` from 2.3.1 to 2.3.2 - [Release notes](https://github.com/micromatch/picomatch/releases) - [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md) - [Commits](micromatch/picomatch@2.3.1...2.3.2) Updates `picomatch` from 4.0.3 to 4.0.4 - [Release notes](https://github.com/micromatch/picomatch/releases) - [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md) - [Commits](micromatch/picomatch@2.3.1...2.3.2) --- updated-dependencies: - dependency-name: picomatch dependency-version: 2.3.2 dependency-type: indirect - dependency-name: picomatch dependency-version: 4.0.4 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Backlog-loop verification: checks/tests green except pre-existing base failures (delta: Failing checks at head vs base: claude-review FAILURE at head; base ref (ce7da5b, == origin/main head) has no claude-review run (workflow is pull_request-triggered; commit-level check-runs for ce7da5b show only 'claude | skipped' + Dependabot). Baseline evidence: claude-review FAILURE on 6/6 sibling PRs (#50,#51,#54,#55,#56,#59) and 8/8 most recent claude-code-review.yml runs (conclusion failure/action_required, branches: chore/merge-satellites, merge/satellites, fix/agent-ready-pr71-baseline-20260922, docs/portfolio-agent-ready-v2-20260922-125500, docs/lintlang-instruction-quality-gate, dependabot/npm_and_yarn/qs-6.15.2, dependabot/npm_and_yarn/dev-dependencies-0010567636). All other head checks SUCCESS. Real numeric delta (npm audit, same npm 10.9.4 / node 22.22.0, fresh INDEPENDENT VERIFICATION OF GROK'S LOAD-BEARING CLAIMS (I re-ran each; all confirmed):
SCOPE OBSERVATION (mine, not raised by grok; recorded, not escalated to a blocking finding): the diff carries lockfile-regeneration churn beyond the two picomatch lines — the root version sync (2 lines, justified in point 4) and 9 DEVIATIONS (what/why, with the conservative option taken):
SAFETY COMPLIANCE: no merge, no approval-as-reviewer, no push, no force-push, no branch or settings change. All work happened in the fresh detached /tmp worktree; the repo's main working tree was never mutated. Cleanup ran: "git -C /home/robot/workspace/agent-next/agent-ready worktree remove /tmp/loop-wt-agent-next_agent-ready-pr60 --force" -> exit 0; "git worktree list" afterward shows only the pre-existing main checkout plus the two pre-existing .worktrees/ entries (luna-agent-ready-pr71-fix-20260922, portfolio-agent-ready-v2-copy-20260922-125500), which I did not create and did not touch; "ls -d /tmp/loop-wt-agent-next_agent-ready-pr60" -> No such file or directory. BOTTOM LINE: independent grok review obtained (writer devin/deepseek != reviewer grok), grok verdict APPROVE with zero findings, and every load-bearing claim in that review reproduced by my own execution. The one item worth the orchestrator's attention is the unsubstituted "PR-head" placeholder in the task text, which will mislead any lane that does not resolve the head explicitly. |
Bumps and picomatch. These dependencies needed to be updated together.
Updates
picomatchfrom 2.3.1 to 2.3.2Release notes
Sourced from picomatch's releases.
Changelog
Sourced from picomatch's changelog.
... (truncated)
Commits
81cba8dPublish 2.3.2fc1f6b6Merge commit from forkeec17aeMerge commit from fork78f8ca4Merge pull request #156 from micromatch/backport-1443f4f10eMerge pull request #144 from Jason3S/jdent-object-propertiesUpdates
picomatchfrom 4.0.3 to 4.0.4Release notes
Sourced from picomatch's releases.
Changelog
Sourced from picomatch's changelog.
... (truncated)
Commits
81cba8dPublish 2.3.2fc1f6b6Merge commit from forkeec17aeMerge commit from fork78f8ca4Merge pull request #156 from micromatch/backport-1443f4f10eMerge pull request #144 from Jason3S/jdent-object-propertiesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.