Skip to content

Lock file maintenance (release-v0.7) - #3487

Open
red-hat-konflux[bot] wants to merge 1 commit into
release-v0.7from
konflux/mintmaker/release-v0.7-release-v0.7/lock-file-maintenance-npm-dependencies
Open

Lock file maintenance (release-v0.7)#3487
red-hat-konflux[bot] wants to merge 1 commit into
release-v0.7from
konflux/mintmaker/release-v0.7-release-v0.7/lock-file-maintenance-npm-dependencies

Conversation

@red-hat-konflux

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

Warning

Some dependencies could not be looked up. Check the warning logs for more information.

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 04:59 AM (* 0-4 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 11, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 4:04 AM UTC · Completed 4:16 AM UTC

Commit: 87c4a29 · View workflow run →

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 11, 2026

Copy link
Copy Markdown

Looks good to me

Previous run

Review

Findings

Low

  • [supply-chain] package-lock.json — lodash is bumped from 4.17.21 to 4.18.1. Verified as a legitimate release (April 2026) under renewed OpenJS Foundation governance, containing security fixes for CVE-2025-13465 (prototype pollution in _.unset/_.omit) and CVE-2026-4800 (code injection in _.template).

  • [supply-chain] package-lock.json — Routine dependency version bumps via Renovate bot: binary-extensions, chokidar, fast-glob, fastq, fsevents, picomatch, reusify, yaml. All resolved URLs point to registry.npmjs.org with sha512 integrity hashes. No anomalies detected.

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added the ready-for-merge All reviewers approved — ready to merge label Aug 11, 2026
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/release-v0.7-release-v0.7/lock-file-maintenance-npm-dependencies branch from 17c6e66 to 6dfa051 Compare August 11, 2026 04:21
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 11, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 4:22 AM UTC · Completed 4:28 AM UTC

Commit: 87c4a29 · View workflow run →

@codecov

codecov Bot commented Aug 11, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

Flag Coverage Δ
generative 69.55% <ø> (ø)
integration 69.55% <ø> (ø)
unit 69.55% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-for-merge All reviewers approved — ready to merge release-v0.7 renovate size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants