Skip to content

chore(deps): bundle outstanding dependabot updates#81

Open
miru-agents wants to merge 1 commit into
mainfrom
claude/setup-cli-dependabot-bundle-3a29ag
Open

chore(deps): bundle outstanding dependabot updates#81
miru-agents wants to merge 1 commit into
mainfrom
claude/setup-cli-dependabot-bundle-3a29ag

Conversation

@miru-agents

@miru-agents miru-agents commented Jun 26, 2026

Copy link
Copy Markdown
Collaborator

Bundles the outstanding Dependabot updates. Commit is created via the GitHub API so it carries a verified signature.

Included

Source PR Update
#78 actions-minor group — bumps pinned SHAs for github/codeql-action (init/autobuild/analyze), ruby/setup-ruby, and super-linter/super-linter

Not included

esbuild / tsx (#73) — this is a ~425 KB package-lock.json rewrite. A verified signature here requires committing through the GitHub API, which isn't feasible for a file that large in this environment. Dependabot's original #73 is already verified and can be merged directly — recommend merging it as-is rather than re-bundling.

npm-development (#76) and npm-production / semver (#65) — already superseded by the previously merged bundle #79; package.json/package-lock.json on main already carry (or exceed) those target versions. These can be closed as superseded.

Verification of the included change

npm run package rebuilds dist/index.js byte-identically (no dist drift), so check-dist should pass.


Generated by Claude Code


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.

…pdates

Bundles dependabot PR #78. Bumps github/codeql-action (init/autobuild/analyze),
ruby/setup-ruby, and super-linter/super-linter to their pinned SHAs.
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant