Skip to content

fix(deps): update transitive devalue to patched 5.9.3 - #52

Open
tembo[bot] wants to merge 1 commit into
masterfrom
tembo/fix-dependabot-devalue
Open

tembo[bot] wants to merge 1 commit into
masterfrom
tembo/fix-dependabot-devalue

Conversation

@tembo

@tembo tembo Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Resolve the master-branch Dependabot security update failure: https://github.com/beyonk/http/actions/runs/37880058097.
  • The updater reported security_update_not_possible: latest resolvable devalue 5.9.2, earliest non-vulnerable version 5.9.3. Its pnpm update command targeted a dependency not declared directly by this project, leaving the transitive lockfile entry unchanged.
  • Update only devalue's lockfile resolution, integrity and Svelte dependency reference to 5.9.3. Svelte 5.57.0 declares devalue ^5.8.1, so the patched version satisfies its existing range; no overrides or application changes.
  • This dynamic Dependabot run has no associated pull request; it ran against master release commit 66dbe81.

Validation

  • pnpm install --frozen-lockfile: passed, including supply-chain policy checks.
  • pnpm why devalue: only version 5.9.3, via the development ESLint/Svelte dependency chain.
  • pnpm test: 74 passing.
  • pnpm build: passed (ESM, CJS and declarations).
  • git diff --check: passed.
  • pnpm lint: four pre-existing array-bracket spacing errors in lib/index.spec.js lines 240 and 249; reproduced on an unchanged master worktree with the same ESLint installation. Left unchanged to minimize scope.

Notifications

Slack notification could not be delivered because no Slack integration is configured.


Want tembo to make any changes? Add a comment with @tembo and i'll get back to work!

View on Tembo  Review in Tembo  View Agent Settings  View on agent

@tembo tembo Bot added the tembo Pull request created by Tembo label Oct 9, 2026
@tembo
tembo Bot requested a review from paulambanks October 9, 2026 03:39
@tembo

tembo Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Requesting review from @paulambanks who has experience with the following files modified in this PR:

  • pnpm-lock.yaml

@pkg-pr-new

pkg-pr-new Bot commented Oct 9, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@beyonk/http@52

commit: b2b806a

@tembo

tembo Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

The same master-branch Dependabot failure recurred in run https://github.com/beyonk/http/actions/runs/37918623683: security_update_not_possible leaves transitive devalue at 5.9.2, while the earliest patched version is 5.9.3. This existing follow-up PR already updates that lockfile entry and has passing checks, so no duplicate fix was opened; the run has no associated original PR, and the requested Slack CI Autofixes notification is blocked because no Slack integration is configured.

@tembo

tembo Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Master run https://github.com/beyonk/http/actions/runs/37921820505 failed with security_update_not_possible: Dependabot could only resolve devalue 5.9.2, while the earliest patched version is 5.9.3; this existing follow-up PR already contains the lockfile fix and has passing checks, so no duplicate PR or branch changes were made. The failed run has no associated original PR, and the requested #engineering CI Autofixes notification could not be delivered because no Slack integration is configured.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

tembo Pull request created by Tembo

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants