Skip to content

[DPEDE-1784](deps): Bump the all-dependencies group across 1 directory with 18 updates - #2110

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot-npm_and_yarn-all-dependencies-f486a7f64d
Open

[DPEDE-1784](deps): Bump the all-dependencies group across 1 directory with 18 updates#2110
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot-npm_and_yarn-all-dependencies-f486a7f64d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 25, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-dependencies group with 18 updates in the / directory:

Package From To
@babel/preset-env 7.29.2 8.0.2
@cypress/code-coverage 3.14.7 4.0.3
@types/node 24.12.2 26.1.1
autoprefixer 10.5.0 10.5.4
chokidar 4.0.3 5.0.0
commander 13.1.0 15.0.0
cross-env 7.0.3 10.1.0
cssnano 7.1.7 8.0.2
cypress 15.14.1 15.19.0
dayjs 1.11.20 1.11.21
express-rate-limit 7.5.1 8.6.0
nyc 17.1.0 18.0.0
ora 8.2.0 9.4.1
sass 1.99.0 1.101.7
ssri 12.0.0 14.0.0
tsx 4.21.0 4.23.1
vite-plugin-istanbul 7.2.1 9.0.1
@rollup/rollup-linux-x64-gnu 4.60.2 4.62.2

Updates @babel/preset-env from 7.29.2 to 8.0.2

Release notes

Sourced from @​babel/preset-env's releases.

v8.0.2 (2026-06-18)

🐛 Bug Fix

  • Other
  • babel-helper-validator-identifier

🏠 Internal

  • babel-plugin-proposal-decorators, babel-plugin-transform-regenerator, babel-preset-env

Committers: 2

v8.0.1 (2026-06-17)

This release includes a breaking change that was in the Babel 8 migration guide's Getting ready section and in the release post, but the actual removal of the feature from the codebase was accidentally not complete.

💥 Breaking Change

  • babel-core, babel-plugin-transform-object-rest-spread, babel-plugin-transform-runtime, babel-preset-env, babel-standalone

Committers: 2

v8.0.0 (2026-06-16)

NOTE: The changelog below is relative to v8.0.0-rc.6. You can find a summary of all the breaking changes shipped in the Babel 8 release line in the migration guide for users and migration guide for plugin developers.

Read the release blog post at http://babeljs.io/blog/2026/06/16/8.0.0!

👓 Spec Compliance

💥 Breaking Change

  • babel-cli, babel-node, babel-plugin-proposal-decorators, babel-plugin-transform-classes, babel-plugin-transform-function-name, babel-plugin-transform-modules-commonjs, babel-plugin-transform-object-rest-spread, babel-plugin-transform-parameters, babel-plugin-transform-react-constant-elements, babel-plugin-transform-regenerator, babel-preset-env, babel-register
  • babel-plugin-transform-runtime, babel-runtime-corejs3, babel-runtime
  • babel-parser

🐛 Bug Fix

  • babel-generator
  • babel-plugin-transform-modules-systemjs

... (truncated)

Changelog

Sourced from @​babel/preset-env's changelog.

v8.0.2 (2026-06-18)

🐛 Bug Fix

  • Other
  • babel-helper-validator-identifier

🏠 Internal

  • babel-plugin-proposal-decorators, babel-plugin-transform-regenerator, babel-preset-env

v8.0.1 (2026-06-17)

💥 Breaking Change

  • babel-core, babel-plugin-transform-object-rest-spread, babel-plugin-transform-runtime, babel-preset-env, babel-standalone

v8.0.0 (2026-06-16)

👓 Spec Compliance

💥 Breaking Change

  • babel-cli, babel-node, babel-plugin-proposal-decorators, babel-plugin-transform-classes, babel-plugin-transform-function-name, babel-plugin-transform-modules-commonjs, babel-plugin-transform-object-rest-spread, babel-plugin-transform-parameters, babel-plugin-transform-react-constant-elements, babel-plugin-transform-regenerator, babel-preset-env, babel-register
  • babel-plugin-transform-runtime, babel-runtime-corejs3, babel-runtime
  • babel-parser

🐛 Bug Fix

  • babel-generator
  • babel-plugin-transform-modules-systemjs

📝 Documentation

🏠 Internal

🏃‍♀️ Performance

v8.0.0-rc.6 (2026-05-25)

🐛 Bug Fix

... (truncated)

Commits

Updates @cypress/code-coverage from 3.14.7 to 4.0.3

Release notes

Sourced from @​cypress/code-coverage's releases.

v4.0.3

4.0.3 (2026-03-23)

Bug Fixes

  • deps: update dependency debug to v4.4.3 (#990) (985dbdd)

v4.0.2

4.0.2 (2026-03-16)

Bug Fixes

  • deps: update dependency dayjs to v1.11.20 (#988) (0540776)

v4.0.1

4.0.1 (2026-02-26)

Bug Fixes

  • deps: update dependency dayjs to v1.11.19 (#983) (a9a10f4)

v4.0.0

4.0.0 (2026-02-10)

chore

BREAKING CHANGES

  • Configure with expose rather than env. Minimum Cypress version is now v15.10.0. Minimum node version is now 20.x.
Commits
  • 995b23a chore(deps): update dependency @​types/debug to v4.1.13 (#989)
  • 985dbdd fix(deps): update dependency debug to v4.4.3 (#990)
  • 72e4299 chore(deps): update dependency serve to v14.2.6 (#987)
  • 0540776 fix(deps): update dependency dayjs to v1.11.20 (#988)
  • fbe9918 chore(deps): update dependency @​types/lodash to v4.17.24 (#984)
  • 649cf9d chore(deps): update nyc, babel-plugin-istanbul, rimraf, and semantic-release ...
  • a9a10f4 fix(deps): update dependency dayjs to v1.11.19 (#983)
  • 067c87c chore(deps): update dependency win to v5.1.1 (#982)
  • 67df880 chore(deps): update dependency lodash to v4.17.23 (#980)
  • fd56f59 chore(deps): update dependency serve to v14.2.5 (#981)
  • Additional commits viewable in compare view

Updates @types/node from 24.12.2 to 26.1.1

Commits

Updates autoprefixer from 10.5.0 to 10.5.4

Release notes

Sourced from autoprefixer's releases.

10.5.4

10.5.3

10.5.2

  • Moved -webkit-fill-available before -moz-available, so Firefox will use -webkit- version which is closer to stretch.

10.5.1

Changelog

Sourced from autoprefixer's changelog.

10.5.4

10.5.3

10.5.2

  • Moved -webkit-fill-available before -moz-available, so Firefox will use -webkit- version which is closer to stretch.

10.5.1

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for autoprefixer since your current version.


Updates chokidar from 4.0.3 to 5.0.0

Release notes

Sourced from chokidar's releases.

5.0.0

  • Make the package ESM-only. Reduces on-disk package size from ~150kb to ~80kb
  • Increase minimum node.js version to v20.19. The versions starting from it support loading esm files from cjs
  • fix: Make types more precise paulmillr/chokidar#1424
  • perf: re-use double slash regex paulmillr/chokidar#1435
  • Update readdirp to ESM-only v5
  • Lots of minor improvements in tests
  • Increase security of NPM releases. Switch to token-less Trusted Publishing, with help of jsbt
  • Switch compilation mode to isolatedDeclaration-based typescript for simplified auto-generated docs

New Contributors

Full Changelog: paulmillr/chokidar@4.0.3...5.0.0

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for chokidar since your current version.


Updates commander from 13.1.0 to 15.0.0

Release notes

Sourced from commander's releases.

v15.0.0

Commander 15 is ESM only. This is expected to be seamless for ESM consumers, but some CommonJS consumers may hit issues with tooling requiring configuration for ESM-only dependencies. See Migration Tips below.

The release of Commander 15 moves Commander 14 into maintenance. Commander 14 will get security updates for 12 months (to May 2027). For more info see Release Policy.

Added

  • show excess command-arguments in error message (#2384)

Fixed

  • Breaking: only lone --no-* option sets default option value to true, default not implicitly set when define both positive and negative option in either order (#2405)
  • update example to use compatible character for MINGW64 (#2475)

Changed

  • Breaking: migrated Commander implementation from CommonJS to ESM (#2464)
  • Breaking: Commander 15 requires Node.js v22.12.0 or higher (for require(esm)).
  • dev: switch tests from Jest to node:test test runner (#2463)

Deleted

  • Breaking: removed deprecated export of commander/esm.mjs (#2464)

Migration Tips

Commander 15 is ESM only, but this does not mean you need to migrate to ESM to use it. Importing ESM from CommonJS is supported by Node.js, and Bun, and Deno. Hopefully it Just Works for you! However, you may be using a different runtime or some other part of your setup that may not yet natively support importing ESM from CommonJS, such as your testing framework or bundler.

If you have problems using Commander 15 in your environment, one option is stay on Commander 14 for now. Commander 14 will get security updates until May 2027 and things will hopefully improve for your setup in the meantime.

v15.0.0-0

Commander 15 is ESM only. This is expected to be seamless for ESM consumers, but some CommonJS consumers may hit issues with tooling requiring configuration for ESM-only dependencies. See Migration Tips below.

The release of Commander 15 in May 2026 will move Commander 14 into maintenance. Commander 14 will get security updates for 12 months (to May 2027). For more info see Release Policy.

Added

  • show excess command-arguments in error message (#2384)

Fixed

  • Breaking: only lone --no-* option sets default option value to true, default not implicitly set when define both positive and negative option in either order (#2405)
  • update example to use compatible character for MINGW64 (#2475)

... (truncated)

Changelog

Sourced from commander's changelog.

[15.0.0] (2026-05-29)

Commander 15 is ESM only. This is expected to be seamless for ESM consumers, but some CommonJS consumers may hit issues with tooling requiring configuration for ESM-only dependencies. See Migration Tips below.

The release of Commander 15 moves Commander 14 into maintenance. Commander 14 will get security updates for 12 months (to May 2027). For more info see Release Policy.

Added

  • show excess command-arguments in error message (#2384)

Fixed

  • Breaking: only lone --no-* option sets default option value to true, default not implicitly set when define both positive and negative option in either order (#2405)
  • update example to use compatible character for MINGW64 (#2475)

Changed

  • Breaking: migrated Commander implementation from CommonJS to ESM (#2464)
  • Breaking: Commander 15 requires Node.js v22.12.0 or higher (for require(esm)).
  • dev: switch tests from Jest to node:test test runner (#2463)

Deleted

  • Breaking: removed deprecated export of commander/esm.mjs (#2464)

Migration Tips

Commander 15 is ESM only, but this does not mean you need to migrate to ESM to use it. Importing ESM from CommonJS is supported by Node.js, and Bun, and Deno. Hopefully it Just Works for you! However, you may be using a different runtime or some other part of your setup that may not yet natively support importing ESM from CommonJS, such as your testing framework or bundler.

If you have problems using Commander 15 in your environment, one option is stay on Commander 14 for now. Commander 14 will get security updates until May 2027 and things will hopefully improve for your setup in the meantime.

[15.0.0-0] (2026-02-22)

(Released as 15.0.0)

[14.0.3] (2026-01-31)

Added

  • Release Policy document (#2462)

Changes

  • old major versions now supported for 12 months instead of just previous major version, to give predictable end-of-life date (#2462)
  • clarify typing for deprecated callback parameter to .outputHelp() (#2427)

... (truncated)

Commits

Updates cross-env from 7.0.3 to 10.1.0

Release notes

Sourced from cross-env's releases.

v10.1.0

10.1.0 (2025-09-29)

Features

  • add support for default value syntax (152ae6a)

For example:

"dev:server": "cross-env wrangler dev --port ${PORT:-8787}",

If PORT is already set, use that value, otherwise fallback to 8787.

Learn more about Shell Parameter Expansion

v10.0.0

10.0.0 (2025-07-25)

TL;DR: You should probably not have to change anything if:

  • You're using a modern maintained version of Node.js (v20+ is tested)
  • You're only using the CLI (most of you are as that's the intended purpose)

In this release (which should have been v8 except I had some issues with automated releases 🙈), I've updated all the things and modernized the package. This happened in #261

Was this needed? Not really, but I just thought it'd be fun to modernize this package.

Here's the highlights of what was done.

  • Replace Jest with Vitest for testing
  • Convert all source files from .js to .ts with proper TypeScript types
  • Use zshy for ESM-only builds (removes CJS support)
  • Adopt @​epic-web/config for TypeScript, ESLint, and Prettier
  • Update to Node.js >=20 requirement
  • Remove kcd-scripts dependency
  • Add comprehensive e2e tests with GitHub Actions matrix testing
  • Update GitHub workflow with caching and cross-platform testing
  • Modernize documentation and remove outdated sections
  • Update all dependencies to latest versions
  • Add proper TypeScript declarations and exports

The tool maintains its original functionality while being completely modernized with the latest tooling and best practices

BREAKING CHANGES

  • This is a major rewrite that changes the module format from CommonJS to ESM-only. The package now requires Node.js >=20 and only exports ESM modules (not relevant in most cases).
Commits
  • 152ae6a feat: add support ofr default value syntax
  • bd70d1a chore: upgrade zshy
  • 8e0b190 chore(ci): get coverage
  • 8635e80 fix(release): manually release a major version
  • 3a58f22 chore: fix npmrc registry
  • b70bfff chore(ci): add names to steps and workflows
  • cc5759d fix(release): manually release a major version
  • 080a859 chore: remove publish script
  • 31e5bc7 chore(ci): restore built files
  • 81e9c34 chore(ci): add back semantic-release
  • Additional commits viewable in compare view

Updates cssnano from 7.1.7 to 8.0.2

Release notes

Sourced from cssnano's releases.

v8.0.2

What's Changed

Full Changelog: https://github.com/cssnano/cssnano/compare/cssnano@8.0.1...cssnano@8.0.2

v8.0.1

What's Changed

Full Changelog: https://github.com/cssnano/cssnano/compare/cssnano@8.0.0...cssnano@8.0.1

v8.0.0

What's Changed

Full Changelog: https://github.com/cssnano/cssnano/compare/cssnano@7.1.9...cssnano@8.0.0

v7.1.9

Bug Fixes

Full Changelog: https://github.com/cssnano/cssnano/compare/cssnano@7.1.8...cssnano@7.1.9

v7.1.8

What's Changed

Full Changelog: https://github.com/cssnano/cssnano/compare/cssnano@7.1.7...cssnano@7.1.8

Commits
  • 185e1c7 Publish cssnano 8.0.2
  • 2ce8c2d chore: update the postcs peer dependency
  • 99bd9c1 docs: update website dependencies
  • 2ca8d4a chore: update development deps
  • b245a0b fix: update caniuse-api
  • 3bf3f4d chore: update postcss-selector-parser
  • 7343c87 fix: preserve apostrophes in svg data uris (#1819)
  • 964b9db chore(util): add benchmark + cpuprofile tooling (#1812)
  • 54a8db2 Include postcss-discard-overridden types in package
  • e0e39ae perf(postcss-merge-longhand): skip processors with no relevant decls
  • Additional commits viewable in compare view

Updates cypress from 15.14.1 to 15.19.0

Release notes

Sourced from cypress's releases.

v15.19.0

Changelog: https://docs.cypress.io/app/references/changelog#15-19-0

v15.18.1

Changelog: https://docs.cypress.io/app/references/changelog#15-18-1

v15.18.0

Changelog: https://docs.cypress.io/app/references/changelog#15-18-0

v15.17.0

Changelog: https://docs.cypress.io/app/references/changelog#15-17-0

v15.16.0

Changelog: https://docs.cypress.io/app/references/changelog#15-16-0

v15.15.0

Changelog: https://docs.cypress.io/app/references/changelog#15-15-0

v15.14.2

Changelog: https://docs.cypress.io/app/references/changelog#15-14-2

Commits
  • d19a47c test: migrate dev-server e2e specs to the reporter iframe (#34301)
  • dd72f31 chore: Update Chrome (stable) to 150.0.7871.128 (#34293)
  • 388f6e0 chore: retrieve SSL.com CodeSignTool for Windows signing from github CDN (#34...
  • 3ff5960 perf: render command log in an isolated iframe to prevent renderer crash (#34...
  • 37a899c fix: allow chaining assertions after should('exist') on raw DOM elements (#34...
  • bfe83a1 chore: clean up the server cookie automation converters and various automatio...
  • 72cef52 chore: Update Chrome (stable) to 150.0.7871.124 and Chrome (beta) to 151.0.79...
  • 6792160 chore: bump websocket-driver to 0.7.5 to resolve critical Snyk vulnerability ...
  • de06a07 test: fix cy-in-cy studio AI test to exercise authenticated flow (#34278)
  • 9e7e850 feat: upgrade chai to 4.5.0 and expose new assertion aliases (#34178)
  • Additional commits viewable in compare view

Updates dayjs from 1.11.20 to 1.11.21

Release notes

Sourced from dayjs's releases.

v1.11.21

1.11.21 (2026-05-26)

Bug Fixes

Changelog

Sourced from dayjs's changelog.

1.11.21 (2026-05-26)

Bug Fixes

Commits

Updates express-rate-limit from 7.5.1 to 8.6.0

Release notes

Sourced from express-rate-limit's releases.

v8.6.0

You can view the changelog here.

v8.5.2

You can view the changelog here.

v8.5.1

You can view the changelog here.

v8.5.0

You can view the changelog here.

v8.4.1

You can view the changelog here.

v8.4.0

You can view the changelog here.

v8.3.2

You can view the changelog here.

v8.3.1

You can view the changelog here.

v8.3.0

You can view the changelog here.

v8.2.1

You can view the changelog here.

v8.2.0

You can view the changelog here.

v8.1.0

You can view the changelog here.

v8.0.1

You can view the changelog here.

v8.0.0

You can view the changelog here.

Commits
  • fffb3c4 8.6.0
  • f366b2d docs: debugging guide, time constants, & v8.6.0 changelog (#652)
  • 593ddd2 fix: make debug output easier to read (#653)
  • ef8c129 fix: Pin safe version of @​asyncapi/specs dev dep (#659)
  • 7b05e0d feat: add time constants to support more readable values for windowMs (#655)
  • 863e730 chore(deps-dev): bump the development-dependencies group with 3 updates (#657)
  • e0e711e fix: correct wording in usage documentation for express-rate-limit (#656)
  • fcd3aa7 chore(deps-dev): bump the development-dependencies group with 3 updates (#651)
  • 99d4298 feat: use debug for debug logging (#641)
  • 23e4dde feat: Run validations once each (#650)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for express-rate-limit since your current version.

Install script changes

This version modifies prepare script that runs during installation. Review the package contents before updating.


Updates nyc from 17.1.0 to 18.0.0

Release notes

Sourced from nyc's releases.

nyc: v18.0.0

18.0.0 (2026-02-22)

⚠ BREAKING CHANGES

  • deps: transitive dependencies now require node 20 || >=22.

Bug Fixes

  • deps: update dependencies pulling in old glob (#1612) (0707729)
Changelog

Sourced from nyc's changelog.

18.0.0 (2026-02-22)

⚠ BREAKING CHANGES

  • deps: transitive dependencies now require node 20 || >=22.

Bug Fixes

  • deps: update dependencies pulling in old glob (#1612) (0707729)
Commits
  • 3ce6d97 chore(main): release nyc 18.0.0 (#1613)
  • b9f6781 build: publication is now manual again due to changes in tokens
  • 0707729 fix(deps)!: update dependencies pulling in old glob (#1612)
  • See full diff in compare view

Updates ora from 8.2.0 to 9.4.1

Release notes

Sourced from ora's releases.

v9.4.1

  • Fix type definitions (#257) 431ebc4
  • Fix failText type to accept unknown instead of Error, matching the actual promise rejection value bc3a283

sindresorhus/ora@v9.4.0...v9.4.1

v9.4.0

  • Add successSymbol and failSymbol options to oraPromise 3d2e0a9

sindresorhus/ora@v9.3.0...v9.4.0

v9.3.0

  • Reduce flicker in rendering 2ab4f76

sindresorhus/ora@v9.2.0...v9.3.0

v9.2.0

  • Update stdin-discarder dependency (#251) 020eaba

sindresorhus/ora@v9.1.0...v9.2.0

v9.1.0

  • Support external writes to stream (console.log) while spinning d2b543a
  • Replace strip-ansi dependency with native stripVTControlCh...

    Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 25, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner June 25, 2026 14:46
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 25, 2026
@lumen-jenkins-prod

Copy link
Copy Markdown

The CI pipeline did not run successfully in https://jenkinsprod.corp.intranet:8443/job/UX-CHI/job/Productive/job/Chi/job/PR-2110/1/. ❌

@cl-aifel-test

cl-aifel-test Bot commented Jun 30, 2026

Copy link
Copy Markdown

🔖 aifel-verdict — AiFEL dependency-triage verdict (schema 1.1)

AiFEL verdict — 🚨 Escalate (breaking-change) — human review required

Group bump of 18 npm devDependencies with 12 major-version jumps; in-repo usage and release notes unavailable; critical CI failing at 64% pass rate — escalated for human review.

TL;DR

  • Merge: 🚫 don't merge yet — 12 packages crossed a major version boundary with undetermined in-repo impact, and the PR's own CI workflow failed. A reviewer must confirm the build pipeline and test suite accept the new major versions before merging.
  • Breaks your code? ⚠️ Undetermined — usage scan was not possible for this group bump; 12 devDependencies (build/test tooling) crossed a major version boundary and could break the build or test pipeline.
  • Security? ✅ no applicable advisories
  • Update: 18 npm packages — you have ^7.27.2 (@babel/preset-env) / ^13.1.0 (commander) / ^7.0.3 (cross-env) / etc., this PR installs major bumps across all 12 (major, spans multiple release generations). Merging upgrades 12 devDependencies through one or more major versions simultaneously.
Signal Value Interpretation
Bump type major 12 of the 18 packages cross a major version boundary (e.g. @babel/preset-env 7→8, commander 13→15, cross-env 7→10, ssri 12→14, vite-plugin-istanbul 7→9); classified major from the manifest diff — the non-standard PR title format ([DPEDE-1784](deps): Bump the all-dependencies group…) could not be auto-parsed for semver
Dependency risk high Multiple major-version jumps across build/test tooling; in-repo API usage could not be scanned for a group bump (no primary package targeted), so breaking-change impact is undetermined — risk stays high until a reviewer confirms the build and tests pass with the new versions
Security risk low No security advisories found for any of the 18 packages; none still affect any new version
CI health risk high 28 critical runs observed; pass rate 64.3%, flakiness 0% → ci_confidence: low. The PR-specific workflow (npm_and_yarn … Update #1438390359) failed; earlier attempts for the same package group (#1427801369, #1424834988, #1419285549) also failed
API usage in repo unknown Group-bump PR — no single primary package was identified by the pre-step; automated usage scan was skipped. Impact is undetermined, not confirmed zero
Cross-repo signal standalone No publishable root manifest found in the repo root — this is an app/internal repo, not a library; breaking changes here do not propagate to external library consumers
Data completeness blind 2 of 5 signals missing: (1) api_usage — group bump, no primary package targeted, usage scan skipped; (2) release_notes — changelog not available for this multi-package group update
📋 Why this route + what AiFEL checked (click to expand)

Why this route?

escalate because: critical CI is failing (pass rate 64.3% over 28 runs, ci_confidence: low), and 12 packages crossed a major version boundary with undetermined in-repo impact (usage scan unavailable for group bump).

Escalation category: breaking-change (multiple major-version bumps with undetermined impact — usage scan was not available for this group bump).

Confidence breakdown — score: 0.65.

  • ✅ No security advisories found for any package in the group

  • ✅ No cascade conflicts with other open Dependabot PRs

  • ✅ Standalone repo — no cross-repo propagation risk

  • ✅ All 12 major-bumped packages appear to be devDependencies (build/test tooling); production runtime is likely unaffected

  • ⚠️ Critical CI low: 28 critical runs at 64.3% pass rate — the PR-specific Dependabot workflow failed

  • ⚠️ API usage unknown — group bump prevented automated scan; cannot confirm absence of breaking-change impact (−0.10)

  • ⚠️ Release notes unavailable — changelog was not fetched for this group bump; cannot confirm which breaking changes apply to this repo (−0.10)

  • ⚠️ CI confidence low: pass rate below 70% threshold (−0.15)

  • 💡 To reach a lower route: (1) Fix the failing critical CI workflows — run npm install && npm test locally against the new versions to identify which major-version bump is causing CI failures; (2) once CI passes on the PR branch and ci_confidence rises to medium or high, the route would drop from escalate to at most spot_check (given the major-version classification); (3) for the highest-impact packages, consult their official migration guides: @babel/preset-env 8.x migration, commander 15.x CHANGELOG, cross-env 10.x, ssri 14.x. Note: fixing informational-only workflows will NOT change the route — only critical check pass rate matters.

What AiFEL checked

  1. Triage — classified major (18-package group bump; 12 packages cross a major version boundary, derived from manifest diff; PR title format non-standard and could not be auto-parsed).
  2. Symbol extraction — UNKNOWN: group bump with no primary package identified; usage scan skipped; impact undetermined, not confirmed zero.
  3. Release-notes comparator — no release notes available (changelog not fetched for multi-package group bump).
  4. CI health — 28 critical runs: pass 64.3%, flaky 0% → confidence low; informational excluded: none identified.
  5. Cascade coordinator — 0 conflicts; no other open Dependabot PRs bump the same packages to a different version.
  6. Data completeness — obtained 3/5 signals; missing: api_usage (group bump, no primary package), release_notes (not available).

Will merging break your code?

⚠️ Undetermined — automated API usage scanning was not possible for this group bump of 18 packages. 12 packages crossed a major version boundary; all appear to be devDependencies (build/test tooling), but major-version jumps in @babel/preset-env 7→8, commander 13→15, cross-env 7→10, ssri 12→14, and vite-plugin-istanbul 7→9 can break the build pipeline or test execution. The repeated CI failures on this PR (and prior attempts at the same group) confirm at least one incompatibility needs investigation before merging.

Security advisories

✅ No security advisories found for any of the 18 packages in this group bump.

Packages — what you have vs what this PR installs

Ecosystem Package You have This PR installs What changes for you
npm @babel/preset-env ^7.27.2 ^8.0.2 major jump — breaking changes expected; impact undetermined
npm @cypress/code-coverage ^3.14.7 ^4.0.3 major jump — impact undetermined
npm @types/node ^24.0.4 ^26.0.1 major jump — impact undetermined
npm chokidar ^4.0.3 ^5.0.0 major jump — impact undetermined
npm commander ^13.1.0 ^15.0.0 major jump — impact undetermined
npm cross-env ^7.0.3 ^10.1.0 major jump — impact undetermined
npm cssnano ^7.0.7 ^8.0.2 major jump — impact undetermined
npm express-rate-limit ^7.5.1 ^8.5.2 major jump — impact undetermined
npm nyc ^17.1.0 ^18.0.0 major jump — impact undetermined
npm ora ^8.2.0 ^9.4.1 major jump — impact undetermined
npm ssri ^12.0.0 ^14.0.0 major jump — impact undetermined
npm vite-plugin-istanbul ^7.2.0 ^9.0.1 major jump — impact undetermined
npm @rollup/rollup-linux-x64-gnu (new) 4.62.2 new optional platform binary added to lockfile
npm @babel/generator 7.29.1 7.29.7 patch — no code impact
npm @babel/helper-define-polyfill-provider 0.6.8 1.0.0 major jump (transitive) — impact undetermined

Machine-readable verdict
{
  "schema_version": "1.1",
  "classification": "major",
  "risk_band": "high",
  "ci_confidence": "low",
  "decision_route": "escalate",
  "data_completeness": "blind",
  "escalate_reason": "risk",
  "missing_signals": [
    {"signal": "api_usage", "reason": "group bump of 18 packages — no primary package identified by pre-step; usage scan skipped"},
    {"signal": "release_notes", "reason": "changelog not available for multi-package group bump"}
  ],
  "confidence": 0.65,
  "packages": [
    {"ecosystem": "npm", "name": "@babel/preset-env", "old_version": "^7.27.2", "new_version": "^8.0.2"},
    {"ecosystem": "npm", "name": "@cypress/code-coverage", "old_version": "^3.14.7", "new_version": "^4.0.3"},
    {"ecosystem": "npm", "name": "@types/node", "old_version": "^24.0.4", "new_version": "^26.0.1"},
    {"ecosystem": "npm", "name": "chokidar", "old_version": "^4.0.3", "new_version": "^5.0.0"},
    {"ecosystem": "npm", "name": "commander", "old_version": "^13.1.0", "new_version": "^15.0.0"},
    {"ecosystem": "npm", "name": "cross-env", "old_version": "^7.0.3", "new_version": "^10.1.0"},
    {"ecosystem": "npm", "name": "cssnano", "old_version": "^7.0.7", "new_version": "^8.0.2"},
    {"ecosystem": "npm", "name": "express-rate-limit", "old_version": "^7.5.1", "new_version": "^8.5.2"},
    {"ecosystem": "npm", "name": "nyc", "old_version": "^17.1.0", "new_version": "^18.0.0"},
    {"ecosystem": "npm", "name": "ora", "old_version": "^8.2.0", "new_version": "^9.4.1"},
    {"ecosystem": "npm", "name": "ssri", "old_version": "^12.0.0", "new_version": "^14.0.0"},
    {"ecosystem": "npm", "name": "vite-plugin-istanbul", "old_version": "^7.2.0", "new_version": "^9.0.1"}
  ],
  "breaking_changes": [],
  "cascade_conflicts": [],
  "summary": "Group bump of 18 npm devDependencies (12 major-version jumps); API usage and release notes unavailable; critical CI failing at 64% pass rate — escalated for human review.",
  "upgrade_risk_note": null,
  "cross_repo_signal": "standalone",
  "api_usage_found": null,
  "advisory_ids": [],
  "max_cvss": null,
  "feedback_capture_marker": "aifel-CenturyLink-Chi-2110",
  "agent_version": "1.1.1-aw"
}

🤖 Generated by AiFEL — AI-assisted Dependabot triage. Advisory only; a human reviewer still decides and merges.
📝 Share your AiFEL experience

@cl-aifel-test cl-aifel-test Bot added the aifel/escalate AiFEL: human review required (breaking change or risk) label Jun 30, 2026
@dependabot
dependabot Bot force-pushed the dependabot-npm_and_yarn-all-dependencies-f486a7f64d branch from d0d0df2 to b225333 Compare July 1, 2026 11:31
@lumen-jenkins-prod

Copy link
Copy Markdown

The CI pipeline did not run successfully in https://jenkinsprod.corp.intranet:8443/job/UX-CHI/job/Productive/job/Chi/job/PR-2110/2/. ❌

@dependabot
dependabot Bot force-pushed the dependabot-npm_and_yarn-all-dependencies-f486a7f64d branch from b225333 to 8657592 Compare July 6, 2026 17:28
@lumen-jenkins-prod

Copy link
Copy Markdown

The CI pipeline did not run successfully in https://jenkinsprod.corp.intranet:8443/job/UX-CHI/job/Productive/job/Chi/job/PR-2110/3/. ❌

@dependabot
dependabot Bot force-pushed the dependabot-npm_and_yarn-all-dependencies-f486a7f64d branch from 8657592 to 9cce907 Compare July 13, 2026 06:07
@lumen-jenkins-prod

Copy link
Copy Markdown

The CI pipeline did not run successfully in https://jenkinsprod.corp.intranet:8443/job/UX-CHI/job/Productive/job/Chi/job/PR-2110/4/. ❌

@dependabot
dependabot Bot force-pushed the dependabot-npm_and_yarn-all-dependencies-f486a7f64d branch from 9cce907 to 0c8da98 Compare July 20, 2026 06:05
@lumen-jenkins-prod

Copy link
Copy Markdown

The CI pipeline did not run successfully in https://jenkinsprod.corp.intranet:8443/job/UX-CHI/job/Productive/job/Chi/job/PR-2110/5/. ❌

…y with 18 updates

Bumps the all-dependencies group with 18 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@babel/preset-env](https://github.com/babel/babel/tree/HEAD/packages/babel-preset-env) | `7.29.2` | `8.0.2` |
| [@cypress/code-coverage](https://github.com/cypress-io/code-coverage) | `3.14.7` | `4.0.3` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `24.12.2` | `26.1.1` |
| [autoprefixer](https://github.com/postcss/autoprefixer) | `10.5.0` | `10.5.4` |
| [chokidar](https://github.com/paulmillr/chokidar) | `4.0.3` | `5.0.0` |
| [commander](https://github.com/tj/commander.js) | `13.1.0` | `15.0.0` |
| [cross-env](https://github.com/kentcdodds/cross-env) | `7.0.3` | `10.1.0` |
| [cssnano](https://github.com/cssnano/cssnano) | `7.1.7` | `8.0.2` |
| [cypress](https://github.com/cypress-io/cypress) | `15.14.1` | `15.19.0` |
| [dayjs](https://github.com/iamkun/dayjs) | `1.11.20` | `1.11.21` |
| [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) | `7.5.1` | `8.6.0` |
| [nyc](https://github.com/istanbuljs/nyc) | `17.1.0` | `18.0.0` |
| [ora](https://github.com/sindresorhus/ora) | `8.2.0` | `9.4.1` |
| [sass](https://github.com/sass/dart-sass) | `1.99.0` | `1.101.7` |
| [ssri](https://github.com/npm/ssri) | `12.0.0` | `14.0.0` |
| [tsx](https://github.com/privatenumber/tsx) | `4.21.0` | `4.23.1` |
| [vite-plugin-istanbul](https://github.com/iFaxity/vite-plugin-istanbul) | `7.2.1` | `9.0.1` |
| [@rollup/rollup-linux-x64-gnu](https://github.com/rollup/rollup) | `4.60.2` | `4.62.2` |



Updates `@babel/preset-env` from 7.29.2 to 8.0.2
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v8.0.2/packages/babel-preset-env)

Updates `@cypress/code-coverage` from 3.14.7 to 4.0.3
- [Release notes](https://github.com/cypress-io/code-coverage/releases)
- [Commits](cypress-io/code-coverage@v3.14.7...v4.0.3)

Updates `@types/node` from 24.12.2 to 26.1.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `autoprefixer` from 10.5.0 to 10.5.4
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](postcss/autoprefixer@10.5.0...10.5.4)

Updates `chokidar` from 4.0.3 to 5.0.0
- [Release notes](https://github.com/paulmillr/chokidar/releases)
- [Commits](paulmillr/chokidar@4.0.3...5.0.0)

Updates `commander` from 13.1.0 to 15.0.0
- [Release notes](https://github.com/tj/commander.js/releases)
- [Changelog](https://github.com/tj/commander.js/blob/master/CHANGELOG.md)
- [Commits](tj/commander.js@v13.1.0...v15.0.0)

Updates `cross-env` from 7.0.3 to 10.1.0
- [Release notes](https://github.com/kentcdodds/cross-env/releases)
- [Changelog](https://github.com/kentcdodds/cross-env/blob/main/CHANGELOG.md)
- [Commits](kentcdodds/cross-env@v7.0.3...v10.1.0)

Updates `cssnano` from 7.1.7 to 8.0.2
- [Release notes](https://github.com/cssnano/cssnano/releases)
- [Commits](https://github.com/cssnano/cssnano/compare/cssnano@7.1.7...cssnano@8.0.2)

Updates `cypress` from 15.14.1 to 15.19.0
- [Release notes](https://github.com/cypress-io/cypress/releases)
- [Changelog](https://github.com/cypress-io/cypress/blob/develop/CHANGELOG.md)
- [Commits](cypress-io/cypress@v15.14.1...v15.19.0)

Updates `dayjs` from 1.11.20 to 1.11.21
- [Release notes](https://github.com/iamkun/dayjs/releases)
- [Changelog](https://github.com/iamkun/dayjs/blob/dev/CHANGELOG.md)
- [Commits](iamkun/dayjs@v1.11.20...v1.11.21)

Updates `express-rate-limit` from 7.5.1 to 8.6.0
- [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases)
- [Commits](express-rate-limit/express-rate-limit@v7.5.1...v8.6.0)

Updates `nyc` from 17.1.0 to 18.0.0
- [Release notes](https://github.com/istanbuljs/nyc/releases)
- [Changelog](https://github.com/istanbuljs/nyc/blob/main/CHANGELOG.md)
- [Commits](istanbuljs/nyc@nyc-v17.1.0...nyc-v18.0.0)

Updates `ora` from 8.2.0 to 9.4.1
- [Release notes](https://github.com/sindresorhus/ora/releases)
- [Commits](sindresorhus/ora@v8.2.0...v9.4.1)

Updates `sass` from 1.99.0 to 1.101.7
- [Release notes](https://github.com/sass/dart-sass/releases)
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md)
- [Commits](sass/dart-sass@1.99.0...1.101.7)

Updates `ssri` from 12.0.0 to 14.0.0
- [Release notes](https://github.com/npm/ssri/releases)
- [Changelog](https://github.com/npm/ssri/blob/main/CHANGELOG.md)
- [Commits](npm/ssri@v12.0.0...v14.0.0)

Updates `tsx` from 4.21.0 to 4.23.1
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.21.0...v4.23.1)

Updates `vite-plugin-istanbul` from 7.2.1 to 9.0.1
- [Release notes](https://github.com/iFaxity/vite-plugin-istanbul/releases)
- [Changelog](https://github.com/iFaxity/vite-plugin-istanbul/blob/next/release.config.mjs)
- [Commits](iFaxity/vite-plugin-istanbul@v7.2.1...v9.0.1)

Updates `@rollup/rollup-linux-x64-gnu` from 4.60.2 to 4.62.2
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md)
- [Commits](rollup/rollup@v4.60.2...v4.62.2)

---
updated-dependencies:
- dependency-name: "@babel/preset-env"
  dependency-version: 8.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-dependencies
- dependency-name: "@cypress/code-coverage"
  dependency-version: 4.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-dependencies
- dependency-name: "@rollup/rollup-linux-x64-gnu"
  dependency-version: 4.62.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-dependencies
- dependency-name: autoprefixer
  dependency-version: 10.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: chokidar
  dependency-version: 5.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-dependencies
- dependency-name: commander
  dependency-version: 15.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-dependencies
- dependency-name: cross-env
  dependency-version: 10.1.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-dependencies
- dependency-name: cssnano
  dependency-version: 8.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-dependencies
- dependency-name: cypress
  dependency-version: 15.18.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: dayjs
  dependency-version: 1.11.21
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: express-rate-limit
  dependency-version: 8.5.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-dependencies
- dependency-name: nyc
  dependency-version: 18.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-dependencies
- dependency-name: ora
  dependency-version: 9.4.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-dependencies
- dependency-name: sass
  dependency-version: 1.101.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: ssri
  dependency-version: 14.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-dependencies
- dependency-name: tsx
  dependency-version: 4.22.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: vite-plugin-istanbul
  dependency-version: 9.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: all-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot-npm_and_yarn-all-dependencies-f486a7f64d branch from 0c8da98 to 264d180 Compare July 24, 2026 08:23
@lumen-jenkins-prod

Copy link
Copy Markdown

The CI pipeline did not run successfully in https://jenkinsprod.corp.intranet:8443/job/UX-CHI/job/Productive/job/Chi/job/PR-2110/6/. ❌

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aifel/escalate AiFEL: human review required (breaking change or risk) dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants