Skip to content

chore(deps): bump browserslist from 4.25.1 to 4.28.8 - #288

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/browserslist-4.28.8
Closed

chore(deps): bump browserslist from 4.25.1 to 4.28.8#288
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/browserslist-4.28.8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps browserslist from 4.25.1 to 4.28.8.

Release notes

Sourced from browserslist's releases.

4.28.8

  • Fixed including kaios in baseline queries (by @​Jaybhade).

4.28.7

4.28.6

4.28.5

4.28.4

  • Fixed SyntaxError regression of 4.28.3.

4.28.3

  • Fixed baseline query case-insensitivity (by @​swwind).

4.28.2

4.28.1

  • Removed Baseline warning since we have it own warning.

4.27.0

  • Added BROWSERSLIST_TRACE_WARNING environment variable.

4.26.3

4.26.2

  • Fixed baseline-browser-mapping version requirement.

4.26.1

  • Updated Firefox ESR.

4.26.0

4.25.4

4.25.3

4.25.2

  • Fixed Node.js --permission support (by @​broofa).
Changelog

Sourced from browserslist's changelog.

4.28.8

  • Fixed including kaios in baseline queries (by @​Jaybhade).

4.28.7

4.28.6

4.28.5

4.28.4

  • Fixed SyntaxError regression of 4.28.3.

4.28.3

  • Fixed baseline query case-insensitivity (by @​swwind).

4.28.2

4.28.1

  • Removed Baseline warning since we have it own warning.

4.48.0

4.27.0

  • Added BROWSERSLIST_TRACE_WARNING environment variable.

4.26.3

4.26.2

  • Fixed baseline-browser-mapping version requirement.

... (truncated)

Commits
  • f2f2e6c Release 4.28.8 version
  • d0787c8 Update dependencies
  • fcf8fa9 Merge pull request #939 from Jaybhade/fix/baseline-kaios-without-downstream
  • 57ecd64 fix: support "including kaios" without downstream
  • 093a0f6 Update EM banner
  • b637868 Release 4.28.7 version
  • 313f465 Update dependencies
  • c935c5a Fix regexp performance
  • d7e9e65 Rewrite structure parsing to make it always fast
  • ec4a55e Fix import order
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for browserslist since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [browserslist](https://github.com/browserslist/browserslist) from 4.25.1 to 4.28.8.
- [Release notes](https://github.com/browserslist/browserslist/releases)
- [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md)
- [Commits](browserslist/browserslist@4.25.1...4.28.8)

---
updated-dependencies:
- dependency-name: browserslist
  dependency-version: 4.28.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 1, 2026
@greptile-apps

greptile-apps Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

PR author is in the excluded authors list.

Copy link
Copy Markdown

Dependabot PR Review — 2026-09-02

Note: Issues are disabled on this repo, so this review is posted directly on the PRs instead of a shared tracking issue (same as the 2026-08-29/08-31 cycles hosted on #273). This PR is the new host — 2 new PRs opened today. Nothing has been merged, approved, or closed — each PR is merged only after an explicit human go-ahead comment on it.

# Package Version Change Bump CI Mergeable Action
#288 (this PR) browserslist 4.25.1→4.28.8 minor 🟢 Green (7/7) blocked (no conflict) New today — auto-merge candidate
#287 browserslist (rn-purchasely-test) 4.28.2→4.28.8 patch 🟢 Green (7/7) blocked New today — auto-merge candidate
#277 nanoid 3.3.11→3.3.18 patch 🔴 build-ios failing, other 6 green unknown* CI Failing — unchanged since 08-11
#276 postcss (expo-purchasely-test) 8.5.12→8.5.26 patch 🟢 Green (7/7) unknown* Auto-merge candidate — unchanged
#275 nanoid (expo-purchasely-test) 3.3.11→3.3.18 patch 🔴 build-ios failing, other 6 green unknown* CI Failing, same pattern as #277 — unchanged
#274 undici 7.28.0→7.29.0 minor 🔴 All 7 jobs failing unknown* CI Failing — security-relevant (1 high + 4 medium CVE fixes), needs root cause — unchanged
#273 undici (expo-purchasely-test) 8.5.0→8.10.0 minor 🟢 Green (7/7) dirty Auto-merge candidate once rebased — see correction below
#272 fast-uri (expo-purchasely-test) 4.1.1→4.1.2 patch 🟢 Green (7/7) dirty Auto-merge candidate once rebased — see correction below

* GitHub reports mergeable_state: unknown while it recomputes; not flagged dirty in this pass, but re-verify before acting.

Root-cause correction on #273/#272: every ·@·d·ependabot r·ebase request posted on those two PRs since 2026-08-27 — including the ones explicitly claiming to be "verbatim this time" — was still posted with obfuscating dots (·@·d·ependabot r·ebase), which Dependabot silently ignores per its own docs. That is almost certainly the entire reason they've sat dirty for a week-plus. A genuinely verbatim ·@·d·ependabot r·ebase (no dots) has just been posted on both.

#274 remains the one PR needing an actual human look: all 7 jobs fail (lint, test, both Android builds, both iOS builds, iOS unit tests) — not the single-job build-ios flake seen on #277/#275 — despite carrying real security fixes.

No hold labels on any of the 8. @kherembourg#288/#287/#276 (once its unknown state clears) look like safe auto-merges whenever you want to give the go-ahead; #274 needs someone to check the job logs.


Generated by Claude Code

@dependabot @github

dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown
Contributor Author

Looks like browserslist is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 2, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/browserslist-4.28.8 branch September 2, 2026 16:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant