Skip to content

chore(deps): update dependency minimatch@3>brace-expansion to v5 - #76

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/minimatch3-brace-expansion-5.x
Open

chore(deps): update dependency minimatch@3>brace-expansion to v5#76
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/minimatch3-brace-expansion-5.x

Conversation

@renovate

@renovate renovate Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
minimatch@3>brace-expansion 1.1.165.0.9 age confidence

Release Notes

juliangruber/brace-expansion (minimatch@3>brace-expansion)

v5.0.9

Compare Source

v5.0.8

Compare Source

v5.0.7

Compare Source

v5.0.6

Compare Source

v5.0.5

Compare Source

v5.0.4

Compare Source

v5.0.3

Compare Source

v5.0.2

Compare Source

v4.0.1

Compare Source


v4.0.0

Compare Source

As a precaution to not risk breaking anything with 278132b, this is a new semver major release

v3.0.6

Compare Source

v3.0.5

Compare Source

v3.0.4

Compare Source

v3.0.3

Compare Source

v3.0.2

Compare Source

v3.0.1

Compare Source


v3.0.0

Compare Source

v2.1.4

Compare Source

v2.1.3

Compare Source

v2.1.2

Compare Source

v2.1.1

Compare Source


v2.1.0

Compare Source

v2.0.3

Compare Source

v2.0.2

Compare Source


v2.0.1

Compare Source

v2.0.0

Compare Source

v1.1.18

Compare Source

v1.1.17

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 6am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@codecov

codecov Bot commented Aug 6, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 88.89%. Comparing base (b5d737c) to head (56d4e5e).

Additional details and impacted files
@@           Coverage Diff           @@
##             main      #76   +/-   ##
=======================================
  Coverage   88.89%   88.89%           
=======================================
  Files           6        6           
  Lines        1369     1369           
  Branches      309      253   -56     
=======================================
  Hits         1217     1217           
  Misses        152      152           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate
renovate Bot force-pushed the renovate/minimatch3-brace-expansion-5.x branch 8 times, most recently from 1e40625 to 0083b56 Compare August 6, 2026 16:35
@timoa

timoa commented Aug 11, 2026

Copy link
Copy Markdown
Owner

🛑 DevSecOps Renovate sweep (TIM-117) — CI gate

Required check Lint, Test, Build & Security is failing on this PR, so the autopilot is skipping it. The CI gate requires a fully green rollup before auto-merge.

Please investigate the failing check (or re-run it after fixes) and re-trigger the sweep if appropriate.

🤖 Automated by DevSecOps autopilot

@timoa

timoa commented Aug 12, 2026

Copy link
Copy Markdown
Owner

DevSecOps autopilot (TIM-119) — skipped: CI gate failed (dependency-review FAILURE; cflite-pr, CodeQL-Build, Detect changes CANCELLED). minimatch@3 transitive bump via brace-expansion — patch-level but CI is broken/cancelled. Please rebase and re-run.

@timoa

timoa commented Aug 13, 2026

Copy link
Copy Markdown
Owner

Skipping — CI is red on this PR (🚫 dependency-review, multiple other checks cancelled). Same root cause as PR #77: a v2→v5 transitive leap of brace-expansion forced via pnpm-workspace.yaml for the minimatch@3 dep path. Not auto-merged; please triage the CI failure and confirm the v2→v5 jump is intended.

@renovate
renovate Bot force-pushed the renovate/minimatch3-brace-expansion-5.x branch from 0083b56 to 2ef69b1 Compare August 13, 2026 13:13
@timoa

timoa commented Aug 14, 2026

Copy link
Copy Markdown
Owner

Renovate PR — DevSecOps sweep (2026-08-14).

CI gate failure blocks auto-merge. Failed check(s):

  • Lint, Test, Build & Security

This is a major version bump (brace-expansion 1.1.16 → 5.0.9, transitive via minimatch@3). Please fix the failing checks. The next sweep will re-evaluate once CI is green.

@timoa

timoa commented Aug 15, 2026

Copy link
Copy Markdown
Owner

Renovate sweep — skipped, blocked. MAJOR bump (minimatch@3>brace-expansion 1.1.16 → 5.0.9) and CI gate failure: Lint, Test, Build & Security is FAILING. Major version jump (four majors!) with breaking changes (ESM-only since 3.0.0, new balancing algorithm in 4.0.0). Please investigate the failing CI and either fix and merge, or close.

@timoa

timoa commented Aug 16, 2026

Copy link
Copy Markdown
Owner

Autopilot: minimatch@3>brace-expansion 1.1.16 → 5.0.9 (major bumps v1 → v5, three majors at once). CI blocked: Lint, Test, Build & Security = FAILURE. Please investigate the lint failure and re-run CI before merging.

@timoa

timoa commented Aug 17, 2026

Copy link
Copy Markdown
Owner

DevSecOps sweep: skipping — required check 'Lint, Test, Build & Security' is FAILING. brace-expansion 1.1.16 → 5.0.9 (transitive of minimatch@3) is a MAJOR bump; v5 changed to ES Modules, which commonly breaks CJS call sites. Please triage and rerun.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate daily sweep (DevSecOps autopilot, 2026-08-18): this PR updates brace-expansion 1.1.16 → 5.0.9 (transitive via minimatch@3, MAJOR delta). Branch name renovate/minimatch3-brace-expansion-5.x confirms major. Per the autopilot risk-tier policy, major bumps require human approval. CI is also failing on Lint, Test, Build & Security (other checks green). Files: pnpm-lock.yaml + pnpm-workspace.yaml (no package.json change). Skipping auto-merge — please review and address both blockers manually.

@timoa

timoa commented Aug 19, 2026

Copy link
Copy Markdown
Owner

Daily Renovate sweep: blocked. minimatch@3>brace-expansion 1.1.16 → 5.0.9 is a major bump (v1 → v5 — multiple major versions including an ESM-only v3), and the Lint, Test, Build & Security check failed. Major-version bumps also require human approval per policy. Please review, fix CI, and merge manually.

@timoa

timoa commented Aug 20, 2026

Copy link
Copy Markdown
Owner

Skipping — CI gate failure: Lint, Test, Build & Security FAILED on this PR. PR bumps transitive brace-expansion 1.1.16 → 5.0.9 (via minimatch@3) (major) and rewrites pnpm-workspace.yaml outside the lockfile. Please triage the failing checks before merging.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps daily sweep: classifying as major (brace-expansion 1.1.16 → 5.0.9, transitively pulled in by minimatch@3). Major version jump + CI failing (Lint, Test, Build & Security FAILURE). Skipping auto-merge; requesting human review and a rebase.

@timoa

timoa commented Aug 22, 2026

Copy link
Copy Markdown
Owner

DevSecOps sweep TIM-173: skipped — failing CI. Lint, Test, Build & Security failed. minimatch@3>brace-expansion 1.1.16 → 5.0.9 (major). CI gate blocks auto-merge. Please fix CI and re-run, or merge manually once green.

@timoa

timoa commented Aug 23, 2026

Copy link
Copy Markdown
Owner

DevSecOps auto-merge is blocked: Lint, Test, Build & Security check failed on the latest run (FAILURE). PR: transitive brace-expansion v1.1.16 → v5.0.9 under minimatch@3 (major). Major bump on a transitive dependency via pnpm overrides — please confirm the override entry is still needed and rerun CI.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR is auto-flagged for human review.

PR #76 bumps brace-expansion (via minimatch@3) from 1.1.16 to 5.0.9 — a major bump (skipping 2, 3, 4). Major bumps require human approval.

CI status: Lint, Test, Build & Security is FAILING. Same v5 brace-expansion behavior change applies here; the failures are likely related. Please review and merge manually if acceptable after triaging the lint breakage.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps autopilot: skipped — MAJOR bump (brace-expansion 1.1.16 → 5.0.9) AND CI failing (Lint, Test, Build & Security = FAILURE). Big version jump through several majors (including ESM-only v3 and v5); please review the breaking changes and the failing build before merging.

@renovate
renovate Bot force-pushed the renovate/minimatch3-brace-expansion-5.x branch from 2ef69b1 to 56d4e5e Compare August 26, 2026 13:46
@timoa

timoa commented Aug 29, 2026

Copy link
Copy Markdown
Owner

DevSecOps autopilot sweep (2026-08-29). CI failed (Lint, Test, Build & Security) — skipping. lockfile-only change would otherwise be auto-mergeable; please rebase and re-run, then re-evaluate on the next daily sweep.

@timoa

timoa commented Aug 30, 2026

Copy link
Copy Markdown
Owner

🤖 Renovate autopilot (DevSecOps, daily sweep @ 2026-08-30):

Skipped — CI gate failure (and major version bump). Required check Lint, Test, Build & Security is FAILING.

This PR bumps transitive brace-expansion from v1.1.16 (via minimatch@3) to v5.0.9 (MAJOR — 1.x → 5.x). Lockfile + pnpm-workspace.yaml only — no workflow files. Major-version updates require human approval.

Action needed: Fix the CI failure on main of workflow-metrics first. Once green, manually verify this transitive bump does not break minimatch v3 consumers; the autopilot does not auto-merge major bumps even when CI is green.

@timoa

timoa commented Aug 31, 2026

Copy link
Copy Markdown
Owner

DevSecOps daily Renovate sweep — skipped, blocked.

Lint, Test, Build & Security check is failing on this PR (minimatch@3>brace-expansion 1.1.16 → 5.0.9, a multi-major bump). The autopilot will not auto-merge with a failing required status check. To unblock: investigate the lint/build failure (likely the ESM-only v5 surface in a CJS context).

Note: this would also have required human approval regardless because of the major version jump. No auto-merge performed.

@timoa

timoa commented Sep 1, 2026

Copy link
Copy Markdown
Owner

DevSecOps autopilot (daily Renovate sweep). Not merging — CI gate failure. Lint, Test, Build & Security failed on the latest run (2026-08-26). This is a major bump of brace-expansion (transitive of minimatch@3) from 1.1.16 to 5.0.9, touching pnpm-lock.yaml and pnpm-workspace.yaml. Major bumps of a glob-expansion helper are sensitive — please investigate the Lint/Test/Build failure, address any breaking changes, re-run CI, and I will pick it up on the next sweep.

@timoa

timoa commented Sep 2, 2026

Copy link
Copy Markdown
Owner

🤖 Renovate autopilot skipping this PR — required CI check failed.

Reason: Lint, Test, Build & Security check failed.

These PRs also bump brace-expansion to v5 across multiple transitive paths — a wider-reaching change worth human review even once CI is green.

@timoa

timoa commented Sep 3, 2026

Copy link
Copy Markdown
Owner

DevSecOps Renovate sweep 2026-09-03: CI is not fully green — the 'Lint, Test, Build & Security' check failed. Skipping auto-merge per the CI gate. The minimatch@3 -> brace-expansion 5.x jump is a major bump in a security-sensitive transitive dep; please rebase once main is green.

@timoa

timoa commented Sep 4, 2026

Copy link
Copy Markdown
Owner

Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): skipping — CI failure on Lint, Test, Build & Security. Same situation as PR #77 but for minimatch@3's transitive brace-expansion (1.1.16 → 5.0.9). Major bump on a transitive dep; please fix CI before merging.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate sweep — not auto-merged. Major bump (brace-expansion → v5, override for minimatch@3) with Lint, Test, Build & Security failing. Same reasoning as the sibling PR for minimatch@9 — these two should probably be evaluated and landed together.

@timoa

timoa commented Sep 6, 2026

Copy link
Copy Markdown
Owner

🤖 Skipping — CI failure. Lint, Test, Build & Security is FAILING on this Renovate PR (brace-expansion lockfile bump via minimatch@3). The autopilot will not merge PRs whose required status checks are not fully green. Please fix the failing job (see https://github.com/timoa/workflow-metrics/actions/runs/31077949041) and re-trigger, or merge manually once CI is green.

@timoa

timoa commented Sep 7, 2026

Copy link
Copy Markdown
Owner

Holding (DevSecOps autopilot). CI gate failure on the Lint, Test, Build & Security check. This is a major-version bump of the transitive brace-expansion package (used by minimatch@3, 1.1.16 → 5.0.9). v4.0.0 / v5.0.0 are documented as breaking. Lockfile + pnpm-workspace.yaml diff only, but the bump crosses multiple majors — needs human review. Skipping auto-merge.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 DevSecOps autopilot (TIM-258) — flagging for human approval.

This PR bumps the transitive minimatch@3>brace-expansion from 1.1.16 → 5.0.9 — a jump across multiple major versions in a single PR. Major bumps (including transitive ones) require human approval per autopilot policy. Additionally, the Lint, Test, Build & Security check is FAILING.

Not approving. Please review the breaking changes across brace-expansion v2→v3/v4/v5 and the failing CI before merging.

@timoa

timoa commented Sep 9, 2026

Copy link
Copy Markdown
Owner

Skipped by DevSecOps Renovate sweep: CI is failing on this PR (Lint/Test/Build/Security). The autopilot does not auto-merge PRs with red CI. Please investigate the failure or rebase on main once it's fixed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant