chore(deps): update dependency minimatch@3>brace-expansion to v5 - #76
chore(deps): update dependency minimatch@3>brace-expansion to v5#76renovate[bot] wants to merge 1 commit into
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #76 +/- ##
=======================================
Coverage 88.89% 88.89%
=======================================
Files 6 6
Lines 1369 1369
Branches 309 253 -56
=======================================
Hits 1217 1217
Misses 152 152 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
1e40625 to
0083b56
Compare
|
🛑 DevSecOps Renovate sweep (TIM-117) — CI gate Required check Please investigate the failing check (or re-run it after fixes) and re-trigger the sweep if appropriate. 🤖 Automated by DevSecOps autopilot |
|
DevSecOps autopilot (TIM-119) — skipped: CI gate failed ( |
|
Skipping — CI is red on this PR (🚫 |
0083b56 to
2ef69b1
Compare
|
Renovate PR — DevSecOps sweep (2026-08-14). CI gate failure blocks auto-merge. Failed check(s):
This is a major version bump (brace-expansion 1.1.16 → 5.0.9, transitive via minimatch@3). Please fix the failing checks. The next sweep will re-evaluate once CI is green. |
|
Renovate sweep — skipped, blocked. MAJOR bump ( |
|
Autopilot: minimatch@3>brace-expansion 1.1.16 → 5.0.9 (major bumps v1 → v5, three majors at once). CI blocked: Lint, Test, Build & Security = FAILURE. Please investigate the lint failure and re-run CI before merging. |
|
DevSecOps sweep: skipping — required check 'Lint, Test, Build & Security' is FAILING. brace-expansion 1.1.16 → 5.0.9 (transitive of minimatch@3) is a MAJOR bump; v5 changed to ES Modules, which commonly breaks CJS call sites. Please triage and rerun. |
timoa
left a comment
There was a problem hiding this comment.
Renovate daily sweep (DevSecOps autopilot, 2026-08-18): this PR updates brace-expansion 1.1.16 → 5.0.9 (transitive via minimatch@3, MAJOR delta). Branch name renovate/minimatch3-brace-expansion-5.x confirms major. Per the autopilot risk-tier policy, major bumps require human approval. CI is also failing on Lint, Test, Build & Security (other checks green). Files: pnpm-lock.yaml + pnpm-workspace.yaml (no package.json change). Skipping auto-merge — please review and address both blockers manually.
|
Daily Renovate sweep: blocked. |
|
Skipping — CI gate failure: |
timoa
left a comment
There was a problem hiding this comment.
DevSecOps daily sweep: classifying as major (brace-expansion 1.1.16 → 5.0.9, transitively pulled in by minimatch@3). Major version jump + CI failing (Lint, Test, Build & Security FAILURE). Skipping auto-merge; requesting human review and a rebase.
|
DevSecOps sweep TIM-173: skipped — failing CI. |
|
DevSecOps auto-merge is blocked: |
timoa
left a comment
There was a problem hiding this comment.
This PR is auto-flagged for human review.
PR #76 bumps brace-expansion (via minimatch@3) from 1.1.16 to 5.0.9 — a major bump (skipping 2, 3, 4). Major bumps require human approval.
CI status: Lint, Test, Build & Security is FAILING. Same v5 brace-expansion behavior change applies here; the failures are likely related. Please review and merge manually if acceptable after triaging the lint breakage.
timoa
left a comment
There was a problem hiding this comment.
DevSecOps autopilot: skipped — MAJOR bump (brace-expansion 1.1.16 → 5.0.9) AND CI failing (Lint, Test, Build & Security = FAILURE). Big version jump through several majors (including ESM-only v3 and v5); please review the breaking changes and the failing build before merging.
2ef69b1 to
56d4e5e
Compare
|
DevSecOps autopilot sweep (2026-08-29). CI failed ( |
|
🤖 Renovate autopilot (DevSecOps, daily sweep @ 2026-08-30): Skipped — CI gate failure (and major version bump). Required check This PR bumps transitive Action needed: Fix the CI failure on |
|
DevSecOps daily Renovate sweep — skipped, blocked.
Note: this would also have required human approval regardless because of the major version jump. No auto-merge performed. |
|
DevSecOps autopilot (daily Renovate sweep). Not merging — CI gate failure. |
|
🤖 Renovate autopilot skipping this PR — required CI check failed. Reason: These PRs also bump |
|
DevSecOps Renovate sweep 2026-09-03: CI is not fully green — the 'Lint, Test, Build & Security' check failed. Skipping auto-merge per the CI gate. The minimatch@3 -> brace-expansion 5.x jump is a major bump in a security-sensitive transitive dep; please rebase once main is green. |
|
Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): skipping — CI failure on |
timoa
left a comment
There was a problem hiding this comment.
Renovate sweep — not auto-merged. Major bump (brace-expansion → v5, override for minimatch@3) with Lint, Test, Build & Security failing. Same reasoning as the sibling PR for minimatch@9 — these two should probably be evaluated and landed together.
|
🤖 Skipping — CI failure. |
|
Holding (DevSecOps autopilot). CI gate failure on the |
timoa
left a comment
There was a problem hiding this comment.
🤖 DevSecOps autopilot (TIM-258) — flagging for human approval.
This PR bumps the transitive minimatch@3>brace-expansion from 1.1.16 → 5.0.9 — a jump across multiple major versions in a single PR. Major bumps (including transitive ones) require human approval per autopilot policy. Additionally, the Lint, Test, Build & Security check is FAILING.
Not approving. Please review the breaking changes across brace-expansion v2→v3/v4/v5 and the failing CI before merging.
|
Skipped by DevSecOps Renovate sweep: CI is failing on this PR (Lint/Test/Build/Security). The autopilot does not auto-merge PRs with red CI. Please investigate the failure or rebase on main once it's fixed. |
This PR contains the following updates:
1.1.16→5.0.9Release Notes
juliangruber/brace-expansion (minimatch@3>brace-expansion)
v5.0.9Compare Source
v5.0.8Compare Source
v5.0.7Compare Source
v5.0.6Compare Source
v5.0.5Compare Source
v5.0.4Compare Source
v5.0.3Compare Source
v5.0.2Compare Source
v4.0.1Compare Source
5a5cc170b6a978v4.0.0Compare Source
278132bdd72a59tea.yaml70e4c1bAs a precaution to not risk breaking anything with
278132b, this is a new semver major releasev3.0.6Compare Source
v3.0.5Compare Source
v3.0.4Compare Source
v3.0.3Compare Source
v3.0.2Compare Source
v3.0.1Compare Source
3059c078229e6f15f9b3cv3.0.0Compare Source
c0360e868c0e379e781e93494c4ddd5a4cb6dad209teste3dd8aed23ede91eb3fa41e7c9cd252053761a94f1dc741cf8ee56265c8756a05978a7v2.1.4Compare Source
v2.1.3Compare Source
v2.1.2Compare Source
v2.1.1Compare Source
c3a817cv2.1.0Compare Source
v2.0.3Compare Source
v2.0.2Compare Source
14f1d91ed7780a36603d5v2.0.1Compare Source
v2.0.0Compare Source
v1.1.18Compare Source
v1.1.17Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.