[dependabot-agent] Bump yaml to 2.9.1 (patch) - #10189
cao-githubnext-gh-aw-cao-write[bot] wants to merge 1 commit into
Conversation
Updates the yaml dependency in the root package and dashboard/site package to the latest patch release. yaml is used by docs/lib/catalog.ts, scripts/package-lifecycle-matrix.mjs, dashboard/site/src/validator.js, and several unit tests. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Duplicate detected. This PR bumps Recommendation: Close this PR in favor of #10419 to avoid redundant review/merge churn. No further dependency-bump action is needed here — the underlying update is already tracked by the other open PR.
|
|
Duplicate dependency bump detected. This PR ( Root cause: three separate Recommendation: close this PR and #10228 in favor of #10419, then delete the stale branch No further action needed from this bot on this PR.
|
|
Duplicate detected: This PR bumps Recommendation: Merge or keep only one of #10189 / #10228 / #10419 and close the other two to avoid confusion and duplicate CI churn. #10419 is the most recent and includes full manifest coverage. No further code change needed here — this is a bookkeeping/triage note only.
|
|
Found three open PRs from this automation that make the identical change (bump
All three have identical diffs (same 4 files, same version bump, same risk profile). Recommend keeping this PR (#10189, the oldest/first) and closing #10228 and #10419 as duplicates to reduce review noise. No new dependency work is being opened in this run to avoid adding a fourth duplicate. Separately: PR #10838 ("Fix undici vulnerabilities via npm override") was closed without merging. The root Control Plane
|
|
Root cause: Three open PRs (#10189, #10228, #10419) independently bump Status: Safe, reviewable, Recommendation: Treat this PR (#10189) as canonical and close #10228 and #10419 as duplicates (see cross-links below) once this one merges, to avoid multiple lockfile-touching bumps of the same dependency landing separately. Next step: Human reviewer: merge this PR, then close #10228 and #10419 as superseded duplicates.
|
|
Duplicate PR consolidation needed Three open pull requests — Verified against current state (this run):
Safe-output tooling available to this agent cannot close pull requests, so consolidation can't be automated here. Recommended: merge
|
|
Consolidation note: two duplicate PRs making this identical Before merging this PR:
|
Dependency Release Train Summary
What changed
yamlpackage.json/package-lock.json(root),dashboard/site/package.json/dashboard/site/package-lock.jsonWhy now
yamlhad a patch release (2.9.1) available in both manifests, which already declare^2.9.0(semver-compatible). No open Dependabot alert or existing PR covers this dependency.Risk assessment
docs/lib/catalog.ts,scripts/package-lifecycle-matrix.mjs); dev dependency indashboard/site(used bydashboard/site/src/validator.jsand its build tooling).require('yaml')/from 'yaml'usages in the files above and intests/unit/workflow-contract.test.mjsandtests/unit/dashboard-site-build.test.mjs.Validation
npm install yaml@2.9.1 --package-lock-only --registry=https://registry.npmjs.org, then fullnpm install --ignore-scripts,npx tsc -p .github/cao/tsconfig.json,npm run test:unitdashboard/site: same lockfile-only update, fullnpm install --ignore-scripts,npm run typecheck,npm testdashboard/siteunit tests: 831/831 tests passed (1 pre-existing failing suite unrelated to this change —node:sqlitebundling intest/unit/data-sqlite-indexeddb.test.js, reproduces identically on unmodifiedmain); root unit tests: same 4–5 pre-existing failures reproduced on unmodifiedmain(activity-cache/workflow-contract sandbox-specific flakiness), none related toyaml.npm run check(lint/test:load/check:svg/compile/docs:build) not run in this sandbox pass; CI is the source of truth for those broader checks.Control Plane
Reviewer checklist
Rollback guidance
yamlback to2.9.0in bothpackage.jsonfiles and regenerate the correspondingpackage-lock.jsonfiles.Smart-Dependabot-Merge-Candidate: yes