Repository navigation
[codex] Refresh vitest security update lockfile - #201
Conversation
bda2e8f to
2e3d419
Compare
|
Repaired the branch behind this PR and re-published it on
GitHub still reports the critical alert on the default branch until this PR merges, but the branch attached to |
|
The previous CI failure is stale relative to the current branch state. Fresh local verification on 2026-06-03 against both the PR head (
Rerunning the GitHub CI workflow now against the current PR head. |
|
Published a follow-up lockfile-only fix for GitHub Actions npm 10 compatibility. Root cause from this heartbeat:
Fresh local verification before push:
Waiting on the new CI run triggered by commit |
|
Executor follow-up from June 3, 2026:
This is now waiting on a maintainer policy decision about keeping or dropping Node 18 in CI/support before the PR can merge cleanly. |
Co-Authored-By: Paperclip <noreply@paperclip.ing>
|
Published a CI-only follow-up at
Fresh verification before push:
Fresh GitHub CI run is now in progress on this commit: https://github.com/biggora/express-useragent/actions/runs/26869900929 |
Summary
vitestfrom^4.0.5to^4.1.0package-lock.jsonso the dependency graph matches the manifestRoot cause
PR #200 updated the Vitest manifest entry but the branch state still failed
npm cibecause the lockfile was not in sync with the declared dependency graph.Validation
npm ci --ignore-scriptsnpm audit --audit-level=critical --jsonnpm testNotes
This draft PR is the equivalent fix path for Dependabot PR #200.