deps: bump c8 from 10.1.3 to 11.0.0 - #55
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [c8](https://github.com/bcoe/c8) from 10.1.3 to 11.0.0. - [Release notes](https://github.com/bcoe/c8/releases) - [Changelog](https://github.com/bcoe/c8/blob/main/CHANGELOG.md) - [Commits](bcoe/c8@v10.1.3...v11.0.0) --- updated-dependencies: - dependency-name: c8 dependency-version: 11.0.0 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Backlog-loop verification: checks/tests green except pre-existing base failures (delta: Head (f86c081, c8 11.0.0) vs base (origin/main ce7da5b, c8 10.1.3), both in fresh detached /tmp worktrees: npm test 57/57 pass on BOTH (0 fail); npm run test:coverage exit 0 on BOTH, coverage summary identical — "All files | 82.95 | 68.88 | 82.14 | 82.95"; npm audit totals identical at 19 (1 low, 8 moderate, 10 high) on BOTH, but the affected-node set is strictly better at head: minimatch advisory range narrows from "<=3.1.3 || 9.0.0 - 9.0.6" to "<=3.1.3" and the node list drops node_modules/test-exclude/node_modules/minimatch (c8's own transitive chain); brace-expansion affected nodes drop 3 -> 2 (test-exclude node removed). Remaining minimatch hits at head are eslint-internal (node_modules/@eslint/config-array|eslintrc|eslint/node_modules/minimatch), unrelated to c8. Net: head is equal on every locally reproducible gate and strictly better on advisories — not worse than base. The one red check (claude-review) is repo-wide infra breakage that predates and is independent of this diff.). Independent review: APPROVE. INDEPENDENT GROK REVIEW (reviewer lane "VERDICT: APPROVE PINNED REF: gh pr view 55 headRefOid f86c081 == local PRIMARY VERIFICATION BY EXECUTION (every load-bearing grok claim re-run by me; all confirmed):
NON-BLOCKING OBSERVATIONS (mine, not grok's; none changes the verdict): DEVIATIONS (conservative option taken, as required):
|
Bumps c8 from 10.1.3 to 11.0.0.
Release notes
Sourced from c8's releases.
Changelog
Sourced from c8's changelog.
Commits
ce78df4chore(main): release 11.0.0 (#577)678eecafix(deps)!: pull newer minimatch addressing CVE-2026-26996 (#576)ec4c5e4chore: .editorconfig to avoid unintended mods to .snap files (#556)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)