Skip to content

deps: bump c8 from 10.1.3 to 11.0.0 - #55

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/c8-11.0.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/c8-11.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 2, 2026

Copy link
Copy Markdown
Contributor

Bumps c8 from 10.1.3 to 11.0.0.

Release notes

Sourced from c8's releases.

v11.0.0

11.0.0 (2026-02-22)

⚠ BREAKING CHANGES

  • deps: transitive deps require 20 || >=22

Bug Fixes

Changelog

Sourced from c8's changelog.

11.0.0 (2026-02-22)

⚠ BREAKING CHANGES

  • deps: transitive deps require 20 || >=22

Bug Fixes

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [c8](https://github.com/bcoe/c8) from 10.1.3 to 11.0.0.
- [Release notes](https://github.com/bcoe/c8/releases)
- [Changelog](https://github.com/bcoe/c8/blob/main/CHANGELOG.md)
- [Commits](bcoe/c8@v10.1.3...v11.0.0)

---
updated-dependencies:
- dependency-name: c8
  dependency-version: 11.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Mar 2, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@robotlearning123

Copy link
Copy Markdown
Member

Backlog-loop verification: checks/tests green except pre-existing base failures (delta: Head (f86c081, c8 11.0.0) vs base (origin/main ce7da5b, c8 10.1.3), both in fresh detached /tmp worktrees: npm test 57/57 pass on BOTH (0 fail); npm run test:coverage exit 0 on BOTH, coverage summary identical — "All files | 82.95 | 68.88 | 82.14 | 82.95"; npm audit totals identical at 19 (1 low, 8 moderate, 10 high) on BOTH, but the affected-node set is strictly better at head: minimatch advisory range narrows from "<=3.1.3 || 9.0.0 - 9.0.6" to "<=3.1.3" and the node list drops node_modules/test-exclude/node_modules/minimatch (c8's own transitive chain); brace-expansion affected nodes drop 3 -> 2 (test-exclude node removed). Remaining minimatch hits at head are eslint-internal (node_modules/@eslint/config-array|eslintrc|eslint/node_modules/minimatch), unrelated to c8. Net: head is equal on every locally reproducible gate and strictly better on advisories — not worse than base. The one red check (claude-review) is repo-wide infra breakage that predates and is independent of this diff.). Independent review: APPROVE.

INDEPENDENT GROK REVIEW (reviewer lane grok, status active per harness/fleet-quota/lanes.tsv, verified 2026-09-22). Writer was dependabot (bot), reviewer grok — writer != reviewer holds. Call ran ONCE, exit 0, no timeout/retry needed. Verbatim grok output tail:

"VERDICT: APPROVE
No findings.
The diff is the c8 10.1.3 -> 11.0.0 bump in package.json:83 and the matching lockfile update. c8 11.0.0's only breaking change is node 20 || >=22 (package-lock.json:1468), which matches this repo's CI matrix (20.x and 22.x). The nested minimatch@9.0.5 copy is gone; coverage resolves to hoisted minimatch@10.2.4 (package-lock.json:3127), which is above the CVE-2026-26996 fix (10.2.1). Registry integrity for c8@11.0.0 and test-exclude@8.0.0 matches the lockfile. npm ci left the lockfile unchanged, and npm run test:coverage passed 57/57 under c8 11.0.0."

PINNED REF: gh pr view 55 headRefOid f86c081 == local git rev-parse FETCH_HEAD f86c081 (fetched via git fetch origin pull/55/head). Worktree HEAD f86c081. Diff is deterministic: git diff --stat origin/main...HEAD -> package-lock.json | 331 +++---, package.json | 2 +- (2 files, 16 insertions, 317 deletions).

PRIMARY VERIFICATION BY EXECUTION (every load-bearing grok claim re-run by me; all confirmed):

  1. package.json:83 -> "c8": "^11.0.0" (sed -n '83p'). package.json diff is exactly 1 line; no source/test files touched.
  2. package-lock.json c8 entry engines "node": "20 || >=22" (sed -n '1462,1478p'; grok cited line 1468, block sits 1468-1470).
  3. minimatch claim CONFIRMED by python3 diff of both lockfiles: on origin/main there is node_modules/test-exclude/node_modules/minimatch -> 9.0.5; at PR head that nested copy is gone and only node_modules/minimatch -> 10.2.4 remains (sed -n '3127' shows the 10.2.4 entry at exactly that line, integrity sha512-oRjTw/97aTBN0R...).
  4. npm ci --no-audit --no-fund -> "added 304 packages in 925ms", then git status --porcelain -- package-lock.json package.json -> EMPTY (lockfile unchanged, confirming grok's claim; this also validates every registry integrity hash in the PR's lockfile, which is the strong form of grok's "integrity matches" claim).
  5. Installed binary: ./node_modules/.bin/c8 --version -> 11.0.0.
  6. npm run test:coverage (script = c8 --reporter=text --reporter=lcov tsx --test test/*.test.ts) -> exit 0, coverage table rendered, "# tests 57 / # pass 57 / # fail 0 / # cancelled 0 / # skipped 0 / # todo 0". Exactly matches grok's 57/57. No skipped/xfail masking.

NON-BLOCKING OBSERVATIONS (mine, not grok's; none changes the verdict):
a) The lockfile also flips its version fields 0.1.0 -> 0.2.0. This is stale-lockfile sync, not scope creep: git show origin/main:package.json already reports version 0.2.0, while main's lockfile still said 0.1.0; dependabot's regeneration corrected the drift. Lockfile-only, no code impact.
b) engines asymmetry: repo package.json engines is >=20.0.0, which nominally admits Node 21, while c8@11 (and test-exclude@8) require 20 || >=22. Theoretical only: no .npmrc/engine-strict exists (verified absent), no CI lane uses 21 (.github/workflows/ci.yml matrix is ['20.x','22.x']; other workflows use 20), node 21 is EOL, and local run on v22.22.0 passes.
c) The minimatch CVE benefit is partial: node_modules/eslint/node_modules/minimatch -> 3.1.2 (plus two more nested 3.1.2 copies under @eslint) exist identically on main and at PR head — pre-existing, untouched by this PR, not a regression.
d) unverified: the specific threshold "10.2.1 is the CVE-2026-26996 fix version" comes from the dependabot PR body/release notes and I did not independently confirm it against the advisory; the factual comparison (hoisted 10.2.4 > 10.2.1, and the vulnerable 9.0.5 copy removed) is verified.
e) gh pr view 55 reports state OPEN, mergeable MERGEABLE, mergeStateStatus BLOCKED. Per repo notes claude-review is broken repo-wide (baseline-delta), so BLOCKED is a CI-gate condition, not this review's verdict. APPROVE here is a code-review verdict only; the loop's safety contract forbids merging/approving on the PR itself, and I performed no repo mutation beyond the temporary /tmp worktree.
f) Test-coverage rule check: this PR adds no production code (1 devDependency line + lockfile), so the "production PRs include tests" rule is not triggered; the existing suite was re-run green under the new c8.

DEVIATIONS (conservative option taken, as required):

  1. The prescribed worktree /tmp/loop-wt-agent-next_agent-ready-pr55 did not exist (ls: No such file or directory), so step 1's in-worktree fetch was impossible; I pre-created it with git worktree add --detach /tmp/loop-wt-agent-next_agent-ready-pr55 f86c08192297f30cb7f7e831a0c670578a73ce6a from the freshly fetched PR head, then ran the step-1 git fetch origin --prune inside it. The main working tree was never mutated; only worktree metadata was added and then removed.
  2. The step-2 prompt's literal token "PR-head" is an unsubstituted workflow placeholder; I replaced it in the prompt with the ref I resolved by execution (f86c081, branch dependabot/npm_and_yarn/c8-11.0.0) so grok reviewed the correct revision. All other prompt wording is verbatim; the command as run is reported in reviewer_cmd.
  3. Grok 1.0.41 --help confirms -p, --single <PROMPT> and --always-approve exist as used. grok-4.7 is the lane's main tier per lanes.tsv.
  4. No PR comment was posted. STEPS 1-4 do not request one, and the safety contract only permits (never requires) comments on foreign-head PRs; posting is left to the orchestration layer. Nothing was pushed; no approvals, no merges, no branch or settings changes.
  5. Temp hygiene: /tmp/grok-pr55-review.log was captured for parsing, its content is quoted in full above, then deleted (the reviewer_cmd regenerates it). Verified no residue: /tmp/loop-wt-agent-next_agent-ready-pr55 removed and absent; git worktree list is back to the 3 pre-existing entries (main, luna-agent-ready-pr71-fix-20260922, portfolio-agent-ready-v2-copy-20260922-125500); the other 3 /tmp/loop-wt-* dirs belong to other lanes and were left untouched.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant