Bump the npm-security group across 1 directory with 2 updates#4052
Bump the npm-security group across 1 directory with 2 updates#4052dependabot[bot] wants to merge 2 commits into
Conversation
size-limit report 📦
|
|
CI process update after #4036 merged: Please rebase or otherwise update this PR onto current Post-merge audit tracker: #4055 Legacy labels currently present here: Recommended update path:
Vocabulary changes:
|
Bumps the npm-security group with 2 updates in the / directory: [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) and [form-data](https://github.com/form-data/form-data). Updates `@babel/core` from 7.28.5 to 7.29.6 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.29.6/packages/babel-core) Updates `form-data` from 4.0.5 to 4.0.6 - [Release notes](https://github.com/form-data/form-data/releases) - [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md) - [Commits](form-data/form-data@v4.0.5...v4.0.6) --- updated-dependencies: - dependency-name: "@babel/core" dependency-version: 7.29.6 dependency-type: direct:production dependency-group: npm-security - dependency-name: form-data dependency-version: 4.0.6 dependency-type: direct:development dependency-group: npm-security ... Signed-off-by: dependabot[bot] <support@github.com>
5d10f86 to
069c2ce
Compare
* origin/main: (40 commits) feat(pro): use built-in Rails i18n compiler for React Intl demo (#4128) Fix pr-merge-ledger UTF-8 crash under non-UTF-8 locale (#4123) Add canonical AI-agent prompts source (prompts.yml) (#4124) Local benchmark runner: raise server-boot timeout for slower machines (#4073) (#4125) Docs(generator): note Pro production devtool for source-mapped SSR stacks (#3893) (#4113) docs: add "Consuming an Unreleased Build" guide and fix pnpm git-subdir syntax (#4117) Address deferred AI-review feedback on PR-helper scripts (#4069) (#4105) Wrap generated demo file paths in onboarding page (Part 1 of #4062) (#4107) fix(ci): build bundle-size base from PR merge commit's first parent (#4110) Add internal RSC architecture deep-dive docs (RoR Pro vs Next.js) (#4006) Disable noisy automatic benchmark regression issue filing (#4071) (#4116) Release-train branching + phase-tiered merge gating (beta/RC/final) (#4018) Fix Webpack dependency selection in install generator (#4109) Document health-probe status-code contract and Control Plane probes (#4053) (#4063) Local dedicated-hardware benchmark runner (#4073) (#4088) docs(tooling): surface SVG diagram alt text in generated llms-full files (#4087) docs(agents): codify review-loop convergence + local/CI parity in PR-batch workflow (#4101) Split RenderFunction: drop the legacy renderer arm (#4096) Add OSS hydrate_on scheduling (#4037) Docs: fix stale evaluate-issue gate cross-reference (#3910) (#4104) ...
|
+ci-status |
CI StatusHead SHA: Only the required gate is active unless hosted CI is requested. |
|
+ci-force-full |
Force-Full Hosted CI RequestedTriggered 9 workflow(s) for View progress in the Actions tab. |
Dependency Security Update ReviewPR: Bump npm-security group — OverviewThis is a Dependabot security update touching 4 files: two Security Assessment
The changelog entry reads:
This is a header injection fix. Unescaped CR ( Even though
Notable fixes across the range:
None of these are security-relevant; they are correctness and tooling improvements. All are within the existing Diff Quality
Verdict✅ Approve and merge. This is a clean, well-scoped security update. The |
Agent blocker noteI updated this PR onto current Dependency update validation is clean locally for the package/lockfile surface:
Hosted force-full CI is currently blocked by a Pro dummy setup issue introduced on current
All three fail during locale generation with: I reproduced the same failure locally with: cd react_on_rails_pro/spec/dummy
RAILS_ENV=test NODE_ENV=test bin/shakapacker-precompile-hookRoot-cause evidence: #4128 changed the Pro dummy to import generated locale modules from Next action: add/track the Pro dummy generated locale output directory, or adjust the locale compiler/hook to create configured output directories before validation. I did not push that Pro-dummy fix here because it widens this Dependabot PR into Pro package setup changes. |
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
|
Closing to keep the 17.0.0 release focused. Tracked in #4187 for later consolidation — reopen or comment |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Bumps the npm-security group with 2 updates in the / directory: @babel/core and form-data.
Updates
@babel/corefrom 7.28.5 to 7.29.6Release notes
Sourced from @babel/core's releases.
... (truncated)
Commits
04ea6b2v7.29.699f498a[7.x packport]Improve input source map handling (#18001)feba0a3Preserve original identifier names from input sourcemaps (#17992) (#17998)aa8394ev7.29.0ad0d03f[7.x backport] feat: Allow specifying startLine in code frame (#17739)d7f4008v7.28.6e130225Polish(standalone): improve message on invalid preset/plugin (#17606)99dcba5chore: enable some ts-eslint rules (#17592)c92c491Improve Unicode handling in code-frame tokenizer (#17589)d725e39AddBABEL_7_TO_8_DANGEROUSLY_DISABLE_VERSION_CHECK(#17569)Updates
form-datafrom 4.0.5 to 4.0.6Changelog
Sourced from form-data's changelog.
Commits
64190dbv4.0.692ae0eb[Deps] updatehasown,mime-typesf31d21e[Dev Deps] update@ljharb/eslint-config,auto-changelog,tape8dff42c[Fix] escape CR, LF, and"in field names and filenames67b0f65[Dev Deps] updatejs-randomness-predictorAgent Merge Criteria
Status: blocked; not mergeable on 2026-06-20 without an explicit maintainer waiver of the full hosted failures.
9c708504d4d1b6b2ff7162285175c2a1c4a2b39a.main; release tracker Release gate: react_on_rails 17.0.0 #3823Agent Release Modeblock readsMode: development.agent-coord doctor/statustimed out, so backend phase was not used.gh pr checks 4052 --repo shakacode/react_on_rails --requiredcurrently showsrequired-pr-gatepassing, and.agents/skills/pr-batch/bin/pr-ci-readiness 4052 --repo shakacode/react_on_railsnow returnsREADYbecause required checks are configured.ready-for-hosted-ci+force-full-hosted-cilabels;gh pr checksshows 43 pass / 14 skipping / 3 failing.build-dummy-app-webpack-test-bundles(https://github.com/shakacode/react_on_rails/actions/runs/27853711881/job/82437369686),dummy-app-rspack-rsc-runtime-gate(https://github.com/shakacode/react_on_rails/actions/runs/27853711881/job/82437369677), andbuild-dummy-app-webpack-test-bundles(https://github.com/shakacode/react_on_rails/actions/runs/27853711889/job/82437386705).UNSTABLE.script/pr-merge-ledger 4052 --repo shakacode/react_on_rails --changelog-classification not_user_visible --strictpassed withcomplete_allowed: true, 0 unknown fields, and 0 violations; this does not override failing full hosted CI.pnpm-lock.yamlchanges are present and were reviewed as dependency maintenance.