Skip to content

fix(dependencies): refresh browserslist lock path - #3322

Merged
drewstone merged 1 commit into
developfrom
security/dependabot-browserslist-20260902
Sep 2, 2026
Merged

fix(dependencies): refresh browserslist lock path#3322
drewstone merged 1 commit into
developfrom
security/dependabot-browserslist-20260902

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Summary

  • refresh the remaining high Dependabot path for browserslist
  • consolidate the Yarn lockfile on browserslist 4.28.8
  • keep the development-only advisory out of runtime dependency paths

Verification

  • yarn install --immutable
  • yarn nx run-many --all --target=typecheck --outputStyle=static
  • pre-push hook: lint, test, and build

Live baseline before merge: 0 critical / 1 high (#420). No alert was dismissed.

@tangletools tangletools left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved drewstone PR — 1fe6233d

This PR was opened by the trusted drewstone account.
The full PR reviewer audit still runs separately and will publish findings if it detects issues.

This approval is provisional. It rests on the audit running. If the audit cannot run — for example the CLI bridge rejects it — this approval is dismissed rather than left standing, so an unrun check never reads as a passing one.

tangletools · auto-approval · reason: drewstone_author · 2026-09-02T00:19:54Z

@drewstone
drewstone merged commit 25ff798 into develop Sep 2, 2026
9 checks passed
@drewstone
drewstone deleted the security/dependabot-browserslist-20260902 branch September 2, 2026 00:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants