Skip to content

fix(deps): batch low-risk dependency updates - #8585

Merged
sarahetter merged 1 commit into
mainfrom
chore/batch-low-risk-deps
Oct 7, 2026
Merged

sarahetter merged 1 commit into
mainfrom
chore/batch-low-risk-deps

Conversation

@sarahetter

Copy link
Copy Markdown
Contributor

Rolls several open bot PRs into one, so they only need one CI cycle and one approval. Under the strict up-to-date rule, merging them one by one means re-running CI each time.

Lockfile changes

Package Change Notes
fast-uri 3.1.4 → 3.1.8 security, 8 advisories (replaces #8583)
@fastify/busboy 3.2.1 → 3.2.2 security, GHSA-gxm5-99cw-xjw9 (replaces #8577)
brace-expansion 1.1.18 → 1.1.21, 2.1.4 → 2.1.7, 5.0.9 → 5.0.12 every nested copy (replaces #8584)

package.json range bumps

The lockfile already resolves these versions, so nothing installed changes:

Not included

Verification

  • npm ci, npm run build, npm run typecheck, npm run lint and npm run format:check all pass.
  • Unit tests: 81 files, 721 tests pass on Node 24.18.
  • On Node 26, generate-autocompletion.test.ts fails its snapshot on main as well. sortOptions returns -1 whenever either side is a base flag, which is not a consistent ordering, so the result depends on V8's sort implementation. That bug predates this PR.

🤖 Generated with Claude Code

- fast-uri 3.1.4 → 3.1.8 (security)
- @fastify/busboy 3.2.1 → 3.2.2 (security)
- brace-expansion patch bumps across all nested copies
- raise ranges for @netlify/server-dev, @netlify/images,
  @netlify/edge-functions and @netlify/types to the versions the
  lockfile already resolves

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sarahetter
sarahetter requested a review from a team as a code owner October 6, 2026 19:24
@sarahetter
sarahetter enabled auto-merge (squash) October 6, 2026 19:25
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Team
  • Run ID: 5e0b534a-a9fe-4292-9853-0db08544c0c5
📥 Commits

Reviewing files that changed from the base of the PR and between 2f8546e and ffbb61b.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • package.json
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. 9 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 10 reviews per hour. Your free on-demand review promotion remains active until October 9, 2026 at 6:00 PM UTC.


📝 Summary

Summary by CodeRabbit

  • Chores
    • Updated project maintenance components. These changes do not affect visible features or behavior.

Walkthrough

The package.json dependency ranges for @netlify/edge-functions, @netlify/images, and @netlify/server-dev are raised. The development dependency range for @netlify/types is also raised.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Suggested reviewers: serhalp

Merge Risk: ⚪ Minimal · up to ffbb6

The dependency ranges and lockfile are consistent, and the four range changes do not alter resolved versions. No actionable merge-blocking risk is established.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: batching dependency updates.
Description check ✅ Passed The description explains the dependency updates, their rationale, exclusions, and reported verification results.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

📊 Benchmark results

Comparing with 2f8546e

  • Dependency count: 1,014 (no change)
  • Package size: 374 MB ⬆️ 0.04% increase vs. 2f8546e
  • Number of ts-expect-error directives: 331 (no change)

@pkg-pr-new

pkg-pr-new Bot commented Oct 6, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/netlify-cli@8585

commit: ffbb61b

@sarahetter
sarahetter disabled auto-merge October 7, 2026 16:12
@sarahetter
sarahetter merged commit edd9f44 into main Oct 7, 2026
37 checks passed
@sarahetter
sarahetter deleted the chore/batch-low-risk-deps branch October 7, 2026 16:12
sarahetter pushed a commit that referenced this pull request Oct 8, 2026
🤖 I have created a release *beep* *boop*
---


## [27.12.0](v27.11.2...v27.12.0)
(2026-10-08)


### Features

* **init:** install Netlify agent skills by default
([#8555](#8555))
([f3d7e82](f3d7e82))
* **init:** sync installed skills with the manifest
([#8556](#8556))
([332666c](332666c))


### Bug Fixes

* **deps:** batch low-risk dependency updates
([#8585](#8585))
([edd9f44](edd9f44))
* **deps:** update content-type to v3 and read the header string
directly ([#8572](#8572))
([969145c](969145c))
* **dev:** use URL separators for static file paths
([#8593](#8593))
([626224b](626224b))
* **init:** report skill sync outcomes accurately on the first run
([#8580](#8580))
([0f2b082](0f2b082))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: token-generator-app[bot] <82042599+token-generator-app[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants