Skip to content

Update dependency c8 to v12 - #329

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/c8-12.x
Open

Update dependency c8 to v12#329
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/c8-12.x

Conversation

@renovate

@renovate renovate Bot commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
c8 ^10.1.3^12.0.0 age confidence

Release Notes

bcoe/c8 (c8)

v12.0.0

Compare Source

⚠ BREAKING CHANGES
  • yargs enforces a stricter range of Node versions ^20.19.0 || ^22.12.0 || >=23
Features

v11.0.0

Compare Source

⚠ BREAKING CHANGES
  • deps: transitive deps require 20 || >=22
Bug Fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@codeant-ai

codeant-ai Bot commented Jul 17, 2026

Copy link
Copy Markdown

Skipping PR review because a bot author is detected.

If you want to trigger CodeAnt AI, comment @codeant-ai review to trigger a manual review.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 4 security issues

Security issues:

  • BlueOak-1.0.0: Open-source license could not be identified (link)
  • BlueOak-1.0.0: Open-source license could not be identified (link)
  • BlueOak-1.0.0: Open-source license could not be identified (link)
  • BlueOak-1.0.0: Open-source license could not be identified (link)
Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path="package-lock.json" line_range="2365-2382" />
<code_context>

</code_context>
<issue_to_address>
**security (license/glob):** BlueOak-1.0.0: Open-source license could not be identified

The obligations of the `BlueOak-1.0.0` license for this code could not be determined automatically. Unknown licenses may carry obligations or restrictions and should be reviewed manually to ensure compliance

*Source: trivy*
</issue_to_address>

### Comment 2
<location path="package-lock.json" line_range="2383-2392" />
<code_context>

</code_context>
<issue_to_address>
**security (license/lru-cache):** BlueOak-1.0.0: Open-source license could not be identified

The obligations of the `BlueOak-1.0.0` license for this code could not be determined automatically. Unknown licenses may carry obligations or restrictions and should be reviewed manually to ensure compliance

*Source: trivy*
</issue_to_address>

### Comment 3
<location path="package-lock.json" line_range="1658-1659" />
<code_context>

</code_context>
<issue_to_address>
**security (license/minimatch):** BlueOak-1.0.0: Open-source license could not be identified

The obligations of the `BlueOak-1.0.0` license for this code could not be determined automatically. Unknown licenses may carry obligations or restrictions and should be reviewed manually to ensure compliance

*Source: trivy*
</issue_to_address>

### Comment 4
<location path="package-lock.json" line_range="1660-1668" />
<code_context>

</code_context>
<issue_to_address>
**security (license/minipass):** BlueOak-1.0.0: Open-source license could not be identified

The obligations of the `BlueOak-1.0.0` license for this code could not be determined automatically. Unknown licenses may carry obligations or restrictions and should be reviewed manually to ensure compliance

*Source: trivy*
</issue_to_address>

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

Comment thread package-lock.json
Comment thread package-lock.json
Comment thread package-lock.json
Comment thread package-lock.json
@codecov

codecov Bot commented Jul 17, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (eca59bd) to head (67a8a72).

Additional details and impacted files
@@            Coverage Diff            @@
##            master      #329   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files            2         2           
  Lines          470       470           
=========================================
  Hits           470       470           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@llamapreview llamapreview Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto Pull Request Review from LlamaPReview

Review Status: Automated Review Skipped

Dear contributor,

Thank you for your Pull Request. LlamaPReview has analyzed your changes and determined that this PR does not require an automated code review.

Analysis Result:

PR contains only dependency version bumps (c8 from ^10.1.3 to ^12.0.0) and associated lock file updates, with no substantive code changes.

We're continuously improving our PR analysis capabilities. Have thoughts on when and how LlamaPReview should perform automated reviews? Share your insights in our GitHub Discussions.

Best regards,
LlamaPReview Team

@renovate
renovate Bot force-pushed the renovate/c8-12.x branch from f815c58 to 67a8a72 Compare July 24, 2026 21:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants