build(deps): bump js-yaml and antora in /antora - #559
Conversation
Bumps [js-yaml](https://github.com/nodeca/js-yaml) to 5.4.1 and updates ancestor dependency [antora](https://gitlab.com/antora/antora/tree/HEAD/packages/antora). These dependencies need to be updated together. Updates `js-yaml` from 4.1.0 to 5.4.1 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](nodeca/js-yaml@4.1.0...5.4.1) Updates `antora` from 3.1.12 to 3.2.0 - [Changelog](https://gitlab.com/antora/antora/blob/main/CHANGELOG.adoc) - [Commits](https://gitlab.com/antora/antora/compare/v3.1.12...v3.2.0) --- updated-dependencies: - dependency-name: js-yaml dependency-version: 5.4.1 dependency-type: indirect - dependency-name: antora dependency-version: 3.2.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
🤖 Finished Review · ✅ Success · Started 7:59 PM UTC · Completed 8:08 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.77 |
|
Looks good to me |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
|
🤖 Finished Retro · ✅ Success · Started 3:13 PM UTC · Completed 3:18 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $1.86 |
Retro: PR #559Timeline. Dependabot opened a PR bumping Diagnosis. The agent's substantive analysis was actually sound (grep found no direct Two secondary infra findings from the trace:
Existing-issue check. Related open work that partially overlaps but does not cover the Renovate-vs-Dependabot policy angle: agents#448/#449/#616 (scope escalation for major lockfile bumps), fullsend#3015 & #3049 (breaking-change screening for Renovate PRs), agents#280 (LGTM-only bodies), agents#501 (suppress Proposals filed: 3 — see linked issues. Proposals filed
Proposals skipped (target repo not allowed)File manually or update
|
Bumps js-yaml to 5.4.1 and updates ancestor dependency antora. These dependencies need to be updated together.
Updates
js-yamlfrom 4.1.0 to 5.4.1Changelog
Sourced from js-yaml's changelog.
... (truncated)
Commits
e5a3ba05.4.1 releasede54dea3Hard-limit merge sequence size to 100dfd3a29Cleanup 6a8e05f, #7976a8e05ffix: count empty merge sources against maxTotalMergeKeys (#797)6b4ff5e5.4.0 released3b3625eUpdate changelog4f25a74Fix file name3bd003bExpose new scalar styling APIfbb3e9dRemove regex lookbehind for ES2015 compatibilityd43c185FixflowSkipColonSpaceby forcingquoteFlowKeysUpdates
antorafrom 3.1.12 to 3.2.0Changelog
Sourced from antora's changelog.
... (truncated)
Commits
85665d0release 3.2.079f23d7add Node.js 26 to test matrix04c952aupgrade xmldom4b923edupdate declared supported versions of Node.jsecc28ebupdate release date on what's new page03b788cadd missing entries from what's new page058f436apply pending formatting to example code9452ccaupgrade js-yaml621fe93refresh dependency lock file57a244eremove unused imagesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.