chore(deps): bump picomatch from 4.0.3 to 4.0.4 in /playground in the npm_and_yarn group across 1 directory - #46
Merged
Ndevu12 merged 3 commits intoMar 28, 2026
Conversation
Bumps the npm_and_yarn group with 1 update in the /playground directory: [picomatch](https://github.com/micromatch/picomatch). Updates `picomatch` from 4.0.3 to 4.0.4 - [Release notes](https://github.com/micromatch/picomatch/releases) - [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md) - [Commits](micromatch/picomatch@4.0.3...4.0.4) --- updated-dependencies: - dependency-name: picomatch dependency-version: 4.0.4 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
Ndevu12
deleted the
dependabot/npm_and_yarn/playground/npm_and_yarn-3f9ee708be
branch
March 28, 2026 19:10
Ndevu12
added a commit
that referenced
this pull request
Jul 31, 2026
Closes 16 of the 18 open Dependabot alerts on the root yarn.lock. (The remaining tar alerts are handled separately in #104.) Direct devDependencies — manifest floor raised alongside the lockfile: vite ^8.0.0 -> ^8.0.16 (resolves 8.2.0) #54 high, #55 medium concurrently ^10.0.0 -> ^10.0.4 #86 high (via shell-quote) concurrently 10.0.4 pins shell-quote 1.9.0 exactly, so bumping the real parent fixes shell-quote properly rather than forcing it with a resolutions override. shell-quote 1.8.4 is gone from the tree entirely. Transitive — lockfile only, all within existing declared ranges: @babel/core 7.29.0 -> 7.29.7 #68 brace-expansion 1.1.12 -> 1.1.18 #103 brace-expansion 5.0.4 -> 5.0.9 #81 js-yaml 4.1.1 -> 4.3.1 #80, #101 postcss 8.5.15 -> 8.5.25 #119 undici 7.24.4 -> 7.29.0 #71, #72, #73, #74, #76, #77 ws 8.19.0 -> 8.21.1 #67 Raising vite to ^8.0.16 initially left a second vite 8.0.8 behind an unrelated `^6 || ^7 || ^8` range, which kept a vulnerable postcss 8.5.15 alive. `yarn up -R` plus `yarn dedupe` collapses both to a single copy, so no stale vulnerable duplicate remains. vite 8.2.0 warns that `__dirname` is unsupported under the native config loader that becomes the default in a future major. Migrated both root vite configs to `import.meta.dirname` so the bump leaves no new warning behind. Available since Node 20.11; CI runs Node 20.x. Verified: build, 286 unit tests, typecheck, lint, format:check, verify:demos. Not fixed here — both blocked upstream, neither reachable in this project: #50 esbuild (low) tsup 8.5.1 is the latest release and pins esbuild ^0.27.0, so 0.28.1 is unreachable without overriding a transitive pin. The advisory is a Windows-only path traversal in the esbuild dev server (servedir); tsup uses the bundler API and never starts that server. #46 uuid (medium) @storybook/addon-actions 8.6.18 pins uuid ^9.0.0. Storybook 9+ drops the uuid dependency entirely, so the real fix is the v8 -> v10 migration, not a pin. The advisory affects v3()/v5()/v6() with a caller supplied buffer; addon-actions only calls v4() with no buffer.
Ndevu12
added a commit
that referenced
this pull request
Jul 31, 2026
…oy (#109) Fixes the **broken GitHub Pages deploy** and closes Dependabot alert **#46** (`uuid`). ## The deploy has been failing on every push `Deploy to GitHub Pages` has failed 6 runs in a row, going back to before any of this weeks security work. The `Build storybook` step dies, and because it fails, every later step — **including the deploy itself** — is skipped: ``` Build nextjs-demo success Build storybook failure Assemble deployment dir skipped Upload Pages artifact skipped Deploy to GitHub Pages skipped ``` So Pages has not published in days. (This is also what looked like "tests being cancelled" — nothing is cancelled; steps after the failure are *skipped*, which renders greyed-out.) ## Root cause `package.json` declared `@storybook/react-vite` at `^10.3.4` while `storybook` / `@storybook/core` stayed at `^8.6.0`. Storybook 8 core cannot load a v10 builder, so preset resolution died: ``` Error: Cannot find module ..._@storybook/builder-vite/dist/index.js ``` I confirmed this reproduces on a clean `main` worktree, so it is genuinely pre-existing and not a side effect of the dependency work. ## Changes | Package | Change | |---|---| | `storybook` | `^8.6.0` → `^10.5.5` | | `@storybook/addon-a11y` | `^8.6.0` → `^10.5.5` | | `@storybook/react-vite` | `^10.3.4` → `^10.5.5` | | `@storybook/addon-essentials` | **removed** — folded into core in v9+ | | `@storybook/blocks` | **removed** — folded into core in v9+, and was declared but never imported anywhere | Config and stories now import from the framework package (`@storybook/react-vite`) instead of the renderer (`@storybook/react`) — the latter was never a declared dependency and only resolved transitively, which is its own latent breakage. ## Closes #46 (`uuid`, medium) properly `@storybook/addon-actions@8.6.18` was the only thing pulling `uuid@^9.0.0`, and it was pinned to a major we could not reach. Storybook 9+ **dropped the `uuid` dependency entirely**, so after this migration `uuid` is absent from the lockfile: ``` grep -c "uuid@npm:" yarn.lock -> 0 ``` That is a real removal, not a `resolutions` override — which is exactly why I left it unfixed in #106 rather than forcing a pin. ## Verification - `yarn build-storybook` — **Storybook build completed successfully** (this is the previously failing step) - `yarn build` · **286 unit tests** · `yarn typecheck` · `yarn lint` · `yarn format:check` — all pass
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 1 update in the /playground directory: picomatch.
Updates
picomatchfrom 4.0.3 to 4.0.4Release notes
Sourced from picomatch's releases.
Commits
e5474fcPublish 4.0.44516eb5Merge commit from fork5eceecdMerge commit from fork0db7dd7Run benchmark again against latest minimatch version (#161)9500377docs: clarify what brace expansion syntax is and isn't supported (#134)2661f23fix typo in globstars.js test name (#138)1798b07docs: fixmakeReexample (#143)9d76bc5chore: undocument removed options (#146)e4d718bRemove unused time-require (#160)38dffebchore(deps): pin dependencies (#158)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.