Skip to content

Bump ajv from 6.12.6 to 6.14.0#3

Closed
dependabot[bot] wants to merge 2 commits intomainfrom
dependabot/npm_and_yarn/ajv-6.14.0
Closed

Bump ajv from 6.12.6 to 6.14.0#3
dependabot[bot] wants to merge 2 commits intomainfrom
dependabot/npm_and_yarn/ajv-6.14.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Feb 22, 2026

Bumps ajv from 6.12.6 to 6.14.0.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

butlersrepos and others added 2 commits December 5, 2025 11:29
Bumps [ajv](https://github.com/ajv-validator/ajv) from 6.12.6 to 6.14.0.
- [Release notes](https://github.com/ajv-validator/ajv/releases)
- [Commits](ajv-validator/ajv@v6.12.6...v6.14.0)

---
updated-dependencies:
- dependency-name: ajv
  dependency-version: 6.14.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Feb 22, 2026
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Mar 9, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/ajv-6.14.0 branch March 9, 2026 23:36
kaiapeacock-eng added a commit that referenced this pull request Mar 24, 2026
Rebuilt all 32 integration skills from context-hub HEAD (post-Kelson's
rebrand PRs #3 and #4) and cleaned up remaining PostHog references in
example code that the build left behind.

Changes:
- SKILL.md files: author, description, key principles, framework
  guidelines, and identifying-users sections now reference Amplitude
- Workflow files: amplitude.track/identify/reset instead of posthog APIs,
  .amplitude-events.json instead of .posthog-events.json
- Doc references: amplitude.com SDK docs replace posthog.com docs
- Example code: Astro window.amplitude, Nuxt $amplitude/useAmplitude(),
  Django amplitude_example module, Android com.example.amplitude package,
  React Native config/amplitude.ts, Swift Package.resolved amplitude-swift,
  Ruby on Rails template text updated

Also stages pre-existing changes to wizard-tools and agent-runner that
add multi-category skill support and an instrumentation skill step.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
bird-m added a commit that referenced this pull request Apr 15, 2026
Review-panel #1 (Severe): Remove competing browser tab in requires_auth
path. The requires_auth branch opened the backend's redirect URL via
opn() then fell through to performAmplitudeAuth which opened a second
browser tab with mismatched PKCE. Now we skip the backend URL and let
performAmplitudeAuth handle the entire flow. Added TODO to evaluate
using the backend URL in a follow-up.

Review-panel #2 (Critical): Init feature flags in agent/CI paths so
_headlessSignupEnabled can be true. Previously the flag was only set in
the TUI interactive path, making the entire agent/CI headless signup
block unreachable dead code.

Review-panel #3 (Important): Pre-populate HeadlessSignupScreen from CLI
--email/--full-name flags. Auto-submit if both are present.

Review-panel #4 (Important): Redact email in agent NDJSON log output
to match the redaction pattern in headless-signup.ts.

Review-panel #7 (Important): Split fullName into first_name/last_name
on first space before sending to provisioning endpoint.

Review-panel #9 (Nit): Replace non-null assertions on
headlessSignupEmail/headlessSignupFullName with an explicit guard.

Review-panel #10 (Nit): Extract completeSignupTokenExchange into
headless-signup.ts as a shared helper used by both the agent/CI and
TUI code paths, reducing duplication and drift risk.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@bird-m bird-m mentioned this pull request Apr 15, 2026
3 tasks
bird-m added a commit that referenced this pull request Apr 16, 2026
…marked instance

Replace hardcoded ANSI RGB values with Brand.blueOnDark and Brand.lilac
via a hexToAnsi helper, keeping heading colors in sync with styles.ts.

Also scope marked config to a local Marked instance instead of mutating
the global singleton, preventing side effects on other marked consumers.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
bird-m added a commit that referenced this pull request Apr 16, 2026
A malformed --email caused the entire CliArgsSchema.safeParse to fail,
triggering the raw-args fallback that silently drops every Zod transform
(most notably projectId string→number coercion). Validate email shape
downstream in performHeadlessSignup / HeadlessSignupScreen instead.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
kelsonpw added a commit that referenced this pull request Apr 17, 2026
… picker)

Batch of bird-m and Bugbot findings from PR #112:

#1 claudeCodeMode default mismatch (medium, flagged 3×):
  addMCPServerToClientsStep silently defaulted to 'plugin' while
  mcp-installer.ts defaulted to 'mcp'. Non-TUI fallback via bin.ts
  could install the plugin with no user prompt. Aligned both to 'mcp'
  as the safer default — plugin is interactive-only now.

#3 remove flow can't uninstall plugin (medium, flagged 2×):
  getInstalledClients only ever instantiated ClaudeCodeMCPClient.
  After plugin install removes the bare `amplitude` MCP entry,
  isServerInstalled returned false and `wizard mcp remove` silently
  skipped Claude Code. Added an explicit ClaudeCodePluginClient probe
  before falling through to the MCP check.

#4 non-TUI `local` flag ignored for plugin path (low, Bugbot):
  addMCPServerToClientsStep now forces 'mcp' mode whenever
  local=true, matching the TUI's behavior. The plugin hardcodes the
  prod URL and can't serve localhost.

#5 `as unknown as RawMCPClient[]` cast (nit, bird-m):
  resolveClientsForMode returns MCPClient[] directly; the local
  RawMCPClient interface was a holdover. Dropped the cast and removed
  the unused interface — install loop now type-checks against
  MCPClient directly.

#6 older Claude CLIs fail opaquely (nit, bird-m):
  ClaudeCodePluginClient.isClientSupported now probes `claude plugin
  --help` in addition to `--version`. resolveClientsForMode is async
  and checks plugin support before swapping — older CLIs quietly keep
  ClaudeCodeMCPClient instead of failing during `marketplace add`.

#7 single-Claude-Code hid plugin/MCP choice (medium, Bugbot):
  detected.length === 1 routed to Phase.Ask, which doesn't show the
  split picker. Now: if the lone detected tool is Claude Code and no
  escape hatch is set, route to Phase.Pick so the user sees plugin vs
  MCP rows.

#8 resolveSelection misleading default (low, Bugbot):
  wantsPlugin || !wantsMcp ? 'plugin' : 'mcp' returned 'plugin' when
  the user unchecked both Claude Code rows. Simplified to
  wantsPlugin ? 'plugin' : 'mcp' — explicit semantics, still correct
  since downstream guards the Claude-Code-absent case.

#9 Codex Windows detection (low, Bugbot):
  `command -v` is POSIX-only; Windows never matched. Use `where codex`
  on win32, `command -v codex` on POSIX. Take the first line since
  `where` may return multiple paths. Narrowed the bundled-app
  exclusion to macOS only (Conductor-specific).

#10 multi-picker uncheck-all dead code (medium, Bugbot):
  MultiPickerMenu's Enter handler fell back to the focused row when
  selected was empty, so a user who unchecked every pre-selected row
  got one install instead of a skip. Now: if defaultSelected was
  provided, an empty set means deliberate — pass [] through to the
  caller. Also fixed lexicographic index sort → numeric.

#? dev script env var at build-time (low, Bugbot):
  `AMPLITUDE_WIZARD_DEV=1 pnpm build` only scoped the var to the
  build subprocess, not the globally-linked binary. Removed from the
  `dev` script since it was ineffective there — `try` still sets it
  at runtime where it actually works.

Addressed in comment, no code change: #2 non-atomic settings.json
write — already replaced with `claude plugin marketplace add` CLI in
commit 4679fc4. No direct file write remains.

974 tests pass, lint clean, smoke test passes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@kelsonpw kelsonpw mentioned this pull request Apr 20, 2026
30 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants