Skip to content

chore(deps-dev): bump pm-changelog from 2026.7.24 to 2026.7.27 - #40

Merged
unbraind merged 1 commit into
mainfrom
dependabot/npm_and_yarn/pm-changelog-2026.7.27
Jul 27, 2026
Merged

chore(deps-dev): bump pm-changelog from 2026.7.24 to 2026.7.27#40
unbraind merged 1 commit into
mainfrom
dependabot/npm_and_yarn/pm-changelog-2026.7.27

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor

Bumps pm-changelog from 2026.7.24 to 2026.7.27.

Release notes

Sourced from pm-changelog's releases.

pm-changelog v2026.7.27

2026.7.27 - 2026-07-27

Other

  • Exclude generated dist output from DeepScan static analysis (pmc-mi7s)
  • Replace hand-built api doubles in extension tests with the SDK activation harness (pmc-x0u4)

pm-changelog v2026.7.26

2026.7.26 - 2026-07-26

Other

  • Enable governance duplicate-detection advisory mode and adopt pm-cli 2026.7.25 (pmc-zbj2)

pm-changelog v2026.7.25

No release notes provided.

Changelog

Sourced from pm-changelog's changelog.

2026.7.27 - 2026-07-27

Other

  • Exclude generated dist output from DeepScan static analysis (pmc-mi7s)
  • Replace hand-built api doubles in extension tests with the SDK activation harness (pmc-x0u4)

2026.7.26 - 2026-07-26

Other

  • Enable governance duplicate-detection advisory mode and adopt pm-cli 2026.7.25 (pmc-zbj2)
Commits
  • 8ae46c2 Release pm-changelog v2026.7.27
  • e1d507e chore(ci): exclude generated dist output from DeepScan analysis (#100)
  • ecec8cf Verify the pm-changelog extension through pm's real activation harness instea...
  • e126a8b Release pm-changelog v2026.7.26
  • 33007d8 chore(governance): enable duplicate-detection advisory mode and adopt pm-cli ...
  • 874fb0d chore(deps-dev): bump @​unbrained/pm-cli from 2026.7.24 to 2026.7.25 (#96)
  • 58479af Release pm-changelog v2026.7.25
  • dbe29bc fix(generator): canonicalize release keys so zero-padded tags match unpadded ...
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 27, 2026
@greptile-apps

greptile-apps Bot commented Jul 27, 2026

Copy link
Copy Markdown

PR author is in the excluded authors list.

@unbraind

Copy link
Copy Markdown
Owner

👎 (non-actionable — recorded so the signal is not lost)

@greptile-apps returned only "PR author is in the excluded authors list." — Dependabot is excluded from review, so this PR received zero automated code-review coverage from Greptile. Downvoted as carrying no review signal, not as a wrong finding.

Recording the consequence rather than treating the exclusion as an implicit pass: on a dependency-bump PR the exclusion is defensible (the diff is a version range and a lockfile), but it does mean the merge decision here rests entirely on CI plus the maintainer review, not on bot analysis. The substantive verification for this bump is the green test suite on the resulting range, which is what is being relied on.

@greptile-apps

greptile-apps Bot commented Jul 27, 2026

Copy link
Copy Markdown

That's an accurate framing. The Dependabot exclusion is a deliberate tradeoff — lockfile-only diffs don't benefit much from static analysis — but it does mean the safety net here is exactly what you described: CI green + maintainer sign-off. No hidden coverage from the bot side.

If you ever want a middle ground (e.g., have Greptile check only the package.json version range change, not the lockfile), that's achievable by scoping the exclusion more narrowly. Worth considering if this repo takes frequent dependency bumps that occasionally introduce breaking API changes.

Tip: You can customize Greptile's behavior for this repo with .greptile/rules.md and .greptile/config.json.

@unbraind

Copy link
Copy Markdown
Owner

@dependabot rebase

#39 landed the 2026.7.27 adoption and refreshed the lockfile, which conflicts with this branch. main still declares pm-changelog: ^2026.7.24, so this bump is still wanted — it just needs to be replayed on the new base.

Bumps [pm-changelog](https://github.com/unbraind/pm-changelog) from 2026.7.24 to 2026.7.27.
- [Release notes](https://github.com/unbraind/pm-changelog/releases)
- [Changelog](https://github.com/unbraind/pm-changelog/blob/main/CHANGELOG.md)
- [Commits](unbraind/pm-changelog@v2026.7.24...v2026.7.27)

---
updated-dependencies:
- dependency-name: pm-changelog
  dependency-version: 2026.7.27
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/pm-changelog-2026.7.27 branch from b5d8f22 to a1413fd Compare July 27, 2026 21:26
@unbraind
unbraind merged commit 4f77853 into main Jul 27, 2026
6 checks passed
@unbraind
unbraind deleted the dependabot/npm_and_yarn/pm-changelog-2026.7.27 branch July 27, 2026 22:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant