Skip to content

chore(deps-dev): bump browserslist from 4.28.2 to 4.28.9 in /judge-lab in the npm_and_yarn group across 1 directory - #772

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/judge-lab/npm_and_yarn-a5e5b913b4
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/judge-lab/npm_and_yarn-a5e5b913b4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown

Bumps the npm_and_yarn group with 1 update in the /judge-lab directory: browserslist.

Updates browserslist from 4.28.2 to 4.28.9

Release notes

Sourced from browserslist's releases.

4.28.9

4.28.8

  • Fixed including kaios in baseline queries (by @​Jaybhade).

4.28.7

4.28.6

4.28.5

4.28.4

  • Fixed SyntaxError regression of 4.28.3.

4.28.3

  • Fixed baseline query case-insensitivity (by @​swwind).
Changelog

Sourced from browserslist's changelog.

4.28.9

4.28.8

  • Fixed including kaios in baseline queries (by @​Jaybhade).

4.28.7

4.28.6

4.28.5

4.28.4

  • Fixed SyntaxError regression of 4.28.3.

4.28.3

  • Fixed baseline query case-insensitivity (by @​swwind).
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for browserslist since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the npm_and_yarn group with 1 update in the /judge-lab directory: [browserslist](https://github.com/browserslist/browserslist).


Updates `browserslist` from 4.28.2 to 4.28.9
- [Release notes](https://github.com/browserslist/browserslist/releases)
- [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md)
- [Commits](browserslist/browserslist@4.28.2...4.28.9)

---
updated-dependencies:
- dependency-name: browserslist
  dependency-version: 4.28.9
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 9, 2026
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown

CodeDecay PR Check

Lead catch: Config area changed — judge-lab/package-lock.json:2893

judge-lab/package-lock.json touches a config area and should be reviewed for regression impact.

Risk: Low · Merge 6/100 · Decay 0/100 · Security 0/100

Full CodeDecay report

CodeDecay Report

Overall risk: Low

Score Value
Merge risk 6/100
Decay risk 0/100
Security risk 0/100
Findings Count
High 2
Medium 0
Low 1

Changed Files

  • judge-lab/package-lock.json modified (+27/-24)

Likely Impacted Areas

  • Low Dependency lockfile (config): judge-lab/package-lock.json

Normalized Impact Graph

Graph artifact: .codedecay/local/impact-graph.json (4968 node(s), 10028 edge(s))

  • Confidence: Direct: 10028, inferred: 0, heuristic: 0
  • codedecay-js-babel-symbols via @babel/parser (available, adapter 1.0.0)
    • Limitation: Call expressions are not connected to target symbols in this adapter version.
    • Limitation: Only JavaScript and TypeScript files parsed by @babel/parser are represented.
    • Limitation: Static import resolution does not resolve runtime dependency injection or dynamic imports.
  • codedecay-python-lezer via @lezer/python (available, adapter 1.0.0)
    • Limitation: Dynamic imports, dependency injection, decorators without literal routes, and framework route registries are not resolved.
    • Limitation: Python impact evidence uses the @lezer/python grammar and conservative module-to-file resolution.
    • Limitation: Static test imports do not prove execution or assertion quality.
  • Graph limitation: A static test import does not prove the symbol executed or that assertions cover its behavior.

Language And Parser Coverage

  • Source files classified: 0
  • Fully supported parser files: 0
  • Limited files: 0
  • Unsupported files: 0

Merge Risk Breakdown

  • Score: 6/100
  • Raw score before dampeners: 6/100
  • Adjusted score before severity cap: 6/100
  • Highest contributing severity: Low

Top contributors:

  • +6 Config area changed (direct): judge-lab/package-lock.json touches a config area and should be reviewed for regression impact.
  • +0 Project invariant may be impacted (memory-context): Untrusted memory context: invariant "No hidden cloud or model call" applies to this change. The OSS CLI must remain useful without telemetry, API keys, hosted services, required LLM calls, or CodeDecayCloud.
  • +0 Project invariant may be impacted (memory-context): Untrusted memory context: invariant "Commands are explicit" applies to this change. CodeDecay must not run project commands unless they are configured and safety.allowCommands is true.

Notes:

  • Untrusted memory context is visible but contributes 0 score until trusted evidence corroborates it.
  • Blast-radius multipliers were suppressed because the current finding set is narrow or low-signal.

Decay Risk Breakdown

  • Score: 0/100
  • Raw score before dampeners: 0/100
  • Adjusted score before severity cap: 0/100

Security Risk Breakdown

  • Score: 0/100
  • Raw score before dampeners: 0/100
  • Adjusted score before severity cap: 0/100

Security Matcher Coverage

  • Changed source files scanned: 0
  • Security candidates found: 0
  • Skipped files: 0

Test Evidence

  • Mode: heuristic-only
  • Sources: none
  • Notes:
  • No runtime coverage artifact was found. Test audit remains heuristic-only.

Untrusted Memory Context

  • Project invariant may be impacted (judge-lab/package-lock.json:2893): Untrusted memory context: invariant "No hidden cloud or model call" applies to this change. The OSS CLI must remain useful without telemetry, API keys, hosted services, required LLM calls, or CodeDecayCloud.
  • Project invariant may be impacted (judge-lab/package-lock.json:2893): Untrusted memory context: invariant "Commands are explicit" applies to this change. CodeDecay must not run project commands unless they are configured and safety.allowCommands is true.

Low Risk Findings

  • Config area changed (judge-lab/package-lock.json:2893): judge-lab/package-lock.json touches a config area and should be reviewed for regression impact.

Recommended Checks

  • Flow check (Pull request redteam review): Check weak or missing test proof
  • Flow check (Pull request redteam review): Keep deterministic evidence separate from AI suggestions
  • Flow check (Pull request redteam review): Review edge cases and agent fix tasks
  • Flow check (Pull request redteam review): Run codedecay redteam against the PR diff
  • Run project command: Full validation (pnpm install && pnpm run lint && pnpm typecheck && pnpm test && pnpm build)
  • Run the test suite for changed packages or apps.
  • Verify flow: Pull request redteam review
  • Verify invariant: Commands are explicit
  • Verify invariant: No hidden cloud or model call

Notes

CodeDecay is deterministic and local-first. This report was generated without telemetry, API keys, LLMs, or model calls.


Found by CodeDecay - deterministic, local-first, no telemetry.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants