Skip to content

deps: re-lock Dependabot #21024 so nodemailer stays at 10.0.12 or later, then land it #21102

Description

@objectstack-fleet

Filing-gate class: ③ maintainer-directed task.
Acting reader: the triage seat grades this card. The lane seat it names dispatches one os-dev for the re-lock. The PM seat in session session_018gA1pE6eJtwHhqx72G8U9X then lands #21024: it holds the landing authorization and is subscribed to the PR.
Dedup: repo:objectstack-ai/objectstack is:issue "21024", open and closed, returned 0 hits. That zero is partly false: #21094 names #21024 in its serial-constraints note, but #21094 is the sibling production-dependency group and excludes this PR. No card covers the re-lock.

Maintainer ruling (verbatim)

按你的推荐:关掉21029立卡,better-auth先放着,21024授权你落地

Given in session session_018gA1pE6eJtwHhqx72G8U9X on 2026-10-01.

Why this card exists

Dependabot's development-dependency group #21024 is reviewed and authorized for landing; see PR comments 5925725899 and 5925754198.

What to do

  1. Work on chore(deps)(deps-dev): bump the development-dependencies group across 1 directory with 16 updates #21024's own branch, dependabot/npm_and_yarn/development-dependencies-e1f7e5c775.
    • Regenerate pnpm-lock.yaml with the repo's tooling: pnpm install --lockfile-only, under the pnpm version that packageManager names.
    • Start from origin/main's lockfile plus the PR's 70 package.json changes. Never edit the lockfile by hand.
    • Add commits on top. ⛔ No rebase, amend or force-push on the Dependabot branch.
  2. Acceptance:
    • nodemailer resolves to 10.0.12 or later. main holds 10.0.12.
    • No resolved version goes DOWN against the merge base. Compare every changed name@version pair.
    • pnpm install --frozen-lockfile passes.
    • The 70 manifest hunks stay exactly as Dependabot wrote them. All of them are devDependencies.
  3. Changeset: none. The PR carries skip-changeset, and nothing it changes publishes.
  4. Report back. The PM seat arms auto-merge once the head is green.

Notes


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratedependenciesPull requests that update a dependency filedomain:devxpriority:p2Medium: important, M3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions