You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
deps: re-lock Dependabot #21024 so nodemailer stays at 10.0.12 or later, then land it #21102
Filing-gate class: ③ maintainer-directed task.
Acting reader: the triage seat grades this card. The lane seat it names dispatches one os-dev for the re-lock. The PM seat in session session_018gA1pE6eJtwHhqx72G8U9X then lands #21024: it holds the landing authorization and is subscribed to the PR.
Dedup: repo:objectstack-ai/objectstack is:issue "21024", open and closed, returned 0 hits. That zero is partly false: #21094 names #21024 in its serial-constraints note, but #21094 is the sibling production-dependency group and excludes this PR. No card covers the re-lock.
Maintainer ruling (verbatim)
按你的推荐:关掉21029立卡,better-auth先放着,21024授权你落地
Given in session session_018gA1pE6eJtwHhqx72G8U9X on 2026-10-01.
Why this card exists
Dependabot's development-dependency group #21024 is reviewed and authorized for landing; see PR comments 5925725899 and 5925754198.
Its one defect. Dependabot's lockfile regeneration moves nodemailer from 10.0.12 DOWN to 10.0.11. No manifest asks for that: @objectstack/plugin-email declares ^10.0.2.
Filing-gate class: ③ maintainer-directed task.
Acting reader: the triage seat grades this card. The lane seat it names dispatches one
os-devfor the re-lock. The PM seat in sessionsession_018gA1pE6eJtwHhqx72G8U9Xthen lands #21024: it holds the landing authorization and is subscribed to the PR.Dedup:
repo:objectstack-ai/objectstack is:issue "21024", open and closed, returned 0 hits. That zero is partly false: #21094 names #21024 in its serial-constraints note, but #21094 is the sibling production-dependency group and excludes this PR. No card covers the re-lock.Maintainer ruling (verbatim)
Given in session
session_018gA1pE6eJtwHhqx72G8U9Xon 2026-10-01.Why this card exists
Dependabot's development-dependency group #21024 is reviewed and authorized for landing; see PR comments 5925725899 and 5925754198.
nodemailerfrom 10.0.12 DOWN to 10.0.11. No manifest asks for that:@objectstack/plugin-emaildeclares^10.0.2.mainafter fix(deps): take the fix for next GHSA-vcvr-r3jv-pc5j (critical) and dompurify GHSA-p98j-92pf-mc4p #21083 merged (headab7aa3ff1b, merge base9b81314c29), and the rebased lockfile still has 10.0.11.name@versionpair moves up.requireTLSwins overignoreTLS/opportunisticTLS; fix(deps): take the fix for the seven OSV advisories turning Validate Package Dependencies red #20564's changeset documented that to operators. Landing 10.0.11 would run the older behaviour in CI and in anything built from the lockfile.What to do
dependabot/npm_and_yarn/development-dependencies-e1f7e5c775.pnpm-lock.yamlwith the repo's tooling:pnpm install --lockfile-only, under the pnpm version thatpackageManagernames.origin/main's lockfile plus the PR's 70package.jsonchanges. Never edit the lockfile by hand.nodemailerresolves to 10.0.12 or later.mainholds 10.0.12.name@versionpair.pnpm install --frozen-lockfilepasses.devDependencies.skip-changeset, and nothing it changes publishes.Notes
completed, when chore(deps)(deps-dev): bump the development-dependencies group across 1 directory with 16 updates #21024 merges.nodemailer10.0.12 or later.Generated by Claude Code