Conversation
0xMMA
added a commit
that referenced
this pull request
Sep 24, 2026
Re-resolved from main's lockfile with npm --before=2026-09-18, then npm audit fix under the same cutoff: every one of the 147 changed versions was published before the cutoff (checked against the registry), and audit still reports 0 vulnerabilities. Angular lands on 21.2.23 instead of the day-old 21.2.24; jsdom 30.1.0, prettier 3.9.8. Matches the 7-day npm cooldown #89 gives Dependabot.
Second review: ignore rules without versions do not apply to security updates (dependabot-core ignore_condition.rb), so advisories can still arrive as PRs; say so instead of claiming the opposite. Dependabot passes --min-release-age only with npm >= 11.10, so packageManager moves 11.9.0 -> 11.19.0 (what the dev box runs) for the cooldown to reach transitive packages. Reasons for the framework-major block no longer claim unresolvability. vi.mock and Vitest-gate wording updated for Angular 21.2.1+ / 22.2.
Owner
Author
PrimeNG 22, @primeuix/* 3 (styled/motion 1, utils 0.8) and primeicons 8 moved from MIT to the commercial PrimeUI License (key required, banner without). Explicit versions ranges so security updates cannot cross the line either; roadmap records the decision it forces on E4 step 2.
7 tasks
Owner
Author
|
Added after the reviews: a licence fence (59da5f0). PrimeNG 22, |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Roadmap housekeeping item: add
gomodandnpmto Dependabot.What
gomod(/) andnpm(/frontend), monthly, grouped.packageManagermoves from npm 11.9.0 to 11.19.0, the version the dev box runs. Dependabot only passes--min-release-agewith npm >= 11.10, and without it the cooldown would not reach transitive packages.@angular/*,primeng,@primeuix/*,primeicons,typescript) is one group, minor/patch only. Their majors needng update, the TypeScript major Angular dictates, and a look at every screen on Windows. A Dependabot PR does none of that.What it does not do (also stated in the file)
ignorerules that have noversionsrange (dependabot-coreignore_condition.rb). An advisory for Wails or a framework package can still arrive as a PR. That is deliberate, because it is the loudest notice. It is not merge-on-green./v4) is never proposed. v0 minor bumps (wire, selfupdate, go-keyring) land ingo-minorand may break the API.Also
.claude/rules/testing.mdand.claude/docs/testing.md:vi.mockhas only been blocked for relative/absolute paths since Angular 21.2.1. The Vitest 5 gate lifts at@angular/build>= 22.2, not with any Angular 22. Duplicated## Go Testsheading removed.Review
Two Opus review rounds.
Verification
dependabot-2.0: 0 errors.npm install --package-lock-only: no lockfile change.