chore(deps): update dependency @tanstack/vue-virtual to v3.13.39 #34
No reviewers
Labels
No labels
idea
points
1
points
13
points
2
points
3
points
5
points
8
priority
p0
priority
p1
priority
p2
priority
p3
state
blocked
state
done
state
in-progress
state
ready
state
review
state
triage
status
declined
status
in-progress
status
planned
status
proposed
status
shipped
status
under-review
type
bug
type
epic
type
feature
type
spike
type
story
type
task
No milestone
No project
No assignees
3 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
tti/tti-ux!34
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/tanstack-virtual-monorepo"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
3.13.34→3.13.39Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.
AI review · advisory
Verdict: looks good — all four reviewers found nothing that needs fixing.
⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 0 distinct, 0 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Panel debate — how this review was reached
Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Round 1 — independent reviews
Synthesis — Devstral 2 123B wrote the final review from 0 confirmed findings.
Transcript
rv-20260813054123-2ca474— full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript
rv-20260813054123-2ca474.2455758f0f0f82f688d8AI review · advisory
Verdict: looks good — all four reviewers found nothing that needs fixing.
⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 0 distinct, 0 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Panel debate — how this review was reached
Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Round 1 — independent reviews
Synthesis — Devstral 2 123B wrote the final review from 0 confirmed findings.
Transcript
rv-20260814054455-fc1475— full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript
rv-20260814054455-fc1475.0f82f688d8268b3e57ceAI review · advisory
Verdict: nothing confirmed — a couple of single-reviewer observations below.
⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 2 distinct, 0 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Panel debate — how this review was reached
Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Round 1 — independent reviews
Round 2 — cross-examination
Devstral 2 123B#1Inconsistent dependency version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1Devstral 2 123B#2Inconsistent dependency version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1Synthesis — Devstral 2 123B wrote the final review from 0 confirmed findings (+2 unconfirmed).
Transcript
rv-20260815053925-6ef939— full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript
rv-20260815053925-6ef939.@ -5496,9 +5518,9 @@}package-lock.json:5518· MEDIUM — Inconsistent dependency versionThe version of
@tanstack/virtual-corein the dependency tree does not match the version specified inpackage.json, which can lead to unexpected behavior or build errors.panel tally 1/4 · reply here or use the finding board to agree/disagree
@ -5525,12 +5547,12 @@}package-lock.json:5547· MEDIUM — Inconsistent dependency versionThe version of
@tanstack/vue-virtualin the dependency tree does not match the version specified inpackage.json, which can lead to unexpected behavior or build errors.panel tally 1/4 · reply here or use the finding board to agree/disagree
chore(deps): update dependency @tanstack/vue-virtual to v3.13.35to chore(deps): update dependency @tanstack/vue-virtual to v3.13.36268b3e57ceabd885071eAI review · advisory
Verdict: 1 thing worth fixing (1 medium).
Findings that didn't map to a diff line:
package-lock.json:3· MEDIUM — New optional peer deps cac@6.7.14 and commander@14.0.3 lack explicit justificationThe diff introduces node_modules/@nuxt/cli/node_modules/cac (6.7.14) and commander (14.0.3) as optional peer deps under @nuxt/cli. Per [standard] tti/coding-standards/shell.md (dependencies: pin the version AND verify a published checksum before extracting or executing anything fetched from the network) and baseline.yml:101 checksum gating, optional peers must still be integrity-pinned and justified, otherwise they widen the unverified-dependency surface the gate is designed to contain.
⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 1 confirmed, 2 refuted · web: 2 queries, 6 results · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Panel debate — how this review was reached
Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Round 1 — independent reviews
Web grounding — web: 2 queries, 6 results: «https://registry.npmjs.org/@tanstack/vue-virtual»; «https://registry.npmjs.org/@tanstack/virtual-core»
Round 2 — cross-examination
Devstral 2 123B#2Dependency version mismatch between parent and child · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1Devstral 2 123B#1Inconsistent dependency version resolution · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1Laguna S 2.1#1New optional peer deps cac@6.7.14 and commander@14.0.3 lack explicit justificati · confirmed: GPT-OSS 120B, Devstral 2 123B · refuted: Gemma 4 31BRaised but refuted (left out of the review above)
Devstral 2 123B#2Dependency version mismatch between parent and child — The diff updates @tanstack/vue-virtual's dependency on @tanstack/virtual-core from "3.17.6" to "3.17.8" and the lockfile entry for @tanstack/virtual-cDevstral 2 123B#1Inconsistent dependency version resolution — The lockfile previously listed @tanstack/virtual-core at version 3.17.6 but the diff changes that entry to version 3.17.8, and no other entries for @tSynthesis — Devstral 2 123B wrote the final review from 1 confirmed finding.
Transcript
rv-20260819053312-49fdcf— full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript
rv-20260819053312-49fdcf.abd885071e91f7c7b3c2AI review · advisory
Verdict: 3 things worth fixing (1 high · 1 medium · 1 low).
Findings that didn't map to a diff line:
package-lock.json:5496· MEDIUM — virtual-core 3.17.6 → 3.17.8 is a transitive dep bump not in package.json range declarationThe diff bumps @tanstack/virtual-core from 3.17.6 to 3.17.8, but package.json declares "@tanstack/vue-virtual": "^3.13.0" — vue-virtual v3.13.36 depends on virtual-core "3.17.8" (exact pin, per the dependencies block). This is internally consistent for this lockfile, BUT the version jump from 3.13.34→3.13.36 pulling 3.17.6→3.17.8 is a minor/patch range expansion; verify these are the exact published shas and that no audit (trivy SAST/SCA per [standard] tti/coding-standards/.forgejo/workflows/baseline.yml:151) flags 3.17.7 as the skipped CVE-fix intermediate.
⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 5 distinct (from 8 reviewer findings), 3 confirmed, 1 refuted · web: not used · context: 1 files · 89 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Panel debate — how this review was reached
Grounding — context: 1 files · 89 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Round 1 — independent reviews
Grouping — 8 reviewer findings describe 5 distinct defects; reviewers who found the same defect independently count as support.
Round 2 — cross-examination
Laguna S 2.1#1package-lock.json name/version mismatch with package.json causes publish failure · also raised by: Devstral 2 123B, Gemma 4 31B · confirmed: GPT-OSS 120B · refuted: —Devstral 2 123B#1Package name mismatch · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31BLaguna S 2.1#2virtual-core 3.17.6 → 3.17.8 is a transitive dep bump not in package.json range · confirmed: Gemma 4 31B, Devstral 2 123B · refuted: —Devstral 2 123B#3Missing license field · also raised by: Laguna S 2.1 · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31BGemma 4 31B#2Inconsistent Node.js engine requirement · confirmed: Devstral 2 123B · refuted: GPT-OSS 120BRaised but refuted (left out of the review above)
Devstral 2 123B#3Missing license field — The diff adds a "license": "Apache-2.0" field to the root package entry in package-lock.json, satisfying the requirement. The alleged missing licenseSynthesis — Devstral 2 123B wrote the final review from 3 confirmed findings (+1 unconfirmed).
Transcript
rv-20260820052614-61266e— full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript
rv-20260820052614-61266e.@ -1,13 +1,14 @@{package-lock.json:1· HIGH — package-lock.json name/version mismatch with package.json causes publish failureThe lockfile root "name" and "version" were changed to "@tti/tti-ux" / "2.0.0", but the PR title and diff scope only mention a dependency update. This mismatch can break dependency resolution and cause publish failures.
panel tally 4/4 · reply here or use the finding board to agree/disagree
package-lock.json:1· HIGH — package-lock.json name/version mismatch with package.json causes publish failureThe lockfile root "name" and "version" were changed to "@tti/tti-ux" / "2.0.0", but the PR title and diff scope only mention a dependency update. This mismatch can break dependency resolution and cause publish failures.
Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):
panel tally 1/4 · reply here or use the finding board to agree/disagree
@ -2630,2 +2631,4 @@}},"node_modules/@nuxt/cli/node_modules/cac": {"version": "6.7.14",package-lock.json:2634· LOW — Inconsistent Node.js engine requirementThe newly added 'commander' dependency requires Node >=20, while 'cac' requires Node >=8. This could cause runtime failures in environments using older LTS versions.
panel tally 2/4 · reply here or use the finding board to agree/disagree
91f7c7b3c2ae205af498AI review · advisory
Verdict: looks good — all four reviewers found nothing that needs fixing.
⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 0 distinct, 0 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Panel debate — how this review was reached
Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Round 1 — independent reviews
Synthesis — Devstral 2 123B wrote the final review from 0 confirmed findings.
Transcript
rv-20260821053732-4f5dc5— full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript
rv-20260821053732-4f5dc5.ae205af498ee880a1060AI review · advisory
Verdict: looks good — all four reviewers found nothing that needs fixing.
⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 1 distinct, 0 confirmed, 1 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Panel debate — how this review was reached
Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Round 1 — independent reviews
Round 2 — cross-examination
Laguna S 2.1#1@tanstack/vue-virtual dependency on @tanstack/virtual-core uses exact pin instea · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Devstral 2 123BRaised but refuted (left out of the review above)
Laguna S 2.1#1@tanstack/vue-virtual dependency on @tanstack/virtual-core uses exact pin instea — The repository's package.json does not declare a @tanstack/virtual-core dependency at all, so there is no caret range to be inconsistent with. The locSynthesis — Devstral 2 123B wrote the final review from 0 confirmed findings.
Transcript
rv-20260830052733-a70738— full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript
rv-20260830052733-a70738.ee880a106081c2a03eabAI review · advisory
Verdict: nothing confirmed — a couple of single-reviewer observations below.
⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 1 distinct, 0 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Panel debate — how this review was reached
Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Round 1 — independent reviews
Round 2 — cross-examination
Devstral 2 123B#1Inconsistent dependency version · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31BSynthesis — Devstral 2 123B wrote the final review from 0 confirmed findings (+1 unconfirmed).
Transcript
rv-20260831052822-073d1d— full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript
rv-20260831052822-073d1d.@ -5510,9 +5532,9 @@}package-lock.json:5532· MEDIUM — Inconsistent dependency versionThe version of
@tanstack/virtual-coreis updated to 3.17.8, but the dependency in@tanstack/vue-virtualstill references the old version 3.17.6, which could lead to version conflicts or unexpected behavior.Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):
panel tally 1/4 · reply here or use the finding board to agree/disagree
81c2a03eab911e74167cAI review · advisory
Verdict: looks good — all four reviewers found nothing that needs fixing.
⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 1 distinct, 0 confirmed, 1 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Panel debate — how this review was reached
Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Round 1 — independent reviews
Grouping — 2 reviewer findings describe 1 distinct defect; reviewers who found the same defect independently count as support.
Round 2 — cross-examination
Devstral 2 123B#1Inconsistent dependency version · also raised by: Laguna S 2.1 · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31BRaised but refuted (left out of the review above)
Devstral 2 123B#1Inconsistent dependency version — The diff updates both the root @tanstack/virtual-core entry and the @tanstack/vue-virtual dependency to version 3.17.8, making them consistent. The evSynthesis — Devstral 2 123B wrote the final review from 0 confirmed findings.
Transcript
rv-20260901054802-642a91— full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript
rv-20260901054802-642a91.911e74167c7c175ee48fAI review · advisory
Verdict: nothing confirmed — a couple of single-reviewer observations below.
⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 4 distinct, 0 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Panel debate — how this review was reached
Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Round 1 — independent reviews
Round 2 — cross-examination
Devstral 2 123B#1Version mismatch in package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31BDevstral 2 123B#2Version mismatch in package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31BDevstral 2 123B#3Version mismatch in package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31BDevstral 2 123B#4Version mismatch in package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31BSynthesis — Devstral 2 123B wrote the final review from 0 confirmed findings (+4 unconfirmed).
Transcript
rv-20260902051607-f34a45— full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript
rv-20260902051607-f34a45.@ -1,12 +1,12 @@{package-lock.json:1· MEDIUM — Version mismatch in package-lock.jsonThe version listed here does not match the version in package.json, which can cause confusion or errors when installing dependencies.
Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):
panel tally 1/4 · reply here or use the finding board to agree/disagree
@ -2643,12 +2643,34 @@}package-lock.json:2643· MEDIUM — Version mismatch in package-lock.jsonThe version listed here does not match the version in package.json, which can cause confusion or errors when installing dependencies.
Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):
panel tally 1/4 · reply here or use the finding board to agree/disagree
@ -5510,9 +5532,9 @@}package-lock.json:5532· MEDIUM — Version mismatch in package-lock.jsonThe version listed here does not match the version in package.json, which can cause confusion or errors when installing dependencies.
Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):
panel tally 1/4 · reply here or use the finding board to agree/disagree
@ -23114,7 +23136,7 @@},MEDIUM — Version mismatch in package-lock.json
The version in package-lock.json does not match the version in package.json.
Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):
panel tally 1/4 · reply here or use the finding board to agree/disagree
chore(deps): update dependency @tanstack/vue-virtual to v3.13.36to chore(deps): update dependency @tanstack/vue-virtual to v3.13.377c175ee48f72f90c207dAI review · advisory
Verdict: lockfile-only change — AI review skipped.
This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic.
⚑ panel: skipped (lockfile-only, 1 file)
Full transcript: http://host.containers.internal:3939/-/ai/v1/review/rv-20260908052639-d899f8
A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.
72f90c207dc9e65b43feAI review · advisory
Verdict: lockfile-only change — AI review skipped.
This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic.
⚑ panel: skipped (lockfile-only, 1 file)
Full transcript: http://host.containers.internal:3939/-/ai/v1/review/rv-20260909054041-44f2e8
A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.
🔧 Security-gate fix map
The gate failed on these dependency findings — fastest path to green for each:
@tiptap/corenpm update core --package-lock-onlyjs-yamlnpm update js-yaml --package-lock-onlysharpnpm update sharp --package-lock-onlysvgonpm update svgo --package-lock-onlyPosted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.
chore(deps): update dependency @tanstack/vue-virtual to v3.13.37to chore(deps): update dependency @tanstack/vue-virtual to v3.13.38c9e65b43fe84555df33cAI review · advisory
Verdict: lockfile-only change — AI review skipped.
This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic.
⚑ panel: skipped (lockfile-only, 1 file)
Full transcript: http://host.containers.internal:3939/-/ai/v1/review/rv-20260912051159-6d547c
A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.
🔧 Security-gate fix map
The gate failed on these dependency findings — fastest path to green for each:
@tiptap/corenpm update core --package-lock-onlyjs-yamlnpm update js-yaml --package-lock-onlysharpnpm update sharp --package-lock-onlysvgonpm update svgo --package-lock-onlyPosted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.
chore(deps): update dependency @tanstack/vue-virtual to v3.13.38to chore(deps): update dependency @tanstack/vue-virtual to v3.13.3984555df33c89534262d3AI review · advisory
Verdict: lockfile-only change — AI review skipped.
This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic.
⚑ panel: skipped (lockfile-only, 1 file)
Full transcript: http://host.containers.internal:3939/-/ai/v1/review/rv-20260915051711-67104a
A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.
🔧 Security-gate fix map
The gate failed on these dependency findings — fastest path to green for each:
@tiptap/corenpm update core --package-lock-onlyjs-yamlnpm update js-yaml --package-lock-onlysharpnpm update sharp --package-lock-onlysvgonpm update svgo --package-lock-onlyPosted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.
89534262d34f7541a7daAI review · advisory
Verdict: lockfile-only change — AI review skipped.
This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic.
⚑ panel: skipped (lockfile-only, 1 file)
A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.
🔧 Security-gate fix map
The gate failed on these dependency findings — fastest path to green for each:
@nuxtjs/mdc@tiptap/corenpm update core --package-lock-onlyjs-yamlnpm update js-yaml --package-lock-onlysharpnpm update sharp --package-lock-onlysvgonpm update svgo --package-lock-onlyPosted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.