chore(deps): update dependency vue to v3.5.43 #38

Open
renovate-bot wants to merge 1 commit from renovate/vue-monorepo into main
Member

This PR contains the following updates:

Package Change Age Confidence
vue (source) 3.5.40 → 3.5.43 age confidence

❗ Important

Release Notes retrieval for this PR were skipped because no github.com credentials were available.
If you are self-hosted, please see this instruction.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [vue](https://vuejs.org/) ([source](https://github.com/vuejs/core)) | [`3.5.40` → `3.5.43`](https://renovatebot.com/diffs/npm/vue/3.5.40/3.5.43) | ![age](https://developer.mend.io/api/mc/badges/age/npm/vue/3.5.43?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/vue/3.5.40/3.5.43?slim=true) | > ❗ **Important** > > Release Notes retrieval for this PR were skipped because no github.com credentials were available. > If you are self-hosted, please see [this instruction](https://github.com/renovatebot/renovate/blob/master/docs/usage/examples/self-hosting.md#githubcom-token-for-release-notes). --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzguMiIsInVwZGF0ZWRJblZlciI6IjQ0LjExNS41IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->
chore(deps): update dependency vue to v3.5.41
All checks were successful
ai-review / review (pull_request) Successful in 1m43s
scan / trivy-fs (pull_request) Successful in 57s
baseline-security / baseline (pull_request) Successful in 2m29s
baseline-security / baseline (push) Successful in 2m34s
scan / trivy-fs (push) Successful in 55s
f1751f8a3a
ai-review-bot left a comment

AI review · advisory

Verdict: looks good — all four reviewers found nothing that needs fixing.

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 0 distinct, 0 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.97): The dependency version updates and additions appear consistent and introduce no obvious bugs or security concerns.
  • Gemma 4 31B (0 findings, confidence 1.0): The pull request correctly updates the vue dependency and its associated compiler packages to v3.5.41 in the lockfile, and the incidental updates to @babel/parser and @babel/types are consistent with
  • Devstral 2 123B (0 findings, confidence 0.95): The pull request updates Vue and related dependencies to v3.5.41, which appears to be a routine dependency bump with no functional changes or security issues introduced.
  • Laguna S 2.1 (0 findings, confidence 0.9): The diff is a clean, internally-consistent lockfile-only bump of Vue 3.5.40→3.5.41 (and its Babel transitive deps 7.29.7→7.29.8), with all Vue sub-packages aligned, matching internal dependency specif

Synthesis — Devstral 2 123B wrote the final review from 0 confirmed findings.

Transcript rv-20260814055217-0bada4 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260814055217-0bada4.

### AI review · advisory <!-- tti-rv:rv-20260814055217-0bada4: --> **Verdict: looks good** — all four reviewers found nothing that needs fixing. <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 0 distinct, 0 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.97): The dependency version updates and additions appear consistent and introduce no obvious bugs or security concerns. - **Gemma 4 31B** (0 findings, confidence 1.0): The pull request correctly updates the vue dependency and its associated compiler packages to v3.5.41 in the lockfile, and the incidental updates to @babel/parser and @babel/types are consistent with - **Devstral 2 123B** (0 findings, confidence 0.95): The pull request updates Vue and related dependencies to v3.5.41, which appears to be a routine dependency bump with no functional changes or security issues introduced. - **Laguna S 2.1** (0 findings, confidence 0.9): The diff is a clean, internally-consistent lockfile-only bump of Vue 3.5.40→3.5.41 (and its Babel transitive deps 7.29.7→7.29.8), with all Vue sub-packages aligned, matching internal dependency specif **Synthesis** — Devstral 2 123B wrote the final review from 0 confirmed findings. <sub>Transcript `rv-20260814055217-0bada4` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260814055217-0bada4`.</sub>
renovate-bot force-pushed renovate/vue-monorepo from f1751f8a3a
All checks were successful
ai-review / review (pull_request) Successful in 1m43s
scan / trivy-fs (pull_request) Successful in 57s
baseline-security / baseline (pull_request) Successful in 2m29s
baseline-security / baseline (push) Successful in 2m34s
scan / trivy-fs (push) Successful in 55s
to f3e4665c3e
All checks were successful
scan / trivy-fs (push) Successful in 46s
baseline-security / baseline (push) Successful in 1m53s
baseline-security / baseline (pull_request) Successful in 1m41s
scan / trivy-fs (pull_request) Successful in 40s
ai-review / review (pull_request) Successful in 3m24s
2026-08-15 05:14:00 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: nothing confirmed — a couple of single-reviewer observations below.

Findings that didn't map to a diff line:

package-lock.json:7799 · MEDIUM — Inconsistent @vue/reactivity version
The @vue/reactivity version in the diff (3.5.41) does not match the version used in the codebase (3.5.40).

Fix: Align the @vue/reactivity version with the rest of the codebase by using version 3.5.40.

package-lock.json:7811 · MEDIUM — Inconsistent @vue/runtime-core version
The @vue/runtime-core version in the diff (3.5.41) does not match the version used in the codebase (3.5.40).

Fix: Align the @vue/runtime-core version with the rest of the codebase by using version 3.5.40.

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 8 distinct, 0 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings):
  • Gemma 4 31B (0 findings, confidence 1.0): The diff consists solely of a routine dependency update for Vue and its associated compiler packages in the lockfile, with no changes to source code or configuration.
  • Devstral 2 123B (12 findings, confidence 0.95): The diff shows a version update for vue and related packages, but the versions are inconsistent with the rest of the codebase.
  • Laguna S 2.1 (0 findings, confidence 0.97): PR is a clean lockfile-only dependency bump for vue 3.5.41 plus its transitive @babel/* and Nuxt CLI sub-deps; all changed lines are mechanically consistent version/integrity updates, no code, configs

Round 2 — cross-examination

  • Devstral 2 123B#1 Inconsistent @babel/parser version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#2 Inconsistent @babel/types version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#3 Inconsistent @vue/compiler-core version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#4 Inconsistent @vue/compiler-dom version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#5 Inconsistent @vue/compiler-sfc version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#6 Inconsistent @vue/compiler-ssr version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#7 Inconsistent @vue/reactivity version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#8 Inconsistent @vue/runtime-core version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1

Synthesis — Devstral 2 123B wrote the final review from 0 confirmed findings (+8 unconfirmed).

Transcript rv-20260815054559-8e0119 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260815054559-8e0119.

### AI review · advisory <!-- tti-rv:rv-20260815054559-8e0119: --> **Verdict: nothing confirmed** — a couple of single-reviewer observations below. Findings that didn't map to a diff line: **`package-lock.json:7799`** · MEDIUM — Inconsistent @vue/reactivity version The @vue/reactivity version in the diff (3.5.41) does not match the version used in the codebase (3.5.40). > **Fix:** Align the @vue/reactivity version with the rest of the codebase by using version 3.5.40. **`package-lock.json:7811`** · MEDIUM — Inconsistent @vue/runtime-core version The @vue/runtime-core version in the diff (3.5.41) does not match the version used in the codebase (3.5.40). > **Fix:** Align the @vue/runtime-core version with the rest of the codebase by using version 3.5.40. <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 8 distinct, 0 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings): - **Gemma 4 31B** (0 findings, confidence 1.0): The diff consists solely of a routine dependency update for Vue and its associated compiler packages in the lockfile, with no changes to source code or configuration. - **Devstral 2 123B** (12 findings, confidence 0.95): The diff shows a version update for vue and related packages, but the versions are inconsistent with the rest of the codebase. - **Laguna S 2.1** (0 findings, confidence 0.97): PR is a clean lockfile-only dependency bump for vue 3.5.41 plus its transitive @babel/* and Nuxt CLI sub-deps; all changed lines are mechanically consistent version/integrity updates, no code, configs **Round 2 — cross-examination** - `Devstral 2 123B#1` Inconsistent @babel/parser version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#2` Inconsistent @babel/types version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#3` Inconsistent @vue/compiler-core version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#4` Inconsistent @vue/compiler-dom version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#5` Inconsistent @vue/compiler-sfc version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#6` Inconsistent @vue/compiler-ssr version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#7` Inconsistent @vue/reactivity version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#8` Inconsistent @vue/runtime-core version · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1 **Synthesis** — Devstral 2 123B wrote the final review from 0 confirmed findings (+8 unconfirmed). <sub>Transcript `rv-20260815054559-8e0119` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260815054559-8e0119`.</sub>
@ -2629,12 +2629,34 @@
}
}
},
"node_modules/@nuxt/cli/node_modules/cac": {
Member

package-lock.json:2632 · MEDIUM — Inconsistent @babel/parser version
The version of @babel/parser in the diff (7.29.8) does not match the version used in the rest of the codebase (7.29.7), which could lead to unexpected behavior or conflicts.

Fix: Align the version by changing it to "version": "7.29.7",.

Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):

"version": "7.29.7",

panel tally 1/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:2632`** · MEDIUM — Inconsistent @babel/parser version The version of @babel/parser in the diff (7.29.8) does not match the version used in the rest of the codebase (7.29.7), which could lead to unexpected behavior or conflicts. > **Fix:** Align the version by changing it to `"version": "7.29.7",`. **Proposed replacement** (one-click ⚡ Apply on the findings board at the top of this PR): ``` "version": "7.29.7", ``` <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260815054559-8e0119:Devstral 2 123B#1 -->
@ -2632,0 +2637,4 @@
"optional": true,
"peer": true,
"engines": {
"node": ">=8"
Member

package-lock.json:2640 · MEDIUM — Inconsistent @babel/types version
The version of @babel/types in the diff (7.29.8) does not match the version used in the rest of the codebase (7.29.7), which could lead to unexpected behavior or conflicts.

Fix: Align the version by changing it to "version": "7.29.7",.

Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):

"version": "7.29.7",

panel tally 1/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:2640`** · MEDIUM — Inconsistent @babel/types version The version of @babel/types in the diff (7.29.8) does not match the version used in the rest of the codebase (7.29.7), which could lead to unexpected behavior or conflicts. > **Fix:** Align the version by changing it to `"version": "7.29.7",`. **Proposed replacement** (one-click ⚡ Apply on the findings board at the top of this PR): ``` "version": "7.29.7", ``` <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260815054559-8e0119:Devstral 2 123B#2 -->
@ -7656,39 +7678,39 @@
}
},
"node_modules/@vue/compiler-core": {
Member

package-lock.json:7680 · MEDIUM — Inconsistent @vue/compiler-core version
The version of @vue/compiler-core in the diff (3.5.41) does not match the version used in the rest of the codebase (3.5.40), which could lead to unexpected behavior or conflicts.

Fix: Align the version by changing it to "version": "3.5.40",.

Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):

"version": "3.5.40",

panel tally 1/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:7680`** · MEDIUM — Inconsistent @vue/compiler-core version The version of @vue/compiler-core in the diff (3.5.41) does not match the version used in the rest of the codebase (3.5.40), which could lead to unexpected behavior or conflicts. > **Fix:** Align the version by changing it to `"version": "3.5.40",`. **Proposed replacement** (one-click ⚡ Apply on the findings board at the top of this PR): ``` "version": "3.5.40", ``` <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260815054559-8e0119:Devstral 2 123B#3 -->
@ -7667,4 +7689,4 @@
"estree-walker": "^2.0.2",
"source-map-js": "^1.2.1"
}
},
Member

MEDIUM — Inconsistent @vue/compiler-dom version

The @vue/compiler-dom version in the diff (3.5.41) does not match the version used in the codebase (3.5.40).

Fix: Align the @vue/compiler-dom version with the rest of the codebase by using version 3.5.40.

Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):

"version": "3.5.40",

panel tally 1/4 · reply here or use the finding board to agree/disagree

**MEDIUM** — Inconsistent @vue/compiler-dom version The @vue/compiler-dom version in the diff (3.5.41) does not match the version used in the codebase (3.5.40). > **Fix:** Align the @vue/compiler-dom version with the rest of the codebase by using version 3.5.40. **Proposed replacement** (one-click ⚡ Apply on the findings board at the top of this PR): ``` "version": "3.5.40", ``` <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260815054559-8e0119:Devstral 2 123B#4 -->
@ -7692,3 +7713,4 @@
"@vue/shared": "3.5.41",
"estree-walker": "^2.0.2",
"magic-string": "^0.30.21",
"postcss": "^8.5.19",
Member

MEDIUM — Inconsistent @vue/compiler-ssr version

The @vue/compiler-ssr version in the diff (3.5.41) does not match the version used in the codebase (3.5.40).

Fix: Align the @vue/compiler-ssr version with the rest of the codebase by using version 3.5.40.

Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):

"version": "3.5.40",

panel tally 1/4 · reply here or use the finding board to agree/disagree

**MEDIUM** — Inconsistent @vue/compiler-ssr version The @vue/compiler-ssr version in the diff (3.5.41) does not match the version used in the codebase (3.5.40). > **Fix:** Align the @vue/compiler-ssr version with the rest of the codebase by using version 3.5.40. **Proposed replacement** (one-click ⚡ Apply on the findings board at the top of this PR): ``` "version": "3.5.40", ``` <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260815054559-8e0119:Devstral 2 123B#6 -->
@ -7682,3 +7704,1 @@
"version": "3.5.40",
"resolved": "https://registry.npmjs.org/@vue/compiler-sfc/-/compiler-sfc-3.5.40.tgz",
"integrity": "sha512-gIf497P4kpuALcvs5n3AEg1Vdn0pSY4XbjASIfHNYF1/MP3T2Mf2STERTubysBxCRxzJGJYtF/O7vwJrxFB3Vw==",
"version": "3.5.41",
Member

MEDIUM — Inconsistent @vue/compiler-sfc version

The @vue/compiler-sfc version in the diff (3.5.41) does not match the version used in the codebase (3.5.40).

Fix: Align the @vue/compiler-sfc version with the rest of the codebase by using version 3.5.40.

Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):

"version": "3.5.40",

panel tally 1/4 · reply here or use the finding board to agree/disagree

**MEDIUM** — Inconsistent @vue/compiler-sfc version The @vue/compiler-sfc version in the diff (3.5.41) does not match the version used in the codebase (3.5.40). > **Fix:** Align the @vue/compiler-sfc version with the rest of the codebase by using version 3.5.40. **Proposed replacement** (one-click ⚡ Apply on the findings board at the top of this PR): ``` "version": "3.5.40", ``` <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260815054559-8e0119:Devstral 2 123B#5 -->
renovate-bot force-pushed renovate/vue-monorepo from f3e4665c3e
All checks were successful
scan / trivy-fs (push) Successful in 46s
baseline-security / baseline (push) Successful in 1m53s
baseline-security / baseline (pull_request) Successful in 1m41s
scan / trivy-fs (pull_request) Successful in 40s
ai-review / review (pull_request) Successful in 3m24s
to d59f9fe345
All checks were successful
scan / trivy-fs (push) Successful in 48s
baseline-security / baseline (push) Successful in 1m34s
scan / trivy-fs (pull_request) Successful in 56s
baseline-security / baseline (pull_request) Successful in 1m55s
ai-review / review (pull_request) Successful in 2m30s
2026-08-20 05:14:16 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: nothing confirmed — a couple of single-reviewer observations below.

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 4 distinct, 0 confirmed, 3 refuted · web: not used · context: 1 files · 89 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 89 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.99): The diff only updates package metadata and dependency versions in the lockfile, which aligns with the package.json changes and does not introduce correctness, security, or best‑practice issues.
  • Gemma 4 31B (1 finding, confidence 0.95): The PR primarily updates the Vue dependency and aligns the lockfile with a major version bump and namespace change; the changes are correct for a dependency update, though the major version jump shoul
  • Devstral 2 123B (3 findings, confidence 0.95): The package-lock.json file has inconsistencies with the package.json file, including mismatched package names and versions, and a missing license field.
  • Laguna S 2.1 (0 findings, confidence 0.95): The diff is a clean package-lock.json update: Vue 3.5.40→3.5.41 (with all @vue/* sub-packages), @babel/parser and @babel/types 7.29.7→7.29.8, plus new transitive optional-peer deps (cac, commander, pe

Round 2 — cross-examination

  • Devstral 2 123B#2 Version mismatch between package.json and package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#1 Package name mismatch between package.json and package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Gemma 4 31B#1 Inconsistent package naming and versioning · confirmed: — · refuted: Devstral 2 123B, Laguna S 2.1
  • Devstral 2 123B#3 Missing license field in the root package entry · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1

Raised but refuted (left out of the review above)

  • Devstral 2 123B#2 Version mismatch between package.json and package-lock.json — The diff updates the version in package-lock.json from "1.9.0" to "2.0.0", matching the version already defined in package.json ("2.0.0"). Therefore t
  • Devstral 2 123B#1 Package name mismatch between package.json and package-lock.json — The diff changes the package name in package-lock.json from "tti-ux" to "@tti/tti-ux", which now aligns with the name defined in package.json ("@tti/t
  • Devstral 2 123B#3 Missing license field in the root package entry — The diff adds a "license": "Apache-2.0" field after "hasInstallScript": true in the root package entry of package-lock.json, satisfying the requiremen

Synthesis — Devstral 2 123B wrote the final review from 0 confirmed findings (+1 unconfirmed).

Transcript rv-20260820053319-bd16ad — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260820053319-bd16ad.

### AI review · advisory <!-- tti-rv:rv-20260820053319-bd16ad: --> **Verdict: nothing confirmed** — a couple of single-reviewer observations below. <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 4 distinct, 0 confirmed, 3 refuted · web: not used · context: 1 files · 89 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 89 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.99): The diff only updates package metadata and dependency versions in the lockfile, which aligns with the package.json changes and does not introduce correctness, security, or best‑practice issues. - **Gemma 4 31B** (1 finding, confidence 0.95): The PR primarily updates the Vue dependency and aligns the lockfile with a major version bump and namespace change; the changes are correct for a dependency update, though the major version jump shoul - **Devstral 2 123B** (3 findings, confidence 0.95): The package-lock.json file has inconsistencies with the package.json file, including mismatched package names and versions, and a missing license field. - **Laguna S 2.1** (0 findings, confidence 0.95): The diff is a clean package-lock.json update: Vue 3.5.40→3.5.41 (with all @vue/* sub-packages), @babel/parser and @babel/types 7.29.7→7.29.8, plus new transitive optional-peer deps (cac, commander, pe **Round 2 — cross-examination** - `Devstral 2 123B#2` Version mismatch between package.json and package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#1` Package name mismatch between package.json and package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Gemma 4 31B#1` Inconsistent package naming and versioning · confirmed: — · refuted: Devstral 2 123B, Laguna S 2.1 - `Devstral 2 123B#3` Missing license field in the root package entry · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 **Raised but refuted** (left out of the review above) - `Devstral 2 123B#2` Version mismatch between package.json and package-lock.json — The diff updates the version in package-lock.json from "1.9.0" to "2.0.0", matching the version already defined in package.json ("2.0.0"). Therefore t - `Devstral 2 123B#1` Package name mismatch between package.json and package-lock.json — The diff changes the package name in package-lock.json from "tti-ux" to "@tti/tti-ux", which now aligns with the name defined in package.json ("@tti/t - `Devstral 2 123B#3` Missing license field in the root package entry — The diff adds a "license": "Apache-2.0" field after "hasInstallScript": true in the root package entry of package-lock.json, satisfying the requiremen **Synthesis** — Devstral 2 123B wrote the final review from 0 confirmed findings (+1 unconfirmed). <sub>Transcript `rv-20260820053319-bd16ad` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260820053319-bd16ad`.</sub>
@ -1,13 +1,14 @@
{
"name": "tti-ux",
"version": "1.9.0",
"name": "@tti/tti-ux",
Member

package-lock.json:2 · MEDIUM — inconsistent package naming and versioning
The package name changed from 'tti-ux' to '@tti/tti-ux' and the version jumped from 1.9.0 to 2.0.0, but the CHANGELOG.md does not document the breaking change required for a major version bump, and the package.json may not yet reflect these changes. This can lead to confusion and failed builds if the manifests are out of sync.

Fix: Document the breaking change in CHANGELOG.md and verify that the package name and version are identical in both package.json and package-lock.json.

panel tally 1/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:2`** · MEDIUM — inconsistent package naming and versioning The package name changed from 'tti-ux' to '@tti/tti-ux' and the version jumped from 1.9.0 to 2.0.0, but the CHANGELOG.md does not document the breaking change required for a major version bump, and the package.json may not yet reflect these changes. This can lead to confusion and failed builds if the manifests are out of sync. > **Fix:** Document the breaking change in CHANGELOG.md and verify that the package name and version are identical in both package.json and package-lock.json. <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260820053319-bd16ad:Gemma 4 31B#1 -->
renovate-bot force-pushed renovate/vue-monorepo from d59f9fe345
All checks were successful
scan / trivy-fs (push) Successful in 48s
baseline-security / baseline (push) Successful in 1m34s
scan / trivy-fs (pull_request) Successful in 56s
baseline-security / baseline (pull_request) Successful in 1m55s
ai-review / review (pull_request) Successful in 2m30s
to f570e4dbb3
All checks were successful
baseline-security / baseline (push) Successful in 1m42s
scan / trivy-fs (push) Successful in 49s
scan / trivy-fs (pull_request) Successful in 59s
baseline-security / baseline (pull_request) Successful in 2m1s
ai-review / review (pull_request) Successful in 2m21s
2026-08-21 05:20:06 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: 1 thing worth fixing (1 low).

Findings that didn't map to a diff line:

package-lock.json:7789 · LOW — Inconsistent @vue/compiler-core version
The @vue/compiler-core version in the diff (3.5.41) does not match the version specified in the package.json file (3.5.32).

Fix: Update the version in package.json to match the version in the diff (3.5.41).

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 1 confirmed, 2 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.9): The dependency version updates in package-lock.json appear consistent with the existing package.json constraints and do not introduce obvious correctness, security, or best‑practice issues.
  • Gemma 4 31B (0 findings, confidence 1.0): The diff contains only dependency updates in package-lock.json, updating vue and related @vue packages to v3.5.41, which is a standard chore update.
  • Devstral 2 123B (3 findings, confidence 0.9): The diff updates Vue and related dependencies to newer versions, but there are inconsistencies with the versions specified in the package.json file.
  • Laguna S 2.1 (0 findings, confidence 0.95): The diff is a lockfile-only dependency bump from vue 3.5.40 to 3.5.41 (with transitive @babel/parser and @babel/types bumps to 7.29.8, and new optional peer deps nested under @nuxt/cli). All @vue/* pa

Round 2 — cross-examination

  • Devstral 2 123B#1 Inconsistent @babel/parser version · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#2 Inconsistent @babel/types version · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#3 Inconsistent @vue/compiler-core version · confirmed: Gemma 4 31B · refuted: GPT-OSS 120B, Laguna S 2.1

Raised but refuted (left out of the review above)

  • Devstral 2 123B#1 Inconsistent @babel/parser version — The package.json does not declare a version for @babel/parser; it is only a transitive dependency managed in package-lock.json. Therefore there is no
  • Devstral 2 123B#2 Inconsistent @babel/types version — Similarly, @babel/types is not listed in package.json, so the claim of a version mismatch in package.json is unsupported.

Synthesis — Devstral 2 123B wrote the final review from 1 confirmed finding.

Transcript rv-20260821054519-47db57 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260821054519-47db57.

### AI review · advisory <!-- tti-rv:rv-20260821054519-47db57: --> **Verdict: 1 thing worth fixing** (1 low). Findings that didn't map to a diff line: **`package-lock.json:7789`** · LOW — Inconsistent @vue/compiler-core version The @vue/compiler-core version in the diff (3.5.41) does not match the version specified in the package.json file (3.5.32). > **Fix:** Update the version in package.json to match the version in the diff (3.5.41). <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 1 confirmed, 2 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.9): The dependency version updates in package-lock.json appear consistent with the existing package.json constraints and do not introduce obvious correctness, security, or best‑practice issues. - **Gemma 4 31B** (0 findings, confidence 1.0): The diff contains only dependency updates in package-lock.json, updating vue and related @vue packages to v3.5.41, which is a standard chore update. - **Devstral 2 123B** (3 findings, confidence 0.9): The diff updates Vue and related dependencies to newer versions, but there are inconsistencies with the versions specified in the package.json file. - **Laguna S 2.1** (0 findings, confidence 0.95): The diff is a lockfile-only dependency bump from vue 3.5.40 to 3.5.41 (with transitive @babel/parser and @babel/types bumps to 7.29.8, and new optional peer deps nested under @nuxt/cli). All @vue/* pa **Round 2 — cross-examination** - `Devstral 2 123B#1` Inconsistent @babel/parser version · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#2` Inconsistent @babel/types version · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#3` Inconsistent @vue/compiler-core version · confirmed: Gemma 4 31B · refuted: GPT-OSS 120B, Laguna S 2.1 **Raised but refuted** (left out of the review above) - `Devstral 2 123B#1` Inconsistent @babel/parser version — The package.json does not declare a version for @babel/parser; it is only a transitive dependency managed in package-lock.json. Therefore there is no - `Devstral 2 123B#2` Inconsistent @babel/types version — Similarly, @babel/types is not listed in package.json, so the claim of a version mismatch in package.json is unsupported. **Synthesis** — Devstral 2 123B wrote the final review from 1 confirmed finding. <sub>Transcript `rv-20260821054519-47db57` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260821054519-47db57`.</sub>
renovate-bot changed title from chore(deps): update dependency vue to v3.5.41 to chore(deps): update dependency vue to v3.5.42 2026-08-28 05:15:29 +00:00
renovate-bot force-pushed renovate/vue-monorepo from f570e4dbb3
All checks were successful
baseline-security / baseline (push) Successful in 1m42s
scan / trivy-fs (push) Successful in 49s
scan / trivy-fs (pull_request) Successful in 59s
baseline-security / baseline (pull_request) Successful in 2m1s
ai-review / review (pull_request) Successful in 2m21s
to 82465c9bd2
All checks were successful
scan / trivy-fs (push) Successful in 51s
baseline-security / baseline (push) Successful in 1m45s
scan / trivy-fs (pull_request) Successful in 52s
ai-review / review (pull_request) Successful in 1m48s
baseline-security / baseline (pull_request) Successful in 1m41s
2026-08-28 05:15:31 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: 1 thing worth fixing (1 high).

Findings that didn't map to a diff line:

package-lock.json:7786 · HIGH — Vue version mismatch
The package-lock.json shows Vue 3.5.42 being installed, but the package.json specifies Vue 3.5.32 as a dependency.

Fix: Update the package.json to specify Vue 3.5.42 as the dependency.

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 1 distinct, 1 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.97): The changes only update dependency versions in package-lock.json and add optional peer dependencies; no code changes introduce bugs or security concerns.
  • Gemma 4 31B (0 findings, confidence 1.0): The diff is a standard dependency update for Vue and its associated compiler/runtime packages in the lockfile, and it appears correct.
  • Devstral 2 123B (1 finding, confidence 0.9): The package-lock.json has been updated to Vue 3.5.42, but the package.json still specifies Vue 3.5.32. This mismatch should be corrected to ensure consistency.
  • Laguna S 2.1 (0 findings, confidence 0.95): The diff is a clean lockfile-only update bumping vue and its @vue/* packages from 3.5.40 to 3.5.42 and transitive @babel/parser + @babel/types from 7.29.7 to 7.29.8; all cross-references, versions, an

Round 2 — cross-examination

  • Devstral 2 123B#1 Vue version mismatch · confirmed: Gemma 4 31B · refuted: GPT-OSS 120B, Laguna S 2.1

Synthesis — Devstral 2 123B wrote the final review from 1 confirmed finding.

Transcript rv-20260828052807-6a44f3 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260828052807-6a44f3.

### AI review · advisory <!-- tti-rv:rv-20260828052807-6a44f3: --> **Verdict: 1 thing worth fixing** (1 high). Findings that didn't map to a diff line: **`package-lock.json:7786`** · HIGH — Vue version mismatch The package-lock.json shows Vue 3.5.42 being installed, but the package.json specifies Vue 3.5.32 as a dependency. > **Fix:** Update the package.json to specify Vue 3.5.42 as the dependency. <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 1 distinct, 1 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.97): The changes only update dependency versions in package-lock.json and add optional peer dependencies; no code changes introduce bugs or security concerns. - **Gemma 4 31B** (0 findings, confidence 1.0): The diff is a standard dependency update for Vue and its associated compiler/runtime packages in the lockfile, and it appears correct. - **Devstral 2 123B** (1 finding, confidence 0.9): The package-lock.json has been updated to Vue 3.5.42, but the package.json still specifies Vue 3.5.32. This mismatch should be corrected to ensure consistency. - **Laguna S 2.1** (0 findings, confidence 0.95): The diff is a clean lockfile-only update bumping vue and its @vue/* packages from 3.5.40 to 3.5.42 and transitive @babel/parser + @babel/types from 7.29.7 to 7.29.8; all cross-references, versions, an **Round 2 — cross-examination** - `Devstral 2 123B#1` Vue version mismatch · confirmed: Gemma 4 31B · refuted: GPT-OSS 120B, Laguna S 2.1 **Synthesis** — Devstral 2 123B wrote the final review from 1 confirmed finding. <sub>Transcript `rv-20260828052807-6a44f3` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260828052807-6a44f3`.</sub>
renovate-bot force-pushed renovate/vue-monorepo from 82465c9bd2
All checks were successful
scan / trivy-fs (push) Successful in 51s
baseline-security / baseline (push) Successful in 1m45s
scan / trivy-fs (pull_request) Successful in 52s
ai-review / review (pull_request) Successful in 1m48s
baseline-security / baseline (pull_request) Successful in 1m41s
to 0a7f94e5a4
All checks were successful
ai-review / review (pull_request) Successful in 2m32s
scan / trivy-fs (push) Successful in 47s
baseline-security / baseline (push) Successful in 1m34s
scan / trivy-fs (pull_request) Successful in 40s
baseline-security / baseline (pull_request) Successful in 1m29s
2026-08-30 05:18:02 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: 3 things worth fixing (2 medium · 1 low).

Findings that didn't map to a diff line:

package-lock.json:2696 · MEDIUM — @nuxt/cli/node_modules/commander added with engines node>=20 mismatch risk
The diff adds node_modules/@nuxt/cli/node_modules/commander at version 14.0.3 with engines.node >= 20. The tti/coding-standards security.md SCA gate requires lockfile engines to match the declared runtime; this repo's package.json does not pin node>=20 in one place, and an unexpected node-20-only transitive under @nuxt/cli could break installs on supported node versions. Needs confirmation that commander@14 is a real transitive of @nuxt/cli and that the node engine floor is intentional.

Fix: Confirm commander@14.0.3 with engines node>=20 is an intentional transitive of the @nuxt/cli version now installed; if so, add a CI note and ensure CI runs on node>=20. If it is a lockfile artifact from a partial install, regenerate the lockfile cleanly with npm install.

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 11 distinct (from 12 reviewer findings), 3 confirmed, 8 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.96): No issues detected in the lockfile changes; all version bumps are compatible and follow standard practices.
  • Gemma 4 31B (0 findings, confidence 1.0): The diff is a standard dependency update for Vue and its associated compiler/runtime packages, with corresponding lockfile updates. No correctness, security, or best-practice issues were found in the
  • Devstral 2 123B (10 findings, confidence 0.9): The package-lock.json file has been updated to reflect the new version of vue and its related packages. However, there are version mismatches between package-lock.json and package.json that need to be
  • Laguna S 2.1 (4 findings, confidence 0.75): The diff is a routine vue 3.5.40 → 3.5.42 bump plus the expected @babel/parser/types bump; the @vue/* internals all move to 3.5.42 and cross-reference consistently. The only concerns are two unexplain

Grouping — 12 reviewer findings describe 11 distinct defects; reviewers who found the same defect independently count as support.

Round 2 — cross-examination

  • Laguna S 2.1#2 @nuxt/cli/node_modules/commander added with engines node>=20 mismatch risk · confirmed: Gemma 4 31B · refuted: GPT-OSS 120B, Devstral 2 123B
  • Laguna S 2.1#1 @nuxt/cli/node_modules/cac added as extraneous nested dependency · confirmed: Gemma 4 31B · refuted: GPT-OSS 120B, Devstral 2 123B
  • Devstral 2 123B#1 Version mismatch in @vue/compiler-core · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#2 Version mismatch in @vue/compiler-dom · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#3 Version mismatch in @vue/compiler-sfc · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#4 Version mismatch in @vue/compiler-ssr · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#5 Version mismatch in @vue/reactivity · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#6 Version mismatch in @vue/runtime-core · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#7 Version mismatch in @vue/runtime-dom · also raised by: Laguna S 2.1 · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B
  • Devstral 2 123B#8 Version mismatch in @vue/server-renderer · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Laguna S 2.1#3 @vue/compiler-sfc dependency on @babel/parser ^7.29.8 is consistent but verify l · confirmed: Gemma 4 31B, Devstral 2 123B · refuted: GPT-OSS 120B

Raised but refuted (left out of the review above)

  • Devstral 2 123B#1 Version mismatch in @vue/compiler-core — @vue/compiler-core is not listed directly in package.json; it is a transitive dependency of the vue package. The lockfile’s version 3.5.42 is co
  • Devstral 2 123B#2 Version mismatch in @vue/compiler-dom — @vue/compiler-dom is also a transitive dependency of vue. The lockfile version (3.5.42) matches the implicit version required by vue, so there i
  • Devstral 2 123B#3 Version mismatch in @vue/compiler-sfc — @vue/compiler-sfc is not pinned in package.json; it is pulled in via vue. The lockfile version 3.5.42 aligns with the vue dependency and there
  • Devstral 2 123B#4 Version mismatch in @vue/compiler-ssr — @vue/compiler-ssr is a transitive dependency of vue. The lockfile correctly lists version 3.5.42, matching the version required by the vue packa

Synthesis — Devstral 2 123B wrote the final review from 3 confirmed findings.

Transcript rv-20260830053356-cfeb34 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260830053356-cfeb34.

### AI review · advisory <!-- tti-rv:rv-20260830053356-cfeb34: --> **Verdict: 3 things worth fixing** (2 medium · 1 low). Findings that didn't map to a diff line: **`package-lock.json:2696`** · MEDIUM — @nuxt/cli/node_modules/commander added with engines node>=20 mismatch risk The diff adds `node_modules/@nuxt/cli/node_modules/commander` at version 14.0.3 with `engines.node >= 20`. The tti/coding-standards security.md SCA gate requires lockfile engines to match the declared runtime; this repo's package.json does not pin node>=20 in one place, and an unexpected node-20-only transitive under @nuxt/cli could break installs on supported node versions. Needs confirmation that commander@14 is a real transitive of @nuxt/cli and that the node engine floor is intentional. > **Fix:** Confirm commander@14.0.3 with engines node>=20 is an intentional transitive of the @nuxt/cli version now installed; if so, add a CI note and ensure CI runs on node>=20. If it is a lockfile artifact from a partial install, regenerate the lockfile cleanly with `npm install`. <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 11 distinct (from 12 reviewer findings), 3 confirmed, 8 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.96): No issues detected in the lockfile changes; all version bumps are compatible and follow standard practices. - **Gemma 4 31B** (0 findings, confidence 1.0): The diff is a standard dependency update for Vue and its associated compiler/runtime packages, with corresponding lockfile updates. No correctness, security, or best-practice issues were found in the - **Devstral 2 123B** (10 findings, confidence 0.9): The package-lock.json file has been updated to reflect the new version of vue and its related packages. However, there are version mismatches between package-lock.json and package.json that need to be - **Laguna S 2.1** (4 findings, confidence 0.75): The diff is a routine vue 3.5.40 → 3.5.42 bump plus the expected @babel/parser/types bump; the @vue/* internals all move to 3.5.42 and cross-reference consistently. The only concerns are two unexplain **Grouping** — 12 reviewer findings describe 11 distinct defects; reviewers who found the same defect independently count as support. **Round 2 — cross-examination** - `Laguna S 2.1#2` @nuxt/cli/node_modules/commander added with engines node>=20 mismatch risk · confirmed: Gemma 4 31B · refuted: GPT-OSS 120B, Devstral 2 123B - `Laguna S 2.1#1` @nuxt/cli/node_modules/cac added as extraneous nested dependency · confirmed: Gemma 4 31B · refuted: GPT-OSS 120B, Devstral 2 123B - `Devstral 2 123B#1` Version mismatch in @vue/compiler-core · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#2` Version mismatch in @vue/compiler-dom · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#3` Version mismatch in @vue/compiler-sfc · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#4` Version mismatch in @vue/compiler-ssr · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#5` Version mismatch in @vue/reactivity · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#6` Version mismatch in @vue/runtime-core · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#7` Version mismatch in @vue/runtime-dom · also raised by: Laguna S 2.1 · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B - `Devstral 2 123B#8` Version mismatch in @vue/server-renderer · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Laguna S 2.1#3` @vue/compiler-sfc dependency on @babel/parser ^7.29.8 is consistent but verify l · confirmed: Gemma 4 31B, Devstral 2 123B · refuted: GPT-OSS 120B **Raised but refuted** (left out of the review above) - `Devstral 2 123B#1` Version mismatch in @vue/compiler-core — `@vue/compiler-core` is not listed directly in `package.json`; it is a transitive dependency of the `vue` package. The lockfile’s version 3.5.42 is co - `Devstral 2 123B#2` Version mismatch in @vue/compiler-dom — `@vue/compiler-dom` is also a transitive dependency of `vue`. The lockfile version (3.5.42) matches the implicit version required by `vue`, so there i - `Devstral 2 123B#3` Version mismatch in @vue/compiler-sfc — `@vue/compiler-sfc` is not pinned in `package.json`; it is pulled in via `vue`. The lockfile version 3.5.42 aligns with the `vue` dependency and there - `Devstral 2 123B#4` Version mismatch in @vue/compiler-ssr — `@vue/compiler-ssr` is a transitive dependency of `vue`. The lockfile correctly lists version 3.5.42, matching the version required by the `vue` packa **Synthesis** — Devstral 2 123B wrote the final review from 3 confirmed findings. <sub>Transcript `rv-20260830053356-cfeb34` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260830053356-cfeb34`.</sub>
@ -2652,0 +2668,4 @@
"optional": true,
"peer": true,
"engines": {
"node": ">=20"
Member

package-lock.json:2671 · MEDIUM — extraneous nested dependency added
The diff adds a new node_modules/@nuxt/cli/node_modules/cac entry that may not be a legitimate dependency of @nuxt/cli, which could lead to unexpected behavior or security issues. This could happen if the package is not properly declared in the dependency tree.

Fix: Verify that cac is a declared dependency of @nuxt/cli in its package.json. If not, regenerate the lockfile with npm install to ensure the entry is hoisted or removed.

panel tally 2/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:2671`** · MEDIUM — extraneous nested dependency added The diff adds a new `node_modules/@nuxt/cli/node_modules/cac` entry that may not be a legitimate dependency of @nuxt/cli, which could lead to unexpected behavior or security issues. This could happen if the package is not properly declared in the dependency tree. > **Fix:** Verify that `cac` is a declared dependency of `@nuxt/cli` in its `package.json`. If not, regenerate the lockfile with `npm install` to ensure the entry is hoisted or removed. <sub>panel tally 2/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260830053356-cfeb34:Laguna S 2.1#1 -->
@ -7796,3 +7817,4 @@
"@vue/shared": "3.5.42",
"entities": "^7.0.1",
"estree-walker": "^2.0.2",
"source-map-js": "^1.2.1"
Member

package-lock.json:7820 · LOW — verify @babel/parser lockstep
The diff updates @vue/compiler-sfc and its dependency on @babel/parser to ^7.29.8. If different packages resolve to different versions of @babel/parser, it could lead to duplicate AST parser instances, causing correctness issues in SFC compilation.

Fix: Run npm ls @babel/parser to confirm all installed copies are 7.29.8. If any resolve to 7.29.7, add an override in package.json to force @babel/parser to ^7.29.8.

panel tally 3/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:7820`** · LOW — verify @babel/parser lockstep The diff updates `@vue/compiler-sfc` and its dependency on `@babel/parser` to `^7.29.8`. If different packages resolve to different versions of `@babel/parser`, it could lead to duplicate AST parser instances, causing correctness issues in SFC compilation. > **Fix:** Run `npm ls @babel/parser` to confirm all installed copies are `7.29.8`. If any resolve to `7.29.7`, add an override in `package.json` to force `@babel/parser` to `^7.29.8`. <sub>panel tally 3/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260830053356-cfeb34:Laguna S 2.1#3 -->
renovate-bot force-pushed renovate/vue-monorepo from 0a7f94e5a4
All checks were successful
ai-review / review (pull_request) Successful in 2m32s
scan / trivy-fs (push) Successful in 47s
baseline-security / baseline (push) Successful in 1m34s
scan / trivy-fs (pull_request) Successful in 40s
baseline-security / baseline (pull_request) Successful in 1m29s
to e34156e570
All checks were successful
scan / trivy-fs (push) Successful in 58s
baseline-security / baseline (push) Successful in 1m50s
baseline-security / baseline (pull_request) Successful in 1m34s
scan / trivy-fs (pull_request) Successful in 42s
ai-review / review (pull_request) Successful in 4m2s
2026-08-31 05:18:52 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: 1 thing worth fixing (1 medium).

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 8 distinct, 1 confirmed, 7 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.97): The lockfile updates only bump versions within existing compatible ranges and introduce optional peer packages; no correctness, security, or best‑practice concerns are evident.
  • Gemma 4 31B (0 findings, confidence 1.0): The diff consists solely of a dependency update for Vue and its associated compiler packages in package-lock.json; all changes are consistent with the PR title and follow standard lockfile update patt
  • Devstral 2 123B (8 findings, confidence 0.85): The PR updates Vue to v3.5.42 and includes several version mismatches between dependencies and their listed versions, which could lead to compatibility issues.
  • Laguna S 2.1 (0 findings, confidence 0.95): The diff is a routine dependency bump of vue from 3.5.40 to 3.5.42 in package-lock.json, with consistent version propagation across all @vue/* packages and @babel/parser/@babel/types; no source code,

Round 2 — cross-examination

  • Devstral 2 123B#5 Version mismatch between @vue/compiler-sfc and its dependencies · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#3 Version mismatch between @vue/compiler-core and @vue/shared · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#2 Version mismatch between @babel/types and its dependencies · confirmed: GPT-OSS 120B · refuted: Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#1 Version mismatch between @babel/parser and @babel/types · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#4 Version mismatch between @vue/compiler-dom and @vue/shared · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#6 Version mismatch between @vue/compiler-ssr and @vue/shared · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#8 Version mismatch between @vue/runtime-core and its dependencies · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#7 Version mismatch between @vue/reactivity and @vue/shared · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1

Raised but refuted (left out of the review above)

  • Devstral 2 123B#5 Version mismatch between @vue/compiler-sfc and its dependencies — The @vue/compiler-sfc package was bumped to 3.5.42 and its internal Vue dependencies (@vue/compiler-core, @vue/compiler-dom, @vue/compiler-ssr, @vue/s
  • Devstral 2 123B#3 Version mismatch between @vue/compiler-core and @vue/shared — @vue/compiler-core is at version 3.5.42 and lists @vue/shared 3.5.42 as a dependency, which matches the installed version. No mismatch exists.
  • Devstral 2 123B#1 Version mismatch between @babel/parser and @babel/types — @babel/parser was also upgraded to 7.29.8 and its dependency on @babel/types is "^7.29.8", which resolves to the installed 7.29.8 version. No mismatch
  • Devstral 2 123B#4 Version mismatch between @vue/compiler-dom and @vue/shared — @vue/compiler-dom is at 3.5.42 and depends on @vue/shared 3.5.42, which is the version installed. The versions are aligned.

Synthesis — Devstral 2 123B wrote the final review from 1 confirmed finding.

Transcript rv-20260831053433-2075fe — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260831053433-2075fe.

### AI review · advisory <!-- tti-rv:rv-20260831053433-2075fe: --> **Verdict: 1 thing worth fixing** (1 medium). <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 8 distinct, 1 confirmed, 7 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.97): The lockfile updates only bump versions within existing compatible ranges and introduce optional peer packages; no correctness, security, or best‑practice concerns are evident. - **Gemma 4 31B** (0 findings, confidence 1.0): The diff consists solely of a dependency update for Vue and its associated compiler packages in package-lock.json; all changes are consistent with the PR title and follow standard lockfile update patt - **Devstral 2 123B** (8 findings, confidence 0.85): The PR updates Vue to v3.5.42 and includes several version mismatches between dependencies and their listed versions, which could lead to compatibility issues. - **Laguna S 2.1** (0 findings, confidence 0.95): The diff is a routine dependency bump of vue from 3.5.40 to 3.5.42 in package-lock.json, with consistent version propagation across all @vue/* packages and @babel/parser/@babel/types; no source code, **Round 2 — cross-examination** - `Devstral 2 123B#5` Version mismatch between @vue/compiler-sfc and its dependencies · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#3` Version mismatch between @vue/compiler-core and @vue/shared · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#2` Version mismatch between @babel/types and its dependencies · confirmed: GPT-OSS 120B · refuted: Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#1` Version mismatch between @babel/parser and @babel/types · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#4` Version mismatch between @vue/compiler-dom and @vue/shared · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#6` Version mismatch between @vue/compiler-ssr and @vue/shared · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#8` Version mismatch between @vue/runtime-core and its dependencies · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#7` Version mismatch between @vue/reactivity and @vue/shared · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 **Raised but refuted** (left out of the review above) - `Devstral 2 123B#5` Version mismatch between @vue/compiler-sfc and its dependencies — The @vue/compiler-sfc package was bumped to 3.5.42 and its internal Vue dependencies (@vue/compiler-core, @vue/compiler-dom, @vue/compiler-ssr, @vue/s - `Devstral 2 123B#3` Version mismatch between @vue/compiler-core and @vue/shared — @vue/compiler-core is at version 3.5.42 and lists @vue/shared 3.5.42 as a dependency, which matches the installed version. No mismatch exists. - `Devstral 2 123B#1` Version mismatch between @babel/parser and @babel/types — @babel/parser was also upgraded to 7.29.8 and its dependency on @babel/types is "^7.29.8", which resolves to the installed 7.29.8 version. No mismatch - `Devstral 2 123B#4` Version mismatch between @vue/compiler-dom and @vue/shared — @vue/compiler-dom is at 3.5.42 and depends on @vue/shared 3.5.42, which is the version installed. The versions are aligned. **Synthesis** — Devstral 2 123B wrote the final review from 1 confirmed finding. <sub>Transcript `rv-20260831053433-2075fe` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260831053433-2075fe`.</sub>
@ -7786,39 +7808,39 @@
}
},
"node_modules/@vue/compiler-core": {
Member

package-lock.json:7810 · MEDIUM — Version mismatch between @babel/types and its dependencies
The version of @babel/types (7.29.8) does not match the version of its dependencies (7.29.7), which could lead to compatibility issues and unexpected behavior.

Fix: Update the dependencies to match the version of @babel/types by changing the version of @babel/helper-string-parser and @babel/helper-validator-identifier to 7.29.8.

Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):

"@babel/types": {
  "version": "7.29.8",
  "resolved": "https://registry.npmjs.org/@babel/types/-/types-7.29.8.tgz",
  "integrity": "sha512-Vj1jF3cPfxg7OAfoI7QnVKLoILlm2JF9pnVHrX8qx7AHMiYWT+NDAA7jChlNgRS4WTLc/fD1lXLmPixluj+3Gg==",
  "license": "MIT",
  "dependencies": {
    "@babel/helper-string-parser": "7.29.8",
    "@babel/helper-validator-identifier": "7.29.8"
  },
  "engines": {
    "node": ">=6.9.0"
  }
}

panel tally 2/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:7810`** · MEDIUM — Version mismatch between @babel/types and its dependencies The version of @babel/types (7.29.8) does not match the version of its dependencies (7.29.7), which could lead to compatibility issues and unexpected behavior. > **Fix:** Update the dependencies to match the version of @babel/types by changing the version of `@babel/helper-string-parser` and `@babel/helper-validator-identifier` to `7.29.8`. **Proposed replacement** (one-click ⚡ Apply on the findings board at the top of this PR): ``` "@babel/types": { "version": "7.29.8", "resolved": "https://registry.npmjs.org/@babel/types/-/types-7.29.8.tgz", "integrity": "sha512-Vj1jF3cPfxg7OAfoI7QnVKLoILlm2JF9pnVHrX8qx7AHMiYWT+NDAA7jChlNgRS4WTLc/fD1lXLmPixluj+3Gg==", "license": "MIT", "dependencies": { "@babel/helper-string-parser": "7.29.8", "@babel/helper-validator-identifier": "7.29.8" }, "engines": { "node": ">=6.9.0" } } ``` <sub>panel tally 2/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260831053433-2075fe:Devstral 2 123B#2 -->
renovate-bot force-pushed renovate/vue-monorepo from e34156e570
All checks were successful
scan / trivy-fs (push) Successful in 58s
baseline-security / baseline (push) Successful in 1m50s
baseline-security / baseline (pull_request) Successful in 1m34s
scan / trivy-fs (pull_request) Successful in 42s
ai-review / review (pull_request) Successful in 4m2s
to f0c0d5b593
All checks were successful
baseline-security / baseline (pull_request) Successful in 1m20s
ai-review / review (pull_request) Successful in 1m45s
scan / trivy-fs (pull_request) Successful in 50s
scan / trivy-fs (push) Successful in 57s
baseline-security / baseline (push) Successful in 2m14s
2026-09-01 05:22:42 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: looks good — all four reviewers found nothing that needs fixing.

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 2 distinct, 0 confirmed, 2 refuted · web: 2 queries, 6 results · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.97): The diff only updates dependency versions in package-lock.json and adds optional peer entries for @nuxt/cli; these changes are benign and align with the allowed version ranges.
  • Gemma 4 31B (0 findings, confidence 1.0): The diff is a standard dependency update for Vue and related compiler packages in package-lock.json; no bugs, security issues, or best-practice gaps were found.
  • Devstral 2 123B (2 findings, confidence 0.8): The Vue version update to 3.5.42 appears to be a routine dependency update, but compatibility with React 19.0.0 should be verified, and the Vue changelog should be reviewed for any breaking changes.
  • Laguna S 2.1 (0 findings):

Web grounding — web: 2 queries, 6 results: «Vue 3.5.42 changelog»; «Vue 3.5.42 breaking changes»

Round 2 — cross-examination

  • Devstral 2 123B#1 Vue version update without corresponding peer dependency updates · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#2 Potential breaking changes in Vue 3.5.42 · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1

Raised but refuted (left out of the review above)

  • Devstral 2 123B#1 Vue version update without corresponding peer dependency updates — The diff only updates Vue to 3.5.42. The React package's peerDependencies do not reference Vue at all, so there is no missing peer dependency to updat
  • Devstral 2 123B#2 Potential breaking changes in Vue 3.5.42 — The evidence shows a version bump to Vue 3.5.42 but provides no indication of actual breaking changes; the claim is speculative and not supported by t

Synthesis — Devstral 2 123B wrote the final review from 0 confirmed findings.

Transcript rv-20260901055326-a64bdd — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260901055326-a64bdd.

### AI review · advisory <!-- tti-rv:rv-20260901055326-a64bdd: --> **Verdict: looks good** — all four reviewers found nothing that needs fixing. <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 2 distinct, 0 confirmed, 2 refuted · web: 2 queries, 6 results · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.97): The diff only updates dependency versions in package-lock.json and adds optional peer entries for @nuxt/cli; these changes are benign and align with the allowed version ranges. - **Gemma 4 31B** (0 findings, confidence 1.0): The diff is a standard dependency update for Vue and related compiler packages in package-lock.json; no bugs, security issues, or best-practice gaps were found. - **Devstral 2 123B** (2 findings, confidence 0.8): The Vue version update to 3.5.42 appears to be a routine dependency update, but compatibility with React 19.0.0 should be verified, and the Vue changelog should be reviewed for any breaking changes. - **Laguna S 2.1** (0 findings): **Web grounding** — web: 2 queries, 6 results: «Vue 3.5.42 changelog»; «Vue 3.5.42 breaking changes» **Round 2 — cross-examination** - `Devstral 2 123B#1` Vue version update without corresponding peer dependency updates · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#2` Potential breaking changes in Vue 3.5.42 · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 **Raised but refuted** (left out of the review above) - `Devstral 2 123B#1` Vue version update without corresponding peer dependency updates — The diff only updates Vue to 3.5.42. The React package's peerDependencies do not reference Vue at all, so there is no missing peer dependency to updat - `Devstral 2 123B#2` Potential breaking changes in Vue 3.5.42 — The evidence shows a version bump to Vue 3.5.42 but provides no indication of actual breaking changes; the claim is speculative and not supported by t **Synthesis** — Devstral 2 123B wrote the final review from 0 confirmed findings. <sub>Transcript `rv-20260901055326-a64bdd` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260901055326-a64bdd`.</sub>
renovate-bot force-pushed renovate/vue-monorepo from f0c0d5b593
All checks were successful
baseline-security / baseline (pull_request) Successful in 1m20s
ai-review / review (pull_request) Successful in 1m45s
scan / trivy-fs (pull_request) Successful in 50s
scan / trivy-fs (push) Successful in 57s
baseline-security / baseline (push) Successful in 2m14s
to 88dbce9bbc
All checks were successful
scan / trivy-fs (push) Successful in 1m6s
baseline-security / baseline (push) Successful in 1m54s
scan / trivy-fs (pull_request) Successful in 41s
baseline-security / baseline (pull_request) Successful in 1m32s
ai-review / review (pull_request) Successful in 3m21s
2026-09-02 05:11:34 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: nothing confirmed — a couple of single-reviewer observations below.

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 0 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.97): The dependency updates in this PR are consistent with the existing version constraints and do not introduce obvious bugs, security regressions, or best‑practice violations.
  • Gemma 4 31B (0 findings, confidence 1.0): The diff is a standard dependency update for Vue and its related compiler/runtime packages, along with a corresponding version bump for the project and its React workspace package; no correctness or s
  • Devstral 2 123B (3 findings, confidence 0.8): The package-lock.json file has version mismatches that need to be corrected to match the package.json file.
  • Laguna S 2.1 (0 findings):

Round 2 — cross-examination

  • Devstral 2 123B#1 Version mismatch in package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B
  • Devstral 2 123B#2 Version mismatch in package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B
  • Devstral 2 123B#3 Version mismatch in package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B

Synthesis — Devstral 2 123B wrote the final review from 0 confirmed findings (+3 unconfirmed).

Transcript rv-20260902052245-1811b1 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260902052245-1811b1.

### AI review · advisory <!-- tti-rv:rv-20260902052245-1811b1: --> **Verdict: nothing confirmed** — a couple of single-reviewer observations below. <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 0 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.97): The dependency updates in this PR are consistent with the existing version constraints and do not introduce obvious bugs, security regressions, or best‑practice violations. - **Gemma 4 31B** (0 findings, confidence 1.0): The diff is a standard dependency update for Vue and its related compiler/runtime packages, along with a corresponding version bump for the project and its React workspace package; no correctness or s - **Devstral 2 123B** (3 findings, confidence 0.8): The package-lock.json file has version mismatches that need to be corrected to match the package.json file. - **Laguna S 2.1** (0 findings): **Round 2 — cross-examination** - `Devstral 2 123B#1` Version mismatch in package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B - `Devstral 2 123B#2` Version mismatch in package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B - `Devstral 2 123B#3` Version mismatch in package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B **Synthesis** — Devstral 2 123B wrote the final review from 0 confirmed findings (+3 unconfirmed). <sub>Transcript `rv-20260902052245-1811b1` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260902052245-1811b1`.</sub>
@ -1,12 +1,12 @@
{
Member

package-lock.json:1 · MEDIUM — Version mismatch in package-lock.json
The version listed here does not match the one in package.json, which can lead to confusion or installation errors when dependencies are installed.

Fix: Update the version in package-lock.json to match the version in package.json ("version": "2.0.0").

Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):

"version": "2.0.0"

panel tally 1/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:1`** · MEDIUM — Version mismatch in package-lock.json The version listed here does not match the one in package.json, which can lead to confusion or installation errors when dependencies are installed. > **Fix:** Update the version in package-lock.json to match the version in package.json (`"version": "2.0.0"`). **Proposed replacement** (one-click ⚡ Apply on the findings board at the top of this PR): ``` "version": "2.0.0" ``` <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260902052245-1811b1:Devstral 2 123B#1 -->
@ -480,12 +480,12 @@
}
Member

package-lock.json:480 · MEDIUM — Version mismatch in package-lock.json
The version listed here does not match the one in package.json, which can lead to confusion or installation errors when dependencies are installed.

Fix: Update the version in package-lock.json to match the version in package.json ("version": "2.0.0").

Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):

"version": "2.0.0"

panel tally 1/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:480`** · MEDIUM — Version mismatch in package-lock.json The version listed here does not match the one in package.json, which can lead to confusion or installation errors when dependencies are installed. > **Fix:** Update the version in package-lock.json to match the version in package.json (`"version": "2.0.0"`). **Proposed replacement** (one-click ⚡ Apply on the findings board at the top of this PR): ``` "version": "2.0.0" ``` <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260902052245-1811b1:Devstral 2 123B#2 -->
@ -23114,7 +23136,7 @@
},
Member

package-lock.json:23136 · MEDIUM — Version mismatch in package-lock.json
The version listed here does not match the one in package.json, which can lead to confusion or installation errors when dependencies are installed.

Fix: Update the version in package-lock.json to match the version in package.json ("version": "2.0.0").

Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):

"version": "2.0.0"

panel tally 1/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:23136`** · MEDIUM — Version mismatch in package-lock.json The version listed here does not match the one in package.json, which can lead to confusion or installation errors when dependencies are installed. > **Fix:** Update the version in package-lock.json to match the version in package.json (`"version": "2.0.0"`). **Proposed replacement** (one-click ⚡ Apply on the findings board at the top of this PR): ``` "version": "2.0.0" ``` <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260902052245-1811b1:Devstral 2 123B#3 -->
renovate-bot force-pushed renovate/vue-monorepo from 88dbce9bbc
All checks were successful
scan / trivy-fs (push) Successful in 1m6s
baseline-security / baseline (push) Successful in 1m54s
scan / trivy-fs (pull_request) Successful in 41s
baseline-security / baseline (pull_request) Successful in 1m32s
ai-review / review (pull_request) Successful in 3m21s
to 08ac552661
Some checks failed
baseline-security / baseline (push) Failing after 1m15s
scan / trivy-fs (push) Failing after 53s
ai-review / review (pull_request) Successful in 59s
scan / trivy-fs (pull_request) Failing after 1m1s
baseline-security / baseline (pull_request) Failing after 1m16s
2026-09-09 05:21:07 +00:00
Compare
Member

AI review · advisory

Verdict: lockfile-only change — AI review skipped.

This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic.

⚑ panel: skipped (lockfile-only, 1 file)

Full transcript: http://host.containers.internal:3939/-/ai/v1/review/rv-20260909054529-426553

A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.

### AI review · advisory **Verdict: lockfile-only change** — AI review skipped. This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic. <sub>⚑ panel: skipped (lockfile-only, 1 file)</sub> <sub>Full transcript: http://host.containers.internal:3939/-/ai/v1/review/rv-20260909054529-426553</sub> <sub>A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.</sub>

🔧 Security-gate fix map

The gate failed on these dependency findings — fastest path to green for each:

finding package installed → fixed do this
GHSA-j95f-988m-3j2f (HIGH) @tiptap/core 3.28.0 → 3.30.5 no fix PR yet — npm update core --package-lock-only
CVE-2026-84375 (HIGH) js-yaml 4.3.1 → 4.3.2, 3.15.2 no fix PR yet — npm update js-yaml --package-lock-only
GHSA-rgj7-g3m4-5g8c (HIGH) sharp 0.35.3 → 0.35.4 no fix PR yet — npm update sharp --package-lock-only
CVE-2026-84370 (HIGH) svgo 4.0.2 → 2.8.4, 3.3.5, 4.1.0 no fix PR yet — npm update svgo --package-lock-only

⚠ main is itself red right now — this PR likely inherits the backlog rather than adding it. Fixing main (rows above) unblocks every open PR at once.

Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.

### 🔧 Security-gate fix map <!-- tti-fixmap:08ac552661e041e75bdfe255c37c05c596471bc2 --> The gate failed on these dependency findings — fastest path to green for each: | finding | package | installed → fixed | do this | |---|---|---|---| | GHSA-j95f-988m-3j2f (HIGH) | `@tiptap/core` | 3.28.0 → 3.30.5 | no fix PR yet — `npm update core --package-lock-only` | | CVE-2026-84375 (HIGH) | `js-yaml` | 4.3.1 → 4.3.2, 3.15.2 | no fix PR yet — `npm update js-yaml --package-lock-only` | | GHSA-rgj7-g3m4-5g8c (HIGH) | `sharp` | 0.35.3 → 0.35.4 | no fix PR yet — `npm update sharp --package-lock-only` | | CVE-2026-84370 (HIGH) | `svgo` | 4.0.2 → 2.8.4, 3.3.5, 4.1.0 | no fix PR yet — `npm update svgo --package-lock-only` | > ⚠ `main` is itself red right now — this PR likely **inherits** the backlog rather than adding it. Fixing `main` (rows above) unblocks every open PR at once. <sub>Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.</sub>
renovate-bot changed title from chore(deps): update dependency vue to v3.5.42 to chore(deps): update dependency vue to v3.5.43 2026-09-18 05:15:08 +00:00
renovate-bot force-pushed renovate/vue-monorepo from 08ac552661
Some checks failed
baseline-security / baseline (push) Failing after 1m15s
scan / trivy-fs (push) Failing after 53s
ai-review / review (pull_request) Successful in 59s
scan / trivy-fs (pull_request) Failing after 1m1s
baseline-security / baseline (pull_request) Failing after 1m16s
to a5c1273a77
Some checks failed
baseline-security / baseline (push) Failing after 1m37s
scan / trivy-fs (push) Failing after 56s
ai-review / review (pull_request) Successful in 55s
baseline-security / baseline (pull_request) Failing after 1m21s
scan / trivy-fs (pull_request) Failing after 1m2s
2026-09-18 05:15:09 +00:00
Compare
Member

AI review · advisory

Verdict: lockfile-only change — AI review skipped.

This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic.

⚑ panel: skipped (lockfile-only, 1 file)

Full transcript: http://host.containers.internal:3939/-/ai/v1/review/rv-20260918051911-c6f4b0

A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.

### AI review · advisory **Verdict: lockfile-only change** — AI review skipped. This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic. <sub>⚑ panel: skipped (lockfile-only, 1 file)</sub> <sub>Full transcript: http://host.containers.internal:3939/-/ai/v1/review/rv-20260918051911-c6f4b0</sub> <sub>A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.</sub>

🔧 Security-gate fix map

The gate failed on these dependency findings — fastest path to green for each:

finding package installed → fixed do this
CVE-2026-63671 (HIGH) @nuxtjs/mdc 0.21.1 → 0.22.1 merge #58 — fix(deps): update dependency @nuxtjs/mdc to ^0.22.0 [securit
GHSA-j95f-988m-3j2f (HIGH) @tiptap/core 3.28.0 → 3.30.5 no fix PR yet — npm update core --package-lock-only
CVE-2026-84375 (HIGH) js-yaml 4.3.1 → 4.3.2, 3.15.2 no fix PR yet — npm update js-yaml --package-lock-only
GHSA-rgj7-g3m4-5g8c (HIGH) sharp 0.35.3 → 0.35.4 no fix PR yet — npm update sharp --package-lock-only
CVE-2026-84370 (HIGH) svgo 4.0.2 → 2.8.4, 3.3.5, 4.1.0 no fix PR yet — npm update svgo --package-lock-only

⚠ main is itself red right now — this PR likely inherits the backlog rather than adding it. Fixing main (rows above) unblocks every open PR at once.

Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.

### 🔧 Security-gate fix map <!-- tti-fixmap:a5c1273a775517ee742c0226c6bda7a19d51fb3c --> The gate failed on these dependency findings — fastest path to green for each: | finding | package | installed → fixed | do this | |---|---|---|---| | CVE-2026-63671 (HIGH) | `@nuxtjs/mdc` | 0.21.1 → 0.22.1 | merge #58 — fix(deps): update dependency @nuxtjs/mdc to ^0.22.0 [securit | | GHSA-j95f-988m-3j2f (HIGH) | `@tiptap/core` | 3.28.0 → 3.30.5 | no fix PR yet — `npm update core --package-lock-only` | | CVE-2026-84375 (HIGH) | `js-yaml` | 4.3.1 → 4.3.2, 3.15.2 | no fix PR yet — `npm update js-yaml --package-lock-only` | | GHSA-rgj7-g3m4-5g8c (HIGH) | `sharp` | 0.35.3 → 0.35.4 | no fix PR yet — `npm update sharp --package-lock-only` | | CVE-2026-84370 (HIGH) | `svgo` | 4.0.2 → 2.8.4, 3.3.5, 4.1.0 | no fix PR yet — `npm update svgo --package-lock-only` | > ⚠ `main` is itself red right now — this PR likely **inherits** the backlog rather than adding it. Fixing `main` (rows above) unblocks every open PR at once. <sub>Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.</sub>
renovate-bot force-pushed renovate/vue-monorepo from a5c1273a77
Some checks failed
baseline-security / baseline (push) Failing after 1m37s
scan / trivy-fs (push) Failing after 56s
ai-review / review (pull_request) Successful in 55s
baseline-security / baseline (pull_request) Failing after 1m21s
scan / trivy-fs (pull_request) Failing after 1m2s
to 5baeaccb94
Some checks failed
baseline-security / baseline (push) Failing after 1m35s
scan / trivy-fs (push) Failing after 1m7s
ai-review / review (pull_request) Successful in 1m13s
scan / trivy-fs (pull_request) Failing after 1m2s
baseline-security / baseline (pull_request) Failing after 1m29s
2026-09-19 05:14:15 +00:00
Compare
Member

AI review · advisory

Verdict: lockfile-only change — AI review skipped.

This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic.

⚑ panel: skipped (lockfile-only, 1 file)

Full transcript: http://host.containers.internal:3939/-/ai/v1/review/rv-20260919052508-b74471

A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.

### AI review · advisory **Verdict: lockfile-only change** — AI review skipped. This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic. <sub>⚑ panel: skipped (lockfile-only, 1 file)</sub> <sub>Full transcript: http://host.containers.internal:3939/-/ai/v1/review/rv-20260919052508-b74471</sub> <sub>A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.</sub>

🔧 Security-gate fix map

The gate failed on these dependency findings — fastest path to green for each:

finding package installed → fixed do this
CVE-2026-63671 (HIGH) @nuxtjs/mdc 0.21.1 → 0.22.1 merge #58 — fix(deps): update dependency @nuxtjs/mdc to ^0.22.0 [securit
GHSA-j95f-988m-3j2f (HIGH) @tiptap/core 3.28.0 → 3.30.5 no fix PR yet — npm update core --package-lock-only
CVE-2026-84375 (HIGH) js-yaml 4.3.1 → 4.3.2, 3.15.2 no fix PR yet — npm update js-yaml --package-lock-only
GHSA-rgj7-g3m4-5g8c (HIGH) sharp 0.35.3 → 0.35.4 no fix PR yet — npm update sharp --package-lock-only
CVE-2026-84370 (HIGH) svgo 4.0.2 → 2.8.4, 3.3.5, 4.1.0 no fix PR yet — npm update svgo --package-lock-only

⚠ main is itself red right now — this PR likely inherits the backlog rather than adding it. Fixing main (rows above) unblocks every open PR at once.

Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.

### 🔧 Security-gate fix map <!-- tti-fixmap:5baeaccb94cec655aa694bbe36ed5e44e4ec138e --> The gate failed on these dependency findings — fastest path to green for each: | finding | package | installed → fixed | do this | |---|---|---|---| | CVE-2026-63671 (HIGH) | `@nuxtjs/mdc` | 0.21.1 → 0.22.1 | merge #58 — fix(deps): update dependency @nuxtjs/mdc to ^0.22.0 [securit | | GHSA-j95f-988m-3j2f (HIGH) | `@tiptap/core` | 3.28.0 → 3.30.5 | no fix PR yet — `npm update core --package-lock-only` | | CVE-2026-84375 (HIGH) | `js-yaml` | 4.3.1 → 4.3.2, 3.15.2 | no fix PR yet — `npm update js-yaml --package-lock-only` | | GHSA-rgj7-g3m4-5g8c (HIGH) | `sharp` | 0.35.3 → 0.35.4 | no fix PR yet — `npm update sharp --package-lock-only` | | CVE-2026-84370 (HIGH) | `svgo` | 4.0.2 → 2.8.4, 3.3.5, 4.1.0 | no fix PR yet — `npm update svgo --package-lock-only` | > ⚠ `main` is itself red right now — this PR likely **inherits** the backlog rather than adding it. Fixing `main` (rows above) unblocks every open PR at once. <sub>Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.</sub>
renovate-bot force-pushed renovate/vue-monorepo from 5baeaccb94
Some checks failed
baseline-security / baseline (push) Failing after 1m35s
scan / trivy-fs (push) Failing after 1m7s
ai-review / review (pull_request) Successful in 1m13s
scan / trivy-fs (pull_request) Failing after 1m2s
baseline-security / baseline (pull_request) Failing after 1m29s
to c4d9c1ddd1
Some checks failed
ai-review / review (pull_request) Successful in 1m10s
scan / trivy-fs (push) Failing after 1m13s
baseline-security / baseline (push) Failing after 1m36s
baseline-security / baseline (pull_request) Failing after 1m35s
scan / trivy-fs (pull_request) Failing after 59s
2026-09-27 23:29:16 +00:00
Compare
Member

AI review · advisory

Verdict: lockfile-only change — AI review skipped.

This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic.

⚑ panel: skipped (lockfile-only, 1 file)

A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.

### AI review · advisory **Verdict: lockfile-only change** — AI review skipped. This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic. <sub>⚑ panel: skipped (lockfile-only, 1 file)</sub> <sub>A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.</sub>

🔧 Security-gate fix map

The gate failed on these dependency findings — fastest path to green for each:

finding package installed → fixed do this
CVE-2026-63671 (HIGH) @nuxtjs/mdc 0.21.1 → 0.22.1 merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f
GHSA-j95f-988m-3j2f (HIGH) @tiptap/core 3.28.0 → 3.30.5 no fix PR yet — npm update core --package-lock-only
CVE-2026-84375 (HIGH) js-yaml 4.3.1 → 4.3.2, 3.15.2 no fix PR yet — npm update js-yaml --package-lock-only
GHSA-rgj7-g3m4-5g8c (HIGH) sharp 0.35.3 → 0.35.4 no fix PR yet — npm update sharp --package-lock-only
CVE-2026-84370 (HIGH) svgo 4.0.2 → 2.8.4, 3.3.5, 4.1.0 no fix PR yet — npm update svgo --package-lock-only

⚠ main is itself red right now — this PR likely inherits the backlog rather than adding it. Fixing main (rows above) unblocks every open PR at once.

Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.

### 🔧 Security-gate fix map <!-- tti-fixmap:c4d9c1ddd1a5858a14a6ef7a778004588e257db2 --> The gate failed on these dependency findings — fastest path to green for each: | finding | package | installed → fixed | do this | |---|---|---|---| | CVE-2026-63671 (HIGH) | `@nuxtjs/mdc` | 0.21.1 → 0.22.1 | merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f | | GHSA-j95f-988m-3j2f (HIGH) | `@tiptap/core` | 3.28.0 → 3.30.5 | no fix PR yet — `npm update core --package-lock-only` | | CVE-2026-84375 (HIGH) | `js-yaml` | 4.3.1 → 4.3.2, 3.15.2 | no fix PR yet — `npm update js-yaml --package-lock-only` | | GHSA-rgj7-g3m4-5g8c (HIGH) | `sharp` | 0.35.3 → 0.35.4 | no fix PR yet — `npm update sharp --package-lock-only` | | CVE-2026-84370 (HIGH) | `svgo` | 4.0.2 → 2.8.4, 3.3.5, 4.1.0 | no fix PR yet — `npm update svgo --package-lock-only` | > ⚠ `main` is itself red right now — this PR likely **inherits** the backlog rather than adding it. Fixing `main` (rows above) unblocks every open PR at once. <sub>Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.</sub>
Some checks failed
ai-review / review (pull_request) Successful in 1m10s
scan / trivy-fs (push) Failing after 1m13s
baseline-security / baseline (push) Failing after 1m36s
baseline-security / baseline (pull_request) Failing after 1m35s
Required
Details
scan / trivy-fs (pull_request) Failing after 59s
This pull request doesn't have enough approvals yet. 0 of 1 approvals granted.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/vue-monorepo:renovate/vue-monorepo
git switch renovate/vue-monorepo
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
tti/tti-ux!38
No description provided.