chore(deps): update vue-language-tools monorepo to v3.3.11 #39

Open
renovate-bot wants to merge 1 commit from renovate/vue-language-tools-monorepo into main
Member

This PR contains the following updates:

Package Change Age Confidence
@vue/language-core (source) 3.3.8 → 3.3.11 age confidence
vue-tsc (source) 3.3.8 → 3.3.11 age confidence

❗ Important

Release Notes retrieval for this PR were skipped because no github.com credentials were available.
If you are self-hosted, please see this instruction.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@vue/language-core](https://github.com/vuejs/language-tools) ([source](https://github.com/vuejs/language-tools/tree/HEAD/packages/language-core)) | [`3.3.8` → `3.3.11`](https://renovatebot.com/diffs/npm/@vue%2flanguage-core/3.3.8/3.3.11) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@vue%2flanguage-core/3.3.11?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@vue%2flanguage-core/3.3.8/3.3.11?slim=true) | | [vue-tsc](https://github.com/vuejs/language-tools) ([source](https://github.com/vuejs/language-tools/tree/HEAD/packages/tsc)) | [`3.3.8` → `3.3.11`](https://renovatebot.com/diffs/npm/vue-tsc/3.3.8/3.3.11) | ![age](https://developer.mend.io/api/mc/badges/age/npm/vue-tsc/3.3.11?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/vue-tsc/3.3.8/3.3.11?slim=true) | > ❗ **Important** > > Release Notes retrieval for this PR were skipped because no github.com credentials were available. > If you are self-hosted, please see [this instruction](https://github.com/renovatebot/renovate/blob/master/docs/usage/examples/self-hosting.md#githubcom-token-for-release-notes). --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzguMiIsInVwZGF0ZWRJblZlciI6IjQ0LjExNS41IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->
chore(deps): update vue-language-tools monorepo to v3.3.9
All checks were successful
scan / trivy-fs (pull_request) Successful in 47s
ai-review / review (pull_request) Successful in 2m48s
baseline-security / baseline (pull_request) Successful in 2m14s
scan / trivy-fs (push) Successful in 52s
baseline-security / baseline (push) Successful in 2m23s
1f60d5d563
ai-review-bot left a comment

AI review · advisory

Verdict: 2 things worth fixing (1 medium · 1 low).

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 2 distinct, 2 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.97): The lockfile updates correctly bump @vue/language-core and vue-tsc versions and add optional peer packages without breaking existing constraints.
  • Gemma 4 31B (0 findings, confidence 1.0): The diff contains only routine dependency updates in package-lock.json for vue-language-tools (v3.3.8 -> v3.3.9) and associated Nuxt CLI transitive dependencies; no logic or configuration changes
  • Devstral 2 123B (0 findings, confidence 1.0): The diff updates the vue-language-tools monorepo from v3.3.8 to v3.3.9, which is a minor version bump and appears to be a routine dependency update with no correctness, security, or best-practice issu
  • Laguna S 2.1 (2 findings, confidence 0.75): The dependency update itself is mechanically correct (@vue/language-core and vue-tsc bumped to 3.3.9 with consistent integrity hashes and a matching @vue/language-core pin in vue-tsc's deps), but the

Round 2 — cross-examination

  • Laguna S 2.1#1 vue-language-tools monorepo update pulled in new transitive deps without package · confirmed: Devstral 2 123B · refuted: GPT-OSS 120B, Gemma 4 31B
  • Laguna S 2.1#2 commander 14.0.3 requires Node >=20 but repo toolchain targets Node 24 only in d · confirmed: Gemma 4 31B, Devstral 2 123B · refuted: GPT-OSS 120B

Synthesis — Devstral 2 123B wrote the final review from 2 confirmed findings.

Transcript rv-20260814055556-6306ad — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260814055556-6306ad.

### AI review · advisory <!-- tti-rv:rv-20260814055556-6306ad: --> **Verdict: 2 things worth fixing** (1 medium · 1 low). <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 2 distinct, 2 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.97): The lockfile updates correctly bump @vue/language-core and vue-tsc versions and add optional peer packages without breaking existing constraints. - **Gemma 4 31B** (0 findings, confidence 1.0): The diff contains only routine dependency updates in `package-lock.json` for `vue-language-tools` (v3.3.8 -> v3.3.9) and associated Nuxt CLI transitive dependencies; no logic or configuration changes - **Devstral 2 123B** (0 findings, confidence 1.0): The diff updates the vue-language-tools monorepo from v3.3.8 to v3.3.9, which is a minor version bump and appears to be a routine dependency update with no correctness, security, or best-practice issu - **Laguna S 2.1** (2 findings, confidence 0.75): The dependency update itself is mechanically correct (@vue/language-core and vue-tsc bumped to 3.3.9 with consistent integrity hashes and a matching @vue/language-core pin in vue-tsc's deps), but the **Round 2 — cross-examination** - `Laguna S 2.1#1` vue-language-tools monorepo update pulled in new transitive deps without package · confirmed: Devstral 2 123B · refuted: GPT-OSS 120B, Gemma 4 31B - `Laguna S 2.1#2` commander 14.0.3 requires Node >=20 but repo toolchain targets Node 24 only in d · confirmed: Gemma 4 31B, Devstral 2 123B · refuted: GPT-OSS 120B **Synthesis** — Devstral 2 123B wrote the final review from 2 confirmed findings. <sub>Transcript `rv-20260814055556-6306ad` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260814055556-6306ad`.</sub>
@ -2629,12 +2629,34 @@
}
}
Member

package-lock.json:2630 · MEDIUM — New dependencies not listed in package.json
The update added three new dependencies (cac, commander, perfect-debounce) under @nuxt/cli in the lockfile, but these aren’t declared in package.json. This can cause npm ci to install different versions than expected, leading to build inconsistencies.

Fix: Run npm install --package-lock-only to regenerate the lockfile based on the current package.json, then commit both files together.

panel tally 2/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:2630`** · MEDIUM — New dependencies not listed in package.json The update added three new dependencies (`cac`, `commander`, `perfect-debounce`) under `@nuxt/cli` in the lockfile, but these aren’t declared in `package.json`. This can cause `npm ci` to install different versions than expected, leading to build inconsistencies. > **Fix:** Run `npm install --package-lock-only` to regenerate the lockfile based on the current `package.json`, then commit both files together. <sub>panel tally 2/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260814055556-6306ad:Laguna S 2.1#1 -->
@ -7783,9 +7805,9 @@
}
},
Member

package-lock.json:7806 · LOW — Dependency requires Node ≥20, but repo doesn’t enforce it
The added commander@14.0.3 requires Node ≥20, but the repo’s workflows and documentation don’t guarantee this. Contributors using older Node versions (e.g., 18) may face silent installation failures.

Fix: Add .node-version or engines.node in package.json to require ≥20, and update all workflows (e.g., baseline.yml) to pin Node ≥20.

panel tally 3/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:7806`** · LOW — Dependency requires Node ≥20, but repo doesn’t enforce it The added `commander@14.0.3` requires Node ≥20, but the repo’s workflows and documentation don’t guarantee this. Contributors using older Node versions (e.g., 18) may face silent installation failures. > **Fix:** Add `.node-version` or `engines.node` in `package.json` to require ≥20, and update all workflows (e.g., `baseline.yml`) to pin Node ≥20. <sub>panel tally 3/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260814055556-6306ad:Laguna S 2.1#2 -->
renovate-bot force-pushed renovate/vue-language-tools-monorepo from 1f60d5d563
All checks were successful
scan / trivy-fs (pull_request) Successful in 47s
ai-review / review (pull_request) Successful in 2m48s
baseline-security / baseline (pull_request) Successful in 2m14s
scan / trivy-fs (push) Successful in 52s
baseline-security / baseline (push) Successful in 2m23s
to c3732f5039
All checks were successful
scan / trivy-fs (push) Successful in 46s
baseline-security / baseline (push) Successful in 1m40s
scan / trivy-fs (pull_request) Successful in 45s
baseline-security / baseline (pull_request) Successful in 1m34s
ai-review / review (pull_request) Successful in 2m45s
2026-08-15 05:14:14 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: 2 things worth fixing (1 high · 1 medium).

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 2 confirmed, 0 refuted · web: 2 queries, 6 results · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings):
  • Gemma 4 31B (0 findings, confidence 1.0): The diff is a standard dependency update for the vue-language-tools monorepo (vue-tsc and @vue/language-core) and reflects typical package-lock.json drift; no correctness or security issues found.
  • Devstral 2 123B (1 finding, confidence 0.8): The update introduces a dependency with a higher Node.js engine requirement, which should be aligned across all dependencies to avoid potential runtime issues.
  • Laguna S 2.1 (2 findings, confidence 0.82): The PR updates @vue/language-core and vue-tsc to v3.3.9 (integrity hashes and dependency pinning present), which is consistent with the title. However it also inserts orphaned cac@6.7.14 and commander

Web grounding — web: 2 queries, 6 results: «https://www.npmjs.com/package/cac»; «https://www.npmjs.com/package/commander»

Round 2 — cross-examination

  • Laguna S 2.1#1 Inserted package-lock entries with no corresponding package.json / no source-of- · confirmed: Gemma 4 31B, Devstral 2 123B · refuted: —
  • Laguna S 2.1#2 Lockfile drift: nested dependency versions not justified by a visible manifest c · confirmed: Gemma 4 31B, Devstral 2 123B · refuted: —
  • Devstral 2 123B#1 Inconsistent Node.js engine requirement · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1

Synthesis — Devstral 2 123B wrote the final review from 2 confirmed findings (+1 unconfirmed).

Transcript rv-20260815054910-181242 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260815054910-181242.

### AI review · advisory <!-- tti-rv:rv-20260815054910-181242: --> **Verdict: 2 things worth fixing** (1 high · 1 medium). <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 2 confirmed, 0 refuted · web: 2 queries, 6 results · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings): - **Gemma 4 31B** (0 findings, confidence 1.0): The diff is a standard dependency update for the vue-language-tools monorepo (vue-tsc and @vue/language-core) and reflects typical package-lock.json drift; no correctness or security issues found. - **Devstral 2 123B** (1 finding, confidence 0.8): The update introduces a dependency with a higher Node.js engine requirement, which should be aligned across all dependencies to avoid potential runtime issues. - **Laguna S 2.1** (2 findings, confidence 0.82): The PR updates @vue/language-core and vue-tsc to v3.3.9 (integrity hashes and dependency pinning present), which is consistent with the title. However it also inserts orphaned cac@6.7.14 and commander **Web grounding** — web: 2 queries, 6 results: «https://www.npmjs.com/package/cac»; «https://www.npmjs.com/package/commander» **Round 2 — cross-examination** - `Laguna S 2.1#1` Inserted package-lock entries with no corresponding package.json / no source-of- · confirmed: Gemma 4 31B, Devstral 2 123B · refuted: — - `Laguna S 2.1#2` Lockfile drift: nested dependency versions not justified by a visible manifest c · confirmed: Gemma 4 31B, Devstral 2 123B · refuted: — - `Devstral 2 123B#1` Inconsistent Node.js engine requirement · confirmed: — · refuted: Gemma 4 31B, Laguna S 2.1 **Synthesis** — Devstral 2 123B wrote the final review from 2 confirmed findings (+1 unconfirmed). <sub>Transcript `rv-20260815054910-181242` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260815054910-181242`.</sub>
@ -2629,12 +2629,34 @@
}
Member

package-lock.json:2629 · MEDIUM — Lockfile entries not justified by a package.json change
Nested dependencies (cac@6.7.14, commander@14.0.3) appear under @nuxt/cli, but package.json does not declare @nuxt/cli. Without a matching manifest change, the lockfile cannot be reproduced, violating the project’s lockfile discipline rule.

Fix: If @nuxt/cli is needed, add it to package.json devDependencies with a version range, then regenerate the lockfile using npm install with the pinned npm major (24) and include the package.json change in this PR.

panel tally 3/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:2629`** · MEDIUM — Lockfile entries not justified by a package.json change Nested dependencies (`cac@6.7.14`, `commander@14.0.3`) appear under `@nuxt/cli`, but `package.json` does not declare `@nuxt/cli`. Without a matching manifest change, the lockfile cannot be reproduced, violating the project’s lockfile discipline rule. > **Fix:** If `@nuxt/cli` is needed, add it to `package.json` devDependencies with a version range, then regenerate the lockfile using `npm install` with the pinned npm major (24) and include the `package.json` change in this PR. <sub>panel tally 3/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260815054910-181242:Laguna S 2.1#2 -->
@ -2629,12 +2629,34 @@
}
}
},
Member

MEDIUM — Inconsistent Node.js engine requirement

The added 'commander' package (v14.0.3) requires Node.js >=20, while the existing 'cac' package (v6.7.14) only requires Node.js >=8. This inconsistency could lead to runtime errors if the environment does not meet the higher requirement.

Fix: Align the Node.js engine requirement for 'cac' with the higher requirement of 'commander' by updating 'cac' to a version that requires Node.js >=20.

Proposed replacement (one-click ⚡ Apply on the findings board at the top of this PR):

"engines": {
        "node": ">=20"
      }

panel tally 1/4 · reply here or use the finding board to agree/disagree

**MEDIUM** — Inconsistent Node.js engine requirement The added 'commander' package (v14.0.3) requires Node.js >=20, while the existing 'cac' package (v6.7.14) only requires Node.js >=8. This inconsistency could lead to runtime errors if the environment does not meet the higher requirement. > **Fix:** Align the Node.js engine requirement for 'cac' with the higher requirement of 'commander' by updating 'cac' to a version that requires Node.js >=20. **Proposed replacement** (one-click ⚡ Apply on the findings board at the top of this PR): ``` "engines": { "node": ">=20" } ``` <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260815054910-181242:Devstral 2 123B#1 -->
@ -2629,12 +2629,34 @@
}
}
},
"node_modules/@nuxt/cli/node_modules/cac": {
Member

package-lock.json:2632 · HIGH — Orphaned lockfile entries without matching package.json dependency
The diff adds cac@6.7.14 and commander@14.0.3 under @nuxt/cli, but package.json does not list @nuxt/cli as a dependency. This violates lockfile discipline and risks non-reproducible installs because npm ci will not generate these entries.

Fix: Remove the orphaned entries unless @nuxt/cli is intentionally added to package.json devDependencies; if it is, regenerate the lockfile with npm install (npm 24) and include the package.json change in this PR.

panel tally 3/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:2632`** · HIGH — Orphaned lockfile entries without matching package.json dependency The diff adds `cac@6.7.14` and `commander@14.0.3` under `@nuxt/cli`, but `package.json` does not list `@nuxt/cli` as a dependency. This violates lockfile discipline and risks non-reproducible installs because `npm ci` will not generate these entries. > **Fix:** Remove the orphaned entries unless `@nuxt/cli` is intentionally added to `package.json` devDependencies; if it is, regenerate the lockfile with `npm install` (npm 24) and include the `package.json` change in this PR. <sub>panel tally 3/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260815054910-181242:Laguna S 2.1#1 -->
renovate-bot changed title from chore(deps): update vue-language-tools monorepo to v3.3.9 to chore(deps): update vue-language-tools monorepo to v3.3.10 2026-08-16 05:17:14 +00:00
renovate-bot force-pushed renovate/vue-language-tools-monorepo from c3732f5039
All checks were successful
scan / trivy-fs (push) Successful in 46s
baseline-security / baseline (push) Successful in 1m40s
scan / trivy-fs (pull_request) Successful in 45s
baseline-security / baseline (pull_request) Successful in 1m34s
ai-review / review (pull_request) Successful in 2m45s
to 41e3046ad4
All checks were successful
scan / trivy-fs (push) Successful in 1m2s
baseline-security / baseline (push) Successful in 2m22s
scan / trivy-fs (pull_request) Successful in 1m4s
ai-review / review (pull_request) Successful in 2m11s
baseline-security / baseline (pull_request) Successful in 3m8s
2026-08-16 05:17:16 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: looks good — all four reviewers found nothing that needs fixing.

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 0 distinct, 0 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.97): No issues found in the changed lines of the diff.
  • Gemma 4 31B (0 findings, confidence 1.0): The diff contains only dependency updates in package-lock.json for @vue/language-core and vue-tsc, along with some transitive dependency additions, all of which appear correct and consistent with the
  • Devstral 2 123B (0 findings, confidence 1.0): The pull request updates vue-language-tools monorepo dependencies from v3.3.8 to v3.3.10, which appears to be a routine maintenance update with no correctness, security, or best-practice issues in the
  • Laguna S 2.1 (0 findings, confidence 0.95): The diff is a chore(deps) update of the vue-language-tools monorepo from v3.3.8 to v3.3.10, bumping @vue/language-core and vue-tsc together with matching integrity hashes in package-lock.json; the vue

Synthesis — Devstral 2 123B wrote the final review from 0 confirmed findings.

Transcript rv-20260816052648-a174e6 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260816052648-a174e6.

### AI review · advisory <!-- tti-rv:rv-20260816052648-a174e6: --> **Verdict: looks good** — all four reviewers found nothing that needs fixing. <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 0 distinct, 0 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.97): No issues found in the changed lines of the diff. - **Gemma 4 31B** (0 findings, confidence 1.0): The diff contains only dependency updates in package-lock.json for @vue/language-core and vue-tsc, along with some transitive dependency additions, all of which appear correct and consistent with the - **Devstral 2 123B** (0 findings, confidence 1.0): The pull request updates vue-language-tools monorepo dependencies from v3.3.8 to v3.3.10, which appears to be a routine maintenance update with no correctness, security, or best-practice issues in the - **Laguna S 2.1** (0 findings, confidence 0.95): The diff is a chore(deps) update of the vue-language-tools monorepo from v3.3.8 to v3.3.10, bumping @vue/language-core and vue-tsc together with matching integrity hashes in package-lock.json; the vue **Synthesis** — Devstral 2 123B wrote the final review from 0 confirmed findings. <sub>Transcript `rv-20260816052648-a174e6` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260816052648-a174e6`.</sub>
renovate-bot force-pushed renovate/vue-language-tools-monorepo from 41e3046ad4
All checks were successful
scan / trivy-fs (push) Successful in 1m2s
baseline-security / baseline (push) Successful in 2m22s
scan / trivy-fs (pull_request) Successful in 1m4s
ai-review / review (pull_request) Successful in 2m11s
baseline-security / baseline (pull_request) Successful in 3m8s
to 6c8e3198eb
All checks were successful
baseline-security / baseline (push) Successful in 1m45s
scan / trivy-fs (push) Successful in 54s
scan / trivy-fs (pull_request) Successful in 55s
baseline-security / baseline (pull_request) Successful in 1m52s
ai-review / review (pull_request) Successful in 2m51s
2026-08-20 05:14:40 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: 1 thing worth fixing (1 medium).

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 7 distinct (from 8 reviewer findings), 1 confirmed, 6 refuted · web: not used · context: 1 files · 89 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 89 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.97): The lockfile changes correctly align the package name, version, and license with the package.json and update dependency versions without apparent issues.
  • Gemma 4 31B (1 finding, confidence 1.0): The PR primarily updates vue-language-tools dependencies as stated, but it also introduces a major version bump (1.9.0 -> 2.0.0) and a package rename (@tti scope) in the lockfile that are not mentione
  • Devstral 2 123B (6 findings, confidence 0.95): The package-lock.json file has several inconsistencies with package.json and missing fields that need to be addressed.
  • Laguna S 2.1 (1 finding, confidence 0.92): The 3.3.8→3.3.10 bump for @vue/language-core + vue-tsc is correct and checksums match the diff. However the package-lock.json root block (name/version/license) was left stale at tti-ux/1.9.0/omitt

Grouping — 8 reviewer findings describe 7 distinct defects; reviewers who found the same defect independently count as support.

Round 2 — cross-examination

  • Devstral 2 123B#2 Version mismatch between package.json and package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#1 Package name mismatch between package.json and package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#4 Missing license field in a dependency entry · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#3 Missing license field in a dependency entry · also raised by: Laguna S 2.1 · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B
  • Gemma 4 31B#1 Unexpected package name and version change · confirmed: Devstral 2 123B · refuted: Laguna S 2.1
  • Devstral 2 123B#5 Version mismatch in @vue/language-core dependency · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#6 Version mismatch in vue-tsc dependency · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1

Raised but refuted (left out of the review above)

  • Devstral 2 123B#2 Version mismatch between package.json and package-lock.json — The lockfile version was updated to "2.0.0", which now matches the version in package.json. The evidence cited is the old version line, not the curren
  • Devstral 2 123B#1 Package name mismatch between package.json and package-lock.json — The package name in the lockfile was changed to "@tti/tti-ux", matching the name in package.json. The cited evidence shows the previous name only.
  • Devstral 2 123B#4 Missing license field in a dependency entry — A "license": "MIT" field has been added to the "commander" entry in the lockfile, resolving the missing license issue.
  • Devstral 2 123B#3 Missing license field in a dependency entry — A "license": "MIT" field has been added to the "cac" entry in the lockfile, addressing the previously missing license.

Synthesis — Devstral 2 123B wrote the final review from 1 confirmed finding.

Transcript rv-20260820053634-ea2348 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260820053634-ea2348.

### AI review · advisory <!-- tti-rv:rv-20260820053634-ea2348: --> **Verdict: 1 thing worth fixing** (1 medium). <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 7 distinct (from 8 reviewer findings), 1 confirmed, 6 refuted · web: not used · context: 1 files · 89 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 89 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.97): The lockfile changes correctly align the package name, version, and license with the package.json and update dependency versions without apparent issues. - **Gemma 4 31B** (1 finding, confidence 1.0): The PR primarily updates vue-language-tools dependencies as stated, but it also introduces a major version bump (1.9.0 -> 2.0.0) and a package rename (@tti scope) in the lockfile that are not mentione - **Devstral 2 123B** (6 findings, confidence 0.95): The package-lock.json file has several inconsistencies with package.json and missing fields that need to be addressed. - **Laguna S 2.1** (1 finding, confidence 0.92): The 3.3.8→3.3.10 bump for @vue/language-core + vue-tsc is correct and checksums match the diff. However the package-lock.json root block (name/version/license) was left stale at `tti-ux`/`1.9.0`/omitt **Grouping** — 8 reviewer findings describe 7 distinct defects; reviewers who found the same defect independently count as support. **Round 2 — cross-examination** - `Devstral 2 123B#2` Version mismatch between package.json and package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#1` Package name mismatch between package.json and package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#4` Missing license field in a dependency entry · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#3` Missing license field in a dependency entry · also raised by: Laguna S 2.1 · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B - `Gemma 4 31B#1` Unexpected package name and version change · confirmed: Devstral 2 123B · refuted: Laguna S 2.1 - `Devstral 2 123B#5` Version mismatch in @vue/language-core dependency · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#6` Version mismatch in vue-tsc dependency · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 **Raised but refuted** (left out of the review above) - `Devstral 2 123B#2` Version mismatch between package.json and package-lock.json — The lockfile version was updated to "2.0.0", which now matches the version in package.json. The evidence cited is the old version line, not the curren - `Devstral 2 123B#1` Package name mismatch between package.json and package-lock.json — The package name in the lockfile was changed to "@tti/tti-ux", matching the name in package.json. The cited evidence shows the previous name only. - `Devstral 2 123B#4` Missing license field in a dependency entry — A "license": "MIT" field has been added to the "commander" entry in the lockfile, resolving the missing license issue. - `Devstral 2 123B#3` Missing license field in a dependency entry — A "license": "MIT" field has been added to the "cac" entry in the lockfile, addressing the previously missing license. **Synthesis** — Devstral 2 123B wrote the final review from 1 confirmed finding. <sub>Transcript `rv-20260820053634-ea2348` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260820053634-ea2348`.</sub>
@ -1,13 +1,14 @@
{
"name": "tti-ux",
"version": "1.9.0",
"name": "@tti/tti-ux",
Member

package-lock.json:2 · MEDIUM — Unexpected package name and version change
The root package name changed from 'tti-ux' to '@tti/tti-ux' and the version jumped from '1.9.0' to '2.0.0', which looks like a major version bump and a scope change that isn’t mentioned in the PR title.

Fix: Update the PR title to reflect the major version bump to v2.0.0 and the transition to the @tti scope, or revert these changes if they were accidental.

panel tally 2/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:2`** · MEDIUM — Unexpected package name and version change The root package name changed from 'tti-ux' to '@tti/tti-ux' and the version jumped from '1.9.0' to '2.0.0', which looks like a major version bump and a scope change that isn’t mentioned in the PR title. > **Fix:** Update the PR title to reflect the major version bump to v2.0.0 and the transition to the @tti scope, or revert these changes if they were accidental. <sub>panel tally 2/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260820053634-ea2348:Gemma 4 31B#1 -->
renovate-bot force-pushed renovate/vue-language-tools-monorepo from 6c8e3198eb
All checks were successful
baseline-security / baseline (push) Successful in 1m45s
scan / trivy-fs (push) Successful in 54s
scan / trivy-fs (pull_request) Successful in 55s
baseline-security / baseline (pull_request) Successful in 1m52s
ai-review / review (pull_request) Successful in 2m51s
to a660994b8b
All checks were successful
scan / trivy-fs (push) Successful in 1m2s
baseline-security / baseline (push) Successful in 1m58s
ai-review / review (pull_request) Successful in 2m27s
scan / trivy-fs (pull_request) Successful in 58s
baseline-security / baseline (pull_request) Successful in 1m54s
2026-08-21 05:20:27 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: 2 things worth fixing (2 medium).

Findings that didn't map to a diff line:

package-lock.json:2630 · MEDIUM — Added commander with engine >=20 may break consumers on older Node versions
The new "commander" package is listed as an optional peer with "engines": { "node": ">=20" }, which can cause install failures for consumers still on Node 18 or earlier.

Fix: Replace commander with a version that supports Node >=18 (e.g., 13.x) or remove it if not required.

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 2 confirmed, 1 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (1 finding, confidence 0.92): The lockfile updates mainly bump versions and add optional peer packages; the only concern is the new commander package requiring Node >=20, which may affect consumers on older Node versions.
  • Gemma 4 31B (0 findings, confidence 1.0): The diff represents a standard dependency update for the Vue language tools monorepo, and the changes to package-lock.json are consistent with the requested version bump to v3.3.10.
  • Devstral 2 123B (2 findings, confidence 0.8): The changes introduce new dependencies that may cause compatibility issues with consuming projects.
  • Laguna S 2.1 (0 findings, confidence 0.97): The diff is a mechanical, correct update of the vue-language-tools monorepo to v3.3.10 in package-lock.json: @vue/language-core 3.3.8 → 3.3.10, vue-tsc 3.3.8 → 3.3.10, the vue-tsc dependency on @vue/l

Round 2 — cross-examination

  • GPT-OSS 120B#1 Added commander with engine >=20 may break consumers on older Node versions · confirmed: Devstral 2 123B · refuted: Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#2 New dependency 'commander' introduced with high Node.js version requirement · confirmed: GPT-OSS 120B · refuted: Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#1 New dependency 'cac' introduced without peer dependency constraint · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1

Raised but refuted (left out of the review above)

  • Devstral 2 123B#1 New dependency 'cac' introduced without peer dependency constraint — The diff only shows a lock‑file entry for cac marked as a peer dependency, but it does not reveal the version constraint (if any) declared in the de

Synthesis — Devstral 2 123B wrote the final review from 2 confirmed findings.

Transcript rv-20260821054747-43428e — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260821054747-43428e.

### AI review · advisory <!-- tti-rv:rv-20260821054747-43428e: --> **Verdict: 2 things worth fixing** (2 medium). Findings that didn't map to a diff line: **`package-lock.json:2630`** · MEDIUM — Added commander with engine >=20 may break consumers on older Node versions The new "commander" package is listed as an optional peer with "engines": { "node": ">=20" }, which can cause install failures for consumers still on Node 18 or earlier. > **Fix:** Replace commander with a version that supports Node >=18 (e.g., 13.x) or remove it if not required. <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 2 confirmed, 1 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (1 finding, confidence 0.92): The lockfile updates mainly bump versions and add optional peer packages; the only concern is the new commander package requiring Node >=20, which may affect consumers on older Node versions. - **Gemma 4 31B** (0 findings, confidence 1.0): The diff represents a standard dependency update for the Vue language tools monorepo, and the changes to package-lock.json are consistent with the requested version bump to v3.3.10. - **Devstral 2 123B** (2 findings, confidence 0.8): The changes introduce new dependencies that may cause compatibility issues with consuming projects. - **Laguna S 2.1** (0 findings, confidence 0.97): The diff is a mechanical, correct update of the vue-language-tools monorepo to v3.3.10 in package-lock.json: @vue/language-core 3.3.8 → 3.3.10, vue-tsc 3.3.8 → 3.3.10, the vue-tsc dependency on @vue/l **Round 2 — cross-examination** - `GPT-OSS 120B#1` Added commander with engine >=20 may break consumers on older Node versions · confirmed: Devstral 2 123B · refuted: Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#2` New dependency 'commander' introduced with high Node.js version requirement · confirmed: GPT-OSS 120B · refuted: Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#1` New dependency 'cac' introduced without peer dependency constraint · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 **Raised but refuted** (left out of the review above) - `Devstral 2 123B#1` New dependency 'cac' introduced without peer dependency constraint — The diff only shows a lock‑file entry for `cac` marked as a peer dependency, but it does not reveal the version constraint (if any) declared in the de **Synthesis** — Devstral 2 123B wrote the final review from 2 confirmed findings. <sub>Transcript `rv-20260821054747-43428e` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260821054747-43428e`.</sub>
@ -2647,4 +2658,4 @@
"version": "0.2.2",
"resolved": "https://registry.npmjs.org/citty/-/citty-0.2.2.tgz",
"integrity": "sha512-+6vJA3L98yv+IdfKGZHBNiGW5KHn22e/JwID0Strsz8h4S/csAu/OuICwxrg44k5MRiZHWIo8XXuJgQTriRP4w==",
"license": "MIT"
Member

MEDIUM — New dependency 'commander' introduced with high Node.js version requirement

The new dependency 'commander' requires Node.js version >=20, which may not be compatible with all consuming projects or build environments.

Fix: Ensure all consuming projects and build environments are compatible with Node.js version >=20.

panel tally 2/4 · reply here or use the finding board to agree/disagree

**MEDIUM** — New dependency 'commander' introduced with high Node.js version requirement The new dependency 'commander' requires Node.js version >=20, which may not be compatible with all consuming projects or build environments. > **Fix:** Ensure all consuming projects and build environments are compatible with Node.js version >=20. <sub>panel tally 2/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260821054747-43428e:Devstral 2 123B#2 -->
renovate-bot changed title from chore(deps): update vue-language-tools monorepo to v3.3.10 to chore(deps): update vue-language-tools monorepo to v3.3.11 2026-08-22 05:10:54 +00:00
renovate-bot force-pushed renovate/vue-language-tools-monorepo from a660994b8b
All checks were successful
scan / trivy-fs (push) Successful in 1m2s
baseline-security / baseline (push) Successful in 1m58s
ai-review / review (pull_request) Successful in 2m27s
scan / trivy-fs (pull_request) Successful in 58s
baseline-security / baseline (pull_request) Successful in 1m54s
to b1b5a236ac
All checks were successful
scan / trivy-fs (push) Successful in 48s
baseline-security / baseline (push) Successful in 1m52s
scan / trivy-fs (pull_request) Successful in 50s
baseline-security / baseline (pull_request) Successful in 1m53s
ai-review / review (pull_request) Successful in 2m14s
2026-08-22 05:10:56 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: 2 things worth fixing (1 medium · 1 low).

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 2 distinct, 2 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.97): No issues detected in the changed lines; version bumps and optional peer entries are consistent with the repository's dependency specifications.
  • Gemma 4 31B (0 findings, confidence 1.0): The diff is a routine dependency update for @vue/language-core and vue-tsc, and a standard lockfile update including optional peer dependencies; no bugs or security issues were identified.
  • Devstral 2 123B (2 findings, confidence 0.85): The pull request updates vue-language-tools monorepo to v3.3.11, which appears to be a routine dependency update. However, there are minor issues with inconsistent Node.js engine requirements and redu
  • Laguna S 2.1 (0 findings, confidence 0.95): The PR is a chore dependency update to the vue-language-tools monorepo (vue-tsc / @vue/language-core from 3.3.8 to 3.3.11) and the accompanying package-lock.json changes look consistent and lock-file-

Round 2 — cross-examination

  • Devstral 2 123B#1 Inconsistent Node.js engine requirement · confirmed: GPT-OSS 120B · refuted: Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#2 Redundant optional and peer dependency flags · confirmed: GPT-OSS 120B · refuted: Gemma 4 31B, Laguna S 2.1

Synthesis — Devstral 2 123B wrote the final review from 2 confirmed findings.

Transcript rv-20260822052112-1a7082 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260822052112-1a7082.

### AI review · advisory <!-- tti-rv:rv-20260822052112-1a7082: --> **Verdict: 2 things worth fixing** (1 medium · 1 low). <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 2 distinct, 2 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.97): No issues detected in the changed lines; version bumps and optional peer entries are consistent with the repository's dependency specifications. - **Gemma 4 31B** (0 findings, confidence 1.0): The diff is a routine dependency update for @vue/language-core and vue-tsc, and a standard lockfile update including optional peer dependencies; no bugs or security issues were identified. - **Devstral 2 123B** (2 findings, confidence 0.85): The pull request updates vue-language-tools monorepo to v3.3.11, which appears to be a routine dependency update. However, there are minor issues with inconsistent Node.js engine requirements and redu - **Laguna S 2.1** (0 findings, confidence 0.95): The PR is a chore dependency update to the vue-language-tools monorepo (vue-tsc / @vue/language-core from 3.3.8 to 3.3.11) and the accompanying package-lock.json changes look consistent and lock-file- **Round 2 — cross-examination** - `Devstral 2 123B#1` Inconsistent Node.js engine requirement · confirmed: GPT-OSS 120B · refuted: Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#2` Redundant optional and peer dependency flags · confirmed: GPT-OSS 120B · refuted: Gemma 4 31B, Laguna S 2.1 **Synthesis** — Devstral 2 123B wrote the final review from 2 confirmed findings. <sub>Transcript `rv-20260822052112-1a7082` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260822052112-1a7082`.</sub>
@ -2643,12 +2643,34 @@
}
}
Member

package-lock.json:2644 · LOW — Redundant optional and peer dependency flags
The 'cac' package is marked as both 'optional' and 'peer', which is redundant and could cause confusion. Typically, a package should be either optional or a peer dependency, not both.

Fix: Review the dependency flags and ensure 'cac' is marked as either 'optional' or 'peer', but not both.

panel tally 2/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:2644`** · LOW — Redundant optional and peer dependency flags The 'cac' package is marked as both 'optional' and 'peer', which is redundant and could cause confusion. Typically, a package should be either optional or a peer dependency, not both. > **Fix:** Review the dependency flags and ensure 'cac' is marked as either 'optional' or 'peer', but not both. <sub>panel tally 2/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260822052112-1a7082:Devstral 2 123B#2 -->
@ -2646,0 +2651,4 @@
"optional": true,
"peer": true,
"engines": {
"node": ">=8"
Member

package-lock.json:2654 · MEDIUM — Inconsistent Node.js engine requirement
The added 'commander' package requires Node.js >=20, while the existing '@nuxt/cli' package allows Node.js >=8. This mismatch could cause runtime errors if the project is run with Node.js versions between 8 and 20.

Fix: Update the project's Node.js version to >=20 or replace the 'commander' package with a version that supports Node.js >=8.

panel tally 2/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:2654`** · MEDIUM — Inconsistent Node.js engine requirement The added 'commander' package requires Node.js >=20, while the existing '@nuxt/cli' package allows Node.js >=8. This mismatch could cause runtime errors if the project is run with Node.js versions between 8 and 20. > **Fix:** Update the project's Node.js version to >=20 or replace the 'commander' package with a version that supports Node.js >=8. <sub>panel tally 2/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260822052112-1a7082:Devstral 2 123B#1 -->
renovate-bot force-pushed renovate/vue-language-tools-monorepo from b1b5a236ac
All checks were successful
scan / trivy-fs (push) Successful in 48s
baseline-security / baseline (push) Successful in 1m52s
scan / trivy-fs (pull_request) Successful in 50s
baseline-security / baseline (pull_request) Successful in 1m53s
ai-review / review (pull_request) Successful in 2m14s
to fea97a48db
All checks were successful
scan / trivy-fs (push) Successful in 1m5s
baseline-security / baseline (push) Successful in 2m1s
scan / trivy-fs (pull_request) Successful in 44s
baseline-security / baseline (pull_request) Successful in 1m32s
ai-review / review (pull_request) Successful in 2m36s
2026-08-30 05:18:16 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: nothing confirmed — a couple of single-reviewer observations below.

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 4 distinct, 0 confirmed, 3 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.97): The diff only updates lockfile versions and adds optional peer entries, which appear correct and consistent with the package.json constraints.
  • Gemma 4 31B (0 findings, confidence 1.0): The diff is a standard dependency update for vue-language-tools and its associated lockfile entries, with no correctness, security, or best-practice issues found.
  • Devstral 2 123B (4 findings, confidence 0.85): The pull request updates vue-language-tools monorepo to v3.3.11, but introduces new transitive dependencies and version inconsistencies that should be addressed.
  • Laguna S 2.1 (0 findings, confidence 0.95): The diff is a routine dependency version bump of the vue-language-tools monorepo from 3.3.8 to 3.3.11 in package-lock.json — @vue/language-core and vue-tsc, plus their @vue/language-core dependency pi

Round 2 — cross-examination

  • Devstral 2 123B#2 New dependency 'commander' added without version pinning in package.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#1 New dependency 'cac' added without version pinning in package.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#4 Version update for 'vue-tsc' not reflected in package.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B
  • Devstral 2 123B#3 Version update for '@vue/language-core' not reflected in package.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1

Raised but refuted (left out of the review above)

  • Devstral 2 123B#2 New dependency 'commander' added without version pinning in package.json — The diff only shows commander added under node_modules/@nuxt/cli/... as an optional peer dependency. It is a transitive dependency, not a direct o
  • Devstral 2 123B#1 New dependency 'cac' added without version pinning in package.json — Similarly, cac appears as an optional peer dependency of @nuxt/cli in the lockfile. It is not a direct dependency, so it is not required to be lis
  • Devstral 2 123B#3 Version update for '@vue/language-core' not reflected in package.json — package.json lists @vue/language-core with version ^3.3.3, allowing 3.3.11 as shown in the lockfile. The claim of a version mismatch is unfounded

Synthesis — Devstral 2 123B wrote the final review from 0 confirmed findings (+1 unconfirmed).

Transcript rv-20260830053739-d92b98 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260830053739-d92b98.

### AI review · advisory <!-- tti-rv:rv-20260830053739-d92b98: --> **Verdict: nothing confirmed** — a couple of single-reviewer observations below. <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 4 distinct, 0 confirmed, 3 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.97): The diff only updates lockfile versions and adds optional peer entries, which appear correct and consistent with the package.json constraints. - **Gemma 4 31B** (0 findings, confidence 1.0): The diff is a standard dependency update for vue-language-tools and its associated lockfile entries, with no correctness, security, or best-practice issues found. - **Devstral 2 123B** (4 findings, confidence 0.85): The pull request updates vue-language-tools monorepo to v3.3.11, but introduces new transitive dependencies and version inconsistencies that should be addressed. - **Laguna S 2.1** (0 findings, confidence 0.95): The diff is a routine dependency version bump of the vue-language-tools monorepo from 3.3.8 to 3.3.11 in package-lock.json — @vue/language-core and vue-tsc, plus their @vue/language-core dependency pi **Round 2 — cross-examination** - `Devstral 2 123B#2` New dependency 'commander' added without version pinning in package.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#1` New dependency 'cac' added without version pinning in package.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#4` Version update for 'vue-tsc' not reflected in package.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B - `Devstral 2 123B#3` Version update for '@vue/language-core' not reflected in package.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 **Raised but refuted** (left out of the review above) - `Devstral 2 123B#2` New dependency 'commander' added without version pinning in package.json — The diff only shows `commander` added under `node_modules/@nuxt/cli/...` as an optional peer dependency. It is a transitive dependency, not a direct o - `Devstral 2 123B#1` New dependency 'cac' added without version pinning in package.json — Similarly, `cac` appears as an optional peer dependency of `@nuxt/cli` in the lockfile. It is not a direct dependency, so it is not required to be lis - `Devstral 2 123B#3` Version update for '@vue/language-core' not reflected in package.json — package.json lists `@vue/language-core` with version `^3.3.3`, allowing 3.3.11 as shown in the lockfile. The claim of a version mismatch is unfounded **Synthesis** — Devstral 2 123B wrote the final review from 0 confirmed findings (+1 unconfirmed). <sub>Transcript `rv-20260830053739-d92b98` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260830053739-d92b98`.</sub>
@ -22631,3 +22653,1 @@
"version": "3.3.8",
"resolved": "https://registry.npmjs.org/vue-tsc/-/vue-tsc-3.3.8.tgz",
"integrity": "sha512-xXmYlVQpcwJDWyGlqbHrGVOl1h3UOsASymRibrHc+iy9j/UNnOrOn4u+fntHz4D6Cs74RtapeqVV6CzJeg+UlA==",
"version": "3.3.11",
Member

package-lock.json:22653 · LOW — Version mismatch for 'vue-tsc' between lockfile and manifest
The package-lock.json pins 'vue-tsc' at 3.3.11, but package.json still allows any 3.3.x (^3.3.3), which can cause confusing or broken installs if the wrong sub-version is pulled.

Fix: Update the version range in package.json to exactly 3.3.11 to match the resolved version in the lockfile.

panel tally 1/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:22653`** · LOW — Version mismatch for 'vue-tsc' between lockfile and manifest The package-lock.json pins 'vue-tsc' at 3.3.11, but package.json still allows any 3.3.x (^3.3.3), which can cause confusing or broken installs if the wrong sub-version is pulled. > **Fix:** Update the version range in package.json to exactly `3.3.11` to match the resolved version in the lockfile. <sub>panel tally 1/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260830053739-d92b98:Devstral 2 123B#4 -->
renovate-bot force-pushed renovate/vue-language-tools-monorepo from fea97a48db
All checks were successful
scan / trivy-fs (push) Successful in 1m5s
baseline-security / baseline (push) Successful in 2m1s
scan / trivy-fs (pull_request) Successful in 44s
baseline-security / baseline (pull_request) Successful in 1m32s
ai-review / review (pull_request) Successful in 2m36s
to e817bf66e5
All checks were successful
scan / trivy-fs (push) Successful in 47s
baseline-security / baseline (push) Successful in 1m58s
ai-review / review (pull_request) Successful in 1m50s
scan / trivy-fs (pull_request) Successful in 52s
baseline-security / baseline (pull_request) Successful in 1m58s
2026-08-31 05:19:09 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: looks good — all four reviewers found nothing that needs fixing.

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 0 distinct, 0 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.97): The lockfile changes only update dependency versions and add optional peer entries; they appear consistent with the package.json constraints and do not introduce obvious bugs or security regressions.
  • Gemma 4 31B (0 findings, confidence 1.0): The diff represents a standard dependency update for the vue-language-tools monorepo and its associated lockfile entries; no correctness, security, or best-practice issues were found.
  • Devstral 2 123B (0 findings, confidence 1.0): The pull request diff appears to be a routine dependency update with no correctness, security, or best-practice issues in the changed lines.
  • Laguna S 2.1 (0 findings, confidence 1.0): The diff is a routine automated dependency update for the vue-language-tools monorepo (vue-tsc and @vue/language-core bumped from 3.3.8 to 3.3.11, with nested @nuxt/cli transitive deps cac/commander a

Synthesis — Devstral 2 123B wrote the final review from 0 confirmed findings.

Transcript rv-20260831053834-9e8dd3 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260831053834-9e8dd3.

### AI review · advisory <!-- tti-rv:rv-20260831053834-9e8dd3: --> **Verdict: looks good** — all four reviewers found nothing that needs fixing. <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 0 distinct, 0 confirmed, 0 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.97): The lockfile changes only update dependency versions and add optional peer entries; they appear consistent with the package.json constraints and do not introduce obvious bugs or security regressions. - **Gemma 4 31B** (0 findings, confidence 1.0): The diff represents a standard dependency update for the vue-language-tools monorepo and its associated lockfile entries; no correctness, security, or best-practice issues were found. - **Devstral 2 123B** (0 findings, confidence 1.0): The pull request diff appears to be a routine dependency update with no correctness, security, or best-practice issues in the changed lines. - **Laguna S 2.1** (0 findings, confidence 1.0): The diff is a routine automated dependency update for the vue-language-tools monorepo (vue-tsc and @vue/language-core bumped from 3.3.8 to 3.3.11, with nested @nuxt/cli transitive deps cac/commander a **Synthesis** — Devstral 2 123B wrote the final review from 0 confirmed findings. <sub>Transcript `rv-20260831053834-9e8dd3` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260831053834-9e8dd3`.</sub>
renovate-bot force-pushed renovate/vue-language-tools-monorepo from e817bf66e5
All checks were successful
scan / trivy-fs (push) Successful in 47s
baseline-security / baseline (push) Successful in 1m58s
ai-review / review (pull_request) Successful in 1m50s
scan / trivy-fs (pull_request) Successful in 52s
baseline-security / baseline (pull_request) Successful in 1m58s
to addda4bfe7
All checks were successful
scan / trivy-fs (push) Successful in 1m3s
baseline-security / baseline (push) Successful in 1m56s
scan / trivy-fs (pull_request) Successful in 47s
baseline-security / baseline (pull_request) Successful in 1m47s
ai-review / review (pull_request) Successful in 2m30s
2026-09-01 05:23:01 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: looks good — all four reviewers found nothing that needs fixing.

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 4 distinct, 0 confirmed, 4 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.97): The lockfile changes only update dependency versions and add optional peer entries; they appear compatible with the project’s Node version and declared ranges, and no correctness or security issues ar
  • Gemma 4 31B (0 findings, confidence 1.0): The diff is a routine dependency update for the Vue language tools monorepo, correctly updating both @vue/language-core and vue-tsc to v3.3.11 in the lockfile.
  • Devstral 2 123B (4 findings, confidence 0.9): The changes in package-lock.json introduce new dependencies and version updates that are not reflected in package.json, which could lead to inconsistencies and version drift.
  • Laguna S 2.1 (0 findings, confidence 0.95): The diff is a routine package-lock.json update bumping @vue/language-core and vue-tsc from 3.3.10 to 3.3.11 within the existing ^3.3.3 range; no package.json range was exceeded, all integrity hashes a

Round 2 — cross-examination

  • Devstral 2 123B#2 New dependency 'commander' added without version pinning in package.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#1 New dependency 'cac' added without version pinning in package.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#3 Version update for '@vue/language-core' not reflected in package.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#4 Version update for 'vue-tsc' not reflected in package.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1

Raised but refuted (left out of the review above)

  • Devstral 2 123B#2 New dependency 'commander' added without version pinning in package.json — The "commander" entry appears only as a transitive dependency under "node_modules/@nuxt/cli"; it is not a direct dependency and therefore does not nee
  • Devstral 2 123B#1 New dependency 'cac' added without version pinning in package.json — Similarly, "cac" is a transitive dependency of "@nuxt/cli". It is expected to appear only in package-lock.json and does not require a direct entry in
  • Devstral 2 123B#3 Version update for '@vue/language-core' not reflected in package.json — package.json specifies "@vue/language-core": "^3.3.3", which permits any 3.x version up to but not including 4.0.0. The lockfile pinning to 3.3.11 is
  • Devstral 2 123B#4 Version update for 'vue-tsc' not reflected in package.json — package.json lists "vue-tsc": "^3.3.3", allowing the 3.3.11 version recorded in the lockfile. This is intentional version range behavior, not a mismat

Synthesis — Devstral 2 123B wrote the final review from 0 confirmed findings.

Transcript rv-20260901055755-925e71 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260901055755-925e71.

### AI review · advisory <!-- tti-rv:rv-20260901055755-925e71: --> **Verdict: looks good** — all four reviewers found nothing that needs fixing. <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 4 distinct, 0 confirmed, 4 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.97): The lockfile changes only update dependency versions and add optional peer entries; they appear compatible with the project’s Node version and declared ranges, and no correctness or security issues ar - **Gemma 4 31B** (0 findings, confidence 1.0): The diff is a routine dependency update for the Vue language tools monorepo, correctly updating both @vue/language-core and vue-tsc to v3.3.11 in the lockfile. - **Devstral 2 123B** (4 findings, confidence 0.9): The changes in package-lock.json introduce new dependencies and version updates that are not reflected in package.json, which could lead to inconsistencies and version drift. - **Laguna S 2.1** (0 findings, confidence 0.95): The diff is a routine package-lock.json update bumping @vue/language-core and vue-tsc from 3.3.10 to 3.3.11 within the existing ^3.3.3 range; no package.json range was exceeded, all integrity hashes a **Round 2 — cross-examination** - `Devstral 2 123B#2` New dependency 'commander' added without version pinning in package.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#1` New dependency 'cac' added without version pinning in package.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#3` Version update for '@vue/language-core' not reflected in package.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#4` Version update for 'vue-tsc' not reflected in package.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 **Raised but refuted** (left out of the review above) - `Devstral 2 123B#2` New dependency 'commander' added without version pinning in package.json — The "commander" entry appears only as a transitive dependency under "node_modules/@nuxt/cli"; it is not a direct dependency and therefore does not nee - `Devstral 2 123B#1` New dependency 'cac' added without version pinning in package.json — Similarly, "cac" is a transitive dependency of "@nuxt/cli". It is expected to appear only in package-lock.json and does not require a direct entry in - `Devstral 2 123B#3` Version update for '@vue/language-core' not reflected in package.json — package.json specifies "@vue/language-core": "^3.3.3", which permits any 3.x version up to but not including 4.0.0. The lockfile pinning to 3.3.11 is - `Devstral 2 123B#4` Version update for 'vue-tsc' not reflected in package.json — package.json lists "vue-tsc": "^3.3.3", allowing the 3.3.11 version recorded in the lockfile. This is intentional version range behavior, not a mismat **Synthesis** — Devstral 2 123B wrote the final review from 0 confirmed findings. <sub>Transcript `rv-20260901055755-925e71` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260901055755-925e71`.</sub>
renovate-bot force-pushed renovate/vue-language-tools-monorepo from addda4bfe7
All checks were successful
scan / trivy-fs (push) Successful in 1m3s
baseline-security / baseline (push) Successful in 1m56s
scan / trivy-fs (pull_request) Successful in 47s
baseline-security / baseline (pull_request) Successful in 1m47s
ai-review / review (pull_request) Successful in 2m30s
to bfc295f766
All checks were successful
scan / trivy-fs (push) Successful in 58s
baseline-security / baseline (push) Successful in 2m9s
scan / trivy-fs (pull_request) Successful in 42s
ai-review / review (pull_request) Successful in 2m0s
baseline-security / baseline (pull_request) Successful in 1m39s
2026-09-02 05:12:04 +00:00
Compare
ai-review-bot left a comment

AI review · advisory

Verdict: looks good — all four reviewers found nothing that needs fixing.

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 0 confirmed, 3 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.97): No problematic changes detected in the modified lines.
  • Gemma 4 31B (0 findings, confidence 1.0): The diff shows a routine dependency update for @vue/language-core and vue-tsc from v3.3.8 to v3.3.11, and a corresponding version bump for the project and its react workspace; no correctness or se
  • Devstral 2 123B (3 findings, confidence 0.8): The diff shows a version mismatch in package-lock.json that needs to be corrected.
  • Laguna S 2.1 (0 findings, confidence 0.96): No issues found — the PR is a clean dependency update that bumps vue-language-tools monorepo packages (@vue/language-core and vue-tsc) from 3.3.8 to 3.3.11, adds two new transitive dependencies (cac 6

Round 2 — cross-examination

  • Devstral 2 123B#1 Version mismatch in package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#2 Version mismatch in package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Devstral 2 123B#3 Version mismatch in package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1

Raised but refuted (left out of the review above)

  • Devstral 2 123B#1 Version mismatch in package-lock.json — The diff shows the top‑level "version" in package-lock.json updated to "2.1.0", matching the version defined in package.json (also "2.1.0"); thus ther
  • Devstral 2 123B#2 Version mismatch in package-lock.json — At line 2643 the package‑lock entry for the root package was changed from "2.0.0" to "2.1.0", which aligns with the version in package.json; no mismat
  • Devstral 2 123B#3 Version mismatch in package-lock.json — Line 23136 shows the version field in package-lock.json set to "2.1.0", again consistent with package.json's version; the claim of a mismatch is incor

Synthesis — Devstral 2 123B wrote the final review from 0 confirmed findings.

Transcript rv-20260902052706-2da830 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260902052706-2da830.

### AI review · advisory <!-- tti-rv:rv-20260902052706-2da830: --> **Verdict: looks good** — all four reviewers found nothing that needs fixing. <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 0 confirmed, 3 refuted · web: not used · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.97): No problematic changes detected in the modified lines. - **Gemma 4 31B** (0 findings, confidence 1.0): The diff shows a routine dependency update for `@vue/language-core` and `vue-tsc` from v3.3.8 to v3.3.11, and a corresponding version bump for the project and its react workspace; no correctness or se - **Devstral 2 123B** (3 findings, confidence 0.8): The diff shows a version mismatch in package-lock.json that needs to be corrected. - **Laguna S 2.1** (0 findings, confidence 0.96): No issues found — the PR is a clean dependency update that bumps vue-language-tools monorepo packages (@vue/language-core and vue-tsc) from 3.3.8 to 3.3.11, adds two new transitive dependencies (cac 6 **Round 2 — cross-examination** - `Devstral 2 123B#1` Version mismatch in package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#2` Version mismatch in package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Devstral 2 123B#3` Version mismatch in package-lock.json · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 **Raised but refuted** (left out of the review above) - `Devstral 2 123B#1` Version mismatch in package-lock.json — The diff shows the top‑level "version" in package-lock.json updated to "2.1.0", matching the version defined in package.json (also "2.1.0"); thus ther - `Devstral 2 123B#2` Version mismatch in package-lock.json — At line 2643 the package‑lock entry for the root package was changed from "2.0.0" to "2.1.0", which aligns with the version in package.json; no mismat - `Devstral 2 123B#3` Version mismatch in package-lock.json — Line 23136 shows the version field in package-lock.json set to "2.1.0", again consistent with package.json's version; the claim of a mismatch is incor **Synthesis** — Devstral 2 123B wrote the final review from 0 confirmed findings. <sub>Transcript `rv-20260902052706-2da830` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260902052706-2da830`.</sub>
renovate-bot force-pushed renovate/vue-language-tools-monorepo from bfc295f766
All checks were successful
scan / trivy-fs (push) Successful in 58s
baseline-security / baseline (push) Successful in 2m9s
scan / trivy-fs (pull_request) Successful in 42s
ai-review / review (pull_request) Successful in 2m0s
baseline-security / baseline (pull_request) Successful in 1m39s
to 280b45b95b
Some checks failed
scan / trivy-fs (push) Failing after 59s
ai-review / review (pull_request) Successful in 59s
baseline-security / baseline (push) Failing after 1m19s
scan / trivy-fs (pull_request) Failing after 56s
baseline-security / baseline (pull_request) Failing after 1m35s
2026-09-09 05:21:42 +00:00
Compare
Member

AI review · advisory

Verdict: lockfile-only change — AI review skipped.

This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic.

⚑ panel: skipped (lockfile-only, 1 file)

Full transcript: http://host.containers.internal:3939/-/ai/v1/review/rv-20260909054743-f7cc5d

A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.

### AI review · advisory **Verdict: lockfile-only change** — AI review skipped. This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic. <sub>⚑ panel: skipped (lockfile-only, 1 file)</sub> <sub>Full transcript: http://host.containers.internal:3939/-/ai/v1/review/rv-20260909054743-f7cc5d</sub> <sub>A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.</sub>

🔧 Security-gate fix map

The gate failed on these dependency findings — fastest path to green for each:

finding package installed → fixed do this
GHSA-j95f-988m-3j2f (HIGH) @tiptap/core 3.28.0 → 3.30.5 no fix PR yet — npm update core --package-lock-only
CVE-2026-84375 (HIGH) js-yaml 4.3.1 → 4.3.2, 3.15.2 no fix PR yet — npm update js-yaml --package-lock-only
GHSA-rgj7-g3m4-5g8c (HIGH) sharp 0.35.3 → 0.35.4 no fix PR yet — npm update sharp --package-lock-only
CVE-2026-84370 (HIGH) svgo 4.0.2 → 2.8.4, 3.3.5, 4.1.0 no fix PR yet — npm update svgo --package-lock-only

⚠ main is itself red right now — this PR likely inherits the backlog rather than adding it. Fixing main (rows above) unblocks every open PR at once.

Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.

### 🔧 Security-gate fix map <!-- tti-fixmap:280b45b95b66c9f195a7bf47c3dbb0d512d38ae6 --> The gate failed on these dependency findings — fastest path to green for each: | finding | package | installed → fixed | do this | |---|---|---|---| | GHSA-j95f-988m-3j2f (HIGH) | `@tiptap/core` | 3.28.0 → 3.30.5 | no fix PR yet — `npm update core --package-lock-only` | | CVE-2026-84375 (HIGH) | `js-yaml` | 4.3.1 → 4.3.2, 3.15.2 | no fix PR yet — `npm update js-yaml --package-lock-only` | | GHSA-rgj7-g3m4-5g8c (HIGH) | `sharp` | 0.35.3 → 0.35.4 | no fix PR yet — `npm update sharp --package-lock-only` | | CVE-2026-84370 (HIGH) | `svgo` | 4.0.2 → 2.8.4, 3.3.5, 4.1.0 | no fix PR yet — `npm update svgo --package-lock-only` | > ⚠ `main` is itself red right now — this PR likely **inherits** the backlog rather than adding it. Fixing `main` (rows above) unblocks every open PR at once. <sub>Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.</sub>
renovate-bot force-pushed renovate/vue-language-tools-monorepo from 280b45b95b
Some checks failed
scan / trivy-fs (push) Failing after 59s
ai-review / review (pull_request) Successful in 59s
baseline-security / baseline (push) Failing after 1m19s
scan / trivy-fs (pull_request) Failing after 56s
baseline-security / baseline (pull_request) Failing after 1m35s
to c42103bedd
Some checks failed
ai-review / review (pull_request) Successful in 1m0s
baseline-security / baseline (push) Failing after 1m27s
scan / trivy-fs (push) Failing after 1m4s
scan / trivy-fs (pull_request) Failing after 1m8s
baseline-security / baseline (pull_request) Failing after 1m39s
2026-09-27 23:30:03 +00:00
Compare
Member

AI review · advisory

Verdict: lockfile-only change — AI review skipped.

This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic.

⚑ panel: skipped (lockfile-only, 1 file)

A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.

### AI review · advisory **Verdict: lockfile-only change** — AI review skipped. This change touches only dependency lockfiles (package-lock.json). The panel does not debate lockfiles — the baseline gate's SCA and secret scans are the control for dependency risk, and they are deterministic. <sub>⚑ panel: skipped (lockfile-only, 1 file)</sub> <sub>A panel of superPOD models reviewed this independently and cross-examined each other; only what survived is shown. Advisory — never a merge gate.</sub>

🔧 Security-gate fix map

The gate failed on these dependency findings — fastest path to green for each:

finding package installed → fixed do this
CVE-2026-63671 (HIGH) @nuxtjs/mdc 0.21.1 → 0.22.1 merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f
GHSA-j95f-988m-3j2f (HIGH) @tiptap/core 3.28.0 → 3.30.5 no fix PR yet — npm update core --package-lock-only
CVE-2026-84375 (HIGH) js-yaml 4.3.1 → 4.3.2, 3.15.2 no fix PR yet — npm update js-yaml --package-lock-only
GHSA-rgj7-g3m4-5g8c (HIGH) sharp 0.35.3 → 0.35.4 no fix PR yet — npm update sharp --package-lock-only
CVE-2026-84370 (HIGH) svgo 4.0.2 → 2.8.4, 3.3.5, 4.1.0 no fix PR yet — npm update svgo --package-lock-only

⚠ main is itself red right now — this PR likely inherits the backlog rather than adding it. Fixing main (rows above) unblocks every open PR at once.

Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.

### 🔧 Security-gate fix map <!-- tti-fixmap:c42103beddf8e783a7f84b35cc2d996b97bc0a4c --> The gate failed on these dependency findings — fastest path to green for each: | finding | package | installed → fixed | do this | |---|---|---|---| | CVE-2026-63671 (HIGH) | `@nuxtjs/mdc` | 0.21.1 → 0.22.1 | merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f | | GHSA-j95f-988m-3j2f (HIGH) | `@tiptap/core` | 3.28.0 → 3.30.5 | no fix PR yet — `npm update core --package-lock-only` | | CVE-2026-84375 (HIGH) | `js-yaml` | 4.3.1 → 4.3.2, 3.15.2 | no fix PR yet — `npm update js-yaml --package-lock-only` | | GHSA-rgj7-g3m4-5g8c (HIGH) | `sharp` | 0.35.3 → 0.35.4 | no fix PR yet — `npm update sharp --package-lock-only` | | CVE-2026-84370 (HIGH) | `svgo` | 4.0.2 → 2.8.4, 3.3.5, 4.1.0 | no fix PR yet — `npm update svgo --package-lock-only` | > ⚠ `main` is itself red right now — this PR likely **inherits** the backlog rather than adding it. Fixing `main` (rows above) unblocks every open PR at once. <sub>Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.</sub>
Some checks failed
ai-review / review (pull_request) Successful in 1m0s
baseline-security / baseline (push) Failing after 1m27s
scan / trivy-fs (push) Failing after 1m4s
scan / trivy-fs (pull_request) Failing after 1m8s
baseline-security / baseline (pull_request) Failing after 1m39s
Required
Details
This pull request doesn't have enough approvals yet. 0 of 1 approvals granted.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/vue-language-tools-monorepo:renovate/vue-language-tools-monorepo
git switch renovate/vue-language-tools-monorepo
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
tti/tti-ux!39
No description provided.