Skip to content

chore(deps): bump the npm_and_yarn group across 1 directory with 1 update - #1295

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/npm_and_yarn-dcc3f92f05
Open

chore(deps): bump the npm_and_yarn group across 1 directory with 1 update#1295
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/npm_and_yarn-dcc3f92f05

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 1 update in the / directory: brace-expansion.

Updates brace-expansion from 5.0.8 to 5.0.9

Commits

Updates brace-expansion from 2.1.2 to 2.1.4

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 3, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 3, 2026 21:16

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — mechanical lockfile-only dependency bump.

Extended reasoning...

Overview

This PR only modifies package-lock.json, bumping the transitive dependency brace-expansion (a sub-dependency of @fastify/otel and other packages) from 5.0.8 to 5.0.9 and from 2.1.2 to 2.1.4. No application source files are touched.

Security risks

None identified. This is a patch-level bump of a transitive dependency used for glob/brace pattern parsing. The changes are limited to test coverage and documentation fixes upstream per the changelog; there is no indication of a security advisory driving this bump, and the integrity hashes in the lockfile are updated consistently with the new versions.

Level of scrutiny

Minimal scrutiny is warranted. This is an auto-generated Dependabot lockfile-only PR with no logic changes, no new files, and no risk of behavioral regression in the storage service itself.

Other factors

No prior reviews exist on this PR. The change is small, mechanical, and matches the standard Dependabot pattern seen in other recent merged PRs in this repo history (e.g. the @fastify/static bump).

@coveralls

Copy link
Copy Markdown

Coverage Report for CI Build 30853908022

Coverage decreased (-0.1%) to 80.395%

Details

  • Coverage decreased (-0.1%) from the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • 19 coverage regressions across 2 files.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

19 previously-covered lines in 2 files lost coverage.

File Lines Losing Coverage Coverage
src/internal/http/agent.ts 17 32.56%
src/http/routes/s3/index.ts 2 86.09%

Coverage Stats

Coverage Status
Relevant Lines: 12654
Covered Lines: 10592
Line Coverage: 83.7%
Relevant Branches: 7504
Covered Branches: 5614
Branch Coverage: 74.81%
Branches in Coverage %: Yes
Coverage Strength: 433.87 hits per line

💛 - Coveralls

…date

Bumps the npm_and_yarn group with 1 update in the / directory: [brace-expansion](https://github.com/juliangruber/brace-expansion).


Updates `brace-expansion` from 5.0.8 to 5.0.9
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.8...v5.0.9)

Updates `brace-expansion` from 2.1.2 to 2.1.4
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.8...v5.0.9)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 2.1.4
  dependency-type: indirect
- dependency-name: brace-expansion
  dependency-version: 5.0.9
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm_and_yarn-dcc3f92f05 branch from 4922c52 to d56e86c Compare August 12, 2026 21:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant