chore(deps): refresh turbo security bump - #504
Merged
Merged
Conversation
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
This was referenced Aug 17, 2026
Closed
Collaborator
Author
Review — PR #504 @ d972845BLOCKING
WARN
VERIFIED CLEAN
VALIDATION
Recommendation: REQUEST CHANGES before manual approval. Next human action: ask the author/agent to remove the unrelated lockfile drift or explicitly split/justify the additional Vite/Storybook transitive refresh; do not merge PR #504 as-is. |
Collaborator
Author
|
@bntvllnt current-head re-review for PR #504 at Review — clean / manual approval readyVERIFIED CLEAN
VALIDATION
No blocking findings remain from the Turbo scope review. Approval is recommended; final merge/approval remains manual. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #503
Supersedes #490
Updates root Turbo from lockfile-resolved 2.8.3 to 2.10.10. Diff is limited to package.json and pnpm-lock.yaml: six renamed platform optional packages and existing ESLint Turbo peer bindings; no unrelated dependency drift.
Independent review
No blocking findings. Reviewed every lockfile hunk. Turbo 2.10.10 exceeds the 2.9.14 fixes for GHSA-hcf7-66rw-9f5r and GHSA-3qcw-2rhx-2726. Package version stays 0.4.0; release workflow unchanged.
Verification at HEAD f5ee000
Quality Gates: frozen installation, pnpm -F @vllnt/ui lint, pnpm -F @vllnt/ui exec tsc --noEmit --project tsconfig.build.json, pnpm build and pnpm test:once all passed. Tests: 327 files / 1718 tests. Registry lint/drift/integrity and story verification/build also passed.
CI ran the synthetic merge; coordinator verified its tree equals the raw PR head tree: 81ea4b8e66ee5224ae294771db07fe1e4e23198d. Current main 38db630 is an ancestor of this head. No local rerun claimed. All currently reported GitHub checks pass, including E2E, React Doctor and CodeQL.
Release and recovery
User authorized landing via PR; preserve automatic 0.4.0 canary behavior. No stable workflow dispatch or latest-tag mutation. Recovery is a normal revert PR if post-merge checks regress. Cross-platform #479/#506 is excluded from this change.