Home

dev / openkara

publicthedavidweng/OpenKara· sync paused
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

chore(deps): bump @testing-library/dom from 10.4.1 to 10.4.2 in the dev-dependencies group

closed
#452 opened by dependabot[bot]dependabot/npm_and_yarn/dev-dependencies-cc4394c5c0→main
Conversation3
dependabot[bot]
Commits
0
Files changed…
opened this pull request
Author
· last week

Bumps the dev-dependencies group with 1 update: [@testing-library/dom](github.com/testing-library/dom-testing-library).

Updates [@testing-library](/testing-library)/dom from 10.4.1 to 10.4.2

Release notes

Sourced from @​testing-library/dom's releases.

v10.4.2

10.4.2 (2026-09-13)

Bug Fixes

  • deps: pin @​types/node to a TypeScript 4-compatible version (#1386) (6049cc0)
Commits
  • 6049cc0 fix(deps): pin @​types/node to a TypeScript 4-compatible version (#1386)
  • e395d5b Switch to trusted publishing (#1368)
  • See full diff in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​testing-library/dom since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting [@dependabot](/dependabot) rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • [@dependabot](/dependabot) rebase will rebase this PR
  • [@dependabot](/dependabot) recreate will recreate this PR, overwriting any edits that have been made to it
  • [@dependabot](/dependabot) show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • [@dependabot](/dependabot) ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • [@dependabot](/dependabot) ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • [@dependabot](/dependabot) ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • [@dependabot](/dependabot) unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • [@dependabot](/dependabot) unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
coderabbitai[bot]commented· last week

[!IMPORTANT]

Review skipped

Bot user detected.

To trigger a single review, invoke the [@coderabbitai](/coderabbitai) review command.

⚙️ Run configuration

Configuration used: Repository: thedavidweng/OpenKara/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 20e0c58d-fa6e-4391-8314-22fc92af7734

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
  • X
  • Mastodon
  • Reddit
  • LinkedIn

Comment [@coderabbitai](/coderabbitai) help to get the list of available commands.

codecov[bot]commented· last week

:x: 3 Tests Failed:

Tests completedFailedPassedSkipped
2368323650
View the top 3 failed test(s) by shortest run time
tests/ci/dependabot-automerge-contract.test.ts > dependabot automerge contract > denylists native audio, model, and windowing crates
Stack Traces | 0.00113s run time
AssertionError: expected null not to be null
 ❯ tests/ci/dependabot-automerge-contract.test.ts:40:26
tests/ci/dependabot-automerge-contract.test.ts > dependabot automerge contract > keeps top-level permissions read-only
Stack Traces | 0.00127s run time
AssertionError: expected 'name: Dependabot auto-merge\n\n# Offi…' to match /permissions:\n  contents: read/

- Expected:
/permissions:\n  contents: read/

+ Received:
"name: Dependabot auto-merge

# Official pattern: pull_request_target so GITHUB_TOKEN has write access on
# Dependabot PRs. Never checkout or execute PR code in this workflow.
# Safety model:
# - Dependabot cooldown delays version-update PRs (supply-chain window)
# - Security updates bypass cooldown and auto-merge ASAP
# - CI/required checks still gate the actual merge when configured
on:
  pull_request_target:

permissions: {}

concurrency:
  group: dependabot-automerge-${{ github.event.pull_request.number }}
  cancel-in-progress: true

jobs:
  automerge:
    name: Enable auto-merge
    if: >
      github.event.pull_request.user.login == 'dependabot[bot]'
      && github.event.pull_request.head.repo.full_name == github.repository
    runs-on: ubuntu-latest
    timeout-minutes: 5
    permissions:
      contents: write
      pull-requests: write
    steps:
      - name: Dependabot metadata
        id: meta
        uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0
        with:
          github-token: ${{ secrets.GITHUB_TOKEN }}
          alert-lookup: true

      - name: Enable auto-merge for safe updates
        env:
          GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
          PR_URL: ${{ github.event.pull_request.html_url }}
          DEP_NAMES: ${{ steps.meta.outputs.dependency-names }}
          PKG_ECOSYSTEM: ${{ steps.meta.outputs.package-ecosystem }}
          UPDATE_TYPE: ${{ steps.meta.outputs.update-type }}
          DEP_TYPE: ${{ steps.meta.outputs.dependency-type }}
          ALERT_STATE: ${{ steps.meta.outputs.alert-state }}
        run: |
          set -euo pipefail
          # Release/review tooling stays manual even when patch/minor.
          deny='googleapis/release-please-action dependabot/fetch-metadata'
          for blocked in $deny; do
            case \",${DEP_NAMES},\" in
              *\",${blocked},\"*)
                echo \"skip auto-merge (denylist): $blocked\"
                exit 0
                ;;
            esac
          done

          eco=\"${PKG_ECOSYSTEM}\"
          ut=\"${UPDATE_TYPE}\"
          dt=\"${DEP_TYPE}\"
          alert=\"${ALERT_STATE}\"

          eligible=false
          reason=\"\"

          # Security updates: always auto-merge (cooldown does not apply to them).
          if [ \"$alert\" = \"OPEN\" ] || [ \"$alert\" = \"FIXED\" ]; then
            eligible=true
            reason=\"security-update\"
          fi

          # Patch updates after cooldown window.
          if [ \"$ut\" = \"version-update:semver-patch\" ]; then
            eligible=true
            reason=\"semver-patch\"
          fi

          # github-actions non-major (covers SHA pin bumps with empty update-type).
          if [ \"$eco\" = \"github-actions\" ] || [ \"$eco\" = \"github_actions\" ]; then
            if [ \"$ut\" != \"version-update:semver-major\" ]; then
              eligible=true
              reason=\"github-actions-non-major\"
            fi
          fi

          # Minor of non-production / indirect / development deps.
          # Production minors stay manual (primary npm supply-chain surface).
          if [ \"$ut\" = \"version-update:semver-minor\" ] && [ \"$dt\" != \"direct:production\" ]; then
            eligible=true
            reason=\"minor-non-production\"
          fi

          if [ \"$eligible\" != true ]; then
            echo \"skip auto-merge: ecosystem=$eco update-type=$ut dependency-type=$dt alert=$alert names=$DEP_NAMES\"
            exit 0
          fi

          echo \"enable auto-merge ($reason): ecosystem=$eco update-type=$ut dependency-type=$dt alert=$alert names=$DEP_NAMES\"
          gh pr merge --auto --squash \"$PR_URL\"
"

 ❯ tests/ci/dependabot-automerge-contract.test.ts:60:22
tests/ci/dependabot-automerge-contract.test.ts > dependabot automerge contract > auto-merge is limited to semver patch and minor updates
Stack Traces | 0.00809s run time
AssertionError: expected [ 'version-update:semver-patch', …(2) ] to deeply equal [ 'version-update:semver-patch', …(1) ]

- Expected
+ Received

  [
    "version-update:semver-patch",
+   "version-update:semver-major",
    "version-update:semver-minor",
  ]

 ❯ tests/ci/dependabot-automerge-contract.test.ts:32:58

To view more test analytics, go to the Test Analytics Dashboard 📋 Got 3 mins? Take this short survey to help us improve Test Analytics.

dependabot[bot]commented· last week

Looks like @testing-library/dom is updatable in another way, so this is no longer needed.

Sign in to comment.

Merge readiness

Checking mergeability after the indexing worker computes the current branch state.

Autopilot

Debug

Reviews

Approved0
ReviewersNone yet

Configure an OpenRouter key in repository settings.