chore(deps): bump baseline-browser-mapping from 2.10.32 to 2.11.22 in /lua-shopping-assistant - #71
Conversation
Bumps [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) from 2.10.32 to 2.11.22. - [Release notes](https://github.com/web-platform-dx/baseline-browser-mapping/releases) - [Commits](web-platform-dx/baseline-browser-mapping@v2.10.32...v2.11.22) --- updated-dependencies: - dependency-name: baseline-browser-mapping dependency-version: 2.11.22 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
richard-lua
left a comment
There was a problem hiding this comment.
Code review — LOW risk
Automated Dependabot bump of the transitive dependency baseline-browser-mapping (2.10.32 → 2.11.22) in lua-shopping-assistant/package-lock.json. The diff changes only the version, resolved, and integrity fields — no source code, manifest ranges, or license changes. The upstream release notes indicate this line of releases actually fixes a security issue (CVE-2026-45819, replacing process.exit() with thrown errors), so the update is beneficial and low blast radius.
The change looks solid: it is a lockfile-only patch/minor bump of a transitive dev-tooling dependency with a pinned integrity hash, and nothing in the diff introduces behavioral or security risk. Recommend letting CI confirm the build/tests pass before merge, and (as always) trusting the integrity hash from npm rather than the PR description.
PR Risk Reviewer — automated senior review of 261954e · risk: low · confidence: 0.90
selcuk-lua
left a comment
There was a problem hiding this comment.
Code review — LOW risk
Lockfile-only bump of the transitive dependency baseline-browser-mapping (2.10.32 → 2.11.22) in lua-shopping-assistant. The diff changes only the version, resolved tarball URL, and SHA-512 integrity hash — no source, API, or contract changes, and the integrity hash preserves supply-chain verification. The change is safe to merge once CI passes.
No blocking findings. One advisory note: the PR body (Dependabot-populated, untrusted) references a security fix and a CVE identifier ("CVE-2026-45819") in the upstream release notes; treat these claims as unverified and confirm against an authoritative advisory source rather than relying on the PR text.
PR Risk Reviewer — automated senior review of 261954e · risk: low · confidence: 0.90
Bumps baseline-browser-mapping from 2.10.32 to 2.11.22.
Release notes
Sourced from baseline-browser-mapping's releases.
Commits
af7c3c4Patch to 2.11.22 because browser or feature data changed7e10cadBrowser or feature data changedebb9702Updating static siteecc57a3Updating static site0e5ed80Patch to 2.11.21 because browser or feature data changed11da0b6Browser or feature data changed69fcc81Updating static siteb964de0Patch to 2.11.20 because browser or feature data changed723099fBrowser or feature data changedf44163dUpdating static siteDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.