Skip to content

chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js - #6158

Merged
max-sixty merged 1 commit into
mainfrom
dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1
Aug 7, 2026
Merged

chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js#6158
max-sixty merged 1 commit into
mainfrom
dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 7, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 4.2.0 to 4.3.1.

Changelog

Sourced from js-yaml's changelog.

4.3.1 - 2026-07-31

Security

  • [backport] Remove quadratic complexity from !!omap duplicate key detection.

4.3.0 - 2026-06-27

Added

  • [backport] Added maxTotalMergeKeys (10000) loader option to limit the total number of keys processed by YAML merge (<<) across one load() / loadAll() call.

Fixed

  • Restore umd builds back to es5.

Removed

  • [backport] maxMergeSeqLength replaced with maxTotalMergeKeys for limiting YAML merge processing.
Commits
  • 86e91b8 4.3.1 released
  • c3cc4b0 Backport quadratic complexity fix for !!omap
  • 33d05b5 4.3.0 released
  • 663bfab Drop demo publish, to not override new v5 one.
  • 1cb8c7b Add v4-legacy tag for publish
  • 02f27af Restore umd builds back to es5
  • 8be84ed Fix es5 compatibility
  • 59423c6 Replace maxMergeSeqLength option with maxTotalMergeKeys (more robust). Ba...
  • 6842ef6 doc polish
  • See full diff in compare view

@dependabotdependabotBot added dependencies javascript Pull requests that update Javascript code labels Aug 7, 2026
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.2.0 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.2.0...4.3.1)
---
updated-dependencies:
- dependency-name: js-yaml
dependency-version: 4.3.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1 branch from abb3853 to cc02072CompareAugust 7, 2026 07:40
@max-sixty
max-sixty merged commit 6a41c1e into mainAug 7, 2026
37 checks passed
@max-sixty
max-sixty deleted the dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1 branch August 7, 2026 23:08
max-sixty pushed a commit to max-sixty/tend that referenced this pull request Aug 12, 2026
…anchored review SHA (#884)
A force-push doesn't just move a PR's head — GitHub also re-points the
prior review's `.commit_id` at the **new** head. `tend-review`'s
pre-flight guard compares that field against `HEAD_SHA` to decide
whether the current commit has already been reviewed, so after a rewrite
it reads `LAST_REVIEW_SHA == HEAD_SHA`, exits silently, and leaves a
stale APPROVE standing as the active verdict on code the bot never read.
## Observed
[`PRQL/prql#6158`](PRQL/prql#6158) (dependabot,
`js-yaml` bump). `prql-bot` submitted an empty-body APPROVE at
06:09:36Z; the head at that moment was `abb3853a` — confirmed by the
`tend-mention` run the review itself triggered six seconds later, which
carries `headSha=abb3853a`. Dependabot then rebased at 07:40:18Z
(`head_ref_force_pushed` → `cc020720`), which re-triggered
[`tend-review`
31158576591](https://github.com/PRQL/prql/actions/runs/31158576591). The
agent ran the full 1 m 47 s and posted nothing.
The reviews endpoint now reports that 06:09:36Z review against a commit
created at 07:40:16Z:
```
{"id":4880377370,"state":"APPROVED","submitted_at":"2026-08-07T06:09:36Z",
"commit_id":"cc0207205f99c5481b8404c805a16a43c91fb3af","body":""}
```
The session log shows the guard firing on exactly that, and the
reasoning is correct given what it was told to read:
> The current HEAD has already been reviewed and approved. There are no
conversation comments, no unanswered questions directed at the bot, and
no unresolved bot review threads to resolve. The triggering event was
`synchronize`, not `ready_for_review`, so no exception applies. Exiting
silently without posting — the existing approval stands as the active
verdict.
## Control
An ordinary push leaves the old anchor intact, so `.commit_id` alone
cannot distinguish the two cases. On
[`PRQL/prql#6159`](PRQL/prql#6159), a review
submitted at 06:58:45Z still reports `commit_id=779b096d` after
`177c1997` landed on top — the guard works there, which is why this has
stayed invisible.
## Fix
Probe the timeline for a `head_ref_force_pushed` newer than the last
substantive bot review. Non-zero ⇒ the reviewed commit was rewritten
away, so ignore `LAST_REVIEW_SHA` and review the head in full. The
incremental path has to be skipped too: after a rewrite
`LAST_REVIEW_SHA` names the current head, so `LAST_REVIEW_SHA..HEAD_SHA`
is empty and every trivial-skip heuristic keyed on it under-reports the
change.
The existing `LAST_REVIEW_SHA` extraction is refactored to keep the
whole review record rather than just `.commit_id`, so `submitted_at`
comes from the same substantive-filtered pick — no second query, no risk
of the two fields resolving to different reviews.
Verified live against three shapes: `#6158` (force-pushed after
approval) → 1; `#6159` (ordinary push) → 0; `#6161` (no prior bot
review) → empty anchor, 0.
## Gates
- **Evidence level**: High, **structural** — no decision point. Every
force-push after a bot review re-points the anchor and defeats the
comparison identically.
- **Occurrences**: 2 for the failure class. This one, plus
[#828](#828) — the same
`LAST_REVIEW_SHA == HEAD_SHA` guard skipping a real commit because the
anchor had moved to something the bot never reviewed (fixed for the
reply-container mechanism in
[#835](#835); the force-push
mechanism is untouched by that fix).
- **Magnitude**: targeted fix — one probe plus one condition, no new
section. Normal bar.
- Wrong-outcome shape, beyond the skipped work: the review record reads
"approved `cc020720`" for a commit the bot never fetched, and the
sequence generalizes to approve-then-rewrite.
Evidence log: https://gist.github.com/192514ea2c36586f9b7f842a482d62ab
---------
Co-authored-by: tend-agent <270458913+tend-agent@users.noreply.github.com>
max-sixty pushed a commit to max-sixty/tend that referenced this pull request Aug 12, 2026
…cy PR (#890)
`weekly`'s dependency-PR step skips approving when `LAST_APPROVAL_SHA ==
HEAD_SHA`. A force-push doesn't just move the head — GitHub re-points
the prior review's commit anchor at the **new** head, so after a rebase
that comparison reads true for a commit the bot never read. The PR is
left carrying an `APPROVED` it never earned, and the one step that would
have re-checked it declines to run.
Dependency PRs are the population tend rewrites on purpose: `nightly`
posts `@dependabot recreate` and ticks renovate's `rebase-check` on
conflicted bot PRs, both of which force-push.
## Observed
[`PRQL/prql#6158`](PRQL/prql#6158) (dependabot,
`js-yaml` bump). `prql-bot` approved at 06:09:36Z; dependabot rebased at
07:40:18Z. Running the current snippet against it now:
```
HEAD_SHA=cc0207205f99c5481b8404c805a16a43c91fb3af
LAST_APPROVAL_SHA=cc0207205f99c5481b8404c805a16a43c91fb3af
-> "Already approved on this commit; skipping."
```
`cc020720` was created 90 minutes after that approval.
## Fix
Take the newest `head_ref_force_pushed` off the timeline and drop
approvals older than it, mirroring the probe
[#884](#884) adds to `review`'s
three anchor sites. Switching from `gh pr view --json reviews` to the
REST endpoint is what makes the filter expressible: `submitted_at` isn't
in the GraphQL projection, and `gh api --jq` takes no `--arg`, so the
comparison pipes to `jq`. Note the field rename that comes with it —
REST carries `.commit_id`, not `.commit.oid`.
The equality test also gains an `-n` guard: with no surviving approval
both sides can now be empty, and `[ "" = "" ]` would skip.
Fixing the approve path alone would leave the stale `APPROVED` standing
on the two paths that *don't* reach it — step 2's "CI is failing,
comment and skip" and "major version bump, comment and skip". Both are
reachable precisely because a rebase changed something, so a
rebased-into-red dependency PR would get a failure comment while still
reading as bot-approved. A new item 6 dismisses any approval older than
the newest rewrite on those paths, using the same
`reviews/$REVIEW_ID/dismissals` call #884 gives `review`. It's
idempotent — a dismissed review reports `DISMISSED`, so the filter stops
matching it.
## Verified live
| PR | shape | before | after |
|---|---|---|---|
| [`#6158`](PRQL/prql#6158) | approved, then
force-pushed | skip | **proceed** |
| [`#6157`](PRQL/prql#6157) | approved, no
rewrite | skip | skip |
| [`#6156`](PRQL/prql#6156) | approved, no
rewrite | skip | skip |
The two controls confirm the redundant-approval suppression the guard
exists for is intact; only the rewritten case flips.
The dismissal filter resolves against the same three: `#6158` selects
review `4880377370` (`prql-bot`, `APPROVED`, `submitted_at` 06:09:36Z,
`commit_id` `cc020720` — the post-rewrite head, re-anchored), and both
controls select nothing.
Flagged in the [review of
#884](#884 (review))
as a separate concern from that diff, which patches `review` only.
---------
Co-authored-by: tend-agent <270458913+tend-agent@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesjavascriptPull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@prql-bot@max-sixty
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js by dependabot[bot] · Pull Request #6158 · PRQL/prql · GitHub
Skip to content

chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js - #6158

Merged
max-sixty merged 1 commit into
mainfrom
dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1
Aug 7, 2026
Merged

chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js#6158
max-sixty merged 1 commit into
mainfrom
dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 7, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 4.2.0 to 4.3.1.

Changelog

Sourced from js-yaml's changelog.

4.3.1 - 2026-07-31

Security

  • [backport] Remove quadratic complexity from !!omap duplicate key detection.

4.3.0 - 2026-06-27

Added

  • [backport] Added maxTotalMergeKeys (10000) loader option to limit the total number of keys processed by YAML merge (<<) across one load() / loadAll() call.

Fixed

  • Restore umd builds back to es5.

Removed

  • [backport] maxMergeSeqLength replaced with maxTotalMergeKeys for limiting YAML merge processing.
Commits
  • 86e91b8 4.3.1 released
  • c3cc4b0 Backport quadratic complexity fix for !!omap
  • 33d05b5 4.3.0 released
  • 663bfab Drop demo publish, to not override new v5 one.
  • 1cb8c7b Add v4-legacy tag for publish
  • 02f27af Restore umd builds back to es5
  • 8be84ed Fix es5 compatibility
  • 59423c6 Replace maxMergeSeqLength option with maxTotalMergeKeys (more robust). Ba...
  • 6842ef6 doc polish
  • See full diff in compare view

@dependabotdependabotBot added dependencies javascript Pull requests that update Javascript code labels Aug 7, 2026
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.2.0 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.2.0...4.3.1)
---
updated-dependencies:
- dependency-name: js-yaml
dependency-version: 4.3.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1 branch from abb3853 to cc02072CompareAugust 7, 2026 07:40
@max-sixty
max-sixty merged commit 6a41c1e into mainAug 7, 2026
37 checks passed
@max-sixty
max-sixty deleted the dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1 branch August 7, 2026 23:08
max-sixty pushed a commit to max-sixty/tend that referenced this pull request Aug 12, 2026
…anchored review SHA (#884)
A force-push doesn't just move a PR's head — GitHub also re-points the
prior review's `.commit_id` at the **new** head. `tend-review`'s
pre-flight guard compares that field against `HEAD_SHA` to decide
whether the current commit has already been reviewed, so after a rewrite
it reads `LAST_REVIEW_SHA == HEAD_SHA`, exits silently, and leaves a
stale APPROVE standing as the active verdict on code the bot never read.
## Observed
[`PRQL/prql#6158`](PRQL/prql#6158) (dependabot,
`js-yaml` bump). `prql-bot` submitted an empty-body APPROVE at
06:09:36Z; the head at that moment was `abb3853a` — confirmed by the
`tend-mention` run the review itself triggered six seconds later, which
carries `headSha=abb3853a`. Dependabot then rebased at 07:40:18Z
(`head_ref_force_pushed` → `cc020720`), which re-triggered
[`tend-review`
31158576591](https://github.com/PRQL/prql/actions/runs/31158576591). The
agent ran the full 1 m 47 s and posted nothing.
The reviews endpoint now reports that 06:09:36Z review against a commit
created at 07:40:16Z:
```
{"id":4880377370,"state":"APPROVED","submitted_at":"2026-08-07T06:09:36Z",
"commit_id":"cc0207205f99c5481b8404c805a16a43c91fb3af","body":""}
```
The session log shows the guard firing on exactly that, and the
reasoning is correct given what it was told to read:
> The current HEAD has already been reviewed and approved. There are no
conversation comments, no unanswered questions directed at the bot, and
no unresolved bot review threads to resolve. The triggering event was
`synchronize`, not `ready_for_review`, so no exception applies. Exiting
silently without posting — the existing approval stands as the active
verdict.
## Control
An ordinary push leaves the old anchor intact, so `.commit_id` alone
cannot distinguish the two cases. On
[`PRQL/prql#6159`](PRQL/prql#6159), a review
submitted at 06:58:45Z still reports `commit_id=779b096d` after
`177c1997` landed on top — the guard works there, which is why this has
stayed invisible.
## Fix
Probe the timeline for a `head_ref_force_pushed` newer than the last
substantive bot review. Non-zero ⇒ the reviewed commit was rewritten
away, so ignore `LAST_REVIEW_SHA` and review the head in full. The
incremental path has to be skipped too: after a rewrite
`LAST_REVIEW_SHA` names the current head, so `LAST_REVIEW_SHA..HEAD_SHA`
is empty and every trivial-skip heuristic keyed on it under-reports the
change.
The existing `LAST_REVIEW_SHA` extraction is refactored to keep the
whole review record rather than just `.commit_id`, so `submitted_at`
comes from the same substantive-filtered pick — no second query, no risk
of the two fields resolving to different reviews.
Verified live against three shapes: `#6158` (force-pushed after
approval) → 1; `#6159` (ordinary push) → 0; `#6161` (no prior bot
review) → empty anchor, 0.
## Gates
- **Evidence level**: High, **structural** — no decision point. Every
force-push after a bot review re-points the anchor and defeats the
comparison identically.
- **Occurrences**: 2 for the failure class. This one, plus
[#828](#828) — the same
`LAST_REVIEW_SHA == HEAD_SHA` guard skipping a real commit because the
anchor had moved to something the bot never reviewed (fixed for the
reply-container mechanism in
[#835](#835); the force-push
mechanism is untouched by that fix).
- **Magnitude**: targeted fix — one probe plus one condition, no new
section. Normal bar.
- Wrong-outcome shape, beyond the skipped work: the review record reads
"approved `cc020720`" for a commit the bot never fetched, and the
sequence generalizes to approve-then-rewrite.
Evidence log: https://gist.github.com/192514ea2c36586f9b7f842a482d62ab
---------
Co-authored-by: tend-agent <270458913+tend-agent@users.noreply.github.com>
max-sixty pushed a commit to max-sixty/tend that referenced this pull request Aug 12, 2026
…cy PR (#890)
`weekly`'s dependency-PR step skips approving when `LAST_APPROVAL_SHA ==
HEAD_SHA`. A force-push doesn't just move the head — GitHub re-points
the prior review's commit anchor at the **new** head, so after a rebase
that comparison reads true for a commit the bot never read. The PR is
left carrying an `APPROVED` it never earned, and the one step that would
have re-checked it declines to run.
Dependency PRs are the population tend rewrites on purpose: `nightly`
posts `@dependabot recreate` and ticks renovate's `rebase-check` on
conflicted bot PRs, both of which force-push.
## Observed
[`PRQL/prql#6158`](PRQL/prql#6158) (dependabot,
`js-yaml` bump). `prql-bot` approved at 06:09:36Z; dependabot rebased at
07:40:18Z. Running the current snippet against it now:
```
HEAD_SHA=cc0207205f99c5481b8404c805a16a43c91fb3af
LAST_APPROVAL_SHA=cc0207205f99c5481b8404c805a16a43c91fb3af
-> "Already approved on this commit; skipping."
```
`cc020720` was created 90 minutes after that approval.
## Fix
Take the newest `head_ref_force_pushed` off the timeline and drop
approvals older than it, mirroring the probe
[#884](#884) adds to `review`'s
three anchor sites. Switching from `gh pr view --json reviews` to the
REST endpoint is what makes the filter expressible: `submitted_at` isn't
in the GraphQL projection, and `gh api --jq` takes no `--arg`, so the
comparison pipes to `jq`. Note the field rename that comes with it —
REST carries `.commit_id`, not `.commit.oid`.
The equality test also gains an `-n` guard: with no surviving approval
both sides can now be empty, and `[ "" = "" ]` would skip.
Fixing the approve path alone would leave the stale `APPROVED` standing
on the two paths that *don't* reach it — step 2's "CI is failing,
comment and skip" and "major version bump, comment and skip". Both are
reachable precisely because a rebase changed something, so a
rebased-into-red dependency PR would get a failure comment while still
reading as bot-approved. A new item 6 dismisses any approval older than
the newest rewrite on those paths, using the same
`reviews/$REVIEW_ID/dismissals` call #884 gives `review`. It's
idempotent — a dismissed review reports `DISMISSED`, so the filter stops
matching it.
## Verified live
| PR | shape | before | after |
|---|---|---|---|
| [`#6158`](PRQL/prql#6158) | approved, then
force-pushed | skip | **proceed** |
| [`#6157`](PRQL/prql#6157) | approved, no
rewrite | skip | skip |
| [`#6156`](PRQL/prql#6156) | approved, no
rewrite | skip | skip |
The two controls confirm the redundant-approval suppression the guard
exists for is intact; only the rewritten case flips.
The dismissal filter resolves against the same three: `#6158` selects
review `4880377370` (`prql-bot`, `APPROVED`, `submitted_at` 06:09:36Z,
`commit_id` `cc020720` — the post-rewrite head, re-anchored), and both
controls select nothing.
Flagged in the [review of
#884](#884 (review))
as a separate concern from that diff, which patches `review` only.
---------
Co-authored-by: tend-agent <270458913+tend-agent@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesjavascriptPull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@prql-bot@max-sixty
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js by dependabot[bot] · Pull Request #6158 · PRQL/prql · GitHub
Skip to content

chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js - #6158

Merged
max-sixty merged 1 commit into
mainfrom
dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1
Aug 7, 2026
Merged

chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js#6158
max-sixty merged 1 commit into
mainfrom
dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 7, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 4.2.0 to 4.3.1.

Changelog

Sourced from js-yaml's changelog.

4.3.1 - 2026-07-31

Security

  • [backport] Remove quadratic complexity from !!omap duplicate key detection.

4.3.0 - 2026-06-27

Added

  • [backport] Added maxTotalMergeKeys (10000) loader option to limit the total number of keys processed by YAML merge (<<) across one load() / loadAll() call.

Fixed

  • Restore umd builds back to es5.

Removed

  • [backport] maxMergeSeqLength replaced with maxTotalMergeKeys for limiting YAML merge processing.
Commits
  • 86e91b8 4.3.1 released
  • c3cc4b0 Backport quadratic complexity fix for !!omap
  • 33d05b5 4.3.0 released
  • 663bfab Drop demo publish, to not override new v5 one.
  • 1cb8c7b Add v4-legacy tag for publish
  • 02f27af Restore umd builds back to es5
  • 8be84ed Fix es5 compatibility
  • 59423c6 Replace maxMergeSeqLength option with maxTotalMergeKeys (more robust). Ba...
  • 6842ef6 doc polish
  • See full diff in compare view

@dependabotdependabotBot added dependencies javascript Pull requests that update Javascript code labels Aug 7, 2026
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.2.0 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.2.0...4.3.1)
---
updated-dependencies:
- dependency-name: js-yaml
dependency-version: 4.3.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1 branch from abb3853 to cc02072CompareAugust 7, 2026 07:40
@max-sixty
max-sixty merged commit 6a41c1e into mainAug 7, 2026
37 checks passed
@max-sixty
max-sixty deleted the dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1 branch August 7, 2026 23:08
max-sixty pushed a commit to max-sixty/tend that referenced this pull request Aug 12, 2026
…anchored review SHA (#884)
A force-push doesn't just move a PR's head — GitHub also re-points the
prior review's `.commit_id` at the **new** head. `tend-review`'s
pre-flight guard compares that field against `HEAD_SHA` to decide
whether the current commit has already been reviewed, so after a rewrite
it reads `LAST_REVIEW_SHA == HEAD_SHA`, exits silently, and leaves a
stale APPROVE standing as the active verdict on code the bot never read.
## Observed
[`PRQL/prql#6158`](PRQL/prql#6158) (dependabot,
`js-yaml` bump). `prql-bot` submitted an empty-body APPROVE at
06:09:36Z; the head at that moment was `abb3853a` — confirmed by the
`tend-mention` run the review itself triggered six seconds later, which
carries `headSha=abb3853a`. Dependabot then rebased at 07:40:18Z
(`head_ref_force_pushed` → `cc020720`), which re-triggered
[`tend-review`
31158576591](https://github.com/PRQL/prql/actions/runs/31158576591). The
agent ran the full 1 m 47 s and posted nothing.
The reviews endpoint now reports that 06:09:36Z review against a commit
created at 07:40:16Z:
```
{"id":4880377370,"state":"APPROVED","submitted_at":"2026-08-07T06:09:36Z",
"commit_id":"cc0207205f99c5481b8404c805a16a43c91fb3af","body":""}
```
The session log shows the guard firing on exactly that, and the
reasoning is correct given what it was told to read:
> The current HEAD has already been reviewed and approved. There are no
conversation comments, no unanswered questions directed at the bot, and
no unresolved bot review threads to resolve. The triggering event was
`synchronize`, not `ready_for_review`, so no exception applies. Exiting
silently without posting — the existing approval stands as the active
verdict.
## Control
An ordinary push leaves the old anchor intact, so `.commit_id` alone
cannot distinguish the two cases. On
[`PRQL/prql#6159`](PRQL/prql#6159), a review
submitted at 06:58:45Z still reports `commit_id=779b096d` after
`177c1997` landed on top — the guard works there, which is why this has
stayed invisible.
## Fix
Probe the timeline for a `head_ref_force_pushed` newer than the last
substantive bot review. Non-zero ⇒ the reviewed commit was rewritten
away, so ignore `LAST_REVIEW_SHA` and review the head in full. The
incremental path has to be skipped too: after a rewrite
`LAST_REVIEW_SHA` names the current head, so `LAST_REVIEW_SHA..HEAD_SHA`
is empty and every trivial-skip heuristic keyed on it under-reports the
change.
The existing `LAST_REVIEW_SHA` extraction is refactored to keep the
whole review record rather than just `.commit_id`, so `submitted_at`
comes from the same substantive-filtered pick — no second query, no risk
of the two fields resolving to different reviews.
Verified live against three shapes: `#6158` (force-pushed after
approval) → 1; `#6159` (ordinary push) → 0; `#6161` (no prior bot
review) → empty anchor, 0.
## Gates
- **Evidence level**: High, **structural** — no decision point. Every
force-push after a bot review re-points the anchor and defeats the
comparison identically.
- **Occurrences**: 2 for the failure class. This one, plus
[#828](#828) — the same
`LAST_REVIEW_SHA == HEAD_SHA` guard skipping a real commit because the
anchor had moved to something the bot never reviewed (fixed for the
reply-container mechanism in
[#835](#835); the force-push
mechanism is untouched by that fix).
- **Magnitude**: targeted fix — one probe plus one condition, no new
section. Normal bar.
- Wrong-outcome shape, beyond the skipped work: the review record reads
"approved `cc020720`" for a commit the bot never fetched, and the
sequence generalizes to approve-then-rewrite.
Evidence log: https://gist.github.com/192514ea2c36586f9b7f842a482d62ab
---------
Co-authored-by: tend-agent <270458913+tend-agent@users.noreply.github.com>
max-sixty pushed a commit to max-sixty/tend that referenced this pull request Aug 12, 2026
…cy PR (#890)
`weekly`'s dependency-PR step skips approving when `LAST_APPROVAL_SHA ==
HEAD_SHA`. A force-push doesn't just move the head — GitHub re-points
the prior review's commit anchor at the **new** head, so after a rebase
that comparison reads true for a commit the bot never read. The PR is
left carrying an `APPROVED` it never earned, and the one step that would
have re-checked it declines to run.
Dependency PRs are the population tend rewrites on purpose: `nightly`
posts `@dependabot recreate` and ticks renovate's `rebase-check` on
conflicted bot PRs, both of which force-push.
## Observed
[`PRQL/prql#6158`](PRQL/prql#6158) (dependabot,
`js-yaml` bump). `prql-bot` approved at 06:09:36Z; dependabot rebased at
07:40:18Z. Running the current snippet against it now:
```
HEAD_SHA=cc0207205f99c5481b8404c805a16a43c91fb3af
LAST_APPROVAL_SHA=cc0207205f99c5481b8404c805a16a43c91fb3af
-> "Already approved on this commit; skipping."
```
`cc020720` was created 90 minutes after that approval.
## Fix
Take the newest `head_ref_force_pushed` off the timeline and drop
approvals older than it, mirroring the probe
[#884](#884) adds to `review`'s
three anchor sites. Switching from `gh pr view --json reviews` to the
REST endpoint is what makes the filter expressible: `submitted_at` isn't
in the GraphQL projection, and `gh api --jq` takes no `--arg`, so the
comparison pipes to `jq`. Note the field rename that comes with it —
REST carries `.commit_id`, not `.commit.oid`.
The equality test also gains an `-n` guard: with no surviving approval
both sides can now be empty, and `[ "" = "" ]` would skip.
Fixing the approve path alone would leave the stale `APPROVED` standing
on the two paths that *don't* reach it — step 2's "CI is failing,
comment and skip" and "major version bump, comment and skip". Both are
reachable precisely because a rebase changed something, so a
rebased-into-red dependency PR would get a failure comment while still
reading as bot-approved. A new item 6 dismisses any approval older than
the newest rewrite on those paths, using the same
`reviews/$REVIEW_ID/dismissals` call #884 gives `review`. It's
idempotent — a dismissed review reports `DISMISSED`, so the filter stops
matching it.
## Verified live
| PR | shape | before | after |
|---|---|---|---|
| [`#6158`](PRQL/prql#6158) | approved, then
force-pushed | skip | **proceed** |
| [`#6157`](PRQL/prql#6157) | approved, no
rewrite | skip | skip |
| [`#6156`](PRQL/prql#6156) | approved, no
rewrite | skip | skip |
The two controls confirm the redundant-approval suppression the guard
exists for is intact; only the rewritten case flips.
The dismissal filter resolves against the same three: `#6158` selects
review `4880377370` (`prql-bot`, `APPROVED`, `submitted_at` 06:09:36Z,
`commit_id` `cc020720` — the post-rewrite head, re-anchored), and both
controls select nothing.
Flagged in the [review of
#884](#884 (review))
as a separate concern from that diff, which patches `review` only.
---------
Co-authored-by: tend-agent <270458913+tend-agent@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesjavascriptPull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@prql-bot@max-sixty
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js by dependabot[bot] · Pull Request #6158 · PRQL/prql · GitHub
Skip to content

chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js - #6158

Merged
max-sixty merged 1 commit into
mainfrom
dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1
Aug 7, 2026
Merged

chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js#6158
max-sixty merged 1 commit into
mainfrom
dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 7, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 4.2.0 to 4.3.1.

Changelog

Sourced from js-yaml's changelog.

4.3.1 - 2026-07-31

Security

  • [backport] Remove quadratic complexity from !!omap duplicate key detection.

4.3.0 - 2026-06-27

Added

  • [backport] Added maxTotalMergeKeys (10000) loader option to limit the total number of keys processed by YAML merge (<<) across one load() / loadAll() call.

Fixed

  • Restore umd builds back to es5.

Removed

  • [backport] maxMergeSeqLength replaced with maxTotalMergeKeys for limiting YAML merge processing.
Commits
  • 86e91b8 4.3.1 released
  • c3cc4b0 Backport quadratic complexity fix for !!omap
  • 33d05b5 4.3.0 released
  • 663bfab Drop demo publish, to not override new v5 one.
  • 1cb8c7b Add v4-legacy tag for publish
  • 02f27af Restore umd builds back to es5
  • 8be84ed Fix es5 compatibility
  • 59423c6 Replace maxMergeSeqLength option with maxTotalMergeKeys (more robust). Ba...
  • 6842ef6 doc polish
  • See full diff in compare view

@dependabotdependabotBot added dependencies javascript Pull requests that update Javascript code labels Aug 7, 2026
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.2.0 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.2.0...4.3.1)
---
updated-dependencies:
- dependency-name: js-yaml
dependency-version: 4.3.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1 branch from abb3853 to cc02072CompareAugust 7, 2026 07:40
@max-sixty
max-sixty merged commit 6a41c1e into mainAug 7, 2026
37 checks passed
@max-sixty
max-sixty deleted the dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1 branch August 7, 2026 23:08
max-sixty pushed a commit to max-sixty/tend that referenced this pull request Aug 12, 2026
…anchored review SHA (#884)
A force-push doesn't just move a PR's head — GitHub also re-points the
prior review's `.commit_id` at the **new** head. `tend-review`'s
pre-flight guard compares that field against `HEAD_SHA` to decide
whether the current commit has already been reviewed, so after a rewrite
it reads `LAST_REVIEW_SHA == HEAD_SHA`, exits silently, and leaves a
stale APPROVE standing as the active verdict on code the bot never read.
## Observed
[`PRQL/prql#6158`](PRQL/prql#6158) (dependabot,
`js-yaml` bump). `prql-bot` submitted an empty-body APPROVE at
06:09:36Z; the head at that moment was `abb3853a` — confirmed by the
`tend-mention` run the review itself triggered six seconds later, which
carries `headSha=abb3853a`. Dependabot then rebased at 07:40:18Z
(`head_ref_force_pushed` → `cc020720`), which re-triggered
[`tend-review`
31158576591](https://github.com/PRQL/prql/actions/runs/31158576591). The
agent ran the full 1 m 47 s and posted nothing.
The reviews endpoint now reports that 06:09:36Z review against a commit
created at 07:40:16Z:
```
{"id":4880377370,"state":"APPROVED","submitted_at":"2026-08-07T06:09:36Z",
"commit_id":"cc0207205f99c5481b8404c805a16a43c91fb3af","body":""}
```
The session log shows the guard firing on exactly that, and the
reasoning is correct given what it was told to read:
> The current HEAD has already been reviewed and approved. There are no
conversation comments, no unanswered questions directed at the bot, and
no unresolved bot review threads to resolve. The triggering event was
`synchronize`, not `ready_for_review`, so no exception applies. Exiting
silently without posting — the existing approval stands as the active
verdict.
## Control
An ordinary push leaves the old anchor intact, so `.commit_id` alone
cannot distinguish the two cases. On
[`PRQL/prql#6159`](PRQL/prql#6159), a review
submitted at 06:58:45Z still reports `commit_id=779b096d` after
`177c1997` landed on top — the guard works there, which is why this has
stayed invisible.
## Fix
Probe the timeline for a `head_ref_force_pushed` newer than the last
substantive bot review. Non-zero ⇒ the reviewed commit was rewritten
away, so ignore `LAST_REVIEW_SHA` and review the head in full. The
incremental path has to be skipped too: after a rewrite
`LAST_REVIEW_SHA` names the current head, so `LAST_REVIEW_SHA..HEAD_SHA`
is empty and every trivial-skip heuristic keyed on it under-reports the
change.
The existing `LAST_REVIEW_SHA` extraction is refactored to keep the
whole review record rather than just `.commit_id`, so `submitted_at`
comes from the same substantive-filtered pick — no second query, no risk
of the two fields resolving to different reviews.
Verified live against three shapes: `#6158` (force-pushed after
approval) → 1; `#6159` (ordinary push) → 0; `#6161` (no prior bot
review) → empty anchor, 0.
## Gates
- **Evidence level**: High, **structural** — no decision point. Every
force-push after a bot review re-points the anchor and defeats the
comparison identically.
- **Occurrences**: 2 for the failure class. This one, plus
[#828](#828) — the same
`LAST_REVIEW_SHA == HEAD_SHA` guard skipping a real commit because the
anchor had moved to something the bot never reviewed (fixed for the
reply-container mechanism in
[#835](#835); the force-push
mechanism is untouched by that fix).
- **Magnitude**: targeted fix — one probe plus one condition, no new
section. Normal bar.
- Wrong-outcome shape, beyond the skipped work: the review record reads
"approved `cc020720`" for a commit the bot never fetched, and the
sequence generalizes to approve-then-rewrite.
Evidence log: https://gist.github.com/192514ea2c36586f9b7f842a482d62ab
---------
Co-authored-by: tend-agent <270458913+tend-agent@users.noreply.github.com>
max-sixty pushed a commit to max-sixty/tend that referenced this pull request Aug 12, 2026
…cy PR (#890)
`weekly`'s dependency-PR step skips approving when `LAST_APPROVAL_SHA ==
HEAD_SHA`. A force-push doesn't just move the head — GitHub re-points
the prior review's commit anchor at the **new** head, so after a rebase
that comparison reads true for a commit the bot never read. The PR is
left carrying an `APPROVED` it never earned, and the one step that would
have re-checked it declines to run.
Dependency PRs are the population tend rewrites on purpose: `nightly`
posts `@dependabot recreate` and ticks renovate's `rebase-check` on
conflicted bot PRs, both of which force-push.
## Observed
[`PRQL/prql#6158`](PRQL/prql#6158) (dependabot,
`js-yaml` bump). `prql-bot` approved at 06:09:36Z; dependabot rebased at
07:40:18Z. Running the current snippet against it now:
```
HEAD_SHA=cc0207205f99c5481b8404c805a16a43c91fb3af
LAST_APPROVAL_SHA=cc0207205f99c5481b8404c805a16a43c91fb3af
-> "Already approved on this commit; skipping."
```
`cc020720` was created 90 minutes after that approval.
## Fix
Take the newest `head_ref_force_pushed` off the timeline and drop
approvals older than it, mirroring the probe
[#884](#884) adds to `review`'s
three anchor sites. Switching from `gh pr view --json reviews` to the
REST endpoint is what makes the filter expressible: `submitted_at` isn't
in the GraphQL projection, and `gh api --jq` takes no `--arg`, so the
comparison pipes to `jq`. Note the field rename that comes with it —
REST carries `.commit_id`, not `.commit.oid`.
The equality test also gains an `-n` guard: with no surviving approval
both sides can now be empty, and `[ "" = "" ]` would skip.
Fixing the approve path alone would leave the stale `APPROVED` standing
on the two paths that *don't* reach it — step 2's "CI is failing,
comment and skip" and "major version bump, comment and skip". Both are
reachable precisely because a rebase changed something, so a
rebased-into-red dependency PR would get a failure comment while still
reading as bot-approved. A new item 6 dismisses any approval older than
the newest rewrite on those paths, using the same
`reviews/$REVIEW_ID/dismissals` call #884 gives `review`. It's
idempotent — a dismissed review reports `DISMISSED`, so the filter stops
matching it.
## Verified live
| PR | shape | before | after |
|---|---|---|---|
| [`#6158`](PRQL/prql#6158) | approved, then
force-pushed | skip | **proceed** |
| [`#6157`](PRQL/prql#6157) | approved, no
rewrite | skip | skip |
| [`#6156`](PRQL/prql#6156) | approved, no
rewrite | skip | skip |
The two controls confirm the redundant-approval suppression the guard
exists for is intact; only the rewritten case flips.
The dismissal filter resolves against the same three: `#6158` selects
review `4880377370` (`prql-bot`, `APPROVED`, `submitted_at` 06:09:36Z,
`commit_id` `cc020720` — the post-rewrite head, re-anchored), and both
controls select nothing.
Flagged in the [review of
#884](#884 (review))
as a separate concern from that diff, which patches `review` only.
---------
Co-authored-by: tend-agent <270458913+tend-agent@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesjavascriptPull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@prql-bot@max-sixty
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js by dependabot[bot] · Pull Request #6158 · PRQL/prql · GitHub
Skip to content

chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js - #6158

Merged
max-sixty merged 1 commit into
mainfrom
dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1
Aug 7, 2026
Merged

chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js#6158
max-sixty merged 1 commit into
mainfrom
dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 7, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 4.2.0 to 4.3.1.

Changelog

Sourced from js-yaml's changelog.

4.3.1 - 2026-07-31

Security

  • [backport] Remove quadratic complexity from !!omap duplicate key detection.

4.3.0 - 2026-06-27

Added

  • [backport] Added maxTotalMergeKeys (10000) loader option to limit the total number of keys processed by YAML merge (<<) across one load() / loadAll() call.

Fixed

  • Restore umd builds back to es5.

Removed

  • [backport] maxMergeSeqLength replaced with maxTotalMergeKeys for limiting YAML merge processing.
Commits
  • 86e91b8 4.3.1 released
  • c3cc4b0 Backport quadratic complexity fix for !!omap
  • 33d05b5 4.3.0 released
  • 663bfab Drop demo publish, to not override new v5 one.
  • 1cb8c7b Add v4-legacy tag for publish
  • 02f27af Restore umd builds back to es5
  • 8be84ed Fix es5 compatibility
  • 59423c6 Replace maxMergeSeqLength option with maxTotalMergeKeys (more robust). Ba...
  • 6842ef6 doc polish
  • See full diff in compare view

@dependabotdependabotBot added dependencies javascript Pull requests that update Javascript code labels Aug 7, 2026
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.2.0 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.2.0...4.3.1)
---
updated-dependencies:
- dependency-name: js-yaml
dependency-version: 4.3.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1 branch from abb3853 to cc02072CompareAugust 7, 2026 07:40
@max-sixty
max-sixty merged commit 6a41c1e into mainAug 7, 2026
37 checks passed
@max-sixty
max-sixty deleted the dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1 branch August 7, 2026 23:08
max-sixty pushed a commit to max-sixty/tend that referenced this pull request Aug 12, 2026
…anchored review SHA (#884)
A force-push doesn't just move a PR's head — GitHub also re-points the
prior review's `.commit_id` at the **new** head. `tend-review`'s
pre-flight guard compares that field against `HEAD_SHA` to decide
whether the current commit has already been reviewed, so after a rewrite
it reads `LAST_REVIEW_SHA == HEAD_SHA`, exits silently, and leaves a
stale APPROVE standing as the active verdict on code the bot never read.
## Observed
[`PRQL/prql#6158`](PRQL/prql#6158) (dependabot,
`js-yaml` bump). `prql-bot` submitted an empty-body APPROVE at
06:09:36Z; the head at that moment was `abb3853a` — confirmed by the
`tend-mention` run the review itself triggered six seconds later, which
carries `headSha=abb3853a`. Dependabot then rebased at 07:40:18Z
(`head_ref_force_pushed` → `cc020720`), which re-triggered
[`tend-review`
31158576591](https://github.com/PRQL/prql/actions/runs/31158576591). The
agent ran the full 1 m 47 s and posted nothing.
The reviews endpoint now reports that 06:09:36Z review against a commit
created at 07:40:16Z:
```
{"id":4880377370,"state":"APPROVED","submitted_at":"2026-08-07T06:09:36Z",
"commit_id":"cc0207205f99c5481b8404c805a16a43c91fb3af","body":""}
```
The session log shows the guard firing on exactly that, and the
reasoning is correct given what it was told to read:
> The current HEAD has already been reviewed and approved. There are no
conversation comments, no unanswered questions directed at the bot, and
no unresolved bot review threads to resolve. The triggering event was
`synchronize`, not `ready_for_review`, so no exception applies. Exiting
silently without posting — the existing approval stands as the active
verdict.
## Control
An ordinary push leaves the old anchor intact, so `.commit_id` alone
cannot distinguish the two cases. On
[`PRQL/prql#6159`](PRQL/prql#6159), a review
submitted at 06:58:45Z still reports `commit_id=779b096d` after
`177c1997` landed on top — the guard works there, which is why this has
stayed invisible.
## Fix
Probe the timeline for a `head_ref_force_pushed` newer than the last
substantive bot review. Non-zero ⇒ the reviewed commit was rewritten
away, so ignore `LAST_REVIEW_SHA` and review the head in full. The
incremental path has to be skipped too: after a rewrite
`LAST_REVIEW_SHA` names the current head, so `LAST_REVIEW_SHA..HEAD_SHA`
is empty and every trivial-skip heuristic keyed on it under-reports the
change.
The existing `LAST_REVIEW_SHA` extraction is refactored to keep the
whole review record rather than just `.commit_id`, so `submitted_at`
comes from the same substantive-filtered pick — no second query, no risk
of the two fields resolving to different reviews.
Verified live against three shapes: `#6158` (force-pushed after
approval) → 1; `#6159` (ordinary push) → 0; `#6161` (no prior bot
review) → empty anchor, 0.
## Gates
- **Evidence level**: High, **structural** — no decision point. Every
force-push after a bot review re-points the anchor and defeats the
comparison identically.
- **Occurrences**: 2 for the failure class. This one, plus
[#828](#828) — the same
`LAST_REVIEW_SHA == HEAD_SHA` guard skipping a real commit because the
anchor had moved to something the bot never reviewed (fixed for the
reply-container mechanism in
[#835](#835); the force-push
mechanism is untouched by that fix).
- **Magnitude**: targeted fix — one probe plus one condition, no new
section. Normal bar.
- Wrong-outcome shape, beyond the skipped work: the review record reads
"approved `cc020720`" for a commit the bot never fetched, and the
sequence generalizes to approve-then-rewrite.
Evidence log: https://gist.github.com/192514ea2c36586f9b7f842a482d62ab
---------
Co-authored-by: tend-agent <270458913+tend-agent@users.noreply.github.com>
max-sixty pushed a commit to max-sixty/tend that referenced this pull request Aug 12, 2026
…cy PR (#890)
`weekly`'s dependency-PR step skips approving when `LAST_APPROVAL_SHA ==
HEAD_SHA`. A force-push doesn't just move the head — GitHub re-points
the prior review's commit anchor at the **new** head, so after a rebase
that comparison reads true for a commit the bot never read. The PR is
left carrying an `APPROVED` it never earned, and the one step that would
have re-checked it declines to run.
Dependency PRs are the population tend rewrites on purpose: `nightly`
posts `@dependabot recreate` and ticks renovate's `rebase-check` on
conflicted bot PRs, both of which force-push.
## Observed
[`PRQL/prql#6158`](PRQL/prql#6158) (dependabot,
`js-yaml` bump). `prql-bot` approved at 06:09:36Z; dependabot rebased at
07:40:18Z. Running the current snippet against it now:
```
HEAD_SHA=cc0207205f99c5481b8404c805a16a43c91fb3af
LAST_APPROVAL_SHA=cc0207205f99c5481b8404c805a16a43c91fb3af
-> "Already approved on this commit; skipping."
```
`cc020720` was created 90 minutes after that approval.
## Fix
Take the newest `head_ref_force_pushed` off the timeline and drop
approvals older than it, mirroring the probe
[#884](#884) adds to `review`'s
three anchor sites. Switching from `gh pr view --json reviews` to the
REST endpoint is what makes the filter expressible: `submitted_at` isn't
in the GraphQL projection, and `gh api --jq` takes no `--arg`, so the
comparison pipes to `jq`. Note the field rename that comes with it —
REST carries `.commit_id`, not `.commit.oid`.
The equality test also gains an `-n` guard: with no surviving approval
both sides can now be empty, and `[ "" = "" ]` would skip.
Fixing the approve path alone would leave the stale `APPROVED` standing
on the two paths that *don't* reach it — step 2's "CI is failing,
comment and skip" and "major version bump, comment and skip". Both are
reachable precisely because a rebase changed something, so a
rebased-into-red dependency PR would get a failure comment while still
reading as bot-approved. A new item 6 dismisses any approval older than
the newest rewrite on those paths, using the same
`reviews/$REVIEW_ID/dismissals` call #884 gives `review`. It's
idempotent — a dismissed review reports `DISMISSED`, so the filter stops
matching it.
## Verified live
| PR | shape | before | after |
|---|---|---|---|
| [`#6158`](PRQL/prql#6158) | approved, then
force-pushed | skip | **proceed** |
| [`#6157`](PRQL/prql#6157) | approved, no
rewrite | skip | skip |
| [`#6156`](PRQL/prql#6156) | approved, no
rewrite | skip | skip |
The two controls confirm the redundant-approval suppression the guard
exists for is intact; only the rewritten case flips.
The dismissal filter resolves against the same three: `#6158` selects
review `4880377370` (`prql-bot`, `APPROVED`, `submitted_at` 06:09:36Z,
`commit_id` `cc020720` — the post-rewrite head, re-anchored), and both
controls select nothing.
Flagged in the [review of
#884](#884 (review))
as a separate concern from that diff, which patches `review` only.
---------
Co-authored-by: tend-agent <270458913+tend-agent@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesjavascriptPull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@prql-bot@max-sixty
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js by dependabot[bot] · Pull Request #6158 · PRQL/prql · GitHub
Skip to content

chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js - #6158

Merged
max-sixty merged 1 commit into
mainfrom
dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1
Aug 7, 2026
Merged

chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js#6158
max-sixty merged 1 commit into
mainfrom
dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 7, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 4.2.0 to 4.3.1.

Changelog

Sourced from js-yaml's changelog.

4.3.1 - 2026-07-31

Security

  • [backport] Remove quadratic complexity from !!omap duplicate key detection.

4.3.0 - 2026-06-27

Added

  • [backport] Added maxTotalMergeKeys (10000) loader option to limit the total number of keys processed by YAML merge (<<) across one load() / loadAll() call.

Fixed

  • Restore umd builds back to es5.

Removed

  • [backport] maxMergeSeqLength replaced with maxTotalMergeKeys for limiting YAML merge processing.
Commits
  • 86e91b8 4.3.1 released
  • c3cc4b0 Backport quadratic complexity fix for !!omap
  • 33d05b5 4.3.0 released
  • 663bfab Drop demo publish, to not override new v5 one.
  • 1cb8c7b Add v4-legacy tag for publish
  • 02f27af Restore umd builds back to es5
  • 8be84ed Fix es5 compatibility
  • 59423c6 Replace maxMergeSeqLength option with maxTotalMergeKeys (more robust). Ba...
  • 6842ef6 doc polish
  • See full diff in compare view

@dependabotdependabotBot added dependencies javascript Pull requests that update Javascript code labels Aug 7, 2026
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.2.0 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.2.0...4.3.1)
---
updated-dependencies:
- dependency-name: js-yaml
dependency-version: 4.3.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1 branch from abb3853 to cc02072CompareAugust 7, 2026 07:40
@max-sixty
max-sixty merged commit 6a41c1e into mainAug 7, 2026
37 checks passed
@max-sixty
max-sixty deleted the dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1 branch August 7, 2026 23:08
max-sixty pushed a commit to max-sixty/tend that referenced this pull request Aug 12, 2026
…anchored review SHA (#884)
A force-push doesn't just move a PR's head — GitHub also re-points the
prior review's `.commit_id` at the **new** head. `tend-review`'s
pre-flight guard compares that field against `HEAD_SHA` to decide
whether the current commit has already been reviewed, so after a rewrite
it reads `LAST_REVIEW_SHA == HEAD_SHA`, exits silently, and leaves a
stale APPROVE standing as the active verdict on code the bot never read.
## Observed
[`PRQL/prql#6158`](PRQL/prql#6158) (dependabot,
`js-yaml` bump). `prql-bot` submitted an empty-body APPROVE at
06:09:36Z; the head at that moment was `abb3853a` — confirmed by the
`tend-mention` run the review itself triggered six seconds later, which
carries `headSha=abb3853a`. Dependabot then rebased at 07:40:18Z
(`head_ref_force_pushed` → `cc020720`), which re-triggered
[`tend-review`
31158576591](https://github.com/PRQL/prql/actions/runs/31158576591). The
agent ran the full 1 m 47 s and posted nothing.
The reviews endpoint now reports that 06:09:36Z review against a commit
created at 07:40:16Z:
```
{"id":4880377370,"state":"APPROVED","submitted_at":"2026-08-07T06:09:36Z",
"commit_id":"cc0207205f99c5481b8404c805a16a43c91fb3af","body":""}
```
The session log shows the guard firing on exactly that, and the
reasoning is correct given what it was told to read:
> The current HEAD has already been reviewed and approved. There are no
conversation comments, no unanswered questions directed at the bot, and
no unresolved bot review threads to resolve. The triggering event was
`synchronize`, not `ready_for_review`, so no exception applies. Exiting
silently without posting — the existing approval stands as the active
verdict.
## Control
An ordinary push leaves the old anchor intact, so `.commit_id` alone
cannot distinguish the two cases. On
[`PRQL/prql#6159`](PRQL/prql#6159), a review
submitted at 06:58:45Z still reports `commit_id=779b096d` after
`177c1997` landed on top — the guard works there, which is why this has
stayed invisible.
## Fix
Probe the timeline for a `head_ref_force_pushed` newer than the last
substantive bot review. Non-zero ⇒ the reviewed commit was rewritten
away, so ignore `LAST_REVIEW_SHA` and review the head in full. The
incremental path has to be skipped too: after a rewrite
`LAST_REVIEW_SHA` names the current head, so `LAST_REVIEW_SHA..HEAD_SHA`
is empty and every trivial-skip heuristic keyed on it under-reports the
change.
The existing `LAST_REVIEW_SHA` extraction is refactored to keep the
whole review record rather than just `.commit_id`, so `submitted_at`
comes from the same substantive-filtered pick — no second query, no risk
of the two fields resolving to different reviews.
Verified live against three shapes: `#6158` (force-pushed after
approval) → 1; `#6159` (ordinary push) → 0; `#6161` (no prior bot
review) → empty anchor, 0.
## Gates
- **Evidence level**: High, **structural** — no decision point. Every
force-push after a bot review re-points the anchor and defeats the
comparison identically.
- **Occurrences**: 2 for the failure class. This one, plus
[#828](#828) — the same
`LAST_REVIEW_SHA == HEAD_SHA` guard skipping a real commit because the
anchor had moved to something the bot never reviewed (fixed for the
reply-container mechanism in
[#835](#835); the force-push
mechanism is untouched by that fix).
- **Magnitude**: targeted fix — one probe plus one condition, no new
section. Normal bar.
- Wrong-outcome shape, beyond the skipped work: the review record reads
"approved `cc020720`" for a commit the bot never fetched, and the
sequence generalizes to approve-then-rewrite.
Evidence log: https://gist.github.com/192514ea2c36586f9b7f842a482d62ab
---------
Co-authored-by: tend-agent <270458913+tend-agent@users.noreply.github.com>
max-sixty pushed a commit to max-sixty/tend that referenced this pull request Aug 12, 2026
…cy PR (#890)
`weekly`'s dependency-PR step skips approving when `LAST_APPROVAL_SHA ==
HEAD_SHA`. A force-push doesn't just move the head — GitHub re-points
the prior review's commit anchor at the **new** head, so after a rebase
that comparison reads true for a commit the bot never read. The PR is
left carrying an `APPROVED` it never earned, and the one step that would
have re-checked it declines to run.
Dependency PRs are the population tend rewrites on purpose: `nightly`
posts `@dependabot recreate` and ticks renovate's `rebase-check` on
conflicted bot PRs, both of which force-push.
## Observed
[`PRQL/prql#6158`](PRQL/prql#6158) (dependabot,
`js-yaml` bump). `prql-bot` approved at 06:09:36Z; dependabot rebased at
07:40:18Z. Running the current snippet against it now:
```
HEAD_SHA=cc0207205f99c5481b8404c805a16a43c91fb3af
LAST_APPROVAL_SHA=cc0207205f99c5481b8404c805a16a43c91fb3af
-> "Already approved on this commit; skipping."
```
`cc020720` was created 90 minutes after that approval.
## Fix
Take the newest `head_ref_force_pushed` off the timeline and drop
approvals older than it, mirroring the probe
[#884](#884) adds to `review`'s
three anchor sites. Switching from `gh pr view --json reviews` to the
REST endpoint is what makes the filter expressible: `submitted_at` isn't
in the GraphQL projection, and `gh api --jq` takes no `--arg`, so the
comparison pipes to `jq`. Note the field rename that comes with it —
REST carries `.commit_id`, not `.commit.oid`.
The equality test also gains an `-n` guard: with no surviving approval
both sides can now be empty, and `[ "" = "" ]` would skip.
Fixing the approve path alone would leave the stale `APPROVED` standing
on the two paths that *don't* reach it — step 2's "CI is failing,
comment and skip" and "major version bump, comment and skip". Both are
reachable precisely because a rebase changed something, so a
rebased-into-red dependency PR would get a failure comment while still
reading as bot-approved. A new item 6 dismisses any approval older than
the newest rewrite on those paths, using the same
`reviews/$REVIEW_ID/dismissals` call #884 gives `review`. It's
idempotent — a dismissed review reports `DISMISSED`, so the filter stops
matching it.
## Verified live
| PR | shape | before | after |
|---|---|---|---|
| [`#6158`](PRQL/prql#6158) | approved, then
force-pushed | skip | **proceed** |
| [`#6157`](PRQL/prql#6157) | approved, no
rewrite | skip | skip |
| [`#6156`](PRQL/prql#6156) | approved, no
rewrite | skip | skip |
The two controls confirm the redundant-approval suppression the guard
exists for is intact; only the rewritten case flips.
The dismissal filter resolves against the same three: `#6158` selects
review `4880377370` (`prql-bot`, `APPROVED`, `submitted_at` 06:09:36Z,
`commit_id` `cc020720` — the post-rewrite head, re-anchored), and both
controls select nothing.
Flagged in the [review of
#884](#884 (review))
as a separate concern from that diff, which patches `review` only.
---------
Co-authored-by: tend-agent <270458913+tend-agent@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesjavascriptPull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@prql-bot@max-sixty
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js by dependabot[bot] · Pull Request #6158 · PRQL/prql · GitHub
Skip to content

chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js - #6158

Merged
max-sixty merged 1 commit into
mainfrom
dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1
Aug 7, 2026
Merged

chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js#6158
max-sixty merged 1 commit into
mainfrom
dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 7, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 4.2.0 to 4.3.1.

Changelog

Sourced from js-yaml's changelog.

4.3.1 - 2026-07-31

Security

  • [backport] Remove quadratic complexity from !!omap duplicate key detection.

4.3.0 - 2026-06-27

Added

  • [backport] Added maxTotalMergeKeys (10000) loader option to limit the total number of keys processed by YAML merge (<<) across one load() / loadAll() call.

Fixed

  • Restore umd builds back to es5.

Removed

  • [backport] maxMergeSeqLength replaced with maxTotalMergeKeys for limiting YAML merge processing.
Commits
  • 86e91b8 4.3.1 released
  • c3cc4b0 Backport quadratic complexity fix for !!omap
  • 33d05b5 4.3.0 released
  • 663bfab Drop demo publish, to not override new v5 one.
  • 1cb8c7b Add v4-legacy tag for publish
  • 02f27af Restore umd builds back to es5
  • 8be84ed Fix es5 compatibility
  • 59423c6 Replace maxMergeSeqLength option with maxTotalMergeKeys (more robust). Ba...
  • 6842ef6 doc polish
  • See full diff in compare view

@dependabotdependabotBot added dependencies javascript Pull requests that update Javascript code labels Aug 7, 2026
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.2.0 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.2.0...4.3.1)
---
updated-dependencies:
- dependency-name: js-yaml
dependency-version: 4.3.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1 branch from abb3853 to cc02072CompareAugust 7, 2026 07:40
@max-sixty
max-sixty merged commit 6a41c1e into mainAug 7, 2026
37 checks passed
@max-sixty
max-sixty deleted the dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1 branch August 7, 2026 23:08
max-sixty pushed a commit to max-sixty/tend that referenced this pull request Aug 12, 2026
…anchored review SHA (#884)
A force-push doesn't just move a PR's head — GitHub also re-points the
prior review's `.commit_id` at the **new** head. `tend-review`'s
pre-flight guard compares that field against `HEAD_SHA` to decide
whether the current commit has already been reviewed, so after a rewrite
it reads `LAST_REVIEW_SHA == HEAD_SHA`, exits silently, and leaves a
stale APPROVE standing as the active verdict on code the bot never read.
## Observed
[`PRQL/prql#6158`](PRQL/prql#6158) (dependabot,
`js-yaml` bump). `prql-bot` submitted an empty-body APPROVE at
06:09:36Z; the head at that moment was `abb3853a` — confirmed by the
`tend-mention` run the review itself triggered six seconds later, which
carries `headSha=abb3853a`. Dependabot then rebased at 07:40:18Z
(`head_ref_force_pushed` → `cc020720`), which re-triggered
[`tend-review`
31158576591](https://github.com/PRQL/prql/actions/runs/31158576591). The
agent ran the full 1 m 47 s and posted nothing.
The reviews endpoint now reports that 06:09:36Z review against a commit
created at 07:40:16Z:
```
{"id":4880377370,"state":"APPROVED","submitted_at":"2026-08-07T06:09:36Z",
"commit_id":"cc0207205f99c5481b8404c805a16a43c91fb3af","body":""}
```
The session log shows the guard firing on exactly that, and the
reasoning is correct given what it was told to read:
> The current HEAD has already been reviewed and approved. There are no
conversation comments, no unanswered questions directed at the bot, and
no unresolved bot review threads to resolve. The triggering event was
`synchronize`, not `ready_for_review`, so no exception applies. Exiting
silently without posting — the existing approval stands as the active
verdict.
## Control
An ordinary push leaves the old anchor intact, so `.commit_id` alone
cannot distinguish the two cases. On
[`PRQL/prql#6159`](PRQL/prql#6159), a review
submitted at 06:58:45Z still reports `commit_id=779b096d` after
`177c1997` landed on top — the guard works there, which is why this has
stayed invisible.
## Fix
Probe the timeline for a `head_ref_force_pushed` newer than the last
substantive bot review. Non-zero ⇒ the reviewed commit was rewritten
away, so ignore `LAST_REVIEW_SHA` and review the head in full. The
incremental path has to be skipped too: after a rewrite
`LAST_REVIEW_SHA` names the current head, so `LAST_REVIEW_SHA..HEAD_SHA`
is empty and every trivial-skip heuristic keyed on it under-reports the
change.
The existing `LAST_REVIEW_SHA` extraction is refactored to keep the
whole review record rather than just `.commit_id`, so `submitted_at`
comes from the same substantive-filtered pick — no second query, no risk
of the two fields resolving to different reviews.
Verified live against three shapes: `#6158` (force-pushed after
approval) → 1; `#6159` (ordinary push) → 0; `#6161` (no prior bot
review) → empty anchor, 0.
## Gates
- **Evidence level**: High, **structural** — no decision point. Every
force-push after a bot review re-points the anchor and defeats the
comparison identically.
- **Occurrences**: 2 for the failure class. This one, plus
[#828](#828) — the same
`LAST_REVIEW_SHA == HEAD_SHA` guard skipping a real commit because the
anchor had moved to something the bot never reviewed (fixed for the
reply-container mechanism in
[#835](#835); the force-push
mechanism is untouched by that fix).
- **Magnitude**: targeted fix — one probe plus one condition, no new
section. Normal bar.
- Wrong-outcome shape, beyond the skipped work: the review record reads
"approved `cc020720`" for a commit the bot never fetched, and the
sequence generalizes to approve-then-rewrite.
Evidence log: https://gist.github.com/192514ea2c36586f9b7f842a482d62ab
---------
Co-authored-by: tend-agent <270458913+tend-agent@users.noreply.github.com>
max-sixty pushed a commit to max-sixty/tend that referenced this pull request Aug 12, 2026
…cy PR (#890)
`weekly`'s dependency-PR step skips approving when `LAST_APPROVAL_SHA ==
HEAD_SHA`. A force-push doesn't just move the head — GitHub re-points
the prior review's commit anchor at the **new** head, so after a rebase
that comparison reads true for a commit the bot never read. The PR is
left carrying an `APPROVED` it never earned, and the one step that would
have re-checked it declines to run.
Dependency PRs are the population tend rewrites on purpose: `nightly`
posts `@dependabot recreate` and ticks renovate's `rebase-check` on
conflicted bot PRs, both of which force-push.
## Observed
[`PRQL/prql#6158`](PRQL/prql#6158) (dependabot,
`js-yaml` bump). `prql-bot` approved at 06:09:36Z; dependabot rebased at
07:40:18Z. Running the current snippet against it now:
```
HEAD_SHA=cc0207205f99c5481b8404c805a16a43c91fb3af
LAST_APPROVAL_SHA=cc0207205f99c5481b8404c805a16a43c91fb3af
-> "Already approved on this commit; skipping."
```
`cc020720` was created 90 minutes after that approval.
## Fix
Take the newest `head_ref_force_pushed` off the timeline and drop
approvals older than it, mirroring the probe
[#884](#884) adds to `review`'s
three anchor sites. Switching from `gh pr view --json reviews` to the
REST endpoint is what makes the filter expressible: `submitted_at` isn't
in the GraphQL projection, and `gh api --jq` takes no `--arg`, so the
comparison pipes to `jq`. Note the field rename that comes with it —
REST carries `.commit_id`, not `.commit.oid`.
The equality test also gains an `-n` guard: with no surviving approval
both sides can now be empty, and `[ "" = "" ]` would skip.
Fixing the approve path alone would leave the stale `APPROVED` standing
on the two paths that *don't* reach it — step 2's "CI is failing,
comment and skip" and "major version bump, comment and skip". Both are
reachable precisely because a rebase changed something, so a
rebased-into-red dependency PR would get a failure comment while still
reading as bot-approved. A new item 6 dismisses any approval older than
the newest rewrite on those paths, using the same
`reviews/$REVIEW_ID/dismissals` call #884 gives `review`. It's
idempotent — a dismissed review reports `DISMISSED`, so the filter stops
matching it.
## Verified live
| PR | shape | before | after |
|---|---|---|---|
| [`#6158`](PRQL/prql#6158) | approved, then
force-pushed | skip | **proceed** |
| [`#6157`](PRQL/prql#6157) | approved, no
rewrite | skip | skip |
| [`#6156`](PRQL/prql#6156) | approved, no
rewrite | skip | skip |
The two controls confirm the redundant-approval suppression the guard
exists for is intact; only the rewritten case flips.
The dismissal filter resolves against the same three: `#6158` selects
review `4880377370` (`prql-bot`, `APPROVED`, `submitted_at` 06:09:36Z,
`commit_id` `cc020720` — the post-rewrite head, re-anchored), and both
controls select nothing.
Flagged in the [review of
#884](#884 (review))
as a separate concern from that diff, which patches `review` only.
---------
Co-authored-by: tend-agent <270458913+tend-agent@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesjavascriptPull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@prql-bot@max-sixty
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js by dependabot[bot] · Pull Request #6158 · PRQL/prql · GitHub
Skip to content

chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js - #6158

Merged
max-sixty merged 1 commit into
mainfrom
dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1
Aug 7, 2026
Merged

chore: bump js-yaml from 4.2.0 to 4.3.1 in /prqlc/bindings/js#6158
max-sixty merged 1 commit into
mainfrom
dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 7, 2026

Copy link
Copy Markdown
Contributor

Bumps js-yaml from 4.2.0 to 4.3.1.

Changelog

Sourced from js-yaml's changelog.

4.3.1 - 2026-07-31

Security

  • [backport] Remove quadratic complexity from !!omap duplicate key detection.

4.3.0 - 2026-06-27

Added

  • [backport] Added maxTotalMergeKeys (10000) loader option to limit the total number of keys processed by YAML merge (<<) across one load() / loadAll() call.

Fixed

  • Restore umd builds back to es5.

Removed

  • [backport] maxMergeSeqLength replaced with maxTotalMergeKeys for limiting YAML merge processing.
Commits
  • 86e91b8 4.3.1 released
  • c3cc4b0 Backport quadratic complexity fix for !!omap
  • 33d05b5 4.3.0 released
  • 663bfab Drop demo publish, to not override new v5 one.
  • 1cb8c7b Add v4-legacy tag for publish
  • 02f27af Restore umd builds back to es5
  • 8be84ed Fix es5 compatibility
  • 59423c6 Replace maxMergeSeqLength option with maxTotalMergeKeys (more robust). Ba...
  • 6842ef6 doc polish
  • See full diff in compare view

@dependabotdependabotBot added dependencies javascript Pull requests that update Javascript code labels Aug 7, 2026
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.2.0 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.2.0...4.3.1)
---
updated-dependencies:
- dependency-name: js-yaml
dependency-version: 4.3.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1 branch from abb3853 to cc02072CompareAugust 7, 2026 07:40
@max-sixty
max-sixty merged commit 6a41c1e into mainAug 7, 2026
37 checks passed
@max-sixty
max-sixty deleted the dependabot/npm_and_yarn/prqlc/bindings/js/js-yaml-4.3.1 branch August 7, 2026 23:08
max-sixty pushed a commit to max-sixty/tend that referenced this pull request Aug 12, 2026
…anchored review SHA (#884)
A force-push doesn't just move a PR's head — GitHub also re-points the
prior review's `.commit_id` at the **new** head. `tend-review`'s
pre-flight guard compares that field against `HEAD_SHA` to decide
whether the current commit has already been reviewed, so after a rewrite
it reads `LAST_REVIEW_SHA == HEAD_SHA`, exits silently, and leaves a
stale APPROVE standing as the active verdict on code the bot never read.
## Observed
[`PRQL/prql#6158`](PRQL/prql#6158) (dependabot,
`js-yaml` bump). `prql-bot` submitted an empty-body APPROVE at
06:09:36Z; the head at that moment was `abb3853a` — confirmed by the
`tend-mention` run the review itself triggered six seconds later, which
carries `headSha=abb3853a`. Dependabot then rebased at 07:40:18Z
(`head_ref_force_pushed` → `cc020720`), which re-triggered
[`tend-review`
31158576591](https://github.com/PRQL/prql/actions/runs/31158576591). The
agent ran the full 1 m 47 s and posted nothing.
The reviews endpoint now reports that 06:09:36Z review against a commit
created at 07:40:16Z:
```
{"id":4880377370,"state":"APPROVED","submitted_at":"2026-08-07T06:09:36Z",
"commit_id":"cc0207205f99c5481b8404c805a16a43c91fb3af","body":""}
```
The session log shows the guard firing on exactly that, and the
reasoning is correct given what it was told to read:
> The current HEAD has already been reviewed and approved. There are no
conversation comments, no unanswered questions directed at the bot, and
no unresolved bot review threads to resolve. The triggering event was
`synchronize`, not `ready_for_review`, so no exception applies. Exiting
silently without posting — the existing approval stands as the active
verdict.
## Control
An ordinary push leaves the old anchor intact, so `.commit_id` alone
cannot distinguish the two cases. On
[`PRQL/prql#6159`](PRQL/prql#6159), a review
submitted at 06:58:45Z still reports `commit_id=779b096d` after
`177c1997` landed on top — the guard works there, which is why this has
stayed invisible.
## Fix
Probe the timeline for a `head_ref_force_pushed` newer than the last
substantive bot review. Non-zero ⇒ the reviewed commit was rewritten
away, so ignore `LAST_REVIEW_SHA` and review the head in full. The
incremental path has to be skipped too: after a rewrite
`LAST_REVIEW_SHA` names the current head, so `LAST_REVIEW_SHA..HEAD_SHA`
is empty and every trivial-skip heuristic keyed on it under-reports the
change.
The existing `LAST_REVIEW_SHA` extraction is refactored to keep the
whole review record rather than just `.commit_id`, so `submitted_at`
comes from the same substantive-filtered pick — no second query, no risk
of the two fields resolving to different reviews.
Verified live against three shapes: `#6158` (force-pushed after
approval) → 1; `#6159` (ordinary push) → 0; `#6161` (no prior bot
review) → empty anchor, 0.
## Gates
- **Evidence level**: High, **structural** — no decision point. Every
force-push after a bot review re-points the anchor and defeats the
comparison identically.
- **Occurrences**: 2 for the failure class. This one, plus
[#828](#828) — the same
`LAST_REVIEW_SHA == HEAD_SHA` guard skipping a real commit because the
anchor had moved to something the bot never reviewed (fixed for the
reply-container mechanism in
[#835](#835); the force-push
mechanism is untouched by that fix).
- **Magnitude**: targeted fix — one probe plus one condition, no new
section. Normal bar.
- Wrong-outcome shape, beyond the skipped work: the review record reads
"approved `cc020720`" for a commit the bot never fetched, and the
sequence generalizes to approve-then-rewrite.
Evidence log: https://gist.github.com/192514ea2c36586f9b7f842a482d62ab
---------
Co-authored-by: tend-agent <270458913+tend-agent@users.noreply.github.com>
max-sixty pushed a commit to max-sixty/tend that referenced this pull request Aug 12, 2026
…cy PR (#890)
`weekly`'s dependency-PR step skips approving when `LAST_APPROVAL_SHA ==
HEAD_SHA`. A force-push doesn't just move the head — GitHub re-points
the prior review's commit anchor at the **new** head, so after a rebase
that comparison reads true for a commit the bot never read. The PR is
left carrying an `APPROVED` it never earned, and the one step that would
have re-checked it declines to run.
Dependency PRs are the population tend rewrites on purpose: `nightly`
posts `@dependabot recreate` and ticks renovate's `rebase-check` on
conflicted bot PRs, both of which force-push.
## Observed
[`PRQL/prql#6158`](PRQL/prql#6158) (dependabot,
`js-yaml` bump). `prql-bot` approved at 06:09:36Z; dependabot rebased at
07:40:18Z. Running the current snippet against it now:
```
HEAD_SHA=cc0207205f99c5481b8404c805a16a43c91fb3af
LAST_APPROVAL_SHA=cc0207205f99c5481b8404c805a16a43c91fb3af
-> "Already approved on this commit; skipping."
```
`cc020720` was created 90 minutes after that approval.
## Fix
Take the newest `head_ref_force_pushed` off the timeline and drop
approvals older than it, mirroring the probe
[#884](#884) adds to `review`'s
three anchor sites. Switching from `gh pr view --json reviews` to the
REST endpoint is what makes the filter expressible: `submitted_at` isn't
in the GraphQL projection, and `gh api --jq` takes no `--arg`, so the
comparison pipes to `jq`. Note the field rename that comes with it —
REST carries `.commit_id`, not `.commit.oid`.
The equality test also gains an `-n` guard: with no surviving approval
both sides can now be empty, and `[ "" = "" ]` would skip.
Fixing the approve path alone would leave the stale `APPROVED` standing
on the two paths that *don't* reach it — step 2's "CI is failing,
comment and skip" and "major version bump, comment and skip". Both are
reachable precisely because a rebase changed something, so a
rebased-into-red dependency PR would get a failure comment while still
reading as bot-approved. A new item 6 dismisses any approval older than
the newest rewrite on those paths, using the same
`reviews/$REVIEW_ID/dismissals` call #884 gives `review`. It's
idempotent — a dismissed review reports `DISMISSED`, so the filter stops
matching it.
## Verified live
| PR | shape | before | after |
|---|---|---|---|
| [`#6158`](PRQL/prql#6158) | approved, then
force-pushed | skip | **proceed** |
| [`#6157`](PRQL/prql#6157) | approved, no
rewrite | skip | skip |
| [`#6156`](PRQL/prql#6156) | approved, no
rewrite | skip | skip |
The two controls confirm the redundant-approval suppression the guard
exists for is intact; only the rewritten case flips.
The dismissal filter resolves against the same three: `#6158` selects
review `4880377370` (`prql-bot`, `APPROVED`, `submitted_at` 06:09:36Z,
`commit_id` `cc020720` — the post-rewrite head, re-anchored), and both
controls select nothing.
Flagged in the [review of
#884](#884 (review))
as a separate concern from that diff, which patches `review` only.
---------
Co-authored-by: tend-agent <270458913+tend-agent@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesjavascriptPull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@prql-bot@max-sixty