chore(deps-dev): bump @unbrained/pm-cli from 2026.8.28 to 2026.8.31 - #72

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.31
Open

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.28 to 2026.8.31#72
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.31

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 4, 2026

Copy link
Copy Markdown
Contributor

Bumps @unbrained/pm-cli from 2026.8.28 to 2026.8.31.

Release notes

Sourced from @​unbrained/pm-cli's releases.

v2026.8.31

@​unbrained/pm-cli 2026.8.31

Source range: v2026.8.30...v2026.8.31

Changelog

Added

  • Workspace position read: one bounded answer to where this workspace stands in the branch-and-merge workflow and what to run next, replacing a protocol the agent must remember (pm-bq0ii8)

Fixed

  • Custom statuses registered without a lifecycle role are silently orphaned from every work-selection surface (pm-0mhspz)
  • GH-1158: Windows Node 24 nightly receipt fixture derives a root-relative expectation from a drive-qualified path (pm-46hpx8)
  • GH-1154: linked-test sandbox guard is command-shape inconsistent and undocumented (pm-s8cth5)
  • The local preflight token-budget gate is red on a workstation and green in hosted CI for the same commit again, because the earlier remediation closed the one ambient channel that had bitten instead of closing the fixture's environment (pm-4o7tlx)
  • The bounded legacy MCP compatibility set stops one revision short of the spec's own legacy boundary, so every current host is refused at initialize and the dual-era guarantee is unmet (pm-edywqn)

Deprecated

  • The project's own agent-facing documentation and skills instruct deprecated command spellings, so the alias-usage signal that decides when a spelling can be retired is manufactured by the instructions rather than observed from callers (pm-q2n4vd)

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.30

@​unbrained/pm-cli 2026.8.30

Source range: v2026.8.29...v2026.8.30

Changelog

Other

  • Adopt eslint-plugin-unicorn 74 with strict lint and packed-consumer proof (pm-6f66vu)

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.29

@​unbrained/pm-cli 2026.8.29

Source range: v2026.8.28...v2026.8.29

Changelog

Fixed

... (truncated)

Changelog

Sourced from @​unbrained/pm-cli's changelog.

2026.8.31 - 2026-08-31

Added

  • Workspace position read: one bounded answer to where this workspace stands in the branch-and-merge workflow and what to run next, replacing a protocol the agent must remember (pm-bq0ii8)

Fixed

  • Custom statuses registered without a lifecycle role are silently orphaned from every work-selection surface (pm-0mhspz)
  • GH-1158: Windows Node 24 nightly receipt fixture derives a root-relative expectation from a drive-qualified path (pm-46hpx8)
  • GH-1154: linked-test sandbox guard is command-shape inconsistent and undocumented (pm-s8cth5)
  • The local preflight token-budget gate is red on a workstation and green in hosted CI for the same commit again, because the earlier remediation closed the one ambient channel that had bitten instead of closing the fixture's environment (pm-4o7tlx)
  • The bounded legacy MCP compatibility set stops one revision short of the spec's own legacy boundary, so every current host is refused at initialize and the dual-era guarantee is unmet (pm-edywqn)

Security

  • Refresh compatible GitHub Actions and tsx tooling dependencies (pm-k47gdd)

Deprecated

  • The project's own agent-facing documentation and skills instruct deprecated command spellings, so the alias-usage signal that decides when a spelling can be retired is manufactured by the instructions rather than observed from callers (pm-q2n4vd)

2026.8.30 - 2026-08-30

Other

  • Adopt eslint-plugin-unicorn 74 with strict lint and packed-consumer proof (pm-6f66vu)

2026.8.29 - 2026-08-29

Fixed

  • GH-1144: hash-only merge receipts contradict report output and cannot reconcile truthfully (pm-z1z96w)
  • GH-1146/1147: external blockers remain stale and validation recommends deleting them (pm-yhle2e)
  • GH-1140: reject ambiguous bare comma tuples for linked file and test mutations (pm-nc94mk)
  • GH-1148: cached drift mismatch can falsely report tracker corruption (pm-sxg7wl)
  • GH-1138: linked test name filters can pass after executing zero tests (pm-ntnv4k)
  • GH-1136: npm 12 object-form npm pack receipts break registry package installs (pm-xrjy8o)
  • The annotation key=value grammar has three divergent comma behaviours, two of which silently corrupt the evidence text before it is made immutable (pm-hu92i3)
  • GH-1150: health remediation for pending merge receipts must perform the repair (pm-r0p3at)
  • GH-1134: required collection recovery omits truthful --clear-* intent (pm-t7wl00)
  • GH-1143: Claude session-file provenance resolver ignores real nested stream fields (pm-f60039)
  • GH-1137: linked docs writes silently persist nonexistent workspace paths (pm-hiqlkh)
  • Sentry release gate aborts valid API queries at a fixed 15-second deadline (pm-b9g2cs)

Other

  • Refresh @​sentry/node 10.72 with packed SDK and release proof (pm-mwhv33)
  • Refresh compatible 2026-08-29 dependency releases (pm-vwuidf)
  • Close the jscpd/CodeFactor sensitivity gap: minTokens 115 misses low-token table clones the CodeFactor bot still files (pm-xspd)
Commits
  • 49802e1 chore(release): cut 2026.8.31
  • a8c785a Merge pull request #1163 from unbraind/feat/workspace-position-lifecycle-context
  • 9a37f37 fix(sdk): fail closed on incomplete lifecycle evidence
  • f6c0011 fix(sdk): render workspace recovery cross-platform
  • db01807 fix(sdk): align workspace recovery and lifecycle context
  • bb16bd6 feat(sdk): add lifecycle-aware workspace readiness
  • 74aabd5 feat(sdk): unify execution trust, quality parity, and Windows receipts (#1160)
  • a64ef8e Decompose the handshake matrix, cover it, and derive the deprecated-spelling map
  • 381dbff Record the reviewed-arrival consequence of the direct-main push on the releas...
  • a326ad6 Restore MCP host interoperability and gate three denominator defects
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary by cubic

Updates @unbrained/pm-cli to 2026.8.31, which includes several bug fixes and a new workspace position feature. The lockfile also drops several transitive dependencies no longer needed by @sentry/node.

Written for commit 0e705a1. Summary will update on new commits.

Review in cubic

Bumps [@unbrained/pm-cli](https://github.com/unbraind/pm-cli) from 2026.8.28 to 2026.8.31.
- [Release notes](https://github.com/unbraind/pm-cli/releases)
- [Changelog](https://github.com/unbraind/pm-cli/blob/main/CHANGELOG.md)
- [Commits](unbraind/pm-cli@v2026.8.28...v2026.8.31)
---
updated-dependencies:
- dependency-name: "@unbrained/pm-cli"
dependency-version: 2026.8.31
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 4, 2026
@greptile-apps

Copy link
Copy Markdown

PR author is in the excluded authors list.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.28 to 2026.8.31 - #72

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.31
Open

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.28 to 2026.8.31#72
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.31

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 4, 2026

Copy link
Copy Markdown
Contributor

Bumps @unbrained/pm-cli from 2026.8.28 to 2026.8.31.

Release notes

Sourced from @​unbrained/pm-cli's releases.

v2026.8.31

@​unbrained/pm-cli 2026.8.31

Source range: v2026.8.30...v2026.8.31

Changelog

Added

  • Workspace position read: one bounded answer to where this workspace stands in the branch-and-merge workflow and what to run next, replacing a protocol the agent must remember (pm-bq0ii8)

Fixed

  • Custom statuses registered without a lifecycle role are silently orphaned from every work-selection surface (pm-0mhspz)
  • GH-1158: Windows Node 24 nightly receipt fixture derives a root-relative expectation from a drive-qualified path (pm-46hpx8)
  • GH-1154: linked-test sandbox guard is command-shape inconsistent and undocumented (pm-s8cth5)
  • The local preflight token-budget gate is red on a workstation and green in hosted CI for the same commit again, because the earlier remediation closed the one ambient channel that had bitten instead of closing the fixture's environment (pm-4o7tlx)
  • The bounded legacy MCP compatibility set stops one revision short of the spec's own legacy boundary, so every current host is refused at initialize and the dual-era guarantee is unmet (pm-edywqn)

Deprecated

  • The project's own agent-facing documentation and skills instruct deprecated command spellings, so the alias-usage signal that decides when a spelling can be retired is manufactured by the instructions rather than observed from callers (pm-q2n4vd)

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.30

@​unbrained/pm-cli 2026.8.30

Source range: v2026.8.29...v2026.8.30

Changelog

Other

  • Adopt eslint-plugin-unicorn 74 with strict lint and packed-consumer proof (pm-6f66vu)

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.29

@​unbrained/pm-cli 2026.8.29

Source range: v2026.8.28...v2026.8.29

Changelog

Fixed

... (truncated)

Changelog

Sourced from @​unbrained/pm-cli's changelog.

2026.8.31 - 2026-08-31

Added

  • Workspace position read: one bounded answer to where this workspace stands in the branch-and-merge workflow and what to run next, replacing a protocol the agent must remember (pm-bq0ii8)

Fixed

  • Custom statuses registered without a lifecycle role are silently orphaned from every work-selection surface (pm-0mhspz)
  • GH-1158: Windows Node 24 nightly receipt fixture derives a root-relative expectation from a drive-qualified path (pm-46hpx8)
  • GH-1154: linked-test sandbox guard is command-shape inconsistent and undocumented (pm-s8cth5)
  • The local preflight token-budget gate is red on a workstation and green in hosted CI for the same commit again, because the earlier remediation closed the one ambient channel that had bitten instead of closing the fixture's environment (pm-4o7tlx)
  • The bounded legacy MCP compatibility set stops one revision short of the spec's own legacy boundary, so every current host is refused at initialize and the dual-era guarantee is unmet (pm-edywqn)

Security

  • Refresh compatible GitHub Actions and tsx tooling dependencies (pm-k47gdd)

Deprecated

  • The project's own agent-facing documentation and skills instruct deprecated command spellings, so the alias-usage signal that decides when a spelling can be retired is manufactured by the instructions rather than observed from callers (pm-q2n4vd)

2026.8.30 - 2026-08-30

Other

  • Adopt eslint-plugin-unicorn 74 with strict lint and packed-consumer proof (pm-6f66vu)

2026.8.29 - 2026-08-29

Fixed

  • GH-1144: hash-only merge receipts contradict report output and cannot reconcile truthfully (pm-z1z96w)
  • GH-1146/1147: external blockers remain stale and validation recommends deleting them (pm-yhle2e)
  • GH-1140: reject ambiguous bare comma tuples for linked file and test mutations (pm-nc94mk)
  • GH-1148: cached drift mismatch can falsely report tracker corruption (pm-sxg7wl)
  • GH-1138: linked test name filters can pass after executing zero tests (pm-ntnv4k)
  • GH-1136: npm 12 object-form npm pack receipts break registry package installs (pm-xrjy8o)
  • The annotation key=value grammar has three divergent comma behaviours, two of which silently corrupt the evidence text before it is made immutable (pm-hu92i3)
  • GH-1150: health remediation for pending merge receipts must perform the repair (pm-r0p3at)
  • GH-1134: required collection recovery omits truthful --clear-* intent (pm-t7wl00)
  • GH-1143: Claude session-file provenance resolver ignores real nested stream fields (pm-f60039)
  • GH-1137: linked docs writes silently persist nonexistent workspace paths (pm-hiqlkh)
  • Sentry release gate aborts valid API queries at a fixed 15-second deadline (pm-b9g2cs)

Other

  • Refresh @​sentry/node 10.72 with packed SDK and release proof (pm-mwhv33)
  • Refresh compatible 2026-08-29 dependency releases (pm-vwuidf)
  • Close the jscpd/CodeFactor sensitivity gap: minTokens 115 misses low-token table clones the CodeFactor bot still files (pm-xspd)
Commits
  • 49802e1 chore(release): cut 2026.8.31
  • a8c785a Merge pull request #1163 from unbraind/feat/workspace-position-lifecycle-context
  • 9a37f37 fix(sdk): fail closed on incomplete lifecycle evidence
  • f6c0011 fix(sdk): render workspace recovery cross-platform
  • db01807 fix(sdk): align workspace recovery and lifecycle context
  • bb16bd6 feat(sdk): add lifecycle-aware workspace readiness
  • 74aabd5 feat(sdk): unify execution trust, quality parity, and Windows receipts (#1160)
  • a64ef8e Decompose the handshake matrix, cover it, and derive the deprecated-spelling map
  • 381dbff Record the reviewed-arrival consequence of the direct-main push on the releas...
  • a326ad6 Restore MCP host interoperability and gate three denominator defects
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary by cubic

Updates @unbrained/pm-cli to 2026.8.31, which includes several bug fixes and a new workspace position feature. The lockfile also drops several transitive dependencies no longer needed by @sentry/node.

Written for commit 0e705a1. Summary will update on new commits.

Review in cubic

Bumps [@unbrained/pm-cli](https://github.com/unbraind/pm-cli) from 2026.8.28 to 2026.8.31.
- [Release notes](https://github.com/unbraind/pm-cli/releases)
- [Changelog](https://github.com/unbraind/pm-cli/blob/main/CHANGELOG.md)
- [Commits](unbraind/pm-cli@v2026.8.28...v2026.8.31)
---
updated-dependencies:
- dependency-name: "@unbrained/pm-cli"
dependency-version: 2026.8.31
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 4, 2026
@greptile-apps

Copy link
Copy Markdown

PR author is in the excluded authors list.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.28 to 2026.8.31 - #72

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.31
Open

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.28 to 2026.8.31#72
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.31

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 4, 2026

Copy link
Copy Markdown
Contributor

Bumps @unbrained/pm-cli from 2026.8.28 to 2026.8.31.

Release notes

Sourced from @​unbrained/pm-cli's releases.

v2026.8.31

@​unbrained/pm-cli 2026.8.31

Source range: v2026.8.30...v2026.8.31

Changelog

Added

  • Workspace position read: one bounded answer to where this workspace stands in the branch-and-merge workflow and what to run next, replacing a protocol the agent must remember (pm-bq0ii8)

Fixed

  • Custom statuses registered without a lifecycle role are silently orphaned from every work-selection surface (pm-0mhspz)
  • GH-1158: Windows Node 24 nightly receipt fixture derives a root-relative expectation from a drive-qualified path (pm-46hpx8)
  • GH-1154: linked-test sandbox guard is command-shape inconsistent and undocumented (pm-s8cth5)
  • The local preflight token-budget gate is red on a workstation and green in hosted CI for the same commit again, because the earlier remediation closed the one ambient channel that had bitten instead of closing the fixture's environment (pm-4o7tlx)
  • The bounded legacy MCP compatibility set stops one revision short of the spec's own legacy boundary, so every current host is refused at initialize and the dual-era guarantee is unmet (pm-edywqn)

Deprecated

  • The project's own agent-facing documentation and skills instruct deprecated command spellings, so the alias-usage signal that decides when a spelling can be retired is manufactured by the instructions rather than observed from callers (pm-q2n4vd)

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.30

@​unbrained/pm-cli 2026.8.30

Source range: v2026.8.29...v2026.8.30

Changelog

Other

  • Adopt eslint-plugin-unicorn 74 with strict lint and packed-consumer proof (pm-6f66vu)

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.29

@​unbrained/pm-cli 2026.8.29

Source range: v2026.8.28...v2026.8.29

Changelog

Fixed

... (truncated)

Changelog

Sourced from @​unbrained/pm-cli's changelog.

2026.8.31 - 2026-08-31

Added

  • Workspace position read: one bounded answer to where this workspace stands in the branch-and-merge workflow and what to run next, replacing a protocol the agent must remember (pm-bq0ii8)

Fixed

  • Custom statuses registered without a lifecycle role are silently orphaned from every work-selection surface (pm-0mhspz)
  • GH-1158: Windows Node 24 nightly receipt fixture derives a root-relative expectation from a drive-qualified path (pm-46hpx8)
  • GH-1154: linked-test sandbox guard is command-shape inconsistent and undocumented (pm-s8cth5)
  • The local preflight token-budget gate is red on a workstation and green in hosted CI for the same commit again, because the earlier remediation closed the one ambient channel that had bitten instead of closing the fixture's environment (pm-4o7tlx)
  • The bounded legacy MCP compatibility set stops one revision short of the spec's own legacy boundary, so every current host is refused at initialize and the dual-era guarantee is unmet (pm-edywqn)

Security

  • Refresh compatible GitHub Actions and tsx tooling dependencies (pm-k47gdd)

Deprecated

  • The project's own agent-facing documentation and skills instruct deprecated command spellings, so the alias-usage signal that decides when a spelling can be retired is manufactured by the instructions rather than observed from callers (pm-q2n4vd)

2026.8.30 - 2026-08-30

Other

  • Adopt eslint-plugin-unicorn 74 with strict lint and packed-consumer proof (pm-6f66vu)

2026.8.29 - 2026-08-29

Fixed

  • GH-1144: hash-only merge receipts contradict report output and cannot reconcile truthfully (pm-z1z96w)
  • GH-1146/1147: external blockers remain stale and validation recommends deleting them (pm-yhle2e)
  • GH-1140: reject ambiguous bare comma tuples for linked file and test mutations (pm-nc94mk)
  • GH-1148: cached drift mismatch can falsely report tracker corruption (pm-sxg7wl)
  • GH-1138: linked test name filters can pass after executing zero tests (pm-ntnv4k)
  • GH-1136: npm 12 object-form npm pack receipts break registry package installs (pm-xrjy8o)
  • The annotation key=value grammar has three divergent comma behaviours, two of which silently corrupt the evidence text before it is made immutable (pm-hu92i3)
  • GH-1150: health remediation for pending merge receipts must perform the repair (pm-r0p3at)
  • GH-1134: required collection recovery omits truthful --clear-* intent (pm-t7wl00)
  • GH-1143: Claude session-file provenance resolver ignores real nested stream fields (pm-f60039)
  • GH-1137: linked docs writes silently persist nonexistent workspace paths (pm-hiqlkh)
  • Sentry release gate aborts valid API queries at a fixed 15-second deadline (pm-b9g2cs)

Other

  • Refresh @​sentry/node 10.72 with packed SDK and release proof (pm-mwhv33)
  • Refresh compatible 2026-08-29 dependency releases (pm-vwuidf)
  • Close the jscpd/CodeFactor sensitivity gap: minTokens 115 misses low-token table clones the CodeFactor bot still files (pm-xspd)
Commits
  • 49802e1 chore(release): cut 2026.8.31
  • a8c785a Merge pull request #1163 from unbraind/feat/workspace-position-lifecycle-context
  • 9a37f37 fix(sdk): fail closed on incomplete lifecycle evidence
  • f6c0011 fix(sdk): render workspace recovery cross-platform
  • db01807 fix(sdk): align workspace recovery and lifecycle context
  • bb16bd6 feat(sdk): add lifecycle-aware workspace readiness
  • 74aabd5 feat(sdk): unify execution trust, quality parity, and Windows receipts (#1160)
  • a64ef8e Decompose the handshake matrix, cover it, and derive the deprecated-spelling map
  • 381dbff Record the reviewed-arrival consequence of the direct-main push on the releas...
  • a326ad6 Restore MCP host interoperability and gate three denominator defects
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary by cubic

Updates @unbrained/pm-cli to 2026.8.31, which includes several bug fixes and a new workspace position feature. The lockfile also drops several transitive dependencies no longer needed by @sentry/node.

Written for commit 0e705a1. Summary will update on new commits.

Review in cubic

Bumps [@unbrained/pm-cli](https://github.com/unbraind/pm-cli) from 2026.8.28 to 2026.8.31.
- [Release notes](https://github.com/unbraind/pm-cli/releases)
- [Changelog](https://github.com/unbraind/pm-cli/blob/main/CHANGELOG.md)
- [Commits](unbraind/pm-cli@v2026.8.28...v2026.8.31)
---
updated-dependencies:
- dependency-name: "@unbrained/pm-cli"
dependency-version: 2026.8.31
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 4, 2026
@greptile-apps

Copy link
Copy Markdown

PR author is in the excluded authors list.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.28 to 2026.8.31 - #72

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.31
Open

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.28 to 2026.8.31#72
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.31

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 4, 2026

Copy link
Copy Markdown
Contributor

Bumps @unbrained/pm-cli from 2026.8.28 to 2026.8.31.

Release notes

Sourced from @​unbrained/pm-cli's releases.

v2026.8.31

@​unbrained/pm-cli 2026.8.31

Source range: v2026.8.30...v2026.8.31

Changelog

Added

  • Workspace position read: one bounded answer to where this workspace stands in the branch-and-merge workflow and what to run next, replacing a protocol the agent must remember (pm-bq0ii8)

Fixed

  • Custom statuses registered without a lifecycle role are silently orphaned from every work-selection surface (pm-0mhspz)
  • GH-1158: Windows Node 24 nightly receipt fixture derives a root-relative expectation from a drive-qualified path (pm-46hpx8)
  • GH-1154: linked-test sandbox guard is command-shape inconsistent and undocumented (pm-s8cth5)
  • The local preflight token-budget gate is red on a workstation and green in hosted CI for the same commit again, because the earlier remediation closed the one ambient channel that had bitten instead of closing the fixture's environment (pm-4o7tlx)
  • The bounded legacy MCP compatibility set stops one revision short of the spec's own legacy boundary, so every current host is refused at initialize and the dual-era guarantee is unmet (pm-edywqn)

Deprecated

  • The project's own agent-facing documentation and skills instruct deprecated command spellings, so the alias-usage signal that decides when a spelling can be retired is manufactured by the instructions rather than observed from callers (pm-q2n4vd)

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.30

@​unbrained/pm-cli 2026.8.30

Source range: v2026.8.29...v2026.8.30

Changelog

Other

  • Adopt eslint-plugin-unicorn 74 with strict lint and packed-consumer proof (pm-6f66vu)

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.29

@​unbrained/pm-cli 2026.8.29

Source range: v2026.8.28...v2026.8.29

Changelog

Fixed

... (truncated)

Changelog

Sourced from @​unbrained/pm-cli's changelog.

2026.8.31 - 2026-08-31

Added

  • Workspace position read: one bounded answer to where this workspace stands in the branch-and-merge workflow and what to run next, replacing a protocol the agent must remember (pm-bq0ii8)

Fixed

  • Custom statuses registered without a lifecycle role are silently orphaned from every work-selection surface (pm-0mhspz)
  • GH-1158: Windows Node 24 nightly receipt fixture derives a root-relative expectation from a drive-qualified path (pm-46hpx8)
  • GH-1154: linked-test sandbox guard is command-shape inconsistent and undocumented (pm-s8cth5)
  • The local preflight token-budget gate is red on a workstation and green in hosted CI for the same commit again, because the earlier remediation closed the one ambient channel that had bitten instead of closing the fixture's environment (pm-4o7tlx)
  • The bounded legacy MCP compatibility set stops one revision short of the spec's own legacy boundary, so every current host is refused at initialize and the dual-era guarantee is unmet (pm-edywqn)

Security

  • Refresh compatible GitHub Actions and tsx tooling dependencies (pm-k47gdd)

Deprecated

  • The project's own agent-facing documentation and skills instruct deprecated command spellings, so the alias-usage signal that decides when a spelling can be retired is manufactured by the instructions rather than observed from callers (pm-q2n4vd)

2026.8.30 - 2026-08-30

Other

  • Adopt eslint-plugin-unicorn 74 with strict lint and packed-consumer proof (pm-6f66vu)

2026.8.29 - 2026-08-29

Fixed

  • GH-1144: hash-only merge receipts contradict report output and cannot reconcile truthfully (pm-z1z96w)
  • GH-1146/1147: external blockers remain stale and validation recommends deleting them (pm-yhle2e)
  • GH-1140: reject ambiguous bare comma tuples for linked file and test mutations (pm-nc94mk)
  • GH-1148: cached drift mismatch can falsely report tracker corruption (pm-sxg7wl)
  • GH-1138: linked test name filters can pass after executing zero tests (pm-ntnv4k)
  • GH-1136: npm 12 object-form npm pack receipts break registry package installs (pm-xrjy8o)
  • The annotation key=value grammar has three divergent comma behaviours, two of which silently corrupt the evidence text before it is made immutable (pm-hu92i3)
  • GH-1150: health remediation for pending merge receipts must perform the repair (pm-r0p3at)
  • GH-1134: required collection recovery omits truthful --clear-* intent (pm-t7wl00)
  • GH-1143: Claude session-file provenance resolver ignores real nested stream fields (pm-f60039)
  • GH-1137: linked docs writes silently persist nonexistent workspace paths (pm-hiqlkh)
  • Sentry release gate aborts valid API queries at a fixed 15-second deadline (pm-b9g2cs)

Other

  • Refresh @​sentry/node 10.72 with packed SDK and release proof (pm-mwhv33)
  • Refresh compatible 2026-08-29 dependency releases (pm-vwuidf)
  • Close the jscpd/CodeFactor sensitivity gap: minTokens 115 misses low-token table clones the CodeFactor bot still files (pm-xspd)
Commits
  • 49802e1 chore(release): cut 2026.8.31
  • a8c785a Merge pull request #1163 from unbraind/feat/workspace-position-lifecycle-context
  • 9a37f37 fix(sdk): fail closed on incomplete lifecycle evidence
  • f6c0011 fix(sdk): render workspace recovery cross-platform
  • db01807 fix(sdk): align workspace recovery and lifecycle context
  • bb16bd6 feat(sdk): add lifecycle-aware workspace readiness
  • 74aabd5 feat(sdk): unify execution trust, quality parity, and Windows receipts (#1160)
  • a64ef8e Decompose the handshake matrix, cover it, and derive the deprecated-spelling map
  • 381dbff Record the reviewed-arrival consequence of the direct-main push on the releas...
  • a326ad6 Restore MCP host interoperability and gate three denominator defects
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary by cubic

Updates @unbrained/pm-cli to 2026.8.31, which includes several bug fixes and a new workspace position feature. The lockfile also drops several transitive dependencies no longer needed by @sentry/node.

Written for commit 0e705a1. Summary will update on new commits.

Review in cubic

Bumps [@unbrained/pm-cli](https://github.com/unbraind/pm-cli) from 2026.8.28 to 2026.8.31.
- [Release notes](https://github.com/unbraind/pm-cli/releases)
- [Changelog](https://github.com/unbraind/pm-cli/blob/main/CHANGELOG.md)
- [Commits](unbraind/pm-cli@v2026.8.28...v2026.8.31)
---
updated-dependencies:
- dependency-name: "@unbrained/pm-cli"
dependency-version: 2026.8.31
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 4, 2026
@greptile-apps

Copy link
Copy Markdown

PR author is in the excluded authors list.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.28 to 2026.8.31 - #72

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.31
Open

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.28 to 2026.8.31#72
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.31

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 4, 2026

Copy link
Copy Markdown
Contributor

Bumps @unbrained/pm-cli from 2026.8.28 to 2026.8.31.

Release notes

Sourced from @​unbrained/pm-cli's releases.

v2026.8.31

@​unbrained/pm-cli 2026.8.31

Source range: v2026.8.30...v2026.8.31

Changelog

Added

  • Workspace position read: one bounded answer to where this workspace stands in the branch-and-merge workflow and what to run next, replacing a protocol the agent must remember (pm-bq0ii8)

Fixed

  • Custom statuses registered without a lifecycle role are silently orphaned from every work-selection surface (pm-0mhspz)
  • GH-1158: Windows Node 24 nightly receipt fixture derives a root-relative expectation from a drive-qualified path (pm-46hpx8)
  • GH-1154: linked-test sandbox guard is command-shape inconsistent and undocumented (pm-s8cth5)
  • The local preflight token-budget gate is red on a workstation and green in hosted CI for the same commit again, because the earlier remediation closed the one ambient channel that had bitten instead of closing the fixture's environment (pm-4o7tlx)
  • The bounded legacy MCP compatibility set stops one revision short of the spec's own legacy boundary, so every current host is refused at initialize and the dual-era guarantee is unmet (pm-edywqn)

Deprecated

  • The project's own agent-facing documentation and skills instruct deprecated command spellings, so the alias-usage signal that decides when a spelling can be retired is manufactured by the instructions rather than observed from callers (pm-q2n4vd)

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.30

@​unbrained/pm-cli 2026.8.30

Source range: v2026.8.29...v2026.8.30

Changelog

Other

  • Adopt eslint-plugin-unicorn 74 with strict lint and packed-consumer proof (pm-6f66vu)

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.29

@​unbrained/pm-cli 2026.8.29

Source range: v2026.8.28...v2026.8.29

Changelog

Fixed

... (truncated)

Changelog

Sourced from @​unbrained/pm-cli's changelog.

2026.8.31 - 2026-08-31

Added

  • Workspace position read: one bounded answer to where this workspace stands in the branch-and-merge workflow and what to run next, replacing a protocol the agent must remember (pm-bq0ii8)

Fixed

  • Custom statuses registered without a lifecycle role are silently orphaned from every work-selection surface (pm-0mhspz)
  • GH-1158: Windows Node 24 nightly receipt fixture derives a root-relative expectation from a drive-qualified path (pm-46hpx8)
  • GH-1154: linked-test sandbox guard is command-shape inconsistent and undocumented (pm-s8cth5)
  • The local preflight token-budget gate is red on a workstation and green in hosted CI for the same commit again, because the earlier remediation closed the one ambient channel that had bitten instead of closing the fixture's environment (pm-4o7tlx)
  • The bounded legacy MCP compatibility set stops one revision short of the spec's own legacy boundary, so every current host is refused at initialize and the dual-era guarantee is unmet (pm-edywqn)

Security

  • Refresh compatible GitHub Actions and tsx tooling dependencies (pm-k47gdd)

Deprecated

  • The project's own agent-facing documentation and skills instruct deprecated command spellings, so the alias-usage signal that decides when a spelling can be retired is manufactured by the instructions rather than observed from callers (pm-q2n4vd)

2026.8.30 - 2026-08-30

Other

  • Adopt eslint-plugin-unicorn 74 with strict lint and packed-consumer proof (pm-6f66vu)

2026.8.29 - 2026-08-29

Fixed

  • GH-1144: hash-only merge receipts contradict report output and cannot reconcile truthfully (pm-z1z96w)
  • GH-1146/1147: external blockers remain stale and validation recommends deleting them (pm-yhle2e)
  • GH-1140: reject ambiguous bare comma tuples for linked file and test mutations (pm-nc94mk)
  • GH-1148: cached drift mismatch can falsely report tracker corruption (pm-sxg7wl)
  • GH-1138: linked test name filters can pass after executing zero tests (pm-ntnv4k)
  • GH-1136: npm 12 object-form npm pack receipts break registry package installs (pm-xrjy8o)
  • The annotation key=value grammar has three divergent comma behaviours, two of which silently corrupt the evidence text before it is made immutable (pm-hu92i3)
  • GH-1150: health remediation for pending merge receipts must perform the repair (pm-r0p3at)
  • GH-1134: required collection recovery omits truthful --clear-* intent (pm-t7wl00)
  • GH-1143: Claude session-file provenance resolver ignores real nested stream fields (pm-f60039)
  • GH-1137: linked docs writes silently persist nonexistent workspace paths (pm-hiqlkh)
  • Sentry release gate aborts valid API queries at a fixed 15-second deadline (pm-b9g2cs)

Other

  • Refresh @​sentry/node 10.72 with packed SDK and release proof (pm-mwhv33)
  • Refresh compatible 2026-08-29 dependency releases (pm-vwuidf)
  • Close the jscpd/CodeFactor sensitivity gap: minTokens 115 misses low-token table clones the CodeFactor bot still files (pm-xspd)
Commits
  • 49802e1 chore(release): cut 2026.8.31
  • a8c785a Merge pull request #1163 from unbraind/feat/workspace-position-lifecycle-context
  • 9a37f37 fix(sdk): fail closed on incomplete lifecycle evidence
  • f6c0011 fix(sdk): render workspace recovery cross-platform
  • db01807 fix(sdk): align workspace recovery and lifecycle context
  • bb16bd6 feat(sdk): add lifecycle-aware workspace readiness
  • 74aabd5 feat(sdk): unify execution trust, quality parity, and Windows receipts (#1160)
  • a64ef8e Decompose the handshake matrix, cover it, and derive the deprecated-spelling map
  • 381dbff Record the reviewed-arrival consequence of the direct-main push on the releas...
  • a326ad6 Restore MCP host interoperability and gate three denominator defects
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary by cubic

Updates @unbrained/pm-cli to 2026.8.31, which includes several bug fixes and a new workspace position feature. The lockfile also drops several transitive dependencies no longer needed by @sentry/node.

Written for commit 0e705a1. Summary will update on new commits.

Review in cubic

Bumps [@unbrained/pm-cli](https://github.com/unbraind/pm-cli) from 2026.8.28 to 2026.8.31.
- [Release notes](https://github.com/unbraind/pm-cli/releases)
- [Changelog](https://github.com/unbraind/pm-cli/blob/main/CHANGELOG.md)
- [Commits](unbraind/pm-cli@v2026.8.28...v2026.8.31)
---
updated-dependencies:
- dependency-name: "@unbrained/pm-cli"
dependency-version: 2026.8.31
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 4, 2026
@greptile-apps

Copy link
Copy Markdown

PR author is in the excluded authors list.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.28 to 2026.8.31 - #72

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.31
Open

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.28 to 2026.8.31#72
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.31

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 4, 2026

Copy link
Copy Markdown
Contributor

Bumps @unbrained/pm-cli from 2026.8.28 to 2026.8.31.

Release notes

Sourced from @​unbrained/pm-cli's releases.

v2026.8.31

@​unbrained/pm-cli 2026.8.31

Source range: v2026.8.30...v2026.8.31

Changelog

Added

  • Workspace position read: one bounded answer to where this workspace stands in the branch-and-merge workflow and what to run next, replacing a protocol the agent must remember (pm-bq0ii8)

Fixed

  • Custom statuses registered without a lifecycle role are silently orphaned from every work-selection surface (pm-0mhspz)
  • GH-1158: Windows Node 24 nightly receipt fixture derives a root-relative expectation from a drive-qualified path (pm-46hpx8)
  • GH-1154: linked-test sandbox guard is command-shape inconsistent and undocumented (pm-s8cth5)
  • The local preflight token-budget gate is red on a workstation and green in hosted CI for the same commit again, because the earlier remediation closed the one ambient channel that had bitten instead of closing the fixture's environment (pm-4o7tlx)
  • The bounded legacy MCP compatibility set stops one revision short of the spec's own legacy boundary, so every current host is refused at initialize and the dual-era guarantee is unmet (pm-edywqn)

Deprecated

  • The project's own agent-facing documentation and skills instruct deprecated command spellings, so the alias-usage signal that decides when a spelling can be retired is manufactured by the instructions rather than observed from callers (pm-q2n4vd)

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.30

@​unbrained/pm-cli 2026.8.30

Source range: v2026.8.29...v2026.8.30

Changelog

Other

  • Adopt eslint-plugin-unicorn 74 with strict lint and packed-consumer proof (pm-6f66vu)

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.29

@​unbrained/pm-cli 2026.8.29

Source range: v2026.8.28...v2026.8.29

Changelog

Fixed

... (truncated)

Changelog

Sourced from @​unbrained/pm-cli's changelog.

2026.8.31 - 2026-08-31

Added

  • Workspace position read: one bounded answer to where this workspace stands in the branch-and-merge workflow and what to run next, replacing a protocol the agent must remember (pm-bq0ii8)

Fixed

  • Custom statuses registered without a lifecycle role are silently orphaned from every work-selection surface (pm-0mhspz)
  • GH-1158: Windows Node 24 nightly receipt fixture derives a root-relative expectation from a drive-qualified path (pm-46hpx8)
  • GH-1154: linked-test sandbox guard is command-shape inconsistent and undocumented (pm-s8cth5)
  • The local preflight token-budget gate is red on a workstation and green in hosted CI for the same commit again, because the earlier remediation closed the one ambient channel that had bitten instead of closing the fixture's environment (pm-4o7tlx)
  • The bounded legacy MCP compatibility set stops one revision short of the spec's own legacy boundary, so every current host is refused at initialize and the dual-era guarantee is unmet (pm-edywqn)

Security

  • Refresh compatible GitHub Actions and tsx tooling dependencies (pm-k47gdd)

Deprecated

  • The project's own agent-facing documentation and skills instruct deprecated command spellings, so the alias-usage signal that decides when a spelling can be retired is manufactured by the instructions rather than observed from callers (pm-q2n4vd)

2026.8.30 - 2026-08-30

Other

  • Adopt eslint-plugin-unicorn 74 with strict lint and packed-consumer proof (pm-6f66vu)

2026.8.29 - 2026-08-29

Fixed

  • GH-1144: hash-only merge receipts contradict report output and cannot reconcile truthfully (pm-z1z96w)
  • GH-1146/1147: external blockers remain stale and validation recommends deleting them (pm-yhle2e)
  • GH-1140: reject ambiguous bare comma tuples for linked file and test mutations (pm-nc94mk)
  • GH-1148: cached drift mismatch can falsely report tracker corruption (pm-sxg7wl)
  • GH-1138: linked test name filters can pass after executing zero tests (pm-ntnv4k)
  • GH-1136: npm 12 object-form npm pack receipts break registry package installs (pm-xrjy8o)
  • The annotation key=value grammar has three divergent comma behaviours, two of which silently corrupt the evidence text before it is made immutable (pm-hu92i3)
  • GH-1150: health remediation for pending merge receipts must perform the repair (pm-r0p3at)
  • GH-1134: required collection recovery omits truthful --clear-* intent (pm-t7wl00)
  • GH-1143: Claude session-file provenance resolver ignores real nested stream fields (pm-f60039)
  • GH-1137: linked docs writes silently persist nonexistent workspace paths (pm-hiqlkh)
  • Sentry release gate aborts valid API queries at a fixed 15-second deadline (pm-b9g2cs)

Other

  • Refresh @​sentry/node 10.72 with packed SDK and release proof (pm-mwhv33)
  • Refresh compatible 2026-08-29 dependency releases (pm-vwuidf)
  • Close the jscpd/CodeFactor sensitivity gap: minTokens 115 misses low-token table clones the CodeFactor bot still files (pm-xspd)
Commits
  • 49802e1 chore(release): cut 2026.8.31
  • a8c785a Merge pull request #1163 from unbraind/feat/workspace-position-lifecycle-context
  • 9a37f37 fix(sdk): fail closed on incomplete lifecycle evidence
  • f6c0011 fix(sdk): render workspace recovery cross-platform
  • db01807 fix(sdk): align workspace recovery and lifecycle context
  • bb16bd6 feat(sdk): add lifecycle-aware workspace readiness
  • 74aabd5 feat(sdk): unify execution trust, quality parity, and Windows receipts (#1160)
  • a64ef8e Decompose the handshake matrix, cover it, and derive the deprecated-spelling map
  • 381dbff Record the reviewed-arrival consequence of the direct-main push on the releas...
  • a326ad6 Restore MCP host interoperability and gate three denominator defects
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary by cubic

Updates @unbrained/pm-cli to 2026.8.31, which includes several bug fixes and a new workspace position feature. The lockfile also drops several transitive dependencies no longer needed by @sentry/node.

Written for commit 0e705a1. Summary will update on new commits.

Review in cubic

Bumps [@unbrained/pm-cli](https://github.com/unbraind/pm-cli) from 2026.8.28 to 2026.8.31.
- [Release notes](https://github.com/unbraind/pm-cli/releases)
- [Changelog](https://github.com/unbraind/pm-cli/blob/main/CHANGELOG.md)
- [Commits](unbraind/pm-cli@v2026.8.28...v2026.8.31)
---
updated-dependencies:
- dependency-name: "@unbrained/pm-cli"
dependency-version: 2026.8.31
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 4, 2026
@greptile-apps

Copy link
Copy Markdown

PR author is in the excluded authors list.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.28 to 2026.8.31 - #72

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.31
Open

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.28 to 2026.8.31#72
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.31

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 4, 2026

Copy link
Copy Markdown
Contributor

Bumps @unbrained/pm-cli from 2026.8.28 to 2026.8.31.

Release notes

Sourced from @​unbrained/pm-cli's releases.

v2026.8.31

@​unbrained/pm-cli 2026.8.31

Source range: v2026.8.30...v2026.8.31

Changelog

Added

  • Workspace position read: one bounded answer to where this workspace stands in the branch-and-merge workflow and what to run next, replacing a protocol the agent must remember (pm-bq0ii8)

Fixed

  • Custom statuses registered without a lifecycle role are silently orphaned from every work-selection surface (pm-0mhspz)
  • GH-1158: Windows Node 24 nightly receipt fixture derives a root-relative expectation from a drive-qualified path (pm-46hpx8)
  • GH-1154: linked-test sandbox guard is command-shape inconsistent and undocumented (pm-s8cth5)
  • The local preflight token-budget gate is red on a workstation and green in hosted CI for the same commit again, because the earlier remediation closed the one ambient channel that had bitten instead of closing the fixture's environment (pm-4o7tlx)
  • The bounded legacy MCP compatibility set stops one revision short of the spec's own legacy boundary, so every current host is refused at initialize and the dual-era guarantee is unmet (pm-edywqn)

Deprecated

  • The project's own agent-facing documentation and skills instruct deprecated command spellings, so the alias-usage signal that decides when a spelling can be retired is manufactured by the instructions rather than observed from callers (pm-q2n4vd)

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.30

@​unbrained/pm-cli 2026.8.30

Source range: v2026.8.29...v2026.8.30

Changelog

Other

  • Adopt eslint-plugin-unicorn 74 with strict lint and packed-consumer proof (pm-6f66vu)

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.29

@​unbrained/pm-cli 2026.8.29

Source range: v2026.8.28...v2026.8.29

Changelog

Fixed

... (truncated)

Changelog

Sourced from @​unbrained/pm-cli's changelog.

2026.8.31 - 2026-08-31

Added

  • Workspace position read: one bounded answer to where this workspace stands in the branch-and-merge workflow and what to run next, replacing a protocol the agent must remember (pm-bq0ii8)

Fixed

  • Custom statuses registered without a lifecycle role are silently orphaned from every work-selection surface (pm-0mhspz)
  • GH-1158: Windows Node 24 nightly receipt fixture derives a root-relative expectation from a drive-qualified path (pm-46hpx8)
  • GH-1154: linked-test sandbox guard is command-shape inconsistent and undocumented (pm-s8cth5)
  • The local preflight token-budget gate is red on a workstation and green in hosted CI for the same commit again, because the earlier remediation closed the one ambient channel that had bitten instead of closing the fixture's environment (pm-4o7tlx)
  • The bounded legacy MCP compatibility set stops one revision short of the spec's own legacy boundary, so every current host is refused at initialize and the dual-era guarantee is unmet (pm-edywqn)

Security

  • Refresh compatible GitHub Actions and tsx tooling dependencies (pm-k47gdd)

Deprecated

  • The project's own agent-facing documentation and skills instruct deprecated command spellings, so the alias-usage signal that decides when a spelling can be retired is manufactured by the instructions rather than observed from callers (pm-q2n4vd)

2026.8.30 - 2026-08-30

Other

  • Adopt eslint-plugin-unicorn 74 with strict lint and packed-consumer proof (pm-6f66vu)

2026.8.29 - 2026-08-29

Fixed

  • GH-1144: hash-only merge receipts contradict report output and cannot reconcile truthfully (pm-z1z96w)
  • GH-1146/1147: external blockers remain stale and validation recommends deleting them (pm-yhle2e)
  • GH-1140: reject ambiguous bare comma tuples for linked file and test mutations (pm-nc94mk)
  • GH-1148: cached drift mismatch can falsely report tracker corruption (pm-sxg7wl)
  • GH-1138: linked test name filters can pass after executing zero tests (pm-ntnv4k)
  • GH-1136: npm 12 object-form npm pack receipts break registry package installs (pm-xrjy8o)
  • The annotation key=value grammar has three divergent comma behaviours, two of which silently corrupt the evidence text before it is made immutable (pm-hu92i3)
  • GH-1150: health remediation for pending merge receipts must perform the repair (pm-r0p3at)
  • GH-1134: required collection recovery omits truthful --clear-* intent (pm-t7wl00)
  • GH-1143: Claude session-file provenance resolver ignores real nested stream fields (pm-f60039)
  • GH-1137: linked docs writes silently persist nonexistent workspace paths (pm-hiqlkh)
  • Sentry release gate aborts valid API queries at a fixed 15-second deadline (pm-b9g2cs)

Other

  • Refresh @​sentry/node 10.72 with packed SDK and release proof (pm-mwhv33)
  • Refresh compatible 2026-08-29 dependency releases (pm-vwuidf)
  • Close the jscpd/CodeFactor sensitivity gap: minTokens 115 misses low-token table clones the CodeFactor bot still files (pm-xspd)
Commits
  • 49802e1 chore(release): cut 2026.8.31
  • a8c785a Merge pull request #1163 from unbraind/feat/workspace-position-lifecycle-context
  • 9a37f37 fix(sdk): fail closed on incomplete lifecycle evidence
  • f6c0011 fix(sdk): render workspace recovery cross-platform
  • db01807 fix(sdk): align workspace recovery and lifecycle context
  • bb16bd6 feat(sdk): add lifecycle-aware workspace readiness
  • 74aabd5 feat(sdk): unify execution trust, quality parity, and Windows receipts (#1160)
  • a64ef8e Decompose the handshake matrix, cover it, and derive the deprecated-spelling map
  • 381dbff Record the reviewed-arrival consequence of the direct-main push on the releas...
  • a326ad6 Restore MCP host interoperability and gate three denominator defects
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary by cubic

Updates @unbrained/pm-cli to 2026.8.31, which includes several bug fixes and a new workspace position feature. The lockfile also drops several transitive dependencies no longer needed by @sentry/node.

Written for commit 0e705a1. Summary will update on new commits.

Review in cubic

Bumps [@unbrained/pm-cli](https://github.com/unbraind/pm-cli) from 2026.8.28 to 2026.8.31.
- [Release notes](https://github.com/unbraind/pm-cli/releases)
- [Changelog](https://github.com/unbraind/pm-cli/blob/main/CHANGELOG.md)
- [Commits](unbraind/pm-cli@v2026.8.28...v2026.8.31)
---
updated-dependencies:
- dependency-name: "@unbrained/pm-cli"
dependency-version: 2026.8.31
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 4, 2026
@greptile-apps

Copy link
Copy Markdown

PR author is in the excluded authors list.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.28 to 2026.8.31 - #72

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.31
Open

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.28 to 2026.8.31#72
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.31

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubSep 4, 2026

Copy link
Copy Markdown
Contributor

Bumps @unbrained/pm-cli from 2026.8.28 to 2026.8.31.

Release notes

Sourced from @​unbrained/pm-cli's releases.

v2026.8.31

@​unbrained/pm-cli 2026.8.31

Source range: v2026.8.30...v2026.8.31

Changelog

Added

  • Workspace position read: one bounded answer to where this workspace stands in the branch-and-merge workflow and what to run next, replacing a protocol the agent must remember (pm-bq0ii8)

Fixed

  • Custom statuses registered without a lifecycle role are silently orphaned from every work-selection surface (pm-0mhspz)
  • GH-1158: Windows Node 24 nightly receipt fixture derives a root-relative expectation from a drive-qualified path (pm-46hpx8)
  • GH-1154: linked-test sandbox guard is command-shape inconsistent and undocumented (pm-s8cth5)
  • The local preflight token-budget gate is red on a workstation and green in hosted CI for the same commit again, because the earlier remediation closed the one ambient channel that had bitten instead of closing the fixture's environment (pm-4o7tlx)
  • The bounded legacy MCP compatibility set stops one revision short of the spec's own legacy boundary, so every current host is refused at initialize and the dual-era guarantee is unmet (pm-edywqn)

Deprecated

  • The project's own agent-facing documentation and skills instruct deprecated command spellings, so the alias-usage signal that decides when a spelling can be retired is manufactured by the instructions rather than observed from callers (pm-q2n4vd)

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.30

@​unbrained/pm-cli 2026.8.30

Source range: v2026.8.29...v2026.8.30

Changelog

Other

  • Adopt eslint-plugin-unicorn 74 with strict lint and packed-consumer proof (pm-6f66vu)

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.29

@​unbrained/pm-cli 2026.8.29

Source range: v2026.8.28...v2026.8.29

Changelog

Fixed

... (truncated)

Changelog

Sourced from @​unbrained/pm-cli's changelog.

2026.8.31 - 2026-08-31

Added

  • Workspace position read: one bounded answer to where this workspace stands in the branch-and-merge workflow and what to run next, replacing a protocol the agent must remember (pm-bq0ii8)

Fixed

  • Custom statuses registered without a lifecycle role are silently orphaned from every work-selection surface (pm-0mhspz)
  • GH-1158: Windows Node 24 nightly receipt fixture derives a root-relative expectation from a drive-qualified path (pm-46hpx8)
  • GH-1154: linked-test sandbox guard is command-shape inconsistent and undocumented (pm-s8cth5)
  • The local preflight token-budget gate is red on a workstation and green in hosted CI for the same commit again, because the earlier remediation closed the one ambient channel that had bitten instead of closing the fixture's environment (pm-4o7tlx)
  • The bounded legacy MCP compatibility set stops one revision short of the spec's own legacy boundary, so every current host is refused at initialize and the dual-era guarantee is unmet (pm-edywqn)

Security

  • Refresh compatible GitHub Actions and tsx tooling dependencies (pm-k47gdd)

Deprecated

  • The project's own agent-facing documentation and skills instruct deprecated command spellings, so the alias-usage signal that decides when a spelling can be retired is manufactured by the instructions rather than observed from callers (pm-q2n4vd)

2026.8.30 - 2026-08-30

Other

  • Adopt eslint-plugin-unicorn 74 with strict lint and packed-consumer proof (pm-6f66vu)

2026.8.29 - 2026-08-29

Fixed

  • GH-1144: hash-only merge receipts contradict report output and cannot reconcile truthfully (pm-z1z96w)
  • GH-1146/1147: external blockers remain stale and validation recommends deleting them (pm-yhle2e)
  • GH-1140: reject ambiguous bare comma tuples for linked file and test mutations (pm-nc94mk)
  • GH-1148: cached drift mismatch can falsely report tracker corruption (pm-sxg7wl)
  • GH-1138: linked test name filters can pass after executing zero tests (pm-ntnv4k)
  • GH-1136: npm 12 object-form npm pack receipts break registry package installs (pm-xrjy8o)
  • The annotation key=value grammar has three divergent comma behaviours, two of which silently corrupt the evidence text before it is made immutable (pm-hu92i3)
  • GH-1150: health remediation for pending merge receipts must perform the repair (pm-r0p3at)
  • GH-1134: required collection recovery omits truthful --clear-* intent (pm-t7wl00)
  • GH-1143: Claude session-file provenance resolver ignores real nested stream fields (pm-f60039)
  • GH-1137: linked docs writes silently persist nonexistent workspace paths (pm-hiqlkh)
  • Sentry release gate aborts valid API queries at a fixed 15-second deadline (pm-b9g2cs)

Other

  • Refresh @​sentry/node 10.72 with packed SDK and release proof (pm-mwhv33)
  • Refresh compatible 2026-08-29 dependency releases (pm-vwuidf)
  • Close the jscpd/CodeFactor sensitivity gap: minTokens 115 misses low-token table clones the CodeFactor bot still files (pm-xspd)
Commits
  • 49802e1 chore(release): cut 2026.8.31
  • a8c785a Merge pull request #1163 from unbraind/feat/workspace-position-lifecycle-context
  • 9a37f37 fix(sdk): fail closed on incomplete lifecycle evidence
  • f6c0011 fix(sdk): render workspace recovery cross-platform
  • db01807 fix(sdk): align workspace recovery and lifecycle context
  • bb16bd6 feat(sdk): add lifecycle-aware workspace readiness
  • 74aabd5 feat(sdk): unify execution trust, quality parity, and Windows receipts (#1160)
  • a64ef8e Decompose the handshake matrix, cover it, and derive the deprecated-spelling map
  • 381dbff Record the reviewed-arrival consequence of the direct-main push on the releas...
  • a326ad6 Restore MCP host interoperability and gate three denominator defects
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary by cubic

Updates @unbrained/pm-cli to 2026.8.31, which includes several bug fixes and a new workspace position feature. The lockfile also drops several transitive dependencies no longer needed by @sentry/node.

Written for commit 0e705a1. Summary will update on new commits.

Review in cubic

Bumps [@unbrained/pm-cli](https://github.com/unbraind/pm-cli) from 2026.8.28 to 2026.8.31.
- [Release notes](https://github.com/unbraind/pm-cli/releases)
- [Changelog](https://github.com/unbraind/pm-cli/blob/main/CHANGELOG.md)
- [Commits](unbraind/pm-cli@v2026.8.28...v2026.8.31)
---
updated-dependencies:
- dependency-name: "@unbrained/pm-cli"
dependency-version: 2026.8.31
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 4, 2026
@greptile-apps

Copy link
Copy Markdown

PR author is in the excluded authors list.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants