Skip to content

build(deps): combine green Dependabot bumps - #9135

Merged
russellwheatley merged 9 commits into
mainfrom
chore/combine-green-dependabot
Aug 4, 2026
Merged

build(deps): combine green Dependabot bumps#9135
russellwheatley merged 9 commits into
mainfrom
chore/combine-green-dependabot

Conversation

@russellwheatley

@russellwheatley russellwheatley commented Jul 31, 2026

Copy link
Copy Markdown
Member

Summary

Notes

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@codecov

codecov Bot commented Jul 31, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 64.09%. Comparing base (59d053e) to head (6525261).

Additional details and impacted files
@@             Coverage Diff              @@
##               main    #9135      +/-   ##
============================================
- Coverage     64.11%   64.09%   -0.02%     
+ Complexity     1909     1908       -1     
============================================
  Files           523      523              
  Lines         41660    41660              
  Branches       6467     6497      +30     
============================================
- Hits          26708    26699       -9     
+ Misses        13522    13485      -37     
- Partials       1430     1476      +46     
Flag Coverage Δ
android-native 63.60% <ø> (-<0.01%) ⬇️
e2e-ts-android 60.12% <ø> (-0.02%) ⬇️
e2e-ts-ios 58.72% <ø> (-0.01%) ⬇️
e2e-ts-macos 49.71% <ø> (-<0.01%) ⬇️
ios-native 58.72% <ø> (-0.01%) ⬇️
jest 50.04% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@just1and0
just1and0 self-requested a review July 31, 2026 10:05
@just1and0
just1and0 requested a review from mikehardy July 31, 2026 10:06
@russellwheatley

Copy link
Copy Markdown
Member Author

Blocked - RNCLI version is locked for the time being due to dependency on react-native-macos.

@russellwheatley russellwheatley added the blocked: do-not-merge Do not merge this issue without approval by the person who labelled this issue as Do Not Merge label Jul 31, 2026
@russellwheatley russellwheatley removed the blocked: do-not-merge Do not merge this issue without approval by the person who labelled this issue as Do Not Merge label Aug 4, 2026
dependabot Bot and others added 9 commits August 4, 2026 06:59
Bumps [web-streams-polyfill](https://github.com/MattiasBuelens/web-streams-polyfill) from 4.2.0 to 4.3.0.
- [Release notes](https://github.com/MattiasBuelens/web-streams-polyfill/releases)
- [Changelog](https://github.com/MattiasBuelens/web-streams-polyfill/blob/master/CHANGELOG.md)
- [Commits](MattiasBuelens/web-streams-polyfill@v4.2.0...v4.3.0)

---
updated-dependencies:
- dependency-name: web-streams-polyfill
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [react-native-url-polyfill](https://github.com/charpeni/react-native-url-polyfill) from 3.0.0 to 4.0.0.
- [Release notes](https://github.com/charpeni/react-native-url-polyfill/releases)
- [Commits](charpeni/react-native-url-polyfill@v3.0.0...v4.0.0)

---
updated-dependencies:
- dependency-name: react-native-url-polyfill
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@react-native-community/cli](https://github.com/react-native-community/cli/tree/HEAD/packages/cli) from 15.1.3 to 20.2.0.
- [Release notes](https://github.com/react-native-community/cli/releases)
- [Changelog](https://github.com/react-native-community/cli/blob/main/packages/cli/CHANGELOG.md)
- [Commits](https://github.com/react-native-community/cli/commits/v20.2.0/packages/cli)

---
updated-dependencies:
- dependency-name: "@react-native-community/cli"
  dependency-version: 20.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/cache/save](https://github.com/actions/cache) from 5.0.5 to 6.1.0.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@27d5ce7...55cc834)

---
updated-dependencies:
- dependency-name: actions/cache/save
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5.3.0 to 5.6.0.
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](actions/setup-java@ad2b381...03ad4de)

---
updated-dependencies:
- dependency-name: actions/setup-java
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Revert the Dependabot CLI 20.x bump; the test app RN/CLI line is locked by react-native-macos. Document the intentional pins in okf-bundle.
Dependabot only bumped cache/save; pin restore to the same v6.1.0 SHA so save/restore stay paired.
Bumps [actions/github-script](https://github.com/actions/github-script) from d746ffe35508b1917358783b479e04febd2b8f71 to 3a2844b7e9c422d3c10d287c895573f7108da1b3.
- [Release notes](https://github.com/actions/github-script/releases)
- [Commits](actions/github-script@d746ffe...3a2844b)

---
updated-dependencies:
- dependency-name: actions/github-script
  dependency-version: 3a2844b7e9c422d3c10d287c895573f7108da1b3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 9f698171ed81b15d1823a05fc7211befd50c8ae0 to df4cb1c069e1874edd31b4311f1884172cec0e10.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@9f69817...df4cb1c)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: df4cb1c069e1874edd31b4311f1884172cec0e10
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@mikehardy
mikehardy force-pushed the chore/combine-green-dependabot branch from af67dc5 to 6525261 Compare August 4, 2026 12:05

@mikehardy mikehardy left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

there were two more dependabot PRs that were for github workflow actions and were green except semantic release rule because the commit didn't include the SHA but the title included the SHA - pulled those in here two, CI going green will be the qualifier for them, as github actions changes

@mikehardy mikehardy added Workflow: Pending Merge Waiting on CI or similar and removed Needs Attention labels Aug 4, 2026
@russellwheatley
russellwheatley merged commit cf7ef7e into main Aug 4, 2026
28 checks passed
@russellwheatley
russellwheatley deleted the chore/combine-green-dependabot branch August 4, 2026 14:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Workflow: Pending Merge Waiting on CI or similar

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants