Skip to content

build(deps): bump lucide-react from 1.20.0 to 1.21.0 - #436

Closed
dependabot[bot] wants to merge 15 commits into
developfrom
dependabot/npm_and_yarn/develop/lucide-react-1.21.0
Closed

build(deps): bump lucide-react from 1.20.0 to 1.21.0#436
dependabot[bot] wants to merge 15 commits into
developfrom
dependabot/npm_and_yarn/develop/lucide-react-1.21.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 23, 2026

Copy link
Copy Markdown
Contributor

Bumps lucide-react from 1.20.0 to 1.21.0.

Release notes

Sourced from lucide-react's releases.

Version 1.21.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.20.0...1.21.0

Commits
  • 5ff536e ci(release.yml): Fix workflow and remove version scripts in package scripts...
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) from 1.20.0 to 1.21.0.
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.21.0/packages/lucide-react)

---
updated-dependencies:
- dependency-name: lucide-react
  dependency-version: 1.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 23, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner June 23, 2026 17:23
@dependabot dependabot Bot added the javascript Pull requests that update javascript code label Jun 23, 2026
@opencode-agent

opencode-agent Bot commented Jun 23, 2026

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

  • Head SHA: 42656498e14593d6a580fac33e8ae61ea2cbde98
  • Workflow run: 28623102993
  • Workflow attempt: 1
  • Gate result: APPROVE (approval step)

Pull request overview

OpenCode reviewed the current-head bounded evidence and found no blocking issues.

Findings

No blocking findings.

Summary

Approval sufficiency: bounded evidence supplied affirmative approval evidence for changed files, coverage/docstring posture, risk surfaces, and current-head verification; approval is not based merely on the absence of known blockers.
Verification posture: CodeGraph evidence was initialized and bounded current-head evidence reviewed for changed-file evidence including apps/desktop/package.json, package-lock.json.
Linter/static: workflow/static review evidence is bounded by the current-head GitHub Checks gate and changed-file evidence.
TDD/regression: coverage execution evidence and focused changed hunks were reviewed from bounded-review-evidence.md.
Coverage: coverage execution evidence reports test coverage as not applicable because no supported changed source files or package manifests were found.
Docstring coverage: coverage execution evidence reports docstring coverage as not applicable because no supported changed source files or package manifests were found.
DAG: CodeGraph/source-backed behavior map connects apps/desktop/package.json to the affected review, runtime, or workflow path and required checks.
PoC/execution: coverage-evidence job executed on the current head and reported PASS.
DDD/domain: workflow and repository-governance invariants were reviewed against changed files in bounded evidence.
CDD/context: CodeGraph evidence, changed-file history, and focused hunks were reviewed from bounded-review-evidence.md.
Similar issues: changed-file history evidence was reviewed for comparable local precedents.
Claim/concept check: bounded evidence, repository source, current-head workflow evidence, and, where numeric, scientific, statistical, or literature-backed claims are affected, original-paper/formula evidence and parameter-recovery expectations were used for claims.
Standards search: standards and external-source checks are delegated to configured OpenCode web_search/Context7/DeepWiki sources when applicable; no evidence-backed standards blocker is present in bounded evidence.
Compatibility/convention: changed workflow/script conventions, object naming, and reserved-word safety for schema/API/config/code surfaces were checked in bounded evidence.
Breaking-change/backcompat: deployment evidence and changed-file history were checked for backward-compatibility risk.
Performance: changed surfaces were checked for performance risk in bounded evidence.
Developer experience: changed automation, review, test, setup, and maintenance surfaces were checked for helpful or obstructive DX impact in bounded evidence.
User experience: connected user, operator, API, CLI, documentation, review-comment, status-check, rendering, and workflow-reader behavior was checked for contradictions against code, docs, and tests in bounded evidence.
Visual/DOM: Playwright visual, DOM locator, ARIA snapshot, console, and responsive evidence were checked when a web UI surface was present; for non-web surfaces, API/CLI/log/docs/workflow interaction evidence was reviewed instead.
Accessibility/i18n: accessibility, localization, and human-readable text surfaces were checked where UI, CLI, API message, docs, logs, or review text changed.
Supply-chain/license: dependency, package, model, container, and external-tool changes were checked in bounded evidence.
Packaging: package, build, test, lint, and security contracts were checked in bounded evidence.
Security/privacy: workflow-token, review-gate, and repository-automation security/privacy boundaries were checked in bounded evidence.

  • Result: APPROVE
  • Reason: Safe dependency update with no breaking changes
  • Head SHA: 42656498e14593d6a580fac33e8ae61ea2cbde98
  • Workflow run: 28623102993
  • Workflow attempt: 1

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file (2 files)"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file (2 files)"]
  R1 --> V1["required checks"]
Loading

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode found current-head GitHub Check failures and could not approve until they are mapped to source-backed fixes.

Findings

Line-specific fallback findings:

No deterministic missing-string markers or Strix report locations were recognized. Use the failed-check evidence below to map each failed check to exact local source lines before approving.

Verification

  • Review source: independent OpenCode failed-check diagnosis using current-head check evidence.
  • Result: REQUEST_CHANGES
  • Reason: one or more GitHub Checks failed on current head c4887e749172808c488e3eb5935636f6d2d1ea00.

Gate evidence

  • Head SHA: c4887e749172808c488e3eb5935636f6d2d1ea00
  • Workflow run: 28158453142
  • Workflow attempt: 1

Failed checks:

Failed check evidence for line-specific fixes:

Failed GitHub Check Evidence

  • PR: #436
  • Head SHA: c4887e749172808c488e3eb5935636f6d2d1ea00
  • Repository: ContextualWisdomLab/bandscope

Line-specific repair contract

  • Treat the check logs and annotations below as diagnostic evidence, not as a complete review.

  • For each actionable failed check, inspect the local source or diff and identify the exact file line that must change.

  • OpenCode REQUEST_CHANGES findings must include path, line, root_cause, fix_direction, regression_test_direction, and suggested_diff.

  • Do not request changes with only a GitHub Actions URL or a generic check name.

  • When Strix logs contain multiple Vulnerability Report or Model ... Vulnerabilities ... sections, include every model-reported vulnerability in the review evidence and findings, including model name, title, severity, endpoint, and Code Locations/path:line evidence when present.

  • Create one OpenCode finding per Strix model vulnerability report; do not satisfy two model reports with one combined finding, even when titles or locations match.

Failed check: build-baseline/build / macos / amd64

Failed job steps

  • step 13: Upload macOS amd64 artifact (failure)

Check annotations

Failed log signal summary

build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0056530Z   if-no-files-found: warn
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:41.6807070Z ##[error]Failed to CreateArtifact: Unable to make request: ENOTFOUND

Failed log excerpt

build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8236250Z Current runner version: '2.335.1'
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8271210Z ##[group]Runner Image Provisioner
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8272480Z Hosted Compute Agent
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8273430Z Version: 20260527.539
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8274370Z Commit: a891dd388383b896fa6ac04a82c0b75cec981078
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8275680Z Build Date: 2026-05-27T21:39:57Z
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8276690Z Worker ID: {c14ddbad-8cb7-45b9-8a83-7d30fd15600d}
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8277750Z Azure Region: westus
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8278650Z ##[endgroup]
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8280940Z ##[group]Operating System
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8281880Z macOS
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8282640Z 15.7.7
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8283360Z 24G720
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8284130Z ##[endgroup]
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8284920Z ##[group]Runner Image
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8285930Z Image: macos-15
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8286790Z Version: 20260609.0193.1
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8288740Z Included Software: https://github.com/actions/runner-images/blob/macos-15/20260609.0193/images/macos/macos-15-Readme.md
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8291250Z Image Release: https://github.com/actions/runner-images/releases/tag/macos-15%2F20260609.0193
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8292790Z ##[endgroup]
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8294690Z ##[group]GITHUB_TOKEN Permissions
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8298060Z Contents: read
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8298990Z Metadata: read
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8299810Z ##[endgroup]
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8302760Z Secret source: Actions
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8304710Z Prepare workflow directory
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.8952470Z Prepare all required actions
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:05.9007150Z Getting action download info
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:06.0790670Z Download action repository 'actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10' (SHA:df4cb1c069e1874edd31b4311f1884172cec0e10)
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:06.2433030Z Download action repository 'actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e' (SHA:48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e)
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:06.3830640Z Download action repository 'actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405' (SHA:a309ff8b426b58ec0e2a45f0f869d46889d02405)
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:06.5213230Z Download action repository 'astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39' (SHA:fac544c07dec837d0ccb6301d7b5580bf5edae39)
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:07.6425320Z Download action repository 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a' (SHA:043fb46d1a93c77aae656e7c1c64a875d1fc6a0a)
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:07.9393160Z Complete job name: build / macos / amd64
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0567150Z ##[group]Run actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0569470Z with:
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0570450Z   persist-credentials: false
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0571620Z   repository: ContextualWisdomLab/bandscope
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0581430Z   token: ***
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0582390Z   ssh-strict: true
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0583320Z   ssh-user: git
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0584230Z   clean: true
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0585190Z   sparse-checkout-cone-mode: true
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0586300Z   fetch-depth: 1
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0587280Z   fetch-tags: false
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0588250Z   show-progress: true
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0589220Z   lfs: false
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0590150Z   submodules: false
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0591240Z   set-safe-directory: true
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0593120Z env:
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0594260Z   GIT_CONFIG_COUNT: 1
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0595320Z   GIT_CONFIG_KEY_0: init.defaultBranch
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0596480Z   GIT_CONFIG_VALUE_0: develop
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0597780Z   BANDSCOPE_ARTIFACT_OS: macos
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0598850Z   BANDSCOPE_ARTIFACT_ARCH: amd64
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0600010Z   BANDSCOPE_TARGET_TRIPLE: x86_64-apple-darwin
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.0601200Z ##[endgroup]
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.3622330Z Syncing repository: ContextualWisdomLab/bandscope
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.3627690Z ##[group]Getting Git version info
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.3629850Z Working directory is '/Users/runner/work/bandscope/bandscope'
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.3632900Z [command]/usr/local/bin/git version
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.3962940Z git version 2.54.0
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.3993660Z ##[endgroup]
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4012580Z Copying '/Users/runner/.gitconfig' to '/Users/runner/work/_temp/32fd1aff-e248-42f8-8c4e-c2715c7e2a4d/.gitconfig'
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4030410Z Temporarily overriding HOME='/Users/runner/work/_temp/32fd1aff-e248-42f8-8c4e-c2715c7e2a4d' before making global git config changes
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4033720Z Adding repository directory to the temporary git global config as a safe directory
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4038220Z [command]/usr/local/bin/git config --global --add safe.directory /Users/runner/work/bandscope/bandscope
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4174100Z Deleting the contents of '/Users/runner/work/bandscope/bandscope'
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4182630Z ##[group]Determining repository object format
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4185350Z ##[endgroup]
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4186970Z ##[group]Initializing the repository
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4195930Z [command]/usr/local/bin/git init /Users/runner/work/bandscope/bandscope
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4548820Z Initialized empty Git repository in /Users/runner/work/bandscope/bandscope/.git/
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4566750Z [command]/usr/local/bin/git remote add origin https://github.com/ContextualWisdomLab/bandscope
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4688460Z ##[endgroup]
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4690180Z ##[group]Disabling automatic garbage collection
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4693300Z [command]/usr/local/bin/git config --local gc.auto 0
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4808680Z ##[endgroup]
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4810630Z ##[group]Setting up auth
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4811860Z Removing SSH command configuration
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4818590Z [command]/usr/local/bin/git config --local --name-only --get-regexp core\.sshCommand
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.4938210Z [command]/usr/local/bin/git submodule foreach --recursive sh -c "git config --local --name-only --get-regexp 'core\.sshCommand' && git config --local --unset-all 'core.sshCommand' || :"
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.6404510Z Removing HTTP extra header
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.6412840Z [command]/usr/local/bin/git config --local --name-only --get-regexp http\.https\:\/\/github\.com\/\.extraheader
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.6512430Z [command]/usr/local/bin/git submodule foreach --recursive sh -c "git config --local --name-only --get-regexp 'http\.https\:\/\/github\.com\/\.extraheader' && git config --local --unset-all 'http.https://github.com/.extraheader' || :"
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.7832860Z Removing includeIf entries pointing to credentials config files
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.7843210Z [command]/usr/local/bin/git config --local --name-only --get-regexp ^includeIf\.gitdir:
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.7982650Z [command]/usr/local/bin/git submodule foreach --recursive git config --local --show-origin --name-only --get-regexp remote.origin.url
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.9385540Z [command]/usr/local/bin/git config --file /Users/runner/work/_temp/git-credentials-5d46b346-d9dc-44a4-b415-2cfd44f0328c.config http.https://github.com/.extraheader AUTHORIZATION: basic ***
build / macos / amd64	UNKNOWN STEP	2026-06-25T08:57:08.9503170Z [command]/usr/local/bin/git config --local includeIf.gitdir:/Users/runner/work/bandscope/bandscope/.git.path /Users/runner/work/_temp/git-credentials-5d46b346-d9dc-44a4-b415-2cfd44f0328c.config

... truncated 796 middle log lines ...

build / macos / amd64	UNKNOWN STEP	2026-06-25T09:00:38.5706190Z    Compiling unicode-segmentation v1.13.3
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:00:38.6707720Z    Compiling getrandom v0.3.4
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:00:39.1406640Z    Compiling png v0.18.1
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:00:39.9790230Z    Compiling keyboard-types v0.7.0
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:00:40.6178240Z    Compiling tao v0.35.3
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:00:46.1173370Z    Compiling tauri-codegen v2.6.3
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:00:49.6496880Z    Compiling serialize-to-javascript-impl v0.1.2
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:00:50.3544370Z    Compiling rfd v0.17.2
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:00:50.8612990Z    Compiling pin-project-lite v0.2.17
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:00:51.2620770Z    Compiling tokio v1.52.3
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:00:58.9505940Z    Compiling serialize-to-javascript v0.1.2
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:00:59.4240350Z    Compiling tauri-macros v2.6.3
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:01:02.2746920Z    Compiling muda v0.19.3
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:01:03.5575230Z    Compiling bandscope-desktop v0.1.0 (/Users/runner/work/bandscope/bandscope/apps/desktop/src-tauri)
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:01:04.5478880Z    Compiling window-vibrancy v0.6.0
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:01:04.9067410Z    Compiling serde_repr v0.1.20
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:01:05.6977370Z    Compiling embed_plist v1.2.2
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:01:14.1961880Z    Compiling mime v0.3.17
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:03:54.7505240Z     Finished `release` profile [optimized] target(s) in 6m 12s
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:03:55.8067480Z        Built application at: /Users/runner/work/bandscope/bandscope/apps/desktop/src-tauri/target/x86_64-apple-darwin/release/bandscope-desktop
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:03:55.8810660Z     Bundling BandScope.app (/Users/runner/work/bandscope/bandscope/apps/desktop/src-tauri/target/x86_64-apple-darwin/release/bundle/macos/BandScope.app)
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:03:56.0072860Z     Bundling BandScope_0.1.3_x64.dmg (/Users/runner/work/bandscope/bandscope/apps/desktop/src-tauri/target/x86_64-apple-darwin/release/bundle/dmg/BandScope_0.1.3_x64.dmg)
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:03:56.0377890Z      Running bundle_dmg.sh
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.1258910Z     Cleaning /Users/runner/work/bandscope/bandscope/apps/desktop/src-tauri/target/x86_64-apple-darwin/release/bundle/macos/BandScope.app
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.1279340Z     Finished 1 bundle at:
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.1285560Z         /Users/runner/work/bandscope/bandscope/apps/desktop/src-tauri/target/x86_64-apple-darwin/release/bundle/dmg/BandScope_0.1.3_x64.dmg
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.1286940Z 
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5249000Z ##[group]Run python3 scripts/release/package_desktop_artifact.py
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5254140Z ^[[36;1mpython3 scripts/release/package_desktop_artifact.py^[[0m
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5785170Z shell: /bin/bash -e {0}
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5785800Z env:
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5786260Z   GIT_CONFIG_COUNT: 1
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5786850Z   GIT_CONFIG_KEY_0: init.defaultBranch
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5787570Z   GIT_CONFIG_VALUE_0: develop
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5788220Z   BANDSCOPE_ARTIFACT_OS: macos
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5788900Z   BANDSCOPE_ARTIFACT_ARCH: amd64
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5789650Z   BANDSCOPE_TARGET_TRIPLE: x86_64-apple-darwin
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5790690Z   pythonLocation: /Users/runner/hostedtoolcache/Python/3.12.10/x64
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5792080Z   PKG_CONFIG_PATH: /Users/runner/hostedtoolcache/Python/3.12.10/x64/lib/pkgconfig
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5793260Z   Python_ROOT_DIR: /Users/runner/hostedtoolcache/Python/3.12.10/x64
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5794820Z   Python2_ROOT_DIR: /Users/runner/hostedtoolcache/Python/3.12.10/x64
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5795800Z   Python3_ROOT_DIR: /Users/runner/hostedtoolcache/Python/3.12.10/x64
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5796790Z   UV_PYTHON_INSTALL_DIR: /Users/runner/work/_temp/uv-python-dir
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.5797960Z ##[endgroup]
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:10.9602750Z Packaged BandScope_0.1.3_x64.dmg to artifacts/bandscope-macos-amd64-ce2b275245d2.dmg
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0052910Z ##[group]Run actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0053900Z with:
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0054910Z   name: bandscope-macos-amd64-ce2b275245d2d903497b0dc1565a7d90c5bf763a
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0055960Z   path: artifacts/*
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0056530Z   if-no-files-found: warn
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0057090Z   compression-level: 6
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0057760Z   overwrite: false
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0058420Z   include-hidden-files: false
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0058960Z   archive: true
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0059430Z env:
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0060000Z   GIT_CONFIG_COUNT: 1
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0060510Z   GIT_CONFIG_KEY_0: init.defaultBranch
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0061140Z   GIT_CONFIG_VALUE_0: develop
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0061790Z   BANDSCOPE_ARTIFACT_OS: macos
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0062420Z   BANDSCOPE_ARTIFACT_ARCH: amd64
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0063080Z   BANDSCOPE_TARGET_TRIPLE: x86_64-apple-darwin
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0064250Z   pythonLocation: /Users/runner/hostedtoolcache/Python/3.12.10/x64
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0065970Z   PKG_CONFIG_PATH: /Users/runner/hostedtoolcache/Python/3.12.10/x64/lib/pkgconfig
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0067340Z   Python_ROOT_DIR: /Users/runner/hostedtoolcache/Python/3.12.10/x64
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0069690Z   Python2_ROOT_DIR: /Users/runner/hostedtoolcache/Python/3.12.10/x64
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0071270Z   Python3_ROOT_DIR: /Users/runner/hostedtoolcache/Python/3.12.10/x64
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0075330Z   UV_PYTHON_INSTALL_DIR: /Users/runner/work/_temp/uv-python-dir
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.0076430Z ##[endgroup]
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.6274030Z With the provided path, there will be 3 files uploaded
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.6285080Z Artifact name is valid!
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:11.6288480Z Root directory input is valid!
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:41.6807070Z ##[error]Failed to CreateArtifact: Unable to make request: ENOTFOUND
build / macos / amd64	UNKNOWN STEP	If you are using self-hosted runners, please make sure your runner has access to all GitHub endpoints: https://docs.github.com/en/actions/hosting-your-own-runners/managing-self-hosted-runners/about-self-hosted-runners#communication-between-self-hosted-runners-and-github
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:41.7341190Z Post job cleanup.
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:41.9774930Z [command]/usr/local/bin/git version
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:42.0773920Z git version 2.54.0
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:42.0850040Z Copying '/Users/runner/.gitconfig' to '/Users/runner/work/_temp/1ffceb06-0244-4505-b56e-3942a4df43ce/.gitconfig'
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:42.0853380Z Temporarily overriding HOME='/Users/runner/work/_temp/1ffceb06-0244-4505-b56e-3942a4df43ce' before making global git config changes
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:42.0855760Z Adding repository directory to the temporary git global config as a safe directory
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:42.0857810Z [command]/usr/local/bin/git config --global --add safe.directory /Users/runner/work/bandscope/bandscope
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:42.0859990Z Removing SSH command configuration
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:42.0861360Z [command]/usr/local/bin/git config --local --name-only --get-regexp core\.sshCommand
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:42.0865260Z [command]/usr/local/bin/git submodule foreach --recursive sh -c "git config --local --name-only --get-regexp 'core\.sshCommand' && git config --local --unset-all 'core.sshCommand' || :"
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:42.2384740Z Removing HTTP extra header
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:42.2394780Z [command]/usr/local/bin/git config --local --name-only --get-regexp http\.https\:\/\/github\.com\/\.extraheader
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:42.2535620Z [command]/usr/local/bin/git submodule foreach --recursive sh -c "git config --local --name-only --get-regexp 'http\.https\:\/\/github\.com\/\.extraheader' && git config --local --unset-all 'http.https://github.com/.extraheader' || :"
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:42.5537480Z Removing includeIf entries pointing to credentials config files
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:42.5584500Z [command]/usr/local/bin/git config --local --name-only --get-regexp ^includeIf\.gitdir:
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:42.5847040Z [command]/usr/local/bin/git submodule foreach --recursive git config --local --show-origin --name-only --get-regexp remote.origin.url
build / macos / amd64	UNKNOWN STEP	2026-06-25T09:04:42.7768190Z Cleaning up orphan processes

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head bounded evidence and found no blocking issues.

Findings

No blocking findings.

Summary

Verification posture: CodeGraph evidence was initialized and bounded current-head evidence reviewed for changed-file evidence including apps/desktop/package.json, package-lock.json.
Linter/static: workflow/static review evidence is bounded by the current-head GitHub Checks gate and changed-file evidence.
TDD/regression: coverage execution evidence and focused changed hunks were reviewed from bounded-review-evidence.md.
Coverage: coverage execution evidence proves 100% test coverage.
Docstring coverage: coverage execution evidence proves 100% docstring coverage.
DAG: Change Flow DAG maps apps/desktop/package.json through bounded evidence, review risk, and required checks.
PoC/execution: coverage-evidence job executed on the current head and reported PASS.
DDD/domain: workflow and repository-governance invariants were reviewed against changed files in bounded evidence.
CDD/context: CodeGraph evidence, changed-file history, and focused hunks were reviewed from bounded-review-evidence.md.
Similar issues: changed-file history evidence was reviewed for comparable local precedents.
Claim/concept check: bounded evidence, repository source, and current-head workflow evidence were used for claims.
Standards search: standards and external-source checks are delegated to configured OpenCode web_search/Context7/DeepWiki sources when applicable; no evidence-backed standards blocker is present in bounded evidence.
Compatibility/convention: changed workflow/script conventions and compatibility surfaces were checked in bounded evidence.
Breaking-change/backcompat: deployment evidence and changed-file history were checked for backward-compatibility risk.
Performance: changed surfaces were checked for performance risk in bounded evidence.
Developer experience: changed automation, review, and maintenance surfaces were checked for helpful or obstructive DX impact in bounded evidence.
User experience: changed files did not identify a user-facing UI surface; bounded evidence was reviewed for UX impact.
Security/privacy: workflow-token, review-gate, and repository-automation security/privacy boundaries were checked in bounded evidence.

  • Result: APPROVE
  • Reason: No blocking issues found in the PR. All changes are well-documented and tested.
  • Head SHA: e87e2073cbf310d90fbde9fcb18d9490a0b3bf9e
  • Workflow run: 28329049239
  • Workflow attempt: 1

@seonghobae
seonghobae enabled auto-merge June 29, 2026 09:05
opencode-agent[bot]
opencode-agent Bot previously approved these changes Jun 29, 2026

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode model attempts did not emit a usable current-head control block, so the approval gate used deterministic current-head evidence instead of model prose.

Findings

No blocking findings.

Summary

  • Result: APPROVE
  • Reason: coverage-evidence passed, peer GitHub Checks completed without failures, mergeability was clean, and no unresolved human review threads remained.
  • Deterministic evidence: current-head changed-file evidence (apps/desktop/package.json, package-lock.json); coverage-evidence result success; peer checks from statusCheckRollup excluding this OpenCode check.
  • Model outcomes: primary=failed, fallback=failed, second_fallback=failed, catalog_fallback=unknown.
  • Head SHA: 86acbe0622ccb62bbd18a59c09af2acff23c2590
  • Workflow run: 28404824893
  • Workflow attempt: 1

Deterministic fallback approval was used only after model-output instability and did not bypass coverage, failed-check, mergeability, or human-review gates.

Change Flow DAG

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file (2 files)"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file (2 files)"]
  R1 --> V1["required checks"]
Loading

@dependabot @github

dependabot Bot commented on behalf of github Jun 30, 2026

Copy link
Copy Markdown
Contributor Author

A newer version of lucide-react exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

@seonghobae

Copy link
Copy Markdown
Collaborator

Security refresh applied from #525 to clear the shared cargo-audit blocker.

Evidence:

  • Added commits 0485d77 and 0728df3 on top of this PR head; pushed head a6a2b02.
  • python3 scripts/checks/verify_supply_chain.py: passed.
  • cargo audit from apps/desktop/src-tauri: passed locally with the repo-owned audit config.
  • python3 scripts/checks/security_gates.py: passed.
  • git diff --check HEAD~2..HEAD: passed.

Security Notes:

  • No security gate was disabled or downgraded.
  • anyhow is refreshed to 1.0.103 for RUSTSEC-2026-0190.
  • RUSTSEC-2026-0194/0195 for quick-xml 0.39.4 remain documented as upstream-owned Tauri/plist and rfd/wayland-scanner transitive exceptions in repo-controlled cargo-audit/OSV configuration; remove the exception when compatible upstream crates move to quick-xml >=0.41.0.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head bounded evidence and found no blocking issues.

Findings

No blocking findings.

Summary

Approval sufficiency: bounded evidence supplied affirmative approval evidence for changed files, coverage/docstring posture, risk surfaces, and current-head verification; approval is not based merely on the absence of known blockers.
Verification posture: CodeGraph evidence was initialized and bounded current-head evidence reviewed for changed-file evidence including apps/desktop/package.json, apps/desktop/src-tauri/.cargo/audit.toml, apps/desktop/src-tauri/Cargo.lock, apps/desktop/src-tauri/osv-scanner.toml, docs/security/dependency-policy.md, and 1 more.
Linter/static: workflow/static review evidence is bounded by the current-head GitHub Checks gate and changed-file evidence.
TDD/regression: coverage execution evidence and focused changed hunks were reviewed from bounded-review-evidence.md.
Coverage: coverage execution evidence reports test coverage as not applicable because no supported changed source files or package manifests were found.
Docstring coverage: coverage execution evidence reports docstring coverage as not applicable because no supported changed source files or package manifests were found.
DAG: CodeGraph/source-backed behavior map connects apps/desktop/package.json to the affected review, runtime, or workflow path and required checks.
PoC/execution: coverage-evidence job executed on the current head and reported PASS.
DDD/domain: workflow and repository-governance invariants were reviewed against changed files in bounded evidence.
CDD/context: CodeGraph evidence, changed-file history, and focused hunks were reviewed from bounded-review-evidence.md.
Similar issues: changed-file history evidence was reviewed for comparable local precedents.
Claim/concept check: bounded evidence, repository source, current-head workflow evidence, and, where numeric, scientific, statistical, or literature-backed claims are affected, original-paper/formula evidence and parameter-recovery expectations were used for claims.
Standards search: standards and external-source checks are delegated to configured OpenCode web_search/Context7/DeepWiki sources when applicable; no evidence-backed standards blocker is present in bounded evidence.
Compatibility/convention: changed workflow/script conventions, object naming, and reserved-word safety for schema/API/config/code surfaces were checked in bounded evidence.
Breaking-change/backcompat: deployment evidence and changed-file history were checked for backward-compatibility risk.
Performance: changed surfaces were checked for performance risk in bounded evidence.
Developer experience: changed automation, review, test, setup, and maintenance surfaces were checked for helpful or obstructive DX impact in bounded evidence.
User experience: connected user, operator, API, CLI, documentation, review-comment, status-check, rendering, and workflow-reader behavior was checked for contradictions against code, docs, and tests in bounded evidence.
Visual/DOM: Playwright visual, DOM locator, ARIA snapshot, console, and responsive evidence were checked when a web UI surface was present; for non-web surfaces, API/CLI/log/docs/workflow interaction evidence was reviewed instead.
Accessibility/i18n: accessibility, localization, and human-readable text surfaces were checked where UI, CLI, API message, docs, logs, or review text changed.
Supply-chain/license: dependency, package, model, container, and external-tool changes were checked in bounded evidence.
Packaging: package, build, test, lint, and security contracts were checked in bounded evidence.
Security/privacy: workflow-token, review-gate, and repository-automation security/privacy boundaries were checked in bounded evidence.

  • Result: APPROVE
  • Reason: Dependency version bump with no material changes to source or test files.
  • Head SHA: a6a2b0292027e538c0477a3266bf8f8a390086a2
  • Workflow run: 28587520620
  • Workflow attempt: 1

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file (5 files)"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file (5 files)"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs: dependency-policy.md"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs: dependency-policy.md"]
  R2 --> V2["docs review"]
Loading

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head bounded evidence and found no blocking issues.

Findings

No blocking findings.

Summary

Approval sufficiency: bounded evidence supplied affirmative approval evidence for changed files, coverage/docstring posture, risk surfaces, and current-head verification; approval is not based merely on the absence of known blockers.
Verification posture: CodeGraph evidence was initialized and bounded current-head evidence reviewed for changed-file evidence including apps/desktop/package.json, package-lock.json.
Linter/static: workflow/static review evidence is bounded by the current-head GitHub Checks gate and changed-file evidence.
TDD/regression: coverage execution evidence and focused changed hunks were reviewed from bounded-review-evidence.md.
Coverage: coverage execution evidence reports test coverage as not applicable because no supported changed source files or package manifests were found.
Docstring coverage: coverage execution evidence reports docstring coverage as not applicable because no supported changed source files or package manifests were found.
DAG: CodeGraph/source-backed behavior map connects apps/desktop/package.json to the affected review, runtime, or workflow path and required checks.
PoC/execution: coverage-evidence job executed on the current head and reported PASS.
DDD/domain: workflow and repository-governance invariants were reviewed against changed files in bounded evidence.
CDD/context: CodeGraph evidence, changed-file history, and focused hunks were reviewed from bounded-review-evidence.md.
Similar issues: changed-file history evidence was reviewed for comparable local precedents.
Claim/concept check: bounded evidence, repository source, current-head workflow evidence, and, where numeric, scientific, statistical, or literature-backed claims are affected, original-paper/formula evidence and parameter-recovery expectations were used for claims.
Standards search: standards and external-source checks are delegated to configured OpenCode web_search/Context7/DeepWiki sources when applicable; no evidence-backed standards blocker is present in bounded evidence.
Compatibility/convention: changed workflow/script conventions, object naming, and reserved-word safety for schema/API/config/code surfaces were checked in bounded evidence.
Breaking-change/backcompat: deployment evidence and changed-file history were checked for backward-compatibility risk.
Performance: changed surfaces were checked for performance risk in bounded evidence.
Developer experience: changed automation, review, test, setup, and maintenance surfaces were checked for helpful or obstructive DX impact in bounded evidence.
User experience: connected user, operator, API, CLI, documentation, review-comment, status-check, rendering, and workflow-reader behavior was checked for contradictions against code, docs, and tests in bounded evidence.
Visual/DOM: Playwright visual, DOM locator, ARIA snapshot, console, and responsive evidence were checked when a web UI surface was present; for non-web surfaces, API/CLI/log/docs/workflow interaction evidence was reviewed instead.
Accessibility/i18n: accessibility, localization, and human-readable text surfaces were checked where UI, CLI, API message, docs, logs, or review text changed.
Supply-chain/license: dependency, package, model, container, and external-tool changes were checked in bounded evidence.
Packaging: package, build, test, lint, and security contracts were checked in bounded evidence.
Security/privacy: workflow-token, review-gate, and repository-automation security/privacy boundaries were checked in bounded evidence.

  • Result: APPROVE
  • Reason: Safe dependency update with no breaking changes
  • Head SHA: 42656498e14593d6a580fac33e8ae61ea2cbde98
  • Workflow run: 28623102993
  • Workflow attempt: 1

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file (2 files)"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file (2 files)"]
  R1 --> V1["required checks"]
Loading

@seonghobae seonghobae closed this Jul 7, 2026
auto-merge was automatically disabled July 7, 2026 05:09

Pull request was closed

@dependabot @github

dependabot Bot commented on behalf of github Jul 7, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@seonghobae seonghobae reopened this Jul 7, 2026
@opencode-agent
opencode-agent Bot enabled auto-merge (squash) July 7, 2026 05:10
@seonghobae

Copy link
Copy Markdown
Collaborator

Closing during org-wide PR backlog reduction. This looks like a low-priority automated maintenance PR (dependency bump), while the repository has a large backlog of security, conflict, and required-workflow work. Reopen or recreate a fresh PR if this change is still needed.

@seonghobae seonghobae closed this Jul 7, 2026
auto-merge was automatically disabled July 7, 2026 07:55

Pull request was closed

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/develop/lucide-react-1.21.0 branch July 7, 2026 07:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant