| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Bumps [browserslist](https://github.com/browserslist/browserslist) from 4.16.6 to 4.28.8. - [Release notes](https://github.com/browserslist/browserslist/releases) - [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md) - [Commits](browserslist/browserslist@4.16.6...4.28.8) --- updated-dependencies: - dependency-name: browserslist dependency-version: 4.28.8 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Scope — Lockfile-only Dependabot update refreshing lifeomic-sample-graphql-client-app/yarn.lock so transitive browserslist resolves to 4.28.8 (from 4.16.6). Worth merging to pick up current browser-target data, parsing fixes, and security patches (prototype pollution, ReDoS, unbounded memory growth) without manifest or application source changes.
CI — Checks were still pending at review time; branch protection will gate merge on completion.
Regression risk — Low: semver-compatible transitive bump within existing ^4.x ranges; no direct manifest edit or app code touched.
Upstream: unknown (author to confirm)
Residual risks / follow-ups
None — because this is a mechanical lockfile refresh for a build-time tooling dependency with no application/runtime source edits and existing semver ranges preserved.
Note: Review generated using Cursor model composer-2.5.
This review was generated by review-bot.
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Bumps browserslist from 4.16.6 to 4.28.8.
Release notesSourced from browserslist's releases.
... (truncated)
ChangelogSourced from browserslist's changelog.
... (truncated)
Commits- f2f2e6c Release 4.28.8 version
- d0787c8 Update dependencies
- fcf8fa9 Merge pull request #939 from Jaybhade/fix/baseline-kaios-without-downstream
- 57ecd64 fix: support "including kaios" without downstream
- 093a0f6 Update EM banner
- b637868 Release 4.28.7 version
- 313f465 Update dependencies
- c935c5a Fix regexp performance
- d7e9e65 Rewrite structure parsing to make it always fast
- ec4a55e Fix import order
- Additional commits viewable in compare view
Maintainer changesThis version was pushed to npm by GitHub Actions, a new releaser for browserslist since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
You can disable automated security fix PRs for this repo from the Security Alerts page.