Skip to content

🚨 Update dependency toml to v5 (main) - autoclosed - #538

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/main-major-npm-dependencies
Closed

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/main-major-npm-dependencies

Conversation

@renovate

@renovate renovate Bot commented Apr 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
toml ^3.0.0 → ^5.0.0 age adoption passing confidence

Release Notes

BinaryMuse/toml-node (toml)

v5.0.0

Compare Source

=====================

  • Breaking: Integers outside JavaScript's safe range (beyond ±Number.MAX_SAFE_INTEGER) now throw a parse error instead of silently returning a rounded value (#​28). Opt in to lossless handling of the full 64-bit range with toml.parse(input, { bigint: true }), which returns all integer values as BigInt.
  • Breaking: Integers outside TOML's 64-bit signed integer range now throw a parse error in either mode, as required by the spec. Previously they were silently rounded.

v4.3.0

Compare Source

=====================

  • Add opt-in Temporal support via toml.parse(input, { useTemporal: true }), mapping offset date-times to Temporal.ZonedDateTime and local date-times/dates/times to Temporal.PlainDateTime/PlainDate/PlainTime. An implementation can be supplied via the temporal option on runtimes without a Temporal global. (#​69)

v4.2.0

Compare Source

=====================

  • Address security advisory GHSA-82x6-q7mm-w9cf (CVE pending), in which deeply nested arrays or inline tables could overflow the call stack and crash the process with an uncatchable RangeError. Nesting is now bounded (default 500 levels), and input past the limit throws a normal parse error. The limit is configurable via toml.parse(input, { maxDepth }).

v4.1.2

Compare Source

=====================

  • Address CVE-2026-63376, in which a specially crafted TOML string could pollute Object.prototype process-wide.

v4.1.1

Compare Source

=====================

  • Increase performance ~5x (#​68)

v4.1.0

Compare Source

=====================

  • Add spec v1.1.0 support (#​67)

v4.0.1

Compare Source

=====================

  • Minor packaging changes

v4.0.0

Compare Source

=====================

  • Modernize tooling and support TOML v1.0.0 spec (#​66)


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Apr 1, 2026

Copy link
Copy Markdown
Contributor

🚀 Preview is available at https://c590c090.enterprise-contract.pages.dev

@renovate
renovate Bot force-pushed the renovate/main-major-npm-dependencies branch from 76c56ab to 95624e2 Compare April 1, 2026 04:54
@github-actions

github-actions Bot commented Apr 1, 2026

Copy link
Copy Markdown
Contributor

🚀 Preview is available at https://f6fec5f2.enterprise-contract.pages.dev

@renovate
renovate Bot force-pushed the renovate/main-major-npm-dependencies branch from 95624e2 to d32374e Compare April 29, 2026 13:52
@github-actions

Copy link
Copy Markdown
Contributor

🚀 Preview is available at https://753bf21a.enterprise-contract.pages.dev

@renovate renovate Bot changed the title 🚨 Update dependency toml to v4 (main) 🚨 Update npm dependencies to v4 (main) Jun 2, 2026
@renovate renovate Bot changed the title 🚨 Update npm dependencies to v4 (main) 🚨 Update npm dependencies (main) (major) Jun 22, 2026
@renovate renovate Bot changed the title 🚨 Update npm dependencies (main) (major) 🚨 Update dependency toml to v4 (main) Jun 25, 2026
@renovate
renovate Bot force-pushed the renovate/main-major-npm-dependencies branch from d32374e to 7676470 Compare June 30, 2026 19:10
@github-actions

Copy link
Copy Markdown
Contributor

🚀 Preview is available at https://a40ae905.enterprise-contract.pages.dev

@renovate
renovate Bot force-pushed the renovate/main-major-npm-dependencies branch from 7676470 to 8e4b407 Compare July 12, 2026 17:05
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 12, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:06 PM UTC · Completed 5:10 PM UTC
Commit: 87c4a29 · View workflow run →

@github-actions

Copy link
Copy Markdown
Contributor

🚀 Preview is available at https://a9aba9aa.enterprise-contract.pages.dev

@fullsend-ai-review

fullsend-ai-review Bot commented Jul 12, 2026 •

Copy link
Copy Markdown

Looks good to me

Previous run

Looks good to me

Previous run (2)

Review — approve

PR: #538 — Update dependency toml to v5
Author: renovate[bot]

Summary

This Renovate PR bumps the toml dev dependency from ^3.0.0 to ^5.0.0 in antora/package.json, skipping v4. The lock file is regenerated accordingly.

Analysis

Correctness. The toml package is used in exactly one place — antora/supplemental-ui/helpers/parseHugoMenu.js — where it parses menu.toml via toml.parse(fileContent). The parsed TOML file contains only string values and small integer weight fields (10–80). The v5.0.0 breaking change (integers outside Number.MAX_SAFE_INTEGER now throw instead of silently rounding) does not affect this usage. The core toml.parse() API is stable across all major versions. The project's Node 24 engine constraint satisfies toml v5's node >= 20 requirement.

Security. The upgrade incorporates two security fixes from the v4.x line:

While toml is a dev dependency used only at build time, these fixes eliminate attack surface if untrusted TOML is ever introduced into the build pipeline.

Intent & coherence. Standard Renovate dependency update. The two-major-version jump is expected — Renovate groups major bumps when the intermediate version is also a major release. The change is appropriately scoped to the dependency declaration and lock file.

Style/conventions. The lock file diff includes removal of "peer": true from several unrelated packages (chevrotain, cytoscape, d3-selection, acorn). This is a normal artifact of npm lock file regeneration when transitive dependency metadata changes. Benign.

Documentation. No documentation changes needed for a dev dependency update.

Cross-repo contracts. No cross-repo impact — toml is consumed only by the Antora build process within this repository.

Verdict

Approve. The upgrade is safe for this project's usage pattern, picks up meaningful security patches, and the breaking changes are inapplicable. The build should be verified via CI before merging.

Previous run (3)

Review — approve

Dependency update: toml v3 → v4 (major)

This Renovate-generated PR bumps the toml npm package from ^3.0.0 to ^4.0.0 in the antora/ subdirectory. Two files are changed: antora/package.json (version specifier) and antora/package-lock.json (resolved version and lockfile refresh).

Correctness

The only call site is antora/supplemental-ui/helpers/parseHugoMenu.js, which uses require("toml") and toml.parse(fileContent). The parse() API is unchanged in v4. The parsed file (menu.toml) uses standard TOML syntax — arrays of tables, strings, integers, and multiline basic strings — all of which are fully supported. The project requires Node.js 24, which satisfies v4's engine constraint of >=20.

The lockfile also removes "peer": true from several transitive dependencies (chevrotain, cytoscape, d3-selection, acorn). These are normal artifacts of npm regenerating the lockfile and do not indicate functional changes.

Security

This upgrade is security-beneficial. v4 includes fixes for:

  • Prototype pollution (GHSA-v5mp-jgw5-2x6j, v4.1.2) — crafted TOML strings could pollute Object.prototype process-wide
  • Stack overflow via deep nesting (GHSA-82x6-q7mm-w9cf, v4.2.0) — deeply nested arrays/inline tables could crash the process with an uncatchable RangeError

Scope & intent

Standard Renovate major dependency update, appropriately scoped to antora/package.json and its lockfile. No source code changes.

No findings

No issues identified. The upgrade is compatible with the existing API usage, satisfies engine constraints, and brings important security fixes.

Previous run (4)

Review — approve ✅

This Renovate PR bumps the toml devDependency from ^3.0.0 to ^4.0.0 (resolved to 4.1.2) in the Antora documentation build tooling.

Changes reviewed

File What changed
antora/package.json Version range updated ^3.0.0 → ^4.0.0
antora/package-lock.json Resolved version 3.0.0 → 4.1.2; added license and engines fields; minor peer marker changes on transitive dependencies

Analysis

API compatibility — The sole usage of toml in this repo is in antora/supplemental-ui/helpers/parseHugoMenu.js, which calls toml.parse(fileContent) on a simple TOML file (antora/menu.toml) containing basic arrays of tables. The parse() function is the core API preserved across major versions. The TOML content uses only fundamental spec features (string values, arrays of tables) compatible with both TOML v0.5 and v1.0/v1.1.

Node.js engine requirement — toml@4.1.2 requires node >= 20. The project's package.json specifies "node": "24", so this constraint is satisfied.

Security — v4.1.2 includes a fix for prototype pollution via crafted TOML input (GHSA-v5mp-jgw5-2x6j). Adopting this version eliminates that vulnerability.

Lock file integrity — The removal of "peer": true markers from several transitive dependencies (chevrotain, cytoscape, d3-selection, acorn) is a normal artifact of npm regenerating the lock file and does not affect runtime behavior.

Scope — This is a devDependency used exclusively for documentation site generation. It is not bundled into any production artifact.

No blocking findings identified.

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added the ready-for-merge All reviewers approved — ready to merge label Jul 12, 2026
@renovate
renovate Bot force-pushed the renovate/main-major-npm-dependencies branch from 8e4b407 to 79a026d Compare July 13, 2026 23:07
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 13, 2026 •

Copy link
Copy Markdown

🤖 Review · ❌ Terminated · Started 11:08 PM UTC · Ended 11:12 PM UTC
Commit: 87c4a29 · View workflow run →

@github-actions

Copy link
Copy Markdown
Contributor

🚀 Preview is available at https://655c7351.enterprise-contract.pages.dev

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added ready-for-merge All reviewers approved — ready to merge and removed ready-for-merge All reviewers approved — ready to merge labels Jul 13, 2026
@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 11:08 PM UTC · Completed 11:12 PM UTC
Commit: 87c4a29 · View workflow run →

@renovate
renovate Bot force-pushed the renovate/main-major-npm-dependencies branch from 79a026d to b44fb51 Compare July 14, 2026 23:34
@renovate renovate Bot changed the title 🚨 Update dependency toml to v4 (main) 🚨 Update dependency toml to v5 (main) Jul 14, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Jul 14, 2026 •

Copy link
Copy Markdown

🤖 Review · ❌ Terminated · Started 11:35 PM UTC · Ended 11:39 PM UTC
Commit: 87c4a29 · View workflow run →

@github-actions

Copy link
Copy Markdown
Contributor

🚀 Preview is available at https://b1273cfa.enterprise-contract.pages.dev

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added ready-for-merge All reviewers approved — ready to merge and removed ready-for-merge All reviewers approved — ready to merge labels Jul 14, 2026
@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 11:35 PM UTC · Completed 11:39 PM UTC
Commit: 87c4a29 · View workflow run →

@renovate
renovate Bot force-pushed the renovate/main-major-npm-dependencies branch from b44fb51 to 8688eff Compare September 2, 2026 17:55
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:57 PM UTC · Completed 6:17 PM UTC

Commit: ca5794c · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $4.26

@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

🚀 Preview is available at https://2dd497a8.enterprise-contract.pages.dev

@fullsend-ai-review fullsend-ai-review Bot added the risk/moderate PR risk: moderate label Sep 2, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Risk Assessment: moderate (2/5)

Details

Bot-authored major dependency upgrade (toml v5) touching only package.json and package-lock.json in the antora directory with minimal change size (2 files, 20 lines), no protected paths, no security-sensitive files, and no CI workflow changes.

Previous run

Risk Assessment: moderate (2/5)

Details

Bot-authored major dependency upgrade (toml v5) touching only package.json and package-lock.json in the antora directory with minimal change size (2 files, 20 lines), no protected paths, no security-sensitive files, and no CI workflow changes.

fullsend-ai-review[bot]

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/main-major-npm-dependencies branch from 8688eff to 21ecdf5 Compare September 3, 2026 16:50
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 3, 2026 •

Copy link
Copy Markdown

🤖 Review · ❌ Terminated · Started 4:51 PM UTC · Ended 5:11 PM UTC

Commit: ca5794c · View workflow run →

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

🚀 Preview is available at https://4aefd665.enterprise-contract.pages.dev

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 4:51 PM UTC · Completed 5:11 PM UTC

Commit: ca5794c · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $3.48

@renovate renovate Bot changed the title 🚨 Update dependency toml to v5 (main) 🚨 Update dependency toml to v5 (main) - autoclosed Sep 4, 2026
@renovate renovate Bot closed this Sep 4, 2026
@renovate
renovate Bot deleted the renovate/main-major-npm-dependencies branch September 4, 2026 01:50
@fullsend-ai-retro

fullsend-ai-retro Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 1:51 AM UTC · Completed 1:55 AM UTC

Commit: ca5794c · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $1.01

@fullsend-ai-retro

Copy link
Copy Markdown

Retro on conforma/conforma.github.io#538 — no new proposals

What happened. Renovate opened this PR on 2026-04-01 to bump the dev-only dependency toml from ^3.0.0 to ^5.0.0 in antora/. Over ~5 months the branch was rebased several times by Renovate; each rebase re-triggered the fullsend review agent. Across the PR's lifetime, the review agent produced 5 unanimous APPROVED reviews on 5 different head SHAs, with no findings and no human ever weighing in. The two most recent runs alone cost $4.26 (run 33664141178) and $3.48 (run 33781065490) at effort=high on opus. Despite the ready-for-merge label being applied, no merge occurred; Renovate ultimately autoclosed the PR on 2026-09-04 (superseded by a newer update PR). All review compute on this PR was effectively wasted.

Everything worth proposing is already tracked. The patterns this retro observed are covered by open issues; filing more would create noise:

  • Auto-merge / skip pipeline for low-risk bot dependency PRs: fullsend-ai/fullsend#3016, #691, #336, #4975, #4989, #4825, #5067, #3347; agents-layer: fullsend-ai/agents#257, #1132. New evidence: 5 unanimous agent approvals over 5 months on a dev-only Renovate bump that ultimately autoclosed unmerged — a strong-signal case for the pre-review early-exit / auto-merge path.
  • Review re-runs on the same head SHA: fullsend-ai/fullsend#4022, #4960. New evidence: head SHA 21ecdf5... was formally APPROVED 3 times (2026-07-14, 2026-09-02, 2026-09-03) with no diff between runs — ~$8 in reviewer spend across those three approvals alone.
  • Skip agent dispatch for PRs that are already closed / superseded: fullsend-ai/fullsend#6725, #1398. New evidence: at least one review dispatched on 2026-09-04 (run 33827277300) around the moment the PR was being autoclosed by Renovate.
  • Autonomy-readiness tracking for review agent on Renovate dep bumps: already tracked per-repo in #3068, #4835, #5010, #5118, #5145. This PR is another consistent data point (bot-authored, moderate 2/5 risk, dev-only, 5/5 agent-approved, zero human churn) but does not warrant a new per-repo tracking issue on its own.

Discovery note. Agents repo resolved from run log as fullsend-ai/agents@v0.40.0 (commit 81b0e9bde0fa).

No proposals filed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

main major ready-for-merge All reviewers approved — ready to merge renovate risk/moderate PR risk: moderate size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants