Skip to content

build(deps): bump ip-address from 10.7.0 to 10.7.2 in /scripts/ci/noema-document-reader - #2534

Draft
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/scripts/ci/noema-document-reader/ip-address-10.7.2
Draft

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/scripts/ci/noema-document-reader/ip-address-10.7.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps ip-address from 10.7.0 to 10.7.2.

Release notes

Sourced from ip-address's releases.

v10.7.2

What's Changed

Full Changelog: beaugunderson/ip-address@v10.7.1...v10.7.2

v10.7.1

What's Changed

Full Changelog: beaugunderson/ip-address@v10.7.0...v10.7.1

Commits
  • 974b48d 10.7.2
  • 4dfe8e5 Accept an arpa suffix in any case and without the root dot in fromArpa (#227)
  • f0c25df 10.7.1
  • 8b34a21 Merge commit from fork
  • 13b6155 Merge commit from fork
  • 469ead1 Reject an address longer than the family allows before parsing it
  • 1343629 Report an address of the other family as not contained
  • 4c2184a Bump js-yaml and brace-expansion in the lockfile (#226)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.7.0 to 10.7.2.
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](beaugunderson/ip-address@v10.7.0...v10.7.2)

---
updated-dependencies:
- dependency-name: ip-address
  dependency-version: 10.7.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot
dependabot Bot requested a review from seonghobae as a code owner September 30, 2026 05:02
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: c2d3a23f-73ca-45a6-969b-3d91e3f1644e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cwl-noema-review cwl-noema-review Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Noema LLM review

The pull request performs a patch-level dependency update for the ip-address package from 10.7.0 to 10.7.2 in the noema-document-reader project. This is a standard maintenance update to keep dependencies current.

Reviewed changed lines

  • scripts/ci/noema-document-reader/package-lock.json:672 (RIGHT): Updating version to 10.7.2.
  • scripts/ci/noema-document-reader/package-lock.json:673 (RIGHT): Updating resolution URL to point to version 10.7.2.
  • scripts/ci/noema-document-reader/package-lock.json:674 (RIGHT): Updating integrity hash for the new version.

Adversarial validation

  • scripts/ci/noema-document-reader/package-lock.json:672 (RIGHT) falsified: The version bump introduces a breaking change to IP parsing logic. — Version numbering follows SemVer; 10.7.0 -> 10.7.2 is a patch update.
  • scripts/ci/noema-document-reader/package-lock.json:674 (RIGHT) falsified: The new integrity hash corresponds to a compromised package. — Hash sha512-7H/2gFSIitxc0hG3nOI1glS8QLo/EHBFFLk8vEUjXY/xu0AdL8jZ9U1IzO2PUm0d2D/ofQcAifb0g6OBkt8U7w== matches registry.
  • Residual risk: negligible

Findings

  • No blocking findings.
  • Result: APPROVE
  • Head SHA: b2a96ecfcbfaa807ea8ee6d4f67bed08efcc2787
  • Reviewer credential: noema-review-github-app-refresh
  • Actor: cwl-noema-review[bot]

@seonghobae
seonghobae marked this pull request as draft September 30, 2026 14:44

Copy link
Copy Markdown
Contributor

Ready is review admission only. Exact head b2a96ecfcbfaa807ea8ee6d4f67bed08efcc2787 has terminal non-GREEN evidence: CodeQL PR run 36671573526 = failure; Python Security run 36671573558 = failure; Security Scan run 36671573474 = failure. I moved the PR back to Draft. A queued or later run cannot rewrite this exact-head terminal record; return to Ready only on a new exact head with applicable terminal GREEN checks and qualifying independent review. No rerun, status synthesis, bypass, force push, destructive rebase, merge, or closure was used.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.

Findings

1. HIGH Current-head GitHub Checks - Fix failed required checks before approval

  • Problem: Failed same-head checks remain for b2a96ecfcbfaa807ea8ee6d4f67bed08efcc2787.
  • Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
  • Fix: Read and fix the failed check logs below, then rerun the current-head checks.
  • Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.

Failed checks:

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["CI script: package-lock.json"]
  S1 --> I1["review and security gate shell path"]
  I1 --> R1["Review risk: CI script: package-lock.json"]
  R1 --> V1["bash -n plus Strix self-test"]
Loading

@opencode-agent

opencode-agent Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant