Skip to content

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.20 to 2026.8.25 - #58

Merged
unbraind merged 4 commits into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.25
Aug 29, 2026
Merged

chore(deps-dev): bump @unbrained/pm-cli from 2026.8.20 to 2026.8.25#58
unbraind merged 4 commits into
mainfrom
dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.25

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 28, 2026

Copy link
Copy Markdown
Contributor

Bumps @unbrained/pm-cli from 2026.8.20 to 2026.8.25.

Release notes

Sourced from @​unbrained/pm-cli's releases.

v2026.8.25

@​unbrained/pm-cli 2026.8.25

Source range: v2026.8.24...v2026.8.25

Changelog

Fixed

  • GH-1104: health must not certify pending lossless merge receipts as reconciled (pm-baksix)
  • Dynamic-read continuation cursors are born stale: pm health emits a cursor that its next invocation rejects (pm-oahhyc)
  • GH-1105: contracts must declare each command projection vocabulary before invocation (pm-q4isdq)
  • The outcome-milestone ladder is a sibling set rather than a layer: 1,024 terminal items reach the roadmap apex through 154 typed roots without traversing any outcome milestone (pm-h6b73t)

Security

PM Tracker Evidence

No closed pm tracker items were updated in the selected release window.

v2026.8.24

@​unbrained/pm-cli 2026.8.24

Source range: v2026.8.23...v2026.8.24

Changelog

Fixed

  • Structured release-failure causes are preserved in blocked-release alerts (pm-x63izf)
  • Bulk writes accept newline/comma IDs from argv, stdin, and @​path with effect-aware exits (pm-3oq022)
  • update-many --dry-run allows filter-only preview for review and bulk-selection workflows (pm-kexu)
  • Releases from the default branch are supported with analyzer evidence (pm-u1baah)

Other

  • Uniform stdin convention: body-file and annotation --file flags accept '-' for stdin (pm-iktj)
  • Single source of surface tiering: one contract-declared tier per command drives CLI help, MCP tool profiles, completions, and docs together (pm-kxci8x)

PM Tracker Evidence

pm tracker summary skipped: Command failed: /opt/hostedtoolcache/node/24.19.0/x64/bin/node /home/runner/work/pm-cli/pm-cli/dist/cli.js list-all --json Deprecated command list-all; use pm list --all.

v2026.8.23

@​unbrained/pm-cli 2026.8.23

Source range: v2026.8.22...v2026.8.23

... (truncated)

Changelog

Sourced from @​unbrained/pm-cli's changelog.

2026.8.25 - 2026-08-25

Fixed

  • GH-1104: health must not certify pending lossless merge receipts as reconciled (pm-baksix)
  • Dynamic-read continuation cursors are born stale: pm health emits a cursor that its next invocation rejects (pm-oahhyc)
  • GH-1105: contracts must declare each command projection vocabulary before invocation (pm-q4isdq)
  • The outcome-milestone ladder is a sibling set rather than a layer: 1,024 terminal items reach the roadmap apex through 154 typed roots without traversing any outcome milestone (pm-h6b73t)

Security

2026.8.24 - 2026-08-24

Fixed

  • Structured release-failure causes are preserved in blocked-release alerts (pm-x63izf)
  • Bulk writes accept newline/comma IDs from argv, stdin, and @​path with effect-aware exits (pm-3oq022)
  • update-many --dry-run allows filter-only preview for review and bulk-selection workflows (pm-kexu)
  • Releases from the default branch are supported with analyzer evidence (pm-u1baah)

Other

  • Uniform stdin convention: body-file and annotation --file flags accept '-' for stdin (pm-iktj)
  • Single source of surface tiering: one contract-declared tier per command drives CLI help, MCP tool profiles, completions, and docs together (pm-kxci8x)

2026.8.23 - 2026-08-23

Added

  • Every instruction the product emits about its own next command is an unexecuted claim: the recovery vocabulary is generated, asserted as text, and run by nothing (pm-h8tpeh)

Changed

  • Update ESLint to compatible 10.9.0 release (pm-940mcx)

Fixed

  • Allow linked tests to opt out of source-workspace injection for self-sandboxing repo-wide gates (pm-efkvdy)
  • Linked-test schema context changes non-PM repository checks, so commands that pass directly fail when recorded and run through pm test (pm-e97jyf)
  • GH-1089: expose reproducible execution through supported CLI and MCP process configuration (pm-gh1089)
  • Budget recovery can recommend a smaller ceiling than the request that already truncated (pm-xam9bt)

Security

  • Linked-test commands are merge-unioned workspace data executed with shell:true — no provenance, allowlist, or confirmation boundary (pm-ed28wi)
  • Cross-harness provenance adapters: automatically resolve native model, version, and effort signals beyond Claude without identity flags (pm-c0lrdm)

Other

... (truncated)

Commits
  • fb094d0 chore(release): cut 2026.8.25
  • 32d7b0e Merge pull request #1111 from unbraind/codex/gh-1109-tracker-intake
  • 92261ed fix(pm): align intake prose with typed graph
  • 230c559 fix(pm): preserve typed intake graph budget
  • 7046585 chore(pm): track GH-1109 sandbox history drift
  • e4afd89 chore(pm): close CodeQL 4.37.8 delivery (#1110)
  • 0ef4d40 Publish exact projections and stabilize read recovery (#1108)
  • 9ad2ac8 chore(pm): refresh ecosystem roadmap and graph governance
  • 1210ae0 chore(pm): record 2026.8.24 release health (#1107)
  • 1c1fcf8 chore(release): cut 2026.8.24
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​unbrained/pm-cli since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 28, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.25 branch from c959a11 to dee83c6 Compare August 28, 2026 20:55
@unbraind

Copy link
Copy Markdown
Owner

Retargeted this bump to exact @unbrained/pm-cli 2026.8.28, including the lockfile. The pinned binary reports 2026.8.28 and ./node_modules/.bin/pm health --strict-exit exits 0. Local npm test and release:check pass. Please run the full review round on the current head.

@greptileai review
/gemini review
@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Aug 28, 2026

Copy link
Copy Markdown

@unbraind: I will run a full review of the current head, including the exact dependency and lockfile update.

✅ Action performed

Full review finished.

@coderabbitai

coderabbitai Bot commented Aug 28, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

Next included review available in 54 minutes.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 90c844f4-dcb8-4bfe-bfea-ccbd25907ac7

📥 Commits

Reviewing files that changed from the base of the PR and between b52aab0 and 925bc23.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (4)
  • .agents/pm/history/pm-github-5igz.jsonl
  • .agents/pm/issues/pm-github-5igz.toon
  • package.json
  • test/compatibility-floor.test.ts

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: cf47fc10-cdd0-4507-bb78-88184555e0a5

📥 Commits

Reviewing files that changed from the base of the PR and between b52aab0 and bbfd050.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (3)
  • .agents/pm/history/pm-github-5igz.jsonl
  • .agents/pm/issues/pm-github-5igz.toon
  • package.json

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


Summary by CodeRabbit

  • Chores
    • Updated the development tooling to version 2026.8.28.
    • Added verification coverage for strict-exit health checks.
    • Updated project tracking records with the latest verification details.

Walkthrough

The PM CLI development dependency is pinned to version 2026.8.28. Issue and history records document the retarget and add verification for pm health --strict-exit.

Changes

PM CLI pin update

Layer / File(s) Summary
Update PM CLI dependency
package.json
Pins @unbrained/pm-cli to 2026.8.28.
Record pin verification
.agents/pm/history/pm-github-5igz.jsonl, .agents/pm/issues/pm-github-5igz.toon
Records the pull request retarget, exact pin verification, and pm health --strict-exit validation.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to bbfd0

This updates a development dependency and related lockfile metadata; no actionable merge-blocking risk remains after normal checks and review.

Suggested reviewers: unbraind

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title correctly identifies a development dependency bump, but it names 2026.8.25 while the current changeset targets 2026.8.28.
Description check ✅ Passed The description is related to the dependency update and provides release notes, although it describes the earlier 2026.8.25 target rather than the current 2026.8.28 target.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (3 skipped: 3 unsupported.)

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.25

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Aug 28, 2026

Copy link
Copy Markdown

Greptile Summary

The PR updates the exact development pin for @unbrained/pm-cli from 2026.8.20 to 2026.8.28 while retaining 2026.8.20 as the consumer compatibility floor.

  • Refreshes the lockfile for the new CLI and its transitive dependencies.
  • Adjusts the compatibility test to allow an exact development pin at or above the declared minimum.
  • Records validation metadata and the corresponding changelog entry.

Confidence Score: 5/5

The PR appears safe to merge.

No blocking failure remains.

Important Files Changed

Filename Overview
package.json Updates the exact pm CLI development dependency while leaving the public peer-dependency floor unchanged.
package-lock.json Locks pm CLI 2026.8.28 and its updated transitive dependency graph with integrity metadata.
test/compatibility-floor.test.ts Replaces strict equality with numeric component-wise floor validation, resolving the previously reported compatibility-test failure.

Reviews (3): Last reviewed commit: "chore(deps-dev): record dependency bump ..." | Re-trigger Greptile

Comment thread package.json
@unbraind

Copy link
Copy Markdown
Owner

Re-review the current head after reconciling test/compatibility-floor.test.ts: the manifest and peer dependency remain a 2026.8.20 consumer minimum, while CI now uses the exact-pinned fleet CLI 2026.8.28. The compatibility test now accepts newer exact development pins. npm test, npm run release:check, and ./node_modules/.bin/pm health --strict-exit pass locally.

@greptileai review
/gemini review
@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Aug 28, 2026

Copy link
Copy Markdown

@unbraind I will run a full review of the current head. I will verify the compatibility-floor logic, the 2026.8.20 consumer minimum, and the exact 2026.8.28 development pin.

⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 54 minutes.

dependabot Bot and others added 4 commits August 29, 2026 07:27
Bumps [@unbrained/pm-cli](https://github.com/unbraind/pm-cli) from 2026.8.20 to 2026.8.25.
- [Release notes](https://github.com/unbraind/pm-cli/releases)
- [Changelog](https://github.com/unbraind/pm-cli/blob/main/CHANGELOG.md)
- [Commits](unbraind/pm-cli@v2026.8.20...v2026.8.25)

---
updated-dependencies:
- dependency-name: "@unbrained/pm-cli"
  dependency-version: 2026.8.25
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Track the post-rebase pm CLI 2026.8.28 compatibility, coverage, changelog, and strict health verification.
@unbraind
unbraind force-pushed the dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.25 branch from 925bc23 to 4e8564d Compare August 29, 2026 05:30
@unbraind

Copy link
Copy Markdown
Owner

@greptileai review

@unbraind

Copy link
Copy Markdown
Owner

/gemini review

@unbraind

Copy link
Copy Markdown
Owner

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Aug 29, 2026

Copy link
Copy Markdown

Rate Limit Exceeded

@unbraind have exceeded the limit for the number of chat messages per hour. Please wait 24 minutes and 7 seconds before sending another message.

@unbraind
unbraind merged commit bbd06f2 into main Aug 29, 2026
8 checks passed
@unbraind
unbraind deleted the dependabot/npm_and_yarn/unbrained/pm-cli-2026.8.25 branch August 29, 2026 05:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant