Follow-up from #16. An independent review of the combined dependency update found that some resolved versions were published only 1–5 days before the update. For example, rolldown 1.2.10 came out 1 day before, @oxc-project/types 0.151.0 3 days before, and tsx 4.23.15 4 days before.
The repo has no soak period for new releases. There is no .github/dependabot.yml cooldown and no npm minimum-release-age setting.
Proposal: pick one of these.
- Add a Dependabot config with a
cooldown (for example 3–7 days).
- Document a minimum release age for manual
npm update runs.
This is not a blocker: all 92 packages have verified registry signatures, and npm audit reports 0 vulnerabilities.
Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high
Follow-up from #16. An independent review of the combined dependency update found that some resolved versions were published only 1–5 days before the update. For example, rolldown 1.2.10 came out 1 day before,
@oxc-project/types0.151.0 3 days before, and tsx 4.23.15 4 days before.The repo has no soak period for new releases. There is no
.github/dependabot.ymlcooldown and no npm minimum-release-age setting.Proposal: pick one of these.
cooldown(for example 3–7 days).npm updateruns.This is not a blocker: all 92 packages have verified registry signatures, and
npm auditreports 0 vulnerabilities.Generated with
xum• Model:anthropic:claude-opus-5-5• Thinking:high