chore(deps-dev): bump esbuild from 0.27.7 to 0.28.1 - #3256
Conversation
Bumps [esbuild](https://github.com/evanw/esbuild) from 0.27.7 to 0.28.1. - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md) - [Commits](evanw/esbuild@v0.27.7...v0.28.1) --- updated-dependencies: - dependency-name: esbuild dependency-version: 0.28.1 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
Astro-Han
left a comment
There was a problem hiding this comment.
Approved exact head fda6ba7031e977c169d726b289be23d025e4e093.
This is a mechanical Dependabot update from esbuild 0.27.7 to 0.28.1. I verified that both direct workspace ranges and all platform binaries converge on 0.28.1; the large lockfile deletion is the expected removal of the now-redundant nested esbuild copy, not unrelated dependency loss. The upstream delta includes security and correctness fixes, and I found no P0–P3 issue in the repository integration.
Dependabot identifies the automation and source release material, so no generative-AI disclosure/trailer is applicable. There is no direct UI/UX behavior change requiring screenshots. This approval is conditional on all required checks finishing green and human ownership of the final dependency/release decision.
AI-assisted review disclosure: OpenAI Codex reviewed the exact dependency graph, lockfile deduplication, upstream release delta, and live CI state; I verified the package identities and repository diff before approving.
中文说明
这是 esbuild 0.27.7 → 0.28.1 的机械升级。两个 workspace 的直接依赖和所有平台二进制都收敛到 0.28.1;lockfile 大量删除来自去掉重复的嵌套 esbuild,不是无关依赖丢失。没有 P0–P3。required checks 全绿并由人工确认最终依赖/发布决定后才 merge-ready。
Bumps esbuild from 0.27.7 to 0.28.1.
Release notes
Sourced from esbuild's releases.
... (truncated)
Changelog
Sourced from esbuild's changelog.
... (truncated)
Commits
bb9db84publish 0.28.1 to npm9ff053esecurity: add integrity checks to the Deno API0a9bf21enforce non-negative size in gzip parsere2a1a71security: forbid\\in local dev server requests83a2cbffix #4482: don't inlineusingdeclarations308ad74fix #4471: renaming of nestedvardeclarationsf013f5ffix some typosaafd6e4chore: fix some minor issues in comments (#4462)15300c3follow up: cjs evaluation fixes1bda0c3fix #4461, fix #4467: esm evaluation fixesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.