Skip to content

chore(deps): bump koa from 2.16.1 to 2.16.4#7275

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/koa-2.16.4
Open

chore(deps): bump koa from 2.16.1 to 2.16.4#7275
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/koa-2.16.4

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Feb 27, 2026

Bumps koa from 2.16.1 to 2.16.4.

Release notes

Sourced from koa's releases.

v2.16.4

What's Changed

v2.16.3

What's Changed

Full Changelog: koajs/koa@v2.16.2...v2.16.3

v2.16.2

What's Changed

Full Changelog: koajs/koa@v2.16.1...v2.16.2

Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for koa since your current version.


Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies javascript Pull requests that update javascript code labels Feb 27, 2026
@greptile-apps
Copy link
Copy Markdown
Contributor

greptile-apps Bot commented Feb 27, 2026

PR author is in the excluded authors list.

Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f7fc1db951

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread yarn.lock
react: ^18.3.1
languageName: unknown
linkType: soft

"@app/address-service@workspace:apps/address-service":
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Restore submodule workspace entries in yarn.lock

This change prunes workspace resolutions down to a subset (starting here with only @app/address-service), removing many app workspaces that still exist as git submodules (for example in .gitmodules) while the CI workflow checks out submodules recursively and then runs yarn install --immutable (.github/workflows/nodejs.condo.ci.yml lines 229-233 and 281). In that environment Yarn will need to restore the missing workspace entries, so immutable installs can fail even though the PR intent is only a koa patch bump.

Useful? React with 👍 / 👎.

@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/koa-2.16.4 branch from f7fc1db to 9df0f22 Compare March 1, 2026 05:49
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/koa-2.16.4 branch from 9df0f22 to 1c03338 Compare March 2, 2026 11:36
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/koa-2.16.4 branch from 1c03338 to 6040e6f Compare March 2, 2026 13:16
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/koa-2.16.4 branch from 6040e6f to c9136fd Compare March 4, 2026 08:17
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/koa-2.16.4 branch from c9136fd to a9af39f Compare March 4, 2026 23:48
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/koa-2.16.4 branch from a9af39f to 95419b6 Compare March 13, 2026 06:15
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/koa-2.16.4 branch from 95419b6 to 0717ac9 Compare March 16, 2026 13:22
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/koa-2.16.4 branch from 0717ac9 to 4b8775b Compare March 17, 2026 20:13
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/koa-2.16.4 branch from 4b8775b to 3af0328 Compare March 20, 2026 15:57
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/koa-2.16.4 branch from 3af0328 to 2634bc9 Compare March 20, 2026 17:52
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/koa-2.16.4 branch from 2634bc9 to 275b852 Compare March 23, 2026 18:54
Bumps [koa](https://github.com/koajs/koa) from 2.16.1 to 2.16.4.
- [Release notes](https://github.com/koajs/koa/releases)
- [Changelog](https://github.com/koajs/koa/blob/master/History.md)
- [Commits](koajs/koa@v2.16.1...v2.16.4)

---
updated-dependencies:
- dependency-name: koa
  dependency-version: 2.16.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/koa-2.16.4 branch from 275b852 to 5dd690e Compare March 29, 2026 08:02
@sonarqubecloud
Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies javascript Pull requests that update javascript code

Development

Successfully merging this pull request may close these issues.

0 participants