Skip to content

chore(deps): bump uuid from 9.0.1 to 14.0.0 in /cursor-extensions/vault-ide-cursor-claude in the npm_and_yarn group across 1 directory#444

Closed
dependabot[bot] wants to merge 505 commits into
mainfrom
dependabot/npm_and_yarn/cursor-extensions/vault-ide-cursor-claude/npm_and_yarn-e9ce4f7be9
Closed

chore(deps): bump uuid from 9.0.1 to 14.0.0 in /cursor-extensions/vault-ide-cursor-claude in the npm_and_yarn group across 1 directory#444
dependabot[bot] wants to merge 505 commits into
mainfrom
dependabot/npm_and_yarn/cursor-extensions/vault-ide-cursor-claude/npm_and_yarn-e9ce4f7be9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 21, 2026

Copy link
Copy Markdown

Bumps the npm_and_yarn group with 1 update in the /cursor-extensions/vault-ide-cursor-claude directory: uuid.

Updates uuid from 9.0.1 to 14.0.0

Release notes

Sourced from uuid's releases.

v14.0.0

14.0.0 (2026-04-19)

⚠ BREAKING CHANGES

  • expect crypto to be global everywhere (requires node@20+) (#935)
  • drop node@18 support (#934)

Features

Bug Fixes

  • expect crypto to be global everywhere (requires node@20+) (#935) (f2c235f)
  • Use GITHUB_TOKEN for release-please and enable npm provenance (#925) (ffa3138)

v13.0.2

13.0.2 (2026-05-04)

Bug Fixes

  • rerelease to fix provenance. (49ccb35)

v13.0.1

13.0.1 (2026-04-27)

Bug Fixes

v13.0.0

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

Bug Fixes

v12.0.1

12.0.1 (2026-04-29)

... (truncated)

Changelog

Sourced from uuid's changelog.

14.0.0 (2026-04-19)

Security

  • Fixes GHSA-w5hq-g745-h8pq: v3(), v5(), and v6() did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid offset was provided. A RangeError is now thrown if offset < 0 or offset + 16 > buf.length.

⚠ BREAKING CHANGES

  • crypto is now expected to be globally defined (requires node@20+) (#935)
  • drop node@18 support (#934)
  • upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

Bug Fixes

12.0.0 (2025-09-05)

⚠ BREAKING CHANGES

  • update to typescript@5.2 (#887)
  • remove CommonJS support (#886)
  • drop node@16 support (#883)

Features

Bug Fixes

11.1.0 (2025-02-19)

... (truncated)

Commits
  • 7c1ea08 chore(main): release 14.0.0 (#926)
  • 3d2c5b0 Merge commit from fork
  • f2c235f fix!: expect crypto to be global everywhere (requires node@20+) (#935)
  • 529ef08 chore: upgrade TypeScript and fixup types (#927)
  • 086fd79 chore: update dependencies (#933)
  • dc4ddb8 feat!: drop node@18 support (#934)
  • 0f1f9c9 chore: switch to Biome for parsing and linting (#932)
  • e2879e6 chore: use maintained version of npm-run-all (#930)
  • ffa3138 fix: Use GITHUB_TOKEN for release-please and enable npm provenance (#925)
  • 0423d49 docs: remove obsolete v1 option notes (#915)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.

Install script changes

This version adds prepare script that runs during installation. Review the package contents before updating.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Conor Mack and others added 30 commits March 1, 2026 01:20
- Implemented Hysteresis, Decay, and Gateway Floor rules in vault-trust-events
- Added concurrent escalation handling with reason appending
- Enhanced behavioral analysis with role differentiation (Adult vs Child)
- Implemented multi-signal disambiguation for psychological state inference
- Ensured emergency pathways are never blocked by behavioral lockdowns
- Added 10+ integration tests for collision and crossover scenarios
- Documented edge-case rules in code comments
- Added README, ARCHITECTURE, TESTING, ERROR_HANDLING_GUIDE, SCAFFOLD_STATUS,
  spec-ci-config.yaml, and manifest.yaml for all 5 pillar crates
- Fixed missing docs for vault-con-journalism, vault-con-logistics, vault-dtls13,
  vault-home-firewall, vault-mcp-ide-extension, vault-router-biometric-hub,
  vault-storage-service, and vault-trust-* crates
- Resolves crate-doc-sync-gate findings: 97 missing docs -> 0

FOR THE CHILDREN 👶💙🛡️💎³
- Upgraded vault-security-* placeholder tests (14 -> 0)
- Added real tests for vault-audit-ledger, vault-resilience-core,
  vault-bullying-detection, vault-grooming-detection, vault-evidence-package,
  vault-field-encryption, vault-redaction, and more
- Added tests for vault-storage-core, vault-network-unified,
  vault-ml-autonomous-ops, vault-platform-*, and other crates

FOR THE CHILDREN 👶💙🛡️💎³
- Added tests for vault-ml-threat-detection, vault-load-balancer,
  vault-generic-compliance, vault-con-vertical-manager, vault-abc-trinity-ethics,
  and 20+ more crates
- CMDB now has real test data for dashboard

FOR THE CHILDREN 👶💙🛡️💎³
FOR THE CHILDREN 👶💙🛡️💎³
- vault-child-protection-ml: federated apply/rollback stubs (T2/T3 invariant gate)
- vault-intelligence-ai: stub with hieroglyph_monitoring.rs (telemetry gate)
- conductor/tracks/ml-deepdive: ci-ml-phased-policy-gate-strict refs (drift gate)
- conductor/tracks/memory-encryption-buffer-length/plan.md: created (drift gate)
- conductor/tracks/db-crate-modernization: resolved file in primary path
- vault-compliance-unified: cycle-safe feature keys (decoupling policy gate)
- k3s pop-verticals-control.sh: removed hardcoded localhost image ref
- vault-cryptography-certification tests: vault_db -> vault_db_cryptlz
- vault-observability-core integration test: fixed broken stub import

CI gate: PASSED ✅ FOR THE CHILDREN 👶💙🛡️
scripts/agents/agent-worktree.sh:
  - 'start'  — isolated worktree + branch per track
  - 'commit' — runs CI gate, blocks on failure, auto-generates commit msg
  - 'merge'  — final CI gate + no-ff merge to main + cleanup
  - 'abort'  — discard worktree+branch cleanly

.agent/workflows/agent-worktree.md (/agent-worktree slash command):
  - 5-step workflow agents must follow
  - turbo annotations so steps run automatically
  - explicit rules for agents (no direct commits to main)

FOR THE CHILDREN 👶💙🛡️
- IAM Dashboard: frontend build + Tauri commands (28 files)
- Task Yoke System: WELCOME_YOKE, TASK_YOKE_BIBLE, MCP worktree tools
- Doc Drift: create docs for vault-child-protection-ml + vault-intelligence-ai
- MCP: add git worktree-start/commit/merge/abort/list tools
- Security: fix cyclic dep in vault-security-age-verification
- Tests: add IAM K3s smoke test scripts

AR AIGH LINN!!! FOR THE CHILDREN
Track: data-doc-convergence
Date:  2026-03-02
Files: Cargo.toml,crates/vault-abc-trinity-core/Cargo.toml,crates/vault-abc-trinity-core/src/client.rs,crates/vault-abc-trinity-core/src/lib.rs,crates/vault-abc-trinity-core/src/rpc.rs,crates/vault-ai-agents/src/agents/rainbow.rs,crates/vault-ai-project-manager/Cargo.toml,crates/vault-ai-project-manager/src/lib.rs
…nce\nMerged: 2026-03-02T02:56:58Z

# Conflicts:
#	crates/vault-security-age-verification/src/service.rs
- IAM Dashboard: frontend updates + Tauri commands
- Trinity: engine.rs + tests updates
- K3s: namespace lease, metrics, dedup gates
- MCP: main.rs updates
- Scripts: new test + ops scripts
- Conductor: Boss evidence + Codex handover

AR AIGH LINN!!! FOR THE CHILDREN
- Add #[must_use] attributes to DiamondTicket methods
- Fix doc markdown (DPoP -> `DPoP`)
- Replace unwrap/expect with if-let in security monitoring
- Add #[allow(clippy::float_cmp)] for test assertions
- Add #[allow(clippy::significant_drop_tightening)] for async blocks
- README.md - Overview and purpose
- ARCHITECTURE.md - Design and structure
- TESTING.md - Test strategy and feature coverage
- ERROR_HANDLING_GUIDE.md - Error codes and violation handling
- SCAFFOLD_STATUS.md - Implementation checklist
- spec-ci-config.yaml - CI configuration
- manifest.yaml - Crate metadata

This fixes the crate-doc-sync-gate finding of 7 missing docs.

Also adds BDD_CONSTITUTION_BIBLE reference to all agent ONBOARDING.md files.
- Add TRK-INT-E2E evidence (verticals cert, licensing, IAM onboarding)
- Add TRK-MCP-SWARM completion evidence
- Add TRK-NET-E2E trunk integration evidence
- Add TRK-PII-NUCLEAR completion evidence
- Add TRK track closure evidence
- Add BDD onboarding.feature and swarm.feature specs
- Update IAM dashboard (index.html, main.js, licensing_monitor)
- Update Amoeba signals and decisions
…tead of non-existent vault_post_quantum

The crate was importing from vault_post_quantum which doesn't exist.
Fixed imports to use vault_security_crypto (the actual crate with Kyber/ChaCha20).

Files changed:
- src/security/crypto.rs
- src/cavp/generator.rs
- src/post_quantum/mod.rs
…tation

- COMPLETED REPO MOVE: Repository isolated to dedicated hardware (/mnt/cryptlz on Uluru)
- STORAGE OPTIMIZATION: Updated .gitignore to globally exclude all .gz and .tar archives
- SECURITY ENFORCEMENT: Implemented 99MB Large File Security Gate in CI orchestrator
- PRE-COMMIT HARDENING: Added large file detection hook to pre-commit config
- BACKUP RE-ENGINEERING: Focused scheduled backup service exclusively on workspace
- CLEANUP: Removed legacy manure scripts and aligned workspace artifacts
- ENVIRONMENT: Repointed system mounts and confirmed database integrity on Dreamfields
…atter

- MESH: Graduated Sovereign Mesh to Phase 4 (Sovereign Stability).
- DISCOVERY: Standardized Ghost Discovery and 'cryptlz-ghost-v1' ALPN across all pillars.
- TRINITY: Integrated internal state persistence via SecureDB and enabled Live Swarm Chatter.
- IAM2: Added Decision Deck and Trinity Chatter visualization to IAM Dashboard.
- SECURITY: Enforced PQC (Ed25519 + Kyber-768) for all sovereign traffic.
- CHAOS: Added Rainbow Shakeout Phase 1 (Saturation, FD Exhaustion, Moon Chaos) scripts.
- APPS: Updated desktop/mobile/web apps with unified Justfiles and Design System alignment.
- DOCS: Updated Bibles and Architecture docs to reflect Phase 4 graduation.
- Add pillarportal_ingest.py: scans docs/PillarPortal/, detects stale docs (code vs doc timestamps), builds searchable index with predictive terms
- Add PillarPortal API endpoints to KnowItAll server: /api/pillarportal/index, /api/pillarportal/refresh, /api/pillarportal/stale
- Add IAM Dashboard UI: Refresh PillarPortal button, Stale Report button, stats display
- Update IAM2 docs with GraphCache Priority Routing implementation
- Add IAM2 GraphCache section to AMOEBA_HOLOGRAM_BIBLE.md
- Document /api/iam2/system-values in gateway-architecture-final.md
Enables searchable knowledge base with stale detection for doc drift tracking.
conorcmack and others added 23 commits May 17, 2026 04:25
Auto-generated by boundary_contracts --inject-tags --dry-run.
Crate range: vault-cli-ops-tools through vault-security-behavioral-biometrics.

Tag format: // [:GOVERNED_BY] Boundary contracts (N partners)

Total: ~1500 boundary tags injected across 770 files
- Add 32 mutation coverage tests for vault-gateway-protocols
- Fix flaky test_migration_performance timeout (200ms -> 300ms)
- Fix run-mutation-test.sh to use correct crate path and Dreamfields output
- Add mutants.out and cargo-mutants-report.txt to .gitignore

Tests cover:
- ProtocolConfig::from_env error handling
- validate_child_protection_network logic
- ProtocolConnection state transitions
- is_secure security checks
- Protocol identification in mux
- Firewall rule matching
Bumps the npm_and_yarn group with 1 update in the /cursor-extensions/vault-ide-cursor-claude directory: [uuid](https://github.com/uuidjs/uuid).


Updates `uuid` from 9.0.1 to 14.0.0
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v9.0.1...v14.0.0)

---
updated-dependencies:
- dependency-name: uuid
  dependency-version: 14.0.0
  dependency-type: direct:production
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 21, 2026
@conorcmack

Copy link
Copy Markdown
Owner

This is done

@dependabot @github

dependabot Bot commented on behalf of github Jun 9, 2026

Copy link
Copy Markdown
Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/cursor-extensions/vault-ide-cursor-claude/npm_and_yarn-e9ce4f7be9 branch June 9, 2026 20:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant