Skip to content

chore(deps): bump vendor/spec-kit from a4e25ce to 4a7341a - #17

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/submodules/vendor/spec-kit-4a7341a
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/submodules/vendor/spec-kit-4a7341a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor

Bumps vendor/spec-kit from a4e25ce to 4a7341a.

Commits
  • e2d4cfa fix: add JSON error handling to auth config loader (#3836)
  • e1617ce fix: use missing_ok=True in extension ZIP cleanup (#3870)
  • 0a70e5b feat(presets): let a preset declare a required extension (#4250)
  • d4ba753 fix(bundler): reject unsupported catalog payload versions (#4090)
  • b5f7708 fix(extensions): install bundled extension updates from the local package (#4...
  • d40c48c docs: clarify autonomous PR handling (#4392)
  • 3eec154 fix(workflows): reject malformed step config on add (#4087)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [vendor/spec-kit](https://github.com/github/spec-kit) from `a4e25ce` to `4a7341a`.
- [Release notes](https://github.com/github/spec-kit/releases)
- [Commits](github/spec-kit@a4e25ce...4a7341a)

---
updated-dependencies:
- dependency-name: vendor/spec-kit
  dependency-version: 4a7341a93d944d6efe153b71da4a1adb9c2b578c
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file submodules Pull requests that update submodules code labels Sep 9, 2026

forkrul commented Sep 11, 2026

Copy link
Copy Markdown
Owner

Superseded by #18 — this one cannot be made green.

4a7341a is an untagged mid-stream commit on spec-kit's default branch, and shellcheck + repo integrity enforces the repo's pinning rule directly:

##[error]vendor/spec-kit is at 4a7341a, which is not an upstream tag

So this is red by design rather than by accident, and rebasing won't change it. #18 bumps to v1.0.6 (96c9bd6) instead — the next actual upstream tag after the current v1.0.5 pin — and moves the README vendored-submodules table with it, which the same CI step also checks.

This PR should be closed rather than merged.


Generated by Claude Code

forkrul added a commit that referenced this pull request Sep 11, 2026
Supersedes #17, which Dependabot aimed at 4a7341a — an untagged mid-stream
commit that CI rejects by rule ("vendor/spec-kit is at 4a7341a, which is not
an upstream tag"). v1.0.6 (96c9bd6) is the next actual upstream tag.

The README vendored-submodules table moves with the pin, because the same CI
step greps it for "| <tag> |". anvil's three fallback templates still exist at
v1.0.6: templates/{spec,plan,tasks}-template.md.

CHANGELOG records the pin on the existing Added line rather than as a Changed
entry: [Unreleased] notes there is no earlier release to change against, and
v1.0.5 was never shipped.

Feature: vendor-pin-maintenance
Symbol: vendor/spec-kit,SUPERPOWERS_KEEP
@forkrul forkrul closed this Sep 11, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/submodules/vendor/spec-kit-4a7341a branch September 11, 2026 21:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file submodules Pull requests that update submodules code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant