Skip to content

chore(deps-dev): bump the npm-frontend-webcoder-ui-patch-minor group across 1 directory with 3 updates#100

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/webcoder_ui/npm-frontend-webcoder-ui-patch-minor-10ead5182d
Open

chore(deps-dev): bump the npm-frontend-webcoder-ui-patch-minor group across 1 directory with 3 updates#100
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/webcoder_ui/npm-frontend-webcoder-ui-patch-minor-10ead5182d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-frontend-webcoder-ui-patch-minor group with 3 updates in the /frontend/webcoder_ui directory: @applitools/eyes-playwright, @chromatic-com/playwright and @playwright/test.

Updates @applitools/eyes-playwright from 1.47.9 to 1.47.11

Commits

Updates @chromatic-com/playwright from 0.14.10 to 0.14.11

Release notes

Sourced from @​chromatic-com/playwright's releases.

@​chromatic-com/playwright@​0.14.11

Patch Changes

  • 2993acf: Fix Module not found: Error: Can't resolve 'storybook/internal/csf' when the archive Storybook is built in a project where storybook is not reachable from the project root (e.g. pnpm, regardless of the hoist setting). Webpack now falls back to resolving storybook/* imports from the storybook install these packages depend on.
  • 0994e2e: Feat: add support for setting colorScheme
Changelog

Sourced from @​chromatic-com/playwright's changelog.

0.14.11

Patch Changes

  • 2993acf: Fix Module not found: Error: Can't resolve 'storybook/internal/csf' when the archive Storybook is built in a project where storybook is not reachable from the project root (e.g. pnpm, regardless of the hoist setting). Webpack now falls back to resolving storybook/* imports from the storybook install these packages depend on.
  • 0994e2e: Feat: add support for setting colorScheme
Commits

Updates @playwright/test from 1.61.0 to 1.61.1

Release notes

Sourced from @​playwright/test's releases.

v1.61.1

Bug Fixes

  • #41365 [Bug]: Expect.Extend matcher with same name as default matcher in same expect instance overrides default matchers implementation to custom matcher
  • #41351 [Bug]: Playwright UI mode: apiRequestContext._wrapApiCall reports unexpected number of bytes (same test passes in headed mode)
  • #41360 [Bug]: Trace viewer: message times in websockets are downscaled by 1000
  • #41311 [Bug]: [Regression]: Sync loader throws "context.conditions?.includes is not a function" on Node 22.15
  • #41371 [Regression]: Sync ESM loader (registerHooks) fails to resolve extensionless .ts subpath imports across pnpm workspace symlinks
Commits
  • 39e3553 cherry-pick(#41399): fix(test): load require-reached files as commonjs in syn...
  • 4328122 chore: mark v1.61.1 (#41404)
  • 2c29a94 fix(tracing): stop recording websocket frames outside of chunks (#41398)
  • 4324b19 cherry-pick(#41367): fix(test): keep builtin expect matchers on base extend
  • 041e7e3 cherry-pick(#41364): fix(har): WebSocket message timestamps should be in mi...
  • b8a0fc3 cherry-pick(#41309, #43149): Revert "fix(firefox): treat `navigationCommitted...
  • b5a3175 cherry-pick(#41319): fix(loader): support other node versions
  • d4724a9 cherry-pick(#41290): feat(docker): add Ubuntu 26.04 (Resolute Raccoon) image
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…across 1 directory with 3 updates

Bumps the npm-frontend-webcoder-ui-patch-minor group with 3 updates in the /frontend/webcoder_ui directory: [@applitools/eyes-playwright](https://github.com/applitools/eyes.sdk.javascript1/tree/HEAD/js/packages/eyes-playwright), [@chromatic-com/playwright](https://github.com/chromaui/chromatic-e2e/tree/HEAD/packages/playwright) and [@playwright/test](https://github.com/microsoft/playwright).


Updates `@applitools/eyes-playwright` from 1.47.9 to 1.47.11
- [Commits](https://github.com/applitools/eyes.sdk.javascript1/commits/HEAD/js/packages/eyes-playwright)

Updates `@chromatic-com/playwright` from 0.14.10 to 0.14.11
- [Release notes](https://github.com/chromaui/chromatic-e2e/releases)
- [Changelog](https://github.com/chromaui/chromatic-e2e/blob/main/packages/playwright/CHANGELOG.md)
- [Commits](https://github.com/chromaui/chromatic-e2e/commits/@chromatic-com/playwright@0.14.11/packages/playwright)

Updates `@playwright/test` from 1.61.0 to 1.61.1
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.61.0...v1.61.1)

---
updated-dependencies:
- dependency-name: "@applitools/eyes-playwright"
  dependency-version: 1.47.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-frontend-webcoder-ui-patch-minor
- dependency-name: "@chromatic-com/playwright"
  dependency-version: 0.14.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-frontend-webcoder-ui-patch-minor
- dependency-name: "@playwright/test"
  dependency-version: 1.61.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-frontend-webcoder-ui-patch-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: area:ci, type:chore. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 20, 2026
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits.
Credits must be used to enable repository wide code reviews.

@Prekzursil

Copy link
Copy Markdown
Owner

PR-specific note (#100). Unique content, verified against the manifest rather than the title: @applitools/eyes-playwright ^1.46.3->^1.47.11, @chromatic-com/playwright ^0.14.10->^0.14.11, @playwright/test 1.61.0->1.61.1. It does NOT contain the websocket-driver fix (#98) or fast-xml-parser (#101), so it supersedes neither.


Diagnosis: left OPEN. This PR is unique and still wanted, but it is blocked by two repo-level defects on main, neither of which this PR causes or can fix.

Blocker 1 — the required quality / quality check cannot pass for any PR.
It fails at step 20, gate-deps osv-scanner. osv-scanner exits 1 on ANY finding,
so the gate is all-or-nothing. Measured locally against a clean clone of main
(osv-scanner 2.3.8, the same version CI pins):

Total 17 packages affected by 25 known vulnerabilities
  (1 Critical, 14 High, 9 Medium, 1 Low) from 2 ecosystems

That set is NOT closable by bounded-floor bumps, so it is an owner call:

  • react-router / react-router-dom 6.30.4 — GHSA-jjmj-jmhj-qwj2 has no
    patched 6.x at all
    . The advisory records introduced 6.30.2 / last_affected 6.30.4 for react-router-dom, and the fix lands only in
    react-router 7.13.0. Clearing it therefore requires a react-router v6 -> v7
    major migration
    , which is a runtime-dependency change with real app impact,
    not a dependency-hygiene bump.
  • svgo 1.3.2 -> 2.8.3 and brace-expansion -> 5.0.8 are also cross-major.
    Note that forcing brace-expansion 5.x is NOT safe here on its own: 5.x
    exports { EXPANSION_MAX, EXPANSION_MAX_LENGTH, expand } with no callable
    module and no default export, while minimatch 3.x/9.x call the module
    directly — measured TypeError: expand is not a function. The consumer has to
    move up (glob/minimatch), not the dependency down.

Blocker 2 — npm ci is broken on main, so verify fails independently.
Reproduced locally on a clean clone of main with no PR applied:

npm error code EUSAGE
npm error Invalid: lock file's ws@7.5.11 does not satisfy ws@7.5.13
npm error `npm ci` can only install packages when your package.json and
npm error package-lock.json ... are in sync.

frontend/webcoder_ui/package.json overrides ws to ^7.5.11; since the lock
was written, 7.5.13 published, so the resolved ideal tree wants 7.5.13 while the
lock still pins 7.5.11. This is a pre-existing main defect (a caret override
drifting), not anything this PR did, and it blocks verify on every PR in the
repo. Fix is a lockfile refresh (npm install in frontend/webcoder_ui)
committed to main.

Note main's last recorded green quality run is 477b7ae from 2026-06-27, which
predates all 25 of these advisories — so main is stale-green, not actually green.

No action taken on this PR beyond this comment: it carries a real, unique change
and should survive.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant