chore(deps): bump 50 patch-level deps across monorepo#40172
Conversation
|
Looks like this PR is not ready to merge, because of the following issues:
Please fix the issues and try again If you have any trouble, please check the PR guidelines |
|
WalkthroughThis PR updates version ranges across many package.json files in the monorepo—primarily bumping ESLint (~9.39.3 → ~9.39.4) and applying various patch/minor dependency upgrades. No source code, runtime logic, or public API declarations were changed. Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Possibly related PRs
Suggested reviewers
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
1 issue found across 71 files
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="packages/apps-engine/package.json">
<violation number="1" location="packages/apps-engine/package.json:80">
P2: Keep the msgpack version in sync across the Apps Engine and Deno runtime manifests; otherwise the two codecs will run against different library versions.</violation>
</file>
Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.
9fae619 to
b1435ff
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #40172 +/- ##
===========================================
- Coverage 69.87% 69.79% -0.09%
===========================================
Files 3296 3296
Lines 119166 119166
Branches 21482 21435 -47
===========================================
- Hits 83270 83169 -101
- Misses 32611 32689 +78
- Partials 3285 3308 +23
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
72a7d62 to
e84897e
Compare
Bumps within current major.minor (no breaking changes), including: `eslint`, `@types/react`, `react-virtuoso`, `webpack`, `dompurify`, `hono`, `katex`, `@swc/core`, `vite`, `ts-jest`, `esbuild`, `bson`, `twilio`, `zustand`, `qs`, `re-resizable`, `overlayscrollbars`, `adm-zip`, `cron`, `codemirror`, `turbo`, `typedoc`, `uuid`, `tinybench`, `sass-loader`, `ts-loader`, `eslint-plugin-jest`, `eslint-plugin-storybook`, `eslint-plugin-testing-library`, `@msgpack/msgpack`, `@noble/ed25519`, `@octokit/core`, `@opentelemetry/api`, `@react-aria/toolbar`, `@react-spectrum/test-utils`, `@codemirror/lang-javascript`, `@xmldom/xmldom`, `meteor-node-stubs`, `jsrsasign`, `sanitize-html`, `@changesets/cli`, `@types/*`. `@react-pdf/renderer` 4.3.3 was held back at 4.3.2 because it transitively pulls a broken `@react-pdf/image@3.1.0` (references unpublished `@react-pdf/svg`). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@octokit/core 5.0.2's OctokitOptions no longer carries the throttle option's contextual type, so the inline callbacks in setupOctokit lost their parameter inference and tripped TS7006. Annotate the parameters to match @octokit/plugin-throttling's LimitHandler signature. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Reverts @react-aria/toolbar from ^3.0.0-nightly-ffb1a9d0d-260323 back to ^3.0.0-nightly.5042 — the newer nightly doesn't ship .d.ts files, causing TS7016 in ui-composer build. Also reverts @react-spectrum/test-utils from ~1.0.0-beta.4 back to ~1.0.0-alpha.8 to stay on the known-good pre-release line. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
The newer nightly (ffb1a9d0d-260323) doesn't ship dist/types.d.ts, causing TS7016 during ui-composer build. Pin to the previous nightly (fb28ab3b4-241024) via a resolution entry to match develop's lockfile. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
re-resizable 6.11.2 no longer emits empty class="" attributes on resize handle divs. Updated CallHistoryContextualbar snapshots to match. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…reorder Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…lures Reverts three patch-level bumps suspected of breaking CI: - cron 1.8.3 -> 1.8.2 (migrated moment-timezone -> luxon internally; suspected cause of Livechat business hours failures) - @noble/ed25519 3.0.1 -> 3.0.0 (new modP() with negative-coordinate validation; suspected cause of E2EE placeholder/PDF export timeouts) - hono 4.12.14 -> 4.12.5 pinned exact (cookie/CORS changes across v4.12.9-v4.12.14; suspected cause of ABAC PERMIT and iframe auth fails) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…patch versions The caret spec (^X.Y.Z) allowed minor version jumps far beyond what a patch-level bump should be: - react-virtuoso: 4.12.0 -> 4.18.5 (+6 minor versions) — likely cause of the channel/team-management members dialog test failures - overlayscrollbars: 2.11.4 -> 2.15.1 (+4 minor versions) - twilio: 5.4.2 -> 5.13.1 (+9 minor versions) Replace ^ with ~ to stay within patch-level. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
|
/jira ARCH-2083 |
|
The milestone "8.5.0" does not exist on the Jira board; the task was created without Fix version. |
Summary
npm-check-updates --target patchacross the workspace.eslint,@types/react,react-virtuoso,webpack,dompurify,hono,katex,@swc/core,vite,ts-jest,esbuild,bson,twilio,zustand,qs,re-resizable,overlayscrollbars,adm-zip,cron,codemirror,turbo,typedoc,uuid,tinybench,sass-loader,ts-loader,@msgpack/msgpack,@noble/ed25519,@octokit/core,@opentelemetry/api,@react-aria/toolbar,@react-spectrum/test-utils,@codemirror/lang-javascript,@xmldom/xmldom,meteor-node-stubs,jsrsasign,sanitize-html,@changesets/cli, plus severaleslint-plugin-*and@types/*.package.jsonfiles +yarn.lockupdated.Notes
@react-pdf/rendererwas held back at^4.3.2. The 4.3.3 release transitively pulls@react-pdf/image@3.1.0, which references the unpublished package@react-pdf/svg^1.1.0—yarn installfails. Worth revisiting once upstream republishes a working@react-pdf/image.@msgpack/msgpack 3.0.0-beta2 → 3.0.1crosses the prerelease→stable boundary (still within3.0.x).katex ~0.16.28 → ~0.16.45(17 patches behind) and@swc/core 1.15.11 → 1.15.26(15 patches) are the largest jumps within their patch ranges.Test plan
yarn installsucceeds (peer-deps warnings are pre-existing ondevelop).yarn turbo run typecheckpasses for 39 workspaces. Pre-existing failures ondevelopwere excluded:core-services,media-calls,federation-matrix,ui-voip,meteor(verified by stashing this PR's changes and reproducing the same failures ondevelop).yarn turbo run testunitpasses on a representative sample (random,api-client,i18n,tools,log-format,sha256,jwt,ui-kit,message-parser,http-router,gazzodown,web-ui-registration,ui-avatar,ui-composer,tracing).ui-clientshows the same 4 pre-existing failures asdevelop.🤖 Generated with Claude Code
Summary by CodeRabbit
Task: ARCH-2109