Repository navigation
Bump the development-dependencies group across 1 directory with 14 updates - #690
Conversation
|
@dependabot rebase |
a36b457 to
8e3ecf2
Compare
There was a problem hiding this comment.
🤖 Codex review: Changes requested — dependency security review is clear, but the exact-head install fails on the repository's supported Node version.
Blocking compatibility finding
On Node 24.14.1 / npm 11.11.0, npm ci --ignore-scripts exits EBADENGINE: current @asamuzakjp/css-color@7.1.2 requires ^22.22.2 || ^24.15.0 || >=26.0.0. jsdom 30.1.1 and related selector/color packages also raise that floor. The repository's engine-strict=true, Node pin, CI, and container build use 24.14.1. Resolve the Node support/pin mismatch consistently, or retain a compatible jsdom dependency set; then rerun installation, tests, lint, TypeScript and builds. Do not force/ignore engines to merge this head.
Upgrade
- 14 development dependencies, including ESLint/CSS, testing-library, Node types, perfectionist/React-refresh/Storybook ESLint plugins, globals, jsdom 29.1.1→30.1.1, Prettier, tailwind-csstree, typescript-eslint, Vite and Vitest 4.1.11→5.0.3 (current rebased resolution).
- Reviewed head:
8e3ecf25aa47661e9c96947a20f13dd30c59a55e, basedfedb5e36e3362ec492f64946baf5254044e94a4.
Security review
- Reviewed every direct artifact and notable transitive/native/parser churn. The cumulative exact-version/integrity ledger covers 222 initial/rebased artifacts; all downloaded SHA-512 values match registry and their applicable lock entries, and all npm registry signatures verify. All 152 advertised SLSA bundles verify with their expected artifact subjects and publishing identities. Old/new source evidence is reused only for identical artifact pairs; additional versions resolved during rebase received delta review.
- No same-version integrity rewrite, source substitution, new install hook, unexpected CLI/native platform family, secret harvesting, or exfiltration path found. Reviewed Vitest's bundled-internal refactor, Vite/Rolldown, jsdom/parser/color and undici churn, ESLint/TypeScript tooling and formatter/compiler changes. Existing package-purpose process/native behavior remains.
- Current Undici 7.29.0→8.11.2 incorporates ten matched advisory fixes, using the verified 8.x fixed boundary 8.10.2. No new applicable advisory found in the changed artifact set.
Compatibility verification
npm ci --ignore-scripts— failed with the engine mismatch above, independently matching current-head GitHub CI.- Executable frontend tests/lint/builds are not run because supported-version installation fails. No lifecycle code was executed by this reproduction.
- Shared baseline all-module
make test/raceandmake lintpass; this PR leaves Go source/module/config inputs unchanged. - Required Pro image CI also fails before build with AWS OIDC
Not authorized to perform sts:AssumeRoleWithWebIdentity; resolving the npm mismatch alone does not clear that merge requirement.
Residual risk
Rolldown native binaries and large generated bundles were inspected through immutable hashes, signatures/provenance and source context, not independent rebuild/disassembly of every platform binary. Existing unrelated critical shell-quote and selector-parser alerts remain in the tree; this review clears the upgrade's supply-chain delta, not all repository vulnerabilities. Node compatibility and required AWS CI remain unresolved.
bd71005 to
b04ef3c
Compare
…dates Bumps the development-dependencies group with 14 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@eslint/css](https://github.com/eslint/css) | `1.4.0` | `2.0.0` | | [@testing-library/react](https://github.com/testing-library/react-testing-library) | `16.3.2` | `16.3.3` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.3.0` | `26.6.3` | | [eslint](https://github.com/eslint/eslint) | `10.9.1` | `10.11.0` | | [eslint-plugin-perfectionist](https://github.com/azat-io/eslint-plugin-perfectionist) | `5.10.1` | `5.12.1` | | [eslint-plugin-react-refresh](https://github.com/ArnaudBarre/eslint-plugin-react-refresh) | `0.5.4` | `0.5.7` | | [eslint-plugin-storybook](https://github.com/storybookjs/storybook/tree/HEAD/code/lib/eslint-plugin) | `10.5.10` | `10.6.1` | | [globals](https://github.com/sindresorhus/globals) | `17.11.0` | `17.12.0` | | [jsdom](https://github.com/jsdom/jsdom) | `29.1.1` | `30.1.1` | | [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.9` | | [tailwind-csstree](https://github.com/humanwhocodes/tailwind-csstree) | `0.3.3` | `0.4.1` | | [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.68.0` | `8.71.0` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.2.2` | `8.3.1` | | [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.11` | `5.0.3` | Updates `@eslint/css` from 1.4.0 to 2.0.0 - [Release notes](https://github.com/eslint/css/releases) - [Changelog](https://github.com/eslint/css/blob/main/CHANGELOG.md) - [Commits](eslint/css@css-v1.4.0...css-v2.0.0) Updates `@testing-library/react` from 16.3.2 to 16.3.3 - [Release notes](https://github.com/testing-library/react-testing-library/releases) - [Changelog](https://github.com/testing-library/react-testing-library/blob/main/CHANGELOG.md) - [Commits](testing-library/react-testing-library@v16.3.2...v16.3.3) Updates `@types/node` from 26.3.0 to 26.6.3 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `eslint` from 10.9.1 to 10.11.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.9.1...v10.11.0) Updates `eslint-plugin-perfectionist` from 5.10.1 to 5.12.1 - [Release notes](https://github.com/azat-io/eslint-plugin-perfectionist/releases) - [Changelog](https://github.com/azat-io/eslint-plugin-perfectionist/blob/main/changelog.md) - [Commits](azat-io/eslint-plugin-perfectionist@v5.10.1...v5.12.1) Updates `eslint-plugin-react-refresh` from 0.5.4 to 0.5.7 - [Release notes](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/releases) - [Changelog](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/blob/main/CHANGELOG.md) - [Commits](ArnaudBarre/eslint-plugin-react-refresh@v0.5.4...v0.5.7) Updates `eslint-plugin-storybook` from 10.5.10 to 10.6.1 - [Release notes](https://github.com/storybookjs/storybook/releases) - [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md) - [Commits](https://github.com/storybookjs/storybook/commits/v10.6.1/code/lib/eslint-plugin) Updates `globals` from 17.11.0 to 17.12.0 - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v17.11.0...v17.12.0) Updates `jsdom` from 29.1.1 to 30.1.1 - [Release notes](https://github.com/jsdom/jsdom/releases) - [Commits](jsdom/jsdom@v29.1.1...v30.1.1) Updates `prettier` from 3.9.6 to 3.9.9 - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](prettier/prettier@3.9.6...3.9.9) Updates `tailwind-csstree` from 0.3.3 to 0.4.1 - [Release notes](https://github.com/humanwhocodes/tailwind-csstree/releases) - [Changelog](https://github.com/humanwhocodes/tailwind-csstree/blob/main/CHANGELOG.md) - [Commits](humanwhocodes/tailwind-csstree@tailwind-csstree-v0.3.3...tailwind-csstree-v0.4.1) Updates `typescript-eslint` from 8.68.0 to 8.71.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/typescript-eslint) Updates `vite` from 8.2.2 to 8.3.1 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite) Updates `vitest` from 4.1.11 to 5.0.3 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest) --- updated-dependencies: - dependency-name: "@eslint/css" dependency-version: 2.0.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: development-dependencies - dependency-name: "@testing-library/react" dependency-version: 16.3.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: development-dependencies - dependency-name: "@types/node" dependency-version: 26.6.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: development-dependencies - dependency-name: eslint dependency-version: 10.11.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: development-dependencies - dependency-name: eslint-plugin-perfectionist dependency-version: 5.12.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: development-dependencies - dependency-name: eslint-plugin-react-refresh dependency-version: 0.5.7 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: development-dependencies - dependency-name: eslint-plugin-storybook dependency-version: 10.6.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: development-dependencies - dependency-name: globals dependency-version: 17.12.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: development-dependencies - dependency-name: jsdom dependency-version: 30.1.1 dependency-type: direct:development update-type: version-update:semver-major dependency-group: development-dependencies - dependency-name: prettier dependency-version: 3.9.9 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: development-dependencies - dependency-name: tailwind-csstree dependency-version: 0.4.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: development-dependencies - dependency-name: typescript-eslint dependency-version: 8.70.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: development-dependencies - dependency-name: vite dependency-version: 8.3.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: development-dependencies - dependency-name: vitest dependency-version: 5.0.1 dependency-type: direct:development update-type: version-update:semver-major dependency-group: development-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
b04ef3c to
fa8ac88
Compare
Updated jsdom dependencies require a newer Node 24 release, and Vitest 5 changes the matcher type parameters. The storage mock also assigns to a read-only jsdom property. Use Node 24.21.0 in CI, release jobs, and image builders, and declare the supported Node release lines. Augment Vitest's matcher interface centrally and register DOM matchers once. Use jsdom's storage in settings coverage and verify serialized values so persistence is exercised through the browser API.
bgentry
left a comment
There was a problem hiding this comment.
🤖 Codex review: Approved after dependency security review and compatibility fixes on the current head.
Upgrade and exact scope
Reviewed head: d50bb259da2472d47c9090e803593ab10771fea8, based on master 44e7ea9a10dc481a9a2de273cfe2be53bb637169; tree f9bc33b30617dcbd39c8a629352333ea1a0ba16c. This covers all 14 development dependency upgrades in the PR table, plus the Node 24.14.1 → 24.21.0 runtime/image correction. The fix is a single added commit on Dependabot's existing current head; no remote history was rewritten.
Root causes and corrections
engine-strict=truemakes the old Node 24.14.1 pins fail installation: jsdom 30.1.1 and its CSS dependency require Node 24.15+ on that release line. CI, release jobs and both frontend image builders now use the reviewed Node 24.21.0 runtime; the manifest and lock agree on^24.15.0 || >=26.0.0, excluding unsupported Node 25.- jsdom 30 exposes read-only
localStorage; the settings mock assigns to it. Settings coverage now uses actual jsdom Storage, resets it between cases and checks the persisted serialized true/false values. - Vitest 5 changes matcher generics. The old test-local
Assertion<T>and global jest-dom declaration conflict with its types. One centralMatchers<R, T>augmentation supplies the DOM matchers, with runtime registration retained once in setup.
Security review
- Reused exact registry/source/provenance evidence only when package, version and integrity identities match. Rehashed all 209 relevant old/new/removal artifact identities across the final PR delta and production-group integration; SHA512, registry SHA1 and prior SHA256 match. No new artifact, nonregistry source, same-version integrity rewrite or unexpected lifecycle hook appears in the final integration delta.
- Duplicate-key-safe lock parsing, exact parent-entry comparison and 730 dependency range checks pass. No hybrid lock entries or unresolved mandatory edges remain. The added commit does not change installed package identities from the current bot head.
- Independently reviewed the added Node runtime and immutable official Docker image pin for Darwin arm64 and Linux amd64/arm64. Official Darwin/source checksums verify with the release-team GPG key; OCI manifests/layers match their digests and canonical recipes; bundled npm bytes match the signed Node source across platforms.
- Fresh advisory queries are unchanged from master: existing postcss-selector-parser GHSA-rj75-hqrm-r3gf (moderate) and shell-quote GHSA-pqg4-j6r4-53mv (critical). This PR does not introduce either advisory.
Compatibility verification
All local checks run against the exact final combined tree under reviewed Node 24.21.0/npm 11.19.0:
- Clean integrity-enforcing
npm ci— passed, lock stable. npm run test:once— 243 tests in 35 files passed.npm run lint— passed.npm run build— TypeScript and production Vite build passed.npm run build-storybook— passed.- Full OSS Docker image, Linux arm64 — passed; resulting executable
-helpsmoke check passed. - Pro frontend Docker stage, Linux amd64 — passed; complete Pro images are checked by GitHub CI.
The prior Dagre fix's full 32-pair comparison across 13 stories in light/dark themes has identical markup/geometry and visually indistinguishable screenshots. A fresh seeded Storybook build of this final combined head additionally passes six browser comparisons: the dense 14-node/19-edge graph before/after Fit View and a resolved transition in both themes. All 11 recorded DOM, SVG, geometry and state fields match exactly in all six. Two screenshots are pixel-identical; the other four differ by 30–59 isolated pixels (max channel difference 14/255), within the same-version repeat control's 59 pixels/24 channel variation. No browser errors or warnings remain.
Residual risk and bounded runtime clearance
This is not a clean vulnerability scan or a reproducible native-binary proof. The preexisting repository advisories above remain. The Node/npm review retains advisory records in bundled npm dependencies with source/reachability assessment for the actual trusted install/build paths; arbitrary hostile query/glob input and optional package-manager features are outside that scope. Optional Corepack 0.36.0 has an unawaited signature-verification call and is explicitly excluded; River invokes bundled npm and does not enable Corepack. Inherited OpenSSL 3.5.8 lacks later 3.5.9 fixes, including DTLS CVE-2026-84782; unchanged OS zlib 1.3.2-r0 lacks the later gz-file API fix, a path not used by Node's JS stream binding. The reviewed builder commands do not enable the affected optional protocol/file operations. Undici's default decompression-limit caveat, large generated/native code, upstream release-key trust, and OCI provenance without independent signature verification remain documented review limits.
Bumps the development-dependencies group with 14 updates in the / directory:
1.4.02.0.016.3.216.3.326.3.026.6.310.9.110.11.05.10.15.12.10.5.40.5.710.5.1010.6.117.11.017.12.029.1.130.1.13.9.63.9.90.3.30.4.18.68.08.71.08.2.28.3.14.1.115.0.3Updates
@eslint/cssfrom 1.4.0 to 2.0.0Release notes
Sourced from @eslint/css's releases.
Changelog
Sourced from @eslint/css's changelog.
Commits
cb52353chore: release 2.0.0 🚀 (#489)510403echore: update dependency@eslint/jsonto ^2.1.0 (#552)c5e7b51docs: Update README sponsorsa851d5cfix: locate!importantafter the value inno-important(#550)506bdbbfeat: check CSS-wide keywords inuse-baseline(#542)2c95233fix: update baseline data (#548)6a3b5c4chore: update actions/checkout action to v7 (#544)3fa306cchore: update actions/setup-node action to v7 (#545)3e7f3d4chore: update googleapis/release-please-action action to v5 (#547)a340c84chore: update dependency c8 to v12 (#546)Updates
@testing-library/reactfrom 16.3.2 to 16.3.3Release notes
Sourced from @testing-library/react's releases.
Commits
20ce75ffix: Avoid act() re-entrant when dispatching events (#1468)be9d81ddocs: fix typos in comments and types (#1446)Updates
@types/nodefrom 26.3.0 to 26.6.3Commits
Updates
eslintfrom 10.9.1 to 10.11.0Release notes
Sourced from eslint's releases.
... (truncated)
Commits
3c0b7c610.11.0321f0a7Build: changelog update for 10.11.0520dd77perf: Implement fast paths in critical areas (#21210)9ecfdc5docs: note that --cache can serve stale results for cross-file rules (#21312)92086c8test: updateEMFILEerror generation for Node.js 26.9.0 compatibility (#21330)9ac7eb6chore: update github/codeql-action action to v4.38.0 (#21331)22b09f5fix: ignore__proto__properties inprefer-object-spread(#21311)24310e3chore: update ecosystem plugins (#21324)d136fa4feat: object-shorthand handle quoted properties forignoreConstructors(#21...45ad79eci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (#21318)Updates
eslint-plugin-perfectionistfrom 5.10.1 to 5.12.1Release notes
Sourced from eslint-plugin-perfectionist's releases.
Changelog
Sourced from eslint-plugin-perfectionist's changelog.
... (truncated)
Commits
43c3464build: publish v5.12.141b088efix: make eslint an optional peer dependencye28e3a0build: publish v5.12.0521314fchore: update dependencies5488d84feat: support oxlint without an eslint installation38eb692refactor: share context option matching and comparatorse3d11ccfix: honor eslint-disable directives with a descriptionf7eae67chore: update github actions3e100d2build: publish v5.11.1ef12a53chore: update dependenciesUpdates
eslint-plugin-react-refreshfrom 0.5.4 to 0.5.7Release notes
Sourced from eslint-plugin-react-refresh's releases.
Changelog
Sourced from eslint-plugin-react-refresh's changelog.
Commits
fd40d83Add allowCompoundComponents option [publish] (#117)620568aSupport re-exporting namespace components (fixes #116) [publish]65c3172[publish] v0.5.58411020Bump depsc28fa15Fix SCREAMING_SNAKE_CASE constant exported viaexport { Name }incorrectly ...554c764[publish] addcontentTypeandsizeto allowExportNames in Next config (#115)Updates
eslint-plugin-storybookfrom 10.5.10 to 10.6.1Release notes
Sourced from eslint-plugin-storybook's releases.
... (truncated)
Changelog
Sourced from eslint-plugin-storybook's changelog.
... (truncated)
Commits
a17b725Bump version from "10.6.0" to "10.6.1" [skip ci]a777773Bump version from "10.6.0-beta.3" to "10.6.0" [skip ci]f32b366Bump version from "10.6.0-beta.2" to "10.6.0-beta.3" [skip ci]0ad1336Bump version from "10.6.0-beta.1" to "10.6.0-beta.2" [skip ci]16359eeBump version from "10.6.0-beta.0" to "10.6.0-beta.1" [skip ci]2e0e2f6Bump version from "10.6.0-alpha.9" to "10.6.0-beta.0" [skip ci]6a6dec2Bump version from "10.6.0-alpha.8" to "10.6.0-alpha.9" [skip ci]cd2d163Bump version from "10.6.0-alpha.7" to "10.6.0-alpha.8" [skip ci]898f0ceBump version from "10.6.0-alpha.6" to "10.6.0-alpha.7" [skip ci]71af1ebESLint Plugin: Restore Node types after cross-package CSF importsUpdates
globalsfrom 17.11.0 to 17.12.0Release notes
Sourced from globals's releases.
Commits
98008c317.12.050a2119Update globals (2026-09-01) (#353)779a11aAdd__webpack_layer__global (#351)Updates
jsdomfrom 29.1.1 to 30.1.1Release notes
Sourced from jsdom's releases.