Skip to content

Bump the development-dependencies group across 1 directory with 14 updates - #690

Merged
bgentry merged 2 commits into
masterfrom
dependabot/npm_and_yarn/development-dependencies-05a3fbdfd1
Oct 8, 2026
Merged

bgentry merged 2 commits into
masterfrom
dependabot/npm_and_yarn/development-dependencies-05a3fbdfd1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the development-dependencies group with 14 updates in the / directory:

Package From To
@eslint/css 1.4.0 2.0.0
@testing-library/react 16.3.2 16.3.3
@types/node 26.3.0 26.6.3
eslint 10.9.1 10.11.0
eslint-plugin-perfectionist 5.10.1 5.12.1
eslint-plugin-react-refresh 0.5.4 0.5.7
eslint-plugin-storybook 10.5.10 10.6.1
globals 17.11.0 17.12.0
jsdom 29.1.1 30.1.1
prettier 3.9.6 3.9.9
tailwind-csstree 0.3.3 0.4.1
typescript-eslint 8.68.0 8.71.0
vite 8.2.2 8.3.1
vitest 4.1.11 5.0.3

Updates @eslint/css from 1.4.0 to 2.0.0

Release notes

Sourced from @​eslint/css's releases.

css: v2.0.0

2.0.0 (2026-09-01)

⚠ BREAKING CHANGES

  • add meta.languages to CSS rules (#447)

Features

Bug Fixes

  • correctly identify font-size in font shorthand (#526) (7ac061e)
  • detect equivalent selectors in no-duplicate-keyframe-selectors (#512) (f4fbea8)
  • distinguish named timeline range keyframe selectors (#507) (c96ceeb)
  • handle CSS case-insensitivity (#530) (c979a85)
  • locate !important after the value in no-important (#550) (a851d5c)
  • recognize nesting feature detection in use-baseline (#531) (de5965b)
  • skip validating values containing env() in no-invalid-properties (#510) (ffc5c32)
  • update baseline data (005db74)
  • update baseline data (43672ee)
  • update baseline data (1ae3a41)
  • update baseline data (#504) (e90e001)
  • update baseline data (#514) (1c8a632)
  • update baseline data (#539) (0f7b823)
  • update baseline data (#548) (2c95233)
  • update dependency @​eslint/css-tree to ^4.0.5 (#511) (500ad2a)
Changelog

Sourced from @​eslint/css's changelog.

2.0.0 (2026-09-01)

⚠ BREAKING CHANGES

  • add meta.languages to CSS rules (#447)

Features

Bug Fixes

  • correctly identify font-size in font shorthand (#526) (7ac061e)
  • detect equivalent selectors in no-duplicate-keyframe-selectors (#512) (f4fbea8)
  • distinguish named timeline range keyframe selectors (#507) (c96ceeb)
  • handle CSS case-insensitivity (#530) (c979a85)
  • locate !important after the value in no-important (#550) (a851d5c)
  • recognize nesting feature detection in use-baseline (#531) (de5965b)
  • skip validating values containing env() in no-invalid-properties (#510) (ffc5c32)
  • update baseline data (005db74)
  • update baseline data (43672ee)
  • update baseline data (1ae3a41)
  • update baseline data (#504) (e90e001)
  • update baseline data (#514) (1c8a632)
  • update baseline data (#539) (0f7b823)
  • update baseline data (#548) (2c95233)
  • update dependency @​eslint/css-tree to ^4.0.5 (#511) (500ad2a)
Commits
  • cb52353 chore: release 2.0.0 🚀 (#489)
  • 510403e chore: update dependency @​eslint/json to ^2.1.0 (#552)
  • c5e7b51 docs: Update README sponsors
  • a851d5c fix: locate !important after the value in no-important (#550)
  • 506bdbb feat: check CSS-wide keywords in use-baseline (#542)
  • 2c95233 fix: update baseline data (#548)
  • 6a3b5c4 chore: update actions/checkout action to v7 (#544)
  • 3fa306c chore: update actions/setup-node action to v7 (#545)
  • 3e7f3d4 chore: update googleapis/release-please-action action to v5 (#547)
  • a340c84 chore: update dependency c8 to v12 (#546)
  • Additional commits viewable in compare view

Updates @testing-library/react from 16.3.2 to 16.3.3

Release notes

Sourced from @​testing-library/react's releases.

v16.3.3

16.3.3 (2026-08-27)

Bug Fixes

  • Avoid act() re-entrant when dispatching events (#1468) (20ce75f)
Commits

Updates @types/node from 26.3.0 to 26.6.3

Commits

Updates eslint from 10.9.1 to 10.11.0

Release notes

Sourced from eslint's releases.

v10.11.0

Features

  • d136fa4 feat: object-shorthand handle quoted properties for ignoreConstructors (#21271) (Pavel)
  • 397b3b8 feat: report unsafe labeled continue in no-unsafe-finally rule (#21316) (electrohyun)
  • d3dd47f feat: only exempt new-cap built-ins that reference the global (#21290) (sethamus)

Bug Fixes

  • 22b09f5 fix: ignore __proto__ properties in prefer-object-spread (#21311) (xbinaryx)
  • b684bb1 fix: make TimePass.parse optional in types and docs (#21313) (ntnyq)
  • 26d11bc fix: don't report __proto__ properties in object-shorthand (#21310) (xbinaryx)

Documentation

  • 9ecfdc5 docs: note that --cache can serve stale results for cross-file rules (#21312) (bytedoe)
  • 6c789ff docs: Update README (GitHub Actions Bot)
  • 5997825 docs: clarify preserve-caught-error known limitation (#21294) (Akinyemi Toluwalase)

Chores

  • 520dd77 perf: Implement fast paths in critical areas (#21210) (Nicholas C. Zakas)
  • 92086c8 test: update EMFILE error generation for Node.js 26.9.0 compatibility (#21330) (Francesco Trotta)
  • 9ac7eb6 chore: update github/codeql-action action to v4.38.0 (#21331) (renovate[bot])
  • 24310e3 chore: update ecosystem plugins (#21324) (ESLint Bot)
  • 45ad79e ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (#21318) (dependabot[bot])
  • ac74e37 chore: Add AGENTS.md with AI disclosure requirements (#21221) (Nicholas C. Zakas)
  • c832660 chore: Upgrade Stylelint to the latest version in docs (#21245) (Jung Hyeon Jun)
  • f9f88fc chore: update ecosystem plugins (#21308) (ESLint Bot)
  • fc81076 ci: add more types integration tests (#20395) (Nitin Kumar)

v10.10.0

Features

  • 264b434 feat: add d and v flags to no-unexpected-multiline (#21305) (Gihyeon Jeong / 정기현)
  • c6cc6c5 feat: check Object.prototype property names in new-cap (#21269) (crimsonjay0)
  • 5661fa6 feat: no-extra-bind false negatives with class fields and static blocks (#21260) (synthex-byte)

Bug Fixes

  • bb47dc6 fix: update dependency file-entry-cache to v11 (#20801) (Milos Djermanovic)
  • 427ac0a fix: use format strings in debug calls (#21247) (Francesco Trotta)
  • 9d81532 fix: support __proto__ in /* exported */ comments (#21261) (sethamus)
  • 87e0a08 fix: prefer-object-has-own autofix breaks when Object is shadowed (#21282) (김채영)
  • 8e2cb14 fix: new-cap false positive for UTC calls with properties: false (#21275) (Pixel)
  • 9f4a364 fix: Ignore static imports in no-unreachable (#21276) (Taha Kotil)

Documentation

  • 2417cad docs: Update README (GitHub Actions Bot)
  • 9cecb8a docs: document \c control letter escapes in no-control-regex (#21286) (한국)
  • 8724829 docs: update compat table links (#21263) (fnx)
  • 5634542 docs: Clarify eqeqeq suggestion behavior (#21256) (Müslüm Yılmaz)

Chores

  • b3d876b chore: disable npm audit in ecosystem tests (#21306) (Francesco Trotta)
  • 1696682 ci: restore EMFILE test on Node.js 26 (#21297) (Marry (Subin Yang))

... (truncated)

Commits
  • 3c0b7c6 10.11.0
  • 321f0a7 Build: changelog update for 10.11.0
  • 520dd77 perf: Implement fast paths in critical areas (#21210)
  • 9ecfdc5 docs: note that --cache can serve stale results for cross-file rules (#21312)
  • 92086c8 test: update EMFILE error generation for Node.js 26.9.0 compatibility (#21330)
  • 9ac7eb6 chore: update github/codeql-action action to v4.38.0 (#21331)
  • 22b09f5 fix: ignore __proto__ properties in prefer-object-spread (#21311)
  • 24310e3 chore: update ecosystem plugins (#21324)
  • d136fa4 feat: object-shorthand handle quoted properties for ignoreConstructors (#21...
  • 45ad79e ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 (#21318)
  • Additional commits viewable in compare view

Updates eslint-plugin-perfectionist from 5.10.1 to 5.12.1

Release notes

Sourced from eslint-plugin-perfectionist's releases.

v5.12.1

   🐞 Bug Fixes

    View changes on GitHub

v5.12.0

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub

v5.11.1

   🐞 Bug Fixes

  • Add safety semicolon when the next element continues an expression  -  by @​azat-io (bbb4d)
  • sort-modules: Detect decorator metadata dependencies without tsconfig  -  by @​azat-io (be18b)

   🏎 Performance

    View changes on GitHub

v5.11.0

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub
Changelog

Sourced from eslint-plugin-perfectionist's changelog.

v5.12.1

compare changes

🐞 Bug Fixes

  • Make eslint an optional peer dependency (41b088e)

❤️ Contributors

v5.12.0

compare changes

🚀 Features

  • Support oxlint without an eslint installation (5488d84)

🐞 Bug Fixes

  • Honor eslint-disable directives with a description (e3d11cc)

❤️ Contributors

v5.11.1

compare changes

🏎 Performance Improvements

  • Build a sortable list's fix once instead of once per report (784725a)

🐞 Bug Fixes

  • sort-modules: Detect decorator metadata dependencies without tsconfig (be18b94)
  • Add safety semicolon when the next element continues an expression (bbb4db2)

❤️ Contributors

... (truncated)

Commits
  • 43c3464 build: publish v5.12.1
  • 41b088e fix: make eslint an optional peer dependency
  • e28e3a0 build: publish v5.12.0
  • 521314f chore: update dependencies
  • 5488d84 feat: support oxlint without an eslint installation
  • 38eb692 refactor: share context option matching and comparators
  • e3d11cc fix: honor eslint-disable directives with a description
  • f7eae67 chore: update github actions
  • 3e100d2 build: publish v5.11.1
  • ef12a53 chore: update dependencies
  • Additional commits viewable in compare view

Updates eslint-plugin-react-refresh from 0.5.4 to 0.5.7

Release notes

Sourced from eslint-plugin-react-refresh's releases.

v0.5.7

Add allowCompoundComponents option (#117)

Default: false (true in vite config)

Don't warn when components are exported as an object gathering them. Every member of the object must be a component, and a member holding an anonymous function requires a component name as key.

This should be enabled if the fast refresh implementation correctly handles this case. Vite supports it since @vitejs/plugin-react 4.7.0, @vitejs/plugin-react-swc 3.11.0.

{
  "react-refresh/only-export-components": [
    "error",
    { "allowCompoundComponents": true }
  ]
}

Enabling this option allows code such as the following:

const Root = () => <></>;
const Label = () => <></>;
export const Tag = { Root, Label };

v0.5.6

  • Support re-exporting namespace components (fixes #116)

v0.5.5

  • Fix SCREAMING_SNAKE_CASE constant exported via export { Name } incorrectly treated as React component #114 (fixes #113)
  • Add contentType and size to allowExportNames in Next config #115
Changelog

Sourced from eslint-plugin-react-refresh's changelog.

0.5.7

Add allowCompoundComponents option (#117)

Default: false (true in vite config)

Don't warn when components are exported as an object gathering them. Every member of the object must be a component, and a member holding an anonymous function requires a component name as key.

This should be enabled if the fast refresh implementation correctly handles this case. Vite supports it since @vitejs/plugin-react 4.7.0, @vitejs/plugin-react-swc 3.11.0.

{
  "react-refresh/only-export-components": [
    "error",
    { "allowCompoundComponents": true }
  ]
}

Enabling this option allows code such as the following:

const Root = () => <></>;
const Label = () => <></>;
export const Tag = { Root, Label };

0.5.6

  • Support re-exporting namespace components (fixes #116)

0.5.5

  • Fix SCREAMING_SNAKE_CASE constant exported via export { Name } incorrectly treated as React component #114 (fixes #113)
  • Add contentType and size to allowExportNames in Next config #115
Commits
  • fd40d83 Add allowCompoundComponents option [publish] (#117)
  • 620568a Support re-exporting namespace components (fixes #116) [publish]
  • 65c3172 [publish] v0.5.5
  • 8411020 Bump deps
  • c28fa15 Fix SCREAMING_SNAKE_CASE constant exported via export { Name } incorrectly ...
  • 554c764 [publish] add contentType and size to allowExportNames in Next config (#115)
  • See full diff in compare view

Updates eslint-plugin-storybook from 10.5.10 to 10.6.1

Release notes

Sourced from eslint-plugin-storybook's releases.

v10.6.1

10.6.1

v10.6.0

10.6.0

New skills architecture for agentic workflows

Storybook 10.6 contains hundreds of fixes and improvements:

  • 💻 CLI bindings for agent tools/skills
  • 🅰️ Angular-Vite MCP/skills support and improved docgen/snippets (experimental)
  • 🟢 Vue MCP/skills support and improved docgen/snippets (experimental)
  • 🧩 Tanstack / NextJS-Vite framework bugfixes
  • ⚡ Improved performance and reduced bundle size

... (truncated)

Changelog

Sourced from eslint-plugin-storybook's changelog.

10.6.1

10.6.0

New skills architecture for agentic workflows

Storybook 10.6 contains hundreds of fixes and improvements:

  • 💻 CLI bindings for agent tools/skills
  • 🅰️ Angular-Vite MCP/skills support and improved docgen/snippets (experimental)
  • 🟢 Vue MCP/skills support and improved docgen/snippets (experimental)
  • 🧩 Tanstack / NextJS-Vite framework bugfixes
  • ⚡ Improved performance and reduced bundle size

... (truncated)

Commits
  • a17b725 Bump version from "10.6.0" to "10.6.1" [skip ci]
  • a777773 Bump version from "10.6.0-beta.3" to "10.6.0" [skip ci]
  • f32b366 Bump version from "10.6.0-beta.2" to "10.6.0-beta.3" [skip ci]
  • 0ad1336 Bump version from "10.6.0-beta.1" to "10.6.0-beta.2" [skip ci]
  • 16359ee Bump version from "10.6.0-beta.0" to "10.6.0-beta.1" [skip ci]
  • 2e0e2f6 Bump version from "10.6.0-alpha.9" to "10.6.0-beta.0" [skip ci]
  • 6a6dec2 Bump version from "10.6.0-alpha.8" to "10.6.0-alpha.9" [skip ci]
  • cd2d163 Bump version from "10.6.0-alpha.7" to "10.6.0-alpha.8" [skip ci]
  • 898f0ce Bump version from "10.6.0-alpha.6" to "10.6.0-alpha.7" [skip ci]
  • 71af1eb ESLint Plugin: Restore Node types after cross-package CSF imports
  • Additional commits viewable in compare view

Updates globals from 17.11.0 to 17.12.0

Release notes

Sourced from globals's releases.

v17.12.0

  • Update globals (2026-09-01) (#353) 50a2119
  • Add __webpack_layer__ global (#351) 779a11a

sindresorhus/globals@v17.11.0...v17.12.0

Commits

Updates jsdom from 29.1.1 to 30.1.1

Release notes

Sourced from jsdom's releases.

v30.1.1

  • Fixed spurious window blur and focusout events and incorrect event.relatedTarget values when focusing an element after removing the previously focused element, which regressed in v30.1.0. (@​asamuzaK)
  • Fixed focus and blur behavior across frames, and focusing the document's viewport through document.documentElement.focus(). (@​asamuzaK)
  • Fixed focus targets removed or disabled by blur listeners becoming active, and text selections made by focus and blur listeners being overwritten. (@​asamuzaK)
  • Fixed element.focus() incorrectly focusing disabled form controls and <input type="hidden"> elements with tabindex="". (@​scttcper)
  • Fixed invalid style.setProperty() calls changing existing !important priorities, serialized styles, or mutation records. (@​FedgeNo)
  • Fixed !important handling when updating CSS longhands after shorthands, using variables or CSS-wide keywords, and assigning style properties directly. (@​FedgeNo)
  • Fixed <noscript> parsing with includeNodeLocations: true or inside frames to honor the runScripts option.
  • Fixed the storageQuota option being ignored by frames.
  • Fixed encoding detection of HTML and XML byte input to honor XML encoding declarations and detect UTF-16 without a byte order mark.
  • Fixed exceptions caused by truncated charset parameters in <meta> elements, and encoding detection incorrectly using incomplete <meta> tags. (@​FedgeNo)
  • Fixed XML serialization errors for namespaces named constructor, toString, __proto__, or "null", and incorrect reuse of namespace prefixes declared on sibling elements.
  • Fixed element.innerHTML and element.outerHTML in XML documents to reject invalid characters in attribute values and avoid stack overflows on large st...

    Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 1, 2026
@bgentry

bgentry commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot dependabot Bot changed the title Bump the development-dependencies group with 14 updates Bump the development-dependencies group across 1 directory with 14 updates Oct 8, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/development-dependencies-05a3fbdfd1 branch from a36b457 to 8e3ecf2 Compare October 8, 2026 00:59

@bgentry bgentry left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Codex review: Changes requested — dependency security review is clear, but the exact-head install fails on the repository's supported Node version.

Blocking compatibility finding
On Node 24.14.1 / npm 11.11.0, npm ci --ignore-scripts exits EBADENGINE: current @asamuzakjp/css-color@7.1.2 requires ^22.22.2 || ^24.15.0 || >=26.0.0. jsdom 30.1.1 and related selector/color packages also raise that floor. The repository's engine-strict=true, Node pin, CI, and container build use 24.14.1. Resolve the Node support/pin mismatch consistently, or retain a compatible jsdom dependency set; then rerun installation, tests, lint, TypeScript and builds. Do not force/ignore engines to merge this head.

Upgrade

  • 14 development dependencies, including ESLint/CSS, testing-library, Node types, perfectionist/React-refresh/Storybook ESLint plugins, globals, jsdom 29.1.1→30.1.1, Prettier, tailwind-csstree, typescript-eslint, Vite and Vitest 4.1.11→5.0.3 (current rebased resolution).
  • Reviewed head: 8e3ecf25aa47661e9c96947a20f13dd30c59a55e, base dfedb5e36e3362ec492f64946baf5254044e94a4.

Security review

  • Reviewed every direct artifact and notable transitive/native/parser churn. The cumulative exact-version/integrity ledger covers 222 initial/rebased artifacts; all downloaded SHA-512 values match registry and their applicable lock entries, and all npm registry signatures verify. All 152 advertised SLSA bundles verify with their expected artifact subjects and publishing identities. Old/new source evidence is reused only for identical artifact pairs; additional versions resolved during rebase received delta review.
  • No same-version integrity rewrite, source substitution, new install hook, unexpected CLI/native platform family, secret harvesting, or exfiltration path found. Reviewed Vitest's bundled-internal refactor, Vite/Rolldown, jsdom/parser/color and undici churn, ESLint/TypeScript tooling and formatter/compiler changes. Existing package-purpose process/native behavior remains.
  • Current Undici 7.29.0→8.11.2 incorporates ten matched advisory fixes, using the verified 8.x fixed boundary 8.10.2. No new applicable advisory found in the changed artifact set.

Compatibility verification

  • npm ci --ignore-scripts — failed with the engine mismatch above, independently matching current-head GitHub CI.
  • Executable frontend tests/lint/builds are not run because supported-version installation fails. No lifecycle code was executed by this reproduction.
  • Shared baseline all-module make test/race and make lint pass; this PR leaves Go source/module/config inputs unchanged.
  • Required Pro image CI also fails before build with AWS OIDC Not authorized to perform sts:AssumeRoleWithWebIdentity; resolving the npm mismatch alone does not clear that merge requirement.

Residual risk
Rolldown native binaries and large generated bundles were inspected through immutable hashes, signatures/provenance and source context, not independent rebuild/disassembly of every platform binary. Existing unrelated critical shell-quote and selector-parser alerts remain in the tree; this review clears the upgrade's supply-chain delta, not all repository vulnerabilities. Node compatibility and required AWS CI remain unresolved.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/development-dependencies-05a3fbdfd1 branch 2 times, most recently from bd71005 to b04ef3c Compare October 8, 2026 01:45
…dates

Bumps the development-dependencies group with 14 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@eslint/css](https://github.com/eslint/css) | `1.4.0` | `2.0.0` |
| [@testing-library/react](https://github.com/testing-library/react-testing-library) | `16.3.2` | `16.3.3` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.3.0` | `26.6.3` |
| [eslint](https://github.com/eslint/eslint) | `10.9.1` | `10.11.0` |
| [eslint-plugin-perfectionist](https://github.com/azat-io/eslint-plugin-perfectionist) | `5.10.1` | `5.12.1` |
| [eslint-plugin-react-refresh](https://github.com/ArnaudBarre/eslint-plugin-react-refresh) | `0.5.4` | `0.5.7` |
| [eslint-plugin-storybook](https://github.com/storybookjs/storybook/tree/HEAD/code/lib/eslint-plugin) | `10.5.10` | `10.6.1` |
| [globals](https://github.com/sindresorhus/globals) | `17.11.0` | `17.12.0` |
| [jsdom](https://github.com/jsdom/jsdom) | `29.1.1` | `30.1.1` |
| [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.9` |
| [tailwind-csstree](https://github.com/humanwhocodes/tailwind-csstree) | `0.3.3` | `0.4.1` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.68.0` | `8.71.0` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.2.2` | `8.3.1` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.11` | `5.0.3` |



Updates `@eslint/css` from 1.4.0 to 2.0.0
- [Release notes](https://github.com/eslint/css/releases)
- [Changelog](https://github.com/eslint/css/blob/main/CHANGELOG.md)
- [Commits](eslint/css@css-v1.4.0...css-v2.0.0)

Updates `@testing-library/react` from 16.3.2 to 16.3.3
- [Release notes](https://github.com/testing-library/react-testing-library/releases)
- [Changelog](https://github.com/testing-library/react-testing-library/blob/main/CHANGELOG.md)
- [Commits](testing-library/react-testing-library@v16.3.2...v16.3.3)

Updates `@types/node` from 26.3.0 to 26.6.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `eslint` from 10.9.1 to 10.11.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.9.1...v10.11.0)

Updates `eslint-plugin-perfectionist` from 5.10.1 to 5.12.1
- [Release notes](https://github.com/azat-io/eslint-plugin-perfectionist/releases)
- [Changelog](https://github.com/azat-io/eslint-plugin-perfectionist/blob/main/changelog.md)
- [Commits](azat-io/eslint-plugin-perfectionist@v5.10.1...v5.12.1)

Updates `eslint-plugin-react-refresh` from 0.5.4 to 0.5.7
- [Release notes](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/releases)
- [Changelog](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/blob/main/CHANGELOG.md)
- [Commits](ArnaudBarre/eslint-plugin-react-refresh@v0.5.4...v0.5.7)

Updates `eslint-plugin-storybook` from 10.5.10 to 10.6.1
- [Release notes](https://github.com/storybookjs/storybook/releases)
- [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md)
- [Commits](https://github.com/storybookjs/storybook/commits/v10.6.1/code/lib/eslint-plugin)

Updates `globals` from 17.11.0 to 17.12.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.11.0...v17.12.0)

Updates `jsdom` from 29.1.1 to 30.1.1
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v29.1.1...v30.1.1)

Updates `prettier` from 3.9.6 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.6...3.9.9)

Updates `tailwind-csstree` from 0.3.3 to 0.4.1
- [Release notes](https://github.com/humanwhocodes/tailwind-csstree/releases)
- [Changelog](https://github.com/humanwhocodes/tailwind-csstree/blob/main/CHANGELOG.md)
- [Commits](humanwhocodes/tailwind-csstree@tailwind-csstree-v0.3.3...tailwind-csstree-v0.4.1)

Updates `typescript-eslint` from 8.68.0 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/typescript-eslint)

Updates `vite` from 8.2.2 to 8.3.1
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite)

Updates `vitest` from 4.1.11 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

---
updated-dependencies:
- dependency-name: "@eslint/css"
  dependency-version: 2.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: development-dependencies
- dependency-name: "@testing-library/react"
  dependency-version: 16.3.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.6.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: eslint
  dependency-version: 10.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: eslint-plugin-perfectionist
  dependency-version: 5.12.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: eslint-plugin-react-refresh
  dependency-version: 0.5.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: eslint-plugin-storybook
  dependency-version: 10.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: globals
  dependency-version: 17.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: jsdom
  dependency-version: 30.1.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: development-dependencies
- dependency-name: prettier
  dependency-version: 3.9.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-dependencies
- dependency-name: tailwind-csstree
  dependency-version: 0.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: typescript-eslint
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: vite
  dependency-version: 8.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development-dependencies
- dependency-name: vitest
  dependency-version: 5.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: development-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/development-dependencies-05a3fbdfd1 branch from b04ef3c to fa8ac88 Compare October 8, 2026 02:29
Updated jsdom dependencies require a newer Node 24 release, and
Vitest 5 changes the matcher type parameters. The storage mock also
assigns to a read-only jsdom property.

Use Node 24.21.0 in CI, release jobs, and image builders, and declare
the supported Node release lines. Augment Vitest's matcher interface
centrally and register DOM matchers once.

Use jsdom's storage in settings coverage and verify serialized values
so persistence is exercised through the browser API.

@bgentry bgentry left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Codex review: Approved after dependency security review and compatibility fixes on the current head.

Upgrade and exact scope

Reviewed head: d50bb259da2472d47c9090e803593ab10771fea8, based on master 44e7ea9a10dc481a9a2de273cfe2be53bb637169; tree f9bc33b30617dcbd39c8a629352333ea1a0ba16c. This covers all 14 development dependency upgrades in the PR table, plus the Node 24.14.1 → 24.21.0 runtime/image correction. The fix is a single added commit on Dependabot's existing current head; no remote history was rewritten.

Root causes and corrections

  • engine-strict=true makes the old Node 24.14.1 pins fail installation: jsdom 30.1.1 and its CSS dependency require Node 24.15+ on that release line. CI, release jobs and both frontend image builders now use the reviewed Node 24.21.0 runtime; the manifest and lock agree on ^24.15.0 || >=26.0.0, excluding unsupported Node 25.
  • jsdom 30 exposes read-only localStorage; the settings mock assigns to it. Settings coverage now uses actual jsdom Storage, resets it between cases and checks the persisted serialized true/false values.
  • Vitest 5 changes matcher generics. The old test-local Assertion<T> and global jest-dom declaration conflict with its types. One central Matchers<R, T> augmentation supplies the DOM matchers, with runtime registration retained once in setup.

Security review

  • Reused exact registry/source/provenance evidence only when package, version and integrity identities match. Rehashed all 209 relevant old/new/removal artifact identities across the final PR delta and production-group integration; SHA512, registry SHA1 and prior SHA256 match. No new artifact, nonregistry source, same-version integrity rewrite or unexpected lifecycle hook appears in the final integration delta.
  • Duplicate-key-safe lock parsing, exact parent-entry comparison and 730 dependency range checks pass. No hybrid lock entries or unresolved mandatory edges remain. The added commit does not change installed package identities from the current bot head.
  • Independently reviewed the added Node runtime and immutable official Docker image pin for Darwin arm64 and Linux amd64/arm64. Official Darwin/source checksums verify with the release-team GPG key; OCI manifests/layers match their digests and canonical recipes; bundled npm bytes match the signed Node source across platforms.
  • Fresh advisory queries are unchanged from master: existing postcss-selector-parser GHSA-rj75-hqrm-r3gf (moderate) and shell-quote GHSA-pqg4-j6r4-53mv (critical). This PR does not introduce either advisory.

Compatibility verification

All local checks run against the exact final combined tree under reviewed Node 24.21.0/npm 11.19.0:

  • Clean integrity-enforcing npm ci — passed, lock stable.
  • npm run test:once — 243 tests in 35 files passed.
  • npm run lint — passed.
  • npm run build — TypeScript and production Vite build passed.
  • npm run build-storybook — passed.
  • Full OSS Docker image, Linux arm64 — passed; resulting executable -help smoke check passed.
  • Pro frontend Docker stage, Linux amd64 — passed; complete Pro images are checked by GitHub CI.

The prior Dagre fix's full 32-pair comparison across 13 stories in light/dark themes has identical markup/geometry and visually indistinguishable screenshots. A fresh seeded Storybook build of this final combined head additionally passes six browser comparisons: the dense 14-node/19-edge graph before/after Fit View and a resolved transition in both themes. All 11 recorded DOM, SVG, geometry and state fields match exactly in all six. Two screenshots are pixel-identical; the other four differ by 30–59 isolated pixels (max channel difference 14/255), within the same-version repeat control's 59 pixels/24 channel variation. No browser errors or warnings remain.

Residual risk and bounded runtime clearance

This is not a clean vulnerability scan or a reproducible native-binary proof. The preexisting repository advisories above remain. The Node/npm review retains advisory records in bundled npm dependencies with source/reachability assessment for the actual trusted install/build paths; arbitrary hostile query/glob input and optional package-manager features are outside that scope. Optional Corepack 0.36.0 has an unawaited signature-verification call and is explicitly excluded; River invokes bundled npm and does not enable Corepack. Inherited OpenSSL 3.5.8 lacks later 3.5.9 fixes, including DTLS CVE-2026-84782; unchanged OS zlib 1.3.2-r0 lacks the later gz-file API fix, a path not used by Node's JS stream binding. The reviewed builder commands do not enable the affected optional protocol/file operations. Undici's default decompression-limit caveat, large generated/native code, upstream release-key trust, and OCI provenance without independent signature verification remain documented review limits.

@bgentry
bgentry merged commit 281bc35 into master Oct 8, 2026
22 checks passed
@bgentry
bgentry deleted the dependabot/npm_and_yarn/development-dependencies-05a3fbdfd1 branch October 8, 2026 02:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant