chore(deps): consolidate pending dependency updates - #1169
Conversation
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
BREAKING CHANGE: updated dependencies to major versions
BREAKING CHANGE: updated dependencies to major versions
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
…security] Signed-off-by: Renovate Bot <bot@renovateapp.com>
…12 [security] Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
…ity] Signed-off-by: Renovate Bot <bot@renovateapp.com>
…ity] Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
…ity] Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
…rity] Signed-off-by: Renovate Bot <bot@renovateapp.com>
…into renovate/consolidate-deps
…' into renovate/consolidate-deps
…ate/consolidate-deps
…ate/consolidate-deps
…renovate/consolidate-deps
…renovate/consolidate-deps
…/consolidate-deps
…/consolidate-deps
…/consolidate-deps
…enovate/consolidate-deps
…novate/consolidate-deps
…enovate/consolidate-deps
Raise every catalog and workspace manifest entry to the highest version requested by the pending update branches, then re-resolve the lockfile so it satisfies the pinned release-age and trust policy. Two follow-up fixes for the toolchain these updates pull in: - `@typescript-eslint/no-unsafe-type-assertion` now rejects the `JSON.parse` result cast in the commitlint bin; read the `type` field via an `in` narrowing instead of asserting a shape. - `e18e/ban-dependencies` now flags the `semver` imports the eslint-config package legitimately needs; disable the rule on those imports, matching the existing suppression for `eslint-plugin-react`.
|
Thank you for following the naming conventions! 🙏 |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (6)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe pull request updates the package manager version, workspace catalogs, and dependency overrides. It also changes package type detection in commitlint config and adds ESLint suppressions for selected imports. ChangesWorkspace dependency configuration
Commitlint package type detection
ESLint dependency-rule suppressions
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Other Merge Risk: ⚪ Minimal · up to The catalog updates do not introduce the reported root dependency mismatch. No actionable merge-blocking issue remains after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change adds a narrowly scoped Axios release-age exception while preserving existing trust and build-script restrictions. The recorded Axios dependency remains unchanged, limiting immediate exposure, but future resolution behavior is not fully established. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
📝 Generate docstrings
🧪 Generate unit tests (beta)
Warning Some tools did not complete. Review the errors below. 🔧 ESLint
package.jsonESLint skipped: missing config or dependency (missing-dependency). The ESLint configuration references a package that is not available in the sandbox. packages/commitlint-config/src/bin.tsESLint skipped: missing config or dependency (missing-dependency). The ESLint configuration references a package that is not available in the sandbox. packages/eslint-config/src/config/plugins/node.tsESLint skipped: missing config or dependency (missing-dependency). The ESLint configuration references a package that is not available in the sandbox.
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
What
Consolidates the 24 open dependency-update branches in this repository into a single branch, so the repository moves forward in one reviewable change instead of one per package.
Every catalog and workspace manifest entry is set to the highest version any of those branches requested, and the lockfile is re-resolved so it satisfies the pinned release-age and trust policy.
Each upstream update commit is preserved as a merge commit, so the individual changes stay reviewable with
git log.Follow-up fixes
The
@vitest/coverage-v8v5 PR is excluded: v5 expects vitest 5 while vitest stays on 4.x, which makestakeCoveragethrowcoverageFilesDirectory is requiredand fails the suite even though every test passes.Validation
pnpm install --frozen-lockfileFindings that also reproduce on
mainare left alone rather than fixed here.After merge
The individual update branches this supersedes can be closed.
Summary by CodeRabbit