Skip to content

chore(deps): consolidate pending dependency updates - #1169

Merged
prisis merged 47 commits into
mainfrom
renovate/consolidate-deps
Oct 3, 2026
Merged

prisis merged 47 commits into
mainfrom
renovate/consolidate-deps

Conversation

@prisis

@prisis prisis commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

What

Consolidates the 24 open dependency-update branches in this repository into a single branch, so the repository moves forward in one reviewable change instead of one per package.

Every catalog and workspace manifest entry is set to the highest version any of those branches requested, and the lockfile is re-resolved so it satisfies the pinned release-age and trust policy.

Each upstream update commit is preserved as a merge commit, so the individual changes stay reviewable with git log.

Follow-up fixes

The @vitest/coverage-v8 v5 PR is excluded: v5 expects vitest 5 while vitest stays on 4.x, which makes takeCoverage throw coverageFilesDirectory is required and fails the suite even though every test passes.

Validation

  • pnpm install --frozen-lockfile
  • the build, lint and test targets this repository gates in CI

Findings that also reproduce on main are left alone rather than fixed here.

After merge

The individual update branches this supersedes can be closed.

Summary by CodeRabbit

  • Chores
    • Updated the package manager version and refreshed shared package versions and compatibility overrides across the workspace.
    • Updated package selections to include fixes for several packages, including an Axios update.
    • Improved handling of package metadata when generating configuration files.

renovate Bot and others added 30 commits October 1, 2026 16:17
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
BREAKING CHANGE: updated dependencies to major versions
BREAKING CHANGE: updated dependencies to major versions
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
…security]

Signed-off-by: Renovate Bot <bot@renovateapp.com>
…12 [security]

Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
…ity]

Signed-off-by: Renovate Bot <bot@renovateapp.com>
…ity]

Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
…ity]

Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
Signed-off-by: Renovate Bot <bot@renovateapp.com>
…rity]

Signed-off-by: Renovate Bot <bot@renovateapp.com>
prisis added 17 commits October 3, 2026 11:12
Raise every catalog and workspace manifest entry to the highest version
requested by the pending update branches, then re-resolve the lockfile so
it satisfies the pinned release-age and trust policy.

Two follow-up fixes for the toolchain these updates pull in:

- `@typescript-eslint/no-unsafe-type-assertion` now rejects the
  `JSON.parse` result cast in the commitlint bin; read the `type` field via
  an `in` narrowing instead of asserting a shape.
- `e18e/ban-dependencies` now flags the `semver` imports the eslint-config
  package legitimately needs; disable the rule on those imports, matching the
  existing suppression for `eslint-plugin-react`.
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Thank you for following the naming conventions! 🙏

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: f66c9f9e-75bc-4c2c-9168-ceabbe663ce7
📥 Commits

Reviewing files that changed from the base of the PR and between 8278997 and 5c6e17a.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (6)
  • package.json
  • packages/commitlint-config/src/bin.ts
  • packages/eslint-config/src/config/plugins/node.ts
  • packages/eslint-config/src/config/plugins/react.ts
  • packages/eslint-config/src/index.ts
  • pnpm-workspace.yaml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The pull request updates the package manager version, workspace catalogs, and dependency overrides. It also changes package type detection in commitlint config and adds ESLint suppressions for selected imports.

Changes

Workspace dependency configuration

Layer / File(s) Summary
Catalogs and workspace settings
package.json, pnpm-workspace.yaml
The package manager version changes to pnpm@11.28.2. Workspace catalog entries are updated, and existing workspace settings are reformatted without changing their listed values.
Dependency overrides and release-age exclusions
pnpm-workspace.yaml
Axios, follow-redirects, ip-address, lodash, lodash-es, nanoid, esbuild, and form-data overrides are added or updated. axios@1.20.0 is added to minimumReleaseAgeExclude.

Commitlint package type detection

Layer / File(s) Summary
Guard package type detection
packages/commitlint-config/src/bin.ts
The code checks that parsed package data is a non-null object with a type property equal to "module" before selecting module syntax.

ESLint dependency-rule suppressions

Layer / File(s) Summary
Suppress selected import checks
packages/eslint-config/src/config/plugins/node.ts, packages/eslint-config/src/config/plugins/react.ts, packages/eslint-config/src/index.ts
Suppressions for e18e/ban-dependencies are added before the selected imports.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 5c6e1

The catalog updates do not introduce the reported root dependency mismatch. No actionable merge-blocking issue remains after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 5c6e1

The change adds a narrowly scoped Axios release-age exception while preserving existing trust and build-script restrictions. The recorded Axios dependency remains unchanged, limiting immediate exposure, but future resolution behavior is not fully established.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The relevant policy is workspace-wide, while the established Axios consumer path is through Nx tooling. This evidence does not establish production-service, tenant-data, or credential exposure.

Trust Boundaries and Controls

  • observed — Axios 1.20.0 is specifically exempted from the workspace's 24-hour release-age control. This is a narrow policy relaxation, not evidence of a malicious package or an exercised attack path; the inspected lockfile still resolves Axios 1.18.1.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: consolidating pending dependency updates.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 4…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Warning

Some tools did not complete. Review the errors below.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

package.json

ESLint skipped: missing config or dependency (missing-dependency). The ESLint configuration references a package that is not available in the sandbox.

packages/commitlint-config/src/bin.ts

ESLint skipped: missing config or dependency (missing-dependency). The ESLint configuration references a package that is not available in the sandbox.

packages/eslint-config/src/config/plugins/node.ts

ESLint skipped: missing config or dependency (missing-dependency). The ESLint configuration references a package that is not available in the sandbox.

  • 2 others

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@prisis
prisis enabled auto-merge (squash) October 3, 2026 10:15
@prisis
prisis merged commit ef0ef8e into main Oct 3, 2026
25 of 26 checks passed
@prisis
prisis deleted the renovate/consolidate-deps branch October 3, 2026 10:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant