fix(deps): update npm dependencies (patch) - #1961
renovate[bot] wants to merge 1 commit into
Conversation
|
|
There was a problem hiding this comment.
🟡 Changes recommended
Critical error-boundary compatibility issues and a CodeMirror lockfile mismatch remain unresolved.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
This Renovate PR updates patch-level npm dependencies across the monorepo and refreshes the shared lockfile.
Changes:
- Updates CodeMirror, TanStack Router, React tooling/types, testing, ESLint, PostCSS, and utility packages.
- Refreshes workspace manifests and transitive lockfile resolutions.
File summaries
| File | Summary |
|---|---|
pnpm-lock.yaml |
Updates dependency resolutions; critical: CodeMirror view/state versions remain mismatched. |
packages/url-state-provider/package.json |
Updates query-string. |
packages/ui-components/package.json |
Updates testing and React DOM types. |
packages/messages-provider/package.json |
Updates React DOM types. |
packages/greenhouse-auth-provider/package.json |
Updates React DOM types. |
packages/config/package.json |
Updates ESLint dependencies. |
apps/template/package.json |
Updates React DOM types. |
apps/supernova/package.json |
Updates router, error boundary, and type dependencies. |
apps/heureka/package.json |
Updates router and related dependencies; critical: error-boundary typing and falsy-value handling require changes. |
apps/greenhouse/package.json |
Updates router, CodeMirror, tooling, and types; critical: error-boundary typing and falsy-value handling require changes. |
apps/example/package.json |
Updates React DOM types. |
apps/doop/package.json |
Updates router and React DOM types. |
apps/carbon/package.json |
Updates error boundary, testing, and React dependencies. |
Review details
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
- Files reviewed: 12/13 changed files
- Comments generated: 4
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| "@codemirror/view": "6.43.11", | ||
| "@tanstack/react-query": "5.102.8", | ||
| "@tanstack/react-router": "1.170.32", | ||
| "@tanstack/react-router": "1.170.33", |
| "@codemirror/view": "6.43.11", | ||
| "@tanstack/react-query": "5.102.8", | ||
| "@tanstack/react-router": "1.170.32", | ||
| "@tanstack/react-router": "1.170.33", |
| "@cloudoperators/juno-url-state-provider": "workspace:*", | ||
| "@tanstack/react-query": "5.102.8", | ||
| "@tanstack/react-router": "1.170.32", | ||
| "@tanstack/react-router": "1.170.33", |
| '@codemirror/view@6.43.10': | ||
| '@codemirror/view@6.43.11': | ||
| dependencies: | ||
| '@codemirror/state': 6.7.2 |
5a1258f to
4a707e4
Compare
4a707e4 to
5784387
Compare
This PR contains the following updates:
6.7.2→6.7.56.43.10→6.43.122.1.0→2.1.11.170.32→1.170.361.168.35→1.168.3814.6.6→14.6.724.13.3→24.13.519.2.5→19.2.70.5.5→0.5.78.5.26→8.5.283.9.6→3.9.79.5.0→9.5.16.1.4→6.1.51.14.1→1.14.2Release Notes
eslint/rewrite (@eslint/compat)
v2.1.1Compare Source
Bug Fixes
TanStack/router (@tanstack/react-router)
v1.170.36Compare Source
Patch Changes
#8390
b747fb8- Keep the Link location cache out of server bundles:buildLocationonly creates, reads and writes it whenisServeris false. Render React Links on the server without the extra prop copies and the forwarded-ref hook. Link SSR rendering is 20-40% faster in the Link benchmarks and the React Start SSR request loop about 7% faster.React
activePropsandinactivePropsnow follow one precedence rule on every link, including links whose destination is blocked for using a disallowed scheme: state props override element props,refand event handlers, whilehref,disabledandtargetstay controlled by the router. Previously a blocked link ignored arefor handler from its inactive props.React
LinkanduseLinkPropssplit router options from element props with one key set on the client and the server. Element props pass through as given: external links forward them verbatim, falsy values included, anduseLinkPropsnow returnschildrenfor router-controlled links as it already did for external ones.#8324
6387d58- Reuse hydration snapshot getters to avoid unnecessary store-instance effect updates when Links and other hydration-aware components rerender.#8318
9b2adaf- Allow active and inactive Link props to override base element props in React and Solid while preserving class/style merging. Keep React'shref,target, anddisabledvalues controlled by routing options. Preserve Vue object and nested-array class bindings, including reactive updates and server rendering, without mutating cached bindings during VNode normalization.#8327
634da91- MakepathParamsAllowedCharactersinitialization-only. Configure it when creating the router; changing allowed characters requires a new router instance. Remove decoder-update bookkeeping and decoder-change checks from route-owned path caches.#8370
e9396c9- Stop exporting the internalisPlainObjectandisPlainArrayhelpers.#8324
6387d58- Avoid a redundant prop copy when rendering native Links while preserving custom-component props and the public hook result.#8252
7e349c3- Reduce the bundle cost of shared Link pathname interpolation while preserving its rendering performance. Reuse one interpolation pass for pathname and optional metadata, keep the bounded cache on the router, and simplify React Link active-state and prop merging.#8370
e9396c9- Reuse built locations for Links whose destination does not depend on the current location.buildLocationkeeps the result per options object when the build never read the current location, and the ReactLinkpasses one stable options object per instance, so navigations resolve unchanged Links with a lookup instead of a full build. The per-route pathname interpolation cache this replaces is removed. Linkparams,searchandactiveOptionsare compared by value on render, so inline object literals with unchanged contents keep reusing the Link's location. Pass a new object to change a destination; like any other React prop, an object mutated in place is not re-read.Updated dependencies [
d76a332,b747fb8,6cfb1e8,700a714,700a714,8fff7fa,f021f6d,ae68535,7e349c3,873c830,7e349c3,634da91,e9396c9,634da91,f151ab0,bc57fa3,9872d2a,d76a332,634da91,634da91,7e349c3,9448caa,e9396c9,700a714,634da91,634da91]:v1.170.35Compare Source
Patch Changes
8c43c71- Upgrade TanStack Store to 0.11 and migrate router subscriptions to useSelector, preserving selector comparisons and Vue subscription cleanup.v1.170.34Compare Source
Patch Changes
#8279
aee42c6- Avoid allocating event-handler arrays and wrapper functions for links without user-supplied event handlers.#8308
9c1871c- Validate navigation and redirect destinations, keep ambiguous relative URLs on the current origin, and constrain prerender requests and output paths. Prevent redirect headers from appearing in serialized server function response bodies.Preserve native form HTTP redirects, route error handling and masks for document redirects, and per-navigation destinations for shared loader redirects. Avoid redundant origin parsing and reduce link styling and server-rendering work. Configured origins must already be normalized.
Keep blocked-link inactive props consistent during React hydration, honor explicit redirect Location headers before checking route options, and refresh Vue link state when destinations become internal. Reuse the protocol-relative URL check while parsing redirect schemes once.
Reduce React link bundle size by sharing pathname comparisons, state-prop selection, and element creation.
Share normalized pathname comparisons in Solid and Vue links to reduce bundle size.
#8311
9aec5a7- React Links resolve state props without temporary class-name arrays or unnecessary style copies.Updated dependencies [
f9836f1,9c1871c,9871c06,0654c0a]:v1.170.33Compare Source
Patch Changes
#8165
2f20c00- Exclude structural descendants below error and not-found boundaries from route lifecycle callbacks. Preserve lifecycle membership through invalidation, hydration, background reloads, and superseded navigation publication.#8209
28a5e45- Preserve falsy thrown values in React and Vue error boundaries. Type React and Vue boundary error components andonCatchcallbacks asunknown. Solid boundary errors remain typed asError; SSR now wraps non-Errorloader errors to match Solid’s native boundary behavior, preserving the original value incause. Router state and loaderonErrorvalues are unchanged.When upgrading React or Vue, narrow boundary errors (for example, with
error instanceof Error) before readingmessageorstack.ErrorComponentProps<TError>remains available for values narrowed to a specific error type. RouteonErrortypes are unchanged.#8161
f0b5eda- Retain successful not-found matches as terminal shared boundaries during client navigation, preserving route context while the destination loads.#8251
0497cae- Use URL.canParse for absolute URL checks in links, navigation, redirects, and build configuration. Preserve a URL constructor fallback for older browsers.#8169
0caf6b9- Fix route-scopeduseMatch,useSearch, anduseParamsAPIs to forward theshouldThrowoption and preserve optional return types whenshouldThrow: false.#8257
cf166d1- Fix repeatedinnerHTMLwrites for unchanged styles and data scripts during React re-renders. This prevents unnecessary CSS parsing and Trusted Types errors during client navigation.Updated dependencies [
edf0e16,2f20c00,28a5e45,08eff50,216c0c4,2f91503,f0b5eda,50eafca,0497cae,ee28348,9035abc,c18e690]:TanStack/router (@tanstack/router-plugin)
v1.168.38Compare Source
Patch Changes
d76a332,b747fb8,6cfb1e8,700a714,700a714,6387d58,7e349c3,9b2adaf,873c830,7e349c3,634da91,e9396c9,634da91,f151ab0,bc57fa3,6387d58,9872d2a,d76a332,634da91,634da91,7e349c3,9448caa,e9396c9,700a714,634da91,634da91]:v1.168.37Compare Source
Patch Changes
#8300
49bcd4d- Refresh compatible build and runtime dependencies.Updated dependencies [
f9836f1,aee42c6,49bcd4d,9c1871c,9aec5a7,9871c06,0654c0a]:v1.168.36Compare Source
Patch Changes
edf0e16,2f20c00,28a5e45,08eff50,216c0c4,2f91503,f0b5eda,50eafca,0497cae,0caf6b9,ee28348,cf166d1,c18e690]:testing-library/user-event (@testing-library/user-event)
v14.6.7Compare Source
ArnaudBarre/eslint-plugin-react-refresh (eslint-plugin-react-refresh)
v0.5.7Compare Source
Add
allowCompoundComponentsoption (#117)Don't warn when components are exported as an object gathering them. Every member of the object must be a component, and a member holding an anonymous function requires a component name as key.
This should be enabled if the fast refresh implementation correctly handles this case. Vite supports it since
@vitejs/plugin-react4.7.0,@vitejs/plugin-react-swc3.11.0.{ "react-refresh/only-export-components": [ "error", { "allowCompoundComponents": true } ] }Enabling this option allows code such as the following:
v0.5.6Compare Source
postcss/postcss (postcss)
v8.5.28Compare Source
v8.5.27Compare Source
/*#(by @dylanpulver).*hack before a comment in Custom Properties (by @Jaybhade).list.comma()(by @MahinAnowar).list.space()(by @MahinAnowar).prettier/prettier (prettier)
v3.9.7Compare Source
🔗 Changelog
sindresorhus/query-string (query-string)
v9.5.1Compare Source
stringifyUrl()dropping a leading#in the fragment identifier and throwing on some absolute URLs47b5b30bvaughn/react-error-boundary (react-error-boundary)
v6.1.5Compare Source
withErrorBoundarykonnorrogers/shadow-dom-testing-library (shadow-dom-testing-library)
v1.14.2Compare Source
Configuration
📅 Schedule: (in timezone Europe/Berlin)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.