Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): pin dependencies #3816

Closed
wants to merge 1 commit into from
Closed

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Mar 8, 2025

This PR contains the following updates:

Package Type Update Change
@biomejs/biome (source) devDependencies pin ^1.9.4 -> 1.9.4
@deepgram/sdk dependencies pin ^3.9.0 -> 3.11.1
@docusaurus/plugin-ideal-image (source) dependencies pin ^3.0.0 -> 3.6.3
@electric-sql/pglite (source) dependencies pin ^0.2.17 -> 0.2.17
@eslint/js (source) devDependencies pin ^9.17.0 -> 9.17.0
@​injectivelabs/sdk-ts dependencies pin ^1.14.33 -> 1.14.41
@jest/globals (source) devDependencies pin ^29.7.0 -> 29.7.0
@langchain/openai (source) dependencies pin ^0.3.16 -> 0.3.17
@octokit/plugin-paginate-rest@>=1.0.0 <11.4.1 pnpm.overrides pin [>=11.4.1 -> 11.4.3](https://renovatebot.com/diffs/npm/@octokit%2fplugin-paginate-rest@&gt;&#x3D;1.0.0 <11.4.1/11.4.3/11.4.3)
@octokit/request-error@>=1.0.0 <5.1.1 pnpm.overrides pin [>=5.1.1 -> 6.1.7](https://renovatebot.com/diffs/npm/@octokit%2frequest-error@&gt;&#x3D;1.0.0 <5.1.1/6.1.7/6.1.7)
@octokit/request@>=1.0.0 <9.2.1 pnpm.overrides pin [>=9.2.1 -> 9.2.2](https://renovatebot.com/diffs/npm/@octokit%2frequest@&gt;&#x3D;1.0.0 <9.2.1/9.2.2/9.2.2)
@octokit/rest dependencies pin ^21.0.2 -> 21.1.0
@radix-ui/react-avatar (source) dependencies pin ^1.1.2 -> 1.1.2
@radix-ui/react-collapsible (source) dependencies pin ^1.1.2 -> 1.1.2
@radix-ui/react-dialog (source) dependencies pin ^1.1.4 -> 1.1.4
@radix-ui/react-label (source) dependencies pin ^2.1.1 -> 2.1.1
@radix-ui/react-separator (source) dependencies pin ^1.1.1 -> 1.1.1
@radix-ui/react-slot (source) dependencies pin ^1.1.1 -> 1.1.1
@radix-ui/react-tabs (source) dependencies pin ^1.1.2 -> 1.1.2
@radix-ui/react-toast (source) dependencies pin ^1.2.4 -> 1.2.4
@radix-ui/react-tooltip (source) dependencies pin ^1.1.6 -> 1.1.6
@react-spring/web dependencies pin ^9.7.5 -> 9.7.5
@supabase/supabase-js dependencies pin ^2.49.1 -> 2.49.1
@tanstack/react-query (source) dependencies pin ^5.63.0 -> 5.62.16
@types/multer (source) devDependencies pin ^1.4.12 -> 1.4.12
@types/node (source) dependencies pin ^20.11.0 -> 20.17.12
@types/node (source) devDependencies pin ^20.11.5 -> 20.17.24
@types/node (source) devDependencies pin ^22.10.5 -> 22.13.5
@types/node (source) devDependencies pin ^22.10.5 -> 22.13.10
@types/node (source) dependencies pin ^22.13.5 -> 22.13.5
@types/semver (source) devDependencies pin ^7.5.8 -> 7.5.8
@uidotdev/usehooks dependencies pin ^2.4.1 -> 2.4.1
@vitejs/plugin-react-swc devDependencies pin ^3.5.0 -> 3.7.2
@vitest/coverage-v8 (source) devDependencies pin ^3.0.2 -> 3.0.7
aiofiles (changelog) dependencies pin ^23.2.1 -> 23.2.1
anthropic dependencies pin ^0.45.0 -> 0.45.0
asyncio dependencies pin ^3.4.3 -> 3.4.3
autoprefixer devDependencies pin ^10.4.19 -> 10.4.20
axios@>=0.8.1 <0.28.0 (source) pnpm.overrides pin [>=0.28.0 -> 1.8.2](https://renovatebot.com/diffs/npm/axios@&gt;&#x3D;0.8.1 <0.28.0/1.8.2/1.8.2)
class-variance-authority dependencies pin ^0.7.1 -> 0.7.1
clsx dependencies pin ^2.1.1 -> 2.1.1
commander dependencies pin ^13.1.0 -> 13.1.0
dayjs (source) dependencies pin ^1.11.13 -> 1.11.13
deepseek dependencies pin ^1.0.0 -> 1.0.0
dompurify@<3.2.4 pnpm.overrides pin >=3.2.4 -> 3.2.4
dotenv dependencies pin ^16.4.7 -> 16.4.7
esbuild@<=0.24.2 pnpm.overrides pin >=0.25.0 -> 0.25.0
esprima dependencies pin ^4.0.1 -> 4.0.1
globals devDependencies pin ^15.14.0 -> 15.14.0
graphviz (changelog) dependencies pin ^0.20.1 -> 0.20.3
handlebars (source) dependencies pin ^4.7.8 -> 4.7.8
isort (changelog) dev pin ^5.13.2 -> 5.13.2
jschema-to-python dependencies pin ^1.2.3 -> 1.2.3
langchain (source) dependencies pin ^0.3.7 -> 0.3.11
langdetect dependencies pin ^0.2.1 -> 0.2.1
lizard (source) dependencies pin ^1.17.10 -> 1.17.13
lodash (source) dependencies pin ^4.17.21 -> 4.17.21
lucide-react (source) dependencies pin ^0.469.0 -> 0.469.0
markdown (changelog) dependencies pin ^3.7 -> 3.7
markitdown dependencies pin ^0.0.1a3 -> 0.0.1a3
mypy (changelog) dev pin ^1.8.0 -> 1.14.1
node (source) engines pin >=18.0.0 -> 23.9.0
nodeenv dependencies pin ^1.8.0 -> 1.9.1
path-to-regexp dependencies pin ^1.7.0 -> 1.9.0
path-to-regexp@<0.1.12 pnpm.overrides pin >=0.1.12 -> 8.2.0
phidata dependencies pin ^2.7.9 -> 2.7.9
pino (source) dependencies pin ^9.6.0 -> 9.6.0
pino-pretty dependencies pin ^13.0.0 -> 13.0.0
postcss (source) devDependencies pin ^8.4.38 -> 8.4.49
pydantic (changelog) dependencies pin ^2.5.3 -> 2.10.5
pytest (changelog) dev pin ^7.4.4 -> 7.4.4
pytest-asyncio (changelog) dev pin ^0.23.3 -> 0.23.8
python dependencies pin ^3.11 -> 3.13.2
radon (source) dependencies pin ^6.0.1 -> 6.0.1
react (source) dependencies pin ^19.0.0 -> 19.0.0
react-aiwriter dependencies pin ^1.0.0 -> 1.0.0
react-dom (source) dependencies pin ^19.0.0 -> 19.0.0
react-router (source) dependencies pin ^7.1.1 -> 7.3.0
react-router-dom (source) dependencies pin ^7.1.1 -> 7.3.0
rich dependencies pin ^13.7.0 -> 13.9.4
semgrep dependencies pin ^1.65.0 -> 1.85.0
semver dependencies pin ^7.6.3 -> 7.7.1
sql.js dependencies pin ^1.12.0 -> 1.12.0
tailwind-merge dependencies pin ^2.6.0 -> 2.6.0
tailwindcss (source) devDependencies pin ^3.4.4 -> 3.4.17
tailwindcss-animate dependencies pin ^1.0.7 -> 1.0.7
termcolor (changelog) dependencies pin ^2.4.0 -> 2.5.0
textual dependencies pin ^0.47.1 -> 0.47.1
tsup (source) devDependencies pin ^8.3.5 -> 8.3.5
typer (changelog) dependencies pin ^0.9.0 -> 0.9.4
typescript-eslint (source) devDependencies pin ^8.18.2 -> 8.19.1
undici@>=6.0.0 <6.21.1 (source) pnpm.overrides pin [>=6.21.1 -> 7.4.0](https://renovatebot.com/diffs/npm/undici@&gt;&#x3D;6.0.0 <6.21.1/7.4.0/7.4.0)
vite-plugin-compression (source) dependencies pin ^0.5.1 -> 0.5.1
vite-tsconfig-paths devDependencies pin ^5.1.4 -> 5.1.4
vitest (source) dependencies pin ^3.0.5 -> 3.0.5
vitest (source) devDependencies pin ^3.0.2 -> 3.0.5
yaml (source) dependencies pin ^2.3.4 -> 2.7.0
zod (source) dependencies pin ^3.24.2 -> 3.24.2

Add the preset :preserveSemverRanges to your config if you don't want to pin your dependencies.


Release Notes

facebook/react (react)

v19.0.0

Compare Source

Below is a list of all new features, APIs, deprecations, and breaking changes. Read React 19 release post and React 19 upgrade guide for more information.

Note: To help make the upgrade to React 19 easier, we’ve published a react@18.3 release that is identical to 18.2 but adds warnings for deprecated APIs and other changes that are needed for React 19. We recommend upgrading to React 18.3.1 first to help identify any issues before upgrading to React 19.

New Features
React
  • Actions: startTransition can now accept async functions. Functions passed to startTransition are called “Actions”. A given Transition can include one or more Actions which update state in the background and update the UI with one commit. In addition to updating state, Actions can now perform side effects including async requests, and the Action will wait for the work to finish before finishing the Transition. This feature allows Transitions to include side effects like fetch() in the pending state, and provides support for error handling, and optimistic updates.
  • useActionState: is a new hook to order Actions inside of a Transition with access to the state of the action, and the pending state. It accepts a reducer that can call Actions, and the initial state used for first render. It also accepts an optional string that is used if the action is passed to a form action prop to support progressive enhancement in forms.
  • useOptimistic: is a new hook to update state while a Transition is in progress. It returns the state, and a set function that can be called inside a transition to “optimistically” update the state to expected final value immediately while the Transition completes in the background. When the transition finishes, the state is updated to the new value.
  • use: is a new API that allows reading resources in render. In React 19, use accepts a promise or Context. If provided a promise, use will suspend until a value is resolved. use can only be used in render but can be called conditionally.
  • ref as a prop: Refs can now be used as props, removing the need for forwardRef.
  • Suspense sibling pre-warming: When a component suspends, React will immediately commit the fallback of the nearest Suspense boundary, without waiting for the entire sibling tree to render. After the fallback commits, React will schedule another render for the suspended siblings to “pre-warm” lazy requests.
React DOM Client
  • <form> action prop: Form Actions allow you to manage forms automatically and integrate with useFormStatus. When a <form> action succeeds, React will automatically reset the form for uncontrolled components. The form can be reset manually with the new requestFormReset API.
  • <button> and <input> formAction prop: Actions can be passed to the formAction prop to configure form submission behavior. This allows using different Actions depending on the input.
  • useFormStatus: is a new hook that provides the status of the parent <form> action, as if the form was a Context provider. The hook returns the values: pending, data, method, and action.
  • Support for Document Metadata: We’ve added support for rendering document metadata tags in components natively. React will automatically hoist them into the <head> section of the document.
  • Support for Stylesheets: React 19 will ensure stylesheets are inserted into the <head> on the client before revealing the content of a Suspense boundary that depends on that stylesheet.
  • Support for async scripts: Async scripts can be rendered anywhere in the component tree and React will handle ordering and deduplication.
  • Support for preloading resources: React 19 ships with preinit, preload, prefetchDNS, and preconnect APIs to optimize initial page loads by moving discovery of additional resources like fonts out of stylesheet loading. They can also be used to prefetch resources used by an anticipated navigation.
React DOM Server
  • Added prerender and prerenderToNodeStream APIs for static site generation. They are designed to work with streaming environments like Node.js Streams and Web Streams. Unlike renderToString, they wait for data to load for HTML generation.
React Server Components
  • RSC features such as directives, server components, and server functions are now stable. This means libraries that ship with Server Components can now target React 19 as a peer dependency with a react-server export condition for use in frameworks that support the Full-stack React Architecture. The underlying APIs used to implement a React Server Components bundler or framework do not follow semver and may break between minors in React 19.x. See docs for how to support React Server Components.
Deprecations
  • Deprecated: element.ref access: React 19 supports ref as a prop, so we’re deprecating element.ref in favor of element.props.ref. Accessing will result in a warning.
  • react-test-renderer: In React 19, react-test-renderer logs a deprecation warning and has switched to concurrent rendering for web usage. We recommend migrating your tests to @​testing-library/react or @​testing-library/react-native
Breaking Changes

React 19 brings in a number of breaking changes, including the removals of long-deprecated APIs. We recommend first upgrading to 18.3.1, where we've added additional deprecation warnings. Check out the upgrade guide for more details and guidance on codemodding.

React
  • New JSX Transform is now required: We introduced a new JSX transform in 2020 to improve bundle size and use JSX without importing React. In React 19, we’re adding additional improvements like using ref as a prop and JSX speed improvements that require the new transform.
  • Errors in render are not re-thrown: Errors that are not caught by an Error Boundary are now reported to window.reportError. Errors that are caught by an Error Boundary are reported to console.error. We’ve introduced onUncaughtError and onCaughtError methods to createRoot and hydrateRoot to customize this error handling.
  • Removed: propTypes: Using propTypes will now be silently ignored. If required, we recommend migrating to TypeScript or another type-checking solution.
  • Removed: defaultProps for functions: ES6 default parameters can be used in place. Class components continue to support defaultProps since there is no ES6 alternative.
  • Removed: contextTypes and getChildContext: Legacy Context for class components has been removed in favor of the contextType API.
  • Removed: string refs: Any usage of string refs need to be migrated to ref callbacks.
  • Removed: Module pattern factories: A rarely used pattern that can be migrated to regular functions.
  • Removed: React.createFactory: Now that JSX is broadly supported, all createFactory usage can be migrated to JSX components.
  • Removed: react-test-renderer/shallow: This has been a re-export of react-shallow-renderer since React 18. If needed, you can continue to use the third-party package directly. We recommend using @​testing-library/react or @​testing-library/react-native instead.
React DOM
  • Removed: react-dom/test-utils: We’ve moved act from react-dom/test-utils to react. All other utilities have been removed.
  • Removed: ReactDOM.render, ReactDOM.hydrate: These have been removed in favor of the concurrent equivalents: ReactDOM.createRoot and ReactDOM.hydrateRoot.
  • Removed: unmountComponentAtNode: Removed in favor of root.unmount().
  • Removed: ReactDOM.findDOMNode: You can replace ReactDOM.findDOMNode with DOM Refs.
Notable Changes
React
  • <Context> as a provider: You can now render <Context> as a provider instead of <Context.Provider>.
  • Cleanup functions for refs: When the component unmounts, React will call the cleanup function returned from the ref callback.
  • useDeferredValue initial value argument: When provided, useDeferredValue will return the initial value for the initial render of a component, then schedule a re-render in the background with the deferredValue returned.
  • Support for Custom Elements: React 19 now passes all tests on Custom Elements Everywhere.
  • StrictMode changes: useMemo and useCallback will now reuse the memoized results from the first render, during the second render. Additionally, StrictMode will now double-invoke ref callback functions on initial mount.
  • UMD builds removed: To load React 19 with a script tag, we recommend using an ESM-based CDN such as esm.sh.
React DOM
  • Diffs for hydration errors: In the case of a mismatch, React 19 logs a single error with a diff of the mismatched content.
  • Compatibility with third-party scripts and extensions: React will now force a client re-render to fix up any mismatched content caused by elements inserted by third-party JS.
TypeScript Changes

The most common changes can be codemodded with npx types-react-codemod@latest preset-19 ./path-to-your-react-ts-files.

  • Removed deprecated TypeScript types:
    • ReactChild (replacement: React.ReactElement | number | string)
    • ReactFragment (replacement: Iterable<React.ReactNode>)
    • ReactNodeArray (replacement: ReadonlyArray<React.ReactNode>)
    • ReactText (replacement: number | string)
    • VoidFunctionComponent (replacement: FunctionComponent)
    • VFC (replacement: FC)
    • Moved to prop-types: Requireable, ValidationMap, Validator, WeakValidationMap
    • Moved to create-react-class: ClassicComponentClass, ClassicComponent, ClassicElement, ComponentSpec, Mixin, ReactChildren, ReactHTML, ReactSVG, SFCFactory
  • Disallow implicit return in refs: refs can now accept cleanup functions. When you return something else, we can’t tell if you intentionally returned something not meant to clean up or returned the wrong value. Implicit returns of anything but functions will now error.
  • Require initial argument to useRef: The initial argument is now required to match useState, createContext etc
  • Refs are mutable by default: Ref objects returned from useRef() are now always mutable instead of sometimes being immutable. This feature was too confusing for users and conflicted with legit cases where refs were managed by React and manually written to.
  • Strict ReactElement typing: The props of React elements now default to unknown instead of any if the element is typed as ReactElement
  • JSX namespace in TypeScript: The global JSX namespace is removed to improve interoperability with other libraries using JSX. Instead, the JSX namespace is available from the React package: import { JSX } from 'react'
  • Better useReducer typings: Most useReducer usage should not require explicit type arguments.
    For example,
    -useReducer<React.Reducer<State, Action>>(reducer)
    +useReducer(reducer)
    or
    -useReducer<React.Reducer<State, Action>>(reducer)
    +useReducer<State, Action>(reducer)
All Changes
React
React DOM

Configuration

📅 Schedule: Branch creation - "every weekend" in timezone UTC, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copy link
Contributor Author

renovate bot commented Mar 8, 2025

⚠️ Artifact update problem

Renovate failed to update artifacts related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml
Scope: all 10 workspace projects
 ERR_PNPM_LOCKFILE_CONFIG_MISMATCH  Cannot proceed with the frozen installation. The current "overrides" configuration doesn't match the value found in the lockfile

Update your lockfile using "pnpm install --no-frozen-lockfile"

File name: client/pnpm-lock.yaml
 ERROR  Failed to switch pnpm to v9.15.0. Looks like pnpm CLI is missing at "/home/ubuntu/.local/share/pnpm/.tools/pnpm/9.15.0/bin" or is incorrect
spawnSync /home/ubuntu/.local/share/pnpm/.tools/pnpm/9.15.0/bin/pnpm ENOENT

Copy link

graphite-app bot commented Mar 8, 2025

How to use the Graphite Merge Queue

Add either label to this PR to merge it via the merge queue:

  • merge-queue - adds this PR to the back of the merge queue
  • merge-queue-hotfix - for urgent hot fixes, skip the queue and merge this PR next

You must have a Graphite account in order to use the merge queue. Sign up using this link.

An organization admin has enabled the Graphite Merge Queue in this repository.

Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue.

Copy link
Contributor

coderabbitai bot commented Mar 8, 2025

Important

Review skipped

Auto reviews are disabled on this repository.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Generate unit testing code for this file.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai generate unit testing code for this file.
    • @coderabbitai modularize this function.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read src/utils.ts and generate unit testing code.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.
    • @coderabbitai help me debug CodeRabbit configuration file.

Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai generate docstrings to generate docstrings for this PR.
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

@lalalune lalalune closed this Mar 8, 2025
@lalalune lalalune deleted the renovate/pin-dependencies branch March 9, 2025 03:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant