Skip to content

chore(deps): bump six npm packages in one branch - #69

Merged
htcom-code merged 1 commit into
mainfrom
chore/deps-bump-67-68
Oct 6, 2026
Merged

htcom-code merged 1 commit into
mainfrom
chore/deps-bump-67-68

Conversation

@htcom-code

Copy link
Copy Markdown
Owner

Why

Dependabot opened #67 (production, 1 update) and #68 (development, 5 updates) against the same base. Both touch package.json and package-lock.json, so merging one would force a rebase and a second CI round on the other. This consolidates both into a single green tree.

What

Package From To Group
lucide-react 1.47.0 1.49.0 production
@types/node 26.6.2 26.6.3 development
vite 8.3.0 8.3.1 development
vitest 5.0.1 5.0.3 development
@vitest/coverage-v8 5.0.1 5.0.3 development
oxlint 1.85.0 1.86.0 development
  • All minor or patch, no breaking changes in the release notes. lucide-react only adds icons and marks @types/react as an optional peer.
  • vitest and @vitest/coverage-v8 move together, so the exact peer pin resolves.
  • The rest of the lock diff is the oxlint platform bindings, @oxc-project/types and the vite/vitest transitive tree.

Lock integrity

The two Dependabot branches merged with no conflicts, so the lock is the exact union of the #67 and #68 locks. It was not regenerated, so nothing drifted past what Dependabot pinned (lucide-react stays at 1.49.0).

Verification (merged tree)

  • npm ci: OK
  • npm run lint: exit 0, 7 warnings, the same only-export-components set as main
  • npm run build: passes. Main JS 520.11 -> 520.06 kB (gzip 164.32 -> 164.28)
  • npm test: 17 files, 199 tests pass
  • npx vitest run --coverage: 199 tests pass. CI never runs coverage, so this is the only check on the @vitest/coverage-v8 bump

Not introduced by this PR

npm audit reports the same 16 findings on this branch as on main. Most come through shadcn and are dev-only. With --omit=dev, one high remains (source-map-js, GHSA-68fv-2mgg-jv7q). It comes in through @tailwindcss/vite / vite / postcss and runs only at build time, so it does not ship in the browser bundle. It will be handled separately.

Closes #67
Closes #68

Dependabot opened #67 (production, 1) and #68 (development, 5) against
the same base. Merging them one at a time would make the other wait for
a rebase and burn a second CI round, so consolidate both into a single
green tree.

- Production: lucide-react 1.47.0 -> 1.49.0
- Development: @types/node 26.6.2 -> 26.6.3, vite 8.3.0 -> 8.3.1,
  vitest and @vitest/coverage-v8 5.0.1 -> 5.0.3, oxlint 1.85.0 -> 1.86.0
- All minor or patch; the rest of the lock diff is the oxlint platform
  bindings, @oxc-project/types and the vite/vitest transitive tree
- The branches merged without conflict, so the lock is the exact union
  of the #67 and #68 locks with no regeneration and no drift
- Gates on the merged tree: lint clean (same 7 warnings as main), build
  passes (main JS 520.11 -> 520.06 kB), 199 tests pass, and
  vitest run --coverage passes since CI never exercises coverage-v8

Closes #67
Closes #68

Tags: #deps #dependabot

Co-Authored-By: htjulia <htjulia1@gmail.com>
@htcom-code
htcom-code merged commit 24cdc3c into main Oct 6, 2026
4 checks passed
@htcom-code
htcom-code deleted the chore/deps-bump-67-68 branch October 6, 2026 02:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant