chore(deps): refresh lockfiles for braces, picomatch, postcss-selector-parser - #169
Open
devtools-agent[bot] wants to merge 1 commit into
Open
devtools-agent[bot] wants to merge 1 commit into
devtools-agent[bot] wants to merge 1 commit into
Conversation
…r-parser Lockfile-only bumps within existing semver ranges; no package.json changes. - package-lock.json: braces 3.0.2 -> 3.0.3 (fill-range 7.0.1 -> 7.1.1) - examples/nextjs, examples/nextjs-approuter: picomatch 2.3.1 -> 2.3.2, postcss-selector-parser 6.1.2 -> 6.1.4 Resolves Dependabot alerts #124, #433, #434, #690, #691. Supersedes #168. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
AI Agent Review LGTM (openai, openai-astra)LGTM. No blocking findings were found. LGTM: lockfile-only refresh, nothing to flagWhat changed
Checks
What I could not check
Outside the changed lines (for information, not a finding)
I did not run any tests, and the diff does not show CI results. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
These are lockfile-only bumps that stay inside the existing semver ranges. No
package.jsonchanges.package-lock.jsonbraces(+fill-range7.0.1 → 7.1.1, required by braces)examples/nextjs/package-lock.jsonpicomatchexamples/nextjs/package-lock.jsonpostcss-selector-parserexamples/nextjs-approuter/package-lock.jsonpicomatchexamples/nextjs-approuter/package-lock.jsonpostcss-selector-parserWhy
This clears 5 of the 9 open Dependabot alerts in one PR. Each package is already allowed by its parent's version range:
bracesviamicromatch/chokidar,picomatchviamicromatch/anymatch/readdirp/jest-util, andpostcss-selector-parserviatailwindcss@3.4^6.0.11. A plainnpm update <pkg>resolves them.The Next example lockfiles were missed when #164 bumped picomatch in the root lockfile only.
Supersedes #168. The root
package-lock.jsondiff here matches Dependabot's braces PR line for line (+11/−7). Close #168 once this merges.The other 4 alerts (react-router in
examples/react-17andexamples/typescript, #626/#627/#633/#719) are not addressed here. They're only fixed in react-router 7.18+, which requires React ≥18, so they're being handled separately.How I validated
I used npm 10.9 on Node 20.19, matching CI's
node: 20 / npm: 10job. I generated the lockfiles withnpm run install:all -- cifollowed by targetednpm update. I then deleted everynode_modulesand ran the CI steps from scratch:npm run install:all -- ci✅ (npm ciaccepts all updated lockfiles)npm run lint:examples✅,eslint --max-warnings 0✅npm run typecheck✅npm run build:all✅ (includesnext buildfor both Next examples)npm run test✅ (13 tests),npm run test:examples✅npm auditno longer reportsbraces,picomatchorpostcss-selector-parserin any of the three projectsI reverted the
.yalc/@rollbar/reactbuild-signature hash that the local build rewrote, so the diff contains only the dependency bumps.🤖 Generated with Claude Code