chore(deps): bump the npm-all group across 1 directory with 12 updates - #57
chore(deps): bump the npm-all group across 1 directory with 12 updates#57dependabot[bot] wants to merge 1 commit into
Conversation
120486d to
7bc5168
Compare
Bumps the npm-all group with 11 updates in the /evalboard directory: | Package | From | To | | --- | --- | --- | | [next](https://github.com/vercel/next.js) | `15.5.22` | `16.2.12` | | [recharts](https://github.com/recharts/recharts) | `2.15.4` | `3.10.1` | | [@testing-library/jest-dom](https://github.com/testing-library/jest-dom) | `6.9.1` | `7.0.0` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `22.20.1` | `26.1.2` | | [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `4.7.0` | `6.0.4` | | [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `3.2.7` | `4.1.10` | | [jsdom](https://github.com/jsdom/jsdom) | `25.0.1` | `30.0.0` | | [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) | `3.4.19` | `4.3.3` | | [typescript](https://github.com/microsoft/TypeScript) | `5.9.3` | `7.0.2` | | [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `3.2.7` | `4.1.10` | | [@azure/storage-blob](https://github.com/Azure/azure-sdk-for-js/tree/HEAD/sdk/storage/storage-blob) | `12.32.0` | `12.33.0` | Updates `next` from 15.5.22 to 16.2.12 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v15.5.22...v16.2.12) Updates `recharts` from 2.15.4 to 3.10.1 - [Release notes](https://github.com/recharts/recharts/releases) - [Changelog](https://github.com/recharts/recharts/blob/main/CHANGELOG.md) - [Commits](recharts/recharts@v2.15.4...v3.10.1) Updates `@testing-library/jest-dom` from 6.9.1 to 7.0.0 - [Release notes](https://github.com/testing-library/jest-dom/releases) - [Changelog](https://github.com/testing-library/jest-dom/blob/main/CHANGELOG.md) - [Commits](testing-library/jest-dom@v6.9.1...v7.0.0) Updates `@types/node` from 22.20.1 to 26.1.2 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `@vitejs/plugin-react` from 4.7.0 to 6.0.4 - [Release notes](https://github.com/vitejs/vite-plugin-react/releases) - [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.0.4/packages/plugin-react) Updates `@vitest/coverage-v8` from 3.2.7 to 4.1.10 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/coverage-v8) Updates `jsdom` from 25.0.1 to 30.0.0 - [Release notes](https://github.com/jsdom/jsdom/releases) - [Commits](jsdom/jsdom@v25.0.1...v30.0.0) Updates `postcss` from 8.5.18 to 8.5.23 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.18...8.5.23) Updates `tailwindcss` from 3.4.19 to 4.3.3 - [Release notes](https://github.com/tailwindlabs/tailwindcss/releases) - [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.3.3/packages/tailwindcss) Updates `typescript` from 5.9.3 to 7.0.2 - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) Updates `vitest` from 3.2.7 to 4.1.10 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/vitest) Updates `@azure/storage-blob` from 12.32.0 to 12.33.0 - [Release notes](https://github.com/Azure/azure-sdk-for-js/releases) - [Changelog](https://github.com/Azure/azure-sdk-for-js/blob/main/sdk/storage/storage-blob/CHANGELOG.md) - [Commits](https://github.com/Azure/azure-sdk-for-js/commits/@azure/storage-blob_12.33.0/sdk/storage/storage-blob) --- updated-dependencies: - dependency-name: "@azure/storage-blob" dependency-version: 12.33.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-all - dependency-name: "@testing-library/jest-dom" dependency-version: 7.0.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-all - dependency-name: "@types/node" dependency-version: 26.1.2 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-all - dependency-name: "@vitejs/plugin-react" dependency-version: 6.0.4 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-all - dependency-name: "@vitest/coverage-v8" dependency-version: 4.1.10 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-all - dependency-name: jsdom dependency-version: 30.0.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-all - dependency-name: next dependency-version: 16.2.12 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-all - dependency-name: postcss dependency-version: 8.5.23 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-all - dependency-name: recharts dependency-version: 3.10.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-all - dependency-name: tailwindcss dependency-version: 4.3.3 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-all - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-all - dependency-name: vitest dependency-version: 4.1.10 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-all ... Signed-off-by: dependabot[bot] <support@github.com>
7bc5168 to
e428115
Compare
Code review: 🚫 Do not merge — this PR breaks the build, the test suite, and the stylingReviewed with three models (Claude Opus, Gemini 3 Pro, GPT-5.3-Codex) plus local reproduction against this exact lockfile ( This is a grouped Dependabot bump crossing eight major versions at once (next 15→16, recharts 2→3, tailwindcss 3→4, typescript 5→7, vitest 3→4, jsdom 25→30, jest-dom 6→7, plugin-react 4→6) with zero accompanying migration. 🔴 Critical 1 —
|
| Package | Declared vite range |
Lockfile resolves |
|---|---|---|
vitest@4.1.10 |
^6.0.0 || ^7.0.0 || ^8.0.0 (both dependencies and peerDependencies) |
5.4.21 ❌ |
@vitejs/plugin-react@6.0.4 |
^8.0.0 (peer) |
5.4.21 ❌ |
Dependabot bumped the direct devDeps but never upgraded the transitive vite, committing a lockfile that violates two declared ranges. The entire test suite is dead — this isn't "some tests fail", nothing runs at all.
🔴 Critical 3 — TypeScript 7 is incompatible with next build ✅ verified
Found only after locally patching Critical 1 — it's masked behind the CSS error:
✓ Compiled successfully in 3.1s
Running TypeScript ...
TypeScript 7.0.2 does not provide the compiler API required by Next.js.
Enable experimental.useTypeScriptCli in your Next.js config, or install TypeScript 6 instead.
Next.js build worker exited with code: 1
Note the trap: tsc --noEmit passes cleanly under TS 7.0.2 ✅. So the typecheck script is green while build is red. Next 16.2.12 requires either experimental.useTypeScriptCli in next.config.mjs or TypeScript ≤ 6 — neither is in this PR.
🟠 High 4 — Silent styling regression: the dashboard ships essentially unstyled ✅ verified
This is the one I'd most want caught, because it does not fail the build. With Critical 1 patched locally, CSS "compiles successfully" — but Tailwind v4 does not auto-load a v3 tailwind.config.ts (it needs an explicit @config, or the theme migrated to CSS @theme), and app/globals.css:1-3 still uses the removed v3 @tailwind base/components/utilities directives. Inspecting the emitted stylesheet:
| Class (used in source) | Occurrences in emitted CSS |
|---|---|
text-gray-900 |
0 |
studio-blue (custom theme colour) |
0 |
uipath-orange (custom theme colour) |
0 |
Total emitted CSS: 12.7 KB, and the only prose hits are the hand-written .analysis-prose rules from globals.css — the @tailwindcss/typography plugin never loads. The utility layer is simply not generated. A green build would ship a visually broken dashboard.
This is where I'd push back on the "minimal fix = just swap the PostCSS plugin" reading: that makes the build exit 0 while leaving the app unstyled. The Tailwind v4 migration (
@import "tailwindcss", theme moved to@theme,@pluginfor typography) is required, not optional.
🟠 High 5 — No CI job covers evalboard/ at all
Every job in .github/workflows/pr-checks.yml is Python (quality-gate, no-uipath-extra, windows-smoke, live-tests, codex-live-tests, byoa-live-tests, action-dogfood). Nothing runs pnpm install/typecheck/test/build for the dashboard. That's precisely why three build-breaking regressions can sit in a green PR. The comment at pr-checks.yml:~102 also excludes evalboard/pnpm-lock.yaml from the OSV scan, so the npm tree gets no vulnerability scanning either.
A minimal job would have caught all of this:
evalboard-checks:
name: Evalboard checks
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@... # SHA-pin to match this file's convention
- uses: actions/setup-node@... # node 20
- run: corepack enable
- working-directory: evalboard
run: pnpm install --frozen-lockfile && pnpm verify(pnpm verify already exists in package.json and chains tsc --noEmit && vitest run && next build.)
🟠 High 6 — Root cause: Dependabot groups majors into one unbisectable PR
.github/dependabot.yml — the npm block groups patterns: ["*"] with no update-types filter, unlike the pip block right above it which deliberately ignores minor+patch. So eight majors land together and a bisect can't attribute anything. Suggested fix, mirroring the existing style:
groups:
npm-all:
patterns: ["*"]
update-types: ["minor", "patch"]Majors then arrive as individual PRs, which is what a tailwind-3→4 or typescript-5→7 migration actually needs.
🟡 Medium / 🟢 Low (informational)
- recharts 2→3 — usage is narrow and low-risk: only
app/_overview/daily-chart.tsxandturn-budget-chart.tsx, usingLineChart/Line/XAxis/YAxis/CartesianGrid/Tooltip/ResponsiveContainer. NoLegend(so the v3align/verticalAlign→position/offsetchange doesn't bite), no removed-defaultPropsreliance, and the custom tooltip's prop types are hand-written so v3 typing changes don't surface. Typecheck passes. But runtime render behaviour is unverified because the test suite can't start. - next 15→16 async params — ✅ not an issue.
app/page.tsx:109,app/path-to-ga/page.tsx:38,app/trends/page.tsx:41alreadyawait searchParams. - jest-dom 6→7 — ✅ low risk. Only core matchers are used across the 28 test files (
toBeInTheDocument×61,toHaveAttribute×12,toHaveTextContent×11,toHaveValue×9), all retained in v7. autoprefixer— redundant under Tailwind v4 (Lightning CSS handles prefixing). Dead weight once migrated.@types/node26 — the repo has no.nvmrc, noenginesfield, and no node pin for evalboard;docker/Dockerfileinstalls node 22 and CI pins node 20. Typing against Node 26 APIs the runtime may not have is a latent trap worth pinning down.@azure/storage-blob— ceiling widened<12.33.0→<12.34.0. The bounded range has no comment explaining why it's bounded, so a reviewer can't tell whether widening re-admits whatever it was guarding against. Worth a one-line comment.
Recommendation
Close this PR and let Dependabot regenerate split PRs, after applying the update-types filter above. Fixing in place means doing a Tailwind v4 migration, a TypeScript 7/Next compatibility decision, and a vite realignment inside a commit labelled chore(deps) — and with no CI covering evalboard, none of it would be verified.
Suggested sequencing:
- First, land the
evalboard-checksCI job and thedependabot.ymlupdate-typesfilter (small, independently valuable, and makes everything after it verifiable). - Then the safe minor/patch group (
@azure/storage-blob, and anything else non-major). - Then one PR per risky major, each with its migration: tailwind 3→4 (postcss plugin +
@import "tailwindcss"+@theme+@plugintypography + drop autoprefixer); vitest 3→4 + plugin-react 4→6 (add explicitvitedevDep so the peer range is satisfiable — plugin-react 6 wants^8); typescript 5→7 (hold until Next's TS7 support is non-experimental, or opt intoexperimental.useTypeScriptCli); next 15→16; recharts 2→3 (land after tests run again, so the chart render tests actually gate it).
Reproduction (node v26.0.0, pnpm 10.9.0):
cd evalboard && pnpm install --frozen-lockfile
pnpm exec tsc --noEmit # exit 0 ← green, and misleading
pnpm test # exit 1 ← ERR_PACKAGE_PATH_NOT_EXPORTED, 0/28 files run
pnpm build # exit 1 ← tailwindcss PostCSS plugin moved🤖 Generated with Claude Code
Bumps the npm-all group with 11 updates in the /evalboard directory:
15.5.2216.2.122.15.43.10.16.9.17.0.022.20.126.1.24.7.06.0.43.2.74.1.1025.0.130.0.03.4.194.3.35.9.37.0.23.2.74.1.1012.32.012.33.0Updates
nextfrom 15.5.22 to 16.2.12Release notes
Sourced from next's releases.
... (truncated)
Commits
2234717v16.2.12957f5ed[Backport] Fixes to support TypeScript 7 (#95831)b56eb16Backport/docs fixes 16.2 - July round (#96031)9beca08v16.2.113c48c7a[16.x] Fix Turbopack middleware matcher with i18n single localeac1eff3[16.x] Improve performance of checking valid MPA form submissions9a4651e[16.x] EnforceserverActions.bodySizeLimitfor Server Actions in Edge runtimeb512063[16.x] Set correct origin for internal redirects in custom serverd303326[16.x] Ensure exotic rewrite param values are properly encoded73b9487[16.x] fix(fetch-cache): key fetch(Request, init) by the effective requestUpdates
rechartsfrom 2.15.4 to 3.10.1Release notes
Sourced from recharts's releases.
... (truncated)
Commits
ffb91873.10.1411b6f2fix(bar): keep barGap correct when maxBarSize clamps the bar width (#2774) (#...58c321bchore(deps-dev): bump postcss from 8.5.10 to 8.5.22 (#7581)f08972bchore(deps-dev): bump the storybook group with 8 updates (#7578)89599d0chore(deps-dev): bump chromatic from 11.29.0 to 18.1.0 (#7579)3da7d87chore(deps-dev): bump typescript-eslint from 8.64.0 to 8.65.0 in the typescri...9764273chore(deps-dev): bump marked from 18.0.5 to 18.0.7 (#7577)a5d7737fix(tooltip): fall back to index-based search when label-based search returns...497e8dfchore(deps-dev): bump fast-uri from 3.1.2 to 3.1.4 (#7576)0776eb0chore(deps): bump immer from 11.1.9 to 11.1.15 (#7575)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for recharts since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
@testing-library/jest-domfrom 6.9.1 to 7.0.0Release notes
Sourced from @testing-library/jest-dom's releases.
Commits
1e39089feat: add toContainAnyBy* and toContainOneBy* query matcherscae44dffeat: add toContainAnyBy* and toContainOneBy* query matchers (#731)55c07ceci: switch release to npm trusted publishing (#726)213256fdocs: move toHaveSelection from the deprecated section (#717)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@testing-library/jest-domsince your current version.Updates
@types/nodefrom 22.20.1 to 26.1.2Commits
Updates
@vitejs/plugin-reactfrom 4.7.0 to 6.0.4Release notes
Sourced from @vitejs/plugin-react's releases.
... (truncated)
Changelog
Sourced from @vitejs/plugin-react's changelog.
... (truncated)
Commits
f4b5498release: plugin-react@6.0.47a40659fix(react):$RefreshSig$ is not definedwith NODE_ENV=production vite dev ...98b32d4fix(deps): update react 19.2.8 (#1298)8ae5449fix: babel-plugin-react-compiler cannot be imported when used in a framework ...f09ea01fix(deps): update all non-major dependencies (#1282)640fd35release: plugin-react@6.0.3889efb0fix(deps): update all non-major dependencies (#1249)6c57dd4fix(plugin-react): use '/' base in bundledDev preamble to fix non-root base p...3cc33a7fix(deps): update react-related dependencies (#1245)c0f7c7fdocs: mention the Biome rule in the "Consistent components exports" section (...Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@vitejs/plugin-reactsince your current version.Updates
@vitest/coverage-v8from 3.2.7 to 4.1.10Release notes
Sourced from @vitest/coverage-v8's releases.
... (truncated)
Commits
db616d2chore: release v4.1.10 (#10718)a7a61e7chore: release v4.1.9 (#10598)e61f2ddchore: release v4.1.8e4067b3fix(browser): disable clientcdpAPI whenallowWrite/allowExec: false[ba...a09d472chore: release v4.1.7a8fd24cchore: release v4.1.6e399846chore: release v4.1.5ac04bacchore: release v4.1.42dc0d62chore: release v4.1.3fc6f482chore: release v4.1.2Updates
jsdomfrom 25.0.1 to 30.0.0Release notes
Sourced from jsdom's releases.
... (truncated)
Commits
20a01fc30.0.08c8e583Precompute WPT expectation matchesf32245cBump Node.js floor and dependencies03ef23bAdd background-position longhandsded056fTest CSS.escape() with numeric IDsd312832Convert CSS values to pixels for computed styles4e0ee41Implement CSS.escape() and CSS.supports()05eb709Fix benchmark:compare script on Windows97c1b90Fix CSS function value serialization15642baAdd benchmark comparison scriptMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for jsdom since your current version.
Install script changes
This version modifies
preparescript that runs during installation. Review the package contents before updating.Updates
postcssfrom 8.5.18 to 8.5.23Release notes
Sourced from postcss's releases.
Changelog
Sourced from postcss's changelog.
Commits
eb9e1feRelease 8.5.23 version9d19c78Update dependencies7beca13Does no load source map file without opts.fromdecea51Typoc18e30dUpdate EM banner98a39adUpdate EM bannera3e48c4Release 8.5.22 versionf49d691Fix custom property losing its semicolon before a comment (#2117)28e0dafRelease 8.5.21 version3d2b4e4Update dependenciesUpdates
tailwindcssfrom 3.4.19 to 4.3.3Release notes
Sourced from tailwindcss's releases.
... (truncated)
Changelog
Sourced from tailwindcss's changelog.