chore: bump the all group in /web with 10 updates#990
Closed
dependabot[bot] wants to merge 1 commit intomainfrom
Closed
chore: bump the all group in /web with 10 updates#990dependabot[bot] wants to merge 1 commit intomainfrom
dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the all group in /web with 10 updates: | Package | From | To | | --- | --- | --- | | [@codemirror/view](https://github.com/codemirror/view) | `6.40.0` | `6.41.0` | | [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.96.0` | `5.96.1` | | [@eslint-react/eslint-plugin](https://github.com/Rel1cx/eslint-react/tree/HEAD/packages/plugins/eslint-plugin) | `3.0.0` | `4.2.1` | | [@playwright/test](https://github.com/microsoft/playwright) | `1.59.0` | `1.59.1` | | [@storybook/addon-a11y](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/a11y) | `10.3.3` | `10.3.4` | | [@storybook/addon-docs](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs) | `10.3.3` | `10.3.4` | | [@storybook/react](https://github.com/storybookjs/storybook/tree/HEAD/code/renderers/react) | `10.3.3` | `10.3.4` | | [@storybook/react-vite](https://github.com/storybookjs/storybook/tree/HEAD/code/frameworks/react-vite) | `10.3.3` | `10.3.4` | | [esbuild](https://github.com/evanw/esbuild) | `0.27.4` | `0.27.5` | | [storybook](https://github.com/storybookjs/storybook/tree/HEAD/code/core) | `10.3.3` | `10.3.4` | Updates `@codemirror/view` from 6.40.0 to 6.41.0 - [Changelog](https://github.com/codemirror/view/blob/main/CHANGELOG.md) - [Commits](codemirror/view@6.40.0...6.41.0) Updates `@tanstack/react-query` from 5.96.0 to 5.96.1 - [Release notes](https://github.com/TanStack/query/releases) - [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md) - [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.96.1/packages/react-query) Updates `@eslint-react/eslint-plugin` from 3.0.0 to 4.2.1 - [Release notes](https://github.com/Rel1cx/eslint-react/releases) - [Changelog](https://github.com/Rel1cx/eslint-react/blob/main/CHANGELOG.md) - [Commits](https://github.com/Rel1cx/eslint-react/commits/v4.2.1/packages/plugins/eslint-plugin) Updates `@playwright/test` from 1.59.0 to 1.59.1 - [Release notes](https://github.com/microsoft/playwright/releases) - [Commits](microsoft/playwright@v1.59.0...v1.59.1) Updates `@storybook/addon-a11y` from 10.3.3 to 10.3.4 - [Release notes](https://github.com/storybookjs/storybook/releases) - [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md) - [Commits](https://github.com/storybookjs/storybook/commits/v10.3.4/code/addons/a11y) Updates `@storybook/addon-docs` from 10.3.3 to 10.3.4 - [Release notes](https://github.com/storybookjs/storybook/releases) - [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md) - [Commits](https://github.com/storybookjs/storybook/commits/v10.3.4/code/addons/docs) Updates `@storybook/react` from 10.3.3 to 10.3.4 - [Release notes](https://github.com/storybookjs/storybook/releases) - [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md) - [Commits](https://github.com/storybookjs/storybook/commits/v10.3.4/code/renderers/react) Updates `@storybook/react-vite` from 10.3.3 to 10.3.4 - [Release notes](https://github.com/storybookjs/storybook/releases) - [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md) - [Commits](https://github.com/storybookjs/storybook/commits/v10.3.4/code/frameworks/react-vite) Updates `esbuild` from 0.27.4 to 0.27.5 - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md) - [Commits](evanw/esbuild@v0.27.4...v0.27.5) Updates `storybook` from 10.3.3 to 10.3.4 - [Release notes](https://github.com/storybookjs/storybook/releases) - [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md) - [Commits](https://github.com/storybookjs/storybook/commits/v10.3.4/code/core) --- updated-dependencies: - dependency-name: "@codemirror/view" dependency-version: 6.41.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all - dependency-name: "@tanstack/react-query" dependency-version: 5.96.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all - dependency-name: "@eslint-react/eslint-plugin" dependency-version: 4.2.1 dependency-type: direct:development update-type: version-update:semver-major dependency-group: all - dependency-name: "@playwright/test" dependency-version: 1.59.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: all - dependency-name: "@storybook/addon-a11y" dependency-version: 10.3.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: all - dependency-name: "@storybook/addon-docs" dependency-version: 10.3.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: all - dependency-name: "@storybook/react" dependency-version: 10.3.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: all - dependency-name: "@storybook/react-vite" dependency-version: 10.3.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: all - dependency-name: esbuild dependency-version: 0.27.5 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: all - dependency-name: storybook dependency-version: 10.3.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: all ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
Contributor
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found. |
Aureliolo
added a commit
that referenced
this pull request
Apr 2, 2026
- lodash-es 4.17.23 -> 4.18.1 (security: prototype pollution, code injection) - @eslint-react/eslint-plugin 3.0.0 -> 4.2.1 (major: remove stale component-hook-factories disables) - @codemirror/view 6.40.0 -> 6.41.0 - @tanstack/react-query 5.96.0 -> 5.96.1 - @playwright/test 1.59.0 -> 1.59.1 (Windows console fix) - @storybook/* 10.3.3 -> 10.3.4 (a11y flake fix, CSF4 Vitest fix) - esbuild 0.27.4 -> 0.27.5 - Full lockfile refresh for transitive deps - Document bash -c workaround for npm --prefix limitation
Owner
|
Consolidated into #987 -- all 10 web dependency updates applied there, including @eslint-react/eslint-plugin v3->v4 migration. |
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Aureliolo
added a commit
that referenced
this pull request
Apr 2, 2026
…ywright, esbuild, codemirror) (#987) Consolidates #986 and #990 into a single web dependency update PR. ### Security fixes (lodash 4.17.23 -> 4.18.1) - **`_.unset` / `_.omit`**: Prototype pollution via constructor/prototype path traversal (GHSA-f23m-r3pf-42rh) - **`_.template`**: Code injection via imports keys (GHSA-r5fr-rjxr-66jc, CVE-2026-4800) ### Package updates | Package | From | To | Type | |---------|------|----|------| | lodash | 4.17.23 | 4.18.1 | security (transitive via inquirer) | | lodash-es | 4.17.23 | 4.18.1 | security (transitive via lighthouse) | | @eslint-react/eslint-plugin | 3.0.0 | 4.2.1 | major (rule prefix flattening, removed component-hook-factories) | | @codemirror/view | 6.40.0 | 6.41.0 | minor (posAtCoords fix, cursorScrollMargin) | | @tanstack/react-query | 5.96.0 | 5.96.1 | patch (DTS rollup fix) | | @playwright/test | 1.59.0 | 1.59.1 | patch (Windows console regression fix) | | @storybook/* (5 pkgs) | 10.3.3 | 10.3.4 | patch (a11y flake fix, CSF4 Vitest fix) | | esbuild | 0.27.4 | 0.27.5 | patch (metafile regression, async generator fix) | ### Additional changes - Full lockfile refresh for all transitive deps - Removed 11 stale `@eslint-react/component-hook-factories` disable comments (rule removed in v4) - Document `bash -c` workaround for `npm --prefix` limitation in CLAUDE.md Closes #986 --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Aurelio <19254254+Aureliolo@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the all group in /web with 10 updates:
6.40.06.41.05.96.05.96.13.0.04.2.11.59.01.59.110.3.310.3.410.3.310.3.410.3.310.3.410.3.310.3.40.27.40.27.510.3.310.3.4Updates
@codemirror/viewfrom 6.40.0 to 6.41.0Changelog
Sourced from
@codemirror/view's changelog.Commits
a0a5ed9Mark version 6.41.0c834ebfEnable the workaround for ghost selections in all forms of Webkit49d72c4Improve posAtCoords in non-uniform height lines4935d24Make the margin used when scrolling the cursor into view configurableed7d625Remove duplicated slash in forum url in READMEc3770d3Fix forum link in readmeUpdates
@tanstack/react-queryfrom 5.96.0 to 5.96.1Release notes
Sourced from
@tanstack/react-query's releases.Changelog
Sourced from
@tanstack/react-query's changelog.Commits
75052a7ci: Version Packages (#10370)Updates
@eslint-react/eslint-pluginfrom 3.0.0 to 4.2.1Release notes
Sourced from
@eslint-react/eslint-plugin's releases.... (truncated)
Changelog
Sourced from
@eslint-react/eslint-plugin's changelog.... (truncated)
Commits
a4eebd2release: 4.2.1c42ef4frelease: 4.2.1-rc.101edc2ffeat(docs): add recipes section; remove unstable-rules-of-props/state (#1679)593e304release: 4.2.1-rc.07145f85docs: add Utility Modules section to README files358cd99Bump to 4.2.1-beta.0 and refactor release scripts674c605release: 4.2.0-beta.3dcaa5aadocs(scripts): add comprehensive README and more automation scripts (#1673)1f38f66release: 4.2.0-beta.2d665ea4test: review pr #1660 #1662 (#1671)Updates
@playwright/testfrom 1.59.0 to 1.59.1Release notes
Sourced from
@playwright/test's releases.Commits
d466ac5chore: mark v1.59.1 (#40005)530e7e5cherry-pick(#4004): fix(cli): kill-all should kill dashboard9aa216ccherry-pick(#39994): Revert "fix(windows): hide console window when spawning ...Updates
@storybook/addon-a11yfrom 10.3.3 to 10.3.4Release notes
Sourced from
@storybook/addon-a11y's releases.Changelog
Sourced from
@storybook/addon-a11y's changelog.Commits
4eff9cdBump version from "10.3.3" to "10.3.4" [skip ci]bf06f9aMerge pull request #34203 from mixelburg/fix/a11y-context-clear-timeout-on-un...Updates
@storybook/addon-docsfrom 10.3.3 to 10.3.4Release notes
Sourced from
@storybook/addon-docs's releases.Changelog
Sourced from
@storybook/addon-docs's changelog.Commits
4eff9cdBump version from "10.3.3" to "10.3.4" [skip ci]4eb227bBuild: Move prettier to oxfmtUpdates
@storybook/reactfrom 10.3.3 to 10.3.4Release notes
Sourced from
@storybook/react's releases.Changelog
Sourced from
@storybook/react's changelog.Commits
4eff9cdBump version from "10.3.3" to "10.3.4" [skip ci]4fb52a2Merge pull request #34393 from mixelburg/fix/docgen-resolver-tsx-fallbackUpdates
@storybook/react-vitefrom 10.3.3 to 10.3.4Release notes
Sourced from
@storybook/react-vite's releases.Changelog
Sourced from
@storybook/react-vite's changelog.Commits
4eff9cdBump version from "10.3.3" to "10.3.4" [skip ci]4fb52a2Merge pull request #34393 from mixelburg/fix/docgen-resolver-tsx-fallback756f6e3Merge pull request #34335 from beeswhacks/upgrade-vite-plugin-react-docgen-ty...Updates
esbuildfrom 0.27.4 to 0.27.5Release notes
Sourced from esbuild's releases.
... (truncated)
Changelog
Sourced from esbuild's changelog.
... (truncated)
Commits
0102ae3publish 0.27.5 to npmeb93887split offCHANGELOG-2025.mda54a51afix #4421: use define for ts parameter props31a7c67remove unused variable in__asyncGenerator1ea01a6update release notesa8f8c0efix: Handle non-awaited async generator (#4417)4844d4bfix #4420, close #4418:metafileJSON regressionedbdce8fix #4432: addes2025as a valid targetUpdates
storybookfrom 10.3.3 to 10.3.4Release notes
Sourced from storybook's releases.
Changelog
Sourced from storybook's changelog.
Commits
4eff9cdBump version from "10.3.3" to "10.3.4" [skip ci]21d37fdMerge pull request #34224 from storybookjs/chore/removeprettierrc4eb227bBuild: Move prettier to oxfmtff9d121Merge pull request #34316 from storybookjs/jeppe/fix-error-reports-on-init5bc8686Merge pull request #34281 from storybookjs/fix-stackblitz-websocketDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions