chore(deps): bump the frontend-dependencies group with 9 updates#198
Conversation
Bumps the frontend-dependencies group with 9 updates: | Package | From | To | | --- | --- | --- | | [@polar-sh/sdk](https://github.com/polarsource/polar-js) | `0.46.2` | `0.46.4` | | [framer-motion](https://github.com/motiondivision/motion) | `12.34.3` | `12.36.0` | | [@commitlint/cli](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/cli) | `20.4.2` | `20.5.0` | | [@commitlint/config-conventional](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/config-conventional) | `20.4.2` | `20.5.0` | | [@iconify-json/lucide](https://github.com/iconify/icon-sets) | `1.2.96` | `1.2.98` | | [rollup-plugin-visualizer](https://github.com/btd/rollup-plugin-visualizer) | `6.0.8` | `6.0.11` | | [lru-cache](https://github.com/isaacs/node-lru-cache) | `11.2.6` | `11.2.7` | | [mongoose](https://github.com/Automattic/mongoose) | `9.2.2` | `9.3.0` | | [svix](https://github.com/svix/svix-webhooks) | `1.86.0` | `1.88.0` | Updates `@polar-sh/sdk` from 0.46.2 to 0.46.4 - [Release notes](https://github.com/polarsource/polar-js/releases) - [Changelog](https://github.com/polarsource/polar-js/blob/main/RELEASES.md) - [Commits](polarsource/polar-js@v0.46.2...v0.46.4) Updates `framer-motion` from 12.34.3 to 12.36.0 - [Changelog](https://github.com/motiondivision/motion/blob/main/CHANGELOG.md) - [Commits](motiondivision/motion@v12.34.3...v12.36.0) Updates `@commitlint/cli` from 20.4.2 to 20.5.0 - [Release notes](https://github.com/conventional-changelog/commitlint/releases) - [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/cli/CHANGELOG.md) - [Commits](https://github.com/conventional-changelog/commitlint/commits/v20.5.0/@commitlint/cli) Updates `@commitlint/config-conventional` from 20.4.2 to 20.5.0 - [Release notes](https://github.com/conventional-changelog/commitlint/releases) - [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/config-conventional/CHANGELOG.md) - [Commits](https://github.com/conventional-changelog/commitlint/commits/v20.5.0/@commitlint/config-conventional) Updates `@iconify-json/lucide` from 1.2.96 to 1.2.98 - [Commits](https://github.com/iconify/icon-sets/commits) Updates `rollup-plugin-visualizer` from 6.0.8 to 6.0.11 - [Changelog](https://github.com/btd/rollup-plugin-visualizer/blob/master/CHANGELOG.md) - [Commits](btd/rollup-plugin-visualizer@v6.0.8...v6.0.11) Updates `lru-cache` from 11.2.6 to 11.2.7 - [Changelog](https://github.com/isaacs/node-lru-cache/blob/main/CHANGELOG.md) - [Commits](isaacs/node-lru-cache@v11.2.6...v11.2.7) Updates `mongoose` from 9.2.2 to 9.3.0 - [Release notes](https://github.com/Automattic/mongoose/releases) - [Changelog](https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md) - [Commits](Automattic/mongoose@9.2.2...9.3.0) Updates `svix` from 1.86.0 to 1.88.0 - [Release notes](https://github.com/svix/svix-webhooks/releases) - [Changelog](https://github.com/svix/svix-webhooks/blob/main/ChangeLog.md) - [Commits](svix/svix-webhooks@v1.86.0...v1.88.0) --- updated-dependencies: - dependency-name: "@polar-sh/sdk" dependency-version: 0.46.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: frontend-dependencies - dependency-name: framer-motion dependency-version: 12.36.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: frontend-dependencies - dependency-name: "@commitlint/cli" dependency-version: 20.5.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: frontend-dependencies - dependency-name: "@commitlint/config-conventional" dependency-version: 20.5.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: frontend-dependencies - dependency-name: "@iconify-json/lucide" dependency-version: 1.2.98 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: frontend-dependencies - dependency-name: rollup-plugin-visualizer dependency-version: 6.0.11 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: frontend-dependencies - dependency-name: lru-cache dependency-version: 11.2.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: frontend-dependencies - dependency-name: mongoose dependency-version: 9.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: frontend-dependencies - dependency-name: svix dependency-version: 1.88.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: frontend-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
AssigneesThe following users could not be added as assignees: LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Greptile SummaryDependabot PR bumping 9 frontend/API dependencies to their latest patch/minor versions. The actual changes in the manifest files are limited to:
Confidence Score: 3/5
Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[Dependabot PR] --> B[api/package.json]
A --> C[apps/frontend/package.json]
A --> D[package-lock.json]
B --> B1["@polar-sh/sdk ^0.46.3 → ^0.46.4"]
B --> B2["lru-cache ^11.2.6 → ^11.2.7"]
C --> C1["@polar-sh/sdk ^0.46.3 → ^0.46.4"]
C --> C2["@commitlint/cli ^20.4.4 → ^20.5.0"]
C --> C3["@commitlint/config-conventional ^20.4.4 → ^20.5.0"]
D --> D1["Updated dependency resolutions"]
D --> D2["⚠️ svix: ^1.88.0 → ^1.86.0 (unintended downgrade)"]
style D2 fill:#ff6b6b,color:#fff
Last reviewed commit: 9e18516 |
| "mongoose": "^9.3.0", | ||
| "resend": "^6.9.3", | ||
| "svix": "^1.88.0" | ||
| "svix": "^1.86.0" |
There was a problem hiding this comment.
Svix version downgraded in lockfile
The packages.api.dependencies.svix specifier was changed from "^1.88.0" to "^1.86.0", but api/package.json still declares "svix": "^1.88.0". This creates a mismatch between the lockfile and the manifest. The base branch correctly had "^1.88.0" here.
This looks like a Dependabot regeneration artifact. After merging, an npm install would likely correct the lockfile, but the inconsistency could cause confusion or unexpected resolution behavior in CI. Consider running npm install to regenerate the lockfile before merging.
| "svix": "^1.86.0" | |
| "svix": "^1.88.0" |
There was a problem hiding this comment.
2 issues found across 3 files
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="apps/frontend/package.json">
<violation number="1" location="apps/frontend/package.json:53">
P2: This dependency bump is incomplete without updating the root lockfile, so clean installs will keep using the previous @polar-sh/sdk version.</violation>
<violation number="2" location="apps/frontend/package.json:82">
P2: The commitlint version bump is also missing the corresponding root lockfile update, so CI will keep installing the old 20.4.2 packages.</violation>
</file>
Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.
| "devDependencies": { | ||
| "@commitlint/cli": "^20.4.4", | ||
| "@commitlint/config-conventional": "^20.4.4", | ||
| "@commitlint/cli": "^20.5.0", |
There was a problem hiding this comment.
P2: The commitlint version bump is also missing the corresponding root lockfile update, so CI will keep installing the old 20.4.2 packages.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At apps/frontend/package.json, line 82:
<comment>The commitlint version bump is also missing the corresponding root lockfile update, so CI will keep installing the old 20.4.2 packages.</comment>
<file context>
@@ -79,8 +79,8 @@
"devDependencies": {
- "@commitlint/cli": "^20.4.4",
- "@commitlint/config-conventional": "^20.4.4",
+ "@commitlint/cli": "^20.5.0",
+ "@commitlint/config-conventional": "^20.5.0",
"@eslint/js": "^9.39.4",
</file context>
| "@clerk/types": "^4.101.18", | ||
| "@modelcontextprotocol/sdk": "^1.27.1", | ||
| "@polar-sh/sdk": "^0.46.3", | ||
| "@polar-sh/sdk": "^0.46.4", |
There was a problem hiding this comment.
P2: This dependency bump is incomplete without updating the root lockfile, so clean installs will keep using the previous @polar-sh/sdk version.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At apps/frontend/package.json, line 53:
<comment>This dependency bump is incomplete without updating the root lockfile, so clean installs will keep using the previous @polar-sh/sdk version.</comment>
<file context>
@@ -50,7 +50,7 @@
"@clerk/types": "^4.101.18",
"@modelcontextprotocol/sdk": "^1.27.1",
- "@polar-sh/sdk": "^0.46.3",
+ "@polar-sh/sdk": "^0.46.4",
"@radix-ui/react-alert-dialog": "^1.1.15",
"@radix-ui/react-dialog": "^1.1.15",
</file context>
Bumps the frontend-dependencies group with 9 updates:
0.46.20.46.412.34.312.36.020.4.220.5.020.4.220.5.01.2.961.2.986.0.86.0.1111.2.611.2.79.2.29.3.01.86.01.88.0Updates
@polar-sh/sdkfrom 0.46.2 to 0.46.4Release notes
Sourced from
@polar-sh/sdk's releases.... (truncated)
Changelog
Sourced from
@polar-sh/sdk's changelog.... (truncated)
Commits
dd61fd3Merge pull request #164 from polarsource/speakeasy-sdk-regen-17731030938bc8ac5empty commit to trigger [run-tests] workflow52631a8## Typescript SDK Changes:6fa8eb1Merge pull request #165 from polarsource/fix/add-missing-webhook-event-types915fa3efix: add missing webhook event types to parseEventec38712## Typescript SDK Changes:Updates
framer-motionfrom 12.34.3 to 12.36.0Changelog
Sourced from framer-motion's changelog.
... (truncated)
Commits
ea66e17v12.36.0db5726dAdding tests for exit animations5ccc21aUpdating changelog06159b3Latested64e5fMerge pull request #3625 from motiondivision/worktree-fix-issue-31415fad98cMerge pull request #3627 from motiondivision/worktree-fix-issue-3103f084bb2Simplify axis-snap logic: use copyAxisInto, remove redundant isShared block3204711Merge pull request #3626 from motiondivision/audit/motion-dom-frameloop25bf593Merge pull request #3629 from motiondivision/worktree-fix-issue-30820dad36bMerge pull request #3634 from motiondivision/worktree-fix-issue-3102Updates
@commitlint/clifrom 20.4.2 to 20.5.0Release notes
Sourced from
@commitlint/cli's releases.... (truncated)
Changelog
Sourced from
@commitlint/cli's changelog.Commits
a7918e9v20.5.0cf80f75fix(cli): validate that --cwd directory exists before execution (#4658)02d7245v20.4.4a746981v20.4.318bd371chore: deps (#4635)8ff7c7ffix: footer parser does not escape special chars for regex #4560 (#4634)Updates
@commitlint/config-conventionalfrom 20.4.2 to 20.5.0Release notes
Sourced from
@commitlint/config-conventional's releases.... (truncated)
Changelog
Sourced from
@commitlint/config-conventional's changelog.Commits
a7918e9v20.5.002d7245v20.4.4a746981v20.4.38ff7c7ffix: footer parser does not escape special chars for regex #4560 (#4634)Updates
@iconify-json/lucidefrom 1.2.96 to 1.2.98Commits
Updates
rollup-plugin-visualizerfrom 6.0.8 to 6.0.11Changelog
Sourced from rollup-plugin-visualizer's changelog.
Commits
a9d913c6.0.11c613c5bCorrect tag33e384c6.0.107896810Update build script for branch1425f706.0.9c69b1b6Update snapshots to accomodate version updatesf606b6bSet minumum version of node to v20023fb44Update dependencies5bea1b2Update supported node version7cae234Update README.md (#205)Updates
lru-cachefrom 11.2.6 to 11.2.7Commits
e787b9f11.2.7e6f15bfformat tests, update project ci settings2ec0b52abstract out the update autopurge fn, formatting879f8b1abstract out setPurgeTimer (internal)88ae941fix: reschedule autopurge timer when updateAgeOnGet resets TTL start757c157remove unused polyfills from testsUpdates
mongoosefrom 9.2.2 to 9.3.0Release notes
Sourced from mongoose's releases.
Changelog
Sourced from mongoose's changelog.
Commits
7666bb8chore: release 9.3.039feb64Merge pull request #16078 from Automattic/9.3ac0701dMerge pull request #16081 from mrazauskas/add-type-constraintsf55c116Merge pull request #16077 from Automattic/vkarpov15/gh-16053bd6f64efix linte5237ebUpdate test/types/inferrawdoctype.test.ts1e9817ffix: add adds type constraints forDocument#$model()andDocument#model()f233efdaddress code review comments31765bbMerge branch 'master' into 9.32963f59Merge branch '9.3' into vkarpov15/gh-16053Updates
svixfrom 1.86.0 to 1.88.0Release notes
Sourced from svix's releases.
Changelog
Sourced from svix's changelog.
Commits
c02f82dRelease v1.88.0 (#2223)56b2481Lib/Go:v1.management.authentication.patch-api-token(#2222)0171c67Revert "Update openapi/client libs" (#2221)9fac4faAdd TransportWrapper option to Go SDK SvixOptions (#2215)308bf04Update openapi/client libs (#2219)554e8adbuild(deps): bump quinn-proto from 0.11.13 to 0.11.14 in /svix-cli (#2216)582bb42build(deps): bump quinn-proto from 0.11.13 to 0.11.14 in /server (#2217)6fe609eRelease v1.87.0 (#2212)0c56d1bRefactor retry-after logic (#2210)70d82e9cli: Update dependencies (#2211)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsSummary by cubic
Update frontend dependency group to pick up recent fixes and features. Notable bumps include
@polar-sh/sdk0.46.4,framer-motion12.36.0, andmongoose9.3.0.Dependencies
@polar-sh/sdk→ 0.46.4 (API/type changes to events and organizations)framer-motion→ 12.36.0 (axis-locked layout animations, bug fixes)@commitlint/cliand@commitlint/config-conventional→ 20.5.0mongoose→ 9.3.0 (TS improvements, new helpers)lru-cache→ 11.2.7 (autopurge timer fix)@iconify-json/lucide,rollup-plugin-visualizer,svixMigration
@polar-sh/sdk: re-check usages ofpolar.events.*and organization endpoints; run type checks and adjust for updated response/request shapes.Written for commit 9e18516. Summary will update on new commits.