chore(deps): bump the frontend-dependencies group with 10 updates#202
Conversation
Bumps the frontend-dependencies group with 10 updates: | Package | From | To | | --- | --- | --- | | [vercel](https://github.com/vercel/vercel/tree/HEAD/packages/cli) | `50.32.5` | `50.33.0` | | [@polar-sh/sdk](https://github.com/polarsource/polar-js) | `0.46.2` | `0.46.4` | | [framer-motion](https://github.com/motiondivision/motion) | `12.34.3` | `12.38.0` | | [@commitlint/cli](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/cli) | `20.4.2` | `20.5.0` | | [@commitlint/config-conventional](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/config-conventional) | `20.4.2` | `20.5.0` | | [@iconify-json/lucide](https://github.com/iconify/icon-sets) | `1.2.96` | `1.2.98` | | [rollup-plugin-visualizer](https://github.com/btd/rollup-plugin-visualizer) | `6.0.8` | `6.0.11` | | [mongoose](https://github.com/Automattic/mongoose) | `9.2.2` | `9.3.1` | | [resend](https://github.com/resend/resend-node) | `6.9.3` | `6.9.4` | | [svix](https://github.com/svix/svix-webhooks) | `1.86.0` | `1.88.0` | Updates `vercel` from 50.32.5 to 50.33.0 - [Release notes](https://github.com/vercel/vercel/releases) - [Changelog](https://github.com/vercel/vercel/blob/main/packages/cli/CHANGELOG.md) - [Commits](https://github.com/vercel/vercel/commits/vercel@50.33.0/packages/cli) Updates `@polar-sh/sdk` from 0.46.2 to 0.46.4 - [Release notes](https://github.com/polarsource/polar-js/releases) - [Changelog](https://github.com/polarsource/polar-js/blob/main/RELEASES.md) - [Commits](polarsource/polar-js@v0.46.2...v0.46.4) Updates `framer-motion` from 12.34.3 to 12.38.0 - [Changelog](https://github.com/motiondivision/motion/blob/main/CHANGELOG.md) - [Commits](motiondivision/motion@v12.34.3...v12.38.0) Updates `@commitlint/cli` from 20.4.2 to 20.5.0 - [Release notes](https://github.com/conventional-changelog/commitlint/releases) - [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/cli/CHANGELOG.md) - [Commits](https://github.com/conventional-changelog/commitlint/commits/v20.5.0/@commitlint/cli) Updates `@commitlint/config-conventional` from 20.4.2 to 20.5.0 - [Release notes](https://github.com/conventional-changelog/commitlint/releases) - [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/config-conventional/CHANGELOG.md) - [Commits](https://github.com/conventional-changelog/commitlint/commits/v20.5.0/@commitlint/config-conventional) Updates `@iconify-json/lucide` from 1.2.96 to 1.2.98 - [Commits](https://github.com/iconify/icon-sets/commits) Updates `rollup-plugin-visualizer` from 6.0.8 to 6.0.11 - [Changelog](https://github.com/btd/rollup-plugin-visualizer/blob/master/CHANGELOG.md) - [Commits](btd/rollup-plugin-visualizer@v6.0.8...v6.0.11) Updates `mongoose` from 9.2.2 to 9.3.1 - [Release notes](https://github.com/Automattic/mongoose/releases) - [Changelog](https://github.com/Automattic/mongoose/blob/master/CHANGELOG.md) - [Commits](Automattic/mongoose@9.2.2...9.3.1) Updates `resend` from 6.9.3 to 6.9.4 - [Release notes](https://github.com/resend/resend-node/releases) - [Commits](resend/resend-node@v6.9.3...v6.9.4) Updates `svix` from 1.86.0 to 1.88.0 - [Release notes](https://github.com/svix/svix-webhooks/releases) - [Changelog](https://github.com/svix/svix-webhooks/blob/main/ChangeLog.md) - [Commits](svix/svix-webhooks@v1.86.0...v1.88.0) --- updated-dependencies: - dependency-name: vercel dependency-version: 50.33.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: frontend-dependencies - dependency-name: "@polar-sh/sdk" dependency-version: 0.46.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: frontend-dependencies - dependency-name: framer-motion dependency-version: 12.38.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: frontend-dependencies - dependency-name: "@commitlint/cli" dependency-version: 20.5.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: frontend-dependencies - dependency-name: "@commitlint/config-conventional" dependency-version: 20.5.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: frontend-dependencies - dependency-name: "@iconify-json/lucide" dependency-version: 1.2.98 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: frontend-dependencies - dependency-name: rollup-plugin-visualizer dependency-version: 6.0.11 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: frontend-dependencies - dependency-name: mongoose dependency-version: 9.3.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: frontend-dependencies - dependency-name: resend dependency-version: 6.9.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: frontend-dependencies - dependency-name: svix dependency-version: 1.88.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: frontend-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
AssigneesThe following users could not be added as assignees: LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Greptile SummaryThis is a Dependabot-generated PR that bumps 10 frontend dependencies across Key concern:
Other observations:
Confidence Score: 2/5
Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[package.json\nvercel ^50.32.5 → ^50.33.0] --> R[Root Workspace]
B[api/package.json\nmongoose ^9.3.0 → ^9.3.1\nsvix ^1.88.0 unchanged] --> API[API Workspace]
C[apps/frontend/package.json\nframer-motion ^12.37.0 → ^12.38.0] --> FE[Frontend Workspace]
R --> LF[package-lock.json]
API --> LF
FE --> LF
LF -->|"✅ vercel 50.33.0\n✅ framer-motion 12.38.0\n✅ mongoose 9.3.1\n✅ @polar-sh/sdk 0.46.4\n✅ @commitlint/* 20.5.0\n✅ rollup-plugin-visualizer 6.0.11\n✅ resend 6.9.4\n✅ svix 1.88.0 (resolved)"| OK[Most deps OK]
LF -->|"⚠️ api workspace entry:\nsvix ^1.88.0 → ^1.86.0\n(should stay ^1.88.0)"| ERR[Lockfile mismatch!\nnpm ci will fail]
Last reviewed commit: "chore(deps): bump th..." |
| "lru-cache": "^11.2.7", | ||
| "mongodb": "^7.1.0", | ||
| "mongoose": "^9.3.0", | ||
| "mongoose": "^9.3.1", |
There was a problem hiding this comment.
Lockfile/manifest version mismatch for
svix
The package-lock.json now declares svix: ^1.86.0 for the api workspace, but api/package.json still specifies "svix": "^1.88.0". These two files are out of sync.
In npm v7+ lockfile format, the packages section mirrors each workspace's package.json exactly. When these disagree, npm ci will fail with a "does not satisfy" error, and npm install will regenerate the lockfile. The PR description also states svix should be bumped from 1.86.0 to 1.88.0, but the lockfile workspace entry is moving in the opposite direction.
Expected post-merge state in package-lock.json (api workspace section):
| "mongoose": "^9.3.1", | |
| "svix": "^1.88.0" |
There was a problem hiding this comment.
2 issues found across 4 files
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="package.json">
<violation number="1" location="package.json:86">
P2: This Vercel CLI bump changes unauthenticated AI-agent startup from a fast failure into an auto-login flow, which can block `npm run dev:vercel` here because the script still omits the required `--token`.</violation>
</file>
<file name="package-lock.json">
<violation number="1" location="package-lock.json:67">
P1: Keep the lockfile workspace dependency aligned with `api/package.json` by using `^1.88.0` for `svix`; this mismatch can break `npm ci` and causes lockfile churn.</violation>
</file>
Reply with feedback, questions, or to request a fix. Tag @cubic-dev-ai to re-run a review.
| "mongoose": "^9.3.1", | ||
| "resend": "^6.9.4", | ||
| "svix": "^1.88.0" | ||
| "svix": "^1.86.0" |
There was a problem hiding this comment.
P1: Keep the lockfile workspace dependency aligned with api/package.json by using ^1.88.0 for svix; this mismatch can break npm ci and causes lockfile churn.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At package-lock.json, line 67:
<comment>Keep the lockfile workspace dependency aligned with `api/package.json` by using `^1.88.0` for `svix`; this mismatch can break `npm ci` and causes lockfile churn.</comment>
<file context>
@@ -62,9 +62,9 @@
+ "mongoose": "^9.3.1",
"resend": "^6.9.4",
- "svix": "^1.88.0"
+ "svix": "^1.86.0"
}
},
</file context>
| "dotenv-cli": "^11.0.0", | ||
| "turbo": "^2.8.17", | ||
| "vercel": "^50.32.5", | ||
| "vercel": "^50.33.0", |
There was a problem hiding this comment.
P2: This Vercel CLI bump changes unauthenticated AI-agent startup from a fast failure into an auto-login flow, which can block npm run dev:vercel here because the script still omits the required --token.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At package.json, line 86:
<comment>This Vercel CLI bump changes unauthenticated AI-agent startup from a fast failure into an auto-login flow, which can block `npm run dev:vercel` here because the script still omits the required `--token`.</comment>
<file context>
@@ -83,7 +83,7 @@
"dotenv-cli": "^11.0.0",
"turbo": "^2.8.17",
- "vercel": "^50.32.5",
+ "vercel": "^50.33.0",
"eslint": "^9.39.4",
"@eslint/js": "^9.39.4",
</file context>
Bumps the frontend-dependencies group with 10 updates:
50.32.550.33.00.46.20.46.412.34.312.38.020.4.220.5.020.4.220.5.01.2.961.2.986.0.86.0.119.2.29.3.16.9.36.9.41.86.01.88.0Updates
vercelfrom 50.32.5 to 50.33.0Release notes
Sourced from vercel's releases.
... (truncated)
Changelog
Sourced from vercel's changelog.
... (truncated)
Commits
a0e6e10Version Packages (#15507)d49ddd2[python tests] resolve python wheel urls in tests to fix broken CI (#15606)9dbc976feat(cli): Add query param for cli source for post-buy (#15599)2d65f45[Vercel CLI] Agent fix for Vercel Login (#15581)a244f2bfeat(cli): track tty in telemetry (#15574)b073975[domains] show unavailable error instead of price check error on domain purch...89f9c77[services] add support for background workers to vc dev (#15434)8ee6645[cli] Preserve --environment in web UI fallback URLs (#15493)d8c186e[CLI] feat: non-interactive mode for redirects (#15450)e2cce32noninteractive mode readme (#15496)Updates
@polar-sh/sdkfrom 0.46.2 to 0.46.4Release notes
Sourced from
@polar-sh/sdk's releases.... (truncated)
Changelog
Sourced from
@polar-sh/sdk's changelog.... (truncated)
Commits
dd61fd3Merge pull request #164 from polarsource/speakeasy-sdk-regen-17731030938bc8ac5empty commit to trigger [run-tests] workflow52631a8## Typescript SDK Changes:6fa8eb1Merge pull request #165 from polarsource/fix/add-missing-webhook-event-types915fa3efix: add missing webhook event types to parseEventec38712## Typescript SDK Changes:Updates
framer-motionfrom 12.34.3 to 12.38.0Changelog
Sourced from framer-motion's changelog.
... (truncated)
Commits
0bfc9fev12.38.0343cb0cUpdating layoutAnchoree99ad2Updating changelog062660bUpdating changgelog303da7dUpdating readmeb075adcMerge pull request #3647 from motiondivision/feat/layout-anchorf0991d6Add missing layoutAnchor !== false guard in attemptToResolveRelativeTargetb5798e9Merge pull request #3642 from motiondivision/worktree-fix-issue-30787686c19Merge pull request #3636 from motiondivision/worktree-fix-issue-3061a95c487Fix auto-scroll in reorder-virtualized test pageUpdates
@commitlint/clifrom 20.4.2 to 20.5.0Release notes
Sourced from
@commitlint/cli's releases.... (truncated)
Changelog
Sourced from
@commitlint/cli's changelog.Commits
a7918e9v20.5.0cf80f75fix(cli): validate that --cwd directory exists before execution (#4658)02d7245v20.4.4a746981v20.4.318bd371chore: deps (#4635)8ff7c7ffix: footer parser does not escape special chars for regex #4560 (#4634)Updates
@commitlint/config-conventionalfrom 20.4.2 to 20.5.0Release notes
Sourced from
@commitlint/config-conventional's releases.... (truncated)
Changelog
Sourced from
@commitlint/config-conventional's changelog.Commits
a7918e9v20.5.002d7245v20.4.4a746981v20.4.38ff7c7ffix: footer parser does not escape special chars for regex #4560 (#4634)Updates
@iconify-json/lucidefrom 1.2.96 to 1.2.98Commits
Updates
rollup-plugin-visualizerfrom 6.0.8 to 6.0.11Changelog
Sourced from rollup-plugin-visualizer's changelog.
Commits
a9d913c6.0.11c613c5bCorrect tag33e384c6.0.107896810Update build script for branch1425f706.0.9c69b1b6Update snapshots to accomodate version updatesf606b6bSet minumum version of node to v20023fb44Update dependencies5bea1b2Update supported node version7cae234Update README.md (#205)Updates
mongoosefrom 9.2.2 to 9.3.1Release notes
Sourced from mongoose's releases.
Changelog
Sourced from mongoose's changelog.
Commits
88673ccchore: release 9.3.189ae6ecMerge pull request #16104 from techcodie/fix-query-cursor-close-context1a6e317Merge pull request #16102 from Automattic/vkarpov15/gh-16046-231bc5a1Fix wrong this context in QueryCursor._read cursor.close callback6a593e3Merge pull request #16083 from mrazauskas/use-tstyche-assertions6043037Update virtuals type in autoTypedVirtuals function81f96d3Import mongoose alongside other mongoose types6bd17b2Fix type definition for HydratedDocType8285600Update type expectations for virtuals in testsc98dde6types(schema): infer schema options correctly for model context in staticsUpdates
resendfrom 6.9.3 to 6.9.4Release notes
Sourced from resend's releases.
Commits
95e4630chore: bump package version to 6.9.4 (#878)3413387chore(deps): update dependency@biomejs/biometo v2.4.7 (#879)0987940feat(api-keys): addlast_used_atfield to API key response (#877)02ee43cchore(deps): update dependency@biomejs/biometo v2.4.6 (#847)35cd31achore(deps): update dependency@types/nodeto v24.11.0 (#856)cfd8a08fix(deps): update dependency svix to v1.86.0 (#849)0acc12dchore(deps): update dependency dotenv to v17.3.1 (