Skip to content

fix(deps): update all non-major dependencies - #1595

Open
renovate[bot] wants to merge 1 commit into
stagefrom
renovate/all-minor-patch
Open

fix(deps): update all non-major dependencies#1595
renovate[bot] wants to merge 1 commit into
stagefrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
@ai-sdk/react (source) 4.0.404.0.55 age confidence dependencies patch 4.0.61 (+4)
@datadog/browser-rum (source) 7.6.17.7.0 age confidence dependencies minor 7.8.0
@datadog/browser-rum-react (source) 7.6.17.7.0 age confidence dependencies minor 7.8.0
@datadog/datadog-ci (source) 5.21.25.22.0 age confidence devDependencies minor
@harperfast/agent-tools (source) 1.2.21.2.3 age confidence dependencies patch
@harperfast/skills (source) 1.11.01.12.1 age confidence dependencies minor
@hookform/resolvers (source) 5.4.05.7.1 age confidence dependencies minor
@playwright/test (source) 1.61.11.62.1 age confidence devDependencies minor
@radix-ui/react-accordion (source) 1.2.181.2.20 age confidence dependencies patch
@radix-ui/react-alert-dialog (source) 1.1.211.1.23 age confidence dependencies patch
@radix-ui/react-context-menu (source) 2.3.52.3.7 age confidence dependencies patch
@radix-ui/react-dialog (source) 1.1.211.1.23 age confidence dependencies patch
@radix-ui/react-dropdown-menu (source) 2.1.222.1.24 age confidence dependencies patch
@radix-ui/react-label (source) 2.1.132.1.15 age confidence dependencies patch
@radix-ui/react-navigation-menu (source) 1.2.201.2.22 age confidence dependencies patch
@radix-ui/react-radio-group (source) 1.4.51.4.7 age confidence dependencies patch
@radix-ui/react-scroll-area (source) 1.2.161.2.18 age confidence dependencies patch
@radix-ui/react-select (source) 2.3.52.3.7 age confidence dependencies patch
@radix-ui/react-separator (source) 1.1.131.1.15 age confidence dependencies patch
@radix-ui/react-slot (source) 1.3.11.3.3 age confidence dependencies patch
@radix-ui/react-switch (source) 1.3.51.3.7 age confidence dependencies patch
@radix-ui/react-tabs (source) 1.1.191.1.21 age confidence dependencies patch
@radix-ui/react-toggle (source) 1.1.161.1.18 age confidence dependencies patch
@radix-ui/react-tooltip (source) 1.2.141.2.16 age confidence dependencies patch
@stripe/stripe-js (source) 9.12.09.13.0 age confidence dependencies minor
@tanstack/react-router (source) 1.170.181.170.19 age confidence dependencies patch 1.170.23 (+3)
@tanstack/react-router-devtools (source) 1.167.01.167.1 age confidence dependencies patch
@types/react (source) 19.2.1719.2.18 age confidence devDependencies patch
@types/react-dom (source) 19.2.319.2.4 age confidence devDependencies patch
@vitejs/plugin-react (source) 6.0.46.0.5 age confidence devDependencies patch
ai (source) 7.0.377.0.52 age confidence dependencies patch 7.0.58 (+4)
axios (source) 1.18.11.19.0 age confidence dependencies minor
create-harper (source) 1.10.121.11.3 age confidence dependencies minor
harper (source) 5.1.235.2.0 age confidence devDependencies minor 5.2.1
lucide-react (source) 1.26.01.28.0 age confidence dependencies minor 1.30.0 (+1)
mermaid 11.16.011.16.1 age confidence dependencies patch
motion 12.42.212.43.0 age confidence dependencies minor
node (source) 24.18.024.19.0 age confidence minor
node (source) 24.18.0-bookworm24.18.1-bookworm age confidence final patch 24.19.0
oxlint (source) 1.75.01.77.0 age confidence devDependencies minor
pnpm (source) 11.17.011.20.0 age confidence packageManager minor
pnpm (source) 11.13.111.20.0 age confidence packageManager minor
pnpm/action-setup v6.0.9v6.0.10 age confidence action patch
react-dropzone 19.1.119.3.0 age confidence dependencies minor
react-hook-form (source) 7.82.07.84.0 age confidence dependencies minor
recharts 3.10.03.10.1 age confidence dependencies patch
swagger-ui-react 5.32.115.32.12 age confidence dependencies patch
vite (source) 8.1.58.2.0 age confidence devDependencies minor 8.2.1

Release Notes

vercel/ai (@​ai-sdk/react)

v4.0.55

Compare Source

Patch Changes

v4.0.54

Compare Source

Patch Changes

v4.0.53

Compare Source

Patch Changes

v4.0.52

Compare Source

Patch Changes
  • ai@​7.0.49

v4.0.51

Compare Source

Patch Changes
  • ai@​7.0.48

v4.0.50

Compare Source

Patch Changes

v4.0.49

Compare Source

Patch Changes
  • ai@​7.0.46

v4.0.48

Compare Source

Patch Changes

v4.0.47

Compare Source

Patch Changes
  • Updated dependencies [015acb4]
    • ai@​7.0.44

v4.0.46

Compare Source

Patch Changes

v4.0.45

Compare Source

Patch Changes

v4.0.44

Compare Source

Patch Changes
  • Updated dependencies [2e2224b]
    • ai@​7.0.41

v4.0.43

Compare Source

Patch Changes
  • Updated dependencies [c3782a6]
    • ai@​7.0.40

v4.0.42

Compare Source

Patch Changes

v4.0.41

Compare Source

Patch Changes
DataDog/browser-sdk (@​datadog/browser-rum)

v7.7.0

Compare Source

Public Changes:

  • ✨ Add a version-agnostic React Router entry point (#​4918)
  • ✨ Shopify Integration - implement dedicated bundle (#​4878)
  • ✨ Add a version-agnostic Vue Router entry point (#​4910)
  • ✨ Enable WebSocket resource tracking behind a beta option (#​4882)
  • 📝 [Salesforce Docs] Align with Tile docs (#​4904)

Internal Changes:

  • ♻️ [js-core] Schema-driven configuration validation across browser-core, browser-logs, and browser-rum-core (#​4798)
  • 🔧 Make Salesforce test apps use rum-salesforce bundle. (#​4893)
  • 🔊 Add SDK_NAME to telemetry (#​4888)
DataDog/datadog-ci (@​datadog/datadog-ci)

v5.22.0

Compare Source

What's Changed

datadog-ci
Documentation
RUM
Serverless
Source Code Integration
Chores

New Contributors

Full Changelog: DataDog/datadog-ci@v5.21.2...v5.22.0

HarperFast/agent-tools (@​harperfast/agent-tools)

v1.2.3

Compare Source

Bug Fixes
  • release: pin conventionalcommits preset to v9 and align release-note sections (d9e9c49)
Dependency Updates
HarperFast/skills (@​harperfast/skills)

v1.12.1

Compare Source

Documentation

v1.12.0

Compare Source

Features
  • harper-best-practices: add delegating-to-the-built-in-agent rule (0c6b9d7), closes harper#626

v1.11.1

Compare Source

Bug Fixes
  • release: consolidate release config so all commit types surface in notes (c71a709)
react-hook-form/resolvers (@​hookform/resolvers)

v5.7.1

Compare Source

v5.7.0

Compare Source

Features

v5.6.0

Compare Source

v5.5.8

Compare Source

Bug Fixes
  • Zod resolver drops validation errors for special root field names (#​869) (2f28787)

v5.5.7

Compare Source

v5.5.6

Compare Source

v5.5.5

Compare Source

Bug Fixes
  • yup resolver overrides ref property in errors object with validation metadata when using checkbox input (#​863) (0f70063)

v5.5.4

Compare Source

Bug Fixes
  • AJV Resolver - When ajv schema contains default for certain properties, getValues() returns the form data with properties overwritten (#​862) (c4b6aab)

v5.5.3

Compare Source

Bug Fixes
  • Conditional/dynamic schema resolution no longer working (#​861) (f8d6533)

v5.5.2

Compare Source

v5.5.1

Compare Source

Bug Fixes
  • [zod v4][zod resolver] error on nested discriminated unions (#​858) (4d01d01)

v5.5.0

Compare Source

Features

v5.4.3

Compare Source

Bug Fixes

v5.4.2

Compare Source

Bug Fixes

v5.4.1

Compare Source

Bug Fixes
  • declare validation libraries as optional peerDependencies (#​850) (d5e5134)
microsoft/playwright (@​playwright/test)

v1.62.1

Compare Source

v1.62.0

Compare Source

🧱 New component testing model

Component testing moves to a stories and galleries model.
A story wraps your component in one specific scenario — hard-coded props, mock data, providers — and a

gallery page that you serve renders stories on demand. The new fixtures.mount() fixture navigates
to the gallery, mounts a story by id, and returns a Locator scoped to the story's root element:

test('click should expand', async ({ mount }) => {
  const component = await mount('components/Expandable/Stateful');
  await component.getByRole('button').click();
  await expect(component.getByTestId('expanded')).toHaveValue('true');
});

Pass a story type as a template argument to type-check its props, and use update(props) /
unmount() on the returned locator to re-render or tear down within a test.

🛑 Cancel operations with AbortSignal

Most operations and web-first assertions now accept a signal option that takes an
AbortSignal, letting you
cancel long-running actions, navigations, waits, and assertions:

const controller = new AbortController();
setTimeout(() => controller.abort(), 1000);

await page.getByRole('button', { name: 'Submit' }).click({ signal: controller.signal });
await expect(page.getByText('Done')).toBeVisible({ signal: controller.signal });

Providing a signal does not disable the default timeout; pass timeout: 0 to disable it.

🖼️ WebP screenshots

expect(page).toHaveScreenshot() and expect(locator).toHaveScreenshot()
can now store snapshots in the WebP format — just give the snapshot a .webp name:

// Visual comparisons store the golden snapshot as lossless WebP.
await expect(page).toHaveScreenshot('homepage.webp');

// Standalone screenshots can trade quality for size with lossy WebP.
await page.screenshot({ path: 'homepage.webp', quality: 50 });

page.screenshot() and locator.screenshot() also accept webp as a type,
where quality 100 (the default) is lossless and lower values use lossy compression.

🧩 Custom test filtering with Reporter.preprocess()

New reporter.preprocess() hook runs after the configuration is resolved and before
reporter.onBegin(), letting a reporter mark individual tests as skipped, excluded,
fixed, or failing through a TestRun object:

class MyReporter {
  async preprocess({ config, suite, testRun }) {
    for (const test of suite.allTests()) {
      if (shouldSkip(test))
        testRun.skip(test);
    }
  }
}
🔁 Isolated retries

New testConfig.retryStrategy controls when failed tests are retried. The default
'immediate' retries as soon as a worker is free; 'isolated' runs all retries at the end,
one by one in a single worker, to minimize interference with the rest of the suite:

// playwright.config.ts
export default defineConfig({
  retries: 2,
  retryStrategy: 'isolated',
});
New APIs
Browser and Context
  • New option credentials includes the context's virtual WebAuthn Credentials (passkeys) in the storage state, so they can be persisted and re-seeded into later contexts.
Actions
  • New scroll option ("auto" | "none") on actions to opt out of Playwright's automatic scroll-into-view.
Network
Evaluation
Command line & MCP
Reporters
  • The HTML report's Merge files grouping — previously only a UI toggle — can now be enabled from the config with the new mergeFiles reporter option:
// playwright.config.ts
export default defineConfig({
  reporter: [['html', { mergeFiles: true }]],
});
Announcements
  • ⚠️ Debian 11 is not supported anymore.
Browser Versions
  • Chromium 151.0.7922.34
  • Mozilla Firefox 153.0
  • WebKit 26.5

This version was also tested against the following stable channels:

  • Google Chrome 151
  • Microsoft Edge 151
radix-ui/primitives (@​radix-ui/react-accordion)

v1.2.20

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-collapsible@1.1.20, @radix-ui/react-collection@1.1.15, @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-direction@1.1.4, @radix-ui/react-id@1.1.4, @radix-ui/react-primitive@2.1.10, @radix-ui/react-use-controllable-state@1.2.6

v1.2.19

  • Updated dependencies: @radix-ui/react-collection@1.1.14, @radix-ui/react-primitive@2.1.9, @radix-ui/react-collapsible@1.1.19
radix-ui/primitives (@​radix-ui/react-alert-dialog)

v1.1.23

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-dialog@1.1.23, @radix-ui/react-primitive@2.1.10

v1.1.22

  • Updated dependencies: @radix-ui/react-dialog@1.1.22, @radix-ui/react-primitive@2.1.9
radix-ui/primitives (@​radix-ui/react-context-menu)

v2.3.7

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-context@1.2.2, @radix-ui/react-menu@2.1.24, @radix-ui/react-primitive@2.1.10, @radix-ui/react-use-controllable-state@1.2.6

v2.3.6

  • Updated dependencies: @radix-ui/react-menu@2.1.23, @radix-ui/react-primitive@2.1.9
radix-ui/primitives (@​radix-ui/react-dialog)

v1.1.23

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-dismissable-layer@1.1.19, @radix-ui/react-focus-guards@1.1.6, @radix-ui/react-focus-scope@1.1.16, @radix-ui/react-id@1.1.4, @radix-ui/react-portal@1.1.17, @radix-ui/react-presence@1.1.10, @radix-ui/react-primitive@2.1.10, @radix-ui/react-slot@1.3.3, @radix-ui/react-use-controllable-state@1.2.6, @radix-ui/react-use-layout-effect@1.1.4

v1.1.22

  • Updated dependencies: @radix-ui/react-slot@1.3.2, @radix-ui/react-primitive@2.1.9, @radix-ui/react-dismissable-layer@1.1.18, @radix-ui/react-focus-scope@1.1.15, @radix-ui/react-portal@1.1.16
radix-ui/primitives (@​radix-ui/react-dropdown-menu)

v2.1.24

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-id@1.1.4, @radix-ui/react-menu@2.1.24, @radix-ui/react-primitive@2.1.10, @radix-ui/react-use-controllable-state@1.2.6

v2.1.23

  • Updated dependencies: @radix-ui/react-menu@2.1.23, @radix-ui/react-primitive@2.1.9
radix-ui/primitives (@​radix-ui/react-label)

v2.1.15

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-primitive@2.1.10

v2.1.14

  • Updated dependencies: @radix-ui/react-primitive@2.1.9
radix-ui/primitives (@​radix-ui/react-navigation-menu)

v1.2.22

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-collection@1.1.15, @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-direction@1.1.4, @radix-ui/react-dismissable-layer@1.1.19, @radix-ui/react-id@1.1.4, @radix-ui/react-presence@1.1.10, @radix-ui/react-primitive@2.1.10, @radix-ui/react-use-callback-ref@1.1.4, @radix-ui/react-use-controllable-state@1.2.6, @radix-ui/react-use-layout-effect@1.1.4, @radix-ui/react-use-previous@1.1.4, @radix-ui/react-visually-hidden@1.2.11

v1.2.21

  • Updated dependencies: @radix-ui/react-collection@1.1.14, @radix-ui/react-primitive@2.1.9, @radix-ui/react-dismissable-layer@1.1.18, @radix-ui/react-visually-hidden@1.2.10
radix-ui/primitives (@​radix-ui/react-radio-group)

v1.4.7

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-direction@1.1.4, @radix-ui/react-presence@1.1.10, @radix-ui/react-primitive@2.1.10, @radix-ui/react-roving-focus@1.1.19, @radix-ui/react-use-controllable-state@1.2.6, `@radix-ui/react-use-s

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • "before 9am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner August 3, 2026 05:03
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 6 times, most recently from 18e2ad0 to e891041 Compare August 4, 2026 12:53

@DavidCockerill DavidCockerill left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes — this needs a code fix rather than a rebase, and there's a security bump inside it that shouldn't wait on that.

The batch isn't validated. Verify PR fails at Type-check, so none of the other 41 bumps were exercised. axios 1.18.1 → 1.19.0 breaks TypedAxios extends Axios — TS2430 at src/config/typedAxios.ts:5; axios widened the generic parameters on its public declarations so the interface extension no longer satisfies the base. renovate/artifacts is also failing.

There's an unremarked security release in here — Node 24.18.1, 11 CVEs, 3 High. Details in the thread; it's currently gated behind an unrelated axios type error, which is the wrong dependency.

Two further axios 1.19.0 changes are runtime-affecting rather than dev-only, worth checking once it compiles: sync request-interceptor dispatch semantics changed (axios#11071 — we install interceptors in installApiUnauthorizedRedirect.ts and getInstanceClient.ts), and repeated trailing slashes are now stripped when combining baseURL (axios#11038 — useEntityRestURL.ts massages baseURL itself). @datadog/browser-rum 7.6.1 → 7.7.0 also ships to browsers.

The good news: no stealth majors (nothing on a 0.x line) and no range widening — 40 of 42 are lockfile-only inside existing carets, with only the harper exact pin and packageManager moving in package.json. And axios raising the form-data floor for GHSA-hmw2-7cc7-3qxx is already covered by the form-data ^4.0.6 override.

Minor and unrelated: e2e/package.json moves packageManager to pnpm 11.19.0 while e2e/Dockerfile still pre-bakes corepack prepare pnpm@11.13.1, which defeats that image's reproducibility intent.

— Reviewed by DAIvid (Claude Opus 5)

Comment thread .nvmrc Outdated
@@ -1 +1 @@
24.18.0
24.18.1

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Worth splitting this one out rather than letting it sit behind the axios break.

Node 24.18.0 → 24.18.1 (here and in e2e/Dockerfile) is an upstream security release — 11 CVEs, 3 High: CVE-2026-56846 and CVE-2026-56848 (http2), CVE-2026-58043 (permission model), plus an undici bump to 7.29.0. Renovate labels it a plain "patch", so nothing in the PR surfaces that.

As batched it can't land until typedAxios.ts is fixed. A standalone PR for the Node pin would land today.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still open at 8596d319, and the case for splitting got stronger.

The bump is no longer the 24.18.1 patch I commented on — renovate re-resolved it to 24.19.0, which its own body table labels minor. typedAxios.ts is untouched and Verify PR still fails on the same single TS2430, so the Node change is still hostage to axios two days on. GitHub has also marked this thread outdated, because renovate rewrote the line it was anchored to.

And e2e/Dockerfile did not follow — it went to 24.18.1-bookworm while this file says 24.19.0. Separate thread there.

A three-line PR setting .nvmrc, the Dockerfile FROM and its leading comment to one version would go green immediately and bank the security content.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Still open at d55f5ba1, third round, and GitHub has now marked this thread outdated a second time for the same reason — renovate rewrote the line it was anchored to. That is the argument in miniature.

Nothing moved: .nvmrc is still 24.19.0, Verify PR still dies on the byte-identical TS2430 in src/config/typedAxios.ts, and that file has not been touched since cc6cd0a2 (2025-12-09). What did move is the batch — 5 files → 13, now including all six deploy workflows and e2e/pnpm-lock.yaml.

So the Node security content has sat behind an unrelated TypeScript error for three days while the thing it is batched with kept growing. A standalone PR for the pins (.nvmrc, the Dockerfile FROM, its corepack prepare pnpm@…, and the stale comment on line 1) is four lines with no lockfile and would go green on the first run.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 95f7d7a to e11fbea Compare August 5, 2026 10:44

@kriszyp kriszyp left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Dispatch codex review (verdict COMMENTS).

🤖 Reviewed with Codex

Comment thread e2e/package.json Outdated
"typescript": "~7.0.0"
},
"packageManager": "pnpm@11.13.1"
"packageManager": "pnpm@11.19.0"

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please update e2e/Dockerfile alongside this pin. It still explicitly prepares pnpm 11.13.1, while this manifest now requests 11.19.0. Corepack will normally honor the nearest packageManager field, but that makes the image prepare/cache one version and then acquire another, undermining the stated reproducibility and adding avoidable setup. The Dockerfile’s first-line Node comment is also still pinned to 24.18.0 after this PR changes the image to 24.18.1.

— KrAIs (Codex)

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 37199ee to 8596d31 Compare August 6, 2026 09:29

@DavidCockerill DavidCockerill left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed at 8596d319. Block stands, and Verify PR is a real break — a rebase won't clear it.

Install dependencies passes on pnpm 11.19.0, so the lockfile resolves cleanly and peer deps are fine. The job then dies at Type-check on one error:

src/config/typedAxios.ts(5,18): error TS2430: Interface 'TypedAxios' incorrectly extends interface 'Axios'.

Cause, confirmed by installing both versions side by side: axios 1.18.1 declares AxiosRequestConfig<D = any> with params?: any; 1.19.0 declares AxiosRequestConfig<D = any, P = any> with params?: P. That any was what let TypedAxios's narrowed overrides pass bivariant parameter checking — with a real type parameter that direction fails, and TS reports the residual mismatch on data.

I tried three shapes under tsc --strict against 1.19.0: threading axios' new P through still fails, dropping the data?: B narrowing still fails, and extends Omit<Axios, 'get'|'delete'|'head'|'options'|'post'|'put'|'patch'|'postForm'|'putForm'|'patchForm'> passes — including the axios.create(...) as TypedAxios cast at src/config/apiClient.ts:11, and with call sites still resolving the generated paths response type. (Caveat: my repro used a synthetic paths type, not the real generated one.)

Worth knowing what this costs: unit tests, lint and Build are all skipped after the type-check failure, so none of the other 168 changed lockfile entries has been validated on this head. renovate/artifacts is separately red, unchanged from last round.

One thing I checked because it looked like a collision and isn't: axios 1.19.0 does not interact with #1598's RFC 9457 error handling. Nothing changed in response-body parsing, transformResponse, responseType, or how response.data is populated on a non-2xx or non-JSON response. The three error-adjacent items land elsewhere — error.message on an otherwise-empty AggregateError, Set serialization in AxiosError.toJSON(), and the params generic (declarations only). #1598's data.title/data.detail reads are safe either way, and there's no file overlap, so merge order doesn't matter.

No hidden majors. Two pre-1.0 packages take semver-breaking steps (@oxc-project/types under oxlint, @datadog/js-core under browser-rum), both transitive and dev/vendor-internal. Worth a look once CI can actually run: vite 8.2.0 dragging rolldown 1.1.5→1.2.2 and dropping the wasm fallback binding, with Build never executed.

Recommendation, same as last round but stronger: split the Node pin out. Details in the threads.

Reviewed by Claude Opus 5 for @DavidCockerill.

Comment thread e2e/Dockerfile
# screenshot baselines are stable and reproducible (generate baselines HERE, not
# on macOS). Multi-arch base — builds natively on Apple Silicon (arm64).
FROM node:24.18.0-bookworm
FROM node:24.18.1-bookworm

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The two Node pins now disagree. This goes to 24.18.1-bookworm, but .nvmrc in the same commit goes to 24.19.0 — renovate lists them as separate entries from two datasources (node-version → minor, docker → patch, with Pending: 24.19.0 on this one).

Merged as-is, the e2e image runs a different Node than local dev and CI, for no reason anybody chose. Worth landing them on the same version.

(The stale pnpm@11.13.1 on line 7 and the stale 24.18.0 in the line-1 comment are already covered by @kriszyp's thread on e2e/package.json:29 — not repeating those, but the same one-line pass fixes all four.)

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from 01780d9 to 3625271 Compare August 7, 2026 05:26

@dawsontoth dawsontoth left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-confirming the block on the current head 3625271d — the rebase since 8596d319 did not clear it, and the diagnosis above still holds exactly.

Local verification with Node 24.18.0, pnpm 11.20.0: pnpm install --frozen-lockfile clean, tsc -b --force fails with the same single error:

src/config/typedAxios.ts(5,18): error TS2430: Interface 'TypedAxios' incorrectly extends interface 'Axios'.

What I can add: the rest of the batch is clean. The open question through the last two rounds has been that CI stops at Type-check, so none of the other bumps have ever been exercised. I ran the batch locally with only axios reverted to 1.18.1 and everything else left at this head:

  • tsc -b --forceexit 0
  • vitest run281/281 test files, 2145 passed | 11 skipped

And with axios back at 1.19.0, the test suite still passes 281/281 — the failure is confined to the type layer. So axios is the sole blocker in a 42-package batch, and the split you recommended is now backed by a green run rather than an assumption. That also means the Node 24.18.1 security pin and the @datadog/browser-rum bump are being gated by one unrelated type error, which is the wrong shape.

Mechanism, confirmed by diffing the two declaration files side by side — it's an arity change, not just a widening:

1.18.1:  get<T = any, R = AxiosResponse<T>,     D = any>(...)
         export interface AxiosRequestConfig<D = any>

1.19.0:  get<T = any, R = AxiosResponseDefault, D = any, P = any>(...): Promise<AxiosResponseResult<T, R, D, P>>
         export interface AxiosRequestConfig<D = any, P = any>

TypedAxios's overrides declare three type parameters (Q, U, R) against a base that now declares four, so TS's positional pairing slides — the error text shows studio's Q being instantiated as the base's P, landing AxiosRequestConfig<D, P> against TypedAxiosRequestConfig<P, never> and failing on data. That's also why the two obvious minimal fixes don't work: I tried TypedAxiosRequestConfig<Q, B> extends AxiosRequestConfig<B, Q> (threading the query type into axios' new P slot, which reads like the semantically right move since P is the params generic) and it produces the identical error. Consistent with the three shapes already tried above — the extends Omit<Axios, ...> approach looks like the one that actually sidesteps the pairing problem, since it stops asking TS to reconcile the two signatures at all.

Not something Renovate can resolve on its own: this needs the typedAxios.ts migration as its own PR, with axios held out of the non-major group until it lands.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 3625271 to d55f5ba Compare August 7, 2026 10:44

@DavidCockerill DavidCockerill left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Round 3 at d55f5ba1. Nothing that mattered changed — but what did change strengthens the case for splitting.

src/config/typedAxios.ts isn't in the diff at all; last touched cc6cd0a2, 2025-12-09. So Verify PR still dies at Type-check on the byte-identical TS2430, and unit tests, lint and Build are all still skipped — leaving all 187 changed package entries unvalidated for a third round. axios is unchanged at 1.18.1 → 1.19.0 and still in the batch.

Recapping the cause once, since it's the whole blocker: axios 1.18.1 declares AxiosRequestConfig<D = any> with params?: any; 1.19.0 declares AxiosRequestConfig<D = any, P = any> with params?: P. The any is what let TypedAxios's narrowed overrides pass bivariant parameter checking. I tested three shapes under tsc --strict against 1.19.0: threading axios' new P through fails, dropping the data?: B narrowing fails, and extends Omit<Axios, 'get'|'delete'|'head'|'options'|'post'|'put'|'patch'|'postForm'|'putForm'|'patchForm'> passes — including the axios.create(...) as TypedAxios cast at src/config/apiClient.ts:11.

Three things are new, and all three argue the same way:

  1. The batch grew 5 → 13 files, adding seven GitHub Actions workflows — including all six deploy workflows — for pnpm/action-setup v6.0.9 → v6.0.10. I dereferenced the annotated tag and the pinned SHA is genuine, so that one's verified clean.
  2. e2e/pnpm-lock.yaml joined, carrying playwright 1.61.1 → 1.62.1. The e2e Dockerfile's own comment ties system deps to the resolved Playwright version "so screenshot baselines are stable and reproducible" — and there is no e2e workflow in .github/workflows/, so no CI job will ever exercise it.
  3. Renovate half-applied @kriszyp's corepack fix: e2e/package.json went to pnpm@11.20.0 while e2e/Dockerfile:7 still prepares 11.13.1. A reviewer's fix produced a second pin mismatch. Thread below.

The Node pins still disagree at exactly the same two values — .nvmrc 24.19.0 vs e2e/Dockerfile 24.18.1-bookworm — and my .nvmrc thread has now been marked outdated a second time, because renovate rewrote the line it was anchored to. Per-line review doesn't durably hold a finding on this PR, which is itself part of the argument.

One improvement: renovate/artifacts, red in rounds 1 and 2, is green now. No majors anywhere across 187 entries; three pre-1.0 transitives take semver-breaking steps, all dev-only or Radix-internal. No react, react-dom, react-query, typescript, or auth/crypto library in the batch.

Recommendation, third time and now empirical rather than stylistic: split the four runtime-pin lines.nvmrc, the Dockerfile FROM, its corepack prepare pnpm@…, and its stale leading comment. Four lines, no lockfile, green on the first run, and it banks Node security content that has been stuck behind a TypeScript error in an unrelated file since 2026-08-04. Optionally split axios out too, so the ~185 bulk bumps can land on a green build — the difference between one blocked PR and one blocked line.

Reviewed by Claude Opus 5 for @DavidCockerill.

Comment thread e2e/Dockerfile
FROM node:24.18.0-bookworm
FROM node:24.18.1-bookworm

RUN corepack enable && corepack prepare pnpm@11.13.1 --activate

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is the other half of @kriszyp's #discussion_r3720046292 — and renovate applying only one side has made the gap wider, not narrower.

e2e/package.json moved to pnpm@11.20.0 in this same commit; this line still prepares 11.13.1. Corepack honours the nearest packageManager field, so the baked version is dead weight at best and a fetch-at-runtime — or a failure in an offline build — at worst, which is exactly the point kriszyp raised.

While this line is being fixed, two more in the same window are stale:

  • line 1 still says Node pinned to the repo's .nvmrc (24.18.0) — wrong against both the FROM (24.18.1) and .nvmrc (24.19.0)
  • line 5, the Node divergence, is #discussion_r3729774054

All four are the standalone-PR candidate described on .nvmrc. Credit to kriszyp for catching the corepack half first.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 750560f to 18ea117 Compare August 7, 2026 22:43
@renovate renovate Bot changed the title chore(deps): update all non-major dependencies fix(deps): update all non-major dependencies Aug 7, 2026
@renovate

renovate Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml
? Verifying lockfile against supply-chain policies (1652 entries)...
✓ Lockfile passes supply-chain policies (1652 entries in 15.9s)
Progress: resolved 1, reused 0, downloaded 0, added 0
Progress: resolved 67, reused 0, downloaded 0, added 0
Progress: resolved 77, reused 0, downloaded 0, added 0
Progress: resolved 81, reused 0, downloaded 0, added 0
Progress: resolved 84, reused 0, downloaded 0, added 0
Progress: resolved 326, reused 0, downloaded 0, added 0
Progress: resolved 436, reused 0, downloaded 0, added 0
Progress: resolved 485, reused 0, downloaded 0, added 0
Progress: resolved 562, reused 0, downloaded 0, added 0
Progress: resolved 851, reused 0, downloaded 0, added 0
Progress: resolved 911, reused 0, downloaded 0, added 0
Progress: resolved 1031, reused 0, downloaded 0, added 0
Progress: resolved 1043, reused 0, downloaded 0, added 0
Progress: resolved 1051, reused 0, downloaded 0, added 0
Progress: resolved 1181, reused 0, downloaded 0, added 0
Progress: resolved 1356, reused 0, downloaded 0, added 0
Progress: resolved 1509, reused 0, downloaded 0, added 0
Progress: resolved 1531, reused 0, downloaded 0, added 0
Progress: resolved 1538, reused 0, downloaded 0, added 0
Progress: resolved 1613, reused 0, downloaded 0, added 0
[ERR_PNPM_UNUSED_PATCH] The following patches were not used: @tanstack/router-core@1.171.15

Either remove them from "patchedDependencies" or update them to match packages in your dependencies.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants