chore(deps): bump the frontend-npm group across 1 directory with 14 updates - #1459
chore(deps): bump the frontend-npm group across 1 directory with 14 updates#1459dependabot[bot] wants to merge 9 commits into
Conversation
…pdates Bumps the frontend-npm group with 14 updates in the /frontend directory: | Package | From | To | | --- | --- | --- | | [@base-ui/react](https://github.com/mui/base-ui/tree/HEAD/packages/react) | `1.6.0` | `1.7.0` | | [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.27.0` | `1.33.0` | | [next](https://github.com/vercel/next.js) | `16.2.12` | `16.3.1` | | [react-resizable-panels](https://github.com/bvaughn/react-resizable-panels) | `4.12.2` | `4.12.3` | | [uuid](https://github.com/uuidjs/uuid) | `14.0.1` | `14.0.2` | | [vis-network](https://github.com/visjs/vis-network) | `10.1.0` | `10.1.2` | | [@playwright/test](https://github.com/microsoft/playwright) | `1.62.0` | `1.62.1` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.2` | `26.2.0` | | [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react) | `19.2.17` | `19.2.18` | | [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `19.2.3` | `19.2.4` | | [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `4.1.10` | `4.1.11` | | [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.2.12` | `16.3.1` | | [postcss](https://github.com/postcss/postcss) | `8.5.24` | `8.5.26` | | [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.10` | `4.1.11` | Updates `@base-ui/react` from 1.6.0 to 1.7.0 - [Release notes](https://github.com/mui/base-ui/releases) - [Changelog](https://github.com/mui/base-ui/blob/master/CHANGELOG.md) - [Commits](https://github.com/mui/base-ui/commits/v1.7.0/packages/react) Updates `lucide-react` from 1.27.0 to 1.33.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.33.0/packages/lucide-react) Updates `next` from 16.2.12 to 16.3.1 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v16.2.12...v16.3.1) Updates `react-resizable-panels` from 4.12.2 to 4.12.3 - [Release notes](https://github.com/bvaughn/react-resizable-panels/releases) - [Changelog](https://github.com/bvaughn/react-resizable-panels/blob/main/CHANGELOG.md) - [Commits](bvaughn/react-resizable-panels@4.12.2...4.12.3) Updates `uuid` from 14.0.1 to 14.0.2 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v14.0.1...v14.0.2) Updates `vis-network` from 10.1.0 to 10.1.2 - [Release notes](https://github.com/visjs/vis-network/releases) - [Changelog](https://github.com/visjs/vis-network/blob/master/HISTORY.md) - [Commits](visjs/vis-network@v10.1.0...v10.1.2) Updates `@playwright/test` from 1.62.0 to 1.62.1 - [Release notes](https://github.com/microsoft/playwright/releases) - [Commits](microsoft/playwright@v1.62.0...v1.62.1) Updates `@types/node` from 26.1.2 to 26.2.0 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `@types/react` from 19.2.17 to 19.2.18 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react) Updates `@types/react-dom` from 19.2.3 to 19.2.4 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom) Updates `@vitest/coverage-v8` from 4.1.10 to 4.1.11 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/coverage-v8) Updates `eslint-config-next` from 16.2.12 to 16.3.1 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](https://github.com/vercel/next.js/commits/v16.3.1/packages/eslint-config-next) Updates `postcss` from 8.5.24 to 8.5.26 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.24...8.5.26) Updates `vitest` from 4.1.10 to 4.1.11 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest) --- updated-dependencies: - dependency-name: "@base-ui/react" dependency-version: 1.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: frontend-npm - dependency-name: lucide-react dependency-version: 1.33.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: frontend-npm - dependency-name: next dependency-version: 16.3.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: frontend-npm - dependency-name: react-resizable-panels dependency-version: 4.12.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: frontend-npm - dependency-name: uuid dependency-version: 14.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: frontend-npm - dependency-name: vis-network dependency-version: 10.1.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: frontend-npm - dependency-name: "@playwright/test" dependency-version: 1.62.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: frontend-npm - dependency-name: "@types/node" dependency-version: 26.2.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: frontend-npm - dependency-name: "@types/react" dependency-version: 19.2.18 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: frontend-npm - dependency-name: "@types/react-dom" dependency-version: 19.2.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: frontend-npm - dependency-name: "@vitest/coverage-v8" dependency-version: 4.1.11 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: frontend-npm - dependency-name: eslint-config-next dependency-version: 16.3.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: frontend-npm - dependency-name: postcss dependency-version: 8.5.26 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: frontend-npm - dependency-name: vitest dependency-version: 4.1.11 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: frontend-npm ... Signed-off-by: dependabot[bot] <support@github.com>
|
PR governance metadata gate is not ready for
|
|
Exact-head remediation for Root cause of the hosted failures was the unupdated Validation: |
|
Disposition for the two current informational review threads on |
|
Exact-head Checks RCA: |
|
Strix failure triage for current head |
|
Fresh security-owner handoff from exact Naruon PR validation on 2026-09-09. Security Scan run
This frontend dependency lane currently proposes Primary advisories: Please treat the next ordinary source successor here (or a clearly designated security-only dependency successor) as requiring at least |
Adopt the current protected develop head as an ordinary second parent while preserving only the six effective frontend dependency/provenance files from the existing Dependabot lane. The protected delta since the old merge base does not overlap those six files, so this avoids dropping 65 protected commits without force-push or destructive rebase. This is ancestry repair only. It intentionally does not claim the current next 16.3.1 / sharp 0.35.0 dependency set is security-complete; current Trivy evidence requires a patched Next.js release and sharp >=0.35.4 before merge.
|
#1623 prerequisite advanced by ordinary RED→GREEN repair after two valid Codex P2 findings. Current exact prerequisite head is Do not treat #1459's overlapping 16.3.4/0.35.4 manifest/lock values as full succession of this new test contract. Keep #1459 as the broader successor; after #1623 normally integrates, ordinary-adopt |
Current authority — 2026-09-09
65b60df44a224ba817af1bc8def34db93ae4b614develop@042b0c70531b229af3acbd0421a2f23098d848b3Non-force ancestry repair
The Dependabot lane was originally based on
81c105645ca6e680f5f8c15ba9c33b67eb63c48b, 65 protected commits behind livedevelop. Ordinary two-parent commit628528e470aa742eacf714a1381f120a14add84apreserves prior #1459 provenance and adopts protecteddevelop@042b0c70531b229af3acbd0421a2f23098d848b3without force-push or destructive rebase.Security RED and repair
Trivy evidence from #1621 run
34300562474, job102306568194, identified two CRITICAL Next.js findings (CVE-2026-75604,GHSA-2xp9-vwfh-vxw4) and one HIGH sharp finding (GHSA-rgj7-g3m4-5g8c) in this group when it still held Next.js16.3.1and sharp0.35.0.Test-first commit
c8a95f54ad3d277a74768aba33ed14d729bc258dadded the first security-floor regression. The one-shot source-fix workflow initially failed becauseactions/setup-noderequested pnpm caching before pnpm existed. Exact child2565ea931abd84d1c0f42df9a88ca1c27a88ef04repaired that causal ordering issue. The next source-fix execution succeeded and produced ordinary child65b60df44a224ba817af1bc8def34db93ae4b614(fix(deps): patch Next.js and sharp security floors). That commit:eslint-config-nextto16.3.4,0.35.4,.github/workflows/repair-frontend-security-lock.ymlin the same commit after its purpose completed.The resulting tree is
57c446c61e2c52bed1e148f850a8dab605704a19; the temporary source-fix workflow is absent from the current head.Hosted verification boundary
The current head's PR-triggered Application CI, Bandit, Semgrep, Security, CodeQL PR and Docker workflow runs terminated as
action_requiredwithout jobs. This is not GREEN evidence and must not be treated as a source failure or silently bypassed. Until the required action is satisfied and the unchanged exact head gets an executable hosted matrix, this broad group is not merge-authorized.#1623 has since advanced by ordinary RED→GREEN repair to exact
e8a54fc5156ac3ffbb79bc8418c5125d7dcdea60. Its predecessor security regression had two valid Codex P2 gaps: it did not structurally bind the root importer/override/snapshot graph, and it did not reject every below-floornext@/sharp@lock entry. REDa5abe047d318477b64c62cdbee5b737aad8054f0reproduced both false-negative classes; GREENe8a54fc...now parses the pnpm lock structurally and enforces all Next.js entries>=16.3.3, all sharp entries>=0.35.4, exact Next.js/eslint-config-next importer identity, referenced snapshots and the reviewed sharp override.On that exact #1623 head, Application CI
34308232588, Bandit34308232672, Semgrep34308232582, Security Scan34308232578, Docker34308232872, coverage evidence/source-tree and direct GitHub Advanced Security CodeQL analyses are terminal GREEN. Formal CodeRabbit reviewPRR_kwDOSNjZ2s8AAAABMvBEOgis APPROVED on exacte8a54fc...; its two original Codex P2 threads are resolved/outdated.#1623 is still not merge-authorized because shared required OpenCode and CodeQL compatibility contexts failed, Noema run
34308231412/ job102329519489failed after a readyorchestrator/freepreflight with HTTP 429 after 214.0s, and Strix remains non-terminal. The Noema owner reproduction is on contextual-orchestrator#1106 comment5595655747and consumer cleanup on.github#2042comment5595656784.Succession rule
Treat #1623 as the canonical narrow protected-base prerequisite and this PR as its broader successor. Once #1623 normally integrates, #1459 must ordinary-adopt #1623's exact structural security lineage or the resulting protected integration before the remaining group dependency updates are evaluated. This branch must never downgrade Next.js/sharp below the reviewed floors and must not revert the stricter structural regression back to the older literal-only test. Do not close either lane merely because their dependency deltas overlap.
Primary references:
Merge boundary
Keep Draft until #1623's prerequisite normally integrates or this branch ordinary-adopts the same exact structural security lineage, this broad group receives a full executable product/build/security matrix GREEN on one unchanged exact head, all then-live required contexts are terminal-success, and qualifying independent approval is post-last-push.
No manifest-only stale-lock edit, hand-written integrity/platform records, force-push, destructive rebase, self-approval, failure-as-flake waiver, dummy/no-op requeue, synthetic status, admin bypass, or gate weakening.