Skip to content

chore(deps): bump the frontend-npm group across 1 directory with 14 updates - #1459

Draft
dependabot[bot] wants to merge 9 commits into
developfrom
dependabot/npm_and_yarn/frontend/frontend-npm-2ebebc913d
Draft

chore(deps): bump the frontend-npm group across 1 directory with 14 updates#1459
dependabot[bot] wants to merge 9 commits into
developfrom
dependabot/npm_and_yarn/frontend/frontend-npm-2ebebc913d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Current authority — 2026-09-09

  • exact head: 65b60df44a224ba817af1bc8def34db93ae4b614
  • protected base adopted by ordinary ancestry repair: develop@042b0c70531b229af3acbd0421a2f23098d848b3
  • lifecycle: Draft / stale-base ancestry repaired / frontend security RED source-fixed / one-shot repair workflow self-removed / PR-triggered hosted workflows require action / fix(deps): patch frontend audit security floors #1623 narrow protected-base prerequisite source+security GREEN but shared required gates non-passing / not merge-authorized

Non-force ancestry repair

The Dependabot lane was originally based on 81c105645ca6e680f5f8c15ba9c33b67eb63c48b, 65 protected commits behind live develop. Ordinary two-parent commit 628528e470aa742eacf714a1381f120a14add84a preserves prior #1459 provenance and adopts protected develop@042b0c70531b229af3acbd0421a2f23098d848b3 without force-push or destructive rebase.

Security RED and repair

Trivy evidence from #1621 run 34300562474, job 102306568194, identified two CRITICAL Next.js findings (CVE-2026-75604, GHSA-2xp9-vwfh-vxw4) and one HIGH sharp finding (GHSA-rgj7-g3m4-5g8c) in this group when it still held Next.js 16.3.1 and sharp 0.35.0.

Test-first commit c8a95f54ad3d277a74768aba33ed14d729bc258d added the first security-floor regression. The one-shot source-fix workflow initially failed because actions/setup-node requested pnpm caching before pnpm existed. Exact child 2565ea931abd84d1c0f42df9a88ca1c27a88ef04 repaired that causal ordering issue. The next source-fix execution succeeded and produced ordinary child 65b60df44a224ba817af1bc8def34db93ae4b614 (fix(deps): patch Next.js and sharp security floors). That commit:

  • updates Next.js + eslint-config-next to 16.3.4,
  • updates the sharp override and generated lock to 0.35.4,
  • preserves the broader dependency-group updates,
  • removes .github/workflows/repair-frontend-security-lock.yml in the same commit after its purpose completed.

The resulting tree is 57c446c61e2c52bed1e148f850a8dab605704a19; the temporary source-fix workflow is absent from the current head.

Hosted verification boundary

The current head's PR-triggered Application CI, Bandit, Semgrep, Security, CodeQL PR and Docker workflow runs terminated as action_required without jobs. This is not GREEN evidence and must not be treated as a source failure or silently bypassed. Until the required action is satisfied and the unchanged exact head gets an executable hosted matrix, this broad group is not merge-authorized.

#1623 has since advanced by ordinary RED→GREEN repair to exact e8a54fc5156ac3ffbb79bc8418c5125d7dcdea60. Its predecessor security regression had two valid Codex P2 gaps: it did not structurally bind the root importer/override/snapshot graph, and it did not reject every below-floor next@/sharp@ lock entry. RED a5abe047d318477b64c62cdbee5b737aad8054f0 reproduced both false-negative classes; GREEN e8a54fc... now parses the pnpm lock structurally and enforces all Next.js entries >=16.3.3, all sharp entries >=0.35.4, exact Next.js/eslint-config-next importer identity, referenced snapshots and the reviewed sharp override.

On that exact #1623 head, Application CI 34308232588, Bandit 34308232672, Semgrep 34308232582, Security Scan 34308232578, Docker 34308232872, coverage evidence/source-tree and direct GitHub Advanced Security CodeQL analyses are terminal GREEN. Formal CodeRabbit review PRR_kwDOSNjZ2s8AAAABMvBEOg is APPROVED on exact e8a54fc...; its two original Codex P2 threads are resolved/outdated.

#1623 is still not merge-authorized because shared required OpenCode and CodeQL compatibility contexts failed, Noema run 34308231412 / job 102329519489 failed after a ready orchestrator/free preflight with HTTP 429 after 214.0s, and Strix remains non-terminal. The Noema owner reproduction is on contextual-orchestrator#1106 comment 5595655747 and consumer cleanup on .github#2042 comment 5595656784.

Succession rule

Treat #1623 as the canonical narrow protected-base prerequisite and this PR as its broader successor. Once #1623 normally integrates, #1459 must ordinary-adopt #1623's exact structural security lineage or the resulting protected integration before the remaining group dependency updates are evaluated. This branch must never downgrade Next.js/sharp below the reviewed floors and must not revert the stricter structural regression back to the older literal-only test. Do not close either lane merely because their dependency deltas overlap.

Primary references:

Merge boundary

Keep Draft until #1623's prerequisite normally integrates or this branch ordinary-adopts the same exact structural security lineage, this broad group receives a full executable product/build/security matrix GREEN on one unchanged exact head, all then-live required contexts are terminal-success, and qualifying independent approval is post-last-push.

No manifest-only stale-lock edit, hand-written integrity/platform records, force-push, destructive rebase, self-approval, failure-as-flake waiver, dummy/no-op requeue, synthetic status, admin bypass, or gate weakening.

…pdates

Bumps the frontend-npm group with 14 updates in the /frontend directory:

| Package | From | To |
| --- | --- | --- |
| [@base-ui/react](https://github.com/mui/base-ui/tree/HEAD/packages/react) | `1.6.0` | `1.7.0` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.27.0` | `1.33.0` |
| [next](https://github.com/vercel/next.js) | `16.2.12` | `16.3.1` |
| [react-resizable-panels](https://github.com/bvaughn/react-resizable-panels) | `4.12.2` | `4.12.3` |
| [uuid](https://github.com/uuidjs/uuid) | `14.0.1` | `14.0.2` |
| [vis-network](https://github.com/visjs/vis-network) | `10.1.0` | `10.1.2` |
| [@playwright/test](https://github.com/microsoft/playwright) | `1.62.0` | `1.62.1` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.2` | `26.2.0` |
| [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react) | `19.2.17` | `19.2.18` |
| [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `19.2.3` | `19.2.4` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `4.1.10` | `4.1.11` |
| [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.2.12` | `16.3.1` |
| [postcss](https://github.com/postcss/postcss) | `8.5.24` | `8.5.26` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.10` | `4.1.11` |



Updates `@base-ui/react` from 1.6.0 to 1.7.0
- [Release notes](https://github.com/mui/base-ui/releases)
- [Changelog](https://github.com/mui/base-ui/blob/master/CHANGELOG.md)
- [Commits](https://github.com/mui/base-ui/commits/v1.7.0/packages/react)

Updates `lucide-react` from 1.27.0 to 1.33.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.33.0/packages/lucide-react)

Updates `next` from 16.2.12 to 16.3.1
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.2.12...v16.3.1)

Updates `react-resizable-panels` from 4.12.2 to 4.12.3
- [Release notes](https://github.com/bvaughn/react-resizable-panels/releases)
- [Changelog](https://github.com/bvaughn/react-resizable-panels/blob/main/CHANGELOG.md)
- [Commits](bvaughn/react-resizable-panels@4.12.2...4.12.3)

Updates `uuid` from 14.0.1 to 14.0.2
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v14.0.1...v14.0.2)

Updates `vis-network` from 10.1.0 to 10.1.2
- [Release notes](https://github.com/visjs/vis-network/releases)
- [Changelog](https://github.com/visjs/vis-network/blob/master/HISTORY.md)
- [Commits](visjs/vis-network@v10.1.0...v10.1.2)

Updates `@playwright/test` from 1.62.0 to 1.62.1
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.62.0...v1.62.1)

Updates `@types/node` from 26.1.2 to 26.2.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@types/react` from 19.2.17 to 19.2.18
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `@types/react-dom` from 19.2.3 to 19.2.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom)

Updates `@vitest/coverage-v8` from 4.1.10 to 4.1.11
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/coverage-v8)

Updates `eslint-config-next` from 16.2.12 to 16.3.1
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.1/packages/eslint-config-next)

Updates `postcss` from 8.5.24 to 8.5.26
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.24...8.5.26)

Updates `vitest` from 4.1.10 to 4.1.11
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest)

---
updated-dependencies:
- dependency-name: "@base-ui/react"
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: frontend-npm
- dependency-name: lucide-react
  dependency-version: 1.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: frontend-npm
- dependency-name: next
  dependency-version: 16.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: frontend-npm
- dependency-name: react-resizable-panels
  dependency-version: 4.12.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
- dependency-name: uuid
  dependency-version: 14.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
- dependency-name: vis-network
  dependency-version: 10.1.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
- dependency-name: "@playwright/test"
  dependency-version: 1.62.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
- dependency-name: "@types/node"
  dependency-version: 26.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: frontend-npm
- dependency-name: "@types/react"
  dependency-version: 19.2.18
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
- dependency-name: "@types/react-dom"
  dependency-version: 19.2.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 4.1.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
- dependency-name: eslint-config-next
  dependency-version: 16.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: frontend-npm
- dependency-name: postcss
  dependency-version: 8.5.26
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
- dependency-name: vitest
  dependency-version: 4.1.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 24, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner August 24, 2026 03:00
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 24, 2026
devin-ai-integration[bot]

This comment was marked as resolved.

@github-actions

github-actions Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 3edb8320b0288f2bba54ce7e28083164e0d51966:

  • Branch is BEHIND the base branch; update the branch and re-run checks.
  • Required check strix is FAILURE on the current head.

devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae

Copy link
Copy Markdown
Contributor

Exact-head remediation for 3edb8320b0288f2bba54ce7e28083164e0d51966:

Root cause of the hosted failures was the unupdated frontend/pnpm-workspace.yaml override: package.json and the lockfile requested PostCSS 8.5.26, while pnpm applied workspace override 8.5.24, so frozen installs failed before build. The workspace override and two lock/security contract tests now use 8.5.26.

Validation: pnpm@11.5.3 install --frozen-lockfile --ignore-scripts; frontend 435 passed, lint, typecheck, and production build; backend 1786 passed, 32 skipped; targeted dependency/security contracts 2 passed; ruff check backend; and git diff --check. The earlier hosted Strix failure remains provider-side NVIDIA 429/direct-provider evidence and is not treated as a source pass.

@seonghobae

Copy link
Copy Markdown
Contributor

Disposition for the two current informational review threads on 3edb8320b0288f2bba54ce7e28083164e0d51966: the vis-network note is cosmetic and the resolved lock is 10.1.2; the .pnpmfile.cjs exception is intentionally pinned to the reviewed PostCSS 8.5.26 contract so a future security-floor change must update the hook and lock together. The actual frozen-install defect was the workspace override, now fixed and covered by the passing install/build evidence.

@seonghobae

Copy link
Copy Markdown
Contributor

Exact-head Checks RCA: strix failed on provider infrastructure, not a source finding. The run records NVIDIA NIM HTTP 429 rate-limit responses, then a configured openai-direct/gpt-5.6-luna fallback HTTP 404; the gate correctly failed closed with no structured vulnerability report. This requires central provider/fallback remediation and a fresh exact-head scan; no source patch was applied to this dependency-only PR.

@seonghobae

seonghobae commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Strix failure triage for current head 3edb8320b0288f2bba54ce7e28083164e0d51966: the job log shows NVIDIA NIM 429 Too Many Requests, then fallback openai-direct/gpt-5.6-luna 404 page not found; the gate explicitly classified this as provider infrastructure unavailable with no authoritative report artifact. No source finding was emitted. Re-ran failed jobs through the Actions API; merge remains blocked until an exact-head authoritative Strix result and required review are available.

@seonghobae seonghobae added maintenance priority: medium Normal-priority or P2 work labels Sep 7, 2026 — with ChatGPT Codex Connector

Copy link
Copy Markdown
Contributor

Fresh security-owner handoff from exact Naruon PR validation on 2026-09-09.

Security Scan run 34300562474, Trivy job 102306568194, checked out exact 12d8cac36562b27c9f23e10eb4e75fbf6535e9be and failed closed on three frontend lockfile findings inherited from the shared dependency tree:

This frontend dependency lane currently proposes next / eslint-config-next only through 16.3.1, which is no longer an adequate security target. Current upstream advisories patch both critical Next.js issues at 16.3.3; sharp's reviewed advisory patches <0.35.4 at 0.35.4 and was updated 2026-09-08.

Primary advisories:

Please treat the next ordinary source successor here (or a clearly designated security-only dependency successor) as requiring at least next + eslint-config-next 16.3.3 and a lock resolution with sharp >=0.35.4, then re-run the full frontend build/tests plus current Trivy against the exact head. Do not represent 16.3.1 as closing these findings. The Docker-concurrency descendant that exposed this fresh scan will not absorb frontend dependency ownership into its two-file CI delta.

Adopt the current protected develop head as an ordinary second parent while preserving only the six effective frontend dependency/provenance files from the existing Dependabot lane. The protected delta since the old merge base does not overlap those six files, so this avoids dropping 65 protected commits without force-push or destructive rebase.

This is ancestry repair only. It intentionally does not claim the current next 16.3.1 / sharp 0.35.0 dependency set is security-complete; current Trivy evidence requires a patched Next.js release and sharp >=0.35.4 before merge.
@seonghobae
seonghobae marked this pull request as draft September 9, 2026 02:47

Copy link
Copy Markdown
Contributor

#1623 prerequisite advanced by ordinary RED→GREEN repair after two valid Codex P2 findings. Current exact prerequisite head is e8a54fc5156ac3ffbb79bc8418c5125d7dcdea60 (RED a5abe047d318477b64c62cdbee5b737aad8054f0). The new structural regression parses pnpm-lock.yaml, binds root Next.js / eslint-config-next importer specifier+resolved version to the reviewed manifests and exact snapshot keys, binds lock overrides.sharp to the workspace override, and rejects every next@ / sharp@ key below 16.3.3 / 0.35.4 across both packages and snapshots. Both predecessor review threads are source-addressed and resolved.

Do not treat #1459's overlapping 16.3.4/0.35.4 manifest/lock values as full succession of this new test contract. Keep #1459 as the broader successor; after #1623 normally integrates, ordinary-adopt e8a54fc... or the protected integration before evaluating the remaining dependency-group delta. Fresh #1623 exact-head workflows are executing, so this is a source-lineage handoff, not merge evidence.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code maintenance priority: medium Normal-priority or P2 work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant