Skip to content

chore(deps): refresh packages, Node 24.21, and security overrides - #166

Merged
95gabor merged 1 commit into
mainfrom
cursor/ecosystem-security-updates-ad5b
Sep 14, 2026
Merged

95gabor merged 1 commit into
mainfrom
cursor/ecosystem-security-updates-ad5b

Conversation

@cursor

@cursor cursor Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

Summary

Weekly dependency/security maintenance (2026-09-14).

Package updates

  • next / eslint-config-next 16.3.4 → 16.3.5
  • react / react-dom 19.2.8 → 19.3.0
  • @types/react / @types/react-dom → 19.3.0
  • @supabase/supabase-js 2.115.0 → 2.116.0
  • next-intl 4.14.2 → 4.14.4
  • lucide-react 1.41.0 → 1.45.0
  • tailwind-merge 3.6.0 → 3.7.0
  • @percy/cli 1.32.8 → 1.32.9
  • lint-staged 17.5.0 → 17.5.1
  • supabase 2.116.0 → 2.117.0
  • yaml 2.9.0 → 2.9.1
  • @types/node 24.13.3 → 24.13.4 (stays on Node 24 types)
  • pnpm 12.3.4 → 12.4.1

Runtime / Docker

  • Node LTS pin: 24.20.0 → 24.21.0 (.nvmrc, engines, node-bootstrap, Dockerfile node:24.21.0-alpine3.24)
  • nginx unchanged: 1.31.5-alpine3.24-slim (latest)

Security overrides

  • Added: js-yaml@4.3.2 (GHSA-2883-xcg3-v3hh), adm-zip@0.6.1 (GHSA-vwc7-r8mq-g2x9)
  • Kept: browserslist@4.28.9, fast-uri@3.1.7, fast-xml-parser@5.11.1, uuid@11.1.1 (still required after refresh)
  • pnpm audit: clean

Held majors (intentional)

  • ESLint 9 (not 10), TypeScript 6 (not 7), @types/node 24 (not 26), Node 24 LTS (not 26 Current)

GitHub Actions

Already on latest major pins (checkout/setup-node/upload-artifact v7, Pages v5/v6, Docker v4/v6/v7, treosh/lighthouse-ci-action v12). No workflow changes needed.

Validation

  • pnpm install --frozen-lockfile
  • pnpm audit — no known vulnerabilities
  • pnpm run lint — pass (existing warnings only)
  • pnpm run typecheck — pass
  • Build/Docker not run here (no Supabase env / Docker in this runner)

Superseded Dependabot PRs (please close)

(gh is read-only in this automation, so these could not be closed automatically.)

Open in Web View Automation 

Bump runtime/tooling pins and patch audit findings via overrides for
js-yaml and adm-zip while keeping ESLint 9 / TypeScript 6 / Node 24.
@coderabbitai

coderabbitai Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 99d82a21-b03c-40b0-aa41-d55a6ea29b34

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Lighthouse results

URL Performance Accessibility Best Practices SEO
http://127.0.0.1:4173/ 66% 99% 96% 100%

Updated automatically by CI.

@95gabor
95gabor marked this pull request as ready for review September 14, 2026 07:28
@github-actions

Copy link
Copy Markdown

Latest full-page screenshot

Full-page PR screenshot

github-actions Bot added a commit that referenced this pull request Sep 14, 2026
@95gabor
95gabor merged commit 726bb37 into main Sep 14, 2026
21 checks passed
@95gabor
95gabor deleted the cursor/ecosystem-security-updates-ad5b branch September 14, 2026 08:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants