Skip to content

Update npm dependencies and pin eslint-plugin-react-hooks via pnpm over… - #106

Open
buildcanada-fabro[bot] wants to merge 11 commits into
mainfrom
fabro/run/01M3AM0MMWXN5W6Y5BJ82P3FJY
Open

buildcanada-fabro[bot] wants to merge 11 commits into
mainfrom
fabro/run/01M3AM0MMWXN5W6Y5BJ82P3FJY

Conversation

@buildcanada-fabro

Copy link
Copy Markdown

Refreshes the dependency tree (package.json + pnpm-lock.yaml) with all updates that were verified to build and pass lint/tests. Also adds a pnpm overrides entry pinning eslint-config-next > eslint-plugin-react-hooks to 7.0.1 to resolve a version mismatch pulled in transitively by eslint-config-next@16.1.7.

Notable version bumps

  • next 16.1.6 → 16.1.7, eslint-config-next 16.1.6 → 16.1.7, next-auth 4.24.13 → 4.24.15
  • jose ^5.9.6 → ^6.2.12
  • openai ^5.15.0 → ^7.20.0
  • three / @types/three ^0.185.1 → ^0.186.0
  • @types/node ^20 → ^26.6.2
  • tsx unpinned range → pinned 4.21.0
  • Wide refresh of transitive deps (Radix UI primitives, PostHog SDKs, Tailwind/oxide binaries, Babel toolchain, @react-three/*, etc.)

These were bundled together because they built cleanly and had no breaking API usage detected in this codebase. Any major upgrade found to actually change API surface used here is tracked separately via its own issue rather than included in this batch.

Fabro Details

Ran 9 stages in 58m 14s for $0.61
Stage Duration Cost Retries
start 0s – 0
toolchain 1s – 0
baseline 2m 24s – 0
discover 13s – 0
triage 22m 19s $0.30 0
apply 4m 42s $0.03 0
verify 4m 2s – 0
fixup 9m 15s $0.04 0
report 14m 58s $0.24 0
Total 58m 14s $0.61 0
Ran DependencyUpdate.fabro (10 nodes and 11 edges)
digraph DependencyUpdate {
    graph [
        goal="Update the repository's npm dependencies: group every safe update into one verified pull request, and file an issue for each major upgrade that changes API surface this codebase uses.",
        model_stylesheet="
            * { model: gpt-6-luna; reasoning_effort: high; }
        ",
        stall_timeout="3600s",
        on_failure="exit"
    ]
    // on_failure=exit: a failed stage ends the run as failed instead of
    // falling through to the next unconditional edge. Only verify routes
    // its failure onward (to fixup).
    rankdir=LR

    start [shape=Mdiamond, label="Start"]
    exit  [shape=Msquare, label="Exit"]

    // ---- Preflight: the baseline must be green before anything changes ----
    toolchain [label="Toolchain", shape=parallelogram, max_retries=1,
        script="set -e; mkdir -p /tmp/deps; corepack enable >/dev/null 2>&1 || true; test -f pnpm-lock.yaml || { echo 'no pnpm-lock.yaml: this workflow only supports pnpm projects'; exit 1; }; node --version; pnpm --version; git --version; echo toolchain ok"]

    baseline [label="Baseline", shape=parallelogram, max_retries=0, timeout="1800s",
        script="set -eo pipefail; export CI=1 NEXT_TELEMETRY_DISABLED=1; pnpm install --frozen-lockfile 2>&1 | tail -n 40; STEPS=$(node -e 'const s=require(\"./package.json\").scripts||{}; console.log(Object.keys(s).filter(k=>k===\"lint\"||k===\"typecheck\"||/^test(:|$)/.test(k)||k===\"build\").join(\" \"))'); echo \"verify steps: $STEPS\"; for s in $STEPS; do echo \"== pnpm run $s\"; pnpm run $s 2>&1 | tail -n 150; done; echo verify ok"]

    // ---- Discover what is outdated and what npm audit knows ----
    discover [label="Discover", shape=parallelogram, max_retries=1,
        script="set -e; pnpm outdated --format json > /tmp/deps/outdated.json || true; pnpm audit --json > /tmp/deps/audit.json 2>/dev/null || true; node -e 'const o=require(\"/tmp/deps/outdated.json\"); const n=Object.keys(o).length; console.log(n+\" outdated packages\"); for (const [k,v] of Object.entries(o)) console.log(k, v.current, \"->\", v.latest, v.dependencyType||\"\");'; echo; echo '--- audit summary ---'; node -e 'try{const a=require(\"/tmp/deps/audit.json\"); console.log(JSON.stringify(a.metadata&&a.metadata.vulnerabilities||{}));}catch(e){console.log(\"no audit data\")}'"]

    // ---- Triage: group safe updates, isolate real breaking majors ----
    triage [label="Triage", prompt="@prompts/triage.md", timeout="2400s"]

    // ---- Apply approved updates, then verify; fix or drop on failure ----
    // No goal_gate on verify: the "nothing to update" edges must be able
    // to reach exit without triggering it.
    apply [label="Apply", prompt="@prompts/apply.md", timeout="1800s"]

    verify [label="Verify", shape=parallelogram, on_failure="route", max_retries=0, timeout="1800s",
        script="set -eo pipefail; export CI=1 NEXT_TELEMETRY_DISABLED=1; pnpm install --frozen-lockfile 2>&1 | tail -n 40; STEPS=$(node -e 'const s=require(\"./package.json\").scripts||{}; console.log(Object.keys(s).filter(k=>k===\"lint\"||k===\"typecheck\"||/^test(:|$)/.test(k)||k===\"build\").join(\" \"))'); echo \"verify steps: $STEPS\"; for s in $STEPS; do echo \"== pnpm run $s\"; pnpm run $s 2>&1 | tail -n 150; done; echo verify ok"]

    fixup [label="Fix or drop", prompt="@prompts/fixup.md", max_visits=3, timeout="1800s"]

    // ---- Final diff review and PR/issue reporting ----
    report [label="Report", prompt="@prompts/report.md", timeout="1200s"]

    start -> toolchain -> baseline -> discover -> triage
    triage -> apply        [label="Updates available"]
    triage -> exit         [label="Nothing to update"]
    apply -> verify
    verify -> report       [condition="outcome=succeeded"]
    verify -> fixup
    fixup -> verify
    report -> exit
}

⚒️ Generated with Fabro

buildcanada-fabro Bot and others added 9 commits September 24, 2026 21:09
Fabro-Run: 01M3AM0MMWXN5W6Y5BJ82P3FJY
Fabro-Completed: 2

⚒️ Generated with [Fabro](https://fabro.sh)

Co-Authored-By: Fabro <noreply@fabro.sh>
Fabro-Run: 01M3AM0MMWXN5W6Y5BJ82P3FJY
Fabro-Completed: 3

⚒️ Generated with [Fabro](https://fabro.sh)

Co-Authored-By: Fabro <noreply@fabro.sh>
Fabro-Run: 01M3AM0MMWXN5W6Y5BJ82P3FJY
Fabro-Completed: 4

⚒️ Generated with [Fabro](https://fabro.sh)

Co-Authored-By: Fabro <noreply@fabro.sh>
Fabro-Run: 01M3AM0MMWXN5W6Y5BJ82P3FJY
Fabro-Completed: 5

⚒️ Generated with [Fabro](https://fabro.sh)

Co-Authored-By: Fabro <noreply@fabro.sh>
Fabro-Run: 01M3AM0MMWXN5W6Y5BJ82P3FJY
Fabro-Completed: 6

⚒️ Generated with [Fabro](https://fabro.sh)

Co-Authored-By: Fabro <noreply@fabro.sh>
Fabro-Run: 01M3AM0MMWXN5W6Y5BJ82P3FJY
Fabro-Completed: 7

⚒️ Generated with [Fabro](https://fabro.sh)

Co-Authored-By: Fabro <noreply@fabro.sh>
Fabro-Run: 01M3AM0MMWXN5W6Y5BJ82P3FJY
Fabro-Completed: 8

⚒️ Generated with [Fabro](https://fabro.sh)

Co-Authored-By: Fabro <noreply@fabro.sh>
Fabro-Run: 01M3AM0MMWXN5W6Y5BJ82P3FJY
Fabro-Completed: 9

⚒️ Generated with [Fabro](https://fabro.sh)

Co-Authored-By: Fabro <noreply@fabro.sh>
Fabro-Run: 01M3AM0MMWXN5W6Y5BJ82P3FJY
Fabro-Completed: 10

⚒️ Generated with [Fabro](https://fabro.sh)

Co-Authored-By: Fabro <noreply@fabro.sh>
@greptile-apps

greptile-apps Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[High risk] Updates Node runtime version and multiple production dependencies.

The PR appears safe to merge, with the previously noted survey interaction coverage remaining non-blocking feedback.

Fix All in CodexFindings

  1. P2 Survey select lacks interaction coverage ▶
Fix with agent prompt
### Issue 1
pnpm-lock.yaml:undefined-17
This updates the Base UI select used by the voter survey from 1.3.0 to 1.8.0, but there is no component or browser test for choosing an option and submitting its value. The existing build and library tests cannot catch a regression in that survey interaction. Add a focused test for it.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Summary

The PR refreshes npm dependencies, pins the React Hooks ESLint plugin through a pnpm override, and aligns CI and the Docker image on Node 26. The latest change replaces Corepack with a global pnpm installation in the Docker base stage.

Reviews (3) · Last reviewed commit: "Install pnpm without bundled Corepack"

Comment thread package.json
Comment thread pnpm-lock.yaml
importers:

.:
dependencies:
'@base-ui/react':
specifier: ^1.3.0
version: 1.3.0(@types/react@19.2.14)(react-dom@19.2.3(react@19.2.3))(react@19.2.3)
version: 1.8.0(@types/react@19.2.14)(date-fns@4.4.0)(react-dom@19.2.3(react@19.2.3))(react@19.2.3)
'@buildcanada/charts':

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Survey select lacks interaction coverage
This updates the Base UI select used by the voter survey from 1.3.0 to 1.8.0, but there is no component or browser test for choosing an option and submitting its value. The existing build and library tests cannot catch a regression in that survey interaction. Add a focused test for it.

Prompt To Fix With AI
This is a comment left during a code review.
Path: pnpm-lock.yaml
Line: 17

Comment:
**Survey select lacks interaction coverage**
This updates the Base UI select used by the voter survey from 1.3.0 to 1.8.0, but there is no component or browser test for choosing an option and submitting its value. The existing build and library tests cannot catch a regression in that survey interaction. Add a focused test for it.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Fix in Codex Fix in Claude Code

Comment thread Dockerfile
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant