Skip to content

chore(deps): lock file maintenance - #1867

Closed
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/lock-file-maintenance
Closed

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/lock-file-maintenance

Conversation

@renovate

@renovate renovate Bot commented Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Update Change
lockFileMaintenance All locks refreshed

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 4am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.


Note

Low Risk
Lockfile-only updates in example projects; no application or action source changes, though refreshed transitive deps could affect CI if installs behave differently.

Overview
Refreshes lock files only under examples/ (npm, pnpm, and yarn) via scheduled lock-file maintenance—no package.json manifest changes.

Across Cypress-focused examples, transitive dev dependencies move to newer patch/minor releases, including qs (6.15.x → 6.16.0), systeminformation (5.31–5.33.x → 5.33.10+), and terminal helpers like ansi-regex and string-width. systeminformation also picks up a stricter Node engine floor (>=10.0.0).

The component-tests example additionally bumps its Vite toolchain (vite 8.2 → 8.3, rolldown 1.2.5 → 1.2.8, related @rolldown/* bindings, postcss, picomatch, nanoid) and react / react-dom (19.2.x → 19.3.0 with scheduler 0.28.0).

The nextjs example lockfile updates next and @next/* (16.3.3 → 16.3.4), sharp / @img/sharp-* (0.35.3 → 0.35.4), matching React 19.3, and related build deps.

A few locks only reshuffle metadata (e.g. dropping redundant root version fields, arch hoisting under clipboardy vs cypress in config/start examples).

Reviewed by Cursor Bugbot for commit 1da1b99. Bugbot is set up for automated code reviews on this repo. Configure here.

@cypress-app-bot

Copy link
Copy Markdown
Collaborator

See the guidelines for reviewing dependency updates for info on how to review dependency update PRs.

@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch 6 times, most recently from 57cbbce to afd5b76 Compare September 1, 2026 13:48
@MikeMcC399

Copy link
Copy Markdown
Collaborator

@MikeMcC399

Copy link
Copy Markdown
Collaborator

Merging this PR should mitigate multiple reported vulnerabilities in transient dependencies of examples.

@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch from afd5b76 to 6dfb30e Compare September 2, 2026 10:22
@jennifer-shehane

Copy link
Copy Markdown
Member

Merge conflicts now need addressing

@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch from 6dfb30e to 286f236 Compare September 2, 2026 10:25
@MikeMcC399

Copy link
Copy Markdown
Collaborator

Merge conflicts now need addressing

Renovate did that automatically

@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch 2 times, most recently from c8e188a to 2ff59f3 Compare September 3, 2026 01:00
@MikeMcC399

Copy link
Copy Markdown
Collaborator

I'm still getting vulnerability alerts from Dependabot.

@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch 6 times, most recently from b7600da to af2c071 Compare September 9, 2026 13:41

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want reviews to match your repository better? Bugbot Learning can learn team-specific rules from PR activity. A team admin can enable Learning in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit af2c071. Configure here.

Comment thread examples/component-tests/package-lock.json Outdated
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch from af2c071 to ea370fe Compare September 9, 2026 13:54
@MikeMcC399

This comment was marked as resolved.

@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch 4 times, most recently from 1b5d5ae to 1c7bc5f Compare September 10, 2026 13:03
@MikeMcC399

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch 3 times, most recently from 2cf2bd2 to 0f3528d Compare September 15, 2026 18:41
@MikeMcC399

This comment was marked as outdated.

@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch from 0f3528d to 741aba8 Compare September 16, 2026 17:15

@MikeMcC399 MikeMcC399 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate is experiencing some compatibility issues following a version rollout.

I suggest to hold back this PR.

Closing it is not effective because it's an evergreen and it will just get recreated with the same issues.

@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch from 741aba8 to cd58585 Compare September 17, 2026 13:25
@renovate
renovate Bot force-pushed the renovate/lock-file-maintenance branch from cd58585 to 1da1b99 Compare September 17, 2026 19:06
@MikeMcC399

Copy link
Copy Markdown
Collaborator

This should be good to go, however I'm going to close it and let Renovate recreate so that we have a clear review from Cursor on it.

@MikeMcC399 MikeMcC399 closed this Sep 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants