Repository navigation
chore(deps): lock file maintenance - #1867
renovate[bot] wants to merge 1 commit into
Conversation
|
See the guidelines for reviewing dependency updates for info on how to review dependency update PRs. |
57cbbce to
afd5b76
Compare
|
|
Merging this PR should mitigate multiple reported vulnerabilities in transient dependencies of examples. |
afd5b76 to
6dfb30e
Compare
|
Merge conflicts now need addressing |
6dfb30e to
286f236
Compare
Renovate did that automatically |
c8e188a to
2ff59f3
Compare
|
I'm still getting vulnerability alerts from Dependabot. |
b7600da to
af2c071
Compare
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Want reviews to match your repository better? Bugbot Learning can learn team-specific rules from PR activity. A team admin can enable Learning in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit af2c071. Configure here.
af2c071 to
ea370fe
Compare
This comment was marked as resolved.
This comment was marked as resolved.
1b5d5ae to
1c7bc5f
Compare
This comment was marked as outdated.
This comment was marked as outdated.
2cf2bd2 to
0f3528d
Compare
This comment was marked as outdated.
This comment was marked as outdated.
0f3528d to
741aba8
Compare
MikeMcC399
left a comment
There was a problem hiding this comment.
Renovate is experiencing some compatibility issues following a version rollout.
I suggest to hold back this PR.
Closing it is not effective because it's an evergreen and it will just get recreated with the same issues.
741aba8 to
cd58585
Compare
cd58585 to
1da1b99
Compare
|
This should be good to go, however I'm going to close it and let Renovate recreate so that we have a clear review from Cursor on it. |

This PR contains the following updates:
🔧 This Pull Request updates lock files to use the latest dependency versions.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.
Note
Low Risk
Lockfile-only updates in example projects; no application or action source changes, though refreshed transitive deps could affect CI if installs behave differently.
Overview
Refreshes lock files only under
examples/(npm, pnpm, and yarn) via scheduled lock-file maintenance—nopackage.jsonmanifest changes.Across Cypress-focused examples, transitive dev dependencies move to newer patch/minor releases, including
qs(6.15.x → 6.16.0),systeminformation(5.31–5.33.x → 5.33.10+), and terminal helpers likeansi-regexandstring-width.systeminformationalso picks up a stricter Node engine floor (>=10.0.0).The component-tests example additionally bumps its Vite toolchain (
vite8.2 → 8.3,rolldown1.2.5 → 1.2.8, related@rolldown/*bindings,postcss,picomatch,nanoid) andreact/react-dom(19.2.x → 19.3.0 withscheduler0.28.0).The nextjs example lockfile updates
nextand@next/*(16.3.3 → 16.3.4),sharp/@img/sharp-*(0.35.3 → 0.35.4), matching React 19.3, and related build deps.A few locks only reshuffle metadata (e.g. dropping redundant root
versionfields,archhoisting underclipboardyvscypressin config/start examples).Reviewed by Cursor Bugbot for commit 1da1b99. Bugbot is set up for automated code reviews on this repo. Configure here.