Skip to content

chore(deps): consolidate dependency bumps (#273, #260, #259, #258, #257, #256, #242) - #284

Closed
sirdeggen wants to merge 8 commits into
mainfrom
chore/consolidate-dep-bumps
Closed

chore(deps): consolidate dependency bumps (#273, #260, #259, #258, #257, #256, #242)#284
sirdeggen wants to merge 8 commits into
mainfrom
chore/consolidate-dep-bumps

Conversation

@sirdeggen

Copy link
Copy Markdown
Contributor

Summary

Consolidates all currently-open dependabot chore/dep-bump PRs into a single branch so CI runs once against the combined change set instead of 7 separate runs.

Cherry-picked cleanly (no conflicts) from:

pnpm install --frozen-lockfile passes locally against the merged lockfiles.

Once this is green on CI and merged, the 7 source PRs above should be closed as superseded.

Test plan

  • CI green on this PR
  • pnpm install --frozen-lockfile verified locally

dependabot Bot added 7 commits July 14, 2026 14:48
…updates

---
updated-dependencies:
- dependency-name: "@libp2p/bootstrap"
  dependency-version: 12.0.26
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bsv-workspace
- dependency-name: "@libp2p/crypto"
  dependency-version: 5.1.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bsv-workspace
- dependency-name: "@libp2p/identify"
  dependency-version: 4.1.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bsv-workspace
- dependency-name: "@libp2p/interface"
  dependency-version: 3.2.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bsv-workspace
- dependency-name: "@libp2p/kad-dht"
  dependency-version: 16.3.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bsv-workspace
- dependency-name: "@libp2p/peer-id"
  dependency-version: 6.0.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bsv-workspace
- dependency-name: "@libp2p/ping"
  dependency-version: 3.1.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bsv-workspace
- dependency-name: "@libp2p/pnet"
  dependency-version: 3.0.24
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bsv-workspace
- dependency-name: "@libp2p/tcp"
  dependency-version: 11.0.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bsv-workspace
- dependency-name: "@rspack/cli"
  dependency-version: 2.1.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: "@rspack/core"
  dependency-version: 2.1.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: "@shikijs/rehype"
  dependency-version: 4.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: "@types/node"
  dependency-version: 26.1.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: "@vitejs/plugin-react"
  dependency-version: 6.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: bsv-workspace
- dependency-name: better-sqlite3
  dependency-version: 12.11.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: chalk
  dependency-version: 5.6.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: bsv-workspace
- dependency-name: eslint
  dependency-version: 10.7.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: fs-extra
  dependency-version: 11.3.6
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: bsv-workspace
- dependency-name: globals
  dependency-version: 17.7.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: jest-fetch-mock
  dependency-version: 4.2.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: bsv-workspace
- dependency-name: knex
  dependency-version: 3.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: libp2p
  dependency-version: 3.3.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bsv-workspace
- dependency-name: mermaid
  dependency-version: 11.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: mongodb
  dependency-version: 7.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: mysql2
  dependency-version: 3.22.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: bsv-workspace
- dependency-name: prettier
  dependency-version: 3.9.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: react-router-dom
  dependency-version: 7.18.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: bsv-workspace
- dependency-name: tsx
  dependency-version: 4.23.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: bsv-workspace
- dependency-name: typescript-eslint
  dependency-version: 8.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: vite
  dependency-version: 8.1.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: vite-react-ssg
  dependency-version: 0.9.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: bsv-workspace
- dependency-name: vitest
  dependency-version: 4.1.10
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: bsv-workspace
- dependency-name: webpack
  dependency-version: 5.108.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: webpack-cli
  dependency-version: 7.2.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: bsv-workspace
- dependency-name: webpack-dev-server
  dependency-version: 6.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: bsv-workspace
...

Signed-off-by: dependabot[bot] <support@github.com>
…dates

Bumps the infra-deps group with 1 update in the /infra/chaintracks-server directory: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node).
Bumps the infra-deps group with 5 updates in the /infra/message-box-server directory:

| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.0.0` | `26.0.1` |
| [firebase-admin](https://github.com/firebase/firebase-admin-node) | `14.0.0` | `14.1.0` |
| [knex](https://github.com/knex/knex) | `3.2.10` | `3.3.0` |
| [mongodb](https://github.com/mongodb/node-mongodb-native) | `7.3.0` | `7.4.0` |
| [axios](https://github.com/axios/axios) | `1.18.0` | `1.18.1` |

Bumps the infra-deps group with 2 updates in the /infra/overlay-server directory: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [mongodb](https://github.com/mongodb/node-mongodb-native).
Bumps the infra-deps group with 2 updates in the /infra/uhrp-server-basic directory: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [axios](https://github.com/axios/axios).
Bumps the infra-deps group with 2 updates in the /infra/uhrp-server-cloud-bucket directory: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [axios](https://github.com/axios/axios).
Bumps the infra-deps group with 1 update in the /infra/uhrp-server-cloud-bucket/notifier directory: [axios](https://github.com/axios/axios).
Bumps the infra-deps group with 2 updates in the /infra/wab directory: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) and [knex](https://github.com/knex/knex).
Bumps the infra-deps group with 3 updates in the /infra/wallet-infra directory: [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node), [knex](https://github.com/knex/knex) and [prettier](https://github.com/prettier/prettier).


Updates `@types/node` from 26.0.0 to 26.0.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@types/node` from 26.0.0 to 26.0.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `firebase-admin` from 14.0.0 to 14.1.0
- [Release notes](https://github.com/firebase/firebase-admin-node/releases)
- [Changelog](https://github.com/firebase/firebase-admin-node/blob/main/CHANGELOG.md)
- [Commits](firebase/firebase-admin-node@v14.0.0...v14.1.0)

Updates `knex` from 3.2.10 to 3.3.0
- [Release notes](https://github.com/knex/knex/releases)
- [Changelog](https://github.com/knex/knex/blob/master/CHANGELOG.md)
- [Commits](knex/knex@3.2.10...3.3.0)

Updates `mongodb` from 7.3.0 to 7.4.0
- [Release notes](https://github.com/mongodb/node-mongodb-native/releases)
- [Changelog](https://github.com/mongodb/node-mongodb-native/blob/main/HISTORY.md)
- [Commits](mongodb/node-mongodb-native@v7.3.0...v7.4.0)

Updates `axios` from 1.18.0 to 1.18.1
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.18.0...v1.18.1)

Updates `@types/node` from 26.0.0 to 26.0.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `mongodb` from 7.3.0 to 7.4.0
- [Release notes](https://github.com/mongodb/node-mongodb-native/releases)
- [Changelog](https://github.com/mongodb/node-mongodb-native/blob/main/HISTORY.md)
- [Commits](mongodb/node-mongodb-native@v7.3.0...v7.4.0)

Updates `@types/node` from 26.0.0 to 26.0.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `axios` from 1.18.0 to 1.18.1
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.18.0...v1.18.1)

Updates `@types/node` from 26.0.0 to 26.0.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `axios` from 1.18.0 to 1.18.1
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.18.0...v1.18.1)

Updates `axios` from 1.18.0 to 1.18.1
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.18.0...v1.18.1)

Updates `@types/node` from 26.0.0 to 26.0.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `knex` from 3.2.10 to 3.3.0
- [Release notes](https://github.com/knex/knex/releases)
- [Changelog](https://github.com/knex/knex/blob/master/CHANGELOG.md)
- [Commits](knex/knex@3.2.10...3.3.0)

Updates `@types/node` from 26.0.0 to 26.0.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `knex` from 3.2.10 to 3.3.0
- [Release notes](https://github.com/knex/knex/releases)
- [Changelog](https://github.com/knex/knex/blob/master/CHANGELOG.md)
- [Commits](knex/knex@3.2.10...3.3.0)

Updates `prettier` from 3.8.4 to 3.9.1
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.8.4...3.9.1)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: infra-deps
- dependency-name: "@types/node"
  dependency-version: 26.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: infra-deps
- dependency-name: firebase-admin
  dependency-version: 14.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: infra-deps
- dependency-name: knex
  dependency-version: 3.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: infra-deps
- dependency-name: mongodb
  dependency-version: 7.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: infra-deps
- dependency-name: axios
  dependency-version: 1.18.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: infra-deps
- dependency-name: "@types/node"
  dependency-version: 26.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: infra-deps
- dependency-name: mongodb
  dependency-version: 7.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: infra-deps
- dependency-name: "@types/node"
  dependency-version: 26.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: infra-deps
- dependency-name: axios
  dependency-version: 1.18.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: infra-deps
- dependency-name: "@types/node"
  dependency-version: 26.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: infra-deps
- dependency-name: axios
  dependency-version: 1.18.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: infra-deps
- dependency-name: axios
  dependency-version: 1.18.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: infra-deps
- dependency-name: "@types/node"
  dependency-version: 26.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: infra-deps
- dependency-name: knex
  dependency-version: 3.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: infra-deps
- dependency-name: "@types/node"
  dependency-version: 26.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: infra-deps
- dependency-name: knex
  dependency-version: 3.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: infra-deps
- dependency-name: prettier
  dependency-version: 3.9.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: infra-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 6.0.1 to 7.0.0.
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](codecov/codecov-action@e79a696...fb8b358)

---
updated-dependencies:
- dependency-name: codecov/codecov-action
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [stefanzweifel/git-auto-commit-action](https://github.com/stefanzweifel/git-auto-commit-action) from 7.1.0 to 7.2.0.
- [Release notes](https://github.com/stefanzweifel/git-auto-commit-action/releases)
- [Changelog](https://github.com/stefanzweifel/git-auto-commit-action/blob/master/CHANGELOG.md)
- [Commits](stefanzweifel/git-auto-commit-action@04702ed...4a55954)

---
updated-dependencies:
- dependency-name: stefanzweifel/git-auto-commit-action
  dependency-version: 7.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@de0fac2...9c091bb)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.4.0 to 6.5.0.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](actions/setup-go@4a36011...924ae3a)

---
updated-dependencies:
- dependency-name: actions/setup-go
  dependency-version: 6.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6.2.0 to 6.3.0.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@a309ff8...ece7cb0)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: 6.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@socket-security

socket-security Bot commented Jul 14, 2026

Copy link
Copy Markdown

@socket-security

socket-security Bot commented Jul 14, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @emnapi/runtime is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/@rspack/core@2.1.3npm/vite@8.1.4npm/@emnapi/runtime@1.11.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@emnapi/runtime@1.11.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm mermaid is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: docs-site/package.jsonnpm/mermaid@11.16.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/mermaid@11.16.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm powershell-utils is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/webpack-dev-server@6.0.0npm/powershell-utils@0.1.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/powershell-utils@0.1.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm webpack is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: packages/helpers/did-client/package.jsonnpm/webpack@5.108.4

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/webpack@5.108.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@ty-everett ty-everett left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Really tired of Dependabot! It should make ONE PR maybe every 3 weeks with all dep changes, not 9 PRs.

And if there is one PR already open it should not open a new one under any circumstances, it should always rebase the old one and it should update it with whatever it was going to do.

Otherwise none of these will ever get merged in a timely manner going forward.

QA issue on 24.x then this is approved

@sirdeggen sirdeggen left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary

This PR consolidates seven Dependabot bump PRs. Action SHAs look correct, but monorepo consolidation is incomplete and should be fixed before merge.

Blocking findings (cannot use Request changes on own PR — please treat as such):

  1. Root pnpm.overrides still pin TypeScript ^6.0.3 while packages declare ^7.0.2; lockfile still resolves 6.0.3.
  2. Root overrides still pin knex 3.2.10 / mysql2 3.22.3 while package.json files declare newer ranges.

Either complete the upgrades (overrides + lockfile) or revert the cosmetic bumps. See inline comments. Do not merge until these are addressed.

"ts-jest": "^29.4.11",
"ts-node": "^10.9.2",
"typescript": "^6.0.3",
"typescript": "^7.0.2",

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[bug] Workspace packages (and docs-site / conformance runners) bump typescript to ^7.0.2, but the root package.json still has pnpm.overrides.typescript: "^6.0.3" (unchanged by this PR) and pnpm-lock.yaml importers still record specifier: ^6.0.3 / version: 6.0.3 (e.g. amountinator importer at lockfile L157–L159). CI jobs use pnpm install --frozen-lockfile (.github/workflows/ci.yml, docs-deploy.yml, release.yaml). That combination is either an outdated-lockfile install failure, or a silent no-op that never installs TypeScript 7 despite the package.json churn. The TypeScript 7 bump is therefore incomplete/inconsistent across the monorepo.

Suggestion: Either (a) complete the TS 7 upgrade by updating root pnpm.overrides.typescript to ^7.0.2 (or removing the pin), regenerating pnpm-lock.yaml so importers show specifier: ^7.0.2 and resolve 7.0.x, and validating tsc/jest/eslint against the Go-based TS 7 compiler; or (b) revert the per-package typescript range bumps until overrides + lockfile can be updated together. Do not land package.json ranges that disagree with the lockfile while frozen installs are required.

"idb": "^8.0.2",
"knex": "^3.2.10",
"mysql2": "^3.22.5",
"knex": "^3.3.0",

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[bug] Workspace packages bump knex to ^3.3.0 (wallet-toolbox, overlay, overlay-express) and mysql2 to ^3.22.6 (wallet-toolbox), but root pnpm.overrides still pin knex: "3.2.10" and mysql2: "3.22.3". The lockfile accordingly still resolves knex 3.2.10 and mysql2 3.22.3 (e.g. wallet-toolbox importer knex/mysql2 entries). Those package.json bumps are therefore cosmetic for the pnpm workspace and create a false sense that knex/mysql2 were upgraded in-app. Infra components (outside the pnpm workspace) do pick up knex 3.3.0 via their own package-locks, so runtime versions will diverge between monorepo packages and infra services after merge.

Suggestion: Update root pnpm.overrides for knex and mysql2 to match the intended ranges (or drop the pins if no longer needed), run pnpm install to refresh the lockfile, and re-verify storage/migration tests. If the overrides must stay for compatibility, do not bump the package.json ranges in this PR—leave them consistent with the forced versions.

Comment thread packages/sdk/package.json
"tsconfig-to-dual-package": "^1.2.0",
"typescript": "^6.0.3",
"typescript-eslint": "^8.61.0"
"typescript": "^7.0.2",

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[suggestion] Even after fixing Issue 1, TypeScript 6 → 7 is a major compiler rewrite (native/Go tsc) with ecosystem breakage risk for tools this repo relies on (ts-jest, typescript-eslint, ts-node, tsup, ts-standard, dual-package tooling). Package.json files already pin ecosystem tools that historically depend on the TypeScript JS API; a pure Dependabot range bump without a green full build/test matrix is high-risk for a consolidation PR.

Suggestion: Treat TS 7 as its own migration PR after CI is green on lockfile consistency. Confirm peer support from typescript-eslint / ts-jest / rspack, run full workspace build + test + lint, and document any required config/default changes (TS 6 deprecations become hard errors in 7).

"@types/node": "^26.0.0",
"chalk": "^4.1.2",
"@types/node": "^26.1.1",
"chalk": "^5.6.2",

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[suggestion] chalk is bumped from ^4.1.2 to ^5.6.2 in wallet-toolbox. Chalk 5 is ESM-only; the only consumer found is a Jest test (test/Wallet/action/createAction2.test.ts uses import chalk from 'chalk'). Depending on Jest/ts-jest ESM configuration, this can fail at runtime even though TypeScript may still typecheck.

Suggestion: Confirm the wallet-toolbox test suite imports chalk successfully under the current Jest config. If not, keep chalk 4 for CJS tests or enable the necessary ESM interop for that package.

Comment thread docs-site/package.json
"react": "^19.2.7",
"react-dom": "^19.2.7",
"react-router-dom": "^6.28.0"
"react-router-dom": "^7.18.1"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[suggestion] react-router-dom major bump ^6.28.0^7.18.1 for the docs site. v7 keeps a compatibility surface for many v6 DOM APIs, and current imports (Link, NavLink, Outlet, useLocation, RouteObject) are still re-exported, so this is likely fine—but it is still a major framework bump in a static docs SSG path (vite-react-ssg) and should not ride silently inside a deps-consolidation PR without a docs build verification.

Suggestion: Ensure the docs-validate / docs-deploy jobs pass on this branch (they should), and skim for any future-flag or loader-related deprecations if the site later adopts data APIs. No code change required if the existing docs CI is green.

"webpack-cli": "^7.0.3",
"webpack-dev-server": "^5.2.5",
"webpack-cli": "^7.2.1",
"webpack-dev-server": "^6.0.0",

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[suggestion] Two major bumps land together in message-box-client: jest-fetch-mock ^3.0.3^4.2.0 and webpack-dev-server ^5.2.5^6.0.0. These are not covered by the root overrides story and will actually resolve if the lockfile matches (webpack-dev-server does appear updated in the lockfile). Either can break local test/dev scripts even if production builds are unaffected.

Suggestion: Run message-box-client tests and any webpack-dev-server-based demo/dev scripts after install. If unused, consider dropping webpack-dev-server rather than major-bumping it in a bulk PR.

Comment thread .github/workflows/ci.yml Outdated

steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nit] All workflows pin actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0, which is the verified v7.0.0 release commit, but most comments still say # v6 (ci.yml, codegen.yml, conformance.yml, infra-release.yaml, release.yaml, wab-marketplace-release.yml). Only docs-deploy.yml correctly comments # v7.0.0. The pin itself is fine and consistent; the version comments are misleading for future audits.

Suggestion: Update every checkout pin comment to # v7.0.0 (or # v7) so SHA annotations match the actual major.

@@ -66,7 +66,7 @@ jobs:
-o conformance/generated/messaging/types.gen.d.ts

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nit] actions/setup-python is bumped to SHA ece7cb06caefa5fff74198d8649806c4678c61a1 (correct for v6.3.0) but the trailing comment remains only # v6 instead of # v6.3.0. Same pattern as other minor action bumps—low impact, but reduces pin auditability.

Suggestion: Annotate as # v6.3.0 (and setup-go as # v6.5.0) for consistency with the codecov pin style (# v7.0.0).

@sirdeggen
sirdeggen marked this pull request as draft July 15, 2026 13:26
Update root overrides for typescript, knex, and mysql2 so package.json
ranges actually resolve, keep chalk 4 for CJS tests, and correct action
pin version comments. Regenerates pnpm-lock.yaml accordingly.
@sonarqubecloud

Copy link
Copy Markdown

Copy link
Copy Markdown
Collaborator

Closing as superseded by #313 and the coordinated plan in #310. The replacement incorporates the actionable review feedback here: it removes the broad root TypeScript/database overrides that masked package compatibility, consolidates all supported ecosystems into one monthly maintenance PR, limits the stream to one open PR, and keeps it automatically rebased. #313 also adds dependency review, high/critical audit enforcement, Socket/CodeQL/Sonar/Codecov gates, and a protected release path. This PR is conflicted and should not be merged.

@ty-everett ty-everett closed this Jul 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants