Skip to content

chore(deps): bump the frontend-npm group across 1 directory with 14 updates - #1459

Closed
dependabot[bot] wants to merge 9 commits into
developfrom
dependabot/npm_and_yarn/frontend/frontend-npm-2ebebc913d
Closed

dependabot[bot] wants to merge 9 commits into
developfrom
dependabot/npm_and_yarn/frontend/frontend-npm-2ebebc913d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Current authority — 2026-09-09

  • exact head: 65b60df44a224ba817af1bc8def34db93ae4b614
  • protected base adopted by ordinary ancestry repair: develop@042b0c70531b229af3acbd0421a2f23098d848b3
  • lifecycle: Draft / stale-base ancestry repaired / frontend security RED source-fixed / one-shot repair workflow self-removed / PR-triggered hosted workflows require action / fix(deps): patch frontend audit security floors #1623 narrow protected-base prerequisite source+security GREEN but shared required gates non-passing / not merge-authorized

Non-force ancestry repair

The Dependabot lane was originally based on 81c105645ca6e680f5f8c15ba9c33b67eb63c48b, 65 protected commits behind live develop. Ordinary two-parent commit 628528e470aa742eacf714a1381f120a14add84a preserves prior #1459 provenance and adopts protected develop@042b0c70531b229af3acbd0421a2f23098d848b3 without force-push or destructive rebase.

Security RED and repair

Trivy evidence from #1621 run 34300562474, job 102306568194, identified two CRITICAL Next.js findings (CVE-2026-75604, GHSA-2xp9-vwfh-vxw4) and one HIGH sharp finding (GHSA-rgj7-g3m4-5g8c) in this group when it still held Next.js 16.3.1 and sharp 0.35.0.

Test-first commit c8a95f54ad3d277a74768aba33ed14d729bc258d added the first security-floor regression. The one-shot source-fix workflow initially failed because actions/setup-node requested pnpm caching before pnpm existed. Exact child 2565ea931abd84d1c0f42df9a88ca1c27a88ef04 repaired that causal ordering issue. The next source-fix execution succeeded and produced ordinary child 65b60df44a224ba817af1bc8def34db93ae4b614 (fix(deps): patch Next.js and sharp security floors). That commit:

  • updates Next.js + eslint-config-next to 16.3.4,
  • updates the sharp override and generated lock to 0.35.4,
  • preserves the broader dependency-group updates,
  • removes .github/workflows/repair-frontend-security-lock.yml in the same commit after its purpose completed.

The resulting tree is 57c446c61e2c52bed1e148f850a8dab605704a19; the temporary source-fix workflow is absent from the current head.

Hosted verification boundary

The current head's PR-triggered Application CI, Bandit, Semgrep, Security, CodeQL PR and Docker workflow runs terminated as action_required without jobs. This is not GREEN evidence and must not be treated as a source failure or silently bypassed. Until the required action is satisfied and the unchanged exact head gets an executable hosted matrix, this broad group is not merge-authorized.

#1623 has since advanced by ordinary RED→GREEN repair to exact e8a54fc5156ac3ffbb79bc8418c5125d7dcdea60. Its predecessor security regression had two valid Codex P2 gaps: it did not structurally bind the root importer/override/snapshot graph, and it did not reject every below-floor next@/sharp@ lock entry. RED a5abe047d318477b64c62cdbee5b737aad8054f0 reproduced both false-negative classes; GREEN e8a54fc... now parses the pnpm lock structurally and enforces all Next.js entries >=16.3.3, all sharp entries >=0.35.4, exact Next.js/eslint-config-next importer identity, referenced snapshots and the reviewed sharp override.

On that exact #1623 head, Application CI 34308232588, Bandit 34308232672, Semgrep 34308232582, Security Scan 34308232578, Docker 34308232872, coverage evidence/source-tree and direct GitHub Advanced Security CodeQL analyses are terminal GREEN. Formal CodeRabbit review PRR_kwDOSNjZ2s8AAAABMvBEOg is APPROVED on exact e8a54fc...; its two original Codex P2 threads are resolved/outdated.

#1623 is still not merge-authorized because shared required OpenCode and CodeQL compatibility contexts failed, Noema run 34308231412 / job 102329519489 failed after a ready orchestrator/free preflight with HTTP 429 after 214.0s, and Strix remains non-terminal. The Noema owner reproduction is on contextual-orchestrator#1106 comment 5595655747 and consumer cleanup on .github#2042 comment 5595656784.

Succession rule

Treat #1623 as the canonical narrow protected-base prerequisite and this PR as its broader successor. Once #1623 normally integrates, #1459 must ordinary-adopt #1623's exact structural security lineage or the resulting protected integration before the remaining group dependency updates are evaluated. This branch must never downgrade Next.js/sharp below the reviewed floors and must not revert the stricter structural regression back to the older literal-only test. Do not close either lane merely because their dependency deltas overlap.

Primary references:

Merge boundary

Keep Draft until #1623's prerequisite normally integrates or this branch ordinary-adopts the same exact structural security lineage, this broad group receives a full executable product/build/security matrix GREEN on one unchanged exact head, all then-live required contexts are terminal-success, and qualifying independent approval is post-last-push.

No manifest-only stale-lock edit, hand-written integrity/platform records, force-push, destructive rebase, self-approval, failure-as-flake waiver, dummy/no-op requeue, synthetic status, admin bypass, or gate weakening.

…pdates

Bumps the frontend-npm group with 14 updates in the /frontend directory:

| Package | From | To |
| --- | --- | --- |
| [@base-ui/react](https://github.com/mui/base-ui/tree/HEAD/packages/react) | `1.6.0` | `1.7.0` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.27.0` | `1.33.0` |
| [next](https://github.com/vercel/next.js) | `16.2.12` | `16.3.1` |
| [react-resizable-panels](https://github.com/bvaughn/react-resizable-panels) | `4.12.2` | `4.12.3` |
| [uuid](https://github.com/uuidjs/uuid) | `14.0.1` | `14.0.2` |
| [vis-network](https://github.com/visjs/vis-network) | `10.1.0` | `10.1.2` |
| [@playwright/test](https://github.com/microsoft/playwright) | `1.62.0` | `1.62.1` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.2` | `26.2.0` |
| [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react) | `19.2.17` | `19.2.18` |
| [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) | `19.2.3` | `19.2.4` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `4.1.10` | `4.1.11` |
| [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.2.12` | `16.3.1` |
| [postcss](https://github.com/postcss/postcss) | `8.5.24` | `8.5.26` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.10` | `4.1.11` |



Updates `@base-ui/react` from 1.6.0 to 1.7.0
- [Release notes](https://github.com/mui/base-ui/releases)
- [Changelog](https://github.com/mui/base-ui/blob/master/CHANGELOG.md)
- [Commits](https://github.com/mui/base-ui/commits/v1.7.0/packages/react)

Updates `lucide-react` from 1.27.0 to 1.33.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.33.0/packages/lucide-react)

Updates `next` from 16.2.12 to 16.3.1
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.2.12...v16.3.1)

Updates `react-resizable-panels` from 4.12.2 to 4.12.3
- [Release notes](https://github.com/bvaughn/react-resizable-panels/releases)
- [Changelog](https://github.com/bvaughn/react-resizable-panels/blob/main/CHANGELOG.md)
- [Commits](bvaughn/react-resizable-panels@4.12.2...4.12.3)

Updates `uuid` from 14.0.1 to 14.0.2
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v14.0.1...v14.0.2)

Updates `vis-network` from 10.1.0 to 10.1.2
- [Release notes](https://github.com/visjs/vis-network/releases)
- [Changelog](https://github.com/visjs/vis-network/blob/master/HISTORY.md)
- [Commits](visjs/vis-network@v10.1.0...v10.1.2)

Updates `@playwright/test` from 1.62.0 to 1.62.1
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.62.0...v1.62.1)

Updates `@types/node` from 26.1.2 to 26.2.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@types/react` from 19.2.17 to 19.2.18
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `@types/react-dom` from 19.2.3 to 19.2.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom)

Updates `@vitest/coverage-v8` from 4.1.10 to 4.1.11
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/coverage-v8)

Updates `eslint-config-next` from 16.2.12 to 16.3.1
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.1/packages/eslint-config-next)

Updates `postcss` from 8.5.24 to 8.5.26
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.24...8.5.26)

Updates `vitest` from 4.1.10 to 4.1.11
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest)

---
updated-dependencies:
- dependency-name: "@base-ui/react"
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: frontend-npm
- dependency-name: lucide-react
  dependency-version: 1.33.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: frontend-npm
- dependency-name: next
  dependency-version: 16.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: frontend-npm
- dependency-name: react-resizable-panels
  dependency-version: 4.12.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
- dependency-name: uuid
  dependency-version: 14.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
- dependency-name: vis-network
  dependency-version: 10.1.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
- dependency-name: "@playwright/test"
  dependency-version: 1.62.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
- dependency-name: "@types/node"
  dependency-version: 26.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: frontend-npm
- dependency-name: "@types/react"
  dependency-version: 19.2.18
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
- dependency-name: "@types/react-dom"
  dependency-version: 19.2.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 4.1.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
- dependency-name: eslint-config-next
  dependency-version: 16.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: frontend-npm
- dependency-name: postcss
  dependency-version: 8.5.26
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
- dependency-name: vitest
  dependency-version: 4.1.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: frontend-npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 24, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner August 24, 2026 03:00
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 24, 2026
devin-ai-integration[bot]

This comment was marked as resolved.

@github-actions

github-actions Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

PR governance metadata gate is not ready for 3edb8320b0288f2bba54ce7e28083164e0d51966:

  • Branch is BEHIND the base branch; update the branch and re-run checks.
  • Required check strix is FAILURE on the current head.

devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae

Copy link
Copy Markdown
Contributor

Exact-head remediation for 3edb8320b0288f2bba54ce7e28083164e0d51966:

Root cause of the hosted failures was the unupdated frontend/pnpm-workspace.yaml override: package.json and the lockfile requested PostCSS 8.5.26, while pnpm applied workspace override 8.5.24, so frozen installs failed before build. The workspace override and two lock/security contract tests now use 8.5.26.

Validation: pnpm@11.5.3 install --frozen-lockfile --ignore-scripts; frontend 435 passed, lint, typecheck, and production build; backend 1786 passed, 32 skipped; targeted dependency/security contracts 2 passed; ruff check backend; and git diff --check. The earlier hosted Strix failure remains provider-side NVIDIA 429/direct-provider evidence and is not treated as a source pass.

@seonghobae

Copy link
Copy Markdown
Contributor

Disposition for the two current informational review threads on 3edb8320b0288f2bba54ce7e28083164e0d51966: the vis-network note is cosmetic and the resolved lock is 10.1.2; the .pnpmfile.cjs exception is intentionally pinned to the reviewed PostCSS 8.5.26 contract so a future security-floor change must update the hook and lock together. The actual frozen-install defect was the workspace override, now fixed and covered by the passing install/build evidence.

@seonghobae

Copy link
Copy Markdown
Contributor

Exact-head Checks RCA: strix failed on provider infrastructure, not a source finding. The run records NVIDIA NIM HTTP 429 rate-limit responses, then a configured openai-direct/gpt-5.6-luna fallback HTTP 404; the gate correctly failed closed with no structured vulnerability report. This requires central provider/fallback remediation and a fresh exact-head scan; no source patch was applied to this dependency-only PR.

@seonghobae

seonghobae commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Strix failure triage for current head 3edb8320b0288f2bba54ce7e28083164e0d51966: the job log shows NVIDIA NIM 429 Too Many Requests, then fallback openai-direct/gpt-5.6-luna 404 page not found; the gate explicitly classified this as provider infrastructure unavailable with no authoritative report artifact. No source finding was emitted. Re-ran failed jobs through the Actions API; merge remains blocked until an exact-head authoritative Strix result and required review are available.

@seonghobae seonghobae added maintenance priority: medium Normal-priority or P2 work labels Sep 7, 2026 — with ChatGPT Codex Connector

Copy link
Copy Markdown
Contributor

Fresh security-owner handoff from exact Naruon PR validation on 2026-09-09.

Security Scan run 34300562474, Trivy job 102306568194, checked out exact 12d8cac36562b27c9f23e10eb4e75fbf6535e9be and failed closed on three frontend lockfile findings inherited from the shared dependency tree:

This frontend dependency lane currently proposes next / eslint-config-next only through 16.3.1, which is no longer an adequate security target. Current upstream advisories patch both critical Next.js issues at 16.3.3; sharp's reviewed advisory patches <0.35.4 at 0.35.4 and was updated 2026-09-08.

Primary advisories:

Please treat the next ordinary source successor here (or a clearly designated security-only dependency successor) as requiring at least next + eslint-config-next 16.3.3 and a lock resolution with sharp >=0.35.4, then re-run the full frontend build/tests plus current Trivy against the exact head. Do not represent 16.3.1 as closing these findings. The Docker-concurrency descendant that exposed this fresh scan will not absorb frontend dependency ownership into its two-file CI delta.

Adopt the current protected develop head as an ordinary second parent while preserving only the six effective frontend dependency/provenance files from the existing Dependabot lane. The protected delta since the old merge base does not overlap those six files, so this avoids dropping 65 protected commits without force-push or destructive rebase.

This is ancestry repair only. It intentionally does not claim the current next 16.3.1 / sharp 0.35.0 dependency set is security-complete; current Trivy evidence requires a patched Next.js release and sharp >=0.35.4 before merge.
@seonghobae
seonghobae marked this pull request as draft September 9, 2026 02:47

Copy link
Copy Markdown
Contributor

#1623 prerequisite advanced by ordinary RED→GREEN repair after two valid Codex P2 findings. Current exact prerequisite head is e8a54fc5156ac3ffbb79bc8418c5125d7dcdea60 (RED a5abe047d318477b64c62cdbee5b737aad8054f0). The new structural regression parses pnpm-lock.yaml, binds root Next.js / eslint-config-next importer specifier+resolved version to the reviewed manifests and exact snapshot keys, binds lock overrides.sharp to the workspace override, and rejects every next@ / sharp@ key below 16.3.3 / 0.35.4 across both packages and snapshots. Both predecessor review threads are source-addressed and resolved.

Do not treat #1459's overlapping 16.3.4/0.35.4 manifest/lock values as full succession of this new test contract. Keep #1459 as the broader successor; after #1623 normally integrates, ordinary-adopt e8a54fc... or the protected integration before evaluating the remaining dependency-group delta. Fresh #1623 exact-head workflows are executing, so this is a source-lineage handoff, not merge evidence.

@dependabot @github

dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 14, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/frontend/frontend-npm-2ebebc913d branch September 14, 2026 05:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code maintenance priority: medium Normal-priority or P2 work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant