Skip to content

Consolidate Dependabot dependency updates - #156

Merged
ArtisKrumins merged 1 commit into
masterfrom
chore/dependabot-consolidated-updates
Sep 15, 2026
Merged

ArtisKrumins merged 1 commit into
masterfrom
chore/dependabot-consolidated-updates

Conversation

@ArtisKrumins

Copy link
Copy Markdown
Contributor

Summary

  • Bumps @docusaurus/core and @docusaurus/preset-classic from 3.9.1 to 3.10.2, which pulls in patched transitive dependencies across the whole build toolchain.
  • Adds overrides for uuid (^11.1.1) and serialize-javascript (^7.1.1) to force-patch two deeply nested transitive packages that npm's own resolver couldn't bump without a spurious "downgrade" suggestion.
  • Also picks up react/react-dom being aligned to the same 19.3.0 version (they had drifted apart and broke the production build).

This consolidates the fixes from all 9 currently open Dependabot PRs (#154, #153, #152, #151, #150, #148, #147, #145, #143) plus additional transitive vulnerabilities that had open Dependabot security alerts but no PR yet. npm audit goes from 65 open Dependabot alerts / 50 local vulnerabilities down to 0.

Doing this as a single consolidated branch avoids running CI/build 9+ separate times for what is ultimately one lockfile. Once this merges, Dependabot should auto-close the individual PRs since the same version bumps are already satisfied on master.

Test plan

  • npm install — clean install, no peer dependency errors
  • npm audit — 0 vulnerabilities (was 50 local / 65 total including alerts without PRs yet)
  • npm run build — production build succeeds
  • npm run serve — verified homepage and a docs page render correctly in a browser, no console errors

🤖 Generated with Claude Code

Bumps @docusaurus/core and @docusaurus/preset-classic to 3.10.2 and
adds npm overrides for uuid and serialize-javascript to resolve all
outstanding Dependabot security alerts in one pass (65 alerts across
9 open PRs plus additional transitive vulnerabilities not yet covered
by a PR). Verified with npm audit (0 vulnerabilities) and a full
docusaurus build.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 15, 2026 07:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Broad dependency and transitive-resolution changes warrant final human review.

Pull request overview

Consolidates Dependabot security updates for the Docusaurus documentation build.

Changes:

  • Upgrades Docusaurus packages to 3.10.2.
  • Adds overrides for patched uuid and serialize-javascript versions.
  • Aligns React dependencies and refreshes dependency resolutions.
File summaries
File Description
package.json Updates Docusaurus dependencies and adds security overrides.
Review details
  • Files reviewed: 1/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@ArtisKrumins
ArtisKrumins merged commit fc066da into master Sep 15, 2026
3 checks passed
@ArtisKrumins
ArtisKrumins deleted the chore/dependabot-consolidated-updates branch September 15, 2026 07:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants