Skip to content

chore(deps): bump react-dom and @types/react-dom - #148

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bun/multi-de36fa8f59
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bun/multi-de36fa8f59

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown

Bumps react-dom and @types/react-dom. These dependencies needed to be updated together.
Updates react-dom from 19.2.4 to 19.3.0

Release notes

Sourced from react-dom's releases.

19.3.0 (September 9, 2026)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.3 release post for more information.

New React Features

New React DOM Features

  • browser(): a new react-dom API that returns a usable which errors during server rendering and resolves in the browser. use(browser()) inside a <Suspense> boundary marks a subtree as browser-only without reporting a recoverable error (@​gnoff: #37143, #37241)
    • Added an onBrowserBailout option to the react-dom/server APIs to observe when a subtree defers to the browser (@​gnoff #37193)

Notable changes

All Changes

React

... (truncated)

Changelog

Sourced from react-dom's changelog.

19.3.0 (September 9, 2026)

New React Features

New React DOM Features

  • browser(): a new react-dom API that returns a usable which errors during server rendering and resolves in the browser. use(browser()) inside a <Suspense> boundary marks a subtree as browser-only without reporting a recoverable error (@​gnoff: #37143, #37241)
    • Added an onBrowserBailout option to the react-dom/server APIs to observe when a subtree defers to the browser (@​gnoff #37193)

Notable changes

All Changes

React

... (truncated)

Commits
  • f4e439e [Fizz] Add nonce to rendered import maps (#37339)
  • 21c89c9 [DOM] Clean up Fragment listeners on signal abort (#37457)
  • 065bc84 [DOM] Unobserve fragment IntersectionObserver targets after exit (#37408)
  • ff7445e [DOM] Update HTML parser rules for new select parser (#34804)
  • 2dc7da7 [test] Bump Jest to 30.4 (#37382)
  • 29d9d31 [DOM] Copy source onto the synthetic toggle event (#37389)
  • 269bd40 [test] Remove the custom toThrow override for legacy V8 error messages (#37...
  • a112448 [DOM] Treat omitted Fragment Event listener options same as capture: false ...
  • 3d05080 [Fizz] Construct the render lifetime controller only when it is needed (#37357)
  • 77ed3f5 [Flight/Fizz] Stop the caller's signal from retaining a finished render (#37315)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for react-dom since your current version.


Updates @types/react-dom from 19.2.3 to 19.3.0

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) and [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom). These dependencies needed to be updated together.

Updates `react-dom` from 19.2.4 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom)

Updates `@types/react-dom` from 19.2.3 to 19.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom)

---
updated-dependencies:
- dependency-name: react-dom
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: "@types/react-dom"
  dependency-version: 19.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 25, 2026
@dependabot
dependabot Bot requested a review from beeeku as a code owner September 25, 2026 14:15
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 25, 2026
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: e08272b4-dcc3-4395-b612-dc63bddeb75e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

beeeku commented Sep 29, 2026

Copy link
Copy Markdown
Owner

CI is red because this bump moves react-dom to 19.3.0 without a matching react bump. React enforces that the two packages be at the exact same version — the docs Astro build hits ensureCorrectIsomorphicReactVersion and fails at server-render time:

Incompatible React versions:
  - react:      19.2.4
  - react-dom:  19.3.0

Failing job: Test (Node 22) in run 36146228904 — the shared root failure surfaces on both Test (Node 22) and Bundle Size (docs build).

Root cause of the split bump: react lives in the root bun workspace ecosystem, react-dom (+ @types/react-dom) surfaced via /apps/docs's npm ecosystem. Dependabot groups within a scope, not across scopes, so the two never land together. See .github/dependabot.yml:29-46 for the /apps/docs group + .github/dependabot.yml:57-66 for the root scope.

Two ways forward:

  1. Add a matching react (+ @types/react) bump on this branch so the pair moves together, then merge.
  2. Close this PR and hand-file one PR that bumps react, react-dom, @types/react, @types/react-dom in lockstep.

Flagging from the audit routine at #141. See #141 for repo-state context.


Generated by Claude Code

@beeeku

beeeku commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Superseded by #160, which folds this bump into a workspace-wide in-range refresh (and, for #148, pairs react with react-dom so the docs build stays consistent).

@beeeku beeeku closed this Sep 29, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/bun/multi-de36fa8f59 branch September 29, 2026 11:12
beeeku added a commit that referenced this pull request Sep 29, 2026
…#115)

Clears every error-level trivy finding in bun.lock (25 -> 0) so
`maina verify` passes without suppression.

Workspace refresh (`bun update -r`, no majors for shipped code):
- Runtime floors move only in approval/mcp (hono ^4.13.11, past the
  4.12.x advisories) and mail (mimetext ^3.0.28, postal-mime ^2.7.6);
  patch changeset included. Peer ranges unchanged.
- Folds in #153 (`@cloudflare/puppeteer` 1.4.0, dev-only) and #154
  (`valibot` 1.5.0). Pairs react + react-dom 19.3, superseding #148.
- Root override `@puppeteer/browsers` ^3.2.3 drops `extract-zip` 2.0.1
  (symlink file-write CVEs, no upstream fix). Dev-only; browser/pdf
  tests pass 35/35 and 51/51.

apps/docs (private, not published) — Astro 5 -> 7:
- astro ^7.2.10, @astrojs/starlight ^0.42.4, @astrojs/react ^7,
  @astrojs/starlight-tailwind ^5, tailwindcss ^4 via @tailwindcss/vite;
  drops @astrojs/tailwind and tailwind.config.ts (CSS-first config).
- Starlight 0.39+ sidebar: autogenerate moves into `items`.
- `bg-gradient-to-r` -> `bg-linear-to-r` (Tailwind 4 rename).
- Fixes the critical AVIF RCE plus SSRF/XSS advisories on astro.
- Same 33 pages built; `astro check` 0 errors; landing + guide pages
  screenshot-compared against the Astro 5 build.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant