Repository navigation
chore(deps): bump react-dom and @types/react-dom - #148
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) and [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom). These dependencies needed to be updated together. Updates `react-dom` from 19.2.4 to 19.3.0 - [Release notes](https://github.com/react/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom) Updates `@types/react-dom` from 19.2.3 to 19.3.0 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom) --- updated-dependencies: - dependency-name: react-dom dependency-version: 19.3.0 dependency-type: direct:production update-type: version-update:semver-minor - dependency-name: "@types/react-dom" dependency-version: 19.3.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
CI is red because this bump moves Failing job: Root cause of the split bump: Two ways forward:
Flagging from the audit routine at #141. See #141 for repo-state context. Generated by Claude Code |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
…#115) Clears every error-level trivy finding in bun.lock (25 -> 0) so `maina verify` passes without suppression. Workspace refresh (`bun update -r`, no majors for shipped code): - Runtime floors move only in approval/mcp (hono ^4.13.11, past the 4.12.x advisories) and mail (mimetext ^3.0.28, postal-mime ^2.7.6); patch changeset included. Peer ranges unchanged. - Folds in #153 (`@cloudflare/puppeteer` 1.4.0, dev-only) and #154 (`valibot` 1.5.0). Pairs react + react-dom 19.3, superseding #148. - Root override `@puppeteer/browsers` ^3.2.3 drops `extract-zip` 2.0.1 (symlink file-write CVEs, no upstream fix). Dev-only; browser/pdf tests pass 35/35 and 51/51. apps/docs (private, not published) — Astro 5 -> 7: - astro ^7.2.10, @astrojs/starlight ^0.42.4, @astrojs/react ^7, @astrojs/starlight-tailwind ^5, tailwindcss ^4 via @tailwindcss/vite; drops @astrojs/tailwind and tailwind.config.ts (CSS-first config). - Starlight 0.39+ sidebar: autogenerate moves into `items`. - `bg-gradient-to-r` -> `bg-linear-to-r` (Tailwind 4 rename). - Fixes the critical AVIF RCE plus SSRF/XSS advisories on astro. - Same 33 pages built; `astro check` 0 errors; landing + guide pages screenshot-compared against the Astro 5 build. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bumps react-dom and @types/react-dom. These dependencies needed to be updated together.
Updates
react-domfrom 19.2.4 to 19.3.0Release notes
Sourced from react-dom's releases.
... (truncated)
Changelog
Sourced from react-dom's changelog.
... (truncated)
Commits
f4e439e[Fizz] Addnonceto renderedimport maps(#37339)21c89c9[DOM] Clean up Fragment listeners on signal abort (#37457)065bc84[DOM] Unobserve fragment IntersectionObserver targets after exit (#37408)ff7445e[DOM] Update HTML parser rules for new select parser (#34804)2dc7da7[test] Bump Jest to 30.4 (#37382)29d9d31[DOM] Copysourceonto the synthetic toggle event (#37389)269bd40[test] Remove the customtoThrowoverride for legacy V8 error messages (#37...a112448[DOM] Treat omitted Fragment Event listener options same ascapture: false...3d05080[Fizz] Construct the render lifetime controller only when it is needed (#37357)77ed3f5[Flight/Fizz] Stop the caller's signal from retaining a finished render (#37315)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for react-dom since your current version.
Updates
@types/react-domfrom 19.2.3 to 19.3.0Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)