Skip to content

chore(deps): bump the javascript-dependencies group across 1 directory with 17 updates - #62

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/javascript-dependencies-71eeb05d16
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/javascript-dependencies-71eeb05d16

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026 •

Copy link
Copy Markdown

Bumps the javascript-dependencies group with 17 updates in the / directory:

Package From To
@prisma/client 6.19.3 7.10.0
@tanstack/react-table 8.21.3 9.2.4
framer-motion 12.43.0 13.4.0
lucide-react 0.525.0 1.46.0
prisma 6.19.3 7.10.0
react-day-picker 9.14.0 10.0.1
react-resizable-panels 3.0.6 4.12.4
react-syntax-highlighter 15.6.6 16.1.1
uuid 11.1.1 14.0.2
@electron/asar 3.4.1 4.3.0
eslint 9.39.5 10.10.0
eslint-config-next 16.2.10 16.3.5
minimatch 3.1.5 10.2.6
typescript 5.9.3 7.0.2
vitest 4.1.11 5.0.1
electron 43.7.3 44.4.1
undici 7.29.1 8.10.2

Updates @prisma/client from 6.19.3 to 7.10.0

Release notes

Sourced from @​prisma/client's releases.

7.10.0

Prisma ORM 7.10.0

Prisma ORM 7.10.0 introduces a compatibility package for running Prisma 7 alongside newer Prisma versions, secures Prisma Studio's local server, and includes fixes across Prisma Client and the PostgreSQL, MariaDB, Neon, SQLite, and Prisma Postgres Serverless adapters.

Highlights

Run Prisma 7 alongside Prisma 8

This release introduces @prisma/prisma7, a compatibility package that lets you retain a matching Prisma 7 CLI and configuration while installing Prisma 8 in the same project.

Once 7.10.0 is released, a side-by-side installation can use:

npm install --save-dev prisma@8 @prisma/prisma7@7.10.0
npm install @prisma/client@7.10.0

Use prisma for the directly installed Prisma 8 CLI and prisma7 for Prisma 7:

npx prisma --version
npx prisma7 --version
npx prisma7 generate
npx prisma7 migrate dev
npx prisma7 db push

Prisma 7 now prefers version-specific configuration files, allowing its configuration to coexist with Prisma 8's prisma.config.* files:

// prisma7.config.ts
import { defineConfig } from '@prisma/prisma7/config'
export default defineConfig({
schema: 'prisma/schema.prisma',
migrations: {
path: 'prisma/migrations',
},
})

Without an explicit --config option, Prisma 7 searches for:

  1. Root-level prisma7.config.* files.
  2. .config/prisma7.* files.
  3. Existing prisma.config.* files as a backwards-compatible fallback.

The supported extensions are .js, .ts, .mjs, .cjs, .mts, and .cts. An explicit config path always takes precedence:

... (truncated)

Commits
  • 05c1b88 Teach Prisma 7 to prefer versioned config files (#30020)
  • cf2bc1f Rename prisma7 package to @​prisma/prisma7 (#30002)
  • ce5a34c Complete downstream actionable Prisma 7 guidance propagation (#29994)
  • 3f13ec6 Complete CLI-owned prisma7 distribution identity (#29969)
  • 179ba0c feat(prisma7): add side-by-side CLI wrapper (#29949)
  • 3fa65ac fix(p2002): correct modelName in nested create unique constraint errors #2959...
  • 6b6d9e9 chore(deps): update engines to 7.10.0-4.0edf323efd1d98336f3f0a68684b56f689b90...
  • b64e33c chore(deps): update engines to 7.10.0-3.9d90ce2c89d5c95a1148aef15e5561ab6c490...
  • 2046f9b feat(client): expose ModelName to compute function in Result extensions (#29782)
  • f2b3abd chore(deps): update engines to 7.10.0-1.6d040c802892de6d56c7e0061b7a10b3e6a0c...
  • Additional commits viewable in compare view

Updates @tanstack/react-table from 8.21.3 to 9.2.4

Release notes

Sourced from @​tanstack/react-table's releases.

@​tanstack/react-table@​9.2.4

Patch Changes

  • Updated dependencies [f72e516]:
    • @​tanstack/table-core@​9.2.4

@​tanstack/react-table@​9.2.3

Patch Changes

@​tanstack/react-table-devtools@​9.1.2

Patch Changes

  • Updated dependencies []:
    • @​tanstack/table-devtools@​9.1.2

@​tanstack/react-table@​9.1.2

Patch Changes

  • Updated dependencies [ff43666]:
    • @​tanstack/table-core@​9.1.2

@​tanstack/react-table-devtools@​9.1.1

Patch Changes

  • Updated dependencies []:
    • @​tanstack/table-devtools@​9.1.1

@​tanstack/react-table@​9.1.1

Patch Changes

  • Updated dependencies [269e0d8]:
    • @​tanstack/table-core@​9.1.1

@​tanstack/react-table-devtools@​9.1.0

Patch Changes

  • Updated dependencies []:
    • @​tanstack/table-devtools@​9.1.0

@​tanstack/react-table@​9.1.0

Patch Changes

  • Updated dependencies [09598d2]:
    • @​tanstack/table-core@​9.1.0

@​tanstack/react-table-devtools@​9.0.1

Patch Changes

... (truncated)

Changelog

Sourced from @​tanstack/react-table's changelog.

9.2.4

Patch Changes

  • Updated dependencies [f72e516]:
    • @​tanstack/table-core@​9.2.4

9.2.3

Patch Changes

9.1.2

Patch Changes

  • Updated dependencies [ff43666]:
    • @​tanstack/table-core@​9.1.2

9.1.1

Patch Changes

  • Updated dependencies [269e0d8]:
    • @​tanstack/table-core@​9.1.1

9.1.0

Patch Changes

  • Updated dependencies [09598d2]:
    • @​tanstack/table-core@​9.1.0

9.0.1

Patch Changes

  • #6521 10accb2 - Column defs built with legacyCreateColumnHelper now accept the built-in filterFn, sortFn, and aggregationFn names, matching the registries useLegacyTable registers at runtime.

  • Updated dependencies []:

    • @​tanstack/table-core@​9.0.1

9.0.0

Major Changes

  • #6512 2327f80 - TanStack Table v9 stable release. See the "Migrating to V9" guide for your framework (e.g. React) for upgrade instructions.

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​tanstack/react-table since your current version.


Updates framer-motion from 12.43.0 to 13.4.0

Changelog

Sourced from framer-motion's changelog.

[13.4.0] 2026-09-14

Added

  • AnimateView: View transitions for React 19.3, built on React's ViewTransition.

[13.3.0] 2026-09-14

Added

  • Hooks for Motion Editor.

Changed

  • springValue/useSpring: 80% reduction in time when retargeting.
  • animate: 10% smaller.
  • animate: 20% reduction in startup time.
  • animate: 10% reduction in per-frame JS.
  • frame: Frame scheduling 10% faster.

Fixed

  • animate: Fixed path drawing calculations.

[13.2.0] 2026-09-03

Added

  • animate.addEffect() for registering effects that lets animate drive non-DOM subjects alongside DOM elements.
  • threeEffect (motion/three) supporting Three.js objects, materials, shader uniforms, TSL uniform nodes and more.
  • vgpuEffect (motion/vgpu) supporting shared uniforms, Effect/Draw/Compute bindings ("params.time"), scene nodes, cameras, lights, materials, orbit controls, CSS colors and vector components.
  • createEffect now accepts test, read and step options and exposes bound motion values via effect.get().

Changed

  • Reduced filesize and improved performance of spring.
  • MotionValueState no longer caches values in latest; effect renders read their motion values directly. set() drops its useDefaultValueType argument.

[13.1.1] 2026-08-18

Fixed

  • Guard animation window access in non-browser runtimes.
  • AnimatePresence: Improved compat with React 19 strict mode.

[13.1.0] 2026-08-10

Added

  • Reorder: Multidimensional reorder.

... (truncated)

Commits
  • a6ea2f9 v13.4.0
  • d6ef844 Changelog
  • 75c4dcf Merge pull request #3824 from motiondivision/codex/react-animate-view
  • a5a7856 Co-locate AnimateView layer animation in framer-motion
  • 5c8bc09 Keep AnimateView group morph with custom values; gate view tests in Playwright
  • 12018e8 Add AnimateView via motion/react-animate-view
  • 939c267 Updating changelog
  • 16cf742 Latest
  • 49f1fe1 v13.3.0
  • f777c92 Updating changelog
  • Additional commits viewable in compare view

Updates lucide-react from 0.525.0 to 1.46.0

Release notes

Sourced from lucide-react's releases.

Version 1.46.0

What's Changed

Full Changelog: lucide-icons/lucide@1.45.0...1.46.0

Version 1.45.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.44.0...1.45.0

Version 1.44.0

What's Changed

... (truncated)

Commits
  • 94e4cb9 chore(dependencies): Update dependencies (#4806)
  • 99d25bd feat(packages): extract icon build logic into @lucide/shared (#4409)
  • 75b5516 chore(dev): upgrade ESLint to latest compatible stack (v10) (#4378)
  • 0f8d48b test(packages): updates unit test snapshots with face-slightly-smiling (#4676)
  • f229f83 chore(depedencies): Update dependencies (#4553)
  • 5ff536e ci(release.yml): Fix workflow and remove version scripts in package scripts...
  • 07c885e fix(docs): fix zephyr-cloud URL in readmes
  • 50d8af5 docs(readme): Update readme files (#4320)
  • 653e44b feat(packages): use .mjs for ESM bundles (#4285)
  • 7623e23 feat(docs): add Zephyr Cloud to Hero Backers tier & rework updateSponsors scr...
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for lucide-react since your current version.


Updates prisma from 6.19.3 to 7.10.0

Commits
Attestation changes

This version has no provenance attestation, while the previous version (6.19.3) was attested. Review the package versions before updating.


Updates react-day-picker from 9.14.0 to 10.0.1

Release notes

Sourced from react-day-picker's releases.

v10.0.1

What's Changed

New Contributors

Full Changelog: gpbl/react-day-picker@v10.0.0...v10.0.1

v10.0.0

DayPicker v10 removes the public APIs deprecated in v9 and introduces a new @daypicker/react package name. Non-Gregorian calendars are now published as standalone @daypicker/* packages.

If your app already uses the current v9 API, the upgrade should be relatively small. If your app still relies on deprecated v9 APIs, those usages should be updated before upgrading.

See the full v10 changelog, the upgrade guide, and the v10 announcement for questions and upgrade feedback.

Install

npm install react-day-picker@latest

For new projects, prefer the scoped package name:

npm install @daypicker/react@latest
import { DayPicker } from "@daypicker/react";
import "@daypicker/react/style.css";

The react-day-picker package remains available in v10 for compatibility.

Breaking Changes

Deprecated navigation props removed

Removed prop Use instead
fromMonth startMonth
fromYear startMonth={new Date(year, 0)}
toMonth endMonth
toYear endMonth={new Date(year, 11)}
fromDate hidden={{ before: date }} and optionally startMonth
toDate hidden={{ after: date }} and optionally endMonth

Deprecated focus and event props removed

... (truncated)

Changelog

Sourced from react-day-picker's changelog.

v10.0.1

Release date: 2026-05-12

This patch release fixes inline styles for component slots and adds @types/react as an optional peer dependency for strict package managers.

What's Changed

  • fix: apply inline styles to all component slots by @​gpbl in #2995
  • fix: add @types/react as an optional peer dependency by @​mrmckeb in #2997

v10.0.0

Release date: 2026-05-08

This major release introduces the @daypicker/react package name, publishes calendar add-on packages under the @daypicker/* scope, and removes public APIs that were deprecated in v9.

Upgrading to v10

Upgrading from v9 should be straightforward if your app does not use any deprecated APIs. See the upgrading guide for details. If you use one of the non-Gregorian calendars, such as Persian, Hebrew, Buddhist, Ethiopic, or Hijri, install the corresponding calendar add-on package alongside DayPicker.

Package Name

For new projects, prefer the @daypicker/react package:

import { DayPicker } from "@daypicker/react";
import "@daypicker/react/style.css";

The react-day-picker package remains available for compatibility and exposes the same DayPicker API in v10.

Calendar Packages

Calendar add-on packages are now published under the @daypicker/* scope. Install the add-on package for the calendar you need alongside @daypicker/react. For example, to use the Persian calendar:

npm install @daypicker/react @daypicker/persian

Breaking Changes

  • Removed deprecated props: fromDate, toDate, fromMonth, toMonth, fromYear, toYear, initialFocus.
  • Removed deprecated event props: onWeekNumberClick, onDayKeyUp, onDayKeyPress, onDayPointerEnter, onDayPointerLeave, onDayTouchCancel, onDayTouchEnd, onDayTouchMove, onDayTouchStart.
  • Removed deprecated type exports from types/deprecated.
  • Removed deprecated aliases: formatMonthCaption, formatYearCaption, labelDay, labelCaption, isMatch, isDateInRange.
  • Removed the deprecated components.Button customization entry.
  • Removed deprecated DeprecatedUI compatibility typing for classNames and styles.
  • Removed deprecated DateLib exports: FormatOptions, LabelOptions, dateLib, and DateLib.Date.
  • Removed the deprecated react-day-picker/jalali subpath. Use react-day-picker/persian.

... (truncated)

Commits

Updates react-resizable-panels from 3.0.6 to 4.12.4

Release notes

Sourced from react-resizable-panels's releases.

4.12.4

  • 743: Don't capture pointer for a detached Separator
  • 741: Separator ARIA values use proper panel indices

4.12.3

  • 730: Guard CSSStyleSheet construction to avoid throwing in unsupported environments (@​leo-yang-qiong)
  • 736: Bugfix: Derived Panel constraints equality check
  • 732: Bugfix: Prevent orphaned groups in "pointerup" edge case (@​waterWang)

4.12.1

  • 723: Bug fix for context menu event (right click) occurring while pointer-resize is active

4.12.0

  • 716): Meta info available to onLayoutChanged callback signalling whether resize event was triggered by direct user input (keyboard or mouse)
  • useDefaultLayout hook supports onlySaveAfterUserInteractions option to only save layouts when directly triggered by user interactions.

4.9.0

  • 702: Add disableDoubleClick prop to Separator to enable turning off the double-click size reset behavior.

4.8.0

  • 699: useDefaultLayout hook automatically migrates legacy layouts to version 4 format; see issue 605 or PR 699 for details on how this works.

4.7.6

  • 698: Replace Panel aria-disabled attribute with data-disabled

4.7.5

  • 696: Improved server rendering support for defaultSize prop

4.7.4

  • 689: Fix edge case bug with pointer event capture

4.7.3

  • 690: Imperative Panel API supports non-percentage sizes

4.7.2

  • 683: Don't scroll separator when setting focus

4.7.1

  • 678: Change default overflow styles to support shadows

4.7.0

  • 677: Add groupResizeBehavior prop to Panel, enabling panels to retain their current size (pixels) size when the parent Group is resized.

4.6.5

  • 670: Check for undefined adoptedStyleSheets (to better support environments like jsdom)
  • 671: Bug-fix: Update in-memory layout cache when group is resized by double-clicking on a separator

4.6.4

  • 664, 665: Resize actions sometimes "jump" on touch devices

... (truncated)

Changelog

Sourced from react-resizable-panels's changelog.

4.12.4

  • 743: Don't capture pointer for a detached Separator
  • 741: Separator ARIA values use proper panel indices

4.12.3

  • 730: Guard CSSStyleSheet construction to avoid throwing in unsupported environments (@​leo-yang-qiong)
  • 736: Bugfix: Derived Panel constraints equality check
  • 732: Bugfix: Prevent orphaned groups in "pointerup" edge case (@​waterWang)

4.12.2

  • 726: Updated inline documentation to clarify size units.

4.12.1

  • 723: Bug fix for context menu event (right click) occurring while pointer-resize is active

4.12.0

  • 716): Meta info available to onLayoutChanged callback signalling whether resize event was triggered by direct user input (keyboard or mouse)
  • useDefaultLayout hook supports onlySaveAfterUserInteractions option to only save layouts when directly triggered by user interactions.

4.11.2

  • 719): Bug fix: Calculate rem-based sizes relative to owner document (not body)

4.11.1

  • 715): Edge case SSR bug fix for panels with defaultSize={0}

4.11.0

  • 712: Separator supports :focus-visible pseudo-class
  • 703: Fix: edge case scenarios when collapsing the last panel
  • 711: Improve legacy browser support wrt global stylesheets

4.10.0

  • 705: Add data-separator="focus" state for Separator elements for more consistent custom CSS styles.

4.9.0

  • 702: Add disableDoubleClick prop to Separator to enable turning off the double-click size reset behavior.

4.8.0

  • 699: useDefaultLayout hook automatically migrates legacy layouts to version 4 format; see issue 605 for details on how this works.

... (truncated)

Commits
  • 152b1a8 4.12.3 -> 4.12.4
  • f711534 fix: skip pointer capture for detached separators (#743)
  • 2419acf fix: use group-relative panel index for Separator aria values (Fixes #740) (#...
  • f9c4227 4.12.2 -> 4.12.3
  • 30503d1 Fix derived Panel constraints equality check (#736)
  • 30aef6a Pending CHANGELOG
  • b1d574e fix: guard CSSStyleSheet construction with adoptedStyleSheets check (#730)
  • 6649f42 fix: don't resurrect stale group entries on pointer-up commit (Fixes #729) (#...
  • a1eeb7a 4.12.1 -> 4.12.2
  • 3e877a1 4.12.0 -> 4.12.1
  • Additional commits viewable in compare view

Updates react-syntax-highlighter from 15.6.6 to 16.1.1

Release notes

Sourced from react-syntax-highlighter's releases.

v16.1.1

What's Changed

New Contributors

Full Changelog: react-syntax-highlighter/react-syntax-highlighter@v16.1.0...v16.1.1

v16.1.0

What's Changed

New Contributors

Full Changelog: react-syntax-highlighter/react-syntax-highlighter@v16.0.0...v16.1.0

v16.0.0

New major version!

16.0.0 brings a major version update to the refractor dependency, which remedies some security issues but could result in a breaking change to your app's dependencies. Please update with care.

What's Changed

New Contributors

Full Changelog: react-syntax-highlighter/react-syntax-highlighter@v15.6.6...v16.0.0

Commits

Updates uuid from 11.1.1 to 14.0.2

Release notes

Sourced from uuid's releases.

v14.0.2

14.0.2 (2026-08-18)

Bug Fixes

  • v1: carry nsecs overflow into the timestamp's high bits (#972) (6adcc1d)
  • v1: set the multicast bit on v1Bytes's own randomly-generated node (#973) (b1da338)
  • v7: align default seq formula in v7Bytes with updateV7State (#965) (a67db57)

v14.0.1

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)

v14.0.0

14.0.0 (2026-04-19)

⚠ BREAKING CHANGES

  • expect crypto to be global everywhere (requires node@20+) (#935)
  • drop node@18 support (#934)

Features

Bug Fixes

  • expect crypto to be global everywhere (requires node@20+) (#935) (f2c235f)
  • Use GITHUB_TOKEN for release-please and enable npm provenance (#925) (ffa3138)

v13.0.2

13.0.2 (2026-05-04)

Bug Fixes

  • rerelease to fix provenance. (49ccb35)

v13.0.1

13.0.1 (2026-04-27)

Bug Fixes

... (truncated)

Changelog

Sourced from uuid's changelog.

14.0.2 (2026-08-18)

Bug Fixes

  • v1: carry n...

    Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 7, 2026
@dependabot
dependabot Bot requested a review from ezzy1630 as a code owner September 7, 2026 14:50
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 7, 2026
@deepsource-io

deepsource-io Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in c84c898...1606cf6 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Docker Sep 19, 2026 5:51p.m. Review ↗
JavaScript Sep 19, 2026 5:51p.m. Review ↗
Python Sep 19, 2026 5:51p.m. Review ↗
Rust Sep 19, 2026 5:51p.m. Review ↗
Shell Sep 19, 2026 5:51p.m. Review ↗
SQL Sep 19, 2026 5:51p.m. Review ↗
Secrets Sep 19, 2026 5:51p.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

ezzy1630 added a commit that referenced this pull request Sep 19, 2026
`bun audit --production` began failing on an unchanged tree as four
advisories published after this branch's last CI run:

- next <16.3.3 — two critical unauthenticated RCEs (GHSA-p293-qw3h-jr36 on
  Windows-hosted servers, GHSA-2xp9-vwfh-vxw4 in the Image Optimization API
  via AVIF). Now ^16.3.5.
- sharp <0.35.4 — bundled libheif vulnerabilities (GHSA-rgj7-g3m4-5g8c).
  Now ^0.35.4.
- js-yaml <4.3.2 — unbounded CPU on empty merge sources
  (GHSA-2883-xcg3-v3hh). It reaches the tree only through eslint and the
  desktop's electron-builder, but the existing `overrides` block pinned it to
  4.3.1 exactly, so the transitive consumers could not resolve the fix on
  their own; the pin moves to 4.3.2.

All three are patch-level within the ranges already in use. This is the
minimal security subset of Dependabot #62, not that PR's full 17-package
group bump.

Verified: `bun audit --production` reports no vulnerabilities; `just check-ts`
clean; `bun run build` compiles the Next app and generates its routes;
`bun run test:unit` 840 pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
ezzy1630 added a commit that referenced this pull request Sep 19, 2026
…al telemetry (#57)

* feat(retrieval): retrieval-v1 cohort, BM25 consolidation, and retrieval telemetry

- Build retrieval-v1 evaluation suite with 5 representative tasks covering named file edits, symptom-based discovery, and cross-file dependencies
- Consolidate canonical token-normalized BM25 implementation in @terminus/context-ir and remove duplicates in context-compiler and aci
- Extract kernelRetrievalPipeline into modular retrieval-pipeline.ts with chunked lexical candidate gated by adaptive profile
- Add RetrievalTelemetryCollector measuring queries, hits, miss rates, latency, and truncation failures
- Support A/A canary testing with identical commits and zero-delta verification

* docs(inventory): regenerate static inventory for test count additions

* fix(retrieval): resolve review feedback, harden graders and pipeline, and fix CI analyzers

- deepsource(js): resolve duplicate exports in bm25, replace function declarations with arrow constants, reduce cyclomatic complexity, remove unused imports, and eliminate static template strings
- deepsource(py): eliminate assert in non-test files, use sys.executable and shutil.which for subprocess calls, update test patterns in .deepsource.toml
- cubic(graders): inspect both uncommitted and committed changes against base commit, run hidden tests first to prevent tampering, validate non-empty root_cause in DISCOVERY.json, verify CLI sync retry propagation, and bound subprocess execution
- cubic(pipeline): bound lexical index cache with LRU eviction and in-flight build dedup, wrap latency accounting in finally block, prevent duplicate failure recording, record admitted fragments, and prioritize scoped paths
- cubic(canary): enforce identical commits and fail on non-zero resolved delta in A/A validation mode
- docs(inventory): regenerate static inventory for test count updates

* fix(retrieval): grant retrieval a READ capability and disclose bounded reads

The retrieval pipeline was handed `buildArtifactContext`, whose capability
token carries only ARTIFACT_INGEST and CODE_INTEL. `files.Read` requires
OperationClass::Read, so every hydration read failed authorization at the
kernel, and the reader's fail-soft `catch` swallowed the denial and returned
`content: null`. Retrieval silently degraded to metadata-only hits in
production while reporting a clean run. This is the same failure the
repository-signal read path already had to fix once.

Mint a dedicated retrieval context with READ + CODE_INTEL over the task's
declared scope, and count refused hydrations in a `hydrationFailures` metric
kept separate from `truncationOrContinuationFailures` — a bounded read still
yields content, a refused one does not, and folding them together would make
the existing metric lie.

A kernel read can also stop at its byte ceiling. `hydrateSearchHit` derived
truncation from `totalLines` alone, which cannot express that bound, so a
byte-truncated slice was rendered as a whole span. The reader now reports the
kernel's `truncated` flag and `continuationToken`, and the fragment header
states which bound was hit and how to continue.

Also from review:

- The retrieval-v1 `policy.yaml` files declared `allowed_commands`,
  `allowed_read_paths`, `allowed_write_paths`, `network`, and `max_memory_mb`.
  No runner reads any of them — `task_contract.py` composes only `risk_class`,
  budgets, secrets, and verification nodes, and the harness rejects scope
  composition from policy outright. The files stated a sandbox constraint that
  nothing enforced, and their write paths contradicted the pytest invocation
  the prompts require. Conform them to the SPEC §41.4 shape the rest of the
  corpus uses and record where write scope is actually enforced: the `scope`
  acceptance criterion and the grader's `git status` inspection.
- Graders ran submissions with `capture_output=True`, buffering an untrusted
  child's entire output before slicing it to 1,000 characters, so a noisy
  submission could exhaust the grader instead of failing. Stream into a
  bounded tail with a 4 MiB ceiling and kill the child past it; an over-limit
  or timed-out run can no longer be graded as a pass.
- Replace `export * from "./bm25.js"` with a named re-export; the wildcard
  pulled the context-ir re-export surface in behind it and made nine names
  ambiguous about which module owns them.

Verification: `just check-ts` clean (boundary, eslint, three typecheck
projects); control agent suite 368 pass; context-compiler 103 pass; python
529 pass; ruff and mypy clean; no codegen drift. The hardened grader runner
was exercised directly against normal, failing, and 200 MB-flooding children.

The cross-file grader finding was not applied: `test_cli_sync_retries` in the
hidden test does call `run_sync` and assert the propagated value, so the CLI
propagation is verified.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(deps): update rustls to 0.23.45 for RUSTSEC-2026-0285

Rustls accepted TLS 1.3 handshake messages sent at the wrong encryption
level when they followed a key-changing message in the same record, contrary
to RFC 8446 §5.1. The advisory published after this branch's last CI run, so
`cargo deny check` began failing on an unchanged tree.

rustls reaches the kernel through terminus-connector's reqwest/hyper-rustls
path, which is the transport for brokered outbound provider calls, so both
the workspace lockfile and the kernel mini-service lockfile are updated. The
kernel lockfile needed `--precise`: a plain `cargo update -p rustls` stopped
at 0.23.43, still inside the affected range.

Verified: `cargo deny check` reports "advisories ok, bans ok, licenses ok,
sources ok" for both the workspace and mini-services/terminus-kernel.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(deps): patch Next.js, sharp, and js-yaml advisories

`bun audit --production` began failing on an unchanged tree as four
advisories published after this branch's last CI run:

- next <16.3.3 — two critical unauthenticated RCEs (GHSA-p293-qw3h-jr36 on
  Windows-hosted servers, GHSA-2xp9-vwfh-vxw4 in the Image Optimization API
  via AVIF). Now ^16.3.5.
- sharp <0.35.4 — bundled libheif vulnerabilities (GHSA-rgj7-g3m4-5g8c).
  Now ^0.35.4.
- js-yaml <4.3.2 — unbounded CPU on empty merge sources
  (GHSA-2883-xcg3-v3hh). It reaches the tree only through eslint and the
  desktop's electron-builder, but the existing `overrides` block pinned it to
  4.3.1 exactly, so the transitive consumers could not resolve the fix on
  their own; the pin moves to 4.3.2.

All three are patch-level within the ranges already in use. This is the
minimal security subset of Dependabot #62, not that PR's full 17-package
group bump.

Verified: `bun audit --production` reports no vulnerabilities; `just check-ts`
clean; `bun run build` compiles the Next app and generates its routes;
`bun run test:unit` 840 pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…y with 17 updates

Bumps the javascript-dependencies group with 17 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@prisma/client](https://github.com/prisma/prisma/tree/HEAD/packages/client) | `6.19.3` | `7.10.0` |
| [@tanstack/react-table](https://github.com/TanStack/table/tree/HEAD/packages/react-table) | `8.21.3` | `9.2.4` |
| [framer-motion](https://github.com/motiondivision/motion) | `12.43.0` | `13.4.0` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `0.525.0` | `1.46.0` |
| [prisma](https://github.com/prisma/prisma-cli/tree/HEAD/packages/prisma) | `6.19.3` | `7.10.0` |
| [react-day-picker](https://github.com/gpbl/react-day-picker/tree/HEAD/packages/react-day-picker) | `9.14.0` | `10.0.1` |
| [react-resizable-panels](https://github.com/bvaughn/react-resizable-panels) | `3.0.6` | `4.12.4` |
| [react-syntax-highlighter](https://github.com/react-syntax-highlighter/react-syntax-highlighter) | `15.6.6` | `16.1.1` |
| [uuid](https://github.com/uuidjs/uuid) | `11.1.1` | `14.0.2` |
| [@electron/asar](https://github.com/electron/asar) | `3.4.1` | `4.3.0` |
| [eslint](https://github.com/eslint/eslint) | `9.39.5` | `10.10.0` |
| [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.2.10` | `16.3.5` |
| [minimatch](https://github.com/isaacs/minimatch) | `3.1.5` | `10.2.6` |
| [typescript](https://github.com/microsoft/TypeScript) | `5.9.3` | `7.0.2` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.11` | `5.0.1` |
| [electron](https://github.com/electron/electron) | `43.7.3` | `44.4.1` |
| [undici](https://github.com/nodejs/undici) | `7.29.1` | `8.10.2` |



Updates `@prisma/client` from 6.19.3 to 7.10.0
- [Release notes](https://github.com/prisma/prisma/releases)
- [Commits](https://github.com/prisma/prisma/commits/7.10.0/packages/client)

Updates `@tanstack/react-table` from 8.21.3 to 9.2.4
- [Release notes](https://github.com/TanStack/table/releases)
- [Changelog](https://github.com/TanStack/table/blob/main/packages/react-table/CHANGELOG.md)
- [Commits](https://github.com/TanStack/table/commits/@tanstack/react-table@9.2.4/packages/react-table)

Updates `framer-motion` from 12.43.0 to 13.4.0
- [Changelog](https://github.com/motiondivision/motion/blob/main/CHANGELOG.md)
- [Commits](motiondivision/motion@v12.43.0...v13.4.0)

Updates `lucide-react` from 0.525.0 to 1.46.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.46.0/packages/lucide-react)

Updates `prisma` from 6.19.3 to 7.10.0
- [Release notes](https://github.com/prisma/prisma-cli/releases)
- [Commits](https://github.com/prisma/prisma-cli/commits/HEAD/packages/prisma)

Updates `react-day-picker` from 9.14.0 to 10.0.1
- [Release notes](https://github.com/gpbl/react-day-picker/releases)
- [Changelog](https://github.com/gpbl/react-day-picker/blob/main/packages/react-day-picker/CHANGELOG.md)
- [Commits](https://github.com/gpbl/react-day-picker/commits/v10.0.1/packages/react-day-picker)

Updates `react-resizable-panels` from 3.0.6 to 4.12.4
- [Release notes](https://github.com/bvaughn/react-resizable-panels/releases)
- [Changelog](https://github.com/bvaughn/react-resizable-panels/blob/main/CHANGELOG.md)
- [Commits](bvaughn/react-resizable-panels@3.0.6...4.12.4)

Updates `react-syntax-highlighter` from 15.6.6 to 16.1.1
- [Release notes](https://github.com/react-syntax-highlighter/react-syntax-highlighter/releases)
- [Changelog](https://github.com/react-syntax-highlighter/react-syntax-highlighter/blob/master/CHANGELOG.MD)
- [Commits](react-syntax-highlighter/react-syntax-highlighter@v15.6.6...v16.1.1)

Updates `uuid` from 11.1.1 to 14.0.2
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v11.1.1...v14.0.2)

Updates `@electron/asar` from 3.4.1 to 4.3.0
- [Release notes](https://github.com/electron/asar/releases)
- [Changelog](https://github.com/electron/asar/blob/main/CHANGELOG.md)
- [Commits](electron/asar@v3.4.1...v4.3.0)

Updates `eslint` from 9.39.5 to 10.10.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v9.39.5...v10.10.0)

Updates `eslint-config-next` from 16.2.10 to 16.3.5
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](https://github.com/vercel/next.js/commits/v16.3.5/packages/eslint-config-next)

Updates `minimatch` from 3.1.5 to 10.2.6
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v3.1.5...v10.2.6)

Updates `typescript` from 5.9.3 to 7.0.2
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v5.9.3...v7.0.2)

Updates `vitest` from 4.1.11 to 5.0.1
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/vitest)

Updates `electron` from 43.7.3 to 44.4.1
- [Release notes](https://github.com/electron/electron/releases)
- [Commits](electron/electron@v43.7.3...v44.4.1)

Updates `undici` from 7.29.1 to 8.10.2
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.29.1...v8.10.2)

---
updated-dependencies:
- dependency-name: "@electron/asar"
  dependency-version: 4.3.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: javascript-dependencies
- dependency-name: "@prisma/client"
  dependency-version: 7.10.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: javascript-dependencies
- dependency-name: "@tanstack/react-table"
  dependency-version: 9.2.4
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: javascript-dependencies
- dependency-name: electron
  dependency-version: 44.2.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: javascript-dependencies
- dependency-name: eslint
  dependency-version: 10.10.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: javascript-dependencies
- dependency-name: eslint-config-next
  dependency-version: 16.3.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: javascript-dependencies
- dependency-name: framer-motion
  dependency-version: 13.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: javascript-dependencies
- dependency-name: lucide-react
  dependency-version: 1.41.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: javascript-dependencies
- dependency-name: minimatch
  dependency-version: 10.2.6
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: javascript-dependencies
- dependency-name: prisma
  dependency-version: 7.10.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: javascript-dependencies
- dependency-name: react-day-picker
  dependency-version: 10.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: javascript-dependencies
- dependency-name: react-resizable-panels
  dependency-version: 4.12.3
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: javascript-dependencies
- dependency-name: react-syntax-highlighter
  dependency-version: 16.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: javascript-dependencies
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: javascript-dependencies
- dependency-name: undici
  dependency-version: 8.10.2
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: javascript-dependencies
- dependency-name: uuid
  dependency-version: 14.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: javascript-dependencies
- dependency-name: vitest
  dependency-version: 5.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: javascript-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump the javascript-dependencies group with 17 updates chore(deps): bump the javascript-dependencies group across 1 directory with 17 updates Sep 19, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/javascript-dependencies-71eeb05d16 branch from 9828650 to 1606cf6 Compare September 19, 2026 17:51
@coderabbitai

coderabbitai Bot commented Sep 19, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: c9332639-068f-4f15-85d6-f3f6fe460500

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Author

Dependabot could not run Bun to update your dependencies due to a configuration error. Because of this, Dependabot cannot update this pull request.

1 similar comment
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Author

Dependabot could not run Bun to update your dependencies due to a configuration error. Because of this, Dependabot cannot update this pull request.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants