chore(deps): bump the javascript-dependencies group across 1 directory with 17 updates - #62
dependabot[bot] wants to merge 1 commit into
Conversation
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| Docker | Sep 19, 2026 5:51p.m. | Review ↗ | |
| JavaScript | Sep 19, 2026 5:51p.m. | Review ↗ | |
| Python | Sep 19, 2026 5:51p.m. | Review ↗ | |
| Rust | Sep 19, 2026 5:51p.m. | Review ↗ | |
| Shell | Sep 19, 2026 5:51p.m. | Review ↗ | |
| SQL | Sep 19, 2026 5:51p.m. | Review ↗ | |
| Secrets | Sep 19, 2026 5:51p.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
`bun audit --production` began failing on an unchanged tree as four advisories published after this branch's last CI run: - next <16.3.3 — two critical unauthenticated RCEs (GHSA-p293-qw3h-jr36 on Windows-hosted servers, GHSA-2xp9-vwfh-vxw4 in the Image Optimization API via AVIF). Now ^16.3.5. - sharp <0.35.4 — bundled libheif vulnerabilities (GHSA-rgj7-g3m4-5g8c). Now ^0.35.4. - js-yaml <4.3.2 — unbounded CPU on empty merge sources (GHSA-2883-xcg3-v3hh). It reaches the tree only through eslint and the desktop's electron-builder, but the existing `overrides` block pinned it to 4.3.1 exactly, so the transitive consumers could not resolve the fix on their own; the pin moves to 4.3.2. All three are patch-level within the ranges already in use. This is the minimal security subset of Dependabot #62, not that PR's full 17-package group bump. Verified: `bun audit --production` reports no vulnerabilities; `just check-ts` clean; `bun run build` compiles the Next app and generates its routes; `bun run test:unit` 840 pass. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…al telemetry (#57) * feat(retrieval): retrieval-v1 cohort, BM25 consolidation, and retrieval telemetry - Build retrieval-v1 evaluation suite with 5 representative tasks covering named file edits, symptom-based discovery, and cross-file dependencies - Consolidate canonical token-normalized BM25 implementation in @terminus/context-ir and remove duplicates in context-compiler and aci - Extract kernelRetrievalPipeline into modular retrieval-pipeline.ts with chunked lexical candidate gated by adaptive profile - Add RetrievalTelemetryCollector measuring queries, hits, miss rates, latency, and truncation failures - Support A/A canary testing with identical commits and zero-delta verification * docs(inventory): regenerate static inventory for test count additions * fix(retrieval): resolve review feedback, harden graders and pipeline, and fix CI analyzers - deepsource(js): resolve duplicate exports in bm25, replace function declarations with arrow constants, reduce cyclomatic complexity, remove unused imports, and eliminate static template strings - deepsource(py): eliminate assert in non-test files, use sys.executable and shutil.which for subprocess calls, update test patterns in .deepsource.toml - cubic(graders): inspect both uncommitted and committed changes against base commit, run hidden tests first to prevent tampering, validate non-empty root_cause in DISCOVERY.json, verify CLI sync retry propagation, and bound subprocess execution - cubic(pipeline): bound lexical index cache with LRU eviction and in-flight build dedup, wrap latency accounting in finally block, prevent duplicate failure recording, record admitted fragments, and prioritize scoped paths - cubic(canary): enforce identical commits and fail on non-zero resolved delta in A/A validation mode - docs(inventory): regenerate static inventory for test count updates * fix(retrieval): grant retrieval a READ capability and disclose bounded reads The retrieval pipeline was handed `buildArtifactContext`, whose capability token carries only ARTIFACT_INGEST and CODE_INTEL. `files.Read` requires OperationClass::Read, so every hydration read failed authorization at the kernel, and the reader's fail-soft `catch` swallowed the denial and returned `content: null`. Retrieval silently degraded to metadata-only hits in production while reporting a clean run. This is the same failure the repository-signal read path already had to fix once. Mint a dedicated retrieval context with READ + CODE_INTEL over the task's declared scope, and count refused hydrations in a `hydrationFailures` metric kept separate from `truncationOrContinuationFailures` — a bounded read still yields content, a refused one does not, and folding them together would make the existing metric lie. A kernel read can also stop at its byte ceiling. `hydrateSearchHit` derived truncation from `totalLines` alone, which cannot express that bound, so a byte-truncated slice was rendered as a whole span. The reader now reports the kernel's `truncated` flag and `continuationToken`, and the fragment header states which bound was hit and how to continue. Also from review: - The retrieval-v1 `policy.yaml` files declared `allowed_commands`, `allowed_read_paths`, `allowed_write_paths`, `network`, and `max_memory_mb`. No runner reads any of them — `task_contract.py` composes only `risk_class`, budgets, secrets, and verification nodes, and the harness rejects scope composition from policy outright. The files stated a sandbox constraint that nothing enforced, and their write paths contradicted the pytest invocation the prompts require. Conform them to the SPEC §41.4 shape the rest of the corpus uses and record where write scope is actually enforced: the `scope` acceptance criterion and the grader's `git status` inspection. - Graders ran submissions with `capture_output=True`, buffering an untrusted child's entire output before slicing it to 1,000 characters, so a noisy submission could exhaust the grader instead of failing. Stream into a bounded tail with a 4 MiB ceiling and kill the child past it; an over-limit or timed-out run can no longer be graded as a pass. - Replace `export * from "./bm25.js"` with a named re-export; the wildcard pulled the context-ir re-export surface in behind it and made nine names ambiguous about which module owns them. Verification: `just check-ts` clean (boundary, eslint, three typecheck projects); control agent suite 368 pass; context-compiler 103 pass; python 529 pass; ruff and mypy clean; no codegen drift. The hardened grader runner was exercised directly against normal, failing, and 200 MB-flooding children. The cross-file grader finding was not applied: `test_cli_sync_retries` in the hidden test does call `run_sync` and assert the propagated value, so the CLI propagation is verified. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(deps): update rustls to 0.23.45 for RUSTSEC-2026-0285 Rustls accepted TLS 1.3 handshake messages sent at the wrong encryption level when they followed a key-changing message in the same record, contrary to RFC 8446 §5.1. The advisory published after this branch's last CI run, so `cargo deny check` began failing on an unchanged tree. rustls reaches the kernel through terminus-connector's reqwest/hyper-rustls path, which is the transport for brokered outbound provider calls, so both the workspace lockfile and the kernel mini-service lockfile are updated. The kernel lockfile needed `--precise`: a plain `cargo update -p rustls` stopped at 0.23.43, still inside the affected range. Verified: `cargo deny check` reports "advisories ok, bans ok, licenses ok, sources ok" for both the workspace and mini-services/terminus-kernel. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(deps): patch Next.js, sharp, and js-yaml advisories `bun audit --production` began failing on an unchanged tree as four advisories published after this branch's last CI run: - next <16.3.3 — two critical unauthenticated RCEs (GHSA-p293-qw3h-jr36 on Windows-hosted servers, GHSA-2xp9-vwfh-vxw4 in the Image Optimization API via AVIF). Now ^16.3.5. - sharp <0.35.4 — bundled libheif vulnerabilities (GHSA-rgj7-g3m4-5g8c). Now ^0.35.4. - js-yaml <4.3.2 — unbounded CPU on empty merge sources (GHSA-2883-xcg3-v3hh). It reaches the tree only through eslint and the desktop's electron-builder, but the existing `overrides` block pinned it to 4.3.1 exactly, so the transitive consumers could not resolve the fix on their own; the pin moves to 4.3.2. All three are patch-level within the ranges already in use. This is the minimal security subset of Dependabot #62, not that PR's full 17-package group bump. Verified: `bun audit --production` reports no vulnerabilities; `just check-ts` clean; `bun run build` compiles the Next app and generates its routes; `bun run test:unit` 840 pass. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…y with 17 updates Bumps the javascript-dependencies group with 17 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@prisma/client](https://github.com/prisma/prisma/tree/HEAD/packages/client) | `6.19.3` | `7.10.0` | | [@tanstack/react-table](https://github.com/TanStack/table/tree/HEAD/packages/react-table) | `8.21.3` | `9.2.4` | | [framer-motion](https://github.com/motiondivision/motion) | `12.43.0` | `13.4.0` | | [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `0.525.0` | `1.46.0` | | [prisma](https://github.com/prisma/prisma-cli/tree/HEAD/packages/prisma) | `6.19.3` | `7.10.0` | | [react-day-picker](https://github.com/gpbl/react-day-picker/tree/HEAD/packages/react-day-picker) | `9.14.0` | `10.0.1` | | [react-resizable-panels](https://github.com/bvaughn/react-resizable-panels) | `3.0.6` | `4.12.4` | | [react-syntax-highlighter](https://github.com/react-syntax-highlighter/react-syntax-highlighter) | `15.6.6` | `16.1.1` | | [uuid](https://github.com/uuidjs/uuid) | `11.1.1` | `14.0.2` | | [@electron/asar](https://github.com/electron/asar) | `3.4.1` | `4.3.0` | | [eslint](https://github.com/eslint/eslint) | `9.39.5` | `10.10.0` | | [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.2.10` | `16.3.5` | | [minimatch](https://github.com/isaacs/minimatch) | `3.1.5` | `10.2.6` | | [typescript](https://github.com/microsoft/TypeScript) | `5.9.3` | `7.0.2` | | [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.1.11` | `5.0.1` | | [electron](https://github.com/electron/electron) | `43.7.3` | `44.4.1` | | [undici](https://github.com/nodejs/undici) | `7.29.1` | `8.10.2` | Updates `@prisma/client` from 6.19.3 to 7.10.0 - [Release notes](https://github.com/prisma/prisma/releases) - [Commits](https://github.com/prisma/prisma/commits/7.10.0/packages/client) Updates `@tanstack/react-table` from 8.21.3 to 9.2.4 - [Release notes](https://github.com/TanStack/table/releases) - [Changelog](https://github.com/TanStack/table/blob/main/packages/react-table/CHANGELOG.md) - [Commits](https://github.com/TanStack/table/commits/@tanstack/react-table@9.2.4/packages/react-table) Updates `framer-motion` from 12.43.0 to 13.4.0 - [Changelog](https://github.com/motiondivision/motion/blob/main/CHANGELOG.md) - [Commits](motiondivision/motion@v12.43.0...v13.4.0) Updates `lucide-react` from 0.525.0 to 1.46.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.46.0/packages/lucide-react) Updates `prisma` from 6.19.3 to 7.10.0 - [Release notes](https://github.com/prisma/prisma-cli/releases) - [Commits](https://github.com/prisma/prisma-cli/commits/HEAD/packages/prisma) Updates `react-day-picker` from 9.14.0 to 10.0.1 - [Release notes](https://github.com/gpbl/react-day-picker/releases) - [Changelog](https://github.com/gpbl/react-day-picker/blob/main/packages/react-day-picker/CHANGELOG.md) - [Commits](https://github.com/gpbl/react-day-picker/commits/v10.0.1/packages/react-day-picker) Updates `react-resizable-panels` from 3.0.6 to 4.12.4 - [Release notes](https://github.com/bvaughn/react-resizable-panels/releases) - [Changelog](https://github.com/bvaughn/react-resizable-panels/blob/main/CHANGELOG.md) - [Commits](bvaughn/react-resizable-panels@3.0.6...4.12.4) Updates `react-syntax-highlighter` from 15.6.6 to 16.1.1 - [Release notes](https://github.com/react-syntax-highlighter/react-syntax-highlighter/releases) - [Changelog](https://github.com/react-syntax-highlighter/react-syntax-highlighter/blob/master/CHANGELOG.MD) - [Commits](react-syntax-highlighter/react-syntax-highlighter@v15.6.6...v16.1.1) Updates `uuid` from 11.1.1 to 14.0.2 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v11.1.1...v14.0.2) Updates `@electron/asar` from 3.4.1 to 4.3.0 - [Release notes](https://github.com/electron/asar/releases) - [Changelog](https://github.com/electron/asar/blob/main/CHANGELOG.md) - [Commits](electron/asar@v3.4.1...v4.3.0) Updates `eslint` from 9.39.5 to 10.10.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v9.39.5...v10.10.0) Updates `eslint-config-next` from 16.2.10 to 16.3.5 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](https://github.com/vercel/next.js/commits/v16.3.5/packages/eslint-config-next) Updates `minimatch` from 3.1.5 to 10.2.6 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.1.5...v10.2.6) Updates `typescript` from 5.9.3 to 7.0.2 - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](microsoft/TypeScript@v5.9.3...v7.0.2) Updates `vitest` from 4.1.11 to 5.0.1 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/vitest) Updates `electron` from 43.7.3 to 44.4.1 - [Release notes](https://github.com/electron/electron/releases) - [Commits](electron/electron@v43.7.3...v44.4.1) Updates `undici` from 7.29.1 to 8.10.2 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.29.1...v8.10.2) --- updated-dependencies: - dependency-name: "@electron/asar" dependency-version: 4.3.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: javascript-dependencies - dependency-name: "@prisma/client" dependency-version: 7.10.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: javascript-dependencies - dependency-name: "@tanstack/react-table" dependency-version: 9.2.4 dependency-type: direct:production update-type: version-update:semver-major dependency-group: javascript-dependencies - dependency-name: electron dependency-version: 44.2.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: javascript-dependencies - dependency-name: eslint dependency-version: 10.10.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: javascript-dependencies - dependency-name: eslint-config-next dependency-version: 16.3.4 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: javascript-dependencies - dependency-name: framer-motion dependency-version: 13.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: javascript-dependencies - dependency-name: lucide-react dependency-version: 1.41.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: javascript-dependencies - dependency-name: minimatch dependency-version: 10.2.6 dependency-type: direct:development update-type: version-update:semver-major dependency-group: javascript-dependencies - dependency-name: prisma dependency-version: 7.10.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: javascript-dependencies - dependency-name: react-day-picker dependency-version: 10.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: javascript-dependencies - dependency-name: react-resizable-panels dependency-version: 4.12.3 dependency-type: direct:production update-type: version-update:semver-major dependency-group: javascript-dependencies - dependency-name: react-syntax-highlighter dependency-version: 16.1.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: javascript-dependencies - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major dependency-group: javascript-dependencies - dependency-name: undici dependency-version: 8.10.2 dependency-type: direct:development update-type: version-update:semver-major dependency-group: javascript-dependencies - dependency-name: uuid dependency-version: 14.0.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: javascript-dependencies - dependency-name: vitest dependency-version: 5.0.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: javascript-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
9828650 to
1606cf6
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Dependabot could not run Bun to update your dependencies due to a configuration error. Because of this, Dependabot cannot update this pull request. |
1 similar comment
|
Dependabot could not run Bun to update your dependencies due to a configuration error. Because of this, Dependabot cannot update this pull request. |
Bumps the javascript-dependencies group with 17 updates in the / directory:
6.19.37.10.08.21.39.2.412.43.013.4.00.525.01.46.06.19.37.10.09.14.010.0.13.0.64.12.415.6.616.1.111.1.114.0.23.4.14.3.09.39.510.10.016.2.1016.3.53.1.510.2.65.9.37.0.24.1.115.0.143.7.344.4.17.29.18.10.2Updates
@prisma/clientfrom 6.19.3 to 7.10.0Release notes
Sourced from @prisma/client's releases.
... (truncated)
Commits
05c1b88Teach Prisma 7 to prefer versioned config files (#30020)cf2bc1fRename prisma7 package to@prisma/prisma7(#30002)ce5a34cComplete downstream actionable Prisma 7 guidance propagation (#29994)3f13ec6Complete CLI-owned prisma7 distribution identity (#29969)179ba0cfeat(prisma7): add side-by-side CLI wrapper (#29949)3fa65acfix(p2002): correct modelName in nested create unique constraint errors #2959...6b6d9e9chore(deps): update engines to 7.10.0-4.0edf323efd1d98336f3f0a68684b56f689b90...b64e33cchore(deps): update engines to 7.10.0-3.9d90ce2c89d5c95a1148aef15e5561ab6c490...2046f9bfeat(client): expose ModelName to compute function in Result extensions (#29782)f2b3abdchore(deps): update engines to 7.10.0-1.6d040c802892de6d56c7e0061b7a10b3e6a0c...Updates
@tanstack/react-tablefrom 8.21.3 to 9.2.4Release notes
Sourced from @tanstack/react-table's releases.
... (truncated)
Changelog
Sourced from @tanstack/react-table's changelog.
... (truncated)
Commits
d01c01bci: Version Packages (#6580)f72e516fix: Add realtime (w/ fake data) trading table example (#6561)3bfc1bfci: Version Packages (#6575)ac4f134docs: add react compiler guidefaa261bfeat: support latest TanStack Devtools and refresh package versions (#6553)ff7653dci: Version Packages (#6533)ff43666refactor(table-core): centralize no-op state update guarding in setStateSlice...058a520ci: Version Packages (#6531)3af6abcci: Version Packages (#6527)896e998ci: Version Packages (#6525)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@tanstack/react-tablesince your current version.Updates
framer-motionfrom 12.43.0 to 13.4.0Changelog
Sourced from framer-motion's changelog.
... (truncated)
Commits
a6ea2f9v13.4.0d6ef844Changelog75c4dcfMerge pull request #3824 from motiondivision/codex/react-animate-viewa5a7856Co-locate AnimateView layer animation in framer-motion5c8bc09Keep AnimateView group morph with custom values; gate view tests in Playwright12018e8Add AnimateView via motion/react-animate-view939c267Updating changelog16cf742Latest49f1fe1v13.3.0f777c92Updating changelogUpdates
lucide-reactfrom 0.525.0 to 1.46.0Release notes
Sourced from lucide-react's releases.
... (truncated)
Commits
94e4cb9chore(dependencies): Update dependencies (#4806)99d25bdfeat(packages): extract icon build logic into@lucide/shared(#4409)75b5516chore(dev): upgrade ESLint to latest compatible stack (v10) (#4378)0f8d48btest(packages): updates unit test snapshots with face-slightly-smiling (#4676)f229f83chore(depedencies): Update dependencies (#4553)5ff536eci(release.yml): Fix workflow and removeversionscripts in package scripts...07c885efix(docs): fix zephyr-cloud URL in readmes50d8af5docs(readme): Update readme files (#4320)653e44bfeat(packages): use .mjs for ESM bundles (#4285)7623e23feat(docs): add Zephyr Cloud to Hero Backers tier & rework updateSponsors scr...Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for lucide-react since your current version.
Updates
prismafrom 6.19.3 to 7.10.0Commits
Attestation changes
This version has no provenance attestation, while the previous version (6.19.3) was attested. Review the package versions before updating.
Updates
react-day-pickerfrom 9.14.0 to 10.0.1Release notes
Sourced from react-day-picker's releases.
... (truncated)
Changelog
Sourced from react-day-picker's changelog.
... (truncated)
Commits
6d3929dbuild: version packages (#2996)885ec9efix: add@types/reactas optional peer dependency (#2997)42c8436fix: apply inline styles to component slots (#2995)4cce3e2docs: remove next install references9af420cdocs: promote v10 website docs (#2990)2c5ba1fbuild: version packages (#2989)b55a878fix: correct dropdown navigation in multi-month calendars (#2977)6af9b1fdocs: fill type alias API descriptions (#2991)2907c64build: version packages (next) (#2965)cdc5a64docs: update v8 website referencesUpdates
react-resizable-panelsfrom 3.0.6 to 4.12.4Release notes
Sourced from react-resizable-panels's releases.
... (truncated)
Changelog
Sourced from react-resizable-panels's changelog.
... (truncated)
Commits
152b1a84.12.3 -> 4.12.4f711534fix: skip pointer capture for detached separators (#743)2419acffix: use group-relative panel index for Separator aria values (Fixes #740) (#...f9c42274.12.2 -> 4.12.330503d1Fix derived Panel constraints equality check (#736)30aef6aPending CHANGELOGb1d574efix: guard CSSStyleSheet construction with adoptedStyleSheets check (#730)6649f42fix: don't resurrect stale group entries on pointer-up commit (Fixes #729) (#...a1eeb7a4.12.1 -> 4.12.23e877a14.12.0 -> 4.12.1Updates
react-syntax-highlighterfrom 15.6.6 to 16.1.1Release notes
Sourced from react-syntax-highlighter's releases.
Commits
ecac533new package lock4957908version bump5853a48Fix: grammar in README.md (#622)fc5d7b7fix: Added a babel plugin to auto add the js exts for esm (#627)d2b43e0Updated installation section in README.md (#633)5eedb7416.1.0c71356ffix refractor imports, migrate to webpack 5, update deps (#621)f024a8cRevert "chore: bump Webpack to v5 (#594)"7b0027bchore: bump Webpack to v5 (#594)9dafbf1Bump simple-git and lint-staged (#614)Updates
uuidfrom 11.1.1 to 14.0.2Release notes
Sourced from uuid's releases.
... (truncated)
Changelog
Sourced from uuid's changelog.