Skip to content

chore: consolidate Dependabot dependency updates - #38

Merged
SHIVAM (ShivamGoyal03) merged 2 commits into
Azure-Samples:mainfrom
ShivamGoyal03:chore/consolidate-dependabot-updates
Sep 10, 2026
Merged

SHIVAM (ShivamGoyal03) merged 2 commits into
Azure-Samples:mainfrom
ShivamGoyal03:chore/consolidate-dependabot-updates

Conversation

@ShivamGoyal03

@ShivamGoyal03 SHIVAM (ShivamGoyal03) commented Sep 10, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Consolidates the currently open Dependabot updates into one tested pull request:

Validation performed

  • python -m pytest -q — 137 passed, 10 skipped (Azure-dependent tests)
  • python run_local.py scenarios/ecommerce.yaml — completed successfully and generated output/review_bundle.json
  • npm --prefix frontend run build — completed successfully with Vite 8.0.16
  • API happy path — health, review, upload, PNG download, Excalidraw download, SPA serving, invalid run ID, and empty input checks passed

Notes

The skipped tests require external Azure/LLM services and were not run against live credentials.

Install and validate the pending frontend and GitHub Actions dependency updates in one change set.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The Vite 8 upgrade introduces stricter Node engine requirements that aren’t currently made explicit in frontend/package.json, which can lead to install/build failures for contributors or CI using older Node versions.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Consolidates multiple Dependabot updates into a single PR by upgrading key frontend build/runtime dependencies (Excalidraw, nanoid, Vite/plugin-react and transitive lockfile updates) and bumping actions/github-script in the issue-management workflow to a pinned v9 commit.

Changes:

  • Bumped @excalidraw/excalidraw and nanoid in the frontend.
  • Upgraded the frontend toolchain to vite@8 and @vitejs/plugin-react@5.2.0, refreshing package-lock.json with updated transitive dependencies.
  • Updated .github/workflows/issue-management.yml to use actions/github-script v9 pinned by immutable SHA.
File summaries
File Description
frontend/package.json Updates top-level frontend dependency and devDependency versions (Excalidraw, nanoid, Vite/plugin-react).
frontend/package-lock.json Regenerates the lockfile to reflect updated frontend dependencies and new transitive graph (e.g., Vite 8 + rolldown).
.github/workflows/issue-management.yml Bumps actions/github-script to the pinned v9.0.0 commit SHA for the issue automation job.
Review details

Files not reviewed (1)

  • frontend/package-lock.json: Generated file
  • Files reviewed: 2/3 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread frontend/package.json
Comment on lines 13 to +16
"license": "MIT",
"dependencies": {
"@excalidraw/excalidraw": "^0.18.0",
"nanoid": "^5.1.6",
"@excalidraw/excalidraw": "^0.18.1",
"nanoid": "^5.1.16",

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in bb34ba6. Added an explicit engines field to frontend/package.json declaring "node": "^20.19.0 || >=22.12.0", matching the constraint that Vite 8 and rolldown 1.0.3 declare in the lockfile. Also bumped the Dockerfile.web frontend build stage from node:20-slim to node:22-slim and documented the requirement in the prerequisites section of AGENTS.md.

Comment thread frontend/package.json
Comment on lines 26 to +28
"devDependencies": {
"@vitejs/plugin-react": "^5.1.4",
"vite": "^7.3.1"
"@vitejs/plugin-react": "^5.2.0",
"vite": "^8.0.16"

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in bb34ba6. Confirmed the lockfile contains zero node_modules/rollup* entries after the Vite 8 upgrade (Vite 8 bundles with rolldown instead), so the override was inert. Removed it and regenerated the lockfile; the only resulting change was the new engines entry, which confirms the override had no effect on resolution. The remaining nanoid, immutable, and dompurify overrides were verified as still present in the dependency tree and were kept.

Declare the Node engine range required by Vite 8, drop the now-unused rollup override, and align the web Docker build image and prerequisites documentation.
@ShivamGoyal03

Copy link
Copy Markdown
Collaborator Author

Both Copilot review comments have been addressed in bb34ba6.

1. Missing Node engine declaration — Added engines: { "node": "^20.19.0 || >=22.12.0" } to frontend/package.json, matching what Vite 8.0.16 and rolldown 1.0.3 declare. Also bumped the Dockerfile.web frontend build stage to node:22-slim and documented the requirement in AGENTS.md.

2. Unused rollup override — Verified the lockfile has no node_modules/rollup* entries after the Vite 8 upgrade, then removed the override. Regenerating the lockfile produced no resolution changes, confirming it was inert. The nanoid, immutable, and dompurify overrides remain and are still active in the tree.

Re-validation after the changes

Check Result
python -m pytest -q 137 passed, 10 skipped
npm ci + npm run build Passed (Vite 8.0.16)
API health / review / PNG download / SPA All 200

@ShivamGoyal03
SHIVAM (ShivamGoyal03) merged commit 9828e16 into Azure-Samples:main Sep 10, 2026
1 check passed
@ShivamGoyal03
SHIVAM (ShivamGoyal03) deleted the chore/consolidate-dependabot-updates branch September 10, 2026 16:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants