chore: consolidate Dependabot dependency updates - #38
SHIVAM (ShivamGoyal03) merged 2 commits into
Conversation
Install and validate the pending frontend and GitHub Actions dependency updates in one change set.
There was a problem hiding this comment.
🟡 Changes recommended
The Vite 8 upgrade introduces stricter Node engine requirements that aren’t currently made explicit in frontend/package.json, which can lead to install/build failures for contributors or CI using older Node versions.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Consolidates multiple Dependabot updates into a single PR by upgrading key frontend build/runtime dependencies (Excalidraw, nanoid, Vite/plugin-react and transitive lockfile updates) and bumping actions/github-script in the issue-management workflow to a pinned v9 commit.
Changes:
- Bumped
@excalidraw/excalidrawandnanoidin the frontend. - Upgraded the frontend toolchain to
vite@8and@vitejs/plugin-react@5.2.0, refreshingpackage-lock.jsonwith updated transitive dependencies. - Updated
.github/workflows/issue-management.ymlto useactions/github-scriptv9 pinned by immutable SHA.
File summaries
| File | Description |
|---|---|
| frontend/package.json | Updates top-level frontend dependency and devDependency versions (Excalidraw, nanoid, Vite/plugin-react). |
| frontend/package-lock.json | Regenerates the lockfile to reflect updated frontend dependencies and new transitive graph (e.g., Vite 8 + rolldown). |
| .github/workflows/issue-management.yml | Bumps actions/github-script to the pinned v9.0.0 commit SHA for the issue automation job. |
Review details
Files not reviewed (1)
- frontend/package-lock.json: Generated file
- Files reviewed: 2/3 changed files
- Comments generated: 2
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| "license": "MIT", | ||
| "dependencies": { | ||
| "@excalidraw/excalidraw": "^0.18.0", | ||
| "nanoid": "^5.1.6", | ||
| "@excalidraw/excalidraw": "^0.18.1", | ||
| "nanoid": "^5.1.16", |
There was a problem hiding this comment.
Addressed in bb34ba6. Added an explicit engines field to frontend/package.json declaring "node": "^20.19.0 || >=22.12.0", matching the constraint that Vite 8 and rolldown 1.0.3 declare in the lockfile. Also bumped the Dockerfile.web frontend build stage from node:20-slim to node:22-slim and documented the requirement in the prerequisites section of AGENTS.md.
| "devDependencies": { | ||
| "@vitejs/plugin-react": "^5.1.4", | ||
| "vite": "^7.3.1" | ||
| "@vitejs/plugin-react": "^5.2.0", | ||
| "vite": "^8.0.16" |
There was a problem hiding this comment.
Addressed in bb34ba6. Confirmed the lockfile contains zero node_modules/rollup* entries after the Vite 8 upgrade (Vite 8 bundles with rolldown instead), so the override was inert. Removed it and regenerated the lockfile; the only resulting change was the new engines entry, which confirms the override had no effect on resolution. The remaining nanoid, immutable, and dompurify overrides were verified as still present in the dependency tree and were kept.
Declare the Node engine range required by Vite 8, drop the now-unused rollup override, and align the web Docker build image and prerequisites documentation.
|
Both Copilot review comments have been addressed in bb34ba6. 1. Missing Node engine declaration — Added 2. Unused rollup override — Verified the lockfile has no Re-validation after the changes
|
Summary
Consolidates the currently open Dependabot updates into one tested pull request:
actions/github-scriptfrom v7.1.0 to v9.0.0 using the verified immutable commit SHA3a2844b7e9c422d3c10d287c895573f7108da1b3.Validation performed
python -m pytest -q— 137 passed, 10 skipped (Azure-dependent tests)python run_local.py scenarios/ecommerce.yaml— completed successfully and generatedoutput/review_bundle.jsonnpm --prefix frontend run build— completed successfully with Vite 8.0.16Notes
The skipped tests require external Azure/LLM services and were not run against live credentials.