Skip to content

chore(deps): bump downshift from 9.0.13 to 9.3.2 - #508

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/downshift-9.3.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/downshift-9.3.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 12, 2026

Copy link
Copy Markdown
Contributor

Bumps downshift from 9.0.13 to 9.3.2.

Release notes

Sourced from downshift's releases.

v9.3.2

9.3.2 (2026-02-19)

Bug Fixes

  • useElementIds: improve fix for webpack analyzer (#1677) (f1862ed)

v9.3.1

9.3.1 (2026-02-13)

Bug Fixes

  • useElementIds: prevent Webpack static analysis issue with useId (#1676) (9e79c4e)

v9.3.0

9.3.0 (2026-02-09)

Features

v9.2.0

9.2.0 (2026-01-30)

Features

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [downshift](https://github.com/downshift-js/downshift) from 9.0.13 to 9.3.2.
- [Release notes](https://github.com/downshift-js/downshift/releases)
- [Changelog](https://github.com/downshift-js/downshift/blob/master/CHANGELOG.md)
- [Commits](downshift-js/downshift@v9.0.13...v9.3.2)

---
updated-dependencies:
- dependency-name: downshift
  dependency-version: 9.3.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 12, 2026
@github-actions github-actions Bot added the chore label Apr 12, 2026
@greptile-apps

greptile-apps Bot commented Apr 12, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This is a dependabot PR bumping downshift from 9.0.13 to 9.3.2, which includes bug fixes for useElementIds (Webpack static analysis issues) and a new useTagGroup hook. The lockfile also contains a silent bump of chrome-devtools-mcp from 0.20.0 to 0.21.0 that is outside the stated scope of this PR and should be verified intentionally.

Confidence Score: 5/5

Safe to merge; the downshift bump is low-risk and the only finding is a P2 observation about an unannounced chrome-devtools-mcp bump in the lockfile.

All findings are P2 or lower. The downshift upgrade is a minor/patch bump with no breaking changes. The chrome-devtools-mcp lockfile change is worth a quick manual check but does not block merging.

bun.lock — verify the unannounced chrome-devtools-mcp 0.20.0 → 0.21.0 bump is intentional.

Important Files Changed

Filename Overview
apps/agent/package.json Bumps downshift version specifier from ^9.0.10 to ^9.3.2; straightforward dependency version update.
bun.lock Resolves downshift to 9.3.2 and updates its transitive deps, but also silently bumps chrome-devtools-mcp from 0.20.0 to 0.21.0 — an unannounced change not covered by this PR.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[PR: bump downshift 9.0.13 → 9.3.2] --> B[apps/agent/package.json\nspecifier: ^9.0.10 → ^9.3.2]
    A --> C[bun.lock resolved: 9.0.13 → 9.3.2]
    C --> D[downshift deps updated\n@babel/runtime, compute-scroll-into-view\nreact-is pin → range, tslib]
    C --> E[⚠️ chrome-devtools-mcp\n0.20.0 → 0.21.0\nnot part of PR scope]
Loading
Prompt To Fix All With AI
This is a comment left during a code review.
Path: bun.lock
Line: 2113

Comment:
**Unexpected `chrome-devtools-mcp` bump in lockfile**

The lockfile contains an unannounced bump of `chrome-devtools-mcp` from `0.20.0` to `0.21.0` that is not mentioned in this PR. This dependabot PR is scoped solely to `downshift`, so any collateral resolution change to `chrome-devtools-mcp` should be reviewed intentionally before merging to ensure no unintended behavior is introduced.

How can I resolve this? If you propose a fix, please make it concise.

Reviews (1): Last reviewed commit: "chore(deps): bump downshift from 9.0.13 ..." | Re-trigger Greptile

Comment thread bun.lock
"chrome-devtools-frontend": ["chrome-devtools-frontend@1.0.1577886", "", {}, "sha512-B9hY3o/0RuVCDWNYh9YnkEbRrPUMCY+NaOgBxvZRzGvqbGSMNckkVSdO67SwWR8bm4fo/qplXbUj0cSr229V6w=="],

"chrome-devtools-mcp": ["chrome-devtools-mcp@0.20.0", "", { "bin": { "chrome-devtools-mcp": "build/src/bin/chrome-devtools-mcp.js", "chrome-devtools": "build/src/bin/chrome-devtools.js" } }, "sha512-wBnt8901lAXdac3AB7WdONYTAXGW+YqqIVVg7PztxYVNPs3VVgM2UZnZT/ICYPIofKTuRBOkRdEE/VYm90ZgYA=="],
"chrome-devtools-mcp": ["chrome-devtools-mcp@0.21.0", "", { "bin": { "chrome-devtools-mcp": "build/src/bin/chrome-devtools-mcp.js", "chrome-devtools": "build/src/bin/chrome-devtools.js" } }, "sha512-d+iqrRmcwpRFV3Q4DRCF2LCoq+WCRU3GhISKQ9v8g+1C2Uh8upj3urkjxNO4QIjhBMIYei/VQ1OQLFceby80Og=="],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Unexpected chrome-devtools-mcp bump in lockfile

The lockfile contains an unannounced bump of chrome-devtools-mcp from 0.20.0 to 0.21.0 that is not mentioned in this PR. This dependabot PR is scoped solely to downshift, so any collateral resolution change to chrome-devtools-mcp should be reviewed intentionally before merging to ensure no unintended behavior is introduced.

Prompt To Fix With AI
This is a comment left during a code review.
Path: bun.lock
Line: 2113

Comment:
**Unexpected `chrome-devtools-mcp` bump in lockfile**

The lockfile contains an unannounced bump of `chrome-devtools-mcp` from `0.20.0` to `0.21.0` that is not mentioned in this PR. This dependabot PR is scoped solely to `downshift`, so any collateral resolution change to `chrome-devtools-mcp` should be reviewed intentionally before merging to ensure no unintended behavior is introduced.

How can I resolve this? If you propose a fix, please make it concise.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants