chore(deps): bump the minor-and-patch group across 1 directory with 17 updates - #3184
chore(deps): bump the minor-and-patch group across 1 directory with 17 updates#3184dependabot[bot] wants to merge 8 commits into
Conversation
3260ebb to
f9edbf5
Compare
|
Summary for review — What is in the diff, beyond the lockfile bump:
Validation: local Not a fast-path merge: it touches licensing (notices) and runtime behavior (pi-tui). Needs a normal review. |
中文这里建议将
我的建议是:本 PR 继续精确固定在 3.2.2,不在这里升级到 3.2.3。 考虑到 resume 尚未完全上线,如果后续确定升级到 3.2.3,我会另开一个独立 PR,统一更新依赖、lockfile、 EnglishI recommend restoring
My recommendation is: keep an exact 3.2.2 pin in this PR and do not upgrade to 3.2.3 here. Since resume has not been fully rolled out, if we later decide to move to 3.2.3, I will open a separate PR that updates the dependency, lockfile, |
|
@zhiiw Fixed in Implemented by Codex at AstroHan’s request. |
…7 updates Bumps the minor-and-patch group with 16 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@astryxdesign/cli](https://github.com/facebook/astryx/tree/HEAD/packages/cli) | `0.4.0` | `0.4.1` | | [@astryxdesign/core](https://github.com/facebook/astryx/tree/HEAD/packages/core) | `0.4.0` | `0.4.1` | | [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) | `2.5.6` | `2.5.8` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.2` | `26.2.0` | | [dugite](https://github.com/desktop/dugite) | `3.2.2` | `3.2.3` | | [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.26.0` | `6.32.2` | | [@openai/agents-core](https://github.com/openai/openai-agents-js) | `0.14.3` | `0.16.0` | | [@larksuiteoapi/node-sdk](https://github.com/larksuite/node-sdk) | `1.72.0` | `1.73.0` | | [ws](https://github.com/websockets/ws) | `8.21.2` | `8.21.3` | | [esbuild](https://github.com/evanw/esbuild) | `0.27.7` | `0.28.2` | | [electron](https://github.com/electron/electron) | `43.2.0` | `43.4.0` | | [@earendil-works/pi-tui](https://github.com/earendil-works/pi/tree/HEAD/packages/tui) | `0.83.0` | `0.84.2` | | [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.28.0` | `1.31.0` | | [@astryxdesign/theme-neutral](https://github.com/facebook/astryx/tree/HEAD/packages/themes/neutral) | `0.4.0` | `0.4.1` | | [@storybook/react-vite](https://github.com/storybookjs/storybook/tree/HEAD/code/frameworks/react-vite) | `10.5.6` | `10.5.8` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.1.5` | `8.2.1` | Updates `@astryxdesign/cli` from 0.4.0 to 0.4.1 - [Release notes](https://github.com/facebook/astryx/releases) - [Changelog](https://github.com/facebook/astryx/blob/main/packages/cli/CHANGELOG.md) - [Commits](https://github.com/facebook/astryx/commits/v0.4.1/packages/cli) Updates `@astryxdesign/core` from 0.4.0 to 0.4.1 - [Release notes](https://github.com/facebook/astryx/releases) - [Changelog](https://github.com/facebook/astryx/blob/main/packages/core/CHANGELOG.md) - [Commits](https://github.com/facebook/astryx/commits/v0.4.1/packages/core) Updates `@biomejs/biome` from 2.5.6 to 2.5.8 - [Release notes](https://github.com/biomejs/biome/releases) - [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md) - [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.8/packages/@biomejs/biome) Updates `@types/node` from 26.1.2 to 26.2.0 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `dugite` from 3.2.2 to 3.2.3 - [Release notes](https://github.com/desktop/dugite/releases) - [Changelog](https://github.com/desktop/dugite/blob/main/docs/releases.md) - [Commits](desktop/dugite@v3.2.2...v3.2.3) Updates `knip` from 6.26.0 to 6.32.2 - [Release notes](https://github.com/webpro-nl/knip/releases) - [Commits](https://github.com/webpro-nl/knip/commits/knip@6.32.2/packages/knip) Updates `@openai/agents-core` from 0.14.3 to 0.16.0 - [Release notes](https://github.com/openai/openai-agents-js/releases) - [Commits](openai/openai-agents-js@v0.14.3...v0.16.0) Updates `@larksuiteoapi/node-sdk` from 1.72.0 to 1.73.0 - [Commits](https://github.com/larksuite/node-sdk/commits) Updates `ws` from 8.21.2 to 8.21.3 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@8.21.2...8.21.3) Updates `esbuild` from 0.27.7 to 0.28.2 - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md) - [Commits](evanw/esbuild@v0.27.7...v0.28.2) Updates `electron` from 43.2.0 to 43.4.0 - [Release notes](https://github.com/electron/electron/releases) - [Commits](electron/electron@v43.2.0...v43.4.0) Updates `@earendil-works/pi-tui` from 0.83.0 to 0.84.2 - [Release notes](https://github.com/earendil-works/pi/releases) - [Changelog](https://github.com/earendil-works/pi/blob/main/packages/tui/CHANGELOG.md) - [Commits](https://github.com/earendil-works/pi/commits/v0.84.2/packages/tui) Updates `lucide-react` from 1.28.0 to 1.31.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.31.0/packages/lucide-react) Updates `@astryxdesign/theme-neutral` from 0.4.0 to 0.4.1 - [Release notes](https://github.com/facebook/astryx/releases) - [Changelog](https://github.com/facebook/astryx/blob/main/packages/themes/neutral/CHANGELOG.md) - [Commits](https://github.com/facebook/astryx/commits/v0.4.1/packages/themes/neutral) Updates `@storybook/react-vite` from 10.5.6 to 10.5.8 - [Release notes](https://github.com/storybookjs/storybook/releases) - [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md) - [Commits](https://github.com/storybookjs/storybook/commits/v10.5.8/code/frameworks/react-vite) Updates `storybook` from 10.5.6 to 10.5.8 - [Release notes](https://github.com/storybookjs/storybook/releases) - [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md) - [Commits](https://github.com/storybookjs/storybook/commits/v10.5.8/code/core) Updates `vite` from 8.1.5 to 8.2.1 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.2.1/packages/vite) --- updated-dependencies: - dependency-name: "@astryxdesign/cli" dependency-version: 0.4.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@astryxdesign/core" dependency-version: 0.4.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@astryxdesign/theme-neutral" dependency-version: 0.4.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@biomejs/biome" dependency-version: 2.5.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@earendil-works/pi-tui" dependency-version: 0.84.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@larksuiteoapi/node-sdk" dependency-version: 1.73.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@openai/agents-core" dependency-version: 0.15.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@storybook/react-vite" dependency-version: 10.5.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@types/node" dependency-version: 26.2.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: dugite dependency-version: 3.2.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: electron dependency-version: 43.4.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: esbuild dependency-version: 0.28.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: knip dependency-version: 6.32.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: lucide-react dependency-version: 1.31.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: storybook dependency-version: 10.5.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: vite dependency-version: 8.2.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: ws dependency-version: 8.21.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
pi-tui 0.84 turns the TUI class into an interface with concrete implementations; TuiMainScreen is the direct successor (main buffer, scrollback preserved). new TUI(terminal) no longer compiles, and the input listener's data parameter lost its inference chain.
patch-package matches patch files by exact version; the 0.4.0 name no longer applied to the bumped package and warned on every install. The patch was regenerated against a clean 0.4.1 tree (verified it applies cleanly and yields the seams the code depends on).
The six bumped packages all ship notices changes: five needed new exact-version copyright overrides (astryx core 0.4.1, pi-tui 0.84.2) or version-pinned text, and both desktop and cli notice files now record the new closure.
astryx 0.4.1 emits the type-scale ladder differently; the committed
maka.{css,js,d.ts} now match the current generator again.
knip 6.32 follows re-export chains, so two dead forwarding layers came out: the pip-electron re-exports in pip-window.ts (no callers since the code moved; pip-window still imports from pip-electron directly) and the QuietPreview type re-export in builtin-preview.ts. The withComputerUsePip forwarding line stays — desktop-native-capability-assembly imports it via pip-window.
3.2.3 only bumps dugite-native to v2.53.0-4 and touches docs/CI, while the Git-bundling pipeline pins the exact version (DUGITE_VERSION in prepare-bundled-git-source.mjs) and its native release. Reverting keeps the bump's other 16 updates without retooling the bundling pin.
Keep the root dependency and lockfile declaration aligned with the bundled Git scripts, allowScripts entry, and recorded native provenance so a routine lock refresh cannot silently select dugite 3.2.3. Generated-by: Codex
432c3b2 to
57917cd
Compare
|
/agentic_review |
Code Review by Qodo
1. Esbuild install script blocked
|
| "electron": "43.4.0", | ||
| "electron-builder": "26.15.3", | ||
| "esbuild": "^0.27.7", | ||
| "esbuild": "^0.28.2", |
There was a problem hiding this comment.
1. Esbuild install script blocked 🐞 Bug ☼ Reliability
The PR installs esbuild 0.28.2 while allowScripts still approves only 0.27.7, so npm 11.19 skips the new package's required install script during clean installs. The desktop preload build then invokes an esbuild installation whose platform binary may be unavailable.
Agent Prompt
## Issue description
The esbuild dependency was upgraded to 0.28.2, but the root `allowScripts` configuration remains pinned to 0.27.7. Update the existing approval to the locked version so clean npm installs run esbuild's install script.
## Issue Context
The repository pins npm 11.19.0, which blocks dependency install scripts without a matching approval. Consolidation or a new configuration path is unnecessary; the smallest correction is replacing the stale version in the existing authority.
## Fix Focus Areas
- package.json[81-85]
- apps/desktop/package.json[76-79]
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
Astro-Han
left a comment
There was a problem hiding this comment.
The dependency update is otherwise coherent on the current head: dugite is now exact at 3.2.2 across the declaration, lockfile, bundled-Git validation, provenance, and script approval; the pi-tui/Astryx migrations and notices are consistent; and all live checks are green.
One small authority mismatch still blocks approval: the existing Qodo thread correctly notes that the locked esbuild@0.28.2 no longer matches the root allowScripts entry for 0.27.7. I am not duplicating that inline finding. From first principles, the existing script-approval map is the right single authority; the smallest fix is simply to replace the stale version and verify the install-script inventory. The PR description should also be refreshed because its generated dependency list still describes the earlier dugite/agents-core state, but that documentation drift is non-blocking.
Reviewed with Codex using three independent reviewer agents and OpenCode Go DeepSeek V4 Flash (high); I verified the exact current head, dependency/provenance chain, existing discussion, and live CI.
中文
当前 head 的依赖更新整体已经一致:dugite 在声明、lockfile、bundled-Git 校验、provenance 和脚本审批中都精确固定为 3.2.2;pi-tui/Astryx 迁移与 notices 也一致,实时检查全绿。
目前只剩一个很小但会阻塞批准的权威不一致:现有 Qodo 行内评论正确指出,实际锁定的 esbuild@0.28.2 已经不匹配根 allowScripts 中的 0.27.7。我不重复发布相同行内问题。按第一性原理,现有脚本审批表就是正确的单一权威;最小修复只是替换过期版本并核验 install-script inventory。PR 描述中的自动依赖清单仍是早期 dugite/agents-core 状态,也建议同步,但不阻塞。
本次由 Codex 配合三个独立 reviewer agent,以及 OpenCode Go DeepSeek V4 Flash(high)审查;我核验了当前精确 head、依赖/provenance 链、已有讨论和实时 CI。
|
Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting |
PR AssessmentWhat problem does this PR solve?This PR refreshes the repository’s dependency set while preserving compatibility across the desktop application, CLI, runtime, generated Astryx theme, dependency patches, license notices, and bundled-Git provenance. How does this PR solve the problem?It updates dependency declarations and the lockfile, migrates the CLI from Is the problem correctly defined?Correct. The compatibility and generated-artifact changes are directly attributable to the dependency refresh. No unrelated state or abstraction was introduced. The PR description is stale, but the implementation scope itself is coherent. Principle-based assessment
Review FindingsP1 BlockerNone. P2 Should Fix[P2 Should Fix] Install-script approval no longer covers the locked esbuild version
SuggestionRefresh the generated PR description. It still claims a Verification
ConclusionMerge conditionally. Condition: update the version-pinned esbuild install-script approval and confirm it no longer appears in the pending inventory. The stale PR description is non-blocking. 点击展开中文PR 判断这个 PR 解决了什么问题?这个 PR 更新仓库依赖,同时保持桌面端、CLI、Runtime、生成的 Astryx 主题、依赖补丁、许可证清单和 bundled-Git provenance 的兼容性。 这个 PR 如何解决这个问题?它更新了依赖声明和 lockfile,将 CLI 从 这个问题定义得对吗?Correct(正确)。 兼容性修改和生成产物更新都直接由依赖升级引起,没有引入无关状态或抽象。PR 描述已经过时,但实现范围本身是一致的。 原则性判断
Review FindingsP1 阻塞无。 P2 应该改[P2 应该改] 安装脚本审批不再覆盖实际锁定的 esbuild 版本
建议刷新自动生成的 PR 描述。它仍声称将 验证
结论有条件合入。 条件:更新版本固定的 esbuild 安装脚本审批,并确认它不再出现在 pending inventory 中。PR 描述过期不阻塞合入。 |
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the minor-and-patch group with 16 updates in the / directory:
0.4.00.4.10.4.00.4.12.5.62.5.826.1.226.2.03.2.23.2.36.26.06.32.20.14.30.16.01.72.01.73.08.21.28.21.30.27.70.28.243.2.043.4.00.83.00.84.21.28.01.31.00.4.00.4.110.5.610.5.88.1.58.2.1Updates
@astryxdesign/clifrom 0.4.0 to 0.4.1Release notes
Sourced from @astryxdesign/cli's releases.
Changelog
Sourced from @astryxdesign/cli's changelog.
Commits
96f9917chore: version packages for v0.4.1 (#5038)1a333a8docs(deslop): recast em dashes and curly apostrophes in CLI and lab docs (#5028)fff8412fix(cli): load theming target states in theme-build override validation (#4778)41f53a0fix(core): move the popup theme targets onto the surface that paints (#5009)c6a994efeat(theme): make the focus outline a token (#4973)Updates
@astryxdesign/corefrom 0.4.0 to 0.4.1Release notes
Sourced from @astryxdesign/core's releases.
Changelog
Sourced from @astryxdesign/core's changelog.
Commits
96f9917chore: version packages for v0.4.1 (#5038)dad87f5fix(selector): make the dropdown search part of the panel, not a box inside i...b575c18docs(deslop): recast em dash in Indicator children description (#4982)3ee137edocs(storybook): remove JS comments from globalIconRegistry@exampleblocks (...ab60c59docs(dense): restore AppShell bestPractices parity in docsDense (#4981)e18b6dbfix(CommandPalette): discard in-flight search responses on close (#3896)647ff7efeat(core): drop 'use client' from server-safe primitives (#4407)3112e99fix(core): TopNavMegaMenu anchors to its trigger outside a <nav> (#4905) (#4916)9e52262fix(table): honor className and style on TableRow (#4391)d6d345cfix(banner): move the 'banner-icon' theme target onto the status Icon so 'sta...Updates
@biomejs/biomefrom 2.5.6 to 2.5.8Release notes
Sourced from @biomejs/biome's releases.
... (truncated)
Changelog
Sourced from @biomejs/biome's changelog.
... (truncated)
Commits
6b8f09cci: release (#11236)23c0369feat(lint): nursery noInvalidPropertyInitValue (#11187)52b44d6feat(lint/html): addnoSvelteLegacyConst(#11247)0a0fbc1feat(lint/js): adduseReactCompiler(#10710)191d051ci: release (#11119)9847e68feat(lint): add noNonScalableViewport rule (#11168)e63354cfeat(lint): add noExtendNative nursery rule (#11136)2fa0a62docs: rework CLI (#11134)e007143feat(lint): add nursery rule noTailwindArbitraryValue (#10094)c171b3bfeat(lint): add ignoreIfStatements option to useNullishCoalescing (#10822)Updates
@types/nodefrom 26.1.2 to 26.2.0Commits
Updates
dugitefrom 3.2.2 to 3.2.3Release notes
Sourced from dugite's releases.
Commits
84cd7163.2.365dc019Pin publish workflow to npm 11 (#630)29a0247Update dugite-native to v2.53.0-4 (#629)03f0b52Merge pull request #628 from desktop/update-actions83065c1Fail early if release already exists in publish workflowac670dbFix heredoc indentation in update-git PR body15f4730Set git author and committer for update-git workflowc1df32cMerge pull request #624 from desktop/docs-updates28bafecUpdate create-github-app-token to v3 in update-git workflow3fb1fbdReplace peter-evans/create-pull-request with gh CLIUpdates
knipfrom 6.26.0 to 6.32.2Release notes
Sourced from knip's releases.
... (truncated)
Commits
196a11aRelease knip@6.32.295f7c52Update dependenciesf9c755eFix Supportedlint-stagedConfigs (#1935)531e2dcSupportoxlint.config.mts(#1934)7959001Supportoxfmt.config.mts(#1933)437b608Release knip@6.32.12febefeFix type-check against typescript@5.0.4982c1d8Handle referenced config files in their own plugin (resolve #1931, close #1932)f21bcbbRelease knip@6.32.0d2c0a07Update dependenciesUpdates
@openai/agents-corefrom 0.14.3 to 0.16.0Release notes
Sourced from @openai/agents-core's releases.