Skip to content

chore: Update dependencies - #53

Merged
stefashkaa merged 3 commits into
mainfrom
chore/update-dependencies
Sep 30, 2026
Merged

stefashkaa merged 3 commits into
mainfrom
chore/update-dependencies

Conversation

@stefashkaa

@stefashkaa stefashkaa commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Description

  • What does this PR do?

    • Updates workspace dependencies, including Angular 22.2, Vite 8.3.1, Vitest 5.0.2, and pnpm 12.8.1
    • Refreshes dependency overrides and regenerates the lockfile
    • Adds Next.js ^16.3.7 to the React package’s dev dependencies
    • Updates the commit-pinned Codecov action to v7.1.1
    • Filters "use client" directive warnings in React library and demo builds. The library’s preserveModules configuration retains these directives
  • Why is this change needed?

Type of Change

  • Bug fix (non-breaking)
  • New feature (non-breaking)
  • Breaking change
  • Documentation update
  • Tests
  • Other (describe below): Dependencies & CI upgrade

Testing

  • pnpm check:release

Screenshots (if applicable)

  • N/A

Checklist

  • Code follows project style guidelines
  • Self-review completed
  • Comments added for complex code
  • Documentation updated
  • No new warnings generated
  • Tests added/updated
  • All tests passing

Manual Coverage (Optional)

Run Coverage Workflow

Maintainers only (write/maintain/admin access): open the workflow, click Run workflow, and set pr_number to this PR number to post/update a coverage comment on this PR

Summary by CodeRabbit

  • Chores
    • Updated project tooling across the demo apps and framework integrations.
    • Improved React build output by filtering out irrelevant "use client" warnings while preserving other warnings.
    • Updated the coverage reporting workflow.

Copilot AI balanced review requested due to automatic review settings September 30, 2026 20:35
@vercel

vercel Bot commented Sep 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
image-demo Ready Ready Preview Sep 30, 2026 8:35pm UTC

Request Review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T20:39:53.481433Z 7591214 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: a5fb5292-7def-4eb2-bedd-48874da83fed

📥 Commits

Reviewing files that changed from the base of the PR and between 99fac40 and 7591214.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (10)
  • .github/workflows/coverage.yml
  • demo/package.json
  • package.json
  • packages/angular/package.json
  • packages/core/package.json
  • packages/react/demo/vite.config.ts
  • packages/react/package.json
  • packages/react/vite.config.ts
  • packages/svelte/package.json
  • pnpm-workspace.yaml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

This change updates dependency versions across the workspace, adds warning filters to two React Vite configurations, adds Next to React development dependencies, and updates the Codecov action version.

Changes

Package version updates

Layer / File(s) Summary
Workspace and package version updates
.github-unrelated package paths: package.json, pnpm-workspace.yaml, packages/angular/package.json, packages/core/package.json, demo/package.json, packages/svelte/package.json
Updates the pnpm requirement and dependency ranges in the root and package manifests, plus Angular, Sass, and Sharp workspace overrides.

React build warning handling

Layer / File(s) Summary
React Vite warning handling
packages/react/vite.config.ts, packages/react/demo/vite.config.ts, packages/react/package.json
Both Vite configurations suppress matching "use client" module-level directive warnings and forward other warnings. Adds Next to React development dependencies.

Coverage upload action

Layer / File(s) Summary
Codecov action version
.github/workflows/coverage.yml
Updates the Codecov upload action from v7.0.0 to v7.1.1.

Priority: ⬆️ High

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 75912

The dependency updates and React warning filters show no established regression, and the lockfile matches the new Next dependency. The Angular Node-version mismatch was already present; no concrete merge-blocking risk is identified.

Architecture Summary

Architecture risk: 🔵 Low · up to 75912

The change affects 7 systems.

Changed systems: packages/react, demo, package.json, packages/angular, packages/core, packages/svelte, pnpm-workspace.yaml

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — packages/react (library) was modified; 3 changed files map to changed impact.
  • observed — demo (service) was modified; 1 changed file maps to changed impact.
  • observed — package.json (service) was modified; 1 changed file maps to changed impact.
  • observed — packages/angular (library) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in demo/package.json: Updated the declared version ranges for @sveltejs/vite-plugin-svelte, sass, and svelte to ^7.3.1, ^1.105.0, and ^5.57.1, respectively, replacing their previous ranges.
  • observed — Modified behavior in package.json: The required package manager version changes from pnpm 12.4.1 to 12.8.1.
  • observed — Modified behavior in package.json: Updates version ranges for @changesets/cli, @types/node, TypeScript ESLint, @vitest/coverage-v8, ESLint, jsdom, lint-staged, Prettier, Vite, and Vitest; the other dependency entries in this block remain unchanged.
  • observed — Modified behavior in packages/angular/package.json: Updated the version ranges for the Analog Angular plugins, Angular build and framework packages, and ng-packagr.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the primary change: workspace and package dependency updates. It is concise and directly related to the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.

Warning

Some tools did not complete. Review the errors below.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install timed out. The project may have too many dependencies for the sandbox.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the version rows,
Then watches warning messages flow.
“Use client” warnings fade from sight,
Other warnings pass along just right.
The coverage upload hops ahead.

Comment @coderabbitai help to get the list of available commands.

@gitar-bot

gitar-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

You are using the Gitar free plan. Upgrade to unlock code review, CI analysis, auto-apply, custom automations, and more.

Gitar

@sonarqubecloud

Copy link
Copy Markdown

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It includes major dependency bumps (notably Vitest 4→5 and framework upgrades) plus a regenerated lockfile whose runtime/build impact needs human verification of CI.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

This PR is a routine dependency-maintenance change for the @desource/image monorepo. It bumps workspace tooling and framework dependencies (Angular 22.2, Vite 8.3.1, Vitest 5, pnpm 12.8.1, Svelte, etc.), refreshes pnpm workspace overrides, pins the Codecov action to a new commit/tag, and adds onwarn handlers so that "use client" MODULE_LEVEL_DIRECTIVE warnings are suppressed during the React library and demo builds. It also adds Next.js to the React package's dev dependencies to satisfy the optional next peer and address a security advisory.

Changes:

  • Bump dependencies across root, core, angular, react, svelte, and demo packages plus workspace overrides; update packageManager to pnpm 12.8.1.
  • Add Rollup onwarn filters in packages/react/vite.config.ts and packages/react/demo/vite.config.ts to silence "use client" directive warnings.
  • Update the pinned Codecov action to v7.1.1 (commit verified to match the tag).
File Description
pnpm-workspace.yaml Bumps Angular devkit/CLI overrides to 22.2.0 and sass/sharp overrides.
packages/​svelte/​package.json Minor bumps to @sveltejs/vite-plugin-svelte and svelte.
packages/​react/​vite.config.ts Adds onwarn to suppress "use client" directive warnings in the library build.
packages/​react/​package.json Adds next@^16.3.7 dev dependency (matches optional next peer).
packages/​react/​demo/​vite.config.ts Adds rollupOptions.onwarn to suppress "use client" warnings; comment references preserveModules not present here.
packages/​core/​package.json Bumps std-env to ^4.3.0.
packages/​angular/​package.json Aligns Angular/Analog/ng-packagr dev dependencies to the 22.2.x line.
package.json Updates pnpm version and multiple root devDependencies, including major bump of Vitest 4→5.
demo/​package.json Minor bumps to Svelte plugin, sass, and svelte.
.github/​workflows/​coverage.yml Repins Codecov action to v7.1.1 (SHA verified).

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread packages/react/demo/vite.config.ts
@stefashkaa
stefashkaa merged commit 524d259 into main Sep 30, 2026
8 checks passed
@stefashkaa
stefashkaa deleted the chore/update-dependencies branch September 30, 2026 21:17

This branch was successfully deployed

1 active deployment
Preview — 75912148 Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants