Skip to content

chore(deps): combine in-range dependency bumps - #2359

Merged
cursor[bot] merged 1 commit into
nextfrom
cursor/combined-inrange-deps-152b
Sep 28, 2026
Merged

cursor[bot] merged 1 commit into
nextfrom
cursor/combined-inrange-deps-152b

Conversation

@siddharthlatest

Copy link
Copy Markdown
Member

Combines the open in-range Dependabot updates that all rewrite a shared Yarn lockfile, instead of merging them one by one.

What changed

Direct ranges, matching the postcss bot PR:

  • postcss in @appbaseio/reactivesearch-vue and the Vue Tailwind example: ^8.4.31 / ^8.4.32 → ^8.5.23
  • A fresh install resolves the PostCSS 8 caret ranges to 8.5.28 (newer patch on the same 8.5 line; the bot PR targeted 8.5.23)

Transitive lockfile bumps that stay on the current major:

  • devalue 5.1.1 → 5.9.2
  • colord 2.9.3 → 2.10.0
  • @xmldom/xmldom 0.8.10 → 0.8.15
  • dompurify 3.2.4 → 3.4.13
  • nanoid 3.3.8 → 3.3.18 (the ^3.3.18 range resolves to 3.3.19; nanoid 5 is unchanged)
  • brace-expansion 1.1.11 → 1.1.18 (2.x is unchanged)

Example lockfiles (not part of the root workspace):

  • packages/maps-native/example: morgan 1.12.0, browserslist 4.28.8, qs 6.16.0, js-yaml 3.15.1
  • packages/native/example: js-yaml 3.15.1, brace-expansion 1.1.18

Lockfile alignment

yarn.lock recorded @appbaseio/reactivecore@9.15.1 while web, vue, native, and maps-native require 10.4.0 exactly. Regenerating the lockfile with yarn install aligns that pin. The refresh also drops a stale Gatsby subgraph that no package.json depends on. That removes joi@17 and socket.io-parser@4.2, so those two bot updates are covered by removal rather than an in-place bump.

Held (not in this PR)

Superseded when this merges

Leave these Dependabot PRs open until this lands: #2357, #2355, #2354, #2353, #2352, #2351, #2350, #2347, #2346, #2345, #2344, #2343, #2342, #2336, #2335.

Checklist

  • In-range dependency updates only. No application refactors.
  • packages/web build and Jest on Node 22 (same commands as CI)
  • Docs / storybook PRs are not needed for a lockfile bump
Open in Web Open in Cursor 

Apply open Dependabot patch and minor updates together, and align
the lockfile pin for @appbaseio/reactivecore to 10.4.0.

Co-authored-by: Siddharth Kothari <siddharthlatest@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants