Skip to content

chore: bump deps#468

Merged
adibarra merged 4 commits into
masterfrom
chore/bump-deps-2026-06-17
Jun 17, 2026
Merged

chore: bump deps#468
adibarra merged 4 commits into
masterfrom
chore/bump-deps-2026-06-17

Conversation

@adibarra

@adibarra adibarra commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Note

Medium Risk
Wide dependency surface (Next, PostHog, Radix, Cypress, esbuild) increases regression risk despite patch/minor bumps; security overrides reduce known CVE exposure.

Overview
Monorepo dependency refresh bumps root tooling (oxfmt 0.55, oxlint 1.70, pnpm 11.7) and rolls forward app/runtime deps including Next 16.2.9, Radix UI patches, Tailwind 4.3.1, Vitest 4.1.9, Cypress 15.17, PostHog, dompurify, and esbuild 0.28.1 across packages/app, constants, db, and mcp, with a matching pnpm-lock.yaml update.

Supply-chain hardening adds pnpm overrides (and lockfile overrides) forcing minimum versions for dompurify, esbuild, and form-data. Oxlint disables unicorn/prefer-export-from in .oxlintrc.json.

No functional app changes in the touched TS files: ScatterGraph.tsx merges two result.push calls; paretoLabels.ts and compare-ssr.ts only batch stops.push / props.push arguments for formatter/linter compliance.

Reviewed by Cursor Bugbot for commit 1af7f2c. Bugbot is set up for automated code reviews on this repo. Configure here.

@adibarra adibarra marked this pull request as ready for review June 17, 2026 21:34
@vercel

vercel Bot commented Jun 17, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
inferencemax-app Ready Ready Preview, Comment Jun 17, 2026 9:34pm

Request Review

@adibarra adibarra merged commit b57f844 into master Jun 17, 2026
24 checks passed
@adibarra adibarra deleted the chore/bump-deps-2026-06-17 branch June 17, 2026 21:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant