Skip to content

chore: force upgrading js deps to resolve all npm dependabot alerts#6875

Merged
hanabi1224 merged 1 commit intomainfrom
hm/bump-js-deps
Apr 8, 2026
Merged

chore: force upgrading js deps to resolve all npm dependabot alerts#6875
hanabi1224 merged 1 commit intomainfrom
hm/bump-js-deps

Conversation

@hanabi1224
Copy link
Copy Markdown
Contributor

@hanabi1224 hanabi1224 commented Apr 8, 2026

Summary of changes

Changes introduced in this pull request:

Reference issue to close (if applicable)

Closes

Other information and links

Change checklist

  • I have performed a self-review of my own code,
  • I have made corresponding changes to the documentation. All new code adheres to the team's documentation standards,
  • I have added tests that prove my fix is effective or that my feature works (if possible),
  • I have made sure the CHANGELOG is up-to-date. All user-facing changes should be reflected in this document.

Outside contributions

  • I have read and agree to the CONTRIBUTING document.
  • I have read and agree to the AI Policy document. I understand that failure to comply with the guidelines will lead to rejection of the pull request.

Summary by CodeRabbit

  • Chores
    • Updated dependencies to latest compatible versions for improved stability and security.

@coderabbitai
Copy link
Copy Markdown
Contributor

coderabbitai Bot commented Apr 8, 2026

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 2b8ace82-8736-4d4b-8b33-db38499b9571

📥 Commits

Reviewing files that changed from the base of the PR and between 86c73fa and 5e0a705.

⛔ Files ignored due to path filters (1)
  • docs/pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • docs/package.json

Walkthrough

Updated the mermaid dependency in docs/package.json from ^11.13.0 to ^11.14.0. Extended the resolutions block with pinned versions for lodash (^4.18.1) and serialize-javascript (^7.0.5), while maintaining the existing dompurify resolution.

Changes

Cohort / File(s) Summary
Dependency Updates
docs/package.json
Bumped mermaid version and added lodash and serialize-javascript to resolutions block.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

Suggested labels

dependencies, javascript

Suggested reviewers

  • LesnyRumcajs
  • sudo-shashank
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title directly describes the main change: upgrading JavaScript dependencies to resolve npm dependabot alerts, which aligns with the changeset modifications to package.json.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch hm/bump-js-deps
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch hm/bump-js-deps

Comment @coderabbitai help to get the list of available commands and usage tips.

@hanabi1224 hanabi1224 marked this pull request as ready for review April 8, 2026 12:23
@hanabi1224 hanabi1224 requested a review from a team as a code owner April 8, 2026 12:23
@hanabi1224 hanabi1224 requested review from LesnyRumcajs and akaladarshi and removed request for a team April 8, 2026 12:23
@hanabi1224 hanabi1224 added this pull request to the merge queue Apr 8, 2026
Merged via the queue into main with commit 31ca1a1 Apr 8, 2026
28 checks passed
@hanabi1224 hanabi1224 deleted the hm/bump-js-deps branch April 8, 2026 12:42
@coderabbitai coderabbitai Bot mentioned this pull request Apr 23, 2026
6 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants