You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Update dependency @hugeicons/react to v1.1.9 - #4012
This is a Renovate-generated dependency update bumping @hugeicons/react from 1.1.6 to 1.1.9 across the monorepo's pnpm catalog and lockfile.
The catalog entry in pnpm-workspace.yaml and all four importer resolutions in pnpm-lock.yaml are updated consistently, with the package integrity hash replaced to match the new version.
Two pre-existing indirect packages (stream-to-promise@2.2.0 and tsconfck@3.1.6) now surface deprecation notices in the lockfile snapshot — these are unrelated to the icons bump and were likely already deprecated before this PR.
Confidence Score: 5/5
Routine icon library patch update with no API or behavioral changes surfaced in the release notes; all lockfile entries are consistent.
The change is limited to version strings and an integrity hash in the pnpm catalog and lockfile. The @hugeicons/react update spans three minor patch versions (1.1.6 → 1.1.9) with no noted breaking changes. All four importer entries are updated uniformly and the snapshot entry is aligned.
• Bump @hugeicons/react from 1.1.6 to 1.1.9 in the pnpm workspace catalog.
• Update pnpm lockfile entries to reflect the new package resolution and integrity.
This is the standard Renovate/pnpm workflow: update the workspace catalog pin and commit the regenerated lockfile. No alternative approach is meaningfully better beyond ensuring CI passes and (optionally) verifying no icon/component API changes impact consumers.
Files changed (2) +12 / -10
Other (2) +12 / -10
pnpm-lock.yamlUpdate lockfile for @hugeicons/react 1.1.9 resolution+11/-9
Update lockfile for @hugeicons/react 1.1.9 resolution
• Updates the locked @hugeicons/react version from 1.1.6 to 1.1.9 (including integrity). Also records new deprecation metadata surfaced for transitive packages during lockfile regeneration.
The lockfile now records stream-to-promise@2.2.0 as deprecated, and it is still pulled in
transitively via vercel -> @vercel/fun. This doesn’t prove a functional regression from the
@hugeicons/react bump, but it is a dependency-hygiene risk worth tracking (e.g., for
security/compliance or future ecosystem breakage).
ⓘ Recommendations generated based on similar findings in past PRs
Evidence
The lockfile explicitly marks stream-to-promise@2.2.0 as deprecated and shows it is depended on by
@vercel/fun@1.3.0, which is in turn a dependency of vercel@53.1.0.
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution
### Issue description
`stream-to-promise@2.2.0` is marked deprecated in the lockfile and is brought in via `vercel -> @vercel/fun`.
### Issue Context
This PR refreshes `pnpm-lock.yaml`, which now surfaces the deprecation metadata. The goal is to remove/avoid deprecated transitive dependencies where feasible.
### Fix Focus Areas
- pnpm-workspace.yaml[60-76]
- pnpm-lock.yaml[9789-9804]
- pnpm-lock.yaml[6676-6680]
### Suggested fix
1. Try upgrading `vercel` to a version whose dependency graph no longer includes `@vercel/fun` (or where `@vercel/fun` no longer depends on `stream-to-promise`).
2. Re-run `pnpm install` and verify `stream-to-promise` is no longer present (or no longer deprecated).
3. If removal isn’t currently possible, document/track the transitive deprecation so it’s not “rediscovered” later.
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
2. Unmaintained tsconfck 🐞 Bug⚙ Maintainability
Description
The lockfile now records tsconfck@3.1.6 as deprecated: unmaintained, and it is used by
vite-tsconfig-paths@6.1.1 (part of the build toolchain). This doesn’t indicate an immediate break
from this PR, but it increases long-term maintenance risk for TS/Vite upgrades.
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution
### Issue description
`tsconfck@3.1.6` is marked `deprecated: unmaintained` in the lockfile and is pulled in by `vite-tsconfig-paths`.
### Issue Context
This PR’s lockfile refresh surfaced the unmaintained status. Since `vite-tsconfig-paths` runs during builds, leaving an unmaintained parser in the toolchain can create avoidable future upgrade friction.
### Fix Focus Areas
- pnpm-workspace.yaml[66-73]
- pnpm-lock.yaml[6943-6947]
- pnpm-lock.yaml[14471-14476]
### Suggested fix
1. Check if a newer `vite-tsconfig-paths` release removes/replaces `tsconfck`.
2. If not, consider an alternative tsconfig-paths solution for Vite, or pin/track this risk explicitly.
3. Re-run `pnpm install` and confirm the dependency graph no longer includes `tsconfck` (or no longer marks it unmaintained).
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.1.6→1.1.9Release Notes
hugeicons/hugeicons (@hugeicons/react)
v1.1.9Compare Source
Configuration
📅 Schedule: (UTC)
* 0-3 1 * *)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.
Greptile Summary
This is a Renovate-generated dependency update bumping
@hugeicons/reactfrom1.1.6to1.1.9across the monorepo's pnpm catalog and lockfile.pnpm-workspace.yamland all four importer resolutions inpnpm-lock.yamlare updated consistently, with the package integrity hash replaced to match the new version.stream-to-promise@2.2.0andtsconfck@3.1.6) now surface deprecation notices in the lockfile snapshot — these are unrelated to the icons bump and were likely already deprecated before this PR.Confidence Score: 5/5
Routine icon library patch update with no API or behavioral changes surfaced in the release notes; all lockfile entries are consistent.
The change is limited to version strings and an integrity hash in the pnpm catalog and lockfile. The @hugeicons/react update spans three minor patch versions (1.1.6 → 1.1.9) with no noted breaking changes. All four importer entries are updated uniformly and the snapshot entry is aligned.
No files require special attention.
Reviews (1): Last reviewed commit: "Update dependency @hugeicons/react to v1..." | Re-trigger Greptile