Skip to content

Update dependency @hugeicons/react to v1.1.9 - #4012

Merged
amitsingh-007 merged 1 commit into
renovate-updatesfrom
renovate/hugeicons-react-1.x
Jul 8, 2026
Merged

amitsingh-007 merged 1 commit into
renovate-updatesfrom
renovate/hugeicons-react-1.x

Conversation

@amitsingh-007

@amitsingh-007 amitsingh-007 commented Jul 8, 2026 •

Copy link
Copy Markdown
Owner

This PR contains the following updates:

Package Change Age Confidence
@hugeicons/react (source) 1.1.6 → 1.1.9 age confidence

Release Notes

hugeicons/hugeicons (@​hugeicons/react)

v1.1.9

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 of the month (* 0-3 1 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

Greptile Summary

This is a Renovate-generated dependency update bumping @hugeicons/react from 1.1.6 to 1.1.9 across the monorepo's pnpm catalog and lockfile.

  • The catalog entry in pnpm-workspace.yaml and all four importer resolutions in pnpm-lock.yaml are updated consistently, with the package integrity hash replaced to match the new version.
  • Two pre-existing indirect packages (stream-to-promise@2.2.0 and tsconfck@3.1.6) now surface deprecation notices in the lockfile snapshot — these are unrelated to the icons bump and were likely already deprecated before this PR.

Confidence Score: 5/5

Routine icon library patch update with no API or behavioral changes surfaced in the release notes; all lockfile entries are consistent.

The change is limited to version strings and an integrity hash in the pnpm catalog and lockfile. The @hugeicons/react update spans three minor patch versions (1.1.6 → 1.1.9) with no noted breaking changes. All four importer entries are updated uniformly and the snapshot entry is aligned.

No files require special attention.

Reviews (1): Last reviewed commit: "Update dependency @hugeicons/react to v1..." | Re-trigger Greptile

@amitsingh-007
amitsingh-007 enabled auto-merge (squash) July 8, 2026 16:22
@amitsingh-007
amitsingh-007 merged commit f9bf44a into renovate-updates Jul 8, 2026
3 checks passed
@amitsingh-007
amitsingh-007 deleted the renovate/hugeicons-react-1.x branch July 8, 2026 16:23
@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Bump @hugeicons/react to v1.1.9

⚙️ Configuration changes 🕐 Less than 10 minutes

Grey Divider

AI Description

• Bump @hugeicons/react from 1.1.6 to 1.1.9 in the pnpm workspace catalog.
• Update pnpm lockfile entries to reflect the new package resolution and integrity.
Diagram

graph TD
  A["pnpm-workspace.yaml (catalog)"] --> B["pnpm-lock.yaml"] --> C["pnpm install / CI"] --> D["@hugeicons/react@1.1.9 (npm)"] --> E["Workspace packages"]
Loading
High-Level Assessment

This is the standard Renovate/pnpm workflow: update the workspace catalog pin and commit the regenerated lockfile. No alternative approach is meaningfully better beyond ensuring CI passes and (optionally) verifying no icon/component API changes impact consumers.

Files changed (2) +12 / -10

Other (2) +12 / -10
pnpm-lock.yamlUpdate lockfile for @hugeicons/react 1.1.9 resolution +11/-9

Update lockfile for @hugeicons/react 1.1.9 resolution

• Updates the locked @hugeicons/react version from 1.1.6 to 1.1.9 (including integrity). Also records new deprecation metadata surfaced for transitive packages during lockfile regeneration.

pnpm-lock.yaml

pnpm-workspace.yamlBump workspace catalog pin for @hugeicons/react to 1.1.9 +1/-1

Bump workspace catalog pin for @hugeicons/react to 1.1.9

• Updates the workspace-level catalog entry to pin @hugeicons/react at version 1.1.9 so all importers resolve the same version.

pnpm-workspace.yaml

@qodo-code-review

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (2) 📘 Rule violations (0) 📜 Skill insights (0)

Context used
✅ Compliance rules (platform): 22 rules

Grey Divider


Informational

1. Deprecated stream-to-promise 🐞 Bug ⚙ Maintainability
Description
The lockfile now records stream-to-promise@2.2.0 as deprecated, and it is still pulled in
transitively via vercel -> @vercel/fun. This doesn’t prove a functional regression from the
@hugeicons/react bump, but it is a dependency-hygiene risk worth tracking (e.g., for
security/compliance or future ecosystem breakage).
Code

pnpm-lock.yaml[R6676-6678]

  stream-to-promise@2.2.0:
    resolution: {integrity: sha512-HAGUASw8NT0k8JvIVutB2Y/9iBk7gpgEyAudXwNJmZERdMITGdajOa4VJfD/kNiA3TppQpTP4J+CtcHwdzKBAw==}
+    deprecated: Deprecated. Use node:stream/promises and node:stream/consumers instead.
Relevance

⭐ Low

Similar lockfile deprecation/upgrade suggestions were rejected (deprecated next/otplib entries in
pnpm-lock).

PR-#3812

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The lockfile explicitly marks stream-to-promise@2.2.0 as deprecated and shows it is depended on by
@vercel/fun@1.3.0, which is in turn a dependency of vercel@53.1.0.

pnpm-lock.yaml[6676-6679]
pnpm-lock.yaml[9789-9804]
pnpm-lock.yaml[14397-14407]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
`stream-to-promise@2.2.0` is marked deprecated in the lockfile and is brought in via `vercel -> @vercel/fun`.

### Issue Context
This PR refreshes `pnpm-lock.yaml`, which now surfaces the deprecation metadata. The goal is to remove/avoid deprecated transitive dependencies where feasible.

### Fix Focus Areas
- pnpm-workspace.yaml[60-76]
- pnpm-lock.yaml[9789-9804]
- pnpm-lock.yaml[6676-6680]

### Suggested fix
1. Try upgrading `vercel` to a version whose dependency graph no longer includes `@vercel/fun` (or where `@vercel/fun` no longer depends on `stream-to-promise`).
2. Re-run `pnpm install` and verify `stream-to-promise` is no longer present (or no longer deprecated).
3. If removal isn’t currently possible, document/track the transitive deprecation so it’s not “rediscovered” later.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


2. Unmaintained tsconfck 🐞 Bug ⚙ Maintainability
Description
The lockfile now records tsconfck@3.1.6 as deprecated: unmaintained, and it is used by
vite-tsconfig-paths@6.1.1 (part of the build toolchain). This doesn’t indicate an immediate break
from this PR, but it increases long-term maintenance risk for TS/Vite upgrades.
Code

pnpm-lock.yaml[R6943-6946]

  tsconfck@3.1.6:
    resolution: {integrity: sha512-ks6Vjr/jEw0P1gmOVwutM3B7fWxoWBL2KRDb1JfqGVawBmO5UsvmWOQFGHBPl5yxYz4eERr19E6L7NMv+Fej4w==}
    engines: {node: ^18 || >=20}
+    deprecated: unmaintained
Relevance

⭐ Low

History shows lockfile deprecation notices aren’t acted on; no accepted precedent for removing
“unmaintained” deps.

PR-#3812

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The lockfile marks tsconfck@3.1.6 as unmaintained and shows vite-tsconfig-paths@6.1.1 depends on
it.

pnpm-lock.yaml[6943-6947]
pnpm-lock.yaml[14471-14476]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
`tsconfck@3.1.6` is marked `deprecated: unmaintained` in the lockfile and is pulled in by `vite-tsconfig-paths`.

### Issue Context
This PR’s lockfile refresh surfaced the unmaintained status. Since `vite-tsconfig-paths` runs during builds, leaving an unmaintained parser in the toolchain can create avoidable future upgrade friction.

### Fix Focus Areas
- pnpm-workspace.yaml[66-73]
- pnpm-lock.yaml[6943-6947]
- pnpm-lock.yaml[14471-14476]

### Suggested fix
1. Check if a newer `vite-tsconfig-paths` release removes/replaces `tsconfck`.
2. If not, consider an alternative tsconfig-paths solution for Vite, or pin/track this risk explicitly.
3. Re-run `pnpm install` and confirm the dependency graph no longer includes `tsconfck` (or no longer marks it unmaintained).

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant