Skip to content

Update dependency shadcn to v4 - #4051

Merged
amitsingh-007 merged 1 commit into
renovate-updatesfrom
renovate/shadcn-4.x
Jul 9, 2026
Merged

amitsingh-007 merged 1 commit into
renovate-updatesfrom
renovate/shadcn-4.x

Conversation

@amitsingh-007

@amitsingh-007 amitsingh-007 commented Jul 8, 2026 •

Copy link
Copy Markdown
Owner

This PR contains the following updates:

Package Change Age Confidence
shadcn (source) 3.8.5 → 4.13.0 age confidence

Release Notes

shadcn-ui/ui (shadcn)

v4.13.0

Compare Source

Minor Changes

v4.12.0

Compare Source

Minor Changes

v4.11.1

Compare Source

Patch Changes

v4.11.0

Compare Source

Minor Changes
Patch Changes

v4.10.0

Compare Source

Minor Changes

v4.9.0

Compare Source

Minor Changes

v4.8.3

Compare Source

Patch Changes

v4.8.2

Compare Source

Patch Changes

v4.8.1

Compare Source

Patch Changes

v4.8.0

Compare Source

Minor Changes
Patch Changes

v4.7.0

Compare Source

Minor Changes
Patch Changes

v4.6.0

Compare Source

Minor Changes
Patch Changes

v4.5.0

Compare Source

Minor Changes

v4.4.0

Compare Source

Minor Changes
Patch Changes

v4.3.1

Compare Source

Patch Changes

v4.3.0

Compare Source

Minor Changes

v4.2.0

Compare Source

Minor Changes

v4.1.2

Compare Source

Patch Changes

v4.1.1

Compare Source

Patch Changes

v4.1.0

Compare Source

Minor Changes

v4.0.8

Compare Source

Patch Changes

v4.0.7

Compare Source

Patch Changes

v4.0.6

Compare Source

Patch Changes

v4.0.5

Compare Source

Patch Changes

v4.0.4

Compare Source

Patch Changes

v4.0.3

Compare Source

Patch Changes

v4.0.2

Compare Source

Patch Changes

v4.0.1

Compare Source

Patch Changes

v4.0.0

Compare Source

Major Changes
Patch Changes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 of the month (* 0-3 1 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

Greptile Summary

This Renovate-generated PR bumps the shadcn CLI dependency from 3.8.5 to 4.13.0 in the pnpm workspace catalog. The project's packages/ui already targets the v4 schema — components.json references style: base-nova and @base-ui/react is a declared peer dependency — so no components.json migration is required.

  • pnpm-workspace.yaml: single-line version bump in the catalog entry for shadcn.
  • pnpm-lock.yaml: reflects the new transitive dependency tree, including removal of @inquirer/*, @mswjs/interceptors, and other packages that were replaced or bundled directly by shadcn v4.

Confidence Score: 5/5

Straightforward CLI tooling version bump; the project is already aligned with the v4 schema and no application runtime code is affected.

Only the shadcn CLI tool (a devDependency) is updated, and the project's components.json and peer dependencies show it was already configured for v4.x. No application logic, runtime paths, or existing component source files are changed by this PR.

No files require special attention.

Reviews (3): Last reviewed commit: "Update dependency shadcn to v4" | Re-trigger Greptile

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Bump shadcn to v4.13.0 (pnpm catalog + lockfile)

⚙️ Configuration changes 🕐 20-40 Minutes

Grey Divider

AI Description

• Update shadcn dependency from 3.8.5 to 4.13.0 via pnpm catalog.
• Refresh pnpm lockfile to reflect new shadcn v4 transitive dependency graph.
• Introduce stricter Node engine requirement from shadcn v4 (>=20.18.1).
Diagram

graph TD
  A(["Dev/CI install"]) --> B["pnpm-workspace.yaml (catalog)"] --> C["pnpm-lock.yaml"] --> D(["shadcn CLI v4.13.0"]) --> E(["Node >=20.18.1"]) --> F{{"shadcn registry"}}
  subgraph Legend
    direction LR
    _run(["Runner/Tool"]) ~~~ _file["Config/Lockfile"] ~~~ _ext{{"External"}}
  end
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Bundle Node/CI upgrade in the same PR
  • ➕ Avoids surprise breakages if CI or dev machines run <20.18.1
  • ➕ Makes the upgrade path explicit and verifiable in one review
  • ➖ Broadens scope beyond dependency update
  • ➖ May require coordinating platform/tooling changes across repos/environments
2. Stage the upgrade (Node/tooling first, then shadcn v4)
  • ➕ Reduces blast radius by validating Node upgrade independently
  • ➕ Simplifies rollback if the Node bump has unrelated issues
  • ➖ Takes two PRs and more coordination time
  • ➖ Delays adoption of shadcn v4
3. Pin shadcn to v3 until Node baseline is confirmed
  • ➕ Zero immediate risk to CI/runtime compatibility
  • ➕ Buys time to validate v4 migration requirements
  • ➖ Misses v4 features and fixes
  • ➖ Accumulates upgrade debt and may make future jump larger

Recommendation: Proceed with this bump only if the repo’s CI and developer baseline already meet shadcn v4’s engine requirement (Node >=20.18.1). If not, prefer staging: upgrade Node/tooling first (or include it in this PR) to prevent install/CLI failures when running pnpm install or shadcn commands.

Files changed (2) +21 / -293

Other (2) +21 / -293
pnpm-lock.yamlResolve shadcn v4 lockfile graph (Node engine + transitive deps) +20/-292

Resolve shadcn v4 lockfile graph (Node engine + transitive deps)

• Updates the pinned shadcn version to 4.13.0 and refreshes the resolved dependency tree. The lockfile reflects shadcn v4’s stricter Node engine requirement (>=20.18.1) and associated transitive dependency shifts (e.g., removal of node-fetch-related deps and addition of undici, plus minor bumps like postcss).

pnpm-lock.yaml

pnpm-workspace.yamlBump workspace catalog shadcn pin to 4.13.0 +1/-1

Bump workspace catalog shadcn pin to 4.13.0

• Updates the workspace catalog entry to pin shadcn from 3.8.5 to 4.13.0 so all importers resolve the new major version consistently.

pnpm-workspace.yaml

Comment thread pnpm-lock.yaml
Comment on lines 6394 to +6397
setprototypeof@1.2.0:
resolution: {integrity: sha512-E5LDX7Wrp85Kil5bhZv46j8jOeboKq5JMmYM3gVGdGH8xFpPWXUMsNrlODCrkoxMEeNi/XZIwuRvY4XNwYMJpw==}

shadcn@3.8.5:
resolution: {integrity: sha512-jPRx44e+eyeV7xwY3BLJXcfrks00+M0h5BGB9l6DdcBW4BpAj4x3lVmVy0TXPEs2iHEisxejr62sZAAw6B1EVA==}
shadcn@4.13.0:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 New Node.js engine minimum constraint

shadcn@4.13.0 (and its new undici@7.28.0 dependency) adds an explicit engines: {node: '>=20.18.1'} requirement that was absent in 3.8.5. Any CI pipeline or developer environment running Node 20 below patch 20.18.1 (e.g., 20.17.x) will break when invoking the shadcn CLI. Worth verifying the Node version pinned in CI satisfies this constraint before merging.

Prompt To Fix With AI
This is a comment left during a code review.
Path: pnpm-lock.yaml
Line: 6394-6397

Comment:
**New Node.js engine minimum constraint**

`shadcn@4.13.0` (and its new `undici@7.28.0` dependency) adds an explicit `engines: {node: '>=20.18.1'}` requirement that was absent in `3.8.5`. Any CI pipeline or developer environment running Node 20 below patch `20.18.1` (e.g., `20.17.x`) will break when invoking the `shadcn` CLI. Worth verifying the Node version pinned in CI satisfies this constraint before merging.

How can I resolve this? If you propose a fix, please make it concise.

Comment thread pnpm-lock.yaml
@qodo-code-review

qodo-code-review Bot commented Jul 8, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (2) 📘 Rule violations (0) 📜 Skill insights (0)

Context used
✅ Compliance rules (platform): 22 rules

Grey Divider


Remediation recommended

1. Unenforced Node engine bump 🐞 Bug ☼ Reliability
Description
shadcn@4.13.0 (and its transitive undici) require Node.js >=20.18.1, but the repo has no
explicit Node version constraint, so installs/CLI usage can break on older Node versions depending
on the environment/package-manager settings.
Code

pnpm-lock.yaml[R6397-6399]

+  shadcn@4.13.0:
+    resolution: {integrity: sha512-5fuJ4jI/GcPeA/iTL4cJivCZuYQGXz/N3bIzyd+Gd/FM6xUCy2MxGG+LaDQuw2cjNy9zGPSFPTEmI048UwPTZA==}
+    engines: {node: '>=20.18.1'}
Relevance

⭐⭐ Medium

No prior reviews enforcing engines.node/.nvmrc; lockfile Node engines tolerated (e.g., PR #3812).

PR-#3812

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The lockfile explicitly declares Node >=20.18.1 for shadcn and undici, while the repo root
package.json does not declare an engines.node constraint (so there is no built-in guard for
non-CI environments). CI uses Node 24, which can mask local incompatibilities.

pnpm-lock.yaml[6397-6401]
pnpm-lock.yaml[6939-6942]
package.json[1-34]
.github/workflows/build.yml[23-28]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
After upgrading to `shadcn@4.13.0`, the dependency graph requires Node.js `>=20.18.1` (e.g., via `shadcn` and `undici`). The repo currently does not declare a Node engine requirement, which can lead to environment-dependent failures when running `pnpm install` or `shadcn` on older Node versions.

## Issue Context
CI uses Node 24, but local/dev or other automation (Vercel/project settings, contributors) may run older Node and hit engine incompatibilities.

## Fix Focus Areas
- package.json[1-40]
- pnpm-lock.yaml[6397-6401]
- pnpm-lock.yaml[6939-6942]

## Suggested fix
- Add an `engines` field at the repo root, e.g.:
 - `"engines": { "node": ">=20.18.1" }` (or a higher minimum if that’s the project standard)
- Optionally add a Node version pin file (e.g., `.nvmrc` / `.node-version`) to align developer environments with CI.
- If you want installs to hard-fail on mismatch, document enabling engine checks (team policy) rather than relying on warnings.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools



Informational

2. shadcn script version drift 🐞 Bug ⚙ Maintainability
Description
The workspace now pins shadcn to 4.13.0, but update:shadcn still runs pnpx shadcn@latest, so
updates can be generated with a different CLI version than the one pinned/locked in this repo.
Code

pnpm-workspace.yaml[60]

+  shadcn: 4.13.0
Relevance

⭐ Low

Repo previously kept update:shadcn running pnpx shadcn@latest; related script-change suggestions
rejected (PR #3946).

PR-#3946

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The catalog pins shadcn: 4.13.0, but the update script explicitly invokes shadcn@latest, which
can resolve to a different version than the one pinned in the repo.

pnpm-workspace.yaml[57-61]
package.json[11-18]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The repo pins `shadcn` via the workspace catalog, but the `update:shadcn` script uses `pnpx shadcn@latest`, which bypasses the pinned version and can lead to non-reproducible component generation.

## Issue Context
This is especially relevant right after a major upgrade, since the CLI’s behavior/templates may change between versions.

## Fix Focus Areas
- package.json[11-18]
- pnpm-workspace.yaml[57-61]

## Suggested fix
- Change the script to use the workspace-installed/pinned CLI, e.g. one of:
 - `pnpm -C packages/ui exec shadcn add ...`
 - or `pnpm -C packages/ui dlx shadcn@4.13.0 add ...` (explicit pin)
- This ensures the generated output corresponds to the version you’re upgrading/testing against.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

Comment thread pnpm-lock.yaml
Comment on lines +6397 to +6399
shadcn@4.13.0:
resolution: {integrity: sha512-5fuJ4jI/GcPeA/iTL4cJivCZuYQGXz/N3bIzyd+Gd/FM6xUCy2MxGG+LaDQuw2cjNy9zGPSFPTEmI048UwPTZA==}
engines: {node: '>=20.18.1'}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remediation recommended

1. Unenforced node engine bump 🐞 Bug ☼ Reliability

shadcn@4.13.0 (and its transitive undici) require Node.js >=20.18.1, but the repo has no
explicit Node version constraint, so installs/CLI usage can break on older Node versions depending
on the environment/package-manager settings.
Agent Prompt
## Issue description
After upgrading to `shadcn@4.13.0`, the dependency graph requires Node.js `>=20.18.1` (e.g., via `shadcn` and `undici`). The repo currently does not declare a Node engine requirement, which can lead to environment-dependent failures when running `pnpm install` or `shadcn` on older Node versions.

## Issue Context
CI uses Node 24, but local/dev or other automation (Vercel/project settings, contributors) may run older Node and hit engine incompatibilities.

## Fix Focus Areas
- package.json[1-40]
- pnpm-lock.yaml[6397-6401]
- pnpm-lock.yaml[6939-6942]

## Suggested fix
- Add an `engines` field at the repo root, e.g.:
  - `"engines": { "node": ">=20.18.1" }` (or a higher minimum if that’s the project standard)
- Optionally add a Node version pin file (e.g., `.nvmrc` / `.node-version`) to align developer environments with CI.
- If you want installs to hard-fail on mismatch, document enabling engine checks (team policy) rather than relying on warnings.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

@amitsingh-007
amitsingh-007 force-pushed the renovate/shadcn-4.x branch from 836d6e6 to 69fddca Compare July 9, 2026 13:04
@amitsingh-007
amitsingh-007 enabled auto-merge July 9, 2026 13:11
@amitsingh-007
amitsingh-007 force-pushed the renovate/shadcn-4.x branch from 69fddca to dd81e20 Compare July 9, 2026 13:18
@amitsingh-007
amitsingh-007 merged commit 332e105 into renovate-updates Jul 9, 2026
2 checks passed
@amitsingh-007
amitsingh-007 deleted the renovate/shadcn-4.x branch July 9, 2026 13:18
@greptile-apps

greptile-apps Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

Want your agent to iterate on Greptile's feedback? Try greploops.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant