Skip to content

Renovate updates - #4062

Merged
amitsingh-007 merged 115 commits into
mainfrom
renovate-updates
Jul 11, 2026
Merged

amitsingh-007 merged 115 commits into
mainfrom
renovate-updates

Conversation

@amitsingh-007

@amitsingh-007 amitsingh-007 commented Jul 10, 2026 •

Copy link
Copy Markdown
Owner

Check if the Pull Request fulfils these requirements

  • Does the extension require a version change?

Summary by Sourcery

Update dependencies and tooling across the monorepo, including the browser extension, and align configs with the new stack.

New Features:

  • Introduce @tanstack/react-store and related selector usage in the extension.
  • Enable tsconfig-based path resolution in the extension build via Vite React plugin.
  • Add explicit type support for node and chrome in the extension TypeScript configuration.

Bug Fixes:

  • Guard against null responses from Firebase auth sign-in and token refresh to avoid invalid state updates.
  • Wrap the avatar editor in a container to preserve background styling while updating types for its ref usage.

Enhancements:

  • Upgrade multiple catalog dependencies to newer versions, including React, Next.js, Tailwind CSS, Firebase, Playwright, Vite, TypeScript, and related libraries.
  • Remove Preact-specific dependencies and configuration in favor of a pure React setup for the extension and shared UI.
  • Tighten and simplify TypeScript path configurations in web, extension, and UI projects to rely on relative paths and shared base config.
  • Update monorepo packageManager version to pnpm 11.10.0.

Build:

  • Add allowBuilds configuration to pnpm-workspace to prevent builds of selected dependencies.
  • Adjust pnpm-workspace catalog entries to track updated dependency versions across apps and packages.

CI:

  • Bump GitHub Actions versions (checkout, pnpm setup, cache, release tag, GitHub release) in release, build, Playwright, downmerge, and Renovate workflows.

Deployment:

  • Update Vercel-related dependencies in the catalog for analytics and speed insights.

Documentation:

  • Refresh AGENTS.md to reflect the extension’s move from Preact to React and simplify the frontend tech stack description.

Tests:

  • Upgrade Playwright test dependency and associated caching setup in CI workflows.

Chores:

  • Bump the browser extension version from 24.9.0 to 24.10.0.
  • Remove unused dependencies such as preact, wouter-preact, and vite-tsconfig-paths from packages and apps.

Greptile Summary

This PR upgrades the monorepo's dependency catalog across the board (React 19.2.6, Next.js 16.2.10, TypeScript 6.0.3, Vite 8.1.3, Firebase 12.15.0, Tailwind 4.3.2, and many others) while migrating the browser extension from Preact to React and fixing several correctness issues.

  • Preact → React extension migration: Replaces @preact/preset-vite + vite-tsconfig-paths with @vitejs/plugin-react and Vite 8's native resolve.tsconfigPaths: true; removes wouter-preact alias and dependency.
  • Correctness fixes: Adds null guards for Firebase signInWithCredential and refreshIdToken responses; wraps preload operations in try/finally so setIsLoading(false) always executes; moves setShouldPreloadData(false) into .finally() to prevent stuck state on errors.
  • API and type updates: Migrates from useStore (@tanstack/react-form) to useSelector (@tanstack/react-store) for form store subscriptions; updates AvatarEditor ref type to the newer AvatarEditorRef from react-avatar-editor 15.x; adjusts "use client" directives in shared UI components to reflect actual client-boundary requirements.

Confidence Score: 5/5

Safe to merge — the changes are well-scoped dependency upgrades paired with targeted correctness improvements and no regressions were identified.

All logic changes are improvements: null guards prevent silent invalid state, try/finally ensures loading flags are always cleared, and the Preact-to-React migration is internally consistent. The resolve.tsconfigPaths: true option is confirmed as a native Vite 8 feature.

No files require special attention.

Reviews (7): Last reviewed commit: "Update shadcn ui components; preserve sc..." | Re-trigger Greptile

amitsingh-007 and others added 30 commits May 10, 2026 09:03
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…xt-release-tag-6.x

Update amitsingh-007/next-release-tag action to v6.5.0
@webext-bot

webext-bot Bot commented Jul 10, 2026

Copy link
Copy Markdown
Extension Size Change:   50.24 KB 🔺
Commit e17bfae
Latest release size 216.10 KB
Current size 266.34 KB
Percent change 23.25 %

Significant size increase in this commit ⚠️

@webext-bot

webext-bot Bot commented Jul 10, 2026

Copy link
Copy Markdown

Extension version is updated from 24.9.0 to 24.10.0

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've left some high level feedback:

Fixed security issues:

  • fast-xml-parser (link) · Dashboard

  • next (link) · Dashboard

  • node-forge (link) · Dashboard

  • protobufjs (link) · Dashboard

  • In ImagePicker.tsx, the ref type for imageCropperRef is now useRef<AvatarEditorRef>(null), but AvatarEditorRef likely doesn’t include null; consider typing this as AvatarEditorRef | null to avoid type mismatches with useRef’s initial value.

  • The new early returns in useFirebaseStore when signInWithCredential or refreshIdToken return falsy values silently abort the operation; consider surfacing an explicit error state or logging so callers can distinguish between a missing token and a transient failure.

Prompt for AI Agents
Please address the comments from this code review:

## Overall Comments
- In `ImagePicker.tsx`, the ref type for `imageCropperRef` is now `useRef<AvatarEditorRef>(null)`, but `AvatarEditorRef` likely doesn’t include `null`; consider typing this as `AvatarEditorRef | null` to avoid type mismatches with `useRef`’s initial value.
- The new early returns in `useFirebaseStore` when `signInWithCredential` or `refreshIdToken` return falsy values silently abort the operation; consider surfacing an explicit error state or logging so callers can distinguish between a missing token and a transient failure.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

@webext-bot

webext-bot Bot commented Jul 10, 2026

Copy link
Copy Markdown
Extension Size Change:   50.25 KB 🔺
Commit d294908
Latest release size 216.10 KB
Current size 266.34 KB
Percent change 23.25 %

Significant size increase in this commit ⚠️

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Upgrade pnpm to v11 and refresh monorepo deps/CI; migrate extension build to React

✨ Enhancement ⚙️ Configuration changes 🐞 Bug fix 📝 Documentation 🕐 40+ Minutes

Grey Divider

AI Description

• Upgrade pnpm/tooling and refresh dependency catalog for the monorepo.
• Update GitHub Actions workflows and Renovate configuration to match new tooling versions.
• Migrate the extension build from Preact-centric setup to React/Vite plugin and adjust app code.
Diagram

graph TD
  A["Renovate config"] --> B["Dependency catalog (pnpm-workspace.yaml)"] --> C["pnpm@11 workspace"] --> D["Turbo builds"] --> E["WXT/Vite (extension)"] --> F["Extension UI code"]
  G["GitHub Actions workflows"] --> C
  E --> H["TS configs"]

  subgraph Legend
    direction LR
    _cfg["Config"] ~~~ _ci["CI workflow"] ~~~ _app["App code"]
  end
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Keep Preact-based extension build (preact preset + wouter-preact alias)
  • ➕ Avoids behavioral/perf differences between React and Preact
  • ➕ Reduces churn in extension build pipeline
  • ➖ Continues carrying Preact-specific dependencies and routing aliasing
  • ➖ May block/complicate future upgrades that assume React-first tooling
2. Split into two PRs: tooling/deps vs. runtime/code changes
  • ➕ Easier rollback if a dependency bump breaks CI/build
  • ➕ Simplifies review by separating config churn from functional changes
  • ➖ More coordination overhead
  • ➖ May require temporary intermediate states or extra Renovate management
3. Use vite-tsconfig-paths plugin instead of WXT tsconfigPaths option
  • ➕ Keeps TS path resolution behavior consistent with generic Vite projects
  • ➕ Potentially clearer debugging if other apps already use the plugin
  • ➖ Extra plugin dependency and config surface
  • ➖ WXT-native support may be better integrated/maintained

Recommendation: The current approach is reasonable: pnpm v11 upgrades often require workspace-level adjustments (e.g., allowBuilds), and moving the extension to a React-first Vite/WXT setup reduces Preact-specific complexity. If this PR becomes flaky in CI, consider splitting (tooling vs code) to isolate breakage, but otherwise the unified upgrade is acceptable.

Files changed (20) +123 / -112

Bug fix (2) +23 / -16
ImagePicker.tsxTighten AvatarEditor ref typing and wrapper styling +17/-16

Tighten AvatarEditor ref typing and wrapper styling

• Updates the ref type to AvatarEditorRef and wraps the editor in a styled container to preserve rounded/background styling. Improves type correctness and avoids relying on the component type as a ref target.

apps/extension/src/entrypoints/popup/panels/PersonsPanel/components/ImagePicker.tsx

useFirebaseStore.tsAdd null-guards around auth/token refresh responses +6/-0

Add null-guards around auth/token refresh responses

• Adds early returns when sign-in or token refresh responses are missing. Prevents downstream state updates from running on undefined/null auth payloads.

apps/extension/src/store/firebase/useFirebaseStore.ts

Refactor (1) +3 / -2
AddOrEditPersonDialog.tsxSwitch TanStack store subscription hook +3/-2

Switch TanStack store subscription hook

• Replaces @tanstack/react-form's useStore usage with @tanstack/react-store's useSelector for reading form store state. This aligns with the newly introduced react-store dependency/API surface.

apps/extension/src/entrypoints/popup/panels/PersonsPanel/components/AddOrEditPersonDialog.tsx

Documentation (1) +2 / -2
AGENTS.mdUpdate monorepo tech stack documentation for extension +2/-2

Update monorepo tech stack documentation for extension

• Removes Preact-specific references for the extension and updates the frontend tech list accordingly. Keeps contributor docs consistent with the current build/runtime choices.

AGENTS.md

Other (16) +95 / -92
renovate-config.jsonScope Renovate to explicit repository +2/-1

Scope Renovate to explicit repository

• Adds a repositories list and adjusts JSON formatting for Renovate configuration. This makes Renovate target a specific repo rather than relying on implicit context.

.github/renovate-config.json

build.ymlBump CI actions for checkout and pnpm setup +2/-2

Bump CI actions for checkout and pnpm setup

• Updates actions/checkout to v7 and pnpm/action-setup to v6. Keeps the build workflow aligned with newer action versions.

.github/workflows/build.yml

downmerge.ymlUpdate checkout action version in downmerge workflow +1/-1

Update checkout action version in downmerge workflow

• Moves actions/checkout from v6 to v7. No behavioral changes beyond consuming the newer upstream action release.

.github/workflows/downmerge.yml

playwright.ymlRefresh Playwright workflow actions and caching +5/-5

Refresh Playwright workflow actions and caching

• Updates checkout to v7, pnpm setup to v6, and cache action to v6. This modernizes CI dependencies used for Playwright runs.

.github/workflows/playwright.yml

release.ymlUpdate release workflow actions and tagging/release steps +10/-10

Update release workflow actions and tagging/release steps

• Bumps checkout/pnpm/cache actions, upgrades next-release-tag action, and moves softprops/action-gh-release to v3. Keeps release automation current with upstream action changes.

.github/workflows/release.yml

renovate.ymlUpdate checkout action used by Renovate workflow +1/-1

Update checkout action used by Renovate workflow

• Upgrades actions/checkout to v7 in the Renovate self-hosted workflow. Improves consistency across workflows.

.github/workflows/renovate.yml

package.jsonBump extension version and drop Preact-related deps +4/-5

Bump extension version and drop Preact-related deps

• Increments extension version to 24.10.0, adds @tanstack/react-store, and replaces Preact/Vite preset with React Vite plugins. Removes wouter-preact and other Preact-related tooling deps to align with React-first build setup.

apps/extension/package.json

tsconfig.jsonAdjust extension TS libs and add chrome/node types +2/-2

Adjust extension TS libs and add chrome/node types

• Removes dom.iterable from lib, adds explicit types for node and chrome, and drops baseUrl override. Aligns the extension’s TS environment with updated shared/base config expectations.

apps/extension/tsconfig.json

wxt.config.tsMigrate WXT/Vite config from Preact preset to React plugin +4/-4

Migrate WXT/Vite config from Preact preset to React plugin

• Replaces @preact/preset-vite and vite-tsconfig-paths usage with @vitejs/plugin-react and WXT’s tsconfigPaths option. Removes the wouter-preact aliasing and simplifies the plugin chain.

apps/extension/wxt.config.ts

tsconfig.jsonNormalize TS path mappings to explicit relative prefixes +4/-5

Normalize TS path mappings to explicit relative prefixes

• Removes baseUrl and updates path aliases to use explicit ./ prefixes. Improves portability and consistency with TS 'bundler' resolution expectations.

apps/web/tsconfig.json

package.jsonUpgrade workspace packageManager to pnpm v11 +1/-1

Upgrade workspace packageManager to pnpm v11

• Updates the packageManager field from pnpm@10.x to pnpm@11.10.0. Ensures local and CI tooling uses the intended pnpm major version.

package.json

tsconfig.base.jsonUpdate base TS config libs/types and interop settings +2/-3

Update base TS config libs/types and interop settings

• Removes dom.iterable from lib, adds node types, and drops some interop-related flags. Centralizes updated TS defaults for packages that extend this base config.

packages/configs/tsconfig.base.json

package.jsonRemove Preact dependency from shared package +0/-1

Remove Preact dependency from shared package

• Drops preact from dependencies, reflecting a React-only shared layer. Reduces duplicated/unused runtime dependencies across the workspace.

packages/shared/package.json

package.jsonRemove Preact dependency from UI package +0/-1

Remove Preact dependency from UI package

• Removes preact from the UI package dependencies. Aligns UI package runtime expectations with React-only consumers.

packages/ui/package.json

tsconfig.jsonDrop baseUrl override from UI TS config +0/-1

Drop baseUrl override from UI TS config

• Removes baseUrl from compilerOptions while keeping explicit path mappings. Reduces divergence from the shared base TS config.

packages/ui/tsconfig.json

pnpm-workspace.yamlAdd pnpm v11 allowBuilds and refresh version catalog +57/-49

Add pnpm v11 allowBuilds and refresh version catalog

• Introduces allowBuilds entries to control postinstall/build scripts for select packages and updates many catalog versions (tooling, frontend libs, and build chain). Also adds @tanstack/react-store and updates major versions like TypeScript and Vite.

pnpm-workspace.yaml

Comment thread apps/extension/package.json
Comment thread pnpm-workspace.yaml
@qodo-code-review

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (2) 📘 Rule violations (1) 📜 Skill insights (0)

Context used
✅ Compliance rules (platform): 22 rules

Grey Divider


Action required

1. Native builds disabled 🐞 Bug ☼ Reliability
Description
pnpm-workspace.yaml disables builds for sharp (and esbuild) via allowBuilds: ... false, but
the web app imports and executes sharp in a runtime API utility. If this setting prevents
install/postinstall build steps, it can cause CI/runtime failures when sharp (native) and tooling
dependencies aren’t prepared correctly.
Code

pnpm-workspace.yaml[R5-13]

+allowBuilds:
+  '@firebase/util': false
+  esbuild: false
+  lefthook: false
+  msw: false
+  protobufjs: false
+  sharp: false
+  spawn-sync: false
+  unrs-resolver: false
Relevance

⭐⭐ Medium

No historical evidence found for pnpm allowBuilds disabling sharp/esbuild; unclear team preference.

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The workspace explicitly sets sharp: false under allowBuilds, while the web code imports and
uses sharp() in a server-side utility, so blocking sharp build/install steps risks breaking that
runtime path.

pnpm-workspace.yaml[5-13]
apps/web/src/app/api/upload-file/utils.ts[1-12]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
The workspace config disables builds for packages that are required at runtime/tooling, notably `sharp` (used by the web API) and `esbuild` (commonly required by bundlers/tooling). This can break installs or runtime execution depending on how pnpm enforces `allowBuilds`.

### Issue Context
`sharp` is imported and used directly in the web API upload utilities.

### Fix Focus Areas
- pnpm-workspace.yaml[5-13]
- apps/web/src/app/api/upload-file/utils.ts[1-12]

### Suggested fix
Adjust `allowBuilds` so packages that must run native/tooling install steps are not disabled, e.g. remove `sharp`/`esbuild` entries or set them to allow builds (according to the intended pnpm semantics in this repo). Then verify `pnpm install` + web build/test in CI succeeds.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools



Informational

2. Unapproved packages/ui dependency edit 📘 Rule violation § Compliance
Description
Pre-existing configuration files under packages/ui (packages/ui/package.json and
packages/ui/tsconfig.json) were modified without any explicit UI approval reference. This violates
the rule that non-new-component changes in packages/ui must be explicitly approved.
Code

packages/ui/package.json[27]

-    "preact": "catalog:",
Relevance

⭐ Low

packages/ui config edits have been merged repeatedly without explicit UI-approval references,
suggesting rule isn’t enforced.

PR-#3946
PR-#3935

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The compliance rule requires explicit approval for modifications to existing packages/ui files
unless the change is only adding a new component. Both packages/ui/package.json and
packages/ui/tsconfig.json are existing config files, and the cited changes reflect a modified
dependency set and a configuration update respectively, yet include no approval reference,
demonstrating the required explicit UI approval is missing.

Rule 1805904: Restrict modifications in packages/ui to new components or approved changes
packages/ui/package.json[1-34]
packages/ui/tsconfig.json[1-14]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Pre-existing files under `packages/ui` were modified (dependency and TypeScript configuration changes) without an explicit UI approval reference, which is required for any non-new-component change in `packages/ui`.

## Issue Context
Compliance requires that modifications to existing `packages/ui` files are limited to adding new components, or otherwise must be explicitly approved (e.g., via a UI approval ID/link).

## Fix Focus Areas
- packages/ui/package.json[1-34]
- packages/ui/tsconfig.json[1-14]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


3. Interop flags removed 🐞 Bug ≡ Correctness
Description
tsconfig.base.json no longer enables esModuleInterop/allowSyntheticDefaultImports, but the
codebase uses default imports from Node built-ins (e.g. import path from 'node:path'), which
typically requires one of those flags with @types/node. This is likely to break TypeScript
type-check/build for config/test/server files that import node:* modules as defaults.
Code

packages/configs/tsconfig.base.json[R5-20]

    "target": "esnext",
    "moduleResolution": "bundler",
    "jsx": "react-jsxdev",
-    "lib": ["esnext", "dom", "dom.iterable"],
+    "lib": ["esnext", "dom"],
+    "types": ["node"],
    "strict": true,
    "allowUnreachableCode": false,
    "allowUnusedLabels": false,
    "allowImportingTsExtensions": true,
-    "allowSyntheticDefaultImports": true,
    "noImplicitReturns": true,
    "noFallthroughCasesInSwitch": true,
    "importHelpers": true,
    "forceConsistentCasingInFileNames": true,
-    "esModuleInterop": true,
    "resolveJsonModule": true,
    "isolatedModules": true,
    "incremental": true,
Relevance

⭐ Low

tsconfig.base already worked without interop in past; repo uses node:* default imports in merged
PRs.

PR-#3788
PR-#3880

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The base TS config now omits interop flags, while multiple repo files still default-import Node
built-ins (node:path, node:process, node:fs), a pattern that relies on those flags with the
Node typings.

packages/configs/tsconfig.base.json[1-23]
apps/extension/wxt.config.ts[1-11]
packages/trpc/src/constants/env.ts[1-15]
playwright.config.ts[1-6]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
The shared TS base config removed CommonJS/`export =` interop options, while the repo still uses default imports from `node:*` modules. This mismatch can cause TypeScript compilation errors.

### Issue Context
Examples in-repo include default imports from `node:path`, `node:process`, and `node:fs`.

### Fix Focus Areas
- packages/configs/tsconfig.base.json[1-23]
- apps/extension/wxt.config.ts[1-6]
- packages/trpc/src/constants/env.ts[1-15]
- playwright.config.ts[1-6]

### Suggested fix
Either:
1) Re-add interop options in `packages/configs/tsconfig.base.json`:
  - `"esModuleInterop": true`
  - `"allowSyntheticDefaultImports": true`

OR
2) Update all default imports from Node built-ins to namespace imports (e.g. `import * as path from 'node:path'`) and remove reliance on synthetic defaults.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

Comment thread pnpm-workspace.yaml
@coderabbitai

coderabbitai Bot commented Jul 10, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

The pull request updates workspace dependencies, pnpm and Turbo configuration, TypeScript settings, and the extension’s migration from Preact to React. It adds runtime guards for Firebase operations, observes DOM mutations when disabling autocomplete, and improves preload cleanup in the web app. Vercel schema metadata is added. GitHub Actions and Renovate configurations are updated with newer action versions and repository settings.

Possibly related issues

Possibly related PRs

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Title check ❓ Inconclusive The title is relevant but too generic to convey the main change. Use a more specific title that highlights the main update, such as the extension React migration and dependency refresh.
✅ Passed checks (3 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description check ✅ Passed The description satisfies the template by answering the required version-change question and includes a detailed summary.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch renovate-updates

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🧹 Nitpick comments (1)
.github/workflows/release.yml (1)

178-179: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick win

Disable checkout credential persistence in Create_Release.

This job does not run git commands after checkout and passes GITHUB_TOKEN directly to the release action. Avoid leaving checkout credentials available to later artifact-processing steps.

Proposed fix
       - name: Checkout repository
         uses: actions/checkout@v7
+        with:
+          persist-credentials: false
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/release.yml around lines 178 - 179, Update the checkout
step in the Create_Release job to disable credential persistence by configuring
actions/checkout with persist-credentials: false, while preserving the existing
repository checkout behavior.

Source: Linters/SAST tools

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@apps/extension/tsconfig.json`:
- Around line 5-6: Restore "dom.iterable" in the lib array of the extension
tsconfig, or refactor forumPageLinks.ts to avoid spreading querySelectorAll()
results; preserve type-checking for iterable DOM collections while retaining the
existing node, chrome, esnext, and dom libraries.

In `@apps/extension/wxt.config.ts`:
- Around line 31-36: Replace the undocumented resolve.tsconfigPaths
configuration in the WXT defineConfig setup with WXT’s top-level alias option,
mapping each project path alias to its corresponding directory. Remove the
resolve.tsconfigPaths block and preserve the existing plugins and build
settings.

---

Nitpick comments:
In @.github/workflows/release.yml:
- Around line 178-179: Update the checkout step in the Create_Release job to
disable credential persistence by configuring actions/checkout with
persist-credentials: false, while preserving the existing repository checkout
behavior.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: c3161fcc-fafe-4580-a7e8-21a393223ab1

📥 Commits

Reviewing files that changed from the base of the PR and between 69736b5 and d294908.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (20)
  • .github/renovate-config.json
  • .github/workflows/build.yml
  • .github/workflows/downmerge.yml
  • .github/workflows/playwright.yml
  • .github/workflows/release.yml
  • .github/workflows/renovate.yml
  • AGENTS.md
  • apps/extension/package.json
  • apps/extension/src/entrypoints/popup/panels/PersonsPanel/components/AddOrEditPersonDialog.tsx
  • apps/extension/src/entrypoints/popup/panels/PersonsPanel/components/ImagePicker.tsx
  • apps/extension/src/store/firebase/useFirebaseStore.ts
  • apps/extension/tsconfig.json
  • apps/extension/wxt.config.ts
  • apps/web/tsconfig.json
  • package.json
  • packages/configs/tsconfig.base.json
  • packages/shared/package.json
  • packages/ui/package.json
  • packages/ui/tsconfig.json
  • pnpm-workspace.yaml
💤 Files with no reviewable changes (3)
  • packages/ui/package.json
  • packages/shared/package.json
  • packages/ui/tsconfig.json

Comment thread apps/extension/tsconfig.json
Comment thread apps/extension/wxt.config.ts
…nputs

Wikipedia and other sites add input elements dynamically after page load.
The previous one-shot script injection missed these inputs, causing flaky
E2E test failures. A MutationObserver ensures all dynamically-added inputs
also get autocomplete=off.
@webext-bot

webext-bot Bot commented Jul 10, 2026

Copy link
Copy Markdown
Extension Size Change:   50.35 KB 🔺
Commit e3a77ce
Latest release size 216.10 KB
Current size 266.45 KB
Percent change 23.30 %

Significant size increase in this commit ⚠️

@webext-bot

webext-bot Bot commented Jul 10, 2026

Copy link
Copy Markdown
Extension Size Change:   50.35 KB 🔺
Commit 026a4c5
Latest release size 216.10 KB
Current size 266.45 KB
Percent change 23.30 %

Significant size increase in this commit ⚠️

firebase-admin 14 requires Node >=22 at runtime; pin engines.node so the
Vercel deployment runs a compatible Node version (fixes web-auth-setup e2e
where token verification failed on the old runtime, leaving the Logout
button permanently disabled).

Also wrap the bookmarks/persons preload in try/finally (and catch the
preload effect) so a failed request resets isLoading instead of pinning
the account UI in a disabled state.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@webext-bot

webext-bot Bot commented Jul 11, 2026

Copy link
Copy Markdown
Extension Size Change:   50.35 KB 🔺
Commit 77ea98c
Latest release size 216.10 KB
Current size 266.45 KB
Percent change 23.30 %

Significant size increase in this commit ⚠️

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (3)
apps/extension/src/entrypoints/background/misc/turnOffInputSuggestions.ts (1)

2-13: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick win

Consider filtering mutations to avoid re-processing all inputs on every DOM change.

The MutationObserver fires on every childList change across the entire document subtree. Each callback re-queries and re-sets autocomplete="off" on all inputs, even ones already processed. On dynamic pages (modals, tooltips, virtual scrolling), this can fire frequently and cause unnecessary work.

An alternative is to inspect mutation.addedNodes and only process newly inserted inputs:

♻️ Optional optimization
 const turnOffAutocomplete = () => {
-  const apply = () =>
-    document
-      .querySelectorAll('input')
-      .forEach((ele) => ele.setAttribute('autocomplete', 'off'));
-
-  apply();
-
-  const observer = new MutationObserver(apply);
+  const setAutocompleteOff = (el: Element) => {
+    if (el.tagName === 'INPUT') {
+      el.setAttribute('autocomplete', 'off');
+    }
+    el.querySelectorAll?.('input').forEach((input) =>
+      input.setAttribute('autocomplete', 'off')
+    );
+  };
+
+  document.querySelectorAll('input').forEach(setAutocompleteOff);
+
+  const observer = new MutationObserver((mutations) => {
+    for (const mutation of mutations) {
+      mutation.addedNodes.forEach((node) => {
+        if (node instanceof Element) {
+          setAutocompleteOff(node);
+        }
+      });
+    }
+  });
   observer.observe(document.documentElement, {
     subtree: true,
     childList: true,
   });
 };
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@apps/extension/src/entrypoints/background/misc/turnOffInputSuggestions.ts`
around lines 2 - 13, Optimize the MutationObserver in apply by processing only
newly added input elements and inputs within added element subtrees, rather than
re-querying all document inputs on every childList mutation; preserve the
initial full-document processing and autocomplete behavior while avoiding
repeated updates to already processed inputs.
apps/web/src/app/persons-panel/hooks/usePreloadPerson.ts (1)

85-91: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick win

clearData has the same loading-state bug that preloadData just fixed.

If deleteCache throws, setIsLoading(false) never runs. Apply the same try/finally pattern.

♻️ Proposed fix
 const clearData = async () => {
   setIsLoading(true);
-  removeFromLocalStorage(STORAGE_KEYS.persons);
-  removeFromLocalStorage(STORAGE_KEYS.personImageUrls);
-  await deleteCache(ECacheBucketKeys.person);
-  setIsLoading(false);
+  try {
+    removeFromLocalStorage(STORAGE_KEYS.persons);
+    removeFromLocalStorage(STORAGE_KEYS.personImageUrls);
+    await deleteCache(ECacheBucketKeys.person);
+  } finally {
+    setIsLoading(false);
+  }
 };
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@apps/web/src/app/persons-panel/hooks/usePreloadPerson.ts` around lines 85 -
91, Update the clearData function to wrap the cleanup operations and await
deleteCache in a try/finally block, keeping setIsLoading(true) before the try
and moving setIsLoading(false) into finally so the loading state resets even
when deletion fails.
apps/web/src/app/bookmark-panel/hooks/usePreloadBookmarks.ts (1)

63-68: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick win

clearData has the same loading-state bug that preloadData just fixed.

If deleteCache throws, setIsLoading(false) never runs and the loading spinner stays forever. Apply the same try/finally pattern for consistency.

♻️ Proposed fix
 const clearData = async () => {
   setIsLoading(true);
-  removeFromLocalStorage(STORAGE_KEYS.bookmarks);
-  await deleteCache(ECacheBucketKeys.favicon);
-  setIsLoading(false);
+  try {
+    removeFromLocalStorage(STORAGE_KEYS.bookmarks);
+    await deleteCache(ECacheBucketKeys.favicon);
+  } finally {
+    setIsLoading(false);
+  }
 };
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@apps/web/src/app/bookmark-panel/hooks/usePreloadBookmarks.ts` around lines 63
- 68, Update the clearData function to wrap the storage removal and deleteCache
call in a try/finally block, ensuring setIsLoading(false) always executes even
when deleteCache throws; preserve the existing loading behavior and cleanup
operations.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@apps/extension/src/entrypoints/background/misc/turnOffInputSuggestions.ts`:
- Around line 2-13: Optimize the MutationObserver in apply by processing only
newly added input elements and inputs within added element subtrees, rather than
re-querying all document inputs on every childList mutation; preserve the
initial full-document processing and autocomplete behavior while avoiding
repeated updates to already processed inputs.

In `@apps/web/src/app/bookmark-panel/hooks/usePreloadBookmarks.ts`:
- Around line 63-68: Update the clearData function to wrap the storage removal
and deleteCache call in a try/finally block, ensuring setIsLoading(false) always
executes even when deleteCache throws; preserve the existing loading behavior
and cleanup operations.

In `@apps/web/src/app/persons-panel/hooks/usePreloadPerson.ts`:
- Around line 85-91: Update the clearData function to wrap the cleanup
operations and await deleteCache in a try/finally block, keeping
setIsLoading(true) before the try and moving setIsLoading(false) into finally so
the loading state resets even when deletion fails.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 8aecb9fd-3fa1-45ab-885c-3ee95b95a840

📥 Commits

Reviewing files that changed from the base of the PR and between d294908 and 77ea98c.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (9)
  • .github/workflows/release.yml
  • apps/extension/package.json
  • apps/extension/src/entrypoints/background/misc/turnOffInputSuggestions.ts
  • apps/extension/src/store/firebase/useFirebaseStore.ts
  • apps/web/package.json
  • apps/web/src/app/bookmark-panel/hooks/usePreloadBookmarks.ts
  • apps/web/src/app/persons-panel/hooks/usePreloadPerson.ts
  • apps/web/src/app/web-ext/page.tsx
  • package.json
💤 Files with no reviewable changes (1)
  • apps/extension/package.json
🚧 Files skipped from review as they are similar to previous changes (2)
  • .github/workflows/release.yml
  • apps/extension/src/store/firebase/useFirebaseStore.ts

firebase-admin 14 pulls in jwks-rsa@4 -> jose@6 (ESM-only). Next/Turbopack
externalizes firebase-admin in the serverless build and require()s it at
runtime; on Vercel's function runtime this throws ERR_REQUIRE_ESM, so every
/api/trpc call 500s and the web preload never completes (auth.setup e2e
timed out waiting for localStorage.bookmarks).

Verified on a Vercel preview: with firebase-admin 13.10.0 (jwks-rsa@3 ->
jose@4, CommonJS) the bookmarksGet/personsGet calls return 200 and
bookmarks are cached. Pinning the Vercel Node version (22/24) does NOT fix
it, so the engines.node pins added earlier are reverted.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@webext-bot

webext-bot Bot commented Jul 11, 2026

Copy link
Copy Markdown
Extension Size Change:   50.35 KB 🔺
Commit 3d3650f
Latest release size 216.10 KB
Current size 266.45 KB
Percent change 23.30 %

Significant size increase in this commit ⚠️

firebase-admin 14 -> jwks-rsa@4 require()s ESM-only jose@6, which crashes
with ERR_REQUIRE_ESM in the Next/Turbopack serverless runtime on Vercel.
Pin jose under jwks-rsa to the dual CJS/ESM 4.15.9 (jwks-rsa only uses
importJWK/exportSPKI, API-identical across jose 4/5/6) — the workaround
endorsed in firebase/firebase-admin-node#3181.

The override is declared in BOTH pnpm-workspace.yaml (read by local pnpm 11,
which bakes it into the lockfile) and package.json#pnpm.overrides (read by
Vercel's pnpm 9); both must match or the frozen install fails with
ERR_PNPM_LOCKFILE_CONFIG_MISMATCH. Remove both once auth0/node-jwks-rsa#508
ships.

Verified on a Vercel preview: bookmarksGet/personsGet/getDownloadUrl return
200 and bookmarks are cached.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@webext-bot

webext-bot Bot commented Jul 11, 2026

Copy link
Copy Markdown
Extension Size Change:   50.35 KB 🔺
Commit 21cd87f
Latest release size 216.10 KB
Current size 266.45 KB
Percent change 23.30 %

Significant size increase in this commit ⚠️

Vercel was building with pnpm 9 (guessed from lockfile/project age) because
it auto-disabled Corepack for Turborepo, despite ENABLE_EXPERIMENTAL_COREPACK=1
and packageManager: pnpm@11.10.0. Pass COREPACK_HOME through turbo so Vercel
honors Corepack and uses the packageManager-pinned pnpm 11, matching local.

Verified on a preview: build log downloads pnpm@11.10.0 (no "Disabling
corepack"), install + build succeed, and /api/trpc returns 200.

With local and Vercel both on pnpm 11, the jwks-rsa>jose override no longer
needs duplicating in package.json#pnpm.overrides (pnpm 11 reads overrides
from pnpm-workspace.yaml); removed it, keeping the single source in
pnpm-workspace.yaml. Also pass ENABLE_EXPERIMENTAL_COREPACK through turbo to
silence its platform-env warning.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@webext-bot

webext-bot Bot commented Jul 11, 2026

Copy link
Copy Markdown
Extension Size Change:   50.35 KB 🔺
Commit 1b49f12
Latest release size 216.10 KB
Current size 266.45 KB
Percent change 23.30 %

Significant size increase in this commit ⚠️

Re-apply the manual forwardRef/viewportRef customization on ScrollArea
that the shadcn update reverted, and fix a spinner strokeWidth type
error by moving it after the props spread.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@webext-bot

webext-bot Bot commented Jul 11, 2026

Copy link
Copy Markdown
Extension Size Change:   50.44 KB 🔺
Commit fcc2ae7
Latest release size 216.10 KB
Current size 266.54 KB
Percent change 23.34 %

Significant size increase in this commit ⚠️

@amitsingh-007
amitsingh-007 merged commit b068dfd into main Jul 11, 2026
7 checks passed
@coderabbitai coderabbitai Bot mentioned this pull request Jul 11, 2026
1 task done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant