Repository navigation
Renovate updates - #4062
Renovate updates#4062
Conversation
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…xt-release-tag-6.x Update amitsingh-007/next-release-tag action to v6.5.0
Extension Size Change: 50.24 KB 🔺
Significant size increase in this commit
|
|
Extension version is updated from |
There was a problem hiding this comment.
Hey - I've left some high level feedback:
Fixed security issues:
-
In
ImagePicker.tsx, the ref type forimageCropperRefis nowuseRef<AvatarEditorRef>(null), butAvatarEditorReflikely doesn’t includenull; consider typing this asAvatarEditorRef | nullto avoid type mismatches withuseRef’s initial value. -
The new early returns in
useFirebaseStorewhensignInWithCredentialorrefreshIdTokenreturn falsy values silently abort the operation; consider surfacing an explicit error state or logging so callers can distinguish between a missing token and a transient failure.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments
- In `ImagePicker.tsx`, the ref type for `imageCropperRef` is now `useRef<AvatarEditorRef>(null)`, but `AvatarEditorRef` likely doesn’t include `null`; consider typing this as `AvatarEditorRef | null` to avoid type mismatches with `useRef`’s initial value.
- The new early returns in `useFirebaseStore` when `signInWithCredential` or `refreshIdToken` return falsy values silently abort the operation; consider surfacing an explicit error state or logging so callers can distinguish between a missing token and a transient failure.Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
Extension Size Change: 50.25 KB 🔺
Significant size increase in this commit
|
PR Summary by QodoUpgrade pnpm to v11 and refresh monorepo deps/CI; migrate extension build to React
AI Description
Diagram
High-Level Assessment
Files changed (20)
|
Code Review by Qodo
1. Native builds disabled
|
📝 WalkthroughWalkthroughThe pull request updates workspace dependencies, pnpm and Turbo configuration, TypeScript settings, and the extension’s migration from Preact to React. It adds runtime guards for Firebase operations, observes DOM mutations when disabling autocomplete, and improves preload cleanup in the web app. Vercel schema metadata is added. GitHub Actions and Renovate configurations are updated with newer action versions and repository settings. Possibly related issues
Possibly related PRs
🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (1 warning, 1 inconclusive)
✅ Passed checks (3 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🧹 Nitpick comments (1)
.github/workflows/release.yml (1)
178-179: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick winDisable checkout credential persistence in
Create_Release.This job does not run git commands after checkout and passes
GITHUB_TOKENdirectly to the release action. Avoid leaving checkout credentials available to later artifact-processing steps.Proposed fix
- name: Checkout repository uses: actions/checkout@v7 + with: + persist-credentials: false🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/release.yml around lines 178 - 179, Update the checkout step in the Create_Release job to disable credential persistence by configuring actions/checkout with persist-credentials: false, while preserving the existing repository checkout behavior.Source: Linters/SAST tools
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/extension/tsconfig.json`:
- Around line 5-6: Restore "dom.iterable" in the lib array of the extension
tsconfig, or refactor forumPageLinks.ts to avoid spreading querySelectorAll()
results; preserve type-checking for iterable DOM collections while retaining the
existing node, chrome, esnext, and dom libraries.
In `@apps/extension/wxt.config.ts`:
- Around line 31-36: Replace the undocumented resolve.tsconfigPaths
configuration in the WXT defineConfig setup with WXT’s top-level alias option,
mapping each project path alias to its corresponding directory. Remove the
resolve.tsconfigPaths block and preserve the existing plugins and build
settings.
---
Nitpick comments:
In @.github/workflows/release.yml:
- Around line 178-179: Update the checkout step in the Create_Release job to
disable credential persistence by configuring actions/checkout with
persist-credentials: false, while preserving the existing repository checkout
behavior.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: c3161fcc-fafe-4580-a7e8-21a393223ab1
⛔ Files ignored due to path filters (1)
pnpm-lock.yamlis excluded by!**/pnpm-lock.yaml
📒 Files selected for processing (20)
.github/renovate-config.json.github/workflows/build.yml.github/workflows/downmerge.yml.github/workflows/playwright.yml.github/workflows/release.yml.github/workflows/renovate.ymlAGENTS.mdapps/extension/package.jsonapps/extension/src/entrypoints/popup/panels/PersonsPanel/components/AddOrEditPersonDialog.tsxapps/extension/src/entrypoints/popup/panels/PersonsPanel/components/ImagePicker.tsxapps/extension/src/store/firebase/useFirebaseStore.tsapps/extension/tsconfig.jsonapps/extension/wxt.config.tsapps/web/tsconfig.jsonpackage.jsonpackages/configs/tsconfig.base.jsonpackages/shared/package.jsonpackages/ui/package.jsonpackages/ui/tsconfig.jsonpnpm-workspace.yaml
💤 Files with no reviewable changes (3)
- packages/ui/package.json
- packages/shared/package.json
- packages/ui/tsconfig.json
…nputs Wikipedia and other sites add input elements dynamically after page load. The previous one-shot script injection missed these inputs, causing flaky E2E test failures. A MutationObserver ensures all dynamically-added inputs also get autocomplete=off.
Extension Size Change: 50.35 KB 🔺
Significant size increase in this commit
|
Extension Size Change: 50.35 KB 🔺
Significant size increase in this commit
|
firebase-admin 14 requires Node >=22 at runtime; pin engines.node so the Vercel deployment runs a compatible Node version (fixes web-auth-setup e2e where token verification failed on the old runtime, leaving the Logout button permanently disabled). Also wrap the bookmarks/persons preload in try/finally (and catch the preload effect) so a failed request resets isLoading instead of pinning the account UI in a disabled state. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Extension Size Change: 50.35 KB 🔺
Significant size increase in this commit
|
There was a problem hiding this comment.
🧹 Nitpick comments (3)
apps/extension/src/entrypoints/background/misc/turnOffInputSuggestions.ts (1)
2-13: 🚀 Performance & Scalability | 🔵 Trivial | ⚡ Quick winConsider filtering mutations to avoid re-processing all inputs on every DOM change.
The
MutationObserverfires on everychildListchange across the entire document subtree. Each callback re-queries and re-setsautocomplete="off"on all inputs, even ones already processed. On dynamic pages (modals, tooltips, virtual scrolling), this can fire frequently and cause unnecessary work.An alternative is to inspect
mutation.addedNodesand only process newly inserted inputs:♻️ Optional optimization
const turnOffAutocomplete = () => { - const apply = () => - document - .querySelectorAll('input') - .forEach((ele) => ele.setAttribute('autocomplete', 'off')); - - apply(); - - const observer = new MutationObserver(apply); + const setAutocompleteOff = (el: Element) => { + if (el.tagName === 'INPUT') { + el.setAttribute('autocomplete', 'off'); + } + el.querySelectorAll?.('input').forEach((input) => + input.setAttribute('autocomplete', 'off') + ); + }; + + document.querySelectorAll('input').forEach(setAutocompleteOff); + + const observer = new MutationObserver((mutations) => { + for (const mutation of mutations) { + mutation.addedNodes.forEach((node) => { + if (node instanceof Element) { + setAutocompleteOff(node); + } + }); + } + }); observer.observe(document.documentElement, { subtree: true, childList: true, }); };🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@apps/extension/src/entrypoints/background/misc/turnOffInputSuggestions.ts` around lines 2 - 13, Optimize the MutationObserver in apply by processing only newly added input elements and inputs within added element subtrees, rather than re-querying all document inputs on every childList mutation; preserve the initial full-document processing and autocomplete behavior while avoiding repeated updates to already processed inputs.apps/web/src/app/persons-panel/hooks/usePreloadPerson.ts (1)
85-91: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick win
clearDatahas the same loading-state bug thatpreloadDatajust fixed.If
deleteCachethrows,setIsLoading(false)never runs. Apply the sametry/finallypattern.♻️ Proposed fix
const clearData = async () => { setIsLoading(true); - removeFromLocalStorage(STORAGE_KEYS.persons); - removeFromLocalStorage(STORAGE_KEYS.personImageUrls); - await deleteCache(ECacheBucketKeys.person); - setIsLoading(false); + try { + removeFromLocalStorage(STORAGE_KEYS.persons); + removeFromLocalStorage(STORAGE_KEYS.personImageUrls); + await deleteCache(ECacheBucketKeys.person); + } finally { + setIsLoading(false); + } };🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@apps/web/src/app/persons-panel/hooks/usePreloadPerson.ts` around lines 85 - 91, Update the clearData function to wrap the cleanup operations and await deleteCache in a try/finally block, keeping setIsLoading(true) before the try and moving setIsLoading(false) into finally so the loading state resets even when deletion fails.apps/web/src/app/bookmark-panel/hooks/usePreloadBookmarks.ts (1)
63-68: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick win
clearDatahas the same loading-state bug thatpreloadDatajust fixed.If
deleteCachethrows,setIsLoading(false)never runs and the loading spinner stays forever. Apply the sametry/finallypattern for consistency.♻️ Proposed fix
const clearData = async () => { setIsLoading(true); - removeFromLocalStorage(STORAGE_KEYS.bookmarks); - await deleteCache(ECacheBucketKeys.favicon); - setIsLoading(false); + try { + removeFromLocalStorage(STORAGE_KEYS.bookmarks); + await deleteCache(ECacheBucketKeys.favicon); + } finally { + setIsLoading(false); + } };🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@apps/web/src/app/bookmark-panel/hooks/usePreloadBookmarks.ts` around lines 63 - 68, Update the clearData function to wrap the storage removal and deleteCache call in a try/finally block, ensuring setIsLoading(false) always executes even when deleteCache throws; preserve the existing loading behavior and cleanup operations.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@apps/extension/src/entrypoints/background/misc/turnOffInputSuggestions.ts`:
- Around line 2-13: Optimize the MutationObserver in apply by processing only
newly added input elements and inputs within added element subtrees, rather than
re-querying all document inputs on every childList mutation; preserve the
initial full-document processing and autocomplete behavior while avoiding
repeated updates to already processed inputs.
In `@apps/web/src/app/bookmark-panel/hooks/usePreloadBookmarks.ts`:
- Around line 63-68: Update the clearData function to wrap the storage removal
and deleteCache call in a try/finally block, ensuring setIsLoading(false) always
executes even when deleteCache throws; preserve the existing loading behavior
and cleanup operations.
In `@apps/web/src/app/persons-panel/hooks/usePreloadPerson.ts`:
- Around line 85-91: Update the clearData function to wrap the cleanup
operations and await deleteCache in a try/finally block, keeping
setIsLoading(true) before the try and moving setIsLoading(false) into finally so
the loading state resets even when deletion fails.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 8aecb9fd-3fa1-45ab-885c-3ee95b95a840
⛔ Files ignored due to path filters (1)
pnpm-lock.yamlis excluded by!**/pnpm-lock.yaml
📒 Files selected for processing (9)
.github/workflows/release.ymlapps/extension/package.jsonapps/extension/src/entrypoints/background/misc/turnOffInputSuggestions.tsapps/extension/src/store/firebase/useFirebaseStore.tsapps/web/package.jsonapps/web/src/app/bookmark-panel/hooks/usePreloadBookmarks.tsapps/web/src/app/persons-panel/hooks/usePreloadPerson.tsapps/web/src/app/web-ext/page.tsxpackage.json
💤 Files with no reviewable changes (1)
- apps/extension/package.json
🚧 Files skipped from review as they are similar to previous changes (2)
- .github/workflows/release.yml
- apps/extension/src/store/firebase/useFirebaseStore.ts
firebase-admin 14 pulls in jwks-rsa@4 -> jose@6 (ESM-only). Next/Turbopack externalizes firebase-admin in the serverless build and require()s it at runtime; on Vercel's function runtime this throws ERR_REQUIRE_ESM, so every /api/trpc call 500s and the web preload never completes (auth.setup e2e timed out waiting for localStorage.bookmarks). Verified on a Vercel preview: with firebase-admin 13.10.0 (jwks-rsa@3 -> jose@4, CommonJS) the bookmarksGet/personsGet calls return 200 and bookmarks are cached. Pinning the Vercel Node version (22/24) does NOT fix it, so the engines.node pins added earlier are reverted. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Extension Size Change: 50.35 KB 🔺
Significant size increase in this commit
|
firebase-admin 14 -> jwks-rsa@4 require()s ESM-only jose@6, which crashes with ERR_REQUIRE_ESM in the Next/Turbopack serverless runtime on Vercel. Pin jose under jwks-rsa to the dual CJS/ESM 4.15.9 (jwks-rsa only uses importJWK/exportSPKI, API-identical across jose 4/5/6) — the workaround endorsed in firebase/firebase-admin-node#3181. The override is declared in BOTH pnpm-workspace.yaml (read by local pnpm 11, which bakes it into the lockfile) and package.json#pnpm.overrides (read by Vercel's pnpm 9); both must match or the frozen install fails with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH. Remove both once auth0/node-jwks-rsa#508 ships. Verified on a Vercel preview: bookmarksGet/personsGet/getDownloadUrl return 200 and bookmarks are cached. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Extension Size Change: 50.35 KB 🔺
Significant size increase in this commit
|
Vercel was building with pnpm 9 (guessed from lockfile/project age) because it auto-disabled Corepack for Turborepo, despite ENABLE_EXPERIMENTAL_COREPACK=1 and packageManager: pnpm@11.10.0. Pass COREPACK_HOME through turbo so Vercel honors Corepack and uses the packageManager-pinned pnpm 11, matching local. Verified on a preview: build log downloads pnpm@11.10.0 (no "Disabling corepack"), install + build succeed, and /api/trpc returns 200. With local and Vercel both on pnpm 11, the jwks-rsa>jose override no longer needs duplicating in package.json#pnpm.overrides (pnpm 11 reads overrides from pnpm-workspace.yaml); removed it, keeping the single source in pnpm-workspace.yaml. Also pass ENABLE_EXPERIMENTAL_COREPACK through turbo to silence its platform-env warning. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Extension Size Change: 50.35 KB 🔺
Significant size increase in this commit
|
Re-apply the manual forwardRef/viewportRef customization on ScrollArea that the shadcn update reverted, and fix a spinner strokeWidth type error by moving it after the props spread. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Extension Size Change: 50.44 KB 🔺
Significant size increase in this commit
|
Check if the Pull Request fulfils these requirements
Summary by Sourcery
Update dependencies and tooling across the monorepo, including the browser extension, and align configs with the new stack.
New Features:
Bug Fixes:
Enhancements:
Build:
CI:
Deployment:
Documentation:
Tests:
Chores:
Greptile Summary
This PR upgrades the monorepo's dependency catalog across the board (React 19.2.6, Next.js 16.2.10, TypeScript 6.0.3, Vite 8.1.3, Firebase 12.15.0, Tailwind 4.3.2, and many others) while migrating the browser extension from Preact to React and fixing several correctness issues.
@preact/preset-vite+vite-tsconfig-pathswith@vitejs/plugin-reactand Vite 8's nativeresolve.tsconfigPaths: true; removeswouter-preactalias and dependency.signInWithCredentialandrefreshIdTokenresponses; wraps preload operations intry/finallysosetIsLoading(false)always executes; movessetShouldPreloadData(false)into.finally()to prevent stuck state on errors.useStore(@tanstack/react-form) touseSelector(@tanstack/react-store) for form store subscriptions; updatesAvatarEditorref type to the newerAvatarEditorReffrom react-avatar-editor 15.x; adjusts"use client"directives in shared UI components to reflect actual client-boundary requirements.Confidence Score: 5/5
Safe to merge — the changes are well-scoped dependency upgrades paired with targeted correctness improvements and no regressions were identified.
All logic changes are improvements: null guards prevent silent invalid state, try/finally ensures loading flags are always cleared, and the Preact-to-React migration is internally consistent. The resolve.tsconfigPaths: true option is confirmed as a native Vite 8 feature.
No files require special attention.
Reviews (7): Last reviewed commit: "Update shadcn ui components; preserve sc..." | Re-trigger Greptile