deps: bump the routine group across 1 directory with 2 updates - #92
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the routine group with 2 updates in the /frontend directory: [jsdom](https://github.com/jsdom/jsdom) and [svelte](https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte). Updates `jsdom` from 30.0.1 to 30.1.1 - [Release notes](https://github.com/jsdom/jsdom/releases) - [Commits](jsdom/jsdom@v30.0.1...v30.1.1) Updates `svelte` from 5.57.0 to 5.57.1 - [Release notes](https://github.com/sveltejs/svelte/releases) - [Changelog](https://github.com/sveltejs/svelte/blob/main/packages/svelte/CHANGELOG.md) - [Commits](https://github.com/sveltejs/svelte/commits/svelte@5.57.1/packages/svelte) --- updated-dependencies: - dependency-name: jsdom dependency-version: 30.1.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: routine - dependency-name: svelte dependency-version: 5.57.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: routine ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
| "whatwg-url": "^17.1.1", | ||
| "xml-name-validator": "^5.0.0" | ||
| }, | ||
| "engines": { |
There was a problem hiding this comment.
🔍 Verify the test image’s Node version
jsdom and two updated dependencies now require Node 22.22.2, 24.15.0, or later compatible releases. The Playwright-based test image does not pin a Node patch version; verify its runtime before relying on CI installs.
(Refers to this code)
Was this helpful? React with 👍 or 👎 to provide feedback.
CherylSnowVeil
left a comment
There was a problem hiding this comment.
Review — routine group bump (jsdom 30.0.1 → 30.1.1, svelte 5.57.0 → 5.57.1)
Reviewed the current head 67e6fcd. Diff is limited to frontend/package.json and frontend/package-lock.json (Dependabot-generated). No actionable findings.
What I verified:
- Lockfile integrity: lockfileVersion 3; root
devDependenciesmatchpackage.jsonexactly; everydependencies/optionalDependenciesreference resolves to a present package; all entries carryresolved+integrity.symbol-treewas fully removed — consistent with jsdom 30.1.x dropping the dependency — and nothing still references it. - vite-toolchain compatibility (per repo guidance, these must move atomically):
vite8.3.0,@sveltejs/vite-plugin-svelte7.3.0,vitest5.0.0,svelte-check4.7.6,typescript6.0.3 are all untouched by this PR, and peer ranges remain satisfied (vite-plugin-sveltewantssvelte ^5.46.4+vite ^8;vitestwantsvite ^6.4||^7||^8,jsdom *;svelte-checkwantstypescript ^5||^6). svelte 5.57.1 satisfies all of them. - Node engine floor: the automated review's flag about
^22.22.2 || ^24.15.0 || >=26.0.0is accurate for the three transitive raises (@asamuzakjp/css-color,@asamuzakjp/dom-selector,w3c-xmlserializer) but is not a new requirement —jsdom30.0.1 already carried that exact floor in the base lockfile (merged in90b8be2, with greenmake teston several PRs since). The effective Node requirement is unchanged. Themcr.microsoft.com/playwright:v1.63.0-nobleimage installs Node 24.x from nodesource at build time. - Blast radius:
jsdomis only the Vitestenvironment(frontend/vite.config.ts) — test-only, no impact on shipped assets.svelte5.57.1 is a patch release.
Two non-blocking notes:
- 🟢 [nit] The
testcheck was still pending at review time — all other checks (snyk, dependency-review, zizmor) are green; merge should wait formake testas usual. - 🟢 [nit, pre-existing — not introduced by this PR] Dependabot's warning on this PR that the
npmlabel doesn't exist is real:.github/dependabot.yml:77setslabels: ["dependencies", "npm"]. Fix by creating the label or dropping it from the config.
Bumps the routine group with 2 updates in the /frontend directory: jsdom and svelte.
Updates
jsdomfrom 30.0.1 to 30.1.1Release notes
Sourced from jsdom's releases.
... (truncated)
Commits
0a117f430.1.1103f67dRemove unnecessary window cleanup from API testscdda00aTest HTTP/2 document and subresource loading7ab92ceUpdate@asamuzakjp/dom-selectorto v9.2.1d940c20Share jsdom settings across descendant windows6ba40cbFix and simplify option propagation3b3be70Preserve CSS priorities across declaration updates97b2758Align focusing and unfocusing with HTMLb7b460bUpdate w3c-xmlserializer to v671d562fUpdate html-encoding-sniffer to v7Updates
sveltefrom 5.57.0 to 5.57.1Release notes
Sourced from svelte's releases.
Changelog
Sourced from svelte's changelog.
Commits
636eaaaVersion Packages (#18750)8030ff2fix: remove incorrect special handling of :export pseudo-selectors (#18839)a72dc8efix: make Object.hasOwn reactive for state proxies (#18838)6eb720achore: scope.js stops importing from the analysis visitors (#18787)e6ae460chore: analysis and transform stop importing each other (#18786)5981c06chore: move parser helpers next to their users (#18785)f2ad10efix: preserve global CSS without scopable elements (#18793)a8a9b02fix: reduce SSR render result garbage collection (#18798)6be176dfix: resolve the fallback of an each block in the enclosing scope (#18803)34b13acfix: keep$state.eagerwhen used as a variable initializer (#18809)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions