Skip to content

chore(deps): consolidate the nine open Dependabot bumps - #262

Merged
bpiwowar merged 1 commit into
masterfrom
chore/consolidate-dependency-bumps
Jul 31, 2026
Merged

chore(deps): consolidate the nine open Dependabot bumps#262
bpiwowar merged 1 commit into
masterfrom
chore/consolidate-dependency-bumps

Conversation

@bpiwowar

Copy link
Copy Markdown
Collaborator

Applies all nine open Dependabot bumps on one branch. They were each green and mergeable, but eight of them edit app/package-lock.json, so merging any one would leave the other seven conflicting.

Closing this branch's PRs is not needed — Dependabot closes its own once the versions land.

Versions

npm — supersedes #250 #251 #252 #253 #255 #258 #259 #260

package from to
axios 1.16.0 1.19.0 direct
postcss 8.5.13 8.5.25 direct, dev
webpack-dev-server 5.2.5 5.2.6 direct, dev
websocket-driver 0.7.4 0.7.5 transitive
svgo 4.0.1 4.0.2 transitive
immutable 5.1.5 5.1.9 transitive
fast-uri 3.1.2 3.1.5 transitive
shell-quote 1.8.4 1.10.0 transitive

uv — supersedes #254: setuptools 82.0.1 → 83.0.0

Some land above what Dependabot asked for, because the caret ranges resolve to the current latest.

The bundle is rebuilt, deliberately

src/experimaestro/webui/data/ is committed and is what ships — the publish workflow builds the wheel from it with no Node involved. A lockfile bump alone would leave users running the old code, so the bump would be inert.

CI does not cover this: pytest.yml creates an empty src/experimaestro/webui/data, so the green checks on the nine PRs say nothing about whether the frontend still builds. npm run build was run locally (succeeds; only the pre-existing bundle-size warnings) and the Python suite re-run against the new uv.lock: 1133 passed, 10 skipped, 1 xfailed.

Two things worth a look

index.css now starts with a UTF-8 BOM. That is the entire rebuild diff. No CSS source carries a BOM, so the toolchain bump introduces it. The CSS spec requires parsers to strip a leading BOM and browsers do, so it is inert — but it is a behaviour change rather than a content change, so it should not be buried in a generated diff. I did not try to suppress it.

axios is an unused dependency. index.js is byte-identical after bumping it 1.16 → 1.19, because axios is not imported anywhere in app/src — the only mentions are package.json and boilerplate Create React App text in app/README.md. So #251 was always inert. Dropping it is a separate change and is not in this PR.

🤖 Generated with Claude Code

All nine open Dependabot PRs were green and mergeable, but eight of them edit
app/package-lock.json, so merging any one would leave the other seven
conflicting. Applying them together avoids that.

npm (supersedes #250 #251 #252 #253 #255 #258 #259 #260):
  axios              1.16.0 -> 1.19.0   (direct)
  postcss            8.5.13 -> 8.5.25   (direct, dev)
  webpack-dev-server  5.2.5 -> 5.2.6    (direct, dev)
  websocket-driver    0.7.4 -> 0.7.5    (transitive)
  svgo                4.0.1 -> 4.0.2    (transitive)
  immutable           5.1.5 -> 5.1.9    (transitive)
  fast-uri            3.1.2 -> 3.1.5    (transitive)
  shell-quote         1.8.4 -> 1.10.0   (transitive)

uv (supersedes #254):
  setuptools         82.0.1 -> 83.0.0

Some land above the version Dependabot asked for because the caret ranges
resolve to the current latest.

The packaged bundle is rebuilt and committed. It has to be: the publish
workflow ships the committed src/experimaestro/webui/data (no Node in CI), so a
lockfile bump alone would leave users on the old code. CI does not cover this
either -- pytest.yml creates an empty webui data directory -- so `npm run build`
was run locally and the Python suite re-run against the new uv.lock
(1133 passed, 10 skipped, 1 xfailed).

The rebuild changes exactly one byte sequence: index.css now starts with a
UTF-8 BOM. No CSS source carries one, so it comes from the toolchain bump. The
CSS spec requires parsers to strip a leading BOM and browsers do, so this is
inert, but it is a behaviour change rather than a content change and is called
out here rather than buried in a generated diff.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LU56vLBFQz5ryt2Sovf9Hj
@bpiwowar
bpiwowar merged commit f435a14 into master Jul 31, 2026
5 checks passed
@bpiwowar
bpiwowar deleted the chore/consolidate-dependency-bumps branch July 31, 2026 12:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant