chore(deps): consolidate the nine open Dependabot bumps - #262
Merged
Conversation
All nine open Dependabot PRs were green and mergeable, but eight of them edit app/package-lock.json, so merging any one would leave the other seven conflicting. Applying them together avoids that. npm (supersedes #250 #251 #252 #253 #255 #258 #259 #260): axios 1.16.0 -> 1.19.0 (direct) postcss 8.5.13 -> 8.5.25 (direct, dev) webpack-dev-server 5.2.5 -> 5.2.6 (direct, dev) websocket-driver 0.7.4 -> 0.7.5 (transitive) svgo 4.0.1 -> 4.0.2 (transitive) immutable 5.1.5 -> 5.1.9 (transitive) fast-uri 3.1.2 -> 3.1.5 (transitive) shell-quote 1.8.4 -> 1.10.0 (transitive) uv (supersedes #254): setuptools 82.0.1 -> 83.0.0 Some land above the version Dependabot asked for because the caret ranges resolve to the current latest. The packaged bundle is rebuilt and committed. It has to be: the publish workflow ships the committed src/experimaestro/webui/data (no Node in CI), so a lockfile bump alone would leave users on the old code. CI does not cover this either -- pytest.yml creates an empty webui data directory -- so `npm run build` was run locally and the Python suite re-run against the new uv.lock (1133 passed, 10 skipped, 1 xfailed). The rebuild changes exactly one byte sequence: index.css now starts with a UTF-8 BOM. No CSS source carries one, so it comes from the toolchain bump. The CSS spec requires parsers to strip a leading BOM and browsers do, so this is inert, but it is a behaviour change rather than a content change and is called out here rather than buried in a generated diff. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LU56vLBFQz5ryt2Sovf9Hj
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Applies all nine open Dependabot bumps on one branch. They were each green and mergeable, but eight of them edit
app/package-lock.json, so merging any one would leave the other seven conflicting.Closing this branch's PRs is not needed — Dependabot closes its own once the versions land.
Versions
npm — supersedes #250 #251 #252 #253 #255 #258 #259 #260
uv — supersedes #254:
setuptools82.0.1 → 83.0.0Some land above what Dependabot asked for, because the caret ranges resolve to the current latest.
The bundle is rebuilt, deliberately
src/experimaestro/webui/data/is committed and is what ships — the publish workflow builds the wheel from it with no Node involved. A lockfile bump alone would leave users running the old code, so the bump would be inert.CI does not cover this:
pytest.ymlcreates an emptysrc/experimaestro/webui/data, so the green checks on the nine PRs say nothing about whether the frontend still builds.npm run buildwas run locally (succeeds; only the pre-existing bundle-size warnings) and the Python suite re-run against the newuv.lock: 1133 passed, 10 skipped, 1 xfailed.Two things worth a look
index.cssnow starts with a UTF-8 BOM. That is the entire rebuild diff. No CSS source carries a BOM, so the toolchain bump introduces it. The CSS spec requires parsers to strip a leading BOM and browsers do, so it is inert — but it is a behaviour change rather than a content change, so it should not be buried in a generated diff. I did not try to suppress it.axiosis an unused dependency.index.jsis byte-identical after bumping it 1.16 → 1.19, because axios is not imported anywhere inapp/src— the only mentions arepackage.jsonand boilerplate Create React App text inapp/README.md. So #251 was always inert. Dropping it is a separate change and is not in this PR.🤖 Generated with Claude Code