Skip to content

chore(deps): bump react-i18next from 15.4.1 to 17.0.15 - #1351

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/react-i18next-17.0.15
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/react-i18next-17.0.15

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps react-i18next from 15.4.1 to 17.0.15.

Changelog

Sourced from react-i18next's changelog.

17.0.15

  • fix(Trans): empty paired component tags now preserve a component's single valid React-element child, whether supplied through a named component map (<wrap></wrap>), a component array (<0></0>), or indexed JSX children (<1></1>). This matches the existing behavior for two or more children and self-closing tags. React represents one JSX child as an element and multiple children as an array; the previous array-only check silently rendered the one-child case empty. Compatibility note: when that sole element contains an interpolation object, the restored raw children can expose an existing React rendering limitation as an error instead of silently rendering empty; the same shape already errors with two children. Fixes #1932.

17.0.14

  • fix: the i18n object returned by useTranslation was only refreshed when i18n.language changed, so a resolvedLanguage (or languages) change of its own kept handing components the previous snapshot. That happens whenever the translations for the current language arrive after the switch — i18next resolves to the fallback until its store has them — and components reading i18n.resolvedLanguage (language switchers, for example) then stayed one switch behind. The cached wrapper is now keyed on all three language fields, which are exactly the ones the surrounding useMemo already depends on; wrapper identity still only changes when the language state does, so the caching from #1885 is unaffected. Reported via next-i18next#2348.

17.0.13

  • fix(types): the selector-form keyPrefix overload of useTranslation() is now available under enableSelector: 'strict'. useTranslation was gated on true | 'optimize' only, so under 'strict' it resolved to the legacy signature and the selector overload disappeared entirely (keyPrefix: ($) => $.ns.foo failed with Type '($: any) => any' is not assignable to type 'undefined'). Trans already handled all three modes. Companion to the same fix for getFixedT in i18next#2446. Thanks @​hovelopin (#1930).

17.0.12

  • fix(IcuTrans): key-less icu.macro nodes (<Trans>Welcome, {name}!</Trans>, <Select>, <Plural> without i18nKey) rendered an empty string since 17.0.0. The macro now emits <IcuTrans defaultTranslation="…"> without a key and IcuTrans passed undefined to t(), which returns ''. Like Trans, IcuTrans now uses defaultTranslation as the key when i18nKey is not provided.

17.0.11

  • chore: html-parse-stringify updated to ^4.0.1. The parser powering <Trans> is now actively maintained under the i18next org (i18next/html-parse-stringify) after years without upstream releases. 4.x brings modern dual ESM/CJS packaging with an exports map, zero runtime dependencies, reworked TypeScript types and a long list of parser fixes (literal < in text, multiline/CRLF attribute values, comments containing >, doctype handling, quote-aware bracket handling).
  • refactor(Trans): the internal escapeLiteralLessThan scanner (~80 lines) is replaced by the parser's new allowedTags option with identical semantics: only numbered tags, kept basic HTML tags and known component names are parsed as markup, any other tag-shaped sequence in the translation stays literal text. Rendered output is unchanged (all 493 tests pass, including the #1880 and #1893 escaping cases).

17.0.10

  • fix(warnings): the useTranslation and Trans "You will need to pass in an i18next instance" warnings now match the useSSR wording, mentioning the props/context alternatives and the most common unexplained cause at scale: duplicate react-i18next copies in monorepo setups. The Trans variant also referenced the internal i18nextReactModule name; it now points to the public initReactI18next API.
  • feat(warnings): development-only warning (SUSPENDED_WHILE_LOADING, logged once) right before useTranslation suspends while translations are loading. With the default useSuspense: true and no <Suspense> boundary this previously surfaced as a blank screen or a cryptic React error; the warning now names both fixes (add a <Suspense> boundary or set react.useSuspense: false). No-op in production builds; the process.env.NODE_ENV check is wrapped so runtimes without a process global (raw ESM in the browser, some edge runtimes) stay silent instead of throwing.
  • ci: weekly workflow typechecking the test suite against @types/react@next / @types/react-dom@next, so the next React major's type changes (like the React 18 TFunctionResult/children wave) surface before user reports.

17.0.9

  • fix: allow TypeScript 7 in the optional typescript peer dependency range (^5 || ^6 || ^7). With typescript@7.0.2 in a project, npm install failed with an ERESOLVE peer conflict. Fixes #1927, thanks @​andikapradanaarif.
  • fix(types): <Trans t={t} ns="ns" …> with a t from useTranslation(['ns']) now typechecks under TypeScript 7. TS7 intersects the Ns inference candidates coming from the t prop (readonly ['ns']) and the ns prop ('ns') into an unsatisfiable 'ns' & readonly ['ns'], where TS6 resolved them. The ns prop on TransProps, TransSelectorProps and IcuTransWithoutContextProps now also accepts a single namespace out of an array-typed Ns (Ns | (Ns extends readonly (infer S extends string)[] ? S : never)) — which matches runtime behavior and is unchanged under TS5/TS6.

17.0.8

  • fix(types): <Trans i18nKey={$ => ...}> now typechecks under enableSelector: 'strict'. The Trans component's conditional type was gated on _EnableSelector extends true | 'optimize', excluding 'strict' and falling back to the legacy string-key signature. Runtime was already correct (it calls keyFromSelector(i18nKey) whenever typeof i18nKey === 'function'); this is a type-only fix that widens the conditional to include 'strict'. Thanks @​Faithfinder (#1921)

17.0.7

  • feat: useTranslation([nsA, nsB, ...]) now passes its full namespace list to getFixedT via the new scopeNs opt (requires i18next ≥ v26.0.10). This makes selector calls with a secondary-namespace prefix resolve correctly under default nsMode: t($ => $.nsB.foo) previously missed silently because the bound ns was the primary string only and i18next's selector rewrite needed an array. Resolution semantics are unchanged — plain t('key') lookups still stay isolated to the primary namespace by default; use nsMode: 'fallback' to opt into multi-ns fallback resolution as before. Fixes i18next#2429 for useTranslation-based callers.

17.0.6

  • fix: restore the v17 nodesToString output format consumed by i18next-cli's extractor while still rendering 1919 correctly
    • 17.0.5 fixed 1919 by changing what nodesToString produced, which inadvertently changed the extracted translation strings for keep-tags wrapping non-keep React elements
    • The fix now lives in the renderer: indexed <N> placeholders nested inside a keep-tag are scoped to that tag's own original React children (matching kept tags by name and positional occurrence at each level), so the translation string format produced by nodesToString is unchanged

17.0.5

  • fix: <Trans /> no longer breaks child rendering when a kept HTML node (transKeepBasicHtmlNodesFor) wraps a non-keep React element 1919 — superseded by 17.0.6, which keeps the same runtime fix without changing the nodesToString output

... (truncated)

Commits
  • 7d38e09 17.0.15
  • 875b327 fix(Trans): preserve single-element children in empty slots
  • 5f8c5f9 17.0.14
  • 6def81a fix: refresh the returned i18n wrapper when resolvedLanguage changes
  • f37ea87 docs: "For AI assistants" paragraph in the README
  • e0592ba chore: keep dev-only and local files out of the npm package
  • addf646 17.0.13
  • 7c634ee changelog v17.0.13
  • 5ceefb0 fix(types): allow selector keyPrefix in useTranslation under enableSelector '...
  • aa7ba52 chore(examples): require activesupport >= 7.2.3.1 in the RN Gemfiles
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 1, 2026

@ripple-code-reviewer ripple-code-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Routine Dependabot bump of react-i18next 15.4.1 → 17.0.15 (a two-major-version jump) with corresponding package.json edit. The lockfile diff is consistent and transitive deps (@babel/runtime, html-parse-stringify, use-sync-external-store) update sensibly. One point worth verifying before merge: the new react-i18next peerDependencies entry now requires i18next >= 26.2.0 (up from >= 23.2.3), but neither the lockfile nor package.json diff shows the project's i18next version being bumped alongside it.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/react-i18next-17.0.15 branch from 8946cc6 to e4512f0 Compare October 7, 2026 21:12

@ripple-code-reviewer ripple-code-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verify i18next peer dependency compatibility - see inline.

Comment thread package.json
"react-error-boundary": "^4.0.13",
"react-helmet-async": "^2.0.4",
"react-i18next": "15.4.1",
"react-i18next": "17.0.15",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Peer dependency: react-i18next 17.0.15 requires i18next >= 26.2.0. Verify i18next version in package.json.

@pdp2121 pdp2121 mentioned this pull request Oct 8, 2026
1 of 10 tasks
pdp2121 added a commit that referenced this pull request Oct 8, 2026
## High Level Overview of Change

Quarterly batch dependency upgrade (2026-Q4). This PR consolidates the
open Dependabot dependency PRs **and** applies any further upgrades
needed to resolve the open Semgrep (DGE) supply-chain tickets that a
package upgrade can fix.

- **21** Dependabot PRs applied (Upgraded); **9** skipped
(peer-dependency or Node-engine conflicts — see the table).
- **0** Semgrep tickets needed an upgrade: the 4 new **Critical** axios
tickets (DGE-8416–8419, `axios ≥ 1.20.0`) are already satisfied on
`main` by the Q3 batch (No-op), and none are left open.
- Twelve of the applied PRs are major bumps, eight of them production
dependencies: `express` 5, `dotenv` 18,
`i18next-browser-languagedetector` 8, `i18next-http-backend` 4,
`react-helmet-async` 3, `react-error-boundary` 6, `vite-plugin-svgr` 5,
`tldts` 7.

> **Express 4 → 5 needed a server fix that CI does not catch — please
review it specifically.** Under Express 5 the production server crashed
on startup (`PathError: Missing parameter name at index 1: *`), because
`path-to-regexp` 8 no longer accepts a bare `*` route. No Jest test
loads `server/`, so `lint:ci`, `build`, `build-ts` and `test:ci` all
passed regardless. Two lines in `server/index.js` were changed to the
Express 5 syntax, and the server was started and probed in both
production and development modes (see Test Plan).

### Context of Change

Quarterly batch of the Dependabot PRs opened on 2026-10-01, plus the
Semgrep tickets a package upgrade can fix. Direct dependency versions
were bumped in `package.json`; `package-lock.json` was updated in place
(never regenerated from scratch). No `overrides` or `resolutions` were
added and no parent range was widened.

### Type of Change

- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [x] Breaking change (fix or feature that would cause existing
functionality to not work as expected)
- [ ] Refactor (non-breaking change that only restructures code)
- [ ] Tests (You added tests for code that already exists, or your new
feature included in this PR)
- [ ] Documentation Updates
- [ ] Translation Updates
- [ ] Release

"Breaking change" is checked because production dependencies cross major
versions (most notably `express` 5). User-facing behavior is unchanged.

### Codebase Modernization

N/A — no file conversions.

- [ ] Updated files to React Hooks
- [ ] Updated files to TypeScript

## Before / After

**`server/index.js`** — Express 5 route syntax (details in
`code-changes.md`):

```js
// before (Express 4)
app.get('*', (_req, res) => { res.sendFile(path.join(__dirname, '/../build/index.html')) })
app.use('*', (req, res) => { /* 404 */ })

// after (Express 5)
app.get('/{*splat}', (_req, res) => { res.sendFile(path.join(__dirname, '/../build/index.html')) })
app.use((req, res) => { /* 404 */ })
```

`/{*splat}` keeps matching `/` itself, as `*` did; `app.use` with no
path already matches every request.

**Prettier 3.9 reformat** — six files re-wrapped by `npm run lint`
(`--fix`), cosmetic only: `BasicInfoCard.test.tsx`, `AMMPool/utils.ts`,
`ConfBalanceTooltipIcon.tsx`, `Notification/index.tsx`,
`TransactionActionIcon.tsx`, `registerServiceWorker.js`.

**Lockfile** — 86 packages changed version, 44 added, 46 removed; most
of the churn is Express 5's own dependency tree (`router`,
`path-to-regexp` 8, `serve-static` 2, …).

All Semgrep tickets closed in Q3 were re-verified against this lockfile
and remain satisfied (e.g. `path-to-regexp` is now 8.4.2 and
`serve-static` 2.2.1, both outside their advisories' affected ranges).

## Test Plan

Run locally on Node 22.14:

- `npm run lint:ci` — passes
- `npm run build` — passes
- `npm run build-ts` — passes
- `npm run test:ci` — 292/293 suites, 1688/1726 tests pass; coverage
thresholds met. The only failure,
`src/containers/shared/test/amendmentUtils.test.ts` (38 tests), calls
the live VHS dev API (`vhs.dev.ripplex.io/v1/network/amendments/info`),
which was returning **HTTP 503** during the run; it fails identically on
an untouched `main` checkout. It is unrelated to this batch and should
pass once the endpoint recovers (or be mocked in a follow-up).
- **Express 5 server smoke test** (not covered by CI), with `node
server`:
- `NODE_ENV=production`: `/` → 200 `index.html`; `/transactions/ABC123`
→ 200 `index.html` (SPA fallback); `/api/v1/healthz` → 200 `success`.
- `NODE_ENV=development`: `/` → 200 (static); `/transactions/ABC123` →
404 `{"error":"route not found"}`; `/api/v1/does-not-exist` → 404.

## Superseded Dependabot PRs

| PR | Package | From | Asked for | Resolved | Status |
MajorVersionUpgrade |

|----|---------|------|-----------|----------|--------|---------------------|
| #1375 | ts-jest | 29.4.9 | 29.4.14 | 29.4.14 | Upgraded | No |
| #1374 | dotenv | 17.4.2 | 18.0.5 | 18.0.6 | Upgraded | Yes
([v18](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)) |
| #1373 | @testing-library/react | 13.4.0 | 16.3.3 | 16.3.3 | Upgraded |
Yes
([v14](https://github.com/testing-library/react-testing-library/releases/tag/v14.0.0),
[v15](https://github.com/testing-library/react-testing-library/releases/tag/v15.0.0),
[v16](https://github.com/testing-library/react-testing-library/releases/tag/v16.0.0))
|
| #1372 | compression | 1.8.1 | 1.8.2 | 1.8.2 | Upgraded | No |
| #1371 | stylelint-scss | 7.0.0 | 7.3.0 | 7.3.0 | Upgraded | No |
| #1370 | @babel/preset-react | 7.28.5 | 8.0.1 | 7.28.5 | Skipped (peer
dep conflict: requires `@babel/core ^8`; installed 7.29.7) | Yes
([v8](https://github.com/babel/babel/releases/tag/v8.0.0)) |
| #1369 | express | 4.22.3 | 5.2.1 | 5.2.1 | Upgraded (with
`server/index.js` route fix) | Yes
([v5](https://github.com/expressjs/express/releases/tag/v5.0.0),
[migration guide](https://expressjs.com/en/guide/migrating-5.html)) |
| #1368 | lint-staged | 15.5.2 | 17.6.0 | 15.5.2 | Skipped (engine
conflict: requires Node ≥ 22.22.1; repo allows `>=22.0.0` with
`engine-strict=true`) | Yes
([v16](https://github.com/lint-staged/lint-staged/releases/tag/v16.0.0),
[v17](https://github.com/lint-staged/lint-staged/releases/tag/v17.0.0))
|
| #1367 | @types/node | 22.19.17 | 26.6.4 | 22.19.17 | Skipped (runtime
is Node 22; Node 26 types would allow APIs missing at runtime) | Yes
([types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/node))
|
| #1366 | jest-environment-jsdom | 30.3.0 | 30.5.2 | 30.5.2 | Upgraded |
No |
| #1365 | i18next-browser-languagedetector | 7.2.2 | 8.2.1 | 8.2.1 |
Upgraded | Yes
([v8](https://github.com/i18next/i18next-browser-languageDetector/blob/master/CHANGELOG.md))
|
| #1364 | eslint-plugin-prettier | 5.5.5 | 5.5.6 | 5.5.6 | Upgraded | No
|
| #1363 | i18next-http-backend | 3.0.6 | 4.0.2 | 4.0.2 | Upgraded | Yes
([v4](https://github.com/i18next/i18next-http-backend/blob/master/CHANGELOG.md))
|
| #1362 | @typescript-eslint/parser | 8.58.2 | 8.71.0 | 8.71.1 |
Upgraded | No |
| #1361 | react / @types/react | 18.3.1 / 18.3.28 | 19.3.0 / 19.3.0 |
18.3.1 / 18.3.28 | Skipped (peer dep conflict: `react-query@3.39.3`, the
last v3, requires `react ≤ 18`) | Yes
([v19](https://github.com/facebook/react/releases/tag/v19.0.0),
[types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/react))
|
| #1360 | react-helmet-async | 2.0.5 | 3.0.0 | 3.0.0 | Upgraded | Yes
([v3](https://github.com/staylor/react-helmet-async/releases/tag/v3.0.0))
|
| #1359 | react-error-boundary | 4.1.2 | 6.1.6 | 6.1.6 | Upgraded | Yes
([v5](https://github.com/bvaughn/react-error-boundary/releases/tag/5.0.0),
[v6](https://github.com/bvaughn/react-error-boundary/releases/tag/6.0.0))
|
| #1358 | react-error-overlay | 6.0.11 | 6.1.0 | 6.1.0 | Upgraded | No |
| #1357 | vite-plugin-environment | 1.1.3 | 1.1.4 | 1.1.3 | Skipped
(peer dep conflict: requires `vite >= 8`; installed 7.3.6) | No |
| #1356 | prettier | 3.6.2 | 3.9.9 | 3.9.9 | Upgraded | No |
| #1355 | xrpl | 4.6.0 | 5.3.0 | 5.3.0 | Upgraded | Yes
([v5](https://github.com/XRPLF/xrpl.js/releases/tag/xrpl%405.0.0)) |
| #1354 | react-router | 7.18.4 | 8.4.0 | 7.18.4 | Skipped (peer dep
conflict: requires `react ≥ 19.2.7`, blocked by #1361; also Node ≥
22.22) | Yes
([v8](https://github.com/remix-run/react-router/releases/tag/react-router%408.0.0))
|
| #1353 | vite-plugin-svgr | 4.5.0 | 5.2.0 | 5.2.0 | Upgraded | Yes
([v5](https://github.com/pd4d10/vite-plugin-svgr/releases/tag/v5.0.0)) |
| #1352 | @typescript-eslint/eslint-plugin | 8.58.2 | 8.71.0 | 8.71.1 |
Upgraded | No |
| #1351 | react-i18next | 15.4.1 | 17.0.15 | 15.4.1 | Skipped (peer dep
conflict: requires `i18next ≥ 26.2.0`; installed 23.16.8) | Yes
([CHANGELOG](https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md))
|
| #1350 | babel-jest | 29.7.0 | 30.5.2 | 30.5.2 | Upgraded | Yes
([v30](https://jestjs.io/blog/2025/06/04/jest-30)) |
| #1349 | tldts | 6.1.86 | 7.4.16 | 7.4.16 | Upgraded | Yes
([v7](https://github.com/remusao/tldts/releases/tag/v7.0.0)) |
| #1348 | eslint-import-resolver-typescript | 4.4.4 | 4.4.5 | 4.4.5 |
Upgraded | No |
| #1347 | @babel/preset-env | 7.29.2 | 8.0.6 | 7.29.2 | Skipped (peer
dep conflict: requires `@babel/core ^8`; installed 7.29.7) | Yes
([v8](https://github.com/babel/babel/releases/tag/v8.0.0)) |
| #1346 | eslint-plugin-react-hooks | 4.6.2 | 7.1.1 | 4.6.2 | Skipped
(peer dep conflict: `eslint-config-airbnb@19.0.4`, the latest, requires
`^4.3.0`) | Yes
([CHANGELOG](https://github.com/facebook/react/blob/main/packages/eslint-plugin-react-hooks/CHANGELOG.md))
|

## Semgrep tickets

Out of scope (not package-upgrade-fixable; not addressed here):
DGE-4837, DGE-4839, DGE-4840, DGE-7803, DGE-7812 (code findings);
DGE-7802, DGE-7804 (config findings); DGE-4831, DGE-4834, DGE-4843,
DGE-7794 (`ripple/explorer-deploy`).

| Ticket | Package | From | Asked for | Resolved | Status |
MajorVersionUpgrade |

|--------|---------|------|-----------|----------|--------|---------------------|
| [DGE-8416](https://ripplelabs.atlassian.net/browse/DGE-8416) | axios |
1.20.0 | ≥ 1.20.0 | 1.20.0 | No-op (already satisfied on main since the
Q3 batch) | No |
| [DGE-8417](https://ripplelabs.atlassian.net/browse/DGE-8417) | axios |
1.20.0 | ≥ 1.20.0 | 1.20.0 | No-op (already satisfied on main since the
Q3 batch) | No |
| [DGE-8418](https://ripplelabs.atlassian.net/browse/DGE-8418) | axios |
1.20.0 | ≥ 1.20.0 | 1.20.0 | No-op (already satisfied on main since the
Q3 batch) | No |
| [DGE-8419](https://ripplelabs.atlassian.net/browse/DGE-8419) | axios |
1.20.0 | ≥ 1.20.0 | 1.20.0 | No-op (already satisfied on main since the
Q3 batch) | No |

No ticket required an upgrade that a Dependabot PR did not already
propose.

## Closing instructions

After merging, run `/batch-deps-upgrade close` to close the superseded
PRs and the resolved Semgrep tickets. It will close these **Upgraded**
Dependabot PRs — #1375, #1374, #1373, #1372, #1371, #1369, #1366, #1365,
#1364, #1363, #1362, #1360, #1359, #1358, #1356, #1355, #1353, #1352,
#1350, #1349, #1348 — and these **No-op** tickets: DGE-8416, DGE-8417,
DGE-8418, DGE-8419.

The following PRs were **Skipped** and should remain open so Dependabot
keeps rebasing them: #1370 (@babel/preset-react), #1368 (lint-staged),
#1367 (@types/node), #1361 (react / @types/react), #1357
(vite-plugin-environment), #1354 (react-router), #1351 (react-i18next),
#1347 (@babel/preset-env), #1346 (eslint-plugin-react-hooks). No Semgrep
tickets stay open.
Bumps [react-i18next](https://github.com/i18next/react-i18next) from 15.4.1 to 17.0.15.
- [Changelog](https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md)
- [Commits](i18next/react-i18next@v15.4.1...v17.0.15)

---
updated-dependencies:
- dependency-name: react-i18next
  dependency-version: 17.0.15
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/react-i18next-17.0.15 branch from ca89a62 to f1d0876 Compare October 8, 2026 15:52

@ripple-code-reviewer ripple-code-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependency-only bump of react-i18next 15.4.1 → 17.0.15 (two major versions) plus its transitive deps (html-parse-stringify 3→4, use-sync-external-store added, void-elements removed, @babel/runtime patch bump). The lockfile and package.json changes are consistent with the stated purpose, but the magnitude of the jump and a tightened peer-dependency range warrant a quick compatibility check before merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants