Repository navigation
chore(deps-dev): bump prettier from 3.6.2 to 3.9.9 - #1356
dependabot[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Routine Dependabot devDependency bump of prettier 3.6.2 → 3.9.9, consistently updated in both package.json and package-lock.json. This is an exact-pin-to-exact-pin dev tooling update (not a caret-range or lockfile downgrade), matches the MR's stated purpose, and no production/runtime code is affected. Nothing to flag.
Bumps [prettier](https://github.com/prettier/prettier) from 3.6.2 to 3.9.9. - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](prettier/prettier@3.6.2...3.9.9) --- updated-dependencies: - dependency-name: prettier dependency-version: 3.9.9 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
8147688 to
264d2b4
Compare
There was a problem hiding this comment.
Routine Dependabot bump of prettier from 3.6.2 to 3.9.9 (dev dependency only), pinned exact version in both package.json and package-lock.json. No source files were touched, and prettier formatting is unaffected since there are no code changes to reformat in this MR. Low risk — purely a dev tooling version update.
## High Level Overview of Change
Quarterly batch dependency upgrade (2026-Q4). This PR consolidates the
open Dependabot dependency PRs **and** applies any further upgrades
needed to resolve the open Semgrep (DGE) supply-chain tickets that a
package upgrade can fix.
- **21** Dependabot PRs applied (Upgraded); **9** skipped
(peer-dependency or Node-engine conflicts — see the table).
- **0** Semgrep tickets needed an upgrade: the 4 new **Critical** axios
tickets (DGE-8416–8419, `axios ≥ 1.20.0`) are already satisfied on
`main` by the Q3 batch (No-op), and none are left open.
- Twelve of the applied PRs are major bumps, eight of them production
dependencies: `express` 5, `dotenv` 18,
`i18next-browser-languagedetector` 8, `i18next-http-backend` 4,
`react-helmet-async` 3, `react-error-boundary` 6, `vite-plugin-svgr` 5,
`tldts` 7.
> **Express 4 → 5 needed a server fix that CI does not catch — please
review it specifically.** Under Express 5 the production server crashed
on startup (`PathError: Missing parameter name at index 1: *`), because
`path-to-regexp` 8 no longer accepts a bare `*` route. No Jest test
loads `server/`, so `lint:ci`, `build`, `build-ts` and `test:ci` all
passed regardless. Two lines in `server/index.js` were changed to the
Express 5 syntax, and the server was started and probed in both
production and development modes (see Test Plan).
### Context of Change
Quarterly batch of the Dependabot PRs opened on 2026-10-01, plus the
Semgrep tickets a package upgrade can fix. Direct dependency versions
were bumped in `package.json`; `package-lock.json` was updated in place
(never regenerated from scratch). No `overrides` or `resolutions` were
added and no parent range was widened.
### Type of Change
- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [x] Breaking change (fix or feature that would cause existing
functionality to not work as expected)
- [ ] Refactor (non-breaking change that only restructures code)
- [ ] Tests (You added tests for code that already exists, or your new
feature included in this PR)
- [ ] Documentation Updates
- [ ] Translation Updates
- [ ] Release
"Breaking change" is checked because production dependencies cross major
versions (most notably `express` 5). User-facing behavior is unchanged.
### Codebase Modernization
N/A — no file conversions.
- [ ] Updated files to React Hooks
- [ ] Updated files to TypeScript
## Before / After
**`server/index.js`** — Express 5 route syntax (details in
`code-changes.md`):
```js
// before (Express 4)
app.get('*', (_req, res) => { res.sendFile(path.join(__dirname, '/../build/index.html')) })
app.use('*', (req, res) => { /* 404 */ })
// after (Express 5)
app.get('/{*splat}', (_req, res) => { res.sendFile(path.join(__dirname, '/../build/index.html')) })
app.use((req, res) => { /* 404 */ })
```
`/{*splat}` keeps matching `/` itself, as `*` did; `app.use` with no
path already matches every request.
**Prettier 3.9 reformat** — six files re-wrapped by `npm run lint`
(`--fix`), cosmetic only: `BasicInfoCard.test.tsx`, `AMMPool/utils.ts`,
`ConfBalanceTooltipIcon.tsx`, `Notification/index.tsx`,
`TransactionActionIcon.tsx`, `registerServiceWorker.js`.
**Lockfile** — 86 packages changed version, 44 added, 46 removed; most
of the churn is Express 5's own dependency tree (`router`,
`path-to-regexp` 8, `serve-static` 2, …).
All Semgrep tickets closed in Q3 were re-verified against this lockfile
and remain satisfied (e.g. `path-to-regexp` is now 8.4.2 and
`serve-static` 2.2.1, both outside their advisories' affected ranges).
## Test Plan
Run locally on Node 22.14:
- `npm run lint:ci` — passes
- `npm run build` — passes
- `npm run build-ts` — passes
- `npm run test:ci` — 292/293 suites, 1688/1726 tests pass; coverage
thresholds met. The only failure,
`src/containers/shared/test/amendmentUtils.test.ts` (38 tests), calls
the live VHS dev API (`vhs.dev.ripplex.io/v1/network/amendments/info`),
which was returning **HTTP 503** during the run; it fails identically on
an untouched `main` checkout. It is unrelated to this batch and should
pass once the endpoint recovers (or be mocked in a follow-up).
- **Express 5 server smoke test** (not covered by CI), with `node
server`:
- `NODE_ENV=production`: `/` → 200 `index.html`; `/transactions/ABC123`
→ 200 `index.html` (SPA fallback); `/api/v1/healthz` → 200 `success`.
- `NODE_ENV=development`: `/` → 200 (static); `/transactions/ABC123` →
404 `{"error":"route not found"}`; `/api/v1/does-not-exist` → 404.
## Superseded Dependabot PRs
| PR | Package | From | Asked for | Resolved | Status |
MajorVersionUpgrade |
|----|---------|------|-----------|----------|--------|---------------------|
| #1375 | ts-jest | 29.4.9 | 29.4.14 | 29.4.14 | Upgraded | No |
| #1374 | dotenv | 17.4.2 | 18.0.5 | 18.0.6 | Upgraded | Yes
([v18](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)) |
| #1373 | @testing-library/react | 13.4.0 | 16.3.3 | 16.3.3 | Upgraded |
Yes
([v14](https://github.com/testing-library/react-testing-library/releases/tag/v14.0.0),
[v15](https://github.com/testing-library/react-testing-library/releases/tag/v15.0.0),
[v16](https://github.com/testing-library/react-testing-library/releases/tag/v16.0.0))
|
| #1372 | compression | 1.8.1 | 1.8.2 | 1.8.2 | Upgraded | No |
| #1371 | stylelint-scss | 7.0.0 | 7.3.0 | 7.3.0 | Upgraded | No |
| #1370 | @babel/preset-react | 7.28.5 | 8.0.1 | 7.28.5 | Skipped (peer
dep conflict: requires `@babel/core ^8`; installed 7.29.7) | Yes
([v8](https://github.com/babel/babel/releases/tag/v8.0.0)) |
| #1369 | express | 4.22.3 | 5.2.1 | 5.2.1 | Upgraded (with
`server/index.js` route fix) | Yes
([v5](https://github.com/expressjs/express/releases/tag/v5.0.0),
[migration guide](https://expressjs.com/en/guide/migrating-5.html)) |
| #1368 | lint-staged | 15.5.2 | 17.6.0 | 15.5.2 | Skipped (engine
conflict: requires Node ≥ 22.22.1; repo allows `>=22.0.0` with
`engine-strict=true`) | Yes
([v16](https://github.com/lint-staged/lint-staged/releases/tag/v16.0.0),
[v17](https://github.com/lint-staged/lint-staged/releases/tag/v17.0.0))
|
| #1367 | @types/node | 22.19.17 | 26.6.4 | 22.19.17 | Skipped (runtime
is Node 22; Node 26 types would allow APIs missing at runtime) | Yes
([types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/node))
|
| #1366 | jest-environment-jsdom | 30.3.0 | 30.5.2 | 30.5.2 | Upgraded |
No |
| #1365 | i18next-browser-languagedetector | 7.2.2 | 8.2.1 | 8.2.1 |
Upgraded | Yes
([v8](https://github.com/i18next/i18next-browser-languageDetector/blob/master/CHANGELOG.md))
|
| #1364 | eslint-plugin-prettier | 5.5.5 | 5.5.6 | 5.5.6 | Upgraded | No
|
| #1363 | i18next-http-backend | 3.0.6 | 4.0.2 | 4.0.2 | Upgraded | Yes
([v4](https://github.com/i18next/i18next-http-backend/blob/master/CHANGELOG.md))
|
| #1362 | @typescript-eslint/parser | 8.58.2 | 8.71.0 | 8.71.1 |
Upgraded | No |
| #1361 | react / @types/react | 18.3.1 / 18.3.28 | 19.3.0 / 19.3.0 |
18.3.1 / 18.3.28 | Skipped (peer dep conflict: `react-query@3.39.3`, the
last v3, requires `react ≤ 18`) | Yes
([v19](https://github.com/facebook/react/releases/tag/v19.0.0),
[types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/react))
|
| #1360 | react-helmet-async | 2.0.5 | 3.0.0 | 3.0.0 | Upgraded | Yes
([v3](https://github.com/staylor/react-helmet-async/releases/tag/v3.0.0))
|
| #1359 | react-error-boundary | 4.1.2 | 6.1.6 | 6.1.6 | Upgraded | Yes
([v5](https://github.com/bvaughn/react-error-boundary/releases/tag/5.0.0),
[v6](https://github.com/bvaughn/react-error-boundary/releases/tag/6.0.0))
|
| #1358 | react-error-overlay | 6.0.11 | 6.1.0 | 6.1.0 | Upgraded | No |
| #1357 | vite-plugin-environment | 1.1.3 | 1.1.4 | 1.1.3 | Skipped
(peer dep conflict: requires `vite >= 8`; installed 7.3.6) | No |
| #1356 | prettier | 3.6.2 | 3.9.9 | 3.9.9 | Upgraded | No |
| #1355 | xrpl | 4.6.0 | 5.3.0 | 5.3.0 | Upgraded | Yes
([v5](https://github.com/XRPLF/xrpl.js/releases/tag/xrpl%405.0.0)) |
| #1354 | react-router | 7.18.4 | 8.4.0 | 7.18.4 | Skipped (peer dep
conflict: requires `react ≥ 19.2.7`, blocked by #1361; also Node ≥
22.22) | Yes
([v8](https://github.com/remix-run/react-router/releases/tag/react-router%408.0.0))
|
| #1353 | vite-plugin-svgr | 4.5.0 | 5.2.0 | 5.2.0 | Upgraded | Yes
([v5](https://github.com/pd4d10/vite-plugin-svgr/releases/tag/v5.0.0)) |
| #1352 | @typescript-eslint/eslint-plugin | 8.58.2 | 8.71.0 | 8.71.1 |
Upgraded | No |
| #1351 | react-i18next | 15.4.1 | 17.0.15 | 15.4.1 | Skipped (peer dep
conflict: requires `i18next ≥ 26.2.0`; installed 23.16.8) | Yes
([CHANGELOG](https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md))
|
| #1350 | babel-jest | 29.7.0 | 30.5.2 | 30.5.2 | Upgraded | Yes
([v30](https://jestjs.io/blog/2025/06/04/jest-30)) |
| #1349 | tldts | 6.1.86 | 7.4.16 | 7.4.16 | Upgraded | Yes
([v7](https://github.com/remusao/tldts/releases/tag/v7.0.0)) |
| #1348 | eslint-import-resolver-typescript | 4.4.4 | 4.4.5 | 4.4.5 |
Upgraded | No |
| #1347 | @babel/preset-env | 7.29.2 | 8.0.6 | 7.29.2 | Skipped (peer
dep conflict: requires `@babel/core ^8`; installed 7.29.7) | Yes
([v8](https://github.com/babel/babel/releases/tag/v8.0.0)) |
| #1346 | eslint-plugin-react-hooks | 4.6.2 | 7.1.1 | 4.6.2 | Skipped
(peer dep conflict: `eslint-config-airbnb@19.0.4`, the latest, requires
`^4.3.0`) | Yes
([CHANGELOG](https://github.com/facebook/react/blob/main/packages/eslint-plugin-react-hooks/CHANGELOG.md))
|
## Semgrep tickets
Out of scope (not package-upgrade-fixable; not addressed here):
DGE-4837, DGE-4839, DGE-4840, DGE-7803, DGE-7812 (code findings);
DGE-7802, DGE-7804 (config findings); DGE-4831, DGE-4834, DGE-4843,
DGE-7794 (`ripple/explorer-deploy`).
| Ticket | Package | From | Asked for | Resolved | Status |
MajorVersionUpgrade |
|--------|---------|------|-----------|----------|--------|---------------------|
| [DGE-8416](https://ripplelabs.atlassian.net/browse/DGE-8416) | axios |
1.20.0 | ≥ 1.20.0 | 1.20.0 | No-op (already satisfied on main since the
Q3 batch) | No |
| [DGE-8417](https://ripplelabs.atlassian.net/browse/DGE-8417) | axios |
1.20.0 | ≥ 1.20.0 | 1.20.0 | No-op (already satisfied on main since the
Q3 batch) | No |
| [DGE-8418](https://ripplelabs.atlassian.net/browse/DGE-8418) | axios |
1.20.0 | ≥ 1.20.0 | 1.20.0 | No-op (already satisfied on main since the
Q3 batch) | No |
| [DGE-8419](https://ripplelabs.atlassian.net/browse/DGE-8419) | axios |
1.20.0 | ≥ 1.20.0 | 1.20.0 | No-op (already satisfied on main since the
Q3 batch) | No |
No ticket required an upgrade that a Dependabot PR did not already
propose.
## Closing instructions
After merging, run `/batch-deps-upgrade close` to close the superseded
PRs and the resolved Semgrep tickets. It will close these **Upgraded**
Dependabot PRs — #1375, #1374, #1373, #1372, #1371, #1369, #1366, #1365,
#1364, #1363, #1362, #1360, #1359, #1358, #1356, #1355, #1353, #1352,
#1350, #1349, #1348 — and these **No-op** tickets: DGE-8416, DGE-8417,
DGE-8418, DGE-8419.
The following PRs were **Skipped** and should remain open so Dependabot
keeps rebasing them: #1370 (@babel/preset-react), #1368 (lint-staged),
#1367 (@types/node), #1361 (react / @types/react), #1357
(vite-plugin-environment), #1354 (react-router), #1351 (react-i18next),
#1347 (@babel/preset-env), #1346 (eslint-plugin-react-hooks). No Semgrep
tickets stay open.
|
Superseded by the 2026-Q4 batch dependency upgrade: #1377 |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps prettier from 3.6.2 to 3.9.9.
Release notes
Sourced from prettier's releases.
... (truncated)
Changelog
Sourced from prettier's changelog.
... (truncated)
Commits
cdd17f2Release 3.9.9dc7b896DisablesingleDollarTextMathinmdast-util-math(#20140)f9be58fGit blame ignore 3.9.888470cbBump Prettier dependency to 3.9.89559cabClean changelog_unreleased4fc8ee8Update dependents count4f2ab67Release 3.9.83d82af8Update Regex related dependencies (#20082)5ec8db1[3.9.x] Markdown: Don't let Liquid objects interrupt paragraphs (#20087)5b142edRelease Release@prettier/plugin-hermes@0.2.3,@prettier/plugin-oxc@0.2.3, an...Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for prettier since your current version.