Skip to content

deps(npm): bump monaco-editor from 0.55.1 to 0.57.0 - #1930

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/monaco-editor-0.57.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/monaco-editor-0.57.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Bumps monaco-editor from 0.55.1 to 0.57.0.

Release notes

Sourced from monaco-editor's releases.

v0.57.0

Changes:

  • #5487: Prepare Monaco Editor 0.57.0 release
  • #5415: Bump uuid and webpack-dev-server in /website
  • #5476: Bump baseline-browser-mapping from 2.9.19 to 2.11.21 in /website
  • #5474: Bump svgo from 2.8.3 to 2.8.4 in /samples/browser-esm-parcel
  • #5479: Bump actions/deploy-pages from 5.0.0 to 5.0.1 in the github-actions group
  • #5468: Bump browserslist from 4.28.1 to 4.28.8 in /website
  • #5475: Bump js-yaml from 4.3.1 to 4.3.2
  • #5470: Bump fast-uri from 3.1.2 to 3.1.7 in /webpack-plugin
  • #5469: Bump nanoid from 3.3.11 to 3.3.18 in /webpack-plugin
  • #5467: Bump fast-uri from 3.1.5 to 3.1.7 in /samples/browser-esm-webpack-typescript-react
  • #5466: Bump fast-uri from 3.1.2 to 3.1.7 in /samples
  • #5465: Bump fast-uri from 3.1.4 to 3.1.7 in /website
  • #5463: Bump postcss-selector-parser from 7.1.0 to 7.1.5 in /website
  • #5416: Bump @​babel/core from 7.17.8 to 7.29.7 in /samples/browser-esm-vite-react
  • #5438: Bump electron from 39.8.5 to 39.8.10 in /samples
  • #5460: Bump the github-actions group with 7 updates
  • #5456: Pin GitHub Actions to full-length commit SHAs
  • #5450: Bump postcss from 8.5.12 to 8.5.26
  • #5449: Bump js-yaml from 4.2.0 to 4.3.1
  • #5439: Bump postcss from 8.5.13 to 8.5.26 in /samples
  • #5441: Bump postcss from 8.5.15 to 8.5.26 in /samples/browser-esm-vite-react
  • #5432: Bump undici from 7.28.0 to 7.29.0
  • #5440: Bump brace-expansion in /website
  • #5436: Bump fast-uri from 3.1.4 to 3.1.5 in /samples/browser-esm-webpack-typescript-react
  • #5437: Bump fast-uri from 3.1.2 to 3.1.5
  • #5413: Bump svgo from 2.8.2 to 2.8.3 in /samples/browser-esm-parcel
  • #5419: Bump launch-editor from 2.12.0 to 2.14.1 in /website
  • #5414: Bump fast-uri from 3.1.2 to 3.1.4 in /samples/browser-esm-webpack-typescript-react
  • #5417: Bump minimatch from 3.1.2 to 3.1.5 in /webpack-plugin
  • #5420: Bump ws from 8.18.0 to 8.21.1 in /samples
  • #5418: Bump http-proxy-middleware from 2.0.9 to 2.0.10 in /samples
  • #5412: Bump fast-uri from 3.1.2 to 3.1.4 in /website
  • #5411: Bump shell-quote from 1.8.4 to 1.10.0 in /website
  • #5409: Bump webpack-dev-server from 5.2.5 to 5.2.6 in /samples
  • #5410: Bump postcss from 8.5.14 to 8.5.23 in /website
  • #5407: Bump immutable from 5.1.5 to 5.1.9 in /website
  • #5401: Bump brace-expansion from 1.1.11 to 1.1.16 in /samples

This list of changes was auto generated.

v0.57.0-rc.2

... (truncated)

Changelog

Sourced from monaco-editor's changelog.

[0.57.0]

New Features and APIs

  • Adds editor.wordWrapIndicator to display an indicator at the wrapping column of soft-wrapped lines.
  • Adds editor.fullwidthCharacterWidth, with font and twoCells modes for rendering full-width characters.
  • Adds languages.score to score a language selector against a URI and language.
  • Exports the editor.DiffEditorViewMode type.
  • Adds isForAnotherDocument to the inline completion languages.LifetimeSummary type.

Updates

  • Updates the editor core to VS Code commit 6a598d4a13031703d483d103c1d934a36ad27971, validated in 0.57.0-rc.2.
  • Updates bundled DOMPurify from 3.4.8 to 3.4.15.

[0.56.0]

Breaking Changes

  • Reorganizes the exported ESM modules to provide supported, tree-shakeable entry points (#5155). The monaco-editor entry point continues to load all features and languages. Custom bundles can now import monaco-editor/editor and opt into:
    • all editor features with monaco-editor/features/register.all, or individual features with monaco-editor/features/<feature>/register;
    • all language definitions with monaco-editor/languages/definitions/register.all, or individual definitions with monaco-editor/languages/definitions/<language>/register;
    • the CSS, HTML, JSON, and TypeScript language features with monaco-editor/languages/features/register.all, or their individual register entry points.
  • Renames the misspelled IOverlayWidgetPosition.stackOridinal property to stackOrdinal.
  • Removes the deprecated IMirrorModel and IWorkerContext worker API types.

New Features and APIs

  • Adds editor.doubleClickSelectsBlock.
  • Adds editor.find.closeOnResult and editor.inlayHints.showLongLineWarning.
  • Adds offWhenInlineCompletions to QuickSuggestionsValue.
  • Adds model and provider option support to inline completion providers.
  • Adds ICodeEditor.revealAllCursors, ICodeEditor.getWidthOfLine, and ICodeEditor.renderAsync.
  • Adds advanced-external and advanced-wasm diff algorithms.
  • Exposes typed native LSP client and transport APIs.

Fixes

  • Treats Markdown returned by language servers as untrusted (#5280).
  • Updates the editor core to the version used by 0.56.0-dev-20260625.
Commits
  • d618242 Merge pull request #5487 from microsoft/hediet/b/release-0.57.0
  • ef061ff Prepare Monaco Editor 0.57.0 release
  • 8e9b0f7 Keep editor release version stable across task retries
  • 3f31304 Prepare VS Code native headers before installing dependencies
  • ebd1312 Use authenticated Foundry Local installer for core builds
  • 176408b Align release build Node version with VS Code 1.139
  • 97d81ca Bump uuid and webpack-dev-server in /website (#5415)
  • f7c7f4c Bump baseline-browser-mapping from 2.9.19 to 2.11.21 in /website (#5476)
  • 36f4fe6 Bump svgo from 2.8.3 to 2.8.4 in /samples/browser-esm-parcel (#5474)
  • f24cd7f Bump actions/deploy-pages in the github-actions group (#5479)
  • Additional commits viewable in compare view


Note

Medium Risk
Monaco is central to YAML/file editing; the jump includes 0.56 breaking changes for custom bundles, though this repo uses the standard entry point via @monaco-editor/react.

Overview
Bumps monaco-editor from 0.55.1 to 0.57.0 in the root lockfile and pins the same version in web and @skyhook-io/k8s-ui (direct dependency and peer dependency). No application source changes.

Consumers still resolve Monaco through @monaco-editor/react (YAML editors and file preview). The upgrade pulls in Monaco’s transitive DOMPurify bump (3.2.7 → 3.4.15 in the lockfile) and editor behavior/API updates from 0.56.x and 0.57.0 (e.g. optional ESM entry-point layout in 0.56, new editor options in 0.57). Worth a quick smoke test of YAML editing and diff/preview flows after install.

Reviewed by Cursor Bugbot for commit 6398fa9. Bugbot is set up for automated code reviews on this repo. Configure here.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit fe55e2d. Configure here.

"elkjs": ">=0.9.0",
"lucide-react": ">=0.400.0",
"monaco-editor": "0.55.1",
"monaco-editor": "0.57.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Monaco deep ESM imports no longer resolve

High Severity

Bumping monaco-editor to 0.57.0 includes the 0.56 ESM export remap, but monacoRuntime.ts still imports monaco-editor/esm/vs/... paths. The new exports map prefixes those specifiers with esm/vs/ again, so they no longer resolve. Vite cannot bundle the runtime, which takes down the YAML editor, diff viewer, and pod file preview.

Additional Locations (2)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit fe55e2d. Configure here.

nadaverell added a commit that referenced this pull request Sep 30, 2026
One tested batch replacing this week's soaked, low-risk Dependabot PRs.
Dependency-only: no application source changes.

**Screening time:** 2026-09-30T08:40:02Z (re-checked 09:12Z, base
`0490dd87` unchanged)
**72h cutoff:** published at or before 2026-09-27T08:40:02Z. Every
resolved version below clears it.

## Included

| PR | Dependency | Old → New | Published (UTC) | Soak | Risk conclusion
|
|---|---|---|---|---|---|
| #1932 | k8s.io/{api, apiextensions-apiserver, apimachinery, apiserver,
cli-runtime, client-go, component-helpers, component-base, streaming} |
v0.37.0 → v0.37.1 | 2026-09-23 20:28–23:27 | ~6.5d | Negligible. Every
staging repo's v0.37.0...v0.37.1 compare is a single "Update
dependencies to v0.37.1 tag" commit touching only go.mod/go.sum.
`streaming` v0.37.1 is the same commit as v0.37.0. |
| #1938 | github.com/jackc/pgx/v5 | v5.10.0 → v5.11.0 | 2026-09-07 23:39
| ~22d | Low. Used only by the Postgres timeline store through `stdlib`.
See notes. |
| #1936 | github.com/klauspost/compress | v1.20.0 → v1.20.1 | 2026-09-25
08:00 | ~5d | Low–moderate. Encoder/decoder performance rewrites plus
correctness fixes; no API or default changes. Radar uses it directly
only for the HTTP gzip encoder. |
| #1934 | modernc.org/sqlite (+ modernc.org/libc) | v1.58.0 → v1.59.0
(libc v1.75.6 → v1.75.7) | sqlite 2026-09-15 07:30; libc 2026-09-01
19:33 | ~15d / ~29d | Low. The transpiled SQLite is unchanged (3.53.4).
libc uses native Go mem*/str* routines. The UDF context-pooling change
doesn't apply because Radar registers no UDFs. |
| #1937 | eslint | 10.10.0 → 10.11.0 | 2026-09-18 20:15 | ~11.5d | Low.
A few rule refinements, no breaking changes. Lint gives 0 errors / 441
warnings, the same as main. |
| #1935 | vite | 8.2.2 → 8.3.1 | 2026-09-24 12:26 | ~6d | Low. Moves
rolldown 1.2.6 → 1.2.11, whose tree-shaking and code-splitting fixes can
change bundle output, so I smoke-tested the built binary in a browser
(below). |
| #1931 | lucide-react | 1.37.0 → 1.48.0 | 2026-09-24 05:53 | ~6d | Low.
No exports were removed between the two tarballs (6137 → 6347). All 226
icon names Radar imports exist in 1.48.0. The k8s-ui peer range
`>=0.400.0` is unchanged. |

### Movement beyond the Dependabot PRs (reviewed, all soaked)
- **k8s alignment:** root `k8s.io/kubectl` and
`k8s.io/csi-translation-lib` (indirect, via `./pkg`) and all of
`pkg/go.mod`'s k8s.io requirements move to v0.37.1 as well. Without
this, #1932 would leave the graph mixing v0.37.0 and v0.37.1.
- kubectl was published 2026-09-24 01:06Z and csi-translation-lib
2026-09-24 00:45Z. Both are go.mod-only tag bumps, like the rest of the
group.
- Module-graph-only entries `k8s.io/{code-generator, kms, metrics}`
v0.37.1 were published 2026-09-23 21:22 / 21:45 / 23:18Z. None of them
appears in go.sum.
- **npm transitives:**
- `rolldown` and all 15 `@rolldown/binding-*` 1.2.6 → 1.2.11 (2026-09-24
13:54–14:30Z)
  - `@oxc-project/types` 0.147.0 → 0.151.0 (2026-09-21)
  - `picomatch` 4.0.5 → 4.0.7 (2026-08-24)
  - Nothing else in `package-lock.json` changed.
- **Newer releases deliberately not picked up:**
  - lucide-react 1.49.0 (2026-09-29) is inside the soak window.
- modernc.org/sqlite v1.60.x (2026-09-28/29) is inside the window, and
it pins libc v1.77.1. libc has an open stack-overflow crash against
v1.77.0 (cznic/libc#60).

## Held / excluded (these PRs stay open)

| PR | Update | Decision | Reason |
|---|---|---|---|
| #1933 | vitest 4.1.11 → 5.0.2 (major) | **Hold** | vitest 5 requires
Node `^22.12 \|\| ^24 \|\| >=26`, but `ci.yml` pins Node 20 for the
Frontend, k8s-ui and Settings jobs. The PR's CI only passed because npm
treats the engine mismatch as a warning (`EBADENGINE`), which Bugbot
also flagged. **Follow-up:** move CI (and CONTRIBUTING's "Node 20+") to
Node 22 first. Note that `web/` runs the hoisted vitest without
declaring it. |
| #1930 | monaco-editor 0.55.1 → 0.57.0 | **Exclude** | Needs source
changes. The deep side-effect imports in
`packages/k8s-ui/src/components/ui/monacoRuntime.ts`
(`esm/vs/editor/contrib/{find,folding,format,gotoError,hover,suggest}/...`)
no longer resolve (TS2882), which fails the Frontend, k8s-ui and
Settings jobs. |
| #1776 | modelcontextprotocol/go-sdk 1.6.1 → 1.8.0 | **Exclude** |
Changes behaviour Radar relies on.
`TestInvestigationHandlerAnnotatesRealToolCallWithoutChangingPublicContract`
fails: "private mount handshake did not mark the scope connected".
Radar's private-mount handling needs adapting first. |
| #1939 | helmfile/helmfile-action v2.2.0 → v2.4.8 | **Exclude** |
Breaks the Helm chart job. Since v2.3.0 the action installs Helm plugins
from `.tgz` release assets
([#648](helmfile/helmfile-action#648)), so
helm-unittest ends up installed twice ("two plugins claim the name
\"unittest\""). It also moved to the node24 runtime (v2.4.0). Needs a
`ci.yml` change to how `helm-plugins` is specified. |

## Radar usage and risk notes
- **pgx 5.11**
([release](https://github.com/jackc/pgx/releases/tag/v5.11.0)):
- It makes connection-string parsing match libpq exactly, which changes
some edge cases: a literal `+` in URI query values, bad percent-encoding
now errors, `#` is data, the last repeated parameter wins, bare IPv6
hosts need brackets, and backslashes in keyword/value strings now
escape.
- That touches user-supplied `RADAR_TIMELINE_POSTGRES_DSN` values with
unusual encoding, which is worth a release-note line.
- The date/time parser rewrite doesn't reach Radar data: timestamps are
stored as int64 nanoseconds.
- The new `Rows.TypeMap` interface method doesn't matter because Radar
implements no custom `pgx.Rows`.
- It also includes security hardening: startup-parameter NUL injection
is rejected, DSN passwords are redacted more thoroughly, and decoders
are hardened against panics.
- The PostgreSQL integration tests skipped locally (no server). CI runs
them with `RADAR_REQUIRE_POSTGRES_TESTS=1` against postgres:17.
- **klauspost/compress 1.20.1**
([release](https://github.com/klauspost/compress/releases/tag/v1.20.1)):
used directly only by `internal/server/compress.go`
(`kgzip.NewWriterLevel`); zstd reaches Radar only transitively (helm,
go-containerregistry, prometheus). In the smoke test, a live
`/api/resources/pods` response came back `Content-Encoding: gzip` and
decoded with system `gunzip` to 269 pods.
- **modernc sqlite/libc**
([CHANGELOG](https://gitlab.com/cznic/sqlite/-/blob/v1.59.0/CHANGELOG.md)):
used by the SQLite timeline store and `ai-runs.db`. libc is exact-pinned
to the version sqlite requires.
- **k8s 0.37.1**
([CHANGELOG-1.37](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.37.md#v1371)):
the library code is identical. The release fixes are in binaries (DRA,
kube-proxy on Windows, kubeadm).
- **vite 8.3 / rolldown**
([8.3.0](https://github.com/vitejs/vite/releases/tag/v8.3.0),
[8.3.1](https://github.com/vitejs/vite/releases/tag/v8.3.1), [rolldown
releases](https://github.com/rolldown/rolldown/releases)):
- Our `manualChunks` does its own `node_modules/` matching, so vite
8.3.0's path-segment change doesn't affect it.
- `@vitejs/plugin-react` 6.1.1 still satisfies its peer range, and
vitest 4.1.11's `vite` peer covers ^8.
- **eslint 10.11**
([release](https://github.com/eslint/eslint/releases/tag/v10.11.0)) and
**lucide-react**
([releases](https://github.com/lucide-icons/lucide/releases)): the
lucide range includes the removal of `trash` (Radar uses `Trash2`) and
glyph redraws for `Trash2` and `Building2`. That's cosmetic; tests that
assert icon class names pass.

## Verification
- **Integrity:** `go mod verify` passes in both root and `pkg`. `go.sum`
/ `pkg/go.sum` were regenerated from main with a clean `go mod tidy`.
Each changes 30 / 14 lines each way, only the modules listed above.
- **Type-check:** `make tsc` passes.
- **Lint:** `cd web && npm run lint` gives 0 errors and 441 warnings
(the same as main).
- **Frontend tests:**
  - `packages/k8s-ui` `npm test`: 209 files, 4030 passed, 1 skipped.
  - `web` `npm run test`: 151 files, 1764 passed.
- **Go tests:**
  - `cd pkg && go test ./...` passes.
- Root `go test ./...` passes except `cmd/desktop`. Its
`TestGetShellEnv` and `TestEnrichEnvPrecedenceAndDiagnostics` hit their
5s login-shell timeout while the full parallel suite was loading the
machine.
- That flake already exists on main and doesn't involve any bumped
module. Re-run on this branch with `go test ./cmd/desktop/ -count=3`,
the tests pass, and they also pass on main.
- **Build:** `make build` passes.
- **Binary smoke test** (built binary against a live GKE cluster):
- All 8 entry assets (index, rolldown-runtime, vendor, ui, monaco
JS/CSS) returned 200.
  - The Pods table rendered with lucide icons.
- The pod drawer's YAML → Edit loaded Monaco along with `monacoRuntime`,
`yamlMonacoRuntime`, the `monacoYaml.worker` and `editor.worker` chunks,
and showed the pod YAML.
- The console showed no errors. The edit was cancelled; nothing was
applied.
- **visual-test:** not run as a full `/visual-test`. The targeted
browser smoke test above covers the rendering-relevant bumps
(vite/rolldown chunking, Monaco loading, lucide icons).

Supersedes #1932, #1938, #1936, #1934, #1937, #1935, #1931

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Patch dependency upgrades with no app code changes; pgx DSN parsing
edge cases are the main operational note for unusual Postgres connection
strings.
> 
> **Overview**
> **Dependency-only batch** — no application source changes. Bumps Go
and npm lockfiles after screening several Dependabot PRs.
> 
> **Go:** Aligns all `k8s.io/*` modules to **v0.37.1** in the root
module, `./pkg`, and checksums (patch tag bumps only). Also bumps **pgx
v5.11.0** (Postgres timeline via `RADAR_TIMELINE_POSTGRES_DSN`),
**klauspost/compress v1.20.1** (HTTP gzip in
`internal/server/compress.go`), and **modernc.org/sqlite v1.59.0** with
**libc v1.75.7** (SQLite timeline / `ai-runs.db`).
> 
> **Frontend:** **vite 8.3.1** (pulls **rolldown 1.2.11** and related
`@rolldown/binding-*` / `@oxc-project/types` transitives in
`package-lock.json`), **eslint 10.11.0**, and **lucide-react 1.48.0** in
`web/` and `packages/k8s-ui`.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
7512c17. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/monaco-editor-0.57.0 branch from fe55e2d to 08b5e17 Compare September 30, 2026 09:54
nadaverell added a commit that referenced this pull request Oct 7, 2026
One tested batch replacing this week's soaked, low-risk Dependabot PRs.
Dependency-only: no application source changes.

**Screening time:** 2026-10-07T08:38:20Z (reconciled again at 09:00Z;
rebased onto `1f05aee9`, which picked up #2015)
**72h cutoff:** published at or before 2026-10-04T08:38:20Z. Every
resolved version below clears it. The npm lockfile was regenerated with
`npm install --package-lock-only --before=2026-10-04T08:38:20Z`, so the
resolver could not float past the cutoff.

## Included

| PR | Dependency | Old → New | Published (UTC) | Soak | Risk conclusion
|
|---|---|---|---|---|---|
| #2000 | modernc.org/sqlite (+ modernc.org/libc) | v1.59.0 → v1.60.1
(libc v1.75.7 → v1.77.1) | sqlite 2026-09-29 08:41; libc 2026-09-21
23:07 | ~8d / ~15.4d | Low–moderate. SQLite stays 3.53.4. The libc range
is substantial on Linux (see notes), so I ran the sqlite-backed stores'
tests in a Linux container. |
| #1998 | github.com/prometheus/common | v0.71.0 → v0.72.0 | 2026-09-28
08:33 | ~9d | Low. The only change on Radar's path is a stricter text
parser (see notes). Its `go 1.26` requirement matches ours. |
| #2001 | github.com/google/go-containerregistry | v0.22.0 → v0.22.1 |
2026-09-04 00:07 | ~33d | Low. SSRF-guard hardening, an authn fix that
stops empty credentials overwriting `AuthConfig.Auth`, and sha512 digest
support. Radar uses `authn`, `name`, `remote`, `v1/google` for image
inspection. |
| #2004 | react-virtuoso | 4.18.13 → 4.18.16 | 2026-09-29 16:03 | ~7.7d
| Low. 4.18.14 adds custom `ul` List wrappers. 4.18.15 fixes
`initialItemCount` clamping, which Radar doesn't use. 4.18.16 stops
TableVirtuoso leaking `skipAnimationFrameInResizeObserver` onto the DOM;
Radar doesn't pass that prop. I smoke-tested the binary in a browser
anyway. |
| #2003 | typescript-eslint (+ 10 `@typescript-eslint/*`) | 8.70.0 →
**8.71.0** | 2026-09-28 17:12 | ~8.6d | Low. Adds a new rule that's
opt-in and not enabled here, plus rule fixes. The set of 444 lint
warnings is identical before and after (0 errors). **8.71.1 (2026-10-05)
is too fresh and was deliberately not picked up.** |
| #2002 | vitest (+ @vitest/mocker, @vitest/spy) | 5.0.2 → 5.0.3 |
2026-09-30 11:30 | ~6.9d | Low. Bug fixes in repeats/retry, cache
revalidation, jsdom Blob and the pool. Both test suites pass. |
| #1999 | prettier | 3.9.8 → 3.9.9 | 2026-09-23 06:31 | ~14d |
Negligible. A Markdown `$`-as-math fix; Radar formats only `.ts/.tsx`.
`prettier --check` reports the same 1089 files before and after. |
| #2015 | source-map-js | 1.2.1 → 1.2.2 | 2026-09-30 14:08 | ~6.8d |
Low. Build/test-time only (postcss, Tailwind, jsdom via css-tree). Fixes
a DoS from malicious indexed source maps (CVE-2026-93749) and a crash
under a no-`unsafe-eval` CSP. |

### Movement beyond the Dependabot PRs (reviewed, all soaked)
- **Go:** `modernc.org/libc` v1.75.7 → v1.77.1 (2026-09-21), the version
sqlite pins.
- Three `go.sum` entries also changed, `golang.org/x/tools` v0.50.0
(2026-09-08), `modernc.org/cc/v4` v4.29.7 (2026-09-12) and
`modernc.org/ccgo/v4` v4.36.1 (2026-09-21). `go mod why` shows each one
is reached only through `go-sdk/mcp.test` or `libc.test`, never a Radar
binary.
  - `pkg/go.mod` is untouched.
- **npm:**
- `ignore` 7.0.9 → 7.0.12 (2026-10-02, ~4.8d), nested under
`@typescript-eslint/eslint-plugin`. These are gitignore-semantics fixes
plus linear-time perf work (no release notes, so I reviewed the
[compare](kaelzhang/node-ignore@7.0.9...7.0.12)).
It's lint-time only, and the lint output is identical.
- `why-is-node-running` 3.2.2 → 3.2.1, a **downgrade** that vitest 5.0.3
pins on purpose
([vitest#11403](vitest-dev/vitest#11403),
avoids `ERR_PNPM_TRUST_DOWNGRADE`). 3.2.1 was published 2024-10-29.
  - Nothing else in `package-lock.json` changed.
- **Too-fresh versions deliberately excluded by the `--before` cutoff:**
- typescript-eslint / `@typescript-eslint/*` 8.71.1 (2026-10-05 17:08Z).
- `magic-string` 1.4.3 (2026-10-05 04:52Z), which a plain refresh would
have pulled under `@vitest/mocker`. It stays at 1.4.2, inside mocker's
`^1.2.3`.

## Held / excluded (these PRs stay open)

| PR | Update | Decision | Reason |
|---|---|---|---|
| #1776 | modelcontextprotocol/go-sdk 1.6.1 → 1.8.0 | **Exclude** | I
re-tested on today's main and it still fails
`TestInvestigationHandlerAnnotatesRealToolCallWithoutChangingPublicContract`
("private mount handshake did not mark the scope connected"). Radar's
private-mount handling needs adapting first; that's a source change. |
| #1930 | monaco-editor 0.55.1 → 0.57.0 | **Exclude** | Unchanged from
last week. The deep side-effect imports in
`packages/k8s-ui/src/components/ui/monacoRuntime.ts` don't resolve under
0.57 (TS2882), and that file hasn't changed since. The PR's CI still
fails the Frontend, k8s-ui and Settings jobs. Needs a source change. |
| #1939 | helmfile/helmfile-action v2.2.0 → v2.4.8 | **Exclude** |
Unchanged from last week. Since v2.3.0 the action installs helm-unittest
twice ([#648](helmfile/helmfile-action#648)), so
the Helm chart job fails. Needs a `ci.yml` change to how `helm-plugins`
is specified. |

## Radar usage and risk notes
- **modernc sqlite 1.60 / libc 1.77.1** ([sqlite
CHANGELOG](https://gitlab.com/cznic/sqlite/-/blob/v1.60.1/CHANGELOG.md),
[libc
compare](https://gitlab.com/cznic/libc/-/compare/v1.75.7...v1.77.1)):
- Radar imports only the `database/sql` driver: the SQLite timeline
store and `ai-runs.db`. It uses no `vfs`, no `pcache`, none of the
removed `lib` constants and no `_pragma`. `StrictPragmas` is opt-in.
- The 1.60.0 change that turns a WAL `-shm` read fault into
`SQLITE_IOERR_IN_PAGE` instead of a crash is a strict improvement.
- The libc range includes musl atomics translated to Go, stdio locking
fixes, and setenv/putenv mirrored into the Go environment on musl.
That's why I ran the targeted Linux run below.
- **Last week's blocker is resolved.** libc v1.77.0's recursive `Xnanf`
stack overflow
([cznic/libc#60](https://gitlab.com/cznic/libc/-/issues/60)) caused us
to hold sqlite 1.60. v1.77.0 is now retracted, and v1.77.1 adds the fix
and a `TestNaN` regression test.
- The issue is still open upstream, so I checked directly: in v1.77.1,
Linux `Xnanf` returns `X__builtin_nanf` (`math.NaN()`), and the issue's
own reproducer prints `NaN NaN NaN` on linux/arm64 with no stack
overflow.
- **prometheus/common 0.72**
([release](https://github.com/prometheus/common/releases/tag/v0.72.0)):
- Radar uses `expfmt.NewTextParser(model.LegacyValidation)` to parse
apiserver metrics in `internal/upgrade/collectors_live.go`, and `model`
in the MCP Prometheus tool.
- The only text-parser change
([#988](prometheus/common#988)) now rejects a
nameless `{}` sample that follows metric metadata. Kubernetes apiserver
exposition never emits one.
- The rest is OpenMetrics 2.0 encoding, which is experimental and unused
here, plus format-constant docs
([#992](prometheus/common#992), backward
compatible).
- **typescript-eslint 8.71.0**
([release](https://github.com/typescript-eslint/typescript-eslint/releases/tag/v8.71.0)),
**vitest 5.0.3**
([release](https://github.com/vitest-dev/vitest/releases/tag/v5.0.3)),
**prettier 3.9.9**
([changelog](https://github.com/prettier/prettier/blob/3.9.9/CHANGELOG.md#399)),
**react-virtuoso**
([releases](https://github.com/petyosi/react-virtuoso/releases)),
**source-map-js 1.2.2**
([compare](7rulnik/source-map-js@v1.2.1...v1.2.2)),
**go-containerregistry 0.22.1**
([release](https://github.com/google/go-containerregistry/releases/tag/v0.22.1)).

## Verification
All results are on the rebased branch (base `1f05aee9`).
- **Integrity:** `npm ci` passes, and `go mod verify` passes for root
and `pkg`.
- **Type-check:** `make tsc` passes.
- **Go tests:** `make test` (root `go test ./...`, 43 packages ok) and
`cd pkg && go test ./...` both pass. The first run failed with "package
unsafe is not in std" and missing `go-build` cache files because the Go
build cache was cleaned during the run; both pass on a clean re-run.
- **Frontend tests:**
  - `packages/k8s-ui` `npm test`: 218 files, 4160 passed, 1 skipped.
  - `web` `npm run test`: 158 files, 1865 passed.
- **Lint:** `cd web && npm run lint` gives 0 errors and 444 warnings,
the same warning set as main. I compared the normalized warning lists
from a clean `npm ci` of `origin/main`.
- **Prettier:** `prettier --check` on `web/src` and
`packages/k8s-ui/src` flags 1089 files before and after, so the bump
changes no formatting.
- **Build:** `make build` passes.
- **Linux targeted test:** `go test ./internal/timeline/ ./internal/ai/`
passes in `golang:1.26` (go1.26.8, linux/arm64) against libc v1.77.1.
Those are the SQLite timeline store and the `ai-runs.db` store.
- **Binary smoke test:** I ran the built binary against a live cluster
with the Pods table at ~100 pods.
- TableVirtuoso virtualized as expected: 5182px of scroll height
rendered 29 rows, then 43 after a mid-scroll.
- Rows rendered correctly mid-list, and the console showed 0 errors and
0 warnings.
- **visual-test:** I didn't run a full `/visual-test`. The only
rendering-relevant bump is react-virtuoso, and the targeted smoke test
above covers it.

Supersedes #2000, #1998, #2001, #2004, #2003, #2002, #1999, #2015

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Dependency-only lockfile and manifest updates with no runtime code
changes; bumps are patch/minor and were screened with tests per the PR
description.
> 
> **Overview**
> This PR **batches soaked Dependabot dependency bumps** with **no
application source changes**—only `go.mod`/`go.sum`, root
`package-lock.json`, and version pins in `packages/k8s-ui/package.json`
and `web/package.json`.
> 
> **Go** updates include `modernc.org/sqlite` (v1.59.0 → v1.60.1) with
its `modernc.org/libc` transitive bump, `github.com/prometheus/common`
(v0.71.0 → v0.72.0), and `github.com/google/go-containerregistry`
(v0.22.0 → v0.22.1), plus related `go.sum` entries for sqlite/libc
toolchain deps.
> 
> **npm** updates cover `react-virtuoso` (4.18.13 → 4.18.16) in k8s-ui
and web, `typescript-eslint` / `@typescript-eslint/*` (8.70.0 → 8.71.0),
`vitest` (5.0.2 → 5.0.3) in k8s-ui, `prettier` (3.9.8 → 3.9.9), and
lockfile-only moves such as `source-map-js` 1.2.2 and vitest’s pinned
`why-is-node-running` downgrade.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
3716b5a. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
Bumps [monaco-editor](https://github.com/microsoft/monaco-editor) from 0.55.1 to 0.57.0.
- [Release notes](https://github.com/microsoft/monaco-editor/releases)
- [Changelog](https://github.com/microsoft/monaco-editor/blob/main/CHANGELOG.md)
- [Commits](microsoft/monaco-editor@v0.55.1...v0.57.0)

---
updated-dependencies:
- dependency-name: monaco-editor
  dependency-version: 0.57.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants