Skip to content

deps: batch soaked Dependabot updates (2026-09-30) - #1942

Merged
nadaverell merged 1 commit into
mainfrom
deps/dependabot-batch-2026-09-30
Sep 30, 2026
Merged

nadaverell merged 1 commit into
mainfrom
deps/dependabot-batch-2026-09-30

Conversation

@nadaverell

@nadaverell nadaverell commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

One tested batch replacing this week's soaked, low-risk Dependabot PRs. Dependency-only: no application source changes.

Screening time: 2026-09-30T08:40:02Z (re-checked 09:12Z, base 0490dd87 unchanged)
72h cutoff: published at or before 2026-09-27T08:40:02Z. Every resolved version below clears it.

Included

PR Dependency Old → New Published (UTC) Soak Risk conclusion
#1932 k8s.io/{api, apiextensions-apiserver, apimachinery, apiserver, cli-runtime, client-go, component-helpers, component-base, streaming} v0.37.0 → v0.37.1 2026-09-23 20:28–23:27 ~6.5d Negligible. Every staging repo's v0.37.0...v0.37.1 compare is a single "Update dependencies to v0.37.1 tag" commit touching only go.mod/go.sum. streaming v0.37.1 is the same commit as v0.37.0.
#1938 github.com/jackc/pgx/v5 v5.10.0 → v5.11.0 2026-09-07 23:39 ~22d Low. Used only by the Postgres timeline store through stdlib. See notes.
#1936 github.com/klauspost/compress v1.20.0 → v1.20.1 2026-09-25 08:00 ~5d Low–moderate. Encoder/decoder performance rewrites plus correctness fixes; no API or default changes. Radar uses it directly only for the HTTP gzip encoder.
#1934 modernc.org/sqlite (+ modernc.org/libc) v1.58.0 → v1.59.0 (libc v1.75.6 → v1.75.7) sqlite 2026-09-15 07:30; libc 2026-09-01 19:33 ~15d / ~29d Low. The transpiled SQLite is unchanged (3.53.4). libc uses native Go mem*/str* routines. The UDF context-pooling change doesn't apply because Radar registers no UDFs.
#1937 eslint 10.10.0 → 10.11.0 2026-09-18 20:15 ~11.5d Low. A few rule refinements, no breaking changes. Lint gives 0 errors / 441 warnings, the same as main.
#1935 vite 8.2.2 → 8.3.1 2026-09-24 12:26 ~6d Low. Moves rolldown 1.2.6 → 1.2.11, whose tree-shaking and code-splitting fixes can change bundle output, so I smoke-tested the built binary in a browser (below).
#1931 lucide-react 1.37.0 → 1.48.0 2026-09-24 05:53 ~6d Low. No exports were removed between the two tarballs (6137 → 6347). All 226 icon names Radar imports exist in 1.48.0. The k8s-ui peer range >=0.400.0 is unchanged.

Movement beyond the Dependabot PRs (reviewed, all soaked)

  • k8s alignment: root k8s.io/kubectl and k8s.io/csi-translation-lib (indirect, via ./pkg) and all of pkg/go.mod's k8s.io requirements move to v0.37.1 as well. Without this, deps(go): bump the k8s group with 7 updates #1932 would leave the graph mixing v0.37.0 and v0.37.1.
    • kubectl was published 2026-09-24 01:06Z and csi-translation-lib 2026-09-24 00:45Z. Both are go.mod-only tag bumps, like the rest of the group.
    • Module-graph-only entries k8s.io/{code-generator, kms, metrics} v0.37.1 were published 2026-09-23 21:22 / 21:45 / 23:18Z. None of them appears in go.sum.
  • npm transitives:
    • rolldown and all 15 @rolldown/binding-* 1.2.6 → 1.2.11 (2026-09-24 13:54–14:30Z)
    • @oxc-project/types 0.147.0 → 0.151.0 (2026-09-21)
    • picomatch 4.0.5 → 4.0.7 (2026-08-24)
    • Nothing else in package-lock.json changed.
  • Newer releases deliberately not picked up:
    • lucide-react 1.49.0 (2026-09-29) is inside the soak window.
    • modernc.org/sqlite v1.60.x (2026-09-28/29) is inside the window, and it pins libc v1.77.1. libc has an open stack-overflow crash against v1.77.0 (cznic/libc#60).

Held / excluded (these PRs stay open)

PR Update Decision Reason
#1933 vitest 4.1.11 → 5.0.2 (major) Hold vitest 5 requires Node ^22.12 || ^24 || >=26, but ci.yml pins Node 20 for the Frontend, k8s-ui and Settings jobs. The PR's CI only passed because npm treats the engine mismatch as a warning (EBADENGINE), which Bugbot also flagged. Follow-up: move CI (and CONTRIBUTING's "Node 20+") to Node 22 first. Note that web/ runs the hoisted vitest without declaring it.
#1930 monaco-editor 0.55.1 → 0.57.0 Exclude Needs source changes. The deep side-effect imports in packages/k8s-ui/src/components/ui/monacoRuntime.ts (esm/vs/editor/contrib/{find,folding,format,gotoError,hover,suggest}/...) no longer resolve (TS2882), which fails the Frontend, k8s-ui and Settings jobs.
#1776 modelcontextprotocol/go-sdk 1.6.1 → 1.8.0 Exclude Changes behaviour Radar relies on. TestInvestigationHandlerAnnotatesRealToolCallWithoutChangingPublicContract fails: "private mount handshake did not mark the scope connected". Radar's private-mount handling needs adapting first.
#1939 helmfile/helmfile-action v2.2.0 → v2.4.8 Exclude Breaks the Helm chart job. Since v2.3.0 the action installs Helm plugins from .tgz release assets (#648), so helm-unittest ends up installed twice ("two plugins claim the name "unittest""). It also moved to the node24 runtime (v2.4.0). Needs a ci.yml change to how helm-plugins is specified.

Radar usage and risk notes

  • pgx 5.11 (release):
    • It makes connection-string parsing match libpq exactly, which changes some edge cases: a literal + in URI query values, bad percent-encoding now errors, # is data, the last repeated parameter wins, bare IPv6 hosts need brackets, and backslashes in keyword/value strings now escape.
    • That touches user-supplied RADAR_TIMELINE_POSTGRES_DSN values with unusual encoding, which is worth a release-note line.
    • The date/time parser rewrite doesn't reach Radar data: timestamps are stored as int64 nanoseconds.
    • The new Rows.TypeMap interface method doesn't matter because Radar implements no custom pgx.Rows.
    • It also includes security hardening: startup-parameter NUL injection is rejected, DSN passwords are redacted more thoroughly, and decoders are hardened against panics.
    • The PostgreSQL integration tests skipped locally (no server). CI runs them with RADAR_REQUIRE_POSTGRES_TESTS=1 against postgres:17.
  • klauspost/compress 1.20.1 (release): used directly only by internal/server/compress.go (kgzip.NewWriterLevel); zstd reaches Radar only transitively (helm, go-containerregistry, prometheus). In the smoke test, a live /api/resources/pods response came back Content-Encoding: gzip and decoded with system gunzip to 269 pods.
  • modernc sqlite/libc (CHANGELOG): used by the SQLite timeline store and ai-runs.db. libc is exact-pinned to the version sqlite requires.
  • k8s 0.37.1 (CHANGELOG-1.37): the library code is identical. The release fixes are in binaries (DRA, kube-proxy on Windows, kubeadm).
  • vite 8.3 / rolldown (8.3.0, 8.3.1, rolldown releases):
    • Our manualChunks does its own node_modules/ matching, so vite 8.3.0's path-segment change doesn't affect it.
    • @vitejs/plugin-react 6.1.1 still satisfies its peer range, and vitest 4.1.11's vite peer covers ^8.
  • eslint 10.11 (release) and lucide-react (releases): the lucide range includes the removal of trash (Radar uses Trash2) and glyph redraws for Trash2 and Building2. That's cosmetic; tests that assert icon class names pass.

Verification

  • Integrity: go mod verify passes in both root and pkg. go.sum / pkg/go.sum were regenerated from main with a clean go mod tidy. Each changes 30 / 14 lines each way, only the modules listed above.
  • Type-check: make tsc passes.
  • Lint: cd web && npm run lint gives 0 errors and 441 warnings (the same as main).
  • Frontend tests:
    • packages/k8s-ui npm test: 209 files, 4030 passed, 1 skipped.
    • web npm run test: 151 files, 1764 passed.
  • Go tests:
    • cd pkg && go test ./... passes.
    • Root go test ./... passes except cmd/desktop. Its TestGetShellEnv and TestEnrichEnvPrecedenceAndDiagnostics hit their 5s login-shell timeout while the full parallel suite was loading the machine.
    • That flake already exists on main and doesn't involve any bumped module. Re-run on this branch with go test ./cmd/desktop/ -count=3, the tests pass, and they also pass on main.
  • Build: make build passes.
  • Binary smoke test (built binary against a live GKE cluster):
    • All 8 entry assets (index, rolldown-runtime, vendor, ui, monaco JS/CSS) returned 200.
    • The Pods table rendered with lucide icons.
    • The pod drawer's YAML → Edit loaded Monaco along with monacoRuntime, yamlMonacoRuntime, the monacoYaml.worker and editor.worker chunks, and showed the pod YAML.
    • The console showed no errors. The edit was cancelled; nothing was applied.
  • visual-test: not run as a full /visual-test. The targeted browser smoke test above covers the rendering-relevant bumps (vite/rolldown chunking, Monaco loading, lucide icons).

Supersedes #1932, #1938, #1936, #1934, #1937, #1935, #1931


Note

Low Risk
Patch dependency upgrades with no app code changes; pgx DSN parsing edge cases are the main operational note for unusual Postgres connection strings.

Overview
Dependency-only batch — no application source changes. Bumps Go and npm lockfiles after screening several Dependabot PRs.

Go: Aligns all k8s.io/* modules to v0.37.1 in the root module, ./pkg, and checksums (patch tag bumps only). Also bumps pgx v5.11.0 (Postgres timeline via RADAR_TIMELINE_POSTGRES_DSN), klauspost/compress v1.20.1 (HTTP gzip in internal/server/compress.go), and modernc.org/sqlite v1.59.0 with libc v1.75.7 (SQLite timeline / ai-runs.db).

Frontend: vite 8.3.1 (pulls rolldown 1.2.11 and related @rolldown/binding-* / @oxc-project/types transitives in package-lock.json), eslint 10.11.0, and lucide-react 1.48.0 in web/ and packages/k8s-ui.

Reviewed by Cursor Bugbot for commit 7512c17. Bugbot is set up for automated code reviews on this repo. Configure here.

Go: pgx/v5 5.11.0, klauspost/compress 1.20.1, modernc.org/sqlite 1.59.0
(libc 1.75.7), k8s.io/* 0.37.1 aligned across root and pkg modules.
npm: eslint 10.11.0, vite 8.3.1 (rolldown 1.2.11), lucide-react 1.48.0.
@nadaverell
nadaverell requested a review from hisco as a code owner September 30, 2026 09:13
@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Batch soaked Go and frontend dependency updates

⚙️ Configuration changes 🕐 20-40 Minutes

Grey Divider

AI Description

• Updates screened Go and frontend dependencies without changing application source.
• Aligns Kubernetes modules at v0.37.1 across the root and pkg Go modules.
• Retains incompatible updates for separate follow-up work.
Diagram

graph TD
  RootGo["Root Go module"] --> PkgGo["pkg Go module"] --> K8s["Kubernetes libraries"]
  RootGo --> Stores["Timeline stores"]
  RootGo --> Compression["HTTP compression"]
  Npm["Frontend manifests"] --> Build["Vite build"] --> UI["React UI"]
  Npm --> UI
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Merge dependency updates separately
  • ➕ Makes a regression easier to attribute or revert.
  • ➕ Keeps database-driver and bundler risk isolated.
  • ➖ Repeats validation across several PRs.
  • ➖ Risks temporarily mixing Kubernetes module versions.

Recommendation: The screened batch is reasonable given the reported Go tests, frontend tests, build, and browser smoke test; aligning Kubernetes versions in both Go modules is preferable to merging those bumps independently. Preserve the separate follow-ups for incompatible updates and note pgx connection-string edge cases in release notes. The supplied diff omits package-lock.json despite the PR description reporting lockfile changes, so confirm that the lockfile changes are included in the actual PR before merging.

Files changed (6) +70 / -70

Other (6) +70 / -70
go.modBump server dependencies and align Kubernetes modules +15/-15

Bump server dependencies and align Kubernetes modules

• Updates pgx/v5, klauspost/compress, and modernc.org/sqlite. Moves the root module's Kubernetes requirements to v0.37.1 and updates the indirect modernc.org/libc requirement.

go.mod

go.sumRefresh root Go module checksums +30/-30

Refresh root Go module checksums

• Replaces checksums for the Go dependency versions selected in the root module, including the Kubernetes, database, and compression updates.

go.sum

package.jsonRaise k8s-ui's lucide-react development version +1/-1

Raise k8s-ui's lucide-react development version

• Raises the lucide-react devDependency from ^1.37.0 to ^1.48.0 without changing the package's peer-dependency range.

packages/k8s-ui/package.json

go.modAlign pkg Kubernetes requirements at v0.37.1 +7/-7

Align pkg Kubernetes requirements at v0.37.1

• Updates all Kubernetes requirements declared by the separate pkg module, including kubectl and csi-translation-lib, to v0.37.1.

pkg/go.mod

go.sumRefresh pkg Kubernetes checksums +14/-14

Refresh pkg Kubernetes checksums

• Replaces checksums for the Kubernetes modules updated in pkg/go.mod.

pkg/go.sum

package.jsonRaise frontend lint, build, and icon versions +3/-3

Raise frontend lint, build, and icon versions

• Raises the declared ESLint version to ^10.11.0, Vite to ^8.3.1, and lucide-react to ^1.48.0.

web/package.json

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can route each severity your way: inline, summary, both, or drop

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant