Skip to content

deps: batch soaked Dependabot updates (2026-10-07) - #2017

Merged
nadaverell merged 1 commit into
mainfrom
deps/dependabot-batch-2026-10-07
Oct 7, 2026
Merged

nadaverell merged 1 commit into
mainfrom
deps/dependabot-batch-2026-10-07

Conversation

@nadaverell

@nadaverell nadaverell commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

One tested batch replacing this week's soaked, low-risk Dependabot PRs. Dependency-only: no application source changes.

Screening time: 2026-10-07T08:38:20Z (reconciled again at 09:00Z; rebased onto 1f05aee9, which picked up #2015)
72h cutoff: published at or before 2026-10-04T08:38:20Z. Every resolved version below clears it. The npm lockfile was regenerated with npm install --package-lock-only --before=2026-10-04T08:38:20Z, so the resolver could not float past the cutoff.

Included

PR Dependency Old → New Published (UTC) Soak Risk conclusion
#2000 modernc.org/sqlite (+ modernc.org/libc) v1.59.0 → v1.60.1 (libc v1.75.7 → v1.77.1) sqlite 2026-09-29 08:41; libc 2026-09-21 23:07 ~8d / ~15.4d Low–moderate. SQLite stays 3.53.4. The libc range is substantial on Linux (see notes), so I ran the sqlite-backed stores' tests in a Linux container.
#1998 github.com/prometheus/common v0.71.0 → v0.72.0 2026-09-28 08:33 ~9d Low. The only change on Radar's path is a stricter text parser (see notes). Its go 1.26 requirement matches ours.
#2001 github.com/google/go-containerregistry v0.22.0 → v0.22.1 2026-09-04 00:07 ~33d Low. SSRF-guard hardening, an authn fix that stops empty credentials overwriting AuthConfig.Auth, and sha512 digest support. Radar uses authn, name, remote, v1/google for image inspection.
#2004 react-virtuoso 4.18.13 → 4.18.16 2026-09-29 16:03 ~7.7d Low. 4.18.14 adds custom ul List wrappers. 4.18.15 fixes initialItemCount clamping, which Radar doesn't use. 4.18.16 stops TableVirtuoso leaking skipAnimationFrameInResizeObserver onto the DOM; Radar doesn't pass that prop. I smoke-tested the binary in a browser anyway.
#2003 typescript-eslint (+ 10 @typescript-eslint/*) 8.70.0 → 8.71.0 2026-09-28 17:12 ~8.6d Low. Adds a new rule that's opt-in and not enabled here, plus rule fixes. The set of 444 lint warnings is identical before and after (0 errors). 8.71.1 (2026-10-05) is too fresh and was deliberately not picked up.
#2002 vitest (+ @vitest/mocker, @vitest/spy) 5.0.2 → 5.0.3 2026-09-30 11:30 ~6.9d Low. Bug fixes in repeats/retry, cache revalidation, jsdom Blob and the pool. Both test suites pass.
#1999 prettier 3.9.8 → 3.9.9 2026-09-23 06:31 ~14d Negligible. A Markdown $-as-math fix; Radar formats only .ts/.tsx. prettier --check reports the same 1089 files before and after.
#2015 source-map-js 1.2.1 → 1.2.2 2026-09-30 14:08 ~6.8d Low. Build/test-time only (postcss, Tailwind, jsdom via css-tree). Fixes a DoS from malicious indexed source maps (CVE-2026-93749) and a crash under a no-unsafe-eval CSP.

Movement beyond the Dependabot PRs (reviewed, all soaked)

  • Go: modernc.org/libc v1.75.7 → v1.77.1 (2026-09-21), the version sqlite pins.
    • Three go.sum entries also changed, golang.org/x/tools v0.50.0 (2026-09-08), modernc.org/cc/v4 v4.29.7 (2026-09-12) and modernc.org/ccgo/v4 v4.36.1 (2026-09-21). go mod why shows each one is reached only through go-sdk/mcp.test or libc.test, never a Radar binary.
    • pkg/go.mod is untouched.
  • npm:
    • ignore 7.0.9 → 7.0.12 (2026-10-02, ~4.8d), nested under @typescript-eslint/eslint-plugin. These are gitignore-semantics fixes plus linear-time perf work (no release notes, so I reviewed the compare). It's lint-time only, and the lint output is identical.
    • why-is-node-running 3.2.2 → 3.2.1, a downgrade that vitest 5.0.3 pins on purpose (vitest#11403, avoids ERR_PNPM_TRUST_DOWNGRADE). 3.2.1 was published 2024-10-29.
    • Nothing else in package-lock.json changed.
  • Too-fresh versions deliberately excluded by the --before cutoff:
    • typescript-eslint / @typescript-eslint/* 8.71.1 (2026-10-05 17:08Z).
    • magic-string 1.4.3 (2026-10-05 04:52Z), which a plain refresh would have pulled under @vitest/mocker. It stays at 1.4.2, inside mocker's ^1.2.3.

Held / excluded (these PRs stay open)

PR Update Decision Reason
#1776 modelcontextprotocol/go-sdk 1.6.1 → 1.8.0 Exclude I re-tested on today's main and it still fails TestInvestigationHandlerAnnotatesRealToolCallWithoutChangingPublicContract ("private mount handshake did not mark the scope connected"). Radar's private-mount handling needs adapting first; that's a source change.
#1930 monaco-editor 0.55.1 → 0.57.0 Exclude Unchanged from last week. The deep side-effect imports in packages/k8s-ui/src/components/ui/monacoRuntime.ts don't resolve under 0.57 (TS2882), and that file hasn't changed since. The PR's CI still fails the Frontend, k8s-ui and Settings jobs. Needs a source change.
#1939 helmfile/helmfile-action v2.2.0 → v2.4.8 Exclude Unchanged from last week. Since v2.3.0 the action installs helm-unittest twice (#648), so the Helm chart job fails. Needs a ci.yml change to how helm-plugins is specified.

Radar usage and risk notes

  • modernc sqlite 1.60 / libc 1.77.1 (sqlite CHANGELOG, libc compare):
    • Radar imports only the database/sql driver: the SQLite timeline store and ai-runs.db. It uses no vfs, no pcache, none of the removed lib constants and no _pragma. StrictPragmas is opt-in.
    • The 1.60.0 change that turns a WAL -shm read fault into SQLITE_IOERR_IN_PAGE instead of a crash is a strict improvement.
    • The libc range includes musl atomics translated to Go, stdio locking fixes, and setenv/putenv mirrored into the Go environment on musl. That's why I ran the targeted Linux run below.
    • Last week's blocker is resolved. libc v1.77.0's recursive Xnanf stack overflow (cznic/libc#60) caused us to hold sqlite 1.60. v1.77.0 is now retracted, and v1.77.1 adds the fix and a TestNaN regression test.
    • The issue is still open upstream, so I checked directly: in v1.77.1, Linux Xnanf returns X__builtin_nanf (math.NaN()), and the issue's own reproducer prints NaN NaN NaN on linux/arm64 with no stack overflow.
  • prometheus/common 0.72 (release):
    • Radar uses expfmt.NewTextParser(model.LegacyValidation) to parse apiserver metrics in internal/upgrade/collectors_live.go, and model in the MCP Prometheus tool.
    • The only text-parser change (#988) now rejects a nameless {} sample that follows metric metadata. Kubernetes apiserver exposition never emits one.
    • The rest is OpenMetrics 2.0 encoding, which is experimental and unused here, plus format-constant docs (#992, backward compatible).
  • typescript-eslint 8.71.0 (release), vitest 5.0.3 (release), prettier 3.9.9 (changelog), react-virtuoso (releases), source-map-js 1.2.2 (compare), go-containerregistry 0.22.1 (release).

Verification

All results are on the rebased branch (base 1f05aee9).

  • Integrity: npm ci passes, and go mod verify passes for root and pkg.
  • Type-check: make tsc passes.
  • Go tests: make test (root go test ./..., 43 packages ok) and cd pkg && go test ./... both pass. The first run failed with "package unsafe is not in std" and missing go-build cache files because the Go build cache was cleaned during the run; both pass on a clean re-run.
  • Frontend tests:
    • packages/k8s-ui npm test: 218 files, 4160 passed, 1 skipped.
    • web npm run test: 158 files, 1865 passed.
  • Lint: cd web && npm run lint gives 0 errors and 444 warnings, the same warning set as main. I compared the normalized warning lists from a clean npm ci of origin/main.
  • Prettier: prettier --check on web/src and packages/k8s-ui/src flags 1089 files before and after, so the bump changes no formatting.
  • Build: make build passes.
  • Linux targeted test: go test ./internal/timeline/ ./internal/ai/ passes in golang:1.26 (go1.26.8, linux/arm64) against libc v1.77.1. Those are the SQLite timeline store and the ai-runs.db store.
  • Binary smoke test: I ran the built binary against a live cluster with the Pods table at ~100 pods.
    • TableVirtuoso virtualized as expected: 5182px of scroll height rendered 29 rows, then 43 after a mid-scroll.
    • Rows rendered correctly mid-list, and the console showed 0 errors and 0 warnings.
  • visual-test: I didn't run a full /visual-test. The only rendering-relevant bump is react-virtuoso, and the targeted smoke test above covers it.

Supersedes #2000, #1998, #2001, #2004, #2003, #2002, #1999, #2015


Note

Low Risk
Dependency-only lockfile and manifest updates with no runtime code changes; bumps are patch/minor and were screened with tests per the PR description.

Overview
This PR batches soaked Dependabot dependency bumps with no application source changes—only go.mod/go.sum, root package-lock.json, and version pins in packages/k8s-ui/package.json and web/package.json.

Go updates include modernc.org/sqlite (v1.59.0 → v1.60.1) with its modernc.org/libc transitive bump, github.com/prometheus/common (v0.71.0 → v0.72.0), and github.com/google/go-containerregistry (v0.22.0 → v0.22.1), plus related go.sum entries for sqlite/libc toolchain deps.

npm updates cover react-virtuoso (4.18.13 → 4.18.16) in k8s-ui and web, typescript-eslint / @typescript-eslint/* (8.70.0 → 8.71.0), vitest (5.0.2 → 5.0.3) in k8s-ui, prettier (3.9.8 → 3.9.9), and lockfile-only moves such as source-map-js 1.2.2 and vitest’s pinned why-is-node-running downgrade.

Reviewed by Cursor Bugbot for commit 3716b5a. Bugbot is set up for automated code reviews on this repo. Configure here.

Bump modernc.org/sqlite v1.60.1 (libc v1.77.1), prometheus/common v0.72.0,
go-containerregistry v0.22.1, react-virtuoso 4.18.16, typescript-eslint
8.71.0, vitest 5.0.3, prettier 3.9.9 and source-map-js 1.2.2. Every resolved
version was published at least 72h before screening (cutoff
2026-10-04T08:38:20Z); the npm lockfile was resolved with --before.
@nadaverell
nadaverell requested a review from hisco as a code owner October 7, 2026 09:09
@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Batch soaked Go and frontend dependency updates

⚙️ Configuration changes 🕐 10-20 Minutes

Grey Divider

AI Description

• Bump three Go dependencies, including SQLite and its libc dependency, after the stated soak
 period.
• Update frontend virtualization and development-tool version ranges without changing application
 source.
• Batch previously separate updates while leaving source-dependent upgrades excluded.
Diagram

graph TD
  Go["Go module"] --> SQLite["SQLite stack"] --> Stores["Database stores"]
  Go --> Integrations["Image and metrics"]
  Npm["npm workspace"] --> UI["k8s-ui package"] --> Web["Web app"] --> Tools["Frontend tooling"]
  Npm --> Web
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Merge Dependabot PRs separately
  • ➕ Isolates regressions and makes individual updates easier to revert.
  • ➖ Repeats integration testing and may produce multiple intermediate dependency states.

Recommendation: The batch is reasonable for screened, soaked updates given the reported Go, frontend, build, and targeted smoke tests. Review the resolved dependency graph as a unit; the supplied diff does not show an npm lockfile change, despite the PR description discussing a regenerated lockfile.

Files changed (4) +23 / -23

Other (4) +23 / -23
go.modBump image, metrics, and SQLite modules +4/-4

Bump image, metrics, and SQLite modules

• Raises go-containerregistry to v0.22.1, prometheus/common to v0.72.0, and modernc.org/sqlite to v1.60.1. Also raises SQLite's indirect modernc.org/libc dependency to v1.77.1.

go.mod

go.sumRefresh checksums for resolved Go modules +14/-14

Refresh checksums for resolved Go modules

• Replaces checksums for the updated direct modules and libc. It also records newer golang.org/x/tools, modernc.org/cc/v4, and modernc.org/ccgo/v4 versions.

go.sum

package.jsonRaise shared UI virtualization and test-tool ranges +2/-2

Raise shared UI virtualization and test-tool ranges

• Raises react-virtuoso from ^4.18.13 to ^4.18.16 and Vitest from ^5.0.2 to ^5.0.3 for the shared UI package.

packages/k8s-ui/package.json

package.jsonRaise web virtualization and formatting-tool ranges +3/-3

Raise web virtualization and formatting-tool ranges

• Raises react-virtuoso to ^4.18.16, Prettier to ^3.9.9, and typescript-eslint to ^8.71.0.

web/package.json

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider

Great, no issues found!

Qodo reviewed your code and found no material issues that require review

Grey Divider

Tip of the day
💡 Did you know, you can route each severity your way: inline, summary, both, or drop

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant