Repository navigation
chore(deps): bump the everything-else group across 1 directory with 10 updates - #6535
dependabot[bot] wants to merge 1 commit into
Conversation
…0 updates Bumps the everything-else group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | @rdi-ui/pipeline | `0.1.35` | `0.1.41` | | [@sentry/electron](https://github.com/getsentry/sentry-electron) | `7.18.0` | `7.20.0` | | [@sentry/react](https://github.com/getsentry/sentry-javascript) | `10.73.0` | `10.75.3` | | [dompurify](https://github.com/cure53/DOMPurify) | `3.4.14` | `3.4.16` | | [jszip](https://github.com/Stuk/jszip) | `3.10.1` | `3.10.2` | | [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.87.0` | `7.89.0` | | [socket.io-client](https://github.com/socketio/socket.io) | `4.8.3` | `4.8.4` | | [csv-stringify](https://github.com/adaltas/node-csv/tree/HEAD/packages/csv-stringify) | `6.8.3` | `6.9.0` | | [moment](https://github.com/moment/moment) | `2.30.1` | `2.31.0` | | [tsx](https://github.com/privatenumber/tsx) | `4.23.13` | `4.23.15` | Updates `@rdi-ui/pipeline` from 0.1.35 to 0.1.41 Updates `@sentry/electron` from 7.18.0 to 7.20.0 - [Release notes](https://github.com/getsentry/sentry-electron/releases) - [Changelog](https://github.com/getsentry/sentry-electron/blob/master/CHANGELOG.md) - [Commits](getsentry/sentry-electron@7.18.0...7.20.0) Updates `@sentry/react` from 10.73.0 to 10.75.3 - [Release notes](https://github.com/getsentry/sentry-javascript/releases) - [Changelog](https://github.com/getsentry/sentry-javascript/blob/10.75.3/CHANGELOG.md) - [Commits](getsentry/sentry-javascript@10.73.0...10.75.3) Updates `dompurify` from 3.4.14 to 3.4.16 - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@3.4.14...3.4.16) Updates `jszip` from 3.10.1 to 3.10.2 - [Changelog](https://github.com/Stuk/jszip/blob/main/CHANGES.md) - [Commits](Stuk/jszip@v3.10.1...v3.10.2) Updates `react-hook-form` from 7.87.0 to 7.89.0 - [Release notes](https://github.com/react-hook-form/react-hook-form/releases) - [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md) - [Commits](react-hook-form/react-hook-form@v7.87.0...v7.89.0) Updates `socket.io-client` from 4.8.3 to 4.8.4 - [Release notes](https://github.com/socketio/socket.io/releases) - [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md) - [Commits](https://github.com/socketio/socket.io/compare/socket.io-client@4.8.3...socket.io-client@4.8.4) Updates `csv-stringify` from 6.8.3 to 6.9.0 - [Changelog](https://github.com/adaltas/node-csv/blob/master/packages/csv-stringify/CHANGELOG.md) - [Commits](https://github.com/adaltas/node-csv/commits/csv-stringify@6.9.0/packages/csv-stringify) Updates `moment` from 2.30.1 to 2.31.0 - [Release notes](https://github.com/moment/moment/releases) - [Changelog](https://github.com/moment/moment/blob/develop/CHANGELOG.md) - [Commits](moment/moment@2.30.1...2.31.0) Updates `tsx` from 4.23.13 to 4.23.15 - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](privatenumber/tsx@v4.23.13...v4.23.15) --- updated-dependencies: - dependency-name: "@rdi-ui/pipeline" dependency-version: 0.1.41 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: everything-else - dependency-name: "@sentry/electron" dependency-version: 7.20.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: everything-else - dependency-name: "@sentry/react" dependency-version: 10.75.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: everything-else - dependency-name: dompurify dependency-version: 3.4.16 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: everything-else - dependency-name: jszip dependency-version: 3.10.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: everything-else - dependency-name: react-hook-form dependency-version: 7.89.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: everything-else - dependency-name: socket.io-client dependency-version: 4.8.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: everything-else - dependency-name: csv-stringify dependency-version: 6.9.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: everything-else - dependency-name: moment dependency-version: 2.31.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: everything-else - dependency-name: tsx dependency-version: 4.23.15 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: everything-else ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: af75e28d17
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| "@sentry/electron": "^7.20.0", | ||
| "@sentry/react": "^10.75.3", |
There was a problem hiding this comment.
Align the Sentry core override with the upgraded SDKs
The unchanged top-level @sentry/core override still forces version 10.73.0: the new lockfile has no nested core copies, even though the upgraded Electron SDK declares an exact @sentry/core@10.75.0 dependency and the React SDK declares 10.75.3. Consequently both main and renderer Sentry initialization run the new SDK packages against an unsupported older core, making error reporting unreliable. Update, remove, or scope the override and regenerate the lockfile; the prior Sentry bump in 7ed66571 made this same override adjustment specifically to avoid this mismatch.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit af75e28. Configure here.
| "@sentry/electron": "^7.18.0", | ||
| "@sentry/react": "^10.73.0", | ||
| "@sentry/electron": "^7.20.0", | ||
| "@sentry/react": "^10.75.3", |
There was a problem hiding this comment.
Stale Sentry core pin after upgrade
Medium Severity
@sentry/react 10.75.3 and @sentry/electron 7.20.0 both require @sentry/core 10.75.x, but the npm overrides entry still forces @sentry/core 10.73.0. The lockfile therefore installs a single stale core while the Electron renderer also dual-inits @sentry/react 10.75.3 against nested 10.75.0 packages. Isolation-scope handling changed in 10.74, so crash reporting can drop events, mix scope data, or throw during capture.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit af75e28. Configure here.


Bumps the everything-else group with 10 updates in the / directory:
0.1.350.1.417.18.07.20.010.73.010.75.33.4.143.4.163.10.13.10.27.87.07.89.04.8.34.8.46.8.36.9.02.30.12.31.04.23.134.23.15Updates
@rdi-ui/pipelinefrom 0.1.35 to 0.1.41Updates
@sentry/electronfrom 7.18.0 to 7.20.0Release notes
Sourced from @sentry/electron's releases.
Changelog
Sourced from @sentry/electron's changelog.
Commits
53df4a7release: 7.20.08ef1411feat: Return the real send result for renderersendFeedback(#1433)9b91a80test: New Electron versions (#1430)88fcf00fix: Honourenabled: falsefor envelopes forwarded from renderers and utili...925accffeat: Update Sentry SDKs to v10.75.0 (#1431)1dcbddeMerge remote-tracking branch 'remotes/origin/release/7.19.0'd604af4release: 7.19.087dfc97test: New Electron versions (#1425)fdd0a64build(deps-dev): Bump vitest from 4.1.0 to 4.1.11 (#1427)02d8e99feat: Update Sentry SDKs to v10.74.0 (#1426)Updates
@sentry/reactfrom 10.73.0 to 10.75.3Release notes
Sourced from @sentry/react's releases.
... (truncated)
Changelog
Sourced from @sentry/react's changelog.
... (truncated)
Commits
3b282c1release: 10.75.3b5ea330meta(changelog): Update changelog for 10.75.3 (#24649)533a6fachore(v10/bundler-plugins): move traces sample rate from 1.0 to 0.3 (#24646)4e91ce5chore(v10/publish): Tag all packages as v10 (#24619)f01ca30fix(v10/tanstackstart-react): Reject non-POST requests to the managed tunnel ...79e6e95Merge remote-tracking branch 'remotes/origin/release/10.75.2' into v10faeac9arelease: 10.75.27175b19meta(changelog): Update changelog for 10.75.2 (#24585)8f5dc60fix(v10/cloudflare): Enforce flush timeout across Workflow lifecycle (#24582)44506dffix(v10/node): Stop leaking unhandled rejections on aborted Vercel AI streams...Updates
dompurifyfrom 3.4.14 to 3.4.16Release notes
Sourced from dompurify's releases.
Commits
b9b9d80release: 3.4.16 (#1636)1d7460crelease: 3.4.15 (#1609)Updates
jszipfrom 3.10.1 to 3.10.2Changelog
Sourced from jszip's changelog.
Commits
020fa33Release preparation for 3.10.2 (#974)d38fda5Fix cross-realm binary type detection in getTypeOf (#578)e682f9aFix grunt build rebundling existing dist via browser field (#971)5adef36Add missing types for JSZip.defaults (#927)41a1342Fix blob support in Node.js 18 and up (#955)643714aMove all continuous integration to GitHub Actions (#942)418c11fUpgrade Playwright to the latest version (#940)2ceb998Create FUNDING.ymlMaintainer changes
This version was pushed to npm by jkoops, a new releaser for jszip since your current version.
Updates
react-hook-formfrom 7.87.0 to 7.89.0Release notes
Sourced from react-hook-form's releases.
... (truncated)
Changelog
Sourced from react-hook-form's changelog.
... (truncated)
Commits
4722d227.89.072a4c98👟 chore: correct form state select option (#13784)14c7bec🕵🏻♂️ chore: remove duplicate default value field (#13783)d9cab62🤖 chore: add optional@types/reactpeer dependency (#13781)c12546c🐞 fix(validateField): skip refs without setCustomValidity under native valida...5fd9ef6🐞 fix(validate): run the latest form level validate function (#13777)7893230🐞 fix(useFieldArray): improve touched fields handling and add tests (#13776)ad8abf6🐴 cancel pending delayError timers for nested paths (#13775)eb159da🐞 fix(getValues): extract only the marked entries of a field array (#13773)4647014🐞 fix: re-index field array touched state when it is not subscribed (#13772)Updates
socket.io-clientfrom 4.8.3 to 4.8.4Release notes
Sourced from socket.io-client's releases.
Commits
11a6f56chore(release): socket.io-client@4.8.400e4e73chore(release): engine.io-client@6.6.7e387ab1chore: use@rollup/plugin-terserinstead of rollup-plugin-terser9738333chore(release): engine.io@6.6.11fc9dd90docs(eio): rework READMEda008a5fix(eio): refresh ping timeout on incoming packets3df3fedfix(eio-client): restore default transport resolutionaaf2af3test: upgrade WebdriverIO to v9b5da079refactor(sio): simplify packet handling switch45873cadocs(protocol): clarify namespace comma restriction for built-in parser (#5545)Updates
csv-stringifyfrom 6.8.3 to 6.9.0Changelog
Sourced from csv-stringify's changelog.
Commits
594c646chore(release): publish9f04145build: latest dependenciesd64d410fix(csv-stringify): quote fields containing a carriage return (#485)963388dfeat(csv-stringify): expose csv error and normalize_options041defffix(csv-stringify): do not alter the source record when columns is set (#504)a38ef06fix(csv-stringify): preserve header cast context when eof is false (#505)8d4173dbuild: latest dev dependenciesc8caa1cbuild: generate latest dist3433750test: eslint format6c45c9bbuild: remove npx usage in package scriptsUpdates
momentfrom 2.30.1 to 2.31.0Release notes
Sourced from moment's releases.
Changelog
Sourced from moment's changelog.
Commits
15b45d4[pkg] Build 2.31.0 (#6452)631cd81[pkg] Update changelog for upcoming release (#6394)6caff9eMerge commit from fork710703b[feature] Add internal date-default hook for Moment Timezone (#6451)863ed94[bugfix] Add stack traces to conditional deprecation warnings (#6450)2c7abe1[bugfix] Apply postformat to locale relative time methods (#6448)9c45ac3[bugfix] Include metadata in all-locales bundle (#6447)f6eefc5[bugfix] Validate timezone offset range (#6446)136b441[bugfix] Avoid Object.assign in duration.humanize (#6443)0d10504[bugfix] Fix locale('proto') corrupting the global locale (#6442)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for moment since your current version.
Updates
tsxfrom 4.23.13 to 4.23.15Release notes
Sourced from tsx's releases.
Commits
ca66105test: fix drive-less file URLs in ESM resolver fixtures2da3407fix: expose require.cache and require.extensions to tsImport CommonJS modules38e1588fix: exclude bare builtins from namespace inheritance562c434fix: make namespaced register() overloads portable for declaration emitedfb1f0build: upgrade pkgroll and externalize CJS loader reference70e7828test: upgrade tinyspy for disposable API9ed2022ci: avoid duplicate release notifications872e77frefactor: use disposables for cleanup6e5236bfix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...Most Recent Ignore Conditions Applied to This Pull Request
You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsNote
Medium Risk
Touches Sentry, HTML sanitization, and the RDI pipeline package with new editor/schema dependencies; mostly routine bumps but worth smoke-testing RDI editors, markdown rendering, realtime sockets, and Electron crash reporting.
Overview
Bumps 10 direct dependencies in
package.jsonand refreshespackage-lock.json; there is no application source change.The largest product-facing shift is
@rdi-ui/pipeline0.1.35→0.1.41, which pulls in CodeMirror lint/autocomplete andcodemirror-json-schema(plusajv) for schema-aware editing in the RDI pipeline UI.@sentry/electron(7.18.0→7.20.0) and@sentry/react(10.73.0→10.75.3) update error reporting for the desktop shell and React UI.dompurify(3.4.14→3.4.16) and devmoment(2.30.1→2.31.0, includes CVE-2026-17495) are security-oriented patches. Remaining bumps are patch/minor:jszip,socket.io-client,react-hook-form,csv-stringify, andtsx.Reviewed by Cursor Bugbot for commit af75e28. Bugbot is set up for automated code reviews on this repo. Configure here.