Skip to content

chore(deps): bump the react group across 1 directory with 4 updates - #297

Draft
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/react-f01e79c410
Draft

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/react-f01e79c410

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the react group with 4 updates in the / directory: react, @types/react, react-dom and @types/react-dom.

Updates react from 18.3.1 to 19.2.8

Release notes

Sourced from react's releases.

19.2.8 (July 21st, 2026)

React Server Components

19.2.7 (June 1st, 2026)

React Server Components

19.2.6 (May 6th, 2026)

React Server Components

19.2.5 (April 8th, 2026)

React Server Components

19.2.4 (January 26th, 2026)

React Server Components

19.2.3 (December 11th, 2025)

React Server Components

19.2.2 (December 11th, 2025)

React Server Components

19.2.1 (December 3rd, 2025)

React Server Components

19.2.0 (Oct 1, 2025)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.2 release post for more information.

New React Features

... (truncated)

Changelog

Sourced from react's changelog.

19.3.0 (September 9, 2026)

New React Features

New React DOM Features

  • browser(): a new react-dom API that returns a usable which errors during server rendering and resolves in the browser. use(browser()) inside a <Suspense> boundary marks a subtree as browser-only without reporting a recoverable error (@​gnoff: #37143, #37241)
    • Added an onBrowserBailout option to the react-dom/server APIs to observe when a subtree defers to the browser (@​gnoff #37193)

Notable changes

All Changes

React

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for react since your current version.


Updates @types/react from 18.3.18 to 19.2.18

Commits

Updates react-dom from 18.3.1 to 19.2.8

Release notes

Sourced from react-dom's releases.

19.2.8 (July 21st, 2026)

React Server Components

19.2.7 (June 1st, 2026)

React Server Components

19.2.6 (May 6th, 2026)

React Server Components

19.2.5 (April 8th, 2026)

React Server Components

19.2.4 (January 26th, 2026)

React Server Components

19.2.3 (December 11th, 2025)

React Server Components

19.2.2 (December 11th, 2025)

React Server Components

19.2.1 (December 3rd, 2025)

React Server Components

19.2.0 (Oct 1, 2025)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.2 release post for more information.

New React Features

... (truncated)

Changelog

Sourced from react-dom's changelog.

19.3.0 (September 9, 2026)

New React Features

New React DOM Features

  • browser(): a new react-dom API that returns a usable which errors during server rendering and resolves in the browser. use(browser()) inside a <Suspense> boundary marks a subtree as browser-only without reporting a recoverable error (@​gnoff: #37143, #37241)
    • Added an onBrowserBailout option to the react-dom/server APIs to observe when a subtree defers to the browser (@​gnoff #37193)

Notable changes

All Changes

React

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for react-dom since your current version.


Updates @types/react-dom from 18.3.5 to 19.2.5

Commits

Updates @types/react from 18.3.18 to 19.3.0

Commits

Updates @types/react-dom from 18.3.5 to 19.2.5

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 25, 2026
@dependabot dependabot Bot changed the title chore(deps): bump the react group with 4 updates chore(deps): bump the react group across 1 directory with 4 updates Aug 26, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/react-f01e79c410 branch from d339591 to 0aef3b5 Compare August 26, 2026 05:14
@shinagawa-web

shinagawa-web commented Aug 31, 2026 •

Copy link
Copy Markdown
Collaborator

@claude
以下の SKILL に従ってライブラリアップデートをレビューしてください。
https://raw.githubusercontent.com/shokai/agent-skills/refs/heads/main/plugins/library-update-review/skills/library-update-review/SKILL.md

【追加観点: ランタイム default 挙動の変化】

major version では API signature が変わらなくても、feature flag のデフォルト反転や内部動作の切替でランタイム挙動が変わることがあります。SKILL Section 6-7 の「API 仕様変更」だけでは補足漏れが起きるので、以下を明示的に確認してレポートに含めてください。

  1. release note / migration guide から「default が変わる挙動」を 1 つずつ列挙する

  2. 各 default 変化について、旧 default に依存するコードパターンを定義する。「◯◯を使っている箇所」のような曖昧な表現ではなく、以下の 3 要素を含むgrep 可能なパターンとして書くこと:

  • API / 設定 / 型の名前 (例: 関数名、prop 名、config key)
  • 使われ方の具体的な形 (例: 親子関係、複数機能の組み合わせ、渡す引数の形)
  • 検索に使うキーワードまたは正規表現
  1. 定義したパターンで codebase 全体を grep し、ヒットを列挙して各件について「旧挙動に依存しているか / 修正が必要か」を判断する

  2. 「flag が未設定 = 暗黙に旧 default に依存していた」箇所も網羅する。diff で flag が削除された箇所の safety だけを見るのは非対称チェックであり、実際に #9194 (react-router v6 → v7) で回帰を見逃した実例です:

  • 検証したこと: 明示的に flag を設定していた 1 箇所からの削除の妥当性
  • 見逃したこと: flag を設定せず暗黙の旧 default に依存していた複数箇所

@claude

claude Bot commented Aug 31, 2026 •

Copy link
Copy Markdown

Claude finished @shinagawa-web's task in 3m 56s —— View job


ライブラリアップデートレビュー: react 18.3.1 → 19.2.8 (react group)

  • SKILL ドキュメントを取得
  • PR の diff を確認
  • 変更対象パッケージの利用箇所を調査
  • React 19 の破壊的変更・default 挙動変化を列挙
  • 旧 default に依存するコードパターンを定義して grep
  • 暗黙的な旧 default 依存箇所も網羅的に確認
  • レビューレポートを投稿

1. 変更サマリ (SKILL §5-6)

Direct dependency 更新 (semver major):

Package Before After 影響 workspace
react ^18.3.1 / ^18.0.0 ^19.2.8 examples/vite-react-openapi, pkgs/docs
react-dom ^18.3.1 / ^18.0.0 ^19.2.8 同上
@types/react ^18.3.18 ^19.2.17 (+transitive 19.2.18) examples/vite-react-openapi
@types/react-dom ^18.3.5 ^19.2.3 examples/vite-react-openapi

18.3.1 → 19.2.8 の間には React 19.0 メジャー と 19.1 / 19.2 マイナーが含まれ、複数のruntime default 挙動反転があるため以下で網羅確認しました。

2. Peer dependency 互換性チェック (package-lock 実測)

Package 宣言 peer React 19 対応
swagger-ui-react@5.32.14 react: ">=16.8.0 <20" ✅ 範囲内
@docusaurus/core@3.10.2 react: "^18.0.0 || ^19.0.0" ✅ 明示対応
@mdx-js/react@3.1.0 react: ">=16" ✅
prism-react-renderer@2.4.1 react: ">=16.0.0" ✅
@vitejs/plugin-react@6.0.2 (vite 8 系) ✅ React 19 サポート済
eslint-plugin-react-hooks@7.1.1 (eslint 9+) ✅

Peer 側での破壊はありません。

3. Runtime default 挙動反転チェック (追加観点)

release note / 19.0 upgrade guide (react.dev/blog/2024/12/05/react-19-upgrade-guide) から default が変わる挙動 を列挙し、それぞれ grep 可能なパターンで codebase を走査しました。

# Default 変化 grep パターン (旧 default 依存) ヒット 判定
D1 Legacy render / hydrate / findDOMNode / unmountComponentAtNode 全廃 (createRoot/hydrateRoot へ) ReactDOM\.(render|hydrate|findDOMNode|unmountComponentAtNode) 0 ✅ 影響なし (main.tsx は既に createRoot)
D2 Legacy Context API (contextTypes / getChildContext) 全廃 contextTypes\b|getChildContext\b 0 ✅
D3 String refs (ref="foo") 全廃 JSX 属性 ref=["'] 0 (<link href=…> の誤ヒットのみ) ✅
D4 function component の defaultProps サポート除去 (旧 default: props 展開時に補完) \.defaultProps\s*= 0 ✅
D5 propTypes runtime 検証除去 (旧 default: import PropTypes して検証) \.propTypes\s*=|from ['"]prop-types['"] 0 ✅
D6 JSX グローバル namespace 廃止 (旧 default: @types/react@18 は declare global { namespace JSX {...} } を提供、19 は React.JSX にネスト) \bJSX\.(Element|IntrinsicElements|IntrinsicAttributes)\b 3 件 ⚠️ 要修正 (下記)
D7 useRef() 引数省略呼び出し不可 (旧 default: undefined 補完) useRef\(\s*\) 0 ✅
D8 <Context.Provider> は非推奨で <Context> 直接使用が新 default (旧コードは動くが警告) \.Provider\b in <X.Provider> JSX 0 ✅
D9 forwardRef 非推奨・ref が普通の prop 化 (旧 default: forwardRef 必須) forwardRef\b 0 ✅
D10 React.FC 実装 children 型が既に消えた (18 で消えたが再確認) React\.FC\b|React\.FunctionComponent 0 ✅
D11 react-dom/test-utils.act 削除 → react からの act へ test-utils|\bact\( 0 ✅
D12 Suspense sibling reveal 挙動変更 (throttle/兄弟の露出順序) Suspense\b|useDeferredValue|useTransition 0 ✅
D13 createRoot の onRecoverableError 既定出力変更 (エラーが console.error に自動出力されない場合あり) createRoot\( 直後に options 引数なし 1 件 (examples/vite-react-openapi/src/main.tsx:6) ⚠️ 影響軽微 (下記)
D14 UMD build 撤廃 (旧 default: <script src="…/umd/react…">) react\/umd|react-dom\/umd 0 ✅
D15 Custom element 属性/プロパティ振り分け仕様変更 (旧 default: 未知 prop は attribute にフォールバック) JSX に - を含むタグ名 <[a-z]+-[a-z]+ 0 (site 内では未使用) ✅
D16 Error boundary 未捕捉時の console.error 動作変更 (onUncaughtError 未指定時のデフォルト) ErrorBoundary|componentDidCatch|onError= 0 ✅
D17 JSX 変換は "react-jsx" 前提 (旧 default: "jsx": "react") tsconfig "jsx" examples/vite-react-openapi/tsconfig.app.json:16 は "react-jsx" / pkgs/docs は @docusaurus/tsconfig (react-jsx) ✅

⚠️ D6 — 唯一の明確な破壊

@types/react@19 は グローバル JSX namespace の宣言を削除 しました (19 upgrade guide "The JSX namespace is now local" 参照)。18 系では declare global { namespace JSX {...} } によりインポートなしで JSX.Element が使えたのが、19 では React.JSX.Element または import { JSX } from "react" が必要です。まさに追加観点で指摘された「flag が未設定 = 暗黙に旧 default に依存」パターンで、pkgs/docs は @types/react を明示していないのに以下 3 箇所で暗黙依存しています:

  • pkgs/docs/src/pages/index.tsx:32 — function Home(): JSX.Element {
  • pkgs/docs/src/components/HomepageFeatures/index.tsx:11 — description: JSX.Element;
  • pkgs/docs/src/components/HomepageFeatures/index.tsx:64 — function HomepageFeatures(): JSX.Element {

pkgs/docs の typecheck script は tsc を直接実行するため、Docusaurus 3.10 が pull-in する @types/react@19 によって TS2503: Cannot find namespace 'JSX' (もしくは TS2694) が発生する可能性が高いです。Docusaurus 公式の React 19 移行ガイド (Docusaurus v3 メジャーアップグレード資料) でも同 issue に触れ、JSX.Element を ReactNode に置換することが推奨されています。

推奨修正:

// pkgs/docs/src/pages/index.tsx
import type { ReactNode } from "react";
export default function Home(): ReactNode { ... }

// pkgs/docs/src/components/HomepageFeatures/index.tsx
import type { ReactNode } from "react";
type FeatureItem = {
  title: string;
  Svg: React.ComponentType<React.ComponentProps<"svg">>;
  description: ReactNode;
};
export default function HomepageFeatures(): ReactNode { ... }

Fix this →

⚠️ D13 — 影響軽微だが観察対象

examples/vite-react-openapi/src/main.tsx:6 の createRoot(...) は options なし呼び出しなので、React 19 で新設された onRecoverableError / onCaughtError / onUncaughtError は既定の console.error 動作を継承します。API signature は変わらないのでそのまま動作しますが、hydration 系エラーのフォーマットが変わり、内部で console.error を監視して開発体験を作っている場合は差分に注意。本サンプルは単純な <SwaggerUI> のマウントで観測点なし、修正不要です。

4. Docusaurus 3.10.2 側の追加チェック

  • @docusaurus/core@3.10.2 の peer には react: "^18.0.0 || ^19.0.0" が明記されており、Docusaurus は 3.9 以降 React 19 対応が入っています。
  • pkgs/docs/tsconfig.json は @docusaurus/tsconfig を extends。3.10 の @docusaurus/tsconfig は "jsx": "react-jsx" を提供するため D17 は問題なし。
  • Docusaurus は Webpack + Babel でビルドし tsc は typecheck のみに使うので、ランタイム影響は D6 型エラーのみ。ただし typecheck が CI に含まれていれば失敗します。

5. @types/react バージョン不整合 (SKILL §7-2)

PR 説明では @types/react が 19.2.17 と 19.2.18 の 2 つ、@types/react-dom が 19.2.3 が 2 度並んでおり、workspace ごとに resolved が分かれています:

  • examples/vite-react-openapi の direct devDep: @types/react@^19.2.17, @types/react-dom@^19.2.3
  • pkgs/docs 側は direct 宣言なし → @docusaurus/module-type-aliases 経由の transitive
  • root package.json への影響なし

同 major (19.2.x) 系で吸収されるので互換性リスクはなし。ただし将来的に root で明示 pin するか、pkgs/docs に @types/react@^19 を direct 追加すると duplicate ツリー抑制に有効です (今回の PR での必須事項ではない)。

6. 総合判定

項目 判定
Peer deps 全体互換 ✅
Runtime API 削除の影響 ✅ なし
Runtime default 反転の影響 ⚠️ 1 件のみ (D6: JSX.Element 3 箇所)
version consistency ✅ (19.2.x で揃う)
CI 影響 ⚠️ pkgs/docs の typecheck が壊れる可能性

マージ前対応推奨: 上記 D6 の 3 箇所を ReactNode に置換。examples/vite-react-openapi 側は既に React 19 互換のコードのみで、無修正で動作します。

その他 D1〜D17 のうち D6/D13 以外は codebase に一切ヒットなく、旧 default に暗黙依存している箇所はありません。
· Branch: dependabot/npm_and_yarn/react-f01e79c410

@shinagawa-web

Copy link
Copy Markdown
Collaborator

⚠️ examples/vite-react-openapi が実際に動きません(ローカル再現済み)

このPRを取り込んでローカルで examples/vite-react-openapi を起動すると、画面が真っ白になり以下のエラーが出ます。

Warning: Invalid hook call. Hooks can only be called inside of the body of a function component. ...
Uncaught TypeError: Cannot read properties of null (reading 'useState')
    at useState (swagger-ui-react.js:966:30)
    at SwaggerUI (swagger-ui-react.js:100921:56)

再現手順

npm install
npm run ex:express:zod:openapi -w examples/misc   # localhost:3000
npm run build -w pkgs/typed-api-spec
npm run dev -w examples/vite-react-openapi        # localhost:5173

localhost:5173 を開くと上記エラーで <SwaggerUI> が描画されません。

原因

swagger-ui-react 自体の peerDependencies は react: ">=16.8.0 <20" で React 19 に対応しているように見えますが、内部で固定バージョンとして持っている依存の一部が React 19 に未対応のままです。今回のPRが実際に固定するバージョンで確認しました。

依存 pin されているバージョン peer react 状態
react-copy-to-clipboard 5.1.1 >=15.3.0(上限なし) ✅ 対応済み
react-debounce-input =3.3.0 ^15.3.0 || 16 || 17 || 18 ❌ 未対応。しかもこのパッケージの最新版も 3.3.0 で、upstream側がReact19対応を出す見込みが薄い
react-inspector ^6.0.1 ^16.8.4 || ^17.0.0 || ^18.0.0 ❌ 未対応(ただし react-inspector 自体の最新版(9.0.0)はReact19対応済み。swagger-ui-react側の依存バージョンが古いまま)

react-debounce-input と react-inspector がReact 18止まりの peer range を持ったまま swagger-ui-react に固定されているため、npm workspaces の hoisting で React が2重にインストールされます。

  • ルート node_modules/react → 18.3.1(これらの制約に引っ張られる。swagger-ui-react はルートにhoistされているのでここを見る)
  • examples/vite-react-openapi/node_modules/react → 19.2.8(アプリ自身の要求)

結果、アプリ本体と swagger-ui-react 配下で 別インスタンスのReact が同一バンドルに混在し、useState のdispatcherがnullになって invalid hook call になっています。

既知の問題であることの確認

upstream (swagger-api/swagger-ui#10243 "React 19 Compatibility with swagger-ui-react") で同じ問題が出ています。2026-07-07に「5.32.9で解決」として自動クローズされていますが、その後も別の症状(createRoot is not a function、#10642)を報告しているコメントがあり、今回のPRが指す swagger-ui-react@5.32.14 の実際の依存関係を見ても react-debounce-input / react-inspector は未修正のままなので、「解決済み」は正確ではなさそうです。

提案

React 19 に今すぐ上げる必要は無いので、このPRはマージせず見送ります。swagger-ui-react 側で react-debounce-input / react-inspector の依存が解消されるのを待って、対応版が出たタイミングで改めて対応します。

@shinagawa-web
shinagawa-web marked this pull request as draft September 2, 2026 02:11
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/react-f01e79c410 branch 7 times, most recently from 9b9c4cd to 13b6981 Compare September 9, 2026 05:18
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/react-f01e79c410 branch 5 times, most recently from 7c3a90b to 9fb88c3 Compare September 17, 2026 05:14
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/react-f01e79c410 branch 5 times, most recently from 252bbd1 to fdf3276 Compare September 25, 2026 05:14
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/react-f01e79c410 branch 3 times, most recently from b8e3a2d to faa4e9e Compare October 1, 2026 05:25
Bumps the react group with 4 updates in the / directory: [react](https://github.com/react/react/tree/HEAD/packages/react), [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react), [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) and [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom).


Updates `react` from 18.3.1 to 19.2.8
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.2.8/packages/react)

Updates `@types/react` from 18.3.18 to 19.2.18
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `react-dom` from 18.3.1 to 19.2.8
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.2.8/packages/react-dom)

Updates `@types/react-dom` from 18.3.5 to 19.2.5
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom)

Updates `@types/react` from 18.3.18 to 19.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `@types/react-dom` from 18.3.5 to 19.2.5
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom)

---
updated-dependencies:
- dependency-name: "@types/react"
  dependency-version: 19.2.17
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: react
- dependency-name: "@types/react"
  dependency-version: 19.2.18
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: react
- dependency-name: "@types/react-dom"
  dependency-version: 19.2.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: react
- dependency-name: "@types/react-dom"
  dependency-version: 19.2.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: react
- dependency-name: react
  dependency-version: 19.2.8
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: react
- dependency-name: react-dom
  dependency-version: 19.2.8
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: react
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/react-f01e79c410 branch from faa4e9e to 2c59c40 Compare October 2, 2026 05:14

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant