Skip to content

chore: update dependencies 2026-09-01 - #704

Closed
claude[bot] wants to merge 1 commit into
mainfrom
agent/update-deps-20260901-143135
Closed

claude[bot] wants to merge 1 commit into
mainfrom
agent/update-deps-20260901-143135

Conversation

@claude

@claude claude Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Summary

peerDependencies

  • webpack-dev-server: ^5.2.4 → ^6.0.0 (peerDependencies, devDependencies) — major (range narrowed — may break consumers)
  • @rsbuild/core: ^2.1.5 → ^2.2.1 (peerDependencies, devDependencies) (range narrowed — may break consumers)
  • @rspack/core: ^2.1.3 → ^2.2.1 (peerDependencies, dependencies, devDependencies) (range narrowed — may break consumers)
  • @swc/core: ^1.15.43 → ^1.16.1 (peerDependencies, devDependencies) (range narrowed — may break consumers)
  • @tanstack/react-query: ^5.101.2 → ^5.102.8 (peerDependencies, dependencies, devDependencies) (range narrowed — may break consumers)
  • @workleap/swc-configs: ^2.3.13 → ^2.3.14 (peerDependencies, devDependencies) (range narrowed — may break consumers)
  • browserslist: ^4.28.5 → ^4.28.8 (peerDependencies, devDependencies) (range narrowed — may break consumers)
  • i18next: ^26.3.6 → ^26.4.0 (peerDependencies, dependencies, devDependencies) (range narrowed — may break consumers)
  • launchdarkly-js-client-sdk: ^3.9.3 → ^3.9.5 (peerDependencies, dependencies) (range narrowed — may break consumers)
  • logrocket: ^12.1.1 → ^12.3.0 (peerDependencies, dependencies) (range narrowed — may break consumers)
  • react: ^19.2.7 → ^19.2.8 (peerDependencies, dependencies) (range narrowed — may break consumers; only sample apps, the @squide/* react peer range stays ^18.0.0 || ^19.0.0)
  • react-dom: ^19.2.7 → ^19.2.8 (peerDependencies, dependencies) (range narrowed — may break consumers; only sample apps, the @squide/* react-dom peer range stays ^18.0.0 || ^19.0.0)
  • react-error-boundary: ^6.1.2 → ^6.1.4 (peerDependencies, dependencies) (range narrowed — may break consumers)
  • react-i18next: ^17.0.9 → ^17.0.12 (peerDependencies, dependencies, devDependencies) (range narrowed — may break consumers)
  • react-router: ^8.2.0 → ^8.3.1 (peerDependencies, dependencies, devDependencies) (range narrowed — may break consumers)
  • storybook: ^10.4.6 → ^10.5.10 (peerDependencies, dependencies, devDependencies) (range narrowed — may break consumers)
  • webpack: ^5.108.4 → ^5.110.2 (peerDependencies, devDependencies) (range narrowed — may break consumers)

dependencies

  • @formatjs/intl-localematcher: ^0.8.11 → ^0.8.13 (dependencies)
  • @module-federation/enhanced: 2.7.0 → 2.9.0 (dependencies)
  • @module-federation/rsbuild-plugin: 2.7.0 → 2.9.0 (dependencies)
  • @opentelemetry/auto-instrumentations-node: 0.78.0 → 0.79.0 (dependencies)
  • @opentelemetry/exporter-trace-otlp-http: 0.220.0 → 0.221.0 (dependencies)
  • @opentelemetry/instrumentation-express: 0.68.0 → 0.69.0 (dependencies)
  • @opentelemetry/instrumentation-http: 0.220.0 → 0.221.0 (dependencies)
  • @opentelemetry/sdk-node: 0.220.0 → 0.221.0 (dependencies)
  • @storybook/addon-a11y: 10.4.6 → 10.5.10 (dependencies)
  • @workleap-telemetry/core: ^2.0.2 → ^2.0.3 (dependencies)
  • @workleap/rsbuild-configs: ^4.1.1 → ^4.1.2 (dependencies, devDependencies)
  • @workleap/telemetry: 3.0.6 → 4.0.0 (dependencies) — major
  • @workleap/webpack-configs: ^1.6.15 → ^1.6.16 (dependencies)
  • html-webpack-plugin: ^5.6.7 → ^5.6.8 (dependencies)
  • msw-storybook-addon: 2.0.7 → 3.0.0 (dependencies) — major
  • storybook-react-rsbuild: 3.3.4 → 3.4.2 (dependencies, devDependencies)
  • uuid: ^14.0.1 → ^14.0.2 (dependencies)

devDependencies

  • @changesets/changelog-github: 0.7.0 → 1.0.0 (devDependencies)
  • @changesets/cli: 2.31.0 → 3.0.1 (devDependencies)
  • @tanstack/react-query-devtools: 5.101.2 → 5.102.8 (devDependencies)
  • @testing-library/react: 16.3.2 → 16.3.3 (devDependencies)
  • @types/node: 26.1.1 → 26.4.0 (devDependencies)
  • @types/react: 19.2.17 → 19.2.18 (devDependencies)
  • @types/react-dom: 19.2.3 → 19.2.5 (devDependencies)
  • @types/semver: 7.7.1 → 7.8.0 (devDependencies)
  • @typescript-eslint/parser: 8.63.0 → 8.68.0 (devDependencies)
  • @vitejs/plugin-react: 6.0.3 → 6.1.1 (devDependencies)
  • @workleap/eslint-configs: 2.0.4 → 2.0.5 (devDependencies)
  • @workleap/stylelint-configs: 2.1.11 → 2.1.12 (devDependencies)
  • agent-browser: 0.31.1 → 0.35.2 (devDependencies)
  • happy-dom: 20.10.6 → 20.12.0 (devDependencies)
  • netlify-cli: 26.2.0 → 27.4.1 (devDependencies)
  • pkg-pr-new: 0.0.75 → 0.0.88 (devDependencies)
  • stylelint: 17.14.0 → 17.14.1 (devDependencies)
  • syncpack: 15.3.2 → 15.3.3 (devDependencies)
  • tsx: 4.23.0 → 4.23.13 (devDependencies)
  • turbo: 2.10.4 → 2.10.12 (devDependencies)
  • vitest: 4.1.10 → 4.1.11 (devDependencies)
  • webpack-cli: 7.2.1 → 7.2.3 (devDependencies)

Code migration

msw-storybook-addon 3.0.0 removed the top-level initialize / mswLoader exports. samples/storybook/.storybook/preview.tsx now uses the CSF 3 entry point (msw-storybook-addon/csf3) and passes a setup function to mswLoader() to preserve onUnhandledRequest: "bypass". Story files continue to use parameters.msw, which that entry point still supports.

Held back

typescript 6.0.3 → 7.0.2 was not applied. typescript-eslint is deliberately excluded from updates by update-outdated-deps:update-versions, and the pinned @typescript-eslint/typescript-estree@8.54.0 crashes on TypeScript 7 (TypeError: Cannot read properties of undefined (reading 'Cjs')), which breaks every eslint task in the repo. See the linked issue.

Validation checklist

  • Step 2a: Linting
  • Step 2b: Tests
  • Step 2c: Endpoints sample app
  • Step 2d: Storybook sample app

🤖 Generated with Claude Code

@claude

claude Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Held-back typescript 6.0.3 → 7.0.2 is tracked in #705.

@pkg-pr-new

pkg-pr-new Bot commented Sep 1, 2026

Copy link
Copy Markdown

Open in StackBlitz

@squide/core

pnpm add https://pkg.pr.new/@squide/core@704

@squide/env-vars

pnpm add https://pkg.pr.new/@squide/env-vars@704

@squide/fakes

pnpm add https://pkg.pr.new/@squide/fakes@704

@squide/firefly

pnpm add https://pkg.pr.new/@squide/firefly@704

@squide/firefly-module-federation

pnpm add https://pkg.pr.new/@squide/firefly-module-federation@704

@squide/firefly-rsbuild-configs

pnpm add https://pkg.pr.new/@squide/firefly-rsbuild-configs@704

@squide/firefly-storybook

pnpm add https://pkg.pr.new/@squide/firefly-storybook@704

@squide/firefly-webpack-configs

pnpm add https://pkg.pr.new/@squide/firefly-webpack-configs@704

@squide/i18next

pnpm add https://pkg.pr.new/@squide/i18next@704

@squide/launch-darkly

pnpm add https://pkg.pr.new/@squide/launch-darkly@704

@squide/msw

pnpm add https://pkg.pr.new/@squide/msw@704

@squide/react-router

pnpm add https://pkg.pr.new/@squide/react-router@704

commit: ff6fba1

"webpack": "^5.108.4",
"webpack-dev-server": "^5.2.4"
"webpack": "^5.110.2",
"webpack-dev-server": "^6.0.0"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

High — dependency compatibility: this peer range is now unsatisfiable together with the package's own runtime dependency.

@squide/firefly-webpack-configs declares @workleap/webpack-configs": "^1.6.16" under dependencies (line 47), and that package peers webpack-dev-server: ^5.2.4:

# pnpm-lock.yaml:7401-7412
'@workleap/webpack-configs@1.6.16':
  peerDependencies:
    ...
    webpack-dev-server: ^5.2.4

No single webpack-dev-server version satisfies both ^6.0.0 (this file) and ^5.2.4 (@workleap/webpack-configs). Consumers on npm will hit ERESOLVE; pnpm users get an unmet-peer warning. The repo's own lockfile already records the violation — @workleap/webpack-configs@1.6.16 is resolved against webpack-dev-server@6.0.0 at pnpm-lock.yaml:18509.

This is also functionally unvalidated. Every dev-server option is produced by @workleap/webpack-configs' defineDevConfig (see packages/firefly-webpack-configs/src/defineConfig.ts:3, :306, :459), which was built and peer-declared against v5. Neither of the PR's browser validation steps starts a webpack dev server — 2c is the rsbuild-based endpoints sample and 2d is Storybook — and CI only runs a production build for basic-webpack (.github/workflows/ci.yml:80-82).

PR #639 deliberately held webpack-dev-server at 5.2.4 for the same class of reason. Suggest holding it again until @workleap/webpack-configs ships a release that peers webpack-dev-server ^6:

Suggested change
"webpack-dev-server": "^6.0.0"
"webpack-dev-server": "^5.2.4"

The matching devDependencies pin (line 68) and the basic-webpack sample pins would need to be reverted to 5.2.4 as well, and the changeset note dropped.

"@squide/firefly-module-federation": patch
"@squide/firefly-rsbuild-configs": patch
"@squide/firefly-storybook": patch
"@squide/firefly-webpack-configs": minor

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Medium — release correctness: if the webpack-dev-server peer bump is kept, this bump level must be major, not minor.

Dropping ^5.2.4 from the peer range removes support for a major version consumers are currently on. @squide/firefly-webpack-configs is at 5.2.12, so a minor releases this as 5.3.0 — consumers with "@squide/firefly-webpack-configs": "^5.2.12" pick it up automatically and their webpack-dev-server@5 install breaks with no signal.

The repo already set this precedent in #639, where the React Router ^7.15.0 → ^8.2.0 peer bump was reclassified from patch to major with a dedicated changeset:

React Router's peer requirement moved from ^7.15.0 to ^8.2.0 — a breaking change for consumers. Per the repo precedent (#240, RR v6→v7 = major) […] are now major instead of patch.

Suggested change
"@squide/firefly-webpack-configs": minor
"@squide/firefly-webpack-configs": major

Note this is moot if the peer bump is reverted per the comment on packages/firefly-webpack-configs/package.json — in that case patch is correct.

@@ -1,10 +1,17 @@
import { initialize as initializeMsw, mswLoader } from "msw-storybook-addon";
import { setupWorker } from "msw/browser";
import { mswLoader } from "msw-storybook-addon/csf3";

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Medium — documentation drift: this migration leaves the published setup guide teaching the API that msw-storybook-addon@3.0.0 removed.

docs/integrations/setup-storybook.md:22-45 still shows the v2 form, verbatim the code this file just replaced:

import { initialize as initializeMsw, mswLoader } from "msw-storybook-addon";
...
initializeMsw({
    onUnhandledRequest: "bypass"
});
...
loaders: [mswLoader]

Because the install step directly above it (docs/integrations/setup-storybook.md:15) is an unpinned pnpm add msw msw-storybook-addon, anyone following the guide gets 3.x and the snippet throws on the missing top-level exports — per this PR's own description, "msw-storybook-addon 3.0.0 removed the top-level initialize / mswLoader exports."

agent-skills/workleap-squide/references/integrations.md:592-596 carries the same stale snippet; it is synced from the docs by .github/workflows/sync-agent-skill.yml, so updating the doc should propagate.

Please update the doc snippet to match this file (and adjust its !#5-7,19 line-highlight annotation, since the line numbers shift).

@claude

claude Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by a newer dependency update run.

@claude claude Bot closed this Sep 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants