Skip to content

chore: update dependencies 2026-09-15 - #711

Open
claude[bot] wants to merge 1 commit into
mainfrom
agent/update-deps-20260915-144257
Open

claude[bot] wants to merge 1 commit into
mainfrom
agent/update-deps-20260915-144257

Conversation

@claude

@claude claude Bot commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • @rsbuild/core: 2.2.2 → 2.2.6 (peerDependencies, devDependencies)
  • @rspack/core: 2.2.2 → 2.2.4 (peerDependencies, dependencies, devDependencies)
  • @swc/core: 1.16.1 → 1.16.2 (peerDependencies, devDependencies)
  • browserslist: 4.28.8 → 4.28.9 (peerDependencies, devDependencies)
  • i18next: 26.4.1 → 26.4.2 (peerDependencies, dependencies, devDependencies)
  • react: 19.2.8 → 19.3.0 (peerDependencies, dependencies, devDependencies)
  • react-dom: 19.2.8 → 19.3.0 (peerDependencies, dependencies, devDependencies)
  • react-error-boundary: 6.1.4 → 6.1.5 (peerDependencies, dependencies)
  • react-i18next: 17.0.13 → 17.0.14 (peerDependencies, dependencies, devDependencies)
  • storybook: 10.5.10 → 10.6.0 (peerDependencies, dependencies, devDependencies) — (range narrowed — may break consumers)
  • webpack: 5.110.3 → 5.111.0 (peerDependencies, devDependencies)
  • webpack-dev-server: 5.2.4 → 6.0.0 (peerDependencies, devDependencies) — (range narrowed — may break consumers)
  • @formatjs/intl-localematcher: 0.8.13 → 0.9.0 (dependencies)
  • @storybook/addon-a11y: 10.5.10 → 10.6.0 (dependencies)
  • @types/react: 19.2.18 → 19.3.0 (dependencies, devDependencies)
  • @types/react-dom: 19.2.5 → 19.3.0 (dependencies, devDependencies)
  • @changesets/changelog-github: 1.0.0 → 1.0.1 (devDependencies)
  • @changesets/cli: 3.0.1 → 3.0.2 (devDependencies)
  • @rslib/core: 0.23.2 → 1.0.0 (devDependencies)
  • @types/node: 26.4.1 → 26.5.1 (devDependencies)
  • @typescript-eslint/parser: 8.69.0 → 8.70.0 (devDependencies)
  • agent-browser: 0.36.0 → 0.37.1 (devDependencies)
  • happy-dom: 20.12.2 → 20.14.5 (devDependencies)
  • netlify-cli: 27.4.2 → 27.6.0 (devDependencies)
  • stylelint: 17.14.1 → 17.15.0 (devDependencies)
  • vitest: 4.1.11 → 5.0.0 (devDependencies)

Migrations applied

Three updates required code or configuration changes:

  1. Rslib 1.0 rewrites new URL(..., import.meta.url) into an asset reference. In @squide/firefly-rsbuild-configs and @squide/firefly-webpack-configs this made packageDirectory resolve to dist/static/assets/index.ts, so the Module Federation runtime plugin paths pointed at files that do not exist and the endpoints remote module failed to build. Both packages now derive the directory with path.dirname(fileURLToPath(import.meta.url)).
  2. Vitest 5 changed the clearMocks default from false to true. Because this repository's tests are written with test.concurrent, a test that completed was clearing the mocks of the sibling tests still running, which failed 18 tests in @squide/core, @squide/firefly and @squide/firefly-module-federation. clearMocks: false is now set explicitly in all 11 package vitest.config.ts files.
  3. webpack-dev-server 6 is a major bump. The basic-webpack sample was additionally validated in a browser (login, navigation, federated remote modules) on top of the required validation steps.

Update not applied

typescript 6.0.3 → 7.0.2 was reverted. TypeScript 7 breaks @typescript-eslint/typescript-estree@8.54.0 (TypeError: Cannot read properties of undefined (reading 'Cjs')), and typescript-eslint is deliberately excluded from update-outdated-deps. This is already tracked in #708, which has been updated with this run's recurrence.

Validation checklist

  • Step 2a: Linting
  • Step 2b: Tests
  • Step 2c: Endpoints sample app
  • Step 2d: Storybook sample app

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@pkg-pr-new

pkg-pr-new Bot commented Sep 15, 2026

Copy link
Copy Markdown

Open in StackBlitz

@squide/core

pnpm add https://pkg.pr.new/@squide/core@711

@squide/env-vars

pnpm add https://pkg.pr.new/@squide/env-vars@711

@squide/fakes

pnpm add https://pkg.pr.new/@squide/fakes@711

@squide/firefly

pnpm add https://pkg.pr.new/@squide/firefly@711

@squide/firefly-module-federation

pnpm add https://pkg.pr.new/@squide/firefly-module-federation@711

@squide/firefly-rsbuild-configs

pnpm add https://pkg.pr.new/@squide/firefly-rsbuild-configs@711

@squide/firefly-storybook

pnpm add https://pkg.pr.new/@squide/firefly-storybook@711

@squide/firefly-webpack-configs

pnpm add https://pkg.pr.new/@squide/firefly-webpack-configs@711

@squide/i18next

pnpm add https://pkg.pr.new/@squide/i18next@711

@squide/launch-darkly

pnpm add https://pkg.pr.new/@squide/launch-darkly@711

@squide/msw

pnpm add https://pkg.pr.new/@squide/msw@711

@squide/react-router

pnpm add https://pkg.pr.new/@squide/react-router@711

commit: 4cbfaa9

"webpack": "^5.110.3",
"webpack-dev-server": "^5.2.4"
"webpack": "^5.111.0",
"webpack-dev-server": "^6.0.0"

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

High — peer dependency conflict (/pnpm)

This package moves its webpack-dev-server peer to ^6.0.0, but its own runtime dependency @workleap/webpack-configs (^1.6.16, line 47) still declares webpack-dev-server: ^5.2.4 as a peer. The two ranges are disjoint, so a consumer can never satisfy both:

@squide/firefly-webpack-configs  → webpack-dev-server ^6.0.0
└── @workleap/webpack-configs@1.6.16 → webpack-dev-server ^5.2.4 (optional peer)

This is already visible in this PR's own lockfile, where the optional peer resolved out of range:

'@workleap/webpack-configs@1.6.16(...)(webpack-dev-server@6.0.0)(webpack@5.111.0)':

Impact on consumers:

  • pnpm — unmet peer webpack-dev-server@^5.2.4: found 6.0.0 warning on every install (this repo has no strict-peer-dependencies, so it only warns here).
  • npm / Yarn classic — hard ERESOLVE install failure, since the conflicting peer is not optional from their resolver's point of view.

auto-install-peers does not rescue this: it only installs missing peers, and webpack-dev-server is present — just at the wrong major.

Note that every other peer in this block narrows within the range @workleap/webpack-configs accepts (@swc/core ^1.16.2 ⊂ ^1.16.1, browserslist ^4.28.9 ⊂ ^4.28.8, webpack ^5.111.0 ⊂ ^5.110.2), so webpack-dev-server is the only incompatible one.

Fix: hold the webpack-dev-server peer (and the matching devDependency + the basic-webpack sample) at ^5.2.4 until a @workleap/webpack-configs release supports v6. If you want to ship v6 support now, widen the range so both majors resolve and add a peerDependencyRules.allowedVersions entry documenting why v6 against @workleap/webpack-configs@1.x is safe — the /pnpm skill's guidance is to keep library peer ranges wide (.agents/skills/pnpm/references/features-peer-deps.md):

Suggested change
"webpack-dev-server": "^6.0.0"
"webpack-dev-server": "^5.2.4 || ^6.0.0"

@@ -0,0 +1,13 @@
---
"@squide/firefly-webpack-configs": minor

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Medium — release correctness

The changeset body states the reason for this bump is that the webpack-dev-server peer range "moved from ^5.2.4 to ^6.0.0, which requires consumers to upgrade." Requiring consumers to upgrade is the definition of a breaking change, so this should be major, not minor.

Concretely: @squide/firefly-webpack-configs is at 5.2.13. A minor publishes 5.3.0, which every consumer on ^5.x picks up on a routine pnpm update — silently landing a package that now demands a webpack-dev-server major they haven't migrated to. Under a major (6.0.0) the same consumers stay pinned until they opt in.

This is moot if you take the fix suggested on packages/firefly-webpack-configs/package.json:43 and hold the peer at ^5.2.4 — then patch is the correct level for the remaining in-range bumps.

Suggested change
"@squide/firefly-webpack-configs": minor
"@squide/firefly-webpack-configs": major

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants