Skip to content

Land lockfile-stable Dependabot bumps - #93

Merged
mattfaltyn merged 1 commit into
mainfrom
deps/safe-dependabot-bumps
Sep 18, 2026
Merged

mattfaltyn merged 1 commit into
mainfrom
deps/safe-dependabot-bumps

Conversation

@mattfaltyn

Copy link
Copy Markdown
Member

Summary

  • Land the four safe Dependabot updates together: react / react-dom 19.3.0, cspell 10.3.0, and jest-environment-jsdom 30.5.1, with a Node 22.18.0 lockfile that stays stable under npm install --package-lock-only.
  • Ignore @types/node majors in Dependabot so it stays on the Node 22 line (#89 already closed).
  • Supersedes #85, #86, #87, and #88, which fail CI on lockfile metadata churn.

Test plan

  • scripts/verify-fast on Node 22.18.0
  • npm install --package-lock-only --ignore-scripts --no-audit --no-fund is a no-op
  • CI validate-build-and-test on this PR
  • Close #85–#88 after merge

Made with Cursor

Dependabot's split PRs fail CI on lockfile metadata; this lands the four safe updates together and ignores @types/node majors.

Co-authored-by: Cursor <cursoragent@cursor.com>
@vercel

vercel Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
build-trilemma Ready Ready Preview Sep 18, 2026 10:55am UTC

Request Review

This branch was successfully deployed

1 active deployment
Preview — a6cb9d1a Deployed Sep 18, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant