fix(deps): update npm minor/patch (apps/web) - #656
Merged
Conversation
renovate
Bot
requested review from
ALARGECOMPANY,
biggest-littlest and
scttbnsn
as code owners
August 3, 2026 04:42
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
renovate
Bot
force-pushed
the
renovate/npm-minor-patch-appsweb
branch
from
August 3, 2026 22:00
9711b61 to
15c1799
Compare
Contributor
Author
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
scttbnsn
added a commit
that referenced
this pull request
Aug 4, 2026
…xact pin (#664) Renovate's apps/web minor/patch group (#656) fails the `Next.js is pinned past the 16.2.9 security advisory batch` guard because it asserts `next === '16.2.11'` exactly — every legitimate bump past the floor breaks CI. Same disease as the fast-uri allowlist fixed in #659. Now: `>= 16.2.11` with an explicit 16.x-line assertion so a new major still fails until deliberately vetted. Lockfile assertion was already a floor. Unblocks #656 and every future next bump.
|
Deployment failed with the following error: Learn More: https://vercel.com/codeswhat?upgradeToPro=build-rate-limit |
scttbnsn
approved these changes
Aug 4, 2026
scttbnsn
added a commit
that referenced
this pull request
Aug 4, 2026
## Summary rc.12 release prep: renames `[Unreleased]` to `[1.6.0-rc.12] — 2026-08-04` and rolls the release identity forward across README (badge + highlights), site config/content, quickstart tag matrix, demo mocks, API docs, the updates highlights page, and the identity/changelog-link tests. Adds the routine dependency-maintenance rollup (#653, #654, #655, #656, #664) and the Crowdin sync note (#665) to the changelog entry. Version files stay at `1.6.0` (base version, set at rc.1 — the release-cut workflow validates base version, full-tag changelog heading). ## rc.12 contents - 🔒 #659 security pins: brace-expansion 5.0.9 (app/ui/e2e), ip-address 10.3.1 (app runtime), fast-uri 4.1.2 (app/ui) - 🐛 #604 maturity badge/gate threshold agreement + surfaced publish-date auth failures - 🐛 #605 agent-mismatch grace during component (re)registration (display only, admission fail-closed) - 🐛 #636 WS log streams accept anonymous-auth sessions - 🐛 #637 explicit 501 for agent containers without controller lifecycle transport After merge: dev→main wholesale-tree sync, then dispatch `release-cut.yml --ref main -f release_tag=v1.6.0-rc.12`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Changelog 🔧 **Changed** - Updated release identity from `1.6.0-rc.11` to `1.6.0-rc.12` across documentation, site content, quickstart materials, API examples, demo mocks, and tests. - Added `v1.6.0-rc.12` release highlights dated August 4, 2026. - Updated changelog links and release metadata expectations. - Kept version files at `1.6.0`. 🔒 **Security** - Added security dependency updates for `#653`, `#654`, `#655`, `#656`, and `#664`. - Added the Crowdin synchronization note for `#665`. - Documented security dependency pins from `#659`. ✨ **Added** - Maturity badge and publish-date authentication updates from `#604`. - Agent-mismatch grace during component registration from `#605`. - Anonymous authentication support for WebSocket log streams from `#636`. - Explicit `501` responses when agent containers lack controller lifecycle transport from `#637`. ## Concerns - Verify all `1.6.0-rc.11` references are intentionally replaced or retained. - Verify the August 4, 2026 release date matches the release workflow. - Run changelog and release-identity tests after the updates. - Confirm the planned `dev` to `main` sync and release-cut workflow occur after merge. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
scttbnsn
added a commit
that referenced
this pull request
Aug 5, 2026
Wholesale-tree sync ahead of the v1.6.0-rc.12 cut: the head commit's tree is `origin/dev/v1.6`'s tree verbatim (`630c64ec`), parented on main's current head (`67f23419`). Squash-merging makes main tree-identical to `dev/v1.6`, satisfying the release-cut drift guard (`git diff --quiet origin/main origin/dev/v1.6`). Brings in since rc.11: #659 security pins, #662/#660/#661/#663 runtime fixes (#636/#604/#605/#637), #664 guard floor, #653–#656 deps, #665 Crowdin, #666 rc.12 prep. After merge: dispatch `release-cut.yml --ref main -f release_tag=v1.6.0-rc.12`. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Changelog - 🔒 Updated dependency security pins and security-version tests. - ✨ Added anonymous-authenticated WebSocket log streams with IP-based rate limits. - ✨ Added agent component-registration state tracking. - 🔧 Downgraded selected update blockers during agent registration. - 🔧 Added controller-Docker transport detection. - 🐛 Added HTTP `501` responses for unsupported agent lifecycle actions. - 🐛 Fixed maturity filtering to use per-container thresholds. - 🐛 Changed Docker publish-date lookup failures to warning logs. - 🔧 Updated dependency versions, release metadata, documentation, mocks, and changelog links from `v1.6.0-rc.11` to `v1.6.0-rc.12`. - ✨ Added release highlights for `v1.6.0-rc.12`. ## Concerns - Fix the French `containerLogs.stderr` value if `"sdterr"` is not intentional. - Verify the release date `August 4, 2026`. - Dispatch the release-cut workflow for `main` with `release_tag=v1.6.0-rc.12` after merging. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.5.5→2.5.61.3.2→1.3.319.2.17→19.2.1819.2.3→19.2.416.12.1→16.14.015.2.0→15.2.116.12.1→16.14.04.3.0→4.3.11.26.0→1.28.016.2.11→16.2.128.5.23→8.5.25Release Notes
biomejs/biome (@biomejs/biome)
v2.5.6Compare Source
Patch Changes
#11035
0e4b03bThanks @ematipico! - Fixed a performance regression innoMisusedPromisesthat caused type inference to run repeatedly while linting a file.#11043
22ec076Thanks @denbezrukov! - Fixed CSS formatting for multiline function arguments preceded by comments:.example { value: outer( 1, /* comment */ nested( - first, - second - ) + first, + second + ) ); }#11007
c9acb25Thanks @BTF-Kabir-2020! - Fixed #9195:useHookAtTopLevelno longer reports hooks in namedforwardRefcomponents that receive arefparameter.#10152
50a9bd8Thanks @Zelys-DFKH! - Fixed #10131: Biome now correctly parses curried arrow functions in ternary consequents when the inner arrow's parameters use a destructuring pattern, e.g.cond ? (x) => ({ a, b }) => body : alt.#11105
8ffe2b9Thanks @dadavidtseng! - Fixed #11092: ThenoUselessTernaryquick fix now preserves operator spacing when simplifying or inverting boolean ternary expressions.#10533
5809875Thanks @Mokto! - Fixed #10515:biome check --writewas not idempotent on Svelte files — multi-line template literals in<script>blocks and block comments in<style>blocks gained an extra indent level on every run.#11040
0abb620Thanks @Mokto! - Fixed an issue where the HTML formatter would duplicate a comment placed directly before a Svelte{@const ...}or{@debug ...}block. The duplication compounded on every subsequent--write, causing the file to grow exponentially.#10858
6d18204Thanks @ruidosujeira! - Fixed #10839: Svelte{#each}array destructuring no longer includes spaces inside square brackets, and multiline bind function expressions now indent their getter, setter, and function body correctly.#11009
2c36626Thanks @ematipico! - Improved the accuracy of type-aware lint rules by resolving more inferred types. For example,noFloatingPromisesnow detects floating Promises returned by aliased callbacks and arrays of Promises created by async mapping callbacks.The following statements are now reported:
#10973
9cb044cThanks @ematipico! - Fixed false positives innoMisleadingReturnTypewhen generic-constraint, normalization, substitution, or structural return-type comparison cannot complete. The rule now suppresses diagnostics rather than suggesting a return type derived from partial information. For example, this unresolved return type is no longer reported:#11071
15047a2Thanks @dyc3! - The HTML parser now accepts mixed-casedoctypedeclarations.#11030
cc90e65Thanks @marschattha! - Therdjsonreporter now populates the severity field of each diagnostic (ERROR,WARNING, orINFO), so tools consuming Reviewdog Diagnostic Format output no longer need to assume a default severity.#11009
2c36626Thanks @ematipico! - Fixed a performance regression in type-aware JavaScript lint rules by inferring only requested types and memoizing export resolution.#11056
903b177Thanks @dyc3! - Added support for Svelte declaration tags usingletandconst. Biome can now parse, format, and lint bindings declared in these tags.#11045
89c27c6Thanks @ematipico! - Improved the performance of Biome formatter up to ~7% across the board.#9806
781d68dThanks @dyc3! - Added the nursery rulenoJsRestrictedProperties, which ports ESLint'sno-restricted-propertiesrule. Biome now flags restricted member access and object destructuring, andbiome migrate eslintpreserves the rule's options.radix-ui/primitives (@radix-ui/react-slot)
v1.3.3nodeca/js-yaml (js-yaml)
v4.3.1Compare Source
lucide-icons/lucide (lucide-react)
v1.28.0Compare Source
v1.27.0: Version 1.27.0Compare Source
What's Changed
square-scissorsicons by @karsa-mistmere in #4581pending-cwicon by @NielsLazaroms in #4439zapandzap-officons by @kapowaz in #4536square-officon by @october-learns in #4496toolboxicon by @karsa-mistmere in #4571user-shieldicon by @MArtytraM99 in #3099mosqueicon by @iskepr in #4494feathericon by @karsa-mistmere in #4584barrelicon by @karsa-mistmere in #4592police-capicon to lab by @uibalint in #3019trophyicon by @karsa-mistmere in #4591piloticon by @jguddas in #2409podcasticon with newmic-*icons by @karsa-mistmere in #4583New Contributors
Full Changelog: lucide-icons/lucide@1.26.0...1.27.0
vercel/next.js (next)
v16.2.12Compare Source
postcss/postcss (postcss)
v8.5.25Compare Source
list.split()for non-string values (by @amir-rezaei).v8.5.24Compare Source
Configuration
📅 Schedule: (in timezone America/New_York)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.