Skip to content

chore: update all dependencies - #184

Merged
cbenning merged 3 commits into
mainfrom
chore/update-dependencies
Oct 6, 2026
Merged

cbenning merged 3 commits into
mainfrom
chore/update-dependencies

Conversation

@cbenning

@cbenning cbenning commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Updates every JS and Python dependency to latest in one PR. Supersedes the open Dependabot PRs: #185 (source-map-js, a transitive dependency), #172 (ws, no longer in the lockfile), #174 (postcss, now 8.5.29), #175 (browserslist, no longer in the lockfile) and #183 (pillow, now 12.3.0).

JS (fussel/web)

  • vite 6 → 8, vitest and @vitest/coverage-v8 4 → 5, @vitejs/plugin-react 4 → 6, jsdom 26 → 30, @testing-library/jest-dom 6 → 7, swiper 12 → 14
  • Patch/minor: react and react-dom 19.3, react-router-dom 7.18, react-photo-album 3.6, react-responsive-masonry 2.9, @testing-library/*
  • Removed the vite resolutions pin; it is no longer needed with a single vite
  • Dropped Node 20 (end-of-life) from the CI matrix, which is now Node 22 and 24: vitest 5, jest-dom 7 and jsdom 30 require Node >= 22 (jsdom 30: >= 22.22.2). Building a site still works on Node 20.19+ / 22.13+; only running the JS tests needs the newer versions.
  • Renamed vite.config.js to vite.config.mjs, since vite 8 warns about ESM syntax in a .js file
  • README: Node prerequisite and config filename updated

Transitive dependencies: both lockfiles are fully refreshed (yarn upgrade and uv lock --upgrade), not just the top-level packages.

Python (uv lock --upgrade)

  • Pillow 12.3, python-slugify 9, rich 15, ruff 0.16, pytest 9.1, beautifulsoup4 4.15, plus minor/patch bumps
  • Slug output for a set of ASCII, accented, CJK and Cyrillic names is identical on python-slugify 8 and 9

Verified: ruff format/check, pytest (114), clean frozen yarn install, JS tests (27) and yarn build with no warnings on Node 22.23.3 and 24.21.0, and an end-to-end run of the generator plus yarn build on sample photos (EXIF-rotated JPEG, PNG, non-ASCII album name).

Needs manual testing (not covered by automated tests):

  • Docker image build (alpine:latest, unpinned nodejs/yarn, Pillow 12.3 on musl)
  • Gallery in a real browser: vite 8 now bundles with rolldown; swiper 12 → 14 and react-photo-album 3.6 are mocked in the JS tests, so masonry layout, modal swiping, keyboard/hash navigation and navigation arrows are untested
  • People/face-tag features with real XMP-tagged photos
  • Terminal output formatting from rich 15

🤖 Generated with Claude Code

cbenning and others added 3 commits October 6, 2026 09:01
JS: vite 6 -> 8, vitest and coverage-v8 4 -> 5, @vitejs/plugin-react 4 -> 6,
jsdom 26 -> 29, @testing-library/jest-dom 6 -> 7, swiper 12 -> 14, plus
patch/minor bumps (react 19.3, react-router-dom 7.18, react-photo-album 3.6,
etc). Drop the vite resolution, which is no longer needed with a single vite.
jsdom stays on 29 because 30 needs Node >= 22.22.2.

Python: `uv lock --upgrade` (Pillow 12.3, python-slugify 9, rich 15, ruff 0.16,
pytest 9.1, beautifulsoup4 4.15, ...).

Rename vite.config.js to vite.config.mjs (vite 8 warns about ESM syntax in a
.js file) and update the README (Node >= 20.19 / 22.13, config filename).

Supersedes the open Dependabot PRs for ws, postcss, browserslist and pillow.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
jest-dom 7 requires Node >= 22, which would break the Node 20 CI job.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
vitest 5 and @testing-library/jest-dom >= 6.10 require Node >= 22, which
breaks the Node 20 CI job. Hold vitest and coverage-v8 on 4.x and jest-dom on
6.9.x. Verified install, tests and build on Node 20.20.2 and 22.21.1.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@cbenning
cbenning merged commit 21a4ce2 into main Oct 6, 2026
7 checks passed
@cbenning
cbenning deleted the chore/update-dependencies branch October 6, 2026 17:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant