Skip to content

chore(deps-dev): bump @storybook/react-vite from 9.1.20 to 10.5.4 - #413

Closed
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/storybook/react-vite-10.5.4
Closed

dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/storybook/react-vite-10.5.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 25, 2026

Copy link
Copy Markdown
Contributor

Bumps @storybook/react-vite from 9.1.20 to 10.5.4.

Release notes

Sourced from @​storybook/react-vite's releases.

v10.5.4

10.5.4

v10.5.3

10.5.3

v10.5.2

10.5.2

v10.5.1

10.5.1

v10.5.0

10.5.0

Foundational changes for new AI workflows

Storybook 10.5 contains hundreds of fixes and improvements:

  • ⚡️ Angular-vite framework: Modern, fast dev, docs, and test (preview)
  • 🌈 Vitest initialGlobals: Test across themes, viewports, locales
  • 🤖 Agentic review: AI-curated visual changesets and search results (experimental)
  • ⚛️ React docgen service: Unified metadata across MCP, Docs, and Controls (experimental)
  • 🧑‍💻 Claude / Codex plugins: One-click ADE integration (experimental)

... (truncated)

Changelog

Sourced from @​storybook/react-vite's changelog.

10.5.4

10.5.3

10.5.2

  • TanStack: Fix createServerFn validator mock - #35185, thanks @​sjh9714!
  • TanStack: Support pathless layout routes (id-only) in story routing - #35465, thanks @​unpunnyfuns!
  • Tanstack-react: Add missing Hydrate export - #35111, thanks @​arun-357!
  • Tanstack-react: Keep JSX-only component references during dead-code elimination - #35206, thanks @​yatishgoel!
  • Vitest: Fix coverage toggle crash on Vite 6 by clearing closed Vitest instance on restart - #35461, thanks @​yannbf!

10.5.1

10.5.0

Foundational changes for new AI workflows

Storybook 10.5 contains hundreds of fixes and improvements:

  • ⚡️ Angular-vite framework: Modern, fast dev, docs, and test (preview)
  • 🌈 Vitest initialGlobals: Test across themes, viewports, locales
  • 🤖 Agentic review: AI-curated visual changesets and search results (experimental)
  • ⚛️ React docgen service: Unified metadata across MCP, Docs, and Controls (experimental)
  • 🧑‍💻 Claude / Codex plugins: One-click ADE integration (experimental)

... (truncated)

Commits
  • 3327dc4 Bump version from "10.5.3" to "10.5.4" [skip ci]
  • 9ac2739 Bump version from "10.5.2" to "10.5.3" [skip ci]
  • b4b00f2 Merge pull request #34971 from storybookjs/valentin/upgrade-typescript-6
  • 518f711 Bump version from "10.5.1" to "10.5.2" [skip ci]
  • c253a06 Bump version from "10.5.0" to "10.5.1" [skip ci]
  • 9dafcd2 Bump version from "10.5.0-beta.2" to "10.5.0" [skip ci]
  • 448db85 Bump version from "10.5.0-beta.1" to "10.5.0-beta.2" [skip ci]
  • a4ce979 Bump version from "10.5.0-beta.0" to "10.5.0-beta.1" [skip ci]
  • f0bf138 Bump version from "10.5.0-alpha.11" to "10.5.0-beta.0" [skip ci]
  • fac05a5 Bump version from "10.5.0-alpha.10" to "10.5.0-alpha.11" [skip ci]
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@storybook/react-vite](https://github.com/storybookjs/storybook/tree/HEAD/code/frameworks/react-vite) from 9.1.20 to 10.5.4.
- [Release notes](https://github.com/storybookjs/storybook/releases)
- [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md)
- [Commits](https://github.com/storybookjs/storybook/commits/v10.5.4/code/frameworks/react-vite)

---
updated-dependencies:
- dependency-name: "@storybook/react-vite"
  dependency-version: 10.5.4
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 25, 2026
Dependabot does not update bun.lock in a Bun workspace
(dependabot-core#14223), so `bun install --frozen-lockfile` reds every CI
job on its PRs before any real signal is produced. Regenerated from the
bumped manifest per the mitigation documented in .github/dependabot.yml.
@Shironex

Copy link
Copy Markdown
Collaborator

Refreshed bun.lock here so CI gets past bun install --frozen-lockfile and produces real signal (Dependabot doesn't update bun.lock in a Bun workspace — dependabot-core#14223).

The result: this PR cannot pass on its own. It moves @storybook/react-vite to 10 while storybook core stays at 9.1.20, and @storybook/react@10 imports Tag from a preview-api surface that doesn't exist in core 9. Full diagnosis and the migration plan (the family must bump in lockstep, plus a play-function Canvas API migration) are in #425.

Shironex added a commit that referenced this pull request Aug 1, 2026
Storybook only runs when every one of its packages sits on the same major, so a
per-package major PR is structurally unmergeable — #413 and #414 each moved half
the family and neither could ever go green (see #425).

This does not contradict #398's decision to ungroup majors: that rationale was
"one migration per PR", and the Storybook family IS one migration whose packages
must move in lockstep. Listed first so Dependabot keeps the family together for
minor/patch too, which have the same lockstep requirement.

Kept as the last commit, touching only this file, so it can be dropped with a
single revert without touching the migration.
Shironex added a commit that referenced this pull request Aug 1, 2026
* chore(web): move the whole Storybook family to 10.5.5 in lockstep

Storybook refuses to run unless every one of its packages sits on the same
major, so `storybook`, `@storybook/react-vite`, `@storybook/addon-vitest` and
`@storybook/addon-a11y` all move together in one change. Splitting them is what
made the two Dependabot PRs structurally unmergeable: #413 moved the framework
and died on `No matching export ... "Tag"` against core 9, #414 moved core only
and made bun resolve a nested storybook@9 under every `@storybook/*` package.

`bun pm ls --all` now shows exactly one core (storybook@10.5.5) and no nested
copies, and `bun install --frozen-lockfile` is clean.

* docs(web): record why setProjectAnnotations stays after the Storybook 10 bump

addon-vitest 10.3+ prints an INFO box telling you to delete this call because it
now provisions preview annotations itself. That is true only for the `storybook`
Vitest project (the one with the plugin). The `unit` project shares this setup
file and has no Storybook plugin, so following the nudge would strip the preview
decorators from every composed-story unit test.

* docs(web): correct the react-dom-shim entry name in the CI-freeze guards

@storybook/react-dom-shim ships dist/react-18.js in Storybook 10 (it was
dist/react-18.mjs in 9). Both optimizeDeps guard comments named the old file;
the guard itself is unchanged (it pre-bundles by package name), only the
explanation of WHICH module it covers was stale.

* chore(ci): group the Storybook family in Dependabot, majors included

Storybook only runs when every one of its packages sits on the same major, so a
per-package major PR is structurally unmergeable — #413 and #414 each moved half
the family and neither could ever go green (see #425).

This does not contradict #398's decision to ungroup majors: that rationale was
"one migration per PR", and the Storybook family IS one migration whose packages
must move in lockstep. Listed first so Dependabot keeps the family together for
minor/patch too, which have the same lockstep requirement.

Kept as the last commit, touching only this file, so it can be dropped with a
single revert without touching the migration.
@Shironex

Shironex commented Aug 1, 2026

Copy link
Copy Markdown
Collaborator

Superseded by #449, which migrated the whole Storybook family to 10.5.5 in lockstep (merged).

This PR could never pass on its own — Storybook requires every package on the same major, and each of #413/#414 moved only half the family. #413 pulled @storybook/react@10 against core 9.1.20 (missing Tag export from storybook/internal/preview-api); #414 moved core alone and bun then resolved a nested storybook@9.1.20 under every @storybook/* package, so two cores coexisted in one install.

Worth recording: the Canvas TS2339 errors seen here were not an API removal. Canvas is a declaration-merged interface that only assembles when exactly one core is installed — in the split install the augmentation landed on a different physical module than @storybook/react-vite@9 resolved StoryContext['canvas'] from, so it stayed {}. With the family consistent, all 50 play-context query calls across 7 files typecheck and execute unchanged; no rewrites were needed.

.github/dependabot.yml now groups the Storybook family with majors included, so future majors arrive as one mergeable PR instead of N unmergeable ones.

@Shironex Shironex closed this Aug 1, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 1, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@github-project-automation github-project-automation Bot moved this from Todo to Done in Nightcore Aug 1, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/storybook/react-vite-10.5.4 branch August 1, 2026 00:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant