Skip to content

chore(deps): bump vue and react stack dependencies - #378

Merged
roble merged 2 commits into
mainfrom
renanroble/bump-frontend-stack-deps
Sep 5, 2026
Merged

roble merged 2 commits into
mainfrom
renanroble/bump-frontend-stack-deps

Conversation

@roble

@roble roble commented Sep 5, 2026

Copy link
Copy Markdown
Collaborator

Bumps both frontend stack stubs to latest via ../scripts/bump-frontend-deps.sh --major, with two deviations forced by upstream constraints (below).

Only stubs/saucebase/stack/{vue,react}/package.json + package-lock.json change — 4 files.

Notable upgrades

Vue: shadcn-vue 2.7.3 → 2.8.2 · reka-ui 2.9.10 → 2.10.4 · vue 3.5.34 → 3.5.42 · vite 8.0.14 → 8.2.2 · @inertiajs/vue3 + @inertiajs/vite 3.6.0/3.2.0 → 3.7.0 · @lucide/vue 1.18.0 → 1.41.0 · @types/node 25.9.1 → 26.4.1 (major) · eslint 10.4.0 → 10.10.0 · tailwindcss 4.3.0 → 4.3.3

React: shadcn 4.7.0 → 4.21.0 · radix-ui 1.4.3 → 1.6.7 · react + react-dom 19.0.0 → 19.2.8 · lucide-react 1.18.0 → 1.41.0 · vite 8.0.0 → 8.2.2 · @inertiajs/react 3.6.0 → 3.7.0 · @types/node 25.6.2 → 26.4.1 (major) · @vitejs/plugin-react 6.0.0 → 6.1.1 · tailwindcss 4.2.0 → 4.3.3

Both stacks also take @playwright/test → 1.63.0, prettier → 3.9.6, typescript-eslint → 8.69.0, tsx → 4.23.13, laravel-vite-plugin → 3.2.0, and the @fontsource-variable/* fonts → 5.3.0.

Deviation 1 — TypeScript held at ^6.0.3

npm-check-updates wants typescript 6.0.3 → 7.0.2 in both stacks, but it cannot install:

peer typescript@">=4.8.4 <6.1.0" from typescript-eslint@8.69.0

typescript-eslint supports TS up to 6.0.x, so TS 7 fails to resolve (ERESOLVE). Held at ^6.0.3 in both stacks; worth revisiting once typescript-eslint ships TS 7 support.

Deviation 2 — vue keeps 7 moderate advisories

npm audit fix --force was rejected here. Its "fix" for the 7 moderate advisories was to downgrade shadcn-vue from ^2.8.2 to ^0.10.5, which replaced them with a worse set — 3 high + 1 critical, via giget / c12. Reverted; shadcn-vue stays at ^2.8.2.

The remaining 7 moderate advisories are a single chain: shadcn-vue → vue-metamorph → postcss-styl. shadcn-vue is a devDependencies CLI for scaffolding components and never enters the built bundle, so this is build-time surface only, and it's not fixable downstream until shadcn-vue bumps vue-metamorph.

React stack: 0 vulnerabilities.

Verification

Both stacks activated, installed, built, and e2e'd locally against the Herd site:

Stack Build E2E
vue pass 53 passed, 1 skipped (1.5m)
react pass 53 passed, 1 skipped (1.1m)

🤖 Generated with Claude Code

Runs ../scripts/bump-frontend-deps.sh --major against both stack stubs.

Notable: shadcn-vue 2.7.3 -> 2.8.2, reka-ui 2.9.10 -> 2.10.4, radix-ui
1.4.3 -> 1.6.7, shadcn 4.7.0 -> 4.21.0, react 19.0.0 -> 19.2.8, vue
3.5.34 -> 3.5.42, vite -> 8.2.2, @types/node 25.x -> 26.4.1.

TypeScript is held at ^6.0.3 in both stacks. ncu wants 7.0.2, but
typescript-eslint@8.69.0 declares peer typescript ">=4.8.4 <6.1.0", so TS 7
fails to resolve.

npm audit fix --force was rejected on the vue stack: it downgraded shadcn-vue
from ^2.8.2 to ^0.10.5, trading 7 moderate advisories for 3 high + 1 critical
via giget/c12. The 7 moderate advisories remain in one dev-only chain
(shadcn-vue -> vue-metamorph -> postcss-styl) and are not fixable downstream.
React stack has 0 vulnerabilities.

Verified: both stacks build and pass e2e (53 passed, 1 skipped each).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 5, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 15 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Team

Run ID: e7628b03-e4f1-4c1f-bb94-83dd72d1eda5

📥 Commits

Reviewing files that changed from the base of the PR and between 2839e1f and 771bfba.

⛔ Files ignored due to path filters (2)
  • stubs/saucebase/stack/react/package-lock.json is excluded by !**/package-lock.json
  • stubs/saucebase/stack/vue/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (2)
  • stubs/saucebase/stack/react/package.json
  • stubs/saucebase/stack/vue/package.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Sep 5, 2026

Copy link
Copy Markdown

@roble
roble merged commit 95d7e6f into main Sep 5, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant