chore(deps): bump the npm-web-nonbreaking group across 1 directory with 16 updates#252
Conversation
…th 16 updates Bumps the npm-web-nonbreaking group with 16 updates in the /web directory: | Package | From | To | | --- | --- | --- | | [@react-three/fiber](https://github.com/pmndrs/react-three-fiber) | `9.5.0` | `9.6.0` | | [fumadocs-core](https://github.com/fuma-nama/fumadocs) | `16.7.7` | `16.8.4` | | [fumadocs-mdx](https://github.com/fuma-nama/fumadocs) | `14.2.11` | `14.3.1` | | [fumadocs-ui](https://github.com/fuma-nama/fumadocs) | `16.7.7` | `16.8.4` | | [next](https://github.com/vercel/next.js) | `16.2.1` | `16.2.4` | | [react](https://github.com/facebook/react/tree/HEAD/packages/react) | `19.2.4` | `19.2.5` | | [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) | `19.2.4` | `19.2.5` | | [@next/eslint-plugin-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-plugin-next) | `16.2.1` | `16.2.4` | | [@tailwindcss/postcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss) | `4.2.2` | `4.2.4` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `22.19.15` | `22.19.17` | | [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.2.1` | `16.2.4` | | [eslint-plugin-react-hooks](https://github.com/facebook/react/tree/HEAD/packages/eslint-plugin-react-hooks) | `7.0.1` | `7.1.1` | | [globals](https://github.com/sindresorhus/globals) | `17.4.0` | `17.5.0` | | [postcss](https://github.com/postcss/postcss) | `8.5.8` | `8.5.10` | | [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) | `4.2.2` | `4.2.4` | | [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.58.0` | `8.59.0` | Updates `@react-three/fiber` from 9.5.0 to 9.6.0 - [Release notes](https://github.com/pmndrs/react-three-fiber/releases) - [Commits](pmndrs/react-three-fiber@v9.5.0...v9.6.0) Updates `fumadocs-core` from 16.7.7 to 16.8.4 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs-core@16.7.7...fumadocs-core@16.8.4) Updates `fumadocs-mdx` from 14.2.11 to 14.3.1 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs-mdx@14.2.11...fumadocs-ui@14.3.1) Updates `fumadocs-ui` from 16.7.7 to 16.8.4 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs-ui@16.7.7...fumadocs-ui@16.8.4) Updates `next` from 16.2.1 to 16.2.4 - [Release notes](https://github.com/vercel/next.js/releases) - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js) - [Commits](vercel/next.js@v16.2.1...v16.2.4) Updates `react` from 19.2.4 to 19.2.5 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.5/packages/react) Updates `react-dom` from 19.2.4 to 19.2.5 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.5/packages/react-dom) Updates `@next/eslint-plugin-next` from 16.2.1 to 16.2.4 - [Release notes](https://github.com/vercel/next.js/releases) - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js) - [Commits](https://github.com/vercel/next.js/commits/v16.2.4/packages/eslint-plugin-next) Updates `@tailwindcss/postcss` from 4.2.2 to 4.2.4 - [Release notes](https://github.com/tailwindlabs/tailwindcss/releases) - [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.2.4/packages/@tailwindcss-postcss) Updates `@types/node` from 22.19.15 to 22.19.17 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `eslint-config-next` from 16.2.1 to 16.2.4 - [Release notes](https://github.com/vercel/next.js/releases) - [Changelog](https://github.com/vercel/next.js/blob/canary/release.js) - [Commits](https://github.com/vercel/next.js/commits/v16.2.4/packages/eslint-config-next) Updates `eslint-plugin-react-hooks` from 7.0.1 to 7.1.1 - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/facebook/react/blob/main/packages/eslint-plugin-react-hooks/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/eslint-plugin-react-hooks@7.1.1/packages/eslint-plugin-react-hooks) Updates `globals` from 17.4.0 to 17.5.0 - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v17.4.0...v17.5.0) Updates `postcss` from 8.5.8 to 8.5.10 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.8...8.5.10) Updates `tailwindcss` from 4.2.2 to 4.2.4 - [Release notes](https://github.com/tailwindlabs/tailwindcss/releases) - [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.2.4/packages/tailwindcss) Updates `typescript-eslint` from 8.58.0 to 8.59.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.59.0/packages/typescript-eslint) --- updated-dependencies: - dependency-name: "@react-three/fiber" dependency-version: 9.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-web-nonbreaking - dependency-name: fumadocs-core dependency-version: 16.8.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-web-nonbreaking - dependency-name: fumadocs-mdx dependency-version: 14.3.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-web-nonbreaking - dependency-name: fumadocs-ui dependency-version: 16.8.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-web-nonbreaking - dependency-name: next dependency-version: 16.2.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-web-nonbreaking - dependency-name: react dependency-version: 19.2.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-web-nonbreaking - dependency-name: react-dom dependency-version: 19.2.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-web-nonbreaking - dependency-name: "@next/eslint-plugin-next" dependency-version: 16.2.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-web-nonbreaking - dependency-name: "@tailwindcss/postcss" dependency-version: 4.2.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-web-nonbreaking - dependency-name: "@types/node" dependency-version: 22.19.17 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-web-nonbreaking - dependency-name: eslint-config-next dependency-version: 16.2.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-web-nonbreaking - dependency-name: eslint-plugin-react-hooks dependency-version: 7.1.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-web-nonbreaking - dependency-name: globals dependency-version: 17.5.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-web-nonbreaking - dependency-name: postcss dependency-version: 8.5.10 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-web-nonbreaking - dependency-name: tailwindcss dependency-version: 4.2.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-web-nonbreaking - dependency-name: typescript-eslint dependency-version: 8.59.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-web-nonbreaking ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
Mogplex PR Review
Status: Attention needed
This is a routine Dependabot dependency bump across 16 packages in the /web directory. The upgrades include two security fixes (postcss XSS, Next.js CVE-2026-23869) and are broadly safe to merge. Two concerns are worth addressing before landing: the lockfile (pnpm-lock.yaml) is absent from the diff, and one package (fumadocs-mdx) lost its npm provenance attestation in the new version.
1 finding was added inline.
Warnings
- Lockfile not updated in this PR (web/package.json)
The PR modifiesweb/package.jsonbut no lockfile (pnpm-lock.yaml, which theenginesfield indicates is the package manager) appears in the diff. Without a committed lockfile update, the actual resolved dependency versions are unknown and reproducibility is not guaranteed. CI may install different transitive versions than intended, and the security fixes in postcss and Next.js may not actually take effect until the lockfile is regenerated and committed. Verify that the lockfile was updated and committed alongside this change, or confirm that your CI pipeline regenerates it from scratch.
Suggestions
- Security fixes included — note for changelog/release tracking (web/package.json)
Two packages in this bump include security fixes that should be tracked: (1)postcss8.5.10 fixes an XSS vulnerability via unescaped</style>in non-bundler output. (2)next16.2.3 backports a fix for CVE-2026-23869. These are good reasons to prioritize landing this PR promptly. No action required beyond merging, but worth noting in release notes or a security advisory if your project tracks such things.
| "next": "^16.2.1", | ||
| "react": "^19.2.4", | ||
| "react-dom": "^19.2.4", | ||
| "fumadocs-core": "^16.8.4", |
There was a problem hiding this comment.
Warning: fumadocs-mdx 14.3.1 has no npm provenance attestation
The PR description explicitly notes: 'This version has no provenance attestation, while the previous version (14.2.11) was attested.' npm provenance attestation links a published package to its source repo and build pipeline, providing supply-chain integrity guarantees. Its absence for 14.3.1 means you cannot cryptographically verify the published artifact was built from the expected source. This is worth confirming with the fumadocs maintainers (fuma-nama/fumadocs) before landing, especially since this is a minor version bump (14.3.x) that introduces a breaking change (Next.js config must now be ESM-only). If the project's security posture requires attestation, consider pinning to 14.2.11 until attestation is restored.
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the npm-web-nonbreaking group with 16 updates in the /web directory:
9.5.09.6.016.7.716.8.414.2.1114.3.116.7.716.8.416.2.116.2.419.2.419.2.519.2.419.2.516.2.116.2.44.2.24.2.422.19.1522.19.1716.2.116.2.47.0.17.1.117.4.017.5.08.5.88.5.104.2.24.2.48.58.08.59.0Updates
@react-three/fiberfrom 9.5.0 to 9.6.0Release notes
Sourced from
@react-three/fiber's releases.Commits
877c839chore: Move ShaderMaterial uniform notes to objects out of pitfalls (#3734)ece1a3fRELEASING: Releasing 1 package(s)26e4716docs(changeset): Fix uniforms refs so they remain stable for ShaderMaterial1fb9fcddocs: fix typos and documentation consistency (#3709)e1a375cfix: Uniforms have stable refs for ShaderMaterial (#3715)582f787docs: fix broken link on "Performance pitfalls" documentation page (#3700)9525ea0Update docker_tag in docs.yml workflow56637a2Upgrade pmndrs/docs workflow to version 38c9b656chore: use latest npm in canary1bdf70bchore: copy canary workflow to masterUpdates
fumadocs-corefrom 16.7.7 to 16.8.4Release notes
Sourced from fumadocs-core's releases.
Commits
e1f19c7Version Packages (#3232)b5ff03bUI: Support new OG image design for Takumi61b15e9Core: fix Shiki languages not loaded under lazy mode9b5d2b3Core: fix file storage1a5433cCore: support$locale6d7399bVersion Packages (#3229)dcb1c25fix: downgrade Tanstack Startf1b66afUI: reduce generated Tailwind CSS bundlea1ca76cDocs: introduce local-md non-RSC usage6faf2deBump depsUpdates
fumadocs-mdxfrom 14.2.11 to 14.3.1Release notes
Sourced from fumadocs-mdx's releases.
Commits
00c01b6Merge pull request #1041 from fuma-nama/changeset-release/devb571b21Version Packagese7443d7UI: Fix development errorsa6a7b70Merge branch 'main' into dev00209d0docs: update information07e343eMerge pull request #1028 from fuma-nama/changeset-release/devd21abf0Version Packagesacffcfdfix Orama type problemsa11804bUI: expose more providers fromfumadocs-ui/provider46d9208CFA: Add option for ESLintAttestation changes
This version has no provenance attestation, while the previous version (14.2.11) was attested. Review the package versions before updating.
Updates
fumadocs-uifrom 16.7.7 to 16.8.4Release notes
Sourced from fumadocs-ui's releases.
... (truncated)
Commits
e1f19c7Version Packages (#3232)b5ff03bUI: Support new OG image design for Takumi61b15e9Core: fix Shiki languages not loaded under lazy mode9b5d2b3Core: fix file storage1a5433cCore: support$locale6d7399bVersion Packages (#3229)dcb1c25fix: downgrade Tanstack Startf1b66afUI: reduce generated Tailwind CSS bundlea1ca76cDocs: introduce local-md non-RSC usage6faf2deBump depsUpdates
nextfrom 16.2.1 to 16.2.4Release notes
Sourced from next's releases.
... (truncated)
Commits
2275bd8v16.2.4e073983Adding more system info to the 'initialize project' trace (#92427)8a540b5Turbopack: shorter error message for ModuleBatchesGraph::get_entry_index (#92...2f5343fTurbopack: shorter error for ChunkGroupInfo::get_index_of (#92814)2ad9d3fturbo-tasks: Fix recomputation loop by allowing cell cleanup on error during ...6f3808eCompiler: Support boolean and number primtives in next.config defines (#92731)fbc7684Scope Safari ?ts= cache-buster to CSS/font assets only (Pages Router) (#92580)805d758Turbopack: fix filesystem watcher config not applying follow_symlinks(false) ...1056faechore: Bump reqwest to 0.13.2 (#92713)d5f649bv16.2.3Updates
reactfrom 19.2.4 to 19.2.5Release notes
Sourced from react's releases.
Commits
23f4f9f19.2.5Updates
react-domfrom 19.2.4 to 19.2.5Release notes
Sourced from react-dom's releases.
Commits
23f4f9f19.2.5Updates
@next/eslint-plugin-nextfrom 16.2.1 to 16.2.4Release notes
Sourced from
@next/eslint-plugin-next's releases.... (truncated)
Commits
2275bd8v16.2.4d5f649bv16.2.352faae3v16.2.2Updates
@tailwindcss/postcssfrom 4.2.2 to 4.2.4Release notes
Sourced from
@tailwindcss/postcss's releases.Changelog
Sourced from
@tailwindcss/postcss's changelog.Commits
69ad7cc4.2.4 (#19948)685c19eFix issue around resolving paths in@tailwindcss/vite(#19947)2e3fa494.2.3 (#19944)4527123docs(postcss): remove duplicated optimize example from README (#19938)aad6017docs/fix-lightning-css-typo-postcss-readme (#19913)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@tailwindcss/postcsssince your current version.Updates
@types/nodefrom 22.19.15 to 22.19.17Commits
Updates
eslint-config-nextfrom 16.2.1 to 16.2.4Release notes
Sourced from eslint-config-next's releases.
... (truncated)
Commits
2275bd8v16.2.4d5f649bv16.2.352faae3v16.2.2Updates
eslint-plugin-react-hooksfrom 7.0.1 to 7.1.1Release notes
Sourced from eslint-plugin-react-hooks's releases.
Changelog
Sourced from eslint-plugin-react-hooks's changelog.
Commits
Updates
globalsfrom 17.4.0 to 17.5.0Release notes
Sourced from globals's releases.
Commits
b8170c817.5.05d84602Update globals (2026-04-12) (#342)1b727e5Fix build script for ES globals (#341)Updates
postcssfrom 8.5.8 to 8.5.10Release notes
Sourced from postcss's releases.
Changelog
Sourced from postcss's changelog.
Commits
33b9790Release 8.5.10 version536c79eEscape </style> in CSS output (#2074)afa96b2Description has been truncated