Skip to content

Build(deps): Bump the npm group across 1 directory with 9 updates - #2350

Merged
nickytonline merged 2 commits into
mainfrom
dependabot/npm_and_yarn/npm-050b24acd9
Aug 20, 2026
Merged

Build(deps): Bump the npm group across 1 directory with 9 updates#2350
nickytonline merged 2 commits into
mainfrom
dependabot/npm_and_yarn/npm-050b24acd9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 20, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm group with 8 updates in the / directory:

Package From To
@mui/icons-material 9.2.0 9.3.1
@mui/x-data-grid 9.10.1 9.11.0
docusaurus-plugin-openapi-docs 5.1.3 5.2.0
docusaurus-theme-openapi-docs 5.1.3 5.2.0
mermaid 11.16.0 11.16.1
js-yaml 5.2.3 5.3.0
oxfmt 0.62.0 0.63.0
oxlint 1.76.0 1.78.0

Updates @mui/icons-material from 9.2.0 to 9.3.1

Release notes

Sourced from @​mui/icons-material's releases.

v9.3.1

A big thanks to the 4 contributors who made this release possible.

@mui/material@9.3.1

@mui/codemod@9.3.1

Core

All contributors of this release in alphabetical order: @​brijeshb42, @​DanailH, @​silviuaavram, @​ZeeshanTamboli

v9.3.0

A big thanks to the 18 contributors who made this release possible. Here are some highlights ✨:

  • ♿️ Keyboard navigation in the Toggle Button Group now follows the roving tabindex pattern.
  • ♿️ The Autocomplete announces its loading and no options messages through a new status slot.

@mui/material@9.3.0

@mui/system@9.3.0

@mui/codemod@9.3.0

Docs

... (truncated)

Changelog

Sourced from @​mui/icons-material's changelog.

9.3.1

Aug 6, 2026

A big thanks to the 4 contributors who made this release possible.

@mui/material@9.3.1

@mui/codemod@9.3.1

Core

All contributors of this release in alphabetical order: @​brijeshb42, @​DanailH, @​silviuaavram, @​ZeeshanTamboli

9.3.0

Aug 4, 2026

A big thanks to the 18 contributors who made this release possible. Here are some highlights ✨:

  • ♿️ Keyboard navigation in the Toggle Button Group now follows the roving tabindex pattern.
  • ♿️ The Autocomplete announces its loading and no options messages through a new status slot.

@mui/material@9.3.0

@mui/system@9.3.0

... (truncated)

Commits

Updates @mui/material from 9.2.0 to 9.3.1

Release notes

Sourced from @​mui/material's releases.

v9.3.1

A big thanks to the 4 contributors who made this release possible.

@mui/material@9.3.1

@mui/codemod@9.3.1

Core

All contributors of this release in alphabetical order: @​brijeshb42, @​DanailH, @​silviuaavram, @​ZeeshanTamboli

v9.3.0

A big thanks to the 18 contributors who made this release possible. Here are some highlights ✨:

  • ♿️ Keyboard navigation in the Toggle Button Group now follows the roving tabindex pattern.
  • ♿️ The Autocomplete announces its loading and no options messages through a new status slot.

@mui/material@9.3.0

@mui/system@9.3.0

@mui/codemod@9.3.0

Docs

... (truncated)

Changelog

Sourced from @​mui/material's changelog.

9.3.1

Aug 6, 2026

A big thanks to the 4 contributors who made this release possible.

@mui/material@9.3.1

@mui/codemod@9.3.1

Core

All contributors of this release in alphabetical order: @​brijeshb42, @​DanailH, @​silviuaavram, @​ZeeshanTamboli

9.3.0

Aug 4, 2026

A big thanks to the 18 contributors who made this release possible. Here are some highlights ✨:

  • ♿️ Keyboard navigation in the Toggle Button Group now follows the roving tabindex pattern.
  • ♿️ The Autocomplete announces its loading and no options messages through a new status slot.

@mui/material@9.3.0

@mui/system@9.3.0

... (truncated)

Commits

Updates @mui/x-data-grid from 9.10.1 to 9.11.0

Release notes

Sourced from @​mui/x-data-grid's releases.

v9.11.0

We'd like to extend a big thank you to the 14 contributors who made this release possible. Here are some highlights ✨:

  • ✨ Add addItems() and getItemSelection() API methods to Tree View

Special thanks go out to these community members for their valuable contributions: @​12joan, @​Anexus5919, @​kevincorizi-sbt, @​mixelburg, @​mustafajw07, @​strazto

The following team members contributed to this release: @​flaviendelangle, @​hasdfa, @​JCQuintas, @​LukasTy, @​MBilalShafi, @​michelengelen, @​noraleonte, @​rita-codes

Data Grid

@mui/x-data-grid@9.11.0

  • [DataGrid] Fix updateRows stripping class prototypes from rows in datasource mode (#22288) @​mixelburg
  • [DataGrid] Do not re-fetch data when an Activity becomes visible (#22603) @​12joan
  • [DataGrid] Fix toolbar button stealing focus when a sibling's disabled state changes (#23204) @​MBilalShafi

@mui/x-data-grid-pro@9.11.0 pro

Same changes as in @mui/x-data-grid@9.11.0.

@mui/x-data-grid-premium@9.11.0 premium

Same changes as in @mui/x-data-grid-pro@9.11.0.

Date and Time Pickers

@mui/x-date-pickers@9.11.0

  • [pickers] Fix day shift when editing dates predating timezone standardization (#23296) @​JCQuintas

@mui/x-date-pickers-pro@9.11.0 pro

Same changes as in @mui/x-date-pickers@9.11.0, plus:

  • [DateRangePicker] Fix disabled filler cells showing the range highlight (#23293) @​JCQuintas

Charts

@mui/x-charts@9.11.0

... (truncated)

Changelog

Sourced from @​mui/x-data-grid's changelog.

9.11.0

Aug 6, 2026

We'd like to extend a big thank you to the 14 contributors who made this release possible. Here are some highlights ✨:

  • ✨ Add addItems() and getItemSelection() API methods to Tree View

Special thanks go out to these community members for their valuable contributions: @​12joan, @​Anexus5919, @​kevincorizi-sbt, @​mixelburg, @​mustafajw07, @​strazto

The following team members contributed to this release: @​flaviendelangle, @​hasdfa, @​JCQuintas, @​LukasTy, @​MBilalShafi, @​michelengelen, @​noraleonte, @​rita-codes

Data Grid

@mui/x-data-grid@9.11.0

  • [DataGrid] Fix updateRows stripping class prototypes from rows in datasource mode (#22288) @​mixelburg
  • [DataGrid] Do not re-fetch data when an Activity becomes visible (#22603) @​12joan
  • [DataGrid] Fix toolbar button stealing focus when a sibling's disabled state changes (#23204) @​MBilalShafi

@mui/x-data-grid-pro@9.11.0 pro

Same changes as in @mui/x-data-grid@9.11.0.

@mui/x-data-grid-premium@9.11.0 premium

Same changes as in @mui/x-data-grid-pro@9.11.0.

Date and Time Pickers

@mui/x-date-pickers@9.11.0

  • [pickers] Fix day shift when editing dates predating timezone standardization (#23296) @​JCQuintas

@mui/x-date-pickers-pro@9.11.0 pro

Same changes as in @mui/x-date-pickers@9.11.0, plus:

  • [DateRangePicker] Fix disabled filler cells showing the range highlight (#23293) @​JCQuintas

Charts

@mui/x-charts@9.11.0

... (truncated)

Commits
  • 0486f84 [release] v9.11.0 (#23295)
  • eacd695 [docs] Replace README peer dependency lists with an npm install command (#23256)
  • 77536d2 [DataGrid] Do not re-fetch data when an Activity becomes visible (#22603)
  • 1ba29f4 [DataGrid] Fix toolbar button stealing focus when a sibling's disabled state ...
  • bbff8c0 [data grid] Fix updateRows stripping class prototypes from rows in datasour...
  • See full diff in compare view

Updates docusaurus-plugin-openapi-docs from 5.1.3 to 5.2.0

Release notes

Sourced from docusaurus-plugin-openapi-docs's releases.

v5.2.0

5.2.0 (2026-08-11)

Minor release adding support for OpenAPI 3.2 hierarchical tags. You can now group the sidebar by tagParent via groupPathsBy, using the new tags[].parent field to build nested tag hierarchies. Also includes a theme fix that bundles code snippet language icons locally (no more external icon requests) and a batch of dependency updates.

🚀 New Feature

  • feat(plugin): support OpenAPI 3.2 hierarchical tags (tags[].parent) (#1603)

🐛 Bug Fix

  • fix(theme): bundle code snippet language icons locally (#1595)

🤖 Dependencies

  • chore(deps): bump the react group across 1 directory with 2 updates (#1590)
  • chore(deps): bump postman-collection from 5.3.0 to 5.3.1 (#1591)
  • chore(deps): bump fast-uri from 3.1.4 to 3.1.5 (#1594)
  • chore(deps): bump github/codeql-action/init from 4.37.2 to 4.37.3 (#1593)
  • chore(deps): bump github/codeql-action/analyze from 4.37.2 to 4.37.3 (#1592)
  • chore(deps): bump ip-address from 10.2.0 to 10.4.0 (#1589)
  • chore(deps): bump nx from 22.6.2 to 22.7.8 (#1587)
  • chore(deps): bump postcss from 8.5.13 to 8.5.25 (#1583)
Changelog

Sourced from docusaurus-plugin-openapi-docs's changelog.

5.2.0 (2026-08-11)

Minor release adding support for OpenAPI 3.2 hierarchical tags. You can now group the sidebar by tagParent via groupPathsBy, using the new tags[].parent field to build nested tag hierarchies. Also includes a theme fix that bundles code snippet language icons locally (no more external icon requests) and a batch of dependency updates.

🚀 New Feature

  • feat(plugin): support OpenAPI 3.2 hierarchical tags (tags[].parent) (#1603)

🐛 Bug Fix

  • fix(theme): bundle code snippet language icons locally (#1595)

🤖 Dependencies

  • chore(deps): bump the react group across 1 directory with 2 updates (#1590)
  • chore(deps): bump postman-collection from 5.3.0 to 5.3.1 (#1591)
  • chore(deps): bump fast-uri from 3.1.4 to 3.1.5 (#1594)
  • chore(deps): bump github/codeql-action/init from 4.37.2 to 4.37.3 (#1593)
  • chore(deps): bump github/codeql-action/analyze from 4.37.2 to 4.37.3 (#1592)
  • chore(deps): bump ip-address from 10.2.0 to 10.4.0 (#1589)
  • chore(deps): bump nx from 22.6.2 to 22.7.8 (#1587)
  • chore(deps): bump postcss from 8.5.13 to 8.5.25 (#1583)
Commits

Updates docusaurus-theme-openapi-docs from 5.1.3 to 5.2.0

Release notes

Sourced from docusaurus-theme-openapi-docs's releases.

v5.2.0

5.2.0 (2026-08-11)

Minor release adding support for OpenAPI 3.2 hierarchical tags. You can now group the sidebar by tagParent via groupPathsBy, using the new tags[].parent field to build nested tag hierarchies. Also includes a theme fix that bundles code snippet language icons locally (no more external icon requests) and a batch of dependency updates.

🚀 New Feature

  • feat(plugin): support OpenAPI 3.2 hierarchical tags (tags[].parent) (#1603)

🐛 Bug Fix

  • fix(theme): bundle code snippet language icons locally (#1595)

🤖 Dependencies

  • chore(deps): bump the react group across 1 directory with 2 updates (#1590)
  • chore(deps): bump postman-collection from 5.3.0 to 5.3.1 (#1591)
  • chore(deps): bump fast-uri from 3.1.4 to 3.1.5 (#1594)
  • chore(deps): bump github/codeql-action/init from 4.37.2 to 4.37.3 (#1593)
  • chore(deps): bump github/codeql-action/analyze from 4.37.2 to 4.37.3 (#1592)
  • chore(deps): bump ip-address from 10.2.0 to 10.4.0 (#1589)
  • chore(deps): bump nx from 22.6.2 to 22.7.8 (#1587)
  • chore(deps): bump postcss from 8.5.13 to 8.5.25 (#1583)
Changelog

Sourced from docusaurus-theme-openapi-docs's changelog.

5.2.0 (2026-08-11)

Minor release adding support for OpenAPI 3.2 hierarchical tags. You can now group the sidebar by tagParent via groupPathsBy, using the new tags[].parent field to build nested tag hierarchies. Also includes a theme fix that bundles code snippet language icons locally (no more external icon requests) and a batch of dependency updates.

🚀 New Feature

  • feat(plugin): support OpenAPI 3.2 hierarchical tags (tags[].parent) (#1603)

🐛 Bug Fix

  • fix(theme): bundle code snippet language icons locally (#1595)

🤖 Dependencies

  • chore(deps): bump the react group across 1 directory with 2 updates (#1590)
  • chore(deps): bump postman-collection from 5.3.0 to 5.3.1 (#1591)
  • chore(deps): bump fast-uri from 3.1.4 to 3.1.5 (#1594)
  • chore(deps): bump github/codeql-action/init from 4.37.2 to 4.37.3 (#1593)
  • chore(deps): bump github/codeql-action/analyze from 4.37.2 to 4.37.3 (#1592)
  • chore(deps): bump ip-address from 10.2.0 to 10.4.0 (#1589)
  • chore(deps): bump nx from 22.6.2 to 22.7.8 (#1587)
  • chore(deps): bump postcss from 8.5.13 to 8.5.25 (#1583)
Commits

Updates mermaid from 11.16.0 to 11.16.1

Release notes

Sourced from mermaid's releases.

mermaid@11.16.1

Patch Changes

  • #8022 12d472c Thanks @​aloisklink! - fix: handle CSS sibling combinators in compileCSS

  • #8022 2cd6dcf Thanks @​aloisklink! - fix: increase protections against prototype pollution

    User-controlled input already has protections against prototype pollution.

    Fixes: GHSA-c4c3-pg64-4m4v

  • #8022 99af3fc Thanks @​aloisklink! - fix(architecture): use Maps and Sets to store groups/services

    Services are now rendered in the order they are defined and more service IDs are now supported.

  • #8022 2cd6dcf Thanks @​aloisklink! - deprecate: Deprecate the mermaidAPI.setConfig() function

    Calling this function has no observable effect, as the next time a render() or parse() is called, the currentConfig is cleared.

  • #8022 630aa7e Thanks @​aloisklink! - fix(xychart): support zero-width x-axis ranges

  • #8022 59b22fa Thanks @​aloisklink! - fix(radar): limit number of ticks to 32

    Setting a ticks value higher than this would only show 32 ticks.

Commits
  • 7ecca0c Version Packages (#8023)
  • 95b1b9c docs: change mermaidAPI.setConfig() changeset (#8024)
  • acc69f1 Merge pull request #8022 from mermaid-js/release/11.16.1
  • eba7287 docs: point changesets to correct commit hashes
  • 12d472c Merge commit from fork
  • 2cd6dcf Merge commit from fork
  • 630aa7e Merge commit from fork
  • 59b22fa Merge commit from fork
  • 99af3fc Merge commit from fork
  • 2337f7e Merge branch 'test/improve-example.html' into release/11.16.1
  • Additional commits viewable in compare view

Updates js-yaml from 5.2.3 to 5.3.0

Changelog

Sourced from js-yaml's changelog.

[5.3.0] - 2026-08-14

This release focuses on reworking the documentation and making small architectural improvements before moving forward.

Added

  • Added completely new documentation.
  • Exported DUMP_SCHEMA, the default schema used by the dumper.
  • Added YAMLException.throwAt() for throwing an error at a source position.

Changed

  • Changed flat constant exports to grouped exports: EVENT_ID, SCALAR_STYLE, COLLECTION_STYLE, and CHOMPING_MODE, along with their value types. The old exports are still preserved, but deprecated.
  • Made identify mandatory for custom tag definitions. Use identify: () => false for load-only tags.

Deprecated

  • Deprecated flat constant exports. Use grouped ones instead.

Removed

  • Removed the MERGE_KEY export (not used anymore after last fixes).

Fixed

  • Validate << sequence items at merge time, so aliased merge sources are checked too.
  • Resolve << outside of a mapping key as the plain string '<<', matching v4, instead of leaking an internal symbol into the result.
Commits
  • 04db458 5.3.0 released
  • 22ce0a0 Changelog update
  • fae37b8 fix: << outside a mapping key no longer leaks the internal merge symbol
  • b62ef83 fix: validate << sequence items at merge time, so aliased sources are check...
  • cc665ec docs: review and update annotations
  • 2aa24a6 Changelog update
  • eec6902 Restore deprecated parser constant exports
  • 03397ac Move throwErrorAt to YAMLException as throwAt
  • d9dd2c7 docs: new condensed theme
  • 0f898e6 docs: annotation tweaks
  • Additional commits viewable in compare view

Updates oxfmt from 0.62.0 to 0.63.0

Changelog

Sourced from oxfmt's changelog.

Changelog

All notable changes to this package will be documented in this file.

The format is based on Keep a Changelog.

[0.64.0] - 2026-08-18

🚀 Features

  • c07fe7c oxfmt: Support experimentalOperatorPosition (#25643) (leaysgur)

📚 Documentation

  • fed6681 oxfmt: Skip expanding overrides options (#25572) (leaysgur)
Commits
  • c42d639 release(apps): oxlint v1.78.0 && oxfmt v0.63.0 (#25473)
  • 00f490d refactor(oxfmt,formatter): split sortImports validation and use type enum (...
  • See full diff in compare view

Updates oxlint from 1.76.0 to 1.78.0

Changelog

Sourced from oxlint's changelog.

[1.78.0] - 2026-08-10

🚀 Features

  • ccb8fe8 linter/jsdoc: Implement no-blank-blocks rule (#25207) (Mikhail Baev)
  • d4a897c linter/eslint: Implement one-var rule (#24470) (Cole Ellison)
  • 5ab9340 linter/jsx-a11y/anchor-has-content: Add options to match eslint (#24571) (Cole Ellison)

🐛 Bug Fixes

  • 9573937 linter/typescript: Validate ban-ts-comment description_format (#25320) (Mikhail Baev)

[1.77.0] - 2026-08-03

🐛 Bug Fixes

  • 5c0fa61 linter/eslint/no-warning-comments: Unify config structs and remove manual options docs (#25151) (Mikhail Baev)

📚 Documentation

  • 9dc7756 linter/typescript/no-unnecessary-condition: Clarify options (#25110) (camc314)
Commits
  • c42d639 release(apps): oxlint v1.78.0 && oxfmt v0.63.0 (#25473)
  • ccb8fe8 feat(linter/jsdoc): implement no-blank-blocks rule (#25207)
  • 9573937 fix(linter/typescript): validate ban-ts-comment description_format (

Bumps the npm group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@mui/icons-material](https://github.com/mui/material-ui/tree/HEAD/packages/mui-icons-material) | `9.2.0` | `9.3.1` |
| [@mui/x-data-grid](https://github.com/mui/mui-x/tree/HEAD/packages/x-data-grid) | `9.10.1` | `9.11.0` |
| [docusaurus-plugin-openapi-docs](https://github.com/PaloAltoNetworks/docusaurus-openapi-docs/tree/HEAD/packages/docusaurus-plugin-openapi-docs) | `5.1.3` | `5.2.0` |
| [docusaurus-theme-openapi-docs](https://github.com/PaloAltoNetworks/docusaurus-openapi-docs/tree/HEAD/packages/docusaurus-theme-openapi-docs) | `5.1.3` | `5.2.0` |
| [mermaid](https://github.com/mermaid-js/mermaid) | `11.16.0` | `11.16.1` |
| [js-yaml](https://github.com/nodeca/js-yaml) | `5.2.3` | `5.3.0` |
| [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.62.0` | `0.63.0` |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.76.0` | `1.78.0` |



Updates `@mui/icons-material` from 9.2.0 to 9.3.1
- [Release notes](https://github.com/mui/material-ui/releases)
- [Changelog](https://github.com/mui/material-ui/blob/master/CHANGELOG.md)
- [Commits](https://github.com/mui/material-ui/commits/v9.3.1/packages/mui-icons-material)

Updates `@mui/material` from 9.2.0 to 9.3.1
- [Release notes](https://github.com/mui/material-ui/releases)
- [Changelog](https://github.com/mui/material-ui/blob/master/CHANGELOG.md)
- [Commits](https://github.com/mui/material-ui/commits/v9.3.1/packages/mui-material)

Updates `@mui/x-data-grid` from 9.10.1 to 9.11.0
- [Release notes](https://github.com/mui/mui-x/releases)
- [Changelog](https://github.com/mui/mui-x/blob/master/CHANGELOG.md)
- [Commits](https://github.com/mui/mui-x/commits/v9.11.0/packages/x-data-grid)

Updates `docusaurus-plugin-openapi-docs` from 5.1.3 to 5.2.0
- [Release notes](https://github.com/PaloAltoNetworks/docusaurus-openapi-docs/releases)
- [Changelog](https://github.com/PaloAltoNetworks/docusaurus-openapi-docs/blob/main/CHANGELOG.md)
- [Commits](https://github.com/PaloAltoNetworks/docusaurus-openapi-docs/commits/v5.2.0/packages/docusaurus-plugin-openapi-docs)

Updates `docusaurus-theme-openapi-docs` from 5.1.3 to 5.2.0
- [Release notes](https://github.com/PaloAltoNetworks/docusaurus-openapi-docs/releases)
- [Changelog](https://github.com/PaloAltoNetworks/docusaurus-openapi-docs/blob/main/CHANGELOG.md)
- [Commits](https://github.com/PaloAltoNetworks/docusaurus-openapi-docs/commits/v5.2.0/packages/docusaurus-theme-openapi-docs)

Updates `mermaid` from 11.16.0 to 11.16.1
- [Release notes](https://github.com/mermaid-js/mermaid/releases)
- [Commits](https://github.com/mermaid-js/mermaid/compare/mermaid@11.16.0...mermaid@11.16.1)

Updates `js-yaml` from 5.2.3 to 5.3.0
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@5.2.3...5.3.0)

Updates `oxfmt` from 0.62.0 to 0.63.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.63.0/npm/oxfmt)

Updates `oxlint` from 1.76.0 to 1.78.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.78.0/npm/oxlint)

---
updated-dependencies:
- dependency-name: "@mui/icons-material"
  dependency-version: 9.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@mui/material"
  dependency-version: 9.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@mui/x-data-grid"
  dependency-version: 9.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: docusaurus-plugin-openapi-docs
  dependency-version: 5.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: docusaurus-theme-openapi-docs
  dependency-version: 5.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: mermaid
  dependency-version: 11.16.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: js-yaml
  dependency-version: 5.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: oxfmt
  dependency-version: 0.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: oxlint
  dependency-version: 1.78.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 20, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 20, 2026 19:16
@dependabot
dependabot Bot requested review from kenjenkins and removed request for a team August 20, 2026 19:16
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 20, 2026
@netlify

netlify Bot commented Aug 20, 2026

Copy link
Copy Markdown

Deploy Preview for pomerium-docs ready!

Name Link
🔨 Latest commit 62a4390
🔍 Latest deploy log https://app.netlify.com/projects/pomerium-docs/deploys/6a875822c6f9b500088f60e8
😎 Deploy Preview https://deploy-preview-2350--pomerium-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@nickytonline
nickytonline force-pushed the dependabot/npm_and_yarn/npm-050b24acd9 branch from 6062e40 to 62a4390 Compare August 20, 2026 19:40
@nickytonline
nickytonline merged commit 23fff09 into main Aug 20, 2026
10 checks passed
@nickytonline

Copy link
Copy Markdown
Member

While debugging the failing `pre-commit` check here, we found that the CI `npm ci` failure was caused by an npm version mismatch, not an out-of-sync lockfile:

  • CI resolves Node via `.tool-versions` (pinned to `22.22.0`), which bundles npm 10.9.4.
  • Local dev machines are commonly on npm 11.x, which resolves an optional nested dependency subtree (`hast-util-to-estree`'s optional dependency on `unist-util-visit`/`unist-util-visit-parents`) differently than npm 10.9.4. npm 11 tolerates the gap; npm 10.9.4 hard-fails `npm ci` on it.
  • Reproduced directly: `npx -y npm@10.9.4 ci` fails locally with the same error CI produces, even against a freshly regenerated lockfile; `npm ci` with npm 11.13.0 succeeds.

Filed ENG-4332 to standardize this repo on npm 11 for both CI and local dev, matching other Pomerium projects.

@nickytonline
nickytonline deleted the dependabot/npm_and_yarn/npm-050b24acd9 branch August 20, 2026 19:42
nickytonline added a commit that referenced this pull request Aug 21, 2026
Node 24 bundles npm 11 by default (24.19.0 ships npm 11.17.0),
matching the convention already used in pomerium/pomerium. This
makes the curl-based "install npm 11.12.1" workaround in
pre-commit.yml and npm-audit-signatures.yml unnecessary — it was
only needed because Node 22 bundles npm 10, and `corepack enable`
does not shim npm on its own (only yarn/pnpm).

- .tool-versions: nodejs 22.22.0 -> 24.19.0
- pre-commit.yml, npm-audit-signatures.yml: drop the manual npm
  install/verify steps, rely on Node's bundled npm
- package.json: bump engines.node floor to >=24.0.0 (the version
  where npm 11 becomes bundled), so it reflects what's actually
  required to avoid the npm 10 lockfile-resolution gap from #2350

Verified locally under node 24.19.0 (bundled npm 11.17.0): npm ci,
npm ci --ignore-scripts, and npm audit signatures --min-release-age=0
all pass.

Follow-up to #2351, in response to review feedback questioning why
Node wasn't just bumped to get npm 11 natively.

AI usage: Claude Code (Sonnet 5) investigated the fix, confirmed
against pomerium/pomerium's convention and Node's release metadata,
and verified the change locally; changes reviewed by Nick Taylor.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
nickytonline added a commit that referenced this pull request Aug 25, 2026
* ci: standardize on npm 11 with min-release-age gate

Fixes a pre-commit CI failure on PR #2350 where npm ci errored with
"Missing: unist-util-visit@4.1.2 from lock file" — Node's bundled npm
10.9.4 resolves an optional nested dependency subtree differently than
npm 11 (hast-util-to-estree's optional dependency on unist-util-visit/
unist-util-visit-parents), and hard-fails on the gap where npm 11
tolerates it.

Also brings this repo in line with the npm 11 + min-release-age
supply-chain hardening rolled out to other Pomerium repos (npm 10
silently ignores min-release-age, so npm 11 is required for it to
take effect at all):

- .npmrc: min-release-age=3
- package.json: engines.npm and packageManager pinned to npm 11.12.1
- pre-commit.yml: installs npm 11.12.1 before npm ci
- npm-audit-signatures.yml: new workflow, verifies registry signatures
  and provenance attestations on package.json/package-lock.json changes

Regenerated package-lock.json with npm 11.12.1.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* chore: trigger build

* ci: enable corepack so nested yarn postinstall scripts work

npm ci was failing because postman-code-generators (a transitive dep
of docusaurus-theme-openapi-docs) shells out to `yarn install` from
its postinstall script. Node's bundled corepack shim for yarn refuses
to run once package.json declares a "packageManager" field (added in
1c198e6 for npm 11), even though that field only pins npm -- it just
needs `corepack enable` to be run first, as its own error message
says.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant