Build(deps): Bump the npm group across 1 directory with 9 updates - #2350
Merged
Conversation
Bumps the npm group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@mui/icons-material](https://github.com/mui/material-ui/tree/HEAD/packages/mui-icons-material) | `9.2.0` | `9.3.1` | | [@mui/x-data-grid](https://github.com/mui/mui-x/tree/HEAD/packages/x-data-grid) | `9.10.1` | `9.11.0` | | [docusaurus-plugin-openapi-docs](https://github.com/PaloAltoNetworks/docusaurus-openapi-docs/tree/HEAD/packages/docusaurus-plugin-openapi-docs) | `5.1.3` | `5.2.0` | | [docusaurus-theme-openapi-docs](https://github.com/PaloAltoNetworks/docusaurus-openapi-docs/tree/HEAD/packages/docusaurus-theme-openapi-docs) | `5.1.3` | `5.2.0` | | [mermaid](https://github.com/mermaid-js/mermaid) | `11.16.0` | `11.16.1` | | [js-yaml](https://github.com/nodeca/js-yaml) | `5.2.3` | `5.3.0` | | [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.62.0` | `0.63.0` | | [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.76.0` | `1.78.0` | Updates `@mui/icons-material` from 9.2.0 to 9.3.1 - [Release notes](https://github.com/mui/material-ui/releases) - [Changelog](https://github.com/mui/material-ui/blob/master/CHANGELOG.md) - [Commits](https://github.com/mui/material-ui/commits/v9.3.1/packages/mui-icons-material) Updates `@mui/material` from 9.2.0 to 9.3.1 - [Release notes](https://github.com/mui/material-ui/releases) - [Changelog](https://github.com/mui/material-ui/blob/master/CHANGELOG.md) - [Commits](https://github.com/mui/material-ui/commits/v9.3.1/packages/mui-material) Updates `@mui/x-data-grid` from 9.10.1 to 9.11.0 - [Release notes](https://github.com/mui/mui-x/releases) - [Changelog](https://github.com/mui/mui-x/blob/master/CHANGELOG.md) - [Commits](https://github.com/mui/mui-x/commits/v9.11.0/packages/x-data-grid) Updates `docusaurus-plugin-openapi-docs` from 5.1.3 to 5.2.0 - [Release notes](https://github.com/PaloAltoNetworks/docusaurus-openapi-docs/releases) - [Changelog](https://github.com/PaloAltoNetworks/docusaurus-openapi-docs/blob/main/CHANGELOG.md) - [Commits](https://github.com/PaloAltoNetworks/docusaurus-openapi-docs/commits/v5.2.0/packages/docusaurus-plugin-openapi-docs) Updates `docusaurus-theme-openapi-docs` from 5.1.3 to 5.2.0 - [Release notes](https://github.com/PaloAltoNetworks/docusaurus-openapi-docs/releases) - [Changelog](https://github.com/PaloAltoNetworks/docusaurus-openapi-docs/blob/main/CHANGELOG.md) - [Commits](https://github.com/PaloAltoNetworks/docusaurus-openapi-docs/commits/v5.2.0/packages/docusaurus-theme-openapi-docs) Updates `mermaid` from 11.16.0 to 11.16.1 - [Release notes](https://github.com/mermaid-js/mermaid/releases) - [Commits](https://github.com/mermaid-js/mermaid/compare/mermaid@11.16.0...mermaid@11.16.1) Updates `js-yaml` from 5.2.3 to 5.3.0 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](nodeca/js-yaml@5.2.3...5.3.0) Updates `oxfmt` from 0.62.0 to 0.63.0 - [Release notes](https://github.com/oxc-project/oxc/releases) - [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md) - [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.63.0/npm/oxfmt) Updates `oxlint` from 1.76.0 to 1.78.0 - [Release notes](https://github.com/oxc-project/oxc/releases) - [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md) - [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.78.0/npm/oxlint) --- updated-dependencies: - dependency-name: "@mui/icons-material" dependency-version: 9.3.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm - dependency-name: "@mui/material" dependency-version: 9.3.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm - dependency-name: "@mui/x-data-grid" dependency-version: 9.11.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm - dependency-name: docusaurus-plugin-openapi-docs dependency-version: 5.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm - dependency-name: docusaurus-theme-openapi-docs dependency-version: 5.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm - dependency-name: mermaid dependency-version: 11.16.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm - dependency-name: js-yaml dependency-version: 5.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm - dependency-name: oxfmt dependency-version: 0.63.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm - dependency-name: oxlint dependency-version: 1.78.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
requested review from
kenjenkins
and removed request for
a team
August 20, 2026 19:16
✅ Deploy Preview for pomerium-docs ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
nickytonline
approved these changes
Aug 20, 2026
nickytonline
approved these changes
Aug 20, 2026
nickytonline
force-pushed
the
dependabot/npm_and_yarn/npm-050b24acd9
branch
from
August 20, 2026 19:40
6062e40 to
62a4390
Compare
Member
|
While debugging the failing `pre-commit` check here, we found that the CI `npm ci` failure was caused by an npm version mismatch, not an out-of-sync lockfile:
Filed ENG-4332 to standardize this repo on npm 11 for both CI and local dev, matching other Pomerium projects. |
2 tasks
nickytonline
added a commit
that referenced
this pull request
Aug 21, 2026
Node 24 bundles npm 11 by default (24.19.0 ships npm 11.17.0), matching the convention already used in pomerium/pomerium. This makes the curl-based "install npm 11.12.1" workaround in pre-commit.yml and npm-audit-signatures.yml unnecessary — it was only needed because Node 22 bundles npm 10, and `corepack enable` does not shim npm on its own (only yarn/pnpm). - .tool-versions: nodejs 22.22.0 -> 24.19.0 - pre-commit.yml, npm-audit-signatures.yml: drop the manual npm install/verify steps, rely on Node's bundled npm - package.json: bump engines.node floor to >=24.0.0 (the version where npm 11 becomes bundled), so it reflects what's actually required to avoid the npm 10 lockfile-resolution gap from #2350 Verified locally under node 24.19.0 (bundled npm 11.17.0): npm ci, npm ci --ignore-scripts, and npm audit signatures --min-release-age=0 all pass. Follow-up to #2351, in response to review feedback questioning why Node wasn't just bumped to get npm 11 natively. AI usage: Claude Code (Sonnet 5) investigated the fix, confirmed against pomerium/pomerium's convention and Node's release metadata, and verified the change locally; changes reviewed by Nick Taylor. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
nickytonline
added a commit
that referenced
this pull request
Aug 25, 2026
* ci: standardize on npm 11 with min-release-age gate Fixes a pre-commit CI failure on PR #2350 where npm ci errored with "Missing: unist-util-visit@4.1.2 from lock file" — Node's bundled npm 10.9.4 resolves an optional nested dependency subtree differently than npm 11 (hast-util-to-estree's optional dependency on unist-util-visit/ unist-util-visit-parents), and hard-fails on the gap where npm 11 tolerates it. Also brings this repo in line with the npm 11 + min-release-age supply-chain hardening rolled out to other Pomerium repos (npm 10 silently ignores min-release-age, so npm 11 is required for it to take effect at all): - .npmrc: min-release-age=3 - package.json: engines.npm and packageManager pinned to npm 11.12.1 - pre-commit.yml: installs npm 11.12.1 before npm ci - npm-audit-signatures.yml: new workflow, verifies registry signatures and provenance attestations on package.json/package-lock.json changes Regenerated package-lock.json with npm 11.12.1. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * chore: trigger build * ci: enable corepack so nested yarn postinstall scripts work npm ci was failing because postman-code-generators (a transitive dep of docusaurus-theme-openapi-docs) shells out to `yarn install` from its postinstall script. Node's bundled corepack shim for yarn refuses to run once package.json declares a "packageManager" field (added in 1c198e6 for npm 11), even though that field only pins npm -- it just needs `corepack enable` to be run first, as its own error message says. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm group with 8 updates in the / directory:
9.2.09.3.19.10.19.11.05.1.35.2.05.1.35.2.011.16.011.16.15.2.35.3.00.62.00.63.01.76.01.78.0Updates
@mui/icons-materialfrom 9.2.0 to 9.3.1Release notes
Sourced from @mui/icons-material's releases.
... (truncated)
Changelog
Sourced from @mui/icons-material's changelog.
... (truncated)
Commits
5b91ac7[release] v9.3.1 (#48935)da37c08v9.3.0 (#48909)2e38eb7Bump chalk to 6.0.0 (#48902)20fe2b6Bump code-infra:devDependencies (#48891)a900cd7Bump react monorepo to 19.2.8 (#48858)8cbc3ceBump code-infra:devDependencies (#48830)a5faab5Bump react monorepo (#48770)ca10194Bump code-infra:devDependencies (#48767)620c9e9Bump babel monorepo to ^7.29.7 (#48766)Updates
@mui/materialfrom 9.2.0 to 9.3.1Release notes
Sourced from @mui/material's releases.
... (truncated)
Changelog
Sourced from @mui/material's changelog.
... (truncated)
Commits
5b91ac7[release] v9.3.1 (#48935)a13824f[transitions] Prevent exit transitions from getting stuck (#48881)54e1993[test][pagination] Add more unit tests (#48927)da37c08v9.3.0 (#48909)0bb0259[tablepagination] Add focus style to default InputBase used in Select (#48871)20fe2b6Bump code-infra:devDependencies (#48891)7fb0110[togglebuttongroup] Add roving tabindex keyboard navigation (#48849)3dfeb20[internal] Fix typos in ListItemButton component code (#48868)27f46faBump@types/sinonto 22.0.0 (#48865)a900cd7Bump react monorepo to 19.2.8 (#48858)Updates
@mui/x-data-gridfrom 9.10.1 to 9.11.0Release notes
Sourced from @mui/x-data-grid's releases.
... (truncated)
Changelog
Sourced from @mui/x-data-grid's changelog.
... (truncated)
Commits
0486f84[release] v9.11.0 (#23295)eacd695[docs] Replace README peer dependency lists with an npm install command (#23256)77536d2[DataGrid] Do not re-fetch data when an Activity becomes visible (#22603)1ba29f4[DataGrid] Fix toolbar button stealing focus when a sibling's disabled state ...bbff8c0[data grid] FixupdateRowsstripping class prototypes from rows in datasour...Updates
docusaurus-plugin-openapi-docsfrom 5.1.3 to 5.2.0Release notes
Sourced from docusaurus-plugin-openapi-docs's releases.
Changelog
Sourced from docusaurus-plugin-openapi-docs's changelog.
Commits
3fa7008Prepare release v5.2.0 (#1604)7950480feat(plugin): support OpenAPI 3.2 hierarchical tags (tags[].parent) (#1603)Updates
docusaurus-theme-openapi-docsfrom 5.1.3 to 5.2.0Release notes
Sourced from docusaurus-theme-openapi-docs's releases.
Changelog
Sourced from docusaurus-theme-openapi-docs's changelog.
Commits
3fa7008Prepare release v5.2.0 (#1604)12ce651fix(theme): bundle code snippet language icons locally (#1595)Updates
mermaidfrom 11.16.0 to 11.16.1Release notes
Sourced from mermaid's releases.
Commits
7ecca0cVersion Packages (#8023)95b1b9cdocs: changemermaidAPI.setConfig()changeset (#8024)acc69f1Merge pull request #8022 from mermaid-js/release/11.16.1eba7287docs: point changesets to correct commit hashes12d472cMerge commit from fork2cd6dcfMerge commit from fork630aa7eMerge commit from fork59b22faMerge commit from fork99af3fcMerge commit from fork2337f7eMerge branch 'test/improve-example.html' into release/11.16.1Updates
js-yamlfrom 5.2.3 to 5.3.0Changelog
Sourced from js-yaml's changelog.
Commits
04db4585.3.0 released22ce0a0Changelog updatefae37b8fix:<<outside a mapping key no longer leaks the internal merge symbolb62ef83fix: validate<<sequence items at merge time, so aliased sources are check...cc665ecdocs: review and update annotations2aa24a6Changelog updateeec6902Restore deprecated parser constant exports03397acMove throwErrorAt to YAMLException as throwAtd9dd2c7docs: new condensed theme0f898e6docs: annotation tweaksUpdates
oxfmtfrom 0.62.0 to 0.63.0Changelog
Sourced from oxfmt's changelog.
Commits
c42d639release(apps): oxlint v1.78.0 && oxfmt v0.63.0 (#25473)00f490drefactor(oxfmt,formatter): splitsortImportsvalidation and use type enum (...Updates
oxlintfrom 1.76.0 to 1.78.0Changelog
Sourced from oxlint's changelog.
Commits
c42d639release(apps): oxlint v1.78.0 && oxfmt v0.63.0 (#25473)ccb8fe8feat(linter/jsdoc): implementno-blank-blocksrule (#25207)9573937fix(linter/typescript): validateban-ts-commentdescription_format (