Skip to content

chore(deps): bump lucide-react from 1.17.0 to 1.18.0 - #33

Merged
BigSimmo merged 1 commit into
mainfrom
dependabot/npm_and_yarn/lucide-react-1.18.0
Jun 17, 2026
Merged

chore(deps): bump lucide-react from 1.17.0 to 1.18.0#33
BigSimmo merged 1 commit into
mainfrom
dependabot/npm_and_yarn/lucide-react-1.18.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 15, 2026

Copy link
Copy Markdown
Contributor

Bumps lucide-react from 1.17.0 to 1.18.0.

Release notes

Sourced from lucide-react's releases.

Version 1.18.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.17.0...1.18.0

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) from 1.17.0 to 1.18.0.
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.18.0/packages/lucide-react)

---
updated-dependencies:
- dependency-name: lucide-react
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 15, 2026
@BigSimmo
BigSimmo merged commit 3893b80 into main Jun 17, 2026
5 of 8 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/lucide-react-1.18.0 branch June 17, 2026 07:52
BigSimmo added a commit that referenced this pull request Jul 22, 2026
Co-authored-by: Cursor <cursoragent@cursor.com>
BigSimmo added a commit that referenced this pull request Jul 31, 2026
* issues: capture the unreadable-CI token, at-risk worktree work, and the unpushed hook fix

Three findings from the 2026-07-30 organisation session that were recorded
nowhere durable:

- #149 the session GitHub PAT lacks Checks: Read, so no agent can confirm a PR
  is green. The endpoint that does work returns an empty result rather than an
  error, so it reads like an absence of checks rather than an absence of
  permission.
- #150 four worktrees on already-merged branches hold uncommitted work that
  exists in no branch and no PR, the largest being +395/-200 across 19 files
  including CI config.
- #151 the pre-commit fail-open for #143 lives only on a never-pushed local
  branch, which is also 17 behind main and conflicts on the file whose count
  sentence main's new docs:update generator now owns.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(ledger): record the session-followup capture review for PR #1490

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(ledger): record #143/#151/#149 reconciliation for PR #1490

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* docs(ledger): supersede PR #1490 reconciliation after remote sync

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* issues: record the worktree snapshots and redirect #151 to PR #1494

#150 — the four at-risk worktrees were snapshotted onto their own already-merged
branches (748ef018f, 5dbd9f965, b7eae51a4, d949859c3), so the work survives a
worktree reclaim. All four are clean now. None is pushed or reviewed; the next
action is per-snapshot promote-or-reset.

#151 — the never-pushed branch is superseded rather than salvageable: its script
and hook reached main by other routes, so the fail-open guard was applied to
main's committed hook in PR #1494 instead.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs: remove credential metadata and correct audit dates

* docs: consolidate session follow-up findings

* docs: record consolidated follow-up review

* issues: record that #101 hydration shipped

PR #1463 merged as dba7356, so #86's "Next X3 unit — rag-hydration.ts" is
now stale. The row records the extraction as shipped and keeps the corrected
boundary: hydration re-homed only two of prepareCoverageGateResults's five
rag.ts-only dependencies, so it did not unblock that function — exactly as the
Codex review on PR #1461 predicted.

This row was deliberately dropped from #1463 itself (commit 6290d02) after
docs/outstanding-issues.md conflicted on five consecutive main syncs. Recording
it separately here is the same pattern used for #1454 via #1461.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GGEBHp4Seoh1jK1vGTNtYS

* docs(ledger): record the landed X3 hydration review

Appended with npm run ledger:append (never hand-written), keyed to the squash
commit dba7356 so ledger:lookup can resolve it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GGEBHp4Seoh1jK1vGTNtYS

* docs: fix the #101 mislabel and key the ledger row to a resolvable ref

Both defects were raised by Codex on PR #1495 and both are real; verified
against the files before accepting.

1. #101 is NOT this extraction. docs/outstanding-issues.md:138 shows #101 is
   "Canary-gated retrieval parallelisation candidates" (P3, rec) — a separate,
   still-open recommendation gated on a live canary pair. Calling the hydration
   extraction "#101" marked that unrelated work as shipped and could have caused
   the live-evaluation work to be skipped. The label came from the original task
   brief and was propagated without checking it against the ledger. Both the
   #86 row and the X3 work-order entry now identify the change as the X3
   hydration unit (PR #1463) instead. #101's own row is untouched and still open.

2. The ledger row did not resolve. `npm run ledger:lookup --
   dba7356` returned NOT REVIEWED, because the
   ref cell held only the slash-form branch token and that branch no longer
   resolves locally, so the throttling record could not prevent a repeat review.
   Appended a superseding record keyed to the landed SHA; the same lookup now
   returns ALREADY REVIEWED. The original row is retained, per the ledger's
   append-only rule.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GGEBHp4Seoh1jK1vGTNtYS

* docs: record consolidated PR reviews

* docs: record ingestion recovery review

* docs(visual): document the platform-scoped baseline layout and how to seed it

`playwright.visual.config.ts` records snapshots under
`__screenshots__/{platform}/`, so a baseline taken on Windows lands in `win32/`
and is never consulted by the `ubuntu-24.04` CI job, which reads `linux/`.
Nothing said so, and committing `win32/` images looks like protection while
providing none.

Records the constraint, names the CI artifact as the supported recorder for
`linux/` baselines, and notes that comparison stays advisory until the jobs come
off `continue-on-error`. Also creates the tracked directory `.gitignore` already
claims exists, which sets `ui_changed=true` (`scripts/ci-change-scope.mjs`) so
the visual job can run and produce that first artifact.

No baselines are added here — they cannot be produced on this platform.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs: correct visual baseline adoption steps

* docs: record visual baseline guidance review

* fix(ui): repair mockup accent token references

* docs: record token-reference repair review

* docs: archive advisory UI scoping task

* docs: record advisory UI closure review

* issues: archive #151 after #1494 and mark #143 fully resolved

PR #1494 landed the fail-open guard on main, so close the open salvage
row and update the #143 archive from PARTIAL to resolved across #1442
and #1494. Also carries the merge of origin/main that cleared the
GitHub DIRTY mergeability state.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* docs(ledger): record PR #1490 main-sync and #151 closeout

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* docs(ledger): record #1496 id-collision renumber for PR #1490

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* issues: record the withdrawn live-region finding as #151 so it is not re-filed

Archive-only row. There is no defect and no work to do — the row exists purely
as a guard rail against repeating a misreading that already happened once.

search-results-header-band.tsx sets aria-live={faulted ? "off" : "polite"} on
its count/status span, which reads like a silenced failure announcement. It is
not: the band mounts a separate fault panel with role="alert" carrying the
failure title, body and Retry, and the mute is deliberate so the two do not both
speak. The reasoning is in a comment directly above the attribute, and
tests/search-results-header-band.dom.test.tsx pins it with singular role queries
that throw on duplicates.

During session 2026-07-30 (PR #1481) this was filed as a real P2 defect on the
strength of the attribute alone, and the proposed fix — escalating the count span
to role="alert"/aria-live="assertive" — would have produced a duplicate
announcement and a red test, making it worse than no change. Codex caught it.
An earlier withdrawal row was then lost to the squash that merged #1481, which
is the row-deletion shape #148 now guards against.

Also records that the mockup's escalation is correct in the mockup and must not
be ported: search-refine-adaptive-mockups.tsx has no fault panel, so there the
count span is the only announcement channel.

#148 needed no work — the merge-base deletion check landed on main
independently, and its output now reports the base it compared against.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JdPa3mHCX5ZQZZvU5GHU3r

* docs(rag): record refuted lexical probe collapse (#98)

* issues: capture the residual id-allocation hazard as #151

#133 is resolved: #1444 removed merge=union and #1479 excluded the ledger from
Prettier, which together fixed conflict frequency. Neither changes id
allocation, which is still read-modify-write against the next-id marker, so
concurrent branches still claim the same number.

Measured on PR #1451: one row was renumbered #135 -> #141 -> #145 -> #147 ->
#149 across four sync cycles. The sharper finding is that GitHub's Update-branch
button resolved one such collision into duplicate #141 rows with the marker left
below main's highest id — git reported success and only
check:outstanding-issues caught it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(issues): attribute the mobile CLS breach — a 128px reserve round trip

#147 asked which elements shift. Driving Chromium against the same
offline production build with a PerformanceObserver on layout-shift
(Lighthouse mobile emulation, reading entry.sources[].node) gives one
dominant cause on all four breaching routes: the entire main content
region moves down 128px and straight back up 128px within 15-60ms. Both
moves score, so it is pure cost with zero net movement — 100% of
/documents/search's 0.220 and about 75% of /dsm's.

The shifting element is the max-sm:pt-[var(--phone-overlay-chrome-h)]
wrapper around <main>. A MutationObserver timeline on the root style
attribute pins the mechanism rather than inferring it: the property goes
CSS seed -> 200px -> 72px, and the 200px is written when the header
stack ALREADY measures 72px (t=1552ms reserve=200px stack=72, corrected
at t=1612ms). usePhoneOverlayChromeReserve reads stack.offsetHeight
while the stack is transiently tall, publishes a value that is stale by
the time it lands, and its ResizeObserver then corrects it.

The CSS seed at globals.css:375 is correct for the settled stack, which
corrects the mechanism recorded on the now-archived #130 — that framed
the defect as the seed under-reserving by 0-8px. Measured, the driver is
a 128px transient over-reserve written by the hook, not the seed. / is
the control: it never writes the property and is the one clean route.

Variance is stated rather than smoothed: /dsm measured 0.363 and 0.219
across two runs, and this harness has no network throttling so /forms
and /therapy-compass run high locally. Only /dsm, /documents/search and
/ reproduced the live dispatch exactly.

Also recorded: attaching a MutationObserver to document.documentElement
inside a Playwright addInitScript throws before the document element
exists, silently killing the CLS observer and reporting a uniform
CLS=0.000 — a false clean bill that voided one run of this harness.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01361jh3eYVjJCzXWjAhdZiF

* docs(ledger): record the #151 capture review for PR #1506

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(review): clarify snapshot branch state

* docs(ledger): record PR #1490 main sync after snapshot wording

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* docs: archive rendered style contract task

* docs: record style contract closure review

* docs: record synced style contract review

* docs: record post-121 style closure review

* docs: normalize style review ledger after sync

* docs: record post-1490 style closure review

* docs: record consolidated PR 1490 review

* docs: record replacement consolidation review

* docs: record reconciled consolidation review

* docs: record post-1511 consolidation review

* docs: normalize PR 1510 ledger after main sync

* docs: record PR 1510 post-sync review

* docs: correct false #98 canary evidence and NOTES triage

Remove the incorrect probe-collapse canary attribution from #98 and
point the unread --med-accent-soft note at #157 without breaking the
seven-token TOKENS_MISSING accounting.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* docs(ledger): record PR #1510 evidence-correction review

Supersede the prior approve-with-no-findings row after correcting the
false #98 canary attribution and NOTES triage drift.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* docs: keep concurrency note inside issue table

* docs: record post-1513 consolidation review

* docs: address CodeRabbit notes on PR #1510

Fix the computed-value-time wording in design-sync notes, give #33 a
unique recommended-queue order, and drop the duplicated #98 Done block.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* docs(ledger): record PR #1510 CodeRabbit fix review

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant