Repository navigation
Conversation
…ons for legend field
There was a problem hiding this comment.
Pull request overview
Adds support for an optional rich-text legend on artwork images (persisted in DB and editable in admin UI), while also updating several dependencies and CI/automation configuration.
Changes:
- Add
legendfield toArtworkImageacross Prisma, Zod schemas, create/update actions, and admin image upload UI. - Render image legends (and adjust source rendering) in the artwork images carousel.
- Upgrade multiple dependencies and modify CI configuration (security audit job commented out) and remove Dependabot config.
Reviewed changes
Copilot reviewed 11 out of 12 changed files in this pull request and generated 5 comments.
Show a summary per file
| File | Description |
|---|---|
| src/schemas/artwork-image.ts | Extends artwork image schemas/types with nullable legend. |
| src/features/artworks/components/artwork-images-carousel.tsx | Displays legend and source under carousel images. |
| src/features/artworks/components/admin/image-upload.tsx | Adds admin editing UI for image legend and initializes legend on upload. |
| src/features/artworks/actions/update-artwork.ts | Persists legend when updating artwork images. |
| src/features/artworks/actions/create-artwork.ts | Persists legend when creating artwork images. |
| src/components/ui/rich-text-editor.tsx | Enables alignment toolbar in single-line config; introduces debug logging. |
| prisma/schema.prisma | Adds legend column to ArtworkImage model. |
| prisma/migrations/20260125101040_add_image_legend/migration.sql | Migration to add legend column to artwork_image. |
| package.json | Dependency upgrades (Next/Prisma/Tiptap/etc.) and overrides update. |
| .github/workflows/ci.yml | Security audit job commented out. |
| .github/dependabot.yml | Removed Dependabot configuration. |
| <div className="text-xs text-muted-foreground"> | ||
| <span className="font-medium">Source: </span> | ||
| <span className="prose prose-xs dark:prose-invert inline"> | ||
| <RichTextViewer content={artworkImage.source} /> | ||
| </div> | ||
| </span> |
There was a problem hiding this comment.
RichTextViewer renders a block-level <div> wrapper. Wrapping it in a <span> here creates invalid HTML (div inside span) and can break typography/layout. Use a block wrapper (e.g. <div>) and style it via RichTextViewer's className prop or outer container instead of an inline <span>.
| # security-audit: | ||
| # name: Security Audit | ||
| # runs-on: ubuntu-latest | ||
| # steps: | ||
| # - name: Checkout code | ||
| # uses: actions/checkout@v5 | ||
|
|
||
| # - name: Setup pnpm | ||
| # uses: pnpm/action-setup@v4 | ||
| # with: | ||
| # version: ${{ env.PNPM_VERSION }} | ||
|
|
||
| # - name: Setup Node.js | ||
| # uses: actions/setup-node@v5 | ||
| # with: | ||
| # node-version: ${{ env.NODE_VERSION }} | ||
| # cache: 'pnpm' | ||
|
|
||
| # - name: Install dependencies | ||
| # run: pnpm install --frozen-lockfile | ||
|
|
||
| # - name: Run security audit | ||
| # run: pnpm audit --audit-level moderate |
There was a problem hiding this comment.
The security audit job is currently commented out, which removes an important CI safety net for vulnerable dependencies. If audits are too noisy, consider keeping the job enabled with an adjusted threshold, ignoring known advisories, or running it on a schedule rather than disabling it entirely.
| # security-audit: | |
| # name: Security Audit | |
| # runs-on: ubuntu-latest | |
| # steps: | |
| # - name: Checkout code | |
| # uses: actions/checkout@v5 | |
| # - name: Setup pnpm | |
| # uses: pnpm/action-setup@v4 | |
| # with: | |
| # version: ${{ env.PNPM_VERSION }} | |
| # - name: Setup Node.js | |
| # uses: actions/setup-node@v5 | |
| # with: | |
| # node-version: ${{ env.NODE_VERSION }} | |
| # cache: 'pnpm' | |
| # - name: Install dependencies | |
| # run: pnpm install --frozen-lockfile | |
| # - name: Run security audit | |
| # run: pnpm audit --audit-level moderate | |
| security-audit: | |
| name: Security Audit | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v5 | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@v4 | |
| with: | |
| version: ${{ env.PNPM_VERSION }} | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v5 | |
| with: | |
| node-version: ${{ env.NODE_VERSION }} | |
| cache: 'pnpm' | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| - name: Run security audit | |
| run: pnpm audit --audit-level moderate |
| "lucide-react": "^0.563.0", | ||
| "next": "16.1.4", | ||
| "next-themes": "^0.4.6", | ||
| "prisma": "^7.1.0", | ||
| "prisma": "^7.3.0", |
There was a problem hiding this comment.
The PR description is still the default template and doesn’t explain the intent of the changes (new image legend field + broad dependency/CI config changes). Please update the PR description with what was done, why, and any rollout/migration notes.
| "overrides": { | ||
| "hono": ">=4.10.3", | ||
| "hono": ">=4.11.4", | ||
| "valibot": ">=1.2.0", | ||
| "js-yaml": ">=4.1.1" | ||
| } |
There was a problem hiding this comment.
This PR removes .github/dependabot.yml (and there’s no replacement config under .github/). That will stop automated dependency update PRs, which is especially risky given the dependency upgrades in this change. Consider restoring Dependabot or adding an alternative (e.g. Renovate).
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
What has been done?
Brief description of what this PR does.
Related issues
Fixes #
Type of change
Screenshots
Add screenshots if there are visual changes.