Skip to content

Staging - #146

Merged
Melv1C merged 6 commits into
mainfrom
staging
Jan 25, 2026
Merged

Melv1C merged 6 commits into
mainfrom
staging

Conversation

@Melv1C

@Melv1C Melv1C commented Jan 25, 2026

Copy link
Copy Markdown
Owner

What has been done?

Brief description of what this PR does.

Related issues

Fixes #

Type of change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation

Screenshots

Add screenshots if there are visual changes.

@Melv1C Melv1C self-assigned this Jan 25, 2026
Copilot AI review requested due to automatic review settings January 25, 2026 12:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds support for an optional rich-text legend on artwork images (persisted in DB and editable in admin UI), while also updating several dependencies and CI/automation configuration.

Changes:

  • Add legend field to ArtworkImage across Prisma, Zod schemas, create/update actions, and admin image upload UI.
  • Render image legends (and adjust source rendering) in the artwork images carousel.
  • Upgrade multiple dependencies and modify CI configuration (security audit job commented out) and remove Dependabot config.

Reviewed changes

Copilot reviewed 11 out of 12 changed files in this pull request and generated 5 comments.

Show a summary per file
File Description
src/schemas/artwork-image.ts Extends artwork image schemas/types with nullable legend.
src/features/artworks/components/artwork-images-carousel.tsx Displays legend and source under carousel images.
src/features/artworks/components/admin/image-upload.tsx Adds admin editing UI for image legend and initializes legend on upload.
src/features/artworks/actions/update-artwork.ts Persists legend when updating artwork images.
src/features/artworks/actions/create-artwork.ts Persists legend when creating artwork images.
src/components/ui/rich-text-editor.tsx Enables alignment toolbar in single-line config; introduces debug logging.
prisma/schema.prisma Adds legend column to ArtworkImage model.
prisma/migrations/20260125101040_add_image_legend/migration.sql Migration to add legend column to artwork_image.
package.json Dependency upgrades (Next/Prisma/Tiptap/etc.) and overrides update.
.github/workflows/ci.yml Security audit job commented out.
.github/dependabot.yml Removed Dependabot configuration.

Comment thread src/components/ui/rich-text-editor.tsx Outdated
Comment on lines +72 to +76
<div className="text-xs text-muted-foreground">
<span className="font-medium">Source: </span>
<span className="prose prose-xs dark:prose-invert inline">
<RichTextViewer content={artworkImage.source} />
</div>
</span>

Copilot AI Jan 25, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

RichTextViewer renders a block-level <div> wrapper. Wrapping it in a <span> here creates invalid HTML (div inside span) and can break typography/layout. Use a block wrapper (e.g. <div>) and style it via RichTextViewer's className prop or outer container instead of an inline <span>.

Copilot uses AI. Check for mistakes.
Comment thread .github/workflows/ci.yml
Comment on lines +47 to +69
# security-audit:
# name: Security Audit
# runs-on: ubuntu-latest
# steps:
# - name: Checkout code
# uses: actions/checkout@v5

# - name: Setup pnpm
# uses: pnpm/action-setup@v4
# with:
# version: ${{ env.PNPM_VERSION }}

# - name: Setup Node.js
# uses: actions/setup-node@v5
# with:
# node-version: ${{ env.NODE_VERSION }}
# cache: 'pnpm'

# - name: Install dependencies
# run: pnpm install --frozen-lockfile

# - name: Run security audit
# run: pnpm audit --audit-level moderate

Copilot AI Jan 25, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The security audit job is currently commented out, which removes an important CI safety net for vulnerable dependencies. If audits are too noisy, consider keeping the job enabled with an adjusted threshold, ignoring known advisories, or running it on a schedule rather than disabling it entirely.

Suggested change
# security-audit:
# name: Security Audit
# runs-on: ubuntu-latest
# steps:
# - name: Checkout code
# uses: actions/checkout@v5
# - name: Setup pnpm
# uses: pnpm/action-setup@v4
# with:
# version: ${{ env.PNPM_VERSION }}
# - name: Setup Node.js
# uses: actions/setup-node@v5
# with:
# node-version: ${{ env.NODE_VERSION }}
# cache: 'pnpm'
# - name: Install dependencies
# run: pnpm install --frozen-lockfile
# - name: Run security audit
# run: pnpm audit --audit-level moderate
security-audit:
name: Security Audit
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v5
- name: Setup pnpm
uses: pnpm/action-setup@v4
with:
version: ${{ env.PNPM_VERSION }}
- name: Setup Node.js
uses: actions/setup-node@v5
with:
node-version: ${{ env.NODE_VERSION }}
cache: 'pnpm'
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Run security audit
run: pnpm audit --audit-level moderate

Copilot uses AI. Check for mistakes.
Comment thread package.json
Comment on lines +72 to +75
"lucide-react": "^0.563.0",
"next": "16.1.4",
"next-themes": "^0.4.6",
"prisma": "^7.1.0",
"prisma": "^7.3.0",

Copilot AI Jan 25, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR description is still the default template and doesn’t explain the intent of the changes (new image legend field + broad dependency/CI config changes). Please update the PR description with what was done, why, and any rollout/migration notes.

Copilot uses AI. Check for mistakes.
Comment thread package.json
Comment on lines 6 to 10
"overrides": {
"hono": ">=4.10.3",
"hono": ">=4.11.4",
"valibot": ">=1.2.0",
"js-yaml": ">=4.1.1"
}

Copilot AI Jan 25, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR removes .github/dependabot.yml (and there’s no replacement config under .github/). That will stop automated dependency update PRs, which is especially risky given the dependency upgrades in this change. Consider restoring Dependabot or adding an alternative (e.g. Renovate).

Copilot uses AI. Check for mistakes.
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
@Melv1C
Melv1C merged commit 3a8e0ca into main Jan 25, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants