Skip to content

[codex] Update npm dependencies - #56

Merged
petercr merged 1 commit into
mainfrom
petercr/update-npm
Jun 16, 2026
Merged

petercr merged 1 commit into
mainfrom
petercr/update-npm

Conversation

@petercr

@petercr petercr commented Jun 16, 2026

Copy link
Copy Markdown
Owner

What changed

  • Refreshed npm workspace dependency pins in package-lock.json.
  • Migrated Biome config to the 2.5 schema and excluded generated Playwright artifacts/raw SVGs from linting.
  • Added workspace source path mappings for @santan/shared in frontend and studio TypeScript configs.
  • Updated loader tests to mock TanStack Start server functions under the newer runtime expectations.
  • Fixed lint/build fallout around SVG accessibility, JSON-LD script rendering, global style logging, and Sanity type literal extraction.
  • Adjusted the contact e2e assertion to match the app behavior when an error node is removed.

Why

The dependency refresh pulled newer toolchain behavior from Biome, TanStack Start, and related packages. These small compatibility fixes keep linting, type-checking, build, and tests passing with the updated lockfile.

Validation

  • npm run lint
  • npm run type-check
  • npm run build
  • npm run vitest
  • npm test: 28 passed, 5 skipped content-dependent post tests

Notes

npm audit still reports transitive Sanity/Vite-related advisories that require breaking/major changes to resolve.

@vercel

vercel Bot commented Jun 16, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
ccw Ready Ready Preview, Comment Jun 16, 2026 4:09am

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​tailwindcss/​oxide-linux-arm64-musl@​4.2.2 ⏵ 4.3.11001004098100
Updated@​tailwindcss/​oxide-linux-x64-gnu@​4.2.2 ⏵ 4.3.11001004098100
Updated@​tailwindcss/​oxide-linux-x64-musl@​4.2.2 ⏵ 4.3.11001004098100
Updated@​tailwindcss/​oxide-win32-x64-msvc@​4.2.2 ⏵ 4.3.11001004098100
Updated@​tanstack/​nitro-v2-vite-plugin@​1.154.9 ⏵ 1.155.0991006998 +1100
Updated@​tanstack/​react-query-devtools@​5.99.0 ⏵ 5.101.01001007198 -1100
Updated@​tanstack/​react-router-devtools@​1.166.13 ⏵ 1.167.074 +110071 +198100
Updated@​commitlint/​cli@​20.5.0 ⏵ 20.5.3100 +11007395100
Updated@​tanstack/​react-router-ssr-query@​1.166.12 ⏵ 1.167.11001007598100
Updated@​tanstack/​react-router@​1.169.2 ⏵ 1.170.1575 -11008498100
Updated@​tanstack/​router-plugin@​1.167.35 ⏵ 1.168.1899 +11007898 -1100
Updated@​types/​react@​19.2.14 ⏵ 19.2.171001007995100
Updatedvitest@​4.1.4 ⏵ 4.1.898 +110079 +199 +2100
Updatedreact-router@​7.14.0 ⏵ 7.17.094 +1100 +2479 +197100
Updated@​tanstack/​devtools-vite@​0.6.0 ⏵ 0.6.1991008096100
Updatedgroq@​5.24.0 ⏵ 5.31.110010080100100
Updated@​types/​node@​25.6.0 ⏵ 25.9.3100 +110081 +196100
Updatedjsdom@​29.0.2 ⏵ 29.1.181100100 +193100
Updatedtsx@​4.21.0 ⏵ 4.22.4100 +110082 +192100
Updatedvite@​7.3.3 ⏵ 7.3.598 +1100 +1882 +198 +2100
Updated@​tanstack/​react-start@​1.167.65 ⏵ 1.168.2599 +110084 +198 -1100
Updatedtailwindcss@​4.2.2 ⏵ 4.3.11001008498100
Updatedreact@​19.2.6 ⏵ 19.2.71001008497100
Updatedturbo@​2.9.6 ⏵ 2.9.18100100 +38597100
Updated@​tanstack/​react-devtools@​0.10.2 ⏵ 0.10.51001008796100
Updated@​tanstack/​react-query@​5.99.0 ⏵ 5.101.0991008898100
Updated@​tailwindcss/​vite@​4.2.2 ⏵ 4.3.1100 +110090 +198100
Updatedreact-dom@​19.2.6 ⏵ 19.2.71001009298100
Updated@​sanity/​client@​7.22.0 ⏵ 7.22.193 +110010094100
Updated@​portabletext/​react@​6.0.3 ⏵ 6.2.09910010094100
Updated@​sanity/​preview-url-secret@​4.0.4 ⏵ 4.0.710010010094 -1100
Updated@​commitlint/​config-conventional@​20.5.0 ⏵ 20.5.310010010095100
See 8 more rows in the dashboard

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm date-fns is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.json → npm/sanity-plugin-documents-pane@3.0.2 → npm/sanity@5.31.1 → npm/date-fns@4.4.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/date-fns@4.4.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm js-yaml is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package-lock.json → npm/@commitlint/cli@20.5.3 → npm/@tanstack/react-start@1.168.25 → npm/js-yaml@4.2.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/js-yaml@4.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm jsdom is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: apps/frontend/package.json → npm/jsdom@29.1.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/jsdom@29.1.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm jsdom is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: apps/frontend/package.json → npm/jsdom@29.1.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/jsdom@29.1.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@petercr
petercr marked this pull request as ready for review June 16, 2026 14:54
@petercr
petercr merged commit 4df8d4b into main Jun 16, 2026
5 checks passed

This branch was successfully deployed

1 active deployment
Preview — 2d264b8a Deployed Jun 16, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant