Repository navigation
chore(deps-dev): bump the react group with 4 updates - #468
Merged
Merged
Conversation
Bumps the react group with 4 updates: [react](https://github.com/react/react/tree/HEAD/packages/react), [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react), [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) and [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom). Updates `react` from 19.2.6 to 19.3.0 - [Release notes](https://github.com/react/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/react/react/commits/v19.3.0/packages/react) Updates `@types/react` from 19.2.15 to 19.3.0 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react) Updates `react-dom` from 19.2.6 to 19.3.0 - [Release notes](https://github.com/react/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom) Updates `@types/react-dom` from 19.2.3 to 19.3.0 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom) --- updated-dependencies: - dependency-name: react dependency-version: 19.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: react - dependency-name: "@types/react" dependency-version: 19.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: react - dependency-name: react-dom dependency-version: 19.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: react - dependency-name: "@types/react-dom" dependency-version: 19.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: react ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
There was a problem hiding this comment.
Findings
- None. This is a routine, internally consistent Dependabot bump:
pnpm-lock.yamlmovesreact@19.3.0,react-dom@19.3.0and the matchingscheduler@0.28.0snapshot together, andreact-dom@19.3.0declarespeerDependencies.react: ^19.3.0, matching the^19.3.0specifiers inapps/desktop/package.json:57-58andpackages/ui/package.json:33-34.@types/react-dom@19.3.0declarespeerDependencies.'@types/react': ^19.3.0, and the importers forapps/desktop(apps/desktop/package.json:45-46) andpackages/ui(packages/ui/package.json:30-31) were bumped in the same commit, so the lockfile introduces no peer mismatch.- The React peer ranges in
packages/ui/package.json:19andpackages/i18n/package.json:24were raised in the same commit asapps/desktop, so no workspace consumer is left onreact@^19.2.6(only the three manifests that referenced React were touched, which matches the changed-file list). - No new packages, no new licenses (react, react-dom, and DefinitelyTyped types are MIT), no change to prod dependency count, so the ≤30 prod-dependency budget is unaffected.
Questions
- Do you expect a changeset for dependency bumps that change the bundled renderer runtime?
react/react-domsit indevDependenciesofapps/desktopbut are bundled into the shipped renderer by electron-vite; this diff includes no.changesetentry. If your release tooling handles dependency bumps implicitly, no action is needed.
Summary
- Review mode: initial
- The PR raises the React group from
19.2.6/@types/react@19.2.15/@types/react-dom@19.0.0to19.3.0acrossapps/desktop,packages/ui, andpackages/i18n, with the lockfile regenerated consistently (including the transitivescheduler0.27.0→0.28.0move). No source, config, workflow, or release-path files are touched, so there is nothing to validate against the linked-issue, license, or release/distribution checks. I found no blocking or non-blocking correctness issue in the diff. - Residual risk worth a manual eye, not a finding: the 19.3.0 release notes call out behavior changes ("Transitions now render independently instead of being entangled into a single render") and opt-in Trusted Types API integration. Neither is expected to regress this app, but if any renderer or sandbox-iframe surface depends on entangled transition scheduling, or sets
require-trusted-types-for 'script'in its CSP, verify it once by hand. - Main CI risk is type-level, not runtime:
@types/react@19.3.0/@types/react-dom@19.3.0can tighten or add types, sotsc --noEmitforapps/desktop(tsconfig.node.json+tsconfig.web.json),packages/ui, andpackages/i18nis the signal to watch before merge.
Testing
- Not run (automation). Suggested:
pnpm install --frozen-lockfile(confirms the regenerated lockfile resolves as committed), thenpnpm lint && pnpm typecheck && pnpm test. For the bundled-runtime angle, add one renderer build (pnpm --filter @open-codesign/desktop build) and a Playwright/Electron smoke pass to confirm React 19.3.0 bundles and mounts correctly; no new unit tests are proportional for a version bump.
Open-CoDesign Bot
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the react group with 4 updates: react, @types/react, react-dom and @types/react-dom.
Updates
reactfrom 19.2.6 to 19.3.0Release notes
Sourced from react's releases.
... (truncated)
Changelog
Sourced from react's changelog.
... (truncated)
Commits
2dc7da7[test] Bump Jest to 30.4 (#37382)4f93894docs: remove stale parentType param from validateChildKeys JSDoc (#36928)dbc3750Update required references to GitHub repo (#36752)900ae09[flow] Bump flow to v0.317.0 (#36701)fbb1370[flow] Bump flow to v0.307.1 (#36199)56922cf[react-native-renderer] Delete Paper (legacy) renderer (#36285)74568e8[Flight] TransportAggregateErrors.errors(#36156)e66ef64[tests] remove withoutStack from assertConsole helpers (#35498)db71391[Fiber] Instrument the lazy initializer thenable in all cases (#35521)3e1abcc[tests] Require exact error messages in assertConsole helpers (#35497)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for react since your current version.
Updates
@types/reactfrom 19.2.15 to 19.3.0Commits
Updates
react-domfrom 19.2.6 to 19.3.0Release notes
Sourced from react-dom's releases.
... (truncated)
Changelog
Sourced from react-dom's changelog.