chore(deps): bump the npm-web-nonbreaking group across 1 directory with 12 updates - #271
Conversation
…th 12 updates Bumps the npm-web-nonbreaking group with 12 updates in the /web directory: | Package | From | To | | --- | --- | --- | | [framer-motion](https://github.com/motiondivision/motion) | `12.40.0` | `12.42.2` | | [fumadocs-core](https://github.com/fuma-nama/fumadocs) | `16.9.3` | `16.10.7` | | [fumadocs-ui](https://github.com/fuma-nama/fumadocs) | `16.9.3` | `16.10.7` | | [next](https://github.com/vercel/next.js) | `16.2.7` | `16.2.10` | | [@next/eslint-plugin-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-plugin-next) | `16.2.7` | `16.2.10` | | [@tailwindcss/postcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss) | `4.3.0` | `4.3.2` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `22.19.20` | `22.20.0` | | [eslint-config-next](https://github.com/vercel/next.js/tree/HEAD/packages/eslint-config-next) | `16.2.7` | `16.2.10` | | [globals](https://github.com/sindresorhus/globals) | `17.6.0` | `17.7.0` | | [postcss](https://github.com/postcss/postcss) | `8.5.15` | `8.5.16` | | [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) | `4.3.0` | `4.3.2` | | [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.60.1` | `8.62.1` | Updates `framer-motion` from 12.40.0 to 12.42.2 - [Changelog](https://github.com/motiondivision/motion/blob/main/CHANGELOG.md) - [Commits](motiondivision/motion@v12.40.0...v12.42.2) Updates `fumadocs-core` from 16.9.3 to 16.10.7 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs-core@16.9.3...fumadocs@16.10.7) Updates `fumadocs-ui` from 16.9.3 to 16.10.7 - [Release notes](https://github.com/fuma-nama/fumadocs/releases) - [Commits](https://github.com/fuma-nama/fumadocs/compare/fumadocs-ui@16.9.3...fumadocs@16.10.7) Updates `next` from 16.2.7 to 16.2.10 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](vercel/next.js@v16.2.7...v16.2.10) Updates `@next/eslint-plugin-next` from 16.2.7 to 16.2.10 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](https://github.com/vercel/next.js/commits/v16.2.10/packages/eslint-plugin-next) Updates `@tailwindcss/postcss` from 4.3.0 to 4.3.2 - [Release notes](https://github.com/tailwindlabs/tailwindcss/releases) - [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.3.2/packages/@tailwindcss-postcss) Updates `@types/node` from 22.19.20 to 22.20.0 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `eslint-config-next` from 16.2.7 to 16.2.10 - [Release notes](https://github.com/vercel/next.js/releases) - [Commits](https://github.com/vercel/next.js/commits/v16.2.10/packages/eslint-config-next) Updates `globals` from 17.6.0 to 17.7.0 - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v17.6.0...v17.7.0) Updates `postcss` from 8.5.15 to 8.5.16 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.15...8.5.16) Updates `tailwindcss` from 4.3.0 to 4.3.2 - [Release notes](https://github.com/tailwindlabs/tailwindcss/releases) - [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.3.2/packages/tailwindcss) Updates `typescript-eslint` from 8.60.1 to 8.62.1 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.62.1/packages/typescript-eslint) --- updated-dependencies: - dependency-name: framer-motion dependency-version: 12.42.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-web-nonbreaking - dependency-name: fumadocs-core dependency-version: 16.10.7 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-web-nonbreaking - dependency-name: fumadocs-ui dependency-version: 16.10.7 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-web-nonbreaking - dependency-name: next dependency-version: 16.2.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-web-nonbreaking - dependency-name: "@next/eslint-plugin-next" dependency-version: 16.2.10 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-web-nonbreaking - dependency-name: "@tailwindcss/postcss" dependency-version: 4.3.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-web-nonbreaking - dependency-name: "@types/node" dependency-version: 22.20.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-web-nonbreaking - dependency-name: eslint-config-next dependency-version: 16.2.10 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-web-nonbreaking - dependency-name: globals dependency-version: 17.7.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-web-nonbreaking - dependency-name: postcss dependency-version: 8.5.16 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-web-nonbreaking - dependency-name: tailwindcss dependency-version: 4.3.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-web-nonbreaking - dependency-name: typescript-eslint dependency-version: 8.62.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-web-nonbreaking ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
Mogplex PR Review
Status: Attention needed
What this PR does: a Dependabot group update ("npm-web-nonbreaking") that bumps 12 dependencies in web/package.json — framer-motion (12.40.0→12.42.2), fumadocs-core & fumadocs-ui (16.9.3→16.10.7), next & @next/eslint-plugin-next & eslint-config-next (16.2.7→16.2.10), @tailwindcss/postcss & tailwindcss (4.3.0→4.3.2), postcss (8.5.15→8.5.16), @types/node (22.19.20→22.20.0), globals (17.6.0→17.7.0), and typescript-eslint (8.60.1→8.62.1). All within semver minor/patch. The diff touches web/package.json only.
Blocking issue (independently verified): the lockfile is missing from this PR. This is a pnpm workspace (pnpm-workspace.yaml lists web; packageManager pnpm@10.12.4) with a single root pnpm-lock.yaml and no lockfile under /web. I fetched pnpm-lock.yaml at the PR head ref and its web: importer still records the OLD specifiers/versions (framer-motion specifier ^12.40.0 / version 12.40.0, next ^16.2.7, tailwindcss & @tailwindcss/postcss 4.3.0, typescript-eslint 8.60.1, globals 17.6.0, plus @types/node, postcss, fumadocs-core/ui, eslint-config-next, @next/eslint-plugin-next), while web/package.json at head already declares the new ranges and listChangedFiles shows only web/package.json changed. Because both CI jobs in .github/workflows/ci.yml (desktop-checks and frontend-checks) run pnpm install --frozen-lockfile, pnpm rejects the manifest/lockfile mismatch (ERR_PNPM_OUTDATED_LOCKFILE) at the install step — indeed 12.40.0 doesn't even satisfy ^12.42.2 — so CI goes red and this is not mergeable as-is; force-merging would break frozen installs for everyone. Root cause: .github/dependabot.yml registers /web as its own package-ecosystem: npm directory, so in a pnpm workspace the shared root lockfile is not regenerated alongside the manifest. Fix: run pnpm install --lockfile-only (or pnpm install --no-frozen-lockfile) and commit the regenerated pnpm-lock.yaml to this branch; longer term, model the workspace at the repo root in the Dependabot config so future update PRs include the lockfile.
Non-blocking notes:
- Behavioral change in fumadocs-ui 16.10.x (verified against the changelog in the PR body): 16.10.2 changes the default table-of-contents variant (the redesigned TOC becomes default; the "clerk" variant reverts to the classic Clerk-like style), and 16.10.0 introduces a new fuma-translate-powered translations API where the surface is the same but some translation keys are renamed and unused labels are ignored (16.10.1 then stabilizes fuma-translate). Still a minor bump, but worth a quick visual check of the docs site if you customize the TOC or translations. fumadocs-core is bumped in lockstep, which is correct.
- Minor version drift: root package.json still pins older ranges for shared tooling (tailwindcss/@tailwindcss/postcss ^4.3.0, postcss ^8.5.15, @types/node ^22.19.20, globals ^17.6.0, and @typescript-eslint/* ^8.60.1). These are caret ranges so pnpm resolves a single satisfying version and there is no hard conflict — just a Dependabot per-directory hygiene nit, not a functional problem.
- Security: no concerns. All 12 are reputable, pre-existing packages bumped within minor/patch (several next releases 16.2.8/9/10 are effectively empty republishes). No new or typosquatted dependencies and no secrets.
Confidence / uncertainty: high on the blocker — I confirmed the head-ref lockfile lacks the new versions, that the manifest carries them, that only web/package.json changed, and that CI uses frozen installs. I did not run pnpm locally, so the exact error wording can vary by pnpm version, but frozen-lockfile mode will reject this mismatch.
Verdict: REQUEST CHANGES — commit the regenerated pnpm-lock.yaml (and preferably fix the Dependabot workspace config) so CI's frozen install passes.
2 findings were added inline.
| "@react-three/rapier": "^2.1.0", | ||
| "framer-motion": "^12.40.0", | ||
| "fumadocs-core": "^16.9.3", | ||
| "framer-motion": "^12.42.2", |
There was a problem hiding this comment.
Critical: Lockfile not updated — pnpm --frozen-lockfile will fail CI
web/package.json bumps 12 specifiers, but the PR does not include the matching lockfile update. This repo is a pnpm workspace (pnpm-workspace.yaml includes web; packageManager pnpm@10.12.4) with a single root pnpm-lock.yaml and no lockfile under /web. I verified pnpm-lock.yaml at the PR head ref — its web: importer still records the OLD specifiers/versions, e.g.:
- framer-motion: specifier ^12.40.0 / version 12.40.0 (manifest now ^12.42.2; 12.40.0 does not even satisfy ^12.42.2)
- next: ^16.2.7 / 16.2.7 (now ^16.2.10)
- tailwindcss and @tailwindcss/postcss: 4.3.0 (now ^4.3.2)
- typescript-eslint: 8.60.1 (now ^8.62.1)
- globals: 17.6.0 (now 17.7.0)
- plus @types/node, postcss, fumadocs-core, fumadocs-ui, eslint-config-next, @next/eslint-plugin-next.
listChangedFiles confirms only web/package.json changed, so the lockfile genuinely was not regenerated.
Impact: both CI jobs in .github/workflows/ci.yml (desktop-checks and frontend-checks) run pnpm install --frozen-lockfile, which refuses to install on a manifest/lockfile specifier mismatch (ERR_PNPM_OUTDATED_LOCKFILE). CI fails at the install step, so this cannot merge as-is; force-merging would break frozen installs for all consumers.
Likely cause: .github/dependabot.yml registers /web as its own package-ecosystem: npm directory; in a pnpm workspace the shared root lockfile then is not updated alongside the manifest.
Suggested fix:
- Regenerate and commit the lockfile on this branch:
pnpm install --lockfile-only(orpnpm install --no-frozen-lockfile), then commit pnpm-lock.yaml. - Longer term, update the Dependabot config to model the pnpm workspace (typically a single root
/directory entry) so future update PRs include the lockfile.
| "fumadocs-mdx": "^14.3.2", | ||
| "fumadocs-ui": "^16.9.3", | ||
| "next": "^16.2.7", | ||
| "fumadocs-ui": "^16.10.7", |
There was a problem hiding this comment.
Suggestion: Heads-up: fumadocs-ui 16.10.x changes the default TOC and translations API
Non-blocking heads-up, verified against the changelog embedded in the PR description. fumadocs-ui moves 16.9.3 → 16.10.7, which crosses two behavioral changes:
- 16.10.2 changes the default table-of-contents variant: the redesigned TOC becomes the new default, and the "clerk" variant reverts to the original Clerk-like style.
- 16.10.0 introduces a new translations API powered by fuma-translate; the API surface is the same, but some translation keys are renamed and unused labels are ignored (16.10.1 then stabilizes fuma-translate).
This stays within a semver minor, so no action is strictly required, but if the docs site customizes the TOC variant or provides custom translation strings, it's worth a quick visual check after the bump. fumadocs-core is bumped in lockstep (16.9.3 → 16.10.7), which is the correct pairing.
Bumps the npm-web-nonbreaking group with 12 updates in the /web directory:
12.40.012.42.216.9.316.10.716.9.316.10.716.2.716.2.1016.2.716.2.104.3.04.3.222.19.2022.20.016.2.716.2.1017.6.017.7.08.5.158.5.164.3.04.3.28.60.18.62.1Updates
framer-motionfrom 12.40.0 to 12.42.2Changelog
Sourced from framer-motion's changelog.
Commits
40e8756v12.42.2718ccc7Merge pull request #3768 from motiondivision/view-cropped-corner-radius19195a4Dedupe corner-radius longhands; merge crop box/radii measurements5299aa6Resolve cropped-clip radius timing once; fix transition-option leak937cdf3Animate cropped view-transition group corner radiusfd2d6f6v12.42.12223d87Hold the old layer when only a non-opacity .new() is set9c84145v12.42.060d7c72Add view-transition group nesting and aspect-aware cropping6437276UpdatingUpdates
fumadocs-corefrom 16.9.3 to 16.10.7Release notes
Sourced from fumadocs-core's releases.
Commits
084bb7bVersion Packages (#3387)3922dccfix(ui): base path in page actions47b8b63Version Packages (#3384)baacf1aperf(mdx): requirecollectionquery param at regex matching593302dVersion Packages (#3382)923e581docs: add more FAQs9fae790add missing changesets6ab44adupdate lock fileb038183fix(local-md): fix deprecation warnings4bf7f0dfix(tanstack-start-spa): remove getPageMarkdownUrl, unused and identical to s...Updates
fumadocs-uifrom 16.9.3 to 16.10.7Release notes
Sourced from fumadocs-ui's releases.
Commits
084bb7bVersion Packages (#3387)3922dccfix(ui): base path in page actions47b8b63Version Packages (#3384)baacf1aperf(mdx): requirecollectionquery param at regex matching593302dVersion Packages (#3382)923e581docs: add more FAQs9fae790add missing changesets6ab44adupdate lock fileb038183fix(local-md): fix deprecation warnings4bf7f0dfix(tanstack-start-spa): remove getPageMarkdownUrl, unused and identical to s...Updates
nextfrom 16.2.7 to 16.2.10Release notes
Sourced from next's releases.
Commits
9dadfd6v16.2.10534d9c1[16.2.x] Release pipeline updates (#95160)98941fcbackport: docs fixes 16.2.x (#94935)6e1a94d[16.2.x][ci]: fix release script to not strip newlines (#94640)f37fad9v16.2.9d9aaaed[cd] Allow tagging semver-lower releases as@latestif@latestpo… (#94627)6f16804v16.2.80dbc1d5[16.2.x][cd] Ensure release can be triggered on old branches (#94598)90e3c81[16.2.x] Align Actions dependencies with Canary (#94339)83f402c[16.2.x][cd] Stop fetching all tags when searching parent tag (#94334)Updates
@next/eslint-plugin-nextfrom 16.2.7 to 16.2.10Release notes
Sourced from @next/eslint-plugin-next's releases.
Commits
9dadfd6v16.2.10534d9c1[16.2.x] Release pipeline updates (#95160)6e1a94d[16.2.x][ci]: fix release script to not strip newlines (#94640)f37fad9v16.2.96f16804v16.2.8411c455v16.2.7Updates
@tailwindcss/postcssfrom 4.3.0 to 4.3.2Release notes
Sourced from @tailwindcss/postcss's releases.
... (truncated)
Changelog
Sourced from @tailwindcss/postcss's changelog.
... (truncated)
Commits
056a1554.3.2 (#20281)8a14a714.3.1 (#20226)522288cServe ESM type declarations to ESM importers of@tailwindcss/postcss(#20228)8dcdb66Bump dependencies (#20095)Updates
@types/nodefrom 22.19.20 to 22.20.0Commits
Updates
eslint-config-nextfrom 16.2.7 to 16.2.10Release notes
Sourced from eslint-config-next's releases.
Commits
9dadfd6v16.2.10534d9c1[16.2.x] Release pipeline updates (#95160)6e1a94d[16.2.x][ci]: fix release script to not strip newlines (#94640)f37fad9v16.2.96f16804v16.2.8411c455v16.2.7Updates
globalsfrom 17.6.0 to 17.7.0Release notes
Sourced from globals's releases.
Commits
a19670c17.7.09611620Update actions (#346)33b75f9Update globals (2026-06-22) (#345)887dd52Fix build script (#344)Updates
postcssfrom 8.5.15 to 8.5.16Release notes
Sourced from postcss's releases.
Changelog
Sourced from postcss's changelog.
Commits
92ccc93Release 8.5.16 version818bdd6Update formatting46e4510FixInput#origin()returning incorrect position (#2036)34942ceFix testsd4feed6Don't clone root-less child nodes in container constructor (#2097)da323fcRevert version update to fix old Node.js on CI8863369Update dependencies3828982Preserve node raws when rehydrating a JSON AST (#2100)d1e80b8Fix Node#rangeBy() ignoring index 0 (#2091)b91e4a6Fix Node.js 26 testsMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for postcss since your current version.
Updates
tailwindcssfrom 4.3.0 to 4.3.2Release notes
Sourced from tailwindcss's releases.
... (truncated)
Changelog
Sourced from tailwindcss's changelog.
... (truncated)
Commits
056a1554.3.2 (#20281)c8b081dAdd suggestions for named opacity modifiers (#20287)c46f654Ensure--alpha(…)is seen as acolor, and--spacing(…)is seen as a `le...5e9f66eEnsure@variantcan be used in JS based APIs (#20252)707c23bEnsure custom variants can be used via@variantinaddBase(#20247)127d170Add bare value support forauto-rows-*andauto-cols-*(#20229)8a14a714.3.1 (#20226)12833aaFix canonicalization bug where we end up with a high precision number (#20221)97a5b3adocs: fix double word 'to to' in test comment (#20216)d01e103Add missinginsetkeyword forinset-shadow-none(#20208)Updates
typescript-eslintfrom 8.60.1 to 8.62.1Release notes
Sourced from typescript-eslint's releases.