Skip to content

fix(deps): bump react and @types/react - #915

Closed
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/multi-7f19880bf6
Closed

dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/multi-7f19880bf6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps react and @types/react. These dependencies needed to be updated together.
Updates react from 19.2.8 to 19.3.0

Release notes

Sourced from react's releases.

19.3.0 (September 9, 2026)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.3 release post for more information.

New React Features

New React DOM Features

  • browser(): a new react-dom API that returns a usable which errors during server rendering and resolves in the browser. use(browser()) inside a <Suspense> boundary marks a subtree as browser-only without reporting a recoverable error (@​gnoff: #37143, #37241)
    • Added an onBrowserBailout option to the react-dom/server APIs to observe when a subtree defers to the browser (@​gnoff #37193)

Notable changes

All Changes

React

... (truncated)

Changelog

Sourced from react's changelog.

19.3.0 (September 9, 2026)

New React Features

New React DOM Features

  • browser(): a new react-dom API that returns a usable which errors during server rendering and resolves in the browser. use(browser()) inside a <Suspense> boundary marks a subtree as browser-only without reporting a recoverable error (@​gnoff: #37143, #37241)
    • Added an onBrowserBailout option to the react-dom/server APIs to observe when a subtree defers to the browser (@​gnoff #37193)

Notable changes

All Changes

React

... (truncated)

Commits

Updates @types/react from 19.2.18 to 19.3.0

Commits


📝 Summary by GitNexus

Summary

This appears to be a narrowly scoped dependency and lockfile change, with limited code-graph reach.

🟡 MEDIUM blast radius. A dependency update for react and @​types/react in package.json and pnpm-lock.yaml, with no graph dependents.

The change is concentrated in dependency configuration rather than application symbols. No affected execution flows or cross-repo consumers were found.

Review the dependency entries in package.json alongside the corresponding lockfile changes in pnpm-lock.yaml.

Added by GitNexus for PR #915. Edit freely — this block is replaced on the next review, everything above it is left untouched.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
@vercel

vercel Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
do-knowledge-studio Ready Ready Preview, v0 Oct 10, 2026 11:02am UTC

@github-actions github-actions Bot added the config label Oct 6, 2026
@codacy-production

Copy link
Copy Markdown
Contributor

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@nexus-check

nexus-check Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor
Akon Labs

GitNexus Review · PR #915

No issues found in 2 changed files.

Summary

This appears to be a narrowly scoped dependency and lockfile change, with limited code-graph reach.

🟡 MEDIUM blast radius. A dependency update for react and @​types/react in package.json and pnpm-lock.yaml, with no graph dependents.

The change is concentrated in dependency configuration rather than application symbols. No affected execution flows or cross-repo consumers were found.

Review the dependency entries in package.json alongside the corresponding lockfile changes in pnpm-lock.yaml.

Full detail lives in the GitNexus check run for this commit.

@nexus-check

nexus-check Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🤖 Agent context for GitNexus Review · PR #915

This comment carries deterministic graph detail for coding agents and reviewers who want the receipts — the main review comment carries the human summary.

🟡 MEDIUM blast radius — no downstream dependents were found in the code graph; a spot-check of the dependents should cover it. (likely driven by file-risk heuristics — no direct dependents or affected modules were found)

Blast Level Dependents Modules Files
🟡 MEDIUM 0 0 2

What changed

Changed Files (2)
File Status
package.json 🟡 modified
pnpm-lock.yaml 🟡 modified

What to check

File Risk (2)
File Risk Category
package.json 🟡 MEDIUM Dependencies
pnpm-lock.yaml 🟢 LOW Lock File

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-7f19880bf6 branch from a645474 to 66b42ec Compare October 6, 2026 06:08
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-7f19880bf6 branch from 66b42ec to 18942ad Compare October 6, 2026 13:44
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-7f19880bf6 branch from 18942ad to a3f24e7 Compare October 6, 2026 13:48
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Blocked merge diagnosis — blocked
⏳ Check run(s) still in progress: ["Trivy","Dependency Verify","Quality Gate","Unit Tests","Codacy Static Code Analysis","labeler","Dependency Advisory Audit","YAML Syntax Validation","Infrastructure as Code Security","Trivy Filesystem Security Scan","Diagnose Blocked Merge State","commitlint","Analyze (javascript-typescript)","Analyze (actions)"]

Bumps [react](https://github.com/react/react/tree/HEAD/packages/react) and [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react). These dependencies needed to be updated together.

Updates `react` from 19.2.8 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react)

Updates `@types/react` from 19.2.18 to 19.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

---
updated-dependencies:
- dependency-name: "@types/react"
  dependency-version: 19.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
- dependency-name: react
  dependency-version: 19.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@d-oit

d-oit commented Oct 10, 2026

Copy link
Copy Markdown
Owner

Closing as superseded — roast and rationale below.

What went wrong: This Dependabot PR bumps react/react-dom/@types/react 19.2.8 → 19.3.0 from a base that main has since moved past. The branch is CONFLICTING and its Unit Tests, Dependency Verify, and Trivy checks are all red — a lockfile-only PR that can no longer produce a green tree is pure CI debt.

Why close instead of fix: The identical runtime bump (react/react-dom 19.3.0 + @types 19.3.0) is already carried, lockfile-regenerated and fully verified (2790 unit tests, 642 production E2E, lint/typecheck/build zero warnings), in the Plan 161/162 batch landing from fix/offline-lazy-view-precache (commit "chore(deps): refresh Next to 16.3.7 and the React runtime to 19.3.0"; Next itself has since advanced past this base to 16.3.8 via #914). Re-driving this PR would duplicate that work and re-open the same conflicts.

Recommendation (roast): Dependabot opened this correctly; it went stale because the manual runtime refresh landed on a different branch first. After the Plan 161/162 batch merges, the next Dependabot run should find react already at 19.3.0 and quiet down. If the group keeps racing manual refreshes, consider adding a weekly (not daily) schedule for the react group in .github/dependabot.yml so manual upgrades get room to land.

@d-oit d-oit closed this Oct 10, 2026
auto-merge was automatically disabled October 10, 2026 14:58

Pull request was closed

@dependabot @github

dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

This branch was successfully deployed

1 active deployment
Preview — a031c0fd Deployed Oct 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

config dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant