You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
fix(deps): bump @tanstack/react-virtual from 3.14.9 to 3.14.13 - #916
#1282b48e3b0 - Skip flushSync for the synchronous notify raised from measureElement. React calls measureElement from a ref callback, i.e. while it is committing, and flushSync cannot flush there — it warns in development instead. The commit phase already runs at discrete (sync) priority, so the update lands in the same lane and the same frame without flushSync. Notifies from every other path (ResizeObserver re-measures, scroll adjustments) still flush synchronously.
#1282b48e3b0 - Skip flushSync for the synchronous notify raised from measureElement. React calls measureElement from a ref callback, i.e. while it is committing, and flushSync cannot flush there — it warns in development instead. The commit phase already runs at discrete (sync) priority, so the update lands in the same lane and the same frame without flushSync. Notifies from every other path (ResizeObserver re-measures, scroll adjustments) still flush synchronously.
A dependency update confined to package metadata, with no downstream callers or traced execution flows in the graph. The reported risk level is medium.
🟡 MEDIUM blast radius. A version update for @tanstack/react-virtual from 3.14.9 to 3.14.13, limited to package.json and pnpm-lock.yaml.
Review the dependency declaration and the corresponding lockfile changes. The graph reports no dependent symbols or affected flows, and there are no cross-repo consumers or HIGH/CRITICAL risk files.
Added by GitNexus for PR #916. Edit freely — this block is replaced on the next review, everything above it is left untouched.
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer TIP This summary will be updated as you push new changes.
A dependency update confined to package metadata, with no downstream callers or traced execution flows in the graph. The reported risk level is medium.
🟡 MEDIUM blast radius. A version update for @tanstack/react-virtual from 3.14.9 to 3.14.13, limited to package.json and pnpm-lock.yaml.
Review the dependency declaration and the corresponding lockfile changes. The graph reports no dependent symbols or affected flows, and there are no cross-repo consumers or HIGH/CRITICAL risk files.
Full detail lives in the GitNexus check run for this commit.
This comment carries deterministic graph detail for coding agents and reviewers who want the receipts — the main review comment carries the human summary.
🟡 MEDIUM blast radius — no downstream dependents were found in the code graph; a spot-check of the dependents should cover it. (likely driven by file-risk heuristics — no direct dependents or affected modules were found)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
configdependenciesPull requests that update a dependency filejavascriptPull requests that update javascript code
1 participant
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps @tanstack/react-virtual from 3.14.9 to 3.14.13.
Release notes
Sourced from @tanstack/react-virtual's releases.
Changelog
Sourced from @tanstack/react-virtual's changelog.
Commits
78371e8ci: Version Packages (#1279)b48e3b0fix(react-virtual): skip flushSync while measuring from the ref callback (#1282)1a57cf7test(react-virtual): wait for smooth scrolls to settle instead of a fixed 2s ...2c0a0eafix(virtual-core): keep a travelling smooth scroll alive through a prepend (#...df47889ci: Version Packages (#1277)171029dci: Version Packages (#1269)4a0adf3fix(virtual-core): re-issue clamped end-anchor compensation once the sizer gr...e9874f0ci: Version Packages (#1247)📝 Summary by GitNexus
Summary
A dependency update confined to package metadata, with no downstream callers or traced execution flows in the graph. The reported risk level is medium.
🟡 MEDIUM blast radius. A version update for
@tanstack/react-virtualfrom3.14.9to3.14.13, limited topackage.jsonandpnpm-lock.yaml.Review the dependency declaration and the corresponding lockfile changes. The graph reports no dependent symbols or affected flows, and there are no cross-repo consumers or HIGH/CRITICAL risk files.
Added by GitNexus for PR #916. Edit freely — this block is replaced on the next review, everything above it is left untouched.