Skip to content

fix(deps): bump @tanstack/react-virtual from 3.14.9 to 3.14.13 - #916

Merged
d-oit merged 1 commit into
mainfrom
dependabot/npm_and_yarn/tanstack/react-virtual-3.14.13
Oct 6, 2026
Merged

d-oit merged 1 commit into
mainfrom
dependabot/npm_and_yarn/tanstack/react-virtual-3.14.13

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @tanstack/react-virtual from 3.14.9 to 3.14.13.

Release notes

Sourced from @​tanstack/react-virtual's releases.

@​tanstack/react-virtual@​3.14.13

Patch Changes

  • #1282 b48e3b0 - Skip flushSync for the synchronous notify raised from measureElement. React calls measureElement from a ref callback, i.e. while it is committing, and flushSync cannot flush there — it warns in development instead. The commit phase already runs at discrete (sync) priority, so the update lands in the same lane and the same frame without flushSync. Notifies from every other path (ResizeObserver re-measures, scroll adjustments) still flush synchronously.

  • Updated dependencies [06d1b6b, 2c0a0ea]:

    • @​tanstack/virtual-core@​3.17.11

@​tanstack/react-virtual@​3.14.12

Patch Changes

  • Updated dependencies [ab3278c]:
    • @​tanstack/virtual-core@​3.17.10

@​tanstack/react-virtual@​3.14.11

Patch Changes

  • Updated dependencies [4a0adf3]:
    • @​tanstack/virtual-core@​3.17.9

@​tanstack/react-virtual@​3.14.10

Patch Changes

Changelog

Sourced from @​tanstack/react-virtual's changelog.

3.14.13

Patch Changes

  • #1282 b48e3b0 - Skip flushSync for the synchronous notify raised from measureElement. React calls measureElement from a ref callback, i.e. while it is committing, and flushSync cannot flush there — it warns in development instead. The commit phase already runs at discrete (sync) priority, so the update lands in the same lane and the same frame without flushSync. Notifies from every other path (ResizeObserver re-measures, scroll adjustments) still flush synchronously.

  • Updated dependencies [06d1b6b, 2c0a0ea]:

    • @​tanstack/virtual-core@​3.17.11

3.14.12

Patch Changes

  • Updated dependencies [ab3278c]:
    • @​tanstack/virtual-core@​3.17.10

3.14.11

Patch Changes

  • Updated dependencies [4a0adf3]:
    • @​tanstack/virtual-core@​3.17.9

3.14.10

Patch Changes

Commits
  • 78371e8 ci: Version Packages (#1279)
  • b48e3b0 fix(react-virtual): skip flushSync while measuring from the ref callback (#1282)
  • 1a57cf7 test(react-virtual): wait for smooth scrolls to settle instead of a fixed 2s ...
  • 2c0a0ea fix(virtual-core): keep a travelling smooth scroll alive through a prepend (#...
  • df47889 ci: Version Packages (#1277)
  • 171029d ci: Version Packages (#1269)
  • 4a0adf3 fix(virtual-core): re-issue clamped end-anchor compensation once the sizer gr...
  • e9874f0 ci: Version Packages (#1247)
  • See full diff in compare view


📝 Summary by GitNexus

Summary

A dependency update confined to package metadata, with no downstream callers or traced execution flows in the graph. The reported risk level is medium.

🟡 MEDIUM blast radius. A version update for @​tanstack/react-virtual from 3.14.9 to 3.14.13, limited to package.json and pnpm-lock.yaml.

Review the dependency declaration and the corresponding lockfile changes. The graph reports no dependent symbols or affected flows, and there are no cross-repo consumers or HIGH/CRITICAL risk files.

Added by GitNexus for PR #916. Edit freely — this block is replaced on the next review, everything above it is left untouched.

@vercel

vercel Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
do-knowledge-studio Ready Ready Preview, v0 Oct 6, 2026 6:10am UTC

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
@github-actions github-actions Bot added the config label Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Blocked merge diagnosis — blocked
⏳ Check run(s) still in progress: ["Codacy Static Code Analysis","Secret Detection","YAML Syntax Validation","Infrastructure as Code Security","Trivy Filesystem Security Scan","Dependency Advisory Audit","Diagnose Blocked Merge State","commitlint","GitHub Actions Workflow Validation","Shell Script Security Analysis","Detect Changes","GitNexus"]

@codacy-production

Copy link
Copy Markdown
Contributor

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@nexus-check

nexus-check Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor
Akon Labs

GitNexus Review · PR #916

No issues found in 2 changed files.

Summary

A dependency update confined to package metadata, with no downstream callers or traced execution flows in the graph. The reported risk level is medium.

🟡 MEDIUM blast radius. A version update for @​tanstack/react-virtual from 3.14.9 to 3.14.13, limited to package.json and pnpm-lock.yaml.

Review the dependency declaration and the corresponding lockfile changes. The graph reports no dependent symbols or affected flows, and there are no cross-repo consumers or HIGH/CRITICAL risk files.

Full detail lives in the GitNexus check run for this commit.

@nexus-check

nexus-check Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🤖 Agent context for GitNexus Review · PR #916

This comment carries deterministic graph detail for coding agents and reviewers who want the receipts — the main review comment carries the human summary.

🟡 MEDIUM blast radius — no downstream dependents were found in the code graph; a spot-check of the dependents should cover it. (likely driven by file-risk heuristics — no direct dependents or affected modules were found)

Blast Level Dependents Modules Files
🟡 MEDIUM 0 0 2

What changed

Changed Files (2)
File Status
package.json 🟡 modified
pnpm-lock.yaml 🟡 modified

What to check

File Risk (2)
File Risk Category
package.json 🟡 MEDIUM Dependencies
pnpm-lock.yaml 🟢 LOW Lock File

Bumps [@tanstack/react-virtual](https://github.com/TanStack/virtual/tree/HEAD/packages/react-virtual) from 3.14.9 to 3.14.13.
- [Release notes](https://github.com/TanStack/virtual/releases)
- [Changelog](https://github.com/TanStack/virtual/blob/main/packages/react-virtual/CHANGELOG.md)
- [Commits](https://github.com/TanStack/virtual/commits/@tanstack/react-virtual@3.14.13/packages/react-virtual)

---
updated-dependencies:
- dependency-name: "@tanstack/react-virtual"
  dependency-version: 3.14.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/tanstack/react-virtual-3.14.13 branch from 3a006a3 to b140aeb Compare October 6, 2026 06:08
@d-oit
d-oit merged commit e92db9c into main Oct 6, 2026
26 checks passed
@d-oit
d-oit deleted the dependabot/npm_and_yarn/tanstack/react-virtual-3.14.13 branch October 6, 2026 13:42

This branch was successfully deployed

1 active deployment
Preview — b140aebe Deployed Oct 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

config dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant