Skip to content

chore: update deps and pin example versions#216

Merged
jxom merged 3 commits intomainfrom
georgen/update-deps
Apr 15, 2026
Merged

chore: update deps and pin example versions#216
jxom merged 3 commits intomainfrom
georgen/update-deps

Conversation

@grandizzy
Copy link
Copy Markdown
Contributor

@grandizzy grandizzy commented Apr 15, 2026

  • Bump catalog versions: react ^19.2.5, viem ^2.47.18, wagmi ^3.6.1, @vitejs/plugin-react ^5.2.0, @wagmi/core ^3.4.2, @types/react ^19.2.14, @types/react-dom ^19.2.3, @tanstack/react-router ^1.168.19, wrangler ^4.82.2, prool ~0.2.4
  • Pin vite-plus to 0.1.15 (0.1.16 causes duplicate vitest instances breaking test suite detection)
  • Pin examples/ deps from latest to explicit versions (react, viem, ox, vite-plugin-mkcert, wrangler) — keeps accounts: "latest" so examples remain clone-able standalone
  • Switch playgrounds/wagmi from "vite-plus": "latest" to "vp": "catalog:" for consistency
  • Bump root package.json deps (elysia, expo-*, playwright-core, testcontainers, mppx, webauthx, zustand)
  • Bump playgrounds and ref-impls deps
  • Resolves 11 of 35 transitive CVEs: axios (CVSS 10.0, 9.3), undici (5 vulns), lodash (3 vulns)
  • 24 remaining CVEs are deep transitive deps (tar, minimatch, file-type, follow-redirects, picomatch, etc.) pinned by upstream — not actionable here

Not bumped (intentionally held back):

  • @types/node stays at ^25.5.0 (^25.6.0 causes vite-plus-test duplication)
  • @vitejs/devtools stays at ^0.1.3 (0.1.13 incompatible with vite-plus@0.1.15)
  • vp (vite-plus) stays at 0.1.15 (0.1.16 has vitest suite detection bug)

Prompted by: georgen

@pkg-pr-new
Copy link
Copy Markdown

pkg-pr-new bot commented Apr 15, 2026

Open in StackBlitz

npm i https://pkg.pr.new/tempoxyz/accounts@216

commit: 901c6f1

@grandizzy grandizzy force-pushed the georgen/update-deps branch from 0168963 to ff0b27a Compare April 15, 2026 14:27
@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Apr 15, 2026

Worker Preview
Wagmi https://df2311c7-accounts-wagmi.porto.workers.dev

@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Apr 15, 2026

Worker Preview
Playground https://6103060e-accounts-playground.porto.workers.dev

@grandizzy grandizzy force-pushed the georgen/update-deps branch 2 times, most recently from 09b4039 to 27d5535 Compare April 15, 2026 14:41
- Bump catalog versions (react, viem, wagmi, vitejs/plugin-react, types/node, types/react, etc.)
- Pin examples/ deps from `latest` to explicit versions (react, viem, ox, vite-plugin-mkcert, wrangler)
- Bump root package.json deps (elysia, expo-*, playwright-core, testcontainers, mppx, webauthx, zustand)
- Bump playgrounds and ref-impls deps

Co-authored-by: grandizzy <38490174+grandizzy@users.noreply.github.com>
Co-authored-by: Amp <amp@ampcode.com>
Amp-Thread-ID: https://ampcode.com/threads/T-019d9179-c196-7237-b643-008fa871803d
@grandizzy grandizzy force-pushed the georgen/update-deps branch from 27d5535 to 93d1fc2 Compare April 15, 2026 14:47
@grandizzy grandizzy requested review from horsefacts and jxom April 15, 2026 14:54
@jxom jxom force-pushed the georgen/update-deps branch from 901c6f1 to 1f36952 Compare April 15, 2026 23:33
@jxom jxom merged commit b724110 into main Apr 15, 2026
9 checks passed
@jxom jxom deleted the georgen/update-deps branch April 15, 2026 23:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants