Skip to content

chore(deps): combined dependabot updates - #2679

Open
kaladivo wants to merge 2 commits into
mainfrom
chore/combined-dependabot-updates
Open

chore(deps): combined dependabot updates#2679
kaladivo wants to merge 2 commits into
mainfrom
chore/combined-dependabot-updates

Conversation

@kaladivo

@kaladivo kaladivo commented Aug 13, 2026

Copy link
Copy Markdown
Collaborator

Combines all open dependabot PRs into a single update:

Dependency From To Where Replaces
next 16.2.9 16.2.11 backoffice-app, web-app #2633
nanoid 5.1.16 6.0.1 content-service #2667
postcss (dev) 8.5.15 8.5.23 backoffice-app #2645
fast-uri 3.1.2 3.1.5 lockfile only (transitive) #2666
js-yaml 3.14.2 3.15.1 lockfile only (transitive) #2663

#2565 (js-yaml 3.15.0) is superseded by the 3.15.1 bump and can be closed as well.

Resolved versions are pinned to exactly what dependabot proposed (package.json ranges stay caret, matching dependabot's own format). js-yaml@4.2.0 instances are intentionally untouched, same as in #2663.

Verified locally: pnpm turbo:typecheck (all 29 workspaces), pnpm turbo:format, and pnpm turbo:lint all pass.

Once this merges, dependabot should auto-close its PRs; if not, they can be closed manually.

Summary by CodeRabbit

  • Chores
    • Updated the web and back-office application frameworks for improved maintenance and compatibility.
    • Updated styling tool support.
    • Updated content service utilities used for generating unique identifiers.
    • Applied routine platform updates across web, back-office, and content services.
    • No user-facing feature or interface changes.

Combines open dependabot PRs into a single update:
- nanoid 5.1.16 -> 6.0.1 (content-service) [#2667]
- fast-uri 3.1.2 -> 3.1.5 [#2666]
- js-yaml 3.14.2 -> 3.15.1 [#2663]
- postcss 8.5.15 -> 8.5.23 (backoffice-app, dev) [#2645]
- next 16.2.9 -> 16.2.11 (backoffice-app, web-app) [#2633]
@coderabbitai

coderabbitai Bot commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 83d6324d-7ac3-4cc6-a565-b3e6ee70b95f

📥 Commits

Reviewing files that changed from the base of the PR and between deb7e33 and 4df6d22.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • apps/web-app/package.json
🚧 Files skipped from review as they are similar to previous changes (1)
  • apps/web-app/package.json

📝 Walkthrough

Walkthrough

The pull request updates Next.js, PostCSS, and Nanoid dependency ranges across the backoffice app, content service, and web app.

Changes

Dependency updates

Layer / File(s) Summary
Framework and tooling updates
apps/backoffice-app/package.json, apps/web-app/package.json
Updates Next.js to ^16.2.11 in both apps. Updates PostCSS to ^8.5.23 in the backoffice app.
Content service dependency update
apps/content-service/package.json
Updates Nanoid to ^6.0.0.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Mergeability Score: ⚪ Minimal · up to 4df6d

This PR updates pinned dependency versions and the lockfile without any identified merge-blocking issue; it is ready to merge after normal checks.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies a combined dependency update, which matches the primary changes across the applications.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/combined-dependabot-updates

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

ESLint install failed. For unrecoverable errors, disable the tool in CodeRabbit configuration.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Aug 13, 2026

Copy link
Copy Markdown

Greptile Summary

The PR combines dependency maintenance updates across the backoffice, content-service, and web applications.

  • Updates Next.js for the backoffice and web applications.
  • Updates nanoid in content-service and PostCSS in backoffice.
  • Refreshes the pnpm lockfile for the declared and transitive dependency updates.

Confidence Score: 5/5

The PR appears safe to merge.

No blocking failure remains.

Important Files Changed

Filename Overview
apps/backoffice-app/package.json Updates Next.js and PostCSS dependency ranges with matching lockfile resolutions.
apps/content-service/package.json Updates nanoid from major version 5 to 6; existing usage remains an ESM named import under the service's Node 24 runtime.
apps/web-app/package.json Updates the Next.js dependency range to 16.2.11.
pnpm-lock.yaml Refreshes direct resolutions and transitive peer-context snapshots for the combined dependency updates.

Reviews (2): Last reviewed commit: "Merge remote-tracking branch 'origin/mai..." | Re-trigger Greptile

@kaladivo
kaladivo enabled auto-merge (rebase) August 13, 2026 16:08
@kaladivo
kaladivo disabled auto-merge August 13, 2026 16:08
@github-actions

Copy link
Copy Markdown

📱 Preview on the staging app

Open Vexl (stage) → Account → Scan QR code and scan this:

PR preview QR code

Preview link: stagingapp.vexl.it://link/?type=load-pr-preview&channel=pr-2679&version=1.44.2

Channel pr-2679
Commit 4df6d22
Runtime 877ab8d4b6cd1b3aa836dbda494b4c893150919e, b5c07c542487bc7e92539b0b09860763590fefd5
Dashboard update group

The preview only loads into staging builds with a matching runtime — if this PR changes native code, ship a new staging build first. To go back to the staging channel: debug screen → "Clear PR preview".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant