Skip to content

chore(deps): bump the updates group across 1 directory with 43 updates - #78

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/grafana-plugin/updates-b4441409cd
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/grafana-plugin/updates-b4441409cd

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown

Bumps the updates group with 43 updates in the /grafana-plugin directory:

Package From To
@dnd-kit/core 6.1.0 6.3.1
@emotion/css 11.10.6 11.13.5
@grafana/data 11.2.0 11.6.16
@grafana/labels 1.6.6 1.6.13
@grafana/runtime 11.2.0 11.6.16
@grafana/schema 11.2.0 11.6.16
@grafana/ui 11.2.0 11.6.16
axios 1.19.0 1.20.0
dayjs 1.11.13 1.11.23
linkify-react 4.3.2 4.3.3
linkifyjs 4.3.2 4.3.3
mobx 6.12.0 6.16.1
mobx-react 9.1.0 9.2.2
openapi-fetch 0.8.2 0.17.0
rc-table 7.47.5 7.55.1
react 18.2.0 18.3.1
react-copy-to-clipboard 5.1.0 5.1.1
react-dom 18.2.0 18.3.1
react-draggable 4.7.1 4.7.2
react-hook-form 7.53.0 7.89.0
react-modal 3.16.1 3.16.3
react-string-replace 0.4.4 0.5.1
react-use 17.5.1 17.6.0
tslib 2.5.3 2.8.1
@jest/globals 30.5.0 30.5.2
@playwright/test 1.62.1 1.63.0
@rsbuild/core 2.2.1 2.2.11
@rsbuild/plugin-react 2.1.0 2.1.1
@swc/core 1.16.1 1.16.12
@testing-library/dom 10.4.1 10.4.2
@testing-library/user-event 14.6.6 14.6.7
@types/node 24.13.3 24.19.0
dompurify 3.4.14 3.4.16
express 4.21.2 4.22.3
jest 30.5.0 30.5.2
jest-environment-jsdom 30.5.0 30.5.2
knip 6.33.0 6.38.0
mailslurp-client 17.4.0 17.6.0
moment-timezone 0.6.3 0.6.4
oxfmt 0.65.0 0.71.0
oxlint 1.80.0 1.86.0
stylelint 17.14.1 17.15.0
ts-jest 29.4.12 29.4.14

Updates @dnd-kit/core from 6.1.0 to 6.3.1

Changelog

Sourced from @​dnd-kit/core's changelog.

6.3.1

Patch Changes

  • #1555 62f632a Thanks @​clauderic! - Added Tab to the list of default key codes that end a drag and drop operation. Can be customized by passing in a custom list of keyCodes to the KeyboardSensor options.

6.3.0

Minor Changes

  • #1539 0c6a28d Thanks @​irobot! - Make it possible to add visual cues when using activation constraints.

    Context

    Activation constraints are used when we want to prevent accidental dragging or when pointer press can mean more than "start dragging".

    A typical use case is a button that needs to respond to both "click" and "drag" gestures. Clicks can be distinguished from drags based on how long the pointer was held pressed.

    The problem

    A control that responds differently to a pointer press based on duration or distance can be confusing to use -- the user has to guess how long to keep holding or how far to keep dragging until their intent is acknowledged.

    Implementing such cues is currently possible by attaching extra event listeners so that we know when a drag is pending. Furthermore, the listener needs to have access to the same constraints that were applied to the sensor initiating the drag. This can be made to work in simple cases, but it becomes error-prone and difficult to maintain in complex scenarios.

    Solution

    This changeset proposes the addition of two new events: onDragPending and onDragAbort.

    onDragPending

    A drag is considered to be pending when the pointer has been pressed and there are activation constraints that need to be satisfied before a drag can start.

    This event is initially fired on pointer press. At this time offset (see below) will be undefined.

    It will subsequently be fired every time the pointer is moved. This is to enable visual cues for distance-based activation.

    The event's payload contains all the information necessary for providing visual feedback:

... (truncated)

Commits
  • 97c1609 Version Packages
  • 62f632a End keyboard drag operation when pressing tab
  • 060c982 Version Packages
  • 9175566 Merge branch 'master' into feature/constraint-cues
  • 2eedcc3 Version Packages
  • 835ae76 Lint
  • 3c4f627 Merge pull request #1543 from clauderic/patch-1
  • baad391 Merge pull request #1542 from clauderic/fix-zero-id
  • b7f46bb Merge pull request #1541 from clauderic/handle-cancel-events
  • 2eb636f Merge pull request #1435 from knaveenkumar3576/user/knaveenkumar3576/improved...
  • Additional commits viewable in compare view

Updates @emotion/css from 11.10.6 to 11.13.5

Release notes

Sourced from @​emotion/css's releases.

@​emotion/css@​11.13.5

Patch Changes

  • #3270 77d930d Thanks @​emmatown! - Fix inconsistent hashes using development vs production bundles/exports conditions when using @emotion/babel-plugin with sourceMap: true (the default). This is particularly visible when using Emotion with the Next.js Pages router where the development condition is used when bundling code but not when importing external code with Node.js.

  • Updated dependencies [77d930d]:

    • @​emotion/serialize@​1.3.3
    • @​emotion/cache@​11.13.5
    • @​emotion/utils@​1.4.2
    • @​emotion/babel-plugin@​11.13.5

@​emotion/css@​11.13.4

Patch Changes

@​emotion/css@​11.13.0

Minor Changes

  • #3198 d8ff8a5 Thanks @​Andarist! - Migrated away from relying on process.env.NODE_ENV checks to differentiate between production and development builds.

    Development builds (and other environment-specific builds) can be used by using proper conditions (see here). Most modern bundlers/frameworks already preconfigure those for the user so no action has to be taken.

    Default files should continue to work in all environments.

Patch Changes

@​emotion/css@​11.12.0

Minor Changes

  • #2558 85772c3 Thanks @​emmatown! - Source code has been migrated to TypeScript. From now on type declarations will be emitted based on that, instead of being hand-written.

Patch Changes

@​emotion/css@​11.11.2

... (truncated)

Commits

Updates @grafana/data from 11.2.0 to 11.6.16

Release notes

Sourced from @​grafana/data's releases.

11.6.16

Download page What's new highlights

Features and enhancements

Bug fixes

  • Datasources: return 400 when payload UID does not match URL UID in PUT /api/datasources/uid/:uid #125516, @​papagian

11.6.15

Download page What's new highlights

Features and enhancements

Bug fixes

11.6.14

Download page What's new highlights

Bug fixes

11.6.14+security-01

Download page What's new highlights

Bug fixes

11.6.14+security-04

... (truncated)

Changelog

Sourced from @​grafana/data's changelog.

11.6.16 (2026-06-23)

Features and enhancements

Bug fixes

  • Datasources: return 400 when payload UID does not match URL UID in PUT /api/datasources/uid/:uid #125516, @​papagian

11.6.15 (2026-06-09)

Features and enhancements

Bug fixes

11.6.14+security-04 (2026-05-12)

Bug fixes

11.6.14+security-01 (2026-03-25)

Bug fixes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​grafana/data since your current version.


Updates @grafana/labels from 1.6.6 to 1.6.13

Commits

Updates @grafana/runtime from 11.2.0 to 11.6.16

Release notes

Sourced from @​grafana/runtime's releases.

11.6.16

Download page What's new highlights

Features and enhancements

Bug fixes

  • Datasources: return 400 when payload UID does not match URL UID in PUT /api/datasources/uid/:uid #125516, @​papagian

11.6.15

Download page What's new highlights

Features and enhancements

Bug fixes

11.6.14

Download page What's new highlights

Bug fixes

11.6.14+security-01

Download page What's new highlights

Bug fixes

11.6.14+security-04

... (truncated)

Changelog

Sourced from @​grafana/runtime's changelog.

11.6.16 (2026-06-23)

Features and enhancements

Bug fixes

  • Datasources: return 400 when payload UID does not match URL UID in PUT /api/datasources/uid/:uid #125516, @​papagian

11.6.15 (2026-06-09)

Features and enhancements

Bug fixes

11.6.14+security-04 (2026-05-12)

Bug fixes

11.6.14+security-01 (2026-03-25)

Bug fixes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​grafana/runtime since your current version.


Updates @grafana/schema from 11.2.0 to 11.6.16

Release notes

Sourced from @​grafana/schema's releases.

11.6.16

Download page What's new highlights

Features and enhancements

Bug fixes

  • Datasources: return 400 when payload UID does not match URL UID in PUT /api/datasources/uid/:uid #125516, @​papagian

11.6.15

Download page What's new highlights

Features and enhancements

Bug fixes

11.6.14

Download page What's new highlights

Bug fixes

11.6.14+security-01

Download page What's new highlights

Bug fixes

11.6.14+security-04

... (truncated)

Changelog

Sourced from @​grafana/schema's changelog.

11.6.16 (2026-06-23)

Features and enhancements

Bug fixes

  • Datasources: return 400 when payload UID does not match URL UID in PUT /api/datasources/uid/:uid #125516, @​papagian

11.6.15 (2026-06-09)

Features and enhancements

Bug fixes

11.6.14+security-04 (2026-05-12)

Bug fixes

11.6.14+security-01 (2026-03-25)

Bug fixes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​grafana/schema since your current version.


Updates @grafana/ui from 11.2.0 to 11.6.16

Release notes

Sourced from @​grafana/ui's releases.

11.6.16

Download page What's new highlights

Features and enhancements

Bug fixes

  • Datasources: return 400 when payload UID does not match URL UID in PUT /api/datasources/uid/:uid #125516, @​papagian

11.6.15

Download page What's new highlights

Features and enhancements

Bug fixes

11.6.14

Download page What's new highlights

Bug fixes

11.6.14+security-01

Download page What's new highlights

Bug fixes

11.6.14+security-04

... (truncated)

Changelog

Sourced from @​grafana/ui's changelog.

11.6.16 (2026-06-23)

Features and enhancements

Bug fixes

  • Datasources: return 400 when payload UID does not match URL UID in PUT /api/datasources/uid/:uid #125516, @​papagian

11.6.15 (2026-06-09)

Features and enhancements

Bug fixes

11.6.14+security-04 (2026-05-12)

Bug fixes

11.6.14+security-01 (2026-03-25)

Bug fixes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​grafana/ui since your current version.


Updates axios from 1.19.0 to 1.20.0

Release notes

Sourced from axios's releases.

v1.20.0 — August 19, 2026

This release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.

⚠️ Breaking Changes & Deprecations

  • HTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (#11082)

🔒 Security Fixes

  • Runtime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (#11141)

🐛 Bug Fixes

  • Interceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (#11087, #11118)
  • Request Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (#11109)
  • XHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (#11094, #11121)
  • Node.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (#11091)
  • Core Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (#11096)

🔧 Maintenance & Chores

  • Dependencies: Updated fast-uri, postcss, js-yaml, mocha, development-tooling groups, and GitHub Actions dependencies. (#11092, #11098, #11099, #11106, #11107, #11122, #11123, #11126, #11127, #11133, #11140, #11143, #11144)
  • Documentation: Applied the v1.19.0 documentation updates, added the missing fs import to the README stream example, introduced localized global search, and repaired the interceptor test link. (#11101, #11113, #11097, #11119)
  • Sponsorship: Updated sponsorship links and data and added ScrapingBee as a sponsor. (#11124, #11136, #11137)
  • CI and Release: Switched ESM smoke tests to locked dependencies and synchronized package and runtime version metadata for v1.20.0. (#11128, #11152)

🌟 New Contributors

We are thrilled to welcome our new contributors. Thank you for helping improve axios:

Full Changelog (axios/axios@v1.19.0...v1.20.0)

Changelog

Sourced from axios's changelog.

Changelog

Commits
  • 84a9f3b chore(release): prepare release 1.20.0 (#11152)
  • e6824ee fix: core methodList, HTTP adapter errors, and add tests (#11096)
  • d8a919f fix(xhr): flush final progress during the live loadend dispatch (#11121)
  • 2d2a21a fix(interceptors): tolerate nullish handlers in syncHandlerEntries (#11118)
  • d19040b fix: harden runtime option handling (#11141)
  • e0a02dd chore(deps): bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 in the github-...
  • d10cb3a chore(deps-dev): bump the development_dependencies group with 4 updates (#11143)
  • 2c94646 chore(deps): bump js-yaml and mocha in /tests/smoke/cjs (#11133)
  • 76c12bc chore(deps-dev): bump js-yaml from 4.3.0 to 4.3.1 (#11140)
  • ba98559 docs: add ScrapingBee sponsor (#11137)
  • Additional commits viewable in compare view

Updates dayjs from 1.11.13 to 1.11.23

Release notes

Sourced from dayjs's releases.

v1.11.23

1.11.23 (2026-08-17)

Bug Fixes

  • plugin: timezone plugin prevent RangeError for invalid Day.js values (#3180) (dad46e6)
  • plugin: timezone plugin prevent RangeError for invalid Day.js values (#3180) (#3181) (2a3785f)

v1.11.22

1.11.22 (2026-08-16)

Bug Fixes

  • plugin: timezone compute instance .tz() offset without host DST (#3174) (e27ee80), closes #3169

v1.11.21

1.11.21 (2026-05-26)

Bug Fixes

v1.11.20

1.11.20 (2026-03-12)

Bug Fixes

  • Update locale km.js to support meridiem (#3017) (9d2b6a1)
  • update updateLocale plugin to merge nested object properties instead of replacing (#3012) (99691c5), closes #1118

v1.11.19

1.11.19 (2025-10-31)

Bug Fixes

  • added usage warnings for diff + updated unit tests (#2948) (

Bumps the updates group with 43 updates in the /grafana-plugin directory:

| Package | From | To |
| --- | --- | --- |
| [@dnd-kit/core](https://github.com/clauderic/dnd-kit/tree/HEAD/packages/core) | `6.1.0` | `6.3.1` |
| [@emotion/css](https://github.com/emotion-js/emotion) | `11.10.6` | `11.13.5` |
| [@grafana/data](https://github.com/grafana/grafana/tree/HEAD/packages/grafana-data) | `11.2.0` | `11.6.16` |
| [@grafana/labels](https://github.com/grafana/gops-labels) | `1.6.6` | `1.6.13` |
| [@grafana/runtime](https://github.com/grafana/grafana/tree/HEAD/packages/grafana-runtime) | `11.2.0` | `11.6.16` |
| [@grafana/schema](https://github.com/grafana/grafana/tree/HEAD/packages/grafana-schema) | `11.2.0` | `11.6.16` |
| [@grafana/ui](https://github.com/grafana/grafana/tree/HEAD/packages/grafana-ui) | `11.2.0` | `11.6.16` |
| [axios](https://github.com/axios/axios) | `1.19.0` | `1.20.0` |
| [dayjs](https://github.com/iamkun/dayjs) | `1.11.13` | `1.11.23` |
| [linkify-react](https://github.com/nfrasser/linkifyjs/tree/HEAD/packages/linkify-react) | `4.3.2` | `4.3.3` |
| [linkifyjs](https://github.com/nfrasser/linkifyjs/tree/HEAD/packages/linkifyjs) | `4.3.2` | `4.3.3` |
| [mobx](https://github.com/mobxjs/mobx) | `6.12.0` | `6.16.1` |
| [mobx-react](https://github.com/mobxjs/mobx) | `9.1.0` | `9.2.2` |
| [openapi-fetch](https://github.com/openapi-ts/openapi-typescript/tree/HEAD/packages/openapi-fetch) | `0.8.2` | `0.17.0` |
| [rc-table](https://github.com/react-component/table) | `7.47.5` | `7.55.1` |
| [react](https://github.com/react/react/tree/HEAD/packages/react) | `18.2.0` | `18.3.1` |
| [react-copy-to-clipboard](https://github.com/nkbt/react-copy-to-clipboard) | `5.1.0` | `5.1.1` |
| [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `18.2.0` | `18.3.1` |
| [react-draggable](https://github.com/react-grid-layout/react-draggable) | `4.7.1` | `4.7.2` |
| [react-hook-form](https://github.com/react-hook-form/react-hook-form) | `7.53.0` | `7.89.0` |
| [react-modal](https://github.com/reactjs/react-modal) | `3.16.1` | `3.16.3` |
| [react-string-replace](https://github.com/iansinnott/react-string-replace) | `0.4.4` | `0.5.1` |
| [react-use](https://github.com/streamich/react-use) | `17.5.1` | `17.6.0` |
| [tslib](https://github.com/Microsoft/tslib) | `2.5.3` | `2.8.1` |
| [@jest/globals](https://github.com/jestjs/jest/tree/HEAD/packages/jest-globals) | `30.5.0` | `30.5.2` |
| [@playwright/test](https://github.com/microsoft/playwright) | `1.62.1` | `1.63.0` |
| [@rsbuild/core](https://github.com/web-infra-dev/rsbuild/tree/HEAD/packages/core) | `2.2.1` | `2.2.11` |
| [@rsbuild/plugin-react](https://github.com/web-infra-dev/rsbuild/tree/HEAD/packages/plugin-react) | `2.1.0` | `2.1.1` |
| [@swc/core](https://github.com/swc-project/swc/tree/HEAD/packages/core) | `1.16.1` | `1.16.12` |
| [@testing-library/dom](https://github.com/testing-library/dom-testing-library) | `10.4.1` | `10.4.2` |
| [@testing-library/user-event](https://github.com/testing-library/user-event) | `14.6.6` | `14.6.7` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `24.13.3` | `24.19.0` |
| [dompurify](https://github.com/cure53/DOMPurify) | `3.4.14` | `3.4.16` |
| [express](https://github.com/expressjs/express) | `4.21.2` | `4.22.3` |
| [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest) | `30.5.0` | `30.5.2` |
| [jest-environment-jsdom](https://github.com/jestjs/jest/tree/HEAD/packages/jest-environment-jsdom) | `30.5.0` | `30.5.2` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.33.0` | `6.38.0` |
| [mailslurp-client](https://github.com/mailslurp/mailslurp-client) | `17.4.0` | `17.6.0` |
| [moment-timezone](https://github.com/moment/moment-timezone) | `0.6.3` | `0.6.4` |
| [oxfmt](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxfmt) | `0.65.0` | `0.71.0` |
| [oxlint](https://github.com/oxc-project/oxc/tree/HEAD/npm/oxlint) | `1.80.0` | `1.86.0` |
| [stylelint](https://github.com/stylelint/stylelint) | `17.14.1` | `17.15.0` |
| [ts-jest](https://github.com/kulshekhar/ts-jest) | `29.4.12` | `29.4.14` |



Updates `@dnd-kit/core` from 6.1.0 to 6.3.1
- [Release notes](https://github.com/clauderic/dnd-kit/releases)
- [Changelog](https://github.com/clauderic/dnd-kit/blob/@dnd-kit/core@6.3.1/packages/core/CHANGELOG.md)
- [Commits](https://github.com/clauderic/dnd-kit/commits/@dnd-kit/core@6.3.1/packages/core)

Updates `@emotion/css` from 11.10.6 to 11.13.5
- [Release notes](https://github.com/emotion-js/emotion/releases)
- [Changelog](https://github.com/emotion-js/emotion/blob/main/CHANGELOG.md)
- [Commits](https://github.com/emotion-js/emotion/compare/@emotion/css@11.10.6...@emotion/css@11.13.5)

Updates `@grafana/data` from 11.2.0 to 11.6.16
- [Release notes](https://github.com/grafana/grafana/releases)
- [Changelog](https://github.com/grafana/grafana/blob/main/CHANGELOG.md)
- [Commits](https://github.com/grafana/grafana/commits/v11.6.16/packages/grafana-data)

Updates `@grafana/labels` from 1.6.6 to 1.6.13
- [Commits](https://github.com/grafana/gops-labels/commits)

Updates `@grafana/runtime` from 11.2.0 to 11.6.16
- [Release notes](https://github.com/grafana/grafana/releases)
- [Changelog](https://github.com/grafana/grafana/blob/main/CHANGELOG.md)
- [Commits](https://github.com/grafana/grafana/commits/v11.6.16/packages/grafana-runtime)

Updates `@grafana/schema` from 11.2.0 to 11.6.16
- [Release notes](https://github.com/grafana/grafana/releases)
- [Changelog](https://github.com/grafana/grafana/blob/main/CHANGELOG.md)
- [Commits](https://github.com/grafana/grafana/commits/v11.6.16/packages/grafana-schema)

Updates `@grafana/ui` from 11.2.0 to 11.6.16
- [Release notes](https://github.com/grafana/grafana/releases)
- [Changelog](https://github.com/grafana/grafana/blob/main/CHANGELOG.md)
- [Commits](https://github.com/grafana/grafana/commits/v11.6.16/packages/grafana-ui)

Updates `axios` from 1.19.0 to 1.20.0
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v1.19.0...v1.20.0)

Updates `dayjs` from 1.11.13 to 1.11.23
- [Release notes](https://github.com/iamkun/dayjs/releases)
- [Changelog](https://github.com/iamkun/dayjs/blob/v1.11.23/CHANGELOG.md)
- [Commits](iamkun/dayjs@v1.11.13...v1.11.23)

Updates `linkify-react` from 4.3.2 to 4.3.3
- [Release notes](https://github.com/nfrasser/linkifyjs/releases)
- [Changelog](https://github.com/nfrasser/linkifyjs/blob/main/CHANGELOG.md)
- [Commits](https://github.com/nfrasser/linkifyjs/commits/v4.3.3/packages/linkify-react)

Updates `linkifyjs` from 4.3.2 to 4.3.3
- [Release notes](https://github.com/nfrasser/linkifyjs/releases)
- [Changelog](https://github.com/nfrasser/linkifyjs/blob/main/CHANGELOG.md)
- [Commits](https://github.com/nfrasser/linkifyjs/commits/v4.3.3/packages/linkifyjs)

Updates `mobx` from 6.12.0 to 6.16.1
- [Release notes](https://github.com/mobxjs/mobx/releases)
- [Commits](https://github.com/mobxjs/mobx/compare/mobx@6.12.0...mobx@6.16.1)

Updates `mobx-react` from 9.1.0 to 9.2.2
- [Release notes](https://github.com/mobxjs/mobx/releases)
- [Commits](https://github.com/mobxjs/mobx/compare/mobx-react@9.1.0...mobx-react@9.2.2)

Updates `openapi-fetch` from 0.8.2 to 0.17.0
- [Release notes](https://github.com/openapi-ts/openapi-typescript/releases)
- [Changelog](https://github.com/openapi-ts/openapi-typescript/blob/main/packages/openapi-fetch/CHANGELOG.md)
- [Commits](https://github.com/openapi-ts/openapi-typescript/commits/openapi-fetch@0.17.0/packages/openapi-fetch)

Updates `rc-table` from 7.47.5 to 7.55.1
- [Release notes](https://github.com/react-component/table/releases)
- [Changelog](https://github.com/react-component/table/blob/master/CHANGELOG.md)
- [Commits](react-component/table@v7.47.5...v7.55.1)

Updates `react` from 18.2.0 to 18.3.1
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v18.3.1/packages/react)

Updates `react-copy-to-clipboard` from 5.1.0 to 5.1.1
- [Release notes](https://github.com/nkbt/react-copy-to-clipboard/releases)
- [Commits](nkbt/react-copy-to-clipboard@v5.1.0...v5.1.1)

Updates `react-dom` from 18.2.0 to 18.3.1
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v18.3.1/packages/react-dom)

Updates `react-draggable` from 4.7.1 to 4.7.2
- [Release notes](https://github.com/react-grid-layout/react-draggable/releases)
- [Changelog](https://github.com/react-grid-layout/react-draggable/blob/master/CHANGELOG.md)
- [Commits](react-grid-layout/react-draggable@v4.7.1...v4.7.2)

Updates `react-hook-form` from 7.53.0 to 7.89.0
- [Release notes](https://github.com/react-hook-form/react-hook-form/releases)
- [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md)
- [Commits](react-hook-form/react-hook-form@v7.53.0...v7.89.0)

Updates `react-modal` from 3.16.1 to 3.16.3
- [Release notes](https://github.com/reactjs/react-modal/releases)
- [Changelog](https://github.com/reactjs/react-modal/blob/master/CHANGELOG.md)
- [Commits](reactjs/react-modal@v3.16.1...v3.16.3)

Updates `react-string-replace` from 0.4.4 to 0.5.1
- [Release notes](https://github.com/iansinnott/react-string-replace/releases)
- [Commits](iansinnott/react-string-replace@v0.4.4...v0.5.1)

Updates `react-use` from 17.5.1 to 17.6.0
- [Release notes](https://github.com/streamich/react-use/releases)
- [Changelog](https://github.com/streamich/react-use/blob/master/CHANGELOG.md)
- [Commits](streamich/react-use@v17.5.1...v17.6.0)

Updates `tslib` from 2.5.3 to 2.8.1
- [Release notes](https://github.com/Microsoft/tslib/releases)
- [Commits](microsoft/tslib@v2.5.3...v2.8.1)

Updates `@jest/globals` from 30.5.0 to 30.5.2
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.2/packages/jest-globals)

Updates `@playwright/test` from 1.62.1 to 1.63.0
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](microsoft/playwright@v1.62.1...v1.63.0)

Updates `@rsbuild/core` from 2.2.1 to 2.2.11
- [Release notes](https://github.com/web-infra-dev/rsbuild/releases)
- [Commits](https://github.com/web-infra-dev/rsbuild/commits/v2.2.11/packages/core)

Updates `@rsbuild/plugin-react` from 2.1.0 to 2.1.1
- [Release notes](https://github.com/web-infra-dev/rsbuild/releases)
- [Changelog](https://github.com/web-infra-dev/rsbuild/blob/main/packages/plugin-react/CHANGELOG.md)
- [Commits](https://github.com/web-infra-dev/rsbuild/commits/v2.1.1/packages/plugin-react)

Updates `@swc/core` from 1.16.1 to 1.16.12
- [Release notes](https://github.com/swc-project/swc/releases)
- [Changelog](https://github.com/swc-project/swc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/swc-project/swc/commits/v1.16.12/packages/core)

Updates `@testing-library/dom` from 10.4.1 to 10.4.2
- [Release notes](https://github.com/testing-library/dom-testing-library/releases)
- [Changelog](https://github.com/testing-library/dom-testing-library/blob/main/CHANGELOG.md)
- [Commits](testing-library/dom-testing-library@v10.4.1...v10.4.2)

Updates `@testing-library/user-event` from 14.6.6 to 14.6.7
- [Release notes](https://github.com/testing-library/user-event/releases)
- [Changelog](https://github.com/testing-library/user-event/blob/main/CHANGELOG.md)
- [Commits](testing-library/user-event@v14.6.6...v14.6.7)

Updates `@types/node` from 24.13.3 to 24.19.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `dompurify` from 3.4.14 to 3.4.16
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.14...3.4.16)

Updates `express` from 4.21.2 to 4.22.3
- [Release notes](https://github.com/expressjs/express/releases)
- [Changelog](https://github.com/expressjs/express/blob/v4.22.3/History.md)
- [Commits](expressjs/express@4.21.2...v4.22.3)

Updates `jest` from 30.5.0 to 30.5.2
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.2/packages/jest)

Updates `jest-environment-jsdom` from 30.5.0 to 30.5.2
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.2/packages/jest-environment-jsdom)

Updates `knip` from 6.33.0 to 6.38.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.38.0/packages/knip)

Updates `mailslurp-client` from 17.4.0 to 17.6.0
- [Changelog](https://github.com/mailslurp/mailslurp-client/blob/master/CHANGELOG.md)
- [Commits](mailslurp/mailslurp-client@v17.4.0...v17.6.0)

Updates `moment-timezone` from 0.6.3 to 0.6.4
- [Release notes](https://github.com/moment/moment-timezone/releases)
- [Changelog](https://github.com/moment/moment-timezone/blob/develop/changelog.md)
- [Commits](moment/moment-timezone@0.6.3...0.6.4)

Updates `oxfmt` from 0.65.0 to 0.71.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxfmt/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxfmt_v0.71.0/npm/oxfmt)

Updates `oxlint` from 1.80.0 to 1.86.0
- [Release notes](https://github.com/oxc-project/oxc/releases)
- [Changelog](https://github.com/oxc-project/oxc/blob/main/npm/oxlint/CHANGELOG.md)
- [Commits](https://github.com/oxc-project/oxc/commits/oxlint_v1.86.0/npm/oxlint)

Updates `stylelint` from 17.14.1 to 17.15.0
- [Release notes](https://github.com/stylelint/stylelint/releases)
- [Changelog](https://github.com/stylelint/stylelint/blob/main/CHANGELOG.md)
- [Commits](stylelint/stylelint@17.14.1...17.15.0)

Updates `ts-jest` from 29.4.12 to 29.4.14
- [Release notes](https://github.com/kulshekhar/ts-jest/releases)
- [Changelog](https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md)
- [Commits](kulshekhar/ts-jest@v29.4.12...v29.4.14)

---
updated-dependencies:
- dependency-name: "@dnd-kit/core"
  dependency-version: 6.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: "@emotion/css"
  dependency-version: 11.13.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: "@grafana/data"
  dependency-version: 11.6.16
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: "@grafana/labels"
  dependency-version: 1.6.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: "@grafana/runtime"
  dependency-version: 11.6.16
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: "@grafana/schema"
  dependency-version: 11.6.16
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: "@grafana/ui"
  dependency-version: 11.6.16
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: axios
  dependency-version: 1.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: dayjs
  dependency-version: 1.11.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: linkify-react
  dependency-version: 4.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: linkifyjs
  dependency-version: 4.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: mobx
  dependency-version: 6.16.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: mobx-react
  dependency-version: 9.2.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: openapi-fetch
  dependency-version: 0.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: rc-table
  dependency-version: 7.55.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: react
  dependency-version: 18.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: react-copy-to-clipboard
  dependency-version: 5.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: react-dom
  dependency-version: 18.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: react-draggable
  dependency-version: 4.7.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: react-hook-form
  dependency-version: 7.89.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: react-modal
  dependency-version: 3.16.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: react-string-replace
  dependency-version: 0.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: react-use
  dependency-version: 17.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: tslib
  dependency-version: 2.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: "@jest/globals"
  dependency-version: 30.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: "@playwright/test"
  dependency-version: 1.63.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: "@rsbuild/core"
  dependency-version: 2.2.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: "@rsbuild/plugin-react"
  dependency-version: 2.1.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: "@swc/core"
  dependency-version: 1.16.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: "@testing-library/dom"
  dependency-version: 10.4.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: "@testing-library/user-event"
  dependency-version: 14.6.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: "@types/node"
  dependency-version: 24.19.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: dompurify
  dependency-version: 3.4.16
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: express
  dependency-version: 4.22.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: jest
  dependency-version: 30.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: jest-environment-jsdom
  dependency-version: 30.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: knip
  dependency-version: 6.38.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: mailslurp-client
  dependency-version: 17.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: moment-timezone
  dependency-version: 0.6.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: updates
- dependency-name: oxfmt
  dependency-version: 0.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: oxlint
  dependency-version: 1.86.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: stylelint
  dependency-version: 17.15.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: updates
- dependency-name: ts-jest
  dependency-version: 29.4.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
@hansi-codes

hansi-codes Bot commented Oct 6, 2026

Copy link
Copy Markdown

🟡 Tier B · Needs changes before merging

The openapi-fetch upgrade breaks the existing custom fetch adapter and prevents normal API requests from being sent.

Updates the Grafana plugin's runtime and development dependencies, including Grafana packages, React, MobX, and build/test tooling. Refreshes the pnpm lockfile to resolve the updated versions.

Verdict New comments Fixed Still open
🛑 Changes requested 1 0 0
Finding Where
🟠 Adapt the custom fetch wrapper to the new Request-based API grafana-plugin/package.json:134
Fix with agent prompt
### Issue 1
grafana-plugin/package.json:134
**Adapt the custom fetch wrapper to the new Request-based API**

`openapi-fetch` 0.17 passes a `Request` to its custom fetch function, but `getCustomFetchFn` in `src/network/oncall-api/http-client.ts:21–31` still expects `(url, requestConfig)` and immediately calls `requestConfig.headers.set`. With the second argument absent, every request through `onCallApi()` throws before reaching the network (including loading alert groups); update the adapter to handle the Request and preserve its headers, method, and body alongside this bump.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.
📂 Walkthrough · 2
File Change
grafana-plugin/package.json Bumps runtime libraries and development tooling versions.
grafana-plugin/pnpm-lock.yaml Refreshes dependency resolutions and peer dependency snapshots.

Reviewed a2825f5 · Details · Comment @hansi-codes review to re-run, or mention @hansi-codes with a question.

@hansi-codes hansi-codes Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Tier B · 1 blocking finding to address. Summary

"mobx-react": "9.2.2",
"object-hash": "^3.0.0",
"openapi-fetch": "^0.8.1",
"openapi-fetch": "^0.17.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Adapt the custom fetch wrapper to the new Request-based API

openapi-fetch 0.17 passes a Request to its custom fetch function, but getCustomFetchFn in src/network/oncall-api/http-client.ts:21–31 still expects (url, requestConfig) and immediately calls requestConfig.headers.set. With the second argument absent, every request through onCallApi() throws before reaching the network (including loading alert groups); update the adapter to handle the Request and preserve its headers, method, and body alongside this bump.

Prompt To Fix With AI
This is a comment left during a code review.
Path: grafana-plugin/package.json
Line: 134

Comment:
**Adapt the custom fetch wrapper to the new Request-based API**

`openapi-fetch` 0.17 passes a `Request` to its custom fetch function, but `getCustomFetchFn` in `src/network/oncall-api/http-client.ts:21–31` still expects `(url, requestConfig)` and immediately calls `requestConfig.headers.set`. With the second argument absent, every request through `onCallApi()` throws before reaching the network (including loading alert groups); update the adapter to handle the Request and preserve its headers, method, and body alongside this bump.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

🟠 Major · bug · Reply if this doesn't apply.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants