build(deps-dev): bump @vitejs/plugin-react from 5.2.0 to 6.0.2#110
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
…n sync (#114) @emnapi/core, @emnapi/runtime, @emnapi/wasi-threads, @napi-rs/wasm-runtime, and @tybys/wasm-util only entered the lockfile as transitive deps of the optional wasm32-wasi platform bindings (@rolldown/binding-wasm32-wasi, @tailwindcss/oxide-wasm32-wasi). Dependabot's lockfile regeneration drops those entries, so every grouped bump since #105 landed with a lock missing @emnapi/* and `npm ci` failed EUSAGE on PRs #110-#113. Pinning them as direct devDependencies guarantees lock entries survive any regeneration; the $-reference overrides collapse the bindings' exact pins onto the root versions so a single entry satisfies the whole tree. The wasi bindings are never installed on CI runners (linux-x64/darwin-arm64 use native bindings), so the forced versions only affect lock resolution. Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
|
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
|
@dependabot recreate |
Bumps [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) from 5.2.0 to 6.0.2. - [Release notes](https://github.com/vitejs/vite-plugin-react/releases) - [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.0.2/packages/plugin-react) --- updated-dependencies: - dependency-name: "@vitejs/plugin-react" dependency-version: 6.0.2 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
1cd83b8 to
1e206f7
Compare
PR SummaryMedium Risk Overview v6 is a major release aligned with Vite 8: React Fast Refresh no longer goes through Babel inside the plugin (Oxc/Vite handles it), so the lockfile drops several transitive dev deps ( Reviewed by Cursor Bugbot for commit 1e206f7. Bugbot is set up for automated code reviews on this repo. Configure here. |
Bumps @vitejs/plugin-react from 5.2.0 to 6.0.2.
Release notes
Sourced from @vitejs/plugin-react's releases.
... (truncated)
Changelog
Sourced from @vitejs/plugin-react's changelog.
... (truncated)
Commits
6535b55release: plugin-react@6.0.2bf0e43bfeat(react): whitelist debugging-options (#1189)3bd1f08feat: use carets for rolldown versions (#1216)2b8df67fix(deps): update all non-major dependencies (#1218)8fa9619fix(deps): update react 19.2.6 (#1211)a4296adfix(deps): update all non-major dependencies (#1209)323ccd7fix(deps): update all non-major dependencies (#1196)a7506e1chore(deps): update vite 8.0.10 (#1198)02cff2afix(deps): update all non-major dependencies (#1184)4b9c890fix(deps): update react 19.2.5 (#1181)