chore(deps): consolidated dependency refresh (supersedes 20 dependabot PRs) - #268
Conversation
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 7.3.3 to 8.0.11. - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.0.11/packages/vite) --- updated-dependencies: - dependency-name: vite dependency-version: 8.0.11 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) from 0.91.1 to 0.95.1. - [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases) - [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md) - [Commits](anthropics/anthropic-sdk-typescript@sdk-v0.91.1...sdk-v0.95.1) --- updated-dependencies: - dependency-name: "@anthropic-ai/sdk" dependency-version: 0.95.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) from 5.2.0 to 6.0.1. - [Release notes](https://github.com/vitejs/vite-plugin-react/releases) - [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.0.1/packages/plugin-react) --- updated-dependencies: - dependency-name: "@vitejs/plugin-react" dependency-version: 6.0.1 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) from 2.4.9 to 2.4.15. - [Release notes](https://github.com/biomejs/biome/releases) - [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md) - [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.4.15/packages/@biomejs/biome) --- updated-dependencies: - dependency-name: "@biomejs/biome" dependency-version: 2.4.15 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [lint-staged](https://github.com/lint-staged/lint-staged) from 16.4.0 to 17.0.4. - [Release notes](https://github.com/lint-staged/lint-staged/releases) - [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md) - [Commits](lint-staged/lint-staged@v16.4.0...v17.0.4) --- updated-dependencies: - dependency-name: lint-staged dependency-version: 17.0.4 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Updates the requirements on [sentry-sdk](https://github.com/getsentry/sentry-python) to permit the latest version. - [Release notes](https://github.com/getsentry/sentry-python/releases) - [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md) - [Commits](getsentry/sentry-python@2.0.0...2.59.0) --- updated-dependencies: - dependency-name: sentry-sdk dependency-version: 2.59.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
--- updated-dependencies: - dependency-name: aiohttp dependency-version: 3.13.5 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Updates the requirements on [pywin32](https://github.com/mhammond/pywin32) to permit the latest version. - [Release notes](https://github.com/mhammond/pywin32/releases) - [Changelog](https://github.com/mhammond/pywin32/blob/main/CHANGES.md) - [Commits](https://github.com/mhammond/pywin32/commits) --- updated-dependencies: - dependency-name: pywin32 dependency-version: '311' dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Updates the requirements on [pandas](https://github.com/pandas-dev/pandas) to permit the latest version. - [Release notes](https://github.com/pandas-dev/pandas/releases) - [Commits](pandas-dev/pandas@v2.2.0...v3.0.2) --- updated-dependencies: - dependency-name: pandas dependency-version: 3.0.2 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Updates the requirements on [httpx](https://github.com/encode/httpx) to permit the latest version. - [Release notes](https://github.com/encode/httpx/releases) - [Changelog](https://github.com/encode/httpx/blob/master/CHANGELOG.md) - [Commits](encode/httpx@0.25.0...0.28.1) --- updated-dependencies: - dependency-name: httpx dependency-version: 0.28.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7. - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4...v7) --- updated-dependencies: - dependency-name: actions/upload-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/upload-pages-artifact](https://github.com/actions/upload-pages-artifact) from 3 to 5. - [Release notes](https://github.com/actions/upload-pages-artifact/releases) - [Commits](actions/upload-pages-artifact@v3...v5) --- updated-dependencies: - dependency-name: actions/upload-pages-artifact dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4...v6) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 8. - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@v4...v8) --- updated-dependencies: - dependency-name: actions/download-artifact dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/configure-pages](https://github.com/actions/configure-pages) from 5 to 6. - [Release notes](https://github.com/actions/configure-pages/releases) - [Commits](actions/configure-pages@v5...v6) --- updated-dependencies: - dependency-name: actions/configure-pages dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [qs](https://github.com/ljharb/qs) from 6.15.0 to 6.15.2. - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.15.0...v6.15.2) --- updated-dependencies: - dependency-name: qs dependency-version: 6.15.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.5 to 5.0.6. - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v5.0.5...v5.0.6) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 5.0.6 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [hono](https://github.com/honojs/hono) from 4.12.16 to 4.12.18. - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.16...v4.12.18) --- updated-dependencies: - dependency-name: hono dependency-version: 4.12.18 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.0 to 3.1.2. - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.0...v3.1.2) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
Warning Review limit reached
Your plan includes 1 review of capacity. Refill in 44 minutes and 28 seconds. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more review capacity refills, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than trial, open-source, and free plans. In all cases, review capacity refills continuously over time. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
📝 WalkthroughWalkthroughThis PR updates dependency and action versions across the project infrastructure and application stack. GitHub Actions in the docs deployment workflow are upgraded to newer majors, backend Python dependencies including data processing and HTTP client libraries are bumped, and frontend JavaScript packages for tooling and SDK client are updated to newer versions. ChangesDependency and Action Version Updates
🎯 2 (Simple) | ⏱️ ~8 minutes
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/docs-site-pages.yml:
- Around line 28-29: The Checkout step using actions/checkout@v6 in
docs-site-pages.yml currently leaves persisted credentials enabled; update the
"Checkout" job step (actions/checkout) to explicitly set persist-credentials:
false so the runner does not keep repository credentials unless this job needs
authenticated git operations.
- Line 29: Update the workflow to pin all mutable action refs to their
corresponding full commit SHAs instead of tags for actions/checkout,
actions/upload-artifact, actions/download-artifact, actions/configure-pages,
actions/upload-pages-artifact, and actions/deploy-pages (replace uses:
actions/...@vX with uses: actions/...@<commit-sha>); in the checkout step (uses:
actions/checkout) add a with: persist-credentials: false entry to disable
credential persistence. Ensure you update the deploy-pages usage as well (the
deploy action referenced separately) to its specific commit SHA.
In `@apps/backend/requirements.txt`:
- Around line 18-19: Update the stale comment that reads "pandas 2.2.0+ required
for pre-built wheels on Python 3.12" to match the actual requirement pinned in
the file (pandas>=3.0.2; python_version >= "3.12") so the rationale reflects
pandas 3.x; locate the comment above the pandas requirement line and change its
version text to reference pandas 3.0.2 (or "pandas 3.x") and optionally note the
same Python 3.12 wheel rationale.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 918800c7-39da-431c-82c0-4ed016cfda82
⛔ Files ignored due to path filters (1)
package-lock.jsonis excluded by!**/package-lock.json,!**/package-lock.json
📒 Files selected for processing (3)
.github/workflows/docs-site-pages.ymlapps/backend/requirements.txtapps/frontend/package.json
…ty review Backend: - Bump litellm 1.84.0rc1 -> 1.86.0. The RC pinned aiohttp==3.13.4 which contradicted aiohttp>=3.13.5 introduced earlier in this PR. 1.86.0 allows aiohttp<4.0,>=3.10 and keeps openai==2.33.0 valid (requires >=2.20.0,<3.0.0). - Update stale comment that still referenced pandas 2.2.0+ rationale after the bump to pandas>=3.0.2. Workflow .github/workflows/docs-site-pages.yml: - Pin actions/checkout, actions/upload-artifact, actions/download-artifact, actions/configure-pages, actions/upload-pages-artifact, actions/deploy-pages to their commit SHAs (zizmor policy: no mutable refs). - Add persist-credentials: false to the checkout step (least privilege; the build job does not perform any authenticated git operations). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Resolves `npm ci` failure on CI: Invalid: lock file's @anthropic-ai/sdk@0.91.1 does not satisfy @anthropic-ai/sdk@0.95.2 Missing: vite@8.0.14 from lock file Missing: @vitejs/plugin-react@6.0.2 from lock file ... The cherry-picked frontend bumps modified apps/frontend/package.json but the project uses npm workspaces, so dependencies resolve into the root package-lock.json. Regenerated via `npm install --package-lock-only --workspaces --include-workspace-root` on Node v20.19.5. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|



Summary
Свёрнутый PR, в одно место собирающий все открытые
chore(deps)иci(deps)обновления от Dependabot. Каждый коммит — оригинальный коммит Dependabot, cherry-pick'нутый поверхdevelop. Авторство и сообщения сохранены.Сводка по группам
Frontend (
apps/frontend/package.json) — 5 обновленийvite7.3.3 → 8.0.11 (major) — chore(deps): Bump vite from 7.3.3 to 8.0.11 in /apps/frontend #249@anthropic-ai/sdk0.91.1 → 0.95.1 — chore(deps): Bump @anthropic-ai/sdk from 0.91.1 to 0.95.1 in /apps/frontend #248@vitejs/plugin-react5.2.0 → 6.0.1 (major) — chore(deps): Bump @vitejs/plugin-react from 5.2.0 to 6.0.1 in /apps/frontend #247@biomejs/biome2.4.9 → 2.4.15 — chore(deps): Bump @biomejs/biome from 2.4.9 to 2.4.15 in /apps/frontend #246lint-staged16.4.0 → 17.0.4 (major) — chore(deps): Bump lint-staged from 16.4.0 to 17.0.4 in /apps/frontend #245Backend (
apps/backend/requirements.txt) — 5 обновленийsentry-sdk≥2.0.0 → ≥2.59.0 — chore(deps): Update sentry-sdk requirement from >=2.0.0 to >=2.59.0 in /apps/backend #244aiohttp≥3.9.0 → ≥3.13.5 — chore(deps): Update aiohttp requirement from >=3.9.0 to >=3.13.5 in /apps/backend #243pywin32≥306 → ≥311 — chore(deps): Update pywin32 requirement from >=306 to >=311 in /apps/backend #242pandas≥2.2.0 → ≥3.0.2 (major) — chore(deps): Update pandas requirement from >=2.2.0 to >=3.0.2 in /apps/backend #241httpx≥0.25.0 → ≥0.28.1 — chore(deps): Update httpx requirement from >=0.25.0 to >=0.28.1 in /apps/backend #239GitHub Actions (
.github/workflows/docs-site-pages.yml) — 5 обновленийactions/upload-artifactv4 → v7 (major) — ci(deps): Bump actions/upload-artifact from 4 to 7 #240actions/upload-pages-artifactv3 → v5 (major) — ci(deps): Bump actions/upload-pages-artifact from 3 to 5 #238actions/checkoutv4 → v6 (major) — ci(deps): Bump actions/checkout from 4 to 6 #237actions/download-artifactv4 → v8 (major) — ci(deps): Bump actions/download-artifact from 4 to 8 #236actions/configure-pagesv5 → v6 — ci(deps): Bump actions/configure-pages from 5 to 6 #235npm root (
package-lock.json) — 4 обновленияqs6.15.0 → 6.15.2 — chore(deps): Bump qs from 6.15.0 to 6.15.2 #265brace-expansion5.0.5 → 5.0.6 — chore(deps): Bump brace-expansion from 5.0.5 to 5.0.6 #259hono4.12.16 → 4.12.18 — chore(deps): Bump hono from 4.12.16 to 4.12.18 #234fast-uri3.1.0 → 3.1.2 — chore(deps): Bump fast-uri from 3.1.0 to 3.1.2 #233Пропущено (уже подтянулось транзитивно)
@hono/node-server1.19.11 → 1.19.14 — ci(deps): Bump @hono/node-server from 1.19.11 to 1.19.14 #211 (версия 1.19.14 пришла вместе с bump hono в chore(deps): Bump hono from 4.12.16 to 4.12.18 #234)Superseded PRs
После мержа закрыть: #265, #259, #249, #248, #247, #246, #245, #244, #243, #242, #241, #240, #239, #238, #237, #236, #235, #234, #233, #211
Test plan
apps/frontend:npm install+npm run build— особое внимание к vite 7→8 и plugin-react 5→6 (breaking changes)apps/frontend: проверить biome конфиг (между 2.4.9 и 2.4.15 могли поменяться правила)apps/frontend: lint-staged 16→17 — проверить, что pre-commit hooks работаютapps/backend: pandas 2→3 — прогнать тесты, использующие pandas (если есть)docs-site-pages.yml— запустить вручную, убедиться что pages build/deploy работает на новых версиях actionsnpm ciв корне отрабатывает без warning'ов о версияхЗамечания
package-lock.jsonсобран последовательным cherry-pick'ом (стратегия-X theirsдля авторазрешения). Возможно, стоит пересобрать локально черезnpm installдля нормализации перед мержем.🤖 Generated with Claude Code
Summary by CodeRabbit