deps: periodic dependency update - #200
Conversation
Update @astrojs/check, @astrojs/node, @fontsource-variable/figtree, @fontsource/ibm-plex-mono, astro, and prettier to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run build. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @anthropic-ai/claude-agent-sdk and @types/node to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run typecheck. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/guard to the 1.10.0 stable release, and bump @types/node and eve to the greatest minor version within the 7-day cooldown window. Verified with npm install, npm run typecheck, and npm run build. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/node and @types/node to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run build (tsc --noEmit). Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fastify/autoload, fastify, prettier, and tsx to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run build (tsc). Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update firebase-functions and firebase-tools to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run check (tsc). Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @langchain/openai and @types/node to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run typecheck. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/guard to the 1.10.0 stable release and bump @types/node to the greatest minor version within the 7-day cooldown window. Verified with npm install. npm run typecheck fails on main before this change too (pre-existing @arcjet/guard/mastra/v1 module resolution and implicit-any errors unrelated to these bumps), so it is not new breakage. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @nestjs/common, @nestjs/core, @nestjs/platform-express, and prettier to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run build (nest build). Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @ai-sdk/openai, @ai-sdk/react, @fontsource-variable/figtree, @fontsource/ibm-plex-mono, @hookform/resolvers, @playwright/test, @types/react, @types/react-dom, ai, next, react, react-dom, and react-hook-form to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run build. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/guard to the 1.10.0 stable release, and bump @types/node, @types/react, @types/react-dom, ai, next, react, react-dom, and workflow to the greatest minor version within the 7-day cooldown window. Verified with npm install, npm run typecheck, and npm run build. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/inspect, @arcjet/next, @fontsource-variable/figtree, @fontsource/ibm-plex-mono, @types/node, @types/react, @types/react-dom, next, react, and react-dom to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run build. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fontsource-variable/figtree, @fontsource/ibm-plex-mono, @types/react, @types/react-dom, next, react, and react-dom to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run build. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fontsource-variable/figtree, @fontsource/ibm-plex-mono, @hookform/resolvers, @types/react, @types/react-dom, next, react, react-dom, and react-hook-form to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run build. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fontsource-variable/figtree, @fontsource/ibm-plex-mono, @hookform/resolvers, @types/react, @types/react-dom, next, react, react-dom, and react-hook-form to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run build. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/guard and @arcjet/sensitive-info-rampart to the 1.10.0 stable release, and bump @ai-sdk/provider-utils, @types/node, @types/react, @types/react-dom, ai, next, react, and react-dom to the greatest minor version within the 7-day cooldown window. Verified with npm install, npm run typecheck, and npm run build (with ARCJET_KEY/AI_GATEWAY_API_KEY set locally; the example throws at module load without them, unrelated to this change). Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/guard, @arcjet/next, and @arcjet/sensitive-info-rampart to the 1.10.0 stable release, and bump @types/node, @types/react, @types/react-dom, next, react, and react-dom to the greatest minor version within the 7-day cooldown window. Verified with npm install, npm run typecheck, and npm run build (with ARCJET_KEY set locally). Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fontsource-variable/figtree, @fontsource/ibm-plex-mono, @types/react, @types/react-dom, next, react, and react-dom to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run build. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/guard and @arcjet/sensitive-info-rampart to the 1.10.0 stable release, and bump @ai-sdk/provider-utils, @types/node, and ai to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run typecheck. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fontsource-variable/figtree, vue, and vue-tsc to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run build (with ARCJET_KEY set locally; the @arcjet/nuxt module throws during nuxt prepare/postinstall without it, unrelated to this change). Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fontsource-variable/figtree, @types/react, @types/react-dom, isbot, react, and react-dom to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run build. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @arcjet/react-router, @react-router/dev, @react-router/node, @react-router/serve, @types/node, @types/react, @types/react-dom, isbot, react, react-dom, and react-router to the greatest minor version within the 7-day cooldown window. npm install hit an ERESOLVE peer conflict from @react-router/dev@7.18.2 requiring react-router@^7.18.2 before the sibling react-router upgrade landed. Followed AGENTS.md's documented procedure: npm install --legacy-peer-deps followed by a plain npm install, which resolved cleanly with no leftover peer overrides. Verified with npm install and npm run build. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fontsource-variable/figtree, @fontsource/ibm-plex-mono, prettier, svelte, and svelte-check to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run build. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Update @fontsource-variable/figtree, @fontsource/ibm-plex-mono, @tanstack/react-router, @tanstack/react-start, @types/react, @types/react-dom, react, and react-dom to the greatest minor version within the 7-day cooldown window. Verified with npm install and npm run build (vite build && tsc --noEmit). Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
GHSA-w5hq-g745-h8pq: uuid <11.1.1 has a missing buffer bounds check in v3/v5/v6 when a buf argument is provided. It reaches this example transitively through newman's postman-collection, postman-request, postman-runtime, and serialised-error dependencies (moderate severity per npm audit). Not directly exploitable here: every call site in those packages uses uuid.v4() with no buf argument, so the affected code path is never reached. Still overrode the transitive uuid to 11.1.1 (patched, CommonJS-compatible) scoped to those four packages, following the same pattern used for firebase-functions' uuid fix, rather than npm audit fix --force which would downgrade newman to 3.9.3. Verified with npm install, npm audit (0 vulnerabilities, was 7 moderate), npm ls uuid (all copies now 11.1.1), and npm run build (tsc --noEmit). Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Record the root-params type reference generated by next build with Next.js 16.3.1 for nextjs-ai-agent, nextjs-bot-categories, nextjs-guard-policy, and nextjs-sensitive-info. Follow-up to the periodic dependency updates in these examples; next-env.d.ts is a generated file and should not be hand-edited. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Regenerate routeTree.gen.ts (alphabetical route re-sort, no route changes) produced by vite build with the updated @tanstack/react-router. Follow-up to the periodic dependency update; routeTree.gen.ts is a generated file and should not be hand-edited. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Arcjet Review — 🟡 Medium Risk
Decision: Needs Review
Rationale: This PR updates dependencies across many example applications and refreshes generated framework files. The changes are mostly version bumps, including a security-motivated override for transitive uuid usage in the express-newman example, and no hardcoded secrets or direct application security regressions are visible in the diff. However, dependency changes are an escalation trigger, the scope spans many frameworks, and some updates touch security-sensitive/example protection packages such as Arcjet guard, sensitive-info-rampart, Next.js, React Router, Firebase Functions, and pre-1.0 packages where minor version bumps can carry breaking changes. I am not confident enough to approve without human verification that installs, lockfile state, and example type/build/test suites pass.
Summary of Changes
Updates package dependencies across multiple examples, adds npm overrides to force uuid 11.1.1 under Newman/Postman transitive packages, refreshes Next.js generated type references, and regenerates the TanStack Start route tree with reordered route declarations.
Escalation Triggers
- Dependency Changes: Multiple package.json files under examples were changed, including runtime framework, security/protection, AI, and testing dependencies.
Review Focus Areas
- Verify that the nested npm overrides for postman-collection, postman-request, postman-runtime, and serialised-error correctly force uuid 11.1.1 in the actual resolved dependency tree.
The PR references a security update for GHSA-w5hq-g745-h8pq; the mitigation should be confirmed with the package manager's installed/resolved output, not just package.json syntax. - Review the eve 0.31.0 to 0.38.3 changelog and run the example's typecheck/build.
For pre-1.0 packages, minor version bumps may include breaking API or behavioral changes. - Run the Next.js example test/typecheck/build paths after the Next, React, AI SDK, React Hook Form, and Playwright updates.
Several runtime and test dependencies move together, which can introduce compatibility issues even when each individual bump is minor or patch-level. - Validate the React Router middleware example after updating @arcjet/react-router and React Router packages from 7.16.x to 7.18.x.
Middleware behavior and server adapters can change across framework minor releases and may affect route protection behavior. - Confirm the regenerated route tree was produced by the expected TanStack generator and that no routes were added, removed, or given incorrect paths.
The generated file appears mostly reordered, but route tree generation controls application routing and should match the source route files. - Confirm that the added .next/types/root-params.d.ts import is expected for the updated Next.js version and that clean installs/builds generate this file.
Referencing generated files that are absent in clean environments can break typechecking.
Notes
No direct code paths for authentication, input handling, cryptography, or secret management were changed in the visible diff. The primary residual risk is dependency resolution and runtime compatibility across the affected examples.
Path filtering: 24 files excluded by ignore paths. 29 of 53 files included in review.
Review: 8f105b81 | Model: openai/gpt-5.5 | Powered by Arcjet Review
|
Caution Review the following alerts detected in dependencies. According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. It is recommended to resolve "Warn" alerts too. Learn more about Socket for GitHub.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Periodic dependency and security update for the examples