fix(deps): update all application-kit packages to v27 - #1041
Open
renovate[bot] wants to merge 1 commit into
Open
fix(deps): update all application-kit packages to v27#1041renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
24.13.0→27.9.024.13.0→27.9.024.13.0→27.9.024.13.0→27.9.024.13.0→27.9.0Release Notes
commercetools/merchant-center-application-kit (@commercetools-frontend/application-config)
v27.9.0Compare Source
Patch Changes
1c22248]:v27.8.0Compare Source
Patch Changes
v27.7.0Compare Source
Patch Changes
v27.6.3Compare Source
Patch Changes
v27.6.2Compare Source
Patch Changes
v27.6.1Compare Source
Patch Changes
v27.6.0Compare Source
Patch Changes
v27.5.4Compare Source
Patch Changes
#4009
fae9486Thanks @ByronDWall! - Scope therolluppnpm override torollup@^4so it only affects Rollup 4.x consumers.The unscoped
"rollup": "^4.59.0"override introduced in 27.5.3 forced@preconstruct/cli'srollup@^2dependency to resolve to Rollup 4.x. Rollup 4 no longer emitsObject.defineProperty(exports, '__esModule', { value: true })in CJS output by default, which brokejest.spyOnon namespace imports (import * as X from 'module') in downstream consumers.Updated dependencies [
fae9486]:v27.5.3Compare Source
Patch Changes
#3989
222259aThanks @misama-ct! - Bump transitive dependencies via pnpm overrides to address 46 high-severity Dependabot alerts. Updated dependencies:@isaacs/brace-expansion>= 5.0.1@remix-run/router>= 1.23.2@xmldom/xmldom>= 0.8.13axios>= 1.15.2immutable>= 3.8.3lodash-es>= 4.17.21minimatch@^3^3.1.4minimatch@^4^4.2.5minimatch@^9^9.0.7minimatch@^10^10.2.3path-to-regexp@^6^6.3.0picomatch@^4^4.0.4rollup^4.59.0semver@^6^6.3.1svgo>= 2.8.1systeminformation>= 5.31.0tar>= 7.5.11tar-fs>= 3.1.1undici>= 6.24.0Updated dependencies [
222259a]:v27.5.2Compare Source
Patch Changes
#3993
241d4b2Thanks @abreu-ct! - Allow module resolution from outside of workspace.Updated dependencies []:
v27.5.1Compare Source
Patch Changes
v27.5.0Compare Source
Patch Changes
v27.4.2Patch Changes
v27.4.1Patch Changes
v27.4.0Compare Source
Patch Changes
v27.3.0Compare Source
Patch Changes
v27.2.0Compare Source
Patch Changes
f9e80c7]:v27.1.0Compare Source
Patch Changes
v27.0.0Compare Source
Patch Changes
v26.1.0Compare Source
Patch Changes
v26.0.2Compare Source
Patch Changes
v26.0.1Compare Source
Patch Changes
#3941
65cc17aThanks @ByronDWall! - fix(security): updateajvto 8.18.0 (ReDoS fix) and@flopflip/*to 15.1.7 (resolves transitivelodashprototype pollution via 4.17.23).The remaining reported vulnerabilities (
minimatchviaserve-handlerandinflightviareact-dev-utils) have no upstream fix available. Both are transitive dependencies ofmc-scriptsdev-only build tooling and pose negligible security risk as they are not included in production bundles.Updated dependencies []:
v26.0.0Compare Source
Patch Changes
v25.2.0Compare Source
Patch Changes
#3923
3b47e62Thanks @tylermorrisford! - Adds overrides for two transient dependencies.#3922
4d19484Thanks @tylermorrisford! - Adds override for transient dependency security issue.#3918
08c578cThanks @tylermorrisford! - Security fixes applied to application-config and react-notifications.#3924
a19546cThanks @tylermorrisford! - Adds override for tar package version.#3917
d817733Thanks @tylermorrisford! - Security fixes applied to application-config.Updated dependencies [
3b47e62,4d19484,a19546c]:v25.1.0Compare Source
Patch Changes
086d7e3]:v25.0.0Compare Source
Patch Changes
95dba14]:commercetools/merchant-center-application-kit (@commercetools-frontend/babel-preset-mc-app)
v27.9.0Compare Source
v27.8.0Compare Source
v27.7.0Compare Source
v27.6.3Compare Source
v27.6.2Compare Source
v27.6.1Compare Source
v27.6.0Compare Source
v27.5.4Compare Source
v27.5.3Compare Source
Patch Changes
#3989
222259aThanks @misama-ct! - Bump transitive dependencies via pnpm overrides to address 46 high-severity Dependabot alerts. Updated dependencies:@isaacs/brace-expansion>= 5.0.1@remix-run/router>= 1.23.2@xmldom/xmldom>= 0.8.13axios>= 1.15.2immutable>= 3.8.3lodash-es>= 4.17.21minimatch@^3^3.1.4minimatch@^4^4.2.5minimatch@^9^9.0.7minimatch@^10^10.2.3path-to-regexp@^6^6.3.0picomatch@^4^4.0.4rollup^4.59.0semver@^6^6.3.1svgo>= 2.8.1systeminformation>= 5.31.0tar>= 7.5.11tar-fs>= 3.1.1undici>= 6.24.0v27.5.2Compare Source
v27.5.1Compare Source
v27.5.0Compare Source
v27.4.2v27.4.1v27.4.0Compare Source
v27.3.0Compare Source
v27.2.0Compare Source
v27.1.0Compare Source
v27.0.0Compare Source
v26.1.0Compare Source
v26.0.2Compare Source
v26.0.1Compare Source
v26.0.0Compare Source
Major Changes
#3934
6c91a27Thanks @ByronDWall! - fix(security): movebabel-plugin-istanbulto optional peer dependency to resolve SNYK-JS-INFLIGHT-6095116The
babel-plugin-istanbulpackage transitively depends on the deprecated and vulnerableinflight@1.0.6viatest-exclude → glob@7 → inflight. By moving it from a direct dependency to an optional peer dependency, consumers of@commercetools-frontend/babel-preset-mc-appwill no longer inherit this vulnerability in their dependency tree.Breaking change: Projects that use
ENABLE_BABEL_PLUGIN_ISTANBUL=truefor code coverage instrumentation must now explicitly installbabel-plugin-istanbulas a dev dependency:A runtime check has been added that provides a clear error message if coverage is enabled but the plugin is not installed. Projects that do not use Istanbul coverage instrumentation are not affected.
v25.2.0Compare Source
Patch Changes
#3923
3b47e62Thanks @tylermorrisford! - Adds overrides for two transient dependencies.#3927
246ba28Thanks @misama-ct! - Fix SNYK-JS-INFLIGHT-6095116 vulnerability by removing dependencies on the deprecatedinflightpackage.#3922
4d19484Thanks @tylermorrisford! - Adds override for transient dependency security issue.#3924
a19546cThanks @tylermorrisford! - Adds override for tar package version.v25.1.0Compare Source
v25.0.0Compare Source
commercetools/merchant-center-application-kit (@commercetools-frontend/constants)
v27.9.0Compare Source
Minor Changes
1c22248Thanks @ByronDWall! - Add a portal target (mc-main-container-portal) insideMainContainerso that fixed-position components likeSaveToolbarcan portal into the MC content area and automatically constrain their width to the main pane, excluding the agent side panel.v27.8.0Compare Source
v27.7.0Compare Source
v27.6.3Compare Source
v27.6.2Compare Source
v27.6.1Compare Source
v27.6.0Compare Source
v27.5.4Compare Source
Patch Changes
#4009
fae9486Thanks @ByronDWall! - Scope therolluppnpm override torollup@^4so it only affects Rollup 4.x consumers.The unscoped
"rollup": "^4.59.0"override introduced in 27.5.3 forced@preconstruct/cli'srollup@^2dependency to resolve to Rollup 4.x. Rollup 4 no longer emitsObject.defineProperty(exports, '__esModule', { value: true })in CJS output by default, which brokejest.spyOnon namespace imports (import * as X from 'module') in downstream consumers.v27.5.3Compare Source
Patch Changes
#3989
222259aThanks @misama-ct! - Bump transitive dependencies via pnpm overrides to address 46 high-severity Dependabot alerts. Updated dependencies:@isaacs/brace-expansion>= 5.0.1@remix-run/router>= 1.23.2@xmldom/xmldom>= 0.8.13axios>= 1.15.2immutable>= 3.8.3lodash-es>= 4.17.21minimatch@^3^3.1.4minimatch@^4^4.2.5minimatch@^9^9.0.7minimatch@^10^10.2.3path-to-regexp@^6^6.3.0picomatch@^4^4.0.4rollup^4.59.0semver@^6^6.3.1svgo>= 2.8.1systeminformation>= 5.31.0tar>= 7.5.11tar-fs>= 3.1.1undici>= 6.24.0v27.5.2Compare Source
v27.5.1Compare Source
v27.5.0Compare Source
v27.4.2v27.4.1v27.4.0Compare Source
v27.3.0Compare Source
v27.2.0Compare Source
Minor Changes
f9e80c7Thanks @yassinejebli! - Add agentic channels service toGRAPHQL_TARGETSv27.1.0Compare Source
v27.0.0Compare Source
v26.1.0Compare Source
v26.0.2Compare Source
v26.0.1Compare Source
v26.0.0Compare Source
v25.2.0Compare Source
Patch Changes
#3923
3b47e62Thanks @tylermorrisford! - Adds overrides for two transient dependencies.#3922
4d19484Thanks @tylermorrisford! - Adds override for transient dependency security issue.#3924
a19546cThanks @tylermorrisford! - Adds override for tar package version.v25.1.0Compare Source
Minor Changes
086d7e3Thanks @LucasGrahn! - Added stores search constant valuesv25.0.0Compare Source
Major Changes
#3910
95dba14Thanks @Sarah4VT! - Jest 30 upgrade - Upgrade guideglobalsconfiguration (NODE_ENV set automatically)crypto.randomUUIDpolyfill (JSDOM 26 native support)uuiddependencycommercetools/merchant-center-application-kit (@commercetools-frontend/eslint-config-mc-app)
v27.9.0Compare Source
Patch Changes
v27.8.0Compare Source
Patch Changes
v27.7.0Compare Source
Patch Changes
v27.6.3Compare Source
Patch Changes
v27.6.2Compare Source
Patch Changes
v27.6.1Compare Source
Patch Changes
v27.6.0Compare Source
Patch Changes
v27.5.4Compare Source
Patch Changes
#4006
1b2d65cThanks @ByronDWall! - Addeslint-import-resolver-typescriptto the base ESLint config block so JS/JSX files can resolve non-hoisted pnpm packages and packages using only theexportsfield.Updated dependencies []:
v27.5.3Compare Source
Patch Changes
#3989
222259aThanks @misama-ct! - Bump transitive dependencies via pnpm overrides to address 46 high-severity Dependabot alerts. Updated dependencies:@isaacs/brace-expansion>= 5.0.1@remix-run/router>= 1.23.2@xmldom/xmldom>= 0.8.13axios>= 1.15.2immutable>= 3.8.3lodash-es>= 4.17.21minimatch@^3^3.1.4minimatch@^4^4.2.5minimatch@^9^9.0.7minimatch@^10^10.2.3path-to-regexp@^6^6.3.0picomatch@^4^4.0.4rollup^4.59.0semver@^6^6.3.1svgo>= 2.8.1systeminformation>= 5.31.0tar>= 7.5.11tar-fs>= 3.1.1undici>= 6.24.0Updated dependencies [
222259a]:v27.5.2Compare Source
Patch Changes
v27.5.1Compare Source
Patch Changes
v27.5.0Compare Source
Patch Changes
v27.4.2Patch Changes
v27.4.1Patch Changes
v27.4.0Compare Source
Minor Changes
54907ffThanks @valoriecarli! - -Removejest-runner-eslintfrom starter templates to fixnpm installfailures caused by its staleeslint@^7 || ^8peer dependency declaration, which hard-fails under npm's strict resolution when ESLint 9 is present.-The
lintscript now callseslint .directly.-Migration guides updated with recommended steps and a workaround for projects that prefer to keep
jest-runner-eslint.Patch Changes
v27.3.0Compare Source
Minor Changes
#3961
8efed36Thanks @nima-ct! - Add bundledno-direct-currency-formattingrule via the@commercetools-frontend/eslint-config-mc-app/rulesinline plugin.This rule disallows direct currency formatting through
intl.formatNumber,intl.formatCurrency,new Intl.NumberFormatwhen using acurrencyoption orstyle: 'currency', and<FormattedNumber />fromreact-intl.Use a shared currency formatting wrapper instead, and allowlist that wrapper path if needed.
v27.2.0Compare Source
Patch Changes
v27.1.0Compare Source
Patch Changes
[
v27.0.0](https://redirect.github.com/commercetools/merchant-center-applConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.