chore(deps): weekly dependency update - #309
Merged
Merged
Conversation
Update pnpm to 11.24.0 and bump dependencies via `pnpm update --latest`: next 16.3.0->16.3.3, eslint-config-next 16.3.0->16.3.3, @types/node 26.2.0->26.4.0, @types/react-dom 19.2.4->19.2.5, dayjs 1.11.21->1.11.23, highlight.js 11.11.1->11.12.0, sharp 0.35.3->0.35.4. eslint was pinned back to 9.39.5 (the maintenance release) after the attempted major bump to eslint 10.9.1 broke `pnpm lint`: eslint-plugin-react 7.37.5 (pulled in transitively by eslint-config-next) throws "contextOrFilename.getFilename is not a function" under ESLint 10's flat config API and has not yet published a compatible release. No GitHub Actions pins or Dockerfile needed changes (already on latest majors / floating tags).
Add a pull_request trigger so PRs (including the ones the weekly dependency-update routine opens) actually get CI-checked before merge. Gate the deploy job to push events only so PRs never trigger a container build/push.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Weekly automated dependency update via
pnpm update --latest.packageManager: pnpm 11.21.0 -> 11.24.0 (viacorepack use pnpm@latest && corepack install)next/eslint-config-next: 16.3.0 -> 16.3.3 (patch)@types/node: 26.2.0 -> 26.4.0 (minor)@types/react-dom: 19.2.4 -> 19.2.5 (patch)dayjs: 1.11.21 -> 1.11.23 (patch)highlight.js: 11.11.1 -> 11.12.0 (minor)sharp: 0.35.3 -> 0.35.4 (patch)eslint: attempted major bump 9.39.5 -> 10.9.1, then reverted — see Needs review below. Final state keeps eslint on9.39.5(themaintenancedist-tag), i.e. no net change to this dependency..github/workflows/CI.ymlaction pins were checked (actions/checkout@v7,actions/setup-node@v7,pnpm/action-setup@v6,actions/cache@v6) — all already track the latest published major tag, so no edits were made.Dockerfileonly uses the floatingnode:lts-alpinetag; no hardcoded versions to flag.package.json, so step was skipped.pnpm-workspace.yamlexists but only configures build/catalog policy (nopackages:field, i.e. not a real multi-package workspace), sopnpm update --latestwas run without-r.Checks run locally
pnpm lintpnpm build(next build --webpack)pnpm starton port 3001, since 3000 was occupied by an unrelated sandbox process)/, page<title>rendered correctly ("Blog by Rui Ying"), no stack traces or new warnings in server outputNo test script exists in
package.json.What I fixed and why it was safe
pnpm update --latestinitially bumpedeslint9.39.5 -> 10.9.1 (a major version). This brokepnpm lintimmediately:This is a known incompatibility:
eslint-plugin-react@7.37.5(pulled in transitively viaeslint-config-next) calls an ESLint rule-context API (context.getFilename()) that ESLint 10's flat-config linter no longer exposes, andeslint-plugin-reacthas not yet shipped a fix. This is not a mechanical rename or a type annotation fix — it's an upstream compatibility gap outside this repo's control, so per the judgment-call rule I did not attempt to patch around it (e.g. no config hacks, no suppressions). Instead I pinnedeslintback to9.39.5, which is ESLint's own publishedmaintenancedist-tag (i.e. the explicitly-supported fallback for exactly this kind of situation), restoring a cleanpnpm lintrun with zero errors/warnings. This is a safe, reversible, and well-documented choice, not a guess at fixing the actual incompatibility.Needs review
eslint9.x -> 10.x. Blocked byeslint-plugin-react@7.37.5(viaeslint-config-next@16.3.3) throwing under ESLint 10's flat-config API (context.getFilename is not a function). Re-attempt this bump onceeslint-config-next/eslint-plugin-reactpublish an ESLint-10-compatible release.