Skip to content

chore(deps): weekly dependency update - #309

Merged
robertying merged 2 commits into
mainfrom
claude/great-hamilton-r69eyr
Aug 29, 2026
Merged

robertying merged 2 commits into
mainfrom
claude/great-hamilton-r69eyr

Conversation

@robertying

@robertying robertying commented Aug 29, 2026 •

Copy link
Copy Markdown
Owner

Summary

Weekly automated dependency update via pnpm update --latest.

  • packageManager: pnpm 11.21.0 -> 11.24.0 (via corepack use pnpm@latest && corepack install)
  • next / eslint-config-next: 16.3.0 -> 16.3.3 (patch)
  • @types/node: 26.2.0 -> 26.4.0 (minor)
  • @types/react-dom: 19.2.4 -> 19.2.5 (patch)
  • dayjs: 1.11.21 -> 1.11.23 (patch)
  • highlight.js: 11.11.1 -> 11.12.0 (minor)
  • sharp: 0.35.3 -> 0.35.4 (patch)
  • eslint: attempted major bump 9.39.5 -> 10.9.1, then reverted — see Needs review below. Final state keeps eslint on 9.39.5 (the maintenance dist-tag), i.e. no net change to this dependency.
  • No other packages had a newer version available.
  • .github/workflows/CI.yml action pins were checked (actions/checkout@v7, actions/setup-node@v7, pnpm/action-setup@v6, actions/cache@v6) — all already track the latest published major tag, so no edits were made.
  • Dockerfile only uses the floating node:lts-alpine tag; no hardcoded versions to flag.
  • No codegen/schema-generation script exists in package.json, so step was skipped.
  • pnpm-workspace.yaml exists but only configures build/catalog policy (no packages: field, i.e. not a real multi-package workspace), so pnpm update --latest was run without -r.

Checks run locally

Script Result
pnpm lint ✅ pass (clean, no output)
pnpm build (next build --webpack) ✅ pass — compiled, typechecked, and generated all 15 static routes successfully
smoke test (pnpm start on port 3001, since 3000 was occupied by an unrelated sandbox process) ✅ pass — HTTP 200 on /, page <title> rendered correctly ("Blog by Rui Ying"), no stack traces or new warnings in server output

No test script exists in package.json.

What I fixed and why it was safe

pnpm update --latest initially bumped eslint 9.39.5 -> 10.9.1 (a major version). This broke pnpm lint immediately:

TypeError: Error while loading rule 'react/display-name': contextOrFilename.getFilename is not a function
    at .../eslint-plugin-react@7.37.5.../lib/util/version.js

This is a known incompatibility: eslint-plugin-react@7.37.5 (pulled in transitively via eslint-config-next) calls an ESLint rule-context API (context.getFilename()) that ESLint 10's flat-config linter no longer exposes, and eslint-plugin-react has not yet shipped a fix. This is not a mechanical rename or a type annotation fix — it's an upstream compatibility gap outside this repo's control, so per the judgment-call rule I did not attempt to patch around it (e.g. no config hacks, no suppressions). Instead I pinned eslint back to 9.39.5, which is ESLint's own published maintenance dist-tag (i.e. the explicitly-supported fallback for exactly this kind of situation), restoring a clean pnpm lint run with zero errors/warnings. This is a safe, reversible, and well-documented choice, not a guess at fixing the actual incompatibility.

Needs review

  • Major bump reverted: eslint 9.x -> 10.x. Blocked by eslint-plugin-react@7.37.5 (via eslint-config-next@16.3.3) throwing under ESLint 10's flat-config API (context.getFilename is not a function). Re-attempt this bump once eslint-config-next/eslint-plugin-react publish an ESLint-10-compatible release.
  • No other unresolved issues. GitHub Actions pins and Dockerfile required no changes (already latest majors / no hardcoded versions to flag).

claude and others added 2 commits August 29, 2026 02:03
Update pnpm to 11.24.0 and bump dependencies via `pnpm update --latest`:
next 16.3.0->16.3.3, eslint-config-next 16.3.0->16.3.3, @types/node
26.2.0->26.4.0, @types/react-dom 19.2.4->19.2.5, dayjs 1.11.21->1.11.23,
highlight.js 11.11.1->11.12.0, sharp 0.35.3->0.35.4.

eslint was pinned back to 9.39.5 (the maintenance release) after the
attempted major bump to eslint 10.9.1 broke `pnpm lint`: eslint-plugin-react
7.37.5 (pulled in transitively by eslint-config-next) throws
"contextOrFilename.getFilename is not a function" under ESLint 10's flat
config API and has not yet published a compatible release. No GitHub
Actions pins or Dockerfile needed changes (already on latest majors /
floating tags).
Add a pull_request trigger so PRs (including the ones the weekly
dependency-update routine opens) actually get CI-checked before merge.
Gate the deploy job to push events only so PRs never trigger a
container build/push.
@robertying
robertying merged commit 62b2ac7 into main Aug 29, 2026
2 checks passed
@robertying
robertying deleted the claude/great-hamilton-r69eyr branch August 29, 2026 02:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants