deps(ts): bump @vitejs/plugin-react from 6.0.1 to 6.0.2 in /frontend#78
deps(ts): bump @vitejs/plugin-react from 6.0.1 to 6.0.2 in /frontend#78dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) from 6.0.1 to 6.0.2. - [Release notes](https://github.com/vitejs/vite-plugin-react/releases) - [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.0.2/packages/plugin-react) --- updated-dependencies: - dependency-name: "@vitejs/plugin-react" dependency-version: 6.0.2 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
…ixes (#81) * chore(deps): consolidate Dependabot PRs #70–#80 + frontend security fixes Consolidates 11 open Dependabot PRs into one branch as latest-compatible within each existing major, regenerates both lockfiles once, and patches 5 frontend security advisories surfaced by `pnpm audit`. Rust (cargo): openssl 0.10.79→0.10.80, reqwest 0.13.3→0.13.4, http 1.4.0→1.4.1, uuid 1.23.1→1.23.2, sysinfo 0.39.2→0.39.3 (#70,#72,#75,#77,#79) Docker: rust 1.95→1.96-bookworm (#71) TS (frontend): react-router(-dom) 7.15.1→7.17.0, typescript-eslint 8.59.3→8.61.1, @vitejs/plugin-react 6.0.1→6.0.2, eslint 10.2.1→10.5.0 (#73,#74,#76,#78,#80) Security (pnpm audit): vite→8.0.16 (GHSA-fx2h-pf6j-xcff HIGH, GHSA-v6wh-96g9-6wx3), js-yaml→4.2.0 (GHSA-h67p-54hq-rp68), brace-expansion→5.0.6 (GHSA-jxxr-4gwj-5jf2), @babel/core≥7.29.6 (GHSA-4x5r-pxfx-6jf8) via pnpm.overrides. Docs: bumped Rust toolchain references (1.95→1.96) in maintainer guide and deployment doc to track the Dockerfile bump. * chore(frontend): migrate to pnpm 11 Bumps the pinned package manager to pnpm 11.7.0 and updates every reference following the existing toolchain-bump pattern (manifest, Docker, CI, docs). - packageManager: pnpm@10.11.0 → pnpm@11.7.0 (CI's `corepack enable pnpm` reads this field, so the version propagates to all CI jobs automatically) - frontend/Dockerfile.frontend: corepack prepare pnpm@11.7.0; COPY the new pnpm-workspace.yaml into the dev stage so the frozen install sees overrides - Move `pnpm.overrides` out of package.json (pnpm 11 no longer reads that field) into frontend/pnpm-workspace.yaml, its new home - Disable pnpm 11's default 24h minimumReleaseAge supply-chain delay (minimumReleaseAge: 0) to preserve pnpm 10 install behavior and keep CI deterministic on same-day Dependabot bumps - README.md / maintainer-guide.md: pnpm 10+ → pnpm 11+ prerequisite Lockfile unchanged — relocating overrides does not alter resolution. Full frontend gate (frozen install, lint, tsc, prettier, test, build, audit) green under pnpm 11.7.0.
Bumps @vitejs/plugin-react from 6.0.1 to 6.0.2.
Release notes
Sourced from @vitejs/plugin-react's releases.
Changelog
Sourced from @vitejs/plugin-react's changelog.
Commits
6535b55release: plugin-react@6.0.2bf0e43bfeat(react): whitelist debugging-options (#1189)3bd1f08feat: use carets for rolldown versions (#1216)2b8df67fix(deps): update all non-major dependencies (#1218)8fa9619fix(deps): update react 19.2.6 (#1211)a4296adfix(deps): update all non-major dependencies (#1209)323ccd7fix(deps): update all non-major dependencies (#1196)a7506e1chore(deps): update vite 8.0.10 (#1198)02cff2afix(deps): update all non-major dependencies (#1184)4b9c890fix(deps): update react 19.2.5 (#1181)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)