Repository navigation
chore(deps): bump dotenv from 17.4.2 to 18.0.5 - #1374
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [dotenv](https://github.com/motdotla/dotenv) from 17.4.2 to 18.0.5. - [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md) - [Commits](motdotla/dotenv@v17.4.2...v18.0.5) --- updated-dependencies: - dependency-name: dotenv dependency-version: 18.0.4 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/dotenv-18.0.4
branch
from
October 7, 2026 21:13
cb2cc54 to
a805c0d
Compare
1 of 10 tasks
pdp2121
added a commit
that referenced
this pull request
Oct 8, 2026
## High Level Overview of Change
Quarterly batch dependency upgrade (2026-Q4). This PR consolidates the
open Dependabot dependency PRs **and** applies any further upgrades
needed to resolve the open Semgrep (DGE) supply-chain tickets that a
package upgrade can fix.
- **21** Dependabot PRs applied (Upgraded); **9** skipped
(peer-dependency or Node-engine conflicts — see the table).
- **0** Semgrep tickets needed an upgrade: the 4 new **Critical** axios
tickets (DGE-8416–8419, `axios ≥ 1.20.0`) are already satisfied on
`main` by the Q3 batch (No-op), and none are left open.
- Twelve of the applied PRs are major bumps, eight of them production
dependencies: `express` 5, `dotenv` 18,
`i18next-browser-languagedetector` 8, `i18next-http-backend` 4,
`react-helmet-async` 3, `react-error-boundary` 6, `vite-plugin-svgr` 5,
`tldts` 7.
> **Express 4 → 5 needed a server fix that CI does not catch — please
review it specifically.** Under Express 5 the production server crashed
on startup (`PathError: Missing parameter name at index 1: *`), because
`path-to-regexp` 8 no longer accepts a bare `*` route. No Jest test
loads `server/`, so `lint:ci`, `build`, `build-ts` and `test:ci` all
passed regardless. Two lines in `server/index.js` were changed to the
Express 5 syntax, and the server was started and probed in both
production and development modes (see Test Plan).
### Context of Change
Quarterly batch of the Dependabot PRs opened on 2026-10-01, plus the
Semgrep tickets a package upgrade can fix. Direct dependency versions
were bumped in `package.json`; `package-lock.json` was updated in place
(never regenerated from scratch). No `overrides` or `resolutions` were
added and no parent range was widened.
### Type of Change
- [ ] Bug fix (non-breaking change which fixes an issue)
- [ ] New feature (non-breaking change which adds functionality)
- [x] Breaking change (fix or feature that would cause existing
functionality to not work as expected)
- [ ] Refactor (non-breaking change that only restructures code)
- [ ] Tests (You added tests for code that already exists, or your new
feature included in this PR)
- [ ] Documentation Updates
- [ ] Translation Updates
- [ ] Release
"Breaking change" is checked because production dependencies cross major
versions (most notably `express` 5). User-facing behavior is unchanged.
### Codebase Modernization
N/A — no file conversions.
- [ ] Updated files to React Hooks
- [ ] Updated files to TypeScript
## Before / After
**`server/index.js`** — Express 5 route syntax (details in
`code-changes.md`):
```js
// before (Express 4)
app.get('*', (_req, res) => { res.sendFile(path.join(__dirname, '/../build/index.html')) })
app.use('*', (req, res) => { /* 404 */ })
// after (Express 5)
app.get('/{*splat}', (_req, res) => { res.sendFile(path.join(__dirname, '/../build/index.html')) })
app.use((req, res) => { /* 404 */ })
```
`/{*splat}` keeps matching `/` itself, as `*` did; `app.use` with no
path already matches every request.
**Prettier 3.9 reformat** — six files re-wrapped by `npm run lint`
(`--fix`), cosmetic only: `BasicInfoCard.test.tsx`, `AMMPool/utils.ts`,
`ConfBalanceTooltipIcon.tsx`, `Notification/index.tsx`,
`TransactionActionIcon.tsx`, `registerServiceWorker.js`.
**Lockfile** — 86 packages changed version, 44 added, 46 removed; most
of the churn is Express 5's own dependency tree (`router`,
`path-to-regexp` 8, `serve-static` 2, …).
All Semgrep tickets closed in Q3 were re-verified against this lockfile
and remain satisfied (e.g. `path-to-regexp` is now 8.4.2 and
`serve-static` 2.2.1, both outside their advisories' affected ranges).
## Test Plan
Run locally on Node 22.14:
- `npm run lint:ci` — passes
- `npm run build` — passes
- `npm run build-ts` — passes
- `npm run test:ci` — 292/293 suites, 1688/1726 tests pass; coverage
thresholds met. The only failure,
`src/containers/shared/test/amendmentUtils.test.ts` (38 tests), calls
the live VHS dev API (`vhs.dev.ripplex.io/v1/network/amendments/info`),
which was returning **HTTP 503** during the run; it fails identically on
an untouched `main` checkout. It is unrelated to this batch and should
pass once the endpoint recovers (or be mocked in a follow-up).
- **Express 5 server smoke test** (not covered by CI), with `node
server`:
- `NODE_ENV=production`: `/` → 200 `index.html`; `/transactions/ABC123`
→ 200 `index.html` (SPA fallback); `/api/v1/healthz` → 200 `success`.
- `NODE_ENV=development`: `/` → 200 (static); `/transactions/ABC123` →
404 `{"error":"route not found"}`; `/api/v1/does-not-exist` → 404.
## Superseded Dependabot PRs
| PR | Package | From | Asked for | Resolved | Status |
MajorVersionUpgrade |
|----|---------|------|-----------|----------|--------|---------------------|
| #1375 | ts-jest | 29.4.9 | 29.4.14 | 29.4.14 | Upgraded | No |
| #1374 | dotenv | 17.4.2 | 18.0.5 | 18.0.6 | Upgraded | Yes
([v18](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)) |
| #1373 | @testing-library/react | 13.4.0 | 16.3.3 | 16.3.3 | Upgraded |
Yes
([v14](https://github.com/testing-library/react-testing-library/releases/tag/v14.0.0),
[v15](https://github.com/testing-library/react-testing-library/releases/tag/v15.0.0),
[v16](https://github.com/testing-library/react-testing-library/releases/tag/v16.0.0))
|
| #1372 | compression | 1.8.1 | 1.8.2 | 1.8.2 | Upgraded | No |
| #1371 | stylelint-scss | 7.0.0 | 7.3.0 | 7.3.0 | Upgraded | No |
| #1370 | @babel/preset-react | 7.28.5 | 8.0.1 | 7.28.5 | Skipped (peer
dep conflict: requires `@babel/core ^8`; installed 7.29.7) | Yes
([v8](https://github.com/babel/babel/releases/tag/v8.0.0)) |
| #1369 | express | 4.22.3 | 5.2.1 | 5.2.1 | Upgraded (with
`server/index.js` route fix) | Yes
([v5](https://github.com/expressjs/express/releases/tag/v5.0.0),
[migration guide](https://expressjs.com/en/guide/migrating-5.html)) |
| #1368 | lint-staged | 15.5.2 | 17.6.0 | 15.5.2 | Skipped (engine
conflict: requires Node ≥ 22.22.1; repo allows `>=22.0.0` with
`engine-strict=true`) | Yes
([v16](https://github.com/lint-staged/lint-staged/releases/tag/v16.0.0),
[v17](https://github.com/lint-staged/lint-staged/releases/tag/v17.0.0))
|
| #1367 | @types/node | 22.19.17 | 26.6.4 | 22.19.17 | Skipped (runtime
is Node 22; Node 26 types would allow APIs missing at runtime) | Yes
([types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/node))
|
| #1366 | jest-environment-jsdom | 30.3.0 | 30.5.2 | 30.5.2 | Upgraded |
No |
| #1365 | i18next-browser-languagedetector | 7.2.2 | 8.2.1 | 8.2.1 |
Upgraded | Yes
([v8](https://github.com/i18next/i18next-browser-languageDetector/blob/master/CHANGELOG.md))
|
| #1364 | eslint-plugin-prettier | 5.5.5 | 5.5.6 | 5.5.6 | Upgraded | No
|
| #1363 | i18next-http-backend | 3.0.6 | 4.0.2 | 4.0.2 | Upgraded | Yes
([v4](https://github.com/i18next/i18next-http-backend/blob/master/CHANGELOG.md))
|
| #1362 | @typescript-eslint/parser | 8.58.2 | 8.71.0 | 8.71.1 |
Upgraded | No |
| #1361 | react / @types/react | 18.3.1 / 18.3.28 | 19.3.0 / 19.3.0 |
18.3.1 / 18.3.28 | Skipped (peer dep conflict: `react-query@3.39.3`, the
last v3, requires `react ≤ 18`) | Yes
([v19](https://github.com/facebook/react/releases/tag/v19.0.0),
[types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/master/types/react))
|
| #1360 | react-helmet-async | 2.0.5 | 3.0.0 | 3.0.0 | Upgraded | Yes
([v3](https://github.com/staylor/react-helmet-async/releases/tag/v3.0.0))
|
| #1359 | react-error-boundary | 4.1.2 | 6.1.6 | 6.1.6 | Upgraded | Yes
([v5](https://github.com/bvaughn/react-error-boundary/releases/tag/5.0.0),
[v6](https://github.com/bvaughn/react-error-boundary/releases/tag/6.0.0))
|
| #1358 | react-error-overlay | 6.0.11 | 6.1.0 | 6.1.0 | Upgraded | No |
| #1357 | vite-plugin-environment | 1.1.3 | 1.1.4 | 1.1.3 | Skipped
(peer dep conflict: requires `vite >= 8`; installed 7.3.6) | No |
| #1356 | prettier | 3.6.2 | 3.9.9 | 3.9.9 | Upgraded | No |
| #1355 | xrpl | 4.6.0 | 5.3.0 | 5.3.0 | Upgraded | Yes
([v5](https://github.com/XRPLF/xrpl.js/releases/tag/xrpl%405.0.0)) |
| #1354 | react-router | 7.18.4 | 8.4.0 | 7.18.4 | Skipped (peer dep
conflict: requires `react ≥ 19.2.7`, blocked by #1361; also Node ≥
22.22) | Yes
([v8](https://github.com/remix-run/react-router/releases/tag/react-router%408.0.0))
|
| #1353 | vite-plugin-svgr | 4.5.0 | 5.2.0 | 5.2.0 | Upgraded | Yes
([v5](https://github.com/pd4d10/vite-plugin-svgr/releases/tag/v5.0.0)) |
| #1352 | @typescript-eslint/eslint-plugin | 8.58.2 | 8.71.0 | 8.71.1 |
Upgraded | No |
| #1351 | react-i18next | 15.4.1 | 17.0.15 | 15.4.1 | Skipped (peer dep
conflict: requires `i18next ≥ 26.2.0`; installed 23.16.8) | Yes
([CHANGELOG](https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md))
|
| #1350 | babel-jest | 29.7.0 | 30.5.2 | 30.5.2 | Upgraded | Yes
([v30](https://jestjs.io/blog/2025/06/04/jest-30)) |
| #1349 | tldts | 6.1.86 | 7.4.16 | 7.4.16 | Upgraded | Yes
([v7](https://github.com/remusao/tldts/releases/tag/v7.0.0)) |
| #1348 | eslint-import-resolver-typescript | 4.4.4 | 4.4.5 | 4.4.5 |
Upgraded | No |
| #1347 | @babel/preset-env | 7.29.2 | 8.0.6 | 7.29.2 | Skipped (peer
dep conflict: requires `@babel/core ^8`; installed 7.29.7) | Yes
([v8](https://github.com/babel/babel/releases/tag/v8.0.0)) |
| #1346 | eslint-plugin-react-hooks | 4.6.2 | 7.1.1 | 4.6.2 | Skipped
(peer dep conflict: `eslint-config-airbnb@19.0.4`, the latest, requires
`^4.3.0`) | Yes
([CHANGELOG](https://github.com/facebook/react/blob/main/packages/eslint-plugin-react-hooks/CHANGELOG.md))
|
## Semgrep tickets
Out of scope (not package-upgrade-fixable; not addressed here):
DGE-4837, DGE-4839, DGE-4840, DGE-7803, DGE-7812 (code findings);
DGE-7802, DGE-7804 (config findings); DGE-4831, DGE-4834, DGE-4843,
DGE-7794 (`ripple/explorer-deploy`).
| Ticket | Package | From | Asked for | Resolved | Status |
MajorVersionUpgrade |
|--------|---------|------|-----------|----------|--------|---------------------|
| [DGE-8416](https://ripplelabs.atlassian.net/browse/DGE-8416) | axios |
1.20.0 | ≥ 1.20.0 | 1.20.0 | No-op (already satisfied on main since the
Q3 batch) | No |
| [DGE-8417](https://ripplelabs.atlassian.net/browse/DGE-8417) | axios |
1.20.0 | ≥ 1.20.0 | 1.20.0 | No-op (already satisfied on main since the
Q3 batch) | No |
| [DGE-8418](https://ripplelabs.atlassian.net/browse/DGE-8418) | axios |
1.20.0 | ≥ 1.20.0 | 1.20.0 | No-op (already satisfied on main since the
Q3 batch) | No |
| [DGE-8419](https://ripplelabs.atlassian.net/browse/DGE-8419) | axios |
1.20.0 | ≥ 1.20.0 | 1.20.0 | No-op (already satisfied on main since the
Q3 batch) | No |
No ticket required an upgrade that a Dependabot PR did not already
propose.
## Closing instructions
After merging, run `/batch-deps-upgrade close` to close the superseded
PRs and the resolved Semgrep tickets. It will close these **Upgraded**
Dependabot PRs — #1375, #1374, #1373, #1372, #1371, #1369, #1366, #1365,
#1364, #1363, #1362, #1360, #1359, #1358, #1356, #1355, #1353, #1352,
#1350, #1349, #1348 — and these **No-op** tickets: DGE-8416, DGE-8417,
DGE-8418, DGE-8419.
The following PRs were **Skipped** and should remain open so Dependabot
keeps rebasing them: #1370 (@babel/preset-react), #1368 (lint-staged),
#1367 (@types/node), #1361 (react / @types/react), #1357
(vite-plugin-environment), #1354 (react-router), #1351 (react-i18next),
#1347 (@babel/preset-env), #1346 (eslint-plugin-react-hooks). No Semgrep
tickets stay open.
Collaborator
|
Superseded by the 2026-Q4 batch dependency upgrade: #1377 |
Contributor
Author
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps dotenv from 17.4.2 to 18.0.5.
Changelog
Sourced from dotenv's changelog.
... (truncated)
Commits
05215e018.0.525bdd0achangelog2d640d2Merge pull request #1066 from AyanAta42/masterc84e2b4Merge pull request #1068 from matzehecht/fix-typescript570146aOptimize fast parser comment scanning4aa0665add typescript module declaration for dotenv/configf1380ecBound fast parser comment scans to the current linea626f72add linkb36a142video links86804c018.0.4