Skip to content

chore (deps): q4 package upgrades - #1377

Merged
pdp2121 merged 2 commits into
mainfrom
q4-package-updates
Oct 8, 2026
Merged

pdp2121 merged 2 commits into
mainfrom
q4-package-updates

Conversation

@pdp2121

@pdp2121 pdp2121 commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

High Level Overview of Change

Quarterly batch dependency upgrade (2026-Q4). This PR consolidates the open Dependabot dependency PRs and applies any further upgrades needed to resolve the open Semgrep (DGE) supply-chain tickets that a package upgrade can fix.

  • 21 Dependabot PRs applied (Upgraded); 9 skipped (peer-dependency or Node-engine conflicts — see the table).
  • 0 Semgrep tickets needed an upgrade: the 4 new Critical axios tickets (DGE-8416–8419, axios ≥ 1.20.0) are already satisfied on main by the Q3 batch (No-op), and none are left open.
  • Twelve of the applied PRs are major bumps, eight of them production dependencies: express 5, dotenv 18, i18next-browser-languagedetector 8, i18next-http-backend 4, react-helmet-async 3, react-error-boundary 6, vite-plugin-svgr 5, tldts 7.

Express 4 → 5 needed a server fix that CI does not catch — please review it specifically. Under Express 5 the production server crashed on startup (PathError: Missing parameter name at index 1: *), because path-to-regexp 8 no longer accepts a bare * route. No Jest test loads server/, so lint:ci, build, build-ts and test:ci all passed regardless. Two lines in server/index.js were changed to the Express 5 syntax, and the server was started and probed in both production and development modes (see Test Plan).

Context of Change

Quarterly batch of the Dependabot PRs opened on 2026-10-01, plus the Semgrep tickets a package upgrade can fix. Direct dependency versions were bumped in package.json; package-lock.json was updated in place (never regenerated from scratch). No overrides or resolutions were added and no parent range was widened.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Refactor (non-breaking change that only restructures code)
  • Tests (You added tests for code that already exists, or your new feature included in this PR)
  • Documentation Updates
  • Translation Updates
  • Release

"Breaking change" is checked because production dependencies cross major versions (most notably express 5). User-facing behavior is unchanged.

Codebase Modernization

N/A — no file conversions.

  • Updated files to React Hooks
  • Updated files to TypeScript

Before / After

server/index.js — Express 5 route syntax (details in code-changes.md):

// before (Express 4)
app.get('*', (_req, res) => { res.sendFile(path.join(__dirname, '/../build/index.html')) })
app.use('*', (req, res) => { /* 404 */ })

// after (Express 5)
app.get('/{*splat}', (_req, res) => { res.sendFile(path.join(__dirname, '/../build/index.html')) })
app.use((req, res) => { /* 404 */ })

/{*splat} keeps matching / itself, as * did; app.use with no path already matches every request.

Prettier 3.9 reformat — six files re-wrapped by npm run lint (--fix), cosmetic only: BasicInfoCard.test.tsx, AMMPool/utils.ts, ConfBalanceTooltipIcon.tsx, Notification/index.tsx, TransactionActionIcon.tsx, registerServiceWorker.js.

Lockfile — 86 packages changed version, 44 added, 46 removed; most of the churn is Express 5's own dependency tree (router, path-to-regexp 8, serve-static 2, …).

All Semgrep tickets closed in Q3 were re-verified against this lockfile and remain satisfied (e.g. path-to-regexp is now 8.4.2 and serve-static 2.2.1, both outside their advisories' affected ranges).

Test Plan

Run locally on Node 22.14:

  • npm run lint:ci — passes
  • npm run build — passes
  • npm run build-ts — passes
  • npm run test:ci — 292/293 suites, 1688/1726 tests pass; coverage thresholds met. The only failure, src/containers/shared/test/amendmentUtils.test.ts (38 tests), calls the live VHS dev API (vhs.dev.ripplex.io/v1/network/amendments/info), which was returning HTTP 503 during the run; it fails identically on an untouched main checkout. It is unrelated to this batch and should pass once the endpoint recovers (or be mocked in a follow-up).
  • Express 5 server smoke test (not covered by CI), with node server:
    • NODE_ENV=production: / → 200 index.html; /transactions/ABC123 → 200 index.html (SPA fallback); /api/v1/healthz → 200 success.
    • NODE_ENV=development: / → 200 (static); /transactions/ABC123 → 404 {"error":"route not found"}; /api/v1/does-not-exist → 404.

Superseded Dependabot PRs

PR Package From Asked for Resolved Status MajorVersionUpgrade
#1375 ts-jest 29.4.9 29.4.14 29.4.14 Upgraded No
#1374 dotenv 17.4.2 18.0.5 18.0.6 Upgraded Yes (v18)
#1373 @testing-library/react 13.4.0 16.3.3 16.3.3 Upgraded Yes (v14, v15, v16)
#1372 compression 1.8.1 1.8.2 1.8.2 Upgraded No
#1371 stylelint-scss 7.0.0 7.3.0 7.3.0 Upgraded No
#1370 @babel/preset-react 7.28.5 8.0.1 7.28.5 Skipped (peer dep conflict: requires @babel/core ^8; installed 7.29.7) Yes (v8)
#1369 express 4.22.3 5.2.1 5.2.1 Upgraded (with server/index.js route fix) Yes (v5, migration guide)
#1368 lint-staged 15.5.2 17.6.0 15.5.2 Skipped (engine conflict: requires Node ≥ 22.22.1; repo allows >=22.0.0 with engine-strict=true) Yes (v16, v17)
#1367 @types/node 22.19.17 26.6.4 22.19.17 Skipped (runtime is Node 22; Node 26 types would allow APIs missing at runtime) Yes (types/node)
#1366 jest-environment-jsdom 30.3.0 30.5.2 30.5.2 Upgraded No
#1365 i18next-browser-languagedetector 7.2.2 8.2.1 8.2.1 Upgraded Yes (v8)
#1364 eslint-plugin-prettier 5.5.5 5.5.6 5.5.6 Upgraded No
#1363 i18next-http-backend 3.0.6 4.0.2 4.0.2 Upgraded Yes (v4)
#1362 @typescript-eslint/parser 8.58.2 8.71.0 8.71.1 Upgraded No
#1361 react / @types/react 18.3.1 / 18.3.28 19.3.0 / 19.3.0 18.3.1 / 18.3.28 Skipped (peer dep conflict: react-query@3.39.3, the last v3, requires react ≤ 18) Yes (v19, types/react)
#1360 react-helmet-async 2.0.5 3.0.0 3.0.0 Upgraded Yes (v3)
#1359 react-error-boundary 4.1.2 6.1.6 6.1.6 Upgraded Yes (v5, v6)
#1358 react-error-overlay 6.0.11 6.1.0 6.1.0 Upgraded No
#1357 vite-plugin-environment 1.1.3 1.1.4 1.1.3 Skipped (peer dep conflict: requires vite >= 8; installed 7.3.6) No
#1356 prettier 3.6.2 3.9.9 3.9.9 Upgraded No
#1355 xrpl 4.6.0 5.3.0 5.3.0 Upgraded Yes (v5)
#1354 react-router 7.18.4 8.4.0 7.18.4 Skipped (peer dep conflict: requires react ≥ 19.2.7, blocked by #1361; also Node ≥ 22.22) Yes (v8)
#1353 vite-plugin-svgr 4.5.0 5.2.0 5.2.0 Upgraded Yes (v5)
#1352 @typescript-eslint/eslint-plugin 8.58.2 8.71.0 8.71.1 Upgraded No
#1351 react-i18next 15.4.1 17.0.15 15.4.1 Skipped (peer dep conflict: requires i18next ≥ 26.2.0; installed 23.16.8) Yes (CHANGELOG)
#1350 babel-jest 29.7.0 30.5.2 30.5.2 Upgraded Yes (v30)
#1349 tldts 6.1.86 7.4.16 7.4.16 Upgraded Yes (v7)
#1348 eslint-import-resolver-typescript 4.4.4 4.4.5 4.4.5 Upgraded No
#1347 @babel/preset-env 7.29.2 8.0.6 7.29.2 Skipped (peer dep conflict: requires @babel/core ^8; installed 7.29.7) Yes (v8)
#1346 eslint-plugin-react-hooks 4.6.2 7.1.1 4.6.2 Skipped (peer dep conflict: eslint-config-airbnb@19.0.4, the latest, requires ^4.3.0) Yes (CHANGELOG)

Semgrep tickets

Out of scope (not package-upgrade-fixable; not addressed here): DGE-4837, DGE-4839, DGE-4840, DGE-7803, DGE-7812 (code findings); DGE-7802, DGE-7804 (config findings); DGE-4831, DGE-4834, DGE-4843, DGE-7794 (ripple/explorer-deploy).

Ticket Package From Asked for Resolved Status MajorVersionUpgrade
DGE-8416 axios 1.20.0 ≥ 1.20.0 1.20.0 No-op (already satisfied on main since the Q3 batch) No
DGE-8417 axios 1.20.0 ≥ 1.20.0 1.20.0 No-op (already satisfied on main since the Q3 batch) No
DGE-8418 axios 1.20.0 ≥ 1.20.0 1.20.0 No-op (already satisfied on main since the Q3 batch) No
DGE-8419 axios 1.20.0 ≥ 1.20.0 1.20.0 No-op (already satisfied on main since the Q3 batch) No

No ticket required an upgrade that a Dependabot PR did not already propose.

Closing instructions

After merging, run /batch-deps-upgrade close to close the superseded PRs and the resolved Semgrep tickets. It will close these Upgraded Dependabot PRs — #1375, #1374, #1373, #1372, #1371, #1369, #1366, #1365, #1364, #1363, #1362, #1360, #1359, #1358, #1356, #1355, #1353, #1352, #1350, #1349, #1348 — and these No-op tickets: DGE-8416, DGE-8417, DGE-8418, DGE-8419.

The following PRs were Skipped and should remain open so Dependabot keeps rebasing them: #1370 (@babel/preset-react), #1368 (lint-staged), #1367 (@types/node), #1361 (react / @types/react), #1357 (vite-plugin-environment), #1354 (react-router), #1351 (react-i18next), #1347 (@babel/preset-env), #1346 (eslint-plugin-react-hooks). No Semgrep tickets stay open.

@pdp2121 pdp2121 changed the title deps: q4 package upgrades chore (deps): q4 package upgrades Oct 8, 2026

@ripple-code-reviewer ripple-code-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a well-documented quarterly dependency batch upgrade. The one behavioral code change — the Express 4→5 route syntax fix in server/index.js (bare * → /{*splat} for the SPA fallback, and dropping the path on the catch-all app.use) — is correct: /{*splat} preserves matching / itself the way the old bare * did, and a path-less app.use already matches every request, so behavior is preserved. The author manually smoke-tested both production and development modes, which is appropriate given CI doesn't load server/. The remaining changes are package.json version bumps (several major, matching the PR's superseded-PR table) and six purely cosmetic Prettier 3.9 re-wraps, none of which introduce logic changes in this diff. No correctness, security, or infrastructure issues were found in the changed lines.

@ripple-code-reviewer ripple-code-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a well-documented, mechanical quarterly dependency-upgrade PR. The only functionally significant change is the Express 4→5 route syntax fix in server/index.js, which was manually smoke-tested in both environments and matches the official migration guide (app.get('/{*splat}', ...) preserves root-path matching, and the no-path app.use catch-all is equivalent to the old '*' pattern). The remaining diffs are version bumps in package.json/package-lock.json (expected given the MR's stated purpose), a pre-commit Prettier rev bump that correctly tracks the package.json Prettier bump, a SKILL.md documentation addition, and cosmetic-only Prettier 3.9 reformatting of type unions and indentation in six files. I did not find any correctness, security, or consistency issues in the changed lines.

@pdp2121

pdp2121 commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator Author

Express 4 -> 5 has been checked and was working fine locally

@pdp2121
pdp2121 merged commit 1a068e5 into main Oct 8, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants