Repository navigation
chore (deps): q4 package upgrades - #1377
Conversation
There was a problem hiding this comment.
This is a well-documented quarterly dependency batch upgrade. The one behavioral code change — the Express 4→5 route syntax fix in server/index.js (bare * → /{*splat} for the SPA fallback, and dropping the path on the catch-all app.use) — is correct: /{*splat} preserves matching / itself the way the old bare * did, and a path-less app.use already matches every request, so behavior is preserved. The author manually smoke-tested both production and development modes, which is appropriate given CI doesn't load server/. The remaining changes are package.json version bumps (several major, matching the PR's superseded-PR table) and six purely cosmetic Prettier 3.9 re-wraps, none of which introduce logic changes in this diff. No correctness, security, or infrastructure issues were found in the changed lines.
There was a problem hiding this comment.
This is a well-documented, mechanical quarterly dependency-upgrade PR. The only functionally significant change is the Express 4→5 route syntax fix in server/index.js, which was manually smoke-tested in both environments and matches the official migration guide (app.get('/{*splat}', ...) preserves root-path matching, and the no-path app.use catch-all is equivalent to the old '*' pattern). The remaining diffs are version bumps in package.json/package-lock.json (expected given the MR's stated purpose), a pre-commit Prettier rev bump that correctly tracks the package.json Prettier bump, a SKILL.md documentation addition, and cosmetic-only Prettier 3.9 reformatting of type unions and indentation in six files. I did not find any correctness, security, or consistency issues in the changed lines.
|
Express 4 -> 5 has been checked and was working fine locally |
High Level Overview of Change
Quarterly batch dependency upgrade (2026-Q4). This PR consolidates the open Dependabot dependency PRs and applies any further upgrades needed to resolve the open Semgrep (DGE) supply-chain tickets that a package upgrade can fix.
axios ≥ 1.20.0) are already satisfied onmainby the Q3 batch (No-op), and none are left open.express5,dotenv18,i18next-browser-languagedetector8,i18next-http-backend4,react-helmet-async3,react-error-boundary6,vite-plugin-svgr5,tldts7.Context of Change
Quarterly batch of the Dependabot PRs opened on 2026-10-01, plus the Semgrep tickets a package upgrade can fix. Direct dependency versions were bumped in
package.json;package-lock.jsonwas updated in place (never regenerated from scratch). Nooverridesorresolutionswere added and no parent range was widened.Type of Change
"Breaking change" is checked because production dependencies cross major versions (most notably
express5). User-facing behavior is unchanged.Codebase Modernization
N/A — no file conversions.
Before / After
server/index.js— Express 5 route syntax (details incode-changes.md):/{*splat}keeps matching/itself, as*did;app.usewith no path already matches every request.Prettier 3.9 reformat — six files re-wrapped by
npm run lint(--fix), cosmetic only:BasicInfoCard.test.tsx,AMMPool/utils.ts,ConfBalanceTooltipIcon.tsx,Notification/index.tsx,TransactionActionIcon.tsx,registerServiceWorker.js.Lockfile — 86 packages changed version, 44 added, 46 removed; most of the churn is Express 5's own dependency tree (
router,path-to-regexp8,serve-static2, …).All Semgrep tickets closed in Q3 were re-verified against this lockfile and remain satisfied (e.g.
path-to-regexpis now 8.4.2 andserve-static2.2.1, both outside their advisories' affected ranges).Test Plan
Run locally on Node 22.14:
npm run lint:ci— passesnpm run build— passesnpm run build-ts— passesnpm run test:ci— 292/293 suites, 1688/1726 tests pass; coverage thresholds met. The only failure,src/containers/shared/test/amendmentUtils.test.ts(38 tests), calls the live VHS dev API (vhs.dev.ripplex.io/v1/network/amendments/info), which was returning HTTP 503 during the run; it fails identically on an untouchedmaincheckout. It is unrelated to this batch and should pass once the endpoint recovers (or be mocked in a follow-up).node server:NODE_ENV=production:/→ 200index.html;/transactions/ABC123→ 200index.html(SPA fallback);/api/v1/healthz→ 200success.NODE_ENV=development:/→ 200 (static);/transactions/ABC123→ 404{"error":"route not found"};/api/v1/does-not-exist→ 404.Superseded Dependabot PRs
@babel/core ^8; installed 7.29.7)server/index.jsroute fix)>=22.0.0withengine-strict=true)react-query@3.39.3, the last v3, requiresreact ≤ 18)vite >= 8; installed 7.3.6)react ≥ 19.2.7, blocked by #1361; also Node ≥ 22.22)i18next ≥ 26.2.0; installed 23.16.8)@babel/core ^8; installed 7.29.7)eslint-config-airbnb@19.0.4, the latest, requires^4.3.0)Semgrep tickets
Out of scope (not package-upgrade-fixable; not addressed here): DGE-4837, DGE-4839, DGE-4840, DGE-7803, DGE-7812 (code findings); DGE-7802, DGE-7804 (config findings); DGE-4831, DGE-4834, DGE-4843, DGE-7794 (
ripple/explorer-deploy).No ticket required an upgrade that a Dependabot PR did not already propose.
Closing instructions
After merging, run
/batch-deps-upgrade closeto close the superseded PRs and the resolved Semgrep tickets. It will close these Upgraded Dependabot PRs — #1375, #1374, #1373, #1372, #1371, #1369, #1366, #1365, #1364, #1363, #1362, #1360, #1359, #1358, #1356, #1355, #1353, #1352, #1350, #1349, #1348 — and these No-op tickets: DGE-8416, DGE-8417, DGE-8418, DGE-8419.The following PRs were Skipped and should remain open so Dependabot keeps rebasing them: #1370 (@babel/preset-react), #1368 (lint-staged), #1367 (@types/node), #1361 (react / @types/react), #1357 (vite-plugin-environment), #1354 (react-router), #1351 (react-i18next), #1347 (@babel/preset-env), #1346 (eslint-plugin-react-hooks). No Semgrep tickets stay open.