Skip to content

[code-infra] Update dependencies to resolve Dependabot security alerts#4988

Merged
Janpot merged 1 commit into
masterfrom
security/dependabot-deps
Jun 11, 2026
Merged

[code-infra] Update dependencies to resolve Dependabot security alerts#4988
Janpot merged 1 commit into
masterfrom
security/dependabot-deps

Conversation

@Janpot

@Janpot Janpot commented Jun 9, 2026

Copy link
Copy Markdown
Member

Resolves open Dependabot security alerts by bumping affected dependencies to patched versions (transitive dev/build deps, plus React Router and the vitest stack).

Next.js is intentionally held at 16.1.7: the patched 16.2.x line is blocked by an upstream webpack MDX build regression (vercel/next.js#91735), so the Next.js advisories stay open for now. The @tanstack/start-server-core / h3 alerts come only from the examples workspace and will resolve once examples are removed (#4759). Nothing in the published package runtime changes.

@pkg-pr-new

pkg-pr-new Bot commented Jun 9, 2026

Copy link
Copy Markdown

commit: 55a04f5

@code-infra-dashboard

code-infra-dashboard Bot commented Jun 9, 2026

Copy link
Copy Markdown

Bundle size

Bundle Parsed size Gzip size
@base-ui/react 0B(0.00%) 0B(0.00%)

Details of bundle changes

Performance

Total duration: 1,147.77 ms -87.78 ms(-7.1%) | Renders: 50 (+0) | Paint: 1,756.18 ms -101.78 ms(-5.5%)

Test Duration Renders
Checkbox mount (500 instances) 48.87 ms ▼-43.73 ms(-47.2%) 1 (+0)

11 tests within noise — details


Check out the code infra dashboard for more information about this PR.

@Janpot Janpot force-pushed the security/dependabot-deps branch 2 times, most recently from bbb23e9 to 64d16fc Compare June 9, 2026 09:24
@netlify

netlify Bot commented Jun 9, 2026

Copy link
Copy Markdown

Deploy Preview for base-ui ready!

Name Link
🔨 Latest commit 55a04f5
🔍 Latest deploy log https://app.netlify.com/projects/base-ui/deploys/6a2821d4099832000864d009
😎 Deploy Preview https://deploy-preview-4988--base-ui.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@Janpot Janpot force-pushed the security/dependabot-deps branch from 64d16fc to be78a89 Compare June 9, 2026 12:01
@Janpot Janpot added the scope: code-infra Involves the code-infra product (https://www.notion.so/mui-org/5562c14178aa42af97bc1fa5114000cd). label Jun 9, 2026
@Janpot Janpot marked this pull request as ready for review June 9, 2026 13:23
@Janpot Janpot requested a review from a team June 9, 2026 13:24
@Janpot Janpot changed the title Update dependencies to resolve Dependabot security alerts [code-infra] Update dependencies to resolve Dependabot security alerts Jun 9, 2026
@github-actions github-actions Bot added the PR: out-of-date The pull request has merge conflicts and can't be merged. label Jun 9, 2026
@Janpot Janpot force-pushed the security/dependabot-deps branch from be78a89 to 55a04f5 Compare June 9, 2026 14:23
@github-actions github-actions Bot removed the PR: out-of-date The pull request has merge conflicts and can't be merged. label Jun 9, 2026
@Janpot Janpot merged commit a31a965 into master Jun 11, 2026
24 of 26 checks passed
@Janpot Janpot deleted the security/dependabot-deps branch June 11, 2026 09:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

scope: code-infra Involves the code-infra product (https://www.notion.so/mui-org/5562c14178aa42af97bc1fa5114000cd).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant