Skip to content

chore(deps): bump Next to 16.3.4 and safe minors - #52

Merged
AdamEXu merged 1 commit into
mainfrom
cursor/deps-2026-09-02-bump-fb2f
Sep 2, 2026
Merged

AdamEXu merged 1 commit into
mainfrom
cursor/deps-2026-09-02-bump-fb2f

Conversation

@AdamEXu

@AdamEXu AdamEXu commented Sep 2, 2026 •

Copy link
Copy Markdown
Member

What & why

Morning dependency maintenance (Adam Xu). Supply-chain review already done — this PR only applies the approved bumps. Next is raised to 16.3.4 (security floor 16.3.3+).

Frontend (frontend/package.json + pnpm-lock.yaml)

Security (must bump)

Package From To
next 16.2.12 16.3.4
eslint-config-next 16.2.12 16.3.4

Safe minors / patches

Package From To
lucide-react ^1.27.0 ^1.39.0 (resolved 1.39.0)
posthog-js ^1.407.3 >=1.422.1 <1.425.0 (resolved 1.424.1)
fumadocs-core ^16.13.0 ^16.15.4 (resolved 16.15.4)
fumadocs-ui ^16.13.0 ^16.15.4 (resolved 16.15.4)
katex ^0.18.1 ^0.18.5 (resolved 0.18.5)
@types/node ^26.1.2 ^26.4.1 (resolved 26.4.1)
@types/react ^19.2.17 ^19.2.18 (resolved 19.2.18)
@types/react-dom ^19.2.3 ^19.2.5 (resolved 19.2.5)

posthog-js is ranged to keep a floor of 1.422.1 and exclude 1.425.x (too fresh for this cycle). Lockfile is on 1.424.1.

Backend (backend/requirements.txt)

Package From To
google-api-python-client 2.199.0 2.200.0

No pip lockfile in-repo; pins live in requirements.txt.

Deferred (not in this PR)

  • fumadocs-mdx major 14 → 15
  • eslint 9 → 10
  • typescript 5.9.x → 7

Skipped (supply-chain / freshness)

  • openai → 3.7.0 — brand-new release; leave at 3.6.0
  • posthog-js 1.425.x — too fresh; pin floor 1.422.1, cap below 1.425.0

Area

  • Frontend
  • Backend
  • Scraper
  • Convex
  • Infra / tooling

How tested

  • cd frontend && pnpm install — lockfile updated; posthog-js resolved to 1.424.1
  • cd frontend && pnpm typecheck — pass (CI hard gate)
  • cd frontend && pnpm build — pass on Next.js 16.3.4 (Turbopack); 16 routes generated
  • cd frontend && pnpm lint — still fails with pre-existing violations (CI is continue-on-error / non-blocking ratchet)
  • google-api-python-client==2.200.0 — pip resolves successfully; pin-only, no backend code change

Security checklist

  • Endpoints returning user data enforce ownership / authorization (no IDOR — a user cannot read another user's data). — N/A, dependency versions only
  • @auth_required is applied to routes that need authentication. — N/A, dependency versions only
  • No SSRF: any outbound/scraped URL is validated (scheme + host) before it is fetched. — N/A, dependency versions only
  • No secrets committed — no .env, *.db, keys, or credentials in the diff.
  • Flask debug mode is not forced on in a production code path. — N/A, dependency versions only
  • OAuth tokens stay encrypted at rest and are never logged or returned in responses. — N/A, dependency versions only

Checks

  • cd frontend && pnpm lint passes. — lint still has the pre-existing backlog; CI treats it as non-blocking
  • Backend still starts and affected endpoints work (make dev-backend). — pin-only google-api-python-client 2.199.0 → 2.200.0; pip dry-run resolves
Open in Web Open in Cursor 

Raise Next and eslint-config-next to 16.3.4 (security floor 16.3.3+),
and bump the approved frontend minors plus google-api-python-client
2.200.0. posthog-js is capped below 1.425.x; openai 3.7.0 and deferred
majors are left unchanged.

Co-authored-by: Adam Xu <AdamEXu@users.noreply.github.com>
@AdamEXu
AdamEXu marked this pull request as ready for review September 2, 2026 15:28
@greptile-apps

greptile-apps Bot commented Sep 2, 2026

Copy link
Copy Markdown

Greptile Summary

The PR updates the frontend’s Next.js, documentation, analytics, rendering, icon, and type dependencies, and advances the backend Google API client pin.

  • Raises Next.js and its ESLint configuration to 16.3.4.
  • Updates the pnpm lockfile to the corresponding dependency graph.
  • Constrains PostHog to the approved 1.422.1–1.424.x range.
  • Updates google-api-python-client to 2.200.0.

Confidence Score: 5/5

The PR appears safe to merge because no concrete changed-code failure remains after reviewing the dependency constraints, locked resolutions, supported runtime targets, and existing usage sites.

The updated manifest and lockfile are consistent, current automated and deployment installs use the frozen lockfile, and no incompatible existing API usage or reachable runtime failure was established.

Important Files Changed

Filename Overview
frontend/package.json Updates direct frontend dependency constraints, with exact pins for Next.js and its ESLint configuration and an explicit upper bound for PostHog.
frontend/pnpm-lock.yaml Regenerates the locked frontend dependency graph consistently with the manifest, including updated Next.js, Fumadocs, PostHog, KaTeX, Lucide, and transitive packages.
backend/requirements.txt Advances the exact google-api-python-client pin from 2.199.0 to 2.200.0 without changing backend code.

Reviews (1): Last reviewed commit: "chore(deps): bump Next to 16.3.4 and saf..." | Re-trigger Greptile

@AdamEXu
AdamEXu merged commit 91c107e into main Sep 2, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants