chore(deps): bump Next to 16.3.4 and safe minors - #52
Merged
Merged
Conversation
Raise Next and eslint-config-next to 16.3.4 (security floor 16.3.3+), and bump the approved frontend minors plus google-api-python-client 2.200.0. posthog-js is capped below 1.425.x; openai 3.7.0 and deferred majors are left unchanged. Co-authored-by: Adam Xu <AdamEXu@users.noreply.github.com>
AdamEXu
marked this pull request as ready for review
September 2, 2026 15:28
Greptile SummaryThe PR updates the frontend’s Next.js, documentation, analytics, rendering, icon, and type dependencies, and advances the backend Google API client pin.
Confidence Score: 5/5The PR appears safe to merge because no concrete changed-code failure remains after reviewing the dependency constraints, locked resolutions, supported runtime targets, and existing usage sites. The updated manifest and lockfile are consistent, current automated and deployment installs use the frozen lockfile, and no incompatible existing API usage or reachable runtime failure was established.
|
| Filename | Overview |
|---|---|
| frontend/package.json | Updates direct frontend dependency constraints, with exact pins for Next.js and its ESLint configuration and an explicit upper bound for PostHog. |
| frontend/pnpm-lock.yaml | Regenerates the locked frontend dependency graph consistently with the manifest, including updated Next.js, Fumadocs, PostHog, KaTeX, Lucide, and transitive packages. |
| backend/requirements.txt | Advances the exact google-api-python-client pin from 2.199.0 to 2.200.0 without changing backend code. |
Reviews (1): Last reviewed commit: "chore(deps): bump Next to 16.3.4 and saf..." | Re-trigger Greptile
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What & why
Morning dependency maintenance (Adam Xu). Supply-chain review already done — this PR only applies the approved bumps. Next is raised to 16.3.4 (security floor 16.3.3+).
Frontend (
frontend/package.json+pnpm-lock.yaml)Security (must bump)
nexteslint-config-nextSafe minors / patches
lucide-reactposthog-js>=1.422.1 <1.425.0(resolved 1.424.1)fumadocs-corefumadocs-uikatex@types/node@types/react@types/react-domposthog-jsis ranged to keep a floor of 1.422.1 and exclude 1.425.x (too fresh for this cycle). Lockfile is on 1.424.1.Backend (
backend/requirements.txt)google-api-python-clientNo pip lockfile in-repo; pins live in
requirements.txt.Deferred (not in this PR)
fumadocs-mdxmajor 14 → 15eslint9 → 10typescript5.9.x → 7Skipped (supply-chain / freshness)
Area
How tested
cd frontend && pnpm install— lockfile updated;posthog-jsresolved to 1.424.1cd frontend && pnpm typecheck— pass (CI hard gate)cd frontend && pnpm build— pass on Next.js 16.3.4 (Turbopack); 16 routes generatedcd frontend && pnpm lint— still fails with pre-existing violations (CI iscontinue-on-error/ non-blocking ratchet)google-api-python-client==2.200.0— pip resolves successfully; pin-only, no backend code changeSecurity checklist
@auth_requiredis applied to routes that need authentication. — N/A, dependency versions only.env,*.db, keys, or credentials in the diff.Checks
cd frontend && pnpm lintpasses. — lint still has the pre-existing backlog; CI treats it as non-blockingmake dev-backend). — pin-onlygoogle-api-python-client2.199.0 → 2.200.0; pip dry-run resolves