chore(dependabot): Update remix-run all together - #18885

Closed
JPeer264 wants to merge 1 commit into
developfrom
jp/remix-update
Closed

chore(dependabot): Update remix-run all together#18885
JPeer264 wants to merge 1 commit into
developfrom
jp/remix-update

Conversation

@JPeer264

Copy link
Copy Markdown
Member

There were 3 different PRs opened for a remix-run update: #18750#18747#18746

Each failed because they needed the other packages to be there. Not all @remix-run/* packages follow the same version update, just some. But it is still better to update all together nontheless

@JPeer264JPeer264 self-assigned this Jan 19, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

- '@opentelemetry/*'
remix:
patterns:
- '@remix-run/*'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remix group defined but packages not in allow list

Medium Severity

The remix group is added with pattern @remix-run/*, but @remix-run/* is not included in the allow list. When an allow list is specified, dependabot only updates dependencies matching those patterns. The group definition is effectively unused because those packages won't receive version updates. To achieve the PR's stated goal of updating remix-run packages together, @remix-run/* needs to be added to the allow list as well.

Additional Locations (1)

Fix in CursorFix in Web

Comment on lines +26 to +28
remix:
patterns:
- '@remix-run/*'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The new remix dependency group will not receive updates because the @remix-run/* pattern is missing from the allow list in the Dependabot configuration.
Severity: CRITICAL

Suggested Fix

Add the @remix-run/* pattern to the allow list in the .github/dependabot.yml file to enable Dependabot to create pull requests for these dependencies.

allow:
- dependency-name: '@sentry/*'
- dependency-name: '@playwright/test'
- dependency-name: '@opentelemetry/*'
- dependency-name: '@remix-run/*'# Add this line
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: .github/dependabot.yml#L26-L28
Potential issue: The `dependabot.yml` configuration is being updated to group
`@remix-run/*` dependencies. However, the configuration includes a restrictive `allow`
list that dictates which dependencies Dependabot can update. The pattern `@remix-run/*`
has not been added to this `allow` list. As a result, Dependabot will ignore all
`@remix-run/*` packages and will not create any pull requests for their updates. This
defeats the purpose of the change and prevents the project from receiving security and
version updates for these dependencies.

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

Copy link
Copy Markdown
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.
⚠️Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

ScenarioRequests/s% of BaselinePrev. Requests/sChange %
GET Baseline9,084-8,835+3%
GET With Sentry1,82220%1,753+4%
GET With Sentry (error only)6,14668%5,998+2%
POST Baseline1,219-1,143+7%
POST With Sentry60550%556+9%
POST With Sentry (error only)1,06687%1,049+2%
MYSQL Baseline3,413-3,329+3%
MYSQL With Sentry51315%472+9%
MYSQL With Sentry (error only)2,75981%2,691+3%

View base workflow run

@JPeer264

Copy link
Copy Markdown
MemberAuthor

Closed as these PRs should have never happened. remix-run is not in the allow list of our dependabot

JPeer264 added a commit that referenced this pull request Jan 28, 2026
This resurrects #18885 and also adds a glob to the `exclude-paths`.
I suspect that `dev-packages` still got updates because there were
missing glob patterns: `**`. At least this is what I understood from the
docs:
https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#exclude-paths-
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@JPeer264@nicohrubec
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore(dependabot): Update remix-run all together - #18885

Closed
JPeer264 wants to merge 1 commit into
developfrom
jp/remix-update
Closed

chore(dependabot): Update remix-run all together#18885
JPeer264 wants to merge 1 commit into
developfrom
jp/remix-update

Conversation

@JPeer264

Copy link
Copy Markdown
Member

There were 3 different PRs opened for a remix-run update: #18750#18747#18746

Each failed because they needed the other packages to be there. Not all @remix-run/* packages follow the same version update, just some. But it is still better to update all together nontheless

@JPeer264JPeer264 self-assigned this Jan 19, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

- '@opentelemetry/*'
remix:
patterns:
- '@remix-run/*'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remix group defined but packages not in allow list

Medium Severity

The remix group is added with pattern @remix-run/*, but @remix-run/* is not included in the allow list. When an allow list is specified, dependabot only updates dependencies matching those patterns. The group definition is effectively unused because those packages won't receive version updates. To achieve the PR's stated goal of updating remix-run packages together, @remix-run/* needs to be added to the allow list as well.

Additional Locations (1)

Fix in CursorFix in Web

Comment on lines +26 to +28
remix:
patterns:
- '@remix-run/*'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The new remix dependency group will not receive updates because the @remix-run/* pattern is missing from the allow list in the Dependabot configuration.
Severity: CRITICAL

Suggested Fix

Add the @remix-run/* pattern to the allow list in the .github/dependabot.yml file to enable Dependabot to create pull requests for these dependencies.

allow:
- dependency-name: '@sentry/*'
- dependency-name: '@playwright/test'
- dependency-name: '@opentelemetry/*'
- dependency-name: '@remix-run/*'# Add this line
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: .github/dependabot.yml#L26-L28
Potential issue: The `dependabot.yml` configuration is being updated to group
`@remix-run/*` dependencies. However, the configuration includes a restrictive `allow`
list that dictates which dependencies Dependabot can update. The pattern `@remix-run/*`
has not been added to this `allow` list. As a result, Dependabot will ignore all
`@remix-run/*` packages and will not create any pull requests for their updates. This
defeats the purpose of the change and prevents the project from receiving security and
version updates for these dependencies.

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

Copy link
Copy Markdown
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.
⚠️Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

ScenarioRequests/s% of BaselinePrev. Requests/sChange %
GET Baseline9,084-8,835+3%
GET With Sentry1,82220%1,753+4%
GET With Sentry (error only)6,14668%5,998+2%
POST Baseline1,219-1,143+7%
POST With Sentry60550%556+9%
POST With Sentry (error only)1,06687%1,049+2%
MYSQL Baseline3,413-3,329+3%
MYSQL With Sentry51315%472+9%
MYSQL With Sentry (error only)2,75981%2,691+3%

View base workflow run

@JPeer264

Copy link
Copy Markdown
MemberAuthor

Closed as these PRs should have never happened. remix-run is not in the allow list of our dependabot

JPeer264 added a commit that referenced this pull request Jan 28, 2026
This resurrects #18885 and also adds a glob to the `exclude-paths`.
I suspect that `dev-packages` still got updates because there were
missing glob patterns: `**`. At least this is what I understood from the
docs:
https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#exclude-paths-
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@JPeer264@nicohrubec
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(dependabot): Update remix-run all together - #18885

Closed
JPeer264 wants to merge 1 commit into
developfrom
jp/remix-update
Closed

chore(dependabot): Update remix-run all together#18885
JPeer264 wants to merge 1 commit into
developfrom
jp/remix-update

Conversation

@JPeer264

Copy link
Copy Markdown
Member

There were 3 different PRs opened for a remix-run update: #18750#18747#18746

Each failed because they needed the other packages to be there. Not all @remix-run/* packages follow the same version update, just some. But it is still better to update all together nontheless

@JPeer264JPeer264 self-assigned this Jan 19, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

- '@opentelemetry/*'
remix:
patterns:
- '@remix-run/*'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remix group defined but packages not in allow list

Medium Severity

The remix group is added with pattern @remix-run/*, but @remix-run/* is not included in the allow list. When an allow list is specified, dependabot only updates dependencies matching those patterns. The group definition is effectively unused because those packages won't receive version updates. To achieve the PR's stated goal of updating remix-run packages together, @remix-run/* needs to be added to the allow list as well.

Additional Locations (1)

Fix in CursorFix in Web

Comment on lines +26 to +28
remix:
patterns:
- '@remix-run/*'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The new remix dependency group will not receive updates because the @remix-run/* pattern is missing from the allow list in the Dependabot configuration.
Severity: CRITICAL

Suggested Fix

Add the @remix-run/* pattern to the allow list in the .github/dependabot.yml file to enable Dependabot to create pull requests for these dependencies.

allow:
- dependency-name: '@sentry/*'
- dependency-name: '@playwright/test'
- dependency-name: '@opentelemetry/*'
- dependency-name: '@remix-run/*'# Add this line
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: .github/dependabot.yml#L26-L28
Potential issue: The `dependabot.yml` configuration is being updated to group
`@remix-run/*` dependencies. However, the configuration includes a restrictive `allow`
list that dictates which dependencies Dependabot can update. The pattern `@remix-run/*`
has not been added to this `allow` list. As a result, Dependabot will ignore all
`@remix-run/*` packages and will not create any pull requests for their updates. This
defeats the purpose of the change and prevents the project from receiving security and
version updates for these dependencies.

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

Copy link
Copy Markdown
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.
⚠️Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

ScenarioRequests/s% of BaselinePrev. Requests/sChange %
GET Baseline9,084-8,835+3%
GET With Sentry1,82220%1,753+4%
GET With Sentry (error only)6,14668%5,998+2%
POST Baseline1,219-1,143+7%
POST With Sentry60550%556+9%
POST With Sentry (error only)1,06687%1,049+2%
MYSQL Baseline3,413-3,329+3%
MYSQL With Sentry51315%472+9%
MYSQL With Sentry (error only)2,75981%2,691+3%

View base workflow run

@JPeer264

Copy link
Copy Markdown
MemberAuthor

Closed as these PRs should have never happened. remix-run is not in the allow list of our dependabot

JPeer264 added a commit that referenced this pull request Jan 28, 2026
This resurrects #18885 and also adds a glob to the `exclude-paths`.
I suspect that `dev-packages` still got updates because there were
missing glob patterns: `**`. At least this is what I understood from the
docs:
https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#exclude-paths-
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@JPeer264@nicohrubec
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(dependabot): Update remix-run all together - #18885

Closed
JPeer264 wants to merge 1 commit into
developfrom
jp/remix-update
Closed

chore(dependabot): Update remix-run all together#18885
JPeer264 wants to merge 1 commit into
developfrom
jp/remix-update

Conversation

@JPeer264

Copy link
Copy Markdown
Member

There were 3 different PRs opened for a remix-run update: #18750#18747#18746

Each failed because they needed the other packages to be there. Not all @remix-run/* packages follow the same version update, just some. But it is still better to update all together nontheless

@JPeer264JPeer264 self-assigned this Jan 19, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

- '@opentelemetry/*'
remix:
patterns:
- '@remix-run/*'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remix group defined but packages not in allow list

Medium Severity

The remix group is added with pattern @remix-run/*, but @remix-run/* is not included in the allow list. When an allow list is specified, dependabot only updates dependencies matching those patterns. The group definition is effectively unused because those packages won't receive version updates. To achieve the PR's stated goal of updating remix-run packages together, @remix-run/* needs to be added to the allow list as well.

Additional Locations (1)

Fix in CursorFix in Web

Comment on lines +26 to +28
remix:
patterns:
- '@remix-run/*'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The new remix dependency group will not receive updates because the @remix-run/* pattern is missing from the allow list in the Dependabot configuration.
Severity: CRITICAL

Suggested Fix

Add the @remix-run/* pattern to the allow list in the .github/dependabot.yml file to enable Dependabot to create pull requests for these dependencies.

allow:
- dependency-name: '@sentry/*'
- dependency-name: '@playwright/test'
- dependency-name: '@opentelemetry/*'
- dependency-name: '@remix-run/*'# Add this line
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: .github/dependabot.yml#L26-L28
Potential issue: The `dependabot.yml` configuration is being updated to group
`@remix-run/*` dependencies. However, the configuration includes a restrictive `allow`
list that dictates which dependencies Dependabot can update. The pattern `@remix-run/*`
has not been added to this `allow` list. As a result, Dependabot will ignore all
`@remix-run/*` packages and will not create any pull requests for their updates. This
defeats the purpose of the change and prevents the project from receiving security and
version updates for these dependencies.

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

Copy link
Copy Markdown
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.
⚠️Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

ScenarioRequests/s% of BaselinePrev. Requests/sChange %
GET Baseline9,084-8,835+3%
GET With Sentry1,82220%1,753+4%
GET With Sentry (error only)6,14668%5,998+2%
POST Baseline1,219-1,143+7%
POST With Sentry60550%556+9%
POST With Sentry (error only)1,06687%1,049+2%
MYSQL Baseline3,413-3,329+3%
MYSQL With Sentry51315%472+9%
MYSQL With Sentry (error only)2,75981%2,691+3%

View base workflow run

@JPeer264

Copy link
Copy Markdown
MemberAuthor

Closed as these PRs should have never happened. remix-run is not in the allow list of our dependabot

JPeer264 added a commit that referenced this pull request Jan 28, 2026
This resurrects #18885 and also adds a glob to the `exclude-paths`.
I suspect that `dev-packages` still got updates because there were
missing glob patterns: `**`. At least this is what I understood from the
docs:
https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#exclude-paths-
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@JPeer264@nicohrubec
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore(dependabot): Update remix-run all together - #18885

Closed
JPeer264 wants to merge 1 commit into
developfrom
jp/remix-update
Closed

chore(dependabot): Update remix-run all together#18885
JPeer264 wants to merge 1 commit into
developfrom
jp/remix-update

Conversation

@JPeer264

Copy link
Copy Markdown
Member

There were 3 different PRs opened for a remix-run update: #18750#18747#18746

Each failed because they needed the other packages to be there. Not all @remix-run/* packages follow the same version update, just some. But it is still better to update all together nontheless

@JPeer264JPeer264 self-assigned this Jan 19, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

- '@opentelemetry/*'
remix:
patterns:
- '@remix-run/*'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remix group defined but packages not in allow list

Medium Severity

The remix group is added with pattern @remix-run/*, but @remix-run/* is not included in the allow list. When an allow list is specified, dependabot only updates dependencies matching those patterns. The group definition is effectively unused because those packages won't receive version updates. To achieve the PR's stated goal of updating remix-run packages together, @remix-run/* needs to be added to the allow list as well.

Additional Locations (1)

Fix in CursorFix in Web

Comment on lines +26 to +28
remix:
patterns:
- '@remix-run/*'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The new remix dependency group will not receive updates because the @remix-run/* pattern is missing from the allow list in the Dependabot configuration.
Severity: CRITICAL

Suggested Fix

Add the @remix-run/* pattern to the allow list in the .github/dependabot.yml file to enable Dependabot to create pull requests for these dependencies.

allow:
- dependency-name: '@sentry/*'
- dependency-name: '@playwright/test'
- dependency-name: '@opentelemetry/*'
- dependency-name: '@remix-run/*'# Add this line
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: .github/dependabot.yml#L26-L28
Potential issue: The `dependabot.yml` configuration is being updated to group
`@remix-run/*` dependencies. However, the configuration includes a restrictive `allow`
list that dictates which dependencies Dependabot can update. The pattern `@remix-run/*`
has not been added to this `allow` list. As a result, Dependabot will ignore all
`@remix-run/*` packages and will not create any pull requests for their updates. This
defeats the purpose of the change and prevents the project from receiving security and
version updates for these dependencies.

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

Copy link
Copy Markdown
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.
⚠️Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

ScenarioRequests/s% of BaselinePrev. Requests/sChange %
GET Baseline9,084-8,835+3%
GET With Sentry1,82220%1,753+4%
GET With Sentry (error only)6,14668%5,998+2%
POST Baseline1,219-1,143+7%
POST With Sentry60550%556+9%
POST With Sentry (error only)1,06687%1,049+2%
MYSQL Baseline3,413-3,329+3%
MYSQL With Sentry51315%472+9%
MYSQL With Sentry (error only)2,75981%2,691+3%

View base workflow run

@JPeer264

Copy link
Copy Markdown
MemberAuthor

Closed as these PRs should have never happened. remix-run is not in the allow list of our dependabot

JPeer264 added a commit that referenced this pull request Jan 28, 2026
This resurrects #18885 and also adds a glob to the `exclude-paths`.
I suspect that `dev-packages` still got updates because there were
missing glob patterns: `**`. At least this is what I understood from the
docs:
https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#exclude-paths-
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@JPeer264@nicohrubec
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(dependabot): Update remix-run all together - #18885

Closed
JPeer264 wants to merge 1 commit into
developfrom
jp/remix-update
Closed

chore(dependabot): Update remix-run all together#18885
JPeer264 wants to merge 1 commit into
developfrom
jp/remix-update

Conversation

@JPeer264

Copy link
Copy Markdown
Member

There were 3 different PRs opened for a remix-run update: #18750#18747#18746

Each failed because they needed the other packages to be there. Not all @remix-run/* packages follow the same version update, just some. But it is still better to update all together nontheless

@JPeer264JPeer264 self-assigned this Jan 19, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

- '@opentelemetry/*'
remix:
patterns:
- '@remix-run/*'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remix group defined but packages not in allow list

Medium Severity

The remix group is added with pattern @remix-run/*, but @remix-run/* is not included in the allow list. When an allow list is specified, dependabot only updates dependencies matching those patterns. The group definition is effectively unused because those packages won't receive version updates. To achieve the PR's stated goal of updating remix-run packages together, @remix-run/* needs to be added to the allow list as well.

Additional Locations (1)

Fix in CursorFix in Web

Comment on lines +26 to +28
remix:
patterns:
- '@remix-run/*'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The new remix dependency group will not receive updates because the @remix-run/* pattern is missing from the allow list in the Dependabot configuration.
Severity: CRITICAL

Suggested Fix

Add the @remix-run/* pattern to the allow list in the .github/dependabot.yml file to enable Dependabot to create pull requests for these dependencies.

allow:
- dependency-name: '@sentry/*'
- dependency-name: '@playwright/test'
- dependency-name: '@opentelemetry/*'
- dependency-name: '@remix-run/*'# Add this line
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: .github/dependabot.yml#L26-L28
Potential issue: The `dependabot.yml` configuration is being updated to group
`@remix-run/*` dependencies. However, the configuration includes a restrictive `allow`
list that dictates which dependencies Dependabot can update. The pattern `@remix-run/*`
has not been added to this `allow` list. As a result, Dependabot will ignore all
`@remix-run/*` packages and will not create any pull requests for their updates. This
defeats the purpose of the change and prevents the project from receiving security and
version updates for these dependencies.

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

Copy link
Copy Markdown
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.
⚠️Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

ScenarioRequests/s% of BaselinePrev. Requests/sChange %
GET Baseline9,084-8,835+3%
GET With Sentry1,82220%1,753+4%
GET With Sentry (error only)6,14668%5,998+2%
POST Baseline1,219-1,143+7%
POST With Sentry60550%556+9%
POST With Sentry (error only)1,06687%1,049+2%
MYSQL Baseline3,413-3,329+3%
MYSQL With Sentry51315%472+9%
MYSQL With Sentry (error only)2,75981%2,691+3%

View base workflow run

@JPeer264

Copy link
Copy Markdown
MemberAuthor

Closed as these PRs should have never happened. remix-run is not in the allow list of our dependabot

JPeer264 added a commit that referenced this pull request Jan 28, 2026
This resurrects #18885 and also adds a glob to the `exclude-paths`.
I suspect that `dev-packages` still got updates because there were
missing glob patterns: `**`. At least this is what I understood from the
docs:
https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#exclude-paths-
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@JPeer264@nicohrubec
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(dependabot): Update remix-run all together - #18885

Closed
JPeer264 wants to merge 1 commit into
developfrom
jp/remix-update
Closed

chore(dependabot): Update remix-run all together#18885
JPeer264 wants to merge 1 commit into
developfrom
jp/remix-update

Conversation

@JPeer264

Copy link
Copy Markdown
Member

There were 3 different PRs opened for a remix-run update: #18750#18747#18746

Each failed because they needed the other packages to be there. Not all @remix-run/* packages follow the same version update, just some. But it is still better to update all together nontheless

@JPeer264JPeer264 self-assigned this Jan 19, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

- '@opentelemetry/*'
remix:
patterns:
- '@remix-run/*'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remix group defined but packages not in allow list

Medium Severity

The remix group is added with pattern @remix-run/*, but @remix-run/* is not included in the allow list. When an allow list is specified, dependabot only updates dependencies matching those patterns. The group definition is effectively unused because those packages won't receive version updates. To achieve the PR's stated goal of updating remix-run packages together, @remix-run/* needs to be added to the allow list as well.

Additional Locations (1)

Fix in CursorFix in Web

Comment on lines +26 to +28
remix:
patterns:
- '@remix-run/*'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The new remix dependency group will not receive updates because the @remix-run/* pattern is missing from the allow list in the Dependabot configuration.
Severity: CRITICAL

Suggested Fix

Add the @remix-run/* pattern to the allow list in the .github/dependabot.yml file to enable Dependabot to create pull requests for these dependencies.

allow:
- dependency-name: '@sentry/*'
- dependency-name: '@playwright/test'
- dependency-name: '@opentelemetry/*'
- dependency-name: '@remix-run/*'# Add this line
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: .github/dependabot.yml#L26-L28
Potential issue: The `dependabot.yml` configuration is being updated to group
`@remix-run/*` dependencies. However, the configuration includes a restrictive `allow`
list that dictates which dependencies Dependabot can update. The pattern `@remix-run/*`
has not been added to this `allow` list. As a result, Dependabot will ignore all
`@remix-run/*` packages and will not create any pull requests for their updates. This
defeats the purpose of the change and prevents the project from receiving security and
version updates for these dependencies.

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

Copy link
Copy Markdown
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.
⚠️Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

ScenarioRequests/s% of BaselinePrev. Requests/sChange %
GET Baseline9,084-8,835+3%
GET With Sentry1,82220%1,753+4%
GET With Sentry (error only)6,14668%5,998+2%
POST Baseline1,219-1,143+7%
POST With Sentry60550%556+9%
POST With Sentry (error only)1,06687%1,049+2%
MYSQL Baseline3,413-3,329+3%
MYSQL With Sentry51315%472+9%
MYSQL With Sentry (error only)2,75981%2,691+3%

View base workflow run

@JPeer264

Copy link
Copy Markdown
MemberAuthor

Closed as these PRs should have never happened. remix-run is not in the allow list of our dependabot

JPeer264 added a commit that referenced this pull request Jan 28, 2026
This resurrects #18885 and also adds a glob to the `exclude-paths`.
I suspect that `dev-packages` still got updates because there were
missing glob patterns: `**`. At least this is what I understood from the
docs:
https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#exclude-paths-
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@JPeer264@nicohrubec
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore(dependabot): Update remix-run all together - #18885

Closed
JPeer264 wants to merge 1 commit into
developfrom
jp/remix-update
Closed

chore(dependabot): Update remix-run all together#18885
JPeer264 wants to merge 1 commit into
developfrom
jp/remix-update

Conversation

@JPeer264

Copy link
Copy Markdown
Member

There were 3 different PRs opened for a remix-run update: #18750#18747#18746

Each failed because they needed the other packages to be there. Not all @remix-run/* packages follow the same version update, just some. But it is still better to update all together nontheless

@JPeer264JPeer264 self-assigned this Jan 19, 2026

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

- '@opentelemetry/*'
remix:
patterns:
- '@remix-run/*'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remix group defined but packages not in allow list

Medium Severity

The remix group is added with pattern @remix-run/*, but @remix-run/* is not included in the allow list. When an allow list is specified, dependabot only updates dependencies matching those patterns. The group definition is effectively unused because those packages won't receive version updates. To achieve the PR's stated goal of updating remix-run packages together, @remix-run/* needs to be added to the allow list as well.

Additional Locations (1)

Fix in CursorFix in Web

Comment on lines +26 to +28
remix:
patterns:
- '@remix-run/*'

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: The new remix dependency group will not receive updates because the @remix-run/* pattern is missing from the allow list in the Dependabot configuration.
Severity: CRITICAL

Suggested Fix

Add the @remix-run/* pattern to the allow list in the .github/dependabot.yml file to enable Dependabot to create pull requests for these dependencies.

allow:
- dependency-name: '@sentry/*'
- dependency-name: '@playwright/test'
- dependency-name: '@opentelemetry/*'
- dependency-name: '@remix-run/*'# Add this line
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: .github/dependabot.yml#L26-L28
Potential issue: The `dependabot.yml` configuration is being updated to group
`@remix-run/*` dependencies. However, the configuration includes a restrictive `allow`
list that dictates which dependencies Dependabot can update. The pattern `@remix-run/*`
has not been added to this `allow` list. As a result, Dependabot will ignore all
`@remix-run/*` packages and will not create any pull requests for their updates. This
defeats the purpose of the change and prevents the project from receiving security and
version updates for these dependencies.

Did we get this right? 👍 / 👎 to inform future reviews.

@github-actions

Copy link
Copy Markdown
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.
⚠️Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

ScenarioRequests/s% of BaselinePrev. Requests/sChange %
GET Baseline9,084-8,835+3%
GET With Sentry1,82220%1,753+4%
GET With Sentry (error only)6,14668%5,998+2%
POST Baseline1,219-1,143+7%
POST With Sentry60550%556+9%
POST With Sentry (error only)1,06687%1,049+2%
MYSQL Baseline3,413-3,329+3%
MYSQL With Sentry51315%472+9%
MYSQL With Sentry (error only)2,75981%2,691+3%

View base workflow run

@JPeer264

Copy link
Copy Markdown
MemberAuthor

Closed as these PRs should have never happened. remix-run is not in the allow list of our dependabot

JPeer264 added a commit that referenced this pull request Jan 28, 2026
This resurrects #18885 and also adds a glob to the `exclude-paths`.
I suspect that `dev-packages` still got updates because there were
missing glob patterns: `**`. At least this is what I understood from the
docs:
https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#exclude-paths-
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@JPeer264@nicohrubec