chore(deps): lock file maintenance - #757

Merged
joryirving merged 1 commit into
mainfrom
renovate/lock-file-maintenance
Aug 10, 2026
Merged

chore(deps): lock file maintenance#757
joryirving merged 1 commit into
mainfrom
renovate/lock-file-maintenance

Conversation

@its-miso

@its-misoits-misoBot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

UpdateChange
lockFileMaintenanceAll locks refreshed

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone America/Edmonton)

  • Branch creation
    • "before 5am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: dsv4f@https://litellm.jory.dev/v1 (openai) — primary route

Recommendation

Approve. This is a routine Renovate lock-file maintenance change: only package-lock.json is modified, package.json (dependency ranges, engines, overrides) is untouched, and every locked version bump is a patch or minor within an already-declared semver range. All CI gates — Lint, Typecheck, Tests, Build, Docker Build, npm audit — pass on the head commit, including a full production-image build on the exact node:24-bookworm-slim host platform.

Change-by-change findings

  • package-lock.json — Refresh bumps about 20 packages: esbuild 0.28.1 → 0.28.2 with all platform binaries in lockstep; rolldown 1.2.2 → 1.2.3 with @​oxc-project/types 0.142.0 → 0.143.0; pg 8.22.0 → 8.23.0 with pg-protocol 1.15.0 → 1.16.0 and @​types/pg 8.20.3 → 8.21.0; hono 4.13.0 → 4.13.1 and @​hono/node-server 2.0.12 → 2.1.0; vite 8.2.0 → 8.2.1; tsx 4.23.11 → 4.23.12; postcss 8.5.25 → 8.5.26 with nanoid 3.3.17 → 3.3.18; plus express-rate-limit, ip-address, readdirp, axe-core, browserslist/caniuse-lite and related data packages. No package.json manifest changes, so no new ranges, engines entries, or overrides are introduced.
  • Breaking-change check (must_check) — No bump crosses a major version. esbuild 0.28.2 release notes were fetched and describe only bug fixes (TypeScript import-alias tree-shaking, CSS minification of &, input-overwrite regression, top-level await codegen, logical-assignment minification, JS-API deadlock reference counting, duplicated target-engine handling, MP3 MIME detection) with no API/behavior-breaking changes. pg 8.23.0 and @​hono/node-server 2.1.0 are minor bumps within ranges the repo already declared; @​types/pg is a types-only minor.
  • Host-platform coupling — The bumped native/toolchain packages (esbuild, rolldown, vite, tsx) run on the Node platform pinned in the Dockerfile (node:24-bookworm-slim) and by engines.node >= 24. Engine ranges recorded in the lockfile for the new versions (esbuild >=18, rolldown ^20.19.0 || >=22.12.0, @​hono/node-server >=20, readdirp >=20.19.0, ip-address >=12) all include Node 24. The CI Docker Build check installed this exact lockfile and ran the production build on that base image successfully — an empirical compatibility check on the host platform.
  • Test-suite check (must_check) — CI Tests succeeded, alongside Lint, Typecheck, Build, Docker Build, and npm audit.

Sources

  • esbuild v0.28.2 release notes: https://github.com/evanw/esbuild/releases/tag/v0.28.2 (stable patch release, bug fixes only)
  • Repository files read: package.json (engines node >=24; dependency ranges unchanged; postcss/sharp overrides preserved) and Dockerfile (node:24-bookworm-slim base image)
  • CI status for the head commit: Lint, Typecheck, Tests, Build, Docker Build, npm audit, review — all success

Standards Compliance

  • The change touches only the lockfile; no source, Prisma schema, auth, environment-variable, Docker, or workflow conventions are affected.
  • The documented postcss and sharp override pins in package.json are left intact, consistent with the repository's advisory-remediation policy ('DO NOT remove without verifying the originating transitive deps have shipped patched versions').
  • The npm audit CI check passes, consistent with the repository's security posture.

Unknowns / Needs Verification

  • An official Node.js 24 support/compatibility matrix page could not be fetched within the tool budget, so no matrix URL is cited. This is mitigated by (a) engine ranges in the lockfile for every newly locked version, all of which include Node 24, and (b) the CI Docker Build that ran npm ci and built on the exact node:24-bookworm-slim host image with this lockfile. If a citable matrix entry is required before merge, confirm Node 24 support status first (e.g., https://nodejs.org/en/about/previous-releases).
  • The Renovate PR-body warning that some dependencies could not be looked up is standard Renovate boilerplate pointing to the dependency dashboard; it does not indicate lockfile inconsistency, since npm ci and the full build/test pipeline passed in CI.

@joryirving
joryirving merged commit dc1e758 into mainAug 10, 2026
8 checks passed
@joryirving
joryirving deleted the renovate/lock-file-maintenance branch August 10, 2026 12:28
@its-saffronits-saffronBot mentioned this pull request Aug 19, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore(deps): lock file maintenance - #757

Merged
joryirving merged 1 commit into
mainfrom
renovate/lock-file-maintenance
Aug 10, 2026
Merged

chore(deps): lock file maintenance#757
joryirving merged 1 commit into
mainfrom
renovate/lock-file-maintenance

Conversation

@its-miso

@its-misoits-misoBot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

UpdateChange
lockFileMaintenanceAll locks refreshed

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone America/Edmonton)

  • Branch creation
    • "before 5am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: dsv4f@https://litellm.jory.dev/v1 (openai) — primary route

Recommendation

Approve. This is a routine Renovate lock-file maintenance change: only package-lock.json is modified, package.json (dependency ranges, engines, overrides) is untouched, and every locked version bump is a patch or minor within an already-declared semver range. All CI gates — Lint, Typecheck, Tests, Build, Docker Build, npm audit — pass on the head commit, including a full production-image build on the exact node:24-bookworm-slim host platform.

Change-by-change findings

  • package-lock.json — Refresh bumps about 20 packages: esbuild 0.28.1 → 0.28.2 with all platform binaries in lockstep; rolldown 1.2.2 → 1.2.3 with @​oxc-project/types 0.142.0 → 0.143.0; pg 8.22.0 → 8.23.0 with pg-protocol 1.15.0 → 1.16.0 and @​types/pg 8.20.3 → 8.21.0; hono 4.13.0 → 4.13.1 and @​hono/node-server 2.0.12 → 2.1.0; vite 8.2.0 → 8.2.1; tsx 4.23.11 → 4.23.12; postcss 8.5.25 → 8.5.26 with nanoid 3.3.17 → 3.3.18; plus express-rate-limit, ip-address, readdirp, axe-core, browserslist/caniuse-lite and related data packages. No package.json manifest changes, so no new ranges, engines entries, or overrides are introduced.
  • Breaking-change check (must_check) — No bump crosses a major version. esbuild 0.28.2 release notes were fetched and describe only bug fixes (TypeScript import-alias tree-shaking, CSS minification of &, input-overwrite regression, top-level await codegen, logical-assignment minification, JS-API deadlock reference counting, duplicated target-engine handling, MP3 MIME detection) with no API/behavior-breaking changes. pg 8.23.0 and @​hono/node-server 2.1.0 are minor bumps within ranges the repo already declared; @​types/pg is a types-only minor.
  • Host-platform coupling — The bumped native/toolchain packages (esbuild, rolldown, vite, tsx) run on the Node platform pinned in the Dockerfile (node:24-bookworm-slim) and by engines.node >= 24. Engine ranges recorded in the lockfile for the new versions (esbuild >=18, rolldown ^20.19.0 || >=22.12.0, @​hono/node-server >=20, readdirp >=20.19.0, ip-address >=12) all include Node 24. The CI Docker Build check installed this exact lockfile and ran the production build on that base image successfully — an empirical compatibility check on the host platform.
  • Test-suite check (must_check) — CI Tests succeeded, alongside Lint, Typecheck, Build, Docker Build, and npm audit.

Sources

  • esbuild v0.28.2 release notes: https://github.com/evanw/esbuild/releases/tag/v0.28.2 (stable patch release, bug fixes only)
  • Repository files read: package.json (engines node >=24; dependency ranges unchanged; postcss/sharp overrides preserved) and Dockerfile (node:24-bookworm-slim base image)
  • CI status for the head commit: Lint, Typecheck, Tests, Build, Docker Build, npm audit, review — all success

Standards Compliance

  • The change touches only the lockfile; no source, Prisma schema, auth, environment-variable, Docker, or workflow conventions are affected.
  • The documented postcss and sharp override pins in package.json are left intact, consistent with the repository's advisory-remediation policy ('DO NOT remove without verifying the originating transitive deps have shipped patched versions').
  • The npm audit CI check passes, consistent with the repository's security posture.

Unknowns / Needs Verification

  • An official Node.js 24 support/compatibility matrix page could not be fetched within the tool budget, so no matrix URL is cited. This is mitigated by (a) engine ranges in the lockfile for every newly locked version, all of which include Node 24, and (b) the CI Docker Build that ran npm ci and built on the exact node:24-bookworm-slim host image with this lockfile. If a citable matrix entry is required before merge, confirm Node 24 support status first (e.g., https://nodejs.org/en/about/previous-releases).
  • The Renovate PR-body warning that some dependencies could not be looked up is standard Renovate boilerplate pointing to the dependency dashboard; it does not indicate lockfile inconsistency, since npm ci and the full build/test pipeline passed in CI.

@joryirving
joryirving merged commit dc1e758 into mainAug 10, 2026
8 checks passed
@joryirving
joryirving deleted the renovate/lock-file-maintenance branch August 10, 2026 12:28
@its-saffronits-saffronBot mentioned this pull request Aug 19, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): lock file maintenance - #757

Merged
joryirving merged 1 commit into
mainfrom
renovate/lock-file-maintenance
Aug 10, 2026
Merged

chore(deps): lock file maintenance#757
joryirving merged 1 commit into
mainfrom
renovate/lock-file-maintenance

Conversation

@its-miso

@its-misoits-misoBot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

UpdateChange
lockFileMaintenanceAll locks refreshed

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone America/Edmonton)

  • Branch creation
    • "before 5am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: dsv4f@https://litellm.jory.dev/v1 (openai) — primary route

Recommendation

Approve. This is a routine Renovate lock-file maintenance change: only package-lock.json is modified, package.json (dependency ranges, engines, overrides) is untouched, and every locked version bump is a patch or minor within an already-declared semver range. All CI gates — Lint, Typecheck, Tests, Build, Docker Build, npm audit — pass on the head commit, including a full production-image build on the exact node:24-bookworm-slim host platform.

Change-by-change findings

  • package-lock.json — Refresh bumps about 20 packages: esbuild 0.28.1 → 0.28.2 with all platform binaries in lockstep; rolldown 1.2.2 → 1.2.3 with @​oxc-project/types 0.142.0 → 0.143.0; pg 8.22.0 → 8.23.0 with pg-protocol 1.15.0 → 1.16.0 and @​types/pg 8.20.3 → 8.21.0; hono 4.13.0 → 4.13.1 and @​hono/node-server 2.0.12 → 2.1.0; vite 8.2.0 → 8.2.1; tsx 4.23.11 → 4.23.12; postcss 8.5.25 → 8.5.26 with nanoid 3.3.17 → 3.3.18; plus express-rate-limit, ip-address, readdirp, axe-core, browserslist/caniuse-lite and related data packages. No package.json manifest changes, so no new ranges, engines entries, or overrides are introduced.
  • Breaking-change check (must_check) — No bump crosses a major version. esbuild 0.28.2 release notes were fetched and describe only bug fixes (TypeScript import-alias tree-shaking, CSS minification of &, input-overwrite regression, top-level await codegen, logical-assignment minification, JS-API deadlock reference counting, duplicated target-engine handling, MP3 MIME detection) with no API/behavior-breaking changes. pg 8.23.0 and @​hono/node-server 2.1.0 are minor bumps within ranges the repo already declared; @​types/pg is a types-only minor.
  • Host-platform coupling — The bumped native/toolchain packages (esbuild, rolldown, vite, tsx) run on the Node platform pinned in the Dockerfile (node:24-bookworm-slim) and by engines.node >= 24. Engine ranges recorded in the lockfile for the new versions (esbuild >=18, rolldown ^20.19.0 || >=22.12.0, @​hono/node-server >=20, readdirp >=20.19.0, ip-address >=12) all include Node 24. The CI Docker Build check installed this exact lockfile and ran the production build on that base image successfully — an empirical compatibility check on the host platform.
  • Test-suite check (must_check) — CI Tests succeeded, alongside Lint, Typecheck, Build, Docker Build, and npm audit.

Sources

  • esbuild v0.28.2 release notes: https://github.com/evanw/esbuild/releases/tag/v0.28.2 (stable patch release, bug fixes only)
  • Repository files read: package.json (engines node >=24; dependency ranges unchanged; postcss/sharp overrides preserved) and Dockerfile (node:24-bookworm-slim base image)
  • CI status for the head commit: Lint, Typecheck, Tests, Build, Docker Build, npm audit, review — all success

Standards Compliance

  • The change touches only the lockfile; no source, Prisma schema, auth, environment-variable, Docker, or workflow conventions are affected.
  • The documented postcss and sharp override pins in package.json are left intact, consistent with the repository's advisory-remediation policy ('DO NOT remove without verifying the originating transitive deps have shipped patched versions').
  • The npm audit CI check passes, consistent with the repository's security posture.

Unknowns / Needs Verification

  • An official Node.js 24 support/compatibility matrix page could not be fetched within the tool budget, so no matrix URL is cited. This is mitigated by (a) engine ranges in the lockfile for every newly locked version, all of which include Node 24, and (b) the CI Docker Build that ran npm ci and built on the exact node:24-bookworm-slim host image with this lockfile. If a citable matrix entry is required before merge, confirm Node 24 support status first (e.g., https://nodejs.org/en/about/previous-releases).
  • The Renovate PR-body warning that some dependencies could not be looked up is standard Renovate boilerplate pointing to the dependency dashboard; it does not indicate lockfile inconsistency, since npm ci and the full build/test pipeline passed in CI.

@joryirving
joryirving merged commit dc1e758 into mainAug 10, 2026
8 checks passed
@joryirving
joryirving deleted the renovate/lock-file-maintenance branch August 10, 2026 12:28
@its-saffronits-saffronBot mentioned this pull request Aug 19, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): lock file maintenance - #757

Merged
joryirving merged 1 commit into
mainfrom
renovate/lock-file-maintenance
Aug 10, 2026
Merged

chore(deps): lock file maintenance#757
joryirving merged 1 commit into
mainfrom
renovate/lock-file-maintenance

Conversation

@its-miso

@its-misoits-misoBot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

UpdateChange
lockFileMaintenanceAll locks refreshed

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone America/Edmonton)

  • Branch creation
    • "before 5am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: dsv4f@https://litellm.jory.dev/v1 (openai) — primary route

Recommendation

Approve. This is a routine Renovate lock-file maintenance change: only package-lock.json is modified, package.json (dependency ranges, engines, overrides) is untouched, and every locked version bump is a patch or minor within an already-declared semver range. All CI gates — Lint, Typecheck, Tests, Build, Docker Build, npm audit — pass on the head commit, including a full production-image build on the exact node:24-bookworm-slim host platform.

Change-by-change findings

  • package-lock.json — Refresh bumps about 20 packages: esbuild 0.28.1 → 0.28.2 with all platform binaries in lockstep; rolldown 1.2.2 → 1.2.3 with @​oxc-project/types 0.142.0 → 0.143.0; pg 8.22.0 → 8.23.0 with pg-protocol 1.15.0 → 1.16.0 and @​types/pg 8.20.3 → 8.21.0; hono 4.13.0 → 4.13.1 and @​hono/node-server 2.0.12 → 2.1.0; vite 8.2.0 → 8.2.1; tsx 4.23.11 → 4.23.12; postcss 8.5.25 → 8.5.26 with nanoid 3.3.17 → 3.3.18; plus express-rate-limit, ip-address, readdirp, axe-core, browserslist/caniuse-lite and related data packages. No package.json manifest changes, so no new ranges, engines entries, or overrides are introduced.
  • Breaking-change check (must_check) — No bump crosses a major version. esbuild 0.28.2 release notes were fetched and describe only bug fixes (TypeScript import-alias tree-shaking, CSS minification of &, input-overwrite regression, top-level await codegen, logical-assignment minification, JS-API deadlock reference counting, duplicated target-engine handling, MP3 MIME detection) with no API/behavior-breaking changes. pg 8.23.0 and @​hono/node-server 2.1.0 are minor bumps within ranges the repo already declared; @​types/pg is a types-only minor.
  • Host-platform coupling — The bumped native/toolchain packages (esbuild, rolldown, vite, tsx) run on the Node platform pinned in the Dockerfile (node:24-bookworm-slim) and by engines.node >= 24. Engine ranges recorded in the lockfile for the new versions (esbuild >=18, rolldown ^20.19.0 || >=22.12.0, @​hono/node-server >=20, readdirp >=20.19.0, ip-address >=12) all include Node 24. The CI Docker Build check installed this exact lockfile and ran the production build on that base image successfully — an empirical compatibility check on the host platform.
  • Test-suite check (must_check) — CI Tests succeeded, alongside Lint, Typecheck, Build, Docker Build, and npm audit.

Sources

  • esbuild v0.28.2 release notes: https://github.com/evanw/esbuild/releases/tag/v0.28.2 (stable patch release, bug fixes only)
  • Repository files read: package.json (engines node >=24; dependency ranges unchanged; postcss/sharp overrides preserved) and Dockerfile (node:24-bookworm-slim base image)
  • CI status for the head commit: Lint, Typecheck, Tests, Build, Docker Build, npm audit, review — all success

Standards Compliance

  • The change touches only the lockfile; no source, Prisma schema, auth, environment-variable, Docker, or workflow conventions are affected.
  • The documented postcss and sharp override pins in package.json are left intact, consistent with the repository's advisory-remediation policy ('DO NOT remove without verifying the originating transitive deps have shipped patched versions').
  • The npm audit CI check passes, consistent with the repository's security posture.

Unknowns / Needs Verification

  • An official Node.js 24 support/compatibility matrix page could not be fetched within the tool budget, so no matrix URL is cited. This is mitigated by (a) engine ranges in the lockfile for every newly locked version, all of which include Node 24, and (b) the CI Docker Build that ran npm ci and built on the exact node:24-bookworm-slim host image with this lockfile. If a citable matrix entry is required before merge, confirm Node 24 support status first (e.g., https://nodejs.org/en/about/previous-releases).
  • The Renovate PR-body warning that some dependencies could not be looked up is standard Renovate boilerplate pointing to the dependency dashboard; it does not indicate lockfile inconsistency, since npm ci and the full build/test pipeline passed in CI.

@joryirving
joryirving merged commit dc1e758 into mainAug 10, 2026
8 checks passed
@joryirving
joryirving deleted the renovate/lock-file-maintenance branch August 10, 2026 12:28
@its-saffronits-saffronBot mentioned this pull request Aug 19, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore(deps): lock file maintenance - #757

Merged
joryirving merged 1 commit into
mainfrom
renovate/lock-file-maintenance
Aug 10, 2026
Merged

chore(deps): lock file maintenance#757
joryirving merged 1 commit into
mainfrom
renovate/lock-file-maintenance

Conversation

@its-miso

@its-misoits-misoBot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

UpdateChange
lockFileMaintenanceAll locks refreshed

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone America/Edmonton)

  • Branch creation
    • "before 5am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: dsv4f@https://litellm.jory.dev/v1 (openai) — primary route

Recommendation

Approve. This is a routine Renovate lock-file maintenance change: only package-lock.json is modified, package.json (dependency ranges, engines, overrides) is untouched, and every locked version bump is a patch or minor within an already-declared semver range. All CI gates — Lint, Typecheck, Tests, Build, Docker Build, npm audit — pass on the head commit, including a full production-image build on the exact node:24-bookworm-slim host platform.

Change-by-change findings

  • package-lock.json — Refresh bumps about 20 packages: esbuild 0.28.1 → 0.28.2 with all platform binaries in lockstep; rolldown 1.2.2 → 1.2.3 with @​oxc-project/types 0.142.0 → 0.143.0; pg 8.22.0 → 8.23.0 with pg-protocol 1.15.0 → 1.16.0 and @​types/pg 8.20.3 → 8.21.0; hono 4.13.0 → 4.13.1 and @​hono/node-server 2.0.12 → 2.1.0; vite 8.2.0 → 8.2.1; tsx 4.23.11 → 4.23.12; postcss 8.5.25 → 8.5.26 with nanoid 3.3.17 → 3.3.18; plus express-rate-limit, ip-address, readdirp, axe-core, browserslist/caniuse-lite and related data packages. No package.json manifest changes, so no new ranges, engines entries, or overrides are introduced.
  • Breaking-change check (must_check) — No bump crosses a major version. esbuild 0.28.2 release notes were fetched and describe only bug fixes (TypeScript import-alias tree-shaking, CSS minification of &, input-overwrite regression, top-level await codegen, logical-assignment minification, JS-API deadlock reference counting, duplicated target-engine handling, MP3 MIME detection) with no API/behavior-breaking changes. pg 8.23.0 and @​hono/node-server 2.1.0 are minor bumps within ranges the repo already declared; @​types/pg is a types-only minor.
  • Host-platform coupling — The bumped native/toolchain packages (esbuild, rolldown, vite, tsx) run on the Node platform pinned in the Dockerfile (node:24-bookworm-slim) and by engines.node >= 24. Engine ranges recorded in the lockfile for the new versions (esbuild >=18, rolldown ^20.19.0 || >=22.12.0, @​hono/node-server >=20, readdirp >=20.19.0, ip-address >=12) all include Node 24. The CI Docker Build check installed this exact lockfile and ran the production build on that base image successfully — an empirical compatibility check on the host platform.
  • Test-suite check (must_check) — CI Tests succeeded, alongside Lint, Typecheck, Build, Docker Build, and npm audit.

Sources

  • esbuild v0.28.2 release notes: https://github.com/evanw/esbuild/releases/tag/v0.28.2 (stable patch release, bug fixes only)
  • Repository files read: package.json (engines node >=24; dependency ranges unchanged; postcss/sharp overrides preserved) and Dockerfile (node:24-bookworm-slim base image)
  • CI status for the head commit: Lint, Typecheck, Tests, Build, Docker Build, npm audit, review — all success

Standards Compliance

  • The change touches only the lockfile; no source, Prisma schema, auth, environment-variable, Docker, or workflow conventions are affected.
  • The documented postcss and sharp override pins in package.json are left intact, consistent with the repository's advisory-remediation policy ('DO NOT remove without verifying the originating transitive deps have shipped patched versions').
  • The npm audit CI check passes, consistent with the repository's security posture.

Unknowns / Needs Verification

  • An official Node.js 24 support/compatibility matrix page could not be fetched within the tool budget, so no matrix URL is cited. This is mitigated by (a) engine ranges in the lockfile for every newly locked version, all of which include Node 24, and (b) the CI Docker Build that ran npm ci and built on the exact node:24-bookworm-slim host image with this lockfile. If a citable matrix entry is required before merge, confirm Node 24 support status first (e.g., https://nodejs.org/en/about/previous-releases).
  • The Renovate PR-body warning that some dependencies could not be looked up is standard Renovate boilerplate pointing to the dependency dashboard; it does not indicate lockfile inconsistency, since npm ci and the full build/test pipeline passed in CI.

@joryirving
joryirving merged commit dc1e758 into mainAug 10, 2026
8 checks passed
@joryirving
joryirving deleted the renovate/lock-file-maintenance branch August 10, 2026 12:28
@its-saffronits-saffronBot mentioned this pull request Aug 19, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): lock file maintenance - #757

Merged
joryirving merged 1 commit into
mainfrom
renovate/lock-file-maintenance
Aug 10, 2026
Merged

chore(deps): lock file maintenance#757
joryirving merged 1 commit into
mainfrom
renovate/lock-file-maintenance

Conversation

@its-miso

@its-misoits-misoBot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

UpdateChange
lockFileMaintenanceAll locks refreshed

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone America/Edmonton)

  • Branch creation
    • "before 5am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: dsv4f@https://litellm.jory.dev/v1 (openai) — primary route

Recommendation

Approve. This is a routine Renovate lock-file maintenance change: only package-lock.json is modified, package.json (dependency ranges, engines, overrides) is untouched, and every locked version bump is a patch or minor within an already-declared semver range. All CI gates — Lint, Typecheck, Tests, Build, Docker Build, npm audit — pass on the head commit, including a full production-image build on the exact node:24-bookworm-slim host platform.

Change-by-change findings

  • package-lock.json — Refresh bumps about 20 packages: esbuild 0.28.1 → 0.28.2 with all platform binaries in lockstep; rolldown 1.2.2 → 1.2.3 with @​oxc-project/types 0.142.0 → 0.143.0; pg 8.22.0 → 8.23.0 with pg-protocol 1.15.0 → 1.16.0 and @​types/pg 8.20.3 → 8.21.0; hono 4.13.0 → 4.13.1 and @​hono/node-server 2.0.12 → 2.1.0; vite 8.2.0 → 8.2.1; tsx 4.23.11 → 4.23.12; postcss 8.5.25 → 8.5.26 with nanoid 3.3.17 → 3.3.18; plus express-rate-limit, ip-address, readdirp, axe-core, browserslist/caniuse-lite and related data packages. No package.json manifest changes, so no new ranges, engines entries, or overrides are introduced.
  • Breaking-change check (must_check) — No bump crosses a major version. esbuild 0.28.2 release notes were fetched and describe only bug fixes (TypeScript import-alias tree-shaking, CSS minification of &, input-overwrite regression, top-level await codegen, logical-assignment minification, JS-API deadlock reference counting, duplicated target-engine handling, MP3 MIME detection) with no API/behavior-breaking changes. pg 8.23.0 and @​hono/node-server 2.1.0 are minor bumps within ranges the repo already declared; @​types/pg is a types-only minor.
  • Host-platform coupling — The bumped native/toolchain packages (esbuild, rolldown, vite, tsx) run on the Node platform pinned in the Dockerfile (node:24-bookworm-slim) and by engines.node >= 24. Engine ranges recorded in the lockfile for the new versions (esbuild >=18, rolldown ^20.19.0 || >=22.12.0, @​hono/node-server >=20, readdirp >=20.19.0, ip-address >=12) all include Node 24. The CI Docker Build check installed this exact lockfile and ran the production build on that base image successfully — an empirical compatibility check on the host platform.
  • Test-suite check (must_check) — CI Tests succeeded, alongside Lint, Typecheck, Build, Docker Build, and npm audit.

Sources

  • esbuild v0.28.2 release notes: https://github.com/evanw/esbuild/releases/tag/v0.28.2 (stable patch release, bug fixes only)
  • Repository files read: package.json (engines node >=24; dependency ranges unchanged; postcss/sharp overrides preserved) and Dockerfile (node:24-bookworm-slim base image)
  • CI status for the head commit: Lint, Typecheck, Tests, Build, Docker Build, npm audit, review — all success

Standards Compliance

  • The change touches only the lockfile; no source, Prisma schema, auth, environment-variable, Docker, or workflow conventions are affected.
  • The documented postcss and sharp override pins in package.json are left intact, consistent with the repository's advisory-remediation policy ('DO NOT remove without verifying the originating transitive deps have shipped patched versions').
  • The npm audit CI check passes, consistent with the repository's security posture.

Unknowns / Needs Verification

  • An official Node.js 24 support/compatibility matrix page could not be fetched within the tool budget, so no matrix URL is cited. This is mitigated by (a) engine ranges in the lockfile for every newly locked version, all of which include Node 24, and (b) the CI Docker Build that ran npm ci and built on the exact node:24-bookworm-slim host image with this lockfile. If a citable matrix entry is required before merge, confirm Node 24 support status first (e.g., https://nodejs.org/en/about/previous-releases).
  • The Renovate PR-body warning that some dependencies could not be looked up is standard Renovate boilerplate pointing to the dependency dashboard; it does not indicate lockfile inconsistency, since npm ci and the full build/test pipeline passed in CI.

@joryirving
joryirving merged commit dc1e758 into mainAug 10, 2026
8 checks passed
@joryirving
joryirving deleted the renovate/lock-file-maintenance branch August 10, 2026 12:28
@its-saffronits-saffronBot mentioned this pull request Aug 19, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): lock file maintenance - #757

Merged
joryirving merged 1 commit into
mainfrom
renovate/lock-file-maintenance
Aug 10, 2026
Merged

chore(deps): lock file maintenance#757
joryirving merged 1 commit into
mainfrom
renovate/lock-file-maintenance

Conversation

@its-miso

@its-misoits-misoBot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

UpdateChange
lockFileMaintenanceAll locks refreshed

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone America/Edmonton)

  • Branch creation
    • "before 5am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: dsv4f@https://litellm.jory.dev/v1 (openai) — primary route

Recommendation

Approve. This is a routine Renovate lock-file maintenance change: only package-lock.json is modified, package.json (dependency ranges, engines, overrides) is untouched, and every locked version bump is a patch or minor within an already-declared semver range. All CI gates — Lint, Typecheck, Tests, Build, Docker Build, npm audit — pass on the head commit, including a full production-image build on the exact node:24-bookworm-slim host platform.

Change-by-change findings

  • package-lock.json — Refresh bumps about 20 packages: esbuild 0.28.1 → 0.28.2 with all platform binaries in lockstep; rolldown 1.2.2 → 1.2.3 with @​oxc-project/types 0.142.0 → 0.143.0; pg 8.22.0 → 8.23.0 with pg-protocol 1.15.0 → 1.16.0 and @​types/pg 8.20.3 → 8.21.0; hono 4.13.0 → 4.13.1 and @​hono/node-server 2.0.12 → 2.1.0; vite 8.2.0 → 8.2.1; tsx 4.23.11 → 4.23.12; postcss 8.5.25 → 8.5.26 with nanoid 3.3.17 → 3.3.18; plus express-rate-limit, ip-address, readdirp, axe-core, browserslist/caniuse-lite and related data packages. No package.json manifest changes, so no new ranges, engines entries, or overrides are introduced.
  • Breaking-change check (must_check) — No bump crosses a major version. esbuild 0.28.2 release notes were fetched and describe only bug fixes (TypeScript import-alias tree-shaking, CSS minification of &, input-overwrite regression, top-level await codegen, logical-assignment minification, JS-API deadlock reference counting, duplicated target-engine handling, MP3 MIME detection) with no API/behavior-breaking changes. pg 8.23.0 and @​hono/node-server 2.1.0 are minor bumps within ranges the repo already declared; @​types/pg is a types-only minor.
  • Host-platform coupling — The bumped native/toolchain packages (esbuild, rolldown, vite, tsx) run on the Node platform pinned in the Dockerfile (node:24-bookworm-slim) and by engines.node >= 24. Engine ranges recorded in the lockfile for the new versions (esbuild >=18, rolldown ^20.19.0 || >=22.12.0, @​hono/node-server >=20, readdirp >=20.19.0, ip-address >=12) all include Node 24. The CI Docker Build check installed this exact lockfile and ran the production build on that base image successfully — an empirical compatibility check on the host platform.
  • Test-suite check (must_check) — CI Tests succeeded, alongside Lint, Typecheck, Build, Docker Build, and npm audit.

Sources

  • esbuild v0.28.2 release notes: https://github.com/evanw/esbuild/releases/tag/v0.28.2 (stable patch release, bug fixes only)
  • Repository files read: package.json (engines node >=24; dependency ranges unchanged; postcss/sharp overrides preserved) and Dockerfile (node:24-bookworm-slim base image)
  • CI status for the head commit: Lint, Typecheck, Tests, Build, Docker Build, npm audit, review — all success

Standards Compliance

  • The change touches only the lockfile; no source, Prisma schema, auth, environment-variable, Docker, or workflow conventions are affected.
  • The documented postcss and sharp override pins in package.json are left intact, consistent with the repository's advisory-remediation policy ('DO NOT remove without verifying the originating transitive deps have shipped patched versions').
  • The npm audit CI check passes, consistent with the repository's security posture.

Unknowns / Needs Verification

  • An official Node.js 24 support/compatibility matrix page could not be fetched within the tool budget, so no matrix URL is cited. This is mitigated by (a) engine ranges in the lockfile for every newly locked version, all of which include Node 24, and (b) the CI Docker Build that ran npm ci and built on the exact node:24-bookworm-slim host image with this lockfile. If a citable matrix entry is required before merge, confirm Node 24 support status first (e.g., https://nodejs.org/en/about/previous-releases).
  • The Renovate PR-body warning that some dependencies could not be looked up is standard Renovate boilerplate pointing to the dependency dashboard; it does not indicate lockfile inconsistency, since npm ci and the full build/test pipeline passed in CI.

@joryirving
joryirving merged commit dc1e758 into mainAug 10, 2026
8 checks passed
@joryirving
joryirving deleted the renovate/lock-file-maintenance branch August 10, 2026 12:28
@its-saffronits-saffronBot mentioned this pull request Aug 19, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@joryirving
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore(deps): lock file maintenance - #757

Merged
joryirving merged 1 commit into
mainfrom
renovate/lock-file-maintenance
Aug 10, 2026
Merged

chore(deps): lock file maintenance#757
joryirving merged 1 commit into
mainfrom
renovate/lock-file-maintenance

Conversation

@its-miso

@its-misoits-misoBot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

UpdateChange
lockFileMaintenanceAll locks refreshed

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: (in timezone America/Edmonton)

  • Branch creation
    • "before 5am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@its-saffronits-saffronBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: dsv4f@https://litellm.jory.dev/v1 (openai) — primary route

Recommendation

Approve. This is a routine Renovate lock-file maintenance change: only package-lock.json is modified, package.json (dependency ranges, engines, overrides) is untouched, and every locked version bump is a patch or minor within an already-declared semver range. All CI gates — Lint, Typecheck, Tests, Build, Docker Build, npm audit — pass on the head commit, including a full production-image build on the exact node:24-bookworm-slim host platform.

Change-by-change findings

  • package-lock.json — Refresh bumps about 20 packages: esbuild 0.28.1 → 0.28.2 with all platform binaries in lockstep; rolldown 1.2.2 → 1.2.3 with @​oxc-project/types 0.142.0 → 0.143.0; pg 8.22.0 → 8.23.0 with pg-protocol 1.15.0 → 1.16.0 and @​types/pg 8.20.3 → 8.21.0; hono 4.13.0 → 4.13.1 and @​hono/node-server 2.0.12 → 2.1.0; vite 8.2.0 → 8.2.1; tsx 4.23.11 → 4.23.12; postcss 8.5.25 → 8.5.26 with nanoid 3.3.17 → 3.3.18; plus express-rate-limit, ip-address, readdirp, axe-core, browserslist/caniuse-lite and related data packages. No package.json manifest changes, so no new ranges, engines entries, or overrides are introduced.
  • Breaking-change check (must_check) — No bump crosses a major version. esbuild 0.28.2 release notes were fetched and describe only bug fixes (TypeScript import-alias tree-shaking, CSS minification of &, input-overwrite regression, top-level await codegen, logical-assignment minification, JS-API deadlock reference counting, duplicated target-engine handling, MP3 MIME detection) with no API/behavior-breaking changes. pg 8.23.0 and @​hono/node-server 2.1.0 are minor bumps within ranges the repo already declared; @​types/pg is a types-only minor.
  • Host-platform coupling — The bumped native/toolchain packages (esbuild, rolldown, vite, tsx) run on the Node platform pinned in the Dockerfile (node:24-bookworm-slim) and by engines.node >= 24. Engine ranges recorded in the lockfile for the new versions (esbuild >=18, rolldown ^20.19.0 || >=22.12.0, @​hono/node-server >=20, readdirp >=20.19.0, ip-address >=12) all include Node 24. The CI Docker Build check installed this exact lockfile and ran the production build on that base image successfully — an empirical compatibility check on the host platform.
  • Test-suite check (must_check) — CI Tests succeeded, alongside Lint, Typecheck, Build, Docker Build, and npm audit.

Sources

  • esbuild v0.28.2 release notes: https://github.com/evanw/esbuild/releases/tag/v0.28.2 (stable patch release, bug fixes only)
  • Repository files read: package.json (engines node >=24; dependency ranges unchanged; postcss/sharp overrides preserved) and Dockerfile (node:24-bookworm-slim base image)
  • CI status for the head commit: Lint, Typecheck, Tests, Build, Docker Build, npm audit, review — all success

Standards Compliance

  • The change touches only the lockfile; no source, Prisma schema, auth, environment-variable, Docker, or workflow conventions are affected.
  • The documented postcss and sharp override pins in package.json are left intact, consistent with the repository's advisory-remediation policy ('DO NOT remove without verifying the originating transitive deps have shipped patched versions').
  • The npm audit CI check passes, consistent with the repository's security posture.

Unknowns / Needs Verification

  • An official Node.js 24 support/compatibility matrix page could not be fetched within the tool budget, so no matrix URL is cited. This is mitigated by (a) engine ranges in the lockfile for every newly locked version, all of which include Node 24, and (b) the CI Docker Build that ran npm ci and built on the exact node:24-bookworm-slim host image with this lockfile. If a citable matrix entry is required before merge, confirm Node 24 support status first (e.g., https://nodejs.org/en/about/previous-releases).
  • The Renovate PR-body warning that some dependencies could not be looked up is standard Renovate boilerplate pointing to the dependency dashboard; it does not indicate lockfile inconsistency, since npm ci and the full build/test pipeline passed in CI.

@joryirving
joryirving merged commit dc1e758 into mainAug 10, 2026
8 checks passed
@joryirving
joryirving deleted the renovate/lock-file-maintenance branch August 10, 2026 12:28
@its-saffronits-saffronBot mentioned this pull request Aug 19, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@joryirving