chore: upgrade react-email to ^6.1.4 - #1206

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-react-email-v6
May 15, 2026
Merged

chore: upgrade react-email to ^6.1.4#1206
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-react-email-v6

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented May 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades react-email from ^5.2.10 to ^6.1.4 in @sourcebot/web.
  • react-email 6 bundles the preview server (and dropped its Next.js dependency), so @react-email/preview-server is removed from devDependencies along with the now-obsolete @react-email/preview-server/next resolution override. Net yarn.lock impact: -302 MiB.
  • Root esbuild resolution bumped ^0.27.3 -> ^0.28.0 to match what react-email 6 ships its binary at (otherwise: Host version "0.28.0" does not match binary version "0.27.7"). The original esbuild resolution was a dedup convenience (chore: deduplicate esbuild via resolution #1118), not a CVE pin, and the tree stays deduped at a single version.
  • Bumped satellite package ranges: @react-email/components^1.0.2 -> ^1.0.12, @react-email/render^2.0.0 -> ^2.0.8.

Test plan

  • yarn install succeeds and yarn.lock shows a single esbuild@0.28.0 resolution
  • yarn workspace @sourcebot/web build compiles successfully against the new versions (the pre-existing OrgRole.GUEST typecheck failure on main is unrelated)
  • yarn dev:emails boots the preview server: React Email 6.1.4 ... Ready in 0.1s
  • No regression in transactional emails (magic link, invite user, join request submitted/approved) when sent from a deployed environment

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated core dependencies including react-email (v6.1.4), esbuild, and related packages to latest versions.

Review Change Stack

Bump `react-email` from `^5.2.10` to `^6.1.4` in the web package.
react-email 6 bundles the preview server into the main package and
drops its Next.js dependency, so `@react-email/preview-server` and
the `@react-email/preview-server/next` resolution override are no
longer needed. Net `yarn.lock` impact is -302 MiB.
Also bumped the `esbuild` root resolution from `^0.27.3` to `^0.28.0`
since react-email 6 requires the matching host/binary, and bumped
the satellite ranges on `@react-email/components` (`^1.0.2` -> `^1.0.12`)
and `@react-email/render` (`^2.0.0` -> `^2.0.8`).
Smoke tested with `yarn workspace @sourcebot/web build` (Next.js
compile passes) and `yarn dev:emails` (preview server boots clean
at 6.1.4).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented May 15, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 10112f4d-85e2-4146-8750-b20fabea3a40

📥 Commits

Reviewing files that changed from the base of the PR and between 34d7f77 and d1ce0ea.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (3)
  • CHANGELOG.md
  • package.json
  • packages/web/package.json

Walkthrough

This PR upgrades the react-email ecosystem from v5 to v6.1.4 across root and web packages, bumps esbuild and brace-expansion versions in the root devDependencies, removes @react-email/preview-server/next (now bundled with v6), and documents the upgrade in CHANGELOG.

Changes

React-email and Build Tool Dependency Upgrades

Layer / File(s)Summary
Root package and changelog documentation
CHANGELOG.md, package.json
CHANGELOG entry added documenting the react-email upgrade to ^6.1.4. Root package.json devDependencies updated: esbuild bumped from ^0.27.3 to ^0.28.0, brace-expansion versions updated, and @react-email/preview-server/next entry removed.
Web package react-email v6 ecosystem upgrade
packages/web/package.json
@react-email/components and @react-email/render upgraded to newer versions in dependencies. @react-email/ui added to devDependencies and react-email bumped from ^5.2.10 to ^6.1.4 to adopt v6 major release.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#1121: Main PR bumps react-email/@react-email/* to newer versions and removes the @react-email/preview-server/next dependency entry while retrieved PR adds Yarn resolutions for @react-email/preview-server/next, both modifying the same react-email-related package wiring.
  • sourcebot-dev/sourcebot#961: Both PRs adjust React Email-related dependencies in packages/web/package.json, with the main PR upgrading the broader react-email/@react-email/* set and the retrieved PR bumping @react-email/preview-server.

Suggested reviewers

  • msukkari
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: upgrading react-email to ^6.1.4, which is the primary objective evident from all three modified files (CHANGELOG.md, package.json, and packages/web/package.json).
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/upgrade-react-email-v6

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 2 commits May 15, 2026 16:23
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Removed the mention of dropping the separate @react-email/preview-server devDependency in the changelog.
@brendan-kellam
brendan-kellam merged commit 2de768d into mainMay 15, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/upgrade-react-email-v6 branch May 15, 2026 23:27
@github-actionsgithub-actionsBot mentioned this pull request May 15, 2026
@github-actions

github-actionsBot commented May 15, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2067
Resolved (non-standard)11
Unresolved0
Strong copyleft0
Weak copyleft39

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.0(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (11)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
@react-grab/cli0.1.29UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
@react-grab/mcp0.1.29UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm registry latest version metadata and GitHub repo livebook-dev/codemirror-lang-elixir LICENSE
element-source0.0.3UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2026 Aiden Bai)
lezer-elixir1.1.2UNKNOWNApache-2.0npm registry latest version metadata and GitHub repo livebook-dev/lezer-elixir LICENSE
map-stream0.1.0UNKNOWNMITnpm registry latest version metadata and GitHub repo dominictarr/map-stream LICENSE
memorystream0.3.1UNKNOWNMITGitHub repo JSBizon/node-memorystream LICENSE (SPDX MIT via GitHub license API)
pause-stream0.0.11["MIT","Apache2"](MIT OR Apache-2.0)License array in package metadata; dual-licensed MIT and Apache 2.0 per LICENSE file in GitHub repo dominictarr/pause-stream
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0LICENSE file in GitHub repo PostHog/posthog-js (Apache License, Version 2.0)
valid-url1.0.9UNKNOWNMITLICENSE file in GitHub repo ogt/valid-url (released under the MIT license)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore: upgrade react-email to ^6.1.4 - #1206

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-react-email-v6
May 15, 2026
Merged

chore: upgrade react-email to ^6.1.4#1206
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-react-email-v6

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented May 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades react-email from ^5.2.10 to ^6.1.4 in @sourcebot/web.
  • react-email 6 bundles the preview server (and dropped its Next.js dependency), so @react-email/preview-server is removed from devDependencies along with the now-obsolete @react-email/preview-server/next resolution override. Net yarn.lock impact: -302 MiB.
  • Root esbuild resolution bumped ^0.27.3 -> ^0.28.0 to match what react-email 6 ships its binary at (otherwise: Host version "0.28.0" does not match binary version "0.27.7"). The original esbuild resolution was a dedup convenience (chore: deduplicate esbuild via resolution #1118), not a CVE pin, and the tree stays deduped at a single version.
  • Bumped satellite package ranges: @react-email/components^1.0.2 -> ^1.0.12, @react-email/render^2.0.0 -> ^2.0.8.

Test plan

  • yarn install succeeds and yarn.lock shows a single esbuild@0.28.0 resolution
  • yarn workspace @sourcebot/web build compiles successfully against the new versions (the pre-existing OrgRole.GUEST typecheck failure on main is unrelated)
  • yarn dev:emails boots the preview server: React Email 6.1.4 ... Ready in 0.1s
  • No regression in transactional emails (magic link, invite user, join request submitted/approved) when sent from a deployed environment

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated core dependencies including react-email (v6.1.4), esbuild, and related packages to latest versions.

Review Change Stack

Bump `react-email` from `^5.2.10` to `^6.1.4` in the web package.
react-email 6 bundles the preview server into the main package and
drops its Next.js dependency, so `@react-email/preview-server` and
the `@react-email/preview-server/next` resolution override are no
longer needed. Net `yarn.lock` impact is -302 MiB.
Also bumped the `esbuild` root resolution from `^0.27.3` to `^0.28.0`
since react-email 6 requires the matching host/binary, and bumped
the satellite ranges on `@react-email/components` (`^1.0.2` -> `^1.0.12`)
and `@react-email/render` (`^2.0.0` -> `^2.0.8`).
Smoke tested with `yarn workspace @sourcebot/web build` (Next.js
compile passes) and `yarn dev:emails` (preview server boots clean
at 6.1.4).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented May 15, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 10112f4d-85e2-4146-8750-b20fabea3a40

📥 Commits

Reviewing files that changed from the base of the PR and between 34d7f77 and d1ce0ea.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (3)
  • CHANGELOG.md
  • package.json
  • packages/web/package.json

Walkthrough

This PR upgrades the react-email ecosystem from v5 to v6.1.4 across root and web packages, bumps esbuild and brace-expansion versions in the root devDependencies, removes @react-email/preview-server/next (now bundled with v6), and documents the upgrade in CHANGELOG.

Changes

React-email and Build Tool Dependency Upgrades

Layer / File(s)Summary
Root package and changelog documentation
CHANGELOG.md, package.json
CHANGELOG entry added documenting the react-email upgrade to ^6.1.4. Root package.json devDependencies updated: esbuild bumped from ^0.27.3 to ^0.28.0, brace-expansion versions updated, and @react-email/preview-server/next entry removed.
Web package react-email v6 ecosystem upgrade
packages/web/package.json
@react-email/components and @react-email/render upgraded to newer versions in dependencies. @react-email/ui added to devDependencies and react-email bumped from ^5.2.10 to ^6.1.4 to adopt v6 major release.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#1121: Main PR bumps react-email/@react-email/* to newer versions and removes the @react-email/preview-server/next dependency entry while retrieved PR adds Yarn resolutions for @react-email/preview-server/next, both modifying the same react-email-related package wiring.
  • sourcebot-dev/sourcebot#961: Both PRs adjust React Email-related dependencies in packages/web/package.json, with the main PR upgrading the broader react-email/@react-email/* set and the retrieved PR bumping @react-email/preview-server.

Suggested reviewers

  • msukkari
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: upgrading react-email to ^6.1.4, which is the primary objective evident from all three modified files (CHANGELOG.md, package.json, and packages/web/package.json).
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/upgrade-react-email-v6

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 2 commits May 15, 2026 16:23
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Removed the mention of dropping the separate @react-email/preview-server devDependency in the changelog.
@brendan-kellam
brendan-kellam merged commit 2de768d into mainMay 15, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/upgrade-react-email-v6 branch May 15, 2026 23:27
@github-actionsgithub-actionsBot mentioned this pull request May 15, 2026
@github-actions

github-actionsBot commented May 15, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2067
Resolved (non-standard)11
Unresolved0
Strong copyleft0
Weak copyleft39

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.0(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (11)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
@react-grab/cli0.1.29UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
@react-grab/mcp0.1.29UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm registry latest version metadata and GitHub repo livebook-dev/codemirror-lang-elixir LICENSE
element-source0.0.3UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2026 Aiden Bai)
lezer-elixir1.1.2UNKNOWNApache-2.0npm registry latest version metadata and GitHub repo livebook-dev/lezer-elixir LICENSE
map-stream0.1.0UNKNOWNMITnpm registry latest version metadata and GitHub repo dominictarr/map-stream LICENSE
memorystream0.3.1UNKNOWNMITGitHub repo JSBizon/node-memorystream LICENSE (SPDX MIT via GitHub license API)
pause-stream0.0.11["MIT","Apache2"](MIT OR Apache-2.0)License array in package metadata; dual-licensed MIT and Apache 2.0 per LICENSE file in GitHub repo dominictarr/pause-stream
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0LICENSE file in GitHub repo PostHog/posthog-js (Apache License, Version 2.0)
valid-url1.0.9UNKNOWNMITLICENSE file in GitHub repo ogt/valid-url (released under the MIT license)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: upgrade react-email to ^6.1.4 - #1206

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-react-email-v6
May 15, 2026
Merged

chore: upgrade react-email to ^6.1.4#1206
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-react-email-v6

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented May 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades react-email from ^5.2.10 to ^6.1.4 in @sourcebot/web.
  • react-email 6 bundles the preview server (and dropped its Next.js dependency), so @react-email/preview-server is removed from devDependencies along with the now-obsolete @react-email/preview-server/next resolution override. Net yarn.lock impact: -302 MiB.
  • Root esbuild resolution bumped ^0.27.3 -> ^0.28.0 to match what react-email 6 ships its binary at (otherwise: Host version "0.28.0" does not match binary version "0.27.7"). The original esbuild resolution was a dedup convenience (chore: deduplicate esbuild via resolution #1118), not a CVE pin, and the tree stays deduped at a single version.
  • Bumped satellite package ranges: @react-email/components^1.0.2 -> ^1.0.12, @react-email/render^2.0.0 -> ^2.0.8.

Test plan

  • yarn install succeeds and yarn.lock shows a single esbuild@0.28.0 resolution
  • yarn workspace @sourcebot/web build compiles successfully against the new versions (the pre-existing OrgRole.GUEST typecheck failure on main is unrelated)
  • yarn dev:emails boots the preview server: React Email 6.1.4 ... Ready in 0.1s
  • No regression in transactional emails (magic link, invite user, join request submitted/approved) when sent from a deployed environment

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated core dependencies including react-email (v6.1.4), esbuild, and related packages to latest versions.

Review Change Stack

Bump `react-email` from `^5.2.10` to `^6.1.4` in the web package.
react-email 6 bundles the preview server into the main package and
drops its Next.js dependency, so `@react-email/preview-server` and
the `@react-email/preview-server/next` resolution override are no
longer needed. Net `yarn.lock` impact is -302 MiB.
Also bumped the `esbuild` root resolution from `^0.27.3` to `^0.28.0`
since react-email 6 requires the matching host/binary, and bumped
the satellite ranges on `@react-email/components` (`^1.0.2` -> `^1.0.12`)
and `@react-email/render` (`^2.0.0` -> `^2.0.8`).
Smoke tested with `yarn workspace @sourcebot/web build` (Next.js
compile passes) and `yarn dev:emails` (preview server boots clean
at 6.1.4).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented May 15, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 10112f4d-85e2-4146-8750-b20fabea3a40

📥 Commits

Reviewing files that changed from the base of the PR and between 34d7f77 and d1ce0ea.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (3)
  • CHANGELOG.md
  • package.json
  • packages/web/package.json

Walkthrough

This PR upgrades the react-email ecosystem from v5 to v6.1.4 across root and web packages, bumps esbuild and brace-expansion versions in the root devDependencies, removes @react-email/preview-server/next (now bundled with v6), and documents the upgrade in CHANGELOG.

Changes

React-email and Build Tool Dependency Upgrades

Layer / File(s)Summary
Root package and changelog documentation
CHANGELOG.md, package.json
CHANGELOG entry added documenting the react-email upgrade to ^6.1.4. Root package.json devDependencies updated: esbuild bumped from ^0.27.3 to ^0.28.0, brace-expansion versions updated, and @react-email/preview-server/next entry removed.
Web package react-email v6 ecosystem upgrade
packages/web/package.json
@react-email/components and @react-email/render upgraded to newer versions in dependencies. @react-email/ui added to devDependencies and react-email bumped from ^5.2.10 to ^6.1.4 to adopt v6 major release.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#1121: Main PR bumps react-email/@react-email/* to newer versions and removes the @react-email/preview-server/next dependency entry while retrieved PR adds Yarn resolutions for @react-email/preview-server/next, both modifying the same react-email-related package wiring.
  • sourcebot-dev/sourcebot#961: Both PRs adjust React Email-related dependencies in packages/web/package.json, with the main PR upgrading the broader react-email/@react-email/* set and the retrieved PR bumping @react-email/preview-server.

Suggested reviewers

  • msukkari
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: upgrading react-email to ^6.1.4, which is the primary objective evident from all three modified files (CHANGELOG.md, package.json, and packages/web/package.json).
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/upgrade-react-email-v6

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 2 commits May 15, 2026 16:23
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Removed the mention of dropping the separate @react-email/preview-server devDependency in the changelog.
@brendan-kellam
brendan-kellam merged commit 2de768d into mainMay 15, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/upgrade-react-email-v6 branch May 15, 2026 23:27
@github-actionsgithub-actionsBot mentioned this pull request May 15, 2026
@github-actions

github-actionsBot commented May 15, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2067
Resolved (non-standard)11
Unresolved0
Strong copyleft0
Weak copyleft39

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.0(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (11)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
@react-grab/cli0.1.29UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
@react-grab/mcp0.1.29UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm registry latest version metadata and GitHub repo livebook-dev/codemirror-lang-elixir LICENSE
element-source0.0.3UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2026 Aiden Bai)
lezer-elixir1.1.2UNKNOWNApache-2.0npm registry latest version metadata and GitHub repo livebook-dev/lezer-elixir LICENSE
map-stream0.1.0UNKNOWNMITnpm registry latest version metadata and GitHub repo dominictarr/map-stream LICENSE
memorystream0.3.1UNKNOWNMITGitHub repo JSBizon/node-memorystream LICENSE (SPDX MIT via GitHub license API)
pause-stream0.0.11["MIT","Apache2"](MIT OR Apache-2.0)License array in package metadata; dual-licensed MIT and Apache 2.0 per LICENSE file in GitHub repo dominictarr/pause-stream
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0LICENSE file in GitHub repo PostHog/posthog-js (Apache License, Version 2.0)
valid-url1.0.9UNKNOWNMITLICENSE file in GitHub repo ogt/valid-url (released under the MIT license)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: upgrade react-email to ^6.1.4 - #1206

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-react-email-v6
May 15, 2026
Merged

chore: upgrade react-email to ^6.1.4#1206
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-react-email-v6

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented May 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades react-email from ^5.2.10 to ^6.1.4 in @sourcebot/web.
  • react-email 6 bundles the preview server (and dropped its Next.js dependency), so @react-email/preview-server is removed from devDependencies along with the now-obsolete @react-email/preview-server/next resolution override. Net yarn.lock impact: -302 MiB.
  • Root esbuild resolution bumped ^0.27.3 -> ^0.28.0 to match what react-email 6 ships its binary at (otherwise: Host version "0.28.0" does not match binary version "0.27.7"). The original esbuild resolution was a dedup convenience (chore: deduplicate esbuild via resolution #1118), not a CVE pin, and the tree stays deduped at a single version.
  • Bumped satellite package ranges: @react-email/components^1.0.2 -> ^1.0.12, @react-email/render^2.0.0 -> ^2.0.8.

Test plan

  • yarn install succeeds and yarn.lock shows a single esbuild@0.28.0 resolution
  • yarn workspace @sourcebot/web build compiles successfully against the new versions (the pre-existing OrgRole.GUEST typecheck failure on main is unrelated)
  • yarn dev:emails boots the preview server: React Email 6.1.4 ... Ready in 0.1s
  • No regression in transactional emails (magic link, invite user, join request submitted/approved) when sent from a deployed environment

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated core dependencies including react-email (v6.1.4), esbuild, and related packages to latest versions.

Review Change Stack

Bump `react-email` from `^5.2.10` to `^6.1.4` in the web package.
react-email 6 bundles the preview server into the main package and
drops its Next.js dependency, so `@react-email/preview-server` and
the `@react-email/preview-server/next` resolution override are no
longer needed. Net `yarn.lock` impact is -302 MiB.
Also bumped the `esbuild` root resolution from `^0.27.3` to `^0.28.0`
since react-email 6 requires the matching host/binary, and bumped
the satellite ranges on `@react-email/components` (`^1.0.2` -> `^1.0.12`)
and `@react-email/render` (`^2.0.0` -> `^2.0.8`).
Smoke tested with `yarn workspace @sourcebot/web build` (Next.js
compile passes) and `yarn dev:emails` (preview server boots clean
at 6.1.4).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented May 15, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 10112f4d-85e2-4146-8750-b20fabea3a40

📥 Commits

Reviewing files that changed from the base of the PR and between 34d7f77 and d1ce0ea.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (3)
  • CHANGELOG.md
  • package.json
  • packages/web/package.json

Walkthrough

This PR upgrades the react-email ecosystem from v5 to v6.1.4 across root and web packages, bumps esbuild and brace-expansion versions in the root devDependencies, removes @react-email/preview-server/next (now bundled with v6), and documents the upgrade in CHANGELOG.

Changes

React-email and Build Tool Dependency Upgrades

Layer / File(s)Summary
Root package and changelog documentation
CHANGELOG.md, package.json
CHANGELOG entry added documenting the react-email upgrade to ^6.1.4. Root package.json devDependencies updated: esbuild bumped from ^0.27.3 to ^0.28.0, brace-expansion versions updated, and @react-email/preview-server/next entry removed.
Web package react-email v6 ecosystem upgrade
packages/web/package.json
@react-email/components and @react-email/render upgraded to newer versions in dependencies. @react-email/ui added to devDependencies and react-email bumped from ^5.2.10 to ^6.1.4 to adopt v6 major release.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#1121: Main PR bumps react-email/@react-email/* to newer versions and removes the @react-email/preview-server/next dependency entry while retrieved PR adds Yarn resolutions for @react-email/preview-server/next, both modifying the same react-email-related package wiring.
  • sourcebot-dev/sourcebot#961: Both PRs adjust React Email-related dependencies in packages/web/package.json, with the main PR upgrading the broader react-email/@react-email/* set and the retrieved PR bumping @react-email/preview-server.

Suggested reviewers

  • msukkari
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: upgrading react-email to ^6.1.4, which is the primary objective evident from all three modified files (CHANGELOG.md, package.json, and packages/web/package.json).
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/upgrade-react-email-v6

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 2 commits May 15, 2026 16:23
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Removed the mention of dropping the separate @react-email/preview-server devDependency in the changelog.
@brendan-kellam
brendan-kellam merged commit 2de768d into mainMay 15, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/upgrade-react-email-v6 branch May 15, 2026 23:27
@github-actionsgithub-actionsBot mentioned this pull request May 15, 2026
@github-actions

github-actionsBot commented May 15, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2067
Resolved (non-standard)11
Unresolved0
Strong copyleft0
Weak copyleft39

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.0(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (11)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
@react-grab/cli0.1.29UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
@react-grab/mcp0.1.29UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm registry latest version metadata and GitHub repo livebook-dev/codemirror-lang-elixir LICENSE
element-source0.0.3UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2026 Aiden Bai)
lezer-elixir1.1.2UNKNOWNApache-2.0npm registry latest version metadata and GitHub repo livebook-dev/lezer-elixir LICENSE
map-stream0.1.0UNKNOWNMITnpm registry latest version metadata and GitHub repo dominictarr/map-stream LICENSE
memorystream0.3.1UNKNOWNMITGitHub repo JSBizon/node-memorystream LICENSE (SPDX MIT via GitHub license API)
pause-stream0.0.11["MIT","Apache2"](MIT OR Apache-2.0)License array in package metadata; dual-licensed MIT and Apache 2.0 per LICENSE file in GitHub repo dominictarr/pause-stream
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0LICENSE file in GitHub repo PostHog/posthog-js (Apache License, Version 2.0)
valid-url1.0.9UNKNOWNMITLICENSE file in GitHub repo ogt/valid-url (released under the MIT license)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore: upgrade react-email to ^6.1.4 - #1206

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-react-email-v6
May 15, 2026
Merged

chore: upgrade react-email to ^6.1.4#1206
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-react-email-v6

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented May 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades react-email from ^5.2.10 to ^6.1.4 in @sourcebot/web.
  • react-email 6 bundles the preview server (and dropped its Next.js dependency), so @react-email/preview-server is removed from devDependencies along with the now-obsolete @react-email/preview-server/next resolution override. Net yarn.lock impact: -302 MiB.
  • Root esbuild resolution bumped ^0.27.3 -> ^0.28.0 to match what react-email 6 ships its binary at (otherwise: Host version "0.28.0" does not match binary version "0.27.7"). The original esbuild resolution was a dedup convenience (chore: deduplicate esbuild via resolution #1118), not a CVE pin, and the tree stays deduped at a single version.
  • Bumped satellite package ranges: @react-email/components^1.0.2 -> ^1.0.12, @react-email/render^2.0.0 -> ^2.0.8.

Test plan

  • yarn install succeeds and yarn.lock shows a single esbuild@0.28.0 resolution
  • yarn workspace @sourcebot/web build compiles successfully against the new versions (the pre-existing OrgRole.GUEST typecheck failure on main is unrelated)
  • yarn dev:emails boots the preview server: React Email 6.1.4 ... Ready in 0.1s
  • No regression in transactional emails (magic link, invite user, join request submitted/approved) when sent from a deployed environment

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated core dependencies including react-email (v6.1.4), esbuild, and related packages to latest versions.

Review Change Stack

Bump `react-email` from `^5.2.10` to `^6.1.4` in the web package.
react-email 6 bundles the preview server into the main package and
drops its Next.js dependency, so `@react-email/preview-server` and
the `@react-email/preview-server/next` resolution override are no
longer needed. Net `yarn.lock` impact is -302 MiB.
Also bumped the `esbuild` root resolution from `^0.27.3` to `^0.28.0`
since react-email 6 requires the matching host/binary, and bumped
the satellite ranges on `@react-email/components` (`^1.0.2` -> `^1.0.12`)
and `@react-email/render` (`^2.0.0` -> `^2.0.8`).
Smoke tested with `yarn workspace @sourcebot/web build` (Next.js
compile passes) and `yarn dev:emails` (preview server boots clean
at 6.1.4).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented May 15, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 10112f4d-85e2-4146-8750-b20fabea3a40

📥 Commits

Reviewing files that changed from the base of the PR and between 34d7f77 and d1ce0ea.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (3)
  • CHANGELOG.md
  • package.json
  • packages/web/package.json

Walkthrough

This PR upgrades the react-email ecosystem from v5 to v6.1.4 across root and web packages, bumps esbuild and brace-expansion versions in the root devDependencies, removes @react-email/preview-server/next (now bundled with v6), and documents the upgrade in CHANGELOG.

Changes

React-email and Build Tool Dependency Upgrades

Layer / File(s)Summary
Root package and changelog documentation
CHANGELOG.md, package.json
CHANGELOG entry added documenting the react-email upgrade to ^6.1.4. Root package.json devDependencies updated: esbuild bumped from ^0.27.3 to ^0.28.0, brace-expansion versions updated, and @react-email/preview-server/next entry removed.
Web package react-email v6 ecosystem upgrade
packages/web/package.json
@react-email/components and @react-email/render upgraded to newer versions in dependencies. @react-email/ui added to devDependencies and react-email bumped from ^5.2.10 to ^6.1.4 to adopt v6 major release.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#1121: Main PR bumps react-email/@react-email/* to newer versions and removes the @react-email/preview-server/next dependency entry while retrieved PR adds Yarn resolutions for @react-email/preview-server/next, both modifying the same react-email-related package wiring.
  • sourcebot-dev/sourcebot#961: Both PRs adjust React Email-related dependencies in packages/web/package.json, with the main PR upgrading the broader react-email/@react-email/* set and the retrieved PR bumping @react-email/preview-server.

Suggested reviewers

  • msukkari
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: upgrading react-email to ^6.1.4, which is the primary objective evident from all three modified files (CHANGELOG.md, package.json, and packages/web/package.json).
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/upgrade-react-email-v6

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 2 commits May 15, 2026 16:23
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Removed the mention of dropping the separate @react-email/preview-server devDependency in the changelog.
@brendan-kellam
brendan-kellam merged commit 2de768d into mainMay 15, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/upgrade-react-email-v6 branch May 15, 2026 23:27
@github-actionsgithub-actionsBot mentioned this pull request May 15, 2026
@github-actions

github-actionsBot commented May 15, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2067
Resolved (non-standard)11
Unresolved0
Strong copyleft0
Weak copyleft39

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.0(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (11)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
@react-grab/cli0.1.29UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
@react-grab/mcp0.1.29UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm registry latest version metadata and GitHub repo livebook-dev/codemirror-lang-elixir LICENSE
element-source0.0.3UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2026 Aiden Bai)
lezer-elixir1.1.2UNKNOWNApache-2.0npm registry latest version metadata and GitHub repo livebook-dev/lezer-elixir LICENSE
map-stream0.1.0UNKNOWNMITnpm registry latest version metadata and GitHub repo dominictarr/map-stream LICENSE
memorystream0.3.1UNKNOWNMITGitHub repo JSBizon/node-memorystream LICENSE (SPDX MIT via GitHub license API)
pause-stream0.0.11["MIT","Apache2"](MIT OR Apache-2.0)License array in package metadata; dual-licensed MIT and Apache 2.0 per LICENSE file in GitHub repo dominictarr/pause-stream
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0LICENSE file in GitHub repo PostHog/posthog-js (Apache License, Version 2.0)
valid-url1.0.9UNKNOWNMITLICENSE file in GitHub repo ogt/valid-url (released under the MIT license)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: upgrade react-email to ^6.1.4 - #1206

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-react-email-v6
May 15, 2026
Merged

chore: upgrade react-email to ^6.1.4#1206
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-react-email-v6

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented May 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades react-email from ^5.2.10 to ^6.1.4 in @sourcebot/web.
  • react-email 6 bundles the preview server (and dropped its Next.js dependency), so @react-email/preview-server is removed from devDependencies along with the now-obsolete @react-email/preview-server/next resolution override. Net yarn.lock impact: -302 MiB.
  • Root esbuild resolution bumped ^0.27.3 -> ^0.28.0 to match what react-email 6 ships its binary at (otherwise: Host version "0.28.0" does not match binary version "0.27.7"). The original esbuild resolution was a dedup convenience (chore: deduplicate esbuild via resolution #1118), not a CVE pin, and the tree stays deduped at a single version.
  • Bumped satellite package ranges: @react-email/components^1.0.2 -> ^1.0.12, @react-email/render^2.0.0 -> ^2.0.8.

Test plan

  • yarn install succeeds and yarn.lock shows a single esbuild@0.28.0 resolution
  • yarn workspace @sourcebot/web build compiles successfully against the new versions (the pre-existing OrgRole.GUEST typecheck failure on main is unrelated)
  • yarn dev:emails boots the preview server: React Email 6.1.4 ... Ready in 0.1s
  • No regression in transactional emails (magic link, invite user, join request submitted/approved) when sent from a deployed environment

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated core dependencies including react-email (v6.1.4), esbuild, and related packages to latest versions.

Review Change Stack

Bump `react-email` from `^5.2.10` to `^6.1.4` in the web package.
react-email 6 bundles the preview server into the main package and
drops its Next.js dependency, so `@react-email/preview-server` and
the `@react-email/preview-server/next` resolution override are no
longer needed. Net `yarn.lock` impact is -302 MiB.
Also bumped the `esbuild` root resolution from `^0.27.3` to `^0.28.0`
since react-email 6 requires the matching host/binary, and bumped
the satellite ranges on `@react-email/components` (`^1.0.2` -> `^1.0.12`)
and `@react-email/render` (`^2.0.0` -> `^2.0.8`).
Smoke tested with `yarn workspace @sourcebot/web build` (Next.js
compile passes) and `yarn dev:emails` (preview server boots clean
at 6.1.4).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented May 15, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 10112f4d-85e2-4146-8750-b20fabea3a40

📥 Commits

Reviewing files that changed from the base of the PR and between 34d7f77 and d1ce0ea.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (3)
  • CHANGELOG.md
  • package.json
  • packages/web/package.json

Walkthrough

This PR upgrades the react-email ecosystem from v5 to v6.1.4 across root and web packages, bumps esbuild and brace-expansion versions in the root devDependencies, removes @react-email/preview-server/next (now bundled with v6), and documents the upgrade in CHANGELOG.

Changes

React-email and Build Tool Dependency Upgrades

Layer / File(s)Summary
Root package and changelog documentation
CHANGELOG.md, package.json
CHANGELOG entry added documenting the react-email upgrade to ^6.1.4. Root package.json devDependencies updated: esbuild bumped from ^0.27.3 to ^0.28.0, brace-expansion versions updated, and @react-email/preview-server/next entry removed.
Web package react-email v6 ecosystem upgrade
packages/web/package.json
@react-email/components and @react-email/render upgraded to newer versions in dependencies. @react-email/ui added to devDependencies and react-email bumped from ^5.2.10 to ^6.1.4 to adopt v6 major release.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#1121: Main PR bumps react-email/@react-email/* to newer versions and removes the @react-email/preview-server/next dependency entry while retrieved PR adds Yarn resolutions for @react-email/preview-server/next, both modifying the same react-email-related package wiring.
  • sourcebot-dev/sourcebot#961: Both PRs adjust React Email-related dependencies in packages/web/package.json, with the main PR upgrading the broader react-email/@react-email/* set and the retrieved PR bumping @react-email/preview-server.

Suggested reviewers

  • msukkari
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: upgrading react-email to ^6.1.4, which is the primary objective evident from all three modified files (CHANGELOG.md, package.json, and packages/web/package.json).
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/upgrade-react-email-v6

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 2 commits May 15, 2026 16:23
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Removed the mention of dropping the separate @react-email/preview-server devDependency in the changelog.
@brendan-kellam
brendan-kellam merged commit 2de768d into mainMay 15, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/upgrade-react-email-v6 branch May 15, 2026 23:27
@github-actionsgithub-actionsBot mentioned this pull request May 15, 2026
@github-actions

github-actionsBot commented May 15, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2067
Resolved (non-standard)11
Unresolved0
Strong copyleft0
Weak copyleft39

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.0(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (11)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
@react-grab/cli0.1.29UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
@react-grab/mcp0.1.29UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm registry latest version metadata and GitHub repo livebook-dev/codemirror-lang-elixir LICENSE
element-source0.0.3UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2026 Aiden Bai)
lezer-elixir1.1.2UNKNOWNApache-2.0npm registry latest version metadata and GitHub repo livebook-dev/lezer-elixir LICENSE
map-stream0.1.0UNKNOWNMITnpm registry latest version metadata and GitHub repo dominictarr/map-stream LICENSE
memorystream0.3.1UNKNOWNMITGitHub repo JSBizon/node-memorystream LICENSE (SPDX MIT via GitHub license API)
pause-stream0.0.11["MIT","Apache2"](MIT OR Apache-2.0)License array in package metadata; dual-licensed MIT and Apache 2.0 per LICENSE file in GitHub repo dominictarr/pause-stream
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0LICENSE file in GitHub repo PostHog/posthog-js (Apache License, Version 2.0)
valid-url1.0.9UNKNOWNMITLICENSE file in GitHub repo ogt/valid-url (released under the MIT license)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore: upgrade react-email to ^6.1.4 - #1206

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-react-email-v6
May 15, 2026
Merged

chore: upgrade react-email to ^6.1.4#1206
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-react-email-v6

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented May 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades react-email from ^5.2.10 to ^6.1.4 in @sourcebot/web.
  • react-email 6 bundles the preview server (and dropped its Next.js dependency), so @react-email/preview-server is removed from devDependencies along with the now-obsolete @react-email/preview-server/next resolution override. Net yarn.lock impact: -302 MiB.
  • Root esbuild resolution bumped ^0.27.3 -> ^0.28.0 to match what react-email 6 ships its binary at (otherwise: Host version "0.28.0" does not match binary version "0.27.7"). The original esbuild resolution was a dedup convenience (chore: deduplicate esbuild via resolution #1118), not a CVE pin, and the tree stays deduped at a single version.
  • Bumped satellite package ranges: @react-email/components^1.0.2 -> ^1.0.12, @react-email/render^2.0.0 -> ^2.0.8.

Test plan

  • yarn install succeeds and yarn.lock shows a single esbuild@0.28.0 resolution
  • yarn workspace @sourcebot/web build compiles successfully against the new versions (the pre-existing OrgRole.GUEST typecheck failure on main is unrelated)
  • yarn dev:emails boots the preview server: React Email 6.1.4 ... Ready in 0.1s
  • No regression in transactional emails (magic link, invite user, join request submitted/approved) when sent from a deployed environment

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated core dependencies including react-email (v6.1.4), esbuild, and related packages to latest versions.

Review Change Stack

Bump `react-email` from `^5.2.10` to `^6.1.4` in the web package.
react-email 6 bundles the preview server into the main package and
drops its Next.js dependency, so `@react-email/preview-server` and
the `@react-email/preview-server/next` resolution override are no
longer needed. Net `yarn.lock` impact is -302 MiB.
Also bumped the `esbuild` root resolution from `^0.27.3` to `^0.28.0`
since react-email 6 requires the matching host/binary, and bumped
the satellite ranges on `@react-email/components` (`^1.0.2` -> `^1.0.12`)
and `@react-email/render` (`^2.0.0` -> `^2.0.8`).
Smoke tested with `yarn workspace @sourcebot/web build` (Next.js
compile passes) and `yarn dev:emails` (preview server boots clean
at 6.1.4).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented May 15, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 10112f4d-85e2-4146-8750-b20fabea3a40

📥 Commits

Reviewing files that changed from the base of the PR and between 34d7f77 and d1ce0ea.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (3)
  • CHANGELOG.md
  • package.json
  • packages/web/package.json

Walkthrough

This PR upgrades the react-email ecosystem from v5 to v6.1.4 across root and web packages, bumps esbuild and brace-expansion versions in the root devDependencies, removes @react-email/preview-server/next (now bundled with v6), and documents the upgrade in CHANGELOG.

Changes

React-email and Build Tool Dependency Upgrades

Layer / File(s)Summary
Root package and changelog documentation
CHANGELOG.md, package.json
CHANGELOG entry added documenting the react-email upgrade to ^6.1.4. Root package.json devDependencies updated: esbuild bumped from ^0.27.3 to ^0.28.0, brace-expansion versions updated, and @react-email/preview-server/next entry removed.
Web package react-email v6 ecosystem upgrade
packages/web/package.json
@react-email/components and @react-email/render upgraded to newer versions in dependencies. @react-email/ui added to devDependencies and react-email bumped from ^5.2.10 to ^6.1.4 to adopt v6 major release.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#1121: Main PR bumps react-email/@react-email/* to newer versions and removes the @react-email/preview-server/next dependency entry while retrieved PR adds Yarn resolutions for @react-email/preview-server/next, both modifying the same react-email-related package wiring.
  • sourcebot-dev/sourcebot#961: Both PRs adjust React Email-related dependencies in packages/web/package.json, with the main PR upgrading the broader react-email/@react-email/* set and the retrieved PR bumping @react-email/preview-server.

Suggested reviewers

  • msukkari
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: upgrading react-email to ^6.1.4, which is the primary objective evident from all three modified files (CHANGELOG.md, package.json, and packages/web/package.json).
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/upgrade-react-email-v6

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 2 commits May 15, 2026 16:23
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Removed the mention of dropping the separate @react-email/preview-server devDependency in the changelog.
@brendan-kellam
brendan-kellam merged commit 2de768d into mainMay 15, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/upgrade-react-email-v6 branch May 15, 2026 23:27
@github-actionsgithub-actionsBot mentioned this pull request May 15, 2026
@github-actions

github-actionsBot commented May 15, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2067
Resolved (non-standard)11
Unresolved0
Strong copyleft0
Weak copyleft39

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.0(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (11)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
@react-grab/cli0.1.29UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
@react-grab/mcp0.1.29UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm registry latest version metadata and GitHub repo livebook-dev/codemirror-lang-elixir LICENSE
element-source0.0.3UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2026 Aiden Bai)
lezer-elixir1.1.2UNKNOWNApache-2.0npm registry latest version metadata and GitHub repo livebook-dev/lezer-elixir LICENSE
map-stream0.1.0UNKNOWNMITnpm registry latest version metadata and GitHub repo dominictarr/map-stream LICENSE
memorystream0.3.1UNKNOWNMITGitHub repo JSBizon/node-memorystream LICENSE (SPDX MIT via GitHub license API)
pause-stream0.0.11["MIT","Apache2"](MIT OR Apache-2.0)License array in package metadata; dual-licensed MIT and Apache 2.0 per LICENSE file in GitHub repo dominictarr/pause-stream
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0LICENSE file in GitHub repo PostHog/posthog-js (Apache License, Version 2.0)
valid-url1.0.9UNKNOWNMITLICENSE file in GitHub repo ogt/valid-url (released under the MIT license)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore: upgrade react-email to ^6.1.4 - #1206

Merged
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-react-email-v6
May 15, 2026
Merged

chore: upgrade react-email to ^6.1.4#1206
brendan-kellam merged 3 commits into
mainfrom
brendan/upgrade-react-email-v6

Conversation

@brendan-kellam

@brendan-kellambrendan-kellam commented May 15, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Upgrades react-email from ^5.2.10 to ^6.1.4 in @sourcebot/web.
  • react-email 6 bundles the preview server (and dropped its Next.js dependency), so @react-email/preview-server is removed from devDependencies along with the now-obsolete @react-email/preview-server/next resolution override. Net yarn.lock impact: -302 MiB.
  • Root esbuild resolution bumped ^0.27.3 -> ^0.28.0 to match what react-email 6 ships its binary at (otherwise: Host version "0.28.0" does not match binary version "0.27.7"). The original esbuild resolution was a dedup convenience (chore: deduplicate esbuild via resolution #1118), not a CVE pin, and the tree stays deduped at a single version.
  • Bumped satellite package ranges: @react-email/components^1.0.2 -> ^1.0.12, @react-email/render^2.0.0 -> ^2.0.8.

Test plan

  • yarn install succeeds and yarn.lock shows a single esbuild@0.28.0 resolution
  • yarn workspace @sourcebot/web build compiles successfully against the new versions (the pre-existing OrgRole.GUEST typecheck failure on main is unrelated)
  • yarn dev:emails boots the preview server: React Email 6.1.4 ... Ready in 0.1s
  • No regression in transactional emails (magic link, invite user, join request submitted/approved) when sent from a deployed environment

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated core dependencies including react-email (v6.1.4), esbuild, and related packages to latest versions.

Review Change Stack

Bump `react-email` from `^5.2.10` to `^6.1.4` in the web package.
react-email 6 bundles the preview server into the main package and
drops its Next.js dependency, so `@react-email/preview-server` and
the `@react-email/preview-server/next` resolution override are no
longer needed. Net `yarn.lock` impact is -302 MiB.
Also bumped the `esbuild` root resolution from `^0.27.3` to `^0.28.0`
since react-email 6 requires the matching host/binary, and bumped
the satellite ranges on `@react-email/components` (`^1.0.2` -> `^1.0.12`)
and `@react-email/render` (`^2.0.0` -> `^2.0.8`).
Smoke tested with `yarn workspace @sourcebot/web build` (Next.js
compile passes) and `yarn dev:emails` (preview server boots clean
at 6.1.4).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@coderabbitai

coderabbitaiBot commented May 15, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 10112f4d-85e2-4146-8750-b20fabea3a40

📥 Commits

Reviewing files that changed from the base of the PR and between 34d7f77 and d1ce0ea.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (3)
  • CHANGELOG.md
  • package.json
  • packages/web/package.json

Walkthrough

This PR upgrades the react-email ecosystem from v5 to v6.1.4 across root and web packages, bumps esbuild and brace-expansion versions in the root devDependencies, removes @react-email/preview-server/next (now bundled with v6), and documents the upgrade in CHANGELOG.

Changes

React-email and Build Tool Dependency Upgrades

Layer / File(s)Summary
Root package and changelog documentation
CHANGELOG.md, package.json
CHANGELOG entry added documenting the react-email upgrade to ^6.1.4. Root package.json devDependencies updated: esbuild bumped from ^0.27.3 to ^0.28.0, brace-expansion versions updated, and @react-email/preview-server/next entry removed.
Web package react-email v6 ecosystem upgrade
packages/web/package.json
@react-email/components and @react-email/render upgraded to newer versions in dependencies. @react-email/ui added to devDependencies and react-email bumped from ^5.2.10 to ^6.1.4 to adopt v6 major release.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • sourcebot-dev/sourcebot#1121: Main PR bumps react-email/@react-email/* to newer versions and removes the @react-email/preview-server/next dependency entry while retrieved PR adds Yarn resolutions for @react-email/preview-server/next, both modifying the same react-email-related package wiring.
  • sourcebot-dev/sourcebot#961: Both PRs adjust React Email-related dependencies in packages/web/package.json, with the main PR upgrading the broader react-email/@react-email/* set and the retrieved PR bumping @react-email/preview-server.

Suggested reviewers

  • msukkari
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title accurately describes the main change: upgrading react-email to ^6.1.4, which is the primary objective evident from all three modified files (CHANGELOG.md, package.json, and packages/web/package.json).
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch brendan/upgrade-react-email-v6

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

brendan-kellamand others added 2 commits May 15, 2026 16:23
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Removed the mention of dropping the separate @react-email/preview-server devDependency in the changelog.
@brendan-kellam
brendan-kellam merged commit 2de768d into mainMay 15, 2026
9 checks passed
@brendan-kellam
brendan-kellam deleted the brendan/upgrade-react-email-v6 branch May 15, 2026 23:27
@github-actionsgithub-actionsBot mentioned this pull request May 15, 2026
@github-actions

github-actionsBot commented May 15, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️Status: PASS

MetricCount
Total packages2067
Resolved (non-standard)11
Unresolved0
Strong copyleft0
Weak copyleft39

Weak Copyleft Packages (informational)

PackageVersionLicense
@img/sharp-libvips-darwin-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-darwin-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.0.5LGPL-3.0-or-later
@img/sharp-libvips-linux-arm1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x1.2.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linux-x641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm641.2.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.0.4LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x641.2.4LGPL-3.0-or-later
@img/sharp-wasm320.33.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm320.34.5Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm640.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia320.34.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.33.5Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x640.34.5Apache-2.0 AND LGPL-3.0-or-later
axe-core4.10.3MPL-2.0
dompurify3.4.0(MPL-2.0 OR Apache-2.0)
lightningcss1.32.0MPL-2.0
lightningcss-android-arm641.32.0MPL-2.0
lightningcss-darwin-arm641.32.0MPL-2.0
lightningcss-darwin-x641.32.0MPL-2.0
lightningcss-freebsd-x641.32.0MPL-2.0
lightningcss-linux-arm-gnueabihf1.32.0MPL-2.0
lightningcss-linux-arm64-gnu1.32.0MPL-2.0
lightningcss-linux-arm64-musl1.32.0MPL-2.0
lightningcss-linux-x64-gnu1.32.0MPL-2.0
lightningcss-linux-x64-musl1.32.0MPL-2.0
lightningcss-win32-arm64-msvc1.32.0MPL-2.0
lightningcss-win32-x64-msvc1.32.0MPL-2.0
Resolved Packages (11)
PackageVersionOriginalResolvedSource
@react-grab/cli0.1.23UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
@react-grab/cli0.1.29UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
@react-grab/mcp0.1.29UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2025 Aiden Bai)
codemirror-lang-elixir4.0.0UNKNOWNApache-2.0npm registry latest version metadata and GitHub repo livebook-dev/codemirror-lang-elixir LICENSE
element-source0.0.3UNKNOWNMITLICENSE file inside the package tarball (MIT License, Copyright (c) 2026 Aiden Bai)
lezer-elixir1.1.2UNKNOWNApache-2.0npm registry latest version metadata and GitHub repo livebook-dev/lezer-elixir LICENSE
map-stream0.1.0UNKNOWNMITnpm registry latest version metadata and GitHub repo dominictarr/map-stream LICENSE
memorystream0.3.1UNKNOWNMITGitHub repo JSBizon/node-memorystream LICENSE (SPDX MIT via GitHub license API)
pause-stream0.0.11["MIT","Apache2"](MIT OR Apache-2.0)License array in package metadata; dual-licensed MIT and Apache 2.0 per LICENSE file in GitHub repo dominictarr/pause-stream
posthog-js1.369.0SEE LICENSE IN LICENSEApache-2.0LICENSE file in GitHub repo PostHog/posthog-js (Apache License, Version 2.0)
valid-url1.0.9UNKNOWNMITLICENSE file in GitHub repo ogt/valid-url (released under the MIT license)

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@brendan-kellam