Skip to content

build(deps): bump react, react-dom and @types/react in /ui#22

Closed
dependabot[bot] wants to merge 310 commits into
mainfrom
dependabot/npm_and_yarn/ui/multi-1fc74d88b4
Closed

build(deps): bump react, react-dom and @types/react in /ui#22
dependabot[bot] wants to merge 310 commits into
mainfrom
dependabot/npm_and_yarn/ui/multi-1fc74d88b4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 15, 2026

Copy link
Copy Markdown

Bumps react, react-dom and @types/react. These dependencies needed to be updated together.
Updates react from 18.3.1 to 19.2.7

Release notes

Sourced from react's releases.

19.2.7 (June 1st, 2026)

React Server Components

19.2.6 (May 6th, 2026)

React Server Components

19.2.5 (April 8th, 2026)

React Server Components

19.2.4 (January 26th, 2026)

React Server Components

19.2.3 (December 11th, 2025)

React Server Components

19.2.2 (December 11th, 2025)

React Server Components

19.2.1 (December 3rd, 2025)

React Server Components

19.2.0 (Oct 1, 2025)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.2 release post for more information.

New React Features

  • <Activity>: A new API to hide and restore the UI and internal state of its children.
  • useEffectEvent is a React Hook that lets you extract non-reactive logic into an Effect Event.
  • cacheSignal (for RSCs) lets your know when the cache() lifetime is over.
  • React Performance tracks appear on the Performance panel’s timeline in your browser developer tools

New React DOM Features

... (truncated)

Changelog

Sourced from react's changelog.

19.2.7 (June 1, 2026)

React Server Components

19.2.6 (May 6, 2026)

React Server Components

19.2.5 (March 18, 2026)

React Server Components

19.2.4 (Jan 26, 2026)

React Server Components

19.2.3 (Dec 11, 2025)

React Server Components

19.2.2 (Dec 11, 2025)

React Server Components

19.2.1 (Dec 3, 2025)

React Server Components

19.2.0 (October 1st, 2025)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.2 release post for more information.

New React Features

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for react since your current version.


Updates react-dom from 18.3.1 to 19.2.7

Release notes

Sourced from react-dom's releases.

19.2.7 (June 1st, 2026)

React Server Components

19.2.6 (May 6th, 2026)

React Server Components

19.2.5 (April 8th, 2026)

React Server Components

19.2.4 (January 26th, 2026)

React Server Components

19.2.3 (December 11th, 2025)

React Server Components

19.2.2 (December 11th, 2025)

React Server Components

19.2.1 (December 3rd, 2025)

React Server Components

19.2.0 (Oct 1, 2025)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.2 release post for more information.

New React Features

  • <Activity>: A new API to hide and restore the UI and internal state of its children.
  • useEffectEvent is a React Hook that lets you extract non-reactive logic into an Effect Event.
  • cacheSignal (for RSCs) lets your know when the cache() lifetime is over.
  • React Performance tracks appear on the Performance panel’s timeline in your browser developer tools

New React DOM Features

... (truncated)

Changelog

Sourced from react-dom's changelog.

19.2.7 (June 1, 2026)

React Server Components

19.2.6 (May 6, 2026)

React Server Components

19.2.5 (March 18, 2026)

React Server Components

19.2.4 (Jan 26, 2026)

React Server Components

19.2.3 (Dec 11, 2025)

React Server Components

19.2.2 (Dec 11, 2025)

React Server Components

19.2.1 (Dec 3, 2025)

React Server Components

19.2.0 (October 1st, 2025)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.2 release post for more information.

New React Features

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for react-dom since your current version.


Updates @types/react from 18.3.12 to 19.2.17

Commits

…l P3-ATS-1)

The WARDYN_TEST_PG bootstrap (env-gate, db.Connect, db.Migrate,
t.Cleanup, embedded.New, New(Config{...})) was copy-pasted three times.
pgHarness is now a thin wrapper over pgHarnessWithRunner that overrides
DefaultPolicy, and the inline copy in
TestReconcileFinalize_TeardownErrorAudited calls pgHarnessWithRunner
directly and reads audit via the established srv.cfg.Audit cast.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…P3-ATS-2)

Five test sites still hand-rolled the verbatim Config preamble
baseTestConfig was extracted to eliminate: approved_egress_test.go x3,
scanresult_test.go x1, and site_config_test.go's newSiteConfigHarness.
Each is now srv := New(baseTestConfig(h, fake)) with any overrides
applied on the returned Config, matching the package norm.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…P3-UWZ-1)

guaranteeSentences was a third parallel prose-projection of RunPolicySpec
duplicating canLines/cantLines, with exactly one caller (policies.tsx) and
zero test coverage. Render ComposeQuickReview inline_policy={policy.spec}
in the stored-policy detail sheet instead, and delete guaranteeSentences.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…il P3-UWZ-2)

The third describe block re-rendered ComposeReview to re-assert the
high-risk ack gate and the no-"unrestricted" invariant, both already
covered as a strict superset by compose-review.test.tsx. Delete the
block, the baseRun fixture, and the now-unused imports.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
run-detail.tsx's ReasonDialog copy had drifted stale: it showed the
credential-mint description for every approve, including egress_domain
and tool_call kinds where no mint happens. Consolidate to one shared
kind-aware ReasonDialog in wardyn/, imported by both run-detail.tsx and
approvals.tsx; thread ApprovalRequest.kind through onDecide.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…l P3-ULS-1)

workspaces.tsx, policies.tsx, and secrets.tsx each re-rolled a
near-verbatim delete-confirm block (state + confirmDelete + destructive
AlertDialog). One shared wardyn/DeleteConfirmDialog now owns the busy
spinner and toast.success/toast.error(getErrorMessage); each screen
keeps only its toDelete state and a short usage.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…ULS-2)

approvals.tsx, audit.tsx, and runs.tsx each duplicated the entire
fetch+setState body between the foreground load() and the silent
background poll. Extract one fetch body per file (fetchAll/fetchEvents/
fetchRuns) shared by both; keeps the deliberate skeleton-vs-silent
behavior the comments defend.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
The "StepIndicator regression" describe block tested a StepIndicator x
SETUP_STEPS pairing that exists nowhere in prod (SetupScreen renders its
own FunnelStepper) plus a PermissionWizard smoke test already covered by
wizard.test.tsx. Delete the block and its now-unused imports; un-export
SETUP_STEPS/SetupStepId since setup-screen.tsx was their only consumer.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…tail P3-USU-2)

CredentialsStep drilled 10 props from SetupScreen for form state only it
uses, unlike its sibling corp steps which keep local state, and included
a patHost field that was never saved, sent to any API, or read anywhere
("informational only" per its own copy). Move appId/savingAppId state +
saveAppId() into CredentialsStep and drop the do-nothing patHost field.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
stepDot(), StepDot, and isFailedStatus() were exported and unit-tested
but never rendered — the import rail uses StepIndicator (step-shell.tsx),
which derives done/active/todo from the current index and has no
failed-dot concept. Delete the dead functions and their tests.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…-ULB-3)

tsconfig.node.json is a Vite-template vestige: its only include
(vite.config.ts) is already in tsconfig.json's own include, and nothing
runs tsc -b or plain tsc on it — only `tsc -p tsconfig.check.json` runs
in CI. Delete it, drop the project-references entry from tsconfig.json,
and drop the references:[] workaround from tsconfig.check.json.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…nytail P3-ULB-4)

package.json declared react/react-dom ONLY as optional peerDependencies
in a private:true end-user app (peerDependencies are library semantics;
nothing depends ON @wardyn/ui) — installation relied on pnpm's
auto-install-peers. Move react/react-dom into dependencies and drop the
peerDependencies/peerDependenciesMeta blocks (also covers DEP-1, the
identical fix). Delete pnpm-workspace.yaml (packages: ['.'], zero refs
anywhere, no parent workspace) — a no-op single-package guard.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…ail P3-STO-1)

194-line hand-rolled memStore + 6 contract tests exercised only the in-file
fake (zero prod code). secretstoretest.RunConformance already asserts the
identical contract (roundtrip, missing->ErrNotFound, overwrite,
delete-idempotent, list) against the real pg backend.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…ail P3-STO-4)

TestMigrationsDiscoveredInLexicalOrder and TestMigrationFilenamesUnique are
fully subsumed by TestMigrationPrefixesNoGapsOrDupes: with the NNNN prefix
regex enforced, lexical order == numeric order (can only fail on a
duplicate prefix, already caught), and duplicate filenames from a single
ReadDir are unreachable.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
Both tests open-coded the connect+migrate+cleanup harness inline while the
same package already has runsPGPool(t) doing exactly this (identical
Getenv-skip/db.Connect/db.Migrate/t.Cleanup(pool.Close) steps).

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
… (ponytail P3-STO-2)

The PG adapter's 38 one-line delegation methods existed only because every
query was a free function taking an explicit *pgxpool.Pool. Make the free
functions methods on PG directly (drop the pool param, bodies unchanged) and
delete the delegation block; Store interface, NewPG, and the SQLite-seam
story are unchanged. Updates all callers: cmd/wardynd/adapters.go,
internal/api test helpers, test/apie2e harness, and the *_pg_test.go suite.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…ytail P3-STO-3)

pgx.Rows structurally satisfies pgx.Row (both declare Scan(dest ...any)
error), so the 5 *Row twin scanners (scanPolicyRow, scanGrantRow,
scanApprovalRow, scanAuditEventRow, scanWorkspaceRow) that duplicated
scanPolicy/scanGrant/scanApproval/scanAuditEvent/scanWorkspace line-for-line
are gone: collectRuns and every List* loop now pass rows straight to the
Row-variant scanner. wsScanDest/fillWorkspace (existed only to share code
between the workspace twins) are folded back into scanWorkspace.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…ytail P3-TYP-1)

internal/identity/identity_test.go was 273 lines asserting the Provider
contract against a hand-rolled fakeProvider, exercising zero production
code (package identity holds only interfaces + registry).

Same invariants are covered against the REAL provider by
identitytest.RunConformance (wired via embedded_conformance_test.go) and
embedded/embedded_test.go (expired token, sponsor defaults, CloudSTS
refusal, revoke).

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
Provider.Keys() exported the verification key as a JWKS 'for the API
to serve', but no route/sidecar/script/doc ever serves or fetches it —
verification is in-process on the same Provider. Delete Keys() and its
TestKeysJWKS twin, plus the jose/encoding-json imports that became
unused. keyID()/kid stay; still stamped into the signer header.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…imeout knob (ponytail P3-TYP-3)

Config.Clock had one prod impl (realClock) and a 19-line test fakeClock
whose Advance() was never called; StopTimeout had zero setters anywhere
(prod or test). Replace Clock with Now func() time.Time, the same
'now func() time.Time // overridable in tests' idiom already used by
embedded.Provider. Drop StopTimeout and use defaultStopTimeout directly
in Tick; the 2-min per-stop bound is preserved as a constant.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…3-SCM-1)

selectConfig mirrored main()'s config-source switch and mostly re-tested the
owning-package loader (internal/egress/proxy). Delete the file; fold the
non-duplicated cases (control_plane_url/run_token required, malformed JSON,
explicit Listen/DecisionBufferSize overrides) into
TestLoadConfigDefaultsAndValidation, which exercises the real LoadConfig.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…tail P3-SCM-2)

buildLocalURL hand-rolled URL joining that url.JoinPath (Go 1.19+) does in
one line; both callers (callMint, pollApproval) only ever pass host:port
bases with no path, so output is unchanged. Delete TestBuildLocalURL, which
only asserted stdlib behavior.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…M-3)

heartbeatLoop/refreshLoop/statsLoop were three copies of identical
ticker+ctx-select boilerplate around a one-line body, each called exactly
once. Replace with a single every(ctx, ival, fn) helper plus three closures;
heartbeat's immediate first beat stays inside its own goroutine so startup
never blocks on a control-plane POST.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
audit_test.go was 156 lines asserting hand-rolled fakes (fakeRecorder/
fakeSink) satisfy interfaces already compile-checked by real impls
(store/recorder.go:16, adapters.go:173/199/234) and covered by
sinks/* tests. No production code path exercised.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
ListCasts had zero production callers (no list-recordings endpoint
anywhere). Drop it from the Store interface, FSStore, the conformance
list subtest, TestFSStore_ListCasts, and the forced fake impl in
recording_upload_test.go. Re-add when a listing feature ships.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…P3-AUX-2)

TestFSStore_Roundtrip and TestFSStore_OpenCast_NotFound (+ isNotFound
helper) are strict subsets of TestFSStore_Conformance's
save_open_roundtrip and open_missing_returns_ErrNotFound, run against
the same NewFSStore(t.TempDir()). TestFSStore_TraversalRejection
(security) and the handler tests are untouched.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
Replace 14 near-identical error-path tests (one-status server -> call ->
assertAPIError) across client_test.go and client_more_test.go with a
single table-driven TestAPIErrorPaths. assertAPIError now returns
*client.APIError so callers can chain Body/Error() assertions; the
duplicate assertAsAPIError helper is deleted.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…nytail P3-SDK-2)

Replace 7 hand-rolled slice-membership/index loops across 5 apie2e test
files with stdlib slices.Contains/ContainsFunc/IndexFunc, and rewrite
equalStringSets as slices.Equal over slices.Sorted(slices.Values(...))
(preserves multiset equality). actionsOf stays (it's a transform, not a
membership check).

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…-SDK-4)

doAdmin, getJSON, and putRaw each hand-rolled the same build-request/
set-bearer/Do/read-body skeleton. Extract one shared doRaw(t, method,
url, bearer, body) in harness_test.go; the three become 1-line wrappers.
doRaw sends Content-Type/Accept: application/json unconditionally —
neither is enforced server-side (recording upload ignores Content-Type;
only an SSE Accept is special-cased), so this is safe for putRaw's raw
asciicast body too.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…onytail P3-SDK-3)

RecordingOptions embeds Options instead of re-declaring
SandboxImage/Timeout/ExitArgv and copying timeout()/image() verbatim;
this changes neither Run's signature nor behaviour, only the 4
RecordingOptions literal call sites in none_test.go (now nest their
fields under Options:).

Weakened per skeptic verify_note: only the 3 preambles that share the
same no-classes-handling KIND (Skipf) — testL0StructuralEgress,
testWaitExitCode, testInteractiveAttach — are folded into a new
createStrongestSandbox helper. testCapabilities (Logf) and
CheckRecordingCapability (fail-closed Errorf) keep their own preambles;
forcing them into one helper was flagged as a misfit.

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
cjohnstoniv and others added 24 commits July 17, 2026 16:43
…tion disclosed, indexes for the run-scoped audit sort (U048/U049/U070/U071)
…U053); one shared finalizeRunTail for watcher+reconciler (U145); terminal lifecycle split to runs_lifecycle.go
…ence; storage posture documented honestly (U098)
…reads AND stale doc rows fail); typed helpers on remaining parseable reads (U084 + codequal)
…rridable so it passes locally and on ubuntu-latest (U064)
…label uses RUN_MODE copy, CLI 401 carries a token hint, OIDC discovery bounded by bootCtx, compose.go/store.go leave the size allowlist
… 18 blind re-assessments), residuals; Fable-audited (two prose corrections applied)
…dual-daemon socket fix

- Demos become a funnel phase before Your Work: four demos as sidebar sub-steps, each with overview + policy YAML + UI-setup steps, an inline audit panel, and a launched-checkmark. Corporate phase moved earlier with one-click skip; SCM stays in Your Work.

- Harness container-login: auto-launch the login sandbox, auto-type 'claude setup-token', auto-open the OAuth URL, add a paste-the-code field, and auto-capture the sk-ant-oat token.

- attach-terminal: own paste end-to-end (raw send + preventDefault + coalescing) and expose a sendText handle; denied demo curls use -sSI so the 403 is visible.

- scripts/lib/common.sh derives WARDYN_DOCKER_SOCK from DOCKER_HOST (dual-daemon tier fix); ci-run.sh drops its duplicate derivation.
A new wardyn-proxy local route (/wardyn/gh/<org>/<repo>) reverse-proxies git-smart-HTTP to github.com: it enforces a per-repo allowlist in cleartext, mints the repo-scoped GitHub App token proxy-side (never into the sandbox), and re-originates upstream. agent-run rewrites granted github URLs to the broker via url.insteadOf; github.com is dropped from run egress. Repo is the unit of trust — an un-granted github repo is denied.

- Per-grant token cache (correctness-critical: a clone is >=2 requests and approval-gated grants are single-use, so no cache would 409 on the second).

- GitGrants threaded run-create -> ProxyConfig -> proxy.Config; built from grant scope.repos plus the declared clone set (run.Repo + WorkspaceRepos), since example grants carry empty repos.

- scanEgressDomains drops the github bundle (keeps ssh-over-443 for ssh_key repos); record-egress never promotes github hosts; example policies drop github.

- Clone + push (git-receive-pack) brokered, repo-scoped. v1 github-HTTPS only; LFS / GHES / ADO-GitLab / in-repo branch confinement deferred.

- Tests: handler (Basic x-access-token auth, sandbox-cred strip, path/service/Git-Protocol preserved, single-mint cache, traversal/ungranted 403s) + wiring helpers; CI/TRY-IT/sdk docs updated.
…d internal markers

Untrack (kept out of the repo) maintainer-local process/design artifacts: review notes, design-tool exports, contributor-campaign results, and the design-system-sync tooling. Genericize a company name in test fixtures. Strip internal review-tracking markers and stray development-mode annotations from code comments. Rename the fat toolchain agent image to a neutral name. No behavior change; build/test/typecheck green.

History is intentionally not rewritten; this cleans the current tree only.
Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
…der the complexity gate)

Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>
Bumps [react](https://github.com/facebook/react/tree/HEAD/packages/react), [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) and [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react). These dependencies needed to be updated together.

Updates `react` from 18.3.1 to 19.2.7
- [Release notes](https://github.com/facebook/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/facebook/react/commits/v19.2.7/packages/react)

Updates `react-dom` from 18.3.1 to 19.2.7
- [Release notes](https://github.com/facebook/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/facebook/react/commits/v19.2.7/packages/react-dom)

Updates `@types/react` from 18.3.12 to 19.2.17
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

---
updated-dependencies:
- dependency-name: "@types/react"
  dependency-version: 19.2.17
  dependency-type: direct:development
  update-type: version-update:semver-major
- dependency-name: react
  dependency-version: 19.2.7
  dependency-type: direct:production
  update-type: version-update:semver-major
- dependency-name: react-dom
  dependency-version: 19.2.7
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump react, react-dom and @types/react in /ui build(deps): bump react, react-dom and @types/react in /ui Jul 18, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/ui/multi-1fc74d88b4 branch from 7548c64 to 97678c7 Compare July 18, 2026 17:41
@dependabot @github

dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/ui/multi-1fc74d88b4 branch July 20, 2026 02:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant