Skip to content
This repository was archived by the owner on Nov 28, 2025. It is now read-only.

fix(deps): update dependency react-spinners to ^0.17.0#444

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/all-dependencies-minor-patch
Open

fix(deps): update dependency react-spinners to ^0.17.0#444
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/all-dependencies-minor-patch

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Jan 1, 2023

This PR contains the following updates:

Package Change Age Confidence
react-spinners (source) ^0.11.0 -> ^0.17.0 age confidence

Release Notes

davidhu2000/react-spinners (react-spinners)

v0.17.0

Compare Source

Features

Chores

Remove unused outputted files from published package, including umd files, duplicated cjs files, test files, and unnecessary config files. This decreased the total package size by 321KB,

- 541KB
+ 220KB

Changelog

Full Changelog: davidhu2000/react-spinners@v0.16.1...v0.17.0

v0.16.1

Compare Source

What's Changed

Full Changelog: davidhu2000/react-spinners@v0.16.0...v0.16.1

v0.16.0

Compare Source

[!CAUTION]
This version included a breaking change in ScaleLoader where the newly introduced barCount prop was not marked as optional. This issue has been patched in v0.16.1.

What's Changed

New Contributors

Full Changelog: davidhu2000/react-spinners@v0.15.0...v0.16.0

v0.15.0

Compare Source

What's Changed

New Contributors

Full Changelog: davidhu2000/react-spinners@0.14.1...v0.15.0

v0.14.1

Compare Source

  • revert #​602 due to issues with test and server side rendering

v0.14.0

Compare Source

  • feat: color prop can accept rgb colors #​586
  • fix: multiple hash loader with different color renders as the same color #​602
  • fix: moon loader wobble if size is not divisible by 7 #​603

v0.13.8

Compare Source

  • bugfix: Remove Animation Fill Mode from CircleLoader to fix SSR mismatch style error. #​558

v0.13.7

Compare Source

  • bugfix: fix PacmanLoader container height/width to adjust with size prop

v0.13.6

Compare Source

  • Improve formatting of example code to include data-testid prop

v0.13.5

Compare Source

  • Improve README to include additional available props via span tag

v0.13.4

Compare Source

  • bugfix: fix server side render issue on HashLoader

v0.13.3

Compare Source

  • bugfix: Fix PuffLoader initial rendering issue

v0.13.2

Compare Source

  • remove next version badge until needed

v0.13.1

Compare Source

  • update homepage in package.json

v0.13.0

Compare Source

  • Rewrite each loader from the ground up using functional components.
  • Replaced @emotion with vanilla javascript and inline style to reduce component size by 75%. This project now have 0 dependencies, while continuing to support server side rendering.
  • Added support for custom props such as aria-label
  • renamed css prop to cssOverride to avoid type conflicts with css-in-js libraries.

v0.12.0

Compare Source

  • Feature: output commonjs, es module, and umd file types.
  • Feature: add support for react 18 #​464

Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, on day 1 of the month ( * 0-3 1 * * ) in timezone Europe/Paris, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Jan 1, 2023
@github-actions github-actions Bot temporarily deployed to standup-renovate-all-dependencies-minor-patch-3yqhdf January 1, 2023 00:45 Inactive
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from 0d677ad to d238e85 Compare January 3, 2023 09:03
@github-actions github-actions Bot temporarily deployed to standup-renovate-all-dependencies-minor-patch-3yqhdf January 3, 2023 09:05 Inactive
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from d238e85 to d0addba Compare January 10, 2023 10:55
@sonarqubecloud
Copy link
Copy Markdown

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@github-actions github-actions Bot temporarily deployed to standup-renovate-all-dependencies-minor-patch-3yqhdf January 10, 2023 11:01 Inactive
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from d0addba to 6664c41 Compare February 14, 2023 10:21
@github-actions github-actions Bot temporarily deployed to standup-renovate-all-dependencies-minor-patch-3yqhdf February 14, 2023 10:25 Inactive
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from 6664c41 to f2a6756 Compare February 21, 2023 13:27
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Feb 21, 2023

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@github-actions github-actions Bot temporarily deployed to standup-renovate-all-dependencies-minor-patch-3yqhdf February 21, 2023 13:30 Inactive
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from f2a6756 to 8735831 Compare March 1, 2023 11:04
@github-actions github-actions Bot temporarily deployed to standup-renovate-all-dependencies-minor-patch-3yqhdf March 1, 2023 11:07 Inactive
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from 8735831 to eceb898 Compare March 14, 2023 11:32
@sonarqubecloud
Copy link
Copy Markdown

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@github-actions github-actions Bot temporarily deployed to standup-renovate-all-dependencies-minor-patch-3yqhdf March 14, 2023 11:34 Inactive
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from eceb898 to ff36791 Compare April 24, 2023 16:28
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from ff36791 to fb54074 Compare May 22, 2023 14:03
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from fb54074 to 1cea9f9 Compare June 13, 2023 08:41
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Jun 13, 2023

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgraceful-fs@​4.2.6 ⏵ 4.2.11100 +1100100 +176100
Updateddebug@​4.3.1 ⏵ 4.3.4100 +1100100 +181100
Updatedreact-spinners@​0.11.0 ⏵ 0.17.0100 +1100100 +183100

View full report

@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from 1cea9f9 to 8d83641 Compare June 13, 2023 10:50
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from 8d83641 to 7f414c1 Compare June 20, 2023 10:24
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from 7f414c1 to 9a0770a Compare July 18, 2023 15:04
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from 00bd667 to f4d7155 Compare November 21, 2024 15:00
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from f4d7155 to fbabd60 Compare December 6, 2024 06:27
@renovate renovate Bot changed the title fix(deps): update dependency react-spinners to ^0.14.0 fix(deps): update dependency react-spinners to ^0.15.0 Dec 6, 2024
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from fbabd60 to 5321243 Compare December 17, 2024 11:49
@sonarqubecloud
Copy link
Copy Markdown

@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from 5321243 to 2b9b545 Compare February 3, 2025 08:45
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from 2b9b545 to 408046e Compare February 13, 2025 13:28
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from 408046e to bf929d8 Compare April 14, 2025 20:49
@renovate renovate Bot changed the title fix(deps): update dependency react-spinners to ^0.15.0 fix(deps): update dependency react-spinners to ^0.16.0 Apr 14, 2025
Copy link
Copy Markdown

@revu-bot revu-bot Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Analysis

Overview

This PR updates the react-spinners package from version 0.11.0 to 0.16.0. The change is minimal and focused solely on this dependency upgrade, with corresponding updates to the yarn.lock file reflecting the new version and its dependency changes.

The PR effectively accomplishes its goal of updating the package to a newer version, which likely includes bug fixes, performance improvements, and compatibility with newer React versions.

Code Quality Review

Strengths

  • The PR is focused on a single concern (updating one dependency), making it easy to review and understand
  • The change is minimal and doesn't introduce any code modifications beyond the dependency update
  • The yarn.lock file is properly updated, ensuring consistent installations across environments
  • The update removes several dependencies that were previously required by react-spinners (notably @emotion/* packages), which reduces the overall dependency footprint

Areas for Improvement

  • No issues identified in the implementation of this change

Security Assessment

  • The update appears to have positive security implications:
    • Newer versions typically include security patches
    • The removal of several dependencies reduces the attack surface
  • No new security vulnerabilities are introduced by this change
  • The update removes several dependencies that could have been potential security risks

Best Practices Evaluation

  • The PR follows best practices for dependency management:
    • Updates a single package at a time
    • Includes the updated lock file
    • Maintains compatibility with the existing React version
  • The new version of react-spinners (0.16.0) expands peer dependency compatibility to include React 18 and 19, which provides better future-proofing
  • The removal of @emotion dependencies suggests the library has been simplified, which is generally a positive change

Recommendations

  • Consider adding a brief changelog or release notes comment to the PR to document what improvements or fixes are included in the new version
  • If this update is part of a larger effort to update dependencies, consider creating a dependency update plan to track progress
  • After merging, verify that the spinners still function correctly in all use cases within the application

Additional Notes

  • The update to react-spinners 0.16.0 has removed the dependency on @emotion/react, which suggests a significant architectural change in the library
  • The peer dependency requirements have been expanded to include React 16-19, making the library more flexible for future React upgrades
  • This change appears to be low-risk but should still be tested to ensure the spinners render correctly in all contexts where they're used

@renovate renovate Bot changed the title fix(deps): update dependency react-spinners to ^0.16.0 fix(deps): update dependency react-spinners to ^0.17.0 Apr 21, 2025
@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from bf929d8 to b685ce7 Compare April 21, 2025 17:07
@sonarqubecloud
Copy link
Copy Markdown

Copy link
Copy Markdown

@revu-bot revu-bot Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Analysis

Overview

This PR updates the react-spinners package from version 0.11.0 to 0.17.0. This is a dependency update that modernizes the loading spinner component library used in the application. The changes are limited to the package.json and yarn.lock files, with no actual code modifications.

Code Quality Review

Strengths

  • The PR is focused on a single concern: updating one dependency
  • The update removes a dependency on @emotion/react which was previously required by react-spinners 0.11.0
  • The yarn.lock changes show proper resolution of dependencies
  • The update expands React compatibility to include React 18 and 19 in peer dependencies

Areas for Improvement

  • No code changes were needed, which is good, but it would be helpful to verify that all spinner implementations in the codebase still work as expected with the new version

Security Assessment

  • The update removes several dependencies (including the entire @emotion ecosystem), which reduces the attack surface
  • Updating to a newer version generally includes security fixes from the package maintainers
  • No direct security concerns are evident in this dependency update

Best Practices Evaluation

  • The PR follows the best practice of keeping dependencies up to date
  • The update is significant (from 0.11.0 to 0.17.0), which represents multiple major version changes in a minor package
  • The yarn.lock file is properly updated, ensuring consistent installations across environments
  • The PR doesn't include any tests to verify that the updated package works correctly with the existing code

Recommendations

  1. Add verification tests: Consider adding or updating tests that specifically verify that components using react-spinners still function correctly after the update.

  2. Document breaking changes: If there are any breaking changes between 0.11.0 and 0.17.0 that required code modifications (not shown in this diff), document them in the PR description.

  3. Consider incremental updates: For future updates, consider making smaller incremental updates (e.g., 0.11.0 → 0.14.0 → 0.17.0) to make it easier to identify and address any issues that might arise.

  4. Update peer dependencies: Ensure that the project's React version is compatible with the new peer dependency requirements (React 16-19).

Additional Notes

  • The removal of the @emotion dependency is a significant change that might affect styling in the application. The new version of react-spinners likely uses a different styling approach.
  • This update appears to be part of ongoing maintenance to keep dependencies current, which is a good practice.
  • The PR is straightforward and low-risk since it only updates a UI component library that's likely used in isolated parts of the application.

@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from b685ce7 to da4f228 Compare August 4, 2025 19:38
@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud Bot commented Aug 4, 2025

@renovate renovate Bot force-pushed the renovate/all-dependencies-minor-patch branch from da4f228 to 365e86f Compare November 18, 2025 13:38
@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented Nov 18, 2025

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: yarn.lock
! Corepack is about to download https://repo.yarnpkg.com/3.7.0/packages/yarnpkg-cli/bin/yarn.js
/opt/containerbase/tools/corepack/0.34.4/24.11.1/node_modules/corepack/dist/lib/corepack.cjs:22053
    throw new Error(
          ^

Error: Server answered with HTTP 500 when performing the request to https://repo.yarnpkg.com/3.7.0/packages/yarnpkg-cli/bin/yarn.js; for troubleshooting help, see https://github.com/nodejs/corepack#troubleshooting
    at fetch (/opt/containerbase/tools/corepack/0.34.4/24.11.1/node_modules/corepack/dist/lib/corepack.cjs:22053:11)
    at process.processTicksAndRejections (node:internal/process/task_queues:103:5)
    at async fetchUrlStream (/opt/containerbase/tools/corepack/0.34.4/24.11.1/node_modules/corepack/dist/lib/corepack.cjs:22076:20)
    at async download (/opt/containerbase/tools/corepack/0.34.4/24.11.1/node_modules/corepack/dist/lib/corepack.cjs:22247:18)
    at async installVersion (/opt/containerbase/tools/corepack/0.34.4/24.11.1/node_modules/corepack/dist/lib/corepack.cjs:22343:55)
    at async Engine.ensurePackageManager (/opt/containerbase/tools/corepack/0.34.4/24.11.1/node_modules/corepack/dist/lib/corepack.cjs:22856:32)
    at async Engine.executePackageManagerRequest (/opt/containerbase/tools/corepack/0.34.4/24.11.1/node_modules/corepack/dist/lib/corepack.cjs:22967:25)
    at async Object.runMain (/opt/containerbase/tools/corepack/0.34.4/24.11.1/node_modules/corepack/dist/lib/corepack.cjs:23667:7)

Node.js v24.11.1

@sonarqubecloud
Copy link
Copy Markdown

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants