Skip to content

Deps/update and bump main#2314

Open
wp99cp wants to merge 44 commits into
devfrom
deps/update-and-bump-main
Open

Deps/update and bump main#2314
wp99cp wants to merge 44 commits into
devfrom
deps/update-and-bump-main

Conversation

@wp99cp

@wp99cp wp99cp commented Jul 1, 2026

Copy link
Copy Markdown
Member

No description provided.

dependabot Bot and others added 30 commits June 29, 2026 20:23
Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.9.3 to 6.0.3.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v5.9.3...v6.0.3)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 6.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [mermaid](https://github.com/mermaid-js/mermaid) from 11.15.0 to 11.16.0.
- [Release notes](https://github.com/mermaid-js/mermaid/releases)
- [Commits](https://github.com/mermaid-js/mermaid/compare/mermaid@11.15.0...mermaid@11.16.0)

---
updated-dependencies:
- dependency-name: mermaid
  dependency-version: 11.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [vue](https://github.com/vuejs/core) from 3.5.38 to 3.5.39.
- [Release notes](https://github.com/vuejs/core/releases)
- [Changelog](https://github.com/vuejs/core/blob/main/CHANGELOG.md)
- [Commits](vuejs/core@v3.5.38...v3.5.39)

---
updated-dependencies:
- dependency-name: vue
  dependency-version: 3.5.39
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 24.13.2 to 26.0.1.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 24.13.2 to 26.0.1.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) from 3.1005.0 to 3.1076.0.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1076.0/clients/client-s3)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-s3"
  dependency-version: 3.1076.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [vue](https://github.com/vuejs/core) from 3.5.38 to 3.5.39.
- [Release notes](https://github.com/vuejs/core/releases)
- [Changelog](https://github.com/vuejs/core/blob/main/CHANGELOG.md)
- [Commits](vuejs/core@v3.5.38...v3.5.39)

---
updated-dependencies:
- dependency-name: vue
  dependency-version: 3.5.39
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [autoprefixer](https://github.com/postcss/autoprefixer) from 10.5.1 to 10.5.2.
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](postcss/autoprefixer@10.5.1...10.5.2)

---
updated-dependencies:
- dependency-name: autoprefixer
  dependency-version: 10.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) from 3.967.0 to 3.1076.0.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1076.0/clients/client-s3)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-s3"
  dependency-version: 3.1076.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@tanstack/vue-query](https://github.com/TanStack/query/tree/HEAD/packages/vue-query) from 5.101.1 to 5.101.2.
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/vue-query/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/@tanstack/vue-query@5.101.2/packages/vue-query)

---
updated-dependencies:
- dependency-name: "@tanstack/vue-query"
  dependency-version: 5.101.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [vite-plugin-node-polyfills](https://github.com/davidmyersdev/vite-plugin-node-polyfills) from 0.26.0 to 0.28.0.
- [Release notes](https://github.com/davidmyersdev/vite-plugin-node-polyfills/releases)
- [Commits](davidmyersdev/vite-plugin-node-polyfills@v0.26.0...v0.28.0)

---
updated-dependencies:
- dependency-name: vite-plugin-node-polyfills
  dependency-version: 0.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) from 8.62.0 to 8.62.1.
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.62.1/packages/eslint-plugin)

---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.62.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@nestjs/typeorm](https://github.com/nestjs/typeorm) from 11.0.2 to 11.0.3.
- [Release notes](https://github.com/nestjs/typeorm/releases)
- [Commits](nestjs/typeorm@11.0.2...11.0.3)

---
updated-dependencies:
- dependency-name: "@nestjs/typeorm"
  dependency-version: 11.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@aws-sdk/s3-request-presigner](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/s3-request-presigner) from 3.1045.0 to 3.1076.0.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-request-presigner/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1076.0/packages/s3-request-presigner)

---
updated-dependencies:
- dependency-name: "@aws-sdk/s3-request-presigner"
  dependency-version: 3.1076.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.9.3 to 6.0.3.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v5.9.3...v6.0.3)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 6.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [dockerode](https://github.com/apocas/dockerode) from 5.0.0 to 5.0.1.
- [Release notes](https://github.com/apocas/dockerode/releases)
- [Commits](apocas/dockerode@v5.0.0...v5.0.1)

---
updated-dependencies:
- dependency-name: dockerode
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) from 3.1010.0 to 3.1076.0.
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.1076.0/clients/client-s3)

---
updated-dependencies:
- dependency-name: "@aws-sdk/client-s3"
  dependency-version: 3.1076.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [systeminformation](https://github.com/sebhildebrandt/systeminformation) from 5.31.9 to 5.31.11.
- [Release notes](https://github.com/sebhildebrandt/systeminformation/releases)
- [Changelog](https://github.com/sebhildebrandt/systeminformation/blob/master/CHANGELOG.md)
- [Commits](sebhildebrandt/systeminformation@v5.31.9...v5.31.11)

---
updated-dependencies:
- dependency-name: systeminformation
  dependency-version: 5.31.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
…sumer/staging/systeminformation-5.31.11' into staging
…staging/aws-sdk/client-s3-3.1076.0' into staging
…sumer/staging/typescript-6.0.3' into staging
…sumer/staging/aws-sdk/s3-request-presigner-3.1076.0' into staging
…staging/typescript-eslint/eslint-plugin-8.62.1' into staging
…/staging/vite-plugin-node-polyfills-0.28.0' into staging
…/staging/tanstack/vue-query-5.101.2' into staging
…sumer/staging/aws-sdk/client-s3-3.1076.0' into staging

# Conflicts:
#	queueConsumer/package.json
Copilot AI review requested due to automatic review settings July 1, 2026 06:24

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR bumps the monorepo version to 0.60.1, updates a set of JS dependencies/lockfiles, and makes a few targeted robustness and maintenance changes across the CLI, backend seed tooling, frontend dialogs, and dependency automation.

Changes:

  • Bump package versions to 0.60.1 across workspace packages and apps, and refresh pnpm-lock.yaml with dependency upgrades.
  • Improve backend seed test-data generation portability by discovering the repo root and using a local CLI venv Python when present.
  • Update Dependabot configuration (add /cli pip updates, and group updates per app) and add minimumReleaseAge policy to pnpm-workspace.yaml.

Reviewed changes

Copilot reviewed 18 out of 19 changed files in this pull request and generated 2 comments.

Show a summary per file
File Description
queueConsumer/package.json Bumps app version and refreshes a few runtime dependency versions.
pnpm-workspace.yaml Adds minimumReleaseAge / exclude list and retains build/override policies.
pnpm-lock.yaml Updates lockfile entries to reflect dependency bumps across the workspace.
packages/validation/package.json Bumps internal package version to 0.60.1.
packages/shared/package.json Bumps internal package version to 0.60.1.
packages/backend-common/src/seeds/user/seed-files.ts Makes test-data generation path + Python executable resolution more portable.
packages/backend-common/package.json Bumps internal package version to 0.60.1.
packages/api-dto/package.json Bumps internal package version to 0.60.1.
package.json Bumps monorepo root version to 0.60.1.
frontend/src/dialogs/modify-mission-location-dialog.vue Updates DTO import path and removes now-unneeded eslint suppressions.
frontend/src/dialogs/modify-file-location-dialog.vue Updates DTO import path and removes now-unneeded eslint suppressions.
frontend/src/components/configure-access-rights/access-rights-manager.vue Adds a file-level eslint disable for no-unsafe-* rules and removes an unnecessary-condition suppression.
frontend/package.json Bumps app version and upgrades selected frontend dependencies.
docs/package.json Bumps app version and upgrades docs tooling deps (node types, mermaid, vue).
cli/setup.cfg Bumps CLI package version to 0.60.1.
cli/kleinkram/api/deser.py Makes file category deserialization tolerate dict-vs-string category shapes (but needs a small robustness tweak).
backend/package.json Bumps app version and upgrades selected backend deps (AWS SDK, Nest TypeORM, node types, eslint plugin, vue).
.github/dependabot.yml Adds pip updates for /cli and groups updates per ecosystem/directory.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

updated_at = _parse_datetime(file[FileObjectKeys.UPDATED_AT])
state = _parse_file_state(file[FileObjectKeys.STATE])
categories = file[FileObjectKeys.CATEGORIES]
categories = [c["name"] if isinstance(c, dict) else c for c in file.get(FileObjectKeys.CATEGORIES, [])]
</template>

<script setup lang="ts">
/* eslint-disable @typescript-eslint/no-unsafe-assignment, @typescript-eslint/no-unsafe-member-access, @typescript-eslint/no-unsafe-call, @typescript-eslint/no-unsafe-return */
@greptile-apps

greptile-apps Bot commented Jul 1, 2026

Copy link
Copy Markdown

Greptile Summary

This PR updates dependency automation and refreshes several build and frontend paths. The main changes are:

  • Adds a scheduled workflow for dependency updates and version bumps.
  • Updates Dependabot grouping and package versions across the workspace.
  • Adjusts Docker builds to include workspace configuration before dependency fetches.
  • Updates mission/file move dialog imports and related TypeScript cleanup.
  • Makes CLI file category parsing and seed test-data path lookup more flexible.

Confidence Score: 5/5

This looks safe to merge.

  • No blocking issues found in the changed code.

Important Files Changed

Filename Overview
.github/workflows/automated-dependency-update.yml Adds the scheduled dependency update workflow and pull request creation path.
.github/dependabot.yml Updates Dependabot ecosystems and groups dependency updates by workspace area.
frontend/src/dialogs/modify-mission-location-dialog.vue Updates the mission DTO import and removes local lint suppressions.
frontend/src/dialogs/modify-file-location-dialog.vue Updates the mission DTO import used by the file move dialog.
cli/kleinkram/api/deser.py Normalizes file categories when the API returns category objects or omits the field.
packages/backend-common/src/seeds/user/seed-files.ts Locates the test-data generator and generated files from either the container path or a local checkout.
docker/backend.Dockerfile Includes workspace configuration before dependency fetch and disables the pnpm release-age delay during image builds.
docker/base.Dockerfile Updates the shared Docker dependency install path to include workspace configuration.
docker/frontend.Dockerfile Applies the same workspace-aware dependency fetch flow to frontend image builds.
docker/queue-consumer.Dockerfile Applies the same workspace-aware dependency fetch flow to queue consumer image builds.

Reviews (4): Last reviewed commit: "fix(ci): bypass minimumReleaseAge check ..." | Re-trigger Greptile

Comment on lines +31 to +32
pr_author=$(echo "$pr" | jq -r '.author.login')
pr_branch=$(echo "$pr" | jq -r '.headRefName')

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 security Human Dependency Branch Deletion

When this scheduled job sees any open PR older than seven days with a deps/* branch, it closes the PR and deletes that branch even if the author is not automation. A developer working from deps/my-update can lose their branch because the delete condition is dependabot[bot] author or deps/* branch name.

Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/automated-dependency-update.yml
Line: 31-32

Comment:
**Human Dependency Branch Deletion**

When this scheduled job sees any open PR older than seven days with a `deps/*` branch, it closes the PR and deletes that branch even if the author is not automation. A developer working from `deps/my-update` can lose their branch because the delete condition is `dependabot[bot]` author or `deps/*` branch name.

How can I resolve this? If you propose a fix, please make it concise.

Comment on lines 56 to 58
const selectedProjectUuid = ref<string | undefined>(
// eslint-disable-next-line @typescript-eslint/no-unsafe-argument, @typescript-eslint/no-unsafe-member-access
properties.mission?.project?.uuid,
properties.mission?.project.uuid,
);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Project Guard Removed

When the dialog receives a mission payload without a loaded project relation, properties.mission?.project.uuid still dereferences project and throws before the dialog can render. The previous ?.project?.uuid path produced undefined, which matches the template's existing handling of missing project data.

Suggested change
const selectedProjectUuid = ref<string | undefined>(
// eslint-disable-next-line @typescript-eslint/no-unsafe-argument, @typescript-eslint/no-unsafe-member-access
properties.mission?.project?.uuid,
properties.mission?.project.uuid,
);
const selectedProjectUuid = ref<string | undefined>(
properties.mission?.project?.uuid,
);
Prompt To Fix With AI
This is a comment left during a code review.
Path: frontend/src/dialogs/modify-mission-location-dialog.vue
Line: 56-58

Comment:
**Project Guard Removed**

When the dialog receives a mission payload without a loaded `project` relation, `properties.mission?.project.uuid` still dereferences `project` and throws before the dialog can render. The previous `?.project?.uuid` path produced `undefined`, which matches the template's existing handling of missing project data.

```suggestion
const selectedProjectUuid = ref<string | undefined>(
    properties.mission?.project?.uuid,
);
```

How can I resolve this? If you propose a fix, please make it concise.

@wp99cp
wp99cp force-pushed the deps/update-and-bump-main branch from a04401e to bef21f0 Compare July 1, 2026 06:53
LevinCeglie added a commit that referenced this pull request Jul 17, 2026
# Conflicts:
#	cli/kleinkram/api/deser.py
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants