Skip to content

chore(deps): bump react family, framer-motion, ws and @modelcontextprotocol/sdk - #108

Merged
totigm merged 5 commits into
mainfrom
chore/dependabot-round-2
Aug 26, 2026
Merged

totigm merged 5 commits into
mainfrom
chore/dependabot-round-2

Conversation

@totigm

@totigm totigm commented Aug 26, 2026

Copy link
Copy Markdown
Owner

Second dependabot round, opened after #100 and #101 landed. Batches five of the six new PRs; changesets/action (#102) is deliberately left out — see below.

Commit Change Replaces
69a94c6 react, react-dom, @types/react, @types/react-dom → 19.2.8 / 19.2.18 / 19.2.5 #103, #107
45a5f70 ws 8.21.1 → 8.21.3 #104
a5fe942 @modelcontextprotocol/sdk 1.29.0 → 1.30.0 #106
9456c95 framer-motion 12.42.2 → 13.1.1 #105
11cd51a dependabot: group the react family —

On the framer-motion major

13.0.0 has exactly one breaking change: the optional @emotion/is-prop-valid dependency was removed in favour of an explicit <MotionConfig isValidProp={isPropValid}>. This repo has no @emotion/*, no styled-components, and no MotionConfig usage, so nothing is affected. The 27 framer-motion imports across apps/web and packages/generator use motion, animate, useReducedMotion, AnimatePresence, useInView, useScroll, useTransform, useSpring and Reorder — all unchanged. 13.1.0's Reorder additions are additive.

On the react grouping

react (#103) and react-dom (#107) arrived as separate PRs — the same lockstep problem the playwright group exists to prevent. They are one runtime split across two packages, and the @types/* must describe the version actually installed. Added a react group, plus the matching exclude-patterns on dev-dependencies so the @types/* packages do not get claimed away from it (the exact failure mode that produced the #94/#99 skew).

Why #102 is not here

changesets/action v1 → v2 is a breaking change this workflow is not ready for. v2 requires the token to be passed as an explicit github-token input — the GITHUB_TOKEN environment variable and the credentials configured by actions/checkout are no longer accepted. .github/workflows/release.yml currently passes it only via env: GITHUB_TOKEN, so merging #102 as-is would break the release pipeline, and the failure would only surface at publish time. It needs a companion edit, not a plain bump.

Verification

Same steps as CI, locally: pnpm install --frozen-lockfile, lint (0), typecheck (10/10), test (9/9), build (7/7), check:exports (13/13).

@vercel

vercel Bot commented Aug 26, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
humanjs Ready Ready Preview Aug 26, 2026 10:11pm

This branch was successfully deployed

1 active deployment
Preview — 11cd51ab Deployed Aug 26, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant