Skip to content

fix(deps): update all non-major dependencies - #1707

Merged
dawsontoth merged 2 commits into
stagefrom
renovate/all-minor-patch
Sep 18, 2026
Merged

dawsontoth merged 2 commits into
stagefrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
@ai-sdk/react (source) 4.0.964.0.103 age confidence dependencies patch 4.0.108 (+4)
@datadog/browser-rum (source) 7.12.07.13.0 age confidence dependencies minor
@datadog/browser-rum-react (source) 7.12.07.13.0 age confidence dependencies minor
@datadog/datadog-ci (source) 5.23.05.24.1 age confidence devDependencies minor
@harperfast/skills (source) 1.12.71.12.10 age confidence dependencies patch
@playwright/test (source) 1.62.11.63.0 age confidence devDependencies minor
@stripe/react-stripe-js 6.9.06.10.0 age confidence dependencies minor
@stripe/stripe-js (source) 9.15.09.16.0 age confidence dependencies minor
@tanstack/react-router (source) 1.170.321.170.36 age confidence dependencies patch 1.170.38 (+1)
@tanstack/react-router-devtools (source) 1.167.11.167.2 age confidence dependencies patch
@types/node (source) 24.13.324.13.4 age confidence dependencies patch 24.13.5
@types/node (source) 24.13.324.13.4 age confidence devDependencies patch 24.13.5
@types/react (source) 19.2.1819.3.0 age confidence devDependencies minor
@types/react-dom (source) 19.2.719.3.0 age confidence devDependencies minor
ai (source) 7.0.937.0.100 age confidence dependencies patch 7.0.105 (+4)
create-harper (source) 1.12.21.12.6 age confidence dependencies patch
happy-dom 20.14.020.14.5 age confidence devDependencies patch
harper (source) 5.2.95.2.12 age confidence devDependencies patch 5.2.13
lucide-react (source) 1.41.01.46.0 age confidence dependencies minor 1.47.0
motion 13.2.013.3.0 age confidence dependencies minor 13.4.0
node (source) 24.20.024.21.0 age confidence minor
node (source) 24.20.0-bookworm24.21.0-bookworm age confidence final minor
oxlint (source) 1.81.01.83.0 age confidence devDependencies minor
pnpm (source) 12.3.412.4.1 age confidence packageManager minor 12.4.2
react (source) 19.2.819.3.0 age confidence dependencies minor
react-dom (source) 19.2.819.3.0 age confidence dependencies minor
react-dropzone 20.1.120.1.2 age confidence dependencies patch
react-hook-form (source) 7.87.07.88.0 age confidence dependencies minor
tailwind-merge (source) 3.6.03.7.0 age confidence dependencies minor
vite (source) 8.2.28.3.0 age confidence devDependencies minor
yaml (source) 2.9.02.9.1 age confidence devDependencies patch
zod (source) 4.5.44.6.5 age confidence dependencies minor

Release Notes

vercel/ai (@​ai-sdk/react)

v4.0.103

Compare Source

Patch Changes
  • Updated dependencies [6431635]
    • ai@​7.0.100

v4.0.102

Compare Source

Patch Changes
  • Updated dependencies [615ac89]
    • ai@​7.0.99

v4.0.101

Compare Source

Patch Changes

v4.0.100

Compare Source

Patch Changes

v4.0.99

Compare Source

Patch Changes

v4.0.98

Compare Source

Patch Changes
  • Updated dependencies [27f6d7a]
    • ai@​7.0.95

v4.0.97

Compare Source

Patch Changes
DataDog/browser-sdk (@​datadog/browser-rum)

v7.13.0

Compare Source

Public Changes:

  • ✨ [RUM-16985] Capture wasm module build_ids and enrich error events (#​4920)
  • ✨ Attach debug IDs to debugger snapshots (#​5028)
  • ✨ [RUM-18194] default RUM service to the applicationId (#​4979)
  • ✨ Add per-element frustration signal opt-outs (#​5005)
  • 🐛 Keep inlining link stylesheets after a client-side navigation (#​5019)
  • 🐛 Send partial snapshots after debugger capture timeout (#​4734)
  • 📝 [Shopify] Update README to point to public docs instead of inline setup snippet (#​5011)
  • ⚗️ Add Canvas image capture [3/n] (#​4980)

Internal Changes:

  • 👷 Rename StringResourceId to StringRoleResourceId (#​5023)
  • 👷 Sync rum-events-format schemas for session replay image content (#​5017)
  • 👷 Use workspace:* protocol for internal monorepo dependencies (#​5016)
  • 👷 [Shopify] Add Slack notification on e2e-shopify-scheduled failure (#​5012)
  • ♻️ introduce Logs plugin API and assemble hook enrichment (#​5014)
  • ♻️ Merge message context into raw logs event at collection time (#​5009)
  • ♻️ Move global monitor functions to js-core (#​4986)
  • ✅ Stabilize base plugin error E2E tests in WebKit (#​5038)
  • ✅ Stabilize Nuxt error E2E tests in WebKit (#​5037)
  • 🔊 Report remote configuration sync metadata on configuration telemetry (#​5001)
DataDog/datadog-ci (@​datadog/datadog-ci)

v5.24.1

Compare Source

What's Changed

Dependencies
Serverless

Full Changelog: DataDog/datadog-ci@v5.24.0...v5.24.1

v5.24.0

Compare Source

What's Changed

datadog-ci
Dependencies
RUM
Serverless
Synthetics
Chores

New Contributors

Full Changelog: DataDog/datadog-ci@v5.23.0...v5.24.0

HarperFast/skills (@​harperfast/skills)

v1.12.10

Compare Source

Bug Fixes

v1.12.9

Compare Source

Bug Fixes
  • rules: correct PUT/PATCH/POST semantics in adding-tables-with-schemas (mode: generate flip blocked on documentation#​650) (#​80) (8a3fcf5)

v1.12.8

Compare Source

Bug Fixes
microsoft/playwright (@​playwright/test)

v1.63.0

Compare Source

stripe/react-stripe-js (@​stripe/react-stripe-js)

v6.10.0

Compare Source

  • Add Link Signup Element wrappers (#​708)
New features
Fixes
Changed
stripe/stripe-js (@​stripe/stripe-js)

v9.16.0

Compare Source

  • Add Link Signup Element types (#​969)
  • Add Custom Checkout tiered and package pricing types (#​966)
New features
Fixes
Changed
TanStack/router (@​tanstack/react-router)

v1.170.36

Compare Source

Patch Changes
  • #​8390 b747fb8 - Keep the Link location cache out of server bundles: buildLocation only creates, reads and writes it when isServer is false. Render React Links on the server without the extra prop copies and the forwarded-ref hook. Link SSR rendering is 20-40% faster in the Link benchmarks and the React Start SSR request loop about 7% faster.

    React activeProps and inactiveProps now follow one precedence rule on every link, including links whose destination is blocked for using a disallowed scheme: state props override element props, ref and event handlers, while href, disabled and target stay controlled by the router. Previously a blocked link ignored a ref or handler from its inactive props.

    React Link and useLinkProps split router options from element props with one key set on the client and the server. Element props pass through as given: external links forward them verbatim, falsy values included, and useLinkProps now returns children for router-controlled links as it already did for external ones.

  • #​8324 6387d58 - Reuse hydration snapshot getters to avoid unnecessary store-instance effect updates when Links and other hydration-aware components rerender.

  • #​8318 9b2adaf - Allow active and inactive Link props to override base element props in React and Solid while preserving class/style merging. Keep React's href, target, and disabled values controlled by routing options. Preserve Vue object and nested-array class bindings, including reactive updates and server rendering, without mutating cached bindings during VNode normalization.

  • #​8327 634da91 - Make pathParamsAllowedCharacters initialization-only. Configure it when creating the router; changing allowed characters requires a new router instance. Remove decoder-update bookkeeping and decoder-change checks from route-owned path caches.

  • #​8370 e9396c9 - Stop exporting the internal isPlainObject and isPlainArray helpers.

  • #​8324 6387d58 - Avoid a redundant prop copy when rendering native Links while preserving custom-component props and the public hook result.

  • #​8252 7e349c3 - Reduce the bundle cost of shared Link pathname interpolation while preserving its rendering performance. Reuse one interpolation pass for pathname and optional metadata, keep the bounded cache on the router, and simplify React Link active-state and prop merging.

  • #​8370 e9396c9 - Reuse built locations for Links whose destination does not depend on the current location. buildLocation keeps the result per options object when the build never read the current location, and the React Link passes one stable options object per instance, so navigations resolve unchanged Links with a lookup instead of a full build. The per-route pathname interpolation cache this replaces is removed. Link params, search and activeOptions are compared by value on render, so inline object literals with unchanged contents keep reusing the Link's location. Pass a new object to change a destination; like any other React prop, an object mutated in place is not re-read.

  • Updated dependencies [d76a332, b747fb8, 6cfb1e8, 700a714, 700a714, 8fff7fa, f021f6d, ae68535, 7e349c3, 873c830, 7e349c3, 634da91, e9396c9, 634da91, f151ab0, bc57fa3, 9872d2a, d76a332, 634da91, 634da91, 7e349c3, 9448caa, e9396c9, 700a714, 634da91, 634da91]:

v1.170.35

Compare Source

Patch Changes
  • #​7824 8c43c71 - Upgrade TanStack Store to 0.11 and migrate router subscriptions to useSelector, preserving selector comparisons and Vue subscription cleanup.

v1.170.34

Compare Source

Patch Changes
  • #​8279 aee42c6 - Avoid allocating event-handler arrays and wrapper functions for links without user-supplied event handlers.

  • #​8308 9c1871c - Validate navigation and redirect destinations, keep ambiguous relative URLs on the current origin, and constrain prerender requests and output paths. Prevent redirect headers from appearing in serialized server function response bodies.

    Preserve native form HTTP redirects, route error handling and masks for document redirects, and per-navigation destinations for shared loader redirects. Avoid redundant origin parsing and reduce link styling and server-rendering work. Configured origins must already be normalized.

    Keep blocked-link inactive props consistent during React hydration, honor explicit redirect Location headers before checking route options, and refresh Vue link state when destinations become internal. Reuse the protocol-relative URL check while parsing redirect schemes once.

    Reduce React link bundle size by sharing pathname comparisons, state-prop selection, and element creation.

    Share normalized pathname comparisons in Solid and Vue links to reduce bundle size.

  • #​8311 9aec5a7 - React Links resolve state props without temporary class-name arrays or unnecessary style copies.

  • Updated dependencies [f9836f1, 9c1871c, 9871c06, 0654c0a]:

v1.170.33

Compare Source

Patch Changes
  • #​8165 2f20c00 - Exclude structural descendants below error and not-found boundaries from route lifecycle callbacks. Preserve lifecycle membership through invalidation, hydration, background reloads, and superseded navigation publication.

  • #​8209 28a5e45 - Preserve falsy thrown values in React and Vue error boundaries. Type React and Vue boundary error components and onCatch callbacks as unknown. Solid boundary errors remain typed as Error; SSR now wraps non-Error loader errors to match Solid’s native boundary behavior, preserving the original value in cause. Router state and loader onError values are unchanged.

    When upgrading React or Vue, narrow boundary errors (for example, with error instanceof Error) before reading message or stack. ErrorComponentProps<TError> remains available for values narrowed to a specific error type. Route onError types are unchanged.

  • #​8161 f0b5eda - Retain successful not-found matches as terminal shared boundaries during client navigation, preserving route context while the destination loads.

  • #​8251 0497cae - Use URL.canParse for absolute URL checks in links, navigation, redirects, and build configuration. Preserve a URL constructor fallback for older browsers.

  • #​8169 0caf6b9 - Fix route-scoped useMatch, useSearch, and useParams APIs to forward the shouldThrow option and preserve optional return types when shouldThrow: false.

  • #​8257 cf166d1 - Fix repeated innerHTML writes for unchanged styles and data scripts during React re-renders. This prevents unnecessary CSS parsing and Trusted Types errors during client navigation.

  • Updated dependencies [edf0e16, 2f20c00, 28a5e45, 08eff50, 216c0c4, 2f91503, f0b5eda, 50eafca, 0497cae, ee28348, 9035abc, c18e690]:

TanStack/router (@​tanstack/react-router-devtools)

v1.167.2

Compare Source

Patch Changes
vercel/ai (ai)

v7.0.100

Compare Source

Patch Changes

v7.0.99

Compare Source

Patch Changes

v7.0.98

Compare Source

Patch Changes

v7.0.97

Compare Source

Patch Changes

v7.0.96

Compare Source

Patch Changes

Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • "before 9am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested review from a team and dawsontoth as code owners September 14, 2026 04:54
@renovate

renovate Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: e2e/pnpm-lock.yaml
Error: ERR_PNPM_STRICT_MIN_RELEASE_AGE_REQUIRES_SAVE

  × updating dependencies
  ╰─▶ minimumReleaseAgeStrict cannot be combined with --no-save: approval
      would require writing to minimumReleaseAgeExclude in pnpm-
      workspace.yaml, which --no-save prevents.
  help: Drop --no-save so the exclude list can be persisted, or set
        minimumReleaseAgeStrict: false.


@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 35c33bd to d80f591 Compare September 14, 2026 10:55

@dawsontoth dawsontoth left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking on one package in this batch: @tanstack/react-router 1.170.32 → 1.170.33 breaks tsc -b. Everything else in the batch is clean. Reproduced and isolated locally (macOS, Node 24.21.0, pnpm 12.4.1).

The failure

This is what reddens Verify PR — the job fails at Type-check, which then skips Run unit tests, Run lint and Build. The Report coverage error further down (ENOENT: coverage-summary.json) is just fallout from vitest never running; it is not a second problem.

src/router/useNewRouter.ts(25,4): error TS2322:
  Type '({ className, error, title, showReturnToHome, children }: ErrorProps) => Element'
    is not assignable to type 'ErrorRouteComponent | undefined'.
  Type ... is not assignable to type
    'LazyExoticComponent<(props: ErrorComponentProps) => any> & { preload?: ... }'.
      ... is missing the following properties from type
      'LazyExoticComponent<(props: ErrorComponentProps) => any>': _result, $$typeof

The offending line is defaultErrorComponent: ErrorComponent in createRouter(...). Upstream narrowed ErrorRouteComponent so it now only accepts a LazyExoticComponent, not a plain function component. Ours is a plain function component (src/components/ErrorComponent.tsx), and defaultNotFoundComponent right above it is the same shape.

Isolated to @tanstack/react-router, and bisected to the patch

Holding only @tanstack/react-router back on this branch, with every other bump in the batch left in place:

@tanstack/react-router tsc -b
1.170.32 (base) exit 0
1.170.33 exit 1
1.170.34 exit 1
1.170.35 (this PR) exit 1

So 1.170.33 introduced it, and stage type-checks clean today (verified — tsc -b exit 0 on 6320a01ef).

A type-narrowing of a public prop in a patch release is an upstream regression, not something we should absorb quietly. Wrapping ErrorComponent in React.lazy to satisfy it would be a real code change made to appease a probable bug, and it would regress the error boundary to a suspense boundary.

Ask

Please split @tanstack/react-router out of this batch — hold it at 1.170.32 (it is already pinned exactly, so a Renovate ignore/pin entry) and let the rest land. I'd rather not hold three good bumps behind one upstream types regression. Worth an upstream issue against TanStack Router too.

The rest of the batch is fine

zod 4.5.4 → 4.6.2, harper 5.2.9 → 5.2.10 and packageManager pnpm 12.3.4 → 12.4.1 are all clean — with @tanstack/react-router held at 1.170.32 and every other bump from this PR in place, tsc -b exits 0.

Not caused by this PR

renovate/artifacts is red, as it is on every studio update that touches the e2e workspace — the pnpm --no-save artifact step, not the lockfile. The lockfile here is fine (pnpm install --frozen-lockfile exit 0). Don't chase it.

@dawsontoth
dawsontoth marked this pull request as draft September 14, 2026 16:19
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from 8f7ab18 to f6e2104 Compare September 15, 2026 06:13
@dawsontoth

Copy link
Copy Markdown
Contributor

Re-checked on the new head f6e21049 — still blocked, but the diagnosis has changed

Renovate force-pushed and moved the blocking package from 1.170.33 to 1.170.35. My CHANGES_REQUESTED stands, but I want to correct what I said last time: I framed this as an upstream regression to wait out. It isn't. It's a deliberate upstream API change, it is in every release from 1.170.33 onward, and it needs a small change in our code. Waiting will not clear it.

Everything else in the batch is clean

Pinning only @tanstack/react-router back to 1.170.32 on this exact head — changing nothing else — makes tsc -b --force exit 0. So zod 4.5.4 → 4.6.2, harper 5.2.9 → 5.2.10, pnpm 12.3.4 → 12.4.1 and .nvmrc 24.20.0 → 24.21.0 are all fine. The router is the sole cause.

Root cause

@tanstack/router-core went 1.171.27 → 1.171.30 between these releases, and ErrorComponentProps changed its default type parameter:

// router-core 1.171.27
export type ErrorComponentProps<TError = Error> = { error: TError; ... }

// router-core 1.171.30
export interface DefaultErrorBoundaryTypes { error: unknown }
/** Frameworks can specialize the error exposed by boundary components and callbacks. */
export interface ErrorBoundaryTypes extends DefaultErrorBoundaryTypes {}
export type ErrorComponentProps<TError = ErrorBoundaryTypes['error']> = { error: TError; ... }

So error went from Error to unknown. Our ErrorProps declares:

error: Error | { message: string | ReactNode };

ErrorRouteComponent is AsyncRouteComponent<ErrorComponentProps>, whose component is the union ((props) => any) | React.LazyExoticComponent<(props) => any>. Under strictFunctionTypes, parameters are contravariant, so the plain-function branch now requires unknown to be assignable to Error | { message: ... } — it isn't, and that branch drops out. TypeScript then reports only the surviving branch, which is why the error reads as though it wants a lazy component:

Type '...(props: ErrorProps) => Element' is missing the following properties
from type 'LazyExoticComponent<(props: ErrorComponentProps) => any>': _result, $$typeof

That message is a red herring — nothing here wants React.lazy.

Every version from .33 on is affected, including the newest

Pristine PR head, only the router version varied, tsc -b --force each time (macOS, Node 24.21.0, pnpm 12.4.1):

@tanstack/react-router tsc -b
1.170.32 ✅ clean
1.170.33 ❌ TS2322
1.170.34 ❌ TS2322
1.170.35 (this PR) ❌ TS2322 — matches CI
1.170.36 (latest, published 09-13) ❌ TS2322

ErrorBoundaryTypes being exported for augmentation, with that doc comment, is upstream saying the unknown default is intentional and permanent.

This is also hiding a real bug of ours

ErrorComponent renders {error.message} with no guard. The route boundary genuinely can hand us a non-Error — a thrown string, or a rejected promise carrying anything — and today that silently renders nothing. The type change is upstream telling us the truth; our type was the optimistic one.

Suggested fix — verified green

 interface ErrorProps {
 	className?: string | undefined;
-	error: Error | { message: string | ReactNode };
+	// The router's error boundary hands us whatever was thrown, which is not
+	// necessarily an Error. @tanstack/react-router >= 1.170.33 types this as
+	// `unknown`, so accept anything and narrow before reading `.message`.
+	error: unknown;
 	title?: string;
 	showReturnToHome?: boolean;
 	children?: ReactNode;
 }
 
+function errorMessage(error: unknown): ReactNode {
+	if (typeof error === 'object' && error !== null && 'message' in error) {
+		return (error as { message: string | ReactNode }).message;
+	}
+	return typeof error === 'string' ? error : 'An unexpected error occurred.';
+}
+
 export function ErrorComponent({ className, error, title, showReturnToHome, children }: ErrorProps) {
@@
-				<CardDescription>{error.message}</CardDescription>
+				<CardDescription>{errorMessage(error)}</CardDescription>

error: unknown still accepts the five direct <ErrorComponent error={{ message: ... }} /> call sites in clusters/upsert/index.tsx, clusters/upsert/ClusterRegions.tsx and instance/apis/APIDocs.tsx — they keep working untouched.

With that patch applied on this head at 1.170.35:

tsc -b --force   exit 0
vitest run       345 files — 3128 passed, 11 skipped, 0 failed
oxlint .         exit 0, clean
vite build       ✓ built in 2.69s

If you'd rather not touch the component in a dependency PR, the one-line alternative is to augment the interface upstream provides for exactly this:

declare module '@tanstack/router-core' {
	interface ErrorBoundaryTypes {
		error: Error | { message: string | ReactNode };
	}
}

I'd take the first one — it fixes the latent unguarded .message rather than asserting the old assumption back into place.

The other red check is not real

renovate/artifacts ("Artifact file update failure") is the recurring lockfile-artifact flake on this repo, not a lockfile problem. pnpm install --frozen-lockfile resolves cleanly here (exit 0), so the committed pnpm-lock.yaml is in sync. The Report coverage error inside Verify PR is likewise just fallout from vitest never running after the type-check failed.

Happy to push the fix onto this branch if you'd like — say the word.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from f6e2104 to e372acc Compare September 16, 2026 01:27
@dawsontoth

Copy link
Copy Markdown
Contributor

Re-checked on the new head e372accd — still blocked on the same one line, but this batch is now much bigger than the one I reviewed

Renovate force-pushed again at 01:27 today. My CHANGES_REQUESTED stands and the diagnosis from my last comment is unchanged and still correct. What's new is the scope of the batch, so I re-ran everything from scratch rather than restating.

What changed since my 09-15 pass

The manifest diff still looks like four lines, but the lockfile refresh pulled a React minor into the tree:

previous head f6e21049 this head e372accd
react / react-dom 19.2.8 19.3.0
@types/react / @types/react-dom 19.2.18 / 19.2.7 19.3.0 / 19.3.0
zod 4.6.2 4.6.4
vite 8.2.2 8.3.0
oxlint 1.81.0 1.82.0
react-hook-form 7.87.0 7.88.0

react is ^19.0.0 in package.json, so 19.3.0 arrives through the lockfile rather than through a visible manifest line. Worth calling out because CI cannot tell you anything about itVerify PR dies at Type-check and then skips Run unit tests, Run lint and Build (confirmed on this exact run: 35044192636). So a React minor, a Vite minor and a zod bump are currently landing with zero functional signal behind a single type error.

The blocker is unchanged

Reproduced on e372accd as-is (macOS, Node 24.21.0, pnpm 12.4.1, pnpm install --frozen-lockfile exit 0):

src/router/useNewRouter.ts(25,4): error TS2322:
  Type '({ className, error, title, showReturnToHome, children }: ErrorProps) => Element'
    is not assignable to type 'ErrorRouteComponent | undefined'.

Same @tanstack/react-router 1.170.35 / router-core ErrorComponentProps<TError = ErrorBoundaryTypes['error']>unknown cause I laid out last time. Still not an upstream regression, still not fixable by waiting, still not something to paper over with React.lazy.

The rest of the enlarged batch is verified clean

I applied only the one-file fix — widening ErrorProps.error to unknown in src/components/ErrorComponent.tsx and narrowing before reading .message — and changed nothing else on this head:

tsc -b --force   exit 0
pnpm test        345 files — 3128 passed | 11 skipped (3139)
pnpm lint        exit 0  (oxlint 1.82.0, clean)
pnpm build       exit 0  (vite 8.3.0)

So React 19.3.0, @types/react 19.3.0, vite 8.3.0, zod 4.6.4, oxlint 1.82.0, harper 5.2.10 and pnpm 12.4.1 are all fine. The router type error is still the sole thing standing between this PR and green, and it is one file.

Ask (unchanged, and now worth more)

Fix ErrorComponent's prop type rather than pinning the router. It's a few lines, it unblocks a batch that now includes a React minor, and it fixes a real latent bug on the way: {error.message} is rendered unguarded today, so a thrown string or non-Error renders nothing in the error boundary. Once that lands, this whole PR goes green as-is — no pin, no ignore rule, no split.

I'm happy to push that commit onto this branch if it's easier — say the word. (Renovate will stop auto-updating the PR body once a human pushes, which is fine at this point.)

Not caused by this PR

renovate/artifacts is red again — ERR_PNPM_STRICT_MIN_RELEASE_AGE_REQUIRES_SAVE on e2e/pnpm-lock.yaml, the pnpm --no-save artifact step. It fires on every studio update touching the e2e workspace. The lockfile itself is fine (--frozen-lockfile exit 0). Don't chase it.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 2ace1a8 to 547c7f9 Compare September 17, 2026 03:15
@dawsontoth

Copy link
Copy Markdown
Contributor

Re-checked on the new head 547c7f93 — same blocker, plus one correction to my last comment

Renovate force-pushed again at 03:15 today. My CHANGES_REQUESTED stands. The router diagnosis is unchanged and I won't restate it. What's new is that renovate/artifacts is a real failure this time, and I told you the opposite yesterday.

Correction: e2e/pnpm-lock.yaml is genuinely out of sync on this head

Yesterday I wrote "The lockfile itself is fine (--frozen-lockfile exit 0). Don't chase it." That was true of the root lockfile, which is what I actually checked. It is not true of e2e/pnpm-lock.yaml on this head, and this batch is the first one where it matters.

This head bumps e2e/package.json's packageManager to pnpm@12.4.1. pnpm 12 records that in the lockfile as packageManagerDependencies, and the artifact step that would have updated it is exactly the one that died on ERR_PNPM_STRICT_MIN_RELEASE_AGE_REQUIRES_SAVE. So the two disagree:

value
e2e/package.jsonpackageManager pnpm@12.4.1
e2e/pnpm-lock.yamlpackageManagerDependencies.pnpm 12.3.4

And e2e/Dockerfile:14 is RUN pnpm install --frozen-lockfile, so building the harness image fails outright:

$ cd e2e && pnpm install --frozen-lockfile
Error: ERR_PNPM_FROZEN_LOCKFILE_WITH_OUTDATED_LOCKFILE

  × resolve package manager dependencies
  ╰─▶ Cannot update packageManagerDependencies with "frozen-lockfile" because
      the lockfile is not up to date

This is caused by this PR — on the base ab1eb190 both sides read 12.3.4 and the frozen install is clean. No PR check catches it, because the e2e harness is driven by the out-of-repo trusted-lane scheduler rather than by a workflow in this repo. That's precisely why it needs saying here: it would land green and break the e2e lane later.

The fix is mechanical — regenerate the one lockfile:

cd e2e && pnpm install --ignore-scripts

I ran it. The delta is packageManagerDependencies 12.3.412.4.1 plus the corresponding @pnpm/exe.* platform entries, and nothing else — no test dependency moves (@playwright/test 1.62.1, mailosaur 11.1.1, typescript 7.0.2, dotenv 17.4.2, @types/node 24.13.3 all unchanged). After that, pnpm install --frozen-lockfile in e2e/ is clean:

✓ Lockfile passes supply-chain policies (verified 8d ago)
Lockfile is up to date, resolution step is skipped

So the general shape of my earlier advice still holds — renovate/artifacts red on this repo is usually cosmetic — but "usually" isn't "always", and the tell is whether the batch actually changed something under e2e/. This one did.

The blocker is unchanged (router is now 1.170.36)

Reproduced on 547c7f93 as-is (macOS, Node 24.21.0, pnpm 12.4.1, root pnpm install --frozen-lockfile exit 0):

src/router/useNewRouter.ts(25,4): error TS2322:
  Type '({ className, error, title, showReturnToHome, children }: ErrorProps) => Element'
    is not assignable to type 'ErrorRouteComponent | undefined'.

Same cause as .33 and .35: router-core types the boundary error as unknown, ErrorComponent declares error: Error | { message: string | ReactNode }, and the parameter position is contravariant. Note the error text dangles LazyExoticComponent at you — that's just TS reporting the last union member, not a hint to reach for React.lazy. Still not an upstream regression, still not fixable by waiting, still one file.

The rest of the batch is verified clean

Applied only the one-file fix (widen ErrorProps.error to unknown, narrow before reading .message), nothing else touched:

tsc -b --force   exit 0
pnpm test        346 files — 3144 passed | 11 skipped (3155)
pnpm lint        exit 0  (oxlint, clean)
pnpm format      exit 0  (dprint, clean)
vite build       ✓ built in 3.00s

And isolated the blocker from the other direction — original ErrorComponent, only @tanstack/react-router reverted to 1.170.32:

tsc -b --force   exit 0

So zod 4.6.5, harper 5.2.10, @tanstack/react-router-devtools 1.167.2, Node 24.21.0 and pnpm 12.4.1 are all fine. Two things stand between this PR and green, and both are small.

Ask

  1. Fix ErrorComponent's prop type rather than pinning the router — it also fixes a live latent bug, since {error.message} is rendered unguarded today and a thrown string renders nothing in the boundary.
  2. Regenerate e2e/pnpm-lock.yaml (one command above).

Happy to push both onto this branch — say the word.

Nits, pre-existing, not blocking

e2e/Dockerfile has two bits of drift Renovate isn't tracking and this PR widens:

  • line 7 pins corepack prepare pnpm@11.20.0 --activate while e2e/package.json now asks for 12.4.1 — corepack honours the packageManager field anyway, so the pin is inert and misleading rather than harmful.
  • the header comment says Node is pinned to .nvmrc (24.19.0); .nvmrc was 24.20.0 before this PR and is 24.21.0 after. The FROM line updates correctly, only the prose is stale.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 547c7f9 to b598fad Compare September 17, 2026 21:10
@dawsontoth

Copy link
Copy Markdown
Contributor

Re-checked on the new head b598fadb — both blockers unchanged

Renovate force-pushed again at 21:10 on the 17th. The only thing that moved since 547c7f93 is harper 5.2.10 → 5.2.12 (devDependency) plus its lockfile entries — nothing else in the batch changed, and neither blocker is affected. CHANGES_REQUESTED stands. I won't restate the diagnosis; see my comment on 547c7f93 above.

Both failures reproduce on this head, verbatim

Root pnpm install --frozen-lockfile exit 0 (macOS, Node 24.21.0, pnpm 12.4.1), then:

$ pnpm exec tsc -b --force
src/router/useNewRouter.ts(25,4): error TS2322:
  Type '({ className, error, title, showReturnToHome, children }: ErrorProps) => Element'
    is not assignable to type 'ErrorRouteComponent | undefined'.

Identical to what Verify PR reports on this head (run 35275154904) — router is still 1.170.36, and the LazyExoticComponent tail of that message is still just TS naming the last union member, not a hint to reach for React.lazy.

$ cd e2e && pnpm install --frozen-lockfile
Error: ERR_PNPM_FROZEN_LOCKFILE_WITH_OUTDATED_LOCKFILE
  × resolve package manager dependencies
  ╰─▶ Cannot update packageManagerDependencies with "frozen-lockfile" because
      the lockfile is not up to date

Still e2e/package.jsonpnpm@12.4.1 vs e2e/pnpm-lock.yaml12.3.4. Still invisible to every check in this repo, still breaks e2e/Dockerfile:14.

The rest of the batch is clean, harper 5.2.12 included

Applied only the one-file ErrorProps fix, nothing else:

tsc -b --force   exit 0
pnpm test        346 files — 3144 passed | 11 skipped (3155)
pnpm lint        exit 0  (oxlint, clean)
pnpm format      exit 0  (dprint, clean)
vite build       ✓ built in 2.77s

And regenerating the e2e lockfile (cd e2e && pnpm install --ignore-scripts) still produces a delta confined to packageManagerDependencies 12.3.412.4.1 and the @pnpm/exe.* platform entries — no test-dependency movement — after which pnpm install --frozen-lockfile in e2e/ is clean.

The fix, for reference

 interface ErrorProps {
 	className?: string | undefined;
-	error: Error | { message: string | ReactNode };
+	error: unknown;
 	title?: string;
 	showReturnToHome?: boolean;
 	children?: ReactNode;
 }
 
+function getErrorMessage(error: unknown): ReactNode {
+	if (error instanceof Error) { return error.message; }
+	if (typeof error === 'object' && error !== null && 'message' in error) {
+		return (error as { message: ReactNode }).message;
+	}
+	if (typeof error === 'string') { return error; }
+	return 'An unexpected error occurred.';
+}
+
 export function ErrorComponent({ className, error, title, showReturnToHome, children }: ErrorProps) {
...
-				<CardDescription>{error.message}</CardDescription>
+				<CardDescription>{getErrorMessage(error)}</CardDescription>

That is dprint-clean as written. It also closes the latent bug I flagged earlier: {error.message} renders nothing today when a string is thrown.

Ask (unchanged)

  1. Widen ErrorProps.error rather than pinning the router.
  2. cd e2e && pnpm install --ignore-scripts and commit the lockfile.

This PR has now been re-pushed four days running with the same two lines outstanding. Say the word and I'll push both onto the branch.

…e change

Two things in this batch needed work before it could go green. This commit
takes the four updates that are safe as-is and defers the one that isn't.

**Deferred: the TanStack router pair.** `@tanstack/react-router`
1.170.32 -> 1.170.36 breaks `tsc -b`:

    src/router/useNewRouter.ts(25,4): error TS2322:
      Type '({ className, error, ... }: ErrorProps) => Element'
        is not assignable to type 'ErrorRouteComponent | undefined'.

`router-core` now types the boundary error as `unknown`, our
`ErrorComponent` declares `error: Error | { message: string | ReactNode }`,
and the parameter position is contravariant. That is an intentional
upstream change, not a regression, so the fix belongs in our
`ErrorProps` -- which makes it a source change, not a dependency bump,
and it wants its own review. Reverted to 1.170.32 here.

`@tanstack/react-router-devtools` 1.167.2 reverts with it, not as
collateral: its peer range is `@tanstack/react-router: ^1.170.36`, so
keeping the devtools bump against a 1.170.32 router would be an unmet
peer. 1.167.1 wants `^1.170.19`, which 1.170.32 satisfies. `pnpm peers
check` reports exactly one unmet peer on this head (`@aws-sdk/client-s3`,
pre-existing and unrelated) -- identical to the batch before this commit.

**Fixed: the e2e lockfile.** The batch bumps `e2e/package.json`'s
`packageManager` to `pnpm@12.4.1`. pnpm 12 records that in the lockfile
as `packageManagerDependencies`, and the Renovate artifact step that
would have refreshed it died on
`ERR_PNPM_STRICT_MIN_RELEASE_AGE_REQUIRES_SAVE`, so the two disagreed and
`e2e/Dockerfile`'s `pnpm install --frozen-lockfile` failed outright. No
check in this repo covers it -- the e2e harness runs from the
out-of-repo trusted-lane scheduler -- so it would have landed green and
broken the e2e lane later. Regenerated; the delta is
`packageManagerDependencies` and the `@pnpm/exe.*` platform entries and
nothing else. No test dependency moves.

What this batch still carries: Node 24.20.0 -> 24.21.0 (`.nvmrc` and the
e2e Dockerfile base), pnpm 12.3.4 -> 12.4.1 in both manifests,
`zod` 4.5.4 -> 4.6.5, and `harper` 5.2.9 -> 5.2.12 (dev).

Verified on this head, with no source files touched:

    pnpm install --frozen-lockfile   exit 0  (root and e2e)
    tsc -b --force                   exit 0
    pnpm test                        346 files - 3144 passed | 11 skipped
    pnpm lint                        exit 0  (oxlint)
    pnpm format                      exit 0  (dprint)
    pnpm build                       exit 0  (built in 2.84s)

Note that Renovate will re-propose the router pair on its next run; the
durable fix is to widen `ErrorProps.error` to `unknown` and narrow before
reading `.message`, which also closes a live latent bug -- `{error.message}`
renders nothing today when a string is thrown.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@renovate

renovate Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@github-actions

Copy link
Copy Markdown

Coverage Report

Status Category Percentage Covered / Total
🔵 Lines 63.23% 8886 / 14052
🔵 Statements 63.56% 9490 / 14930
🔵 Functions 55.82% 2227 / 3989
🔵 Branches 57.21% 6472 / 11312
File CoverageNo changed files found.
Generated in workflow #1929 for commit eb69f15 by the Vitest Coverage Report Action

@dawsontoth
dawsontoth dismissed their stale review September 18, 2026 14:57

Both blockers are resolved in eb69f15 — the router pair is deferred out of the batch and the e2e lockfile is regenerated. Verify PR and Verify Commits are green. Dismissing my own stale review; this still needs a human approval.

@dawsontoth

Copy link
Copy Markdown
Contributor

Took this over and pushed eb69f15f. The batch now carries only the updates that land without a source change, and both checks are greenVerify PR and Verify Commits. I've dismissed my own changes-requested; this still wants a human approval.

What's still in

from to
Node (.nvmrc + e2e Dockerfile base) 24.20.0 24.21.0
pnpm (packageManager, both manifests) 12.3.4 12.4.1
zod 4.5.4 4.6.5
harper (dev) 5.2.9 5.2.12

What came out, and why the devtools came with it

@tanstack/react-router is back at 1.170.32. The 1.170.36 bump needs ErrorProps widened, which is a source change wanting its own review rather than a line in a dependency batch.

@tanstack/react-router-devtools reverted to 1.167.1 alongside it — not as collateral, but because it had to. I checked the peer ranges rather than assuming the devtools bump was independently safe:

peer @tanstack/react-router
react-router-devtools@1.167.2 ^1.170.36
react-router-devtools@1.167.1 ^1.170.19

So keeping 1.167.2 against a 1.170.32 router would have left an unmet peer. This also corrects something in my earlier comment: I'd written that the devtools bump was "verified clean" from my isolation test, where I reverted only the router. That test did typecheck — but it was sitting on an unmet peer I didn't check for at the time. Reverting the pair together is the correct move, and pnpm peers check now reports exactly one unmet peer on this head (@aws-sdk/client-s3, pre-existing and unrelated) — byte-identical to what the unmodified batch reported, which is the comparison that actually settles it.

The e2e lockfile is fixed, not deferred

Regenerated e2e/pnpm-lock.yaml, so packageManagerDependencies now agrees with e2e/package.json at pnpm@12.4.1 and e2e/Dockerfile:14's frozen install works again. The delta is that key plus the @pnpm/exe.* platform entries and nothing else — I diffed it with the platform noise filtered out and the remainder was empty. No test dependency moves.

Verification — no source files touched

pnpm install --frozen-lockfile   exit 0   (root)
pnpm install --frozen-lockfile   exit 0   (e2e)
tsc -b --force                   exit 0
pnpm test                        346 files — 3144 passed | 11 skipped (3155)
pnpm lint                        exit 0   (oxlint)
pnpm format                      exit 0   (dprint)
pnpm build                       exit 0   (built in 2.84s)

git status at the end: only package.json, pnpm-lock.yaml and e2e/pnpm-lock.yaml.

One thing to decide, not urgent

Renovate will re-propose the router pair on its next run — nothing here holds it back, and renovate/artifacts will fail the same way again the next time a batch touches e2e/. So this buys a clean landing now, not a permanent fix.

The durable fix is still the one-file change: widen ErrorProps.error to unknown and narrow before reading .message. It also closes a live latent bug — {error.message} renders nothing today when a string is thrown. I have it written and verified (tsc 0, full suite green, dprint-clean). Say the word and I'll open it as its own PR, which is where a source change of that kind belongs.

@dawsontoth
dawsontoth marked this pull request as ready for review September 18, 2026 15:01
@dawsontoth
dawsontoth added this pull request to the merge queue Sep 18, 2026
Merged via the queue into stage with commit 267aee7 Sep 18, 2026
3 checks passed
@dawsontoth
dawsontoth deleted the renovate/all-minor-patch branch September 18, 2026 15:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant