Skip to content

chore(deps): batch Next, React, R3F and Bun upgrades - #1021

Merged
pascal[bot] merged 4 commits into
mainfrom
fleet/bot-dependencies/xml-parser-20261008
Oct 10, 2026
Merged

pascal[bot] merged 4 commits into
mainfrom
fleet/bot-dependencies/xml-parser-20261008

Conversation

@pascal

@pascal pascal Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Changes

Reuse the existing XML-parser upgrade branch for the daily dependency batch:

  • Next.js and its ESLint plugin: 16.3.0 to 16.4.0.
  • React, React DOM and their types: 19.3.0 across the workspace; R3F: 9.8.1.
  • Bun package-manager declaration and Bun types: 1.4.2.
  • Dev-only fast-xml-parser: 5.11.2.

The branch also aligns the vendored pointer-event provenance and installed-version regression with R3F 9.8.1. Root overrides pin the React/R3F versions; independent review must verify compatibility and the vendored implementation, not assume the label change proves parity. The diff spans 14 files, including manifests, bun.lock and the pointer-event implementation/test.

Validation

Current head: c1572c2.
GitHub checks on this exact head passed: quality, cli-smoke, Changed paths and ci (run 38090816790 and run 38090816781). GitHub reports the draft mergeable.

Earlier local validation in this PR covered an older XML-only head and does not validate this expanded batch. Independent repository-native validation and guarded review are still required. No merge, publication or deployed acceptance is claimed.


Note

Medium Risk
Upgrades the full React/Next/R3F runtime and re-baselines vendored 3D pointer-event logic; regressions could affect rendering, routing, and editor interaction unless differential tests and CI cover the new stack.

Overview
Batches a monorepo dependency upgrade: Next.js 16.4.0, React / React DOM 19.3.0 (with matching @types), and @react-three/fiber 9.8.1 across apps and packages. Root package.json overrides now also pin react, react-dom, and @react-three/fiber so the workspace resolves a single stack.

Bun is bumped to 1.4.2 (packageManager and @types/bun). fast-xml-parser moves to 5.11.2 at the root and in editor-related dev deps. @next/eslint-plugin-next follows Next at 16.4.0. bun.lock reflects transitive updates (e.g. sharp, scheduler) from those bumps.

In @pascal-app/viewer, the vendored pointer-events.ts provenance and the differential test’s version pin are updated from R3F 9.6.1 → 9.8.1 so custom pointer/camera-drag behavior stays aligned with the installed fiber version.

Reviewed by Cursor Bugbot for commit c1572c2. Bugbot is set up for automated code reviews on this repo. Configure here.

@pascal pascal Bot changed the title chore(deps): update XML validation and print test parser chore(deps): batch Next, React, R3F and Bun upgrades Oct 10, 2026
@pascal
pascal Bot marked this pull request as ready for review October 10, 2026 22:50
@pascal
pascal Bot merged commit 1a6eb14 into main Oct 10, 2026
4 checks passed

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want reviews to match your repository better? Bugbot Learning can learn team-specific rules from PR activity. A team admin can enable Learning in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit c1572c2. Configure here.

Comment thread package.json
"node": ">=20.9.0"
},
"packageManager": "bun@1.3.14",
"packageManager": "bun@1.4.2",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bun version pins left mismatched

Medium Severity

packageManager now declares bun@1.4.2, but Dockerfile and .github/workflows/release.yml still install 1.3.14. Those files already document that this skew makes bun install --frozen-lockfile fail, so Docker builds and release publishes can break while main CI, which reads package.json, still passes.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit c1572c2. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants