From d60622907cacf886fadceb1fae942d6721f8edab Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 25 Aug 2026 15:07:51 +0000 Subject: [PATCH 1/3] Bump the npm_and_yarn group across 1 directory with 3 updates Bumps the npm_and_yarn group with 3 updates in the /frontend directory: [js-yaml](https://github.com/nodeca/js-yaml), [brace-expansion](https://github.com/juliangruber/brace-expansion) and [deepmerge-ts](https://github.com/RebeccaStevens/deepmerge-ts). Updates `js-yaml` from 4.3.0 to 4.3.1 - [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md) - [Commits](https://github.com/nodeca/js-yaml/compare/4.3.0...4.3.1) Updates `brace-expansion` from 1.1.15 to 1.1.18 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.15...v1.1.18) Updates `deepmerge-ts` from 7.1.5 to 8.0.2 - [Release notes](https://github.com/RebeccaStevens/deepmerge-ts/releases) - [Changelog](https://github.com/RebeccaStevens/deepmerge-ts/blob/main/CHANGELOG.md) - [Commits](https://github.com/RebeccaStevens/deepmerge-ts/compare/v7.1.5...v8.0.2) --- updated-dependencies: - dependency-name: js-yaml dependency-version: 4.3.1 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: brace-expansion dependency-version: 1.1.18 dependency-type: indirect dependency-group: npm_and_yarn - dependency-name: deepmerge-ts dependency-version: 8.0.2 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] --- frontend/package-lock.json | 158 +++++++++++++++++++------------------ frontend/package.json | 8 +- 2 files changed, 84 insertions(+), 82 deletions(-) diff --git a/frontend/package-lock.json b/frontend/package-lock.json index 70fcadf92..991d77689 100644 --- a/frontend/package-lock.json +++ b/frontend/package-lock.json @@ -20,7 +20,7 @@ "@vitejs/plugin-react": "^5.0.0", "autoprefixer": "^10.4.21", "fracturedjsonjs": "^5.0.1", - "js-yaml": "^4.3.0", + "js-yaml": "^4.3.1", "loglevel": "^1.9.2", "npm-run-all2": "^7.0.2", "ome-zarr.js": "^0.0.17", @@ -31,10 +31,10 @@ "react-hot-toast": "^2.5.2", "react-icons": "^5.5.0", "react-resizable-panels": "^3.0.2", - "react-router": "^7.18.2", - "react-shepherd": "^6.1.9", + "react-router": "^8.3.0", + "react-shepherd": "^7.0.6", "react-syntax-highlighter": "^16.1.0", - "shepherd.js": "^14.5.1", + "shepherd.js": "^15.3.0", "tailwindcss": "^3.4.17", "zarrita": "^0.7.3", "zod": "^4.3.6" @@ -967,9 +967,9 @@ "license": "MIT" }, "node_modules/@eslint/config-array/node_modules/brace-expansion": { - "version": "1.1.15", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", - "integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", + "version": "1.1.18", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.18.tgz", + "integrity": "sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==", "dev": true, "license": "MIT", "dependencies": { @@ -1090,9 +1090,9 @@ "license": "MIT" }, "node_modules/@eslint/eslintrc/node_modules/brace-expansion": { - "version": "1.1.15", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", - "integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", + "version": "1.1.18", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.18.tgz", + "integrity": "sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==", "dev": true, "license": "MIT", "dependencies": { @@ -1256,28 +1256,28 @@ } }, "node_modules/@floating-ui/core": { - "version": "1.7.5", - "resolved": "https://registry.npmjs.org/@floating-ui/core/-/core-1.7.5.tgz", - "integrity": "sha512-1Ih4WTWyw0+lKyFMcBHGbb5U5FtuHJuujoyyr5zTaWS5EYMeT6Jb2AuDeftsCsEuchO+mM2ij5+q9crhydzLhQ==", + "version": "1.8.0", + "resolved": "https://registry.npmjs.org/@floating-ui/core/-/core-1.8.0.tgz", + "integrity": "sha512-0CIZ5itps/8x7BG8dEIhs53BvCUH2PCoogtakwRTut+Arm58sJooJ0AuZhLw2HJYIR5cMLNPBSS728sPho2khQ==", "license": "MIT", "dependencies": { - "@floating-ui/utils": "^0.2.11" + "@floating-ui/utils": "^0.2.12" } }, "node_modules/@floating-ui/dom": { - "version": "1.7.6", - "resolved": "https://registry.npmjs.org/@floating-ui/dom/-/dom-1.7.6.tgz", - "integrity": "sha512-9gZSAI5XM36880PPMm//9dfiEngYoC6Am2izES1FF406YFsjvyBMmeJ2g4SAju3xWwtuynNRFL2s9hgxpLI5SQ==", + "version": "1.8.0", + "resolved": "https://registry.npmjs.org/@floating-ui/dom/-/dom-1.8.0.tgz", + "integrity": "sha512-yXSrzeHZBTZadLOlfyhCkJHNeLJnHRnRInwdZ40L7ZiaAtrBwoYlsDrX3v5zB1Utk7CLfzcOVnVVWoXEky7Ceg==", "license": "MIT", "dependencies": { - "@floating-ui/core": "^1.7.5", - "@floating-ui/utils": "^0.2.11" + "@floating-ui/core": "^1.8.0", + "@floating-ui/utils": "^0.2.12" } }, "node_modules/@floating-ui/utils": { - "version": "0.2.11", - "resolved": "https://registry.npmjs.org/@floating-ui/utils/-/utils-0.2.11.tgz", - "integrity": "sha512-RiB/yIh78pcIxl6lLMG0CgBXAZ2Y0eVHqMPYugu+9U0AeT6YBeiJpf7lbdJNIugFP5SIjwNRgo4DhR1Qxi26Gg==", + "version": "0.2.12", + "resolved": "https://registry.npmjs.org/@floating-ui/utils/-/utils-0.2.12.tgz", + "integrity": "sha512-HpCo8tmWzLVad5s2d19EhAz5zqrrQ6s69qd6moPMQvkOuSwDT1YgRfWSVuc4ennqrgv3OHppiOGMQ7oC13yIww==", "license": "MIT" }, "node_modules/@humanfs/core": { @@ -2668,13 +2668,6 @@ } } }, - "node_modules/@scarf/scarf": { - "version": "1.4.0", - "resolved": "https://registry.npmjs.org/@scarf/scarf/-/scarf-1.4.0.tgz", - "integrity": "sha512-xxeapPiUXdZAE3che6f3xogoJPeZgig6omHEy1rIY5WVsB3H2BHNnZH+gHG6x91SCWyQCzWGsuL2Hh3ClO5/qQ==", - "hasInstallScript": true, - "license": "Apache-2.0" - }, "node_modules/@standard-schema/spec": { "version": "1.1.0", "resolved": "https://registry.npmjs.org/@standard-schema/spec/-/spec-1.1.0.tgz", @@ -4488,16 +4481,16 @@ "license": "MIT" }, "node_modules/brace-expansion": { - "version": "5.0.6", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.6.tgz", - "integrity": "sha512-kLpxurY4Z4r9sgMsyG0Z9uzsBlgiU/EFKhj/h91/8yHu0edo7XuixOIH3VcJ8kkxs6/jPzoI6U9Vj3WqbMQ94g==", + "version": "5.0.9", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.9.tgz", + "integrity": "sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==", "dev": true, "license": "MIT", "dependencies": { "balanced-match": "^4.0.2" }, "engines": { - "node": "18 || 20 || >=22" + "node": "20 || >=22" } }, "node_modules/braces": { @@ -5126,6 +5119,7 @@ "version": "1.1.1", "resolved": "https://registry.npmjs.org/cookie/-/cookie-1.1.1.tgz", "integrity": "sha512-ei8Aos7ja0weRpFzJnEA9UHJ/7XQmqglbRwnf2ATjcB9Wq874VKH9kfjjirM6UhU2/E5fFYadylyhFldcqSidQ==", + "dev": true, "license": "MIT", "engines": { "node": ">=18" @@ -5135,6 +5129,12 @@ "url": "https://opencollective.com/express" } }, + "node_modules/cookie-es": { + "version": "3.1.1", + "resolved": "https://registry.npmjs.org/cookie-es/-/cookie-es-3.1.1.tgz", + "integrity": "sha512-UaXxwISYJPTr9hwQxMFYZ7kNhSXboMXP+Z3TRX6f1/NyaGPfuNUZOWP1pUEb75B2HjfklIYLVRfWiFZJyC6Npg==", + "license": "MIT" + }, "node_modules/core-util-is": { "version": "1.0.3", "resolved": "https://registry.npmjs.org/core-util-is/-/core-util-is-1.0.3.tgz", @@ -5373,12 +5373,22 @@ } }, "node_modules/deepmerge-ts": { - "version": "7.1.5", - "resolved": "https://registry.npmjs.org/deepmerge-ts/-/deepmerge-ts-7.1.5.tgz", - "integrity": "sha512-HOJkrhaYsweh+W+e74Yn7YStZOilkoPb6fycpwNLKzSPtruFs48nYis0zy5yJz1+ktUhHxoRDJ27RQAWLIJVJw==", + "version": "8.0.2", + "resolved": "https://registry.npmjs.org/deepmerge-ts/-/deepmerge-ts-8.0.2.tgz", + "integrity": "sha512-uqbvqLUMrc6p0MO+WBRtTxY55hmyh94WRwI5a++PZe54X+bfVh59FSN7uWCBCW1CCVjzjnrwzfI8zidE2obMMw==", + "funding": [ + { + "type": "ko-fi", + "url": "https://ko-fi.com/rebeccastevens" + }, + { + "type": "tidelift", + "url": "https://tidelift.com/funding/github/npm/deepmerge-ts" + } + ], "license": "BSD-3-Clause", "engines": { - "node": ">=16.0.0" + "node": ">=16.9.0" } }, "node_modules/default-browser": { @@ -6081,9 +6091,9 @@ "license": "MIT" }, "node_modules/eslint-plugin-react/node_modules/brace-expansion": { - "version": "1.1.15", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", - "integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", + "version": "1.1.18", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.18.tgz", + "integrity": "sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==", "dev": true, "license": "MIT", "dependencies": { @@ -6217,9 +6227,9 @@ "license": "MIT" }, "node_modules/eslint/node_modules/brace-expansion": { - "version": "1.1.15", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz", - "integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==", + "version": "1.1.18", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.18.tgz", + "integrity": "sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==", "dev": true, "license": "MIT", "dependencies": { @@ -7846,9 +7856,9 @@ "license": "MIT" }, "node_modules/js-yaml": { - "version": "4.3.0", - "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.0.tgz", - "integrity": "sha512-1td788aAnnZ5qs7V2QIRl1owjtYpbKt749Y3xauqQgwIIGF/xXWz1wMTEBx5O3LK3lXLVuqXPdPxj2BoFHaW9Q==", + "version": "4.3.1", + "resolved": "https://registry.npmjs.org/js-yaml/-/js-yaml-4.3.1.tgz", + "integrity": "sha512-CY6crGq313MX8GkwvB7tzgp99vjQxY1++5y10/BKN/GUfHqWaOGQMNZkBvqSzsZKWk/ijwHlWzzkLulsGHhjWQ==", "funding": [ { "type": "github", @@ -9830,9 +9840,9 @@ "license": "MIT" }, "node_modules/npm-run-all2/node_modules/brace-expansion": { - "version": "2.1.1", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.1.1.tgz", - "integrity": "sha512-WR1cURNjuvBLMZBMbqM0UoE+WAfdUcEV1ccD8PVBVOI+Z3ND4+SZbN8RsfT2bMuG1qwz5RFvPukSZm5fF2D5eA==", + "version": "2.1.4", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-2.1.4.tgz", + "integrity": "sha512-hGfVzPxthbf3+2yjg/RBs60cB0FhqBS/zvdV/4wn4/BmN0bNMMHPc4V/BbFieqf1TKAGGAHnY4eSjajCl0f2Xg==", "license": "MIT", "dependencies": { "balanced-match": "^1.0.0" @@ -10996,20 +11006,19 @@ } }, "node_modules/react-router": { - "version": "7.18.2", - "resolved": "https://registry.npmjs.org/react-router/-/react-router-7.18.2.tgz", - "integrity": "sha512-aUVMjFm3GAPTTZL7oYr5E7ETiqfQCHRLH+B+5afnICvf0r7kkK4eR6SMuwbSTJw/7t+12khT/Kahij49fqOCIg==", + "version": "8.3.0", + "resolved": "https://registry.npmjs.org/react-router/-/react-router-8.3.0.tgz", + "integrity": "sha512-qyPMvW83jGIct3yiieisxdk9M745anqhpIMKN5m1t6yBMfgVPpt77aHOqs5fUlEJRMCGffg9BaQLH9oPVOL7xQ==", "license": "MIT", "dependencies": { - "cookie": "^1.0.1", - "set-cookie-parser": "^2.6.0" + "cookie-es": "^3.1.1" }, "engines": { - "node": ">=20.0.0" + "node": ">=22.22.0" }, "peerDependencies": { - "react": ">=18", - "react-dom": ">=18" + "react": ">=19.2.7", + "react-dom": ">=19.2.7" }, "peerDependenciesMeta": { "react-dom": { @@ -11017,24 +11026,18 @@ } } }, - "node_modules/react-router/node_modules/set-cookie-parser": { - "version": "2.7.2", - "resolved": "https://registry.npmjs.org/set-cookie-parser/-/set-cookie-parser-2.7.2.tgz", - "integrity": "sha512-oeM1lpU/UvhTxw+g3cIfxXHyJRc/uidd3yK1P242gzHds0udQBYzs3y8j4gCCW+ZJ7ad0yctld8RYO+bdurlvw==", - "license": "MIT" - }, "node_modules/react-shepherd": { - "version": "6.1.9", - "resolved": "https://registry.npmjs.org/react-shepherd/-/react-shepherd-6.1.9.tgz", - "integrity": "sha512-kSFs7ER9+tDAQ9a80CGTaWHpuNf/6RNnnAqtPxFqZSt5NnlKi6T8/E93sYMPOibhvdtpG5pIZpeT3JI1+Ppqiw==", - "license": "MIT", + "version": "7.0.6", + "resolved": "https://registry.npmjs.org/react-shepherd/-/react-shepherd-7.0.6.tgz", + "integrity": "sha512-TzMY/KhzJ8KWT8nrG2Y/Jin5NakNUdbt3QR+TyzKGDippZwnTCKeddsaOOLvlm4SImhVwPB54yftvSKtAQhSQQ==", + "license": "AGPL-3.0", "dependencies": { - "shepherd.js": "14.5.1" + "shepherd.js": "15.3.0" }, "peerDependencies": { - "react": "^18.2.0", - "react-dom": "^18.2.0", - "typescript": "^5.0.0" + "react": "^18.0.0 || ^19.0.0", + "react-dom": "^18.0.0 || ^19.0.0", + "typescript": "^5.0.0 || ^6.0.0 || ^7.0.0" } }, "node_modules/react-syntax-highlighter": { @@ -11663,17 +11666,16 @@ } }, "node_modules/shepherd.js": { - "version": "14.5.1", - "resolved": "https://registry.npmjs.org/shepherd.js/-/shepherd.js-14.5.1.tgz", - "integrity": "sha512-VuvPvLG1QjNOLP7AIm2HGyfmxEIz8QdskvWOHwUcxLDibYWjLRBmCWd8LSL5FlwhBW7D/GU+3gNVC/ASxAWdxg==", + "version": "15.3.0", + "resolved": "https://registry.npmjs.org/shepherd.js/-/shepherd.js-15.3.0.tgz", + "integrity": "sha512-A9plZQ1qGX1aDLTrX0cbVowdnE0mOc1pjRie7O9c2cQHiDHI1zaxH2fVe65WH/2ch5nbK0JPu+vQecD7WYw5zw==", "license": "AGPL-3.0", "dependencies": { - "@floating-ui/dom": "^1.7.0", - "@scarf/scarf": "^1.4.0", - "deepmerge-ts": "^7.1.1" + "@floating-ui/dom": "^1.8.0", + "deepmerge-ts": "^8.0.0" }, "engines": { - "node": "18.* || >= 20" + "node": ">= 20" } }, "node_modules/side-channel": { diff --git a/frontend/package.json b/frontend/package.json index 3c2619a07..b27301cb9 100644 --- a/frontend/package.json +++ b/frontend/package.json @@ -42,7 +42,7 @@ "@vitejs/plugin-react": "^5.0.0", "autoprefixer": "^10.4.21", "fracturedjsonjs": "^5.0.1", - "js-yaml": "^4.3.0", + "js-yaml": "^4.3.1", "loglevel": "^1.9.2", "npm-run-all2": "^7.0.2", "ome-zarr.js": "^0.0.17", @@ -53,10 +53,10 @@ "react-hot-toast": "^2.5.2", "react-icons": "^5.5.0", "react-resizable-panels": "^3.0.2", - "react-router": "^7.18.2", - "react-shepherd": "^6.1.9", + "react-router": "^8.3.0", + "react-shepherd": "^7.0.6", "react-syntax-highlighter": "^16.1.0", - "shepherd.js": "^14.5.1", + "shepherd.js": "^15.3.0", "tailwindcss": "^3.4.17", "zarrita": "^0.7.3", "zod": "^4.3.6" From 9bb3d1a5b36e9ac0c99ec1797a2ef55ad5d57b37 Mon Sep 17 00:00:00 2001 From: Allison Truhlar Date: Wed, 16 Sep 2026 10:50:57 -0400 Subject: [PATCH 2/3] fix(deps): revert unintended react-router 7->8 major bump from dependabot PR dependabot's grouped npm_and_yarn update pinned react-router to ^8.3.0, which requires react>=19.2.7, conflicting with this repo's react ^18.3.1. Keep react-router on ^7.x and retain the intended js-yaml, brace-expansion, and deepmerge-ts bumps. --- frontend/package-lock.json | 30 +++++++++++++++--------------- frontend/package.json | 2 +- 2 files changed, 16 insertions(+), 16 deletions(-) diff --git a/frontend/package-lock.json b/frontend/package-lock.json index 991d77689..5c6df725b 100644 --- a/frontend/package-lock.json +++ b/frontend/package-lock.json @@ -31,7 +31,7 @@ "react-hot-toast": "^2.5.2", "react-icons": "^5.5.0", "react-resizable-panels": "^3.0.2", - "react-router": "^8.3.0", + "react-router": "^7.18.2", "react-shepherd": "^7.0.6", "react-syntax-highlighter": "^16.1.0", "shepherd.js": "^15.3.0", @@ -5119,7 +5119,6 @@ "version": "1.1.1", "resolved": "https://registry.npmjs.org/cookie/-/cookie-1.1.1.tgz", "integrity": "sha512-ei8Aos7ja0weRpFzJnEA9UHJ/7XQmqglbRwnf2ATjcB9Wq874VKH9kfjjirM6UhU2/E5fFYadylyhFldcqSidQ==", - "dev": true, "license": "MIT", "engines": { "node": ">=18" @@ -5129,12 +5128,6 @@ "url": "https://opencollective.com/express" } }, - "node_modules/cookie-es": { - "version": "3.1.1", - "resolved": "https://registry.npmjs.org/cookie-es/-/cookie-es-3.1.1.tgz", - "integrity": "sha512-UaXxwISYJPTr9hwQxMFYZ7kNhSXboMXP+Z3TRX6f1/NyaGPfuNUZOWP1pUEb75B2HjfklIYLVRfWiFZJyC6Npg==", - "license": "MIT" - }, "node_modules/core-util-is": { "version": "1.0.3", "resolved": "https://registry.npmjs.org/core-util-is/-/core-util-is-1.0.3.tgz", @@ -11006,19 +10999,20 @@ } }, "node_modules/react-router": { - "version": "8.3.0", - "resolved": "https://registry.npmjs.org/react-router/-/react-router-8.3.0.tgz", - "integrity": "sha512-qyPMvW83jGIct3yiieisxdk9M745anqhpIMKN5m1t6yBMfgVPpt77aHOqs5fUlEJRMCGffg9BaQLH9oPVOL7xQ==", + "version": "7.18.4", + "resolved": "https://registry.npmjs.org/react-router/-/react-router-7.18.4.tgz", + "integrity": "sha512-PUPQcMhMGRAslLcvtlPz/kmzBEWPhLdgLFrL7pLNepBL6dX0lWj4WD2cUYVgYCuT3jxvghYFg81cDTj44DhetQ==", "license": "MIT", "dependencies": { - "cookie-es": "^3.1.1" + "cookie": "^1.0.1", + "set-cookie-parser": "^2.6.0" }, "engines": { - "node": ">=22.22.0" + "node": ">=20.0.0" }, "peerDependencies": { - "react": ">=19.2.7", - "react-dom": ">=19.2.7" + "react": ">=18", + "react-dom": ">=18" }, "peerDependenciesMeta": { "react-dom": { @@ -11026,6 +11020,12 @@ } } }, + "node_modules/react-router/node_modules/set-cookie-parser": { + "version": "2.7.2", + "resolved": "https://registry.npmjs.org/set-cookie-parser/-/set-cookie-parser-2.7.2.tgz", + "integrity": "sha512-oeM1lpU/UvhTxw+g3cIfxXHyJRc/uidd3yK1P242gzHds0udQBYzs3y8j4gCCW+ZJ7ad0yctld8RYO+bdurlvw==", + "license": "MIT" + }, "node_modules/react-shepherd": { "version": "7.0.6", "resolved": "https://registry.npmjs.org/react-shepherd/-/react-shepherd-7.0.6.tgz", diff --git a/frontend/package.json b/frontend/package.json index b27301cb9..215d9a0d3 100644 --- a/frontend/package.json +++ b/frontend/package.json @@ -53,7 +53,7 @@ "react-hot-toast": "^2.5.2", "react-icons": "^5.5.0", "react-resizable-panels": "^3.0.2", - "react-router": "^8.3.0", + "react-router": "^7.18.2", "react-shepherd": "^7.0.6", "react-syntax-highlighter": "^16.1.0", "shepherd.js": "^15.3.0", From 37d31c595f2bb6260f5a8b2ab03fa0e228597ddc Mon Sep 17 00:00:00 2001 From: Allison Truhlar Date: Wed, 16 Sep 2026 14:35:25 -0400 Subject: [PATCH 3/3] fix(deps): drop react-shepherd; use the shepherd.js singleton directly react-shepherd@7.0.6 (pulled in by the shepherd.js 14->15 bump that the deepmerge-ts CVE fix requires) ships a dist bundle with React 19's jsx-runtime inlined. Its ShepherdJourneyProvider therefore creates elements tagged Symbol.for("react.transitional.element"), which React 18 rejects as an invalid child (minified error #31). Because the provider wrapped MainLayout's whole subtree, every page load crashed before the login form rendered, failing all 33 Playwright tests. react-shepherd is only a context wrapper around the shepherd.js singleton, so replace it: StartTour imports Shepherd from shepherd.js directly and MainLayout no longer needs the provider. deepmerge-ts now resolves to 8.0.2 (fixes GHSA-ggr8-5vv4-36mx / Dependabot alert #73). Verified: node-check (no new errors), test-frontend 316/316, test-ui 33/33, test-backend 772/772, and a headless smoke test of the onboarding tour (start, choose workflow, Next, cancel) with no console or page errors. --- frontend/package-lock.json | 16 +--------------- frontend/package.json | 1 - frontend/src/components/tours/StartTour.tsx | 21 ++++++++++----------- frontend/src/layouts/MainLayout.tsx | 5 ++--- 4 files changed, 13 insertions(+), 30 deletions(-) diff --git a/frontend/package-lock.json b/frontend/package-lock.json index 5c6df725b..7c2b9477a 100644 --- a/frontend/package-lock.json +++ b/frontend/package-lock.json @@ -32,7 +32,6 @@ "react-icons": "^5.5.0", "react-resizable-panels": "^3.0.2", "react-router": "^7.18.2", - "react-shepherd": "^7.0.6", "react-syntax-highlighter": "^16.1.0", "shepherd.js": "^15.3.0", "tailwindcss": "^3.4.17", @@ -11026,20 +11025,6 @@ "integrity": "sha512-oeM1lpU/UvhTxw+g3cIfxXHyJRc/uidd3yK1P242gzHds0udQBYzs3y8j4gCCW+ZJ7ad0yctld8RYO+bdurlvw==", "license": "MIT" }, - "node_modules/react-shepherd": { - "version": "7.0.6", - "resolved": "https://registry.npmjs.org/react-shepherd/-/react-shepherd-7.0.6.tgz", - "integrity": "sha512-TzMY/KhzJ8KWT8nrG2Y/Jin5NakNUdbt3QR+TyzKGDippZwnTCKeddsaOOLvlm4SImhVwPB54yftvSKtAQhSQQ==", - "license": "AGPL-3.0", - "dependencies": { - "shepherd.js": "15.3.0" - }, - "peerDependencies": { - "react": "^18.0.0 || ^19.0.0", - "react-dom": "^18.0.0 || ^19.0.0", - "typescript": "^5.0.0 || ^6.0.0 || ^7.0.0" - } - }, "node_modules/react-syntax-highlighter": { "version": "16.1.1", "resolved": "https://registry.npmjs.org/react-syntax-highlighter/-/react-syntax-highlighter-16.1.1.tgz", @@ -12607,6 +12592,7 @@ "version": "5.8.3", "resolved": "https://registry.npmjs.org/typescript/-/typescript-5.8.3.tgz", "integrity": "sha512-p1diW6TqL9L07nNxvRMM7hMMw4c5XOo/1ibL4aAIGmSAt9slTE1Xgw5KWuof2uTOvCg9BY7ZRi+GaF+7sfgPeQ==", + "dev": true, "license": "Apache-2.0", "bin": { "tsc": "bin/tsc", diff --git a/frontend/package.json b/frontend/package.json index 215d9a0d3..df7fd4f86 100644 --- a/frontend/package.json +++ b/frontend/package.json @@ -54,7 +54,6 @@ "react-icons": "^5.5.0", "react-resizable-panels": "^3.0.2", "react-router": "^7.18.2", - "react-shepherd": "^7.0.6", "react-syntax-highlighter": "^16.1.0", "shepherd.js": "^15.3.0", "tailwindcss": "^3.4.17", diff --git a/frontend/src/components/tours/StartTour.tsx b/frontend/src/components/tours/StartTour.tsx index 8768fc350..155324e1f 100644 --- a/frontend/src/components/tours/StartTour.tsx +++ b/frontend/src/components/tours/StartTour.tsx @@ -1,7 +1,7 @@ import { Button } from '@material-tailwind/react'; import type { ButtonProps } from '@material-tailwind/react'; import { useNavigate } from 'react-router'; -import { useShepherd } from 'react-shepherd'; +import Shepherd from 'shepherd.js'; import type { Tour } from 'shepherd.js'; import { tourSteps, backButton, exitButton } from './tourSteps'; import { useZoneAndFspMapContext } from '@/contexts/ZonesAndFspMapContext'; @@ -33,7 +33,6 @@ export default function StartTour({ ...buttonProps }: StartTourProps) { const navigate = useNavigate(); - const shepherd = useShepherd(); const { zonesAndFspQuery } = useZoneAndFspMapContext(); // Check if running on Janelia filesystem @@ -205,7 +204,7 @@ export default function StartTour({ { text: 'Take Another Tour', action: function (this: any) { - const currentTour = shepherd.activeTour as Tour; + const currentTour = Shepherd.activeTour as Tour; // Re-setup workflow buttons to ensure they work when returning setupWorkflowButtons(currentTour); // Show the workflow selection step @@ -231,7 +230,7 @@ export default function StartTour({ { text: 'Navigation', action: async function (this: any) { - const currentTour = shepherd.activeTour as Tour; + const currentTour = Shepherd.activeTour as Tour; navigate('/browse'); await waitForElement('[data-tour="navigation-input"]'); setupNavigationInputStep(currentTour); @@ -243,7 +242,7 @@ export default function StartTour({ { text: 'Data Links', action: async function (this: any) { - const currentTour = shepherd.activeTour as Tour; + const currentTour = Shepherd.activeTour as Tour; if (isJaneliaFilesystem) { navigate( '/browse/nrs_opendata/ome-zarr-examples/fused-timeseries.zarr' @@ -271,7 +270,7 @@ export default function StartTour({ workflowButtons.push({ text: 'Neuroglancer Links', action: async function (this: any) { - const currentTour = shepherd.activeTour as Tour; + const currentTour = Shepherd.activeTour as Tour; navigate('/nglinks'); await waitForElement('[data-tour="nglinks-page"]'); setupCompletionButtons(currentTour); @@ -284,7 +283,7 @@ export default function StartTour({ workflowButtons.push({ text: 'File Conversion', action: async function (this: any) { - const currentTour = shepherd.activeTour as Tour; + const currentTour = Shepherd.activeTour as Tour; if (isJaneliaFilesystem) { navigate( '/browse/nrs_opendata/ome-zarr-examples/fused-timeseries.zarr' @@ -310,7 +309,7 @@ export default function StartTour({ workflowButtons.push({ text: 'Exit', action: function (this: any) { - const currentTour = shepherd.activeTour as Tour; + const currentTour = Shepherd.activeTour as Tour; currentTour.cancel(); }, classes: 'shepherd-button-secondary' @@ -321,9 +320,9 @@ export default function StartTour({ const handleStartTour = () => { // Get or create the tour instance - let tour = shepherd.activeTour as Tour | undefined; + let tour = Shepherd.activeTour as Tour | undefined; if (!tour) { - tour = new shepherd.Tour({ + tour = new Shepherd.Tour({ useModalOverlay: true, defaultStepOptions: { classes: 'shepherd-theme-default', @@ -335,7 +334,7 @@ export default function StartTour({ modalOverlayOpeningRadius: 4 } }); - shepherd.activeTour = tour; + Shepherd.activeTour = tour; } // Add steps if not already added diff --git a/frontend/src/layouts/MainLayout.tsx b/frontend/src/layouts/MainLayout.tsx index 47dd6a229..a97ac970d 100644 --- a/frontend/src/layouts/MainLayout.tsx +++ b/frontend/src/layouts/MainLayout.tsx @@ -4,7 +4,6 @@ import { Outlet, useParams } from 'react-router'; import { Toaster } from 'react-hot-toast'; import { ErrorBoundary } from 'react-error-boundary'; -import { ShepherdJourneyProvider } from 'react-shepherd'; import 'shepherd.js/dist/css/shepherd.css'; import '@/components/tours/shepherd-overrides.css'; @@ -32,7 +31,7 @@ const MainLayoutContent = () => { const bare = isConnectLoginPopup(); return ( - + <> { onRetry={checkHealth} open={showWarningOverlay} /> - + ); };