Bump sonner from 1.7.4 to 2.0.7 in /app#318
Conversation
Completed Working on "Code Review"✅ Review submitted: COMMENT. Total comments: 1 across 1 file. |
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the Comment |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
There was a problem hiding this comment.
Findings Overview
- Totals: 1 comment (Minor: 1). No blocker or critical issues detected.
Key Theme
- Dead dependency upgrade — sonner@2.0.7 is now unused because the app relies on @radix-ui/react-toast for notifications, so the upgrade only increases supply-chain surface without delivering functionality.
Next Steps
- Remove sonner from app/package.json and its lockfile entries, or reintroduce and cover its real usage with tests before upgrading.
| "react-router-dom": "^6.30.1", | ||
| "recharts": "^2.15.4", | ||
| "sonner": "^1.7.4", | ||
| "sonner": "^2.0.7", |
There was a problem hiding this comment.
[MINOR]: The app no longer imports sonner (the toast UI is built on @radix-ui/react-toast), so upgrading it here just keeps an unused dependency and increases supply-chain surface without any tests covering it. Please drop sonner from app/package.json (and lockfile) unless you reintroduce real usage.
9d10770 to
811438b
Compare
ce0f317 to
6b36f51
Compare
|
@dependabot rebase |
Bumps [sonner](https://github.com/emilkowalski/sonner) from 1.7.4 to 2.0.7. - [Release notes](https://github.com/emilkowalski/sonner/releases) - [Commits](https://github.com/emilkowalski/sonner/commits/v2.0.7) --- updated-dependencies: - dependency-name: sonner dependency-version: 2.0.7 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
6b36f51 to
f52bf9d
Compare
Bumps sonner from 1.7.4 to 2.0.7.
Release notes
Sourced from sonner's releases.
... (truncated)
Commits
You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)