Repository navigation
Refreshed '.vortex/' dev dependencies for September 2026 and cleared high-severity npm advisories in the root and theme lock files. - #3168
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: ASSERTIVE Plan: Team Run ID: ⛔ Files ignored due to path filters (4)
📒 Files selected for processing (3)
Included review availability: This review used your included allowance. 1 included review remains after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. WalkthroughThe changes update dependency constraints in two Composer manifests and change the fixture directory path used by an installer unit test. ChangesDependency constraint updates
Installer test fixture path
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~8 minutes Change: Other Merge Risk: ⚪ Minimal · up to The fixture lookup remains valid, and no concrete merge-blocking issue was established in the dependency updates. 🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 1 files. (2 skipped: 2 unsupported.) Full details: Title checkExplanation The title describes the .vortex dependency refresh, but it also claims that root and theme lock files cleared high-severity npm advisories. The provided changes do not support that claim, so the title is misleading.
✨ Finishing Touches 💡 2📝 Generate docstrings 💡
🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
A rabbit checks the version rows, Comment |
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
1 similar comment
This comment has been minimized.
This comment has been minimized.
…eme 'package-lock.json' to clear high-severity npm advisories.
|
📖 Documentation preview for this pull request has been deployed to Netlify: https://6abcc52e3403ef5dff700657--vortex-docs.netlify.app This preview is rebuilt on every commit and is not the production documentation site. |
|
Code coverage (threshold: 90%) Per-class coverage |
This comment has been minimized.
This comment has been minimized.
2 similar comments
This comment has been minimized.
This comment has been minimized.
|
Code coverage (threshold: 90%) Per-class coverage |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #3168 +/- ##
==========================================
- Coverage 87.02% 86.65% -0.37%
==========================================
Files 114 106 -8
Lines 5255 5089 -166
Branches 49 3 -46
==========================================
- Hits 4573 4410 -163
+ Misses 682 679 -3 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Summary
The lock files under
.vortex/fordocs,installerandtestsnow resolve the newest releases inside their existing constraints:.vortex/installer/composer.lockmoves 22 packages,.vortex/tests/composer.lockmoves 19, and theyarn.lockfiles in.vortex/docsand.vortex/testsfollow. The template's rootpackage-lock.jsonandweb/themes/custom/your_site_theme/package-lock.jsonnow lock patchedbrace-expansion,fast-uriandundicireleases..vortex/tooling/is out of scope. No constraint was edited by hand: the onlycomposer.jsonedits are whatbump-after-updatewrote (10 lower bounds in.vortex/installer/composer.json, 5 in.vortex/tests/composer.json), and nopackage.jsonchanged.The required
auditandci/circleci: auditchecks were failing onmainitself, becausenpm audit --package-lock-onlyfound high-severity advisories againstbrace-expansion1.1.18 and 5.0.9,fast-uri3.1.6 andundici7.29.0 in the root lock, and againstbrace-expansion1.1.18 andfast-uri3.1.6 in the theme lock, so no PR againstmaincould go green. On the refreshed.vortex/installerlock,rector/rector2.6.7'sDirnameDirConcatStringToDirectStringPathRectorflagsdirname(__DIR__) . '/Fixtures/env'at.vortex/installer/tests/Unit/Utils/EnvTest.php:94, soahoy --file .vortex/.ahoy.yml lint-installerfails until that line reads__DIR__ . '/../Fixtures/env'.After merge, both npm audits report
found 0 vulnerabilities, so the audit checks pass onmainagain, and.vortex/docsruns Vale 3.23.0, which reports 3 advisoryVortex.SentenceLengthwarnings oncontent/README.mdx(lines 47, 114 and 135) where 3.22.0 reported 0. Only Vale errors failyarn lint-proseand CI. The rootcomposer.json, everypackage.json, thepatches.lock.jsonfiles,.vortex/tooling/and the installer fixtures under.vortex/installer/tests/Fixtures/are untouched, and the baseline fixture's.ignorecontentlistspackage-lock.json, so the lock changes need no snapshot update.Before / After
Changes
.vortex/installercomposer.locktakes 22 in-range updates, includingalexskrypnyk/phpunit-helpers1.0.0 to 1.2.0,alexskrypnyk/str2name1.6.0 to 1.7.0,phpunit/phpunit12.5.34 to 12.5.37,phpstan/phpstan2.2.13 to 2.2.16,rector/rector2.6.6 to 2.6.7,symfony/console7.4.18 to 7.4.20,symfony/yaml7.4.18 to 7.4.20,symfony/finder7.4.17 to 7.4.20,ergebnis/composer-normalize2.52.0 to 2.54.0,laravel/serializable-closure2.0.16 to 2.1.0 andnikic/php-parser5.8.0 to 5.9.0.composer.jsonhas 10 lower bounds raised to the locked version bybump-after-update:alexskrypnyk/str2name,symfony/console,symfony/yaml,alexskrypnyk/phpunit-helpers,ergebnis/composer-normalize,laravel/serializable-closure,phpstan/phpstan,phpunit/phpunit,rector/rectorandsymfony/finder.tests/Unit/Utils/EnvTest.phpline 94 builds the fixture path as__DIR__ . '/../Fixtures/env'instead ofdirname(__DIR__) . '/Fixtures/env'..vortex/testscomposer.locktakes 19 in-range updates, includingalexskrypnyk/csvtable1.2.0 to 1.3.0,alexskrypnyk/phpunit-helpers1.0.0 to 1.2.0,phpunit/phpunit12.5.34 to 12.5.37,phpstan/phpstan2.2.13 to 2.2.16 andrector/rector2.6.6 to 2.6.7.composer.jsonhas 5 lower bounds raised bybump-after-update:alexskrypnyk/phpunit-helpers,ergebnis/composer-normalize,phpstan/phpstan,phpunit/phpunitandrector/rector.yarn.lockkeeps the direct dependencymarkdownlint-cli2at 0.18.1; only transitive entries moved:ignore7.0.8 to 7.0.10,micromark-factory-space2.0.1 to 2.1.0, new caret-range resolutions ofmicromark-core-commonmark2.0.4 andmicromark-util-types2.0.3, and a newmicromark-util-edit-map1.0.0..vortex/docsyarn.lockhas 743 insertions and 640 deletions; the notable direct moves are@vvago/vale3.22.0 to 3.23.0 andprettier3.9.6 to 3.9.9.Template npm lock files
package-lock.json: the hoistedbrace-expansion1.1.18 to 1.1.21 (reached throughminimatch3.1.5), the copies nested underglobandtest-exclude5.0.9 to 5.0.12,fast-uri3.1.6 to 3.1.8 andundici7.29.0 to 7.30.0.web/themes/custom/your_site_theme/package-lock.json:brace-expansion1.1.18 to 1.1.21 andfast-uri3.1.6 to 3.1.8.package.jsonchanged and the rootoverridesblock is untouched. The installer'sNpmLock::sync()and theToolsHandlerProcessTestassertions read only the lock's root entry and itsnode_modules/<name>keys, which these transitive bumps don't change.Subsystems touched
.vortex/docs: Composer no (no Composer manifest), Yarn yes (yarn.lock)..vortex/installer: Composer yes (composer.lock, plus 10bump-after-updateedits incomposer.json; thevendor-bin/boxsub-composer took 16 in-range updates but its lock is gitignored, so nothing from it is in the diff), Yarn no (no Yarn manifest).patches.lock.jsonunchanged..vortex/tests: Composer yes (composer.lock, plus 5bump-after-updateedits incomposer.json), Yarn yes (yarn.lock, transitive entries only).patches.lock.jsonunchanged.package-lock.jsonin both), manifests unchanged.Lint and audit status
Local lint passed for every updated
.vortex/subsystem, which is the gate for opening this PR. Tests weren't run locally by design; CI is the source of truth.docs(ahoy --file .vortex/.ahoy.yml lint-docs): eslint and prettier clean, markdownlint 0 errors across 82 files, cspell 0 issues in 82 files, Vale 0 errors and 3 warnings. The 3 warnings areVortex.SentenceLengthoncontent/README.mdxlines 47, 114 and 135 (43, 50 and 33 words). They're new with Vale 3.23.0: the latestmaindocs CI run, still on Vale 3.22.0, printed0 errors, 0 warnings and 0 suggestions in 82 files. Each flagged line is the first<li>of a JSX<ul>, and each word count equals the total of that whole list, so 3.23.0 reads each unpunctuated JSX list as 1 sentence. Vale warnings are advisory (only errors fail the run and CI), so the page's prose is left for a separate change rather than edited inside a dependency refresh.installer(ahoy --file .vortex/.ahoy.yml lint-installer): the first run failed because Rector 2.6.7'sDirnameDirConcatStringToDirectStringPathRectorflaggedtests/Unit/Utils/EnvTest.php:94, rewritingdirname(__DIR__) . '/Fixtures/env'to__DIR__ . '/../Fixtures/env'.ahoy --file .vortex/.ahoy.yml lint-installer-fixapplied it, and the re-run is green (phpcs, phpstan, rector). That 1-line change is lint-fix output, not a hand edit.tests(ahoy --file .vortex/.ahoy.yml lint-tests): green on the first run (phpcs, phpstan, rector).npm audit --package-lock-onlyandnpm audit --package-lock-only --prefix=web/themes/custom/your_site_theme, the commands both audit jobs run, reportfound 0 vulnerabilities.Major versions available
These sit outside the current constraints and aren't part of this PR.
.vortex/docs(Yarn).vortex/installer(Composer).vortex/tests(Composer)