Skip to content

Refreshed '.vortex/' dev dependencies for September 2026 and cleared high-severity npm advisories in the root and theme lock files. - #3168

Merged
AlexSkrypnyk merged 2 commits into
mainfrom
feature/vortex-dev-deps-september-2026
Sep 30, 2026
Merged

AlexSkrypnyk merged 2 commits into
mainfrom
feature/vortex-dev-deps-september-2026

Conversation

@AlexSkrypnyk

@AlexSkrypnyk AlexSkrypnyk commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Summary

The lock files under .vortex/ for docs, installer and tests now resolve the newest releases inside their existing constraints: .vortex/installer/composer.lock moves 22 packages, .vortex/tests/composer.lock moves 19, and the yarn.lock files in .vortex/docs and .vortex/tests follow. The template's root package-lock.json and web/themes/custom/your_site_theme/package-lock.json now lock patched brace-expansion, fast-uri and undici releases. .vortex/tooling/ is out of scope. No constraint was edited by hand: the only composer.json edits are what bump-after-update wrote (10 lower bounds in .vortex/installer/composer.json, 5 in .vortex/tests/composer.json), and no package.json changed.

The required audit and ci/circleci: audit checks were failing on main itself, because npm audit --package-lock-only found high-severity advisories against brace-expansion 1.1.18 and 5.0.9, fast-uri 3.1.6 and undici 7.29.0 in the root lock, and against brace-expansion 1.1.18 and fast-uri 3.1.6 in the theme lock, so no PR against main could go green. On the refreshed .vortex/installer lock, rector/rector 2.6.7's DirnameDirConcatStringToDirectStringPathRector flags dirname(__DIR__) . '/Fixtures/env' at .vortex/installer/tests/Unit/Utils/EnvTest.php:94, so ahoy --file .vortex/.ahoy.yml lint-installer fails until that line reads __DIR__ . '/../Fixtures/env'.

After merge, both npm audits report found 0 vulnerabilities, so the audit checks pass on main again, and .vortex/docs runs Vale 3.23.0, which reports 3 advisory Vortex.SentenceLength warnings on content/README.mdx (lines 47, 114 and 135) where 3.22.0 reported 0. Only Vale errors fail yarn lint-prose and CI. The root composer.json, every package.json, the patches.lock.json files, .vortex/tooling/ and the installer fixtures under .vortex/installer/tests/Fixtures/ are untouched, and the baseline fixture's .ignorecontent lists package-lock.json, so the lock changes need no snapshot update.

Before / After

BEFORE (main)                                   AFTER (this branch)

┌─ Locked versions (.vortex) ────────────┐      ┌─ Locked versions (.vortex) ────────────┐
│ alexskrypnyk/phpunit-helpers  1.0.0    │ ───▶ │ alexskrypnyk/phpunit-helpers  1.2.0    │
│ phpunit/phpunit               12.5.34  │ ───▶ │ phpunit/phpunit               12.5.37  │
│ phpstan/phpstan               2.2.13   │ ───▶ │ phpstan/phpstan               2.2.16   │
│ rector/rector                 2.6.6    │ ───▶ │ rector/rector                 2.6.7    │
│ @vvago/vale (docs)            3.22.0   │ ───▶ │ @vvago/vale (docs)            3.23.0   │
└────────────────────────────────────────┘      └────────────────────────────────────────┘

┌─ npm audit (root + theme locks) ───────┐      ┌─ npm audit (root + theme locks) ───────┐
│ brace-expansion   1.1.18 / 5.0.9       │ ───▶ │ brace-expansion   1.1.21 / 5.0.12      │
│ fast-uri          3.1.6                │ ───▶ │ fast-uri          3.1.8                │
│ undici            7.29.0 (root only)   │ ───▶ │ undici            7.30.0 (root only)   │
│ high findings: root 3, theme 2         │ ───▶ │ high findings: root 0, theme 0         │
└────────────────────────────────────────┘      └────────────────────────────────────────┘

┌─ EnvTest.php:94 ───────────────────────┐      ┌─ EnvTest.php:94 ───────────────────────┐
│ dirname(__DIR__) . '/Fixtures/env'     │ ───▶ │ __DIR__ . '/../Fixtures/env'           │
└────────────────────────────────────────┘      └────────────────────────────────────────┘

┌─ Vale on content/README.mdx ───────────┐      ┌─ Vale on content/README.mdx ───────────┐
│ 3.22.0                                 │ ───▶ │ 3.23.0                                 │
│ Vortex.SentenceLength: 0 warnings      │ ───▶ │ Vortex.SentenceLength: 3 warnings      │
│                                        │      │ (lines 47, 114, 135; advisory only)    │
└────────────────────────────────────────┘      └────────────────────────────────────────┘

Changes

.vortex/installer

  • composer.lock takes 22 in-range updates, including alexskrypnyk/phpunit-helpers 1.0.0 to 1.2.0, alexskrypnyk/str2name 1.6.0 to 1.7.0, phpunit/phpunit 12.5.34 to 12.5.37, phpstan/phpstan 2.2.13 to 2.2.16, rector/rector 2.6.6 to 2.6.7, symfony/console 7.4.18 to 7.4.20, symfony/yaml 7.4.18 to 7.4.20, symfony/finder 7.4.17 to 7.4.20, ergebnis/composer-normalize 2.52.0 to 2.54.0, laravel/serializable-closure 2.0.16 to 2.1.0 and nikic/php-parser 5.8.0 to 5.9.0.
  • composer.json has 10 lower bounds raised to the locked version by bump-after-update: alexskrypnyk/str2name, symfony/console, symfony/yaml, alexskrypnyk/phpunit-helpers, ergebnis/composer-normalize, laravel/serializable-closure, phpstan/phpstan, phpunit/phpunit, rector/rector and symfony/finder.
  • tests/Unit/Utils/EnvTest.php line 94 builds the fixture path as __DIR__ . '/../Fixtures/env' instead of dirname(__DIR__) . '/Fixtures/env'.

.vortex/tests

  • composer.lock takes 19 in-range updates, including alexskrypnyk/csvtable 1.2.0 to 1.3.0, alexskrypnyk/phpunit-helpers 1.0.0 to 1.2.0, phpunit/phpunit 12.5.34 to 12.5.37, phpstan/phpstan 2.2.13 to 2.2.16 and rector/rector 2.6.6 to 2.6.7.
  • composer.json has 5 lower bounds raised by bump-after-update: alexskrypnyk/phpunit-helpers, ergebnis/composer-normalize, phpstan/phpstan, phpunit/phpunit and rector/rector.
  • yarn.lock keeps the direct dependency markdownlint-cli2 at 0.18.1; only transitive entries moved: ignore 7.0.8 to 7.0.10, micromark-factory-space 2.0.1 to 2.1.0, new caret-range resolutions of micromark-core-commonmark 2.0.4 and micromark-util-types 2.0.3, and a new micromark-util-edit-map 1.0.0.

.vortex/docs

  • yarn.lock has 743 insertions and 640 deletions; the notable direct moves are @vvago/vale 3.22.0 to 3.23.0 and prettier 3.9.6 to 3.9.9.

Template npm lock files

  • package-lock.json: the hoisted brace-expansion 1.1.18 to 1.1.21 (reached through minimatch 3.1.5), the copies nested under glob and test-exclude 5.0.9 to 5.0.12, fast-uri 3.1.6 to 3.1.8 and undici 7.29.0 to 7.30.0.
  • web/themes/custom/your_site_theme/package-lock.json: brace-expansion 1.1.18 to 1.1.21 and fast-uri 3.1.6 to 3.1.8.
  • Each new version sits inside the range its dependents already declare, so neither package.json changed and the root overrides block is untouched. The installer's NpmLock::sync() and the ToolsHandlerProcessTest assertions read only the lock's root entry and its node_modules/<name> keys, which these transitive bumps don't change.

Subsystems touched

  • .vortex/docs: Composer no (no Composer manifest), Yarn yes (yarn.lock).
  • .vortex/installer: Composer yes (composer.lock, plus 10 bump-after-update edits in composer.json; the vendor-bin/box sub-composer took 16 in-range updates but its lock is gitignored, so nothing from it is in the diff), Yarn no (no Yarn manifest). patches.lock.json unchanged.
  • .vortex/tests: Composer yes (composer.lock, plus 5 bump-after-update edits in composer.json), Yarn yes (yarn.lock, transitive entries only). patches.lock.json unchanged.
  • Template root and theme: npm yes (package-lock.json in both), manifests unchanged.

Lint and audit status

Local lint passed for every updated .vortex/ subsystem, which is the gate for opening this PR. Tests weren't run locally by design; CI is the source of truth.

  • docs (ahoy --file .vortex/.ahoy.yml lint-docs): eslint and prettier clean, markdownlint 0 errors across 82 files, cspell 0 issues in 82 files, Vale 0 errors and 3 warnings. The 3 warnings are Vortex.SentenceLength on content/README.mdx lines 47, 114 and 135 (43, 50 and 33 words). They're new with Vale 3.23.0: the latest main docs CI run, still on Vale 3.22.0, printed 0 errors, 0 warnings and 0 suggestions in 82 files. Each flagged line is the first <li> of a JSX <ul>, and each word count equals the total of that whole list, so 3.23.0 reads each unpunctuated JSX list as 1 sentence. Vale warnings are advisory (only errors fail the run and CI), so the page's prose is left for a separate change rather than edited inside a dependency refresh.
  • installer (ahoy --file .vortex/.ahoy.yml lint-installer): the first run failed because Rector 2.6.7's DirnameDirConcatStringToDirectStringPathRector flagged tests/Unit/Utils/EnvTest.php:94, rewriting dirname(__DIR__) . '/Fixtures/env' to __DIR__ . '/../Fixtures/env'. ahoy --file .vortex/.ahoy.yml lint-installer-fix applied it, and the re-run is green (phpcs, phpstan, rector). That 1-line change is lint-fix output, not a hand edit.
  • tests (ahoy --file .vortex/.ahoy.yml lint-tests): green on the first run (phpcs, phpstan, rector).
  • npm audit: npm audit --package-lock-only and npm audit --package-lock-only --prefix=web/themes/custom/your_site_theme, the commands both audit jobs run, report found 0 vulnerabilities.

Major versions available

These sit outside the current constraints and aren't part of this PR.

.vortex/docs (Yarn)

Package Installed Latest
@babel/core 7.29.7 8.0.6
@babel/preset-env 7.29.7 8.0.6
@babel/preset-react 7.29.7 8.0.1
@eslint/js 9.39.5 10.0.1
@testing-library/jest-dom 5.17.0 7.0.1
@testing-library/react 14.3.1 16.3.3
babel-jest 29.7.0 30.5.2
cspell 8.19.4 10.3.6
eslint 9.39.5 10.11.0
globals 16.5.0 17.12.0
jest 29.7.0 30.5.2
jest-environment-jsdom 29.7.0 30.5.2
react 18.3.1 19.3.0
react-dom 18.3.1 19.3.0
sharp-cli 5.3.0 6.1.0

.vortex/installer (Composer)

Package Installed Latest
drevops/phpcs-standard 0.6.2 1.0.0
guzzlehttp/guzzle 7.15.5 8.2.0

.vortex/tests (Composer)

Package Installed Latest
drevops/phpcs-standard 0.6.2 1.0.0

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: ASSERTIVE

Plan: Team

Run ID: 04a9ef53-799f-4848-9acb-72a1995cf2c9

📥 Commits

Reviewing files that changed from the base of the PR and between 5614bc8 and d25d73a.

⛔ Files ignored due to path filters (4)
  • .vortex/docs/yarn.lock is excluded by !**/yarn.lock, !**/*.lock
  • .vortex/installer/composer.lock is excluded by !**/*.lock
  • .vortex/tests/composer.lock is excluded by !**/*.lock
  • .vortex/tests/yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (3)
  • .vortex/installer/composer.json
  • .vortex/installer/tests/Unit/Utils/EnvTest.php
  • .vortex/tests/composer.json

Included review availability: This review used your included allowance. 1 included review remains after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


Walkthrough

The changes update dependency constraints in two Composer manifests and change the fixture directory path used by an installer unit test.

Changes

Dependency constraint updates

Layer / File(s) Summary
Composer dependency constraints
.vortex/installer/composer.json, .vortex/tests/composer.json
Updates runtime and development dependency constraints in both Composer manifests.

Installer test fixture path

Layer / File(s) Summary
Environment test fixture lookup
.vortex/installer/tests/Unit/Utils/EnvTest.php
Builds the fixture directory path from __DIR__ instead of dirname(__DIR__).

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to d25d7

The fixture lookup remains valid, and no concrete merge-blocking issue was established in the dependency updates.

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 1 files. (2 skipped: 2 … Write docstrings for the functions missing them to satisfy the coverage threshold.
Title check ⚠️ Warning The title describes the .vortex dependency refresh, but it also claims that root and theme lock files cleared high-severity npm advisories. The provided changes do not support that claim, so the title… Revise the title to describe the .vortex dependency updates and, if useful, the EnvTest fixture-path fix. Remove the claim about root and theme lock files and npm advisories.
✅ Passed checks (3 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 1 files. (2 skipped: 2 unsupported.)

Full details: Title check

Explanation

The title describes the .vortex dependency refresh, but it also claims that root and theme lock files cleared high-severity npm advisories. The provided changes do not support that claim, so the title is misleading.

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

A rabbit checks the version rows,
Then finds the path where env data grows.
The fixtures sit beside the test,
The bumps are logged and put to rest.
One hop, one pass, the changes close.

Comment @coderabbitai help to get the list of available commands.

@AlexSkrypnyk

This comment has been minimized.

@github-actions

This comment has been minimized.

@AlexSkrypnyk

This comment has been minimized.

1 similar comment
@AlexSkrypnyk

This comment has been minimized.

…eme 'package-lock.json' to clear high-severity npm advisories.
@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

📖 Documentation preview for this pull request has been deployed to Netlify:

https://6abcc52e3403ef5dff700657--vortex-docs.netlify.app

This preview is rebuilt on every commit and is not the production documentation site.

@github-actions

Copy link
Copy Markdown

Code coverage (threshold: 90%)

  Classes: 100.00% (1/1)
  Methods: 100.00% (2/2)
  Lines:   100.00% (230/230)
Per-class coverage
Drupal\ys_demo\Plugin\Block\CounterBlock
  Methods: 100.00% ( 2/ 2)   Lines: 100.00% ( 10/ 10)

@AlexSkrypnyk

This comment has been minimized.

2 similar comments
@AlexSkrypnyk

This comment has been minimized.

@AlexSkrypnyk

Copy link
Copy Markdown
Member Author

Code coverage (threshold: 90%)

  Classes: 100.00% (1/1)
  Methods: 100.00% (2/2)
  Lines:   100.00% (230/230)
Per-class coverage
Drupal\ys_demo\Plugin\Block\CounterBlock
  Methods: 100.00% ( 2/ 2)   Lines: 100.00% ( 10/ 10)

@codecov

codecov Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 86.65%. Comparing base (5614bc8) to head (e04097c).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #3168      +/-   ##
==========================================
- Coverage   87.02%   86.65%   -0.37%     
==========================================
  Files         114      106       -8     
  Lines        5255     5089     -166     
  Branches       49        3      -46     
==========================================
- Hits         4573     4410     -163     
+ Misses        682      679       -3     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@AlexSkrypnyk AlexSkrypnyk changed the title Refreshed '.vortex/' dev dependencies and lint-fix fallout for September 2026. Refreshed '.vortex/' dev dependencies for September 2026 and cleared high-severity npm advisories in the root and theme lock files. Sep 30, 2026
@AlexSkrypnyk AlexSkrypnyk added the Needs review Pull request needs a review from assigned developers label Sep 30, 2026
@AlexSkrypnyk
AlexSkrypnyk merged commit f576e44 into main Sep 30, 2026
38 checks passed
@AlexSkrypnyk
AlexSkrypnyk deleted the feature/vortex-dev-deps-september-2026 branch September 30, 2026 08:27
@AlexSkrypnyk AlexSkrypnyk added this to the 1.42.0 milestone Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Needs review Pull request needs a review from assigned developers

Projects

Status: Release queue

Development

Successfully merging this pull request may close these issues.

1 participant