Skip to content

fix(deps): source-map-js 1.2.2 for Dependabot alert 76, open 1.3.0-beta.0 (#1051) - #1052

Merged
Shieldxx merged 1 commit into
mainfrom
fix/1051-source-map-js
Oct 10, 2026
Merged

Shieldxx merged 1 commit into
mainfrom
fix/1051-source-map-js

Conversation

@Shieldxx

@Shieldxx Shieldxx commented Oct 10, 2026 •

Copy link
Copy Markdown
Collaborator

Closes #1051

What does this PR do?

Two lines that each wait on the next PR anyway:

  • Dependabot alert 76: the lockfile now resolves source-map-js 1.2.2 instead of 1.2.1 (GHSA-68fv-2mgg-jv7q, high). It is build and test tooling only, pulled in by @tailwindcss/node, postcss and css-tree (through jsdom). All three already accept ^1.2.1, so no range changes. It is dev: true and not in the packaged app. We deferred it until after v1.2.4, so that tag stayed the exact build the smoke covered.
  • Opens 1.3.0: the version goes 1.2.4 → 1.3.0-beta.0 (github-release step 0). Mid-cycle builds then identify themselves instead of claiming the version that shipped.

What the tests prove

No code change. On this branch, after npm ci:

  • source-map-js resolves to 1.2.2.
  • format, lint and typecheck pass.
  • vitest: 132 files and 1275 tests pass on three consecutive runs. One run before those reported one test file failed (1273 of 1275 reported). I did not chase it; it has not reproduced.
  • The packaged build (electron-builder --dir, unsigned config) has an asar of 882 entries with every runtime dependency.
  • audit:runtime passes.

Type of change

  • Bug fix
  • New feature
  • Refactor / cleanup
  • Docs / config

Smoke check

  • Needs no manual check. Reason: lockfile-only change to a build-time dependency that is not in the shipped app, plus the prerelease version string. The packaged asar is unchanged in content (882 entries, every runtime dependency present).
  • Needs a manual check. What to do, and what a correct result looks like:

Checklist

  • npm run build passes (packaged with electron-builder --dir, unsigned config)
  • npm run typecheck passes
  • npm run format:check passes
  • Tested manually (not needed, see Smoke check)

Screenshots

Not a visual change.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Release
    • The application version is now 1.3.0-beta.0, identifying this build as a beta in the 1.3.0 release series. This update does not describe any changes to user-facing features or behavior.

…ta.0 (#1051)

Lockfile-only: source-map-js 1.2.1 -> 1.2.2 (GHSA-68fv-2mgg-jv7q), pulled
in by @tailwindcss/node, postcss and css-tree; dev tooling, not in the
packaged app. Deferred until after v1.2.4 so the tag stayed the smoked
build. The same PR opens the next milestone at 1.3.0-beta.0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: Stashpeak/SimLauncher/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 0203d3f9-208a-430b-b01d-731a2a575698

📥 Commits

Reviewing files that changed from the base of the PR and between c256a2d and 6068701.


⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json

📒 Files selected for processing (1)
  • package.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.



📝 Walkthrough

Walkthrough

The package version changes from 1.2.4 to 1.3.0-beta.0.

Changes

Release version

Layer / File(s) Summary
Update package version
package.json
The package version changes from 1.2.4 to 1.3.0-beta.0.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other


Merge Risk: ⚪ Minimal · up to 60687

No actionable version or packaging mismatch is evident, so this change appears ready to merge after normal checks.

Pre-merge checks | Passed 3 | Inconclusive 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Linked Issues check Inconclusive Issue #1051 requires source-map-js@1.2.2, no dependency range changes, passing gates, and a packaged asar with every runtime dependency. The reviewed summary confirms the version change to `1.3.0-be… Provide reviewable evidence for the lockfile resolution and the required gate and packaged-asar results. The excluded package-lock.json prevents direct verification of the dependency update and range preservation.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check Passed The title clearly identifies both primary changes: updating source-map-js to 1.2.2 for Dependabot alert 76 and opening version 1.3.0-beta.0. It is specific and related to the changeset.
Description check Passed The description follows the required template. It includes the linked issue, change summary, change type, smoke-check decision, validation results, checklist status, and screenshot note. It provides s…
Out of Scope Changes check Passed The reviewed summary reports only the package version change. Issue #1051 explicitly includes opening 1.3.0-beta.0, and the reported lockfile update is directly related to the issue's security fix. …

Full details: Linked Issues check

Explanation

Issue #1051 requires source-map-js@1.2.2, no dependency range changes, passing gates, and a packaged asar with every runtime dependency. The reviewed summary confirms the version change to 1.3.0-beta.0, but package-lock.json is excluded from review and no independent evidence establishes its resolved version or the required gate and asar results. The issue's coding requirements cannot be fully assessed.


✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@stashpeak-review-bot stashpeak-review-bot Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Review Bot

🏷 config 🕐 ~2-5 min 🐞 0 🔐 0 🧪 0 📏 0

The diff only touches package.json, bumping the version string from 1.2.4 to 1.3.0-beta.0 to open the next milestone. The lockfile upgrade to source-map-js 1.2.2 described in the PR body (and verified present in the checked-out package-lock.json, dev-only dependency) isn't part of the shown diff, but the visible change itself is a trivial, no-logic version bump with no runtime, security, or test impact, and nothing in the repo standards block (process spawning, kill matching, IPC contract) applies to it.

Walkthrough (1 file)
File Note
package.json Version bumped 1.2.4 -> 1.3.0-beta.0 to mark the start of the next milestone; only consumer is the release workflow's tag/version match check, which isn't affected.

Total: $0.0171 (plus subscription)

Full-lane cost

Review bot usage

mode engine model tokens in tokens out cost time comments
full claude-code claude-sonnet-5 16 2653 sub 44234 ms 0
shadow api openai/gpt-5.6-terra 2630 666 $0.0146 6623 ms 1
shadow api deepseek/deepseek-v4-flash 2693 576 $0.0003 7636 ms 0
shadow api xiaomi/mimo-v2.6-flash 2675 793 $0.0006 21013 ms 1
shadow api nvidia/nemotron-3-ultra-550b-a55b:free 2726 823 $0.0000 25077 ms 0
shadow-verify api-agentic xiaomi/mimo-v2.6-flash 30907 2457 $0.0016 53918 ms 1

@Shieldxx
Shieldxx merged commit 010c747 into main Oct 10, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

security(deps): source-map-js 1.2.2 for Dependabot alert 76 (dev tooling only)

1 participant