Skip to content

chore(test): refresh e2e fixtures - #508

Open
clerk-cookie wants to merge 1 commit into
mainfrom
chore/refresh-e2e-fixtures
Open

clerk-cookie wants to merge 1 commit into
mainfrom
chore/refresh-e2e-fixtures

Conversation

@clerk-cookie

Copy link
Copy Markdown
Contributor

Automated refresh of E2E test fixtures via the refresh-fixtures workflow.

Generated by bun run e2e:refresh-fixtures. Review the diff for any
unexpected framework changes (especially major version bumps in
upstream scaffolders) before merging.

Dependency audit

2 high-or-above advisories in the fixture lockfiles.

Fixture Package Severity Vulnerable range Advisory
nextjs-app-router-next14 next critical 9.3.4-canary.0 - 16.3.0-preview.10 Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration
Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
Next.js: HTTP request smuggling in rewrites
…and 20 more
nextjs-app-router-next14 postcss high <=8.5.22 PostCSS has XSS via Unescaped </style> in its CSS Stringify Output
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when from is unset
…and 1 more

Reproduce locally with bun run e2e:audit-fixtures. Fixtures are
throwaway scaffolded apps, so an advisory here is not shipped risk —
but a new entry means an upstream scaffolder started resolving to a
vulnerable release, which is worth understanding before merging.

Triggered by: schedule on refs/heads/main

@changeset-bot

changeset-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 3a9b148

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
test/e2e/fixtures/expo/AGENTS.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 887da900-8112-4bab-a33c-bb5cfb018469

📥 Commits

Reviewing files that changed from the base of the PR and between a16595f and 3a9b148.

⛔ Files ignored due to path filters (12)
  • test/e2e/fixtures/astro/package-lock.json is excluded by !**/package-lock.json
  • test/e2e/fixtures/expo/package-lock.json is excluded by !**/package-lock.json
  • test/e2e/fixtures/express/package-lock.json is excluded by !**/package-lock.json
  • test/e2e/fixtures/fastify/package-lock.json is excluded by !**/package-lock.json
  • test/e2e/fixtures/nextjs-app-router-next14/package-lock.json is excluded by !**/package-lock.json
  • test/e2e/fixtures/nextjs-app-router/package-lock.json is excluded by !**/package-lock.json
  • test/e2e/fixtures/nextjs-pages-router/package-lock.json is excluded by !**/package-lock.json
  • test/e2e/fixtures/nuxt/package-lock.json is excluded by !**/package-lock.json
  • test/e2e/fixtures/react-router/package-lock.json is excluded by !**/package-lock.json
  • test/e2e/fixtures/react/package-lock.json is excluded by !**/package-lock.json
  • test/e2e/fixtures/tanstack-start/package-lock.json is excluded by !**/package-lock.json
  • test/e2e/fixtures/vue/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (12)
  • test/e2e/fixtures/expo/app.json
  • test/e2e/fixtures/expo/package.json
  • test/e2e/fixtures/express/package.json
  • test/e2e/fixtures/fastify/package.json
  • test/e2e/fixtures/nextjs-app-router/package.json
  • test/e2e/fixtures/nextjs-pages-router/package.json
  • test/e2e/fixtures/react-router/package.json
  • test/e2e/fixtures/react/index.html
  • test/e2e/fixtures/react/package.json
  • test/e2e/fixtures/tanstack-start/package.json
  • test/e2e/fixtures/vue/index.html
  • test/e2e/fixtures/vue/package.json
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Updated dependency versions in several E2E fixtures. Changed the Expo fixture’s name, slug, and scheme, and changed the React and Vue fixture page titles.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to 3a9b1

This fixture-only refresh has no established merge-blocking defect and is mergeable subject to normal E2E checks.

Architecture Summary

Architecture risk: 🔵 Low · up to 3a9b1

The change affects 1 system.

Changed systems: test

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — test (service) was modified; 12 changed files map to changed impact.

Before / after behavior

  • observed — Modified behavior in test/e2e/fixtures/expo/app.json: The Expo app name and slug now end in 1q3pp1, and its scheme is now clerkfixtureexpo1q3pp1; these replace the corresponding qytbqw values.
  • observed — Modified behavior in test/e2e/fixtures/expo/package.json: Updated the pinned versions of @expo/ui, expo, expo-constants, and expo-router by one patch release each; the intervening dependency versions remain unchanged.
  • observed — Modified behavior in test/e2e/fixtures/express/package.json: Updates the @types/node devDependency from 26.6.2 to 26.6.3.
  • observed — Modified behavior in test/e2e/fixtures/fastify/package.json: Updates the @types/node dev dependency from 26.6.2 to 26.6.3.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the automated refresh of E2E test fixtures, which is the main change.
Description check ✅ Passed The description explains that the E2E fixtures were refreshed, identifies the generation workflow, and documents the dependency audit findings.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants