chore(test): refresh e2e fixtures - #508
clerk-cookie wants to merge 1 commit into
Conversation
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (12)
📒 Files selected for processing (12)
🔗 Linked repositories identifiedCodeRabbit considers these linked repositories for cross-repo context during reviews:
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughUpdated dependency versions in several E2E fixtures. Changed the Expo fixture’s name, slug, and scheme, and changed the React and Vue fixture page titles. Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Merge Risk: ⚪ Minimal · up to This fixture-only refresh has no established merge-blocking defect and is mergeable subject to normal E2E checks. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Comment ✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
|
Automated refresh of E2E test fixtures via the
refresh-fixturesworkflow.Generated by
bun run e2e:refresh-fixtures. Review the diff for anyunexpected framework changes (especially major version bumps in
upstream scaffolders) before merging.
Dependency audit
2
high-or-above advisories in the fixture lockfiles.nextjs-app-router-next14next9.3.4-canary.0 - 16.3.0-preview.10Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components
Next.js: HTTP request smuggling in rewrites
…and 20 more
nextjs-app-router-next14postcss<=8.5.22PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when
fromis unset…and 1 more
Reproduce locally with
bun run e2e:audit-fixtures. Fixtures arethrowaway scaffolded apps, so an advisory here is not shipped risk —
but a new entry means an upstream scaffolder started resolving to a
vulnerable release, which is worth understanding before merging.
Triggered by: schedule on refs/heads/main