Repository navigation
chore(deps): bump browserslist, qs, joi, js-yaml in example lockfile - #155
Merged
Merged
Conversation
yarn up -R with yarn 4.2.2; all entries stay within their major. image-size stays on 1.x (metro pins it; fix is 2.x only).
ethanpschoen
marked this pull request as ready for review
September 25, 2026 18:34
alexchavez1
approved these changes
Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of this change
Bumps
example/yarn.lockin place, the same way #144 did. I usedyarn up -Rwith yarn 4.2.2 (the example'spackageManager). No newresolutions;example/package.jsonis unchanged.Knock-on changes:
@ketch-com/ketch-react-native@file:../packageentry is left exactly as on main. yarn hashes that entry from the packedpackage/, which includes the gitignoredlib/build output. That makes its checksum machine-dependent: two runs in the same checkout produced different values. As a result,yarn install --immutableinexample/fails on main and on this branch alike, and only that one entry differs.No entry changes major.
Not included: image-size (#476). The only fix is 2.x, and metro pins 1.x.
This is separate from #154 (the
package/lockfiles). #154 was already approved, so this change goes in its own PR rather than being added to that one.Why is this change being made?
How was this tested? How can the reviewer verify your testing?
CI doesn't build
example/, so these checks were run locally inexample/(Node 23.11.0, yarn 4.2.2), on main and on this branch:yarn install(non-immutable) difffile:../packagechecksum changes; every dependency entry is consistenttsc --noEmitThe eslint warning is the existing
no-path-concatinmetro.config.js. The bundles are identical because every bumped package is build tooling.Not run:
webdriverioon main and on this branch alike, and it needs a device.resolutionsentry"qs": "^6.14.1"now puts body-parser on qs 6.16.0, and that isn't exercised under the dev server.Related issues
Closes Dependabot alerts #432, #433, #442, #449, #450, #469, #470 and #472. Vanta: KD-18416, KD-18415.
Checklist
Note
Low Risk
Lockfile-only transitive upgrades to dev/build dependencies; no application source changes and local checks reported identical Metro bundles.
Overview
Updates
example/yarn.lockonly (nopackage.jsonchanges) by refreshing resolved versions for build-tooling and security-related transitive deps, mainly viayarn up -R.Direct bumps:
browserslist4.28.1 → 4.29.1 (withcaniuse-lite,electron-to-chromium,node-releases,update-browserslist-db, andbaseline-browser-mapping, including CLI pathdist/cli.js→dist/cli.cjs),qs6.15.2 → 6.16.0 (addsside-channel@^1.1.1/side-channel-list@^1.0.1),joi17.13.4 → 17.13.8, andjs-yaml4.3.1 → 4.3.2.Aligns with the example app’s existing
resolutionsforqsandjs-yaml; intended to clear Dependabot alerts without changing app/runtime bundle output.Reviewed by Cursor Bugbot for commit 678a5d4. Configure here.