Skip to content

chore(deps): bump the connectrpc group across 1 directory with 2 updates - #1192

Merged
zxxma merged 3 commits into
mainfrom
dependabot/npm_and_yarn/frontend/connectrpc-49b6e1a7c5
Sep 15, 2026
Merged

zxxma merged 3 commits into
mainfrom
dependabot/npm_and_yarn/frontend/connectrpc-49b6e1a7c5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the connectrpc group with 2 updates in the /frontend directory: @connectrpc/connect and @connectrpc/connect-web.

Updates @connectrpc/connect from 2.1.2 to 2.2.0

Release notes

Sourced from @​connectrpc/connect's releases.

v2.2.0

What's Changed

[!IMPORTANT]

This release adds a security-related feature for servers: the request gate is a function that runs after the request headers are available. Throwing a ConnectError in the gate rejects a request before messages are read, decompressed, or parsed. Use this option to reject unauthenticated requests instead of interceptors. See the documentation for details.

We also recommend that you configure a message size limit for your server, see the readMaxBytes option.

New Contributors

Full Changelog: connectrpc/connect-es@v2.1.2...v2.2.0

Commits

Updates @connectrpc/connect-web from 2.1.2 to 2.2.0

Release notes

Sourced from @​connectrpc/connect-web's releases.

v2.2.0

What's Changed

[!IMPORTANT]

This release adds a security-related feature for servers: the request gate is a function that runs after the request headers are available. Throwing a ConnectError in the gate rejects a request before messages are read, decompressed, or parsed. Use this option to reject unauthenticated requests instead of interceptors. See the documentation for details.

We also recommend that you configure a message size limit for your server, see the readMaxBytes option.

New Contributors

Full Changelog: connectrpc/connect-es@v2.1.2...v2.2.0

Commits

@dependabot @github

dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, frontend. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from zxxma as a code owner September 14, 2026 18:07
@netlify

netlify Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for memba-multisig canceled.

Name Link
🔨 Latest commit 2073e62
🔍 Latest deploy log https://app.netlify.com/projects/memba-multisig/deploys/6aa91191a7e9ba000897b67a

@dependabot dependabot Bot changed the title chore(deps): bump the connectrpc group in /frontend with 2 updates chore(deps): bump the connectrpc group across 1 directory with 2 updates Sep 14, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/frontend/connectrpc-49b6e1a7c5 branch 2 times, most recently from c72f7d8 to 6c1c0b0 Compare September 14, 2026 20:13
Bumps the connectrpc group with 2 updates in the /frontend directory: [@connectrpc/connect](https://github.com/connectrpc/connect-es/tree/HEAD/packages/connect) and [@connectrpc/connect-web](https://github.com/connectrpc/connect-es/tree/HEAD/packages/connect-web).


Updates `@connectrpc/connect` from 2.1.2 to 2.2.0
- [Release notes](https://github.com/connectrpc/connect-es/releases)
- [Commits](https://github.com/connectrpc/connect-es/commits/v2.2.0/packages/connect)

Updates `@connectrpc/connect-web` from 2.1.2 to 2.2.0
- [Release notes](https://github.com/connectrpc/connect-es/releases)
- [Commits](https://github.com/connectrpc/connect-es/commits/v2.2.0/packages/connect-web)

---
updated-dependencies:
- dependency-name: "@connectrpc/connect"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: connectrpc
- dependency-name: "@connectrpc/connect-web"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: connectrpc
...

Signed-off-by: dependabot[bot] <support@github.com>
@zxxma

zxxma commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Merge-train position: after #1201 → #1190 → #1189.

Reviewed head: 409c96f814681d819497dd1d104b28f6d37bb219. Keep connect and connect-web aligned at 2.2.0. Upstream's Node20 support change raises engine requirements for server adapters, not these two installed core/browser packages; it does remove upstream Node20 CI. Memba's own Node20/22 compatibility checks therefore remain important.

Local integration after the backend dependency updates merged cleanly. Frozen installation, typecheck, lint, production build, production/dev audit gates and 319 focused transport/auth/multisig/privacy/game tests passed on each of Node20 and Node22. The combined backend race suite also passed.

After the predecessors merge, refresh against current main and run fresh full exact-head CI with ordinary approval. Do not remove Node20 from the repository matrix to make this update pass. The local focused matrix is not a substitute for full PR CI.

@github-actions

github-actions Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

The latest Buf updates on your PR. Results from workflow CI / proto (pull_request).

BuildFormatLintBreakingUpdated (UTC)
✅ passed✅ passed✅ passed✅ passedSep 15, 2026, 9:36 AM

@zxxma

zxxma commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Summary

Refreshed against merged #1189, then caught the concurrent #1202 merge and refreshed again. Final candidate: 2073e6220f28cdecdfe37eb9ebe758c0dfc84d18, based on f1b322e4c63a099b900cce12a863142aae17118e. Both updates used normal fast-forward pushes; no force push.

The PR still changes only frontend/package.json and frontend/package-lock.json (11 insertions / 11 deletions). Resolved Connect core/web versions move together from 2.1.2 to 2.2.0; Protobuf remains 2.15.0. No application, generated protocol, flag, workflow or simulator change is introduced by this PR.

Compatibility review found no actionable scoped issue. The Node >=22 engines change in the upstream release applies to server adapters, not these installed packages. Local Node20 compatibility was explicitly validated; this is not a claim of upstream Node20 support. Existing auth self-heal still uses the same Unauthenticated error code. No request-gate/early-auth migration is enabled.

Test plan and evidence

  • Frozen install, lint, TypeScript/production build, bundle-isolation gate, production and development audit gates: passed.
  • Full local Node20 and Node22 suites: 5,062 passes / 15 skips each. All six Gno integration files were then run with the exact CI pin and REQUIRE_GNO=1: 30/30 passed on each runtime, covering the 14 toolchain skips. The remaining skip is the opt-in corpus generator.
  • Local Chromium: 232 passed / four skipped, including all three unchanged visual snapshots; mobile guardrails: 59/59 passed. No retries or snapshot updates.
  • Worker rebuilt byte-identically.
  • Fresh full backend build/race/coverage/lint/vulnerability checks after incorporating Count every arcade broadcast attempt toward the cycle limit #1202: passed; coverage 47.2%, lint zero issues, zero affected symbols/imported-package vulnerabilities (ten module-level findings remain).
  • Extra local loopback probe: real Connect JS2.2 transports against the generated Connect-Go1.21 handler, with its metrics interceptor and Go race detector. Node20/22 × protobuf/JSON/gRPC-web all passed rejection/authenticated-fixture-read/pre-cancellation checks. Repeated successfully after Count every arcade broadcast attempt toward the cycle limit #1202. This temporary fixture-only overlay is not a committed or hosted test, wallet test or chain test.
  • The exact first candidate's immutable preview passed four fresh mobile touch-start/pause smoke sessions with outbound writes blocked. After the backend-only Count every arcade broadcast attempt toward the cycle limit #1202 refresh, the entire frontend tree is unchanged. Netlify canceled the new attempt during no-content-change detection; its success status is not a newly built/tested preview.

Final exact-head CI and security: all passed, including both Node versions, backend, Docker, workspaces, Buf and security scans. Final rollup: 18 successes, three neutral Netlify metadata checks for the no-content-change cancellation. Hosted Chromium: 229 passed / seven skipped (unchanged local visual snapshots cover three of those skips); guardrails: 59 passed. No flaky or retried browser result reported.

Existing non-blocking warnings remain: backend coverage below the 50% target, total JS 4,675KB above the 3MB warning threshold, and missing Lighthouse upload artifact. No gate or assertion was weakened. Six existing default-branch advisories outside this diff (one high indirect gRPC xDS alert; five medium workspace alerts) remain separate follow-up work; passing this PR is not an advisory-free claim.

Review handoff

Final remote check: head 2073e622, base/current main f1b322e4, MERGEABLE, no unresolved review threads and no additional page. Normal independent approving review is still required; this evidence comment is not an approving review. Ready for that review and normal merge, without bypassing protection. #1191 remains excluded from this merge train. No mainnet realm deployment, wallet ceremony or unrelated feature-worktree change was performed.

@zxxma
zxxma merged commit f8302d4 into main Sep 15, 2026
21 checks passed
@zxxma
zxxma deleted the dependabot/npm_and_yarn/frontend/connectrpc-49b6e1a7c5 branch September 15, 2026 09:50
@zxxma

zxxma commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Post-merge verification

Merged as f8302d49913cdd8905a3baa8cd2f6d09fb9c770d; its complete tree exactly matches the validated PR candidate. Local main is clean and current.

  • Post-merge CI, security, and frontend main-push gate: all passed. Chromium 229 passed/seven skipped; guardrails 59 passed, no retries reported.
  • Netlify production deploy 6aa914fa7a67740008073a41 is ready with commit_ref exactly f8302d49. Four fresh mobile touch-start/pause smoke sessions passed, with outbound writes/telemetry blocked and no page errors. This is not wallet or live RPC acceptance evidence.
  • Backend health remains application/database ok, version f1b322e. This frontend-only merge did not trigger a backend deployment.
  • Existing coverage, bundle-size and Lighthouse-artifact warnings remain unchanged. No gates were weakened.

The approved dependency train is complete. #1191 remains excluded. Six existing dependency alerts (five distinct advisories) remain separate hardening follow-up work; no mainnet realm deployment or signing ceremony was performed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant