Skip to content

chore: land closed GUI dependency floors and workspace margin fixes - #278

Merged
cursor[bot] merged 2 commits into
mainfrom
cursor/land-closed-unmerged-d7c9
Sep 25, 2026
Merged

cursor[bot] merged 2 commits into
mainfrom
cursor/land-closed-unmerged-d7c9

Conversation

@ChefGroep

@ChefGroep OnlineChef (ChefGroep) commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Recover two closed-without-merge intents that are not on main, checked by diff rather than by the close comments.

  • #248 raised @tanstack/react-virtual from ^3.14.5 to ^3.14.11. The lock on main was still 3.14.5. This installs 3.14.13 (current 3.14 patch, above that floor) and @tanstack/virtual-core 3.17.11. The 3.14.6–3.14.13 notes are patch fixes; useVirtualizer in Logs and Debug is unchanged.
  • #247 raised @types/node from ^26.4.1 to ^26.5.1. The lock on main was 26.5.0, which does not satisfy ^26.5.1. This installs 26.6.2. Dev-only types. Nested @types/node 24 copies dedupe onto that version.
  • #172 margin shorthand (0 0 8px 0 to 0 0 8px, and the storage 12px/16px equivalents) in the three workspace stylesheets, plus const for the stale websocket pump flag that is never reassigned. The other #172 prefer-const hunks are behavior-equivalent and are not included: the pre-commit formatter would reflow entire modules (cleanup.ts, auth-context.ts, release-notes.ts, and several tests) for a binding-kind change.

Security

  • No new install scripts, credentials, auth decisions, or release gates. @types/node does not ship runtime code. react-virtual stays on the existing 3.14 API.
  • The websocket test change does not alter cancellation behavior.
  • Lockfile refresh was generated with Bun 1.4.2, the CI pin.

Verification

  • cd gui && bun install --frozen-lockfile
  • bun run typecheck
  • bun test tests/ws-endpoint.test.ts
  • cd gui && bun run test && bun run lint && bun run build
  • bun run privacy:scan

Linear

  • Issue: none. This recovers closed pull requests #247, #248, and the applicable hunks of #172.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.
Open in Web Open in Cursor 

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Summary by CodeRabbit

  • Chores
    • Updated dependency version ranges.
  • Style
    • Cleaned up stylesheet formatting without changing appearance or behavior.
  • Tests
    • Made a test variable immutable; test coverage and assertions are unchanged.

Recover the dependency intent from closed PRs #248 and #247. Main still
resolved @tanstack/react-virtual 3.14.5 and @types/node 26.5.0; those
pull requests raised the ranges above that. Install the current patch
releases (3.14.13 and 26.6.2) with a Bun 1.4.2 lockfile.

Security: both are patch bumps inside the existing major. react-virtual
stays on the 3.14 API used by the logs and debug virtualizers.
@types/node is dev-only and does not change the runtime. The lockfile
drops nested @types/node 24 copies that now dedupe onto 26.6.2.

Co-authored-by: OnlineChef <chefadmin@chefgroep.online>
Recover the margin shorthand from closed PR #172 in the three workspace
stylesheets, plus the prefer-const binding in the stale websocket pump
test. The other prefer-const hunks in that pull request are behavior
equivalent and stay unstaged: formatting them reflows entire modules.

Security: stylesheet shorthand only. The websocket test binding is never
reassigned, so the stale-pump assertion is unchanged.

Co-authored-by: OnlineChef <chefadmin@chefgroep.online>
@cursor

cursor Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_2daad1fb-d14f-401e-9161-097da5a4dba6)

@github-actions github-actions Bot added the chore label Sep 25, 2026
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: GroepOnline/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: c0fcdd4c-d3b9-4e1e-a578-bd9b622d9a27

📥 Commits

Reviewing files that changed from the base of the PR and between 46a853a and 8626b11.

⛔ Files ignored due to path filters (1)
  • gui/bun.lock is excluded by !**/*.lock
📒 Files selected for processing (5)
  • gui/package.json
  • gui/src/styles-apikeys-workspace.css
  • gui/src/styles-storage-workspace.css
  • gui/src/styles-subagents-workspace.css
  • tests/ws-endpoint.test.ts

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The pull request updates two GUI dependency ranges, reformats declarations in three workspace stylesheets without changing their described behavior, and changes a test variable from let to const.

Changes

GUI dependency updates

Layer / File(s) Summary
Update GUI dependency ranges
gui/package.json:22,36
The @tanstack/react-virtual range changes to ^3.14.13. The @types/node range changes to ^26.6.2.

Workspace CSS formatting

Layer / File(s) Summary
Reformat workspace style declarations
gui/src/styles-apikeys-workspace.css:260–261,390,449–452, gui/src/styles-storage-workspace.css:88–90,206,289–292,322–330, gui/src/styles-subagents-workspace.css:182–185,220,312,386
The changes reformat shadow and transition declarations and remove redundant margin shorthand values. The described CSS values and spacing remain unchanged. The spans at lines 220 and 312 show no declaration changes.

WebSocket endpoint test cleanup

Layer / File(s) Summary
Update stale-pump test declaration
tests/ws-endpoint.test.ts:270
The stale-pump cleanup test changes current from let to const. Its initial value and subsequent assertions remain unchanged.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Suggested reviewers: wibias, lidge-jun

Merge Risk: ⚪ Minimal · up to 8626b

The dependency updates match the committed lockfile, and the CSS and test edits preserve behavior. No material merge risk is identified.

Architecture Summary

Architecture risk: 🔵 Low · up to 8626b

The change affects 2 systems.

Changed systems: gui, tests

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — gui (service) was modified; 4 changed files map to changed impact.
  • observed — tests (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in gui/package.json: Updated the @tanstack/react-virtual dependency range from ^3.14.5 to ^3.14.13.
  • observed — Modified behavior in gui/package.json: Updated the @types/node dependency range from ^26.4.1 to ^26.6.2.
  • observed — Modified behavior in gui/src/styles-apikeys-workspace.css: Reformatted the model-list inset box-shadow declaration across two lines; its color-mix value and shadow parameters are unchanged.
  • observed — Modified behavior in gui/src/styles-apikeys-workspace.css: Removed the redundant trailing zero from the section-title margin shorthand; the effective margin is unchanged.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main changes: GUI dependency floor updates and workspace margin fixes. It is concise, specific, and related to the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​tanstack/​react-virtual@​3.14.5 ⏵ 3.14.13100 +110069 +196100
Updated@​types/​node@​26.5.0 ⏵ 26.6.2100 +110081 +196100

View full report

@cursor
cursor Bot merged commit d8610e0 into main Sep 25, 2026
27 of 28 checks passed
@cursor
cursor Bot deleted the cursor/land-closed-unmerged-d7c9 branch September 25, 2026 18:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants