chore(deps): bump react-dom and @types/react-dom in /frontend/web - #8
Open
dependabot[bot] wants to merge 3 commits into
Open
dependabot[bot] wants to merge 3 commits into
dependabot[bot] wants to merge 3 commits into
Conversation
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/frontend/web/multi-15e0f44842
branch
2 times, most recently
from
September 3, 2026 17:54
e2a8be3 to
78494f0
Compare
Everything pending from the last rounds of review, in one commit.
Cost and abuse
- The rate limiter keyed callers on the leftmost X-Forwarded-For entry, which the
client writes. A fresh value per request meant a fresh bucket, so the limit on
the three LLM endpoints could be skipped at will. It now reads the rightmost
hop, written by the proxy in front of the app. The test that asserted the old
behaviour is corrected, and a new one makes the attack and expects a 429.
- Windows were emptied but never removed: one entry per distinct caller for the
life of the process. Idle clients are swept past 10,000 entries.
- /assistant and /search took any question length and any k; one request could
send all 2,562 profiles to the model. Capped at 500 characters and k <= 12
(the longest eval question is 66 characters; the dashboard asks for 6).
- CORS admitted every *.vercel.app with credentials, so any stranger's app
could spend the budget from its visitors' browsers, each with a new bucket.
Now: localhost, the production alias, and previews of a configured Vercel
scope (CORS_PREVIEW_SCOPE). Credentials off; the dashboard sends none.
Production cannot refit
- scikit-learn, xgboost, lightgbm, shap and rapidfuzz move to a `train` extra.
The API imports none of them, and Render no longer installs them.
- With the libraries absent, a stale predictions file is served and flagged
(`predictions_stale` in /talent/model-info) instead of triggering a 250MB
refit on a 512MB instance; a missing one is a 503 naming the command.
The team and value fallbacks do the same.
- tests/test_footprint.py fails if importing the API loads any training
library, if the value artifact needs lightgbm to read, or if the published
predictions are missing what the API reads.
Earlier fixes, not yet committed
- The value router wrote its artifact to src/models/ (parents[3] from
api/routers/ is src/), leaving the committed one holding a pickled
LGBMRegressor. Fixed, and the artifact regenerated in the right place.
- The RAGAS snapshot named gemini-2.5-flash as judge; the run was graded on
LM Studio. One judge_name() now resolves it for both the request and the
provenance. The snapshot is relabelled to google/gemma-4-e4b.
- Answers cut off by the token limit are trimmed to the last sentence and
flagged `truncated`; the assistant budget goes from 1400 to 3000 tokens.
RAG: "who makes the most X" returns who makes the most X
- Retrieval ranked leaders questions by similarity, so the six profiles that
read most like the question reached the prompt, not the six that lead the
metric -- and a faithful answer then named the best of the wrong six. RAGAS
cannot see this: faithfulness and context precision are both satisfied.
scripts/eval_metric_leaders.py checks it against the database for the 42
leaders questions in the bank. Similarity alone returned 19% of the true top
six and the actual leader 12 times in 42; ordering the filtered pool by the
metric returns 99% and the leader 42 times in 42. "Quem faz mais cortes"
used to include a goalkeeper with 0.00 clearances.
- The playing role (wing-back, centre-back, striker...) is now a hard filter,
parsed by the same earliest-mention rule as the position group and derived
from each player's primary position when the index loads -- no migration,
no re-embedding. Without it a wider pool let centre-backs into wing-back
questions; with it, 100% of returned players are in the role asked for.
- Metric verbs are recognised ("rematam", "press", "conduzem", "complete the
most passes"); each used to find no metric and fall back to similarity.
- The prompt says the list is the top of the pool in order, and the response
carries `ranked_by`.
- Fixed a latent misalignment: metric notes were paired with profiles by list
position, so a player with no values would have shifted every later
player's figures onto the wrong paragraph.
Data layer
- tests/test_quality.py covers the rules that decide whether a whole season
enters the pool: a full league, a truncated one, a single-club export (which
is not a fragment), and null away sides (which must not become a phantom
club, as they did in Ligue 1). The null-side test fails if that fix is
reverted.
- parse_value_eur moves from ml/value.py to etl/sofifa.py, the source whose
format it parses; importing the SoFIFA loader no longer pulls in lightgbm.
Housekeeping: CI lints scripts/, ruff format applied, README brought up to
date (212 tests, 10 competitions, the real model figures, the precompute step).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ESLint - eslint + eslint-config-next 16.3.3 with the flat config Next 16 documents (core-web-vitals and typescript). `npm run lint` fails on any warning, and CI already runs it -- the step existed but had nothing to run. - The first run found five effects that set state synchronously to reset it before a fetch, each costing an extra render. They now keep every response with the request that produced it and derive "loading" from a mismatch (MetricDistribution, MetricScatter, PlayerAvatar, PlayerPickerModal). - The picker had no guard against out-of-order responses: a slow answer to an earlier keystroke could replace the results for the current query. Fixed with the same keyed results and a stale flag; its focus timer is cleared too. - Removed an unused generic, an unused import, and an `activeSlot` prop that Assistant and NLSearch received but never read. page.tsx - 1,649 lines to 996. The seven sub-components below Home move to their own files under app/components/, each importing only what it uses. Verified by multiset diff of every code line before and after: nothing lost or added. Behaviour - The distribution and scatter charts say which selected player they cannot plot and why, instead of dropping them silently. - A truncated assistant answer carries a note saying it stopped early. - The model ladder says when the served predictions are stale. - Assistant sources are titled "Top 6 by <metric> per 90, highest first" when the question asked who leads, so the list reads as the ordering it is. - Pending layout work in globals.css (chart framing and centring) from earlier rounds. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bumps [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) and [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom). These dependencies needed to be updated together. Updates `react-dom` from 19.2.4 to 19.3.0 - [Release notes](https://github.com/react/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom) Updates `@types/react-dom` from 19.2.3 to 19.3.0 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom) --- updated-dependencies: - dependency-name: "@types/react-dom" dependency-version: 19.2.5 dependency-type: direct:development update-type: version-update:semver-patch - dependency-name: react-dom dependency-version: 19.2.8 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/frontend/web/multi-15e0f44842
branch
from
September 24, 2026 21:00
78494f0 to
49a67eb
Compare
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps react-dom and @types/react-dom. These dependencies needed to be updated together.
Updates
react-domfrom 19.2.4 to 19.3.0Release notes
Sourced from react-dom's releases.
... (truncated)
Changelog
Sourced from react-dom's changelog.
... (truncated)
Commits
f4e439e[Fizz] Addnonceto renderedimport maps(#37339)21c89c9[DOM] Clean up Fragment listeners on signal abort (#37457)065bc84[DOM] Unobserve fragment IntersectionObserver targets after exit (#37408)ff7445e[DOM] Update HTML parser rules for new select parser (#34804)2dc7da7[test] Bump Jest to 30.4 (#37382)29d9d31[DOM] Copysourceonto the synthetic toggle event (#37389)269bd40[test] Remove the customtoThrowoverride for legacy V8 error messages (#37...a112448[DOM] Treat omitted Fragment Event listener options same ascapture: false...3d05080[Fizz] Construct the render lifetime controller only when it is needed (#37357)77ed3f5[Flight/Fizz] Stop the caller's signal from retaining a finished render (#37315)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for react-dom since your current version.
Updates
@types/react-domfrom 19.2.3 to 19.3.0Commits