Skip to content

chore(deps): bump react-dom and @types/react-dom in /frontend/web - #8

Open
dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/npm_and_yarn/frontend/web/multi-15e0f44842
Open

dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/npm_and_yarn/frontend/web/multi-15e0f44842

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps react-dom and @types/react-dom. These dependencies needed to be updated together.
Updates react-dom from 19.2.4 to 19.3.0

Release notes

Sourced from react-dom's releases.

19.3.0 (September 9, 2026)

Below is a list of all new features, APIs, and bug fixes.

Read the React 19.3 release post for more information.

New React Features

New React DOM Features

  • browser(): a new react-dom API that returns a usable which errors during server rendering and resolves in the browser. use(browser()) inside a <Suspense> boundary marks a subtree as browser-only without reporting a recoverable error (@​gnoff: #37143, #37241)
    • Added an onBrowserBailout option to the react-dom/server APIs to observe when a subtree defers to the browser (@​gnoff #37193)

Notable changes

All Changes

React

... (truncated)

Changelog

Sourced from react-dom's changelog.

19.3.0 (September 9, 2026)

New React Features

New React DOM Features

  • browser(): a new react-dom API that returns a usable which errors during server rendering and resolves in the browser. use(browser()) inside a <Suspense> boundary marks a subtree as browser-only without reporting a recoverable error (@​gnoff: #37143, #37241)
    • Added an onBrowserBailout option to the react-dom/server APIs to observe when a subtree defers to the browser (@​gnoff #37193)

Notable changes

All Changes

React

... (truncated)

Commits
  • f4e439e [Fizz] Add nonce to rendered import maps (#37339)
  • 21c89c9 [DOM] Clean up Fragment listeners on signal abort (#37457)
  • 065bc84 [DOM] Unobserve fragment IntersectionObserver targets after exit (#37408)
  • ff7445e [DOM] Update HTML parser rules for new select parser (#34804)
  • 2dc7da7 [test] Bump Jest to 30.4 (#37382)
  • 29d9d31 [DOM] Copy source onto the synthetic toggle event (#37389)
  • 269bd40 [test] Remove the custom toThrow override for legacy V8 error messages (#37...
  • a112448 [DOM] Treat omitted Fragment Event listener options same as capture: false ...
  • 3d05080 [Fizz] Construct the render lifetime controller only when it is needed (#37357)
  • 77ed3f5 [Flight/Fizz] Stop the caller's signal from retaining a finished render (#37315)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for react-dom since your current version.


Updates @types/react-dom from 19.2.3 to 19.3.0

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 1, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/frontend/web/multi-15e0f44842 branch 2 times, most recently from e2a8be3 to 78494f0 Compare September 3, 2026 17:54
pinthoz and others added 3 commits September 24, 2026 21:57
Everything pending from the last rounds of review, in one commit.

Cost and abuse
- The rate limiter keyed callers on the leftmost X-Forwarded-For entry, which the
  client writes. A fresh value per request meant a fresh bucket, so the limit on
  the three LLM endpoints could be skipped at will. It now reads the rightmost
  hop, written by the proxy in front of the app. The test that asserted the old
  behaviour is corrected, and a new one makes the attack and expects a 429.
- Windows were emptied but never removed: one entry per distinct caller for the
  life of the process. Idle clients are swept past 10,000 entries.
- /assistant and /search took any question length and any k; one request could
  send all 2,562 profiles to the model. Capped at 500 characters and k <= 12
  (the longest eval question is 66 characters; the dashboard asks for 6).
- CORS admitted every *.vercel.app with credentials, so any stranger's app
  could spend the budget from its visitors' browsers, each with a new bucket.
  Now: localhost, the production alias, and previews of a configured Vercel
  scope (CORS_PREVIEW_SCOPE). Credentials off; the dashboard sends none.

Production cannot refit
- scikit-learn, xgboost, lightgbm, shap and rapidfuzz move to a `train` extra.
  The API imports none of them, and Render no longer installs them.
- With the libraries absent, a stale predictions file is served and flagged
  (`predictions_stale` in /talent/model-info) instead of triggering a 250MB
  refit on a 512MB instance; a missing one is a 503 naming the command.
  The team and value fallbacks do the same.
- tests/test_footprint.py fails if importing the API loads any training
  library, if the value artifact needs lightgbm to read, or if the published
  predictions are missing what the API reads.

Earlier fixes, not yet committed
- The value router wrote its artifact to src/models/ (parents[3] from
  api/routers/ is src/), leaving the committed one holding a pickled
  LGBMRegressor. Fixed, and the artifact regenerated in the right place.
- The RAGAS snapshot named gemini-2.5-flash as judge; the run was graded on
  LM Studio. One judge_name() now resolves it for both the request and the
  provenance. The snapshot is relabelled to google/gemma-4-e4b.
- Answers cut off by the token limit are trimmed to the last sentence and
  flagged `truncated`; the assistant budget goes from 1400 to 3000 tokens.

RAG: "who makes the most X" returns who makes the most X
- Retrieval ranked leaders questions by similarity, so the six profiles that
  read most like the question reached the prompt, not the six that lead the
  metric -- and a faithful answer then named the best of the wrong six. RAGAS
  cannot see this: faithfulness and context precision are both satisfied.
  scripts/eval_metric_leaders.py checks it against the database for the 42
  leaders questions in the bank. Similarity alone returned 19% of the true top
  six and the actual leader 12 times in 42; ordering the filtered pool by the
  metric returns 99% and the leader 42 times in 42. "Quem faz mais cortes"
  used to include a goalkeeper with 0.00 clearances.
- The playing role (wing-back, centre-back, striker...) is now a hard filter,
  parsed by the same earliest-mention rule as the position group and derived
  from each player's primary position when the index loads -- no migration,
  no re-embedding. Without it a wider pool let centre-backs into wing-back
  questions; with it, 100% of returned players are in the role asked for.
- Metric verbs are recognised ("rematam", "press", "conduzem", "complete the
  most passes"); each used to find no metric and fall back to similarity.
- The prompt says the list is the top of the pool in order, and the response
  carries `ranked_by`.
- Fixed a latent misalignment: metric notes were paired with profiles by list
  position, so a player with no values would have shifted every later
  player's figures onto the wrong paragraph.

Data layer
- tests/test_quality.py covers the rules that decide whether a whole season
  enters the pool: a full league, a truncated one, a single-club export (which
  is not a fragment), and null away sides (which must not become a phantom
  club, as they did in Ligue 1). The null-side test fails if that fix is
  reverted.
- parse_value_eur moves from ml/value.py to etl/sofifa.py, the source whose
  format it parses; importing the SoFIFA loader no longer pulls in lightgbm.

Housekeeping: CI lints scripts/, ruff format applied, README brought up to
date (212 tests, 10 competitions, the real model figures, the precompute step).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ESLint
- eslint + eslint-config-next 16.3.3 with the flat config Next 16 documents
  (core-web-vitals and typescript). `npm run lint` fails on any warning, and CI
  already runs it -- the step existed but had nothing to run.
- The first run found five effects that set state synchronously to reset it
  before a fetch, each costing an extra render. They now keep every response
  with the request that produced it and derive "loading" from a mismatch
  (MetricDistribution, MetricScatter, PlayerAvatar, PlayerPickerModal).
- The picker had no guard against out-of-order responses: a slow answer to an
  earlier keystroke could replace the results for the current query. Fixed
  with the same keyed results and a stale flag; its focus timer is cleared too.
- Removed an unused generic, an unused import, and an `activeSlot` prop that
  Assistant and NLSearch received but never read.

page.tsx
- 1,649 lines to 996. The seven sub-components below Home move to their own
  files under app/components/, each importing only what it uses. Verified by
  multiset diff of every code line before and after: nothing lost or added.

Behaviour
- The distribution and scatter charts say which selected player they cannot
  plot and why, instead of dropping them silently.
- A truncated assistant answer carries a note saying it stopped early.
- The model ladder says when the served predictions are stale.
- Assistant sources are titled "Top 6 by <metric> per 90, highest first" when
  the question asked who leads, so the list reads as the ordering it is.
- Pending layout work in globals.css (chart framing and centring) from earlier
  rounds.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bumps [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) and [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom). These dependencies needed to be updated together.

Updates `react-dom` from 19.2.4 to 19.3.0
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.3.0/packages/react-dom)

Updates `@types/react-dom` from 19.2.3 to 19.3.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom)

---
updated-dependencies:
- dependency-name: "@types/react-dom"
  dependency-version: 19.2.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
- dependency-name: react-dom
  dependency-version: 19.2.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump react-dom and @types/react-dom in /frontend/web chore(deps): bump react-dom and @types/react-dom in /frontend/web Sep 24, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/frontend/web/multi-15e0f44842 branch from 78494f0 to 49a67eb Compare September 24, 2026 21:00
@vercel

vercel Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
footy-vision Error Error Sep 24, 2026 9:01pm UTC

This branch had an error being deployed

1 failed deployment
Preview — 49a67eb0 Deployed Sep 24, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant