Skip to content

build(deps): bump three from 0.181.1 to 0.181.2 - #2281

Open
dependabot[bot] wants to merge 2 commits into
masterfrom
dependabot/npm_and_yarn/three-0.181.2
Open

dependabot[bot] wants to merge 2 commits into
masterfrom
dependabot/npm_and_yarn/three-0.181.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Nov 24, 2025 •

Copy link
Copy Markdown
Contributor

Bumps three from 0.181.1 to 0.181.2.

Commits

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Nov 24, 2025
@github-actions
github-actions Bot enabled auto-merge November 24, 2025 01:04
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/three-0.181.2 branch 2 times, most recently from aa7b374 to 9dfd9e3 Compare November 25, 2025 09:29
@grzanka

grzanka commented Dec 1, 2025

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/three-0.181.2 branch from 9dfd9e3 to 6883c3a Compare December 1, 2025 14:45
@grzanka

grzanka commented Mar 30, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/three-0.181.2 branch from 6883c3a to 13313e8 Compare March 30, 2026 19:22
@martastn martastn self-assigned this Sep 20, 2026
@martastn

Copy link
Copy Markdown
Contributor

Review:

!! Note on the PR description: it says 0.181.1 → 0.181.2, but the actual diff in package.json/package-lock.json on this branch is 0.181.1 → 0.183.2. Reviewed accordingly against the larger diff.

Where three is used in this repo:

  • Direct import (from three) across src/ThreeEditor/*.
  • three/examples/jsm/...: OrbitControls, TransformControls, RoomEnvironment, lil-gui, Line2/LineGeometry/LineMaterial, RGBELoader, TGALoader.
  • Deep imports straight into three/src/math/...: generateUUID and Vector3.
  • Renderer: THREE.WebGLRenderer only (no WebGPURenderer anywhere).

Checked the official migration guide (181→182, 182→183) against actual usage:

  • PCFSoftShadowMap deprecation, WebGPURenderer shadow/SSR/WebGLCubeRenderTarget changes, PostProcessing→RenderPipeline, VOXLoader, MeshPostProcessingMaterial, Sky- none of these APIs/features are used in this codebase. No impact.
  • THREE.Clock deprecated in favor of THREE.Timer- used in ViewportManager.js for the animation loop. Confirmed by running it that the deprecation only logs a one-time console.warn in the constructor. Fixed as part of this PR: migrated clock.getDelta() → timer.update(timestamp); timer.getDelta(), using the timestamp already provided by renderer.setAnimationLoop. Only usage site in the codebase.
  • RoomEnvironment position change (this.position.y = -3.5 added, shifts the PMREM lighting look)- used in ViewportManager.js only inside case ModelViewer: of the sceneEnvironmentChanged signal handler. Verified- statically (grepped every .dispatch() call in the repo) and empirically (added a temporary log, exercised settings in the running app)- that this signal is never dispatched anywhere. Zero observable impact.

Verification performed, and its actual scope:

  • All changed/deep-imported file paths (/...) exist and export the same symbols in three@0.183.2. npx tsc --noEmit- 0 errors. Caveat: true but not checkJs, and files likeViewportManager.js have no // @ts-check pragma- confirmed by injecting a bogus method call into it, which tsc did not flag. So the .ts/``.tsx files that import three directly (PropertyField.tsx, SidebarTreeList.tsx, StoreService.tsx, RemoteWorkerSimulationService.ts); it says nothing about type-correctness infiles, including the Clock→Timer fix above (verified at runtime instead).
  • @types/three is pinned at ^0.177.0.
    above, since most three-touching code files described above.
  • jsroot bundles its own isolated three@0.162.0- no version conflict with the top-level package.

Proposed follow-up issues (not blockers for this PR):

  1. @types/three is stuck at ^0.177.0, now six versions behind three@0.183.2. Should be bumped alongside three going forward (ideally have Depp manually whenever three moves) so typedeclarations don't silently drift further from the real API.
  2. Dead signal handlers: sceneEnvironmenndChanged are never dispatched anywhere in the codebase. This is why the RoomEnvironment position change in three@0.183 has zero observable effect here.
  3. Deep imports from three/src/... internal paths (three/src/math/MathUtils.js, three/src/math/Vector3.js in
    SidebarTreeList.tsx / PropertyField.tnon-public API surface, which is far more likely to move/break across versions than the top-level three export. Both generateUUID and Vector3 are
    available from import ... from 'threeng to that for stability against futurethree.js bumps.
  4. ViewportManager.js (and the rest of isn't type-checked by tsc at all, sincetsconfig.json has allowJs: true but no checkJs, and these files have no // @ts-check pragma. Confirmed by injecting a bogus method call that this means the Clock→Timer fix bundled in this PR (and any future three.js-API changes touching this file) get no compiler safety net.

Confirmed safe to merge

@martastn

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

dependabot Bot and others added 2 commits September 21, 2026 18:04
Bumps [three](https://github.com/mrdoob/three.js) from 0.181.1 to 0.181.2.
- [Release notes](https://github.com/mrdoob/three.js/releases)
- [Commits](https://github.com/mrdoob/three.js/commits)

---
updated-dependencies:
- dependency-name: three
  dependency-version: 0.181.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@martastn
martastn force-pushed the dependabot/npm_and_yarn/three-0.181.2 branch from f1779a9 to abfa04e Compare September 21, 2026 16:08
@grzanka
grzanka requested review from grzanka and a balanced review from Copilot September 21, 2026 17:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

new THREE.Timer() will throw at runtime because Timer is not a top-level three export and must be imported from the addons path.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 1 High severity · 1 Low severity

Open (2)
What changed in this PR

This PR is presented as a Dependabot dependency bump for three, but it does two things: it raises the three dependency and it modifies ViewportManager.js to switch the animation loop from THREE.Clock to THREE.Timer (the Clock replacement introduced/encouraged in newer three.js releases). It fits into the ThreeEditor viewport rendering path, which drives per-frame animation updates.

Changes:

  • Bump three in package.json and package-lock.json (actual target is ^0.183.2, not 0.181.2 as the title states).
  • Replace THREE.Clock with THREE.Timer in the viewport animation loop and feed the setAnimationLoop timestamp into timer.update(timestamp) before reading timer.getDelta().
File Description
package.json Updates the three dependency range (to ^0.183.2).
package-lock.json Locks three to 0.183.2 with updated resolved URL/integrity.
src/​ThreeEditor/​js/​viewport/​ViewportManager.js Swaps Clock for Timer in the animate loop; introduces new THREE.Timer() and timer.update(timestamp).

Key concerns found during review:

  • new THREE.Timer() will throw at runtime: Timer is not a top-level three export (unlike Clock) and must be imported from three/examples/jsm/misc/Timer.js.
  • The PR title/description says 0.181.1 → 0.181.2, but the diff bumps to 0.183.2, a minor-version change that also motivates the source edit.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

// animations

const clock = new THREE.Clock(); // only used for animations
const timer = new THREE.Timer(); // only used for animations
Comment thread package.json
"signals": "^1.0.0",
"split-grid": "^1.0.11",
"three": "^0.181.1",
"three": "^0.183.2",

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants