Skip to content

chore: refresh Start example dependencies - #519

Merged
tannerlinsley merged 1 commit into
mainfrom
chore/start-example-dependencies
Oct 1, 2026
Merged

tannerlinsley merged 1 commit into
mainfrom
chore/start-example-dependencies

Conversation

@tannerlinsley

@tannerlinsley tannerlinsley commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Refresh Start and matching Router dependencies in the four standalone React and Solid examples. Update the two committed lockfiles and generated route trees.

Each standalone example now records the native dependency scripts it allows in its own pnpm workspace file. These examples are outside the root workspace, so the root install policy does not cover them. The Tailwind oxide install script was reviewed before approval.

Validation: root build, 267 unit tests, and production builds of all four examples passed. All seven blocking CLI browser tests passed under Node 24.15.0, and the repository pre-commit build and full test workflow passed. The earlier Node 26 run stalled during browser shutdown. Scaffolding templates already use latest Start, and published CLI source did not change. No changeset is needed.

Summary by CodeRabbit

  • Maintenance
    • Updated router and framework versions across the React and Solid examples.
    • Updated example build settings to allow required package build scripts.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 8447a2a9-7f22-4a6f-bcd0-f7cf1e135ed3

📥 Commits

Reviewing files that changed from the base of the PR and between acf927a and a70be60.

⛔ Files ignored due to path filters (2)
  • examples/react/ecommerce/pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
  • examples/react/resume/pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (10)
  • examples/react/blog/package.json
  • examples/react/blog/pnpm-workspace.yaml
  • examples/react/ecommerce/package.json
  • examples/react/ecommerce/pnpm-workspace.yaml
  • examples/react/ecommerce/src/routeTree.gen.ts
  • examples/react/resume/package.json
  • examples/react/resume/pnpm-workspace.yaml
  • examples/solid/blog/package.json
  • examples/solid/blog/pnpm-workspace.yaml
  • examples/solid/blog/src/routeTree.gen.ts

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

React and Solid examples update dependency ranges and pnpm build-script allowlists. Two generated route trees reorder route entries while retaining their route metadata.

Changes

Example updates

Layer / File(s) Summary
Dependency and build-script settings
examples/react/{blog,ecommerce,resume}/package.json, examples/react/{blog,ecommerce,resume}/pnpm-workspace.yaml, examples/solid/blog/{package.json,pnpm-workspace.yaml}
Updates selected TanStack dependency ranges and adds pnpm build-script allowlist entries for @tailwindcss/oxide, esbuild, and, in some examples, lightningcss.
Generated route entry order
examples/react/ecommerce/src/routeTree.gen.ts, examples/solid/blog/src/routeTree.gen.ts
Reorders route imports, initialization declarations, and FileRoutesByPath entries. Route paths, IDs, parent assignments, and metadata remain associated with their routes.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to a70be

No actionable install, build, or routing regression was established, so no material merge-blocking risk remains.

Security Architecture Review

Security architecture risk: 🔵 Low · up to a70be

The permissions are limited to named native-build dependencies rather than enabling all dependency scripts. The route changes preserve existing paths and do not demonstrate a new boundary bypass. Remaining uncertainty concerns dependency-script behavior and the privileges available during installation.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The direct configuration scope is the four standalone example installations. If an approved dependency supplies malicious lifecycle code, its effective reach would follow the installing process's privileges and accessible resources, not the example directory alone. Installer identity, credentials, and sandboxing are not established by the inspected configuration.

Trust Boundaries and Controls

  • observed — The root workspace package patterns exclude these React and Solid examples. Their new policies explicitly enumerate approved package names rather than granting blanket script permission; the approvals contain no version restriction.

Hardening Proposals

  • proposed — Run approved dependency scripts with least-privileged, isolated installation credentials, and reassess approvals when resolved package versions change. These are containment proposals, not findings that current installations expose privileged credentials.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: refreshing Start-related dependencies in the example projects.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​tanstack/​react-ai-devtools@​0.2.19 ⏵ 0.2.7193 +231009998100

View full report

@tannerlinsley
tannerlinsley merged commit 3f2d3d3 into main Oct 1, 2026
7 checks passed
@tannerlinsley
tannerlinsley deleted the chore/start-example-dependencies branch October 1, 2026 18:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant