Skip to content

Conversation

@valentinpalkovic
Copy link
Contributor

@valentinpalkovic valentinpalkovic commented Dec 12, 2025

Closes #33348

What I did

Checklist for Contributors

Testing

The changes in this PR are covered in the following automated tests:

  • stories
  • unit tests
  • integration tests
  • end-to-end tests

Manual testing

This section is mandatory for all contributions. If you believe no manual test is necessary, please state so explicitly. Thanks!

Documentation

  • Add or update documentation reflecting your changes
  • If you are deprecating/removing a feature, make sure to update
    MIGRATION.MD

Checklist for Maintainers

  • When this PR is ready for testing, make sure to add ci:normal, ci:merged or ci:daily GH label to it to run a specific set of sandboxes. The particular set of sandboxes can be found in code/lib/cli-storybook/src/sandbox-templates.ts

  • Make sure this PR contains one of the labels below:

    Available labels
    • bug: Internal changes that fixes incorrect behavior.
    • maintenance: User-facing maintenance tasks.
    • dependencies: Upgrading (sometimes downgrading) dependencies.
    • build: Internal-facing build tooling & test updates. Will not show up in release changelog.
    • cleanup: Minor cleanup style change. Will not show up in release changelog.
    • documentation: Documentation only changes. Will not show up in release changelog.
    • feature request: Introducing a new feature.
    • BREAKING CHANGE: Changes that break compatibility in some way with current major version.
    • other: Changes that don't fit in the above categories.

🦋 Canary release

This PR does not have a canary release associated. You can request a canary release of this pull request by mentioning the @storybookjs/core team here.

core team members can create a canary release here or locally with gh workflow run --repo storybookjs/storybook publish.yml --field pr=<PR_NUMBER>

Summary by CodeRabbit

  • Chores
    • Updated an internal dependency to improve build compatibility and stability.

Note: This release contains internal maintenance updates with no user-facing changes.

✏️ Tip: You can customize this high-level summary in your review settings.

@valentinpalkovic valentinpalkovic self-assigned this Dec 12, 2025
@valentinpalkovic valentinpalkovic added maintenance User-facing maintenance tasks security ci:normal labels Dec 12, 2025
@nx-cloud
Copy link

nx-cloud bot commented Dec 12, 2025

View your CI Pipeline Execution ↗ for commit b783937

Command Status Duration Result
nx run-many -t compile,check,knip,test,pretty-d... ✅ Succeeded 6m 37s View ↗

☁️ Nx Cloud last updated this comment at 2025-12-12 14:18:12 UTC

@coderabbitai
Copy link
Contributor

coderabbitai bot commented Dec 12, 2025

📝 Walkthrough

Walkthrough

Updated the React-Vite framework package dependency: bumped @joshwooding/vite-plugin-react-docgen-typescript from 0.6.1 to 0.6.3 in code/frameworks/react-vite/package.json. No functional or control-flow changes detected.

Changes

Cohort / File(s) Summary
Dependency Update
code/frameworks/react-vite/package.json
Updated @joshwooding/vite-plugin-react-docgen-typescript from 0.6.1 to ^0.6.3

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

  • Confirm the version bump is intentional and consistent with lockfiles/build configs.
  • Scan the plugin changelog/release notes for any minor behavioral changes.

📜 Recent review details

Configuration used: CodeRabbit UI

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 2591244 and b783937.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (1)
  • code/frameworks/react-vite/package.json (1 hunks)
🚧 Files skipped from review as they are similar to previous changes (1)
  • code/frameworks/react-vite/package.json
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: normal
  • GitHub Check: nx
  • GitHub Check: Core Unit Tests, windows-latest

Comment @coderabbitai help to get the list of available commands and usage tips.

@valentinpalkovic valentinpalkovic force-pushed the valentin/update-vite-plugin-react-docgen-typescript branch from 2591244 to b783937 Compare December 12, 2025 14:09
@valentinpalkovic valentinpalkovic added the patch:yes Bugfix & documentation PR that need to be picked to main branch label Dec 12, 2025
@storybook-app-bot
Copy link

Package Benchmarks

Commit: b783937, ran on 12 December 2025 at 14:22:53 UTC

The following packages have significant changes to their size or dependencies:

@storybook/nextjs-vite

Before After Difference
Dependency count 128 127 🎉 -1 🎉
Self size 1.12 MB 1.12 MB 🚨 +36 B 🚨
Dependency size 21.96 MB 21.97 MB 🚨 +11 KB 🚨
Bundle Size Analyzer Link Link

@storybook/react-native-web-vite

Before After Difference
Dependency count 160 159 🎉 -1 🎉
Self size 30 KB 30 KB 🎉 -18 B 🎉
Dependency size 23.14 MB 23.15 MB 🚨 +11 KB 🚨
Bundle Size Analyzer Link Link

@storybook/react-vite

Before After Difference
Dependency count 118 117 🎉 -1 🎉
Self size 35 KB 35 KB 🚨 +1 B 🚨
Dependency size 19.75 MB 19.76 MB 🚨 +11 KB 🚨
Bundle Size Analyzer Link Link

@valentinpalkovic valentinpalkovic merged commit bda866e into next Dec 12, 2025
72 of 74 checks passed
@valentinpalkovic valentinpalkovic deleted the valentin/update-vite-plugin-react-docgen-typescript branch December 12, 2025 14:30
valentinpalkovic added a commit that referenced this pull request Dec 12, 2025
…n-react-docgen-typescript

React-Vite: Update @joshwooding/vite-plugin-react-docgen-typescript
(cherry picked from commit bda866e)
@github-actions github-actions bot added the patch:done Patch/release PRs already cherry-picked to main/release branch label Dec 12, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci:normal maintenance User-facing maintenance tasks patch:done Patch/release PRs already cherry-picked to main/release branch patch:yes Bugfix & documentation PR that need to be picked to main branch security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: High severity vulnerability in @storybook/react-vite

2 participants