Skip to content

feat(deps): update dependency @radix-ui/react-slot (1.3.3 → 1.4.0) - #1185

Merged
joryirving merged 1 commit into
mainfrom
renovate/radix-ui-primitives-monorepo
Oct 6, 2026
Merged

joryirving merged 1 commit into
mainfrom
renovate/radix-ui-primitives-monorepo

Conversation

@its-miso

@its-miso its-miso Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@radix-ui/react-slot (source) 1.3.3 → 1.4.0 age adoption passing confidence

Release Notes

radix-ui/primitives (@​radix-ui/react-slot)

v1.4.0

  • Added support for multiple aria-describedby attributes.
  • Fixed compatibility issues with React Server Components.

Configuration

📅 Schedule: (in timezone America/Edmonton)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@its-miso
its-miso Bot requested a review from joryirving as a code owner October 5, 2026 23:21
@its-miso its-miso Bot added the type/minor label Oct 5, 2026

@its-saffron its-saffron Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: MiniMax-M3 (anthropic) — primary route · pr-reviewer-action v3.3.0

Recommendation: approve

A minimal Renovate patch bump of @radix-ui/react-slot from 1.3.3 to 1.4.0, confined to a single 3-line hunk in package-lock.json. No source files were touched and no transitive dependency drifted.

Change-by-change findings

  • package-lock.json (node_modules/@radix-ui/react-slot): 1.3.3 → 1.4.0, tarball react-slot-1.4.0.tgz, new integrity hash, license unchanged. The dependencies sub-entry still pins @radix-ui/react-compose-refs: 1.1.5, exactly as before. No other entries in the lockfile were modified by this PR (changedFiles: 1).
  • package.json: No change. The declared range ^1.2.4 continues to satisfy 1.4.0, and no overrides block needs touching (the existing security overrides for postcss, sharp, deepmerge-ts, mysql2 are unrelated).

Claims verification

  • Claim 1 (1.3.3 → 1.4.0 in package.json + lockfile): Held: 2/2. package-lock.json resolves to 1.4.0; the package.json semver range was unchanged and still permits it.
  • Claim 2 (only the @radix-ui/react-slot lockfile entry modified): Held: 2/2. Single hunk; the unrelated @radix-ui/react-slot@1.2.3 entry nested under node_modules/@radix-ui/react-primitive was left intact.
  • Claim 3 (@radix-ui/react-compose-refs stays at 1.1.5): Held: 2/2. Top-level entry at line 2531-2533 is still 1.1.5, and the dependencies block on the updated react-slot@1.4.0 still pins 1.1.5.
  • Claim 4 (backward-compatibility per release notes / Mend badge): Held: 2/2 with caveat. The only in-tree consumer is src/components/ui/button.tsx, which uses the public Slot named export — its signature is unchanged in 1.4.0. The v1.4.0 release notes describe purely additive changes (multiple aria-describedby, RSC compatibility fix). CI evidence on this head (fbe4010c) shows the full pipeline (Lint, Typecheck, Build, Tests, Coverage, npm audit, Docker Build, smoke) passed, which is the strongest available empirical signal that the upgrade is runtime-compatible.

Sources

  • Upstream release notes (in PR body): "Added support for multiple aria-describedby attributes. Fixed compatibility issues with React Server Components." — purely additive, no breaking API changes documented.
  • In-tree consumer: src/components/ui/button.tsx (only file importing @radix-ui/react-slot).
  • CI Check Results: all 13 reported checks passed for commit fbe4010c5a5a09583d0b300f9bd45581082ccc20.

Standards Compliance

The repository standards file (AGENTS.md) does not impose a per-package review gate; it requires lint/typecheck to pass in CI and forbids committing secrets. Neither is violated here. The repository's AI review conventions (.github/ai-review-rules.md) favor direct, practical reviews and explicitly prefer non-blocking comments for Renovate dependency bumps when there is no real defect — this PR fits that pattern.

Unknowns or Needs Verification

  • The Mend / Renovate compatibility badge URL (developer.mend.io/api/mc/badges/compatibility/...) is on a host outside the allowed fetch list, so the live "Passing" indicator could not be re-fetched in this review. This is informational only: the upstream changelog and CI results together already substantiate the compatibility claim for the only consumer in the repo.
  • No upstream release tag with the literal name 1.4.0 was returned by the GitHub releases enrichment for radix-ui/primitives (the most recent tag observed was 1.6.7); the changelog still lists the 1.4.0 entry as described in the PR body. This is informational only and consistent with radix-ui's monorepo tag-aliasing convention.

Required Check Dispositions

  • check for breaking API changes in updated dependencies — satisfied. The upstream 1.4.0 notes describe only additive changes; the sole in-tree consumer (src/components/ui/button.tsx) uses the stable Slot named export, and CI (Lint/Typecheck/Build/Tests) all passed on the bumped head.
  • run full test suite after upgrade — satisfied. CI reports Tests, Coverage, Typecheck, Build, Lint, npm audit, Docker Build, and smoke all green for fbe4010c.

@joryirving
joryirving merged commit 73133e7 into main Oct 6, 2026
14 checks passed
@joryirving
joryirving deleted the renovate/radix-ui-primitives-monorepo branch October 6, 2026 02:38
@its-miso its-miso Bot mentioned this pull request Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant