Skip to content

chore(deps): Upgrade Cypress, wait-on, and @box peer packages - #772

Open
jackiejou wants to merge 8 commits into
masterfrom
chore/upgrade-cypress-15
Open

chore(deps): Upgrade Cypress, wait-on, and @box peer packages#772
jackiejou wants to merge 8 commits into
masterfrom
chore/upgrade-cypress-15

Conversation

@jackiejou

@jackiejou jackiejou commented Aug 28, 2026

Copy link
Copy Markdown
Collaborator

Summary

Upgrades Cypress to 15, wait-on to 9, and the @box peer packages, including @box/combobox-with-api. The e2e runner uses cypress.config.js, engines.node is 20+, and the webpack-dev-server build emits a classic script for the test page.

Why

Keep Cypress, wait-on, and the @box peer set current with the other Preview packages.

Test plan

  • Travis E2E job on this PR completes
  • Build, lint, and unit jobs stay green

@jackiejou
jackiejou requested a review from a team as a code owner August 28, 2026 18:45
@socket-security

socket-security Bot commented Aug 28, 2026

Copy link
Copy Markdown

@socket-security

socket-security Bot commented Aug 28, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm json-schema is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: yarn.locknpm/cypress@15.21.1npm/json-schema@0.4.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/json-schema@0.4.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@jackiejou
jackiejou force-pushed the chore/upgrade-cypress-15 branch from 7f6b0de to 8b4b97a Compare August 28, 2026 21:21
@jackiejou jackiejou changed the title chore(deps): Upgrade Cypress to 15 and wait-on to 9 chore(deps): Upgrade Cypress, wait-on, and @box peer packages Aug 28, 2026
@jackiejou
jackiejou force-pushed the chore/upgrade-cypress-15 branch 3 times, most recently from 099387d to 1bf9678 Compare August 28, 2026 23:17
@jackiejou
jackiejou force-pushed the chore/upgrade-cypress-15 branch from 1bf9678 to c212dde Compare August 28, 2026 23:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant