Skip to content

fix: bump threaded-annotations to 4.5.3 and activity-feed to 2.3.12 - #4733

Merged
mergify[bot] merged 1 commit into
box:masterfrom
jackiejou:bump-threaded-annotations-4.5.3-activity-feed-2.3.12
Jul 29, 2026
Merged

fix: bump threaded-annotations to 4.5.3 and activity-feed to 2.3.12#4733
mergify[bot] merged 1 commit into
box:masterfrom
jackiejou:bump-threaded-annotations-4.5.3-activity-feed-2.3.12

Conversation

@jackiejou

@jackiejou jackiejou commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Description

Bumps @box/threaded-annotations to 4.5.3 and @box/activity-feed to 2.3.12, along with the peer versions threaded-annotations 4.5.x requires.

Package Before After
@box/threaded-annotations ^4.4.1 ^4.5.3
@box/activity-feed ^2.3.7 ^2.3.12
@box/blueprint-web ^16.16.1 ^16.18.0
@box/blueprint-web-assets ^5.6.5 ^5.6.8
@box/collaboration-popover ^2.2.5 ^2.2.8
@box/readable-time ^2.2.5 ^2.2.8
@box/user-selector ^2.2.5 ^2.2.8

Ranges updated in both devDependencies and peerDependencies; lockfile deduplicated so each bumped package resolves to a single version.

Testing

  • Pre-push hook build and changedSince tests passed locally
  • Spot-check ContentSidebar activity feed / annotations in Storybook or a consumer app

Summary by CodeRabbit

  • Chores
    • Updated several Box component packages to newer compatible versions.
    • Aligned development and peer package requirements for improved compatibility.

Includes peer bumps required by threaded-annotations 4.5.x: blueprint-web
16.18.0, blueprint-web-assets 5.6.8, collaboration-popover 2.2.8,
readable-time 2.2.8, user-selector 2.2.8. Lockfile deduplicated.
@jackiejou
jackiejou requested a review from a team as a code owner July 29, 2026 18:41
@coderabbitai

coderabbitai Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 4f411d15-87c3-4575-8f33-0fd4db9279cd

📥 Commits

Reviewing files that changed from the base of the PR and between dc07626 and 11e61d2.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (1)
  • package.json

Walkthrough

Updates selected @box/* package versions in devDependencies and peerDependencies within package.json.

Changes

Dependency version alignment

Layer / File(s) Summary
Package dependency version updates
package.json
Selected @box/* versions are bumped consistently in development and peer dependency declarations; the existing @box/cldr-data constraint is unchanged.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Possibly related PRs

Suggested labels: ready-to-merge

Suggested reviewers: tjiang-box, jmcbgaston, jfox-box

Poem

I’m a rabbit with packages stacked,
Fresh little versions in a neat-lined track.
Dev and peer hops now match in flight,
While unchanged constraints stay tucked just right.
Nibble, merge, and ship tonight!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main dependency bumps, including the most important packages changed.
Description check ✅ Passed The description names the dependency bumps, shows before/after versions, and includes a testing section.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@socket-security

Copy link
Copy Markdown

@mergify mergify Bot added the queued label Jul 29, 2026
@mergify

mergify Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Merge Queue Status

  • Entered queue2026-07-29 18:57 UTC · Rule: Automatic strict merge · triggered by rule Automatic merge queue
  • Checks skipped · PR is already up-to-date
  • Merged2026-07-29 18:57 UTC · at 11e61d261b697f33aeba862e02873a14260cbccc · squash

This pull request spent 16 seconds in the queue, including 2 seconds running CI.

Required conditions to merge
  • github-review-approved [🛡 GitHub branch protection]
  • any of [🛡 GitHub branch protection]:
    • check-success = Summary
    • check-neutral = Summary
    • check-skipped = Summary
  • any of [🛡 GitHub branch protection]:
    • check-success = lint_test_build
    • check-neutral = lint_test_build
    • check-skipped = lint_test_build
  • any of [🛡 GitHub branch protection]:
    • check-success = license/cla
    • check-neutral = license/cla
    • check-skipped = license/cla
  • any of [🛡 GitHub branch protection]:
    • check-success = lint_pull_request
    • check-neutral = lint_pull_request
    • check-skipped = lint_pull_request

@mergify
mergify Bot merged commit ad5822f into box:master Jul 29, 2026
10 of 11 checks passed
@mergify mergify Bot removed the queued label Jul 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants