…lato
Applies the four dependency bumps Snyk opened as #2681, #2684, #2685 and #2686:
next 16.2.10 -> 16.2.11
react 19.2.7 -> 19.2.8
react-dom 19.2.7 -> 19.2.8
@fontsource/lato ^5.2.7 -> ^5.3.0
The Snyk PRs bumped regression-test/package.json without regenerating the lockfile. This app
is outside the pnpm workspace and uses npm, so the visual-regression workflow installs it with
`npm ci`, which hard-fails when package.json and package-lock.json disagree. Every one of those
PRs therefore died on the "Install regression-test dependencies" step.
Regenerated regression-test/package-lock.json alongside the manifest so `npm ci` resolves again.
The remaining lockfile churn is npm re-nesting @tailwindcss/oxide-wasm32-wasi's bundled deps
rather than hoisting them; no packages were added or dropped.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude <noreply@anthropic.com>
Snyk has created this PR to upgrade @fontsource/lato from 5.2.7 to 5.3.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 1 version ahead of your current version.
The recommended version was released 22 days ago.
Issues fixed by the recommended upgrade:
SNYK-JS-SHARP-18184259
SNYK-JS-SHARP-18184418
SNYK-JS-NANOID-18506897
SNYK-JS-NANOID-18506894
SNYK-JS-SHARP-18184262
SNYK-JS-SHARP-18184416
Breaking Change Risk
Release notes
Package name: @fontsource/lato
-
5.3.0 - 2026-07-19
-
5.2.7 - 2025-09-17
from @fontsource/lato GitHub release notesImportant
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: