Skip to content

build(deps): bump react-intersection-observer from 10.1.0 to 11.0.0 - #6795

Merged
joeherm merged 1 commit into
mainfrom
dependabot/npm_and_yarn/react-intersection-observer-11.0.0
Sep 4, 2026
Merged

joeherm merged 1 commit into
mainfrom
dependabot/npm_and_yarn/react-intersection-observer-11.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 12, 2026

Copy link
Copy Markdown
Contributor

Bumps react-intersection-observer from 10.1.0 to 11.0.0.

Release notes

Sourced from react-intersection-observer's releases.

v11.0.0

v11 delivers a ground-up observer lifecycle rewrite, making observation and cleanup more resilient across React 17, 18, and 19. Shared callback-ref handling, idempotent cleanup, and improved threshold behavior make hooks more predictable in real-world mounting and unmounting scenarios.

It also introduces a new Blume-powered documentation site with clearer guides and examples. Storybook and the README have been refreshed to make getting started easier.

Smaller improvements include private vulnerability reporting, stronger PR quality checks with Fallow, dependency updates, and expanded observer lifecycle tests.

What's Changed

Full Changelog: thebuilder/react-intersection-observer@v10.1.0...v11.0.0

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [react-intersection-observer](https://github.com/thebuilder/react-intersection-observer) from 10.1.0 to 11.0.0.
- [Release notes](https://github.com/thebuilder/react-intersection-observer/releases)
- [Commits](thebuilder/react-intersection-observer@v10.1.0...v11.0.0)

---
updated-dependencies:
- dependency-name: react-intersection-observer
  dependency-version: 11.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 12, 2026
@mozilla-blender

Copy link
Copy Markdown
Contributor

Reviewing this major version bump. Workflow run

@mozilla-blender

Copy link
Copy Markdown
Contributor

NEEDS_REVIEW: this major version bump needs code-owner review

Confidence: medium
Reason: v11.0.0 ships no removed or renamed exports, and the only import in this repo (useInView + the IntersectionOptions type in frontend/src/hooks/gaViewPing.ts) still exists, so the bump compiles and CI is fully green. However, the release is described as a 'ground-up observer lifecycle rewrite' with three behavioral fixes that land squarely on the API this repo depends on: 'fix: respect threshold before trigger once cleanup', 'fix: make observe cleanup idempotent', and 'Fix callback ref cleanup compatibility across React 17-19'. useGaViewPing drives Google Analytics 'View' pings exclusively from the useInView onChange callback with threshold: 1, and it re-dispatches a caller-supplied onChange by hand. A lifecycle/threshold timing change would cause view pings to fire twice or not at all. That is a silent analytics regression: it produces no type error, no render error, and no test failure, which is consistent with CI passing. There is no test for gaViewPing.ts (no gaViewPing.test.ts sibling), jest.config.js contains no IntersectionObserver mock or moduleNameMapper, and the full set of useGaViewPing consumers across frontend/src/components and frontend/src/pages could not be enumerated because the Bash/grep tooling failed in this environment (bwrap loopback error), so the blast radius is unverified. Under the conservative rule, unverified blast radius plus an untested behavioral change to the exact callback contract in use means this should get human eyes rather than auto-merge.

Breaking changes: Ground-up observer lifecycle rewrite (observation and cleanup reworked across React 17/18/19) - behavioral, not API-level; fix: respect threshold before trigger once cleanup (thebuilder/react-intersection-observer#762) - changes when the observer fires relative to the configured threshold, and this repo passes threshold: 1; fix: make observe cleanup idempotent (#763) - repeat cleanup no longer double-unobserves, which can change onChange emission on remount; Fix callback ref cleanup compatibility across React 17-19 (#760) - changes callback-ref teardown semantics for the ref returned by useInView; refactor: share callback-ref observation between hooks (#765) - useInView and useOnInView now share observation internals; No exports were removed or renamed in v11.0.0; useInView and IntersectionOptions remain available; Inherited from v10.0.0 (already adopted at 10.1.0, so not new in this bump): useInView/useOnInView/InView ignore the browser's initial inView === false emission for onChange
Affected code: frontend/src/hooks/gaViewPing.ts:1 - import { IntersectionOptions, useInView } from "react-intersection-observer"; frontend/src/hooks/gaViewPing.ts:13-38 - useGaViewPing calls useInView({ threshold: 1, ...options, onChange }) and only destructures { ref }; the onChange handler sends the GA 'View' event and manually re-invokes options.onChange(inView, entry); frontend/src/hooks/gaViewPing.ts:20 - caller-supplied options are spread in, so any consumer may inject triggerOnce/skip/rootMargin/root/initialInView, all of which are touched by the #762 triggerOnce-vs-threshold cleanup fix; frontend/package.json:34 - sole declaration of the dependency (frontend workspace only; root package.json does not declare it); UNVERIFIED: all useGaViewPing consumers under frontend/src/components/** and frontend/src/pages/** could not be enumerated (no working grep/glob in this environment), so the number of affected components is unknown
Test coverage: Effectively none for the dependency's behavior. There is no gaViewPing.test.ts alongside frontend/src/hooks/gaViewPing.ts. frontend/jest.config.js (jest-environment-jsdom, setupFilesAfterEnv: jest.setup.ts) contains no reference to 'intersection' and no moduleNameMapper, and frontend/jest.setup.ts could not be read to confirm whether an IntersectionObserver polyfill or mock exists; jsdom does not implement IntersectionObserver natively. Coverage thresholds are branches 70 / functions 70 / lines 80 / statements 80 over src/**, which says nothing about this specific hook. Frontend Tests, Mypy, CodeQL, the Docker build and the netlify deploy preview all pass, which confirms the bump type-checks, builds and does not crash renders, but passing CI cannot detect the failure mode at issue here (a GA view ping firing zero or two times instead of once), because no test asserts onChange emission timing for useGaViewPing.

@joeherm
joeherm added this pull request to the merge queue Sep 4, 2026

@mozilla-blender mozilla-blender Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

BLEnder auto-merge: all safety gates passed (CI green, patch/minor, compat 92%, no advisories).

Merged via the queue into main with commit 2a5339a Sep 4, 2026
26 checks passed
@joeherm
joeherm deleted the dependabot/npm_and_yarn/react-intersection-observer-11.0.0 branch September 4, 2026 20:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant