Skip to content

build(deps): bump @atlaskit/pragmatic-drag-and-drop-hitbox from 2.0.0 to 2.1.0 - #3002

Closed
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/main/atlaskit/pragmatic-drag-and-drop-hitbox-2.1.0
Closed

dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/main/atlaskit/pragmatic-drag-and-drop-hitbox-2.1.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @atlaskit/pragmatic-drag-and-drop-hitbox from 2.0.0 to 2.1.0.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note

Low Risk
Dependency-only minor bump for drag-and-drop hitbox utilities; possible dual major versions of the core Atlaskit package in the lockfile, but no direct code changes.

Overview
Bumps @atlaskit/pragmatic-drag-and-drop-hitbox from 2.0.0 to 2.1.0 in special-pages/package.json, with the root package-lock.json updated accordingly.

The lockfile also records that hitbox 2.1.0 depends on @atlaskit/pragmatic-drag-and-drop ^3.0.0 (nested 3.0.0), while special-pages still declares the core package at ^2.0.2—so runtime may resolve two major versions unless hoisting aligns them. No app source changes; new-tab favorites DnD (PragmaticDND.js) continues to import the same hitbox APIs.

Reviewed by Cursor Bugbot for commit 1682db2. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps [@atlaskit/pragmatic-drag-and-drop-hitbox](https://github.com/atlassian/pragmatic-drag-and-drop) from 2.0.0 to 2.1.0.
- [Commits](https://github.com/atlassian/pragmatic-drag-and-drop/commits)

---
updated-dependencies:
- dependency-name: "@atlaskit/pragmatic-drag-and-drop-hitbox"
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Update one or more dependencies version minor Increment the minor version when merged labels Aug 31, 2026
@dependabot
dependabot Bot requested review from a team and daxtheduck as code owners August 31, 2026 10:53
@dependabot dependabot Bot added dependencies Update one or more dependencies version minor Increment the minor version when merged labels Aug 31, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Injected PR Evaluation: Web Compatibility & Security

Scope note: This Dependabot PR only updates special-pages/package.json and package-lock.json. There are zero changes to injected/, messaging/, or any runtime injected feature code.

Web Compatibility Assessment

File Lines Severity Finding
— — info No injected/src/ changes. API surface fidelity, prototype patching, DOM interaction safety, timing/race patterns, platform-specific injected behavior, and third-party script compatibility categories are not applicable to this diff.
package-lock.json 155–170 info @atlaskit/pragmatic-drag-and-drop-hitbox@2.1.0 now depends on @atlaskit/pragmatic-drag-and-drop@^3.0.0, while special-pages/package.json still declares @atlaskit/pragmatic-drag-and-drop@^2.0.2. npm resolves both (v2 top-level, v3 nested under hitbox). This is a special-pages NTP favorites concern only — not third-party web compatibility. Favorites DnD integration tests pass locally (re-orders items, support drop on placeholders, accepts external drag/drop).

Security Assessment

File Lines Severity Finding
— — info No changes to captured-globals.js, wrapper-utils.js, message-bridge.js, messaging transports, or shouldExemptMethod(). Global capture hygiene, messaging trust boundaries, prototype attacks, and iframe security categories are not applicable.
— — info Dependency-only bump in special-pages (embedded NTP page, not injected into hostile third-party pages). No new postMessage, eval, dynamic code execution, or config-gated feature surface introduced.

Risk Level

Low Risk — dependency-only change with no injected runtime code; special-pages favorites DnD tests green.

Recommendations

  1. Optional follow-up: Consider bumping @atlaskit/pragmatic-drag-and-drop to ^3.x in special-pages/package.json to align with hitbox 2.1.0's peer dependency and avoid dual-version bundling (not blocking — tests pass today).
  2. No injected-specific action required.
Open in Web View Automation 

Sent by Cursor Automation: Web compat and sec

Comment thread package-lock.json
"license": "Apache-2.0",
"dependencies": {
"@atlaskit/pragmatic-drag-and-drop": "^2.0.0",
"@atlaskit/pragmatic-drag-and-drop": "^3.0.0",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

info (special-pages only, not injected): Hitbox 2.1.0 pulls in @atlaskit/pragmatic-drag-and-drop@^3.0.0 (nested v3.0.0 below), while the app still imports adapters from v2 (^2.0.2 in special-pages/package.json). Favorites DnD integration tests pass with this layout, but consolidating to a single major version would reduce bundle size and avoid future cross-version drag-state edge cases.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Dependency update review: @atlaskit/pragmatic-drag-and-drop-hitbox 2.0.0 → 2.1.0

Verdict: Do not merge in isolation — combine with @atlaskit/pragmatic-drag-and-drop v3 bump


Confirmed issue: duplicate core package versions

Hitbox 2.1.0 declares a dependency on @atlaskit/pragmatic-drag-and-drop ^3.0.0, but this PR leaves the direct dependency at ^2.0.2. After npm ci:

special-pages
├── @atlaskit/pragmatic-drag-and-drop-hitbox@2.1.0
│   └── @atlaskit/pragmatic-drag-and-drop@3.0.0
└── @atlaskit/pragmatic-drag-and-drop@2.0.2

PragmaticDND.js imports adapters, monitors, and previews from the v2 instance, while hitbox utilities (attachClosestEdge, extractClosestEdge, reorderWithEdge) run against the v3 instance. Pragmatic DND relies on shared internal state across these modules — two copies can cause subtle runtime failures (drag monitors not firing, edge detection mismatches) even when tests pass.

Recommendation: Close this PR and merge the combined fix in # (or merge alongside Dependabot PR #3000).


Changelog impact (low risk once deduped)

Package Change Impact on this repo
hitbox 2.1.0 Deprecates package-root imports ✅ No impact — code already uses dedicated entry points (/closest-edge, /util/reorder-with-edge, etc.)
hitbox 2.1.0 Updated core dep to ^3.0.0 ⚠️ Requires coordinated core bump
core 3.0.0 New direct export paths; legacy paths kept as deprecated shims ✅ No code changes needed — PragmaticDND.js import paths remain valid

Test coverage

DND behavior is covered by 3 Playwright integration tests in favorites.spec.js:

  • re-orders items
  • support drop on placeholders
  • accepts external drag/drop

These pass on this branch (3/3), but they do not exercise every adapter path (e.g. custom drag preview, canMonitor filtering). No unit tests exist for PragmaticDND.js.

Validation needed after combined bump: manual smoke test of favorites drag-reorder on macOS Safari and Windows (native drag preview behavior was the original reason for the v2.0.1 bump in PR #2826).


Is this dependency still needed?

Yes. @atlaskit/pragmatic-drag-and-drop + hitbox are the sole DND implementation for new-tab favorites (PragmaticDND.js). No alternative DND library is used elsewhere in the repo. The Atlassian library remains the right choice for native HTML5 drag-and-drop with edge-based reordering.


Supply chain risk: Low

  • Publisher: Atlassian (@atlaskit/*), Apache-2.0
  • Source: github.com/atlassian/pragmatic-drag-and-drop (public monorepo)
  • Downloads: ~860k/week for hitbox
  • No known CVEs in the version range
  • Note: hitbox 2.2.0 is now latest (published after this PR); a combined bump to ^2.1.0 / ^3.0.0 resolves to 2.2.0 / 3.1.0 automatically

Fix PR

Opened # combining both bumps so npm dedupes to a single core instance. Dependabot PR #3000 (core v3 only) also exists but has the inverse problem — it leaves hitbox at ^2.0.0.

Open in Web View Automation 

Sent by Cursor Automation: Review dependabot

"dependencies": {
"@atlaskit/pragmatic-drag-and-drop": "^2.0.2",
"@atlaskit/pragmatic-drag-and-drop-hitbox": "^2.0.0",
"@atlaskit/pragmatic-drag-and-drop-hitbox": "^2.1.0",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Blocking: hitbox ^2.1.0 pulls in @atlaskit/pragmatic-drag-and-drop@^3.0.0 as a nested dependency, but this line still pins the direct dependency to ^2.0.2. That installs two versions of the core package side-by-side.

Bump this to ^3.0.0 in the same PR (see combined fix PR).

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Dependency update review: @atlaskit/pragmatic-drag-and-drop-hitbox 2.0.0 → 2.1.0

Verdict: Do not merge in isolation — combine with @atlaskit/pragmatic-drag-and-drop v3 bump


Confirmed issue: duplicate core package versions

Hitbox 2.1.0 declares a dependency on @atlaskit/pragmatic-drag-and-drop ^3.0.0, but this PR leaves the direct dependency at ^2.0.2. After npm ci:

special-pages
├── @atlaskit/pragmatic-drag-and-drop-hitbox@2.1.0
│   └── @atlaskit/pragmatic-drag-and-drop@3.0.0
└── @atlaskit/pragmatic-drag-and-drop@2.0.2

PragmaticDND.js imports adapters, monitors, and previews from the v2 instance, while hitbox utilities (attachClosestEdge, extractClosestEdge, reorderWithEdge) run against the v3 instance. Pragmatic DND relies on shared internal state across these modules — two copies can cause subtle runtime failures (drag monitors not firing, edge detection mismatches) even when tests pass.

Recommendation: Close this PR and merge the combined fix in #3003 (or merge alongside Dependabot PR #3000).


Changelog impact (low risk once deduped)

Package Change Impact on this repo
hitbox 2.1.0 Deprecates package-root imports ✅ No impact — code already uses dedicated entry points (/closest-edge, /util/reorder-with-edge, etc.)
hitbox 2.1.0 Updated core dep to ^3.0.0 ⚠️ Requires coordinated core bump
core 3.0.0 New direct export paths; legacy paths kept as deprecated shims ✅ No code changes needed — PragmaticDND.js import paths remain valid

Test coverage

DND behavior is covered by 3 Playwright integration tests in favorites.spec.js:

  • re-orders items
  • support drop on placeholders
  • accepts external drag/drop

These pass on this branch (3/3), but they do not exercise every adapter path (e.g. custom drag preview, canMonitor filtering). No unit tests exist for PragmaticDND.js.

Validation needed after combined bump: manual smoke test of favorites drag-reorder on macOS Safari and Windows (native drag preview behavior was the original reason for the v2.0.1 bump in PR #2826).


Is this dependency still needed?

Yes. @atlaskit/pragmatic-drag-and-drop + hitbox are the sole DND implementation for new-tab favorites (PragmaticDND.js). No alternative DND library is used elsewhere in the repo. The Atlassian library remains the right choice for native HTML5 drag-and-drop with edge-based reordering.


Supply chain risk: Low

  • Publisher: Atlassian (@atlaskit/*), Apache-2.0
  • Source: github.com/atlassian/pragmatic-drag-and-drop (public monorepo)
  • Downloads: ~860k/week for hitbox
  • No known CVEs in the version range
  • Note: hitbox 2.2.0 is now latest (published after this PR); a combined bump to ^2.1.0 / ^3.0.0 resolves to 2.2.0 / 3.1.0 automatically

Fix PR

Opened #3003 combining both bumps so npm dedupes to a single core instance. Dependabot PR #3000 (core v3 only) also has the inverse problem — it leaves hitbox at ^2.0.0.

Open in Web View Automation 

Sent by Cursor Automation: Review dependabot

"dependencies": {
"@atlaskit/pragmatic-drag-and-drop": "^2.0.2",
"@atlaskit/pragmatic-drag-and-drop-hitbox": "^2.0.0",
"@atlaskit/pragmatic-drag-and-drop-hitbox": "^2.1.0",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Blocking: hitbox ^2.1.0 pulls in @atlaskit/pragmatic-drag-and-drop@^3.0.0 as a nested dependency, but this line still pins the direct dependency to ^2.0.2. That installs two versions of the core package side-by-side.

Bump this to ^3.0.0 in the same PR (see combined fix PR #3003).

Copy link
Copy Markdown
Contributor

·@·d·ependabot r·ebase


Generated by Claude Code

@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

[Beta] Generated file diff

Time updated: Tue, 08 Sep 2026 15:39:54 GMT

Apple
    - apple/pages/new-tab/dist/index.js

File has changed

Integration
    - integration/pages/new-tab/dist/index.js

File has changed

Windows
    - windows/pages/new-tab/dist/index.js

File has changed

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependency update review: @atlaskit/pragmatic-drag-and-drop-hitbox 2.0.0 → 2.1.0

Verdict: Do not merge in isolation. The hitbox bump is safe functionally, but it implicitly upgrades the core pragmatic-drag-and-drop peer to v3 while the app still depends on v2 — leaving two copies of the core library installed.


Confirmed issues

1. Dual core versions installed (blocking)

hitbox@2.1.0 depends on @atlaskit/pragmatic-drag-and-drop@^3.0.0, but special-pages/package.json still pins the direct dependency at ^2.0.2.

After npm ci:

special-pages
├── @atlaskit/pragmatic-drag-and-drop-hitbox@2.1.0
│   └── @atlaskit/pragmatic-drag-and-drop@3.0.0   ← nested
└── @atlaskit/pragmatic-drag-and-drop@2.0.2       ← direct

PragmaticDND.js imports adapters from the direct v2 instance (element/adapter, external/adapter, combine, etc.) while hitbox utilities (attachClosestEdge, extractClosestEdge, reorderWithEdge) run against the nested v3 instance. Pragmatic DnD relies on shared drag state across these modules — two major versions side-by-side is an unsupported layout.

Impact: ~4.4 MB of duplicated node_modules on disk; potential subtle drag-and-drop breakage in production browsers even when headless tests pass.

Fix: Bump @atlaskit/pragmatic-drag-and-drop to ^3.0.0 in the same change. Draft PRs already exist: #3003 and #3004 (combined core + hitbox bump). Recommend closing this PR in favor of one of those.


Changelog analysis

hitbox 2.1.0 (changelog):

  • Deprecates package-root imports in favor of dedicated entry points — no impact; PragmaticDND.js already uses @atlaskit/pragmatic-drag-and-drop-hitbox/closest-edge and util/* paths.
  • Updated dependencies → pulls in core ^3.0.0 (the root cause of issue #1).

core 3.0.0 (changelog):

  • Adds new direct export paths; legacy paths (element/adapter, external/adapter, etc.) preserved as deprecated compatibility shims.
  • No breaking API changes for the import paths used in PragmaticDND.js.

Test coverage

Area Coverage
Unit tests for PragmaticDND.js None
Integration: reorder (re-orders items) ✅ favorites.spec.js
Integration: placeholder drop ✅ favorites.spec.js
Integration: external drag/drop ✅ favorites.spec.js
Cross-browser manual DnD Not covered

Ran locally with the dual-version layout: 3/3 DnD integration tests passed. Passing tests do not eliminate the dual-version risk.


Is this dependency still needed?

Yes. @atlaskit/pragmatic-drag-and-drop + hitbox is the only DnD solution in the repo, used exclusively for new-tab favorites reordering (PragmaticDND.js → FavoritesCustomized.js). No lighter in-repo alternative exists; the library is the right tool for grid reordering with external drop support.


Supply chain

Check Status
Publisher Atlassian (@atlaskit/*) — established maintainer
License Apache-2.0
Source github.com/atlassian/pragmatic-drag-and-drop
Lockfile integrity SHA-512 hashes present for both packages
Install scripts None
Known CVEs in this bump None identified

Low supply-chain risk.


Recommended action

  1. Close #3002 without merging.
  2. Merge #3003 (or #3004) which bumps both pragmatic-drag-and-drop → ^3.0.0 and hitbox → ^2.1.0 together.
  3. Optionally coordinate with Dependabot PR #3000 (core-only bump) — same dual-version issue applies there in reverse.

No new fix PR needed; #3003/#3004 already cover this.

Open in Web View Automation 

Sent by Cursor Automation: Review dependabot

"dependencies": {
"@atlaskit/pragmatic-drag-and-drop": "^2.0.2",
"@atlaskit/pragmatic-drag-and-drop-hitbox": "^2.0.0",
"@atlaskit/pragmatic-drag-and-drop-hitbox": "^2.1.0",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Blocking: hitbox@2.1.0 depends on @atlaskit/pragmatic-drag-and-drop@^3.0.0, but this line still pins the direct dependency to ^2.0.2. After install, npm resolves two major versions of the core package:

@atlaskit/pragmatic-drag-and-drop@2.0.2        (direct — used by PragmaticDND adapters)
@atlaskit/pragmatic-drag-and-drop@3.0.0        (nested under hitbox — used by closest-edge utils)

Bump this to ^3.0.0 in the same PR. Draft fix already open: #3003.

@dependabot @github

dependabot Bot commented on behalf of github Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/main/atlaskit/pragmatic-drag-and-drop-hitbox-2.1.0 branch September 11, 2026 11:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Update one or more dependencies version minor Increment the minor version when merged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant