build(deps): bump @atlaskit/pragmatic-drag-and-drop-hitbox from 2.0.0 to 2.1.0 - #3002
dependabot[bot] wants to merge 2 commits into
Conversation
Bumps [@atlaskit/pragmatic-drag-and-drop-hitbox](https://github.com/atlassian/pragmatic-drag-and-drop) from 2.0.0 to 2.1.0. - [Commits](https://github.com/atlassian/pragmatic-drag-and-drop/commits) --- updated-dependencies: - dependency-name: "@atlaskit/pragmatic-drag-and-drop-hitbox" dependency-version: 2.1.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Injected PR Evaluation: Web Compatibility & Security
Scope note: This Dependabot PR only updates special-pages/package.json and package-lock.json. There are zero changes to injected/, messaging/, or any runtime injected feature code.
Web Compatibility Assessment
| File | Lines | Severity | Finding |
|---|---|---|---|
| — | — | info | No injected/src/ changes. API surface fidelity, prototype patching, DOM interaction safety, timing/race patterns, platform-specific injected behavior, and third-party script compatibility categories are not applicable to this diff. |
package-lock.json |
155–170 | info | @atlaskit/pragmatic-drag-and-drop-hitbox@2.1.0 now depends on @atlaskit/pragmatic-drag-and-drop@^3.0.0, while special-pages/package.json still declares @atlaskit/pragmatic-drag-and-drop@^2.0.2. npm resolves both (v2 top-level, v3 nested under hitbox). This is a special-pages NTP favorites concern only — not third-party web compatibility. Favorites DnD integration tests pass locally (re-orders items, support drop on placeholders, accepts external drag/drop). |
Security Assessment
| File | Lines | Severity | Finding |
|---|---|---|---|
| — | — | info | No changes to captured-globals.js, wrapper-utils.js, message-bridge.js, messaging transports, or shouldExemptMethod(). Global capture hygiene, messaging trust boundaries, prototype attacks, and iframe security categories are not applicable. |
| — | — | info | Dependency-only bump in special-pages (embedded NTP page, not injected into hostile third-party pages). No new postMessage, eval, dynamic code execution, or config-gated feature surface introduced. |
Risk Level
Low Risk — dependency-only change with no injected runtime code; special-pages favorites DnD tests green.
Recommendations
- Optional follow-up: Consider bumping
@atlaskit/pragmatic-drag-and-dropto^3.xinspecial-pages/package.jsonto align with hitbox 2.1.0's peer dependency and avoid dual-version bundling (not blocking — tests pass today). - No injected-specific action required.
Sent by Cursor Automation: Web compat and sec
| "license": "Apache-2.0", | ||
| "dependencies": { | ||
| "@atlaskit/pragmatic-drag-and-drop": "^2.0.0", | ||
| "@atlaskit/pragmatic-drag-and-drop": "^3.0.0", |
There was a problem hiding this comment.
info (special-pages only, not injected): Hitbox 2.1.0 pulls in @atlaskit/pragmatic-drag-and-drop@^3.0.0 (nested v3.0.0 below), while the app still imports adapters from v2 (^2.0.2 in special-pages/package.json). Favorites DnD integration tests pass with this layout, but consolidating to a single major version would reduce bundle size and avoid future cross-version drag-state edge cases.
There was a problem hiding this comment.
Stale comment
Dependency update review:
@atlaskit/pragmatic-drag-and-drop-hitbox2.0.0 → 2.1.0Verdict: Do not merge in isolation — combine with
@atlaskit/pragmatic-drag-and-dropv3 bump
Confirmed issue: duplicate core package versions
Hitbox 2.1.0 declares a dependency on
@atlaskit/pragmatic-drag-and-drop^3.0.0, but this PR leaves the direct dependency at ^2.0.2. Afternpm ci:special-pages ├── @atlaskit/pragmatic-drag-and-drop-hitbox@2.1.0 │ └── @atlaskit/pragmatic-drag-and-drop@3.0.0 └── @atlaskit/pragmatic-drag-and-drop@2.0.2
PragmaticDND.jsimports adapters, monitors, and previews from the v2 instance, while hitbox utilities (attachClosestEdge,extractClosestEdge,reorderWithEdge) run against the v3 instance. Pragmatic DND relies on shared internal state across these modules — two copies can cause subtle runtime failures (drag monitors not firing, edge detection mismatches) even when tests pass.Recommendation: Close this PR and merge the combined fix in # (or merge alongside Dependabot PR #3000).
Changelog impact (low risk once deduped)
Package Change Impact on this repo hitbox 2.1.0 Deprecates package-root imports ✅ No impact — code already uses dedicated entry points ( /closest-edge,/util/reorder-with-edge, etc.)hitbox 2.1.0 Updated core dep to ^3.0.0 ⚠️ Requires coordinated core bumpcore 3.0.0 New direct export paths; legacy paths kept as deprecated shims ✅ No code changes needed — PragmaticDND.jsimport paths remain valid
Test coverage
DND behavior is covered by 3 Playwright integration tests in
favorites.spec.js:
re-orders itemssupport drop on placeholdersaccepts external drag/dropThese pass on this branch (3/3), but they do not exercise every adapter path (e.g. custom drag preview,
canMonitorfiltering). No unit tests exist forPragmaticDND.js.Validation needed after combined bump: manual smoke test of favorites drag-reorder on macOS Safari and Windows (native drag preview behavior was the original reason for the v2.0.1 bump in PR #2826).
Is this dependency still needed?
Yes.
@atlaskit/pragmatic-drag-and-drop+ hitbox are the sole DND implementation for new-tab favorites (PragmaticDND.js). No alternative DND library is used elsewhere in the repo. The Atlassian library remains the right choice for native HTML5 drag-and-drop with edge-based reordering.
Supply chain risk: Low
- Publisher: Atlassian (
@atlaskit/*), Apache-2.0- Source: github.com/atlassian/pragmatic-drag-and-drop (public monorepo)
- Downloads: ~860k/week for hitbox
- No known CVEs in the version range
- Note: hitbox 2.2.0 is now latest (published after this PR); a combined bump to
^2.1.0/^3.0.0resolves to 2.2.0 / 3.1.0 automatically
Fix PR
Opened # combining both bumps so npm dedupes to a single core instance. Dependabot PR #3000 (core v3 only) also exists but has the inverse problem — it leaves hitbox at ^2.0.0.
Sent by Cursor Automation: Review dependabot
| "dependencies": { | ||
| "@atlaskit/pragmatic-drag-and-drop": "^2.0.2", | ||
| "@atlaskit/pragmatic-drag-and-drop-hitbox": "^2.0.0", | ||
| "@atlaskit/pragmatic-drag-and-drop-hitbox": "^2.1.0", |
There was a problem hiding this comment.
^2.1.0 pulls in @atlaskit/pragmatic-drag-and-drop@^3.0.0 as a nested dependency, but this line still pins the direct dependency to ^2.0.2. That installs two versions of the core package side-by-side.
Bump this to ^3.0.0 in the same PR (see combined fix PR).
There was a problem hiding this comment.
Stale comment
Dependency update review:
@atlaskit/pragmatic-drag-and-drop-hitbox2.0.0 → 2.1.0Verdict: Do not merge in isolation — combine with
@atlaskit/pragmatic-drag-and-dropv3 bump
Confirmed issue: duplicate core package versions
Hitbox 2.1.0 declares a dependency on
@atlaskit/pragmatic-drag-and-drop^3.0.0, but this PR leaves the direct dependency at ^2.0.2. Afternpm ci:special-pages ├── @atlaskit/pragmatic-drag-and-drop-hitbox@2.1.0 │ └── @atlaskit/pragmatic-drag-and-drop@3.0.0 └── @atlaskit/pragmatic-drag-and-drop@2.0.2
PragmaticDND.jsimports adapters, monitors, and previews from the v2 instance, while hitbox utilities (attachClosestEdge,extractClosestEdge,reorderWithEdge) run against the v3 instance. Pragmatic DND relies on shared internal state across these modules — two copies can cause subtle runtime failures (drag monitors not firing, edge detection mismatches) even when tests pass.Recommendation: Close this PR and merge the combined fix in #3003 (or merge alongside Dependabot PR #3000).
Changelog impact (low risk once deduped)
Package Change Impact on this repo hitbox 2.1.0 Deprecates package-root imports ✅ No impact — code already uses dedicated entry points ( /closest-edge,/util/reorder-with-edge, etc.)hitbox 2.1.0 Updated core dep to ^3.0.0 ⚠️ Requires coordinated core bumpcore 3.0.0 New direct export paths; legacy paths kept as deprecated shims ✅ No code changes needed — PragmaticDND.jsimport paths remain valid
Test coverage
DND behavior is covered by 3 Playwright integration tests in
favorites.spec.js:
re-orders itemssupport drop on placeholdersaccepts external drag/dropThese pass on this branch (3/3), but they do not exercise every adapter path (e.g. custom drag preview,
canMonitorfiltering). No unit tests exist forPragmaticDND.js.Validation needed after combined bump: manual smoke test of favorites drag-reorder on macOS Safari and Windows (native drag preview behavior was the original reason for the v2.0.1 bump in PR #2826).
Is this dependency still needed?
Yes.
@atlaskit/pragmatic-drag-and-drop+ hitbox are the sole DND implementation for new-tab favorites (PragmaticDND.js). No alternative DND library is used elsewhere in the repo. The Atlassian library remains the right choice for native HTML5 drag-and-drop with edge-based reordering.
Supply chain risk: Low
- Publisher: Atlassian (
@atlaskit/*), Apache-2.0- Source: github.com/atlassian/pragmatic-drag-and-drop (public monorepo)
- Downloads: ~860k/week for hitbox
- No known CVEs in the version range
- Note: hitbox 2.2.0 is now latest (published after this PR); a combined bump to
^2.1.0/^3.0.0resolves to 2.2.0 / 3.1.0 automatically
Fix PR
Opened #3003 combining both bumps so npm dedupes to a single core instance. Dependabot PR #3000 (core v3 only) also has the inverse problem — it leaves hitbox at ^2.0.0.
Sent by Cursor Automation: Review dependabot
| "dependencies": { | ||
| "@atlaskit/pragmatic-drag-and-drop": "^2.0.2", | ||
| "@atlaskit/pragmatic-drag-and-drop-hitbox": "^2.0.0", | ||
| "@atlaskit/pragmatic-drag-and-drop-hitbox": "^2.1.0", |
There was a problem hiding this comment.
^2.1.0 pulls in @atlaskit/pragmatic-drag-and-drop@^3.0.0 as a nested dependency, but this line still pins the direct dependency to ^2.0.2. That installs two versions of the core package side-by-side.
Bump this to ^3.0.0 in the same PR (see combined fix PR #3003).
|
·@·d·ependabot r·ebase Generated by Claude Code |
…tic-drag-and-drop-hitbox-2.1.0
[Beta] Generated file diffTime updated: Tue, 08 Sep 2026 15:39:54 GMT AppleFile has changed IntegrationFile has changed WindowsFile has changed |
There was a problem hiding this comment.
Dependency update review: @atlaskit/pragmatic-drag-and-drop-hitbox 2.0.0 → 2.1.0
Verdict: Do not merge in isolation. The hitbox bump is safe functionally, but it implicitly upgrades the core pragmatic-drag-and-drop peer to v3 while the app still depends on v2 — leaving two copies of the core library installed.
Confirmed issues
1. Dual core versions installed (blocking)
hitbox@2.1.0 depends on @atlaskit/pragmatic-drag-and-drop@^3.0.0, but special-pages/package.json still pins the direct dependency at ^2.0.2.
After npm ci:
special-pages
├── @atlaskit/pragmatic-drag-and-drop-hitbox@2.1.0
│ └── @atlaskit/pragmatic-drag-and-drop@3.0.0 ← nested
└── @atlaskit/pragmatic-drag-and-drop@2.0.2 ← direct
PragmaticDND.js imports adapters from the direct v2 instance (element/adapter, external/adapter, combine, etc.) while hitbox utilities (attachClosestEdge, extractClosestEdge, reorderWithEdge) run against the nested v3 instance. Pragmatic DnD relies on shared drag state across these modules — two major versions side-by-side is an unsupported layout.
Impact: ~4.4 MB of duplicated node_modules on disk; potential subtle drag-and-drop breakage in production browsers even when headless tests pass.
Fix: Bump @atlaskit/pragmatic-drag-and-drop to ^3.0.0 in the same change. Draft PRs already exist: #3003 and #3004 (combined core + hitbox bump). Recommend closing this PR in favor of one of those.
Changelog analysis
hitbox 2.1.0 (changelog):
- Deprecates package-root imports in favor of dedicated entry points — no impact;
PragmaticDND.jsalready uses@atlaskit/pragmatic-drag-and-drop-hitbox/closest-edgeandutil/*paths. - Updated dependencies → pulls in core
^3.0.0(the root cause of issue #1).
core 3.0.0 (changelog):
- Adds new direct export paths; legacy paths (
element/adapter,external/adapter, etc.) preserved as deprecated compatibility shims. - No breaking API changes for the import paths used in
PragmaticDND.js.
Test coverage
| Area | Coverage |
|---|---|
Unit tests for PragmaticDND.js |
None |
Integration: reorder (re-orders items) |
✅ favorites.spec.js |
| Integration: placeholder drop | ✅ favorites.spec.js |
| Integration: external drag/drop | ✅ favorites.spec.js |
| Cross-browser manual DnD | Not covered |
Ran locally with the dual-version layout: 3/3 DnD integration tests passed. Passing tests do not eliminate the dual-version risk.
Is this dependency still needed?
Yes. @atlaskit/pragmatic-drag-and-drop + hitbox is the only DnD solution in the repo, used exclusively for new-tab favorites reordering (PragmaticDND.js → FavoritesCustomized.js). No lighter in-repo alternative exists; the library is the right tool for grid reordering with external drop support.
Supply chain
| Check | Status |
|---|---|
| Publisher | Atlassian (@atlaskit/*) — established maintainer |
| License | Apache-2.0 |
| Source | github.com/atlassian/pragmatic-drag-and-drop |
| Lockfile integrity | SHA-512 hashes present for both packages |
| Install scripts | None |
| Known CVEs in this bump | None identified |
Low supply-chain risk.
Recommended action
- Close #3002 without merging.
- Merge #3003 (or #3004) which bumps both
pragmatic-drag-and-drop→^3.0.0andhitbox→^2.1.0together. - Optionally coordinate with Dependabot PR #3000 (core-only bump) — same dual-version issue applies there in reverse.
No new fix PR needed; #3003/#3004 already cover this.
Sent by Cursor Automation: Review dependabot
| "dependencies": { | ||
| "@atlaskit/pragmatic-drag-and-drop": "^2.0.2", | ||
| "@atlaskit/pragmatic-drag-and-drop-hitbox": "^2.0.0", | ||
| "@atlaskit/pragmatic-drag-and-drop-hitbox": "^2.1.0", |
There was a problem hiding this comment.
hitbox@2.1.0 depends on @atlaskit/pragmatic-drag-and-drop@^3.0.0, but this line still pins the direct dependency to ^2.0.2. After install, npm resolves two major versions of the core package:
@atlaskit/pragmatic-drag-and-drop@2.0.2 (direct — used by PragmaticDND adapters)
@atlaskit/pragmatic-drag-and-drop@3.0.0 (nested under hitbox — used by closest-edge utils)
Bump this to ^3.0.0 in the same PR. Draft fix already open: #3003.
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |


Bumps @atlaskit/pragmatic-drag-and-drop-hitbox from 2.0.0 to 2.1.0.
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Note
Low Risk
Dependency-only minor bump for drag-and-drop hitbox utilities; possible dual major versions of the core Atlaskit package in the lockfile, but no direct code changes.
Overview
Bumps
@atlaskit/pragmatic-drag-and-drop-hitboxfrom2.0.0to2.1.0inspecial-pages/package.json, with the rootpackage-lock.jsonupdated accordingly.The lockfile also records that hitbox 2.1.0 depends on
@atlaskit/pragmatic-drag-and-drop^3.0.0 (nested 3.0.0), whilespecial-pagesstill declares the core package at^2.0.2—so runtime may resolve two major versions unless hoisting aligns them. No app source changes; new-tab favorites DnD (PragmaticDND.js) continues to import the same hitbox APIs.Reviewed by Cursor Bugbot for commit 1682db2. Bugbot is set up for automated code reviews on this repo. Configure here.