github-actions[bot]
0650ae970f
chore(lockfile): refresh pnpm-lock.yaml ( #10136 )
...
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
2026-07-23 18:51:14 -07:00
github-actions[bot]
486ecac5e9
chore(lockfile): refresh pnpm-lock.yaml ( #9964 )
...
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
2026-07-22 08:58:37 -07:00
dependabot[bot]
0d2bfee972
build(deps): bump radix-ui from 1.6.0 to 1.6.4 ( #9895 )
...
Bumps
[radix-ui](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/radix-ui )
from 1.6.0 to 1.6.4.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/radix-ui/primitives/blob/main/packages/react/radix-ui/CHANGELOG.md ">radix-ui's
changelog</a>.</em></p>
<blockquote>
<h2>1.6.4</h2>
<ul>
<li>Fixed a regression where importing primitives from the root
<code>radix-ui</code> entry point erased every primitive's types to
<code>any</code>.</li>
</ul>
<h2>1.6.3</h2>
<h3>Dialog</h3>
<ul>
<li>Fixed broken ARIA references in Dialogs where title or description
elements are not rendered.</li>
</ul>
<h3>Slider</h3>
<ul>
<li>Fixed a bug where <code>onValueCommit</code> was not called when a
slider thumb was dragged across another thumb.</li>
</ul>
<h3>Toast</h3>
<ul>
<li>Fixed <code>Toast</code> removing non-focused toasts when pressing
<code>Escape</code>.</li>
</ul>
<h3>Tooltip</h3>
<ul>
<li>Fixed a bug where <code>Tooltip.Content</code> children were mounted
to the DOM twice.</li>
</ul>
<h3>Other updates</h3>
<ul>
<li>Fixed overriding inline animation style in
<code>Popper.Content</code>.</li>
<li>Improved tree-shaking so bundlers can drop unused components.
Component parts are now marked <code>/* @__PURE__ */</code> and use
named render functions instead of <code>Component.displayName =
...</code> assignments, which previously prevented dead-code elimination
with some bundlers.</li>
<li>Widened <code>virtualRef</code> prop type to allow
<code>RefObject<Measurable | null></code> in popover
components.</li>
<li>Fixed dev-only checks with conditional exports to drop dev-warnings
from production builds.</li>
<li>Added per-primitive subpath entry points so each primitive can be
imported directly, eg. <code>import { Accordion } from
'radix-ui/accordion'</code> or <code>import * as Accordion from
'radix-ui/accordion'</code>. This mirrors the namespaced exports
available from the root <code>radix-ui</code> entry point.</li>
<li>Fixed a bug where updating a <code>Checkbox</code>,
<code>Switch</code>, or <code>RadioGroup</code> value programmatically
(eg. a "select all" control) while inside a
<code><form></code> would dispatch a <code>click</code> event from
the hidden bubble input that propagated to ancestor <code>onClick</code>
handlers.</li>
</ul>
<h2>1.6.2</h2>
<h3>Other updates</h3>
<ul>
<li>Added CSS custom properties for Navigation Menu item indicators'
translate values.</li>
<li>Fixed a bug in Dismissable Layer causing background nested popovers
to close all layers on outside click</li>
<li>Fixed runtime errors for <code>Form.Message</code>,
<code>Form.Control</code>, <code>Form.Label</code> and
<code>Form.ValidityState</code> that are correctly rendered outside of
<code>Form.Field</code> components</li>
<li>Fixed a bug in form control components to ensure their values are
updated when their associated form's is reset. This affects
<code>RadioGroup</code>, <code>Slider</code>, <code>Select</code>, and
<code>Switch</code>.</li>
<li>Fixed menu items, tab triggers, toolbar links, and select items
intercepting <code>Space</code>/<code>Enter</code> keys that originate
from focusable descendants.</li>
<li>Fixed a bug where calling an event handler without an argument would
throw, preventing successive event handlers from being called. This
affected all components that accept event handlers with internal
implementations.</li>
<li>Fixed a bug in Context Menu to ensure that the menu properly
re-anchors to the latest pointer position when re-triggered in its open
state.</li>
<li>Fixed stale <code>onEscapeKeyDown</code>/<code>onDismiss</code>
handlers on React 19.2.</li>
<li>Fixed items in a Roving Focus Group not being auto-focused on mount
within a Focus Scope component.</li>
<li>Fixed a regression in Dismissable Layer originating from a <a
href="https://redirect.github.com/react/react/pull/34831 ">bug in React's
<code>useEffectEvent</code></a>.</li>
<li>Fixed <code>--radix-scroll-area-corner-width</code> and
<code>--radix-scroll-area-corner-height</code> not resetting to
<code>0</code> when a corner is removed. Previously these values would
stick around and leave a permanent gap on the remaining scrollbar.</li>
<li>Fixed a bug in Slider where stepping with the keyboard would skip a
valid value when the current value is off the step grid. Stepping now
snaps to the next step-aligned value in the direction of travel,
matching native <code><input type="range"></code>
behavior.</li>
</ul>
<h2>1.6.1</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/radix-ui/primitives/commits/HEAD/packages/react/radix-ui ">compare
view</a></li>
</ul>
</details>
<details>
<summary>Attestation changes</summary>
<p>This version has no provenance attestation, while the previous
version (1.6.0) was attested. Review the <a
href="https://www.npmjs.com/package/radix-ui?activeTab=versions ">package
versions</a> before updating.</p>
</details>
<br />
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 12:55:55 -05:00
dependabot[bot]
31c59f8822
build(deps-dev): bump @playwright/test from 1.58.2 to 1.61.1 ( #9887 )
...
Bumps [@playwright/test](https://github.com/microsoft/playwright ) from
1.58.2 to 1.61.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/microsoft/playwright/releases ">@playwright/test's
releases</a>.</em></p>
<blockquote>
<h2>v1.61.1</h2>
<h3>Bug Fixes</h3>
<ul>
<li><a
href="https://redirect.github.com/microsoft/playwright/issues/41365 ">#41365</a>
[Bug]: Expect.Extend matcher with same name as default matcher in same
expect instance overrides default matchers implementation to custom
matcher</li>
<li><a
href="https://redirect.github.com/microsoft/playwright/issues/41351 ">#41351</a>
[Bug]: Playwright UI mode: apiRequestContext._wrapApiCall reports
unexpected number of bytes (same test passes in headed mode)</li>
<li><a
href="https://redirect.github.com/microsoft/playwright/issues/41360 ">#41360</a>
[Bug]: Trace viewer: message times in websockets are downscaled by
1000</li>
<li><a
href="https://redirect.github.com/microsoft/playwright/issues/41311 ">#41311</a>
[Bug]: [Regression]: Sync loader throws
"context.conditions?.includes is not a function" on Node
22.15</li>
<li><a
href="https://redirect.github.com/microsoft/playwright/issues/41371 ">#41371</a>
[Regression]: Sync ESM loader (registerHooks) fails to resolve
extensionless .ts subpath imports across pnpm workspace symlinks</li>
</ul>
<h2>v1.61.0</h2>
<h2>🔑 WebAuthn passkeys</h2>
<p>New <a
href="https://playwright.dev/docs/api/class-credentials ">Credentials</a>
virtual authenticator, available via <a
href="https://playwright.dev/docs/api/class-browsercontext#browser-context-credentials ">browserContext.credentials</a>,
lets tests register passkeys and answer
<code>navigator.credentials.create()</code> /
<code>navigator.credentials.get()</code> ceremonies in the page — no
real hardware key required, works in all browsers:</p>
<pre lang="js"><code>const context = await browser.newContext();
<p>// Seed a passkey your backend provisioned for a test user.
await context.credentials.create('example.com', {
id: credentialId,
userHandle,
privateKey,
publicKey,
});
await context.credentials.install();</p>
<p>const page = await context.newPage();
await page.goto('<a
href="https://example.com/login ">https://example.com/login </a>');
// The page's navigator.credentials.get() is answered with the seeded
passkey.
</code></pre></p>
<p>You can also let the app register a passkey once in a setup test,
read it back with <a
href="https://playwright.dev/docs/api/class-credentials#credentials-get ">credentials.get()</a>,
and seed it into later tests — see <a
href="https://playwright.dev/docs/api/class-credentials ">Credentials</a>
for details.</p>
<h2>🗃️ Web Storage</h2>
<p>New <a
href="https://playwright.dev/docs/api/class-webstorage ">WebStorage</a>
API, available via <a
href="https://playwright.dev/docs/api/class-page#page-local-storage ">page.localStorage</a>
and <a
href="https://playwright.dev/docs/api/class-page#page-session-storage ">page.sessionStorage</a>,
reads and writes the page's storage for the current origin:</p>
<pre lang="js"><code>await page.localStorage.setItem('token', 'abc');
const token = await page.localStorage.getItem('token');
const items = await page.sessionStorage.items();
</code></pre>
<h2>New APIs</h2>
<h3>Network</h3>
<ul>
<li><a
href="https://playwright.dev/docs/api/class-apiresponse#api-response-security-details ">apiResponse.securityDetails()</a>
and <a
href="https://playwright.dev/docs/api/class-apiresponse#api-response-server-addr ">apiResponse.serverAddr()</a>
mirror the browser-side <a
href="https://playwright.dev/docs/api/class-response#response-security-details ">response.securityDetails()</a>
and <a
href="https://playwright.dev/docs/api/class-response#response-server-addr ">response.serverAddr()</a>.</li>
</ul>
<h3>Browser and Screencast</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="39e3553a4f "><code>39e3553</code></a>
cherry-pick(<a
href="https://redirect.github.com/microsoft/playwright/issues/41399 ">#41399</a>):
fix(test): load require-reached files as commonjs in syn...</li>
<li><a
href="4328122a0f "><code>4328122</code></a>
chore: mark v1.61.1 (<a
href="https://redirect.github.com/microsoft/playwright/issues/41404 ">#41404</a>)</li>
<li><a
href="2c29a94ed5 "><code>2c29a94</code></a>
fix(tracing): stop recording websocket frames outside of chunks (<a
href="https://redirect.github.com/microsoft/playwright/issues/41398 ">#41398</a>)</li>
<li><a
href="4324b19041 "><code>4324b19</code></a>
cherry-pick(<a
href="https://redirect.github.com/microsoft/playwright/issues/41367 ">#41367</a>):
fix(test): keep builtin expect matchers on base extend</li>
<li><a
href="041e7e3000 "><code>041e7e3</code></a>
cherry-pick(<a
href="https://redirect.github.com/microsoft/playwright/issues/41364 ">#41364</a>):
fix(har): <code>WebSocket</code> message timestamps should be in
mi...</li>
<li><a
href="b8a0fc3393 "><code>b8a0fc3</code></a>
cherry-pick(<a
href="https://redirect.github.com/microsoft/playwright/issues/41309 ">#41309</a>,
<a
href="https://redirect.github.com/microsoft/playwright/issues/43149 ">#43149</a>):
Revert "fix(firefox): treat `navigationCommitted...</li>
<li><a
href="b5a31759e6 "><code>b5a3175</code></a>
cherry-pick(<a
href="https://redirect.github.com/microsoft/playwright/issues/41319 ">#41319</a>):
fix(loader): support other node versions</li>
<li><a
href="d4724a91b2 "><code>d4724a9</code></a>
cherry-pick(<a
href="https://redirect.github.com/microsoft/playwright/issues/41290 ">#41290</a>):
feat(docker): add Ubuntu 26.04 (Resolute Raccoon) image</li>
<li><a
href="1cc5a90cfa "><code>1cc5a90</code></a>
cherry-pick(<a
href="https://redirect.github.com/microsoft/playwright/issues/41295 ">#41295</a>):
chore: PLAYWRIGHT_TRACING_NO_WEBSOCKET_FRAMES and PLAYWR...</li>
<li><a
href="a6772bdede "><code>a6772bd</code></a>
cherry-pick(<a
href="https://redirect.github.com/microsoft/playwright/issues/41280 ">#41280</a>):
Revert "fix(trace-viewer): add keyboard navigation to `N...</li>
<li>Additional commits viewable in <a
href="https://github.com/microsoft/playwright/compare/v1.58.2...v1.61.1 ">compare
view</a></li>
</ul>
</details>
<br />
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 12:26:18 -05:00
dependabot[bot]
a3f583b5a9
build(deps-dev): bump @tailwindcss/vite from 4.3.0 to 4.3.3 ( #9892 )
...
Bumps
[@tailwindcss/vite](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-vite )
from 4.3.0 to 4.3.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/tailwindlabs/tailwindcss/releases ">@tailwindcss/vite's
releases</a>.</em></p>
<blockquote>
<h2>v4.3.3</h2>
<h3>Fixed</h3>
<ul>
<li>Support <code>--watch --poll[=ms]</code> in
<code>@tailwindcss/cli</code> when filesystem events are unreliable or
unavailable (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20297 ">#20297</a>)</li>
<li>Canonicalization: match arbitrary hex colors against theme colors
case-insensitively (e.g. <code>bg-[#fff]</code> and
<code>bg-[#FFF]</code> → <code>bg-white</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20298 ">#20298</a>)</li>
<li>Prevent Preflight from overriding Firefox's native
<code>iframe:focus-visible</code> outline styles (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20292 ">#20292</a>)</li>
<li>Ensure <code>theme('colors.foo')</code> in JS plugins resolves
correctly when both <code>--color-foo</code> and
<code>--color-foo-bar</code> exist (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20299 ">#20299</a>)</li>
<li>Ensure fractional opacity modifiers work with named shadow sizes
like <code>shadow-sm/12.5</code>, <code>text-shadow-sm/12.5</code>,
<code>drop-shadow-sm/12.5</code>, and <code>inset-shadow-sm/12.5</code>
(<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20302 ">#20302</a>)</li>
<li>Parse selectors like <code>[data-foo]div</code> as two selectors
instead of one (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20303 ">#20303</a>)</li>
<li>Ensure <code>@tailwindcss/postcss</code> rebuilds when a
preprocessor like Sass changes the input CSS without changing the input
file on disk (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20310 ">#20310</a>)</li>
<li>Ensure CSS nesting is handled even when Lightning CSS isn't run,
such as in <code>@tailwindcss/browser</code> and Tailwind Play (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20124 ">#20124</a>)</li>
<li>Prevent achromatic theme colors from shifting hue when mixed in
polar color spaces like <code>oklch</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20314 ">#20314</a>)</li>
<li>Ensure <code>--spacing(0)</code> is optimized to <code>0px</code>
instead of <code>0</code> so it remains a <code><length></code>
when used in <code>calc(…)</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20319 ">#20319</a>)</li>
<li>Load <code>@parcel/watcher</code> only when needed in
<code>@tailwindcss/cli --watch</code> mode, so one-off builds and
<code>--watch --poll</code> work when <code>@parcel/watcher</code> can't
be loaded (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20325 ">#20325</a>)</li>
<li>Use explicit platform fonts instead of <code>system-ui</code> and
<code>ui-sans-serif</code> so CJK text respects the page's
<code>lang</code> attribute on Windows (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20318 ">#20318</a>)</li>
<li>Prevent <code>@tailwindcss/upgrade</code> from rewriting ignored
files when run from a subdirectory (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20329 ">#20329</a>)</li>
<li>Ensure earlier <code>@source</code> rules pointing to nested files
are scanned when later <code>@source</code> rules point to files in
parent folders (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20335 ">#20335</a>)</li>
<li>Prevent <code>@tailwindcss/vite</code> from triggering full page
reloads when scanned files are processed by Vite but haven't been loaded
as modules yet (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20336 ">#20336</a>)</li>
</ul>
<h2>v4.3.2</h2>
<h3>Fixed</h3>
<ul>
<li>Support bare spacing values for <code>auto-rows-*</code> and
<code>auto-cols-*</code> utilities (e.g. <code>auto-rows-12</code> and
<code>auto-cols-16</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20229 ">#20229</a>)</li>
<li>Prevent <code>@tailwindcss/cli</code> in <code>--watch</code> mode
from crashing on Windows when <code>@source</code> points to a directory
that doesn't exist (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20242 ">#20242</a>)</li>
<li>Prevent <code>@tailwindcss/vite</code> from crashing in Deno v2.8.x
when <code>context.parentURL</code> is not a valid URL (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20245 ">#20245</a>)</li>
<li>Ensure <code>@tailwindcss/cli</code> in <code>--watch</code> mode
rebuilds when the input CSS file changes in an ignored directory (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20246 ">#20246</a>)</li>
<li>Allow <code>@variant</code> rules used in <code>addBase(…)</code> to
use custom variants defined later (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20247 ">#20247</a>)</li>
<li>Prevent <code>@tailwindcss/vite</code> from crashing during HMR when
scanned files or directories are deleted (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20259 ">#20259</a>)</li>
<li>Generate <code>font-size</code> instead of <code>color</code>
declarations for <code>text-[--spacing(…)]</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20260 ">#20260</a>)</li>
<li>Prevent <code>@source</code> patterns from scanning unrelated
sibling files and folders (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20263 ">#20263</a>)</li>
<li>Extract class candidates adjacent to Template Toolkit delimiters
like <code>%]…[%</code> in <code>.tt</code>, <code>.tt2</code>, and
<code>.tx</code> files (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20269 ">#20269</a>)</li>
<li>Extract class candidates from conditional Maud syntax like
<code>p.text-black[condition]</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20269 ">#20269</a>)</li>
<li>Prevent <code>@position-try</code> rules from triggering unknown
at-rule warnings when optimizing CSS (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20277 ">#20277</a>)</li>
<li>Support class suggestions for named opacity modifiers from
<code>--opacity</code> theme values (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20287 ">#20287</a>)</li>
<li>Prevent type errors in <code>@tailwindcss/postcss</code> when used
with newer PostCSS patch releases (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20289 ">#20289</a>)</li>
</ul>
<h2>v4.3.1</h2>
<h3>Added</h3>
<ul>
<li>Add <code>--silent</code> option to suppress output in
<code>@tailwindcss/cli</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20100 ">#20100</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Remove deprecation warnings by using
<code>Module#registerHooks</code> instead of
<code>Module#register</code> on Node 26+ (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20028 ">#20028</a>)</li>
<li>Canonicalization: don't crash when plugin utilities throw for
unsupported values (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20052 ">#20052</a>)</li>
<li>Allow <code>@apply</code> to be used with CSS mixins (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19427 ">#19427</a>)</li>
<li>Ensure <code>not-*</code> correctly negates <code>@container</code>
queries, including <code>style(…)</code> queries (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20059 ">#20059</a>)</li>
<li>Ensure <code>drop-shadow-*</code> color utilities work with custom
shadow values containing <code>calc(…)</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20080 ">#20080</a>)</li>
<li>Fix 'Sourcemap is likely to be incorrect' warnings when using
<code>@tailwindcss/vite</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20103 ">#20103</a>)</li>
<li>Ensure <code>@tailwindcss/webpack</code> can be installed in Rspack
projects without requiring <code>webpack</code> as a peer dependency (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20027 ">#20027</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md ">@tailwindcss/vite's
changelog</a>.</em></p>
<blockquote>
<h2>[4.3.3] - 2026-07-16</h2>
<h3>Fixed</h3>
<ul>
<li>Support <code>--watch --poll[=ms]</code> in
<code>@tailwindcss/cli</code> when filesystem events are unreliable or
unavailable (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20297 ">#20297</a>)</li>
<li>Canonicalization: match arbitrary hex colors against theme colors
case-insensitively (e.g. <code>bg-[#fff]</code> and
<code>bg-[#FFF]</code> → <code>bg-white</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20298 ">#20298</a>)</li>
<li>Prevent Preflight from overriding Firefox's native
<code>iframe:focus-visible</code> outline styles (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20292 ">#20292</a>)</li>
<li>Ensure <code>theme('colors.foo')</code> in JS plugins resolves
correctly when both <code>--color-foo</code> and
<code>--color-foo-bar</code> exist (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20299 ">#20299</a>)</li>
<li>Ensure fractional opacity modifiers work with named shadow sizes
like <code>shadow-sm/12.5</code>, <code>text-shadow-sm/12.5</code>,
<code>drop-shadow-sm/12.5</code>, and <code>inset-shadow-sm/12.5</code>
(<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20302 ">#20302</a>)</li>
<li>Parse selectors like <code>[data-foo]div</code> as two selectors
instead of one (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20303 ">#20303</a>)</li>
<li>Ensure <code>@tailwindcss/postcss</code> rebuilds when a
preprocessor like Sass changes the input CSS without changing the input
file on disk (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20310 ">#20310</a>)</li>
<li>Ensure CSS nesting is handled even when Lightning CSS isn't run,
such as in <code>@tailwindcss/browser</code> and Tailwind Play (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20124 ">#20124</a>)</li>
<li>Prevent achromatic theme colors from shifting hue when mixed in
polar color spaces like <code>oklch</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20314 ">#20314</a>)</li>
<li>Ensure <code>--spacing(0)</code> is optimized to <code>0px</code>
instead of <code>0</code> so it remains a <code><length></code>
when used in <code>calc(…)</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20319 ">#20319</a>)</li>
<li>Load <code>@parcel/watcher</code> only when needed in
<code>@tailwindcss/cli --watch</code> mode, so one-off builds and
<code>--watch --poll</code> work when <code>@parcel/watcher</code> can't
be loaded (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20325 ">#20325</a>)</li>
<li>Use explicit platform fonts instead of <code>system-ui</code> and
<code>ui-sans-serif</code> so CJK text respects the page's
<code>lang</code> attribute on Windows (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20318 ">#20318</a>)</li>
<li>Prevent <code>@tailwindcss/upgrade</code> from rewriting ignored
files when run from a subdirectory (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20329 ">#20329</a>)</li>
<li>Ensure earlier <code>@source</code> rules pointing to nested files
are scanned when later <code>@source</code> rules point to files in
parent folders (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20335 ">#20335</a>)</li>
<li>Prevent <code>@tailwindcss/vite</code> from triggering full page
reloads when scanned files are processed by Vite but haven't been loaded
as modules yet (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20336 ">#20336</a>)</li>
</ul>
<h2>[4.3.2] - 2026-06-26</h2>
<h3>Fixed</h3>
<ul>
<li>Support bare spacing values for <code>auto-rows-*</code> and
<code>auto-cols-*</code> utilities (e.g. <code>auto-rows-12</code> and
<code>auto-cols-16</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20229 ">#20229</a>)</li>
<li>Prevent <code>@tailwindcss/cli</code> in <code>--watch</code> mode
from crashing on Windows when <code>@source</code> points to a directory
that doesn't exist (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20242 ">#20242</a>)</li>
<li>Prevent <code>@tailwindcss/vite</code> from crashing in Deno v2.8.x
when <code>context.parentURL</code> is not a valid URL (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20245 ">#20245</a>)</li>
<li>Ensure <code>@tailwindcss/cli</code> in <code>--watch</code> mode
rebuilds when the input CSS file changes in an ignored directory (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20246 ">#20246</a>)</li>
<li>Allow <code>@variant</code> rules used in <code>addBase(…)</code> to
use custom variants defined later (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20247 ">#20247</a>)</li>
<li>Prevent <code>@tailwindcss/vite</code> from crashing during HMR when
scanned files or directories are deleted (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20259 ">#20259</a>)</li>
<li>Generate <code>font-size</code> instead of <code>color</code>
declarations for <code>text-[--spacing(…)]</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20260 ">#20260</a>)</li>
<li>Prevent <code>@source</code> patterns from scanning unrelated
sibling files and folders (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20263 ">#20263</a>)</li>
<li>Extract class candidates adjacent to Template Toolkit delimiters
like <code>%]…[%</code> in <code>.tt</code>, <code>.tt2</code>, and
<code>.tx</code> files (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20269 ">#20269</a>)</li>
<li>Extract class candidates from conditional Maud syntax like
<code>p.text-black[condition]</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20269 ">#20269</a>)</li>
<li>Prevent <code>@position-try</code> rules from triggering unknown
at-rule warnings when optimizing CSS (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20277 ">#20277</a>)</li>
<li>Support class suggestions for named opacity modifiers from
<code>--opacity</code> theme values (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20287 ">#20287</a>)</li>
<li>Prevent type errors in <code>@tailwindcss/postcss</code> when used
with newer PostCSS patch releases (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20289 ">#20289</a>)</li>
</ul>
<h2>[4.3.1] - 2026-06-12</h2>
<h3>Added</h3>
<ul>
<li>Add <code>--silent</code> option to suppress output in
<code>@tailwindcss/cli</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20100 ">#20100</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Remove deprecation warnings by using
<code>Module#registerHooks</code> instead of
<code>Module#register</code> on Node 26+ (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20028 ">#20028</a>)</li>
<li>Canonicalization: don't crash when plugin utilities throw for
unsupported values (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20052 ">#20052</a>)</li>
<li>Allow <code>@apply</code> to be used with CSS mixins (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19427 ">#19427</a>)</li>
<li>Ensure <code>not-*</code> correctly negates <code>@container</code>
queries, including <code>style(…)</code> queries (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20059 ">#20059</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="c2b24dd15f "><code>c2b24dd</code></a>
4.3.3 (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-vite/issues/20334 ">#20334</a>)</li>
<li><a
href="bdcd7087b3 "><code>bdcd708</code></a>
Don't trigger a full page reload for scanned files that Vite processes
as mod...</li>
<li><a
href="056a155072 "><code>056a155</code></a>
4.3.2 (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-vite/issues/20281 ">#20281</a>)</li>
<li><a
href="bb6a10937c "><code>bb6a109</code></a>
use <code>.ts</code> instead of <code>.css</code></li>
<li><a
href="8a14a71010 "><code>8a14a71</code></a>
4.3.1 (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-vite/issues/20226 ">#20226</a>)</li>
<li><a
href="73983e1cf5 "><code>73983e1</code></a>
Fix 'Sourcemap is likely to be incorrect' warnings when using
`@tailwindcss/v...</li>
<li>See full diff in <a
href="https://github.com/tailwindlabs/tailwindcss/commits/v4.3.3/packages/@tailwindcss-vite ">compare
view</a></li>
</ul>
</details>
<br />
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 12:16:25 -05:00
dependabot[bot]
8e856d2518
build(deps): bump @codemirror/state from 6.7.0 to 6.7.1 ( #9890 )
...
Bumps [@codemirror/state](https://github.com/codemirror/state ) from
6.7.0 to 6.7.1.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/codemirror/state/commits ">compare view</a></li>
</ul>
</details>
<br />
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 12:06:44 -05:00
dependabot[bot]
34f5674cbe
build(deps): bump react-i18next from 17.0.9 to 17.0.10 ( #9889 )
...
Bumps [react-i18next](https://github.com/i18next/react-i18next ) from
17.0.9 to 17.0.10.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md ">react-i18next's
changelog</a>.</em></p>
<blockquote>
<h2>17.0.10</h2>
<ul>
<li>fix(warnings): the <code>useTranslation</code> and
<code>Trans</code> "You will need to pass in an i18next
instance" warnings now match the <code>useSSR</code> wording,
mentioning the props/context alternatives and the most common
unexplained cause at scale: duplicate react-i18next copies in monorepo
setups. The <code>Trans</code> variant also referenced the internal
<code>i18nextReactModule</code> name; it now points to the public
<code>initReactI18next</code> API.</li>
<li>feat(warnings): development-only warning
(<code>SUSPENDED_WHILE_LOADING</code>, logged once) right before
<code>useTranslation</code> suspends while translations are loading.
With the default <code>useSuspense: true</code> and no
<code><Suspense></code> boundary this previously surfaced as a
blank screen or a cryptic React error; the warning now names both fixes
(add a <code><Suspense></code> boundary or set
<code>react.useSuspense: false</code>). No-op in production builds; the
<code>process.env.NODE_ENV</code> check is wrapped so runtimes without a
<code>process</code> global (raw ESM in the browser, some edge runtimes)
stay silent instead of throwing.</li>
<li>ci: weekly workflow typechecking the test suite against
<code>@types/react@next</code> / <code>@types/react-dom@next</code>, so
the next React major's type changes (like the React 18
<code>TFunctionResult</code>/children wave) surface before user
reports.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="3b71c2766c "><code>3b71c27</code></a>
17.0.10</li>
<li><a
href="57c3500e6a "><code>57c3500</code></a>
build</li>
<li><a
href="c62476f4d1 "><code>c62476f</code></a>
chore: sync package-lock with i18next ^26.2.0 devDependency bump</li>
<li><a
href="0126bd1cad "><code>0126bd1</code></a>
improve instance warnings (monorepo hint) + dev-only suspense warning +
weekl...</li>
<li>See full diff in <a
href="https://github.com/i18next/react-i18next/compare/v17.0.9...v17.0.10 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 12:04:36 -05:00
dependabot[bot]
dc7f09be0d
build(deps-dev): bump vitest from 4.1.8 to 4.1.10 ( #9886 )
...
Bumps
[vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest )
from 4.1.8 to 4.1.10.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vitest-dev/vitest/releases ">vitest's
releases</a>.</em></p>
<blockquote>
<h2>v4.1.10</h2>
<h3> 🐞 Bug Fixes</h3>
<ul>
<li><strong>browser</strong>: Check fs access in builtin commands
[backport to v4] - by <a
href="https://github.com/hi-ogawa "><code>@hi-ogawa</code></a>,
<strong>Hiroshi Ogawa</strong> and <strong>OpenCode
(claude-opus-4-8)</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10680 ">vitest-dev/vitest#10680</a>
<a href="https://github.com/vitest-dev/vitest/commit/5c18dd267 "><!-- raw
HTML omitted -->(5c18d)<!-- raw HTML omitted --></a></li>
<li><strong>vm</strong>: Fix external module resolve error with deps
optimizer query for encoded URI [backport to v4] - by <a
href="https://github.com/SveLil "><code>@SveLil</code></a> and <a
href="https://github.com/hi-ogawa "><code>@hi-ogawa</code></a> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10661 ">vitest-dev/vitest#10661</a>
<a href="https://github.com/vitest-dev/vitest/commit/bae52b511 "><!-- raw
HTML omitted -->(bae52)<!-- raw HTML omitted --></a></li>
</ul>
<h5> <a
href="https://github.com/vitest-dev/vitest/compare/v4.1.9...v4.1.10 ">View
changes on GitHub</a></h5>
<h2>v4.1.9</h2>
<h3>🐞 Bug Fixes</h3>
<ul>
<li>Fix <code>importOriginal</code> with optimizer and query import
[backport to v4] - by <strong>Hiroshi Ogawa</strong>, <strong>David
Harris</strong>, <strong>Codex</strong>and <strong>Vladimir</strong> in
<a
href="https://redirect.github.com/vitest-dev/vitest/issues/10546 ">vitest-dev/vitest#10546</a>
<a href="https://github.com/vitest-dev/vitest/commit/a5180190c "><!-- raw
HTML omitted -->(a5180)<!-- raw HTML omitted --></a></li>
<li><strong>browser</strong>:
<ul>
<li>Wait for orchestrator readiness before resolving browser sessions
[backport to v4] - by <strong>Vladimir</strong> and <strong>Séamus
O'Connor</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10555 ">vitest-dev/vitest#10555</a>
<a href="https://github.com/vitest-dev/vitest/commit/7fb29651a "><!-- raw
HTML omitted -->(7fb29)<!-- raw HTML omitted --></a></li>
<li>Wait for iframe tester readiness before preparing [backport to v4] -
by <strong>Vladimir</strong> and <strong>Séamus O'Connor</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10497 ">vitest-dev/vitest#10497</a>
and <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10556 ">vitest-dev/vitest#10556</a>
<a href="https://github.com/vitest-dev/vitest/commit/fbc626c40 "><!-- raw
HTML omitted -->(fbc62)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>mocker</strong>:
<ul>
<li>Hoist vi.mock() for vite-plus/test imports [backport to v4] - by
<strong>Hiroshi Ogawa</strong>, <strong>LongYinan</strong>,
<strong>Claude Opus 4.8</strong> and <strong>Vladimir</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10548 ">vitest-dev/vitest#10548</a>
<a href="https://github.com/vitest-dev/vitest/commit/2c9559c02 "><!-- raw
HTML omitted -->(2c955)<!-- raw HTML omitted --></a></li>
</ul>
</li>
<li><strong>pool</strong>:
<ul>
<li>Prevent test run hang on worker crash [backport to v4] - by
<strong>Ari Perkkiö</strong> and <strong>Jattioui Ismail</strong> in <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10543 ">vitest-dev/vitest#10543</a>
and <a
href="https://redirect.github.com/vitest-dev/vitest/issues/10564 ">vitest-dev/vitest#10564</a>
<a href="https://github.com/vitest-dev/vitest/commit/934b0f587 "><!-- raw
HTML omitted -->(934b0)<!-- raw HTML omitted --></a></li>
</ul>
</li>
</ul>
<h5><a
href="https://github.com/vitest-dev/vitest/compare/v4.1.8...v4.1.9 ">View
changes on GitHub</a></h5>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="db616d227b "><code>db616d2</code></a>
chore: release v4.1.10 (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/10718 ">#10718</a>)</li>
<li><a
href="bae52b5112 "><code>bae52b5</code></a>
fix(vm): fix external module resolve error with deps optimizer query for
enco...</li>
<li><a
href="a7a61e78c7 "><code>a7a61e7</code></a>
chore: release v4.1.9 (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/10598 ">#10598</a>)</li>
<li><a
href="934b0f587c "><code>934b0f5</code></a>
fix(pool): prevent test run hang on worker crash (<a
href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/10543 ">#10543</a>)
[backport to v4] (#...</li>
<li><a
href="7fb29651af "><code>7fb2965</code></a>
fix(browser): wait for orchestrator readiness before resolving browser
sessio...</li>
<li><a
href="a5180190c1 "><code>a518019</code></a>
fix: fix <code>importOriginal</code> with optimizer and query import
[backport to v4] (#...</li>
<li>See full diff in <a
href="https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/vitest ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 12:04:11 -05:00
dependabot[bot]
4d736b681d
build(deps): bump ws from 8.19.0 to 8.21.1 ( #9891 )
...
Bumps [ws](https://github.com/websockets/ws ) from 8.19.0 to 8.21.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/websockets/ws/releases ">ws's
releases</a>.</em></p>
<blockquote>
<h2>8.21.1</h2>
<h1>Bug fixes</h1>
<ul>
<li>Empty fragments are now counted toward the limit (a2f4e7c0).</li>
<li>The default values of the <code>maxBufferedChunks</code> and
<code>maxFragments</code> options have
been reduced (f197ac65).</li>
</ul>
<h2>8.21.0</h2>
<h1>Features</h1>
<ul>
<li>Introduced the <code>maxBufferedChunks</code> and
<code>maxFragments</code> options (2b2abd45).</li>
</ul>
<h1>Bug fixes</h1>
<ul>
<li>Fixed a remote memory exhaustion DoS vulnerability (2b2abd45).</li>
</ul>
<p>A high volume of tiny fragments and data chunks could be sent by a
peer, using
modest network traffic, to crash a <code>ws</code> server or client due
to OOM.</p>
<pre lang="js"><code>import { WebSocket, WebSocketServer } from 'ws';
<p>const wss = new WebSocketServer({ port: 0 }, function () {
const data = Buffer.alloc(1);
const options = { fin: false };
const { port } = wss.address();
const ws = new WebSocket(<code>ws://localhost:${port}</code>);</p>
<p>ws.on('open', function () {
(function send() {
ws.send(data, options, function (err) {
if (err) return;
send();
});
})();
});</p>
<p>ws.on('error', console.error);
ws.on('close', function (code, reason) {
console.log(<code>client close - code: ${code} reason:
${reason.toString()}</code>);
});
});</p>
<p>wss.on('connection', function (ws) {
ws.on('error', console.error);
ws.on('close', function (code, reason) {
console.log(<code>server close - code: ${code} reason:
${reason.toString()}</code>);
});
});
</code></pre></p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="ae1de54330 "><code>ae1de54</code></a>
[dist] 8.21.1</li>
<li><a
href="8e9511b86b "><code>8e9511b</code></a>
[ci] Trust Coveralls Homebrew tap</li>
<li><a
href="f197ac6514 "><code>f197ac6</code></a>
[fix] Lower default values of <code>maxBufferedChunks</code> and
<code>maxFragments</code></li>
<li><a
href="8df8265c2f "><code>8df8265</code></a>
[ci] Update actions/checkout action to v7</li>
<li><a
href="a2f4e7c046 "><code>a2f4e7c</code></a>
[fix] Count empty fragments toward the limit (<a
href="https://redirect.github.com/websockets/ws/issues/2329 ">#2329</a>)</li>
<li><a
href="e79f912cb3 "><code>e79f912</code></a>
[pkg] Approve install scripts for bufferutil and utf-8-validate</li>
<li><a
href="4ea355d6d3 "><code>4ea355d</code></a>
[doc] Document 32-bit signed integer coercion for option values</li>
<li><a
href="2120f4c8c6 "><code>2120f4c</code></a>
[example] Remove uuid dependency</li>
<li><a
href="4c534a6b8a "><code>4c534a6</code></a>
[security] Add latest vulnerability to SECURITY.md</li>
<li><a
href="bca91adf15 "><code>bca91ad</code></a>
[dist] 8.21.0</li>
<li>Additional commits viewable in <a
href="https://github.com/websockets/ws/compare/8.19.0...8.21.1 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 12:03:45 -05:00
dependabot[bot]
e171e6f9e6
build(deps): bump react-router-dom from 7.16.0 to 7.18.1 ( #9888 )
...
Bumps
[react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom )
from 7.16.0 to 7.18.1.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/remix-run/react-router/blob/react-router-dom@7.18.1/packages/react-router-dom/CHANGELOG.md ">react-router-dom's
changelog</a>.</em></p>
<blockquote>
<h2>v7.18.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>Fix incorrect <code>package.json</code> <code>main</code> field for
CommonJS builds (<a
href="https://redirect.github.com/remix-run/react-router/pull/15238 ">#15238</a>)</li>
<li>Updated dependencies:
<ul>
<li><a
href="https://github.com/remix-run/react-router/releases/tag/react-router@7.18.1 "><code>react-router@7.18.1</code></a></li>
</ul>
</li>
</ul>
<h2>v7.18.0</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies:
<ul>
<li><a
href="https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0 "><code>react-router@7.18.0</code></a></li>
</ul>
</li>
</ul>
<h2>v7.17.0</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies:
<ul>
<li><a
href="https://github.com/remix-run/react-router/releases/tag/react-router@7.17.0 "><code>react-router@7.17.0</code></a></li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="afdf85d3c1 "><code>afdf85d</code></a>
Release v7.18.1 (<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15253 ">#15253</a>)</li>
<li><a
href="2ecaa1ddbb "><code>2ecaa1d</code></a>
Fix react-router-dom main entry metadata (<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15238 ">#15238</a>)</li>
<li><a
href="6fb1e79f83 "><code>6fb1e79</code></a>
Release v7.18.0 (<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15187 ">#15187</a>)</li>
<li><a
href="195a0d03c1 "><code>195a0d0</code></a>
Release v7.17.0 (<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15145 ">#15145</a>)</li>
<li>See full diff in <a
href="https://github.com/remix-run/react-router/commits/react-router-dom@7.18.1/packages/react-router-dom ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 12:03:39 -05:00
dependabot[bot]
8cdb3552b4
build(deps): bump @lexical/link from 0.46.0 to 0.48.0 ( #9885 )
...
Bumps
[@lexical/link](https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link )
from 0.46.0 to 0.48.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/facebook/lexical/releases ">@lexical/link's
releases</a>.</em></p>
<blockquote>
<p>v0.48.0 is a maintenance release focused on bug fixes across
Markdown, tables, lists, links, and selection. It's headlined by a fix
for a v0.46.0 regression that broke native text drag-and-drop (<a
href="https://redirect.github.com/facebook/lexical/pull/8842 ">#8842</a>)
and a couple of notable security hardening fixes. It also adds a handful
of new features, including an <code>MdastHtmlExtension</code> with
examples for authoring custom Markdown constructs (collapsibles,
<code>kbd</code>, alerts, footnotes), a customizable Yjs shared-type
root name for collaborative editing, and new table row manipulation
helpers.</p>
<h2>New APIs & Features</h2>
<ul>
<li><a
href="https://lexical.dev/docs/api/modules/lexical_table "><code>@lexical/table</code></a>
— Added <code>$moveTableRow</code> for reordering table rows, plus the
previously missing <code>$unmergeCellNode</code> export (<a
href="https://redirect.github.com/facebook/lexical/pull/8833 ">#8833</a>)</li>
<li><a
href="https://lexical.dev/docs/api/modules/lexical_yjs "><code>@lexical/yjs</code></a>
/ <a
href="https://lexical.dev/docs/api/modules/lexical_react "><code>@lexical/react</code></a>
— The Yjs shared-type root name is now customizable, so Lexical can
share a Yjs document with other content that uses a different root key
(<a
href="https://redirect.github.com/facebook/lexical/pull/8841 ">#8841</a>)</li>
<li><a
href="https://lexical.dev/docs/api/modules/lexical_extension "><code>@lexical/extension</code></a>
/ <a
href="https://lexical.dev/docs/api/modules/lexical_mdast "><code>@lexical/mdast</code></a>
— Added <code>MdastHtmlExtension</code> and Markdown custom-construct
examples (collapsible sections, <code>kbd</code>, alerts, footnotes)
demonstrating how to extend the Markdown ↔ mdast pipeline. See the <a
href="https://lexical.dev/docs/serialization/markdown-mdast ">Markdown
& mdast serialization guide</a> (<a
href="https://redirect.github.com/facebook/lexical/pull/8826 ">#8826</a>)</li>
</ul>
<h2>Notable Fixes</h2>
<p><strong>Drag & drop (fix for v0.46.0 regression)</strong></p>
<ul>
<li>Don't cancel <code>dragover</code> for text drags, so native drops
work again (<a
href="https://redirect.github.com/facebook/lexical/pull/8842 ">#8842</a>)</li>
</ul>
<p><strong>Security</strong></p>
<ul>
<li><code>LinkNode.sanitizeUrl()</code> now fails closed on unparseable
URLs, preventing a potential XSS vector (<a
href="https://redirect.github.com/facebook/lexical/pull/8846 ">#8846</a>)</li>
<li>Fixed a <code>serialize-javascript</code> dependency vulnerability
(<a
href="https://redirect.github.com/facebook/lexical/pull/8803 ">#8803</a>)</li>
</ul>
<p><strong>Markdown & code</strong></p>
<ul>
<li>Roundtrip overlapping inline formats correctly through
mdast/Markdown (<a
href="https://redirect.github.com/facebook/lexical/pull/8825 ">#8825</a>)</li>
<li>Force re-tokenization after an async language load so highlighting
appears once the grammar is ready (<a
href="https://redirect.github.com/facebook/lexical/pull/8830 ">#8830</a>)</li>
</ul>
<p><strong>Tables</strong></p>
<ul>
<li>Auto-scroll while drag-selecting cells past the visible edge (<a
href="https://redirect.github.com/facebook/lexical/pull/8822 ">#8822</a>)</li>
<li>Enable table copy in read-only mode (<a
href="https://redirect.github.com/facebook/lexical/pull/8845 ">#8845</a>)</li>
</ul>
<p><strong>Lists & character limit</strong></p>
<ul>
<li>Backspace at the start of a list item now outdents or converts to a
paragraph (<a
href="https://redirect.github.com/facebook/lexical/pull/8829 ">#8829</a>)</li>
<li>Merge adjacent <code>OverflowNode</code>s in
<code>useCharacterLimit</code> (<a
href="https://redirect.github.com/facebook/lexical/pull/8831 ">#8831</a>)</li>
<li>Count block separators when wrapping character-limit overflow (<a
href="https://redirect.github.com/facebook/lexical/pull/8840 ">#8840</a>)</li>
</ul>
<p><strong>Links & selection</strong></p>
<ul>
<li>Disable link opening for disabled autolinks (<a
href="https://redirect.github.com/facebook/lexical/pull/8839 ">#8839</a>)</li>
<li>Skip <code>scrollIntoViewIfNeeded</code> when the selection rect is
above the editor, fixing a Safari RTL caret jump (<a
href="https://redirect.github.com/facebook/lexical/pull/8848 ">#8848</a>)</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>[lexical-mdast][lexical-markdown] Bug Fix: Roundtrip overlapping
inline formats by <a
href="https://github.com/etrepum "><code>@etrepum</code></a> in <a
href="https://redirect.github.com/facebook/lexical/pull/8825 ">facebook/lexical#8825</a></li>
<li>[lexical-table][lexical-playground] Bug Fix: Auto-scroll while
drag-selecting cells past the visible edge by <a
href="https://github.com/JohnJunior "><code>@JohnJunior</code></a> in <a
href="https://redirect.github.com/facebook/lexical/pull/8822 ">facebook/lexical#8822</a></li>
<li>[lexical-code-shiki] Bug Fix: force re-tokenize after async language
load by <a
href="https://github.com/ochevallier "><code>@ochevallier</code></a> in
<a
href="https://redirect.github.com/facebook/lexical/pull/8830 ">facebook/lexical#8830</a></li>
<li>[lexical-react] Bug Fix: Merge adjacent OverflowNodes in
useCharacterLimit by <a
href="https://github.com/mayrang "><code>@mayrang</code></a> in <a
href="https://redirect.github.com/facebook/lexical/pull/8831 ">facebook/lexical#8831</a></li>
<li>Open playground links in a new tab by <a
href="https://github.com/potatowagon "><code>@potatowagon</code></a> in
<a
href="https://redirect.github.com/facebook/lexical/pull/8837 ">facebook/lexical#8837</a></li>
<li>[lexical-rich-text][lexical-plain-text] Bug Fix: don't cancel
dragover for text drags so native drops work again by <a
href="https://github.com/etrepum "><code>@etrepum</code></a> in <a
href="https://redirect.github.com/facebook/lexical/pull/8842 ">facebook/lexical#8842</a></li>
<li>[lexical-link] Bug Fix: disable link opening for disabled autolink
in… by <a
href="https://github.com/ochevallier "><code>@ochevallier</code></a> in
<a
href="https://redirect.github.com/facebook/lexical/pull/8839 ">facebook/lexical#8839</a></li>
<li>[lexical-table] Feature: Add $moveTableRow function & Add
missing export for $unmergeCellNode by <a
href="https://github.com/hamo-o "><code>@hamo-o</code></a> in <a
href="https://redirect.github.com/facebook/lexical/pull/8833 ">facebook/lexical#8833</a></li>
<li>[lexical-list] Bug Fix: Backspace at start of list item outdents or
converts to paragraph by <a
href="https://github.com/mayrang "><code>@mayrang</code></a> in <a
href="https://redirect.github.com/facebook/lexical/pull/8829 ">facebook/lexical#8829</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/facebook/lexical/blob/main/CHANGELOG.md ">@lexical/link's
changelog</a>.</em></p>
<blockquote>
<h2>v0.48.0 (2026-07-16)</h2>
<ul>
<li>lexical-reactlexical-table Bug Fix Enable table copy in read-only
mode (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8845 ">#8845</a>)
mayrang</li>
<li>lexical-extensionlexical-mdastdev-mdast-editor-example Feature Add
MdastHtmlExtension and Markdown custom-construct examples (collapsible,
kbd, alerts, footnotes) (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8826 ">#8826</a>)
Bob Ippolito</li>
<li>Fix fail closed in LinkNode.sanitizeUrl() on unparseable URLs (XSS)
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8846 ">#8846</a>)
xiezhenjia-meta</li>
<li>lexical Chore Fix serialize-javascript package dependency
vulnerability (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8803 ">#8803</a>)
vijay ojha</li>
<li>lexical-react Bug Fix Count block separators in character limit
overflow wrapping (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8840 ">#8840</a>)
mayrang</li>
<li>lexical-yjslexical-react Feature Customizable Yjs shared-type root
name (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8841 ">#8841</a>)
mayrang</li>
<li>lexical-list Bug Fix Backspace at start of list item outdents or
converts to paragraph (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8829 ">#8829</a>)
mayrang</li>
<li>lexical-table Feature Add moveTableRow function Add missing export
for unmergeCellNode (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8833 ">#8833</a>)</li>
<li>lexical-link Bug Fix disable link opening for disabled autolink in
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8839 ">#8839</a>)
Olivier Chevallier</li>
<li>lexical-rich-textlexical-plain-text Bug Fix dont cancel dragover for
text drags so native drops work again (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8842 ">#8842</a>)
Bob Ippolito</li>
<li>Open playground links in a new tab (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8837 ">#8837</a>)
Sherry</li>
<li>lexical-react Bug Fix Merge adjacent OverflowNodes in
useCharacterLimit (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8831 ">#8831</a>)
mayrang</li>
<li>lexical-code-shiki Bug Fix force re-tokenize after async language
load (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8830 ">#8830</a>)
Olivier Chevallier</li>
<li>lexical-tablelexical-playground Bug Fix Auto-scroll while
drag-selecting cells past the visible edge (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8822 ">#8822</a>)
Oleksandr Trukhnii</li>
<li>lexical-mdastlexical-markdown Bug Fix Roundtrip overlapping inline
formats (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8825 ">#8825</a>)
Bob Ippolito</li>
<li>v0.47.0 (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8821 ">#8821</a>)
Bob Ippolito</li>
<li>v0.47.0 Lexical GitHub Actions Bot</li>
</ul>
<h2>v0.47.0 (2026-07-10)</h2>
<ul>
<li>lexicallexical-rich-text Bug Fix Fix formatText toggle direction and
add SETTEXTFORMATCOMMAND (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8807 ">#8807</a>)
mayrang</li>
<li>scripts Bug Fix Let npm prompt for OTP when publishing bootstrap
stubs (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8820 ">#8820</a>)
Bob Ippolito</li>
<li>lexical-playground Bug Fix Clear inline font-size when converting to
heading (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8800 ">#8800</a>)
mayrang</li>
<li>lexical-tablelexical-playground Feature setTableRowIsHeader and
setTableColumnIsHeader utilities (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8815 ">#8815</a>)
mayrang</li>
<li>lexical-website Documentation Update Rewrite testing guide (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8811 ">#8811</a>)
mayrang</li>
<li>lexical-mdastlexical-rich-text Feature lexicalmdast, a
micromarkmdast-based alternative to lexicalmarkdown (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8794 ">#8794</a>)
Bob Ippolito</li>
<li>Make dependency-check resilient to transient registry errors (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8818 ">#8818</a>)
Gerard Rovira</li>
<li>lexical Refactor Move event module globals into per-editor
InputState (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8809 ">#8809</a>)
mayrang</li>
<li>lexical Bug Fix getDocument() should fall back to the global
document when there is no active editor (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8813 ">#8813</a>)
Sherry</li>
<li>lexical-playground Bug Fix Keep cell background color modal open on
first click (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8806 ">#8806</a>)
sahir</li>
<li>lexical-playground Bug Fix Use consistent default maxWidth for
markdown-imported images (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8810 ">#8810</a>)
mayrang</li>
<li>lexical-devtoolslexical-playground Chore Update flow, hermes, and
babel packages to latest (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8795 ">#8795</a>)
Bob Ippolito</li>
<li>Add a 7-day pnpm minimumReleaseAge to match the Dependabot cooldown
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8808 ">#8808</a>)
Gerard Rovira</li>
<li>lexical Chore Fix tmp package dependency vulnerability (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8802 ">#8802</a>)
vijay ojha</li>
<li>lexical Chore Add missing Flow type declarations (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8799 ">#8799</a>)
mayrang</li>
<li>lexical-markdown Feature Add generateNodesFromMarkdownString (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8789 ">#8789</a>)
mayrang</li>
<li>lexicallexical-playground Chore Refactor IME composition test
infrastructure and add browser-level coverage (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8793 ">#8793</a>)
mayrang</li>
<li>lexical-playground Bug Fix Use viewBox dimensions for unsized
Excalidraw output (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8798 ">#8798</a>)
mayrang</li>
<li>lexical-table Bug Fix Export insertTableRowAtNode and
insertTableColumnAtNode (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8791 ">#8791</a>)</li>
<li>lexical-playgroundlexical-website Feature Add Vercel Analytics and
Speed Insights (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8796 ">#8796</a>)
Gerard Rovira</li>
<li>lexicallexical-eslint-plugin Feature Add getDocument() API and
Shadow DOM lint enforcement (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8788 ">#8788</a>)
mayrang</li>
<li>scripts Bug Fix strip misplaced pure annotations from prod builds
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8786 ">#8786</a>)
Bob Ippolito</li>
<li>lexical Bug Fix deleteCharacter overwrites X11 PRIMARY selection via
Selection.modify (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8774 ">#8774</a>)
Bob Ippolito</li>
<li>lexical-playground Bug Fix Support Unicode URLs in autolink matcher
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8787 ">#8787</a>)
mayrang</li>
<li>lexical-table Feature Spread pasted TSV text across table cells (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8780 ">#8780</a>)
mayrang</li>
<li>Breaking Changelexical Bug Fix Preserve DOM element when composing
on segmented TextNode middle (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8784 ">#8784</a>)
mayrang</li>
<li>Breaking Changelexical-reactlexical-devtools-core Chore Drop React
17 support, baseline is now React 18 (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8782 ">#8782</a>)
Bob Ippolito</li>
<li>lexical-playgroundlexical Feature Ruby annotation node with floating
editor (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8741 ">#8741</a>)
mayrang</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="284b7491d0 "><code>284b749</code></a>
v0.48.0</li>
<li><a
href="365516c5fc "><code>365516c</code></a>
Fix: fail closed in LinkNode.sanitizeUrl() on unparseable URLs (XSS) (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8846 ">#8846</a>)</li>
<li><a
href="71562324c7 "><code>7156232</code></a>
[lexical-link] Bug Fix: disable link opening for disabled autolink in…
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8839 ">#8839</a>)</li>
<li><a
href="e4b7cc3f42 "><code>e4b7cc3</code></a>
v0.47.0 (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8821 ">#8821</a>)</li>
<li><a
href="a7666ab11f "><code>a7666ab</code></a>
[*][lexical-devtools][lexical-playground] Chore: Update flow, hermes,
and bab...</li>
<li><a
href="e649ab28b7 "><code>e649ab2</code></a>
[lexical][lexical-eslint-plugin] Feature: Add $getDocument() API and
Shadow D...</li>
<li><a
href="7b76175cc9 "><code>7b76175</code></a>
[lexical-playground] Bug Fix: Support Unicode URLs in autolink matcher
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8787 ">#8787</a>)</li>
<li><a
href="62a4b30f38 "><code>62a4b30</code></a>
[lexical][*] Feature: registerEventListener / registerEventListeners DOM
help...</li>
<li><a
href="d04ea9e836 "><code>d04ea9e</code></a>
[lexical-a11y][lexical-react][lexical-playground][lexical-website]
Feature: @...</li>
<li><a
href="51d47b77e8 "><code>51d47b7</code></a>
[lexical] Bug Fix: Clean up trailing shadow root after select-all delete
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-link/issues/8751 ">#8751</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/facebook/lexical/commits/v0.48.0/packages/lexical-link ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 12:03:36 -05:00
dependabot[bot]
2683555d13
build(deps): bump @codemirror/language from 6.12.3 to 6.12.4 ( #9894 )
...
Bumps [@codemirror/language](https://github.com/codemirror/language )
from 6.12.3 to 6.12.4.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/codemirror/language/commits ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 12:03:27 -05:00
dependabot[bot]
db61cc97d3
build(deps-dev): bump tsx from 4.22.4 to 4.23.1 ( #9480 )
...
Bumps [tsx](https://github.com/privatenumber/tsx ) from 4.22.4 to 4.23.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/privatenumber/tsx/releases ">tsx's
releases</a>.</em></p>
<blockquote>
<h2>v4.23.1</h2>
<h2><a
href="https://github.com/privatenumber/tsx/compare/v4.23.0...v4.23.1 ">4.23.1</a>
(2026-07-13)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>support tsImport after global preload (<a
href="8d4ffc24f3 ">8d4ffc2</a>)</li>
<li><strong>watch:</strong> avoid clearing piped output (<a
href="95d0672e02 ">95d0672</a>)</li>
<li><strong>watch:</strong> treat script and dependency paths literally
(<a
href="79fddde523 ">79fddde</a>)</li>
</ul>
<h3>Performance Improvements</h3>
<ul>
<li>index transform cache lazily (<a
href="e818ad6081 ">e818ad6</a>)</li>
<li>load esbuild lazily in CLI (<a
href="d0679381b6 ">d067938</a>)</li>
<li>map Node TypeScript formats directly (<a
href="cdcc6232a3 ">cdcc623</a>)</li>
<li>use sync module hooks on Node v22.22.3+ (<a
href="f8992f1a50 ">f8992f1</a>)</li>
</ul>
<hr />
<p>This release is also available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/tsx/v/4.23.1 "><code>npm
package (@latest dist-tag)</code></a></li>
</ul>
<h2>v4.23.0</h2>
<h1><a
href="https://github.com/privatenumber/tsx/compare/v4.22.5...v4.23.0 ">4.23.0</a>
(2026-07-03)</h1>
<h3>Bug Fixes</h3>
<ul>
<li>avoid redundant filesystem probes during module resolution (<a
href="257bbbb7eb ">257bbbb</a>),
closes <a
href="https://redirect.github.com/privatenumber/tsx/issues/809 ">privatenumber/tsx#809</a></li>
</ul>
<h3>Features</h3>
<ul>
<li>add multi-scenario startup benchmark suite (<a
href="c178197b10 ">c178197</a>),
closes <a
href="https://redirect.github.com/privatenumber/tsx/issues/809 ">privatenumber/tsx#809</a>
<a
href="https://redirect.github.com/privatenumber/tsx/issues/809 ">#809</a>
<a href="https://github.com/hi/issues/signal ">hi#signal</a> <a
href="https://redirect.github.com/privatenumber/tsx/issues/145 ">privatenumber/tsx#145</a>
<a
href="https://redirect.github.com/privatenumber/tsx/issues/809 ">#809</a></li>
</ul>
<hr />
<p>This release is also available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/tsx/v/4.23.0 "><code>npm
package (@latest dist-tag)</code></a></li>
</ul>
<h2>v4.22.5</h2>
<h2><a
href="https://github.com/privatenumber/tsx/compare/v4.22.4...v4.22.5 ">4.22.5</a>
(2026-07-02)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>isolate hook state per async module.register() registration (<a
href="a305f365f0 ">a305f36</a>)</li>
</ul>
<hr />
<p>This release is also available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/tsx/v/4.22.5 "><code>npm
package (@latest dist-tag)</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="79fddde523 "><code>79fddde</code></a>
fix(watch): treat script and dependency paths literally</li>
<li><a
href="e818ad6081 "><code>e818ad6</code></a>
perf: index transform cache lazily</li>
<li><a
href="cdcc6232a3 "><code>cdcc623</code></a>
perf: map Node TypeScript formats directly</li>
<li><a
href="d0679381b6 "><code>d067938</code></a>
perf: load esbuild lazily in CLI</li>
<li><a
href="95d0672e02 "><code>95d0672</code></a>
fix(watch): avoid clearing piped output</li>
<li><a
href="6fd4607e8a "><code>6fd4607</code></a>
docs: add per-page metadata</li>
<li><a
href="f4176d8c63 "><code>f4176d8</code></a>
docs: generate sitemap</li>
<li><a
href="8d4ffc24f3 "><code>8d4ffc2</code></a>
fix: support tsImport after global preload</li>
<li><a
href="f0e89b244c "><code>f0e89b2</code></a>
docs: document Node's public type-stripping API vs internal loader
path</li>
<li><a
href="f8992f1a50 "><code>f8992f1</code></a>
perf: use sync module hooks on Node v22.22.3+</li>
<li>Additional commits viewable in <a
href="https://github.com/privatenumber/tsx/compare/v4.22.4...v4.23.1 ">compare
view</a></li>
</ul>
</details>
<br />
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-16 13:59:26 -05:00
dependabot[bot]
c4da1c925f
build(deps): bump @agentclientprotocol/claude-agent-acp from 0.52.0 to 0.59.0 ( #9484 )
...
Bumps
[@agentclientprotocol/claude-agent-acp](https://github.com/agentclientprotocol/claude-agent-acp )
from 0.52.0 to 0.59.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/agentclientprotocol/claude-agent-acp/releases ">@agentclientprotocol/claude-agent-acp's
releases</a>.</em></p>
<blockquote>
<h2>v0.59.0</h2>
<h2><a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.58.1...v0.59.0 ">0.59.0</a>
(2026-07-13)</h2>
<h3>Features</h3>
<ul>
<li><strong>deps-dev:</strong> bump nanoid from 3.3.15 to 3.3.16 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/875 ">#875</a>)
(<a
href="e67dacdcac ">e67dacd</a>)</li>
<li><strong>deps:</strong> bump
<code>@anthropic-ai/claude-agent-sdk</code> to 0.3.207 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/874 ">#874</a>)
(<a
href="c7f5b8fe76 ">c7f5b8f</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Add subagent parent tool use attribution (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/859 ">#859</a>)
(<a
href="9cd48c597a ">9cd48c5</a>)</li>
<li>forward result text when the turn emitted no assistant message (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/858 ">#858</a>)
(<a
href="61ae8609d4 ">61ae860</a>)</li>
<li>hold a turn open while its background subagents are still live (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/870 ">#870</a>)
(<a
href="7a70f82739 ">7a70f82</a>)</li>
<li>Refine tool calls from streamed input (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/867 ">#867</a>)
(<a
href="2c19974d5b ">2c19974</a>)</li>
<li>Seed context window from SDK usage report (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/868 ">#868</a>)
(<a
href="3ba2d367a2 ">3ba2d36</a>),
closes <a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/596 ">#596</a></li>
<li>Skip synthetic login messages on replay (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/869 ">#869</a>)
(<a
href="c7dff3cf7e ">c7dff3c</a>),
closes <a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/863 ">#863</a></li>
</ul>
<h2>v0.58.1</h2>
<h2><a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.58.0...v0.58.1 ">0.58.1</a>
(2026-07-09)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Use valid npm version for publish (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/855 ">#855</a>)
(<a
href="8b366d8e9a ">8b366d8</a>)</li>
</ul>
<h2>v0.58.0</h2>
<h2><a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.57.0...v0.58.0 ">0.58.0</a>
(2026-07-09)</h2>
<h3>Features</h3>
<ul>
<li><strong>deps:</strong> update to
<code>@anthropic-ai/claude-agent-sdk</code> 0.3.205 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/854 ">#854</a>)
(<a
href="f664ced76d ">f664ced</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Preserve live model on resumed sessions (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/848 ">#848</a>)
(<a
href="f3d8ae3eb3 ">f3d8ae3</a>),
closes <a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/845 ">#845</a></li>
<li>Report usage for cancelled active turns (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/846 ">#846</a>)
(<a
href="b03318f59c ">b03318f</a>),
closes <a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/844 ">#844</a></li>
<li>tolerate missing text in streamed thinking chunks (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/852 ">#852</a>)
(<a
href="e944ceddea ">e944ced</a>)</li>
<li>Use SDK guards for elicitation validation (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/850 ">#850</a>)
(<a
href="32b93501d7 ">32b9350</a>)</li>
</ul>
<h2>v0.57.0</h2>
<h2><a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.56.0...v0.57.0 ">0.57.0</a>
(2026-07-07)</h2>
<h3>Features</h3>
<ul>
<li>Update <code>@anthropic-ai/claude-agent-sdk</code> to 0.3.202 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/843 ">#843</a>)
(<a
href="1612c07895 ">1612c07</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/agentclientprotocol/claude-agent-acp/blob/main/CHANGELOG.md ">@agentclientprotocol/claude-agent-acp's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.58.1...v0.59.0 ">0.59.0</a>
(2026-07-13)</h2>
<h3>Features</h3>
<ul>
<li><strong>deps-dev:</strong> bump nanoid from 3.3.15 to 3.3.16 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/875 ">#875</a>)
(<a
href="e67dacdcac ">e67dacd</a>)</li>
<li><strong>deps:</strong> bump
<code>@anthropic-ai/claude-agent-sdk</code> to 0.3.207 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/874 ">#874</a>)
(<a
href="c7f5b8fe76 ">c7f5b8f</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Add subagent parent tool use attribution (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/859 ">#859</a>)
(<a
href="9cd48c597a ">9cd48c5</a>)</li>
<li>forward result text when the turn emitted no assistant message (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/858 ">#858</a>)
(<a
href="61ae8609d4 ">61ae860</a>)</li>
<li>hold a turn open while its background subagents are still live (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/870 ">#870</a>)
(<a
href="7a70f82739 ">7a70f82</a>)</li>
<li>Refine tool calls from streamed input (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/867 ">#867</a>)
(<a
href="2c19974d5b ">2c19974</a>)</li>
<li>Seed context window from SDK usage report (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/868 ">#868</a>)
(<a
href="3ba2d367a2 ">3ba2d36</a>),
closes <a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/596 ">#596</a></li>
<li>Skip synthetic login messages on replay (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/869 ">#869</a>)
(<a
href="c7dff3cf7e ">c7dff3c</a>),
closes <a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/863 ">#863</a></li>
</ul>
<h2><a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.58.0...v0.58.1 ">0.58.1</a>
(2026-07-09)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>Use valid npm version for publish (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/855 ">#855</a>)
(<a
href="8b366d8e9a ">8b366d8</a>)</li>
</ul>
<h2><a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.57.0...v0.58.0 ">0.58.0</a>
(2026-07-09)</h2>
<h3>Features</h3>
<ul>
<li><strong>deps:</strong> update to
<code>@anthropic-ai/claude-agent-sdk</code> 0.3.205 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/854 ">#854</a>)
(<a
href="f664ced76d ">f664ced</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Preserve live model on resumed sessions (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/848 ">#848</a>)
(<a
href="f3d8ae3eb3 ">f3d8ae3</a>),
closes <a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/845 ">#845</a></li>
<li>Report usage for cancelled active turns (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/846 ">#846</a>)
(<a
href="b03318f59c ">b03318f</a>),
closes <a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/844 ">#844</a></li>
<li>tolerate missing text in streamed thinking chunks (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/852 ">#852</a>)
(<a
href="e944ceddea ">e944ced</a>)</li>
<li>Use SDK guards for elicitation validation (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/850 ">#850</a>)
(<a
href="32b93501d7 ">32b9350</a>)</li>
</ul>
<h2><a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.56.0...v0.57.0 ">0.57.0</a>
(2026-07-07)</h2>
<h3>Features</h3>
<ul>
<li>Update <code>@anthropic-ai/claude-agent-sdk</code> to 0.3.202 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/843 ">#843</a>)
(<a
href="1612c07895 ">1612c07</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="30b7c06f76 "><code>30b7c06</code></a>
chore(main): release 0.59.0 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/860 ">#860</a>)</li>
<li><a
href="c7f5b8fe76 "><code>c7f5b8f</code></a>
feat(deps): bump <code>@anthropic-ai/claude-agent-sdk</code> to 0.3.207
(<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/874 ">#874</a>)</li>
<li><a
href="7a70f82739 "><code>7a70f82</code></a>
fix: hold a turn open while its background subagents are still live (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/870 ">#870</a>)</li>
<li><a
href="e67dacdcac "><code>e67dacd</code></a>
feat(deps-dev): bump nanoid from 3.3.15 to 3.3.16 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/875 ">#875</a>)</li>
<li><a
href="61ae8609d4 "><code>61ae860</code></a>
fix: forward result text when the turn emitted no assistant message (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/858 ">#858</a>)</li>
<li><a
href="2c19974d5b "><code>2c19974</code></a>
fix: Refine tool calls from streamed input (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/867 ">#867</a>)</li>
<li><a
href="c7dff3cf7e "><code>c7dff3c</code></a>
fix: Skip synthetic login messages on replay (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/869 ">#869</a>)</li>
<li><a
href="3ba2d367a2 "><code>3ba2d36</code></a>
fix: Seed context window from SDK usage report (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/868 ">#868</a>)</li>
<li><a
href="f4e750decf "><code>f4e750d</code></a>
feat(deps): bump the minor group with 11 updates (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/862 ">#862</a>)</li>
<li><a
href="9cd48c597a "><code>9cd48c5</code></a>
fix: Add subagent parent tool use attribution (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/859 ">#859</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.52.0...v0.59.0 ">compare
view</a></li>
</ul>
</details>
<br />
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-16 13:17:13 -05:00
github-actions[bot]
b0e9e3664f
chore(lockfile): refresh pnpm-lock.yaml ( #9305 )
...
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
2026-07-14 13:19:59 -05:00
dependabot[bot]
2617bee422
build(deps-dev): bump @storybook/addon-docs from 10.4.6 to 10.5.0 ( #9483 )
...
Bumps
[@storybook/addon-docs](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs )
from 10.4.6 to 10.5.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/releases ">@storybook/addon-docs's
releases</a>.</em></p>
<blockquote>
<h2>v10.5.0</h2>
<h2>10.5.0</h2>
<blockquote>
<p><em>Foundational changes for new AI workflows</em></p>
</blockquote>
<p>Storybook 10.5 contains hundreds of fixes and improvements:</p>
<ul>
<li>⚡ ️ Angular-vite framework: Modern, fast dev, docs, and test
(preview)</li>
<li>🌈 Vitest initialGlobals: Test across themes, viewports, locales</li>
<li>🤖 Agentic review: AI-curated visual changesets and search results
(experimental)</li>
<li>⚛️ React docgen service: Unified metadata across MCP, Docs, and
Controls (experimental)</li>
<li>🧑💻 Claude / Codex plugins: One-click ADE integration
(experimental)</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>A11y: Fix MDX heading anchors not keyboard accessible - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34368 ">#34368</a>,
thanks <a
href="https://github.com/TheSeydiCharyyev "><code>@TheSeydiCharyyev</code></a>!</li>
<li>A11y: Handle lang attribute throughout preview - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35321 ">#35321</a>,
thanks <a
href="https://github.com/Sidnioulz "><code>@Sidnioulz</code></a>!</li>
<li>A11y: Surface required args and keyboard-reachable Setup controls in
ArgsTable - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35306 ">#35306</a>,
thanks <a
href="https://github.com/Sidnioulz "><code>@Sidnioulz</code></a>!</li>
<li>Addon A11y: Preserve disabled a11y rules with runOnly - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34649 ">#34649</a>,
thanks <a
href="https://github.com/cyphercodes "><code>@cyphercodes</code></a>!</li>
<li>Addon Docs: DocsContent not filling available width when TOC is
enabled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35043 ">#35043</a>,
thanks <a
href="https://github.com/k-utsumi "><code>@k-utsumi</code></a>!</li>
<li>Addon Docs: Resolve CSF4 module exports without a default export -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/34834 ">#34834</a>,
thanks <a
href="https://github.com/TheSeydiCharyyev "><code>@TheSeydiCharyyev</code></a>!</li>
<li>Addon Docs: Resolve providerImportSource to a path instead of a
file:// URL - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34841 ">#34841</a>,
thanks <a
href="https://github.com/TheSeydiCharyyev "><code>@TheSeydiCharyyev</code></a>!</li>
<li>Addon Vitest: Add an initialGlobals option to pin a project's
globals - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35226 ">#35226</a>,
thanks <a
href="https://github.com/lifeiscontent "><code>@lifeiscontent</code></a>!</li>
<li>Addon Vitest: Avoid erroring out on benign Win process exits - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35287 ">#35287</a>,
thanks <a
href="https://github.com/Sidnioulz "><code>@Sidnioulz</code></a>!</li>
<li>Addon Vitest: Fix dynamic import failure with Vitest 3 - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34927 ">#34927</a>,
thanks <a
href="https://github.com/Sidnioulz "><code>@Sidnioulz</code></a>!</li>
<li>Addon Vitest: Subscribe for run completion before triggering it - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35291 ">#35291</a>,
thanks <a
href="https://github.com/tsushanth "><code>@tsushanth</code></a>!</li>
<li>Angular: Add versioned `@types/node` to packages installed during
`storybook init` - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34192 ">#34192</a>,
thanks <a
href="https://github.com/copilot-swe-agent "><code>@copilot-swe-agent</code></a>!</li>
<li>Angular: Fix custom paths for stats.json on angular - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34551 ">#34551</a>,
thanks <a
href="https://github.com/mrginglymus "><code>@mrginglymus</code></a>!</li>
<li>Angular: Fix zone.js drop in angular-to-angular-vite migration +
schema sync + transform widening - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35386 ">#35386</a>,
thanks <a
href="https://github.com/valentinpalkovic "><code>@valentinpalkovic</code></a>!</li>
<li>Angular: Install <code>@analogjs/vite-plugin-angular</code> in
angular-to-angular-vite automigration - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35432 ">#35432</a>,
thanks <a
href="https://github.com/valentinpalkovic "><code>@valentinpalkovic</code></a>!</li>
<li>Angular: Introduce <code>@storybook/angular-vite</code> package -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/34202 ">#34202</a>,
thanks <a
href="https://github.com/brandonroberts "><code>@brandonroberts</code></a>!</li>
<li>Angular: Support Angular 22 in Webpack framework - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35318 ">#35318</a>,
thanks <a
href="https://github.com/EtiennePasteur "><code>@EtiennePasteur</code></a>!</li>
<li>Angular: Use future-proof API for component reflection - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35228 ">#35228</a>,
thanks <a
href="https://github.com/Sidnioulz "><code>@Sidnioulz</code></a>!</li>
<li>Babel: Remove bugfixes from preset-env in v8 - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35266 ">#35266</a>,
thanks <a
href="https://github.com/Sidnioulz "><code>@Sidnioulz</code></a>!</li>
<li>Builder Vite: Fix empty external globals imports - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34348 ">#34348</a>,
thanks <a
href="https://github.com/raashish1601 "><code>@raashish1601</code></a>!</li>
<li>Builder Vite: Support configLoader via builder options - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34080 ">#34080</a>,
thanks <a
href="https://github.com/holvi-sebastian "><code>@holvi-sebastian</code></a>!</li>
<li>CLI: Add `storybook ai <!-- raw HTML omitted -->` MCP passthrough
behind `STORYBOOK_FEATURE_AI_CLI` - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35125 ">#35125</a>,
thanks <a
href="https://github.com/kasperpeulen "><code>@kasperpeulen</code></a>!</li>
<li>CLI: Add telemetry for the `storybook ai <!-- raw HTML omitted -->`
passthrough - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35138 ">#35138</a>,
thanks <a
href="https://github.com/kasperpeulen "><code>@kasperpeulen</code></a>!</li>
<li>CLI: Allow -p shorthand to --port for ai command - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35390 ">#35390</a>,
thanks <a
href="https://github.com/huang-julien "><code>@huang-julien</code></a>!</li>
<li>CLI: Bundle the `ai` command in core so it never downloads
`@storybook/cli` - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35147 ">#35147</a>,
thanks <a
href="https://github.com/kasperpeulen "><code>@kasperpeulen</code></a>!</li>
<li>CLI: Do not auto-open the browser in storybook dev under AI agents -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35412 ">#35412</a>,
thanks <a
href="https://github.com/kasperpeulen "><code>@kasperpeulen</code></a>!</li>
<li>CLI: Exit process after successful build - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34735 ">#34735</a>,
thanks <a
href="https://github.com/torleifhalseth "><code>@torleifhalseth</code></a>!</li>
<li>CLI: Fix angular-to-angular-vite migration failing to configure
addon-vitest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35404 ">#35404</a>,
thanks <a
href="https://github.com/valentinpalkovic "><code>@valentinpalkovic</code></a>!</li>
<li>CLI: Fix silent hang in deferred addon configuration during upgrade
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35423 ">#35423</a>,
thanks <a
href="https://github.com/valentinpalkovic "><code>@valentinpalkovic</code></a>!</li>
<li>CLI: Fix upgrade crash on Storybook latest version check - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35156 ">#35156</a>,
thanks <a
href="https://github.com/yatishgoel "><code>@yatishgoel</code></a>!</li>
<li>CLI: Handle nested array schema for AI help - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35424 ">#35424</a>,
thanks <a
href="https://github.com/huang-julien "><code>@huang-julien</code></a>!</li>
<li>CLI: Install MCP when upgrade is ran by agent - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35215 ">#35215</a>,
thanks <a
href="https://github.com/huang-julien "><code>@huang-julien</code></a>!</li>
<li>CLI: Load Storybook AI help from preset metadata - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35212 ">#35212</a>,
thanks <a
href="https://github.com/kasperpeulen "><code>@kasperpeulen</code></a>!</li>
<li>CLI: Match `storybook ai` instances by config dir as well as cwd -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35392 ">#35392</a>,
thanks <a
href="https://github.com/kasperpeulen "><code>@kasperpeulen</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md ">@storybook/addon-docs's
changelog</a>.</em></p>
<blockquote>
<h2>10.5.0</h2>
<blockquote>
<p><em>Foundational changes for new AI workflows</em></p>
</blockquote>
<p>Storybook 10.5 contains hundreds of fixes and improvements:</p>
<ul>
<li>⚡ ️ Angular-vite framework: Modern, fast dev, docs, and test
(preview)</li>
<li>🌈 Vitest initialGlobals: Test across themes, viewports, locales</li>
<li>🤖 Agentic review: AI-curated visual changesets and search results
(experimental)</li>
<li>⚛️ React docgen service: Unified metadata across MCP, Docs, and
Controls (experimental)</li>
<li>🧑💻 Claude / Codex plugins: One-click ADE integration
(experimental)</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>A11y: Fix MDX heading anchors not keyboard accessible - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34368 ">#34368</a>,
thanks <a
href="https://github.com/TheSeydiCharyyev "><code>@TheSeydiCharyyev</code></a>!</li>
<li>A11y: Handle lang attribute throughout preview - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35321 ">#35321</a>,
thanks <a
href="https://github.com/Sidnioulz "><code>@Sidnioulz</code></a>!</li>
<li>A11y: Surface required args and keyboard-reachable Setup controls in
ArgsTable - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35306 ">#35306</a>,
thanks <a
href="https://github.com/Sidnioulz "><code>@Sidnioulz</code></a>!</li>
<li>Addon A11y: Preserve disabled a11y rules with runOnly - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34649 ">#34649</a>,
thanks <a
href="https://github.com/cyphercodes "><code>@cyphercodes</code></a>!</li>
<li>Addon Docs: DocsContent not filling available width when TOC is
enabled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35043 ">#35043</a>,
thanks <a
href="https://github.com/k-utsumi "><code>@k-utsumi</code></a>!</li>
<li>Addon Docs: Resolve CSF4 module exports without a default export -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/34834 ">#34834</a>,
thanks <a
href="https://github.com/TheSeydiCharyyev "><code>@TheSeydiCharyyev</code></a>!</li>
<li>Addon Docs: Resolve providerImportSource to a path instead of a
file:// URL - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34841 ">#34841</a>,
thanks <a
href="https://github.com/TheSeydiCharyyev "><code>@TheSeydiCharyyev</code></a>!</li>
<li>Addon Vitest: Add an initialGlobals option to pin a project's
globals - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35226 ">#35226</a>,
thanks <a
href="https://github.com/lifeiscontent "><code>@lifeiscontent</code></a>!</li>
<li>Addon Vitest: Avoid erroring out on benign Win process exits - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35287 ">#35287</a>,
thanks <a
href="https://github.com/Sidnioulz "><code>@Sidnioulz</code></a>!</li>
<li>Addon Vitest: Fix dynamic import failure with Vitest 3 - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34927 ">#34927</a>,
thanks <a
href="https://github.com/Sidnioulz "><code>@Sidnioulz</code></a>!</li>
<li>Addon Vitest: Subscribe for run completion before triggering it - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35291 ">#35291</a>,
thanks <a
href="https://github.com/tsushanth "><code>@tsushanth</code></a>!</li>
<li>Angular: Add versioned <code>@types/node</code> to packages
installed during <code>storybook init</code> - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34192 ">#34192</a>,
thanks <a
href="https://github.com/copilot-swe-agent "><code>@copilot-swe-agent</code></a>!</li>
<li>Angular: Fix custom paths for stats.json on angular - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34551 ">#34551</a>,
thanks <a
href="https://github.com/mrginglymus "><code>@mrginglymus</code></a>!</li>
<li>Angular: Fix zone.js drop in angular-to-angular-vite migration +
schema sync + transform widening - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35386 ">#35386</a>,
thanks <a
href="https://github.com/valentinpalkovic "><code>@valentinpalkovic</code></a>!</li>
<li>Angular: Install <code>@analogjs/vite-plugin-angular</code> in
angular-to-angular-vite automigration - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35432 ">#35432</a>,
thanks <a
href="https://github.com/valentinpalkovic "><code>@valentinpalkovic</code></a>!</li>
<li>Angular: Introduce <code>@storybook/angular-vite</code> package -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/34202 ">#34202</a>,
thanks <a
href="https://github.com/brandonroberts "><code>@brandonroberts</code></a>!</li>
<li>Angular: Support Angular 22 in Webpack framework - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35318 ">#35318</a>,
thanks <a
href="https://github.com/EtiennePasteur "><code>@EtiennePasteur</code></a>!</li>
<li>Angular: Use future-proof API for component reflection - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35228 ">#35228</a>,
thanks <a
href="https://github.com/Sidnioulz "><code>@Sidnioulz</code></a>!</li>
<li>Babel: Remove bugfixes from preset-env in v8 - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35266 ">#35266</a>,
thanks <a
href="https://github.com/Sidnioulz "><code>@Sidnioulz</code></a>!</li>
<li>Builder Vite: Fix empty external globals imports - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34348 ">#34348</a>,
thanks <a
href="https://github.com/raashish1601 "><code>@raashish1601</code></a>!</li>
<li>Builder Vite: Support configLoader via builder options - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34080 ">#34080</a>,
thanks <a
href="https://github.com/holvi-sebastian "><code>@holvi-sebastian</code></a>!</li>
<li>CLI: Add <code>storybook ai <tool></code> MCP passthrough
behind <code>STORYBOOK_FEATURE_AI_CLI</code> - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35125 ">#35125</a>,
thanks <a
href="https://github.com/kasperpeulen "><code>@kasperpeulen</code></a>!</li>
<li>CLI: Add telemetry for the <code>storybook ai <command></code>
passthrough - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35138 ">#35138</a>,
thanks <a
href="https://github.com/kasperpeulen "><code>@kasperpeulen</code></a>!</li>
<li>CLI: Allow -p shorthand to --port for ai command - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35390 ">#35390</a>,
thanks <a
href="https://github.com/huang-julien "><code>@huang-julien</code></a>!</li>
<li>CLI: Bundle the <code>ai</code> command in core so it never
downloads <code>@storybook/cli</code> - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35147 ">#35147</a>,
thanks <a
href="https://github.com/kasperpeulen "><code>@kasperpeulen</code></a>!</li>
<li>CLI: Do not auto-open the browser in storybook dev under AI agents -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35412 ">#35412</a>,
thanks <a
href="https://github.com/kasperpeulen "><code>@kasperpeulen</code></a>!</li>
<li>CLI: Exit process after successful build - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34735 ">#34735</a>,
thanks <a
href="https://github.com/torleifhalseth "><code>@torleifhalseth</code></a>!</li>
<li>CLI: Fix angular-to-angular-vite migration failing to configure
addon-vitest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35404 ">#35404</a>,
thanks <a
href="https://github.com/valentinpalkovic "><code>@valentinpalkovic</code></a>!</li>
<li>CLI: Fix silent hang in deferred addon configuration during upgrade
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35423 ">#35423</a>,
thanks <a
href="https://github.com/valentinpalkovic "><code>@valentinpalkovic</code></a>!</li>
<li>CLI: Fix upgrade crash on Storybook latest version check - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35156 ">#35156</a>,
thanks <a
href="https://github.com/yatishgoel "><code>@yatishgoel</code></a>!</li>
<li>CLI: Handle nested array schema for AI help - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35424 ">#35424</a>,
thanks <a
href="https://github.com/huang-julien "><code>@huang-julien</code></a>!</li>
<li>CLI: Install MCP when upgrade is ran by agent - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35215 ">#35215</a>,
thanks <a
href="https://github.com/huang-julien "><code>@huang-julien</code></a>!</li>
<li>CLI: Load Storybook AI help from preset metadata - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35212 ">#35212</a>,
thanks <a
href="https://github.com/kasperpeulen "><code>@kasperpeulen</code></a>!</li>
<li>CLI: Match <code>storybook ai</code> instances by config dir as well
as cwd - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35392 ">#35392</a>,
thanks <a
href="https://github.com/kasperpeulen "><code>@kasperpeulen</code></a>!</li>
<li>CLI: Prefer agent-matched Storybook instances - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35235 ">#35235</a>,
thanks <a
href="https://github.com/kasperpeulen "><code>@kasperpeulen</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="9dafcd22ed "><code>9dafcd2</code></a>
Bump version from "10.5.0-beta.2" to "10.5.0" [skip
ci]</li>
<li><a
href="448db85e65 "><code>448db85</code></a>
Bump version from "10.5.0-beta.1" to "10.5.0-beta.2"
[skip ci]</li>
<li><a
href="a4ce9790a7 "><code>a4ce979</code></a>
Bump version from "10.5.0-beta.0" to "10.5.0-beta.1"
[skip ci]</li>
<li><a
href="f0bf138a0a "><code>f0bf138</code></a>
Bump version from "10.5.0-alpha.11" to
"10.5.0-beta.0" [skip ci]</li>
<li><a
href="fac05a5741 "><code>fac05a5</code></a>
Bump version from "10.5.0-alpha.10" to
"10.5.0-alpha.11" [skip ci]</li>
<li><a
href="4057c4169f "><code>4057c41</code></a>
Bump version from "10.5.0-alpha.9" to
"10.5.0-alpha.10" [skip ci]</li>
<li><a
href="91b9c34e58 "><code>91b9c34</code></a>
Merge pull request <a
href="https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs/issues/35321 ">#35321</a>
from storybookjs/sidnioulz/fix-html-lang-refreshed</li>
<li><a
href="383d5905db "><code>383d590</code></a>
Merge branch 'next' into sidnioulz/fix-html-lang-refreshed</li>
<li><a
href="520c70129d "><code>520c701</code></a>
UI: Add docs.lang and htmlLang parameters</li>
<li><a
href="d71aa77e16 "><code>d71aa77</code></a>
Merge origin/next into docgen/worker-threading</li>
<li>Additional commits viewable in <a
href="https://github.com/storybookjs/storybook/commits/v10.5.0/code/addons/docs ">compare
view</a></li>
</ul>
</details>
<br />
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-14 10:08:29 -07:00
dependabot[bot]
d7961919f5
build(deps): bump react-i18next from 17.0.8 to 17.0.9 ( #9481 )
...
Bumps [react-i18next](https://github.com/i18next/react-i18next ) from
17.0.8 to 17.0.9.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md ">react-i18next's
changelog</a>.</em></p>
<blockquote>
<h2>17.0.9</h2>
<ul>
<li>fix: allow TypeScript 7 in the optional <code>typescript</code> peer
dependency range (<code>^5 || ^6 || ^7</code>). With
<code>typescript@7.0.2</code> in a project, <code>npm install</code>
failed with an <code>ERESOLVE</code> peer conflict. Fixes <a
href="https://redirect.github.com/i18next/react-i18next/issues/1927 ">#1927</a>,
thanks <a
href="https://github.com/andikapradanaarif "><code>@andikapradanaarif</code></a>.</li>
<li>fix(types): <code><Trans t={t} ns="ns" …></code>
with a <code>t</code> from <code>useTranslation(['ns'])</code> now
typechecks under TypeScript 7. TS7 intersects the <code>Ns</code>
inference candidates coming from the <code>t</code> prop (<code>readonly
['ns']</code>) and the <code>ns</code> prop (<code>'ns'</code>) into an
unsatisfiable <code>'ns' & readonly ['ns']</code>, where TS6
resolved them. The <code>ns</code> prop on <code>TransProps</code>,
<code>TransSelectorProps</code> and
<code>IcuTransWithoutContextProps</code> now also accepts a single
namespace out of an array-typed <code>Ns</code> (<code>Ns | (Ns extends
readonly (infer S extends string)[] ? S : never)</code>) — which matches
runtime behavior and is unchanged under TS5/TS6.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="8b4a9ea139 "><code>8b4a9ea</code></a>
17.0.9</li>
<li><a
href="422bab13d4 "><code>422bab1</code></a>
fix: support typescript 7 — widen peer range and fix Trans ns inference
under...</li>
<li><a
href="6e18aa95b5 "><code>6e18aa9</code></a>
README: mention npx i18next-cli localize as the zero-to-localized
path</li>
<li>See full diff in <a
href="https://github.com/i18next/react-i18next/compare/v17.0.8...v17.0.9 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-14 10:06:00 -07:00
dependabot[bot]
072f1e9b8e
build(deps): bump dompurify from 3.4.8 to 3.4.12 ( #9478 )
...
[//]: # (dependabot-start)
⚠️ **Dependabot is rebasing this PR** ⚠️
Rebasing might not happen immediately, so don't worry if this takes some
time.
Note: if you make any changes to this PR yourself, they will take
precedence over the rebase.
---
[//]: # (dependabot-end)
Bumps [dompurify](https://github.com/cure53/DOMPurify ) from 3.4.8 to
3.4.12.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/cure53/DOMPurify/releases ">dompurify's
releases</a>.</em></p>
<blockquote>
<h2>DOMPurify 3.4.12</h2>
<ul>
<li>Fixed an issue where a hook would not get called for custom
elements, thanks <a
href="https://github.com/Rikuxx0 "><code>@Rikuxx0</code></a></li>
<li>Hardened the handling of hooks removing elements, <a
href="https://github.com/mkrause-bee360 "><code>@mkrause-bee360</code></a></li>
<li>Added support for a few new SVG attributes, thanks <a
href="https://github.com/cbn-falias "><code>@cbn-falias</code></a> &
<a
href="https://github.com/Develop-KIM "><code>@Develop-KIM</code></a></li>
<li>Hardened the handling of declarative partial updates</li>
<li>Updated the documentation is several spots, README, wiki, etc.</li>
<li>Bumped several dependencies where possible</li>
</ul>
<h2>DOMPurify 3.4.11</h2>
<ul>
<li>Fixed an issue with a leaky config for hooks via
<code>setConfig</code>, thanks <a
href="https://github.com/trace37labs "><code>@trace37labs</code></a></li>
<li>Bumped vulnerable development dependencies to arrive at plain 0 with
<code>npm audit</code></li>
<li>Updated the <code>osv-scanner</code> suppression list as no
vulnerable dependencies are left for now</li>
<li>Updated up the linting tool-chain and removed now-redundant lint
directives</li>
<li>Updated the documentation is several spots, README, wiki, etc.</li>
<li>Bumped several dependencies where possible</li>
</ul>
<h2>DOMPurify 3.4.10</h2>
<ul>
<li>Refactored codebase for clarity: extracted the public type
declarations into <code>types.ts</code></li>
<li>Decomposed the three largest sanitizer functions into focused
helpers</li>
<li>Removed duplicated defaults and dead branches, consolidated
<code>SAFE_FOR_TEMPLATES</code> scrubbing into single shared path</li>
<li>Improved per-node performance by hoisting the mXSS probe regexes and
testing <code>textContent</code> before <code>innerHTML</code></li>
<li>Added a deterministic micro-benchmark harness (<code>npm run
bench</code>) with a <code>--compare</code> mode</li>
<li>Reduced CI cost by running the full three-engine browser suite once
per PR</li>
<li>Refreshed the <code>demos/</code> folder so every demo runs again,
and added a SVG-via-<code><img></code> demo</li>
<li>Documented the bench and <code>test:happydom</code> scripts in the
README</li>
<li>Completed the Attack Classes & Bypass History wiki page</li>
<li>Bumped several dependencies where possible</li>
</ul>
<h2>DOMPurify 3.4.9</h2>
<ul>
<li>Further improved the handling of Trusted Types config options,
thanks <a
href="https://github.com/offset "><code>@offset</code></a></li>
<li>Further improved the handling of <code>IN_PLACE</code> sanitization,
thanks <a
href="https://github.com/mozfreddyb "><code>@mozfreddyb</code></a></li>
<li>Added more test coverage for <code>IN_PLACE</code> and Trusted Types
related usage</li>
<li>Bumped several dependencies where possible</li>
<li>Updated README and wiki with more accurate documentation &
attack samples</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="a9ca1e5374 "><code>a9ca1e5</code></a>
release: 3.4.12 (<a
href="https://redirect.github.com/cure53/DOMPurify/issues/1537 ">#1537</a>)</li>
<li><a
href="0cae518740 "><code>0cae518</code></a>
release: 3.4.11 (<a
href="https://redirect.github.com/cure53/DOMPurify/issues/1494 ">#1494</a>)</li>
<li><a
href="6ee5716f83 "><code>6ee5716</code></a>
release: 3.4.10 (<a
href="https://redirect.github.com/cure53/DOMPurify/issues/1478 ">#1478</a>)</li>
<li><a
href="52102472d4 "><code>5210247</code></a>
release: 3.4.9 (<a
href="https://redirect.github.com/cure53/DOMPurify/issues/1459 ">#1459</a>)</li>
<li>See full diff in <a
href="https://github.com/cure53/DOMPurify/compare/3.4.8...3.4.12 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-14 10:03:46 -07:00
dependabot[bot]
ff09d8c1d8
build(deps): bump lexical from 0.46.0 to 0.47.0 ( #9486 )
...
Bumps
[lexical](https://github.com/facebook/lexical/tree/HEAD/packages/lexical )
from 0.46.0 to 0.47.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/facebook/lexical/releases ">lexical's
releases</a>.</em></p>
<blockquote>
<p>v0.47.0 is a monthly release with a lot of bug fixes, particularly
related to IME and composition, and is headlined by two new experimental
packages:</p>
<ul>
<li><a
href="https://lexical.dev/docs/api/modules/lexical_mdast "><code>@lexical/mdast</code></a>
(<a
href="https://redirect.github.com/facebook/lexical/pull/8794 ">#8794</a>)
— a <a href="https://github.com/micromark/micromark ">micromark</a>/<a
href="https://github.com/syntax-tree/mdast ">mdast</a>-based alternative
to <code>@lexical/markdown</code>. Parsing, serialization, and markdown
shortcuts all go through the same parser used by <code>remark</code>, so
CommonMark + GFM compliance comes for free and there is no second
grammar to keep in sync. The original syntax of each construct is
preserved on the nodes, so re-serializing produces minimally different
Markdown. <code>@lexical/markdown</code> remains the supported default
for production apps. See the new <a
href="https://lexical.dev/docs/serialization/markdown-mdast ">Markdown
with <code>@lexical/mdast</code> guide</a>.</li>
<li><a
href="https://lexical.dev/docs/api/modules/lexical_a11y "><code>@lexical/a11y</code></a>
(<a
href="https://redirect.github.com/facebook/lexical/pull/8591 ">#8591</a>)
— framework-agnostic accessibility helpers (ARIA live regions, focus
management, roving tab index, focus trap) usable from React, Svelte,
Vue, Solid, or vanilla DOM, with React wrappers shipping from
<code>@lexical/react</code>. The playground adopts them as part of a
WCAG AA reference pass, and the keyboard contracts Lexical follows are
documented in the new <a
href="https://lexical.dev/docs/concepts/keyboard-accessibility ">Keyboard
Accessibility guide</a>.</li>
</ul>
<p>Beyond the headliners: React 18 is now the baseline (see Breaking
Changes), the playground gains Find and Replace and a Ruby annotation
node with a floating editor, tables learn to spread pasted TSV across
cells and get row/column header utilities, and there is a long list of
IME/composition, selection, and navigation fixes.</p>
<p>Special recognition once again goes to <a
href="https://github.com/mayrang "><code>@mayrang</code></a> who has
been plowing through IME, accessibility, and other input related issues
as well as the really cool new Find and Replace and Ruby Annotations
playground features.</p>
<h2>Breaking Changes</h2>
<h3><code>@lexical/react</code> / <code>@lexical/devtools-core</code> —
React 17 support dropped (<a
href="https://redirect.github.com/facebook/lexical/pull/8782 ">#8782</a>)</h3>
<p>React 18 is now the minimum supported version; the <code>react</code>
/ <code>react-dom</code> peerDependencies require <code>>=18</code>,
and React 17 compatibility code paths were removed. If you are already
on React 18 or 19, no changes are required.</p>
<h3><code>lexical</code> — DOM element preserved when composing on a
segmented TextNode (<a
href="https://redirect.github.com/facebook/lexical/pull/8784 ">#8784</a>)</h3>
<p>Starting IME composition in the middle of a segmented
<code>TextNode</code> (e.g. a mention) previously replaced the node —
destroying its DOM element and breaking the browser's composition
tracking (caret flashing and styling bleed on Chrome). The node now
temporarily switches to <code>normal</code> mode for the duration of
composition, keeping the same node key and DOM element, and is cleaned
up when composition ends. Subclass transforms or method overrides that
assume a segmented node is always in segmented mode must account for
this transient state — see the updated <a
href="https://lexical.dev/docs/api/classes/lexical.TextNode#setmode "><code>TextNode.setMode()</code>
documentation</a>.</p>
<h2>New APIs</h2>
<ul>
<li><a
href="https://lexical.dev/docs/api/modules/lexical "><code>lexical</code></a>
— <code>$getDocument()</code> returns the owner document of the active
editor (correct inside a <a
href="https://lexical.dev/docs/concepts/shadow-dom ">Shadow DOM or
iframe</a>), falling back to the global document when there is no active
editor; a new <code>@lexical/eslint-plugin</code> rule enforces its use
over the <code>document</code> global (<a
href="https://redirect.github.com/facebook/lexical/pull/8788 ">#8788</a>,
<a
href="https://redirect.github.com/facebook/lexical/pull/8813 ">#8813</a>)</li>
<li><a
href="https://lexical.dev/docs/api/modules/lexical "><code>lexical</code></a>
— <code>registerEventListener</code> /
<code>registerEventListeners</code>, type-safe
<code>addEventListener</code> helpers that return cleanup functions, now
used throughout the codebase — see the updated <a
href="https://lexical.dev/docs/concepts/dom-events ">Working with DOM
Events guide</a> (<a
href="https://redirect.github.com/facebook/lexical/pull/8767 ">#8767</a>)</li>
<li><a
href="https://lexical.dev/docs/api/modules/lexical "><code>lexical</code></a>
— <code>SET_TEXT_FORMAT_COMMAND</code> sets (rather than toggles) the
selection's text format (see <a
href="https://lexical.dev/docs/concepts/commands ">Commands</a>); the
same PR fixes <code>formatText</code> toggle direction (<a
href="https://redirect.github.com/facebook/lexical/pull/8807 ">#8807</a>)</li>
<li><a
href="https://lexical.dev/docs/api/modules/lexical_markdown "><code>@lexical/markdown</code></a>
— <code>$generateNodesFromMarkdownString</code> parses a markdown string
into Lexical nodes without inserting them into the document or modifying
the selection (<a
href="https://redirect.github.com/facebook/lexical/pull/8789 ">#8789</a>)</li>
<li><a
href="https://lexical.dev/docs/api/modules/lexical_table "><code>@lexical/table</code></a>
— <code>$setTableRowIsHeader</code> and
<code>$setTableColumnIsHeader</code> utilities (<a
href="https://redirect.github.com/facebook/lexical/pull/8815 ">#8815</a>);
<code>$insertTableRowAtNode</code> and
<code>$insertTableColumnAtNode</code> are now exported (<a
href="https://redirect.github.com/facebook/lexical/pull/8791 ">#8791</a>)</li>
</ul>
<h2>Notable Fixes</h2>
<p><strong>IME, composition & mobile</strong></p>
<ul>
<li>Prevent text duplication on iOS Safari when formatting during
composition (<a
href="https://redirect.github.com/facebook/lexical/pull/8755 ">#8755</a>)</li>
<li>Skip ZWSP insertion for format mismatch on Android Chrome (<a
href="https://redirect.github.com/facebook/lexical/pull/8769 ">#8769</a>);
deduplicate speech-to-text insertion on Android Chrome (<a
href="https://redirect.github.com/facebook/lexical/pull/8759 ">#8759</a>)</li>
<li>Event module globals moved into per-editor <code>InputState</code>
(<a
href="https://redirect.github.com/facebook/lexical/pull/8809 ">#8809</a>);
refactored IME composition test infrastructure with browser-level
coverage (<a
href="https://redirect.github.com/facebook/lexical/pull/8793 ">#8793</a>)</li>
</ul>
<p><strong>Selection & navigation</strong></p>
<ul>
<li>ArrowUp/Down no longer skip block decorators (<a
href="https://redirect.github.com/facebook/lexical/pull/8775 ">#8775</a>);
<code>deleteLine</code> no longer removes adjacent block decorators (<a
href="https://redirect.github.com/facebook/lexical/pull/8744 ">#8744</a>)</li>
<li>Keep selection inside single-child inline elements (<a
href="https://redirect.github.com/facebook/lexical/pull/8772 ">#8772</a>);
fix navigation across unmergeable TextNode boundaries in inline-grid
containers (<a
href="https://redirect.github.com/facebook/lexical/pull/8797 ">#8797</a>)</li>
<li><code>$setBlocksType</code> properly handles block-end focus in
backward selections (<a
href="https://redirect.github.com/facebook/lexical/pull/8753 ">#8753</a>);
<code>insertNodes</code> re-resolves a detached firstBlock (<a
href="https://redirect.github.com/facebook/lexical/pull/8764 ">#8764</a>)</li>
<li>Place the block cursor between decorators and shadow roots (<a
href="https://redirect.github.com/facebook/lexical/pull/8758 ">#8758</a>);
clean up the trailing shadow root after select-all delete (<a
href="https://redirect.github.com/facebook/lexical/pull/8751 ">#8751</a>)</li>
<li><code>deleteCharacter</code> no longer overwrites the X11 PRIMARY
selection via <code>Selection.modify</code> (<a
href="https://redirect.github.com/facebook/lexical/pull/8774 ">#8774</a>)</li>
<li>Defer <code>onUpdate</code> callbacks during nested commits (<a
href="https://redirect.github.com/facebook/lexical/pull/8672 ">#8672</a>)</li>
</ul>
<p><strong>Markdown, code & tables</strong></p>
<ul>
<li>Fence-like lines inside a code block stay content (<a
href="https://redirect.github.com/facebook/lexical/pull/8734 ">#8734</a>);
prevent formatting on <code>TabNode</code> inside code blocks (<a
href="https://redirect.github.com/facebook/lexical/pull/8752 ">#8752</a>)</li>
<li>Pasted TSV text spreads across table cells (<a
href="https://redirect.github.com/facebook/lexical/pull/8780 ">#8780</a>)</li>
</ul>
<p><strong>Playground & website</strong></p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/facebook/lexical/blob/main/CHANGELOG.md ">lexical's
changelog</a>.</em></p>
<blockquote>
<h2>v0.47.0 (2026-07-10)</h2>
<ul>
<li>lexicallexical-rich-text Bug Fix Fix formatText toggle direction and
add SETTEXTFORMATCOMMAND (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8807 ">#8807</a>)
mayrang</li>
<li>scripts Bug Fix Let npm prompt for OTP when publishing bootstrap
stubs (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8820 ">#8820</a>)
Bob Ippolito</li>
<li>lexical-playground Bug Fix Clear inline font-size when converting to
heading (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8800 ">#8800</a>)
mayrang</li>
<li>lexical-tablelexical-playground Feature setTableRowIsHeader and
setTableColumnIsHeader utilities (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8815 ">#8815</a>)
mayrang</li>
<li>lexical-website Documentation Update Rewrite testing guide (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8811 ">#8811</a>)
mayrang</li>
<li>lexical-mdastlexical-rich-text Feature lexicalmdast, a
micromarkmdast-based alternative to lexicalmarkdown (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8794 ">#8794</a>)
Bob Ippolito</li>
<li>Make dependency-check resilient to transient registry errors (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8818 ">#8818</a>)
Gerard Rovira</li>
<li>lexical Refactor Move event module globals into per-editor
InputState (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8809 ">#8809</a>)
mayrang</li>
<li>lexical Bug Fix getDocument() should fall back to the global
document when there is no active editor (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8813 ">#8813</a>)
Sherry</li>
<li>lexical-playground Bug Fix Keep cell background color modal open on
first click (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8806 ">#8806</a>)
sahir</li>
<li>lexical-playground Bug Fix Use consistent default maxWidth for
markdown-imported images (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8810 ">#8810</a>)
mayrang</li>
<li>lexical-devtoolslexical-playground Chore Update flow, hermes, and
babel packages to latest (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8795 ">#8795</a>)
Bob Ippolito</li>
<li>Add a 7-day pnpm minimumReleaseAge to match the Dependabot cooldown
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8808 ">#8808</a>)
Gerard Rovira</li>
<li>lexical Chore Fix tmp package dependency vulnerability (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8802 ">#8802</a>)
vijay ojha</li>
<li>lexical Chore Add missing Flow type declarations (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8799 ">#8799</a>)
mayrang</li>
<li>lexical-markdown Feature Add generateNodesFromMarkdownString (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8789 ">#8789</a>)
mayrang</li>
<li>lexicallexical-playground Chore Refactor IME composition test
infrastructure and add browser-level coverage (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8793 ">#8793</a>)
mayrang</li>
<li>lexical-playground Bug Fix Use viewBox dimensions for unsized
Excalidraw output (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8798 ">#8798</a>)
mayrang</li>
<li>lexical-table Bug Fix Export insertTableRowAtNode and
insertTableColumnAtNode (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8791 ">#8791</a>)</li>
<li>lexical-playgroundlexical-website Feature Add Vercel Analytics and
Speed Insights (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8796 ">#8796</a>)
Gerard Rovira</li>
<li>lexicallexical-eslint-plugin Feature Add getDocument() API and
Shadow DOM lint enforcement (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8788 ">#8788</a>)
mayrang</li>
<li>scripts Bug Fix strip misplaced pure annotations from prod builds
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8786 ">#8786</a>)
Bob Ippolito</li>
<li>lexical Bug Fix deleteCharacter overwrites X11 PRIMARY selection via
Selection.modify (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8774 ">#8774</a>)
Bob Ippolito</li>
<li>lexical-playground Bug Fix Support Unicode URLs in autolink matcher
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8787 ">#8787</a>)
mayrang</li>
<li>lexical-table Feature Spread pasted TSV text across table cells (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8780 ">#8780</a>)
mayrang</li>
<li>Breaking Changelexical Bug Fix Preserve DOM element when composing
on segmented TextNode middle (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8784 ">#8784</a>)
mayrang</li>
<li>Breaking Changelexical-reactlexical-devtools-core Chore Drop React
17 support, baseline is now React 18 (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8782 ">#8782</a>)
Bob Ippolito</li>
<li>lexical-playgroundlexical Feature Ruby annotation node with floating
editor (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8741 ">#8741</a>)
mayrang</li>
<li>lexical-playground Feature Find and Replace (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8779 ">#8779</a>)
mayrang</li>
<li>lexical-playground Bug Fix restore RTL checkbox position in
checklist (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8783 ">#8783</a>)
Aldo Ryanda</li>
<li>lexical-rich-text Bug Fix Stop ArrowUpDown from skipping block
decorators (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8775 ">#8775</a>)
mayrang</li>
<li>lexical-playground Bug Fix Convert remaining icon glyphs to
mask-image for forced-colors support (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8781 ">#8781</a>)
mayrang</li>
<li>fix(lexical) use extends for type parameter bound in
registerEventListeners flow type (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8778 ">#8778</a>)
Sherry</li>
<li>lexical Bug Fix Keep selection inside single-child inline elements
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8772 ">#8772</a>)
mayrang</li>
<li>lexical Feature registerEventListener registerEventListeners DOM
helpers (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8767 ">#8767</a>)
Bob Ippolito</li>
<li>lexical-playground Bug Fix Restore floating toolbar comment icon
after mask-image conversion (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8773 ">#8773</a>)
mayrang</li>
<li>lexical Bug Fix Skip ZWSP insertion for format mismatch on Android
Chrome (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8769 ">#8769</a>)
mayrang</li>
<li>lexical-a11ylexical-reactlexical-playgroundlexical-website Feature
lexicala11y framework-agnostic accessibility helpers WCAG AA reference
adoption (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8591 ">#8591</a>)
mayrang</li>
<li>Add missing copyright headers to 4 source files (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8768 ">#8768</a>)
xiezhenjia-meta</li>
<li>lexical-website Bug Fix Remove horizontal scroll on homepage hero
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8760 ">#8760</a>)
Bakhtiyar</li>
<li>lexical-selection Bug Fix re-resolve detached firstBlock in insert
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8764 ">#8764</a>)
Olivier Chevallier</li>
<li>lexical Modernize InlineFormattableNode Flow stub syntax rejected by
fb-www flow strict (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8763 ">#8763</a>)
Sherry</li>
<li>lexical-utils Bug Fix positionNodeOnRange leaking orphan rect nodes
when rects shrink (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8762 ">#8762</a>)
Durvesh Pilankar</li>
<li>docs fix duplicated words in comments and docs (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8761 ">#8761</a>)
Durvesh Pilankar</li>
<li>lexical-selection Bug Fix Properly handle block end focus in
backward selections during setBlocksType (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8753 ">#8753</a>)
Olivier Chevallier</li>
<li>lexicallexical-extension Bug Fix Align DecoratorTextNode format with
TextNode in mixed selections (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8737 ">#8737</a>)
sahir</li>
<li>lexical Bug Fix Clean up trailing shadow root after select-all
delete (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8751 ">#8751</a>)
mayrang</li>
<li>lexicallexical-rich-text Bug Fix Place block cursor between
decorators and shadow roots (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8758 ">#8758</a>)
mayrang</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="77ccc19b1e "><code>77ccc19</code></a>
v0.47.0</li>
<li><a
href="18a0abf202 "><code>18a0abf</code></a>
[lexical][lexical-rich-text][lexical-selection] Bug Fix: Fix navigation
acros...</li>
<li><a
href="02d2562c99 "><code>02d2562</code></a>
[lexical][lexical-rich-text] Bug Fix: Fix formatText toggle direction
and add...</li>
<li><a
href="932aa67ec9 "><code>932aa67</code></a>
[lexical] Refactor: Move event module globals into per-editor InputState
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8809 ">#8809</a>)</li>
<li><a
href="b00510c74a "><code>b00510c</code></a>
[lexical] Bug Fix: $getDocument() should fall back to the global
document whe...</li>
<li><a
href="a7666ab11f "><code>a7666ab</code></a>
[*][lexical-devtools][lexical-playground] Chore: Update flow, hermes,
and bab...</li>
<li><a
href="c07e832ab8 "><code>c07e832</code></a>
[lexical] Chore: Add missing Flow type declarations (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical/issues/8799 ">#8799</a>)</li>
<li><a
href="38051a7498 "><code>38051a7</code></a>
[lexical][lexical-playground] Chore: Refactor IME composition test
infrastruc...</li>
<li><a
href="e649ab28b7 "><code>e649ab2</code></a>
[lexical][lexical-eslint-plugin] Feature: Add $getDocument() API and
Shadow D...</li>
<li><a
href="69abb09cec "><code>69abb09</code></a>
[lexical] Bug Fix: deleteCharacter overwrites X11 PRIMARY selection via
Selec...</li>
<li>Additional commits viewable in <a
href="https://github.com/facebook/lexical/commits/v0.47.0/packages/lexical ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-14 10:02:57 -07:00
dependabot[bot]
753544d704
build(deps): bump @clack/prompts from 0.10.1 to 0.11.0 ( #9485 )
...
Bumps
[@clack/prompts](https://github.com/bombshell-dev/clack/tree/HEAD/packages/prompts )
from 0.10.1 to 0.11.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/bombshell-dev/clack/releases ">@clack/prompts's
releases</a>.</em></p>
<blockquote>
<h2><code>@clack/prompts</code><a
href="https://github.com/0 "><code>@0</code></a>.11.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>07ca32d: Reverted a change where placeholders were being set as
values on return.</li>
</ul>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [07ca32d]
<ul>
<li><code>@clack/core</code><a
href="https://github.com/0 "><code>@0</code></a>.5.0</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/bombshell-dev/clack/blob/@clack/prompts@0.11.0/packages/prompts/CHANGELOG.md ">@clack/prompts's
changelog</a>.</em></p>
<blockquote>
<h2>0.11.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>07ca32d: Reverted a change where placeholders were being set as
values on return.</li>
</ul>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [07ca32d]
<ul>
<li><code>@clack/core</code><a
href="https://github.com/0 "><code>@0</code></a>.5.0</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="737f172569 "><code>737f172</code></a>
[ci] release (<a
href="https://github.com/bombshell-dev/clack/tree/HEAD/packages/prompts/issues/325 ">#325</a>)</li>
<li><a
href="07ca32dcfc "><code>07ca32d</code></a>
fix: revert placeholder-on-return change (<a
href="https://github.com/bombshell-dev/clack/tree/HEAD/packages/prompts/issues/324 ">#324</a>)</li>
<li>See full diff in <a
href="https://github.com/bombshell-dev/clack/commits/@clack/prompts@0.11.0/packages/prompts ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-14 10:02:53 -07:00
dependabot[bot]
f92a6648d5
build(deps): bump better-auth from 1.6.20 to 1.6.23 ( #9479 )
...
Bumps
[better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth )
from 1.6.20 to 1.6.23.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/better-auth/better-auth/releases ">better-auth's
releases</a>.</em></p>
<blockquote>
<h2>v1.6.23</h2>
<h2><code>better-auth</code></h2>
<h3>Features</h3>
<ul>
<li>Added Yandex as a social OAuth provider (<a
href="https://redirect.github.com/better-auth/better-auth/pull/9138 ">#9138</a>)</li>
</ul>
<p>For detailed changes, see <a
href="9dfceee140/packages/better-auth/CHANGELOG.md "><code>CHANGELOG</code></a></p>
<h2><code>@better-auth/drizzle-adapter</code></h2>
<h3>Bug Fixes</h3>
<ul>
<li>Fixed affected row counting for D1 and postgres-js adapters (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10257 ">#10257</a>)</li>
</ul>
<p>For detailed changes, see <a
href="9dfceee140/packages/drizzle-adapter/CHANGELOG.md "><code>CHANGELOG</code></a></p>
<h2><code>@better-auth/stripe</code></h2>
<h3>Bug Fixes</h3>
<ul>
<li>Fixed organization subscription actions (cancel, upgrade, restore,
and the billing portal) that could act on the wrong organization.</li>
</ul>
<p>For detailed changes, see <a
href="9dfceee140/packages/stripe/CHANGELOG.md "><code>CHANGELOG</code></a></p>
<h2><code>auth</code></h2>
<h3>Bug Fixes</h3>
<ul>
<li>Fixed string default values not being properly escaped in the
generated Drizzle schema (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10259 ">#10259</a>)</li>
</ul>
<p>For detailed changes, see <a
href="9dfceee140/packages/cli/CHANGELOG.md "><code>CHANGELOG</code></a></p>
<h2>Contributors</h2>
<p>Thanks to everyone who contributed to this release:</p>
<p><a href="https://github.com/bytaesu "><code>@bytaesu</code></a>, <a
href="https://github.com/vladflotsky "><code>@vladflotsky</code></a></p>
<p><strong>Full changelog:</strong> <a
href="https://github.com/better-auth/better-auth/compare/v1.6.22...v1.6.23 "><code>v1.6.22...v1.6.23</code></a></p>
<h2>v1.6.22</h2>
<h2><code>better-auth</code></h2>
<h3>Bug Fixes</h3>
<ul>
<li>Fixed unproven credentials not being revoked during magic link and
email OTP sign-in (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10239 ">#10239</a>)</li>
<li>Fixed server-side OAuth requests to refuse redirect responses
instead of following them (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10241 ">#10241</a>)</li>
</ul>
<p>For detailed changes, see <a
href="a90d061de7/packages/better-auth/CHANGELOG.md "><code>CHANGELOG</code></a></p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md ">better-auth's
changelog</a>.</em></p>
<blockquote>
<h2>1.6.23</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/9138 ">#9138</a>
<a
href="8581f97ea0 "><code>8581f97</code></a>
Thanks <a
href="https://github.com/vladflotsky "><code>@vladflotsky</code></a>! -
Add a pre-configured Yandex provider helper for the generic OAuth
plugin.</p>
</li>
<li>
<p>Updated dependencies [<a
href="930b260cfd "><code>930b260</code></a>]:</p>
<ul>
<li><code>@better-auth/drizzle-adapter</code><a
href="https://github.com/1 "><code>@1</code></a>.6.23</li>
<li><code>@better-auth/core</code><a
href="https://github.com/1 "><code>@1</code></a>.6.23</li>
<li><code>@better-auth/kysely-adapter</code><a
href="https://github.com/1 "><code>@1</code></a>.6.23</li>
<li><code>@better-auth/memory-adapter</code><a
href="https://github.com/1 "><code>@1</code></a>.6.23</li>
<li><code>@better-auth/mongo-adapter</code><a
href="https://github.com/1 "><code>@1</code></a>.6.23</li>
<li><code>@better-auth/prisma-adapter</code><a
href="https://github.com/1 "><code>@1</code></a>.6.23</li>
<li><code>@better-auth/telemetry</code><a
href="https://github.com/1 "><code>@1</code></a>.6.23</li>
</ul>
</li>
</ul>
<h2>1.6.22</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10239 ">#10239</a>
<a
href="c06a56d83a "><code>c06a56d</code></a>
Thanks <a
href="https://github.com/gustavovalverde "><code>@gustavovalverde</code></a>!
- Magic-link and email-OTP sign-in now reset the credentials on an
account whose email had never been confirmed. When verification resolves
to such an account, any existing password on it is removed and its
sessions are revoked before the user is signed in, so proven control of
the mailbox is the source of truth for the account.</p>
<p>If you signed up with email and password but first signed in through
a magic link or email OTP rather than confirming the verification email,
your password is cleared and you will need to set a new one through
password reset.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10240 ">#10240</a>
<a
href="3a035e968e "><code>3a035e9</code></a>
Thanks <a
href="https://github.com/gustavovalverde "><code>@gustavovalverde</code></a>!
- Add account-level lockout for two-factor verification. The attempt
limit applies per account across sign-in challenges and across factors:
TOTP, email-OTP, and backup codes share one counter, and a successful
verification resets it.</p>
<p>Enabled by default: an account locks for 15 minutes after 10
consecutive failed verifications, and locked attempts return
<code>429</code> with the <code>ACCOUNT_TEMPORARILY_LOCKED</code> error
code. Configure it with <code>twoFactor({ accountLockout: { enabled,
maxFailedAttempts, durationSeconds } })</code>.</p>
<p>Run a database migration after upgrading: this adds
<code>failedVerificationCount</code> and <code>lockedUntil</code>
columns to the <code>twoFactor</code> table.</p>
</li>
<li>
<p>Updated dependencies [<a
href="8bd43d9d83 "><code>8bd43d9</code></a>]:</p>
<ul>
<li><code>@better-auth/core</code><a
href="https://github.com/1 "><code>@1</code></a>.6.22</li>
<li><code>@better-auth/drizzle-adapter</code><a
href="https://github.com/1 "><code>@1</code></a>.6.22</li>
<li><code>@better-auth/kysely-adapter</code><a
href="https://github.com/1 "><code>@1</code></a>.6.22</li>
<li><code>@better-auth/memory-adapter</code><a
href="https://github.com/1 "><code>@1</code></a>.6.22</li>
<li><code>@better-auth/mongo-adapter</code><a
href="https://github.com/1 "><code>@1</code></a>.6.22</li>
<li><code>@better-auth/prisma-adapter</code><a
href="https://github.com/1 "><code>@1</code></a>.6.22</li>
<li><code>@better-auth/telemetry</code><a
href="https://github.com/1 "><code>@1</code></a>.6.22</li>
</ul>
</li>
</ul>
<h2>1.6.21</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10212 ">#10212</a>
<a
href="e0762a127c "><code>e0762a1</code></a>
Thanks <a href="https://github.com/bytaesu "><code>@bytaesu</code></a>!
- In root-mounted deployments, requests whose path does not start with
the configured <code>basePath</code> now return 404 instead of resolving
to an endpoint.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10187 ">#10187</a>
<a
href="882cf9e592 "><code>882cf9e</code></a>
Thanks <a
href="https://github.com/ping-maxwell "><code>@ping-maxwell</code></a>!
- Admin permission changes and bans now take effect immediately for
admin APIs, even when session cookie cache is enabled. Sensitive session
checks also continue to work in stateless apps where signed cookies are
the session record.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/9939 ">#9939</a>
<a
href="f52e1ab50b "><code>f52e1ab</code></a>
Thanks <a
href="https://github.com/benpsnyder "><code>@benpsnyder</code></a>! -
fixes a bug causing deviceAuthorization() throwing a ZodError at
construction when called without a schema option</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10196 ">#10196</a>
<a
href="b5bec193a5 "><code>b5bec19</code></a>
Thanks <a
href="https://github.com/Paola3stefania "><code>@Paola3stefania</code></a>!
- OAuth sign-up and account-link profile sync now ignore provider
profile values for user fields marked <code>input: false</code>.
Input-allowed additional fields still persist from
<code>mapProfileToUser</code>, and schema defaults still apply when
OAuth creates a user. Apps that used <code>mapProfileToUser</code> to
fill <code>input: false</code> fields should set those fields in
server-side provisioning code instead.</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="9dfceee140 "><code>9dfceee</code></a>
chore: release v1.6.23 (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10260 ">#10260</a>)</li>
<li><a
href="8581f97ea0 "><code>8581f97</code></a>
feat(oauth): add Yandex social provider (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/9138 ">#9138</a>)</li>
<li><a
href="a90d061de7 "><code>a90d061</code></a>
chore: release v1.6.22 (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10245 ">#10245</a>)</li>
<li><a
href="3a035e968e "><code>3a035e9</code></a>
fix(two-factor): add account-level verification lockout (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10240 ">#10240</a>)</li>
<li><a
href="c06a56d83a "><code>c06a56d</code></a>
fix: revoke unproven credentials on magic-link/email-OTP sign-in (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10239 ">#10239</a>)</li>
<li><a
href="414169d95a "><code>414169d</code></a>
chore: release v1.6.21 (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10184 ">#10184</a>)</li>
<li><a
href="f52e1ab50b "><code>f52e1ab</code></a>
fix(device-authorization): make <code>schema</code> option optional
under Zod v4 (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/9939 ">#9939</a>)</li>
<li><a
href="882cf9e592 "><code>882cf9e</code></a>
fix(admin): use authoritative session reads for authorization (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10187 ">#10187</a>)</li>
<li><a
href="b5bec193a5 "><code>b5bec19</code></a>
fix(oauth): apply user input rules to provider profiles (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10196 ">#10196</a>)</li>
<li><a
href="471f81c1ab "><code>471f81c</code></a>
refactor: centralize request IP resolver in core (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10216 ">#10216</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/better-auth/better-auth/commits/v1.6.23/packages/better-auth ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-14 10:02:48 -07:00
dependabot[bot]
dcb7c323ed
build(deps-dev): bump @storybook/react-vite from 10.4.6 to 10.5.0 ( #9482 )
...
Bumps
[@storybook/react-vite](https://github.com/storybookjs/storybook/tree/HEAD/code/frameworks/react-vite )
from 10.4.6 to 10.5.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/releases ">@storybook/react-vite's
releases</a>.</em></p>
<blockquote>
<h2>v10.5.0</h2>
<h2>10.5.0</h2>
<blockquote>
<p><em>Foundational changes for new AI workflows</em></p>
</blockquote>
<p>Storybook 10.5 contains hundreds of fixes and improvements:</p>
<ul>
<li>⚡ ️ Angular-vite framework: Modern, fast dev, docs, and test
(preview)</li>
<li>🌈 Vitest initialGlobals: Test across themes, viewports, locales</li>
<li>🤖 Agentic review: AI-curated visual changesets and search results
(experimental)</li>
<li>⚛️ React docgen service: Unified metadata across MCP, Docs, and
Controls (experimental)</li>
<li>🧑💻 Claude / Codex plugins: One-click ADE integration
(experimental)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md ">@storybook/react-vite's
changelog</a>.</em></p>
<blockquote>
<h2>10.5.0</h2>
<blockquote>
<p><em>Foundational changes for new AI workflows</em></p>
</blockquote>
<p>Storybook 10.5 contains hundreds of fixes and improvements:</p>
<ul>
<li>⚡ ️ Angular-vite framework: Modern, fast dev, docs, and test
(preview)</li>
<li>🌈 Vitest initialGlobals: Test across themes, viewports, locales</li>
<li>🤖 Agentic review: AI-curated visual changesets and search results
(experimental)</li>
<li>⚛️ React docgen service: Unified metadata across MCP, Docs, and
Controls (experimental)</li>
<li>🧑💻 Claude / Codex plugins: One-click ADE integration
(experimental)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="9dafcd22ed "><code>9dafcd2</code></a>
Bump version from "10.5.0-beta.2" to "10.5.0" [skip
ci]</li>
<li><a
href="448db85e65 "><code>448db85</code></a>
Bump version from "10.5.0-beta.1" to "10.5.0-beta.2"
[skip ci]</li>
<li><a
href="a4ce9790a7 "><code>a4ce979</code></a>
Bump version from "10.5.0-beta.0" to "10.5.0-beta.1"
[skip ci]</li>
<li><a
href="f0bf138a0a "><code>f0bf138</code></a>
Bump version from "10.5.0-alpha.11" to
"10.5.0-beta.0" [skip ci]</li>
<li><a
href="fac05a5741 "><code>fac05a5</code></a>
Bump version from "10.5.0-alpha.10" to
"10.5.0-alpha.11" [skip ci]</li>
<li><a
href="4057c4169f "><code>4057c41</code></a>
Bump version from "10.5.0-alpha.9" to
"10.5.0-alpha.10" [skip ci]</li>
<li><a
href="da84210b49 "><code>da84210</code></a>
Bump version from "10.5.0-alpha.8" to
"10.5.0-alpha.9" [skip ci]</li>
<li><a
href="c347410b9f "><code>c347410</code></a>
Bump version from "10.5.0-alpha.7" to
"10.5.0-alpha.8" [skip ci]</li>
<li><a
href="d16ab3008a "><code>d16ab30</code></a>
React: Align react-docgen versions</li>
<li><a
href="c9a1ac9f72 "><code>c9a1ac9</code></a>
Bump version from "10.5.0-alpha.6" to
"10.5.0-alpha.7" [skip ci]</li>
<li>Additional commits viewable in <a
href="https://github.com/storybookjs/storybook/commits/v10.5.0/code/frameworks/react-vite ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-14 10:02:39 -07:00
dependabot[bot]
26bd07400b
build(deps-dev): bump tailwindcss from 4.3.0 to 4.3.2 ( #9477 )
...
Bumps
[tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss )
from 4.3.0 to 4.3.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/tailwindlabs/tailwindcss/releases ">tailwindcss's
releases</a>.</em></p>
<blockquote>
<h2>v4.3.2</h2>
<h3>Fixed</h3>
<ul>
<li>Support bare spacing values for <code>auto-rows-*</code> and
<code>auto-cols-*</code> utilities (e.g. <code>auto-rows-12</code> and
<code>auto-cols-16</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20229 ">#20229</a>)</li>
<li>Prevent <code>@tailwindcss/cli</code> in <code>--watch</code> mode
from crashing on Windows when <code>@source</code> points to a directory
that doesn't exist (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20242 ">#20242</a>)</li>
<li>Prevent <code>@tailwindcss/vite</code> from crashing in Deno v2.8.x
when <code>context.parentURL</code> is not a valid URL (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20245 ">#20245</a>)</li>
<li>Ensure <code>@tailwindcss/cli</code> in <code>--watch</code> mode
rebuilds when the input CSS file changes in an ignored directory (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20246 ">#20246</a>)</li>
<li>Allow <code>@variant</code> rules used in <code>addBase(…)</code> to
use custom variants defined later (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20247 ">#20247</a>)</li>
<li>Prevent <code>@tailwindcss/vite</code> from crashing during HMR when
scanned files or directories are deleted (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20259 ">#20259</a>)</li>
<li>Generate <code>font-size</code> instead of <code>color</code>
declarations for <code>text-[--spacing(…)]</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20260 ">#20260</a>)</li>
<li>Prevent <code>@source</code> patterns from scanning unrelated
sibling files and folders (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20263 ">#20263</a>)</li>
<li>Extract class candidates adjacent to Template Toolkit delimiters
like <code>%]…[%</code> in <code>.tt</code>, <code>.tt2</code>, and
<code>.tx</code> files (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20269 ">#20269</a>)</li>
<li>Extract class candidates from conditional Maud syntax like
<code>p.text-black[condition]</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20269 ">#20269</a>)</li>
<li>Prevent <code>@position-try</code> rules from triggering unknown
at-rule warnings when optimizing CSS (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20277 ">#20277</a>)</li>
<li>Support class suggestions for named opacity modifiers from
<code>--opacity</code> theme values (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20287 ">#20287</a>)</li>
<li>Prevent type errors in <code>@tailwindcss/postcss</code> when used
with newer PostCSS patch releases (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20289 ">#20289</a>)</li>
</ul>
<h2>v4.3.1</h2>
<h3>Added</h3>
<ul>
<li>Add <code>--silent</code> option to suppress output in
<code>@tailwindcss/cli</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20100 ">#20100</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Remove deprecation warnings by using
<code>Module#registerHooks</code> instead of
<code>Module#register</code> on Node 26+ (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20028 ">#20028</a>)</li>
<li>Canonicalization: don't crash when plugin utilities throw for
unsupported values (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20052 ">#20052</a>)</li>
<li>Allow <code>@apply</code> to be used with CSS mixins (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19427 ">#19427</a>)</li>
<li>Ensure <code>not-*</code> correctly negates <code>@container</code>
queries, including <code>style(…)</code> queries (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20059 ">#20059</a>)</li>
<li>Ensure <code>drop-shadow-*</code> color utilities work with custom
shadow values containing <code>calc(…)</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20080 ">#20080</a>)</li>
<li>Fix 'Sourcemap is likely to be incorrect' warnings when using
<code>@tailwindcss/vite</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20103 ">#20103</a>)</li>
<li>Ensure <code>@tailwindcss/webpack</code> can be installed in Rspack
projects without requiring <code>webpack</code> as a peer dependency (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20027 ">#20027</a>)</li>
<li>Canonicalization: don't suggest invalid <code>calc(…)</code>
expressions (e.g. <code>px-[calc(1rem+0px)]</code> →
<code>px-[calc(1rem+0)]</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20127 ">#20127</a>)</li>
<li>Canonicalization: avoid suggesting large spacing-scale values for
arbitrary lengths (e.g. <code>left-[99999px]</code> →
<code>left-[99999px]</code>, not <code>left-24999.75</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20130 ">#20130</a>)</li>
<li>Ensure <code>@tailwindcss/cli</code> in <code>--watch</code> mode
recovers when a tracked dependency is deleted and restored (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20137 ">#20137</a>)</li>
<li>Ensure standalone <code>@tailwindcss/cli</code> binaries are ignored
when scanning for class candidates (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20139 ">#20139</a>)</li>
<li>Ensure class candidates are extracted from Twig
<code>addClass(…)</code> and <code>removeClass(…)</code> calls (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20198 ">#20198</a>)</li>
<li>Don't crash in the Ruby or Vue preprocessors when scanning files
containing invalid UTF-8 bytes (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19588 ">#19588</a>)</li>
<li>Allow <code>@variant</code> to be used inside <code>addBase</code>
(<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19480 ">#19480</a>)</li>
<li>Ensure <code>@source</code> globs with symlinks are preserved (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20203 ">#20203</a>)</li>
<li>Ensure later <code>@source</code> rules can re-include files
excluded by earlier <code>@source not</code> rules (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20203 ">#20203</a>)</li>
<li>Upgrade: don't migrate empty class rules to invalid
<code>@utility</code> rules (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20205 ">#20205</a>)</li>
<li>Ensure transitions between <code>inset-shadow-none</code> and other
inset shadows work correctly (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20208 ">#20208</a>)</li>
<li>Ensure explicitly referenced <code>@source</code> directories are
scanned even when ignored by git (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20214 ">#20214</a>)</li>
<li>Ensure <code>@source</code> globs ending in <code>**/*</code>
preserve dynamic path segments to avoid scanning too many files (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20217 ">#20217</a>)</li>
<li>Canonicalization: don't fold <code>calc(…)</code> divisions when the
result would require high precision (e.g.
<code>w-[calc(100%/3.5)]</code> → <code>w-[calc(100%/3.5)]</code>, not
<code>w-[28.571428571428573%]</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20221 ">#20221</a>)</li>
<li>Serve ESM type declarations to ESM importers of
<code>@tailwindcss/postcss</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20228 ">#20228</a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Generate <code>0</code> instead of <code>calc(var(--spacing) *
0)</code> for spacing utilities like <code>m-0</code> and
<code>left-0</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20196 ">#20196</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md ">tailwindcss's
changelog</a>.</em></p>
<blockquote>
<h2>[4.3.2] - 2026-06-26</h2>
<h3>Fixed</h3>
<ul>
<li>Support bare spacing values for <code>auto-rows-*</code> and
<code>auto-cols-*</code> utilities (e.g. <code>auto-rows-12</code> and
<code>auto-cols-16</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20229 ">#20229</a>)</li>
<li>Prevent <code>@tailwindcss/cli</code> in <code>--watch</code> mode
from crashing on Windows when <code>@source</code> points to a directory
that doesn't exist (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20242 ">#20242</a>)</li>
<li>Prevent <code>@tailwindcss/vite</code> from crashing in Deno v2.8.x
when <code>context.parentURL</code> is not a valid URL (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20245 ">#20245</a>)</li>
<li>Ensure <code>@tailwindcss/cli</code> in <code>--watch</code> mode
rebuilds when the input CSS file changes in an ignored directory (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20246 ">#20246</a>)</li>
<li>Allow <code>@variant</code> rules used in <code>addBase(…)</code> to
use custom variants defined later (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20247 ">#20247</a>)</li>
<li>Prevent <code>@tailwindcss/vite</code> from crashing during HMR when
scanned files or directories are deleted (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20259 ">#20259</a>)</li>
<li>Generate <code>font-size</code> instead of <code>color</code>
declarations for <code>text-[--spacing(…)]</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20260 ">#20260</a>)</li>
<li>Prevent <code>@source</code> patterns from scanning unrelated
sibling files and folders (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20263 ">#20263</a>)</li>
<li>Extract class candidates adjacent to Template Toolkit delimiters
like <code>%]…[%</code> in <code>.tt</code>, <code>.tt2</code>, and
<code>.tx</code> files (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20269 ">#20269</a>)</li>
<li>Extract class candidates from conditional Maud syntax like
<code>p.text-black[condition]</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20269 ">#20269</a>)</li>
<li>Prevent <code>@position-try</code> rules from triggering unknown
at-rule warnings when optimizing CSS (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20277 ">#20277</a>)</li>
<li>Support class suggestions for named opacity modifiers from
<code>--opacity</code> theme values (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20287 ">#20287</a>)</li>
<li>Prevent type errors in <code>@tailwindcss/postcss</code> when used
with newer PostCSS patch releases (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20289 ">#20289</a>)</li>
</ul>
<h2>[4.3.1] - 2026-06-12</h2>
<h3>Added</h3>
<ul>
<li>Add <code>--silent</code> option to suppress output in
<code>@tailwindcss/cli</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20100 ">#20100</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Remove deprecation warnings by using
<code>Module#registerHooks</code> instead of
<code>Module#register</code> on Node 26+ (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20028 ">#20028</a>)</li>
<li>Canonicalization: don't crash when plugin utilities throw for
unsupported values (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20052 ">#20052</a>)</li>
<li>Allow <code>@apply</code> to be used with CSS mixins (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19427 ">#19427</a>)</li>
<li>Ensure <code>not-*</code> correctly negates <code>@container</code>
queries, including <code>style(…)</code> queries (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20059 ">#20059</a>)</li>
<li>Ensure <code>drop-shadow-*</code> color utilities work with custom
shadow values containing <code>calc(…)</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20080 ">#20080</a>)</li>
<li>Fix 'Sourcemap is likely to be incorrect' warnings when using
<code>@tailwindcss/vite</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20103 ">#20103</a>)</li>
<li>Ensure <code>@tailwindcss/webpack</code> can be installed in Rspack
projects without requiring <code>webpack</code> as a peer dependency (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20027 ">#20027</a>)</li>
<li>Canonicalization: don't suggest invalid <code>calc(…)</code>
expressions (e.g. <code>px-[calc(1rem+0px)]</code> →
<code>px-[calc(1rem+0)]</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20127 ">#20127</a>)</li>
<li>Canonicalization: avoid suggesting large spacing-scale values for
arbitrary lengths (e.g. <code>left-[99999px]</code> →
<code>left-[99999px]</code>, not <code>left-24999.75</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20130 ">#20130</a>)</li>
<li>Ensure <code>@tailwindcss/cli</code> in <code>--watch</code> mode
recovers when a tracked dependency is deleted and restored (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20137 ">#20137</a>)</li>
<li>Ensure standalone <code>@tailwindcss/cli</code> binaries are ignored
when scanning for class candidates (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20139 ">#20139</a>)</li>
<li>Ensure class candidates are extracted from Twig
<code>addClass(…)</code> and <code>removeClass(…)</code> calls (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20198 ">#20198</a>)</li>
<li>Don't crash in the Ruby or Vue preprocessors when scanning files
containing invalid UTF-8 bytes (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19588 ">#19588</a>)</li>
<li>Allow <code>@variant</code> to be used inside <code>addBase</code>
(<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19480 ">#19480</a>)</li>
<li>Ensure <code>@source</code> globs with symlinks are preserved (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20203 ">#20203</a>)</li>
<li>Ensure later <code>@source</code> rules can re-include files
excluded by earlier <code>@source not</code> rules (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20203 ">#20203</a>)</li>
<li>Upgrade: don't migrate empty class rules to invalid
<code>@utility</code> rules (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20205 ">#20205</a>)</li>
<li>Ensure transitions between <code>inset-shadow-none</code> and other
inset shadows work correctly (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20208 ">#20208</a>)</li>
<li>Ensure explicitly referenced <code>@source</code> directories are
scanned even when ignored by git (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20214 ">#20214</a>)</li>
<li>Ensure <code>@source</code> globs ending in <code>**/*</code>
preserve dynamic path segments to avoid scanning too many files (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20217 ">#20217</a>)</li>
<li>Canonicalization: don't fold <code>calc(…)</code> divisions when the
result would require high precision (e.g.
<code>w-[calc(100%/3.5)]</code> → <code>w-[calc(100%/3.5)]</code>, not
<code>w-[28.571428571428573%]</code>) (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20221 ">#20221</a>)</li>
<li>Serve ESM type declarations to ESM importers of
<code>@tailwindcss/postcss</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/20228 ">#20228</a>)</li>
</ul>
<h3>Changed</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="056a155072 "><code>056a155</code></a>
4.3.2 (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss/issues/20281 ">#20281</a>)</li>
<li><a
href="c8b081d963 "><code>c8b081d</code></a>
Add suggestions for named opacity modifiers (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss/issues/20287 ">#20287</a>)</li>
<li><a
href="c46f654fa0 "><code>c46f654</code></a>
Ensure <code>--alpha(…)</code> is seen as a <code>color</code>, and
<code>--spacing(…)</code> is seen as a `le...</li>
<li><a
href="5e9f66e428 "><code>5e9f66e</code></a>
Ensure <code>@variant</code> can be used in JS based APIs (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss/issues/20252 ">#20252</a>)</li>
<li><a
href="707c23b955 "><code>707c23b</code></a>
Ensure custom variants can be used via <code>@variant</code> in
<code>addBase</code> (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss/issues/20247 ">#20247</a>)</li>
<li><a
href="127d17033a "><code>127d170</code></a>
Add bare value support for <code>auto-rows-*</code> and
<code>auto-cols-*</code> (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss/issues/20229 ">#20229</a>)</li>
<li><a
href="8a14a71010 "><code>8a14a71</code></a>
4.3.1 (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss/issues/20226 ">#20226</a>)</li>
<li><a
href="12833aa4b3 "><code>12833aa</code></a>
Fix canonicalization bug where we end up with a high precision number
(<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss/issues/20221 ">#20221</a>)</li>
<li><a
href="97a5b3abfb "><code>97a5b3a</code></a>
docs: fix double word 'to to' in test comment (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss/issues/20216 ">#20216</a>)</li>
<li><a
href="d01e103cc4 "><code>d01e103</code></a>
Add missing <code>inset</code> keyword for
<code>inset-shadow-none</code> (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss/issues/20208 ">#20208</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/tailwindlabs/tailwindcss/commits/v4.3.2/packages/tailwindcss ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-14 10:02:37 -07:00
github-actions[bot]
4d50fa9f29
chore(lockfile): refresh pnpm-lock.yaml ( #9304 )
...
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
2026-07-09 13:10:22 -05:00
github-actions[bot]
ea301442e8
chore(lockfile): refresh pnpm-lock.yaml ( #9252 )
...
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
2026-07-08 22:15:41 -07:00
dependabot[bot]
bdd3aa2110
build(deps): bump sharp from 0.35.2 to 0.35.3 ( #9061 )
...
Bumps [sharp](https://github.com/lovell/sharp ) from 0.35.2 to 0.35.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lovell/sharp/releases ">sharp's
releases</a>.</em></p>
<blockquote>
<h2>v0.35.3</h2>
<ul>
<li>
<p>Tighten verification of <code>text</code> dimensions, TIFF tile
dimensions and <code>extend</code> values.</p>
</li>
<li>
<p>Improve code bundler support by resolving path to libvips binary.</p>
</li>
<li>
<p>Increase default concurrency when use of
<code>MALLOC_ARENA_MAX</code> is detected.</p>
</li>
<li>
<p>Emit warning about binaries provided by Electron for use on
Linux.</p>
</li>
<li>
<p>Add <code>hasAlpha</code> property to output <code>info</code>.
<a
href="https://redirect.github.com/lovell/sharp/issues/4500 ">#4500</a></p>
</li>
<li>
<p>TypeScript: Return more precise
<code>Buffer<ArrayBuffer></code> from <code>toBuffer</code>.
<a href="https://redirect.github.com/lovell/sharp/pull/4520 ">#4520</a>
<a href="https://github.com/Andarist "><code>@Andarist</code></a></p>
</li>
<li>
<p>Bound <code>clahe</code> width and height to avoid signed overflow.
<a href="https://redirect.github.com/lovell/sharp/pull/4551 ">#4551</a>
<a
href="https://github.com/metsw24-max "><code>@metsw24-max</code></a></p>
</li>
<li>
<p>Bound <code>trim</code> margin to avoid signed overflow.
<a href="https://redirect.github.com/lovell/sharp/pull/4552 ">#4552</a>
<a
href="https://github.com/metsw24-max "><code>@metsw24-max</code></a></p>
</li>
<li>
<p>Reject infinite values when validating numbers.
<a href="https://redirect.github.com/lovell/sharp/pull/4553 ">#4553</a>
<a
href="https://github.com/metsw24-max "><code>@metsw24-max</code></a></p>
</li>
<li>
<p>Bound extract region to libvips coordinate limit.
<a href="https://redirect.github.com/lovell/sharp/pull/4555 ">#4555</a>
<a
href="https://github.com/metsw24-max "><code>@metsw24-max</code></a></p>
</li>
<li>
<p>Verify background colour values are numbers.
<a href="https://redirect.github.com/lovell/sharp/pull/4556 ">#4556</a>
<a
href="https://github.com/metsw24-max "><code>@metsw24-max</code></a></p>
</li>
<li>
<p>Bound create and raw input dimensions to coordinate limit.
<a href="https://redirect.github.com/lovell/sharp/pull/4558 ">#4558</a>
<a
href="https://github.com/metsw24-max "><code>@metsw24-max</code></a></p>
</li>
<li>
<p>Tighten recomb and affine matrix verification.
<a href="https://redirect.github.com/lovell/sharp/pull/4560 ">#4560</a>
<a
href="https://github.com/chatman-media "><code>@chatman-media</code></a></p>
</li>
<li>
<p>Verify cache memory limit to avoid overflow.
<a href="https://redirect.github.com/lovell/sharp/pull/4561 ">#4561</a>
<a
href="https://github.com/metsw24-max "><code>@metsw24-max</code></a></p>
</li>
</ul>
<h2>v0.35.3-rc.2</h2>
<ul>
<li>Tighten verification of <code>text</code> dimensions, TIFF tile
dimensions and <code>extend</code> values.</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="1018449164 "><code>1018449</code></a>
Release v0.35.3</li>
<li><a
href="ba303a799d "><code>ba303a7</code></a>
Prerelease v0.35.3-rc.2</li>
<li><a
href="4f94fc5162 "><code>4f94fc5</code></a>
Upgrade to sharp-libvips v1.3.2</li>
<li><a
href="c5e7a3ff20 "><code>c5e7a3f</code></a>
Bump devDeps, fix Deno/Windows smoke tests</li>
<li><a
href="9a8d002688 "><code>9a8d002</code></a>
Docs: Add changelog entry and note about transferable <a
href="https://redirect.github.com/lovell/sharp/issues/4520 ">#4520</a></li>
<li><a
href="8694db0bac "><code>8694db0</code></a>
TypeScript: Return more precise <code>Buffer\<ArrayBuffer></code>
from <code>toBuffer</code> (<a
href="https://redirect.github.com/lovell/sharp/issues/4520 ">#4520</a>)</li>
<li><a
href="e000d0b5e1 "><code>e000d0b</code></a>
Prerelease v0.35.3-rc.1</li>
<li><a
href="9554ca9553 "><code>9554ca9</code></a>
Prerelease v0.35.3-rc.0</li>
<li><a
href="6a29fd55db "><code>6a29fd5</code></a>
Emit warning about native binaries on Linux Electron</li>
<li><a
href="540d2eada4 "><code>540d2ea</code></a>
Increase default concurrency when use of MALLOC_ARENA_MAX detected</li>
<li>Additional commits viewable in <a
href="https://github.com/lovell/sharp/compare/v0.35.2...v0.35.3 ">compare
view</a></li>
</ul>
</details>
<br />
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-07 13:03:30 -07:00
dependabot[bot]
a058f761f3
build(deps-dev): bump rollup from 4.61.1 to 4.62.2 ( #9070 )
...
[//]: # (dependabot-start)
⚠️ **Dependabot is rebasing this PR** ⚠️
Rebasing might not happen immediately, so don't worry if this takes some
time.
Note: if you make any changes to this PR yourself, they will take
precedence over the rebase.
---
[//]: # (dependabot-end)
Bumps [rollup](https://github.com/rollup/rollup ) from 4.61.1 to 4.62.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/rollup/rollup/releases ">rollup's
releases</a>.</em></p>
<blockquote>
<h2>v4.62.2</h2>
<h2>4.62.2</h2>
<p><em>2026-06-19</em></p>
<h3>Bug Fixes</h3>
<ul>
<li>Do not add spurious side-effect-free external imports to chunks when
using minChunkSize (<a
href="https://redirect.github.com/rollup/rollup/issues/6411 ">#6411</a>)</li>
</ul>
<h3>Pull Requests</h3>
<ul>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6411 ">#6411</a>:
Skip side-effect-free external imports when hoisting is disabled (<a
href="https://github.com/morgan-coded "><code>@morgan-coded</code></a>,
<a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6416 ">#6416</a>:
refactor(rust/parser_ast): extract property AstConverter write buffer
kind logic to new method (<a
href="https://github.com/fabianbernhart "><code>@fabianbernhart</code></a>,
<a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
</ul>
<h2>v4.62.1</h2>
<h2>4.62.1</h2>
<p><em>2026-06-19</em></p>
<h3>Bug Fixes</h3>
<ul>
<li>Preserve multipart file extensions when deconflicting output chunks
(<a
href="https://redirect.github.com/rollup/rollup/issues/6408 ">#6408</a>)</li>
<li>Fix an issue where getLogFilter would match additional logs (<a
href="https://redirect.github.com/rollup/rollup/issues/6415 ">#6415</a>)</li>
</ul>
<h3>Pull Requests</h3>
<ul>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6393 ">#6393</a>:
Use import attributes for importing JSON (<a
href="https://github.com/selfisekai "><code>@selfisekai</code></a>, <a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6408 ">#6408</a>:
fix: insert conflict numbers before first extension in multi-extension
filenames (<a
href="https://github.com/LeSingh1 "><code>@LeSingh1</code></a>, <a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6415 ">#6415</a>:
fix: advance value past wildcard prefix before suffix check in
getLogFilter (<a
href="https://github.com/JSap0914 "><code>@JSap0914</code></a>, <a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6417 ">#6417</a>:
chore(deps): update msys2/setup-msys2 digest to 66cd2cc (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot])</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6418 ">#6418</a>:
fix(deps): update minor/patch updates (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot], <a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6419 ">#6419</a>:
chore(deps): update dependency eslint-plugin-unicorn to v66 (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot])</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6420 ">#6420</a>:
chore(deps): lock file maintenance minor/patch updates (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot], <a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
</ul>
<h2>v4.62.0</h2>
<h2>4.62.0</h2>
<p><em>2026-06-13</em></p>
<h3>Features</h3>
<ul>
<li>Ensure that shared dependencies between manual chunks and entry
points receive a serparate chunk (<a
href="https://redirect.github.com/rollup/rollup/issues/6374 ">#6374</a>)</li>
</ul>
<h3>Pull Requests</h3>
<ul>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6374 ">#6374</a>:
Extract the static dependencies imported by manual chunks into separate
chunks (<a
href="https://github.com/TrickyPi "><code>@TrickyPi</code></a>, <a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6405 ">#6405</a>:
fix(deps): update minor/patch updates (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot])</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6406 ">#6406</a>:
chore(deps): pin dependency concurrently to v9 (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot], <a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6407 ">#6407</a>:
chore(deps): lock file maintenance minor/patch updates (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot])</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6409 ">#6409</a>:
chore(deps): update minor/patch updates to v6.2.0 (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot])</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/rollup/rollup/blob/master/CHANGELOG.md ">rollup's
changelog</a>.</em></p>
<blockquote>
<h2>4.62.2</h2>
<p><em>2026-06-19</em></p>
<h3>Bug Fixes</h3>
<ul>
<li>Do not add spurious side-effect-free external imports to chunks when
using minChunkSize (<a
href="https://redirect.github.com/rollup/rollup/issues/6411 ">#6411</a>)</li>
</ul>
<h3>Pull Requests</h3>
<ul>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6411 ">#6411</a>:
Skip side-effect-free external imports when hoisting is disabled (<a
href="https://github.com/morgan-coded "><code>@morgan-coded</code></a>,
<a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6416 ">#6416</a>:
refactor(rust/parser_ast): extract property AstConverter write buffer
kind logic to new method (<a
href="https://github.com/fabianbernhart "><code>@fabianbernhart</code></a>,
<a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
</ul>
<h2>4.62.1</h2>
<p><em>2026-06-19</em></p>
<h3>Bug Fixes</h3>
<ul>
<li>Preserve multipart file extensions when deconflicting output chunks
(<a
href="https://redirect.github.com/rollup/rollup/issues/6408 ">#6408</a>)</li>
<li>Fix an issue where getLogFilter would match additional logs (<a
href="https://redirect.github.com/rollup/rollup/issues/6415 ">#6415</a>)</li>
</ul>
<h3>Pull Requests</h3>
<ul>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6393 ">#6393</a>:
Use import attributes for importing JSON (<a
href="https://github.com/selfisekai "><code>@selfisekai</code></a>, <a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6408 ">#6408</a>:
fix: insert conflict numbers before first extension in multi-extension
filenames (<a
href="https://github.com/LeSingh1 "><code>@LeSingh1</code></a>, <a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6415 ">#6415</a>:
fix: advance value past wildcard prefix before suffix check in
getLogFilter (<a
href="https://github.com/JSap0914 "><code>@JSap0914</code></a>, <a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6417 ">#6417</a>:
chore(deps): update msys2/setup-msys2 digest to 66cd2cc (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot])</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6418 ">#6418</a>:
fix(deps): update minor/patch updates (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot], <a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6419 ">#6419</a>:
chore(deps): update dependency eslint-plugin-unicorn to v66 (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot])</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6420 ">#6420</a>:
chore(deps): lock file maintenance minor/patch updates (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot], <a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
</ul>
<h2>4.62.0</h2>
<p><em>2026-06-13</em></p>
<h3>Features</h3>
<ul>
<li>Ensure that shared dependencies between manual chunks and entry
points receive a serparate chunk (<a
href="https://redirect.github.com/rollup/rollup/issues/6374 ">#6374</a>)</li>
</ul>
<h3>Pull Requests</h3>
<ul>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6374 ">#6374</a>:
Extract the static dependencies imported by manual chunks into separate
chunks (<a
href="https://github.com/TrickyPi "><code>@TrickyPi</code></a>, <a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6405 ">#6405</a>:
fix(deps): update minor/patch updates (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot])</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6406 ">#6406</a>:
chore(deps): pin dependency concurrently to v9 (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot], <a
href="https://github.com/lukastaegert "><code>@lukastaegert</code></a>)</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6407 ">#6407</a>:
chore(deps): lock file maintenance minor/patch updates (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot])</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6409 ">#6409</a>:
chore(deps): update minor/patch updates to v6.2.0 (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot])</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6410 ">#6410</a>:
chore(deps): lock file maintenance minor/patch updates (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot])</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6412 ">#6412</a>:
fix(deps): update minor/patch updates (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot])</li>
<li><a
href="https://redirect.github.com/rollup/rollup/pull/6413 ">#6413</a>:
chore(deps): update dependency eslint-plugin-unicorn to v65 (<a
href="https://github.com/renovate "><code>@renovate</code></a>[bot])</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="8faa187773 "><code>8faa187</code></a>
4.62.2</li>
<li><a
href="a38a795c48 "><code>a38a795</code></a>
refactor(rust/parser_ast): extract property AstConverter write buffer
kind lo...</li>
<li><a
href="6cc5c316bb "><code>6cc5c31</code></a>
Skip side-effect-free external imports when hoisting is disabled (<a
href="https://redirect.github.com/rollup/rollup/issues/6411 ">#6411</a>)</li>
<li><a
href="caacf701b8 "><code>caacf70</code></a>
4.62.1</li>
<li><a
href="d1e8297966 "><code>d1e8297</code></a>
Add missing ignore</li>
<li><a
href="1ba1fc2387 "><code>1ba1fc2</code></a>
fix: insert conflict numbers before first extension in multi-extension
filena...</li>
<li><a
href="532bd0ade7 "><code>532bd0a</code></a>
Use import attributes for importing JSON (<a
href="https://redirect.github.com/rollup/rollup/issues/6393 ">#6393</a>)</li>
<li><a
href="2cd8194aa8 "><code>2cd8194</code></a>
fix: advance value past wildcard prefix before suffix check in
getLogFilter (...</li>
<li><a
href="dfac590bd5 "><code>dfac590</code></a>
fix(deps): update minor/patch updates (<a
href="https://redirect.github.com/rollup/rollup/issues/6418 ">#6418</a>)</li>
<li><a
href="1d6db3d325 "><code>1d6db3d</code></a>
chore(deps): update dependency eslint-plugin-unicorn to v66 (<a
href="https://redirect.github.com/rollup/rollup/issues/6419 ">#6419</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/rollup/rollup/compare/v4.61.1...v4.62.2 ">compare
view</a></li>
</ul>
</details>
<br />
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-07 13:02:36 -07:00
Nicky Leach
2ef70c3673
build(deps): upgrade lexical family to 0.46.0 and pin via overrides (fixes dual-version getType crash) ( #9180 )
2026-07-07 13:00:26 -07:00
dependabot[bot]
5356b7d737
build(deps): bump @tanstack/react-query from 5.90.21 to 5.101.2 ( #9067 )
...
Bumps
[@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query )
from 5.90.21 to 5.101.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/TanStack/query/releases ">@tanstack/react-query's
releases</a>.</em></p>
<blockquote>
<h2><code>@tanstack/react-query-devtools</code><a
href="https://github.com/5 "><code>@5</code></a>.101.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a
href="f5bf180d93 "><code>f5bf180</code></a>,
<a
href="25cdd975fe "><code>25cdd97</code></a>,
<a
href="ecd89c8faf "><code>ecd89c8</code></a>,
<a
href="01c763444e "><code>01c7634</code></a>,
<a
href="49012dbd51 "><code>49012db</code></a>]:
<ul>
<li><code>@tanstack/query-devtools</code><a
href="https://github.com/5 "><code>@5</code></a>.101.2</li>
<li><code>@tanstack/react-query</code><a
href="https://github.com/5 "><code>@5</code></a>.101.2</li>
</ul>
</li>
</ul>
<h2><code>@tanstack/react-query-next-experimental</code><a
href="https://github.com/5 "><code>@5</code></a>.101.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies []:
<ul>
<li><code>@tanstack/react-query</code><a
href="https://github.com/5 "><code>@5</code></a>.101.2</li>
</ul>
</li>
</ul>
<h2><code>@tanstack/react-query-persist-client</code><a
href="https://github.com/5 "><code>@5</code></a>.101.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies []:
<ul>
<li><code>@tanstack/query-persist-client-core</code><a
href="https://github.com/5 "><code>@5</code></a>.101.2</li>
<li><code>@tanstack/react-query</code><a
href="https://github.com/5 "><code>@5</code></a>.101.2</li>
</ul>
</li>
</ul>
<h2><code>@tanstack/react-query</code><a
href="https://github.com/5 "><code>@5</code></a>.101.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies []:
<ul>
<li><code>@tanstack/query-core</code><a
href="https://github.com/5 "><code>@5</code></a>.101.2</li>
</ul>
</li>
</ul>
<h2><code>@tanstack/react-query-devtools</code><a
href="https://github.com/5 "><code>@5</code></a>.101.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies []:
<ul>
<li><code>@tanstack/query-devtools</code><a
href="https://github.com/5 "><code>@5</code></a>.101.1</li>
<li><code>@tanstack/react-query</code><a
href="https://github.com/5 "><code>@5</code></a>.101.1</li>
</ul>
</li>
</ul>
<h2><code>@tanstack/react-query-next-experimental</code><a
href="https://github.com/5 "><code>@5</code></a>.101.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies []:
<ul>
<li><code>@tanstack/react-query</code><a
href="https://github.com/5 "><code>@5</code></a>.101.1</li>
</ul>
</li>
</ul>
<h2><code>@tanstack/react-query-persist-client</code><a
href="https://github.com/5 "><code>@5</code></a>.101.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies []:
<ul>
<li><code>@tanstack/query-persist-client-core</code><a
href="https://github.com/5 "><code>@5</code></a>.101.1</li>
<li><code>@tanstack/react-query</code><a
href="https://github.com/5 "><code>@5</code></a>.101.1</li>
</ul>
</li>
</ul>
<h2><code>@tanstack/react-query</code><a
href="https://github.com/5 "><code>@5</code></a>.101.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a
href="9eff92ed86 "><code>9eff92e</code></a>]:</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md ">@tanstack/react-query's
changelog</a>.</em></p>
<blockquote>
<h2>5.101.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies []:
<ul>
<li><code>@tanstack/query-core</code><a
href="https://github.com/5 "><code>@5</code></a>.101.2</li>
</ul>
</li>
</ul>
<h2>5.101.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a
href="9eff92ed86 "><code>9eff92e</code></a>]:
<ul>
<li><code>@tanstack/query-core</code><a
href="https://github.com/5 "><code>@5</code></a>.101.1</li>
</ul>
</li>
</ul>
<h2>5.101.0</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies []:
<ul>
<li><code>@tanstack/query-core</code><a
href="https://github.com/5 "><code>@5</code></a>.101.0</li>
</ul>
</li>
</ul>
<h2>5.100.14</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p>fix(react-query): do not go into optimistic fetching state when not
subscribed (<a
href="https://redirect.github.com/TanStack/query/pull/10759 ">#10759</a>)</p>
</li>
<li>
<p>Updated dependencies []:</p>
<ul>
<li><code>@tanstack/query-core</code><a
href="https://github.com/5 "><code>@5</code></a>.100.14</li>
</ul>
</li>
</ul>
<h2>5.100.13</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies [<a
href="d423168f62 "><code>d423168</code></a>]:
<ul>
<li><code>@tanstack/query-core</code><a
href="https://github.com/5 "><code>@5</code></a>.100.13</li>
</ul>
</li>
</ul>
<h2>5.100.12</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies []:
<ul>
<li><code>@tanstack/query-core</code><a
href="https://github.com/5 "><code>@5</code></a>.100.12</li>
</ul>
</li>
</ul>
<h2>5.100.11</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies []:
<ul>
<li><code>@tanstack/query-core</code><a
href="https://github.com/5 "><code>@5</code></a>.100.11</li>
</ul>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="610e8d1684 "><code>610e8d1</code></a>
ci: Version Packages (<a
href="https://github.com/TanStack/query/tree/HEAD/packages/react-query/issues/10996 ">#10996</a>)</li>
<li><a
href="1f84256a2e "><code>1f84256</code></a>
docs: document the <code>select</code> typing caveat for
parallel-queries hooks (<a
href="https://github.com/TanStack/query/tree/HEAD/packages/react-query/issues/10984 ">#10984</a>)</li>
<li><a
href="b80929716f "><code>b809297</code></a>
ci: Version Packages (<a
href="https://github.com/TanStack/query/tree/HEAD/packages/react-query/issues/10977 ">#10977</a>)</li>
<li><a
href="ccc843ea44 "><code>ccc843e</code></a>
test({react,preact}-query/useQueries): move type-only tests to
'useQueries.te...</li>
<li><a
href="415461346f "><code>4154613</code></a>
test({react,preact}-query/useMutation): split 'should handle conditional
logi...</li>
<li><a
href="8bb5fdea3e "><code>8bb5fde</code></a>
test({react,preact}-query/useMutation): split 'should pass meta to
mutation' ...</li>
<li><a
href="87426a3016 "><code>87426a3</code></a>
test(react-query): replace deprecated 'toBeCalledTimes' with
'toHaveBeenCalle...</li>
<li><a
href="feb1efd804 "><code>feb1efd</code></a>
test(*): move 'vi.useRealTimers' to the end of 'afterEach' so cleanup
runs un...</li>
<li><a
href="f3d8d2abbf "><code>f3d8d2a</code></a>
ci: Version Packages (<a
href="https://github.com/TanStack/query/tree/HEAD/packages/react-query/issues/10774 ">#10774</a>)</li>
<li><a
href="532bb298fb "><code>532bb29</code></a>
fix(tests): disable local coverage instrumentation (<a
href="https://github.com/TanStack/query/tree/HEAD/packages/react-query/issues/10776 ">#10776</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/TanStack/query/commits/@tanstack/react-query@5.101.2/packages/react-query ">compare
view</a></li>
</ul>
</details>
<br />
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-07 10:14:51 -07:00
dependabot[bot]
aac7e2ed15
build(deps): bump acpx from 0.11.2 to 0.12.0 ( #9062 )
...
Bumps [acpx](https://github.com/openclaw/acpx ) from 0.11.2 to 0.12.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/openclaw/acpx/releases ">acpx's
releases</a>.</em></p>
<blockquote>
<h2>acpx 0.12.0</h2>
<h2>v0.12.0</h2>
<h3>Changes</h3>
<ul>
<li>Agents/built-ins: add Grok Build via <code>grok agent stdio</code>,
including cached-login and <code>XAI_API_KEY</code> authentication
selection. Thanks <a
href="https://github.com/TheAngryPit "><code>@TheAngryPit</code></a>.
(<a
href="https://redirect.github.com/openclaw/acpx/pull/426 ">#426</a>)</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>CLI/queue: drain active turns before releasing queue-owner leases
and preserve typed retryable shutdown responses while terminating agent
bridges. Thanks <a
href="https://github.com/superWorldSavior "><code>@superWorldSavior</code></a>.
(<a
href="https://redirect.github.com/openclaw/acpx/pull/430 ">#430</a>)</li>
<li>CLI/quiet output: emit exactly one structured stderr diagnostic for
direct and queued prompt failures without adding diagnostics to stdout.
Thanks <a
href="https://github.com/superWorldSavior "><code>@superWorldSavior</code></a>.
(<a
href="https://redirect.github.com/openclaw/acpx/pull/431 ">#431</a>)</li>
</ul>
<h3>Verification</h3>
<ul>
<li>npm: <a
href="https://www.npmjs.com/package/acpx/v/0.12.0 ">https://www.npmjs.com/package/acpx/v/0.12.0 </a></li>
<li>Registry tarball: <a
href="https://registry.npmjs.org/acpx/-/acpx-0.12.0.tgz ">https://registry.npmjs.org/acpx/-/acpx-0.12.0.tgz </a></li>
<li>Integrity:
<code>sha512-APYpN04XFWrCGuSBvM4HTKWWFH8uSIuzc+qI7aCGeVdP9o4euZeBosFEkmNUHvBOop0XBemg6d8RsNvzXN3Mgw==</code></li>
<li>Candidate CI: <a
href="https://github.com/openclaw/acpx/actions/runs/28718352566 ">https://github.com/openclaw/acpx/actions/runs/28718352566 </a></li>
<li>Trusted publish: <a
href="https://github.com/openclaw/acpx/actions/runs/28718550655 ">https://github.com/openclaw/acpx/actions/runs/28718550655 </a></li>
<li>Full local tests, coverage, docs, conformance, mutation, security
audits, packed-install CLI smoke, runtime export smoke, lifecycle proof,
and fresh autoreview passed before tagging.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/openclaw/acpx/blob/main/CHANGELOG.md ">acpx's
changelog</a>.</em></p>
<blockquote>
<h2>2026.7.4 (v0.12.0)</h2>
<h3>Changes</h3>
<ul>
<li>Agents/built-ins: add Grok Build via <code>grok agent stdio</code>,
including cached-login and <code>XAI_API_KEY</code> authentication
selection. Thanks <a
href="https://github.com/TheAngryPit "><code>@TheAngryPit</code></a>.</li>
</ul>
<h3>Breaking</h3>
<h3>Fixes</h3>
<ul>
<li>
<p>CLI/queue: drain active turns before releasing queue-owner leases and
preserve typed retryable shutdown responses while terminating agent
bridges. Thanks <a
href="https://github.com/superWorldSavior "><code>@superWorldSavior</code></a>.</p>
</li>
<li>
<p>CLI/quiet output: emit exactly one structured stderr diagnostic for
direct and queued prompt failures without adding diagnostics to stdout.
Thanks <a
href="https://github.com/superWorldSavior "><code>@superWorldSavior</code></a>.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="6a24a546d2 "><code>6a24a54</code></a>
chore(release): prepare acpx 0.12.0</li>
<li><a
href="ffd8549355 "><code>ffd8549</code></a>
fix: surface quiet-mode failures on stderr (<a
href="https://redirect.github.com/openclaw/acpx/issues/431 ">#431</a>)</li>
<li><a
href="87327c6e4a "><code>87327c6</code></a>
fix: make queue owner shutdown lossless (<a
href="https://redirect.github.com/openclaw/acpx/issues/430 ">#430</a>)</li>
<li><a
href="7d05c37b47 "><code>7d05c37</code></a>
feat: add Grok Build ACP agent (<a
href="https://redirect.github.com/openclaw/acpx/issues/426 ">#426</a>)</li>
<li><a
href="95d75cd000 "><code>95d75cd</code></a>
chore(deps): bump tsx to 4.23.0 (<a
href="https://redirect.github.com/openclaw/acpx/issues/429 ">#429</a>)</li>
<li><a
href="bce1c96d9d "><code>bce1c96</code></a>
chore(deps-dev): update development toolchain (<a
href="https://redirect.github.com/openclaw/acpx/issues/428 ">#428</a>)</li>
<li><a
href="8a643e725a "><code>8a643e7</code></a>
chore(deps-dev): refresh TypeScript native preview (<a
href="https://redirect.github.com/openclaw/acpx/issues/427 ">#427</a>)</li>
<li><a
href="a18bf74c4b "><code>a18bf74</code></a>
chore(deps): bump <code>@agentclientprotocol/sdk</code> from 0.28.1 to
1.1.0 (<a
href="https://redirect.github.com/openclaw/acpx/issues/421 ">#421</a>)</li>
<li><a
href="1d882575e3 "><code>1d88257</code></a>
chore(deps-dev): bump the development group with 7 updates</li>
<li><a
href="c2689c025f "><code>c2689c0</code></a>
chore(deps-dev): bump <code>@types/node</code> from 25.9.3 to
26.0.1</li>
<li>Additional commits viewable in <a
href="https://github.com/openclaw/acpx/compare/v0.11.2...v0.12.0 ">compare
view</a></li>
</ul>
</details>
<br />
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-07 10:05:10 -07:00
dependabot[bot]
077ba611fa
build(deps-dev): bump @types/multer from 2.1.0 to 2.2.0 ( #9065 )
...
Bumps
[@types/multer](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/multer )
from 2.1.0 to 2.2.0.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/multer ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-07 10:03:47 -07:00
dependabot[bot]
faaa9b22e5
build(deps-dev): bump storybook from 10.4.2 to 10.4.6 ( #9063 )
...
Bumps
[storybook](https://github.com/storybookjs/storybook/tree/HEAD/code/core )
from 10.4.2 to 10.4.6.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/releases ">storybook's
releases</a>.</em></p>
<blockquote>
<h2>v10.4.6</h2>
<h2>10.4.6</h2>
<ul>
<li>CSF: Allow partial globals overrides in story and meta annotations -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/34985 ">#34985</a>,
thanks <a
href="https://github.com/TheSeydiCharyyev "><code>@TheSeydiCharyyev</code></a>!</li>
<li>Dependencies: Upgrade esbuild - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35157 ">#35157</a>,
thanks <a
href="https://github.com/Kakadus "><code>@Kakadus</code></a>!</li>
</ul>
<h2>v10.4.5</h2>
<h2>10.4.5</h2>
<ul>
<li>Core: Rework AI checklist feature gate - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35053 ">#35053</a>,
thanks <a
href="https://github.com/Sidnioulz "><code>@Sidnioulz</code></a>!</li>
<li>Preview: Stop mixed CSF3+4 stories getting core annotations injected
twice - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35094 ">#35094</a>,
thanks <a
href="https://github.com/JReinhold "><code>@JReinhold</code></a>!</li>
</ul>
<h2>v10.4.4</h2>
<h2>10.4.4</h2>
<ul>
<li>Telemetry: Add timeout to event-log POST to prevent build hang - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35085 ">#35085</a>,
thanks <a
href="https://github.com/badams "><code>@badams</code></a>!</li>
</ul>
<h2>v10.4.3</h2>
<h2>10.4.3</h2>
<ul>
<li>Addon Docs: Fix Primary and Controls blocks not rendering in custom
MDX pages - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34496 ">#34496</a>,
thanks <a
href="https://github.com/NYCU-Chung "><code>@NYCU-Chung</code></a>!</li>
<li>Core: Respect !dev tag on MDX docs in sidebar - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35031 ">#35031</a>,
thanks <a
href="https://github.com/JReinhold "><code>@JReinhold</code></a>!</li>
<li>React: Add support for resolving subcomponents attached as
properties of a parent component - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34967 ">#34967</a>,
thanks <a
href="https://github.com/yatishgoel "><code>@yatishgoel</code></a>!</li>
<li>UI: Prevent docs page scroll reset on HMR re-render - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35021 ">#35021</a>,
thanks <a
href="https://github.com/LongTangGithub "><code>@LongTangGithub</code></a>!</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md ">storybook's
changelog</a>.</em></p>
<blockquote>
<h2>10.4.6</h2>
<ul>
<li>CSF: Allow partial globals overrides in story and meta annotations -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/34985 ">#34985</a>,
thanks <a
href="https://github.com/TheSeydiCharyyev "><code>@TheSeydiCharyyev</code></a>!</li>
<li>Dependencies: Upgrade esbuild - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35157 ">#35157</a>,
thanks <a
href="https://github.com/Kakadus "><code>@Kakadus</code></a>!</li>
</ul>
<h2>10.4.5</h2>
<ul>
<li>Core: Rework AI checklist feature gate - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35053 ">#35053</a>,
thanks <a
href="https://github.com/Sidnioulz "><code>@Sidnioulz</code></a>!</li>
<li>Preview: Stop mixed CSF3+4 stories getting core annotations injected
twice - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35094 ">#35094</a>,
thanks <a
href="https://github.com/JReinhold "><code>@JReinhold</code></a>!</li>
</ul>
<h2>10.4.4</h2>
<ul>
<li>Telemetry: Add timeout to event-log POST to prevent build hang - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35085 ">#35085</a>,
thanks <a
href="https://github.com/badams "><code>@badams</code></a>!</li>
</ul>
<h2>10.4.3</h2>
<ul>
<li>Addon Docs: Fix Primary and Controls blocks not rendering in custom
MDX pages - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34496 ">#34496</a>,
thanks <a
href="https://github.com/NYCU-Chung "><code>@NYCU-Chung</code></a>!</li>
<li>Core: Respect !dev tag on MDX docs in sidebar - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35031 ">#35031</a>,
thanks <a
href="https://github.com/JReinhold "><code>@JReinhold</code></a>!</li>
<li>React: Add support for resolving subcomponents attached as
properties of a parent component - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34967 ">#34967</a>,
thanks <a
href="https://github.com/yatishgoel "><code>@yatishgoel</code></a>!</li>
<li>UI: Prevent docs page scroll reset on HMR re-render - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35021 ">#35021</a>,
thanks <a
href="https://github.com/LongTangGithub "><code>@LongTangGithub</code></a>!</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="5496a4270d "><code>5496a42</code></a>
Bump version from "10.4.5" to "10.4.6" [skip
ci]</li>
<li><a
href="a80a5afddd "><code>a80a5af</code></a>
Merge pull request <a
href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/34985 ">#34985</a>
from TheSeydiCharyyev/fix/issue-34951-partial-globals</li>
<li><a
href="5b929cadfb "><code>5b929ca</code></a>
Merge pull request <a
href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/35157 ">#35157</a>
from Kakadus/update-esbuild</li>
<li><a
href="48e7b20074 "><code>48e7b20</code></a>
Bump version from "10.4.4" to "10.4.5" [skip
ci]</li>
<li><a
href="730f744aa6 "><code>730f744</code></a>
Merge pull request <a
href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/35094 ">#35094</a>
from storybookjs/jeppe-cursor/a236965c</li>
<li><a
href="dc88f70020 "><code>dc88f70</code></a>
Merge pull request <a
href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/35053 ">#35053</a>
from storybookjs/sidnioulz/double-gate-ai-optin</li>
<li><a
href="5adebe753f "><code>5adebe7</code></a>
Bump version from "10.4.3" to "10.4.4" [skip
ci]</li>
<li><a
href="ce1491d9e4 "><code>ce1491d</code></a>
Merge pull request <a
href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/35085 ">#35085</a>
from badams/fix/telemetry-fetch-timeout</li>
<li><a
href="624e6187fd "><code>624e618</code></a>
Bump version from "10.4.2" to "10.4.3" [skip
ci]</li>
<li><a
href="c898822822 "><code>c898822</code></a>
Merge pull request <a
href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/34496 ">#34496</a>
from NYCU-Chung/fix/docs-blocks-custom-mdx</li>
<li>Additional commits viewable in <a
href="https://github.com/storybookjs/storybook/commits/v10.4.6/code/core ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-07 10:02:51 -07:00
dependabot[bot]
f10464fee4
build(deps): bump @radix-ui/react-slot from 1.2.4 to 1.3.0 ( #9066 )
...
Bumps
[@radix-ui/react-slot](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/slot )
from 1.2.4 to 1.3.0.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/radix-ui/primitives/blob/main/packages/react/slot/CHANGELOG.md ">@radix-ui/react-slot's
changelog</a>.</em></p>
<blockquote>
<h2>1.3.0</h2>
<h3>Added generic type arguments for <code>SlotProps</code> and
<code>createSlot</code></h3>
<p><code>SlotProps</code> and <code>createSlot</code> now accept generic
type arguments to specify the type of element a slot should render, as
well as its props.</p>
<pre lang="tsx"><code>const Slot = createSlot<HTMLButtonElement,
MyCustomButtonProps>('Slot');
</code></pre>
<h2>1.2.5</h2>
<ul>
<li>Fixed infinite re-render loop in React 19 caused by
<code>Slot</code> creating a new ref callback on every render</li>
<li>Added support for nested <code>Slottable</code> via a render prop,
so a slotted element can be wrapped while still merging Slot props and
refs onto it</li>
<li>Added repository.directory to all package.json files</li>
<li>Improved error messages for invalid slot children</li>
<li>Updated dependencies:
<code>@radix-ui/react-compose-refs@1.1.3</code></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/radix-ui/primitives/commits/HEAD/packages/react/slot ">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions ">GitHub Actions</a>, a new
releaser for <code>@radix-ui/react-slot</code> since your current
version.</p>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-07 10:02:47 -07:00
dependabot[bot]
773bf45720
build(deps): bump @zed-industries/codex-acp from 0.12.0 to 0.16.0 ( #9068 )
...
Bumps
[@zed-industries/codex-acp](https://github.com/zed-industries/codex-acp )
from 0.12.0 to 0.16.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/zed-industries/codex-acp/releases ">@zed-industries/codex-acp's
releases</a>.</em></p>
<blockquote>
<h2>Release 0.16.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Update Codex dependencies to rust-v0.137.0 by <a
href="https://github.com/benbrandt "><code>@benbrandt</code></a> in <a
href="https://redirect.github.com/zed-industries/codex-acp/pull/320 ">zed-industries/codex-acp#320</a></li>
<li>Use thread store for session listing by <a
href="https://github.com/benbrandt "><code>@benbrandt</code></a> in <a
href="https://redirect.github.com/zed-industries/codex-acp/pull/321 ">zed-industries/codex-acp#321</a></li>
<li>chore(acp): Update to ACP 0.14.0 by <a
href="https://github.com/mrjones2014 "><code>@mrjones2014</code></a> in
<a
href="https://redirect.github.com/zed-industries/codex-acp/pull/317 ">zed-industries/codex-acp#317</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/mrjones2014 "><code>@mrjones2014</code></a>
made their first contribution in <a
href="https://redirect.github.com/zed-industries/codex-acp/pull/317 ">zed-industries/codex-acp#317</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/zed-industries/codex-acp/compare/v0.15.0...v0.16.0 ">https://github.com/zed-industries/codex-acp/compare/v0.15.0...v0.16.0 </a></p>
<h2>Release 0.15.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Update Codex to 0.133.0 by <a
href="https://github.com/benbrandt "><code>@benbrandt</code></a> in <a
href="https://redirect.github.com/zed-industries/codex-acp/pull/303 ">zed-industries/codex-acp#303</a></li>
<li>Stop output buffer resend in terminal_interaction stdin path by <a
href="https://github.com/frozename "><code>@frozename</code></a> in <a
href="https://redirect.github.com/zed-industries/codex-acp/pull/270 ">zed-industries/codex-acp#270</a></li>
<li>fix: Detach pending permission request tasks on cancel by <a
href="https://github.com/benbrandt "><code>@benbrandt</code></a> in <a
href="https://redirect.github.com/zed-industries/codex-acp/pull/304 ">zed-industries/codex-acp#304</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/zed-industries/codex-acp/compare/v0.14.0...v0.15.0 ">https://github.com/zed-industries/codex-acp/compare/v0.14.0...v0.15.0 </a></p>
<h2>Release 0.14.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Bump openssl from 0.10.78 to 0.10.79 in the cargo group across 1
directory by <a
href="https://github.com/dependabot "><code>@dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/zed-industries/codex-acp/pull/265 ">zed-industries/codex-acp#265</a></li>
<li>Update to codex 0.129 by <a
href="https://github.com/benbrandt "><code>@benbrandt</code></a> in <a
href="https://redirect.github.com/zed-industries/codex-acp/pull/268 ">zed-industries/codex-acp#268</a></li>
<li>Fix O(N²) memory growth in exec_command_output_delta fallback by <a
href="https://github.com/frozename "><code>@frozename</code></a> in <a
href="https://redirect.github.com/zed-industries/codex-acp/pull/269 ">zed-industries/codex-acp#269</a></li>
<li>Emit image generation tool calls by <a
href="https://github.com/benbrandt "><code>@benbrandt</code></a> in <a
href="https://redirect.github.com/zed-industries/codex-acp/pull/271 ">zed-industries/codex-acp#271</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/frozename "><code>@frozename</code></a>
made their first contribution in <a
href="https://redirect.github.com/zed-industries/codex-acp/pull/269 ">zed-industries/codex-acp#269</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/zed-industries/codex-acp/compare/v0.13.0...v0.14.0 ">https://github.com/zed-industries/codex-acp/compare/v0.13.0...v0.14.0 </a></p>
<h2>Release 0.13.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Upgrade to codex 0.128.0 by <a
href="https://github.com/benbrandt "><code>@benbrandt</code></a> in <a
href="https://redirect.github.com/zed-industries/codex-acp/pull/261 ">zed-industries/codex-acp#261</a></li>
<li>Reload auth file before failing check_auth() by <a
href="https://github.com/anvilpete "><code>@anvilpete</code></a> in <a
href="https://redirect.github.com/zed-industries/codex-acp/pull/259 ">zed-industries/codex-acp#259</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/anvilpete "><code>@anvilpete</code></a>
made their first contribution in <a
href="https://redirect.github.com/zed-industries/codex-acp/pull/259 ">zed-industries/codex-acp#259</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/zed-industries/codex-acp/compare/v0.12.0...v0.13.0 ">https://github.com/zed-industries/codex-acp/compare/v0.12.0...v0.13.0 </a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="bb590500e8 "><code>bb59050</code></a>
Bump version to 0.16.0</li>
<li><a
href="c81fa46d89 "><code>c81fa46</code></a>
chore(acp): Update to ACP 0.14.0 (<a
href="https://redirect.github.com/zed-industries/codex-acp/issues/317 ">#317</a>)</li>
<li><a
href="4a853a1cf6 "><code>4a853a1</code></a>
Use thread store for session listing (<a
href="https://redirect.github.com/zed-industries/codex-acp/issues/321 ">#321</a>)</li>
<li><a
href="9841e8b5a8 "><code>9841e8b</code></a>
Update Codex dependencies to rust-v0.137.0 (<a
href="https://redirect.github.com/zed-industries/codex-acp/issues/320 ">#320</a>)</li>
<li><a
href="863d433fc9 "><code>863d433</code></a>
v0.15.0</li>
<li><a
href="f67ca5f35f "><code>f67ca5f</code></a>
fix: Detach pending permission request tasks on cancel (<a
href="https://redirect.github.com/zed-industries/codex-acp/issues/304 ">#304</a>)</li>
<li><a
href="8aef91bc08 "><code>8aef91b</code></a>
Stop output buffer resend in terminal_interaction stdin path (<a
href="https://redirect.github.com/zed-industries/codex-acp/issues/270 ">#270</a>)</li>
<li><a
href="0c2d8280f2 "><code>0c2d828</code></a>
Update README.md</li>
<li><a
href="d9bf1c1579 "><code>d9bf1c1</code></a>
Update Codex to 0.133.0 (<a
href="https://redirect.github.com/zed-industries/codex-acp/issues/303 ">#303</a>)</li>
<li><a
href="156cb0da12 "><code>156cb0d</code></a>
Emit image generation tool calls (<a
href="https://redirect.github.com/zed-industries/codex-acp/issues/271 ">#271</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/zed-industries/codex-acp/compare/v0.12.0...v0.16.0 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-07 10:02:43 -07:00
github-actions[bot]
f95efe6292
chore(lockfile): refresh pnpm-lock.yaml ( #8957 )
...
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
2026-07-03 18:55:34 -07:00
dependabot[bot]
5bd6c6ec3c
build(deps): bump acpx from 0.6.1 to 0.11.2 ( #8741 )
...
Bumps [acpx](https://github.com/openclaw/acpx ) from 0.6.1 to 0.11.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/openclaw/acpx/releases ">acpx's
releases</a>.</em></p>
<blockquote>
<h2>acpx 0.11.0</h2>
<h2>v0.11.0</h2>
<h3>Changes</h3>
<ul>
<li>Agents/built-ins: bump the default Claude ACP adapter range to
<code>@agentclientprotocol/claude-agent-acp@^0.37.0</code>. Thanks <a
href="https://github.com/trumpyla "><code>@trumpyla</code></a>.</li>
<li>Runtime/embedding: surface cost, token usage breakdowns, and
advertised command metadata on runtime status/events. Thanks <a
href="https://github.com/DaniAkash "><code>@DaniAkash</code></a>.</li>
<li>Agents/built-ins: add <code>fast-agent</code> as a built-in
fast-agent ACP adapter via <code>uvx fast-agent-mcp acp</code>.</li>
<li>Agents/built-ins: add <code>mux</code> as a built-in coder/mux ACP
adapter via <code>npx -y mux@^0.27.0 acp</code>. Thanks <a
href="https://github.com/ThomasK33 "><code>@ThomasK33</code></a>.</li>
<li>CLI: add <code>acpx compare</code> to run one prompt across multiple
agents and summarize timing, token usage, stop reason, permissions, and
final output side by side. Thanks <a
href="https://github.com/mvanhorn "><code>@mvanhorn</code></a>.</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>CLI/Claude: isolate built-in Claude ACP sessions from user settings
by default so globally enabled channel and daemon plugins cannot
interfere with a spawned session. Set
<code>ACPX_CLAUDE_INCLUDE_USER_SETTINGS=1</code> to restore user
settings deliberately. Fixes <a
href="https://redirect.github.com/openclaw/acpx/issues/361 ">#361</a>.</li>
<li>ACP/models: support SDK 0.25 model config options while preserving
<code>session/set_model</code> compatibility for adapters that
explicitly advertise legacy model metadata.</li>
<li>CLI/Claude: let Claude Code adjudicate model selectors missing from
a stale advertised model list on later persistent turns, and preserve
the adapter-reported current model after model switches. Thanks <a
href="https://github.com/oakif "><code>@oakif</code></a>.</li>
<li>Client/ACP: advertise scoped Devin/Windsurf-compatible client
metadata and handle Devin extension requests/notifications without noisy
method-not-found logs. Thanks <a
href="https://github.com/LivioGama "><code>@LivioGama</code></a>.</li>
<li>Runtime/sessions: treat corrupt public file-session records as
missing while preserving genuine filesystem errors. Thanks <a
href="https://github.com/KrasimirKralev "><code>@KrasimirKralev</code></a>.</li>
</ul>
<h3>Verification</h3>
<ul>
<li>npm: <a
href="https://www.npmjs.com/package/acpx/v/0.11.0 ">https://www.npmjs.com/package/acpx/v/0.11.0 </a></li>
<li>Registry tarball: <a
href="https://registry.npmjs.org/acpx/-/acpx-0.11.0.tgz ">https://registry.npmjs.org/acpx/-/acpx-0.11.0.tgz </a></li>
<li>Integrity:
<code>sha512-l42LJFmd6kvbr1UytvwWmr5Mdy/v9l3FM6Necs01PWbjUIkxjCdxg97duqoRfRqxtDAfnNPb1IlgIf2ZgMZQqA==</code></li>
<li>Candidate CI: <a
href="https://github.com/openclaw/acpx/actions/runs/27676359224 ">https://github.com/openclaw/acpx/actions/runs/27676359224 </a></li>
<li>Trusted publish: <a
href="https://github.com/openclaw/acpx/actions/runs/27676823793 ">https://github.com/openclaw/acpx/actions/runs/27676823793 </a></li>
<li>Packed CLI and real Codex ACP adapter E2E passed before
tagging.</li>
</ul>
<h2>2026.5.23 (v0.10.0)</h2>
<h3>Changes</h3>
<ul>
<li>CLI/sessions: add <code>sessions export</code> and <code>sessions
import</code> for moving portable session archives between machines.
Thanks <a
href="https://github.com/mvanhorn "><code>@mvanhorn</code></a>.</li>
</ul>
<h3>Release Proof</h3>
<ul>
<li>npm: <a
href="https://www.npmjs.com/package/acpx/v/0.10.0 ">https://www.npmjs.com/package/acpx/v/0.10.0 </a></li>
<li>registry tarball: <a
href="https://registry.npmjs.org/acpx/-/acpx-0.10.0.tgz ">https://registry.npmjs.org/acpx/-/acpx-0.10.0.tgz </a></li>
<li>integrity:
<code>sha512-hd48XV03gG3sd409T1lDrOKJTTz1ap4g0wrndXjxQ590tN85pBYlvfNLyerybvGRrtUGsZjNdt99r1jpIt6ukA==</code></li>
<li>release workflow: <a
href="https://github.com/openclaw/acpx/actions/runs/26323055145 ">https://github.com/openclaw/acpx/actions/runs/26323055145 </a></li>
<li>CI: <a
href="https://github.com/openclaw/acpx/actions/runs/26323053524 ">https://github.com/openclaw/acpx/actions/runs/26323053524 </a></li>
</ul>
<h2>2026.5.22 (v0.9.0)</h2>
<h3>Changes</h3>
<ul>
<li>Tooling: add Slophammer TypeScript quality gates for coverage,
complexity,
unsafe types, mutation testing, DRY checks, and dependency
boundaries.</li>
<li>Agents/built-ins: switch the default Codex adapter to
<code>@agentclientprotocol/codex-acp</code>, with Codex model selection
handled through advertised ACP model ids, and bump the default Claude
ACP adapter range.</li>
<li>Tooling: add a repo-local autoreview skill and helper for
Codex-first</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/openclaw/acpx/blob/main/CHANGELOG.md ">acpx's
changelog</a>.</em></p>
<blockquote>
<h2>2026.6.23 (v0.11.2)</h2>
<h3>Changes</h3>
<h3>Breaking</h3>
<h3>Fixes</h3>
<ul>
<li>Runtime/status: persist token usage reported on successful prompt
responses,
including adapters that only provide a sparse
<code>usage_update</code>.</li>
</ul>
<h2>Unreleased</h2>
<h3>Changes</h3>
<h3>Breaking</h3>
<h3>Fixes</h3>
<h2>2026.6.23 (v0.11.1)</h2>
<h3>Changes</h3>
<ul>
<li>Runtime/embedding: preserve per-agent environment variables across
ACP session
creation, queue handoff, persistence, and reconnects. Thanks <a
href="https://github.com/zhangguiping-xydt "><code>@zhangguiping-xydt</code></a>.</li>
</ul>
<h3>Breaking</h3>
<h3>Fixes</h3>
<ul>
<li>CLI/queue: harden command parsing, queue-owner startup, stale
process cleanup,
and release/CI checks found by <code>clawpatch</code>.</li>
<li>Windows/Claude: only export a native <code>.exe</code> as
<code>CLAUDE_CODE_EXECUTABLE</code>;
unresolved <code>.cmd</code>, <code>.bat</code>, and <code>.ps1</code>
shims now fall back to the Claude ACP
adapter's bundled native binary. Fixes <a
href="https://redirect.github.com/openclaw/openclaw/issues/93465 ">openclaw/openclaw#93465</a>.</li>
<li>Client/ACP: ignore non-object JSON lines from adapter stdout before
ACP
dispatch, preventing primitive frames from crashing the SDK message
path.</li>
<li>ACP/models: call the current SDK <code>session/set_model</code>
method for legacy model
metadata instead of the generic extension fallback.</li>
<li>CLI/config: add <code>--mcp-config</code> for session-scoped MCP
servers without writing
a project config file. Live persistent sessions reject MCP config
changes until
closed. Fixes <a
href="https://redirect.github.com/openclaw/acpx/issues/387 ">#387</a>.</li>
</ul>
<h2>2026.6.17 (v0.11.0)</h2>
<h3>Changes</h3>
<ul>
<li>Agents/built-ins: bump the default Claude ACP adapter range to
<code>@agentclientprotocol/claude-agent-acp@^0.37.0</code>. Thanks <a
href="https://github.com/trumpyla "><code>@trumpyla</code></a>.</li>
<li>Runtime/embedding: surface cost, token usage breakdowns, and
advertised command metadata on runtime status/events. Thanks <a
href="https://github.com/DaniAkash "><code>@DaniAkash</code></a>.</li>
<li>Agents/built-ins: add <code>fast-agent</code> as a built-in
fast-agent ACP adapter via <code>uvx fast-agent-mcp acp</code>.</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/openclaw/acpx/commits/v0.11.2 ">compare
view</a></li>
</ul>
</details>
<br />
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 10:11:40 -07:00
dependabot[bot]
c06e2be21a
build(deps): bump @tailwindcss/typography from 0.5.19 to 0.5.20 ( #8738 )
...
Bumps
[@tailwindcss/typography](https://github.com/tailwindlabs/tailwindcss-typography )
from 0.5.19 to 0.5.20.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/tailwindlabs/tailwindcss-typography/releases ">@tailwindcss/typography's
releases</a>.</em></p>
<blockquote>
<h2>v0.5.20</h2>
<h3>Fixed</h3>
<ul>
<li>Support installing with stable versions of Tailwind CSS v4 (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/424 ">#424</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/tailwindlabs/tailwindcss-typography/blob/main/CHANGELOG.md ">@tailwindcss/typography's
changelog</a>.</em></p>
<blockquote>
<h2>[0.5.20] - 2026-06-08</h2>
<h3>Fixed</h3>
<ul>
<li>Support installing with stable versions of Tailwind CSS v4 (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss-typography/pull/424 ">#424</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="e3714a3fe5 "><code>e3714a3</code></a>
0.5.20</li>
<li><a
href="f34283d296 "><code>f34283d</code></a>
Update tailwindcss peer dependency version (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/424 ">#424</a>)</li>
<li><a
href="543de42743 "><code>543de42</code></a>
bump Node.js</li>
<li><a
href="881b0488df "><code>881b048</code></a>
Setup OIDC (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/423 ">#423</a>)</li>
<li><a
href="74a3da779b "><code>74a3da7</code></a>
Fix typo in README.md (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/413 ">#413</a>)</li>
<li><a
href="3963dfede4 "><code>3963dfe</code></a>
Bump js-yaml from 3.14.1 to 3.14.2 (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/410 ">#410</a>)</li>
<li><a
href="abf85cc6e1 "><code>abf85cc</code></a>
className instead of classname (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss-typography/issues/406 ">#406</a>)</li>
<li>See full diff in <a
href="https://github.com/tailwindlabs/tailwindcss-typography/compare/v0.5.19...v0.5.20 ">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions ">GitHub Actions</a>, a new
releaser for <code>@tailwindcss/typography</code> since your current
version.</p>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 10:05:08 -07:00
dependabot[bot]
8f3fa07d59
build(deps): bump @pierre/diffs from 1.1.22 to 1.2.11 ( #8744 )
...
Bumps @pierre/diffs from 1.1.22 to 1.2.11.
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 10:04:31 -07:00
dependabot[bot]
b755ab55fd
build(deps): bump multer from 2.1.1 to 2.2.0 ( #8743 )
...
Bumps [multer](https://github.com/expressjs/multer ) from 2.1.1 to 2.2.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/expressjs/multer/releases ">multer's
releases</a>.</em></p>
<blockquote>
<h2>v2.2.0</h2>
<h2>Important</h2>
<ul>
<li>Fix <a
href="https://www.cve.org/CVERecord?id=CVE-2026-5038 ">CVE-2026-5038</a>
(<a
href="https://github.com/expressjs/multer/security/advisories/GHSA-3p4h-7m6x-2hcm ">GHSA-3p4h-7m6x-2hcm</a>)</li>
<li>Fix <a
href="https://www.cve.org/CVERecord?id=CVE-2026-5079 ">CVE-2026-5079</a>
(<a
href="https://github.com/expressjs/multer/security/advisories/GHSA-72gw-mp4g-v24j ">GHSA-72gw-mp4g-v24j</a>)</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>chore(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 by <a
href="https://github.com/dependabot "><code>@dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/multer/pull/1397 ">expressjs/multer#1397</a></li>
<li>chore(deps): bump github/codeql-action from 4.32.4 to 4.36.1 by <a
href="https://github.com/dependabot "><code>@dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/multer/pull/1409 ">expressjs/multer#1409</a></li>
<li>chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 by <a
href="https://github.com/dependabot "><code>@dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/expressjs/multer/pull/1410 ">expressjs/multer#1410</a></li>
<li>ci: add Node 26 to test matrix by <a
href="https://github.com/gameroman "><code>@gameroman</code></a> in <a
href="https://redirect.github.com/expressjs/multer/pull/1404 ">expressjs/multer#1404</a></li>
<li>Release: 2.2.0 by <a
href="https://github.com/UlisesGascon "><code>@UlisesGascon</code></a>
in <a
href="https://redirect.github.com/expressjs/multer/pull/1412 ">expressjs/multer#1412</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/gameroman "><code>@gameroman</code></a>
made their first contribution in <a
href="https://redirect.github.com/expressjs/multer/pull/1404 ">expressjs/multer#1404</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/expressjs/multer/compare/v2.1.1...v2.2.0 ">https://github.com/expressjs/multer/compare/v2.1.1...v2.2.0 </a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/expressjs/multer/blob/main/CHANGELOG.md ">multer's
changelog</a>.</em></p>
<blockquote>
<h2>2.2.0</h2>
<ul>
<li>Fix <a
href="https://www.cve.org/CVERecord?id=CVE-2026-5038 ">CVE-2026-5038</a>
(<a
href="https://github.com/expressjs/multer/security/advisories/GHSA-3p4h-7m6x-2hcm ">GHSA-3p4h-7m6x-2hcm</a>)</li>
<li>Fix <a
href="https://www.cve.org/CVERecord?id=CVE-2026-5079 ">CVE-2026-5079</a>
(<a
href="https://github.com/expressjs/multer/security/advisories/GHSA-72gw-mp4g-v24j ">GHSA-72gw-mp4g-v24j</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="2e2af08157 "><code>2e2af08</code></a>
2.2.0 (<a
href="https://redirect.github.com/expressjs/multer/issues/1412 ">#1412</a>)</li>
<li><a
href="a192b5278f "><code>a192b52</code></a>
feat: add fieldNestingDepth limit option</li>
<li><a
href="9c801c7136 "><code>9c801c7</code></a>
fix: clean up in-progress disk writes on abort</li>
<li><a
href="0adb21d029 "><code>0adb21d</code></a>
ci: add Node 26 to test matrix (<a
href="https://redirect.github.com/expressjs/multer/issues/1404 ">#1404</a>)</li>
<li><a
href="f5e17c39c8 "><code>f5e17c3</code></a>
chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 (<a
href="https://redirect.github.com/expressjs/multer/issues/1410 ">#1410</a>)</li>
<li><a
href="de1fefd9d2 "><code>de1fefd</code></a>
chore(deps): bump github/codeql-action from 4.32.4 to 4.36.1 (<a
href="https://redirect.github.com/expressjs/multer/issues/1409 ">#1409</a>)</li>
<li><a
href="67abfc89f4 "><code>67abfc8</code></a>
chore(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (<a
href="https://redirect.github.com/expressjs/multer/issues/1397 ">#1397</a>)</li>
<li>See full diff in <a
href="https://github.com/expressjs/multer/compare/v2.1.1...v2.2.0 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 10:04:26 -07:00
dependabot[bot]
c5a47c1fd9
build(deps): bump mermaid from 11.12.3 to 11.16.0 ( #8740 )
...
Bumps [mermaid](https://github.com/mermaid-js/mermaid ) from 11.12.3 to
11.16.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/mermaid-js/mermaid/releases ">mermaid's
releases</a>.</em></p>
<blockquote>
<h2>mermaid@11.16.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7535 ">#7535</a>
<a
href="ea1c48f53f "><code>ea1c48f</code></a>
Thanks <a
href="https://github.com/ragelink "><code>@ragelink</code></a>! -
feat(cynefin): Adds the Cynefin framework as a new diagram type (beta)
to Mermaid (available as <code>cynefin-beta</code>). The Cynefin
framework, created by Dave Snowden, is a decision-making framework that
categorizes problems into five complexity domains, widely used in agile,
incident management, strategy, and organizational design.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7721 ">#7721</a>
<a
href="f45cc2cc56 "><code>f45cc2c</code></a>
Thanks <a
href="https://github.com/notionparallax "><code>@notionparallax</code></a>!
- feat(treeView): add box-drawing character input support for treeView
diagrams</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7550 ">#7550</a>
<a
href="f1f4d45ee0 "><code>f1f4d45</code></a>
Thanks <a
href="https://github.com/DominicBurkart "><code>@DominicBurkart</code></a>!
- feat(xychart): add per-point text labels for xychart line plots</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7527 ">#7527</a>
<a
href="b4d0442dd1 "><code>b4d0442</code></a>
Thanks <a
href="https://github.com/notionparallax "><code>@notionparallax</code></a>!
- feat(treeView): Extends the existing treeView-beta diagram with
features useful for representing file/directory structures.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7793 ">#7793</a>
<a
href="a6f097d580 "><code>a6f097d</code></a>
Thanks <a href="https://github.com/SSDWGG "><code>@SSDWGG</code></a>! -
feat(er): support optional ER attribute types with a <code>?</code>
suffix</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7772 ">#7772</a>
<a
href="37f2e36fa0 "><code>37f2e36</code></a>
Thanks <a
href="https://github.com/devareddy05 "><code>@devareddy05</code></a>! -
feat(gantt): support multiple <code>excludes</code> /
<code>includes</code> lines so long exclusion lists can be split into
commented groups (<a
href="https://redirect.github.com/mermaid-js/mermaid/issues/6270 ">#6270</a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7708 ">#7708</a>
<a
href="4e63e9d338 "><code>4e63e9d</code></a>
Thanks <a href="https://github.com/txmxthy "><code>@txmxthy</code></a>!
- feat(architecture): add <code>align row|column {ids…}</code> directive
to architecture-beta diagrams so authors can declare horizontal or
vertical alignment of services explicitly.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7760 ">#7760</a>
<a
href="05223bee47 "><code>05223be</code></a>
Thanks <a
href="https://github.com/ngdaniels "><code>@ngdaniels</code></a>! -
feat(pie): Enhance Pie Chart - Enable donut chart, Set legend position,
and highlight slice</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7251 ">#7251</a>
<a
href="216e4e9a61 "><code>216e4e9</code></a>
Thanks <a href="https://github.com/ydah "><code>@ydah</code></a>! -
feat(railroad): Add support for Railroad Diagrams (Syntax Diagrams) with
four input syntaxes: IR (railroad-beta), EBNF (railroad-ebnf-beta), ABNF
(railroad-abnf-beta), and PEG (railroad-peg-beta).</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7774 ">#7774</a>
<a
href="e5c75e6b79 "><code>e5c75e6</code></a>
Thanks <a
href="https://github.com/ngdaniels "><code>@ngdaniels</code></a>! -
feat(xychart): enable rotate label on X-axis</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7791 ">#7791</a>
<a
href="974fa7b7e7 "><code>974fa7b</code></a>
Thanks <a
href="https://github.com/knsv-bot "><code>@knsv-bot</code></a>! -
feat(swimlane): add swimlane as a standalone diagram type with a
dedicated layered orthogonal layout algorithm</p>
</li>
</ul>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7744 ">#7744</a>
<a
href="633c261dad "><code>633c261</code></a>
Thanks <a
href="https://github.com/ashishjain0512 "><code>@ashishjain0512</code></a>!
- fix(architecture): add <code>architecture.seed</code> config option to
make architecture diagrams render deterministically. Resolves <a
href="https://redirect.github.com/mermaid-js/mermaid/issues/7729 ">#7729</a>.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7732 ">#7732</a>
<a
href="c8ba156f55 "><code>c8ba156</code></a>
Thanks <a href="https://github.com/rkdfx "><code>@rkdfx</code></a>! -
fix: tolerate leading horizontal whitespace before YAML frontmatter
delimiters. Closes <a
href="https://redirect.github.com/mermaid-js/mermaid/issues/7613 ">mermaid-js/mermaid#7613</a></p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7314 ">#7314</a>
<a
href="4e4e6c4a10 "><code>4e4e6c4</code></a>
Thanks <a
href="https://github.com/darshanr0107 "><code>@darshanr0107</code></a>!
- fix(flowchart): Prevent crash when flowchart node shape is
undefined</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7762 ">#7762</a>
<a
href="cfd23916f3 "><code>cfd2391</code></a>
Thanks <a
href="https://github.com/Dharya-dev "><code>@Dharya-dev</code></a>! -
fix(class): support styling and callbacks for generic classes</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7284 ">#7284</a>
<a
href="c1f116d366 "><code>c1f116d</code></a>
Thanks <a
href="https://github.com/darshanr0107 "><code>@darshanr0107</code></a>!
- fix(gantt): Render gantt vertical markers without affecting row layout
or chart height</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7786 ">#7786</a>
<a
href="72fbab1a4d "><code>72fbab1</code></a>
Thanks <a
href="https://github.com/knsv-bot "><code>@knsv-bot</code></a>! -
fix(er): allow special characters (e.g. dots) in ER diagram attribute
names and types by escaping them with backticks</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7672 ">#7672</a>
<a
href="4887e9721c "><code>4887e97</code></a>
Thanks <a
href="https://github.com/sjackson0109 "><code>@sjackson0109</code></a>!
- fix(flowchart): respect per-subgraph direction keyword in Dagre
layout. Fixes <a
href="https://redirect.github.com/mermaid-js/mermaid/issues/4648 ">#4648</a></p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7734 ">#7734</a>
<a
href="a4c1e507a3 "><code>a4c1e50</code></a>
Thanks <a href="https://github.com/OfirHaf "><code>@OfirHaf</code></a>!
- fix(block): read block padding and sanitize config dynamically instead
of at module load time</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7674 ">#7674</a>
<a
href="cc750896b2 "><code>cc75089</code></a>
Thanks <a
href="https://github.com/cyphercodes "><code>@cyphercodes</code></a>! -
fix(block): respect current DOMPurify config when sanitizing labels</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7711 ">#7711</a>
<a
href="be2e282014 "><code>be2e282</code></a>
Thanks <a
href="https://github.com/Jinacker "><code>@Jinacker</code></a>! -
fix(flowchart): render flowchart and state self-loop edges as a single
SVG path.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7781 ">#7781</a>
<a
href="d945968c13 "><code>d945968</code></a>
Thanks <a
href="https://github.com/Dharya-dev "><code>@Dharya-dev</code></a>! -
fix(radar): align axis labels based on angular position to prevent
clipping</p>
</li>
<li>
<p><a
href="https://redirect.github.com/mermaid-js/mermaid/pull/7661 ">#7661</a>
<a
href="2f5e9e8c9a "><code>2f5e9e8</code></a>
Thanks <a
href="https://github.com/nabila401 "><code>@nabila401</code></a>! -
fix(venn): fix 3-circle venn diagram union rendering</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="7c0cafcf42 "><code>7c0cafc</code></a>
Version Packages: v11.16.0 (<a
href="https://redirect.github.com/mermaid-js/mermaid/issues/7916 ">#7916</a>)</li>
<li><a
href="26acd1a8c6 "><code>26acd1a</code></a>
Merge pull request <a
href="https://redirect.github.com/mermaid-js/mermaid/issues/7915 ">#7915</a>
from mermaid-js/release/11.16.0</li>
<li><a
href="5a8eae7b0b "><code>5a8eae7</code></a>
Merge branch 'master' into release/11.16.0</li>
<li><a
href="dd5ea777ae "><code>dd5ea77</code></a>
Merge pull request <a
href="https://redirect.github.com/mermaid-js/mermaid/issues/7913 ">#7913</a>
from mermaid-js/pebr/fix-changesets</li>
<li><a
href="658ee66388 "><code>658ee66</code></a>
docs: fix missing bumps of <code>@mermaid-js/parser</code></li>
<li><a
href="04259a18ff "><code>04259a1</code></a>
docs: fix author and commit on examples changeset</li>
<li><a
href="c9dcfb15e1 "><code>c9dcfb1</code></a>
docs: update changeset diagram scopes</li>
<li><a
href="a34dab9217 "><code>a34dab9</code></a>
docs: remove swimlane/cynefin bugfix changesets</li>
<li><a
href="e81f31ffd6 "><code>e81f31f</code></a>
docs: remove local-editor changeset</li>
<li><a
href="7223f03c73 "><code>7223f03</code></a>
Minor correction</li>
<li>Additional commits viewable in <a
href="https://github.com/mermaid-js/mermaid/compare/mermaid@11.12.3...mermaid@11.16.0 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 10:04:21 -07:00
dependabot[bot]
d2fa57ab98
build(deps): bump sharp from 0.34.5 to 0.35.2 ( #8739 )
...
Bumps [sharp](https://github.com/lovell/sharp ) from 0.34.5 to 0.35.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lovell/sharp/releases ">sharp's
releases</a>.</em></p>
<blockquote>
<h2>v0.35.2</h2>
<ul>
<li>
<p>TypeScript: Add <code>mediaType</code> to metadata response.
<a
href="https://redirect.github.com/lovell/sharp/issues/4492 ">#4492</a></p>
</li>
<li>
<p>Improve WebAssembly fallback detection.
<a
href="https://redirect.github.com/lovell/sharp/issues/4513 ">#4513</a></p>
</li>
<li>
<p>Improve code bundler support with stub binaries.
<a
href="https://redirect.github.com/lovell/sharp/issues/4543 ">#4543</a></p>
</li>
<li>
<p>Verify GIF <code>effort</code> option is an integer.
<a href="https://redirect.github.com/lovell/sharp/pull/4544 ">#4544</a>
<a
href="https://github.com/metsw24-max "><code>@metsw24-max</code></a></p>
</li>
<li>
<p>Verify <code>recomb</code> matrix entries are numbers.
<a href="https://redirect.github.com/lovell/sharp/pull/4545 ">#4545</a>
<a
href="https://github.com/metsw24-max "><code>@metsw24-max</code></a></p>
</li>
<li>
<p>TypeScript: Replace namespace with named exports for ESM.
<a
href="https://redirect.github.com/lovell/sharp/issues/4546 ">#4546</a></p>
</li>
<li>
<p>Bound dilate and erode width to avoid mask-size overflow.
<a href="https://redirect.github.com/lovell/sharp/pull/4548 ">#4548</a>
<a
href="https://github.com/metsw24-max "><code>@metsw24-max</code></a></p>
</li>
<li>
<p>Verify <code>convolve</code> kernel values are numbers.
<a href="https://redirect.github.com/lovell/sharp/pull/4549 ">#4549</a>
<a
href="https://github.com/metsw24-max "><code>@metsw24-max</code></a></p>
</li>
</ul>
<h2>v0.35.2-rc.2</h2>
<ul>
<li>
<p>TypeScript: Add <code>mediaType</code> to metadata response.
<a
href="https://redirect.github.com/lovell/sharp/issues/4492 ">#4492</a></p>
</li>
<li>
<p>Improve WebAssembly fallback detection.
<a
href="https://redirect.github.com/lovell/sharp/issues/4513 ">#4513</a></p>
</li>
<li>
<p>Improve code bundler support with stub binaries.
<a
href="https://redirect.github.com/lovell/sharp/issues/4543 ">#4543</a></p>
</li>
<li>
<p>Verify GIF <code>effort</code> option is an integer.
<a href="https://redirect.github.com/lovell/sharp/pull/4544 ">#4544</a>
<a
href="https://github.com/metsw24-max "><code>@metsw24-max</code></a></p>
</li>
<li>
<p>Verify <code>recomb</code> matrix entries are numbers.
<a href="https://redirect.github.com/lovell/sharp/pull/4545 ">#4545</a>
<a
href="https://github.com/metsw24-max "><code>@metsw24-max</code></a></p>
</li>
<li>
<p>TypeScript: Replace namespace with named exports for ESM.
<a
href="https://redirect.github.com/lovell/sharp/issues/4546 ">#4546</a></p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="c9622a38ed "><code>c9622a3</code></a>
Release v0.35.2</li>
<li><a
href="cd4568fd41 "><code>cd4568f</code></a>
Upgrade to sharp-libvips v1.3.1</li>
<li><a
href="78390cf3d2 "><code>78390cf</code></a>
Tests: Add font file to prevent font discovery flakiness (<a
href="https://redirect.github.com/lovell/sharp/issues/4550 ">#4550</a>)</li>
<li><a
href="61210b4d0a "><code>61210b4</code></a>
Verify convolve kernel values are numbers (<a
href="https://redirect.github.com/lovell/sharp/issues/4549 ">#4549</a>)</li>
<li><a
href="1cb27dcca4 "><code>1cb27dc</code></a>
Prerelease v0.35.2-rc.2</li>
<li><a
href="c7606c3ca7 "><code>c7606c3</code></a>
Upgrade to sharp-libvips v1.3.1-rc.0</li>
<li><a
href="29d1e9e4d3 "><code>29d1e9e</code></a>
Prerelease v0.35.2-rc.1</li>
<li><a
href="bbba0a16ba "><code>bbba0a1</code></a>
Improve code bundler support with stub binaries</li>
<li><a
href="ab528662ea "><code>ab52866</code></a>
Bound dilate and erode width to avoid mask-size overflow (<a
href="https://redirect.github.com/lovell/sharp/issues/4548 ">#4548</a>)</li>
<li><a
href="0f594dde40 "><code>0f594dd</code></a>
Prerelease v0.35.2-rc.0</li>
<li>Additional commits viewable in <a
href="https://github.com/lovell/sharp/compare/v0.34.5...v0.35.2 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 10:04:17 -07:00
dependabot[bot]
29a26cbd65
build(deps): bump @codemirror/state from 6.5.4 to 6.7.0 ( #8736 )
...
Bumps [@codemirror/state](https://github.com/codemirror/state ) from
6.5.4 to 6.7.0.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/codemirror/state/blob/main/CHANGELOG.md ">@codemirror/state's
changelog</a>.</em></p>
<blockquote>
<h2>6.6.0 (2026-03-12)</h2>
<h3>New features</h3>
<p><code>EditorSelection.range</code> now takes an optional
<code>assoc</code> argument.</p>
<p><code>SelectionRange.extend</code> can now be given a third argument
to specify associativity.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/codemirror/state/commits ">compare view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 10:04:13 -07:00
dependabot[bot]
63aef57d49
build(deps): bump dotenv from 17.3.1 to 17.4.2 ( #8737 )
...
Bumps [dotenv](https://github.com/motdotla/dotenv ) from 17.3.1 to
17.4.2.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md ">dotenv's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/motdotla/dotenv/compare/v17.4.1...v17.4.2 ">17.4.2</a>
(2026-04-12)</h2>
<h3>Changed</h3>
<ul>
<li>Improved skill files - tightened up details (<a
href="https://redirect.github.com/motdotla/dotenv/pull/1009 ">#1009</a>)</li>
</ul>
<h2><a
href="https://github.com/motdotla/dotenv/compare/v17.4.0...v17.4.1 ">17.4.1</a>
(2026-04-05)</h2>
<h3>Changed</h3>
<ul>
<li>Change text <code>injecting</code> to <code>injected</code> (<a
href="https://redirect.github.com/motdotla/dotenv/pull/1005 ">#1005</a>)</li>
</ul>
<h2><a
href="https://github.com/motdotla/dotenv/compare/v17.3.1...v17.4.0 ">17.4.0</a>
(2026-04-01)</h2>
<h3>Added</h3>
<ul>
<li>Add <code>skills/</code> folder with focused agent skills:
<code>skills/dotenv/SKILL.md</code> (core usage) and
<code>skills/dotenvx/SKILL.md</code> (encryption, multiple environments,
variable expansion) for AI coding agent discovery via the skills.sh
ecosystem (<code>npx skills add motdotla/dotenv</code>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Tighten up logs: <code>◇ injecting env (14) from .env</code> (<a
href="https://redirect.github.com/motdotla/dotenv/pull/1003 ">#1003</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="f116f70310 "><code>f116f70</code></a>
17.4.2</li>
<li><a
href="3a8161274f "><code>3a81612</code></a>
fix visual order of faq</li>
<li><a
href="13f55a89e1 "><code>13f55a8</code></a>
Merge branch 'skill'</li>
<li><a
href="4bbbf73f09 "><code>4bbbf73</code></a>
reorganize faq</li>
<li><a
href="c3da64bb2b "><code>c3da64b</code></a>
Merge pull request <a
href="https://redirect.github.com/motdotla/dotenv/issues/1009 ">#1009</a>
from motdotla/skill</li>
<li><a
href="6f743b173f "><code>6f743b1</code></a>
update source</li>
<li><a
href="fc2c6247e8 "><code>fc2c624</code></a>
update skill</li>
<li><a
href="972315ba74 "><code>972315b</code></a>
Tighten up skill</li>
<li><a
href="2795fce3d1 "><code>2795fce</code></a>
reorganize faq</li>
<li><a
href="d5495d4ae8 "><code>d5495d4</code></a>
adjust skill</li>
<li>Additional commits viewable in <a
href="https://github.com/motdotla/dotenv/compare/v17.3.1...v17.4.2 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 10:04:01 -07:00
dependabot[bot]
01f49b1fa0
build(deps): bump @aws-sdk/client-s3 from 3.1072.0 to 3.1075.0 ( #8742 )
...
Bumps
[@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3 )
from 3.1072.0 to 3.1075.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases ">@aws-sdk/client-s3's
releases</a>.</em></p>
<blockquote>
<h2>v3.1075.0</h2>
<h4>3.1075.0(2026-06-23)</h4>
<h5>New Features</h5>
<ul>
<li><strong>client-kafka:</strong> Amazon MSK Replicator now supports
mTLS authentication when connecting to external Apache Kafka clusters,
enabling customers to replicate data from clusters that require mutual
TLS for client authentication. This capability is supported when
replicating to Amazon MSK Express brokers. (<a
href="005f9529d4 ">005f9529</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.1075.0.zip</strong></p>
<h2>v3.1074.0</h2>
<h4>3.1074.0(2026-06-22)</h4>
<h5>Chores</h5>
<ul>
<li><strong>xml-builder:</strong>
<ul>
<li>move testing devDeps to root, remove unused nodable dep (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8118 ">#8118</a>)
(<a
href="ed82880d26 ">ed82880d</a>)</li>
<li>parse XML internally (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/7863 ">#7863</a>)
(<a
href="74d0a07143 ">74d0a071</a>)</li>
</ul>
</li>
</ul>
<h5>Documentation Changes</h5>
<ul>
<li>typo in contributing.md (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8116 ">#8116</a>)
(<a
href="87ff33d30e ">87ff33d3</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>clients:</strong> update client endpoints as of 2026-06-22
(<a
href="3a55a33387 ">3a55a333</a>)</li>
<li><strong>client-cloudwatch-logs:</strong> CloudWatch Logs Updates -
New APIs introduced to support syslog ingestion to a log group. For more
information, see CloudWatch Logs API documentation. (<a
href="01a3b51350 ">01a3b513</a>)</li>
<li><strong>client-bedrock-agentcore:</strong> Adds an optional
extractionMode field to CreateEvent. SKIP retains the event in
short-term memory but excludes it from long-term memory extraction. (<a
href="749753adae ">749753ad</a>)</li>
<li><strong>client-omics:</strong> Adds support for scratch ephemeral
storage mounted at tmp (<a
href="331e3023c1 ">331e3023</a>)</li>
<li><strong>client-application-signals:</strong> Application Signals now
supports dynamic instrumentation and Service Events telemetry. Add
instrumentation at runtime without restarts, and use fine-grained
profiling data to quickly pinpoint latency and error root causes. (<a
href="f93b1c0333 ">f93b1c03</a>)</li>
<li><strong>client-mediaconnect:</strong> AWS MediaConnect now supports
Content Quality Analysis for Router Inputs, enabling detection of black
frames, frozen frames, and silent audio with configurable thresholds.
(<a
href="05054853a5 ">05054853</a>)</li>
<li><strong>client-lambda-core:</strong> Initial release of the AWS
Lambda Core SDK with APIs to create, manage, and tag network connectors
that enable Lambda compute resources to access private resources in your
Amazon VPC. (<a
href="e35cdab89f ">e35cdab8</a>)</li>
<li><strong>client-lambda:</strong> Add support for tagging Network
Connector resources in AWS Lambda. (<a
href="fbfc40785e ">fbfc4078</a>)</li>
<li><strong>client-guardduty:</strong> Added AI-powered investigations
that automatically analyze security findings, correlate related
activity, and produce structured summaries with risk assessment,
confidence scoring, MITRE technique classification, and actionable next
steps. (<a
href="83c2983945 ">83c29839</a>)</li>
<li><strong>client-lambda-microvms:</strong> Lambda MicroVMs GA launch.
Lambda MicroVMs enable isolated and highly responsive execution of
user-supplied or LLM-generated code. (<a
href="5519a7e28f ">5519a7e2</a>)</li>
<li><strong>client-kafka:</strong> Amazon MSK Replicator now supports
mTLS authentication when connecting to external Apache Kafka clusters,
enabling customers to replicate data from clusters that require mutual
TLS for client authentication. This capability is supported when
replicating to Amazon MSK Express brokers. (<a
href="ce7d1bf501 ">ce7d1bf5</a>)</li>
<li><strong>client-quicksight:</strong> Updated the Amazon Quick Spaces
API to remove unsupported SPACE and ARTIFACT values from the
SpaceQuickSightResourceType enum. (<a
href="e1b325d42e ">e1b325d4</a>)</li>
<li><strong>client-ec2:</strong> This release adds support for AMI
Watermark and Allowed AMIs integration (<a
href="d1698bed39 ">d1698bed</a>)</li>
<li><strong>client-direct-connect:</strong> Added VIF rate limiting
support for AWS Direct Connect, allowing customers to set bandwidth
allocations on virtual interfaces to manage traffic on dedicated
connections. (<a
href="228a95dc0c ">228a95dc</a>)</li>
</ul>
<h5>Bug Fixes</h5>
<ul>
<li><strong>cloudfront-signer:</strong> filename asterisk apostrophe
encoding fix (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8119 ">#8119</a>)
(<a
href="35acab408b ">35acab40</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.1074.0.zip</strong></p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md ">@aws-sdk/client-s3's
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1074.0...v3.1075.0 ">3.1075.0</a>
(2026-06-23)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1073.0...v3.1074.0 ">3.1074.0</a>
(2026-06-22)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1072.0...v3.1073.0 ">3.1073.0</a>
(2026-06-19)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@aws-sdk/client-s3</code></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="29ee199934 "><code>29ee199</code></a>
Publish v3.1075.0</li>
<li><a
href="c48dfa08aa "><code>c48dfa0</code></a>
Publish v3.1074.0</li>
<li><a
href="74d0a07143 "><code>74d0a07</code></a>
chore(xml-builder): parse XML internally (<a
href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3/issues/7863 ">#7863</a>)</li>
<li><a
href="ee71adc966 "><code>ee71adc</code></a>
Publish v3.1073.0</li>
<li>See full diff in <a
href="https://github.com/aws/aws-sdk-js-v3/commits/v3.1075.0/clients/client-s3 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 10:03:31 -07:00
dependabot[bot]
1b180fae1f
build(deps): bump @agentclientprotocol/claude-agent-acp from 0.48.0 to 0.52.0 ( #8745 )
...
Bumps
[@agentclientprotocol/claude-agent-acp](https://github.com/agentclientprotocol/claude-agent-acp )
from 0.48.0 to 0.52.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/agentclientprotocol/claude-agent-acp/releases ">@agentclientprotocol/claude-agent-acp's
releases</a>.</em></p>
<blockquote>
<h2>v0.52.0</h2>
<h2><a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.51.0...v0.52.0 ">0.52.0</a>
(2026-06-25)</h2>
<h3>Features</h3>
<ul>
<li>Add version flag handling (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/813 ">#813</a>)
(<a
href="9616bdac47 ">9616bda</a>),
closes <a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/809 ">#809</a></li>
<li><strong>deps-dev:</strong> bump expect-type from 1.3.0 to 1.4.0 in
the minor group (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/814 ">#814</a>)
(<a
href="61272acb30 ">61272ac</a>)</li>
<li><strong>deps:</strong> Update
<code>@anthropic-ai/claude-agent-sdk</code> to 0.3.191 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/810 ">#810</a>)
(<a
href="228f02ecfb ">228f02e</a>)</li>
<li>Push session title updates at turn end (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/812 ">#812</a>)
(<a
href="1fe7ec09a3 ">1fe7ec0</a>)</li>
</ul>
<h2>v0.51.0</h2>
<h2><a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.50.0...v0.51.0 ">0.51.0</a>
(2026-06-24)</h2>
<h3>Features</h3>
<ul>
<li><strong>deps:</strong> bump the minor group with 11 updates (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/807 ">#807</a>)
(<a
href="8f6ebd1d91 ">8f6ebd1</a>)</li>
</ul>
<h2>v0.50.0</h2>
<h2><a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.49.0...v0.50.0 ">0.50.0</a>
(2026-06-23)</h2>
<h3>Features</h3>
<ul>
<li><strong>acp:</strong> Handle ACP request cancellation signals (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/801 ">#801</a>)
(<a
href="9013d1d468 ">9013d1d</a>)</li>
<li><strong>deps:</strong> bump actions/checkout from 6.0.3 to 7.0.0 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/803 ">#803</a>)
(<a
href="044c43e0c8 ">044c43e</a>)</li>
<li><strong>deps:</strong> upgrade to
<code>@anthropic-ai/claude-agent-sdk</code><a
href="https://github.com/0 "><code>@0</code></a>.3.186 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/806 ">#806</a>)
(<a
href="a7e6137f68 ">a7e6137</a>)</li>
</ul>
<h2>v0.49.0</h2>
<h2><a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.48.0...v0.49.0 ">0.49.0</a>
(2026-06-22)</h2>
<h3>Features</h3>
<ul>
<li>Update to claude-agent-sdk 0.3.185 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/798 ">#798</a>)
(<a
href="8dc8c86426 ">8dc8c86</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Deduplicate streamed assistant blocks by content (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/800 ">#800</a>)
(<a
href="960f62d765 ">960f62d</a>)</li>
<li>Infer 1M context from model descriptions (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/799 ">#799</a>)
(<a
href="508453c288 ">508453c</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/agentclientprotocol/claude-agent-acp/blob/main/CHANGELOG.md ">@agentclientprotocol/claude-agent-acp's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.51.0...v0.52.0 ">0.52.0</a>
(2026-06-25)</h2>
<h3>Features</h3>
<ul>
<li>Add version flag handling (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/813 ">#813</a>)
(<a
href="9616bdac47 ">9616bda</a>),
closes <a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/809 ">#809</a></li>
<li><strong>deps-dev:</strong> bump expect-type from 1.3.0 to 1.4.0 in
the minor group (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/814 ">#814</a>)
(<a
href="61272acb30 ">61272ac</a>)</li>
<li><strong>deps:</strong> Update
<code>@anthropic-ai/claude-agent-sdk</code> to 0.3.191 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/810 ">#810</a>)
(<a
href="228f02ecfb ">228f02e</a>)</li>
<li>Push session title updates at turn end (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/812 ">#812</a>)
(<a
href="1fe7ec09a3 ">1fe7ec0</a>)</li>
</ul>
<h2><a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.50.0...v0.51.0 ">0.51.0</a>
(2026-06-24)</h2>
<h3>Features</h3>
<ul>
<li><strong>deps:</strong> bump the minor group with 11 updates (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/807 ">#807</a>)
(<a
href="8f6ebd1d91 ">8f6ebd1</a>)</li>
</ul>
<h2><a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.49.0...v0.50.0 ">0.50.0</a>
(2026-06-23)</h2>
<h3>Features</h3>
<ul>
<li><strong>acp:</strong> Handle ACP request cancellation signals (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/801 ">#801</a>)
(<a
href="9013d1d468 ">9013d1d</a>)</li>
<li><strong>deps:</strong> bump actions/checkout from 6.0.3 to 7.0.0 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/803 ">#803</a>)
(<a
href="044c43e0c8 ">044c43e</a>)</li>
<li><strong>deps:</strong> upgrade to
<code>@anthropic-ai/claude-agent-sdk</code><a
href="https://github.com/0 "><code>@0</code></a>.3.186 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/806 ">#806</a>)
(<a
href="a7e6137f68 ">a7e6137</a>)</li>
</ul>
<h2><a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.48.0...v0.49.0 ">0.49.0</a>
(2026-06-22)</h2>
<h3>Features</h3>
<ul>
<li>Update to claude-agent-sdk 0.3.185 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/798 ">#798</a>)
(<a
href="8dc8c86426 ">8dc8c86</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Deduplicate streamed assistant blocks by content (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/800 ">#800</a>)
(<a
href="960f62d765 ">960f62d</a>)</li>
<li>Infer 1M context from model descriptions (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/799 ">#799</a>)
(<a
href="508453c288 ">508453c</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="e9163f8553 "><code>e9163f8</code></a>
chore(main): release 0.52.0 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/811 ">#811</a>)</li>
<li><a
href="61272acb30 "><code>61272ac</code></a>
feat(deps-dev): bump expect-type from 1.3.0 to 1.4.0 in the minor group
(<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/814 ">#814</a>)</li>
<li><a
href="9616bdac47 "><code>9616bda</code></a>
feat: Add version flag handling (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/813 ">#813</a>)</li>
<li><a
href="1fe7ec09a3 "><code>1fe7ec0</code></a>
feat: Push session title updates at turn end (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/812 ">#812</a>)</li>
<li><a
href="228f02ecfb "><code>228f02e</code></a>
feat(deps): Update <code>@anthropic-ai/claude-agent-sdk</code> to
0.3.191 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/810 ">#810</a>)</li>
<li><a
href="23626c9a43 "><code>23626c9</code></a>
chore(main): release 0.51.0 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/808 ">#808</a>)</li>
<li><a
href="8f6ebd1d91 "><code>8f6ebd1</code></a>
feat(deps): bump the minor group with 11 updates (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/807 ">#807</a>)</li>
<li><a
href="07911601cc "><code>0791160</code></a>
chore(main): release 0.50.0 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/802 ">#802</a>)</li>
<li><a
href="a7e6137f68 "><code>a7e6137</code></a>
feat(deps): upgrade to <code>@anthropic-ai/claude-agent-sdk</code><a
href="https://github.com/0 "><code>@0</code></a>.3.186 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/806 ">#806</a>)</li>
<li><a
href="044c43e0c8 "><code>044c43e</code></a>
feat(deps): bump actions/checkout from 6.0.3 to 7.0.0 (<a
href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/803 ">#803</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.48.0...v0.52.0 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 10:03:26 -07:00
github-actions[bot]
098a98091c
chore(lockfile): refresh pnpm-lock.yaml ( #8673 )
...
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
2026-06-26 16:09:41 -05:00
dependabot[bot]
8bfe5a4791
build(deps-dev): bump @storybook/addon-docs from 10.3.5 to 10.4.6 ( #8466 )
...
Bumps
[@storybook/addon-docs](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs )
from 10.3.5 to 10.4.6.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/releases ">@storybook/addon-docs's
releases</a>.</em></p>
<blockquote>
<h2>v10.4.6</h2>
<h2>10.4.6</h2>
<ul>
<li>CSF: Allow partial globals overrides in story and meta annotations -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/34985 ">#34985</a>,
thanks <a
href="https://github.com/TheSeydiCharyyev "><code>@TheSeydiCharyyev</code></a>!</li>
<li>Dependencies: Upgrade esbuild - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35157 ">#35157</a>,
thanks <a
href="https://github.com/Kakadus "><code>@Kakadus</code></a>!</li>
</ul>
<h2>v10.4.5</h2>
<h2>10.4.5</h2>
<ul>
<li>Core: Rework AI checklist feature gate - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35053 ">#35053</a>,
thanks <a
href="https://github.com/Sidnioulz "><code>@Sidnioulz</code></a>!</li>
<li>Preview: Stop mixed CSF3+4 stories getting core annotations injected
twice - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35094 ">#35094</a>,
thanks <a
href="https://github.com/JReinhold "><code>@JReinhold</code></a>!</li>
</ul>
<h2>v10.4.4</h2>
<h2>10.4.4</h2>
<ul>
<li>Telemetry: Add timeout to event-log POST to prevent build hang - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35085 ">#35085</a>,
thanks <a
href="https://github.com/badams "><code>@badams</code></a>!</li>
</ul>
<h2>v10.4.3</h2>
<h2>10.4.3</h2>
<ul>
<li>Addon Docs: Fix Primary and Controls blocks not rendering in custom
MDX pages - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34496 ">#34496</a>,
thanks <a
href="https://github.com/NYCU-Chung "><code>@NYCU-Chung</code></a>!</li>
<li>Core: Respect !dev tag on MDX docs in sidebar - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35031 ">#35031</a>,
thanks <a
href="https://github.com/JReinhold "><code>@JReinhold</code></a>!</li>
<li>React: Add support for resolving subcomponents attached as
properties of a parent component - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34967 ">#34967</a>,
thanks <a
href="https://github.com/yatishgoel "><code>@yatishgoel</code></a>!</li>
<li>UI: Prevent docs page scroll reset on HMR re-render - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35021 ">#35021</a>,
thanks <a
href="https://github.com/LongTangGithub "><code>@LongTangGithub</code></a>!</li>
</ul>
<h2>v10.4.2</h2>
<h2>10.4.2</h2>
<ul>
<li>Bug: Fix Windows command resolution for non-Node package managers -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/33534 ">#33534</a>,
thanks <a
href="https://github.com/copilot-swe-agent "><code>@copilot-swe-agent</code></a>!</li>
<li>Build: Upgrade type-fest to latest version 5.6.0 - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34791 ">#34791</a>,
thanks <a
href="https://github.com/tobiasdiez "><code>@tobiasdiez</code></a>!</li>
<li>CSF: Fix parsing of string literal export names - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34901 ">#34901</a>,
thanks <a
href="https://github.com/shilman "><code>@shilman</code></a>!</li>
<li>Publish: Add npm provenance attestations - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34936 ">#34936</a>,
thanks <a
href="https://github.com/copilot-swe-agent "><code>@copilot-swe-agent</code></a>!</li>
</ul>
<h2>v10.4.1</h2>
<h2>10.4.1</h2>
<ul>
<li>Angular: Detect model() signal outputs (type inference + compodoc
autodocs + runtime binding) - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34833 ">#34833</a>,
thanks <a
href="https://github.com/valentinpalkovic "><code>@valentinpalkovic</code></a>!</li>
<li>Build: Upgrade type-fest to latest version 5.6.0 - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34791 ">#34791</a>,
thanks <a
href="https://github.com/tobiasdiez "><code>@tobiasdiez</code></a>!</li>
<li>CLI: Run `npx expo install --fix` after init for Expo projects - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34803 ">#34803</a>,
thanks <a
href="https://github.com/ndelangen "><code>@ndelangen</code></a>!</li>
<li>CLI: Support `peerDependencies` in framework detection for component
libraries - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34516 ">#34516</a>,
thanks <a
href="https://github.com/zhyd1997 "><code>@zhyd1997</code></a>!</li>
<li>Next.js: Add useLinkStatus mock to next/link export mock - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34593 ">#34593</a>,
thanks <a
href="https://github.com/philwolstenholme "><code>@philwolstenholme</code></a>!</li>
<li>Vue3: Specify a specific version for non-dev dependency - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34794 ">#34794</a>,
thanks <a
href="https://github.com/ScopeyNZ "><code>@ScopeyNZ</code></a>!</li>
</ul>
<h2>v10.4.0</h2>
<h2>10.4.0</h2>
<blockquote>
<p><em>AI-assisted setup, change-aware review, and stronger framework
support</em></p>
</blockquote>
<p>Storybook 10.4 contains hundreds of fixes and improvements
including:</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md ">@storybook/addon-docs's
changelog</a>.</em></p>
<blockquote>
<h2>10.4.6</h2>
<ul>
<li>CSF: Allow partial globals overrides in story and meta annotations -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/34985 ">#34985</a>,
thanks <a
href="https://github.com/TheSeydiCharyyev "><code>@TheSeydiCharyyev</code></a>!</li>
<li>Dependencies: Upgrade esbuild - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35157 ">#35157</a>,
thanks <a
href="https://github.com/Kakadus "><code>@Kakadus</code></a>!</li>
</ul>
<h2>10.4.5</h2>
<ul>
<li>Core: Rework AI checklist feature gate - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35053 ">#35053</a>,
thanks <a
href="https://github.com/Sidnioulz "><code>@Sidnioulz</code></a>!</li>
<li>Preview: Stop mixed CSF3+4 stories getting core annotations injected
twice - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35094 ">#35094</a>,
thanks <a
href="https://github.com/JReinhold "><code>@JReinhold</code></a>!</li>
</ul>
<h2>10.4.4</h2>
<ul>
<li>Telemetry: Add timeout to event-log POST to prevent build hang - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35085 ">#35085</a>,
thanks <a
href="https://github.com/badams "><code>@badams</code></a>!</li>
</ul>
<h2>10.4.3</h2>
<ul>
<li>Addon Docs: Fix Primary and Controls blocks not rendering in custom
MDX pages - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34496 ">#34496</a>,
thanks <a
href="https://github.com/NYCU-Chung "><code>@NYCU-Chung</code></a>!</li>
<li>Core: Respect !dev tag on MDX docs in sidebar - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35031 ">#35031</a>,
thanks <a
href="https://github.com/JReinhold "><code>@JReinhold</code></a>!</li>
<li>React: Add support for resolving subcomponents attached as
properties of a parent component - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34967 ">#34967</a>,
thanks <a
href="https://github.com/yatishgoel "><code>@yatishgoel</code></a>!</li>
<li>UI: Prevent docs page scroll reset on HMR re-render - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35021 ">#35021</a>,
thanks <a
href="https://github.com/LongTangGithub "><code>@LongTangGithub</code></a>!</li>
</ul>
<h2>10.4.2</h2>
<ul>
<li>Bug: Fix Windows command resolution for non-Node package managers -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/33534 ">#33534</a>,
thanks <a
href="https://github.com/copilot-swe-agent "><code>@copilot-swe-agent</code></a>!</li>
<li>Build: Upgrade type-fest to latest version 5.6.0 - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34791 ">#34791</a>,
thanks <a
href="https://github.com/tobiasdiez "><code>@tobiasdiez</code></a>!</li>
<li>CSF: Fix parsing of string literal export names - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34901 ">#34901</a>,
thanks <a
href="https://github.com/shilman "><code>@shilman</code></a>!</li>
<li>Publish: Add npm provenance attestations - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34936 ">#34936</a>,
thanks <a
href="https://github.com/copilot-swe-agent "><code>@copilot-swe-agent</code></a>!</li>
</ul>
<h2>10.4.1</h2>
<ul>
<li>Angular: Detect model() signal outputs (type inference + compodoc
autodocs + runtime binding) - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34833 ">#34833</a>,
thanks <a
href="https://github.com/valentinpalkovic "><code>@valentinpalkovic</code></a>!</li>
<li>Build: Upgrade type-fest to latest version 5.6.0 - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34791 ">#34791</a>,
thanks <a
href="https://github.com/tobiasdiez "><code>@tobiasdiez</code></a>!</li>
<li>CLI: Run <code>npx expo install --fix</code> after init for Expo
projects - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34803 ">#34803</a>,
thanks <a
href="https://github.com/ndelangen "><code>@ndelangen</code></a>!</li>
<li>CLI: Support <code>peerDependencies</code> in framework detection
for component libraries - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34516 ">#34516</a>,
thanks <a
href="https://github.com/zhyd1997 "><code>@zhyd1997</code></a>!</li>
<li>Next.js: Add useLinkStatus mock to next/link export mock - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34593 ">#34593</a>,
thanks <a
href="https://github.com/philwolstenholme "><code>@philwolstenholme</code></a>!</li>
<li>Vue3: Specify a specific version for non-dev dependency - <a
href="https://redirect.github.com/storybookjs/storybook/pull/34794 ">#34794</a>,
thanks <a
href="https://github.com/ScopeyNZ "><code>@ScopeyNZ</code></a>!</li>
</ul>
<h2>10.4.0</h2>
<blockquote>
<p><em>AI-assisted setup, change-aware review, and stronger framework
support</em></p>
</blockquote>
<p>Storybook 10.4 contains hundreds of fixes and improvements
including:</p>
<ul>
<li>🤖 Agentic Setup: New CLI workflow for AI-assisted Storybook setup
and onboarding</li>
<li>🔍 Change review: Sidebar filtering to highlight new, modified, and
related stories based on git changes</li>
<li>🧭 Sidebar review tools: Status filtering, URL-persisted filters, and
clearer review signals in the sidebar</li>
<li>⚛️ TanStack React: New <code>@storybook/tanstack-react</code>
framework with routing and server function support</li>
<li>🧩 React MCP: Faster, more accurate component docgen powered by the
TypeScript Language Server</li>
<li>📱 React Native: Zero config RN project initialization</li>
<li>🤝 Sharing: Easily publish and share your local Storybook with
teammates, powered by Chromatic</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="5496a4270d "><code>5496a42</code></a>
Bump version from "10.4.5" to "10.4.6" [skip
ci]</li>
<li><a
href="48e7b20074 "><code>48e7b20</code></a>
Bump version from "10.4.4" to "10.4.5" [skip
ci]</li>
<li><a
href="5adebe753f "><code>5adebe7</code></a>
Bump version from "10.4.3" to "10.4.4" [skip
ci]</li>
<li><a
href="624e6187fd "><code>624e618</code></a>
Bump version from "10.4.2" to "10.4.3" [skip
ci]</li>
<li><a
href="c898822822 "><code>c898822</code></a>
Merge pull request <a
href="https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs/issues/34496 ">#34496</a>
from NYCU-Chung/fix/docs-blocks-custom-mdx</li>
<li><a
href="c920fd08c7 "><code>c920fd0</code></a>
Merge pull request <a
href="https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs/issues/35021 ">#35021</a>
from LongTangGithub/fix/docs-hmr-scroll-to-top</li>
<li><a
href="1750494e9f "><code>1750494</code></a>
Merge pull request <a
href="https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs/issues/35031 ">#35031</a>
from storybookjs/jeppe/fix-mdx-no-dev-tag</li>
<li><a
href="298dea20c6 "><code>298dea2</code></a>
Bump version from "10.4.1" to "10.4.2" [skip
ci]</li>
<li><a
href="cc19ae1a21 "><code>cc19ae1</code></a>
Bump version from "10.4.0" to "10.4.1" [skip
ci]</li>
<li><a
href="f8c16d115c "><code>f8c16d1</code></a>
Bump version from "10.4.0-beta.0" to "10.4.0" [skip
ci]</li>
<li>Additional commits viewable in <a
href="https://github.com/storybookjs/storybook/commits/v10.4.6/code/addons/docs ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Nicky Leach <nicky@paperclip.ing>
Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-06-23 13:04:49 -07:00
github-actions[bot]
1c4ca29bf3
fix(deps): regenerate lockfile so react/react-dom resolve to 19.2.7 (repair #8557 merge) ( #8559 )
...
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work.
> - The JavaScript workspace depends on a frozen pnpm lockfile so CI and
installs resolve the same dependency graph everywhere.
> - PR #8557 updated the React package manifests and overrides to
`^19.2.7`, but master kept a stale lockfile.
> - That left master unable to run `pnpm install --frozen-lockfile`
because the lockfile override metadata no longer matched `package.json`.
> - This pull request refreshes only `pnpm-lock.yaml` from current
master so the dependency graph matches the already-merged manifests.
> - The benefit is that master CI can install dependencies again and
React/React DOM consistently resolve to `19.2.7`.
## Linked Issues or Issue Description
Bug fix: PR #8557 merged React/React DOM manifest and override
alignment, but the resulting master branch retained a stale
`pnpm-lock.yaml`. Running `CI=true pnpm install --frozen-lockfile` on
master failed with `ERR_PNPM_LOCKFILE_CONFIG_MISMATCH`, and the lockfile
still resolved React packages through `19.2.4` entries instead of
`19.2.7`.
Related public PR: #8557 .
## What Changed
- Refreshed `pnpm-lock.yaml` from current master.
- Kept the diff lockfile-only.
- Brought `react` and `react-dom` lockfile resolution to `19.2.7`.
## Verification
- `CI=true pnpm install --frozen-lockfile`
- `git diff --name-status origin/master..HEAD` shows only
`pnpm-lock.yaml`.
- Lockfile inspection shows `react@19.2.7` and `react-dom@19.2.7`
entries.
## Risks
Low risk. This is a generated lockfile-only refresh. The main risk is
merge-time lockfile drift if master changes dependencies before this
lands; if that happens, regenerate the lockfile instead of taking the
stale master side.
## Model Used
OpenAI GPT-5 Codex via Codex CLI, with repository tool use and command
execution.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
2026-06-23 12:09:54 -07:00
dependabot[bot]
72d4f2ad99
build(deps): bump better-auth from 1.4.18 to 1.6.20 ( #8464 )
...
Bumps
[better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth )
from 1.4.18 to 1.6.20.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/better-auth/better-auth/releases ">better-auth's
releases</a>.</em></p>
<blockquote>
<h2>v1.6.20</h2>
<h2><code>better-auth</code></h2>
<h3>Bug Fixes</h3>
<ul>
<li>Fixed account-linking logs to route through the configured logger
(<a
href="https://redirect.github.com/better-auth/better-auth/pull/10121 ">#10121</a>)</li>
<li>Fixed TypeScript inference errors by declaring inherited
<code>APIError</code> properties (<a
href="https://redirect.github.com/better-auth/better-auth/pull/8734 ">#8734</a>)</li>
<li>Fixed refresh cookie <code>Max-Age</code> to be capped at
<code>expiresIn</code> (<a
href="https://redirect.github.com/better-auth/better-auth/pull/9621 ">#9621</a>)</li>
</ul>
<p>For detailed changes, see <a
href="c342f42fff/packages/better-auth/CHANGELOG.md "><code>CHANGELOG</code></a></p>
<h2><code>@better-auth/i18n</code></h2>
<h3>Bug Fixes</h3>
<ul>
<li>Fixed English language fallback behavior and improved i18n
documentation (<a
href="https://redirect.github.com/better-auth/better-auth/pull/9872 ">#9872</a>)</li>
</ul>
<p>For detailed changes, see <a
href="c342f42fff/packages/i18n/CHANGELOG.md "><code>CHANGELOG</code></a></p>
<h2>Contributors</h2>
<p>Thanks to everyone who contributed to this release:</p>
<p><a
href="https://github.com/adityachaudhary99 "><code>@adityachaudhary99</code></a>,
<a href="https://github.com/dipan-ck "><code>@dipan-ck</code></a>, <a
href="https://github.com/sleepe229 "><code>@sleepe229</code></a>, <a
href="https://github.com/WilsonnnTan "><code>@WilsonnnTan</code></a></p>
<p><strong>Full changelog:</strong> <a
href="https://github.com/better-auth/better-auth/compare/v1.6.19...v1.6.20 "><code>v1.6.19...v1.6.20</code></a></p>
<h2>v1.6.19</h2>
<h2><code>better-auth</code></h2>
<h3>Features</h3>
<ul>
<li>Added support for pre-binding device codes to a specific user in the
device authorization plugin (<a
href="https://redirect.github.com/better-auth/better-auth/pull/9995 ">#9995</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li>Fixed headerless session checks (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10053 ">#10053</a>)</li>
<li>Fixed cookie cache fallback lookup (<a
href="https://redirect.github.com/better-auth/better-auth/pull/9348 ">#9348</a>)</li>
<li>Fixed <code>sendVerificationEmail</code> errors not being surfaced
to the client (<a
href="https://redirect.github.com/better-auth/better-auth/pull/8863 ">#8863</a>)</li>
<li>Fixed auth client return types not being emitted correctly in
TypeScript declaration builds (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10071 ">#10071</a>)</li>
<li>Fixed session and account cache cookies being silently dropped when
near the browser's per-cookie size limit by splitting them into chunks
(<a
href="https://redirect.github.com/better-auth/better-auth/pull/10088 ">#10088</a>)</li>
<li>Fixed single-use verification flows (such as magic-link) hanging on
connection-limited database adapters by reusing active transactions (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10070 ">#10070</a>)</li>
<li>Fixed the domain not being included when clearing cross-subdomain
cookies in the <code>last-login-method</code> plugin (<a
href="https://redirect.github.com/better-auth/better-auth/pull/9319 ">#9319</a>)</li>
<li>Fixed the <code>oauth-popup</code> plugin leaking internal OAuth
state keys into <code>additionalData</code> (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10067 ">#10067</a>)</li>
<li>Reverted the headerless session check fix (<a
href="https://redirect.github.com/better-auth/better-auth/pull/10074 ">#10074</a>)</li>
</ul>
<p>For detailed changes, see <a
href="ac4d81df74/packages/better-auth/CHANGELOG.md "><code>CHANGELOG</code></a></p>
<h2><code>auth</code></h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md ">better-auth's
changelog</a>.</em></p>
<blockquote>
<h2>1.6.20</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10121 ">#10121</a>
<a
href="21448b1b77 "><code>21448b1</code></a>
Thanks <a
href="https://github.com/adityachaudhary99 "><code>@adityachaudhary99</code></a>!
- OAuth account-linking and create-user error logs now respect a custom
<code>logger</code> configured in <code>betterAuth()</code>, instead of
always being written to the default console logger.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/9621 ">#9621</a>
<a
href="8ecf23817f "><code>8ecf238</code></a>
Thanks <a
href="https://github.com/dipan-ck "><code>@dipan-ck</code></a>! -
Session refresh no longer emits a cookie Max-Age above the browser's
400-day ceiling when using a database without fractional-second
precision.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/8734 ">#8734</a>
<a
href="930f5341d9 "><code>930f534</code></a>
Thanks <a
href="https://github.com/sleepe229 "><code>@sleepe229</code></a>! -
declare inherited APIError properties to fix TypeScript inference
errors</p>
</li>
<li>
<p>Updated dependencies []:</p>
<ul>
<li><code>@better-auth/core</code><a
href="https://github.com/1 "><code>@1</code></a>.6.20</li>
<li><code>@better-auth/drizzle-adapter</code><a
href="https://github.com/1 "><code>@1</code></a>.6.20</li>
<li><code>@better-auth/kysely-adapter</code><a
href="https://github.com/1 "><code>@1</code></a>.6.20</li>
<li><code>@better-auth/memory-adapter</code><a
href="https://github.com/1 "><code>@1</code></a>.6.20</li>
<li><code>@better-auth/mongo-adapter</code><a
href="https://github.com/1 "><code>@1</code></a>.6.20</li>
<li><code>@better-auth/prisma-adapter</code><a
href="https://github.com/1 "><code>@1</code></a>.6.20</li>
<li><code>@better-auth/telemetry</code><a
href="https://github.com/1 "><code>@1</code></a>.6.20</li>
</ul>
</li>
</ul>
<h2>1.6.19</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10088 ">#10088</a>
<a
href="de4aa52e99 "><code>de4aa52</code></a>
Thanks <a href="https://github.com/bytaesu "><code>@bytaesu</code></a>!
- Session and account cache cookies near the browser's per-cookie size
limit (for example with a long <code>cookiePrefix</code> or many cached
fields) are now split into chunks instead of being silently dropped by
the browser. A cache too large to fit even when chunked is skipped with
a warning rather than failing the request, so reads fall back to the
database.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/9995 ">#9995</a>
<a
href="b4b02660c7 "><code>b4b0266</code></a>
Thanks <a
href="https://github.com/ElGauchooooo "><code>@ElGauchooooo</code></a>!
- The device authorization plugin now accepts an optional
<code>user_id</code> when issuing a device code via
<code>/device/code</code>, pre-binding the code to that user. Only the
bound user can approve or deny the code, so a publicly visible user code
can no longer be claimed by someone else.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10086 ">#10086</a>
<a
href="5bd5e1cc73 "><code>5bd5e1c</code></a>
Thanks <a
href="https://github.com/gustavovalverde "><code>@gustavovalverde</code></a>!
- Refresh-token rotation and token revocation, two-factor backup-code
regeneration, device-code claiming, and organization invitation
acceptance now work on Prisma. Concurrent or repeat requests in these
flows could previously return an error on Prisma instead of the expected
result.</p>
<p>On MongoDB servers older than 5.0, these flows and other guarded
value updates (rate-limit window resets, API-key refills) no longer fail
with an empty-update error.</p>
<p><code>@better-auth/core</code>: <code>incrementOne</code> now reports
a clear error when called with no <code>increment</code> and no
<code>set</code>.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/9319 ">#9319</a>
<a
href="581f8271fb "><code>581f827</code></a>
Thanks <a
href="https://github.com/ping-maxwell "><code>@ping-maxwell</code></a>!
- fix(last-login-method): include domain when clearing cross-subdomain
cookies</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10067 ">#10067</a>
<a
href="840788502a "><code>8407885</code></a>
Thanks <a href="https://github.com/bytaesu "><code>@bytaesu</code></a>!
- The <code>oauth-popup</code> plugin now ignores internal OAuth state
fields passed through its <code>additionalData</code> parameter, so
<code>additionalData</code> only ever carries your own custom
values.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/9555 ">#9555</a>
<a
href="c1a8a64c14 "><code>c1a8a64</code></a>
Thanks <a
href="https://github.com/ChrisMGeo "><code>@ChrisMGeo</code></a>! - Fix
invalid OpenAPI output for Better Auth callback, session, and passkey
routes so client generators can consume the schema.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10071 ">#10071</a>
<a
href="635f190870 "><code>635f190</code></a>
Thanks <a
href="https://github.com/gustavovalverde "><code>@gustavovalverde</code></a>!
- Auth clients exported from wrapper packages can now be emitted in
TypeScript declaration builds without extra type annotations.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/10070 ">#10070</a>
<a
href="a787e0b66b "><code>a787e0b</code></a>
Thanks <a
href="https://github.com/gustavovalverde "><code>@gustavovalverde</code></a>!
- Single-use verification flows no longer hang on database adapters that
use a one-connection pool. This fixes magic-link verification and
similar token checks in connection-limited serverless database
setups.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/9348 ">#9348</a>
<a
href="c2f718fcde "><code>c2f718f</code></a>
Thanks <a
href="https://github.com/ping-maxwell "><code>@ping-maxwell</code></a>!
- fix: cookie cache fallback lookup</p>
</li>
<li>
<p><a
href="https://redirect.github.com/better-auth/better-auth/pull/8863 ">#8863</a>
<a
href="7d18175637 "><code>7d18175</code></a>
Thanks <a
href="https://github.com/ping-maxwell "><code>@ping-maxwell</code></a>!
- <code>sendVerificationEmail</code> was invoked via
<code>runInBackgroundOrAwait</code>, which could defer work when
<code>advanced.backgroundTasks.handler</code> is configured (so the
handler could return <strong>200</strong> before the email callback
finished) and, in the default path, <strong>caught and logged errors
without rethrowing</strong>. User callbacks that throw
<code>APIError</code> (e.g. <strong>429</strong> from a rate limiter)
were therefore not reliably reflected in the HTTP response (<a
href="https://redirect.github.com/better-auth/better-auth/issues/8757 ">better-auth/better-auth#8757</a>).</p>
<p>Now we await <code>sendVerificationEmailFn</code> so failures surface
to the client with the correct status. The unauthenticated
<code>/send-verification-email</code> path enforces a constant-time
floor (500 ms) so that the response duration does not reveal whether the
email belongs to a real unverified user.</p>
</li>
<li>
<p>Updated dependencies [<a
href="08959936d2 "><code>0895993</code></a>,
<a
href="5bd5e1cc73 "><code>5bd5e1c</code></a>,
<a
href="a787e0b66b "><code>a787e0b</code></a>]:</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="c342f42fff "><code>c342f42</code></a>
chore: release v1.6.20 (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10108 ">#10108</a>)</li>
<li><a
href="21448b1b77 "><code>21448b1</code></a>
fix: route account-linking logs through the configured logger (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10121 ">#10121</a>)</li>
<li><a
href="8ecf23817f "><code>8ecf238</code></a>
fix(session): cap refresh cookie Max-Age at expiresIn (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/9621 ">#9621</a>)</li>
<li><a
href="ac4d81df74 "><code>ac4d81d</code></a>
chore: release v1.6.19 (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10034 ">#10034</a>)</li>
<li><a
href="1e69725027 "><code>1e69725</code></a>
docs: clarify stateless Cognito token refresh (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10092 ">#10092</a>)</li>
<li><a
href="de4aa52e99 "><code>de4aa52</code></a>
fix(cookies): chunk session and account cookies near the browser size
limit (...</li>
<li><a
href="5bd5e1cc73 "><code>5bd5e1c</code></a>
fix: make guarded state transitions portable on Prisma (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10086 ">#10086</a>)</li>
<li><a
href="36f345b1bc "><code>36f345b</code></a>
revert: fix: allow headerless get session checks (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10053 ">#10053</a>)
(<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10074 ">#10074</a>)</li>
<li><a
href="635f190870 "><code>635f190</code></a>
fix(client): name auth client return types (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10071 ">#10071</a>)</li>
<li><a
href="d009daedc7 "><code>d009dae</code></a>
fix: allow headerless get session checks (<a
href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10053 ">#10053</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/better-auth/better-auth/commits/v1.6.20/packages/better-auth ">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions ">GitHub Actions</a>, a new
releaser for better-auth since your current version.</p>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Nicky Leach <nicky@paperclip.ing>
Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-06-23 11:01:40 -07:00
dependabot[bot]
65d45688fe
build(deps-dev): bump esbuild from 0.28.0 to 0.28.1 ( #8470 )
...
[//]: # (dependabot-start)
⚠️ **Dependabot is rebasing this PR** ⚠️
Rebasing might not happen immediately, so don't worry if this takes some
time.
Note: if you make any changes to this PR yourself, they will take
precedence over the rebase.
---
[//]: # (dependabot-end)
Bumps [esbuild](https://github.com/evanw/esbuild ) from 0.28.0 to 0.28.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/evanw/esbuild/releases ">esbuild's
releases</a>.</em></p>
<blockquote>
<h2>v0.28.1</h2>
<ul>
<li>
<p>Disallow <code>\</code> in local development server HTTP requests (<a
href="https://github.com/evanw/esbuild/security/advisories/GHSA-g7r4-m6w7-qqqr ">GHSA-g7r4-m6w7-qqqr</a>)</p>
<p>This release fixes a security issue where HTTP requests to esbuild's
local development server could traverse outside of the serve directory
on Windows using a <code>\</code> backslash character. It happened due
to the use of Go's <code>path.Clean()</code> function, which only
handles Unix-style <code>/</code> characters. HTTP requests with paths
containing <code>\</code> are no longer allowed.</p>
<p>Thanks to <a
href="https://github.com/dellalibera "><code>@dellalibera</code></a> for
reporting this issue.</p>
</li>
<li>
<p>Add integrity checks to the Deno API (<a
href="https://github.com/evanw/esbuild/security/advisories/GHSA-gv7w-rqvm-qjhr ">GHSA-gv7w-rqvm-qjhr</a>)</p>
<p>The previous release of esbuild added integrity checks to esbuild's
npm install script. This release also adds integrity checks to esbuild's
Deno install script. Now esbuild's Deno API will also fail with an error
if the downloaded esbuild binary contains something other than the
expected content.</p>
<p>Note that esbuild's Deno API installs from
<code>registry.npmjs.org</code> by default, but allows the
<code>NPM_CONFIG_REGISTRY</code> environment variable to override this
with a custom package registry. This change means that the esbuild
executable served by <code>NPM_CONFIG_REGISTRY</code> must now match the
expected content.</p>
<p>Thanks to <a
href="https://github.com/sondt99 "><code>@sondt99</code></a> for
reporting this issue.</p>
</li>
<li>
<p>Avoid inlining <code>using</code> and <code>await using</code>
declarations (<a
href="https://redirect.github.com/evanw/esbuild/issues/4482 ">#4482</a>)</p>
<p>Previously esbuild's minifier sometimes incorrectly inlined
<code>using</code> and <code>await using</code> declarations into
subsequent uses of that declaration, which then fails to dispose of the
resource correctly. This bug happened because inlining was done for
<code>let</code> and <code>const</code> declarations by avoiding doing
it for <code>var</code> declarations, which no longer worked when more
declaration types were added. Here's an example:</p>
<pre lang="js"><code>// Original code
{
using x = new Resource()
x.activate()
}
<p>// Old output (with --minify)<br />
new Resource().activate();</p>
<p>// New output (with --minify)<br />
{using e=new Resource;e.activate()}<br />
</code></pre></p>
</li>
<li>
<p>Fix module evaluation when an error is thrown (<a
href="https://redirect.github.com/evanw/esbuild/issues/4461 ">#4461</a>,
<a
href="https://redirect.github.com/evanw/esbuild/pull/4467 ">#4467</a>)</p>
<p>If an error is thrown during module evaluation, esbuild previously
didn't preserve the state of the module for subsequent module
references. This was observable if <code>import()</code> or
<code>require()</code> is used to import a module multiple times. The
thrown error is supposed to be thrown by every call to
<code>import()</code> or <code>require()</code>, not just the first.
With this release, esbuild will now throw the same error every time you
call <code>import()</code> or <code>require()</code> on a module that
throws during its evaluation.</p>
</li>
<li>
<p>Fix some edge cases around the <code>new</code> operator (<a
href="https://redirect.github.com/evanw/esbuild/issues/4477 ">#4477</a>)</p>
<p>Previously esbuild incorrectly printed certain edge cases involving
complex expressions inside the target of a <code>new</code> expression
(specifically an optional chain and/or a tagged template literal). The
generated code for the <code>new</code> target was not correctly wrapped
with parentheses, and either contained a syntax error or had different
semantics. These edge cases have been fixed so that they now correctly
wrap the <code>new</code> target in parentheses. Here is an example of
some affected code:</p>
<pre lang="js"><code>// Original code
new (foo()`bar`)()
new (foo()?.bar)()
<p>// Old output<br />
new foo()<code>bar</code>();<br />
new (foo())?.bar();</p>
<p></code></pre></p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/evanw/esbuild/blob/main/CHANGELOG.md ">esbuild's
changelog</a>.</em></p>
<blockquote>
<h2>0.28.1</h2>
<ul>
<li>
<p>Disallow <code>\</code> in local development server HTTP requests (<a
href="https://github.com/evanw/esbuild/security/advisories/GHSA-g7r4-m6w7-qqqr ">GHSA-g7r4-m6w7-qqqr</a>)</p>
<p>This release fixes a security issue where HTTP requests to esbuild's
local development server could traverse outside of the serve directory
on Windows using a <code>\</code> backslash character. It happened due
to the use of Go's <code>path.Clean()</code> function, which only
handles Unix-style <code>/</code> characters. HTTP requests with paths
containing <code>\</code> are no longer allowed.</p>
<p>Thanks to <a
href="https://github.com/dellalibera "><code>@dellalibera</code></a> for
reporting this issue.</p>
</li>
<li>
<p>Add integrity checks to the Deno API (<a
href="https://github.com/evanw/esbuild/security/advisories/GHSA-gv7w-rqvm-qjhr ">GHSA-gv7w-rqvm-qjhr</a>)</p>
<p>The previous release of esbuild added integrity checks to esbuild's
npm install script. This release also adds integrity checks to esbuild's
Deno install script. Now esbuild's Deno API will also fail with an error
if the downloaded esbuild binary contains something other than the
expected content.</p>
<p>Note that esbuild's Deno API installs from
<code>registry.npmjs.org</code> by default, but allows the
<code>NPM_CONFIG_REGISTRY</code> environment variable to override this
with a custom package registry. This change means that the esbuild
executable served by <code>NPM_CONFIG_REGISTRY</code> must now match the
expected content.</p>
<p>Thanks to <a
href="https://github.com/sondt99 "><code>@sondt99</code></a> for
reporting this issue.</p>
</li>
<li>
<p>Avoid inlining <code>using</code> and <code>await using</code>
declarations (<a
href="https://redirect.github.com/evanw/esbuild/issues/4482 ">#4482</a>)</p>
<p>Previously esbuild's minifier sometimes incorrectly inlined
<code>using</code> and <code>await using</code> declarations into
subsequent uses of that declaration, which then fails to dispose of the
resource correctly. This bug happened because inlining was done for
<code>let</code> and <code>const</code> declarations by avoiding doing
it for <code>var</code> declarations, which no longer worked when more
declaration types were added. Here's an example:</p>
<pre lang="js"><code>// Original code
{
using x = new Resource()
x.activate()
}
<p>// Old output (with --minify)<br />
new Resource().activate();</p>
<p>// New output (with --minify)<br />
{using e=new Resource;e.activate()}<br />
</code></pre></p>
</li>
<li>
<p>Fix module evaluation when an error is thrown (<a
href="https://redirect.github.com/evanw/esbuild/issues/4461 ">#4461</a>,
<a
href="https://redirect.github.com/evanw/esbuild/pull/4467 ">#4467</a>)</p>
<p>If an error is thrown during module evaluation, esbuild previously
didn't preserve the state of the module for subsequent module
references. This was observable if <code>import()</code> or
<code>require()</code> is used to import a module multiple times. The
thrown error is supposed to be thrown by every call to
<code>import()</code> or <code>require()</code>, not just the first.
With this release, esbuild will now throw the same error every time you
call <code>import()</code> or <code>require()</code> on a module that
throws during its evaluation.</p>
</li>
<li>
<p>Fix some edge cases around the <code>new</code> operator (<a
href="https://redirect.github.com/evanw/esbuild/issues/4477 ">#4477</a>)</p>
<p>Previously esbuild incorrectly printed certain edge cases involving
complex expressions inside the target of a <code>new</code> expression
(specifically an optional chain and/or a tagged template literal). The
generated code for the <code>new</code> target was not correctly wrapped
with parentheses, and either contained a syntax error or had different
semantics. These edge cases have been fixed so that they now correctly
wrap the <code>new</code> target in parentheses. Here is an example of
some affected code:</p>
<pre lang="js"><code>// Original code
new (foo()`bar`)()
new (foo()?.bar)()
<p>// Old output<br />
new foo()<code>bar</code>();<br />
new (foo())?.bar();<br />
</code></pre></p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="bb9db84c02 "><code>bb9db84</code></a>
publish 0.28.1 to npm</li>
<li><a
href="9ff053e53b "><code>9ff053e</code></a>
security: add integrity checks to the Deno API</li>
<li><a
href="0a9bf2135b "><code>0a9bf21</code></a>
enforce non-negative size in gzip parser</li>
<li><a
href="e2a1a71320 "><code>e2a1a71</code></a>
security: forbid <code>\\</code> in local dev server requests</li>
<li><a
href="83a2cbfc35 "><code>83a2cbf</code></a>
fix <a
href="https://redirect.github.com/evanw/esbuild/issues/4482 ">#4482</a>:
don't inline <code>using</code> declarations</li>
<li><a
href="308ad745d8 "><code>308ad74</code></a>
fix <a
href="https://redirect.github.com/evanw/esbuild/issues/4471 ">#4471</a>:
renaming of nested <code>var</code> declarations</li>
<li><a
href="f013f5f99a "><code>f013f5f</code></a>
fix some typos</li>
<li><a
href="aafd6e48b1 "><code>aafd6e4</code></a>
chore: fix some minor issues in comments (<a
href="https://redirect.github.com/evanw/esbuild/issues/4462 ">#4462</a>)</li>
<li><a
href="15300c30b5 "><code>15300c3</code></a>
follow up: cjs evaluation fixes</li>
<li><a
href="1bda0c31d7 "><code>1bda0c3</code></a>
fix <a
href="https://redirect.github.com/evanw/esbuild/issues/4461 ">#4461</a>,
fix <a
href="https://redirect.github.com/evanw/esbuild/issues/4467 ">#4467</a>:
esm evaluation fixes</li>
<li>Additional commits viewable in <a
href="https://github.com/evanw/esbuild/compare/v0.28.0...v0.28.1 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-23 10:15:23 -07:00