diff --git a/CHANGELOG.md b/CHANGELOG.md index d623b4c0..2f23fa34 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,6 +9,7 @@ and the versioning follows [Semantic Versioning](https://semver.org/). ### ✨ Added +- The code editor is now Monaco 0.56.0 (from 0.55.1), which also drops the outdated sanitizer copy behind most of the open dependency advisories. - The bundled review engine is now pr-agent 0.45.0 (from 0.39.0). Two long-standing local fixes are no longer needed — a single-line file change is rendered correctly upstream now, and a binary file no longer has to be worked around — and its YAML handling is more tolerant of imperfect model output. - Mentions now render as a pill instead of blending into the surrounding text, so it is obvious at a glance when someone is named — on the activity page, in the inline diff comments, in drafts, and in the PR description alike. - Proxy settings now take a list of **direct connections**: hosts that bypass the proxy and connect straight out, so an internal code platform, its git remote, or a self-hosted model stays reachable while everything else still goes through the proxy. Uses the familiar `NO_PROXY` syntax (a domain covers its subdomains), and applies to every outbound path at once — REST, git and the LLM call. diff --git a/CHANGELOG.zh-CN.md b/CHANGELOG.zh-CN.md index d3c62396..008f7183 100644 --- a/CHANGELOG.zh-CN.md +++ b/CHANGELOG.zh-CN.md @@ -9,6 +9,7 @@ ### ✨ 新增 +- 代码编辑器升级至 Monaco 0.56.0(原 0.55.1),同时替换掉了此前多数依赖安全告警所指向的过时清理库副本。 - 内置评审引擎升级至 pr-agent 0.45.0(原 0.39.0)。两处长期存在的本地修补不再需要——单行文件变更在上游已渲染正确,二进制文件也无需再绕开——其 YAML 解析对不规范的模型输出也更宽容。 - @提及 改为胶囊标签展示,不再淹没在正文里,一眼即可看出点到了谁——活动页、内联 diff 评论、草稿与 PR 描述一致生效。 - 代理设置新增**直连地址**列表:列出的地址跳过代理直接连接,内网代码平台、它的 git 远端或自建模型服务因此保持可达,其余流量照常走代理。沿用通行的 `NO_PROXY` 写法(填域名同时覆盖子域),并对所有出站路径一并生效——REST、git 与 LLM 调用。 diff --git a/apps/desktop/package.json b/apps/desktop/package.json index b5ea2309..843b87c3 100644 --- a/apps/desktop/package.json +++ b/apps/desktop/package.json @@ -81,7 +81,7 @@ "i18next": "^26.3.1", "i18next-resources-to-backend": "^1.2.1", "mermaid": "^11.4.0", - "monaco-editor": "^0.55.0", + "monaco-editor": "^0.56.0", "pino": "^9.5.0", "pino-roll": "^3.0.0", "react": "^19.2.0", diff --git a/apps/desktop/src/renderer/src/lib/monaco-setup.ts b/apps/desktop/src/renderer/src/lib/monaco-setup.ts index 811209ff..a06d081f 100644 --- a/apps/desktop/src/renderer/src/lib/monaco-setup.ts +++ b/apps/desktop/src/renderer/src/lib/monaco-setup.ts @@ -5,16 +5,8 @@ // When M1+ actually needs syntax highlighting, import the corresponding language worker on demand. import * as monaco from 'monaco-editor'; -import editorWorker from 'monaco-editor/esm/vs/editor/editor.worker?worker'; +import editorWorker from 'monaco-editor/editor/editor.worker.js?worker'; import { loader } from '@monaco-editor/react'; -// The 4 contribution submodules for "worker-backed language services" (editor.main already loaded them; importing -// again here is only to grab their named-exported *Defaults; ES module singletons won't re-execute). Their runtime -// JS named-exports typescriptDefaults / jsonDefaults / cssDefaults … but the .d.ts is wrongly `export {}` (monaco -// 0.55 ESM bundling defect), so import as namespace and cast via unknown below into the known shapes, without any. -import * as tsLang from 'monaco-editor/esm/vs/language/typescript/monaco.contribution.js'; -import * as jsonLang from 'monaco-editor/esm/vs/language/json/monaco.contribution.js'; -import * as cssLang from 'monaco-editor/esm/vs/language/css/monaco.contribution.js'; -import * as htmlLang from 'monaco-editor/esm/vs/language/html/monaco.contribution.js'; // Third-party editor themes (IStandaloneThemeData shape, vendored from monaco-themes, see editor-themes/NOTICE.md), // registered via defineTheme below for selection. ids align with @meebox/shared EDITOR_THEME_OPTIONS; vs / vs-dark / // hc-* are Monaco built-ins, no registration needed. Vendored in place rather than an npm dependency: monaco-themes' @@ -135,22 +127,19 @@ export function getEditorThemeColors(id: string): EditorThemeColorData | null { * (the window fallback below degrades to pure insurance). The other 80+ languages are pure monarch tokenizer * coloring with no worker backend, unaffected and needing no handling. */ -interface LangServiceDefaults { - // Passing an empty ModeConfiguration (each field is optional, absent = don't register that provider) = turn off all features - setModeConfiguration(modeConfiguration: object): void; -} -// The runtime named exports exist (see each contribution.js's export), but their .d.ts is wrongly `export {}`, so -// cast via unknown into the known *Defaults shape (without any); filter as fallback when a name is missing, so a future monaco rename won't crash. -const defaultsOf = (mod: unknown, names: readonly string[]): LangServiceDefaults[] => - names - .map((n) => (mod as Record)[n]) - .filter((d): d is LangServiceDefaults => typeof d?.setModeConfiguration === 'function'); - +// monaco 0.56.0 moved these language services from `vs/language//monaco.contribution.js` (whose .d.ts was an +// empty `export {}`, forcing a cast through unknown) to typed namespaces on the package entry. Reading them from +// `monaco` is both the supported path and fully typed, so the previous hand-written shape + name lookup is gone. for (const d of [ - ...defaultsOf(tsLang, ['typescriptDefaults', 'javascriptDefaults']), - ...defaultsOf(jsonLang, ['jsonDefaults']), - ...defaultsOf(cssLang, ['cssDefaults', 'scssDefaults', 'lessDefaults']), - ...defaultsOf(htmlLang, ['htmlDefaults', 'handlebarDefaults', 'razorDefaults']), + monaco.typescript.typescriptDefaults, + monaco.typescript.javascriptDefaults, + monaco.json.jsonDefaults, + monaco.css.cssDefaults, + monaco.css.scssDefaults, + monaco.css.lessDefaults, + monaco.html.htmlDefaults, + monaco.html.handlebarDefaults, + monaco.html.razorDefaults, ]) { d.setModeConfiguration({}); } @@ -169,6 +158,13 @@ for (const d of [ * don't affect rendering, and can't be eradicated on the app side → **silently ignored by default** (as known * issues). To diagnose, run `localStorage.setItem('meebox.monacoDebug','1')` in devtools and refresh to see the * details of the swallowed errors. + * + * **Re-checked at monaco 0.56.0: both still present, so this stays.** `Missing requestHandler` is still a plain + * `Promise.reject` from `editorWebWorker.$fmr`, and `TextModel got disposed` still goes through + * `onUnexpectedError(new BugIndicatingError(...))` in `diffEditorWidget` — i.e. they still surface as an + * unhandledrejection and a window error respectively, which is what the two listeners below catch. Re-check on the + * next upgrade rather than assuming: this suppression is deliberately narrow, and outliving its cause would mean + * silently swallowing a message that had become meaningful again. */ const MONACO_DEBUG = (() => { try { diff --git a/package-lock.json b/package-lock.json index 71027e61..f3f5c9ca 100644 --- a/package-lock.json +++ b/package-lock.json @@ -55,7 +55,7 @@ "i18next": "^26.3.1", "i18next-resources-to-backend": "^1.2.1", "mermaid": "^11.4.0", - "monaco-editor": "^0.55.0", + "monaco-editor": "^0.56.0", "pino": "^9.5.0", "pino-roll": "^3.0.0", "react": "^19.2.0", @@ -5852,9 +5852,9 @@ } }, "node_modules/dompurify": { - "version": "3.2.7", - "resolved": "https://registry.npmjs.org/dompurify/-/dompurify-3.2.7.tgz", - "integrity": "sha512-WhL/YuveyGXJaerVlMYGWhvQswa7myDG17P7Vu65EWC05o8vfeNbvNf4d/BOvH99+ZW+LlQsc1GDKMa1vNK6dw==", + "version": "3.4.8", + "resolved": "https://registry.npmjs.org/dompurify/-/dompurify-3.4.8.tgz", + "integrity": "sha512-yb1cEmaOum7wFvOCSQxyfgVlv5D47Rc30iZWoMpbDIWTnJ6grDDQyu2KFJzB2k7u0pMuJcQ1zphH//fFnw2tjQ==", "license": "(MPL-2.0 OR Apache-2.0)", "optionalDependencies": { "@types/trusted-types": "^2.0.7" @@ -9920,12 +9920,12 @@ } }, "node_modules/monaco-editor": { - "version": "0.55.1", - "resolved": "https://registry.npmjs.org/monaco-editor/-/monaco-editor-0.55.1.tgz", - "integrity": "sha512-jz4x+TJNFHwHtwuV9vA9rMujcZRb0CEilTEwG2rRSpe/A7Jdkuj8xPKttCgOh+v/lkHy7HsZ64oj+q3xoAFl9A==", + "version": "0.56.0", + "resolved": "https://registry.npmjs.org/monaco-editor/-/monaco-editor-0.56.0.tgz", + "integrity": "sha512-sXboRm3BeBeLm938eaiyLMe0OxzfXIlZvbv4ir/jVgQy1zDhWjgmny0WoN45fuDKhCCQsYMbBJrv/A6jd8aCUg==", "license": "MIT", "dependencies": { - "dompurify": "3.2.7", + "dompurify": "3.4.8", "marked": "14.0.0" } },