Skip to content

chore(deps): bump the npm-minor-patch group with 61 updates - #1045

Closed
dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-1482c0a728
Closed

dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/npm_and_yarn/npm-minor-patch-1482c0a728

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 16, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-minor-patch group with 61 updates:

Package From To
@actions/languageservice 0.3.55 0.3.58
@actions/workflow-parser 0.3.55 0.3.58
@codemirror/autocomplete 6.20.0 6.20.3
@codemirror/commands 6.10.1 6.10.3
@codemirror/language 6.12.1 6.12.3
@codemirror/legacy-modes 6.5.2 6.5.3
@codemirror/lint 6.9.2 6.9.7
@codemirror/search 6.6.0 6.7.1
@codemirror/state 6.5.4 6.6.0
@codemirror/view 6.39.11 6.43.1
@joplin/turndown-plugin-gfm 1.0.64 1.0.67
@panzoom/panzoom 4.6.1 4.6.2
@tauri-apps/api 2.9.1 2.11.0
@tauri-apps/plugin-dialog 2.6.0 2.7.1
@tauri-apps/plugin-fs 2.4.5 2.5.1
@tauri-apps/plugin-opener 2.5.3 2.5.4
@tauri-apps/plugin-store 2.4.2 2.4.3
@tauri-apps/plugin-updater 2.9.0 2.10.1
@tiptap/core 3.20.0 3.26.1
@tiptap/extension-blockquote 3.20.0 3.26.1
@tiptap/extension-bullet-list 3.20.0 3.26.1
@tiptap/extension-code-block-lowlight 3.20.0 3.26.1
@tiptap/extension-heading 3.20.0 3.26.1
@tiptap/extension-horizontal-rule 3.20.0 3.26.1
@tiptap/extension-image 3.20.0 3.26.1
@tiptap/extension-link 3.20.0 3.26.1
@tiptap/extension-ordered-list 3.20.0 3.26.1
@tiptap/extension-paragraph 3.20.0 3.26.1
@tiptap/extension-table 3.20.0 3.26.1
@tiptap/extension-table-row 3.20.0 3.26.1
@tiptap/pm 3.20.0 3.26.1
@tiptap/react 3.20.0 3.26.1
@tiptap/starter-kit 3.20.0 3.26.1
@xyflow/react 12.10.2 12.11.0
dompurify 3.4.2 3.4.10
katex 0.16.28 0.17.0
mermaid 11.12.2 11.15.0
react 19.2.4 19.2.7
@types/react 19.2.9 19.2.17
react-arborist 3.4.3 3.10.5
react-dom 19.2.4 19.2.7
react-router-dom 7.13.0 7.18.0
turndown 7.2.2 7.2.4
vscode-languageserver-types 3.17.5 3.18.0
yaml 2.8.4 2.9.0
zustand 5.0.10 5.0.14
@hypothesi/tauri-mcp-server 0.7.0 0.11.2
@tailwindcss/vite 4.1.18 4.3.1
@tauri-apps/cli 2.9.6 2.11.2
@vitest/coverage-v8 4.0.16 4.1.9
dependency-cruiser 17.3.9 17.4.3
knip 6.15.0 6.17.1
markdownlint-cli2 0.21.0 0.22.1
tailwindcss 4.1.18 4.3.1
tsx 4.21.0 4.22.4
typescript-eslint 8.54.0 8.61.1
vitest 4.0.16 4.1.9
@modelcontextprotocol/sdk 1.27.1 1.29.0
ws 8.18.3 8.21.0
@yao-pkg/pkg 6.14.1 6.20.0
esbuild 0.27.2 0.28.1

Updates @actions/languageservice from 0.3.55 to 0.3.58

Commits

Updates @actions/workflow-parser from 0.3.55 to 0.3.58

Commits

Updates @codemirror/autocomplete from 6.20.0 to 6.20.3

Changelog

Sourced from @​codemirror/autocomplete's changelog.

6.20.1 (2026-03-02)

Bug fixes

Clicking the horizontal dots at the top/bottom of a list of completion options now moves the selection there, so that more completions become visible.

Commits

Updates @codemirror/commands from 6.10.1 to 6.10.3

Changelog

Sourced from @​codemirror/commands's changelog.

6.10.3 (2026-03-12)

Bug fixes

Make sure selection-extending commands preserve the associativity of the selection head.

6.10.2 (2026-02-06)

Bug fixes

Move the selection to a less surprising place when undoing, moving the selection, redoing, then undoing again.

Commits
  • 6f83cb9 Mark version 6.10.3
  • 8364073 Properly preserve selection associativity in selection-extending commands
  • aa61d5c Add more tests for vertical cursor and selection motion
  • dbae3a1 Mark version 6.10.2
  • beecd58 Use a more reasonable start selection for the inverse of applied history events
  • 0587e5d Add a test cursorLineDown skipping trailing inline widgets
  • fe13f95 Add some more explicit type annotations
  • 2f99b7b Use git+https format for package.json repository field
  • a6196d9 Query configuration at start of line in changeLineComment
  • See full diff in compare view

Updates @codemirror/language from 6.12.1 to 6.12.3

Changelog

Sourced from @​codemirror/language's changelog.

6.12.3 (2026-03-25)

Bug fixes

Fix a crash in bracketMatching when composing at end of document.

6.12.2 (2026-02-25)

Bug fixes

Make sure brackets are highlighted in the initial editor state.

Pause bracket matching updates during composition, to avoid disrupting Mobile Safari's fragile composition handling.

Commits
  • f5af31e Mark version 6.12.3
  • 371c9ba Fix bogus bracket highlighting being generated at end of document
  • 9531899 Remove duplicated slash in forum url in README
  • 2f4e701 Fix forum link in readme
  • b5cd54b Mark version 6.12.2
  • 5f86763 Pause bracket matching updates during composition
  • af8dca9 Properly show matched brackets in the initial editor state
  • 693a25e Use git+https format for package.json repository field
  • See full diff in compare view

Updates @codemirror/legacy-modes from 6.5.2 to 6.5.3

Commits

Updates @codemirror/lint from 6.9.2 to 6.9.7

Changelog

Sourced from @​codemirror/lint's changelog.

6.9.5 (2026-03-02)

Bug fixes

Use more appropriate background colors for the selected diagnostic in dark mode.

6.9.4 (2026-02-11)

Bug fixes

Make sure nextDiagnostic selects entire diagnostics, even when they overlap with other diagnostics.

6.9.3 (2026-01-27)

Bug fixes

Fix an issue where the lint panel inappropriately blocks the default behavior of key combinations with Ctrl, Alt, or Cmd held.

Commits

Updates @codemirror/search from 6.6.0 to 6.7.1

Commits

Updates @codemirror/state from 6.5.4 to 6.6.0

Changelog

Sourced from @​codemirror/state's changelog.

6.6.0 (2026-03-12)

New features

EditorSelection.range now takes an optional assoc argument.

SelectionRange.extend can now be given a third argument to specify associativity.

Commits
  • 821d9b7 Mark version 6.6.0
  • e035c74 Support an assoc argument to EditorSelection.range and SelectionRange.extend
  • eef74db Add type conversions to asArray
  • See full diff in compare view

Updates @codemirror/view from 6.39.11 to 6.43.1

Changelog

Sourced from @​codemirror/view's changelog.

6.41.0 (2026-04-01)

Bug fixes

Fix an issue where EditorView.posAtCoords could incorrectly return a position near a higher element on the line, in mixed-font-size lines.

Expand the workaround for the Webkit bug that causes nonexistent selections to stay visible to be active on non-Safari Webkit browsers.

New features

The new EditorView.cursorScrollMargin facet can now be used to configure the extra space used when scrolling the cursor into view.

6.40.0 (2026-03-12)

Bug fixes

Fix a bug that caused Shift-Enter/Backspace/Delete on iOS to lose the shift modifier when delivered to key event handlers.

Fix an issue where EditorView.moveVertically could move to the wrong place in wrapped lines with a large line height.

Make sure the selection head associativity is properly set for mouse selections made with shift held down.

New features

WidgetType.updateDOM is now called with the previous widget value as third argument.

6.39.17 (2026-03-10)

Bug fixes

Improve touch tap-selection on line wrapping boundaries.

Make drawSelection draw our own selection handles on iOS.

Fix an issue where posAtCoords, when querying line wrapping points, got confused by extra empty client rectangles produced by Safari.

6.39.16 (2026-03-02)

Bug fixes

Perform scroll stabilization on the document or wrapping scrollable elements, when the user scrolls the editor.

Fix an issue where changing decorations right before a composition could end up corrupting the visible DOM.

Fix an issue where some types of text input over a selection would be read as happening in wrong position.

6.39.15 (2026-02-20)

Bug fixes

... (truncated)

Commits

Updates @joplin/turndown-plugin-gfm from 1.0.64 to 1.0.67

Commits

Updates @panzoom/panzoom from 4.6.1 to 4.6.2

Release notes

Sourced from @​panzoom/panzoom's releases.

Release 4.6.2

4.6.2 (2026-04-02)

Commits
  • 1284fbc chore: release 4.6.2
  • cb243f4 chore(deps): upgrade dependencies, including typescript@6 (#699)
  • 4a16877 ci(deps): bump actions/cache from 5.0.3 to 5.0.4 in the github-actions group ...
  • 46c06d4 chore(deps): bump the github-actions group with 3 updates (#696)
  • b36c82f chore(deps): upgrade dependencies (#695)
  • 8a0fbef chore(release): remove dist after release
  • See full diff in compare view

Updates @tauri-apps/api from 2.9.1 to 2.11.0

Release notes

Sourced from @​tauri-apps/api's releases.

@​tauri-apps/api v2.11.0

No known vulnerabilities found

[2.11.0]

New Features

  • 074299c08 (#14307) Add Bring All to Front predefined menu item type
  • a12142a48 (#14357) Add macos support for setting the icon and icon template state in the same step of the main thread, to prevent flickering.
  • 001c8fe3d (#14722) Add a WebView option to control browser-level general autofill behavior. This option does not disable password or credit card autofill. On Windows (WebView2), setting it to true disables the general autofill "Suggestions" UI, which may appear even when autocomplete="off" is specified on input elements. On Linux, macOS, iOS, and Android, this option is currently unsupported and performs no operation.
  • eb0312ea9 (#15199) Propagates the Event::Suspended and Event::Resumed events from tao when they are emitted on mobile targets.
> @tauri-apps/api@2.11.0 npm-publish /home/runner/work/tauri/tauri/packages/api
> pnpm build && cd ./dist && pnpm publish --access public --loglevel silly --no-git-checks

> @​tauri-apps/api@​2.11.0 build /home/runner/work/tauri/tauri/packages/api > rollup -c --configPlugin typescript

�[36m �[1m./src/app.ts, ./src/core.ts, ./src/dpi.ts, ./src/event.ts, ./src/image.ts, ./src/index.ts, ./src/menu.ts, ./src/mocks.ts, ./src/path.ts, ./src/tray.ts, ./src/webview.ts, ./src/webviewWindow.ts, ./src/window.ts�[22m → �[1m./dist, ./dist�[22m...�[39m �[32mcreated �[1m./dist, ./dist�[22m in �[1m1s�[22m�[39m �[36m �[1msrc/index.ts�[22m → �[1m../../crates/tauri/scripts/bundle.global.js�[22m...�[39m �[32mcreated �[1m../../crates/tauri/scripts/bundle.global.js�[22m in �[1m1.6s�[22m�[39m npm verbose cli /opt/hostedtoolcache/node/24.14.1/x64/bin/node /opt/hostedtoolcache/node/24.14.1/x64/bin/npm npm info using npm@11.11.0 npm info using node@v24.14.1 npm silly config load:file:/opt/hostedtoolcache/node/24.14.1/x64/lib/node_modules/npm/npmrc npm silly config load:file:/tmp/62753b73fd2498862aee9b07ed29cc21/.npmrc npm silly config load:file:/home/runner/.npmrc npm silly config load:file:/home/runner/.config/pnpm/rc npm verbose title npm publish tauri-apps-api-2.11.0.tgz npm verbose argv "publish" "--ignore-scripts" "tauri-apps-api-2.11.0.tgz" "--access" "public" "--loglevel" "silly" npm verbose logfile logs-max:10 dir:/home/runner/.npm/_logs/2026-04-30T15_51_13_171Z- npm verbose logfile /home/runner/.npm/_logs/2026-04-30T15_51_13_171Z-debug-0.log npm warn Unknown env config "verify-deps-before-run". This will stop working in the next major version of npm. See npm help npmrc for supported config options. npm warn Unknown env config "npm-globalconfig". This will stop working in the next major version of npm. See npm help npmrc for supported config options. npm warn Unknown env config "_jsr-registry". This will stop working in the next major version of npm. See npm help npmrc for supported config options. </tr></table>

... (truncated)

Commits
  • e60834f Apply Version Updates From Current Changes (#15041)
  • df05c00 chore: minor bump for codegen crate
  • 13bea17 chore: fmt
  • 9808236 fix(macOS): correct value for work_area.position.y (#14655)
  • eb0312e feat(mobile): Propagate tao::Event::Suspended and tao::Event::Resumed to the ...
  • 4ef5797 feat(ios): add --no-sign and --archive-only flags to ios build (#15061)
  • 110336c fix(macOS): fix incorrect window position on multi-monitor setups (#15250)
  • c00a3db feat(macros): add support for rename command macro in tauri-macros #14173 (#1...
  • 764b913 feat(cli): restart Android emulator if it is disconnected from adb (#14313)
  • 1035f12 fix(windows): tauri-bundler detect arm system (#14923)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​tauri-apps/api since your current version.


Updates @tauri-apps/plugin-dialog from 2.6.0 to 2.7.1

Release notes

Sourced from @​tauri-apps/plugin-dialog's releases.

dialog-js v2.7.1

[2.7.1]

Dependencies

  • Upgraded to fs-js@2.5.1
npm warn Unknown user config "always-auth". This will stop working in the next major version of npm. See `npm help npmrc` for supported config options.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-dialog@2.7.1
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 3.5kB README.md
npm notice 6.9kB dist-js/index.cjs
npm notice 14.6kB dist-js/index.d.ts
npm notice 6.8kB dist-js/index.js
npm notice 11B dist-js/init.d.ts
npm notice 657B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-dialog
npm notice version: 2.7.1
npm notice filename: tauri-apps-plugin-dialog-2.7.1.tgz
npm notice package size: 6.7 kB
npm notice unpacked size: 33.3 kB
npm notice shasum: fc83387de807c8d064d2b64b1b813b84e8286a12
npm notice integrity: sha512-OK1UBXYt+ojcm[...]FmEOjIY9IhzOQ==
npm notice total files: 7
npm notice
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=1429011725
+ @tauri-apps/plugin-dialog@2.7.1

dialog v2.7.1

[2.7.1]

Dependencies

  • Upgraded to fs-js@2.5.1

... (truncated)

Commits
  • e7a68fa publish new versions (#3068)
  • b5550a3 chore: temp delete updater changefile
  • 93426f8 fix: fix docsrs builds
  • 4ee61e0 Revert "chore: temp delete updater changefile"
  • 06124af publish new versions (#2972)
  • 060219e chore(deps): update dependency @​rollup/plugin-typescript to v12.3.0 (#3067)
  • c7e9766 chore(deps): update tauri monorepo (v2) (#3058)
  • d4a8ce9 chore(deps): update rust crate tokio-tungstenite to 0.28 (#3016)
  • cdc7eec chore(deps): update dependency @​rollup/plugin-typescript to v12.2.0 (#3066)
  • 6314b00 chore: temp delete updater changefile
  • Additional commits viewable in compare view

Updates @tauri-apps/plugin-fs from 2.4.5 to 2.5.1

Release notes

Sourced from @​tauri-apps/plugin-fs's releases.

fs-js v2.5.1

[2.5.1]

npm warn Unknown user config "always-auth". This will stop working in the next major version of npm. See `npm help npmrc` for supported config options.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-fs@2.5.1
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 2.4kB README.md
npm notice 32.8kB dist-js/index.cjs
npm notice 32.6kB dist-js/index.d.ts
npm notice 32.0kB dist-js/index.js
npm notice 697B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-fs
npm notice version: 2.5.1
npm notice filename: tauri-apps-plugin-fs-2.5.1.tgz
npm notice package size: 21.5 kB
npm notice unpacked size: 101.5 kB
npm notice shasum: e1b8643d41c74251699fcdecc800877d18a4a6fc
npm notice integrity: sha512-9Lz+Jopp6QyeE[...]tqPB/XEMS3NhQ==
npm notice total files: 6
npm notice
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=1429011689
+ @tauri-apps/plugin-fs@2.5.1

fs v2.5.1

[2.5.1]

</tr></table> 

... (truncated)

Commits
  • 5c7668b publish new versions (#3397)
  • ec05401 chore(deps): update rust crate toml to v1 (#3323)
  • b86e999 chore(deps): update tauri packages to 2.11 (#3407)
  • c463d8a chore(deps): update rustls-webpki in lockfile, ignore core2 in audit (#3405)
  • 1bb7beb chore(deps): bump openssl (#3402)
  • 3412fa2 docs(readme): fix platform support matrix (opener supports mobile)
  • af81fda docs(readme): fix platform support matrix (mobile is supported)
  • c1fd33b fix(opener): allow open network share locations (#3343)
  • 250857b chore(deps): update dependency typescript to v6 (#3363)
  • 964e13f fix(store): dead lock trying to set while exiting (#3395)
  • Additional commits viewable in compare view

Updates @tauri-apps/plugin-opener from 2.5.3 to 2.5.4

Release notes

Sourced from @​tauri-apps/plugin-opener's releases.

opener-js v2.5.4

[2.5.4]

npm warn Unknown user config "always-auth". This will stop working in the next major version of npm. See `npm help npmrc` for supported config options.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-opener@2.5.4
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 4.2kB README.md
npm notice 3.1kB dist-js/index.cjs
npm notice 2.0kB dist-js/index.d.ts
npm notice 3.1kB dist-js/index.js
npm notice 11B dist-js/init.d.ts
npm notice 730B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-opener
npm notice version: 2.5.4
npm notice filename: tauri-apps-plugin-opener-2.5.4.tgz
npm notice package size: 3.5 kB
npm notice unpacked size: 14.1 kB
npm notice shasum: b37883e4d36125b8c5a0c74f683395958a65bd7d
npm notice integrity: sha512-1HnPkb+AmgO29[...]aUJtT57lfO9CQ==
npm notice total files: 7
npm notice
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=1429011743
+ @tauri-apps/plugin-opener@2.5.4

opener v2.5.4

[2.5.4]

... (truncated)

Commits

Updates @tauri-apps/plugin-store from 2.4.2 to 2.4.3

Release notes

Sourced from @​tauri-apps/plugin-store's releases.

barcode-scanner-js v2.4.3

[2.4.3]

npm warn Unknown user config "always-auth". This will stop working in the next major version of npm.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-barcode-scanner@2.4.3
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 3.3kB README.md
npm notice 2.2kB dist-js/index.cjs
npm notice 1.6kB dist-js/index.d.ts
npm notice 2.1kB dist-js/index.js
npm notice 754B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-barcode-scanner
npm notice version: 2.4.3
npm notice filename: tauri-apps-plugin-barcode-scanner-2.4.3.tgz
npm notice package size: 3.4 kB
npm notice unpacked size: 10.9 kB
npm notice shasum: a401570d2698692fa6878bd816122ac3f8d7142d
npm notice integrity: sha512-y5jIRTFqCeUnc[...]cJWhCfKu6qOQA==
npm notice total files: 6
npm notice
npm notice Security Notice: Classic tokens have been revoked. Granular tokens are now limited to 90 days and require 2FA by default. Update your CI/CD workflows to avoid disruption. Learn more https://gh.io/all-npm-classic-tokens-revoked
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=804717978
+ @tauri-apps/plugin-barcode-scanner@2.4.3

barcode-scanner v2.4.3

[2.4.3]

... (truncated)

Commits
  • 06124af publish new versions (#2972)
  • 060219e chore(deps): update dependency @​rollup/plugin-typescript to v12.3.0 (#3067)
  • c7e9766 chore(deps): update tauri monorepo (v2) (#3058)
  • d4a8ce9 chore(deps): update rust crate tokio-tungstenite to 0.28 (#3016)
  • cdc7eec chore(deps): update dependency @​rollup/plugin-typescript to v12.2.0 (#3066)
  • 6314b00 chore: temp delete updater changefile
  • fb4c8ae chore(deps): update dependency typescript-eslint to v8.46.2 (#3060)
  • fccc1cf chore(deps): update eslint monorepo to v9.38.0 (#3044)
  • 3702308 chore(deps): update dependency rollup to v4.52.5 (#3043)
  • c9c8b39 chore(deps): update dependency typescript-eslint to v8.46.1 (#3025)
  • Additional commits viewable in compare view

Updates @tauri-apps/plugin-updater from 2.9.0 to 2.10.1

Release notes

Sourced from @​tauri-apps/plugin-updater's releases.

updater-js v2.10.1

[2.10.1]

  • 31ab6f8d (#3285 by @​hrzlgnm) fix: preserve file extension of updater package, otherwise users may get confused when presented with a sudo dialog suggesting to install a file with the extension .rpm using dpkg -i
npm warn Unknown user config "always-auth". This will stop working in the next major version of npm. See `npm help npmrc` for supported config options.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-updater@2.10.1
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 3.1kB README.md
npm notice 2.6kB dist-js/index.cjs
npm notice 2.3kB dist-js/index.d.ts
npm notice 2.6kB dist-js/index.js
npm notice 659B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-updater
npm notice version: 2.10.1
npm notice filename: tauri-apps-plugin-updater-2.10.1.tgz
npm notice package size: 3.7 kB
npm notice unpacked size: 12.1 kB
npm notice shasum: ea0efd766890394b6c719b9fc21de7da0029c69c
npm notice integrity: sha512-NFYMg+tWOZPJd[...]Y1WVCNHnh3eRA==
npm notice total files: 6
npm notice
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=1235993797
+ @tauri-apps/plugin-updater@2.10.1

updater v2.10.1

[2.10.1]

  • 31ab6f8d (#3285 by @​hrzlgnm) fix: preserve file extension of updater package, otherwise users may get confused when presented with a sudo dialog suggesting to install a file with the extension .rpm using dpkg -i
</tr></table> 

... (truncated)

Commits
  • d6a3898 Publish New Versions (v2) (#3268)
  • 2e5bcdf chore(deps): fix audits (#3373)
  • 4374b4f chore(notification): remove unused dev-deps (#3372)
  • f75d21d chore(deps): remove used of tauri-utils build feature (#3360)
  • 4b95f5e chore(deps): update dependency eslint to v10.1.0 (#3357)
  • 99c3e37 chore(deps): bump tar in /plugins/updater/tests/updater-migration/v1-app (#3352)
  • eaac19a chore(deps): update rust crate tar to v0.4.45 [security] (#3353)
  • 5183e31 chore(deps): update dependency typescript-eslint to v8.57.1 (#3344)
  • 2c0883e chore(deps): update dependency vite to v8 (#3346)
  • 024ec0c fix(deep-link): ChromeOS deep link calls filtered and ignored by plugin (fix ...
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​tauri-apps/plugin-updater since your current version.


Updates @tiptap/core from 3.20.0 to 3.26.1

Release notes

Sourced from @​tiptap/core's releases.

v3.26.1

@​tiptap/extension-node-range

Patch Changes

  • a38c9c0: Fixed drag-and-drop duplicating blocks during collaboration. When a remote collaborator edited the document mid-drag, dropping left an empty copy of the dragged block at its original position. This fix also requires a version of @tiptap/y-tiptap that restores node range selections across remote updates.
  • a38c9c0: Bump @tiptap/y-tiptap to version ^3.0.5
  • @​tiptap/core@​3.26.1
    • @​tiptap/pm@​3.26.1

@​tiptap/extension-drag-handle

Patch Changes

  • a38c9c0: Restore the node range selection after dragging multiple blocks. Previously, dropping a multi-block drag left a text selection inside the moved content instead of keeping the dragged blocks selected.
  • a38c9c0: Bump @tiptap/y-tiptap to version ^3.0.5
  • Updated dependencies [a38c9c0]
  • Updated dependencies [a38c9c0]
    • @​tiptap/extension-node-range@​3.26.1
    • @​tiptap/extension-collaboration@​3.26.1
    • @​tiptap/core@​3.26.1
    • @​tiptap/pm@​3.26.1

@​tiptap/extension-collaboration-caret

Patch Changes

  • a38c9c0: Bump @tiptap/y-tiptap to version ^3.0.5
  • @​tiptap/core@​3.26.1
    • @​tiptap/pm@​3.26.1

@​tiptap/extension-collaboration

Patch Changes

  • a38c9c0: Bump @tiptap/y-tiptap to version ^3.0.5
  • @​tiptap/core@​3.26.1
    • @​tiptap/pm@​3.26.1

v3.26.0

@​tiptap/extension-blockquote

Minor Changes

  • 7fb19eb: Backspace at the start of a non-first child of a blockquote now lifts that child out, splitting the blockquote around it. A second backspace at the start of a top-level textblock whose previous sibling is a blockquote merges the textblock's inline content into the blockquote's last textblock instead of pulling the paragraph back inside.

Patch Changes

  • @​tiptap/core@​3.26.0

... (truncated)

Changelog

Sourced from @​tiptap/core's changelog.

3.26.1

Patch Changes

  • @​tiptap/pm@​3.26.1

3.26.0

Patch Changes

  • @​tiptap/pm@​3.26.0

3.25.0

Patch Changes

  • ec291dd: Fix: dragging an inline/resizable image within the editor no longer creates a duplicate

    When the Image extension was configured with inline: true or resize enabled, dragging an image within the editor could insert a duplicate at the drop position instead of moving it. This happened because the browser's native image drag behavior could populate dataTransfer.files, causing the FileHandler extension to intercept the drop before ProseMirror's internal move logic could run.

  • 454e9b8: Add clearable mark option (default true). unsetAllMarks now skips marks with clearable: false, so semantic marks like comments are not removed by "clear formatting".

  • 9cf8db0: Add attrsEqual and marksEqual utility functions to @tiptap/core. attrsEqual compares two attribute objects for equality regardless of key ordering. marksEqual compares two arrays of mark objects by type and attributes using attrsEqual.

  • 3d4f94c: Fix plain-text copy of table cell selections including content from unselected cells in between. Each selected range is now serialized independently and joined in document order, so dragging upward (reverse selection) also produces output in document order.

  • Updated dependencies [c1a2ce8]

    • @​tiptap/pm@​3.25.0

3.24.0

Patch Changes

  • Updated dependencies [7c0499b]
    • @​tiptap/pm@​3.24.0

3.23.6

Patch Changes

  • d168376: Fix deleteSelection to properly handle inline nodes with text* content. The selection is now expanded to include the entire inline node boundaries when deleting, preventing incorrect collapse of inline text nodes.
    • @​tiptap/pm@​3.23.6

3.23.5

Patch Changes

  • 835caf5: Fix $pos() returning correct node for non-text atom nodes instead of doc node

  • 95e138c: fix(nodeview): eliminate unnecessary re-renders, add opt-in position tracking

    NodeViews no longer re-render when decorations or position change without content changes. Added trackNodeViewPosition option — when enabled, the component re-renders on every position shift so calls to getPos() stay

... (truncated)

Commits
  • 6c1efd3 chore(release): publish a new stable version (#7934)
  • 2477351 chore(release): publish a new stable version
  • 5d50336 chore(release): publish a new stable ve...

    Description has been truncated

Bumps the npm-minor-patch group with 61 updates:

| Package | From | To |
| --- | --- | --- |
| [@actions/languageservice](https://github.com/actions/languageservices) | `0.3.55` | `0.3.58` |
| [@actions/workflow-parser](https://github.com/actions/languageservices) | `0.3.55` | `0.3.58` |
| [@codemirror/autocomplete](https://github.com/codemirror/autocomplete) | `6.20.0` | `6.20.3` |
| [@codemirror/commands](https://github.com/codemirror/commands) | `6.10.1` | `6.10.3` |
| [@codemirror/language](https://github.com/codemirror/language) | `6.12.1` | `6.12.3` |
| [@codemirror/legacy-modes](https://github.com/codemirror/legacy-modes) | `6.5.2` | `6.5.3` |
| [@codemirror/lint](https://github.com/codemirror/lint) | `6.9.2` | `6.9.7` |
| [@codemirror/search](https://github.com/codemirror/search) | `6.6.0` | `6.7.1` |
| [@codemirror/state](https://github.com/codemirror/state) | `6.5.4` | `6.6.0` |
| [@codemirror/view](https://github.com/codemirror/view) | `6.39.11` | `6.43.1` |
| [@joplin/turndown-plugin-gfm](https://github.com/laurent22/joplin-turndown-plugin-gfm) | `1.0.64` | `1.0.67` |
| [@panzoom/panzoom](https://github.com/timmywil/panzoom) | `4.6.1` | `4.6.2` |
| [@tauri-apps/api](https://github.com/tauri-apps/tauri) | `2.9.1` | `2.11.0` |
| [@tauri-apps/plugin-dialog](https://github.com/tauri-apps/plugins-workspace) | `2.6.0` | `2.7.1` |
| [@tauri-apps/plugin-fs](https://github.com/tauri-apps/plugins-workspace) | `2.4.5` | `2.5.1` |
| [@tauri-apps/plugin-opener](https://github.com/tauri-apps/plugins-workspace) | `2.5.3` | `2.5.4` |
| [@tauri-apps/plugin-store](https://github.com/tauri-apps/plugins-workspace) | `2.4.2` | `2.4.3` |
| [@tauri-apps/plugin-updater](https://github.com/tauri-apps/plugins-workspace) | `2.9.0` | `2.10.1` |
| [@tiptap/core](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core) | `3.20.0` | `3.26.1` |
| [@tiptap/extension-blockquote](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-blockquote) | `3.20.0` | `3.26.1` |
| [@tiptap/extension-bullet-list](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-bullet-list) | `3.20.0` | `3.26.1` |
| [@tiptap/extension-code-block-lowlight](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-code-block-lowlight) | `3.20.0` | `3.26.1` |
| [@tiptap/extension-heading](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-heading) | `3.20.0` | `3.26.1` |
| [@tiptap/extension-horizontal-rule](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-horizontal-rule) | `3.20.0` | `3.26.1` |
| [@tiptap/extension-image](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-image) | `3.20.0` | `3.26.1` |
| [@tiptap/extension-link](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-link) | `3.20.0` | `3.26.1` |
| [@tiptap/extension-ordered-list](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-ordered-list) | `3.20.0` | `3.26.1` |
| [@tiptap/extension-paragraph](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-paragraph) | `3.20.0` | `3.26.1` |
| [@tiptap/extension-table](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-table) | `3.20.0` | `3.26.1` |
| [@tiptap/extension-table-row](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-table-row) | `3.20.0` | `3.26.1` |
| [@tiptap/pm](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/pm) | `3.20.0` | `3.26.1` |
| [@tiptap/react](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/react) | `3.20.0` | `3.26.1` |
| [@tiptap/starter-kit](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/starter-kit) | `3.20.0` | `3.26.1` |
| [@xyflow/react](https://github.com/xyflow/xyflow/tree/HEAD/packages/react) | `12.10.2` | `12.11.0` |
| [dompurify](https://github.com/cure53/DOMPurify) | `3.4.2` | `3.4.10` |
| [katex](https://github.com/KaTeX/KaTeX) | `0.16.28` | `0.17.0` |
| [mermaid](https://github.com/mermaid-js/mermaid) | `11.12.2` | `11.15.0` |
| [react](https://github.com/facebook/react/tree/HEAD/packages/react) | `19.2.4` | `19.2.7` |
| [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react) | `19.2.9` | `19.2.17` |
| [react-arborist](https://github.com/jameskerr/react-arborist) | `3.4.3` | `3.10.5` |
| [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) | `19.2.4` | `19.2.7` |
| [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom) | `7.13.0` | `7.18.0` |
| [turndown](https://github.com/mixmark-io/turndown) | `7.2.2` | `7.2.4` |
| [vscode-languageserver-types](https://github.com/Microsoft/vscode-languageserver-node/tree/HEAD/types) | `3.17.5` | `3.18.0` |
| [yaml](https://github.com/eemeli/yaml) | `2.8.4` | `2.9.0` |
| [zustand](https://github.com/pmndrs/zustand) | `5.0.10` | `5.0.14` |
| [@hypothesi/tauri-mcp-server](https://github.com/hypothesi/mcp-server-tauri/tree/HEAD/packages/mcp-server) | `0.7.0` | `0.11.2` |
| [@tailwindcss/vite](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-vite) | `4.1.18` | `4.3.1` |
| [@tauri-apps/cli](https://github.com/tauri-apps/tauri) | `2.9.6` | `2.11.2` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `4.0.16` | `4.1.9` |
| [dependency-cruiser](https://github.com/sverweij/dependency-cruiser) | `17.3.9` | `17.4.3` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.15.0` | `6.17.1` |
| [markdownlint-cli2](https://github.com/DavidAnson/markdownlint-cli2) | `0.21.0` | `0.22.1` |
| [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) | `4.1.18` | `4.3.1` |
| [tsx](https://github.com/privatenumber/tsx) | `4.21.0` | `4.22.4` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.54.0` | `8.61.1` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `4.0.16` | `4.1.9` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.27.1` | `1.29.0` |
| [ws](https://github.com/websockets/ws) | `8.18.3` | `8.21.0` |
| [@yao-pkg/pkg](https://github.com/yao-pkg/pkg) | `6.14.1` | `6.20.0` |
| [esbuild](https://github.com/evanw/esbuild) | `0.27.2` | `0.28.1` |


Updates `@actions/languageservice` from 0.3.55 to 0.3.58
- [Release notes](https://github.com/actions/languageservices/releases)
- [Commits](actions/languageservices@release-v0.3.55...release-v0.3.58)

Updates `@actions/workflow-parser` from 0.3.55 to 0.3.58
- [Release notes](https://github.com/actions/languageservices/releases)
- [Commits](actions/languageservices@release-v0.3.55...release-v0.3.58)

Updates `@codemirror/autocomplete` from 6.20.0 to 6.20.3
- [Changelog](https://github.com/codemirror/autocomplete/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/autocomplete/commits)

Updates `@codemirror/commands` from 6.10.1 to 6.10.3
- [Changelog](https://github.com/codemirror/commands/blob/main/CHANGELOG.md)
- [Commits](codemirror/commands@6.10.1...6.10.3)

Updates `@codemirror/language` from 6.12.1 to 6.12.3
- [Changelog](https://github.com/codemirror/language/blob/main/CHANGELOG.md)
- [Commits](codemirror/language@6.12.1...6.12.3)

Updates `@codemirror/legacy-modes` from 6.5.2 to 6.5.3
- [Changelog](https://github.com/codemirror/legacy-modes/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/legacy-modes/commits)

Updates `@codemirror/lint` from 6.9.2 to 6.9.7
- [Changelog](https://github.com/codemirror/lint/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/lint/commits)

Updates `@codemirror/search` from 6.6.0 to 6.7.1
- [Changelog](https://github.com/codemirror/search/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/search/commits)

Updates `@codemirror/state` from 6.5.4 to 6.6.0
- [Changelog](https://github.com/codemirror/state/blob/main/CHANGELOG.md)
- [Commits](codemirror/state@6.5.4...6.6.0)

Updates `@codemirror/view` from 6.39.11 to 6.43.1
- [Changelog](https://github.com/codemirror/view/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/view/commits)

Updates `@joplin/turndown-plugin-gfm` from 1.0.64 to 1.0.67
- [Commits](https://github.com/laurent22/joplin-turndown-plugin-gfm/commits)

Updates `@panzoom/panzoom` from 4.6.1 to 4.6.2
- [Release notes](https://github.com/timmywil/panzoom/releases)
- [Commits](timmywil/panzoom@4.6.1...4.6.2)

Updates `@tauri-apps/api` from 2.9.1 to 2.11.0
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](https://github.com/tauri-apps/tauri/compare/@tauri-apps/api-v2.9.1...@tauri-apps/api-v2.11.0)

Updates `@tauri-apps/plugin-dialog` from 2.6.0 to 2.7.1
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@log-v2.6.0...log-v2.7.1)

Updates `@tauri-apps/plugin-fs` from 2.4.5 to 2.5.1
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@fs-v2.4.5...fs-v2.5.1)

Updates `@tauri-apps/plugin-opener` from 2.5.3 to 2.5.4
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@http-v2.5.3...http-v2.5.4)

Updates `@tauri-apps/plugin-store` from 2.4.2 to 2.4.3
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@fs-v2.4.2...fs-v2.4.3)

Updates `@tauri-apps/plugin-updater` from 2.9.0 to 2.10.1
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@updater-v2.9.0...updater-v2.10.1)

Updates `@tiptap/core` from 3.20.0 to 3.26.1
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/core/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.26.1/packages/core)

Updates `@tiptap/extension-blockquote` from 3.20.0 to 3.26.1
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/extension-blockquote/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.26.1/packages/extension-blockquote)

Updates `@tiptap/extension-bullet-list` from 3.20.0 to 3.26.1
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/extension-bullet-list/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.26.1/packages/extension-bullet-list)

Updates `@tiptap/extension-code-block-lowlight` from 3.20.0 to 3.26.1
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/extension-code-block-lowlight/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.26.1/packages/extension-code-block-lowlight)

Updates `@tiptap/extension-heading` from 3.20.0 to 3.26.1
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/extension-heading/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.26.1/packages/extension-heading)

Updates `@tiptap/extension-horizontal-rule` from 3.20.0 to 3.26.1
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/extension-horizontal-rule/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.26.1/packages/extension-horizontal-rule)

Updates `@tiptap/extension-image` from 3.20.0 to 3.26.1
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/extension-image/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.26.1/packages/extension-image)

Updates `@tiptap/extension-link` from 3.20.0 to 3.26.1
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/extension-link/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.26.1/packages/extension-link)

Updates `@tiptap/extension-ordered-list` from 3.20.0 to 3.26.1
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/extension-ordered-list/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.26.1/packages/extension-ordered-list)

Updates `@tiptap/extension-paragraph` from 3.20.0 to 3.26.1
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/extension-paragraph/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.26.1/packages/extension-paragraph)

Updates `@tiptap/extension-table` from 3.20.0 to 3.26.1
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/extension-table/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.26.1/packages/extension-table)

Updates `@tiptap/extension-table-row` from 3.20.0 to 3.26.1
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.26.1/packages/extension-table-row)

Updates `@tiptap/pm` from 3.20.0 to 3.26.1
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/pm/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.26.1/packages/pm)

Updates `@tiptap/react` from 3.20.0 to 3.26.1
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/react/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.26.1/packages/react)

Updates `@tiptap/starter-kit` from 3.20.0 to 3.26.1
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/starter-kit/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.26.1/packages/starter-kit)

Updates `@xyflow/react` from 12.10.2 to 12.11.0
- [Release notes](https://github.com/xyflow/xyflow/releases)
- [Changelog](https://github.com/xyflow/xyflow/blob/main/packages/react/CHANGELOG.md)
- [Commits](https://github.com/xyflow/xyflow/commits/@xyflow/react@12.11.0/packages/react)

Updates `dompurify` from 3.4.2 to 3.4.10
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.2...3.4.10)

Updates `katex` from 0.16.28 to 0.17.0
- [Release notes](https://github.com/KaTeX/KaTeX/releases)
- [Changelog](https://github.com/KaTeX/KaTeX/blob/main/CHANGELOG.md)
- [Commits](KaTeX/KaTeX@v0.16.28...v0.17.0)

Updates `mermaid` from 11.12.2 to 11.15.0
- [Release notes](https://github.com/mermaid-js/mermaid/releases)
- [Commits](https://github.com/mermaid-js/mermaid/compare/mermaid@11.12.2...mermaid@11.15.0)

Updates `react` from 19.2.4 to 19.2.7
- [Release notes](https://github.com/facebook/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/facebook/react/commits/v19.2.7/packages/react)

Updates `@types/react` from 19.2.9 to 19.2.17
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `react-arborist` from 3.4.3 to 3.10.5
- [Release notes](https://github.com/jameskerr/react-arborist/releases)
- [Changelog](https://github.com/jameskerr/react-arborist/blob/main/CHANGELOG.md)
- [Commits](jameskerr/react-arborist@v3.4.3...v3.10.5)

Updates `react-dom` from 19.2.4 to 19.2.7
- [Release notes](https://github.com/facebook/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/facebook/react/commits/v19.2.7/packages/react-dom)

Updates `react-router-dom` from 7.13.0 to 7.18.0
- [Release notes](https://github.com/remix-run/react-router/releases)
- [Changelog](https://github.com/remix-run/react-router/blob/main/packages/react-router-dom/CHANGELOG.md)
- [Commits](https://github.com/remix-run/react-router/commits/react-router-dom@7.18.0/packages/react-router-dom)

Updates `turndown` from 7.2.2 to 7.2.4
- [Release notes](https://github.com/mixmark-io/turndown/releases)
- [Commits](mixmark-io/turndown@v7.2.2...v7.2.4)

Updates `vscode-languageserver-types` from 3.17.5 to 3.18.0
- [Release notes](https://github.com/Microsoft/vscode-languageserver-node/releases)
- [Commits](https://github.com/Microsoft/vscode-languageserver-node/commits/release/types/3.18.0/types)

Updates `yaml` from 2.8.4 to 2.9.0
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.8.4...v2.9.0)

Updates `zustand` from 5.0.10 to 5.0.14
- [Release notes](https://github.com/pmndrs/zustand/releases)
- [Commits](pmndrs/zustand@v5.0.10...v5.0.14)

Updates `@hypothesi/tauri-mcp-server` from 0.7.0 to 0.11.2
- [Release notes](https://github.com/hypothesi/mcp-server-tauri/releases)
- [Changelog](https://github.com/hypothesi/mcp-server-tauri/blob/main/packages/mcp-server/CHANGELOG.md)
- [Commits](https://github.com/hypothesi/mcp-server-tauri/commits/v0.11.2/packages/mcp-server)

Updates `@tailwindcss/vite` from 4.1.18 to 4.3.1
- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)
- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.3.1/packages/@tailwindcss-vite)

Updates `@tauri-apps/cli` from 2.9.6 to 2.11.2
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](https://github.com/tauri-apps/tauri/compare/@tauri-apps/cli-v2.9.6...@tauri-apps/cli-v2.11.2)

Updates `@types/react` from 19.2.9 to 19.2.17
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `@vitest/coverage-v8` from 4.0.16 to 4.1.9
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.9/packages/coverage-v8)

Updates `dependency-cruiser` from 17.3.9 to 17.4.3
- [Release notes](https://github.com/sverweij/dependency-cruiser/releases)
- [Changelog](https://github.com/sverweij/dependency-cruiser/blob/main/CHANGELOG.md)
- [Commits](sverweij/dependency-cruiser@v17.3.9...v17.4.3)

Updates `knip` from 6.15.0 to 6.17.1
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.17.1/packages/knip)

Updates `markdownlint-cli2` from 0.21.0 to 0.22.1
- [Changelog](https://github.com/DavidAnson/markdownlint-cli2/blob/main/CHANGELOG.md)
- [Commits](DavidAnson/markdownlint-cli2@v0.21.0...v0.22.1)

Updates `tailwindcss` from 4.1.18 to 4.3.1
- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)
- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.3.1/packages/tailwindcss)

Updates `tsx` from 4.21.0 to 4.22.4
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.21.0...v4.22.4)

Updates `typescript-eslint` from 8.54.0 to 8.61.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.61.1/packages/typescript-eslint)

Updates `vitest` from 4.0.16 to 4.1.9
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.9/packages/vitest)

Updates `@modelcontextprotocol/sdk` from 1.27.1 to 1.29.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@v1.27.1...v1.29.0)

Updates `ws` from 8.18.3 to 8.21.0
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.18.3...8.21.0)

Updates `@yao-pkg/pkg` from 6.14.1 to 6.20.0
- [Release notes](https://github.com/yao-pkg/pkg/releases)
- [Changelog](https://github.com/yao-pkg/pkg/blob/main/CHANGELOG.md)
- [Commits](https://github.com/yao-pkg/pkg/commits)

Updates `esbuild` from 0.27.2 to 0.28.1
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md)
- [Commits](evanw/esbuild@v0.27.2...v0.28.1)

---
updated-dependencies:
- dependency-name: "@actions/languageservice"
  dependency-version: 0.3.58
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@actions/workflow-parser"
  dependency-version: 0.3.58
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@codemirror/autocomplete"
  dependency-version: 6.20.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@codemirror/commands"
  dependency-version: 6.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@codemirror/language"
  dependency-version: 6.12.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@codemirror/legacy-modes"
  dependency-version: 6.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@codemirror/lint"
  dependency-version: 6.9.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@codemirror/search"
  dependency-version: 6.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@codemirror/state"
  dependency-version: 6.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@codemirror/view"
  dependency-version: 6.43.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@joplin/turndown-plugin-gfm"
  dependency-version: 1.0.67
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@panzoom/panzoom"
  dependency-version: 4.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@tauri-apps/api"
  dependency-version: 2.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tauri-apps/plugin-dialog"
  dependency-version: 2.7.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tauri-apps/plugin-fs"
  dependency-version: 2.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tauri-apps/plugin-opener"
  dependency-version: 2.5.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@tauri-apps/plugin-store"
  dependency-version: 2.4.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@tauri-apps/plugin-updater"
  dependency-version: 2.10.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tiptap/core"
  dependency-version: 3.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tiptap/extension-blockquote"
  dependency-version: 3.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tiptap/extension-bullet-list"
  dependency-version: 3.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tiptap/extension-code-block-lowlight"
  dependency-version: 3.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tiptap/extension-heading"
  dependency-version: 3.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tiptap/extension-horizontal-rule"
  dependency-version: 3.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tiptap/extension-image"
  dependency-version: 3.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tiptap/extension-link"
  dependency-version: 3.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tiptap/extension-ordered-list"
  dependency-version: 3.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tiptap/extension-paragraph"
  dependency-version: 3.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tiptap/extension-table"
  dependency-version: 3.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tiptap/extension-table-row"
  dependency-version: 3.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tiptap/pm"
  dependency-version: 3.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tiptap/react"
  dependency-version: 3.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tiptap/starter-kit"
  dependency-version: 3.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@xyflow/react"
  dependency-version: 12.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: dompurify
  dependency-version: 3.4.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: katex
  dependency-version: 0.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: mermaid
  dependency-version: 11.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: react
  dependency-version: 19.2.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@types/react"
  dependency-version: 19.2.17
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: react-arborist
  dependency-version: 3.10.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: react-dom
  dependency-version: 19.2.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: react-router-dom
  dependency-version: 7.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: turndown
  dependency-version: 7.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: vscode-languageserver-types
  dependency-version: 3.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: yaml
  dependency-version: 2.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: zustand
  dependency-version: 5.0.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@hypothesi/tauri-mcp-server"
  dependency-version: 0.11.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tailwindcss/vite"
  dependency-version: 4.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@tauri-apps/cli"
  dependency-version: 2.11.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@types/react"
  dependency-version: 19.2.17
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm-minor-patch
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 4.1.9
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: dependency-cruiser
  dependency-version: 17.4.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: knip
  dependency-version: 6.17.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: markdownlint-cli2
  dependency-version: 0.22.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: tailwindcss
  dependency-version: 4.3.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: tsx
  dependency-version: 4.22.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: typescript-eslint
  dependency-version: 8.61.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: vitest
  dependency-version: 4.1.9
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.29.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: ws
  dependency-version: 8.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: "@yao-pkg/pkg"
  dependency-version: 6.20.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
- dependency-name: esbuild
  dependency-version: 0.28.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 16, 2026
xiaolai added 2 commits June 20, 2026 16:34
…ver-types 3.18

vscode-languageserver-types 3.18.0 widened `Diagnostic.message` to
`string | MarkupContent`. Add a `messageText` extractor and use it where
the message is read as a string (translate + classifyCode).
The npm minor-patch group bumps several tools/libs that the gates flag:
- knip 6.15 → 6.17 is stricter: it now exits non-zero on newly-detected
  unlisted binaries. Allowlist the ps/powershell spawns in the mcp-server's
  parent-process detection. (The website's mermaid/vitepress ignores stay —
  website deps aren't installed in the root CI job, so they ARE needed there;
  knip only reports them as redundant config hints locally, which don't fail.)
- Raise vendor-tiptap (3.18→3.26), vendor-lezer (transitive), and
  vendor-mermaid (11.12→11.15) size budgets to match real upstream growth.
  vendor-mermaid is lazy, so no cold-start impact.
@xiaolai
xiaolai force-pushed the dependabot/npm_and_yarn/npm-minor-patch-1482c0a728 branch from 080a18b to 9017f83 Compare June 20, 2026 09:19
@xiaolai
xiaolai enabled auto-merge (squash) June 27, 2026 01:16
@xiaolai

xiaolai commented Jun 27, 2026

Copy link
Copy Markdown
Owner

@dependabot recreate

@dependabot @github

dependabot Bot commented on behalf of github Jun 27, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

xiaolai added a commit that referenced this pull request Jun 27, 2026
…globals 17) + cargo minor/patch group

Verified with full `pnpm check:all` (lint, build, coverage, sidecar,
content-server, size) + `cargo check` + 728 Rust tests.

- @vitejs/plugin-react 4 → 5, globals 16 → 17: drop-in (dev/build only, no
  bundle impact). Replaces #1048, #1054.
- eslint-plugin-react-hooks 5 → 7: v7 folded the React Compiler rule set into
  `recommended`, flagging 67 pre-existing sites (set-state-in-effect, refs,
  manual-memoization, immutability). Adopting those is a deliberate codebase
  refactor, not a version bump — so they're deferred in eslint.config.js
  (documented) to preserve the prior enforcement level, and exhaustive-deps is
  pinned to its historical `warn`. Replaces #1050.
- cargo minor/patch updates within semver (`cargo update`): reproduces the
  cargo-minor-patch group (#1040), which failed as a blind bump against a
  stale base. Compiles clean + all Rust tests pass.

Note: the root npm minor/patch group (#1045) is intentionally NOT swept in
here — it carries a mermaid 11.12→11.16 (+~800 kB lazy chunk) and tiptap
3.18→3.27 growth that trips the size gate and warrants a separate, conscious
decision rather than an automatic limit bump. Left to dependabot.
xiaolai added a commit that referenced this pull request Jun 27, 2026
`pnpm update -r` within semver — reproduces the dependabot minor/patch groups
#1045 (root), #1036 (mcp), and #1051 (@eslint/js) as one verified change.
Full `pnpm check:all` green.

- Size growth accepted (approved): mermaid 11.12 → 11.16 (+~800 kB, lazy
  chunk — never in cold start) and tiptap 3.18 → 3.27 (+18 kB eager). Both
  size-limit ceilings bumped with documented reasons in .size-limit.cjs.
- schema.ts: vscode-languageserver-types reached LSP 3.18, which widened
  Diagnostic.message to `string | MarkupContent`; flatten MarkupContent to
  its text via a messageText() helper.

Completes #1045 / #1036 / #1051.
@xiaolai

xiaolai commented Jun 27, 2026

Copy link
Copy Markdown
Owner

Superseded by #1062 — folded into the consolidated dependency PR (minor/patch sweep, verified green). Size growth from mermaid/tiptap accepted with documented size-limit bumps.

@xiaolai xiaolai closed this Jun 27, 2026
auto-merge was automatically disabled June 27, 2026 03:08

Pull request was closed

@dependabot @github

dependabot Bot commented on behalf of github Jun 27, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/npm-minor-patch-1482c0a728 branch June 27, 2026 03:08
xiaolai added a commit that referenced this pull request Jun 27, 2026
…h, done correctly) (#1062)

* chore(deps): upgrade rust-i18n 3→4, dirs 5→6, toml 0.8→0.9

All three are drop-in for VMark's usage — verified locally with
`cargo check` + 728 passing tests:

- rust-i18n 4: the 3→4 breaking changes are all trait-level (custom Backend
  impls + the dropped once_cell re-export). We use only the i18n!/t! macros
  and set_locale, which are unchanged. MSRV 1.80 is satisfied.
- dirs 6: home_dir() is unchanged (our only call); we never use config_dir,
  so its macOS churn is irrelevant.
- toml 0.9: we parse into toml::Table (not Value, sidestepping the
  FromStr-now-parses-values break) and use to_string_pretty (signature
  unchanged). Resolves to 0.9.10 — the +spec-1.1.0 suffix is build metadata
  on the published 0.9.10, not a separate preview track.

Completes the intent of dependabot #1044 / #1042 / #1043, which failed as
blind bumps, done correctly with verification.

* chore(deps): upgrade JS majors — i18next 26, lucide-react 1, zod 4 (mcp), react-i18next 16.6

Done correctly with the code migrations dependabot's blind bumps couldn't do.
Verified with the full `pnpm check:all` (tsc, lint, sidecar + content-server
tests, build, coverage, size).

- i18next 25 → 26: `initImmediate` was removed; renamed back to `initAsync`
  (same semantics). src/i18n.ts updated. react-i18next bumped 16.5 → 16.6
  (peer `>= 25.10.9` admits i18next 26).
- lucide-react 0.562 → 1.x: v1 removed all brand icons. AboutSettings imported
  the now-removed `Github`, so it ships the GitHub mark as a local inline SVG
  (GithubMark.tsx) matching the lucide render contract. All other 74 icons
  resolve unchanged. Settings-page size limit nudged 94 → 95 kB for the SVG.
- zod 3 → 4 (vmark-mcp-server): single-arg `z.record()` was removed; cli.ts now
  passes an explicit key schema (`z.record(z.string(), z.unknown())`). The MCP
  SDK 1.27.1 peers `^3.25 || ^4.0`, so zod 4 is accepted.

Completes the intent of dependabot #1052 / #1046 / #1037 / #1047.

* chore(deps): dev-tooling majors (vite-plugin-react 5, react-hooks 7, globals 17) + cargo minor/patch group

Verified with full `pnpm check:all` (lint, build, coverage, sidecar,
content-server, size) + `cargo check` + 728 Rust tests.

- @vitejs/plugin-react 4 → 5, globals 16 → 17: drop-in (dev/build only, no
  bundle impact). Replaces #1048, #1054.
- eslint-plugin-react-hooks 5 → 7: v7 folded the React Compiler rule set into
  `recommended`, flagging 67 pre-existing sites (set-state-in-effect, refs,
  manual-memoization, immutability). Adopting those is a deliberate codebase
  refactor, not a version bump — so they're deferred in eslint.config.js
  (documented) to preserve the prior enforcement level, and exhaustive-deps is
  pinned to its historical `warn`. Replaces #1050.
- cargo minor/patch updates within semver (`cargo update`): reproduces the
  cargo-minor-patch group (#1040), which failed as a blind bump against a
  stale base. Compiles clean + all Rust tests pass.

Note: the root npm minor/patch group (#1045) is intentionally NOT swept in
here — it carries a mermaid 11.12→11.16 (+~800 kB lazy chunk) and tiptap
3.18→3.27 growth that trips the size gate and warrants a separate, conscious
decision rather than an automatic limit bump. Left to dependabot.

* chore(deps): npm minor/patch sweep (root + mcp + content-server)

`pnpm update -r` within semver — reproduces the dependabot minor/patch groups
#1045 (root), #1036 (mcp), and #1051 (@eslint/js) as one verified change.
Full `pnpm check:all` green.

- Size growth accepted (approved): mermaid 11.12 → 11.16 (+~800 kB, lazy
  chunk — never in cold start) and tiptap 3.18 → 3.27 (+18 kB eager). Both
  size-limit ceilings bumped with documented reasons in .size-limit.cjs.
- schema.ts: vscode-languageserver-types reached LSP 3.18, which widened
  Diagnostic.message to `string | MarkupContent`; flatten MarkupContent to
  its text via a messageText() helper.

Completes #1045 / #1036 / #1051.

* docs(eslint): link react-hooks-7 rule deferral to tracking issue #1063

* fix(deps): reconcile pnpm-lock with dompurify override so --frozen-lockfile passes

The minor/patch sweep left pnpm-lock.yaml frozen-inconsistent: the direct
dompurify dep (^3.4.11) and the pnpm.overrides entry (>=3.3.2) disagreed in a
way non-frozen install tolerates but CI's --frozen-lockfile rejects
(ERR_PNPM_OUTDATED_LOCKFILE). Plain pnpm install reconciles it. check:all green.

* fix(knip): re-add mermaid + vitepress to website ignore lists

The minor/patch sweep shifted node_modules hoisting enough that knip (on a
clean --frozen-lockfile install, as CI runs) can no longer statically trace
the website's mermaid usage (rendered via vitepress's component system) or
resolve the `vitepress` binary — flagging both as error-level (Unused
devDependencies / Unlisted binaries). Both are genuinely used; the earlier
gate-fix removed these ignore entries as "stale," but they're load-bearing
across hoisting states. Verified with a clean install + full check:all.
xiaolai added a commit that referenced this pull request Aug 12, 2026
…h, done correctly) (#1062)

* chore(deps): upgrade rust-i18n 3→4, dirs 5→6, toml 0.8→0.9

All three are drop-in for VMark's usage — verified locally with
`cargo check` + 728 passing tests:

- rust-i18n 4: the 3→4 breaking changes are all trait-level (custom Backend
  impls + the dropped once_cell re-export). We use only the i18n!/t! macros
  and set_locale, which are unchanged. MSRV 1.80 is satisfied.
- dirs 6: home_dir() is unchanged (our only call); we never use config_dir,
  so its macOS churn is irrelevant.
- toml 0.9: we parse into toml::Table (not Value, sidestepping the
  FromStr-now-parses-values break) and use to_string_pretty (signature
  unchanged). Resolves to 0.9.10 — the +spec-1.1.0 suffix is build metadata
  on the published 0.9.10, not a separate preview track.

Completes the intent of dependabot #1044 / #1042 / #1043, which failed as
blind bumps, done correctly with verification.

* chore(deps): upgrade JS majors — i18next 26, lucide-react 1, zod 4 (mcp), react-i18next 16.6

Done correctly with the code migrations dependabot's blind bumps couldn't do.
Verified with the full `pnpm check:all` (tsc, lint, sidecar + content-server
tests, build, coverage, size).

- i18next 25 → 26: `initImmediate` was removed; renamed back to `initAsync`
  (same semantics). src/i18n.ts updated. react-i18next bumped 16.5 → 16.6
  (peer `>= 25.10.9` admits i18next 26).
- lucide-react 0.562 → 1.x: v1 removed all brand icons. AboutSettings imported
  the now-removed `Github`, so it ships the GitHub mark as a local inline SVG
  (GithubMark.tsx) matching the lucide render contract. All other 74 icons
  resolve unchanged. Settings-page size limit nudged 94 → 95 kB for the SVG.
- zod 3 → 4 (vmark-mcp-server): single-arg `z.record()` was removed; cli.ts now
  passes an explicit key schema (`z.record(z.string(), z.unknown())`). The MCP
  SDK 1.27.1 peers `^3.25 || ^4.0`, so zod 4 is accepted.

Completes the intent of dependabot #1052 / #1046 / #1037 / #1047.

* chore(deps): dev-tooling majors (vite-plugin-react 5, react-hooks 7, globals 17) + cargo minor/patch group

Verified with full `pnpm check:all` (lint, build, coverage, sidecar,
content-server, size) + `cargo check` + 728 Rust tests.

- @vitejs/plugin-react 4 → 5, globals 16 → 17: drop-in (dev/build only, no
  bundle impact). Replaces #1048, #1054.
- eslint-plugin-react-hooks 5 → 7: v7 folded the React Compiler rule set into
  `recommended`, flagging 67 pre-existing sites (set-state-in-effect, refs,
  manual-memoization, immutability). Adopting those is a deliberate codebase
  refactor, not a version bump — so they're deferred in eslint.config.js
  (documented) to preserve the prior enforcement level, and exhaustive-deps is
  pinned to its historical `warn`. Replaces #1050.
- cargo minor/patch updates within semver (`cargo update`): reproduces the
  cargo-minor-patch group (#1040), which failed as a blind bump against a
  stale base. Compiles clean + all Rust tests pass.

Note: the root npm minor/patch group (#1045) is intentionally NOT swept in
here — it carries a mermaid 11.12→11.16 (+~800 kB lazy chunk) and tiptap
3.18→3.27 growth that trips the size gate and warrants a separate, conscious
decision rather than an automatic limit bump. Left to dependabot.

* chore(deps): npm minor/patch sweep (root + mcp + content-server)

`pnpm update -r` within semver — reproduces the dependabot minor/patch groups
#1045 (root), #1036 (mcp), and #1051 (@eslint/js) as one verified change.
Full `pnpm check:all` green.

- Size growth accepted (approved): mermaid 11.12 → 11.16 (+~800 kB, lazy
  chunk — never in cold start) and tiptap 3.18 → 3.27 (+18 kB eager). Both
  size-limit ceilings bumped with documented reasons in .size-limit.cjs.
- schema.ts: vscode-languageserver-types reached LSP 3.18, which widened
  Diagnostic.message to `string | MarkupContent`; flatten MarkupContent to
  its text via a messageText() helper.

Completes #1045 / #1036 / #1051.

* docs(eslint): link react-hooks-7 rule deferral to tracking issue #1063

* fix(deps): reconcile pnpm-lock with dompurify override so --frozen-lockfile passes

The minor/patch sweep left pnpm-lock.yaml frozen-inconsistent: the direct
dompurify dep (^3.4.11) and the pnpm.overrides entry (>=3.3.2) disagreed in a
way non-frozen install tolerates but CI's --frozen-lockfile rejects
(ERR_PNPM_OUTDATED_LOCKFILE). Plain pnpm install reconciles it. check:all green.

* fix(knip): re-add mermaid + vitepress to website ignore lists

The minor/patch sweep shifted node_modules hoisting enough that knip (on a
clean --frozen-lockfile install, as CI runs) can no longer statically trace
the website's mermaid usage (rendered via vitepress's component system) or
resolve the `vitepress` binary — flagging both as error-level (Unused
devDependencies / Unlisted binaries). Both are genuinely used; the earlier
gate-fix removed these ignore entries as "stale," but they're load-bearing
across hoisting states. Verified with a clean install + full check:all.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant