Skip to content

chore(deps): bump low-risk dev tooling + render libs (safe subset of #1002)#1004

Merged
xarmian merged 1 commit into
mainfrom
chore/deps-safe-batch
Jul 22, 2026
Merged

chore(deps): bump low-risk dev tooling + render libs (safe subset of #1002)#1004
xarmian merged 1 commit into
mainfrom
chore/deps-safe-batch

Conversation

@xarmian

@xarmian xarmian commented Jul 22, 2026

Copy link
Copy Markdown
Collaborator

What

Extracts the genuinely low-risk bumps from grouped Dependabot #1002 (which can't be merged as-is — it's stale, reverts the BUG-2278 advisory overrides, and bundles a coordinated @tiptap/* 3.28 bump needing schema-version verification + a svelte 5.56 runtime bump needing focus-suite revalidation).

Safe subset (dev tooling + rendering libs; no collab/runtime/build-compiler surface):
@playwright/test 1.59.1→1.61.1 · marked 18.0.3→18.0.7 · svelte-check 4.4.7→4.7.3 · mermaid 11.14.0→11.16.0 · layercake 10.0.2→10.0.3 · svelte-dnd-action 0.9.69→0.9.74.

Deliberately excluded (verified unchanged): @tiptap/*, svelte, @sveltejs/vite-plugin-svelte, yjs, and the kit/vite/rolldown toolchain — those get their own validated PRs.

Verification

npm audit --omit=dev 0 vulns · check:tiptap-pins OK · npm ci in sync · build · check (0 errors) · test (464) — all green. Codex: CLEAN.

https://claude.ai/code/session_01EZ6yr6pAUFb1uffan912ra

…1002)

Extracts the genuinely low-risk bumps from the grouped Dependabot PR #1002,
which as a whole can't be merged (it's stale — reverts the BUG-2278 advisory
overrides — and bundles a coordinated @tiptap/* 3.22.5->3.28.0 bump that needs
schema-version verification plus a svelte 5.55->5.56 runtime bump that needs
focus-suite revalidation).

Safe subset (dev tooling + rendering libs only; no collab/runtime/build-compiler
surface): @playwright/test 1.59.1->1.61.1, marked 18.0.3->18.0.7, svelte-check
4.4.7->4.7.3, mermaid 11.14.0->11.16.0, layercake 10.0.2->10.0.3,
svelte-dnd-action 0.9.69->0.9.74.

Deliberately EXCLUDED (verified unchanged): @tiptap/*, svelte,
@sveltejs/vite-plugin-svelte, yjs, and the kit/vite/rolldown toolchain — those
need their own validated PRs.

Gates: audit 0 prod vulns, check:tiptap-pins OK, npm ci in sync, build, check
(0 errors), test (464) all green.

Claude-Session: https://claude.ai/code/session_01EZ6yr6pAUFb1uffan912ra
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant