Commit Graph
15572 Commits
Author SHA1 Message Date
Jake Howell 0a42334f77 refactor(site): demui Form.stories.tsx stories (#27762)
Replace MUI `TextField` in the Form Storybook stories with `FormField`,
wired through Formik and `getFormHelpers` so the examples match how real
forms use the layout components.
2026-08-03 19:08:30 +10:00
dependabot[bot] b05a499a36 chore: bump autoprefixer from 10.5.0 to 10.5.4 in /site (#27755)
Bumps [autoprefixer](https://github.com/postcss/autoprefixer) from
10.5.0 to 10.5.4.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/autoprefixer/releases">autoprefixer's
releases</a>.</em></p>
<blockquote>
<h2>10.5.4</h2>
<ul>
<li>Fixed prefixed rule duplication (by <a
href="https://github.com/xianjianlf2"><code>@​xianjianlf2</code></a>).</li>
</ul>
<h2>10.5.3</h2>
<ul>
<li>Fixed brackets and gradient parser (<a
href="https://github.com/alanturing881"><code>@​alanturing881</code></a>).</li>
</ul>
<h2>10.5.2</h2>
<ul>
<li>Moved <code>-webkit-fill-available</code> before
<code>-moz-available</code>, so Firefox
will use <code>-webkit-</code> version which is closer to
<code>stretch</code>.</li>
</ul>
<h2>10.5.1</h2>
<ul>
<li>Fixed <code>grid-area</code> span reset for overriding areas (by <a
href="https://github.com/puneetdixit200"><code>@​puneetdixit200</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md">autoprefixer's
changelog</a>.</em></p>
<blockquote>
<h2>10.5.4</h2>
<ul>
<li>Fixed prefixed rule duplication (by <a
href="https://github.com/xianjianlf2"><code>@​xianjianlf2</code></a>).</li>
</ul>
<h2>10.5.3</h2>
<ul>
<li>Fixed brackets and gradient parser (<a
href="https://github.com/alanturing881"><code>@​alanturing881</code></a>).</li>
</ul>
<h2>10.5.2</h2>
<ul>
<li>Moved <code>-webkit-fill-available</code> before
<code>-moz-available</code>, so Firefox
will use <code>-webkit-</code> version which is closer to
<code>stretch</code>.</li>
</ul>
<h2>10.5.1</h2>
<ul>
<li>Fixed <code>grid-area</code> span reset for overriding areas (by <a
href="https://github.com/puneetdixit200"><code>@​puneetdixit200</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/postcss/autoprefixer/commit/4cad00f0e839f3d7bbcdcc00b7df6fc448fb28f3"><code>4cad00f</code></a>
Release 10.5.4 version</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/e62a4b1782f4ece51070feba79b0ff19f4305c68"><code>e62a4b1</code></a>
Update CI config</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/c8f0d0ae00f5bb28bbcc3413f70b088020007469"><code>c8f0d0a</code></a>
Update dependencies</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/cae35771dc4a4dfeda637a31dc1795ace6d9d28b"><code>cae3577</code></a>
Move back to latest pnpm 11</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/fd31eb33b56ab9663d298b5bf08ae4ff47f76878"><code>fd31eb3</code></a>
Fix duplicated prefixed selectors on reformatted CSS (<a
href="https://redirect.github.com/postcss/autoprefixer/issues/1552">#1552</a>)</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/958d390787c31c3044c1fb68ec37efc29637e26b"><code>958d390</code></a>
Release 10.5.3 version</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/21d2adb4d1fc6103c1e3cc39c991de59fdb5496e"><code>21d2adb</code></a>
Fix gradient parser</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/f7ddae99f0ebfa3961a5c14bd9ecb7d4310601a6"><code>f7ddae9</code></a>
Fix bracket parser</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/10ea5e7b8511a3e07aeb8a0f50f61496bc3faf4f"><code>10ea5e7</code></a>
Update dependencies and remove patch</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/b6e8a2a4672cafafcb3bb2c72cd0027a31b1a320"><code>b6e8a2a</code></a>
Update Dev Container</li>
<li>Additional commits viewable in <a
href="https://github.com/postcss/autoprefixer/compare/10.5.0...10.5.4">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for autoprefixer since your current version.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=autoprefixer&package-manager=npm_and_yarn&previous-version=10.5.0&new-version=10.5.4)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 11:24:31 +00:00
dependabot[bot] 4fc605abe6 chore: bump motion from 12.40.0 to 12.42.2 in /site (#27748)
Bumps [motion](https://github.com/motiondivision/motion) from 12.40.0 to
12.42.2.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/motiondivision/motion/blob/main/CHANGELOG.md">motion's
changelog</a>.</em></p>
<blockquote>
<h2>[12.42.2] 2026-07-01</h2>
<h3>Fixed</h3>
<ul>
<li><code>animateView</code>: Cropped group layers now animate
<code>border-radius</code> from the old to new radius.</li>
</ul>
<h2>[12.42.1] 2026-06-30</h2>
<h3>Fixed</h3>
<ul>
<li><code>animateView</code>: Old layer fade out now cancelled when
defining <code>.new()</code>.</li>
</ul>
<h2>[12.42.0] 2026-06-24</h2>
<h3>Changed</h3>
<ul>
<li><code>animateView</code>: Layers are automatically grouped to match
their DOM-hierarchy. New <code>.group(false)</code> method
opts-out.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li><code>animateView</code>: Auto-crop is now aspect-ratio aware,
disabling crops for matching aspect-ratios.</li>
<li><code>animateView</code>: Disabled automatic
<code>border-radius</code> animation.</li>
</ul>
<h2>[12.41.0] 2026-06-23</h2>
<h3>Added</h3>
<ul>
<li><code>animateView</code>: Moves from Motion+ Early Access and alpha
to main library.</li>
<li><code>animateView</code>: <code>.add()</code> resolves a CSS
selector or <code>Element</code> to automatically generate, apply and
remove <code>view-transition-name</code>.</li>
<li><code>animateView</code>: <code>.new()</code> and
<code>.old()</code> configures values to animate on new and old
layers.</li>
<li><code>animateView</code>: <code>.layout()</code> can set a custom
transition on the size/position animation of the currently selected
elements.</li>
<li><code>animateView</code>: Group layers now automatically crop with
children set to <code>cover</code>, with <code>border-radius</code>
animating from old radius to new. <code>.crop(false)</code> disables
this behaviour.</li>
<li><code>animateView</code>: <code>.class(name)</code> tags currently
selected elements with a <code>view-transition-class</code> as a custom
CSS hook.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li><code>AnimatePresence</code>: Prevent stuck exit animations when
children interrupt.</li>
<li><code>drag</code>: Child <code>e.stopPropagation()</code> no longer
break drag end.</li>
<li>Fixing Next.js OOM on Windows when importing via <code>motion</code>
package.</li>
<li><code>animateLayout</code>: Improve handling of parallel/interleaved
calls.</li>
</ul>
<h3>Changed</h3>
<ul>
<li><code>animateView</code>: <code>.enter()</code> and
<code>.exit()</code> now refer specifically to <code>new</code> and
<code>old</code> layers where there are no matching <code>old</code> or
<code>new</code> layers.</li>
<li><code>animateView</code>: Interrupted transition setups now return
resolved animation rather than throwing.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/motiondivision/motion/commit/40e8756c63b258c9dd07de9501cb788410eefb02"><code>40e8756</code></a>
v12.42.2</li>
<li><a
href="https://github.com/motiondivision/motion/commit/718ccc7d4e8d17dddb36e73198b730fac57267c4"><code>718ccc7</code></a>
Merge pull request <a
href="https://redirect.github.com/motiondivision/motion/issues/3768">#3768</a>
from motiondivision/view-cropped-corner-radius</li>
<li><a
href="https://github.com/motiondivision/motion/commit/19195a4bfc77389afb9cfd06bb2fb9eaeb798e8f"><code>19195a4</code></a>
Dedupe corner-radius longhands; merge crop box/radii measurements</li>
<li><a
href="https://github.com/motiondivision/motion/commit/5299aa65a2428c55728d28b68c0d3242052d8b7a"><code>5299aa6</code></a>
Resolve cropped-clip radius timing once; fix transition-option leak</li>
<li><a
href="https://github.com/motiondivision/motion/commit/937cdf396c29fa2826ba0836c1e6f1a1466e5064"><code>937cdf3</code></a>
Animate cropped view-transition group corner radius</li>
<li><a
href="https://github.com/motiondivision/motion/commit/fd2d6f66d1cffcfeb2e2e0d9e39dc54796025db2"><code>fd2d6f6</code></a>
v12.42.1</li>
<li><a
href="https://github.com/motiondivision/motion/commit/2223d873d8c78bab03301e5d9e3272c6d76907e6"><code>2223d87</code></a>
Hold the old layer when only a non-opacity .new() is set</li>
<li><a
href="https://github.com/motiondivision/motion/commit/9c841455973b280c7989befd6dc918da0246a7fa"><code>9c84145</code></a>
v12.42.0</li>
<li><a
href="https://github.com/motiondivision/motion/commit/60d7c72bc3d8052e2453424542d102467f3ed2fc"><code>60d7c72</code></a>
Add view-transition group nesting and aspect-aware cropping</li>
<li><a
href="https://github.com/motiondivision/motion/commit/6437276caa543467a3bc407514ad0a4f842c37e0"><code>6437276</code></a>
Updating</li>
<li>Additional commits viewable in <a
href="https://github.com/motiondivision/motion/compare/v12.40.0...v12.42.2">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 11:22:31 +00:00
dependabot[bot] 6abd926807 chore: bump express from 4.21.2 to 4.22.2 in /site (#27752)
Bumps [express](https://github.com/expressjs/express) from 4.21.2 to
4.22.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/expressjs/express/releases">express's
releases</a>.</em></p>
<blockquote>
<h2>v4.22.2</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: restore &gt;20 array parsing for <code>req.query</code>
repeated keys (<a
href="https://github.com/expressjs/express/commit/8d09bfe6d88983da5c3e12cfdd54782c4dc675db"><code>8d09bfe6</code></a>)
<ul>
<li>This also unifies array-cap behavior across notations. Indexed
notation (<code>a[0]=...</code>) was historically capped at qs's default
<code>arrayLimit</code> of 20 even in older qs versions; after this
change it also allows up to 1000 items.</li>
</ul>
</li>
<li>deps: qs@~6.15.1</li>
<li>deps: body-parser@~1.20.5</li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/suuuuuuminnnnnn"><code>@​suuuuuuminnnnnn</code></a>
made their first contribution in <a
href="https://redirect.github.com/expressjs/express/pull/7021">expressjs/express#7021</a></li>
<li><a href="https://github.com/SAY-5"><code>@​SAY-5</code></a> made
their first contribution in <a
href="https://redirect.github.com/expressjs/express/pull/7181">expressjs/express#7181</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/expressjs/express/compare/v4.22.1...v4.22.2">https://github.com/expressjs/express/compare/v4.22.1...v4.22.2</a></p>
<h2>v4.22.1</h2>
<h2>What's Changed</h2>
<blockquote>
<p>[!IMPORTANT]<br />
The prior release (4.22.0) included an erroneous breaking change related
to the extended query parser. There is no actual security vulnerability
associated with this behavior (CVE-2024-51999 has been rejected). The
change has been fully reverted in this release.</p>
</blockquote>
<ul>
<li>Release: 4.22.1 by <a
href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a>
in <a
href="https://redirect.github.com/expressjs/express/pull/6934">expressjs/express#6934</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/expressjs/express/compare/4.22.0...v4.22.1">https://github.com/expressjs/express/compare/4.22.0...v4.22.1</a></p>
<h2>4.22.0</h2>
<h2>Important: Security</h2>
<ul>
<li>Security fix for <a
href="https://www.cve.org/CVERecord?id=CVE-2024-51999">CVE-2024-51999</a>
(<a
href="https://github.com/expressjs/express/security/advisories/GHSA-pj86-cfqh-vqx6">GHSA-pj86-cfqh-vqx6</a>)</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>Refactor: improve readability by <a
href="https://github.com/sazk07"><code>@​sazk07</code></a> in <a
href="https://redirect.github.com/expressjs/express/pull/6190">expressjs/express#6190</a></li>
<li>ci: add support for Node.js@23.0 by <a
href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a>
in <a
href="https://redirect.github.com/expressjs/express/pull/6080">expressjs/express#6080</a></li>
<li>Method functions with no path should error by <a
href="https://github.com/wesleytodd"><code>@​wesleytodd</code></a> in <a
href="https://redirect.github.com/expressjs/express/pull/5957">expressjs/express#5957</a></li>
<li>ci: updated github actions ci workflow by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/express/pull/6323">expressjs/express#6323</a></li>
<li>ci: reorder <code>npm i</code> steps to fix ci for older node
versions by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/express/pull/6336">expressjs/express#6336</a></li>
<li>Backport: ci: add node.js 24 to test matrix by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/express/pull/6506">expressjs/express#6506</a></li>
<li>chore(4.x): wider range for query test skip by <a
href="https://github.com/jonchurch"><code>@​jonchurch</code></a> in <a
href="https://redirect.github.com/expressjs/express/pull/6513">expressjs/express#6513</a></li>
<li>use tilde notation for certain dependencies by <a
href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a>
in <a
href="https://redirect.github.com/expressjs/express/pull/6905">expressjs/express#6905</a></li>
<li>deps: qs@6.14.0 by <a
href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a>
in <a
href="https://redirect.github.com/expressjs/express/pull/6909">expressjs/express#6909</a></li>
<li>deps: use tilde notation for <code>qs</code> by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/express/pull/6919">expressjs/express#6919</a></li>
<li>Release: 4.22.0 by <a
href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a>
in <a
href="https://redirect.github.com/expressjs/express/pull/6921">expressjs/express#6921</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/expressjs/express/compare/4.21.2...4.22.0">https://github.com/expressjs/express/compare/4.21.2...4.22.0</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/expressjs/express/blob/v4.22.2/History.md">express's
changelog</a>.</em></p>
<blockquote>
<h1>4.22.2 / 2026-05-011</h1>
<ul>
<li>fix: restore &gt;20 array parsing for <code>req.query</code>
repeated keys (<a
href="https://github.com/expressjs/express/commit/8d09bfe6d88983da5c3e12cfdd54782c4dc675db"><code>8d09bfe6</code></a>)
<ul>
<li>This also unifies array-cap behavior across notations. Indexed
notation (<code>a[0]=...</code>) was historically capped at qs's default
<code>arrayLimit</code> of 20 even in older qs versions; after this
change it also allows up to 1000 items.</li>
</ul>
</li>
<li>deps: qs@~6.15.1</li>
<li>deps: body-parser@~1.20.5</li>
</ul>
<h1>4.22.1 / 2025-12-01</h1>
<ul>
<li>Revert security fix for <a
href="https://www.cve.org/CVERecord?id=CVE-2024-51999">CVE-2024-51999</a>
(<a
href="https://github.com/expressjs/express/security/advisories/GHSA-pj86-cfqh-vqx6">GHSA-pj86-cfqh-vqx6</a>)
<ul>
<li>The prior release (4.22.0) included an erroneous breaking change
related to the extended query parser. There is no actual security
vulnerability associated with this behavior (CVE-2024-51999 has been
rejected). The change has been fully reverted in this release.</li>
</ul>
</li>
</ul>
<h1>4.22.0 / 2025-12-01</h1>
<ul>
<li>Security fix for <a
href="https://www.cve.org/CVERecord?id=CVE-2024-51999">CVE-2024-51999</a>
(<a
href="https://github.com/expressjs/express/security/advisories/GHSA-pj86-cfqh-vqx6">GHSA-pj86-cfqh-vqx6</a>)</li>
<li>deps: use tilde notation for dependencies</li>
<li>deps: qs@6.14.0</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/expressjs/express/commit/df0abc9333a3398b97b71f6ea7cd77d5ea3e9f97"><code>df0abc9</code></a>
4.22.2</li>
<li><a
href="https://github.com/expressjs/express/commit/836d36668ea750f78b4373b4de79bbd22634e6ec"><code>836d366</code></a>
<code>4.x</code> update qs to 6.15.1, body-parser 1.20.5 (<a
href="https://redirect.github.com/expressjs/express/issues/7224">#7224</a>)</li>
<li><a
href="https://github.com/expressjs/express/commit/8d09bfe6d88983da5c3e12cfdd54782c4dc675db"><code>8d09bfe</code></a>
fix: restore array parsing for req.query repeated keys (<a
href="https://redirect.github.com/expressjs/express/issues/7181">#7181</a>)</li>
<li><a
href="https://github.com/expressjs/express/commit/d39e8ad1778a0b8a606a5a7b17096d0cc5ec722d"><code>d39e8ad</code></a>
deps: body-parser@~1.20.4 (<a
href="https://redirect.github.com/expressjs/express/issues/7021">#7021</a>)</li>
<li><a
href="https://github.com/expressjs/express/commit/efe85d9fdc9e3a62f7a1121b4f5f484862298b48"><code>efe85d9</code></a>
deps: qs@^6.14.1 (<a
href="https://redirect.github.com/expressjs/express/issues/6972">#6972</a>)</li>
<li><a
href="https://github.com/expressjs/express/commit/f62378e1bc776259c0a471476c2dc043a02ac762"><code>f62378e</code></a>
📝 add note to history</li>
<li><a
href="https://github.com/expressjs/express/commit/12fae14531a78f19a2caaa5d4f58d9b01eaf3194"><code>12fae14</code></a>
4.22.1</li>
<li><a
href="https://github.com/expressjs/express/commit/5ddf311af32e772a77fd48b6266ce2f1ba330e1a"><code>5ddf311</code></a>
Revert &quot;sec: security patch for CVE-2024-51999&quot;</li>
<li><a
href="https://github.com/expressjs/express/commit/49744abd1120484fe64d7bde1cd3197c32523b6e"><code>49744ab</code></a>
4.22.0 (<a
href="https://redirect.github.com/expressjs/express/issues/6921">#6921</a>)</li>
<li><a
href="https://github.com/expressjs/express/commit/6e97452f600a3b01719fbc5517d833c7646b0bb7"><code>6e97452</code></a>
sec: security patch for CVE-2024-51999</li>
<li>Additional commits viewable in <a
href="https://github.com/expressjs/express/compare/4.21.2...v4.22.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=express&package-manager=npm_and_yarn&previous-version=4.21.2&new-version=4.22.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 11:21:29 +00:00
dependabot[bot] 025a3b253d chore: bump @lexical/utils from 0.44.0 to 0.48.0 in /site (#27751)
Bumps
[@lexical/utils](https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils)
from 0.44.0 to 0.48.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/facebook/lexical/releases">@​lexical/utils's
releases</a>.</em></p>
<blockquote>
<p>v0.48.0 is a maintenance release focused on bug fixes across
Markdown, tables, lists, links, and selection. It's headlined by a fix
for a v0.46.0 regression that broke native text drag-and-drop (<a
href="https://redirect.github.com/facebook/lexical/pull/8842">#8842</a>)
and a couple of notable security hardening fixes. It also adds a handful
of new features, including an <code>MdastHtmlExtension</code> with
examples for authoring custom Markdown constructs (collapsibles,
<code>kbd</code>, alerts, footnotes), a customizable Yjs shared-type
root name for collaborative editing, and new table row manipulation
helpers.</p>
<h2>New APIs &amp; Features</h2>
<ul>
<li><a
href="https://lexical.dev/docs/api/modules/lexical_table"><code>@lexical/table</code></a>
— Added <code>$moveTableRow</code> for reordering table rows, plus the
previously missing <code>$unmergeCellNode</code> export (<a
href="https://redirect.github.com/facebook/lexical/pull/8833">#8833</a>)</li>
<li><a
href="https://lexical.dev/docs/api/modules/lexical_yjs"><code>@lexical/yjs</code></a>
/ <a
href="https://lexical.dev/docs/api/modules/lexical_react"><code>@lexical/react</code></a>
— The Yjs shared-type root name is now customizable, so Lexical can
share a Yjs document with other content that uses a different root key
(<a
href="https://redirect.github.com/facebook/lexical/pull/8841">#8841</a>)</li>
<li><a
href="https://lexical.dev/docs/api/modules/lexical_extension"><code>@lexical/extension</code></a>
/ <a
href="https://lexical.dev/docs/api/modules/lexical_mdast"><code>@lexical/mdast</code></a>
— Added <code>MdastHtmlExtension</code> and Markdown custom-construct
examples (collapsible sections, <code>kbd</code>, alerts, footnotes)
demonstrating how to extend the Markdown ↔ mdast pipeline. See the <a
href="https://lexical.dev/docs/serialization/markdown-mdast">Markdown
&amp; mdast serialization guide</a> (<a
href="https://redirect.github.com/facebook/lexical/pull/8826">#8826</a>)</li>
</ul>
<h2>Notable Fixes</h2>
<p><strong>Drag &amp; drop (fix for v0.46.0 regression)</strong></p>
<ul>
<li>Don't cancel <code>dragover</code> for text drags, so native drops
work again (<a
href="https://redirect.github.com/facebook/lexical/pull/8842">#8842</a>)</li>
</ul>
<p><strong>Security</strong></p>
<ul>
<li><code>LinkNode.sanitizeUrl()</code> now fails closed on unparseable
URLs, preventing a potential XSS vector (<a
href="https://redirect.github.com/facebook/lexical/pull/8846">#8846</a>)</li>
<li>Fixed a <code>serialize-javascript</code> dependency vulnerability
(<a
href="https://redirect.github.com/facebook/lexical/pull/8803">#8803</a>)</li>
</ul>
<p><strong>Markdown &amp; code</strong></p>
<ul>
<li>Roundtrip overlapping inline formats correctly through
mdast/Markdown (<a
href="https://redirect.github.com/facebook/lexical/pull/8825">#8825</a>)</li>
<li>Force re-tokenization after an async language load so highlighting
appears once the grammar is ready (<a
href="https://redirect.github.com/facebook/lexical/pull/8830">#8830</a>)</li>
</ul>
<p><strong>Tables</strong></p>
<ul>
<li>Auto-scroll while drag-selecting cells past the visible edge (<a
href="https://redirect.github.com/facebook/lexical/pull/8822">#8822</a>)</li>
<li>Enable table copy in read-only mode (<a
href="https://redirect.github.com/facebook/lexical/pull/8845">#8845</a>)</li>
</ul>
<p><strong>Lists &amp; character limit</strong></p>
<ul>
<li>Backspace at the start of a list item now outdents or converts to a
paragraph (<a
href="https://redirect.github.com/facebook/lexical/pull/8829">#8829</a>)</li>
<li>Merge adjacent <code>OverflowNode</code>s in
<code>useCharacterLimit</code> (<a
href="https://redirect.github.com/facebook/lexical/pull/8831">#8831</a>)</li>
<li>Count block separators when wrapping character-limit overflow (<a
href="https://redirect.github.com/facebook/lexical/pull/8840">#8840</a>)</li>
</ul>
<p><strong>Links &amp; selection</strong></p>
<ul>
<li>Disable link opening for disabled autolinks (<a
href="https://redirect.github.com/facebook/lexical/pull/8839">#8839</a>)</li>
<li>Skip <code>scrollIntoViewIfNeeded</code> when the selection rect is
above the editor, fixing a Safari RTL caret jump (<a
href="https://redirect.github.com/facebook/lexical/pull/8848">#8848</a>)</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>[lexical-mdast][lexical-markdown] Bug Fix: Roundtrip overlapping
inline formats by <a
href="https://github.com/etrepum"><code>@​etrepum</code></a> in <a
href="https://redirect.github.com/facebook/lexical/pull/8825">facebook/lexical#8825</a></li>
<li>[lexical-table][lexical-playground] Bug Fix: Auto-scroll while
drag-selecting cells past the visible edge by <a
href="https://github.com/JohnJunior"><code>@​JohnJunior</code></a> in <a
href="https://redirect.github.com/facebook/lexical/pull/8822">facebook/lexical#8822</a></li>
<li>[lexical-code-shiki] Bug Fix: force re-tokenize after async language
load by <a
href="https://github.com/ochevallier"><code>@​ochevallier</code></a> in
<a
href="https://redirect.github.com/facebook/lexical/pull/8830">facebook/lexical#8830</a></li>
<li>[lexical-react] Bug Fix: Merge adjacent OverflowNodes in
useCharacterLimit by <a
href="https://github.com/mayrang"><code>@​mayrang</code></a> in <a
href="https://redirect.github.com/facebook/lexical/pull/8831">facebook/lexical#8831</a></li>
<li>Open playground links in a new tab by <a
href="https://github.com/potatowagon"><code>@​potatowagon</code></a> in
<a
href="https://redirect.github.com/facebook/lexical/pull/8837">facebook/lexical#8837</a></li>
<li>[lexical-rich-text][lexical-plain-text] Bug Fix: don't cancel
dragover for text drags so native drops work again by <a
href="https://github.com/etrepum"><code>@​etrepum</code></a> in <a
href="https://redirect.github.com/facebook/lexical/pull/8842">facebook/lexical#8842</a></li>
<li>[lexical-link] Bug Fix: disable link opening for disabled autolink
in… by <a
href="https://github.com/ochevallier"><code>@​ochevallier</code></a> in
<a
href="https://redirect.github.com/facebook/lexical/pull/8839">facebook/lexical#8839</a></li>
<li>[lexical-table] Feature: Add $moveTableRow function &amp; Add
missing export for $unmergeCellNode by <a
href="https://github.com/hamo-o"><code>@​hamo-o</code></a> in <a
href="https://redirect.github.com/facebook/lexical/pull/8833">facebook/lexical#8833</a></li>
<li>[lexical-list] Bug Fix: Backspace at start of list item outdents or
converts to paragraph by <a
href="https://github.com/mayrang"><code>@​mayrang</code></a> in <a
href="https://redirect.github.com/facebook/lexical/pull/8829">facebook/lexical#8829</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/facebook/lexical/blob/main/CHANGELOG.md">@​lexical/utils's
changelog</a>.</em></p>
<blockquote>
<h2>v0.48.0 (2026-07-16)</h2>
<ul>
<li>lexical-reactlexical-table Bug Fix Enable table copy in read-only
mode (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8845">#8845</a>)
mayrang</li>
<li>lexical-extensionlexical-mdastdev-mdast-editor-example Feature Add
MdastHtmlExtension and Markdown custom-construct examples (collapsible,
kbd, alerts, footnotes) (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8826">#8826</a>)
Bob Ippolito</li>
<li>Fix fail closed in LinkNode.sanitizeUrl() on unparseable URLs (XSS)
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8846">#8846</a>)
xiezhenjia-meta</li>
<li>lexical Chore Fix serialize-javascript package dependency
vulnerability (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8803">#8803</a>)
vijay ojha</li>
<li>lexical-react Bug Fix Count block separators in character limit
overflow wrapping (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8840">#8840</a>)
mayrang</li>
<li>lexical-yjslexical-react Feature Customizable Yjs shared-type root
name (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8841">#8841</a>)
mayrang</li>
<li>lexical-list Bug Fix Backspace at start of list item outdents or
converts to paragraph (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8829">#8829</a>)
mayrang</li>
<li>lexical-table Feature Add moveTableRow function Add missing export
for unmergeCellNode (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8833">#8833</a>)</li>
<li>lexical-link Bug Fix disable link opening for disabled autolink in
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8839">#8839</a>)
Olivier Chevallier</li>
<li>lexical-rich-textlexical-plain-text Bug Fix dont cancel dragover for
text drags so native drops work again (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8842">#8842</a>)
Bob Ippolito</li>
<li>Open playground links in a new tab (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8837">#8837</a>)
Sherry</li>
<li>lexical-react Bug Fix Merge adjacent OverflowNodes in
useCharacterLimit (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8831">#8831</a>)
mayrang</li>
<li>lexical-code-shiki Bug Fix force re-tokenize after async language
load (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8830">#8830</a>)
Olivier Chevallier</li>
<li>lexical-tablelexical-playground Bug Fix Auto-scroll while
drag-selecting cells past the visible edge (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8822">#8822</a>)
Oleksandr Trukhnii</li>
<li>lexical-mdastlexical-markdown Bug Fix Roundtrip overlapping inline
formats (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8825">#8825</a>)
Bob Ippolito</li>
<li>v0.47.0 (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8821">#8821</a>)
Bob Ippolito</li>
<li>v0.47.0 Lexical GitHub Actions Bot</li>
</ul>
<h2>v0.47.0 (2026-07-10)</h2>
<ul>
<li>lexicallexical-rich-text Bug Fix Fix formatText toggle direction and
add SETTEXTFORMATCOMMAND (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8807">#8807</a>)
mayrang</li>
<li>scripts Bug Fix Let npm prompt for OTP when publishing bootstrap
stubs (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8820">#8820</a>)
Bob Ippolito</li>
<li>lexical-playground Bug Fix Clear inline font-size when converting to
heading (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8800">#8800</a>)
mayrang</li>
<li>lexical-tablelexical-playground Feature setTableRowIsHeader and
setTableColumnIsHeader utilities (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8815">#8815</a>)
mayrang</li>
<li>lexical-website Documentation Update Rewrite testing guide (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8811">#8811</a>)
mayrang</li>
<li>lexical-mdastlexical-rich-text Feature lexicalmdast, a
micromarkmdast-based alternative to lexicalmarkdown (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8794">#8794</a>)
Bob Ippolito</li>
<li>Make dependency-check resilient to transient registry errors (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8818">#8818</a>)
Gerard Rovira</li>
<li>lexical Refactor Move event module globals into per-editor
InputState (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8809">#8809</a>)
mayrang</li>
<li>lexical Bug Fix getDocument() should fall back to the global
document when there is no active editor (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8813">#8813</a>)
Sherry</li>
<li>lexical-playground Bug Fix Keep cell background color modal open on
first click (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8806">#8806</a>)
sahir</li>
<li>lexical-playground Bug Fix Use consistent default maxWidth for
markdown-imported images (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8810">#8810</a>)
mayrang</li>
<li>lexical-devtoolslexical-playground Chore Update flow, hermes, and
babel packages to latest (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8795">#8795</a>)
Bob Ippolito</li>
<li>Add a 7-day pnpm minimumReleaseAge to match the Dependabot cooldown
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8808">#8808</a>)
Gerard Rovira</li>
<li>lexical Chore Fix tmp package dependency vulnerability (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8802">#8802</a>)
vijay ojha</li>
<li>lexical Chore Add missing Flow type declarations (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8799">#8799</a>)
mayrang</li>
<li>lexical-markdown Feature Add generateNodesFromMarkdownString (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8789">#8789</a>)
mayrang</li>
<li>lexicallexical-playground Chore Refactor IME composition test
infrastructure and add browser-level coverage (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8793">#8793</a>)
mayrang</li>
<li>lexical-playground Bug Fix Use viewBox dimensions for unsized
Excalidraw output (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8798">#8798</a>)
mayrang</li>
<li>lexical-table Bug Fix Export insertTableRowAtNode and
insertTableColumnAtNode (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8791">#8791</a>)</li>
<li>lexical-playgroundlexical-website Feature Add Vercel Analytics and
Speed Insights (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8796">#8796</a>)
Gerard Rovira</li>
<li>lexicallexical-eslint-plugin Feature Add getDocument() API and
Shadow DOM lint enforcement (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8788">#8788</a>)
mayrang</li>
<li>scripts Bug Fix strip misplaced pure annotations from prod builds
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8786">#8786</a>)
Bob Ippolito</li>
<li>lexical Bug Fix deleteCharacter overwrites X11 PRIMARY selection via
Selection.modify (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8774">#8774</a>)
Bob Ippolito</li>
<li>lexical-playground Bug Fix Support Unicode URLs in autolink matcher
(<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8787">#8787</a>)
mayrang</li>
<li>lexical-table Feature Spread pasted TSV text across table cells (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8780">#8780</a>)
mayrang</li>
<li>Breaking Changelexical Bug Fix Preserve DOM element when composing
on segmented TextNode middle (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8784">#8784</a>)
mayrang</li>
<li>Breaking Changelexical-reactlexical-devtools-core Chore Drop React
17 support, baseline is now React 18 (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8782">#8782</a>)
Bob Ippolito</li>
<li>lexical-playgroundlexical Feature Ruby annotation node with floating
editor (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8741">#8741</a>)
mayrang</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/facebook/lexical/commit/284b7491d014c412a11ecc8e4b8ea8e09e07f7e9"><code>284b749</code></a>
v0.48.0</li>
<li><a
href="https://github.com/facebook/lexical/commit/e4b7cc3f420226059c8aa30df6e89bd5fadbea90"><code>e4b7cc3</code></a>
v0.47.0 (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8821">#8821</a>)</li>
<li><a
href="https://github.com/facebook/lexical/commit/a7666ab11f5e8c674a3f5ca8a83d2e92f1b171d0"><code>a7666ab</code></a>
[*][lexical-devtools][lexical-playground] Chore: Update flow, hermes,
and bab...</li>
<li><a
href="https://github.com/facebook/lexical/commit/e649ab28b7e2dd58c1b4798c446e611f54356518"><code>e649ab2</code></a>
[lexical][lexical-eslint-plugin] Feature: Add $getDocument() API and
Shadow D...</li>
<li><a
href="https://github.com/facebook/lexical/commit/62a4b30f382b4dc60cacd1a9d753a2d1f44d9f5e"><code>62a4b30</code></a>
[lexical][*] Feature: registerEventListener / registerEventListeners DOM
help...</li>
<li><a
href="https://github.com/facebook/lexical/commit/cf25494881c9c04b090f6681d7b603ec31e157ff"><code>cf25494</code></a>
[lexical-utils] Bug Fix: positionNodeOnRange leaking orphan rect nodes
when r...</li>
<li><a
href="https://github.com/facebook/lexical/commit/1803c54f0e9cffad42a145e3bcaaf5051fe7fdee"><code>1803c54</code></a>
[lexical-selection] Bug Fix: Properly handle block end focus in backward
sele...</li>
<li><a
href="https://github.com/facebook/lexical/commit/fc162d45ae707869f47066f1aafc6fe47b1dfae1"><code>fc162d4</code></a>
[lexical-extension][lexical-playground] Chore: Some cleanups (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8732">#8732</a>)</li>
<li><a
href="https://github.com/facebook/lexical/commit/041c8642c0c0f4d0b7e791f3c499dfeac50a4a9e"><code>041c864</code></a>
v0.46.0 (<a
href="https://github.com/facebook/lexical/tree/HEAD/packages/lexical-utils/issues/8748">#8748</a>)</li>
<li><a
href="https://github.com/facebook/lexical/commit/6352a9a7f99c33d10e8b2698738d3bb6c5b6fe51"><code>6352a9a</code></a>
[lexical-utils][lexical-react] Chore: Move getScrollParent to
<code>@​lexical/utils</code> ...</li>
<li>Additional commits viewable in <a
href="https://github.com/facebook/lexical/commits/v0.48.0/packages/lexical-utils">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for <code>@​lexical/utils</code> since your current
version.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@lexical/utils&package-manager=npm_and_yarn&previous-version=0.44.0&new-version=0.48.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 11:20:57 +00:00
dependabot[bot] e63bbc8a32 chore: bump tailwindcss from 3.4.18 to 3.4.19 in /site (#27750)
Bumps
[tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss)
from 3.4.18 to 3.4.19.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/tailwindlabs/tailwindcss/releases">tailwindcss's
releases</a>.</em></p>
<blockquote>
<h2>v3.4.19</h2>
<h3>Fixed</h3>
<ul>
<li>Don’t break <code>sibling-*()</code> functions when used inside
<code>calc(…)</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19335">#19335</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md">tailwindcss's
changelog</a>.</em></p>
<blockquote>
<h2>[3.4.19] - 2025-12-10</h2>
<h3>Fixed</h3>
<ul>
<li>Don’t break <code>sibling-*()</code> functions when used inside
<code>calc(…)</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19335">#19335</a>)</li>
</ul>
<h2>[4.1.17] - 2025-11-06</h2>
<h3>Fixed</h3>
<ul>
<li>Substitute <code>@variant</code> inside legacy JS APIs (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19263">#19263</a>)</li>
<li>Prevent occasional crash on Windows when loaded into a worker thread
(<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19242">#19242</a>)</li>
</ul>
<h2>[4.1.16] - 2025-10-23</h2>
<h3>Fixed</h3>
<ul>
<li>Discard candidates with an empty data type (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19172">#19172</a>)</li>
<li>Fix canonicalization of arbitrary variants with attribute selectors
(<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19176">#19176</a>)</li>
<li>Fix invalid colors due to nested <code>&amp;</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19184">#19184</a>)</li>
<li>Improve canonicalization for <code>&amp; &gt; :pseudo</code> and
<code>&amp; :pseudo</code> arbitrary variants (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19178">#19178</a>)</li>
</ul>
<h2>[4.1.15] - 2025-10-20</h2>
<h3>Fixed</h3>
<ul>
<li>Fix Safari devtools rendering issue due to <code>color-mix</code>
fallback (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19069">#19069</a>)</li>
<li>Suppress Lightning CSS warnings about <code>:deep</code>,
<code>:slotted</code>, and <code>:global</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19094">#19094</a>)</li>
<li>Fix resolving theme keys when starting with the name of another
theme key in JS configs and plugins (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19097">#19097</a>)</li>
<li>Allow named groups in combination with <code>not-*</code>,
<code>has-*</code>, and <code>in-*</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19100">#19100</a>)</li>
<li>Prevent important utilities from affecting other utilities (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19110">#19110</a>)</li>
<li>Don’t index into strings with the <code>theme(…)</code> function (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19111">#19111</a>)</li>
<li>Fix parsing issue when <code>\t</code> is used in at-rules (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19130">#19130</a>)</li>
<li>Upgrade: Canonicalize utilities containing <code>0</code> values (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19095">#19095</a>)</li>
<li>Upgrade: Migrate deprecated <code>break-words</code> to
<code>wrap-break-word</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19157">#19157</a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Remove the <code>postinstall</code> script from oxide (<a
href="https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss/issues/19149">#19149</a>)(<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/19149">tailwindlabs/tailwindcss#19149</a>)</li>
</ul>
<h2>[4.1.14] - 2025-10-01</h2>
<h3>Fixed</h3>
<ul>
<li>Handle <code>'</code> syntax in ClojureScript when extracting
classes (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/18888">#18888</a>)</li>
<li>Handle <code>@variant</code> inside <code>@custom-variant</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/18885">#18885</a>)</li>
<li>Merge suggestions when using <code>@utility</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/18900">#18900</a>)</li>
<li>Ensure that file system watchers created when using the CLI are
always cleaned up (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/18905">#18905</a>)</li>
<li>Do not generate <code>grid-column</code> utilities when configuring
<code>grid-column-start</code> or <code>grid-column-end</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/18907">#18907</a>)</li>
<li>Do not generate <code>grid-row</code> utilities when configuring
<code>grid-row-start</code> or <code>grid-row-end</code> (<a
href="https://redirect.github.com/tailwindlabs/tailwindcss/pull/18907">#18907</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/tailwindlabs/tailwindcss/commits/v3.4.19/packages/tailwindcss">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=tailwindcss&package-manager=npm_and_yarn&previous-version=3.4.18&new-version=3.4.19)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 11:20:05 +00:00
dependabot[bot] c3bd8bece4 chore: bump @fontsource-variable/geist from 5.2.9 to 5.3.0 in /site (#27749)
Bumps
[@fontsource-variable/geist](https://github.com/fontsource/font-files/tree/HEAD/fonts/variable/geist)
from 5.2.9 to 5.3.0.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/fontsource/font-files/commits/HEAD/fonts/variable/geist">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@fontsource-variable/geist&package-manager=npm_and_yarn&previous-version=5.2.9&new-version=5.3.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 11:19:32 +00:00
dependabot[bot] 0b3212ddf2 chore: bump @fontsource/source-code-pro from 5.2.7 to 5.3.0 in /site (#27746)
Bumps
[@fontsource/source-code-pro](https://github.com/fontsource/font-files/tree/HEAD/fonts/google/source-code-pro)
from 5.2.7 to 5.3.0.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/fontsource/font-files/commits/HEAD/fonts/google/source-code-pro">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@fontsource/source-code-pro&package-manager=npm_and_yarn&previous-version=5.2.7&new-version=5.3.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 11:18:15 +00:00
dependabot[bot] 2cbb6629e4 chore: bump humanize-duration from 3.33.1 to 3.34.0 in /site (#27742)
Bumps
[humanize-duration](https://github.com/EvanHahn/HumanizeDuration.js)
from 3.33.1 to 3.34.0.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/EvanHahn/HumanizeDuration.js/blob/main/HISTORY.md">humanize-duration's
changelog</a>.</em></p>
<blockquote>
<h1>3.34.0 / 2026-06-29</h1>
<ul>
<li>new: Norwegian Nynorsk support (<code>nn</code>)</li>
<li>fix: Lithuanian now uses the singular form for counts such as 101
and 201 (for example &quot;101 diena&quot; instead of &quot;101
dienų&quot;)</li>
</ul>
<h1>3.33.2 / 2025-12-07</h1>
<ul>
<li>fix: Romanian now correctly uses &quot;de&quot; before nouns for
numbers &gt;= 20 such as &quot;20 de minute&quot; instead of &quot;20
minute&quot; (see <a
href="https://redirect.github.com/EvanHahn/HumanizeDuration.js/pull/235">#235</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/EvanHahn/HumanizeDuration.js/commit/49fa19c1e64833630f1f5a2b7ef5b5410933c372"><code>49fa19c</code></a>
3.34.0</li>
<li><a
href="https://github.com/EvanHahn/HumanizeDuration.js/commit/47ab9424702dd10808d5b6292fdcf8dfd340103a"><code>47ab942</code></a>
Update changelog and bower.json for 3.34.0 release</li>
<li><a
href="https://github.com/EvanHahn/HumanizeDuration.js/commit/545a37b2d8318f6b21851cc886ff2edf7a79e3cf"><code>545a37b</code></a>
Update devDependencies to latest versions</li>
<li><a
href="https://github.com/EvanHahn/HumanizeDuration.js/commit/23607f9fa017638809dad87d9f6961f7d99d7487"><code>23607f9</code></a>
Update TypeScript to latest (RC) version</li>
<li><a
href="https://github.com/EvanHahn/HumanizeDuration.js/commit/0883f5dbf59c6d81aac57279e969d621dad6e31b"><code>0883f5d</code></a>
Update changelog with Norwegian Nynorsk change</li>
<li><a
href="https://github.com/EvanHahn/HumanizeDuration.js/commit/ffcfa2a482570db1ed4a967f2ed28259eb9bb0ea"><code>ffcfa2a</code></a>
Update ESLint dependencies to latest version</li>
<li><a
href="https://github.com/EvanHahn/HumanizeDuration.js/commit/c2791af9d6818242fa9dee636004dde2980b3033"><code>c2791af</code></a>
Update Git URL</li>
<li><a
href="https://github.com/EvanHahn/HumanizeDuration.js/commit/0f69e090fa5e702aaabab1df610db2302fa97359"><code>0f69e09</code></a>
Fix Lithuanian form for counts like 101 and 201 (<a
href="https://redirect.github.com/EvanHahn/HumanizeDuration.js/issues/237">#237</a>)</li>
<li><a
href="https://github.com/EvanHahn/HumanizeDuration.js/commit/fd49da2861bfd3f76711e8b4b87977d699dee983"><code>fd49da2</code></a>
Add Norwegian Nynorsk (nn) language</li>
<li><a
href="https://github.com/EvanHahn/HumanizeDuration.js/commit/b961e8cace217f77f4481981ec5108065f0de2af"><code>b961e8c</code></a>
Mention <code>Intl.DurationFormat</code> in the readme</li>
<li>Additional commits viewable in <a
href="https://github.com/EvanHahn/HumanizeDuration.js/compare/v3.33.1...v3.34.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=humanize-duration&package-manager=npm_and_yarn&previous-version=3.33.1&new-version=3.34.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 11:16:43 +00:00
dependabot[bot] 4c079ef689 chore: bump axios from 1.18.0 to 1.18.1 in /site (#27741)
Bumps [axios](https://github.com/axios/axios) from 1.18.0 to 1.18.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/axios/axios/releases">axios's
releases</a>.</em></p>
<blockquote>
<h2>v1.18.1 — June 21, 2026</h2>
<p>This release focuses on Node HTTP adapter fixes, safer AxiosError
serialisation, runtime/type correctness fixes, documentation updates,
and dependency maintenance.</p>
<h2>🐛 Bug Fixes</h2>
<ul>
<li>AxiosError Serialisation: Made AxiosError#cause non-enumerable to
prevent circular JSON serialisation failures when errors include nested
causes. (<a
href="https://redirect.github.com/axios/axios/issues/10913">#10913</a>)</li>
<li>Node HTTP Adapter: Guarded socket.setKeepAlive for proxy agent
streams, accepted path-only URLs when socketPath is configured, deferred
environment proxy handling to Node, and explicitly passed maxBodyLength
through to follow-redirects. (<a
href="https://redirect.github.com/axios/axios/issues/10917">#10917</a>,
<a
href="https://redirect.github.com/axios/axios/issues/10930">#10930</a>,
<a
href="https://redirect.github.com/axios/axios/issues/10942">#10942</a>,
<a
href="https://redirect.github.com/axios/axios/issues/10993">#10993</a>)</li>
<li>Runtime and Type Correctness: Fixed several runtime crashes, type
definition mismatches, and incorrect error handling paths. (<a
href="https://redirect.github.com/axios/axios/issues/10959">#10959</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11021">#11021</a>)</li>
<li>AxiosURLSearchParams: Switched the encoder callback to an arrow
function so <code>encoder.call(this)</code> receives the
<code>AxiosURLSearchParams</code> instance correctly. (<a
href="https://redirect.github.com/axios/axios/issues/11019">#11019</a>)</li>
</ul>
<h2>🔧 Maintenance &amp; Chores</h2>
<ul>
<li>
<p>Documentation: Documented sensitive headers and status transition
behaviour, prepared cleaned-up docs, added Deno install instructions,
and clarified that request data is request-specific (<a
href="https://redirect.github.com/axios/axios/issues/11007">#11007</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11010">#11010</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11023">#11023</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11025">#11025</a>)</p>
</li>
<li>
<p>Dependencies: Bumped vite, rollup, form-data, js-yaml, and multer
across the root project, docs, smoke tests, and module test workspaces.
(<a
href="https://redirect.github.com/axios/axios/issues/11011">#11011</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11012">#11012</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11013">#11013</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11014">#11014</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11015">#11015</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11016">#11016</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11017">#11017</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11026">#11026</a>)</p>
</li>
</ul>
<h2>🌟 New Contributors</h2>
<p>We are thrilled to welcome our new contributors. Thank you for
helping improve axios:</p>
<ul>
<li><a
href="https://github.com/webdevelopersrinu"><code>@​webdevelopersrinu</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/10913">#10913</a>)</li>
<li><a href="https://github.com/sijie-Z"><code>@​sijie-Z</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/10993">#10993</a>)</li>
<li><a
href="https://github.com/bartlomieju"><code>@​bartlomieju</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11023">#11023</a>)</li>
<li><a href="https://github.com/JSap0914"><code>@​JSap0914</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11019">#11019</a>)</li>
</ul>
<p><a
href="https://github.com/axios/axios/compare/v1.18.0...v1.18.1">Full
Changelog</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/axios/axios/blob/v1.x/CHANGELOG.md">axios's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<h2>v1.19.0 — July 22, 2026</h2>
<p>This release raises the form-data security floor, adds configuration
and type-system capabilities, and fixes NO_PROXY matching, interceptor
errors, progress reporting, and serialization edge cases.</p>
<h2>🔒 Security Fixes</h2>
<ul>
<li>Multipart Form Data: Raised the form-data dependency floor to
^4.0.6, preventing fresh installations from resolving versions affected
by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (<a
href="https://github.com/advisories/GHSA-hmw2-7cc7-3qxx">https://github.com/advisories/GHSA-hmw2-7cc7-3qxx</a>).
(<a
href="https://redirect.github.com/axios/axios/issues/11028">#11028</a>)</li>
</ul>
<h2>🚀 New Features</h2>
<ul>
<li>Configuration Extensibility: Preserved own-enumerable symbol-keyed
fields through mergeConfig and added a generic params type across public
TypeScript declarations, responses, errors,
adapters, and serializers. (<a
href="https://redirect.github.com/axios/axios/issues/11043">#11043</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11081">#11081</a>)</li>
<li>Header Parameter Parsing: Added the opt-in
AxiosHeaders.parseParameters() parser for quote-aware, RFC-style HTTP
parameter parsing while preserving legacy parsing behavior. (<a
href="https://redirect.github.com/axios/axios/issues/11051">#11051</a>)</li>
<li>HTTP Status Codes: Added the missing Cloudflare 520
WebServerReturnsAnUnknownError status and matching ESM/CJS declarations.
(<a
href="https://redirect.github.com/axios/axios/issues/11067">#11067</a>)</li>
</ul>
<h2>🐛 Bug Fixes</h2>
<ul>
<li>
<p>Form Data Conversion: Limited formDataToJSON path splitting to dot
and bracket notation, preserving literal punctuation in keys, and
removed browser-facing Buffer.from usage from toFormData to avoid
unnecessary polyfills. (<a
href="https://redirect.github.com/axios/axios/issues/11006">#11006</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11018">#11018</a>)</p>
</li>
<li>
<p>Proxy Bypass: Canonicalized IPv4 shorthand, octal, and hexadecimal
forms during NO_PROXY matching and honored * entries within comma- or
space-separated bypass lists. (<a
href="https://redirect.github.com/axios/axios/issues/11029">#11029</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11053">#11053</a>)</p>
</li>
<li>
<p>Cancellation: Propagated already-aborted input signals immediately
when composing abort signals. (<a
href="https://redirect.github.com/axios/axios/issues/11035">#11035</a>)</p>
</li>
<li>
<p>Header Handling: Preserved empty first values for duplicate singleton
headers and made AxiosHeaders#getSetCookie() consistently return arrays
for present values. (<a
href="https://redirect.github.com/axios/axios/issues/11036">#11036</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11037">#11037</a>)</p>
</li>
<li>
<p>URL Handling: Included normalized, safely redacted offending URLs in
malformed-protocol errors and removed repeated trailing slashes when
combining base URLs. (<a
href="https://redirect.github.com/axios/axios/issues/11008">#11008</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11038">#11038</a>)</p>
</li>
<li>
<p>Progress Events: Clamped malformed negative progress values to zero
and ensured final Node.js download progress events are delivered before
streamed responses close. (<a
href="https://redirect.github.com/axios/axios/issues/11039">#11039</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11040">#11040</a>)</p>
</li>
<li>
<p>Error and JSON Serialization: Serialized Set values as arrays in
JSON-compatible snapshots and synthesized useful AxiosError messages
from otherwise-empty AggregateError instances. (<a
href="https://redirect.github.com/axios/axios/issues/11044">#11044</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11059">#11059</a>)</p>
</li>
<li>
<p>Content-Length Enforcement: Corrected base64 data: URL size
estimation so maxContentLength is enforced consistently by the HTTP and
Fetch adapters. (<a
href="https://redirect.github.com/axios/axios/issues/11061">#11061</a>)</p>
</li>
<li>
<p>Synchronous Interceptors: Prevented requests from being dispatched
after synchronous request interceptors fail unless their paired
rejection handler resolves successfully. (<a
href="https://redirect.github.com/axios/axios/issues/11071">#11071</a>)</p>
</li>
</ul>
<h2>🔧 Maintenance &amp; Chores</h2>
<ul>
<li>Dependencies: Updated development and test tooling, the docs
fixture's Axios version, and GitHub Actions integrations including
Checkout, Setup Node, Setup Deno, and Zizmor. (<a
href="https://redirect.github.com/axios/axios/issues/11031">#11031</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11055">#11055</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11056">#11056</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11058">#11058</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11079">#11079</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11080">#11080</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11088">#11088</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11089">#11089</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11090">#11090</a>)</li>
<li>Build Outputs: Limited sourcemap generation to published minified
bundles, removing broken map references from non-minified builds. (<a
href="https://redirect.github.com/axios/axios/issues/11054">#11054</a>)</li>
<li>Form Data Internals: Centralized FormData header handling and made
the Node.js adapter tolerate getHeaders() returning undefined under the
content-only policy. (<a
href="https://redirect.github.com/axios/axios/issues/11062">#11062</a>)</li>
<li>Developer Experience: Ignored common local AI-tooling directories
and fixed a constant-reassignment crash when the development sandbox
serves its root path. (<a
href="https://redirect.github.com/axios/axios/issues/11032">#11032</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11073">#11073</a>)</li>
<li>Documentation: Updated sponsor information, clarified that baseURL
is not a path-security boundary, scoped provenance claims to attested
releases, and corrected the configuration-defaults documentation. (<a
href="https://redirect.github.com/axios/axios/issues/11041">#11041</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11068">#11068</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11076">#11076</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11078">#11078</a>)</li>
<li>Publishing: Simplified v1 publishing to use the npm version bundled
with Node.js 26 and updated package metadata for the 1.19.0 release. (<a
href="https://redirect.github.com/axios/axios/issues/11083">#11083</a>,
<a
href="https://redirect.github.com/axios/axios/issues/11095">#11095</a>)</li>
</ul>
<h2>🌟 New Contributors</h2>
<p>We are thrilled to welcome our new contributors. Thank you for
helping improve Axios:</p>
<ul>
<li><a
href="https://github.com/afonsojramos"><code>@​afonsojramos</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11028">#11028</a>)</li>
<li><a
href="https://github.com/MahinAnowar"><code>@​MahinAnowar</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11006">#11006</a>)</li>
<li><a
href="https://github.com/yassertawfik4"><code>@​yassertawfik4</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11024">#11024</a>)</li>
<li><a
href="https://github.com/AnandSundar"><code>@​AnandSundar</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11029">#11029</a>)</li>
<li><a
href="https://github.com/lin-hongkuan"><code>@​lin-hongkuan</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11035">#11035</a>)</li>
<li><a
href="https://github.com/Wali007-lab"><code>@​Wali007-lab</code></a> (<a
href="https://redirect.github.com/axios/axios/issues/11054">#11054</a>)</li>
<li><a href="https://github.com/magicdawn"><code>@​magicdawn</code></a>
(<a
href="https://redirect.github.com/axios/axios/issues/11043">#11043</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/axios/axios/commit/a209bfb1e5dcbce3cecbf4bd955339d006358887"><code>a209bfb</code></a>
chore(release): prepare release 1.18.1 (<a
href="https://redirect.github.com/axios/axios/issues/11027">#11027</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/fa6a55ef99235074d2c11d80a1064ef02850d598"><code>fa6a55e</code></a>
chore(deps-dev): bump multer from 2.1.1 to 2.2.0 (<a
href="https://redirect.github.com/axios/axios/issues/11026">#11026</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/40e7be8a78dd43caaeb2313cc4be3f8e714be91d"><code>40e7be8</code></a>
docs: clarifies that request data is request-specific in axios (<a
href="https://redirect.github.com/axios/axios/issues/11025">#11025</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/a446b39b19c8b570214a4158520c5ddd5b020366"><code>a446b39</code></a>
fix(AxiosURLSearchParams): use arrow function so encoder.call(this)
receives ...</li>
<li><a
href="https://github.com/axios/axios/commit/cf1306a42d97960b635c894c83658f2692e53585"><code>cf1306a</code></a>
docs: add Deno to install instructions (<a
href="https://redirect.github.com/axios/axios/issues/11023">#11023</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/b32880af48017457a1203ab2e63720902d3b71b3"><code>b32880a</code></a>
fix: incorrect use of error (<a
href="https://redirect.github.com/axios/axios/issues/11021">#11021</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/1792eda11aff8fe0f8c8a6e5ae6ff305740a6460"><code>1792eda</code></a>
fix: ensure maxBodyLength is explicitly passed to follow-redirects (<a
href="https://redirect.github.com/axios/axios/issues/10993">#10993</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/30499d6af0961ec38619792013a534d1933b08a9"><code>30499d6</code></a>
fix: various runtime crashes and type definition mismatches (<a
href="https://redirect.github.com/axios/axios/issues/10959">#10959</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/20ce9c412ebd88823d1a4a47000cb133a8f79440"><code>20ce9c4</code></a>
fix(http): defer env proxy handling to Node (<a
href="https://redirect.github.com/axios/axios/issues/10942">#10942</a>)</li>
<li><a
href="https://github.com/axios/axios/commit/e64bcf9c5af231d6f37d8389b1e57ded314fff86"><code>e64bcf9</code></a>
chore(deps): merge branch 'v1.x' into tests/module/cjs (<a
href="https://redirect.github.com/axios/axios/issues/11014">#11014</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/axios/axios/compare/v1.18.0...v1.18.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=axios&package-manager=npm_and_yarn&previous-version=1.18.0&new-version=1.18.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 11:16:25 +00:00
dependabot[bot] f2774d4d3c chore: bump the react group across 1 directory with 3 updates (#27734)
[//]: # (dependabot-start)
⚠️  **Dependabot is rebasing this PR** ⚠️ 

Rebasing might not happen immediately, so don't worry if this takes some
time.

Note: if you make any changes to this PR yourself, they will take
precedence over the rebase.

---

[//]: # (dependabot-end)

Bumps the react group with 3 updates in the /site directory:
[react](https://github.com/react/react/tree/HEAD/packages/react),
[@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react)
and
[react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom).

Updates `react` from 19.2.6 to 19.2.8
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/react/react/releases">react's
releases</a>.</em></p>
<blockquote>
<h2>19.2.8 (July 21st, 2026)</h2>
<h2>React Server Components</h2>
<ul>
<li>Performance improvements when decoding
(<a
href="https://redirect.github.com/facebook/react/pull/37087">#37087</a>
by <a href="https://github.com/eps1lon"><code>@​eps1lon</code></a>)</li>
</ul>
<h2>19.2.7 (June 1st, 2026)</h2>
<h2>React Server Components</h2>
<ul>
<li>Fixed missing <code>FormData</code> entries in Server Actions which
regressed in 19.2.6
(<a
href="https://redirect.github.com/facebook/react/pull/36566">#36566</a>
by <a
href="https://github.com/unstubbable"><code>@​unstubbable</code></a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/react/react/blob/main/CHANGELOG.md">react's
changelog</a>.</em></p>
<blockquote>
<h2>19.2.7 (June 1, 2026)</h2>
<h3>React Server Components</h3>
<ul>
<li>Fixed missing <code>FormData</code> entries in Server Actions which
regressed in 19.2.6 (<a
href="https://github.com/unstubbable"><code>@​unstubbable</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36566">#36566</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/react/react/commit/1dd4ecbdabf826f527fc9a58c05ea70375b7d170"><code>1dd4ecb</code></a>
[FlightReply] Performance improvements when decoding (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/37087">#37087</a>)</li>
<li><a
href="https://github.com/react/react/commit/b0d2fdb78bdfae075a7fa02ddcebbf25f90952c2"><code>b0d2fdb</code></a>
[19.2.x] Update required references to GitHub repo (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/36753">#36753</a>)</li>
<li><a
href="https://github.com/react/react/commit/6117d7cca4906492c51fe6a03381e35adfd86e7d"><code>6117d7c</code></a>
Version 19.2.7 (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/36591">#36591</a>)</li>
<li>See full diff in <a
href="https://github.com/react/react/commits/v19.2.8/packages/react">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for react since your current version.</p>
</details>
<br />

Updates `@types/react` from 19.2.15 to 19.2.17
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react">compare
view</a></li>
</ul>
</details>
<br />

Updates `react-dom` from 19.2.6 to 19.2.8
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/react/react/releases">react-dom's
releases</a>.</em></p>
<blockquote>
<h2>19.2.8 (July 21st, 2026)</h2>
<h2>React Server Components</h2>
<ul>
<li>Performance improvements when decoding
(<a
href="https://redirect.github.com/facebook/react/pull/37087">#37087</a>
by <a href="https://github.com/eps1lon"><code>@​eps1lon</code></a>)</li>
</ul>
<h2>19.2.7 (June 1st, 2026)</h2>
<h2>React Server Components</h2>
<ul>
<li>Fixed missing <code>FormData</code> entries in Server Actions which
regressed in 19.2.6
(<a
href="https://redirect.github.com/facebook/react/pull/36566">#36566</a>
by <a
href="https://github.com/unstubbable"><code>@​unstubbable</code></a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/react/react/blob/main/CHANGELOG.md">react-dom's
changelog</a>.</em></p>
<blockquote>
<h2>19.2.7 (June 1, 2026)</h2>
<h3>React Server Components</h3>
<ul>
<li>Fixed missing <code>FormData</code> entries in Server Actions which
regressed in 19.2.6 (<a
href="https://github.com/unstubbable"><code>@​unstubbable</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36566">#36566</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/react/react/commit/1dd4ecbdabf826f527fc9a58c05ea70375b7d170"><code>1dd4ecb</code></a>
[FlightReply] Performance improvements when decoding (<a
href="https://github.com/react/react/tree/HEAD/packages/react-dom/issues/37087">#37087</a>)</li>
<li><a
href="https://github.com/react/react/commit/b0d2fdb78bdfae075a7fa02ddcebbf25f90952c2"><code>b0d2fdb</code></a>
[19.2.x] Update required references to GitHub repo (<a
href="https://github.com/react/react/tree/HEAD/packages/react-dom/issues/36753">#36753</a>)</li>
<li><a
href="https://github.com/react/react/commit/6117d7cca4906492c51fe6a03381e35adfd86e7d"><code>6117d7c</code></a>
Version 19.2.7 (<a
href="https://github.com/react/react/tree/HEAD/packages/react-dom/issues/36591">#36591</a>)</li>
<li>See full diff in <a
href="https://github.com/react/react/commits/v19.2.8/packages/react-dom">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for react-dom since your current version.</p>
</details>
<br />

Updates `@types/react` from 19.2.15 to 19.2.17
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 11:13:11 +00:00
dependabot[bot] 8342acee99 chore: bump @types/node from 22.20.0 to 22.20.1 in /offlinedocs (#27740)
Bumps
[@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
from 22.20.0 to 22.20.1.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@types/node&package-manager=npm_and_yarn&previous-version=22.20.0&new-version=22.20.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 11:12:04 +00:00
dependabot[bot] 599e0ba98e chore: bump @chakra-ui/react from 2.10.9 to 2.10.10 in /offlinedocs (#27739)
Bumps
[@chakra-ui/react](https://github.com/chakra-ui/chakra-ui/tree/HEAD/packages/react)
from 2.10.9 to 2.10.10.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/chakra-ui/chakra-ui/commits/@chakra-ui/react@2.10.10/packages/react">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@chakra-ui/react&package-manager=npm_and_yarn&previous-version=2.10.9&new-version=2.10.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 11:11:47 +00:00
dependabot[bot] b518713ab7 chore: bump sanitize-html from 2.17.5 to 2.17.6 in /offlinedocs (#27738)
Bumps
[sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html)
from 2.17.5 to 2.17.6.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md">sanitize-html's
changelog</a>.</em></p>
<blockquote>
<h2>2.17.6 (2026-07-10)</h2>
<h3>Fixes</h3>
<ul>
<li>Allow transformTags to emit text when textFilter is set, even if the
tag is initially empty. This is consistent with the documentation.
Thanks to <a href="https://github.com/spokodev">spokodev</a> for the
fix.</li>
</ul>
<h3>Security</h3>
<ul>
<li>Fixed an XSS/allowlist bypass in which the contents of a raw-text
element (<code>textarea</code> or <code>xmp</code>) nested inside an
<code>svg</code> or <code>math</code> root were re-emitted without
HTML-escaping. <code>sanitize-html</code> treated that content as inert
raw text because <code>htmlparser2</code> 10.x classified raw-text
elements by tag name and ignored the namespace, but a real HTML5 parser
treats <code>textarea</code>/<code>xmp</code> as ordinary foreign
elements inside SVG/MathML and re-parses their contents as live markup.
As a result, markup and event-handler attributes that the allowlist
never permitted (for example <code>&lt;svg&gt;&lt;textarea&gt;&lt;img
src=x onerror=alert(1)&gt;</code>) could survive sanitization and
execute in the browser. This is now fixed on two fronts:
<code>htmlparser2</code> was upgraded to 12.x, which is namespace-aware
and parses <code>textarea</code>/<code>xmp</code> inside SVG/MathML as
ordinary elements, so their non-allowlisted children (such as the
injected <code>img</code>) are dropped by the allowlist instead of being
preserved as raw text; and any raw-text content
<code>sanitize-html</code> still emits for these tags (at HTML
integration points such as
<code>foreignObject</code>/<code>mtext</code>, or outside foreign
content) is always HTML-escaped. The default configuration is not
affected; the precondition is an <code>allowedTags</code> that includes
<code>svg</code> or <code>math</code> together with
<code>textarea</code> or <code>xmp</code>. Thanks to <a
href="https://github.com/khoadb175">khoadb175</a> for responsibly
disclosing the vulnerability.</li>
<li>Fixed a mutation-XSS / <code>allowedTags</code> bypass affecting
configurations that allow the <code>textarea</code> or <code>xmp</code>
raw-text tags. <code>htmlparser2</code> 10.x did not recognize an end
tag with a trailing solidus (e.g. <code>&lt;/textarea/&gt;</code>) as
closing the element, so it kept the following markup as raw text, but a
spec-compliant browser treats <code>&lt;/textarea/&gt;</code> as a valid
close and parses that markup as a live element. Because raw-text content
was re-emitted without escaping, a payload such as
<code>&lt;textarea&gt;&lt;/textarea/&gt;&lt;img src=x
onerror=...&gt;</code> could smuggle non-allowlisted, executable markup
through the sanitizer. The default configuration was not affected. This
is now defended at two layers: <code>htmlparser2</code> was upgraded to
12.x, whose tokenizer closes these end tags correctly, and the raw text
sanitize-html emits for these tags is always escaped so no
<code>&lt;</code> can reopen a tag when the output is re-parsed
(<code>textarea</code>, an RCDATA element whose entities
<code>htmlparser2</code> decodes, is escaped like normal text, while
<code>xmp</code>, a raw-text element, has only its angle brackets
escaped to avoid double-encoding already-encoded entities). Because
<code>htmlparser2</code> is ESM-only from version 11 onward,
<code>sanitize-html</code> now requires Node.js
<code>&gt;=22.12.0</code> (the first 22.x release in which
<code>require()</code> of an ES module is available unflagged). Thanks
to <a href="https://github.com/bibu123456">bibu123456</a> for reporting
the vulnerability and <a href="https://github.com/Kayiz-PT">Kayiz-PT</a>
for coordinating the disclosure (GHSA-jxwj-j7wr-gfrw).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/apostrophecms/apostrophe/commits/HEAD/packages/sanitize-html">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=sanitize-html&package-manager=npm_and_yarn&previous-version=2.17.5&new-version=2.17.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 11:11:32 +00:00
dependabot[bot] e0fc756a75 chore: bump prettier from 3.9.4 to 3.9.6 in /offlinedocs (#27737)
Bumps [prettier](https://github.com/prettier/prettier) from 3.9.4 to
3.9.6.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/prettier/prettier/releases">prettier's
releases</a>.</em></p>
<blockquote>
<h2>3.9.6</h2>
<h2>What's Changed</h2>
<ul>
<li>Preserve quotes for methods named <code>new</code> (<a
href="https://redirect.github.com/prettier/prettier/pull/19621">prettier/prettier#19621</a>
by <a href="https://github.com/kovsu"><code>@​kovsu</code></a>)</li>
<li>Support <code>import defer</code> in <code>typescript</code> parser
(<a
href="https://redirect.github.com/prettier/prettier/pull/19624">prettier/prettier#19624</a>,
<a
href="https://redirect.github.com/prettier/prettier/pull/19675">prettier/prettier#19675</a>
by <a href="https://github.com/fisker"><code>@​fisker</code></a>)</li>
<li>Added a new official plugin <a
href="https://github.com/prettier/prettier/tree/3.9.6/packages/plugin-yuku"><code>@prettier/plugin-yuku</code>
🚀</a> (<a
href="https://redirect.github.com/prettier/prettier/pull/19628">prettier/prettier#19628</a>,
<a
href="https://redirect.github.com/prettier/prettier/pull/19629">prettier/prettier#19629</a>
by <a href="https://github.com/fisker"><code>@​fisker</code></a>)</li>
</ul>
<p>🔗 <a
href="https://github.com/prettier/prettier/blob/3.9.6/CHANGELOG.md#396">Changelog</a></p>
<h2>3.9.5</h2>
<p>🔗 <a
href="https://github.com/prettier/prettier/blob/3.9.5/CHANGELOG.md#395">Changelog</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/prettier/prettier/blob/main/CHANGELOG.md">prettier's
changelog</a>.</em></p>
<blockquote>
<h1>3.9.6</h1>
<p><a
href="https://github.com/prettier/prettier/compare/3.9.5...3.9.6">diff</a></p>
<h4>TypeScript: Preserve quotes for methods named <code>new</code> (<a
href="https://redirect.github.com/prettier/prettier/pull/19621">#19621</a>
by <a href="https://github.com/kovsu"><code>@​kovsu</code></a>)</h4>
<!-- raw HTML omitted -->
<pre lang="tsx"><code>// Input
interface Container {
  &quot;new&quot;(id: string): number;
}
<p>// Prettier 3.9.5<br />
interface Container {<br />
new(id: string): number;<br />
}</p>
<p>// Prettier 3.9.6<br />
interface Container {<br />
&quot;new&quot;(id: string): number;<br />
}<br />
</code></pre></p>
<h4>TypeScript: Support <code>import defer</code> (<a
href="https://redirect.github.com/prettier/prettier/pull/19624">#19624</a>,
<a
href="https://redirect.github.com/prettier/prettier/pull/19675">#19675</a>
by <a href="https://github.com/fisker"><code>@​fisker</code></a>)</h4>
<!-- raw HTML omitted -->
<pre lang="tsx"><code>// Input
import defer * as foo from &quot;foo&quot;;
<p>// Prettier 3.9.5<br />
import * as foo from &quot;foo&quot;;</p>
<p>// Prettier 3.9.6<br />
import defer * as foo from &quot;foo&quot;;<br />
</code></pre></p>
<h4>JavaScript: Added a new official plugin
<code>@prettier/plugin-yuku</code> (<a
href="https://redirect.github.com/prettier/prettier/pull/19628">#19628</a>,
<a
href="https://redirect.github.com/prettier/prettier/pull/19629">#19629</a>
by <a href="https://github.com/fisker"><code>@​fisker</code></a>)</h4>
<p><code>@prettier/plugin-yuku</code> is powered by <a
href="https://yuku.fyi/">Yuku</a> (A high-performance
JavaScript/TypeScript compiler toolchain written in Zig).</p>
<p>This plugin includes two new parsers: <code>yuku</code> (JavaScript
syntax) and <code>yuku-ts</code> (TypeScript syntax).</p>
<p><strong>To use this plugin:</strong></p>
<ol>
<li>
<p>Install the plugin:</p>
<pre lang="bash"><code>yarn add --dev prettier @prettier/plugin-yuku
</code></pre>
</li>
</ol>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/prettier/prettier/commit/8f0c95057cc91d5836409466cd9d9af3bb901e84"><code>8f0c950</code></a>
Release 3.9.6</li>
<li><a
href="https://github.com/prettier/prettier/commit/e9107647d0497d8ff1cacbb0f970d4543df77c1c"><code>e910764</code></a>
Update changelog</li>
<li><a
href="https://github.com/prettier/prettier/commit/ec3f1c7bd74495992bc6954323a1a7fc8368808e"><code>ec3f1c7</code></a>
Update typescript-eslint to v8.65.0 (<a
href="https://redirect.github.com/prettier/prettier/issues/19675">#19675</a>)</li>
<li><a
href="https://github.com/prettier/prettier/commit/73d2efc2c6cba6f579585c88ef171132d90834ec"><code>73d2efc</code></a>
Update Yuku parser to v0.7.0 (<a
href="https://redirect.github.com/prettier/prettier/issues/19664">#19664</a>)</li>
<li><a
href="https://github.com/prettier/prettier/commit/dd5e24eabeab1f75ad573c79781e5fd408bcfad3"><code>dd5e24e</code></a>
Preserve quotes for <code>TSMethodSignature</code> nodes named
<code>new</code> (<a
href="https://redirect.github.com/prettier/prettier/issues/19621">#19621</a>)</li>
<li><a
href="https://github.com/prettier/prettier/commit/c03ab4e71c23154d6b11537eee3c938f0d0f67d3"><code>c03ab4e</code></a>
Update dependency eslint-plugin-unicorn to v72 (<a
href="https://redirect.github.com/prettier/prettier/issues/19633">#19633</a>)</li>
<li><a
href="https://github.com/prettier/prettier/commit/b74dd53076c7208291a6b2e585c310844b41d35f"><code>b74dd53</code></a>
Update Yuku parser to v0.6.5 (<a
href="https://redirect.github.com/prettier/prettier/issues/19654">#19654</a>)</li>
<li><a
href="https://github.com/prettier/prettier/commit/f1b594ea1db1520c383d0e281d623551f671f824"><code>f1b594e</code></a>
Update dependency eslint-plugin-simple-import-sort to v14 (<a
href="https://redirect.github.com/prettier/prettier/issues/19655">#19655</a>)</li>
<li><a
href="https://github.com/prettier/prettier/commit/0d9dfb61530986373000dd107ea58ceebb79e233"><code>0d9dfb6</code></a>
Update Yuku parser to v0.6.4 (<a
href="https://redirect.github.com/prettier/prettier/issues/19650">#19650</a>)</li>
<li><a
href="https://github.com/prettier/prettier/commit/3bbb8159eb55575d4042653aa99f5f92a1416c19"><code>3bbb815</code></a>
Remove <code>typescript-only</code> directory (<a
href="https://redirect.github.com/prettier/prettier/issues/19636">#19636</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/prettier/prettier/compare/3.9.4...3.9.6">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=prettier&package-manager=npm_and_yarn&previous-version=3.9.4&new-version=3.9.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-01 11:11:07 +00:00
Jake Howell 79724ab0ba chore(site): migrate all <Dialog />s off MUI (#27506)
> 🤖 This PR was modified by Coder Agents on behalf of Jake Howell.

Removes Material UI from every dialog, moving them onto the internal
shadcn/radix `Dialog` primitives. After this change there are **no**
`@mui/material/Dialog` usages left in `site/src`.

## Changes

- Consolidated `components/Dialogs/*` → `components/Dialog/*` and folded
the old `ConfirmDeleteDialog` into `ConfirmDialog` (`type="delete"`).
- Rewrote `ConfirmDialog`, `DeleteDialog`, `WorkspaceDeleteDialog`,
`ScheduleDialog`, and `AnnouncementBannerDialog` onto the internal
primitives (native `Input`/`Label`/`Checkbox`/`Link` instead of MUI).
- Finished the migration for the last two MUI hold-outs:
`UpdateBuildParametersDialog` and `MissingTemplateVariablesDialog`.
- Dialog prop types now compose the rendered component's props
(`ComponentProps<typeof Dialog>` / MUI `DialogProps`) instead of
hand-rolled `{ open; onOpenChange }` shapes.

## Testing

AI-Driven manual dogfood sweep in a live instance (premium license),
driven in a browser. Each dialog checked for logical rendering (layout,
variant styling, buttons, no overlap/blank/console error) and function
(open, primary action, cancel/close, guard states):

| Dialog / surface | How tested | Result |
| --- | --- | --- |
| `ConfirmDialog` (delete / info / success) | Token delete,
update-confirm, change-version | ✅ |
| `DeleteDialog` (type-to-confirm) | Delete user, group, license,
provider, OAuth2 app | ✅ |
| `WorkspaceDeleteDialog` | Workspace actions → Delete (+ orphan path
via failed workspace) | ✅ |
| `ScheduleDialog` | Template schedule → dormancy/deletion warning | ✅ |
| `AnnouncementBannerDialog` | Deployment → Appearance → New banner
(live preview + color) | ✅ |
| `ChangeWorkspaceVersionDialog` | Workspace actions → Change version |
✅ |
| `DownloadLogsDialog` | Workspace actions → Download logs | ✅ |
| Batch delete (workspaces) | Workspaces list → multi-select → Delete |
✅ |
| `TemplatePageHeader` delete | Template → Delete (cancelled) | ✅ |
| `FileDialog` (create/rename/delete) | Template editor file tree | ✅ |
| `MissingTemplateVariablesDialog` *(migrated)* | Editor → add variable
→ Build | ✅ |
| `PublishTemplateVersionDialog` | Editor → Publish | ✅ |
| `UpdateBuildParametersDialog` *(migrated)* | Classic flow + required
param → workspace Update (renders + submits) | ✅ |
| Update-confirmation (`WorkspaceUpdateDialogs`) | Workspace Update | ✅
|
| Suspend/activate confirm | Users → member row | ✅ |
| `ResetPasswordDialog` | Users → member → Reset password | ✅ |
| Token delete confirm | Settings → Tokens | ✅ |
| Create-token confirm | Token create flow | ✅ |
| SSH key regenerate confirm | Settings → SSH Keys | ✅ |
| Change-login-type confirm | Settings → Security | ✅ |
| Secret delete | Settings → Secrets | ✅ |
| Group delete | Admin → Groups | ✅ |
| Org member remove | Admin → Organization → Members | ✅ |
| License remove | Deployment → Licenses (cancelled) | ✅ |
| Announcement banner delete | Deployment → Appearance | ✅ |
| OAuth2 app delete | Deployment → OAuth2 apps | ✅ |
| `ModelFormDialogs` (form + delete) | AI → Models | ✅ |
| Provider delete | AI → Providers | ✅ |
| Gateway key create/delete | AI → Gateway keys | ✅ |
| `MCPServerFormDialogs` delete | AI → MCP servers | ✅ |
| Personal skill (create form + delete) | Agents → Personal Skills | ✅ |
| Spend user-override (add + delete) | AI → Spend | ✅ |

Human tested:

- [x] template version promote/archive
- [x] external-auth/OAuth2-provider delete 
- [x] custom-role delete
- [x] cancel-provisioner-job

Things that have a chance to bleed:

- tasks dialogs
- dormant inline confirm

Should be known that each of these renders through the already-verified
`ConfirmDialog`/`DeleteDialog`, so the underlying component is covered
even where the specific trigger wasn't reachable.

<details>
<summary>Plan &amp; decision log</summary>

**Goal:** finish the de-MUI migration everywhere and confirm every
affected modal renders logically and functions.

**Phase 1 - complete the migration**

- Confirmed only two files still rendered MUI `Dialog`
(`UpdateBuildParametersDialog`, `MissingTemplateVariablesDialog`);
ported both to the internal primitives, preserving the `{ open, onClose,
... }` public API (mapped to `onOpenChange` internally) so call sites
were unchanged. radix now wires `aria-labelledby`/`aria-describedby`,
removing a duplicated element id.

**Phase 2 - sighting sweep (live browser, premium license)**

- Batch A (workspaces/tasks): 4 PASS, rest state-gated.
- Batch B (templates): `MissingTemplateVariablesDialog`, `FileDialog`,
`PublishTemplateVersionDialog`, template delete - all PASS.
- `UpdateBuildParametersDialog`: reached by enabling classic parameter
flow + pushing a version with a required parameter - PASS (renders +
submits).
- Batch C (users/org/settings): 10 PASS.
- Batch D (deployment/AI): 10 PASS.

**Decisions**

- Kept `ConfirmDialog`-wrapper prop types explicit (composing
`DialogProps` there reintroduced a MUI smell).
- Dropped the unused `ConfirmDialogType` export (knip) and updated the
`WorkspacePage` orphan-delete test: the radix `Checkbox` puts the test
id on the `role=checkbox` button itself, so the previous
`within(...).getByRole` no longer matched.

</details>
2026-07-31 03:23:00 +00:00
Michael Suchacz bc9c7855d9 fix: build actionlint from source to avoid the shellcheck deadlock (#27679) 2026-07-31 02:42:49 +02:00
dylanhuff-at-coder e30a7bcd0d fix(site/src/pages/UserSettingsPage/SecretsPage): prevent Add secret dialog overflow (#27649) 2026-07-30 18:14:34 -04:00
Danielle Maywood 46d01fca65 refactor(site/src/pages/AgentsPage/components/ChatElements/tools): replace label/icon switches with tables and registry invariants (#27706)
Stacked on #27697. Do not merge before it; this diff is against that
branch, not main.

Replaces the `ToolLabel` and `ToolIcon` string switches with lookup
tables, and makes the registry/table agreement a CI failure instead of a
manual audit. No behaviour change; every label and icon renders
identically.

## Why

Three enumerations of the same tool-name set (`toolRenderers`, the label
switch, the icon switch) were kept in agreement by convention alone, and
drifted repeatedly (#27684, #27687, #27697 each deleted arms a
registered renderer had silently shadowed). Switches are unenumerable,
so the drift was invisible to both tsc and tests.

## What changed

- `genericToolLabels` (ToolLabel.tsx): the four generic-rendered labels
(`process_signal`, `process_list`, `attach_file`, `advisor`) as a
`Partial<Record<string, FC>>`. `ToolLabel` is now a table lookup plus
the MCP/raw-name fallback.
- `toolIcons` (ToolIcon.tsx): all 19 built-in icon names as a
`Partial<Record<string, LucideIcon>>`, same pattern. Unknown/MCP names
still fall to `WrenchIcon`.
- `Tool.tsx`: exports `toolRenderers` (it is the single source of truth
for dispatch; the tests read it directly).
- `toolLabelVisibility.test.ts`: fails if a registered renderer that
does not delegate to `GenericToolRenderer` shadows a `genericToolLabels`
entry, naming the arm. `process_signal` (known delegator) and `advisor`
(consumed directly by `AdvisorTool`) are allowlisted in the test. This
is the tripwire requested in review on #27697, as a CI failure rather
than a comment.
- `toolIconsCoverage.test.ts`: fails if a registered renderer has no
dedicated icon, with `read_skill_file` allowlisted for its `read_skill`
icon alias.

## Design notes

- The invariant checks live in tests, not in the type system. TypeScript
cannot assert a runtime object's key set against an independent intent
without either re-listing the names (the `satisfies Record<union, ...>`
approach, rejected as ugly repetition) or abusing conditional types. The
tables are plain objects; the tests own the invariant. A generated union
from the Go `chattool` constants is the proper long-term fix and is
deliberately out of scope.
- No `as const` / union key types: they added annotation without buying
safety the tests don't already provide, and nothing consumes `keyof
typeof` here.

## Validation

- `tsc --noEmit`, `biome check --error-on-warnings`, knip: clean.
- Unit (`--project=unit src/pages/AgentsPage`): 1502 passed, 2 skipped
(base: 1500/2; +2 are the new invariant tests).
- Storybook (`--project=storybook src/pages/AgentsPage`): 949 passed, 2
failed, identical to base: `AgentChatPageView.stories.tsx > Scroll To
Bottom Button Works With Inverse Scroll` and `Tool.stories.tsx > MCP
Tool Completed`. Both reproduce on unmodified main, so pre-existing and
unrelated. One additional flake (`AgentChatPage.stories.tsx > Slash
Compact Yields To Personal Skill`) failed once under parallel load and
passed in isolation on the final code.
- Line delta vs #27697: +148 / -98 across 5 files.

Generated by Coder Agents.
2026-07-30 22:58:57 +01:00
Danielle Maywood 9bc681fa6e fix(site/src/pages/AgentsPage/components/ChatElements/tools): delete unreachable switch arms from ToolLabel and ToolIcon (#27697)
Deletes unreachable switch arms from `ToolLabel` (14 arms) and
`ToolIcon` (1 arm). No behaviour change; the deleted arms could never be
reached, so the rendered output is identical.

## Reachability proof

`ToolLabel` has exactly two call sites:

1. `Tool.tsx` `GenericToolRenderer` (line 950), reached when a tool name
has no `toolRenderers` entry or when its registered renderer delegates
to `GenericToolRenderer`.
2. `AdvisorTool.tsx` (line 72), which hardcodes `name="advisor"`.

Dispatch in `Tool.tsx`: subagent names (`spawn_agent`, `wait_agent`,
`message_agent`, `interrupt_agent`, plus legacy `spawn_subagent`,
`close_agent`) route to `SubagentRenderer`; everything else hits
`toolRenderers[name] ?? GenericToolRenderer`. None of the subagent names
appear in either switch.

Every registered renderer was checked for delegation:

| ToolLabel arm | Shadowing renderer | Delegates? |
| --- | --- | --- |
| `execute` | `ExecuteRenderer` -> `ExecuteTool` | No |
| `process_output` | `ProcessOutputRenderer` -> `ProcessOutputTool` | No
|
| `read_file` | `ReadFileRenderer` -> `ReadFileTool` | No |
| `write_file` | `WriteFileRenderer` -> `WriteFileTool` | No |
| `edit_files` | `EditFilesRenderer` -> `EditFilesTool` | No |
| `create_workspace` | `CreateWorkspaceRenderer` ->
`CreateWorkspaceTool` | No |
| `start_workspace` | `StartWorkspaceRenderer` -> `StartWorkspaceTool` |
No |
| `list_templates` | `ListTemplatesRenderer` -> `ListTemplatesTool` | No
|
| `read_template` | `ReadTemplateRenderer` -> `ReadTemplateTool` | No |
| `read_skill` | `ReadSkillRenderer` -> `ReadSkillTool` | No |
| `read_skill_file` | `ReadSkillFileRenderer` -> `ReadSkillTool` | No |
| `chat_summarized` | `ChatSummarizedRenderer` -> `ChatSummarizedTool` |
No |
| `propose_plan` | `ProposePlanRenderer` -> `ProposePlanTool` | No |
| `computer` | `ComputerRenderer` -> `ComputerTool` | No |

Kept arms:

- `process_signal`: `ProcessSignalRenderer` IS a registry key but
delegates to `GenericToolRenderer`, so the arm stays reachable. Kept.
- `advisor`: hardcoded by `AdvisorTool.tsx`. Kept.
- `process_list`, `attach_file`: no registry entry, not subagent names,
so they fall through to `GenericToolRenderer`. Kept.
- `default`: covers MCP tools and any unregistered name. Kept.

`ToolIcon` is rendered by `ToolCall.LeadingIcon` / `ToolCall.Header
iconName`, and every dedicated per-tool component passes its own fixed
name (`execute`, `process_output`, `read_file`, `write_file`,
`edit_files`, `list_templates`, `read_template`, `read_skill`,
`chat_summarized`, `ask_user_question`, `propose_plan`, `computer`,
`start_workspace`, `list_agents`, `create_workspace`, `advisor`), so
those arms are reachable and kept. `thinking` is passed directly from
`StreamingOutput.tsx` and `ConversationTimeline.tsx`, and
`chat_summarized` covers `list_agents` via the shared `BotIcon` arm.
`read_skill_file` is the only arm whose renderer
(`ReadSkillFileRenderer`) renders `ReadSkillTool` with the hardcoded
`iconName="read_skill"`, so nothing ever passes `read_skill_file` to
`ToolIcon`. That arm alone is deleted.

No exports, helpers, or imports became dead (verified with knip, which
passes clean).

## Delta and tests

- Line delta: -119 (ToolLabel -118, ToolIcon -1), 0 insertions.
- Unit (`--project=unit src/pages/AgentsPage`): 1500 passed, 2 skipped
before and after.
- Storybook (`--project=storybook src/pages/AgentsPage`): 949 passed, 2
failed before and after, identical failures both runs:
`AgentChatPageView.stories.tsx > Scroll To Bottom Button Works With
Inverse Scroll` and `Tool.stories.tsx > MCP Tool Completed`. Both
reproduce on unmodified main (MCP Tool Completed also fails in isolation
on main), so they are pre-existing and unrelated.
- `tsc --noEmit`, `biome check --error-on-warnings`, and knip all pass.

Generated by Coder Agents.
2026-07-30 22:58:57 +01:00
Jeremy Ruppel 218829d444 refactor(site): use uuid package instead of generateUUID helper (#27709) 2026-07-30 16:52:29 -04:00
McKayla はな 6cfefc0685 chore: replace isChromatic with isPixel (#26832)
Swaps `chromatic/isChromatic` for `@coder/pixel-storybook`'s `isPixel()`
so the
snapshot-determinism gates (fixed workspace name, frozen Spinner, fixed
CLI
origin, no scroll, font loader) fire under pixel instead of Chromatic.
Drops the
now-unused `chromatic` dependency.

Stacked on #27658 (pixel-storybook 0.3); `isPixel` comes from the new
`@coder/pixel-storybook/storyapi` subpath. Verified the app and
Storybook
builds both bundle `isPixel` cleanly, and `tsc` passes with the
dependency
removed.

This is the last piece of the Chromatic removal; the story params
migrated in
#26844 and the addon came out in #27353.

<details>
<summary>Chromatic removal sequence</summary>

1. Remove the Chromatic CI job + scripts + docs reference. (#26777,
merged)
2. **This PR** — `isChromatic()` → `isPixel()`; drop the `chromatic`
dependency.
3. `data-pixel` + `pixel.exclude`; drop `delay` / `pauseAnimationAtEnd`.
(#26778,
   merged)
4. Migrate story snapshot params (`viewports` / `diffThreshold` / theme
modes →
   `pixel.matrix`); delete `testHelpers/chromatic.ts`. (#26844, merged)
5. Remove the `@chromatic-com/storybook` addon. (done on main in #27353)

</details>

---

> Generated by Coder Agents on behalf of @aslilac.
2026-07-30 11:47:26 -06:00
McKayla はな 95275d9659 chore: upgrade to @coder/pixel-storybook 0.3 (#27658)
includes some fixes to improve performance and reduce the number of
false positives
2026-07-30 11:47:25 -06:00
Josh FreeandCopilot 2acfe7e829 feat(coderd/externalauth/gitprovider): use conditional requests for GitHub JSON reads (#27628)
Fixes #27627.

## What

The chat diff-status gitsync worker polls open pull requests on a fixed
10s interval and re-downloads the full JSON body every tick, even when
nothing changed, because the GitHub client never sends `If-None-Match` /
ETag.

This adds a small, concurrency-safe, bounded in-memory ETag+body cache
(`coderd/externalauth/gitprovider/conditional.go`) and wires it into
`githubProvider.decodeJSON`. When an ETag is cached for a request, we
send `If-None-Match`; on `304 Not Modified` we decode the cached body;
on `200` we cache `{etag, body}` when an ETag is present and the body is
under a size cap.

## Why

`304` responses do not count against GitHub's primary rate limit, but
full `200`s do. Today every unchanged poll burns quota that the same
token also needs for interactive Git and API operations, so busy
instances can hit rate-limit errors and stalls elsewhere. Unchanged PRs
now revalidate for free with no behavior change; only genuine changes
transfer a body.

## Details

- Cache key = request URL + a hash of the token, so one token's response
is never served under another; raw tokens are not retained.
- Bounded by entry count (LRU eviction, default 2048) and per-body size
(1 MiB) to cap memory.
- Scope limited to the JSON reads through `decodeJSON`; the raw-diff
path (`fetchDiff`, up to `MaxDiffSize`) is intentionally left out to
avoid caching large bodies.

## Tests

`TestConditionalRequestReuse` in `github_test.go` covers:
- `NotModifiedReusesCachedBody` — a warm poll sends `If-None-Match` with
the prior ETag and reuses the cached body on `304`, yielding the same
result with exactly two upstream requests.
- `DifferentTokenDoesNotShareCache` — a different token never sends
another token's cached ETag.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 4959e1f9-f8e6-4e97-a487-f395a0123c79
2026-07-30 17:36:39 +01:00
Paweł Banaszewski 6df24634fd fix: remove nodePort from required service fields of ai-gateway chart (#27696)
Updates schema for ai-gateway chart. Missing piece from
https://github.com/coder/coder/pull/27682
2026-07-30 17:53:28 +02:00
Danielle Maywood 11e03cfb3a fix(site/src/pages/AgentsPage/components/ChatElements/tools): delete dead execute auth_required flow (#27687)
Stacked on #27684. Addresses review note CRF-2 from that PR: the kept
`auth_required` execute path is dead by the same premise that PR proved
for `wait_for_external_auth`.

The chatd execute tool's `ExecuteResult` struct
(`coderd/x/chatd/chattool/execute.go:79-88`) has no `auth_required`,
`authenticate_url`, or `provider_*` fields, so the execute tool cannot
emit the payload this path parsed. The `authenticate_url` matches
elsewhere in Go are the unrelated workspace-creation external-auth flow
(`codersdk.TemplateVersionExternalAuth`). Per `bb3a363ed4`, the
`auth_required` execute payload was written and removed on an unmerged
branch before #22290 squash merged, so no server version ever emitted
it.

Removes:
- `ExecuteAuthRequiredTool` and its `ExecuteRenderer` branch
- the `authenticateURL`/`providerLabel` chain in `getExecuteRenderData`,
and the `Boolean(data.authenticateURL)` disjunct in
`shouldRenderExecuteTool`
- the `ExecuteAuthRequired` Storybook story
- the now-dead `toProviderLabel` helper and its test block
- the `auth_required` visibility test case

The `providerLabel` identifiers elsewhere under `site/src`
(ModelSelector, ModelRow, AISettings) belong to the unrelated AI
model/provider selector and are untouched.

🤖 This pull request was created with Coder Agents.
2026-07-30 16:20:11 +01:00
Danielle Maywood 4003f0086f fix(site/src/pages/AgentsPage/components/ChatElements/tools): delete unreachable WaitForExternalAuth tool code (#27684)
The backend never emits a `wait_for_external_auth` tool call (no
references in any Go source, the chatd tool registry, or anywhere
outside the frontend), so the entire frontend rendering path for it was
unreachable.

Removes the `WaitForExternalAuthTool` component, its renderer and
`toolRenderers` entry, the `ToolIcon` case, and the four Storybook
stories, along with the imports that only they used (`CheckIcon`,
`LoaderIcon`, `LogInIcon`, and `toProviderLabel` in `Tool.tsx`).

Kept the separate, live `execute` auth-required flow:
`ExecuteAuthRequiredTool` and the `toProviderLabel` usage in
`toolVisibility.ts` belong to the `authenticateURL` path, not this dead
tool.

Refs #27593

🤖 This pull request was created with Coder Agents.
2026-07-30 16:20:10 +01:00
Susana Ferreira 3f1973f45c docs: document AI Gateway cost controls (#27643)
### Description

Adds documentation for AI Governance Cost Control, including how
administrators configure budgets, how effective groups are resolved, how
enforcement works, and where spend reporting is available.

### Changes

- Replace the placeholder cost control page with a full admin guide
- Document deployment settings, group budgets, user overrides, and
effective group resolution
- Explain estimated spend, unpriced models, notifications, enforcement,
and spend reporting
- Add migration guidance for Coder Agents Cost Control
- Add screenshots for group budgets and user overrides

Closes
[AIGOV-476](https://linear.app/codercom/issue/AIGOV-476/add-documentation-for-ai-bridge-cost-controls).

> [!NOTE]
> Initially generated by Coder Agents, modified and reviewed by
@ssncferreira
2026-07-30 15:04:39 +00:00
Susana Ferreira 7b104b6a98 fix: add info log level to unpriced models message (#27693)
Change the unpriced models log to info level.

Refs https://github.com/coder/coder/pull/27678
2026-07-30 14:47:23 +00:00
Jeremy Ruppel a86e67d3d9 fix(site/src/modules/templates/TemplateExampleCard): point Use template to builder (#27663)
## Summary

Updates the "Use template" button on `TemplateExampleCard` to link to
the template builder instead of the legacy create flow.

- `/templates/new?exampleId=${example.id}` →
`/templates/new/builder?base=${example.id}`

This affects everywhere the card is rendered: the Templates page empty
state and the Starter Templates gallery page.

## Notes

The "View all starter templates" button in the empty state keeps its
existing `templateBuilderEnabled` conditional (unchanged).

---

_This PR was generated by Coder Agents on behalf of @jeremyruppel._
2026-07-30 10:46:40 -04:00
Jeremy Ruppel cf7f876880 feat(site): add generateUUID helper (#27661)
Adds a `generateUUID()` helper to `site/src/utils/uuid.ts`.

It uses `crypto.randomUUID()` when available, and otherwise falls back
to `crypto.getRandomValues()`, setting the version (4) and variant (RFC
4122) bits before formatting the 16 random bytes into the standard
`8-4-4-4-12` UUID string.

Seriously open to any implementation here, let me know if you have a
favorite!

---
_This PR was created by Coder Agents on behalf of @jeremyruppel._
2026-07-30 10:46:40 -04:00
Michael Suchacz b3852c707b fix(site/src/pages/AISettingsPage/SpendPage): announce cost controls move in v2.36 (#27688)
Corrects the version in the AI settings Spend banner: cost controls
features move to AI Governance in **v2.36**, not v2.37.

Updates the banner copy in `SpendPageView` and the matching Storybook
play assertion. No other changes.

The `release/2.36` backport is opened manually as #27690, so this PR
does not carry the `cherry-pick` label.

> Mux, an AI agent, prepared this PR on Mike's behalf.
2026-07-30 16:01:27 +02:00
Susana Ferreira b4eda32a2e fix: hide AI budget override controls without permission (#27654)
### Description

Setting a user's AI budget override updates both the user and the group
its spend is charged to, so it requires `user:update` and
`group:update`. Organization admins have group update but only site-wide
user read, so they could tick "Override group budget", enter an amount,
and then fail on save.

The dialog now shows the member's budget as read-only when the viewer
can't change it.

### Changes

- Gate the override controls on `user:update` (site-wide) in addition to
the group permission the page already checks
- Replace the form with a read-only view: the group's budget, followed
by "To update this limit, contact a Coder administrator."
- Swap the whole view rather than disabling the checkbox, since an
existing override seeds the form enabled and unchecking it would call
the delete endpoint and fail the same way
- Add stories for the read-only dialog and for the page-level wiring

> [!NOTE]
> Initially generated by Claude Opus 5, modified and reviewed by
@ssncferreira
2026-07-30 14:28:41 +01:00
Paweł Banaszewski e819dd4af6 fix(helm/ai-gateway): render service nodePort with an explicit if guard (#27682)
> Coder Agents generated this commit

Replace the with block around the Service nodePort field with an if
guard that references .Values.service.nodePort directly. The with form
rebinds the dot inside the block, so a later addition that needs .Values
or .Release there would break.

Extend the default_values fixture to enable ingress and httproute with
only the values each one requires, so the golden file covers every
template with the minimum viable configuration.

Add a mustNotContain list to the render test cases. Golden files are
rewritten wholesale by TestUpdateGoldenFiles, so these assertions pin
optional fields and resources that each fixture leaves unset, including
the Service nodePort.
2026-07-30 14:47:07 +02:00
Spike Curtis dc31791c88 test: don't use ptytest for client side of SSH session tests (#27681)
In our initial batches of test refactors, I left the SSH session tests using `ptytest` because I (erroneously) thought that we still needed a client side PTY when the SSH server creates a PTY. This is incorrect and plain in-process IO is fine on the client side.  
  
closes https://github.com/coder/internal/issues/1400   
(again)<!--

If you have used AI to produce some or all of this PR, please ensure you have read our [AI Contribution guidelines](https://coder.com/docs/about/contributing/AI_CONTRIBUTING) before submitting.

-->
2026-07-30 14:30:15 +02:00
3f3fd1c4d7 feat: show network request summary on AI session detail card (#27418)
Frontend for the AI session network summary. Adds Network calls, Blocked
network requests, and Top domains rows to the Session summary card on
the individual AI session detail page, driven by the network fields on
the session threads response.

Renders "Disabled" when network monitoring was not active and "No
activity" when there were no calls. Covered by Storybook stories for
each state.

### PR map (merge strictly bottom-up)

This change is a 4-PR stack. Each PR depends on all the ones below it,
so merge in this exact order:

1. #27417 — backend network summary
2. #27418 — frontend summary rows
3. #27425 — backend per-call list `network_call_logs`
4. #27426 — frontend network-calls panel

Refs AIGOV-463

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Cian Johnston <cian@coder.com>
2026-07-30 13:23:51 +02:00
841a1765f7 feat: add network calls summary to AI session threads API (#27417)
Backend for the AI session network summary. Exposes total/blocked
network calls and top destination domains on the session threads
endpoint (`GET /api/v2/ai-gateway/sessions/{id}`).

Total and blocked reuse the existing Agent Firewall aggregation from the
sessions list query, so the numbers match the sessions table. Top
domains are a new server-side aggregation
(`GetAIBridgeSessionTopDomains`) over boundary logs, using the same
interception-window correlation. There is no network-error state,
matching the current data model.

Frontend consuming these fields is in a separate stacked PR.

### PR map (merge strictly bottom-up)

This change is a 4-PR stack. Each PR depends on all the ones below it,
so merge in this exact order:

1. #27417 — backend network summary (base `main`)
2. #27418 — frontend summary rows (base #27417)
3. #27425 — backend per-call list `network_call_logs` (base #27418)
4. #27426 — frontend network-calls panel (base #27425)

Refs AIGOV-463

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Cian Johnston <cian@coder.com>
2026-07-30 13:09:46 +02:00
Susana Ferreira 3660ffecdd fix: add warn log level to unpriced models message (#27678)
When a model is missing from the price table, token usage is still
recorded but with a NULL cost, so AI spend for that model goes
unattributed. This was logged at debug level, which means it is
invisible in a default deployment.
Log it at warn level instead so admins can see which provider/model
pairs need a price row and act on it.
2026-07-30 12:03:22 +01:00
Michael Suchacz 95a2c2ba02 feat: back the per-chat cost endpoint with AI Gateway data (#27328)
## Stack Context

This stack removes native chat cost tracking and native chat usage
limits, making the AI Gateway the single source of AI spend data and
budget enforcement.

1. **This PR:** re-back the per-chat cost endpoint with AI Gateway data.
2. Remove native chat usage limits end to end, rewiring the sidebar
indicator to gateway spend.
3. Remove native chat cost tracking end to end, deleting the
Analytics/Spend cost UI.

## What?

`GET /api/experimental/chats/{chat}/cost` summed
`chat_messages.total_cost_micros`, which native chat cost tracking
maintained. It now aggregates AI Gateway interception data instead, and
has no native fallback.

- New `GetAIBridgeChatCost` query, authorized through the root chat so
members can read their own chat's cost without gaining access to raw
interception rows.
- Response fields renamed: `priced_message_count` -> `request_count`,
`unpriced_messages_having_usage_count` -> `unpriced_request_count`.
- The chat summary sidebar keys its cost cache by root chat, and hides
the cost row where the AI Gateway is off or unlicensed. The root cost is
invalidated when a chat leaves an active status and when a generated
title lands, since title generation bills its own gateway request.

`GetChatModelUsageCostByChatID` and the rest of native cost tracking are
untouched here; PR 3 removes them.

## Why?

Native cost tracking duplicates what the AI Gateway already records, and
the two disagree. Repointing the endpoint first means the cost UI keeps
working while the native implementation is deleted later in the stack.

Two behaviour changes follow from gateway semantics and are intentional:

- **Requests, not messages.** The gateway records interceptions, so
counts are requests. Title-generation traffic now counts.
- **Whole-tree totals.** The gateway records the *spawning* chat's ID as
the interception session ID, so a subagent's requests are attributed to
its immediate parent, not always the root. Only a whole chat tree can be
summed, so the query resolves the root and aggregates the tree, and
every chat in a tree reports the same total. Native returned per-subtree
totals.

## Attribution and counting semantics

The aggregate groups token usage per interception before counting, so
the reported numbers are per request even though a request records one
usage row per provider response:

- `RequestCount` counts finished `Coder Agents` interceptions in the
tree, including unpriced ones.
- `UnpricedRequestCount` counts requests with at least one usage row the
gateway could not price. It is a subset of `RequestCount`.
- `TotalCostMicros` omits only unpriced usage, so a partially priced
request still contributes its priced portion. The sidebar therefore says
`Excludes unpriced usage from N request(s)` rather than claiming whole
requests were dropped.

A recorded cost of zero is a free request, not an unpriced one. Usage
without an effective group is excluded, matching what never reached
`ai_user_daily_spend`.

## Authorization

Reads go through `ExtractChatParam` plus `ResourceChat`, with no
cost-specific RBAC widening. `TestGetChatCost/MemberCanReadOwnChat`
covers a scoped `agents-access` member reading their own chat's cost,
and `MemberCannotReadOtherUsersChat` still asserts 404 for a non-owner.
Plain members without `agents-access` cannot create or read chats at
all, so they never reach this endpoint.

## Known limitation

AI Gateway data has its own retention period, 60 days by default and
configured independently of chat retention, so spend for requests older
than that is no longer reported. A chat whose gateway records have all
been purged reports zero cost, which is indistinguishable from genuinely
free usage under this contract. The endpoint documents the caveat;
#27330 documents it on the Spend Management page.

In-flight interceptions are excluded, since cost is only known once the
response is recorded. A chat's cost therefore lags the active turn by
one request.

## Rebase note

Rebased onto `main` after #27579 removed the `ai-gateway-cost-control`
experiment. The per-chat cost row is now gated on the `aibridge` feature
alone, matching how #27579 degated the other cost-control surfaces.

> Mux prepared this PR on Mike's behalf.
2026-07-30 13:01:48 +02:00
Jaayden Halko 54d5eb7ec2 feat: add hourly hb_agent_runtime_v1 usage events for Coder Agent runtime (#27312)
closes CODAGT-839
closes CODAGT-843
closes CODAGT-773

## Summary

Adds a new heartbeat usage event type, `hb_agent_runtime_v1`, measuring
the total agent-loop runtime of Coder Agents (chats) per UTC hour, plus
a reconciler that generates one event per hour with self-healing
backfill over a trailing 7-day window. Events flow to Tallyman through
the existing publisher unchanged. This measures the new Coder Agents
(the `chats` tables), not the deprecated Tasks counted by
`dc_managed_agents_v1`.

Independent of #27508, which fixes the dead ai-seats cron registration.
Both PRs carry the identical `usage_event` create permission hunk for
the usage-publisher subject (this feature's generator and the ai-seats
cron each need it for heartbeat inserts), so they can land in either
order and the overlap merges cleanly.

> [!WARNING]
> **Do not include this in a release until Tallyman accepts
`hb_agent_runtime_v1`.** The publisher marks permanently rejected events
as done-forever, and the generator then sees those buckets as complete
locally, so their usage would be silently and permanently lost.

## Details

Each event's payload is `{"runtime_ms": N}`: the sum of
`chat_messages.runtime_ms` for messages created in the hour bucket `[H,
H+1)`, across all chats (sub-agents, API-created, archived, and
soft-deleted messages included). Events use deterministic IDs
(`hb_agent_runtime_v1:<bucket start>`) with `created_at` set to the
bucket start, so concurrent replicas race safely via `ON CONFLICT (id)
DO NOTHING` without locking, and daily rollups attribute backfilled
hours to the correct day. Idle hours produce zero-valued events. A
bucket becomes eligible 5 minutes after it closes; hours missing for
longer than the 7-day window are forfeited, which can only undercount.

Note that this makes `usage_events.created_at` explicitly the *event
occurrence time* rather than the row insertion time; the two only
diverge for backfilled events. It already behaved as the occurrence
timestamp (it drives the daily rollup day and is shipped to
Tallyman/Metronome as the event timestamp), and the migration now
documents this with a `COMMENT ON COLUMN`, which also surfaces as a Go
doc comment on `UsageEvent.CreatedAt`.

The new `usage.Generator` runs unconditionally in enterprise builds; the
`publish_usage_data` license flag continues to gate egress only, so
air-gapped deployments still fill their local ledger. The
`aggregate_usage_event()` trigger sums `runtime_ms` per day into
`usage_events_daily` (unlike `hb_ai_seats_v1`, which takes the daily
max).

`InsertHeartbeatUsageEvent` now takes an explicit `createdAt` so
generators can backfill historical buckets; the cron passes
`clock.Now()` to preserve its existing behavior.

## Tallyman follow-up

<details>
<summary>Prompt for the Tallyman-repo agent</summary>

> **Task**: Add support for the new Coder usage event type
`hb_agent_runtime_v1` so Tallyman accepts, validates, and forwards it to
Metronome.
>
> **Background**: coder/coder PR (this PR) adds hourly heartbeat events
measuring Coder Agent runtime. Events arrive via the existing
`/api/v1/events/ingest` endpoint with: `event_type:
"hb_agent_runtime_v1"`, `event_data: {"runtime_ms": <int64 >= 0>}`,
deterministic `id` of the form `hb_agent_runtime_v1:2026-07-15_14:00:00`
(UTC hour bucket start), and `created_at` set to the bucket start (may
be up to ~8 days in the past due to backfill; within Metronome's 34-day
dedup window). Zero-value events are normal (idle hours).
>
> **Work**:
> 1. Update Tallyman's vendored/imported `coderd/usage/usagetypes` (or
equivalent) to the coder/coder commit that adds
`UsageEventTypeHBAgentRuntimeV1` and `HBAgentRuntime`.
> 2. Ensure ingestion validation accepts the type (`Valid()` switches)
and rejects negative `runtime_ms`.
> 3. Ensure Metronome forwarding maps the event with transaction ID
derived from the event `id` as for existing types, passing `runtime_ms`
through as the property for a SUM-aggregated billable metric ("Coder
Agent Hours" = `SUM(runtime_ms) / 3,600,000`).
> 4. Do NOT permanently reject unknown-but-well-formed future `hb_*`
types if avoidable; at minimum confirm current behavior for unknown
types (temporary vs permanent rejection) and report it.
> 5. Tests: ingest accept/validate, dedup by ID, Metronome payload
mapping.
>
> **Constraint**: this must be deployed to tallyman-prod **before** any
coder/coder release containing the event generator; coderd treats
permanent rejections as terminal per event.

</details>
2026-07-30 08:37:45 +01:00
McKayla はな 2b28515d9b refactor: migrate story snapshot params to pixel (#26844) 2026-07-29 18:13:55 -06:00
Bobby Ho d210b311dc ci(.github): retry build-tool downloads in Windows signing jobs (#27664)
## Problem

The Windows code-signing path downloads two build tools with bare `wget`
and no retry, in both `ci.yaml` (`build` job) and `release.yaml`
(`release` job):

- `rcodesign` from GitHub releases
- `jsign-6.0.jar` from GitHub releases

A single transient network failure on either fetch fails the whole job.
In `ci.yaml` that turns `main` red via the `required` aggregator; in
`release.yaml` it fails a release.

This has happened. `Install rcodesign` failed on **2026-02-25** (in the
since-deleted `build-dylib` job), **2026-03-04**, and **2026-04-30**.

## Root cause

Two parts, one structural and one local.

**Structural:** GitHub Actions has no per-step retry. This repo already
knows toolchain provisioning is network-flaky and has
`.github/scripts/retry.sh` (3 attempts, 2s/4s/8s backoff), applied in
roughly 20 places. But `retry.sh` is a shell wrapper, so it can only
wrap `run:` steps. These four downloads are `run:` steps that were
simply never wrapped.

**Local:** the failing step's body, under `set -euo pipefail`, is
exactly three commands:

```sh
wget -O /tmp/rcodesign.tar.gz https://github.com/indygreg/apple-platform-rs/releases/download/apple-codesign%2F0.22.0/...
sudo tar -xzf /tmp/rcodesign.tar.gz -C /usr/bin --strip-components=1 ...
rm /tmp/rcodesign.tar.gz
```

`tar` and `rm` operate on a file that was just written, so they are
deterministic. The only nondeterministic command in the step is the
network fetch, and a truncated download surfaces as a `tar` failure
whose cause is still the network.

### How we know

Enumerated failed runs through the GitHub Actions API and extracted, per
run, every failed job together with the names of its failed steps.

| Scan | Scope | Runs |
|---|---|---|
| `ci.yaml`, `main` | 2025-08-01 to 2026-07-29 | 934 |
| `ci.yaml`, all branches | most recent failures | 150 |
| `release.yaml` | all recorded failures | 22 |

The 934 is effectively the complete set; the API reports 923 failed
`main` runs over that period and the scans overlap slightly.

`Install rcodesign` appears **3 times on 3 separate dates**. Being
spread across dates rather than clustered, these behave as
**independent** events. That distinction is what selects the remedy, and
it is why this change is retry rather than removal.

For contrast, the `Setup Java` failures in the same jobs are **4
failures inside a single 90-minute window** on 2026-05-28, all from an
`api.azul.com` edge failure. That is a correlated outage, where every
attempt shares the same degraded dependency and retry provably cannot
help. **That defect is not addressed here** and needs a different fix;
see "Not addressed" below.

### Limits of the evidence

Stating these plainly so a reviewer can weigh them:

- **Cause is not directly confirmed.** Logs for all three `rcodesign`
failures are past GitHub's 90-day retention. The inference from the step
body above is strong but circumstantial.
- **Step-level attribution only reaches back about five months.** GitHub
prunes per-step detail from the jobs API while keeping job-level
conclusions. Probed directly: runs from 2026-03-01 onward return
populated `steps` arrays; runs from 2026-02-05 and earlier return empty
ones. So the true count over the full period could be higher; it cannot
be lower.
- **Impact is small.** This whole class of failure is 10 of 800
attributed non-`required` job failures, about **1.25%** of measured
`main` CI failure volume. This is not a significant reliability
improvement and should not be reviewed as one. The Postgres-backed Go
tests alone are over 40%.

## Solution

Wrap all four downloads in the existing retry helper:

```yaml
- ./.github/scripts/retry.sh -- wget -O /tmp/rcodesign.tar.gz https://...
```

Four lines changed, one per site: `ci.yaml:1287`, `ci.yaml:1321`,
`release.yaml:199`, `release.yaml:225`.

**How it works.** `retry.sh` runs the command, and on non-zero exit
sleeps 2s, 4s, then 8s before re-attempting, up to 3 attempts, then
fails with the original command in the error message. On success the
first time, behavior is unchanged.

**Why it works for these failures.** They are independent events, so
each attempt is a fresh trial with an independent chance of success. A
GitHub releases CDN blip on one run says nothing about the next 2
seconds. This is exactly the regime retry is for.

**Why retry rather than deletion.** These artifacts genuinely are not
present on the runner, so the network call is unavoidable. It can only
be made survivable. (Where a dependency *is* avoidable, deletion is the
better answer, which is the shape the `setup-java` fix will take.)

**Why `wget -O` is safe to retry.** `-O` truncates its output file on
each attempt, so a partial download from a failed attempt is overwritten
rather than appended to. No corruption path.

## Risks

Low, and worth naming precisely.

| Risk | Assessment |
|---|---|
| Behavior change on the success path | None. `retry.sh` execs the
command directly; a first-attempt success is identical to today. |
| A persistently broken URL now takes longer to fail | Yes, by up to 14s
of backoff, then it fails exactly as it does today. Negligible against a
job that takes tens of minutes. |
| `retry.sh` mangling `wget`'s own flags | `retry.sh` parses its own
options with `getopt`, so this was the main correctness concern.
Verified explicitly, both argument orders used in these workflows. See
Verification. |
| Relative path `./.github/scripts/retry.sh` resolving wrongly | These
steps set no `working-directory`, so cwd is the repo root. Deliberately
**excluded** the third `wget` at `release.yaml:713`
(`publish-homebrew`), which runs after `cd "$temp_dir"` where a
repo-relative path would break. |
| Retry masking a real regression | Bounded to 3 attempts over 14s. This
is not job-level auto-retry, which would hide regressions and is
explicitly not proposed. |

### Verification gap a reviewer should know about

**The changed steps do not run on PR CI.** `ci.yaml`'s `build` job is
gated on `github.ref == 'refs/heads/main' || startsWith(github.ref,
'refs/heads/release/')`, and `release.yaml` runs only on release. So
these four steps will execute for the first time on merge to `main`.
Verification below is therefore local plus static analysis, not a live
run of the modified steps.

## Verification

`retry.sh` argument passing, using a stub that prints what it received,
for both argument orders present in these workflows:

```
--- form A: -O before URL (rcodesign style) ---
argc=3
  arg1=[-O]
  arg2=[/tmp/rcodesign.tar.gz]
  arg3=[https://github.com/indygreg/apple-platform-rs/releases/download/apple-codesign%2F0.22.0/apple-codesign-0.22.0-x86_64-unknown-linux-musl.tar.gz]
--- form B: URL before -O (jsign style) ---
argc=3
  arg1=[https://github.com/ebourg/jsign/releases/download/6.0/jsign-6.0.jar]
  arg2=[-O]
  arg3=[/tmp/jsign-6.0.jar]
```

Order preserved and the `%2F` encoding in the rcodesign URL intact,
which was the specific failure mode to rule out.

`make lint/actions` (actionlint plus zizmor security audit):

```
✓ lint/actions/actionlint
No findings to report. Good job! (29 ignored, 102 suppressed)
```

`make pre-commit-light`:

```
✓ fmt/shfmt        ✓ lint/markdown    ✓ lint/actions/actionlint
✓ fmt/terraform    ✓ lint/shellcheck  ✓ lint/helm
✓ fmt/markdown     ✓ lint/bootstrap   ✓ lint/emdash
                   ✓ lint/migrations  ✓ lint/typos
                                      ✓ lint/mise-versions
✓ pre-commit-light passed (14s)
```

## Not addressed

Deliberately out of scope, listed so the remaining exposure is visible:

- **`actions/setup-java` with `distribution: "zulu"`** in both files.
This resolves a JDK from `api.azul.com` and downloads it from
`cdn.azul.com` on **every** run, confirmed from a successful `main`
build's log, because a `Java_Zulu_jdk` tool-cache lookup can never hit
the runner's cache. This is the correlated-outage defect from 2026-05-28
and retry cannot fix it.

The probe on this branch ([run
30492093096](https://github.com/coder/coder/actions/runs/30492093096))
has now answered what the fix should be. `depot-ubuntu-22.04-8` ships:

  ```
  RESULT: java found at /usr/bin/java
  OpenJDK Runtime Environment Temurin-11.0.31+11 (build 11.0.31+11)

  JAVA_HOME=/usr/lib/jvm/temurin-11-jdk-amd64
  JAVA_HOME_8_X64 / _11_X64 / _17_X64 / _21_X64 / _25_X64  (all present)
  tool cache: Java_Temurin-Hotspot_jdk
  ```

So the job downloads **Zulu 11.0.32+9 over two third-party hosts while
Temurin 11.0.31+11 is already on the runner's `PATH`**. The follow-up PR
will point `JAVA_HOME` at `$JAVA_HOME_11_X64` and drop the action, which
removes both Azul hosts while keeping the Java 11 pin rather than
inheriting whatever the image default becomes.
- **`storybook`'s `pnpm/action-setup`**, the last direct use in the repo
and the same unguarded `registry.npmjs.org` dependency originally
reported on the issue. Note `cache: true` does **not** mitigate it: per
the action's own `action.yml`, `cache` caches "the pnpm store
directory", not the pnpm binary.

## Scope

This PR is now a **single commit** (`673162b84e`) containing only the
four-line retry change.

A throwaway probe workflow briefly lived on this branch to answer the
JDK question above. It has served its purpose and the commit was
dropped, so nothing diagnostic remains here to review. Its result is
quoted in "Not addressed" and will be carried into the follow-up PR.

Refs coder/internal#929
2026-07-29 17:05:22 -07:00
Bobby HoandClaude Opus 5 4e512f786f fix: prefetch outdated Coder CLI in e2e setup instead of in the test (#27629)
## Summary

`e2e/tests/outdatedCLI.spec.ts` has a 30 second budget in which it must
create a template and workspace, start an agent, download an 84 MiB
release binary from GitHub, and then exercise the actual thing under
test: whether a `v2.8.0` client can still SSH into a workspace served by
HEAD. In the run that filed this ticket, `install.sh` spent **20.04
seconds** of that budget on an HTTP request the test does not need,
leaving 5.4 seconds for the download. The SSH flow never executed.

Worth being precise about the shape, because it changes the fix. The
stall is not in the code under test and it is not an SSH problem.
`install.sh` resolves the latest stable release version
**unconditionally**, even when `--version 2.8.0` is passed explicitly,
and on the pinned path that value feeds nothing but a cosmetic
post-install advisory string. Two thirds of the test's budget went to
producing one sentence of console output that the test discards.

Refs: https://github.com/coder/internal/issues/1571

## Problem

### What the test is for

This is a backward-compatibility test, and `v2.8.0` is the compatibility
floor it enforces rather than a "supported version" in the
release-channel sense. The pin traces to one code comment, `we no longer
support versions prior to Tailnet v2 API support`, citing 059e533544;
that commit first shipped in v2.8.0, so the pin sits exactly on the
boundary it names. Worth stating plainly: this is the oldest client
expected to still interoperate, not a version that receives patches.
Release support is mainline / stable / n-2 / ESR, all far newer.

The test's value is that it runs the *real* historical binary, compiled
in Feb 2024, against a current server: `codersdk` REST compatibility,
tailnet coordination v2, DERP negotiation, `coder ssh --stdio` as an SSH
transport, and the agent accepting a session. Nobody gets to assert what
that old client sends over the wire, which is exactly why the binary has
to be downloaded rather than faked.

The structural defect is that the download shares a timeout with the
assertion:

```text
┌─────────────────────────────────────────────────────────────────┐
│  ONE 30-second Playwright test budget                           │
├──────────────────────────────┬──────────────────────────────────┤
│  What we want to measure     │  Incidental setup                │
│  (deterministic, local)      │  (network, non-deterministic)    │
│                              │                                  │
│  • template + workspace      │  • HTTP HEAD to github.com       │
│  • agent connect             │  • 84 MiB download from          │
│  • coder ssh --stdio         │    GitHub release CDN            │
│  • SSH handshake + exec      │  • tar extraction                │
│  • workspace stop            │                                  │
└──────────────────────────────┴──────────────────────────────────┘
      ~7-14 s, stable                   0 s (cached) .. ∞ (unbounded)
```

A test that asserts protocol compatibility should not be able to fail
because `github.com` was slow.

### The evidence

CI runs Playwright with `DEBUG: pw:api`, and `downloadCoderVersion`
passes `TRACE=1` to `install.sh`, which makes it `set -x`. The job log
therefore stamps every phase. Reconstructed from [job
80049661296](https://github.com/coder/coder/actions/runs/27124540074/job/80049661296),
`t=` relative to test start:

```text
t=+0.000  08:17:44.671  browserContext.newPage                      <- test starts
t=+0.882  08:17:45.553  login complete
t=+4.228  08:17:48.899  workspace create submitted
t=+4.519  08:17:49.190  agent-status-ready visible                  <- startAgent returns
t=+4.526  08:17:49.197  install.sh: parse_arg --version 2.8.0 ...   <- downloadCoderVersion
t=+4.531  08:17:49.202  curl -sSLI https://github.com/coder/coder/releases/latest
                        :
                        :   20.042 SECONDS OF NOTHING
                        :   (agent logs keepalives; the page sits idle)
                        :
t=+24.573 08:18:09.244  response= 200 .../releases/tag/v2.33.6      <- probe returns
t=+24.575 08:18:09.246  STABLE_VERSION=2.33.6                       <- feeds a log line
t=+24.582 08:18:09.253  curl -#fL -o .../coder_2.8.0_linux_amd64.tar.gz.incomplete
                        :   5.4 s of an 84 MiB download
t=+30.000 08:18:14.671  Playwright kills the test
```

Three observations rule out the originally suspected cause (slow SSH
readiness or general runner slowness):

- **The SSH flow never started.** `sshIntoWorkspace` is called after
`downloadCoderVersion` returns, and it never returned. There is no
`coder ssh --stdio` process in the log.
- **The agent was healthy.** `agent-status-ready` resolved in 88 ms, and
through the entire 20 second stall the agent logs a live DERP
connection, successful STUN, and a completed wireguard handshake.
- **The runner was fast, not slow.** Login plus template plus workspace
plus agent took 4.5 seconds.

### Where the 20 seconds goes

```text
install.sh main()
  ...
  L431   STABLE_VERSION=$(echo_latest_stable_version)   <- ALWAYS runs
                |
                +-- echo_latest_stable_version()  (install.sh:94)
                      curl -sSLI https://github.com/coder/coder/releases/latest
                      #  no --connect-timeout
                      #  no --max-time
                      #  non-200 => exit 1  (hard failure)

  L454-461  the only consumers when --version is pinned:
              if VERSION == STABLE_VERSION: STABLE=1

  L148      advisory="To install our stable release (v${STABLE_VERSION}), ..."
  L159      "Coder ${channel}release v${VERSION} installed. ${advisory}"
```

That is the whole dependency chain. `-sSLI` also follows redirects and
`/releases/latest` *is* a redirect, so this is at minimum two
round-trips to `github.com` with no timeout ceiling on either.

### Why 30 seconds and not 60

`test.setTimeout(60_000)` used to be on this test. #16236 removed it,
and that removal was deliberate: it was itself a flake fix
(coder/internal#204, #279) whose thesis was that `go run` compiling
inside a resource-constrained test run was the problem. Having pre-built
the binary, it consistently stripped the allowances that existed to
absorb compile time:

| File | Change in #16236 | Was that allowance really compile time? |
|---|---|---|
| `app.spec.ts` | `setTimeout(75_000)` removed, click timeout `60_000`
-> `10_000` | Yes |
| `webTerminal.spec.ts` | `setTimeout(75_000)` removed | Yes |
| `helpers.ts` | agent-ready wait `45_000` -> `15_000` | Yes |
| `outdatedCLI.spec.ts` | `setTimeout(60_000)` removed | **No: also an
84 MiB download** |
| `outdatedAgent.spec.ts` | timeout untouched, 60 s survives | n/a |

The reasoning was sound and the sweep internally consistent. It had one
blind spot: for `app.spec.ts` and `webTerminal.spec.ts` that budget
genuinely was the compiler's, but here it covered compile time **plus**
a release download, and only the compile half went away. With 60
seconds, the failing run above would have finished in roughly 31 to 43
seconds and passed.

### Budget arithmetic

At `t=+24.58` the test still had to do:

| Remaining work | Realistic cost |
|---|---:|
| Download 84 MiB tarball | 2 - 8 s |
| `tar` extract | 0.3 - 1 s |
| `coder ssh --stdio` cold start | 0.5 - 2 s |
| Tailnet dial + SSH handshake | 1 - 3 s |
| `stopWorkspace` | 2 - 4 s |
| **Needed** | **~6 - 18 s** |
| **Available** | **5.42 s** |

## Fix

Move the download into the existing `testsSetup` Playwright project,
where it gets a 300 second budget and where a failure is attributed to
the download rather than to SSH.

```mermaid
flowchart TB
    subgraph BEFORE["BEFORE: one budget, two concerns"]
        direction TB
        T1["tests project, timeout 30s"]
        T1A["outdatedCLI.spec.ts<br/>login / template / workspace / agent<br/><b>downloadCoderVersion &lt;- NETWORK</b><br/>sshIntoWorkspace / exec / stopWorkspace"]
        T1 --> T1A
    end

    subgraph AFTER["AFTER: network work has its own clock"]
        direction TB
        S2["testsSetup project, timeout 300s"]
        S2A["downloadCoderVersions.spec.ts<br/>stable-version probe + 84 MiB + retries<br/>all live HERE"]
        T2["tests project, timeout 60s"]
        T2A["outdatedCLI.spec.ts<br/>downloadCoderVersion = cache hit, ~300ms<br/>SSH path gets the whole budget"]
        S2 --> S2A
        S2A -- "dependencies" --> T2
        T2 --> T2A
    end

    BEFORE ~~~ AFTER

    style T1A fill:#ffe5e5,stroke:#cc0000,stroke-width:2px
    style S2A fill:#e5ffe5,stroke:#007700,stroke-width:2px
    style T2A fill:#e5ffe5,stroke:#007700,stroke-width:2px
```

### Why it works

`downloadCoderVersion` was already idempotent and cache-checking: it
spawns `<binaryPath> version` first and returns early on exit 0. So the
test keeps its existing call and that call simply becomes a no-op
costing a few hundred milliseconds. **No test logic changes.**

```mermaid
sequenceDiagram
    autonumber
    participant S as testsSetup:<br/>downloadCoderVersions
    participant IS as install.sh
    participant GH as github.com
    participant T as tests:<br/>outdatedCLI
    participant CD as coderd + agent

    Note over S: budget 300s
    S->>IS: downloadCoderVersion(v2.8.0)
    IS->>GH: stable-version probe (unbounded)
    IS->>GH: fetch 84 MiB asset
    GH-->>IS: /tmp/coder-e2e-cache/bin/coder-e2e-2.8.0
    IS-->>S: binaryPath

    Note over T: budget 60s, local only
    T->>T: downloadCoderVersion(v2.8.0)
    Note right of T: spawn "<bin> version" -> exit 0<br/>returns early, ~300ms, no network
    T->>CD: coder ssh --stdio, handshake, exec "exit 0"
    CD-->>T: exit code 0
```

### Why the prefetch is non-fatal

The obvious implementation raises on failure. That would be wrong here,
and I verified why rather than assuming: `tests` declares `dependencies:
["testsSetup"]`, and a failing setup project stops dependent tests from
**running at all**. Adding a deliberately-throwing setup spec produced:

```text
✓  1 [testsSetup] › addUsersAndLicense.spec.ts › setup deployment (11.7s)
✓  2 [testsSetup] › downloadCoderVersions.spec.ts › download outdated CLI (353ms)
✘  3 [testsSetup] › zzTempFail.spec.ts › temporary blast radius probe (0ms)
  1 failed
  1 did not run      <- outdatedCLI never ran
  2 passed
```

So raising would convert a one-test flake into a whole-suite outage on
any GitHub hiccup. Instead the prefetch logs a warning and returns, and
the test's own `downloadCoderVersion` call fetches inline as it does
today. The failure path is therefore no worse than the status quo, and
the success path removes the network from the test entirely.

Of the three policies available (fail hard, fall back inline, or skip
the test), this is the only one that cannot regress anything: it never
blocks the suite, and it never silently drops coverage the way an
auto-skip would.

### Restoring the 60 second budget

This is the second half of the change, and it exists for the fallback
path above. It cannot reintroduce what #16236 fixed: the timeout value
has no causal relationship to how the binary is produced, `coderBinary`
stays pre-built, `go run` stays gone, and only `outdatedCLI.spec.ts` is
touched.

It does give back a bounded sliver of the CI-latency goal, and the bound
is small. A passing run is unaffected. The cost lands only when this one
test hangs, and then it is +30 s once: `--workers 1` so there is no
fan-out, `CODER_E2E_TEST_RETRIES` is unset in CI so `retries` is 0 and
nothing multiplies it, and the job budget is `timeout-minutes: 20`.

## Measurements

Four scenarios, locally on darwin/arm64 against a freshly built
`site/e2e/bin/coder`:

| Scenario | setup spec | `outdatedCLI` | `install.sh` inside the test?
| Result |
|---|---:|---:|---|---|
| Cold, empty cache | 5.7 s | 10.0 s | **no**, ran in setup | ✓ passed |
| Warm cache | 340 ms | 11.9 s | **no**, 0 invocations | ✓ passed |
| Prefetch fails, cache empty | 1 ms | 15.4 s | yes, inline fallback | ✓
passed |
| Setup spec throws | n/a | did not run | n/a | blast radius above |

The cold run is the load-bearing one: `install.sh` is invoked from the
setup spec and the test runs local-only in 10.0 s, so the 84 MiB
download and the 20 s probe are no longer on the assertion's clock.

For context on what "local only" costs, eight consecutive `main` runs
where the CI cache already made `install.sh` a no-op:

| Job | duration |
|---|---:|
| 90382498172 | 11.7 s |
| 90352398170 | 12.1 s |
| 90335547858 | 8.1 s |
| 90317232684 | 13.7 s |
| 90297156949 | 8.4 s |
| 90280065546 | 6.9 s |
| 90265047082 | 6.9 s |
| 90250803989 | 6.6 s |

6.6 to 13.7 seconds. This change makes that the only path rather than
the lucky one.

Also checked: the test name is byte identical (`ssh with client v2.8.0`)
so flake tracking keeps matching it, `outdatedAgent` remains skipped,
and `webTerminal`, `auditLogs`, and `updateTemplate` still pass, so the
added setup dependency disturbs nothing. The full 60-test suite was not
run locally because the premium tests need `CODER_E2E_LICENSE`.

## Also in this change

The pinned versions move to `site/e2e/constants.ts` as
`oldestSupportedCLIVersion` and `oldestSupportedAgentVersion`, so the
setup spec and the tests share one source of truth, and the comments
explaining *why* those particular versions travel with them. The CI
cache key follows them there: it previously hashed the two spec files,
and now hashes `constants.ts`, so it still invalidates exactly when a
pinned version changes.

## Not addressed here

The 20 second probe is relocated, not removed. `install.sh` still
resolves the latest stable version on every pinned install, with no
`--connect-timeout` or `--max-time`, and still treats a non-200 as
fatal, so a GitHub hiccup can fail an install whose target tarball is
already cached locally. That is a user-facing bug in its own right and
wants its own PR, since fixing it means deciding what a pinned install
should print when we no longer look up what "stable" currently is.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-29 16:26:13 -07:00
Cian Johnston dc1d6c3f3a ci: explicitly specify bash in mise tools installation (#27666)
Should hopefully fix [this
issue](https://github.com/coder/coder/actions/runs/30412236628/job/90710968864?pr=27628)
2026-07-29 21:48:41 +00:00
Susana Ferreira 740f5f7e1e chore: drop stale cost control experiment params (#27650)
Removes two stale `experiments: ["ai-gateway-cost-control"]` story
parameters from `GroupPage.stories.tsx`.

Refs #27579 #27553
2026-07-29 19:15:46 +01:00
Paweł BanaszewskiandCian Johnston 18128b7b52 docs: add standalone AI Gateway docs (#27592)
Documents standalone AI Gateway deployment, Gateway key authentication,
monitoring, and the updated embedded vs standalone topology in the AI
Gateway docs.

---------

Co-authored-by: Cian Johnston <cian@coder.com>
2026-07-29 19:38:22 +02:00
Jake Howell 6c42309ccb feat(site): modernize OAuth2 applications settings UI (#27562)
Follow up to #27561 

Modernizes the Deployment Settings OAuth2 Applications create/edit/list
UI to match the AI Providers pattern: fat page views, card layout, and a
Formik + Yup form using shared field primitives.

- Rework CreateOAuth2AppPageView / EditOAuth2AppPageView into fat views
with provider-style layout (back link, avatar + title, bordered cards,
cancel/submit footer)
- Rewrite OAuth2AppForm with Formik/Yup, FormField descriptions, and
IconPickerField (live header avatar on create/edit)
- Order edit page as settings → endpoints (Client ID / Auth / Token via
CodeExample) → secrets
- Align list page row styling and add a Callback URL column
- Update Storybook stories for the new fat-view + form validation
behavior

| Old | New |
| --- | --- |
| <img width="2936" height="1802" alt="old-oauth2-application-create"
src="https://github.com/user-attachments/assets/98c1dec1-c273-43a7-a517-a31ae48bc17c"
/> | <img width="2936" height="1802" alt="new-oauth2-application-create"
src="https://github.com/user-attachments/assets/9d2e1d6b-6905-469f-b9e0-cf8ae3b14f3d"
/> |
| <img width="2936" height="1802" alt="old-oauth2-application-list"
src="https://github.com/user-attachments/assets/3d38daab-1d93-4acb-bff0-d7299da884fd"
/> | <img width="2936" height="1802" alt="new-oauth2-application-list"
src="https://github.com/user-attachments/assets/b3cc56ac-a810-4742-9ea7-27e20caa9bb7"
/> |
| <img width="2936" height="2030" alt="old-oauth2-application-update"
src="https://github.com/user-attachments/assets/544ad92b-ae2b-4b10-907d-c94bcc3d12c4"
/> | <img width="2936" height="3470" alt="new-oauth2-application-update"
src="https://github.com/user-attachments/assets/6e4d228d-8deb-4934-989a-b9c98b633509"
/> |
2026-07-30 02:46:09 +10:00
Jake Howell 659fb48a1d fix: demui <OAuth2AppForm /> (#27561)
This pull-request removes the MUI styles from the `<OAuth2AppForm />`
and adjacent components.
2026-07-30 00:47:06 +10:00
Jake Howell 0b93731ebf fix(site): reflect submitting state during batch update (#27630)
> 🤖 This PR was written by Coder Agents on behalf of Jake Howell.

## Problem

When bulk updating workspaces, the confirmation modal's **Update**
button never entered a submitting/loading state, so there was no
feedback that the update was actually in progress.

## Root cause

The `BatchUpdateModalForm` shows a spinner when its `isProcessing` prop
is `true`. That prop is fed by `batchActions.isProcessing` from
`useBatchActions`. However, the `isProcessing` value was OR-ing together
every mutation's `isPending` flag **except** `updateAllMutation` — the
one that actually performs the batch update:

```ts
isProcessing:
  favoriteAllMutation.isPending ||
  unfavoriteAllMutation.isPending ||
  startAllMutation.isPending ||
  stopAllMutation.isPending ||
  deleteAllMutation.isPending,
  // updateAllMutation.isPending was missing
```

As a result, the button stayed idle for the entire duration of a bulk
update.

## Fix

Include `updateAllMutation.isPending` in the `isProcessing` derivation
so the button spinner and disabled state correctly reflect an in-flight
batch update.

## Testing

- [ ] Manually verify the Update button shows the spinner and is
disabled while a bulk update runs.
2026-07-30 00:46:33 +10:00
Michael Suchacz 4bf9b9d1e6 feat(site): surface chat lifecycle hook outcomes in the chats UI (#27430)
Surfaces chat lifecycle hook outcomes in the chats UI. Final PR of the
lifecycle hooks stack (#27401, #27428, #27429), all now merged.

- Show hook notices attached to their user message as timeline notes
(`role="note"` so historical notices stay out of the screen reader's
assertive live region), and show an info tooltip for notices on queued
messages.
- Cache the full inserted message batch from send and edit responses so
hook-inserted messages survive stream reconnects and queue promotion.
- Reconcile the promoted queue head after sending to an errored chat so
a missed or delayed queue update neither duplicates nor hides messages,
and clear the stale error status so the Thinking indicator appears
before the websocket status event.
- Ignore an authoritative queue snapshot that still contains a
just-promoted message: queued messages are delete-only, so such a
snapshot predates the promotion and would both re-show the promoted
message and drop messages queued since. Fresh snapshots apply in full
and clear the suppression.
- Cache the store's reconciled queue on `queue_update` instead of the
raw event, so a stale update cannot re-show a promoted message after
REST re-hydration.
- Refresh chat details when a send or edit fails, because a failed hook
dispatch can move the chat to the error state.
- Surface tool result error text in the tool rows: the execute failure
tooltip shows the actual error instead of a hardcoded "Command failed",
and a failed `write_file` renders an error label with the result error
text instead of "Wrote <file>" with an args-derived diff of content that
was never written. This makes hook tool denials legible in the timeline,
and benefits every failed execute or write.

- Label a tool call blocked by `pre_tool_use` as failed instead of `Ran
<command>`, matching what the write and edit tools already do. The
wording derives from the tool-result error flag, so a command that ran
and exited non-zero is unaffected.
- Render a hook notice below the message it annotates rather than above
it, which reads correctly for a "your prompt was rewritten" card.
- Give both hook outcomes their own treatment on the create path, where
they previously fell through to the generic error alert and an expected
policy decision appeared with a stack trace, response data, and a
workspaces action. Classification keys on the structured response body
rather than the status code, so ordinary permission errors keep their
existing rendering.

- Unrelated to the hooks work, de-flake `SchedulePage.test.tsx`. Its
`fillForm` helper wrapped an already-retrying `findByLabelText` in
`waitFor`, so the two 1s budgets raced and a slow first render failed
`test-js` with "Timed out in waitFor". This is separable from the rest
of the PR if you would rather it land on its own.

> This PR was written by Mux, an AI coding agent, on Mike's behalf.
2026-07-29 16:45:11 +02:00