Skip to content

build(deps): migrate the TipTap stack to 3.30.4 - #399

Draft
dependabot[bot] wants to merge 4 commits into
mainfrom
dependabot/npm_and_yarn/tiptap/core-3.30.4
Draft

build(deps): migrate the TipTap stack to 3.30.4#399
dependabot[bot] wants to merge 4 commits into
mainfrom
dependabot/npm_and_yarn/tiptap/core-3.30.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown

Migration scope

This Draft is the predecessor source lane for one coherent TipTap 3.30.4 dependency family. It replaces the v2 collaboration cursor, placeholder, and table imports; disables new StarterKit defaults that would change Inkspan behavior; and uses the v3 emitUpdate option for callback-suppressed document replacement. The historical v2 root-cause record remains separate from current integration guidance.

Consolidated successor and dependency order

#402 is the combined successor. It includes this PR's commit history, the #400 transitive security graph, the full Python PR matrix repair, and subsequent collaboration runtime, packed consumer, declaration, and callback corrections. The previous instruction to wait for #400 and then separately restack this old migration head is superseded.

Keep this predecessor open and Draft until #402 integrates into protected main and a fresh comparison proves complete inheritance of every valid delta, including any later commits. If residual work exists, reconcile it with the canonical owner instead of discarding it or creating a competing source writer.

Evidence authority

Earlier local migration test counts do not prove the current combined source. Re-fetch exact heads/bases, ancestry, checks, formal review, security, package/browser/Office evidence, and applicable governance before readiness, integration, or closure. Source version 0.7.0 in the successor is preparation, not registry publication. No force push, self-approval, gate weakening, or predecessor-evidence transfer.

Bumps [@tiptap/core](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core) from 2.27.2 to 3.30.4.
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/v3.30.4/packages/core/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.30.4/packages/core)

---
updated-dependencies:
- dependency-name: "@tiptap/core"
  dependency-version: 3.30.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 3, 2026

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 2 potential issues.

Devin Review

Comment thread package.json Outdated
Comment thread package.json Outdated
@seonghobae
seonghobae marked this pull request as draft September 4, 2026 12:57
@seonghobae

Copy link
Copy Markdown
Contributor

Current-head RCA for 481e581d331c7587619b7d460b4032b54a5b9d10: this changes only @tiptap/core to 3.30.4 while the React adapter, StarterKit, extensions, and @tiptap/pm remain on 2.27.2. Exact-head CI consequently fails the public editor graph at setContent and extension command/type boundaries (toolbar commands, StarterKit, image extensions, restore paths, and related tests). Dependency review also fails on this mixed-major graph.

The PR is returned to Draft rather than closed. Repair requires one coherent TipTap v3 migration lane with all peer packages aligned, version-specific API adaptations, the full editor/collaboration/browser/package suite, accessibility and SSR/form behavior checks, and measured bundle/runtime evidence. Do not merge or mark Ready while the mixed-major graph remains.

Preserve the v2 editor schema and callback behavior while adopting the patched coherent TipTap 3.30.4 package family.

Signed-off-by: Seongho Bae <me@seonghobae.me>
@seonghobae seonghobae changed the title chore(deps): bump @tiptap/core from 2.27.2 to 3.30.4 build(deps): migrate the TipTap stack to 3.30.4 Sep 4, 2026
Signed-off-by: Seongho Bae <me@seonghobae.me>
@seonghobae

Copy link
Copy Markdown
Contributor

Current-head local verification for 87b5fef after the final documentation commit:

  • pnpm peers check: no peer dependency issues
  • pnpm run typecheck: passed
  • pnpm test -- --run: 880/880 passed
  • full Playwright suite: 70/70 passed across Chromium 151, Firefox 153, WebKit 26.5, and consensus

The local Playwright evidence intentionally has no CI head/package identity (headSha and packageSha256 are null), so it does not replace the queued exact-checkout protected workflow or independent review.

Signed-off-by: Seongho Bae <me@seonghobae.me>
@seonghobae

Copy link
Copy Markdown
Contributor

Draft exact head 6b059f2f29598b6584b29b25a637edf751a5f426에서 기존 build-and-test 실패를 수정했습니다. 원인은 published @tiptap/react@3.30.4의 ESM/CJS 선언이 내부 namespace에 없는 Editor를 참조한 upstream 생성 오류였습니다. 아직 7일 숙성 기간을 지나지 않은 3.31.x 예외는 추가하지 않고, pnpm native patch로 잘못된 네 참조만 직접 import된 Editor로 교정했습니다. 검증: typecheck, 전체 build, packed ESM/CJS/SSR/strict-TypeScript 소비자, 156 files / 880 tests, coverage 100%, doctoring 계약 2/2, git diff --check 통과. #400 병합·재스택 전까지 Draft는 유지합니다.

@seonghobae

Copy link
Copy Markdown
Contributor

@codex review exact current head 6b059f2f29598b6584b29b25a637edf751a5f426. Review the bounded declaration patch and supply-chain policy; keep Draft until #400 lands and this branch is restacked.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

Copy link
Copy Markdown
Contributor

Fresh downstream release acceptance from #389: exact release head f1f93d917697e98977fa9fee46f43c7249812377 checked out successfully in Security Scan 33875063962 / Trivy job 101075074557 and failed on GHSA-cp6q-959q-f8rh for @tiptap/core (MEDIUM, security-severity 5.5). Current protected main@a40b9489665bed7d95af619a6079b9c51cab299a still declares the v2 TipTap family, so #399 is the canonical runtime owner path for that release-blocking defect.

Keep the existing order: #400 must integrate first; then adopt its protected-main descendant into #399 by normal non-force ancestry and preserve this PR's coherent TipTap 3.30.4 family/migration semantics. Exact successor acceptance requires: no mixed v2/v3 TipTap graph; peer check clean; typecheck; complete 100%-coverage suite; build + packed package consumers; Chromium/Firefox/WebKit browser evidence; collaboration/paste-safe-link/envelope-restore regressions; exact-head Security Scan with GHSA-cp6q-959q-f8rh absent; SAST/CodeQL terminal; and independent current-head review. Do not suppress Trivy or treat #389's failed scan as a release-branch-only defect. #389 has been returned to Draft until protected #400#399 integration and fresh release-head evidence.

seonghobae added a commit that referenced this pull request Sep 4, 2026
Validate the Python matrix repair together with the patched TipTap runtime and transitive advisory delta so protected checks can converge on one exact head. PRs #399 and #400 retain provenance until this successor integrates.

Signed-off-by: Seongho Bae <seonghobae@users.noreply.github.com>

Commit-Message-Assisted-by: Claude (via Claude Code)

# Conflicts:
#	pnpm-lock.yaml
@seonghobae

Copy link
Copy Markdown
Contributor

#402 head 43788779가 이 TipTap 3.30.4 migration의 유효 델타를 non-force로 완전 승계했습니다. 순환 gate를 한 exact head에서 검증 중이며, #402 protected merge 전에는 이 PR을 닫지 않습니다.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant