build(deps): migrate the TipTap stack to 3.30.4 - #399
Conversation
Bumps [@tiptap/core](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core) from 2.27.2 to 3.30.4. - [Release notes](https://github.com/ueberdosis/tiptap/releases) - [Changelog](https://github.com/ueberdosis/tiptap/blob/v3.30.4/packages/core/CHANGELOG.md) - [Commits](https://github.com/ueberdosis/tiptap/commits/v3.30.4/packages/core) --- updated-dependencies: - dependency-name: "@tiptap/core" dependency-version: 3.30.4 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
|
Current-head RCA for The PR is returned to Draft rather than closed. Repair requires one coherent TipTap v3 migration lane with all peer packages aligned, version-specific API adaptations, the full editor/collaboration/browser/package suite, accessibility and SSR/form behavior checks, and measured bundle/runtime evidence. Do not merge or mark Ready while the mixed-major graph remains. |
Preserve the v2 editor schema and callback behavior while adopting the patched coherent TipTap 3.30.4 package family. Signed-off-by: Seongho Bae <me@seonghobae.me>
Signed-off-by: Seongho Bae <me@seonghobae.me>
|
Current-head local verification for
The local Playwright evidence intentionally has no CI head/package identity ( |
Signed-off-by: Seongho Bae <me@seonghobae.me>
|
Draft exact head |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Fresh downstream release acceptance from #389: exact release head Keep the existing order: #400 must integrate first; then adopt its protected-main descendant into #399 by normal non-force ancestry and preserve this PR's coherent TipTap 3.30.4 family/migration semantics. Exact successor acceptance requires: no mixed v2/v3 TipTap graph; peer check clean; typecheck; complete 100%-coverage suite; build + packed package consumers; Chromium/Firefox/WebKit browser evidence; collaboration/paste-safe-link/envelope-restore regressions; exact-head Security Scan with GHSA-cp6q-959q-f8rh absent; SAST/CodeQL terminal; and independent current-head review. Do not suppress Trivy or treat #389's failed scan as a release-branch-only defect. #389 has been returned to Draft until protected #400 → #399 integration and fresh release-head evidence. |
Validate the Python matrix repair together with the patched TipTap runtime and transitive advisory delta so protected checks can converge on one exact head. PRs #399 and #400 retain provenance until this successor integrates. Signed-off-by: Seongho Bae <seonghobae@users.noreply.github.com> Commit-Message-Assisted-by: Claude (via Claude Code) # Conflicts: # pnpm-lock.yaml
Migration scope
This Draft is the predecessor source lane for one coherent TipTap 3.30.4 dependency family. It replaces the v2 collaboration cursor, placeholder, and table imports; disables new StarterKit defaults that would change Inkspan behavior; and uses the v3 emitUpdate option for callback-suppressed document replacement. The historical v2 root-cause record remains separate from current integration guidance.
Consolidated successor and dependency order
#402 is the combined successor. It includes this PR's commit history, the #400 transitive security graph, the full Python PR matrix repair, and subsequent collaboration runtime, packed consumer, declaration, and callback corrections. The previous instruction to wait for #400 and then separately restack this old migration head is superseded.
Keep this predecessor open and Draft until #402 integrates into protected
mainand a fresh comparison proves complete inheritance of every valid delta, including any later commits. If residual work exists, reconcile it with the canonical owner instead of discarding it or creating a competing source writer.Evidence authority
Earlier local migration test counts do not prove the current combined source. Re-fetch exact heads/bases, ancestry, checks, formal review, security, package/browser/Office evidence, and applicable governance before readiness, integration, or closure. Source version 0.7.0 in the successor is preparation, not registry publication. No force push, self-approval, gate weakening, or predecessor-evidence transfer.