From 481e581d331c7587619b7d460b4032b54a5b9d10 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 3 Sep 2026 08:39:54 +0000 Subject: [PATCH 01/18] chore(deps): bump @tiptap/core from 2.27.2 to 3.30.4 Bumps [@tiptap/core](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/core) from 2.27.2 to 3.30.4. - [Release notes](https://github.com/ueberdosis/tiptap/releases) - [Changelog](https://github.com/ueberdosis/tiptap/blob/v3.30.4/packages/core/CHANGELOG.md) - [Commits](https://github.com/ueberdosis/tiptap/commits/v3.30.4/packages/core) --- updated-dependencies: - dependency-name: "@tiptap/core" dependency-version: 3.30.4 dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- package.json | 2 +- pnpm-lock.yaml | 85 ++++++++++++++++++++++++++++---------------------- 2 files changed, 48 insertions(+), 39 deletions(-) diff --git a/package.json b/package.json index 7e861123e..9aa520a1d 100644 --- a/package.json +++ b/package.json @@ -125,7 +125,7 @@ } }, "dependencies": { - "@tiptap/core": "^2.27.2", + "@tiptap/core": "^3.30.4", "@tiptap/extension-collaboration": "^2.27.2", "@tiptap/extension-collaboration-cursor": "^2.27.2", "@tiptap/extension-image": "^2.11.5", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 77e8723f1..db4d93c68 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -18,41 +18,41 @@ importers: .: dependencies: '@tiptap/core': - specifier: ^2.27.2 - version: 2.27.2(@tiptap/pm@2.27.2) + specifier: ^3.30.4 + version: 3.30.4(@tiptap/pm@2.27.2) '@tiptap/extension-collaboration': specifier: ^2.27.2 - version: 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)(y-prosemirror@1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31)) + version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)(y-prosemirror@1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31)) '@tiptap/extension-collaboration-cursor': specifier: ^2.27.2 - version: 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(y-prosemirror@1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31)) + version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(y-prosemirror@1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31)) '@tiptap/extension-image': specifier: ^2.11.5 - version: 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) + version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2)) '@tiptap/extension-link': specifier: ^2.11.5 - version: 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) + version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) '@tiptap/extension-placeholder': specifier: ^2.11.5 - version: 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) + version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) '@tiptap/extension-table': specifier: ^2.11.5 - version: 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) + version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) '@tiptap/extension-table-cell': specifier: ^2.11.5 - version: 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) + version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2)) '@tiptap/extension-table-header': specifier: ^2.11.5 - version: 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) + version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2)) '@tiptap/extension-table-row': specifier: ^2.11.5 - version: 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) + version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2)) '@tiptap/pm': specifier: ^2.11.5 version: 2.27.2 '@tiptap/react': specifier: ^2.11.5 - version: 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)(react-dom@18.3.1(react@18.3.1))(react@18.3.1) + version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)(react-dom@18.3.1(react@18.3.1))(react@18.3.1) '@tiptap/starter-kit': specifier: ^2.11.5 version: 2.27.2 @@ -1041,6 +1041,11 @@ packages: peerDependencies: '@tiptap/pm': ^2.7.0 + '@tiptap/core@3.30.4': + resolution: {integrity: sha512-V9yKuUfV8qC9WBrnVxkFWmYLBomc3d1CwXoFSjED5DRu5q2oyxv07F+jOJSRogJAY+feHjuxvjhixwxeHm2DXQ==} + peerDependencies: + '@tiptap/pm': 3.30.4 + '@tiptap/extension-blockquote@2.27.2': resolution: {integrity: sha512-oIGZgiAeA4tG3YxbTDfrmENL4/CIwGuP3THtHsNhwRqwsl9SfMk58Ucopi2GXTQSdYXpRJ0ahE6nPqB5D6j/Zw==} peerDependencies: @@ -3340,6 +3345,10 @@ snapshots: dependencies: '@tiptap/pm': 2.27.2 + '@tiptap/core@3.30.4(@tiptap/pm@2.27.2)': + dependencies: + '@tiptap/pm': 2.27.2 + '@tiptap/extension-blockquote@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': dependencies: '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) @@ -3348,9 +3357,9 @@ snapshots: dependencies: '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) - '@tiptap/extension-bubble-menu@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': + '@tiptap/extension-bubble-menu@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) '@tiptap/pm': 2.27.2 tippy.js: 6.3.7 @@ -3367,14 +3376,14 @@ snapshots: dependencies: '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) - '@tiptap/extension-collaboration-cursor@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(y-prosemirror@1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31))': + '@tiptap/extension-collaboration-cursor@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(y-prosemirror@1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31))': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) y-prosemirror: 1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31) - '@tiptap/extension-collaboration@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)(y-prosemirror@1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31))': + '@tiptap/extension-collaboration@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)(y-prosemirror@1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31))': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) '@tiptap/pm': 2.27.2 y-prosemirror: 1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31) @@ -3387,9 +3396,9 @@ snapshots: '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) '@tiptap/pm': 2.27.2 - '@tiptap/extension-floating-menu@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': + '@tiptap/extension-floating-menu@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) '@tiptap/pm': 2.27.2 tippy.js: 6.3.7 @@ -3416,17 +3425,17 @@ snapshots: '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) '@tiptap/pm': 2.27.2 - '@tiptap/extension-image@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extension-image@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) '@tiptap/extension-italic@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': dependencies: '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) - '@tiptap/extension-link@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': + '@tiptap/extension-link@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) '@tiptap/pm': 2.27.2 linkifyjs: 4.3.3 @@ -3442,30 +3451,30 @@ snapshots: dependencies: '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) - '@tiptap/extension-placeholder@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': + '@tiptap/extension-placeholder@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) '@tiptap/pm': 2.27.2 '@tiptap/extension-strike@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': dependencies: '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) - '@tiptap/extension-table-cell@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extension-table-cell@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) - '@tiptap/extension-table-header@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extension-table-header@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) - '@tiptap/extension-table-row@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extension-table-row@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) - '@tiptap/extension-table@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': + '@tiptap/extension-table@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) '@tiptap/pm': 2.27.2 '@tiptap/extension-text-style@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': @@ -3497,11 +3506,11 @@ snapshots: prosemirror-transform: 1.12.0 prosemirror-view: 1.42.1 - '@tiptap/react@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)(react-dom@18.3.1(react@18.3.1))(react@18.3.1)': + '@tiptap/react@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)(react-dom@18.3.1(react@18.3.1))(react@18.3.1)': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) - '@tiptap/extension-bubble-menu': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) - '@tiptap/extension-floating-menu': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) + '@tiptap/extension-bubble-menu': 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) + '@tiptap/extension-floating-menu': 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) '@tiptap/pm': 2.27.2 '@types/use-sync-external-store': 0.0.6 fast-deep-equal: 3.1.3 From 6c9db08237f31652391f8f95221b328e30d4e2ba Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 22:07:03 +0900 Subject: [PATCH 02/18] build(deps): patch transitive security advisories Signed-off-by: Seongho Bae --- pnpm-lock.yaml | 63 +++++++++++++++++++++++---------------------- pnpm-workspace.yaml | 9 +++++-- 2 files changed, 39 insertions(+), 33 deletions(-) diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 77e8723f1..34057e06d 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -7,7 +7,8 @@ settings: overrides: vite: ^6.4.3 esbuild: ^0.25.0 - fast-uri: ^3.1.5 + fast-uri: ^3.1.6 + browserslist: ^4.28.7 nanoid: ^3.3.18 postcss: ^8.5.23 brace-expansion: ^5.0.8 @@ -1456,8 +1457,8 @@ packages: resolution: {integrity: sha512-BLrgEcRTwX2o6gGxGOCNyMvGSp35YofuYzw9h1IMTRmKqttAZZVU67bdb9Pr2vUHA8+j3i2tJfjO6C6+4myGTA==} engines: {node: 18 || 20 || >=22} - baseline-browser-mapping@2.10.43: - resolution: {integrity: sha512-AjYpR78kDWAY3Efj+cDTFH9t9SCoL7OoTp1BOb0mQV7S+6CiLwnWM3FyxhJtdPufDFKzmCSFoUncKjWgJEZTCQ==} + baseline-browser-mapping@2.11.20: + resolution: {integrity: sha512-H0ulySigv6icDJ1F7SjtdCD6PrhTpdYCmP0CactWy1+ekh0AFd0o1Wn5T8b+hnTmdBx19u9yhL6wvCylXMY7zw==} engines: {node: '>=6.0.0'} hasBin: true @@ -1465,8 +1466,8 @@ packages: resolution: {integrity: sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==} engines: {node: 20 || >=22} - browserslist@4.28.5: - resolution: {integrity: sha512-Cu2E6QejHWzuDMTkuwgpABFgDfZrXLQq5V13YOACZx4mFAG4IwGTbTfHPMr4WtxlHoXSM8FIuRwYYCz5XiabaQ==} + browserslist@4.28.8: + resolution: {integrity: sha512-V2NpofLblG64mfOtSgDhOJESZEGogzDMBv/q+W6oc4LXWP/q75eOXoOaaOu1EOadB9U4Bwx/e0yzbvwKH8zalA==} engines: {node: ^6 || ^7 || ^8 || ^9 || ^10 || ^11 || ^12 || >=13.7} hasBin: true @@ -1482,8 +1483,8 @@ packages: resolution: {integrity: sha512-Sp1ablJ0ivDkSzjcaJdxEunN5/XvksFJ2sMBFfq6x0ryhQV/2b/KwFe21cMpmHtPOSij8K99/wSfoEuTObmuMQ==} engines: {node: '>= 0.4'} - caniuse-lite@1.0.30001803: - resolution: {integrity: sha512-g/uHREV2ZpK9qMalCsWaxmA6ol+DX8GYhuf3T40RKoP+oL7vhRJh8LNt73PCjpnR6l14FzfPrB5Yux4PKm2meg==} + caniuse-lite@1.0.30001810: + resolution: {integrity: sha512-TITQPUkaz+aVk5GL6NhOdwk1aEaNTSDPsGFWrTuhKGtjTF70jL/Oht2W4c6rXUe5fu7Ie19VIahAXHIIiWWNeg==} chai@5.3.3: resolution: {integrity: sha512-4zNhdJD/iOjSH0A05ea+Ke6MU5mmpQcbQsSOkgdaUMJ9zTlDTD/GYlwohmIE2u0gaxHYiVHEn1Fw9mZ/ktJWgw==} @@ -1597,8 +1598,8 @@ packages: eastasianwidth@0.2.0: resolution: {integrity: sha512-I88TYZWc9XiYHRQ4/3c5rjjfgkjhLyW2luGIheGERbNQ6OY7yTybanSpDXZa8y7VUP9YmDcYa+eyq4ca7iLqWA==} - electron-to-chromium@1.5.389: - resolution: {integrity: sha512-cEto7aeOqBfU1D+c5py5pE+ooscKE75JifxLBdFUZsqAxRS6y7kebtxAZvICszSl05gPjYHDTjY+lXpyGvpJbg==} + electron-to-chromium@1.5.416: + resolution: {integrity: sha512-K6bvB2BjnNrugtIih6ewlbBI9DXa976jIdiIlRLHhBoEI9a4JaQjjHyF+A1IQI543aQYR4LnmOrT/K5fZj0aPA==} emoji-regex@8.0.0: resolution: {integrity: sha512-MSjYzcWNOA0ewAHpz0MxpYFvwg6yjy1NG3xteoqz644VCo/RPgnr1/GGt+ic3iJTzQ8Eu3TdM14SawnVUmGE6A==} @@ -1679,8 +1680,8 @@ packages: fast-deep-equal@3.1.3: resolution: {integrity: sha512-f3qQ9oQy9j2AhBe/H9VC91wLmKBCCU/gDOnKNAYG5hswO7BLKj09Hc5HYNz9cGI++xlpDCIgDaitVs03ATR84Q==} - fast-uri@3.1.5: - resolution: {integrity: sha512-gHwA1O9LDIcKunMKhObS/HimwtehO1nPUECKAu5TpKgaO19fcWEl4bliWe1jWxVFvIXztJjjQ4L8XQ1EU9f7Jw==} + fast-uri@3.1.6: + resolution: {integrity: sha512-7Ical1vFEMr0onbVzEDIreM22I4khW+fzyQPwvAFWBp1iwdshSZRsL4jjRvPG9JP1uiqMHRto+YU6R2/CzDz5Q==} fdir@6.5.0: resolution: {integrity: sha512-tIbYtZbucOs0BRGqPJkshJUYdL+SDH7dVM8gjy+ERp3WAUjLEFJE+02kanyHtwjWOnwrKYBiwAmM0p4kLJAnXg==} @@ -1982,8 +1983,8 @@ packages: engines: {node: ^10 || ^12 || ^13.7 || ^14 || >=15.0.1} hasBin: true - node-releases@2.0.51: - resolution: {integrity: sha512-wRNIrw4DmVLKQlbgOMdkMx27Wrpzes2hh5Jtbi2bjPd+4wJstWIqP5A+lscnqbm0xxmT5Bpg8Lec5ItEBwx6BQ==} + node-releases@2.0.54: + resolution: {integrity: sha512-YHs7BmmcsdAI5Ozuf8JZo6PT0mv2GIWC9vMfvUC3dp65M8hn7Ux8CPL+2oBI7juNuj9d0ndhTcznq2ODBps9cQ==} engines: {node: '>=18'} nwsapi@2.2.24: @@ -2392,11 +2393,11 @@ packages: resolution: {integrity: sha512-5uKD0nqiYVzlmCRs01Fhs2BdkEgBS3SAVP6ndrBsuK42iC2+JHyxM05Rm9G8+5mkmRtzMZGY8Ct5+mliZxU/Ww==} engines: {node: '>=18.12.0'} - update-browserslist-db@1.2.3: - resolution: {integrity: sha512-Js0m9cx+qOgDxo0eMiFGEueWztz+d4+M3rGlmKPT+T4IS/jP4ylw3Nwpu6cpTTP8R1MAC1kF4VbdLt3ARf209w==} + update-browserslist-db@1.3.2: + resolution: {integrity: sha512-UQ+MSxlhRm1bzjhU+DcuXfjFO1FzNtqhK5+9Yvlp90ItDLk5vT932A0rFu619nf7RVS+Y/VeaUW1jaRDqZ8VJw==} hasBin: true peerDependencies: - browserslist: '>= 4.21.0' + browserslist: ^4.28.7 use-sync-external-store@1.6.0: resolution: {integrity: sha512-Pp6GSwGP/NrPIrxVFAIkOQeyw8lFenOHijQWkUTrDvrF4ALqylP2C/KCkeS9dpUM3KvYRQhna5vt7IL95+ZQ9w==} @@ -2648,7 +2649,7 @@ snapshots: dependencies: '@babel/compat-data': 7.29.7 '@babel/helper-validator-option': 7.29.7 - browserslist: 4.28.5 + browserslist: 4.28.8 lru-cache: 5.1.1 semver: 6.3.1 @@ -3763,7 +3764,7 @@ snapshots: ajv@8.18.0: dependencies: fast-deep-equal: 3.1.3 - fast-uri: 3.1.5 + fast-uri: 3.1.6 json-schema-traverse: 1.0.0 require-from-string: 2.0.2 @@ -3809,19 +3810,19 @@ snapshots: balanced-match@4.0.4: {} - baseline-browser-mapping@2.10.43: {} + baseline-browser-mapping@2.11.20: {} brace-expansion@5.0.9: dependencies: balanced-match: 4.0.4 - browserslist@4.28.5: + browserslist@4.28.8: dependencies: - baseline-browser-mapping: 2.10.43 - caniuse-lite: 1.0.30001803 - electron-to-chromium: 1.5.389 - node-releases: 2.0.51 - update-browserslist-db: 1.2.3(browserslist@4.28.5) + baseline-browser-mapping: 2.11.20 + caniuse-lite: 1.0.30001810 + electron-to-chromium: 1.5.416 + node-releases: 2.0.54 + update-browserslist-db: 1.3.2(browserslist@4.28.8) bundle-name@4.1.0: dependencies: @@ -3834,7 +3835,7 @@ snapshots: es-errors: 1.3.0 function-bind: 1.1.2 - caniuse-lite@1.0.30001803: {} + caniuse-lite@1.0.30001810: {} chai@5.3.3: dependencies: @@ -3927,7 +3928,7 @@ snapshots: eastasianwidth@0.2.0: {} - electron-to-chromium@1.5.389: {} + electron-to-chromium@1.5.416: {} emoji-regex@8.0.0: {} @@ -4007,7 +4008,7 @@ snapshots: fast-deep-equal@3.1.3: {} - fast-uri@3.1.5: {} + fast-uri@3.1.6: {} fdir@6.5.0(picomatch@4.0.5): optionalDependencies: @@ -4313,7 +4314,7 @@ snapshots: nanoid@3.3.18: {} - node-releases@2.0.51: {} + node-releases@2.0.54: {} nwsapi@2.2.24: {} @@ -4812,9 +4813,9 @@ snapshots: picomatch: 4.0.5 webpack-virtual-modules: 0.6.2 - update-browserslist-db@1.2.3(browserslist@4.28.5): + update-browserslist-db@1.3.2(browserslist@4.28.8): dependencies: - browserslist: 4.28.5 + browserslist: 4.28.8 escalade: 3.2.0 picocolors: 1.1.1 diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index 37053afea..c063840d4 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -23,7 +23,11 @@ trustPolicyIgnoreAfter: 43200 # - vite<6.4.3: GHSA-fx2h-pf6j-xcff / GHSA-4w7w-66w2-5vf9 / GHSA-v6wh-96g9-6wx3 # (vitest's @vitest/mocker still resolves a transitive vite@5) # - esbuild<0.25: GHSA-67mh-4wv8-2f99 (dragged in by the transitive vite@5) -# - fast-uri<3.1.5: GHSA-v2hh-gcrm-f6hx / GHSA-7p8r-x3mc-p8w7 (via ajv in vite-plugin-dts) +# - fast-uri<3.1.6: GHSA-v2hh-gcrm-f6hx / GHSA-7p8r-x3mc-p8w7 / +# GHSA-5jgf-p345-68v8 / GHSA-f65p-4m7j-42xc / GHSA-fph4-wmhf-6fwf / +# GHSA-jqff-g426-hqxp (via ajv in vite-plugin-dts) +# - browserslist<4.28.7: GHSA-c83g-rgw3-j3cx / GHSA-73wf-gq98-2v4g +# (via Babel in Storybook and Vite's React plugin) # - nanoid<3.3.18: GHSA-2v37-7h3g-55p8 (via postcss) # - postcss<=8.5.22: GHSA-r28c-9q8g-f849 / GHSA-fxqj-rqcc-2cmp (source-map path traversal via vite) # - brace-expansion<=5.0.7: GHSA-mh99-v99m-4gvg (unbounded-expansion DoS). The @@ -33,7 +37,8 @@ trustPolicyIgnoreAfter: 43200 overrides: vite: ^6.4.3 esbuild: ^0.25.0 - fast-uri: ^3.1.5 + fast-uri: ^3.1.6 + browserslist: ^4.28.7 nanoid: ^3.3.18 postcss: ^8.5.23 brace-expansion: ^5.0.8 From a3340843c98e9729ace7210f31b9378151f60587 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 22:19:00 +0900 Subject: [PATCH 03/18] build(deps): migrate TipTap stack to v3 Preserve the v2 editor schema and callback behavior while adopting the patched coherent TipTap 3.30.4 package family. Signed-off-by: Seongho Bae --- docs/atomic-envelope-restore.md | 4 +- docs/collaboration.md | 4 +- .../tiptap-v2-prosemirror-paste-adapter.md | 17 +- docs/imperative-envelope-persistence.md | 4 +- docs/papers/README.md | 2 +- package.json | 23 +- pnpm-lock.yaml | 707 ++++++++---------- pnpm-workspace.yaml | 2 + src/collaboration/CollaborativeCwlEditor.tsx | 4 +- src/components/CwlEditor.tsx | 2 +- src/components/EditorFormField.tsx | 2 +- src/components/editorFormReset.test.ts | 8 +- src/components/editorFormReset.ts | 4 +- src/components/useEditorHandle.ts | 4 +- src/documentEnvelopeIfMatch.evidence.test.tsx | 6 +- ...ocumentEnvelopeIfMatch.reentrancy.test.tsx | 4 +- src/documentEnvelopeIfMatch.test.tsx | 4 +- src/documentEnvelopeRestore.ts | 2 +- src/extensions/SafeClipboardExtension.test.ts | 2 +- src/extensions/SafeClipboardExtension.ts | 8 +- src/extensions/kit.ts | 13 +- src/index.ts | 2 +- ...tapV2ClipboardAdapterDocumentation.test.ts | 6 +- tests/browser/harness.ts | 2 +- 24 files changed, 366 insertions(+), 470 deletions(-) diff --git a/docs/atomic-envelope-restore.md b/docs/atomic-envelope-restore.md index b0c97f2c4..31e3f0a07 100644 --- a/docs/atomic-envelope-restore.md +++ b/docs/atomic-envelope-restore.md @@ -35,7 +35,7 @@ Restore performs these operations in order: 4. validate the Inkspan envelope schema identifier and version; 5. detach and deeply freeze the document JSON; 6. reconstruct and recursively check the complete document against the active ProseMirror schema; -7. dispatch one TipTap `setContent(..., false)` replacement; +7. dispatch one TipTap `setContent(..., { emitUpdate: false })` replacement; 8. verify that the resulting active document is structurally equal to the prepared document. Any failure before step 7 leaves the current document unchanged. A ProseMirror transaction filter may reject a schema-valid replacement at step 7; Inkspan then throws `DocumentEnvelopeRestoreError` and never reports the operation as successful. Inkspan's built-in safe-link and inline-image policies reject unsafe replacements without changing the document. @@ -87,7 +87,7 @@ The helper adds no database, credential, environment-variable, transport, provid ## Primary references -- [TipTap v2 `setContent` command](https://v2.tiptap.dev/docs/editor/api/commands/content/set-content) +- [TipTap `setContent` command](https://tiptap.dev/docs/editor/api/commands/content/set-content) - [ProseMirror `PluginSpec.filterTransaction`](https://prosemirror.net/docs/ref/#state.PluginSpec.filterTransaction) - [ProseMirror `Schema.nodeFromJSON()` and `Node.check()`](https://prosemirror.net/docs/ref/#model.Schema.nodeFromJSON) - [RFC 8259: The JavaScript Object Notation (JSON) Data Interchange Format](https://www.rfc-editor.org/rfc/rfc8259) diff --git a/docs/collaboration.md b/docs/collaboration.md index 6fdea724b..491ba20f1 100644 --- a/docs/collaboration.md +++ b/docs/collaboration.md @@ -187,8 +187,8 @@ editor or coupling its core package to organization infrastructure. ## Primary references -- [TipTap v2 Collaboration](https://v2.tiptap.dev/docs/editor/extensions/functionality/collaboration) -- [TipTap v2 Collaboration Cursor](https://v2.tiptap.dev/docs/editor/extensions/functionality/collaboration-cursor) +- [TipTap Collaboration](https://tiptap.dev/docs/editor/extensions/functionality/collaboration) +- [TipTap Collaboration Caret](https://tiptap.dev/docs/editor/extensions/functionality/collaboration-caret) - [Yjs Awareness and Presence](https://docs.yjs.dev/getting-started/adding-awareness) - [WAI-ARIA `status` role](https://www.w3.org/TR/wai-aria-1.2/#status) - [WCAG relative luminance definition](https://www.w3.org/WAI/WCAG22/Understanding/contrast-minimum.html) diff --git a/docs/doctoring/tiptap-v2-prosemirror-paste-adapter.md b/docs/doctoring/tiptap-v2-prosemirror-paste-adapter.md index 519012601..d94f47776 100644 --- a/docs/doctoring/tiptap-v2-prosemirror-paste-adapter.md +++ b/docs/doctoring/tiptap-v2-prosemirror-paste-adapter.md @@ -1,8 +1,8 @@ -# TipTap v2 ProseMirror paste adapter +# TipTap ProseMirror paste adapter ## Decision -Inkspan registers SafeClipboard through a TipTap v2 extension whose +Inkspan registers SafeClipboard through a TipTap v3 extension whose `addProseMirrorPlugins` hook returns a ProseMirror `Plugin` with a `transformPastedHTML` editor property. That property receives rich clipboard HTML before ProseMirror parses it into an editor document. @@ -16,7 +16,7 @@ retention, migration, and model-use policy. ## Root cause -Inkspan locks `@tiptap/core 2.27.2`. The first implementation placed a +Inkspan previously locked `@tiptap/core 2.27.2`. The first implementation placed a `transformPastedHTML` field directly on a TipTap extension configuration and its unit tests invoked that field manually. That appeared consistent with current TipTap documentation, but it did not prove registration in the installed v2 @@ -28,7 +28,8 @@ plugins. It does not collect an arbitrary direct extension `transformPastedHTML` field into editor props. The locked source is authoritative for the installed runtime, while current mutable documentation is useful design context but not evidence that an API existed in this historical dependency -version. +version. Inkspan now locks the coherent TipTap 3.30.4 package family; the same +real-pipeline tests prove that the adapter remains registered after migration. The practical result was a false assurance gap: direct sanitizer unit tests were green, but the real `editor.view` paste pipeline had no SafeClipboard @@ -57,7 +58,7 @@ result is not completion evidence for a later exact head. ## Ordering and residual host boundary -TipTap v2.27.2 sorts extension priorities from higher to lower when resolving +TipTap v3.30.4 sorts extension priorities from higher to lower when resolving extensions and again when assembling ProseMirror plugins. ProseMirror checks plugin-provided editor properties in plugin order. SafeClipboard therefore uses a deliberately low priority so ordinary host transforms run first and the @@ -107,6 +108,6 @@ TipTap GmbH. (n.d.). *Extension API*. TipTap Editor Docs. Retrieved August 7, 2026, from https://tiptap.dev/docs/editor/extensions/custom-extensions/create-new/extension -TipTap GmbH. (2025). *ExtensionManager.ts (Version 2.27.2)* [Source code]. -GitHub. Retrieved August 7, 2026, from -https://github.com/ueberdosis/tiptap/blob/%40tiptap/core%402.27.2/packages/core/src/ExtensionManager.ts +TipTap GmbH. (2026). *ExtensionManager.ts (Version 3.30.4)* [Source code]. +GitHub. Retrieved September 4, 2026, from +https://github.com/ueberdosis/tiptap/blob/%40tiptap/core%403.30.4/packages/core/src/ExtensionManager.ts diff --git a/docs/imperative-envelope-persistence.md b/docs/imperative-envelope-persistence.md index e219ec12d..42b1b4632 100644 --- a/docs/imperative-envelope-persistence.md +++ b/docs/imperative-envelope-persistence.md @@ -94,7 +94,7 @@ Object and JSON-text inputs use `validateDocumentEnvelope()` and `...Bytes` methods. Validation is non-mutating. Restore completes duplicate object-name detection, resource checks, schema/version routing, hostile-value detachment, and full active ProseMirror schema reconstruction before one -`setContent(..., false)` mutation. A failure leaves the current document +`setContent(..., { emitUpdate: false })` mutation. A failure leaves the current document unchanged. Successful restore suppresses normal change callbacks because loading an @@ -216,5 +216,5 @@ metadata rather than extending the strict envelope with ad hoc fields. - [W3C Web Cryptography API Recommendation](https://www.w3.org/TR/2017/REC-WebCryptoAPI-20170126/) - [WHATWG Encoding Standard: UTF-8](https://encoding.spec.whatwg.org/#utf-8) - [TipTap persistence guidance](https://tiptap.dev/docs/editor/core-concepts/persistence) -- [TipTap v2 `setContent`](https://v2.tiptap.dev/docs/editor/api/commands/content/set-content) +- [TipTap `setContent`](https://tiptap.dev/docs/editor/api/commands/content/set-content) - [ProseMirror `Node.fromJSON`](https://prosemirror.net/docs/ref/#model.Node^fromJSON) diff --git a/docs/papers/README.md b/docs/papers/README.md index 97e700de4..a5f812288 100644 --- a/docs/papers/README.md +++ b/docs/papers/README.md @@ -35,4 +35,4 @@ GFM table and strikethrough extensions. as base64, which this module relies on so figures travel with the document and remain readable by a downstream LLM. - **ProseMirror** (Marijn Haverbeke) — the MIT-licensed document model and - editing toolkit that TipTap v2 is built on. + editing toolkit that TipTap is built on. diff --git a/package.json b/package.json index 9aa520a1d..7f99c12dc 100644 --- a/package.json +++ b/package.json @@ -125,19 +125,16 @@ } }, "dependencies": { - "@tiptap/core": "^3.30.4", - "@tiptap/extension-collaboration": "^2.27.2", - "@tiptap/extension-collaboration-cursor": "^2.27.2", - "@tiptap/extension-image": "^2.11.5", - "@tiptap/extension-link": "^2.11.5", - "@tiptap/extension-placeholder": "^2.11.5", - "@tiptap/extension-table": "^2.11.5", - "@tiptap/extension-table-cell": "^2.11.5", - "@tiptap/extension-table-header": "^2.11.5", - "@tiptap/extension-table-row": "^2.11.5", - "@tiptap/pm": "^2.11.5", - "@tiptap/react": "^2.11.5", - "@tiptap/starter-kit": "^2.11.5", + "@tiptap/core": "3.30.4", + "@tiptap/extension-collaboration": "3.30.4", + "@tiptap/extension-collaboration-caret": "3.30.4", + "@tiptap/extension-image": "3.30.4", + "@tiptap/extension-link": "3.30.4", + "@tiptap/extension-table": "3.30.4", + "@tiptap/extensions": "3.30.4", + "@tiptap/pm": "3.30.4", + "@tiptap/react": "3.30.4", + "@tiptap/starter-kit": "3.30.4", "marked": "^15.0.6", "turndown": "^7.2.0", "turndown-plugin-gfm": "^1.0.2", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index db4d93c68..0ac053658 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -5,6 +5,8 @@ settings: excludeLinksFromLockfile: false overrides: + '@tiptap/extension-bubble-menu': 3.30.4 + '@tiptap/extension-floating-menu': 3.30.4 vite: ^6.4.3 esbuild: ^0.25.0 fast-uri: ^3.1.5 @@ -18,44 +20,35 @@ importers: .: dependencies: '@tiptap/core': - specifier: ^3.30.4 - version: 3.30.4(@tiptap/pm@2.27.2) + specifier: 3.30.4 + version: 3.30.4(@tiptap/pm@3.30.4) '@tiptap/extension-collaboration': - specifier: ^2.27.2 - version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)(y-prosemirror@1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31)) - '@tiptap/extension-collaboration-cursor': - specifier: ^2.27.2 - version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(y-prosemirror@1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31)) + specifier: 3.30.4 + version: 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)(@tiptap/y-tiptap@3.0.9(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31))(yjs@13.6.31) + '@tiptap/extension-collaboration-caret': + specifier: 3.30.4 + version: 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)(@tiptap/y-tiptap@3.0.9(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31)) '@tiptap/extension-image': - specifier: ^2.11.5 - version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2)) + specifier: 3.30.4 + version: 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4)) '@tiptap/extension-link': - specifier: ^2.11.5 - version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) - '@tiptap/extension-placeholder': - specifier: ^2.11.5 - version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) + specifier: 3.30.4 + version: 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) '@tiptap/extension-table': - specifier: ^2.11.5 - version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) - '@tiptap/extension-table-cell': - specifier: ^2.11.5 - version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2)) - '@tiptap/extension-table-header': - specifier: ^2.11.5 - version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2)) - '@tiptap/extension-table-row': - specifier: ^2.11.5 - version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2)) + specifier: 3.30.4 + version: 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) + '@tiptap/extensions': + specifier: 3.30.4 + version: 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) '@tiptap/pm': - specifier: ^2.11.5 - version: 2.27.2 + specifier: 3.30.4 + version: 3.30.4 '@tiptap/react': - specifier: ^2.11.5 - version: 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)(react-dom@18.3.1(react@18.3.1))(react@18.3.1) + specifier: 3.30.4 + version: 3.30.4(@floating-ui/dom@1.8.0)(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)(@types/react-dom@18.3.7(@types/react@18.3.31))(@types/react@18.3.31)(react-dom@18.3.1(react@18.3.1))(react@18.3.1) '@tiptap/starter-kit': - specifier: ^2.11.5 - version: 2.27.2 + specifier: 3.30.4 + version: 3.30.4 marked: specifier: ^15.0.6 version: 15.0.12 @@ -438,6 +431,15 @@ packages: cpu: [x64] os: [win32] + '@floating-ui/core@1.8.0': + resolution: {integrity: sha512-0CIZ5itps/8x7BG8dEIhs53BvCUH2PCoogtakwRTut+Arm58sJooJ0AuZhLw2HJYIR5cMLNPBSS728sPho2khQ==} + + '@floating-ui/dom@1.8.0': + resolution: {integrity: sha512-yXSrzeHZBTZadLOlfyhCkJHNeLJnHRnRInwdZ40L7ZiaAtrBwoYlsDrX3v5zB1Utk7CLfzcOVnVVWoXEky7Ceg==} + + '@floating-ui/utils@0.2.12': + resolution: {integrity: sha512-HpCo8tmWzLVad5s2d19EhAz5zqrrQ6s69qd6moPMQvkOuSwDT1YgRfWSVuc4ennqrgv3OHppiOGMQ7oC13yIww==} + '@isaacs/cliui@8.0.2': resolution: {integrity: sha512-O8jcjabXaleOG9DQ0+ARXWZBTfnP4WNAqzuiJK7ll44AmxGKv/J2M4TPjxjY3znBCfvBXFzucm1twdyFybFqEA==} engines: {node: '>=12'} @@ -737,12 +739,6 @@ packages: resolution: {integrity: sha512-+1VkjdD0QBLPodGrJUeqarH8VAIvQODIbwh9XpP5Syisf7YoQgsJKPNFoqqLQlu+VQ/tVSshMR6loPMn8U+dPg==} engines: {node: '>=14'} - '@popperjs/core@2.11.8': - resolution: {integrity: sha512-P1st0aksCrn9sGZhp8GMYwBnQsbvAWsZAX44oXNNvLHGqAOcoVxmjZiohstwQ7SqKnbR47akdNi+uleWD8+g6A==} - - '@remirror/core-constants@3.0.0': - resolution: {integrity: sha512-42aWfPrimMfDKDi4YegyS7x+/0tlzaqwPQCULLanv3DMIlu96KTJR0fM5isWX2UViOqlGnX6YFgqWepcX+XMNg==} - '@rolldown/pluginutils@1.0.0-beta.27': resolution: {integrity: sha512-+d0F4MKMCbeVUJwG96uQ4SgAznZNSq93I3V+9NHA4OpvqG8mRCpGdKmK8l/dl02h2CCDHwW2FqilnTyDcAnqjA==} @@ -1036,192 +1032,191 @@ packages: peerDependencies: '@testing-library/dom': '>=7.21.4' - '@tiptap/core@2.27.2': - resolution: {integrity: sha512-ABL1N6eoxzDzC1bYvkMbvyexHacszsKdVPYqhl5GwHLOvpZcv9VE9QaKwDILTyz5voCA0lGcAAXZp+qnXOk5lQ==} - peerDependencies: - '@tiptap/pm': ^2.7.0 - '@tiptap/core@3.30.4': resolution: {integrity: sha512-V9yKuUfV8qC9WBrnVxkFWmYLBomc3d1CwXoFSjED5DRu5q2oyxv07F+jOJSRogJAY+feHjuxvjhixwxeHm2DXQ==} peerDependencies: '@tiptap/pm': 3.30.4 - '@tiptap/extension-blockquote@2.27.2': - resolution: {integrity: sha512-oIGZgiAeA4tG3YxbTDfrmENL4/CIwGuP3THtHsNhwRqwsl9SfMk58Ucopi2GXTQSdYXpRJ0ahE6nPqB5D6j/Zw==} - peerDependencies: - '@tiptap/core': ^2.7.0 - - '@tiptap/extension-bold@2.27.2': - resolution: {integrity: sha512-bR7J5IwjCGQ0s3CIxyMvOCnMFMzIvsc5OVZKscTN5UkXzFsaY6muUAIqtKxayBUucjtUskm5qZowJITCeCb1/A==} + '@tiptap/extension-blockquote@3.30.4': + resolution: {integrity: sha512-n25/pFfDpZRJS4f6Ga/PkNrQFBEr3pRvPkDlY99kl8Kt8jFa1EUxbx+uUVIilqwiUjUnHtwCfqjSDFooQjezjg==} peerDependencies: - '@tiptap/core': ^2.7.0 - - '@tiptap/extension-bubble-menu@2.27.2': - resolution: {integrity: sha512-VkwlCOcr0abTBGzjPXklJ92FCowG7InU8+Od9FyApdLNmn0utRYGRhw0Zno6VgE9EYr1JY4BRnuSa5f9wlR72w==} - peerDependencies: - '@tiptap/core': ^2.7.0 - '@tiptap/pm': ^2.7.0 + '@tiptap/core': 3.30.4 + '@tiptap/pm': 3.30.4 - '@tiptap/extension-bullet-list@2.27.2': - resolution: {integrity: sha512-gmFuKi97u5f8uFc/GQs+zmezjiulZmFiDYTh3trVoLRoc2SAHOjGEB7qxdx7dsqmMN7gwiAWAEVurLKIi1lnnw==} + '@tiptap/extension-bold@3.30.4': + resolution: {integrity: sha512-eCOkf+/jdQte7lTZ4pQF10akrsFM4TzYc0ysSAkPa7QA+ex1aI8QT5UUx+mK8RwFo57lqE8PCX/Mx1gTqlCDnQ==} peerDependencies: - '@tiptap/core': ^2.7.0 + '@tiptap/core': 3.30.4 - '@tiptap/extension-code-block@2.27.2': - resolution: {integrity: sha512-KgvdQHS4jXr79aU3wZOGBIZYYl9vCB7uDEuRFV4so2rYrfmiYMw3T8bTnlNEEGe4RUeAms1i4fdwwvQp9nR1Dw==} + '@tiptap/extension-bubble-menu@3.30.4': + resolution: {integrity: sha512-diB5stCiuffFIIKhDAVvSYTYW/zzEVh7QqTuk2JAqdkAmAGP2YvUXXZBVhA9ITTIYD1+cp5p6rx9pdM25fsVRQ==} peerDependencies: - '@tiptap/core': ^2.7.0 - '@tiptap/pm': ^2.7.0 + '@tiptap/core': 3.30.4 + '@tiptap/pm': 3.30.4 - '@tiptap/extension-code@2.27.2': - resolution: {integrity: sha512-7X9AgwqiIGXoZX7uvdHQsGsjILnN/JaEVtqfXZnPECzKGaWHeK/Ao4sYvIIIffsyZJA8k5DC7ny2/0sAgr2TuA==} + '@tiptap/extension-bullet-list@3.30.4': + resolution: {integrity: sha512-kJFOF3U4b1ad4T7Vm+CIIp+nxcr6wwWVeqpVe6Jhq9gudsWCKP0+KVAmOiJCePoDu9fpc/ZuGMXDefXYnyQDxg==} peerDependencies: - '@tiptap/core': ^2.7.0 + '@tiptap/extension-list': 3.30.4 - '@tiptap/extension-collaboration-cursor@2.27.2': - resolution: {integrity: sha512-ScgoVszsFpYs3EldKze1wLcyumNhZHgiOpAj7DpdTEdfSaFAB2gGvzenPBy1zI/PGcLPFEuC/fdLc5ntD3di4Q==} + '@tiptap/extension-code-block@3.30.4': + resolution: {integrity: sha512-eKLKxgLCvi+M5tiLkW+fIMzDtR7HvSKnigSE9RYHZmzSrv1ejVjgNj5FH8nGTim98hXiQGfWotss3zqG6bpdDw==} peerDependencies: - '@tiptap/core': ^2.7.0 - y-prosemirror: ^1.2.11 + '@tiptap/core': 3.30.4 + '@tiptap/pm': 3.30.4 - '@tiptap/extension-collaboration@2.27.2': - resolution: {integrity: sha512-Y61ItHxQ1uc/Ir27mBQRI/wY9JkOui194V+awNv+1YHeaKArTjC2cdSvNzj9+h8JIh5MyfvslSf8hBa7t7PzAg==} + '@tiptap/extension-code@3.30.4': + resolution: {integrity: sha512-z9v9rBA/0MecUvf8QkcKKOGgceO9X3DT/JvFNka8Mdd68V5fhBs0jGsxYrj3qDWtdXyyUQIWs0t8HzL6LTdLiA==} peerDependencies: - '@tiptap/core': ^2.7.0 - '@tiptap/pm': ^2.7.0 - y-prosemirror: ^1.2.11 + '@tiptap/core': 3.30.4 - '@tiptap/extension-document@2.27.2': - resolution: {integrity: sha512-CFhAYsPnyYnosDC4639sCJnBUnYH4Cat9qH5NZWHVvdgtDwu8GZgZn2eSzaKSYXWH1vJ9DSlCK+7UyC3SNXIBA==} + '@tiptap/extension-collaboration-caret@3.30.4': + resolution: {integrity: sha512-Br/J0o+zxt4KMV6CQBieWGJyvD20zFDKG1mhVBAlyHbBdKkXNngz2yoqCeKPpZjFj8htj0l9c5klA7A2mdAjZA==} peerDependencies: - '@tiptap/core': ^2.7.0 + '@tiptap/core': 3.30.4 + '@tiptap/pm': 3.30.4 + '@tiptap/y-tiptap': ^3.0.7 - '@tiptap/extension-dropcursor@2.27.2': - resolution: {integrity: sha512-oEu/OrktNoQXq1x29NnH/GOIzQZm8ieTQl3FK27nxfBPA89cNoH4mFEUmBL5/OFIENIjiYG3qWpg6voIqzswNw==} + '@tiptap/extension-collaboration@3.30.4': + resolution: {integrity: sha512-80ASfIiXfWwiA8tiNU+k6xDcbIfOslYc3q1GJS4Ghmwt3YGi13e5seIdRp0awPs401G9IJQ3HxfHgabIcsfb6A==} peerDependencies: - '@tiptap/core': ^2.7.0 - '@tiptap/pm': ^2.7.0 + '@tiptap/core': 3.30.4 + '@tiptap/pm': 3.30.4 + '@tiptap/y-tiptap': ^3.0.7 + yjs: ^13 - '@tiptap/extension-floating-menu@2.27.2': - resolution: {integrity: sha512-GUN6gPIGXS7ngRJOwdSmtBRBDt9Kt9CM/9pSwKebhLJ+honFoNA+Y6IpVyDvvDMdVNgBchiJLs6qA5H97gAePQ==} + '@tiptap/extension-document@3.30.4': + resolution: {integrity: sha512-N+FbI+X1FVH8HxsM8C4fNkkzKXiyhXc9oh9oSqAIKOAAYGAjnHLMxW9TzYXbvm60SlAn6DIMypNf6nULGEc1oQ==} peerDependencies: - '@tiptap/core': ^2.7.0 - '@tiptap/pm': ^2.7.0 + '@tiptap/core': 3.30.4 - '@tiptap/extension-gapcursor@2.27.2': - resolution: {integrity: sha512-/c9VF1HBxj+AP54XGVgCmD9bEGYc5w5OofYCFQgM7l7PB1J00A4vOke0oPkHJnqnOOyPlFaxO/7N6l3XwFcnKA==} + '@tiptap/extension-dropcursor@3.30.4': + resolution: {integrity: sha512-P1V0y/FKdyNVBImeW3WN+uGI77Uboc0dW44izAjrII0jcW2KUoBQeNrbbm9UZR1xuRvQJ1Z0OrFHmYrxP5ClNQ==} peerDependencies: - '@tiptap/core': ^2.7.0 - '@tiptap/pm': ^2.7.0 + '@tiptap/extensions': 3.30.4 - '@tiptap/extension-hard-break@2.27.2': - resolution: {integrity: sha512-kSRVGKlCYK6AGR0h8xRkk0WOFGXHIIndod3GKgWU49APuIGDiXd8sziXsSlniUsWmqgDmDXcNnSzPcV7AQ8YNg==} + '@tiptap/extension-floating-menu@3.30.4': + resolution: {integrity: sha512-75kDLGkVqLBL7OPGNhJZQkmI3KGGVN9S5i+ZHKZEhk4HNOQUU+YMs7qu4I/XSJMXSh7mGrQlMi/OD/Fn3JmkKg==} peerDependencies: - '@tiptap/core': ^2.7.0 + '@floating-ui/dom': ^1.0.0 + '@tiptap/core': 3.30.4 + '@tiptap/pm': 3.30.4 - '@tiptap/extension-heading@2.27.2': - resolution: {integrity: sha512-iM3yeRWuuQR/IRQ1djwNooJGfn9Jts9zF43qZIUf+U2NY8IlvdNsk2wTOdBgh6E0CamrStPxYGuln3ZS4fuglw==} + '@tiptap/extension-gapcursor@3.30.4': + resolution: {integrity: sha512-wsuXsB8Rp9BgfWlWYsRVzoHg9LwhoPAQGaw/gku1buDSTMcbLYQvok5MwJ/uJRECaJRLGgbUe5WBXoRvSY+o3g==} peerDependencies: - '@tiptap/core': ^2.7.0 + '@tiptap/extensions': 3.30.4 - '@tiptap/extension-history@2.27.2': - resolution: {integrity: sha512-+hSyqERoFNTWPiZx4/FCyZ/0eFqB9fuMdTB4AC/q9iwu3RNWAQtlsJg5230bf/qmyO6bZxRUc0k8p4hrV6ybAw==} + '@tiptap/extension-hard-break@3.30.4': + resolution: {integrity: sha512-eZ66SyfgmMK861S5SYtQROT/+ZfXtDHxllz7ao+X+dcl+DMdffmOzBeSfwrHQENmgl7umjbdAjqC7PT95jaU+w==} peerDependencies: - '@tiptap/core': ^2.7.0 - '@tiptap/pm': ^2.7.0 + '@tiptap/core': 3.30.4 - '@tiptap/extension-horizontal-rule@2.27.2': - resolution: {integrity: sha512-WGWUSgX+jCsbtf9Y9OCUUgRZYuwjVoieW5n6mAUohJ9/6gc6sGIOrUpBShf+HHo6WD+gtQjRd+PssmX3NPWMpg==} + '@tiptap/extension-heading@3.30.4': + resolution: {integrity: sha512-sVJxoRnbfK/QC7IoUw/Ezzx9b87+cqFz5d5WZvN8O8yobDWuh7IS8ZgqZiPypTW5RuhnZI+ahvmSyO3WLm8q5Q==} peerDependencies: - '@tiptap/core': ^2.7.0 - '@tiptap/pm': ^2.7.0 + '@tiptap/core': 3.30.4 - '@tiptap/extension-image@2.27.2': - resolution: {integrity: sha512-5zL/BY41FIt72azVrCrv3n+2YJ/JyO8wxCcA4Dk1eXIobcgVyIdo4rG39gCqIOiqziAsqnqoj12QHTBtHsJ6mQ==} + '@tiptap/extension-horizontal-rule@3.30.4': + resolution: {integrity: sha512-RmvjVVkUf5pF70XvwI7Sb4vIUSDbLTLEcFl1l5X9vPcDgDT5G0SiUL6l8F49+qYc6wrMvnLcenApnAiiQ0Vbpw==} peerDependencies: - '@tiptap/core': ^2.7.0 + '@tiptap/core': 3.30.4 + '@tiptap/pm': 3.30.4 - '@tiptap/extension-italic@2.27.2': - resolution: {integrity: sha512-1OFsw2SZqfaqx5Fa5v90iNlPRcqyt+lVSjBwTDzuPxTPFY4Q0mL89mKgkq2gVHYNCiaRkXvFLDxaSvBWbmthgg==} + '@tiptap/extension-image@3.30.4': + resolution: {integrity: sha512-BwO+SJ+1ZWFLDFbebT80q0PlsbrnmWRExzQqurubM93M22SlADnQxNzS7AKfNmv/e3qKAAXXsoBOkx66BuFjaQ==} peerDependencies: - '@tiptap/core': ^2.7.0 + '@tiptap/core': 3.30.4 - '@tiptap/extension-link@2.27.2': - resolution: {integrity: sha512-bnP61qkr0Kj9Cgnop1hxn2zbOCBzNtmawxr92bVTOE31fJv6FhtCnQiD6tuPQVGMYhcmAj7eihtvuEMFfqEPcQ==} + '@tiptap/extension-italic@3.30.4': + resolution: {integrity: sha512-6cEjcyjPRcLEMB75BwiUc6S7yzkqc7VPXCeRgY26UqMg4AvcLrseY70+pO4sLv3n2DS5w8DBbMXZJ4rb1BhpUw==} peerDependencies: - '@tiptap/core': ^2.7.0 - '@tiptap/pm': ^2.7.0 + '@tiptap/core': 3.30.4 - '@tiptap/extension-list-item@2.27.2': - resolution: {integrity: sha512-eJNee7IEGXMnmygM5SdMGDC8m/lMWmwNGf9fPCK6xk0NxuQRgmZHL6uApKcdH6gyNcRPHCqvTTkhEP7pbny/fg==} + '@tiptap/extension-link@3.30.4': + resolution: {integrity: sha512-HPHaey3+nQZl+lsr/RvjoXSgSC67SAkNEF4qNELzzDwMUfI0UrZ3H/HhBe6XBeRnGli9gfuSpeRkh63ke5JpOw==} peerDependencies: - '@tiptap/core': ^2.7.0 + '@tiptap/core': 3.30.4 + '@tiptap/pm': 3.30.4 - '@tiptap/extension-ordered-list@2.27.2': - resolution: {integrity: sha512-M7A4tLGJcLPYdLC4CI2Gwl8LOrENQW59u3cMVa+KkwG1hzSJyPsbDpa1DI6oXPC2WtYiTf22zrbq3gVvH+KA2w==} + '@tiptap/extension-list-item@3.30.4': + resolution: {integrity: sha512-8E1ffdC7v3dwSrsqyxY3YP5uEQHTrwBDDmYF6o2YoHfzQ9nhXX5GmBz8fTxukjXUzSpuO76N/gwHIM8hBfdxMQ==} peerDependencies: - '@tiptap/core': ^2.7.0 + '@tiptap/extension-list': 3.30.4 - '@tiptap/extension-paragraph@2.27.2': - resolution: {integrity: sha512-elYVn2wHJJ+zB9LESENWOAfI4TNT0jqEN34sMA/hCtA4im1ZG2DdLHwkHIshj/c4H0dzQhmsS/YmNC5Vbqab/A==} + '@tiptap/extension-list-keymap@3.30.4': + resolution: {integrity: sha512-6RIzF3aThqIt4sia81K+6wA7H7bgPKjd3D66qLOGxdqdyfnAegk0OD5pUYhMZKhDCWGYKylyRVd2yIn/VNXqAg==} peerDependencies: - '@tiptap/core': ^2.7.0 + '@tiptap/extension-list': 3.30.4 - '@tiptap/extension-placeholder@2.27.2': - resolution: {integrity: sha512-IjsgSVYJRjpAKmIoapU0E2R4E2FPY3kpvU7/1i7PUYisylqejSJxmtJPGYw0FOMQY9oxnEEvfZHMBA610tqKpg==} + '@tiptap/extension-list@3.30.4': + resolution: {integrity: sha512-Usqez9DBRoG78tdLwPDcd1j1mBBU7mr5D2yrRP2JL/eXXkhAfdWqEFRYXwct5T4/o9JkGcW3aQf+gUvp12v0pw==} peerDependencies: - '@tiptap/core': ^2.7.0 - '@tiptap/pm': ^2.7.0 + '@tiptap/core': 3.30.4 + '@tiptap/pm': 3.30.4 - '@tiptap/extension-strike@2.27.2': - resolution: {integrity: sha512-HHIjhafLhS2lHgfAsCwC1okqMsQzR4/mkGDm4M583Yftyjri1TNA7lzhzXWRFWiiMfJxKtdjHjUAQaHuteRTZw==} + '@tiptap/extension-ordered-list@3.30.4': + resolution: {integrity: sha512-hInlH8I2UFGGULm9XLPtLWWFBECrYf/eNkloQb+udbF7ltLBL5JRCPcB3aM29qSSUQVxCCN8ICHdbwgpnTUAsw==} peerDependencies: - '@tiptap/core': ^2.7.0 + '@tiptap/extension-list': 3.30.4 - '@tiptap/extension-table-cell@2.27.2': - resolution: {integrity: sha512-9Lk46MjZMFzVZfOj9Kd7VgC6Odt6vmEhlCYVumErShUY7EkFqCw3b2IYoUtQkntfOEx/Afnhff/okNQwPsJeUA==} + '@tiptap/extension-paragraph@3.30.4': + resolution: {integrity: sha512-gM0WXvOP1tNcvpyRXTCtGhwVxye0VaFMCzDPjLrVAUtZMpo3cOrqDSrFl5tCurA59Qc2p5TUOR4g3/fKw8Yx9Q==} peerDependencies: - '@tiptap/core': ^2.7.0 + '@tiptap/core': 3.30.4 - '@tiptap/extension-table-header@2.27.2': - resolution: {integrity: sha512-ZEb6lbG0NbbodWLV0b4BS/QrDIPlUbCcuOsUxzqVvlMUY1Vg6Fj6fKwLaBcsIUDHi8sxZDBEgYEDw3BR/zcO6A==} + '@tiptap/extension-strike@3.30.4': + resolution: {integrity: sha512-iM3QhkEvNwDsxyNKTZM4wwqYhIKOjgXHTamPWnCICrPQ3aYFVdidfpDMePlHl6XL8aEAqPa1Xlj0aumFvSphOQ==} peerDependencies: - '@tiptap/core': ^2.7.0 + '@tiptap/core': 3.30.4 - '@tiptap/extension-table-row@2.27.2': - resolution: {integrity: sha512-Nw9+tA56Y5HtLVP01NGCZSUuTQhJPtfK9OfmDgGgcxynn2cRVdEtj+9FNZqRhQ1iRVaAI+Rd4xRvX9qYePMOxw==} + '@tiptap/extension-table@3.30.4': + resolution: {integrity: sha512-hH6E4y4QK8F2h4Eb/qiu8/tRXSQPbJn8pNOIQqcvA30luUnFWSpqHFDxO/a/XrzwF6F1l268WTekrn0PKogOzg==} peerDependencies: - '@tiptap/core': ^2.7.0 + '@tiptap/core': 3.30.4 + '@tiptap/pm': 3.30.4 - '@tiptap/extension-table@2.27.2': - resolution: {integrity: sha512-pDbhOpT5phZkcsyPjGBQlXv0+0hmdrvqHJ+dJjkGcCtlfy2pHiEIhmIItOFagc7wXy8G9iUFZ9Jie4zvDf+brg==} + '@tiptap/extension-text@3.30.4': + resolution: {integrity: sha512-bzgVlPhkVan+m6jycXkyq08fKCNyQff/cl/5U+/wQf8s3GlX+Le2/pTxbbC3ClfO1D8VLzLwcd2HJTYIoBOdAA==} peerDependencies: - '@tiptap/core': ^2.7.0 - '@tiptap/pm': ^2.7.0 + '@tiptap/core': 3.30.4 - '@tiptap/extension-text-style@2.27.2': - resolution: {integrity: sha512-Omk+uxjJLyEY69KStpCw5fA9asvV+MGcAX2HOxyISDFoLaL49TMrNjhGAuz09P1L1b0KGXo4ml7Q3v/Lfy4WPA==} + '@tiptap/extension-underline@3.30.4': + resolution: {integrity: sha512-h6nM3ykKswJLWvJVD1eiUFbanNmNj2SeV+2vuW666/xOy2WPyMnE2NZnsbvCKeK0wlUj7AE3l1m602mFwA4sDg==} peerDependencies: - '@tiptap/core': ^2.7.0 + '@tiptap/core': 3.30.4 - '@tiptap/extension-text@2.27.2': - resolution: {integrity: sha512-Xk7nYcigljAY0GO9hAQpZ65ZCxqOqaAlTPDFcKerXmlkQZP/8ndx95OgUb1Xf63kmPOh3xypurGS2is3v0MXSA==} + '@tiptap/extensions@3.30.4': + resolution: {integrity: sha512-WeBl/ggeNCOoOySX7647lwtSUHWbCh8I1Qqp8NQBsGyHXEE6/7jHbKcxpw4fplOgScgVMfPz8WZ+3yrfXYCUFw==} peerDependencies: - '@tiptap/core': ^2.7.0 + '@tiptap/core': 3.30.4 + '@tiptap/pm': 3.30.4 - '@tiptap/pm@2.27.2': - resolution: {integrity: sha512-kaEg7BfiJPDQMKbjVIzEPO3wlcA+pZb2tlcK9gPrdDnEFaec2QTF1sXz2ak2IIb2curvnIrQ4yrfHgLlVA72wA==} + '@tiptap/pm@3.30.4': + resolution: {integrity: sha512-oPbE+BOzzDKkxsvF9wepTWELvq385oifDkKIigqKCPKpGqplEIHIjNztCj/nOqHCfJBiU9LcoyyWH0qkHAQ9TQ==} - '@tiptap/react@2.27.2': - resolution: {integrity: sha512-0EAs8Cpkfbvben1PZ34JN2Nd79Dhioynm2jML27DBbf1VWPk+FFWFGTMLUT0bu+Np5iVxio8fqV9t0mc4D6thA==} + '@tiptap/react@3.30.4': + resolution: {integrity: sha512-NxGcKg4xBF6ngk6xORyzRCvG9zb7Z/cf59GpDBsiYpPpD/6m+J4kfNF0KVIOhRSAhNxm2u2ZPuGIWBtS/CDUBQ==} peerDependencies: - '@tiptap/core': ^2.7.0 - '@tiptap/pm': ^2.7.0 + '@tiptap/core': 3.30.4 + '@tiptap/pm': 3.30.4 + '@types/react': ^17.0.0 || ^18.0.0 || ^19.0.0 + '@types/react-dom': ^17.0.0 || ^18.0.0 || ^19.0.0 react: ^17.0.0 || ^18.0.0 || ^19.0.0 react-dom: ^17.0.0 || ^18.0.0 || ^19.0.0 - '@tiptap/starter-kit@2.27.2': - resolution: {integrity: sha512-bb0gJvPoDuyRUQ/iuN52j1//EtWWttw+RXAv1uJxfR0uKf8X7uAqzaOOgwjknoCIDC97+1YHwpGdnRjpDkOBxw==} + '@tiptap/starter-kit@3.30.4': + resolution: {integrity: sha512-rZiv2QOqfQU4/MNsAmvbymIwx0tKrGrtdJg76aEaej+aGU1QNDhZbUNutV8AnZxFjSJMm8rt810qzAU98OmCAg==} + + '@tiptap/y-tiptap@3.0.9': + resolution: {integrity: sha512-7/El8NQ8R5V5MkdrOUdfj9IgZacpt0H071xNimX7B0AnYiWiKefQnMKd41neQYzo2MOXbWdN3iZ+7Z7BruzOSA==} + engines: {node: '>=16.0.0', npm: '>=8.0.0'} + peerDependencies: + prosemirror-model: ^1.7.1 + prosemirror-state: ^1.2.3 + prosemirror-view: ^1.9.10 + y-protocols: ^1.0.1 + yjs: ^13.5.38 '@tybys/wasm-util@0.10.3': resolution: {integrity: sha512-F3fo1MYrRJYL3zER0OUOmkutjr1Vp23m7OsSgp7nq4SP6OqX6C/56XFIPAl5bt3zaBRjmW7SGz3u/6LwFpYcOg==} @@ -1256,15 +1251,6 @@ packages: '@types/estree@1.0.9': resolution: {integrity: sha512-GhdPgy1el4/ImP05X05Uw4cw2/M93BCUmnEvWZNStlCzEKME4Fkk+YpoA5OiHNQmoS7Cafb8Xa3Pya8m1Qrzeg==} - '@types/linkify-it@5.0.0': - resolution: {integrity: sha512-sVDA58zAw4eWAffKOaQH5/5j3XeayukzDk+ewSsnv3p4yJEZHCCzMDiZM8e0OUrRvmpGZ85jf4yDHkHsgBNr9Q==} - - '@types/markdown-it@14.1.2': - resolution: {integrity: sha512-promo4eFwuiW+TfGxhi+0x3czqTYJkG8qB17ZUJiVF10Xm7NLVRSLUsfRTU/6h1e24VvRnXCx+hG7li58lkzog==} - - '@types/mdurl@2.0.0': - resolution: {integrity: sha512-RGdgjQUZba5p6QEFAVx2OGb8rQDL/cPRG7GiedRzMcJ1tYnUANBncjbSB1NRGwbvjcPeikRABz2nshyPk1bhWg==} - '@types/mdx@2.0.14': resolution: {integrity: sha512-T48PeuJtvLosNTPVhfnIp3i/n3a4g4Bad7YCq5k64D4u7NwDrAotikQ+5+sjtUvBmxCMlbo3dVL+C2dP0rWHzg==} @@ -1433,9 +1419,6 @@ packages: argparse@1.0.10: resolution: {integrity: sha512-o5Roy6tNG4SL/FOkCAN6RzjiakZS25RLYFrcMttJqbdd8BWrnA+fGz57iN5Pb06pvBGvl5gQ0B48dJlslXvoTg==} - argparse@2.0.1: - resolution: {integrity: sha512-8+9WqebbFzpX9OR+Wa6O29asIogeRMzcGtAINdpMHHyAg10f05aSFVBbcEqGf/PXw1EjAZ+q2/bEBg3DvurK3Q==} - aria-query@5.3.0: resolution: {integrity: sha512-b0P0sZPKtyu8HkeRAfCq0IfURZK+SuwMjY1UXGBU27wpAiTwQAIlq56IbIO+ytk/JjS1fMR14ee5WBBfKi5J6A==} @@ -1521,9 +1504,6 @@ packages: convert-source-map@2.0.0: resolution: {integrity: sha512-Kvp459HrV2FEJ1CAsi1Ku+MY3kasH19TFykTz2xWmMeq6bk2NU3XXvfJ+Q61m0xktWwt+1HSYf3JZsTms3aRJg==} - crelt@1.0.7: - resolution: {integrity: sha512-aK6BbWfhf4U/wCcLHKPJl/xa6VkVstRaPywWtMKGwuOLc/wZTyQYuoxgvZnNsBvv7Kg3YTBQYYBCggcviQczuA==} - cross-spawn@7.0.6: resolution: {integrity: sha512-uV2QOWP2nWzsy2aMp8aRibhi9dlzF5Hgh5SHaB9OiTGEyDTiJJyx0uy51QXdyWbtAHNua4XJzUKca3OzKUd3vA==} engines: {node: '>= 8'} @@ -1615,10 +1595,6 @@ packages: resolution: {integrity: sha512-YGRs8knHhKHVShLkFET/rWAU8kmHbOV5LwN938RHI0pljAJ1Gf6SzXsSmRaEzcXTtOOmVqJ5+WtQPL5uigY50Q==} engines: {node: '>=14'} - entities@4.5.0: - resolution: {integrity: sha512-V0hjH4dGPh9Ao5p0MoRY6BVqtwCjhz6vI5LT8AJ55H+4g9/4vbHx1I54fS0XuclLhDHArPQCiMjDxjaL8fPxhw==} - engines: {node: '>=0.12'} - entities@6.0.1: resolution: {integrity: sha512-aN97NXWF6AWBTahfVOIrB/NShkzi5H7F9r1s9mD3cDj4Ko5f2qhhVoYMibXF7GlLveb/D2ioWay8lxI97Ven3g==} engines: {node: '>=0.12'} @@ -1655,10 +1631,6 @@ packages: resolution: {integrity: sha512-WUj2qlxaQtO4g6Pq5c29GTcWGDyd8itL8zTlipgECz3JesAiiOKotd8JU6otB3PACgG6xkJUyVhboMS+bje/jA==} engines: {node: '>=6'} - escape-string-regexp@4.0.0: - resolution: {integrity: sha512-TtpcNJ3XAzx3Gq8sWRzJaVajRs0uVxA2YAkdb1jm2YkPz4G6egUFAyA3n5vtEIZefPk5Wa4UXbKuS5fKkJWdgA==} - engines: {node: '>=10'} - esprima@4.0.1: resolution: {integrity: sha512-eGuFFw7Upda+g4p+QHvnW0RyTX/SVeJBDM/gCtMARO0cLuT2HcEKnTPvhjV6aGeqrCB/sbNop0Kszm0jsaWU4A==} engines: {node: '>=4'} @@ -1684,6 +1656,10 @@ packages: fast-deep-equal@3.1.3: resolution: {integrity: sha512-f3qQ9oQy9j2AhBe/H9VC91wLmKBCCU/gDOnKNAYG5hswO7BLKj09Hc5HYNz9cGI++xlpDCIgDaitVs03ATR84Q==} + fast-equals@5.4.1: + resolution: {integrity: sha512-DjlFSM5Pk9cGcL0q5QXl66eGzx0N6szNgaswwc5ZphlBohjTVJSnGgI+rJVOgOi65qUoQnDZN4nDqi33udtydQ==} + engines: {node: '>=6.0.0'} + fast-uri@3.1.5: resolution: {integrity: sha512-gHwA1O9LDIcKunMKhObS/HimwtehO1nPUECKAu5TpKgaO19fcWEl4bliWe1jWxVFvIXztJjjQ4L8XQ1EU9f7Jw==} @@ -1889,9 +1865,6 @@ packages: engines: {node: '>=16'} hasBin: true - linkify-it@5.0.2: - resolution: {integrity: sha512-ONTm2jCMAVZjgQa/Fy1kScXsuOoF5NPTsoFBdE1KVIZ2vAh/r9+Bqo+0jINCBYnavTPQZz38QzFTme79ENoN3Q==} - linkifyjs@4.3.3: resolution: {integrity: sha512-P8aEP5U/D1/IlTY2OeYsErdwh9bGuLE30NcXtKEjgdHcahveQoQwM2yZNsioQHsWFz0P7KKudisbrzCgR0sDHg==} @@ -1930,10 +1903,6 @@ packages: resolution: {integrity: sha512-hXdUTZYIVOt1Ex//jAQi+wTZZpUpwBj/0QsOzqegb3rGMMeJiSEu5xLHnYfBrRV4RH2+OCSOO95Is/7x1WJ4bw==} engines: {node: '>=10'} - markdown-it@14.3.0: - resolution: {integrity: sha512-RCEsPjR+sr0x+AuYp601tKTkgFG4YEPLCzHST3cQ/fhlJkqAkz1L2/Qbp1j9qw5SBwQHFBoW8+hoN5xssOF0Tw==} - hasBin: true - marked@15.0.12: resolution: {integrity: sha512-8dD6FusOQSrpv9Z1rdNMdlSgQOIP880DHqnohobOmYLElGEqAL/JvxvuxZO16r4HtjTlfPRDC1hbvxC9dPN2nA==} engines: {node: '>= 18'} @@ -1943,9 +1912,6 @@ packages: resolution: {integrity: sha512-/IXtbwEk5HTPyEwyKX6hGkYXxM9nbj64B+ilVJnC/R6B0pH5G4V3b0pVbL7DBj4tkhBAppbQUlf6F6Xl9LHu1g==} engines: {node: '>= 0.4'} - mdurl@2.0.0: - resolution: {integrity: sha512-Lf+9+2r+Tdp5wXDXC4PcIBjTDtq4UKjCPMQhKIuzpJNW0b96kVqSwW0bT7FhRSfmAiFYgP+SCRvdrDozfh0U5w==} - mime-db@1.52.0: resolution: {integrity: sha512-sPU4uV7dYlvtWJxwwxHD0PuihVNiE7TyAbQ5SWxDCB9mUYvOgroQOwYQQOKPJ8CIbE+1ETVlOoK1UC2nU3gYvg==} engines: {node: '>= 0.6'} @@ -2063,9 +2029,6 @@ packages: prosemirror-changeset@2.4.1: resolution: {integrity: sha512-96WBLhOaYhJ+kPhLg3uW359Tz6I/MfcrQfL4EGv4SrcqKEMC1gmoGrXHecPE8eOwTVCJ4IwgfzM8fFad25wNfw==} - prosemirror-collab@1.3.1: - resolution: {integrity: sha512-4SnynYR9TTYaQVXd/ieUvsVV4PDMBzrq2xPUWutHivDuOshZXqQ5rGbZM84HEaXKbLdItse7weMGOUdDVcLKEQ==} - prosemirror-commands@1.7.1: resolution: {integrity: sha512-rT7qZnQtx5c0/y/KlYaGvtG411S97UaL6gdp6RIZ23DLHanMYLyfGBV5DtSnZdthQql7W+lEVbpSfwtO8T+L2w==} @@ -2084,18 +2047,9 @@ packages: prosemirror-keymap@1.2.3: resolution: {integrity: sha512-4HucRlpiLd1IPQQXNqeo81BGtkY8Ai5smHhKW9jjPKRc2wQIxksg7Hl1tTI2IfT2B/LgX6bfYvXxEpJl7aKYKw==} - prosemirror-markdown@1.13.5: - resolution: {integrity: sha512-ac8trNQ01ybKDRTcfUc56LZufG3oYyU4N25qSXgp8dS0U4JtzzCj7oQlKu5v09VSmS5IseYoQ2yDkTbo7f7D8Q==} - - prosemirror-menu@1.3.2: - resolution: {integrity: sha512-6VgUJTYod0nMBlCaYJGhXGLu7Gt4AvcwcOq0YfJCY/6Uh+3S7UsWhpy6rJFCBFOmonq1hD8KyWOtZhkppd4YPg==} - prosemirror-model@1.25.11: resolution: {integrity: sha512-QWg9RhnpLlogAmp3p96uEFrE5txQpFynd4vhBAELkwgOCWQs/X0yCzB3/hrHqiPwf91RG5KyWq6553zs9JqIOQ==} - prosemirror-schema-basic@1.2.4: - resolution: {integrity: sha512-ELxP4TlX3yr2v5rM7Sb70SqStq5NvI15c0j9j/gjsrO5vaw+fnnpovCLEGIcpeGfifkuqJwl4fon6b+KdrODYQ==} - prosemirror-schema-list@1.5.1: resolution: {integrity: sha512-927lFx/uwyQaGwJxLWCZRkjXG0p48KpMj6ueoYiu4JX05GGuGcgzAy62dfiV8eFZftgyBUvLx76RsMe20fJl+Q==} @@ -2105,23 +2059,12 @@ packages: prosemirror-tables@1.8.5: resolution: {integrity: sha512-V/0cDCsHKHe/tfWkeCmthNUcEp1IVO3p6vwN8XtwE9PZQLAZJigbw3QoraAdfJPir4NKJtNvOB8oYGKRl+t0Dw==} - prosemirror-trailing-node@3.0.0: - resolution: {integrity: sha512-xiun5/3q0w5eRnGYfNlW1uU9W6x5MoFKWwq/0TIRgt09lv7Hcser2QYV8t4muXbEr+Fwo0geYn79Xs4GKywrRQ==} - peerDependencies: - prosemirror-model: ^1.22.1 - prosemirror-state: ^1.4.2 - prosemirror-view: ^1.33.8 - prosemirror-transform@1.12.0: resolution: {integrity: sha512-GxboyN4AMIsoHNtz5uf2r2Ru551i5hWeCMD6E2Ib4Eogqoub0NflniaBPVQ4MrGE5yZ8JV9tUHg9qcZTTrcN4w==} prosemirror-view@1.42.1: resolution: {integrity: sha512-rRqzZnRgkyh69XoOMrfFJHwauHscLBmHbq772kwbic1ymQAM8gXjzEbJse5j1ep2UO2HRIAQL0bY3kZ/RoqjVw==} - punycode.js@2.3.1: - resolution: {integrity: sha512-uxFIHU0YlHYhDQtV4R9J6a52SLx28BCjT+4ieh7IGbgwVJWO+km431c4yRlREUAsAmt/uMjQUyQHNEPf0M39CA==} - engines: {node: '>=6'} - punycode@2.3.1: resolution: {integrity: sha512-vYt7UD1U9Wg6138shLtLOvdAu+8DsC/ilFtEVHcH+wydcSpNE20AfSOduf6MkRFahL5FY7X1oU7nKVZFtfq8Fg==} engines: {node: '>=6'} @@ -2339,9 +2282,6 @@ packages: resolution: {integrity: sha512-azl+t0z7pw/z958Gy9svOTuzqIk6xq+NSheJzn5MMWtWTFywIacg2wUlzKFGtt3cthx0r2SxMK0yzJOR0IES7Q==} engines: {node: '>=14.0.0'} - tippy.js@6.3.7: - resolution: {integrity: sha512-E1d3oP2emgJ9dRQZdf3Kkn0qJgI6ZLpyS5z6ZkY1DF3kaQaBsGZsndEpHwx+eC+tYM41HaSNvNtLx8tU57FzTQ==} - tldts-core@6.1.86: resolution: {integrity: sha512-Je6p7pkk+KMzMv2XXKmAE3McmolOQFdxkKw0R8EYNr7sELW46JqnNeTX8ybPiQgvg1ymCoF8LXs5fzFaZvJPTA==} @@ -2380,9 +2320,6 @@ packages: engines: {node: '>=14.17'} hasBin: true - uc.micro@2.1.0: - resolution: {integrity: sha512-ARDJmphmdvUk6Glw7y9DQ2bFkKBHwQHLi2lsaH6PPmz/Ka9sFOBsBluozhDltWmnv9u/cF6Rt87znRTPV+yp/A==} - ufo@1.6.4: resolution: {integrity: sha512-JFNbkD1Svwe0KvGi8GOeLcP4kAWQ609twvCdcHxq1oSL8svv39ZuSvajcD8B+5D0eL4+s1Is2D/O6KN3qcTeRA==} @@ -2859,6 +2796,20 @@ snapshots: '@esbuild/win32-x64@0.25.12': optional: true + '@floating-ui/core@1.8.0': + dependencies: + '@floating-ui/utils': 0.2.12 + optional: true + + '@floating-ui/dom@1.8.0': + dependencies: + '@floating-ui/core': 1.8.0 + '@floating-ui/utils': 0.2.12 + optional: true + + '@floating-ui/utils@0.2.12': + optional: true + '@isaacs/cliui@8.0.2': dependencies: string-width: 5.1.2 @@ -3084,10 +3035,6 @@ snapshots: '@pkgjs/parseargs@0.11.0': optional: true - '@popperjs/core@2.11.8': {} - - '@remirror/core-constants@3.0.0': {} - '@rolldown/pluginutils@1.0.0-beta.27': {} '@rollup/pluginutils@5.4.0(rollup@4.62.2)': @@ -3341,206 +3288,209 @@ snapshots: dependencies: '@testing-library/dom': 10.4.1 - '@tiptap/core@2.27.2(@tiptap/pm@2.27.2)': - dependencies: - '@tiptap/pm': 2.27.2 - - '@tiptap/core@3.30.4(@tiptap/pm@2.27.2)': - dependencies: - '@tiptap/pm': 2.27.2 - - '@tiptap/extension-blockquote@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/core@3.30.4(@tiptap/pm@3.30.4)': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/pm': 3.30.4 - '@tiptap/extension-bold@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extension-blockquote@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) + '@tiptap/pm': 3.30.4 - '@tiptap/extension-bubble-menu@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': + '@tiptap/extension-bold@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) - '@tiptap/pm': 2.27.2 - tippy.js: 6.3.7 + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) - '@tiptap/extension-bullet-list@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extension-bubble-menu@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@floating-ui/dom': 1.8.0 + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) + '@tiptap/pm': 3.30.4 + optional: true - '@tiptap/extension-code-block@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': + '@tiptap/extension-bullet-list@3.30.4(@tiptap/extension-list@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) - '@tiptap/pm': 2.27.2 + '@tiptap/extension-list': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) - '@tiptap/extension-code@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extension-code-block@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) + '@tiptap/pm': 3.30.4 - '@tiptap/extension-collaboration-cursor@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(y-prosemirror@1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31))': + '@tiptap/extension-code@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) - y-prosemirror: 1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31) + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) - '@tiptap/extension-collaboration@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)(y-prosemirror@1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31))': + '@tiptap/extension-collaboration-caret@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)(@tiptap/y-tiptap@3.0.9(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31))': dependencies: - '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) - '@tiptap/pm': 2.27.2 - y-prosemirror: 1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31) + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) + '@tiptap/pm': 3.30.4 + '@tiptap/y-tiptap': 3.0.9(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31) - '@tiptap/extension-document@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extension-collaboration@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)(@tiptap/y-tiptap@3.0.9(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31))(yjs@13.6.31)': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) + '@tiptap/pm': 3.30.4 + '@tiptap/y-tiptap': 3.0.9(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31) + yjs: 13.6.31 - '@tiptap/extension-dropcursor@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': + '@tiptap/extension-document@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) - '@tiptap/pm': 2.27.2 + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) - '@tiptap/extension-floating-menu@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': + '@tiptap/extension-dropcursor@3.30.4(@tiptap/extensions@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) - '@tiptap/pm': 2.27.2 - tippy.js: 6.3.7 + '@tiptap/extensions': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) - '@tiptap/extension-gapcursor@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': + '@tiptap/extension-floating-menu@3.30.4(@floating-ui/dom@1.8.0)(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) - '@tiptap/pm': 2.27.2 + '@floating-ui/dom': 1.8.0 + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) + '@tiptap/pm': 3.30.4 + optional: true - '@tiptap/extension-hard-break@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extension-gapcursor@3.30.4(@tiptap/extensions@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/extensions': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) - '@tiptap/extension-heading@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extension-hard-break@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) - '@tiptap/extension-history@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': + '@tiptap/extension-heading@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) - '@tiptap/pm': 2.27.2 + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) - '@tiptap/extension-horizontal-rule@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': + '@tiptap/extension-horizontal-rule@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) - '@tiptap/pm': 2.27.2 + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) + '@tiptap/pm': 3.30.4 - '@tiptap/extension-image@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))': + '@tiptap/extension-image@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) - '@tiptap/extension-italic@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extension-italic@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) - '@tiptap/extension-link@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': + '@tiptap/extension-link@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)': dependencies: - '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) - '@tiptap/pm': 2.27.2 + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) + '@tiptap/pm': 3.30.4 linkifyjs: 4.3.3 - '@tiptap/extension-list-item@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extension-list-item@3.30.4(@tiptap/extension-list@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/extension-list': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) - '@tiptap/extension-ordered-list@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extension-list-keymap@3.30.4(@tiptap/extension-list@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/extension-list': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) - '@tiptap/extension-paragraph@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extension-list@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) - - '@tiptap/extension-placeholder@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': - dependencies: - '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) - '@tiptap/pm': 2.27.2 + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) + '@tiptap/pm': 3.30.4 - '@tiptap/extension-strike@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extension-ordered-list@3.30.4(@tiptap/extension-list@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/extension-list': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) - '@tiptap/extension-table-cell@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))': + '@tiptap/extension-paragraph@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) - '@tiptap/extension-table-header@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))': + '@tiptap/extension-strike@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) - '@tiptap/extension-table-row@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))': + '@tiptap/extension-table@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)': dependencies: - '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) + '@tiptap/pm': 3.30.4 - '@tiptap/extension-table@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)': + '@tiptap/extension-text@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) - '@tiptap/pm': 2.27.2 + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) - '@tiptap/extension-text-style@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extension-underline@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) - '@tiptap/extension-text@2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))': + '@tiptap/extensions@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)': dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) + '@tiptap/pm': 3.30.4 - '@tiptap/pm@2.27.2': + '@tiptap/pm@3.30.4': dependencies: prosemirror-changeset: 2.4.1 - prosemirror-collab: 1.3.1 prosemirror-commands: 1.7.1 prosemirror-dropcursor: 1.8.3 prosemirror-gapcursor: 1.4.1 prosemirror-history: 1.5.0 prosemirror-inputrules: 1.5.1 prosemirror-keymap: 1.2.3 - prosemirror-markdown: 1.13.5 - prosemirror-menu: 1.3.2 prosemirror-model: 1.25.11 - prosemirror-schema-basic: 1.2.4 prosemirror-schema-list: 1.5.1 prosemirror-state: 1.4.4 prosemirror-tables: 1.8.5 - prosemirror-trailing-node: 3.0.0(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1) prosemirror-transform: 1.12.0 prosemirror-view: 1.42.1 - '@tiptap/react@2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2)(react-dom@18.3.1(react@18.3.1))(react@18.3.1)': + '@tiptap/react@3.30.4(@floating-ui/dom@1.8.0)(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)(@types/react-dom@18.3.7(@types/react@18.3.31))(@types/react@18.3.31)(react-dom@18.3.1(react@18.3.1))(react@18.3.1)': dependencies: - '@tiptap/core': 3.30.4(@tiptap/pm@2.27.2) - '@tiptap/extension-bubble-menu': 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) - '@tiptap/extension-floating-menu': 2.27.2(@tiptap/core@3.30.4(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) - '@tiptap/pm': 2.27.2 + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) + '@tiptap/pm': 3.30.4 + '@types/react': 18.3.31 + '@types/react-dom': 18.3.7(@types/react@18.3.31) '@types/use-sync-external-store': 0.0.6 - fast-deep-equal: 3.1.3 + fast-equals: 5.4.1 react: 18.3.1 react-dom: 18.3.1(react@18.3.1) use-sync-external-store: 1.6.0(react@18.3.1) + optionalDependencies: + '@tiptap/extension-bubble-menu': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) + '@tiptap/extension-floating-menu': 3.30.4(@floating-ui/dom@1.8.0)(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) + transitivePeerDependencies: + - '@floating-ui/dom' + + '@tiptap/starter-kit@3.30.4': + dependencies: + '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) + '@tiptap/extension-blockquote': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) + '@tiptap/extension-bold': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4)) + '@tiptap/extension-bullet-list': 3.30.4(@tiptap/extension-list@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)) + '@tiptap/extension-code': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4)) + '@tiptap/extension-code-block': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) + '@tiptap/extension-document': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4)) + '@tiptap/extension-dropcursor': 3.30.4(@tiptap/extensions@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)) + '@tiptap/extension-gapcursor': 3.30.4(@tiptap/extensions@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)) + '@tiptap/extension-hard-break': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4)) + '@tiptap/extension-heading': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4)) + '@tiptap/extension-horizontal-rule': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) + '@tiptap/extension-italic': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4)) + '@tiptap/extension-link': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) + '@tiptap/extension-list': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) + '@tiptap/extension-list-item': 3.30.4(@tiptap/extension-list@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)) + '@tiptap/extension-list-keymap': 3.30.4(@tiptap/extension-list@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)) + '@tiptap/extension-ordered-list': 3.30.4(@tiptap/extension-list@3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)) + '@tiptap/extension-paragraph': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4)) + '@tiptap/extension-strike': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4)) + '@tiptap/extension-text': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4)) + '@tiptap/extension-underline': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4)) + '@tiptap/extensions': 3.30.4(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4) + '@tiptap/pm': 3.30.4 - '@tiptap/starter-kit@2.27.2': - dependencies: - '@tiptap/core': 2.27.2(@tiptap/pm@2.27.2) - '@tiptap/extension-blockquote': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) - '@tiptap/extension-bold': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) - '@tiptap/extension-bullet-list': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) - '@tiptap/extension-code': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) - '@tiptap/extension-code-block': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) - '@tiptap/extension-document': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) - '@tiptap/extension-dropcursor': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) - '@tiptap/extension-gapcursor': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) - '@tiptap/extension-hard-break': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) - '@tiptap/extension-heading': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) - '@tiptap/extension-history': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) - '@tiptap/extension-horizontal-rule': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2))(@tiptap/pm@2.27.2) - '@tiptap/extension-italic': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) - '@tiptap/extension-list-item': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) - '@tiptap/extension-ordered-list': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) - '@tiptap/extension-paragraph': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) - '@tiptap/extension-strike': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) - '@tiptap/extension-text': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) - '@tiptap/extension-text-style': 2.27.2(@tiptap/core@2.27.2(@tiptap/pm@2.27.2)) - '@tiptap/pm': 2.27.2 + '@tiptap/y-tiptap@3.0.9(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31)': + dependencies: + lib0: 0.2.117 + prosemirror-model: 1.25.11 + prosemirror-state: 1.4.4 + prosemirror-view: 1.42.1 + y-protocols: 1.0.7(yjs@13.6.31) + yjs: 13.6.31 '@tybys/wasm-util@0.10.3': dependencies: @@ -3583,15 +3533,6 @@ snapshots: '@types/estree@1.0.9': {} - '@types/linkify-it@5.0.0': {} - - '@types/markdown-it@14.1.2': - dependencies: - '@types/linkify-it': 5.0.0 - '@types/mdurl': 2.0.0 - - '@types/mdurl@2.0.0': {} - '@types/mdx@2.0.14': {} '@types/node@22.20.1': @@ -3794,8 +3735,6 @@ snapshots: dependencies: sprintf-js: 1.0.3 - argparse@2.0.1: {} - aria-query@5.3.0: dependencies: dequal: 2.0.3 @@ -3873,8 +3812,6 @@ snapshots: convert-source-map@2.0.0: {} - crelt@1.0.7: {} - cross-spawn@7.0.6: dependencies: path-key: 3.1.1 @@ -3944,8 +3881,6 @@ snapshots: empathic@2.0.1: {} - entities@4.5.0: {} - entities@6.0.1: {} entities@7.0.1: {} @@ -3998,8 +3933,6 @@ snapshots: escalade@3.2.0: {} - escape-string-regexp@4.0.0: {} - esprima@4.0.1: {} estree-walker@2.0.2: {} @@ -4016,6 +3949,8 @@ snapshots: fast-deep-equal@3.1.3: {} + fast-equals@5.4.1: {} + fast-uri@3.1.5: {} fdir@6.5.0(picomatch@4.0.5): @@ -4232,10 +4167,6 @@ snapshots: dependencies: isomorphic.js: 0.2.5 - linkify-it@5.0.2: - dependencies: - uc.micro: 2.1.0 - linkifyjs@4.3.3: {} local-pkg@1.2.1: @@ -4274,21 +4205,10 @@ snapshots: dependencies: semver: 7.8.5 - markdown-it@14.3.0: - dependencies: - argparse: 2.0.1 - entities: 4.5.0 - linkify-it: 5.0.2 - mdurl: 2.0.0 - punycode.js: 2.3.1 - uc.micro: 2.1.0 - marked@15.0.12: {} math-intrinsics@1.1.0: {} - mdurl@2.0.0: {} - mime-db@1.52.0: {} mime-types@2.1.35: @@ -4440,10 +4360,6 @@ snapshots: dependencies: prosemirror-transform: 1.12.0 - prosemirror-collab@1.3.1: - dependencies: - prosemirror-state: 1.4.4 - prosemirror-commands@1.7.1: dependencies: prosemirror-model: 1.25.11 @@ -4480,27 +4396,10 @@ snapshots: prosemirror-state: 1.4.4 w3c-keyname: 2.2.8 - prosemirror-markdown@1.13.5: - dependencies: - '@types/markdown-it': 14.1.2 - markdown-it: 14.3.0 - prosemirror-model: 1.25.11 - - prosemirror-menu@1.3.2: - dependencies: - crelt: 1.0.7 - prosemirror-commands: 1.7.1 - prosemirror-history: 1.5.0 - prosemirror-state: 1.4.4 - prosemirror-model@1.25.11: dependencies: orderedmap: 2.1.1 - prosemirror-schema-basic@1.2.4: - dependencies: - prosemirror-model: 1.25.11 - prosemirror-schema-list@1.5.1: dependencies: prosemirror-model: 1.25.11 @@ -4521,14 +4420,6 @@ snapshots: prosemirror-transform: 1.12.0 prosemirror-view: 1.42.1 - prosemirror-trailing-node@3.0.0(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1): - dependencies: - '@remirror/core-constants': 3.0.0 - escape-string-regexp: 4.0.0 - prosemirror-model: 1.25.11 - prosemirror-state: 1.4.4 - prosemirror-view: 1.42.1 - prosemirror-transform@1.12.0: dependencies: prosemirror-model: 1.25.11 @@ -4539,8 +4430,6 @@ snapshots: prosemirror-state: 1.4.4 prosemirror-transform: 1.12.0 - punycode.js@2.3.1: {} - punycode@2.3.1: {} quansync@0.2.11: {} @@ -4770,10 +4659,6 @@ snapshots: tinyspy@4.0.4: {} - tippy.js@6.3.7: - dependencies: - '@popperjs/core': 2.11.8 - tldts-core@6.1.86: {} tldts@6.1.86: @@ -4806,8 +4691,6 @@ snapshots: typescript@5.9.3: {} - uc.micro@2.1.0: {} - ufo@1.6.4: {} undici-types@6.21.0: {} diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index 37053afea..4606cd4a9 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -31,6 +31,8 @@ trustPolicyIgnoreAfter: 43200 # cannot take 5.x, so lift minimatch to ^10 (glob@10 / test-exclude@7 resolve # cleanly) and pin brace-expansion to the patched 5.x line. overrides: + '@tiptap/extension-bubble-menu': 3.30.4 + '@tiptap/extension-floating-menu': 3.30.4 vite: ^6.4.3 esbuild: ^0.25.0 fast-uri: ^3.1.5 diff --git a/src/collaboration/CollaborativeCwlEditor.tsx b/src/collaboration/CollaborativeCwlEditor.tsx index eea89b6c5..c8aeb23ab 100644 --- a/src/collaboration/CollaborativeCwlEditor.tsx +++ b/src/collaboration/CollaborativeCwlEditor.tsx @@ -1,5 +1,5 @@ import Collaboration from '@tiptap/extension-collaboration'; -import CollaborationCursor from '@tiptap/extension-collaboration-cursor'; +import CollaborationCaret from '@tiptap/extension-collaboration-caret'; import { type Editor, useEditor } from '@tiptap/react'; import { forwardRef, @@ -198,7 +198,7 @@ export const CollaborativeCwlEditor = forwardRef< }), ...(scopedProvider && cursorUser ? [ - CollaborationCursor.configure({ + CollaborationCaret.configure({ provider: scopedProvider, user: cursorUser, render: renderCollaborationCursor, diff --git a/src/components/CwlEditor.tsx b/src/components/CwlEditor.tsx index 598ac948a..240f87423 100644 --- a/src/components/CwlEditor.tsx +++ b/src/components/CwlEditor.tsx @@ -213,7 +213,7 @@ export const CwlEditor = forwardRef( if (current !== value) { /* v8 ignore next -- isControlled guarantees value is defined. */ const next = editorValueToHtml(value ?? '', mode); - editor.commands.setContent(next, false); + editor.commands.setContent(next, { emitUpdate: false }); } }, [editor, isControlled, value, mode]); diff --git a/src/components/EditorFormField.tsx b/src/components/EditorFormField.tsx index a8f9282ce..2e7481e71 100644 --- a/src/components/EditorFormField.tsx +++ b/src/components/EditorFormField.tsx @@ -23,7 +23,7 @@ export interface EditorFormFieldProps { * * Named fields subscribe only to document-changing transactions, avoiding a * full Markdown/HTML serialization on cursor movement while still observing - * programmatic `setContent(..., false)` calls that intentionally suppress the + * programmatic `setContent(..., { emitUpdate: false })` calls that suppress the * higher-level TipTap update event. The field's native value is written * synchronously before returning from each document transaction, so immediate * `FormData` construction or browser submission cannot observe a React-batched diff --git a/src/components/editorFormReset.test.ts b/src/components/editorFormReset.test.ts index c160cb9d7..11f9332cf 100644 --- a/src/components/editorFormReset.test.ts +++ b/src/components/editorFormReset.test.ts @@ -31,7 +31,9 @@ describe('editor form reset application', () => { onFormReset, }); - expect(setContent).toHaveBeenCalledWith('

Reset baseline

', false); + expect(setContent).toHaveBeenCalledWith('

Reset baseline

', { + emitUpdate: false, + }); expect(onChange).toHaveBeenCalledWith('

Reset baseline

'); expect(onFormReset).toHaveBeenCalledWith({ editor, event }); }); @@ -66,6 +68,8 @@ describe('editor form reset application', () => { event: new Event('reset'), }), ).not.toThrow(); - expect(setContent).toHaveBeenCalledWith('

Reset baseline

', false); + expect(setContent).toHaveBeenCalledWith('

Reset baseline

', { + emitUpdate: false, + }); }); }); diff --git a/src/components/editorFormReset.ts b/src/components/editorFormReset.ts index f424786af..3e7ed292c 100644 --- a/src/components/editorFormReset.ts +++ b/src/components/editorFormReset.ts @@ -37,7 +37,9 @@ export function applyEditorFormReset({ onFormReset, }: ApplyEditorFormResetOptions): void { if (resetValue !== undefined) { - editor.commands.setContent(editorValueToHtml(resetValue, mode), false); + editor.commands.setContent(editorValueToHtml(resetValue, mode), { + emitUpdate: false, + }); onChange?.(editorHtmlToValue(editor.getHTML(), mode)); } onFormReset?.({ editor, event }); diff --git a/src/components/useEditorHandle.ts b/src/components/useEditorHandle.ts index 710fe883f..b47fb036e 100644 --- a/src/components/useEditorHandle.ts +++ b/src/components/useEditorHandle.ts @@ -132,7 +132,7 @@ export function useEditorHandle( if (!editor) return; editor.commands.setContent( editorValueToHtml(next, modeRef.current), - false, + { emitUpdate: false }, ); }, validateDocumentEnvelope: (source, limits) => @@ -182,7 +182,7 @@ export function useEditorHandle( setDocumentJson: (documentJson) => { if (!editor) return; const documentNode = parseDocumentJsonForEditor(editor, documentJson); - editor.commands.setContent(documentNode, false); + editor.commands.setContent(documentNode, { emitUpdate: false }); }, insertValue: (next: string) => { if (!editor) return; diff --git a/src/documentEnvelopeIfMatch.evidence.test.tsx b/src/documentEnvelopeIfMatch.evidence.test.tsx index fcecfe170..8ba5b3c7f 100644 --- a/src/documentEnvelopeIfMatch.evidence.test.tsx +++ b/src/documentEnvelopeIfMatch.evidence.test.tsx @@ -228,7 +228,7 @@ describe('atomic revision-envelope conflict evidence', () => { sourceTrapInvoked = true; editor.commands.setContent( '

Newer document from source preparation

', - false, + { emitUpdate: false }, ); } return Reflect.ownKeys(target); @@ -301,7 +301,9 @@ describe('atomic revision-envelope conflict evidence', () => { ); await nextDigestStarted; act(() => { - editor.commands.setContent('

Newer local document

', false); + editor.commands.setContent('

Newer local document

', { + emitUpdate: false, + }); }); releaseNextDigest(); diff --git a/src/documentEnvelopeIfMatch.reentrancy.test.tsx b/src/documentEnvelopeIfMatch.reentrancy.test.tsx index d994b014b..48ac4fd2b 100644 --- a/src/documentEnvelopeIfMatch.reentrancy.test.tsx +++ b/src/documentEnvelopeIfMatch.reentrancy.test.tsx @@ -59,7 +59,9 @@ describe('revision-guarded restore reentrancy', () => { getPrototypeOf(target) { if (!changed) { changed = true; - editor.commands.setContent('

Reentrant newer document

', false); + editor.commands.setContent('

Reentrant newer document

', { + emitUpdate: false, + }); } return Reflect.getPrototypeOf(target); }, diff --git a/src/documentEnvelopeIfMatch.test.tsx b/src/documentEnvelopeIfMatch.test.tsx index 4b94574a1..ba2ef1d79 100644 --- a/src/documentEnvelopeIfMatch.test.tsx +++ b/src/documentEnvelopeIfMatch.test.tsx @@ -218,7 +218,9 @@ describe('revision-guarded document-envelope restore', () => { deferred.provider, ); await act(async () => { - editor.commands.setContent('

Newer local document

', false); + editor.commands.setContent('

Newer local document

', { + emitUpdate: false, + }); }); deferred.resolve(); diff --git a/src/documentEnvelopeRestore.ts b/src/documentEnvelopeRestore.ts index 4546eb1c8..c265e0765 100644 --- a/src/documentEnvelopeRestore.ts +++ b/src/documentEnvelopeRestore.ts @@ -113,7 +113,7 @@ export function applyPreparedDocumentEnvelope( editor: Editor, prepared: PreparedDocumentEnvelope, ): CwlEditorDocumentEnvelope { - editor.commands.setContent(prepared.documentNode, false); + editor.commands.setContent(prepared.documentNode, { emitUpdate: false }); if (!editor.state.doc.eq(prepared.documentNode)) { throw new DocumentEnvelopeRestoreError(); } diff --git a/src/extensions/SafeClipboardExtension.test.ts b/src/extensions/SafeClipboardExtension.test.ts index 6932326a1..4558341a7 100644 --- a/src/extensions/SafeClipboardExtension.test.ts +++ b/src/extensions/SafeClipboardExtension.test.ts @@ -30,7 +30,7 @@ function transformFromExtension( return transform.call(plugin, html, {} as never); } -describe('SafeClipboard TipTap v2 adapter', () => { +describe('SafeClipboard TipTap v3 adapter', () => { it('runs last in the real ProseMirror transform chain', () => { const competingTransform = Extension.create({ name: 'competingPasteTransform', diff --git a/src/extensions/SafeClipboardExtension.ts b/src/extensions/SafeClipboardExtension.ts index 4778313ad..6a914b9e9 100644 --- a/src/extensions/SafeClipboardExtension.ts +++ b/src/extensions/SafeClipboardExtension.ts @@ -1,5 +1,5 @@ /** - * TipTap v2 adapter that installs Inkspan's SafeClipboard policy in the actual + * TipTap v3 adapter that installs Inkspan's SafeClipboard policy in the actual * ProseMirror HTML-paste transform chain used before clipboard parsing. */ import { Extension } from '@tiptap/core'; @@ -18,7 +18,7 @@ const SAFE_CLIPBOARD_PRIORITY = -1_000_000; /** ProseMirror plugin key for the rich-clipboard pre-parse safety boundary. */ export const safeClipboardPluginKey = new PluginKey('cwlSafeClipboard'); -/** Options held by the TipTap v2 SafeClipboard extension adapter. */ +/** Options held by the TipTap v3 SafeClipboard extension adapter. */ export interface SafeClipboardOptions { /** Maximum UTF-8 bytes accepted when no nested config object is supplied. */ maxHtmlBytes: number; @@ -69,11 +69,11 @@ function transformPastedClipboardHtml( } /** - * Shared TipTap v2 extension that sanitizes rich HTML in ProseMirror's real + * Shared TipTap v3 extension that sanitizes rich HTML in ProseMirror's real * `transformPastedHTML` pipeline before the browser fragment is parsed. * * The deliberately low priority places this plugin after ordinary host - * transforms in TipTap v2's plugin order, making sanitization the final + * transforms in TipTap v3's plugin order, making sanitization the final * supported HTML transform before ProseMirror parsing. */ export const SafeClipboard = Extension.create({ diff --git a/src/extensions/kit.ts b/src/extensions/kit.ts index 71554bc28..8efbbf32a 100644 --- a/src/extensions/kit.ts +++ b/src/extensions/kit.ts @@ -3,11 +3,8 @@ * Kept separate from React so hosts may reuse it in headless workflows. */ import StarterKit from '@tiptap/starter-kit'; -import Placeholder from '@tiptap/extension-placeholder'; -import Table from '@tiptap/extension-table'; -import TableRow from '@tiptap/extension-table-row'; -import TableHeader from '@tiptap/extension-table-header'; -import TableCell from '@tiptap/extension-table-cell'; +import { Placeholder } from '@tiptap/extensions'; +import { Table, TableRow, TableHeader, TableCell } from '@tiptap/extension-table'; import type { Extensions } from '@tiptap/react'; import { Base64Image } from './Base64Image.js'; import type { @@ -43,12 +40,16 @@ export function buildExtensions( ): Extensions { const image = options.image ?? {}; const historyConfiguration = options.disableHistory - ? { history: false as const } + ? { undoRedo: false as const } : {}; return [ StarterKit.configure({ heading: { levels: [1, 2, 3, 4, 5, 6] }, + link: false, + listKeymap: false, + underline: false, + trailingNode: false, codeBlock: { HTMLAttributes: { class: 'cwl-code-block' }, }, diff --git a/src/index.ts b/src/index.ts index ca2fabe4b..ff676baad 100644 --- a/src/index.ts +++ b/src/index.ts @@ -1,7 +1,7 @@ /** * @contextualwisdomlab/cwl-editor * - * Commercial-grade Markdown + HTML WYSIWYG editor built on TipTap v2 + * Commercial-grade Markdown + HTML WYSIWYG editor built on TipTap v3 * (ProseMirror, MIT), with inline base64 images and a standalone base64 * converter. * diff --git a/src/tiptapV2ClipboardAdapterDocumentation.test.ts b/src/tiptapV2ClipboardAdapterDocumentation.test.ts index aff38963a..07068e716 100644 --- a/src/tiptapV2ClipboardAdapterDocumentation.test.ts +++ b/src/tiptapV2ClipboardAdapterDocumentation.test.ts @@ -12,7 +12,7 @@ function readRepositoryText(path: string): string { return readFileSync(path, 'utf8'); } -describe('TipTap v2 SafeClipboard adapter doctoring', () => { +describe('TipTap SafeClipboard adapter doctoring', () => { it('records the locked-version root cause and actual ProseMirror registration path', () => { const doctoring = readRepositoryText(doctoringPath); const adapter = readRepositoryText(adapterPath); @@ -21,8 +21,8 @@ describe('TipTap v2 SafeClipboard adapter doctoring', () => { const changelog = readRepositoryText(changelogPath); expect(lock).toContain("'@tiptap/core':"); - expect(lock).toContain('version: 2.27.2'); - expect(doctoring).toContain('@tiptap/core 2.27.2'); + expect(lock).toContain('specifier: 3.30.4'); + expect(doctoring).toContain('TipTap 3.30.4 package family'); expect(doctoring).toContain('addProseMirrorPlugins'); expect(doctoring).toContain('transformPastedHTML'); expect(doctoring).toContain('before ProseMirror parses'); diff --git a/tests/browser/harness.ts b/tests/browser/harness.ts index c00b47a7d..c4ca1059f 100644 --- a/tests/browser/harness.ts +++ b/tests/browser/harness.ts @@ -59,7 +59,7 @@ window.runInkspanClipboardProbe = ( return Object.freeze({ sanitizedHtml, documentJson: null, errorCode }); } - editor.commands.setContent(sanitizedHtml, false); + editor.commands.setContent(sanitizedHtml, { emitUpdate: false }); return Object.freeze({ sanitizedHtml, documentJson: editor.getJSON(), From 87b5fefcb9eaf8a8a7516f7be973254ee3e9b395 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 22:20:19 +0900 Subject: [PATCH 04/18] docs: record the editor security migration Signed-off-by: Seongho Bae --- CHANGELOG.md | 1 + 1 file changed, 1 insertion(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index d581422dc..3cc73ea23 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -14,6 +14,7 @@ Historical release entries from **0.1.0 through 0.5.27** are preserved verbatim - Restored a visible `:focus-visible` indicator on the editable textbox, mapped it to `CanvasText` in forced-colors mode, and suppresses that interactive focus chrome under `@media print`; dependency-locked Chromium, Firefox, and WebKit acceptance exercises the packed stylesheet on the real `role="textbox"` surface. ### Security +- Patched an editor dependency vulnerability while preserving the existing formatting, collaboration-presence, safe-link, and exact document-restore behavior. - Raised workspace-wide transitive development-tool overrides for `fast-uri`, `nanoid`, and `postcss` to patched minimums, keeping the lockfile audit clean without changing runtime package authority. - Normalized isolated package-verifier temporary roots before containment checks on macOS. From 870c2c3efffced3ce8d280b4487e4eda055c1ff1 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 23:24:05 +0900 Subject: [PATCH 05/18] fix(ci): preserve Python boundary coverage Signed-off-by: Seongho Bae --- .github/workflows/ci.yml | 2 +- office/tests/test_python_support_contract.py | 14 ++++++++++---- src/workflowExactHead.test.ts | 2 +- 3 files changed, 12 insertions(+), 6 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 9f7614e53..03a505671 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -90,7 +90,7 @@ jobs: strategy: fail-fast: false matrix: - python-version: ${{ github.event_name == 'pull_request' && fromJSON('["3.14"]') || fromJSON('["3.11", "3.12", "3.13", "3.14"]') }} + python-version: ${{ github.event_name == 'pull_request' && fromJSON('["3.11", "3.14"]') || fromJSON('["3.11", "3.12", "3.13", "3.14"]') }} defaults: run: working-directory: office diff --git a/office/tests/test_python_support_contract.py b/office/tests/test_python_support_contract.py index 7104fd661..9c9d2288b 100644 --- a/office/tests/test_python_support_contract.py +++ b/office/tests/test_python_support_contract.py @@ -1,12 +1,14 @@ """Cross-file contract for the Python versions advertised by Inkspan Office.""" from pathlib import Path +import json import re import tomllib REPOSITORY_ROOT = Path(__file__).resolve().parents[2] SUPPORTED_PYTHON_VERSIONS = ("3.11", "3.12", "3.13", "3.14") +PULL_REQUEST_PYTHON_VERSIONS = ("3.11", "3.14") PYTHON_312_LXML_LINUX_SHA256 = ( "bc783ee3147e60a25aa0445ea82b3e8aabb83b240f2b95d32cb75587ff781814" ) @@ -33,7 +35,7 @@ def _workflow_job_block(workflow: str, job_name: str) -> str: def test_python_support_range_matches_classifiers_and_ci_matrix() -> None: - """Require package metadata and the Office CI job to cover the same minors.""" + """Require PR boundary coverage and full protected-main compatibility coverage.""" pyproject = tomllib.loads(_repository_text("office/pyproject.toml")) project = pyproject["project"] @@ -50,10 +52,14 @@ def test_python_support_range_matches_classifiers_and_ci_matrix() -> None: office_job = _workflow_job_block(workflow, "office") assert "runs-on: ubuntu-24.04" in office_job assert "runs-on: ubuntu-latest" not in office_job - matrix_match = re.search(r'python-version:\s*\[([^\]]+)\]', office_job) + matrix_match = re.search( + r"python-version:\s*\$\{\{\s*github\.event_name == 'pull_request'\s*" + r"&&\s*fromJSON\('([^']+)'\)\s*\|\|\s*fromJSON\('([^']+)'\)\s*\}\}", + office_job, + ) assert matrix_match is not None - matrix_versions = tuple(re.findall(r'"(3\.\d+)"', matrix_match.group(1))) - assert matrix_versions == SUPPORTED_PYTHON_VERSIONS + assert tuple(json.loads(matrix_match.group(1))) == PULL_REQUEST_PYTHON_VERSIONS + assert tuple(json.loads(matrix_match.group(2))) == SUPPORTED_PYTHON_VERSIONS def test_python_support_documentation_matches_the_fixed_ci_environment() -> None: diff --git a/src/workflowExactHead.test.ts b/src/workflowExactHead.test.ts index 828c28287..404fc6230 100644 --- a/src/workflowExactHead.test.ts +++ b/src/workflowExactHead.test.ts @@ -74,7 +74,7 @@ describe('exact-head CI workflow contract', () => { ); expect(workflow).toContain('cancel-in-progress: true'); expect(officeJob).toContain( - "python-version: ${{ github.event_name == 'pull_request' && fromJSON('[\"3.14\"]') || fromJSON('[\"3.11\", \"3.12\", \"3.13\", \"3.14\"]') }}", + "python-version: ${{ github.event_name == 'pull_request' && fromJSON('[\"3.11\", \"3.14\"]') || fromJSON('[\"3.11\", \"3.12\", \"3.13\", \"3.14\"]') }}", ); expect(releaseWorkflow).toContain( 'group: ${{ github.workflow }}-${{ github.repository }}-${{ github.ref_name }}', From 93fd077adc8eb5c6980dc47af7cedaef2f211537 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 4 Sep 2026 23:31:58 +0900 Subject: [PATCH 06/18] fix(ci): restore full Python PR matrix Signed-off-by: Seongho Bae --- .github/workflows/ci.yml | 2 +- office/tests/test_python_support_contract.py | 14 ++++---------- src/workflowExactHead.test.ts | 2 +- 3 files changed, 6 insertions(+), 12 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 03a505671..eb28caf79 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -90,7 +90,7 @@ jobs: strategy: fail-fast: false matrix: - python-version: ${{ github.event_name == 'pull_request' && fromJSON('["3.11", "3.14"]') || fromJSON('["3.11", "3.12", "3.13", "3.14"]') }} + python-version: ["3.11", "3.12", "3.13", "3.14"] defaults: run: working-directory: office diff --git a/office/tests/test_python_support_contract.py b/office/tests/test_python_support_contract.py index 9c9d2288b..7104fd661 100644 --- a/office/tests/test_python_support_contract.py +++ b/office/tests/test_python_support_contract.py @@ -1,14 +1,12 @@ """Cross-file contract for the Python versions advertised by Inkspan Office.""" from pathlib import Path -import json import re import tomllib REPOSITORY_ROOT = Path(__file__).resolve().parents[2] SUPPORTED_PYTHON_VERSIONS = ("3.11", "3.12", "3.13", "3.14") -PULL_REQUEST_PYTHON_VERSIONS = ("3.11", "3.14") PYTHON_312_LXML_LINUX_SHA256 = ( "bc783ee3147e60a25aa0445ea82b3e8aabb83b240f2b95d32cb75587ff781814" ) @@ -35,7 +33,7 @@ def _workflow_job_block(workflow: str, job_name: str) -> str: def test_python_support_range_matches_classifiers_and_ci_matrix() -> None: - """Require PR boundary coverage and full protected-main compatibility coverage.""" + """Require package metadata and the Office CI job to cover the same minors.""" pyproject = tomllib.loads(_repository_text("office/pyproject.toml")) project = pyproject["project"] @@ -52,14 +50,10 @@ def test_python_support_range_matches_classifiers_and_ci_matrix() -> None: office_job = _workflow_job_block(workflow, "office") assert "runs-on: ubuntu-24.04" in office_job assert "runs-on: ubuntu-latest" not in office_job - matrix_match = re.search( - r"python-version:\s*\$\{\{\s*github\.event_name == 'pull_request'\s*" - r"&&\s*fromJSON\('([^']+)'\)\s*\|\|\s*fromJSON\('([^']+)'\)\s*\}\}", - office_job, - ) + matrix_match = re.search(r'python-version:\s*\[([^\]]+)\]', office_job) assert matrix_match is not None - assert tuple(json.loads(matrix_match.group(1))) == PULL_REQUEST_PYTHON_VERSIONS - assert tuple(json.loads(matrix_match.group(2))) == SUPPORTED_PYTHON_VERSIONS + matrix_versions = tuple(re.findall(r'"(3\.\d+)"', matrix_match.group(1))) + assert matrix_versions == SUPPORTED_PYTHON_VERSIONS def test_python_support_documentation_matches_the_fixed_ci_environment() -> None: diff --git a/src/workflowExactHead.test.ts b/src/workflowExactHead.test.ts index 404fc6230..615f75644 100644 --- a/src/workflowExactHead.test.ts +++ b/src/workflowExactHead.test.ts @@ -74,7 +74,7 @@ describe('exact-head CI workflow contract', () => { ); expect(workflow).toContain('cancel-in-progress: true'); expect(officeJob).toContain( - "python-version: ${{ github.event_name == 'pull_request' && fromJSON('[\"3.11\", \"3.14\"]') || fromJSON('[\"3.11\", \"3.12\", \"3.13\", \"3.14\"]') }}", + 'python-version: ["3.11", "3.12", "3.13", "3.14"]', ); expect(releaseWorkflow).toContain( 'group: ${{ github.workflow }}-${{ github.repository }}-${{ github.ref_name }}', From d94232290c08dbef50751acc1bc35d5c72516bfa Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 02:26:47 +0900 Subject: [PATCH 07/18] test(ci): cover event-specific Python matrix Signed-off-by: Seongho Bae --- office/tests/test_python_support_contract.py | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/office/tests/test_python_support_contract.py b/office/tests/test_python_support_contract.py index 7104fd661..209f48454 100644 --- a/office/tests/test_python_support_contract.py +++ b/office/tests/test_python_support_contract.py @@ -50,10 +50,14 @@ def test_python_support_range_matches_classifiers_and_ci_matrix() -> None: office_job = _workflow_job_block(workflow, "office") assert "runs-on: ubuntu-24.04" in office_job assert "runs-on: ubuntu-latest" not in office_job - matrix_match = re.search(r'python-version:\s*\[([^\]]+)\]', office_job) + matrix_match = re.search(r"python-version:\s*(.+)", office_job) assert matrix_match is not None - matrix_versions = tuple(re.findall(r'"(3\.\d+)"', matrix_match.group(1))) - assert matrix_versions == SUPPORTED_PYTHON_VERSIONS + pull_request_versions, push_versions = ( + tuple(re.findall(r'"(3\.\d+)"', versions)) + for versions in re.findall(r"fromJSON\('(\[[^']+\])'\)", matrix_match.group(1)) + ) + assert pull_request_versions == (SUPPORTED_PYTHON_VERSIONS[-1],) + assert push_versions == SUPPORTED_PYTHON_VERSIONS def test_python_support_documentation_matches_the_fixed_ci_environment() -> None: From ca31a266ddad06681375de812aba7611bba44124 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 02:32:54 +0900 Subject: [PATCH 08/18] test(ci): bind Python matrix to event Signed-off-by: Seongho Bae --- office/tests/test_python_support_contract.py | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/office/tests/test_python_support_contract.py b/office/tests/test_python_support_contract.py index 209f48454..a52ddec39 100644 --- a/office/tests/test_python_support_contract.py +++ b/office/tests/test_python_support_contract.py @@ -50,11 +50,16 @@ def test_python_support_range_matches_classifiers_and_ci_matrix() -> None: office_job = _workflow_job_block(workflow, "office") assert "runs-on: ubuntu-24.04" in office_job assert "runs-on: ubuntu-latest" not in office_job - matrix_match = re.search(r"python-version:\s*(.+)", office_job) + matrix_match = re.search( + r"python-version:\s*\$\{\{\s*github\.event_name\s*==\s*'pull_request'" + r"\s*&&\s*fromJSON\('(\[[^']+\])'\)\s*\|\|\s*" + r"fromJSON\('(\[[^']+\])'\)\s*\}\}", + office_job, + ) assert matrix_match is not None pull_request_versions, push_versions = ( tuple(re.findall(r'"(3\.\d+)"', versions)) - for versions in re.findall(r"fromJSON\('(\[[^']+\])'\)", matrix_match.group(1)) + for versions in matrix_match.groups() ) assert pull_request_versions == (SUPPORTED_PYTHON_VERSIONS[-1],) assert push_versions == SUPPORTED_PYTHON_VERSIONS From 6b059f2f29598b6584b29b25a637edf751a5f426 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 02:41:31 +0900 Subject: [PATCH 09/18] fix(deps): repair TipTap React declarations Signed-off-by: Seongho Bae --- .../tiptap-v2-prosemirror-paste-adapter.md | 5 ++ patches/@tiptap__react@3.30.4.patch | 70 +++++++++++++++++++ pnpm-lock.yaml | 7 +- pnpm-workspace.yaml | 3 + ...tapV2ClipboardAdapterDocumentation.test.ts | 7 ++ 5 files changed, 90 insertions(+), 2 deletions(-) create mode 100644 patches/@tiptap__react@3.30.4.patch diff --git a/docs/doctoring/tiptap-v2-prosemirror-paste-adapter.md b/docs/doctoring/tiptap-v2-prosemirror-paste-adapter.md index d94f47776..401c8c4dd 100644 --- a/docs/doctoring/tiptap-v2-prosemirror-paste-adapter.md +++ b/docs/doctoring/tiptap-v2-prosemirror-paste-adapter.md @@ -30,6 +30,11 @@ for the installed runtime, while current mutable documentation is useful design context but not evidence that an API existed in this historical dependency version. Inkspan now locks the coherent TipTap 3.30.4 package family; the same real-pipeline tests prove that the adapter remains registered after migration. +The published `@tiptap/react` 3.30.4 ESM and CommonJS declarations qualify four +`Editor` references through an internal namespace that does not export that +type. The lockfile applies one bounded patch to those declarations, and the +packed strict-TypeScript consumer check prevents the broken public types from +shipping. The practical result was a false assurance gap: direct sanitizer unit tests were green, but the real `editor.view` paste pipeline had no SafeClipboard diff --git a/patches/@tiptap__react@3.30.4.patch b/patches/@tiptap__react@3.30.4.patch new file mode 100644 index 000000000..c5fb3308f --- /dev/null +++ b/patches/@tiptap__react@3.30.4.patch @@ -0,0 +1,70 @@ +diff --git a/dist/index.d.cts b/dist/index.d.cts +index 331a7a57ec202e68d67e2c692c4b1bedb928c6cc..5fc696b31890d469d3b1cd07bc2f860f5cfc782e 100644 +--- a/dist/index.d.cts ++++ b/dist/index.d.cts +@@ -402,7 +402,7 @@ declare function ReactWidgetRenderer

= object>(com + */ + type TiptapContextType = { + /** The Tiptap editor instance. */ +- editor: index_d_exports.Editor; ++ editor: Editor; + }; + /** + * React context that stores the current editor instance. +@@ -459,18 +459,18 @@ declare const useTiptap: () => TiptapContextType; + * } + * ``` + */ +-declare function useTiptapState(selector: (context: EditorStateSnapshot) => TSelectorResult, equalityFn?: (a: TSelectorResult, b: TSelectorResult | null) => boolean): TSelectorResult; ++declare function useTiptapState(selector: (context: EditorStateSnapshot) => TSelectorResult, equalityFn?: (a: TSelectorResult, b: TSelectorResult | null) => boolean): TSelectorResult; + type TiptapWrapperEditorInstanceProps = { + /** + * The editor instance to provide to child components. + * Use `useEditor()` to create this instance. + */ +- editor: index_d_exports.Editor; ++ editor: Editor; + } | { + /** + * @deprecated Use `editor` instead. Will be removed in the next major version. + */ +- instance: index_d_exports.Editor; ++ instance: Editor; + }; + /** + * Props for the `Tiptap` root/provider component. +diff --git a/dist/index.d.ts b/dist/index.d.ts +index 1ea46992a97b34957359edd7e70186dfa060fe87..1aeb997fa11b4dfb57604596dded3f54f2c3e270 100644 +--- a/dist/index.d.ts ++++ b/dist/index.d.ts +@@ -402,7 +402,7 @@ declare function ReactWidgetRenderer

= object>(com + */ + type TiptapContextType = { + /** The Tiptap editor instance. */ +- editor: index_d_exports.Editor; ++ editor: Editor; + }; + /** + * React context that stores the current editor instance. +@@ -459,18 +459,18 @@ declare const useTiptap: () => TiptapContextType; + * } + * ``` + */ +-declare function useTiptapState(selector: (context: EditorStateSnapshot) => TSelectorResult, equalityFn?: (a: TSelectorResult, b: TSelectorResult | null) => boolean): TSelectorResult; ++declare function useTiptapState(selector: (context: EditorStateSnapshot) => TSelectorResult, equalityFn?: (a: TSelectorResult, b: TSelectorResult | null) => boolean): TSelectorResult; + type TiptapWrapperEditorInstanceProps = { + /** + * The editor instance to provide to child components. + * Use `useEditor()` to create this instance. + */ +- editor: index_d_exports.Editor; ++ editor: Editor; + } | { + /** + * @deprecated Use `editor` instead. Will be removed in the next major version. + */ +- instance: index_d_exports.Editor; ++ instance: Editor; + }; + /** + * Props for the `Tiptap` root/provider component. diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 0ac053658..b6d6bb2b3 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -15,6 +15,9 @@ overrides: brace-expansion: ^5.0.8 minimatch: ^10.0.0 +patchedDependencies: + '@tiptap/react@3.30.4': af087c2b6d7b037140520eccaea4545af8309648a75f788ed6d7f6afa37cb1c7 + importers: .: @@ -45,7 +48,7 @@ importers: version: 3.30.4 '@tiptap/react': specifier: 3.30.4 - version: 3.30.4(@floating-ui/dom@1.8.0)(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)(@types/react-dom@18.3.7(@types/react@18.3.31))(@types/react@18.3.31)(react-dom@18.3.1(react@18.3.1))(react@18.3.1) + version: 3.30.4(patch_hash=af087c2b6d7b037140520eccaea4545af8309648a75f788ed6d7f6afa37cb1c7)(@floating-ui/dom@1.8.0)(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)(@types/react-dom@18.3.7(@types/react@18.3.31))(@types/react@18.3.31)(react-dom@18.3.1(react@18.3.1))(react@18.3.1) '@tiptap/starter-kit': specifier: 3.30.4 version: 3.30.4 @@ -3439,7 +3442,7 @@ snapshots: prosemirror-transform: 1.12.0 prosemirror-view: 1.42.1 - '@tiptap/react@3.30.4(@floating-ui/dom@1.8.0)(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)(@types/react-dom@18.3.7(@types/react@18.3.31))(@types/react@18.3.31)(react-dom@18.3.1(react@18.3.1))(react@18.3.1)': + '@tiptap/react@3.30.4(patch_hash=af087c2b6d7b037140520eccaea4545af8309648a75f788ed6d7f6afa37cb1c7)(@floating-ui/dom@1.8.0)(@tiptap/core@3.30.4(@tiptap/pm@3.30.4))(@tiptap/pm@3.30.4)(@types/react-dom@18.3.7(@types/react@18.3.31))(@types/react@18.3.31)(react-dom@18.3.1(react@18.3.1))(react@18.3.1)': dependencies: '@tiptap/core': 3.30.4(@tiptap/pm@3.30.4) '@tiptap/pm': 3.30.4 diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index 4606cd4a9..f4796a091 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -40,3 +40,6 @@ overrides: postcss: ^8.5.23 brace-expansion: ^5.0.8 minimatch: ^10.0.0 + +patchedDependencies: + '@tiptap/react@3.30.4': patches/@tiptap__react@3.30.4.patch diff --git a/src/tiptapV2ClipboardAdapterDocumentation.test.ts b/src/tiptapV2ClipboardAdapterDocumentation.test.ts index 07068e716..faae00206 100644 --- a/src/tiptapV2ClipboardAdapterDocumentation.test.ts +++ b/src/tiptapV2ClipboardAdapterDocumentation.test.ts @@ -5,6 +5,8 @@ const doctoringPath = 'docs/doctoring/tiptap-v2-prosemirror-paste-adapter.md'; const adapterPath = 'src/extensions/SafeClipboardExtension.ts'; const kitPath = 'src/extensions/kit.ts'; const lockPath = 'pnpm-lock.yaml'; +const workspacePath = 'pnpm-workspace.yaml'; +const reactPatchPath = 'patches/@tiptap__react@3.30.4.patch'; const changelogPath = 'CHANGELOG.md'; /** Read one authoritative repository artifact for deterministic contract tests. */ @@ -18,11 +20,16 @@ describe('TipTap SafeClipboard adapter doctoring', () => { const adapter = readRepositoryText(adapterPath); const kit = readRepositoryText(kitPath); const lock = readRepositoryText(lockPath); + const workspace = readRepositoryText(workspacePath); + const reactPatch = readRepositoryText(reactPatchPath); const changelog = readRepositoryText(changelogPath); expect(lock).toContain("'@tiptap/core':"); expect(lock).toContain('specifier: 3.30.4'); expect(doctoring).toContain('TipTap 3.30.4 package family'); + expect(doctoring).toContain('packed strict-TypeScript consumer check'); + expect(workspace).toContain("'@tiptap/react@3.30.4':"); + expect(reactPatch).toContain('EditorStateSnapshot'); expect(doctoring).toContain('addProseMirrorPlugins'); expect(doctoring).toContain('transformPastedHTML'); expect(doctoring).toContain('before ProseMirror parses'); From 3d4efaaa56db459d85ce4857aea8ee9d73e4a35c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 03:39:18 +0900 Subject: [PATCH 10/18] repair(ci): keep security lane out of Python policy --- office/tests/test_python_support_contract.py | 15 +++------------ 1 file changed, 3 insertions(+), 12 deletions(-) diff --git a/office/tests/test_python_support_contract.py b/office/tests/test_python_support_contract.py index a52ddec39..7104fd661 100644 --- a/office/tests/test_python_support_contract.py +++ b/office/tests/test_python_support_contract.py @@ -50,19 +50,10 @@ def test_python_support_range_matches_classifiers_and_ci_matrix() -> None: office_job = _workflow_job_block(workflow, "office") assert "runs-on: ubuntu-24.04" in office_job assert "runs-on: ubuntu-latest" not in office_job - matrix_match = re.search( - r"python-version:\s*\$\{\{\s*github\.event_name\s*==\s*'pull_request'" - r"\s*&&\s*fromJSON\('(\[[^']+\])'\)\s*\|\|\s*" - r"fromJSON\('(\[[^']+\])'\)\s*\}\}", - office_job, - ) + matrix_match = re.search(r'python-version:\s*\[([^\]]+)\]', office_job) assert matrix_match is not None - pull_request_versions, push_versions = ( - tuple(re.findall(r'"(3\.\d+)"', versions)) - for versions in matrix_match.groups() - ) - assert pull_request_versions == (SUPPORTED_PYTHON_VERSIONS[-1],) - assert push_versions == SUPPORTED_PYTHON_VERSIONS + matrix_versions = tuple(re.findall(r'"(3\.\d+)"', matrix_match.group(1))) + assert matrix_versions == SUPPORTED_PYTHON_VERSIONS def test_python_support_documentation_matches_the_fixed_ci_environment() -> None: From 85c77656212f332eb97e44becdaa238bd218a6d7 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 07:04:41 +0900 Subject: [PATCH 11/18] fix(types): isolate packed declarations from TipTap React Use the stable core Editor types in emitted declarations and reject packed declarations that import TipTap React internals. Signed-off-by: Seongho Bae Commit-Message-Assisted-by: Claude (via Claude Code) --- src/collaboration/CollaborativeCwlEditor.tsx | 3 ++- src/components/CwlEditor.tsx | 3 ++- src/components/EditorFormField.tsx | 2 +- src/components/EditorFrame.tsx | 3 ++- src/components/Toolbar.tsx | 2 +- src/components/editorDocumentSnapshot.ts | 2 +- src/components/editorFormReset.ts | 2 +- src/components/useEditorHandle.ts | 2 +- src/documentEnvelopeIfMatch.ts | 2 +- src/documentEnvelopeRestore.ts | 2 +- src/documentSchema.ts | 2 +- src/extensions/kit.ts | 2 +- src/types.ts | 3 +-- tests/package/verify-package.mjs | 13 +++++++++++++ 14 files changed, 29 insertions(+), 14 deletions(-) diff --git a/src/collaboration/CollaborativeCwlEditor.tsx b/src/collaboration/CollaborativeCwlEditor.tsx index c8aeb23ab..fd16dfdb0 100644 --- a/src/collaboration/CollaborativeCwlEditor.tsx +++ b/src/collaboration/CollaborativeCwlEditor.tsx @@ -1,6 +1,7 @@ import Collaboration from '@tiptap/extension-collaboration'; import CollaborationCaret from '@tiptap/extension-collaboration-caret'; -import { type Editor, useEditor } from '@tiptap/react'; +import type { Editor } from '@tiptap/core'; +import { useEditor } from '@tiptap/react'; import { forwardRef, useCallback, diff --git a/src/components/CwlEditor.tsx b/src/components/CwlEditor.tsx index 240f87423..c0b6e0661 100644 --- a/src/components/CwlEditor.tsx +++ b/src/components/CwlEditor.tsx @@ -1,4 +1,5 @@ -import { type Editor, useEditor } from '@tiptap/react'; +import type { Editor } from '@tiptap/core'; +import { useEditor } from '@tiptap/react'; import { forwardRef, useCallback, diff --git a/src/components/EditorFormField.tsx b/src/components/EditorFormField.tsx index 2e7481e71..d15121833 100644 --- a/src/components/EditorFormField.tsx +++ b/src/components/EditorFormField.tsx @@ -1,4 +1,4 @@ -import type { Editor } from '@tiptap/react'; +import type { Editor } from '@tiptap/core'; import { useEffect, useRef } from 'react'; import type { EditorMode } from '../types.js'; import { editorHtmlToValue } from './editorSerialization.js'; diff --git a/src/components/EditorFrame.tsx b/src/components/EditorFrame.tsx index 9cf49c23f..ebd1e85de 100644 --- a/src/components/EditorFrame.tsx +++ b/src/components/EditorFrame.tsx @@ -1,4 +1,5 @@ -import { EditorContent, type Editor } from '@tiptap/react'; +import type { Editor } from '@tiptap/core'; +import { EditorContent } from '@tiptap/react'; import { useCallback, type KeyboardEvent, type ReactNode } from 'react'; import type { EditorMode, ImageConfig } from '../types.js'; import { EditorFormField } from './EditorFormField.js'; diff --git a/src/components/Toolbar.tsx b/src/components/Toolbar.tsx index 55136e550..6e89966fb 100644 --- a/src/components/Toolbar.tsx +++ b/src/components/Toolbar.tsx @@ -1,4 +1,4 @@ -import type { Editor } from '@tiptap/react'; +import type { Editor } from '@tiptap/core'; import { useCallback, useEffect, diff --git a/src/components/editorDocumentSnapshot.ts b/src/components/editorDocumentSnapshot.ts index b10d5ac86..10f42630d 100644 --- a/src/components/editorDocumentSnapshot.ts +++ b/src/components/editorDocumentSnapshot.ts @@ -1,5 +1,5 @@ import type { JSONContent } from '@tiptap/core'; -import type { Editor } from '@tiptap/react'; +import type { Editor } from '@tiptap/core'; import { markdownToPlainText } from '../markdown/plainText.js'; import type { CwlEditorDocumentSnapshot, diff --git a/src/components/editorFormReset.ts b/src/components/editorFormReset.ts index 3e7ed292c..d5a0f28e4 100644 --- a/src/components/editorFormReset.ts +++ b/src/components/editorFormReset.ts @@ -1,4 +1,4 @@ -import type { Editor } from '@tiptap/react'; +import type { Editor } from '@tiptap/core'; import type { CwlEditorFormResetEvent, EditorMode, diff --git a/src/components/useEditorHandle.ts b/src/components/useEditorHandle.ts index b47fb036e..e871f0a03 100644 --- a/src/components/useEditorHandle.ts +++ b/src/components/useEditorHandle.ts @@ -1,4 +1,4 @@ -import type { Editor } from '@tiptap/react'; +import type { Editor } from '@tiptap/core'; import { useImperativeHandle, type ForwardedRef, diff --git a/src/documentEnvelopeIfMatch.ts b/src/documentEnvelopeIfMatch.ts index 0b459afd2..e89ec3a73 100644 --- a/src/documentEnvelopeIfMatch.ts +++ b/src/documentEnvelopeIfMatch.ts @@ -1,5 +1,5 @@ import type { Node as ProseMirrorNode } from '@tiptap/pm/model'; -import type { Editor } from '@tiptap/react'; +import type { Editor } from '@tiptap/core'; import { createDocumentEnvelope, type CwlEditorDocumentEnvelope, diff --git a/src/documentEnvelopeRestore.ts b/src/documentEnvelopeRestore.ts index c265e0765..8b45ffa57 100644 --- a/src/documentEnvelopeRestore.ts +++ b/src/documentEnvelopeRestore.ts @@ -1,4 +1,4 @@ -import type { Editor } from '@tiptap/react'; +import type { Editor } from '@tiptap/core'; import { parseDocumentEnvelope, parseDocumentEnvelopeBytes, diff --git a/src/documentSchema.ts b/src/documentSchema.ts index e9498b7f1..b471386e8 100644 --- a/src/documentSchema.ts +++ b/src/documentSchema.ts @@ -1,6 +1,6 @@ import type { JSONContent } from '@tiptap/core'; import type { Node as ProseMirrorNode } from '@tiptap/pm/model'; -import type { Editor } from '@tiptap/react'; +import type { Editor } from '@tiptap/core'; import { createDocumentEnvelope } from './documentEnvelope.js'; const INCOMPATIBLE_DOCUMENT_MESSAGE = diff --git a/src/extensions/kit.ts b/src/extensions/kit.ts index 8efbbf32a..965794de4 100644 --- a/src/extensions/kit.ts +++ b/src/extensions/kit.ts @@ -5,7 +5,7 @@ import StarterKit from '@tiptap/starter-kit'; import { Placeholder } from '@tiptap/extensions'; import { Table, TableRow, TableHeader, TableCell } from '@tiptap/extension-table'; -import type { Extensions } from '@tiptap/react'; +import type { Extensions } from '@tiptap/core'; import { Base64Image } from './Base64Image.js'; import type { ClipboardConfig, diff --git a/src/types.ts b/src/types.ts index 0292d4a22..1b4c19587 100644 --- a/src/types.ts +++ b/src/types.ts @@ -1,5 +1,4 @@ -import type { JSONContent } from '@tiptap/core'; -import type { Editor } from '@tiptap/react'; +import type { Editor, JSONContent } from '@tiptap/core'; import type { CwlEditorDocumentEnvelope, DocumentEnvelopeLimits, diff --git a/tests/package/verify-package.mjs b/tests/package/verify-package.mjs index 82a03e312..5ed3c69bd 100644 --- a/tests/package/verify-package.mjs +++ b/tests/package/verify-package.mjs @@ -124,6 +124,19 @@ function verifyPackedFiles(filePaths) { [], `npm package contains development-only files: ${forbiddenPaths.join(', ')}`, ); + + const reactDeclarationImports = [...filePaths] + .filter((filePath) => filePath.endsWith('.d.ts')) + .filter((filePath) => + readFileSync(join(repositoryRoot, filePath), 'utf8').includes( + "from '@tiptap/react'", + ), + ); + assert.deepEqual( + reactDeclarationImports, + [], + `npm declarations depend on TipTap React internals: ${reactDeclarationImports.join(', ')}`, + ); } /** Write and execute an ESM or CommonJS package-consumer smoke test. */ From b444332b6d10d960dce8452b6d54688ed3816fc7 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 07:05:49 +0900 Subject: [PATCH 12/18] docs(tiptap): tighten migration evidence Use the valid upstream source tag and bind the lockfile version assertion to the TipTap core dependency block. Signed-off-by: Seongho Bae Commit-Message-Assisted-by: Claude (via Claude Code) --- docs/doctoring/tiptap-v2-prosemirror-paste-adapter.md | 2 +- src/tiptapV2ClipboardAdapterDocumentation.test.ts | 5 +++-- 2 files changed, 4 insertions(+), 3 deletions(-) diff --git a/docs/doctoring/tiptap-v2-prosemirror-paste-adapter.md b/docs/doctoring/tiptap-v2-prosemirror-paste-adapter.md index 401c8c4dd..bdd48ab37 100644 --- a/docs/doctoring/tiptap-v2-prosemirror-paste-adapter.md +++ b/docs/doctoring/tiptap-v2-prosemirror-paste-adapter.md @@ -115,4 +115,4 @@ https://tiptap.dev/docs/editor/extensions/custom-extensions/create-new/extension TipTap GmbH. (2026). *ExtensionManager.ts (Version 3.30.4)* [Source code]. GitHub. Retrieved September 4, 2026, from -https://github.com/ueberdosis/tiptap/blob/%40tiptap/core%403.30.4/packages/core/src/ExtensionManager.ts +https://github.com/ueberdosis/tiptap/blob/v3.30.4/packages/core/src/ExtensionManager.ts diff --git a/src/tiptapV2ClipboardAdapterDocumentation.test.ts b/src/tiptapV2ClipboardAdapterDocumentation.test.ts index faae00206..4ddca709f 100644 --- a/src/tiptapV2ClipboardAdapterDocumentation.test.ts +++ b/src/tiptapV2ClipboardAdapterDocumentation.test.ts @@ -24,8 +24,9 @@ describe('TipTap SafeClipboard adapter doctoring', () => { const reactPatch = readRepositoryText(reactPatchPath); const changelog = readRepositoryText(changelogPath); - expect(lock).toContain("'@tiptap/core':"); - expect(lock).toContain('specifier: 3.30.4'); + expect(lock).toMatch( + /^\s+'@tiptap\/core':\n\s+specifier: 3\.30\.4$/mu, + ); expect(doctoring).toContain('TipTap 3.30.4 package family'); expect(doctoring).toContain('packed strict-TypeScript consumer check'); expect(workspace).toContain("'@tiptap/react@3.30.4':"); From 202084ddf37cabd61b0490e45c514313c7c8fda3 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 07:14:06 +0900 Subject: [PATCH 13/18] fix(collaboration): declare v3 runtime binding Publish the direct TipTap Yjs binding required by the collaboration extensions and remove the unused v2 adapter dependency. Signed-off-by: Seongho Bae Commit-Message-Assisted-by: Claude (via Claude Code) --- docs/collaboration.md | 2 +- package.json | 2 +- pnpm-lock.yaml | 25 +++---------------- ...tapV2ClipboardAdapterDocumentation.test.ts | 6 +++++ 4 files changed, 11 insertions(+), 24 deletions(-) diff --git a/docs/collaboration.md b/docs/collaboration.md index 491ba20f1..772ea5190 100644 --- a/docs/collaboration.md +++ b/docs/collaboration.md @@ -48,7 +48,7 @@ export function SharedDocument({ The collaboration entrypoint is built separately from the ordinary editor. Applications importing only `@contextualwisdomlab/cwl-editor` do not include -Yjs, `y-prosemirror`, or the TipTap collaboration extensions in their browser +Yjs, `@tiptap/y-tiptap`, or the TipTap collaboration extensions in their browser bundle. ## Ownership boundary diff --git a/package.json b/package.json index 7f99c12dc..5683bcf31 100644 --- a/package.json +++ b/package.json @@ -135,10 +135,10 @@ "@tiptap/pm": "3.30.4", "@tiptap/react": "3.30.4", "@tiptap/starter-kit": "3.30.4", + "@tiptap/y-tiptap": "3.0.9", "marked": "^15.0.6", "turndown": "^7.2.0", "turndown-plugin-gfm": "^1.0.2", - "y-prosemirror": "^1.3.7", "yjs": "^13.6.30" }, "devDependencies": { diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 7e60df7df..bfe9a1d76 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -53,6 +53,9 @@ importers: '@tiptap/starter-kit': specifier: 3.30.4 version: 3.30.4 + '@tiptap/y-tiptap': + specifier: 3.0.9 + version: 3.0.9(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31) marked: specifier: ^15.0.6 version: 15.0.12 @@ -62,9 +65,6 @@ importers: turndown-plugin-gfm: specifier: ^1.0.2 version: 1.0.2 - y-prosemirror: - specifier: ^1.3.7 - version: 1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31) yjs: specifier: ^13.6.30 version: 13.6.31 @@ -2514,16 +2514,6 @@ packages: xmlchars@2.2.0: resolution: {integrity: sha512-JZnDKK8B0RCDw84FNdDAIpZK+JuJw+s7Lz8nksI7SIuU3UXJJslUthsi+uWBUYOwPFwW7W7PRLRfUKpxjtjFCw==} - y-prosemirror@1.3.7: - resolution: {integrity: sha512-NpM99WSdD4Fx4if5xOMDpPtU3oAmTSjlzh5U4353ABbRHl1HtAFUx6HlebLZfyFxXN9jzKMDkVbcRjqOZVkYQg==} - engines: {node: '>=16.0.0', npm: '>=8.0.0'} - peerDependencies: - prosemirror-model: ^1.7.1 - prosemirror-state: ^1.2.3 - prosemirror-view: ^1.9.10 - y-protocols: ^1.0.1 - yjs: ^13.5.38 - y-protocols@1.0.7: resolution: {integrity: sha512-YSVsLoXxO67J6eE/nV4AtFtT3QEotZf5sK5BHxFBXso7VDUT3Tx07IfA6hsu5Q5OmBdMkQVmFZ9QOA7fikWvnw==} engines: {node: '>=16.0.0', npm: '>=8.0.0'} @@ -4868,15 +4858,6 @@ snapshots: xmlchars@2.2.0: {} - y-prosemirror@1.3.7(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.1)(y-protocols@1.0.7(yjs@13.6.31))(yjs@13.6.31): - dependencies: - lib0: 0.2.117 - prosemirror-model: 1.25.11 - prosemirror-state: 1.4.4 - prosemirror-view: 1.42.1 - y-protocols: 1.0.7(yjs@13.6.31) - yjs: 13.6.31 - y-protocols@1.0.7(yjs@13.6.31): dependencies: lib0: 0.2.117 diff --git a/src/tiptapV2ClipboardAdapterDocumentation.test.ts b/src/tiptapV2ClipboardAdapterDocumentation.test.ts index 4ddca709f..46d4c30d9 100644 --- a/src/tiptapV2ClipboardAdapterDocumentation.test.ts +++ b/src/tiptapV2ClipboardAdapterDocumentation.test.ts @@ -6,6 +6,7 @@ const adapterPath = 'src/extensions/SafeClipboardExtension.ts'; const kitPath = 'src/extensions/kit.ts'; const lockPath = 'pnpm-lock.yaml'; const workspacePath = 'pnpm-workspace.yaml'; +const packagePath = 'package.json'; const reactPatchPath = 'patches/@tiptap__react@3.30.4.patch'; const changelogPath = 'CHANGELOG.md'; @@ -21,6 +22,9 @@ describe('TipTap SafeClipboard adapter doctoring', () => { const kit = readRepositoryText(kitPath); const lock = readRepositoryText(lockPath); const workspace = readRepositoryText(workspacePath); + const manifest = JSON.parse(readRepositoryText(packagePath)) as { + dependencies?: Record; + }; const reactPatch = readRepositoryText(reactPatchPath); const changelog = readRepositoryText(changelogPath); @@ -30,6 +34,8 @@ describe('TipTap SafeClipboard adapter doctoring', () => { expect(doctoring).toContain('TipTap 3.30.4 package family'); expect(doctoring).toContain('packed strict-TypeScript consumer check'); expect(workspace).toContain("'@tiptap/react@3.30.4':"); + expect(manifest.dependencies?.['@tiptap/y-tiptap']).toBe('3.0.9'); + expect(manifest.dependencies).not.toHaveProperty('y-prosemirror'); expect(reactPatch).toContain('EditorStateSnapshot'); expect(doctoring).toContain('addProseMirrorPlugins'); expect(doctoring).toContain('transformPastedHTML'); From d1f275355b3a948776d4e9c5b3a2e4938a09402b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 07:25:42 +0900 Subject: [PATCH 14/18] fix(collaboration): ship y-tiptap peer runtime Signed-off-by: Seongho Bae Commit-Message-Assisted-by: Claude (via Claude Code) --- docs/revision-guarded-restore.md | 2 +- package.json | 4 ++++ pnpm-lock.yaml | 12 ++++++++++++ src/tiptapV2ClipboardAdapterDocumentation.test.ts | 4 ++++ 4 files changed, 21 insertions(+), 1 deletion(-) diff --git a/docs/revision-guarded-restore.md b/docs/revision-guarded-restore.md index e2f1cbea2..c9001f5ea 100644 --- a/docs/revision-guarded-restore.md +++ b/docs/revision-guarded-restore.md @@ -155,7 +155,7 @@ normalized envelope. This second asynchronous boundary is required to return a trustworthy resulting strong validator without a later host race. After the digest resolves, Inkspan checks editor lifecycle and active document identity again. Only then does it apply the already prepared node with one -`setContent(documentNode, false)` replacement without another asynchronous +`setContent(documentNode, { emitUpdate: false })` replacement without another asynchronous boundary or attacker-controlled property access. TipTap commands can report command execution before ProseMirror transaction diff --git a/package.json b/package.json index 5683bcf31..ad4236862 100644 --- a/package.json +++ b/package.json @@ -137,8 +137,12 @@ "@tiptap/starter-kit": "3.30.4", "@tiptap/y-tiptap": "3.0.9", "marked": "^15.0.6", + "prosemirror-model": "^1.7.1", + "prosemirror-state": "^1.2.3", + "prosemirror-view": "^1.9.10", "turndown": "^7.2.0", "turndown-plugin-gfm": "^1.0.2", + "y-protocols": "^1.0.1", "yjs": "^13.6.30" }, "devDependencies": { diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index bfe9a1d76..8eb48d98a 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -59,12 +59,24 @@ importers: marked: specifier: ^15.0.6 version: 15.0.12 + prosemirror-model: + specifier: ^1.7.1 + version: 1.25.11 + prosemirror-state: + specifier: ^1.2.3 + version: 1.4.4 + prosemirror-view: + specifier: ^1.9.10 + version: 1.42.1 turndown: specifier: ^7.2.0 version: 7.2.4 turndown-plugin-gfm: specifier: ^1.0.2 version: 1.0.2 + y-protocols: + specifier: ^1.0.1 + version: 1.0.7(yjs@13.6.31) yjs: specifier: ^13.6.30 version: 13.6.31 diff --git a/src/tiptapV2ClipboardAdapterDocumentation.test.ts b/src/tiptapV2ClipboardAdapterDocumentation.test.ts index 46d4c30d9..6e8943a1e 100644 --- a/src/tiptapV2ClipboardAdapterDocumentation.test.ts +++ b/src/tiptapV2ClipboardAdapterDocumentation.test.ts @@ -35,6 +35,10 @@ describe('TipTap SafeClipboard adapter doctoring', () => { expect(doctoring).toContain('packed strict-TypeScript consumer check'); expect(workspace).toContain("'@tiptap/react@3.30.4':"); expect(manifest.dependencies?.['@tiptap/y-tiptap']).toBe('3.0.9'); + expect(manifest.dependencies?.['prosemirror-model']).toBe('^1.7.1'); + expect(manifest.dependencies?.['prosemirror-state']).toBe('^1.2.3'); + expect(manifest.dependencies?.['prosemirror-view']).toBe('^1.9.10'); + expect(manifest.dependencies?.['y-protocols']).toBe('^1.0.1'); expect(manifest.dependencies).not.toHaveProperty('y-prosemirror'); expect(reactPatch).toContain('EditorStateSnapshot'); expect(doctoring).toContain('addProseMirrorPlugins'); From b229572fc2634313813d1e174f9315d1f703d31c Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 07:36:47 +0900 Subject: [PATCH 15/18] feat!: version the TipTap 3 migration BREAKING CHANGE: Hosts using getEditor() or buildExtensions() must upgrade TipTap integrations to v3. Signed-off-by: Seongho Bae Commit-Message-Assisted-by: Claude (via Claude Code) --- CHANGELOG.md | 15 ++++++++++++++- README.md | 17 ++++++++++++++++- docs/release-security.md | 2 +- office/pyproject.toml | 2 +- package.json | 3 ++- pnpm-lock.yaml | 8 ++++---- ...iptapV2ClipboardAdapterDocumentation.test.ts | 10 +++++++++- tests/package/verify-package.mjs | 7 +++++++ 8 files changed, 54 insertions(+), 10 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 3cc73ea23..e3243a6a2 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -14,10 +14,23 @@ Historical release entries from **0.1.0 through 0.5.27** are preserved verbatim - Restored a visible `:focus-visible` indicator on the editable textbox, mapped it to `CanvasText` in forced-colors mode, and suppresses that interactive focus chrome under `@media print`; dependency-locked Chromium, Firefox, and WebKit acceptance exercises the packed stylesheet on the real `role="textbox"` surface. ### Security -- Patched an editor dependency vulnerability while preserving the existing formatting, collaboration-presence, safe-link, and exact document-restore behavior. - Raised workspace-wide transitive development-tool overrides for `fast-uri`, `nanoid`, and `postcss` to patched minimums, keeping the lockfile audit clean without changing runtime package authority. - Normalized isolated package-verifier temporary roots before containment checks on macOS. +## [0.7.0] — 2026-09-05 + +### Release +- Unified the npm editor and `inkspan-office` package manifests at **0.7.0** for the TipTap v3 migration release candidate; protected integration and registry publication remain separate acceptance gates. + +### Breaking +- Upgraded the public TipTap editor ABI from v2 to the coherent TipTap 3.30.4 package family. Hosts that consume `CwlEditorHandle.getEditor()` or pass TipTap extensions to `buildExtensions()` must upgrade those host imports and extensions to v3; v2 and v3 editor graphs must not be mixed. + +### Migration and rollback +- Upgrade Inkspan and every host-owned TipTap extension as one dependency-lock change, then re-run the host's editor, collaboration, and packed-consumer checks. Before adoption, rollback restores Inkspan 0.6.x and the host TipTap 2 dependency graph together; the document-envelope schema is unchanged and needs no stored-document migration. + +### Security +- Patched the TipTap runtime advisory while preserving formatting, collaboration presence, safe-link enforcement, and exact document restore behavior within the new v3 ABI. + ## [0.6.0] — 2026-08-10 ### Release diff --git a/README.md b/README.md index dfc5713cf..ce7b2af21 100644 --- a/README.md +++ b/README.md @@ -87,6 +87,21 @@ runtime. pnpm add @contextualwisdomlab/cwl-editor react react-dom ``` +### Migrate to 0.7.0 + +Inkspan 0.7.0 upgrades its public editor boundary from TipTap 2 to TipTap +3.30.4. Hosts that call `getEditor()` or pass `additionalExtensions` to +`buildExtensions()` must upgrade their TipTap extensions and imports to the +same v3 package family; do not mix v2 and v3 extensions or ProseMirror graphs. +Hosts that use only `CwlEditor` props still need to test their editor workflows +before adopting the new minor release. + +To roll back before adopting 0.7.0, restore Inkspan 0.6.x and the host's TipTap +2 dependencies together. The document-envelope schema is unchanged, so this +rollback needs no stored-document migration. After adopting 0.7.0 APIs, revert +host extension code and dependency locks as one reviewed change rather than +downgrading Inkspan alone. + ### Quick start ```tsx @@ -746,4 +761,4 @@ capabilities they require. - **Fonts:** Noto Sans families are SIL Open Font License 1.1. See [`LICENSE`](LICENSE), [`src/fonts/OFL.txt`](src/fonts/OFL.txt), and -[`src/fonts/NOTICE`](src/fonts/NOTICE). \ No newline at end of file +[`src/fonts/NOTICE`](src/fonts/NOTICE). diff --git a/docs/release-security.md b/docs/release-security.md index 08e1d6ff7..a778e9e72 100644 --- a/docs/release-security.md +++ b/docs/release-security.md @@ -118,7 +118,7 @@ The isolated GitHub publication job requests a short-lived OpenID Connect identi Consumers should verify release-level and file-level provenance, the SBOM predicate, and checksums, using the actual version and filenames from the selected release: ```bash -VERSION=0.6.0 +VERSION=0.7.0 gh release verify "v${VERSION}" --repo ContextualWisdomLab/inkspan diff --git a/office/pyproject.toml b/office/pyproject.toml index 3fefcd7b9..2970ceb3a 100644 --- a/office/pyproject.toml +++ b/office/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta" [project] name = "inkspan-office" -version = "0.6.0" +version = "0.7.0" description = "Deterministic JSON-to-DOCX/XLSX/PPTX renderer for AI-authored Inkspan documents" readme = "README.md" requires-python = ">=3.11,<3.15" diff --git a/package.json b/package.json index ad4236862..78bf18a02 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@contextualwisdomlab/cwl-editor", - "version": "0.6.0", + "version": "0.7.0", "description": "Inkspan — commercial-grade Markdown + HTML WYSIWYG editor module (TipTap/ProseMirror, MIT) with SSR-safe client hydration, native form integration, lossless document snapshots, preparse-resource-bounded duplicate-name-safe versioned persistence envelopes, canonical JSON plus strict UTF-8 byte round trips, SHA-256 strong revision validators, framework-independent pure and imperative atomic revision-envelope evidence, local If-Match restore guards, atomic before/after revision-envelope transition evidence for optimistic concurrency, a provider-neutral bounded single-flight autosave coordinator, and a server-validator-bound durable autosave session, one-call imperative envelope export and atomic active-schema restore, host-owned lifecycle callbacks, strict link and image policies, accessible editing controls, provider-neutral Yjs collaboration, a standalone base64 converter, and bundled offline multilingual Noto Sans fonts.", "license": "MIT", "author": "ContextualWisdomLab", @@ -125,6 +125,7 @@ } }, "dependencies": { + "@floating-ui/dom": "^1.0.0", "@tiptap/core": "3.30.4", "@tiptap/extension-collaboration": "3.30.4", "@tiptap/extension-collaboration-caret": "3.30.4", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 8eb48d98a..186464fa2 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -23,6 +23,9 @@ importers: .: dependencies: + '@floating-ui/dom': + specifier: ^1.0.0 + version: 1.8.0 '@tiptap/core': specifier: 3.30.4 version: 3.30.4(@tiptap/pm@3.30.4) @@ -2805,16 +2808,13 @@ snapshots: '@floating-ui/core@1.8.0': dependencies: '@floating-ui/utils': 0.2.12 - optional: true '@floating-ui/dom@1.8.0': dependencies: '@floating-ui/core': 1.8.0 '@floating-ui/utils': 0.2.12 - optional: true - '@floating-ui/utils@0.2.12': - optional: true + '@floating-ui/utils@0.2.12': {} '@isaacs/cliui@8.0.2': dependencies: diff --git a/src/tiptapV2ClipboardAdapterDocumentation.test.ts b/src/tiptapV2ClipboardAdapterDocumentation.test.ts index 6e8943a1e..1dd5d25d5 100644 --- a/src/tiptapV2ClipboardAdapterDocumentation.test.ts +++ b/src/tiptapV2ClipboardAdapterDocumentation.test.ts @@ -6,9 +6,10 @@ const adapterPath = 'src/extensions/SafeClipboardExtension.ts'; const kitPath = 'src/extensions/kit.ts'; const lockPath = 'pnpm-lock.yaml'; const workspacePath = 'pnpm-workspace.yaml'; -const packagePath = 'package.json'; + const packagePath = 'package.json'; const reactPatchPath = 'patches/@tiptap__react@3.30.4.patch'; const changelogPath = 'CHANGELOG.md'; +const readmePath = 'README.md'; /** Read one authoritative repository artifact for deterministic contract tests. */ function readRepositoryText(path: string): string { @@ -27,6 +28,7 @@ describe('TipTap SafeClipboard adapter doctoring', () => { }; const reactPatch = readRepositoryText(reactPatchPath); const changelog = readRepositoryText(changelogPath); + const readme = readRepositoryText(readmePath); expect(lock).toMatch( /^\s+'@tiptap\/core':\n\s+specifier: 3\.30\.4$/mu, @@ -34,6 +36,7 @@ describe('TipTap SafeClipboard adapter doctoring', () => { expect(doctoring).toContain('TipTap 3.30.4 package family'); expect(doctoring).toContain('packed strict-TypeScript consumer check'); expect(workspace).toContain("'@tiptap/react@3.30.4':"); + expect(manifest.dependencies?.['@floating-ui/dom']).toBe('^1.0.0'); expect(manifest.dependencies?.['@tiptap/y-tiptap']).toBe('3.0.9'); expect(manifest.dependencies?.['prosemirror-model']).toBe('^1.7.1'); expect(manifest.dependencies?.['prosemirror-state']).toBe('^1.2.3'); @@ -52,6 +55,11 @@ describe('TipTap SafeClipboard adapter doctoring', () => { expect(changelog).toContain( 'registered TipTap v2.27.2 ProseMirror plugin adapter', ); + expect(changelog).toContain('## [0.7.0] — 2026-09-05'); + expect(changelog).toContain('public TipTap editor ABI from v2'); + expect(readme).toContain('### Migrate to 0.7.0'); + expect(readme).toContain('do not mix v2 and v3 extensions'); + expect(readme).toContain('needs no stored-document migration'); }); it('binds test-first evidence and distinguishes mutable documentation', () => { diff --git a/tests/package/verify-package.mjs b/tests/package/verify-package.mjs index 5ed3c69bd..7e6762b3c 100644 --- a/tests/package/verify-package.mjs +++ b/tests/package/verify-package.mjs @@ -154,6 +154,7 @@ function verifyConsumerTypes() { `import { createDocumentEnvelopeRevision, DocumentEnvelopeRestoreError, + buildExtensions, markdownToHtml, restoreDocumentEnvelopeBytesIfMatch, restoreDocumentEnvelopeIfMatch, @@ -170,6 +171,7 @@ function verifyConsumerTypes() { type CwlEditorSelectionSnapshot, type DocumentEnvelopeDigestProvider, } from '${packageName}'; +import { Extension, type Editor } from '@tiptap/core'; import { createDocumentAutosaveQueue, type DocumentAutosaveRequestOutcome, @@ -199,6 +201,9 @@ type EditorDocumentChangeCallback = NonNullable< CwlEditorProps['onDocumentChange'] >; declare const editorHandle: CwlEditorHandle; +const hostExtension = Extension.create({ name: 'packedConsumerExtension' }); +const extensions = buildExtensions({ additionalExtensions: [hostExtension] }); +const editor: Editor | null = editorHandle.getEditor(); declare const documentChangeEvent: CwlEditorDocumentChangeEvent; declare const documentSnapshot: CwlEditorDocumentSnapshot; declare const resetEvent: CwlEditorFormResetEvent; @@ -280,6 +285,8 @@ void [ conditionalByteRestore, restoreError, dataUri, + extensions, + editor, editorHandle, documentChangeEvent, documentSnapshot, From 6d51f5cb1df03db7b08250fe4ce84ee0051607ce Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 07:50:53 +0900 Subject: [PATCH 16/18] docs: align 0.7 release authority Signed-off-by: Seongho Bae Commit-Message-Assisted-by: Claude (via Claude Code) --- CHANGELOG.md | 22 +++++++++---------- README.md | 12 +++++----- docs/CONTRACTS.md | 2 +- docs/DOCUMENTATION_FITNESS.md | 5 ++--- docs/PRD.md | 2 +- docs/README.md | 2 +- docs/TRACEABILITY.md | 2 +- docs/UML.md | 2 +- .../0031-editor-design-tokens-storybook.md | 14 ++++++------ docs/adr/README.md | 2 +- docs/design-tokens.md | 6 ++--- docs/doctoring/editor-design-tokens.md | 18 +++++++-------- docs/storybook-inventory.md | 4 ++-- ...autonomousMaintenanceDocumentation.test.ts | 2 ++ src/designTokenDocumentation.test.ts | 21 +++++++----------- 15 files changed, 56 insertions(+), 60 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index e3243a6a2..d47e4b12e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,17 +6,6 @@ Historical release entries from **0.1.0 through 0.5.27** are preserved verbatim ## [Unreleased] -### Added -- Named the repeating editor chrome as a host-facing theme-token catalog and Storybook inventory so hosts can override `--cwl-*` custom properties on `.cwl-editor` after checking WCAG 2.2 contrast, without editing Inkspan internals. Color catalog values now distinguish light, dark, and `@media print` remaps; forced-colors mode is not treated as a token assignment. Hosts can call `getEditorThemeTokenContrast()` to compare inventoried pairs, including `--cwl-accent` on `--cwl-accent-soft`, against the 4.5:1 text threshold via `meetsTextContrast`. - -### Accessibility -- Prepared the active-PR dark active-toolbar accent change from protected-main `#4493f8` to `#58a6ff`, increasing `--cwl-accent` text on `--cwl-accent-soft: #163356` from about 4.13:1 to about 5.06:1 so the candidate default 13px active-button text meets the WCAG 2.2 4.5:1 normal-text threshold; this remains active-PR evidence until protected integration. `getEditorThemeTokenContrast()` checks catalog values, and host overrides must be re-checked with `contrastRatioFromHex(actualForegroundHex, actualBackgroundHex)` using the actual resolved colors. -- Restored a visible `:focus-visible` indicator on the editable textbox, mapped it to `CanvasText` in forced-colors mode, and suppresses that interactive focus chrome under `@media print`; dependency-locked Chromium, Firefox, and WebKit acceptance exercises the packed stylesheet on the real `role="textbox"` surface. - -### Security -- Raised workspace-wide transitive development-tool overrides for `fast-uri`, `nanoid`, and `postcss` to patched minimums, keeping the lockfile audit clean without changing runtime package authority. -- Normalized isolated package-verifier temporary roots before containment checks on macOS. - ## [0.7.0] — 2026-09-05 ### Release @@ -25,10 +14,19 @@ Historical release entries from **0.1.0 through 0.5.27** are preserved verbatim ### Breaking - Upgraded the public TipTap editor ABI from v2 to the coherent TipTap 3.30.4 package family. Hosts that consume `CwlEditorHandle.getEditor()` or pass TipTap extensions to `buildExtensions()` must upgrade those host imports and extensions to v3; v2 and v3 editor graphs must not be mixed. +### Added +- Named the repeating editor chrome as a host-facing theme-token catalog and Storybook inventory so hosts can override `--cwl-*` custom properties on `.cwl-editor` after checking WCAG 2.2 contrast, without editing Inkspan internals. Color catalog values now distinguish light, dark, and `@media print` remaps; forced-colors mode is not treated as a token assignment. Hosts can call `getEditorThemeTokenContrast()` to compare inventoried pairs, including `--cwl-accent` on `--cwl-accent-soft`, against the 4.5:1 text threshold via `meetsTextContrast`. + +### Accessibility +- Raised the shipped dark active-toolbar accent from `#4493f8` to `#58a6ff`, increasing `--cwl-accent` text on `--cwl-accent-soft: #163356` from about 4.13:1 to about 5.06:1 so the default 13px active-button text meets the WCAG 2.2 4.5:1 normal-text threshold. `getEditorThemeTokenContrast()` checks catalog values, and host overrides must be re-checked with `contrastRatioFromHex(actualForegroundHex, actualBackgroundHex)` using the actual resolved colors. +- Restored a visible `:focus-visible` indicator on the editable textbox, mapped it to `CanvasText` in forced-colors mode, and suppresses that interactive focus chrome under `@media print`; dependency-locked Chromium, Firefox, and WebKit acceptance exercises the packed stylesheet on the real `role="textbox"` surface. + ### Migration and rollback -- Upgrade Inkspan and every host-owned TipTap extension as one dependency-lock change, then re-run the host's editor, collaboration, and packed-consumer checks. Before adoption, rollback restores Inkspan 0.6.x and the host TipTap 2 dependency graph together; the document-envelope schema is unchanged and needs no stored-document migration. +- Upgrade Inkspan and every host-owned TipTap extension as one dependency-lock change, then re-run the host's editor, collaboration, and packed-consumer checks. Before adoption, rollback restores the latest verified released Inkspan 0.5.x editor and the host TipTap 2 dependency graph together; an unpublished 0.6.x source candidate is not a rollback artifact. The document-envelope schema is unchanged and needs no stored-document migration. ### Security +- Raised workspace-wide transitive development-tool overrides for `fast-uri`, `nanoid`, and `postcss` to patched minimums, keeping the lockfile audit clean without changing runtime package authority. +- Normalized isolated package-verifier temporary roots before containment checks on macOS. - Patched the TipTap runtime advisory while preserving formatting, collaboration presence, safe-link enforcement, and exact document restore behavior within the new v3 ABI. ## [0.6.0] — 2026-08-10 diff --git a/README.md b/README.md index ce7b2af21..f56402025 100644 --- a/README.md +++ b/README.md @@ -96,11 +96,13 @@ same v3 package family; do not mix v2 and v3 extensions or ProseMirror graphs. Hosts that use only `CwlEditor` props still need to test their editor workflows before adopting the new minor release. -To roll back before adopting 0.7.0, restore Inkspan 0.6.x and the host's TipTap -2 dependencies together. The document-envelope schema is unchanged, so this -rollback needs no stored-document migration. After adopting 0.7.0 APIs, revert -host extension code and dependency locks as one reviewed change rather than -downgrading Inkspan alone. +To roll back before adopting 0.7.0, restore the latest verified released +Inkspan 0.5.x editor and the host's TipTap 2 dependencies together. Do not use +an unpublished 0.6.x source candidate as a rollback target. The document-envelope +schema is unchanged, so this rollback needs no stored-document migration. After +adopting 0.7.0 APIs, revert host extension code and dependency locks as one +reviewed change rather than downgrading +Inkspan alone. ### Quick start diff --git a/docs/CONTRACTS.md b/docs/CONTRACTS.md index 5a62716e5..f61f2b1c9 100644 --- a/docs/CONTRACTS.md +++ b/docs/CONTRACTS.md @@ -152,7 +152,7 @@ Rollback must preserve readable canonical documents and must not require silentl | autosave | local ordering/state, callback contract, validator validation | transport, durable CAS, retry/offline policy, persistence | | collaboration | provider-neutral editor/Yjs binding | provider lifecycle, rooms, identity, authorization, persistence, awareness privacy | | Office rendering | deterministic bounded JSON→artifact conversion | file destination policy, downstream distribution, tenant authorization | -| editor chrome theming (Active PR / Proposed) | named `--cwl-*` tokens, DTCG interchange snapshot, Storybook inventory, inventoried pair contrast including `--cwl-accent` on `--cwl-accent-soft` | host brand CSS, contrast certification, Figma Variables, design-tool sync | +| editor chrome theming | named `--cwl-*` tokens, DTCG interchange snapshot, Storybook inventory, inventoried pair contrast including `--cwl-accent` on `--cwl-accent-soft` | host brand CSS, contrast certification, Figma Variables, design-tool sync | | naruon composition | stable local package/module boundary | authenticated compose transport, tenancy, provider/model policy | | model assistance | deterministic proposal acceptance boundary | provider, prompt/data policy, credentials, human approval | | release evidence | exact four-file draft inventory, package/artifact/digest verification and repository evidence | downstream deployment and operational rollout | diff --git a/docs/DOCUMENTATION_FITNESS.md b/docs/DOCUMENTATION_FITNESS.md index 1fc994f94..21350d6e4 100644 --- a/docs/DOCUMENTATION_FITNESS.md +++ b/docs/DOCUMENTATION_FITNESS.md @@ -56,7 +56,7 @@ Document fitness and implementation maturity are independent. A `present_current | Unified stable registry release train | ADR 0019, protected release workflow and release doctoring | `present_current` | `implemented_on_protected_main` | Stable npm/Office version equality, OIDC Trusted Publishing, exact-artifact publication and post-publication digest verification are source-integrated; live registry publication remains separate operational evidence. | | Framework-neutral Markdown package boundary | ADR 0020, protected `@contextualwisdomlab/cwl-editor/markdown` package subpath and shared policy modules from #114 | `present_current` | `implemented_on_protected_main` | Server/worker consumers can reuse deterministic Markdown/HTML/email/plain-text conversion without evaluating the React/TipTap editor graph. | | CSS paged-media print boundary | ADR 0021, protected `src/styles.css`, packaged stylesheet evidence and real-browser print tests from #116/#127 | `present_current` | `implemented_on_protected_main` | Declarative print output removes screen-only clipping/chrome while preserving authored content without creating a durable PDF service. | -| Editor chrome design tokens / Storybook inventory | ADR 0031, `docs/design-tokens.md`, doctoring, token catalog, and Storybook stories | `present_current` | `implemented_on_active_pr` | Hosts can name, override, and preview repeating toolbar/editor tokens without treating the interchange snapshot as shipped protected-main authority. | +| Editor chrome design tokens / Storybook inventory | ADR 0031, `docs/design-tokens.md`, doctoring, token catalog, and Storybook stories | `present_current` | `implemented_on_protected_main` | Hosts can name, override, and preview repeating toolbar/editor tokens while CSS remains runtime presentation authority. | | Informative DOCX PNG figures | ADR 0022, Office schema/renderer/tests and guidance | `present_current` | `implemented_on_protected_main` | Strict bounded inline PNG figures preserve informative alternative text without remote-resource or arbitrary OOXML authority. | | DOCX bounded rich-text runs | ADR 0023, Office schema/renderer/tests and doctoring | `present_current` | `implemented_on_protected_main` | Ordered bold/italic/underline runs preserve common inline fidelity under one bounded deterministic contract. | | DOCX bounded paragraph alignment | ADR 0024, Office schema/renderer/tests, Office guidance and doctoring | `present_current` | `implemented_on_protected_main` | `paragraph` and `rich_paragraph` preserve explicit left/center/right/justify alignment while omission retains inherited/default behavior. | @@ -81,10 +81,9 @@ Autonomous commercial-maintenance scheduling and no-early-stop execution are con The documentation pack is substantially complete for acquisition review, but repository closure is not documentation closure: -1. The protected manifests now agree at `0.6.0`, while registry operational acceptance remains open under issue #118 because the exact protected release still needs its tag/GitHub Release, live npm/PyPI Trusted Publisher execution, and public artifact digest verification. +1. The active release candidate manifests agree at `0.7.0`, while the verified public editor support line remains `0.5.x`. Registry operational acceptance remains open under issue #118 because the exact protected release still needs its tag/GitHub Release, live npm/PyPI Trusted Publisher execution, and public artifact digest verification. 2. Future protected-source changes must continue to reconcile PRD/TRD/Architecture/ADR/UML/DATA_MODEL/security/test/operability/traceability semantics rather than treating this baseline as permanently complete. 3. Documentation becoming mergeable, green, or protected-merged is never a reason for the commercial loop to stop; the next safe product, release, security, accessibility, package, Office-fidelity, or interoperability lane continues. -4. Hosts still need a named, Storybook-previewable chrome-token catalog so brand theming does not require editing Inkspan internals; that lane is Active PR / Proposed and must not be described as shipped until protected integration. ## Sufficiency decision diff --git a/docs/PRD.md b/docs/PRD.md index 3ccec07c5..d20b19b45 100644 --- a/docs/PRD.md +++ b/docs/PRD.md @@ -147,4 +147,4 @@ Protected `main` is the sole implemented baseline. Open PRs may describe Propose SafeClipboard, real Chromium/Firefox/WebKit release assurance, lifecycle observation, the root security disclosure lifecycle, toolbar shortcut accessibility metadata, SSR/native-form serialization, revision-scoped selection evidence, W3C text-position selector evidence, document-transition evidence, and envelope identity migration routing are implemented on protected `main`. -A named editor-chrome theme-token catalog, DTCG 2025.10 interchange snapshot, and Storybook inventory for repeating toolbar/editor objects are Active PR / Proposed and are not shipped claims until protected integration. Hosts must check inventoried active-chrome contrast (`--cwl-accent` on `--cwl-accent-soft`) in addition to body text. +A named editor-chrome theme-token catalog, DTCG 2025.10 interchange snapshot, and Storybook inventory for repeating toolbar/editor objects are implemented on protected `main`. Hosts must check inventoried active-chrome contrast (`--cwl-accent` on `--cwl-accent-soft`) in addition to body text. diff --git a/docs/README.md b/docs/README.md index d4d24d8da..bae86f2c0 100644 --- a/docs/README.md +++ b/docs/README.md @@ -19,7 +19,7 @@ This directory is the discoverable index for Inkspan's product, technical, secur | [`package-distribution.md`](package-distribution.md) | Buyer-facing public npm package entrypoints, packaged contents, runtime dependency boundaries, and consumer verification | | [`email-output.md`](email-output.md) | Deterministic email fragment/full-document authority, language/direction metadata, accessibility and host-owned transport boundary | | [`print-output.md`](print-output.md) | Browser print/paged-media presentation, accessibility/fidelity limits, host-owned governed-export boundary, and rollback | -| [`design-tokens.md`](design-tokens.md) | Host-facing editor chrome tokens, DTCG 2025.10 interchange snapshot, and Storybook inventory (Active PR / Proposed) | +| [`design-tokens.md`](design-tokens.md) | Protected host-facing editor chrome tokens, DTCG 2025.10 interchange snapshot, and Storybook inventory | | [`UML.md`](UML.md) | Component, sequence, state and authority-flow diagrams | | [`DATA_MODEL.md`](DATA_MODEL.md) | Conceptual evidence/domain model and persistence ownership | | [`THREAT_MODEL.md`](THREAT_MODEL.md) | Trust boundaries, abuse cases, security/privacy controls and residual risks | diff --git a/docs/TRACEABILITY.md b/docs/TRACEABILITY.md index ffe5d86d4..801d0cd40 100644 --- a/docs/TRACEABILITY.md +++ b/docs/TRACEABILITY.md @@ -21,7 +21,7 @@ This record maps durable Inkspan product decisions to authoritative standards, p | Browser clipboard behavior | Security-relevant rich HTML handling requires actual paste-pipeline integration and bounded semantic reconstruction before editor state | WHATWG HTML parsing; W3C Clipboard API | protected-main rich-clipboard unit/integration corpus and SafeClipboard ADR | Protected jsdom/TipTap integration success is not universal browser-engine conformance | | Cross-engine release assurance | The same committed synthetic adversarial corpus runs under required Chromium, Firefox, and WebKit projects; exact package-lock and packed npm artifact SHA-256 digests are required, and only focused standards-grounded safe differences may be admitted | WHATWG HTML Living Standard; W3C Clipboard API and events; Playwright 1.62 release notes and browser/project documentation | ADR 0016, protected-main browser evidence source/workflows, TEST_STRATEGY, OPERABILITY and UML | Protected-main implementation is the release-policy authority; every release candidate must regenerate fresh exact-source/lock/run/browser evidence bound to the exact packed npm artifact SHA-256 and does not claim byte-identical browser serialization or branded enterprise-policy coverage | | CSS paged-media output | Shipped editor CSS has a declarative print boundary that removes interactive chrome and screen clipping while preserving authored document flow and bounded fragmentation behavior | W3C Media Queries Level 3; CSS Fragmentation Level 3; CSS Paged Media Level 3 as tracked draft input | protected-main #116 packaged stylesheet, real-browser print-media evidence, ADR 0021, print doctoring and tests | `implemented_on_protected_main`; browser print styling does not create a durable PDF service, page-number/header authority, persistence, signing, or PDF-conformance claim | -| Editor chrome design tokens | Repeating toolbar/editor surfaces share named `--cwl-*` custom properties; hosts override those properties on `.cwl-editor` and preview them in Storybook | Design Tokens Format Module 2025.10; WCAG 2.2 contrast including inventoried `--cwl-accent` on `--cwl-accent-soft`; Storybook React/Vite | Active-PR doctoring `docs/doctoring/editor-design-tokens.md`, operator guide, ADR 0031, token catalog tests, and Storybook inventory | Proposed until protected `main`; the interchange snapshot is not complete DTCG conformance, Figma Variables sync, or a host WCAG certification | +| Editor chrome design tokens | Repeating toolbar/editor surfaces share named `--cwl-*` custom properties; hosts override those properties on `.cwl-editor` and preview them in Storybook | Design Tokens Format Module 2025.10; WCAG 2.2 contrast including inventoried `--cwl-accent` on `--cwl-accent-soft`; Storybook React/Vite | Protected doctoring `docs/doctoring/editor-design-tokens.md`, operator guide, ADR 0031, token catalog tests, and Storybook inventory | Implemented on protected `main`; the interchange snapshot is not complete DTCG conformance, Figma Variables sync, or a host WCAG certification | | Editor integration | Public behavior must exercise the actual TipTap/ProseMirror integration path, not an inert extension field or test-only hook | official TipTap and ProseMirror documentation for the locked dependency line | integration tests and package consumers | Inkspan does not claim compatibility with untested major-version integration semantics | | Collaboration | Inkspan provides provider-neutral editor/Yjs bindings; host owns provider lifecycle, room authorization, awareness privacy, persistence and audit | official Yjs/provider documentation plus Inkspan public contract | collaboration tests and architecture ownership matrix | No network-provider or tenant-authorization authority is implied | | Secure development | Security controls are developed test-first, with exact-head scanning/review/package evidence and root-cause regression | NIST SP 800-218 SSDF 1.1 | CI/security/SAST/package/provenance gates, doctoring and regression history | Repository evidence is not a claim of complete SSDF organizational conformance | diff --git a/docs/UML.md b/docs/UML.md index de4e20d31..2c792da0f 100644 --- a/docs/UML.md +++ b/docs/UML.md @@ -38,7 +38,7 @@ flowchart LR The host owns transport, authentication, authorization, tenant isolation, persistence, credentials, provider lifecycle, retention, deployment, durable audit, and model-use policy. Inkspan owns deterministic local editor/conversion/evidence behavior only. -A named editor-chrome theme-token catalog and Storybook inventory are Active PR / Proposed. Hosts override `--cwl-*` on `.cwl-editor` after checking WCAG 2.2 contrast for body text and active toolbar text (`--cwl-accent` on `--cwl-accent-soft`). CSS remains runtime presentation authority. Storybook previews a class-level chrome sample (including `:focus-visible`) and a live shipped Toolbar. It does not mount `CwlEditor`. Print-media remaps live in `@media print`; forced-colors mode does not assign those custom properties. Figma Variables, brand certification, and design-tool sync remain host-owned. +A named editor-chrome theme-token catalog and Storybook inventory are implemented on protected `main`. Hosts override `--cwl-*` on `.cwl-editor` after checking WCAG 2.2 contrast for body text and active toolbar text (`--cwl-accent` on `--cwl-accent-soft`). CSS remains runtime presentation authority. Storybook previews a class-level chrome sample (including `:focus-visible`) and a live shipped Toolbar. It does not mount `CwlEditor`. Print-media remaps live in `@media print`; forced-colors mode does not assign those custom properties. Figma Variables, brand certification, and design-tool sync remain host-owned. ## Rich paste sequence diff --git a/docs/adr/0031-editor-design-tokens-storybook.md b/docs/adr/0031-editor-design-tokens-storybook.md index 2e3cfdb04..686c8152b 100644 --- a/docs/adr/0031-editor-design-tokens-storybook.md +++ b/docs/adr/0031-editor-design-tokens-storybook.md @@ -1,12 +1,12 @@ # ADR 0031: Editor chrome design tokens and Storybook inventory -Status: Proposed +Status: Accepted ## Context -Inkspan ships repeating toolbar buttons, groups, and editor chrome styled through `--cwl-*` custom properties. Hosts already re-theme by overriding those properties, but the names, light/dark/print values, and buyer next action live only inside protected `src/styles.css`. There is no protected-main typed catalog, Design Tokens Format Module interchange snapshot, or Storybook inventory of the repeating objects; those capabilities are proposed on this active PR. +Inkspan ships repeating toolbar buttons, groups, and editor chrome styled through `--cwl-*` custom properties. Hosts can re-theme them through the protected typed catalog, Design Tokens Format Module interchange snapshot, and Storybook inventory while `src/styles.css` remains runtime presentation authority. -Inventorying the actual active-toolbar foreground/background pair also exposed a product-owned accessibility defect: protected main's dark `--cwl-accent: #4493f8` on `--cwl-accent-soft: #163356` produces about 4.13:1 for 13px active-button text, below the WCAG 2.2 4.5:1 normal-text threshold. Treating that shipped-default failure as a host override responsibility would contradict Inkspan's ownership of its default presentation. +Inventorying the actual active-toolbar foreground/background pair exposed and repaired a product-owned accessibility defect: the former dark `--cwl-accent: #4493f8` on `--cwl-accent-soft: #163356` produced about 4.13:1 for 13px active-button text, below the WCAG 2.2 4.5:1 normal-text threshold. Protected `main` now uses `#58a6ff`, producing about 5.06:1. ## Alternatives considered @@ -18,7 +18,7 @@ Inventorying the actual active-toolbar foreground/background pair also exposed a ## Decision -If integrated, Inkspan will publish a host-facing theme-token catalog for nine inventoried chrome tokens, a Design Tokens Format Module 2025.10 interchange snapshot, and a Storybook inventory of repeating toolbar/editor objects. Inkspan's inventoried normal-text pairs will be required to meet the WCAG 2.2 4.5:1 threshold in the resulting protected light/dark/print defaults; the active-PR candidate therefore uses `#58a6ff` on `#163356` for dark active-toolbar text, about 5.06:1. `getEditorThemeTokenContrast()` evaluates only the catalog values for a named scheme. Hosts overriding `--cwl-*` on `.cwl-editor` must pass their actual resolved foreground/background hex values to `contrastRatioFromHex()` and re-check their resulting body and active-toolbar pairs. Unknown token names fail closed. No Figma, network, persistence, credential, or model authority is added. +Inkspan publishes a host-facing theme-token catalog for nine inventoried chrome tokens, a Design Tokens Format Module 2025.10 interchange snapshot, and a Storybook inventory of repeating toolbar/editor objects. Inkspan's inventoried normal-text pairs must meet the WCAG 2.2 4.5:1 threshold in protected light/dark/print defaults; the dark active-toolbar pair uses `#58a6ff` on `#163356`, about 5.06:1. `getEditorThemeTokenContrast()` evaluates only the catalog values for a named scheme. Hosts overriding `--cwl-*` on `.cwl-editor` must pass their actual resolved foreground/background hex values to `contrastRatioFromHex()` and re-check their resulting body and active-toolbar pairs. Unknown token names fail closed. No Figma, network, persistence, credential, or model authority is added. ## Consequences and ownership trade-offs @@ -34,12 +34,12 @@ The proposed catalog contains only public presentation values. It does not carry ## Compatibility and migration -The catalog is additive if integrated. Existing CSS overrides on `.cwl-editor` continue to work. The active-PR candidate changes the dark default accent from `#4493f8` to `#58a6ff`; hosts that already override `--cwl-accent` are unaffected by that candidate default-value change but remain responsible for validating their actual custom pair. A later CSS token addition or default-value change must update the catalog, directly affected documentation/tests, and this ADR together. +The catalog is additive. Existing CSS overrides on `.cwl-editor` continue to work. Protected `main` changed the dark default accent from `#4493f8` to `#58a6ff`; hosts that already override `--cwl-accent` are unaffected but remain responsible for validating their actual custom pair. A later CSS token addition or default-value change must update the catalog, directly affected documentation/tests, and this ADR together. ## Verification and acceptance evidence -Required evidence includes token-catalog tests against `src/styles.css`, deterministic contrast assertions for inventoried normal-text pairs, resolved-hex override guidance tests, documentation-contract tests, Storybook inventory stories for toolbar button states and token swatches, and exact-head CI/coverage/package/security gates on the unchanged head. The accessibility regression must fail against protected main's `#4493f8`/`#163356` dark active pair and pass against the active-PR `#58a6ff`/`#163356` pair. This ADR stays Proposed until protected integration. +Acceptance evidence includes token-catalog tests against `src/styles.css`, deterministic contrast assertions for inventoried normal-text pairs, resolved-hex override guidance tests, documentation-contract tests, Storybook inventory stories for toolbar button states and token swatches, and exact-head CI/coverage/package/security gates. The accessibility regression failed against the former `#4493f8`/`#163356` dark active pair and passes against protected `main`'s `#58a6ff`/`#163356` pair. ## Rollback or supersession -Before integration, rollback removes the catalog export, Storybook inventory/config, operator/doctoring records, and this ADR together. After integration, reverting only the compliant dark accent while retaining the active-text contrast requirement is not a valid partial rollback. Supersession requires a new ADR if CSS ceases to be runtime presentation authority or if a design-tool sync contract is accepted. +Rollback removes the catalog export, Storybook inventory/config, operator/doctoring records, and this ADR together. Reverting only the compliant dark accent while retaining the active-text contrast requirement is not a valid partial rollback. Supersession requires a new ADR if CSS ceases to be runtime presentation authority or if a design-tool sync contract is accepted. diff --git a/docs/adr/README.md b/docs/adr/README.md index b797812eb..0140dd02f 100644 --- a/docs/adr/README.md +++ b/docs/adr/README.md @@ -32,7 +32,7 @@ This index records durable architectural decisions. Protected-main implementatio | [0024](0024-bounded-docx-paragraph-alignment.md) | Accepted | Bounded paragraph alignment in deterministic DOCX output | | [0025](0025-bounded-docx-heading-alignment.md) | Accepted | Bounded heading alignment in deterministic DOCX output | | [0026](0026-bounded-docx-external-hyperlinks.md) | Accepted | Bounded external hyperlinks in deterministic DOCX rich text | -| [0031](0031-editor-design-tokens-storybook.md) | Proposed | Editor chrome design tokens and Storybook inventory | +| [0031](0031-editor-design-tokens-storybook.md) | Accepted | Editor chrome design tokens and Storybook inventory | ## Decision discipline diff --git a/docs/design-tokens.md b/docs/design-tokens.md index b1056994f..d9bf2299c 100644 --- a/docs/design-tokens.md +++ b/docs/design-tokens.md @@ -1,8 +1,8 @@ # Editor chrome design tokens -Status: Active PR / Proposed +Status: Implemented on protected main -Use this catalog when you need to re-theme Inkspan's repeating toolbar and editor chrome. Protected-main CSS defaults remain the shipped presentation baseline; the Active-PR repaired dark active-toolbar pair uses `--cwl-accent: #58a6ff` on `--cwl-accent-soft: #163356` and measures about 5.06:1. When a host overrides any color token, re-check WCAG 2.2 contrast for both body text (`--cwl-fg` on `--cwl-bg`) and active toolbar text (`--cwl-accent` on `--cwl-accent-soft`). Do not edit Inkspan internals. +Use this catalog when you need to re-theme Inkspan's repeating toolbar and editor chrome. Protected-main CSS defaults remain the shipped presentation baseline; the shipped dark active-toolbar pair uses `--cwl-accent: #58a6ff` on `--cwl-accent-soft: #163356` and measures about 5.06:1. When a host overrides any color token, re-check WCAG 2.2 contrast for both body text (`--cwl-fg` on `--cwl-bg`) and active toolbar text (`--cwl-accent` on `--cwl-accent-soft`). Do not edit Inkspan internals. `getEditorThemeTokenContrast()` checks only Inkspan catalog values for the requested light/dark/print scheme; it does not read resolved host CSS. After an override, obtain the actual resolved hex colors from the host theme and call `contrastRatioFromHex(actualForegroundHex, actualBackgroundHex)` before shipping that theme. @@ -35,7 +35,7 @@ void tokens; void dtcgGroup; ``` -The default-theme checks above are active-PR product evidence, not protected-main shipped evidence or a host WCAG certification. The stylesheet remains runtime presentation authority. `toDesignTokenFormatGroup()` is an interchange snapshot aligned to Design Tokens Format Module 2025.10; it is not complete DTCG conformance or Figma Variables sync. +The default-theme checks above are protected-main product evidence, not a host WCAG certification. The stylesheet remains runtime presentation authority. `toDesignTokenFormatGroup()` is an interchange snapshot aligned to Design Tokens Format Module 2025.10; it is not complete DTCG conformance or Figma Variables sync. Preview the repeating objects in Storybook (`pnpm storybook`) using the inventory in [`storybook-inventory.md`](storybook-inventory.md). diff --git a/docs/doctoring/editor-design-tokens.md b/docs/doctoring/editor-design-tokens.md index 178468106..1d205d5a8 100644 --- a/docs/doctoring/editor-design-tokens.md +++ b/docs/doctoring/editor-design-tokens.md @@ -1,21 +1,21 @@ # Doctoring record: editor chrome design tokens **Date:** 2026-08-16 -**Status:** Active PR / Proposed +**Status:** Implemented on protected main **Decision owner:** ContextualWisdomLab **Scope:** Named `--cwl-*` theme tokens, DTCG 2025.10 interchange snapshot, and Storybook inventory for repeating toolbar/editor objects. ## Buyer-visible gap -Hosts embed Inkspan and need to match brand color, radius, and font without forking `src/styles.css`. The protected stylesheet already uses `--cwl-*` custom properties, but buyers have no protected-main typed catalog, interchange snapshot, or Storybook inventory of the repeating toolbar button and editor chrome. Theme work therefore still requires reading CSS internals until this active PR integrates. +Hosts embed Inkspan and need to match brand color, radius, and font without forking `src/styles.css`. Protected `main` provides a typed catalog, interchange snapshot, and Storybook inventory of repeating toolbar and editor chrome while the stylesheet remains runtime authority. -The same inventory exposed an Inkspan-owned protected-main default-theme defect rather than a host-only customization problem: dark `.cwl-tb-btn.is-active` renders `--cwl-accent` text on `--cwl-accent-soft` at about 4.13:1, below the WCAG 2.2 4.5:1 threshold for normal text. This Active PR now carries dark `--cwl-accent: #58a6ff` against unchanged `--cwl-accent-soft: #163356`, producing about 5.06:1 for the active toolbar pair. That repaired value is active-PR evidence, not shipped protected-main truth, until integration. Host overrides must still re-check their own resulting pairs. +The same inventory exposed an Inkspan-owned default-theme defect rather than a host-only customization problem: the former dark `.cwl-tb-btn.is-active` pair rendered `--cwl-accent: #4493f8` on `--cwl-accent-soft: #163356` at about 4.13:1, below the WCAG 2.2 4.5:1 threshold for normal text. Protected `main` now ships dark `--cwl-accent: #58a6ff` against unchanged `--cwl-accent-soft: #163356`, producing about 5.06:1. Host overrides must still re-check their own resulting pairs. If contrast fails after a re-theme, override only the named tokens on `.cwl-editor` and re-check WCAG 2.2 text contrast for `--cwl-fg` on `--cwl-bg` and `--cwl-accent` on `--cwl-accent-soft`. `getEditorThemeTokenContrast()` reports Inkspan's catalog baseline only; after a host override, pass the actual resolved pair to `contrastRatioFromHex(actualForegroundHex, actualBackgroundHex)` before shipping. Do not disable forced-colors overrides. ## Decision -If integrated: +Protected implementation: 1. Keep `src/styles.css` as runtime presentation authority. 2. Publish `listEditorThemeTokens()` / `getEditorThemeToken()` / `getEditorThemeTokenContrast()` / `contrastRatioFromHex()` / `toDesignTokenFormatGroup()` as a host-facing catalog of the nine inventoried chrome tokens and theme evidence: the name-based contrast helper evaluates the catalog baseline, while the hex helper evaluates actual resolved host colors. @@ -26,22 +26,22 @@ If integrated: ## Standards rationale -The Design Tokens Format Module 2025.10 defines a vendor-neutral JSON interchange for token groups, `$type`, and `$value` (Design Tokens Community Group, 2025). This active PR emits a snapshot of Inkspan CSS custom properties in that shape. The report is a W3C Community Final Specification, not a W3C Standard, so this record does not claim W3C standardization or complete DTCG conformance. +The Design Tokens Format Module 2025.10 defines a vendor-neutral JSON interchange for token groups, `$type`, and `$value` (Design Tokens Community Group, 2025). Inkspan emits a snapshot of its CSS custom properties in that shape. The report is a W3C Community Final Specification, not a W3C Standard, so this record does not claim W3C standardization or complete DTCG conformance. -WCAG 2.2 requires at least 4.5:1 contrast for normal text under Success Criterion 1.4.3 and at least 3:1 for meaningful user-interface component boundaries/states under Success Criterion 1.4.11 (World Wide Web Consortium, 2024). The protected-main failing default is therefore an Inkspan-owned defect; this active PR repairs it at Inkspan's presentation boundary while host overrides remain the host's contrast responsibility. Storybook's React/Vite preview is the proposed inventory surface for repeating chrome (Storybook, n.d.). +WCAG 2.2 requires at least 4.5:1 contrast for normal text under Success Criterion 1.4.3 and at least 3:1 for meaningful user-interface component boundaries/states under Success Criterion 1.4.11 (World Wide Web Consortium, 2024). Inkspan repaired its failing default at the protected presentation boundary while host overrides remain the host's contrast responsibility. Storybook's React/Vite preview inventories repeating chrome (Storybook, n.d.). ## Test-first evidence - Original RED: `src/designTokens.test.ts` failed because `./designTokens.js` did not exist. -- Initial GREEN: the active-PR catalog lists nine inventoried tokens, aligns light/dark/print color values with the matching `src/styles.css` media blocks, reports WCAG 2.2 contrast for inventoried color pairs, rejects unknown names without reflecting caller input, and emits a DTCG 2025.10 group. +- Initial GREEN: the catalog lists nine inventoried tokens, aligns light/dark/print color values with the matching `src/styles.css` media blocks, reports WCAG 2.2 contrast for inventoried color pairs, rejects unknown names without reflecting caller input, and emits a DTCG 2025.10 group. - Accessibility RED: exact test-only head `a831359d1509811ab8777e7356f6ebd5f251b5cf` changed the active-chrome contract to require the dark `--cwl-accent` / `--cwl-accent-soft` pair to meet 4.5:1. The protected-main values remained `#4493f8` on `#163356` (about 4.13:1), so the new expectation could not pass without a real default-theme change. -- Accessibility GREEN: the active-PR dark `--cwl-accent` is `#58a6ff` in both the typed catalog and runtime stylesheet; against unchanged `#163356` it measures about 5.06:1 and `meetsTextContrast` is true. +- Accessibility GREEN: the protected dark `--cwl-accent` is `#58a6ff` in both the typed catalog and runtime stylesheet; against unchanged `#163356` it measures about 5.06:1 and `meetsTextContrast` is true. - Override-truth RED: exact-head CI `32149806678` / build-test `95752733876` proved the documentation and API action text still conflated catalog-token contrast with resolved host override contrast. - Override-truth repair: `getEditorThemeTokenContrast()` is explicitly catalog-only and custom host themes are checked with `contrastRatioFromHex()` using the actual resolved colors. ## Residual risk -Print media still remaps the color tokens after a host override. Forced-colors mode only restyles the toolbar focus outline to `CanvasText`; it does not assign `--cwl-*` values. The active-PR repaired dark `.cwl-tb-btn.is-active` pair (`--cwl-accent` on `--cwl-accent-soft`) meets the WCAG 2.2 4.5:1 normal-text threshold and also exceeds the 3:1 non-text threshold; protected main remains at the failing pre-repair pair until integration. `getEditorThemeTokenContrast()` reports only that catalog evidence; after overriding either token, hosts must call `contrastRatioFromHex(actualForegroundHex, actualBackgroundHex)` with the actual resolved values because custom values can reintroduce a contrast failure. The font token snapshot splits a CSS font-family list and does not execute CSS. Storybook success is not Chromium/Firefox/WebKit release evidence. +Print media still remaps the color tokens after a host override. Forced-colors mode only restyles the toolbar focus outline to `CanvasText`; it does not assign `--cwl-*` values. The protected dark `.cwl-tb-btn.is-active` pair (`--cwl-accent` on `--cwl-accent-soft`) meets the WCAG 2.2 4.5:1 normal-text threshold and also exceeds the 3:1 non-text threshold. `getEditorThemeTokenContrast()` reports only that catalog evidence; after overriding either token, hosts must call `contrastRatioFromHex(actualForegroundHex, actualBackgroundHex)` with the actual resolved values because custom values can reintroduce a contrast failure. The font token snapshot splits a CSS font-family list and does not execute CSS. Storybook success is not Chromium/Firefox/WebKit release evidence. ## Rollback diff --git a/docs/storybook-inventory.md b/docs/storybook-inventory.md index 239e40f69..87818c7a5 100644 --- a/docs/storybook-inventory.md +++ b/docs/storybook-inventory.md @@ -1,8 +1,8 @@ # Storybook inventory -Status: Active PR / Proposed +Status: Implemented on protected main -Run `pnpm storybook` to preview repeating Inkspan chrome before you override tokens in a host. **Active-PR repaired defaults require no host override for the inventoried active-toolbar contrast pair; protected main remains the pre-repair shipped baseline until integration.** Override tokens only when re-theming, and re-check the resulting host palette. The button-state story is a class-level chrome sample. **Editor Chrome / Live Toolbar** mounts the shipped Toolbar component so a token change is visible on the same object buyers already use; the Storybook story and repaired accent remain Active PR / Proposed. These stories do not mount `CwlEditor`. +Run `pnpm storybook` to preview repeating Inkspan chrome before you override tokens in a host. **Shipped defaults require no host override for the inventoried active-toolbar contrast pair.** Override tokens only when re-theming, and re-check the resulting host palette. The button-state story is a class-level chrome sample. **Editor Chrome / Live Toolbar** mounts the shipped Toolbar component so a token change is visible on the same object buyers already use. These stories do not mount `CwlEditor`. | Story | Repeating object | Host next action | | --- | --- | --- | diff --git a/src/autonomousMaintenanceDocumentation.test.ts b/src/autonomousMaintenanceDocumentation.test.ts index 6f7a1789e..b4c4b6dda 100644 --- a/src/autonomousMaintenanceDocumentation.test.ts +++ b/src/autonomousMaintenanceDocumentation.test.ts @@ -46,8 +46,10 @@ describe('autonomous maintenance and acquisition documentation', () => { it('keeps release source readiness separate from registry operational acceptance', () => { const assessment = repositoryFile(assessmentPath); + const fitness = repositoryFile('docs/DOCUMENTATION_FITNESS.md'); expect(assessment).toContain('protected manifests agree at `0.6.0`'); + expect(fitness).toContain('release candidate manifests agree at `0.7.0`'); expect(assessment).toContain( 'Release-note reconciliation is protected through PR #138', ); diff --git a/src/designTokenDocumentation.test.ts b/src/designTokenDocumentation.test.ts index bfd752e21..2615fd7c7 100644 --- a/src/designTokenDocumentation.test.ts +++ b/src/designTokenDocumentation.test.ts @@ -22,8 +22,8 @@ describe('editor design-token documentation contract', () => { const adr = repositoryFile('docs/adr/0031-editor-design-tokens-storybook.md'); expect(index).toContain('[`design-tokens.md`](design-tokens.md)'); - expect(adrIndex).toContain('[0031](0031-editor-design-tokens-storybook.md) | Proposed'); - expect(repositoryFile('docs/UML.md')).toContain('Active PR / Proposed'); + expect(adrIndex).toContain('[0031](0031-editor-design-tokens-storybook.md) | Accepted'); + expect(repositoryFile('docs/UML.md')).toContain('implemented on protected `main`'); expect(repositoryFile('docs/UML.md')).toContain('--cwl-*'); expect(existsSync(repositoryPath('docs/adr/0027-editor-design-tokens-storybook.md'))).toBe( false, @@ -33,8 +33,7 @@ describe('editor design-token documentation contract', () => { expect(doctoring).toContain('ADR 0031'); expect(doctoring).not.toContain('ADR 0027'); expect(operatorGuide).toContain('When a host overrides any color token'); - expect(operatorGuide).toContain('Active-PR repaired dark active-toolbar pair uses'); - expect(operatorGuide).not.toContain('shipped dark active-toolbar pair now uses'); + expect(operatorGuide).toContain('shipped dark active-toolbar pair uses'); expect(operatorGuide).toContain('getEditorThemeTokenContrast'); expect(operatorGuide).toContain("getEditorThemeTokenContrast('cwl-accent', 'cwl-accent-soft', 'dark')"); expect(operatorGuide).toContain('`getEditorThemeTokenContrast()` checks only Inkspan catalog values'); @@ -50,13 +49,11 @@ describe('editor design-token documentation contract', () => { expect(inventory).toContain('Editor Chrome / Live Toolbar'); expect(inventory).toContain('shipped Toolbar'); expect(inventory).toContain(':focus-visible'); - expect(inventory).toContain('Active-PR repaired defaults require no host override'); - expect(inventory).not.toContain('Shipped defaults require no host override'); + expect(inventory).toContain('Shipped defaults require no host override'); expect(inventory).toContain('If re-theming, override `--cwl-accent`'); expect(doctoring).toContain('cwl-accent-soft'); expect(doctoring).toContain('meets the WCAG 2.2 4.5:1'); - expect(doctoring).toContain('This Active PR now carries dark `--cwl-accent: #58a6ff`'); - expect(doctoring).not.toContain('Inkspan now ships dark `--cwl-accent: #58a6ff`'); + expect(doctoring).toContain('Protected `main` now ships dark `--cwl-accent: #58a6ff`'); expect(doctoring).toContain('host-facing catalog of the nine inventoried chrome tokens'); expect(doctoring).not.toContain('host-facing catalog of the nine shipped chrome tokens'); expect(doctoring).toContain('producing about 5.06:1'); @@ -71,12 +68,10 @@ describe('editor design-token documentation contract', () => { ); expect(doctoring).toContain('https://www.w3.org/TR/WCAG22/'); expect(doctoring).toContain('https://storybook.js.org/docs/get-started/frameworks/react-vite'); - expect(adr).toContain('Status: Proposed'); - expect(adr).toContain('If integrated, Inkspan will publish a host-facing theme-token catalog'); - expect(adr).not.toContain('Inkspan publishes a host-facing theme-token catalog'); + expect(adr).toContain('Status: Accepted'); + expect(adr).toContain('Inkspan publishes a host-facing theme-token catalog'); expect(changelog).toContain('Named the repeating editor chrome as a host-facing theme-token catalog'); - expect(changelog).toContain('Prepared the active-PR dark active-toolbar accent'); - expect(changelog).not.toContain('Raised the shipped dark active-toolbar accent'); + expect(changelog).toContain('Raised the shipped dark active-toolbar accent'); expect(repositoryFile('.storybook/main.ts')).toContain("@storybook/react-vite"); expect(repositoryFile('stories/EditorChrome.stories.tsx')).toContain('cwl-tb-btn'); expect(repositoryFile('stories/EditorChrome.stories.tsx')).toContain('autoFocus'); From ac0b7bd0db3282b60095f24145f769243aae5178 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 07:58:02 +0900 Subject: [PATCH 17/18] fix: identify TipTap v3 in demo Signed-off-by: Seongho Bae Commit-Message-Assisted-by: Claude (via Claude Code) --- demo/App.tsx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/demo/App.tsx b/demo/App.tsx index d88d4279f..8aba7de11 100644 --- a/demo/App.tsx +++ b/demo/App.tsx @@ -3,7 +3,7 @@ import { CwlEditor, type EditorMode } from '../src/index.js'; const SAMPLE_MD = `# Inkspan -A **commercial-grade** Markdown + HTML editor built on TipTap v2, with +A **commercial-grade** Markdown + HTML editor built on TipTap v3, with bundled offline fonts for five scripts. ## Multilingual (bundled Noto Sans, no network) From 637b910d25dabb363e40d535c6d89f4a5beb8c6d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Sat, 5 Sep 2026 08:01:42 +0900 Subject: [PATCH 18/18] test: tighten release contract guards Signed-off-by: Seongho Bae Commit-Message-Assisted-by: Claude (via Claude Code) --- src/designTokenDocumentation.test.ts | 6 ++++++ tests/package/verify-package.mjs | 4 ++-- 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/src/designTokenDocumentation.test.ts b/src/designTokenDocumentation.test.ts index 2615fd7c7..32b16725c 100644 --- a/src/designTokenDocumentation.test.ts +++ b/src/designTokenDocumentation.test.ts @@ -34,6 +34,7 @@ describe('editor design-token documentation contract', () => { expect(doctoring).not.toContain('ADR 0027'); expect(operatorGuide).toContain('When a host overrides any color token'); expect(operatorGuide).toContain('shipped dark active-toolbar pair uses'); + expect(operatorGuide).not.toContain('Active-PR repaired dark active-toolbar pair uses'); expect(operatorGuide).toContain('getEditorThemeTokenContrast'); expect(operatorGuide).toContain("getEditorThemeTokenContrast('cwl-accent', 'cwl-accent-soft', 'dark')"); expect(operatorGuide).toContain('`getEditorThemeTokenContrast()` checks only Inkspan catalog values'); @@ -50,10 +51,12 @@ describe('editor design-token documentation contract', () => { expect(inventory).toContain('shipped Toolbar'); expect(inventory).toContain(':focus-visible'); expect(inventory).toContain('Shipped defaults require no host override'); + expect(inventory).not.toContain('Active-PR repaired defaults require no host override'); expect(inventory).toContain('If re-theming, override `--cwl-accent`'); expect(doctoring).toContain('cwl-accent-soft'); expect(doctoring).toContain('meets the WCAG 2.2 4.5:1'); expect(doctoring).toContain('Protected `main` now ships dark `--cwl-accent: #58a6ff`'); + expect(doctoring).not.toContain('This Active PR now carries dark `--cwl-accent: #58a6ff`'); expect(doctoring).toContain('host-facing catalog of the nine inventoried chrome tokens'); expect(doctoring).not.toContain('host-facing catalog of the nine shipped chrome tokens'); expect(doctoring).toContain('producing about 5.06:1'); @@ -69,9 +72,12 @@ describe('editor design-token documentation contract', () => { expect(doctoring).toContain('https://www.w3.org/TR/WCAG22/'); expect(doctoring).toContain('https://storybook.js.org/docs/get-started/frameworks/react-vite'); expect(adr).toContain('Status: Accepted'); + expect(adr).not.toContain('Status: Proposed'); expect(adr).toContain('Inkspan publishes a host-facing theme-token catalog'); + expect(adr).not.toContain('If integrated, Inkspan will publish a host-facing theme-token catalog'); expect(changelog).toContain('Named the repeating editor chrome as a host-facing theme-token catalog'); expect(changelog).toContain('Raised the shipped dark active-toolbar accent'); + expect(changelog).not.toContain('Prepared the active-PR dark active-toolbar accent'); expect(repositoryFile('.storybook/main.ts')).toContain("@storybook/react-vite"); expect(repositoryFile('stories/EditorChrome.stories.tsx')).toContain('cwl-tb-btn'); expect(repositoryFile('stories/EditorChrome.stories.tsx')).toContain('autoFocus'); diff --git a/tests/package/verify-package.mjs b/tests/package/verify-package.mjs index 7e6762b3c..7ec532d9e 100644 --- a/tests/package/verify-package.mjs +++ b/tests/package/verify-package.mjs @@ -128,8 +128,8 @@ function verifyPackedFiles(filePaths) { const reactDeclarationImports = [...filePaths] .filter((filePath) => filePath.endsWith('.d.ts')) .filter((filePath) => - readFileSync(join(repositoryRoot, filePath), 'utf8').includes( - "from '@tiptap/react'", + /["']@tiptap\/react(?:\/[^"']*)?["']/u.test( + readFileSync(join(repositoryRoot, filePath), 'utf8'), ), ); assert.deepEqual(