Skip to content

Keep html-to-image at 1.11.11 - #129

Merged
Isma-L154 merged 1 commit into
mainfrom
deps/pin-html-to-image
Sep 24, 2026
Merged

Isma-L154 merged 1 commit into
mainfrom
deps/pin-html-to-image

Conversation

@Isma-L154

Copy link
Copy Markdown
Owner

Closes #128.

Summary

Dependabot now ignores html-to-image versions above 1.11.11.

Why

#127 (1.11.13) passed CI, but when I exported the starter diagram with it, the edge paths were missing: the to internet arrow kept its label and arrowhead, but the line was gone. React Flow's download-image guide pins 1.11.11 for this reason (#119). The E2E test checks the PNG file (signature, size), not what is drawn in it, so CI cannot catch the regression.

Security considerations

If a security fix ever lands above 1.11.11, this rule has to be revisited deliberately; Dependabot security alerts are not affected by ignore.

1.11.13 (#127) passed CI but its PNG export drops edge paths, the
regression React Flow's guide warns about for later versions. Tell
Dependabot to leave it alone.
@github-actions

Copy link
Copy Markdown

Preview: https://b02c2cd6-terravisual.ilsproj.workers.dev

Security headers were verified against this deployment.

@Isma-L154
Isma-L154 merged commit 15df82f into main Sep 24, 2026
7 checks passed
@Isma-L154
Isma-L154 deleted the deps/pin-html-to-image branch September 24, 2026 03:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Keep html-to-image at 1.11.11: later versions drop edges from the PNG export

1 participant