Fix dependency update checks and source launcher cleanup - #23
Merged
Merged
Conversation
Bumps the npm-major group with 4 updates: [mermaid](https://github.com/mermaid-js/mermaid), [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react), [electron](https://github.com/electron/electron) and [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). Updates `mermaid` from 11.17.2 to 12.0.0 - [Release notes](https://github.com/mermaid-js/mermaid/releases) - [Commits](https://github.com/mermaid-js/mermaid/compare/mermaid@11.17.2...mermaid@12.0.0) Updates `@vitejs/plugin-react` from 5.2.0 to 6.1.1 - [Release notes](https://github.com/vitejs/vite-plugin-react/releases) - [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.1.1/packages/plugin-react) Updates `electron` from 41.10.7 to 44.4.3 - [Release notes](https://github.com/electron/electron/releases) - [Commits](electron/electron@v41.10.7...v44.4.3) Updates `vite` from 7.3.6 to 8.3.0 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/create-vite@8.3.0/packages/vite) --- updated-dependencies: - dependency-name: mermaid dependency-version: 12.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-major - dependency-name: "@vitejs/plugin-react" dependency-version: 6.1.1 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-major - dependency-name: electron dependency-version: 44.4.3 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-major - dependency-name: vite dependency-version: 8.3.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-major ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
deleted the
dependabot/npm_and_yarn/npm-major-30f0319fbd
branch
September 23, 2026 20:20
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Old dependency proposals stopped at npm audit before tests because their obsolete lockfiles contained vulnerable packages. The new major group also introduced vulnerable lodash-es through Mermaid 12. This update starts from current main, keeps Mermaid 11.17.2 and Electron 41, updates React, Vite and Playwright, raises electron-builder’s minimum to the tested version, and regenerates a lockfile with zero audit findings.
Source launchers consistently require Node.js 22.12 or newer. Development and preview signal handlers remain registered until cleanup finishes after Rolldown loads, and the build helper asks the user to close a running app. The renderer uses a stable HMR context reference so CodeQL can parse its startup code.
Validation:
a62e40ad: 422 CI tests, 415 passed, seven platform/runtime skips, zero failures; audit, release preflight, build and Electron smoke pass.a62e40adextractssrc/main.jsxand completes queries/upload with no syntax diagnostic. The PR overlay, which restored main’s cached base, still reported the old line and column; this full analysis verifies the updated file directly.b81a2268passes on Windows x64 and both Mac architectures: real Codex 0.156.1 contract, development/preview, packaged apps and all six installer containers. Windows NSIS is 13/13 and portable 9/9; their apps and each Mac app/DMG/ZIP are 14/14, with zero runtime errors and normal exits. Checksums and uploads pass.src/main.jsx: all 1,483 production bundle files are byte-identical to the native-tested tree; local development/preview passes 9/9 with zero errors and a normal exit.The first Windows attempt timed out in an existing 60-second private PowerShell probe. One targeted retry passed the same immutable source and unchanged assertions/limits; the cause of the initial timeout is not established. This workflow validates installers without publishing a new release.