Bump @xyflow/react from 12.11.1 to 12.11.2 - #8
Conversation
Bumps [@xyflow/react](https://github.com/xyflow/xyflow/tree/HEAD/packages/react) from 12.11.1 to 12.11.2. - [Release notes](https://github.com/xyflow/xyflow/releases) - [Changelog](https://github.com/xyflow/xyflow/blob/main/packages/react/CHANGELOG.md) - [Commits](https://github.com/xyflow/xyflow/commits/@xyflow/react@12.11.2/packages/react) --- updated-dependencies: - dependency-name: "@xyflow/react" dependency-version: 12.11.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
### Verdict: APPROVE **Automated evidence-backed PR review · 2026-07-28** --- #### Executive Summary - Dependabot patch bump: `@xyflow/react` 12.11.1 → 12.11.2. 2 files (package.json + lock file), 9 additions, 9 deletions. - Socket supply chain scores improved or held: SC 99 (+1), Vuln 100 (+1), Quality 95 (+2), Maintenance 100, License 100. - `mergeStatus: ready`. No code-level concerns. No regression risk for a patch-level dependency bump. - 21 days open with no blocker. Safe to merge. --- #### Objective Evidence: PR title (Dependabot), branch `dependabot/npm_and_yarn/xyflow/react-12.11.2`, Socket diff scan (thread `17a7e4c5`). Bump `@xyflow/react` from 12.11.1 to 12.11.2 (patch). Lock file updated accordingly. --- #### PR Sync Status GitHub, CI (mergeStatus: ready), Socket scan, and diff are all in sync at head `db3c547a`. No review threads open. No Linear issue expected for an automated dependency bump. --- #### Rubric Score | Category | Score | Evidence | Risk / Required Action | |---|---:|---|---| | Objective Alignment | 5 | Patch bump, correct files | | | Linear / Ticket Alignment | 3 | No linked issue — expected for Dependabot | | | Checklist Completion | 5 | Automated PR; Socket scan complete | | | Code Quality | 5 | package.json + lock file only | | | Architecture / Repo Conventions | 5 | Follows Dependabot pattern | | | Tests | 5 | N/A — version bump only | | | CI/CD | 5 | mergeStatus: ready; Socket clean | | | Security / Privacy | 5 | SC 99, Vuln 100, Quality 95 — no regressions | | | Documentation | 5 | N/A | | | Review Comment Resolution | 5 | No open threads | | | Commit Hygiene | 5 | Single Dependabot commit | | | Operational / Deployment Risk | 4 | Patch bump — minimal risk | | **Total: 57/60 (95%) → APPROVE** No blockers. Recommend merging. --- #### Staleness - **Opened**: 2026-07-07 (21 days ago) - **Last meaningful activity**: 2026-07-07T05:24 (Socket scan) - **Blocker**: None --- #### Evidence Log - Linear diff `6240517b` — xyflow-vite-react-flow-template#8, head `db3c547acfaa9818a0d1aa37a7f6dc6f482f036c` - Socket scan thread `17a7e4c5`: SC 99, Vuln 100, Quality 95, Maintenance 100, License 100 - mergeStatus: ready; no Copilot/CodeRabbit issues _Automated review · Evidence-Backed GitHub PR Review routine_ |
Bumps @xyflow/react from 12.11.1 to 12.11.2.
Release notes
Sourced from @xyflow/react's releases.
Changelog
Sourced from @xyflow/react's changelog.
Commits
3ab66efchore(packages): bump01d58b6Merge pull request #5846 from AlaricBaraou/perf/viewport-imperative-transform742860cperf(react): skip minimap re-renders when its geometry is unchanged17c64a1perf(react): apply the viewport transform imperatively instead of re-renderin...775bdd6Merge pull request #5825 from AlaricBaraou/perf/xydrag-draggable-only576a43drefactor(react): pass nodesDraggable to prevent wrong initial state5072914perf(react): only create an XYDrag instance for draggable nodesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)