Skip to content

Bump @xyflow/react from 12.11.1 to 12.11.2 - #8

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/xyflow/react-12.11.2
Open

Bump @xyflow/react from 12.11.1 to 12.11.2#8
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/xyflow/react-12.11.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 7, 2026

Copy link
Copy Markdown
Contributor

Bumps @xyflow/react from 12.11.1 to 12.11.2.

Release notes

Sourced from @​xyflow/react's releases.

@​xyflow/react@​12.11.2

Patch Changes

Changelog

Sourced from @​xyflow/react's changelog.

12.11.2

Patch Changes

Commits
  • 3ab66ef chore(packages): bump
  • 01d58b6 Merge pull request #5846 from AlaricBaraou/perf/viewport-imperative-transform
  • 742860c perf(react): skip minimap re-renders when its geometry is unchanged
  • 17c64a1 perf(react): apply the viewport transform imperatively instead of re-renderin...
  • 775bdd6 Merge pull request #5825 from AlaricBaraou/perf/xydrag-draggable-only
  • 576a43d refactor(react): pass nodesDraggable to prevent wrong initial state
  • 5072914 perf(react): only create an XYDrag instance for draggable nodes
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@xyflow/react](https://github.com/xyflow/xyflow/tree/HEAD/packages/react) from 12.11.1 to 12.11.2.
- [Release notes](https://github.com/xyflow/xyflow/releases)
- [Changelog](https://github.com/xyflow/xyflow/blob/main/packages/react/CHANGELOG.md)
- [Commits](https://github.com/xyflow/xyflow/commits/@xyflow/react@12.11.2/packages/react)

---
updated-dependencies:
- dependency-name: "@xyflow/react"
  dependency-version: 12.11.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 7, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​xyflow/​react@​12.11.1 ⏵ 12.11.299 +1100100 +195 +2100

View full report

Copy link
Copy Markdown
Member

### Verdict: APPROVE

**Automated evidence-backed PR review · 2026-07-28**

---

#### Executive Summary

- Dependabot patch bump: `@xyflow/react` 12.11.1 → 12.11.2. 2 files (package.json + lock file), 9 additions, 9 deletions.

- Socket supply chain scores improved or held: SC 99 (+1), Vuln 100 (+1), Quality 95 (+2), Maintenance 100, License 100.

- `mergeStatus: ready`. No code-level concerns. No regression risk for a patch-level dependency bump.

- 21 days open with no blocker. Safe to merge.

---

#### Objective

Evidence: PR title (Dependabot), branch `dependabot/npm_and_yarn/xyflow/react-12.11.2`, Socket diff scan (thread `17a7e4c5`).

Bump `@xyflow/react` from 12.11.1 to 12.11.2 (patch). Lock file updated accordingly.

---

#### PR Sync Status

GitHub, CI (mergeStatus: ready), Socket scan, and diff are all in sync at head `db3c547a`. No review threads open. No Linear issue expected for an automated dependency bump.

---

#### Rubric Score

| Category | Score | Evidence | Risk / Required Action |

|---|---:|---|---|

| Objective Alignment | 5 | Patch bump, correct files | |

| Linear / Ticket Alignment | 3 | No linked issue — expected for Dependabot | |

| Checklist Completion | 5 | Automated PR; Socket scan complete | |

| Code Quality | 5 | package.json + lock file only | |

| Architecture / Repo Conventions | 5 | Follows Dependabot pattern | |

| Tests | 5 | N/A — version bump only | |

| CI/CD | 5 | mergeStatus: ready; Socket clean | |

| Security / Privacy | 5 | SC 99, Vuln 100, Quality 95 — no regressions | |

| Documentation | 5 | N/A | |

| Review Comment Resolution | 5 | No open threads | |

| Commit Hygiene | 5 | Single Dependabot commit | |

| Operational / Deployment Risk | 4 | Patch bump — minimal risk | |

**Total: 57/60 (95%) → APPROVE**

No blockers. Recommend merging.

---

#### Staleness

- **Opened**: 2026-07-07 (21 days ago)

- **Last meaningful activity**: 2026-07-07T05:24 (Socket scan)

- **Blocker**: None

---

#### Evidence Log

- Linear diff `6240517b` — xyflow-vite-react-flow-template#8, head `db3c547acfaa9818a0d1aa37a7f6dc6f482f036c`

- Socket scan thread `17a7e4c5`: SC 99, Vuln 100, Quality 95, Maintenance 100, License 100

- mergeStatus: ready; no Copilot/CodeRabbit issues

_Automated review · Evidence-Backed GitHub PR Review routine_

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant