Conversation
Supersedes dependabot #981, which changed package.json only and failed bun install --frozen-lockfile in CI. Regenerates bun.lock against the public npm registry and refreshes the sha384 SRI on the two routes that load /vendor/mermaid.min.js (update-sri.mjs).
There was a problem hiding this comment.
1 issue found across 4 files
Confidence score: 3/5
- In
package.json, Mermaid 12’s ES2024 bundle may fail to parse in browsers below Safari 17.4, disabling Mermaid rendering for those users; transpile the bundle or narrow the supported browser target.
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="package.json">
<violation number="1" location="package.json:36">
P2: Mermaid 12's ES2024 bundle is copied without transpilation, but this app still declares the broad `defaults` browser target. Browsers below Safari 17.4 may fail to parse the script and lose Mermaid rendering; transpile the vendor bundle or explicitly raise the supported browser baseline.</violation>
</file>
Shadow auto-approve: would not auto-approve because issues were found.
Re-trigger cubic
| "jsqr": "^1.4.0", | ||
| "marked": "^18.0.5", | ||
| "mermaid": "^11.15.0", | ||
| "mermaid": "^12.0.0", |
There was a problem hiding this comment.
P2: Mermaid 12's ES2024 bundle is copied without transpilation, but this app still declares the broad defaults browser target. Browsers below Safari 17.4 may fail to parse the script and lose Mermaid rendering; transpile the vendor bundle or explicitly raise the supported browser baseline.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At package.json, line 36:
<comment>Mermaid 12's ES2024 bundle is copied without transpilation, but this app still declares the broad `defaults` browser target. Browsers below Safari 17.4 may fail to parse the script and lose Mermaid rendering; transpile the vendor bundle or explicitly raise the supported browser baseline.</comment>
<file context>
@@ -33,7 +33,7 @@
"jsqr": "^1.4.0",
"marked": "^18.0.5",
- "mermaid": "^11.15.0",
+ "mermaid": "^12.0.0",
"node-forge": "^1.4.0",
"pako": "^3.0.0",
</file context>
There was a problem hiding this comment.
Checked against the real targets rather than Mermaid's advertised floor; no change needed here.
npx browserslist(defaults) resolves to Chrome 109+, Safari/iOS 18.5+, Firefox 140+, Samsung 28, plus UC 15.5, QQ 14.9, KaiOS 2.5/3.x and Opera Mini.- Parsing the shipped
mermaid.min.jswith acorn: both 11.15.0 and 12.0.0 fail atecmaVersion: 2021(class static blocks) and pass at 2022, so the syntax floor did not move. Neither bundle has a regexvflag, as a literal or throughRegExp(..., "v"). - There are no ES2023/2024 built-ins in the 12 bundle (
Object.groupBy,Map.groupBy,Promise.withResolvers,toSorted/toReversed/toSpliced,findLast,isWellFormed,Array.fromAsyncall absent). What it does use (Object.hasOwn,.at,structuredClone) is covered by Chrome 109. - The browsers in
defaultsthat cannot parse 12 (KaiOS, Opera Mini, UC 15.5, QQ 14.9) could not parse 11.15 either.
So the bump does not narrow support, and neither transpiling nor raising the baseline is warranted.
|
Follow-up verification (OmOcat, no approve/merge/deploy): CI on #984 confirmed from logs (runs 36488773217 / 36488739483): Bundle / SRI / lockfile
Mermaid 12 release notes vs this app
Real-browser QA (Chromium against Pre-existing bug found (not caused by this PR): on mobile (390px), switching the Markdown Editor to the Preview tab shows empty Mermaid diagrams, because the diagrams are rendered while the preview pane is hidden. With 11.15.0 the same steps even throw Gate review: APPROVE (HIGH). The first pass was REJECT for one procedural reason: there was no code review report for this change. After that report was added (it covers the diff, the slop/overfit check and the lockfile registry/integrity), the re-review found no blocking issues. The decisions listed in #984 still stand: keep ELK or pin |
Mermaid 12 moves flowchart/state/class/sequence diagrams to the ELK layout, the neo look, and a 120px node min width / wrap width. Neither route set these, so every diagram silently re-laid out. Pin layout 'dagre', look 'classic', and the 11.x flowchart/state minNodeWidth/wrappingWidth in both mermaid.initialize call sites so the bump stays behaviour-neutral. Rendered flowchart, state, sequence, class and long-label samples now match 11.15.0 viewBox sizes exactly.
There was a problem hiding this comment.
0 issues found across 2 files (changes from recent commits).
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Shadow auto-approve: would not auto-approve. Auto-approval blocked by 1 unresolved issue from previous reviews.
Re-trigger cubic
Supersedes #981 (dependabot), which changed
package.jsononly.What changed
package.json:mermaid^11.15.0->^12.0.0(same as chore(deps): bump mermaid from 11.17.2 to 12.0.0 #981).bun.lock: regenerated against the public npm registry (mermaid@12.0.0,@mermaid-js/parser@2.0.0, addselkjs,chevrotainand friends). 26-line diff, no private registry URLs.src/routes/mermaid-studio.js,src/routes/markdown-editor.js: thesha384SRI on/vendor/mermaid.min.jswas refreshed withnode scripts/update-sri.mjs. Without this change the browser blocks the new bundle and both tools stop rendering.src/routes/mermaid-studio.js,src/routes/markdown-editor.js(b269868):mermaid.initializenow pins the 11.x defaults that 12 changed:layout: 'dagre',look: 'classic', andflowchart/stateminNodeWidth: 0, wrappingWidth: 200. The bump therefore does not change how diagrams look. Flowchart, state, sequence, class and long-label samples render with exactly the 11.15.0 viewBox sizes.Evidence
bun install --frozen-lockfileon chore(deps): bump mermaid from 11.17.2 to 12.0.0 #981's tree fails witherror: lockfile had changes, but lockfile is frozen, the same error CI reported. On this branch the same command passes.bun run buildexits 0.vitest runpasses 59 files and 712 tests./vendor/mermaid.min.jsbytes served bywrangler dev, and the bundle containsversion:"12.0.0".wrangler dev, with 11.15.0 injected via route interception for the baseline. Covered desktop 1280 and mobile 390, light and dark themes, the Mermaid Studio flowchart and sequence sample, the Markdown Editor flowchart + subgraph and stateDiagram, and Download SVG.theme: default|darkand the pinned text colours.diagram.svgwith the SVG xmlns, and the file renders on its own.look: classicis unchanged, whilelayoutmoves fromdagretoelk.Notes
layout: 'dagre'alone was not enough:look: neoand the 120px min/wrap width still widened nodes (Studio 408x475 -> 572x502). With the full pin, both routes match 11.15.0 at 1280/390 in light and dark.mermaid.min.jsgrows from 3.31 MB to 5.58 MB raw, and from 0.91 MB to 1.60 MB gzipped (+0.69 MB), because the IIFE build now inlines ELK. This only affects/mermaid-studioand/markdown-editor. Settinglayout: 'dagre'does not shrink the file.mermaid.min.jshas the same syntax floor as 11.15.0. Both parse with acorn at ES2022 and fail at ES2021 on class static blocks. Neither uses the regexvflag or ES2023/2024 built-ins such asObject.groupBy,Promise.withResolversortoSorted.defaultsresolves to Chrome 109+ / Safari 18.5+, and the entries that cannot parse 12 (KaiOS, Opera Mini, UC 15.5, QQ 14.9) could not parse 11.15 either. Support is not narrowed, and no transpile is needed.Risk
Medium-low. The change is limited to two routes. The main risk is the visual change and the larger download described above.
Rollback
Revert this commit. That restores
^11.15.0, the oldbun.lockand the old SRI together; the three must move as one unit.Summary by cubic
Upgrades
mermaidto 12.0.0 (supersedes #981) and regeneratesbun.lockso the bump installs cleanly in CI, which #981 missed by changing onlypackage.json. Refreshes thesha384SRI for/vendor/mermaid.min.json both routes; without it the browser blocks the new bundle and Mermaid Studio and the Markdown Editor stop rendering.Mermaid 12 changes the default layout, look, and node sizing, so both
mermaid.initializecalls now pin the 11.x values to keep the bump behavior-neutral.Migration
layout: 'dagre',look: 'classic', and the 11.x min node width / wrapping width, so rendered diagrams keep their previous shape and size.mermaid.min.jsgrows from 3.31 MB to 5.58 MB raw (1.60 MB gzipped) and only affects/mermaid-studioand/markdown-editor.defaultsbrowserslist resolves to Safari 18.5, so there is no conflict.Written for commit b269868. Summary will update on new commits.