Skip to content

chore(deps): frontend patch updates within current majors - #91

Open
0xMMA wants to merge 3 commits into
mainfrom
chore/frontend-patches
Open

0xMMA wants to merge 3 commits into
mainfrom
chore/frontend-patches

Conversation

@0xMMA

@0xMMA 0xMMA commented Sep 24, 2026

Copy link
Copy Markdown
Owner

Frontend dependency refresh that stays inside every current major. No source changes.

Versions

Package Before After Note
@angular/* (animations, common, compiler, core, forms, platform-browser, router, build, cli, compiler-cli) 21.2.0 21.2.24 moved together
primeng 21.1.3 21.1.10
dotenv 17.3.1 17.4.2
jsdom 30.1.0 30.1.1
prettier 3.9.8 3.9.9
@wailsio/runtime ^3.0.0-alpha.79 3.0.0-alpha.79 (exact) pinned, see below
transitive, via npm audit fix (no --force) esbuild 0.27.3→0.28.2, postcss 8.5.8→8.5.28, browserslist 4.28.1→4.29.1, nanoid 3.3.11→3.3.19, immutable 5.1.5→5.1.9, baseline-browser-mapping 2.10.0→2.11.26, plus caniuse-lite, electron-to-chromium, node-releases, update-browserslist-db

Unchanged on purpose: @primeuix/themes 2.0.3 (latest 2.x), primeicons 7, typescript 5.9.3, vitest 4.1.11, rxjs, tslib, @playwright/test 1.63.0 (all already at the newest version inside their major or range).

Explicitly not in this PR: Angular 22, PrimeNG 22, @primeuix/themes 3, primeicons 8, TypeScript 7, Vitest 5, dotenv 18, and the real Wails bump.

Why pin @wailsio/runtime: the caret range ^3.0.0-alpha.79 admits 3.0.0-beta.25, and npm outdated already reported that as "Wanted". A routine npm update would have moved the JS runtime to beta while Go stays on alpha.72. The pin keeps it where it is until the Wails bump lands on both sides in its own PR.

Declared ranges were raised to the installed versions (e.g. ^21.2.24), so the manifest and the lockfile agree on the floor.

Changelog notes

PrimeNG 21.1.4 to 21.1.10. The published changelog lists one fix per release, and none of them touch a component this app imports (button, card, checkbox, config, inputnumber, inputtext, message, progressspinner, select, tabs, tag, textarea, toggleswitch, tooltip):

  • 21.1.4 orderlist controlsPosition, 21.1.5 drawer outside click, 21.1.6 accordion scroll, 21.1.7 autocomplete chips, 21.1.8 drawer CSP, 21.1.9 datepicker type error. 21.1.10 has no changelog entry ("Full Changelog" link only).

    I diffed the published npm tarballs 21.1.3 against 21.1.10, ignoring Angular's version: metadata and the /* istanbul ignore next */ comments the newer compiler emits. Real code changes appear only in autocomplete, datepicker, drawer, multiselect, orderlist and primeng/motion. None of those is imported here except motion, which p-message and the select overlay pull in. Its only change is overflow: hidden during height animations (the 21.1.6 accordion fix). None of the CSS class names or --p-* tokens changed in any component the app uses.

  • Dark-mode tokens: @primeuix/themes and @primeuix/styles stay at 2.0.3. The variables and classes that src/styles.scss overrides (--p-surface-*, --p-card-background, --p-text-color, .p-inputtext, .p-select, .p-tablist, .p-tabpanels, .p-textarea) are untouched.

  • PrimeNG now depends on @primeuix/utils ^0.7.2 (was 0.6.x). The 0.7 API change is additive: isCssSupported, and a broader toElement.

Angular 21.2.1 to 21.2.24.

  • Mostly security hardening in the compiler, core, common and http packages. This closes 11 advisories that npm audit reported against 21.2.0: XSS through i18n attributes, two-way bindings, namespaces and host bindings, formatDate/digitsInfo out-of-memory DoS, and HttpTransferCache leaks. Most of the http and platform-server items do not apply here because the app has no SSR and no HttpClient.
  • The app uses [innerHTML] once, in the text-enhancement markdown view. Plain innerHTML sanitization is unchanged; the hardening targets two-way, i18n, SVG/MathML and host bindings.
  • Router: browserUrl popstate fix and numeric-key URL parsing. The app uses neither.
  • @angular/build pulls in vite 7.3.6, esbuild 0.28.1, postcss and undici bumps, so most of the audit findings go away.
  • The unit-test builder still sets isolate: false and still declares vitest ^4.0.8 as its peer. .claude/rules/testing.md therefore stays accurate. Since 21.2.1, vi.mock is blocked only for relative imports rather than for all of them. The rule "use DI mocking" still holds; the wording in testing.md is slightly broader than the tool now enforces.

Verification

All on this branch, in a fresh worktree:

  • npm ci: clean install, found 0 vulnerabilities
  • npm test: 14 files, 198 tests passed, 0 failed
  • npm run build: builds. The one warning, text-enhancement.component.ts component styles over the 4 kB budget, comes from our own SCSS and was there before this change.
  • npx playwright test (whole suite, against this branch's ng serve): 58 passed, 3 skipped, 0 failed in 47 s. For comparison, origin/main produced 55 passed, 3 failed, 3 skipped in 4.9 min with the machine at load average 28. The failures were three shell-menu layout timing tests, and all 36 passed on rerun, so they were load flakes rather than regressions.
  • git status is clean after the E2E run (generated output is gitignored).
  • go build -o bin/KeyLint .: compiles. go test ./internal/...: all packages ok.
  • npm audit: before 39 (1 critical, 21 high, 14 moderate, 3 low), after 0.

Visual regression (PrimeNG patch bump)

I took Playwright screenshots of 17 states on origin/main and on this branch: same viewport (1280×860, DPR 1), same script, animations disabled. They cover fix (empty, filled, collapsed sidebar, collapsed tooltip), pyramidize/enhance, settings (General, AI Providers, App Defaults, About, and an open p-select overlay), dev-tools, and the welcome wizard (steps 1 to 4, with the provider dropdown open and after a selection). For the wizard, IsFirstRun was answered true via page.route.

Result: 15 of 17 are byte-identical. The other two differ by sub-perceptual antialiasing only:

  • fix, filled: 43 pixels changed by 1–2 RGB units, on the rounded corners of the focused textarea border and the Fix button
  • enhance: 2 pixels changed by 2 RGB units

Nothing is visible at 100 %. I also looked at the screenshots themselves.

Unrelated observation, present on both sides and not caused by this PR: in dark mode the p-select overlay panels, the "No AI API key configured" banner and the global-instruction input on the Pyramidize page render with light backgrounds.

Merge check against frozen PR #31

git merge-tree --write-tree --name-only origin/feature/shortcut-double-press HEAD produces no conflicting files, and PR #31 does not touch frontend/package*.json. At the current tips, PR #31 against origin/main also merges clean, so the known internal/features/settings/model.go conflict no longer reproduces.

Skipped

  • No manual run inside the Wails webview (WebKit2GTK / WebView2). The screenshots and E2E ran in Chromium against ng serve, which has no Wails bridge. The runtime package is byte-for-byte unchanged, so the bridge is not affected by this PR.

0xMMA and others added 3 commits September 25, 2026 00:00
Patch and minor updates that stay inside the current majors:

- @angular/* (incl. build, cli, compiler-cli) 21.2.0 -> 21.2.24
- primeng 21.1.3 -> 21.1.10
- dotenv 17.3.1 -> 17.4.2, jsdom 30.1.0 -> 30.1.1, prettier 3.9.8 -> 3.9.9

Pin @wailsio/runtime exactly to 3.0.0-alpha.79. Its caret range
admits 3.0.0-beta.25, so a routine `npm update` would move the JS
runtime to beta while the Go side stays on alpha.72. The Wails bump
belongs in its own change.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
`npm audit fix` without --force: only lockfile entries inside their
existing ranges move (esbuild 0.28.2, postcss 8.5.28, browserslist
4.29.1, nanoid 3.3.19, immutable 5.1.9, baseline-browser-mapping
2.11.26 and their browserslist data). npm audit now reports 0.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Re-resolved from main's lockfile with npm --before=2026-09-18, then npm audit fix under the same cutoff: every one of the 147 changed versions was published before the cutoff (checked against the registry), and audit still reports 0 vulnerabilities. Angular lands on 21.2.23 instead of the day-old 21.2.24; jsdom 30.1.0, prettier 3.9.8. Matches the 7-day npm cooldown #89 gives Dependabot.
@0xMMA

0xMMA commented Sep 24, 2026

Copy link
Copy Markdown
Owner Author

Review follow-up: the lockfile had pinned 21 versions under 7 days old (Angular 21.2.24 was ~28h old), inconsistent with the 7-day npm cooldown #89 introduces. Re-resolved with npm --before=2026-09-18 from main's lockfile, then npm audit fix under the same cutoff. All 147 changed versions were published before the cutoff (checked per package against the registry). npm audit: 0 vulnerabilities. Unit tests 198/198, build OK locally; e2e in CI.

@0xMMA

0xMMA commented Sep 24, 2026

Copy link
Copy Markdown
Owner Author

Merge-ready: CI green (build-linux, build-windows, e2e, test), Opus review with review-pr fork supplement: no defects; its D1 finding (day-old versions) addressed by re-resolving under a 7-day cutoff (0f55c4a). Merge before #89 and before the Angular 22 PR, which stacks on this branch.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant