Conversation
Patch and minor updates that stay inside the current majors: - @angular/* (incl. build, cli, compiler-cli) 21.2.0 -> 21.2.24 - primeng 21.1.3 -> 21.1.10 - dotenv 17.3.1 -> 17.4.2, jsdom 30.1.0 -> 30.1.1, prettier 3.9.8 -> 3.9.9 Pin @wailsio/runtime exactly to 3.0.0-alpha.79. Its caret range admits 3.0.0-beta.25, so a routine `npm update` would move the JS runtime to beta while the Go side stays on alpha.72. The Wails bump belongs in its own change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
`npm audit fix` without --force: only lockfile entries inside their existing ranges move (esbuild 0.28.2, postcss 8.5.28, browserslist 4.29.1, nanoid 3.3.19, immutable 5.1.9, baseline-browser-mapping 2.11.26 and their browserslist data). npm audit now reports 0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Re-resolved from main's lockfile with npm --before=2026-09-18, then npm audit fix under the same cutoff: every one of the 147 changed versions was published before the cutoff (checked against the registry), and audit still reports 0 vulnerabilities. Angular lands on 21.2.23 instead of the day-old 21.2.24; jsdom 30.1.0, prettier 3.9.8. Matches the 7-day npm cooldown #89 gives Dependabot.
Owner
Author
|
Review follow-up: the lockfile had pinned 21 versions under 7 days old (Angular 21.2.24 was ~28h old), inconsistent with the 7-day npm cooldown #89 introduces. Re-resolved with |
Owner
Author
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Frontend dependency refresh that stays inside every current major. No source changes.
Versions
@angular/*(animations, common, compiler, core, forms, platform-browser, router, build, cli, compiler-cli)primengdotenvjsdomprettier@wailsio/runtime^3.0.0-alpha.793.0.0-alpha.79(exact)npm audit fix(no--force)Unchanged on purpose:
@primeuix/themes2.0.3 (latest 2.x),primeicons7,typescript5.9.3,vitest4.1.11,rxjs,tslib,@playwright/test1.63.0 (all already at the newest version inside their major or range).Explicitly not in this PR: Angular 22, PrimeNG 22,
@primeuix/themes3, primeicons 8, TypeScript 7, Vitest 5, dotenv 18, and the real Wails bump.Why pin
@wailsio/runtime: the caret range^3.0.0-alpha.79admits3.0.0-beta.25, andnpm outdatedalready reported that as "Wanted". A routinenpm updatewould have moved the JS runtime to beta while Go stays on alpha.72. The pin keeps it where it is until the Wails bump lands on both sides in its own PR.Declared ranges were raised to the installed versions (e.g.
^21.2.24), so the manifest and the lockfile agree on the floor.Changelog notes
PrimeNG 21.1.4 to 21.1.10. The published changelog lists one fix per release, and none of them touch a component this app imports (button, card, checkbox, config, inputnumber, inputtext, message, progressspinner, select, tabs, tag, textarea, toggleswitch, tooltip):
21.1.4 orderlist controlsPosition, 21.1.5 drawer outside click, 21.1.6 accordion scroll, 21.1.7 autocomplete chips, 21.1.8 drawer CSP, 21.1.9 datepicker type error. 21.1.10 has no changelog entry ("Full Changelog" link only).
I diffed the published npm tarballs 21.1.3 against 21.1.10, ignoring Angular's
version:metadata and the/* istanbul ignore next */comments the newer compiler emits. Real code changes appear only in autocomplete, datepicker, drawer, multiselect, orderlist andprimeng/motion. None of those is imported here exceptmotion, whichp-messageand the select overlay pull in. Its only change isoverflow: hiddenduring height animations (the 21.1.6 accordion fix). None of the CSS class names or--p-*tokens changed in any component the app uses.Dark-mode tokens:
@primeuix/themesand@primeuix/stylesstay at 2.0.3. The variables and classes thatsrc/styles.scssoverrides (--p-surface-*,--p-card-background,--p-text-color,.p-inputtext,.p-select,.p-tablist,.p-tabpanels,.p-textarea) are untouched.PrimeNG now depends on
@primeuix/utils^0.7.2 (was 0.6.x). The 0.7 API change is additive:isCssSupported, and a broadertoElement.Angular 21.2.1 to 21.2.24.
npm auditreported against 21.2.0: XSS through i18n attributes, two-way bindings, namespaces and host bindings,formatDate/digitsInfoout-of-memory DoS, and HttpTransferCache leaks. Most of the http and platform-server items do not apply here because the app has no SSR and no HttpClient.[innerHTML]once, in the text-enhancement markdown view. PlaininnerHTMLsanitization is unchanged; the hardening targets two-way, i18n, SVG/MathML and host bindings.browserUrlpopstate fix and numeric-key URL parsing. The app uses neither.@angular/buildpulls in vite 7.3.6, esbuild 0.28.1, postcss and undici bumps, so most of the audit findings go away.isolate: falseand still declares vitest^4.0.8as its peer..claude/rules/testing.mdtherefore stays accurate. Since 21.2.1,vi.mockis blocked only for relative imports rather than for all of them. The rule "use DI mocking" still holds; the wording in testing.md is slightly broader than the tool now enforces.Verification
All on this branch, in a fresh worktree:
npm ci: clean install,found 0 vulnerabilitiesnpm test: 14 files, 198 tests passed, 0 failednpm run build: builds. The one warning,text-enhancement.component.tscomponent styles over the 4 kB budget, comes from our own SCSS and was there before this change.npx playwright test(whole suite, against this branch'sng serve): 58 passed, 3 skipped, 0 failed in 47 s. For comparison,origin/mainproduced 55 passed, 3 failed, 3 skipped in 4.9 min with the machine at load average 28. The failures were threeshell-menulayout timing tests, and all 36 passed on rerun, so they were load flakes rather than regressions.git statusis clean after the E2E run (generated output is gitignored).go build -o bin/KeyLint .: compiles.go test ./internal/...: all packages ok.npm audit: before 39 (1 critical, 21 high, 14 moderate, 3 low), after 0.Visual regression (PrimeNG patch bump)
I took Playwright screenshots of 17 states on
origin/mainand on this branch: same viewport (1280×860, DPR 1), same script, animations disabled. They cover fix (empty, filled, collapsed sidebar, collapsed tooltip), pyramidize/enhance, settings (General, AI Providers, App Defaults, About, and an openp-selectoverlay), dev-tools, and the welcome wizard (steps 1 to 4, with the provider dropdown open and after a selection). For the wizard,IsFirstRunwas answeredtrueviapage.route.Result: 15 of 17 are byte-identical. The other two differ by sub-perceptual antialiasing only:
Nothing is visible at 100 %. I also looked at the screenshots themselves.
Unrelated observation, present on both sides and not caused by this PR: in dark mode the
p-selectoverlay panels, the "No AI API key configured" banner and the global-instruction input on the Pyramidize page render with light backgrounds.Merge check against frozen PR #31
git merge-tree --write-tree --name-only origin/feature/shortcut-double-press HEADproduces no conflicting files, and PR #31 does not touchfrontend/package*.json. At the current tips, PR #31 againstorigin/mainalso merges clean, so the knowninternal/features/settings/model.goconflict no longer reproduces.Skipped
ng serve, which has no Wails bridge. The runtime package is byte-for-byte unchanged, so the bridge is not affected by this PR.