Skip to content

chore(examples): bump rich-text-editor-ndevu to v0.1.1 - #54

Merged
Ndevu12 merged 2 commits into
mainfrom
chore/examples-bump-rich-text-editor-0-1-1
Mar 27, 2026
Merged

chore(examples): bump rich-text-editor-ndevu to v0.1.1#54
Ndevu12 merged 2 commits into
mainfrom
chore/examples-bump-rich-text-editor-0-1-1

Conversation

@Ndevu12

@Ndevu12 Ndevu12 commented Mar 27, 2026

Copy link
Copy Markdown
Owner

Update the Next.js and React demo apps to use rich-text-editor-ndevu v0.1.1 and refresh lockfiles so newly introduced package dependencies resolve consistently.

Update the Next.js and React demo apps to use rich-text-editor-ndevu v0.1.1 and refresh lockfiles so newly introduced package dependencies resolve consistently.
@Ndevu12 Ndevu12 self-assigned this Mar 27, 2026
@Ndevu12 Ndevu12 added enhancement New feature or request fix Providing fixes for some issues/bugs labels Mar 27, 2026
Documented new additions including a security policy, updates to examples and development tools, and improvements to the CI/release workflow. Fixed redundant publish checks for manual releases.
@Ndevu12
Ndevu12 merged commit 7bab32e into main Mar 27, 2026
8 checks passed
@Ndevu12
Ndevu12 deleted the chore/examples-bump-rich-text-editor-0-1-1 branch March 27, 2026 13:23
Ndevu12 added a commit that referenced this pull request Jul 31, 2026
Closes 16 of the 18 open Dependabot alerts on the root yarn.lock.
(The remaining tar alerts are handled separately in #104.)

Direct devDependencies — manifest floor raised alongside the lockfile:

  vite          ^8.0.0  -> ^8.0.16   (resolves 8.2.0)  #54 high, #55 medium
  concurrently  ^10.0.0 -> ^10.0.4                     #86 high (via shell-quote)

concurrently 10.0.4 pins shell-quote 1.9.0 exactly, so bumping the real
parent fixes shell-quote properly rather than forcing it with a resolutions
override. shell-quote 1.8.4 is gone from the tree entirely.

Transitive — lockfile only, all within existing declared ranges:

  @babel/core       7.29.0  -> 7.29.7   #68
  brace-expansion   1.1.12  -> 1.1.18   #103
  brace-expansion   5.0.4   -> 5.0.9    #81
  js-yaml           4.1.1   -> 4.3.1    #80, #101
  postcss           8.5.15  -> 8.5.25   #119
  undici            7.24.4  -> 7.29.0   #71, #72, #73, #74, #76, #77
  ws                8.19.0  -> 8.21.1   #67

Raising vite to ^8.0.16 initially left a second vite 8.0.8 behind an
unrelated `^6 || ^7 || ^8` range, which kept a vulnerable postcss 8.5.15
alive. `yarn up -R` plus `yarn dedupe` collapses both to a single copy, so
no stale vulnerable duplicate remains.

vite 8.2.0 warns that `__dirname` is unsupported under the native config
loader that becomes the default in a future major. Migrated both root vite
configs to `import.meta.dirname` so the bump leaves no new warning behind.
Available since Node 20.11; CI runs Node 20.x.

Verified: build, 286 unit tests, typecheck, lint, format:check, verify:demos.

Not fixed here — both blocked upstream, neither reachable in this project:

  #50 esbuild (low)   tsup 8.5.1 is the latest release and pins esbuild
                      ^0.27.0, so 0.28.1 is unreachable without overriding
                      a transitive pin. The advisory is a Windows-only path
                      traversal in the esbuild dev server (servedir); tsup
                      uses the bundler API and never starts that server.

  #46 uuid (medium)   @storybook/addon-actions 8.6.18 pins uuid ^9.0.0.
                      Storybook 9+ drops the uuid dependency entirely, so
                      the real fix is the v8 -> v10 migration, not a pin.
                      The advisory affects v3()/v5()/v6() with a caller
                      supplied buffer; addon-actions only calls v4() with
                      no buffer.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request fix Providing fixes for some issues/bugs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant