Repository navigation
chore(deps): upgrade all packages to latest + align shared versions - #4597
Merged
Merged
Conversation
|
Website preview ready: https://pr-4597-marktext-website.ransixi.workers.dev Built from |
|
Build artifacts for PR #4597: Run: https://github.com/marktext/marktext/actions/runs/27888432342
|
Jocs
force-pushed
the
chore/upgrade-deps-latest
branch
4 times, most recently
from
June 20, 2026 18:40
42b0381 to
cb21f86
Compare
Jocs
changed the base branch from
chore/security-dependabot-remediation
to
develop
June 21, 2026 00:16
Routine `pnpm update -r` across the workspace — bumps every dependency to its latest release within the existing major (no breaking-major changes) and updates the package.json caret floors. Highlights: - desktop: electron 42.1.0->42.4.1, electron-builder 26.8.1->26.15.3, axios 1.16.1->1.18.0, element-plus 2.14.0->2.14.2, vue 3.5.34->3.5.38, vue-i18n 11.4.2->11.4.6, electron-updater 6.8.3->6.8.9, vitest 4.1.6->4.1.9 - muya/muyajs: snabbdom 3.6.3->3.6.4, fuse.js 7.3.0->7.4.2 - tooling: prettier 3.8.4, tsx 4.22.4, @playwright/test 1.61.0, typescript-eslint 8.61.1, eslint-plugin-* bumps - website: react 19.2.7, wrangler 4.103.0, @axe-core/playwright 4.11.3 @types/node kept on the v22 line to match the Node 22 runtime. Shared deps now align across packages except the cross-major splits (eslint/typescript/ vite) handled in following commits. Verified: lint 0 errors, typecheck clean, muya 143 unit + 4 conformance, desktop 17 unit, build:unpack OK. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Aligns desktop's TypeScript with muya (already on 6). vue-tsc 2->3 (vue-language-tools 3); typescript-eslint 8.61 supports TS <6.1 and vue-tsc 3 peers TS >=5, so the desktop type-check stack moves cleanly. Verified: `vue-tsc --noEmit` passes on desktop. TypeScript is type-check-only tooling here (esbuild drives build + vitest), so runtime/build are unaffected. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Bumps the math renderer to 0.17 and normalizes muya's pin from an exact `0.16.47` to `^0.17.0`, so the declared version is consistent across the three packages. mermaid + micromark-extension-math keep their own transitive katex 0.16.x (forcing those to 0.17 risks their math rendering). Verified: muya 143 unit + 4 conformance, desktop 17 unit, build:unpack OK. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
plist is used in a single place: parsing the macOS NSFilenamesPboardType clipboard payload via `plist.parse()` (main/ipc/shell.ts). The parse API is stable across the major bump — desktop type-check passes against plist 5's types and build:unpack is clean. Transitive plist 3.x pulled by other tooling is left as-is. Verified: desktop typecheck clean, build:unpack OK. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Desktop's router uses only modern APIs (createRouter + createWebHashHistory, RouteRecordRaw, named/children/redirect routes, <router-view>) — none of the deprecated APIs v5 removes. v5's only required peer is vue ^3.5.34 (satisfied); pinia / @pinia/colada / vite peers are optional. Verified: desktop typecheck clean, 17 unit suites pass, build:unpack OK. Real-app routing is additionally exercised by the e2e / run-on-pr-head CI jobs. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
marked 17+ changed tokenization in ways muya's parser layer must absorb: - Task lists: marked now emits a `checkbox` token and keeps the literal "[ ] " / "[x] " marker in the item content (in a paragraph's `text` for loose lists). muya renders the marker from the task-list-item `checked` meta, so `compatibleTaskList` now strips it from both tight and loose items — otherwise every md -> state -> md round-trip duplicated the checkbox. - Indented code: the `code` token text now carries a trailing newline (fenced does not); markdownToState strips it so indented blocks round-trip. - Setext headings: conformance improved — CommonMark #84/#89 and GFM #54/#59 now pass and are removed from expected-failures.json. Verified: muya 143 unit + 4 conformance suites (compliance up), desktop 17 unit, build:unpack OK. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Re-checked every security override against the upgraded tree. The dependency
refresh now resolves patched versions natively, so 7 of the 8 overrides are
redundant and removed:
@babel/core (7.29.6), form-data (4.0.6), js-yaml (4.2.0), tar (7.5.16),
tmp (0.2.6), undici (7.28.0), ws (8.21.0)
Kept:
- esbuild >=0.27.0 <0.28.1 -> 0.28.1: vite 7.3.5 (desktop, pinned by
electron-vite which peers vite <=7) still pulls the vulnerable esbuild
0.27.7; this bridges it until electron-vite supports vite 8.
- postcss 8.5.15: pre-existing (since #4314), pins to current latest 8.x.
Verified: lockfile keeps every previously-flagged package at a patched
version; build:unpack OK.
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
muya pinned mermaid to an exact "11.15.0" while desktop/muyajs use "^11.15.0". Normalize to "^11.15.0" so the declared version is consistent across packages (resolves to the same 11.15.0). Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
vue-router 5 passed typecheck/unit/build but broke the desktop app launch in e2e: every suite's beforeAll timed out because the renderer never reached ready (renderer errors captured by the e2e helper). Unit tests don't mount the full app + router, so the runtime regression only surfaced in e2e. Revert to ^4.6.4 (latest 4.x, known-good). vue-router 5 needs a dedicated migration PR with e2e verification, like codemirror 6 / website next 16. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
plist 5 ships ESM-only with named exports and no CJS `exports` entry, so the
externalized main-process `require('plist')` threw
ERR_PACKAGE_PATH_NOT_EXPORTED at startup — the app never launched, which failed
every desktop e2e suite (beforeAll launch timeout). The earlier vue-router
revert was a red herring; muya's own e2e passed, ruling out the engine.
Fix: exclude plist from externalization so electron-vite bundles it as CommonJS
(same pattern as electron-store), and switch shell.ts to a namespace import
(`import * as plist`) since plist 5 dropped its default export.
Verified: build:unpack bundles plist inline (no runtime require('plist')),
typecheck clean.
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
…xvfb CI) Root-caused the desktop e2e teardown cascade. app.close() hangs cumulatively across the workers:1 sequential run on Linux/xvfb: each Electron app leaves child processes that don't terminate promptly, accumulating until close — then later launches — fail (~16 "Worker teardown timeout" + did-not-run). It does NOT reproduce on macOS (113/114 local), and is not font-list / vue-router / @playwright/test / electron-updater (each eliminated with evidence: e.g. font-list 2.0.2 leaks the same handle; reverting playwright/vue-router didn't help). The only changed process-runtime dependency is electron 42.1->42.4 (clean-CI #4596 ran 42.1.0). Pin to ~42.1.0; revisit 42.x once its headless-Linux child-process teardown is stable. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Split the two "mounts the html_tag into the live editor DOM" cases (<u>/<mark>) out of formatToggle.spec.ts into formatToggleHtmlTagMount.spec.ts (jsdom). They route a live element through DOMPurify, which strips all elements under happy-dom on dompurify 3.4.8+ (its namespace hardening isn't satisfied there). The rest of formatToggle.spec.ts stays on happy-dom because its selection / picker assertions rely on happy-dom's selection behavior. Consistent with the other DOMPurify-dependent specs moved to jsdom in the dompurify bump. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
Jocs
force-pushed
the
chore/upgrade-deps-latest
branch
from
June 21, 2026 00:27
cb21f86 to
9a27344
Compare
hisaboh
added a commit
to hisaboh/remarks
that referenced
this pull request
Jun 27, 2026
upstream が持ち込んだ主なもの: - list serialization 刷新(空項目保持 marktext#4696/marktext#4697、markerOverride/_isLooseParentList) - code fence 長の保持 marktext#4755、ソースモード undo/redo、math/diagram スクロール - flush()/_flushOperationCache() による pending-edit 同期 marktext#2938 - plain-inline-spaces 保持の paste marktext#4706、大規模依存アップグレード marktext#4597 ほか 採用/保持の判断: - フォーク保持: CLAUDE.md、setWrapCodeBlocks、PDF 描画 - 両立: fence info(フォーク) + fenceLength(upstream)、whole-line paste(フォーク) + plain-inline-spaces(upstream)、@tauri-apps/cli 保持 + upstream バージョンアップ採用 - upstream 採用: flush 機構(フォークの flushPendingChanges / _commitOperationCache / _rafHandle / _isGoing を除去、呼び出し側 editor.vue を flush() に更新) 波及修正: - フォークの空 paragraph 往復保持を top-level (_listType 空) に限定し、upstream の 空リスト項目処理と両立(muya unit 10件の回帰を解消) - pnpm-lock.yaml をマージ後 package.json から再生成 検証(全緑): muya lint:types / check-circular / unit 1397 / conformance 1347、 desktop typecheck / unit 695、build:tauri 成功・実機動作確認 OK Co-Authored-By: Claude Opus 4.8 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Workspace-wide dependency upgrade to latest + shared-dependency version alignment + a recheck of the
pnpm.overridesadded by the security work.Landed upgrades
pnpm update -r(within-major latest)@types/nodekept on v22 to match the Node 22 runtime)vue-tsc --noEmitpassesplist.parse()call site; type-checksmarked 16 → 18 (muya parser migration)
marked 17+ changed tokenization; muya's parser layer was adapted:
checkboxtoken and keeps the literal[ ]/[x]marker in the item content (inparagraph.textfor loose lists). muya renders the marker from the task-list-itemcheckedmeta, socompatibleTaskListnow strips it from both tight and loose items — otherwise every md → state → md round-trip duplicated the checkbox.codetoken text now carries a trailing newline (fenced does not);markdownToStatestrips it so indented blocks round-trip.expected-failures.json.Deferred (need dedicated PRs)
Both are ground-up migrations of core features that can't be verified inside a bulk dependency bump:
defineMode/getMode/multiplexingMode/overlayMode/startState/modeURL/requireMode/Pass). CM6 is EditorState/EditorView + Lezer grammars. Staying on the latest CM5 (5.65.21, still maintained).rehype-pretty-code) on the standalone docs app; needsnext build+ Cloudflare deploy verification.@opennextjs/cloudflaredoes support next 16, so this is feasible as its own PR. The website's safe within-major updates (react/wrangler/tailwind/…) are included here and its type-check + lint pass.Shared-dependency consistency
Most shared deps are now aligned (dompurify, snabbdom, vitest, electron, katex, mermaid, @types/node, @playwright/test, jsdom, …). Remaining splits are upstream-constrained exceptions:
neostandard(peers eslint^9only); muya uses antfu (10)electron-vitepeers vite<=7Override recheck
Re-checked every override against the upgraded tree. The upgrades now resolve patched versions natively, so 7 of 8 security overrides were removed (@babel/core, form-data, js-yaml, tar, tmp, undici, ws). Kept: esbuild (vite 7.3.5 still pulls vulnerable esbuild 0.27.7; bridges until electron-vite supports vite 8) and the pre-existing postcss pin.
Verification
pnpm lint0 errors ·pnpm typecheckclean · muya lint/types clean · website type-check + lint passpnpm build:unpackbuilds cleanly🤖 Generated with Claude Code