Repository navigation
chore: update dependencies to latest compatible versions - #534
Merged
Mohamed Mansour (mohamedmansour) merged 5 commits intoSep 14, 2026
Merged
Mohamed Mansour (mohamedmansour) merged 5 commits into
Mohamed Mansour (mohamedmansour) merged 5 commits into
Conversation
Mohamed Mansour (mohamedmansour)
changed the base branch from
main
to
mohamedmansour-rustls-security-update
September 14, 2026 17:55
Base automatically changed from
mohamedmansour-rustls-security-update
to
main
September 14, 2026 17:56
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Mohamed Mansour (mohamedmansour)
force-pushed
the
mohamedmansour-latest-dependency-updates
branch
from
September 14, 2026 18:04
ecfdd66 to
c2d3e04
Compare
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Adapt the pnpm 12 setup from #506 to GitHub Actions and both current Azure installation paths. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use the maintained native pnpm setup action and make the all-offscreen fixture's geometry match its observer state. Preserve startup and no-hydration assertions while covering pointer wakeups. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
mcritzjam
approved these changes
Sep 14, 2026
Mohamed Mansour (mohamedmansour)
deleted the
mohamedmansour-latest-dependency-updates
branch
September 14, 2026 20:19
Mohamed Mansour (mohamedmansour)
added a commit
that referenced
this pull request
Sep 18, 2026
## Release Bumps WebUI to `0.0.29`. Previous release tag: `v0.0.28` ## Changes since `v0.0.28` Features: - Ship version-matched AI authoring guidance with `@microsoft/webui`, using a lightweight skill that reads the installed package's reference (feat: bundle versioned AI guidance with WebUI #522 by @mohamedmansour). - Add plugin-aware component discovery, with filename-based HTML components and manifest-driven FAST components (feat: add plugin-aware component discovery #524 by @mohamedmansour). - Add WebUI Press `--show=all|content` for shell-free documentation views that preserve SSR, hydration, authored examples, and accessible theme behavior (feat: add WebUI Press content mode #525 by @mohamedmansour). - Automatically support Trusted Types for compiled templates and generated CSS import maps without promoting arbitrary state HTML to trusted content (feat: use Trusted Types automatically in the framework #536 by @mohamedmansour). - Keep explicit streaming imports lightweight so applications can load streaming support early and application code later (feat: keep explicit streaming imports lightweight #539 by @mohamedmansour). - Render tree-shaped state with file-scoped named `<for id="...">` bodies, including forward references and recursive reuse without extra client runtime code. Use unbraced `each="item in items"`; the legacy `template` spelling and FAST component references produce actionable diagnostics (feat: add file-scoped recursive for loops #547 by @mohamedmansour). Fixes: - Preserve table-rooted hydration ownership and correctly compile whitespace-bearing, nested directives, preventing duplicate controls after reactive updates. Rebuild templates to receive the compiler fix (fix: preserve table-rooted hydration paths #512 by @mohamedmansour; fix: align client directive parsing with the HTML scanner #531 by @mohamedmansour). - Emit reachable stylesheets and templates in deterministic traversal order. External plugin implementations must adapt the affected `HandlerPlugin` and bootstrap component collection interfaces from hash sets to slices (fix: render reachable-component ordering deterministically #519 by @janechu). - Resolve bare CEM module specifiers through their owning packages, respecting export maps, package boundaries, and cache invalidation when nearer dependencies appear (fix: resolve bare CEM module specifiers #528 by @janechu). - Prevent spurious dev-server rebuilds from read-only filesystem activity and recursive traversal of linked workspace dependencies (Improve benchmark telemetry and dev-server watching #521 by @mohamedmansour). - Update rustls to address TLS 1.3 handshake encryption-level validation advisory RUSTSEC-2026-0285 (fix: update rustls to address RUSTSEC-2026-0285 #533 by @mohamedmansour). - Forward bare boolean and ARIA component inputs into SSR state while preserving empty literal attributes and existing conditional boolean bindings (fix: forward HTML component inputs during SSR #540 by @mohamedmansour). - Preserve sibling route declaration order across SSR and client routing so equally specific routes select the correct pending and error boundaries (fix: preserve route order for pending and error boundaries #541 by @mohamedmansour). - Handle skipped or superseded router view transitions without unhandled animation rejections, while preserving route-commit errors and responsive subsequent navigation (fix: handle router view transition rejections #543 by @mohamedmansour). - Wait for active dev-server rebuilds and their bundler subprocesses before graceful shutdown, preventing output writes after the server exits (fix: wait for dev-server rebuilds during shutdown #546 by @mohamedmansour). - Preserve global theme defaults when custom properties are overridden only by scoped selectors or conditional rules, so unmatched component instances retain their intended colors (fix: preserve theme defaults under scoped CSS overrides #548 by @mohamedmansour). Docs: - Add a data-driven Benchmark Explorer, centralize performance guidance, distinguish independent SSR/browser metrics, and publish resource telemetry with accessible methodology details (docs: centralize performance guidance and benchmark data #486 by @mohamedmansour; Improve benchmark telemetry and dev-server watching #521 by @mohamedmansour). - Update AI reference installation and migration guidance while retaining `/ai`, and clarify plugin-specific discovery and FAST converted-template requirements (feat: bundle versioned AI guidance with WebUI #522 by @mohamedmansour; feat: add plugin-aware component discovery #524 by @mohamedmansour). - Document owned Rust partial rendering, streaming state ownership, and watcher hashing benchmarks, including measurement scope and tradeoffs (perf: reduce partial response allocations #510 by @mohamedmansour; perf: move streaming command processing off async workers #529 by @mohamedmansour; perf: bound watcher hashing memory with reusable scratch #530 by @mohamedmansour). - Document automatic Trusted Types support, CSP enforcement, and first-declared precedence for equally specific routes and their pending/error boundaries (feat: use Trusted Types automatically in the framework #536 by @mohamedmansour; fix: preserve route order for pending and error boundaries #541 by @mohamedmansour). - Explain named recursive loops and their compatibility limits, scoped CSS token defaults, and router view-transition error handling (feat: add file-scoped recursive for loops #547 by @mohamedmansour; fix: preserve theme defaults under scoped CSS overrides #548 by @mohamedmansour; fix: handle router view transition rejections #543 by @mohamedmansour). Maintenance: - Reduce partial-response and per-render allocations through owned state projection, borrowed graph traversal, scalar formatting, and borrowed nested route trees. Rust callers use ownership-taking `Protocol::render_partial(Value, ...)`; JSON boundaries retain `render_partial_json` (perf: reduce partial response allocations #510 by @mohamedmansour; perf: cut per-render handler allocations #511 by @mohamedmansour; perf: avoid cloning nested route trees #513 by @mohamedmansour). - Move streaming command deserialization, validation, and default preparation onto the existing blocking renderer, transferring owned records and state rather than cloning retained projections (perf: move streaming command processing off async workers #529 by @mohamedmansour). - Bound watcher hashing content storage to one reusable 8 KiB buffer instead of repeated file-sized allocations while preserving invalidation behavior (perf: bound watcher hashing memory with reusable scratch #530 by @mohamedmansour). - Parallelize release WASM builds and artifact staging, and consolidate dependency scanning before release jobs (chore: parallelize release pipeline work #509 by @mohamedmansour). - Refresh compatible Rust and JavaScript dependencies and migrate repository tooling and CI to pnpm 12.3.4 while preserving existing audit constraints (chore: update dependencies to latest compatible versions #534 by @mohamedmansour). ## Validation - `cargo xtask check` - `pnpm --dir crates/webui-press test` (16 passed). - `pnpm --dir packages/webui-framework exec playwright test recursive-repeat --workers=2 --reporter=line` (6 passed). - `pnpm --dir packages/webui-router exec playwright test --grep "view transition rejection ownership" --workers=2 --reporter=line` (4 passed). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This change is based on
mainataa1d9905e2d540da6e13557d672427d260237e70, which already includes the merged rustls security fix from #533. The old security commit is not included in this PR's commit range.Update third-party Rust requirements, the pnpm catalog, the two example
tsxrequirements, and lockfiles using live registry metadata and Cargo/pnpm tooling, including supported stable major releases. Also migrate repository tooling and CI to the explicitly requested pnpm 12.3.4, adapting #506 to the current pipeline structure. Preserve all WebUI/local package versions, workspace links, catalog references, optional peer compatibility ranges, the Rust toolchain pin, and Node.js 22. No framework runtime changes, public API changes, or new audit exceptions.Registry-versus-resolution verification on 2026-09-14 confirms 44 of 51 direct Rust dependencies at latest stable, with seven audit-constrained exceptions below. Public npm version histories and the installed graph confirm all 23 application dependency names resolve to their highest stable releases, plus the intentional
typescript-6compatibility-test alias at the latest stable 6.x release,6.0.3. The primary TypeScript version remains7.0.2.Notable upgrades include comrak
0.55.0, actix-web4.15.0, tokio1.53.1, napi3.12.4, napi-derive3.6.5, Electron44.3.0, Playwright1.63.0, esbuild0.28.2, Node types26.5.1, FAST Element3.0.3, tsx4.23.13, and CodeMirror updates. Electron'slatesttag points to a 45 alpha; this PR deliberately selects the highest stable release instead.pnpm 12 and pipeline migration
packageManageris pnpm@12.3.4. This is the user's explicit selection and the highest stable version available in the configured registry, not the latest public release, 12.4.1.pnpm/setup@703c52620218391530e48b9e8870d5c0082e1b9b(v2.1.0) with pnpm 12.3.4,node@22, caching enabled, and dependency installation kept as a separate step. This maintained action installs the native pnpm executable directly and verifies npm's signature and checksum.PNPM_HOME/binon PATH. Existing frozen installs, store caching, and shell failure handling are preserved. Upgrade repository tooling to pnpm 12 #506 contained only the older assembly location; this change also covers the newer validation stage.The earlier portability fix removed machine-specific npm tarball URLs; the subsequent library refresh updated Electron/Node types and deduplicated compatible type packages. All 172 application resolutions remain SHA-512-only. The nine new package-manager resolutions use pnpm's officially generated SHA-1 hashes, which are weaker than SHA-512; each was independently compared with the exact version's public npm
dist.shasumand matched. Neither document contains registry-specific tarball URLs. The native checksum-refresh command did not upgrade the environment-document hashes; no manual cache edits or invented policy bypasses were used. The 172-entry supply-chain result below must not be interpreted as verification of those nine manager entries.CI repairs
The first pipeline migration exposed two distinct failures, addressed in
36c657a0:@pnpm/exebootstrap. Its Node SEA installer rejects Intel macOS before the requested pnpm 12.3.4 is installed, affecting the macOS build and both macOS wheel jobs. The maintained v2.1.0 action removes that bootstrap and selects pnpm 12's native platform package directly. No platform was skipped and pnpm was not downgraded. Source/input-contract checks are complete; macOS execution must still be confirmed by the new CI run.#visibleat the viewport origin, where legitimate pointer-over activation could hydrate it. Real pointer movement reproduced the exact['visible']failure locally. The test now positions the compiled fixture offscreen before bootstrap, asserts all tracked roots are actually beyond the viewport plus lead margin, and exercises pointer movement. The original one-startup-cohort and empty-hydrated assertions remain. No framework runtime behavior was changed.Rust versions constrained by the existing audit policy
The initial all-latest resolution failed the unchanged
cargo denyduplicate-crate policy. Existing latest napi/prost/pyo3 and other upstream dependencies still requiresyn2, while these newer releases introducesyn3. The selected versions are the newest releases that avoid those incompatible duplicate chains; these are patch-release holds, not omitted major-version upgrades.serde 1.0.229 -> serde_core =1.0.229 -> serde_derive =1.0.229 -> syn ^3; the core crate's exact derive edge participates in Cargo resolution.thiserror-impl 2.0.19and2.0.20requiresyn ^3; the implementation version is exact.clap 4.6.4..4.6.6 -> clap_derive =4.6.4 -> syn ^3.0.2.futures-util 0.3.34 -> futures-macro =0.3.34 -> syn ^3.0.wasm-bindgen-macro-support 0.2.128 -> syn ^3.0.js-sys 0.3.105 -> wasm-bindgen =0.2.128, requiring the preceding blocked macro chain.rcgen 0.14.10 -> pem ^4 -> base64 0.23; actix-http and awc still requirebase64 0.22.The lockfile also retains compatible transitive releases for these transitions:
tokio-macros 2.7.1,displaydoc 0.2.6,zerovec-derive 0.11.3, the ICU 2.2 family withzerovec 0.11.6,potential_utf 0.1.5,tinystr 0.8.3,multiversion 0.8.0, and the coupled futures 0.3.33 packages. No audit policy was weakened. The pre-existing, unused example-local Cargo.lock is unchanged; the Rust example belongs to the workspace and resolves through the root lockfile.Validation under pnpm 12.3.4
cargo xtask checkpassed in 135.6 seconds under this toolchain, including formatting, clippy, protocol drift, unchanged dependency audits, workspace tests, native builds, all three WASM variants, all examples, benchmark smoke validation, and docs. This is a fresh pnpm-12 run, not a claim based on the earlier pnpm-11 gate.pnpm install --offline --frozen-lockfile --no-trust-lockfile, using cached public-registry metadata withno-downgradepolicy unchanged: all 172 application entries passed supply-chain verification, and pnpm 12 installed the 127 applicable packages and ran approved lifecycle scripts.pnpm auditread both YAML documents, reporting 181 dependencies and zero advisories. This advisory scan is separate from integrity/policy verification.rust-version, so this metadata check is not a claim of a full Rust 1.93 build.Local registry limitation
The configured registry provides pnpm 12.3.4 but omits public 12.4.1 and the newest Electron 44.3.0 / Node types 26.5.1 metadata. An online strict install therefore correctly rejected the two missing application releases; a bounded public-registry native verification attempt did not complete, and native public metadata requests report transport errors. The successful pnpm-12 install used its supported offline mode with previously cached public-registry metadata while keeping policy verification enabled. Fresh online installation in this local environment remains dependent on registry availability/transport; no TLS or supply-chain protections were disabled, and no application dependencies were downgraded.