Skip to content

chore: update dependencies to latest compatible versions - #534

Merged
Mohamed Mansour (mohamedmansour) merged 5 commits into
mainfrom
mohamedmansour-latest-dependency-updates
Sep 14, 2026
Merged

Mohamed Mansour (mohamedmansour) merged 5 commits into
mainfrom
mohamedmansour-latest-dependency-updates

Conversation

@mohamedmansour

@mohamedmansour Mohamed Mansour (mohamedmansour) commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Summary

This change is based on main at aa1d9905e2d540da6e13557d672427d260237e70, which already includes the merged rustls security fix from #533. The old security commit is not included in this PR's commit range.

Update third-party Rust requirements, the pnpm catalog, the two example tsx requirements, and lockfiles using live registry metadata and Cargo/pnpm tooling, including supported stable major releases. Also migrate repository tooling and CI to the explicitly requested pnpm 12.3.4, adapting #506 to the current pipeline structure. Preserve all WebUI/local package versions, workspace links, catalog references, optional peer compatibility ranges, the Rust toolchain pin, and Node.js 22. No framework runtime changes, public API changes, or new audit exceptions.

Registry-versus-resolution verification on 2026-09-14 confirms 44 of 51 direct Rust dependencies at latest stable, with seven audit-constrained exceptions below. Public npm version histories and the installed graph confirm all 23 application dependency names resolve to their highest stable releases, plus the intentional typescript-6 compatibility-test alias at the latest stable 6.x release, 6.0.3. The primary TypeScript version remains 7.0.2.

Notable upgrades include comrak 0.55.0, actix-web 4.15.0, tokio 1.53.1, napi 3.12.4, napi-derive 3.6.5, Electron 44.3.0, Playwright 1.63.0, esbuild 0.28.2, Node types 26.5.1, FAST Element 3.0.3, tsx 4.23.13, and CodeMirror updates. Electron's latest tag points to a 45 alpha; this PR deliberately selects the highest stable release instead.

pnpm 12 and pipeline migration

  • Root packageManager is pnpm@12.3.4. This is the user's explicit selection and the highest stable version available in the configured registry, not the latest public release, 12.4.1.
  • GitHub's shared build action uses immutable pnpm/setup@703c52620218391530e48b9e8870d5c0082e1b9b (v2.1.0) with pnpm 12.3.4, node@22, caching enabled, and dependency installation kept as a separate step. This maintained action installs the native pnpm executable directly and verifies npm's signature and checksum.
  • Both Azure installation sites—hotfix validation and release assembly—replace Corepack bootstrap with the official installer pinned to 12.3.4 and PNPM_HOME/bin on PATH. Existing frozen installs, store caching, and shell failure handling are preserved. Upgrade repository tooling to pnpm 12 #506 contained only the older assembly location; this change also covers the newer validation stage.
  • pnpm 12 generates an environment YAML document before the application lock document. The environment document records pnpm and eight platform binaries. The entire 172-entry application document is unchanged by the tooling migration and CI repairs.

The earlier portability fix removed machine-specific npm tarball URLs; the subsequent library refresh updated Electron/Node types and deduplicated compatible type packages. All 172 application resolutions remain SHA-512-only. The nine new package-manager resolutions use pnpm's officially generated SHA-1 hashes, which are weaker than SHA-512; each was independently compared with the exact version's public npm dist.shasum and matched. Neither document contains registry-specific tarball URLs. The native checksum-refresh command did not upgrade the environment-document hashes; no manual cache edits or invented policy bypasses were used. The 172-entry supply-chain result below must not be interpreted as verification of those nine manager entries.

CI repairs

The first pipeline migration exposed two distinct failures, addressed in 36c657a0:

  • macOS bootstrap: the v1 action referenced by Upgrade repository tooling to pnpm 12 #506 hardcodes a legacy @pnpm/exe bootstrap. Its Node SEA installer rejects Intel macOS before the requested pnpm 12.3.4 is installed, affecting the macOS build and both macOS wheel jobs. The maintained v2.1.0 action removes that bootstrap and selects pnpm 12's native platform package directly. No platform was skipped and pnpm was not downgraded. Source/input-contract checks are complete; macOS execution must still be confirmed by the new CI run.
  • All-offscreen startup fixture: this E2E failure already existed on the pre-pnpm-12 dependency head. The test mocked every observer entry as offscreen but left #visible at the viewport origin, where legitimate pointer-over activation could hydrate it. Real pointer movement reproduced the exact ['visible'] failure locally. The test now positions the compiled fixture offscreen before bootstrap, asserts all tracked roots are actually beyond the viewport plus lead margin, and exercises pointer movement. The original one-startup-cohort and empty-hydrated assertions remain. No framework runtime behavior was changed.

Rust versions constrained by the existing audit policy

The initial all-latest resolution failed the unchanged cargo deny duplicate-crate policy. Existing latest napi/prost/pyo3 and other upstream dependencies still require syn 2, while these newer releases introduce syn 3. The selected versions are the newest releases that avoid those incompatible duplicate chains; these are patch-release holds, not omitted major-version upgrades.

Direct dependency Selected Latest stable Exact reason for holding
serde 1.0.228 1.0.229 serde 1.0.229 -> serde_core =1.0.229 -> serde_derive =1.0.229 -> syn ^3; the core crate's exact derive edge participates in Cargo resolution.
thiserror 2.0.18 2.0.20 Both thiserror-impl 2.0.19 and 2.0.20 require syn ^3; the implementation version is exact.
clap 4.6.3 4.6.6 clap 4.6.4..4.6.6 -> clap_derive =4.6.4 -> syn ^3.0.2.
futures-util 0.3.33 0.3.34 futures-util 0.3.34 -> futures-macro =0.3.34 -> syn ^3.0.
wasm-bindgen 0.2.127 0.2.128 The exact-version macro chain ends at wasm-bindgen-macro-support 0.2.128 -> syn ^3.0.
js-sys 0.3.104 0.3.105 js-sys 0.3.105 -> wasm-bindgen =0.2.128, requiring the preceding blocked macro chain.
rcgen 0.14.9 0.14.10 rcgen 0.14.10 -> pem ^4 -> base64 0.23; actix-http and awc still require base64 0.22.

The lockfile also retains compatible transitive releases for these transitions: tokio-macros 2.7.1, displaydoc 0.2.6, zerovec-derive 0.11.3, the ICU 2.2 family with zerovec 0.11.6, potential_utf 0.1.5, tinystr 0.8.3, multiversion 0.8.0, and the coupled futures 0.3.33 packages. No audit policy was weakened. The pre-existing, unused example-local Cargo.lock is unchanged; the Rust example belongs to the workspace and resolves through the root lockfile.

Validation under pnpm 12.3.4

  • Ordinary activation reports 12.3.4. After both CI repairs, cargo xtask check passed in 135.6 seconds under this toolchain, including formatting, clippy, protocol drift, unchanged dependency audits, workspace tests, native builds, all three WASM variants, all examples, benchmark smoke validation, and docs. This is a fresh pnpm-12 run, not a claim based on the earlier pnpm-11 gate.
  • The corrected startup regression passed 10 consecutive runs with retries disabled. The full compiled-fixture framework browser suite then passed 314 tests with 2 pre-existing skips and retries disabled on Windows. E2E TypeScript checking also passed. No assertions, retries, thresholds, or test coverage were weakened.
  • Supported pnpm install --offline --frozen-lockfile --no-trust-lockfile, using cached public-registry metadata with no-downgrade policy unchanged: all 172 application entries passed supply-chain verification, and pnpm 12 installed the 127 applicable packages and ran approved lifecycle scripts.
  • Native/projection 72 passed against this checkout's rebuilt addon; framework units 346 passed; router units 113 passed. Electron example build and binary-version smoke passed with 44.3.0.
  • pnpm audit read both YAML documents, reporting 181 dependencies and zero advisories. This advisory scan is separate from integrity/policy verification.
  • YAML structural assertions confirm matching 12.3.4 pins in the root manifest, GitHub setup, both Azure install scripts, and environment lock document, while preserving Node 22, caching, and frozen installs. Existing release-pipeline regression tests: 2 passed. The updated action's declared inputs and native downloader implementation were checked against the pinned upstream source.
  • Automated comparisons confirm the full application lock document did not change during tooling migration or CI repairs, all nine generated manager hashes match public npm metadata for their exact versions, and no registry-specific tarball URLs were introduced.
  • Earlier broad-upgrade validation: targeted Rust tests node 41, press 122, wasm 29; streaming server tests 10; router Playwright 33 passed / 4 existing skips. No new skips or weakened tests.
  • MSRV metadata check covers 111 new/upgraded resolved Rust packages. The highest declared minimum among them is Rust 1.88; no resolved package declares a minimum above the workspace's 1.93. Twelve upgraded crates omit rust-version, so this metadata check is not a claim of a full Rust 1.93 build.

Local registry limitation

The configured registry provides pnpm 12.3.4 but omits public 12.4.1 and the newest Electron 44.3.0 / Node types 26.5.1 metadata. An online strict install therefore correctly rejected the two missing application releases; a bounded public-registry native verification attempt did not complete, and native public metadata requests report transport errors. The successful pnpm-12 install used its supported offline mode with previously cached public-registry metadata while keeping policy verification enabled. Fresh online installation in this local environment remains dependent on registry availability/transport; no TLS or supply-chain protections were disabled, and no application dependencies were downgraded.

@mohamedmansour
Mohamed Mansour (mohamedmansour) changed the base branch from main to mohamedmansour-rustls-security-update September 14, 2026 17:55
Base automatically changed from mohamedmansour-rustls-security-update to main September 14, 2026 17:56
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@mohamedmansour
Mohamed Mansour (mohamedmansour) force-pushed the mohamedmansour-latest-dependency-updates branch from ecfdd66 to c2d3e04 Compare September 14, 2026 18:04
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Adapt the pnpm 12 setup from #506 to GitHub Actions and both current Azure installation paths.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use the maintained native pnpm setup action and make the all-offscreen fixture's geometry match its observer state. Preserve startup and no-hydration assertions while covering pointer wakeups.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@mohamedmansour
Mohamed Mansour (mohamedmansour) merged commit 628141f into main Sep 14, 2026
35 checks passed
@mohamedmansour
Mohamed Mansour (mohamedmansour) deleted the mohamedmansour-latest-dependency-updates branch September 14, 2026 20:19
Mohamed Mansour (mohamedmansour) added a commit that referenced this pull request Sep 18, 2026
## Release

Bumps WebUI to `0.0.29`.

Previous release tag: `v0.0.28`

## Changes since `v0.0.28`

Features:

- Ship version-matched AI authoring guidance with `@microsoft/webui`,
using a lightweight skill that reads the installed package's reference
(feat: bundle versioned AI guidance with WebUI #522 by @mohamedmansour).
- Add plugin-aware component discovery, with filename-based HTML
components and manifest-driven FAST components (feat: add plugin-aware
component discovery #524 by @mohamedmansour).
- Add WebUI Press `--show=all|content` for shell-free documentation
views that preserve SSR, hydration, authored examples, and accessible
theme behavior (feat: add WebUI Press content mode #525 by
@mohamedmansour).
- Automatically support Trusted Types for compiled templates and
generated CSS import maps without promoting arbitrary state HTML to
trusted content (feat: use Trusted Types automatically in the framework
#536 by @mohamedmansour).
- Keep explicit streaming imports lightweight so applications can load
streaming support early and application code later (feat: keep explicit
streaming imports lightweight #539 by @mohamedmansour).
- Render tree-shaped state with file-scoped named `<for id="...">`
bodies, including forward references and recursive reuse without extra
client runtime code. Use unbraced `each="item in items"`; the legacy
`template` spelling and FAST component references produce actionable
diagnostics (feat: add file-scoped recursive for loops #547 by
@mohamedmansour).

Fixes:

- Preserve table-rooted hydration ownership and correctly compile
whitespace-bearing, nested directives, preventing duplicate controls
after reactive updates. Rebuild templates to receive the compiler fix
(fix: preserve table-rooted hydration paths #512 by @mohamedmansour;
fix: align client directive parsing with the HTML scanner #531 by
@mohamedmansour).
- Emit reachable stylesheets and templates in deterministic traversal
order. External plugin implementations must adapt the affected
`HandlerPlugin` and bootstrap component collection interfaces from hash
sets to slices (fix: render reachable-component ordering
deterministically #519 by @janechu).
- Resolve bare CEM module specifiers through their owning packages,
respecting export maps, package boundaries, and cache invalidation when
nearer dependencies appear (fix: resolve bare CEM module specifiers #528
by @janechu).
- Prevent spurious dev-server rebuilds from read-only filesystem
activity and recursive traversal of linked workspace dependencies
(Improve benchmark telemetry and dev-server watching #521 by
@mohamedmansour).
- Update rustls to address TLS 1.3 handshake encryption-level validation
advisory RUSTSEC-2026-0285 (fix: update rustls to address
RUSTSEC-2026-0285 #533 by @mohamedmansour).
- Forward bare boolean and ARIA component inputs into SSR state while
preserving empty literal attributes and existing conditional boolean
bindings (fix: forward HTML component inputs during SSR #540 by
@mohamedmansour).
- Preserve sibling route declaration order across SSR and client routing
so equally specific routes select the correct pending and error
boundaries (fix: preserve route order for pending and error boundaries
#541 by @mohamedmansour).
- Handle skipped or superseded router view transitions without unhandled
animation rejections, while preserving route-commit errors and
responsive subsequent navigation (fix: handle router view transition
rejections #543 by @mohamedmansour).
- Wait for active dev-server rebuilds and their bundler subprocesses
before graceful shutdown, preventing output writes after the server
exits (fix: wait for dev-server rebuilds during shutdown #546 by
@mohamedmansour).
- Preserve global theme defaults when custom properties are overridden
only by scoped selectors or conditional rules, so unmatched component
instances retain their intended colors (fix: preserve theme defaults
under scoped CSS overrides #548 by @mohamedmansour).

Docs:

- Add a data-driven Benchmark Explorer, centralize performance guidance,
distinguish independent SSR/browser metrics, and publish resource
telemetry with accessible methodology details (docs: centralize
performance guidance and benchmark data #486 by @mohamedmansour; Improve
benchmark telemetry and dev-server watching #521 by @mohamedmansour).
- Update AI reference installation and migration guidance while
retaining `/ai`, and clarify plugin-specific discovery and FAST
converted-template requirements (feat: bundle versioned AI guidance with
WebUI #522 by @mohamedmansour; feat: add plugin-aware component
discovery #524 by @mohamedmansour).
- Document owned Rust partial rendering, streaming state ownership, and
watcher hashing benchmarks, including measurement scope and tradeoffs
(perf: reduce partial response allocations #510 by @mohamedmansour;
perf: move streaming command processing off async workers #529 by
@mohamedmansour; perf: bound watcher hashing memory with reusable
scratch #530 by @mohamedmansour).
- Document automatic Trusted Types support, CSP enforcement, and
first-declared precedence for equally specific routes and their
pending/error boundaries (feat: use Trusted Types automatically in the
framework #536 by @mohamedmansour; fix: preserve route order for pending
and error boundaries #541 by @mohamedmansour).
- Explain named recursive loops and their compatibility limits, scoped
CSS token defaults, and router view-transition error handling (feat: add
file-scoped recursive for loops #547 by @mohamedmansour; fix: preserve
theme defaults under scoped CSS overrides #548 by @mohamedmansour; fix:
handle router view transition rejections #543 by @mohamedmansour).

Maintenance:

- Reduce partial-response and per-render allocations through owned state
projection, borrowed graph traversal, scalar formatting, and borrowed
nested route trees. Rust callers use ownership-taking
`Protocol::render_partial(Value, ...)`; JSON boundaries retain
`render_partial_json` (perf: reduce partial response allocations #510 by
@mohamedmansour; perf: cut per-render handler allocations #511 by
@mohamedmansour; perf: avoid cloning nested route trees #513 by
@mohamedmansour).
- Move streaming command deserialization, validation, and default
preparation onto the existing blocking renderer, transferring owned
records and state rather than cloning retained projections (perf: move
streaming command processing off async workers #529 by @mohamedmansour).
- Bound watcher hashing content storage to one reusable 8 KiB buffer
instead of repeated file-sized allocations while preserving invalidation
behavior (perf: bound watcher hashing memory with reusable scratch #530
by @mohamedmansour).
- Parallelize release WASM builds and artifact staging, and consolidate
dependency scanning before release jobs (chore: parallelize release
pipeline work #509 by @mohamedmansour).
- Refresh compatible Rust and JavaScript dependencies and migrate
repository tooling and CI to pnpm 12.3.4 while preserving existing audit
constraints (chore: update dependencies to latest compatible versions
#534 by @mohamedmansour).

## Validation

- `cargo xtask check`
- `pnpm --dir crates/webui-press test` (16 passed).
- `pnpm --dir packages/webui-framework exec playwright test
recursive-repeat --workers=2 --reporter=line` (6 passed).
- `pnpm --dir packages/webui-router exec playwright test --grep "view
transition rejection ownership" --workers=2 --reporter=line` (4 passed).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants