chore(deps): refresh patches after dependency upgrades - #5839
Conversation
…3 updates Bumps the minor-and-patch group with 23 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@astryxdesign/cli](https://github.com/facebook/astryx/tree/HEAD/packages/cli) | `0.6.2` | `0.6.3` | | [@astryxdesign/core](https://github.com/facebook/astryx/tree/HEAD/packages/core) | `0.6.2` | `0.6.3` | | [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) | `2.5.13` | `2.5.14` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.5.1` | `26.6.3` | | [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.35.1` | `6.38.0` | | [@modelcontextprotocol/client](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.1.0` | | [@modelcontextprotocol/node](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.1.0` | | [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.30.0` | `1.30.1` | | [@modelcontextprotocol/server](https://github.com/modelcontextprotocol/typescript-sdk) | `2.0.0` | `2.1.0` | | [@larksuiteoapi/node-sdk](https://github.com/larksuite/node-sdk) | `1.73.3` | `1.74.0` | | [image-dimensions](https://github.com/sindresorhus/image-dimensions) | `2.5.1` | `2.6.0` | | [@agentclientprotocol/sdk](https://github.com/agentclientprotocol/typescript-sdk) | `1.4.0` | `1.5.0` | | [systeminformation](https://github.com/sebhildebrandt/systeminformation) | `5.33.10` | `5.33.13` | | [@earendil-works/pi-tui](https://github.com/earendil-works/pi/tree/HEAD/packages/tui) | `0.85.1` | `0.87.1` | | [katex](https://github.com/KaTeX/KaTeX) | `0.18.7` | `0.18.9` | | [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.45.0` | `1.48.0` | | [@jackwener/opencli](https://github.com/jackwener/opencli) | `1.8.7` | `1.8.8` | | [@astryxdesign/theme-neutral](https://github.com/facebook/astryx/tree/HEAD/packages/themes/neutral) | `0.6.2` | `0.6.3` | | [@babel/parser](https://github.com/babel/babel/tree/HEAD/packages/babel-parser) | `7.29.7` | `7.29.9` | | [electron-builder](https://github.com/electron-userland/electron-builder/tree/HEAD/packages/electron-builder) | `26.16.1` | `26.17.0` | | [simple-icons](https://github.com/simple-icons/simple-icons) | `16.31.0` | `16.32.0` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.3.0` | `8.3.1` | | [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro) | `7.3.2` | `7.3.5` | Updates `@astryxdesign/cli` from 0.6.2 to 0.6.3 - [Release notes](https://github.com/facebook/astryx/releases) - [Changelog](https://github.com/facebook/astryx/blob/main/packages/cli/CHANGELOG.md) - [Commits](https://github.com/facebook/astryx/commits/v0.6.3/packages/cli) Updates `@astryxdesign/core` from 0.6.2 to 0.6.3 - [Release notes](https://github.com/facebook/astryx/releases) - [Changelog](https://github.com/facebook/astryx/blob/main/packages/core/CHANGELOG.md) - [Commits](https://github.com/facebook/astryx/commits/v0.6.3/packages/core) Updates `@biomejs/biome` from 2.5.13 to 2.5.14 - [Release notes](https://github.com/biomejs/biome/releases) - [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md) - [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.14/packages/@biomejs/biome) Updates `@types/node` from 26.5.1 to 26.6.3 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `knip` from 6.35.1 to 6.38.0 - [Release notes](https://github.com/webpro-nl/knip/releases) - [Commits](https://github.com/webpro-nl/knip/commits/knip@6.38.0/packages/knip) Updates `@modelcontextprotocol/client` from 2.0.0 to 2.1.0 - [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases) - [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/client@2.0.0...@modelcontextprotocol/client@2.1.0) Updates `@modelcontextprotocol/node` from 2.0.0 to 2.1.0 - [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases) - [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/node@2.0.0...@modelcontextprotocol/node@2.1.0) Updates `@modelcontextprotocol/sdk` from 1.30.0 to 1.30.1 - [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases) - [Commits](modelcontextprotocol/typescript-sdk@1.30.0...1.30.1) Updates `@modelcontextprotocol/server` from 2.0.0 to 2.1.0 - [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases) - [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/@modelcontextprotocol/server@2.0.0...@modelcontextprotocol/server@2.1.0) Updates `@larksuiteoapi/node-sdk` from 1.73.3 to 1.74.0 - [Commits](https://github.com/larksuite/node-sdk/commits) Updates `image-dimensions` from 2.5.1 to 2.6.0 - [Release notes](https://github.com/sindresorhus/image-dimensions/releases) - [Commits](sindresorhus/image-dimensions@v2.5.1...v2.6.0) Updates `@agentclientprotocol/sdk` from 1.4.0 to 1.5.0 - [Release notes](https://github.com/agentclientprotocol/typescript-sdk/releases) - [Changelog](https://github.com/agentclientprotocol/typescript-sdk/blob/main/CHANGELOG.md) - [Commits](agentclientprotocol/typescript-sdk@v1.4.0...v1.5.0) Updates `systeminformation` from 5.33.10 to 5.33.13 - [Release notes](https://github.com/sebhildebrandt/systeminformation/releases) - [Changelog](https://github.com/sebhildebrandt/systeminformation/blob/master/CHANGELOG.md) - [Commits](sebhildebrandt/systeminformation@v5.33.10...v5.33.13) Updates `@earendil-works/pi-tui` from 0.85.1 to 0.87.1 - [Release notes](https://github.com/earendil-works/pi/releases) - [Changelog](https://github.com/earendil-works/pi/blob/main/packages/tui/CHANGELOG.md) - [Commits](https://github.com/earendil-works/pi/commits/v0.87.1/packages/tui) Updates `katex` from 0.18.7 to 0.18.9 - [Release notes](https://github.com/KaTeX/KaTeX/releases) - [Changelog](https://github.com/KaTeX/KaTeX/blob/main/CHANGELOG.md) - [Commits](KaTeX/KaTeX@v0.18.7...v0.18.9) Updates `lucide-react` from 1.45.0 to 1.48.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.48.0/packages/lucide-react) Updates `@jackwener/opencli` from 1.8.7 to 1.8.8 - [Release notes](https://github.com/jackwener/opencli/releases) - [Changelog](https://github.com/jackwener/OpenCLI/blob/main/CHANGELOG.md) - [Commits](jackwener/OpenCLI@v1.8.7...v1.8.8) Updates `@astryxdesign/theme-neutral` from 0.6.2 to 0.6.3 - [Release notes](https://github.com/facebook/astryx/releases) - [Changelog](https://github.com/facebook/astryx/blob/main/packages/themes/neutral/CHANGELOG.md) - [Commits](https://github.com/facebook/astryx/commits/v0.6.3/packages/themes/neutral) Updates `@babel/parser` from 7.29.7 to 7.29.9 - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.29.9/packages/babel-parser) Updates `electron-builder` from 26.16.1 to 26.17.0 - [Release notes](https://github.com/electron-userland/electron-builder/releases) - [Changelog](https://github.com/electron-userland/electron-builder/blob/electron-builder@26.17.0/packages/electron-builder/CHANGELOG.md) - [Commits](https://github.com/electron-userland/electron-builder/commits/electron-builder@26.17.0/packages/electron-builder) Updates `simple-icons` from 16.31.0 to 16.32.0 - [Release notes](https://github.com/simple-icons/simple-icons/releases) - [Commits](simple-icons/simple-icons@16.31.0...16.32.0) Updates `vite` from 8.3.0 to 8.3.1 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite) Updates `astro` from 7.3.2 to 7.3.5 - [Release notes](https://github.com/withastro/astro/releases) - [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md) - [Commits](https://github.com/withastro/astro/commits/astro@7.3.5/packages/astro) --- updated-dependencies: - dependency-name: "@astryxdesign/cli" dependency-version: 0.6.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@astryxdesign/core" dependency-version: 0.6.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@biomejs/biome" dependency-version: 2.5.14 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@types/node" dependency-version: 26.6.3 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: knip dependency-version: 6.38.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@modelcontextprotocol/client" dependency-version: 2.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@modelcontextprotocol/node" dependency-version: 2.1.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@modelcontextprotocol/sdk" dependency-version: 1.30.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@modelcontextprotocol/server" dependency-version: 2.1.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@larksuiteoapi/node-sdk" dependency-version: 1.74.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: image-dimensions dependency-version: 2.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@agentclientprotocol/sdk" dependency-version: 1.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: systeminformation dependency-version: 5.33.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@earendil-works/pi-tui" dependency-version: 0.87.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: katex dependency-version: 0.18.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: lucide-react dependency-version: 1.48.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@jackwener/opencli" dependency-version: 1.8.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@astryxdesign/theme-neutral" dependency-version: 0.6.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: "@babel/parser" dependency-version: 7.29.9 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: electron-builder dependency-version: 26.17.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: simple-icons dependency-version: 16.32.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: vite dependency-version: 8.3.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: astro dependency-version: 7.3.5 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Generated-by: Codex
9c151cb to
d0960b7
Compare
hqhq1025
left a comment
There was a problem hiding this comment.
The dependency refresh and regenerated patches install and build successfully, but the required test check is failing on the Astryx surface inventory. I found one blocking issue; the remaining focused patch/integration checks passed. The macOS ZIP behavior was not exercised locally (hosted macOS packaging succeeded). This is not a merge approval.
Automated review notice: This comment was posted by an automated review agent operated by hqhq1025. It is not an independent human review and does not replace one.
Generated-by: Codex
jackwener
left a comment
There was a problem hiding this comment.
Reviewed head d0960b78a4557f51ce1181b6154701943757ed28, which supersedes #5833. Clean install now works (package, package-linux, windows_recovery and audit are green). test is still red, so this is not ready yet.
Blocker (P1, mechanical): test stops at the Astryx surface-inventory check. It fails with "astryx surface inventory is stale; run: npm run astryx:surface-inventory:write": docs/astryx-surface-file-inventory.md records the @astryxdesign/core version it was generated against, and that version is now 0.6.3. The job ends there, so the UI, Desktop and Storybook suites have not run on this head. That matters because of the next point.
The @astryxdesign/core patch is a real re-port, not a re-anchor. pi-tui, @modelcontextprotocol/client and app-builder-lib only move context lines; their added lines are unchanged. The Astryx patch's added lines differ substantively, because upstream 0.6.3 reworked the Markdown path (parseMarkdown → parseMarkdownAst, new countBlockTextLength / countInlineTextLength helpers, a parsedText === '' early return). The behaviors in patches/README.md need their guarding tests and stories to pass on this head before merging: the tokenizer caching only valid languages, CodeBlock geometry, the composer layout-effect sync, and the host-owned trigger and anchor state. In particular that means the app-shell submission stories and the 1,200-line CodeBlock geometry run.
Other checks:
overrides["@jackwener/opencli@1.8.8"].undici = "7.29.1"clears GHSA-3wwx-pv8p-q78v; the shipped-dependency audit is green.- The install-script allowlist moves to
esbuild@0.28.2and@jackwener/opencli@1.8.8, andLICENSEand the notices follow the new versions.
P3: in app-builder-lib 26.17.0, the Maka hunk that forces the system zip for macOS update ZIPs now sits after upstream's new storedPaths is not supported with the native zip fallback guard, so a mac ZIP with storedPaths would bypass that guard. Today only the NSIS target sets storedPaths, so nothing is affected. Moving the Maka override above the guard would keep it fail-closed if a mac caller ever appears.
Not run locally.
hqhq1025
left a comment
There was a problem hiding this comment.
The prior Astryx inventory failure is fixed: the committed inventory now names core 0.6.3 and the generator check passes. This revision also regenerates the theme artifacts and adjusts the Astryx Spinner and macOS archive patches. A clean install, test build, focused patch/inventory tests, theme check, notices, and license checks pass locally; I found no substantiated P0–P3 issue in the reviewed paths. The current-head hosted test job is still running, so this is not a readiness or merge approval. I did not exercise the macOS ZIP path or a packaged Desktop locally.
Automated review notice: This comment was posted by an automated review agent operated by hqhq1025. It is not an independent human review and does not replace one.
jackwener
left a comment
There was a problem hiding this comment.
Approving at ff72d4a00135ba00dacbcbb4b50dd05bf658606e: every hosted check is green, including the full test job, so the UI, Desktop and Storybook suites guarding the re-ported Astryx patch now pass.
078bc9b3bregenerates the surface inventory (@astryxdesign/core@0.6.3) and the generated theme headers. The 0.6.3 theme builder also emits a:scope { font-family: var(--font-family-body) }rule.ff72d4a00completes the Astryx re-port. The spinner re-pin now follows 0.6.3's rotation host: it listens on the host span, filters to its ownanimationstart, and ships the matching keyframes. It also closes my P3: the Maka override inapp-builder-libnow runs before upstream'sstoredPathsnative-zip guard, so that guard stays fail-closed.- As reviewed in #5839 (review): the pi-tui, MCP client and app-builder-lib patches keep their added lines, the undici 7.29.1 override clears GHSA-3wwx-pv8p-q78v, and the allowlist and notices follow the new versions.
Not run locally.
Astro-Han
left a comment
There was a problem hiding this comment.
Reviewed exact head ff72d4a00135ba00dacbcbb4b50dd05bf658606e as a second reviewer, focusing on the patch set and the lockfile.
All 14 patches apply to the locked versions. The build passes and the notices are consistent. The pi-tui, MCP client, app-builder-lib and Astryx Markdown patches keep their original intent. The lockfile adds no new install scripts or license changes. The two major bumps (tinyclip, obug) and the new verkit come in via astro, which only the website uses. undici 7.29.1 is the fixed version for GHSA-3wwx-pv8p-q78v.
P2: the Spinner re-port stacks two animations (inline on patches/@astryxdesign+core+0.6.3.patch). Astryx 0.6.3 no longer rotates the spinner. It now animates the arc's stroke-dashoffset (x1nlxm0d → x1wbvqyn-B, linear) and dropped the rotate keyframes. The patch re-adds a rotate keyframe (xqng64z-B) and a steps(16) rotation on the host span, but it leaves upstream's dash animation on the circle.
- In headless Chromium, the patched spinner reports two concurrent 0.73s animations: the host rotating in steps and the circle's dash moving linearly. The arc travels about two turns per cycle and mixes stepped with smooth motion.
- The patch's stated goal is to avoid per-frame SVG repaint on the main thread. The linear dash-offset animation still repaints every frame, so that goal is lost.
- The story in
packages/ui/stories/functional-motion.stories.tsxstill passes, becausesvg.getAnimations()without{subtree: true}doesn't see the circle's animation. repinonly re-pins the host animation.- Suggested fix: keep a single mechanism. Either step the arc's dash animation and re-pin the circle, or keep the host rotation and drop the arc's animation classes. Then have the story assert exactly one animation with
{subtree: true}.
P3 (inline): LICENSE still says the theme artifacts are based on theme-neutral v0.6.2, but they were regenerated from 0.6.3.
Nit: only packages/ui bumps lucide-react, so Desktop bundles both 1.48.0 (nested) and 1.45.0 (root). The notices list both, so this is just a dedupe opportunity.
Commands run:
npm ci --ignore-scripts+apply-dependency-patches(14/14)check:asf-headers,check:third-party-notices(both variants)git diff --checkastryx:theme --checkastryx:surface-inventory(23/23)npm run build- mcp/cli/ui
test:dist: 261/261, 1334 pass with 3 skipped, 692/692 check:release: one failure inscripts/desktop-release-targets.test.mjs, a Node test-runner deserialization error. The file passes 4/4 on its own, so this looks environmental.
Not run: Storybook in a browser, and the Desktop app.
Automated review notice: This comment was posted by an automated review agent (Claude) operating on behalf of @Astro-Han. It is not an independent human review and does not replace one.
…5860) Astryx 0.6.3 moved the spinner's motion from rotating the svg to a linear stroke-dashoffset animation on the arc circle. The #5839 re-port kept our stepped rotation on the host span but left the arc animation in place, so two animations ran together: the arc travelled two turns per cycle, mixed stepped with smooth motion, and still repainted the SVG every frame. Keep the host span's steps(16) rotation, which the compositor runs, and drop the arc's animation classes. Upstream's dash-offset approach avoids a WebKit cap wobble on iOS, which Maka's Chromium-only renderer does not hit. The timeline-origin batch now reads the host again, and the patch's source copy defines the rotation keyframes it references. The story asserts a single animation across the spinner subtree; the old svg-only check could not see the arc's animation. LICENSE now names theme-neutral v0.6.3, which #5839 regenerated the theme artifacts from. Generated-by: Claude Code
Brings in the dependency-refresh train through apache#5839/apache#5860. The single conflict was the root allowScripts block: upstream mechanically carried "@jackwener/opencli@1.8.8": true forward from the dependabot bump, while this branch holds the reviewed deny (opencli's skipped shell-completion postinstall produces no artifact Maka needs). Keep the deny decisions and re-key the three bumped versions to the new lockfile: @jackwener/opencli 1.8.7 -> 1.8.8, @astryxdesign/cli and @astryxdesign/core 0.6.2 -> 0.6.3. The other six entries already match. scripts/check-allow-scripts.mjs passes against the merged lockfile (9/9 install-script packages covered) and its suite stays green. Generated-by: GLM-5.3-Flash (ZCode)
Summary
Supersedes Dependabot PR #5833. Its dependency upgrades leave the repository's local patch files targeting older package versions, which makes clean installs fail.
Verification
Passed: npm ci (including patch application), npm run build, npm run check:release (211 passed, 1 skipped), npm run lint, npm run format:check, npm run typecheck, npm audit signatures, and the shipped-dependency audit (0 moderate-or-higher advisories).
The local full workspace integration run is not green in this sandbox. A focused ACP startup failure reproduces because temporary test workspaces are created below /tmp, where this environment has an invalid /tmp/.git; workspace identity detection then invokes Git and fails before the test reaches the changed dependencies. The original broader run also had Host/Desktop timeouts. Hosted CI on a clean runner is still required.
AI use
Tool(s) and scope: Codex regenerated the dependency patches, updated the transitive security override and notices, and ran the listed validation.
Checklist
Does this PR entail a change in behavior?