Skip to content

release: beta → main (next stable) - #271

Open
eFAILution wants to merge 54 commits into
mainfrom
beta
Open

eFAILution wants to merge 54 commits into
mainfrom
beta

Conversation

@eFAILution

Copy link
Copy Markdown
Owner

Rolling integration PR for the next stable release. It stays open while beta is refined, and picks up every new commit merged to beta automatically. Do not merge until the release is ready — merging to main cuts a stable GitHub Release straight away.

What is on beta today

Commit
#263 fix(completion): a !reference tag anywhere in the file broke all input completion
#264 chore(deps): js-yaml 4.2.0 → 4.3.2 (transitive)
#265 chore(deps-dev): fast-uri 3.1.5 → 3.1.7
#266 chore(deps-dev): dev-dependencies group, 9 updates
#267 chore(deps-dev): mocha 11.8.0 → 12.0.0

Plus the chore(release) bumps to 0.17.0 and 0.17.1.

Headline change

#263 fixes a total-parse-failure bug. GitLab's !reference [.job, key] tag belongs to no YAML schema, so js-yaml threw on it and the parse returned nothing for the entire file — include: block included — even when the tag sat in an unrelated job further down. Completion, hover and validation all went silent, and deleting the !reference line was the only workaround. A new GITLAB_CI_SCHEMA teaches the parser the tag.

Known gaps in that schema are tracked separately in #268, #269 and #270; none of them blocks this release.

Security

#267 is not just a version bump. mocha 11 carried diff and serialize-javascript advisories; npm audit on beta now reports 0 vulnerabilities, down from 3 (1 low, 1 moderate, 1 high).

Versioning

beta sits at 0.17.1. Odd minor is the pre-release channel, per the repo's even/odd convention. On merge, .release-it.json's requireEvenMinor rolls this forward to an even minor (0.18.0) for the stable channel. Nothing to do by hand.

Note that the VS Code Marketplace publish is still a separate manual workflow_dispatch; a GitHub Release from this merge does not by itself ship anything to users.

Verification on beta

  • npm ci clean, lockfile in sync with package.json
  • npm run lint clean (eslint --max-warnings 0)
  • node esbuild.js and tsc --noEmit clean on both tsconfigs
  • 387 unit tests passing, extension-host suite passing
  • npm audit: 0 vulnerabilities

Before merging

X-Guardian and others added 7 commits September 8, 2026 07:59
…ut completion (#263)

* fix(completion): a !reference tag anywhere in the file suppresses all input completion

* Fix referenceTag

---------

Co-authored-by: Simon Heather <simon.heather@yulife.com>
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.2.0 to 4.3.2.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md)
- [Commits](nodeca/js-yaml@4.2.0...4.3.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.7.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.5...v3.1.7)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the dev-dependencies group with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [@octokit/core](https://github.com/octokit/core.js) | `7.0.7` | `7.0.8` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.2.0` | `26.4.1` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.67.0` | `8.69.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.67.0` | `8.69.0` |
| [eslint](https://github.com/eslint/eslint) | `10.8.1` | `10.9.1` |
| [globals](https://github.com/sindresorhus/globals) | `17.11.0` | `17.12.0` |
| [js-yaml](https://github.com/nodeca/js-yaml) | `5.3.0` | `5.4.1` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.12` | `4.23.13` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.67.0` | `8.69.0` |


Updates `@octokit/core` from 7.0.7 to 7.0.8
- [Release notes](https://github.com/octokit/core.js/releases)
- [Commits](octokit/core.js@v7.0.7...v7.0.8)

Updates `@types/node` from 26.2.0 to 26.4.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@typescript-eslint/eslint-plugin` from 8.67.0 to 8.69.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.69.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.67.0 to 8.69.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.69.0/packages/parser)

Updates `eslint` from 10.8.1 to 10.9.1
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.8.1...v10.9.1)

Updates `globals` from 17.11.0 to 17.12.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.11.0...v17.12.0)

Updates `js-yaml` from 5.3.0 to 5.4.1
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@5.3.0...5.4.1)

Updates `tsx` from 4.23.12 to 4.23.13
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.12...v4.23.13)

Updates `typescript-eslint` from 8.67.0 to 8.69.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.69.0/packages/typescript-eslint)

---
updated-dependencies:
- dependency-name: "@octokit/core"
  dependency-version: 7.0.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.4.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.69.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.69.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: eslint
  dependency-version: 10.9.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: globals
  dependency-version: 17.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: js-yaml
  dependency-version: 5.4.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: tsx
  dependency-version: 4.23.13
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: typescript-eslint
  dependency-version: 8.69.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [mocha](https://github.com/mochajs/mocha) from 11.8.0 to 12.0.0.
- [Release notes](https://github.com/mochajs/mocha/releases)
- [Changelog](https://github.com/mochajs/mocha/blob/main/CHANGELOG.md)
- [Commits](mochajs/mocha@v11.8.0...v12.0.0)

---
updated-dependencies:
- dependency-name: mocha
  dependency-version: 12.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
#273)

Co-authored-by: Simon Heather <simon.heather@yulife.com>
@github-actions

github-actions Bot commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

🛡️ Security Hardening Pipeline Results

Branch: beta
Commit: 745f15c

Workflow Run: 523
Branch: beta
Commit: 745f15c

Scan Status

Scanner Status
bandit ⏭️ skipped
checkov ⏭️ skipped
clamav ⏭️ skipped
codeql ✅ PASS
container ⏭️ skipped
dependency-review ✅ PASS
gitleaks ✅ PASS
grype ⏭️ skipped
lint ⏭️ skipped
opengrep ⏭️ skipped
osv ✅ PASS
sbom ⏭️ skipped
supply-chain ⏭️ skipped
trivy-container ⏭️ skipped
trivy-iac ⏭️ skipped
zap ⏭️ skipped

✅ All enabled scanners completed successfully.

Summaries Collected: 4

Scanner Results

🔬 CodeQL SAST (Javascript)

Status: Completed

Findings Summary

Critical High Medium Low Total
0 0 0 0 0

No security findings detected for Javascript.

Artifacts: CodeQL Reports (Javascript)

🔗 Dependency Review

Status: ✅ No issues found

No vulnerable or license-violating dependencies detected in this PR.
📋 View full report

🔑 Gitleaks (Secrets)

No 🔑 Gitleaks (Secrets) findings summary was produced.

📦 OSV (Dependencies)

No 📦 OSV (Dependencies) findings summary was produced.


Generated by Argus


Generated by Argus

github-actions Bot and others added 3 commits September 8, 2026 23:54
Co-authored-by: Simon Heather <simon.heather@yulife.com>
Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
@eFAILution
eFAILution deployed to publish-beta September 9, 2026 01:24 — with GitHub Actions Active
Cid-oe and others added 4 commits September 9, 2026 07:31
…s panel (#280)

* fix(details): make Refresh Versions work in the browser-opened details panel

* Fix test

* fix(browser): label monorepo versions and surface version-change failures

Ports the two gaps #281 caught into this branch.

- The browser details panel's fetchVersions never sent versionLabels, so a
  refresh reverted the dropdown from '1.0.0' back to 'deploy-1.0.0' on a
  tag-per-component source. It now sends them like the detached panel does.
- versionChangeError still hid the spinner and said nothing, the same silent
  failure this branch fixes one case block over. It now reports in the same
  slot, and both entry points clear a stale error before retrying.

Rather than copy the label loop a third time, it moves to buildVersionLabels
in tagScoping (pure, unit-tested) and the two existing copies collapse onto
it. That also compiles the tag template once per list instead of once per tag.

Co-authored-by: Cid-oe <cid066a86@gmail.com>

---------

Co-authored-by: Simon Heather <simon.heather@yulife.com>
Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
Co-authored-by: Cid-oe <cid066a86@gmail.com>
X-Guardian and others added 3 commits September 11, 2026 07:54
…nder CSP (#275)

* refactor(webview): serve loading-view CSS from linted external file under CSP

* Bump stylelint version

* Fix review comments

---------

Co-authored-by: Simon Heather <simon.heather@yulife.com>
…ity-hardening.yml (#293)

Bumps [huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml](https://github.com/huntridge-labs/argus) from 1.12.3 to 1.12.4.
- [Release notes](https://github.com/huntridge-labs/argus/releases)
- [Changelog](https://github.com/huntridge-labs/argus/blob/main/CHANGELOG.md)
- [Commits](huntridge-labs/argus@9b444d8...cc7ef8e)

---
updated-dependencies:
- dependency-name: huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml
  dependency-version: 1.12.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
eFAILution and others added 2 commits September 21, 2026 14:04
Rebuilds #302, #303 and #304 against beta. All three were opened against
main, whose package.json trails beta by everything in #297, so most of
what they propose is already here and their lockfiles no longer apply.

  @release-it/conventional-changelog  ^12.0.0 -> ^12.0.2
  @types/node                         ^26.5.1 -> ^26.6.1
  dotenv                              ^17.4.2 -> ^18.0.0
  js-yaml                             ^5.4.1  -> ^5.4.2
  mocha                               ^12.0.0 -> ^12.0.2
  release-it                          ^21.0.2 -> ^21.1.0

js-yaml is the only one that reaches the packaged extension — src
imports it and esbuild bundles it — and it is a patch. The rest are
tooling.

The root conventional-changelog-conventionalcommits pin stays at 9.3.1;
the 10.x that moves in the lockfile is release-it's own nested copy,
already on 10.x before this change. dotenv is declared but imported
nowhere in the repo, so its major bump is inert — worth removing rather
than tracking, separately.

release-it 21.1.0 pulls in one new transitive package, verkit@0.4.0
(MIT). Every version here was published at least three days ago.

Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
X-Guardian and others added 8 commits September 23, 2026 14:48
…xternal assets (#308)

* refactor(webview): serve the no-sources and error views from linted external assets

* fix(browser): restore the fatal-error view's collapsed initial state

`getErrorHtml` set `class` twice on the raw-error block:

    <pre class="error-raw" id="error-raw" class="is-hidden">

HTML5 keeps the first `class` and discards later duplicates, so
`is-hidden` never applied. The block rendered expanded on open, and
because the toggle flips the class rather than reading it, the button's
label was inverted from then on: "Show details" while the text was
already showing, "Hide details" only after a second click.

That is a regression from the `style="display: none;"` it replaced, and
it sits in the one view the PR notes as unverifiable by hand — it is the
catch-all for an exception during load. The `isAuth` branch narrows it
further, which is why the error-list check did not surface it.

Adds a source-level guard. The builders are private methods on a class
that imports `vscode`, so the unit suite cannot call them; this reads the
file as text and rejects any element carrying the same attribute twice.
Verified load-bearing: reintroducing the duplicate fails it and names the
tag. Covers all six builders, including the ones later steps will touch.

Also widens the stylelint `custom-property-pattern` override. The
diagnosis was right — stylelint checks the pattern against `var()` reads,
not just declarations, so VS Code's camelCase theme variables genuinely
trip it. But requiring every custom property to start with `vscode-`
rejects one this project declares for itself: a plain `--spacing-sm: 8px`
fails, complaining about kebab-case on a name that is already kebab-case.
Kept as an alternative so both hold.

---------

Co-authored-by: Simon Heather <simon.heather@yulife.com>
Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
…rnal assets (#309)

* refactor(webview): serve the component details panel from linted external assets

* Fix cancel buttons

* Resolve codeql issues

* fix(details): open component links from the extension host, not the webview

CodeQL flagged both details-panel links as client-side XSS (high) and
client-side URL redirect (medium). The `httpUrl` scheme guard added in
14e8f29 did block every script-bearing scheme, but it left the design
that produced the alerts in place: attacker-influenced data arriving by
`postMessage` and being assigned to `.href`. `documentationUrl` comes
straight from a catalog project's `documentation_url`, which whoever
publishes the component controls.

The sink is removed rather than guarded:

- The anchors carry no URL (`href="#"` plus `data-action`). Clicking one
  posts `openLink` with a link *name*; the extension host resolves the
  URL from the component it already holds, validates it, and opens it
  with `vscode.env.openExternal`. A compromised document can ask to open
  a link the component already names, and nothing else.
- `openExternal` applies VS Code's trusted-domain confirmation, which
  shows the destination before any untrusted host is opened. That is the
  actual mitigation for the redirect finding, not just a way to quiet it.
- The client now only sets link *text*, via `textContent`.

The first render had the same flaw on the server side, pre-existing on
beta: both URLs were interpolated into `href` and link text unescaped
and unvalidated. They now go through the same check and `escapeHtml`.

One shared, vscode-free check (`src/webview/safeUrl.ts`) serves the
first render, every update, and the host-side opener. Beyond the scheme
allowlist it returns the parsed `href` rather than the input, so what is
shown and opened is exactly what was validated, and it rejects embedded
credentials: `https://gitlab.com@evil.example/` reads as gitlab.com and
resolves to evil.example.

Also carries `documentationUrl` across a version switch. A cached
version has none, so replacing the active component dropped it and the
Project URL link would have stopped working after the first switch.

Tests: `safeHttpUrl` against ten hostile schemes, relative and
protocol-relative URLs, and userinfo. Two source-level guards pin the
design: the client script may not assign `href`/`src`/`action` or touch
`location`/`window.open`, and the builder may not interpolate a metadata
URL into an `href`. Both fail against the code before this commit.

---------

Co-authored-by: Simon Heather <simon.heather@yulife.com>
Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
…ssets (#311)

* refactor(webview): serve the Component Browser from linted external assets

* fix(browser): stop publisher-controlled text from running in the Component Browser

Moving the browser's script into a linted file let CodeQL see it for the
first time: 8 client-side XSS and 2 prototype-pollution alerts. They are
real and pre-existing, not introduced by the extraction.

Version tags, component names and spec fields are set by whoever
publishes a component, and git accepts quotes and angle brackets in a
tag name. The browser concatenated those values into `innerHTML` and
into `onclick` source, and this panel runs scripts with no CSP yet.

Client (componentBrowser.ts):
- The dropdown, Details/Insert buttons, error banner and version line
  are built as elements, with text via `textContent` and handlers as
  closures, instead of as markup strings.
- Switching version repoints the buttons by assigning `onclick`
  closures, found by a `data-role`, instead of rewriting their handler
  text with the version inside it.
- Selectors built from names go through `CSS.escape`.
- Version entries are written through `storeVersion`, which refuses
  `__proto__`, `constructor` and `prototype` and uses null-prototype
  maps.

Server (componentBrowserProvider.ts), where the first render had the
same flaw:
- Values passed to an `onclick`/`onchange` handler use `handlerArg`:
  `JSON.stringify` for the JavaScript string, then `escapeHtml` for the
  attribute. `escapeHtml` alone is not enough; the browser decodes
  `&#39;` back to `'` before the handler runs.
- Names, paths, instances, versions and source titles are escaped in
  text and attributes.
- The version map is built from null-prototype objects, so a component
  or version named `__proto__` cannot write to Object.prototype in the
  extension host.
- The details panel's name, source, instance, URL, summary, usage,
  notes and parameter fields are escaped (#238).

Tests: `handlerArg` against hostile tag names, checked by decoding the
attribute the way a browser does and confirming it parses as exactly one
string equal to the input; plus source guards that the client builds
markup only through the escaping renderer, never writes handler text,
and stores versions only through the key check.

* fix(browser): hold component versions in Maps, not objects keyed by publisher text

The previous commit refused `__proto__`, `constructor` and `prototype`
before writing a version entry. That guard was correct, but it is a
blocklist, and CodeQL (rightly) does not treat one as proof: its medium
prototype-pollution alert stayed open on the write.

Component names and version strings are set by whoever publishes a
component. Storing them as keys of a plain object is the root of the
problem, since both reads and writes then reach `Object.prototype` for a
handful of names. A `Map` has no such keys, so the bug class is removed
rather than filtered.

`readVersionData` builds `Map<string, Map<string, VersionEntry>>` from
the embedded JSON, keeping only well-formed entries; `storeVersion` and
`findVersion` are the only way in and out. The `window` global it
replaces had no readers outside this bundle.

---------

Co-authored-by: Simon Heather <simon.heather@yulife.com>
Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
* test(webview): fail the build when a builder emits inline code

Script, style and event handlers written inside a TypeScript template
literal are invisible to tsc, eslint, stylelint and CodeQL. That is how
the details-panel link flaw (#309) and the duplicate `class` in the
fatal-error view (#308) both shipped. #288 has been moving each view's
inline code into linted files under src/webview; this keeps it from
coming back.

Every `get…Html` builder is checked for an inline `<script>`, an inline
`<style>`, an `on…=` handler attribute, and a `style=` attribute. A
`<script type="application/json">` block is data rather than code, and
is how a builder hands state to its client script, so it is allowed.

getComponentBrowserHtml is the one view #288 has not reached yet. It
gets a ceiling rather than an exemption: its counts can only go down,
and reaching zero fails the suite until its entry is deleted, so the
allowance cannot outlive the work it exists for.

A sanity test fails if fewer than six builders are found, so a rename
cannot make the rest pass vacuously.

Verified by reintroducing each kind of regression: an `onclick` in the
no-sources view, an inline script in the details panel, and one extra
handler in the browser view each fail with the builder and count named.

* test(webview): lower the Component Browser ceilings to what #311 left

#311 moved the browser's script and stylesheet into external files and
rebuilt its dynamic controls without inline handlers. Its counts are now
0 inline scripts, 0 style blocks, 15 handlers and 4 style attributes.

Lowering the ceilings to match is what makes them a ratchet: at the old
values an inline <script> could have come back without failing the
build.

---------

Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
X-Guardian and others added 6 commits September 29, 2026 07:32
* fix(browser): make version preferences save

* Fix review comments

* Update markdownDescription

---------

Co-authored-by: Simon Heather <simon.heather@yulife.com>
…ity-hardening.yml (#314)

Bumps [huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml](https://github.com/huntridge-labs/argus) from 1.12.3 to 1.12.6.
- [Release notes](https://github.com/huntridge-labs/argus/releases)
- [Changelog](https://github.com/huntridge-labs/argus/blob/main/CHANGELOG.md)
- [Commits](huntridge-labs/argus@9b444d8...3fb133a)

---
updated-dependencies:
- dependency-name: huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml
  dependency-version: 1.12.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.8.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.5...v3.1.8)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
Bumps [dotenv](https://github.com/motdotla/dotenv) from 17.4.2 to 18.0.3.
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v17.4.2...v18.0.3)

---
updated-dependencies:
- dependency-name: dotenv
  dependency-version: 18.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
Bumps the dev-dependencies group with 14 updates:

| Package | From | To |
| --- | --- | --- |
| [@commitlint/cli](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/cli) | `21.2.2` | `21.2.3` |
| [@commitlint/config-conventional](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/config-conventional) | `21.2.2` | `21.2.3` |
| [@octokit/core](https://github.com/octokit/core.js) | `7.0.7` | `7.0.8` |
| [@release-it/conventional-changelog](https://github.com/release-it/conventional-changelog) | `12.0.0` | `12.0.2` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.2.0` | `26.6.2` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.67.0` | `8.70.1` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.67.0` | `8.70.1` |
| [cz-emoji-conventional](https://github.com/promet99/cz-emoji-conventional) | `1.2.1` | `1.3.0` |
| [eslint](https://github.com/eslint/eslint) | `10.8.1` | `10.11.0` |
| [globals](https://github.com/sindresorhus/globals) | `17.11.0` | `17.12.0` |
| [js-yaml](https://github.com/nodeca/js-yaml) | `5.3.0` | `5.4.2` |
| [release-it](https://github.com/release-it/release-it) | `21.0.2` | `21.1.0` |
| [tsx](https://github.com/privatenumber/tsx) | `4.23.12` | `4.23.15` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.67.0` | `8.70.1` |


Updates `@commitlint/cli` from 21.2.2 to 21.2.3
- [Release notes](https://github.com/conventional-changelog/commitlint/releases)
- [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/cli/CHANGELOG.md)
- [Commits](https://github.com/conventional-changelog/commitlint/commits/v21.2.3/@commitlint/cli)

Updates `@commitlint/config-conventional` from 21.2.2 to 21.2.3
- [Release notes](https://github.com/conventional-changelog/commitlint/releases)
- [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/config-conventional/CHANGELOG.md)
- [Commits](https://github.com/conventional-changelog/commitlint/commits/v21.2.3/@commitlint/config-conventional)

Updates `@octokit/core` from 7.0.7 to 7.0.8
- [Release notes](https://github.com/octokit/core.js/releases)
- [Commits](octokit/core.js@v7.0.7...v7.0.8)

Updates `@release-it/conventional-changelog` from 12.0.0 to 12.0.2
- [Release notes](https://github.com/release-it/conventional-changelog/releases)
- [Commits](release-it/conventional-changelog@12.0.0...12.0.2)

Updates `@types/node` from 26.2.0 to 26.6.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@typescript-eslint/eslint-plugin` from 8.67.0 to 8.70.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.67.0 to 8.70.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/parser)

Updates `cz-emoji-conventional` from 1.2.1 to 1.3.0
- [Release notes](https://github.com/promet99/cz-emoji-conventional/releases)
- [Commits](promet99/cz-emoji-conventional@v1.2.1...v1.3.0)

Updates `eslint` from 10.8.1 to 10.11.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.8.1...v10.11.0)

Updates `globals` from 17.11.0 to 17.12.0
- [Release notes](https://github.com/sindresorhus/globals/releases)
- [Commits](sindresorhus/globals@v17.11.0...v17.12.0)

Updates `js-yaml` from 5.3.0 to 5.4.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@5.3.0...5.4.2)

Updates `release-it` from 21.0.2 to 21.1.0
- [Release notes](https://github.com/release-it/release-it/releases)
- [Changelog](https://github.com/release-it/release-it/blob/main/CHANGELOG.md)
- [Commits](release-it/release-it@21.0.2...21.1.0)

Updates `tsx` from 4.23.12 to 4.23.15
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](privatenumber/tsx@v4.23.12...v4.23.15)

Updates `typescript-eslint` from 8.67.0 to 8.70.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/typescript-eslint)

---
updated-dependencies:
- dependency-name: "@commitlint/cli"
  dependency-version: 21.2.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: "@commitlint/config-conventional"
  dependency-version: 21.2.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: "@octokit/core"
  dependency-version: 7.0.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: "@release-it/conventional-changelog"
  dependency-version: 12.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: "@types/node"
  dependency-version: 26.6.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: cz-emoji-conventional
  dependency-version: 1.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: eslint
  dependency-version: 10.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: globals
  dependency-version: 17.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: js-yaml
  dependency-version: 5.4.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: release-it
  dependency-version: 21.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: tsx
  dependency-version: 4.23.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: typescript-eslint
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
X-Guardian and others added 3 commits October 2, 2026 07:36
…-Policy (#318)

* refactor(webview): put the Component Browser under a Content-Security-Policy

* Resolve review comments

* Update comments

* Fix componentBrowser

---------

Co-authored-by: Simon Heather <simon.heather@yulife.com>
* fix(component): drop the https:// scheme from inserted components

* Resolve review comments

---------

Co-authored-by: Simon Heather <simon.heather@yulife.com>
@eFAILution
eFAILution deployed to publish-beta October 2, 2026 11:42 — with GitHub Actions Active
@eFAILution

Copy link
Copy Markdown
Owner Author

@X-Guardian I'm freezing code changes on Beta and starting the release evaluation. Looking to publish a new stable early next week. Thanks for another round of great contributions!

@eFAILution
eFAILution marked this pull request as ready for review October 2, 2026 11:45
@X-Guardian

X-Guardian commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

No problem @eFAILution, it's nice to contribute to a useful VSCode extension.

I'm preparing one more PR that refactors the inline html into tsx views, but there are no user facing changes, so doesn't matter if it is not in the next release.

eFAILution and others added 2 commits October 2, 2026 09:17
* docs(readme): modernize the README layout

Centered header with Marketplace badges, a short quick start, one
section per feature next to its demo, and collapsible reference
sections for settings, advanced setup, and troubleshooting.

* docs(readme): swap in new feature GIFs

Re-recorded demos for the Component Browser, completion, hover, input
checks, and version upgrades. Adds a GIF to the version section, which
had none.

---------

Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>

This branch was successfully deployed

1 active (outdated) deployment
publish-beta — 6c371f59 Deployed Oct 2, 2026 by eFAILution via publish #29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants