release: beta → main (next stable) - #271
eFAILution wants to merge 54 commits into
Conversation
…ut completion (#263) * fix(completion): a !reference tag anywhere in the file suppresses all input completion * Fix referenceTag --------- Co-authored-by: Simon Heather <simon.heather@yulife.com>
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.2.0 to 4.3.2. - [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.2/CHANGELOG.md) - [Commits](nodeca/js-yaml@4.2.0...4.3.2) --- updated-dependencies: - dependency-name: js-yaml dependency-version: 4.3.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.7. - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.5...v3.1.7) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.7 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the dev-dependencies group with 9 updates: | Package | From | To | | --- | --- | --- | | [@octokit/core](https://github.com/octokit/core.js) | `7.0.7` | `7.0.8` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.2.0` | `26.4.1` | | [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.67.0` | `8.69.0` | | [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.67.0` | `8.69.0` | | [eslint](https://github.com/eslint/eslint) | `10.8.1` | `10.9.1` | | [globals](https://github.com/sindresorhus/globals) | `17.11.0` | `17.12.0` | | [js-yaml](https://github.com/nodeca/js-yaml) | `5.3.0` | `5.4.1` | | [tsx](https://github.com/privatenumber/tsx) | `4.23.12` | `4.23.13` | | [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.67.0` | `8.69.0` | Updates `@octokit/core` from 7.0.7 to 7.0.8 - [Release notes](https://github.com/octokit/core.js/releases) - [Commits](octokit/core.js@v7.0.7...v7.0.8) Updates `@types/node` from 26.2.0 to 26.4.1 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `@typescript-eslint/eslint-plugin` from 8.67.0 to 8.69.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.69.0/packages/eslint-plugin) Updates `@typescript-eslint/parser` from 8.67.0 to 8.69.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.69.0/packages/parser) Updates `eslint` from 10.8.1 to 10.9.1 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.8.1...v10.9.1) Updates `globals` from 17.11.0 to 17.12.0 - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v17.11.0...v17.12.0) Updates `js-yaml` from 5.3.0 to 5.4.1 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](nodeca/js-yaml@5.3.0...5.4.1) Updates `tsx` from 4.23.12 to 4.23.13 - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](privatenumber/tsx@v4.23.12...v4.23.13) Updates `typescript-eslint` from 8.67.0 to 8.69.0 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.69.0/packages/typescript-eslint) --- updated-dependencies: - dependency-name: "@octokit/core" dependency-version: 7.0.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: "@types/node" dependency-version: 26.4.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: "@typescript-eslint/eslint-plugin" dependency-version: 8.69.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: "@typescript-eslint/parser" dependency-version: 8.69.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: eslint dependency-version: 10.9.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: globals dependency-version: 17.12.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: js-yaml dependency-version: 5.4.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: tsx dependency-version: 4.23.13 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: typescript-eslint dependency-version: 8.69.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [mocha](https://github.com/mochajs/mocha) from 11.8.0 to 12.0.0. - [Release notes](https://github.com/mochajs/mocha/releases) - [Changelog](https://github.com/mochajs/mocha/blob/main/CHANGELOG.md) - [Commits](mochajs/mocha@v11.8.0...v12.0.0) --- updated-dependencies: - dependency-name: mocha dependency-version: 12.0.0 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
#273) Co-authored-by: Simon Heather <simon.heather@yulife.com>
🛡️ Security Hardening Pipeline ResultsBranch: Workflow Run: 523 Scan Status
Summaries Collected: 4 Scanner Results🔬 CodeQL SAST (Javascript)Status: Completed Findings Summary
No security findings detected for Javascript. Artifacts: CodeQL Reports (Javascript) 🔗 Dependency ReviewStatus: ✅ No issues found No vulnerable or license-violating dependencies detected in this PR. 🔑 Gitleaks (Secrets)No 🔑 Gitleaks (Secrets) findings summary was produced. 📦 OSV (Dependencies)No 📦 OSV (Dependencies) findings summary was produced. Generated by Argus Generated by Argus |
Co-authored-by: Simon Heather <simon.heather@yulife.com> Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
…s panel (#280) * fix(details): make Refresh Versions work in the browser-opened details panel * Fix test * fix(browser): label monorepo versions and surface version-change failures Ports the two gaps #281 caught into this branch. - The browser details panel's fetchVersions never sent versionLabels, so a refresh reverted the dropdown from '1.0.0' back to 'deploy-1.0.0' on a tag-per-component source. It now sends them like the detached panel does. - versionChangeError still hid the spinner and said nothing, the same silent failure this branch fixes one case block over. It now reports in the same slot, and both entry points clear a stale error before retrying. Rather than copy the label loop a third time, it moves to buildVersionLabels in tagScoping (pure, unit-tested) and the two existing copies collapse onto it. That also compiles the tag template once per list instead of once per tag. Co-authored-by: Cid-oe <cid066a86@gmail.com> --------- Co-authored-by: Simon Heather <simon.heather@yulife.com> Co-authored-by: eFAILution <eFAILution@users.noreply.github.com> Co-authored-by: Cid-oe <cid066a86@gmail.com>
…nder CSP (#275) * refactor(webview): serve loading-view CSS from linted external file under CSP * Bump stylelint version * Fix review comments --------- Co-authored-by: Simon Heather <simon.heather@yulife.com>
…ity-hardening.yml (#293) Bumps [huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml](https://github.com/huntridge-labs/argus) from 1.12.3 to 1.12.4. - [Release notes](https://github.com/huntridge-labs/argus/releases) - [Changelog](https://github.com/huntridge-labs/argus/blob/main/CHANGELOG.md) - [Commits](huntridge-labs/argus@9b444d8...cc7ef8e) --- updated-dependencies: - dependency-name: huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml dependency-version: 1.12.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Rebuilds #302, #303 and #304 against beta. All three were opened against main, whose package.json trails beta by everything in #297, so most of what they propose is already here and their lockfiles no longer apply. @release-it/conventional-changelog ^12.0.0 -> ^12.0.2 @types/node ^26.5.1 -> ^26.6.1 dotenv ^17.4.2 -> ^18.0.0 js-yaml ^5.4.1 -> ^5.4.2 mocha ^12.0.0 -> ^12.0.2 release-it ^21.0.2 -> ^21.1.0 js-yaml is the only one that reaches the packaged extension — src imports it and esbuild bundles it — and it is a patch. The rest are tooling. The root conventional-changelog-conventionalcommits pin stays at 9.3.1; the 10.x that moves in the lockfile is release-it's own nested copy, already on 10.x before this change. dotenv is declared but imported nowhere in the repo, so its major bump is inert — worth removing rather than tracking, separately. release-it 21.1.0 pulls in one new transitive package, verkit@0.4.0 (MIT). Every version here was published at least three days ago. Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
…xternal assets (#308) * refactor(webview): serve the no-sources and error views from linted external assets * fix(browser): restore the fatal-error view's collapsed initial state `getErrorHtml` set `class` twice on the raw-error block: <pre class="error-raw" id="error-raw" class="is-hidden"> HTML5 keeps the first `class` and discards later duplicates, so `is-hidden` never applied. The block rendered expanded on open, and because the toggle flips the class rather than reading it, the button's label was inverted from then on: "Show details" while the text was already showing, "Hide details" only after a second click. That is a regression from the `style="display: none;"` it replaced, and it sits in the one view the PR notes as unverifiable by hand — it is the catch-all for an exception during load. The `isAuth` branch narrows it further, which is why the error-list check did not surface it. Adds a source-level guard. The builders are private methods on a class that imports `vscode`, so the unit suite cannot call them; this reads the file as text and rejects any element carrying the same attribute twice. Verified load-bearing: reintroducing the duplicate fails it and names the tag. Covers all six builders, including the ones later steps will touch. Also widens the stylelint `custom-property-pattern` override. The diagnosis was right — stylelint checks the pattern against `var()` reads, not just declarations, so VS Code's camelCase theme variables genuinely trip it. But requiring every custom property to start with `vscode-` rejects one this project declares for itself: a plain `--spacing-sm: 8px` fails, complaining about kebab-case on a name that is already kebab-case. Kept as an alternative so both hold. --------- Co-authored-by: Simon Heather <simon.heather@yulife.com> Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
…rnal assets (#309) * refactor(webview): serve the component details panel from linted external assets * Fix cancel buttons * Resolve codeql issues * fix(details): open component links from the extension host, not the webview CodeQL flagged both details-panel links as client-side XSS (high) and client-side URL redirect (medium). The `httpUrl` scheme guard added in 14e8f29 did block every script-bearing scheme, but it left the design that produced the alerts in place: attacker-influenced data arriving by `postMessage` and being assigned to `.href`. `documentationUrl` comes straight from a catalog project's `documentation_url`, which whoever publishes the component controls. The sink is removed rather than guarded: - The anchors carry no URL (`href="#"` plus `data-action`). Clicking one posts `openLink` with a link *name*; the extension host resolves the URL from the component it already holds, validates it, and opens it with `vscode.env.openExternal`. A compromised document can ask to open a link the component already names, and nothing else. - `openExternal` applies VS Code's trusted-domain confirmation, which shows the destination before any untrusted host is opened. That is the actual mitigation for the redirect finding, not just a way to quiet it. - The client now only sets link *text*, via `textContent`. The first render had the same flaw on the server side, pre-existing on beta: both URLs were interpolated into `href` and link text unescaped and unvalidated. They now go through the same check and `escapeHtml`. One shared, vscode-free check (`src/webview/safeUrl.ts`) serves the first render, every update, and the host-side opener. Beyond the scheme allowlist it returns the parsed `href` rather than the input, so what is shown and opened is exactly what was validated, and it rejects embedded credentials: `https://gitlab.com@evil.example/` reads as gitlab.com and resolves to evil.example. Also carries `documentationUrl` across a version switch. A cached version has none, so replacing the active component dropped it and the Project URL link would have stopped working after the first switch. Tests: `safeHttpUrl` against ten hostile schemes, relative and protocol-relative URLs, and userinfo. Two source-level guards pin the design: the client script may not assign `href`/`src`/`action` or touch `location`/`window.open`, and the builder may not interpolate a metadata URL into an `href`. Both fail against the code before this commit. --------- Co-authored-by: Simon Heather <simon.heather@yulife.com> Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
…ssets (#311) * refactor(webview): serve the Component Browser from linted external assets * fix(browser): stop publisher-controlled text from running in the Component Browser Moving the browser's script into a linted file let CodeQL see it for the first time: 8 client-side XSS and 2 prototype-pollution alerts. They are real and pre-existing, not introduced by the extraction. Version tags, component names and spec fields are set by whoever publishes a component, and git accepts quotes and angle brackets in a tag name. The browser concatenated those values into `innerHTML` and into `onclick` source, and this panel runs scripts with no CSP yet. Client (componentBrowser.ts): - The dropdown, Details/Insert buttons, error banner and version line are built as elements, with text via `textContent` and handlers as closures, instead of as markup strings. - Switching version repoints the buttons by assigning `onclick` closures, found by a `data-role`, instead of rewriting their handler text with the version inside it. - Selectors built from names go through `CSS.escape`. - Version entries are written through `storeVersion`, which refuses `__proto__`, `constructor` and `prototype` and uses null-prototype maps. Server (componentBrowserProvider.ts), where the first render had the same flaw: - Values passed to an `onclick`/`onchange` handler use `handlerArg`: `JSON.stringify` for the JavaScript string, then `escapeHtml` for the attribute. `escapeHtml` alone is not enough; the browser decodes `'` back to `'` before the handler runs. - Names, paths, instances, versions and source titles are escaped in text and attributes. - The version map is built from null-prototype objects, so a component or version named `__proto__` cannot write to Object.prototype in the extension host. - The details panel's name, source, instance, URL, summary, usage, notes and parameter fields are escaped (#238). Tests: `handlerArg` against hostile tag names, checked by decoding the attribute the way a browser does and confirming it parses as exactly one string equal to the input; plus source guards that the client builds markup only through the escaping renderer, never writes handler text, and stores versions only through the key check. * fix(browser): hold component versions in Maps, not objects keyed by publisher text The previous commit refused `__proto__`, `constructor` and `prototype` before writing a version entry. That guard was correct, but it is a blocklist, and CodeQL (rightly) does not treat one as proof: its medium prototype-pollution alert stayed open on the write. Component names and version strings are set by whoever publishes a component. Storing them as keys of a plain object is the root of the problem, since both reads and writes then reach `Object.prototype` for a handful of names. A `Map` has no such keys, so the bug class is removed rather than filtered. `readVersionData` builds `Map<string, Map<string, VersionEntry>>` from the embedded JSON, keeping only well-formed entries; `storeVersion` and `findVersion` are the only way in and out. The `window` global it replaces had no readers outside this bundle. --------- Co-authored-by: Simon Heather <simon.heather@yulife.com> Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
* test(webview): fail the build when a builder emits inline code Script, style and event handlers written inside a TypeScript template literal are invisible to tsc, eslint, stylelint and CodeQL. That is how the details-panel link flaw (#309) and the duplicate `class` in the fatal-error view (#308) both shipped. #288 has been moving each view's inline code into linted files under src/webview; this keeps it from coming back. Every `get…Html` builder is checked for an inline `<script>`, an inline `<style>`, an `on…=` handler attribute, and a `style=` attribute. A `<script type="application/json">` block is data rather than code, and is how a builder hands state to its client script, so it is allowed. getComponentBrowserHtml is the one view #288 has not reached yet. It gets a ceiling rather than an exemption: its counts can only go down, and reaching zero fails the suite until its entry is deleted, so the allowance cannot outlive the work it exists for. A sanity test fails if fewer than six builders are found, so a rename cannot make the rest pass vacuously. Verified by reintroducing each kind of regression: an `onclick` in the no-sources view, an inline script in the details panel, and one extra handler in the browser view each fail with the builder and count named. * test(webview): lower the Component Browser ceilings to what #311 left #311 moved the browser's script and stylesheet into external files and rebuilt its dynamic controls without inline handlers. Its counts are now 0 inline scripts, 0 style blocks, 15 handlers and 4 style attributes. Lowering the ceilings to match is what makes them a ratchet: at the old values an inline <script> could have come back without failing the build. --------- Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
* fix(browser): make version preferences save * Fix review comments * Update markdownDescription --------- Co-authored-by: Simon Heather <simon.heather@yulife.com>
…ity-hardening.yml (#314) Bumps [huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml](https://github.com/huntridge-labs/argus) from 1.12.3 to 1.12.6. - [Release notes](https://github.com/huntridge-labs/argus/releases) - [Changelog](https://github.com/huntridge-labs/argus/blob/main/CHANGELOG.md) - [Commits](huntridge-labs/argus@9b444d8...3fb133a) --- updated-dependencies: - dependency-name: huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml dependency-version: 1.12.6 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.8. - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.5...v3.1.8) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.8 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
Bumps [dotenv](https://github.com/motdotla/dotenv) from 17.4.2 to 18.0.3. - [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md) - [Commits](motdotla/dotenv@v17.4.2...v18.0.3) --- updated-dependencies: - dependency-name: dotenv dependency-version: 18.0.3 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
Bumps the dev-dependencies group with 14 updates: | Package | From | To | | --- | --- | --- | | [@commitlint/cli](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/cli) | `21.2.2` | `21.2.3` | | [@commitlint/config-conventional](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/config-conventional) | `21.2.2` | `21.2.3` | | [@octokit/core](https://github.com/octokit/core.js) | `7.0.7` | `7.0.8` | | [@release-it/conventional-changelog](https://github.com/release-it/conventional-changelog) | `12.0.0` | `12.0.2` | | [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.2.0` | `26.6.2` | | [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.67.0` | `8.70.1` | | [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.67.0` | `8.70.1` | | [cz-emoji-conventional](https://github.com/promet99/cz-emoji-conventional) | `1.2.1` | `1.3.0` | | [eslint](https://github.com/eslint/eslint) | `10.8.1` | `10.11.0` | | [globals](https://github.com/sindresorhus/globals) | `17.11.0` | `17.12.0` | | [js-yaml](https://github.com/nodeca/js-yaml) | `5.3.0` | `5.4.2` | | [release-it](https://github.com/release-it/release-it) | `21.0.2` | `21.1.0` | | [tsx](https://github.com/privatenumber/tsx) | `4.23.12` | `4.23.15` | | [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.67.0` | `8.70.1` | Updates `@commitlint/cli` from 21.2.2 to 21.2.3 - [Release notes](https://github.com/conventional-changelog/commitlint/releases) - [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/cli/CHANGELOG.md) - [Commits](https://github.com/conventional-changelog/commitlint/commits/v21.2.3/@commitlint/cli) Updates `@commitlint/config-conventional` from 21.2.2 to 21.2.3 - [Release notes](https://github.com/conventional-changelog/commitlint/releases) - [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/config-conventional/CHANGELOG.md) - [Commits](https://github.com/conventional-changelog/commitlint/commits/v21.2.3/@commitlint/config-conventional) Updates `@octokit/core` from 7.0.7 to 7.0.8 - [Release notes](https://github.com/octokit/core.js/releases) - [Commits](octokit/core.js@v7.0.7...v7.0.8) Updates `@release-it/conventional-changelog` from 12.0.0 to 12.0.2 - [Release notes](https://github.com/release-it/conventional-changelog/releases) - [Commits](release-it/conventional-changelog@12.0.0...12.0.2) Updates `@types/node` from 26.2.0 to 26.6.2 - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node) Updates `@typescript-eslint/eslint-plugin` from 8.67.0 to 8.70.1 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/eslint-plugin) Updates `@typescript-eslint/parser` from 8.67.0 to 8.70.1 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/parser) Updates `cz-emoji-conventional` from 1.2.1 to 1.3.0 - [Release notes](https://github.com/promet99/cz-emoji-conventional/releases) - [Commits](promet99/cz-emoji-conventional@v1.2.1...v1.3.0) Updates `eslint` from 10.8.1 to 10.11.0 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v10.8.1...v10.11.0) Updates `globals` from 17.11.0 to 17.12.0 - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v17.11.0...v17.12.0) Updates `js-yaml` from 5.3.0 to 5.4.2 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](nodeca/js-yaml@5.3.0...5.4.2) Updates `release-it` from 21.0.2 to 21.1.0 - [Release notes](https://github.com/release-it/release-it/releases) - [Changelog](https://github.com/release-it/release-it/blob/main/CHANGELOG.md) - [Commits](release-it/release-it@21.0.2...21.1.0) Updates `tsx` from 4.23.12 to 4.23.15 - [Release notes](https://github.com/privatenumber/tsx/releases) - [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs) - [Commits](privatenumber/tsx@v4.23.12...v4.23.15) Updates `typescript-eslint` from 8.67.0 to 8.70.1 - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/typescript-eslint) --- updated-dependencies: - dependency-name: "@commitlint/cli" dependency-version: 21.2.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: "@commitlint/config-conventional" dependency-version: 21.2.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: "@octokit/core" dependency-version: 7.0.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: "@release-it/conventional-changelog" dependency-version: 12.0.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: "@types/node" dependency-version: 26.6.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: "@typescript-eslint/eslint-plugin" dependency-version: 8.70.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: "@typescript-eslint/parser" dependency-version: 8.70.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: cz-emoji-conventional dependency-version: 1.3.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: eslint dependency-version: 10.11.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: globals dependency-version: 17.12.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: js-yaml dependency-version: 5.4.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: release-it dependency-version: 21.1.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies - dependency-name: tsx dependency-version: 4.23.15 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-dependencies - dependency-name: typescript-eslint dependency-version: 8.70.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: dev-dependencies ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
…-Policy (#318) * refactor(webview): put the Component Browser under a Content-Security-Policy * Resolve review comments * Update comments * Fix componentBrowser --------- Co-authored-by: Simon Heather <simon.heather@yulife.com>
* fix(component): drop the https:// scheme from inserted components * Resolve review comments --------- Co-authored-by: Simon Heather <simon.heather@yulife.com>
|
@X-Guardian I'm freezing code changes on Beta and starting the release evaluation. Looking to publish a new stable early next week. Thanks for another round of great contributions! |
|
No problem @eFAILution, it's nice to contribute to a useful VSCode extension. I'm preparing one more PR that refactors the inline html into tsx views, but there are no user facing changes, so doesn't matter if it is not in the next release. |
* docs(readme): modernize the README layout Centered header with Marketplace badges, a short quick start, one section per feature next to its demo, and collapsible reference sections for settings, advanced setup, and troubleshooting. * docs(readme): swap in new feature GIFs Re-recorded demos for the Component Browser, completion, hover, input checks, and version upgrades. Adds a GIF to the version section, which had none. --------- Co-authored-by: eFAILution <eFAILution@users.noreply.github.com>
Rolling integration PR for the next stable release. It stays open while
betais refined, and picks up every new commit merged tobetaautomatically. Do not merge until the release is ready — merging tomaincuts a stable GitHub Release straight away.What is on
betatodayfix(completion): a!referencetag anywhere in the file broke all input completionchore(deps): js-yaml 4.2.0 → 4.3.2 (transitive)chore(deps-dev): fast-uri 3.1.5 → 3.1.7chore(deps-dev): dev-dependencies group, 9 updateschore(deps-dev): mocha 11.8.0 → 12.0.0Plus the
chore(release)bumps to 0.17.0 and 0.17.1.Headline change
#263 fixes a total-parse-failure bug. GitLab's
!reference [.job, key]tag belongs to no YAML schema, so js-yaml threw on it and the parse returned nothing for the entire file —include:block included — even when the tag sat in an unrelated job further down. Completion, hover and validation all went silent, and deleting the!referenceline was the only workaround. A newGITLAB_CI_SCHEMAteaches the parser the tag.Known gaps in that schema are tracked separately in #268, #269 and #270; none of them blocks this release.
Security
#267 is not just a version bump. mocha 11 carried
diffandserialize-javascriptadvisories;npm auditonbetanow reports 0 vulnerabilities, down from 3 (1 low, 1 moderate, 1 high).Versioning
betasits at 0.17.1. Odd minor is the pre-release channel, per the repo's even/odd convention. On merge,.release-it.json'srequireEvenMinorrolls this forward to an even minor (0.18.0) for the stable channel. Nothing to do by hand.Note that the VS Code Marketplace publish is still a separate manual
workflow_dispatch; a GitHub Release from this merge does not by itself ship anything to users.Verification on
betanpm ciclean, lockfile in sync withpackage.jsonnpm run lintclean (eslint --max-warnings 0)node esbuild.jsandtsc --noEmitclean on both tsconfigsnpm audit: 0 vulnerabilitiesBefore merging
betais feature-complete for this releasebetatip<<:) #268 (YAML merge keys) should land first