Skip to content

chore(deps): bump the npm group across 1 directory with 16 updates - #745

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-a3ccb50007
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/npm-a3ccb50007

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm group with 16 updates in the / directory:

Package From To
@tauri-apps/api 2.11.1 2.12.0
@tauri-apps/plugin-process 2.3.1 2.4.0
@tauri-apps/plugin-shell 2.3.6 2.4.0
@tauri-apps/plugin-updater 2.12.0 2.13.0
lucide-react 1.47.0 1.48.0
react-resizable-panels 4.13.1 4.14.1
sql-formatter 15.8.2 15.9.0
@tauri-apps/cli 2.11.5 2.12.0
@vitest/browser 5.0.1 5.0.2
@vitest/browser-playwright 5.0.1 5.0.2
@vitest/coverage-v8 5.0.1 5.0.2
jsdom 30.1.0 30.1.1
prettier 3.9.8 3.9.9
typescript-eslint 8.70.0 8.70.1
vite 8.3.0 8.3.1
vitest 5.0.1 5.0.2

Updates @tauri-apps/api from 2.11.1 to 2.12.0

Release notes

Sourced from @​tauri-apps/api's releases.

@​tauri-apps/api v2.12.0

All found vulnerabilities were already reviewed and decided to be ignored
2 ignored: 2 high

[2.12.0]

New Features

  • d8d02ba60 (#14767) Added the exit function to @tauri-apps/api/app, backed by the new plugin:app|exit command (core:app:allow-exit permission), to exit the app without requiring the @tauri-apps/plugin-process plugin.
  • 990f77eb2 (#15961) Added JsImage type alias and documented its relationship to the Rust JsImage
  • 29265557c (#15410) Added noRedirectionBitmap option to the Window and WebviewWindow constructors on Windows.
  • 6edc2f4d4 (#14926) Added Window::set_fullscreen_on_monitor, WebviewWindow::set_fullscreen_on_monitor and the setFullscreenOnMonitor JavaScript API to make a window fullscreen on the monitor containing a given physical position, along with the core:window:allow-set-fullscreen-on-monitor permission.

Enhancements

  • be019795a (#14103) Add ECMAScript Explicit Resource Management to Resource. You can now use the using syntax in supported browsers or with polyfills:

    import { create, BaseDirectory } from "@tauri-apps/plugin-fs"
    ...
    {
      await using file = await create("foo/bar.txt", { baseDir: BaseDirectory.AppConfig });
      await file.write(new TextEncoder().encode("Hello world"));
      // Before `file` goes out of scope, it is disposed by calling `file[Symbol.asyncDispose]()` and awaited.
    }
  • 4a5065653 (#14454) Added Regular and Clear Liquid Glass window effects, and the interactive window effects option (macOS 27.0+) that enables the glass' visual response to user interactions.

Bug Fixes

  • 4fabe2ff1 (#16067) Fix Window.setBackgroundColor, Webview.setBackgroundColor and WebviewWindow.setBackgroundColor sending a color argument while the plugin:window|set_background_color and plugin:webview|set_webview_background_color commands expect label and value. The color was always deserialized as None, so instead of applying the given color the call cleared the background of the calling window/webview.
  • 32efd0232 (#15957) Image.rgba now returns a more specific type Promise<Uint8Array<ArrayBuffer>> instead of the default Promise<Uint8Array<ArrayBufferLike>
$ pnpm build && cd ./dist && pnpm publish --access public --loglevel debug --no-git-checks
$ rollup -c --configPlugin typescript
�[36m
�[1m./src/app.ts, ./src/core.ts, ./src/dpi.ts, ./src/event.ts, ./src/image.ts, ./src/index.ts, ./src/menu.ts, ./src/mocks.ts, ./src/path.ts, ./src/tray.ts, ./src/webview.ts, ./src/webviewWindow.ts, ./src/window.ts�[22m → �[1m./dist, ./dist�[22m...�[39m
�[32mcreated �[1m./dist, ./dist�[22m in �[1m757ms�[22m�[39m
�[36m
</tr></table> 

... (truncated)

Commits
  • 4f46cfc fix(ci): pnpm publish should use "debug" loglevel instead of "silly"
  • 726822c apply version updates (#15634)
  • 9f8922a docs(core): extend app_directories_override documentation (#16139)
  • dc894d4 chore: remove change file for unreleased fix (#16140)
  • 152529e Revert "feat(core): add android activityEmbedding config (#15255)" (#16138)
  • 7456ddd Revert "fix(core): proper unique identifier for menu items on channels store"...
  • 15468de fix(bundler): recognize deb and rpm as self-contained updater targets (#16064)
  • 8e70283 fix(bundler): update linuxdeploy and linuxdeploy-plugin-gtk (#16062)
  • 1b91b7b fix(cli): list all locked crate versions in tauri info (#16102)
  • ff7cd8d fix(cli): harden updater key generation and signing (#16118)
  • Additional commits viewable in compare view

Updates @tauri-apps/plugin-process from 2.3.1 to 2.4.0

Release notes

Sourced from @​tauri-apps/plugin-process's releases.

stronghold-js v2.4.0

[2.4.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-stronghold@2.4.0
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 4.7kB README.md
npm notice 19.4kB dist-js/index.cjs
npm notice 21.1kB dist-js/index.d.ts
npm notice 19.2kB dist-js/index.js
npm notice 750B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-stronghold
npm notice version: 2.4.0
npm notice filename: tauri-apps-plugin-stronghold-2.4.0.tgz
npm notice package size: 8.7 kB
npm notice unpacked size: 66.0 kB
npm notice shasum: 47b370840be057acd7d8f76046a9978a622cfcbe
npm notice integrity: sha512-5FIKueS+4xs66[...]j7Mzwt0NX4r1A==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=2969525576
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-stronghold@2.4.0

stronghold v2.4.0

[2.4.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​tauri-apps/plugin-process since your current version.


Updates @tauri-apps/plugin-shell from 2.3.6 to 2.4.0

Release notes

Sourced from @​tauri-apps/plugin-shell's releases.

stronghold-js v2.4.0

[2.4.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-stronghold@2.4.0
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 4.7kB README.md
npm notice 19.4kB dist-js/index.cjs
npm notice 21.1kB dist-js/index.d.ts
npm notice 19.2kB dist-js/index.js
npm notice 750B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-stronghold
npm notice version: 2.4.0
npm notice filename: tauri-apps-plugin-stronghold-2.4.0.tgz
npm notice package size: 8.7 kB
npm notice unpacked size: 66.0 kB
npm notice shasum: 47b370840be057acd7d8f76046a9978a622cfcbe
npm notice integrity: sha512-5FIKueS+4xs66[...]j7Mzwt0NX4r1A==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=2969525576
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-stronghold@2.4.0

stronghold v2.4.0

[2.4.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.

... (truncated)

Commits

Updates @tauri-apps/plugin-updater from 2.12.0 to 2.13.0

Release notes

Sourced from @​tauri-apps/plugin-updater's releases.

updater-js v2.13.0

[2.13.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.

bug

  • 101e1b06 (#3615) On Linux, check() no longer sets SSL_CERT_FILE and SSL_CERT_DIR to Debian paths. The override pointed rustls to files that do not exist on distros with a different layout, such as ALT Linux, and left every TLS client in the app without root certificates.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-updater@2.13.0
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 3.2kB README.md
npm notice 6.7kB dist-js/index.cjs
npm notice 7.1kB dist-js/index.d.ts
npm notice 6.6kB dist-js/index.js
npm notice 659B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-updater
npm notice version: 2.13.0
npm notice filename: tauri-apps-plugin-updater-2.13.0.tgz
npm notice package size: 4.8 kB
npm notice unpacked size: 25.1 kB
npm notice shasum: 309eff1cef34817ad6238c7f78fa4a3385e72b63
npm notice integrity: sha512-9iwTSOlxMPZGI[...]bR+PxQxf2qKMQ==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=2969525636
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-updater@2.13.0

updater v2.13.0

[2.13.0]

... (truncated)

Commits

Updates lucide-react from 1.47.0 to 1.48.0

Release notes

Sourced from lucide-react's releases.

Version 1.48.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.47.0...1.48.0

Commits

Updates react-resizable-panels from 4.13.1 to 4.14.1

Release notes

Sourced from react-resizable-panels's releases.

4.14.1

  • 720: Bugfix: Constraints applied because of a Group size change (e.g. a pixel-based minSize when the window is small) no longer permanently alter the layout; the requested layout is restored once the constraint no longer applies
    • onLayoutChanged meta includes a new requestedLayout attribute; useDefaultLayout and useDefaultGridLayout persist this value instead of the constrained layout

4.14.0

  • New Grid, Cell, and Gridline components for resizable two-dimensional layouts:
    • Columns and rows support the same size constraints as Panels (e.g. min/max size, collapsible)
    • Cells can span multiple columns and/or rows
    • Dragging where column and row boundaries intersect resizes both axes
    • Gridlines (optional, like Separators) can span a subset of tracks to avoid spanning cells
  • New useDefaultGridLayout, useGridRef, and useGridCallbackRef hooks

4.13.3

  • 755: Bugfix: Separator behind a modal <dialog> can no longer be dragged

4.13.2

  • 751: Separator no longer retains focus after a drag
  • 753: Fix Panel order in environments like JSDom with invalid offset values
Changelog

Sourced from react-resizable-panels's changelog.

4.14.1

  • 720: Bugfix: Constraints applied because of a Group size change (e.g. a pixel-based minSize when the window is small) no longer permanently alter the layout; the requested layout is restored once the constraint no longer applies
    • onLayoutChanged meta includes a new requestedLayout attribute; useDefaultLayout and useDefaultGridLayout persist this value instead of the constrained layout

4.14.0

  • New Grid, Cell, and Gridline components for resizable two-dimensional layouts:
    • Columns and rows support the same size constraints as Panels (e.g. min/max size, collapsible)
    • Cells can span multiple columns and/or rows
    • Dragging where column and row boundaries intersect resizes both axes
    • Gridlines (optional, like Separators) can span a subset of tracks to avoid spanning cells
  • New useDefaultGridLayout, useGridRef, and useGridCallbackRef hooks

4.13.3

  • 755: Bugfix: Separator behind a modal <dialog> can no longer be dragged

4.13.2

  • 751: Separator no longer retains focus after a drag
  • 753: Fix Panel order in environments like JSDom with invalid offset values
Commits
  • 0cd376c 4.14.0 -> 4.14.1
  • 1b329c6 Bugfix: Size constraints and windows/group resize (#757)
  • c961976 4.13.3 -> 4.14.0
  • 144e65d Grid, Gridline, and Cell components (#756)
  • ffa22a1 4.13.2 -> 4.13.3
  • cd49125 Bugfix: Separator behind a modal <dialog> can not be dragged (#755)
  • 9a2bb1f 4.13.1 -> 4.13.2
  • 3b6671e Fix panel (re)ordering bug for environments like JSDom with no positions/offs...
  • f6622c4 Bugfix: Separator keeps invisible focus after a drag (#752)
  • See full diff in compare view

Updates sql-formatter from 15.8.2 to 15.9.0

Release notes

Sourced from sql-formatter's releases.

15.9.0

Parsing improvements

  • Support \restrict and \unrestrict commands found in SQL created by pg_dump (#935) (thanks to sophalter)
  • Treat a reserved word after AS as an alias (#801, #972) (thanks to Christopher Pruijsen)
  • Support % as the modulo operator in SingleStoreDB (#578, #971) (thanks to Max Freedom Pollard)

Formatting improvements

  • Keep a space when densing - before a negative operand (thanks to Sarath Francis)
  • Keep spaces around PostgreSQL OPERATOR() with denseOperators (#958) (thanks to Sarath Francis)
  • Remove extra space after BETWEEN _ AND _ expression (#959) (thanks to Sarath Francis)
  • Keep DuckDB array-slice colon dense inside [] (#960) (thanks to Vincent Gao)

Performance

  • Avoid quadratic accumulation when parsing long SQL expression lists (#840, #963) (thanks to Alex Coleman)
Commits
  • 63dc9f8 15.9.0
  • a9a2223 Add a note about the need to pnpm login for release
  • 021b391 Treat a reserved word after AS as an alias (#972)
  • b77a536 Add Christopher Pruijsen to AUTHORS
  • 55c68bb Address review: narrow isAsKeyword, move tests to shared helpers
  • bcd3a42 Treat a reserved word after AS as an alias
  • a68e988 Support % as the modulo operator in SingleStoreDB (#971)
  • 1ff85d8 Add Max Freedom Pollard to AUTHORS
  • de7587e fix(singlestoredb): support % as the modulo operator
  • f6de1cd Merge branch 'fix/pgdump-restrict-commands'
  • Additional commits viewable in compare view

Updates @tauri-apps/cli from 2.11.5 to 2.12.0

Release notes

Sourced from @​tauri-apps/cli's releases.

@​tauri-apps/cli v2.12.0

[2.12.0]

New Features

  • f6c1eb253 (#15401) Added bundle.windows.bundleVCRuntime to copy the Visual C++ runtime DLLs into Windows MSI and NSIS installers. The bundler locates the runtime through VCTOOLS_REDIST_DIR or the bundled vswhere.exe.

  • f76b1d3ae (#15644) The bundler now prints the size of each generated bundle next to its path in the Finished N bundles at: output (directories such as macOS .app bundles are measured recursively).

  • af465eae1 (#15619) Add a --no-binary-patching flag to tauri build and tauri bundle. When set, the bundler skips patching the main executable with bundle type information (and the subsequent re-signing), leaving an already-signed binary untouched. Patching is only required when shipping multiple bundle types per platform that should each update with their own installer format.

  • 0646cc162 (#15620) Add a --fit option to tauri icon to accept non-square source images. --fit cover center-crops the source to a square (clipping the longer side) and --fit contain pads the shorter side with transparency. Non-square sources without --fit keep erroring, now with a hint pointing to the flag.

  • f6c1eb253 (#15401) Added build.windows.staticVCRuntime to control MSVC static runtime linking. The STATIC_VCRUNTIME environment variable is now deprecated and emits a migration warning when used.

  • f45ec0dcf Record the app version in the trusted comment of updater signatures, so a signed artifact is bound to the version it was released as.

    An update endpoint response is not signed, and the signature only covers the downloaded artifact, so the announced version on its own does not prove which release the url and signature point at. minisign covers the trusted comment with its global signature, which lets the updater plugin compare the two and reject a response that pairs a version number with a different release. Enable requireSignedVersion in the updater plugin configuration to enforce this.

    tauri build fills the version in automatically, and tauri plugin add updater now enables requireSignedVersion for the project it is adding the plugin to. tauri signer sign gains an --app-version flag for signing updater artifacts by hand, and warns when it is omitted.

Enhancements

  • e19121427 (#15993) Don't always rewrite Cargo.toml file from CRLF line endings to LF

  • aebf38c84 (#15694) Migrate the Android Gradle scripts from the deprecated kotlinOptions DSL to compilerOptions, which is accepted by both Kotlin Gradle Plugin 1.9.x and 2.x. This lets projects move to Kotlin 2.x without hitting the hard error that 2.3+ raises on the old DSL.

    This increased the minimum supported Gradle version to 8.13, if your gradle is on an earlier version, delete src-tauri/gen/android/gradle/wrapper/gradle-wrapper.properties and re-run tauri android init to update it.

  • d89d8fa62 (#15780) Warn during Android commands (init/dev/build) when the active Java version is too new for the Gradle version the project uses (e.g. Java 27 against the Gradle 9.6.1 the template ships, or Java 25 against a project still on Gradle 8.14), instead of letting the build fail later with a cryptic error. The warning points to the Gradle/Java compatibility matrix and suggests a supported JDK.

  • c3d21bd60 (#15730) Use Theme.Material3.DayNight.NoActionBar instead of Theme.MaterialComponents.DayNight.NoActionBar when running tauri android init

  • f654f470c (#15862) Update template to use targetSdk = 37

  • cdaf7eab6 (#15765) Clarify that the tauri init frontend commands run before tauri dev and tauri build, and can be left empty when they are not needed.

  • d0f38df06 (#15997) When stdin is not a terminal, tauri init now automatically skips prompts, avoiding IO errors in CI and scripts. This eliminates the need to pass --ci explicitly in non-interactive environments.

  • ca160ad48 (#15895) tauri build now warns when productName is still set to the default tauri-app, since it names the generated bundles and is written into install paths and metadata that are expected to be unique to your application. The config documentation for productName now lists what the field controls on each platform, and identifier's documentation notes that the default value is rejected.

  • 010f06bae (#15737) Document the TAURI_SIGNING_PRIVATE_KEY_PATH environment variable and clarify that TAURI_SIGNING_PRIVATE_KEY accepts a string or a path for the build and bundle command but must be the literal key string for the signer sign command, both in ENVIRONMENT_VARIABLES.md and in the signer generate command output.

Bug Fixes

  • 9bad06b9f (#16096) tauri capability new and tauri permission new now accept an --out path to a file that does not exist yet, trim comma-separated prompt answers (so fs:default, core:default works), report invalid permissions as errors instead of panicking, and reject identifiers that are not valid file names (such as ../../x), which previously let them write outside of the capabilities or permissions directory.
  • 9642b3087 (#16117) tauri add now honors --tag, --rev and --branch for official plugins instead of silently installing the registry version, and rejects passing more than one of them. With npm, the JS package requirement is now ~<version> like the other package managers, instead of >=<version> which allowed a later major version.
  • cada1cd4f (#16105) Fix Android dev server port forwarding: adb reverse --list is now matched on the exact port (so tcp:80 no longer matches tcp:8080), stale forwards on other connected devices are actually removed, and the forward verification gives up with a warning after a few attempts instead of retrying forever.
  • d5bd04658 (#16111) Fix bundle > android > debugApplicationIdSuffix being written to the signingConfigs debug block instead of the buildTypes one, and keep the existing content of single-line debug blocks such as getByName("debug") { isDebuggable = true } instead of dropping it.
  • ba17da2e5 (#16101) tauri icon now generates 72x72 Android hdpi launcher icons (previously 49x49) and writes the Android launcher background color in #RRGGBB/#AARRGGBB notation instead of the raw CSS color string, which Android rejected or misread. Invalid SVG sources and --png 0 now return an error instead of panicking.
  • 272842a57 (#16128) Fix error messages that printed placeholders such as {t} literally instead of the value, e.g. "Could not find an Android device matching {t}".
  • 10ad4e54e (#16127) The Bash completions generated by tauri completions no longer replace the completions of cargo, npm, pnpm, yarn, bun and deno. They now define a _tauri_cli function registered only for the tauri and cargo-tauri commands. Generating completions when running the cargo-tauri binary directly no longer panics.
  • 0e4ded72a (#16107) Fix binaries in src/bin and src/main.rs being left out of bundles when Cargo.toml declares a [[bin]] target without a path.
  • 8e0fa2e2f (#16097) Fix the bundler using the host target triple when --target is not passed but build.target is set in .cargo/config.toml. The CLI now also accepts build.target as an array and honors the CARGO_BUILD_TARGET environment variable.
  • 7bb0a5421 (#16120) Fix the Cargo.toml feature rewrite corrupting a string dependency version that has a trailing comment or uses single quotes (e.g. tauri = "2" # pin became "2#pin"). The version value is now kept as-is and the comment is preserved.
  • e4630258e (#16114) Fix the CLI's working directory being left changed to the config directory when the Tauri configuration fails to parse, for example when tauri dev reloads an invalid config.
  • 1b91b7b7b (#16102) tauri info now logs a warning when it cannot check the latest crate version on crates.io instead of silently ignoring the failure, and no longer panics if crates.io returns a version it cannot parse.
  • 1b91b7b7b (#16102) tauri info now lists every locked version of a Rust crate when Cargo.lock contains more than one, and no longer panics when the crates.io response cannot be parsed.
  • 6507d0b8b (#16124) tauri dev now reports an error instead of panicking when the beforeDevCommand cannot be spawned or the devUrl host cannot be resolved, and no longer risks stopping the beforeDevCommand process tree twice when Ctrl+C and the app exit race.
  • c1ea96ad6 (#16110) Fix tauri dev not reacting to the app exiting when a process spawned by the app kept its stderr open, and stop keeping the whole app stderr output in memory. Also fix command output capture that could return empty output when the command finished before its output was read.
  • d61fbdc3e (#16109) Fix Cargo.toml feature injection and the v1 migration only updating either [dependencies] or [target.'cfg(..)'.dependencies], whichever came first in the file. Both the main and all target-specific dependency tables are now updated.
  • 5d995ed35 (#16017) Normalize gen/android/gradlew CRLF line endings to LF on all host platforms, not only Unix. A gradlew checked out with CRLF broke sh ./gradlew on Windows hosts using Git Bash. The rewrite only runs when a CRLF is actually present. A failure to rewrite aborts on Unix, where the script is executed directly; on Windows the CLI invokes gradlew.bat, so failures there only warn.
  • 6d943c420 (#16065) Fix the tauri capability new command description, which said "Create a new permission file", and the --skip-stapling help text on tauri build and tauri bundle, whose first line described the opposite of what the flag does.

... (truncated)

Commits

Bumps the npm group with 16 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@tauri-apps/api](https://github.com/tauri-apps/tauri) | `2.11.1` | `2.12.0` |
| [@tauri-apps/plugin-process](https://github.com/tauri-apps/plugins-workspace) | `2.3.1` | `2.4.0` |
| [@tauri-apps/plugin-shell](https://github.com/tauri-apps/plugins-workspace) | `2.3.6` | `2.4.0` |
| [@tauri-apps/plugin-updater](https://github.com/tauri-apps/plugins-workspace) | `2.12.0` | `2.13.0` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.47.0` | `1.48.0` |
| [react-resizable-panels](https://github.com/bvaughn/react-resizable-panels) | `4.13.1` | `4.14.1` |
| [sql-formatter](https://github.com/sql-formatter-org/sql-formatter) | `15.8.2` | `15.9.0` |
| [@tauri-apps/cli](https://github.com/tauri-apps/tauri) | `2.11.5` | `2.12.0` |
| [@vitest/browser](https://github.com/vitest-dev/vitest/tree/HEAD/packages/browser) | `5.0.1` | `5.0.2` |
| [@vitest/browser-playwright](https://github.com/vitest-dev/vitest/tree/HEAD/packages/browser-playwright) | `5.0.1` | `5.0.2` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `5.0.1` | `5.0.2` |
| [jsdom](https://github.com/jsdom/jsdom) | `30.1.0` | `30.1.1` |
| [prettier](https://github.com/prettier/prettier) | `3.9.8` | `3.9.9` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.70.0` | `8.70.1` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.3.0` | `8.3.1` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.1` | `5.0.2` |



Updates `@tauri-apps/api` from 2.11.1 to 2.12.0
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](https://github.com/tauri-apps/tauri/compare/@tauri-apps/api-v2.11.1...@tauri-apps/api-v2.12.0)

Updates `@tauri-apps/plugin-process` from 2.3.1 to 2.4.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@os-v2.3.1...os-v2.4.0)

Updates `@tauri-apps/plugin-shell` from 2.3.6 to 2.4.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@nfc-v2.3.6...os-v2.4.0)

Updates `@tauri-apps/plugin-updater` from 2.12.0 to 2.13.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@updater-v2.12.0...updater-v2.13.0)

Updates `lucide-react` from 1.47.0 to 1.48.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.48.0/packages/lucide-react)

Updates `react-resizable-panels` from 4.13.1 to 4.14.1
- [Release notes](https://github.com/bvaughn/react-resizable-panels/releases)
- [Changelog](https://github.com/bvaughn/react-resizable-panels/blob/main/CHANGELOG.md)
- [Commits](bvaughn/react-resizable-panels@4.13.1...4.14.1)

Updates `sql-formatter` from 15.8.2 to 15.9.0
- [Release notes](https://github.com/sql-formatter-org/sql-formatter/releases)
- [Commits](sql-formatter-org/sql-formatter@v15.8.2...v15.9.0)

Updates `@tauri-apps/cli` from 2.11.5 to 2.12.0
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](https://github.com/tauri-apps/tauri/compare/@tauri-apps/cli-v2.11.5...@tauri-apps/cli-v2.12.0)

Updates `@vitest/browser` from 5.0.1 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/browser)

Updates `@vitest/browser-playwright` from 5.0.1 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/browser-playwright)

Updates `@vitest/coverage-v8` from 5.0.1 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/coverage-v8)

Updates `jsdom` from 30.1.0 to 30.1.1
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v30.1.0...v30.1.1)

Updates `prettier` from 3.9.8 to 3.9.9
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.8...3.9.9)

Updates `typescript-eslint` from 8.70.0 to 8.70.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.1/packages/typescript-eslint)

Updates `vite` from 8.3.0 to 8.3.1
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.1/packages/vite)

Updates `vitest` from 5.0.1 to 5.0.2
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.2/packages/vitest)

---
updated-dependencies:
- dependency-name: "@tauri-apps/api"
  dependency-version: 2.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@tauri-apps/plugin-process"
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@tauri-apps/plugin-shell"
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@tauri-apps/plugin-updater"
  dependency-version: 2.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: lucide-react
  dependency-version: 1.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: react-resizable-panels
  dependency-version: 4.14.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: sql-formatter
  dependency-version: 15.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@tauri-apps/cli"
  dependency-version: 2.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm
- dependency-name: "@vitest/browser"
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@vitest/browser-playwright"
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: jsdom
  dependency-version: 30.1.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: prettier
  dependency-version: 3.9.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: typescript-eslint
  dependency-version: 8.70.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: vite
  dependency-version: 8.3.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
- dependency-name: vitest
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: npm
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Dependency updates javascript npm/JavaScript updates labels Oct 5, 2026
EVWorth added a commit that referenced this pull request Oct 5, 2026
)

* fix(deps): match tauri-plugin-updater to its npm package, and check it in CI

#740 moved @tauri-apps/plugin-updater to 2.12.0 while the
tauri-plugin-updater crate stayed at 2.11.0. `tauri build` refuses to
start when a Tauri npm package and its crate disagree on major.minor
("Found version mismatched Tauri packages"), so main could not build a
release. Nothing on a PR runs `tauri build`; only the release workflow
does, so CI stayed green.

Bump the crate to 2.12.0 (published 2026-09-20, past the seven-day
rule). The lockfile moves that one package and nothing else; tauri
stays at 2.11.5.

scripts/check-tauri-versions.sh applies the CLI's rule without a build:
@tauri-apps/api pairs with `tauri`, @tauri-apps/plugin-<x> with
tauri-plugin-<x>, compared from package-lock.json and Cargo.lock. It
runs in the Version Consistency job, which already triggers on either
lockfile, and in `just lint`. Against main's lockfiles it reports the
updater pair; with this change all four pairs agree.
scripts/test-check-tauri-versions.sh covers matching pairs, a plugin
a minor ahead, api-vs-tauri, patch-only differences, packages with no
crate, crate-name prefixes, nested npm copies, and no pairs at all.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg

* chore(deps): bump Tauri to 2.12 on the npm and Rust sides together

`tauri build` requires each Tauri npm package and its crate to share a
major.minor, and Dependabot proposes npm and cargo separately: #745
moved the JS packages alone, which the new check-tauri-versions.sh
would fail. This moves every pair in one change.

  @tauri-apps/api 2.11.1 -> 2.12.0        tauri 2.11.5 -> 2.12.0
  @tauri-apps/cli 2.11.5 -> 2.12.0        tauri-build 2.6.3 -> 2.7.0
  @tauri-apps/plugin-process 2.3.1 -> 2.4.0   tauri-plugin-process 2.3.1 -> 2.4.0
  @tauri-apps/plugin-shell 2.3.6 -> 2.4.0     tauri-plugin-shell 2.3.6 -> 2.4.0
  @tauri-apps/plugin-updater 2.12.0 -> 2.13.0 tauri-plugin-updater 2.12.0 -> 2.13.0

All are the 2026-09-26 releases, nine days old; the .1 point releases
from 2026-09-29/30 are inside the seven-day window and left for later.
Cargo resolved tauri's internal crates (tauri-runtime, -runtime-wry,
-utils, -macros, -codegen, tauri-plugin) to their 09-30 releases, so
those are pinned back in the lockfile to the 09-26 set tauri 2.12.0
shipped with. The rest of the lockfile churn is tauri's own new
transitive versions (wry 0.57, tao 0.37, muda, tray-icon, webview2-com)
and drops the old windows 0.61 family and the unmaintained unic-*
crates, which takes cargo audit's non-blocking warnings from 9 to 4.

The plugins' 2.4/2.13 releases require tauri ^2.12, which is why
Dependabot could not offer them on their own.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg

---------

Co-authored-by: Claude <noreply@anthropic.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 5, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/npm-a3ccb50007 branch October 5, 2026 03:19
EVWorth added a commit that referenced this pull request Oct 5, 2026
… rmcp once (#750)

Two Dependabot shapes kept producing PRs that cannot pass:

- Tauri: npm and cargo were proposed separately, so a Tauri release
  arrived as npm-only (#745), which check-tauri-versions.sh fails and
  `tauri build` refuses. The plugin crates never moved at all: each new
  plugin minor requires the new `tauri`, and a per-ecosystem update
  moves one dependency at a time. A `tauri` multi-ecosystem group now
  owns @tauri-apps/* on npm and tauri, tauri-build, tauri-plugin-* on
  cargo, so both halves land in one PR. Its member entries carry the
  same 7-day cooldown and hold back majors; the regular npm and cargo
  entries ignore those names so nothing is proposed twice.
- rmcp: pinned exactly in both the app crate and crates/mas-mcp, and
  Dependabot bumped only one (#736, twice), which cannot resolve. The
  pin moves to [workspace.dependencies]; both crates inherit it, so a
  bump is one edit. The lockfile does not change.

Checked against SchemaStore's dependabot-2.0 schema (0 errors).


Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates javascript npm/JavaScript updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants