Skip to content

chore(deps): bump Tauri to 2.12 on the npm and Rust sides together - #749

Merged
EVWorth merged 3 commits into
mainfrom
claude/tauri-2.12
Oct 5, 2026
Merged

EVWorth merged 3 commits into
mainfrom
claude/tauri-2.12

Conversation

@EVWorth

@EVWorth EVWorth commented Oct 5, 2026

Copy link
Copy Markdown
Owner

This builds on #747: it includes #747's commit, and the version check from #747 is what verifies this PR. Merge #747 first and this diff shrinks to the Tauri bump alone.

Why both sides at once

tauri build requires each Tauri npm package and its crate to be on the same major.minor. Dependabot proposes npm and cargo changes separately: #745 moved the JS packages alone, which the new check would fail. The cargo side never got the Rust half at all. Every 2.4/2.13 plugin requires tauri ^2.12, and Dependabot hasn't offered tauri itself (more on that below).

npm crate
@tauri-apps/api 2.11.1 → 2.12.0 tauri 2.11.5 → 2.12.0
@tauri-apps/cli 2.11.5 → 2.12.0 tauri-build 2.6.3 → 2.7.0
@tauri-apps/plugin-process 2.3.1 → 2.4.0 tauri-plugin-process 2.3.1 → 2.4.0
@tauri-apps/plugin-shell 2.3.6 → 2.4.0 tauri-plugin-shell 2.3.6 → 2.4.0
@tauri-apps/plugin-updater 2.12.0 → 2.13.0 tauri-plugin-updater 2.12.0 → 2.13.0

Seven-day rule

  • Every package above is a 2026-09-26 release, nine days old.
  • The .1 point releases (Sept 29–30) are still inside the window and are left for later.
  • Cargo resolved Tauri's internal crates (tauri-runtime, tauri-runtime-wry, tauri-utils, tauri-macros, tauri-codegen, tauri-plugin) to their Sept 30 releases. I pinned them back in the lockfile to the Sept 26 set that tauri 2.12.0 shipped with.
  • I checked every other crate that moved; the newest is from Sept 26.

The rest of the lockfile

  • Cargo: the remaining changes are Tauri 2.12's own new transitive versions: wry 0.57, tao 0.37, muda 0.20, tray-icon 0.25 and webview2-com 0.39. It also drops the old windows 0.61 crates and the unmaintained unic-* crates, which cuts cargo audit's non-blocking warnings from 9 to 4.
  • npm: only @tauri-apps/* entries changed. Most of the diff is the CLI's per-platform binaries.

Verification

  • scripts/check-tauri-versions.sh: all 4 pairs agree.
  • npx tauri build --debug --no-bundle: passes the version check and builds the app.
  • cargo clippy --all-targets --all-features -D warnings on the full workspace: clean.
  • Tests: cargo test -p sqlpilot --lib 61/61, and the six library crates 486/486.
  • cargo test --test export_bindings passes and src/lib/bindings.ts is unchanged.
  • scripts/cargo-audit-check.sh: 0 vulnerabilities. npm audit signatures and npm audit --audit-level=critical: pass.
  • npm run test:unit: 2970 pass. The one exception is main.test.tsx, whose 10s hook timeout happens on main too in my container, and which passes in CI.

Not covered

The app wasn't launched, because my container has no display. Worth a quick smoke test (open a connection, run a query, check for updates) before the next release.

Follow-ups

🤖 Generated with Claude Code

https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg


Generated by Claude Code

claude added 3 commits October 5, 2026 02:48
…t in CI

#740 moved @tauri-apps/plugin-updater to 2.12.0 while the
tauri-plugin-updater crate stayed at 2.11.0. `tauri build` refuses to
start when a Tauri npm package and its crate disagree on major.minor
("Found version mismatched Tauri packages"), so main could not build a
release. Nothing on a PR runs `tauri build`; only the release workflow
does, so CI stayed green.

Bump the crate to 2.12.0 (published 2026-09-20, past the seven-day
rule). The lockfile moves that one package and nothing else; tauri
stays at 2.11.5.

scripts/check-tauri-versions.sh applies the CLI's rule without a build:
@tauri-apps/api pairs with `tauri`, @tauri-apps/plugin-<x> with
tauri-plugin-<x>, compared from package-lock.json and Cargo.lock. It
runs in the Version Consistency job, which already triggers on either
lockfile, and in `just lint`. Against main's lockfiles it reports the
updater pair; with this change all four pairs agree.
scripts/test-check-tauri-versions.sh covers matching pairs, a plugin
a minor ahead, api-vs-tauri, patch-only differences, packages with no
crate, crate-name prefixes, nested npm copies, and no pairs at all.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg
`tauri build` requires each Tauri npm package and its crate to share a
major.minor, and Dependabot proposes npm and cargo separately: #745
moved the JS packages alone, which the new check-tauri-versions.sh
would fail. This moves every pair in one change.

  @tauri-apps/api 2.11.1 -> 2.12.0        tauri 2.11.5 -> 2.12.0
  @tauri-apps/cli 2.11.5 -> 2.12.0        tauri-build 2.6.3 -> 2.7.0
  @tauri-apps/plugin-process 2.3.1 -> 2.4.0   tauri-plugin-process 2.3.1 -> 2.4.0
  @tauri-apps/plugin-shell 2.3.6 -> 2.4.0     tauri-plugin-shell 2.3.6 -> 2.4.0
  @tauri-apps/plugin-updater 2.12.0 -> 2.13.0 tauri-plugin-updater 2.12.0 -> 2.13.0

All are the 2026-09-26 releases, nine days old; the .1 point releases
from 2026-09-29/30 are inside the seven-day window and left for later.
Cargo resolved tauri's internal crates (tauri-runtime, -runtime-wry,
-utils, -macros, -codegen, tauri-plugin) to their 09-30 releases, so
those are pinned back in the lockfile to the 09-26 set tauri 2.12.0
shipped with. The rest of the lockfile churn is tauri's own new
transitive versions (wry 0.57, tao 0.37, muda, tray-icon, webview2-com)
and drops the old windows 0.61 family and the unmaintained unic-*
crates, which takes cargo audit's non-blocking warnings from 9 to 4.

The plugins' 2.4/2.13 releases require tauri ^2.12, which is why
Dependabot could not offer them on their own.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg
# Conflicts:
#	src-tauri/Cargo.lock
#	src-tauri/Cargo.toml
@EVWorth
EVWorth merged commit 24ea30e into main Oct 5, 2026
12 checks passed
@EVWorth
EVWorth deleted the claude/tauri-2.12 branch October 5, 2026 03:16
@EVWorth EVWorth mentioned this pull request Oct 5, 2026
EVWorth added a commit that referenced this pull request Oct 5, 2026
Version bump across the three manifests and the two lockfile entries
that record the app's own version.

What 1.2.0 contains since 1.1.0:

- Each editor tab runs on its own server session, so SET @var,
  temporary tables and multi-run transactions carry across runs (#734)
- Separate connection lanes for the agent and for backups/restores, so
  neither can starve the editor; the pool-exhausted message says what
  is holding the pool (#732, #727)
- Copy button beside Expand for long cell values, such as SHOW CREATE
  TABLE (#748)
- Linux/Wayland: WebKitGTK's DMABUF renderer is turned off, for the
  black area left after resizing the window (#742)
- Tauri 2.12 on both the npm and Rust sides (#749), and the dependency
  roll-up in #740
- rustls TLS 1.3 advisory RUSTSEC-2026-0285 patched (#728)

Also the first release built with rustup in place of
dtolnay/rust-toolchain (#746), so the release jobs' toolchain step runs
on Windows and macOS for the first time.


Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants