Repository navigation
chore(deps): bump Tauri to 2.12 on the npm and Rust sides together - #749
Merged
Merged
Conversation
…t in CI #740 moved @tauri-apps/plugin-updater to 2.12.0 while the tauri-plugin-updater crate stayed at 2.11.0. `tauri build` refuses to start when a Tauri npm package and its crate disagree on major.minor ("Found version mismatched Tauri packages"), so main could not build a release. Nothing on a PR runs `tauri build`; only the release workflow does, so CI stayed green. Bump the crate to 2.12.0 (published 2026-09-20, past the seven-day rule). The lockfile moves that one package and nothing else; tauri stays at 2.11.5. scripts/check-tauri-versions.sh applies the CLI's rule without a build: @tauri-apps/api pairs with `tauri`, @tauri-apps/plugin-<x> with tauri-plugin-<x>, compared from package-lock.json and Cargo.lock. It runs in the Version Consistency job, which already triggers on either lockfile, and in `just lint`. Against main's lockfiles it reports the updater pair; with this change all four pairs agree. scripts/test-check-tauri-versions.sh covers matching pairs, a plugin a minor ahead, api-vs-tauri, patch-only differences, packages with no crate, crate-name prefixes, nested npm copies, and no pairs at all. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg
`tauri build` requires each Tauri npm package and its crate to share a major.minor, and Dependabot proposes npm and cargo separately: #745 moved the JS packages alone, which the new check-tauri-versions.sh would fail. This moves every pair in one change. @tauri-apps/api 2.11.1 -> 2.12.0 tauri 2.11.5 -> 2.12.0 @tauri-apps/cli 2.11.5 -> 2.12.0 tauri-build 2.6.3 -> 2.7.0 @tauri-apps/plugin-process 2.3.1 -> 2.4.0 tauri-plugin-process 2.3.1 -> 2.4.0 @tauri-apps/plugin-shell 2.3.6 -> 2.4.0 tauri-plugin-shell 2.3.6 -> 2.4.0 @tauri-apps/plugin-updater 2.12.0 -> 2.13.0 tauri-plugin-updater 2.12.0 -> 2.13.0 All are the 2026-09-26 releases, nine days old; the .1 point releases from 2026-09-29/30 are inside the seven-day window and left for later. Cargo resolved tauri's internal crates (tauri-runtime, -runtime-wry, -utils, -macros, -codegen, tauri-plugin) to their 09-30 releases, so those are pinned back in the lockfile to the 09-26 set tauri 2.12.0 shipped with. The rest of the lockfile churn is tauri's own new transitive versions (wry 0.57, tao 0.37, muda, tray-icon, webview2-com) and drops the old windows 0.61 family and the unmaintained unic-* crates, which takes cargo audit's non-blocking warnings from 9 to 4. The plugins' 2.4/2.13 releases require tauri ^2.12, which is why Dependabot could not offer them on their own. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg
# Conflicts: # src-tauri/Cargo.lock # src-tauri/Cargo.toml
Merged
EVWorth
added a commit
that referenced
this pull request
Oct 5, 2026
Version bump across the three manifests and the two lockfile entries that record the app's own version. What 1.2.0 contains since 1.1.0: - Each editor tab runs on its own server session, so SET @var, temporary tables and multi-run transactions carry across runs (#734) - Separate connection lanes for the agent and for backups/restores, so neither can starve the editor; the pool-exhausted message says what is holding the pool (#732, #727) - Copy button beside Expand for long cell values, such as SHOW CREATE TABLE (#748) - Linux/Wayland: WebKitGTK's DMABUF renderer is turned off, for the black area left after resizing the window (#742) - Tauri 2.12 on both the npm and Rust sides (#749), and the dependency roll-up in #740 - rustls TLS 1.3 advisory RUSTSEC-2026-0285 patched (#728) Also the first release built with rustup in place of dtolnay/rust-toolchain (#746), so the release jobs' toolchain step runs on Windows and macOS for the first time. Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This builds on #747: it includes #747's commit, and the version check from #747 is what verifies this PR. Merge #747 first and this diff shrinks to the Tauri bump alone.
Why both sides at once
tauri buildrequires each Tauri npm package and its crate to be on the same major.minor. Dependabot proposes npm and cargo changes separately: #745 moved the JS packages alone, which the new check would fail. The cargo side never got the Rust half at all. Every 2.4/2.13 plugin requirestauri ^2.12, and Dependabot hasn't offeredtauriitself (more on that below).@tauri-apps/apitauri@tauri-apps/clitauri-build@tauri-apps/plugin-processtauri-plugin-process@tauri-apps/plugin-shelltauri-plugin-shell@tauri-apps/plugin-updatertauri-plugin-updaterSeven-day rule
tauri-runtime,tauri-runtime-wry,tauri-utils,tauri-macros,tauri-codegen,tauri-plugin) to their Sept 30 releases. I pinned them back in the lockfile to the Sept 26 set thattauri2.12.0 shipped with.The rest of the lockfile
windows0.61 crates and the unmaintainedunic-*crates, which cuts cargo audit's non-blocking warnings from 9 to 4.@tauri-apps/*entries changed. Most of the diff is the CLI's per-platform binaries.Verification
scripts/check-tauri-versions.sh: all 4 pairs agree.npx tauri build --debug --no-bundle: passes the version check and builds the app.cargo clippy --all-targets --all-features -D warningson the full workspace: clean.cargo test -p sqlpilot --lib61/61, and the six library crates 486/486.cargo test --test export_bindingspasses andsrc/lib/bindings.tsis unchanged.scripts/cargo-audit-check.sh: 0 vulnerabilities.npm audit signaturesandnpm audit --audit-level=critical: pass.npm run test:unit: 2970 pass. The one exception ismain.test.tsx, whose 10s hook timeout happens on main too in my container, and which passes in CI.Not covered
The app wasn't launched, because my container has no display. Worth a quick smoke test (open a connection, run a query, check for updates) before the next release.
Follow-ups
rmcpto 3.5.0 incrates/mas-mcponly. The app crate still pins=3.4.0, the same split as before, so it won't resolve as-is.🤖 Generated with Claude Code
https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg
Generated by Claude Code