Repository navigation
chore: apply grouped dependency updates from #388 and #390 - #393
Conversation
Consolidates dependabot's production-dependencies (#388) and dev-dependencies (#390) grouped updates, plus the two workspace-config changes neither PR could make: - bump the prettier override 3.9.4 -> 3.9.6 so the exact pin matches the new ^3.9.6 manifest floors (single formatter version workspace-wide) - drop brace-expansion from minimumReleaseAgeExclude; its cooldown elapsed 2026-07-26 (the >=5.0.8 override stays) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012szNNjysHff51G26SSTWeA
|
Warning Review limit reached
Next review available in: 4 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (6)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub. |
Preview DeploymentPreview URL: https://0da93207.bestax.pages.dev |
There was a problem hiding this comment.
Deep review — 0 blocking · 1 advisory
| # | Severity | Area | Finding | Location |
|---|---|---|---|---|
| 1 | 🔵 Advisory | Robustness | Full lint/test/build gate not re-run in this sandbox (approval-gated); verified statically + via format:check, otherwise relying on CI + the PR's local pnpm all claim |
pnpm-lock.yaml |
Overall: This is a consolidation of two grouped dependabot bumps plus two pnpm-workspace.yaml edits, and it holds up. I read every manifest against the resolved lockfile importers and every declared specifier matches its resolution (root/docs → react 19.2.8, commitlint 21.2.1, semantic-release 25.0.8, docusaurus 3.10.2, fontawesome 7.3.1; create-bestax → wait-on 9.1.0 / @types/node 26.1.1). The riskiest change on paper — @typescript-eslint 8.8.1 → 8.65.0 — is a same-major jump and lint config loads it by range; I couldn't execute lint here, so that's the one thing a human/CI should confirm is green.
Residual risk: the failure class here is a supply-chain / lockfile-drift regression. I chased each way it could still bite:
- Lockfile drift from manifests — refuted: read all four importers'
specifier/versionpairs; every one satisfies its manifest range, no stale pins. - Dropped security override — refuted: the lockfile
overridesheader and resolved packages still carry all five (serialize-javascript@7.0.6,sharp@0.35.3,postcss@8.5.21,brace-expansion@5.0.8as a single copy,prettier@3.9.6); thebrace-expansion: '>=5.0.8'security override survives theminimumReleaseAgeExcluderemoval. brace-expansioncooldown not actually elapsed — refuted:5.0.8published 2026-07-23,minimumReleaseAgeis 3 days, today is 2026-07-27, so it clears the gate; a future non-frozen install would fall back to the locked5.0.8(>=3 days old) if a newer one appeared, so no install breakage.- Prettier bump churn — refuted empirically:
format:checkpasses untouched under3.9.6, and theoverridespin was bumped in lockstep so no split-copy disagreement.
🏄 Two gnarly lockfile PRs paddled out as one clean set wave, brah — every dep lines up, the security overrides held their edge, and the only thing left is letting CI ride lint to shore. Good to go.
|
🎉 This PR is included in version 3.7.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
…oth CLIs (#447) * chore(deps): consolidate dependabot updates, pin patched minimatch and yaml Consolidates #427, #428, #431, #432 and #440 into one PR so the shared pnpm-lock.yaml is regenerated once instead of forcing dependabot to rebase six branches serially. Same approach as #393 for #388/#390. docusaurus-plugin-llms 0.5.x pins its own dependencies exactly rather than by range, which dragged minimatch back to 9.0.3 (three high ReDoS advisories) and yaml to 2.8.1, failing both `pnpm audit --audit-level=high` and Dependency Review on #440. Two scoped overrides restore the patched versions; the rest of that group was already clean. @semantic-release/changelog 7 and @semantic-release/git 11 are the same CJS-to-ESM wave and are taken together. Every option the release configs actually pass (changelogFile, assets, message) is unchanged, and both declare a semantic-release peer of >=20.1.0, satisfied by ^25.0.8. @testing-library/jest-dom 7 removes no matchers; the new required peer @testing-library/dom is already resolved at 10.4.1 via @testing-library/react. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * feat(create-bestax): require Node 22 and take chalk 6 chalk 6 drops support for Node below 22. The API surface this package uses is unchanged — every call site is a default import using .red/.yellow/.green and friends — so no calling code changes. Raising engines.node to >=22 brings the manifest in line with what the docs have claimed all along: the installation guide already states "Node.js: 22.0.0 or higher (the current LTS baseline)". The version guard in src/index.ts moves ahead of every import and stops using chalk. Import declarations are hoisted and evaluated before any statement in the module, and chalk 6 itself requires Node >= 22 — so a static import would fail to load on exactly the runtimes the guard exists to catch, replacing a clear message with an opaque loader error. ./cli.js is now imported dynamically for the same reason. BREAKING CHANGE: create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * feat(bestax-migrate): require Node 22 and take chalk 6 chalk 6 drops support for Node below 22. The API surface this package uses is unchanged, so no calling code changes. The version guard in src/index.ts moves ahead of every import and no longer depends on anything: import declarations are hoisted and evaluated before any statement in the module, and chalk 6 itself requires Node >= 22, so a static import would fail to load on exactly the runtimes the guard exists to catch. ./cli.js is now imported dynamically for the same reason. @babel/parser deliberately stays on 7.x. Babel 8 removes the `deprecatedImportAssert` plugin with no replacement, and this package parses the legacy `import x from 'y' assert { type: 'json' }` form on purpose — a codemod that migrates older codebases must not crash on the syntax those codebases still contain. There is a regression test for it ("parses the legacy import-assert syntax"), which Babel 8 fails outright. jscodeshift 17 bundles its own Babel 7 regardless, so staying on 7 also keeps a single parser in the tree rather than two. BREAKING CHANGE: bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
# [4.0.0](https://github.com/allxsmith/bestax/compare/create-bestax@3.8.0...create-bestax@4.0.0) (2026-08-01) ### Bug Fixes * **bestax-migrate:** give the kitchen-sink e2e a per-process scratch dir ([2211ea5](2211ea5)) * **bestax-migrate:** reject pnpm's workspace alias form instead of unwrapping it ([de6a900](de6a900)) * **bestax-migrate:** require the pack script to exist, not just be named ([5315efe](5315efe)) * **bestax-migrate:** resolve bare workspace: and guard the catalog: protocol ([7fda9db](7fda9db)), closes [#417](#417) [#412](#412) * **bestax-migrate:** resolve workspace: specifiers before publishing ([782829a](782829a)), closes [bestax-migrate#test](https://github.com/bestax-migrate/issues/test) [#412](#412) * **bestax-migrate:** stop the pack hooks excusing a catalog: devDependency ([4127ead](4127ead)), closes [#412-shaped](#412) * **docs:** stop cssnano stripping Font Awesome [@font-face](https://github.com/font-face), add [#3](#3) CSS framework blog post ([#401](#401)) ([5d114e1](5d114e1)), closes [#400](#400) ### chore * **deps:** consolidate the dependabot backlog, require Node 22 in both CLIs ([#447](#447)) ([e68148c](e68148c)), closes [#427](#427) [#428](#428) [#431](#431) [#432](#432) [#440](#440) [#393](#393) ### Features * **bestax-migrate:** require Node 22 and take chalk 6 ([#449](#449)) ([4c0e1e2](4c0e1e2)), closes [#447](#447) * **create-bestax:** require Node 22 and take chalk 6 ([#448](#448)) ([90fced2](90fced2)), closes [#447](#447) ### BREAKING CHANGES * **bestax-migrate:** bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. This applies to the runtime the codemod executes on, not to the app being migrated. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * **create-bestax:** create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * **deps:** create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * feat(bestax-migrate): require Node 22 and take chalk 6 chalk 6 drops support for Node below 22. The API surface this package uses is unchanged, so no calling code changes. The version guard in src/index.ts moves ahead of every import and no longer depends on anything: import declarations are hoisted and evaluated before any statement in the module, and chalk 6 itself requires Node >= 22, so a static import would fail to load on exactly the runtimes the guard exists to catch. ./cli.js is now imported dynamically for the same reason. @babel/parser deliberately stays on 7.x. Babel 8 removes the `deprecatedImportAssert` plugin with no replacement, and this package parses the legacy `import x from 'y' assert { type: 'json' }` form on purpose — a codemod that migrates older codebases must not crash on the syntax those codebases still contain. There is a regression test for it ("parses the legacy import-assert syntax"), which Babel 8 fails outright. jscodeshift 17 bundles its own Babel 7 regardless, so staying on 7 also keeps a single parser in the tree rather than two. * **deps:** bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
# [2.0.0](https://github.com/allxsmith/bestax/compare/bestax-migrate@1.0.0...bestax-migrate@2.0.0) (2026-08-01) ### Bug Fixes * **bestax-migrate:** give the kitchen-sink e2e a per-process scratch dir ([2211ea5](2211ea5)) * **bestax-migrate:** reject pnpm's workspace alias form instead of unwrapping it ([de6a900](de6a900)) * **bestax-migrate:** require the pack script to exist, not just be named ([5315efe](5315efe)) * **bestax-migrate:** resolve bare workspace: and guard the catalog: protocol ([7fda9db](7fda9db)), closes [#417](#417) [#412](#412) * **bestax-migrate:** resolve workspace: specifiers before publishing ([782829a](782829a)), closes [bestax-migrate#test](https://github.com/bestax-migrate/issues/test) [#412](#412) * **bestax-migrate:** stop the pack hooks excusing a catalog: devDependency ([4127ead](4127ead)), closes [#412-shaped](#412) * **create-bestax:** concrete inline-style → helper-prop mapping for the never-inline rule ([#357](#357)) ([5f72a90](5f72a90)), closes [#350](#350) [#350](#350) * **docs:** stop cssnano stripping Font Awesome [@font-face](https://github.com/font-face), add [#3](#3) CSS framework blog post ([#401](#401)) ([5d114e1](5d114e1)), closes [#400](#400) ### chore * **deps:** consolidate the dependabot backlog, require Node 22 in both CLIs ([#447](#447)) ([e68148c](e68148c)), closes [#427](#427) [#428](#428) [#431](#431) [#432](#432) [#440](#440) [#393](#393) ### Features * **bestax-migrate:** require Node 22 and take chalk 6 ([#449](#449)) ([4c0e1e2](4c0e1e2)), closes [#447](#447) * **bulma-ui:** ship agent-discovery files in the npm tarball ([#345](#345)) ([4b58739](4b58739)), closes [#344](#344) [#344](#344) [#344](#344) * **create-bestax:** add controlled-Burger Navbar to the landing archetype ([#355](#355)) ([36d4d09](36d4d09)), closes [#348](#348) * **create-bestax:** agent-validated guidance for skills, scaffold CLAUDE.md, and catalog ([#365](#365)) ([6fd06ae](6fd06ae)), closes [#2](#2) * **create-bestax:** require Node 22 and take chalk 6 ([#448](#448)) ([90fced2](90fced2)), closes [#447](#447) * **create-bestax:** scaffold .claude/launch.json with the AI skills opt-in ([#343](#343)) ([189135a](189135a)) * **create-bestax:** set scaffolded index.html title to the project name ([#356](#356)) ([3bfbea3](3bfbea3)), closes [#349](#349) [#349](#349) ### BREAKING CHANGES * **bestax-migrate:** bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. This applies to the runtime the codemod executes on, not to the app being migrated. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * **create-bestax:** create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * **deps:** create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * feat(bestax-migrate): require Node 22 and take chalk 6 chalk 6 drops support for Node below 22. The API surface this package uses is unchanged, so no calling code changes. The version guard in src/index.ts moves ahead of every import and no longer depends on anything: import declarations are hoisted and evaluated before any statement in the module, and chalk 6 itself requires Node >= 22, so a static import would fail to load on exactly the runtimes the guard exists to catch. ./cli.js is now imported dynamically for the same reason. @babel/parser deliberately stays on 7.x. Babel 8 removes the `deprecatedImportAssert` plugin with no replacement, and this package parses the legacy `import x from 'y' assert { type: 'json' }` form on purpose — a codemod that migrates older codebases must not crash on the syntax those codebases still contain. There is a regression test for it ("parses the legacy import-assert syntax"), which Babel 8 fails outright. jscodeshift 17 bundles its own Babel 7 regardless, so staying on 7 also keeps a single parser in the tree rather than two. * **deps:** bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
|
🎉 This PR is included in version 2.0.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
## [5.8.1](https://github.com/allxsmith/bestax/compare/@allxsmith/bestax-bulma@5.8.0...@allxsmith/bestax-bulma@5.8.1) (2026-08-07) ### Bug Fixes * **bestax-migrate:** give the kitchen-sink e2e a per-process scratch dir ([2211ea5](2211ea5)) * **bestax-migrate:** reject pnpm's workspace alias form instead of unwrapping it ([de6a900](de6a900)) * **bestax-migrate:** require the pack script to exist, not just be named ([5315efe](5315efe)) * **bestax-migrate:** resolve bare workspace: and guard the catalog: protocol ([7fda9db](7fda9db)), closes [#417](#417) [#412](#412) * **bestax-migrate:** resolve workspace: specifiers before publishing ([782829a](782829a)), closes [bestax-migrate#test](https://github.com/bestax-migrate/issues/test) [#412](#412) * **bestax-migrate:** stop the pack hooks excusing a catalog: devDependency ([4127ead](4127ead)), closes [#412-shaped](#412) * **bulma-ui:** deprecate CSS-less color values, warn in dev, fix has-text fall-through ([fb111eb](fb111eb)) * **bulma-ui:** fail closed on missing process and scope color guidance to real props ([117c0c0](117c0c0)) * **create-bestax:** concrete inline-style → helper-prop mapping for the never-inline rule ([#357](#357)) ([5f72a90](5f72a90)), closes [#350](#350) [#350](#350) * **create-bestax:** validate at submit in the bestax-form signup example ([0b9518f](0b9518f)) * **create-bestax:** wire labeled controls in the skill showcase story ([af49a16](af49a16)) * **docs:** announce the hero copy, and stop remounting the icons ([98e2cb0](98e2cb0)), closes [#434](#434) * **docs:** correct the frozen-install translation and reject leaked fences ([1883de3](1883de3)) * **docs:** drop dead nomodule ionicons fallback ([82be3e4](82be3e4)) * **docs:** harden PackageManagerTabs and document how to author it ([5b0d3e6](5b0d3e6)), closes [#434](#434) * **docs:** harden the hero copy button and share the tab storage key ([9e16cd7](9e16cd7)) * **docs:** make the hero package-manager switcher a real radiogroup ([aa14ff2](aa14ff2)), closes [#434](#434) * **docs:** stop cssnano stripping Font Awesome [@font-face](https://github.com/font-face), add [#3](#3) CSS framework blog post ([#401](#401)) ([5d114e1](5d114e1)), closes [#400](#400) ### chore * **deps:** consolidate the dependabot backlog, require Node 22 in both CLIs ([#447](#447)) ([e68148c](e68148c)), closes [#427](#427) [#428](#428) [#431](#431) [#432](#432) [#440](#440) [#393](#393) ### Features * **bestax-migrate:** require Node 22 and take chalk 6 ([#449](#449)) ([4c0e1e2](4c0e1e2)), closes [#447](#447) * **create-bestax:** add controlled-Burger Navbar to the landing archetype ([#355](#355)) ([36d4d09](36d4d09)), closes [#348](#348) * **create-bestax:** agent-validated guidance for skills, scaffold CLAUDE.md, and catalog ([#365](#365)) ([6fd06ae](6fd06ae)), closes [#2](#2) * **create-bestax:** require Node 22 and take chalk 6 ([#448](#448)) ([90fced2](90fced2)), closes [#447](#447) * **create-bestax:** set scaffolded index.html title to the project name ([#356](#356)) ([3bfbea3](3bfbea3)), closes [#349](#349) [#349](#349) * **docs:** add package-manager switches to the homepage hero ([374caf8](374caf8)) * **docs:** add PackageManagerTabs and register it globally ([23c9989](23c9989)) * **docs:** show all posts in the blog sidebar ([d29e9c6](d29e9c6)) ### Performance Improvements * **docs:** defer live previews until they scroll into view ([d6bf87b](d6bf87b)) * **docs:** share one parsed stylesheet set across every live preview ([feb993a](feb993a)) ### BREAKING CHANGES * **bestax-migrate:** bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. This applies to the runtime the codemod executes on, not to the app being migrated. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * **create-bestax:** create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * **deps:** create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * feat(bestax-migrate): require Node 22 and take chalk 6 chalk 6 drops support for Node below 22. The API surface this package uses is unchanged, so no calling code changes. The version guard in src/index.ts moves ahead of every import and no longer depends on anything: import declarations are hoisted and evaluated before any statement in the module, and chalk 6 itself requires Node >= 22, so a static import would fail to load on exactly the runtimes the guard exists to catch. ./cli.js is now imported dynamically for the same reason. @babel/parser deliberately stays on 7.x. Babel 8 removes the `deprecatedImportAssert` plugin with no replacement, and this package parses the legacy `import x from 'y' assert { type: 'json' }` form on purpose — a codemod that migrates older codebases must not crash on the syntax those codebases still contain. There is a regression test for it ("parses the legacy import-assert syntax"), which Babel 8 fails outright. jscodeshift 17 bundles its own Babel 7 regardless, so staying on 7 also keeps a single parser in the tree rather than two. * **deps:** bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
|
🎉 This PR is included in version 5.8.1 🎉 The release is available on: Your semantic-release bot 📦🚀 |
# 1.0.0 (2026-08-12) * feat(bulma-ui)!: remove bestax-bulma-prefixed CSS variant ([94baa34](94baa34)) * feat(create-bestax)!: require Node.js 18+ and align with bestax-bulma v2 ([#118](#118)) ([b22f183](b22f183)) ### Bug Fixes * add comprehensive rules to prevent bulma-ui versioning on non-bulma-ui commits ([#122](#122)) ([525ccfa](525ccfa)), closes [#119](#119) * **bestax-mcp:** derive the near-miss guidance from the skill, and only when it helps ([1141cca](1141cca)) * **bestax-mcp:** do not split a helper-prop table cell on an escaped pipe ([bdac820](bdac820)) * **bestax-mcp:** lead get_helper_props with the inline-style prohibition ([ffc627a](ffc627a)) * **bestax-mcp:** make list_components point at the next step ([8ddb2fd](8ddb2fd)) * **bestax-mcp:** make tests and cached builds work from a clean checkout ([6e63820](6e63820)), closes [bestax-mcp#build](https://github.com/bestax-mcp/issues/build) * **bestax-mcp:** name list_components as the entry point, not search_bestax ([206380b](206380b)) * **bestax-mcp:** name the three near-miss components in the list_components footer ([1c7af67](1c7af67)) * **bestax-mcp:** route helper questions to the tool that answers them ([cd6ce12](cd6ce12)) * **bestax-mcp:** validate the one input that is not ours, and bound the rest ([3e1adc9](3e1adc9)) * **bestax-migrate:** give the kitchen-sink e2e a per-process scratch dir ([2211ea5](2211ea5)) * **bestax-migrate:** reject pnpm's workspace alias form instead of unwrapping it ([de6a900](de6a900)) * **bestax-migrate:** require the pack script to exist, not just be named ([5315efe](5315efe)) * **bestax-migrate:** resolve bare workspace: and guard the catalog: protocol ([7fda9db](7fda9db)), closes [#417](#417) [#412](#412) * **bestax-migrate:** resolve workspace: specifiers before publishing ([782829a](782829a)), closes [bestax-migrate#test](https://github.com/bestax-migrate/issues/test) [#412](#412) * **bestax-migrate:** stop the pack hooks excusing a catalog: devDependency ([4127ead](4127ead)), closes [#412-shaped](#412) * **bulma-ui:** a11y + case-insensitive Taginput matching from PR review ([d576829](d576829)) * **bulma-ui:** accept router props like `to` on Navbar.Item without casts ([#311](#311)) ([b78856b](b78856b)), closes [#306](#306) * **bulma-ui:** Add build step to publish in ci.yml ([e3707fc](e3707fc)) * **bulma-ui:** add fontawesome-free as explicit devDependency ([a4a5389](a4a5389)) * **bulma-ui:** add missing exports ([0d16633](0d16633)) * **bulma-ui:** Add Skeleton to exports ([e481599](e481599)) * **bulma-ui:** another attempt to fix semantic release builds with ci.yml ([cc3a3e2](cc3a3e2)) * **bulma-ui:** another attempt to fix semantic release builds with ci.yml ([314bc39](314bc39)) * **bulma-ui:** another attempt to fix semantic release builds with ci.yml ([c930693](c930693)) * **bulma-ui:** associate Autocomplete and Taginput labels with their inner inputs ([7ae37d4](7ae37d4)) * **bulma-ui:** associate Autocomplete and Taginput labels with their inner inputs ([384bd38](384bd38)) * **bulma-ui:** associate the form label prop with its control via a generated id ([e6686af](e6686af)) * **bulma-ui:** complete domain migration and fix semantic-release configuration ([#64](#64)) ([f4cd71d](f4cd71d)) * **bulma-ui:** correct blog post examples and add Modal compound components ([#81](#81)) ([559c2e3](559c2e3)) * **bulma-ui:** correct NPM_TOKEN env variable in ci.yml ([94b48b4](94b48b4)) * **bulma-ui:** cover horizontal-layout group label association ([ef3ca9f](ef3ca9f)) * **bulma-ui:** deprecate CSS-less color values, warn in dev, fix has-text fall-through ([fb111eb](fb111eb)) * **bulma-ui:** fail closed on missing process and scope color guidance to real props ([117c0c0](117c0c0)) * **bulma-ui:** Fix release.config.js to include package-lock.json ([390da59](390da59)) * **bulma-ui:** fix standalone Badge pointer-events, pulse halo, and falsy content ([#295](#295)) ([a9db031](a9db031)), closes [#264](#264) * **bulma-ui:** full classPrefix support across layout/grid + prefix utils ([4ce0b53](4ce0b53)) * **bulma-ui:** honor the htmlFor opt-out in the convenience hook and tighten the association docs ([92aa622](92aa622)) * **bulma-ui:** improve npm package discoverability with optimized keywords and badges ([#72](#72)) ([8c7a696](8c7a696)) * **bulma-ui:** Initial semantic release changes ([b78d785](b78d785)) * **bulma-ui:** keep Taginput's fallback name unless the label targets its input ([73cec33](73cec33)) * **bulma-ui:** keep Taginput's fallback name unless the label targets its input ([ca5996a](ca5996a)) * **bulma-ui:** migrate domain from bestax.cc to bestax.io ([#64](#64)) ([4870b1e](4870b1e)) * **bulma-ui:** migrate ionicons to v8 to unblock publish and Storybook ([927a55b](927a55b)), closes [#142](#142) * **bulma-ui:** name Rate, Checkboxes, and Radios groups from their labels via aria-labelledby ([dce0ee7](dce0ee7)) * **bulma-ui:** name Rate, Checkboxes, and Radios groups from their labels via aria-labelledby ([#497](#497)) ([5c4222e](5c4222e)) * **bulma-ui:** name the three near-miss components in AGENTS.md ([c63f491](c63f491)), closes [#344](#344) * **bulma-ui:** never let labelProps.htmlFor wire a group label to a control ([3b3aaaf](3b3aaaf)) * **bulma-ui:** publish rewritten README to npm ([9810081](9810081)) * **bulma-ui:** publish with npm provenance attestation ([172da62](172da62)), closes [#180](#180) * **bulma-ui:** reference llms docs from README and package.json ([#198](#198)) ([db8aab3](db8aab3)) * **bulma-ui:** reject predicate-blocked values during manual entry ([a8f6e28](a8f6e28)) * **bulma-ui:** resolve flex item properties and Card compound component issues ([#55](#55)) ([e774da3](e774da3)) * **bulma-ui:** resolve flex item properties and Card compound component issues ([#55](#55)) ([7641a53](7641a53)) * **bulma-ui:** resolve react-hooks v7 and [@eslint-react](https://github.com/eslint-react) findings ([14caaaf](14caaaf)) * **bulma-ui:** resolve security vulnerabilities and update dependencies ([#128](#128)) ([112f6e4](112f6e4)), closes [#127](#127) * **bulma-ui:** restrict semantic-release to bulma-ui scoped commits only ([2d67bf9](2d67bf9)), closes [#62](#62) * **bulma-ui:** retry failed Avatar src, flatten Fragment children in Avatars, RTL-safe overlap ([#297](#297)) ([c00b9db](c00b9db)) * **bulma-ui:** route every hardcoded class through the prefix helpers; add classPrefix sweep test ([#301](#301)) ([a50b134](a50b134)), closes [#286](#286) * **bulma-ui:** setup gpg signing with semantic-release ([3e24722](3e24722)) * **bulma-ui:** strip redundant library prefix from Icon name ([#242](#242)) ([dbe3622](dbe3622)), closes [#189](#189) * **bulma-ui:** trigger release to publish via OIDC trusted publishing ([e2d09c5](e2d09c5)) * **bulma-ui:** update bundle size claims to accurate 21KB gzipped ([#66](#66)) ([6e381bd](6e381bd)) * **bulma-ui:** update package-lock.json ([853d585](853d585)) * **bulma-ui:** update package.json for better seo, exports, types, engines, funding, etc ([98cbc56](98cbc56)) * **bulma-ui:** use createRequire for ESM compatibility in Storybook 10 ([#130](#130)) ([b27e60e](b27e60e)), closes [#129](#129) * **ci:** collect screenshots as artifacts and commit in single batch to avoid conflicts ([27b259d](27b259d)) * **ci:** ensure npm install uses fresh downloads with --prefer-online ([1f2e15d](1f2e15d)) * **ci:** properly extract base path for recursive file search ([e0330ff](e0330ff)) * **ci:** use find command instead of glob module in verified-commit action ([0e2d159](0e2d159)) * **ci:** use npm ci for scaffolded app dependencies ([35652c8](35652c8)) * **create-bestax:** concrete inline-style → helper-prop mapping for the never-inline rule ([#357](#357)) ([5f72a90](5f72a90)), closes [#350](#350) [#350](#350) * **create-bestax:** correct browser title to prioritize Bestax branding ([#106](#106)) ([23aa535](23aa535)), closes [#105](#105) * **create-bestax:** correct template path resolution from ../../ to ../ ([65b4493](65b4493)), closes [#78](#78) * **create-bestax:** dark-mode contrast rules in theming/layout skills and docs ([#303](#303)) ([490bf21](490bf21)), closes [#194](#194) [#195](#195) * **create-bestax:** exclude templates directory from linting and typecheck ([18fec0b](18fec0b)) * **create-bestax:** fail fast with guidance instead of hanging when stdin is not a TTY ([#293](#293)) ([46a172d](46a172d)), closes [#192](#192) * **create-bestax:** move templates into package directory and update docs ([195bf01](195bf01)), closes [#78](#78) * **create-bestax:** point scaffolded CLAUDE.md at llms docs; document skills ([#198](#198)) ([b2e0514](b2e0514)) * **create-bestax:** publish with npm provenance attestation ([21ffe8f](21ffe8f)), closes [#180](#180) * **create-bestax:** put the near-miss guidance where every session sees it ([6db49f3](6db49f3)) * **create-bestax:** read version from package.json instead of hardcoded value ([#109](#109)) ([8605699](8605699)) * **create-bestax:** refresh README and bump scaffolded bestax-bulma to ^5 ([4e19e86](4e19e86)) * **create-bestax:** reject dot-only project names, pin icon versions, bundle bestax-icons skill ([#310](#310)) ([ddff8e5](ddff8e5)) * **create-bestax:** scaffold @allxsmith/bestax-bulma ^4.0.0 ([1d3b802](1d3b802)) * **create-bestax:** scaffold bundled bestax CSS flavors, not stock Bulma ([43621dc](43621dc)) * **create-bestax:** ship improved bundled skills + component catalog ([#199](#199)) ([a1515c2](a1515c2)) * **create-bestax:** shrink the near-miss block and pin the copies together ([d582da5](d582da5)) * **create-bestax:** skills-sync conformance gate + theming skill reference backfill ([#326](#326)) ([9584133](9584133)), closes [#285](#285) * **create-bestax:** stop the skills teaching a Theme call that does not compile ([2935bb2](2935bb2)) * **create-bestax:** synchronize version with bestax-bulma to 2.4.0 ([623ee79](623ee79)), closes [#96](#96) * **create-bestax:** teach the skills the three components Bulma hides ([22dcff7](22dcff7)) * **create-bestax:** update template dependency to ^2.4.0 ([200971d](200971d)) * **create-bestax:** use scenario-specific screenshot directories to prevent overwrites ([#108](#108)) ([c675957](c675957)), closes [#107](#107) * **create-bestax:** validate at submit in the bestax-form signup example ([0b9518f](0b9518f)) * **create-bestax:** wire labeled controls in the skill showcase story ([af49a16](af49a16)) * **docs:** announce the hero copy, and stop remounting the icons ([98e2cb0](98e2cb0)), closes [#434](#434) * **docs:** correct Content Signals syntax in robots.txt ([#134](#134)) ([85dd9de](85dd9de)) * **docs:** correct the frozen-install translation and reject leaked fences ([1883de3](1883de3)) * **docs:** drop dead nomodule ionicons fallback ([82be3e4](82be3e4)) * **docs:** emit per-page markdown so llms.txt links resolve ([#200](#200)) ([7877083](7877083)) * **docs:** escape apostrophe in QuickStart notification text ([25d6d72](25d6d72)) * **docs:** generate llms.txt so the advertised homepage link resolves ([9fae464](9fae464)), closes [#177](#177) * **docs:** give every batch run its own port — slot reuse was corrupting runs ([6ef1755](6ef1755)) * **docs:** harden PackageManagerTabs and document how to author it ([5b0d3e6](5b0d3e6)), closes [#434](#434) * **docs:** harden the hero copy button and share the tab storage key ([9e16cd7](9e16cd7)) * **docs:** improve homepage hero layout and button spacing ([5f7a5a7](5f7a5a7)) * **docs:** make the eval batch resumable after a container restart ([d56229e](d56229e)) * **docs:** make the hero package-manager switcher a real radiogroup ([aa14ff2](aa14ff2)), closes [#434](#434) * **docs:** move robots.txt to correct deployment location ([#90](#90)) ([1e2aeee](1e2aeee)) * **docs:** rebrand and reorganize Storybook ([#83](#83)) ([dfb9937](dfb9937)) * **docs:** remove Google Analytics and add robots.txt ([94776f7](94776f7)) * **docs:** stop cssnano stripping Font Awesome [@font-face](https://github.com/font-face), add [#3](#3) CSS framework blog post ([#401](#401)) ([5d114e1](5d114e1)), closes [#400](#400) * **docs:** update Storybook logo path to /img/logo.svg for deployed site ([bf59758](bf59758)) * **e2e:** correct notification CSS selectors to use contains instead of ends-with ([182acc1](182acc1)) * implement independent package versioning strategy ([#111](#111)) ([7819c73](7819c73)), closes [#110](#110) * prevent bulma-ui from versioning on create-bestax commits ([#120](#120)) ([4dfaf9c](4dfaf9c)), closes [#119](#119) * resolve React Hooks violations and ESLint configuration issues ([32d2931](32d2931)) * upgrade Turbo, Storybook, and Docusaurus dependencies ([5b4ebdd](5b4ebdd)), closes [#98](#98) ### chore * **deps:** consolidate the dependabot backlog, require Node 22 in both CLIs ([#447](#447)) ([e68148c](e68148c)), closes [#427](#427) [#428](#428) [#431](#431) [#432](#432) [#440](#440) [#393](#393) ### Documentation * fix stale versioning and coverage docs; drop CLAUDE.md stale-docs flags ([71c4583](71c4583)) ### Features * add theme system and config provider with comprehensive test coverage ([f3ca7f0](f3ca7f0)) * **bestax-mcp:** serve component docs, props, examples and skills over MCP ([c2abcc4](c2abcc4)) * **bestax-migrate:** react-bulma-components → bestax-bulma codemod CLI, skill, and docs ([#333](#333)) ([e04a12b](e04a12b)), closes [#1e6b99](https://github.com/allxsmith/bestax/issues/1e6b99) * **bestax-migrate:** require Node 22 and take chalk 6 ([#449](#449)) ([4c0e1e2](4c0e1e2)), closes [#447](#447) * **bulma-ui:** add Avatar, Avatars, and Badge components ([#257](#257)) ([0817018](0817018)), closes [#256](#256) * **bulma-ui:** add colorMode dark-mode prop to Theme ([4acc41e](4acc41e)), closes [#174](#174) * **bulma-ui:** add consistent gap prop to Columns, aliasing gapSize ([#300](#300)) ([6c36455](6c36455)), closes [#282](#282) * **bulma-ui:** add cursor helper, closeDelay prop, and polish Tooltip stories ([37945b5](37945b5)) * **bulma-ui:** add extra components, form elements, and SCSS styles ([59daf28](59daf28)) * **bulma-ui:** add HTML element wrapper components ([#135](#135)) ([#136](#136)) ([20fb16d](20fb16d)) * **bulma-ui:** add manual-entry stories for format, bounds, and blocked-value variations ([e93d51c](e93d51c)) * **bulma-ui:** add Reveal component for scroll-triggered animations ([#255](#255)) ([a89c574](a89c574)) * **bulma-ui:** Add skeletons ([6c46e4b](6c46e4b)) * **bulma-ui:** add themed Checkbox/Radio, convenience Field components, and Autocomplete cleanup ([3c57a5a](3c57a5a)) * **bulma-ui:** add typing-first story variants for all picker property variations ([078433f](078433f)) * **bulma-ui:** associate Field's label with a composed base control ([219f631](219f631)) * **bulma-ui:** avatar/badge a11y batch — decorative alt, accessible names, live region, button type, surplus i18n, focus ring ([#298](#298)) ([508477f](508477f)), closes [#266](#266) [#266](#266) * **bulma-ui:** change the default primary color to [#1](#1 ([8872620](8872620)), closes [#1e6b99](https://github.com/allxsmith/bestax/issues/1e6b99) [#1e6b99](https://github.com/allxsmith/bestax/issues/1e6b99) * **bulma-ui:** compound (dot-notation) sub-components for all parent/child families via shared withSubComponents helper ([#331](#331)) ([07516c5](07516c5)) * **bulma-ui:** dim and blur the calendar behind the Datetimepicker time wheels ([3d90619](3d90619)) * **bulma-ui:** finalize the 3.0 component set ([87ccc0e](87ccc0e)) * **bulma-ui:** make Button and Link as prop polymorphic (React.ElementType) ([#238](#238)) ([ce90304](ce90304)), closes [#188](#188) * **bulma-ui:** require React 18 as the minimum supported version ([c7251b0](c7251b0)) * **bulma-ui:** ship agent-discovery files in the npm tarball ([#345](#345)) ([4b58739](4b58739)), closes [#344](#344) [#344](#344) [#344](#344) * **ci:** add verified-commit action for GPG-signed commits ([d078dfa](d078dfa)) * **create-bestax:** add bestax-optimize skill for shrinking built CSS ([#329](#329)) ([f597b9f](f597b9f)) * **create-bestax:** add CLI tool with Vite templates and automated publishing ([9748c3d](9748c3d)) * **create-bestax:** add controlled-Burger Navbar to the landing archetype ([#355](#355)) ([36d4d09](36d4d09)), closes [#348](#348) * **create-bestax:** add cross-platform emoji support with figures ([#103](#103)) ([15567d9](15567d9)) * **create-bestax:** add README with templates location note ([8ddc73d](8ddc73d)) * **create-bestax:** add visual regression testing and synchronized versioning ([17e1e22](17e1e22)), closes [#94](#94) * **create-bestax:** agent-validated guidance for skills, scaffold CLAUDE.md, and catalog ([#365](#365)) ([6fd06ae](6fd06ae)), closes [#2](#2) * **create-bestax:** bestax-icons skill — teach agents the icon system ([#302](#302)) ([61c8ef2](61c8ef2)), closes [#287](#287) * **create-bestax:** improve favicon visibility and add distinct branding ([621590d](621590d)), closes [#100](#100) * **create-bestax:** modernize templates (Vite 8, ESLint 10, TS 6) + add working lint config ([4537629](4537629)), closes [#167](#167) * **create-bestax:** offer to install the bestax AI skills when scaffolding ([625b7bf](625b7bf)), closes [#174](#174) * **create-bestax:** require Node 22 and take chalk 6 ([#448](#448)) ([90fced2](90fced2)), closes [#447](#447) * **create-bestax:** scaffold .claude/launch.json with the AI skills opt-in ([#343](#343)) ([189135a](189135a)) * **create-bestax:** scaffold-aware CLAUDE.md with setup facts and house style ([#271](#271)) ([c1681b0](c1681b0)) * **create-bestax:** set scaffolded index.html title to the project name ([#356](#356)) ([3bfbea3](3bfbea3)), closes [#349](#349) [#349](#349) * **docs:** add Google Analytics tracking for usage insights ([#68](#68)) ([90ab951](90ab951)) * **docs:** add package-manager switches to the homepage hero ([374caf8](374caf8)) * **docs:** add PackageManagerTabs and register it globally ([23c9989](23c9989)) * **docs:** add pronunciation guide and dark mode support ([#58](#58)) ([48a8916](48a8916)) * **docs:** aggregate-runs.mjs — distribution stats across a runs directory ([5de9c07](5de9c07)) * **docs:** batch runner for the eval harness, with the concurrency fixes it needed ([f8e268c](f8e268c)) * **docs:** migrate from GitHub Pages to Cloudflare Pages ([#132](#132)) ([2154672](2154672)), closes [#131](#131) * **docs:** rubric v2 and a brief that demands the components beyond Bulma ([e6047be](e6047be)) * **docs:** show all posts in the blog sidebar ([d29e9c6](d29e9c6)) * **form:** add Datepicker, Timepicker, and Datetimepicker components ([c6684e6](c6684e6)) ### Performance Improvements * **bestax-mcp:** stop get_helper_props costing half the session ([b865651](b865651)) * **docs:** defer live previews until they scroll into view ([d6bf87b](d6bf87b)) * **docs:** share one parsed stylesheet set across every live preview ([feb993a](feb993a)) ### BREAKING CHANGES * **bestax-migrate:** bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. This applies to the runtime the codemod executes on, not to the app being migrated. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * **create-bestax:** create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * **deps:** create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * feat(bestax-migrate): require Node 22 and take chalk 6 chalk 6 drops support for Node below 22. The API surface this package uses is unchanged, so no calling code changes. The version guard in src/index.ts moves ahead of every import and no longer depends on anything: import declarations are hoisted and evaluated before any statement in the module, and chalk 6 itself requires Node >= 22, so a static import would fail to load on exactly the runtimes the guard exists to catch. ./cli.js is now imported dynamically for the same reason. @babel/parser deliberately stays on 7.x. Babel 8 removes the `deprecatedImportAssert` plugin with no replacement, and this package parses the legacy `import x from 'y' assert { type: 'json' }` form on purpose — a codemod that migrates older codebases must not crash on the syntax those codebases still contain. There is a regression test for it ("parses the legacy import-assert syntax"), which Babel 8 fails outright. jscodeshift 17 bundles its own Babel 7 regardless, so staying on 7 also keeps a single parser in the tree rather than two. * **deps:** bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * footer requirement, and the commitlint scope rule - CONTRIBUTING.md: replace the type-less commit example with a commitlint-valid conventional format (verified against commitlint); correct all four coverage mentions to the real jest thresholds (bulma-ui 99%, create-bestax 95%/78% branches); fix the npm package name (@allxsmith/bestax-bulma, plus create-bestax) and link VERSIONING.md - CLAUDE.md: remove the stale-docs warning and asides now that the underlying docs are correct; point at VERSIONING.md again Closes #206. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0131uD6QKmAij7Byk3SByyLh * the @allxsmith/bestax-bulma/versions/bestax-bulma-prefixed.css export is removed. Use versions/bestax-prefixed.css with classPrefix="bestax-". * **bulma-ui:** React 16 and 17 are no longer supported; the minimum supported React version is now 18. * **bulma-ui:** Snackbar has been removed and merged into Toast; use Toast with its positioning and queue props instead. * **bulma-ui:** form controls now auto-wrap in Field/Control, and Checkbox and Radio ship new themed visuals. See the 2.x -> 3.x migration guide. * This version requires Node.js 18.0.0 or higher. The CLI now enforces this requirement and will exit with an error message if running on older Node.js versions. This aligns create-bestax with the bestax-bulma v2.x ecosystem. * fix(create-bestax): correct Prettier formatting in index.ts * None - all changes are additive and backward compatible
|
🎉 This PR is included in version 1.0.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
Pull Request
Description
Consolidated application of dependabot's two grouped npm update PRs, plus the two
pnpm-workspace.yamlchanges neither of them could make. One reviewable change instead of two conflicting lockfile PRs.@allxsmith/bestax-bulma)create-bestax)@allxsmith/bestax-docs)pnpm-workspace.yamlFrom #388 (production-dependencies group):
From #390 (dev-dependencies group):
pnpm-workspace.yaml:3.9.4→3.9.6— chore(deps-dev): bump the dev-dependencies group across 1 directory with 12 updates #390 raised the manifest floors to^3.9.6, but the exact-pin override would have silently kept 3.9.4 installed, making the manifests lie. Bumped together so the workspace keeps a single, honest formatter version. (prettier 3.9.6 produced zero formatting churn —format:checkpasses untouched.)brace-expansionfromminimumReleaseAgeExclude— its own comment scheduled removal after 2026-07-26 (cooldown elapsed). Thebrace-expansion: '>=5.0.8'security override stays.Related Issue(s)
Refs #388, #390 — supersedes both (they'll be closed once this merges).
Refs #170 — obsolete (edits a
docs/package-lock.jsonthat doesn't exist on main; dependabot itself requested closure).Refs #322 — TS 7 is blocked by toolchain peers (typescript-eslint
<6.1.0, ts-jest<7); handled separately with a tracking issue.Type of Change
Checklist
No component/API changes → no docs, stories, or skill-catalog updates owed (
gen:catalog:checkandcheck:conformanceboth pass).Additional Context
Local verification (Node 22, pnpm 11.9.0):
pnpm all(build, typecheck, test+coverage, bundle:stats, lint, format:check, storybook build) — 20/20 tasks green;gen:catalog:checkclean;check:conformance✓;pnpm audit --audit-level=highpasses (4 pre-existing low/moderate findings, unchanged from main). All bumped versions clear the 3-dayminimumReleaseAgecooldown (publish dates 2026-07-08…07-21). Only the three allowlisted native builders ran during install.chore:commit → no package release; the raised floors ship with each package's next regular release.🤖 Generated with Claude Code
https://claude.ai/code/session_012szNNjysHff51G26SSTWeA
Generated by Claude Code