Skip to content

chore(deps): consolidate the dependabot backlog, require Node 22 in both CLIs - #447

Merged
allxsmith merged 3 commits into
mainfrom
chore/consolidate-dependency-updates
Aug 1, 2026
Merged

allxsmith merged 3 commits into
mainfrom
chore/consolidate-dependency-updates

Conversation

@allxsmith

Copy link
Copy Markdown
Owner

Pull Request

⚠️ Merge with a merge commit, not squash

The three commits carry three different scopes. semantic-release keys releases off the scope of
each commit, so squashing collapses them into one and the second package silently never releases.

Description

Consolidates the Dependabot backlog into one PR so the shared pnpm-lock.yaml is regenerated
once, instead of merging seven lockfile-touching PRs serially with a Dependabot rebase between
each. Same approach as #393 for #388/#390.

Supersedes and closes #427, #428, #429, #431, #432, #440. #430 is not taken — see below.

  • bulma-ui (@allxsmith/bestax-bulma) — devDependencies only, no release
  • create-bestax (create-bestax)
  • docs (@allxsmith/bestax-docs)
  • Other (please specify): bestax-migrate, root tooling

Related Issue(s)

Closes #427
Closes #428
Closes #429
Closes #431
Closes #432
Closes #440

Refs #430

Type of Change

  • Bug fix
  • Build tooling
  • Other: dependency maintenance, two breaking Node-floor bumps

Releases this produces

Verified by running the real releaseRules from each release.config.js against the actual
commits on this branch:

package result
@allxsmith/bestax-bulma no release
create-bestax major → 4.0.0
bestax-migrate major → 2.0.0

bestax-migrate@2.0.0 also carries the four pending fix(bestax-migrate) commits from
#412/#417 that have been waiting on the publishing outage.

Merge #446 first. This PR triggers real releases, so it needs the GitHub App token fix
already on main, or the release push is rejected with GH006 exactly as before.

Commit 1 — chore(deps), no release

#427, #428, #431, #432 and the 16 clean bumps from #440, plus two new pnpm-workspace.yaml
overrides.

Why #440 was red. One line: docusaurus-plugin-llms ^0.4.0 → ^0.5.1. From 0.5.0 that
plugin pins its own dependencies exactly ("minimatch": "9.0.3" rather than "^9.0.3"), so
the range no longer floats to a patched release the way it did on 0.4.x. That dragged
minimatch back from 9.0.9 to 9.0.3 — inside three high ReDoS advisories
(GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj, GHSA-23c5-xmqv-rm74) — and yaml from 2.9.0 to
2.8.1 (GHSA-48c2-rrv3-qjmp). That failed both pnpm audit --audit-level=high and
Dependency Review, which rejected the same three GHSAs via fail-on-severity: high.

Two scoped overrides restore the patched versions, matching how serialize-javascript,
sharp, postcss and brace-expansion are already handled. Scoped to the affected major so
the minimatch 10.x elsewhere in the tree is untouched. pnpm audit --audit-level=high is
back to main's exact baseline: 1 low, 3 moderate, 0 high.

@semantic-release/changelog 7 and @semantic-release/git 11 are the same CJS→ESM wave and
are taken together. Every option the release configs actually pass (changelogFile, assets,
message) is unchanged, and both declare a semantic-release peer of >=20.1.0, satisfied by
^25.0.8. Verified by a --dry-run that loads every plugin successfully.

@testing-library/jest-dom 7 removes no matchers; the new required peer
@testing-library/dom is already resolved at 10.4.1 via @testing-library/react.

Commits 2 and 3 — Node 22 floors (breaking)

chalk 6 drops Node < 22. The API surface both CLIs use is unchanged — every call site is a
default import using .red/.yellow/.green — so no calling code changes. Raising
engines.node brings the manifests in line with what the docs already claim:
docs/docs/guides/getting-started/installation.md has said "Node.js: 22.0.0 or higher" all
along. Node 18 and 20 are both past end-of-life.

Both version guards moved ahead of every import and no longer use chalk. Import declarations
are hoisted and evaluated before any statement in the module, and chalk 6 itself requires
Node ≥ 22 — so a static import would fail to load on exactly the runtimes the guard exists to
catch, replacing a clear upgrade message with an opaque loader error. ./cli.js is now
imported dynamically for the same reason.

Why #430 (@babel/parser 7 → 8) is not included

Babel 8 removes the deprecatedImportAssert plugin with no replacement, so
import data from './data.json' assert { type: 'json' } no longer parses. bestax-migrate
supports that syntax deliberately — runner.ts says so, and there is a dedicated regression
test, "parses the legacy import-assert syntax", which also asserts the assertion survives
into the output. Babel 8 fails it with SyntaxError: Missing semicolon.

A codemod that migrates older codebases must not crash on the syntax those codebases still
contain, so this is a real capability loss rather than a config detail. Babel 8 additionally
removes the pipelineOperator minimal proposal, which throws at runtime rather than being
ignored. jscodeshift 17 bundles its own Babel 7 regardless, so staying on 7 also keeps a single
parser in the tree instead of two. Recommend closing #430.

Checklist

  • My code follows the project style guidelines
  • I have performed a self-review of my code
  • I have added/updated documentation as needed
  • All new and existing tests passed
  • Any relevant dependencies are updated

Verification run locally

  • pnpm all — clean (build, typecheck, test, coverage, bundle:stats, lint, format:check, storybook)
  • pnpm audit --audit-level=high — 0 high
  • pnpm run check:conformance — 0 violations; gen:catalog:check clean; check:urls all 6 resolve
  • pnpm --filter bestax-migrate validate:corpus — 0 crashes, 31/32 transformed, no unknown-component TODOs
  • Both CLIs smoke-tested from dist/ after the entry-point restructure

Additional Context

Test and Preview Deployment was red on all eight Dependabot PRs and is unrelated to any of
them: GitHub scopes Dependabot pull_request runs to the separate Dependabot secrets store,
so CLOUDFLARE_API_TOKEN is empty and wrangler aborts. Across the last 60 runs of that
workflow, every dependabot[bot] run failed and every human run passed. It is not a required
check. Worth silencing separately with an if: github.actor != 'dependabot[bot]' guard on the
test-deploy job.

…d yaml

Consolidates #427, #428, #431, #432 and #440 into one PR so the shared
pnpm-lock.yaml is regenerated once instead of forcing dependabot to rebase
six branches serially. Same approach as #393 for #388/#390.

docusaurus-plugin-llms 0.5.x pins its own dependencies exactly rather than by
range, which dragged minimatch back to 9.0.3 (three high ReDoS advisories) and
yaml to 2.8.1, failing both `pnpm audit --audit-level=high` and Dependency
Review on #440. Two scoped overrides restore the patched versions; the rest of
that group was already clean.

@semantic-release/changelog 7 and @semantic-release/git 11 are the same
CJS-to-ESM wave and are taken together. Every option the release configs
actually pass (changelogFile, assets, message) is unchanged, and both declare
a semantic-release peer of >=20.1.0, satisfied by ^25.0.8.

@testing-library/jest-dom 7 removes no matchers; the new required peer
@testing-library/dom is already resolved at 10.4.1 via @testing-library/react.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
chalk 6 drops support for Node below 22. The API surface this package uses is
unchanged — every call site is a default import using .red/.yellow/.green and
friends — so no calling code changes.

Raising engines.node to >=22 brings the manifest in line with what the docs
have claimed all along: the installation guide already states "Node.js: 22.0.0
or higher (the current LTS baseline)".

The version guard in src/index.ts moves ahead of every import and stops using
chalk. Import declarations are hoisted and evaluated before any statement in
the module, and chalk 6 itself requires Node >= 22 — so a static import would
fail to load on exactly the runtimes the guard exists to catch, replacing a
clear message with an opaque loader error. ./cli.js is now imported
dynamically for the same reason.

BREAKING CHANGE: create-bestax now requires Node.js 22 or newer. Node 18 and 20
are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
chalk 6 drops support for Node below 22. The API surface this package uses is
unchanged, so no calling code changes.

The version guard in src/index.ts moves ahead of every import and no longer
depends on anything: import declarations are hoisted and evaluated before any
statement in the module, and chalk 6 itself requires Node >= 22, so a static
import would fail to load on exactly the runtimes the guard exists to catch.
./cli.js is now imported dynamically for the same reason.

@babel/parser deliberately stays on 7.x. Babel 8 removes the
`deprecatedImportAssert` plugin with no replacement, and this package parses
the legacy `import x from 'y' assert { type: 'json' }` form on purpose — a
codemod that migrates older codebases must not crash on the syntax those
codebases still contain. There is a regression test for it ("parses the legacy
import-assert syntax"), which Babel 8 fails outright. jscodeshift 17 bundles
its own Babel 7 regardless, so staying on 7 also keeps a single parser in the
tree rather than two.

BREAKING CHANGE: bestax-migrate now requires Node.js 22 or newer. Node 18 and
20 are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
@coderabbitai

coderabbitai Bot commented Aug 1, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@allxsmith, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 44 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: f6378506-eab2-4a15-8efd-d02610d743c7

📥 Commits

Reviewing files that changed from the base of the PR and between f2daf68 and d2d4ec4.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml, !pnpm-lock.yaml
📒 Files selected for processing (8)
  • bestax-migrate/package.json
  • bestax-migrate/src/index.ts
  • bulma-ui/package.json
  • create-bestax/package.json
  • create-bestax/src/index.ts
  • docs/package.json
  • package.json
  • pnpm-workspace.yaml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @storybook/addon-onboarding is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: bulma-ui/package.json → npm/@storybook/addon-onboarding@10.5.5

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@storybook/addon-onboarding@10.5.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@github-actions

github-actions Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://c3180339.bestax.pages.dev

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Consolidates a backlog of Dependabot dependency bumps into a single lockfile regeneration, and raises the Node.js minimum version to 22 for both CLI packages (create-bestax and bestax-migrate) to support chalk@6 and ensure the Node version guards execute before any static imports.

Changes:

  • Added scoped pnpm overrides to keep patched minimatch and yaml versions when upgrading docusaurus-plugin-llms.
  • Updated dependency versions across the root, docs, and bulma-ui workspaces (dev tooling and docs deps).
  • Updated both CLIs to require Node 22 (engines) and restructured their entrypoints to run the version guard before dynamically importing the rest of the CLI.

Reviewed changes

Copilot reviewed 8 out of 9 changed files in this pull request and generated no comments.

Show a summary per file
File Description
pnpm-workspace.yaml Adds scoped overrides to prevent vulnerable transitive downgrades (minimatch/yaml) introduced by docusaurus-plugin-llms.
package.json Updates root dev-tooling dependencies (eslint, semantic-release plugins, turbo, wrangler, etc.).
docs/package.json Updates docs deps including material-symbols and docusaurus-plugin-llms.
bulma-ui/package.json Updates bulma-ui devDependencies (storybook suite, jest-dom, playwright, rollup, sass, eslint).
create-bestax/src/index.ts Moves Node version guard ahead of any static imports and uses dynamic import + top-level await for the CLI load.
create-bestax/package.json Bumps CLI dependencies (chalk/fs-extra/etc.) and raises engines.node to >=22.
bestax-migrate/src/index.ts Moves Node version guard ahead of any static imports and uses dynamic import + top-level await for the CLI load.
bestax-migrate/package.json Bumps chalk and raises engines.node to >=22.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Deep review — 0 blocking · 1 advisory

# Severity Area Finding Location
1 🔵 Advisory Robustness This PR triggers two live major releases (create-bestax@4, bestax-migrate@2) and simultaneously bumps the release-path plugins @semantic-release/changelog 6→7 and @semantic-release/git 10→11; that combination could not be exercised here (no network / no real --dry-run). Relies on the author's stated dry-run. package.json:34-35

Overall: The change is sound. The dependency bumps are mechanical, and the one piece of real logic (restructuring both CLI entry points to run the Node-version guard before any static import) is correct: on a rejected runtime the guard prints its message and process.exit(1)s before the top-level await import('./cli.js') ever loads chalk 6 (whose engines.node I confirmed is >=22). Both packages build, create-bestax passes 206/206 and bestax-migrate 184/185 (the lone failure is an environmental e2e needing the workspace lib built, not this PR). The riskiest surface is the release machinery, since this PR itself fires the releases; that is where a human should focus, ideally a real semantic-release --dry-run on the CI Node before merge.

Residual risk:

  • Security regression re-entering the tree — refuted: lockfile resolves yaml@2 to 2.9.0 and minimatch@9 to 9.0.9 via the two new scoped overrides; the only other minimatch copies are 10.2.5 and 3.1.5 (the ReDoS fix landed in 3.0.5, so 3.1.5 is patched). Consistent with the claimed "0 high".
  • CLI breaking on a supported runtime — refuted: compiled dist/index.js shows the guard ahead of the dynamic import, no eager chalk/commander/figures load; the friendly message reaches all Node >=14.8 (top-level await parses there), well below the new 22 floor. Only truly ancient (<14.8, decade-EOL) Node would surface a parse error instead of the message, which is acceptable.
  • Silent breakage of the shipped llms.txt surface (docusaurus-plugin-llms 0.4 to 0.5, which pins deps exactly) — refuted: every option the config passes (generateLLMsTxt, generateLLMsFullTxt, generateMarkdownFiles, excludeImports, removeDuplicateHeadings, includeOrder, includeUnmatchedLast, docsDir, ...) still exists in the installed 0.5.1 types/lib.

🏄 Pure lockfile-and-guard cleanup, dude, no gnarly surprises in the break. Chalk 6 rides the Node-22 wave and the guard bails out clean before it ever paddles out. Merge it with a merge commit like the sign says and you are golden.

@allxsmith
allxsmith merged commit e68148c into main Aug 1, 2026
43 checks passed
@allxsmith
allxsmith deleted the chore/consolidate-dependency-updates branch August 1, 2026 01:06
allxsmith added a commit that referenced this pull request Aug 1, 2026
Documents the Node floor in the package README, which had no requirements
section at all.

The implementation landed in #447 (chalk ^6.0.0, engines.node >=22, and a
version guard that no longer depends on chalk to report a too-old runtime).
That PR was squash-merged, which collapsed its three scoped commits into a
single `chore(deps)` commit, so the release signal was lost and none of it
was ever published. This commit carries that signal.

BREAKING CHANGE: create-bestax now requires Node.js 22 or newer. Node 18 and 20
are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
allxsmith added a commit that referenced this pull request Aug 1, 2026
Documents the Node floor in the package README, which had no requirements
section at all.

The implementation landed in #447 (chalk ^6.0.0, engines.node >=22, and a
version guard that no longer depends on chalk to report a too-old runtime).
That PR was squash-merged, which collapsed its three scoped commits into a
single `chore(deps)` commit, so the release signal was lost.

Without this footer the next release would have been computed as a patch from
the four fix(bestax-migrate) commits still queued since 1.0.0 — publishing a
raised Node floor and a chalk major inside a 1.0.1, which is exactly wrong.

BREAKING CHANGE: bestax-migrate now requires Node.js 22 or newer. Node 18 and
20 are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1. This applies to the runtime the codemod executes
on, not to the app being migrated.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
bestax-release-bot Bot pushed a commit that referenced this pull request Aug 1, 2026
# [4.0.0](https://github.com/allxsmith/bestax/compare/create-bestax@3.8.0...create-bestax@4.0.0) (2026-08-01)

### Bug Fixes

* **bestax-migrate:** give the kitchen-sink e2e a per-process scratch dir ([2211ea5](2211ea5))
* **bestax-migrate:** reject pnpm's workspace alias form instead of unwrapping it ([de6a900](de6a900))
* **bestax-migrate:** require the pack script to exist, not just be named ([5315efe](5315efe))
* **bestax-migrate:** resolve bare workspace: and guard the catalog: protocol ([7fda9db](7fda9db)), closes [#417](#417) [#412](#412)
* **bestax-migrate:** resolve workspace: specifiers before publishing ([782829a](782829a)), closes [bestax-migrate#test](https://github.com/bestax-migrate/issues/test) [#412](#412)
* **bestax-migrate:** stop the pack hooks excusing a catalog: devDependency ([4127ead](4127ead)), closes [#412-shaped](#412)
* **docs:** stop cssnano stripping Font Awesome [@font-face](https://github.com/font-face), add [#3](#3) CSS framework blog post ([#401](#401)) ([5d114e1](5d114e1)), closes [#400](#400)

### chore

* **deps:** consolidate the dependabot backlog, require Node 22 in both CLIs ([#447](#447)) ([e68148c](e68148c)), closes [#427](#427) [#428](#428) [#431](#431) [#432](#432) [#440](#440) [#393](#393)

### Features

* **bestax-migrate:** require Node 22 and take chalk 6 ([#449](#449)) ([4c0e1e2](4c0e1e2)), closes [#447](#447)
* **create-bestax:** require Node 22 and take chalk 6 ([#448](#448)) ([90fced2](90fced2)), closes [#447](#447)

### BREAKING CHANGES

* **bestax-migrate:** bestax-migrate now requires Node.js 22 or newer. Node 18 and
20 are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1. This applies to the runtime the codemod executes
on, not to the app being migrated.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
* **create-bestax:** create-bestax now requires Node.js 22 or newer. Node 18 and 20
are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
* **deps:** create-bestax now requires Node.js 22 or newer. Node 18 and 20
are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh

* feat(bestax-migrate): require Node 22 and take chalk 6

chalk 6 drops support for Node below 22. The API surface this package uses is
unchanged, so no calling code changes.

The version guard in src/index.ts moves ahead of every import and no longer
depends on anything: import declarations are hoisted and evaluated before any
statement in the module, and chalk 6 itself requires Node >= 22, so a static
import would fail to load on exactly the runtimes the guard exists to catch.
./cli.js is now imported dynamically for the same reason.

@babel/parser deliberately stays on 7.x. Babel 8 removes the
`deprecatedImportAssert` plugin with no replacement, and this package parses
the legacy `import x from 'y' assert { type: 'json' }` form on purpose — a
codemod that migrates older codebases must not crash on the syntax those
codebases still contain. There is a regression test for it ("parses the legacy
import-assert syntax"), which Babel 8 fails outright. jscodeshift 17 bundles
its own Babel 7 regardless, so staying on 7 also keeps a single parser in the
tree rather than two.
* **deps:** bestax-migrate now requires Node.js 22 or newer. Node 18 and
20 are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 4.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

bestax-release-bot Bot pushed a commit that referenced this pull request Aug 1, 2026
# [2.0.0](https://github.com/allxsmith/bestax/compare/bestax-migrate@1.0.0...bestax-migrate@2.0.0) (2026-08-01)

### Bug Fixes

* **bestax-migrate:** give the kitchen-sink e2e a per-process scratch dir ([2211ea5](2211ea5))
* **bestax-migrate:** reject pnpm's workspace alias form instead of unwrapping it ([de6a900](de6a900))
* **bestax-migrate:** require the pack script to exist, not just be named ([5315efe](5315efe))
* **bestax-migrate:** resolve bare workspace: and guard the catalog: protocol ([7fda9db](7fda9db)), closes [#417](#417) [#412](#412)
* **bestax-migrate:** resolve workspace: specifiers before publishing ([782829a](782829a)), closes [bestax-migrate#test](https://github.com/bestax-migrate/issues/test) [#412](#412)
* **bestax-migrate:** stop the pack hooks excusing a catalog: devDependency ([4127ead](4127ead)), closes [#412-shaped](#412)
* **create-bestax:** concrete inline-style → helper-prop mapping for the never-inline rule ([#357](#357)) ([5f72a90](5f72a90)), closes [#350](#350) [#350](#350)
* **docs:** stop cssnano stripping Font Awesome [@font-face](https://github.com/font-face), add [#3](#3) CSS framework blog post ([#401](#401)) ([5d114e1](5d114e1)), closes [#400](#400)

### chore

* **deps:** consolidate the dependabot backlog, require Node 22 in both CLIs ([#447](#447)) ([e68148c](e68148c)), closes [#427](#427) [#428](#428) [#431](#431) [#432](#432) [#440](#440) [#393](#393)

### Features

* **bestax-migrate:** require Node 22 and take chalk 6 ([#449](#449)) ([4c0e1e2](4c0e1e2)), closes [#447](#447)
* **bulma-ui:** ship agent-discovery files in the npm tarball ([#345](#345)) ([4b58739](4b58739)), closes [#344](#344) [#344](#344) [#344](#344)
* **create-bestax:** add controlled-Burger Navbar to the landing archetype ([#355](#355)) ([36d4d09](36d4d09)), closes [#348](#348)
* **create-bestax:** agent-validated guidance for skills, scaffold CLAUDE.md, and catalog ([#365](#365)) ([6fd06ae](6fd06ae)), closes [#2](#2)
* **create-bestax:** require Node 22 and take chalk 6 ([#448](#448)) ([90fced2](90fced2)), closes [#447](#447)
* **create-bestax:** scaffold .claude/launch.json with the AI skills opt-in ([#343](#343)) ([189135a](189135a))
* **create-bestax:** set scaffolded index.html title to the project name ([#356](#356)) ([3bfbea3](3bfbea3)), closes [#349](#349) [#349](#349)

### BREAKING CHANGES

* **bestax-migrate:** bestax-migrate now requires Node.js 22 or newer. Node 18 and
20 are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1. This applies to the runtime the codemod executes
on, not to the app being migrated.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
* **create-bestax:** create-bestax now requires Node.js 22 or newer. Node 18 and 20
are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
* **deps:** create-bestax now requires Node.js 22 or newer. Node 18 and 20
are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh

* feat(bestax-migrate): require Node 22 and take chalk 6

chalk 6 drops support for Node below 22. The API surface this package uses is
unchanged, so no calling code changes.

The version guard in src/index.ts moves ahead of every import and no longer
depends on anything: import declarations are hoisted and evaluated before any
statement in the module, and chalk 6 itself requires Node >= 22, so a static
import would fail to load on exactly the runtimes the guard exists to catch.
./cli.js is now imported dynamically for the same reason.

@babel/parser deliberately stays on 7.x. Babel 8 removes the
`deprecatedImportAssert` plugin with no replacement, and this package parses
the legacy `import x from 'y' assert { type: 'json' }` form on purpose — a
codemod that migrates older codebases must not crash on the syntax those
codebases still contain. There is a regression test for it ("parses the legacy
import-assert syntax"), which Babel 8 fails outright. jscodeshift 17 bundles
its own Babel 7 regardless, so staying on 7 also keeps a single parser in the
tree rather than two.
* **deps:** bestax-migrate now requires Node.js 22 or newer. Node 18 and
20 are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 2.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

bestax-release-bot Bot pushed a commit that referenced this pull request Aug 7, 2026
## [5.8.1](https://github.com/allxsmith/bestax/compare/@allxsmith/bestax-bulma@5.8.0...@allxsmith/bestax-bulma@5.8.1) (2026-08-07)

### Bug Fixes

* **bestax-migrate:** give the kitchen-sink e2e a per-process scratch dir ([2211ea5](2211ea5))
* **bestax-migrate:** reject pnpm's workspace alias form instead of unwrapping it ([de6a900](de6a900))
* **bestax-migrate:** require the pack script to exist, not just be named ([5315efe](5315efe))
* **bestax-migrate:** resolve bare workspace: and guard the catalog: protocol ([7fda9db](7fda9db)), closes [#417](#417) [#412](#412)
* **bestax-migrate:** resolve workspace: specifiers before publishing ([782829a](782829a)), closes [bestax-migrate#test](https://github.com/bestax-migrate/issues/test) [#412](#412)
* **bestax-migrate:** stop the pack hooks excusing a catalog: devDependency ([4127ead](4127ead)), closes [#412-shaped](#412)
* **bulma-ui:** deprecate CSS-less color values, warn in dev, fix has-text fall-through ([fb111eb](fb111eb))
* **bulma-ui:** fail closed on missing process and scope color guidance to real props ([117c0c0](117c0c0))
* **create-bestax:** concrete inline-style → helper-prop mapping for the never-inline rule ([#357](#357)) ([5f72a90](5f72a90)), closes [#350](#350) [#350](#350)
* **create-bestax:** validate at submit in the bestax-form signup example ([0b9518f](0b9518f))
* **create-bestax:** wire labeled controls in the skill showcase story ([af49a16](af49a16))
* **docs:** announce the hero copy, and stop remounting the icons ([98e2cb0](98e2cb0)), closes [#434](#434)
* **docs:** correct the frozen-install translation and reject leaked fences ([1883de3](1883de3))
* **docs:** drop dead nomodule ionicons fallback ([82be3e4](82be3e4))
* **docs:** harden PackageManagerTabs and document how to author it ([5b0d3e6](5b0d3e6)), closes [#434](#434)
* **docs:** harden the hero copy button and share the tab storage key ([9e16cd7](9e16cd7))
* **docs:** make the hero package-manager switcher a real radiogroup ([aa14ff2](aa14ff2)), closes [#434](#434)
* **docs:** stop cssnano stripping Font Awesome [@font-face](https://github.com/font-face), add [#3](#3) CSS framework blog post ([#401](#401)) ([5d114e1](5d114e1)), closes [#400](#400)

### chore

* **deps:** consolidate the dependabot backlog, require Node 22 in both CLIs ([#447](#447)) ([e68148c](e68148c)), closes [#427](#427) [#428](#428) [#431](#431) [#432](#432) [#440](#440) [#393](#393)

### Features

* **bestax-migrate:** require Node 22 and take chalk 6 ([#449](#449)) ([4c0e1e2](4c0e1e2)), closes [#447](#447)
* **create-bestax:** add controlled-Burger Navbar to the landing archetype ([#355](#355)) ([36d4d09](36d4d09)), closes [#348](#348)
* **create-bestax:** agent-validated guidance for skills, scaffold CLAUDE.md, and catalog ([#365](#365)) ([6fd06ae](6fd06ae)), closes [#2](#2)
* **create-bestax:** require Node 22 and take chalk 6 ([#448](#448)) ([90fced2](90fced2)), closes [#447](#447)
* **create-bestax:** set scaffolded index.html title to the project name ([#356](#356)) ([3bfbea3](3bfbea3)), closes [#349](#349) [#349](#349)
* **docs:** add package-manager switches to the homepage hero ([374caf8](374caf8))
* **docs:** add PackageManagerTabs and register it globally ([23c9989](23c9989))
* **docs:** show all posts in the blog sidebar ([d29e9c6](d29e9c6))

### Performance Improvements

* **docs:** defer live previews until they scroll into view ([d6bf87b](d6bf87b))
* **docs:** share one parsed stylesheet set across every live preview ([feb993a](feb993a))

### BREAKING CHANGES

* **bestax-migrate:** bestax-migrate now requires Node.js 22 or newer. Node 18 and
20 are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1. This applies to the runtime the codemod executes
on, not to the app being migrated.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
* **create-bestax:** create-bestax now requires Node.js 22 or newer. Node 18 and 20
are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
* **deps:** create-bestax now requires Node.js 22 or newer. Node 18 and 20
are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh

* feat(bestax-migrate): require Node 22 and take chalk 6

chalk 6 drops support for Node below 22. The API surface this package uses is
unchanged, so no calling code changes.

The version guard in src/index.ts moves ahead of every import and no longer
depends on anything: import declarations are hoisted and evaluated before any
statement in the module, and chalk 6 itself requires Node >= 22, so a static
import would fail to load on exactly the runtimes the guard exists to catch.
./cli.js is now imported dynamically for the same reason.

@babel/parser deliberately stays on 7.x. Babel 8 removes the
`deprecatedImportAssert` plugin with no replacement, and this package parses
the legacy `import x from 'y' assert { type: 'json' }` form on purpose — a
codemod that migrates older codebases must not crash on the syntax those
codebases still contain. There is a regression test for it ("parses the legacy
import-assert syntax"), which Babel 8 fails outright. jscodeshift 17 bundles
its own Babel 7 regardless, so staying on 7 also keeps a single parser in the
tree rather than two.
* **deps:** bestax-migrate now requires Node.js 22 or newer. Node 18 and
20 are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 5.8.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

bestax-release-bot Bot pushed a commit that referenced this pull request Aug 12, 2026
# 1.0.0 (2026-08-12)

* feat(bulma-ui)!: remove bestax-bulma-prefixed CSS variant ([94baa34](94baa34))
* feat(create-bestax)!: require Node.js 18+ and align with bestax-bulma v2 ([#118](#118)) ([b22f183](b22f183))

### Bug Fixes

* add comprehensive rules to prevent bulma-ui versioning on non-bulma-ui commits ([#122](#122)) ([525ccfa](525ccfa)), closes [#119](#119)
* **bestax-mcp:** derive the near-miss guidance from the skill, and only when it helps ([1141cca](1141cca))
* **bestax-mcp:** do not split a helper-prop table cell on an escaped pipe ([bdac820](bdac820))
* **bestax-mcp:** lead get_helper_props with the inline-style prohibition ([ffc627a](ffc627a))
* **bestax-mcp:** make list_components point at the next step ([8ddb2fd](8ddb2fd))
* **bestax-mcp:** make tests and cached builds work from a clean checkout ([6e63820](6e63820)), closes [bestax-mcp#build](https://github.com/bestax-mcp/issues/build)
* **bestax-mcp:** name list_components as the entry point, not search_bestax ([206380b](206380b))
* **bestax-mcp:** name the three near-miss components in the list_components footer ([1c7af67](1c7af67))
* **bestax-mcp:** route helper questions to the tool that answers them ([cd6ce12](cd6ce12))
* **bestax-mcp:** validate the one input that is not ours, and bound the rest ([3e1adc9](3e1adc9))
* **bestax-migrate:** give the kitchen-sink e2e a per-process scratch dir ([2211ea5](2211ea5))
* **bestax-migrate:** reject pnpm's workspace alias form instead of unwrapping it ([de6a900](de6a900))
* **bestax-migrate:** require the pack script to exist, not just be named ([5315efe](5315efe))
* **bestax-migrate:** resolve bare workspace: and guard the catalog: protocol ([7fda9db](7fda9db)), closes [#417](#417) [#412](#412)
* **bestax-migrate:** resolve workspace: specifiers before publishing ([782829a](782829a)), closes [bestax-migrate#test](https://github.com/bestax-migrate/issues/test) [#412](#412)
* **bestax-migrate:** stop the pack hooks excusing a catalog: devDependency ([4127ead](4127ead)), closes [#412-shaped](#412)
* **bulma-ui:** a11y + case-insensitive Taginput matching from PR review ([d576829](d576829))
* **bulma-ui:** accept router props like `to` on Navbar.Item without casts ([#311](#311)) ([b78856b](b78856b)), closes [#306](#306)
* **bulma-ui:** Add build step to publish in ci.yml ([e3707fc](e3707fc))
* **bulma-ui:** add fontawesome-free as explicit devDependency ([a4a5389](a4a5389))
* **bulma-ui:** add missing exports ([0d16633](0d16633))
* **bulma-ui:** Add Skeleton to exports ([e481599](e481599))
* **bulma-ui:** another attempt to fix semantic release builds with ci.yml ([cc3a3e2](cc3a3e2))
* **bulma-ui:** another attempt to fix semantic release builds with ci.yml ([314bc39](314bc39))
* **bulma-ui:** another attempt to fix semantic release builds with ci.yml ([c930693](c930693))
* **bulma-ui:** associate Autocomplete and Taginput labels with their inner inputs ([7ae37d4](7ae37d4))
* **bulma-ui:** associate Autocomplete and Taginput labels with their inner inputs ([384bd38](384bd38))
* **bulma-ui:** associate the form label prop with its control via a generated id ([e6686af](e6686af))
* **bulma-ui:** complete domain migration and fix semantic-release configuration ([#64](#64)) ([f4cd71d](f4cd71d))
* **bulma-ui:** correct blog post examples and add Modal compound components ([#81](#81)) ([559c2e3](559c2e3))
* **bulma-ui:** correct NPM_TOKEN env variable in ci.yml ([94b48b4](94b48b4))
* **bulma-ui:** cover horizontal-layout group label association ([ef3ca9f](ef3ca9f))
* **bulma-ui:** deprecate CSS-less color values, warn in dev, fix has-text fall-through ([fb111eb](fb111eb))
* **bulma-ui:** fail closed on missing process and scope color guidance to real props ([117c0c0](117c0c0))
* **bulma-ui:** Fix release.config.js to include package-lock.json ([390da59](390da59))
* **bulma-ui:** fix standalone Badge pointer-events, pulse halo, and falsy content ([#295](#295)) ([a9db031](a9db031)), closes [#264](#264)
* **bulma-ui:** full classPrefix support across layout/grid + prefix utils ([4ce0b53](4ce0b53))
* **bulma-ui:** honor the htmlFor opt-out in the convenience hook and tighten the association docs ([92aa622](92aa622))
* **bulma-ui:** improve npm package discoverability with optimized keywords and badges ([#72](#72)) ([8c7a696](8c7a696))
* **bulma-ui:** Initial semantic release changes ([b78d785](b78d785))
* **bulma-ui:** keep Taginput's fallback name unless the label targets its input ([73cec33](73cec33))
* **bulma-ui:** keep Taginput's fallback name unless the label targets its input ([ca5996a](ca5996a))
* **bulma-ui:** migrate domain from bestax.cc to bestax.io ([#64](#64)) ([4870b1e](4870b1e))
* **bulma-ui:** migrate ionicons to v8 to unblock publish and Storybook ([927a55b](927a55b)), closes [#142](#142)
* **bulma-ui:** name Rate, Checkboxes, and Radios groups from their labels via aria-labelledby ([dce0ee7](dce0ee7))
* **bulma-ui:** name Rate, Checkboxes, and Radios groups from their labels via aria-labelledby ([#497](#497)) ([5c4222e](5c4222e))
* **bulma-ui:** name the three near-miss components in AGENTS.md ([c63f491](c63f491)), closes [#344](#344)
* **bulma-ui:** never let labelProps.htmlFor wire a group label to a control ([3b3aaaf](3b3aaaf))
* **bulma-ui:** publish rewritten README to npm ([9810081](9810081))
* **bulma-ui:** publish with npm provenance attestation ([172da62](172da62)), closes [#180](#180)
* **bulma-ui:** reference llms docs from README and package.json ([#198](#198)) ([db8aab3](db8aab3))
* **bulma-ui:** reject predicate-blocked values during manual entry ([a8f6e28](a8f6e28))
* **bulma-ui:** resolve flex item properties and Card compound component issues ([#55](#55)) ([e774da3](e774da3))
* **bulma-ui:** resolve flex item properties and Card compound component issues ([#55](#55)) ([7641a53](7641a53))
* **bulma-ui:** resolve react-hooks v7 and [@eslint-react](https://github.com/eslint-react) findings ([14caaaf](14caaaf))
* **bulma-ui:** resolve security vulnerabilities and update dependencies ([#128](#128)) ([112f6e4](112f6e4)), closes [#127](#127)
* **bulma-ui:** restrict semantic-release to bulma-ui scoped commits only ([2d67bf9](2d67bf9)), closes [#62](#62)
* **bulma-ui:** retry failed Avatar src, flatten Fragment children in Avatars, RTL-safe overlap ([#297](#297)) ([c00b9db](c00b9db))
* **bulma-ui:** route every hardcoded class through the prefix helpers; add classPrefix sweep test ([#301](#301)) ([a50b134](a50b134)), closes [#286](#286)
* **bulma-ui:** setup gpg signing with semantic-release ([3e24722](3e24722))
* **bulma-ui:** strip redundant library prefix from Icon name ([#242](#242)) ([dbe3622](dbe3622)), closes [#189](#189)
* **bulma-ui:** trigger release to publish via OIDC trusted publishing ([e2d09c5](e2d09c5))
* **bulma-ui:** update bundle size claims to accurate 21KB gzipped ([#66](#66)) ([6e381bd](6e381bd))
* **bulma-ui:** update package-lock.json ([853d585](853d585))
* **bulma-ui:** update package.json for better seo, exports, types, engines, funding, etc ([98cbc56](98cbc56))
* **bulma-ui:** use createRequire for ESM compatibility in Storybook 10 ([#130](#130)) ([b27e60e](b27e60e)), closes [#129](#129)
* **ci:** collect screenshots as artifacts and commit in single batch to avoid conflicts ([27b259d](27b259d))
* **ci:** ensure npm install uses fresh downloads with --prefer-online ([1f2e15d](1f2e15d))
* **ci:** properly extract base path for recursive file search ([e0330ff](e0330ff))
* **ci:** use find command instead of glob module in verified-commit action ([0e2d159](0e2d159))
* **ci:** use npm ci for scaffolded app dependencies ([35652c8](35652c8))
* **create-bestax:** concrete inline-style → helper-prop mapping for the never-inline rule ([#357](#357)) ([5f72a90](5f72a90)), closes [#350](#350) [#350](#350)
* **create-bestax:** correct browser title to prioritize Bestax branding ([#106](#106)) ([23aa535](23aa535)), closes [#105](#105)
* **create-bestax:** correct template path resolution from ../../ to ../ ([65b4493](65b4493)), closes [#78](#78)
* **create-bestax:** dark-mode contrast rules in theming/layout skills and docs ([#303](#303)) ([490bf21](490bf21)), closes [#194](#194) [#195](#195)
* **create-bestax:** exclude templates directory from linting and typecheck ([18fec0b](18fec0b))
* **create-bestax:** fail fast with guidance instead of hanging when stdin is not a TTY ([#293](#293)) ([46a172d](46a172d)), closes [#192](#192)
* **create-bestax:** move templates into package directory and update docs ([195bf01](195bf01)), closes [#78](#78)
* **create-bestax:** point scaffolded CLAUDE.md at llms docs; document skills ([#198](#198)) ([b2e0514](b2e0514))
* **create-bestax:** publish with npm provenance attestation ([21ffe8f](21ffe8f)), closes [#180](#180)
* **create-bestax:** put the near-miss guidance where every session sees it ([6db49f3](6db49f3))
* **create-bestax:** read version from package.json instead of hardcoded value ([#109](#109)) ([8605699](8605699))
* **create-bestax:** refresh README and bump scaffolded bestax-bulma to ^5 ([4e19e86](4e19e86))
* **create-bestax:** reject dot-only project names, pin icon versions, bundle bestax-icons skill ([#310](#310)) ([ddff8e5](ddff8e5))
* **create-bestax:** scaffold @allxsmith/bestax-bulma ^4.0.0 ([1d3b802](1d3b802))
* **create-bestax:** scaffold bundled bestax CSS flavors, not stock Bulma ([43621dc](43621dc))
* **create-bestax:** ship improved bundled skills + component catalog ([#199](#199)) ([a1515c2](a1515c2))
* **create-bestax:** shrink the near-miss block and pin the copies together ([d582da5](d582da5))
* **create-bestax:** skills-sync conformance gate + theming skill reference backfill ([#326](#326)) ([9584133](9584133)), closes [#285](#285)
* **create-bestax:** stop the skills teaching a Theme call that does not compile ([2935bb2](2935bb2))
* **create-bestax:** synchronize version with bestax-bulma to 2.4.0 ([623ee79](623ee79)), closes [#96](#96)
* **create-bestax:** teach the skills the three components Bulma hides ([22dcff7](22dcff7))
* **create-bestax:** update template dependency to ^2.4.0 ([200971d](200971d))
* **create-bestax:** use scenario-specific screenshot directories to prevent overwrites ([#108](#108)) ([c675957](c675957)), closes [#107](#107)
* **create-bestax:** validate at submit in the bestax-form signup example ([0b9518f](0b9518f))
* **create-bestax:** wire labeled controls in the skill showcase story ([af49a16](af49a16))
* **docs:** announce the hero copy, and stop remounting the icons ([98e2cb0](98e2cb0)), closes [#434](#434)
* **docs:** correct Content Signals syntax in robots.txt ([#134](#134)) ([85dd9de](85dd9de))
* **docs:** correct the frozen-install translation and reject leaked fences ([1883de3](1883de3))
* **docs:** drop dead nomodule ionicons fallback ([82be3e4](82be3e4))
* **docs:** emit per-page markdown so llms.txt links resolve ([#200](#200)) ([7877083](7877083))
* **docs:** escape apostrophe in QuickStart notification text ([25d6d72](25d6d72))
* **docs:** generate llms.txt so the advertised homepage link resolves ([9fae464](9fae464)), closes [#177](#177)
* **docs:** give every batch run its own port — slot reuse was corrupting runs ([6ef1755](6ef1755))
* **docs:** harden PackageManagerTabs and document how to author it ([5b0d3e6](5b0d3e6)), closes [#434](#434)
* **docs:** harden the hero copy button and share the tab storage key ([9e16cd7](9e16cd7))
* **docs:** improve homepage hero layout and button spacing ([5f7a5a7](5f7a5a7))
* **docs:** make the eval batch resumable after a container restart ([d56229e](d56229e))
* **docs:** make the hero package-manager switcher a real radiogroup ([aa14ff2](aa14ff2)), closes [#434](#434)
* **docs:** move robots.txt to correct deployment location ([#90](#90)) ([1e2aeee](1e2aeee))
* **docs:** rebrand and reorganize Storybook ([#83](#83)) ([dfb9937](dfb9937))
* **docs:** remove Google Analytics and add robots.txt ([94776f7](94776f7))
* **docs:** stop cssnano stripping Font Awesome [@font-face](https://github.com/font-face), add [#3](#3) CSS framework blog post ([#401](#401)) ([5d114e1](5d114e1)), closes [#400](#400)
* **docs:** update Storybook logo path to /img/logo.svg for deployed site ([bf59758](bf59758))
* **e2e:** correct notification CSS selectors to use contains instead of ends-with ([182acc1](182acc1))
* implement independent package versioning strategy ([#111](#111)) ([7819c73](7819c73)), closes [#110](#110)
* prevent bulma-ui from versioning on create-bestax commits ([#120](#120)) ([4dfaf9c](4dfaf9c)), closes [#119](#119)
* resolve React Hooks violations and ESLint configuration issues ([32d2931](32d2931))
* upgrade Turbo, Storybook, and Docusaurus dependencies ([5b4ebdd](5b4ebdd)), closes [#98](#98)

### chore

* **deps:** consolidate the dependabot backlog, require Node 22 in both CLIs ([#447](#447)) ([e68148c](e68148c)), closes [#427](#427) [#428](#428) [#431](#431) [#432](#432) [#440](#440) [#393](#393)

### Documentation

* fix stale versioning and coverage docs; drop CLAUDE.md stale-docs flags ([71c4583](71c4583))

### Features

* add theme system and config provider with comprehensive test coverage ([f3ca7f0](f3ca7f0))
* **bestax-mcp:** serve component docs, props, examples and skills over MCP ([c2abcc4](c2abcc4))
* **bestax-migrate:** react-bulma-components → bestax-bulma codemod CLI, skill, and docs ([#333](#333)) ([e04a12b](e04a12b)), closes [#1e6b99](https://github.com/allxsmith/bestax/issues/1e6b99)
* **bestax-migrate:** require Node 22 and take chalk 6 ([#449](#449)) ([4c0e1e2](4c0e1e2)), closes [#447](#447)
* **bulma-ui:** add Avatar, Avatars, and Badge components ([#257](#257)) ([0817018](0817018)), closes [#256](#256)
* **bulma-ui:** add colorMode dark-mode prop to Theme ([4acc41e](4acc41e)), closes [#174](#174)
* **bulma-ui:** add consistent gap prop to Columns, aliasing gapSize ([#300](#300)) ([6c36455](6c36455)), closes [#282](#282)
* **bulma-ui:** add cursor helper, closeDelay prop, and polish Tooltip stories ([37945b5](37945b5))
* **bulma-ui:** add extra components, form elements, and SCSS styles ([59daf28](59daf28))
* **bulma-ui:** add HTML element wrapper components ([#135](#135)) ([#136](#136)) ([20fb16d](20fb16d))
* **bulma-ui:** add manual-entry stories for format, bounds, and blocked-value variations ([e93d51c](e93d51c))
* **bulma-ui:** add Reveal component for scroll-triggered animations ([#255](#255)) ([a89c574](a89c574))
* **bulma-ui:** Add skeletons ([6c46e4b](6c46e4b))
* **bulma-ui:** add themed Checkbox/Radio, convenience Field components, and Autocomplete cleanup ([3c57a5a](3c57a5a))
* **bulma-ui:** add typing-first story variants for all picker property variations ([078433f](078433f))
* **bulma-ui:** associate Field's label with a composed base control ([219f631](219f631))
* **bulma-ui:** avatar/badge a11y batch — decorative alt, accessible names, live region, button type, surplus i18n, focus ring ([#298](#298)) ([508477f](508477f)), closes [#266](#266) [#266](#266)
* **bulma-ui:** change the default primary color to [#1](#1 ([8872620](8872620)), closes [#1e6b99](https://github.com/allxsmith/bestax/issues/1e6b99) [#1e6b99](https://github.com/allxsmith/bestax/issues/1e6b99)
* **bulma-ui:** compound (dot-notation) sub-components for all parent/child families via shared withSubComponents helper ([#331](#331)) ([07516c5](07516c5))
* **bulma-ui:** dim and blur the calendar behind the Datetimepicker time wheels ([3d90619](3d90619))
* **bulma-ui:** finalize the 3.0 component set ([87ccc0e](87ccc0e))
* **bulma-ui:** make Button and Link as prop polymorphic (React.ElementType) ([#238](#238)) ([ce90304](ce90304)), closes [#188](#188)
* **bulma-ui:** require React 18 as the minimum supported version ([c7251b0](c7251b0))
* **bulma-ui:** ship agent-discovery files in the npm tarball ([#345](#345)) ([4b58739](4b58739)), closes [#344](#344) [#344](#344) [#344](#344)
* **ci:** add verified-commit action for GPG-signed commits ([d078dfa](d078dfa))
* **create-bestax:** add bestax-optimize skill for shrinking built CSS ([#329](#329)) ([f597b9f](f597b9f))
* **create-bestax:** add CLI tool with Vite templates and automated publishing ([9748c3d](9748c3d))
* **create-bestax:** add controlled-Burger Navbar to the landing archetype ([#355](#355)) ([36d4d09](36d4d09)), closes [#348](#348)
* **create-bestax:** add cross-platform emoji support with figures ([#103](#103)) ([15567d9](15567d9))
* **create-bestax:** add README with templates location note ([8ddc73d](8ddc73d))
* **create-bestax:** add visual regression testing and synchronized versioning ([17e1e22](17e1e22)), closes [#94](#94)
* **create-bestax:** agent-validated guidance for skills, scaffold CLAUDE.md, and catalog ([#365](#365)) ([6fd06ae](6fd06ae)), closes [#2](#2)
* **create-bestax:** bestax-icons skill — teach agents the icon system ([#302](#302)) ([61c8ef2](61c8ef2)), closes [#287](#287)
* **create-bestax:** improve favicon visibility and add distinct branding ([621590d](621590d)), closes [#100](#100)
* **create-bestax:** modernize templates (Vite 8, ESLint 10, TS 6) + add working lint config ([4537629](4537629)), closes [#167](#167)
* **create-bestax:** offer to install the bestax AI skills when scaffolding ([625b7bf](625b7bf)), closes [#174](#174)
* **create-bestax:** require Node 22 and take chalk 6 ([#448](#448)) ([90fced2](90fced2)), closes [#447](#447)
* **create-bestax:** scaffold .claude/launch.json with the AI skills opt-in ([#343](#343)) ([189135a](189135a))
* **create-bestax:** scaffold-aware CLAUDE.md with setup facts and house style ([#271](#271)) ([c1681b0](c1681b0))
* **create-bestax:** set scaffolded index.html title to the project name ([#356](#356)) ([3bfbea3](3bfbea3)), closes [#349](#349) [#349](#349)
* **docs:** add Google Analytics tracking for usage insights ([#68](#68)) ([90ab951](90ab951))
* **docs:** add package-manager switches to the homepage hero ([374caf8](374caf8))
* **docs:** add PackageManagerTabs and register it globally ([23c9989](23c9989))
* **docs:** add pronunciation guide and dark mode support ([#58](#58)) ([48a8916](48a8916))
* **docs:** aggregate-runs.mjs — distribution stats across a runs directory ([5de9c07](5de9c07))
* **docs:** batch runner for the eval harness, with the concurrency fixes it needed ([f8e268c](f8e268c))
* **docs:** migrate from GitHub Pages to Cloudflare Pages ([#132](#132)) ([2154672](2154672)), closes [#131](#131)
* **docs:** rubric v2 and a brief that demands the components beyond Bulma ([e6047be](e6047be))
* **docs:** show all posts in the blog sidebar ([d29e9c6](d29e9c6))
* **form:** add Datepicker, Timepicker, and Datetimepicker components ([c6684e6](c6684e6))

### Performance Improvements

* **bestax-mcp:** stop get_helper_props costing half the session ([b865651](b865651))
* **docs:** defer live previews until they scroll into view ([d6bf87b](d6bf87b))
* **docs:** share one parsed stylesheet set across every live preview ([feb993a](feb993a))

### BREAKING CHANGES

* **bestax-migrate:** bestax-migrate now requires Node.js 22 or newer. Node 18 and
20 are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1. This applies to the runtime the codemod executes
on, not to the app being migrated.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
* **create-bestax:** create-bestax now requires Node.js 22 or newer. Node 18 and 20
are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
* **deps:** create-bestax now requires Node.js 22 or newer. Node 18 and 20
are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh

* feat(bestax-migrate): require Node 22 and take chalk 6

chalk 6 drops support for Node below 22. The API surface this package uses is
unchanged, so no calling code changes.

The version guard in src/index.ts moves ahead of every import and no longer
depends on anything: import declarations are hoisted and evaluated before any
statement in the module, and chalk 6 itself requires Node >= 22, so a static
import would fail to load on exactly the runtimes the guard exists to catch.
./cli.js is now imported dynamically for the same reason.

@babel/parser deliberately stays on 7.x. Babel 8 removes the
`deprecatedImportAssert` plugin with no replacement, and this package parses
the legacy `import x from 'y' assert { type: 'json' }` form on purpose — a
codemod that migrates older codebases must not crash on the syntax those
codebases still contain. There is a regression test for it ("parses the legacy
import-assert syntax"), which Babel 8 fails outright. jscodeshift 17 bundles
its own Babel 7 regardless, so staying on 7 also keeps a single parser in the
tree rather than two.
* **deps:** bestax-migrate now requires Node.js 22 or newer. Node 18 and
20 are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1.

Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
* footer requirement, and the commitlint scope rule
- CONTRIBUTING.md: replace the type-less commit example with a
  commitlint-valid conventional format (verified against commitlint);
  correct all four coverage mentions to the real jest thresholds
  (bulma-ui 99%, create-bestax 95%/78% branches); fix the npm package
  name (@allxsmith/bestax-bulma, plus create-bestax) and link VERSIONING.md
- CLAUDE.md: remove the stale-docs warning and asides now that the
  underlying docs are correct; point at VERSIONING.md again

Closes #206.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0131uD6QKmAij7Byk3SByyLh
* the @allxsmith/bestax-bulma/versions/bestax-bulma-prefixed.css
export is removed. Use versions/bestax-prefixed.css with classPrefix="bestax-".
* **bulma-ui:** React 16 and 17 are no longer supported; the minimum
supported React version is now 18.
* **bulma-ui:** Snackbar has been removed and merged into Toast; use Toast
with its positioning and queue props instead.
* **bulma-ui:** form controls now auto-wrap in Field/Control, and Checkbox
and Radio ship new themed visuals. See the 2.x -> 3.x migration guide.
* This version requires Node.js 18.0.0 or higher. The CLI now enforces this requirement and will exit with an error message if running on older Node.js versions. This aligns create-bestax with the bestax-bulma v2.x ecosystem.

* fix(create-bestax): correct Prettier formatting in index.ts
* None - all changes are additive and backward compatible
@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 1.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

allxsmith added a commit that referenced this pull request Aug 17, 2026
…aims

bestax-mcp was left out of verify-provenance on the strength of #502, which
says CI has no release step for it. That issue is stale: ci.yml has had a
`Semantic Release (bestax-mcp)` step since the pipeline change, and 1.0.0 is
on the registry with a SLSA provenance attestation. Verified it installs
clean alongside the other three, so it belongs in both lists.

SECURITY.md's supported-versions table had drifted two majors behind on two
packages and never gained a row for the fourth: create-bestax is 4.x not 3.x,
bestax-migrate is 2.x not 1.x, and bestax-mcp was missing entirely. Both
majors were the Node 22 requirement from #447, not an API break. That table
is what tells users which line receives security fixes, so being wrong about
it is a security-relevant inaccuracy rather than a docs nit. The provenance
bullet said "all three published packages" for the same reason.

The docs security guide carried a narrower version of the same claim, naming
only two of the four packages.
allxsmith added a commit that referenced this pull request Aug 17, 2026
…aims

bestax-mcp was left out of verify-provenance on the strength of #502, which
says CI has no release step for it. That issue is stale: ci.yml has had a
`Semantic Release (bestax-mcp)` step since the pipeline change, and 1.0.0 is
on the registry with a SLSA provenance attestation. Verified it installs
clean alongside the other three, so it belongs in both lists.

SECURITY.md's supported-versions table had drifted two majors behind on two
packages and never gained a row for the fourth: create-bestax is 4.x not 3.x,
bestax-migrate is 2.x not 1.x, and bestax-mcp was missing entirely. Both
majors were the Node 22 requirement from #447, not an API break. That table
is what tells users which line receives security fixes, so being wrong about
it is a security-relevant inaccuracy rather than a docs nit. The provenance
bullet said "all three published packages" for the same reason.

The docs security guide carried a narrower version of the same claim, naming
only two of the four packages.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants