Repository navigation
chore(deps): consolidate the dependabot backlog, require Node 22 in both CLIs - #447
Conversation
…d yaml Consolidates #427, #428, #431, #432 and #440 into one PR so the shared pnpm-lock.yaml is regenerated once instead of forcing dependabot to rebase six branches serially. Same approach as #393 for #388/#390. docusaurus-plugin-llms 0.5.x pins its own dependencies exactly rather than by range, which dragged minimatch back to 9.0.3 (three high ReDoS advisories) and yaml to 2.8.1, failing both `pnpm audit --audit-level=high` and Dependency Review on #440. Two scoped overrides restore the patched versions; the rest of that group was already clean. @semantic-release/changelog 7 and @semantic-release/git 11 are the same CJS-to-ESM wave and are taken together. Every option the release configs actually pass (changelogFile, assets, message) is unchanged, and both declare a semantic-release peer of >=20.1.0, satisfied by ^25.0.8. @testing-library/jest-dom 7 removes no matchers; the new required peer @testing-library/dom is already resolved at 10.4.1 via @testing-library/react. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
chalk 6 drops support for Node below 22. The API surface this package uses is unchanged — every call site is a default import using .red/.yellow/.green and friends — so no calling code changes. Raising engines.node to >=22 brings the manifest in line with what the docs have claimed all along: the installation guide already states "Node.js: 22.0.0 or higher (the current LTS baseline)". The version guard in src/index.ts moves ahead of every import and stops using chalk. Import declarations are hoisted and evaluated before any statement in the module, and chalk 6 itself requires Node >= 22 — so a static import would fail to load on exactly the runtimes the guard exists to catch, replacing a clear message with an opaque loader error. ./cli.js is now imported dynamically for the same reason. BREAKING CHANGE: create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
chalk 6 drops support for Node below 22. The API surface this package uses is
unchanged, so no calling code changes.
The version guard in src/index.ts moves ahead of every import and no longer
depends on anything: import declarations are hoisted and evaluated before any
statement in the module, and chalk 6 itself requires Node >= 22, so a static
import would fail to load on exactly the runtimes the guard exists to catch.
./cli.js is now imported dynamically for the same reason.
@babel/parser deliberately stays on 7.x. Babel 8 removes the
`deprecatedImportAssert` plugin with no replacement, and this package parses
the legacy `import x from 'y' assert { type: 'json' }` form on purpose — a
codemod that migrates older codebases must not crash on the syntax those
codebases still contain. There is a regression test for it ("parses the legacy
import-assert syntax"), which Babel 8 fails outright. jscodeshift 17 bundles
its own Babel 7 regardless, so staying on 7 also keeps a single parser in the
tree rather than two.
BREAKING CHANGE: bestax-migrate now requires Node.js 22 or newer. Node 18 and
20 are both past end-of-life. Running it on an older runtime prints an explicit
upgrade message and exits 1.
Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
|
Warning Review limit reached
Next review available in: 44 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (8)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub. |
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Preview DeploymentPreview URL: https://c3180339.bestax.pages.dev |
There was a problem hiding this comment.
Pull request overview
Consolidates a backlog of Dependabot dependency bumps into a single lockfile regeneration, and raises the Node.js minimum version to 22 for both CLI packages (create-bestax and bestax-migrate) to support chalk@6 and ensure the Node version guards execute before any static imports.
Changes:
- Added scoped
pnpmoverrides to keep patchedminimatchandyamlversions when upgradingdocusaurus-plugin-llms. - Updated dependency versions across the root, docs, and bulma-ui workspaces (dev tooling and docs deps).
- Updated both CLIs to require Node 22 (
engines) and restructured their entrypoints to run the version guard before dynamically importing the rest of the CLI.
Reviewed changes
Copilot reviewed 8 out of 9 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| pnpm-workspace.yaml | Adds scoped overrides to prevent vulnerable transitive downgrades (minimatch/yaml) introduced by docusaurus-plugin-llms. |
| package.json | Updates root dev-tooling dependencies (eslint, semantic-release plugins, turbo, wrangler, etc.). |
| docs/package.json | Updates docs deps including material-symbols and docusaurus-plugin-llms. |
| bulma-ui/package.json | Updates bulma-ui devDependencies (storybook suite, jest-dom, playwright, rollup, sass, eslint). |
| create-bestax/src/index.ts | Moves Node version guard ahead of any static imports and uses dynamic import + top-level await for the CLI load. |
| create-bestax/package.json | Bumps CLI dependencies (chalk/fs-extra/etc.) and raises engines.node to >=22. |
| bestax-migrate/src/index.ts | Moves Node version guard ahead of any static imports and uses dynamic import + top-level await for the CLI load. |
| bestax-migrate/package.json | Bumps chalk and raises engines.node to >=22. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Deep review — 0 blocking · 1 advisory
| # | Severity | Area | Finding | Location |
|---|---|---|---|---|
| 1 | 🔵 Advisory | Robustness | This PR triggers two live major releases (create-bestax@4, bestax-migrate@2) and simultaneously bumps the release-path plugins @semantic-release/changelog 6→7 and @semantic-release/git 10→11; that combination could not be exercised here (no network / no real --dry-run). Relies on the author's stated dry-run. | package.json:34-35 |
Overall: The change is sound. The dependency bumps are mechanical, and the one piece of real logic (restructuring both CLI entry points to run the Node-version guard before any static import) is correct: on a rejected runtime the guard prints its message and process.exit(1)s before the top-level await import('./cli.js') ever loads chalk 6 (whose engines.node I confirmed is >=22). Both packages build, create-bestax passes 206/206 and bestax-migrate 184/185 (the lone failure is an environmental e2e needing the workspace lib built, not this PR). The riskiest surface is the release machinery, since this PR itself fires the releases; that is where a human should focus, ideally a real semantic-release --dry-run on the CI Node before merge.
Residual risk:
- Security regression re-entering the tree — refuted: lockfile resolves yaml@2 to 2.9.0 and minimatch@9 to 9.0.9 via the two new scoped overrides; the only other minimatch copies are 10.2.5 and 3.1.5 (the ReDoS fix landed in 3.0.5, so 3.1.5 is patched). Consistent with the claimed "0 high".
- CLI breaking on a supported runtime — refuted: compiled dist/index.js shows the guard ahead of the dynamic import, no eager chalk/commander/figures load; the friendly message reaches all Node >=14.8 (top-level await parses there), well below the new 22 floor. Only truly ancient (<14.8, decade-EOL) Node would surface a parse error instead of the message, which is acceptable.
- Silent breakage of the shipped llms.txt surface (docusaurus-plugin-llms 0.4 to 0.5, which pins deps exactly) — refuted: every option the config passes (generateLLMsTxt, generateLLMsFullTxt, generateMarkdownFiles, excludeImports, removeDuplicateHeadings, includeOrder, includeUnmatchedLast, docsDir, ...) still exists in the installed 0.5.1 types/lib.
🏄 Pure lockfile-and-guard cleanup, dude, no gnarly surprises in the break. Chalk 6 rides the Node-22 wave and the guard bails out clean before it ever paddles out. Merge it with a merge commit like the sign says and you are golden.
Documents the Node floor in the package README, which had no requirements section at all. The implementation landed in #447 (chalk ^6.0.0, engines.node >=22, and a version guard that no longer depends on chalk to report a too-old runtime). That PR was squash-merged, which collapsed its three scoped commits into a single `chore(deps)` commit, so the release signal was lost and none of it was ever published. This commit carries that signal. BREAKING CHANGE: create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
Documents the Node floor in the package README, which had no requirements section at all. The implementation landed in #447 (chalk ^6.0.0, engines.node >=22, and a version guard that no longer depends on chalk to report a too-old runtime). That PR was squash-merged, which collapsed its three scoped commits into a single `chore(deps)` commit, so the release signal was lost. Without this footer the next release would have been computed as a patch from the four fix(bestax-migrate) commits still queued since 1.0.0 — publishing a raised Node floor and a chalk major inside a 1.0.1, which is exactly wrong. BREAKING CHANGE: bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. This applies to the runtime the codemod executes on, not to the app being migrated. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
# [4.0.0](https://github.com/allxsmith/bestax/compare/create-bestax@3.8.0...create-bestax@4.0.0) (2026-08-01) ### Bug Fixes * **bestax-migrate:** give the kitchen-sink e2e a per-process scratch dir ([2211ea5](2211ea5)) * **bestax-migrate:** reject pnpm's workspace alias form instead of unwrapping it ([de6a900](de6a900)) * **bestax-migrate:** require the pack script to exist, not just be named ([5315efe](5315efe)) * **bestax-migrate:** resolve bare workspace: and guard the catalog: protocol ([7fda9db](7fda9db)), closes [#417](#417) [#412](#412) * **bestax-migrate:** resolve workspace: specifiers before publishing ([782829a](782829a)), closes [bestax-migrate#test](https://github.com/bestax-migrate/issues/test) [#412](#412) * **bestax-migrate:** stop the pack hooks excusing a catalog: devDependency ([4127ead](4127ead)), closes [#412-shaped](#412) * **docs:** stop cssnano stripping Font Awesome [@font-face](https://github.com/font-face), add [#3](#3) CSS framework blog post ([#401](#401)) ([5d114e1](5d114e1)), closes [#400](#400) ### chore * **deps:** consolidate the dependabot backlog, require Node 22 in both CLIs ([#447](#447)) ([e68148c](e68148c)), closes [#427](#427) [#428](#428) [#431](#431) [#432](#432) [#440](#440) [#393](#393) ### Features * **bestax-migrate:** require Node 22 and take chalk 6 ([#449](#449)) ([4c0e1e2](4c0e1e2)), closes [#447](#447) * **create-bestax:** require Node 22 and take chalk 6 ([#448](#448)) ([90fced2](90fced2)), closes [#447](#447) ### BREAKING CHANGES * **bestax-migrate:** bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. This applies to the runtime the codemod executes on, not to the app being migrated. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * **create-bestax:** create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * **deps:** create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * feat(bestax-migrate): require Node 22 and take chalk 6 chalk 6 drops support for Node below 22. The API surface this package uses is unchanged, so no calling code changes. The version guard in src/index.ts moves ahead of every import and no longer depends on anything: import declarations are hoisted and evaluated before any statement in the module, and chalk 6 itself requires Node >= 22, so a static import would fail to load on exactly the runtimes the guard exists to catch. ./cli.js is now imported dynamically for the same reason. @babel/parser deliberately stays on 7.x. Babel 8 removes the `deprecatedImportAssert` plugin with no replacement, and this package parses the legacy `import x from 'y' assert { type: 'json' }` form on purpose — a codemod that migrates older codebases must not crash on the syntax those codebases still contain. There is a regression test for it ("parses the legacy import-assert syntax"), which Babel 8 fails outright. jscodeshift 17 bundles its own Babel 7 regardless, so staying on 7 also keeps a single parser in the tree rather than two. * **deps:** bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
|
🎉 This PR is included in version 4.0.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
# [2.0.0](https://github.com/allxsmith/bestax/compare/bestax-migrate@1.0.0...bestax-migrate@2.0.0) (2026-08-01) ### Bug Fixes * **bestax-migrate:** give the kitchen-sink e2e a per-process scratch dir ([2211ea5](2211ea5)) * **bestax-migrate:** reject pnpm's workspace alias form instead of unwrapping it ([de6a900](de6a900)) * **bestax-migrate:** require the pack script to exist, not just be named ([5315efe](5315efe)) * **bestax-migrate:** resolve bare workspace: and guard the catalog: protocol ([7fda9db](7fda9db)), closes [#417](#417) [#412](#412) * **bestax-migrate:** resolve workspace: specifiers before publishing ([782829a](782829a)), closes [bestax-migrate#test](https://github.com/bestax-migrate/issues/test) [#412](#412) * **bestax-migrate:** stop the pack hooks excusing a catalog: devDependency ([4127ead](4127ead)), closes [#412-shaped](#412) * **create-bestax:** concrete inline-style → helper-prop mapping for the never-inline rule ([#357](#357)) ([5f72a90](5f72a90)), closes [#350](#350) [#350](#350) * **docs:** stop cssnano stripping Font Awesome [@font-face](https://github.com/font-face), add [#3](#3) CSS framework blog post ([#401](#401)) ([5d114e1](5d114e1)), closes [#400](#400) ### chore * **deps:** consolidate the dependabot backlog, require Node 22 in both CLIs ([#447](#447)) ([e68148c](e68148c)), closes [#427](#427) [#428](#428) [#431](#431) [#432](#432) [#440](#440) [#393](#393) ### Features * **bestax-migrate:** require Node 22 and take chalk 6 ([#449](#449)) ([4c0e1e2](4c0e1e2)), closes [#447](#447) * **bulma-ui:** ship agent-discovery files in the npm tarball ([#345](#345)) ([4b58739](4b58739)), closes [#344](#344) [#344](#344) [#344](#344) * **create-bestax:** add controlled-Burger Navbar to the landing archetype ([#355](#355)) ([36d4d09](36d4d09)), closes [#348](#348) * **create-bestax:** agent-validated guidance for skills, scaffold CLAUDE.md, and catalog ([#365](#365)) ([6fd06ae](6fd06ae)), closes [#2](#2) * **create-bestax:** require Node 22 and take chalk 6 ([#448](#448)) ([90fced2](90fced2)), closes [#447](#447) * **create-bestax:** scaffold .claude/launch.json with the AI skills opt-in ([#343](#343)) ([189135a](189135a)) * **create-bestax:** set scaffolded index.html title to the project name ([#356](#356)) ([3bfbea3](3bfbea3)), closes [#349](#349) [#349](#349) ### BREAKING CHANGES * **bestax-migrate:** bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. This applies to the runtime the codemod executes on, not to the app being migrated. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * **create-bestax:** create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * **deps:** create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * feat(bestax-migrate): require Node 22 and take chalk 6 chalk 6 drops support for Node below 22. The API surface this package uses is unchanged, so no calling code changes. The version guard in src/index.ts moves ahead of every import and no longer depends on anything: import declarations are hoisted and evaluated before any statement in the module, and chalk 6 itself requires Node >= 22, so a static import would fail to load on exactly the runtimes the guard exists to catch. ./cli.js is now imported dynamically for the same reason. @babel/parser deliberately stays on 7.x. Babel 8 removes the `deprecatedImportAssert` plugin with no replacement, and this package parses the legacy `import x from 'y' assert { type: 'json' }` form on purpose — a codemod that migrates older codebases must not crash on the syntax those codebases still contain. There is a regression test for it ("parses the legacy import-assert syntax"), which Babel 8 fails outright. jscodeshift 17 bundles its own Babel 7 regardless, so staying on 7 also keeps a single parser in the tree rather than two. * **deps:** bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
|
🎉 This PR is included in version 2.0.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
## [5.8.1](https://github.com/allxsmith/bestax/compare/@allxsmith/bestax-bulma@5.8.0...@allxsmith/bestax-bulma@5.8.1) (2026-08-07) ### Bug Fixes * **bestax-migrate:** give the kitchen-sink e2e a per-process scratch dir ([2211ea5](2211ea5)) * **bestax-migrate:** reject pnpm's workspace alias form instead of unwrapping it ([de6a900](de6a900)) * **bestax-migrate:** require the pack script to exist, not just be named ([5315efe](5315efe)) * **bestax-migrate:** resolve bare workspace: and guard the catalog: protocol ([7fda9db](7fda9db)), closes [#417](#417) [#412](#412) * **bestax-migrate:** resolve workspace: specifiers before publishing ([782829a](782829a)), closes [bestax-migrate#test](https://github.com/bestax-migrate/issues/test) [#412](#412) * **bestax-migrate:** stop the pack hooks excusing a catalog: devDependency ([4127ead](4127ead)), closes [#412-shaped](#412) * **bulma-ui:** deprecate CSS-less color values, warn in dev, fix has-text fall-through ([fb111eb](fb111eb)) * **bulma-ui:** fail closed on missing process and scope color guidance to real props ([117c0c0](117c0c0)) * **create-bestax:** concrete inline-style → helper-prop mapping for the never-inline rule ([#357](#357)) ([5f72a90](5f72a90)), closes [#350](#350) [#350](#350) * **create-bestax:** validate at submit in the bestax-form signup example ([0b9518f](0b9518f)) * **create-bestax:** wire labeled controls in the skill showcase story ([af49a16](af49a16)) * **docs:** announce the hero copy, and stop remounting the icons ([98e2cb0](98e2cb0)), closes [#434](#434) * **docs:** correct the frozen-install translation and reject leaked fences ([1883de3](1883de3)) * **docs:** drop dead nomodule ionicons fallback ([82be3e4](82be3e4)) * **docs:** harden PackageManagerTabs and document how to author it ([5b0d3e6](5b0d3e6)), closes [#434](#434) * **docs:** harden the hero copy button and share the tab storage key ([9e16cd7](9e16cd7)) * **docs:** make the hero package-manager switcher a real radiogroup ([aa14ff2](aa14ff2)), closes [#434](#434) * **docs:** stop cssnano stripping Font Awesome [@font-face](https://github.com/font-face), add [#3](#3) CSS framework blog post ([#401](#401)) ([5d114e1](5d114e1)), closes [#400](#400) ### chore * **deps:** consolidate the dependabot backlog, require Node 22 in both CLIs ([#447](#447)) ([e68148c](e68148c)), closes [#427](#427) [#428](#428) [#431](#431) [#432](#432) [#440](#440) [#393](#393) ### Features * **bestax-migrate:** require Node 22 and take chalk 6 ([#449](#449)) ([4c0e1e2](4c0e1e2)), closes [#447](#447) * **create-bestax:** add controlled-Burger Navbar to the landing archetype ([#355](#355)) ([36d4d09](36d4d09)), closes [#348](#348) * **create-bestax:** agent-validated guidance for skills, scaffold CLAUDE.md, and catalog ([#365](#365)) ([6fd06ae](6fd06ae)), closes [#2](#2) * **create-bestax:** require Node 22 and take chalk 6 ([#448](#448)) ([90fced2](90fced2)), closes [#447](#447) * **create-bestax:** set scaffolded index.html title to the project name ([#356](#356)) ([3bfbea3](3bfbea3)), closes [#349](#349) [#349](#349) * **docs:** add package-manager switches to the homepage hero ([374caf8](374caf8)) * **docs:** add PackageManagerTabs and register it globally ([23c9989](23c9989)) * **docs:** show all posts in the blog sidebar ([d29e9c6](d29e9c6)) ### Performance Improvements * **docs:** defer live previews until they scroll into view ([d6bf87b](d6bf87b)) * **docs:** share one parsed stylesheet set across every live preview ([feb993a](feb993a)) ### BREAKING CHANGES * **bestax-migrate:** bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. This applies to the runtime the codemod executes on, not to the app being migrated. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * **create-bestax:** create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * **deps:** create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * feat(bestax-migrate): require Node 22 and take chalk 6 chalk 6 drops support for Node below 22. The API surface this package uses is unchanged, so no calling code changes. The version guard in src/index.ts moves ahead of every import and no longer depends on anything: import declarations are hoisted and evaluated before any statement in the module, and chalk 6 itself requires Node >= 22, so a static import would fail to load on exactly the runtimes the guard exists to catch. ./cli.js is now imported dynamically for the same reason. @babel/parser deliberately stays on 7.x. Babel 8 removes the `deprecatedImportAssert` plugin with no replacement, and this package parses the legacy `import x from 'y' assert { type: 'json' }` form on purpose — a codemod that migrates older codebases must not crash on the syntax those codebases still contain. There is a regression test for it ("parses the legacy import-assert syntax"), which Babel 8 fails outright. jscodeshift 17 bundles its own Babel 7 regardless, so staying on 7 also keeps a single parser in the tree rather than two. * **deps:** bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh
|
🎉 This PR is included in version 5.8.1 🎉 The release is available on: Your semantic-release bot 📦🚀 |
# 1.0.0 (2026-08-12) * feat(bulma-ui)!: remove bestax-bulma-prefixed CSS variant ([94baa34](94baa34)) * feat(create-bestax)!: require Node.js 18+ and align with bestax-bulma v2 ([#118](#118)) ([b22f183](b22f183)) ### Bug Fixes * add comprehensive rules to prevent bulma-ui versioning on non-bulma-ui commits ([#122](#122)) ([525ccfa](525ccfa)), closes [#119](#119) * **bestax-mcp:** derive the near-miss guidance from the skill, and only when it helps ([1141cca](1141cca)) * **bestax-mcp:** do not split a helper-prop table cell on an escaped pipe ([bdac820](bdac820)) * **bestax-mcp:** lead get_helper_props with the inline-style prohibition ([ffc627a](ffc627a)) * **bestax-mcp:** make list_components point at the next step ([8ddb2fd](8ddb2fd)) * **bestax-mcp:** make tests and cached builds work from a clean checkout ([6e63820](6e63820)), closes [bestax-mcp#build](https://github.com/bestax-mcp/issues/build) * **bestax-mcp:** name list_components as the entry point, not search_bestax ([206380b](206380b)) * **bestax-mcp:** name the three near-miss components in the list_components footer ([1c7af67](1c7af67)) * **bestax-mcp:** route helper questions to the tool that answers them ([cd6ce12](cd6ce12)) * **bestax-mcp:** validate the one input that is not ours, and bound the rest ([3e1adc9](3e1adc9)) * **bestax-migrate:** give the kitchen-sink e2e a per-process scratch dir ([2211ea5](2211ea5)) * **bestax-migrate:** reject pnpm's workspace alias form instead of unwrapping it ([de6a900](de6a900)) * **bestax-migrate:** require the pack script to exist, not just be named ([5315efe](5315efe)) * **bestax-migrate:** resolve bare workspace: and guard the catalog: protocol ([7fda9db](7fda9db)), closes [#417](#417) [#412](#412) * **bestax-migrate:** resolve workspace: specifiers before publishing ([782829a](782829a)), closes [bestax-migrate#test](https://github.com/bestax-migrate/issues/test) [#412](#412) * **bestax-migrate:** stop the pack hooks excusing a catalog: devDependency ([4127ead](4127ead)), closes [#412-shaped](#412) * **bulma-ui:** a11y + case-insensitive Taginput matching from PR review ([d576829](d576829)) * **bulma-ui:** accept router props like `to` on Navbar.Item without casts ([#311](#311)) ([b78856b](b78856b)), closes [#306](#306) * **bulma-ui:** Add build step to publish in ci.yml ([e3707fc](e3707fc)) * **bulma-ui:** add fontawesome-free as explicit devDependency ([a4a5389](a4a5389)) * **bulma-ui:** add missing exports ([0d16633](0d16633)) * **bulma-ui:** Add Skeleton to exports ([e481599](e481599)) * **bulma-ui:** another attempt to fix semantic release builds with ci.yml ([cc3a3e2](cc3a3e2)) * **bulma-ui:** another attempt to fix semantic release builds with ci.yml ([314bc39](314bc39)) * **bulma-ui:** another attempt to fix semantic release builds with ci.yml ([c930693](c930693)) * **bulma-ui:** associate Autocomplete and Taginput labels with their inner inputs ([7ae37d4](7ae37d4)) * **bulma-ui:** associate Autocomplete and Taginput labels with their inner inputs ([384bd38](384bd38)) * **bulma-ui:** associate the form label prop with its control via a generated id ([e6686af](e6686af)) * **bulma-ui:** complete domain migration and fix semantic-release configuration ([#64](#64)) ([f4cd71d](f4cd71d)) * **bulma-ui:** correct blog post examples and add Modal compound components ([#81](#81)) ([559c2e3](559c2e3)) * **bulma-ui:** correct NPM_TOKEN env variable in ci.yml ([94b48b4](94b48b4)) * **bulma-ui:** cover horizontal-layout group label association ([ef3ca9f](ef3ca9f)) * **bulma-ui:** deprecate CSS-less color values, warn in dev, fix has-text fall-through ([fb111eb](fb111eb)) * **bulma-ui:** fail closed on missing process and scope color guidance to real props ([117c0c0](117c0c0)) * **bulma-ui:** Fix release.config.js to include package-lock.json ([390da59](390da59)) * **bulma-ui:** fix standalone Badge pointer-events, pulse halo, and falsy content ([#295](#295)) ([a9db031](a9db031)), closes [#264](#264) * **bulma-ui:** full classPrefix support across layout/grid + prefix utils ([4ce0b53](4ce0b53)) * **bulma-ui:** honor the htmlFor opt-out in the convenience hook and tighten the association docs ([92aa622](92aa622)) * **bulma-ui:** improve npm package discoverability with optimized keywords and badges ([#72](#72)) ([8c7a696](8c7a696)) * **bulma-ui:** Initial semantic release changes ([b78d785](b78d785)) * **bulma-ui:** keep Taginput's fallback name unless the label targets its input ([73cec33](73cec33)) * **bulma-ui:** keep Taginput's fallback name unless the label targets its input ([ca5996a](ca5996a)) * **bulma-ui:** migrate domain from bestax.cc to bestax.io ([#64](#64)) ([4870b1e](4870b1e)) * **bulma-ui:** migrate ionicons to v8 to unblock publish and Storybook ([927a55b](927a55b)), closes [#142](#142) * **bulma-ui:** name Rate, Checkboxes, and Radios groups from their labels via aria-labelledby ([dce0ee7](dce0ee7)) * **bulma-ui:** name Rate, Checkboxes, and Radios groups from their labels via aria-labelledby ([#497](#497)) ([5c4222e](5c4222e)) * **bulma-ui:** name the three near-miss components in AGENTS.md ([c63f491](c63f491)), closes [#344](#344) * **bulma-ui:** never let labelProps.htmlFor wire a group label to a control ([3b3aaaf](3b3aaaf)) * **bulma-ui:** publish rewritten README to npm ([9810081](9810081)) * **bulma-ui:** publish with npm provenance attestation ([172da62](172da62)), closes [#180](#180) * **bulma-ui:** reference llms docs from README and package.json ([#198](#198)) ([db8aab3](db8aab3)) * **bulma-ui:** reject predicate-blocked values during manual entry ([a8f6e28](a8f6e28)) * **bulma-ui:** resolve flex item properties and Card compound component issues ([#55](#55)) ([e774da3](e774da3)) * **bulma-ui:** resolve flex item properties and Card compound component issues ([#55](#55)) ([7641a53](7641a53)) * **bulma-ui:** resolve react-hooks v7 and [@eslint-react](https://github.com/eslint-react) findings ([14caaaf](14caaaf)) * **bulma-ui:** resolve security vulnerabilities and update dependencies ([#128](#128)) ([112f6e4](112f6e4)), closes [#127](#127) * **bulma-ui:** restrict semantic-release to bulma-ui scoped commits only ([2d67bf9](2d67bf9)), closes [#62](#62) * **bulma-ui:** retry failed Avatar src, flatten Fragment children in Avatars, RTL-safe overlap ([#297](#297)) ([c00b9db](c00b9db)) * **bulma-ui:** route every hardcoded class through the prefix helpers; add classPrefix sweep test ([#301](#301)) ([a50b134](a50b134)), closes [#286](#286) * **bulma-ui:** setup gpg signing with semantic-release ([3e24722](3e24722)) * **bulma-ui:** strip redundant library prefix from Icon name ([#242](#242)) ([dbe3622](dbe3622)), closes [#189](#189) * **bulma-ui:** trigger release to publish via OIDC trusted publishing ([e2d09c5](e2d09c5)) * **bulma-ui:** update bundle size claims to accurate 21KB gzipped ([#66](#66)) ([6e381bd](6e381bd)) * **bulma-ui:** update package-lock.json ([853d585](853d585)) * **bulma-ui:** update package.json for better seo, exports, types, engines, funding, etc ([98cbc56](98cbc56)) * **bulma-ui:** use createRequire for ESM compatibility in Storybook 10 ([#130](#130)) ([b27e60e](b27e60e)), closes [#129](#129) * **ci:** collect screenshots as artifacts and commit in single batch to avoid conflicts ([27b259d](27b259d)) * **ci:** ensure npm install uses fresh downloads with --prefer-online ([1f2e15d](1f2e15d)) * **ci:** properly extract base path for recursive file search ([e0330ff](e0330ff)) * **ci:** use find command instead of glob module in verified-commit action ([0e2d159](0e2d159)) * **ci:** use npm ci for scaffolded app dependencies ([35652c8](35652c8)) * **create-bestax:** concrete inline-style → helper-prop mapping for the never-inline rule ([#357](#357)) ([5f72a90](5f72a90)), closes [#350](#350) [#350](#350) * **create-bestax:** correct browser title to prioritize Bestax branding ([#106](#106)) ([23aa535](23aa535)), closes [#105](#105) * **create-bestax:** correct template path resolution from ../../ to ../ ([65b4493](65b4493)), closes [#78](#78) * **create-bestax:** dark-mode contrast rules in theming/layout skills and docs ([#303](#303)) ([490bf21](490bf21)), closes [#194](#194) [#195](#195) * **create-bestax:** exclude templates directory from linting and typecheck ([18fec0b](18fec0b)) * **create-bestax:** fail fast with guidance instead of hanging when stdin is not a TTY ([#293](#293)) ([46a172d](46a172d)), closes [#192](#192) * **create-bestax:** move templates into package directory and update docs ([195bf01](195bf01)), closes [#78](#78) * **create-bestax:** point scaffolded CLAUDE.md at llms docs; document skills ([#198](#198)) ([b2e0514](b2e0514)) * **create-bestax:** publish with npm provenance attestation ([21ffe8f](21ffe8f)), closes [#180](#180) * **create-bestax:** put the near-miss guidance where every session sees it ([6db49f3](6db49f3)) * **create-bestax:** read version from package.json instead of hardcoded value ([#109](#109)) ([8605699](8605699)) * **create-bestax:** refresh README and bump scaffolded bestax-bulma to ^5 ([4e19e86](4e19e86)) * **create-bestax:** reject dot-only project names, pin icon versions, bundle bestax-icons skill ([#310](#310)) ([ddff8e5](ddff8e5)) * **create-bestax:** scaffold @allxsmith/bestax-bulma ^4.0.0 ([1d3b802](1d3b802)) * **create-bestax:** scaffold bundled bestax CSS flavors, not stock Bulma ([43621dc](43621dc)) * **create-bestax:** ship improved bundled skills + component catalog ([#199](#199)) ([a1515c2](a1515c2)) * **create-bestax:** shrink the near-miss block and pin the copies together ([d582da5](d582da5)) * **create-bestax:** skills-sync conformance gate + theming skill reference backfill ([#326](#326)) ([9584133](9584133)), closes [#285](#285) * **create-bestax:** stop the skills teaching a Theme call that does not compile ([2935bb2](2935bb2)) * **create-bestax:** synchronize version with bestax-bulma to 2.4.0 ([623ee79](623ee79)), closes [#96](#96) * **create-bestax:** teach the skills the three components Bulma hides ([22dcff7](22dcff7)) * **create-bestax:** update template dependency to ^2.4.0 ([200971d](200971d)) * **create-bestax:** use scenario-specific screenshot directories to prevent overwrites ([#108](#108)) ([c675957](c675957)), closes [#107](#107) * **create-bestax:** validate at submit in the bestax-form signup example ([0b9518f](0b9518f)) * **create-bestax:** wire labeled controls in the skill showcase story ([af49a16](af49a16)) * **docs:** announce the hero copy, and stop remounting the icons ([98e2cb0](98e2cb0)), closes [#434](#434) * **docs:** correct Content Signals syntax in robots.txt ([#134](#134)) ([85dd9de](85dd9de)) * **docs:** correct the frozen-install translation and reject leaked fences ([1883de3](1883de3)) * **docs:** drop dead nomodule ionicons fallback ([82be3e4](82be3e4)) * **docs:** emit per-page markdown so llms.txt links resolve ([#200](#200)) ([7877083](7877083)) * **docs:** escape apostrophe in QuickStart notification text ([25d6d72](25d6d72)) * **docs:** generate llms.txt so the advertised homepage link resolves ([9fae464](9fae464)), closes [#177](#177) * **docs:** give every batch run its own port — slot reuse was corrupting runs ([6ef1755](6ef1755)) * **docs:** harden PackageManagerTabs and document how to author it ([5b0d3e6](5b0d3e6)), closes [#434](#434) * **docs:** harden the hero copy button and share the tab storage key ([9e16cd7](9e16cd7)) * **docs:** improve homepage hero layout and button spacing ([5f7a5a7](5f7a5a7)) * **docs:** make the eval batch resumable after a container restart ([d56229e](d56229e)) * **docs:** make the hero package-manager switcher a real radiogroup ([aa14ff2](aa14ff2)), closes [#434](#434) * **docs:** move robots.txt to correct deployment location ([#90](#90)) ([1e2aeee](1e2aeee)) * **docs:** rebrand and reorganize Storybook ([#83](#83)) ([dfb9937](dfb9937)) * **docs:** remove Google Analytics and add robots.txt ([94776f7](94776f7)) * **docs:** stop cssnano stripping Font Awesome [@font-face](https://github.com/font-face), add [#3](#3) CSS framework blog post ([#401](#401)) ([5d114e1](5d114e1)), closes [#400](#400) * **docs:** update Storybook logo path to /img/logo.svg for deployed site ([bf59758](bf59758)) * **e2e:** correct notification CSS selectors to use contains instead of ends-with ([182acc1](182acc1)) * implement independent package versioning strategy ([#111](#111)) ([7819c73](7819c73)), closes [#110](#110) * prevent bulma-ui from versioning on create-bestax commits ([#120](#120)) ([4dfaf9c](4dfaf9c)), closes [#119](#119) * resolve React Hooks violations and ESLint configuration issues ([32d2931](32d2931)) * upgrade Turbo, Storybook, and Docusaurus dependencies ([5b4ebdd](5b4ebdd)), closes [#98](#98) ### chore * **deps:** consolidate the dependabot backlog, require Node 22 in both CLIs ([#447](#447)) ([e68148c](e68148c)), closes [#427](#427) [#428](#428) [#431](#431) [#432](#432) [#440](#440) [#393](#393) ### Documentation * fix stale versioning and coverage docs; drop CLAUDE.md stale-docs flags ([71c4583](71c4583)) ### Features * add theme system and config provider with comprehensive test coverage ([f3ca7f0](f3ca7f0)) * **bestax-mcp:** serve component docs, props, examples and skills over MCP ([c2abcc4](c2abcc4)) * **bestax-migrate:** react-bulma-components → bestax-bulma codemod CLI, skill, and docs ([#333](#333)) ([e04a12b](e04a12b)), closes [#1e6b99](https://github.com/allxsmith/bestax/issues/1e6b99) * **bestax-migrate:** require Node 22 and take chalk 6 ([#449](#449)) ([4c0e1e2](4c0e1e2)), closes [#447](#447) * **bulma-ui:** add Avatar, Avatars, and Badge components ([#257](#257)) ([0817018](0817018)), closes [#256](#256) * **bulma-ui:** add colorMode dark-mode prop to Theme ([4acc41e](4acc41e)), closes [#174](#174) * **bulma-ui:** add consistent gap prop to Columns, aliasing gapSize ([#300](#300)) ([6c36455](6c36455)), closes [#282](#282) * **bulma-ui:** add cursor helper, closeDelay prop, and polish Tooltip stories ([37945b5](37945b5)) * **bulma-ui:** add extra components, form elements, and SCSS styles ([59daf28](59daf28)) * **bulma-ui:** add HTML element wrapper components ([#135](#135)) ([#136](#136)) ([20fb16d](20fb16d)) * **bulma-ui:** add manual-entry stories for format, bounds, and blocked-value variations ([e93d51c](e93d51c)) * **bulma-ui:** add Reveal component for scroll-triggered animations ([#255](#255)) ([a89c574](a89c574)) * **bulma-ui:** Add skeletons ([6c46e4b](6c46e4b)) * **bulma-ui:** add themed Checkbox/Radio, convenience Field components, and Autocomplete cleanup ([3c57a5a](3c57a5a)) * **bulma-ui:** add typing-first story variants for all picker property variations ([078433f](078433f)) * **bulma-ui:** associate Field's label with a composed base control ([219f631](219f631)) * **bulma-ui:** avatar/badge a11y batch — decorative alt, accessible names, live region, button type, surplus i18n, focus ring ([#298](#298)) ([508477f](508477f)), closes [#266](#266) [#266](#266) * **bulma-ui:** change the default primary color to [#1](#1 ([8872620](8872620)), closes [#1e6b99](https://github.com/allxsmith/bestax/issues/1e6b99) [#1e6b99](https://github.com/allxsmith/bestax/issues/1e6b99) * **bulma-ui:** compound (dot-notation) sub-components for all parent/child families via shared withSubComponents helper ([#331](#331)) ([07516c5](07516c5)) * **bulma-ui:** dim and blur the calendar behind the Datetimepicker time wheels ([3d90619](3d90619)) * **bulma-ui:** finalize the 3.0 component set ([87ccc0e](87ccc0e)) * **bulma-ui:** make Button and Link as prop polymorphic (React.ElementType) ([#238](#238)) ([ce90304](ce90304)), closes [#188](#188) * **bulma-ui:** require React 18 as the minimum supported version ([c7251b0](c7251b0)) * **bulma-ui:** ship agent-discovery files in the npm tarball ([#345](#345)) ([4b58739](4b58739)), closes [#344](#344) [#344](#344) [#344](#344) * **ci:** add verified-commit action for GPG-signed commits ([d078dfa](d078dfa)) * **create-bestax:** add bestax-optimize skill for shrinking built CSS ([#329](#329)) ([f597b9f](f597b9f)) * **create-bestax:** add CLI tool with Vite templates and automated publishing ([9748c3d](9748c3d)) * **create-bestax:** add controlled-Burger Navbar to the landing archetype ([#355](#355)) ([36d4d09](36d4d09)), closes [#348](#348) * **create-bestax:** add cross-platform emoji support with figures ([#103](#103)) ([15567d9](15567d9)) * **create-bestax:** add README with templates location note ([8ddc73d](8ddc73d)) * **create-bestax:** add visual regression testing and synchronized versioning ([17e1e22](17e1e22)), closes [#94](#94) * **create-bestax:** agent-validated guidance for skills, scaffold CLAUDE.md, and catalog ([#365](#365)) ([6fd06ae](6fd06ae)), closes [#2](#2) * **create-bestax:** bestax-icons skill — teach agents the icon system ([#302](#302)) ([61c8ef2](61c8ef2)), closes [#287](#287) * **create-bestax:** improve favicon visibility and add distinct branding ([621590d](621590d)), closes [#100](#100) * **create-bestax:** modernize templates (Vite 8, ESLint 10, TS 6) + add working lint config ([4537629](4537629)), closes [#167](#167) * **create-bestax:** offer to install the bestax AI skills when scaffolding ([625b7bf](625b7bf)), closes [#174](#174) * **create-bestax:** require Node 22 and take chalk 6 ([#448](#448)) ([90fced2](90fced2)), closes [#447](#447) * **create-bestax:** scaffold .claude/launch.json with the AI skills opt-in ([#343](#343)) ([189135a](189135a)) * **create-bestax:** scaffold-aware CLAUDE.md with setup facts and house style ([#271](#271)) ([c1681b0](c1681b0)) * **create-bestax:** set scaffolded index.html title to the project name ([#356](#356)) ([3bfbea3](3bfbea3)), closes [#349](#349) [#349](#349) * **docs:** add Google Analytics tracking for usage insights ([#68](#68)) ([90ab951](90ab951)) * **docs:** add package-manager switches to the homepage hero ([374caf8](374caf8)) * **docs:** add PackageManagerTabs and register it globally ([23c9989](23c9989)) * **docs:** add pronunciation guide and dark mode support ([#58](#58)) ([48a8916](48a8916)) * **docs:** aggregate-runs.mjs — distribution stats across a runs directory ([5de9c07](5de9c07)) * **docs:** batch runner for the eval harness, with the concurrency fixes it needed ([f8e268c](f8e268c)) * **docs:** migrate from GitHub Pages to Cloudflare Pages ([#132](#132)) ([2154672](2154672)), closes [#131](#131) * **docs:** rubric v2 and a brief that demands the components beyond Bulma ([e6047be](e6047be)) * **docs:** show all posts in the blog sidebar ([d29e9c6](d29e9c6)) * **form:** add Datepicker, Timepicker, and Datetimepicker components ([c6684e6](c6684e6)) ### Performance Improvements * **bestax-mcp:** stop get_helper_props costing half the session ([b865651](b865651)) * **docs:** defer live previews until they scroll into view ([d6bf87b](d6bf87b)) * **docs:** share one parsed stylesheet set across every live preview ([feb993a](feb993a)) ### BREAKING CHANGES * **bestax-migrate:** bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. This applies to the runtime the codemod executes on, not to the app being migrated. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * **create-bestax:** create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * **deps:** create-bestax now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * feat(bestax-migrate): require Node 22 and take chalk 6 chalk 6 drops support for Node below 22. The API surface this package uses is unchanged, so no calling code changes. The version guard in src/index.ts moves ahead of every import and no longer depends on anything: import declarations are hoisted and evaluated before any statement in the module, and chalk 6 itself requires Node >= 22, so a static import would fail to load on exactly the runtimes the guard exists to catch. ./cli.js is now imported dynamically for the same reason. @babel/parser deliberately stays on 7.x. Babel 8 removes the `deprecatedImportAssert` plugin with no replacement, and this package parses the legacy `import x from 'y' assert { type: 'json' }` form on purpose — a codemod that migrates older codebases must not crash on the syntax those codebases still contain. There is a regression test for it ("parses the legacy import-assert syntax"), which Babel 8 fails outright. jscodeshift 17 bundles its own Babel 7 regardless, so staying on 7 also keeps a single parser in the tree rather than two. * **deps:** bestax-migrate now requires Node.js 22 or newer. Node 18 and 20 are both past end-of-life. Running it on an older runtime prints an explicit upgrade message and exits 1. Claude-Session: https://claude.ai/code/session_01TGA6sFTUGsJ6oXhfpjKEnh * footer requirement, and the commitlint scope rule - CONTRIBUTING.md: replace the type-less commit example with a commitlint-valid conventional format (verified against commitlint); correct all four coverage mentions to the real jest thresholds (bulma-ui 99%, create-bestax 95%/78% branches); fix the npm package name (@allxsmith/bestax-bulma, plus create-bestax) and link VERSIONING.md - CLAUDE.md: remove the stale-docs warning and asides now that the underlying docs are correct; point at VERSIONING.md again Closes #206. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0131uD6QKmAij7Byk3SByyLh * the @allxsmith/bestax-bulma/versions/bestax-bulma-prefixed.css export is removed. Use versions/bestax-prefixed.css with classPrefix="bestax-". * **bulma-ui:** React 16 and 17 are no longer supported; the minimum supported React version is now 18. * **bulma-ui:** Snackbar has been removed and merged into Toast; use Toast with its positioning and queue props instead. * **bulma-ui:** form controls now auto-wrap in Field/Control, and Checkbox and Radio ship new themed visuals. See the 2.x -> 3.x migration guide. * This version requires Node.js 18.0.0 or higher. The CLI now enforces this requirement and will exit with an error message if running on older Node.js versions. This aligns create-bestax with the bestax-bulma v2.x ecosystem. * fix(create-bestax): correct Prettier formatting in index.ts * None - all changes are additive and backward compatible
|
🎉 This PR is included in version 1.0.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
…aims bestax-mcp was left out of verify-provenance on the strength of #502, which says CI has no release step for it. That issue is stale: ci.yml has had a `Semantic Release (bestax-mcp)` step since the pipeline change, and 1.0.0 is on the registry with a SLSA provenance attestation. Verified it installs clean alongside the other three, so it belongs in both lists. SECURITY.md's supported-versions table had drifted two majors behind on two packages and never gained a row for the fourth: create-bestax is 4.x not 3.x, bestax-migrate is 2.x not 1.x, and bestax-mcp was missing entirely. Both majors were the Node 22 requirement from #447, not an API break. That table is what tells users which line receives security fixes, so being wrong about it is a security-relevant inaccuracy rather than a docs nit. The provenance bullet said "all three published packages" for the same reason. The docs security guide carried a narrower version of the same claim, naming only two of the four packages.
…aims bestax-mcp was left out of verify-provenance on the strength of #502, which says CI has no release step for it. That issue is stale: ci.yml has had a `Semantic Release (bestax-mcp)` step since the pipeline change, and 1.0.0 is on the registry with a SLSA provenance attestation. Verified it installs clean alongside the other three, so it belongs in both lists. SECURITY.md's supported-versions table had drifted two majors behind on two packages and never gained a row for the fourth: create-bestax is 4.x not 3.x, bestax-migrate is 2.x not 1.x, and bestax-mcp was missing entirely. Both majors were the Node 22 requirement from #447, not an API break. That table is what tells users which line receives security fixes, so being wrong about it is a security-relevant inaccuracy rather than a docs nit. The provenance bullet said "all three published packages" for the same reason. The docs security guide carried a narrower version of the same claim, naming only two of the four packages.
Pull Request
The three commits carry three different scopes. semantic-release keys releases off the scope of
each commit, so squashing collapses them into one and the second package silently never releases.
Description
Consolidates the Dependabot backlog into one PR so the shared
pnpm-lock.yamlis regeneratedonce, instead of merging seven lockfile-touching PRs serially with a Dependabot rebase between
each. Same approach as #393 for #388/#390.
Supersedes and closes #427, #428, #429, #431, #432, #440. #430 is not taken — see below.
@allxsmith/bestax-bulma) — devDependencies only, no releasecreate-bestax)@allxsmith/bestax-docs)bestax-migrate, root toolingRelated Issue(s)
Closes #427
Closes #428
Closes #429
Closes #431
Closes #432
Closes #440
Refs #430
Type of Change
Releases this produces
Verified by running the real
releaseRulesfrom eachrelease.config.jsagainst the actualcommits on this branch:
@allxsmith/bestax-bulmacreate-bestaxbestax-migratebestax-migrate@2.0.0also carries the four pendingfix(bestax-migrate)commits from#412/#417 that have been waiting on the publishing outage.
Commit 1 —
chore(deps), no release#427, #428, #431, #432 and the 16 clean bumps from #440, plus two new
pnpm-workspace.yamloverrides.
Why #440 was red. One line:
docusaurus-plugin-llms^0.4.0 → ^0.5.1. From 0.5.0 thatplugin pins its own dependencies exactly (
"minimatch": "9.0.3"rather than"^9.0.3"), sothe range no longer floats to a patched release the way it did on 0.4.x. That dragged
minimatchback from 9.0.9 to 9.0.3 — inside three high ReDoS advisories(GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj, GHSA-23c5-xmqv-rm74) — and
yamlfrom 2.9.0 to2.8.1 (GHSA-48c2-rrv3-qjmp). That failed both
pnpm audit --audit-level=highandDependency Review, which rejected the same three GHSAs viafail-on-severity: high.Two scoped overrides restore the patched versions, matching how
serialize-javascript,sharp,postcssandbrace-expansionare already handled. Scoped to the affected major sothe
minimatch10.x elsewhere in the tree is untouched.pnpm audit --audit-level=highisback to main's exact baseline: 1 low, 3 moderate, 0 high.
@semantic-release/changelog7 and@semantic-release/git11 are the same CJS→ESM wave andare taken together. Every option the release configs actually pass (
changelogFile,assets,message) is unchanged, and both declare asemantic-releasepeer of>=20.1.0, satisfied by^25.0.8. Verified by a--dry-runthat loads every plugin successfully.@testing-library/jest-dom7 removes no matchers; the new required peer@testing-library/domis already resolved at 10.4.1 via@testing-library/react.Commits 2 and 3 — Node 22 floors (breaking)
chalk 6 drops Node < 22. The API surface both CLIs use is unchanged — every call site is a
default import using
.red/.yellow/.green— so no calling code changes. Raisingengines.nodebrings the manifests in line with what the docs already claim:docs/docs/guides/getting-started/installation.mdhas said "Node.js: 22.0.0 or higher" allalong. Node 18 and 20 are both past end-of-life.
Both version guards moved ahead of every import and no longer use chalk. Import declarations
are hoisted and evaluated before any statement in the module, and chalk 6 itself requires
Node ≥ 22 — so a static import would fail to load on exactly the runtimes the guard exists to
catch, replacing a clear upgrade message with an opaque loader error.
./cli.jsis nowimported dynamically for the same reason.
Why #430 (
@babel/parser7 → 8) is not includedBabel 8 removes the
deprecatedImportAssertplugin with no replacement, soimport data from './data.json' assert { type: 'json' }no longer parses.bestax-migratesupports that syntax deliberately —
runner.tssays so, and there is a dedicated regressiontest, "parses the legacy import-assert syntax", which also asserts the assertion survives
into the output. Babel 8 fails it with
SyntaxError: Missing semicolon.A codemod that migrates older codebases must not crash on the syntax those codebases still
contain, so this is a real capability loss rather than a config detail. Babel 8 additionally
removes the
pipelineOperatorminimalproposal, which throws at runtime rather than beingignored. jscodeshift 17 bundles its own Babel 7 regardless, so staying on 7 also keeps a single
parser in the tree instead of two. Recommend closing #430.
Checklist
Verification run locally
pnpm all— clean (build, typecheck, test, coverage, bundle:stats, lint, format:check, storybook)pnpm audit --audit-level=high— 0 highpnpm run check:conformance— 0 violations;gen:catalog:checkclean;check:urlsall 6 resolvepnpm --filter bestax-migrate validate:corpus— 0 crashes, 31/32 transformed, no unknown-component TODOsdist/after the entry-point restructureAdditional Context
Test and Preview Deploymentwas red on all eight Dependabot PRs and is unrelated to any ofthem: GitHub scopes Dependabot
pull_requestruns to the separate Dependabot secrets store,so
CLOUDFLARE_API_TOKENis empty and wrangler aborts. Across the last 60 runs of thatworkflow, every
dependabot[bot]run failed and every human run passed. It is not a requiredcheck. Worth silencing separately with an
if: github.actor != 'dependabot[bot]'guard on thetest-deployjob.