Skip to content

chore: bump the all group across 1 directory with 9 updates - #5

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/all-00b09de5f4
Jul 25, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/all-00b09de5f4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the all group with 9 updates in the / directory:

Package From To
@radix-ui/react-accordion 1.2.12 1.2.20
@radix-ui/react-tabs 1.1.13 1.1.21
@radix-ui/react-tooltip 1.2.8 1.2.16
@tailwindcss/vite 4.3.0 4.3.3
@tanstack/react-query 5.101.0 5.101.4
uuid 14.0.0 14.0.1
@types/jszip 3.4.0 3.4.1
autoprefixer 10.5.0 10.5.4
tailwindcss 4.3.0 4.3.3

Updates @radix-ui/react-accordion from 1.2.12 to 1.2.20

Changelog

Sourced from @​radix-ui/react-accordion's changelog.

1.2.20

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-collapsible@1.1.20, @radix-ui/react-collection@1.1.15, @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-direction@1.1.4, @radix-ui/react-id@1.1.4, @radix-ui/react-primitive@2.1.10, @radix-ui/react-use-controllable-state@1.2.6

1.2.19

  • Updated dependencies: @radix-ui/react-collection@1.1.14, @radix-ui/react-primitive@2.1.9, @radix-ui/react-collapsible@1.1.19

1.2.18

  • Republish through CI to attach provenance attestations. The previous versions of these packages were published manually outside of CI and therefore shipped without provenance; this patch re-releases the same code through the CI pipeline so every package includes an attestation.
  • Updated dependencies: @radix-ui/primitive@1.1.7, @radix-ui/react-collapsible@1.1.18, @radix-ui/react-collection@1.1.13, @radix-ui/react-compose-refs@1.1.4, @radix-ui/react-context@1.2.1, @radix-ui/react-direction@1.1.3, @radix-ui/react-id@1.1.3, @radix-ui/react-primitive@2.1.8, @radix-ui/react-use-controllable-state@1.2.5

1.2.17

  • Improved tree-shaking so bundlers can drop unused components. Component parts are now marked /* @__PURE__ */ and use named render functions instead of Component.displayName = ... assignments, which previously prevented dead-code elimination with some bundlers.
  • Updated dependencies: @radix-ui/react-collapsible@1.1.17, @radix-ui/react-use-controllable-state@1.2.4, @radix-ui/primitive@1.1.6, @radix-ui/react-collection@1.1.12, @radix-ui/react-compose-refs@1.1.3, @radix-ui/react-context@1.2.0, @radix-ui/react-direction@1.1.2, @radix-ui/react-id@1.1.2, @radix-ui/react-primitive@2.1.7

1.2.16

  • Updated dependencies: @radix-ui/primitive@1.1.5, @radix-ui/react-context@1.2.0, @radix-ui/react-collapsible@1.1.16, @radix-ui/react-collection@1.1.12

1.2.15

  • Updated dependencies: @radix-ui/react-primitive@2.1.7, @radix-ui/react-collapsible@1.1.15, @radix-ui/react-collection@1.1.11

1.2.14

  • Fixed Duplicate index signature errors that surfaced when consuming multiple packages together.
  • Updated dependencies: @radix-ui/react-primitive@2.1.6, @radix-ui/react-collection@1.1.10, @radix-ui/react-collapsible@1.1.14

1.2.13

  • Added repository.directory to all package.json files
  • Updated dependencies: @radix-ui/react-collapsible@1.1.13, @radix-ui/react-collection@1.1.9, @radix-ui/react-direction@1.1.2, @radix-ui/primitive@1.1.4, @radix-ui/react-compose-refs@1.1.3, @radix-ui/react-context@1.1.4, @radix-ui/react-id@1.1.2, @radix-ui/react-primitive@2.1.5, @radix-ui/react-use-controllable-state@1.2.3
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​radix-ui/react-accordion since your current version.


Updates @radix-ui/react-tabs from 1.1.13 to 1.1.21

Changelog

Sourced from @​radix-ui/react-tabs's changelog.

1.1.21

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-context@1.2.2, @radix-ui/react-direction@1.1.4, @radix-ui/react-id@1.1.4, @radix-ui/react-presence@1.1.10, @radix-ui/react-primitive@2.1.10, @radix-ui/react-roving-focus@1.1.19, @radix-ui/react-use-controllable-state@1.2.6

1.1.20

  • Updated dependencies: @radix-ui/react-primitive@2.1.9, @radix-ui/react-roving-focus@1.1.18

1.1.19

  • Republish through CI to attach provenance attestations. The previous versions of these packages were published manually outside of CI and therefore shipped without provenance; this patch re-releases the same code through the CI pipeline so every package includes an attestation.
  • Updated dependencies: @radix-ui/primitive@1.1.7, @radix-ui/react-context@1.2.1, @radix-ui/react-direction@1.1.3, @radix-ui/react-id@1.1.3, @radix-ui/react-presence@1.1.9, @radix-ui/react-primitive@2.1.8, @radix-ui/react-roving-focus@1.1.17, @radix-ui/react-use-controllable-state@1.2.5

1.1.18

  • Improved tree-shaking so bundlers can drop unused components. Component parts are now marked /* @__PURE__ */ and use named render functions instead of Component.displayName = ... assignments, which previously prevented dead-code elimination with some bundlers.
  • Updated dependencies: @radix-ui/react-presence@1.1.8, @radix-ui/react-roving-focus@1.1.16, @radix-ui/react-use-controllable-state@1.2.4, @radix-ui/primitive@1.1.6, @radix-ui/react-context@1.2.0, @radix-ui/react-direction@1.1.2, @radix-ui/react-id@1.1.2, @radix-ui/react-primitive@2.1.7

1.1.17

  • Fixed menu items, tab triggers, toolbar links, and select items intercepting Space/Enter keys that originate from focusable descendants.
  • Updated dependencies: @radix-ui/primitive@1.1.5, @radix-ui/react-context@1.2.0, @radix-ui/react-roving-focus@1.1.15, @radix-ui/react-presence@1.1.7

1.1.16

  • Updated dependencies: @radix-ui/react-primitive@2.1.7, @radix-ui/react-roving-focus@1.1.14

1.1.15

  • Updated dependencies: @radix-ui/react-primitive@2.1.6, @radix-ui/react-roving-focus@1.1.13

1.1.14

  • Fixed triggers referencing a non-existent element via aria-controls when their content is removed from the DOM (credit to @​dodomorandi for the original PR)
  • Added repository.directory to all package.json files
  • Updated dependencies: @radix-ui/react-presence@1.1.6, @radix-ui/react-direction@1.1.2, @radix-ui/primitive@1.1.4, @radix-ui/react-context@1.1.4, @radix-ui/react-id@1.1.2, @radix-ui/react-primitive@2.1.5, @radix-ui/react-roving-focus@1.1.12, @radix-ui/react-use-controllable-state@1.2.3
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​radix-ui/react-tabs since your current version.


Updates @radix-ui/react-tooltip from 1.2.8 to 1.2.16

Changelog

Sourced from @​radix-ui/react-tooltip's changelog.

1.2.16

  • Reverted breaking changes that caused compatibility issues with React Server Components.
  • Updated dependencies: @radix-ui/react-compose-refs@1.1.5, @radix-ui/react-context@1.2.2, @radix-ui/react-dismissable-layer@1.1.19, @radix-ui/react-id@1.1.4, @radix-ui/react-popper@1.3.7, @radix-ui/react-portal@1.1.17, @radix-ui/react-presence@1.1.10, @radix-ui/react-primitive@2.1.10, @radix-ui/react-slot@1.3.3, @radix-ui/react-use-controllable-state@1.2.6, @radix-ui/react-use-layout-effect@1.1.4, @radix-ui/react-visually-hidden@1.2.11

1.2.15

  • Updated dependencies: @radix-ui/react-slot@1.3.2, @radix-ui/react-primitive@2.1.9, @radix-ui/react-dismissable-layer@1.1.18, @radix-ui/react-popper@1.3.6, @radix-ui/react-portal@1.1.16, @radix-ui/react-visually-hidden@1.2.10

1.2.14

  • Republish through CI to attach provenance attestations. The previous versions of these packages were published manually outside of CI and therefore shipped without provenance; this patch re-releases the same code through the CI pipeline so every package includes an attestation.
  • Updated dependencies: @radix-ui/primitive@1.1.7, @radix-ui/react-compose-refs@1.1.4, @radix-ui/react-context@1.2.1, @radix-ui/react-dismissable-layer@1.1.17, @radix-ui/react-id@1.1.3, @radix-ui/react-popper@1.3.5, @radix-ui/react-portal@1.1.15, @radix-ui/react-presence@1.1.9, @radix-ui/react-primitive@2.1.8, @radix-ui/react-slot@1.3.1, @radix-ui/react-use-controllable-state@1.2.5, @radix-ui/react-use-layout-effect@1.1.3, @radix-ui/react-visually-hidden@1.2.9

1.2.13

  • Fixed a bug where Tooltip.Content children were mounted to the DOM twice.
  • Improved tree-shaking so bundlers can drop unused components. Component parts are now marked /* @__PURE__ */ and use named render functions instead of Component.displayName = ... assignments, which previously prevented dead-code elimination with some bundlers.
  • Updated dependencies: @radix-ui/react-popper@1.3.4, @radix-ui/react-dismissable-layer@1.1.16, @radix-ui/react-portal@1.1.14, @radix-ui/react-presence@1.1.8, @radix-ui/react-visually-hidden@1.2.8, @radix-ui/react-use-controllable-state@1.2.4, @radix-ui/primitive@1.1.6, @radix-ui/react-compose-refs@1.1.3, @radix-ui/react-context@1.2.0, @radix-ui/react-id@1.1.2, @radix-ui/react-primitive@2.1.7, @radix-ui/react-slot@1.3.0, @radix-ui/react-use-layout-effect@1.1.2

1.2.12

  • Updated dependencies: @radix-ui/react-dismissable-layer@1.1.15, @radix-ui/primitive@1.1.5, @radix-ui/react-context@1.2.0, @radix-ui/react-presence@1.1.7, @radix-ui/react-popper@1.3.3

1.2.11

  • Updated dependencies: @radix-ui/react-primitive@2.1.7, @radix-ui/react-dismissable-layer@1.1.14, @radix-ui/react-popper@1.3.2, @radix-ui/react-portal@1.1.13, @radix-ui/react-visually-hidden@1.2.7

1.2.10

  • Updated dependencies: @radix-ui/react-slot@1.3.0, @radix-ui/react-popper@1.3.1, @radix-ui/react-dismissable-layer@1.1.13, @radix-ui/react-primitive@2.1.6, @radix-ui/react-portal@1.1.12, @radix-ui/react-visually-hidden@1.2.6

1.2.9

  • Fixed runtime error when event target is non-Node
  • Fixed a Tooltip bug so that skipDelayDuration={0} works as expected. Previously, the open delay could still be skipped when moving between triggers.
  • Added repository.directory to all package.json files
  • Updated dependencies: @radix-ui/react-presence@1.1.6, @radix-ui/react-popper@1.3.0, @radix-ui/react-slot@1.2.5, @radix-ui/react-dismissable-layer@1.1.12, @radix-ui/primitive@1.1.4, @radix-ui/react-compose-refs@1.1.3, @radix-ui/react-context@1.1.4, @radix-ui/react-id@1.1.2, @radix-ui/react-portal@1.1.11, @radix-ui/react-primitive@2.1.5, @radix-ui/react-use-controllable-state@1.2.3, @radix-ui/react-visually-hidden@1.2.5
Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​radix-ui/react-tooltip since your current version.


Updates @tailwindcss/vite from 4.3.0 to 4.3.3

Release notes

Sourced from @​tailwindcss/vite's releases.

v4.3.3

Fixed

  • Support --watch --poll[=ms] in @tailwindcss/cli when filesystem events are unreliable or unavailable (#20297)
  • Canonicalization: match arbitrary hex colors against theme colors case-insensitively (e.g. bg-[#fff] and bg-[#FFF] → bg-white) (#20298)
  • Prevent Preflight from overriding Firefox's native iframe:focus-visible outline styles (#20292)
  • Ensure theme('colors.foo') in JS plugins resolves correctly when both --color-foo and --color-foo-bar exist (#20299)
  • Ensure fractional opacity modifiers work with named shadow sizes like shadow-sm/12.5, text-shadow-sm/12.5, drop-shadow-sm/12.5, and inset-shadow-sm/12.5 (#20302)
  • Parse selectors like [data-foo]div as two selectors instead of one (#20303)
  • Ensure @tailwindcss/postcss rebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (#20310)
  • Ensure CSS nesting is handled even when Lightning CSS isn't run, such as in @tailwindcss/browser and Tailwind Play (#20124)
  • Prevent achromatic theme colors from shifting hue when mixed in polar color spaces like oklch (#20314)
  • Ensure --spacing(0) is optimized to 0px instead of 0 so it remains a <length> when used in calc(…) (#20319)
  • Load @parcel/watcher only when needed in @tailwindcss/cli --watch mode, so one-off builds and --watch --poll work when @parcel/watcher can't be loaded (#20325)
  • Use explicit platform fonts instead of system-ui and ui-sans-serif so CJK text respects the page's lang attribute on Windows (#20318)
  • Prevent @tailwindcss/upgrade from rewriting ignored files when run from a subdirectory (#20329)
  • Ensure earlier @source rules pointing to nested files are scanned when later @source rules point to files in parent folders (#20335)
  • Prevent @tailwindcss/vite from triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (#20336)

v4.3.2

Fixed

  • Support bare spacing values for auto-rows-* and auto-cols-* utilities (e.g. auto-rows-12 and auto-cols-16) (#20229)
  • Prevent @tailwindcss/cli in --watch mode from crashing on Windows when @source points to a directory that doesn't exist (#20242)
  • Prevent @tailwindcss/vite from crashing in Deno v2.8.x when context.parentURL is not a valid URL (#20245)
  • Ensure @tailwindcss/cli in --watch mode rebuilds when the input CSS file changes in an ignored directory (#20246)
  • Allow @variant rules used in addBase(…) to use custom variants defined later (#20247)
  • Prevent @tailwindcss/vite from crashing during HMR when scanned files or directories are deleted (#20259)
  • Generate font-size instead of color declarations for text-[--spacing(…)] (#20260)
  • Prevent @source patterns from scanning unrelated sibling files and folders (#20263)
  • Extract class candidates adjacent to Template Toolkit delimiters like %]…[% in .tt, .tt2, and .tx files (#20269)
  • Extract class candidates from conditional Maud syntax like p.text-black[condition] (#20269)
  • Prevent @position-try rules from triggering unknown at-rule warnings when optimizing CSS (#20277)
  • Support class suggestions for named opacity modifiers from --opacity theme values (#20287)
  • Prevent type errors in @tailwindcss/postcss when used with newer PostCSS patch releases (#20289)

v4.3.1

Added

  • Add --silent option to suppress output in @tailwindcss/cli (#20100)

Fixed

  • Remove deprecation warnings by using Module#registerHooks instead of Module#register on Node 26+ (#20028)
  • Canonicalization: don't crash when plugin utilities throw for unsupported values (#20052)
  • Allow @apply to be used with CSS mixins (#19427)
  • Ensure not-* correctly negates @container queries, including style(…) queries (#20059)
  • Ensure drop-shadow-* color utilities work with custom shadow values containing calc(…) (#20080)
  • Fix 'Sourcemap is likely to be incorrect' warnings when using @tailwindcss/vite (#20103)
  • Ensure @tailwindcss/webpack can be installed in Rspack projects without requiring webpack as a peer dependency (#20027)

... (truncated)

Changelog

Sourced from @​tailwindcss/vite's changelog.

[4.3.3] - 2026-07-16

Fixed

  • Support --watch --poll[=ms] in @tailwindcss/cli when filesystem events are unreliable or unavailable (#20297)
  • Canonicalization: match arbitrary hex colors against theme colors case-insensitively (e.g. bg-[#fff] and bg-[#FFF] → bg-white) (#20298)
  • Prevent Preflight from overriding Firefox's native iframe:focus-visible outline styles (#20292)
  • Ensure theme('colors.foo') in JS plugins resolves correctly when both --color-foo and --color-foo-bar exist (#20299)
  • Ensure fractional opacity modifiers work with named shadow sizes like shadow-sm/12.5, text-shadow-sm/12.5, drop-shadow-sm/12.5, and inset-shadow-sm/12.5 (#20302)
  • Parse selectors like [data-foo]div as two selectors instead of one (#20303)
  • Ensure @tailwindcss/postcss rebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (#20310)
  • Ensure CSS nesting is handled even when Lightning CSS isn't run, such as in @tailwindcss/browser and Tailwind Play (#20124)
  • Prevent achromatic theme colors from shifting hue when mixed in polar color spaces like oklch (#20314)
  • Ensure --spacing(0) is optimized to 0px instead of 0 so it remains a <length> when used in calc(…) (#20319)
  • Load @parcel/watcher only when needed in @tailwindcss/cli --watch mode, so one-off builds and --watch --poll work when @parcel/watcher can't be loaded (#20325)
  • Use explicit platform fonts instead of system-ui and ui-sans-serif so CJK text respects the page's lang attribute on Windows (#20318)
  • Prevent @tailwindcss/upgrade from rewriting ignored files when run from a subdirectory (#20329)
  • Ensure earlier @source rules pointing to nested files are scanned when later @source rules point to files in parent folders (#20335)
  • Prevent @tailwindcss/vite from triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (#20336)

[4.3.2] - 2026-06-26

Fixed

  • Support bare spacing values for auto-rows-* and auto-cols-* utilities (e.g. auto-rows-12 and auto-cols-16) (#20229)
  • Prevent @tailwindcss/cli in --watch mode from crashing on Windows when @source points to a directory that doesn't exist (#20242)
  • Prevent @tailwindcss/vite from crashing in Deno v2.8.x when context.parentURL is not a valid URL (#20245)
  • Ensure @tailwindcss/cli in --watch mode rebuilds when the input CSS file changes in an ignored directory (#20246)
  • Allow @variant rules used in addBase(…) to use custom variants defined later (#20247)
  • Prevent @tailwindcss/vite from crashing during HMR when scanned files or directories are deleted (#20259)
  • Generate font-size instead of color declarations for text-[--spacing(…)] (#20260)
  • Prevent @source patterns from scanning unrelated sibling files and folders (#20263)
  • Extract class candidates adjacent to Template Toolkit delimiters like %]…[% in .tt, .tt2, and .tx files (#20269)
  • Extract class candidates from conditional Maud syntax like p.text-black[condition] (#20269)
  • Prevent @position-try rules from triggering unknown at-rule warnings when optimizing CSS (#20277)
  • Support class suggestions for named opacity modifiers from --opacity theme values (#20287)
  • Prevent type errors in @tailwindcss/postcss when used with newer PostCSS patch releases (#20289)

[4.3.1] - 2026-06-12

Added

  • Add --silent option to suppress output in @tailwindcss/cli (#20100)

Fixed

  • Remove deprecation warnings by using Module#registerHooks instead of Module#register on Node 26+ (#20028)
  • Canonicalization: don't crash when plugin utilities throw for unsupported values (#20052)
  • Allow @apply to be used with CSS mixins (#19427)
  • Ensure not-* correctly negates @container queries, including style(…) queries (#20059)

... (truncated)

Commits

Updates @tanstack/react-query from 5.101.0 to 5.101.4

Release notes

Sourced from @​tanstack/react-query's releases.

@​tanstack/react-query-devtools@​5.101.4

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-devtools@​5.101.4
    • @​tanstack/react-query@​5.101.4

@​tanstack/react-query-next-experimental@​5.101.4

Patch Changes

  • Updated dependencies []:
    • @​tanstack/react-query@​5.101.4

@​tanstack/react-query-persist-client@​5.101.4

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-persist-client-core@​5.101.4
    • @​tanstack/react-query@​5.101.4

@​tanstack/react-query@​5.101.4

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-core@​5.101.4

@​tanstack/react-query-devtools@​5.101.3

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-devtools@​5.101.3
    • @​tanstack/react-query@​5.101.3

@​tanstack/react-query-next-experimental@​5.101.3

Patch Changes

  • Updated dependencies []:
    • @​tanstack/react-query@​5.101.3

@​tanstack/react-query-persist-client@​5.101.3

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-persist-client-core@​5.101.3
    • @​tanstack/react-query@​5.101.3

@​tanstack/react-query@​5.101.3

Patch Changes

... (truncated)

Changelog

Sourced from @​tanstack/react-query's changelog.

5.101.4

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-core@​5.101.4

5.101.3

Patch Changes

  • Updated dependencies [7e3c822]:
    • @​tanstack/query-core@​5.101.3

5.101.2

Patch Changes

  • Updated dependencies []:
    • @​tanstack/query-core@​5.101.2

5.101.1

Patch Changes

  • Updated dependencies [9eff92e]:
    • @​tanstack/query-core@​5.101.1
Commits
  • 86bb8a6 ci: Version Packages (#11094)
  • 181ea82 ci: Version Packages (#11089)
  • 6d55b07 test({react,preact}-query): use the '.then()' convention consistently (#11085)
  • 44f38df test({react,preact,solid}-query/useInfiniteQuery): inline the shared 'fetchIt...
  • d1558c1 test({react,preact}-query/usePrefetchQuery): inline the 'generateQueryFn' fac...
  • 99690d1 test({react,preact}-query/usePrefetchInfiniteQuery): inline single-use helper...
  • 10770f0 test({react,preact}-query/usePrefetchInfiniteQuery): inline the shared 'Suspe...
  • dbd5a86 test({react,preact}-query/usePrefetchQuery): inline the shared 'Suspended' co...
  • b955f60 test({react,preact}-query/useSuspenseQuery): assert the 'loading' fallback is...
  • b9c657e test({react,preact}-query/usePrefetchQuery): assert the 'Loading...' fallback...
  • Additional commits viewable in compare view

Updates uuid from 14.0.0 to 14.0.1

Release notes

Sourced from uuid's releases.

v14.0.1

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)
Changelog

Sourced from uuid's changelog.

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)
Commits
Install script changes

This version modifies prepare script that runs during installation. Review the package contents before updating.


Updates @types/jszip from 3.4.0 to 3.4.1

Changelog

Sourced from @​types/jszip's changelog.


title: Changelog layout: default section: main

v3.10.1 2022-08-02

  • Add sponsorship files.
    • If you appreciate the time spent maintaining JSZip then I would really appreciate your sponsorship.
  • Consolidate metadata types and expose OnUpdateCallback #851 and #852
  • use const instead var in example from README.markdown #828
  • Switch manual download link to HTTPS #839

Internals:

  • Replace jshint with eslint #842
  • Add performance tests #834

v3.10.0 2022-05-20

  • Change setimmediate dependency to more efficient one. Fixes Stuk/jszip#617 (see #829)
  • Update types of currentFile metadata to include null (see #826)

v3.9.1 2022-04-06

  • Fix recursive definition of InputFileFormat introduced in 3.9.0.

v3.9.0 2022-04-04

  • Update types JSZip#loadAsync to accept a promise for data, and remove arguments from new JSZip() (see #752)
  • Update types for compressionOptions to JSZipFileOptions and JSZipGeneratorOptions (see #722)
  • Add types for generateInternalStream (see #774)

v3.8.0 2022-03-30

  • Santize filenames when files are loaded with loadAsync, to avoid "zip slip" attacks. The original filename is available on each zip entry as unsafeOriginalName. See the documentation. Many thanks to McCaulay Hudson for reporting.

v3.7.1 2021-08-05

  • Fix build of dist files.
    • Note: this version ensures the changes from 3.7.0 are actually included in the dist files. Thanks to Evan W for reporting.

v3.7.0 2021-07-23

  • Fix: Use a null prototype object for this.files (see #766)
    • This change might break existing code if it uses prototype methods on the .files property of a zip object, for example zip.files.toString(). This approach is taken to prevent files in the zip overriding object methods that would exist on a normal object.

v3.6.0 2021-02-09

... (truncated)

Commits

Updates autoprefixer from 10.5.0 to 10.5.4

Release notes

Sourced from autoprefixer's releases.

10.5.4

10.5.3

10.5.2

  • Moved -webkit-fill-available before -moz-available, so Firefox will use -webkit- version which is closer to stretch.

10.5.1

Changelog

Sourced from autoprefixer's changelog.

10.5.4

10.5.3

10.5.2

  • Moved -webkit-fill-available before -moz-available, so Firefox will use -webkit- version which is closer to stretch.

10.5.1

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for autoprefixer since your current version.


Updates tailwindcss from 4.3.0 to 4.3.3

Release notes

Sourced from tailwindcss's releases.

v4.3.3

Fixed

  • Support --watch --poll[=ms] in @tailwindcss/cli when filesystem events are unreliable or unavailable (#20297)
  • Canonicalization: match arbitrary hex colors against theme colors case-insensitively (e.g. bg-[#fff] and bg-[#FFF] → bg-white) (#20298)
  • Prevent Preflight from overriding Firefox's native iframe:focus-visible outline styles (#20292)
  • Ensure theme('colors.foo') in JS plugins resolves correctly when both --color-foo and --color-foo-bar exist (#20299)
  • Ensure fractional opacity modifiers work with named shadow sizes like shadow-sm/12.5, text-shadow-sm/12.5, drop-shadow-sm/12.5, and inset-shadow-sm/12.5 (#20302)
  • Parse selectors like [data-foo]div as two selectors instead of one (#20303)
  • Ensure @tailwindcss/postcss rebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (#20310)
  • Ensure CSS nesting is handled even when Lightning CSS isn't run, such as in @tailwindcss/browser and Tailwind Play (#20124)
  • Prevent achromatic theme colors from shifting hue when mixed in polar color spaces like oklch (#20314)
  • Ensure --spacing(0) is optimized to 0px instead of 0 so it remains a <length> when used in calc(…) (#20319)
  • Load @parcel/watcher only when needed in @tailwindcss/cli --watch mode, so one-off builds and --watch --poll work when @parcel/watcher can't be loaded (#20325)
  • Use explicit platform fonts instead of system-ui and ui-sans-serif so CJK text respects the page's lang attribute on Windows (#20318)
  • Prevent @tailwindcss/upgrade from rewriting ignored files when run from a subdirectory (#20329)
  • Ensure earlier @source rules pointing to nested files are scanned when later @source rules point to files in parent folders (#20335)
  • Prevent @tailwindcss/vite from triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (#20336)

v4.3.2

Fixed

  • Support bare spacing values for auto-rows-* and auto-cols-* utilities (e.g. auto-rows-12 and auto-cols-16) (#20229)
  • Prevent @tailwindcss/cli in --watch mode from crashing on Windows when @source points to a directory that doesn't exist (#20242)
  • Prevent @tailwindcss/vite from crashing in Deno v2.8.x when context.parentURL is not a valid URL (#20245)
  • Ensure @tailwindcss/cli in --watch mode rebuilds when the input CSS file changes in an ignored directory (#20246)
  • Allow @variant rules used in addBase(…) to use custom variants defined later (#20247)
  • Prevent @tailwindcss/vite from crashing during HMR when scanned files or directories are deleted (#20259)
  • Generate font-size instead of color declarations for text-[--spacing(…)] (#20260)
  • Prevent @source patterns from scanning unrelated sibling files and folders (#20263)
  • Extract class candidates adjacent to Template Toolkit delimiters like %]…[% in .tt, .tt2, and .tx files (#20269)
  • Extract class candidates from conditional Maud syntax like p.text-black[condition] (#20269)
  • Prevent @position-try rules from triggering unknown at-rule warnings when optimizing CSS (#20277)
  • Support class suggestions for named opacity modifiers from --opacity theme values (#20287)
  • Prevent type errors in @tailwindcss/postcss when used with newer PostCSS patch releases (#20289)

v4.3.1

Added

  • Add --silent option to suppress output in @tailwindcss/cli (#20100)

Fixed

  • Remove deprecation warnings by using Module#registerHooks instead of Module#register on Node 26+ (#20028)
  • Canonicalization: don't crash when plugin utilities throw for unsupported values (#20052)
  • Allow @apply to be used with CSS mixins (#19427)
  • Ensure not-* correctly negates @container queries, including style(…) queries (#20059)
  • Ensure drop-shadow-* color utilities work with custom shadow values containing calc(…) (#20080)
  • Fix 'Sourcemap is likely to be incorrect' warnings when using @tailwindcss/vite (#20103)
  • Ensure @tailwindcss/webpack can be installed in Rspack projects without requiring webpack as a peer dependency (#20027)

... (truncated)

Changelog

Sourced from tailwindcss's changelog.

[4.3.3] - 2026-07-16

Fixed

  • Support --watch --poll[=ms] in @tailwindcss/cli when filesystem events are unreliable or unavailable (#20297)
  • Canonicalization: match arbitrary hex colors against theme colors case-insensitively (e.g. bg-[#fff] and bg-[#FFF] → bg-white) (#20298)
  • Prevent Preflight from overriding Firefox's native iframe:focus-visible outline styles (#20292)
  • Ensure theme('colors.foo') in JS plugins resolves correctly when both --color-foo and --color-foo-bar exist (#20299)
  • Ensure fractional opacity modifiers work with named shadow sizes like shadow-sm/12.5, text-shadow-sm/12.5, drop-shadow-sm/12.5, and inset-shadow-sm/12.5 (#20302)
  • Parse selectors like [data-foo]div as two selectors instead of one (#20303)
  • Ensure @tailwindcss/postcss rebuilds when a preprocessor like Sass changes the input CSS without changing the input file on disk (#20310)
  • Ensure CSS nesting is handled even when Lightning CSS isn't run, such as in @tailwindcss/browser and Tailwind Play (#20124)
  • Prevent achromatic theme colors from shifting hue when mixed in polar color spaces like oklch (#20314)
  • Ensure --spacing(0) is optimized to 0px instead of 0 so it remains a <length> when used in calc(…) (#20319)
  • Load @parcel/watcher only when needed in @tailwindcss/cli --watch mode, so one-off builds and --watch --poll work when @parcel/watcher can't be loaded (#20325)
  • Use explicit platform fonts instead of system-ui and ui-sans-serif so CJK text respects the page's lang attribute on Windows (#20318)
  • Prevent @tailwindcss/upgrade from rewriting ignored files when run from a subdirectory (#20329)
  • Ensure earlier @source rules pointing to nested files are scanned when later @source rules point to files in parent folders (#20335)
  • Prevent @tailwindcss/vite from triggering full page reloads when scanned files are processed by Vite but haven't been loaded as modules yet (#20336)

[4.3.2] - 2026-06-26

Fixed

  • Support bare spacing values for auto-rows-* and auto-cols-* utilities (e.g. auto-rows-12 and auto-cols-16) (#20229)
  • Prevent @tailwindcss/cli in --watch mode from crashing on Windows when @source points to a directory that doesn't exist (#20242)
  • Prevent @tailwindcss/vite from crashing in Deno v2.8.x when context.parentURL is not a valid URL (#20245)
  • Ensure @tailwindcss/cli in --watch mode rebuilds when the input CSS file changes in an ignored directory (#20246)
  • Allow @variant rules used in addBase(…) to use custom variants defined later (#20247)
  • Prevent @tailwindcss/vite from crashing during HMR when scanned files or directories are deleted (#20259)
  • Generate font-size instead of color declarations for text-[--spacing(…)] (#20260)
  • Prevent @source patterns from scanning unrelated sibling files and folders (#20263)
  • Extract class...

    Description has been truncated

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 24, 2026
@dependabot
dependabot Bot requested a review from tonythethompson as a code owner July 24, 2026 07:02
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 24, 2026

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @dependabot[bot], you have reached your weekly rate limit of 500000 diff characters.

Please try again later or upgrade to continue using Sourcery

@dependabot dependabot Bot changed the title chore: bump the all group with 9 updates chore: bump the all group across 1 directory with 9 updates Jul 24, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/all-00b09de5f4 branch from d8cafb6 to 24b80dc Compare July 24, 2026 09:26
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/all-00b09de5f4 branch 2 times, most recently from 65f1d47 to b38f5e5 Compare July 25, 2026 07:38
Bumps the all group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@radix-ui/react-accordion](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/accordion) | `1.2.12` | `1.2.20` |
| [@radix-ui/react-tabs](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/tabs) | `1.1.13` | `1.1.21` |
| [@radix-ui/react-tooltip](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/tooltip) | `1.2.8` | `1.2.16` |
| [@tailwindcss/vite](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-vite) | `4.3.0` | `4.3.3` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.101.0` | `5.101.4` |
| [uuid](https://github.com/uuidjs/uuid) | `14.0.0` | `14.0.1` |
| [@types/jszip](https://github.com/Stuk/jszip) | `3.4.0` | `3.4.1` |
| [autoprefixer](https://github.com/postcss/autoprefixer) | `10.5.0` | `10.5.4` |
| [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) | `4.3.0` | `4.3.3` |



Updates `@radix-ui/react-accordion` from 1.2.12 to 1.2.20
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/accordion/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/accordion)

Updates `@radix-ui/react-tabs` from 1.1.13 to 1.1.21
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/tabs/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/tabs)

Updates `@radix-ui/react-tooltip` from 1.2.8 to 1.2.16
- [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/tooltip/CHANGELOG.md)
- [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/tooltip)

Updates `@tailwindcss/vite` from 4.3.0 to 4.3.3
- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)
- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.3.3/packages/@tailwindcss-vite)

Updates `@tanstack/react-query` from 5.101.0 to 5.101.4
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.101.4/packages/react-query)

Updates `uuid` from 14.0.0 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v14.0.0...v14.0.1)

Updates `@types/jszip` from 3.4.0 to 3.4.1
- [Changelog](https://github.com/Stuk/jszip/blob/main/CHANGES.md)
- [Commits](https://github.com/Stuk/jszip/commits)

Updates `autoprefixer` from 10.5.0 to 10.5.4
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](postcss/autoprefixer@10.5.0...10.5.4)

Updates `tailwindcss` from 4.3.0 to 4.3.3
- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)
- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.3.3/packages/tailwindcss)

---
updated-dependencies:
- dependency-name: "@radix-ui/react-accordion"
  dependency-version: 1.2.18
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: "@radix-ui/react-tabs"
  dependency-version: 1.1.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: "@radix-ui/react-tooltip"
  dependency-version: 1.2.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: "@tailwindcss/vite"
  dependency-version: 4.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: "@tanstack/react-query"
  dependency-version: 5.101.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: "@types/jszip"
  dependency-version: 3.4.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: autoprefixer
  dependency-version: 10.5.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: tailwindcss
  dependency-version: 4.3.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/all-00b09de5f4 branch from b38f5e5 to ac705da Compare July 25, 2026 07:42
@github-actions
github-actions Bot merged commit 7849a33 into main Jul 25, 2026
7 of 8 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/all-00b09de5f4 branch July 25, 2026 08:09
tonythethompson added a commit that referenced this pull request Aug 4, 2026
CUDA install UX (#12, #13, #16, #17, #18, #19, #21, #22, #25)
- hardwareProbe.mergeDetectedProviders: simplify cudaOk ternary to
  `input.cudaLoadable !== false` — same semantic, half the surface.
- hardwareProbe's pre-Maxwell box reason + recipeHardwareCompatibility's
  CUDA-floor reason now name Maxwell SM 5.0 as 'GeForce GTX 750 Ti or
  GTX 9xx series' instead of mistakenly borrowing 'GeForce RTX 20xx+'
  (RTX 20xx is Turing SM 7.5 — the floor above — which previously
  implied a Pascal SM 6.x owner had an unsupported card).
- recipeHardwareCompatibility widens tensorRtInstallHint to ePInstallHint
  and routes the onnxruntime-gpu install hint through it so the
  probe's detail string (driver/wheel mismatch, missing module, etc.)
  is preserved end-to-end.
- IHVIntegrationPanel gates the CUDA toolkit download-link paragraph
  on `cudaEpInVenv` so it only renders when the EP is actually
  registered — removes the contradictory 'CUDA EP detected / install
  button shown' state.
- InputEnvironmentPanel renders the requiresInstall hint directly so
  the label and the pip-install command can never disagree again (the
  old code branched on `kind` and silently printed the TensorRT label
  next to the onnxruntime install command). Drop the now-dead
  pinnedTensorRtLabel + tensorrtRtxEpAbiLabel imports.
- system.ts hardens the ORT GPU probe with an explicit 30 s timeout
  (a broken driver install can leave the onnxruntime import hanging
  and bind the HTTP request) and derives the pinned-version string from
  pinnedOrtGpuLabel() instead of hardcoding '1.26.0' — a wheel bump in
  oliveGpuRuntime now propagates to every error message and install
  hint without further edits.
- system.ts notes generator now derives its suggested pip command from
  pinnedOrtGpuInstallCommand() instead of a literal 'pip install
  onnxruntime-gpu==1.26.0' string.

Shared install helpers (#23, #24, #26)
- src/server/services/shared/pipInstall.ts is the single NDJSON-aware
  pip install helper used by every install route; the local copies in
  cuda.ts + tensorrt-rtx.ts deleted (kept the exact byte-shape so the
  UIs NDJSON parser keeps working unchanged).
- cuda.ts exports ensureOnnxRuntimeGpu; tensorrt-rtx.ts calls it
  directly instead of carrying a private duplicate (mirror drift was
  the actual bug — they were diverging in subtle ways).
- cuda.ts ensureOnnxRuntimeGpu explicitly returns libsDir: null on
  success so the documented return-type contract is honoured and
  external callers can distinguish "no library directory available"
  from "field not set".
- tensorrt-rtx.ts uses platform-appropriate native-lib extensions:
  onnxruntime_providers_nv_tensorrt_rtx.dll on win32,
  libonnxruntime_providers_nv_tensorrt_rtx.so on Linux, .dylib on
  Darwin (a hardcoded .dll hides the real reason an import fails on
  non-Windows platforms). The probe script picks the right extension
  at runtime.

Manifest / dedupe (#5, #20, #6)
- cudaDeps.cudaDownloadUrlForOs routes darwin to the archive landing
  page (Apple dropped CUDA toolkit support after CUDA 11.6) and uses
  word-boundary regexes so 'darwin' no longer accidentally hits the
  Windows branch via the substring 'win'.
- tensorrtRtxDeps.tensorrtRtxEpAbiInstallCommand now derives the
  manual pip command from the args list (same delegation pattern
  pinnedTensorRtInstallCommand uses), so an index/version bump cannot
  desync the server-side install and the user-facing fallback hint.
- src/server/shared/anyDotVenvDir.ts is the single chokidar
  ANY_DOT_VENV_DIR regex; vite.config.ts and server.ts both import
  from here so a rename/back-up of the venv directory is filtered out
  by both Vite watchlists in lockstep.

Test fixtures (#14, #15)
- cudaDeps.test isPreMaxwellNvidiaBox describe block: split the
  mislabeled 'every card is at or above the floor' assertion into
  two focused tests (every-card-above-floor / every-card-below-floor);
  add a darwin routing suite (asserts darwin does NOT hit the Windows
  branch via substring 'win' and lands on the archive landing page).
- providerCatalog.test cross-family lockstep test title now uses a
  template literal so the floor number interpolates into the test
  name (was a verbatim '$floor' string).

e2e/scroll-bounds-guardrail.spec.ts (#7, #8, #9)
- Page.evaluate wraps Radix Tooltip elements in the full
  Provider/Root/Trigger/Portal/Content hierarchy using
  React.createElement so the elements go through the JSX reconciler
  (plain RdxTooltip.Portal(...) / Content(...) function calls were
  missing Radix's Provider context and the sentinel never mounted).
- DOM-fallback branch preserves the actual import-error string so a
  future failure is filed with the real reason, not a synthetic
  'Radix bare imports did not resolve' placeholder.
- Added paint-time hit-test: document.elementFromPoint at the bbox
  centre must resolve to the sentinel (or one of its ancestors up
  to #root). getClientRects alone cannot detect overflow:hidden
  clipping because clip preserves the rect coordinates; the hit-test
  is the actual guardrail.
- Restrict the lint-disable comment to the placeholder line so the
  prettier/sonar warnings stay clean.

Verified: tsc clean, 734/734 unit tests + 229/229 server tests pass,
pnpm validate:recipe ok, pnpm lint 9 pre-existing warnings / 0 new
errors, live /api/system/hardware-probe?refresh=1 reflects the
updated probe fields.
tonythethompson added a commit that referenced this pull request Aug 4, 2026
* feat: CUDA+TensorRT install UX, lock SM-floor drift, bound scroll overshoot

Provider compat & install
- CUDA gets the same one-click install UX TRT/TRT-RTX already have: dedicated
  /api/env/install-onnxruntime-gpu route pip-installs the pinned 1.26.0 wheel
  into .venv with NDJSON progress, alongside the existing tensorrt / tensorrt-
  rtx routes (src/server/routes/env.ts, src/server/services/olive/cuda.ts).
- IHV panel surfaces the right CTA per state: external link to NVIDIA's CUDA
  Toolkit archive (system-level install), pip button for onnxruntime-gpu, or
  rose terminator for pre-Maxwell GPUs that no install can recover.
- Probe split into 4 user-facing states: no GPU / pre-Maxwell / driver+wheel
  missing / driver+toolkit+EP mismatch — the hidden one-line "NVIDIA CUDA was
  not detected" is gone.

Hardware probe + recipe compat
- Add cudaToolkit? and cuda? fields to HardwareProbeResult, with
  cudaLoadable gate on mergeDetectedProviders so recipe compat and IHV
  panel install button fire in lockstep.
- Pre-Maxwell SM 5.0 short-circuit on CUDA recipes, mirroring the existing
  pre-Turing SM 7.5 short-circuit: never advertise an install on a card that
  cannot run the EP.
- Center the SM floors in cudaDeps.ts and tensorrtRtxDeps so they're the
  single source of truth and importable by tests.

SM-floor drift guards (NEW)
- providerCatalog.ts TRT-RTX chip: chip + tooltip.requirements both cite 7.5
  numerically, name Turing / RTX 20xx, call out Maxwell/Pascal/Kepler.
- providerCatalog.ts full-TensorRT chip: same treatment — previously had no
  numeric anchor, just "Turing or newer (GeForce RTX 20xx+)".
- recipeHardwareCompatibility pre-Turing reason: drift-guard describe block
  imports the constant and asserts it appears in BOTH TRT and TRT-RTX
  reasons; locks the "Turing / RTX 20xx+" tie-in phrase and ensures the
  install hint stays undefined on pre-Turing boxes.
- providerCatalog.test.ts: full sibling describe block for the full-TensorRT
  half of the family, including a cross-family lockstep assertion (both
  halves must contain the same numeric constant).
- Future Bump of TENSORRT_FAMILY_MIN_COMPUTE_CAPABILITY fails CI in 3 test
  files (hardwareProbe / providerCatalog / recipeHardwareCompatibility) and
  forces all 4 user-facing surfaces to update atomically.

Scroll bound + Vite watcher
- App-level, IHV panel, and InputEnvironmentPanel clipped to
  min-h-0 overflow-hidden under a properly bounded scroll container so the
  page can't be scrolled past the end into empty space (CSS-only, no JS).
- e2e/scroll-bounds-guardrail.spec.ts mounts a Radix portal at #root and
  asserts it isn't clipped — guards the next person from re-applying the
  #root overflow lock that would break portals.
- vite.config.ts: ignore .venv*, .venv.bak, .venv.old, .venv-renamed so
  venv tooling (renames, swaps) no longer triggers page reloads.

Tests
- src/lib/cudaDeps.test.ts (18) — SM 5.0 floor lock + pre-Maxwell
  classification + pinned install command.
- src/lib/tensorrtRtxDeps.test.ts — RTF EP-ABI install command shape.
- src/lib/__tests__/providerCatalog.test.ts (16) — SM 7.5 lockstep across
  catalog chip and hardware-probe reason for BOTH halves of the family.
- src/lib/__tests__/recipeHardwareCompatibility.test.ts (23) — full SM-floor
  drift-guard describe block plus install-needed scenarios for CUDA/TRT/
  TRT-RTX on supported and pre-floor hardware.
- src/lib/hardwareProbe.test.ts + tensorrtDeps.test.ts — extended for CUDA
  4-state branching and TRT/TRT-RTX install-hint gating.

Verified
- pnpm exec tsc --noEmit: clean
- pnpm lint: 9 pre-existing warnings, 0 new, 0 errors
- pnpm vitest run --config vitest.config.ts: 731/731 passing
- Live preview at http://127.0.0.1:3000/ verified wiring (cudaToolkit field
  now surfaces on /api/system/hardware-probe).

* fix: Use .venv-scoped CUDA readiness

* fix: Compute scroll position relative to container

* feat: OpenVINO stack install button mirroring TensorRT UX

- Add openvino + optimum-intel[openvino] install via NDJSON /api/env/install-openvino into .venv

- Probe openvino version, Core().available_devices and optimum.intel availability

- Wire requiresInstall/openvinoNeedsInstall badge and install button in IHVIntegrationPanel

- Link to Intel GPU/NPU driver docs when discrete devices are absent

- Update recipe inference and hardwareProbe/pickRecommendedProvider for OpenVINO

- Add unit test for openvino stack install args

* refactor(openvino): split probe script, parse and install logic to reduce complexity

* fix: 2 findings — Unify shared venv install mutex; Rate-limit OpenVINO i

- Unify shared venv install mutex
- Rate-limit OpenVINO installation

* fix: 2 findings — Preserve partial OpenVINO probe results; Parallelize h

- Preserve partial OpenVINO probe results
- Parallelize hardware probe calls

* fix: address Greptile review feedback

- Add optimum.intel import check in recipe inference

- Restrict OpenVINO hardware detection to Intel-branded CPUs

- Surface optimum.intel import errors in probe detail

- Apply heavyCommandRateLimit to all venv install routes

* Update src/server/services/olive/openvino.ts

Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

* Update src/lib/cudaDeps.ts

Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>

* fix: apply CodeRabbit auto-fixes

Fixed 6 file(s) based on 5 unresolved review comments.

Co-authored-by: CodeRabbit <noreply@coderabbit.ai>

* fix: install and verify onnxruntime-openvino for OpenVINO EP

Codex P1: openvino + optimum-intel alone do not register
OpenVINOExecutionProvider. Install onnxruntime-openvino, remove
conflicting ORT wheels with a warning, and gate readiness on the EP.
P2 (shared venv pip mutex) was already unified on this branch.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix: address PR #106 review feedback across 23 outstanding threads

CUDA install UX (#12, #13, #16, #17, #18, #19, #21, #22, #25)
- hardwareProbe.mergeDetectedProviders: simplify cudaOk ternary to
  `input.cudaLoadable !== false` — same semantic, half the surface.
- hardwareProbe's pre-Maxwell box reason + recipeHardwareCompatibility's
  CUDA-floor reason now name Maxwell SM 5.0 as 'GeForce GTX 750 Ti or
  GTX 9xx series' instead of mistakenly borrowing 'GeForce RTX 20xx+'
  (RTX 20xx is Turing SM 7.5 — the floor above — which previously
  implied a Pascal SM 6.x owner had an unsupported card).
- recipeHardwareCompatibility widens tensorRtInstallHint to ePInstallHint
  and routes the onnxruntime-gpu install hint through it so the
  probe's detail string (driver/wheel mismatch, missing module, etc.)
  is preserved end-to-end.
- IHVIntegrationPanel gates the CUDA toolkit download-link paragraph
  on `cudaEpInVenv` so it only renders when the EP is actually
  registered — removes the contradictory 'CUDA EP detected / install
  button shown' state.
- InputEnvironmentPanel renders the requiresInstall hint directly so
  the label and the pip-install command can never disagree again (the
  old code branched on `kind` and silently printed the TensorRT label
  next to the onnxruntime install command). Drop the now-dead
  pinnedTensorRtLabel + tensorrtRtxEpAbiLabel imports.
- system.ts hardens the ORT GPU probe with an explicit 30 s timeout
  (a broken driver install can leave the onnxruntime import hanging
  and bind the HTTP request) and derives the pinned-version string from
  pinnedOrtGpuLabel() instead of hardcoding '1.26.0' — a wheel bump in
  oliveGpuRuntime now propagates to every error message and install
  hint without further edits.
- system.ts notes generator now derives its suggested pip command from
  pinnedOrtGpuInstallCommand() instead of a literal 'pip install
  onnxruntime-gpu==1.26.0' string.

Shared install helpers (#23, #24, #26)
- src/server/services/shared/pipInstall.ts is the single NDJSON-aware
  pip install helper used by every install route; the local copies in
  cuda.ts + tensorrt-rtx.ts deleted (kept the exact byte-shape so the
  UIs NDJSON parser keeps working unchanged).
- cuda.ts exports ensureOnnxRuntimeGpu; tensorrt-rtx.ts calls it
  directly instead of carrying a private duplicate (mirror drift was
  the actual bug — they were diverging in subtle ways).
- cuda.ts ensureOnnxRuntimeGpu explicitly returns libsDir: null on
  success so the documented return-type contract is honoured and
  external callers can distinguish "no library directory available"
  from "field not set".
- tensorrt-rtx.ts uses platform-appropriate native-lib extensions:
  onnxruntime_providers_nv_tensorrt_rtx.dll on win32,
  libonnxruntime_providers_nv_tensorrt_rtx.so on Linux, .dylib on
  Darwin (a hardcoded .dll hides the real reason an import fails on
  non-Windows platforms). The probe script picks the right extension
  at runtime.

Manifest / dedupe (#5, #20, #6)
- cudaDeps.cudaDownloadUrlForOs routes darwin to the archive landing
  page (Apple dropped CUDA toolkit support after CUDA 11.6) and uses
  word-boundary regexes so 'darwin' no longer accidentally hits the
  Windows branch via the substring 'win'.
- tensorrtRtxDeps.tensorrtRtxEpAbiInstallCommand now derives the
  manual pip command from the args list (same delegation pattern
  pinnedTensorRtInstallCommand uses), so an index/version bump cannot
  desync the server-side install and the user-facing fallback hint.
- src/server/shared/anyDotVenvDir.ts is the single chokidar
  ANY_DOT_VENV_DIR regex; vite.config.ts and server.ts both import
  from here so a rename/back-up of the venv directory is filtered out
  by both Vite watchlists in lockstep.

Test fixtures (#14, #15)
- cudaDeps.test isPreMaxwellNvidiaBox describe block: split the
  mislabeled 'every card is at or above the floor' assertion into
  two focused tests (every-card-above-floor / every-card-below-floor);
  add a darwin routing suite (asserts darwin does NOT hit the Windows
  branch via substring 'win' and lands on the archive landing page).
- providerCatalog.test cross-family lockstep test title now uses a
  template literal so the floor number interpolates into the test
  name (was a verbatim '$floor' string).

e2e/scroll-bounds-guardrail.spec.ts (#7, #8, #9)
- Page.evaluate wraps Radix Tooltip elements in the full
  Provider/Root/Trigger/Portal/Content hierarchy using
  React.createElement so the elements go through the JSX reconciler
  (plain RdxTooltip.Portal(...) / Content(...) function calls were
  missing Radix's Provider context and the sentinel never mounted).
- DOM-fallback branch preserves the actual import-error string so a
  future failure is filed with the real reason, not a synthetic
  'Radix bare imports did not resolve' placeholder.
- Added paint-time hit-test: document.elementFromPoint at the bbox
  centre must resolve to the sentinel (or one of its ancestors up
  to #root). getClientRects alone cannot detect overflow:hidden
  clipping because clip preserves the rect coordinates; the hit-test
  is the actual guardrail.
- Restrict the lint-disable comment to the placeholder line so the
  prettier/sonar warnings stay clean.

Verified: tsc clean, 734/734 unit tests + 229/229 server tests pass,
pnpm validate:recipe ok, pnpm lint 9 pre-existing warnings / 0 new
errors, live /api/system/hardware-probe?refresh=1 reflects the
updated probe fields.

* fix: add missing useOpenVinoInstall hook for CI typecheck

CodeRabbit's auto-fix imported @/components/features/useOpenVinoInstall
but never added the module, so pnpm lint (tsc) failed with TS2307.

Co-authored-by: Anthony Thompson <github@trackdub.com>

* fix: address follow-up review on tensorrt.ts pipInstall, install mutex, state-4 test

- tensorrt.ts: extract private pipInstall to ../shared/pipInstall.ts;
  local spawn-based copy removed, all 4 install call-sites now route
  through the shared helper so cuda/tensorrt/tensorrt-rtx agree on
  error contract and the '[deps]' output prefix.
- IHVIntegrationPanel.tsx: replace installingTrt | installingTrtRtx |
  installingOrtGpu trio of mutex flags with a single installInProgress
  derived from all three. The three handler guards, setInstalling(true)
  cleanup, and React Button disabled props all use the unified flag so a
  concurrent pip install can no longer race the shared .venv.
- hardwareProbe.test.ts: state-4 fixture now passes cuda.loadable:true
  so the install-hint branch (state 3) is bypassed and the cascade
  reaches the state-4 driver/wheel mismatch reason. Without cuda.loadable
  the fixture was exercising state 3 instead of state 4, so the assertion
  originally committed failed to validate the intended branch.

🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>

* Update src/components/features/IHVIntegrationPanel.tsx

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

* fix: extract HardwareProviderCard to clear CodeFactor complexity

Move the provider-card map (Very Complex Method) out of
IHVIntegrationPanel into a dedicated component with chrome helpers
and install/conflict subcomponents so CodeFactor can pass on PR 108.

Co-authored-by: Anthony Thompson <github@trackdub.com>

* fix: address CodeRabbit OpenVINO review findings

Share NDJSON install helper with residual-frame flush, add hook tests,
require --upgrade with eager strategy, tighten Intel hardware detection
via computeOpenVinoCompatibleHardware + lspci/Win32 probe, and gate ORT
wheel uninstall with install-failure recovery messaging.

Co-authored-by: Anthony Thompson <github@trackdub.com>

---------

Co-authored-by: qodo-code-review[bot] <151058649+qodo-code-review[bot]@users.noreply.github.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: CodeRabbit <noreply@coderabbit.ai>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Codebuff <noreply@codebuff.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant