Skip to content

chore(deps): bump svelte, @sveltejs/vite-plugin-svelte and typewriter-editor in /examples/password_manager/frontend - #337

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/examples/password_manager/frontend/multi-56a5e6f8b5
Closed

chore(deps): bump svelte, @sveltejs/vite-plugin-svelte and typewriter-editor in /examples/password_manager/frontend#337
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/examples/password_manager/frontend/multi-56a5e6f8b5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 17, 2026

Copy link
Copy Markdown
Contributor

Bumps svelte, @sveltejs/vite-plugin-svelte and typewriter-editor. These dependencies needed to be updated together.
Updates svelte from 4.2.20 to 5.53.12

Release notes

Sourced from svelte's releases.

svelte@5.53.12

Patch Changes

  • fix: update select.__value on change (#17745)

  • chore: add invariant helper for debugging (#17929)

  • fix: ensure deriveds values are correct across batches (#17917)

  • fix: handle async RHS in assignment_value_stale (#17925)

  • fix: avoid traversing clean roots (#17928)

svelte@5.53.11

Patch Changes

  • fix: remove untrack circular dependency (#17910)

  • fix: recover from errors that leave a corrupted effect tree (#17888)

  • fix: properly lazily evaluate RHS when checking for assignment_value_stale (#17906)

  • fix: resolve boundary in correct batch when hydrating (#17914)

  • chore: rebase batches after process, not during (#17900)

svelte@5.53.10

Patch Changes

  • fix: re-process batch if new root effects were scheduled (#17895)

svelte@5.53.9

Patch Changes

  • fix: better bind:this cleanup timing (#17885)

svelte@5.53.8

Patch Changes

  • fix: {@html} no longer duplicates content inside contenteditable elements (#17853)

  • fix: don't access inert block effects (#17882)

  • fix: handle asnyc updates within pending boundary (#17873)

  • perf: avoid re-traversing the effect tree after $: assignments (#17848)

  • chore: simplify scheduling logic (#17805)

svelte@5.53.7

... (truncated)

Changelog

Sourced from svelte's changelog.

5.53.12

Patch Changes

  • fix: update select.__value on change (#17745)

  • chore: add invariant helper for debugging (#17929)

  • fix: ensure deriveds values are correct across batches (#17917)

  • fix: handle async RHS in assignment_value_stale (#17925)

  • fix: avoid traversing clean roots (#17928)

5.53.11

Patch Changes

  • fix: remove untrack circular dependency (#17910)

  • fix: recover from errors that leave a corrupted effect tree (#17888)

  • fix: properly lazily evaluate RHS when checking for assignment_value_stale (#17906)

  • fix: resolve boundary in correct batch when hydrating (#17914)

  • chore: rebase batches after process, not during (#17900)

5.53.10

Patch Changes

  • fix: re-process batch if new root effects were scheduled (#17895)

5.53.9

Patch Changes

  • fix: better bind:this cleanup timing (#17885)

5.53.8

Patch Changes

  • fix: {@html} no longer duplicates content inside contenteditable elements (#17853)

  • fix: don't access inert block effects (#17882)

  • fix: handle asnyc updates within pending boundary (#17873)

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for svelte since your current version.


Updates @sveltejs/vite-plugin-svelte from 3.1.2 to 7.0.0

Release notes

Sourced from @​sveltejs/vite-plugin-svelte's releases.

@​sveltejs/vite-plugin-svelte@​7.0.0

Major Changes

  • breaking(deps): require vite 8 (#1266)

  • breaking(options): remove deprecated options (#1274)

    • vitePlugin.hot in svelte.config.js use compilerOptions.hmr instead
    • vitePlugin.ignorePluginPreprocessors in svelte.config.js no longer needed
    • api.idFilter of vite-plugin-svelte:api use api.filter instead
    • plugin.api.sveltePreprocess of other vite plugins Update affected plugins to a newer version or remove them. See docs for more information.
  • breaking(dev): no longer overrides compilerOptions.cssHash because Svelte now produces a stable css hash by itself (#1271)

  • breaking(inspector): integrate vite-plugin-svelte-inspector into vite-plugin-svelte to avoid circular dependency (#1270)

  • breaking(deps): require svelte 5.46.4 or later (#1271)

Patch Changes

  • chore: upgrade vitefu to compatible peer dependency range (#1286)

  • remove author field from package.json (#1281)

@​sveltejs/vite-plugin-svelte@​7.0.0-next.1

Patch Changes

  • chore: upgrade vitefu to compatible peer dependency range (#1286)

  • remove author field from package.json (#1281)

@​sveltejs/vite-plugin-svelte@​7.0.0-next.0

Major Changes

  • breaking(deps): require vite 8 (#1266)

  • breaking(deps): require svelte 5.46.4 or later (#1271)

... (truncated)

Changelog

Sourced from @​sveltejs/vite-plugin-svelte's changelog.

7.0.0

Major Changes

  • breaking(deps): require vite 8 (#1266)

  • breaking(options): remove deprecated options (#1274)

    • vitePlugin.hot in svelte.config.js use compilerOptions.hmr instead
    • vitePlugin.ignorePluginPreprocessors in svelte.config.js no longer needed
    • api.idFilter of vite-plugin-svelte:api use api.filter instead
    • plugin.api.sveltePreprocess of other vite plugins Update affected plugins to a newer version or remove them. See docs for more information.
  • breaking(dev): no longer overrides compilerOptions.cssHash because Svelte now produces a stable css hash by itself (#1271)

  • breaking(inspector): integrate vite-plugin-svelte-inspector into vite-plugin-svelte to avoid circular dependency (#1270)

  • breaking(deps): require svelte 5.46.4 or later (#1271)

Patch Changes

  • chore: upgrade vitefu to compatible peer dependency range (#1286)

  • remove author field from package.json (#1281)

7.0.0-next.1

Patch Changes

  • chore: upgrade vitefu to compatible peer dependency range (#1286)

  • remove author field from package.json (#1281)

7.0.0-next.0

Major Changes

  • breaking(deps): require vite 8 (#1266)

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for @​sveltejs/vite-plugin-svelte since your current version.


Updates typewriter-editor from 0.9.4 to 0.12.9

Commits

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

…-editor

Bumps [svelte](https://github.com/sveltejs/svelte/tree/HEAD/packages/svelte), [@sveltejs/vite-plugin-svelte](https://github.com/sveltejs/vite-plugin-svelte/tree/HEAD/packages/vite-plugin-svelte) and [typewriter-editor](https://github.com/typewriter-editor/typewriter). These dependencies needed to be updated together.

Updates `svelte` from 4.2.20 to 5.53.12
- [Release notes](https://github.com/sveltejs/svelte/releases)
- [Changelog](https://github.com/sveltejs/svelte/blob/main/packages/svelte/CHANGELOG.md)
- [Commits](https://github.com/sveltejs/svelte/commits/svelte@5.53.12/packages/svelte)

Updates `@sveltejs/vite-plugin-svelte` from 3.1.2 to 7.0.0
- [Release notes](https://github.com/sveltejs/vite-plugin-svelte/releases)
- [Changelog](https://github.com/sveltejs/vite-plugin-svelte/blob/main/packages/vite-plugin-svelte/CHANGELOG.md)
- [Commits](https://github.com/sveltejs/vite-plugin-svelte/commits/@sveltejs/vite-plugin-svelte@7.0.0/packages/vite-plugin-svelte)

Updates `typewriter-editor` from 0.9.4 to 0.12.9
- [Release notes](https://github.com/typewriter-editor/typewriter/releases)
- [Commits](https://github.com/typewriter-editor/typewriter/commits)

---
updated-dependencies:
- dependency-name: svelte
  dependency-version: 5.53.12
  dependency-type: direct:development
- dependency-name: "@sveltejs/vite-plugin-svelte"
  dependency-version: 7.0.0
  dependency-type: direct:production
- dependency-name: typewriter-editor
  dependency-version: 0.12.9
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 17, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner March 17, 2026 13:35
@marc0olo

Copy link
Copy Markdown
Member

Closing as obsolete: the examples/ directory was removed from this repo in #377 (moved to dfinity/examples), so this PR patches paths that no longer exist on main. It has been in a conflicted state since then.

Dependency updates for those examples belong in dfinity/examples now.

@marc0olo marc0olo closed this Aug 26, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/examples/password_manager/frontend/multi-56a5e6f8b5 branch August 26, 2026 19:38
marc0olo added a commit that referenced this pull request Aug 27, 2026
Clears **all 12 open Dependabot advisories** in one change. Supersedes
#397, #380 and #409.

## Changes

| Package | Was | Now | Alerts cleared |
|---|---|---|---|
| `openssl` | 0.10.73 | **0.10.81** | 8 — 5 high, 2 medium, 1 low |
| `openssl-sys` | 0.9.109 | 0.9.117 | (transitive) |
| `rustls-webpki` | 0.103.10 | **0.103.15** | 3 — 1 high, 2 low |
| `rand` | 0.8.5 | **0.8.8** | 1 — low |

Each alert was checked against its own patched version; all 12 verify as
cleared. `openssl` and `rustls-webpki` land *newer* than the superseded
PRs proposed (0.10.80 / 0.103.13).

Three files, and the lockfile moves exactly four package versions — no
transitive churn.

## Why not `rand` 0.10.2, as #409 proposed

`rand` is the only one of the three that reaches shipped code — it is a
**runtime** dependency of the published `ic-vetkeys` crate (plus
`ic-vetkeys-test-utils`, `ic-vetkeys-manager-canister`,
`ic-vetkeys-canisters-tests`).

But the advisory
([GHSA-cq8v-f236-94qc](GHSA-cq8v-f236-94qc),
**low**) is:

```
vulnerable range:  >= 0.7.0, < 0.8.6
first patched:     0.8.6
```

0.8.6 is a **patch** release. #409 proposed `0.10.2` — two breaking
majors past the fix — which would force a `rand` 0.8 → 0.10 API
migration across four crates including the published crypto crate, plus
a lockstep `rand_chacha` 0.3 → 0.10 move. That is a large, risky change
to absorb for a low-severity advisory that a patch bump resolves. This
PR moves the manifest floor to `0.8.6` and the lock resolves `0.8.8`.

(The `rand 0.10.2` already in `Cargo.lock` is unrelated — it arrives via
`quinn-proto`, transitively under the dev-only `reqwest`, and is
untouched here.)

## Severity in context

`openssl` and `rustls-webpki` account for 11 of the 12 alerts, including
all 6 highs — but their real exposure is **CI-only**. Both reach the
tree solely via `reqwest`, which sits under `[dev-dependencies]` next to
`pocket-ic`, and the canisters compile to `wasm32-unknown-unknown` where
neither can exist. Neither appears in the published crate's dependency
list:

```
rand           req=^0.8.5    kind=normal
rand_chacha    req=^0.3.1    kind=normal
pocket-ic      req=^15.0.0   kind=dev
```

GitHub reports `scope=runtime` for all of them, but that is inferred
from `Cargo.lock`, which carries no dev/runtime split for transitive
packages. The manifests are the authority here.

## No release required

Published `ic-vetkeys@0.9.0` declares `rand = "^0.8.5"` — i.e. `>=0.8.5,
<0.9.0`. **`0.8.8` already satisfies that**, so anyone building against
0.9.0 today resolves the fixed version automatically; nobody is pinned
to the vulnerable 0.8.5 except via a stale local lockfile, which `cargo
update -p rand` fixes without any action from us.

`Cargo.lock` is not consumed by dependents of a library crate, and
dev-dependencies never propagate — so the `openssl` / `rustls-webpki`
half has zero consumer impact by construction.

The manifest floor bump to `0.8.6` only takes effect when we next
publish, and is belt-and-braces for the stale-lockfile case. **It can
ride the next release rather than triggering one.** Nothing here affects
`@icp-sdk/vetkeys` (npm) or the Motoko package.

## Verification

Ran the backend CI commands verbatim:

- `cargo build --release --target wasm32-unknown-unknown` for all four
canister crates — **pass**
- `cargo test` — **14 passed, 0 failed**, including the pocket-ic
integration tests (`key_sharing_should_work`,
`should_preserve_state_across_upgrade`,
`should_get_accessible_shared_key_ids`, …) that exercise the crypto
paths using `rand`
- `cargo test --doc` — pass (the 4 `ignored` doc-tests carry
pre-existing `ignore` annotations, unchanged here)
- `cargo clippy -- -Dwarnings` — pass
- `cargo fmt --check` — pass

`rand` 0.8.5 → 0.8.8 is a patch bump inside 0.8, so no API change was
expected; the green build and integration tests confirm it rather than
assume it.

## Superseded

- #397 — `openssl` → 0.10.80. Included here at 0.10.81.
- #380 — `rustls-webpki` → 0.103.13. Included here at 0.103.15.
- #409 — `rand` → 0.10.2. Replaced with the 0.8.x patch fix, per above.

Also closed as obsolete while triaging: #337, #316, #315 (targeted
`examples/`, removed in #377) and #406 (`vite` 7.3.5, already superseded
by `^7.3.6` from #434).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant