Sync Primer view_components upstream through v0.53.1 - #519
Open
myabc wants to merge 33 commits into
Open
Conversation
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…tion-dependencies group across 1 directory (primer#4115) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…#4129) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ates (primer#4123) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…4151) Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ates (primer#4158) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Merges primer/view_components up to 18aa9c4, the parent of upstream Release Tracking primer#4154. Component change: reserves height as well as width in .ToggleSwitch-statusIcon so the switch no longer jumps when the loading spinner appears (primer#4152). Keeps the fork's workflow files unchanged: the upstream conflicts are GitHub Action version bumps (the fork pins by SHA through its own Dependabot) and the migration of gem publishing to RubyGems Trusted Publishing, which does not apply to the fork's release flow. Replays the rails-html-sanitizer 1.7.1 and loofah 2.25.2 bumps that merge=ours dropped from both Gemfile.locks. Remaining upstream lockfile bumps are left to the fork's weekly Dependabot. Regenerates static/classnames.* from a clean tree, which also picks up class names the fork's own sources already carried.
🦋 Changeset detectedLatest commit: 914fb8e The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
There was a problem hiding this comment.
Pull request overview
Syncs the OpenProject fork of Primer ViewComponents with upstream through v0.53.1, bringing in the ToggleSwitch layout fix plus related dependency and generated-file updates while preserving fork-specific publishing/workflow behavior.
Changes:
- Prevent ToggleSwitch layout “jump” when showing loading/error status icons by reserving status icon height and centering content.
- Add system test coverage to ensure the ToggleSwitch track position and spinner centering remain stable.
- Update dependencies/lockfiles (Ruby + npm) and refresh generated static class name allowlists; add a changeset for the user-facing fix.
Reviewed changes
Copilot reviewed 8 out of 12 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
app/components/primer/alpha/toggle_switch.pcss |
Reserves .ToggleSwitch-statusIcon height and centers icon/spinner to avoid layout shift. |
test/system/alpha/toggle_switch_test.rb |
Adds system tests asserting the switch doesn’t move and the spinner is centered. |
.changeset/hungry-poems-shout.md |
Documents the ToggleSwitch fix as a patch release for the forked package. |
static/classnames.js |
Updates generated/maintained class name allowlist to match current sources. |
static/classnames.cjs |
Same allowlist update for CommonJS consumers. |
package.json |
Bumps markdownlint-cli2 dev dependency. |
package-lock.json |
Regenerates lockfile to reflect updated npm dependency graph. |
Gemfile |
Bumps selenium-webdriver and yard constraints. |
Gemfile.lock |
Updates resolved Ruby dependencies including sanitizer/security-related bumps. |
demo/package.json |
Bumps @primer/css in the demo app. |
demo/package-lock.json |
Regenerates demo lockfile for updated npm dependencies. |
demo/Gemfile.lock |
Updates resolved demo Ruby dependencies consistent with root bundle updates. |
Files not reviewed (1)
- demo/package-lock.json: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🤖 Opened by an agent on Alex's behalf.
Syncs the fork with
primer/view_componentsthrough upstream v0.53.1 — merge target18aa9c415(parent of Release Tracking primer#4154).Upstream changes included
.ToggleSwitch-statusIcon. Ships with a changeset (patch) and a new system test.selenium-webdriver4.44,yard0.9.45,markdownlint-cli20.23,@primer/css22.3.0 in/demo, plus GitHub Action major bumps (actions/setup-node7,actions/stale11,actions/labeler7,actions/cache6.1.0,github/codeql-action4.37.3,stefanzweifel/git-auto-commit-action7.2.0).Conflicts resolved
package.json: kept fork identity (name/version/description); took upstream'smarkdownlint-cli2bump.package-lock.jsonregenerated withnpm install(the merge had left conflict markers in it)..github/workflows/: resolved as ours, leaving them byte-identical tomain. The upstream side was only Action version bumps — this fork pins Actions by SHA and its own Dependabot raises them — plus the RubyGems Trusted Publishing migration, which does not apply here: the fork publishesopenproject-primer_view_componentswith its own shared RubyGems token and its own npm scope. All 13 files re-validated as YAML after resolution.Gemfile: took upstream'sselenium-webdriverandyardbumps; bothGemfile.locks refreshed withbundle install.Dependency bumps replayed by hand
Gemfile.lockismerge=ours, so upstream's lockfile-only bumps are dropped on merge. Replayed the security-relevant pair in both bundles withbundle update --conservative:rails-html-sanitizer1.7.0 → 1.7.1 (Bump rails-html-sanitizer from 1.7.0 to 1.7.1 primer/view_components#4145, Bump rails-html-sanitizer from 1.7.0 to 1.7.1 in /demo primer/view_components#4144)loofah2.25.1 → 2.25.2 (Bump loofah from 2.25.1 to 2.25.2 in /demo primer/view_components#4141)Everything else upstream locked ahead of us (
postcss8.5.25,axe-core4.12.1,playwright1.62.0,svgo4.0.2,msgpack1.8.2) is non-urgent and left to the fork's weekly Dependabot.Notes
git clean -fdx -- app/first) — no phantom classes leaked intostatic/.static/classnames.{js,cjs}gainedBox-list,Button--mediumandcontainer-{md,lg,xl}. These come from sources already onmain(collapsible_header.pcss,segmented_control.pcss,layout.pcss); CI regeneratesstatic/*.jsonbut neverclassnames.*, so those files had drifted stale.tsconfig.jsonverified intact — the fork's recursiveinclude(app/components/primer/**/*.ts) survived the merge.main's baseline: the remaining rubocop/eslint offenses are all in files this merge does not touch.