Skip to content

chore(deps): bump the production-dependencies group across 1 directory with 7 updates - #12

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-faaac8ca66
Open

chore(deps): bump the production-dependencies group across 1 directory with 7 updates#12
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/production-dependencies-faaac8ca66

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown

Bumps the production-dependencies group with 7 updates in the / directory:

Package From To
@lexical/rich-text 0.35.0 0.49.0
@tauri-apps/api 2.11.0 2.11.1
@tauri-apps/plugin-dialog 2.7.1 2.7.2
mermaid 11.16.1 11.17.2
lexical 0.35.0 0.49.0
react 19.2.7 19.2.8
react-dom 19.2.7 19.2.8

Updates @lexical/rich-text from 0.35.0 to 0.49.0

Release notes

Sourced from @​lexical/rich-text's releases.

v0.49.0 is a monthly release headlined by the completion of the $config() protocol migration for Lexical's built-in node classes (#8640), a breaking change that replaces per-node getType()/clone()/importJSON()/importDOM()/transform() boilerplate with runtime-synthesized behavior. It ships with a cluster of follow-up fixes hardening the synthesized getType() and clone() (including a stack overflow in compiled builds), an opt-in sticky horizontal scrollbar for overflowing tables, and a broad batch of fixes across tables, Markdown, HTML, code highlighting, and selection.

Breaking Changes

  • lexical — Built-in node classes are ported to the $config() protocol. The static importJSON(), importDOM(), clone(), and transform() methods are no longer present on ported nodes; use the higher-level equivalents instead (LexicalEditor.parseEditorState/$generateNodesFromDOM, the $cloneWithProperties helper, and extensions or $transform in $config). getType() is unchanged and safe to keep using, __type is now readonly, and node constructors require zero-argument defaults. Custom nodes may keep their static methods, but adopting $config() is recommended (#8640)
  • lexicalLexicalCommand<T>'s payload type is now invariant to prevent unsafe structural compatibility between commands. Previously correct code (including explicit generics) needs no changes; only unsafe LexicalCommand<unknown> usage must switch to the newly exported AnyLexicalCommand alias. dispatchCommand's payload argument is now optional when a command's payload type is undefined or void, and redundant explicit type parameters were dropped from the registerCommand/registerNodeTransform call sites (#8877)

New APIs & Features

  • @lexical/table — Opt-in sticky horizontal scrollbar for tables wider than their container, so the scrollbar stays anchored at the viewport bottom instead of only being reachable at the end of the table. Enable it with hasStickyScrollbar: true in the table config; style it via the new tableStickyScrollbar theme key (#8790)
  • @lexical/table — The <colgroup> element is now omitted from the table DOM when column widths are undefined, producing cleaner markup and letting the browser auto-size columns; it is created or removed dynamically as widths change (#8850)
  • lexical — Added an editor operation benchmark suite (paragraph split, bold formatting, range deletion, paste, select-all format) measured through full DOM reconciliation, to help contributors track core editing performance (#8856)

Deprecations

  • @lexical/table$createTableSelection is deprecated in favor of $createTableSelectionFrom, which takes the table node plus anchor/focus cells and validates them, instead of returning a blank selection with placeholder 'root' keys that must be overwritten (#8855)
  • @lexical/tablegetShape() is deprecated because it computes incorrect bounds for merged cells; use the now-exported $computeTableCellRectBoundary (with $computeTableMap) instead (#8853)

Notable Fixes

$config() follow-ups (#8640)

  • The synthesized clone() now applies afterCloneFrom() when called directly (e.g. NodeClass.clone(node)), fixing silent property loss across 25+ core nodes (#8864)
  • The synthesized getType() no longer returns the superclass type when inherited, fixing node-type collisions during editor registration (#8867)
  • The synthesized getType() no longer recurses infinitely when a bundler copies it onto a subclass as an own static, fixing stack overflows in compiled/minified builds (#8869)

Tables

  • DELETE_LINE_COMMAND (Cmd/Ctrl-based delete-line shortcuts) now works inside table cells instead of being silently swallowed (#8851)
  • Table alignment now works when cells are selected in any direction, not just top-left→bottom-right (#8883)

Selection & editing

  • Editor updates dispatched from a read-only context (e.g. inside editor.read()) now run in a fresh writable update instead of being silently dropped, with a dev warning (#8863)
  • Firefox now creates a selection and shows the block cursor when clicking in the gap between block decorators (#8862)
  • Pressing ArrowUp before a leading non-inline decorator no longer moves the selection out of the editor (#8887)

Markdown, HTML & code

  • Typing a list marker at the start of a heading no longer converts the heading into a list (#8879)
  • HTML import now evaluates unrestricted CSS selector groups (e.g. p, .foo) against all elements instead of only tag-matched ones (#8873)
  • Concurrent async language/theme loads in the Shiki highlighter are deduplicated and merged into a single history entry, avoiding spurious undo states (#8854)
  • QuoteNode.updateDOM now accepts the EditorConfig argument the reconciler passes to every other node, for API consistency (#8882)

Playground & website

  • Playground scroll padding now accounts for the sticky toolbar so selections scrolled into view from above aren't hidden behind it (#8849)
  • Fixed a homepage crash caused by a minified dev build, and isolated each embedded example in its own error boundary so one failure no longer takes down the page (#8861)

What's Changed

... (truncated)

Changelog

Sourced from @​lexical/rich-text's changelog.

v0.49.0 (2026-07-29)

  • lexical-markdown Bug Fix Preserve headings when typing list shortcuts (#8879) Steven Dang
  • lexical-rich-text Bug Fix Forward editorConfig to QuoteNode.updateDOM (#8882) Sha Halimi
  • lexical-table Bug Fix Table alignment fails when selecting in non-TL-BR direction (#8883) sahir
  • Breaking Changelexical Chore Remove redundant registerCommandregisterNodeTransform generics (#8877) mayrang
  • lexical-html Bug Fix Dispatch unrestricted CSS selector groups (#8873) Madan kumar
  • lexical-playground Bug Fix Deterministic history coalescing for flaky webkit undo tests (#8874) Bob Ippolito
  • lexical Performance Skip redundant selection restoration in removeTextFromCaretRange (#8872) mayrang
  • lexical Refactor Simplify RangeSelection.insertText via removeText decomposition (#8870) mayrang
  • lexical-list Chore Remove redundant decorator-adjacent backspace handler (#8871) mayrang
  • lexical-table Feature Skip colgroup element in table DOM with undefined col widths (#8850) Zachary Gallafent
  • lexical Bug Fix Create selection when clicking between block decorators on Firefox (#8862) mayrang
  • fix config() synthesized getType() recurses infinitely when inherited as own static (#8867 follow-up) (#8869) Sherry
  • lexicallexical-website Bug Fix Homepage crash from optimized dev build (#8861) Bob Ippolito
  • lexical Bug Fix run editor updates dispatched from a read-only context in a fresh writable update (#8863) Sherry
  • lexical Feature Editor operation benchmarks (#8856) mayrang
  • lexical Chore Migrate LexicalSelection tests to buildEditorFromExtensions (#8865) mayrang
  • fix config() synthesized getType() inherited by subclasses causes node-type collision (#8640) (#8867) Sherry
  • fix config() auto-synthesized clone() loses properties when called directly (#8640) (#8864) Sherry
  • lexical-tablelexical Feature Sticky scrollbar for overflowing tables (#8790) mayrang
  • lexical-code-shiki Bug Fix Deduplicate async loads and merge into history (#8854) Alexis
  • lexical-table Chore Remove dead code in table command handlers (#8857) mayrang
  • lexical-tablelexical-playground Chore Deprecate getShape() and migrate playground (#8853) mayrang
  • lexical-list Chore Rename isNestedListNode to isNestedListNode (#8843) Bob Ippolito
  • lexical-playground Bug Fix account for sticky toolbar in scroll padding (#8849) Bob Ippolito
  • Breaking Changeslexical Refactor Port node classes to the config() protocol (#8640) Bob Ippolito
  • lexical-table Chore Deprecate createTableSelection in favor of createTableSelectionFrom (#8855) mayrang
  • lexical-table Bug Fix Enable DELETELINECOMMAND in table cells (#8851) mayrang
  • lexical Bug Fix Scope bench vitest projects to exclude regular test files (#8852) mayrang
  • v0.48.0 (#8847) Bob Ippolito
  • v0.48.0 Lexical GitHub Actions Bot

v0.48.0 (2026-07-16)

  • lexical-reactlexical-table Bug Fix Enable table copy in read-only mode (#8845) mayrang
  • lexical-extensionlexical-mdastdev-mdast-editor-example Feature Add MdastHtmlExtension and Markdown custom-construct examples (collapsible, kbd, alerts, footnotes) (#8826) Bob Ippolito
  • Fix fail closed in LinkNode.sanitizeUrl() on unparseable URLs (XSS) (#8846) xiezhenjia-meta
  • lexical Chore Fix serialize-javascript package dependency vulnerability (#8803) vijay ojha
  • lexical-react Bug Fix Count block separators in character limit overflow wrapping (#8840) mayrang
  • lexical-yjslexical-react Feature Customizable Yjs shared-type root name (#8841) mayrang
  • lexical-list Bug Fix Backspace at start of list item outdents or converts to paragraph (#8829) mayrang
  • lexical-table Feature Add moveTableRow function Add missing export for unmergeCellNode (#8833)
  • lexical-link Bug Fix disable link opening for disabled autolink in (#8839) Olivier Chevallier
  • lexical-rich-textlexical-plain-text Bug Fix dont cancel dragover for text drags so native drops work again (#8842) Bob Ippolito
  • Open playground links in a new tab (#8837) Sherry
  • lexical-react Bug Fix Merge adjacent OverflowNodes in useCharacterLimit (#8831) mayrang
  • lexical-code-shiki Bug Fix force re-tokenize after async language load (#8830) Olivier Chevallier
  • lexical-tablelexical-playground Bug Fix Auto-scroll while drag-selecting cells past the visible edge (#8822) Oleksandr Trukhnii
  • lexical-mdastlexical-markdown Bug Fix Roundtrip overlapping inline formats (#8825) Bob Ippolito

... (truncated)

Commits
  • ffe9092 v0.49.0
  • 9f99510 [lexical-rich-text] Bug Fix: Keep block cursor in editor when ArrowUp at star...
  • c7630f9 [lexical-rich-text] Bug Fix: Forward editorConfig to QuoteNode.updateDOM (#8882)
  • 82cdae1 [Breaking Change][lexical] Chore: Remove redundant registerCommand/registerNo...
  • 5fc8eae [Breaking Changes][lexical] Refactor: Port node classes to the $config() prot...
  • ba4d6d0 v0.48.0 (#8847)
  • 364e128 [lexical-rich-text][lexical-plain-text] Bug Fix: don't cancel dragover for te...
  • e4b7cc3 v0.47.0 (#8821)
  • 18a0abf [lexical][lexical-rich-text][lexical-selection] Bug Fix: Fix navigation acros...
  • 02d2562 [lexical][lexical-rich-text] Bug Fix: Fix formatText toggle direction and add...
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​lexical/rich-text since your current version.


Updates @tauri-apps/api from 2.11.0 to 2.11.1

Release notes

Sourced from @​tauri-apps/api's releases.

@​tauri-apps/api v2.11.1

No known vulnerabilities found

[2.11.1]

Enhancements

  • 916782601 (#15520 by @​polw1) Document that Monitor.size, Monitor.position and Monitor.workArea are in physical pixels, with examples showing how to convert them to the logical pixels expected by window creation options via toLogical(monitor.scaleFactor).
> @tauri-apps/api@2.11.1 npm-publish /home/runner/work/tauri/tauri/packages/api
> pnpm build && cd ./dist && pnpm publish --access public --loglevel silly --no-git-checks

> @​tauri-apps/api@​2.11.1 build /home/runner/work/tauri/tauri/packages/api > rollup -c --configPlugin typescript

�[36m �[1m./src/app.ts, ./src/core.ts, ./src/dpi.ts, ./src/event.ts, ./src/image.ts, ./src/index.ts, ./src/menu.ts, ./src/mocks.ts, ./src/path.ts, ./src/tray.ts, ./src/webview.ts, ./src/webviewWindow.ts, ./src/window.ts�[22m → �[1m./dist, ./dist�[22m...�[39m �[32mcreated �[1m./dist, ./dist�[22m in �[1m883ms�[22m�[39m �[36m �[1msrc/index.ts�[22m → �[1m../../crates/tauri/scripts/bundle.global.js�[22m...�[39m �[32mcreated �[1m../../crates/tauri/scripts/bundle.global.js�[22m in �[1m1.4s�[22m�[39m npm verbose cli /opt/hostedtoolcache/node/24.16.0/x64/bin/node /opt/hostedtoolcache/node/24.16.0/x64/bin/npm npm info using npm@11.13.0 npm info using node@v24.16.0 npm silly config load:file:/opt/hostedtoolcache/node/24.16.0/x64/lib/node_modules/npm/npmrc npm silly config load:file:/tmp/286e8dee195254a4370e608b672019b0/.npmrc npm silly config load:file:/home/runner/.npmrc npm silly config load:file:/home/runner/.config/pnpm/rc npm verbose title npm publish tauri-apps-api-2.11.1.tgz npm verbose argv "publish" "--ignore-scripts" "tauri-apps-api-2.11.1.tgz" "--access" "public" "--loglevel" "silly" npm verbose logfile logs-max:10 dir:/home/runner/.npm/_logs/2026-06-17T13_41_23_851Z- npm verbose logfile /home/runner/.npm/_logs/2026-06-17T13_41_23_851Z-debug-0.log npm warn Unknown env config "verify-deps-before-run". This will stop working in the next major version of npm. See npm help npmrc for supported config options. npm warn Unknown env config "npm-globalconfig". This will stop working in the next major version of npm. See npm help npmrc for supported config options. npm warn Unknown env config "overrides". This will stop working in the next major version of npm. See npm help npmrc for supported config options. npm warn Unknown env config "_jsr-registry". This will stop working in the next major version of npm. See npm help npmrc for supported config options. npm silly logfile done cleaning log files npm verbose publish [ 'tauri-apps-api-2.11.1.tgz' ] </tr></table>

... (truncated)

Commits

Updates @tauri-apps/plugin-dialog from 2.7.1 to 2.7.2

Release notes

Sourced from @​tauri-apps/plugin-dialog's releases.

dialog-js v2.7.2

[2.7.2]

  • 40ae0a7f (#3491 by @​Legend-Master) Use com.google.android.material.dialog.MaterialAlertDialogBuilder instead of AlertDialog so the dialog follows the app's theme
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-dialog@2.7.2
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 3.5kB README.md
npm notice 6.9kB dist-js/index.cjs
npm notice 14.6kB dist-js/index.d.ts
npm notice 6.8kB dist-js/index.js
npm notice 11B dist-js/init.d.ts
npm notice 657B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-dialog
npm notice version: 2.7.2
npm notice filename: tauri-apps-plugin-dialog-2.7.2.tgz
npm notice package size: 6.7 kB
npm notice unpacked size: 33.3 kB
npm notice shasum: 322d0874bae71fed6d10c76168fa0f7f4d5dd875
npm notice integrity: sha512-pX0IGm1I3I6wc[...]0jQGQNyOvLrsg==
npm notice total files: 7
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=2194858458
+ @tauri-apps/plugin-dialog@2.7.2

dialog v2.7.2

[2.7.2]

  • 40ae0a7f (#3491 by @​Legend-Master) Use com.google.android.material.dialog.MaterialAlertDialogBuilder instead of AlertDialog so the dialog follows the app's theme

... (truncated)

Commits

Updates mermaid from 11.16.1 to 11.17.2

Release notes

Sourced from mermaid's releases.

mermaid@11.17.2

Patch Changes

  • #8125 178d7c7 Thanks @​knsv-bot! - fix: restore the edgePaths class on the edge group in rendered SVG, and point the flowchart, block and user journey stylesheets at it

mermaid@11.17.1

Patch Changes

  • #8092 31ce60a Thanks @​pbrolin47! - fix(c4): wrap element labels to c4.width again

    C4 element labels (System, Container, Component, Person and their _Ext variants) stopped wrapping in 11.17.0, so long descriptions rendered on one unbroken line and the shape grew sideways well past the configured c4.width. The unified-shapes label helper gated wrapping on the root-level wrap option, which has no schema default and is therefore undefined; it now gates on c4.wrap (default true), which is what the legacy renderer used.

  • #8088 c66200b Thanks @​ashishjain0512! - fix: neo-look arrowheads and crow's-foot markers no longer fall back to default theme colours/stroke widths on the first render with layout: elk. State diagram arrowheads stayed dark on dark themes, and ER / requirement markers were drawn at the default stroke width, because markers were created from the layout package's own bundled copy of mermaid, whose config had not been initialized yet.

  • #8079 281cd7b Thanks @​ashishjain0512! - fix(class): class diagram relation markers (composition, aggregation, extension, dependency, lollipop) no longer scale with the edge stroke width, so they stay outside the class box boundary in themes that set strokeWidth: 2 (redux, redux-dark, redux-color, redux-dark-color, neo, neo-dark) with the default classic look.

mermaid@11.17.0

Minor Changes

Patch Changes

  • #7847 215fe89 Thanks @​filipsajdak! - fix(c4): named attributes such as $tags, $link and $sprite are no longer clobbered to undefined when they arrive in an earlier positional slot of Person/System/Container/Component/Boundary/Rel statements.

  • #7871 8d874c4 Thanks @​knsv-bot! - fix(flowchart): stop dagre layout from spamming warn-level logs on every node/edge/cluster

  • #8071 b3d1f63 Thanks @​pbrolin47! - fix(block): sibling blocks overlapping in block diagrams when one has a label wider than 200px

  • #7870 71b8843 Thanks @​knsv-bot! - fix: a RangeError: Invalid array length crash when rendering certain edges.

  • #7924 9cbef5d Thanks @​nightt5879! - fix(treeView): icons disappearing after strict security sanitization.

... (truncated)

Commits

Updates lexical from 0.35.0 to 0.49.0

Release notes

Sourced from lexical's releases.

v0.49.0 is a monthly release headlined by the completion of the $config() protocol migration for Lexical's built-in node classes (#8640), a breaking change that replaces per-node getType()/clone()/importJSON()/importDOM()/transform() boilerplate with runtime-synthesized behavior. It ships with a cluster of follow-up fixes hardening the synthesized getType() and clone() (including a stack overflow in compiled builds), an opt-in sticky horizontal scrollbar for overflowing tables, and a broad batch of fixes across tables, Markdown, HTML, code highlighting, and selection.

Breaking Changes

  • lexical — Built-in node classes are ported to the $config() protocol. The static importJSON(), importDOM(), clone(), and transform() methods are no longer present on ported nodes; use the higher-level equivalents instead (LexicalEditor.parseEditorState/$generateNodesFromDOM, the $cloneWithProperties helper, and extensions or $transform in $config). getType() is unchanged and safe to keep using, __type is now readonly, and node constructors require zero-argument defaults. Custom nodes may keep their static methods, but adopting $config() is recommended (#8640)
  • lexicalLexicalCommand<T>'s payload type is now invariant to prevent unsafe structural compatibility between commands. Previously correct code (including explicit generics) needs no changes; only unsafe LexicalCommand<unknown> usage must switch to the newly exported AnyLexicalCommand alias. dispatchCommand's payload argument is now optional when a command's payload type is undefined or void, and redundant explicit type parameters were dropped from the registerCommand/registerNodeTransform call sites (#8877)

New APIs & Features

  • @lexical/table — Opt-in sticky horizontal scrollbar for tables wider than their container, so the scrollbar stays anchored at the viewport bottom instead of only being reachable at the end of the table. Enable it with hasStickyScrollbar: true in the table config; style it via the new tableStickyScrollbar theme key (#8790)
  • @lexical/table — The <colgroup> element is now omitted from the table DOM when column widths are undefined, producing cleaner markup and letting the browser auto-size columns; it is created or removed dynamically as widths change (#8850)
  • lexical — Added an editor operation benchmark suite (paragraph split, bold formatting, range deletion, paste, select-all format) measured through full DOM reconciliation, to help contributors track core editing performance (#8856)

Deprecations

  • @lexical/table$createTableSelection is deprecated in favor of $createTableSelectionFrom, which takes the table node plus anchor/focus cells and validates them, instead of returning a blank selection with placeholder 'root' keys that must be overwritten (#8855)
  • @lexical/tablegetShape() is deprecated because it computes incorrect bounds for merged cells; use the now-exported $computeTableCellRectBoundary (with $computeTableMap) instead (#8853)

Notable Fixes

$config() follow-ups (#8640)

  • The synthesized clone() now applies afterCloneFrom() when called directly (e.g. NodeClass.clone(node)), fixing silent property loss across 25+ core nodes (#8864)
  • The synthesized getType() no longer returns the superclass type when inherited, fixing node-type collisions during editor registration (#8867)
  • The synthesized getType() no longer recurses infinitely when a bundler copies it onto a subclass as an own static, fixing stack overflows in compiled/minified builds (#8869)

Tables

  • DELETE_LINE_COMMAND (Cmd/Ctrl-based delete-line shortcuts) now works inside table cells instead of being silently swallowed (#8851)
  • Table alignment now works when cells are selected in any direction, not just top-left→bottom-right (#8883)

Selection & editing

  • Editor updates dispatched from a read-only context (e.g. inside editor.read()) now run in a fresh writable update instead of being silently dropped, with a dev warning (#8863)
  • Firefox now creates a selection and shows the block cursor when clicking in the gap between block decorators (#8862)
  • Pressing ArrowUp before a leading non-inline decorator no longer moves the selection out of the editor (#8887)

Markdown, HTML & code

  • Typing a list marker at the start of a heading no longer converts the heading into a list (#8879)
  • HTML import now evaluates unrestricted CSS selector groups (e.g. p, .foo) against all elements instead of only tag-matched ones (#8873)
  • Concurrent async language/theme loads in the Shiki highlighter are deduplicated and merged into a single history entry, avoiding spurious undo states (#8854)
  • QuoteNode.updateDOM now accepts the EditorConfig argument the reconciler passes to every other node, for API consistency (#8882)

Playground & website

  • Playground scroll padding now accounts for the sticky toolbar so selections scrolled into view from above aren't hidden behind it (#8849)
  • Fixed a homepage crash caused by a minified dev build, and isolated each embedded example in its own error boundary so one failure no longer takes down the page (#8861)

What's Changed

... (truncated)

Changelog

Sourced from lexical's changelog.

v0.49.0 (2026-07-29)

  • lexical-markdown Bug Fix Preserve headings when typing list shortcuts (#8879) Steven Dang
  • lexical-rich-text Bug Fix Forward editorConfig to QuoteNode.updateDOM (#8882) Sha Halimi
  • lexical-table Bug Fix Table alignment fails when selecting in non-TL-BR direction (#8883) sahir
  • Breaking Changelexical Chore Remove redundant registerCommandregisterNodeTransform generics (#8877) mayrang
  • lexical-html Bug Fix Dispatch unrestricted CSS selector groups (#8873) Madan kumar
  • lexical-playground Bug Fix Deterministic history coalescing for flaky webkit undo tests (#8874) Bob Ippolito
  • lexical Performance Skip redundant selection restoration in removeTextFromCaretRange (#8872) mayrang
  • lexical Refactor Simplify RangeSelection.insertText via removeText decomposition (#8870) mayrang
  • lexical-list Chore Remove redundant decorator-adjacent backspace handler (#8871) mayrang
  • lexical-table Feature Skip colgroup element in table DOM with undefined col widths (#8850) Zachary Gallafent
  • lexical Bug Fix Create selection when clicking between block decorators on Firefox (#8862) mayrang
  • fix config() synthesized getType() recurses infinitely when inherited as own static (#8867 follow-up) (#8869) Sherry
  • lexicallexical-website Bug Fix Homepage crash from optimized dev build (#8861) Bob Ippolito
  • lexical Bug Fix run editor updates dispatched from a read-only context in a fresh writable update (#8863) Sherry
  • lexical Feature Editor operation benchmarks (#8856) mayrang
  • lexical Chore Migrate LexicalSelection tests to buildEditorFromExtensions (#8865) mayrang
  • fix config() synthesized getType() inherited by subclasses causes node-type collision (#8640) (#8867) Sherry
  • fix config() auto-synthesized clone() loses properties when called directly (#8640) (#8864) Sherry
  • lexical-tablelexical Feature Sticky scrollbar for overflowing tables (#8790) mayrang
  • lexical-code-shiki Bug Fix Deduplicate async loads and merge into history (#8854) Alexis
  • lexical-table Chore Remove dead code in table command handlers (#8857) mayrang
  • lexical-tablelexical-playground Chore Deprecate getShape() and migrate playground (#8853) mayrang
  • lexical-list Chore Rename isNestedListNode to isNestedListNode (#8843) Bob Ippolito
  • lexical-playground Bug Fix account for sticky toolbar in scroll padding (#8849) Bob Ippolito
  • Breaking Changeslexical Refactor Port node classes to the config() protocol (#8640) Bob Ippolito
  • lexical-table Chore Deprecate createTableSelection in favor of createTableSelectionFrom (#8855) mayrang
  • lexical-table Bug Fix Enable DELETELINECOMMAND in table cells (#8851) mayrang
  • lexical Bug Fix Scope bench vitest projects to exclude regular test files (#8852) mayrang
  • v0.48.0 (#8847) Bob Ippolito
  • v0.48.0 Lexical GitHub Actions Bot

v0.48.0 (2026-07-16)

  • lexical-reactlexical-table Bug Fix Enable table copy in read-only mode (#8845) mayrang
  • lexical-extensionlexical-mdastdev-mdast-editor-example Feature Add MdastHtmlExtension and Markdown custom-construct examples (collapsible, kbd, alerts, footnotes) (#8826) Bob Ippolito
  • Fix fail closed in LinkNode.sanitizeUrl() on unparseable URLs (XSS) (#8846) xiezhenjia-meta
  • lexical Chore Fix serialize-javascript package dependency vulnerability (#8803) vijay ojha
  • lexical-react Bug Fix Count block separators in character limit overflow wrapping (#8840) mayrang
  • lexical-yjslexical-react Feature Customizable Yjs shared-type root name (#8841) mayrang
  • lexical-list Bug Fix Backspace at start of list item outdents or converts to paragraph (#8829) mayrang
  • lexical-table Feature Add moveTableRow function Add missing export for unmergeCellNode (#8833)
  • lexical-link Bug Fix disable link opening for disabled autolink in (#8839) Olivier Chevallier
  • lexical-rich-textlexical-plain-text Bug Fix dont cancel dragover for text drags so native drops work again (#8842) Bob Ippolito
  • Open playground links in a new tab (#8837) Sherry
  • lexical-react Bug Fix Merge adjacent OverflowNodes in useCharacterLimit (#8831) mayrang
  • lexical-code-shiki Bug Fix force re-tokenize after async language load (#8830) Olivier Chevallier
  • lexical-tablelexical-playground Bug Fix Auto-scroll while drag-selecting cells past the visible edge (#8822) Oleksandr Trukhnii
  • lexical-mdastlexical-markdown Bug Fix Roundtrip overlapping inline formats (#8825) Bob Ippolito

... (truncated)

Commits
  • ffe9092 v0.49.0
  • 82cdae1 [Breaking Change][lexical] Chore: Remove redundant registerCommand/registerNo...
  • 0a84aef [lexical] Performance: Skip redundant selection restoration in $removeTextFro...
  • 97fef1f [lexical] Refactor: Simplify RangeSelection.insertText via removeText decompo...
  • 443012c [lexical] Bug Fix: Create selection when clicking between block decorators on...
  • fccc283 fix: $config() synthesized getType() recurses infinitely when inherited as ow...
  • 3429b57 [lexical][lexical-website] Bug Fix: Homepage crash from optimized dev build (...
  • aabfaaa [lexical] Bug Fix: run editor updates dispatched from a read-only context in ...
  • e5e345d [lexical] Feature: Editor operation benchmarks (#8856)
  • 385a93c [lexical] Chore: Migrate LexicalSelection tests to buildEditorFromExtensions ...
  • Additional commits vi...

    Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 24, 2026
…y with 7 updates

Bumps the production-dependencies group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@lexical/rich-text](https://github.com/facebook/lexical/tree/HEAD/packages/lexical-rich-text) | `0.35.0` | `0.49.0` |
| [@tauri-apps/api](https://github.com/tauri-apps/tauri) | `2.11.0` | `2.11.1` |
| [@tauri-apps/plugin-dialog](https://github.com/tauri-apps/plugins-workspace) | `2.7.1` | `2.7.2` |
| [mermaid](https://github.com/mermaid-js/mermaid) | `11.16.1` | `11.17.2` |
| [lexical](https://github.com/facebook/lexical/tree/HEAD/packages/lexical) | `0.35.0` | `0.49.0` |
| [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.7` | `19.2.8` |
| [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.7` | `19.2.8` |



Updates `@lexical/rich-text` from 0.35.0 to 0.49.0
- [Release notes](https://github.com/facebook/lexical/releases)
- [Changelog](https://github.com/facebook/lexical/blob/main/CHANGELOG.md)
- [Commits](https://github.com/facebook/lexical/commits/v0.49.0/packages/lexical-rich-text)

Updates `@tauri-apps/api` from 2.11.0 to 2.11.1
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](https://github.com/tauri-apps/tauri/compare/@tauri-apps/api-v2.11.0...@tauri-apps/api-v2.11.1)

Updates `@tauri-apps/plugin-dialog` from 2.7.1 to 2.7.2
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@log-v2.7.1...dialog-v2.7.2)

Updates `mermaid` from 11.16.1 to 11.17.2
- [Release notes](https://github.com/mermaid-js/mermaid/releases)
- [Commits](https://github.com/mermaid-js/mermaid/compare/mermaid@11.16.1...mermaid@11.17.2)

Updates `lexical` from 0.35.0 to 0.49.0
- [Release notes](https://github.com/facebook/lexical/releases)
- [Changelog](https://github.com/facebook/lexical/blob/main/CHANGELOG.md)
- [Commits](https://github.com/facebook/lexical/commits/v0.49.0/packages/lexical)

Updates `react` from 19.2.7 to 19.2.8
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.2.8/packages/react)

Updates `react-dom` from 19.2.7 to 19.2.8
- [Release notes](https://github.com/react/react/releases)
- [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/react/react/commits/v19.2.8/packages/react-dom)

---
updated-dependencies:
- dependency-name: "@lexical/rich-text"
  dependency-version: 0.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@tauri-apps/api"
  dependency-version: 2.11.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@tauri-apps/plugin-dialog"
  dependency-version: 2.7.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: lexical
  dependency-version: 0.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: mermaid
  dependency-version: 11.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: react
  dependency-version: 19.2.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: react-dom
  dependency-version: 19.2.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/production-dependencies-faaac8ca66 branch from 23f319a to 1805787 Compare August 31, 2026 14:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants