Skip to content

chore(deps): bump mermaid from 11.16.0 to 11.16.1 - #170

Merged
helebest merged 1 commit into
mainfrom
dependabot/npm_and_yarn/mermaid-11.16.1
Aug 8, 2026
Merged

chore(deps): bump mermaid from 11.16.0 to 11.16.1#170
helebest merged 1 commit into
mainfrom
dependabot/npm_and_yarn/mermaid-11.16.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 8, 2026

Copy link
Copy Markdown
Contributor

Bumps mermaid from 11.16.0 to 11.16.1.

Release notes

Sourced from mermaid's releases.

mermaid@11.16.1

Patch Changes

  • #8022 12d472c Thanks @​aloisklink! - fix: handle CSS sibling combinators in compileCSS

  • #8022 2cd6dcf Thanks @​aloisklink! - fix: increase protections against prototype pollution

    User-controlled input already has protections against prototype pollution.

    Fixes: GHSA-c4c3-pg64-4m4v

  • #8022 99af3fc Thanks @​aloisklink! - fix(architecture): use Maps and Sets to store groups/services

    Services are now rendered in the order they are defined and more service IDs are now supported.

  • #8022 2cd6dcf Thanks @​aloisklink! - deprecate: Deprecate the mermaidAPI.setConfig() function

    Calling this function has no observable effect, as the next time a render() or parse() is called, the currentConfig is cleared.

  • #8022 630aa7e Thanks @​aloisklink! - fix(xychart): support zero-width x-axis ranges

  • #8022 59b22fa Thanks @​aloisklink! - fix(radar): limit number of ticks to 32

    Setting a ticks value higher than this would only show 32 ticks.

Commits
  • 7ecca0c Version Packages (#8023)
  • 95b1b9c docs: change mermaidAPI.setConfig() changeset (#8024)
  • acc69f1 Merge pull request #8022 from mermaid-js/release/11.16.1
  • eba7287 docs: point changesets to correct commit hashes
  • 12d472c Merge commit from fork
  • 2cd6dcf Merge commit from fork
  • 630aa7e Merge commit from fork
  • 59b22fa Merge commit from fork
  • 99af3fc Merge commit from fork
  • 2337f7e Merge branch 'test/improve-example.html' into release/11.16.1
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [mermaid](https://github.com/mermaid-js/mermaid) from 11.16.0 to 11.16.1.
- [Release notes](https://github.com/mermaid-js/mermaid/releases)
- [Commits](https://github.com/mermaid-js/mermaid/compare/mermaid@11.16.0...mermaid@11.16.1)

---
updated-dependencies:
- dependency-name: mermaid
  dependency-version: 11.16.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 8, 2026

helebest commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

Automated dependency review — mermaid 11.16.0 → 11.16.1

Step 1 — Code review

  • Consistency: The diff matches the PR description exactly — package.json + package-lock.json move mermaid from ^11.16.0 to ^11.16.1 (2 files, +5/−5), no unrelated changes.
  • Correctness / effectiveness: Patch release; achieves its stated purpose (single dependency bump).
  • Security: This is a security-relevant patch. 11.16.1 hardens against prototype pollution (GHSA-c4c3-pg64-4m4v) and fixes CSS sibling-combinator handling in compileCSS. mermaidAPI.setConfig() is deprecated but the app does not call it (Mermaid is used via the markdown reader's fenced mermaid blocks). No breaking API changes affect our usage.
  • Conventions / test coverage: Version-only change; no functional code touched, so no new tests are warranted.

Step 2 — Regression verification

The required Verify (typecheck + coverage + build + e2e) job — which runs the full npm run verify gate (lint + format:check + typecheck + coverage + build + Playwright e2e) against this PR's head — passed. ✅

Step 3 — CI status

Required checks all green on e630928: Verify, Gate integrity, CodeQL / Analyze, Secret scan (gitleaks).

The two red jobs — Dependency audit (prod, high+) and Container scan (trivy) — are pre-existing failures on main, unrelated to this bump. The audit failure is entirely in the googleapis@google-cloud/opentelemetry-cloud-monitoring-exporteruuid/teeny-request transitive chain (nothing mermaid touches), and trivy reports base-image OS CVEs. Both fail identically on every open PR (including trivial patches) and did not block the recently merged dependency PRs (#160#163). This bump does not introduce or worsen them.

Step 4 — Decision

All meaningful checks pass and the change is a safe, security-improving patch. Proceeding to squash merge.


Generated by Claude Code

@helebest
helebest merged commit 9e1167a into main Aug 8, 2026
8 of 10 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/mermaid-11.16.1 branch August 8, 2026 05:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant