Skip to content

release: beta → main (next stable) - #344

Draft
eFAILution wants to merge 2 commits into
mainfrom
beta
Draft

eFAILution wants to merge 2 commits into
mainfrom
beta

Conversation

@eFAILution

Copy link
Copy Markdown
Owner

Rolling integration PR for the next stable release. It stays open while beta is refined and picks up every new commit merged to beta automatically. Do not merge until the release is ready. Merging to main cuts a stable GitHub Release straight away.

What is on beta today

Commit
#325 refactor(webview): render every webview document from type-checked TSX views, escaped by default

Plus the chore(release) bump to 0.19.0.

Headline change

#325 moves the Component Browser, details panel, loading, no-sources and error views out of template literals into TSX views rendered with preact-render-to-string. Markup errors now fail tsc, every interpolation is escaped unless it goes through one of the two raw-HTML helpers in Page.tsx, and lint bans inline styles, inline handlers and raw HTML elsewhere. No user-facing change is intended. It was checked by hand in a real VS Code against the packaged build, with no CSP violations (see the comments on #325).

Security

npm audit on beta reports 22 findings (21 high, 1 critical). All of them sit in dev tooling: release-it, stylelint, commitizen and their transitive deps (basic-ftp, braces, shell-quote). None are imported from src/, so none ship in the VSIX. Open Dependabot PRs #340, #342 and #343 target beta and may clear some of these.

Versioning

beta sits at 0.19.0. Odd minor is the pre-release channel. On merge, .release-it.json's requireEvenMinor rolls this forward to 0.20.0 for the stable channel.

The VS Code Marketplace publish is still a separate manual workflow_dispatch. A GitHub Release from this merge does not ship anything to users by itself.

Verification on beta

Before merging

X-Guardian and others added 2 commits October 6, 2026 10:53
Move every webview document from template literals into TSX views rendered with preact-render-to-string. Escaping is now on by default, markup errors fail tsc, and lint bans inline styles, handlers and raw HTML outside Page.tsx.
@eFAILution
eFAILution deployed to publish-beta October 6, 2026 15:29 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
publish-beta — 9910dda6 Deployed Oct 6, 2026 by eFAILution via publish #30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants