Repository navigation
release: beta → main (next stable) - #344
Draft
eFAILution wants to merge 2 commits into
Draft
eFAILution wants to merge 2 commits into
eFAILution wants to merge 2 commits into
Conversation
Move every webview document from template literals into TSX views rendered with preact-render-to-string. Escaping is now on by default, markup errors fail tsc, and lint bans inline styles, handlers and raw HTML outside Page.tsx.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rolling integration PR for the next stable release. It stays open while
betais refined and picks up every new commit merged tobetaautomatically. Do not merge until the release is ready. Merging tomaincuts a stable GitHub Release straight away.What is on
betatodayrefactor(webview): render every webview document from type-checked TSX views, escaped by defaultPlus the
chore(release)bump to 0.19.0.Headline change
#325 moves the Component Browser, details panel, loading, no-sources and error views out of template literals into TSX views rendered with
preact-render-to-string. Markup errors now failtsc, every interpolation is escaped unless it goes through one of the two raw-HTML helpers inPage.tsx, and lint bans inline styles, inline handlers and raw HTML elsewhere. No user-facing change is intended. It was checked by hand in a real VS Code against the packaged build, with no CSP violations (see the comments on #325).Security
npm auditonbetareports 22 findings (21 high, 1 critical). All of them sit in dev tooling:release-it,stylelint,commitizenand their transitive deps (basic-ftp,braces,shell-quote). None are imported fromsrc/, so none ship in the VSIX. Open Dependabot PRs #340, #342 and #343 targetbetaand may clear some of these.Versioning
betasits at 0.19.0. Odd minor is the pre-release channel. On merge,.release-it.json'srequireEvenMinorrolls this forward to 0.20.0 for the stable channel.The VS Code Marketplace publish is still a separate manual
workflow_dispatch. A GitHub Release from this merge does not ship anything to users by itself.Verification on
betaBefore merging
betais feature-complete for this releasebeta(chore(ci): bump huntridge-labs/argus/.github/workflows/reusable-security-hardening.yml from 1.12.6 to 1.12.7 #340, chore(deps-dev): bump @octokit/plugin-paginate-rest from 15.0.0 to 16.0.0 #342, chore(deps-dev): bump the dev-dependencies group across 1 directory with 10 updates #343)betatip