Skip to content

chore(deps): roll up the pending dependency bumps - #740

Merged
EVWorth merged 1 commit into
mainfrom
claude/zen-babbage-6vq06i
Oct 5, 2026
Merged

EVWorth merged 1 commit into
mainfrom
claude/zen-babbage-6vq06i

Conversation

@EVWorth

@EVWorth EVWorth commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Combines the three open bot PRs into one, with the fixes each needed to pass CI. Supersedes #736, #737 and #738.

cargo (#736): rmcp 3.3.0 → 3.4.0

  • Dependabot bumped rmcp only in crates/mas-mcp. The app crate pins the same exact version (=3.3.0), so cargo couldn't resolve a version and Lint (Rust) and Test Rust both failed. This PR bumps both.
  • rmcp 3.4 deprecates the ServerInfo alias in favour of ServerConfig, which clippy -D warnings rejects. The three uses in mas-mcp/src/server.rs are renamed. ServerInfo is only an alias, so nothing changes at runtime.
  • dirs 6 → 7 is listed in chore(deps): bump the cargo group across 1 directory with 2 updates #736's title, but its diff never changed it. A major bump deserves its own look, so it's left out.

npm (#737): the 13 group updates

  • jsdom 30.1.0 pulls in whatwg-url@17.1.1. That version's registry metadata advertises a provenance attestation, but the registry returns 404 for it, so npm audit signatures fails. jsdom's copy is locked at 17.1.2 instead: it has the same dependencies, was published 13 days ago (inside .npmrc's min-release-age=7), and its attestation verifies. npm update would have picked 17.2.0, published today, so the lockfile entry was edited directly.

dprint (#738): @dprint/json 0.23.0 → 0.24.0

  • Includes the package.json key order the new plugin enforces, the same reformat the bot PR made. CI never ran on chore(deps): bump dprint plugins #738 because a bot opened it, so it runs here.

Verification (locally)

  • cargo test on the six crates CI runs: pass. cargo clippy -p mas-mcp --all-targets --all-features -D warnings: clean. cargo fmt --check: clean. The full-workspace clippy needs GTK, which this container doesn't have, so CI covers it.
  • npm audit signatures and npm audit --audit-level=critical: pass. npm run lint: no errors. npm run type-check and dprint check: clean.
  • npm run test:unit: 2970 pass. src/__tests__/main.test.tsx hits its 10s hook timeout under the full parallel run in this container, and does the same on unmodified main here. It passes on its own and passes on main in CI.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg


Generated by Claude Code

Combines the three open bot PRs, each fixed so CI can pass:

- cargo (#736): rmcp 3.3.0 -> 3.4.0. Dependabot bumped only mas-mcp, but
  the app crate pins rmcp to the same exact version, so cargo could not
  resolve. Bump both. rmcp 3.4 deprecates the ServerInfo alias in favour
  of ServerConfig; rename the three uses in mas-mcp so clippy -D warnings
  stays clean. dirs 6 -> 7 is listed in that PR's title but its diff never
  changed it, so it is left for a separate PR.
- npm (#737): the 13 group updates. jsdom 30.1.0 pulls whatwg-url 17.1.1,
  whose registry metadata advertises a provenance attestation the registry
  serves as 404, which fails `npm audit signatures`. Lock jsdom's copy at
  17.1.2 instead (same dependencies; 13 days old, inside min-release-age).
- dprint (#738): @dprint/json 0.23.0 -> 0.24.0, plus the package.json key
  order it now enforces.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg
@EVWorth
EVWorth merged commit 59fa84e into main Oct 5, 2026
12 checks passed
@EVWorth
EVWorth deleted the claude/zen-babbage-6vq06i branch October 5, 2026 01:02
EVWorth added a commit that referenced this pull request Oct 5, 2026
…t in CI (#747)

#740 moved @tauri-apps/plugin-updater to 2.12.0 while the
tauri-plugin-updater crate stayed at 2.11.0. `tauri build` refuses to
start when a Tauri npm package and its crate disagree on major.minor
("Found version mismatched Tauri packages"), so main could not build a
release. Nothing on a PR runs `tauri build`; only the release workflow
does, so CI stayed green.

Bump the crate to 2.12.0 (published 2026-09-20, past the seven-day
rule). The lockfile moves that one package and nothing else; tauri
stays at 2.11.5.

scripts/check-tauri-versions.sh applies the CLI's rule without a build:
@tauri-apps/api pairs with `tauri`, @tauri-apps/plugin-<x> with
tauri-plugin-<x>, compared from package-lock.json and Cargo.lock. It
runs in the Version Consistency job, which already triggers on either
lockfile, and in `just lint`. Against main's lockfiles it reports the
updater pair; with this change all four pairs agree.
scripts/test-check-tauri-versions.sh covers matching pairs, a plugin
a minor ahead, api-vs-tauri, patch-only differences, packages with no
crate, crate-name prefixes, nested npm copies, and no pairs at all.


Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg

Co-authored-by: Claude <noreply@anthropic.com>
EVWorth added a commit that referenced this pull request Oct 5, 2026
)

* fix(deps): match tauri-plugin-updater to its npm package, and check it in CI

#740 moved @tauri-apps/plugin-updater to 2.12.0 while the
tauri-plugin-updater crate stayed at 2.11.0. `tauri build` refuses to
start when a Tauri npm package and its crate disagree on major.minor
("Found version mismatched Tauri packages"), so main could not build a
release. Nothing on a PR runs `tauri build`; only the release workflow
does, so CI stayed green.

Bump the crate to 2.12.0 (published 2026-09-20, past the seven-day
rule). The lockfile moves that one package and nothing else; tauri
stays at 2.11.5.

scripts/check-tauri-versions.sh applies the CLI's rule without a build:
@tauri-apps/api pairs with `tauri`, @tauri-apps/plugin-<x> with
tauri-plugin-<x>, compared from package-lock.json and Cargo.lock. It
runs in the Version Consistency job, which already triggers on either
lockfile, and in `just lint`. Against main's lockfiles it reports the
updater pair; with this change all four pairs agree.
scripts/test-check-tauri-versions.sh covers matching pairs, a plugin
a minor ahead, api-vs-tauri, patch-only differences, packages with no
crate, crate-name prefixes, nested npm copies, and no pairs at all.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg

* chore(deps): bump Tauri to 2.12 on the npm and Rust sides together

`tauri build` requires each Tauri npm package and its crate to share a
major.minor, and Dependabot proposes npm and cargo separately: #745
moved the JS packages alone, which the new check-tauri-versions.sh
would fail. This moves every pair in one change.

  @tauri-apps/api 2.11.1 -> 2.12.0        tauri 2.11.5 -> 2.12.0
  @tauri-apps/cli 2.11.5 -> 2.12.0        tauri-build 2.6.3 -> 2.7.0
  @tauri-apps/plugin-process 2.3.1 -> 2.4.0   tauri-plugin-process 2.3.1 -> 2.4.0
  @tauri-apps/plugin-shell 2.3.6 -> 2.4.0     tauri-plugin-shell 2.3.6 -> 2.4.0
  @tauri-apps/plugin-updater 2.12.0 -> 2.13.0 tauri-plugin-updater 2.12.0 -> 2.13.0

All are the 2026-09-26 releases, nine days old; the .1 point releases
from 2026-09-29/30 are inside the seven-day window and left for later.
Cargo resolved tauri's internal crates (tauri-runtime, -runtime-wry,
-utils, -macros, -codegen, tauri-plugin) to their 09-30 releases, so
those are pinned back in the lockfile to the 09-26 set tauri 2.12.0
shipped with. The rest of the lockfile churn is tauri's own new
transitive versions (wry 0.57, tao 0.37, muda, tray-icon, webview2-com)
and drops the old windows 0.61 family and the unmaintained unic-*
crates, which takes cargo audit's non-blocking warnings from 9 to 4.

The plugins' 2.4/2.13 releases require tauri ^2.12, which is why
Dependabot could not offer them on their own.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg

---------

Co-authored-by: Claude <noreply@anthropic.com>
@EVWorth EVWorth mentioned this pull request Oct 5, 2026
EVWorth added a commit that referenced this pull request Oct 5, 2026
Version bump across the three manifests and the two lockfile entries
that record the app's own version.

What 1.2.0 contains since 1.1.0:

- Each editor tab runs on its own server session, so SET @var,
  temporary tables and multi-run transactions carry across runs (#734)
- Separate connection lanes for the agent and for backups/restores, so
  neither can starve the editor; the pool-exhausted message says what
  is holding the pool (#732, #727)
- Copy button beside Expand for long cell values, such as SHOW CREATE
  TABLE (#748)
- Linux/Wayland: WebKitGTK's DMABUF renderer is turned off, for the
  black area left after resizing the window (#742)
- Tauri 2.12 on both the npm and Rust sides (#749), and the dependency
  roll-up in #740
- rustls TLS 1.3 advisory RUSTSEC-2026-0285 patched (#728)

Also the first release built with rustup in place of
dtolnay/rust-toolchain (#746), so the release jobs' toolchain step runs
on Windows and macOS for the first time.


Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants