chore(deps): roll up the pending dependency bumps - #740
Merged
Merged
Conversation
Combines the three open bot PRs, each fixed so CI can pass: - cargo (#736): rmcp 3.3.0 -> 3.4.0. Dependabot bumped only mas-mcp, but the app crate pins rmcp to the same exact version, so cargo could not resolve. Bump both. rmcp 3.4 deprecates the ServerInfo alias in favour of ServerConfig; rename the three uses in mas-mcp so clippy -D warnings stays clean. dirs 6 -> 7 is listed in that PR's title but its diff never changed it, so it is left for a separate PR. - npm (#737): the 13 group updates. jsdom 30.1.0 pulls whatwg-url 17.1.1, whose registry metadata advertises a provenance attestation the registry serves as 404, which fails `npm audit signatures`. Lock jsdom's copy at 17.1.2 instead (same dependencies; 13 days old, inside min-release-age). - dprint (#738): @dprint/json 0.23.0 -> 0.24.0, plus the package.json key order it now enforces. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg
This was referenced Oct 5, 2026
EVWorth
added a commit
that referenced
this pull request
Oct 5, 2026
…t in CI (#747) #740 moved @tauri-apps/plugin-updater to 2.12.0 while the tauri-plugin-updater crate stayed at 2.11.0. `tauri build` refuses to start when a Tauri npm package and its crate disagree on major.minor ("Found version mismatched Tauri packages"), so main could not build a release. Nothing on a PR runs `tauri build`; only the release workflow does, so CI stayed green. Bump the crate to 2.12.0 (published 2026-09-20, past the seven-day rule). The lockfile moves that one package and nothing else; tauri stays at 2.11.5. scripts/check-tauri-versions.sh applies the CLI's rule without a build: @tauri-apps/api pairs with `tauri`, @tauri-apps/plugin-<x> with tauri-plugin-<x>, compared from package-lock.json and Cargo.lock. It runs in the Version Consistency job, which already triggers on either lockfile, and in `just lint`. Against main's lockfiles it reports the updater pair; with this change all four pairs agree. scripts/test-check-tauri-versions.sh covers matching pairs, a plugin a minor ahead, api-vs-tauri, patch-only differences, packages with no crate, crate-name prefixes, nested npm copies, and no pairs at all. Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg Co-authored-by: Claude <noreply@anthropic.com>
EVWorth
added a commit
that referenced
this pull request
Oct 5, 2026
) * fix(deps): match tauri-plugin-updater to its npm package, and check it in CI #740 moved @tauri-apps/plugin-updater to 2.12.0 while the tauri-plugin-updater crate stayed at 2.11.0. `tauri build` refuses to start when a Tauri npm package and its crate disagree on major.minor ("Found version mismatched Tauri packages"), so main could not build a release. Nothing on a PR runs `tauri build`; only the release workflow does, so CI stayed green. Bump the crate to 2.12.0 (published 2026-09-20, past the seven-day rule). The lockfile moves that one package and nothing else; tauri stays at 2.11.5. scripts/check-tauri-versions.sh applies the CLI's rule without a build: @tauri-apps/api pairs with `tauri`, @tauri-apps/plugin-<x> with tauri-plugin-<x>, compared from package-lock.json and Cargo.lock. It runs in the Version Consistency job, which already triggers on either lockfile, and in `just lint`. Against main's lockfiles it reports the updater pair; with this change all four pairs agree. scripts/test-check-tauri-versions.sh covers matching pairs, a plugin a minor ahead, api-vs-tauri, patch-only differences, packages with no crate, crate-name prefixes, nested npm copies, and no pairs at all. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg * chore(deps): bump Tauri to 2.12 on the npm and Rust sides together `tauri build` requires each Tauri npm package and its crate to share a major.minor, and Dependabot proposes npm and cargo separately: #745 moved the JS packages alone, which the new check-tauri-versions.sh would fail. This moves every pair in one change. @tauri-apps/api 2.11.1 -> 2.12.0 tauri 2.11.5 -> 2.12.0 @tauri-apps/cli 2.11.5 -> 2.12.0 tauri-build 2.6.3 -> 2.7.0 @tauri-apps/plugin-process 2.3.1 -> 2.4.0 tauri-plugin-process 2.3.1 -> 2.4.0 @tauri-apps/plugin-shell 2.3.6 -> 2.4.0 tauri-plugin-shell 2.3.6 -> 2.4.0 @tauri-apps/plugin-updater 2.12.0 -> 2.13.0 tauri-plugin-updater 2.12.0 -> 2.13.0 All are the 2026-09-26 releases, nine days old; the .1 point releases from 2026-09-29/30 are inside the seven-day window and left for later. Cargo resolved tauri's internal crates (tauri-runtime, -runtime-wry, -utils, -macros, -codegen, tauri-plugin) to their 09-30 releases, so those are pinned back in the lockfile to the 09-26 set tauri 2.12.0 shipped with. The rest of the lockfile churn is tauri's own new transitive versions (wry 0.57, tao 0.37, muda, tray-icon, webview2-com) and drops the old windows 0.61 family and the unmaintained unic-* crates, which takes cargo audit's non-blocking warnings from 9 to 4. The plugins' 2.4/2.13 releases require tauri ^2.12, which is why Dependabot could not offer them on their own. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg --------- Co-authored-by: Claude <noreply@anthropic.com>
Merged
EVWorth
added a commit
that referenced
this pull request
Oct 5, 2026
Version bump across the three manifests and the two lockfile entries that record the app's own version. What 1.2.0 contains since 1.1.0: - Each editor tab runs on its own server session, so SET @var, temporary tables and multi-run transactions carry across runs (#734) - Separate connection lanes for the agent and for backups/restores, so neither can starve the editor; the pool-exhausted message says what is holding the pool (#732, #727) - Copy button beside Expand for long cell values, such as SHOW CREATE TABLE (#748) - Linux/Wayland: WebKitGTK's DMABUF renderer is turned off, for the black area left after resizing the window (#742) - Tauri 2.12 on both the npm and Rust sides (#749), and the dependency roll-up in #740 - rustls TLS 1.3 advisory RUSTSEC-2026-0285 patched (#728) Also the first release built with rustup in place of dtolnay/rust-toolchain (#746), so the release jobs' toolchain step runs on Windows and macOS for the first time. Claude-Session: https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Combines the three open bot PRs into one, with the fixes each needed to pass CI. Supersedes #736, #737 and #738.
cargo (#736): rmcp 3.3.0 → 3.4.0
rmcponly incrates/mas-mcp. The app crate pins the same exact version (=3.3.0), so cargo couldn't resolve a version and Lint (Rust) and Test Rust both failed. This PR bumps both.ServerInfoalias in favour ofServerConfig, whichclippy -D warningsrejects. The three uses inmas-mcp/src/server.rsare renamed.ServerInfois only an alias, so nothing changes at runtime.dirs6 → 7 is listed in chore(deps): bump the cargo group across 1 directory with 2 updates #736's title, but its diff never changed it. A major bump deserves its own look, so it's left out.npm (#737): the 13 group updates
whatwg-url@17.1.1. That version's registry metadata advertises a provenance attestation, but the registry returns 404 for it, sonpm audit signaturesfails. jsdom's copy is locked at 17.1.2 instead: it has the same dependencies, was published 13 days ago (inside.npmrc'smin-release-age=7), and its attestation verifies.npm updatewould have picked 17.2.0, published today, so the lockfile entry was edited directly.dprint (#738): @dprint/json 0.23.0 → 0.24.0
package.jsonkey order the new plugin enforces, the same reformat the bot PR made. CI never ran on chore(deps): bump dprint plugins #738 because a bot opened it, so it runs here.Verification (locally)
cargo teston the six crates CI runs: pass.cargo clippy -p mas-mcp --all-targets --all-features -D warnings: clean.cargo fmt --check: clean. The full-workspace clippy needs GTK, which this container doesn't have, so CI covers it.npm audit signaturesandnpm audit --audit-level=critical: pass.npm run lint: no errors.npm run type-checkanddprint check: clean.npm run test:unit: 2970 pass.src/__tests__/main.test.tsxhits its 10s hook timeout under the full parallel run in this container, and does the same on unmodifiedmainhere. It passes on its own and passes on main in CI.🤖 Generated with Claude Code
https://claude.ai/code/session_01SCNjpC4VgppHSFs7P6rkZg
Generated by Claude Code