Skip to content

chore(deps): bump mermaid from 11.16.0 to 11.16.1 - #58

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/mermaid-11.16.1
Closed

chore(deps): bump mermaid from 11.16.0 to 11.16.1#58
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/mermaid-11.16.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps mermaid from 11.16.0 to 11.16.1.

Release notes

Sourced from mermaid's releases.

mermaid@11.16.1

Patch Changes

  • #8022 12d472c Thanks @​aloisklink! - fix: handle CSS sibling combinators in compileCSS

  • #8022 2cd6dcf Thanks @​aloisklink! - fix: increase protections against prototype pollution

    User-controlled input already has protections against prototype pollution.

    Fixes: GHSA-c4c3-pg64-4m4v

  • #8022 99af3fc Thanks @​aloisklink! - fix(architecture): use Maps and Sets to store groups/services

    Services are now rendered in the order they are defined and more service IDs are now supported.

  • #8022 2cd6dcf Thanks @​aloisklink! - deprecate: Deprecate the mermaidAPI.setConfig() function

    Calling this function has no observable effect, as the next time a render() or parse() is called, the currentConfig is cleared.

  • #8022 630aa7e Thanks @​aloisklink! - fix(xychart): support zero-width x-axis ranges

  • #8022 59b22fa Thanks @​aloisklink! - fix(radar): limit number of ticks to 32

    Setting a ticks value higher than this would only show 32 ticks.

Commits
  • 7ecca0c Version Packages (#8023)
  • 95b1b9c docs: change mermaidAPI.setConfig() changeset (#8024)
  • acc69f1 Merge pull request #8022 from mermaid-js/release/11.16.1
  • eba7287 docs: point changesets to correct commit hashes
  • 12d472c Merge commit from fork
  • 2cd6dcf Merge commit from fork
  • 630aa7e Merge commit from fork
  • 59b22fa Merge commit from fork
  • 99af3fc Merge commit from fork
  • 2337f7e Merge branch 'test/improve-example.html' into release/11.16.1
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Dependency updates javascript Pull requests that update javascript code labels Aug 24, 2026
@dependabot
dependabot Bot requested a review from ulises-jeremias as a code owner August 24, 2026 05:15
@vercel

vercel Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
website-3g7t Ready Ready Preview Aug 24, 2026 5:20am

@dependabot dependabot Bot added dependencies Dependency updates javascript Pull requests that update javascript code labels Aug 24, 2026
@github-actions

github-actions Bot commented Aug 24, 2026

Copy link
Copy Markdown
Fails
🚫

node failed.

Log

Details
Error:  TypeError: ts.transpileModule is not a function
    at typescriptify (/usr/src/danger/dist/runner/runners/utils/transpiler.js:160:21)
    at /usr/src/danger/dist/runner/runners/utils/transpiler.js:235:44
    at /usr/src/danger/dist/runner/runners/inline.js:154:53
    at step (/usr/src/danger/dist/runner/runners/inline.js:56:23)
    at Object.next (/usr/src/danger/dist/runner/runners/inline.js:37:53)
    at /usr/src/danger/dist/runner/runners/inline.js:31:71
    at new Promise (<anonymous>)
    at __awaiter (/usr/src/danger/dist/runner/runners/inline.js:27:12)
    at runDangerfileEnvironment (/usr/src/danger/dist/runner/runners/inline.js:123:132)
    at /usr/src/danger/dist/platforms/GitHub.js:181:38
danger-results://tmp/danger-results-654d916a.json

Generated by 🚫 dangerJS against b3d7092

@github-actions

github-actions Bot commented Aug 24, 2026

Copy link
Copy Markdown

🦙 MegaLinter status: ❌ ERROR

Descriptor Linter Files Fixed Errors Warnings Elapsed time
✅ ACTION actionlint 5 0 0 0.06s
✅ BASH bash-exec 1 0 0 0.0s
✅ BASH shellcheck 1 0 0 0.2s
⚠️ BASH shfmt 1 1 0 0.01s
✅ COPYPASTE jscpd yes no no 4.47s
❌ EDITORCONFIG editorconfig-checker 176 1 0 0.64s
✅ JAVASCRIPT standard 1 0 0 1.85s
✅ JSON jsonlint 10 0 0 0.2s
✅ JSON npm-package-json-lint yes no no 0.76s
✅ JSON prettier 10 0 0 0.65s
✅ JSON v8r 10 0 0 12.51s
✅ MARKDOWN markdownlint 10 0 0 0.72s
⚠️ MARKDOWN markdown-table-formatter 10 1 0 0.28s
✅ REPOSITORY checkov yes no no 17.49s
✅ REPOSITORY gitleaks yes no no 1.21s
✅ REPOSITORY git_diff yes no no 0.02s
✅ REPOSITORY secretlint yes no no 1.81s
❌ REPOSITORY trivy yes 1 no 13.63s
✅ REPOSITORY trufflehog yes no no 4.08s
❌ SPELL cspell 177 46 0 8.35s
⚠️ YAML prettier 13 1 2 1.18s
✅ YAML yamllint 13 0 0 0.6s

See detailed report in MegaLinter reports

MegaLinter is graciously provided by OX Security

Bumps [mermaid](https://github.com/mermaid-js/mermaid) from 11.16.0 to 11.16.1.
- [Release notes](https://github.com/mermaid-js/mermaid/releases)
- [Commits](https://github.com/mermaid-js/mermaid/compare/mermaid@11.16.0...mermaid@11.16.1)

---
updated-dependencies:
- dependency-name: mermaid
  dependency-version: 11.16.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@ulises-jeremias

Copy link
Copy Markdown
Member

Triage 2026-08-25 (maintenance sweep): BLOCKED — not safe to merge.

All 8 open dependabot PRs fail the same MegaLinter gate as main (32756066890):

  • cspell 46 errors (vmodules/vweb/… Spanish i18n, pnpm-lock) — needs combined .cspell.json allowlist PR
  • trivy HIGH vuln on pnpm-lock.yaml (brace-expansion CVE-2026-14257/69152, sharp→libvips) + tools/danger/package-lock.json undici CVE-2026-13697 — needs lockfile bump (none of these 8 PRs fixes all 3)
  • editorconfig-checker on public/install.sh / non-blocking markdown-table-formatter & yaml prettier
  • Danger / pr-review also failing (ts.transpileModule in danger bundle)

test/type-check/Vercel are green, so this is not a code regression from the dep bump. Keep open; do not merge until a combined cspell+trivy+editorconfig fix lands on main, then rebase these dependabots. One-per-lockfile-dir rule applies — batch by / vs /tools/danger.

Post-merge gate on main: tests ✅, type-check ✅, todo ✅, dynamic dependabot updates ✅, MegaLinter ❌ (same 3 linters). No merge attempted.

@ulises-jeremias

Copy link
Copy Markdown
Member

Closing as superseded by #62. Main now declares Mermaid ^11.16.1 and resolves 11.17.2; the required post-merge checks are green.

@dependabot @github

dependabot Bot commented on behalf of github Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/mermaid-11.16.1 branch August 26, 2026 19:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant