Skip to content

chore(deps): bump bits-ui from 2.19.1 to 2.19.3 in /web - #59

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/web/bits-ui-2.19.3
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/web/bits-ui-2.19.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 26, 2026 •

Copy link
Copy Markdown

Bumps bits-ui from 2.19.1 to 2.19.3.

Release notes

Sourced from bits-ui's releases.

bits-ui@2.19.3

Patch Changes

  • Prevent delayed focus-scope autofocus from overriding focus already established in the scope or a nested scope. (#2165)

  • fix(Dialog, AlertDialog): pass preventOverflowTextSelection to the text selection layer explicitly instead of letting it ride the rest props onto the rendered content element as a preventoverflowtextselection attribute. (#2154)

  • fix(Floating): ignore autoUpdate callbacks that fire after the floating element's effect is destroyed to avoid derived_inert (#2164)

  • Fix user-select: none being stranded on <body> after clicking inside forceMounted content (Popover, Tooltip, Dialog, AlertDialog, Menu, Select), which left the whole page unselectable until a reload. (#2161)

  • refactor: the context-menu attribute names and the floating root/anchor state move to leaf modules, so DismissibleLayer no longer imports the menu module for two strings, and FloatingLayer / FloatingLayer.Anchor no longer import the floating content module (and @floating-ui/dom) to register a root and its trigger. No behaviour change. (#2158)

  • fix(Menu): the trigger's aria-controls links to the content when the menu starts open. The content registers its id by replacing a plain field on the menu state, which a trigger rendered before the content had already read as empty and never re-read; the registration is now reactive. (#2159)

  • fix(Combobox): open the trigger on a touch tap instead of on touch down, so a finger that lands on it while scrolling no longer opens the list. Takes the Select trigger's touch timing. (#2156)

  • perf: avoid O(n) work per rendered item on hot paths (#2110)

    • Select/Combobox: item props now derive from per-item booleans, so moving the highlight or changing the value only rebuilds props (and re-diffs attributes) for the items that actually changed instead of every mounted item
    • Select/Combobox (multiple): selection lookups use a set instead of scanning the value array once per item
    • Calendar/RangeCalendar: data-today resolves the local timezone once per calendar rather than once per cell
    • Menu family: the document-level pointermove listener is only attached while keyboard mode is active
    • ScrollArea, Slider, NavigationMenu: internal resize observation shares a single ResizeObserver across all observed elements
  • fix(TimeField): keep the day period when typing the hour and then editing another segment in 12-hour mode (#2148)

  • Fix user-select: none being left on <body> when something else on the page calls preventDefault() on a pointerup, which made the whole page unselectable. The text-selection layer's release is internal cleanup and no longer skipped when the event's default action has been cancelled. (#2163)

  • fix(Collapsible): invalidate deferred measurements when content is replaced or destroyed (#2149)

  • Fix outside clicks being lost while dismissible content such as DropdownMenu is opening. (#2143)

bits-ui@2.19.2

Patch Changes

  • fix: render the id attribute on Popper-based content elements (Tooltip, Popover, Select, Combobox, DropdownMenu, ContextMenu, Menubar, LinkPreview) so aria-describedby on triggers resolves correctly (#2094)

  • fix: restore body styles on the captured document when delayed scroll-lock cleanup runs after the global document is torn down or replaced (#2133)

  • fix: respect an explicit Tabs.Content tabindex while preserving the default panel tab stop (#2132)

Commits
  • 4ece125 Version Packages (#2144)
  • 86d3875 test(ScrollArea): drive the resize-teardown test with a real resize (#2170)
  • e60291e fix(TimeField): keep the day period after typing the hour in 12-hour mode (#2...
  • c29acb2 refactor: leaf modules for the context-menu attribute names and the floating ...
  • cb111ef fix: invalidate deferred Collapsible measurements on cleanup (#2149)
  • fedf05f fix(Dialog, AlertDialog): pass preventOverflowTextSelection to the layer inst...
  • a2f53b9 fix(Combobox): open the trigger on a touch tap instead of on touch down (#2156)
  • 44e2ff7 fix(Menu): the trigger's aria-controls links to the content when the menu sta...
  • cc0a50e fix(TextSelectionLayer): release the held lock before arming a new one (#2161)
  • 3cffb10 fix(TextSelectionLayer): release the body lock even when pointerup is cance...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [bits-ui](https://github.com/huntabyte/bits-ui) from 2.19.1 to 2.19.3.
- [Release notes](https://github.com/huntabyte/bits-ui/releases)
- [Commits](https://github.com/huntabyte/bits-ui/compare/bits-ui@2.19.1...bits-ui@2.19.3)

---
updated-dependencies:
- dependency-name: bits-ui
  dependency-version: 2.19.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Dependency updates frontend Frontend / web labels Sep 26, 2026
@dependabot
dependabot Bot requested a review from Sudo-Ivan as a code owner September 26, 2026 09:36
@dependabot dependabot Bot added dependencies Dependency updates frontend Frontend / web labels Sep 26, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​bits-ui@​2.19.1 ⏵ 2.19.3100 +110091 +196 +3100

View full report

@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Author

Looks like bits-ui is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 28, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/web/bits-ui-2.19.3 branch September 28, 2026 01:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates frontend Frontend / web

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants