fix(draw): restore collaborative UI and patch pinned dependencies - #118
Merged
mldangelo-oai merged 3 commits intoOct 3, 2026
Merged
Conversation
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.0.14 to 8.0.16. - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.0.16/packages/vite) --- updated-dependencies: - dependency-name: vite dependency-version: 8.0.16 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <[email protected]>
Contributor
Author
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
dependabot
Bot
deleted the
dependabot/npm_and_yarn/plugins/draw/ui/vite-8.0.16
branch
October 3, 2026 01:02
# Conflicts: # plugins/draw/ui/package-lock.json # plugins/draw/ui/package.json
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
mldangelo-oai
added a commit
that referenced
this pull request
Oct 3, 2026
🤖 I have created a release *beep* *boop* --- ## [0.14.1](v0.14.0...v0.14.1) (2026-10-03) ### Features - Add `crab version` as an alias for checking the installed version ([#128](#128)). - Add `crab env encrypt <staging-dir> [output-file]` to retry snapshot encryption without rerunning the agent. Preserve staging on failure, reject existing backups and output inside staging, and handle relative paths and names beginning with a dash ([#68](#68)). ### Bug Fixes - Restore Draw canvas styling, initialize collaboration after the Excalidraw API is ready, and display collaborator cursors. Browser checks cover Mermaid conversion, shared edits, and scene reloads ([#118](#118)). - Patch Nano ID and lodash-es versions pinned inside Excalidraw dependencies, and update Sass to remove the vulnerable Chokidar/Braces chain ([#118](#118)). - Upgrade Zod to v4 ([#50](#50)), Excalidraw to v0.18.1 ([#104](#104)), and React to v19 ([#105](#105)). - Address Draw UI dependency alerts ([#102](#102)) and refresh plugin locks with patched Engine.IO, Socket.IO parser, Immutable, DOMPurify, Mermaid, PostCSS, Vite, and Vitest dependencies ([#116](#116), [#130](#130)). - Load Node type definitions explicitly so the Tax plugin compiles, and keep the Draw UI lockfile installable with npm 10 and 11 ([#116](#116)). ### Development - Upgrade all plugin compilers to TypeScript 7.0.2 and require at least Vite 8.0.16 and Vitest 4.1.11, while retaining Node 20/22/24 support ([#125](#125)). - Build and test every plugin on Node 20, 22, and 24; add Draw UI type checking and Promptfoo parser/configuration smoke tests ([#116](#116), [#125](#125)). - Update the pinned checkout, setup-node, and CI aggregation actions ([#124](#124), [#153](#153), [#154](#154)). --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Michael D'Angelo <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Draw could render without its Excalidraw styles and skip collaboration setup when the canvas API became ready after the initial effect. Load the stylesheet, start collaboration when the API is available, and pass participant cursors to Excalidraw. A two-browser check verified Mermaid conversion, live drawing/text updates, collaborator cursors, and restoring the shared scene after reload.
Patch the remaining exact-pinned UI dependencies with scoped Nano ID overrides, lodash-es 4.18.1, and Sass 1.105.0. The Sass update removes the vulnerable Chokidar/Braces chain. Keep Node 20 support and an npm 10/11-compatible lockfile. The original Vite minimum update is already included through #125.
Validation:
The repository CI additionally runs Draw and both other plugins on Node 20, 22, and 24, plus CLI unit tests and ShellCheck.