Skip to content

build(deps): bump mermaid from 11.15.0 to 11.16.1 - #203

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/mermaid-11.16.1
Aug 18, 2026
Merged

build(deps): bump mermaid from 11.15.0 to 11.16.1#203
github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/mermaid-11.16.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 18, 2026

Copy link
Copy Markdown
Contributor

Bumps mermaid from 11.15.0 to 11.16.1.

Release notes

Sourced from mermaid's releases.

mermaid@11.16.1

Patch Changes

  • #8022 12d472c Thanks @​aloisklink! - fix: handle CSS sibling combinators in compileCSS

  • #8022 2cd6dcf Thanks @​aloisklink! - fix: increase protections against prototype pollution

    User-controlled input already has protections against prototype pollution.

    Fixes: GHSA-c4c3-pg64-4m4v

  • #8022 99af3fc Thanks @​aloisklink! - fix(architecture): use Maps and Sets to store groups/services

    Services are now rendered in the order they are defined and more service IDs are now supported.

  • #8022 2cd6dcf Thanks @​aloisklink! - deprecate: Deprecate the mermaidAPI.setConfig() function

    Calling this function has no observable effect, as the next time a render() or parse() is called, the currentConfig is cleared.

  • #8022 630aa7e Thanks @​aloisklink! - fix(xychart): support zero-width x-axis ranges

  • #8022 59b22fa Thanks @​aloisklink! - fix(radar): limit number of ticks to 32

    Setting a ticks value higher than this would only show 32 ticks.

mermaid@11.16.0

Minor Changes

  • #7535 ea1c48f Thanks @​ragelink! - feat(cynefin): Adds the Cynefin framework as a new diagram type (beta) to Mermaid (available as cynefin-beta). The Cynefin framework, created by Dave Snowden, is a decision-making framework that categorizes problems into five complexity domains, widely used in agile, incident management, strategy, and organizational design.

  • #7721 f45cc2c Thanks @​notionparallax! - feat(treeView): add box-drawing character input support for treeView diagrams

  • #7550 f1f4d45 Thanks @​DominicBurkart! - feat(xychart): add per-point text labels for xychart line plots

  • #7527 b4d0442 Thanks @​notionparallax! - feat(treeView): Extends the existing treeView-beta diagram with features useful for representing file/directory structures.

  • #7793 a6f097d Thanks @​SSDWGG! - feat(er): support optional ER attribute types with a ? suffix

  • #7772 37f2e36 Thanks @​devareddy05! - feat(gantt): support multiple excludes / includes lines so long exclusion lists can be split into commented groups (#6270)

  • #7708 4e63e9d Thanks @​txmxthy! - feat(architecture): add align row|column {ids…} directive to architecture-beta diagrams so authors can declare horizontal or vertical alignment of services explicitly.

  • #7760 05223be Thanks @​ngdaniels! - feat(pie): Enhance Pie Chart - Enable donut chart, Set legend position, and highlight slice

  • #7251 216e4e9 Thanks @​ydah! - feat(railroad): Add support for Railroad Diagrams (Syntax Diagrams) with four input syntaxes: IR (railroad-beta), EBNF (railroad-ebnf-beta), ABNF (railroad-abnf-beta), and PEG (railroad-peg-beta).

  • #7774 e5c75e6 Thanks @​ngdaniels! - feat(xychart): enable rotate label on X-axis

... (truncated)

Commits
  • 7ecca0c Version Packages (#8023)
  • 95b1b9c docs: change mermaidAPI.setConfig() changeset (#8024)
  • acc69f1 Merge pull request #8022 from mermaid-js/release/11.16.1
  • eba7287 docs: point changesets to correct commit hashes
  • 12d472c Merge commit from fork
  • 2cd6dcf Merge commit from fork
  • 630aa7e Merge commit from fork
  • 59b22fa Merge commit from fork
  • 99af3fc Merge commit from fork
  • 2337f7e Merge branch 'test/improve-example.html' into release/11.16.1
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [mermaid](https://github.com/mermaid-js/mermaid) from 11.15.0 to 11.16.1.
- [Release notes](https://github.com/mermaid-js/mermaid/releases)
- [Commits](https://github.com/mermaid-js/mermaid/compare/mermaid@11.15.0...mermaid@11.16.1)

---
updated-dependencies:
- dependency-name: mermaid
  dependency-version: 11.16.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 18, 2026
@github-actions
github-actions Bot merged commit 4abd188 into main Aug 18, 2026
3 of 4 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/mermaid-11.16.1 branch August 18, 2026 01:31
@github-actions

Copy link
Copy Markdown
Contributor

🤖 Codex-Style Code Review by OpenCode (Vue Best Practice Enabled)

💡 Autonomous AI Reviewer inspecting git commit history and Vue code quality.

PR Review: build(deps): bump mermaid from 11.15.0 to 11.16.1 (#203)

Scope

Dependabot dependency bump. Only package.json and package-lock.json changed; **no application source code touAll checks pass. Writing the review
Review complete — report written to review_report.md.

Verdict: ✅ Approve. This is a Dependabot bump of mermaid ^11.15.0^11.16.1 (package.json + lockfile only, no app code).

Key findings:

  • Security-motivated: 11.16.0 backports 5 CVEs (CSS sanitization, stylis scope escape); 11.16.1 fixes GHSA-c4c3-pg64-4m4v prototype pollution. Project usage (mermaid.initialize()/render() in src/services/pltxt2htm/advancedParser.ts:22-45) is unaffected.
  • Verified locally: npm ci ✅ (948 pkgs), npm run build -- --mode production ✅, npm run eslint ✅ (0 errors).
  • 🟡 One note: the lockfile churn drops esbuild@0.28.1 + 28 @esbuild/* binaries (~530 lines) unrelated to the bump — harmless since vite 8 uses rolldown and esbuild is now only an optional peer, but worth being aware of.
  • PR merge ref equals origin/main (already merged).
    unaffected by 11.16.x. The deprecated mermaidAPI.setConfig() has no bearing on this project.
  • Security value (this is the main reason to bump): 11.16.0 backports 5 security fixes (CVE-2026-41150/41148/41149/41159/41907 — gantt loop, CSS sanitization via CSSOM, stylis scope escape, uuid range); 11.16.1 adds GHSA-c4c3-pg64-4m4v prototype-pollution hardening and a CSS sibling-combinator fix. Combined with the existing securityLevel: 'strict' config, diagram rendering becomes notably safer.
  • Semver: ^11.15.0 already resolves to 11.16.1 for fresh installs; this bump pins the minimum so cached/stale 11.15.x installs converge. Low breaking-change risk within the same major.

Concerns

🟡 Unrelated lockfile churn — esbuild dropped from the lockfile. The regenerated lockfile deletes esbuild@0.28.1 and all 28 @esbuild/* platform binaries (~530 lines removed), which has nothing to do with the mermaid bump. I verified this is benign: vite 8.0.16 bundles with rolldown and lists esbuild only as an optional peer, npm ci and the production build both succeed without it, and no source/config file references esbuild. Still, a dependabot PR ideally shouldn't carry unrelated lockfile changes; please confirm the lockfile was regenerated deliberately (or accept the churn knowingly) to avoid surprising diffs on future bumps.

Decision

Approve. Security-motivated, patch-level bump with no breaking API impact; all CI-equivalent gates (npm ci, build, lint) verified locally. The only note is the unrelated esbuild lockfile churn, which is confirmed harmless but worth being aware of.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants