Repository navigation
chore(deps): bump @tiptap/suggestion from 3.27.3 to 3.30.1 in /client - #56
Closed
dependabot[bot] wants to merge 524 commits into
Closed
dependabot[bot] wants to merge 524 commits into
dependabot[bot] wants to merge 524 commits into
Conversation
- CL-H1: screen_capture_stop 与 dispose 结算防抖中悬挂的 pendingStartResolve,消除渲染层 invoke 永久挂起(快速开始→停止、帧超时重启链不再卡死) - CL-H2: importTable 每行显式按首行列集合取值(缺失补 null),修复 IndexedDB 迁移行间字段不一致时的列错位静默数据损坏 - CL-H3: db:search LIKE 降级路径统一 LIMIT 20,常见词搜索不再同步全表扫描 + 全量 IPC 传输 - CL-H4: rebuildIndex 改为异步分批执行(每批 500 行 + setImmediate 让出事件循环),数万文档重建不再阻塞主进程窗口/托盘/IPC;同步更新 main.ts 与 migration:complete 调用点 - CL-H5: rateCard 增加 isRating 防重入锁(try/finally 保证异常释放),消除双击/触屏误触导致的同一卡片双调度与重复复习记录 验证: npm run lint (0 errors) + npm run test (875 passed) + npm run build 全部通过
…atchdog上限 - CL-M1: ai:stream:start 的 API 路径白名单校验(仅 /api/v1/(ai|multimodal)/ 前缀,拒绝 ?/# 注入),堵住代理访问任意网关端点 - CL-M2: postJsonStream 读取阶段 30s 无数据超时(原仅覆盖建连)+ 所有退出路径 reader.cancel() 释放连接 + 外部 abort 信号检测 - CL-M3: safeHandleBatched 返回真实结果(最后一次调用结算 Promise),microtask 异常 reject 给调用方而非 unhandledRejection - CL-M4: 屏幕采集缩略图 1920×1080 → 1280×720(extractFrame 目标分辨率),多窗口每帧位图分配降 56% - CL-M5: db:batch 批量操作条数上限 1000,防止单事务长期持有写锁阻塞全部 db IPC - CL-M6: columnCache 失效策略——initialize/close/checkpointAndClose 时 clear,运行期 schema 变更不再过滤新列 - CL-M7: MCP Bridge 子进程最小环境白名单(14 个基础变量),不再透传宿主全部环境变量(供应链凭据泄露面) - CL-M8: displayMedia handler 校验请求 frame 来源(file:// 或 localhost),非应用来源拒绝授权(防静默录屏+系统音频) - CL-M9: dbFileMigrator 复制前检查目标目录已存在 keban.db 则拒绝(防覆盖旧库);备份名加时间戳并保留最近 5 份 - CL-M10: 帧超时 watchdog 连续重启上限 3 次(收到有效帧清零),耗尽后停止并 toast 提示,消除幽灵采集循环 - CL-M11: callWithLocalFallback 本地探测缓存过期时先刷新再决策,不再静默跳过本地推理 验证: npm run lint (0 errors) + npm run test (875 passed) + npm run build 全部通过
- CL-L1: fs:read-file 禁止读取数据库文件(keban.db*)+ 50MB 大小限制 - CL-L2: ai:set-gateway-url 拒绝自定义端口与路径(CSP connect-src 动态放行的攻击面收窄) - CL-L3: backup:save 校验 JSON 内容与 100MB 上限 - CL-L4: 自动更新状态机(idle/checking/available/downloading/downloaded/error)——install 仅 downloaded 态、download 仅 available 态,防止任意时机触发退出安装与并发下载 - CL-L5: chatRepository.getMessages limit 钳制 1-200 - CL-L6: preload 专用监听 API(onWindowClosing/onMaximizedChanged/onSyncBeforeQuit)纳入 ALLOWED_EVENT_CHANNELS 校验 - CL-L7: schema ALTER 区分 duplicate column(幂等成功)与其他错误(记日志且不推进 user_version,保留重试机会) - CL-L8: video_record_stopped 确认事件校验绑定窗口 sender - CL-L9: ai:stream 活跃流在发起窗口销毁时 abort 清理 - CL-L10: uncaughtException 崩溃恢复——DB checkpoint 落盘后 relaunch,不再带病运行 - CL-L11: saveAIConfigAction 网关地址同步失败抛错 + gatewaySyncError 状态可观测 验证: npm run lint (0 errors) + npm run test (875 passed) + npm run build 全部通过
- SYNC-H1: Push 冲突判定收紧为 client version <= server version——相同版本号不同内容的静默覆盖改为返回冲突(双设备并发编辑不再丢数据;幂等重试由 op.ID 去重覆盖) - SYNC-H2: WS sync_request 每连接在飞查询上限 2(信号槽),单连接洪泛不再打满数据库连接池(50)拖垮全部用户 - SYNC-M1: Resolve 增加 FOR UPDATE 行锁 + 版本必须大于服务端版本(拒绝版本回退);成功后广播到其他在线设备(实时收敛) - SYNC-M2: Push 广播条件从 opSeqNoByID 非空改为 accepted 非空——无 ID 操作(fallback ID)落库后同样广播 - SYNC-M3: CRDTPush changeset SHA-256 哈希幂等去重((user_id, changeset_hash) 唯一索引 + 并发兜底),网络重试不再重复落库膨胀 - SYNC-L2: Pull/CRDTPull 的 deviceId 白名单校验(防回环与超长参数) 验证: go build + go vet + go test 全部通过
- ALG-H1: FSRS S0(G) 从 FSRS-4 硬编码常量 [0.4,0.6,2.4,9.0] 改为权重 w[0..3](fsrs-rs 官方语义 S0(G)=w[G-1]);修正误导注释(权重为项目自定义非官方默认、w[6] 为保留位不参与 difficulty 更新、D0 为固定表近似并标注官方公式);同步更新测试断言 - ALG-M1: sm2 easeFactor 缺失/NaN/0 防御(回退 2.5),消除 NaN interval → Invalid Date 无限传播 - ALG-M2: rateCard 中 updateCard 改为 await + try/catch——异步写失败不再 unhandled rejection;review 已落库时继续推进 UI(内存态最新,DB 旧值下次复习覆盖,不丢数据不重复调度) - ALG-L1: SM-2 历史 interval 反推 stability 的近似性注释说明 - ALG-L2: goldenErrorMultiplier 历史遗留接口注释(实际由 store 层 compressForGoldenError 后处理生效) 验证: lint 0 errors + 875 tests passed + build 成功(FSRS/SM2 44 项算法测试全通过)
- WEB-L1: DownloadCta 版本信息 fetch 增加 5s 超时 + 单次重试;加载中显示加载提示,源站不可达时明确回退 GitHub Release(原实现 DNS 挂起时按钮一直显示兜底值,无法区分加载中与故障)
- SYNC2-H3: pause() 不再置 syncInProgress(该锁由 sync finally 释放),resume 等待加 15s 超时兜底——存储路径切换等流程不再永久挂起 - SYNC2-H1: resolve 成功后 markEntityLogsSynced 清理该实体全部未同步日志——配合服务端版本语义收紧(<=冲突),消除 resolve 后旧日志永久循环冲突 - SYNC2-H2: 冲突对象 localData 携带真实本地数据(最后一条 payload 日志,纯 delete 回退读业务表),localVersion 取最后一条日志版本——修复保留本地提交空对象清空实体数据 - SYNC2-H4: operationLog.synced 写入数值 0/1 与查询 equals(0/1) 类型一致,修复 oplog push 链路静默失效与模式切换丢数据;类型同步改为 0|1 验证: lint 0 errors + 875 tests passed
- SYNC2-L1: oplog pull cursor advances only to last successfully applied version, preventing permanent skip of failed operations - SYNC2-L2: autoSync no longer counts lock/offline states as failures, avoiding spurious exponential backoff after network recovery - SYNC2-L3: getPendingCRDTChanges supports per-table filtering, fixing push starvation when multiple tables have pending changes - SYNC2-L4: offline queue max version read by version instead of createdAt to avoid duplicate versions within the same millisecond - SYNC2-L5: reset per-table CRDT in-memory doc on persistence failure, preventing baseline drift and MissingDependencyError
- #1: JWT algorithm now injected via SUPABASE_JWT_ALGORITHM (default HS256, aligned with Supabase default signing); placeholder detection prevents 'configured' false impression causing whole-site 401 - #2: remove double rollback on streaming rate-limit overrun - the Lua script already atomically DECRs, manual rollback let users drain their own quotas into negative counts - #3: error_pattern chain/router defensive validation - missing fields from LLM JSON output filtered instead of 500 (ValidationError) - #4: GLM generate_vision returns actual clamped max_tokens; vision chain logs truncation warning when output approaches the limit
- #5: Gemini generate_stream iteration moved into thread pool via asyncio.to_thread, unblocking the event loop during streaming - #6: providers return real input/output token split; fallback cost tracking prefers it and falls back to 60/40 estimate instead of the misleading 50/50 split (output priced 2-3x higher) - #7: balance queries use Key pool primary key (plural env vars), DeepSeek balance no longer silently skipped - #8: JWKS fetch distinguishes network failures (stale cache reuse with 60s retry backoff) from HTTP/key errors (fail-closed), preventing whole-site 401 on transient Supabase hiccups - #9: import_concept registered in TIMEOUT_CONFIG/RATE_LIMITS plus startup validation warning for unregistered features - #10: error_pattern cache key includes user_id and hashes full content, preventing cross-user result reuse
- #11: vision confidence redefined as structured-extraction completeness (text 0.5 + aux fields 0.5) instead of fabricated 0.9/0.3; GLM ASR fabricated 0.9 fixed to 0.0 placeholder - #12: fallback chain budget comments unified to *3.0 matching implementation (was *1.5, misleading maintainers) - #13: key rotation moved to with_retry_and_timeout wrapper so vision/stream/ASR/video paths rotate keys too, not just generate - #14: JWT_SECRET marked as dead config in .env/.env.example with SUPABASE_JWT_ALGORITHM documented; startup warning when legacy JWT_SECRET is set but SUPABASE_JWT_SECRET is empty
- M1: feynman setExplanation no longer auto-advances step (double advance skipped step2 view); progression owned by advanceStep - M2: pomodoro wall-clock calibration completion branch now plays sounds and sends notifications like the normal path - M3: coral streak/check-in/progress use local dates consistently (UTC+8 midnight planting was counted as previous day) - M4: plantCoral re-reads DB before set, no longer overwrites concurrent plant with stale snapshot - M5: CryptoManager init failure now explicit (hasInitFailed, throws); device key material encrypted via Electron safeStorage IPC (previously plaintext in localStorage); fix missing logger import in SyncEngine (phase 1 regression) - M6: useAudioPlayer.play clears running fadeOut interval - M7: convertWeakPointsToFlashcards batches card creation before marking mastered, avoiding duplicate cards on retry - M8: useVoiceInput serializes stop/start (pending flag + re-check), old stop can no longer kill a newly started capture
- ELEC2-M1: MCP manager init failure resets initialized flag and retries with exponential backoff (1s-30s, max 8 attempts) - the stale flag previously disabled MCP silently for the whole run - ELEC2-L1: window recreation (macOS activate) resets sync-before-quit state machine - stale requested=true + completed=false made the new window impossible to close - ELEC2-L2: audio capture runtime degradation re-checks capturing before restarting the provider, eliminating ghost capture when stop() races with degradeToEndpoint
High:
- OfflineQueue: orderBy('version') on non-indexed field throws Dexie
SchemaError, breaking offline enqueue (regression from SYNC2-L4);
switched to sortBy in-memory (enqueue/getPendingItems/getReadyItems)
- auth.py JWKS: network-failure branch now bounded by stale-grace
window (was unbounded stale reuse); in-lock retry_after reuse
added; 5xx treated as transient (stale reuse) vs 4xx fail-closed
Medium:
- error_pattern: cache-hit path now validates/filters like first-run
(was bypassing validation -> 500); cache stores cleaned data;
negative count/empty keywords filtered
- Key rotation: removed per-provider generate rotate (double rotation
with wrapper made even-key pools never use the 2nd key)
- writeWithLog: resetTable failure no longer propagates to block the
main write path
- SyncEngine: finally clears syncInProgress unconditionally (pause
during in-flight sync left the lock, resume waited 15s timeout)
- feynmanStepSlice: catch path now syncs zustand store so retry does
not duplicate cards for already-created weak points
- windowManager: window recreation clears syncTimeoutTimer (stale
timer would app.quit() the rebuilt window)
- rate_limit: global-limit overrun now rolls back the feature counter
(Lua only rolls back the exceeded layer)
Low:
- markEntityLogsSynced matches synced !== 1 (legacy boolean/undefined)
- parseLocalDate validates format; daysBetween NaN -> Infinity
- ecosystem initialize uses local date; restore() re-reads DB
- worldState streak diff uses Math.round tolerance
- useVoiceInput start timeout surfaces error message
- Gemini stream uses provider thread pool (not default executor)
- qwen_vision returns max_tokens for truncation detection
- jwt_algorithm normalized strip().upper()
- X1: CryptoManager.init now wired to auth lifecycle (login derives device key via safeStorage, logout clears; init failure surfaces explicit warning toast instead of silent plaintext); mcpManager gains shuttingDown flag - no retry scheduling after shutdown and retryAttempts reset for dev hot-reload - X2: electron.d.ts duplicate Window.electronAPI declaration removed (env.d.ts is the single authoritative superset; conflicting signatures were masked by skipLibCheck) - X4: Gemini vision/multi/video return real input/output token split for cost tracking; DeepSeek input tokens use cache-miss portion (cache-hit billed at 1/4 price, previously overestimated) - X5: error_pattern cache key uses only fields the chain consumes (first 20 correctAnswer/userAnswer, no flashcardId) - improves hit rate without correctness impact - X6: feature-config startup validation extracted to shared function and applied to streaming registry (was middleware-only, streaming misconfigs silently fell back to 300s timeout / default limits)
- 收入方案设计:docs/product/temporary-revenue-implementation.md - 数据库层:schema.ts 新增 beta_profile/licenses/invite_codes 三表,SCHEMA_VERSION=10 - 类型系统:client/src/types/beta.ts — UserTier/TIER_RANK/TIER_PERKS 权益矩阵 - 状态管理:betaStore.ts — Zustand persist 持久化 tier/激活码/邀请码 - UI组件:BetaProfile(身份卡片)、InviteCodeSection(邀请码管理)、 LicenseActivation(激活码输入+服务端验证)、UpgradePrompt(非阻断升级引导) - 权限Hook:useTierAccess(tier-based 功能访问控制)、useBetaProfile(metadata加载) - SettingsPage 集成:ProfileSettings 后插入 BetaProfile 区域 - AI网关集成:rate_limit.py TIER_LIMITS 分级配额 + providers.py TIER_MODEL_ACCESS 分级路由 - 新增路由:routers/license.py(激活码验证) + routers/beta.py(邀请码API) - 管理工具:scripts/license-gen.mjs(激活码离线生成,支持 PRO/LIFE/SND1/THM1) - 代码审查修复:修复 recalcEffectiveTier 排序、激活码大小写、tier 参数传递、 服务端验证缺失、v10迁移、邀请码数量逻辑、cohort 类型转换、import re 延迟导入等30个问题 - 路由注册:main.py 和 __init__.py 注册 license_router 和 beta_router
…Classifier 进程名兜底)
- 预置 ~/.bubblewrap/config.json(jdkPath/androidSdkPath),消除全新 runner 上 JDK 安装交互提示导致的 exit 130(v0.38~v0.40 build-apk 连续失败根因) - 删除语义错误的 bubblewrap update(--manifest 应指向本地 twa-manifest.json 而非 web manifest URL);工程已入库,直接 build 即可 - build 密码改经 BUBBLEWRAP_KEYSTORE_PASSWORD/BUBBLEWRAP_KEY_PASSWORD 环境变量传入(CLI 无密码参数,原 --keystorePass 等被静默忽略) - 签名参数改用 --signingKeyPath/--signingKeyAlias(原 --keystorePath 无效, 会落到 twa-manifest.json 中的 Windows 本地路径) - 防御:SDK tools/bin 占位 + build-tools 36.1.0 缺失时显式预装 - keystore secret 缺失时 exit 1 显式失败;GitHub Release 上传仅 tag 触发时执行 已在本地完成全链路构建验证(gradle assembleRelease + zipalign + apksigner, 产出 2.6MB 签名 APK 验证通过)
Bumps [@tiptap/suggestion](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/suggestion) from 3.27.3 to 3.30.1. - [Release notes](https://github.com/ueberdosis/tiptap/releases) - [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/suggestion/CHANGELOG.md) - [Commits](https://github.com/ueberdosis/tiptap/commits/v3.30.1/packages/suggestion) --- updated-dependencies: - dependency-name: "@tiptap/suggestion" dependency-version: 3.30.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Author
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
dependabot
Bot
deleted the
dependabot/npm_and_yarn/client/tiptap/suggestion-3.30.1
branch
August 21, 2026 03:19
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps @tiptap/suggestion from 3.27.3 to 3.30.1.
Release notes
Sourced from @tiptap/suggestion's releases.
... (truncated)
Changelog
Sourced from @tiptap/suggestion's changelog.
... (truncated)
Commits
4c4933dchore(release): release new stable release (#8181)7901bc2chore(release): release new stable release (#8142)5158212chore(release): release new stable release (#8132)896564achore(release): release new stable release (#8128)1afef87chore(release): release new stable release (#8087)c5f4b57chore(release): release new stable release (#8038)24263ecchore(release): publish a new stable versionDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)