Skip to content

merge: upstream 54 commits#313

Open
github-actions[bot] wants to merge 55 commits into
masterfrom
merge/upstream
Open

merge: upstream 54 commits#313
github-actions[bot] wants to merge 55 commits into
masterfrom
merge/upstream

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot commented May 4, 2026

Upstream Merge

54 new commits from plasmicapp/plasmic master.

Review using the Files Changed tab. The commit list includes upstream history.

Conflicts to resolve

git fetch origin merge/upstream
git checkout merge/upstream
# Resolve conflicts, then:
git push origin merge/upstream

Conflicted files:

plasmicpkgs-dev/package.json
platform/canvas-packages/package.json
platform/canvas-packages/yarn.lock
platform/loader-bundle-env/package.json
platform/loader-bundle-env/yarn.lock
platform/wab/package.json
platform/wab/src/wab/server/loader/gen-code-bundle.ts
platform/wab/src/wab/server/loader/gen-html-bundle.ts
platform/wab/src/wab/server/routes/loader.ts
platform/wab/src/wab/server/util/apm-util.ts
platform/wab/src/wab/server/util/s3-util.ts
platform/wab/src/wab/server/workers/prefill-cloudfront.ts
platform/wab/src/wab/shared/urls.ts
platform/wab/yarn.lock
yarn.lock

Before merging

See Upstream Merge Runbook.

  • Conflicts resolved (if any)
  • EP integrity tests pass
  • yarn.lock regenerated for modified package.json
  • CI triggered (close/reopen PR to trigger checks)
  • Merge with "Create a merge commit" — do NOT squash

sampullman and others added 29 commits April 28, 2026 03:06
GitOrigin-RevId: 94e25c0ea7431f3ce71d7fd63e8d42141ae5506e
GitOrigin-RevId: 41fbc3889b46cf8091bfa1fd2f2420128eb69b36
* feat: Highlight advanced props

* refactor / feedback

GitOrigin-RevId: 9edeb0b183b9fd6b373fd34a2e5cc27046d47426
GitOrigin-RevId: 68a5104052a763fd2c26fe4594fcd2e25a3cf54a
GitOrigin-RevId: 2f0f105d5b68cde85f24d6cacd93403dc92ad08f
GitOrigin-RevId: a845a88dda6b07356a3f321bf96d1c957653695f
GitOrigin-RevId: 3a101dcff4b6b5f6ce7db7752de7ac2c9901ab70
GitOrigin-RevId: a28317aef02a2eb91feb92387f2d0399cdbae87e
GitOrigin-RevId: fb745d5933efe7bfbbdb86d5e21383c51efcc73f
GitOrigin-RevId: 17782c920adf9f475363e16224f6f997b0d52154
Upgraded minor and patch versions across all platform workspaces.

Skipped version upgrades will be documented in a separate PR.

GitOrigin-RevId: a209f961d539ef5e67a72607eff1a7f74e038009
GitOrigin-RevId: 3fa1e141dd7097621f0de65f1fc610062248d23b
…(#2713)

@octokit/app bumped 16.1.1 -> 16.1.2 and @octokit/auth-unauthenticated
bumped 7.0.2 -> 7.0.3; rename patch files to silence version mismatch
warnings on yarn install.

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
GitOrigin-RevId: 8eb7d2aa0b8aa95e78238e83466edf147bbd6970
@ai-sdk/react bumped from 3.0.80 to 3.0.170 as a transitive dependency of
@ai-sdk/google-vertex v4. In that range, addToolOutput changed its return
type from Promise<void> to void | PromiseLike<void>. Widening spawn's
parameter type accommodates this without forcing every call site to cast.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
GitOrigin-RevId: cebf1df3da538c25819eb5d24c3100927f7de897
GitOrigin-RevId: 0e2dbc3d49d6dd874fa88fedc881de96fc42e8e9
…events (#2712)

BaseAnalytics.track() was not passing this.baseEventProperties to
mergeProperties, so properties like `production` and `host` set via
appendBaseEventProperties were never included in events sent to PostHog
(server-side).

mergeSane (lodash mergeWith) mutates the first argument in place. All
call sites pass class members as the first argument, so each call would
permanently accumulate properties from subsequent calls. Merge into a
fresh {} instead.

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
GitOrigin-RevId: 96f0f681abbce3f2f5e9b7079342f9785b84ea5d
Upgrade devDependency ranges across all `packages/` workspaces.

## devDependency ranges narrowed to latest

**packages/cli**
- `@babel/core` ^7.12.3 → ^7.29.0
- `@babel/generator` ^7.12.1 → ^7.29.1
- `@babel/parser` ^7.12.3 → ^7.29.2
- `@babel/preset-typescript` ^7.12.1 → ^7.28.5
- `@babel/traverse` ^7.12.1 → ^7.29.0
- `@babel/types` ^7.23.0 → ^7.29.0
- `@types/babel__core` ^7.20.3 → ^7.20.5
- `@types/babel__generator` ^7.6.6 → ^7.27.0
- `@types/babel__traverse` ^7.20.3 → ^7.28.0
- `@types/cli-progress` ^3.11.0 → ^3.11.6
- `@types/lodash` ^4.14.157 → ^4.17.24
- `@types/semver` ^7.3.1 → ^7.7.1
- `@types/tmp` ^0.2.0 → ^0.2.6
- `esbuild` 0.17.18 → 0.27.7
- `lodash` ^4.17.19 → ^4.18.1
- `prettier` ^3.6.2 → ^3.8.3
- `semver` ^7.3.2 → ^7.7.4
- `socket.io-client` ^4.1.2 → ^4.8.3
- `tmp` ^0.2.1 → ^0.2.5
- `ts-jest` ^29.1.1 → ^29.4.9
- `tsx` ^4.20.6 → ^4.21.0
- `utility-types` ^3.10.0 → ^3.11.0
- `winston` ^3.3.3 → ^3.19.0

**packages/create-plasmic-app**
- `@types/lodash` ^4.14.168 → ^4.17.24
- `@types/semver` ^7.3.5 → ^7.7.1
- `tsx` ^4.20.6 → ^4.21.0

**packages/host**
- `@rollup/plugin-json` ^6.0.0 → ^6.1.0
- `@types/classnames` ^2.3.0 → ^2.3.4
- `rollup-plugin-banner2` ^1.2.2 → ^1.3.1

**packages/loader-react**
- `@types/pascalcase` ^1.0.0 → ^1.0.3

**packages/nextjs-app-router**
- `@types/yargs` ^17.0.32 → ^17.0.35

**packages/react-web**
- `@babel/core` ^7.14.6 → ^7.29.0
- `@babel/preset-env` ^7.22.15 → ^7.29.2
- `@babel/preset-react` ^7.22.15 → ^7.28.5
- `@babel/preset-typescript` ^7.22.15 → ^7.28.5
- `@rollup/plugin-json` ^6.0.0 → ^6.1.0
- `@types/classnames` ^2.3.1 → ^2.3.4
- `@types/clone` ^2.1.1 → ^2.1.4
- `@types/dlv` ^1.1.2 → ^1.1.5

**packages/react-web-runtime**
- `rollup` ^4.1.4 → ^4.60.2

## Lockfile deduplication

- Ran `yarn-deduplicate --strategy fewer` after install — reduced from 729 to 470 duplicate entries vs master
- Manually preserved two lockfile entries that dedup would incorrectly merge:
  - `@types/react@*` kept at 18.x (merging up to 19.x breaks `plasmicpkgs/react-slick` build — TS2786)
  - `@testing-library/user-event@^14.4.0` kept at 14.6.x (merging down to 14.5.2 breaks react-aria storybook focus tests)

## Skipped

- `react-aria` / `@react-aria/*` / `@react-stately/*` / `@react-types/*` — blocked by PLA-12485 (focus regression on overlay dismiss)

GitOrigin-RevId: 34942a8d48b026e372fe772a77752283cef420cf
 - @plasmicapp/cli@0.1.361
 - create-plasmic-app@0.0.142
 - @plasmicapp/data-sources@1.0.3
 - @plasmicapp/host@2.0.2
 - @plasmicapp/loader-gatsby@2.0.3
 - @plasmicapp/loader-nextjs@2.0.3
 - @plasmicapp/loader-react@2.0.3
 - @plasmicapp/nextjs-app-router@1.0.23
 - @plasmicapp/react-web@1.0.3
 - @plasmicapp/react-web-runtime@1.0.3
 - plasmicpkgs-dev@0.0.62
 - @plasmicpkgs/airtable@0.0.259
 - @plasmicpkgs/antd@2.0.167
 - @plasmicpkgs/antd5@0.0.340
 - @plasmicpkgs/plasmic-chakra-ui@0.0.75
 - @plasmicpkgs/cms@0.0.22
 - @plasmicpkgs/commerce@0.0.243
 - @plasmicpkgs/commerce-commercetools@0.0.193
 - @plasmicpkgs/commerce-local@0.0.243
 - @plasmicpkgs/commerce-saleor@0.0.207
 - @plasmicpkgs/commerce-shopify@0.0.251
 - @plasmicpkgs/commerce-swell@0.0.253
 - @plasmicpkgs/contentful@0.0.17
 - @plasmicpkgs/dnd-kit@0.0.22
 - @plasmicpkgs/fetch@0.0.35
 - @plasmicpkgs/framer-motion@0.0.243
 - @plasmicpkgs/plasmic-google-maps@0.0.24
 - @plasmicpkgs/graphql@0.0.29
 - @plasmicpkgs/plasmic-keen-slider@0.0.88
 - @plasmicpkgs/lottie-react@0.0.237
 - @plasmicpkgs/plasmic-mailchimp@0.0.22
 - @plasmicpkgs/plasmic-basic-components@0.0.274
 - @plasmicpkgs/plasmic-calendly@0.0.91
 - @plasmicpkgs/plasmic-cms@0.0.313
 - @plasmicpkgs/plasmic-content-stack@0.0.199
 - @plasmicpkgs/plasmic-contentful@0.0.193
 - @plasmicpkgs/plasmic-embed-css@0.1.229
 - @plasmicpkgs/plasmic-eventbrite@0.0.77
 - @plasmicpkgs/plasmic-giphy@0.0.77
 - @plasmicpkgs/plasmic-graphcms@0.0.216
 - @plasmicpkgs/plasmic-hubspot@0.0.89
 - @plasmicpkgs/plasmic-intercom@0.0.22
 - @plasmicpkgs/plasmic-link-preview@1.0.147
 - @plasmicpkgs/plasmic-nav@0.0.215
 - @plasmicpkgs/plasmic-pigeon-maps@0.0.77
 - @plasmicpkgs/plasmic-query@0.0.264
 - @plasmicpkgs/plasmic-rich-components@1.0.246
 - @plasmicpkgs/plasmic-sanity-io@1.0.224
 - @plasmicpkgs/plasmic-soundcloud@0.0.89
 - @plasmicpkgs/plasmic-strapi@0.1.201
 - @plasmicpkgs/plasmic-tabs@0.0.86
 - @plasmicpkgs/plasmic-typeform@0.0.89
 - @plasmicpkgs/plasmic-wordpress@0.0.171
 - @plasmicpkgs/plasmic-wordpress-graphql@0.0.161
 - @plasmicpkgs/plasmic-yotpo@0.0.88
 - @plasmicpkgs/radix-ui@0.0.103
 - @plasmicpkgs/react-aria@0.0.177
 - @plasmicpkgs/react-audio-player@0.0.72
 - @plasmicpkgs/react-awesome-reveal@3.8.247
 - @plasmicpkgs/react-chartjs-2@1.0.155
 - @plasmicpkgs/react-parallax-tilt@0.0.245
 - @plasmicpkgs/react-quill@1.0.108
 - @plasmicpkgs/react-scroll-parallax@0.0.254
 - @plasmicpkgs/react-slick@0.0.266
 - @plasmicpkgs/react-twitter-widgets@0.0.243
 - @plasmicpkgs/react-youtube@7.13.249
 - @plasmicpkgs/rive@0.0.31
 - @plasmicpkgs/plasmic-spotify@0.0.22
 - @plasmicpkgs/strapi@0.0.20
 - @plasmicpkgs/tiptap@0.0.28
 - @plasmicpkgs/vanilla-cookieconsent@0.0.21
 - @plasmicpkgs/wordpress@0.0.21

GitOrigin-RevId: f110feb3414bdfdcbd84167e91a951f8dcd4dd60
GitOrigin-RevId: be922d505cb61d4f6df699d002b4a3ba7540e0a3
Resolves critical/moderate audit vulnerabilities:
- handlebars: JS injection via AST type confusion (CVE, patch >=4.7.9)
- protobufjs: arbitrary code execution (patch >=7.5.5) - via posthog-js opentelemetry chain

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
GitOrigin-RevId: 29c254c6d581dd53094239218f0356e1a1c1ba2e
* fix: Choice prop codegen when options use object form

* test: wabToTsType

GitOrigin-RevId: 4b7d5bff4f86adc6f3917ecf1cd7a03e0af01a81
GitOrigin-RevId: 7e53e05781d6af6873315d1ad4eb4776e2e00697
GitOrigin-RevId: 13aad22bce0f9357d55549ead01d8b6df8d8733d
 - plasmicpkgs-dev@0.0.63
 - @plasmicpkgs/fetch@0.0.36
 - @plasmicpkgs/graphql@0.0.30

GitOrigin-RevId: a9a1f69ead8f2aebcc4e9b5a63c040c271a92252
GitOrigin-RevId: 643a9d8dfb2d09c8a2c1bd5178ad47683220e0a4
Adds a `loader_bundle_cache_total` Prometheus counter that tracks S3
bundle cache hits and misses, labeled by source ("prefill" vs "live"),
so we can measure how often a live CDN request triggers an esbuild
run vs being served from a prefilled S3 cache.

Adds cache miss log message with the cache key.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
GitOrigin-RevId: 29dd37be14bd3bab0922875ff51bf3f49b95a3b9
GitOrigin-RevId: 26a99ab7a4b47a43145712b8b0e4b68f8d7db9e8
GitOrigin-RevId: 8765cdc08085347514c193d541654af29c24d15a
GitOrigin-RevId: d781fb8e8a177f3cf7c58d0b632642c94c9bdebc
jaslong and others added 26 commits May 4, 2026 17:07
When setupNextJs throws, ctx stays undefined and afterAll still calls
teardownNextJs, producing a spurious destructuring TypeError that hides
the real failure. Accept undefined and return early.

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
GitOrigin-RevId: 98833dacfb6fabe628021d2be5517d87006025b3
GitOrigin-RevId: 7f5190aecaf43aa6bff6861576c184410a5e17a9
 - @plasmicapp/data-sources@1.0.4
 - @plasmicapp/react-web@1.0.4
 - @plasmicapp/react-web-runtime@1.0.4
 - @plasmicpkgs/antd5@0.0.341
 - @plasmicpkgs/plasmic-link-preview@1.0.148
 - @plasmicpkgs/plasmic-rich-components@1.0.247
 - @plasmicpkgs/tiptap@0.0.29

GitOrigin-RevId: aed0870defb894a50985f5b656f3f50e167b835e
GitOrigin-RevId: 7eae933dda12ba7568558cf6c655ff3469057239
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
GitOrigin-RevId: bceffb3c803ec2ff99d904d524bac7ee3e0e4fb3
GitOrigin-RevId: 5dd48526aaa45495ecad498b3e8691d3d12dcbf3
* feat(insertHtml): added replace tpl capability in insertHtml tool

* fix(insertHtml): ensure replace works within paste operation to do proper validation and fixups for removal and insertion

* chore: variable name changes

GitOrigin-RevId: f432c4a9e54a8be2d39052392cc96a3483224334
GitOrigin-RevId: 77ca6bb919834066819b050a1159b66ab7610418
GitOrigin-RevId: 048843f0301687df626e79619f98d5d51b652daa
 - @plasmicapp/data-sources@1.0.5
 - @plasmicapp/react-web@1.0.5
 - @plasmicapp/react-web-runtime@1.0.5
 - @plasmicpkgs/antd5@0.0.342
 - @plasmicpkgs/plasmic-link-preview@1.0.149
 - @plasmicpkgs/plasmic-rich-components@1.0.248
 - @plasmicpkgs/tiptap@0.0.30

GitOrigin-RevId: 28870c80765c35a985b945cd9bbd976d92b88f63
GitOrigin-RevId: 6aaf9f1417a61ea248e222c7487991504efc83f5
GitOrigin-RevId: 0177a3ede7420189ceb29ab6574e69d9d6d98fe0
GitOrigin-RevId: fe8ccb93494bfcf0e1b1a8af63b0b63c40fd5453
…740)

GitOrigin-RevId: 5e9e1ae1a3c0b03cb53b4f1877cc149ad63875b6
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
GitOrigin-RevId: 5e051fc7f85411902eb94aa5c29b92941e154021
GitOrigin-RevId: 2533f13afcdd031358c1c52579febff21d1a8827
GitOrigin-RevId: 3e7af71d16dc2d761629b4260db2a7d5635008cc
GitOrigin-RevId: c5c8b46f9dac84ad17a49de86dc614d290799fa0
 - create-plasmic-app@0.0.143
 - @plasmicapp/react-web@1.0.6
 - @plasmicapp/react-web-runtime@1.0.6
 - @plasmicpkgs/antd5@0.0.343

GitOrigin-RevId: 5f674c9df3345496989eb0d1e09ddd30604757a9
GitOrigin-RevId: 1a4ec2d512f388c750b9bfa006bf75f0cc9a577a
GitOrigin-RevId: a963be98d93695eb77fdf6c417362095081d40f2
GitOrigin-RevId: 014b8d5684c094815d51bcb78660314d47a5e59a
GitOrigin-RevId: b8fdbb1042529499784f78dc3a7ef952553f6514
GitOrigin-RevId: 77517639c290c557c99ad11256d4e46d09a1daa8
 - create-plasmic-app@0.0.144

GitOrigin-RevId: 94026327bd519c5a334ca974ef9d6d3d12855f25
@github-actions github-actions Bot changed the title merge: upstream 29 commits merge: upstream 54 commits May 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants