Skip to content

Bump the bundled Scalar UI to 1.62.5 - #113

Merged
FumingPower3925 merged 2 commits into
mainfrom
bump-scalar-1.62.5
Jul 8, 2026
Merged

Bump the bundled Scalar UI to 1.62.5#113
FumingPower3925 merged 2 commits into
mainfrom
bump-scalar-1.62.5

Conversation

@FumingPower3925

Copy link
Copy Markdown
Owner

Supersedes #112 (the Dependabot all-ui-bundles group PR, which only edits package.json).

Bumps the bundled Scalar UI (@scalar/api-reference) 1.62.1 → 1.62.5 across all pin sites: CDN version + SRI in ui/scalar, embedded version + //go:generate URL + re-vendored assets/standalone.js + hash pin in ui/scalaremb, and the package.json tracker.

Supply-chain verification

  • Provenance: 1.62.5 carries an npm signature and SLSA build provenance (slsa.dev/provenance/v1) attesting it was built from github.com/scalar/scalar via .github/workflows/main.yml on a GitHub-hosted runner (subject @scalar/api-reference@1.62.5).
  • Integrity: the npm tarball's computed sha512 matches the published dist.integrity; the jsDelivr copy is byte-identical to the tarball; the sha384 SRI is recomputed from those verified bytes (sha384-qgSpG+…).
  • No new phone-home: the external-host set is byte-identical to 1.62.1 (49 hosts, zero new domains), and the active-network surface is unchanged (fetch("http/sendBeacon/analytics = 0; .track(/telemetry counts identical to 1.62.1 — pre-existing Vue reactivity + a config toggle, fenced by the strict connect-src 'self' CSP).
  • Version chain: monotonic 1.62.1 → …→ 1.62.5, sequential publish times, @latest = 1.62.5, no republished versions.

What 1.62.2–1.62.5 changes

Patch releases only — rendering/behavior fixes: response-property deep links, an allOf + oneOf/anyOf property-merge fix (#9664), AsyncAPI layout/tag tweaks, an auth-selector prop, an SSR-hydration fix. 1.62.3/1.62.4 are empty workspace bumps. No breaking change to @scalar/api-reference; data-url/data-configuration auto-mount is intact.

Verification

  • gofmt/vet/build/go test -race ./.../golangci-lint clean; Scalar pinning, embedded-asset-integrity, and package.json parity tests pass.
  • uismoke renders all nine UIs under the enforced CSP: Scalar (CDN + embedded) mounts, the CSP-safe defaults still hide the phone-home chrome, and WithConfiguration still works. Rendered + screenshotted for visual fidelity.

Scalar @scalar/api-reference 1.62.1 -> 1.62.5 across the CDN pin, the
embedded bundle, and the package.json tracker. The 1.62.2-1.62.5 patches
are rendering/behavior fixes (response-property deep links, an
allOf + oneOf/anyOf property-merge fix, AsyncAPI layout tweaks); the
data-configuration and CSP contracts stdocs relies on are unchanged.

Supersedes #112. The bundle was verified byte-identical across the npm
tarball and jsDelivr, its sha512 matches the published dist integrity,
it carries SLSA build provenance from github.com/scalar/scalar, and the
external-host set is unchanged from 1.62.1.
@FumingPower3925
FumingPower3925 merged commit 6c625ec into main Jul 8, 2026
40 checks passed
FumingPower3925 added a commit that referenced this pull request Jul 8, 2026
Scalar @scalar/api-reference 1.62.1 -> 1.62.5 across the CDN pin, the
embedded bundle, and the package.json tracker. The 1.62.2-1.62.5 patches
are rendering/behavior fixes (response-property deep links, an
allOf + oneOf/anyOf property-merge fix, AsyncAPI layout tweaks); the
data-configuration and CSP contracts stdocs relies on are unchanged.

Supersedes #112. The bundle was verified byte-identical across the npm
tarball and jsDelivr, its sha512 matches the published dist integrity,
it carries SLSA build provenance from github.com/scalar/scalar, and the
external-host set is unchanged from 1.62.1.
@FumingPower3925
FumingPower3925 deleted the bump-scalar-1.62.5 branch July 8, 2026 14:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant