Skip to content

chore(deps): bump @tiptap/extension-table from 3.30.1 to 3.30.2 in /sdk/typescript - #34

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/sdk/typescript/tiptap/extension-table-3.30.2
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/sdk/typescript/tiptap/extension-table-3.30.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 23, 2026

Copy link
Copy Markdown
Contributor

Bumps @tiptap/extension-table from 3.30.1 to 3.30.2.

Release notes

Sourced from @​tiptap/extension-table's releases.

v3.30.2

@​tiptap/core

Patch Changes

  • Keep mixed JSX children as separate siblings in DOM output.
  • Fixed a bug where editor.chain and editor.can can not be accessed on editor initialization

@​tiptap/extension-image

Patch Changes

  • Fix resizable images staying hidden when the image is cached or fails to load.
Changelog

Sourced from @​tiptap/extension-table's changelog.

3.30.2

Patch Changes

  • Updated dependencies [3dffed5]
  • Updated dependencies [214a140]
    • @​tiptap/core@​3.30.2
    • @​tiptap/pm@​3.30.2
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@tiptap/extension-table](https://github.com/ueberdosis/tiptap/tree/HEAD/packages/extension-table) from 3.30.1 to 3.30.2.
- [Release notes](https://github.com/ueberdosis/tiptap/releases)
- [Changelog](https://github.com/ueberdosis/tiptap/blob/main/packages/extension-table/CHANGELOG.md)
- [Commits](https://github.com/ueberdosis/tiptap/commits/v3.30.2/packages/extension-table)

---
updated-dependencies:
- dependency-name: "@tiptap/extension-table"
  dependency-version: 3.30.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 23, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 23, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: security. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@mmlong818 mmlong818 closed this Sep 4, 2026
@mmlong818
mmlong818 deleted the dependabot/npm_and_yarn/sdk/typescript/tiptap/extension-table-3.30.2 branch September 4, 2026 18:14
@dependabot @github

dependabot Bot commented on behalf of github Sep 4, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

mmlong818 added a commit that referenced this pull request Sep 11, 2026
11 条告警在 2026-09-11 被批量标记成 false positive。逐条读过代码之后,其中三条确实是
误报,四条不是:

真误报(维持驳回):
- #42 model-scheduler.ts:createHmac 用的是每进程 randomBytes(32) 盐,只做连接池 key
  且不落盘,代码注释已写明意图;
- #35 data-sync.ts:sha256 算的是密文做完整性校验,口令走的是 scryptSync;
- #44 workbench-ui.js:route.href 来自应用自己注入的 ClownfishProductStructure,
  不是 DOM 读入的外部输入。

以下四条是真的:

#43 server.ts 连接指纹。原先是 sha256 覆盖 {provider, protocol, baseUrl, apiKey},
并把结果写进任务 payload 落进 agent-jobs.json。四个字段里三个是公开可知的,等于给
apiKey 留了个可离线验证的摘要。指纹要回答的只是「连接变没变」,而 connectionRevision
本来就在这四项任一变化时铸新 UUID——语义等价且完全不碰密钥。同一个仓库里
model-scheduler.ts 早就用每进程 HMAC 盐避开了同一问题,这里的标准本来就该一致。

行为影响:改之前入队的任务,其 payload 里存的是旧的 sha256,比对必然不等,会走
「连接已改变,不会把共享材料发送到另一服务」这条既有拒绝路径——是安全方向,且正是
model-cross-entry 测试覆盖的那条路径。

#38 scramble-wallpaper.js 只转义了引号没转义反斜杠,值又被拼进 url("...")。以反斜杠
结尾的壁纸地址会把闭合引号转义掉从而逃逸成 CSS。壁纸地址用户可设。改为先转义反斜杠
再转义引号,并丢掉在 CSS 字符串里非法的控制字符。

#34 office-workbench.js 的 /^(\s*#\s*)+$/ 是嵌套量词,输入是用户文档正文。实测:
把它喂给 " # ".repeat(24) + "!",超过 199 秒没有返回。段落此前已 trim 且非空,
换成线性的 [#\s]+ 判定等价。

#32/#33 ui-evidence.ts:&amp; 排在 &lt; 前面解码,会把 &amp;lt; 二次解码成真的 <;
剥标签的正则不认 </script > 这种带尾随空白的闭合标签,脚本正文会被当正文留下。
&amp; 挪到最后解,闭合标签允许尾随空白。

测试在 tests/unit/companion-codeql-fixes.test.ts,每条都验证过「撤掉修复就会失败」:
撤掉前三处 → 4 条失败;把 &amp; 解码挪回最前 → 对应那条失败。

ReDoS 那条最初写成了跑构造输入加超时断言,实测会让测试进程挂死 199 秒而不是快速失败
(同步正则没法从同一线程里掐断),已改成断言正则形状,构造输入留在注释里。

为可测把 ui-evidence.ts 的 textOf 导出——剥标签与实体解码的顺序值得直接对行为下断言,
而不是只断言正则长什么样。

npm run check 通过(919 项测试 918 通过、0 失败、1 跳过)。
mmlong818 added a commit that referenced this pull request Sep 25, 2026
11 条告警在 2026-09-11 被批量标记成 false positive。逐条读过代码之后,其中三条确实是
误报,四条不是:

真误报(维持驳回):
- #42 model-scheduler.ts:createHmac 用的是每进程 randomBytes(32) 盐,只做连接池 key
  且不落盘,代码注释已写明意图;
- #35 data-sync.ts:sha256 算的是密文做完整性校验,口令走的是 scryptSync;
- #44 workbench-ui.js:route.href 来自应用自己注入的 ClownfishProductStructure,
  不是 DOM 读入的外部输入。

以下四条是真的:

#43 server.ts 连接指纹。原先是 sha256 覆盖 {provider, protocol, baseUrl, apiKey},
并把结果写进任务 payload 落进 agent-jobs.json。四个字段里三个是公开可知的,等于给
apiKey 留了个可离线验证的摘要。指纹要回答的只是「连接变没变」,而 connectionRevision
本来就在这四项任一变化时铸新 UUID——语义等价且完全不碰密钥。同一个仓库里
model-scheduler.ts 早就用每进程 HMAC 盐避开了同一问题,这里的标准本来就该一致。

行为影响:改之前入队的任务,其 payload 里存的是旧的 sha256,比对必然不等,会走
「连接已改变,不会把共享材料发送到另一服务」这条既有拒绝路径——是安全方向,且正是
model-cross-entry 测试覆盖的那条路径。

#38 scramble-wallpaper.js 只转义了引号没转义反斜杠,值又被拼进 url("...")。以反斜杠
结尾的壁纸地址会把闭合引号转义掉从而逃逸成 CSS。壁纸地址用户可设。改为先转义反斜杠
再转义引号,并丢掉在 CSS 字符串里非法的控制字符。

#34 office-workbench.js 的 /^(\s*#\s*)+$/ 是嵌套量词,输入是用户文档正文。实测:
把它喂给 " # ".repeat(24) + "!",超过 199 秒没有返回。段落此前已 trim 且非空,
换成线性的 [#\s]+ 判定等价。

#32/#33 ui-evidence.ts:&amp; 排在 &lt; 前面解码,会把 &amp;lt; 二次解码成真的 <;
剥标签的正则不认 </script > 这种带尾随空白的闭合标签,脚本正文会被当正文留下。
&amp; 挪到最后解,闭合标签允许尾随空白。

测试在 tests/unit/companion-codeql-fixes.test.ts,每条都验证过「撤掉修复就会失败」:
撤掉前三处 → 4 条失败;把 &amp; 解码挪回最前 → 对应那条失败。

ReDoS 那条最初写成了跑构造输入加超时断言,实测会让测试进程挂死 199 秒而不是快速失败
(同步正则没法从同一线程里掐断),已改成断言正则形状,构造输入留在注释里。

为可测把 ui-evidence.ts 的 textOf 导出——剥标签与实体解码的顺序值得直接对行为下断言,
而不是只断言正则长什么样。

npm run check 通过(919 项测试 918 通过、0 失败、1 跳过)。
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant