Bumps the npm_and_yarn group with 1 update in the / directory: mermaid [QUARANTINED_URL: github.com].
Bumps the npm_and_yarn group with 1 update in the /harness directory: js-yaml [QUARANTINED_URL: github.com].
Updates mermaid from 11.16.0 to 11.16.1
Release notes
Sourced from mermaid's releases.
mermaid@11.16.1
Patch Changes
-
#8022 12d472c Thanks @aloisklink! - fix: handle CSS sibling combinators in compileCSS
-
#8022 2cd6dcf Thanks @aloisklink! - fix: increase protections against prototype pollution
User-controlled input already has protections against prototype pollution.
Fixes: GHSA-c4c3-pg64-4m4v
-
#8022 99af3fc Thanks @aloisklink! - fix(architecture): use Maps and Sets to store groups/services
Services are now rendered in the order they are defined and more service IDs
are now supported.
-
#8022 2cd6dcf Thanks @aloisklink! - deprecate: Deprecate the mermaidAPI.setConfig() function
Calling this function has no observable effect, as the next time a
render() or parse() is called, the currentConfig is cleared.
-
#8022 630aa7e Thanks @aloisklink! - fix(xychart): support zero-width x-axis ranges
-
#8022 59b22fa Thanks @aloisklink! - fix(radar): limit number of ticks to 32
Setting a ticks value higher than this would only show 32 ticks.
Commits
Updates js-yaml from 4.3.0 to 4.3.1
Changelog
Sourced from js-yaml's changelog.
4.3.1 - 2026-07-31
Security
- [backport] Remove quadratic complexity from
!!omap duplicate key detection.
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
@dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
@dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
@dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
@dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
You can disable automated security fix PRs for this repo from the Security Alerts page [QUARANTINED_URL: github.com].
Bumps the npm_and_yarn group with 1 update in the / directory: mermaid [QUARANTINED_URL: github.com]. Bumps the npm_and_yarn group with 1 update in the /harness directory: js-yaml [QUARANTINED_URL: github.com].
Updates
mermaidfrom 11.16.0 to 11.16.1Release notes
Sourced from mermaid's releases.
Commits
7ecca0cVersion Packages (#8023)95b1b9cdocs: changemermaidAPI.setConfig()changeset (#8024)acc69f1Merge pull request #8022 from mermaid-js/release/11.16.1eba7287docs: point changesets to correct commit hashes12d472cMerge commit from fork2cd6dcfMerge commit from fork630aa7eMerge commit from fork59b22faMerge commit from fork99af3fcMerge commit from fork2337f7eMerge branch 'test/improve-example.html' into release/11.16.1Updates
js-yamlfrom 4.3.0 to 4.3.1Changelog
Sourced from js-yaml's changelog.
Commits
86e91b84.3.1 releasedc3cc4b0Backport quadratic complexity fix for !!omapDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the Security Alerts page [QUARANTINED_URL: github.com].