Skip to content

[Docs Site] Bump mermaid from 11.16.0 to 11.16.1 - #32620

Open
dependabot[bot] wants to merge 1 commit into
productionfrom
dependabot/npm_and_yarn/mermaid-11.16.1
Open

[Docs Site] Bump mermaid from 11.16.0 to 11.16.1#32620
dependabot[bot] wants to merge 1 commit into
productionfrom
dependabot/npm_and_yarn/mermaid-11.16.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 8, 2026

Copy link
Copy Markdown
Contributor

Bumps mermaid from 11.16.0 to 11.16.1.

Release notes

Sourced from mermaid's releases.

mermaid@11.16.1

Patch Changes

  • #8022 12d472c Thanks @​aloisklink! - fix: handle CSS sibling combinators in compileCSS

  • #8022 2cd6dcf Thanks @​aloisklink! - fix: increase protections against prototype pollution

    User-controlled input already has protections against prototype pollution.

    Fixes: GHSA-c4c3-pg64-4m4v

  • #8022 99af3fc Thanks @​aloisklink! - fix(architecture): use Maps and Sets to store groups/services

    Services are now rendered in the order they are defined and more service IDs are now supported.

  • #8022 2cd6dcf Thanks @​aloisklink! - deprecate: Deprecate the mermaidAPI.setConfig() function

    Calling this function has no observable effect, as the next time a render() or parse() is called, the currentConfig is cleared.

  • #8022 630aa7e Thanks @​aloisklink! - fix(xychart): support zero-width x-axis ranges

  • #8022 59b22fa Thanks @​aloisklink! - fix(radar): limit number of ticks to 32

    Setting a ticks value higher than this would only show 32 ticks.

Commits
  • 7ecca0c Version Packages (#8023)
  • 95b1b9c docs: change mermaidAPI.setConfig() changeset (#8024)
  • acc69f1 Merge pull request #8022 from mermaid-js/release/11.16.1
  • eba7287 docs: point changesets to correct commit hashes
  • 12d472c Merge commit from fork
  • 2cd6dcf Merge commit from fork
  • 630aa7e Merge commit from fork
  • 59b22fa Merge commit from fork
  • 99af3fc Merge commit from fork
  • 2337f7e Merge branch 'test/improve-example.html' into release/11.16.1
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [mermaid](https://github.com/mermaid-js/mermaid) from 11.16.0 to 11.16.1.
- [Release notes](https://github.com/mermaid-js/mermaid/releases)
- [Commits](https://github.com/mermaid-js/mermaid/compare/mermaid@11.16.0...mermaid@11.16.1)

---
updated-dependencies:
- dependency-name: mermaid
  dependency-version: 11.16.1
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team as a code owner August 8, 2026 05:33
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 8, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 8, 2026 05:33
@cloudflare-docs-bot

cloudflare-docs-bot Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

Dependabot review

Package Impact Recommendation
mermaid 11.16.0 → 11.16.1 🟠 Medium ⚠️ Verify

Overall: ✅ Merge + spot-check

mermaid 11.16.1 is a patch release containing a security fix for prototype pollution (GHSA-c4c3-pg64-4m4v) and several bug fixes for architecture, xychart, and radar diagrams, plus CSS sibling combinator handling and deprecation of mermaidAPI.setConfig(). This repo uses mermaid as a direct devDependency for client-side rendering of visitor-visible diagrams. The client script only calls mermaid.initialize() and mermaid.render() — both unchanged. None of the specifically patched diagram types (architecture, xychart, radar) appear in the content repository. Overall risk is low, but because mermaid directly renders public-facing content, a quick spot-check of pages with diagrams is prudent.

Package details

mermaid: 11.16.0 → 11.16.1

Type: security fix
Dependency type: direct

What changed

  • Security fix: increased protections against prototype pollution (GHSA-c4c3-pg64-4m4v).
  • Bug fix: handle CSS sibling combinators in compileCSS.
  • Bug fix(architecture): use Maps/Sets for groups/services rendering.
  • Bug fix(xychart): support zero-width x-axis ranges.
  • Bug fix(radar): limit number of ticks to 32.
  • Deprecation of mermaidAPI.setConfig() (no runtime effect).

Usage in this repo
Direct dependency used client-side in src/scripts/mermaid.client.ts (calls mermaid.initialize() and mermaid.render()) and build-time in src/plugins/satteri/mermaid.ts to transform mermaid code fences into pre.mermaid elements. Many content pages contain mermaid fenced code blocks.

Impact: 🟠 Medium — mermaid renders visitor-visible diagrams, so any rendering regression would affect published content. However, the patch only fixes bugs in specific diagram types not used in this repo, and the security fix does not change the called APIs.


@github-actions github-actions Bot added the size/l label Aug 8, 2026
@github-actions

github-actions Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

This pull request requires reviews from CODEOWNERS as it changes files that match the following patterns:

Pattern Owners
package.json @cloudflare/content-engineering
* @cloudflare/product-owners

@github-actions

github-actions Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

@mwsyalzfary387-ux mwsyalzfary387-ux left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

شكرا لكم

@mwsyalzfary387-ux

Copy link
Copy Markdown

ممكن فتح السحب

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code size/l

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants