Skip to content

fix(release): prepare verified 3.0.3 regression fixes - #260

Merged
wybaby168 merged 56 commits into
mainfrom
codex/release-3.0.3-a177a45
Sep 9, 2026
Merged

fix(release): prepare verified 3.0.3 regression fixes#260
wybaby168 merged 56 commits into
mainfrom
codex/release-3.0.3-a177a45

Conversation

@wybaby168

Copy link
Copy Markdown
Member

Summary

  • Prepare 3.0.3 from private source a177a45de4094e536b775ca2f4103982998b412a, retaining 47 topic commits and the original Dependabot chore(deps): bump maplibre-gl from 5.24.0 to 6.4.1 in the security-updates group across 1 directory #259 commit.
  • Fix Word, spreadsheet, PDF, asset-loading and CAD output regressions; add static HTML/source and RequireJS entries. Keep Vue 2.6/2.7 compatibility.
  • Adopt MapLibre 6.4.1 with a self-contained offline Worker and tested attribution sanitization. Keep audit exceptions explicit and bounded.

Related issue

#242
#243
#245
#247
#248
#250
#255
#256
#257
#258

Issue closure follows production verification, not this merge.

Change classification

  • User-visible UI or rendering change
  • Non-visual change
  • File-format or renderer behavior
  • Public API, package, Worker, WASM, or deployment-path change

Verification

Check Result
pnpm release:channels:pre-publish with Actions publisher and the completed 3.0.2 baseline Pass; optional Gitee token warning
node apps/viewer-demo/scripts/verify-ios-pdf-navigation.mjs Pass on iPhone 17 Pro / iOS 26.4 Simulator; normalizes the starting page using real Previous taps
Built-demo GeoJSON/KML/GPX browser checks at 1280px and 390px Pass, 6/6; exact clean source a177a45, real offline Workers and visible zoom controls
pnpm release:standard:rehearse, followed by same-head frozen continuation after a temporary registry metadata 404 Pass: 88 tarballs, 64/64 cold closures, eight-framework CLI PDF smokes; 95 frozen files verified at a177a45 without rebuilding or repacking
node scripts/verify-public-main.mjs Pass, including the final screenshot; unchanged 340 MiB source budget and private-source exclusions

Sample / fixture evidence

  • apps/viewer-demo/public/example/word-wps-contract.doc
  • packages/renderers/doc/test/fixtures/native-revisions/
  • apps/viewer-demo/public/example/word-cover.docx
  • apps/viewer-demo/scripts/verify-renderer-sanitization.mjs constructs the hostile attribution and verifies two offline map lifecycles.

Visual evidence

Actual clean-source a177a45 demo, 390px viewport:

GeoJSON offline map and zoom controls

Risk and compatibility

Checklist

  • I added or updated focused automated coverage, or explained why it is not needed.
  • I updated user-facing documentation or release notes when behavior or API changed, or marked them not applicable.
  • I verified offline/private-deployment paths when changing Worker, WASM, fonts, vendor assets, or URLs.
  • I did not commit secrets, customer files, private samples, generated caches, or unrelated changes.

Local 3.0.3 preparation only. No release rehearsal, publication, deployment, or issue closure is authorized before the maintainer says start.

Source commit: 76f25ff225100ac8cf57b774cb988e10d13af115
Public-safe replay; generated artifacts are refreshed separately.
Local 3.0.3 preparation only. No release rehearsal, publication, deployment, or issue closure is authorized before the maintainer says start.

Source commit: a4fb763021f78fc9cf117e373ef7a3ff28250df6
Public-safe replay; generated artifacts are refreshed separately.
Local 3.0.3 preparation only. No release rehearsal, publication, deployment, or issue closure is authorized before the maintainer says start.

Source commit: bb0003fd73dc7364810a19aab9f1ff7792660785
Public-safe replay; generated artifacts are refreshed separately.
Local 3.0.3 preparation only. No release rehearsal, publication, deployment, or issue closure is authorized before the maintainer says start.

Source commit: 0198f5db05c2649b1801918185633b2ce0dcd2ed
Public-safe replay; generated artifacts are refreshed separately.
…snapshots

Local 3.0.3 preparation only. No release rehearsal, publication, deployment, or issue closure is authorized before the maintainer says start.

Source commit: 12fb5c2ad02321f6b8ebca2f11e501fa42b4dac5
Public-safe replay; generated artifacts are refreshed separately.
Local 3.0.3 preparation only. No release rehearsal, publication, deployment, or issue closure is authorized before the maintainer says start.

Source commit: 8fa24c7fab1d11f82750753c2e499797d3d28225
Public-safe replay; generated artifacts are refreshed separately.
…espaces

Source commit: 3f3c65f7940f27834a18790401e5be8e0e1851db
Public-safe replay; generated artifacts are refreshed separately.
Source commit: 44b1dd44cb77b9aa524b44aac67b72f825360cf2
Public-safe replay; generated artifacts are refreshed separately.
…ples

Source commit: 44281b8f877f006b0cdc14f1537bd66448546bda
Public-safe replay; generated artifacts are refreshed separately.
Source commit: fa4811d9e3a0a764f81c320663415cfa55b160c0
Public-safe replay; generated artifacts are refreshed separately.
Source commit: 577d63333f54ed7c143891874ac759f544cd722e
Public-safe replay; generated artifacts are refreshed separately.
Keep renderer image downloads within owning-viewer permissions, lifecycle and watermark checks. Bound copied-asset manifests and reject unrecognized paths. Add executable cancellation and malformed-input tests.

Source commit: 8c3bf0efaa35d26e0f1d340531c595dd4b179e00
Public-safe replay; generated artifacts are refreshed separately.
Keep the iPhone viewport stable after keyboard dismissal and size toolbar controls by the actual host. Download current CAD views as guarded PNG/JPEG images. Resolve standard copied PPTX assets in Angular production while preserving explicit and package Worker paths.

Source commit: 0e87500ea0bff45d8846e928683d8fd0fe53d4ac
Public-safe replay; generated artifacts are refreshed separately.
Exercise copied and package Workers in a cold Angular 22 application through all 20 slides. Check original PDF fonts, actual CAD downloads, permissions, mobile layout and real Safari keyboard/navigation. Tie cold-consumer evidence to tarball hashes and assert DOCX geometry at the public load-complete boundary.

Source commit: 7a741880d788428c0ef9bf3e714dae5ef2c34340
Public-safe replay; generated artifacts are refreshed separately.
Document native image output and permissions, mobile controls, Angular asset copying and exact-file evidence. Separate current source and local Demo checks from the future frozen release and production verification. Keep missing private XLS, revised Word and OFD originals explicit; no publication or issue closure is authorized until the maintainer starts release.

Source commit: 457d721e68291650870ac564c311dbeea3da0867
Public-safe replay; generated artifacts are refreshed separately.
Use native Microsoft Word DOC/DOCX files and independently saved accepted/rejected copies as references. Preserve control-character CHPX state and merge paragraphs only at removed revision marks, without changing the parsed tree or crossing table cells and story boundaries.

Twelve new DOC regressions and actual Chromium/WebKit settings checks pass. Prepare the DOCX asset cache key for the unpublished 0.3.30 upstream candidate; registry dependency changes remain approval-gated for the 3.0.3 release.

Source commit: 7379144c94587720adce899f372157ae911cde3e
Public-safe replay; generated artifacts are refreshed separately.
Resolve nested document and resource XML bases before compatibility fallbacks, preserve parent path semantics, and match OFD element names by namespace URI. Keep readable content when nonessential resources are absent and propagate malformed XML/JBIG2 failures instead of hanging.

Twenty constructed unit cases and nineteen actual uploads per Chromium/WebKit pass, alongside existing seals, image placement, pageblock and fidelity checks. Keep the historical pageblock fixture timestamp deterministic. These cases do not claim to reproduce the unavailable original from issue 57.

Source commit: 69831ad463b8233393a3d04e7234b5f9043d07c6
Public-safe replay; generated artifacts are refreshed separately.
Add native Word and constructed OFD samples to the Demo, same-file review-mode checks, and cold Vue CLI/React coverage. Run actual browser checks in all three Vue 2.6 CLI3 build modes and fail early for missing package entrypoints.

Document independent Office references, supported revision boundaries, async OFD failures and still-unseen private originals. Refresh the read-only GitHub issue ledger. Validation: 755 unit tests plus one missing external fixture, 21 issue gates, 47 built-Demo cases, 21 cold consumers, 3 Angular paths, 3 Vue 2.6 browser/build modes, Chromium/WebKit and actual iPhone Safari checks. Local preparation only; no rehearsal, publish, deploy, push, reply or closure.

Source commit: d5802a7afb3fe7d4f2e608e48793a043d5f7f712
Public-safe replay; generated artifacts are refreshed separately.
…shing

Avoid the duplicate ecosystem build in standard packing and the duplicate renderer build in viewer asset staging. Pack verified output in isolated directories with lifecycle scripts disabled; bound registry reads and trusted uploads, drain active jobs on failure, and verify exact integrity before skipping or advancing a dependency layer.

Validation: 33 governance/publisher tests, 14 release helper tests, 18 maintenance guards, syntax and whitespace checks. Live read-only validation found all 88 previous release versions with matching latest tags in 22.245 seconds. No candidate packages were published by these checks.

Source commit: 6402ed7b78b95b212f262c7a5497502c911f7801
Public-safe replay; generated artifacts are refreshed separately.
…isions

Pin both public attachment URLs to the existing WPS fixture hash. Native Word and a separately converted DOCX report zero revisions. Add desktop and narrow upload checks for all four tables and preserve the missing-deletion follow-up boundary.

Validation: 49 candidate Demo cases and 994 resource responses pass; the sales contract also passes independently in Chromium and WebKit. These are candidate checks, not a frozen release or production result.

Source commit: fef8a35aeab570901584eaa14194f5bc15394de5
Public-safe replay; generated artifacts are refreshed separately.
Retain both LSPD fields, use natural leading for single spacing, and distinguish exact/minimum twips. Decode the four font slots separately and resolve the bounded STSHI default-font indices.

Verified against the issue 236 sales-contract fixture and native Word reference. Eleven focused unit cases and the existing DOC regressions pass; the old Demo fails the font-metric regression. No filename or content-specific rendering branches.

Source commit: a4969dad2c80ca62d9d8709f2ccada082f665a84
Public-safe replay; generated artifacts are refreshed separately.
Check actual text wrapping, font extents, table geometry, original file bytes and English/Chinese sample-picker interactions in Chromium and WebKit. Keep the no-revision attachment distinct from the missing-deletion screenshot follow-up.

Document local font fallback and the actual DOCX Worker auto-mode asset boundary. Eight contract browser cases and the 51-case candidate Demo suite pass; this is not production release evidence.

Source commit: 2e20b4c41acaddc0abb319afb95c8262e738727c
Public-safe replay; generated artifacts are refreshed separately.
Read back all 200 issues and 34 post-close comment groups through gh. Record the contract typography red/green tests, native Word revision boundary, 767 passed units plus one missing-fixture skip, and 51 candidate browser scenarios.

Retain DWF -> CAD -> File Viewer publication order. Record the upstream npm authorization failures and required msdoc-viewer 0.2.6 alias instead of claiming 3.0.3 has been frozen, published or deployed.

Source commit: da70a6c27707bb5b9baea810bcfb7e5d1a2aba47
Public-safe replay; generated artifacts are refreshed separately.
A local chunked-response probe reads all 43,971 contract bytes with the expected SHA-256 in the page, but Chromium exposes an empty DevTools body after response.blob(). This caused a false failure when reading back the saved Demo.

Fetch the real server response through the browser route, hash it, and forward the unmodified response. Keep the visible sample click, exact deployed-byte checks and rendering assertions. All eight Chromium/WebKit contract cases pass on the saved candidate; no runtime change or weakened integrity check.

Source commit: 48df81db4daa944fa72ed76335bfff4ddc6e198a
Public-safe replay; generated artifacts are refreshed separately.
The saved candidate repeats all 51 scenarios, eight contract browser checks and four bilingual documentation pages. Keep asset response hashes in their own reports instead of treating cache-dependent request counts as a stable product metric.

Source commit: 23b412c29877f87b61416e42e529654cac276504
Public-safe replay; generated artifacts are refreshed separately.
Source commit: a6864b96128a06b87c80f9465d281b0c9f33719f
Public-safe replay; generated artifacts are refreshed separately.
…n copies

Reproduce #257 with published 3.0.2 in a cold pnpm nested-root application: the requested PPTX Worker resolves to HTML. Walk ancestor runtime declarations without crossing a nearer light-runtime boundary, preserve explicit output roots, and anchor Full dependencies before optimization.

Verify six Vite 6.4.3/8.2.2 dev/build/custom-root cases with all 20 slide records, final-slide rendering, and real Worker URL, MIME and SHA-256. The reporter project is not claimed as tested.

Source commit: 0d17739e22e3183e13e2706ec994c96afe287229
Public-safe replay; generated artifacts are refreshed separately.
Add separate light/full AMD modules while preserving the script-tag global API and ESM exports. Isolate bundled vendor define branches lexically, preserve global this under strict evaluation, and capture each loader context API without modifying the host define.

Reproduce the old undefined-module failure using RequireJS 2.3.7. Verify extracted candidate tarballs and the built component Demo in Chromium and WebKit: five real formats, all 22 lazy renderer registrations, host modules, multiple contexts and local Worker/WASM responses. Include a local loader, the full upstream license, bilingual integration examples, and AMD distribution checks.

Source commit: 4db5140d3e7151a18d51e326ae25d5cefe27d197
Public-safe replay; generated artifacts are refreshed separately.
…cutable

Inventory 202 issues, eight open reports and 34 post-close comment groups using gh only. Keep candidate proof, missing originals, published artifacts and production closure distinct; no issue or security alert is closed by this refresh.

Accept complete configuration-only bug reports without demanding a document, while preserving file-fidelity sample requirements. Wire the real RequireJS and cold Vite browser checks into Public CI and derive release gate execution from declared special checks. Retain both security specs in public sync and replace the obsolete code-only HTML sample expectation with actual preview/source, opaque sandbox and CSP checks.

Validation: 770 passing Vitest tests, one external-fixture skip, 35 governance tests, 18 maintenance boundary checks, six cold Vite cases and packed/built/saved RequireJS browser checks. Preserve the full-matrix failure at the stale HTML contract; eight targeted bilingual sample cards pass after correction, but a complete new rehearsal remains required.

Source commit: 8e7d2787607bf31b53bc54e5250c1530ac18f9d7
Public-safe replay; generated artifacts are refreshed separately.
…ollout

Continue local repairs and readiness verification only. The September 8 instruction supersedes earlier standing release permission: notify on verified readiness and wait for explicit rollout instructions before any public release, deployment or issue closure.

Source commit: 228b02983475fe2f31974723d0565d7fd5799398
Public-safe replay; generated artifacts are refreshed separately.
wybaby168 and others added 26 commits September 9, 2026 09:34
…ined

Reproduce the missing sibling AMD helper in an exported web-full cold build, then the optional PDF repair dependency failure under npm shallow installation. Export canonical local build helpers, offline assets and RequireJS fixtures, reject escaping imports, and bundle the opt-in repair implementation in the package that owns pdf-lib while keeping renderer registration shared.

Verify web and web-full with fresh official-registry installs outside the source tree, complete builds, the asset CLI and Chromium/WebKit RequireJS checks. Seven export/import contracts and one isolated capability runtime test pass. No public release or deployment is performed; the full release matrix and upstream closure remain separate readiness gates.

Source commit: 0b4e4f7d36ddafcd9f48880d285c16000e313497
Public-safe replay; generated artifacts are refreshed separately.
Run the installed Vite CLI directly on an isolated port and terminate the owned child before rejecting startup failures. Preserve bounded waits and add real-process lifecycle tests. The Vue 2.6 cold PPTX and binary PPT paths pass after the original empty-output startup timeout.

Regenerate the standard spreadsheet Worker from the already-committed canonical web asset and verify identical SHA-256. Record the 316-card sample regression, standalone build closure, 780 passing root tests with one external-fixture skip, governance checks and remaining readiness boundaries. A complete new matrix and frozen dependency closure are still required; publication remains reserved for the maintainer.

Source commit: 359b1cec485729184037047ae89b06e2ac8442da
Public-safe replay; generated artifacts are refreshed separately.
…me provenance

Reproduce an unhandled PDF.js 5.4.624 rejection by canceling the real document transport at Ready. End detached startup, recovery and password continuations after cancellation without hiding active parsing errors. Keep the pinned source patch in both the staged renderer and public workspace dependency declarations.

Share schema-4 source, transform, patch and payload verification across renderer builds and real npm/pnpm/Vue 2.6 cold installs. Exercise 40 deterministic cancellations across Chromium/WebKit real and main-thread Workers, subsequent text/canvas rendering, invalid-file errors and explicit transport identity. Keep failure diagnostics and ensure Public CI installs browsers before this gate.

Validation: 809 root tests passed, one external-fixture skip; 35 governance tests and 18 maintenance boundary checks; three Vue CLI3 build/browser modes; npm/pnpm owner-asset cold installs; 20 built RequireJS cases. No public publication or deployment; complete clean-head matrix and final upstream closure remain required.

Source commit: 9206b8deb9396cafd151de2972197e2cf50872ca
Public-safe replay; generated artifacts are refreshed separately.
Reproduce stale CHM and Adobe resource Workers in the shipped capability packs, then regenerate canonical viewer, compatibility and asset-pack copies from the existing bounded-parser source fixes. Verify CHM Worker/WASM and every declared Adobe payload byte against its owning renderer rather than accepting mere file presence.

Refresh spreadsheet Workers from the current core toolbar translations and initialization order without changing the declared spreadsheet engine. All four Worker groups match across the generated distribution copies. CHM and Adobe asset verification, component Demo build and the 3613-file offline Demo archive check pass.

Source commit: 17bf9d12aa9fa8c77db87532b22eb113687445c6
Public-safe replay; generated artifacts are refreshed separately.
…gates

Keep original matrix/build failures separate from focused successful reruns. Record 809 passing tests, the external-fixture skip, exact transport cancellation checks, schema-4 cold installs, fresh Demo artifacts and generated security asset parity. Distinguish current declared upstream versions from isolated unpublished candidates and reserve all publication for the maintainer.

Source commit: ec3c066f4066858c43bed05e0831dc01f9b51fda
Public-safe replay; generated artifacts are refreshed separately.
…oots

Recognize bundled and directly served package Workers before probing copied-asset manifests. Preserve explicit Worker URLs and shared asset bases, and retain the standard copy fallback for Angular production.

Add URL and lifecycle regressions, remove Angular's optional-manifest 404 exemption, and include the resolver gate in public exports and CI.

Verified 820 root tests (one external-fixture skip), 40 focused tests, type checks, 35 governance tests, 18 maintenance boundaries, rebuilt component Demo, and three actual Angular cold-install modes. Full clean-source matrix and frozen 3.0.3 dependency closure remain pending; no public publishing or deployment.

Source commit: 0902e28f7ff70ef157a997feb793a71cdf67a362
Public-safe replay; generated artifacts are refreshed separately.
The combined candidate run retained 20 parsed slides but timed out on the last slide after Angular rebuilt the renamed public manifest and reloaded the page. Preserve that failure rather than retrying through it.

Stop each owned dev server before mutating fixtures, restart for the package-Worker case, restore files after shutdown, and assert one main-document navigation. Add four cleanup/order regressions and export them with Public CI.

Verified 824 unit tests (one missing external fixture), 35 governance checks, 18 maintenance boundaries, and a complete cold Vue/React 21-case plus Angular three-mode run using hash-verified upstream candidates. The earlier 0902e28 clean-source matrix passed all 22 commands and native iPhone Safari passed; final dependency versions and publishing remain unapproved and unfrozen.

Source commit: e0c40baa059a39bcf8ea92328c6079eccbff4ced
Public-safe replay; generated artifacts are refreshed separately.
Align 87 packages at 3.0.3 and advance msdoc-viewer to 0.2.6. Install DOCX 0.3.30, styled-exceljs 0.21.5 and CAD 0.8.2 with DWF 0.6.7 from the official registry; regenerate CLI, license and offline asset metadata.

Validation: registry tarballs matched the tested upstream bytes, 88 package versions and 1008 component targets verified, governance and 18 maintenance boundaries passed. Full frozen rehearsal and production rollout remain separate mandatory gates.

Source commit: 1ffd9b756fef5397629f5a371a227bb66dc2db83
Public-safe replay; generated artifacts are refreshed separately.
Use registry-verified DOCX 0.3.31 and styled-exceljs 0.21.6. Derive DOCX cache versions from the shared core constant, synchronize runtime constants from exact renderer dependencies, and cover standard/full package assets independently. Refresh offline Workers and CAD 0.8.2 payloads; preserve Vue 2 and the CAD 0.8.0 compatibility path.

Validated: 22 runtime tests, version-sync tests, 88 package versions, 1008 matrix targets, repository governance and 18 maintenance boundaries. The earlier frozen rehearsal failed and must be rerun at this source commit.

Source commit: 05f1afb683df786629114bc001967b8a986663ba
Public-safe replay; generated artifacts are refreshed separately.
… dependency

Write the same per-package JSON report into Actions logs and the job summary. Keep immutable package checks and failure behavior unchanged; avoid classifying a successful publish as failed only because Actions artifact storage is exhausted.

Source commit: e2a4c88bf19d3a5fd6531e388f4406a76d08934a
Public-safe replay; generated artifacts are refreshed separately.
Reproduce a 617-to-616px DWFx export-height drift: the hovered upload trigger was translated up by one pixel when its visual bounds became the persistent document inset. Resolve the capsule target from untranslated bounds while preserving the existing hover effect and centered-width compensation. Keep exact raster-dimension assertions, add opt-in ancestor geometry traces, and run the capsule regression in release and Public CI. Seven unit tests, type checking, four CAD backends plus seven output-policy cases, and three additional native DWFx runs passed. Update both language changelogs.

Source commit: de69fb012d35f686b432f7c8ca1fc295a78c7f5f
Public-safe replay; generated artifacts are refreshed separately.
Review upstream 3.4.15 release notes and retain XML clobbering hardening while eliminating mixed direct sanitizer versions. Refresh the DICOM production license ledger without changing pako or package budgets. Renderer sanitizer and Chromium/Firefox/WebKit RTF/DOC/DOCX policy checks passed.

Source commit: 7c9b289b252ecf6fbbbf22718f660f343581ad3e
Public-safe replay; generated artifacts are refreshed separately.
Bumps the security-updates group with 1 update in the / directory: [maplibre-gl](https://github.com/maplibre/maplibre-gl-js).


Updates `maplibre-gl` from 5.24.0 to 6.4.1
- [Release notes](https://github.com/maplibre/maplibre-gl-js/releases)
- [Changelog](https://github.com/maplibre/maplibre-gl-js/blob/main/CHANGELOG.md)
- [Commits](maplibre/maplibre-gl-js@v5.24.0...v6.4.1)

---
updated-dependencies:
- dependency-name: maplibre-gl
  dependency-version: 6.4.1
  dependency-type: direct:production
  dependency-group: security-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Pin direct non-signature ZIP consumers to verified upstream JSZip 3.10.2 and rebuild dependent workers without increasing closure budgets. Old 3.10.1 rejects foreign binary input; four Node/browser-distribution tests cover round trips. Preserve separately audited opt-in signature dependency. Add explicit Actions publishing checks and require this release successful, exact-tag, full-inventory publish evidence at postcheck instead of local npm credentials. Dry runs and stale/partial results are rejected. Full ecosystem build, Vue2.6 CLI3 real browser, sanitizer/license/governance and policy tests passed.

Source commit: 6647dd500e16af680c9c7d6a7d14d894de9ddb0e
Public-safe replay; generated artifacts are refreshed separately.
The DOCX engine allows JSZip >=3.0.0 but the old lock snapshot retained 3.10.1 alongside pinned direct 3.10.2. Align only that compatible transitive resolution, leaving opt-in signature unchanged. Verify engine/runtime ZIP identity and run cheap ZIP/sanitizer checks before expensive builds. Standard profile now passes unchanged limits at 93 packages, 29.60 MiB packed and 99.82 MiB unpacked; five ZIP tests pass.

Source commit: 5eac95f214e64fdd131c2baa5841105d7f76e25e
Public-safe replay; generated artifacts are refreshed separately.
…mples

Audit README changes since ab6c5136: PPT 0.3.4 runtime references and RequireJS AMD entries only; retain all three hash protections. Check baselines and non-interactive copy instructions before expensive rehearsal builds, with negative regression tests. Exclude component sample mirrors already regenerated from canonical viewer-demo sources. The 340 MiB public checkout budget stays unchanged. Public boundary, 35 governance tests, and 18 maintenance boundaries passed.

Source commit: 65c495e9ac3befa8882a50984932b899df1394ee
Public-safe replay; generated artifacts are refreshed separately.
…ffline maps

Adopt the MapLibre 6.4.1 security update from PR #259. Reproduced the old attribution sanitizer executing an adjacent ontoggle handler; the real browser gate now covers the patched control and two offline worker lifecycles. Adapt the ErrorLike event contract and bundle the module worker locally with its upstream license.

Upgrade js-yaml, sharp and Vitest security versions; replace unused Browserify lookup tooling with the same exact browser shims. Refresh the DICOM license ledger. Keep only the existing Vue 2 exception and a tested, version/export/consumer-bounded exception for dcmjs unused adm-zip dependency, which has no patched npm release. Move official registry audit before expensive rehearsal work.

Upstream-PR: #259

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

Source commit: b8bedc868c6a77e3529969850b6403a5f1687fb3
Public-safe replay; generated artifacts are refreshed separately.
Use descendant selectors matching the real MapLibre button/icon DOM; the browser gate renders the actual geo component and checks both visible glyphs. Preserve existing map worker and sanitizer assertions.

The iOS failure capture started on page 2, and the next tap correctly reached page 3. Establish page 1 through real Previous taps and assert the initial state before the unchanged 1-2-3-2-1, search and keyboard checks. Do not reset user reading state in product code.

Source commit: a177a45de4094e536b775ca2f4103982998b412a
Public-safe replay; generated artifacts are refreshed separately.
Source commit: a177a45de4094e536b775ca2f4103982998b412a

Retain 47 public-safe topic commits with their original authors and source
commit references. Refresh manifests, generated assets, dependency locks and
license records from the verified release candidate. Private maintenance
scripts and the Chrome extension remain excluded.

Include the actual a177a45 mobile GeoJSON regression screenshot as PR evidence.

Preserve the original Dependabot PR #259 commit as a merge parent. The
MapLibre 6.4.1 update includes the required typed event and self-contained
offline Worker adaptations, not the failing dependency-only patch.
Regenerate the DICOM license ledger against this source's installed dependency
graph rather than applying a context-mismatched old public ledger patch.

Private-only or generated changes folded into this boundary:
5d2f250c556c4d7ec6d4a07f0251138796438d6b fix(release): require fresh compatibility aliases when freezing
e763c4252c41d7b427b9aacdc8366f665927ad43 fix(assets): preserve compatibility runtime roots during payload refresh
a464946eac2a2afaad25dfed1d6be1033abc7595 chore(demo): synchronize 3.0.3 component runtime snapshots
d7a56413a703d5eeeac59de57704fb727448c1dd fix(packages): align sanitizer pins across renderer consumers

Verification: frozen standard rehearsal, 64 cold-install combinations,
entry chunk budgets, packed CLI and eight-framework browser checks.
The same-head frozen continuation after a temporary esbuild metadata 404
passed without rebuilding, repacking or changing the 94 frozen inputs.
Source commit: a177a45de4094e536b775ca2f4103982998b412a

The unanchored output/ ignore rule excluded these two new files from public staging. Both files are byte-identical to the frozen release source. Verified no other existing public-safe source files were omitted and pnpm build:core passes. Fixes the TS2307 failure in Public CI run 34335942345 without changing release tarballs.
Source commit: a177a45de4094e536b775ca2f4103982998b412a

Project the root regression specs and Vitest aliases required by the generated public gate suite.
Native Word references remain the semantic oracle. Word accept/reject saves can rewrite package-wide theme, font defaults, and compatibility metadata, so compare source mode line topology and source style stability instead of unrelated cross-file heights.

Source commit: 0a4c5778a2599769c4b6d746ec142f5627c9dbaa
Source commit: 06197c4d4475051c967241edb6c342f875303cb7
Source commit: 48fc36b7dec53e24a1a0c86d6d9e0d70b72bd975
Use the documented presentation.workerUrl fallback when the asset manifest is intentionally unavailable. Frozen 3.0.3 artifacts remain unchanged.
Keep the capability asset pack aligned with the renderer build when wasm-opt is unavailable.
@wybaby168
wybaby168 merged commit fb65b21 into main Sep 9, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant