From e02d636442f28fb12b232a438c3768bca563bb6f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 1 Jul 2026 10:12:27 +0000 Subject: [PATCH 1/3] chore(deps): bump solid-js from 1.8.17 to 1.9.13 Bumps [solid-js](https://github.com/solidjs/solid) from 1.8.17 to 1.9.13. - [Release notes](https://github.com/solidjs/solid/releases) - [Changelog](https://github.com/solidjs/solid/blob/main/CHANGELOG.md) - [Commits](https://github.com/solidjs/solid/compare/v1.8.17...v1.9.13) --- updated-dependencies: - dependency-name: solid-js dependency-version: 1.9.13 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- package.json | 2 +- pnpm-lock.yaml | 46 +++++++++++++++++++++++----------------------- 2 files changed, 24 insertions(+), 24 deletions(-) diff --git a/package.json b/package.json index 1834a1c..2543503 100644 --- a/package.json +++ b/package.json @@ -45,7 +45,7 @@ "remark-supersub": "^1.0.0", "sharp": "0.32.6", "shiki": "^3.22.0", - "solid-js": "^1.8.17", + "solid-js": "^1.9.13", "tailwindcss": "^4.3.1", "twoslash": "^0.3.8", "unified": "^11.0.5", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index af300f6..3acea0b 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -19,7 +19,7 @@ importers: version: 3.7.3 '@astrojs/solid-js': specifier: ^6.0.1 - version: 6.0.1(@types/node@22.19.21)(jiti@2.7.0)(lightningcss@1.32.0)(solid-js@1.8.17)(tsx@4.21.0)(yaml@2.4.2) + version: 6.0.1(@types/node@22.19.21)(jiti@2.7.0)(lightningcss@1.32.0)(solid-js@1.9.13)(tsx@4.21.0)(yaml@2.4.2) '@fontsource-variable/brygada-1918': specifier: ^5.2.8 version: 5.2.8 @@ -78,8 +78,8 @@ importers: specifier: ^3.22.0 version: 3.22.0 solid-js: - specifier: ^1.8.17 - version: 1.8.17 + specifier: ^1.9.13 + version: 1.9.13 tailwindcss: specifier: ^4.3.1 version: 4.3.1 @@ -4781,14 +4781,14 @@ packages: engines: {node: '>=10'} hasBin: true - seroval-plugins@1.5.2: - resolution: {integrity: sha512-qpY0Cl+fKYFn4GOf3cMiq6l72CpuVaawb6ILjubOQ+diJ54LfOWaSSPsaswN8DRPIPW4Yq+tE1k5aKd7ILyaFg==} + seroval-plugins@1.5.4: + resolution: {integrity: sha512-S0xQPhUTefAhNvNWFg0c1J8qJArHt5KdtJ/cFAofo06KD1MVSeFWyl4iiu+ApDIuw0WhjpOfCdgConOfAnLgkw==} engines: {node: '>=10'} peerDependencies: seroval: ^1.0 - seroval@1.5.2: - resolution: {integrity: sha512-xcRN39BdsnO9Tf+VzsE7b3JyTJASItIV1FVFewJKCFcW4s4haIKS3e6vj8PGB9qBwC7tnuOywQMdv5N4qkzi7Q==} + seroval@1.5.4: + resolution: {integrity: sha512-46uFvgrXTVxZcUorgSSRZ4y+ieqLLQRMlG4bnCZKW3qI6BZm7Rg4ntMW4p1mILEEBZWrFlcpp0AyIIlM6jD9iw==} engines: {node: '>=10'} set-function-length@1.2.2: @@ -4881,8 +4881,8 @@ packages: resolution: {integrity: sha512-HLpt+uLy/pxB+bum/9DzAgiKS8CX1EvbWxI4zlmgGCExImLdiad2iCwXT5Z4c9c3Eq8rP2318mPW2c+QbtjK8A==} engines: {node: '>= 10.0.0', npm: '>= 3.0.0'} - solid-js@1.8.17: - resolution: {integrity: sha512-E0FkUgv9sG/gEBWkHr/2XkBluHb1fkrHywUgA6o6XolPDCJ4g1HaLmQufcBBhiF36ee40q+HpG/vCZu7fLpI3Q==} + solid-js@1.9.13: + resolution: {integrity: sha512-6hJeJMOcEX8ktqjpDoJZEmld3ijvcvWBDtiXBm7f4332SiFN66QeAQI1REQshvyUoISsSeJ4PHDauKYbwao9JQ==} solid-refresh@0.6.3: resolution: {integrity: sha512-F3aPsX6hVw9ttm5LYlth8Q15x6MlI/J3Dn+o3EQyRTtTxidepSTwAYdozt01/YA+7ObcciagGEyXIopGZzQtbA==} @@ -5694,11 +5694,11 @@ snapshots: stream-replace-string: 2.0.0 zod: 4.3.6 - '@astrojs/solid-js@6.0.1(@types/node@22.19.21)(jiti@2.7.0)(lightningcss@1.32.0)(solid-js@1.8.17)(tsx@4.21.0)(yaml@2.4.2)': + '@astrojs/solid-js@6.0.1(@types/node@22.19.21)(jiti@2.7.0)(lightningcss@1.32.0)(solid-js@1.9.13)(tsx@4.21.0)(yaml@2.4.2)': dependencies: - solid-js: 1.8.17 + solid-js: 1.9.13 vite: 7.3.6(@types/node@22.19.21)(jiti@2.7.0)(lightningcss@1.32.0)(tsx@4.21.0)(yaml@2.4.2) - vite-plugin-solid: 2.11.10(solid-js@1.8.17)(vite@7.3.6(@types/node@22.19.21)(jiti@2.7.0)(lightningcss@1.32.0)(tsx@4.21.0)(yaml@2.4.2)) + vite-plugin-solid: 2.11.10(solid-js@1.9.13)(vite@7.3.6(@types/node@22.19.21)(jiti@2.7.0)(lightningcss@1.32.0)(tsx@4.21.0)(yaml@2.4.2)) transitivePeerDependencies: - '@testing-library/jest-dom' - '@types/node' @@ -10932,11 +10932,11 @@ snapshots: semver@7.7.4: {} - seroval-plugins@1.5.2(seroval@1.5.2): + seroval-plugins@1.5.4(seroval@1.5.4): dependencies: - seroval: 1.5.2 + seroval: 1.5.4 - seroval@1.5.2: {} + seroval@1.5.4: {} set-function-length@1.2.2: dependencies: @@ -11082,18 +11082,18 @@ snapshots: ip-address: 10.1.0 smart-buffer: 4.2.0 - solid-js@1.8.17: + solid-js@1.9.13: dependencies: csstype: 3.2.3 - seroval: 1.5.2 - seroval-plugins: 1.5.2(seroval@1.5.2) + seroval: 1.5.4 + seroval-plugins: 1.5.4(seroval@1.5.4) - solid-refresh@0.6.3(solid-js@1.8.17): + solid-refresh@0.6.3(solid-js@1.9.13): dependencies: '@babel/generator': 7.24.6 '@babel/helper-module-imports': 7.24.6 '@babel/types': 7.29.0 - solid-js: 1.8.17 + solid-js: 1.9.13 source-map-js@1.2.1: {} @@ -11642,14 +11642,14 @@ snapshots: '@types/unist': 3.0.3 vfile-message: 4.0.3 - vite-plugin-solid@2.11.10(solid-js@1.8.17)(vite@7.3.6(@types/node@22.19.21)(jiti@2.7.0)(lightningcss@1.32.0)(tsx@4.21.0)(yaml@2.4.2)): + vite-plugin-solid@2.11.10(solid-js@1.9.13)(vite@7.3.6(@types/node@22.19.21)(jiti@2.7.0)(lightningcss@1.32.0)(tsx@4.21.0)(yaml@2.4.2)): dependencies: '@babel/core': 7.24.6 '@types/babel__core': 7.20.5 babel-preset-solid: 1.8.17(@babel/core@7.24.6) merge-anything: 5.1.7 - solid-js: 1.8.17 - solid-refresh: 0.6.3(solid-js@1.8.17) + solid-js: 1.9.13 + solid-refresh: 0.6.3(solid-js@1.9.13) vite: 7.3.6(@types/node@22.19.21)(jiti@2.7.0)(lightningcss@1.32.0)(tsx@4.21.0)(yaml@2.4.2) vitefu: 1.1.1(vite@7.3.6(@types/node@22.19.21)(jiti@2.7.0)(lightningcss@1.32.0)(tsx@4.21.0)(yaml@2.4.2)) transitivePeerDependencies: From 656efdd3d9573318e2a34a51cf2eb53fdceaaec3 Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 2 Jul 2026 10:15:32 +0000 Subject: [PATCH 2/3] fix: type Blockquote against HTMLQuoteElement; skip Vercel deploy for Dependabot The solid-js 1.9 bump tightened JSX.BlockquoteHTMLAttributes typing, which requires HTMLQuoteElement (blockquote's real DOM interface, with its 'cite' attribute) rather than the generic HTMLElement used here. Under exactOptionalPropertyTypes this became a type error on the spread ref. Also carries the shared CI fix: Dependabot PRs run from the same repo (not a fork), so the deploy step's fork-only guard let it through even though GitHub withholds repository secrets from dependabot-actor runs, causing deploy.mjs to fail with 'missing --token'. Treat dependabot[bot] runs the same as fork PRs. Co-Authored-By: Claude Sonnet 5 --- .github/workflows/ci.yml | 6 +++--- src/lib/prose/Blockquote.tsx | 4 +++- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index ee676d3..4072a65 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -96,7 +96,7 @@ jobs: - name: Deploy Preview to Vercel if: ${{ github.event_name != 'push' && github.event_name != 'workflow_dispatch' && - (!github.event.pull_request.head.repo.fork || + ((!github.event.pull_request.head.repo.fork && github.actor != 'dependabot[bot]') || (github.event_name == 'pull_request_target' && contains(github.event.pull_request.labels.*.name, 'trusted'))) }} run: node .github/scripts/deploy.mjs --token=${{ secrets.VERCEL_TOKEN }} @@ -104,7 +104,7 @@ jobs: - name: Create GitHub Preview Deployment if: ${{ github.event_name != 'push' && github.event_name != 'workflow_dispatch' && - (!github.event.pull_request.head.repo.fork || + ((!github.event.pull_request.head.repo.fork && github.actor != 'dependabot[bot]') || (github.event_name == 'pull_request_target' && contains(github.event.pull_request.labels.*.name, 'trusted'))) }} uses: chrnorm/deployment-action@500aa6a23c81ffa1acf71072aee3cfa2cc2e556a @@ -132,7 +132,7 @@ jobs: needs: build-and-deploy runs-on: ubuntu-latest if: - ${{ !github.event.pull_request.head.repo.fork || + ${{ (!github.event.pull_request.head.repo.fork && github.actor != 'dependabot[bot]') || (github.event_name == 'pull_request_target' && contains(github.event.pull_request.labels.*.name, 'trusted')) }} steps: diff --git a/src/lib/prose/Blockquote.tsx b/src/lib/prose/Blockquote.tsx index 545a800..1581997 100644 --- a/src/lib/prose/Blockquote.tsx +++ b/src/lib/prose/Blockquote.tsx @@ -2,7 +2,9 @@ import type { JSX } from "solid-js"; import styles from "./Blockquote.module.css"; -export function Blockquote(props: JSX.BlockquoteHTMLAttributes) { +export function Blockquote( + props: JSX.BlockquoteHTMLAttributes, +) { return (
Date: Thu, 2 Jul 2026 10:39:09 +0000 Subject: [PATCH 3/3] fix: type Blockquote against JSX.HTMLAttributes, not BlockquoteHTMLAttributes The previous attempt typed props as JSX.BlockquoteHTMLAttributes, but solid-js's BlockquoteHTMLAttributes hardcodes its ref type independent of the generic parameter, so the mismatch just flipped direction (now the JSX intrinsic's inferred ref didn't satisfy our declared props). Blockquote doesn't use the cite attribute, so follow the same pattern already used by the sibling Pre component (HTMLAttributes matching the intrinsic element type) instead of the element-specific attributes interface. Co-Authored-By: Claude Sonnet 5 --- src/lib/prose/Blockquote.tsx | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/src/lib/prose/Blockquote.tsx b/src/lib/prose/Blockquote.tsx index 1581997..f85b942 100644 --- a/src/lib/prose/Blockquote.tsx +++ b/src/lib/prose/Blockquote.tsx @@ -2,9 +2,7 @@ import type { JSX } from "solid-js"; import styles from "./Blockquote.module.css"; -export function Blockquote( - props: JSX.BlockquoteHTMLAttributes, -) { +export function Blockquote(props: JSX.HTMLAttributes) { return (