2 hours ago
scalar

Release 2026-09-29

Releases

@scalar/helpers@0.16.0

Minor Changes

  • #10390: Add unescapeJsonPointerSegment to unescape JSON Pointer segments without decoding literal percent sequences. Preserve the existing URI-decoding behavior of unescapeJsonPointer.

Patch Changes

  • #10385: feat: add UTM parameters identifying the integration to the "Powered by Scalar" link

@scalar/openapi-to-markdown@1.4.0

Minor Changes

  • #10394: Add opt-in linked schema rendering with caller-supplied model URLs for bounded operation, model, and webhook pages. Keep default expansion unchanged, retain reference siblings and inline schemas, and omit generated examples in linked mode.

@scalar/docusaurus@0.8.45

Patch Changes

  • #10375: Raise muted text, code-string blue and the deprecated schema row to the 4.5:1 text contrast minimum across the shipped themes

    An accessibility audit turned up text that is legible in the default theme but not in several of the presets, which pair the default greys and blues with an off-white page background. Nine presets and four integration themes get a hue-preserving nudge:

    • Light --scalar-color-2 now clears 4.5:1 on both the page background and the grey card background in every preset. That covers alternate, bluePlanet, mars and saturn, which paired the default grey with an off-white page, and custom-theme-starter, deepSpace, elysiajs, fastify, kepler and purple, which copied the default grey and were left behind when the default moved.
    • Light --scalar-color-blue, which colours code strings, now clears 4.5:1 on the grey example background in alternate, bluePlanet, deepSpace, elysiajs, fastify, kepler and moon, and in the Docusaurus, NestJS, Next.js and SvelteKit themes.
    • Dark --scalar-color-blue now clears 4.5:1 in purple and saturn, and in the Hono and Docusaurus dark themes.
    • Deprecated schema rows no longer fade their contents to 75% opacity, which had dropped their muted text to 3.0:1. The diagonal stripes, the strikethrough on the property name and the Deprecated badge still mark the row.
    • The AsyncAPI send and receive pills blend their label further toward the body text colour, so they read against the tinted fill in every preset but laserwave.
    • --scalar-focus-color sits further from the accent so a keyboard focus ring clears 3:1 on --scalar-background-3 as well, which some presets use for the selected sidebar item.

    laserwave still misses in light mode, where it reuses its dark accents unchanged; bringing it up is a redesign of the preset rather than a nudge.

  • #10373: fix(api-reference): correct selected state, focus ring, target size and reflow of reference controls

    • Client library tabs no longer announce a featured tab as selected while a client picked from "More" is active
    • The response card "Copy example value" button shows a keyboard focus ring again
    • The schema tree toggle keeps its 24px hit box in narrow layouts
    • The schema property copy-link button gets a 24px hit box without changing its layout
    • Heading copy-link buttons no longer widen the page in narrow layouts

    Rename the always-present layout container class and CSS container name from narrow-references-container to references-container.

@scalar/hono-api-reference@0.12.7

Patch Changes

  • #10375: Raise muted text, code-string blue and the deprecated schema row to the 4.5:1 text contrast minimum across the shipped themes

    An accessibility audit turned up text that is legible in the default theme but not in several of the presets, which pair the default greys and blues with an off-white page background. Nine presets and four integration themes get a hue-preserving nudge:

    • Light --scalar-color-2 now clears 4.5:1 on both the page background and the grey card background in every preset. That covers alternate, bluePlanet, mars and saturn, which paired the default grey with an off-white page, and custom-theme-starter, deepSpace, elysiajs, fastify, kepler and purple, which copied the default grey and were left behind when the default moved.
    • Light --scalar-color-blue, which colours code strings, now clears 4.5:1 on the grey example background in alternate, bluePlanet, deepSpace, elysiajs, fastify, kepler and moon, and in the Docusaurus, NestJS, Next.js and SvelteKit themes.
    • Dark --scalar-color-blue now clears 4.5:1 in purple and saturn, and in the Hono and Docusaurus dark themes.
    • Deprecated schema rows no longer fade their contents to 75% opacity, which had dropped their muted text to 3.0:1. The diagonal stripes, the strikethrough on the property name and the Deprecated badge still mark the row.
    • The AsyncAPI send and receive pills blend their label further toward the body text colour, so they read against the tinted fill in every preset but laserwave.
    • --scalar-focus-color sits further from the accent so a keyboard focus ring clears 3:1 on --scalar-background-3 as well, which some presets use for the selected sidebar item.

    laserwave still misses in light mode, where it reuses its dark accents unchanged; bringing it up is a redesign of the preset rather than a nudge.

@scalar/nestjs-api-reference@1.2.24

Patch Changes

  • #10375: Raise muted text, code-string blue and the deprecated schema row to the 4.5:1 text contrast minimum across the shipped themes

    An accessibility audit turned up text that is legible in the default theme but not in several of the presets, which pair the default greys and blues with an off-white page background. Nine presets and four integration themes get a hue-preserving nudge:

    • Light --scalar-color-2 now clears 4.5:1 on both the page background and the grey card background in every preset. That covers alternate, bluePlanet, mars and saturn, which paired the default grey with an off-white page, and custom-theme-starter, deepSpace, elysiajs, fastify, kepler and purple, which copied the default grey and were left behind when the default moved.
    • Light --scalar-color-blue, which colours code strings, now clears 4.5:1 on the grey example background in alternate, bluePlanet, deepSpace, elysiajs, fastify, kepler and moon, and in the Docusaurus, NestJS, Next.js and SvelteKit themes.
    • Dark --scalar-color-blue now clears 4.5:1 in purple and saturn, and in the Hono and Docusaurus dark themes.
    • Deprecated schema rows no longer fade their contents to 75% opacity, which had dropped their muted text to 3.0:1. The diagonal stripes, the strikethrough on the property name and the Deprecated badge still mark the row.
    • The AsyncAPI send and receive pills blend their label further toward the body text colour, so they read against the tinted fill in every preset but laserwave.
    • --scalar-focus-color sits further from the accent so a keyboard focus ring clears 3:1 on --scalar-background-3 as well, which some presets use for the selected sidebar item.

    laserwave still misses in light mode, where it reuses its dark accents unchanged; bringing it up is a redesign of the preset rather than a nudge.

@scalar/nextjs-api-reference@0.12.5

Patch Changes

  • #10375: Raise muted text, code-string blue and the deprecated schema row to the 4.5:1 text contrast minimum across the shipped themes

    An accessibility audit turned up text that is legible in the default theme but not in several of the presets, which pair the default greys and blues with an off-white page background. Nine presets and four integration themes get a hue-preserving nudge:

    • Light --scalar-color-2 now clears 4.5:1 on both the page background and the grey card background in every preset. That covers alternate, bluePlanet, mars and saturn, which paired the default grey with an off-white page, and custom-theme-starter, deepSpace, elysiajs, fastify, kepler and purple, which copied the default grey and were left behind when the default moved.
    • Light --scalar-color-blue, which colours code strings, now clears 4.5:1 on the grey example background in alternate, bluePlanet, deepSpace, elysiajs, fastify, kepler and moon, and in the Docusaurus, NestJS, Next.js and SvelteKit themes.
    • Dark --scalar-color-blue now clears 4.5:1 in purple and saturn, and in the Hono and Docusaurus dark themes.
    • Deprecated schema rows no longer fade their contents to 75% opacity, which had dropped their muted text to 3.0:1. The diagonal stripes, the strikethrough on the property name and the Deprecated badge still mark the row.
    • The AsyncAPI send and receive pills blend their label further toward the body text colour, so they read against the tinted fill in every preset but laserwave.
    • --scalar-focus-color sits further from the accent so a keyboard focus ring clears 3:1 on --scalar-background-3 as well, which some presets use for the selected sidebar item.

    laserwave still misses in light mode, where it reuses its dark accents unchanged; bringing it up is a redesign of the preset rather than a nudge.

@scalar/sveltekit@0.3.24

Patch Changes

  • #10375: Raise muted text, code-string blue and the deprecated schema row to the 4.5:1 text contrast minimum across the shipped themes

    An accessibility audit turned up text that is legible in the default theme but not in several of the presets, which pair the default greys and blues with an off-white page background. Nine presets and four integration themes get a hue-preserving nudge:

    • Light --scalar-color-2 now clears 4.5:1 on both the page background and the grey card background in every preset. That covers alternate, bluePlanet, mars and saturn, which paired the default grey with an off-white page, and custom-theme-starter, deepSpace, elysiajs, fastify, kepler and purple, which copied the default grey and were left behind when the default moved.
    • Light --scalar-color-blue, which colours code strings, now clears 4.5:1 on the grey example background in alternate, bluePlanet, deepSpace, elysiajs, fastify, kepler and moon, and in the Docusaurus, NestJS, Next.js and SvelteKit themes.
    • Dark --scalar-color-blue now clears 4.5:1 in purple and saturn, and in the Hono and Docusaurus dark themes.
    • Deprecated schema rows no longer fade their contents to 75% opacity, which had dropped their muted text to 3.0:1. The diagonal stripes, the strikethrough on the property name and the Deprecated badge still mark the row.
    • The AsyncAPI send and receive pills blend their label further toward the body text colour, so they read against the tinted fill in every preset but laserwave.
    • --scalar-focus-color sits further from the accent so a keyboard focus ring clears 3:1 on --scalar-background-3 as well, which some presets use for the selected sidebar item.

    laserwave still misses in light mode, where it reuses its dark accents unchanged; bringing it up is a redesign of the preset rather than a nudge.

@scalar/api-client@3.21.2

Patch Changes

  • #10369: fix: correct the semantics of the authentication card and of nested schema lists

    Two findings from an accessibility audit, both programmatic only with no change to how anything renders:

    • The reference's Authentication card announced its title as a level two heading, which put a card of controls in the document outline next to the real tag and operation headings. The title is now plain text and the card is exposed as a named group instead, so it stays findable without claiming to open a passage of the page. Collapsible sections in the API client are unaffected and keep their headings.
    • A schema panel whose root is a composition, a primitive or an array wraps a single nameless row that carries the real property list, so assistive tech announced "list with 1 item" before the list the reader wanted. That wrapper is now presentational and only the real property list is announced.
  • #10371: fix: tidy the client modal header at narrow widths

    The method label and copy button now stay inside the address bar at every width instead of moving to a floating row of their own, and the send button spans the full width once it wraps. Below the lg breakpoint, where the address bar fills the header row and its method chip reaches the panel edge, the sidebar toggle moves onto the backdrop as a circle that mirrors the close button in the opposite corner. At wider widths it keeps its original place inside the panel.

  • #10374: fix: resolve accessibility audit findings in the client modal

    • Auth fields (Bearer Token, Username, API key and OAuth inputs) now expose their visible label as the accessible name in both the masked and unmasked state
    • Request and response filter tabs no longer carry aria-controls, so screen readers announce each tab once when arrowing through them
    • Opening the modal from a "Test Request" button now moves focus to the close button first
  • #10369: fix: address a batch of screen reader and keyboard accessibility findings

    Corrects programmatic semantics only, with no change to how anything renders: the current sidebar item now reports aria-current, the single content type readout leaves the tab order, collapsible sections no longer announce their title twice, the password toggle reports its state through aria-pressed, the two document download buttons get distinct accessible names, response status tabs announce what each code means, and the client picker and its search field get accessible names.

  • #10361: Preserve configured OAuth redirect URLs when changing credentials or clearing tokens, and hide refresh controls when no refresh token is available.

    Previously saved redirect overrides, including empty strings and prefilled page origins, remain unchanged because they cannot be distinguished from intentional user choices. Users affected by the earlier bug must enter the intended redirect URL again.

    The public @scalar/workspace-store OAuth secrets types now expose x-scalar-secret-redirect-uri as optional (string | undefined). Consumers must handle an absent override separately from an explicit empty string.

  • #10363: Avoid duplicate available OAuth2 entries when scopes are selected, and apply configured default scopes when selecting an available scheme.

@scalar/api-reference@1.72.2

Patch Changes

  • #10369: fix: correct the semantics of the authentication card and of nested schema lists

    Two findings from an accessibility audit, both programmatic only with no change to how anything renders:

    • The reference's Authentication card announced its title as a level two heading, which put a card of controls in the document outline next to the real tag and operation headings. The title is now plain text and the card is exposed as a named group instead, so it stays findable without claiming to open a passage of the page. Collapsible sections in the API client are unaffected and keep their headings.
    • A schema panel whose root is a composition, a primitive or an array wraps a single nameless row that carries the real property list, so assistive tech announced "list with 1 item" before the list the reader wanted. That wrapper is now presentational and only the real property list is announced.
  • #10364: Prevent repeated introduction fragments when reopening API descriptions that start with a Markdown heading.

  • #10375: Raise muted text, code-string blue and the deprecated schema row to the 4.5:1 text contrast minimum across the shipped themes

    An accessibility audit turned up text that is legible in the default theme but not in several of the presets, which pair the default greys and blues with an off-white page background. Nine presets and four integration themes get a hue-preserving nudge:

    • Light --scalar-color-2 now clears 4.5:1 on both the page background and the grey card background in every preset. That covers alternate, bluePlanet, mars and saturn, which paired the default grey with an off-white page, and custom-theme-starter, deepSpace, elysiajs, fastify, kepler and purple, which copied the default grey and were left behind when the default moved.
    • Light --scalar-color-blue, which colours code strings, now clears 4.5:1 on the grey example background in alternate, bluePlanet, deepSpace, elysiajs, fastify, kepler and moon, and in the Docusaurus, NestJS, Next.js and SvelteKit themes.
    • Dark --scalar-color-blue now clears 4.5:1 in purple and saturn, and in the Hono and Docusaurus dark themes.
    • Deprecated schema rows no longer fade their contents to 75% opacity, which had dropped their muted text to 3.0:1. The diagonal stripes, the strikethrough on the property name and the Deprecated badge still mark the row.
    • The AsyncAPI send and receive pills blend their label further toward the body text colour, so they read against the tinted fill in every preset but laserwave.
    • --scalar-focus-color sits further from the accent so a keyboard focus ring clears 3:1 on --scalar-background-3 as well, which some presets use for the selected sidebar item.

    laserwave still misses in light mode, where it reuses its dark accents unchanged; bringing it up is a redesign of the preset rather than a nudge.

  • #10385: feat: add UTM parameters identifying the integration to the "Powered by Scalar" link

  • #10375: fix: raise text and focus ring contrast flagged by an accessibility audit

    The default light blue is a touch deeper so code strings and read-only labels meet 4.5:1, the required label darkens in light mode, keyboard focus rings now draw from a new --scalar-focus-color token that meets 3:1 against hovered and selected surfaces, and the schema union pipe, Default, Example and Pattern labels use the regular muted text colour.

  • #10373: fix(api-reference): correct selected state, focus ring, target size and reflow of reference controls

    • Client library tabs no longer announce a featured tab as selected while a client picked from "More" is active
    • The response card "Copy example value" button shows a keyboard focus ring again
    • The schema tree toggle keeps its 24px hit box in narrow layouts
    • The schema property copy-link button gets a 24px hit box without changing its layout
    • Heading copy-link buttons no longer widen the page in narrow layouts

    Rename the always-present layout container class and CSS container name from narrow-references-container to references-container.

  • #10369: fix: address a batch of screen reader and keyboard accessibility findings

    Corrects programmatic semantics only, with no change to how anything renders: the current sidebar item now reports aria-current, the single content type readout leaves the tab order, collapsible sections no longer announce their title twice, the password toggle reports its state through aria-pressed, the two document download buttons get distinct accessible names, response status tabs announce what each code means, and the client picker and its search field get accessible names.

  • #10379: fix: remove the duplicate copy button from the example response header

    The response card carried its own copy button in the tab strip, added in 2023 when the card had no other copy affordance. The code block inside it later gained a built-in copy button of its own, which left every response card showing two buttons that copy the same content. Only the code block's button remains.

  • #10388: Prevent Safari from outlining an entire operation section after sidebar navigation while preserving focus on the navigation target.

@scalar/blocks@0.4.1

Patch Changes

  • #10392: Give code samples, including virtualized large examples, a named keyboard-scrollable region and keep copy buttons descriptively named before hover or focus.

  • #10369: fix: address a batch of screen reader and keyboard accessibility findings

    Corrects programmatic semantics only, with no change to how anything renders: the current sidebar item now reports aria-current, the single content type readout leaves the tab order, collapsible sections no longer announce their title twice, the password toggle reports its state through aria-pressed, the two document download buttons get distinct accessible names, response status tabs announce what each code means, and the client picker and its search field get accessible names.

@scalar/components@0.30.4

Patch Changes

  • #10392: Give code samples, including virtualized large examples, a named keyboard-scrollable region and keep copy buttons descriptively named before hover or focus.

  • #10385: feat: add UTM parameters identifying the integration to the "Powered by Scalar" link

  • #10369: fix: address a batch of screen reader and keyboard accessibility findings

    Corrects programmatic semantics only, with no change to how anything renders: the current sidebar item now reports aria-current, the single content type readout leaves the tab order, collapsible sections no longer announce their title twice, the password toggle reports its state through aria-pressed, the two document download buttons get distinct accessible names, response status tabs announce what each code means, and the client picker and its search field get accessible names.

@scalar/sidebar@0.11.9

Patch Changes

  • #10369: fix: address a batch of screen reader and keyboard accessibility findings

    Corrects programmatic semantics only, with no change to how anything renders: the current sidebar item now reports aria-current, the single content type readout leaves the tab order, collapsible sections no longer announce their title twice, the password toggle reports its state through aria-pressed, the two document download buttons get distinct accessible names, response status tabs announce what each code means, and the client picker and its search field get accessible names.

@scalar/themes@0.18.1

Patch Changes

  • #10375: Raise muted text, code-string blue and the deprecated schema row to the 4.5:1 text contrast minimum across the shipped themes

    An accessibility audit turned up text that is legible in the default theme but not in several of the presets, which pair the default greys and blues with an off-white page background. Nine presets and four integration themes get a hue-preserving nudge:

    • Light --scalar-color-2 now clears 4.5:1 on both the page background and the grey card background in every preset. That covers alternate, bluePlanet, mars and saturn, which paired the default grey with an off-white page, and custom-theme-starter, deepSpace, elysiajs, fastify, kepler and purple, which copied the default grey and were left behind when the default moved.
    • Light --scalar-color-blue, which colours code strings, now clears 4.5:1 on the grey example background in alternate, bluePlanet, deepSpace, elysiajs, fastify, kepler and moon, and in the Docusaurus, NestJS, Next.js and SvelteKit themes.
    • Dark --scalar-color-blue now clears 4.5:1 in purple and saturn, and in the Hono and Docusaurus dark themes.
    • Deprecated schema rows no longer fade their contents to 75% opacity, which had dropped their muted text to 3.0:1. The diagonal stripes, the strikethrough on the property name and the Deprecated badge still mark the row.
    • The AsyncAPI send and receive pills blend their label further toward the body text colour, so they read against the tinted fill in every preset but laserwave.
    • --scalar-focus-color sits further from the accent so a keyboard focus ring clears 3:1 on --scalar-background-3 as well, which some presets use for the selected sidebar item.

    laserwave still misses in light mode, where it reuses its dark accents unchanged; bringing it up is a redesign of the preset rather than a nudge.

  • #10375: fix: raise text and focus ring contrast flagged by an accessibility audit

    The default light blue is a touch deeper so code strings and read-only labels meet 4.5:1, the required label darkens in light mode, keyboard focus rings now draw from a new --scalar-focus-color token that meets 3:1 against hovered and selected surfaces, and the schema union pipe, Default, Example and Pattern labels use the regular muted text colour.

@scalar/types@0.22.2

Patch Changes

  • #10369: fix: address a batch of screen reader and keyboard accessibility findings

    Corrects programmatic semantics only, with no change to how anything renders: the current sidebar item now reports aria-current, the single content type readout leaves the tab order, collapsible sections no longer announce their title twice, the password toggle reports its state through aria-pressed, the two document download buttons get distinct accessible names, response status tabs announce what each code means, and the client picker and its search field get accessible names.

@scalar/workspace-store@0.67.1

Patch Changes

  • #10383: Populate object parameter values from property examples when no parameter or root schema value is provided.

  • #10361: Preserve configured OAuth redirect URLs when changing credentials or clearing tokens, and hide refresh controls when no refresh token is available.

    Previously saved redirect overrides, including empty strings and prefilled page origins, remain unchanged because they cannot be distinguished from intentional user choices. Users affected by the earlier bug must enter the intended redirect URL again.

    The public @scalar/workspace-store OAuth secrets types now expose x-scalar-secret-redirect-uri as optional (string | undefined). Consumers must handle an absent override separately from an explicit empty string.

@scalar/astro@0.4.24

@scalar/express-api-reference@0.10.24

@scalar/fastify-api-reference@1.72.2

@scalar/nuxt@0.6.75

@scalar/starlight@0.2.9

@scalar/agent-chat@0.12.38

@scalar/api-client-react@2.0.52

@scalar/api-reference-react@0.9.75

@scalar/asyncapi-upgrader@0.1.14

@scalar/asyncapi-validator@0.1.7

@scalar/client-side-rendering@0.4.6

@scalar/core@0.5.38

@scalar/import@0.5.28

@scalar/json-magic@0.15.3

@scalar/json-schema-validator@0.1.7

@scalar/localization@0.2.4

@scalar/mock-server@0.17.1

@scalar/nextjs-openapi@0.3.45

@scalar/oas-utils@0.20.7

@scalar/object-utils@1.3.28

@scalar/openapi-parser@0.29.8

@scalar/openapi-upgrader@0.4.1

@scalar/openapi-validator@0.1.7

@scalar/postman-to-openapi@0.7.24

@scalar/pre-post-request-scripts@0.4.50

@scalar/release-notes@0.2.4

@scalar/schemas@0.12.2

@scalar/server-side-rendering@0.1.54

@scalar/snippetz@0.10.3

@scalar/use-hooks@0.4.16

@scalar/void-server@2.5.14

@scalarapi/docker-api-reference@0.6.9

Bundled API Reference

  • @scalar/api-reference@1.72.2

@scalar/aspire@0.11.27

Bundled API Reference

  • @scalar/api-reference@1.72.2

@scalar/aspnetcore@2.17.11

Bundled API Reference

  • @scalar/api-reference@1.72.2

@scalar/aws-lambda@0.2.15

Bundled API Reference

  • @scalar/api-reference@1.72.2

@scalar/azure-functions@0.2.21

Bundled API Reference

  • @scalar/api-reference@1.72.2

@scalar/java-integration@0.6.75

Bundled API Reference

  • @scalar/api-reference@1.72.2

scalar_api_reference@0.2.9

Bundled API Reference

  • @scalar/api-reference@1.72.2

@scalar/mock-server-docker@0.2.65

scalar-app@1.1.35

3 hours ago
next.js

v16.3.7

[!NOTE] This release is backporting bug fixes. It does not include all pending features/changes on canary.

Core Changes

  • turbo-tasks-backend: fix strongly consistent read hanging on a canceled task (#98931)

Credits

Huge thanks to @lukesandberg for helping!

3 hours ago
taro

chore(release): publish 4.3.0

📦 特性(feat)

🐛 修复(fix)

Summary by CodeRabbit

  • 版本更新
    • Taro 及其相关工具、插件、组件和平台适配包已从 4.2.2-beta.5 更新至 4.3.0。
3 hours ago
univer

🕶️ Release v1.0.3

Univer 1.0.3

New features

  • Pivot tables (Pro): Copy pivot tables together with worksheets.
  • Shape hyperlinks (Pro): Show hyperlink popups when hovering over shape text in Sheets, Docs, Slides, and Boards.
  • Notifications: Support custom CSS classes per notification.
  • Extensions: Expose the destination worksheet name to copy-sheet interceptors.

Improvements and fixes

  • Formulas: Improve conditional aggregate performance with array criteria.
  • Cell editing: Double-click a cell to select its editable content.
  • Sheets: Fix automatic row heights after paste, filter range updates, and formula editor focus and help positioning.
  • Docs: Preserve selections in long documents and improve paste controls.
  • Emoji picker: Support searching by localized names and keywords.
  • Networking: Fix interceptor disposal and completion handling for merged requests.
  • Cross-document formulas (Pro): Fix stale results after referenced sheets become available.
  • Embedded editors (Pro): Fix missing tools, scrolling behavior, and shape tool activation.
  • Boards (Pro): Avoid redundant undo entries for unchanged text styles.
  • Docs (Pro): Fix mobile editor dependencies and hide empty table menus.
  • Charts (Pro): Fix referenced data-source selection and activation.
  • Collaboration (Pro): Respect the offline-caching setting from startup.

Breaking changes and upgrading

Custom Pro chart integrations require updates:

  • Chart reference APIs moved from @univerjs-pro/engine-chart to @univerjs-pro/chart-embed. Register UniverChartEmbedPlugin when using referenced charts.
  • ChartReferencedDataSourceEditor was removed. Custom editors should use ReferencedDataSelector from @univerjs-pro/embed-unit-ui with host-specific controls.
  • ChartResourceRepository is now abstract and requires host-specific data-source decoding.
  • Saved chart resources no longer include a version field. Existing supported resources remain readable, but older SDK versions may reject newly saved resources.

Keep interdependent Univer and Univer Pro packages aligned at 1.0.3, including applications that read and write shared chart resources.

Full changelog: v1.0.2…v1.0.3

4 hours ago
editor

v4.3.1

4.3.1 (2026-09-29)

Bug Fixes

  • core: keep bold that runs past italic intact on export (13eb781), closes #735 #986
  • core: keep the formatting around links and inline HTML on import (2d89958)
  • deps: serialize markdown with mdast-util-to-markdown 2.1.3 (ad2b04c), closes #xA
5 hours ago
hono

v4.13.11

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: hono/serve-static and the adapters built on it (hono/bun, hono/deno, hono/cloudflare-workers, @hono/bun, @hono/deno, @hono/cloudflare-workers). Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in @hono/node-server v2.1.3.

6 hours ago
fast-xml-parser

v5.11.2

What's Changed

New Contributors

Full Changelog: https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.11.1...v5.11.2

7 hours ago
swc
8 hours ago
react-redux

v9.4.0-alpha.2

This alpha release fixes two bugs in useSignalSelector: stale values rendered in the gap between a dispatch and the store notification, and tracking proxies leaking out of values a selector held onto from an earlier run. It also cuts the cost of spreading or enumerating objects inside selectors, and adds test coverage for using useSignalSelector with RTK Query's hooks. The stock Provider and useSelector are unchanged.

npm install react-redux@alpha

This is still an alpha. Please try it out and give us feedback! The alpha.0 notes cover what useSignalSelector is and how to opt in.

Changelog

Renders between a dispatch and the store notification now see current state

Once a useSignalSelector hook had its full dependency graph built, its getSnapshot returned a cached result that only updated when the store notified subscribers. Normally that happens synchronously inside dispatch(), but there are several cases where React renders the component before that notification arrives:

  • RTK's configureStore includes the autoBatchEnhancer, which delays notifications for batched actions (like RTK Query's pending and fulfilled actions) until the next animation frame
  • a parent re-renders for its own reasons in that gap
  • a useSelector component and a useSignalSelector component in the same tree render in the same pass
  • an action dispatched from a layout effect, which React picks up in its post-commit snapshot check

In all of these, useSignalSelector could render the previous value, and a useSelector and a useSignalSelector reading the same field could disagree within one render.

getSnapshot now checks whether store.getState() has moved since the cached result was computed. If it has, it re-runs the selector against the current state. useSignalSelector also now passes React a new getSnapshot when the selector reference changes, matching useSelector, so React's post-commit consistency check runs in the same cases it does for useSelector.

Values held from an earlier selector run are unwrapped

The render-time fallback path above runs the selector against raw state, and we assumed its result could never contain tracking proxies. That assumption was wrong. A selector that holds onto a value from an earlier tracked run, via a closure or a ref, can return a proxy from that earlier run.

RTK Query does exactly this: its query hooks keep the last result so they can show the previous data while a new arg loads. With a stable selectFromResult, the component received a proxy of the previous data during that window instead of the raw state object. Results from that path are now unwrapped the same way as the main path.

Spreading and enumerating objects is cheaper

Spreading an object in a selector ({ ...state.user }), or using Object.keys/values/entries, Object.assign, JSON.stringify, or for...in, previously recorded a dependency on the object's key list plus one dependency per field. Reading every field of an immutably-updated object is equivalent to depending on the object's identity, so a full enumeration of a nested object now collapses into a single identity dependency on that object.

Partial enumerations still track precisely: Object.keys(obj).length, or reading only some fields after enumerating, keeps field-level dependencies. The root state object and arrays are excluded, since their tracking already works differently.

This mostly shows up with RTK Query, whose selectors spread each cache entry. In our RTK Query benchmark, useSignalSelector time per dispatch dropped by about 20-30%.

RTK Query compatibility

We've added an interop test suite that runs RTK Query's hooks on top of useSignalSelector, via a custom createApi:

import {
  buildCreateApi,
  coreModule,
  reactHooksModule,
} from '@reduxjs/toolkit/query/react'
import { useDispatch, useSignalSelector, useStore } from 'react-redux'

export const createApi = buildCreateApi(
  coreModule(),
  reactHooksModule({
    hooks: { useDispatch, useSelector: useSignalSelector, useStore },
  }),
)

The tests cover query phases, selectFromResult, mutations and invalidation, skip, arg changes, and render counts, which match useSelector exactly. The types line up too: useSignalSelector satisfies the hooks.useSelector option type with no casts.

Writing those tests turned up two bugs on the RTK side, both fixed in RTK 2.13.0. useQueryState passed a new inline selector to useSelector on every render, which forced useSignalSelector to re-run the full tracked selector on every render. It also let isSuccess flip on unrelated re-renders during a refetch after an error. With 2.13.0, useSignalSelector selector runs per dispatch in our RTK Query benchmark showed a ~30% drop vs alpha.2. We recommend 2.13.0+ if you try this setup.

Performance

10 s per scenario, this release vs 9.3.0, Chrome, react-dom/profiling, RTK 2.12.

Scenario Script Blocked Notes
tree-view -54% -77%
many-components-many-slices -31% -54%
realistic-slice-count -27% -80%
deeptree-nested-hooks -24% -61%
entity-list -22% -45%
rapid-dispatch -21% -65%
multi-selector-component -20% -82%
price-ticker -19% -58% stock drops frames
selective-update -15% -64%
forms -12% -80%
entity-list-array -9% -62%
many-components-same-slice +3% +96% flat; work moved into dispatch
rtkq-separate-queries +4% +21%
one-component-many-slices +28% +32% 20,000 top-level keys
derived-selectors +53% +144%

Render counts match 9.3.0 within noise, except where stock drops frames under load.

rtkq-separate-queries moved from +9% in alpha.1 to +4%. derived-selectors and one-component-many-slices remain the two scenarios where useSignalSelector is slower than useSelector. Their numbers vary a lot between runs, and before/after runs of this release's changes showed no measurable difference for either.

What's Changed

  • Add prototype signals+path-tracking implementation by @markerikson in #2318

Full Changelog: https://github.com/reduxjs/react-redux/compare/v9.4.0-alpha.1...v9.4.0-alpha.2

8 hours ago
redux-toolkit

v2.13.0

This feature release updates our build tooling to TSDown and PNPM, adds official TypeScript 7 support, and includes a long list of bugfixes across RTK Query, createAsyncThunk, createEntityAdapter, and combineSlices.

Changelog

Build Tooling Updates

We've fully modernizing modernized our build tooling across all of the Redux repos. That included switching from Yarn to PNPM, ESLint to Oxlint, Prettier to Oxfmt, and TSUp to TSDown.

The part that matters for users is that we now build the package with TSDown instead of tsup. The package layout, exports definitions, and exported APIs are all unchanged from 2.12. We've checked the new build with attw, and verified that CJS and ESM entry points load in both dev and prod builds, and that the legacy-esm artifacts still target ES2017. The contents of the bundles do look a bit different (smaller CJS artifacts, slightly different helper output in the legacy-esm files). If you see any behavior differences that look build-related, please file an issue!

This is also our first release published via the updated PNPM-based workflow, still using NPM Trusted Publishing. We've also added pkg.pr.new previews for every commit, so you can try out a PR build before it's released.

Docs Updates

We've shipped a new combined Redux libraries docs site! The core docs site at https://redux.js.org now contains the docs for all of our libraries: Redux core and usage guides, Redux Toolkit, React Redux, and Reselect. The prior standalone docs sites for RTK, R-R, and Reselect now redirect to their respective sections of the combined docs. We've also done a major cleanup pass on the docs, deduplicating pages that had similarities (like the Next.js or RTK2 migration pages that lived in both the core and RTK docs), and updating outdated content (modernizing example code snippets, deleting dead links, and making RTK and hooks the default patterns shown). The RTK content now lives at https://redux.js.org/toolkit/ .

TypeScript 7 Support

TS 7.0 (the native Go port) is now out! We fixed the remaining type errors in RTK when checked by TS 7.0 and 7.1, and TS 7.0 is now part of our CI test matrix.

Per our TS support policy of matching DefinitelyTyped's support window, we've also updated our support matrix to TS 5.6+. As always, RTK may still work with earlier versions, but we no longer test against them.

RTK Query Fixes

useQueryState (and thus useQuery) was passing a new inline selector to useSelector on every render, and also reading the store directly during render. The selector is now memoized, and the direct store read is gone. This also fixes a bug where isSuccess could flip from false to true on an unrelated re-render while a query was refetching after an error. isSuccess now correctly stays false in that case.

data now reflects cache updates made via updateQueryData while a refetch is in flight, instead of showing the previous result.

Polling now reads the current cache state when each poll fires, rather than the state at the time the poll was scheduled. This means skipPollingIfUnfocused respects focus loss that happens after scheduling, and polls stop if their cache entry was removed.

We fixed a race where a duplicate query request rejected by the thunk condition could cause queued tag invalidations to run too early and be lost, leaving stale data in the cache.

Tags with falsy ids like 0 now invalidate and clean up correctly.

Lazy query hooks now re-subscribe correctly when effects restart while the hook state is preserved, such as with Fast Refresh or <Activity>.

Infinite queries no longer trigger onQueryStarted when fetching past the end of the list, and the infinite query hook result type now includes the page error flags.

fetchBaseQuery only treats a URL as absolute if it starts with a scheme.

We also fixed an error when rehydrating state for an endpoint name that has no definition.

Other Fixes

createAsyncThunk no longer swallows aborts that happen before the pending action is dispatched, and now correctly sets rejectedWithValue when rejectWithValue is called with a falsy payload.

createEntityAdapter's setAll now keeps the last item when given duplicate IDs, matching setMany. The sorted adapter's updateMany now merges multiple updates for the same ID before applying them.

combineSlices now keeps its internal state proxy cache per instance, so multiple combined reducers no longer interfere with each other.

The immutability check middleware now handles circular references in state.

The dynamic middleware now caches its composed middleware chains when the list of middleware hasn't changed.

What's Changed

Full Changelog: https://github.com/reduxjs/redux-toolkit/compare/v2.12.0...v2.13.0