Skip to content

Dependabot: Add npm entry so security update PRs can be rebased#79076

Merged
manzoorwanijk merged 2 commits into
trunkfrom
fix/dependabot-npm-security-updates
Jun 12, 2026
Merged

Dependabot: Add npm entry so security update PRs can be rebased#79076
manzoorwanijk merged 2 commits into
trunkfrom
fix/dependabot-npm-security-updates

Conversation

@manzoorwanijk

Copy link
Copy Markdown
Member

What?

Adds an npm entry to .github/dependabot.yml so that Dependabot security updates for npm packages have an owning config block. Version updates for npm remain disabled via open-pull-requests-limit: 0.

Why?

Dependabot security updates run from the repository's security settings, independently of dependabot.yml, and will open PRs for npm vulnerabilities even though we only configure the github-actions ecosystem today. Because there is no npm entry, those PRs have no owning config, so @dependabot rebase and @dependabot recreate both fail with a misleading message:

The dependabot.yml entry that created this PR has been deleted so this PR can't be rebased. Please close the PR so Dependabot can create a new one with the current dependabot.yml.

This leaves the only recourse as closing the PR and waiting for the next scan — see the loop on #75964. Adding an npm ecosystem entry gives these security PRs a config owner so rebase/recreate work, and lets us apply consistent labels and a cooldown.

We deliberately do not want to enable npm version updates across this monorepo, which would flood the repo with hundreds of PRs. Setting open-pull-requests-limit: 0 disables version updates while leaving security updates unaffected (the limit does not apply to them).

How?

  • Add a package-ecosystem: 'npm' entry rooted at /.
  • Set open-pull-requests-limit: 0 to keep version updates off while security updates continue.
  • Apply a 7-day cooldown and the dependencies / [Type] Build Tooling labels, mirroring the existing github-actions configuration.

Testing Instructions

  1. Confirm the YAML is valid and parses (e.g. npx js-yaml .github/dependabot.yml or any YAML linter).
  2. After merge, the next Dependabot npm security PR should accept @dependabot rebase / @dependabot recreate instead of reporting a missing config entry, and should carry the configured labels.
  3. Verify no new npm version-update PRs are opened (only security updates).

Use of AI Tools

This PR was drafted with the assistance of Claude Code. All changes were reviewed by the author.

@manzoorwanijk
manzoorwanijk requested a review from desrosj as a code owner June 10, 2026 08:11
Dependabot security updates run independently of dependabot.yml and open
npm PRs even though only the github-actions ecosystem is configured.
Without an npm entry those PRs have no owning config, so rebase/recreate
fail. Add an npm entry with open-pull-requests-limit: 0 to give security
updates a config owner while keeping noisy version updates disabled.
@github-actions

github-actions Bot commented Jun 10, 2026

Copy link
Copy Markdown

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message.

Co-authored-by: manzoorwanijk <manzoorwanijk@git.wordpress.org>
Co-authored-by: aduth <aduth@git.wordpress.org>
Co-authored-by: desrosj <desrosj@git.wordpress.org>

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

@manzoorwanijk
manzoorwanijk force-pushed the fix/dependabot-npm-security-updates branch from 9969a6d to 5bfa5f1 Compare June 10, 2026 08:11
@manzoorwanijk manzoorwanijk added the [Type] Security Related to security concerns or efforts label Jun 10, 2026
@manzoorwanijk manzoorwanijk self-assigned this Jun 10, 2026
@github-actions

github-actions Bot commented Jun 10, 2026

Copy link
Copy Markdown

Flaky tests detected in 295ac56.
Some tests passed with failed attempts. The failures may not be related to this commit but are still reported for visibility. See the documentation for more information.

🔍 Workflow run URL: https://github.com/WordPress/gutenberg/actions/runs/27321031938
📝 Reported issues:

@aduth aduth left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd be curious if folks like @desrosj would be interested to keep and continue maintaining the dependency updates for non-security updates? There's some engagement here on our part.

Comment thread .github/dependabot.yml
Comment on lines +30 to +37
# disables noisy npm *version* updates across the monorepo;
# *security* updates ignore this limit and keep running.
open-pull-requests-limit: 0
cooldown:
default-days: 7
labels:
- 'dependencies'
- '[Type] Build Tooling'

@aduth aduth Jun 10, 2026

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm trying to understand this configuration in relation to the behavior you describe in the original comment. If security updates don't consider dependabot.yml, then what's the point of adding cooldown and labels here? Will security updates consider those aspects of the configuration (which for labeling would be great to avoid a little bit of maintainer tedium)? And would we want a cooldown for security updates, or want those immediately?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch! When a matching ecosystem entry exists, security PRs honor labels (on the default branch) but not cooldown ("only available for version updates"). open-pull-requests-limit is also ignored by security updates.

So labels is the point - it removes the manual labeling tedium you linked. cooldown is inert here (and we wouldn't want to delay security fixes anyway). I'll update it.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for checking and sharing the resource 👍 Glad that the labels will be applying.

@aduth

aduth commented Jun 11, 2026

Copy link
Copy Markdown
Member

Could we add the configuration without disabling the version updates, and would that help with the root issue of Dependabot's inability to rebase, and the application of a "[Type]" label that our CI enforces?

I'm not as sure about disabling the version updates. Looking through historical pull requests with the "dependencies" label, @desrosj seems quite engaged with these.

@desrosj desrosj left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not as sure about disabling the version updates. Looking through historical pull requests with the "dependencies" label, @desrosj seems quite engaged with these.

All of the npm-related Dependabot PRs that I have interacted with so far have been related to vulnerability reports. To my knowledge, no non-security PRs are being created by the bot.

Because there is no npm entry, those PRs have no owning config, so @dependabot rebase and @dependabot recreate both fail with a misleading message

I'm not certain that the lack of a configuration is the reason that Dependabot is unable to perform any desired actions on a given PR. My interpretation was that the dependabot.yml file had been modified after the pull request had been opened. The file is not updated often, but there have been 2 changes so far this year. If my understanding is correct, any PR created prior to May 22, 2026 will not be able to rebase/recreate.

It looks like all of the open Dependabot PRs were created prior to this date. To see if this could be confirmed, I looked at #77655. It was created in April 2026, and was last rebased successfully on May 12, 2026. I just tried to rebase again with @dependabot rebase and received the message about the Dependabot entry being deleted.

All this said, it appears accurate that there is no way to override the default labels without defining an entry in the configuration file. I think this is probably fine to merge to ensure those are properly assigned when the PR is created. However, I do lean towards not explicitly calling out that the entry configures security updates and instead note that npm updates in general are being disabled. I don't feel strongly about that, though.

@manzoorwanijk

Copy link
Copy Markdown
Member Author

We can evaluate it after merge.

@manzoorwanijk
manzoorwanijk merged commit 29f4f14 into trunk Jun 12, 2026
43 of 45 checks passed
@manzoorwanijk
manzoorwanijk deleted the fix/dependabot-npm-security-updates branch June 12, 2026 16:45
@github-actions github-actions Bot added this to the Gutenberg 23.5 milestone Jun 12, 2026
@manzoorwanijk

Copy link
Copy Markdown
Member Author

Dependenabot is a useless createion - it still doesn't seem to work - #75964 (comment)

@desrosj

desrosj commented Jun 13, 2026

Copy link
Copy Markdown
Member

@manzoorwanijk were you expecting it to retroactively work for old PRs? That was not my expectation, so curious what you had in mind.

I agree that it's annoying when any change to the configuration file results in the PR being unable to be updated with the bot, but let's see how this goes as new PRs are created.

Also, if the expectations are more clear and the full team does a better job keeping up with these, we won't end up with this many old PRs, which will minimize this scenario.

@manzoorwanijk

Copy link
Copy Markdown
Member Author

@manzoorwanijk were you expecting it to retroactively work for old PRs? That was not my expectation, so curious what you had in mind.

my expectation was that @dependabot recreate comment would work for PRs created before this change.

I agree that it's annoying when any change to the configuration file results in the PR being unable to be updated with the bot, but let's see how this goes as new PRs are created.

Also, if the expectations are more clear and the full team does a better job keeping up with these, we won't end up with this many old PRs, which will minimize this scenario.

I think it may work if we enable the version updates by setting the pull request number to greater than 0.

pento pushed a commit to WordPress/wordpress-develop that referenced this pull request Jul 14, 2026
This updates the pinned commit hash of the Gutenberg repository from `98a796c8780c480ef7bcfe03c42302d9564d785c` (version `23.4.0`) to `b5574edc8a952b2f1e528693761a97b1b3b580eb` (version `23.5.0`).

A full list of changes included in this commit can be found on GitHub: https://github.com/WordPress/gutenberg/compare/v23.4.0..v23.5.0.

The following commits are included:

- Site Editor: Fix admin color scheme bleeding through the mobile content scrollbar gutter (WordPress/gutenberg#79056)
- Build: Add GUTENBERG_CHECK_INSTALLED_DEPS env var to opt out of installed-deps check (WordPress/gutenberg#79068)
- Media Editor: Keep the modal skeleton pinned in the editor flow (WordPress/gutenberg#79070)
- Editor: Hide cmd palette shortcut in document bar when admin bar is shown (WordPress/gutenberg#79060)
- Math format: seed LaTeX input from the current selection (WordPress/gutenberg#79052)
- Omnibar: Rename experiment to match iteration issue (WordPress/gutenberg#79074)
- Theme: Add Figma scopes to element size tokens (WordPress/gutenberg#79032)
- Admin bar in editor experiment: show site icon instead of dashicon if set (WordPress/gutenberg#79049)
- Math format: Simplify the onClick handler and use canonical selected-text capture (WordPress/gutenberg#79081)
- Style Engine: Export public TypeScript types (WordPress/gutenberg#79079)
- Image: Fix pasted images stretching when dimensions are preserved (WordPress/gutenberg#79067)
- Update `@ariakit/react` to 0.4.29 (WordPress/gutenberg#79055)
- Navigation: Use block context to determine whether Page List is nested in Submenu (WordPress/gutenberg#79048)
- Fix code editor cursor jump on remote RTC updates (WordPress/gutenberg#79005)
- Fix: Custom HTML block preview keeps expanding when iframe uses height:100vh (WordPress/gutenberg#78677)
- Image block: don't show crop icon while image is uploading (WordPress/gutenberg#79103)
- Media Editor Modal: Add a loading and simple error state (WordPress/gutenberg#79101)
- Add React 19 as an experimental flag (WordPress/gutenberg#79077)
- Try: Remove Tab (Tab list item) block  (WordPress/gutenberg#77439)
- Navigation block: Fix responsive style states for typography settings (WordPress/gutenberg#79072)
- Popover: add open/close motion and fix close re-anchor (WordPress/gutenberg#78885)
- Remove unused build:profile-types and component-usage-stats scripts (WordPress/gutenberg#79113)
- RTC: Allow disabling collaboration by post type (WordPress/gutenberg#78984)
- Omnipresent Toolbar: increase top padding in sidebar nav title (WordPress/gutenberg#79083)
- Add support for aspect ratio and related controls in viewport states (WordPress/gutenberg#78795)
- Fix responsive element styles front end output (WordPress/gutenberg#79135)
- BaseControl: add text-wrap: pretty (WordPress/gutenberg#79112)
- wp-build: Return null from getPackageInfo on resolve miss instead of throwing (WordPress/gutenberg#78715)
- Global styles revisions: replace active text with badge (WordPress/gutenberg#79137)
- Editor: Disable saving while a non-post entity is being saved (WordPress/gutenberg#79069)
- Add xl border radius token for page shell surfaces. (WordPress/gutenberg#78913)
- Add corner radius presets to ThemeProvider (WordPress/gutenberg#78816)
- theme: rename `bg`/`fg` design token groups to `background`/`foreground` (WordPress/gutenberg#79098)
- Theme: Enforce sRGB seed-color input contract for ThemeProvider (WordPress/gutenberg#79148)
- Theme: Rename `--wpds-color-stroke-focus-brand` token to `--wpds-color-stroke-focus` (WordPress/gutenberg#79125)
- refactor: Move 'glob' dependency to appropriate workspaces (WordPress/gutenberg#79145)
- Add lock-unlock route as a workspace and update dependencies (WordPress/gutenberg#79138)
- Dependabot: Add npm entry so security update PRs can be rebased (WordPress/gutenberg#79076)
- refactor: rename '@wordpress/lock-unlock' to '@wordpress/routes-lock-unlock' across the codebase (WordPress/gutenberg#79163)
- Panel: Recommend CollapsibleCard for use outside the block inspector (WordPress/gutenberg#78863)
- Editor: Migrate FlatTermSelector to UI Stack component (WordPress/gutenberg#78659)
- design-system-mcp: Remove Storybook dependency in TypeScript types (WordPress/gutenberg#79132)
- Bump rollup from 4.55.1 to 4.59.0 (WordPress/gutenberg#75964)
- Media modal: small tweak to gutters (WordPress/gutenberg#79168)
- Icon Block: Add flip and rotate transformation controls (WordPress/gutenberg#77017)
- Media Editor: Magnify the crop to fill the canvas (WordPress/gutenberg#79044)
- Update capitalisation and spelling within the welcome tour (WordPress/gutenberg#53028)
- Feature: Need to add “Show More” / “Show Less” toggle in Note. (WordPress/gutenberg#77446)
- Correct behaviour of flex child fixed width and introduce max width option (WordPress/gutenberg#79073)
- Eslint: move deps from root into tools/eslint and packages/eslint-plugin (WordPress/gutenberg#79110)
- Gallery: Hide Navigation button type when lightbox editing is disabled (WordPress/gutenberg#79147)
- Add more React internals polyfills (WordPress/gutenberg#79142)
- [DataViewsPicker]: `DataViewsPicker.BulkActionToolbar` now renders only the bulk-selection info and action buttons (WordPress/gutenberg#79180)
- Block Editor: Fix potential crash from 'useBlockToolbarPopoverProps' (WordPress/gutenberg#79178)
- Tabs: Simplify layout and prune redundant block supports (WordPress/gutenberg#77646)
- e2e: Retry transient theme activation failures in pages spec (WordPress/gutenberg#79171)
- Revisions screen with picker-activity layout (WordPress/gutenberg#77333)
- chore: remove glob from root pkg json (WordPress/gutenberg#79183)
- Core Data: Don't use 'useQuerySelect' in 'useEntityRecord(s)' hooks (WordPress/gutenberg#76198)
- Revisions: Ignore empty `[]/{}` meta values in the Meta diff panel (WordPress/gutenberg#79185)
- UI Field.Description: add `text-wrap: pretty` (WordPress/gutenberg#79143)
- Blocks: Migrate Markdown converter from showdown to marked (WordPress/gutenberg#77953)
- Bump shivammathur/setup-php (WordPress/gutenberg#79193)
- Icons block: insert an icon by default (WordPress/gutenberg#79111)
- Theme: Add tests for ThemeProvider and useThemeProviderStyles (WordPress/gutenberg#79126)
- Icon block: Move flip controls to toolbar group. (WordPress/gutenberg#79192)
- Packages: Fix the published dependency surface of npm packages (WordPress/gutenberg#79095)
- Block Library: Remove unused Babel optimization plugin (WordPress/gutenberg#79162)
- Automated Testing: Use static value for IS_GUTENBERG_PLUGIN env setup (WordPress/gutenberg#79201)
- Scripts: Avoid tests getting published to npm (WordPress/gutenberg#79204)
- Theme: Add disabled variants for brand and error interactive color tokens (WordPress/gutenberg#79124)
- Fix: State styles – clear `background-image` when hover sets a solid `background-color` (WordPress/gutenberg#78992)
- Media editor: Snap crop handles to source pixels (WordPress/gutenberg#79139)
- Image block: remove duplicate data-wp-bind--srcset in the lightbox overlay (WordPress/gutenberg#79202)
- Template Part: Remove restriction on tabs / inspector fills (WordPress/gutenberg#79181)
- Editor: Guard PostViewLink against post types without a labels object (WordPress/gutenberg#79160)
- Media editor modal: Fix keyboard resizing for locked aspect-ratio crops (WordPress/gutenberg#79207)
- wp-build: Resolve @wordpress/build from __dirname in resolve-miss test (WordPress/gutenberg#79208)
- Theme: forward ThemeProvider cornerRadius preset to :root for root providers (WordPress/gutenberg#79153)
- Refactor Prettier configuration and update dependencies (WordPress/gutenberg#79219)
- chore: Add missing root devDependencies for WordPress packages (WordPress/gutenberg#79221)
- Refactor: Update  npm-package-json-lint configuration (WordPress/gutenberg#79223)
- Components: Complete WPDS token migration for remaining borders (WordPress/gutenberg#79003)
- Plugin: Bump minimum required WordPress version to 6.9 (WordPress/gutenberg#79196)
- Autocomplete: Add Group and GroupLabel primitives (WordPress/gutenberg#78901)
- Pullquote: Migrate to text-align block support (WordPress/gutenberg#79225)
- Style Book: Fix crash when previewing variations for blocks without examples (WordPress/gutenberg#79131)
- Theme: Add stroke-surface tokens for the caution tone (WordPress/gutenberg#79198)
- Icon block: Default to core/info via block.json instead of an insert-time effect (WordPress/gutenberg#79212)
- Backport changelog and package version updates from wp/latest (WordPress/gutenberg#79234)
- V2 Site Editor: Fix template edit routes (WordPress/gutenberg#79230)
- Grid: Prepare `@wordpress/grid` for npm publishing as experimental 0.1.0 (WordPress/gutenberg#79071)
- File Block: Replace on-mount downloadButtonText effect with a default variation (WordPress/gutenberg#79236)
- Components, DataViews: Adopt --wpds-dimension-size-* tokens (WordPress/gutenberg#79093)
- Refactor: move stylelint config and deps to tools/stylelint workspace (WordPress/gutenberg#79226)
- Revert "Components: Complete WPDS token migration for remaining borders (WordPress/gutenberg#79003)" (WordPress/gutenberg#79243)
- Edit Post: Refactor and cleanup InitPatternModal component (WordPress/gutenberg#79190)
- Widget Primitives: extract into `@wordpress/widget-primitives` (WordPress/gutenberg#79134)
- chore: remove @wordpress/vips dependency from root (WordPress/gutenberg#79249)
- design-system-mcp: Improve README overview and setup instructions (WordPress/gutenberg#79238)
- Components: Re-land WPDS border token migration with Emotion-safe comments (WordPress/gutenberg#79244)
- Theme: Provide design-system token defaults without a runtime `<ThemeProvider>` (WordPress/gutenberg#78664)
- List View block support: Hide list tab when allowedBlocks is empty, with no children (WordPress/gutenberg#78932)
- Handle WP.org SVN missing tag warnings (WordPress/gutenberg#79257)
- CI: Run PHP unit tests on PHP 8.4 and 8.5 (WordPress/gutenberg#79260)
- mark @types/react as an optional peer dependency (WordPress/gutenberg#79272)
- Block bindings : add support to list-item (WordPress/gutenberg#78947)
- document widget-modules endpoint experiment gate (WordPress/gutenberg#79264)
- Storybook: Upgrade Storybook to 10.4 (WordPress/gutenberg#77382)
- Core Data: Cleanup edits matching persisted record on undo/redo (WordPress/gutenberg#77100)
- Notes: Simplify 'Show more/less' collapse logic (WordPress/gutenberg#79261)
- File Block: Combine audio/video/image to file transforms (WordPress/gutenberg#79242)
- Button: Use font weight token (WordPress/gutenberg#79278)
- Avoid dirtying related navigation entities during passive render (WordPress/gutenberg#79000)
- Theme: Skip serializing `data-wpds-root-provider="false"` on non-root providers (WordPress/gutenberg#79253)
- Patterns: Migrate modals to @wordpress/ui components and fix rename input width (WordPress/gutenberg#79233)
- ESLint, UI, Components: Mark `Tooltip` from `@wordpress/ui` as recommended (WordPress/gutenberg#78693)
- Theme: differentiate `--wpds-color-fg-interactive-{brand,error}-active` vs resting state tokens (WordPress/gutenberg#79151)
- Document AlertDialog as ConfirmDialog successor in Storybook (WordPress/gutenberg#79293)
- Elements: Accept both md5 and sequential `wp-elements-*` class names in tests (WordPress/gutenberg#79300)
- Cover block: add media editor modal (WordPress/gutenberg#79258)
- Blocks: Use positional sprintf placeholders in avatar, comment, and search renderers (WordPress/gutenberg#79290)
- DataForm: Fix panel field control overflow clipping and remove button overrides (WordPress/gutenberg#79275)
- Experiment: Editor Inspector with DataForm - remove revision panel and add link (WordPress/gutenberg#79195)
- Upload Media: Add error taxonomy, localized messages, and dev diagnostics (WordPress/gutenberg#74917)
- Block Fields: Fix crash resolving pattern overrides bindings (WordPress/gutenberg#79092)
- Media: Rename HEIC companion metadata key to source_image (WordPress/gutenberg#79307)
- DataForm: Align `label-side` gap of `panel` layout with `regular` layout (WordPress/gutenberg#79311)
- Theme: Add design tokens maintainer's guide documentation (WordPress/gutenberg#79157)
- Remove ObliviousHarmony from CODEOWNERS for packages/env (WordPress/gutenberg#79308)
- Widget Dashboard: extract into `@wordpress/widget-dashboard` (WordPress/gutenberg#79268)
- Sync editor settings in layout effect (fixes autosave e2e) (WordPress/gutenberg#78799)
- Remove Lighthouse patch (WordPress/gutenberg#79319)
- Editor: Remove orphaned editor-help component leftovers (WordPress/gutenberg#79324)
- Plugins API: Fix the plugin 'render' property validation (WordPress/gutenberg#79315)
- Components: Improve Menu unit tests performance by removing sleeps (WordPress/gutenberg#79295)
- UI Button: Fix loading state in forced colors (WordPress/gutenberg#78820)
- Media Editor: Fix crop canvas pinch zoom (WordPress/gutenberg#79332)
- Docs: Fix typos in README files (WordPress/gutenberg#79331)
- Media Editor: Align crop settle state with transition completion (WordPress/gutenberg#79339)
- KSES: Allow SVG-specific presentation attributes in safe_style_css (WordPress/gutenberg#79172)
- Widget Primitives: decouple discovery from a hardcoded endpoint (WordPress/gutenberg#79322)
- Site Editor: Save hub button styling while saving (WordPress/gutenberg#79287)
- Migrate compose package to TypeScript  (WordPress/gutenberg#70618)
- Vips: bump wasm-vips to 0.0.18 for high-bit-depth AVIF decoding (WordPress/gutenberg#79179)
- Experimental: Expand Editor Inspector: Use DataForm experiment to templates (WordPress/gutenberg#76934)
- Site Editor: Change 'Identity' nav item position (WordPress/gutenberg#79292)
- Block Bindings: Preserve nested lists when binding List Item content (WordPress/gutenberg#79346)
- Site Editor: Handle `aria-current` natively in `SidebarNavigationItem` (WordPress/gutenberg#79305)
- RichText: Fix duplicated format wrappers when typing inside an applied format (WordPress/gutenberg#79091)
- Vips: inline WASM with compact UTF-8 binary encoding instead of base64 (WordPress/gutenberg#79188)
- View Config API and REST Endpoint: make them core ready (WordPress/gutenberg#79347)
- Validation: Add a published-dependency audit script (WordPress/gutenberg#79094)
- Reconcile feature-detection docblock with implemented checks (WordPress/gutenberg#75851)
- fix typo in block-filter.md file (WordPress/gutenberg#79367)
- Search block: Add opt-in support for the semantic <search> element (WordPress/gutenberg#78485)
- Dashboard: revert H1 to "Dashboard" and fix heading hierarchy (WordPress/gutenberg#79251)
- Components: Make ResizableBox children prop optional (WordPress/gutenberg#79370)
- Grid overlays: Use canvas iframe window for viewport visibility detection (WordPress/gutenberg#79255)
- Widget Primitives: make contract and story docs host-agnostic (WordPress/gutenberg#79358)
- Use symbols for style states to avoid property clashes (WordPress/gutenberg#79210)
- Ignore markdown linting for backport-changelog MD files (WordPress/gutenberg#79392)
- Add media control icons (WordPress/gutenberg#78987)
- Icons: Use snake_case `file_path` key in icon registry (WordPress/gutenberg#79100)
- Editor: Use `Stack` for post summary (WordPress/gutenberg#79397)
- Theme: Run stylelint plugin tests via the Node API (WordPress/gutenberg#79199)
- Command Palette: Exclude assets from block editor settings endpoint (WordPress/gutenberg#79396)
- List item: Remove orphaned convertToListItems util (WordPress/gutenberg#79400)
- Video: Apply `inert` directly instead of wrapping in `Disabled` (WordPress/gutenberg#79371)
- Site Editor: Introduce isHidden prop for SidebarNavigationItem (WordPress/gutenberg#79352)
- Post Editor: Use the correct directory for recent preload improvements (WordPress/gutenberg#79359)
- Configure Flakiness.io reporting for e2e tests (WordPress/gutenberg#79173)
- View Config: request a subset of properties with the `_fields` parameter (WordPress/gutenberg#79355)
- Storybook: Reorganize design system introduction for first touch-point usefulness (WordPress/gutenberg#79360)
- Block editor: Convert utility modules to TypeScript (WordPress/gutenberg#79323)
- devops: configure report auto-upload for flakiness.io dashboard (WordPress/gutenberg#79411)
- UI: Simplify focus ring styles (WordPress/gutenberg#78823)
- TextControl: Hard deprecate 40px default size (WordPress/gutenberg#79386)
- devops: upload unit test results to flakiness dashboard (WordPress/gutenberg#79414)
- Clarify Core-specific steps when bumping support (WordPress/gutenberg#79416)
- Pattern editing: show root block identity when editing pattern sections (WordPress/gutenberg#79417)
- Patterns: Add a missing gap to 'Enable overrides' modal (WordPress/gutenberg#79421)
- Audio: Apply `inert` directly instead of wrapping in `Disabled` (WordPress/gutenberg#79423)
- Experimental: Expand Editor Inspector: Use DataForm experiment to template parts (WordPress/gutenberg#79399)
- Base Styles: Add wpds-var Sass helper for design token fallbacks (WordPress/gutenberg#78698)
- Block Editor: Allow overriding `disableContentOnlyForTemplateParts` setting (WordPress/gutenberg#79191)
- Mark all controlled/mode block changes non-persistent (WordPress/gutenberg#79350)
- Revert "Base Styles: Add wpds-var Sass helper for design token fallbacks (WordPress/gutenberg#78698)" (WordPress/gutenberg#79429)
- Popover: Align transition state styles (WordPress/gutenberg#79410)
- DataForm panel layout: fix double-clicking a field row leaving the flyout stuck open (WordPress/gutenberg#79348)
- Classic Block: Port PHPUnit coverage for wp_declare_classic_block_necessary (WordPress/gutenberg#79434)
- Fields: Move author fields for templates and template parts (WordPress/gutenberg#79395)
- Theme: Drop `--wpds-dimension-base` from the public token surface (WordPress/gutenberg#79254)
- Merge shared stylelint disallowed-list in components (WordPress/gutenberg#79425)
- Edit Post: Refactor MetaBoxesSection to use data hooks (WordPress/gutenberg#79433)
- View config endpoint: bring back changes from core (WordPress/gutenberg#79438)
- devops: separate environments for jest date tests (WordPress/gutenberg#79453)
- UI: Disable instant overlay popup transitions (WordPress/gutenberg#79432)
- Components: Refactor withFallbackStyles from class to function component (WordPress/gutenberg#78837)
- Automated Testing: Globally shim Element#getClientRects (WordPress/gutenberg#79353)
- Theme: Promote ThemeProvider to stable API (WordPress/gutenberg#78958)
- Automated Testing: Add babel-plugin-transform-import-meta to emulate import.meta.dirname (WordPress/gutenberg#79362)
- E2E: Support WordPress installs served from a subdirectory (WordPress/gutenberg#79166)
- Custom HTML: Fix scrollbar after tab switch in modal (WordPress/gutenberg#78571)
- Theme: apply ThemeProvider styles inline (I2) (WordPress/gutenberg#78678)
- Add flex vertical alignment tool to block inspector layout panel (WordPress/gutenberg#79426)
- Block Supports: Relocate text and bg color controls to Typography and Background panels (WordPress/gutenberg#77279)
- Add e2e coverage for pattern wrapper block identity (WordPress/gutenberg#79462)
- Storybook: Include playground stories and MDX in CI smoke tests (WordPress/gutenberg#79454)
- BoxControl: respect a consumer-supplied placeholder via inputProps (WordPress/gutenberg#79466)
- Media Fields: Ensure the current post is always included in the initial options (WordPress/gutenberg#79467)
- Global Styles: Add textShadow style support (WordPress/gutenberg#73320)
- Media Fields: Avoid focus loss when detaching the current parent (WordPress/gutenberg#79468)
- CI: Disallow new dependencies in the root package.json (WordPress/gutenberg#78616)
- Experimental: Preserve editor panel visibility in the DataForm post summary (WordPress/gutenberg#79441)
- Tabs: Pre-stabilization API cleanup and refactoring (WordPress/gutenberg#79337)
- BoxControl: Hard deprecate 40px default size (WordPress/gutenberg#79419)
- Image Block: Remove chained entity record calls (WordPress/gutenberg#79469)
- UI: Use isomorphic layout effects (WordPress/gutenberg#79458)
- Components: add Emotion migration guardrails (WordPress/gutenberg#79442)
- devops: separate histories for different node.js versions (WordPress/gutenberg#79473)
- Components: migrate Divider to SCSS module (WordPress/gutenberg#79444)
- Block Library: unwrap Classic block migration notice experiment (WordPress/gutenberg#78165)
- Editor: Refactor AutosaveMonitor to a function component (WordPress/gutenberg#79043)
- Boot: run page `init` modules in `initSinglePage` (WordPress/gutenberg#79394)
- DataFormPostSummary: fix different `useSelect` returned values  (WordPress/gutenberg#79478)
- Icons: self declare color (WordPress/gutenberg#79320)
- Theme: Document ramp memoization contract (WordPress/gutenberg#79459)
- tools: Restrict layout effect imports in UI and theme (WordPress/gutenberg#79476)
- CI: Avoid full-history checkout for the root-dependencies check (WordPress/gutenberg#79489)
- Simplify playlist track state (WordPress/gutenberg#79448)
- prepend_to_selector: optimized with str_replace() (WordPress/gutenberg#76556)
- Components: migrate Surface to SCSS module (WordPress/gutenberg#79445)
- Docs: Add a widget anatomy doc and lighten the widget system doc (WordPress/gutenberg#79435)
- Media Editor: remove inline cropper (follow-up to WordPress/gutenberg#78653) (WordPress/gutenberg#78654)
- Grid: Add option to stretch columns with auto-fit for better layout flexibility (WordPress/gutenberg#79356)
- Guidelines: Use str_starts_with() in is_block_meta_key() (WordPress/gutenberg#79491)
- Color popover: move contrast warning notice to the bottom (WordPress/gutenberg#79512)
- BorderBoxControl: Hard deprecate 40px default size (WordPress/gutenberg#79420)
- Remove Classic Block conversion from BlockInvalidWarning (WordPress/gutenberg#79500)
- [RTC] Add granular collaboration control (WordPress/gutenberg#79184)
- FontSizePicker: Hard deprecate 40px default size (WordPress/gutenberg#79481)
- React 19: patch to support legacy inert attribute values (WordPress/gutenberg#79475)
- Icons: Add Storybook React Vite dev dependency (WordPress/gutenberg#79506)
- QueryControls: Complete __next40pxDefaultSize cleanup (WordPress/gutenberg#79485)
- Block editor: use core/registered-block in reducer tests (WordPress/gutenberg#79522)
- UI: Update @base-ui/react to 1.6.0 (WordPress/gutenberg#79408)
- Refactor: Replace strpos with str_starts_with for improved consistency (WordPress/gutenberg#79519)
- Block Library: Remove redundant parentheses around assignments (WordPress/gutenberg#79516)
- Tabs: Focus first tab when adding Tabs block (WordPress/gutenberg#79507)
- ui/IconButton: Restore default tooltip delay (WordPress/gutenberg#79505)
- FocalPointPicker: Complete __next40pxDefaultSize cleanup (WordPress/gutenberg#79487)
- Components: document CSS module class composition (WordPress/gutenberg#79490)
- BorderControl: Hard deprecate 40px default size (WordPress/gutenberg#79418)
- Components: migrate Truncate to SCSS module (WordPress/gutenberg#79446)
- Show the admin bar in the Post and Site Editor by default (WordPress/gutenberg#79197)
- SearchControl: Complete __next40pxDefaultSize cleanup (WordPress/gutenberg#79538)
- Stylelint: Enforce module class naming in UI packages (WordPress/gutenberg#79504)
- Components: Add missing descriptions for design system components (WordPress/gutenberg#79460)
- LetterSpacingControl: Hard deprecate 40px default size (WordPress/gutenberg#79533)
- Experiments: Move screen under Settings, drop top-level Gutenberg menu and Demo page (WordPress/gutenberg#79456)
- Tabs: Combine and cleanup toolbar controls (WordPress/gutenberg#79537)
- Tabs: Fix dirty editor state on mount caused by tab-list sync (WordPress/gutenberg#79540)
- RTC: fix undo / redo breakage when plug-in with metabox is loaded (WordPress/gutenberg#79510)
- Block Supports: Guard elements hover rendering against missing hover selector (WordPress/gutenberg#79511)
- Commands: add toggle for content-only pattern/template part editing (WordPress/gutenberg#78383)
- Integrate Resizable Editor with Device Preview and add Responsive editing (WordPress/gutenberg#75121)
- Pattern editing: use section block selector for pattern display identity (WordPress/gutenberg#79565)
- Commands: Suggest pattern editing toggle for selected patterns (WordPress/gutenberg#79566)
- Tabs: Select tab panel when caret moves into tab (WordPress/gutenberg#79558)
- Fix unsetting values in viewport states for grid and constrained layouts (WordPress/gutenberg#79520)
- Add layout and block spacing support to Latest Posts block (WordPress/gutenberg#77989)
- Widget inserter: more accurate widget previews (WordPress/gutenberg#79517)
- Tabs: Remove unnecessary callback memoization (WordPress/gutenberg#79567)
- Icons: Add PHP method(s) for rendering inline SVG icons from the registry (WordPress/gutenberg#78332)
- Tab List: Fix render inline formatting on frontend (WordPress/gutenberg#79554)
- Divider: Restore lower border specificity (WordPress/gutenberg#79534)
- Tabs: Remove redundant block selection from Add/Remove tab actions (WordPress/gutenberg#79571)
- Icons: Fix viewBox attribute casing assertion for older WP versions (WordPress/gutenberg#79576)
- Add icon state classes to Accordion block (WordPress/gutenberg#74257)
- Pattern editing: Fade block outside the edited pattern in List View (WordPress/gutenberg#73997)
- Experiments: move long intro to content (WordPress/gutenberg#79578)
- Updating image urls (WordPress/gutenberg#79529)
- `useTypingObserver`: capture the window reference for cleanup (WordPress/gutenberg#78772)
- Tabs: Fix rich text label comparation when syncing the list (WordPress/gutenberg#79582)
- Add `PluginPostStatusInfo` in DataForm post summary (WordPress/gutenberg#79586)
- theme: Protect design tokens CSS import (WordPress/gutenberg#79551)
- TreeSelect: Hard deprecate 40px default size (WordPress/gutenberg#79550)
- Storybook: Scope Docs theme providers (WordPress/gutenberg#79496)
- Base Styles: Reapply wpds-var Sass helper (WordPress/gutenberg#79470)
- Docs: Add image hosting guidance to the documentation contributors guide (WordPress/gutenberg#79574)
- CODEOWNERS: assign widget dashboard areas to @retrofox (WordPress/gutenberg#79484)
- Automated Testing: Use three-dot diff comparison for changelog checks (WordPress/gutenberg#79548)
- Base Styles: disallow direct var(--wpds-*) usage (WordPress/gutenberg#79424)
- Abilities: Support URI schema format (WordPress/gutenberg#79555)
- LineHeightControl: Hard deprecate 40px default size (WordPress/gutenberg#79589)
- Theme: Revert ThemeProvider stable API (WordPress/gutenberg#79594)
- Experimental: Expand DataForm inspector to patterns (WordPress/gutenberg#79452)
- RTC: Fix autosave update with no content (WordPress/gutenberg#79591)
- Icons: Add APIs for collection and icon registration (WordPress/gutenberg#77260)
- TextIndentControl: Remove unnecessary __next40pxDefaultSize prop (WordPress/gutenberg#79597)
- FontFamilyControl: Hard deprecate 40px default size (WordPress/gutenberg#79593)
- Icons Registry test: Fix trigger_error suppression on WP < 7.0 (WordPress/gutenberg#79607)
- Global Styles: Migrate color palette tabs to @wordpress/ui (WordPress/gutenberg#79281)
- Experiments: Shorten the plugin settings page name (WordPress/gutenberg#79579)
- Widget Primitives: Add `WidgetAttributeField` for typed attribute schemas (WordPress/gutenberg#79544)
- Fix - Accordion: Text in a closed accordion panel cannot be found via the browser search (WordPress/gutenberg#74744)
- Icons Registry: Allow digits and underscores in icon slugs (WordPress/gutenberg#79623)
- Knowledge: Rename the Guidelines CPT storage primitive to Knowledge (WordPress/gutenberg#79149)
- Update @terrazzo/* to 2.4.0 and regenerate design tokens (WordPress/gutenberg#79627)
- Tabs: RichText handlers for adding/removing tabs (WordPress/gutenberg#79583)
- Declare @types/node explicitly and harden no-unsafe-wp-apis (WordPress/gutenberg#79626)
- Knowledge: Dissolve the Guidelines singleton into per-scope rows (WordPress/gutenberg#79263)
- Jest: Mock CSS module class names (WordPress/gutenberg#79535)
- React 19 patch: log warnings when polyfills are hit (WordPress/gutenberg#79624)
- Upgrade browserslist to ^4.28.4 (WordPress/gutenberg#79630)
- Dedupe @testing-library/dom to a single 10.4.1 in the lockfile (WordPress/gutenberg#79631)
- Theme: Restore public ThemeProvider export (WordPress/gutenberg#79620)
- Paste: move spaces out of inline formatting elements (WordPress/gutenberg#79637)
- Blocks: Add innerContent support for static inner blocks, adopt it in the HTML block (WordPress/gutenberg#79115)
- Update webpack to 5.108.1 (WordPress/gutenberg#79633)
- RangeControl: Hard deprecate 40px default size (WordPress/gutenberg#79590)
- Animated GIF to video conversion (via mediabunny) plus conversion controls (WordPress/gutenberg#78410)
- Expose widget category through the build pipeline and REST API (WordPress/gutenberg#79638)
- Button: Fix corner artifacts by using background-clip: border-box (WordPress/gutenberg#79524)
- Notes: inline (partial-text) notes via hybrid marker + strip-on-render approach (WordPress/gutenberg#78218)
- balance top padding for sidebar controls (WordPress/gutenberg#79660)
- Guidelines E2E Tests: wait for boot to load copy page (WordPress/gutenberg#79663)
- Media Editor: Use new Tabs component from the ui package, and its minimal variant (WordPress/gutenberg#79664)
- View config: Add better post type default `form` (WordPress/gutenberg#79625)
- Opt in to npm v11 supply-chain security features (WordPress/gutenberg#79614)
- Revert "Opt in to npm v11 supply-chain security features (WordPress/gutenberg#79614)" (WordPress/gutenberg#79667)
- Navigation Link: Fix "[object Object]" in link preview for untitled entities (WordPress/gutenberg#79616)
- Update stylelint to 16.26.1 (WordPress/gutenberg#79648)
- Remove redundant @jest-environment jsdom pragmas from unit tests (WordPress/gutenberg#79672)
- npm dedupe (WordPress/gutenberg#79618)
- E2E: Ban uuid package via ESLint, use crypto.randomUUID() instead (WordPress/gutenberg#79673)
- Jest: Add missing clsx dev dependency (WordPress/gutenberg#79677)
- Style Engine: Preserve important gradient declarations (WordPress/gutenberg#79568)
- Widget Dashboard: Refactor tile header and toolbar chrome (WordPress/gutenberg#79639)
- Widget Dashboard: Anchor settings drawer to the right and toggle it from the gear (WordPress/gutenberg#79683)
- Declare undeclared workspace dependencies (WordPress/gutenberg#79684)
- Move icon tests out of phpunit/experimental (WordPress/gutenberg#79695)
- WP Build: improve documentation for routes (WordPress/gutenberg#79688)
- Packages: Backport UI and theme release changelogs (WordPress/gutenberg#79690)
- Bump preactjs/compressed-size-action (WordPress/gutenberg#79587)
- Bump js-yaml from 3.14.2 to 3.15.0 (WordPress/gutenberg#79644)
- FontAppearanceControl: Hard deprecate 40px default size (WordPress/gutenberg#79635)
- Bump actions/cache from 5.0.5 to 6.1.0 in /.github/setup-node (WordPress/gutenberg#79692)
- Bump actions/cache from 5.0.5 to 6.1.0 in /.github/workflows (WordPress/gutenberg#79693)
- Bump actions/checkout from 6.0.3 to 7.0.0 in /.github/workflows (WordPress/gutenberg#79488)
- Editor: Move focus to revisions slider when entering revisions mode (WordPress/gutenberg#79691)
- Packages: Backport package release metadata (WordPress/gutenberg#79702)
- Update: simplify inline-note marker stripping to match core backport (WordPress/gutenberg#79670)
- Add an e2e test for single paragraph selection on triple click (WordPress/gutenberg#79706)
- ComboboxControl: Hard deprecate 40px default size (WordPress/gutenberg#79636)
- FormFileUpload: Hard deprecate 40px default size (WordPress/gutenberg#79655)
- Automated Testing: Enforce dependencies checks consistently for development files (WordPress/gutenberg#79703)
- Base Styles: Make Sass token fallbacks self-contained (WordPress/gutenberg#79651)
- Radio: Hard deprecate 40px default size (WordPress/gutenberg#79657)
- ToggleGroupControl: Hard deprecate 40px default size (WordPress/gutenberg#79656)
- Heading: Fix ESLint warnings (WordPress/gutenberg#79694)
- Media Inserter: Add a simple Attached images category with attach and detach behaviour (WordPress/gutenberg#79336)
- Upgrade Playwright to v1.61 (WordPress/gutenberg#78632)
- Icons: Add an icon collections REST endpoint and tighten name rules (WordPress/gutenberg#79686)
- Experimental Media Modal: Ensure selection is properly cleared between open/close (WordPress/gutenberg#79731)
- Image: Use Playwright's locator.drop for media placeholder drop test (WordPress/gutenberg#79733)
- Add repeat all icon (WordPress/gutenberg#79698)
- Widgets: translate `title`, `description`, and `keywords` server-side (WordPress/gutenberg#79701)
- Build: Support --skip-types in npm run dev (WordPress/gutenberg#79736)
- Release: Revert to 23.5rc-3 (WordPress/gutenberg#79741)
- Render the selected static inner block synchronously (WordPress/gutenberg#79726)
- Revert "Bump plugin version to 23.5.0" (WordPress/gutenberg#79744)
- Build: Replace unmaintained release actions (WordPress/gutenberg#78258)
- Build: Use GUTENBERG_TOKEN when creating the release draft (WordPress/gutenberg#79747)
- CI: Enforce pruned ESLint suppressions during lint (WordPress/gutenberg#79708)
- Revert "Bump plugin version to 23.5.0" (WordPress/gutenberg#79750)

Props desrosj, wildworks.
Fixes #65589.

git-svn-id: https://develop.svn.wordpress.org/trunk@62738 602fd350-edb4-49c9-b593-d223f7449a82
markjaquith pushed a commit to markjaquith/WordPress that referenced this pull request Jul 14, 2026
This updates the pinned commit hash of the Gutenberg repository from `98a796c8780c480ef7bcfe03c42302d9564d785c` (version `23.4.0`) to `b5574edc8a952b2f1e528693761a97b1b3b580eb` (version `23.5.0`).

A full list of changes included in this commit can be found on GitHub: https://github.com/WordPress/gutenberg/compare/v23.4.0..v23.5.0.

The following commits are included:

- Site Editor: Fix admin color scheme bleeding through the mobile content scrollbar gutter (WordPress/gutenberg#79056)
- Build: Add GUTENBERG_CHECK_INSTALLED_DEPS env var to opt out of installed-deps check (WordPress/gutenberg#79068)
- Media Editor: Keep the modal skeleton pinned in the editor flow (WordPress/gutenberg#79070)
- Editor: Hide cmd palette shortcut in document bar when admin bar is shown (WordPress/gutenberg#79060)
- Math format: seed LaTeX input from the current selection (WordPress/gutenberg#79052)
- Omnibar: Rename experiment to match iteration issue (WordPress/gutenberg#79074)
- Theme: Add Figma scopes to element size tokens (WordPress/gutenberg#79032)
- Admin bar in editor experiment: show site icon instead of dashicon if set (WordPress/gutenberg#79049)
- Math format: Simplify the onClick handler and use canonical selected-text capture (WordPress/gutenberg#79081)
- Style Engine: Export public TypeScript types (WordPress/gutenberg#79079)
- Image: Fix pasted images stretching when dimensions are preserved (WordPress/gutenberg#79067)
- Update `@ariakit/react` to 0.4.29 (WordPress/gutenberg#79055)
- Navigation: Use block context to determine whether Page List is nested in Submenu (WordPress/gutenberg#79048)
- Fix code editor cursor jump on remote RTC updates (WordPress/gutenberg#79005)
- Fix: Custom HTML block preview keeps expanding when iframe uses height:100vh (WordPress/gutenberg#78677)
- Image block: don't show crop icon while image is uploading (WordPress/gutenberg#79103)
- Media Editor Modal: Add a loading and simple error state (WordPress/gutenberg#79101)
- Add React 19 as an experimental flag (WordPress/gutenberg#79077)
- Try: Remove Tab (Tab list item) block  (WordPress/gutenberg#77439)
- Navigation block: Fix responsive style states for typography settings (WordPress/gutenberg#79072)
- Popover: add open/close motion and fix close re-anchor (WordPress/gutenberg#78885)
- Remove unused build:profile-types and component-usage-stats scripts (WordPress/gutenberg#79113)
- RTC: Allow disabling collaboration by post type (WordPress/gutenberg#78984)
- Omnipresent Toolbar: increase top padding in sidebar nav title (WordPress/gutenberg#79083)
- Add support for aspect ratio and related controls in viewport states (WordPress/gutenberg#78795)
- Fix responsive element styles front end output (WordPress/gutenberg#79135)
- BaseControl: add text-wrap: pretty (WordPress/gutenberg#79112)
- wp-build: Return null from getPackageInfo on resolve miss instead of throwing (WordPress/gutenberg#78715)
- Global styles revisions: replace active text with badge (WordPress/gutenberg#79137)
- Editor: Disable saving while a non-post entity is being saved (WordPress/gutenberg#79069)
- Add xl border radius token for page shell surfaces. (WordPress/gutenberg#78913)
- Add corner radius presets to ThemeProvider (WordPress/gutenberg#78816)
- theme: rename `bg`/`fg` design token groups to `background`/`foreground` (WordPress/gutenberg#79098)
- Theme: Enforce sRGB seed-color input contract for ThemeProvider (WordPress/gutenberg#79148)
- Theme: Rename `--wpds-color-stroke-focus-brand` token to `--wpds-color-stroke-focus` (WordPress/gutenberg#79125)
- refactor: Move 'glob' dependency to appropriate workspaces (WordPress/gutenberg#79145)
- Add lock-unlock route as a workspace and update dependencies (WordPress/gutenberg#79138)
- Dependabot: Add npm entry so security update PRs can be rebased (WordPress/gutenberg#79076)
- refactor: rename '@wordpress/lock-unlock' to '@wordpress/routes-lock-unlock' across the codebase (WordPress/gutenberg#79163)
- Panel: Recommend CollapsibleCard for use outside the block inspector (WordPress/gutenberg#78863)
- Editor: Migrate FlatTermSelector to UI Stack component (WordPress/gutenberg#78659)
- design-system-mcp: Remove Storybook dependency in TypeScript types (WordPress/gutenberg#79132)
- Bump rollup from 4.55.1 to 4.59.0 (WordPress/gutenberg#75964)
- Media modal: small tweak to gutters (WordPress/gutenberg#79168)
- Icon Block: Add flip and rotate transformation controls (WordPress/gutenberg#77017)
- Media Editor: Magnify the crop to fill the canvas (WordPress/gutenberg#79044)
- Update capitalisation and spelling within the welcome tour (WordPress/gutenberg#53028)
- Feature: Need to add “Show More” / “Show Less” toggle in Note. (WordPress/gutenberg#77446)
- Correct behaviour of flex child fixed width and introduce max width option (WordPress/gutenberg#79073)
- Eslint: move deps from root into tools/eslint and packages/eslint-plugin (WordPress/gutenberg#79110)
- Gallery: Hide Navigation button type when lightbox editing is disabled (WordPress/gutenberg#79147)
- Add more React internals polyfills (WordPress/gutenberg#79142)
- [DataViewsPicker]: `DataViewsPicker.BulkActionToolbar` now renders only the bulk-selection info and action buttons (WordPress/gutenberg#79180)
- Block Editor: Fix potential crash from 'useBlockToolbarPopoverProps' (WordPress/gutenberg#79178)
- Tabs: Simplify layout and prune redundant block supports (WordPress/gutenberg#77646)
- e2e: Retry transient theme activation failures in pages spec (WordPress/gutenberg#79171)
- Revisions screen with picker-activity layout (WordPress/gutenberg#77333)
- chore: remove glob from root pkg json (WordPress/gutenberg#79183)
- Core Data: Don't use 'useQuerySelect' in 'useEntityRecord(s)' hooks (WordPress/gutenberg#76198)
- Revisions: Ignore empty `[]/{}` meta values in the Meta diff panel (WordPress/gutenberg#79185)
- UI Field.Description: add `text-wrap: pretty` (WordPress/gutenberg#79143)
- Blocks: Migrate Markdown converter from showdown to marked (WordPress/gutenberg#77953)
- Bump shivammathur/setup-php (WordPress/gutenberg#79193)
- Icons block: insert an icon by default (WordPress/gutenberg#79111)
- Theme: Add tests for ThemeProvider and useThemeProviderStyles (WordPress/gutenberg#79126)
- Icon block: Move flip controls to toolbar group. (WordPress/gutenberg#79192)
- Packages: Fix the published dependency surface of npm packages (WordPress/gutenberg#79095)
- Block Library: Remove unused Babel optimization plugin (WordPress/gutenberg#79162)
- Automated Testing: Use static value for IS_GUTENBERG_PLUGIN env setup (WordPress/gutenberg#79201)
- Scripts: Avoid tests getting published to npm (WordPress/gutenberg#79204)
- Theme: Add disabled variants for brand and error interactive color tokens (WordPress/gutenberg#79124)
- Fix: State styles – clear `background-image` when hover sets a solid `background-color` (WordPress/gutenberg#78992)
- Media editor: Snap crop handles to source pixels (WordPress/gutenberg#79139)
- Image block: remove duplicate data-wp-bind--srcset in the lightbox overlay (WordPress/gutenberg#79202)
- Template Part: Remove restriction on tabs / inspector fills (WordPress/gutenberg#79181)
- Editor: Guard PostViewLink against post types without a labels object (WordPress/gutenberg#79160)
- Media editor modal: Fix keyboard resizing for locked aspect-ratio crops (WordPress/gutenberg#79207)
- wp-build: Resolve @wordpress/build from __dirname in resolve-miss test (WordPress/gutenberg#79208)
- Theme: forward ThemeProvider cornerRadius preset to :root for root providers (WordPress/gutenberg#79153)
- Refactor Prettier configuration and update dependencies (WordPress/gutenberg#79219)
- chore: Add missing root devDependencies for WordPress packages (WordPress/gutenberg#79221)
- Refactor: Update  npm-package-json-lint configuration (WordPress/gutenberg#79223)
- Components: Complete WPDS token migration for remaining borders (WordPress/gutenberg#79003)
- Plugin: Bump minimum required WordPress version to 6.9 (WordPress/gutenberg#79196)
- Autocomplete: Add Group and GroupLabel primitives (WordPress/gutenberg#78901)
- Pullquote: Migrate to text-align block support (WordPress/gutenberg#79225)
- Style Book: Fix crash when previewing variations for blocks without examples (WordPress/gutenberg#79131)
- Theme: Add stroke-surface tokens for the caution tone (WordPress/gutenberg#79198)
- Icon block: Default to core/info via block.json instead of an insert-time effect (WordPress/gutenberg#79212)
- Backport changelog and package version updates from wp/latest (WordPress/gutenberg#79234)
- V2 Site Editor: Fix template edit routes (WordPress/gutenberg#79230)
- Grid: Prepare `@wordpress/grid` for npm publishing as experimental 0.1.0 (WordPress/gutenberg#79071)
- File Block: Replace on-mount downloadButtonText effect with a default variation (WordPress/gutenberg#79236)
- Components, DataViews: Adopt --wpds-dimension-size-* tokens (WordPress/gutenberg#79093)
- Refactor: move stylelint config and deps to tools/stylelint workspace (WordPress/gutenberg#79226)
- Revert "Components: Complete WPDS token migration for remaining borders (WordPress/gutenberg#79003)" (WordPress/gutenberg#79243)
- Edit Post: Refactor and cleanup InitPatternModal component (WordPress/gutenberg#79190)
- Widget Primitives: extract into `@wordpress/widget-primitives` (WordPress/gutenberg#79134)
- chore: remove @wordpress/vips dependency from root (WordPress/gutenberg#79249)
- design-system-mcp: Improve README overview and setup instructions (WordPress/gutenberg#79238)
- Components: Re-land WPDS border token migration with Emotion-safe comments (WordPress/gutenberg#79244)
- Theme: Provide design-system token defaults without a runtime `<ThemeProvider>` (WordPress/gutenberg#78664)
- List View block support: Hide list tab when allowedBlocks is empty, with no children (WordPress/gutenberg#78932)
- Handle WP.org SVN missing tag warnings (WordPress/gutenberg#79257)
- CI: Run PHP unit tests on PHP 8.4 and 8.5 (WordPress/gutenberg#79260)
- mark @types/react as an optional peer dependency (WordPress/gutenberg#79272)
- Block bindings : add support to list-item (WordPress/gutenberg#78947)
- document widget-modules endpoint experiment gate (WordPress/gutenberg#79264)
- Storybook: Upgrade Storybook to 10.4 (WordPress/gutenberg#77382)
- Core Data: Cleanup edits matching persisted record on undo/redo (WordPress/gutenberg#77100)
- Notes: Simplify 'Show more/less' collapse logic (WordPress/gutenberg#79261)
- File Block: Combine audio/video/image to file transforms (WordPress/gutenberg#79242)
- Button: Use font weight token (WordPress/gutenberg#79278)
- Avoid dirtying related navigation entities during passive render (WordPress/gutenberg#79000)
- Theme: Skip serializing `data-wpds-root-provider="false"` on non-root providers (WordPress/gutenberg#79253)
- Patterns: Migrate modals to @wordpress/ui components and fix rename input width (WordPress/gutenberg#79233)
- ESLint, UI, Components: Mark `Tooltip` from `@wordpress/ui` as recommended (WordPress/gutenberg#78693)
- Theme: differentiate `--wpds-color-fg-interactive-{brand,error}-active` vs resting state tokens (WordPress/gutenberg#79151)
- Document AlertDialog as ConfirmDialog successor in Storybook (WordPress/gutenberg#79293)
- Elements: Accept both md5 and sequential `wp-elements-*` class names in tests (WordPress/gutenberg#79300)
- Cover block: add media editor modal (WordPress/gutenberg#79258)
- Blocks: Use positional sprintf placeholders in avatar, comment, and search renderers (WordPress/gutenberg#79290)
- DataForm: Fix panel field control overflow clipping and remove button overrides (WordPress/gutenberg#79275)
- Experiment: Editor Inspector with DataForm - remove revision panel and add link (WordPress/gutenberg#79195)
- Upload Media: Add error taxonomy, localized messages, and dev diagnostics (WordPress/gutenberg#74917)
- Block Fields: Fix crash resolving pattern overrides bindings (WordPress/gutenberg#79092)
- Media: Rename HEIC companion metadata key to source_image (WordPress/gutenberg#79307)
- DataForm: Align `label-side` gap of `panel` layout with `regular` layout (WordPress/gutenberg#79311)
- Theme: Add design tokens maintainer's guide documentation (WordPress/gutenberg#79157)
- Remove ObliviousHarmony from CODEOWNERS for packages/env (WordPress/gutenberg#79308)
- Widget Dashboard: extract into `@wordpress/widget-dashboard` (WordPress/gutenberg#79268)
- Sync editor settings in layout effect (fixes autosave e2e) (WordPress/gutenberg#78799)
- Remove Lighthouse patch (WordPress/gutenberg#79319)
- Editor: Remove orphaned editor-help component leftovers (WordPress/gutenberg#79324)
- Plugins API: Fix the plugin 'render' property validation (WordPress/gutenberg#79315)
- Components: Improve Menu unit tests performance by removing sleeps (WordPress/gutenberg#79295)
- UI Button: Fix loading state in forced colors (WordPress/gutenberg#78820)
- Media Editor: Fix crop canvas pinch zoom (WordPress/gutenberg#79332)
- Docs: Fix typos in README files (WordPress/gutenberg#79331)
- Media Editor: Align crop settle state with transition completion (WordPress/gutenberg#79339)
- KSES: Allow SVG-specific presentation attributes in safe_style_css (WordPress/gutenberg#79172)
- Widget Primitives: decouple discovery from a hardcoded endpoint (WordPress/gutenberg#79322)
- Site Editor: Save hub button styling while saving (WordPress/gutenberg#79287)
- Migrate compose package to TypeScript  (WordPress/gutenberg#70618)
- Vips: bump wasm-vips to 0.0.18 for high-bit-depth AVIF decoding (WordPress/gutenberg#79179)
- Experimental: Expand Editor Inspector: Use DataForm experiment to templates (WordPress/gutenberg#76934)
- Site Editor: Change 'Identity' nav item position (WordPress/gutenberg#79292)
- Block Bindings: Preserve nested lists when binding List Item content (WordPress/gutenberg#79346)
- Site Editor: Handle `aria-current` natively in `SidebarNavigationItem` (WordPress/gutenberg#79305)
- RichText: Fix duplicated format wrappers when typing inside an applied format (WordPress/gutenberg#79091)
- Vips: inline WASM with compact UTF-8 binary encoding instead of base64 (WordPress/gutenberg#79188)
- View Config API and REST Endpoint: make them core ready (WordPress/gutenberg#79347)
- Validation: Add a published-dependency audit script (WordPress/gutenberg#79094)
- Reconcile feature-detection docblock with implemented checks (WordPress/gutenberg#75851)
- fix typo in block-filter.md file (WordPress/gutenberg#79367)
- Search block: Add opt-in support for the semantic <search> element (WordPress/gutenberg#78485)
- Dashboard: revert H1 to "Dashboard" and fix heading hierarchy (WordPress/gutenberg#79251)
- Components: Make ResizableBox children prop optional (WordPress/gutenberg#79370)
- Grid overlays: Use canvas iframe window for viewport visibility detection (WordPress/gutenberg#79255)
- Widget Primitives: make contract and story docs host-agnostic (WordPress/gutenberg#79358)
- Use symbols for style states to avoid property clashes (WordPress/gutenberg#79210)
- Ignore markdown linting for backport-changelog MD files (WordPress/gutenberg#79392)
- Add media control icons (WordPress/gutenberg#78987)
- Icons: Use snake_case `file_path` key in icon registry (WordPress/gutenberg#79100)
- Editor: Use `Stack` for post summary (WordPress/gutenberg#79397)
- Theme: Run stylelint plugin tests via the Node API (WordPress/gutenberg#79199)
- Command Palette: Exclude assets from block editor settings endpoint (WordPress/gutenberg#79396)
- List item: Remove orphaned convertToListItems util (WordPress/gutenberg#79400)
- Video: Apply `inert` directly instead of wrapping in `Disabled` (WordPress/gutenberg#79371)
- Site Editor: Introduce isHidden prop for SidebarNavigationItem (WordPress/gutenberg#79352)
- Post Editor: Use the correct directory for recent preload improvements (WordPress/gutenberg#79359)
- Configure Flakiness.io reporting for e2e tests (WordPress/gutenberg#79173)
- View Config: request a subset of properties with the `_fields` parameter (WordPress/gutenberg#79355)
- Storybook: Reorganize design system introduction for first touch-point usefulness (WordPress/gutenberg#79360)
- Block editor: Convert utility modules to TypeScript (WordPress/gutenberg#79323)
- devops: configure report auto-upload for flakiness.io dashboard (WordPress/gutenberg#79411)
- UI: Simplify focus ring styles (WordPress/gutenberg#78823)
- TextControl: Hard deprecate 40px default size (WordPress/gutenberg#79386)
- devops: upload unit test results to flakiness dashboard (WordPress/gutenberg#79414)
- Clarify Core-specific steps when bumping support (WordPress/gutenberg#79416)
- Pattern editing: show root block identity when editing pattern sections (WordPress/gutenberg#79417)
- Patterns: Add a missing gap to 'Enable overrides' modal (WordPress/gutenberg#79421)
- Audio: Apply `inert` directly instead of wrapping in `Disabled` (WordPress/gutenberg#79423)
- Experimental: Expand Editor Inspector: Use DataForm experiment to template parts (WordPress/gutenberg#79399)
- Base Styles: Add wpds-var Sass helper for design token fallbacks (WordPress/gutenberg#78698)
- Block Editor: Allow overriding `disableContentOnlyForTemplateParts` setting (WordPress/gutenberg#79191)
- Mark all controlled/mode block changes non-persistent (WordPress/gutenberg#79350)
- Revert "Base Styles: Add wpds-var Sass helper for design token fallbacks (WordPress/gutenberg#78698)" (WordPress/gutenberg#79429)
- Popover: Align transition state styles (WordPress/gutenberg#79410)
- DataForm panel layout: fix double-clicking a field row leaving the flyout stuck open (WordPress/gutenberg#79348)
- Classic Block: Port PHPUnit coverage for wp_declare_classic_block_necessary (WordPress/gutenberg#79434)
- Fields: Move author fields for templates and template parts (WordPress/gutenberg#79395)
- Theme: Drop `--wpds-dimension-base` from the public token surface (WordPress/gutenberg#79254)
- Merge shared stylelint disallowed-list in components (WordPress/gutenberg#79425)
- Edit Post: Refactor MetaBoxesSection to use data hooks (WordPress/gutenberg#79433)
- View config endpoint: bring back changes from core (WordPress/gutenberg#79438)
- devops: separate environments for jest date tests (WordPress/gutenberg#79453)
- UI: Disable instant overlay popup transitions (WordPress/gutenberg#79432)
- Components: Refactor withFallbackStyles from class to function component (WordPress/gutenberg#78837)
- Automated Testing: Globally shim Element#getClientRects (WordPress/gutenberg#79353)
- Theme: Promote ThemeProvider to stable API (WordPress/gutenberg#78958)
- Automated Testing: Add babel-plugin-transform-import-meta to emulate import.meta.dirname (WordPress/gutenberg#79362)
- E2E: Support WordPress installs served from a subdirectory (WordPress/gutenberg#79166)
- Custom HTML: Fix scrollbar after tab switch in modal (WordPress/gutenberg#78571)
- Theme: apply ThemeProvider styles inline (I2) (WordPress/gutenberg#78678)
- Add flex vertical alignment tool to block inspector layout panel (WordPress/gutenberg#79426)
- Block Supports: Relocate text and bg color controls to Typography and Background panels (WordPress/gutenberg#77279)
- Add e2e coverage for pattern wrapper block identity (WordPress/gutenberg#79462)
- Storybook: Include playground stories and MDX in CI smoke tests (WordPress/gutenberg#79454)
- BoxControl: respect a consumer-supplied placeholder via inputProps (WordPress/gutenberg#79466)
- Media Fields: Ensure the current post is always included in the initial options (WordPress/gutenberg#79467)
- Global Styles: Add textShadow style support (WordPress/gutenberg#73320)
- Media Fields: Avoid focus loss when detaching the current parent (WordPress/gutenberg#79468)
- CI: Disallow new dependencies in the root package.json (WordPress/gutenberg#78616)
- Experimental: Preserve editor panel visibility in the DataForm post summary (WordPress/gutenberg#79441)
- Tabs: Pre-stabilization API cleanup and refactoring (WordPress/gutenberg#79337)
- BoxControl: Hard deprecate 40px default size (WordPress/gutenberg#79419)
- Image Block: Remove chained entity record calls (WordPress/gutenberg#79469)
- UI: Use isomorphic layout effects (WordPress/gutenberg#79458)
- Components: add Emotion migration guardrails (WordPress/gutenberg#79442)
- devops: separate histories for different node.js versions (WordPress/gutenberg#79473)
- Components: migrate Divider to SCSS module (WordPress/gutenberg#79444)
- Block Library: unwrap Classic block migration notice experiment (WordPress/gutenberg#78165)
- Editor: Refactor AutosaveMonitor to a function component (WordPress/gutenberg#79043)
- Boot: run page `init` modules in `initSinglePage` (WordPress/gutenberg#79394)
- DataFormPostSummary: fix different `useSelect` returned values  (WordPress/gutenberg#79478)
- Icons: self declare color (WordPress/gutenberg#79320)
- Theme: Document ramp memoization contract (WordPress/gutenberg#79459)
- tools: Restrict layout effect imports in UI and theme (WordPress/gutenberg#79476)
- CI: Avoid full-history checkout for the root-dependencies check (WordPress/gutenberg#79489)
- Simplify playlist track state (WordPress/gutenberg#79448)
- prepend_to_selector: optimized with str_replace() (WordPress/gutenberg#76556)
- Components: migrate Surface to SCSS module (WordPress/gutenberg#79445)
- Docs: Add a widget anatomy doc and lighten the widget system doc (WordPress/gutenberg#79435)
- Media Editor: remove inline cropper (follow-up to WordPress/gutenberg#78653) (WordPress/gutenberg#78654)
- Grid: Add option to stretch columns with auto-fit for better layout flexibility (WordPress/gutenberg#79356)
- Guidelines: Use str_starts_with() in is_block_meta_key() (WordPress/gutenberg#79491)
- Color popover: move contrast warning notice to the bottom (WordPress/gutenberg#79512)
- BorderBoxControl: Hard deprecate 40px default size (WordPress/gutenberg#79420)
- Remove Classic Block conversion from BlockInvalidWarning (WordPress/gutenberg#79500)
- [RTC] Add granular collaboration control (WordPress/gutenberg#79184)
- FontSizePicker: Hard deprecate 40px default size (WordPress/gutenberg#79481)
- React 19: patch to support legacy inert attribute values (WordPress/gutenberg#79475)
- Icons: Add Storybook React Vite dev dependency (WordPress/gutenberg#79506)
- QueryControls: Complete __next40pxDefaultSize cleanup (WordPress/gutenberg#79485)
- Block editor: use core/registered-block in reducer tests (WordPress/gutenberg#79522)
- UI: Update @base-ui/react to 1.6.0 (WordPress/gutenberg#79408)
- Refactor: Replace strpos with str_starts_with for improved consistency (WordPress/gutenberg#79519)
- Block Library: Remove redundant parentheses around assignments (WordPress/gutenberg#79516)
- Tabs: Focus first tab when adding Tabs block (WordPress/gutenberg#79507)
- ui/IconButton: Restore default tooltip delay (WordPress/gutenberg#79505)
- FocalPointPicker: Complete __next40pxDefaultSize cleanup (WordPress/gutenberg#79487)
- Components: document CSS module class composition (WordPress/gutenberg#79490)
- BorderControl: Hard deprecate 40px default size (WordPress/gutenberg#79418)
- Components: migrate Truncate to SCSS module (WordPress/gutenberg#79446)
- Show the admin bar in the Post and Site Editor by default (WordPress/gutenberg#79197)
- SearchControl: Complete __next40pxDefaultSize cleanup (WordPress/gutenberg#79538)
- Stylelint: Enforce module class naming in UI packages (WordPress/gutenberg#79504)
- Components: Add missing descriptions for design system components (WordPress/gutenberg#79460)
- LetterSpacingControl: Hard deprecate 40px default size (WordPress/gutenberg#79533)
- Experiments: Move screen under Settings, drop top-level Gutenberg menu and Demo page (WordPress/gutenberg#79456)
- Tabs: Combine and cleanup toolbar controls (WordPress/gutenberg#79537)
- Tabs: Fix dirty editor state on mount caused by tab-list sync (WordPress/gutenberg#79540)
- RTC: fix undo / redo breakage when plug-in with metabox is loaded (WordPress/gutenberg#79510)
- Block Supports: Guard elements hover rendering against missing hover selector (WordPress/gutenberg#79511)
- Commands: add toggle for content-only pattern/template part editing (WordPress/gutenberg#78383)
- Integrate Resizable Editor with Device Preview and add Responsive editing (WordPress/gutenberg#75121)
- Pattern editing: use section block selector for pattern display identity (WordPress/gutenberg#79565)
- Commands: Suggest pattern editing toggle for selected patterns (WordPress/gutenberg#79566)
- Tabs: Select tab panel when caret moves into tab (WordPress/gutenberg#79558)
- Fix unsetting values in viewport states for grid and constrained layouts (WordPress/gutenberg#79520)
- Add layout and block spacing support to Latest Posts block (WordPress/gutenberg#77989)
- Widget inserter: more accurate widget previews (WordPress/gutenberg#79517)
- Tabs: Remove unnecessary callback memoization (WordPress/gutenberg#79567)
- Icons: Add PHP method(s) for rendering inline SVG icons from the registry (WordPress/gutenberg#78332)
- Tab List: Fix render inline formatting on frontend (WordPress/gutenberg#79554)
- Divider: Restore lower border specificity (WordPress/gutenberg#79534)
- Tabs: Remove redundant block selection from Add/Remove tab actions (WordPress/gutenberg#79571)
- Icons: Fix viewBox attribute casing assertion for older WP versions (WordPress/gutenberg#79576)
- Add icon state classes to Accordion block (WordPress/gutenberg#74257)
- Pattern editing: Fade block outside the edited pattern in List View (WordPress/gutenberg#73997)
- Experiments: move long intro to content (WordPress/gutenberg#79578)
- Updating image urls (WordPress/gutenberg#79529)
- `useTypingObserver`: capture the window reference for cleanup (WordPress/gutenberg#78772)
- Tabs: Fix rich text label comparation when syncing the list (WordPress/gutenberg#79582)
- Add `PluginPostStatusInfo` in DataForm post summary (WordPress/gutenberg#79586)
- theme: Protect design tokens CSS import (WordPress/gutenberg#79551)
- TreeSelect: Hard deprecate 40px default size (WordPress/gutenberg#79550)
- Storybook: Scope Docs theme providers (WordPress/gutenberg#79496)
- Base Styles: Reapply wpds-var Sass helper (WordPress/gutenberg#79470)
- Docs: Add image hosting guidance to the documentation contributors guide (WordPress/gutenberg#79574)
- CODEOWNERS: assign widget dashboard areas to @retrofox (WordPress/gutenberg#79484)
- Automated Testing: Use three-dot diff comparison for changelog checks (WordPress/gutenberg#79548)
- Base Styles: disallow direct var(--wpds-*) usage (WordPress/gutenberg#79424)
- Abilities: Support URI schema format (WordPress/gutenberg#79555)
- LineHeightControl: Hard deprecate 40px default size (WordPress/gutenberg#79589)
- Theme: Revert ThemeProvider stable API (WordPress/gutenberg#79594)
- Experimental: Expand DataForm inspector to patterns (WordPress/gutenberg#79452)
- RTC: Fix autosave update with no content (WordPress/gutenberg#79591)
- Icons: Add APIs for collection and icon registration (WordPress/gutenberg#77260)
- TextIndentControl: Remove unnecessary __next40pxDefaultSize prop (WordPress/gutenberg#79597)
- FontFamilyControl: Hard deprecate 40px default size (WordPress/gutenberg#79593)
- Icons Registry test: Fix trigger_error suppression on WP < 7.0 (WordPress/gutenberg#79607)
- Global Styles: Migrate color palette tabs to @wordpress/ui (WordPress/gutenberg#79281)
- Experiments: Shorten the plugin settings page name (WordPress/gutenberg#79579)
- Widget Primitives: Add `WidgetAttributeField` for typed attribute schemas (WordPress/gutenberg#79544)
- Fix - Accordion: Text in a closed accordion panel cannot be found via the browser search (WordPress/gutenberg#74744)
- Icons Registry: Allow digits and underscores in icon slugs (WordPress/gutenberg#79623)
- Knowledge: Rename the Guidelines CPT storage primitive to Knowledge (WordPress/gutenberg#79149)
- Update @terrazzo/* to 2.4.0 and regenerate design tokens (WordPress/gutenberg#79627)
- Tabs: RichText handlers for adding/removing tabs (WordPress/gutenberg#79583)
- Declare @types/node explicitly and harden no-unsafe-wp-apis (WordPress/gutenberg#79626)
- Knowledge: Dissolve the Guidelines singleton into per-scope rows (WordPress/gutenberg#79263)
- Jest: Mock CSS module class names (WordPress/gutenberg#79535)
- React 19 patch: log warnings when polyfills are hit (WordPress/gutenberg#79624)
- Upgrade browserslist to ^4.28.4 (WordPress/gutenberg#79630)
- Dedupe @testing-library/dom to a single 10.4.1 in the lockfile (WordPress/gutenberg#79631)
- Theme: Restore public ThemeProvider export (WordPress/gutenberg#79620)
- Paste: move spaces out of inline formatting elements (WordPress/gutenberg#79637)
- Blocks: Add innerContent support for static inner blocks, adopt it in the HTML block (WordPress/gutenberg#79115)
- Update webpack to 5.108.1 (WordPress/gutenberg#79633)
- RangeControl: Hard deprecate 40px default size (WordPress/gutenberg#79590)
- Animated GIF to video conversion (via mediabunny) plus conversion controls (WordPress/gutenberg#78410)
- Expose widget category through the build pipeline and REST API (WordPress/gutenberg#79638)
- Button: Fix corner artifacts by using background-clip: border-box (WordPress/gutenberg#79524)
- Notes: inline (partial-text) notes via hybrid marker + strip-on-render approach (WordPress/gutenberg#78218)
- balance top padding for sidebar controls (WordPress/gutenberg#79660)
- Guidelines E2E Tests: wait for boot to load copy page (WordPress/gutenberg#79663)
- Media Editor: Use new Tabs component from the ui package, and its minimal variant (WordPress/gutenberg#79664)
- View config: Add better post type default `form` (WordPress/gutenberg#79625)
- Opt in to npm v11 supply-chain security features (WordPress/gutenberg#79614)
- Revert "Opt in to npm v11 supply-chain security features (WordPress/gutenberg#79614)" (WordPress/gutenberg#79667)
- Navigation Link: Fix "[object Object]" in link preview for untitled entities (WordPress/gutenberg#79616)
- Update stylelint to 16.26.1 (WordPress/gutenberg#79648)
- Remove redundant @jest-environment jsdom pragmas from unit tests (WordPress/gutenberg#79672)
- npm dedupe (WordPress/gutenberg#79618)
- E2E: Ban uuid package via ESLint, use crypto.randomUUID() instead (WordPress/gutenberg#79673)
- Jest: Add missing clsx dev dependency (WordPress/gutenberg#79677)
- Style Engine: Preserve important gradient declarations (WordPress/gutenberg#79568)
- Widget Dashboard: Refactor tile header and toolbar chrome (WordPress/gutenberg#79639)
- Widget Dashboard: Anchor settings drawer to the right and toggle it from the gear (WordPress/gutenberg#79683)
- Declare undeclared workspace dependencies (WordPress/gutenberg#79684)
- Move icon tests out of phpunit/experimental (WordPress/gutenberg#79695)
- WP Build: improve documentation for routes (WordPress/gutenberg#79688)
- Packages: Backport UI and theme release changelogs (WordPress/gutenberg#79690)
- Bump preactjs/compressed-size-action (WordPress/gutenberg#79587)
- Bump js-yaml from 3.14.2 to 3.15.0 (WordPress/gutenberg#79644)
- FontAppearanceControl: Hard deprecate 40px default size (WordPress/gutenberg#79635)
- Bump actions/cache from 5.0.5 to 6.1.0 in /.github/setup-node (WordPress/gutenberg#79692)
- Bump actions/cache from 5.0.5 to 6.1.0 in /.github/workflows (WordPress/gutenberg#79693)
- Bump actions/checkout from 6.0.3 to 7.0.0 in /.github/workflows (WordPress/gutenberg#79488)
- Editor: Move focus to revisions slider when entering revisions mode (WordPress/gutenberg#79691)
- Packages: Backport package release metadata (WordPress/gutenberg#79702)
- Update: simplify inline-note marker stripping to match core backport (WordPress/gutenberg#79670)
- Add an e2e test for single paragraph selection on triple click (WordPress/gutenberg#79706)
- ComboboxControl: Hard deprecate 40px default size (WordPress/gutenberg#79636)
- FormFileUpload: Hard deprecate 40px default size (WordPress/gutenberg#79655)
- Automated Testing: Enforce dependencies checks consistently for development files (WordPress/gutenberg#79703)
- Base Styles: Make Sass token fallbacks self-contained (WordPress/gutenberg#79651)
- Radio: Hard deprecate 40px default size (WordPress/gutenberg#79657)
- ToggleGroupControl: Hard deprecate 40px default size (WordPress/gutenberg#79656)
- Heading: Fix ESLint warnings (WordPress/gutenberg#79694)
- Media Inserter: Add a simple Attached images category with attach and detach behaviour (WordPress/gutenberg#79336)
- Upgrade Playwright to v1.61 (WordPress/gutenberg#78632)
- Icons: Add an icon collections REST endpoint and tighten name rules (WordPress/gutenberg#79686)
- Experimental Media Modal: Ensure selection is properly cleared between open/close (WordPress/gutenberg#79731)
- Image: Use Playwright's locator.drop for media placeholder drop test (WordPress/gutenberg#79733)
- Add repeat all icon (WordPress/gutenberg#79698)
- Widgets: translate `title`, `description`, and `keywords` server-side (WordPress/gutenberg#79701)
- Build: Support --skip-types in npm run dev (WordPress/gutenberg#79736)
- Release: Revert to 23.5rc-3 (WordPress/gutenberg#79741)
- Render the selected static inner block synchronously (WordPress/gutenberg#79726)
- Revert "Bump plugin version to 23.5.0" (WordPress/gutenberg#79744)
- Build: Replace unmaintained release actions (WordPress/gutenberg#78258)
- Build: Use GUTENBERG_TOKEN when creating the release draft (WordPress/gutenberg#79747)
- CI: Enforce pruned ESLint suppressions during lint (WordPress/gutenberg#79708)
- Revert "Bump plugin version to 23.5.0" (WordPress/gutenberg#79750)

Props desrosj, wildworks.
Fixes #65589.
Built from https://develop.svn.wordpress.org/trunk@62738


git-svn-id: http://core.svn.wordpress.org/trunk@62022 1a063a9b-81f0-0310-95a4-ce76da25c4cd
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

[Type] Security Related to security concerns or efforts

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants