Skip to content

chore(deps)(deps-dev): bump vite from 5.4.21 to 7.3.1 - #197

Merged
hotlong merged 1 commit into
mainfrom
dependabot/npm_and_yarn/vite-7.3.1
Feb 1, 2026
Merged

hotlong merged 1 commit into
mainfrom
dependabot/npm_and_yarn/vite-7.3.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jan 26, 2026 •

Copy link
Copy Markdown
Contributor

Bumps vite from 5.4.21 to 7.3.1.

Release notes

Sourced from vite's releases.

v7.3.1

Please refer to CHANGELOG.md for details.

v7.3.0

Please refer to CHANGELOG.md for details.

v7.2.7

Please refer to CHANGELOG.md for details.

v7.2.6

Please refer to CHANGELOG.md for details.

v7.2.5

Please refer to CHANGELOG.md for details.

Note: 7.2.5 failed to publish so it is skipped on npm

v7.2.4

Please refer to CHANGELOG.md for details.

v7.2.3

Please refer to CHANGELOG.md for details.

v7.2.2

Please refer to CHANGELOG.md for details.

plugin-legacy@7.2.1

Please refer to CHANGELOG.md for details.

v7.2.1

Please refer to CHANGELOG.md for details.

plugin-legacy@7.2.0

Please refer to CHANGELOG.md for details.

v7.2.0

Please refer to CHANGELOG.md for details.

v7.2.0-beta.1

Please refer to CHANGELOG.md for details.

v7.2.0-beta.0

Please refer to CHANGELOG.md for details.

v7.1.12

Please refer to CHANGELOG.md for details.

v7.1.11

Please refer to CHANGELOG.md for details.

... (truncated)

Changelog

Sourced from vite's changelog.

7.3.1 (2026-01-07)

Features

  • add ignoreOutdatedRequests option to optimizeDeps (#21364) (9d39d37)

7.3.0 (2025-12-15)

Features

  • deps: update esbuild from ^0.25.0 to ^0.27.0 (#21183) (cff26ec)

7.2.7 (2025-12-08)

Bug Fixes

7.2.6 (2025-12-01)

7.2.5 (2025-12-01)

Bug Fixes

Performance Improvements

Documentation

  • clarify manifest.json imports field is JS chunks only (#21136) (46d3077)

Miscellaneous Chores

7.2.4 (2025-11-20)

Bug Fixes

  • revert "perf(deps): replace debug with obug (#21107)" (2d66b7b)

7.2.3 (2025-11-20)

Bug Fixes

  • allow multiple bindCLIShortcuts calls with shortcut merging (#21103) (5909efd)
  • deps: update all non-major dependencies (#21096) (6a34ac3)
  • deps: update all non-major dependencies (#21128) (4f8171e)

Performance Improvements

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript labels Jan 26, 2026
@vercel

vercel Bot commented Jan 26, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
spec Ready Ready Preview, Comment Jan 31, 2026 5:20am

Request Review

Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 5.4.21 to 7.3.1.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/v7.3.1/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v7.3.1/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 7.3.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/vite-7.3.1 branch from 493098c to 7b81167 Compare January 31, 2026 05:09
@hotlong
hotlong merged commit 5cb3bc4 into main Feb 1, 2026
11 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/vite-7.3.1 branch February 1, 2026 02:47
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Sep 28, 2026
…he declaration-parity ratchet and the browser dump (objectstack-ai#19921)

Fixes objectstack-ai#17735
Clause-②: no

Executes maintainer ruling **丙** on objectstack-ai#17735 (ruling record `5724940904`,
batch objectstack-ai#151 item 2; verification record `5717306177`; maintainer
re-affirmation `5791879338` over ruling objectstack-ai#197 A's PR objectstack-ai#19270 path). The
fence notes `5756239563` and `5786373289` are cleared: PR objectstack-ai#19270 was
closed unmerged by the re-affirmation, and the census in claim
`5800589054` found every path clear. PR objectstack-ai#18608 (squash `681ebe4246`)
already discharged the earlier ruling's item 4 (the `check-generated.ts`
`why` string). This PR does steps 1–3 of 丙 and leaves step 4's list in
place. The witness ledger is the one exception, shrunk by three rows
(see Deviations).

⚠️ **Governed surfaces:** `AGENTS.md` and `docs/adr/**` (Tier H), plus
`.claude/hooks/**` (Tier S, comments only). This PR stays **draft** and
lands by the maintainer's hand.

## Step 3 first: the byte comparison decided the shape of this PR

Both producers were run once over one built tree,
`.cache/objectui-62597c588072` (objectui at pin
`62597c588072636e9c30ea35b3d89b1e46fd765d`, built by `pnpm
objectui:build`, `VERDICT command-exit 0`):

```text
$ node scripts/gen-sdui-manifest-node.mjs            # the new built-tree producer (this PR)
✓ wrote sdui.manifest.json (59 components, 85726 bytes, sha256 22c83c9ec701…)
$ PLAYWRIGHT_BROWSERS_PATH=SCRATCH/pw bash scripts/gen-sdui-manifest.sh   # the browser dump, as on main
✓ wrote 59 public blocks → packages/console/dist/sdui.manifest.json
$ cmp packages/console/dist/sdui.manifest.json sdui.manifest.json; echo CMP_EXIT=$?
CMP_EXIT=0
$ sha256sum packages/console/dist/sdui.manifest.json sdui.manifest.json
22c83c9ec70163559c2bd8f7b1613174d8660ad9949d15ed483a4189b7857c9a  packages/console/dist/sdui.manifest.json
22c83c9ec70163559c2bd8f7b1613174d8660ad9949d15ed483a4189b7857c9a  sdui.manifest.json
```

The outputs are **identical**, so the ruling's copy branch applies.
`build-console.sh` now copies the tracked `sdui.manifest.json` into
`packages/console/dist/`. `scripts/gen-sdui-manifest.sh`, `pnpm
sdui:manifest` and cut-rc's Playwright install step are retired. The
dump ran against the container's chromium 1194, exposed under the
revision name that playwright 1.62.1 asks for through a scratch
`PLAYWRIGHT_BROWSERS_PATH`. Nothing was installed. The dump script's
trailing ratchet did not run: it is guarded on the baseline file, which
this branch had already deleted, and that guard sits after the dump
wrote its file.

## Step 1: M1 is the standing producer

- **`scripts/gen-sdui-manifest-node.mjs`** takes no arguments.
- It derives the modules root `.cache/objectui-SHA12/apps/console` from
`.objectui-sha`.
- It refuses to run, with `pnpm objectui:build` as the remedy, when the
tree is missing, when the tree's HEAD is not the pin, or when the tree
is not built (`apps/console/node_modules/@object-ui/core/dist/index.js`
absent). It also refuses any argument, so the retired
`--objectui-version` and `--modules-root` fail loudly instead of being
ignored.
  - The temp-npm-install default is deleted.
- The runner file is written to its own `mkdtemp` dir and removed
afterwards. A resolve hook re-anchors bare specifiers to the modules
root, so module resolution is unchanged and nothing lands in the build
tree. Measured: 0 runner files in `apps/console`, 0 leftover temp dirs.
  - Output is deterministic: two runs, `cmp` identical.
- **`scripts/sdui-manifest.record.json`** now records `source:
built-tree`, `modulesRoot` and `objectuiWorkspaceVersion` (read from the
built `@object-ui/core/package.json`), and its `//` block is rewritten.
- **`scripts/check-sdui-manifest.mjs`** is re-keyed.
- The presence check now requires `source` (it must equal `built-tree`),
`modulesRoot` and `objectuiWorkspaceVersion`.
- Check 4 compares `objectuiWorkspaceVersion`, and the header prose and
every remedy line name `pnpm objectui:build && node
scripts/gen-sdui-manifest-node.mjs`.
- The self-test seed writes the new keys. One new row, `a record from
the retired npm-install route is RED`, raises the floor to 12.
- **npm-route prose rewritten** in: the generator header (the
dead-citation fact of objectstack-ai#18627 is restated without a number), the record's
`//` block, `build-console.sh`'s trailing reminder, the `AGENTS.md`
pin-move paragraph (located by content), `docs/releases-maintenance.md`
(the "After the pin moves" section, the pin-policy step 4 and the rc-cut
step 2), `scripts/bump-objectui.sh` (header, NEXT STEP text and the
not-on-main warning) and the `lint.yml` comment on the
`check-sdui-manifest` step.
- **Artefact regenerated at the pin:** 57 → **59** components (`box` and
`object-tree` added), 66,910 → **85,726** bytes, sha256 `49211fee7792…`
→ `22c83c9ec701…`.
- 19 components differ in their input-name set: 38 names appear only in
the new artefact and 3 only in the old.
  - `dataSource` is now on 15 components (it was on 0).
  - `actionType` replaces `type` on `action:button` and `action:icon`.
  - `flex.isContainer` is now `true`.
  - `dashboard.refreshInterval` became `refreshIntervalSeconds`.
- The rest are `object-kanban`/`object-calendar` inputs, plus
`text.align` and `text.variant`.

## Step 2: the parity ratchet retires

Removed:
`packages/spec/scripts/check-react-blocks-declaration-parity.ts`, its
test, `packages/spec/react-declaration-parity.baseline.json`, the gate's
only helper `packages/spec/scripts/manifest-prescription.ts` (the two
deleted files were its only importers), the
`check:react-declaration-parity` script, the `lint.yml` step, and the
cut-rc steps `Install a Playwright browser for the manifest dump` and
`Declaration-parity ratchet at the committed pin (ADR-0082 D4)`.

ADR-0082 decision 4 gains exactly one status line: 「retired 2026-09-18
by maintainer ruling on objectstack-ai#17735; the artefact stays for the CLI witness
and the freshness gate」. That is an amendment, not a rewrite.

Knock-on edits:

- `check:generated`'s `EXTERNAL_INPUT_REQUIRED` bucket is now empty. The
bucket and its reconciliation are kept, and the ledger test asserts `0
needing an external input`.
- `published-projection-choke-point.test.ts` loses the deleted file's
allowance row.
- `gen-sdui-manifest.sh` goes with its three tests
(`gen-sdui-manifest-cleanup`, `-collision` and `-write-target`), which
are also removed from `vitest.repo-tests.json`.
- `pnpm check:cross-package-test-inputs` reported two dispositions after
the deletion, and both are applied. It reported
`scripts/gen-sdui-manifest.sh` as an unheld glob for
`create-objectstack`, so it comes out of the declaration and
`turbo.json`. It reported that `check-generated-ledger.test.ts` no
longer reads outside its package, so it comes out of the spec repo-tests
list.

## Folded cards (ruling step 5)

objectstack-ai#18627 (dead citation in the generator header), objectstack-ai#18633
(`releases-maintenance.md` clause and the instruction that caused the
version skew) and objectstack-ai#18632 (the parity header's 「dumped from」 sentence)
are folded here. All three are already closed as not planned, each with
a pointer to this card, so there is nothing further to close. objectstack-ai#18407
stays open, and it is not addressed here. **objectstack-ai#14490 re-measure reading:**
the regenerated artefact has `actionType` on `action:button` and
`action:icon`, and neither block has an input named `type`. The artefact
also contains `object-tree` now.

## Changesets

- `skip-changeset` is the ruling's route for the scripts and the ADR
line.
- Because step 3's copy landed, this PR adds
`.changeset/sdui-manifest-one-producer.md` (`@objectstack/console:
patch`).
- Which labels to apply is the seat's call. I wrote none.

⚠️ **Premise correction for the changeset.** Ruling step 6 describes the
dist as gaining 「a file it already shipped from the browser dump」.
Measured, that is false. The published `@objectstack/console` 17.0.0,
17.3.0 and 17.4.0 tarballs contain **0** `sdui.manifest.json` (control:
`package/dist/index.html` 1 each). `pnpm run release` re-runs
`build-console.sh`, which recreates `dist/` from scratch, so the RC
cut's copy never reached a tarball. The changeset states that. It also
states that the console's `exports` map (`./package.json` only) keeps
the file unreachable through `exports` for now.

## Deviations, and why

1. **`packages/lint/src/sdui-jsx-baseline.json` is shrunk by 3 rows**,
although the dispatch listed it as untouched. With the regenerated
manifest, `flex` declares `isContainer`, so the 32 `jsx-not-a-container`
warnings no longer fire. The witness test (unedited) fails with 「STALE
ledger rows … delete these rows … in this same PR」. The rows were
deleted, none was added, and no count was raised, which is the ledger's
own shrink-only rule. The ruling's step 1 regeneration forces this.
2. **Comment-only edits outside the claimed file surface**, made because
the dispatch asked for no dangling reference:
- `.claude/hooks/guard-process-kill.sh` and its selftest said `pgrep -s`
teardown is "live in two tracked scripts", one of which this PR deletes.
- `scripts/pm/os-verify-lock.sh`, `scripts/publish-smoke.sh`,
`scripts/check-sdui-lockstep.mjs`,
`scripts/check-pnpm-filter-targets.mjs` and
`scripts/pnpm-filter-targets.mjs` (the `FOREIGN_SCOPES` reason string).
- `packages/spec/src/ui/react-blocks.ts` (a line comment naming the
deleted baseline).
- `docs/audits/2026-06-react-blocks-conformance.md` (a retirement note
above its run instructions).
3. `scripts/objectui-changeset-digest.mjs`'s self-test asserted that the
bump prints `pnpm sdui:manifest`. It now asserts the bump prints `node
scripts/gen-sdui-manifest-node.mjs`, `pnpm objectui:build` and `NEXT
STEP`.

## References kept on purpose (history, not pointers)

- `packages/spec/CHANGELOG.md` (release-owned).
- ADR-0082's body and addenda (amendment only).
- `docs/protocol-upgrade-guide.md`, and the `packages/spec/src`
narratives in `component.zod.ts` (×3), `conversions/registry.ts`,
`migrations/registry.ts` and
`retired-keys/17.ui__RecordDetailsProps__layout.ts`. These explain why a
past gate stayed green.
- `docs/audits/...` (dated record).
- Past-tense comments in `publish-smoke.sh`,
`publish-smoke-port-collision.test.ts`,
`scaffold-e2e-boot-probe.test.ts` and `lib/docs-import-surface.ts`.
- Fixture strings in `scripts/check-agent-test-spelling.mjs` and
`scripts/pm/ci-failure.mjs`.

## Acceptance notes

- `component.zod.ts` still has one forward-looking sentence: the
`check:react-declaration-parity` gate 「carries the spec↔objectui parity
burden going forward」. It is TSDoc on published spec source, so it was
left for the spec seat.
- The witness test's title still says 「57-component public tier」. The
test is unedited per the dispatch, and its assertion reads `length > 0`.

## Local verification

All results below were taken on head `b7d0b3693a`, the final commit,
after `git rev-parse --short HEAD`.

- **Gate union:**
- `node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack
--commands` derived 155 families.
- All 155 were run, each with its exit code recorded before any pipe,
and **all 155 exited 0**. That includes `check:pm-dispatch-gates` (1905
cases, run detached because it exceeds the foreground cap), plus
`check:dual-build-cjs-loads`, `check:lean-entry-closure` and
`check:type-check-debt` after a full `turbo run build
--filter='./packages/*' --filter='./packages/*/*'` (72/72 tasks).
- Reconciliation with `--ran` exited 0: 「155 derived, 155 run, 0
NOT-MEASURED, 0 UNRUN」.
- NOT MEASURED, as the derivation prints them: the 10 workflow-valued
families, the six CI jobs scheduled by these paths (Test Core, Temporal
Conformance, Dogfood Regression Gate, Dogfood Verify CLI, Build Core,
Console Pin Gate), and the workspace, examples and downstream type-check
programs. These belong to CI.
- **Lint:** eslint narrowed to the 12 changed lintable files,
`--no-inline-config --format json`.
  - The JSON reports 12 files, 0 errors and 0 warnings.
- This narrowing is safe because `eslint.config.mjs` enables no
type-aware linting (no `parserOptions.project`), and nothing imports a
deleted file. So no untouched file's verdict can move. The repo-wide
`pnpm lint` belongs to CI.
- Tests:
  - `@objectstack/lint` full `vitest run`: 108 files, 4121 tests passed.
- spec targeted run (`check-generated-ledger`,
`published-projection-choke-point`, `publish-smoke-port-collision`,
`publish-smoke-boot-failure`): 4 files, 38 tests passed.
- `@objectstack/vitest-filter-preflight` `config-wiring-sweep.test.ts`:
65 passed.
  - `@objectstack/spec typecheck` (src, scripts and test layer): exit 0.
- Self-tests: `bump-objectui.selftest.sh` 20/20,
`guard-process-kill.selftest.sh` 69/69, `os-verify-lock.sh --self-test`
pass, `check-sdui-manifest.mjs --self-test` 12 cases.
- Gate at the pin, with the objectui oracle: `node
scripts/check-sdui-manifest.mjs --require-objectui` exit 0, reporting
「@object-ui 17.6.0 is the version objectui 62597c588072… declares」.
- Ablation (one-shot, restored byte-exact by
`scripts/ablation-replace.mjs`): with the re-key reverted to
`['objectuiSha', 'sha256', 'components']`, the self-test reds on exactly
the new row (「a record from the retired npm-install route is RED —
expected RED, got GREEN」, exit 1). The restore leaves the blob equal to
HEAD `b6484613ce99` and `git diff HEAD` empty.
- Generator refusals, probed on a scratch copy (each exit 1, nothing
written): an argument, no tree, a tree at the wrong HEAD, and a tree at
the pin but not built.
- `build-console.sh`'s new block was exercised on fixtures: fresh
(copied, ✓ line), stale record pin (copied, ⚠ with the regeneration
step) and missing artefact (exit 1). A full `pnpm objectui:build` on
this branch's first commit also passed; that run's ending came before
the copy block existed.

## 维护者速读(草稿)

**改了什么** —— `sdui.manifest.json` 只剩一个生产者:`gen-sdui-manifest-node.mjs`
直接读 pin 上已构建好的 objectui 树,不再从 npm 装旧包。声明对齐门禁(ADR-0082 D4)和浏览器 dump
一起退役。console 构建把这份受跟踪的 manifest 原样拷进 dist。

**为什么改** —— 裁决 丙。实测两个生产者在同一棵已构建树上逐字节相同(`cmp` 退出码
0),所以浏览器那一路没有存在的必要。manifest 重新生成后,缺的 `dataSource`、`actionType` 等 38
个输入全部回来了。

**风险与代价(含回滚)** —— 以后升 pin 要先 `pnpm objectui:build`(约 10 分钟),再跑生成器。每个 PR
的门禁照旧离线,不变。console 包会第一次真的带上这个文件:此前发布的 17.0.0、17.3.0、17.4.0 都没有。但包的
`exports` 只导出 `./package.json`,CLI 现在还读不到它,所以对用户没有行为变化。回滚就是 revert 这个
PR。

**席位意见** ——

**你要做的** —— 审阅后亲手合并(治理面:AGENTS.md、ADR)。

---
_Generated by [Claude
Code](https://claude.ai/code/session_013RDBh5DqXd2xnLwvHLgLFr)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Sep 28, 2026
…s / related_list with one true describe shared with record:quick_actions (objectstack-ai#19913)

Fixes objectstack-ai#18159

Clause-②: yes

<sub>Rewritten short by the `domain:spec#5` seat (2026-09-23T19:59Z).
The dev reports are on objectstack-ai#18159 (`5798750532`, `5800008407`, `5800978880`,
`5801656924`); the earlier long body is in the edit history.</sub>

`requiredPermissions` is now declared on `record:details`,
`record:highlights` and `record:related_list`, with the shape
`record:quick_actions` already has (`z.array(z.string()).optional()`).
Ruling: batch objectstack-ai#197 item 2, letter A (`5749268463`), after objectui#10058
became installable at `.objectui-sha` `62597c588072`.

## One describe, four blocks (seat ruling `5798783314`)

The ruling asks for the same describe as `record:quick_actions`. That
published describe said "…every named permission **on this object**",
which is false for the renderer at the pin: the check is
`hasCapabilities`, and the renderer's own comment says the capability
"is not object-scoped". So all four blocks now share ONE describe, from
one constant (`RECORD_BLOCK_REQUIRED_PERMISSIONS_DESCRIPTION`). **The
published `record:quick_actions` describe changes; its shape does not.**
The describe states:
- the names are ADR-0066 capabilities, not object actions;
- the user must hold all of them;
- when one is missing, the block shows an insufficient-permissions
notice instead of its content;
- it is presentation only, and the data API still serves the data;
- a client that cannot resolve the user's capabilities renders the block
(fails open).

The renderer lines behind each clause are in the dev report
`5800008407`.

## Other changes

- The texts that said the key is "deliberately NOT declared" are
rewritten: the `RecordDetailsProps` family header, the related-list and
highlights pointers, and the test header.
- The absence pins are now accept pins: a parse probe and `.shape`
enumeration per block, with `aria` and `fields` as lit controls, plus a
pin that the four JSON Schemas of the key are identical. Removing the
three declarations turns 11 of 25 pins red.
- `authorable-surface/ui.json` and `component.mdx` are regenerated.

## `Check Changeset` is red on purpose

The pending note `.changeset/18159-record-block-field-security-pair.md`
(from PR objectstack-ai#19185) said the third key "is deliberately NOT declared". This
PR makes that false, so the PR corrects it. That is a DELIBERATE
CORRECTION under `check-empty-changeset.mjs`: the check stays red, and
the correction awaits the maintainer's written confirmation on this PR.
The line to confirm is quoted verbatim in `5801679846`. `Check
Changeset` is not a required context.

## Fix round 2026-09-25: `origin/main` merged, objectui pin re-measured

Fix round for `domain:spec#4` (session
`session_019c3Hi6ZMU1p6m6aA6Bz45d`), new head `b19ac16c77`. The merge
queue dequeued the PR. `Type Check · source gates` failed at
`check:objectui-pin-citations`: objectstack-ai#20036 (`0bf85eaae6`) moved
`.objectui-sha` from `62597c588072` to `f8a9d0fb0596`, and the shared
`requiredPermissions` docblock in `component.zod.ts` still asserted the
old pin. This round adds three commits and changes nothing else:

- `62decd77dd` merges `origin/main` at `66960564d9` with
`scripts/pm/os-regen-merge.sh` (merge commit; no rebase or force-push).
It had no text conflict.
- `a3075b6ace` regenerates `packages/spec/authorable-surface/ui.json` on
the merged tree. In that file the merge driver kept this branch's side
and dropped main's 13 `DocNavItem` keys. The regenerated file has main's
keys plus this PR's three `requiredPermissions` keys, and nothing else.
- `b19ac16c77` re-measures the docblock at the new pin. It updates the
sha and the anchors together (10 lines replaced, 0 added).

### What was measured

objectui at `f8a9d0fb0596f4521076628e2bbfe27e6ce67d52` was read from a
scratch fetch of both pins. The seven cited files match the codeload
tarball of the same commit byte for byte. All 21 anchors in the docblock
were re-read. **At the new pin, each cited range holds the same text it
held at `62597c588072`.** No read point changed meaning or disappeared.

- `record-details.tsx` shifted +1 (one new import line).
`record-related-list.tsx` shifted +34 (an import block and the
props-type docblock). Nine anchors get new numbers.
- `record-highlights.tsx`, `record-quick-actions.tsx`,
`MePermissionsProvider.tsx`, `PermissionProvider.tsx` and
`usePermissions.ts` did not change between the two pins, so their twelve
anchors keep their numbers.

| Anchor, old → new | First line of the range at `f8a9d0fb0596` |
|---|---|
| `record-details.tsx:234` → `:235` | `if (required.length > 0 &&
!perms.hasCapabilities(required)) {` |
| `record-details.tsx:223` → `:224` | `* capability is not
object-scoped, and the old && objectName conjunct was` |
| `record-details.tsx:234-242` → `:235-243` | `if (required.length > 0
&& !perms.hasCapabilities(required)) {` |
| `record-details.tsx:186` → `:187` | `if (!ctx) {` |
| `record-related-list.tsx:242` → `:276` | `if (required.length > 0 &&
!perms.hasCapabilities(required)) {` |
| `record-related-list.tsx:229` → `:263` | `* capability is not
object-scoped. This site never carried the` |
| `record-related-list.tsx:242-250` → `:276-284` | `if (required.length
> 0 && !perms.hasCapabilities(required)) {` |
| `record-related-list.tsx:184` → `:218` | `if (!objectName) {` |
| `record-related-list.tsx:202` → `:236` | `if (perms.isLoaded &&
!perms.can(objectName, 'read')) {` |
| `record-highlights.tsx:93` (unchanged) | `const highlightsAllowed =
required.length === 0 \|\| perms.hasCapabilities(required);` |
| `record-highlights.tsx:77` (unchanged) | `* capability is not
object-scoped, and the old && objectName conjunct was` |
| `record-highlights.tsx:151-164` (unchanged) | `if (!highlightsAllowed)
{` |
| `record-highlights.tsx:146-149` (unchanged) |
`useRegisterHighlightFields(` |
| `record-quick-actions.tsx:263` (unchanged) | `if (required.length > 0
&& !perms.hasCapabilities(required)) {` |
| `record-quick-actions.tsx:252` (unchanged) | `* capability is not
object-scoped, and the old && objectName guard was a` |
| `record-quick-actions.tsx:263-271` (unchanged) | `if (required.length
> 0 && !perms.hasCapabilities(required)) {` |
| `MePermissionsProvider.tsx:416`, and the later `:416` (unchanged) |
`return required.every((p) => held.has(p));` |
| `MePermissionsProvider.tsx:414` (unchanged) | `if
(!Array.isArray(perms)) return true;` |
| `PermissionProvider.tsx:77` (unchanged) | `const ALL_CAPABILITIES:
PermissionContextValue['hasCapabilities'] = () => true;` |
| `usePermissions.ts:45` (unchanged) | `hasCapabilities: () => true,` |

(The inner backticks around `&& objectName` in the three docblock lines
are left out of the table.)

One observation from the re-read, which changes no anchor. The
props-type docblock that `record-related-list.tsx` gained (`:89-92`)
says no block the contract maps onto this tag declares
`requiredPermissions`, and says not to reopen the type to admit it. This
PR makes that sentence stale. That is the objectui half ruled **A** on
objectstack-ai/objectui#10281, and it moves to the `domain:ui` seat. The
renderer's read of the key (`:240-242`, through a cast) and its gate
(`:276`) are unchanged.

### Gates, on head `b19ac16c77`

- `check:objectui-pin-citations` exits 0 on `--self-test`, on the
ordinary run and on `--verify-anchors`, with objectui at the new pin
supplied through `OBJECTUI_ROOT`. The ordinary run prints: "48 asserting
objectui pin citation(s) match .objectui-sha (f8a9d0fb0), 40 historical
citation(s) recorded and not checked, across 1555 spec source(s). 7
anchor content assertion(s) verified against objectui at f8a9d0fb0". CI
has no objectui checkout, so it verifies the sha label only.
- `pnpm --filter @objectstack/spec build`, then `check:generated`: all
15 generated artifacts are up to date. `typecheck` exits 0. The full
spec suite: 535 files, 15727 passed, 2 todo.
- `node scripts/pm/dispatch-gates.mjs --commands` derived 107 commands
for this change set. All 107 ran, and `--ran` reconciles 107 of 107 with
recorded exit codes and 0 NOT MEASURED. Seven of them first exited 3 (no
build to read). They were re-run green after building the lint closure,
the client-react closure and then every package. 106 exit 0. The one
exit 1 is `check-empty-changeset.mjs`. That is the deliberate correction
described above, which the maintainer confirmed at head `aeb6a57456`
(`5823706830`).
- The changesets are byte-identical to that head: `git diff --exit-code
aeb6a57 b19ac16 --
.changeset/18159-record-block-field-security-pair.md
.changeset/18159-record-block-required-permissions.md` exits 0. The
blobs are `d502a9a04c6a` and `80546d851168` on both heads. The test file
and `component.mdx` are byte-identical to that head as well.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01Sfe5YjBLwB9J3y8fvm2xq1

---------

Co-authored-by: Claude <noreply@anthropic.com>

This branch was successfully deployed

1 active deployment
Preview — 7b811673 Deployed Jan 31, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file size/xs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant