Skip to content

chore(deps): bump the npm-minor group in /app with 5 updates - #212

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/app/npm-minor-03db6dc1ef
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/app/npm-minor-03db6dc1ef

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm-minor group in /app with 5 updates:

Package From To
@tauri-apps/api 2.11.1 2.12.1
@tauri-apps/plugin-dialog 2.7.3 2.8.1
@tauri-apps/plugin-process 2.3.1 2.4.0
@tauri-apps/plugin-updater 2.12.0 2.13.1
@tauri-apps/cli 2.11.5 2.12.1

Updates @tauri-apps/api from 2.11.1 to 2.12.1

Release notes

Sourced from @​tauri-apps/api's releases.

@​tauri-apps/api v2.12.1

All found vulnerabilities were already reviewed and decided to be ignored
2 ignored: 2 high

[2.12.1]

Bug Fixes

  • c9a3cb892 (#16166 by @​FabianLars) The macos-private-api feature flag / macOSPrivateAPI tauri.conf.json value is no longer required to use transparency or fullscreen on macOS.
$ pnpm build && cd ./dist && pnpm publish --access public --loglevel debug --no-git-checks
$ rollup -c --configPlugin typescript
�[36m
�[1m./src/app.ts, ./src/core.ts, ./src/dpi.ts, ./src/event.ts, ./src/image.ts, ./src/index.ts, ./src/menu.ts, ./src/mocks.ts, ./src/path.ts, ./src/tray.ts, ./src/webview.ts, ./src/webviewWindow.ts, ./src/window.ts�[22m → �[1m./dist, ./dist�[22m...�[39m
�[32mcreated �[1m./dist, ./dist�[22m in �[1m997ms�[22m�[39m
�[36m
�[1msrc/index.ts�[22m → �[1m../../crates/tauri/scripts/bundle.global.js�[22m...�[39m
�[32mcreated �[1m../../crates/tauri/scripts/bundle.global.js�[22m in �[1m1.5s�[22m�[39m
GET https://run-actions-2-azure-eastus.actions.githubusercontent.com/210//idtoken/dd253aee-436e-8e22-8c02-25aaaa05b17c/69013391-05d6-5397-b35a-e76c0a237b30?api-version=2.0&audience=npm%3Aregistry.npmjs.org 200 336ms
📦 @tauri-apps/api@2.12.1 → https://registry.npmjs.org/
GET https://run-actions-2-azure-eastus.actions.githubusercontent.com/210//idtoken/dd253aee-436e-8e22-8c02-25aaaa05b17c/69013391-05d6-5397-b35a-e76c0a237b30?api-version=2.0&audience=sigstore 200 107ms
Signed provenance statement with source and build information
✅ Published package @tauri-apps/api@2.12.1

@​tauri-apps/api v2.12.0

All found vulnerabilities were already reviewed and decided to be ignored
2 ignored: 2 high

[2.12.0]

... (truncated)

Commits

Updates @tauri-apps/plugin-dialog from 2.7.3 to 2.8.1

Release notes

Sourced from @​tauri-apps/plugin-dialog's releases.

dialog-js v2.8.1

[2.8.1]

  • 569ee82c Fix the docs.rs build for Android: the build script now detects docs.rs through the DOCS_RS environment variable, since cfg(docsrs) is never set for build scripts.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-dialog@2.8.1
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 3.5kB README.md
npm notice 7.1kB dist-js/index.cjs
npm notice 15.1kB dist-js/index.d.ts
npm notice 7.0kB dist-js/index.js
npm notice 11B dist-js/init.d.ts
npm notice 657B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-dialog
npm notice version: 2.8.1
npm notice filename: tauri-apps-plugin-dialog-2.8.1.tgz
npm notice package size: 6.8 kB
npm notice unpacked size: 34.3 kB
npm notice shasum: f29f3c28862a1ed767b6fd241f34abf26129f88f
npm notice integrity: sha512-/DtE3B62JgpYu[...]phsKnb+738Dmw==
npm notice total files: 7
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=3028120915
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-dialog@2.8.1

dialog v2.8.1

[2.8.1]

  • 569ee82c Fix the docs.rs build for Android: the build script now detects docs.rs through the DOCS_RS environment variable, since cfg(docsrs) is never set for build scripts.

... (truncated)

Commits
  • d4835d0 publish new versions (#3660)
  • 569ee82 fix: mobile docs.rs builds
  • 25f3874 chore(deps): update dependency eslint-plugin-security to v4.1.0 (#3661)
  • 2fd4bed chore(autostart): update auto-launch to 0.6 (#3546)
  • e511284 publish new versions (#3647)
  • ce59e96 docs(log): remove unrelated single-instance comment from log readme
  • 29130c2 ci: run clippy on all platforms (#3650)
  • 4353819 chore: add changefile to re-release plugin-http npm package as 2.8.0 (#3656)
  • ec14142 chore(deps): update dependency @​types/node to v24 (#3649)
  • 90b9869 chore(deps): update rust crate dirs to v7 (#3573)
  • Additional commits viewable in compare view

Updates @tauri-apps/plugin-process from 2.3.1 to 2.4.0

Release notes

Sourced from @​tauri-apps/plugin-process's releases.

stronghold-js v2.4.0

[2.4.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.
npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-stronghold@2.4.0
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 4.7kB README.md
npm notice 19.4kB dist-js/index.cjs
npm notice 21.1kB dist-js/index.d.ts
npm notice 19.2kB dist-js/index.js
npm notice 750B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-stronghold
npm notice version: 2.4.0
npm notice filename: tauri-apps-plugin-stronghold-2.4.0.tgz
npm notice package size: 8.7 kB
npm notice unpacked size: 66.0 kB
npm notice shasum: 47b370840be057acd7d8f76046a9978a622cfcbe
npm notice integrity: sha512-5FIKueS+4xs66[...]j7Mzwt0NX4r1A==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=2969525576
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-stronghold@2.4.0

stronghold v2.4.0

[2.4.0]

  • ae3c808e (#3602) The plugin's global API script (used with app.withGlobalTauri) now resolves the core API from window.__TAURI__ instead of bundling its own copy of @tauri-apps/api. Values created with the core API are now accepted by plugin APIs in global mode (e.g. an Image from window.__TAURI__.image passed to clipboardManager.writeImage, which previously failed the instanceof check against the plugin's private copy), and the script is considerably smaller.
  • 9b29b601 Update MSRV to 1.90 to match tauri.
  • a87a3c7d Update documentation.

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​tauri-apps/plugin-process since your current version.


Updates @tauri-apps/plugin-updater from 2.12.0 to 2.13.1

Release notes

Sourced from @​tauri-apps/plugin-updater's releases.

updater-js v2.13.1

[2.13.1]

  • ecd3273e (#3480 by @​renovate) Updated windows-rs dependencies:

    • deep-link: updated windows-registry to 0.6 and windows-result to 0.4. The public Error::Windows variant wraps windows_result::Error; applications using this type directly should update their windows-result dependency.
    • opener: updated windows to 0.62. The public Error::Win32Error variant wraps windows::core::Error; applications using this type directly should update their windows dependency.
    • single-instance: updated windows-sys to 0.61
    • updater: updated windows-sys to 0.61
  • 90b9869e (#3573 by @​renovate) Updated dirs to v7

  • 22e286f3 (#3501 by @​renovate) Updated dependency infer to 0.22

npm warn publish npm auto-corrected some errors in your package.json when publishing.  Please run "npm pkg fix" to address these errors.
npm warn publish errors corrected:
npm warn publish "repository" was changed from a string to an object
npm warn publish "repository.url" was normalized to "git+https://github.com/tauri-apps/plugins-workspace.git"
npm notice
npm notice 📦  @tauri-apps/plugin-updater@2.13.1
npm notice Tarball Contents
npm notice 888B LICENSE.spdx
npm notice 3.2kB README.md
npm notice 6.7kB dist-js/index.cjs
npm notice 7.1kB dist-js/index.d.ts
npm notice 6.6kB dist-js/index.js
npm notice 659B package.json
npm notice Tarball Details
npm notice name: @tauri-apps/plugin-updater
npm notice version: 2.13.1
npm notice filename: tauri-apps-plugin-updater-2.13.1.tgz
npm notice package size: 4.8 kB
npm notice unpacked size: 25.1 kB
npm notice shasum: 2ad227ba05293fe34c5c59c0ff8a1cd690c8e9a8
npm notice integrity: sha512-+STDzJ0sdQLIm[...]/AJz0jxysytiw==
npm notice total files: 6
npm notice
npm notice npm tokens that bypass 2FA are being restricted for account changes and direct publishing. Learn how to prepare: https://gh.io/npm-gat-bypass2fa-deprecation
npm notice Publishing to https://registry.npmjs.org/ with tag latest and public access
npm notice publish Signed provenance statement with source and build information from GitHub Actions
npm notice publish Provenance statement published to transparency log: https://search.sigstore.dev/?logIndex=3005269671
npm notice Your package is being processed and may take a few minutes to become available.
+ @tauri-apps/plugin-updater@2.13.1

updater v2.13.1

... (truncated)

Commits
  • e511284 publish new versions (#3647)
  • ce59e96 docs(log): remove unrelated single-instance comment from log readme
  • 29130c2 ci: run clippy on all platforms (#3650)
  • 4353819 chore: add changefile to re-release plugin-http npm package as 2.8.0 (#3656)
  • ec14142 chore(deps): update dependency @​types/node to v24 (#3649)
  • 90b9869 chore(deps): update rust crate dirs to v7 (#3573)
  • 22e286f chore(deps): update rust crate infer to 0.22 (#3501)
  • ecd3273 chore(deps): update windows-rs and webview2 crates (#3480)
  • aa2cc64 fix(android): Migrate Gradle scripts to compilerOptions DSL (#3478)
  • a2364a5 fix: integration test
  • Additional commits viewable in compare view

Updates @tauri-apps/cli from 2.11.5 to 2.12.1

Release notes

Sourced from @​tauri-apps/cli's releases.

@​tauri-apps/cli v2.12.1

[2.12.1]

Enhancements

Dependencies

  • Upgraded to tauri-cli@2.12.1

@​tauri-apps/cli v2.12.0

[2.12.0]

New Features

  • f6c1eb253 (#15401) Added bundle.windows.bundleVCRuntime to copy the Visual C++ runtime DLLs into Windows MSI and NSIS installers. The bundler locates the runtime through VCTOOLS_REDIST_DIR or the bundled vswhere.exe.

  • f76b1d3ae (#15644) The bundler now prints the size of each generated bundle next to its path in the Finished N bundles at: output (directories such as macOS .app bundles are measured recursively).

  • af465eae1 (#15619) Add a --no-binary-patching flag to tauri build and tauri bundle. When set, the bundler skips patching the main executable with bundle type information (and the subsequent re-signing), leaving an already-signed binary untouched. Patching is only required when shipping multiple bundle types per platform that should each update with their own installer format.

  • 0646cc162 (#15620) Add a --fit option to tauri icon to accept non-square source images. --fit cover center-crops the source to a square (clipping the longer side) and --fit contain pads the shorter side with transparency. Non-square sources without --fit keep erroring, now with a hint pointing to the flag.

  • f6c1eb253 (#15401) Added build.windows.staticVCRuntime to control MSVC static runtime linking. The STATIC_VCRUNTIME environment variable is now deprecated and emits a migration warning when used.

  • f45ec0dcf Record the app version in the trusted comment of updater signatures, so a signed artifact is bound to the version it was released as.

    An update endpoint response is not signed, and the signature only covers the downloaded artifact, so the announced version on its own does not prove which release the url and signature point at. minisign covers the trusted comment with its global signature, which lets the updater plugin compare the two and reject a response that pairs a version number with a different release. Enable requireSignedVersion in the updater plugin configuration to enforce this.

    tauri build fills the version in automatically, and tauri plugin add updater now enables requireSignedVersion for the project it is adding the plugin to. tauri signer sign gains an --app-version flag for signing updater artifacts by hand, and warns when it is omitted.

Enhancements

  • e19121427 (#15993) Don't always rewrite Cargo.toml file from CRLF line endings to LF

  • aebf38c84 (#15694) Migrate the Android Gradle scripts from the deprecated kotlinOptions DSL to compilerOptions, which is accepted by both Kotlin Gradle Plugin 1.9.x and 2.x. This lets projects move to Kotlin 2.x without hitting the hard error that 2.3+ raises on the old DSL.

    This increased the minimum supported Gradle version to 8.13, if your gradle is on an earlier version, delete src-tauri/gen/android/gradle/wrapper/gradle-wrapper.properties and re-run tauri android init to update it.

  • d89d8fa62 (#15780) Warn during Android commands (init/dev/build) when the active Java version is too new for the Gradle version the project uses (e.g. Java 27 against the Gradle 9.6.1 the template ships, or Java 25 against a project still on Gradle 8.14), instead of letting the build fail later with a cryptic error. The warning points to the Gradle/Java compatibility matrix and suggests a supported JDK.

  • c3d21bd60 (#15730) Use Theme.Material3.DayNight.NoActionBar instead of Theme.MaterialComponents.DayNight.NoActionBar when running tauri android init

  • f654f470c (#15862) Update template to use targetSdk = 37

  • cdaf7eab6 (#15765) Clarify that the tauri init frontend commands run before tauri dev and tauri build, and can be left empty when they are not needed.

  • d0f38df06 (#15997) When stdin is not a terminal, tauri init now automatically skips prompts, avoiding IO errors in CI and scripts. This eliminates the need to pass --ci explicitly in non-interactive environments.

  • ca160ad48 (#15895) tauri build now warns when productName is still set to the default tauri-app, since it names the generated bundles and is written into install paths and metadata that are expected to be unique to your application. The config documentation for productName now lists what the field controls on each platform, and identifier's documentation notes that the default value is rejected.

  • 010f06bae (#15737) Document the TAURI_SIGNING_PRIVATE_KEY_PATH environment variable and clarify that TAURI_SIGNING_PRIVATE_KEY accepts a string or a path for the build and bundle command but must be the literal key string for the signer sign command, both in ENVIRONMENT_VARIABLES.md and in the signer generate command output.

Bug Fixes

  • 9bad06b9f (#16096) tauri capability new and tauri permission new now accept an --out path to a file that does not exist yet, trim comma-separated prompt answers (so fs:default, core:default works), report invalid permissions as errors instead of panicking, and reject identifiers that are not valid file names (such as ../../x), which previously let them write outside of the capabilities or permissions directory.
  • 9642b3087 (#16117) tauri add now honors --tag, --rev and --branch for official plugins instead of silently installing the registry version, and rejects passing more than one of them. With npm, the JS package requirement is now ~<version> like the other package managers, instead of >=<version> which allowed a later major version.
  • cada1cd4f (#16105) Fix Android dev server port forwarding: adb reverse --list is now matched on the exact port (so tcp:80 no longer matches tcp:8080), stale forwards on other connected devices are actually removed, and the forward verification gives up with a warning after a few attempts instead of retrying forever.
  • d5bd04658 (#16111) Fix bundle > android > debugApplicationIdSuffix being written to the signingConfigs debug block instead of the buildTypes one, and keep the existing content of single-line debug blocks such as getByName("debug") { isDebuggable = true } instead of dropping it.
  • ba17da2e5 (#16101) tauri icon now generates 72x72 Android hdpi launcher icons (previously 49x49) and writes the Android launcher background color in #RRGGBB/#AARRGGBB notation instead of the raw CSS color string, which Android rejected or misread. Invalid SVG sources and --png 0 now return an error instead of panicking.
  • 272842a57 (#16128) Fix error messages that printed placeholders such as {t} literally instead of the value, e.g. "Could not find an Android device matching {t}".
  • 10ad4e54e (#16127) The Bash completions generated by tauri completions no longer replace the completions of cargo, npm, pnpm, yarn, bun and deno. They now define a _tauri_cli function registered only for the tauri and cargo-tauri commands. Generating completions when running the cargo-tauri binary directly no longer panics.

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the npm-minor group in /app with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [@tauri-apps/api](https://github.com/tauri-apps/tauri) | `2.11.1` | `2.12.1` |
| [@tauri-apps/plugin-dialog](https://github.com/tauri-apps/plugins-workspace) | `2.7.3` | `2.8.1` |
| [@tauri-apps/plugin-process](https://github.com/tauri-apps/plugins-workspace) | `2.3.1` | `2.4.0` |
| [@tauri-apps/plugin-updater](https://github.com/tauri-apps/plugins-workspace) | `2.12.0` | `2.13.1` |
| [@tauri-apps/cli](https://github.com/tauri-apps/tauri) | `2.11.5` | `2.12.1` |


Updates `@tauri-apps/api` from 2.11.1 to 2.12.1
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](https://github.com/tauri-apps/tauri/compare/@tauri-apps/api-v2.11.1...@tauri-apps/api-v2.12.1)

Updates `@tauri-apps/plugin-dialog` from 2.7.3 to 2.8.1
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@dialog-v2.7.3...dialog-v2.8.1)

Updates `@tauri-apps/plugin-process` from 2.3.1 to 2.4.0
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@os-v2.3.1...os-v2.4.0)

Updates `@tauri-apps/plugin-updater` from 2.12.0 to 2.13.1
- [Release notes](https://github.com/tauri-apps/plugins-workspace/releases)
- [Commits](tauri-apps/plugins-workspace@updater-v2.12.0...updater-v2.13.1)

Updates `@tauri-apps/cli` from 2.11.5 to 2.12.1
- [Release notes](https://github.com/tauri-apps/tauri/releases)
- [Commits](https://github.com/tauri-apps/tauri/compare/@tauri-apps/cli-v2.11.5...@tauri-apps/cli-v2.12.1)

---
updated-dependencies:
- dependency-name: "@tauri-apps/api"
  dependency-version: 2.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor
- dependency-name: "@tauri-apps/plugin-dialog"
  dependency-version: 2.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor
- dependency-name: "@tauri-apps/plugin-process"
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor
- dependency-name: "@tauri-apps/plugin-updater"
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: npm-minor
- dependency-name: "@tauri-apps/cli"
  dependency-version: 2.12.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: npm-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 4, 2026
@dependabot
dependabot Bot requested a review from Muawiya-contact as a code owner October 4, 2026 09:33
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 4, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants