Patch Changes
-
#1982
0e6e9fbThanks @whitphx! - Remove web-vitals from @stlite/browser and @stlite/react that don't use it -
#1989
8746191Thanks @whitphx! - Configure a 1-weekexclude-newercooldown for uv resolution to reduce exposure to PyPI supply-chain attacks when resolving the Python dependencies used to build the kernel's Pyodide wheels.
What's Changed
🏕 Updates
- Fix changeset-check job by @whitphx in #1983
- Introduce uv workspace with frozen CI sync by @whitphx in #1981
- Dev/remove web vitals from unused packages by @whitphx in #1982
- Add uv dependency cooldown to mitigate supply-chain risk by @whitphx in #1989
- Use GitHub App token in dependabot-changeset workflow by @whitphx in #1990
- Version Packages by @whitphx-changesets-bot[bot] in #1987
👒 Dependencies
- Bump glob from 13.0.0 to 13.0.6 by @dependabot[bot] in #1986
- Bump actions/github-script from 7.0.1 to 8.0.0 by @dependabot[bot] in #1985
- Bump dependabot/fetch-metadata from 2.3.0 to 3.0.0 by @dependabot[bot] in #1984
Full Changelog: https://github.com/whitphx/stlite/compare/@stlite/browser@1.7.0...@stlite/browser@1.7.1