Skip to content

Bump axe-core from 4.12.1 to 4.13.0 in /sandbox/browser-web-v1 - #31

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/sandbox/browser-web-v1/axe-core-4.13.0
Open

Bump axe-core from 4.12.1 to 4.13.0 in /sandbox/browser-web-v1#31
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/sandbox/browser-web-v1/axe-core-4.13.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 15, 2026

Copy link
Copy Markdown

Bumps axe-core from 4.12.1 to 4.13.0.

Release notes

Sourced from axe-core's releases.

Release 4.13.0

In summary, this release adds:

  1. Support Element Internals: A modern way for building accessible component libraries Axe-core is the first accessibility tool to support this major new web feature! Thanks to RedHat and Adobe for working with us to figure out the right way forward.

  2. A new Swedish translation, thanks to our a community contribution

  3. A new Finish contribution (not open source), thanks to our Scandinavian partner

  4. 10 False positives closed, including all the critical ones!

  5. And 13 updates to get Axe-core consistent with the latest web standards

This release is one of the bigger changes we've done in a few years, so likely issue numbers are going to change in adopting this version.

Features

  • aria-actions: add aria-actions to allowed ARIA attributes (#5200) (029655d), closes #4584 #5199, references #5215 #5215
  • aria-allowed-attr: flag deprecated ARIA attributes as needs-review (#5246) (518f3cc), closes #3341
  • aria-prohibited-attr: allow many elements to be named and disallow label and body from being named (#5259) (d8b1ea5)
  • aria-roles: add sectionheader and sectionfooter roles (#5238) (c36c109), closes #4734, references #4734
  • aria/get-aria-value: new function to get aria values of a node (#5109) (a7d8f3e), references #5042
  • aria/has-attr-value: new function to check if node has aria value (#5136) (61f2624), references #5109
  • aria: support role=image as equivalent to role=img (#5248) (5aa8aaf), closes #4656, references #5272
  • checks/aria: support ARIA element internals properties (#5172) (9b7f754)
  • checks/label: support ARIA element internals properties (#5170) (21c5f8b)
  • checks/navigation: support ARIA element internals properties (#5167) (2c3a98f)
  • commons/aria: support ARIA element internals properties (#5171) (31f09e7)
  • commons/dom: support ARIA element internals properties (#5163) (f0a12cf)
  • commons/forms: support ARIA element internals properties (#5165) (27a4686)
  • commons/matches/fromPrimative: deprecate in favor of correct spelling (#5270) (31cfb2e)
  • commons/text: support ARIA element internals properties (#5169) (e841a33)
  • commons/text: support form-associated labels via element internals (#5182) (57cfe0a), closes #5045, references #5170 #5039 #5151 #5039
  • dom/getResolvedRefs: new function to get the resolved virtual nodes of idrefs (#5151) (489cdea), references #5109
  • element-internals: enable ElementInternals by default (#5284) (2740d42), closes #5277
  • i18n: Add Swedish locale (#5190) (dcd13f2), references #5189
  • matches: add inSectioningContent, hasChild, and isSummaryForDetails matches (#5262) (c47cdcd)
  • rules: support ARIA element internals properties (#5168) (065baf7)
  • standards/ariaAttrs: add caseInsensitive property for attributes (#5224) (bcd791c)

Bug Fixes

  • aria-allowed-role: allow roles on a non-details summary (#5242) (3bd9875), closes #3911, references #3443 #3911
  • aria-allowed-role: restrict figure roles with child figcaption (#5240) (178a635), closes #3443
  • aria-prohibited-attr: visible aria-labelledby requires review only (#5285) (fd6fa9f)
  • axe.d.ts: make enabled property of RuleMetadata optional (#5129) (90fce18)
  • color-contrast: fix various stacking context bugs (#5214) (d5e5b04), references #8 #5213

... (truncated)

Changelog

Sourced from axe-core's changelog.

4.13.0 (2026-08-05)

Features

  • aria-actions: add aria-actions to allowed ARIA attributes (#5200) (029655d), closes #4584 #5199, references #5215 #5215
  • aria-allowed-attr: flag deprecated ARIA attributes as needs-review (#5246) (518f3cc), closes #3341
  • aria-prohibited-attr: allow many elements to be named and disallow label and body from being named (#5259) (d8b1ea5)
  • aria-roles: add sectionheader and sectionfooter roles (#5238) (c36c109), closes #4734, references #4734
  • aria/get-aria-value: new function to get aria values of a node (#5109) (a7d8f3e), references #5042
  • aria/has-attr-value: new function to check if node has aria value (#5136) (61f2624), references #5109
  • aria: support role=image as equivalent to role=img (#5248) (5aa8aaf), closes #4656, references #5272
  • checks/aria: support ARIA element internals properties (#5172) (9b7f754)
  • checks/label: support ARIA element internals properties (#5170) (21c5f8b)
  • checks/navigation: support ARIA element internals properties (#5167) (2c3a98f)
  • commons/aria: support ARIA element internals properties (#5171) (31f09e7)
  • commons/dom: support ARIA element internals properties (#5163) (f0a12cf)
  • commons/forms: support ARIA element internals properties (#5165) (27a4686)
  • commons/matches/fromPrimative: deprecate in favor of correct spelling (#5270) (31cfb2e)
  • commons/text: support ARIA element internals properties (#5169) (e841a33)
  • commons/text: support form-associated labels via element internals (#5182) (57cfe0a), closes #5045, references #5170 #5039 #5151 #5039
  • dom/getResolvedRefs: new function to get the resolved virtual nodes of idrefs (#5151) (489cdea), references #5109
  • element-internals: enable ElementInternals by default (#5284) (2740d42), closes #5277
  • i18n: Add Swedish locale (#5190) (dcd13f2), references #5189
  • matches: add inSectioningContent, hasChild, and isSummaryForDetails matches (#5262) (c47cdcd)
  • rules: support ARIA element internals properties (#5168) (065baf7)
  • standards/ariaAttrs: add caseInsensitive property for attributes (#5224) (bcd791c)

Bug Fixes

  • aria-allowed-role: allow roles on a non-details summary (#5242) (3bd9875), closes #3911, references #3443 #3911
  • aria-allowed-role: restrict figure roles with child figcaption (#5240) (178a635), closes #3443
  • aria-prohibited-attr: visible aria-labelledby requires review only (#5285) (fd6fa9f)
  • axe.d.ts: make enabled property of RuleMetadata optional (#5129) (90fce18)
  • color-contrast: fix various stacking context bugs (#5214) (d5e5b04), references #8 #5213
  • gather-internals: handle non-HTMLElement nodes (#5161) (06e84c3)
  • get-selector: escape control characters in attribute selectors (#5273) (4b60ac5), closes #5204 #5204
  • image-alt: allow whitespace alt on presentational images (#5218) (c5dd0ef), closes #5216
  • landmark-unique: exclude section/form with non-landmark roles from landmark match (#5085) (c5fd013), closes #4722 #5064
  • name the image role in role-img-alt and svg-img-alt metadata (#5279) (995a269), closes #5272, references #5248 #5248
  • standards: update aria-errormessage and aria-details to be idrefs (#5157) (fb94f8a)
Commits
  • 1cc54b9 chore(release): v4.13.0 (#5288)
  • a1c9ebb chore(release): 4.13.0
  • 98400d7 test(arialabelledby-text): cover closed shadow DOM and out-of-tree idrefs (#5...
  • bcd791c feat(standards/ariaAttrs): add caseInsensitive property for attributes (#5224)
  • fd6fa9f fix(aria-prohibited-attr): visible aria-labelledby requires review only (#5285)
  • 013ee82 ci: increase wait-for-npm-ready timeout for publish scan delay (#5286)
  • c5fd013 fix(landmark-unique): exclude section/form with non-landmark roles from landm...
  • dcd13f2 feat(i18n): Add Swedish locale (#5190)
  • a713bd8 test(hasAriaValue): reenable skipped test due to firefox crash (#5229)
  • fb94f8a fix(standards): update aria-errormessage and aria-details to be idrefs (#5157)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Open in Devin Review

Bumps [axe-core](https://github.com/dequelabs/axe-core) from 4.12.1 to 4.13.0.
- [Release notes](https://github.com/dequelabs/axe-core/releases)
- [Changelog](https://github.com/dequelabs/axe-core/blob/develop/CHANGELOG.md)
- [Commits](dequelabs/axe-core@v4.12.1...v4.13.0)

---
updated-dependencies:
- dependency-name: axe-core
  dependency-version: 4.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 15, 2026

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 2 potential issues.

Open in Devin Review

"type": "module",
"dependencies": {
"axe-core": "4.12.1",
"axe-core": "4.13.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 Recorded accessibility-tool version no longer matches the version actually used in evaluations

The accessibility checker used by the browser evaluator was upgraded ("axe-core": "4.13.0" at sandbox/browser-web-v1/package.json:6) without updating the frozen environment record that is stored with every evaluation, so runs are labelled with a version that was not actually used.
Impact: Evaluation results are recorded with the wrong accessibility-tool version, breaking reproducibility claims, and the environment consistency check fails.

Frozen environment descriptor drift between package.json and EVALUATION_ENVIRONMENT_V1

lib/domain/ranked-catalog.ts:45 still declares axeCore: "4.12.1". This descriptor is persisted as evaluationPolicy for runs (lib/evaluation/frontend.ts:58, lib/data/catalog-admin.ts:312), while the sandbox evaluator imports axe-core from sandbox/browser-web-v1/package.json (sandbox/browser-web-v1/evaluate.mjs:4), now 4.13.0. tests/security-policy.test.ts:1258-1276 asserts the two must match, so the local gate (npm test) required by CONTRIBUTING.md will fail.

Prompt for agents
The axe-core dependency in sandbox/browser-web-v1/package.json was bumped to 4.13.0, but the frozen evaluation environment descriptor EVALUATION_ENVIRONMENT_V1 in lib/domain/ranked-catalog.ts still records axeCore: "4.12.1". That descriptor is persisted as the evaluationPolicy for every frontend evaluation run (lib/evaluation/frontend.ts, lib/data/catalog-admin.ts), so stored provenance would claim a version that was not used, and tests/security-policy.test.ts ("browser evaluator packages match the frozen environment descriptor") will fail. Decide whether the environment pin should be updated in lockstep (and whether bumping the checker changes scoring behavior enough to require a new environment/snapshot version), then keep package.json, the lockfile, and the descriptor consistent.
Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

"type": "module",
"dependencies": {
"axe-core": "4.12.1",
"axe-core": "4.13.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 axe-core 4.13.0 changes rule outcomes, which can shift accessibility scores

The evaluator counts critical accessibility violations from axe.run(document) (sandbox/browser-web-v1/evaluate.mjs:254-266). Release 4.13.0 enables ElementInternals support by default, adds/changes several rules (deprecated ARIA attrs flagged as needs-review, aria-prohibited-attr changes, color-contrast stacking-context fixes) and the upstream notes themselves say issue numbers are likely to change. Because the sandbox is a pinned, reproducibility-critical scoring environment, this bump can change scores for previously graded submissions; a reviewer should decide whether this warrants a new evaluation environment/snapshot version rather than an in-place pin bump.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants