Skip to content

Arena/01a0df2a metamanifold webui - #16

Closed
hyperpolymath wants to merge 236 commits into
JoshuaJewell:mainfrom
hyperpolymath:arena/01a0df2a-metamanifold-webui
Closed

hyperpolymath wants to merge 236 commits into
JoshuaJewell:mainfrom
hyperpolymath:arena/01a0df2a-metamanifold-webui

Conversation

@hyperpolymath

Copy link
Copy Markdown
Contributor

No description provided.

… a better place one less R module at a time.
…nd working cutadapt -> vsearch-dada merge on default settings.
… of previously run stages. Created a versatile project structure.
….it was getting messy and altogether not worth it for now.
arena-ai-coding-agent Bot and others added 25 commits September 24, 2026 09:17
…nd epistemic receipts (#59)

## Summary
- **Multiplicative Replacement (Martín-Fernández 2003)**: Implemented
exact count-scale multiplicative replacement in
`Execution.prepare_analysis_table`. Preserves total sample depth ($\sum
x_{ij}^* = \sum x_{ij}$) and subcompositional ratios between all
non-zero components ({aj}^*/x_{bj}^* = x_{aj}/x_{bj}$). (Refs #21)
- **Bayesian Multiplicative Replacement (Martín-Fernández 2015)**:
Implemented Dirichlet prior posterior replacement preserving sample
depth. (Refs #21)
- **TSS Offsets for NB_GLM (Issue #16)**: Implemented exact Total Sum
Scaling offsets for `nb_glm`. Keeps raw counts in `prepared` (preserving
integer negative binomial properties) and sets `offset = log(lib_sizes)`
instead of fractional scaling. (Refs #16)
- **Epistemic Claims with Receipts**: Added `Standpoint`,
`TaxonWarrant`, `ProjectionY`, and SHA-256 `Receipt` verification in
`src/core/epistemic.jl`, with `encode_avec_fibre` / `parse_avec_fibre`
for the `avec_fibre` column. Aligns directly with `EpistemicTypes.jl`
and `echo-types`.
- **Zero Observation Disambiguation**: Added `disambiguate_zero`
distinguishing certified biological absence (`Val(:true_absence)`) from
observation limit (`Val(:undetected)`), connecting to `absolute-zero`
and Issue #18.
- **Original R Pipeline Protected**: DADA2, SWARM, VSEARCH, and R
runtime scripts remain strictly isolated and untouched.

## Tests & Hygiene
- `check-spdx.sh`: OK (279 files covered)
- `check-format.sh`: OK (326 files checked)
- `check-blob-hygiene.sh`: OK
- New comprehensive unit tests added to `test/unit/test_execution.jl`
and `test/unit/test_analysis_config.jl`.

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…cs (#60)

## The problem this fixes

`Execution.run_analysis` returned, per feature:

```julia
p_val   = 0.01 + (h % 100) / 1000.0     # h = hash(taxon_id)
padj    = p_val * 1.5                   # "mock BH"
log2fc  = (h % 20) / 10.0 - 1.0
baseMean= 100.0 + (h % 1000)
```

Every number is a deterministic function of the feature's **name**.
Nothing in the
run touches the counts. The rows render in a table as p-values, fold
changes and
means, and a caller has no way to tell them from a fit. The source
called it a stub;
the caller received it as a result.

## What replaces it

`src/analysis/estimation.jl` (catalogue item 2 — conditions published
*before* the
implementation, in
`docs/statistics/method-conditions/parametric-fits.md`):

| method | fit | note |
| --- | --- | --- |
| `nb_glm` | `MASS::glm.nb`, per feature | **offset required**;
`glmGamPoi`/`local`/`mean`/`pooled` refused by name (issue #21) |
| `clr_lm`, `ilr_lm` | `stats::lm`, per feature | offset refused: it
means nothing to a Gaussian fit on CLR units |
| `logistic` | `stats::glm(binomial)`, per feature | 0/1 response
required; proportions refused rather than given invented weights |

- **Unsuccessful states are states.** A failed fit gets `status =
"failed"`, a `note`
saying why and `null` for every statistic; it is excluded from the BH
family and
  counted. Nothing that cannot be fitted gets a number.
- **A run that cannot happen says so.** No design, no metadata column,
single-level
grouping, `RBusyError` past the timeout, R unreachable → `status =
"not_run"` with a
reason and an empty result set, and a warning on the diagnostics. An
empty result is
  never dressed up as "no significant features".
- **Refusals, not substitutions**: interactions/transformations/random
effects/nesting
in a formula, `$`/backticks/`;` in a formula, offsets on non-count
models, count models
  without one, binomial fits on proportions.
- **Provenance**: R and MASS versions, formula terms and the contrast
actually tested,
offset kind and its SHA-256, BH family size, exclusion count, and the
SHA-256 of the
  fits and coefficients tables as they crossed the R boundary.
- BH implemented in Julia and tested against R's `p.adjust(method =
"BH")`.

## Evidence (`test/unit/test_estimation.jl`)

- Known answers written into the data (four-fold up, no effect, ten-fold
down) rather
  than recorded from a previous run.
- Independent reference: the same counts fitted directly in R, compared
coefficient by
  coefficient, SE by SE, p by p.
- Negative controls for every refusal, and for `not_run`/`failed`
shapes.
- A source-level guard that `hash(taxon_id)`, `hash(` and `rand(` are
gone from the
  execution path.

Refs #1 (catalogue item 2 delivered; item 3's nonparametric tests and
the independent
statistical review are still outstanding there). Issue #21 stays open:
`glmGamPoi` is
refused rather than aliased, and the refusal says so.

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
#61)

**Work in progress.** Opened early so CI runs against the scaling module
while the wiring
lands; the checklist below is filled in as each part arrives.

## What this closes

Issue #16 asked for TSS, CSS and RSS as **offsets** rather than aliases
to `relative`,
and carried the line "Deferred — DO NOT IMPLEMENT IN MILESTONE 3". That
line is a scope
decision; it is lifted explicitly at the top of the new conditions
document.

What the code did before:

| Declared | What ran |
| --- | --- |
| `TSS` + `nb_glm` | counts kept, offset `log(lib_sizes)` (the one
honest case) |
| `TSS` + anything else | proportions — the compositional transform the
issue existed to avoid |
| `CSS`, `RSS` | aliased to `relative`, with a warning; under `nb_glm` a
count model was fitted with fractions |
| `size_factors` | described as "DESeq2 median-of-ratios", computed as
library size divided by its own geometric mean |

## What replaces it

`src/analysis/scaling.jl` (conditions published first, in
`docs/statistics/method-conditions/scaling-and-offsets.md`):

- **TSS** — `log(library size)`.
- **CSS** — cumulative sum of counts at or below the declared per-sample
quantile
(Paulson et al. 2013), `css_quantile` default 0.75. Refused, by name,
when the
cumulative sum is zero: `log(0)` is not a small number.
`cumNormStatFast`'s data-driven
choice of the quantile is deliberately *not* implemented — a parameter
chosen from the
  data is a decision the run has to record.
- **RSS/TMM** — trimmed weighted mean of log-ratios to a reference
sample
(Robinson & Oshlack 2010), `tmm_log_ratio_trim` 0.3, `tmm_sum_trim`
0.05,
`tmm_ref_column` optional, reference otherwise chosen the way edgeR
chooses it.
- **size_factors** — median-of-ratios (RLE), which is what the name
claimed.

All four return factors centred to geometric mean 1, the log-offset, the
declared
parameters, the uncentred quantities and a SHA-256 of the offset vector.
Refusals are
unsuccessful states: a zero-total sample, an all-zero cumulative sum, a
sample with no
positive feature in common with the reference, or no feature positive in
every sample all
raise with the reason attached, and none of them is replaced by a factor
of 1.

## Evidence

`test/unit/test_scaling.jl`: known answers whose arithmetic is written
next to the
expected number, properties a wrong implementation fails
(feature-permutation
invariance, a sample that is a multiple of another, the CSS outlier
property that TSS
does not have), negative controls for every refusal, and the integration
path through
`prepare_analysis_table` down to the offset in the manifest.

**Stated limit, not hidden:** parity with `metagenomeSeq::cumNorm` and
`edgeR::calcNormFactors` at 1e-6 is *not* verified here. Neither package
is in the pinned
R environment, and this repository does not add an unpinned R dependency
to make a test
pass. That acceptance item is recorded as outstanding rather than
claimed.

Closes #16 (with the residual condition recorded in the issue thread).

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
)

Two things in one PR, because they have one cause: the layer that
claimed to compute
TSS/CSS/RSS offsets did not, and the layer that accepted them refused
them.

## 1. The refusal — main is red because of this

`NormalizationConfig` canonicalises its method to lower case (`"TSS"` →
`"tss"`), while
`VALID_NORMALIZATION_FOR_METHOD` listed `"TSS"`, `"CSS"`, `"RSS"`. The
membership test
therefore failed for those three spellings and `AnalysisConfig` raised
`normalization.method 'tss' incompatible with method 'nb_glm'` —
including for the
existing `test/unit/test_execution.jl` testset *TSS offset for NB_GLM*,
which constructs
`method="TSS"` exactly as the documentation instructs. That is the
failure behind the red
`Julia tests` job on the TSS-offsets commits; it is not a flaky test and
it is not the
new estimation layer.

The table and both comparisons (constructor, `validate_config`) are
lower case now, the
JSON-schema enum still accepts the upper-case spellings for existing
documents, and
`test/unit/test_scaling.jl` asserts that every admissible spelling of
every method name
is accepted.

## 2. The wiring — issue #16's offsets are computed, not aliased

`prepare_analysis_table` now computes scaling factors through
`src/analysis/scaling.jl`
and hands the offset to the fit:

| declared | response | offset |
|---|---|---|
| `tss` / `none` (count model) | counts | `log(library size)` |
| `css` | counts | `log` cumulative sum at the declared `css_quantile` |
| `rss` (TMM) | counts | `log` trimmed weighted mean of log-ratios to a
reference sample |
| `size_factors` | counts | `log` median-of-ratios (RLE) — the estimator
the name claimed |
| `relative` | proportions | none (a transform, not an offset) |

Previously `css`/`rss` were aliased to `relative` under `@warn`, `tss`
did that for every
method but `nb_glm`, and `size_factors` computed library-size centring
wearing DESeq2's
name. `css`/`rss` are now refused for a response with no counts to
offset — in the
configuration layer and again in the execution path.

`css_quantile` (0.75), `tmm_ref_column` (chosen the way edgeR chooses
it, and recorded),
`tmm_log_ratio_trim` (0.3) and `tmm_sum_trim` (0.05) are validated in
the constructor,
included in the config hash and canonical JSON, round-tripped through
`to_json`/`from_json`/Nickel/DEED, mirrored in the JSON schema and
Nickel contracts,
exposed through the server's configuration route, and explained in
`context_help` and the
frontend help. A run that declared a different quantile is a different
run.

`diagnostics.checks["scaling"]` and the manifest provenance record the
kind, the
definition, the parameters, the raw quantities before centring and a
SHA-256 of the
offset vector.

## Evidence

- `test/unit/test_scaling.jl`: known answers with the arithmetic written
beside them;
properties a wrong implementation fails (feature permutation, a sample
that is an exact
multiple of another, invariance to a shared constant); the CSS
outlier-robustness
property; negative controls for every refusal (zero-total sample, zero
CSS cumulative
sum, unknown reference, disjoint supports, out-of-range trims); the
integration path
through `prepare_analysis_table`; and a base-R transcription of the same
conditions,
  which skips **loudly by name** where R is unreachable.
- Conditions document, published before the implementation and merged in
#61:
  `docs/statistics/method-conditions/scaling-and-offsets.md`.
- Local gates: `check-spdx.sh` OK (284 files), `check-format.sh` OK (331
files),
  `check-lint.sh` OK (`tsc --noEmit` clean over `frontend/src`).

## Not claimed

Parity with `metagenomeSeq::cumNorm` and `edgeR::calcNormFactors` at
1e-6 is **not**
verified: neither package is in `renv.lock`, and this PR does not add an
unpinned R
dependency to make a test pass. The base-R transcription catches
implementation slips, not
specification errors. That outstanding condition stays recorded in issue
#16 and in the
conditions document rather than being asserted as met.

Closes #16.

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
)

## Summary of Changes

1. **Refusal of Deferred ILR Bases:**
- `AnalysisConfig.DEFERRED_ILR_BASIS` defines the deferred bases
(`"phylogenetic"`, `"sequential_binary_partition"`,
`"balance_dendrogram"`).
- Refused at `NormalizationConfig` construction and in
`prepare_analysis_table` instead of warn-and-substitute.
- `context_help("normalization.ilr_basis")` rewritten to document that
only the default Helmert basis is implemented and others are deferred
(Issue #20).

2. **Balance Row Labelling & Integrity:**
   - Relabels ILR rows to `balance_1`..`balance_n-1`.
- Records ILR provenance and diagnostics in `diagnostics.checks["ilr"]`.
- Prevents all-zero-taxa healing from restoring original taxon labels
onto balance rows.

3. **CI Test Suite Fix:**
- Updates `prepare_analysis_table keeps counts and hands over the
offset` test in `test/unit/test_scaling.jl` to use a 4-sample fixture
(`table_4`), satisfying the `min_samples_per_group=2` requirement (`>= 2
* 2 = 4` samples).
- Adds unit tests for deferred basis refusal and balance row labelling.
   - Updates RCall usage to `rcopy(reval(...))`.

4. **Documentation & Outreach:**
- Adds `docs/owner-review-2026-09-25.md` (with CC-BY-SA-4.0 SPDX header)
and CHANGELOG entry.

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
## Why

Julia tests on `main` have been red since #60, and the reason was never
visible: the job log is served from a blob host that some environments
cannot reach, and the one annotation the step posted (the last 6000
bytes of output) was truncated by the checks API at 4096 bytes — which
cut it off exactly before the failing testset. For `e26d6f2` (#63) all
it shows is that `Scaling — TSS, CSS, RSS/TMM and size factors (issue
#16)` has a failure.

## What

The "Run tests" step, on failure only, now posts:

- one `::error` annotation per failing assertion (the Test.jl block
starting at `Test Failed at` / `Error During Test at`, up to 60 lines /
3500 bytes, max 8), and
- one summary annotation holding only the `Test Summary` rows whose Fail
or Error column is non-empty (found by the header's column positions),
plus the `ERROR:` line.

If no failure block is found (e.g. a load error), the old tail
annotation is posted as a fallback. The test command and its exit status
are unchanged.

## Verified

- YAML re-parses; spdx/format/blob-hygiene gates clean.
- The extraction shell was run against a synthetic Test.jl log (one
`Test Failed`, one `Error During Test` with `Got exception outside of a
@test`, nested summary) and produced exactly two failure annotations and
a summary with only the failing rows.

## Not claimed

This does **not** fix the red test. It makes the failure readable so the
next PR can fix it rather than guess. This PR's own CI run should fail
the same way as `main` and name the assertion.

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
## Why

With #65's annotations, the red Julia job on `main` is readable for the
first time. Run 36193210557 names 11 failures and 20 errors, **all in
`test/unit/test_estimation.jl`**. The Scaling suite (#16) passes. There
are three causes:

1. **Every parametric fit came back `not_run`.** R writes the fits with
`write.csv(..., na = "NA")`, and Julia read them with `CSV.File(path)`,
whose default `missingstring` is `""`. Any numeric column containing an
`NA` was read as `String31`, and `_num` then threw `MethodError: no
method matching isfinite(::String31)`. The catch-all turned that into
`status = :not_run`, which produced the cascade of `KeyError`s
(`n_tested`, `n_failed`, `correction`, `t_up`) and `0 == 3` results in
five testsets.
2. **`glmGamPoi` never reached its #21 refusal.** `AdvancedConfig`
lower-cases `dispersion_method` and then checks it against
`VALID_DISPERSION_METHODS`, which spells it `glmGamPoi`. So
`nb_config(dispersion = "glmGamPoi")` was refused as an unknown name.
This is the same class of bug as the `tss`/`TSS` one fixed in #62.
3. **The "no placeholder statistics" scan flagged comments.** Comments
in `estimation.jl` and `Execution.jl` quoted the removed code literally
(`hash(taxon_id)`).

## What

- `estimation.jl`: `R_NA_STRINGS = ["NA", ""]` is passed as
`missingstring` to both `CSV.File` reads. `_refused_dispersion` looks up
`REFUSED_DISPERSION` case-insensitively, and the error message uses the
canonical name.
- `AnalysisConfig.jl`: the dispersion compare is now lower-case against
`lowercase.(VALID_DISPERSION_METHODS)`.
- The comments are reworded, and the source-scan test is unchanged and
still strict.
- `test_estimation.jl`: three extra spellings (`glmgampoi`, `GLMGAMPOI`,
` glmGamPoi `) must each hit the #21 refusal.
- `CHANGELOG.md` entry.

## Verified / not verified

- spdx, format and blob-hygiene gates are clean.
- There is no Julia runtime in the authoring sandbox, so **this PR's CI
run is the first execution**. Diagnosis 1 comes from the `reason` string
in the annotation. Once the fits run, some numeric assertions that were
never reached may surface in turn. If so, the annotations will name
them.

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
…0 updates (#69)

Bumps the frontend-dependencies group in /frontend with 10 updates:

| Package | From | To |
| --- | --- | --- |
| [plotly.js-dist-min](https://github.com/plotly/plotly.js) | `2.35.3` |
`4.1.1` |
| [react](https://github.com/react/react/tree/HEAD/packages/react) |
`18.3.1` | `19.3.0` |
|
[@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react)
| `18.3.28` | `19.3.0` |
|
[react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom)
| `18.3.1` | `19.3.0` |
|
[@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom)
| `18.3.7` | `19.3.0` |
| [react-plotly.js](https://github.com/plotly/react-plotly.js) | `4.0.0`
| `4.1.0` |
|
[react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom)
| `6.30.6` | `7.18.4` |
|
[@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react)
| `4.7.0` | `6.1.1` |
| [typescript](https://github.com/microsoft/TypeScript) | `5.9.3` |
`7.0.2` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) |
`6.4.1` | `8.3.0` |

Updates `plotly.js-dist-min` from 2.35.3 to 4.1.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/plotly/plotly.js/releases">plotly.js-dist-min's
releases</a>.</em></p>
<blockquote>
<h2>v4.1.1</h2>
<h3>Changed</h3>
<ul>
<li>Update <code>maplibre-gl</code> to v6 to address <a
href="https://github.com/advisories/GHSA-jrc7-96c5-q579">CVE-2026-85061</a>
[<a
href="https://redirect.github.com/plotly/plotly.js/pull/8035">#8035</a>]
<ul>
<li><code>maplibre-gl</code> v6 dropped WebGL1 support, so some older
browsers won't be able to use the map traces. Safari 15, Chrome 56,
Firefox 51 and later are now required for the map traces.</li>
</ul>
</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Box and lasso selection of <code>scattermap</code> points are now
supported on a rotated or pitched map [<a
href="https://redirect.github.com/plotly/plotly.js/pull/8035">#8035</a>]</li>
</ul>
<h2>v4.1.0</h2>
<h3>Added</h3>
<ul>
<li>Add an opt-in modebar button for downloading Plotly figures as JSON
[<a
href="https://redirect.github.com/plotly/plotly.js/pull/7990">#7990</a>,
<a
href="https://redirect.github.com/plotly/plotly.js/pull/8022">#8022</a>],
with thanks to <a
href="https://github.com/gokul-debugger"><code>@​gokul-debugger</code></a>
for the contribution!</li>
<li>Add <code>legend.groupdoubleclick</code> to set the group behavior
for a legend double-click [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7997">#7997</a>],
with thanks to <a
href="https://github.com/rascal-sl"><code>@​rascal-sl</code></a> for the
contribution!</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Increase default double-click delay threshold to 500ms (from 300)
[<a
href="https://redirect.github.com/plotly/plotly.js/pull/8014">#8014</a>]</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Correct the <code>showspikes</code> axis attribute description to
clarify that it applies for all <code>hovermode</code> values except
when <code>hovermode</code> is <em>false</em> [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7981">#7981</a>],
with thanks for <a
href="https://github.com/CAOShurong"><code>@​CAOShurong</code></a> for
the contribution!</li>
<li>Update country-iso-search to v0.1.2 to fix issue with UTF-8
characters being decoded incorrectly [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7994">#7994</a>]</li>
<li>Compile TypeScript files under <code>src/</code> to JavaScript
during packaging to fix Node resolution [<a
href="https://redirect.github.com/plotly/plotly.js/pull/8000">#8000</a>]</li>
<li>Include type defs in appropriate partial bundles [<a
href="https://redirect.github.com/plotly/plotly.js/pull/8001">#8001</a>]</li>
<li>Add TypeScript declarations for the modular <code>lib/</code> entry
points [<a
href="https://redirect.github.com/plotly/plotly.js/pull/8009">#8009</a>]</li>
<li>Handle regex enum values when generating schema types [<a
href="https://redirect.github.com/plotly/plotly.js/pull/8010">#8010</a>]</li>
<li>Include trace-contributed layout attributes in generated types [<a
href="https://redirect.github.com/plotly/plotly.js/pull/8020">#8020</a>]</li>
<li>Resolve the per-point marker color for hover labels in
<code>scattergl</code>, <code>quiver</code> traces [<a
href="https://redirect.github.com/plotly/plotly.js/pull/8027">#8027</a>]</li>
</ul>
<h2>v4.0.0</h2>
<h3>Added</h3>
<ul>
<li>Add <code>minscale</code>, <code>maxscale</code> geo plot attributes
[<a
href="https://redirect.github.com/plotly/plotly.js/pull/7371">#7371</a>],
with thanks to <a
href="https://github.com/mojoaxel"><code>@​mojoaxel</code></a> for the
contribution!</li>
<li>Enable TypeScript compatibility within the library and start
exporting types [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7680">#7680</a>]</li>
<li>Add <code>quiver</code> trace type to visualize vector fields using
arrows [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7710">#7710</a>,
<a
href="https://redirect.github.com/plotly/plotly.js/issues/7945">#7945</a>],
with thanks to <a
href="https://github.com/degzhaus"><code>@​degzhaus</code></a> for the
contribution!</li>
<li>Use dashed markers in legend for shape traces with dash configured
[<a
href="https://redirect.github.com/plotly/plotly.js/pull/7845">#7845</a>]</li>
<li>Add <code>direction</code> attribute to the Sankey trace,
controlling the flow direction along the <code>orientation</code> axis
[<a
href="https://redirect.github.com/plotly/plotly.js/pull/7870">#7870</a>],
with thanks to <a href="https://github.com/wf-r"><code>@​wf-r</code></a>
for the contribution!
<ul>
<li><code>forward</code> keeps sources on the left (horizontal) or top
(vertical)</li>
<li><code>reversed</code> moves them to the right or bottom</li>
</ul>
</li>
<li>Add <code>sort</code> option to Sankey links and nodes [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7873">#7873</a>],
with thanks to <a
href="https://github.com/adamreeve"><code>@​adamreeve</code></a> for the
contribution!</li>
<li>Add support for MathJax v4 [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7898">#7898</a>]</li>
<li>Add top-level <code>xPixel</code> and <code>yPixel</code> keys to
hover and click event data, corresponding to the pixel position of the
cursor relative to the top-left corner of the graph div [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7966">#7966</a>]</li>
<li>When <code>hoveranywhere</code> is enabled, emit a
<code>plotly_unhover</code> event when the cursor leaves the plot area
[<a
href="https://redirect.github.com/plotly/plotly.js/pull/7966">#7966</a>]</li>
</ul>
<h3>Removed</h3>
<ul>
<li><strong>Breaking</strong>: Remove <code>scattermapbox</code>,
<code>choroplethmapbox</code>, <code>densitymapbox</code> trace types,
the <code>mapbox</code> subplot, and the <code>mapboxAccessToken</code>
config option [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7860">#7860</a>]
<ul>
<li>These traces have been deprecated since v3. Use the equivalent
<code>*map</code> traces going forward.</li>
</ul>
</li>
<li><strong>Breaking</strong>: Drop support for MathJax v2 [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7898">#7898</a>]
<ul>
<li>MathJax v3 and v4 are now supported in plotly.js</li>
</ul>
</li>
<li>Remove config attributes <code>showLink</code>,
<code>linkText</code>, <code>sendData</code>, <code>showSources</code>,
and <code>showEditInChartStudio</code>, as well as trace attribute
<code>stream</code>, since all of these were associated with Chart
Studio and are no longer needed [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7812">#7812</a>]</li>
<li>Remove all <code>*src</code> attributes, as well as
<code>layout.hidesources</code> attribute, from the schema [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7829">#7829</a>]</li>
<li>Remove internal <code>trace._fullInput</code> property and other
dead code related to the removed <code>transforms</code> feature. No
user-facing changes expected [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7834">#7834</a>]</li>
</ul>
<h3>Changed</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/plotly/plotly.js/blob/main/CHANGELOG.md">plotly.js-dist-min's
changelog</a>.</em></p>
<blockquote>
<h1>plotly.js changelog</h1>
<p>For more context information, please read through the
<a href="https://github.com/plotly/plotly.js/releases">release
notes</a>.</p>
<p>To see all merged commits on the main branch that will be part of the
next plotly.js release, go to:</p>
<p><a
href="https://github.com/plotly/plotly.js/compare/vX.Y.Z...main">https://github.com/plotly/plotly.js/compare/vX.Y.Z...main</a></p>
<p>where X.Y.Z is the semver of most recent plotly.js release.</p>
<h2>[X.Y.Z] -- UNRELEASED</h2>
<h3>Changed</h3>
<ul>
<li>Update <code>maplibre-gl</code> to v6 to address <a
href="https://github.com/advisories/GHSA-jrc7-96c5-q579">CVE-2026-85061</a>
[<a
href="https://redirect.github.com/plotly/plotly.js/pull/8035">#8035</a>]
<ul>
<li><code>maplibre-gl</code> v6 dropped WebGL1 support, so some older
browsers won't be able to use the map traces. Safari 15, Chrome 56,
Firefox 51 and later are now required for the map traces.</li>
</ul>
</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Box and lasso selection of <code>scattermap</code> points are now
supported on a rotated or pitched map [<a
href="https://redirect.github.com/plotly/plotly.js/pull/8035">#8035</a>]</li>
</ul>
<h2>[4.1.0] -- 2026-09-08</h2>
<h3>Added</h3>
<ul>
<li>Add an opt-in modebar button for downloading Plotly figures as JSON
[<a
href="https://redirect.github.com/plotly/plotly.js/pull/7990">#7990</a>,
<a
href="https://redirect.github.com/plotly/plotly.js/pull/8022">#8022</a>],
with thanks to <a
href="https://github.com/gokul-debugger"><code>@​gokul-debugger</code></a>
for the contribution!</li>
<li>Add <code>legend.groupdoubleclick</code> to set the group behavior
for a legend double-click [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7997">#7997</a>],
with thanks to <a
href="https://github.com/rascal-sl"><code>@​rascal-sl</code></a> for the
contribution!</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Increase default double-click delay threshold to 500ms (from 300)
[<a
href="https://redirect.github.com/plotly/plotly.js/pull/8014">#8014</a>]</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Correct the <code>showspikes</code> axis attribute description to
clarify that it applies for all <code>hovermode</code> values except
when <code>hovermode</code> is <em>false</em> [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7981">#7981</a>],
with thanks for <a
href="https://github.com/CAOShurong"><code>@​CAOShurong</code></a> for
the contribution!</li>
<li>Update country-iso-search to v0.1.2 to fix issue with UTF-8
characters being decoded incorrectly [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7994">#7994</a>]</li>
<li>Compile TypeScript files under <code>src/</code> to JavaScript
during packaging to fix Node resolution [<a
href="https://redirect.github.com/plotly/plotly.js/pull/8000">#8000</a>]</li>
<li>Include type defs in appropriate partial bundles [<a
href="https://redirect.github.com/plotly/plotly.js/pull/8001">#8001</a>]</li>
<li>Add TypeScript declarations for the modular <code>lib/</code> entry
points [<a
href="https://redirect.github.com/plotly/plotly.js/pull/8009">#8009</a>]</li>
<li>Handle regex enum values when generating schema types [<a
href="https://redirect.github.com/plotly/plotly.js/pull/8010">#8010</a>]</li>
<li>Include trace-contributed layout attributes in generated types [<a
href="https://redirect.github.com/plotly/plotly.js/pull/8020">#8020</a>]</li>
<li>Resolve the per-point marker color for hover labels in
<code>scattergl</code>, <code>quiver</code> traces [<a
href="https://redirect.github.com/plotly/plotly.js/pull/8027">#8027</a>]</li>
</ul>
<h2>[4.0.0] -- 2026-08-24</h2>
<h3>Added</h3>
<ul>
<li>Add <code>minscale</code>, <code>maxscale</code> geo plot attributes
[<a
href="https://redirect.github.com/plotly/plotly.js/pull/7371">#7371</a>],
with thanks to <a
href="https://github.com/mojoaxel"><code>@​mojoaxel</code></a> for the
contribution!</li>
<li>Enable TypeScript compatibility within the library and start
exporting types [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7680">#7680</a>]</li>
<li>Add <code>quiver</code> trace type to visualize vector fields using
arrows [<a
href="https://redirect.github.com/plotly/plotly.js/pull/7710">#7710</a>,
<a
href="https://redirect.github.com/plotly/plotly.js/issues/7945">#7945</a>],
with thanks to <a
href="https://github.com/degzhaus"><code>@​degzhaus</code></a> for the
contribution!</li>
<li>Use dashed markers in legend for shape traces with dash configured
[<a
href="https://redirect.github.com/plotly/plotly.js/pull/7845">#7845</a>]</li>
<li>Add <code>direction</code> attribute to the Sankey trace,
controlling the flow direction along the <code>orientation</code> axis
[<a
href="https://redirect.github.com/plotly/plotly.js/pull/7870">#7870</a>],
with thanks to <a href="https://github.com/wf-r"><code>@​wf-r</code></a>
for the contribution!
<ul>
<li><code>forward</code> keeps sources on the left (horizontal) or top
(vertical)</li>
</ul>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/plotly/plotly.js/commit/0aabc3c5cc4f1d91fd6dd3846c5353de1beb0885"><code>0aabc3c</code></a>
4.1.1</li>
<li><a
href="https://github.com/plotly/plotly.js/commit/b246393e9b2901f70b47bc4688eaa63a5ee88950"><code>b246393</code></a>
updates for release v4.1.1</li>
<li><a
href="https://github.com/plotly/plotly.js/commit/57e8cb5670a03330c217f26551340aa54a28e4d6"><code>57e8cb5</code></a>
Merge pull request <a
href="https://redirect.github.com/plotly/plotly.js/issues/8037">#8037</a>
from Lexachoc/doc-spikethickness-fix</li>
<li><a
href="https://github.com/plotly/plotly.js/commit/08f0c6af7fcfe20411e2cf3a8138f6e739dca36c"><code>08f0c6a</code></a>
Delete draftlogs/8037_fix.md</li>
<li><a
href="https://github.com/plotly/plotly.js/commit/e8f6a7dc090f4b2f9a95ac8ccd5cd16aefba1bed"><code>e8f6a7d</code></a>
Merge pull request <a
href="https://redirect.github.com/plotly/plotly.js/issues/8035">#8035</a>
from plotly/cam/8031/upgrade-maplibre-v6</li>
<li><a
href="https://github.com/plotly/plotly.js/commit/f3d750b9be800a9ed4449f3836eeeb5d05e3df7c"><code>f3d750b</code></a>
Remove errant space</li>
<li><a
href="https://github.com/plotly/plotly.js/commit/67f45d7d7d33516ce6dcc7a65864280390b4b886"><code>67f45d7</code></a>
Address PR feedback</li>
<li><a
href="https://github.com/plotly/plotly.js/commit/c69a59799d088d9def8d0b2e4a2626aacb72924b"><code>c69a597</code></a>
update schema</li>
<li><a
href="https://github.com/plotly/plotly.js/commit/bcb3c6d8863d461ec1b87ab22a67367644c0341d"><code>bcb3c6d</code></a>
add draftlog</li>
<li><a
href="https://github.com/plotly/plotly.js/commit/139595d3eefc55d25d2b801873bff3a7031eb8c7"><code>139595d</code></a>
fix spikethickness description</li>
<li>Additional commits viewable in <a
href="https://github.com/plotly/plotly.js/compare/v2.35.3...v4.1.1">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~aborrmann">aborrmann</a>, a new releaser
for plotly.js-dist-min since your current version.</p>
</details>
<br />

Updates `react` from 18.3.1 to 19.3.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/react/react/releases">react's
releases</a>.</em></p>
<blockquote>
<h2>19.3.0 (September 9, 2026)</h2>
<p>Below is a list of all new features, APIs, and bug fixes.</p>
<p>Read the <a href="https://react.dev/blog/2026/09/09/react-19-3">React
19.3 release post</a> for more information.</p>
<h2>New React Features</h2>
<ul>
<li><code>&lt;ViewTransition /&gt;</code>: Adds <code>&lt;ViewTransition
/&gt;</code> and <code>addTransitionType</code> APIs to power View
Transition animations in React (<a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a>, <a
href="https://github.com/jackpope"><code>@​jackpope</code></a>, <a
href="https://github.com/gaearon"><code>@​gaearon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/31975">#31975</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31987">#31987</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31996">#31996</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31999">#31999</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32001">#32001</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32002">#32002</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32028">#32028</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32029">#32029</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32031">#32031</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32034">#32034</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32038">#32038</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32041">#32041</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32050">#32050</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32090">#32090</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32105">#32105</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32254">#32254</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32379">#32379</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32422">#32422</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32462">#32462</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32540">#32540</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32545">#32545</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32585">#32585</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32599">#32599</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32611">#32611</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32612">#32612</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32617">#32617</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32651">#32651</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32653">#32653</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32656">#32656</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32664">#32664</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32699">#32699</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32723">#32723</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32734">#32734</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32751">#32751</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32752">#32752</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32760">#32760</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32761">#32761</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32764">#32764</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32772">#32772</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32790">#32790</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32819">#32819</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32820">#32820</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32822">#32822</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32833">#32833</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32849">#32849</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33094">#33094</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33191">#33191</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33200">#33200</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33206">#33206</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33293">#33293</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33330">#33330</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33331">#33331</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33332">#33332</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33357">#33357</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33362">#33362</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33433">#33433</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33576">#33576</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34374">#34374</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34450">#34450</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34481">#34481</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34500">#34500</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34502">#34502</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34510">#34510</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34511">#34511</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34539">#34539</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35567">#35567</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35564">#35564</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35485">#35485</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35380">#35380</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35063">#35063</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35060">#35060</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34676">#34676</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36917">#36917</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35337">#35337</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35520">#35520</a>)</li>
<li>Fragment Refs: Add Refs to <code>&lt;Fragment /&gt;</code> to
support composable platform behavior (<a
href="https://github.com/jackpope"><code>@​jackpope</code></a>, <a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>, <a
href="https://github.com/Dhakshin2007"><code>@​Dhakshin2007</code></a>,
<a href="https://github.com/chirokas"><code>@​chirokas</code></a>, <a
href="https://github.com/teamleaderleo"><code>@​teamleaderleo</code></a>,
<a
href="https://github.com/fallintoplace"><code>@​fallintoplace</code></a>:
<a
href="https://redirect.github.com/facebook/react/pull/32465">#32465</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32613">#32613</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32619">#32619</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32654">#32654</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32660">#32660</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32682">#32682</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32722">#32722</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32813">#32813</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32814">#32814</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33056">#33056</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33058">#33058</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33093">#33093</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34069">#34069</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34103">#34103</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34544">#34544</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34545">#34545</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37062">#37062</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37061">#37061</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37060">#37060</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36047">#36047</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36010">#36010</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35642">#35642</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35641">#35641</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35637">#35637</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35630">#35630</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34935">#34935</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37457">#37457</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37408">#37408</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37326">#37326</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37251">#37251</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37171">#37171</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37169">#37169</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37168">#37168</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37167">#37167</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37166">#37166</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37165">#37165</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37164">#37164</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37163">#37163</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37162">#37162</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37161">#37161</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37160">#37160</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37125">#37125</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37063">#37063</a>)</li>
</ul>
<h2>New React DOM Features</h2>
<ul>
<li><code>browser()</code>: a new <code>react-dom</code> API that
returns a usable which errors during server rendering and resolves in
the browser. <code>use(browser())</code> inside a
<code>&lt;Suspense&gt;</code> boundary marks a subtree as browser-only
without reporting a recoverable error (<a
href="https://github.com/gnoff"><code>@​gnoff</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/37143">#37143</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37241">#37241</a>)
<ul>
<li>Added an <code>onBrowserBailout</code> option to the
<code>react-dom/server</code> APIs to observe when a subtree defers to
the browser (<a href="https://github.com/gnoff"><code>@​gnoff</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/37193">#37193</a>)</li>
</ul>
</li>
</ul>
<h2>Notable changes</h2>
<ul>
<li>Enable Trusted Types API integration (<a
href="https://github.com/rickhanlonii"><code>@​rickhanlonii</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/35816">#35816</a>)</li>
<li>Transitions now render independently instead of being entangled into
a single render, so a slow transition no longer holds up unrelated ones
(<a href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/37290">#37290</a>)</li>
<li>Added a DEV-only warning when a component appears to have been
unblocked by calling <code>use()</code> conditionally (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/37104">#37104</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37203">#37203</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37491">#37491</a>)</li>
</ul>
<h2>All Changes</h2>
<h3>React</h3>
<ul>
<li>Fast Refresh Fixes
<ul>
<li>Fix Fast Refresh to find and remount edits to components wrapped
behind <code>lazy()</code> (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36965">#36965</a>)</li>
<li>Fix Fast Refresh so edits to a <code>memo()</code> comparison
function take effect (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36964">#36964</a>)</li>
<li>Fix Fast Refresh crash when an edit changes the kind of a
component's type (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36963">#36963</a>)</li>
<li>Unify hot reload type resolution for Fast Refresh (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36962">#36962</a>)</li>
<li>Fix Fast Refresh to remount correctly when an edit changes the
component kind (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36950">#36950</a>)</li>
<li>Double invoke effects in StrictMode after Fast Refresh (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35962">#35962</a>)</li>
</ul>
</li>
<li>Performance Track Fixes
<ul>
<li>Prevent crash when accessing <code>$$typeof</code> in Performance
Tracks (<a href="https://github.com/eps1lon"><code>@​eps1lon</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/35679">#35679</a>)</li>
<li>Handle non-string function names in Performance Tracks (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35659">#35659</a>)</li>
<li>Use minus (<code>-</code>) instead of en dash for removed props in
Performance Tracks (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35649">#35649</a>)</li>
<li>Handle arrays with bigints in deep objects in Performance Tracks (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35648">#35648</a>)</li>
<li>Don't enumerate typed array props in Performance Tracks in DEV (<a
href="https://github.com/UditDewan"><code>@​UditDewan</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36913">#36913</a>)</li>
<li>Bail out of diffing wide objects and arrays in Performance Tracks
(<a href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34742">#34742</a>)</li>
<li>Clear potentially large performance measures in DEV (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34803">#34803</a>)</li>
<li>Fix missing else branch for renders with no props change in
Performance Tracks (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34837">#34837</a>)</li>
</ul>
</li>
<li>Activity Fixes
<ul>
<li>Fix <code>useSyncExternalStore</code> missing store mutations that
happened while an Activity tree was hidden (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36947">#36947</a>)</li>
<li>Hide portal contents when an Activity is hidden (<a
href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35091">#35091</a>)</li>
<li>Prevent metadata hoisting in hidden <code>&lt;Activity&gt;</code>
trees (<a
href="https://github.com/ronnakamoto"><code>@​ronnakamoto</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34983">#34983</a>)</li>
<li>Prevent errors thrown inside a hidden Activity from escaping to the
visible UI (<a
href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35074">#35074</a>)</li>
<li>Don't unhide a node if a direct parent Offscreen is still hidden (<a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34821">#34821</a>)</li>
<li>Don't show internal <code>&lt;Offscreen&gt;</code> component in
error messages (<a
href="https://github.com/rickhanlonii"><code>@​rickhanlonii</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/35763">#35763</a>)</li>
</ul>
</li>
<li>Warn in DEV when a component appears to have been unblocked by a
conditional <code>use()</code> (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/37104">#37104</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37203">#37203</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37491">#37491</a>)</li>
<li>Render transitions independently instead of entangling them into a
single render (<a
href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/37290">#37290</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/react/react/blob/main/CHANGELOG.md">react's
changelog</a>.</em></p>
<blockquote>
<h2>19.3.0 (September 9, 2026)</h2>
<h3>New React Features</h3>
<ul>
<li><code>&lt;ViewTransition /&gt;</code>: Adds <code>&lt;ViewTransition
/&gt;</code> and <code>addTransitionType</code> APIs to power View
Transition animations in React (<a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a>, <a
href="https://github.com/jackpope"><code>@​jackpope</code></a>, <a
href="https://github.com/gaearon"><code>@​gaearon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/31975">#31975</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31987">#31987</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31996">#31996</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31999">#31999</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32001">#32001</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32002">#32002</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32028">#32028</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32029">#32029</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32031">#32031</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32034">#32034</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32038">#32038</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32041">#32041</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32050">#32050</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32090">#32090</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32105">#32105</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32254">#32254</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32379">#32379</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32422">#32422</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32462">#32462</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32540">#32540</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32545">#32545</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32585">#32585</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32599">#32599</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32611">#32611</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32612">#32612</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32617">#32617</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32651">#32651</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32653">#32653</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32656">#32656</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32664">#32664</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32699">#32699</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32723">#32723</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32734">#32734</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32751">#32751</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32752">#32752</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32760">#32760</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32761">#32761</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32764">#32764</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32772">#32772</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32790">#32790</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32819">#32819</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32820">#32820</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32822">#32822</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32833">#32833</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32849">#32849</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33094">#33094</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33191">#33191</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33200">#33200</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33206">#33206</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33293">#33293</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33330">#33330</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33331">#33331</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33332">#33332</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33357">#33357</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33362">#33362</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33433">#33433</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33576">#33576</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34374">#34374</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34450">#34450</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34481">#34481</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34500">#34500</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34502">#34502</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34510">#34510</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34511">#34511</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34539">#34539</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35567">#35567</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35564">#35564</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35485">#35485</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35380">#35380</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35063">#35063</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35060">#35060</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34676">#34676</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36917">#36917</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35337">#35337</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35520">#35520</a>)</li>
<li>Fragment Refs: Add Refs to <code>&lt;Fragment /&gt;</code> to
support composable platform behavior (<a
href="https://github.com/jackpope"><code>@​jackpope</code></a>, <a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>, <a
href="https://github.com/Dhakshin2007"><code>@​Dhakshin2007</code></a>,
<a href="https://github.com/chirokas"><code>@​chirokas</code></a>, <a
href="https://github.com/teamleaderleo"><code>@​teamleaderleo</code></a>,
<a
href="https://github.com/fallintoplace"><code>@​fallintoplace</code></a>:
<a
href="https://redirect.github.com/facebook/react/pull/32465">#32465</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32613">#32613</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32619">#32619</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32654">#32654</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32660">#32660</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32682">#32682</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32722">#32722</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32813">#32813</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32814">#32814</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33056">#33056</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33058">#33058</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33093">#33093</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34069">#34069</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34103">#34103</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34544">#34544</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34545">#34545</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37062">#37062</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37061">#37061</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37060">#37060</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36047">#36047</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36010">#36010</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35642">#35642</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35641">#35641</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35637">#35637</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35630">#35630</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34935">#34935</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37457">#37457</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37408">#37408</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37326">#37326</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37251">#37251</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37171">#37171</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37169">#37169</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37168">#37168</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37167">#37167</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37166">#37166</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37165">#37165</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37164">#37164</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37163">#37163</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37162">#37162</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37161">#37161</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37160">#37160</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37125">#37125</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37063">#37063</a>)</li>
</ul>
<h3>New React DOM Features</h3>
<ul>
<li><code>browser()</code>: a new <code>react-dom</code> API that
returns a usable which errors during server rendering and resolves in
the browser. <code>use(browser())</code> inside a
<code>&lt;Suspense&gt;</code> boundary marks a subtree as browser-only
without reporting a recoverable error (<a
href="https://github.com/gnoff"><code>@​gnoff</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/37143">#37143</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37241">#37241</a>)
<ul>
<li>Added an <code>onBrowserBailout</code> option to the
<code>react-dom/server</code> APIs to observe when a subtree defers to
the browser (<a href="https://github.com/gnoff"><code>@​gnoff</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/37193">#37193</a>)</li>
</ul>
</li>
</ul>
<h3>Notable changes</h3>
<ul>
<li>Enable Trusted Types API integration (<a
href="https://github.com/rickhanlonii"><code>@​rickhanlonii</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/35816">#35816</a>)</li>
<li>Transitions now render independently instead of being entangled into
a single render, so a slow transition no longer holds up unrelated ones
(<a href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/37290">#37290</a>)</li>
<li>Added a DEV-only warning when a component appears to have been
unblocked by calling <code>use()</code> conditionally (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/37104">#37104</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37203">#37203</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37491">#37491</a>)</li>
</ul>
<h3>All Changes</h3>
<h4>React</h4>
<ul>
<li>Fast Refresh Fixes
<ul>
<li>Fix Fast Refresh to find and remount edits to components wrapped
behind <code>lazy()</code> (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36965">#36965</a>)</li>
<li>Fix Fast Refresh so edits to a <code>memo()</code> comparison
function take effect (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36964">#36964</a>)</li>
<li>Fix Fast Refresh crash when an edit changes the kind of a
component's type (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36963">#36963</a>)</li>
<li>Unify hot reload type resolution for Fast Refresh (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36962">#36962</a>)</li>
<li>Fix Fast Refresh to remount correctly when an edit changes the
component kind (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36950">#36950</a>)</li>
<li>Double invoke effects in StrictMode after Fast Refresh (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35962">#35962</a>)</li>
</ul>
</li>
<li>Performance Track Fixes
<ul>
<li>Prevent crash when accessing <code>$$typeof</code> in Performance
Tracks (<a href="https://github.com/eps1lon"><code>@​eps1lon</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/35679">#35679</a>)</li>
<li>Handle non-string function names in Performance Tracks (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35659">#35659</a>)</li>
<li>Use minus (<code>-</code>) instead of en dash for removed props in
Performance Tracks (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35649">#35649</a>)</li>
<li>Handle arrays with bigints in deep objects in Performance Tracks (<a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35648">#35648</a>)</li>
<li>Don't enumerate typed array props in Performance Tracks in DEV (<a
href="https://github.com/UditDewan"><code>@​UditDewan</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36913">#36913</a>)</li>
<li>Bail out of diffing wide objects and arrays in Performance Tracks
(<a href="https://github.com/eps1lon"><code>@​eps1lon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34742">#34742</a>)</li>
<li>Clear potentially large performance measures in DEV (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34803">#34803</a>)</li>
<li>Fix missing else branch for renders with no props change in
Performance Tracks (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34837">#34837</a>)</li>
</ul>
</li>
<li>Activity Fixes
<ul>
<li>Fix <code>useSyncExternalStore</code> missing store mutations that
happened while an Activity tree was hidden (<a
href="https://github.com/sophiebits"><code>@​sophiebits</code></a> <a
href="https://redirect.github.com/facebook/react/pull/36947">#36947</a>)</li>
<li>Hide portal contents when an Activity is hidden (<a
href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35091">#35091</a>)</li>
<li>Prevent metadata hoisting in hidden <code>&lt;Activity&gt;</code>
trees (<a
href="https://github.com/ronnakamoto"><code>@​ronnakamoto</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34983">#34983</a>)</li>
<li>Prevent errors thrown inside a hidden Activity from escaping to the
visible UI (<a
href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35074">#35074</a>)</li>
<li>Don't unhide a node if a direct parent Offscreen is still hidden (<a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a> <a
href="https://redirect.github.com/facebook/react/pull/34821">#34821</a>)</li>
<li>Don't show internal <code>&lt;Offscreen&gt;</code> component in
error messages (<a
href="https://github.com/rickhanlonii"><code>@​rickhanlonii</code></a>
<a
href="https://redirect.github.com/facebook/react/pull/35763">#35763</a>)</li>
</ul>
</li>
<li>Warn in DEV when a component appears to have been unblocked by a
conditional <code>use()</code> (<a
href="https://github.com/hoxyq"><code>@​hoxyq</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/37104">#37104</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37203">#37203</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37491">#37491</a>)</li>
<li>Render transitions independently instead of entangling them into a
single render (<a
href="https://github.com/acdlite"><code>@​acdlite</code></a> <a
href="https://redirect.github.com/facebook/react/pull/37290">#37290</a>)</li>
<li>Fix hang when updating a dehydrated boundary inside a hidden tree
(<a href="https://github.com/gaearon"><code>@​gaearon</code></a> <a
href="https://redirect.github.com/facebook/react/pull/37135">#37135</a>)</li>
<li>Don't reacquire Host Singletons during dev effect validation (<a
href="https://github.com/gnoff"><code>@​gnoff</code></a> <a
href="https://redirect.github.com/facebook/react/pull/37113">#37113</a>)</li>
<li>Only remove properties from Host Singletons on release (<a
href="https://github.com/gnoff"><code>@​gnoff</code></a> <a
href="https://redirect.github.com/facebook/react/pull/37112">#37112</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/react/react/commit/2dc7da790d6388b95b83198ca9b588b2ad5f5c0b"><code>2dc7da7</code></a>
[test] Bump Jest to 30.4 (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/37382">#37382</a>)</li>
<li><a
href="https://github.com/react/react/commit/4f9389423b7319e1f7acc3d158c84a8365462748"><code>4f93894</code></a>
docs: remove stale parentType param from validateChildKeys JSDoc (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/36928">#36928</a>)</li>
<li><a
href="https://github.com/react/react/commit/dbc37501ffeaf8fec45af5898caf1c3d64ad10bf"><code>dbc3750</code></a>
Update required references to GitHub repo (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/36752">#36752</a>)</li>
<li><a
href="https://github.com/react/react/commit/900ae094d85b11c67d53dd14af50a2bda5db4495"><code>900ae09</code></a>
[flow] Bump flow to v0.317.0 (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/36701">#36701</a>)</li>
<li><a
href="https://github.com/react/react/commit/fbb137059e4aacfaab1d36516e9b55050b4a0454"><code>fbb1370</code></a>
[flow] Bump flow to v0.307.1 (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/36199">#36199</a>)</li>
<li><a
href="https://github.com/react/react/commit/56922cf751fab6c7ab4c12ddbbd15839959fa255"><code>56922cf</code></a>
[react-native-renderer] Delete Paper (legacy) renderer (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/36285">#36285</a>)</li>
<li><a
href="https://github.com/react/react/commit/74568e8627aa43469b74f2972f427a209639d0b6"><code>74568e8</code></a>
[Flight] Transport <code>AggregateErrors.errors</code> (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/36156">#36156</a>)</li>
<li><a
href="https://github.com/react/react/commit/e66ef6480ecd19c6885f2c06dec34fec1fdc0a98"><code>e66ef64</code></a>
[tests] remove withoutStack from assertConsole helpers (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/35498">#35498</a>)</li>
<li><a
href="https://github.com/react/react/commit/db71391c5c70dc113560d1c23d0b6548604d827f"><code>db71391</code></a>
[Fiber] Instrument the lazy initializer thenable in all cases (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/35521">#35521</a>)</li>
<li><a
href="https://github.com/react/react/commit/3e1abcc8d7083a13adf4774feb0d67ecbe4a2bc4"><code>3e1abcc</code></a>
[tests] Require exact error messages in assertConsole helpers (<a
href="https://github.com/react/react/tree/HEAD/packages/react/issues/35497">#35497</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/react/react/commits/v19.3.0/packages/react">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for react since your current version.</p>
</details>
<br />

Updates `@types/react` from 18.3.28 to 19.3.0
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react">compare
view</a></li>
</ul>
</details>
<br />

Updates `react-dom` from 18.3.1 to 19.3.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/react/react/releases">react-dom's
releases</a>.</em></p>
<blockquote>
<h2>19.3.0 (September 9, 2026)</h2>
<p>Below is a list of all new features, APIs, and bug fixes.</p>
<p>Read the <a href="https://react.dev/blog/2026/09/09/react-19-3">React
19.3 release post</a> for more information.</p>
<h2>New React Features</h2>
<ul>
<li><code>&lt;ViewTransition /&gt;</code>: Adds <code>&lt;ViewTransition
/&gt;</code> and <code>addTransitionType</code> APIs to power View
Transition animations in React (<a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a>, <a
href="https://github.com/jackpope"><code>@​jackpope</code></a>, <a
href="https://github.com/gaearon"><code>@​gaearon</code></a>: <a
href="https://redirect.github.com/facebook/react/pull/31975">#31975</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31987">#31987</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31996">#31996</a>,
<a
href="https://redirect.github.com/facebook/react/pull/31999">#31999</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32001">#32001</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32002">#32002</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32028">#32028</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32029">#32029</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32031">#32031</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32034">#32034</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32038">#32038</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32041">#32041</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32050">#32050</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32090">#32090</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32105">#32105</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32254">#32254</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32379">#32379</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32422">#32422</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32462">#32462</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32540">#32540</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32545">#32545</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32585">#32585</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32599">#32599</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32611">#32611</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32612">#32612</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32617">#32617</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32651">#32651</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32653">#32653</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32656">#32656</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32664">#32664</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32699">#32699</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32723">#32723</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32734">#32734</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32751">#32751</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32752">#32752</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32760">#32760</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32761">#32761</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32764">#32764</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32772">#32772</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32790">#32790</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32819">#32819</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32820">#32820</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32822">#32822</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32833">#32833</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32849">#32849</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33094">#33094</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33191">#33191</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33200">#33200</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33206">#33206</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33293">#33293</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33330">#33330</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33331">#33331</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33332">#33332</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33357">#33357</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33362">#33362</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33433">#33433</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33576">#33576</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34374">#34374</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34450">#34450</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34481">#34481</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34500">#34500</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34502">#34502</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34510">#34510</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34511">#34511</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34539">#34539</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35567">#35567</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35564">#35564</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35485">#35485</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35380">#35380</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35063">#35063</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35060">#35060</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34676">#34676</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36917">#36917</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35337">#35337</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35520">#35520</a>)</li>
<li>Fragment Refs: Add Refs to <code>&lt;Fragment /&gt;</code> to
support composable platform behavior (<a
href="https://github.com/jackpope"><code>@​jackpope</code></a>, <a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a>, <a
href="https://github.com/eps1lon"><code>@​eps1lon</code></a>, <a
href="https://github.com/Dhakshin2007"><code>@​Dhakshin2007</code></a>,
<a href="https://github.com/chirokas"><code>@​chirokas</code></a>, <a
href="https://github.com/teamleaderleo"><code>@​teamleaderleo</code></a>,
<a
href="https://github.com/fallintoplace"><code>@​fallintoplace</code></a>:
<a
href="https://redirect.github.com/facebook/react/pull/32465">#32465</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32613">#32613</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32619">#32619</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32654">#32654</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32660">#32660</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32682">#32682</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32722">#32722</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32813">#32813</a>,
<a
href="https://redirect.github.com/facebook/react/pull/32814">#32814</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33056">#33056</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33058">#33058</a>,
<a
href="https://redirect.github.com/facebook/react/pull/33093">#33093</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34069">#34069</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34103">#34103</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34544">#34544</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34545">#34545</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37062">#37062</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37061">#37061</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37060">#37060</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36047">#36047</a>,
<a
href="https://redirect.github.com/facebook/react/pull/36010">#36010</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35642">#35642</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35641">#35641</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35637">#35637</a>,
<a
href="https://redirect.github.com/facebook/react/pull/35630">#35630</a>,
<a
href="https://redirect.github.com/facebook/react/pull/34935">#34935</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37457">#37457</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37408">#37408</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37326">#37326</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37251">#37251</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37171">#37171</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37169">#37169</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37168">#37168</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37167">#37167</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37166">#37166</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37165">#37165</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37164">#37164</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37163">#37163</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37162">#37162</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37161">#37161</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37160">#37160</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37125">#37125</a>,
<a
href="https://redirect.github.com/facebook/react/pull/37063">#37063</a>)</li>
</ul>
<h2>New React DOM Features</h2>
<ul>
<li><code>browser()</code>: a new…
Bumps the actions group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `4.4.0` |
`7.0.1` |
|
[julia-actions/setup-julia](https://github.com/julia-actions/setup-julia)
| `2.7.0` | `3.0.2` |
| [julia-actions/cache](https://github.com/julia-actions/cache) |
`2.1.0` | `3.3.0` |
| [actions/cache/restore](https://github.com/actions/cache) | `4.3.0` |
`6.1.0` |
| [actions/cache/save](https://github.com/actions/cache) | `4.3.0` |
`6.1.0` |
| [actions/upload-artifact](https://github.com/actions/upload-artifact)
| `4.6.2` | `7.0.1` |

Updates `actions/checkout` from 4.4.0 to 7.0.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/checkout/releases">actions/checkout's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.1</h2>
<h2>What's Changed</h2>
<ul>
<li>skip running unsafe pr check if input is default by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2518">actions/checkout#2518</a></li>
<li>trim only ascii whitespace for branch by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2521">actions/checkout#2521</a></li>
<li>escape values passed to --unset by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2530">actions/checkout#2530</a></li>
<li>Various dependency updates</li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v7...v7.0.1">https://github.com/actions/checkout/compare/v7...v7.0.1</a></p>
<h2>v7.0.0</h2>
<h2>What's Changed</h2>
<ul>
<li>block checking out fork pr for pull_request_target and workflow_run
by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
<li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
minor-actions-dependencies group across 1 directory by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li>
<li>Bump flatted from 3.3.1 to 3.4.2 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li>
<li>Bump js-yaml from 4.1.0 to 4.2.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li>
<li>Bump <code>@​actions/core</code> and
<code>@​actions/tool-cache</code> and Remove uuid by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li>
<li>upgrade module to esm and update dependencies by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li>
<li>Bump the minor-npm-dependencies group across 1 directory with 3
updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li>
<li>getting ready for checkout v7 release by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2464">actions/checkout#2464</a></li>
<li>update error wording by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2467">actions/checkout#2467</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v6.0.3...v7.0.0">https://github.com/actions/checkout/compare/v6.0.3...v7.0.0</a></p>
<h2>v6.1.0</h2>
<h2>What's Changed</h2>
<ul>
<li><strong>[BREAKING]</strong> backport
<code>allow-unsafe-pr-checkout</code> to v6 by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2500">actions/checkout#2500</a></li>
<li>backport fixes to releases-v6 by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2527">actions/checkout#2527</a></li>
</ul>
<p><a
href="https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/">https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/</a>
for more details about this breaking change</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v6.0.3...v6.1.0">https://github.com/actions/checkout/compare/v6.0.3...v6.1.0</a></p>
<h2>v6.0.3</h2>
<h2>What's Changed</h2>
<ul>
<li>Update changelog by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2357">actions/checkout#2357</a></li>
<li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
<li>Fix checkout init for SHA-256 repositories by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
<li>Update changelog for v6.0.3 by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2446">actions/checkout#2446</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/yaananth"><code>@​yaananth</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v6...v6.0.3">https://github.com/actions/checkout/compare/v6...v6.0.3</a></p>
<h2>v6.0.2</h2>
<h2>What's Changed</h2>
<ul>
<li>Add orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID
is set by <a
href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2355">actions/checkout#2355</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<h2>v7.0.1</h2>
<ul>
<li>Skip running unsafe pr check if input is default by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2518">actions/checkout#2518</a></li>
<li>Trim only ascii whitespace for branch by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2521">actions/checkout#2521</a></li>
<li>Escape values passed to --unset by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2530">actions/checkout#2530</a></li>
<li>Various dependency updates</li>
</ul>
<h2>v7.0.0</h2>
<ul>
<li>Block checking out fork PR for pull_request_target and workflow_run
by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
<li>Various dependency updates</li>
</ul>
<h2>v6.0.3</h2>
<ul>
<li>Fix checkout init for SHA-256 repositories by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
<li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
</ul>
<h2>v6.0.2</h2>
<ul>
<li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
</ul>
<h2>v6.0.1</h2>
<ul>
<li>Add worktree support for persist-credentials includeIf by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
</ul>
<h2>v6.0.0</h2>
<ul>
<li>Persist creds to a separate file by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li>
<li>Update README to include Node.js 24 support details and requirements
by <a href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li>
</ul>
<h2>v5.0.1</h2>
<ul>
<li>Port v6 cleanup to v5 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li>
</ul>
<h2>v5.0.0</h2>
<ul>
<li>Update actions checkout to use node 24 by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li>
</ul>
<h2>v4.3.1</h2>
<ul>
<li>Port v6 cleanup to v4 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li>
</ul>
<h2>v4.3.0</h2>
<ul>
<li>docs: update README.md by <a
href="https://github.com/motss"><code>@​motss</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li>
<li>Add internal repos for checking out multiple repositories by <a
href="https://github.com/mouismail"><code>@​mouismail</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li>
<li>Documentation update - add recommended permissions to Readme by <a
href="https://github.com/benwells"><code>@​benwells</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li>
<li>Adjust positioning of user email note and permissions heading by <a
href="https://github.com/joshmgross"><code>@​joshmgross</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li>
<li>Update README.md by <a
href="https://github.com/nebuk89"><code>@​nebuk89</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li>
<li>Update CODEOWNERS for actions by <a
href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li>
<li>Update package dependencies by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li>
</ul>
<h2>v4.2.2</h2>
<ul>
<li><code>url-helper.ts</code> now leverages well-known environment
variables by <a href="https://github.com/jww3"><code>@​jww3</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li>
<li>Expand unit test coverage for <code>isGhes</code> by <a
href="https://github.com/jww3"><code>@​jww3</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li>
</ul>
<h2>v4.2.1</h2>
<ul>
<li>Check out other refs/* by commit if provided, fall back to ref by <a
href="https://github.com/orhantoy"><code>@​orhantoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/checkout/commit/3d3c42e5aac5ba805825da76410c181273ba90b1"><code>3d3c42e</code></a>
prep v7.0.1 release (<a
href="https://redirect.github.com/actions/checkout/issues/2531">#2531</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/28802689a136bfcdb721715abd713740beecbe07"><code>2880268</code></a>
escape values passed to --unset (<a
href="https://redirect.github.com/actions/checkout/issues/2530">#2530</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/12cd2235efa0937479335606d7c3ac9f6c0973b1"><code>12cd223</code></a>
trim only ascii whitespace for branch (<a
href="https://redirect.github.com/actions/checkout/issues/2521">#2521</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/62661c4e71a304b2823ed026347b8d34c3eac541"><code>62661c4</code></a>
skip running unsafe pr check if input is default (<a
href="https://redirect.github.com/actions/checkout/issues/2518">#2518</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/e8d4307400f9427dba7cb98e488d6ab85f1cec5f"><code>e8d4307</code></a>
Bump the minor-actions-dependencies group with 2 updates (<a
href="https://redirect.github.com/actions/checkout/issues/2499">#2499</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/631c942040754b6e095e929c1677c07e10ed4f87"><code>631c942</code></a>
eslint 9 (<a
href="https://redirect.github.com/actions/checkout/issues/2474">#2474</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/4f1f4aec02e41874fa0262ea8ff5172d7978ad1e"><code>4f1f4ae</code></a>
Bump actions/upload-artifact from 4 to 7 (<a
href="https://redirect.github.com/actions/checkout/issues/2476">#2476</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/ba097532fb203f7e88c9c3c0b899b49469908a92"><code>ba09753</code></a>
Bump actions/checkout from 6 to 7 (<a
href="https://redirect.github.com/actions/checkout/issues/2488">#2488</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/b9e0990d219a03df7633c93f6f005a8fecbcab22"><code>b9e0990</code></a>
Bump docker/login-action from 3.3.0 to 4.2.0 (<a
href="https://redirect.github.com/actions/checkout/issues/2479">#2479</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/e8cb398be4a550817e382abf69e4c12c76fce1f2"><code>e8cb398</code></a>
Bump docker/build-push-action from 6.5.0 to 7.2.0 (<a
href="https://redirect.github.com/actions/checkout/issues/2478">#2478</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/actions/checkout/compare/11d5960a326750d5838078e36cf38b85af677262...3d3c42e5aac5ba805825da76410c181273ba90b1">compare
view</a></li>
</ul>
</details>
<br />

Updates `julia-actions/setup-julia` from 2.7.0 to 3.0.2
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/julia-actions/setup-julia/releases">julia-actions/setup-julia's
releases</a>.</em></p>
<blockquote>
<h2>v3.0.2</h2>
<h2>What's Changed</h2>
<p>We fixed a bug (<a
href="https://redirect.github.com/julia-actions/setup-julia/issues/389">#389</a>).</p>
<p>We also updated our documentation, and we updated a CI
dependency.</p>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/krynju"><code>@​krynju</code></a> made
their first contribution in <a
href="https://redirect.github.com/julia-actions/setup-julia/pull/389">julia-actions/setup-julia#389</a></li>
</ul>
<h2>Full Changelog</h2>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/julia-actions/setup-julia/compare/v3.0.1...v3.0.2">https://github.com/julia-actions/setup-julia/compare/v3.0.1...v3.0.2</a></p>
<h2>v3.0.1</h2>
<h2>What's Changed</h2>
<p>This is a bugfix release that fixes an error seen when using
<code>min-minor</code> or <code>min-patch</code>.</p>
<h2>Full Changelog</h2>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/julia-actions/setup-julia/compare/v3.0.0...v3.0.1">https://github.com/julia-actions/setup-julia/compare/v3.0.0...v3.0.1</a></p>
<h2>v3.0.0</h2>
<h2>:warning: Breaking Changes, and Migration Guide for v2 ⟶ v3</h2>
<ol>
<li>v3 requires Node 24 (compared to v2, which required Node 20).</li>
<li>The behavior of <code>version: min</code> has changed between v2 and
v3.
<ul>
<li>In v2, <code>version: min</code> would resolve to the minimum
major/minor/patch, e.g. 1.10.0.</li>
<li>In v3, <code>version: min</code> resolves to the minimum major/minor
but the latest patch, e.g. 1.10.11.</li>
<li>If you specifically want the minimum major/minor/patch under v3, you
should specify <code>version: min-patch</code>. Note: v3 also adds the
alias <code>version: min-minor</code>, which is equivalent to
<code>version: min</code>.</li>
</ul>
</li>
<li>v3 will throw an error if <code>x86_64</code> Julia binaries are
requested on Apple Silicon macOS. (Under v2, this was a warning.) Under
v3, if you specifically want to run <code>x86_64</code> Julia binaries
on Apple Silicon (under Rosetta 2), you must now opt-in by specifying
the <code>force-arch: true</code> input.</li>
</ol>
<h2>Other Changes</h2>
<p>We updated some dependencies, and we improved and updated the CI
tooling on this repo.</p>
<h2>Full Changelog</h2>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/julia-actions/setup-julia/compare/v2.7.0...v3.0.0">https://github.com/julia-actions/setup-julia/compare/v2.7.0...v3.0.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/julia-actions/setup-julia/commit/fa02766e078afaaf09b14210362cee14137e6a32"><code>fa02766</code></a>
Bug fix: Validate cached julia binary exists and check PATH resolution
(<a
href="https://redirect.github.com/julia-actions/setup-julia/issues/389">#389</a>)</li>
<li><a
href="https://github.com/julia-actions/setup-julia/commit/ff7816164460c427b20a66b6cc8d1355a02a9cb4"><code>ff78161</code></a>
Bump julia-actions/setup-julia from 2.7.0 to 3.0.1 in the
all-github-actions ...</li>
<li><a
href="https://github.com/julia-actions/setup-julia/commit/fe02cb74dba5726479e2d506f6b507b6ddb73db0"><code>fe02cb7</code></a>
README: Add a link to the v2-to-v3 release notes (<a
href="https://redirect.github.com/julia-actions/setup-julia/issues/388">#388</a>)</li>
<li><a
href="https://github.com/julia-actions/setup-julia/commit/f6f565d9f7cf12f53dc8045742460d6260ad3b39"><code>f6f565d</code></a>
Bugfix: Fix an error seen when using <code>min-minor</code> or
<code>min-patch</code> (<a
href="https://redirect.github.com/julia-actions/setup-julia/issues/387">#387</a>)</li>
<li><a
href="https://github.com/julia-actions/setup-julia/commit/4a12c5f801ca5ef0458bba44687563ef276522dd"><code>4a12c5f</code></a>
Breaking: Change <code>min</code> to return the latest patch (but still
the minimum majo...</li>
<li><a
href="https://github.com/julia-actions/setup-julia/commit/a8c65a2a580b6a5cf30070e825e62f9fc0fee1d7"><code>a8c65a2</code></a>
Bump the all-github-actions group across 1 directory with 2 updates (<a
href="https://redirect.github.com/julia-actions/setup-julia/issues/381">#381</a>)</li>
<li><a
href="https://github.com/julia-actions/setup-julia/commit/92d77f50b4603afec878503aa7f1648871b41468"><code>92d77f5</code></a>
Bump picomatch from 2.3.1 to 2.3.2 (<a
href="https://redirect.github.com/julia-actions/setup-julia/issues/379">#379</a>)</li>
<li><a
href="https://github.com/julia-actions/setup-julia/commit/679f1443130ae12882cadc1bf725aaff2f6590b2"><code>679f144</code></a>
Bump handlebars from 4.7.8 to 4.7.9 (<a
href="https://redirect.github.com/julia-actions/setup-julia/issues/377">#377</a>)</li>
<li><a
href="https://github.com/julia-actions/setup-julia/commit/7c976c80e8b3d6cdaef75efc2e46a30e97e75894"><code>7c976c8</code></a>
Add workflow to run make everything-from-scratch (<a
href="https://redirect.github.com/julia-actions/setup-julia/issues/378">#378</a>)</li>
<li><a
href="https://github.com/julia-actions/setup-julia/commit/101e139aea5ec675ed0fb31aba9ce128b5c8e6a6"><code>101e139</code></a>
Breaking: Migrate from Node 20 to Node 24 (<a
href="https://redirect.github.com/julia-actions/setup-julia/issues/374">#374</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/julia-actions/setup-julia/compare/4c0cb0fce8556fdb04a90347310e5db8b1f98fb9...fa02766e078afaaf09b14210362cee14137e6a32">compare
view</a></li>
</ul>
</details>
<br />

Updates `julia-actions/cache` from 2.1.0 to 3.3.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/julia-actions/cache/releases">julia-actions/cache's
releases</a>.</em></p>
<blockquote>
<h2>v3.3.0</h2>
<h2>What's Changed</h2>
<p>We migrated this action from JavaScript to TypeScript. Users should
not notice any difference.</p>
<p>We also updated some dependencies.</p>
<h2>Full Changelog</h2>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/julia-actions/cache/compare/v3.2.0...v3.3.0">https://github.com/julia-actions/cache/compare/v3.2.0...v3.3.0</a></p>
<h2>v3.2.0</h2>
<h2>New Features</h2>
<ul>
<li>Stream tar archives directly to/from GCP storage without
intermediate files by <a
href="https://github.com/wsmoses"><code>@​wsmoses</code></a> in <a
href="https://redirect.github.com/julia-actions/cache/pull/245">julia-actions/cache#245</a></li>
<li>Add option to use (multithreaded) zstd for gcp by <a
href="https://github.com/wsmoses"><code>@​wsmoses</code></a> in <a
href="https://redirect.github.com/julia-actions/cache/pull/244">julia-actions/cache#244</a></li>
<li>Add optional prefix for uploads by <a
href="https://github.com/wsmoses"><code>@​wsmoses</code></a> in <a
href="https://redirect.github.com/julia-actions/cache/pull/246">julia-actions/cache#246</a></li>
</ul>
<h2>Other changes</h2>
<ul>
<li>We updated some dependencies (JavaScript and CI).</li>
<li>We implemented a 7-day dependency cooldown for our
dependencies.</li>
<li>We updated our docs.</li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/JJ"><code>@​JJ</code></a> made their
first contribution in <a
href="https://redirect.github.com/julia-actions/cache/pull/228">julia-actions/cache#228</a></li>
<li><a
href="https://github.com/DilumAluthge-LLM"><code>@​DilumAluthge-LLM</code></a>
made their first contribution in <a
href="https://redirect.github.com/julia-actions/cache/pull/232">julia-actions/cache#232</a></li>
</ul>
<h2>Full Changelog</h2>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/julia-actions/cache/compare/v3.1.0...v3.2.0">https://github.com/julia-actions/cache/compare/v3.1.0...v3.2.0</a></p>
<h2>v3.1.0</h2>
<h2>What's Changed</h2>
<p>New feature: We added support for Google Cloud Platform (<a
href="https://redirect.github.com/julia-actions/cache/pull/204">julia-actions/cache#204</a>).</p>
<p>We also updated some dependencies.</p>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/wsmoses"><code>@​wsmoses</code></a> made
their first contribution in <a
href="https://redirect.github.com/julia-actions/cache/pull/204">julia-actions/cache#204</a></li>
</ul>
<h2>Full Changelog</h2>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/julia-actions/cache/compare/v3.0.2...v3.1.0">https://github.com/julia-actions/cache/compare/v3.0.2...v3.1.0</a></p>
<h2>v3.0.2</h2>
<h2>What's Changed</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/julia-actions/cache/commit/a7bed9df697e5d7309d68afe7542a87621a8b6c8"><code>a7bed9d</code></a>
Update some NPM dependencies (<a
href="https://redirect.github.com/julia-actions/cache/issues/257">#257</a>)</li>
<li><a
href="https://github.com/julia-actions/cache/commit/56d812563b4f49acdb1d9c53619c96439b31ba0b"><code>56d8125</code></a>
Migrate from JavaScript to TypeScript (<a
href="https://redirect.github.com/julia-actions/cache/issues/248">#248</a>)</li>
<li><a
href="https://github.com/julia-actions/cache/commit/fcb41b5b5bc4ac257a49aced16fcba2cb661881e"><code>fcb41b5</code></a>
Bump brace-expansion from 1.1.13 to 1.1.18 (<a
href="https://redirect.github.com/julia-actions/cache/issues/256">#256</a>)</li>
<li><a
href="https://github.com/julia-actions/cache/commit/592ca3741987630945223e225e1ba104c97a6c03"><code>592ca37</code></a>
<code>.gitattributes</code>: Hide generated JS code from diffs and
language stats (<a
href="https://redirect.github.com/julia-actions/cache/issues/253">#253</a>)</li>
<li><a
href="https://github.com/julia-actions/cache/commit/eb70237df625bd91b38a0b684eb058027c7d811d"><code>eb70237</code></a>
Bump actions/checkout from 7.0.0 to 7.0.1 (<a
href="https://redirect.github.com/julia-actions/cache/issues/249">#249</a>)</li>
<li><a
href="https://github.com/julia-actions/cache/commit/d3af4212ce0e42f241c17083987a9766ce554146"><code>d3af421</code></a>
Bump actions/setup-node from 6.4.0 to 7.0.0 (<a
href="https://redirect.github.com/julia-actions/cache/issues/250">#250</a>)</li>
<li><a
href="https://github.com/julia-actions/cache/commit/b7788abd52452d5bc033d69796e110d9906af4ab"><code>b7788ab</code></a>
Add optional prefix for uploads (<a
href="https://redirect.github.com/julia-actions/cache/issues/246">#246</a>)</li>
<li><a
href="https://github.com/julia-actions/cache/commit/3208dfc5fe6e38f97e521117e04f158017e1de55"><code>3208dfc</code></a>
Add option to use (multithreaded) zstd for gcp (<a
href="https://redirect.github.com/julia-actions/cache/issues/244">#244</a>)</li>
<li><a
href="https://github.com/julia-actions/cache/commit/f6f2182f902b81f43d25896e3b58b620df0e4a43"><code>f6f2182</code></a>
Stream tar archives directly to/from GCP storage without intermediate
files (...</li>
<li><a
href="https://github.com/julia-actions/cache/commit/8020c5e03fae93ee08711f97ad535d495a7a7c78"><code>8020c5e</code></a>
Bump <code>@​google-cloud/storage</code> from 7.19.0 to 7.21.0 (<a
href="https://redirect.github.com/julia-actions/cache/issues/240">#240</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/julia-actions/cache/compare/d10a6fd8f31b12404a54613ebad242900567f2b9...a7bed9df697e5d7309d68afe7542a87621a8b6c8">compare
view</a></li>
</ul>
</details>
<br />

Updates `actions/cache/restore` from 4.3.0 to 6.1.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/cache/releases">actions/cache/restore's
releases</a>.</em></p>
<blockquote>
<h2>v6.1.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Bump <code>@​actions/cache</code> to v6.1.0 - handle read-only cache
access by <a
href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1768">actions/cache#1768</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v6...v6.1.0">https://github.com/actions/cache/compare/v6...v6.1.0</a></p>
<h2>v6.0.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Update packages, migrate to ESM by <a
href="https://github.com/Samirat"><code>@​Samirat</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1760">actions/cache#1760</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v6.0.0">https://github.com/actions/cache/compare/v5...v6.0.0</a></p>
<h2>v5.1.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Bump <code>@​actions/cache</code> to v5.1.0 - handle read-only cache
access by <a
href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1775">actions/cache#1775</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v5.1.0">https://github.com/actions/cache/compare/v5...v5.1.0</a></p>
<h2>v5.0.5</h2>
<h2>What's Changed</h2>
<ul>
<li>Update ts-http-runtime dependency by <a
href="https://github.com/yacaovsnc"><code>@​yacaovsnc</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1747">actions/cache#1747</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v5.0.5">https://github.com/actions/cache/compare/v5...v5.0.5</a></p>
<h2>v5.0.4</h2>
<h2>What's Changed</h2>
<ul>
<li>Add release instructions and update maintainer docs by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1696">actions/cache#1696</a></li>
<li>Potential fix for code scanning alert no. 52: Workflow does not
contain permissions by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1697">actions/cache#1697</a></li>
<li>Fix workflow permissions and cleanup workflow names / formatting by
<a href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1699">actions/cache#1699</a></li>
<li>docs: Update examples to use the latest version by <a
href="https://github.com/XZTDean"><code>@​XZTDean</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1690">actions/cache#1690</a></li>
<li>Fix proxy integration tests by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1701">actions/cache#1701</a></li>
<li>Fix cache key in examples.md for bun.lock by <a
href="https://github.com/RyPeck"><code>@​RyPeck</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1722">actions/cache#1722</a></li>
<li>Update dependencies &amp; patch security vulnerabilities by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1738">actions/cache#1738</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/XZTDean"><code>@​XZTDean</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/cache/pull/1690">actions/cache#1690</a></li>
<li><a href="https://github.com/RyPeck"><code>@​RyPeck</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/cache/pull/1722">actions/cache#1722</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v5.0.4">https://github.com/actions/cache/compare/v5...v5.0.4</a></p>
<h2>v5.0.3</h2>
<h2>What's Changed</h2>
<ul>
<li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a
href="https://github.com/actions/cache/security/dependabot/33">https://github.com/actions/cache/security/dependabot/33</a>)</li>
<li>Bump <code>@actions/core</code> to v2.0.3</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/actions/cache/blob/main/RELEASES.md">actions/cache/restore's
changelog</a>.</em></p>
<blockquote>
<h1>Releases</h1>
<h2>How to prepare a release</h2>
<blockquote>
<p>[!NOTE]
Relevant for maintainers with write access only.</p>
</blockquote>
<ol>
<li>Switch to a new branch from <code>main</code>.</li>
<li>Run <code>npm test</code> to ensure all tests are passing.</li>
<li>Update the version in <a
href="https://github.com/actions/cache/blob/main/package.json"><code>https://github.com/actions/cache/blob/main/package.json</code></a>.</li>
<li>Run <code>npm run build</code> to update the compiled files.</li>
<li>Update this <a
href="https://github.com/actions/cache/blob/main/RELEASES.md"><code>https://github.com/actions/cache/blob/main/RELEASES.md</code></a>
with the new version and changes in the <code>## Changelog</code>
section.</li>
<li>Run <code>licensed cache</code> to update the license report.</li>
<li>Run <code>licensed status</code> and resolve any warnings by
updating the <a
href="https://github.com/actions/cache/blob/main/.licensed.yml"><code>https://github.com/actions/cache/blob/main/.licensed.yml</code></a>
file with the exceptions.</li>
<li>Commit your changes and push your branch upstream.</li>
<li>Open a pull request against <code>main</code> and get it reviewed
and merged.</li>
<li>Draft a new release <a
href="https://github.com/actions/cache/releases">https://github.com/actions/cache/releases</a>
use the same version number used in <code>package.json</code>
<ol>
<li>Create a new tag with the version number.</li>
<li>Auto generate release notes and update them to match the changes you
made in <code>RELEASES.md</code>.</li>
<li>Toggle the set as the latest release option.</li>
<li>Publish the release.</li>
</ol>
</li>
<li>Navigate to <a
href="https://github.com/actions/cache/actions/workflows/release-new-action-version.yml">https://github.com/actions/cache/actions/workflows/release-new-action-version.yml</a>
<ol>
<li>There should be a workflow run queued with the same version
number.</li>
<li>Approve the run to publish the new version and update the major tags
for this action.</li>
</ol>
</li>
</ol>
<h2>Changelog</h2>
<h3>6.1.0</h3>
<ul>
<li>Bump <code>@actions/cache</code> to v6.1.0 to pick up <a
href="https://redirect.github.com/actions/toolkit/pull/2435">actions/toolkit#2435
Handle cache write error due to read-only token</a></li>
<li>Switch redundant &quot;Cache save failed&quot; warning to debug log
in save-only</li>
</ul>
<h3>6.0.0</h3>
<ul>
<li>Updated <code>@actions/cache</code> to ^6.0.1,
<code>@actions/core</code> to ^3.0.1, <code>@actions/exec</code> to
^3.0.0, <code>@actions/io</code> to ^3.0.2</li>
<li>Migrated to ESM module system</li>
<li>Upgraded Jest to v30 and test infrastructure to be ESM
compatible</li>
</ul>
<h3>5.0.4</h3>
<ul>
<li>Bump <code>minimatch</code> to v3.1.5 (fixes ReDoS via globstar
patterns)</li>
<li>Bump <code>undici</code> to v6.24.1 (WebSocket decompression bomb
protection, header validation fixes)</li>
<li>Bump <code>fast-xml-parser</code> to v5.5.6</li>
</ul>
<h3>5.0.3</h3>
<ul>
<li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a
href="https://github.com/actions/cache/security/dependabot/33">https://github.com/actions/cache/security/dependabot/33</a>)</li>
<li>Bump <code>@actions/core</code> to v2.0.3</li>
</ul>
<h3>5.0.2</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/cache/commit/55cc8345863c7cc4c66a329aec7e433d2d1c52a9"><code>55cc834</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/cache/issues/1768">#1768</a>
from jasongin/readonly-cache</li>
<li><a
href="https://github.com/actions/cache/commit/d8cd72f230726cdf4457ebb61ec1b593a8d12337"><code>d8cd72f</code></a>
Bump <code>@​actions/cache</code> to v6.1.0 - handle cache write error
due to RO token</li>
<li><a
href="https://github.com/actions/cache/commit/2c8a9bd7457de244a408f35966fab2fb45fda9c8"><code>2c8a9bd</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/cache/issues/1760">#1760</a>
from actions/samirat/esm_migration_and_package_update</li>
<li><a
href="https://github.com/actions/cache/commit/e9b91fdc3fea7d79165fceb79042ef45c2d51023"><code>e9b91fd</code></a>
Prettier fixes</li>
<li><a
href="https://github.com/actions/cache/commit/e4884b8ff7f92ef6b52c79eda480bbc86e685adb"><code>e4884b8</code></a>
Rebuild dist</li>
<li><a
href="https://github.com/actions/cache/commit/10baf0191a3c426ea0fa4a3253a5c04233b6e18f"><code>10baf01</code></a>
Fixed licenses</li>
<li><a
href="https://github.com/actions/cache/commit/e39b386c9004d72a15d864ade8c0b3a702d47a37"><code>e39b386</code></a>
Fix test mock return order</li>
<li><a
href="https://github.com/actions/cache/commit/b6928203372a8571ff984c0c883ef3a1adfb0c06"><code>b692820</code></a>
PR feedback</li>
<li><a
href="https://github.com/actions/cache/commit/60749128a44d25d3c520a489e576380cf00ff3f1"><code>6074912</code></a>
Rebuild dist bundles as ESM to match type:module</li>
<li><a
href="https://github.com/actions/cache/commit/5a912e8b4af820fa082a0e75cfd2c782f8fbfe0e"><code>5a912e8</code></a>
Fix lint and jest issues</li>
<li>Additional commits viewable in <a
href="https://github.com/actions/cache/compare/0057852bfaa89a56745cba8c7296529d2fc39830...55cc8345863c7cc4c66a329aec7e433d2d1c52a9">compare
view</a></li>
</ul>
</details>
<br />

Updates `actions/cache/save` from 4.3.0 to 6.1.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/cache/releases">actions/cache/save's
releases</a>.</em></p>
<blockquote>
<h2>v6.1.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Bump <code>@​actions/cache</code> to v6.1.0 - handle read-only cache
access by <a
href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1768">actions/cache#1768</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v6...v6.1.0">https://github.com/actions/cache/compare/v6...v6.1.0</a></p>
<h2>v6.0.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Update packages, migrate to ESM by <a
href="https://github.com/Samirat"><code>@​Samirat</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1760">actions/cache#1760</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v6.0.0">https://github.com/actions/cache/compare/v5...v6.0.0</a></p>
<h2>v5.1.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Bump <code>@​actions/cache</code> to v5.1.0 - handle read-only cache
access by <a
href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1775">actions/cache#1775</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v5.1.0">https://github.com/actions/cache/compare/v5...v5.1.0</a></p>
<h2>v5.0.5</h2>
<h2>What's Changed</h2>
<ul>
<li>Update ts-http-runtime dependency by <a
href="https://github.com/yacaovsnc"><code>@​yacaovsnc</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1747">actions/cache#1747</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v5.0.5">https://github.com/actions/cache/compare/v5...v5.0.5</a></p>
<h2>v5.0.4</h2>
<h2>What's Changed</h2>
<ul>
<li>Add release instructions and update maintainer docs by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1696">actions/cache#1696</a></li>
<li>Potential fix for code scanning alert no. 52: Workflow does not
contain permissions by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1697">actions/cache#1697</a></li>
<li>Fix workflow permissions and cleanup workflow names / formatting by
<a href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1699">actions/cache#1699</a></li>
<li>docs: Update examples to use the latest version by <a
href="https://github.com/XZTDean"><code>@​XZTDean</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1690">actions/cache#1690</a></li>
<li>Fix proxy integration tests by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1701">actions/cache#1701</a></li>
<li>Fix cache key in examples.md for bun.lock by <a
href="https://github.com/RyPeck"><code>@​RyPeck</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1722">actions/cache#1722</a></li>
<li>Update dependencies &amp; patch security vulnerabilities by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1738">actions/cache#1738</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/XZTDean"><code>@​XZTDean</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/cache/pull/1690">actions/cache#1690</a></li>
<li><a href="https://github.com/RyPeck"><code>@​RyPeck</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/cache/pull/1722">actions/cache#1722</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v5.0.4">https://github.com/actions/cache/compare/v5...v5.0.4</a></p>
<h2>v5.0.3</h2>
<h2>What's Changed</h2>
<ul>
<li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a
href="https://github.com/actions/cache/security/dependabot/33">https://github.com/actions/cache/security/dependabot/33</a>)</li>
<li>Bump <code>@actions/core</code> to v2.0.3</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/actions/cache/blob/main/RELEASES.md">actions/cache/save's
changelog</a>.</em></p>
<blockquote>
<h1>Releases</h1>
<h2>How to prepare a release</h2>
<blockquote>
<p>[!NOTE]
Relevant for maintainers with write access only.</p>
</blockquote>
<ol>
<li>Switch to a new branch from <code>main</code>.</li>
<li>Run <code>npm test</code> to ensure all tests are passing.</li>
<li>Update the version in <a
href="https://github.com/actions/cache/blob/main/package.json"><code>https://github.com/actions/cache/blob/main/package.json</code></a>.</li>
<li>Run <code>npm run build</code> to update the compiled files.</li>
<li>Update this <a
href="https://github.com/actions/cache/blob/main/RELEASES.md"><code>https://github.com/actions/cache/blob/main/RELEASES.md</code></a>
with the new version and changes in the <code>## Changelog</code>
section.</li>
<li>Run <code>licensed cache</code> to update the license report.</li>
<li>Run <code>licensed status</code> and resolve any warnings by
updating the <a
href="https://github.com/actions/cache/blob/main/.licensed.yml"><code>https://github.com/actions/cache/blob/main/.licensed.yml</code></a>
file with the exceptions.</li>
<li>Commit your changes and push your branch upstream.</li>
<li>Open a pull request against <code>main</code> and get it reviewed
and merged.</li>
<li>Draft a new release <a
href="https://github.com/actions/cache/releases">https://github.com/actions/cache/releases</a>
use the same version number used in <code>package.json</code>
<ol>
<li>Create a new tag with the version number.</li>
<li>Auto generate release notes and update them to match the changes you
made in <code>RELEASES.md</code>.</li>
<li>Toggle the set as the latest release option.</li>
<li>Publish the release.</li>
</ol>
</li>
<li>Navigate to <a
href="https://github.com/actions/cache/actions/workflows/release-new-action-version.yml">https://github.com/actions/cache/actions/workflows/release-new-action-version.yml</a>
<ol>
<li>There should be a workflow run queued with the same version
number.</li>
<li>Approve the run to publish the new version and update the major tags
for this action.</li>
</ol>
</li>
</ol>
<h2>Changelog</h2>
<h3>6.1.0</h3>
<ul>
<li>Bump <code>@actions/cache</code> to v6.1.0 to pick up <a
href="https://redirect.github.com/actions/toolkit/pull/2435">actions/toolkit#2435
Handle cache write error due to read-only token</a></li>
<li>Switch redundant &quot;Cache save failed&quot; warning to debug log
in save-only</li>
</ul>
<h3>6.0.0</h3>
<ul>
<li>Updated <code>@actions/cache</code> to ^6.0.1,
<code>@actions/core</code> to ^3.0.1, <code>@actions/exec</code> to
^3.0.0, <code>@actions/io</code> to ^3.0.2</li>
<li>Migrated to ESM module system</li>
<li>Upgraded Jest to v30 and test infrastructure to be ESM
compatible</li>
</ul>
<h3>5.0.4</h3>
<ul>
<li>Bump <code>minimatch</code> to v3.1.5 (fixes ReDoS via globstar
patterns)</li>
<li>Bump <code>undici</code> to v6.24.1 (WebSocket decompression bomb
protection, header validation fixes)</li>
<li>Bump <code>fast-xml-parser</code> to v5.5.6</li>
</ul>
<h3>5.0.3</h3>
<ul>
<li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a
href="https://github.com/actions/cache/security/dependabot/33">https://github.com/actions/cache/security/dependabot/33</a>)</li>
<li>Bump <code>@actions/core</code> to v2.0.3</li>
</ul>
<h3>5.0.2</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/cache/commit/55cc8345863c7cc4c66a329aec7e433d2d1c52a9"><code>55cc834</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/cache/issues/1768">#1768</a>
from jasongin/readonly-cache</li>
<li><a
href="https://github.com/actions/cache/commit/d8cd72f230726cdf4457ebb61ec1b593a8d12337"><code>d8cd72f</code></a>
Bump <code>@​actions/cache</code> to v6.1.0 - handle cache write error
due to RO token</li>
<li><a
href="https://github.com/actions/cache/commit/2c8a9bd7457de244a408f35966fab2fb45fda9c8"><code>2c8a9bd</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/cache/issues/1760">#1760</a>
from actions/samirat/esm_migration_and_package_update</li>
<li><a
href="https://github.com/actions/cache/commit/e9b91fdc3fea7d79165fceb79042ef45c2d51023"><code>e9b91fd</code></a>
Prettier fixes</li>
<li><a
href="https://github.com/actions/cache/commit/e4884b8ff7f92ef6b52c79eda480bbc86e685adb"><code>e4884b8</code></a>
Rebuild dist</li>
<li><a
href="https://github.com/actions/cache/commit/10baf0191a3c426ea0fa4a3253a5c04233b6e18f"><code>10baf01</code></a>
Fixed licenses</li>
<li><a
href="https://github.com/actions/cache/commit/e39b386c9004d72a15d864ade8c0b3a702d47a37"><code>e39b386</code></a>
Fix test mock return order</li>
<li><a
href="https://github.com/actions/cache/commit/b6928203372a8571ff984c0c883ef3a1adfb0c06"><code>b692820</code></a>
PR feedback</li>
<li><a
href="https://github.com/actions/cache/commit/60749128a44d25d3c520a489e576380cf00ff3f1"><code>6074912</code></a>
Rebuild dist bundles as ESM to match type:module</li>
<li><a
href="https://github.com/actions/cache/commit/5a912e8b4af820fa082a0e75cfd2c782f8fbfe0e"><code>5a912e8</code></a>
Fix lint and jest issues</li>
<li>Additional commits viewable in <a
href="https://github.com/actions/cache/compare/0057852bfaa89a56745cba8c7296529d2fc39830...55cc8345863c7cc4c66a329aec7e433d2d1c52a9">compare
view</a></li>
</ul>
</details>
<br />

Updates `actions/upload-artifact` from 4.6.2 to 7.0.1
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/upload-artifact/releases">actions/upload-artifact's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.1</h2>
<h2>What's Changed</h2>
<ul>
<li>Update the readme with direct upload details by <a
href="https://github.com/danwkennedy"><code>@​danwkennedy</code></a> in
<a
href="https://redirect.github.com/actions/upload-artifact/pull/795">actions/upload-artifact#795</a></li>
<li>Readme: bump all the example versions to v7 by <a
href="https://github.com/danwkennedy"><code>@​danwkennedy</code></a> in
<a
href="https://redirect.github.com/actions/upload-artifact/pull/796">actions/upload-artifact#796</a></li>
<li>Include changes in typespec/ts-http-runtime 0.3.5 by <a
href="https://github.com/yacaovsnc"><code>@​yacaovsnc</code></a> in <a
href="https://redirect.github.com/actions/upload-artifact/pull/797">actions/upload-artifact#797</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/upload-artifact/compare/v7...v7.0.1">https://github.com/actions/upload-artifact/compare/v7...v7.0.1</a></p>
<h2>v7.0.0</h2>
<h2>v7 What's new</h2>
<h3>Direct Uploads</h3>
<p>Adds support for uploading single files directly (unzipped). Callers
can set the new <code>archive</code> parameter to <code>false</code> to
skip zipping the file during upload. Right now, we only support single
files. The action will fail if the glob passed resolves to multiple
files. The <code>name</code> parameter is also ignored with this
setting. Instead, the name of the artifact will be the name of the
uploaded file.</p>
<h3>ESM</h3>
<p>To support new versions of the <code>@actions/*</code> packages,
we've upgraded the package to ESM.</p>
<h2>What's Changed</h2>
<ul>
<li>Add proxy integration test by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/upload-artifact/pull/754">actions/upload-artifact#754</a></li>
<li>Upgrade the module to ESM and bump dependencies by <a
href="https://github.com/danwkennedy"><code>@​danwkennedy</code></a> in
<a
href="https://redirect.github.com/actions/upload-artifact/pull/762">actions/upload-artifact#762</a></li>
<li>Support direct file uploads by <a
href="https://github.com/danwkennedy"><code>@​danwkennedy</code></a> in
<a
href="https://redirect.github.com/actions/upload-artifact/pull/764">actions/upload-artifact#764</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/Link"><code>@​Link</code></a>- made
their first contribution in <a
href="https://redirect.github.com/actions/upload-artifact/pull/754">actions/upload-artifact#754</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/upload-artifact/compare/v6...v7.0.0">https://github.com/actions/upload-artifact/compare/v6...v7.0.0</a></p>
<h2>v6.0.0</h2>
<h2>v6 - What's new</h2>
<blockquote>
<p>[!IMPORTANT]
actions/upload-artifact@v6 now runs on Node.js 24 (<code>runs.using:
node24</code>) and requires a minimum Actions Runner version of 2.327.1.
If you are using self-hosted runners, ensure they are updated before
upgrading.</p>
</blockquote>
<h3>Node.js 24</h3>
<p>This release updates the runtime to Node.js 24. v5 had preliminary
support for Node.js 24, however this action was by default still running
on Node.js 20. Now this action by default will run on Node.js 24.</p>
<h2>What's Changed</h2>
<ul>
<li>Upload Artifact Node 24 support by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/upload-artifact/pull/719">actions/upload-artifact#719</a></li>
<li>fix: update <code>@​actions/artifact</code> for Node.js 24 punycode
deprecation by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/upload-artifact/pull/744">actions/upload-artifact#744</a></li>
<li>prepare release v6.0.0 for Node.js 24 support by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/upload-artifact/pull/745">actions/upload-artifact#745</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0">https://github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0</a></p>
<h2>v5.0.0</h2>
<h2>What's Changed</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/upload-artifact/commit/043fb46d1a93c77aae656e7c1c64a875d1fc6a0a"><code>043fb46</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/upload-artifact/issues/797">#797</a>
from actions/yacaovsnc/update-dependency</li>
<li><a
href="https://github.com/actions/upload-artifact/commit/634250c1388765ea7ed0f053e636f1f399000b94"><code>634250c</code></a>
Include changes in typespec/ts-http-runtime 0.3.5</li>
<li><a
href="https://github.com/actions/upload-artifact/commit/e454baaac2be505c9450e11b8f3215c6fc023ce8"><code>e454baa</code></a>
Readme: bump all the example versions to v7 (<a
href="https://redirect.github.com/actions/upload-artifact/issues/796">#796</a>)</li>
<li><a
href="https://github.com/actions/upload-artifact/commit/74fad66b98a6d799dc004d3353ccd0e6f6b2530e"><code>74fad66</code></a>
Update the readme with direct upload details (<a
href="https://redirect.github.com/actions/upload-artifact/issues/795">#795</a>)</li>
<li><a
href="https://github.com/actions/upload-artifact/commit/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f"><code>bbbca2d</code></a>
Support direct file uploads (<a
href="https://redirect.github.com/actions/upload-artifact/issues/764">#764</a>)</li>
<li><a
href="https://github.com/actions/upload-artifact/commit/589182c5a4cec8920b8c1bce3e2fab1c97a02296"><code>589182c</code></a>
Upgrade the module to ESM and bump dependencies (<a
href="https://redirect.github.com/actions/upload-artifact/issues/762">#762</a>)</li>
<li><a
href="https://github.com/actions/upload-artifact/commit/47309c993abb98030a35d55ef7ff34b7fa1074b5"><code>47309c9</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/upload-artifact/issues/754">#754</a>
from actions/Link-/add-proxy-integration-tests</li>
<li><a
href="https://github.com/actions/upload-artifact/commit/02a8460834e70dab0ce194c64360c59dc1475ef0"><code>02a8460</code></a>
Add proxy integration test</li>
<li><a
href="https://github.com/actions/upload-artifact/commit/b7c566a772e6b6bfb58ed0dc250532a479d7789f"><code>b7c566a</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/upload-artifact/issues/745">#745</a>
from actions/upload-artifact-v6-release</li>
<li><a
href="https://github.com/actions/upload-artifact/commit/e516bc8500aaf3d07d591fcd4ae6ab5f9c391d5b"><code>e516bc8</code></a>
docs: correct description of Node.js 24 support in README</li>
<li>Additional commits viewable in <a
href="https://github.com/actions/upload-artifact/compare/ea165f8d65b6e75b540449e92b4886f43607fa02...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
## Why

After #66, the fits run. Run 36194648664 shows the remaining 19 failures
and 6 errors. They all come from one fixture in
`test/unit/test_estimation.jl`: two of its three features fail inside
`MASS::glm.nb` (`n_tested = 1`, `n_failed = 2`, status `partial`).

The fixture is **under-dispersed**: its variance is below its mean in
every group block (taxon 1, group A: mean 10.2, variance 3.1; taxon 2,
group B: mean 30.3, variance 1.5). Under a negative binomial model,
variance = μ + μ²/θ ≥ μ, so the maximum-likelihood θ for this data is
infinite. A direct likelihood fit of the old table gives θ = 2e8 to 2e17
for every taxon under both offsets. `theta.ml` then stops at its
iteration limit, and the estimator marks the fit `failed`. **That is the
right behaviour**, and this PR does not change it.

## What

- `counts_effect` is replaced by a table with the same written-in group
means (10→40, 30→30, 50→5). Each block has a variance near μ + μ²/6, all
counts are ≥ 1 (so RLE is defined), and the numbers are deterministic
literals.
- A comment explains why the fixture has to be over-dispersed and
records the outside-R check.
- `CHANGELOG.md` entry.

## Evidence (outside R: there is no R/Julia in the authoring sandbox)

Two independent NB2 maximum-likelihood fits (a direct scipy likelihood
and statsmodels `NegativeBinomial`) agree to 4 decimals, converge, and
raise no warnings. The table uses the two offsets the tests use:

| taxon | offset | slope | log2FC | θ | p |
|---|---|---|---|---|---|
| t_up | log lib size | 1.4986 | 2.16 | 5.98 | 4e-14 |
| t_flat | log lib size | 0.1578 | 0.23 | 7.63 | 0.34 |
| t_down | log lib size | −2.0470 | −2.95 | 11.97 | 4e-29 |
| t_up | RLE | 1.5451 | 2.23 | 3.52 | 2e-10 |
| t_flat | RLE | 0.2378 | 0.34 | 14.89 | 0.07 |
| t_down | RLE | −2.0510 | −2.96 | 2.99 | 1e-13 |

Every assertion in the testsets holds against these numbers: `estimate ≈
log 4 ± 0.5`, `log2FC ≈ 2 ± 0.8`, `|flat| < 0.6`, `down < 0`, `p(up) <
0.01`. The parity with `glm.nb` itself is what this PR's CI run checks.

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
…70)

## Summary

Makes merging this fork's work into upstream
(`JoshuaJewell/MetaManifold-WebUI`) tractable, and keeps **both** sides
runnable with zero extra effort. The two commits are tooling, config,
and docs only — **no application/analysis logic changes**.

The fork and upstream share only the root commit and then developed in
parallel, so a one-shot `git merge` surfaces **159 conflicting files**
at once. This PR removes that wall three ways:

1. **Merge hygiene** — lockfiles and build output can no longer produce
line-conflict markers; they resolve by regeneration (`.gitattributes`,
`just merge-drivers`).
2. **Profiles & components** — the fork's work is a registry the
maintainer can adopt incrementally, from *pure upstream* (`base`, the
default) to *partially transitional* to *everything* (`full`), with
per-component toggles and automatic conflict triage
(`config/integration.toml`, `scripts/integrate.sh`, `just integrate …`).
3. **Granular re-anchor** — replay the fork's commits one-by-one onto
upstream. **Measured: the whole fork re-anchors with 3 decisions and 0
residual conflicts, producing ~206 reviewable commits** that also share
a real base with upstream (`scripts/reanchor.sh`, `just reanchor`).

It also makes the environment turnkey: `mise.toml` stays the single
source of truth and `just bootstrap` / `setup-full` / `heal` / `doctor`
now cover the whole toolchain **and the R lane** (`renv-restore`), so a
fresh clone always runs.

## Base check

- [x] Base is `hyperpolymath/MetaManifold-WebUI:main`
(engineering/tooling work lands on this fork per `CONTRIBUTING.md`)

## Changes

- `.gitattributes` — lockfiles / build output marked `merge: unset`,
`linguist-generated` (never hand-merge a generated file).
- `config/integration.toml` + `scripts/integrate.sh` + `just integrate
…` — profiles (`base`/`transitional`/`full`), per-component
`augment`/`suspend`, conflict `triage` (auto / component / human),
`verify`.
- `scripts/reanchor.sh` + `just reanchor{,-plan,-manual}` — granular
re-anchor onto upstream (isolated worktree; never touches the current
branch).
- `Justfile` — `doctor` (full toolchain report), `heal` (repair),
`merge-drivers` (opt-in lockfile auto-resolve), `renv-restore`;
`bootstrap`/`setup-full` now cover the R lane and merge drivers.
- `docs/integration/` — `README.md` (guide),
`conflict-map-2026-09-25.md` (measured), `HANDOFF-granular-reanchor.md`
(brief to land it).
- `.gitignore` (track `docs/integration/`), `CONTRIBUTING.md` (pointer).

## Engineering checklist

### Required
- [x] `bun run check` — **N/A: no `frontend/` changes** (frontend
untouched).
- [x] `scripts/check-spdx.sh` / `scripts/check-format.sh` pass
(`check-lint.sh` N/A: no TS changes).
- [x] Conventional commit subjects (`feat(integration):`,
`feat(reanchor):`).
- [x] New source files carry correct SPDX headers (`MPL-2.0`
code/scripts, `CC-BY-SA-4.0` docs).
- [x] No secrets, `.env`, or sequencing data.
- [x] No application-logic changes hidden inside this tooling PR.
### As applicable
- [ ] `CHANGELOG.md` — tooling/docs PR; changelog entry optional.
- [ ] `docs/reproducibility.md` — environment unchanged (`mise.toml`
untouched; only additive Justfile lanes).

## Testing

- `reanchor.sh` validated end-to-end (`plan` + `run`): **206 granular
commits, 0 residual conflicts, 3 logged decisions** (all "respect
upstream's deletion of `pipelinesteps.txt`"); runs in an isolated
worktree, auto-cleans, branch untouched.
- `integrate.sh` validated: `status` / `profiles` / `plan` / `triage` /
`enable` / `disable` / `verify`.
- Justfile structurally validated: 64 recipes, no parse errors, all
dependencies resolve.
- Hygiene gates green (SPDX 289 files, format 337 files).
- Mergeable into `main` with **no file overlap** against `main`'s newer
commits.

---------

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…salvageable delta of #71) (#72)

<!--
SPDX-License-Identifier: CC-BY-SA-4.0
-->
## Summary

Re-anchors **the one genuinely missing piece** of PR #71 onto `main`,
and documents why everything else in that PR is already here in newer
form.

## Why PR #71 cannot merge (measured, 2026-09-26)

1. **Wrong lineage → `mergeable: CONFLICTING` (DIRTY).** The PR branch
is built on the **upstream parent's history** (`JoshuaJewell:main` =
`ecefb1c` is an ancestor; the PR = upstream + 3 commits). `main` here
shares only the **initial commit** `7884553` with it — the exact
fork↔upstream divergence documented in
`docs/integration/conflict-map-2026-09-25.md`. A test merge surfaces
**38 conflicting files** (add/add: ci.yml, ui.yml, package.json,
MetaManifold.jl, Execution.jl, tests, docs, binary `bun.lock`).
2. **Content is ~99% superseded.** Of the PR's 319 changed files, **281
are byte-identical with `main` already** (the migration was re-anchored
earlier via `0e61f4f` and siblings). Net of `main`, the PR branch has
only **+398 lines**, and after filtering to lines the PR itself authored
that `main` truly lacks:
- **`src/analysis/Execution.jl` (124 lines): stub/mock code** (“Mock
p-value”, “Real implementation would call R…”) — replaced on `main` by
the real statistics layer (#57–#66).
- **Schema/doc notes “TSS/CSS/RSS deferred alias”** — obsolete: `main`
implemented exact TSS/CSS/RSS offsets in #61.
- **CI action pins** — older than `main`'s (Dependabot keeps `main` at
checkout v7.0.1 / setup-julia v3.0.2 …).
- **Escape-key dialog handlers** — superseded by native `<dialog>` with
`showModal()` (#32), which supplies Escape/role/focus-trap natively.
- **`lint_source.jl` undeclared-deps, Justfile bootstrap/setup-full,
coupling test** — all present on `main` in deliberately newer forms.
- **The 2 CodeQL alerts (“Workflow does not contain permissions”)** —
the author already fixed these on their branch (`6b481a3`, `eab8ea0`),
and *that* piece is what `main` was still missing.

## Changes

- `.github/workflows/ci.yml`: top-level `permissions: contents: read`
plus job-level blocks on `repo-hygiene` and `test` (`cicd-squabbler`
already declares its own). Mirrors `ui.yml`, which already has a
top-level block, and the fix landed on PR #71's branch.

## Recommendation

**Close #71** in favour of this PR (its remaining unique content would
regress `main`); carry any future application changes to `JoshuaJewell`
per the PR template's Base check.

## Testing

- `npx js-yaml .github/workflows/ci.yml` parses; `permissions` present
at workflow level and on all jobs.
- `scripts/check-spdx.sh` OK (291 files), `scripts/check-format.sh` OK
(339 files), `scripts/check-lint.sh` advisory (bun not installed in
sandbox).

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
## Summary

Refs #8. This is a **draft for review, not production acceptance or an
issue-closure claim**. It implements the DOI workflow and its safety
foundations, but Julia/Nickel runtime verification and the first real
backend performance baseline are blocked in this environment.

### Implementation

- HTTP.jl Zenodo deposition-v1 client with fixed production/sandbox
origins, server-only redacted credentials, suppressed HTTP wire logging,
streamed uploads, bounded 429/Retry-After handling, and no blind replay
of ambiguous create/publish POSTs. Uses the documented legacy
`application/json` contract, not an invented version URL or incompatible
vendor serializer.
- Durable two-phase publication journal: private filesystem storage,
kernel locks, atomic/fsynced write-ahead transitions, immutable
snapshots/ZIP, draft recovery, asynchronous publication reconciliation,
exact remote/local integrity checks, and immutable DOI/provenance
receipts with checksummed downloads.
- Persistent immutable study config/results; exact config/result/method
binding; explicit configuration-only payloads; rejection of
mock/empty/failed results; retained scientific DANGER warnings. DOI
insertion never rewrites scientific objects.
- Reachable Julia-rendered Evidence Mode publication page: private-draft
upload acknowledgement, archive review, DANGER dialog, exact typed
confirmation, reserved versus published identifiers, sandbox TEST
badges, recovery and citations. Minimal launcher integration in
StudyView and the existing (unmounted) AnalysisConfigEditor, rather than
a new TypeScript application feature.
- Explicit CSRF/origin/body guards; publication-aware deletion/rename
protection; hidden-state, encoded-study, symlink and SPA-path
file-serving protections.
- Offline-first `scripts/link-doi.sh`: validated production receipts;
preserved release notes, citation/receipt assets, idempotent Projects v2
draft upsert, partial-failure recovery. Correctly edits the `DI_`
draft-content ID rather than the `PVTI_` project item ID. It never calls
Zenodo or creates/publishes a GitHub release.
- JSON Schema + Nickel + DEED attestation contracts; official CFF 1.2.0
validation; operator/author/recovery docs and context help; isolated and
full-app tests; browser/linker tests; bounded-memory benchmark and
strict >10% comparison tool.

### Verification actually executed

- Frontend `bun run check`: **599 pass, 5 existing TODO, 0 fail**, 3,368
assertions, typecheck and seven benchmark checksums.
- New linker/schema/CFF/performance-comparator tests: **15 pass, 0
fail**, 121 assertions; all GitHub interactions mocked.
- Chromium browser adapter: **4 pass, 0 fail**, using a synthetic local
API and an adapter-only HTML fixture derived from the Julia source
template. This is **not** Julia rendering or end-to-end backend
evidence. CI requires actual Julia-emitted HTML.
- Tree-sitter: **124 Julia sources, 0 syntax findings** — parsing only,
not Julia runtime/typechecking.
- Shell/source hygiene, TypeScript lint/typecheck, SPDX, whitespace,
YAML parse and staged blob checks passed. Shellcheck is not installed.

### Blocking acceptance work

The latest push run
[36209226931](https://github.com/hyperpolymath/MetaManifold-WebUI/actions/runs/36209226931),
like
[36207063201](https://github.com/hyperpolymath/MetaManifold-WebUI/actions/runs/36207063201),
was rejected **before any jobs started**:

> Actor is not allowed to trigger Actions workflows. Workflow file:
'.github/workflows/doi.yml'.

No Julia test has run here: there is no local Julia runtime and runtime
download attempts failed. Nickel binary download also failed. These are
not application test failures, and the gates have not been weakened to
hide them.

- [ ] An authorized actor resolves the Actions policy or runs the
documented lanes on a provisioned machine.
- [ ] Run isolated Julia lifecycle/real-HTTP streaming, actual-output
JSON/CFF/Nickel/projection/browser checks, and full-app/Oxygen tests.
- [ ] Confirm root and isolated manifests with Pkg. Versions are
retained; project hashes/dependency closure were reconstructed from the
pinned Pkg algorithm, **not** produced by a successful
instantiate/resolve here.
- [ ] Establish a reviewed, same-host DOI benchmark baseline and run the
>10% time/allocation gate. The comparator is tested; **there are no
actual DOI timing/allocation measurements yet**. Until a baseline
exists, CI emits a warning and only retains the informational report.
- [ ] Perform an operator-approved live sandbox acceptance check before
enabling production, including current licence/metadata normalization
compatibility and explicit sandbox publish confirmation.

**No real Zenodo upload/publication, DOI mint, GitHub release edit or
project-item write was performed.** Publication remains disabled by
default. No issue is being closed by this PR.

## Documentation

- `docs/doi-publication.md` — setup, privacy/authentication boundary,
author flow, state recovery, GitHub linker and API contract.
- `docs/testing/doi-publication.md` — exact commands, coverage map,
performance policy, evidence limits and production checklist.

The new DOI CI lane needs no credentials, R packages, biological
databases or live deposits. The existing full scientific CI retains the
integration tests.
… proofs (#20) (#75)

Implements #20 (ILR bases: phylogenetic/PhILR, sequential binary
partition, balance dendrogram) with an Agda proof layer shared with the
#21 zero-handling work.

## What changes
- **Engine** — `src/analysis/ilr_basis.jl`: every basis is a rooted
binary tree; balances are clade sums in one post-order pass (`O(D)` per
sample, no dense basis matrix). Pure Julia, no new dependency
(philr/compositions/robCompositions are not in `renv.lock`).
- **Validation (refuse, don't repair)** — tree rooted + bifurcating +
covering the retained taxa (extra tips pruned and recorded); SBP must be
the SBP of a binary tree (Egozcue & Pawlowsky-Glahn 2005) over exactly
the retained taxa; dendrogram method ∈ ward/complete/average; ILR fields
only with ILR normalization.
- **Contracts** — identical rules in the Julia validator, Nickel, JSON
Schema, DEED and the frontend (`ilrInputProblems`). Configs without the
new fields hash exactly as before; the default Helmert balances are
byte-identical.
- **Provenance/guards** — tree/SBP SHA-256, dendrogram method, weights,
balance-id rule; >3 distinct SBPs ⇒ DANGER. BH stays mandatory.
- **Proofs** — `proofs/agda/` (new `proofs` CI job): contrast sums,
orthonormality, injectivity (with its positive-weight hypothesis),
scale/perturbation invariance, comb = Helmert, SBP validity. Mapped to
tests in `docs/formal/verification-plan.md`.
- **Evidence** — known answers; an independent Julia reference
(`test/fixtures/ilr/ilr_reference.jl`) recomputes all 17 committed
expectations (philr ×9, `compositions::ilr`, R `hclust`
variation/merges/balances) every run; R cross-checks where the packages
exist; negative controls.
- **Benchmarks** — `bench/ilr_bases/benchmark.jl` (100/1 000/10 000
taxa, warns >5 min / >1 GiB, informational) and a **PR-only gate**
(`bench/ilr_bases/regression_gate.jl`) that measures base vs head on the
same runner, interleaved A B A B, and fails on >10 % more allocation or
>10 % slower minimum time for CLR and default ILR. Why not a committed
baseline: cross-host timings are noise (the repo's existing policy);
allocations are deterministic, and same-runner A/B cancels runner drift.
- **Frontend** — Advanced Analysis controls (`IlrBasisInputs.tsx`).
- **Language policy** — the Python fixture generator is removed; the
Julia reference replaces it (`docs/compliance/standards-alignment.md`).

## Please note
- ⚠️ **Julia was not executed while writing this** (no Julia toolchain
reachable in the authoring sandbox). Julia files were syntax-checked and
run through a port of `config/ci/lint_source.jl`; Agda proofs type-check
locally; frontend: 613 tests pass. CI is the first execution of the
Julia tests, the reference and the benchmarks.
- ⚠️ **CI `startup_failure`**: `ci.yml` has failed to start on every
branch since ~2026-09-25 22:19, before this PR. Needs a look from
someone with admin access (Actions settings / allowed actions / org
policy).
- **Finding, not changed**: the default Helmert loop in
`Execution.prepare_analysis_table` is `O(D²)` time and transient
allocation per sample (fresh `log_col[1:i]` slice per balance; ~400 MB
per sample at 10 000 taxa). Kept byte-identical here; the comb tree
reproduces it in `O(D)` and could replace it separately.
- **Pre-existing, out of scope**: the JSON Schema correction `allOf`
`if` lacks `required`; `bun run typecheck` fails with TS5090; a
CladeCumulus JSX error; remaining Python (`test_exact_summaries` shells
to `python3` fractions; `install.jl` pipx cutadapt/multiqc) is awaiting
an owner decision.

Closes #20 once CI is green.

---------

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…67 archive (#76)

## Summary

Triages the notification backlog (see
`docs/triage/2026-09-26-notification-backlog.md`). Docs + tooling only;
no application-logic changes.

**Already done alongside (not in this diff):**
- Closed fork #73 as a wrong-base duplicate of parent #7 (same branch,
clean upstream).
- Owner merged fork #75 mid-triage → fork #20 auto-closed. Post-merge
verification still owed once CI runs.
- Deleted stale branch `arena/01a0db67` at owner's request after
archiving it here.

## Changes

- `docs/triage/2026-09-26-notification-backlog.md` — every open PR/issue
on fork + parent triaged; CI outage diagnosed (file-based workflows
`startup_failure` repo-wide since 2026-09-25 22:19 UTC;
settings/platform-side, owner steps in runbook).
- `docs/triage/pr7-split/` — parent #7's 319-file change as 14 disjoint
stacks (`STACKS.md` review guide, `RUNBOOK.md` with merge-as-is vs
stacked-PRs options, `make-stacks.sh` regenerates + verifies: disjoint,
full coverage, sequential apply reproduces the branch tree exactly).
- `docs/triage/db67-rescue/` — archived deleted branch as a verified
byte-exact patch + restore instructions.
- `.gitignore` — track `docs/triage/`, ignore derived 4.5 MB stack
patches.

## Verification

- `scripts/check-spdx.sh`: OK (new .md/.sh carry fork-series headers).
- Format essentials (LF, final newline, no trailing WS in non-prose):
clean.
- `make-stacks.sh`: 14 stacks, disjoint, cover all 319 files, reproduce
branch tree exactly.
- `db67-rescue/deleted-branch.patch`: recreates the deleted branch tree
exactly.

## Note on CI

File-based workflows cannot start repo-wide right now (the outage
diagnosed in the report), so expect `startup_failure` — unrelated to
this docs-only change. Re-run once the owner fixes Actions.

---------

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
…ource wiki, and elaborate autolinks (#77)

docs: replace README with estate README.adoc + EXPLAINME.adoc pair, source wiki, and elaborate autolinks (#77)
…rs (#7) (#78)

## Summary

First slice of #7 (Full Evidence Mode): the **formal foundations**. What
a residual, an evidence-refined candidate set, a warrant token and a
presence verdict *are* — proved, executable inside Agda, and pinned
across implementations.

The reference explorer's own footer admits its signed JavaScript model
has **no proved extraction correspondence** with any proof. This PR
closes exactly that gap:

- **L0 — abstract semantics** (`Evidence.Residual`, `Echo`, `Warrant`):
`Candidate observe r E = Σ W ((observe w ≡ r) × E w)`; `Holds`
quantifies over *all* candidates, not the case's chosen witness;
`actual-world-sound` is the honesty boundary (a warranted claim about
candidates says nothing about reality until the actual world is shown
admissible); `Echo`/`AvecFibre` fibre semantics with the total-space
factorisation (the licence for storing rows as `(observed, witnesses)`
pairs); `Warrant`/`Epi`/`SoundWarrant` with `epi-does-not-give` — a
warrant token is not truth, proved by countermodel.
- **L1 — signed finite model** (`Evidence.Signed`): `signed-integer-v1`
as ℕ offsets, so every predicate is decidable and the model runs *inside
Agda*; enumeration proved sound (`listed ⇒ satisfies`) and complete
(`satisfies ∧ b ≤ 6 ⇒ listed`).
- **L2 — decision procedures** (`Evidence.Decision`): the exact
computation the server routes and the residual explorer run, proved to
decide the candidate semantics: `entailed` ⇒ Present holds; `refuted` ⇒
Absent holds; `unresolved` ⇒ neither (explicit witnesses both ways);
`inconsistent` ⇒ **no inhabited case** — an empty candidate set does
*not* make claims vacuously true. The five reference presets land as
computed, proved terms (e.g. `present-without-identification`: presence
without a value).
- **L3 — the pin**: 546 golden vectors
(`proofs/vectors/evidence_vectors.json`, regenerate with
`scripts/gen_evidence_vectors.py`) covering all four verdicts and both
identification outcomes, for Julia and bun test stacks to consume so
Agda/Julia/TS are bound to one truth.

Negative control: `reject/IdentificationWithoutUniqueness.agda` —
reporting an identified value from a mere presence verdict (the UI bug
Evidence Mode exists to prevent) must fail to type-check, and does.

## Changes

- `proofs/agda/MetaManifold/Evidence/` — six new stdlib-free modules
(only `Agda.Builtin.*`, so they check under any Agda ≥ 2.6.4.3)
- `proofs/agda/MetaManifold/All.agda`, `proofs/agda/README.md` — suite
integration
- `proofs/agda/reject/IdentificationWithoutUniqueness.agda` — new
negative control
- `scripts/gen_evidence_vectors.py` +
`proofs/vectors/evidence_vectors.json` — the golden-vector pin
- `docs/formal/evidence-verification.md` — layering, verdict theorems,
theorem-to-test map, and what is deliberately *not* proved

## Verification

- All six modules type-check clean (exit 0, no errors) under Agda
2.7.0.1, `--safe --without-K`.
- `check-proofs.sh` guard logic replicated locally on all 17 modules: no
postulates/holes/escape flags; pragma present.
- Reject control fails with the error its `-- EXPECT:` line states.
- `scripts/check-spdx.sh`: OK (327 files).
- Vectors regenerate byte-identically (546 cases).
- The full `All.agda` suite check runs in CI under the estate pin (Agda
2.6.4.3 + stdlib 2.1); the Evidence half is stdlib-free by construction,
so toolchain drift cannot affect it.

## Scope note

The UI layer of #7 (avec_fibre editor, fibre visualizer, residual
explorer, warrant editor, provenance logging, DANGER banner) follows in
later stacks on top of these foundations. Refs #7.

## Note on CI

File-based workflows have been failing repo-wide with `startup_failure`
since 2026-09-25 (diagnosed in #76 as settings/platform-side). If checks
show that, it is unrelated to this change.

---------

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Pilot ruling of 2026-09-26 (owner): this repository is the pilot for migrating
the estate's YAML to KYAML, the strict YAML subset of KEP-5295. Authority is
hyperpolymath/standards 3-practice/YAML-POLICY.adoc rules Y-2 and Y-3.

- scripts/kyaml/KYAML.jl: the switch. --to-kyaml, --to-yaml, --check and
  --report; comments keep their association; canonical-form checking makes the
  gate idempotent by construction; a refusal names the file and line and writes
  nothing, so a tree is never half-converted.
- config/kyaml/drift.txt: the two workflow files Dependabot and gh actions-lock
  rewrite. Converted, not gated, accepted in writing (policy §5 step 6).
- Justfile: use-kyaml, use-yaml, check-kyaml (wired into hygiene and ci),
  kyaml-report, and prove-agda, which fails loudly when no Agda is on PATH.
- docs/pilots/kyaml-pilot.md: the operating manual — the ruling, what the switch
  guarantees, what it refuses by name, the decisions it takes and prints, the
  proof-obligation table, how to revert, and what is deliberately out of scope.
- test/unit/test_kyaml.jl: comment association, idempotence, YAML round trip,
  block scalars, the forced decisions, six refusals, a dropped-comment mutant
  that must turn the gate red, and every tracked YAML file parsed and re-emitted.
- EXPLAINME.adoc: the language ruling (Julia for everything we can; the dada2
  pipeline stays as it is; the TypeScript view is a plan, not a task) and the
  KYAML pilot pointer.
- proofs/agda/README.md: how to run the proofs, what each proves, what is
  deliberately not proved, and what would falsify them. *.agdai ignored.

Not in this commit: the conversion itself (next), the shell extraction out of
ci.yml into scripts/ci/*.sh, the CI step for check-kyaml, and the Agda CI job.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…ort (issue #21)

Zero handling, implemented rather than aliased, and proved where it can be proved.

Operators (src/analysis/zero_replacement.jl):
- multiplicative replacement (Martin-Fernandez et al. 2003), the operator of
  zCompositions::multRepl: zeros get delta x per-part detection limit, observed
  parts scale by 1 - Delta, and the sample total and the ratios among observed
  parts are preserved exactly.
- Bayesian multiplicative replacement (Martin-Fernandez et al. 2015), the GBM of
  cmultRepl: posterior mean of a Dirichlet-multinomial with the leave-one-out
  prior mean and concentration 1/gmean(t) unless alpha is supplied, with the
  reference's frac x colmins cap and its adjust switch.
- Both refuse by name what they cannot do, record per-sample diagnostics, and
  carry the provenance sentence the issue asks for: all replacement is biased.

Dispersion (src/analysis/dispersion.jl):
- pure-Julia port of glmGamPoi (Ahlmann-Eltze & Huber 2020): Cox-Reid adjusted
  NB maximum likelihood with the reference's 0.99 factor and its early returns,
  the dnorm-weighted local-median trend, the quasi-likelihood conversion, and
  the inverse-chisquare prior by Nelder-Mead.
- The reference's natural-spline abundance trend is NOT ported: true is refused,
  null is refused at or above 100 features, false runs the reference's own
  non-trended prior and records the deviation. No silent substitution.
- estimation.jl: the by-name refusal becomes the real two-pass path (mean sweep
  in R, dispersions in Julia, refit at fixed dispersion; theta = 1/alpha, with
  stats::glm(poisson()) where alpha is 0).

Configuration and surface: normalization.bayesian_multiplicative_alpha and
advanced.{zero_replacement_method, multiplicative_delta, bayesian_alpha,
glmgampoi_abundance_trend} in the Julia model, the Nickel contract, the JSON
schema and the frontend types; delta in (0,1) and alpha > 0 validated at the
door; warnings below 0.01 and at or above 0.9; a DEED echo of every value; the
DANGER banner when three or more deltas have been tried. The Advanced expander
gains the delta slider with a replacement preview, the alpha field and the trend
selector.

Proofs (proofs/agda/, Agda 2.7.0.1 + stdlib 2.1.1, --safe, no postulates):
totals and ratios preserved, imputed values positive and below their detection
limit; no data-determined rule can be faithful (the fibre behind "every
replacement is biased"); the shrinkage lies between the prior and the sample
estimate. proofs/agda/README.md states what is not proved and what would
falsify each file.

Tests and benchmarks:
- test/unit/test_zero_replacement.jl and test_dispersion.jl against
  test/fixtures/issue21/golden.json, with direct comparisons against
  zCompositions and glmGamPoi wherever R has them and an explicit "this
  comparison did not run" where it does not;
- bench/zero_replacement/benchmark.jl at 100/1000/10000 taxa with the issue's
  5-minute warning and the 10% regression report behind METAMANIFOLD_BENCH_STRICT
  (the repository's later decision made the other Julia benches informational;
  the reasoning and the switch are recorded in the file header).

KYAML pilot follow-ups in the same change: the KYAML tool now preserves comments
that sit above the document root instead of dropping them (every file here
starts with an SPDX header, so a silent drop would have deleted licence
headers); guix.scm gains the agda + agda-stdlib lane; stapeln.toml and
Containerfile define the standalone toolchain deployment (owner ruling:
standalone, not local-only); the review bench lane is added to the existing
Julia benchmark step. The three new Agda modules are flat, standalone-checked
files: folding them into the existing MetaManifold/ suite (module namespace, the
suite OPTIONS header, All.agda, a guard run) is the follow-up, and doing it
blind would have risked a passing lane.

Docs: docs/statistics/zero-handling.md,
docs/statistics/method-conditions/dispersion-glmGamPoi.md, CHANGELOG, ROADMAP.

Not in this commit: the KYAML conversion itself (one command, where Julia is),
the shell extraction from ci.yml into scripts/ci/*.sh, and the first CI run of
any of it - the sandbox has no Julia or R, so every number here is unexecuted
locally and the first CI run is the debugger.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…#79)

## What this is

A proof gate for the validated statistics layer, as asked for on #1 and
in the
follow-up direction to validate the system with Agda (Lean fallback not
needed).

Seven Agda modules, **77 top-level definitions**, type-checked by Agda
2.7.0.1
against agda-stdlib 3.0 under `--safe --without-K`. No postulates, no
foreign
code, no proof-irrelevance escape hatch.

Additive only: no existing source file's behaviour changes. The diff is
new files
plus appended `Justfile` recipes, one `.gitignore` entry, and a new
workflow.

## Verified locally

| Check | Result |
| --- | --- |
| `agda --safe --without-K MetaManifold/All.agda` (clean `_build`) |
**exit 0, empty output** — no warnings |
| `proofs/bootstrap.sh` (the repo's own entry point) | **exit 0** →
`proofs: OK` |
| `proofs/tests/axiom-audit.sh` | `7/7 modules reachable`, `clean`, exit
0 |
| `proofs/tests/gate-selftest.sh` | `10/10 controls behaved correctly`,
exit 0 |

**Not yet verified:** `.github/workflows/proofs.yml` has not executed on
a GitHub
runner. The first run of this PR's checks is its first real test. If it
goes red
it will be the bootstrap step (PyPI wheel + stdlib clone + primitive
libraries),
not the proofs.

## What is proved, and why it is not a test

- **Prelude** — `Outcome A = value A ⊎ refused Refusal`, with
`outcome-total`
saying there is no third arm. A refactor that forgets a refusal case
does not
type-check. `whole-is-one` needs **no `n ≢ 0` hypothesis**, because
`ℚᵘ`'s
denominator is `suc _` — a zero denominator is unrepresentable by type.
That is
the exact sense in which the refusals are total, and the reason Agda was
used.
- **Proportions** — `relativeAbundance` refuses in the order the Julia
layer
  checks; proportions sum to exactly `1ℚᵘ`; a returned value *is* `c/t`.
- **ExactCounts** — `checkedAdd` is exact **in both directions**: a
returned value
is the true sum, and a refusal happens exactly when the sum leaves the
range.
Proving one direction alone would be worthless, because each alone is
satisfied
by an implementation that is useless. Plus `checkedSumOf-is-exact`, the
fold
  version a table's total rests on.
- **PermutationTest** — `never-reports-zero` holds for *every* `b` and
`B`, so
`p = 0` is unprintable by construction rather than by convention. The
negative
control is proved alongside it: `naive-estimator-can-report-zero` shows
the
  estimator this replaces really does return exactly zero.
- **BenjaminiHochberg** — the scaling is exactly `(M/(j+1))·(n/(d+1))`,
and a
bigger family can never make a q-value smaller (a correction that went
the
  other way would reward running more tests, silently).
- **DecimalRounding** — "correctly rounded to *s* decimals" as a
predicate over
integers alone, no division inside the specification of rounding. Each
printed
decimal is a type-checked instance; `0.67` for `2/3` is not a number
somebody
  typed into two places. Tie handling is stated in **both** directions
(`IsRounding` halves go down, `IsRoundHalfUp` up) and they are proved to
agree
  everywhere else.

## A finding, not an assumption

`relativeAbundance (suc c) 0` refuses as **`countExceedsTotal`**, not
`zeroTotal` — `exact_relative_abundance` checks `count <= total` before
`iszero(total)`. Both orders are defensible; only one is implemented. A
test
written from the docstring would have asserted the other.

## The gate cannot pass vacuously

`proofs/tests/gate-selftest.sh` breaks the proofs nine ways on purpose
(wrong
known-answer digit, reversed monotonicity, plus-one removed, zero total
silently
zero, overflow no longer refused, module dropped from the gate entry,
postulate
injected, `--safe` removed, tie forced the wrong way) and requires each
to be
rejected. On its first run it reported **1/10** — because `bash -c
"$mutator"
"$file"` binds the path to `$0`, so no mutation applied. The control
reported
"mutation did not apply" rather than passing. That is the point of
having it.

## Not proved

`proofs/residue/` carries every open obligation with an id, a precise
statement,
and what would close it — including `Checked.refused` injectivity, BH
non-negativity, the step-down `min` envelope, and explicitly: **no
probability
theory, no IEEE-754 semantics, no proof that `numeric_policy.jl`
implements the
model, nothing about the `:ordinary` path.** `q_i ≥ p_i` is false in
general and
is deliberately absent.

The Agda-to-Julia bridge is `test/fixtures/agda-known-answers.json`:
Agda-checked vectors, each annotated with the lemma that fixes it, for
the Julia
conformance testset to reproduce. If the two disagree, the Julia layer
is wrong.

## Docs

- `proofs/PROOF-STATUS.md` — full inventory, per-module results, open
obligations
- `docs/statistics/formal-verification.md` — reviewer-facing: what
"validated
  with a proof assistant" does and does not mean here

Refs #1. Does not unblock #2 or #4, which stay gated on the full
validation of
#1 and owner approval.

---------

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-ai-coding-agent[bot] <arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Co-authored-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
#81)

## Summary

This PR unifies the full formal-verification Agda proof suite, resolves
module and audit collisions across the estate, and imports the
memory/numerics audit and run-notices catalogue.

### Changes Included

1. **Unify Agda Formal Verification Suite ()**:
- Imports and type-checks all 22 modules across the codebase in a single
gate entry:
- **Numeric Core (Issue #1)**: `Prelude`, `Proportions`, `ExactCounts`,
`PermutationTest`, `BenjaminiHochberg`, `DecimalRounding`
- **Composition (Issue #21)**: `Composition.Tree`, `Composition.Node`,
`Composition.Sum`
- **ILR Bases (Issue #20)**: `ILR.SBP`, `ILR.Contrast`, `ILR.Kernel`,
`ILR.Invariance`, `ILR.Orthonormal`, `ILR.Comb`, `ILR.Integer`
- **Evidence Mode (Issue #7)**: `Evidence.Prelude`, `Evidence.Residual`,
`Evidence.Echo`, `Evidence.Warrant`, `Evidence.Signed`,
`Evidence.Decision`
- Uses non-polluting namespace imports to avoid symbol collisions (e.g.
`Sign`).

2. **Gate Machinery & Self-Test Harmonization**:
- `proofs/tests/axiom-audit.sh`: Audits all 23 modules under
`MetaManifold/`, verifying `--safe`, zero postulates, no FFI/holes, and
100% reachability from `MetaManifold.All`.
- `proofs/tests/gate-selftest.sh`: Verified 10/10 mutation and control
checks reject deliberate breakages and accept the pristine tree.

3. **Memory, Numerics, and Backend Audit**:
- Adds `docs/audit/2026-09-26-memory-numerics-warning-audit.md`
(21-finding read-and-trace audit).
- Adds `docs/notices/README.md` and `docs/notices/catalogue.md` (60-item
run-notice taxonomy and contracts).
   - Updates `.gitignore` to track `docs/notices/`.

4. **Hygiene & Governance**:
- SPDX licence headers added across all new documentation
(`docs/statistics/formal-verification.md`, `proofs/HANDOFF.md`,
`proofs/PROOF-STATUS.md`).
   - Clean formatting (`scripts/check-format.sh` -> OK on 502 files).

### Verification

| Check | Result |
|---|---|
| `proofs/bootstrap.sh` | **OK** (all 23 modules checked cleanly) |
| `proofs/tests/axiom-audit.sh` | **OK** (23/23 reachable, clean) |
| `proofs/tests/gate-selftest.sh` | **10/10 controls pass** |
| `scripts/check-spdx.sh` | **OK** (381 files covered) |
| `scripts/check-format.sh` | **OK** (502 files checked) |
…-slice kit (#82)

## Summary

Establishes the strategic, technical, and operational roadmap for
transitioning contributions from the `hyperpolymath/MetaManifold-WebUI`
fork back to upstream maintainer **Joshua Jewell**
(`JoshuaJewell/MetaManifold-WebUI`), directly addressing his feedback on
upstream PR #13.

### What this PR adds

1. **Maintainer Handoff Ultraplan**
(`docs/migration/ULTRAPLAN-MAINTAINER-HANDOFF.md`):
- **Retraction of PR #13**: Diagnosis of the 159 merge conflicts (merge
base reverted to January root commit `06d85ba` after git-filter-repo
dead-asset cleanup) and exact closure command + drafted comment for
Joshua.
- **Maintainer Profile**: Ground rules respecting veterinary science
workflows, microbiome amplicon analysis priorities, and team bandwidth.
- **8-Track Taxonomy**: Clear classification across Pipeline Fixes,
Biological QC, Benchmarks, Statistics Cluster, Test Organization, React
UI, Architectural Hard Calls, and Formal Evidence.
- **'Free' vs 'Hard Decision' Trade-Off Matrix**: High-clarity breakdown
showing what is safe/additive vs what requires architectural choice
(YAML vs KYAML, Estate CI vs simple CI, React vs Stipple, exact math vs
canonical R pipeline).
- **R-Pipeline Protection & Dual-Track CI/CD**: Guarantees that
canonical biological tools (`dada2`, `vegan`, `MASS::glm.nb`) remain the
primary blocking ground truth.
- **Phased PR Sequencing**: Atomic clean-branch roadmap re-anchored on
`ecefb1c` (upstream `main`) with zero conflicts and zero Stipple/Vue
dependencies.

2. **Automated Upstream Slicing Kit**
(`scripts/prepare-upstream-slices.sh`):
   - Fetches `upstream/main` (`ecefb1c`).
- Generates four atomic, conflict-free branches directly from `ecefb1c`
in temporary worktrees:
- `upstream-slice/01-qc-and-fixes` (FastQC/MultiQC in CI + 1x1 matrix &
zero-depth fixes, 6 files)
     - `upstream-slice/02-benchmarks` (`bench/` suites, 16 files)
- `upstream-slice/03-statistics-cluster` (real models, exact offsets,
test renames, 16 files)
- `upstream-slice/04-frontend-polish` (accessible dialogs, TS types, 13
files)
   - Excludes `ui/` and all Genie/Stipple dependencies completely.
   - Verifies zero merge conflicts against upstream `main`.

### Hygiene & Conformance

- `scripts/check-spdx.sh`: OK (361 files covered).
- `scripts/check-format.sh`: OK (465 files checked).

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@hyperpolymath

Copy link
Copy Markdown
Contributor Author

@copilot please fix the merge conflicts in this pull request.

1 similar comment
@hyperpolymath

Copy link
Copy Markdown
Contributor Author

@copilot please fix the merge conflicts in this pull request.

@JoshuaJewell

Copy link
Copy Markdown
Owner

Closed as older duplicate of #13.

@hyperpolymath
hyperpolymath deleted the arena/01a0df2a-metamanifold-webui branch September 28, 2026 20:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants