Skip to content

feat: web: bump @protolabsai/design ^0.11.0 + @protolabsai/ui ^0.66.1; tokenNameGuard accepts _ token names (protoContent#525/#547 step 3, card 1 foundation) - #3888

Merged
mabry1985 merged 1 commit into
mainfrom
feat/bd-7cux-web-bump-protolabsai-design-0-11-0-proto
Sep 29, 2026
Merged

mabry1985 merged 1 commit into
mainfrom
feat/bd-7cux-web-bump-protolabsai-design-0-11-0-proto

Conversation

@mabry1985

Copy link
Copy Markdown
Member

Summary

Bumps @protolabsai/design from ^0.10.1 to ^0.11.0 and @protolabsai/ui from ^0.63.0 to ^0.66.1 in apps/web/package.json, regenerates the root package-lock.json, and widens the token-name guard's DECL/VAR_REF/NESTED_HEAD character classes from [a-z0-9-] to [a-z0-9_-] so the new underscore-keyed space tokens (--pl-space-0_5, --pl-space-1_5, --pl-space-2_5) are captured whole rather than truncated at the _. The new radius scale (--pl-radius-md/-lg/-xl/-pill) and spacing half-steps are added to the spot-check and a meta assertion confirms whole-name capture for var(--pl-space-0_5). Two generated files were also refreshed to keep existing gates green: THIRD_PARTY_LICENSES.md (attribution, which the prior candidate forgot) and tests/data/ds-plugin-kit-tokens.txt (DS plugin-kit token snapshot, which gained 11 new entries from the bump).

Refs protoLabsAI/protoContent#525
Refs protoLabsAI/protoContent#547

…; tokenNameGuard accepts `_` token names (protoContent#525/#547 step 3, card 1 foundation)
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 24 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 503f92ca-961e-44fb-bedd-aaa2875501c8

📥 Commits

Reviewing files that changed from the base of the PR and between eedcfc1 and 442178d.

⛔ Files ignored due to path filters (2)
  • THIRD_PARTY_LICENSES.md is excluded by !*.md
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (4)
  • apps/web/package.json
  • apps/web/src/app/tokenNameGuard.test.ts
  • changelog.d/3887.changed.md
  • tests/data/ds-plugin-kit-tokens.txt

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@protoreview protoreview Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

QA panel review — WARN

code-review-structural · head 442178d4ea5c · formal

Low-risk dependency bump with a targeted regex widening; the real risk is the Python test file left behind. Fix first: update _VAR_REF and _TOKEN_DEF in tests/test_plugin_view_ds_tokens.py to include underscore in the character class, and remove --pl-radius-md from KNOWN_MISSPELLINGS — both are confirmed by the verifier against the snapshot and changelog. The panel was unanimous; no disagreements. Verification confirmed both majors and marked the protopatch minor as uncertain (pre-existing CI orchestration gap, not introduced by this PR). Coverage gap: no finder examined the plugin-kit.css snapshot for completeness against the full token set.

Findings

Severity Location Finding Verified
🟠 major tests/test_plugin_view_ds_tokens.py:53 The Python test's _VAR_REF and _TOKEN_DEF regexes use [a-z0-9-] which does not match underscore, so they will truncate names like --pl-space-0_5 to --pl-space-… confirmed
🟠 major tests/test_plugin_view_ds_tokens.py:44 KNOWN_MISSPELLINGS maps --pl-radius-md to --pl-radius, but --pl-radius-md is now a real token in @protolabsai/design@0.11.0 (confirmed by the snapshot file whi… confirmed
🟡 minor apps/web/package.json:10 Declared project typecheck/test commands run only Python tooling and skip the TypeScript app's tsc and Vitest checks ⚠️ uncertain
findings JSON (machine-readable)
[
  {
    "file": "tests/test_plugin_view_ds_tokens.py",
    "line": 53,
    "severity": "major",
    "category": "cross-file",
    "claim": "The Python test's _VAR_REF and _TOKEN_DEF regexes use [a-z0-9-] which does not match underscore, so they will truncate names like --pl-space-0_5 to --pl-space-0; the equivalent TypeScript regexes in tokenNameGuard.test.ts were widened to [a-z0-9_-] in this PR but the Python test was not updated, causing test_the_token_snapshot_matches_the_real_kit to fail and test_every_referenced_token_is_defined to produce false positives.",
    "evidence": "_VAR_REF = re.compile(r\"var\\(\\s*(--pl-[a-z0-9-]+)\")\n_TOKEN_DEF = re.compile(r\"^\\s*(--pl-[a-z0-9-]+)\\s*:\", re.M)",
    "verdict": "confirmed",
    "note": "Regexes verbatim in file at head; diff shows TS DECL/VAR_REF/NESTED_HEAD widened to [a-z0-9_-]; snapshot at head has no underscore tokens; changelog confirms --pl-space-0_5/-1_5/-2_5 added in 0.11.0."
  },
  {
    "file": "tests/test_plugin_view_ds_tokens.py",
    "line": 44,
    "severity": "major",
    "category": "cross-file",
    "claim": "KNOWN_MISSPELLINGS maps --pl-radius-md to --pl-radius, but --pl-radius-md is now a real token in @protolabsai/design@0.11.0 (confirmed by the snapshot file which includes it and by the changelog); any plugin view using var(--pl-radius-md) will be flagged as a misspelling by test_no_known_misspelled_ds_tokens.",
    "evidence": "\"--pl-radius-md\": \"--pl-radius\",",
    "verdict": "confirmed",
    "note": "Entry verbatim in KNOWN_MISSPELLINGS at head; snapshot file contains --pl-radius-md; TS test spot-checks it in defined set; changelog confirms radius scale added in 0.11.0."
  },
  {
    "file": "apps/web/package.json",
    "line": 10,
    "severity": "minor",
    "category": "build-release",
    "claim": "Declared project typecheck/test commands run only Python tooling and skip the TypeScript app's tsc and Vitest checks",
    "evidence": "The detected project commands are `uv run ruff check .` / `uv run ruff format --check .` / `uv run pytest`, all Python-only. The TypeScript app's only tsc invocation lives in the `build` script (package.json line 10) and its tests run via `vitest run` (line 14). A CI or developer relying on the detected commands will not type-check or run tests for the owned .ts files, so type errors or regression Fix: Extend the root typecheck/lint/test orchestration to also run `npm --prefix apps/web run build` (or a dedicated tsc typecheck) and `npm --prefix apps/web run test`, or update the detected commands to (protopatch confidence: high)",
    "source": "protopatch",
    "verdict": "uncertain",
    "note": "package.json confirms tsc in build and vitest in test, but the 'detected project commands' claim references CI orchestration config not visible in this PR diff; pre-existing condition, not a defect introduced by this dependency bump."
  }
]

2 finding(s) excluded from the verdict by in-diff confinement (file not among this PR's changed paths):

  • tests/test_plugin_view_ds_tokens.py (major) — The Python test's _VAR_REF and _TOKEN_DEF regexes use [a-z0-9-] which does not match underscore, so they will truncate names like --pl-space-0_5 to --pl-space-0
  • tests/test_plugin_view_ds_tokens.py (major) — KNOWN_MISSPELLINGS maps --pl-radius-md to --pl-radius, but --pl-radius-md is now a real token in @protolabsai/design@0.11.0 (confirmed by the snapshot file whic

@protoreview protoreview Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Promoting the WARN verdict for head 442178d4ea5c: all checks terminal-green, zero unresolved review threads. (approve-on-green)

Open findings carried by this approval — non-blocking, but they did not go away:

  • major tests/test_plugin_view_ds_tokens.py:53 — The Python test's _VAR_REF and _TOKEN_DEF regexes use [a-z0-9-] which does not match underscore, so they will truncate names like --pl-space-0_5 to --pl-space-0; the equivalent TypeScript regexes in t
  • major tests/test_plugin_view_ds_tokens.py:44 — KNOWN_MISSPELLINGS maps --pl-radius-md to --pl-radius, but --pl-radius-md is now a real token in @protolabsai/design@0.11.0 (confirmed by the snapshot file which includes it and by the changelog); any
  • minor apps/web/package.json:10 — Declared project typecheck/test commands run only Python tooling and skip the TypeScript app's tsc and Vitest checks

Approving a WARN does not resolve its findings (issue #22).

@mabry1985
mabry1985 merged commit 2a241a5 into main Sep 29, 2026
36 of 38 checks passed
@mabry1985
mabry1985 deleted the feat/bd-7cux-web-bump-protolabsai-design-0-11-0-proto branch September 29, 2026 20:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant