Skip to content

chore(deps): bump mermaid from 11.15.0 to 11.16.1 - #3484

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/mermaid-11.16.1
Open

chore(deps): bump mermaid from 11.15.0 to 11.16.1#3484
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/mermaid-11.16.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 8, 2026

Copy link
Copy Markdown
Contributor

Bumps mermaid from 11.15.0 to 11.16.1.

Release notes

Sourced from mermaid's releases.

mermaid@11.16.1

Patch Changes

  • #8022 12d472c Thanks @​aloisklink! - fix: handle CSS sibling combinators in compileCSS

  • #8022 2cd6dcf Thanks @​aloisklink! - fix: increase protections against prototype pollution

    User-controlled input already has protections against prototype pollution.

    Fixes: GHSA-c4c3-pg64-4m4v

  • #8022 99af3fc Thanks @​aloisklink! - fix(architecture): use Maps and Sets to store groups/services

    Services are now rendered in the order they are defined and more service IDs are now supported.

  • #8022 2cd6dcf Thanks @​aloisklink! - deprecate: Deprecate the mermaidAPI.setConfig() function

    Calling this function has no observable effect, as the next time a render() or parse() is called, the currentConfig is cleared.

  • #8022 630aa7e Thanks @​aloisklink! - fix(xychart): support zero-width x-axis ranges

  • #8022 59b22fa Thanks @​aloisklink! - fix(radar): limit number of ticks to 32

    Setting a ticks value higher than this would only show 32 ticks.

mermaid@11.16.0

Minor Changes

  • #7535 ea1c48f Thanks @​ragelink! - feat(cynefin): Adds the Cynefin framework as a new diagram type (beta) to Mermaid (available as cynefin-beta). The Cynefin framework, created by Dave Snowden, is a decision-making framework that categorizes problems into five complexity domains, widely used in agile, incident management, strategy, and organizational design.

  • #7721 f45cc2c Thanks @​notionparallax! - feat(treeView): add box-drawing character input support for treeView diagrams

  • #7550 f1f4d45 Thanks @​DominicBurkart! - feat(xychart): add per-point text labels for xychart line plots

  • #7527 b4d0442 Thanks @​notionparallax! - feat(treeView): Extends the existing treeView-beta diagram with features useful for representing file/directory structures.

  • #7793 a6f097d Thanks @​SSDWGG! - feat(er): support optional ER attribute types with a ? suffix

  • #7772 37f2e36 Thanks @​devareddy05! - feat(gantt): support multiple excludes / includes lines so long exclusion lists can be split into commented groups (#6270)

  • #7708 4e63e9d Thanks @​txmxthy! - feat(architecture): add align row|column {ids…} directive to architecture-beta diagrams so authors can declare horizontal or vertical alignment of services explicitly.

  • #7760 05223be Thanks @​ngdaniels! - feat(pie): Enhance Pie Chart - Enable donut chart, Set legend position, and highlight slice

  • #7251 216e4e9 Thanks @​ydah! - feat(railroad): Add support for Railroad Diagrams (Syntax Diagrams) with four input syntaxes: IR (railroad-beta), EBNF (railroad-ebnf-beta), ABNF (railroad-abnf-beta), and PEG (railroad-peg-beta).

  • #7774 e5c75e6 Thanks @​ngdaniels! - feat(xychart): enable rotate label on X-axis

... (truncated)

Commits
  • 7ecca0c Version Packages (#8023)
  • 95b1b9c docs: change mermaidAPI.setConfig() changeset (#8024)
  • acc69f1 Merge pull request #8022 from mermaid-js/release/11.16.1
  • eba7287 docs: point changesets to correct commit hashes
  • 12d472c Merge commit from fork
  • 2cd6dcf Merge commit from fork
  • 630aa7e Merge commit from fork
  • 59b22fa Merge commit from fork
  • 99af3fc Merge commit from fork
  • 2337f7e Merge branch 'test/improve-example.html' into release/11.16.1
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note

Low Risk
Lockfile-only semver patch/minor bump for a client-side diagram library; main residual risk is rare rendering or parsing regressions in existing Mermaid blocks, offset by included security fixes.

Overview
Dependency-only update: mermaid is raised from ^11.15.0 to ^11.16.1 in package.json, with the corresponding pnpm-lock.yaml refresh (including transitive updates such as @mermaid-js/parser, cytoscape, dompurify, and optional AWS SDK entries tied to the lockfile graph).

There are no application source changes—diagrams still load through the existing client Mermaid component and dynamic import("mermaid").

The upgrade pulls in 11.16.1 security and bug fixes (notably stronger prototype-pollution protections for user-controlled diagram input, plus CSS/architecture/xychart/radar fixes) and 11.16.0 diagram features that docs can use without code changes (new beta diagram types, treeView/architecture/gantt/ER/pie enhancements).

Reviewed by Cursor Bugbot for commit 0bf619c. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps [mermaid](https://github.com/mermaid-js/mermaid) from 11.15.0 to 11.16.1.
- [Release notes](https://github.com/mermaid-js/mermaid/releases)
- [Commits](https://github.com/mermaid-js/mermaid/compare/mermaid@11.15.0...mermaid@11.16.1)

---
updated-dependencies:
- dependency-name: mermaid
  dependency-version: 11.16.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 8, 2026
@vercel

vercel Bot commented Aug 8, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
langfuse-docs Ready Ready Preview Aug 8, 2026 5:02am

Request Review

@dosubot dosubot Bot added the size:XS This PR changes 0-9 lines, ignoring generated files. label Aug 8, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0bf619c. Configure here.

Comment thread package.json
"marked": "^16.3.0",
"mdast-util-mdx-jsx": "^3.2.0",
"mermaid": "^11.15.0",
"mermaid": "^11.16.1",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Subgraph direction edges may break

Medium Severity

Bumping mermaid to 11.16.1 pulls in the 11.16.0 Dagre change that breaks edges into subgraphs that declare an inner direction. The incident-report flowchart uses that pattern (direction TB inside region subgraphs, with edges from Cloudflare into those ALBs), so those cross-subgraph links can fail to render. The 11.16.1 notes cover security and other patches, not that flowchart regression.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 0bf619c. Configure here.

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — straightforward dependency bump.

What was reviewed: confirmed the diff is limited to package.json/pnpm-lock.yaml with no application source changes; checked that the mermaid component still uses the same dynamic import("mermaid") API surface unaffected by this bump; verified the lockfile's transitive updates (dompurify, cytoscape, AWS SDK) are consistent version bumps, not manual edits.

Extended reasoning...

Overview

This PR is a Dependabot-generated dependency bump of mermaid from 11.15.0 to 11.16.1 (a patch/minor semver-compatible upgrade). Only package.json (one version string) and pnpm-lock.yaml (regenerated lockfile) are touched. No application code, components, or docs content are modified.

Security risks

None introduced by this PR. The mermaid 11.16.1 release notes actually include a security fix (increased protections against prototype pollution, GHSA-c4c3-pg64-4m4v), making this bump a net positive from a security standpoint. The lockfile also picks up a dompurify bump (3.3.3 -> 3.4.13 as a new resolved version alongside the existing one) which is a legitimate transitive dependency of the newer mermaid/iconify chain, not a manual or suspicious edit.

Level of scrutiny

Low scrutiny is appropriate here: this is a lockfile-only, semver-compatible dependency bump for a client-side diagramming library with no first-party code changes. The change is mechanical and fully generated by Dependabot tooling.

Other factors

A bug-hunting pass already ran and found no issues, and additionally investigated whether the mermaid bump causes duplicate dompurify copies via lockfile dedup — ruled out as not a real problem (multiple resolved versions in a pnpm lockfile is normal and expected, not a bug). No outstanding review comments exist on this PR, and there's no prior review from me to reconcile against.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code size:XS This PR changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants