Skip to content

Bump esbuild and vite in /ki-hypothesen-test - #20

Closed
dependabot[bot] wants to merge 20 commits into
Matrixfrom
dependabot/npm_and_yarn/ki-hypothesen-test/multi-64d6452dd2
Closed

dependabot[bot] wants to merge 20 commits into
Matrixfrom
dependabot/npm_and_yarn/ki-hypothesen-test/multi-64d6452dd2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 5, 2026 •

Copy link
Copy Markdown

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Removes esbuild. It's no longer used after updating ancestor dependency vite. These dependencies need to be updated together.

Removes esbuild

Updates vite from 5.4.21 to 8.2.2

Release notes

Sourced from vite's releases.

plugin-legacy@8.2.2

Please refer to CHANGELOG.md for details.

v8.2.2

Please refer to CHANGELOG.md for details.

plugin-legacy@8.2.1

Please refer to CHANGELOG.md for details.

v8.2.1

Please refer to CHANGELOG.md for details.

create-vite@8.2.0

Please refer to CHANGELOG.md for details.

plugin-legacy@8.2.0

Please refer to CHANGELOG.md for details.

v8.2.0

Please refer to CHANGELOG.md for details.

v8.2.0-beta.0

Please refer to CHANGELOG.md for details.

v8.1.5

Please refer to CHANGELOG.md for details.

v8.1.4

Please refer to CHANGELOG.md for details.

v8.1.3

Please refer to CHANGELOG.md for details.

v8.1.2

Please refer to CHANGELOG.md for details.

v8.1.1

Please refer to CHANGELOG.md for details.

create-vite@8.1.0

Please refer to CHANGELOG.md for details.

plugin-legacy@8.1.0

Please refer to CHANGELOG.md for details.

v8.1.0

Please refer to CHANGELOG.md for details.

plugin-legacy@8.1.0-beta.0

Please refer to CHANGELOG.md for details.

... (truncated)

Changelog

Sourced from vite's changelog.

8.2.2 (2026-08-20)

Features

  • deps: widen @vitejs/devtools peer range to v0.5.0 (#23302) (495d9ff)

Bug Fixes

  • bundled-dev: handle lazy request error (#23291) (3ba026d)
  • bundled-dev: hot update through circular imports instead of reloading (#23259) (3dbddef)
  • config: resolve sourcemap paths against sourcemap location (#23239) (05a003e)
  • css: don't pass empty targets to lightningcss (#23295) (2804636)
  • define: fix match escaped dots to support $-prefixed define keys (#23249) (dcf88bd)
  • deps: update all non-major dependencies (#23217) (ba958bd)
  • deps: update rolldown-related dependencies (#23218) (83ecb2c)
  • module-runner: exclude completed modules from in-flight cycle detection (fix #22999) (#23009) (d9b10a9)
  • optimizer: close custom extension analysis bundles (#23207) (8fb7675)
  • reduce Windows 8.3-short-name detection false-positives (#23066) (02cffa9)
  • respect resolve.preserveSymlinks when resolving root (fix #23197) (#23198) (8413052)
  • ssr: rewrite computed key of destructing parameter (#23307) (9db0b61)
  • vite: update outdated upstream file links in license comments (#23285) (c0f2fc6)

Documentation

Miscellaneous Chores

Code Refactoring

  • use JSON import attributes instead of readFileSync in constants (#23258) (1d9fa39)
  • use named regex constants over inline literals (#22964) (5c1c6c6)

Tests

  • define: close rolldown bundler after generate (#23231) (b4d66fe)
  • module-runner: add TLA circular import case (#23299) (4a261f2)
  • module-runner: simplify server-hmr tests (#23300) (599b44b)
  • ssr: add destructing assignment case for moduleRunnerTransform (#23308) (cb77e2a)

Build System

  • use JSON import attributes instead of readFIleSync in rolldown configs (#23251) (d615bcd)

8.2.1 (2026-08-06)

Bug Fixes

  • build: make client chunkImportMap work with sharedPlugins: true (#23184) (15f0307)
  • bundled-dev: inject client script tag before chunk scripts (#23161) (eac0cc8)

... (truncated)

Commits
  • de1111a release: v8.2.2
  • cb77e2a test(ssr): add destructing assignment case for moduleRunnerTransform (#23308)
  • 9db0b61 fix(ssr): rewrite computed key of destructing parameter (#23307)
  • 8413052 fix: respect resolve.preserveSymlinks when resolving root (fix #23197) (#23...
  • 05a003e fix(config): resolve sourcemap paths against sourcemap location (#23239)
  • 495d9ff feat(deps): widen @vitejs/devtools peer range to v0.5.0 (#23302)
  • 1d9fa39 refactor: use JSON import attributes instead of readFileSync in constants (#2...
  • 2804636 fix(css): don't pass empty targets to lightningcss (#23295)
  • 599b44b test(module-runner): simplify server-hmr tests (#23300)
  • 4a261f2 test(module-runner): add TLA circular import case (#23299)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

MarcelRaschke and others added 20 commits June 29, 2026 03:48
- Add SECURITY.md with vulnerability reporting guidelines
- Add CodeQL workflow for C++ static analysis
- Add clang-tidy workflow for code quality checks
- Add cppcheck workflow for additional static analysis
- Add Dependabot configuration for dependency scanning
- Update README.md with security information and links

Closes #security-policy

Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
- Add SBOM generation workflow with Syft (SPDX and CycloneDX)
- Add Fuzzing workflow with AFL++ for kissfft library
- Add Trivy vulnerability scanning workflow

These workflows complement the existing CodeQL, clang-tidy, and cppcheck
workflows for comprehensive security coverage.

Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
- Add CONTRIBUTING.md with security guidelines, coding standards, and contribution rules
- Add ISSUE_TEMPLATE for bug reports, feature requests, and security vulnerabilities
- Add PULL_REQUEST_TEMPLATE.md for standardized PR descriptions
- Add CODEOWNERS for repository ownership
- Add labeler.yml for automatic issue/PR labeling
- Optimize clang-tidy workflow with path filtering and CMake integration
- Optimize cppcheck workflow with path filtering and artifact upload
- Optimize fuzzing workflow with configurable time and manual dispatch
- Add build.yml for Linux/Windows build testing
- Add ci.yml for comprehensive CI pipeline

Closes #contributing-guidelines

Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
- Add CODE_OF_CONDUCT.md based on Contributor Covenant
- Add OWASP ZAP workflow for dynamic security analysis
- Optimize all workflows with actions/cache for:
  - clang-tidy (CMake build cache)
  - cppcheck (cppcheck cache)
  - build.yml (CMake dependencies cache)
  - ci.yml (all tool caches)
  - fuzzing.yml (AFL++ corpus cache)
- Adjust fuzzing duration to 600s (10 minutes) default
- Add parallel fuzzing support with configurable cores
- Add input validation for Fuzzing workflow
- Add cache for Trivy and Syft in CI pipeline

Closes #owasp-zap Closes #workflow-optimization

Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
- Add Snyk workflow for vulnerability scanning (requires SNYK_TOKEN secret)
- Add SonarQube workflow for code quality analysis (requires SONAR_TOKEN)
- Add sonar-project.properties for SonarQube configuration
- Add kodi-addon-checks.yml for Kodi-specific validations:
  - Addon XML validation
  - Kodi API compatibility checks
  - Visualization-specific requirements
  - Thread safety checks
  - Performance considerations
- Add DEPENDENCY_POLICY.md with:
  - Approved dependencies list
  - Dependency update process
  - Security requirements
  - License compatibility matrix
  - Maintenance schedule

These additions provide comprehensive security and quality analysis
for the visualization.matrix addon, tailored specifically for Kodi addons.

Closes #snyk Closes #sonarqube Closes #kodi-checks Closes #dependency-policy

Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
- Add Semgrep workflow for custom security rules with .semgrep.yml
  - Rules for memory safety (malloc, strcpy, sprintf)
  - Kodi-specific rules (deprecated APIs, required methods)
  - FFT-specific rules (input validation, power-of-two checks)
  - Modern C++ best practices (const references, nullptr, auto)
- Add CHANGELOG.md following Keep a Changelog format
- Add changelog.yml workflow for automatic CHANGELOG generation
  - Triggered on push to master/Matrix/Nexus
  - Triggered on tag pushes (v*)
  - Manual dispatch with version input
  - Dry-run mode for testing
- Add Dockerfile for consistent build environments
  - Multi-stage build (builder + runtime)
  - Installs all build dependencies (CMake, g++, Mesa, clang-tidy, cppcheck)
  - Clones Kodi source for addon building
  - Supports multi-arch builds (amd64, arm64, arm/v7)
- Add docker.yml workflow for Docker builds and security scanning
  - Builds Docker image with Buildx
  - Supports multi-platform builds
  - Scans images with Trivy
  - Pushes to GitHub Container Registry

Closes #semgrep Closes #changelog Closes #docker-builds

Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
Add comprehensive security, CI/CD, Docker, and changelog framework
- Clamp m_albumX and m_albumY to [-1.0, 1.0] to prevent album art from
  extending beyond the screen edges in the Album preset.
- Fix redundant m_AlbumNeedsUpload assignment (set to false after upload).
- Resolves FIXME comment in RenderTo() for proper framing.

Closes #N/A

Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
- Add new 'Neon' preset (labelId 30108) to g_presets list.
- Create neon.frag.glsl shader with:
  - Pulsing neon grid background
  - Audio-reactive brightness and glow effects
  - Cyan/magenta color scheme
- Uses only audio channel (no textures required).

Closes #N/A

Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
…e108b

Fix album art framing to stay within screen bounds
…hos² themes

- New GLSL shader (odysseus.frag.glsl) combining:
  - Dynamic matrix grid with falling symbols (⛵ Odysseus, ✈ Hermes, ➕ Helvetia, π)
  - π-based noise and patterns
  - Odysseus' spiral path
  - Hermes' winged shapes
  - Helvetia's Swiss cross
  - Mythos² recursive matrix layers
  - Audio reactivity for all elements
- Added preset to main.cpp (ID 30109)
- Added localized string for Odysseus preset

Closes #751c4c

Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
* feat: Major optimizations and modernizations

- Modernized CMake build system (3.20+, FetchContent for kissfft)
- Consolidated CI/CD workflows into single main.yml
- Improved code quality with std::vector and modern C++ practices
- Optimized Docker multi-stage build with .dockerignore
- Added clang-format configuration and workflow
- Added cache management workflow
- Removed obsolete Find*.cmake files
- Fixed memory management (automatic cleanup with vectors)
- Fixed potential bug in m_AlbumNeedsUpload logic
- Improved type safety with constexpr and static_cast

Closes #optimization-request

Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>

* chore: remove trailing whitespace from merged shaders

Co-authored-by: MarcelRaschke <42359664+MarcelRaschke@users.noreply.github.com>

---------

Co-authored-by: Vibe Nuage Agent <vibe@mistral.ai>
Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
…nce (#6)

- Fix FIXME 1: Clamp album position to prevent overflow over screen edges
- Fix FIXME 2: Reset m_AlbumNeedsUpload after upload (only for album shader)
- Add Google Test framework and unit tests for BlackmanWindow, LinearToDecibels, SmoothingOverTime
- Add SHADERS.md with comprehensive documentation of all shaders, uniforms, and constants
- Optimize performance: Only set m_AlbumNeedsUpload for album shader (channel[3] == 2)

Closes #N/A

Co-authored-by: Vibe Nuage Agent <vibe@mistral.ai>
Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Add an independent React + Vite + TypeScript SPA in the
ki-hypothesen-test/ subfolder (unrelated to the C++ Kodi addon).

Components:
- Sidebar: collapsible, searchable topics sidebar (categories + topics)
- LessonsTab: knowledge base with category cards, popular & recent lessons
- TopicModal: accessible modal for topic details + related lessons

Data/types/hooks:
- types/hypothesis.ts: Hypothesis type incl.  field + status enums
- types/topics.ts: Category / Topic / Lesson types
- data/topics.json: static categories, topics, lessons
- hooks/useTopics.ts: custom hook with derived popular/recent views

App.tsx wires tabs (Hypotheses / Knowledge Base), sidebar, modal,
hypothesis form with topic dropdown, and filterable hypothesis table.

Uses  for all type-only imports (verbatimModuleSyntax).
Build verified: tsc -b + vite build pass.

Co-authored-by: Vibe Nuage Agent <vibe@mistral.ai>
Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
…ake (#11)

- CMake: activate the BUILD_TESTING path (was a no-op) via add_subdirectory(tests)
  so ctest actually runs the existing GoogleTest suite.
- CMake: make ENABLE_COVERAGE use directory-scoped add_compile/add_link_options
  (--coverage -O0 -g) ordered before the test subdirectory so the test target
  inherits coverage flags too; guard against non-GCC/Clang toolchains.
- CMake: replace the brittle clang-tidy target-property stub with proper
  CMAKE_CXX_CLANG_TIDY / CMAKE_CXX_CPPCHECK wiring that finds the tools and
  gracefully skips when absent (ENABLE_CLANG_TIDY / ENABLE_CPPCHECK).
- CMake: add optional ENABLE_TRACY / TRACY_ON_DEMAND options that define
  TRACY_ENABLE/TRACY_ON_DEMAND and add the tracy include dir when the headers
  are present, and no-op otherwise.
- tests/CMakeLists.txt: convert from a standalone project() to a proper
  subdirectory; fetch GoogleTest via FetchContent (no system GTest dependency)
  and register the test with add_test.
- src/tracyprofiler.h: dependency-free instrumentation shim that pulls in Tracy
  zones when TRACY_ENABLE is defined and the headers exist, else expands to
  no-ops, so sources can be instrumented unconditionally.
- .github/workflows/code-coverage.yml: new gcov/lcov CI workflow that builds
  with BUILD_TESTING+ENABLE_COVERAGE, runs ctest, captures/filters lcov, and
  uploads an HTML coverage report.

Co-authored-by: Vibe Nuage Agent <vibe@mistral.ai>
Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
…sistence (#16)

* feat: expand topics, customize Tailwind styling, add localStorage persistence

- Add 3 new categories (Modellarchitekturen, Datenverarbeitung, Zukunft & Forschung)
- Add 12 new topics with 28 lessons (total: 6 categories, 22 topics, 36 lessons)
- Customize Tailwind with primary/secondary color palettes, Inter font, animations
- Add useLocalStorage hook for hypothesis persistence across sessions
- Add delete functionality with confirmation
- Update all components to use custom Tailwind classes

Closes #14

Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>

* docs: add built KI Hypothesen Test app to docs/ki-hypothesen-test/

Static build of the React/Vite app for GitHub Pages deployment.
Serves at: https://MarcelRaschke.github.io/visualization.matrix/ki-hypothesen-test/

Closes #14

Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>

---------

Co-authored-by: Vibe Nuage Agent <vibe@mistral.ai>
Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
- Define 5 phases with clear milestones (2025-2026)
- Include prioritization matrix and success metrics (KPIs)
- Add Gantt chart for visual timeline
- Document risks, dependencies, and resource requirements
- Link to existing project documentation

Closes #roadmap (if applicable)

Co-authored-by: Vibe Nuage Agent <vibe@mistral.ai>
Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
Co-authored-by: Vibe Nuage Agent <vibe@mistral.ai>
Co-authored-by: MarcelRaschke <MarcelRaschke@users.noreply.github.com>
Removes [esbuild](https://github.com/evanw/esbuild). It's no longer used after updating ancestor dependency [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). These dependencies need to be updated together.


Removes `esbuild`

Updates `vite` from 5.4.21 to 8.2.2
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.2.2/packages/vite)

---
updated-dependencies:
- dependency-name: esbuild
  dependency-version:
  dependency-type: indirect
- dependency-name: vite
  dependency-version: 8.2.2
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 5, 2026
@dependabot
dependabot Bot requested a review from MarcelRaschke as a code owner September 5, 2026 18:03
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 5, 2026
@MarcelRaschke

Copy link
Copy Markdown
Owner

@copilot, behebe bitte die Mergekonflikte in diesem Pull Request.

@MarcelRaschke
MarcelRaschke changed the base branch from master to Matrix September 11, 2026 21:13
@dependabot @github

dependabot Bot commented on behalf of github Sep 11, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/ki-hypothesen-test/multi-64d6452dd2 branch September 11, 2026 21:14
@github-project-automation github-project-automation Bot moved this from In progress to Done in proto Sep 11, 2026
@github-project-automation github-project-automation Bot moved this from In progress to Reviewer approved in proto Sep 11, 2026
@github-project-automation github-project-automation Bot moved this to In progress in proto Sep 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

Status: Done
Status: Reviewer approved

Development

Successfully merging this pull request may close these issues.

3 participants