These packages are imported by code under src/ and ship in the browser bundle, but were
listed as devDependencies, which made Dependabot label their alerts "development" scope.
No version changes; the lockfile diff only flips dev flags. Shipped code is unchanged: the
only bundle difference is the package.json text that vite's `define: { __pkg__ }` inlines
into three chunks, and the content-hash file names that follow from it.
@sveltejs/kit stays a devDependency on purpose: its client runtime ships, but its advisories
are server-side and moving it would drag vite and its plugins out of dev scope too.
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
* chore(frontend): upgrade quill to 2.0.3
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* fix(apps): load rich text editor HTML through Quill's converter so stored lists survive Quill 2
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* fix(apps): emit standard ul/ol from the rich text editor output under Quill 2
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* fix(apps): keep checklist state when normalising the rich text editor output
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
* fix(frontend): keep nested template literals intact in template inputs
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: fail a flow step with an unresolvable $args tag instead of hanging
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): surface input expression errors when running a step test
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): treat an escaped \${ as literal text when escaping backticks
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: accept the string "null" as a tag component, reject only JSON null
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: leave a same_worker step's inert tag alone, log an unresolved flow tag
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): escape every backtick when the template walk desynchronizes
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: leave a dedicated runnable's inert step tag alone
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: reroute a step only when its own tag is what failed to resolve
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* refactor: name the inert-tag guard step_is_pulled_by_tag
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: reject a tag only when it interpolates to nothing at all
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): validate the template walk instead of trusting a balanced stack
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* docs: describe what an unresolvable tag actually interpolates to
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* refactor(frontend): decide template escaping with a real parser, not a hand-rolled scan
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* refactor: name is_flow_step on push now that it is load-bearing
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): heal an expression escaped before nested templates were handled
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: reroute a step whose tag reads args that failed to evaluate
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: never hand a job that failed before running to a dedicated runner
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: reroute only a step whose args failed, leave other tags untouched
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: drop the post-preprocessor tag fallback, leaving tag resolution untouched
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* refactor: leave interpolate_args exactly as it was
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* test: use a generic example in the template literal tests
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): show an expression escaped by the old rule as it was authored
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): surface input expression errors from every step-run entry point
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* docs: state what is_dedicated_worker actually reads
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): heal only text whose backticks were all escaped by the old rule
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): match the old rule textually so an authored backslash still heals
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(frontend): heal only expressions the old rule broke, never ones that parse
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
* fix(parser-py): keep first param when def main( line has trailing comment
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* chore: bump windmill-parser-wasm-py to 1.782.0
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>