A concise grammar of interactive graphics, built on Vega.
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
ci: run format, schema, and examples checks on fork PRs (#9877) Avoids getting PRs with incorrect formatting or outdated examples etc. | 1 个月前 | |
chore: add husky pre-commit hook with lint-staged (#9763) # Motivation This PR adds pre-commit hooks to catch formatting issues locally before CI, reduce wasted CI minutes, and ensure consistent code style across the codebase (related to vega/vega#4237). # Changes - Adds `husky@^9.1.7` for git hooks management - Adds `lint-staged@^16.2.7` to run linters only on staged files - Configures pre-commit hook to run `npx lint-staged` - Adds `"prepare": "husky"` script to auto-initialize hooks on `npm install` - Configures lint-staged to run `eslint --fix` on `*.{js,ts,mjs,cjs}` files - Updates `.gitignore` to exclude `.claude/` directory # Testing - [x] Run `npm install` to verify the prepare script initializes husky - [x] Make a change to a JS/TS file with a formatting issue - [x] Stage and commit the change - [x] Verify the pre-commit hook runs and auto-fixes the formatting issue - [x] Verify CI passes Co-authored-by: Claude Sonnet 4.5 (1M context) <noreply@anthropic.com> | 3 个月前 | |
chore: update contributing docs for testing (#9546) | 1 年前 | |
feat!: update to vega 6 (#9572) Update to Vega 6. --------- Co-authored-by: GitHub Actions Bot <vega-actions-bot@users.noreply.github.com> | 1 年前 | |
chore(deps): bump vega to 6.4.0 (#9925) Bumps `vega` (peer) and `vega-cli` (dev) to 6.4.0, with the lockfile regenerated. **Snapshots.** All 202 `test-runtime/snapshots/**/*.svg` are regenerated. The cause is vega/vega#4302, which is already in 6.3.0 — not the 6.4.0 bump itself: - 197 files: only `stroke-miterlimit` `10` → `4`. - 5 files (`interval/{translate,zoom}/bound/repeat_*.svg`): also a 1px layout shift (width `392` → `391`, legend `translate(320,0)` → `translate(319,0)`, and in `repeat_2` row offsets `356`/`712` → `355`/`710`). That is the other half of #4302 — stroke bounds now expand by half the stroke width with join-aware slack instead of the full width, so computed group bounds are slightly tighter. Reproduced against 6.3.0; 6.2.0 renders `392`. CI's own automation regenerated `examples/compiled/**` on top of this for the same reason — same two deltas, no `.vg.json` changed. **Schema.** `build/vega-lite-schema.json` picks up the `container:resize` stream from vega-typings 2.3.0. **Heads up for page-level baselines:** 6.4.0 sets `vertical-align: bottom` on canvas and SVG DOM roots, removing the baseline-descender gap. Intrinsic chart dimensions are unchanged, but occupied container height shrinks a few px. --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: GitHub Actions Bot <vega-actions-bot@users.noreply.github.com> | 17 天前 | |
chore(deps): bump vega to 6.4.0 (#9925) Bumps `vega` (peer) and `vega-cli` (dev) to 6.4.0, with the lockfile regenerated. **Snapshots.** All 202 `test-runtime/snapshots/**/*.svg` are regenerated. The cause is vega/vega#4302, which is already in 6.3.0 — not the 6.4.0 bump itself: - 197 files: only `stroke-miterlimit` `10` → `4`. - 5 files (`interval/{translate,zoom}/bound/repeat_*.svg`): also a 1px layout shift (width `392` → `391`, legend `translate(320,0)` → `translate(319,0)`, and in `repeat_2` row offsets `356`/`712` → `355`/`710`). That is the other half of #4302 — stroke bounds now expand by half the stroke width with join-aware slack instead of the full width, so computed group bounds are slightly tighter. Reproduced against 6.3.0; 6.2.0 renders `392`. CI's own automation regenerated `examples/compiled/**` on top of this for the same reason — same two deltas, no `.vg.json` changed. **Schema.** `build/vega-lite-schema.json` picks up the `container:resize` stream from vega-typings 2.3.0. **Heads up for page-level baselines:** 6.4.0 sets `vertical-align: bottom` on canvas and SVG DOM roots, removing the baseline-descender gap. Intrinsic chart dimensions are unchanged, but occupied container height shrinks a few px. --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: GitHub Actions Bot <vega-actions-bot@users.noreply.github.com> | 17 天前 | |
ci: run format, schema, and examples checks on fork PRs (#9877) Avoids getting PRs with incorrect formatting or outdated examples etc. | 1 个月前 | |
fix: Make ranged marks compatible with offset channels (#9823) In short, this PR changes ranged marks in offset channels so that they compile as true ranged marks with consistent baseline, grouping, and axis alignment. There are still some things to fix with the examples but it would be helpful with high level comments on the overall approach even before then. (Note that all the screenshot are including https://github.com/vega/vega-lite/pull/9817, otherwise they would be upside down) ### Details Currently, ranged marks are not working well in offset channels. For example, a bar mark simply places a rectangle of fixed size at the location of the offset. I think that the desired behavior should mimic how bars work across other quantitative channel, ie start from a baseline and extent to the data value, which is what I have tried to implement here: | Before this PR | After this PR | |-|-| | <img width="132" height="99" alt="image" src="https://github.com/user-attachments/assets/931fc2fe-eaac-4299-a9d4-7634c3277960" /> | <img width="132" height="99" alt="image" src="https://github.com/user-attachments/assets/4e164c4b-95cb-4569-8306-611a59670bab" /> | [Open the Chart in the Vega Editor](https://vega.github.io/editor/#/url/vega-lite/N4IgJghgLhIFygG4QDYFcCmBneBtUscIAgiADQgBG8ATABwUDG8IAHueCwLYgC+ZBFgCEO1OAFZxTFuwphufASEIgAwqPgAWAMzSiszkQB2iwUQAiGuAE4AjHrYd5x08pakKYugxDMiATycFfjMQEU94SQdAuWClFXUIuB1ooJcQtwsrKN8WGMMQE14AXX4QLggAJwBreFAofwAHDBZKKsUQDCNGAHswAEsjAHM6xwQQADN+jBRnNzL-AHkJiawMKFGpmbnqCgbmlgBHNAgjKH6Yc8QWhc3p2ZZmXmegA) Similarly, area marks display unusual behavior currently and don't show up at all. With the changes in this PR, they will show similar to how the line mark from #9819 display: | Before this PR | After this PR | Line in #9819 | |-|-|-| | <img width="132" height="99" alt="image" src="https://github.com/user-attachments/assets/00872695-fb90-4f8f-8a7b-1d08f31c52ea" /> | <img width="132" height="99" alt="image" src="https://github.com/user-attachments/assets/46df4888-f487-47b4-aa3c-6e3e1f425026" /> | <img width="132" height="99" alt="image" src="https://github.com/user-attachments/assets/22e834b9-0b3c-4f5e-957f-dd496767ca94" /> | [Open the Chart in the Vega Editor](https://vega.github.io/editor/#/url/vega-lite/N4IgJghgLhIFygG4QDYFcCmBneBtUscIAgiADQgBG8ATABwUDG8IAHueCwLYgC+ZBFgCEO1OAFZxTFuwphufASEIgAwqPgAWAMzSiszkQB2iwUQAiGuAE4AjHrYd5x08pakKYugxDMiATycFfjMQEU94SQdAuWClFXUIuB1ooJcQtwsrKN8WGMMQE14AXX4QLggAJwBreFAofwAHDBYqjFgyjCNGAHswAEsjAHM6xwQQADN+jBRnNzL-AHkJiawMKFGpmbnqCgbmlgBHNAgjKH6Yc8QWhc3p2ZZmXmegA) I also chose to align axis/tick/label behavior with the new baseline semantics, anchoring them at the bottom of the bar/area, because I thought it looked odd when they were in the middle of the band: <img width="132" height="99" alt="image" src="https://github.com/user-attachments/assets/09c013e5-f372-483e-b015-1a69fc18efc2" /> I think that a case could be made for including a grid line by default as a baseline, but I was unsure if this was too automagical, so I left it out in this implementation. It is quite helpful, particularly when the marks have different range, but maybe it should be added manually for consistency: |Without gridline| With gridline | |-|-| | <img width="132" height="99" alt="image" src="https://github.com/user-attachments/assets/533c90c6-e9e4-4929-8f4a-b58b6834f15f" /> | <img width="132" height="99" alt="image" src="https://github.com/user-attachments/assets/4449c14f-5d54-4d2d-8978-98d77f4baef2" /> | <details> <summary><h2>Checklist</h2></summary> - [x] This PR is atomic (i.e., it fixes one issue at a time). - [x] The title is a concise [semantic commit message](https://www.conventionalcommits.org/) (e.g. "fix: correctly handle undefined properties"). - [x] `npm test` runs successfully - For new features: - [x] Has unit tests. - [x] Has documentation under `site/docs/` + examples. Tips: - https://medium.com/@greenberg/writing-pull-requests-your-coworkers-might-enjoy-reading-9d0307e93da3 is a nice article about writing a nice PR. - Use draft PR for work in progress PRs / when you want early feedback (https://github.blog/2019-02-14-introducing-draft-pull-requests/). </details> --------- Co-authored-by: GitHub Actions Bot <vega-actions-bot@users.noreply.github.com> Co-authored-by: Dominik Moritz <domoritz@gmail.com> | 1 个月前 | |
fix: support escaped fields in point selections (#9904) ## PR Description ### Summary Use `flatAccessWithDatum` when extracting point-selection values. - Escaped fields (ex. `"field": "y\\[foo\\]"`) now access `datum["y[foo]"]`. - This change applies to point-selection and bound input selections. - Existing point-selection behavior remains unchanged for fields without escaped chars. - Added regression testing for point tuples and nearest bound selections. ### Motivation Point selections manually generated datum access with `stringValue`, which quoted escaped field paths without interpreting them: ```js datum["y\\[foo\\]"] ``` Other Vega-Lite compiler paths use shared field-access helpers that correctly generate: ```js datum["y[foo]"] ``` This caused point-selection behavior to differ from rendering, transforms, predicates, and other generated expressions. As a result, point selections did not work as expected for marks using escaped field names. ### History! In 2019, [#5351](https://github.com/vega/vega-lite/pull/5351) changed selection field access to manual bracket lookup to support flattened fields such as `nested.a`. This fixed nested selections but bypassed the shared helper that interprets escaped field names. Escaped bracket support was later added in [#5730](https://github.com/vega/vega-lite/pull/5730), but point selections did not inherit the fix when selection types were consolidated in [#6927](https://github.com/vega/vega-lite/pull/6927). <img alt="2026-07-29-escape-brackets-selection" src="https://github.com/user-attachments/assets/ad6f472c-b3f0-4aa0-8228-c607808c713f" /> | 6 天前 | |
chore(deps): bump vega to 6.4.0 (#9925) Bumps `vega` (peer) and `vega-cli` (dev) to 6.4.0, with the lockfile regenerated. **Snapshots.** All 202 `test-runtime/snapshots/**/*.svg` are regenerated. The cause is vega/vega#4302, which is already in 6.3.0 — not the 6.4.0 bump itself: - 197 files: only `stroke-miterlimit` `10` → `4`. - 5 files (`interval/{translate,zoom}/bound/repeat_*.svg`): also a 1px layout shift (width `392` → `391`, legend `translate(320,0)` → `translate(319,0)`, and in `repeat_2` row offsets `356`/`712` → `355`/`710`). That is the other half of #4302 — stroke bounds now expand by half the stroke width with join-aware slack instead of the full width, so computed group bounds are slightly tighter. Reproduced against 6.3.0; 6.2.0 renders `392`. CI's own automation regenerated `examples/compiled/**` on top of this for the same reason — same two deltas, no `.vg.json` changed. **Schema.** `build/vega-lite-schema.json` picks up the `container:resize` stream from vega-typings 2.3.0. **Heads up for page-level baselines:** 6.4.0 sets `vertical-align: bottom` on canvas and SVG DOM roots, removing the baseline-descender gap. Intrinsic chart dimensions are unchanged, but occupied container height shrinks a few px. --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: GitHub Actions Bot <vega-actions-bot@users.noreply.github.com> | 17 天前 | |
fix: support escaped fields in point selections (#9904) ## PR Description ### Summary Use `flatAccessWithDatum` when extracting point-selection values. - Escaped fields (ex. `"field": "y\\[foo\\]"`) now access `datum["y[foo]"]`. - This change applies to point-selection and bound input selections. - Existing point-selection behavior remains unchanged for fields without escaped chars. - Added regression testing for point tuples and nearest bound selections. ### Motivation Point selections manually generated datum access with `stringValue`, which quoted escaped field paths without interpreting them: ```js datum["y\\[foo\\]"] ``` Other Vega-Lite compiler paths use shared field-access helpers that correctly generate: ```js datum["y[foo]"] ``` This caused point-selection behavior to differ from rendering, transforms, predicates, and other generated expressions. As a result, point selections did not work as expected for marks using escaped field names. ### History! In 2019, [#5351](https://github.com/vega/vega-lite/pull/5351) changed selection field access to manual bracket lookup to support flattened fields such as `nested.a`. This fixed nested selections but bypassed the shared helper that interprets escaped field names. Escaped bracket support was later added in [#5730](https://github.com/vega/vega-lite/pull/5730), but point selections did not inherit the fix when selection types were consolidated in [#6927](https://github.com/vega/vega-lite/pull/6927). <img alt="2026-07-29-escape-brackets-selection" src="https://github.com/user-attachments/assets/ad6f472c-b3f0-4aa0-8228-c607808c713f" /> | 6 天前 | |
chore: add husky pre-commit hook with lint-staged (#9763) # Motivation This PR adds pre-commit hooks to catch formatting issues locally before CI, reduce wasted CI minutes, and ensure consistent code style across the codebase (related to vega/vega#4237). # Changes - Adds `husky@^9.1.7` for git hooks management - Adds `lint-staged@^16.2.7` to run linters only on staged files - Configures pre-commit hook to run `npx lint-staged` - Adds `"prepare": "husky"` script to auto-initialize hooks on `npm install` - Configures lint-staged to run `eslint --fix` on `*.{js,ts,mjs,cjs}` files - Updates `.gitignore` to exclude `.claude/` directory # Testing - [x] Run `npm install` to verify the prepare script initializes husky - [x] Make a change to a JS/TS file with a formatting issue - [x] Stage and commit the change - [x] Verify the pre-commit hook runs and auto-fixes the formatting issue - [x] Verify CI passes Co-authored-by: Claude Sonnet 4.5 (1M context) <noreply@anthropic.com> | 3 个月前 | |
feat!: esm only package (#9527) Part of https://github.com/vega/vega/issues/3990 | 1 年前 | |
chore: fix release script | 1 年前 | |
chore: release v6.4.3 | 4 个月前 | |
docs: Update the instructions for how to build the docs (#9829) Update the contributing notes about how to build the documentation. | 1 个月前 | |
docs: format license text so GitHub recognizes it (#6821) | 5 年前 | |
docs: update links and materials (#9586) | 1 年前 | |
chore(deps): bump the npm_and_yarn group across 1 directory with 2 updates (#9719) Bumps the npm_and_yarn group with 2 updates in the / directory: [glob](https://github.com/isaacs/node-glob) and [js-yaml](https://github.com/nodeca/js-yaml). Updates `glob` from 11.0.3 to 11.1.0 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/isaacs/node-glob/blob/main/changelog.md">glob's changelog</a>.</em></p> <blockquote> <h1>changeglob</h1> <h2>12</h2> <ul> <li>Remove the unsafe <code>--shell</code> option. The <code>--shell</code> option is now ONLY supported on known shells where the behavior can be implemented safely.</li> </ul> <h2>11.1</h2> <p><a href="https://github.com/isaacs/node-glob/security/advisories/GHSA-5j98-mcp5-4vw2">GHSA-5j98-mcp5-4vw2</a></p> <ul> <li>Add the <code>--shell</code> option for the command line, with a warning that this is unsafe. (It will be removed in v12.)</li> <li>Add the <code>--cmd-arg</code>/<code>-g</code> as a way to <em>safely</em> add positional arguments to the command provided to the CLI tool.</li> <li>Detect commands with space or quote characters on known shells, and pass positional arguments to them safely, avoiding <code>shell:true</code> execution.</li> </ul> <h2>11.0</h2> <ul> <li>Drop support for node before v20</li> </ul> <h2>10.4</h2> <ul> <li>Add <code>includeChildMatches: false</code> option</li> <li>Export the <code>Ignore</code> class</li> </ul> <h2>10.3</h2> <ul> <li>Add <code>--default -p</code> flag to provide a default pattern</li> <li>exclude symbolic links to directories when <code>follow</code> and <code>nodir</code> are both set</li> </ul> <h2>10.2</h2> <ul> <li>Add glob cli</li> </ul> <h2>10.1</h2> <ul> <li>Return <code>'.'</code> instead of the empty string <code>''</code> when the current working directory is returned as a match.</li> <li>Add <code>posix: true</code> option to return <code>/</code> delimited paths, even on Windows.</li> </ul> <h2>10.0.0</h2> <ul> <li>No default exports, only named exports</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/isaacs/node-glob/commit/2551fb51440d402fa2120457bf460e546ee9964d"><code>2551fb5</code></a> 11.1.0</li> <li><a href="https://github.com/isaacs/node-glob/commit/47473c046b91c67269df7a66eab782a6c2716146"><code>47473c0</code></a> bin: Do not expose filenames to shell expansion</li> <li><a href="https://github.com/isaacs/node-glob/commit/bc33fe1c6a47abd497703d79ad96036e7891ff62"><code>bc33fe1</code></a> skip tilde test on systems that lack tilde expansion</li> <li><a href="https://github.com/isaacs/node-glob/commit/59bf9ca211bda5636c4fe9e32d41530c90a4f30d"><code>59bf9ca</code></a> fix notes</li> <li><a href="https://github.com/isaacs/node-glob/commit/dde4fa66c87e24b37bb5be28ed10c6e12019edac"><code>dde4fa6</code></a> docs(README): add #anchor and improve <code>note</code>s</li> <li><a href="https://github.com/isaacs/node-glob/commit/0559b0ed13c0f8147cd2ac9d48bb49684caaf20e"><code>0559b0e</code></a> docs: add better links to path-scurry docs</li> <li><a href="https://github.com/isaacs/node-glob/commit/c9773c249b4b9ed6b2447222c226f9d20c6ce916"><code>c9773c2</code></a> fix: correct typos in <code>README.md</code></li> <li><a href="https://github.com/isaacs/node-glob/commit/13e68eadbc4f0aacd9d6ffbcb4b28a34d5d8512c"><code>13e68ea</code></a> Fix punctuation in traversal function documentation</li> <li><a href="https://github.com/isaacs/node-glob/commit/1527e2b8107e95122ab6e9b6f6312f121693d53d"><code>1527e2b</code></a> fix repo url</li> <li><a href="https://github.com/isaacs/node-glob/commit/7e190e8776a7fa66fba40827de5f9effd1c52f9d"><code>7e190e8</code></a> fix typo <code>maths</code> → <code>paths</code></li> <li>Additional commits viewable in <a href="https://github.com/isaacs/node-glob/compare/v11.0.3...v11.1.0">compare view</a></li> </ul> </details> <br /> Updates `js-yaml` from 3.14.1 to 3.14.2 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md">js-yaml's changelog</a>.</em></p> <blockquote> <h2>[3.14.2] - 2025-11-15</h2> <h3>Security</h3> <ul> <li>Backported v4.1.1 fix to v3</li> </ul> <h2>[4.1.1] - 2025-11-12</h2> <h3>Security</h3> <ul> <li>Fix prototype pollution issue in yaml merge (<<) operator.</li> </ul> <h2>[4.1.0] - 2021-04-15</h2> <h3>Added</h3> <ul> <li>Types are now exported as <code>yaml.types.XXX</code>.</li> <li>Every type now has <code>options</code> property with original arguments kept as they were (see <code>yaml.types.int.options</code> as an example).</li> </ul> <h3>Changed</h3> <ul> <li><code>Schema.extend()</code> now keeps old type order in case of conflicts (e.g. Schema.extend([ a, b, c ]).extend([ b, a, d ]) is now ordered as <code>abcd</code> instead of <code>cbad</code>).</li> </ul> <h2>[4.0.0] - 2021-01-03</h2> <h3>Changed</h3> <ul> <li>Check <a href="https://github.com/nodeca/js-yaml/blob/master/migrate_v3_to_v4.md">migration guide</a> to see details for all breaking changes.</li> <li>Breaking: "unsafe" tags <code>!!js/function</code>, <code>!!js/regexp</code>, <code>!!js/undefined</code> are moved to <a href="https://github.com/nodeca/js-yaml-js-types">js-yaml-js-types</a> package.</li> <li>Breaking: removed <code>safe*</code> functions. Use <code>load</code>, <code>loadAll</code>, <code>dump</code> instead which are all now safe by default.</li> <li><code>yaml.DEFAULT_SAFE_SCHEMA</code> and <code>yaml.DEFAULT_FULL_SCHEMA</code> are removed, use <code>yaml.DEFAULT_SCHEMA</code> instead.</li> <li><code>yaml.Schema.create(schema, tags)</code> is removed, use <code>schema.extend(tags)</code> instead.</li> <li><code>!!binary</code> now always mapped to <code>Uint8Array</code> on load.</li> <li>Reduced nesting of <code>/lib</code> folder.</li> <li>Parse numbers according to YAML 1.2 instead of YAML 1.1 (<code>01234</code> is now decimal, <code>0o1234</code> is octal, <code>1:23</code> is parsed as string instead of base60).</li> <li><code>dump()</code> no longer quotes <code>:</code>, <code>[</code>, <code>]</code>, <code>(</code>, <code>)</code> except when necessary, <a href="https://redirect.github.com/nodeca/js-yaml/issues/470">#470</a>, <a href="https://redirect.github.com/nodeca/js-yaml/issues/557">#557</a>.</li> <li>Line and column in exceptions are now formatted as <code>(X:Y)</code> instead of <code>at line X, column Y</code> (also present in compact format), <a href="https://redirect.github.com/nodeca/js-yaml/issues/332">#332</a>.</li> <li>Code snippet created in exceptions now contains multiple lines with line numbers.</li> <li><code>dump()</code> now serializes <code>undefined</code> as <code>null</code> in collections and removes keys with <code>undefined</code> in mappings, <a href="https://redirect.github.com/nodeca/js-yaml/issues/571">#571</a>.</li> <li><code>dump()</code> with <code>skipInvalid=true</code> now serializes invalid items in collections as null.</li> <li>Custom tags starting with <code>!</code> are now dumped as <code>!tag</code> instead of <code>!<!tag></code>, <a href="https://redirect.github.com/nodeca/js-yaml/issues/576">#576</a>.</li> <li>Custom tags starting with <code>tag:yaml.org,2002:</code> are now shorthanded using <code>!!</code>, <a href="https://redirect.github.com/nodeca/js-yaml/issues/258">#258</a>.</li> </ul> <h3>Added</h3> <ul> <li>Added <code>.mjs</code> (es modules) support.</li> <li>Added <code>quotingType</code> and <code>forceQuotes</code> options for dumper to configure string literal style, <a href="https://redirect.github.com/nodeca/js-yaml/issues/290">#290</a>, <a href="https://redirect.github.com/nodeca/js-yaml/issues/529">#529</a>.</li> <li>Added <code>styles: { '!!null': 'empty' }</code> option for dumper (serializes <code>{ foo: null }</code> as "<code>foo: </code>"), <a href="https://redirect.github.com/nodeca/js-yaml/issues/570">#570</a>.</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/nodeca/js-yaml/commit/9963d366dfbde0c69722452bcd40b41e7e4160a0"><code>9963d36</code></a> 3.14.2 released</li> <li><a href="https://github.com/nodeca/js-yaml/commit/10d3c8e70a6888543f5cdb656bb39f73e0ea77c1"><code>10d3c8e</code></a> dist rebuild</li> <li><a href="https://github.com/nodeca/js-yaml/commit/5278870a17454fe8621dbd8c445c412529525266"><code>5278870</code></a> fix prototype pollution in merge (<<) (<a href="https://redirect.github.com/nodeca/js-yaml/issues/731">#731</a>)</li> <li>See full diff in <a href="https://github.com/nodeca/js-yaml/compare/3.14.1...3.14.2">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/vega/vega-lite/network/alerts). </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Dominik Moritz <domoritz@gmail.com> | 9 个月前 | |
chore(deps): bump vega to 6.4.0 (#9925) Bumps `vega` (peer) and `vega-cli` (dev) to 6.4.0, with the lockfile regenerated. **Snapshots.** All 202 `test-runtime/snapshots/**/*.svg` are regenerated. The cause is vega/vega#4302, which is already in 6.3.0 — not the 6.4.0 bump itself: - 197 files: only `stroke-miterlimit` `10` → `4`. - 5 files (`interval/{translate,zoom}/bound/repeat_*.svg`): also a 1px layout shift (width `392` → `391`, legend `translate(320,0)` → `translate(319,0)`, and in `repeat_2` row offsets `356`/`712` → `355`/`710`). That is the other half of #4302 — stroke bounds now expand by half the stroke width with join-aware slack instead of the full width, so computed group bounds are slightly tighter. Reproduced against 6.3.0; 6.2.0 renders `392`. CI's own automation regenerated `examples/compiled/**` on top of this for the same reason — same two deltas, no `.vg.json` changed. **Schema.** `build/vega-lite-schema.json` picks up the `container:resize` stream from vega-typings 2.3.0. **Heads up for page-level baselines:** 6.4.0 sets `vertical-align: bottom` on canvas and SVG DOM roots, removing the baseline-descender gap. Intrinsic chart dimensions are unchanged, but occupied container height shrinks a few px. --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: GitHub Actions Bot <vega-actions-bot@users.noreply.github.com> | 17 天前 | |
chore(deps): bump vega to 6.4.0 (#9925) Bumps `vega` (peer) and `vega-cli` (dev) to 6.4.0, with the lockfile regenerated. **Snapshots.** All 202 `test-runtime/snapshots/**/*.svg` are regenerated. The cause is vega/vega#4302, which is already in 6.3.0 — not the 6.4.0 bump itself: - 197 files: only `stroke-miterlimit` `10` → `4`. - 5 files (`interval/{translate,zoom}/bound/repeat_*.svg`): also a 1px layout shift (width `392` → `391`, legend `translate(320,0)` → `translate(319,0)`, and in `repeat_2` row offsets `356`/`712` → `355`/`710`). That is the other half of #4302 — stroke bounds now expand by half the stroke width with join-aware slack instead of the full width, so computed group bounds are slightly tighter. Reproduced against 6.3.0; 6.2.0 renders `392`. CI's own automation regenerated `examples/compiled/**` on top of this for the same reason — same two deltas, no `.vg.json` changed. **Schema.** `build/vega-lite-schema.json` picks up the `container:resize` stream from vega-typings 2.3.0. **Heads up for page-level baselines:** 6.4.0 sets `vertical-align: bottom` on canvas and SVG DOM roots, removing the baseline-descender gap. Intrinsic chart dimensions are unchanged, but occupied container height shrinks a few px. --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: GitHub Actions Bot <vega-actions-bot@users.noreply.github.com> | 17 天前 | |
feat!: esm only package (#9527) Part of https://github.com/vega/vega/issues/3990 | 1 年前 | |
feat: export the schema (#9574) | 1 年前 | |
fix(scale): evaluate signals in unioned domains, upgrade to TypeScript 6 (#9922) Two things, both of which fell out of upgrading `typescript` from `~5.9.3` to `~6.0.3`. ## 1. Bug fix: signals in unioned scale domains were silently dropped Making a type honest (see `VgScaleMultiDataRefWithSort` below) surfaced a real, user-visible bug. ```json {"params": [{"name": "lo", "value": 2}, {"name": "hi", "value": 8}], "layer": [ {"encoding": {"y": {"field": "v", "type": "quantitative", "scale": {"domain": [{"expr": "lo"}, {"expr": "hi"}]}}}, ...}, {"encoding": {"y": {"field": "v", "type": "quantitative", "scale": {"domain": [0, 5]}}}, ...}], "resolve": {"scale": {"y": "shared"}}} ``` compiled to `"domain": {"fields": [[{"signal":"lo"},{"signal":"hi"}], [0,5]]}`. Running that through Vega, the `y` domain resolved to **`[0,5]` instead of `[0,8]`** — the explicit signal domain contributed nothing and was dropped without any warning. The spec also fails validation against Vega's own `vega-schema.json`. **Root cause is an asymmetry in Vega's parser** (`packages/vega-parser/src/parsers/scale.js`). A top-level `domain` array goes through `explicitDomain` → `parseLiteral` per element, which resolves `{signal}` (and errors on any other object). But an array nested in `domain.fields` goes through `multipleDomain` → `fieldRef`, whose array branch does a raw `coll.value = {$ingest: data}` with no `parseLiteral` — so signal objects are ingested as literal data and never evaluated, silently. The neighbouring `d.signal` branch does the right thing via `setdata(...)`. So the same `[{signal: 'lo'}, 5]` syntax means two different things depending on where it appears. **I'm filing a separate PR against vega** to make `fieldRef` resolve signals the way every other literal-array path does. Vega-Lite still needs to emit something that works today: it peer-depends on `vega ^6.0.0`, and the `{signal: "[...]"}` form is valid under Vega's *current* published schema and works on every 6.x. So this is the portable encoding, not a workaround — it stays correct after the Vega fix lands. ```ts /** Vega ingests an array in `domain.fields` as literal data without evaluating signals inside it. */ function unionDomainField(domain: VgNonUnionDomain): VgNonUnionDomain { if (isArray(domain) && domain.some(isSignalRef)) { return {signal: `[${domain.map((v) => (isSignalRef(v) ? v.signal : util.stringify(v))).join(', ')}]`}; } return domain; } ``` Now emits `{"fields": [{"signal":"[lo, hi]"}, [0,5]]}`, which resolves to the correct `[0,8]` and validates. Only arrays that actually contain signals are rewritten, so **all 633 compiled examples are byte-identical**. Two tests added. The single-domain path was always correct and is untouched. ## 2. TypeScript 6.0 **TS 6.0 enables `strict` by default.** Our `tsconfig.json` never set `strict`, so it was off; it explicitly sets `strictNullChecks: false` (still respected), but everything else in the strict family is now on. Two flags did all the damage: | flag | errors | |---|---| | `strictFunctionTypes` — function parameters checked contravariantly instead of bivariantly | 22 | | `strictBindCallApply` — `.call`/`.apply`/`.bind` typed precisely instead of `(thisArg: any, ...args: any[]) => any` | 5 | Confirmed by isolating the flags: `npx tsc --strict false` on the un-fixed tree gives 0 errors. Every one of the 27 was **pre-existing unsoundness that bivariance was hiding**, not a new TS restriction, so the fixes make signatures honest rather than suppressing them. ### Notable fixes - **`ModelWithField` now carries its mapping type** — `forEachFieldDef`/`reduceFieldDef` yield `keyof M`, so a `UnitModel` gives `Channel` and a `FacetModel` gives `FacetChannel`. This replaces an `as Channel` assertion with a guarantee that follows from the arguments. Two signatures were wrong underneath it: `reduce` declared its callback as returning the *mapping* type rather than the accumulator, and `TimeUnitNode` annotated its accumulator as `TimeUnitComponent` when it is a `Dict` of them — which is exactly why it carried a `(timeUnitComponent as any)[…]`. That cast is gone too. - **`reduceFieldDef`** previously declared its callback's channel as `Channel`, but it lives on `ModelWithField` and `FacetModel extends ModelWithField`, so `'row' | 'column' | 'facet'` really did flow through. Now truthful via the generic above. - **`Split` tie-breakers** (`split.ts`, `scale/{domain,parse,properties}.ts`) — `mergeValuesWithExplicit`'s `tieBreaker` parameter declared `propertyOf: string`, but every actual tie-breaker takes the narrower `SplitParentProperty`. Also `domainsTieBreaker` declared `property: 'domains'` while two of its three call sites pass `'domain'` — the type was the lie, not the call, so it's widened to `'domain' | 'domains'`. **No warning message text changes.** - **`encoding.ts` `reduce`** declared it passes `TypedFieldDef<string>` to its callback; the implementation passes whatever is in the mapping. Corrected to `ChannelDef`. `strictBindCallApply` exposed this via the internal `f.call(...)`. - **`VgScaleMultiDataRefWithSort`** (`vega.schema.ts`) — intended to override vega's `fields` with a wider type, but `ScaleMultiDataRef & {fields: ...}` *intersects* rather than overrides, producing a `fields` type nearly nothing could satisfy, so the declared `any[]` never took effect. Changed to `Omit<ScaleMultiDataRef, 'fields'> & {...}`, matching the `Omit` idiom already used further down the same file. This is what surfaced the domain bug above. - **`selectionCompilers`** (`selection/index.ts`) — `SelectionCompiler<T>` uses `T` only in parameter position, so `SelectionCompiler<'point'>` is no longer assignable to `SelectionCompiler<SelectionType>`. All four dispatch loops guard every call behind `c.defined(selCmpt)`, which is exactly the type discriminator. Widened only the array's element type to `SelectionCompiler<any>`, so each compiler module keeps its narrow `<'point'>` / `<'interval'>` annotation and stays fully checked at its definition site. This is the one place the PR loses type safety. - **`Object.assign.apply(null, toMerge)`** (`axis/config.ts`) → `Object.assign({}, ...toMerge)` with the seed `{}` dropped from the array. Equivalent for both the populated and empty cases. - **`tsconfig.build.json`** — added `rootDir: "src"`. TS 6 now emits TS5011 during the rollup build asking for it explicitly. Verified the emitted bundles are byte-identical and the 375 `.d.ts` files land in the same places. ## Verification - `npx tsc` — clean. - `npx vitest run test/` — 3346 passed. - `npx vitest run examples/` — 3277 passed. - `npm run test:runtime -- --browser.headless` — 55 passed, 1 skipped (pre-existing `it.skip`). - `npm run lint` — clean. - `npm run build` — succeeds; TS5011 gone. - `npm run schema` — regenerated `build/vega-lite-schema.json` is **byte-identical** to the committed one. - **All 633 example specs compile to byte-identical Vega output** vs the committed `examples/compiled/*.vg.json` baseline, before and after the domain fix. ## Toolchain compatibility `typescript-eslint@8.64` declares `typescript: ">=4.8.4 <6.1.0"`, so 6.0.3 is in range. `ts-json-schema-generator` pins its own `typescript@5.9.3` as a direct dependency, so schema generation is unaffected either way. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> | 21 天前 | |
chore(deps): bump the npm_and_yarn group across 1 directory with 2 updates (#9719) Bumps the npm_and_yarn group with 2 updates in the / directory: [glob](https://github.com/isaacs/node-glob) and [js-yaml](https://github.com/nodeca/js-yaml). Updates `glob` from 11.0.3 to 11.1.0 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/isaacs/node-glob/blob/main/changelog.md">glob's changelog</a>.</em></p> <blockquote> <h1>changeglob</h1> <h2>12</h2> <ul> <li>Remove the unsafe <code>--shell</code> option. The <code>--shell</code> option is now ONLY supported on known shells where the behavior can be implemented safely.</li> </ul> <h2>11.1</h2> <p><a href="https://github.com/isaacs/node-glob/security/advisories/GHSA-5j98-mcp5-4vw2">GHSA-5j98-mcp5-4vw2</a></p> <ul> <li>Add the <code>--shell</code> option for the command line, with a warning that this is unsafe. (It will be removed in v12.)</li> <li>Add the <code>--cmd-arg</code>/<code>-g</code> as a way to <em>safely</em> add positional arguments to the command provided to the CLI tool.</li> <li>Detect commands with space or quote characters on known shells, and pass positional arguments to them safely, avoiding <code>shell:true</code> execution.</li> </ul> <h2>11.0</h2> <ul> <li>Drop support for node before v20</li> </ul> <h2>10.4</h2> <ul> <li>Add <code>includeChildMatches: false</code> option</li> <li>Export the <code>Ignore</code> class</li> </ul> <h2>10.3</h2> <ul> <li>Add <code>--default -p</code> flag to provide a default pattern</li> <li>exclude symbolic links to directories when <code>follow</code> and <code>nodir</code> are both set</li> </ul> <h2>10.2</h2> <ul> <li>Add glob cli</li> </ul> <h2>10.1</h2> <ul> <li>Return <code>'.'</code> instead of the empty string <code>''</code> when the current working directory is returned as a match.</li> <li>Add <code>posix: true</code> option to return <code>/</code> delimited paths, even on Windows.</li> </ul> <h2>10.0.0</h2> <ul> <li>No default exports, only named exports</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/isaacs/node-glob/commit/2551fb51440d402fa2120457bf460e546ee9964d"><code>2551fb5</code></a> 11.1.0</li> <li><a href="https://github.com/isaacs/node-glob/commit/47473c046b91c67269df7a66eab782a6c2716146"><code>47473c0</code></a> bin: Do not expose filenames to shell expansion</li> <li><a href="https://github.com/isaacs/node-glob/commit/bc33fe1c6a47abd497703d79ad96036e7891ff62"><code>bc33fe1</code></a> skip tilde test on systems that lack tilde expansion</li> <li><a href="https://github.com/isaacs/node-glob/commit/59bf9ca211bda5636c4fe9e32d41530c90a4f30d"><code>59bf9ca</code></a> fix notes</li> <li><a href="https://github.com/isaacs/node-glob/commit/dde4fa66c87e24b37bb5be28ed10c6e12019edac"><code>dde4fa6</code></a> docs(README): add #anchor and improve <code>note</code>s</li> <li><a href="https://github.com/isaacs/node-glob/commit/0559b0ed13c0f8147cd2ac9d48bb49684caaf20e"><code>0559b0e</code></a> docs: add better links to path-scurry docs</li> <li><a href="https://github.com/isaacs/node-glob/commit/c9773c249b4b9ed6b2447222c226f9d20c6ce916"><code>c9773c2</code></a> fix: correct typos in <code>README.md</code></li> <li><a href="https://github.com/isaacs/node-glob/commit/13e68eadbc4f0aacd9d6ffbcb4b28a34d5d8512c"><code>13e68ea</code></a> Fix punctuation in traversal function documentation</li> <li><a href="https://github.com/isaacs/node-glob/commit/1527e2b8107e95122ab6e9b6f6312f121693d53d"><code>1527e2b</code></a> fix repo url</li> <li><a href="https://github.com/isaacs/node-glob/commit/7e190e8776a7fa66fba40827de5f9effd1c52f9d"><code>7e190e8</code></a> fix typo <code>maths</code> → <code>paths</code></li> <li>Additional commits viewable in <a href="https://github.com/isaacs/node-glob/compare/v11.0.3...v11.1.0">compare view</a></li> </ul> </details> <br /> Updates `js-yaml` from 3.14.1 to 3.14.2 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md">js-yaml's changelog</a>.</em></p> <blockquote> <h2>[3.14.2] - 2025-11-15</h2> <h3>Security</h3> <ul> <li>Backported v4.1.1 fix to v3</li> </ul> <h2>[4.1.1] - 2025-11-12</h2> <h3>Security</h3> <ul> <li>Fix prototype pollution issue in yaml merge (<<) operator.</li> </ul> <h2>[4.1.0] - 2021-04-15</h2> <h3>Added</h3> <ul> <li>Types are now exported as <code>yaml.types.XXX</code>.</li> <li>Every type now has <code>options</code> property with original arguments kept as they were (see <code>yaml.types.int.options</code> as an example).</li> </ul> <h3>Changed</h3> <ul> <li><code>Schema.extend()</code> now keeps old type order in case of conflicts (e.g. Schema.extend([ a, b, c ]).extend([ b, a, d ]) is now ordered as <code>abcd</code> instead of <code>cbad</code>).</li> </ul> <h2>[4.0.0] - 2021-01-03</h2> <h3>Changed</h3> <ul> <li>Check <a href="https://github.com/nodeca/js-yaml/blob/master/migrate_v3_to_v4.md">migration guide</a> to see details for all breaking changes.</li> <li>Breaking: "unsafe" tags <code>!!js/function</code>, <code>!!js/regexp</code>, <code>!!js/undefined</code> are moved to <a href="https://github.com/nodeca/js-yaml-js-types">js-yaml-js-types</a> package.</li> <li>Breaking: removed <code>safe*</code> functions. Use <code>load</code>, <code>loadAll</code>, <code>dump</code> instead which are all now safe by default.</li> <li><code>yaml.DEFAULT_SAFE_SCHEMA</code> and <code>yaml.DEFAULT_FULL_SCHEMA</code> are removed, use <code>yaml.DEFAULT_SCHEMA</code> instead.</li> <li><code>yaml.Schema.create(schema, tags)</code> is removed, use <code>schema.extend(tags)</code> instead.</li> <li><code>!!binary</code> now always mapped to <code>Uint8Array</code> on load.</li> <li>Reduced nesting of <code>/lib</code> folder.</li> <li>Parse numbers according to YAML 1.2 instead of YAML 1.1 (<code>01234</code> is now decimal, <code>0o1234</code> is octal, <code>1:23</code> is parsed as string instead of base60).</li> <li><code>dump()</code> no longer quotes <code>:</code>, <code>[</code>, <code>]</code>, <code>(</code>, <code>)</code> except when necessary, <a href="https://redirect.github.com/nodeca/js-yaml/issues/470">#470</a>, <a href="https://redirect.github.com/nodeca/js-yaml/issues/557">#557</a>.</li> <li>Line and column in exceptions are now formatted as <code>(X:Y)</code> instead of <code>at line X, column Y</code> (also present in compact format), <a href="https://redirect.github.com/nodeca/js-yaml/issues/332">#332</a>.</li> <li>Code snippet created in exceptions now contains multiple lines with line numbers.</li> <li><code>dump()</code> now serializes <code>undefined</code> as <code>null</code> in collections and removes keys with <code>undefined</code> in mappings, <a href="https://redirect.github.com/nodeca/js-yaml/issues/571">#571</a>.</li> <li><code>dump()</code> with <code>skipInvalid=true</code> now serializes invalid items in collections as null.</li> <li>Custom tags starting with <code>!</code> are now dumped as <code>!tag</code> instead of <code>!<!tag></code>, <a href="https://redirect.github.com/nodeca/js-yaml/issues/576">#576</a>.</li> <li>Custom tags starting with <code>tag:yaml.org,2002:</code> are now shorthanded using <code>!!</code>, <a href="https://redirect.github.com/nodeca/js-yaml/issues/258">#258</a>.</li> </ul> <h3>Added</h3> <ul> <li>Added <code>.mjs</code> (es modules) support.</li> <li>Added <code>quotingType</code> and <code>forceQuotes</code> options for dumper to configure string literal style, <a href="https://redirect.github.com/nodeca/js-yaml/issues/290">#290</a>, <a href="https://redirect.github.com/nodeca/js-yaml/issues/529">#529</a>.</li> <li>Added <code>styles: { '!!null': 'empty' }</code> option for dumper (serializes <code>{ foo: null }</code> as "<code>foo: </code>"), <a href="https://redirect.github.com/nodeca/js-yaml/issues/570">#570</a>.</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/nodeca/js-yaml/commit/9963d366dfbde0c69722452bcd40b41e7e4160a0"><code>9963d36</code></a> 3.14.2 released</li> <li><a href="https://github.com/nodeca/js-yaml/commit/10d3c8e70a6888543f5cdb656bb39f73e0ea77c1"><code>10d3c8e</code></a> dist rebuild</li> <li><a href="https://github.com/nodeca/js-yaml/commit/5278870a17454fe8621dbd8c445c412529525266"><code>5278870</code></a> fix prototype pollution in merge (<<) (<a href="https://redirect.github.com/nodeca/js-yaml/issues/731">#731</a>)</li> <li>See full diff in <a href="https://github.com/nodeca/js-yaml/compare/3.14.1...3.14.2">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/vega/vega-lite/network/alerts). </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Dominik Moritz <domoritz@gmail.com> | 9 个月前 | |
chore(deps): bump the npm_and_yarn group across 1 directory with 2 updates (#9719) Bumps the npm_and_yarn group with 2 updates in the / directory: [glob](https://github.com/isaacs/node-glob) and [js-yaml](https://github.com/nodeca/js-yaml). Updates `glob` from 11.0.3 to 11.1.0 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/isaacs/node-glob/blob/main/changelog.md">glob's changelog</a>.</em></p> <blockquote> <h1>changeglob</h1> <h2>12</h2> <ul> <li>Remove the unsafe <code>--shell</code> option. The <code>--shell</code> option is now ONLY supported on known shells where the behavior can be implemented safely.</li> </ul> <h2>11.1</h2> <p><a href="https://github.com/isaacs/node-glob/security/advisories/GHSA-5j98-mcp5-4vw2">GHSA-5j98-mcp5-4vw2</a></p> <ul> <li>Add the <code>--shell</code> option for the command line, with a warning that this is unsafe. (It will be removed in v12.)</li> <li>Add the <code>--cmd-arg</code>/<code>-g</code> as a way to <em>safely</em> add positional arguments to the command provided to the CLI tool.</li> <li>Detect commands with space or quote characters on known shells, and pass positional arguments to them safely, avoiding <code>shell:true</code> execution.</li> </ul> <h2>11.0</h2> <ul> <li>Drop support for node before v20</li> </ul> <h2>10.4</h2> <ul> <li>Add <code>includeChildMatches: false</code> option</li> <li>Export the <code>Ignore</code> class</li> </ul> <h2>10.3</h2> <ul> <li>Add <code>--default -p</code> flag to provide a default pattern</li> <li>exclude symbolic links to directories when <code>follow</code> and <code>nodir</code> are both set</li> </ul> <h2>10.2</h2> <ul> <li>Add glob cli</li> </ul> <h2>10.1</h2> <ul> <li>Return <code>'.'</code> instead of the empty string <code>''</code> when the current working directory is returned as a match.</li> <li>Add <code>posix: true</code> option to return <code>/</code> delimited paths, even on Windows.</li> </ul> <h2>10.0.0</h2> <ul> <li>No default exports, only named exports</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/isaacs/node-glob/commit/2551fb51440d402fa2120457bf460e546ee9964d"><code>2551fb5</code></a> 11.1.0</li> <li><a href="https://github.com/isaacs/node-glob/commit/47473c046b91c67269df7a66eab782a6c2716146"><code>47473c0</code></a> bin: Do not expose filenames to shell expansion</li> <li><a href="https://github.com/isaacs/node-glob/commit/bc33fe1c6a47abd497703d79ad96036e7891ff62"><code>bc33fe1</code></a> skip tilde test on systems that lack tilde expansion</li> <li><a href="https://github.com/isaacs/node-glob/commit/59bf9ca211bda5636c4fe9e32d41530c90a4f30d"><code>59bf9ca</code></a> fix notes</li> <li><a href="https://github.com/isaacs/node-glob/commit/dde4fa66c87e24b37bb5be28ed10c6e12019edac"><code>dde4fa6</code></a> docs(README): add #anchor and improve <code>note</code>s</li> <li><a href="https://github.com/isaacs/node-glob/commit/0559b0ed13c0f8147cd2ac9d48bb49684caaf20e"><code>0559b0e</code></a> docs: add better links to path-scurry docs</li> <li><a href="https://github.com/isaacs/node-glob/commit/c9773c249b4b9ed6b2447222c226f9d20c6ce916"><code>c9773c2</code></a> fix: correct typos in <code>README.md</code></li> <li><a href="https://github.com/isaacs/node-glob/commit/13e68eadbc4f0aacd9d6ffbcb4b28a34d5d8512c"><code>13e68ea</code></a> Fix punctuation in traversal function documentation</li> <li><a href="https://github.com/isaacs/node-glob/commit/1527e2b8107e95122ab6e9b6f6312f121693d53d"><code>1527e2b</code></a> fix repo url</li> <li><a href="https://github.com/isaacs/node-glob/commit/7e190e8776a7fa66fba40827de5f9effd1c52f9d"><code>7e190e8</code></a> fix typo <code>maths</code> → <code>paths</code></li> <li>Additional commits viewable in <a href="https://github.com/isaacs/node-glob/compare/v11.0.3...v11.1.0">compare view</a></li> </ul> </details> <br /> Updates `js-yaml` from 3.14.1 to 3.14.2 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md">js-yaml's changelog</a>.</em></p> <blockquote> <h2>[3.14.2] - 2025-11-15</h2> <h3>Security</h3> <ul> <li>Backported v4.1.1 fix to v3</li> </ul> <h2>[4.1.1] - 2025-11-12</h2> <h3>Security</h3> <ul> <li>Fix prototype pollution issue in yaml merge (<<) operator.</li> </ul> <h2>[4.1.0] - 2021-04-15</h2> <h3>Added</h3> <ul> <li>Types are now exported as <code>yaml.types.XXX</code>.</li> <li>Every type now has <code>options</code> property with original arguments kept as they were (see <code>yaml.types.int.options</code> as an example).</li> </ul> <h3>Changed</h3> <ul> <li><code>Schema.extend()</code> now keeps old type order in case of conflicts (e.g. Schema.extend([ a, b, c ]).extend([ b, a, d ]) is now ordered as <code>abcd</code> instead of <code>cbad</code>).</li> </ul> <h2>[4.0.0] - 2021-01-03</h2> <h3>Changed</h3> <ul> <li>Check <a href="https://github.com/nodeca/js-yaml/blob/master/migrate_v3_to_v4.md">migration guide</a> to see details for all breaking changes.</li> <li>Breaking: "unsafe" tags <code>!!js/function</code>, <code>!!js/regexp</code>, <code>!!js/undefined</code> are moved to <a href="https://github.com/nodeca/js-yaml-js-types">js-yaml-js-types</a> package.</li> <li>Breaking: removed <code>safe*</code> functions. Use <code>load</code>, <code>loadAll</code>, <code>dump</code> instead which are all now safe by default.</li> <li><code>yaml.DEFAULT_SAFE_SCHEMA</code> and <code>yaml.DEFAULT_FULL_SCHEMA</code> are removed, use <code>yaml.DEFAULT_SCHEMA</code> instead.</li> <li><code>yaml.Schema.create(schema, tags)</code> is removed, use <code>schema.extend(tags)</code> instead.</li> <li><code>!!binary</code> now always mapped to <code>Uint8Array</code> on load.</li> <li>Reduced nesting of <code>/lib</code> folder.</li> <li>Parse numbers according to YAML 1.2 instead of YAML 1.1 (<code>01234</code> is now decimal, <code>0o1234</code> is octal, <code>1:23</code> is parsed as string instead of base60).</li> <li><code>dump()</code> no longer quotes <code>:</code>, <code>[</code>, <code>]</code>, <code>(</code>, <code>)</code> except when necessary, <a href="https://redirect.github.com/nodeca/js-yaml/issues/470">#470</a>, <a href="https://redirect.github.com/nodeca/js-yaml/issues/557">#557</a>.</li> <li>Line and column in exceptions are now formatted as <code>(X:Y)</code> instead of <code>at line X, column Y</code> (also present in compact format), <a href="https://redirect.github.com/nodeca/js-yaml/issues/332">#332</a>.</li> <li>Code snippet created in exceptions now contains multiple lines with line numbers.</li> <li><code>dump()</code> now serializes <code>undefined</code> as <code>null</code> in collections and removes keys with <code>undefined</code> in mappings, <a href="https://redirect.github.com/nodeca/js-yaml/issues/571">#571</a>.</li> <li><code>dump()</code> with <code>skipInvalid=true</code> now serializes invalid items in collections as null.</li> <li>Custom tags starting with <code>!</code> are now dumped as <code>!tag</code> instead of <code>!<!tag></code>, <a href="https://redirect.github.com/nodeca/js-yaml/issues/576">#576</a>.</li> <li>Custom tags starting with <code>tag:yaml.org,2002:</code> are now shorthanded using <code>!!</code>, <a href="https://redirect.github.com/nodeca/js-yaml/issues/258">#258</a>.</li> </ul> <h3>Added</h3> <ul> <li>Added <code>.mjs</code> (es modules) support.</li> <li>Added <code>quotingType</code> and <code>forceQuotes</code> options for dumper to configure string literal style, <a href="https://redirect.github.com/nodeca/js-yaml/issues/290">#290</a>, <a href="https://redirect.github.com/nodeca/js-yaml/issues/529">#529</a>.</li> <li>Added <code>styles: { '!!null': 'empty' }</code> option for dumper (serializes <code>{ foo: null }</code> as "<code>foo: </code>"), <a href="https://redirect.github.com/nodeca/js-yaml/issues/570">#570</a>.</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/nodeca/js-yaml/commit/9963d366dfbde0c69722452bcd40b41e7e4160a0"><code>9963d36</code></a> 3.14.2 released</li> <li><a href="https://github.com/nodeca/js-yaml/commit/10d3c8e70a6888543f5cdb656bb39f73e0ea77c1"><code>10d3c8e</code></a> dist rebuild</li> <li><a href="https://github.com/nodeca/js-yaml/commit/5278870a17454fe8621dbd8c445c412529525266"><code>5278870</code></a> fix prototype pollution in merge (<<) (<a href="https://redirect.github.com/nodeca/js-yaml/issues/731">#731</a>)</li> <li>See full diff in <a href="https://github.com/nodeca/js-yaml/compare/3.14.1...3.14.2">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/vega/vega-lite/network/alerts). </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Dominik Moritz <domoritz@gmail.com> | 9 个月前 | |
chore: update contributing docs for testing (#9546) | 1 年前 |
以下内容由 AI 翻译,如有问题请 点此提交 issue 反馈
Vega-Lite 

Vega-Lite 提供了一种更高级的视觉分析语法,能够生成完整的 Vega 规范。
您可以在 Vega-Lite 网站 上找到更多详细信息,包括 文档、示例、使用说明 以及 教程。
在在线 Vega 编辑器 中尝试使用 Vega-Lite。
我们也欢迎贡献。请查看 CONTRIBUTING.md 了解贡献和开发指南,以及我们的 行为准则。
在 我们的路线图 中了解未来的规划。
团队
Vega-Lite 的开发由 华盛顿大学交互数据实验室(UW IDL)的校友和成员领导,包括 Kanit "Ham" Wongsuphasawat(现就职于 Databricks)、Dominik Moritz(现就职于 CMU / Apple)、Arvind Satyanarayan(现就职于 MIT)和 Jeffrey Heer(UW IDL)。
Vega-Lite 得益于社区的显著贡献。请查看 贡献者页面 以获取完整的贡献者列表。
引用 Vega-Lite
@article{2017-vega-lite,
doi = {10.1109/tvcg.2016.2599030},
year = {2017},
author = {Arvind Satyanarayan and Dominik Moritz and Kanit Wongsuphasawat and Jeffrey Heer},
title = {Vega-Lite: A Grammar of Interactive Graphics},
journal = {{IEEE} Transactions on Visualization \& Computer Graphics (Proc. InfoVis)},
url = {http://idl.cs.washington.edu/papers/vega-lite},
}
请提供需要翻译的文本内容,这样我才能为您翻译成通俗、专业、优雅且流畅的中文。
项目介绍
《基于Vega构建的互动图像简洁语法》【此简介由AI生成】
BSD-3-Clause TypeScript10.52 K提交数chartsdeclarative-languageplotvegavega-litevisual-analysisvisualizationvisualization-grammar
定制我的领域