Skip to content

Build(deps): bump @primer/view-components from 0.52.2 to 0.53.1 - #1023

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/primer/view-components-0.53.1
Open

Build(deps): bump @primer/view-components from 0.52.2 to 0.53.1#1023
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/primer/view-components-0.53.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 24, 2026

Copy link
Copy Markdown
Contributor

Bumps @primer/view-components from 0.52.2 to 0.53.1.

Release notes

Sourced from @​primer/view-components's releases.

v0.53.1

Patch Changes

  • #4133 0098814 Thanks @​jonrohan! - Downgrade @oddbird/popover-polyfill to ^0.5.2 and pin it via Dependabot ignore so it won't get bumped again.

v0.53.0

Minor Changes

  • #4110 bf92d87 Thanks @​dylanatsmith! - Blankslate: The heading and body text now use the smaller compact sizes by default, and the redundant responsive @container block has been removed since the compact typography it produced is now the default

Patch Changes

  • #3696 8b8d542 Thanks @​myabc! - Fix incorrect label for attribute value when scope_id_to_model: false

  • #4113 7c52375 Thanks @​liuliu-dev! - Reject javascript: and vbscript: URI schemes in href (defense in depth). When a component (e.g. Primer::Beta::Label, Primer::Beta::Button, Primer::Beta::Link) is rendered as an anchor with an unsafe href, the value is now rejected — raising in non-production environments and silently dropped (rendered as an anchor with no href) in production.

  • #4107 222a846 Thanks @​dylanatsmith! - Fix ToggleSwitch knob spacing and border-radius to match primer/react

Changelog

Sourced from @​primer/view-components's changelog.

0.53.1

Patch Changes

  • #4133 0098814 Thanks @​jonrohan! - Downgrade @oddbird/popover-polyfill to ^0.5.2 and pin it via Dependabot ignore so it won't get bumped again.

0.53.0

Minor Changes

  • #4110 bf92d87 Thanks @​dylanatsmith! - Blankslate: The heading and body text now use the smaller compact sizes by default, and the redundant responsive @container block has been removed since the compact typography it produced is now the default

Patch Changes

  • #3696 8b8d542 Thanks @​myabc! - Fix incorrect label for attribute value when scope_id_to_model: false

  • #4113 7c52375 Thanks @​liuliu-dev! - Reject javascript: and vbscript: URI schemes in href (defense in depth). When a component (e.g. Primer::Beta::Label, Primer::Beta::Button, Primer::Beta::Link) is rendered as an anchor with an unsafe href, the value is now rejected — raising in non-production environments and silently dropped (rendered as an anchor with no href) in production.

  • #4107 222a846 Thanks @​dylanatsmith! - Fix ToggleSwitch knob spacing and border-radius to match primer/react

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jul 24, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/primer/view-components-0.53.1 branch from 57f4c37 to c97e03f Compare July 24, 2026 14:47
Bumps [@primer/view-components](https://github.com/primer/view_components) from 0.52.2 to 0.53.1.
- [Release notes](https://github.com/primer/view_components/releases)
- [Changelog](https://github.com/primer/view_components/blob/main/CHANGELOG.md)
- [Commits](primer/view_components@v0.52.2...v0.53.1)

---
updated-dependencies:
- dependency-name: "@primer/view-components"
  dependency-version: 0.53.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/primer/view-components-0.53.1 branch from c97e03f to 6b10b55 Compare July 24, 2026 14:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants