Skip to content

release: theme-elementary v2 🚀 - #692

Merged
aryanjasala merged 155 commits into
mainfrom
theme-elementary-v2
Oct 1, 2026
Merged

aryanjasala merged 155 commits into
mainfrom
theme-elementary-v2

Conversation

@aryanjasala

@aryanjasala aryanjasala commented May 26, 2026 •

Copy link
Copy Markdown
Member

🎉 Theme Elementary v2 rebuilds the starter on rtCamp's shared WordPress stack: runtime code comes from rtcamp/wp-primitives, and setup, scaffolding, releases and lint configs come from @rtcamp/wp-tooling and the @rtcamp npm packages. Merging this makes v2 what main ships.

✨ What's new

🏗️ Architecture

  • PSR-4 PHP under inc/ with a Main bootstrap and a graceful Autoloader: Core/ for theme-wide services, Modules/ for feature areas, Abstracts/ and Helpers/. Strict types throughout. Replaces v1's inc/classes, inc/helpers and inc/traits.
  • Built on rtcamp/wp-primitives ^2.0, with theme-owned adapters for its services: asset loading (AssetLoader), components (ComponentLoader), template parts (TemplateLoader), runtime feature flags (FeatureSelector), logging (Logger) and encryption (Encryptor).
  • Runtime feature flags under Settings → Features turn retained features on and off without deleting code.

🚀 Setup and scaffolding

  • npm run init turns the starter into your theme: name, namespace, text domain and prefixes, which example sets to keep, and which optional features to enable. Run it again later to manage features.
  • npx wp-tooling add generates features (custom post types, blocks, REST controllers, WP-CLI commands, settings pages and more) together with their tests.
  • Optional development features, on or off at any time:
    • ⚡ HMR: BrowserSync live reload for the frontend, and React Fast Refresh for blocks in the editor.
    • 🌊 Tailwind CSS v4, with theme tokens generated from theme.json.
    • 🛠️ Dev Tools: Query Monitor, the MCP Adapter and rtcamp/wp-dev-tools runtime telemetry in the local wp-env site.

🎨 Assets

  • Sources live in src/ (components, CSS, JS, fonts, images) and build to assets/build/, with blocks under assets/build/blocks/. Builds use @wordpress/scripts 36.
  • Example components (button, card) show the PHP, JS and SCSS pattern for reusable pieces.

✅ Quality

  • PHPUnit suite (101 tests, about 88% line coverage) and Jest suite (59 tests).
  • PHPCS with the rtCamp standard (rtcamp/wp-phpcs), PHPStan (rtcamp/wp-phpstan), and ESLint and Stylelint from @rtcamp/eslint-config and @rtcamp/stylelint-config.
  • CI through rtCamp/wp-shared-workflows: lint, Jest, build, and PHPUnit across PHP 8.2 to 8.4 and WordPress 6.5 to 7.0.
  • No open npm or Composer security advisories.

🤖 AI tooling

  • Shared conventions in AGENTS.md, Claude Code skills (/init, /scaffold, /setup), and GitHub Copilot prompts and instructions synced from wp-primitives.
  • A committed knowledge graph (graphify-out/) so assistants can query the codebase's structure instead of reading every file.

📚 Docs

  • Guides for getting started, initialization, local development, included features, scaffolding, the asset pipeline, HMR and Tailwind, published as a docs site.

⚠️ Breaking changes from v1

v2 is a new starter, not an in-place upgrade. Existing v1-based themes keep working as they are.

  • Requires PHP 8.2+, WordPress 6.6+ and Node.js 22.19+.
  • New directory layout and namespaces (rtCamp\Theme\Elementary\…); v1's classes, helpers and traits are removed.
  • The Composer package is now rtcamp/theme-elementary.
  • Build output paths changed (assets/build/…).

🧪 Testing

  • CI on this PR: lint, Jest, build, and the PHPUnit matrix
  • Locally, on the merged v2: npm ci on npm 10 and 11, lint:all, Jest, build:prod, PHPCS, PHPStan, PHPUnit through wp-env, block HMR and BrowserSync against a running site, and npm run init on a fresh copy

bhavz-10 and others added 30 commits March 31, 2026 10:32
Refactor: PSR-4 PHP Structure Migration
Update style.css to remove @ tags and make the Description more descriptive. Make other changes based on return types and description.
…strict-types-docblock-cleanup

PHP 8.2 Compatibility, Strict Types & Docblock Cleanup
* chore: Update output messages in CI workflow to include repository name and replace `::set-output ` with `$GITHUB_OUTPUT`

* chore: Enhance CI workflow by adding node version retrieval and caching for node_modules

* chore: Remove GHA workflow count from job triggers and outputs

* chore: Update IGNORE_PATH_REGEX to also allow .github/actions through

* chore: Fix regex

* fix: Correct typo in external dependencies comment

* fix: Add missing newline at end of README.md

* fix: Update cache condition for Node dependencies installation
Reorganize the theme's frontend source into a top-level src/ directory
with context-based subdirectories (frontend/, admin/, editor/) that
webpack discovers automatically via readAllFileEntries. This separates
source from compiled output (assets/build/) and removes the need for
manual webpack entry configuration.

- Move CSS and JS source files into src/{css,js}/frontend/
- Add placeholder directories for admin, editor, shared, globals, mixins
- Update readAllFileEntries to scan context subdirectories automatically
- Integrate font copying and SVGO optimization into the webpack pipeline
- Update lint scripts to target src/
- Remove unused cross-env dependency, add copy-webpack-plugin and svgo
- Update README.md and docs to reflect new structure
aryanjasala and others added 4 commits October 1, 2026 23:46
* Chore(deps): Bump tmp from 0.2.5 to 0.2.7 (#694)

Bumps [tmp](https://github.com/raszi/node-tmp) from 0.2.5 to 0.2.7.
- [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md)
- [Commits](raszi/node-tmp@v0.2.5...v0.2.7)

---
updated-dependencies:
- dependency-name: tmp
  dependency-version: 0.2.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump shell-quote from 1.8.3 to 1.8.4 (#711)

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.3 to 1.8.4.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](ljharb/shell-quote@v1.8.3...v1.8.4)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.8.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump launch-editor from 2.13.1 to 2.14.1 (#723)

Bumps [launch-editor](https://github.com/vitejs/launch-editor) from 2.13.1 to 2.14.1.
- [Commits](vitejs/launch-editor@v2.13.1...v2.14.1)

---
updated-dependencies:
- dependency-name: launch-editor
  dependency-version: 2.14.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump form-data from 4.0.5 to 4.0.6 (#722)

Bumps [form-data](https://github.com/form-data/form-data) from 4.0.5 to 4.0.6.
- [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md)
- [Commits](form-data/form-data@v4.0.5...v4.0.6)

---
updated-dependencies:
- dependency-name: form-data
  dependency-version: 4.0.6
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump @babel/core from 7.29.0 to 7.29.6 (#724)

Bumps [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) from 7.29.0 to 7.29.6.
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.29.6/packages/babel-core)

---
updated-dependencies:
- dependency-name: "@babel/core"
  dependency-version: 7.29.6
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump ws and @wp-playground/cli (#735)

Bumps [ws](https://github.com/websockets/ws) and [@wp-playground/cli](https://github.com/WordPress/wordpress-playground). These dependencies needed to be updated together.

Updates `ws` from 8.18.3 to 8.21.1
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.18.3...8.21.1)

Updates `ws` from 8.19.0 to 8.21.1
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.18.3...8.21.1)

Updates `ws` from 7.5.10 to 7.5.12
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.18.3...8.21.1)

Updates `@wp-playground/cli` from 3.1.3 to 3.1.44
- [Release notes](https://github.com/WordPress/wordpress-playground/releases)
- [Changelog](https://github.com/WordPress/wordpress-playground/blob/trunk/CHANGELOG.md)
- [Commits](WordPress/wordpress-playground@v3.1.3...v3.1.44)

---
updated-dependencies:
- dependency-name: ws
  dependency-version: 8.21.1
  dependency-type: indirect
- dependency-name: ws
  dependency-version: 8.21.1
  dependency-type: indirect
- dependency-name: ws
  dependency-version: 7.5.12
  dependency-type: indirect
- dependency-name: "@wp-playground/cli"
  dependency-version: 3.1.44
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump websocket-driver from 0.7.4 to 0.7.5 (#738)

Bumps [websocket-driver](https://github.com/faye/websocket-driver-node) from 0.7.4 to 0.7.5.
- [Changelog](https://github.com/faye/websocket-driver-node/blob/main/CHANGELOG.md)
- [Commits](faye/websocket-driver-node@0.7.4...0.7.5)

---
updated-dependencies:
- dependency-name: websocket-driver
  dependency-version: 0.7.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump svgo (#740)

Bumps  and [svgo](https://github.com/svg/svgo). These dependencies needed to be updated together.

Updates `svgo` from 3.3.3 to 3.3.4
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v3.3.3...v3.3.4)

Updates `svgo` from 4.0.1 to 4.0.2
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v3.3.3...v3.3.4)

---
updated-dependencies:
- dependency-name: svgo
  dependency-version: 3.3.4
  dependency-type: indirect
- dependency-name: svgo
  dependency-version: 4.0.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump shell-quote from 1.8.4 to 1.10.0 (#742)

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.4 to 1.10.0.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](ljharb/shell-quote@v1.8.4...v1.10.0)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.10.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump immutable from 5.1.5 to 5.1.9 (#745)

Bumps [immutable](https://github.com/immutable-js/immutable-js) from 5.1.5 to 5.1.9.
- [Release notes](https://github.com/immutable-js/immutable-js/releases)
- [Changelog](https://github.com/immutable-js/immutable-js/blob/main/CHANGELOG.md)
- [Commits](immutable-js/immutable-js@v5.1.5...v5.1.9)

---
updated-dependencies:
- dependency-name: immutable
  dependency-version: 5.1.9
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump fast-xml-parser from 5.10.0 to 5.10.1 (#741)

Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) from 5.10.0 to 5.10.1.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-parser@v5.10.0...v5.10.1)

---
updated-dependencies:
- dependency-name: fast-xml-parser
  dependency-version: 5.10.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump fast-uri from 3.1.3 to 3.1.4 (#743)

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.3 to 3.1.4.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.3...v3.1.4)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump postcss from 8.5.10 to 8.5.22 (#744)

Bumps [postcss](https://github.com/postcss/postcss) from 8.5.10 to 8.5.22.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.10...8.5.22)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.22
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump fast-uri from 3.1.4 to 3.1.5 (#754)

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.4 to 3.1.5.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.4...v3.1.5)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump postcss from 8.5.22 to 8.5.25 (#755)

Bumps [postcss](https://github.com/postcss/postcss) from 8.5.22 to 8.5.25.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.22...8.5.25)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.25
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Run Copilot code review on GitHub-hosted runners

* Chore(deps): Bump postcss-selector-parser (#760)

Bumps  and [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser). These dependencies needed to be updated together.

Updates `postcss-selector-parser` from 7.1.1 to 7.1.5
- [Release notes](https://github.com/postcss/postcss-selector-parser/releases)
- [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss-selector-parser@v7.1.1...7.1.5)

Updates `postcss-selector-parser` from 6.1.2 to 6.1.4
- [Release notes](https://github.com/postcss/postcss-selector-parser/releases)
- [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss-selector-parser@v7.1.1...7.1.5)

---
updated-dependencies:
- dependency-name: postcss-selector-parser
  dependency-version: 7.1.5
  dependency-type: indirect
- dependency-name: postcss-selector-parser
  dependency-version: 6.1.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump fast-uri from 3.1.5 to 3.1.7 (#762)

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.7.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.5...v3.1.7)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump @humanfs/node from 0.16.7 to 0.16.8 (#763)

Bumps [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) from 0.16.7 to 0.16.8.
- [Release notes](https://github.com/humanwhocodes/humanfs/releases)
- [Changelog](https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md)
- [Commits](https://github.com/humanwhocodes/humanfs/commits/node-v0.16.8/packages/node)

---
updated-dependencies:
- dependency-name: "@humanfs/node"
  dependency-version: 0.16.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump joi from 18.0.2 to 18.2.8 (#764)

Bumps [joi](https://github.com/hapijs/joi) from 18.0.2 to 18.2.8.
- [Commits](hapijs/joi@v18.0.2...v18.2.8)

---
updated-dependencies:
- dependency-name: joi
  dependency-version: 18.2.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump baseline-browser-mapping from 2.10.0 to 2.11.21 (#767)

Bumps [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) from 2.10.0 to 2.11.21.
- [Release notes](https://github.com/web-platform-dx/baseline-browser-mapping/releases)
- [Commits](web-platform-dx/baseline-browser-mapping@v2.10.0...v2.11.21)

---
updated-dependencies:
- dependency-name: baseline-browser-mapping
  dependency-version: 2.11.21
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump svgo (#765)

Bumps  and [svgo](https://github.com/svg/svgo). These dependencies needed to be updated together.

Updates `svgo` from 3.3.4 to 3.3.5
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v3.3.4...v3.3.5)

Updates `svgo` from 4.0.2 to 4.1.0
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v3.3.4...v3.3.5)

---
updated-dependencies:
- dependency-name: svgo
  dependency-version: 3.3.5
  dependency-type: indirect
- dependency-name: svgo
  dependency-version: 4.1.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump js-yaml (#766)

Bumps  and [js-yaml](https://github.com/nodeca/js-yaml). These dependencies needed to be updated together.

Updates `js-yaml` from 3.14.2 to 3.15.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md)
- [Commits](nodeca/js-yaml@3.14.2...3.15.2)

Updates `js-yaml` from 4.1.1 to 4.3.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md)
- [Commits](nodeca/js-yaml@3.14.2...3.15.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 3.15.2
  dependency-type: indirect
- dependency-name: js-yaml
  dependency-version: 4.3.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* feat(init): init skill simplification and add dev-tools feature

* feat(tests): add dev-tools and init wrapper test cases

* docs: add guides and documentation workflow

Consolidate onboarding, development, feature, and maintainer guidance, and build the documentation site through the shared workflow.

* fix: update cleanup targets in scaffold config

* docs: address PR review feedback on documentation

* Chore(deps): Bump adm-zip and @wordpress/scripts (#780)

Bumps [adm-zip](https://github.com/cthackers/adm-zip) to 0.6.1 and updates ancestor dependency [@wordpress/scripts](https://github.com/WordPress/gutenberg/tree/HEAD/packages/scripts). These dependencies need to be updated together.


Updates `adm-zip` from 0.5.16 to 0.6.1
- [Release notes](https://github.com/cthackers/adm-zip/releases)
- [Changelog](https://github.com/cthackers/adm-zip/blob/master/history.md)
- [Commits](cthackers/adm-zip@v0.5.16...v0.6.1)

Updates `@wordpress/scripts` from 31.5.0 to 35.0.0
- [Release notes](https://github.com/WordPress/gutenberg/releases)
- [Changelog](https://github.com/WordPress/gutenberg/blob/trunk/packages/scripts/CHANGELOG.md)
- [Commits](https://github.com/WordPress/gutenberg/commits/@wordpress/scripts@35.0.0/packages/scripts)

---
updated-dependencies:
- dependency-name: adm-zip
  dependency-version: 0.6.1
  dependency-type: indirect
- dependency-name: "@wordpress/scripts"
  dependency-version: 35.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* docs: address readability feedback across all documentation

* docs: unify troubleshooting headings, fix inaccuracies, and tighten prose

* docs: drop hard-wrapped lines, rebuild asset/hmr/tailwind docs from source

* docs: address second-round review feedback

- Restore Directory Structure section in asset-building-process.md, replacing the Source to output table
- Revert BrowserSync constant to ELEMENTARY_THEME_BROWSER_SYNC_URL in hmr.md
- Point Copilot prompts URL to theme-elementary-v2 where prompts exist (absolute because relative breaks after init removes .github/prompts)
- Re-add folder structure section to README.md

* chore: rename wp-framework to wp-primitives

* fix: address rename audit findings

- restore truthful composer.lock where the rename had falsified it
- correct unresolvable ^1.0 constraints in install docs
- document the HANDLE_PREFIX and text-domain breaks
- add the 1.0.x to 2.0.0 migration guide
- prune the superseded instructions file on sync

* Chore(deps): Bump markdown-it and @wordpress/scripts (#783)

Bumps [markdown-it](https://github.com/markdown-it/markdown-it) to 14.3.2 and updates ancestor dependency [@wordpress/scripts](https://github.com/WordPress/gutenberg/tree/HEAD/packages/scripts). These dependencies need to be updated together.


Updates `markdown-it` from 12.3.2 to 14.3.2
- [Changelog](https://github.com/markdown-it/markdown-it/blob/14.3.2/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@12.3.2...14.3.2)

Updates `@wordpress/scripts` from 35.0.0 to 36.0.0
- [Release notes](https://github.com/WordPress/gutenberg/releases)
- [Changelog](https://github.com/WordPress/gutenberg/blob/trunk/packages/scripts/CHANGELOG.md)
- [Commits](https://github.com/WordPress/gutenberg/commits/@wordpress/scripts@36.0.0/packages/scripts)

---
updated-dependencies:
- dependency-name: markdown-it
  dependency-version: 14.3.2
  dependency-type: indirect
- dependency-name: "@wordpress/scripts"
  dependency-version: 36.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(deps): make package-lock.json installable with npm 10

The lockfile from #777 was written by npm 11 (Node 24). npm 10.9 (Node 22, the version every shared wp-ci job uses) rejects it: npm ci fails with 'Missing: @emnapi/core@2.0.0-alpha.5 from lock file', so lint-js, lint-css, test-js, test-php and build would all fail before running anything.

Regenerated with npm 10.9.2 via npm install --package-lock-only. This adds the two missing @emnapi entries and restores the peer flags npm 10 writes. Verified npm ci --dry-run passes on both npm 10.9.2 (Node 22.14) and npm 11.6.2 (Node 24.12).

* chore(ai): sync primitives-php instructions with wp-primitives 2.0

npm install runs sync-ai (prepare hook), which regenerates the tracked .github/instructions/primitives-php.instructions.md from the installed framework. The committed copy predates AbstractAbility and AbstractFeature, so every fresh install left the tree dirty. Regenerated from the wp-primitives 2.0 candidate (#98 head) and corrected AGENTS.md, which claimed the file is absent until synced although it is committed for Copilot review.

* style(js): fix ESLint errors in configs, bin scripts and JS tests

246 errors were prettier formatting: these files used WordPress paren spacing while the resolved prettier (3.9.6, pulled in by @wordpress/eslint-plugin) enforces the standard style that src/ already follows. Fixed with eslint --fix.

Seven needed a manual change: optional catch binding for two unused catch variables, eslint-disable-next-line for three deliberate console.warn calls in webpack.config.js, a reflowed eslint.config.mjs docblock line that jsdoc parsed as an @WordPress tag, and moving the excludeDirs early return ahead of the fullPath assignment in scanDirectory (same behaviour, satisfies no-unused-vars-before-return). Jest suite still passes (35/35).

* build(lint): lint every project JS file, not only src/

lint:js only covered ./src, but the shared wp-ci lint-js job runs ESLint on every changed .js file in a PR. Root configs, bin/ scripts and tests/js were never linted locally and carried 253 errors, so any PR touching webpack.config.js, bin/* or a test would fail CI. eslint.config.mjs already ignores node_modules, vendor and assets/build.

* fix(phpcs): use element syntax for the I18n text_domain property

PHPCS printed a deprecation on every run: passing array values as a comma-separated string has been deprecated since PHP_CodeSniffer 3.3 and is removed in 4.0, so the text-domain check would break on the PHPCS 4 upgrade. Matches the rtcamp/wp-phpcs example ruleset. The init engine still finds and rewrites the elementary-theme token.

* fix(tests): enable WP_DEBUG in the wp-env tests environment

#725 moved test:php and pretest:php from the cli container to tests-cli. wp-env (11.7) defaults the tests environment to WP_DEBUG false, so the framework Logger stays silent there and LoggerTest fails twice (test_levels_write_label_prefix_message_and_context asserts WP_DEBUG, test_no_context_omits_the_json_segment finds an empty log). #725 merged without a CI run, so this was never caught.

Setting WP_DEBUG for the tests environment restores the behaviour the suite was written against. Verified on wp-env with PHP 8.2 and the latest core: 59 tests, 0 failures (was 2 failures).

* ci(auto-merge): only merge bot PRs after a green Test and Measure run

workflow_run fires on every completion, failures included, and neither job checked the conclusion. rtBot has been merging red Dependabot bumps into main: #783 (09-30) and #780 (09-20) merged with Lint CSS, Lint JS and JS unit tests failing.

- require workflow_run.conclusion == success, event == pull_request and a same-repository head before either job runs
- match on workflow_run.actor.login instead of the spoofable github.actor (zizmor bot-conditions)
- drop workflow-level write permissions and the unneeded checkout; gh gets the repo from GH_REPO and merges with GH_BOT_TOKEN (zizmor excessive-permissions, artipacked)
- group concurrency on the triggering branch; github.head_ref is empty for workflow_run, so every run shared one group and cancelled the others

actionlint clean; zizmor still reports dangerous-triggers for workflow_run itself, which is inherent to this pattern and mitigated because nothing from the PR is checked out or executed.

* ci(docs): build on main and v2, deploy only from the default branch

The Documentation workflow only ran for theme-elementary-v2 and only deployed from it. Once #692 lands v2 on main, docs changes on main would never build or deploy, and the docs site (still 404) would stay down. Builds now run for PRs and pushes on both branches; Pages deploys only from the repository default branch, so nothing changes until v2 is on main.

* docs(skills): describe lint/phpcs/full as the rtcamp/wp-phpcs standard

The setup skill said lint/phpcs/full uses vendor/rtcamp/wp-primitives/phpcs.xml.dist. The framework export-ignores that file (absent from dist installs), and it is the framework's internal config, not a consumer ruleset. Matches the wp-tooling fix that repoints the scaffold at rtCampWP-Basic from rtcamp/wp-phpcs.

* chore(node): pin .nvmrc to Node 22 to match shared CI and plugin-elementary

The theme pinned v24 (npm 11) while every shared wp-ci job installs Node 22 (npm 10), and the plugin skeleton pins 22. Following the theme's .nvmrc is how #777 produced an npm 11 lockfile that npm 10 rejects. npm 10 lockfiles install cleanly on npm 11, so 22 keeps local and CI on one lockfile format.

* Chore(deps-dev): Bump brace-expansion from 1.1.12 to 1.1.21 (#784)

Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.12 to 1.1.21.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v1.1.12...v1.1.21)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* build(lint): keep Jest coverage output out of ESLint

lint:js runs wp-scripts lint-js on the whole project since e38e947, so after any coverage run (npm run test:js -- --coverage writes tests/logs) it also linted tests/logs/lcov-report/*.js and failed with 6 eslint-comments errors. That broke lint:js, lint:all, lint:js:fix and lint-staged in any clone that had run coverage. Ignore tests/logs (the configured coverageDirectory) and coverage (the Jest default).

* docs(skills): say lint/phpcs/full extends the strict rtCampWP standard

d9b0e0a described lint/phpcs/full as rtCampWP-Basic. wp-tooling golive/fixes (febd9e9) moved that scaffold to the strict rtCampWP standard, and this theme's own phpcs.xml.dist extends rtCampWP. Copy the wp-tooling setup skill row so both skills say the same thing.

* fix(scaffold): keep core FeaturesSettingsPage when removing example sets

Removing the settings example (also through --remove-examples) deleted all of inc/Modules/Settings, including the core FeaturesSettingsPage that inc/Main.php registers outside the example markers. The generated theme failed PHPStan with class.notFound for Modules\Settings\FeaturesSettingsPage, and since the Loader instantiates every Main::CLASSES entry it would fatal on boot. That is David's documented init flow (docs/initialization.md).

The settings example now removes only ThemeOptions.php and its test. The block-extension example also removes its PHP and Jest tests, and the shortcode example also removes template-parts/author-bio.php, so a generated theme keeps no tests or templates for code it no longer has.

* test(js): cover webpack entry helpers and the media-text module

webpack.config.js also exports readAllFileEntries and toPort (same pattern as getComponentEntries; webpack only reads the config array) so the Jest suite can test them. Adds tests/js/media-text.test.js for the media-text frontend module.

* test(php): cover assets, features, settings, helpers and block extensions

Adds PHPUnit coverage for AbstractThemeFeature, the autoloader, Assets enqueueing, Util, ThemeOptions, MediaTextInteractive, AuthorBio, FeaturesSettingsPage, Features and ThemeSetup. The author-bio template assertion moves from TemplatesTest to AuthorBioTest, so removing the shortcode example removes it with the template.

Two cases are corrected against real WordPress: the text domain test reads the registry's protected custom_paths (WP_Textdomain_Registry has no has_custom_path()), and the settings test accepts the empty label and description defaults that register_setting() fills ('label' since WP 6.6). Dev VM: 101 tests, 267 assertions, 0 failures on PHP 8.2/WP 6.5 and PHP 8.4/WP 7.1; line coverage 34.98% to 88.48% (215/243).

* fix(scripts): keep npm run lint:all and npm test to the checks

lint:* also matched lint:all itself and every :fix, report and lint:staged script, and test:* started the Jest watcher, so neither aggregate behaved as a check. Both now list the check scripts.

* fix(dev-server): read port settings as whole numbers only

parseInt took 8888foo as 8888. BS_PORT and BLOCKS_DEV_SERVER_PORT now have to be all digits, so anything else falls back to the default; the toPort tests cover 8888foo, 30.5 and 0x10.

* fix(tailwind): put the entry's imports first and accept Tailwind at-rules

@import has to come before other rules, so @source moves after the imports. Stylelint now accepts the Tailwind v4 at-rules; the feature's entry file failed scss/at-rule-no-unknown and no-invalid-position-at-import-rule, and CI lints every file a pull request changes.

* fix(patterns): exit when a pattern file is loaded outside WordPress

footer, hidden-404, media-text-interactive and page-creation-pattern call WordPress functions, so a direct request fatals. They now exit before any output, after the pattern header.

* fix(graphify): report only an installed graphify

verify.sh looked for the interpreter through uv tool run, which installs graphify on demand, so it could report success on a machine without it. It now checks the installed uv tool environment only.

* chore(graph): regenerate the committed knowledge graph

The rename left graph.json with mixed identities: nodes pointed at primitives-php.instructions.md while their ids and edge endpoints still said instructions_framework_php_instructions. Regenerated with graphify update . and graphify cluster-only . --no-label --no-viz (tree-sitter only, graphify 0.9.73). No old ids or machine-specific paths remain; the graph now also covers the code and tests added since June (754 to 999 nodes).

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: rtBot <43742164+rtBot@users.noreply.github.com>
Co-authored-by: Immanuel Raj <iamimmanuelraj@gmail.com>
Co-authored-by: Aditya Singh <adityasinghboss1234@gmail.com>
composer.json requires rtcamp/wp-primitives ^2.0, but composer.lock still
locked rtcamp/wp-framework v1.0.1, so composer install failed with
"Required package rtcamp/wp-primitives is not present in the lock file".
chore(deps): lock rtcamp/wp-primitives v2.0.0
chore: use the published @rtCamp and rtcamp packages, rename to rtcamp/theme-elementary
aryanjasala and others added 2 commits October 2, 2026 02:22
* Chore(deps): Bump tmp from 0.2.5 to 0.2.7 (#694)

Bumps [tmp](https://github.com/raszi/node-tmp) from 0.2.5 to 0.2.7.
- [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md)
- [Commits](raszi/node-tmp@v0.2.5...v0.2.7)

---
updated-dependencies:
- dependency-name: tmp
  dependency-version: 0.2.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump shell-quote from 1.8.3 to 1.8.4 (#711)

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.3 to 1.8.4.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](ljharb/shell-quote@v1.8.3...v1.8.4)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.8.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump launch-editor from 2.13.1 to 2.14.1 (#723)

Bumps [launch-editor](https://github.com/vitejs/launch-editor) from 2.13.1 to 2.14.1.
- [Commits](vitejs/launch-editor@v2.13.1...v2.14.1)

---
updated-dependencies:
- dependency-name: launch-editor
  dependency-version: 2.14.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump form-data from 4.0.5 to 4.0.6 (#722)

Bumps [form-data](https://github.com/form-data/form-data) from 4.0.5 to 4.0.6.
- [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md)
- [Commits](form-data/form-data@v4.0.5...v4.0.6)

---
updated-dependencies:
- dependency-name: form-data
  dependency-version: 4.0.6
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump @babel/core from 7.29.0 to 7.29.6 (#724)

Bumps [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) from 7.29.0 to 7.29.6.
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.29.6/packages/babel-core)

---
updated-dependencies:
- dependency-name: "@babel/core"
  dependency-version: 7.29.6
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump ws and @wp-playground/cli (#735)

Bumps [ws](https://github.com/websockets/ws) and [@wp-playground/cli](https://github.com/WordPress/wordpress-playground). These dependencies needed to be updated together.

Updates `ws` from 8.18.3 to 8.21.1
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.18.3...8.21.1)

Updates `ws` from 8.19.0 to 8.21.1
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.18.3...8.21.1)

Updates `ws` from 7.5.10 to 7.5.12
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.18.3...8.21.1)

Updates `@wp-playground/cli` from 3.1.3 to 3.1.44
- [Release notes](https://github.com/WordPress/wordpress-playground/releases)
- [Changelog](https://github.com/WordPress/wordpress-playground/blob/trunk/CHANGELOG.md)
- [Commits](WordPress/wordpress-playground@v3.1.3...v3.1.44)

---
updated-dependencies:
- dependency-name: ws
  dependency-version: 8.21.1
  dependency-type: indirect
- dependency-name: ws
  dependency-version: 8.21.1
  dependency-type: indirect
- dependency-name: ws
  dependency-version: 7.5.12
  dependency-type: indirect
- dependency-name: "@wp-playground/cli"
  dependency-version: 3.1.44
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump websocket-driver from 0.7.4 to 0.7.5 (#738)

Bumps [websocket-driver](https://github.com/faye/websocket-driver-node) from 0.7.4 to 0.7.5.
- [Changelog](https://github.com/faye/websocket-driver-node/blob/main/CHANGELOG.md)
- [Commits](faye/websocket-driver-node@0.7.4...0.7.5)

---
updated-dependencies:
- dependency-name: websocket-driver
  dependency-version: 0.7.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump svgo (#740)

Bumps  and [svgo](https://github.com/svg/svgo). These dependencies needed to be updated together.

Updates `svgo` from 3.3.3 to 3.3.4
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v3.3.3...v3.3.4)

Updates `svgo` from 4.0.1 to 4.0.2
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v3.3.3...v3.3.4)

---
updated-dependencies:
- dependency-name: svgo
  dependency-version: 3.3.4
  dependency-type: indirect
- dependency-name: svgo
  dependency-version: 4.0.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump shell-quote from 1.8.4 to 1.10.0 (#742)

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.4 to 1.10.0.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](ljharb/shell-quote@v1.8.4...v1.10.0)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.10.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump immutable from 5.1.5 to 5.1.9 (#745)

Bumps [immutable](https://github.com/immutable-js/immutable-js) from 5.1.5 to 5.1.9.
- [Release notes](https://github.com/immutable-js/immutable-js/releases)
- [Changelog](https://github.com/immutable-js/immutable-js/blob/main/CHANGELOG.md)
- [Commits](immutable-js/immutable-js@v5.1.5...v5.1.9)

---
updated-dependencies:
- dependency-name: immutable
  dependency-version: 5.1.9
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump fast-xml-parser from 5.10.0 to 5.10.1 (#741)

Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) from 5.10.0 to 5.10.1.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-parser@v5.10.0...v5.10.1)

---
updated-dependencies:
- dependency-name: fast-xml-parser
  dependency-version: 5.10.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump fast-uri from 3.1.3 to 3.1.4 (#743)

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.3 to 3.1.4.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.3...v3.1.4)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump postcss from 8.5.10 to 8.5.22 (#744)

Bumps [postcss](https://github.com/postcss/postcss) from 8.5.10 to 8.5.22.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.10...8.5.22)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.22
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump fast-uri from 3.1.4 to 3.1.5 (#754)

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.4 to 3.1.5.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.4...v3.1.5)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump postcss from 8.5.22 to 8.5.25 (#755)

Bumps [postcss](https://github.com/postcss/postcss) from 8.5.22 to 8.5.25.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.22...8.5.25)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.25
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Run Copilot code review on GitHub-hosted runners

* Chore(deps): Bump postcss-selector-parser (#760)

Bumps  and [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser). These dependencies needed to be updated together.

Updates `postcss-selector-parser` from 7.1.1 to 7.1.5
- [Release notes](https://github.com/postcss/postcss-selector-parser/releases)
- [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss-selector-parser@v7.1.1...7.1.5)

Updates `postcss-selector-parser` from 6.1.2 to 6.1.4
- [Release notes](https://github.com/postcss/postcss-selector-parser/releases)
- [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss-selector-parser@v7.1.1...7.1.5)

---
updated-dependencies:
- dependency-name: postcss-selector-parser
  dependency-version: 7.1.5
  dependency-type: indirect
- dependency-name: postcss-selector-parser
  dependency-version: 6.1.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump fast-uri from 3.1.5 to 3.1.7 (#762)

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.7.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.5...v3.1.7)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump @humanfs/node from 0.16.7 to 0.16.8 (#763)

Bumps [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) from 0.16.7 to 0.16.8.
- [Release notes](https://github.com/humanwhocodes/humanfs/releases)
- [Changelog](https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md)
- [Commits](https://github.com/humanwhocodes/humanfs/commits/node-v0.16.8/packages/node)

---
updated-dependencies:
- dependency-name: "@humanfs/node"
  dependency-version: 0.16.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump joi from 18.0.2 to 18.2.8 (#764)

Bumps [joi](https://github.com/hapijs/joi) from 18.0.2 to 18.2.8.
- [Commits](hapijs/joi@v18.0.2...v18.2.8)

---
updated-dependencies:
- dependency-name: joi
  dependency-version: 18.2.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump baseline-browser-mapping from 2.10.0 to 2.11.21 (#767)

Bumps [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) from 2.10.0 to 2.11.21.
- [Release notes](https://github.com/web-platform-dx/baseline-browser-mapping/releases)
- [Commits](web-platform-dx/baseline-browser-mapping@v2.10.0...v2.11.21)

---
updated-dependencies:
- dependency-name: baseline-browser-mapping
  dependency-version: 2.11.21
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump svgo (#765)

Bumps  and [svgo](https://github.com/svg/svgo). These dependencies needed to be updated together.

Updates `svgo` from 3.3.4 to 3.3.5
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v3.3.4...v3.3.5)

Updates `svgo` from 4.0.2 to 4.1.0
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v3.3.4...v3.3.5)

---
updated-dependencies:
- dependency-name: svgo
  dependency-version: 3.3.5
  dependency-type: indirect
- dependency-name: svgo
  dependency-version: 4.1.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump js-yaml (#766)

Bumps  and [js-yaml](https://github.com/nodeca/js-yaml). These dependencies needed to be updated together.

Updates `js-yaml` from 3.14.2 to 3.15.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md)
- [Commits](nodeca/js-yaml@3.14.2...3.15.2)

Updates `js-yaml` from 4.1.1 to 4.3.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md)
- [Commits](nodeca/js-yaml@3.14.2...3.15.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 3.15.2
  dependency-type: indirect
- dependency-name: js-yaml
  dependency-version: 4.3.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump adm-zip and @wordpress/scripts (#780)

Bumps [adm-zip](https://github.com/cthackers/adm-zip) to 0.6.1 and updates ancestor dependency [@wordpress/scripts](https://github.com/WordPress/gutenberg/tree/HEAD/packages/scripts). These dependencies need to be updated together.


Updates `adm-zip` from 0.5.16 to 0.6.1
- [Release notes](https://github.com/cthackers/adm-zip/releases)
- [Changelog](https://github.com/cthackers/adm-zip/blob/master/history.md)
- [Commits](cthackers/adm-zip@v0.5.16...v0.6.1)

Updates `@wordpress/scripts` from 31.5.0 to 35.0.0
- [Release notes](https://github.com/WordPress/gutenberg/releases)
- [Changelog](https://github.com/WordPress/gutenberg/blob/trunk/packages/scripts/CHANGELOG.md)
- [Commits](https://github.com/WordPress/gutenberg/commits/@wordpress/scripts@35.0.0/packages/scripts)

---
updated-dependencies:
- dependency-name: adm-zip
  dependency-version: 0.6.1
  dependency-type: indirect
- dependency-name: "@wordpress/scripts"
  dependency-version: 35.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump markdown-it and @wordpress/scripts (#783)

Bumps [markdown-it](https://github.com/markdown-it/markdown-it) to 14.3.2 and updates ancestor dependency [@wordpress/scripts](https://github.com/WordPress/gutenberg/tree/HEAD/packages/scripts). These dependencies need to be updated together.


Updates `markdown-it` from 12.3.2 to 14.3.2
- [Changelog](https://github.com/markdown-it/markdown-it/blob/14.3.2/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@12.3.2...14.3.2)

Updates `@wordpress/scripts` from 35.0.0 to 36.0.0
- [Release notes](https://github.com/WordPress/gutenberg/releases)
- [Changelog](https://github.com/WordPress/gutenberg/blob/trunk/packages/scripts/CHANGELOG.md)
- [Commits](https://github.com/WordPress/gutenberg/commits/@wordpress/scripts@36.0.0/packages/scripts)

---
updated-dependencies:
- dependency-name: markdown-it
  dependency-version: 14.3.2
  dependency-type: indirect
- dependency-name: "@wordpress/scripts"
  dependency-version: 36.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump brace-expansion from 1.1.12 to 1.1.21 (#784)

Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.12 to 1.1.21.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v1.1.12...v1.1.21)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(deps): clear every npm security advisory

npm audit reported 93 vulnerabilities (62 high) on v2. Now 0.

- @wordpress/scripts 32.3.0 -> 35.0.0, the first release whose e2e
  tooling no longer pulls in extract-zip, which has no patched version.
  @wordpress/jest-preset-default 12.47.0 -> 14.2.0 to match (Jest 30).
- @wordpress/env 11.7.0 -> 11.16.0 (drops extract-zip),
  @wordpress/babel-preset-default 8.47.0 -> 8.56.0, browserslist 4.28.2 ->
  4.29.3, svgo 4.0.1 -> 4.1.0.
- overrides, for fixes the parents' ranges do not reach:
  webpack-dev-server 6.0.0 (no patched 5.x; was pinned to 5.2.1),
  serialize-javascript 7.1.2 (was 7.0.3), minimatch 3.1.5 for v3 consumers
  only (was 3.1.3 for every consumer), qs 6.16.0, markdownlint-cli 0.49.1
  and js-yaml 5.4.2 for its v5 consumers.
- webpack.blocks.config.js and docs/hmr.md no longer say the dev server is
  v5; the proxy workaround still applies to v6.

* test(js): assert the duplicate-entry warning with jest-console

@wordpress/jest-console 9 (via jest-preset-default 14) fails any test that
calls console.warn unless the test expects it through its own matchers, so
spying on console.warn no longer works. Use toHaveWarnedWith with the exact
message.

* fix(deps): update squizlabs/php_codesniffer to 3.13.6

3.13.5 is affected by CVE-2026-67434 (OS command injection,
GHSA-hmqg-cxww-wqhq).

* build(deps): match plugin-elementary's security setup

Follows rtCamp/plugin-elementary#28 and #29 so both starters stay on the
same toolchain:

- @wordpress/scripts 36.0.0 instead of 35.0.0. 36 runs Vitest for
  test-unit-js and drops the bundled Jest preset, Babel transform and
  GitHub Actions reporter, so test:js uses wp-scripts test-unit-jest, jest
  and jest-environment-jsdom 30.5.0 are direct dev dependencies,
  @wordpress/jest-preset-default is removed, and tests/js/jest.config.js
  sets up jsdom, test discovery and a style mock itself.
- webpack-dev-server stays on 5.x at 5.2.6, which is patched; only its
  sockjs > uuid dependency needed an override. This reverts the 6.0.0
  override and the doc and comment changes that went with it.
- Overrides are scoped to the parent that pins the old version (express >
  qs, markdownlint-cli > js-yaml, copy-webpack-plugin >
  serialize-javascript, sockjs > uuid, @wordpress/scripts > adm-zip)
  instead of applying everywhere.
- The duplicate-entry test goes back to spying on console.warn, since
  @wordpress/jest-console no longer loads without the preset.

npm audit still reports 0 vulnerabilities.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: rtBot <43742164+rtBot@users.noreply.github.com>
Co-authored-by: Immanuel Raj <iamimmanuelraj@gmail.com>
#790 was squash-merged, which dropped the earlier sync's link to main, so
#692 conflicted again. main only changed package.json and package-lock.json
(v1 Dependabot bumps, superseded by v2's dependencies) and
copilot-code-review.yml (identical on v2), so the tree stays exactly as v2
has it.
aryanjasala and others added 2 commits October 2, 2026 02:26
* Chore(deps): Bump tmp from 0.2.5 to 0.2.7 (#694)

Bumps [tmp](https://github.com/raszi/node-tmp) from 0.2.5 to 0.2.7.
- [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md)
- [Commits](raszi/node-tmp@v0.2.5...v0.2.7)

---
updated-dependencies:
- dependency-name: tmp
  dependency-version: 0.2.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump shell-quote from 1.8.3 to 1.8.4 (#711)

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.3 to 1.8.4.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](ljharb/shell-quote@v1.8.3...v1.8.4)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.8.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump launch-editor from 2.13.1 to 2.14.1 (#723)

Bumps [launch-editor](https://github.com/vitejs/launch-editor) from 2.13.1 to 2.14.1.
- [Commits](vitejs/launch-editor@v2.13.1...v2.14.1)

---
updated-dependencies:
- dependency-name: launch-editor
  dependency-version: 2.14.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump form-data from 4.0.5 to 4.0.6 (#722)

Bumps [form-data](https://github.com/form-data/form-data) from 4.0.5 to 4.0.6.
- [Changelog](https://github.com/form-data/form-data/blob/master/CHANGELOG.md)
- [Commits](form-data/form-data@v4.0.5...v4.0.6)

---
updated-dependencies:
- dependency-name: form-data
  dependency-version: 4.0.6
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump @babel/core from 7.29.0 to 7.29.6 (#724)

Bumps [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) from 7.29.0 to 7.29.6.
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.29.6/packages/babel-core)

---
updated-dependencies:
- dependency-name: "@babel/core"
  dependency-version: 7.29.6
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump ws and @wp-playground/cli (#735)

Bumps [ws](https://github.com/websockets/ws) and [@wp-playground/cli](https://github.com/WordPress/wordpress-playground). These dependencies needed to be updated together.

Updates `ws` from 8.18.3 to 8.21.1
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.18.3...8.21.1)

Updates `ws` from 8.19.0 to 8.21.1
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.18.3...8.21.1)

Updates `ws` from 7.5.10 to 7.5.12
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.18.3...8.21.1)

Updates `@wp-playground/cli` from 3.1.3 to 3.1.44
- [Release notes](https://github.com/WordPress/wordpress-playground/releases)
- [Changelog](https://github.com/WordPress/wordpress-playground/blob/trunk/CHANGELOG.md)
- [Commits](WordPress/wordpress-playground@v3.1.3...v3.1.44)

---
updated-dependencies:
- dependency-name: ws
  dependency-version: 8.21.1
  dependency-type: indirect
- dependency-name: ws
  dependency-version: 8.21.1
  dependency-type: indirect
- dependency-name: ws
  dependency-version: 7.5.12
  dependency-type: indirect
- dependency-name: "@wp-playground/cli"
  dependency-version: 3.1.44
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump websocket-driver from 0.7.4 to 0.7.5 (#738)

Bumps [websocket-driver](https://github.com/faye/websocket-driver-node) from 0.7.4 to 0.7.5.
- [Changelog](https://github.com/faye/websocket-driver-node/blob/main/CHANGELOG.md)
- [Commits](faye/websocket-driver-node@0.7.4...0.7.5)

---
updated-dependencies:
- dependency-name: websocket-driver
  dependency-version: 0.7.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump svgo (#740)

Bumps  and [svgo](https://github.com/svg/svgo). These dependencies needed to be updated together.

Updates `svgo` from 3.3.3 to 3.3.4
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v3.3.3...v3.3.4)

Updates `svgo` from 4.0.1 to 4.0.2
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v3.3.3...v3.3.4)

---
updated-dependencies:
- dependency-name: svgo
  dependency-version: 3.3.4
  dependency-type: indirect
- dependency-name: svgo
  dependency-version: 4.0.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump shell-quote from 1.8.4 to 1.10.0 (#742)

Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.4 to 1.10.0.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](ljharb/shell-quote@v1.8.4...v1.10.0)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.10.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump immutable from 5.1.5 to 5.1.9 (#745)

Bumps [immutable](https://github.com/immutable-js/immutable-js) from 5.1.5 to 5.1.9.
- [Release notes](https://github.com/immutable-js/immutable-js/releases)
- [Changelog](https://github.com/immutable-js/immutable-js/blob/main/CHANGELOG.md)
- [Commits](immutable-js/immutable-js@v5.1.5...v5.1.9)

---
updated-dependencies:
- dependency-name: immutable
  dependency-version: 5.1.9
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump fast-xml-parser from 5.10.0 to 5.10.1 (#741)

Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) from 5.10.0 to 5.10.1.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-parser@v5.10.0...v5.10.1)

---
updated-dependencies:
- dependency-name: fast-xml-parser
  dependency-version: 5.10.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump fast-uri from 3.1.3 to 3.1.4 (#743)

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.3 to 3.1.4.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.3...v3.1.4)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump postcss from 8.5.10 to 8.5.22 (#744)

Bumps [postcss](https://github.com/postcss/postcss) from 8.5.10 to 8.5.22.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.10...8.5.22)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.22
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump fast-uri from 3.1.4 to 3.1.5 (#754)

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.4 to 3.1.5.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.4...v3.1.5)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump postcss from 8.5.22 to 8.5.25 (#755)

Bumps [postcss](https://github.com/postcss/postcss) from 8.5.22 to 8.5.25.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.22...8.5.25)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.25
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Run Copilot code review on GitHub-hosted runners

* Chore(deps): Bump postcss-selector-parser (#760)

Bumps  and [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser). These dependencies needed to be updated together.

Updates `postcss-selector-parser` from 7.1.1 to 7.1.5
- [Release notes](https://github.com/postcss/postcss-selector-parser/releases)
- [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss-selector-parser@v7.1.1...7.1.5)

Updates `postcss-selector-parser` from 6.1.2 to 6.1.4
- [Release notes](https://github.com/postcss/postcss-selector-parser/releases)
- [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss-selector-parser@v7.1.1...7.1.5)

---
updated-dependencies:
- dependency-name: postcss-selector-parser
  dependency-version: 7.1.5
  dependency-type: indirect
- dependency-name: postcss-selector-parser
  dependency-version: 6.1.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump fast-uri from 3.1.5 to 3.1.7 (#762)

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.7.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.5...v3.1.7)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump @humanfs/node from 0.16.7 to 0.16.8 (#763)

Bumps [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node) from 0.16.7 to 0.16.8.
- [Release notes](https://github.com/humanwhocodes/humanfs/releases)
- [Changelog](https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md)
- [Commits](https://github.com/humanwhocodes/humanfs/commits/node-v0.16.8/packages/node)

---
updated-dependencies:
- dependency-name: "@humanfs/node"
  dependency-version: 0.16.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump joi from 18.0.2 to 18.2.8 (#764)

Bumps [joi](https://github.com/hapijs/joi) from 18.0.2 to 18.2.8.
- [Commits](hapijs/joi@v18.0.2...v18.2.8)

---
updated-dependencies:
- dependency-name: joi
  dependency-version: 18.2.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump baseline-browser-mapping from 2.10.0 to 2.11.21 (#767)

Bumps [baseline-browser-mapping](https://github.com/web-platform-dx/baseline-browser-mapping) from 2.10.0 to 2.11.21.
- [Release notes](https://github.com/web-platform-dx/baseline-browser-mapping/releases)
- [Commits](web-platform-dx/baseline-browser-mapping@v2.10.0...v2.11.21)

---
updated-dependencies:
- dependency-name: baseline-browser-mapping
  dependency-version: 2.11.21
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump svgo (#765)

Bumps  and [svgo](https://github.com/svg/svgo). These dependencies needed to be updated together.

Updates `svgo` from 3.3.4 to 3.3.5
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v3.3.4...v3.3.5)

Updates `svgo` from 4.0.2 to 4.1.0
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v3.3.4...v3.3.5)

---
updated-dependencies:
- dependency-name: svgo
  dependency-version: 3.3.5
  dependency-type: indirect
- dependency-name: svgo
  dependency-version: 4.1.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump js-yaml (#766)

Bumps  and [js-yaml](https://github.com/nodeca/js-yaml). These dependencies needed to be updated together.

Updates `js-yaml` from 3.14.2 to 3.15.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md)
- [Commits](nodeca/js-yaml@3.14.2...3.15.2)

Updates `js-yaml` from 4.1.1 to 4.3.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/3.15.2/CHANGELOG.md)
- [Commits](nodeca/js-yaml@3.14.2...3.15.2)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 3.15.2
  dependency-type: indirect
- dependency-name: js-yaml
  dependency-version: 4.3.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump adm-zip and @wordpress/scripts (#780)

Bumps [adm-zip](https://github.com/cthackers/adm-zip) to 0.6.1 and updates ancestor dependency [@wordpress/scripts](https://github.com/WordPress/gutenberg/tree/HEAD/packages/scripts). These dependencies need to be updated together.


Updates `adm-zip` from 0.5.16 to 0.6.1
- [Release notes](https://github.com/cthackers/adm-zip/releases)
- [Changelog](https://github.com/cthackers/adm-zip/blob/master/history.md)
- [Commits](cthackers/adm-zip@v0.5.16...v0.6.1)

Updates `@wordpress/scripts` from 31.5.0 to 35.0.0
- [Release notes](https://github.com/WordPress/gutenberg/releases)
- [Changelog](https://github.com/WordPress/gutenberg/blob/trunk/packages/scripts/CHANGELOG.md)
- [Commits](https://github.com/WordPress/gutenberg/commits/@wordpress/scripts@35.0.0/packages/scripts)

---
updated-dependencies:
- dependency-name: adm-zip
  dependency-version: 0.6.1
  dependency-type: indirect
- dependency-name: "@wordpress/scripts"
  dependency-version: 35.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps): Bump markdown-it and @wordpress/scripts (#783)

Bumps [markdown-it](https://github.com/markdown-it/markdown-it) to 14.3.2 and updates ancestor dependency [@wordpress/scripts](https://github.com/WordPress/gutenberg/tree/HEAD/packages/scripts). These dependencies need to be updated together.


Updates `markdown-it` from 12.3.2 to 14.3.2
- [Changelog](https://github.com/markdown-it/markdown-it/blob/14.3.2/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@12.3.2...14.3.2)

Updates `@wordpress/scripts` from 35.0.0 to 36.0.0
- [Release notes](https://github.com/WordPress/gutenberg/releases)
- [Changelog](https://github.com/WordPress/gutenberg/blob/trunk/packages/scripts/CHANGELOG.md)
- [Commits](https://github.com/WordPress/gutenberg/commits/@wordpress/scripts@36.0.0/packages/scripts)

---
updated-dependencies:
- dependency-name: markdown-it
  dependency-version: 14.3.2
  dependency-type: indirect
- dependency-name: "@wordpress/scripts"
  dependency-version: 36.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Chore(deps-dev): Bump brace-expansion from 1.1.12 to 1.1.21 (#784)

Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.12 to 1.1.21.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v1.1.12...v1.1.21)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix(deps): clear every npm security advisory

npm audit reported 93 vulnerabilities (62 high) on v2. Now 0.

- @wordpress/scripts 32.3.0 -> 35.0.0, the first release whose e2e
  tooling no longer pulls in extract-zip, which has no patched version.
  @wordpress/jest-preset-default 12.47.0 -> 14.2.0 to match (Jest 30).
- @wordpress/env 11.7.0 -> 11.16.0 (drops extract-zip),
  @wordpress/babel-preset-default 8.47.0 -> 8.56.0, browserslist 4.28.2 ->
  4.29.3, svgo 4.0.1 -> 4.1.0.
- overrides, for fixes the parents' ranges do not reach:
  webpack-dev-server 6.0.0 (no patched 5.x; was pinned to 5.2.1),
  serialize-javascript 7.1.2 (was 7.0.3), minimatch 3.1.5 for v3 consumers
  only (was 3.1.3 for every consumer), qs 6.16.0, markdownlint-cli 0.49.1
  and js-yaml 5.4.2 for its v5 consumers.
- webpack.blocks.config.js and docs/hmr.md no longer say the dev server is
  v5; the proxy workaround still applies to v6.

* test(js): assert the duplicate-entry warning with jest-console

@wordpress/jest-console 9 (via jest-preset-default 14) fails any test that
calls console.warn unless the test expects it through its own matchers, so
spying on console.warn no longer works. Use toHaveWarnedWith with the exact
message.

* fix(deps): update squizlabs/php_codesniffer to 3.13.6

3.13.5 is affected by CVE-2026-67434 (OS command injection,
GHSA-hmqg-cxww-wqhq).

* build(deps): match plugin-elementary's security setup

Follows rtCamp/plugin-elementary#28 and #29 so both starters stay on the
same toolchain:

- @wordpress/scripts 36.0.0 instead of 35.0.0. 36 runs Vitest for
  test-unit-js and drops the bundled Jest preset, Babel transform and
  GitHub Actions reporter, so test:js uses wp-scripts test-unit-jest, jest
  and jest-environment-jsdom 30.5.0 are direct dev dependencies,
  @wordpress/jest-preset-default is removed, and tests/js/jest.config.js
  sets up jsdom, test discovery and a style mock itself.
- webpack-dev-server stays on 5.x at 5.2.6, which is patched; only its
  sockjs > uuid dependency needed an override. This reverts the 6.0.0
  override and the doc and comment changes that went with it.
- Overrides are scoped to the parent that pins the old version (express >
  qs, markdownlint-cli > js-yaml, copy-webpack-plugin >
  serialize-javascript, sockjs > uuid, @wordpress/scripts > adm-zip)
  instead of applying everywhere.
- The duplicate-entry test goes back to spying on console.warn, since
  @wordpress/jest-console no longer loads without the preset.

npm audit still reports 0 vulnerabilities.

* test(php): run PHPUnit in a separate wp-env config

wp-env 11.16 deprecates the env.tests block and the automatic tests
environment. The replacement it documents is a second config file, so
.wp-env.tests.json defines the test environment (port 5891, its own
containers and database, WP_DEBUG on), and .wp-env.json sets
testsEnvironment to false. pretest:php starts that environment and
test:php runs PHPUnit in its cli container.

A second config, not the development environment's cli container: wp-env's
wp-tests-config.php there uses the site's database and wp_ prefix, so the
suite would wipe the development site's content.

CI keeps working unchanged: WP_ENV_PHP_VERSION and WP_ENV_CORE apply to the
test environment too. The docs drop the test-only WP_DEBUG override, which
the committed test config now covers.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: rtBot <43742164+rtBot@users.noreply.github.com>
Co-authored-by: Immanuel Raj <iamimmanuelraj@gmail.com>
chore: merge main into theme-elementary-v2 (merge commit only)
@aryanjasala
aryanjasala marked this pull request as ready for review October 1, 2026 20:59
@aryanjasala aryanjasala changed the title release: theme-elementary v2 release: theme-elementary v2 🚀 Oct 1, 2026
wp-shared-workflows is tagged v1.0.0, and @v1 moves forward to compatible
v1.x releases. It carries the changed-files linting fix that #692's Lint PHP
job needs, and its wp-ci.yml takes every input this caller passes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants