Skip to content

build(deps): bump shiki from 3.23.0 to 4.3.1 - #58

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/shiki-4.3.1
Open

build(deps): bump shiki from 3.23.0 to 4.3.1#58
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/shiki-4.3.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 10, 2026

Copy link
Copy Markdown
Contributor

Bumps shiki from 3.23.0 to 4.3.1.

Release notes

Sourced from shiki's releases.

v4.3.1

   🚀 Features

    View changes on GitHub

v4.3.0

   🚀 Features

    View changes on GitHub

v4.2.0

   🚀 Features

   🐞 Bug Fixes

    View changes on GitHub

v4.1.0

   🐞 Bug Fixes

    View changes on GitHub

v4.0.2

   🐞 Bug Fixes

    View changes on GitHub

v4.0.1

   🐞 Bug Fixes

    View changes on GitHub

v4.0.0

   🚨 Breaking Changes

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 10, 2026
@vercel

vercel Bot commented Jul 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
open-chat Ignored Ignored Jul 20, 2026 3:46pm

@ajanraj

ajanraj commented Jul 11, 2026

Copy link
Copy Markdown
Owner

Dependency review: holding this PR for bundle/PWA impact.\n\nWhy not merged:\n- Direct API usage is Shiki v4-compatible, and Node 24 meets its runtime requirement.\n- However, @streamdown/code currently requires Shiki v3. The lockfile therefore includes full Shiki v4 and a nested full Shiki v3.\n- CI build comparison showed the PWA precache growing from 18,717.87 KiB to 27,955.75 KiB: +9,237.88 KiB / 49.4%, with entries increasing from 700 to 1001.\n- Format, lint, typecheck, 1,112 tests, build, and audit otherwise passed.\n\nNext steps:\n1. Upgrade @streamdown/code/Streamdown to a Shiki v4-compatible release, or remove the separate direct Shiki dependency.\n2. Regenerate bun.lock.\n3. Re-run CI and compare bundle/precache output.\n4. Merge once the duplicate Shiki payload is gone, or explicitly accept the added ~9 MiB offline payload.

Bumps [shiki](https://github.com/shikijs/shiki/tree/HEAD/packages/shiki) from 3.23.0 to 4.3.1.
- [Release notes](https://github.com/shikijs/shiki/releases)
- [Commits](https://github.com/shikijs/shiki/commits/v4.3.1/packages/shiki)

---
updated-dependencies:
- dependency-name: shiki
  dependency-version: 4.3.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/bun/shiki-4.3.1 branch from 576b548 to 9ed296d Compare July 20, 2026 15:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant