* main: (39 commits)
@uppy/components: add imageThumbnail prop to FilesList/FilesGrid (#5985)
Remove already published changesets
Revert "[ci] release (#5973)"
Revert "build(deps): bump actions/setup-node from 4 to 5" (#5986)
[ci] release (#5973)
build(deps): bump devalue from 5.1.1 to 5.3.2 (#5937)
build(deps): bump brace-expansion from 1.1.11 to 1.1.12 (#5820)
build(deps): bump docker/metadata-action from 5.7.0 to 5.8.0 (#5870)
build(deps-dev): bump vite from 6.3.5 to 6.3.6 (#5972)
build(deps): bump actions/setup-node from 4 to 5 (#5954)
add typescript as a dev dep in stackblitz env (#5976)
add back "main" in uppy bundle (#5975)
add back framework wrappers for @uppy/status-bar (#5948)
@uppy/components: fix dropzone global id (#5967)
Update translations for pl_PL.ts (#5969)
Dot no crash process in upload-to-cdn if version already exists
[ci] release (#5939)
Optmize Stackblitz install times (#5968)
Fix changeset
Export UppyContext and UppyContextSymbol (#5966)
...
Reverts transloadit/uppy#5954
because it fails the release
```
/usr/local/bin/yarn cache dir
error Error: Failed to replace env in config: ${NPM_TOKEN}
at /usr/local/lib/node_modules/yarn/lib/cli.js:95453:13
at String.replace (<anonymous>)
at envReplace (/usr/local/lib/node_modules/yarn/lib/cli.js:95448:16)
at Function.normalizeConfig (/usr/local/lib/node_modules/yarn/lib/cli.js:31940:69)
at NpmRegistry.<anonymous> (/usr/local/lib/node_modules/yarn/lib/cli.js:31970:34)
at Generator.next (<anonymous>)
at step (/usr/local/lib/node_modules/yarn/lib/cli.js:310:30)
at /usr/local/lib/node_modules/yarn/lib/cli.js:321:13
info Visit https://yarnpkg.com/en/docs/cli/cache for documentation about this command.
Error: error Error: Failed to replace env in config: ${NPM_TOKEN}
at /usr/local/lib/node_modules/yarn/lib/cli.js:95453:13
at String.replace (<anonymous>)
at envReplace (/usr/local/lib/node_modules/yarn/lib/cli.js:95448:16)
at Function.normalizeConfig (/usr/local/lib/node_modules/yarn/lib/cli.js:31940:69)
at NpmRegistry.<anonymous> (/usr/local/lib/node_modules/yarn/lib/cli.js:31970:34)
at Generator.next (<anonymous>)
at step (/usr/local/lib/node_modules/yarn/lib/cli.js:310:30)
at /usr/local/lib/node_modules/yarn/lib/cli.js:321:13
```
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.
# Releases
## @uppy/angular@1.1.0
### Minor Changes
- 92a0a0d: Add back framework wrappers for @uppy/status-bar plugin
## @uppy/react@5.1.0
### Minor Changes
- 92a0a0d: Add back framework wrappers for @uppy/status-bar plugin
### Patch Changes
- Updated dependencies [d6b3aa5]
- @uppy/components@1.0.3
## @uppy/svelte@5.1.0
### Minor Changes
- 92a0a0d: Add back framework wrappers for @uppy/status-bar plugin
### Patch Changes
- Updated dependencies [d6b3aa5]
- @uppy/components@1.0.3
## @uppy/vue@3.1.0
### Minor Changes
- 92a0a0d: Add back framework wrappers for @uppy/status-bar plugin
### Patch Changes
- Updated dependencies [d6b3aa5]
- @uppy/components@1.0.3
## @uppy/components@1.0.3
### Patch Changes
- d6b3aa5: fix dom ID conflicts in dropzone and file-input
## @uppy/locales@5.0.1
### Patch Changes
- 48cfa09: Update translations for pl_PL.ts
## uppy@5.1.3
### Patch Changes
- ce0c9d6: Put "main" back in package.json
- Updated dependencies [48cfa09]
- @uppy/locales@5.0.1
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Bumps [devalue](https://github.com/sveltejs/devalue) from 5.1.1 to
5.3.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/sveltejs/devalue/releases">devalue's
releases</a>.</em></p>
<blockquote>
<h2>v5.3.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>0623a47: fix: disallow array method access when parsing</li>
<li>0623a47: fix: disallow <code>__proto__</code> properties on
objects</li>
</ul>
<h2>v5.3.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>ae904c5: fix: correctly differentiate between +0 and -0</li>
</ul>
<h2>v5.3.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>2896e7b: feat: support Temporal</li>
<li>fec694d: feat: support <code>URL</code> and
<code>URLSearchParams</code> objects</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/sveltejs/devalue/blob/main/CHANGELOG.md">devalue's
changelog</a>.</em></p>
<blockquote>
<h2>5.3.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>0623a47: fix: disallow array method access when parsing</li>
<li>0623a47: fix: disallow <code>__proto__</code> properties on
objects</li>
</ul>
<h2>5.3.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>ae904c5: fix: correctly differentiate between +0 and -0</li>
</ul>
<h2>5.3.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>2896e7b: feat: support Temporal</li>
<li>fec694d: feat: support <code>URL</code> and
<code>URLSearchParams</code> objects</li>
</ul>
<h2>5.2.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>e46f4c8: fix: handle repeated array buffers and subarrays</li>
<li>2dfa504: fix: handle custom classes with null proto as pojo</li>
</ul>
<h2>5.2.0</h2>
<ul>
<li>Handle custom classes with null proto as pojo (<a
href="https://redirect.github.com/sveltejs/devalue/pull/95">#95</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="86a6a66d2c"><code>86a6a66</code></a>
Version Packages (<a
href="https://redirect.github.com/sveltejs/devalue/issues/109">#109</a>)</li>
<li><a
href="0623a47c95"><code>0623a47</code></a>
Merge commit from fork</li>
<li><a
href="02d20e8a79"><code>02d20e8</code></a>
Version Packages (<a
href="https://redirect.github.com/sveltejs/devalue/issues/108">#108</a>)</li>
<li><a
href="ae904c5b18"><code>ae904c5</code></a>
fix stringify not picking up negative zero if a normal zero has appeared
befo...</li>
<li><a
href="e95b87a6cc"><code>e95b87a</code></a>
fix pkg.repository</li>
<li><a
href="8300172d1d"><code>8300172</code></a>
fix changeset config</li>
<li><a
href="434d8aefb9"><code>434d8ae</code></a>
Version Packages (<a
href="https://redirect.github.com/sveltejs/devalue/issues/106">#106</a>)</li>
<li><a
href="67c8334b82"><code>67c8334</code></a>
mention support for URL/URLSearchParams/Temporal in README</li>
<li><a
href="fec694d87e"><code>fec694d</code></a>
feat: support URL and URLSearchParams (<a
href="https://redirect.github.com/sveltejs/devalue/issues/92">#92</a>)</li>
<li><a
href="2896e7bef2"><code>2896e7b</code></a>
Add support for Temporal objects (<a
href="https://redirect.github.com/sveltejs/devalue/issues/98">#98</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/sveltejs/devalue/compare/v5.1.1...v5.3.2">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~svelte-admin">svelte-admin</a>, a new
releaser for devalue since your current version.</p>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/transloadit/uppy/network/alerts).
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion)
from 1.1.11 to 1.1.12.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/juliangruber/brace-expansion/releases">brace-expansion's
releases</a>.</em></p>
<blockquote>
<h2>v1.1.12</h2>
<ul>
<li>pkg: publish on tag 1.x c460dbd</li>
<li>fmt ccb8ac6</li>
<li>Fix potential ReDoS Vulnerability or Inefficient Regular Expression
(<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/65">#65</a>)
c3c73c8</li>
</ul>
<hr />
<p><a
href="https://github.com/juliangruber/brace-expansion/compare/v1.1.11...v1.1.12">https://github.com/juliangruber/brace-expansion/compare/v1.1.11...v1.1.12</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="44f33b47c5"><code>44f33b4</code></a>
1.1.12</li>
<li><a
href="c460dbd68e"><code>c460dbd</code></a>
pkg: publish on tag 1.x</li>
<li><a
href="ccb8ac6d42"><code>ccb8ac6</code></a>
fmt</li>
<li><a
href="c3c73c8b08"><code>c3c73c8</code></a>
Fix potential ReDoS Vulnerability or Inefficient Regular Expression (<a
href="https://redirect.github.com/juliangruber/brace-expansion/issues/65">#65</a>)</li>
<li>See full diff in <a
href="https://github.com/juliangruber/brace-expansion/compare/1.1.11...v1.1.12">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
You can trigger a rebase of this PR by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/transloadit/uppy/network/alerts).
</details>
> **Note**
> Automatic rebases have been disabled on this pull request as it has
been open for over 30 days.
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
fixes#5946
Root Cause :
`createDropzone` used a single global `id` for the file input
(`'uppy-dropzone-file-input'`) Clicking any `<Dropzone />` did
`document.getElementById(<global-id>).click()`, which always targeted
the first input in the DOM, so files were added to the first Uppy
instance.
9bac4c8398/packages/%40uppy/components/src/hooks/dropzone.ts (L73-L77)
**Solutions :**
Simplest solution would have been to just make the input id unique per
Uppy instance using `ctx.uppy.getID()`, and click that specific input.
```typescript
const fileInputId = 'uppy-dropzone-file-input-' + ctx.uppy.getID()
```
**Caveats**:
If users don’t pass a custom id to `new Uppy()`, all instances default
to uppy, so ids still collide across instances.
Multiple Dropzones under one instance still share the same id.
Switched to a ref-based approach so clicks trigger the input directly,
without relying on `document.getElementById` lookups. It still falls
back to a DOM click for backward compatibility.
**StackBlitz Link :**
https://stackblitz.com/github/qxprakash/uppy/tree/debug_dropzone/examples/react?file=package.json&embed=1&view=editor&showSidebar=1&hideTerminal=1
**Update: Went for the ID based solution upon discussion with the team
as it's simpler.**
StackBlitz examples took **146+ seconds** to start due to heavy dev
dependencies
### Optimizations
- Eliminate heavy dev deps like `playwright (~200MB)` `@vitest/browser`
`vitest`
- Aggressive install flags: `--prefer-offline --reporter=silent
--ignore-scripts --no-optional`
- use pnpm
- Results **React example: 146s → ~25s (83% faster)**
- add example-nextjs and example-reactrouter to changeset ignore too
(examples aren't part of releases)
- also remove the salty-experts-yawn.md changeset because it's no longer
relevant
this should fix broken github actions build currently on `main`
see
https://github.com/transloadit/uppy/pull/5942#issuecomment-3282585747
---------
Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: mifi <402547+mifi@users.noreply.github.com>
Adds a stability warning comment to the top of all `src/style.scss`
files in the following Uppy packages to inform consumers that the source
code and variables are not part of the stable API:
- @uppy/audio
- @uppy/core
- @uppy/dashboard
- @uppy/drag-drop
- @uppy/drop-target
- @uppy/image-editor
- @uppy/provider-views
- @uppy/screen-capture
- @uppy/status-bar
- @uppy/url
- @uppy/webcam
The comment added is:
```scss
// NOTE TO CONSUMERS: The code and variables in these source files are not considered stable and can change at any time, even in minor and patch releases!
```
This warning helps clarify that while the compiled CSS output and public
APIs remain stable, the internal SCSS source files, variables, and
implementation details should not be relied upon by consumers as they
may change without notice in any release.
The changes are minimal and surgical - exactly one line added to the top
of each file with no other modifications to existing code.
<!-- START COPILOT CODING AGENT SUFFIX -->
*This pull request was created as a result of the following prompt from
Copilot chat.*
> Add the following comment at the very top of each src/style.scss file
in the following Uppy packages: @uppy/audio, @uppy/core,
@uppy/dashboard, @uppy/drag-drop, @uppy/drop-target, @uppy/image-editor,
@uppy/provider-views, @uppy/screen-capture, @uppy/status-bar, @uppy/url,
@uppy/webcam.
>
> Comment to add:
> // NOTE TO CONSUMERS: The code and variables in these source files are
not considered stable and can change at any time, even in minor and
patch releases!
>
> Ensure the comment is the first line in each file, above any existing
code or imports.
<!-- START COPILOT CODING AGENT TIPS -->
---
✨ Let Copilot coding agent [set things up for
you](https://github.com/transloadit/uppy/issues/new?title=✨+Set+up+Copilot+instructions&body=Configure%20instructions%20for%20this%20repository%20as%20documented%20in%20%5BBest%20practices%20for%20Copilot%20coding%20agent%20in%20your%20repository%5D%28https://gh.io/copilot-coding-agent-tips%29%2E%0A%0A%3COnboard%20this%20repo%3E&assignees=copilot)
— coding agent works faster and does higher quality work when set up for
your repo.
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: mifi <402547+mifi@users.noreply.github.com>
Co-authored-by: Prakash <qxprakash@gmail.com>
Co-authored-by: Mikael Finstad <finstaden@gmail.com>
Bumps [form-data](https://github.com/form-data/form-data) from 2.5.1 to
2.5.5.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/form-data/form-data/releases">form-data's
releases</a>.</em></p>
<blockquote>
<h2>v2.5.2</h2>
<h3>Fixes</h3>
<ul>
<li><code>Buffer.from</code> and <code>Buffer.alloc</code> require node
4+</li>
<li>npmignore temporary build files (<a
href="https://redirect.github.com/form-data/form-data/issues/532">#532</a>)</li>
<li>move util.isArray to Array.isArray (<a
href="https://redirect.github.com/form-data/form-data/issues/564">#564</a>)</li>
</ul>
<h3>Tests</h3>
<ul>
<li>migrate from travis to GHA</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/form-data/form-data/blob/v2.5.5/CHANGELOG.md">form-data's
changelog</a>.</em></p>
<blockquote>
<h2><a
href="https://github.com/form-data/form-data/compare/v2.5.4...v2.5.5">v2.5.5</a>
- 2025-07-18</h2>
<h3>Commits</h3>
<ul>
<li>[meta] actually ensure the readme backup isn’t published <a
href="10626c0a9b"><code>10626c0</code></a></li>
<li>[Fix] use proper dependency <a
href="026abe5c5c"><code>026abe5</code></a></li>
</ul>
<h2><a
href="https://github.com/form-data/form-data/compare/v2.5.3...v2.5.4">v2.5.4</a>
- 2025-07-17</h2>
<h3>Fixed</h3>
<ul>
<li>[Fix] <code>append</code>: avoid a crash on nullish values <a
href="https://redirect.github.com/form-data/form-data/issues/577"><code>[#577](https://github.com/form-data/form-data/issues/577)</code></a></li>
</ul>
<h3>Commits</h3>
<ul>
<li>[eslint] update linting config <a
href="8bf2492e05"><code>8bf2492</code></a></li>
<li>[meta] add <code>auto-changelog</code> <a
href="b5101ad3d5"><code>b5101ad</code></a></li>
<li>[Tests] handle predict-v8-randomness failures in node < 17 and
node > 23 <a
href="0e93122358"><code>0e93122</code></a></li>
<li>[Fix] Switch to using <code>crypto</code> random for boundary values
<a
href="b88316c94b"><code>b88316c</code></a></li>
<li>[Fix] validate boundary type in <code>setBoundary()</code> method <a
href="131ae5efa3"><code>131ae5e</code></a></li>
<li>[Tests] Switch to newer v8 prediction library; enable node 24
testing <a
href="c97cfbed9e"><code>c97cfbe</code></a></li>
<li>[Refactor] use <code>hasown</code> <a
href="97ac9c208b"><code>97ac9c2</code></a></li>
<li>[meta] remove local commit hooks <a
href="be99d4eea5"><code>be99d4e</code></a></li>
<li>[Dev Deps] remove unused deps <a
href="ddbc89b6d6"><code>ddbc89b</code></a></li>
<li>[meta] fix scripts to use prepublishOnly <a
href="e351a97e9f"><code>e351a97</code></a></li>
<li>[Dev Deps] remove unused script <a
href="8f23366484"><code>8f23366</code></a></li>
<li>[Dev Deps] add missing peer dep <a
href="02ff026fda"><code>02ff026</code></a></li>
<li>[meta] fix readme capitalization <a
href="2fd5f61ebf"><code>2fd5f61</code></a></li>
</ul>
<h2><a
href="https://github.com/form-data/form-data/compare/v2.5.2...v2.5.3">v2.5.3</a>
- 2025-02-14</h2>
<h3>Merged</h3>
<ul>
<li>[Fix] set <code>Symbol.toStringTag</code> when available <a
href="https://redirect.github.com/form-data/form-data/pull/573"><code>[#573](https://github.com/form-data/form-data/issues/573)</code></a></li>
</ul>
<h3>Fixed</h3>
<ul>
<li>[Fix] set <code>Symbol.toStringTag</code> when available (<a
href="https://redirect.github.com/form-data/form-data/issues/573">#573</a>)
<a
href="https://redirect.github.com/form-data/form-data/issues/396"><code>[#396](https://github.com/form-data/form-data/issues/396)</code></a></li>
</ul>
<h3>Commits</h3>
<ul>
<li>[Refactor] use <code>Object.prototype.hasOwnProperty.call</code> <a
href="6e682d4bd4"><code>6e682d4</code></a></li>
<li>[Dev Deps] update <code>@types/node</code>, <code>browserify</code>,
<code>coveralls</code>, <code>eslint</code>, <code>formidable</code>,
<code>in-publish</code>, <code>phantomjs-prebuilt</code>,
<code>pkgfiles</code>, <code>pre-commit</code>, <code>request</code>,
<code>tape</code>, <code>typescript</code> <a
href="819f6b7a54"><code>819f6b7</code></a></li>
<li>Only apps should have lockfiles <a
href="b170ee2b22"><code>b170ee2</code></a></li>
<li>[Deps] update <code>combined-stream</code>, <code>mime-types</code>
<a
href="6b1ca1dc73"><code>6b1ca1d</code></a></li>
<li>Bumped version 2.5.3 <a
href="9457283e1d"><code>9457283</code></a></li>
<li>[Dev Deps] pin <code>request</code> which via
<code>tough-cookie</code> ^2.4 depends on <code>psl</code> <a
href="9dbe192be3"><code>9dbe192</code></a></li>
</ul>
<h2><a
href="https://github.com/form-data/form-data/compare/v2.5.1...v2.5.2">v2.5.2</a>
- 2024-10-10</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="40de5a7420"><code>40de5a7</code></a>
v2.5.5</li>
<li><a
href="026abe5c5c"><code>026abe5</code></a>
[Fix] use proper dependency</li>
<li><a
href="10626c0a9b"><code>10626c0</code></a>
[meta] actually ensure the readme backup isn’t published</li>
<li><a
href="efe6c26931"><code>efe6c26</code></a>
v2.5.4</li>
<li><a
href="c97cfbed9e"><code>c97cfbe</code></a>
[Tests] Switch to newer v8 prediction library; enable node 24
testing</li>
<li><a
href="0e93122358"><code>0e93122</code></a>
[Tests] handle predict-v8-randomness failures in node < 17 and node
> 23</li>
<li><a
href="b88316c94b"><code>b88316c</code></a>
[Fix] Switch to using <code>crypto</code> random for boundary
values</li>
<li><a
href="b70869dad2"><code>b70869d</code></a>
[Fix] <code>append</code>: avoid a crash on nullish values</li>
<li><a
href="131ae5efa3"><code>131ae5e</code></a>
[Fix] validate boundary type in <code>setBoundary()</code> method</li>
<li><a
href="8bf2492e05"><code>8bf2492</code></a>
[eslint] update linting config</li>
<li>Additional commits viewable in <a
href="https://github.com/form-data/form-data/compare/v2.5.1...v2.5.5">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~ljharb">ljharb</a>, a new releaser for
form-data since your current version.</p>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/transloadit/uppy/network/alerts).
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Had to create a new PR since after the 5.0 merge, #5818 was throwing
errors.
## Examples Added
- **React Router v7**
- Uppy Dashboard with Tus, XHR, and Transloadit , tus server implemented
using react-router/express adapter , rest using regular resource routes
- This still doesn't have hot reloading in the dev server though , can
be added through nodemon
- **Next.js**
- Uppy Dashboard with Tus, XHR, and Transloadit
- **Angular**
- Uppy Dashboard and Dashboard Modal with Tus
- The blocker was `@uppy/angular` — its build was failing because it
could not resolve modules and types for its dependencies
(`@uppy/dashboard`, `@uppy/utils`, `@uppy/provider-views`,
`@uppy/core`).
```typescript
------------------------------------------------------------------------------
Building entry point '@uppy/angular'
------------------------------------------------------------------------------
✖ Compiling with Angular sources in Ivy partial compilation mode.
../dashboard/lib/Dashboard.d.ts:1:106 - error TS2307: Cannot find module '@uppy/core' or its corresponding type declarations.
1 import type { Body, DefinePluginOpts, Meta, State, UIPluginOptions, UnknownPlugin, Uppy, UppyFile } from '@uppy/core';
~~~~~~~~~~~~
../dashboard/lib/Dashboard.d.ts:2:26 - error TS2307: Cannot find module '@uppy/core' or its corresponding type declarations.
2 import { UIPlugin } from '@uppy/core';
~~~~~~~~~~~~
../dashboard/lib/Dashboard.d.ts:3:35 - error TS2307: Cannot find module '@uppy/provider-views' or its corresponding type declarations.
```
Angular (TypeScript with moduleResolution: node) required a "main" or
"types" field in each dependency’s package.json, and ignored their
"exports" map.
it was added in #5935 but no explanation of why.
if you look at the build output of for example
`packages/@uppy/react/lib/headless/generated/Dropzone.js`:
```js
import { jsx as _jsx } from "react/jsx-runtime";
// This file was generated by build-components.mjs
// ANY EDITS WILL BE OVERWRITTEN!
import { Dropzone as PreactDropzone, } from '@uppy/components';
import { h as preactH, render as preactRender } from 'preact';
// biome-ignore lint/correctness/noUnusedImports: it's needed
import { createElement as h, useContext, useEffect, useRef } from 'react';
import { UppyContext } from '../UppyContextProvider.js';
export default function Dropzone(props) {
const ref = useRef(null);
const ctx = useContext(UppyContext);
useEffect(() => {
if (ref.current) {
preactRender(preactH(PreactDropzone, {
...props,
ctx,
}), ref.current);
}
}, [ctx, props]);
return _jsx("div", { ref: ref });
}
```
as can be seen there is no usage of `h`. `import { jsx as _jsx } from
"react/jsx-runtime";` is being injected for React JSX. see also
https://github.com/transloadit/uppy/pull/5896#issuecomment-3169210799
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.
# Releases
## @uppy/companion@6.0.1
### Patch Changes
- 49522ec: Remove preact/compat imports in favor of preact, preventing
JSX type issues in certain setups.
## @uppy/components@1.0.1
### Patch Changes
- 49522ec: Remove preact/compat imports in favor of preact, preventing
JSX type issues in certain setups.
- Updated dependencies [49522ec]
- @uppy/core@5.0.1
## @uppy/core@5.0.1
### Patch Changes
- 49522ec: Remove preact/compat imports in favor of preact, preventing
JSX type issues in certain setups.
- Updated dependencies [49522ec]
- @uppy/utils@7.0.1
## @uppy/dashboard@5.0.1
### Patch Changes
- 49522ec: Remove preact/compat imports in favor of preact, preventing
JSX type issues in certain setups.
- Updated dependencies [49522ec]
- @uppy/provider-views@5.0.1
- @uppy/utils@7.0.1
- @uppy/core@5.0.1
## @uppy/drag-drop@5.0.1
### Patch Changes
- 49522ec: Remove preact/compat imports in favor of preact, preventing
JSX type issues in certain setups.
- Updated dependencies [49522ec]
- @uppy/utils@7.0.1
- @uppy/core@5.0.1
## @uppy/provider-views@5.0.1
### Patch Changes
- 49522ec: Remove preact/compat imports in favor of preact, preventing
JSX type issues in certain setups.
- Updated dependencies [49522ec]
- @uppy/utils@7.0.1
- @uppy/core@5.0.1
## @uppy/react@5.0.2
### Patch Changes
- 49522ec: Remove preact/compat imports in favor of preact, preventing
JSX type issues in certain setups.
- Updated dependencies [49522ec]
- @uppy/components@1.0.1
- @uppy/dashboard@5.0.1
- @uppy/utils@7.0.1
- @uppy/core@5.0.1
## @uppy/svelte@5.0.1
### Patch Changes
- 49522ec: Remove preact/compat imports in favor of preact, preventing
JSX type issues in certain setups.
- Updated dependencies [49522ec]
- @uppy/components@1.0.1
- @uppy/dashboard@5.0.1
- @uppy/core@5.0.1
## @uppy/utils@7.0.1
### Patch Changes
- 49522ec: Remove preact/compat imports in favor of preact, preventing
JSX type issues in certain setups.
## @uppy/vue@3.0.2
### Patch Changes
- 49522ec: Remove preact/compat imports in favor of preact, preventing
JSX type issues in certain setups.
- Updated dependencies [49522ec]
- @uppy/components@1.0.1
- @uppy/dashboard@5.0.1
- @uppy/core@5.0.1
## uppy@5.1.1
### Patch Changes
- 7abd062: Add missing styles for drag-drop and status-bar
- Updated dependencies [49522ec]
- @uppy/provider-views@5.0.1
- @uppy/dashboard@5.0.1
- @uppy/drag-drop@5.0.1
- @uppy/core@5.0.1
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
We drag it in unneccesarily in the bundle and it can cause JSX clashes
in React apps with `"jsx": "preserve"` in their `tsconfig.json`
(https://github.com/preactjs/preact/issues/4908)
- Remove `@types/react` from companion (unused)
- Fix tsconfig's for @uppy/utils (build was fine, but editor diagnostics
weren't)
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.
# Releases
## @uppy/drag-drop@5.0.0
### Major Changes
- 3290864: All packages now have export maps. This is a breaking change
in two cases:
1. The css imports have changed from
`@uppy[package]/dist/styles.min.css` to
`@uppy[package]/css/styles.min.css`
2. You were importing something that wasn't exported from the root, for
instance `@uppy/core/lib/foo.js`. You can now only import things we
explicitly exported.
## @uppy/status-bar@5.0.0
### Major Changes
- 3290864: All packages now have export maps. This is a breaking change
in two cases:
1. The css imports have changed from
`@uppy[package]/dist/styles.min.css` to
`@uppy[package]/css/styles.min.css`
2. You were importing something that wasn't exported from the root, for
instance `@uppy/core/lib/foo.js`. You can now only import things we
explicitly exported.
## uppy@5.1.0
### Minor Changes
- 3290864: Bring back StatusBar and DragDrop into the CDN bundle
### Patch Changes
- Updated dependencies [3290864]
- @uppy/status-bar@5.0.0
- @uppy/drag-drop@5.0.0
## @uppy/react@5.0.1
### Patch Changes
- a063bc3: Remove status-bar from export map
## @uppy/vue@3.0.1
### Patch Changes
- a063bc3: Remove status-bar from export map
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
While the frameworks have good alternatives now with new components and
hooks, Uppy is also popular in 'vanilla' JS setups without frameworks
using the CDN bundle. Consumers of this were left with no viable
alternative so it's sensible to bring back status bar and drag drop for
the CDN publish (at least until we also publish/document using hooks via
CDN). The framework packages don't really need this, as the alternatives
are viable there.
- Bring back `@uppy/status-bar` and `@uppy/drag-drop` from git tag
`4.18.1` (latest release before 5.0)
- Put exports maps on both packages
- Put both packages in the CDN bundle
- Version appropriately with changesets
- Override existing locale keys. Unfortunately now that status-bar was
merged into dashboard, the keys need to exist in both places but our
tooling was setup to error when the same keys are found. Now it just
overrides the existing key (to the same value in this case)