Skip to content

build(deps): update devframe to 1.2.2 - #221

Merged
erkamyaman merged 2 commits into
pangular-inspector:mainfrom
erkamyaman:build/devframe-1.2.2
Oct 6, 2026
Merged

erkamyaman merged 2 commits into
pangular-inspector:mainfrom
erkamyaman:build/devframe-1.2.2

Conversation

@erkamyaman

@erkamyaman erkamyaman commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

What and why

Updates devframe and the @devframes/* packages to ^1.2.2 (root, packages/devtools, examples/angular-native). 1.2.1 includes devframes/devframe#425, which fixes the two axe violations on the standalone hub page from #206: the dock iframe now has a title, and the page has a nav ("Docks") and a main landmark. 1.2.2 adds features we don't use. No code changes were needed. extension/ui is rebuilt because the panel bundles the devframe client.

Closes #206

How it was verified

  • pnpm commit:check, pnpm format:check, pnpm typecheck, pnpm skills:check
  • pnpm test:devtools (1166) and pnpm test:panel
  • pnpm docs:build, pnpm test:axe, pnpm install --frozen-lockfile
  • pnpm extension:build and extension/ui committed
  • axe on /__devframes/ with the SSR demo, dark and light: frame-title and region are gone; the panel loads live data through the hub

Notes for reviewers

With the hub's new <main>, axe flagged landmark-unique because our panel's <main> in the dock iframe was unnamed too. The panel's main is now named after the active inspector tab (e.g. "Dashboard"), and axe on /__devframes/ reports 0 violations in dark and light.

Summary by CodeRabbit

  • Accessibility
    • The main content region now has a label that reflects the active tab, or the current view title when no tab matches. Assistive technology can use this label to identify the content being displayed as users move between tabs and views.

devframe 1.2.1 ships the hub UI fix from devframes/devframe#425: dock iframes get their title and the standalone hub page gets nav and main landmarks, which clears the frame-title and region axe violations on /__devframes/.

Closes pangular-inspector#206
@erkamyaman erkamyaman self-assigned this Oct 6, 2026
@github-actions github-actions Bot added area: package The ng-devtools package (packages/ng-devtools) area: extension The Chrome extension area: demo The demo apps labels Oct 6, 2026
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: aad1d21c-1f06-4b85-aff2-aba5d42a3ff3
📥 Commits

Reviewing files that changed from the base of the PR and between 3255b06 and 6828dfc.

⛔ Files ignored due to path filters (2)
  • extension/ui/assets/index-CRdjMW3X.js is excluded by !**/assets/index-[0-9a-z_-][0-9a-z_-][0-9a-z_-][0-9a-z_-][0-9a-z_-][0-9a-z_-][0-9a-z_-][0-9a-z_-].js
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (6)
  • app/src/app.ts
  • examples/angular-native/package.json
  • extension/ui/assets/browser-agent-rpc-BXhoSh1z-Bzura7CV.js
  • extension/ui/index.html
  • package.json
  • packages/devtools/package.json

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The main content region now has an accessible label based on the active tab or view title. Devframe dependency ranges change to ^1.2.2, and extension UI files reference a different bundled JavaScript asset.

Changes

Accessibility and Devframe update

Layer / File(s) Summary
Add a computed main content label
app/src/app.ts
The main content region’s accessible label uses the active tab’s label when available. Otherwise, it uses the view title.
Update Devframe dependency ranges
package.json, packages/devtools/package.json, examples/angular-native/package.json
Devframe dependency ranges change from ^1.2.0 to ^1.2.2.
Update extension UI asset references
extension/ui/index.html, extension/ui/assets/browser-agent-rpc-BXhoSh1z-Bzura7CV.js
The extension HTML and browser-agent RPC bundle reference index-CRdjMW3X.js.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Bug fix · Severity of issue fixed: Low

Merge Risk: ⚪ Minimal · up to 6828d

The main landmark receives a label from the active tab or view title, and the dependency and extension references are consistent. No concrete PR-introduced issue remains to block merging.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 6828d

No introduced security weakness was established. The accessible-label change does not add capabilities, and existing entrypoint configuration is unchanged. However, the upgraded dependencies implement security-sensitive behavior that could not be fully compared.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The security-relevant scope is the existing development bridge, hub, and connected inspector RPC clients, rather than the accessible-label output. Effective network exposure and maximum independently attackable scope cannot be established without deployment topology and upstream enforcement behavior.

Trust Boundaries and Controls

  • observed — Unchanged hub wiring supplies its default origin registry unless overridden. That registry accepts Chrome extension origins or delegates to Devframe's origin helper. MCP authorization defaults to an environment-provided or generated token unless the caller supplies MCP configuration or disables authentication. Effective enforcement remains partly delegated to the upgraded packages.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 2 files. (4 skipped: 4 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: updating devframe to version 1.2.2.
Linked Issues check ✅ Passed Issue [#206] requires upgrading the released hub packages and rerunning axe on /__devframes/. The PR updates the relevant @devframes/* dependencies to ^1.2.2 and reports that pnpm test:axe fou…
Out of Scope Changes check ✅ Passed The dependency updates, panel landmark label, and rebuilt extension/ui support the [#206] hub accessibility fix and its verification. The summaries show no unrelated changes.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 2 files. (4 skipped: 4 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

With devframe 1.2.2 the hub page has its own main landmark, and axe compares landmarks across the dock iframe, so the two unnamed mains failed landmark-unique. The panel's main is now named after the active inspector tab.
@github-actions github-actions Bot added the area: panel The devtools panel app (app/) label Oct 6, 2026
@erkamyaman
erkamyaman merged commit afeff31 into pangular-inspector:main Oct 6, 2026
7 of 8 checks passed
@erkamyaman
erkamyaman deleted the build/devframe-1.2.2 branch October 6, 2026 21:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: demo The demo apps area: extension The Chrome extension area: package The ng-devtools package (packages/ng-devtools) area: panel The devtools panel app (app/)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Hub page fails axe: unnamed dock iframe and no landmarks

1 participant