Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 5, 2026

Bumps vega-functions to 6.1.1 and updates ancestor dependencies vega-functions, vega, vega-embed and vega-lite. These dependencies need to be updated together.

Updates vega-functions from 5.18.0 to 6.1.1

Release notes

Sourced from vega-functions's releases.

v6.1.1

Full Changelog: vega/vega@v6.1.0...v6.1.1

v6.1.0

What's Changed

Full Changelog: vega/vega@v6.0.0...v6.1.0

v6.0.0

changes since v5.33.0

monorepo

vega-typings

docs

v5.33.0

Changes since v5.32.0

docs

v5.32.0

Changes since v5.31.0

vega-expression

  • Add base64 string encoder/decoder to vega-expression and vega-interpreter (via #4009). (Thanks @​hydrosquall!)

vega-typings

docs

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by hydrosquall, a new releaser for vega-functions since your current version.


Updates vega from 5.33.0 to 6.2.0

Release notes

Sourced from vega's releases.

v6.2.0

What's Changed

... (truncated)

Commits

Updates vega-embed from 6.22.2 to 7.1.0

Release notes

Sourced from vega-embed's releases.

Release 7.1.0

7.1.0 (2025-10-09)

Bug Fixes

Release 7.0.2

7.0.2 (2025-03-29)

Bug Fixes

  • correct repo entry (7e78bc8)
  • use embed.js for clearer mapping to what file we are using (30a8437)

Release 7.0.1

7.0.1 (2025-03-28)

Bug Fixes

Release 7.0.0

What's Changed

... (truncated)

Changelog

Sourced from vega-embed's changelog.

7.1.0 (2025-10-09)

Bug Fixes

7.0.2 (2025-03-29)

Bug Fixes

  • correct repo entry (7e78bc8)
  • use embed.js for clearer mapping to what file we are using (30a8437)

7.0.1 (2025-03-28)

Bug Fixes

7.0.0 (2025-03-28)

Bug Fixes

6.29.0 (2024-11-19)

Features

6.28.0 (2024-11-07)

Features

6.27.1 (2024-11-07)

Bug Fixes

  • correct types reference (794b9cc)

... (truncated)

Commits
  • 1bd3e9c chore: release v7.1.0
  • 6f47dc0 fix: handle logLevel correctly (#1475)
  • bab3d91 chore(deps-dev): bump del-cli from 6.0.0 to 7.0.0 (#1474)
  • afb1079 chore(deps): bump actions/setup-node from 4 to 5 (#1465)
  • cbc4bc2 chore(deps-dev): bump @​vitest/eslint-plugin from 1.3.6 to 1.3.13 (#1473)
  • bcee73b chore(deps): bump codecov/codecov-action from 5.5.0 to 5.5.1 (#1464)
  • 63c9d5f chore(deps-dev): bump release-it from 19.0.4 to 19.0.5 (#1470)
  • 307f7ab chore(deps-dev): bump typescript from 5.8.3 to 5.9.3 (#1472)
  • 78af475 chore(deps-dev): bump rollup from 4.50.0 to 4.52.3 (#1471)
  • daa266b chore(deps-dev): bump vega-lite from 6.2.0 to 6.4.1 (#1468)
  • Additional commits viewable in compare view

Updates vega-lite from 5.14.1 to 6.4.1

Release notes

Sourced from vega-lite's releases.

Release 6.4.1

6.4.1 (2025-09-23)

Bug Fixes

  • do not apply the color domain order for the unstacked ungrouped chart (#9687) (921fdf7)

Release 6.4.0

6.4.0 (2025-09-17)

Bug Fixes

Features

Release 6.3.1

6.3.1 (2025-09-10)

Bug Fixes

Features

  • add interactive geographic facet visualizations for species habitat data (#9661) (5798e77), closes #9659
  • align stack order only for nominal color domains (#9645) (e201a9d)
  • for interactive charts, changed cursor to pointer (#9358) (ee740b5)

Release 6.2.0

6.2.0 (2025-06-27)

Bug Fixes

  • docs: improve header alignment for facet_bullet graph example (#9554) (99a43e4)
  • ensure temporal field propagates to time expression (#8757) (473f359)
  • turn off aria for the generated voronoi layer from nearest spec (#9624) (8588c14)

... (truncated)

Changelog

Sourced from vega-lite's changelog.

6.4.1 (2025-09-23)

Bug Fixes

  • do not apply the color domain order for the unstacked ungrouped chart (#9687) (921fdf7)

6.4.0 (2025-09-17)

Bug Fixes

Features

6.3.1 (2025-09-10)

Bug Fixes

Features

  • add interactive geographic facet visualizations for species habitat data (#9661) (5798e77), closes #9659
  • align stack order only for nominal color domains (#9645) (e201a9d)
  • for interactive charts, changed cursor to pointer (#9358) (ee740b5)

6.2.0 (2025-06-27)

Bug Fixes

  • docs: improve header alignment for facet_bullet graph example (#9554) (99a43e4)
  • ensure temporal field propagates to time expression (#8757) (473f359)
  • turn off aria for the generated voronoi layer from nearest spec (#9624) (8588c14)

Features

... (truncated)

Commits
  • d4492fe chore: release v6.4.1
  • 921fdf7 fix: do not apply the color domain order for the unstacked ungrouped chart (#...
  • cb93216 chore(deps-dev): bump rexml from 3.4.1 to 3.4.2 in /site in the bundler group...
  • 4932bf1 chore: release v6.4.0
  • fcc2486 chore: update deps (#9685)
  • c785de5 feat: support newlines in tooltips (#9678)
  • 0ff8505 fix: height/width of 0 ignored (#9676)
  • f1052b6 chore: release v6.3.1
  • 9ffd522 chore(deps): bump the npm_and_yarn group across 1 directory with 3 updates (#...
  • 0e6537c chore(deps): bump the npm_and_yarn group with 2 updates (#9673)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Greptile Summary

This PR updates the Vega visualization library ecosystem from v5 to v6, including major version bumps for vega, vega-embed, and vega-lite.

Key Changes:

  • vega: 5.33.0 → 6.2.0 (major version)
  • vega-embed: 6.22.2 → 7.1.0 (major version)
  • vega-lite: 5.14.1 → 6.4.1 (major version)

Breaking Changes:

  • All packages are now ESM-only (no CommonJS support)
  • vega-embed default renderer changed from canvas to SVG
  • Vega 6 removed source maps for bundled files and old compatibility libraries

Potential Impact:

  • The ESM-only change may affect module loading if the catalog uses CommonJS imports
  • Default renderer change from canvas to SVG could affect rendering behavior and performance characteristics
  • Applications using Vega visualizations should be tested thoroughly to ensure compatibility

Testing Recommendations:

  • Verify all Vega/Vega-Lite visualizations render correctly
  • Check that the SVG renderer works as expected (previously defaulted to canvas)
  • Test in different browsers to ensure ESM compatibility
  • Verify bundle size hasn't increased significantly

Confidence Score: 3/5

  • This PR involves multiple major version updates with breaking changes; thorough testing of visualization features is required before merging
  • The PR updates critical visualization dependencies with multiple major version bumps and breaking changes (ESM-only, default renderer change). While these are standard dependency updates from a trusted library, the breaking changes could affect existing functionality. The lack of code changes beyond package.json suggests no adaptation was made for the breaking changes, which is concerning. Testing is essential to verify compatibility.
  • Verify that the application code properly handles the ESM-only modules and the new SVG default renderer for vega-embed

Important Files Changed

Filename Overview
catalog/package.json Major version bumps for vega (5→6), vega-embed (6→7), and vega-lite (5→6) with breaking changes including ESM-only and default renderer changes
catalog/package-lock.json Lock file update reflecting the vega dependency changes, ensuring consistent installation across environments

Sequence Diagram

sequenceDiagram
    participant D as Dependabot
    participant P as package.json
    participant L as package-lock.json
    participant V as Vega Libraries
    participant C as Catalog App
    
    D->>P: Update vega 5.33.0 → 6.2.0
    D->>P: Update vega-embed 6.22.2 → 7.1.0
    D->>P: Update vega-lite 5.14.1 → 6.4.1
    D->>L: Regenerate lock file
    
    Note over V: Breaking Changes:<br/>- ESM only<br/>- SVG default renderer<br/>- No source maps
    
    C->>V: Import vega modules
    V-->>C: ESM modules loaded
    
    C->>V: Initialize vega-embed
    V-->>C: Use SVG renderer (new default)
    
    Note over C: Potential Issues:<br/>- CommonJS compatibility<br/>- Renderer behavior changes<br/>- Bundle size impact
Loading

Bumps [vega-functions](https://github.com/vega/vega) to 6.1.1 and updates ancestor dependencies [vega-functions](https://github.com/vega/vega), [vega](https://github.com/vega/vega), [vega-embed](https://github.com/vega/vega-embed) and [vega-lite](https://github.com/vega/vega-lite). These dependencies need to be updated together.


Updates `vega-functions` from 5.18.0 to 6.1.1
- [Release notes](https://github.com/vega/vega/releases)
- [Commits](vega/vega@v5.18.0...v6.1.1)

Updates `vega` from 5.33.0 to 6.2.0
- [Release notes](https://github.com/vega/vega/releases)
- [Commits](vega/vega@v5.33.0...v6.2.0)

Updates `vega-embed` from 6.22.2 to 7.1.0
- [Release notes](https://github.com/vega/vega-embed/releases)
- [Changelog](https://github.com/vega/vega-embed/blob/main/CHANGELOG.md)
- [Commits](vega/vega-embed@v6.22.2...v7.1.0)

Updates `vega-lite` from 5.14.1 to 6.4.1
- [Release notes](https://github.com/vega/vega-lite/releases)
- [Changelog](https://github.com/vega/vega-lite/blob/main/CHANGELOG.md)
- [Commits](vega/vega-lite@v5.14.1...v6.4.1)

---
updated-dependencies:
- dependency-name: vega-functions
  dependency-version: 6.1.1
  dependency-type: indirect
- dependency-name: vega
  dependency-version: 6.2.0
  dependency-type: direct:production
- dependency-name: vega-embed
  dependency-version: 7.1.0
  dependency-type: direct:production
- dependency-name: vega-lite
  dependency-version: 6.4.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jan 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant