Skip to content

fix(deps): update react-email monorepo to v6.9.0#44

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/react-email-monorepo
Open

fix(deps): update react-email monorepo to v6.9.0#44
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/react-email-monorepo

Conversation

@renovate

@renovate renovate Bot commented Dec 10, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@react-email/ui (source) 6.0.06.9.0 age confidence
react-email (source) 6.0.06.9.0 age confidence

Release Notes

resend/react-email (@​react-email/ui)

v6.9.0

Compare Source

Minor Changes
  • badeb1b: The preview props editor now lives in a collapsible panel beside the preview, with a syntax-highlighted JSON editor. Static builds show the props read-only.
Patch Changes
  • 4166fb6: Disconnect hot reload sockets when preview components unmount to prevent connections from accumulating across template navigation.

v6.8.1

Compare Source

Patch Changes
  • c93a676: Make the preview toolbar and its menus responsive across desktop and mobile interactions

v6.8.0

Compare Source

Minor Changes
  • 9605c04: Add a Props tab to the preview toolbar for live-editing the props a template is rendered with. Edits re-render the preview without changing the template's PreviewProps, invalid JSON is flagged inline, and a reset restores the template defaults.
Patch Changes
  • 7b32bf6: Fixed toolbar tabs not responding on statically built previews when the page was opened with a toolbar-panel query param in the URL.

v6.7.0

Compare Source

v6.6.9

Compare Source

v6.6.8

Compare Source

Patch Changes
  • cb2e3d0: Fix out-of-memory crashes when saving a shared component during email dev. Hot reload now re-renders only the preview you have open and invalidates the cache for the other affected templates, instead of eagerly re-rendering every dependent template on each save.

v6.6.7

Compare Source

v6.6.6

Compare Source

Patch Changes
  • b68009f: Stop failing email build when the spam check API errors or times out — the build now logs a warning and continues without a baked-in spam score.

v6.6.5

Compare Source

Patch Changes
  • 1213e82: fix mismatch between motion dependencies causing problems in build for some users

v6.6.4

Compare Source

v6.6.3

Compare Source

Patch Changes
  • 5ad1d79: Update the existing Resend template on upload instead of always creating a new one. The "Upload to Resend" and "Bulk Upload" actions now look the template up by name and update it in place when exactly one matches, so re-uploading no longer produces duplicates (welcome, welcome (1), ...).

v6.6.2

Compare Source

v6.6.1

Compare Source

Patch Changes
  • 1dd2bff: Fix line and column calculation for CRLF line endings in the email validation diagnostics. A \r\n was being counted as two line breaks, so line and column numbers reported for templates authored with Windows line endings were off.

v6.6.0

Compare Source

v6.5.0

Compare Source

Minor Changes
  • 3875d2a: add a --clients option to email dev and a COMPATIBILITY_EMAIL_CLIENTS environment variable to narrow which email clients trigger compatibility warnings. By default the preview still warns for gmail, apple-mail, outlook, and yahoo. Teams that only target one or two clients can now skip the noise: email dev --clients outlook,apple-mail. The CLI flag wins over the env var; an empty or fully-invalid list falls back to the defaults so warnings can't be silently switched off. Builds on #​2797 by @​ReemX.

v6.4.0

Compare Source

v6.3.3

Compare Source

Patch Changes
  • 86745ec: reject paths that resolve outside the configured emails directory in renderEmailByPath and getEmailPathFromSlug to close a path-traversal vector in the preview server

v6.3.2

Compare Source

v6.3.1

Compare Source

Patch Changes
  • 27587f1: stop accepting the emails directory path as a server-action argument

    The getEmailsDirectoryMetadataAction server action used to take an
    absolute filesystem path from the client and walk that directory on the
    server, which allowed any caller of the endpoint to enumerate arbitrary
    directories on the host. The action now reads the path from the server-only
    REACT_EMAIL_INTERNAL_EMAILS_DIR_ABSOLUTE_PATH env variable and ignores
    client input.

v6.3.0

Compare Source

Minor Changes
  • 99cadf3: support previewing HTML email templates
Patch Changes
  • fd140fc: quality of life improvements to the send email flow:
    • infer a proper title based on the file name
    • store preferred subject per email when modified
    • store recipient for testing in local storage as well

v6.2.0

Compare Source

v6.1.5

Compare Source

v6.1.4

Compare Source

v6.1.3

Compare Source

Patch Changes

v6.1.1

Compare Source

v6.1.0

Compare Source

Minor Changes
  • dee7254: add hsl/hsla compatibility detection

v6.0.8

Compare Source

v6.0.7

Compare Source

v6.0.6

Compare Source

v6.0.5

Compare Source

Patch Changes
  • 61df218: Fix the preview server package build so Turbopack's externalized esbuild alias is included in the published tarball.

v6.0.4

Compare Source

Patch Changes
  • 96af3a7: Replace ora with picospinner for CLI and preview spinner output.

v6.0.3

Compare Source

v6.0.2

Compare Source

Patch Changes
  • 6b24228: fallback behavior for prompt copying when too long

v6.0.1

Compare Source

resend/react-email (react-email)

v6.9.0

Compare Source

v6.8.1

Compare Source

v6.8.0

Compare Source

Minor Changes
  • 9605c04: Add a Props tab to the preview toolbar for live-editing the props a template is rendered with. Edits re-render the preview without changing the template's PreviewProps, invalid JSON is flagged inline, and a reset restores the template defaults.
Patch Changes
  • d7743bc: Ship per-module build output with sideEffects: false so bundlers can tree-shake unused components. Importing a component no longer pulls prismjs, marked, and tailwindcss into the bundle unless CodeBlock, Markdown, or Tailwind is actually used.
  • 7b32bf6: Fixed toolbar tabs not responding on statically built previews when the page was opened with a toolbar-panel query param in the URL.

v6.7.0

Compare Source

Minor Changes
  • b448c3b: Enable custom export extensions via --extension/-e (e.g. .blade.php).
Patch Changes

v6.6.9

Compare Source

Patch Changes
  • bc2f7e3: Fix group utilities including bad rules that don't work

v6.6.8

Compare Source

Patch Changes
  • dca3c01: Fix email build computing the wrong output file tracing root in nested-workspace monorepos (e.g. a package one or more directories below the true repo root), which caused Vercel deploys to fail with an ENOENT error on the routes manifest.

v6.6.7

Compare Source

Patch Changes
  • 6a5ff2a: Escape double quotes in Markdown link href/title and image title attributes, matching the escaping already applied to image src/alt. A markdown title like 'The "Complete" Guide' no longer breaks out of the attribute in the rendered HTML.
  • 4cf4c72: Fix two-value logical shorthands whose values aren't all numeric (e.g. margin-inline: 1rem auto, padding-inline: 10px calc(1rem + 2px)) producing invalid duplicated longhands. They are now split into the correct per-side declarations.
  • fa77d55: Merge declarations when the same class is defined by multiple Tailwind rules (e.g. a preset and a child config override).
  • fa52a04: Convert Tailwind's rgba(r g b / a) syntax to rgb(r,g,b,a) syntax for better email client support.
  • fc8318c: Fix Tailwind classes not being inlined into styles for <Section>, <Column> and <Row>.

v6.6.6

Compare Source

Patch Changes
  • b4ac0d5: Fix Button emitting mso-text-raise without a unit on its Outlook padding spacer (e.g. mso-text-raise:18), which Outlook treats as invalid. The value now carries px, matching the unit React already adds on the button label.
  • cb3c468: Fix email build so the generated preview app deploys on Vercel by tracing files from the user's project root instead of the .react-email subfolder.
  • Updated dependencies [c300cfb]

v6.6.5

Compare Source

v6.6.4

Compare Source

Patch Changes
  • f8279be: Fix Tailwind pill utilities like rounded-t-full and rounded-e-full leaving an unrenderable calc(infinity * 1px) in the inlined email CSS (previously only rounded-full was converted to 9999px).

v6.6.3

Compare Source

v6.6.2

Compare Source

Patch Changes
  • 437c414: Fix Tailwind opacity modifiers (e.g. bg-blue-600/50) rendering an invalid percentage alpha that breaks in some email clients.

v6.6.1

Compare Source

Patch Changes
  • 21bac49: Fix Markdown corrupting double quotes in markdownCustomStyles. Inline style values containing a " (e.g. fontFamily: '"Times New Roman", serif') were escaped to the apostrophe entity &#x27; instead of &quot;, silently rewriting the quoted value. Double quotes are now escaped as &quot;.
  • Updated dependencies [60a5b09]

v6.6.0

Compare Source

Minor Changes
  • 16ff94c: add a useTitleTag in Preview component so users can disable it if they want to

v6.5.0

Compare Source

Minor Changes
  • 3875d2a: add a --clients option to email dev and a COMPATIBILITY_EMAIL_CLIENTS environment variable to narrow which email clients trigger compatibility warnings. By default the preview still warns for gmail, apple-mail, outlook, and yahoo. Teams that only target one or two clients can now skip the noise: email dev --clients outlook,apple-mail. The CLI flag wins over the env var; an empty or fully-invalid list falls back to the defaults so warnings can't be silently switched off. Builds on #​2797 by @​ReemX.
Patch Changes
  • d47825a: Add accessibility defaults to components: dir/lang on Body, an empty alt fallback on Img, role="presentation" on the Markdown table, and a <title> from Preview.

v6.4.0

Compare Source

Minor Changes
  • ba99365: resolve and strip unresolved --tw-* CSS variables in non-inlinable rules so Tailwind media query utilities no longer break Gmail

v6.3.3

Compare Source

v6.3.2

Compare Source

Patch Changes
  • fbda5c8: increase whitespace padding to 200 characters for better Gmail preview text rendering

v6.3.1

Compare Source

Patch Changes
  • c610dc0: fix: padding in Container/Section failing on Klaviyo and Outlook desktop

v6.3.0

Compare Source

v6.2.0

Compare Source

Minor Changes
  • 192d82a: Add theme and utility props to <Tailwind> for Tailwind v4 CSS-first configuration. Both accept a CSS string and can be combined with the existing config prop.

    import themeCss from "./theme.css?inline";
    
    <Tailwind theme={themeCss}>
      <div className="bg-brand font-display">Custom themed content</div>
    </Tailwind>;

    Empty strings are no-ops. The base Tailwind theme and utilities are still loaded — theme and utility layer on top.

    The preview server, email export, and the caniemail compatibility check all understand the Vite-style ?inline and ?raw suffixes on CSS imports, so the pattern above works the same in your project and inside the preview UI. The compatibility check also extracts the theme and utility props (in addition to config) when analyzing your template, so any caniemail incompatibilities in CSS produced by those props will surface as warnings.

    Internal note: the exported setupTailwind helper now takes { config, cssConfigs } instead of a positional TailwindConfig. Calling it with the old shape throws with a migration hint.

Patch Changes
  • 06f1d05: Watch directories targeted by dynamic import() template literals so changes to runtime-resolved files trigger preview reloads.

v6.1.5

Compare Source

Patch Changes
  • 1a61cb0: Avoid OOM when running email export on projects with many templates. esbuild builds now run in batches of 10 entry points, and the render phase runs each batch of 25 templates inside a worker_threads worker so V8 isolate memory is reclaimed between batches.

v6.1.4

Compare Source

Patch Changes
  • 1c386ce: Avoid spamming each spinner frame as a new line on non-TTY streams (CI logs, pipes, dumb terminals). The spinner now logs each status text once instead of redrawing animated frames when the output is not a TTY.
  • ad6a9de: - deprecate packageManager CLI option for email build, only supporting npm
    • ensure email build dependency installation includes dev dependencies

v6.1.3

Compare Source

v6.1.1

Compare Source

Patch Changes
  • 3c62bd0: fix divider with extra borders around other corners

v6.1.0

Compare Source

Patch Changes
  • 47eeece: Tailwind: clearer error when <Head> is outside <Tailwind>

v6.0.8

Compare Source

Patch Changes
  • 65525e0: Tailwind: parse non inline configuration variables

v6.0.7

Compare Source

Patch Changes
  • 87a2486: undo nesting of all media queries, and replace >= <= exxpressions with min-width/max-width on the Tailwind component

v6.0.6

Compare Source

Patch Changes
  • 84bb7ab: collapse empty-fallback var() refs in inline styles

v6.0.5

Compare Source

v6.0.4

Compare Source

Patch Changes

v6.0.3

Compare Source

Patch Changes
  • bb51e5e: fix missing react and react-dom peer dependencies

v6.0.2

Compare Source

Patch Changes
  • 63b6e71: Fix Markdown component crashing on CommonMark loose lists with paragraph continuations

v6.0.1

Compare Source

Patch Changes
  • 599b8c5: fix type issues in starter template and in react-email

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title fix(deps): update dependency react-email to v5.0.6 fix(deps): update dependency react-email to v5.0.7 Dec 10, 2025
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from 0b0f960 to c5235ee Compare December 10, 2025 17:00
@renovate renovate Bot changed the title fix(deps): update dependency react-email to v5.0.7 fix(deps): update dependency react-email to v5.0.8 Dec 12, 2025
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from c5235ee to 83913f0 Compare December 12, 2025 15:48
@renovate renovate Bot changed the title fix(deps): update dependency react-email to v5.0.8 fix(deps): update react-email monorepo Dec 18, 2025
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from 83913f0 to cc5c0db Compare December 18, 2025 15:44
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from cc5c0db to 1166b94 Compare December 29, 2025 14:53
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch 3 times, most recently from 2fca422 to 0fc0db5 Compare January 13, 2026 18:46
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch 4 times, most recently from a890424 to d997e8e Compare January 20, 2026 18:46
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch 3 times, most recently from 8b3254f to c59db99 Compare February 6, 2026 22:34
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from c59db99 to ed6e4e9 Compare February 18, 2026 16:08
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from ed6e4e9 to 5dd1a33 Compare February 28, 2026 02:15
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch 2 times, most recently from d1da3b1 to cb20f2b Compare March 17, 2026 22:37
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from cb20f2b to 542728d Compare April 1, 2026 02:40
@socket-security

socket-security Bot commented Apr 1, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​react-email/​ui@​6.0.0 ⏵ 6.9.059 -1710076 -1099 +1100
Updatednpm/​react-email@​6.0.0 ⏵ 6.9.0991009198 +1100

View full report

@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from 542728d to 2b1d25d Compare April 9, 2026 16:39
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch 2 times, most recently from d01af56 to 518c492 Compare April 17, 2026 16:57
@renovate renovate Bot changed the title fix(deps): update react-email monorepo fix(deps): update react-email monorepo - autoclosed Apr 22, 2026
@renovate renovate Bot closed this Apr 22, 2026
@renovate
renovate Bot deleted the renovate/react-email-monorepo branch April 22, 2026 16:22
@renovate renovate Bot changed the title fix(deps): update react-email monorepo - autoclosed fix(deps): update react-email monorepo to v6.0.1 Apr 27, 2026
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch 2 times, most recently from 2df764a to 49864b7 Compare May 13, 2026 18:57
@renovate renovate Bot changed the title fix(deps): update react-email monorepo to v6.1.3 fix(deps): update react-email monorepo to v6.1.4 May 13, 2026
@renovate renovate Bot changed the title fix(deps): update react-email monorepo to v6.1.4 fix(deps): update react-email monorepo to v6.1.5 May 18, 2026
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch 2 times, most recently from 80550a6 to 8d1b6db Compare May 21, 2026 16:39
@renovate renovate Bot changed the title fix(deps): update react-email monorepo to v6.1.5 fix(deps): update react-email monorepo to v6.2.0 May 21, 2026
@socket-security

socket-security Bot commented May 21, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm css-tree is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?npm/react-email@6.9.0npm/css-tree@3.2.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/css-tree@3.2.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm jiti is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?npm/react-email@6.9.0npm/jiti@2.6.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/jiti@2.6.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm next is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?npm/@react-email/ui@6.9.0npm/next@16.2.6

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/next@16.2.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from 8d1b6db to 76ca065 Compare May 21, 2026 23:11
@renovate renovate Bot changed the title fix(deps): update react-email monorepo to v6.2.0 fix(deps): update react-email monorepo to v6.3.0 May 21, 2026
@renovate renovate Bot changed the title fix(deps): update react-email monorepo to v6.3.0 fix(deps): update react-email monorepo to v6.3.1 May 22, 2026
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from 76ca065 to b7f45d7 Compare May 22, 2026 17:07
@renovate renovate Bot changed the title fix(deps): update react-email monorepo to v6.3.1 fix(deps): update react-email monorepo to v6.3.2 May 22, 2026
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch 2 times, most recently from 3d36c82 to 51e15ab Compare May 25, 2026 15:11
@renovate renovate Bot changed the title fix(deps): update react-email monorepo to v6.3.2 fix(deps): update react-email monorepo to v6.3.3 May 25, 2026
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from 51e15ab to 89411fe Compare May 26, 2026 23:47
@renovate renovate Bot changed the title fix(deps): update react-email monorepo to v6.3.3 fix(deps): update react-email monorepo to v6.4.0 May 26, 2026
@renovate renovate Bot changed the title fix(deps): update react-email monorepo to v6.4.0 fix(deps): update react-email monorepo to v6.5.0 May 27, 2026
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from 89411fe to 2859051 Compare May 27, 2026 20:08
@renovate renovate Bot changed the title fix(deps): update react-email monorepo to v6.5.0 fix(deps): update react-email monorepo to v6.6.0 Jun 9, 2026
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from 2859051 to f0ae714 Compare June 9, 2026 13:13
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from f0ae714 to 7f663b4 Compare June 16, 2026 20:43
@renovate renovate Bot changed the title fix(deps): update react-email monorepo to v6.6.0 fix(deps): update react-email monorepo to v6.6.3 Jun 16, 2026
@renovate renovate Bot changed the title fix(deps): update react-email monorepo to v6.6.3 fix(deps): update react-email monorepo to v6.6.4 Jun 22, 2026
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from 7f663b4 to 771cdc0 Compare June 22, 2026 23:41
@renovate renovate Bot changed the title fix(deps): update react-email monorepo to v6.6.4 fix(deps): update react-email monorepo to v6.6.5 Jun 25, 2026
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from 771cdc0 to a7eee5d Compare June 25, 2026 19:27
@renovate
renovate Bot force-pushed the renovate/react-email-monorepo branch from a7eee5d to 47e0344 Compare July 3, 2026 03:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants