Skip to content

Version Packages - #458

Merged
jcbsfilho merged 1 commit into
mainfrom
changeset-release/main
Jul 8, 2026
Merged

Version Packages#458
jcbsfilho merged 1 commit into
mainfrom
changeset-release/main

Conversation

@pablodiehl

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@aziontech/builder@1.0.5

Patch Changes

  • #457 e238045 Thanks @jcbsfilho! - security(deps): remediate pnpm audit vulnerabilities

    • bump vite to ^7.3.6, fixing high-severity dev-server path traversal
      and arbitrary file read advisories (GHSA-v2wj-q39q-566r, GHSA-p9ff-h696-f583)
    • add pnpm.overrides forcing patched versions of transitive deps flagged
      by pnpm audit: undici, lodash, postcss, fast-uri, qs, esbuild,
      brace-expansion, js-yaml, @babel/core and
      @babel/plugin-transform-modules-systemjs
    • bump direct deps lodash-es and tmp to their patched releases in
      builder/config packages
    • drop unused crypto-browserify polyfill dependency from unenv-preset
    • replace ip-cidr with ipaddr.js for CIDR matching in the network-list
      polyfill
    • replace @fastly/http-compute-js with fetch-to-node (same API, zero
      dependencies) in the Next.js 12.3.x custom server preset, removing
      @fastly/js-compute and the unfixed decompress vulnerability pulled in
      transitively via @bytecodealliance/weval
  • Updated dependencies [e238045]:

    • @aziontech/unenv-preset@1.0.2
    • @aziontech/config@1.0.2
    • @aziontech/presets@1.1.2

@aziontech/config@1.0.2

Patch Changes

  • #457 e238045 Thanks @jcbsfilho! - security(deps): remediate pnpm audit vulnerabilities
    • bump vite to ^7.3.6, fixing high-severity dev-server path traversal
      and arbitrary file read advisories (GHSA-v2wj-q39q-566r, GHSA-p9ff-h696-f583)
    • add pnpm.overrides forcing patched versions of transitive deps flagged
      by pnpm audit: undici, lodash, postcss, fast-uri, qs, esbuild,
      brace-expansion, js-yaml, @babel/core and
      @babel/plugin-transform-modules-systemjs
    • bump direct deps lodash-es and tmp to their patched releases in
      builder/config packages
    • drop unused crypto-browserify polyfill dependency from unenv-preset
    • replace ip-cidr with ipaddr.js for CIDR matching in the network-list
      polyfill
    • replace @fastly/http-compute-js with fetch-to-node (same API, zero
      dependencies) in the Next.js 12.3.x custom server preset, removing
      @fastly/js-compute and the unfixed decompress vulnerability pulled in
      transitively via @bytecodealliance/weval

@aziontech/presets@1.1.2

Patch Changes

  • #457 e238045 Thanks @jcbsfilho! - security(deps): remediate pnpm audit vulnerabilities

    • bump vite to ^7.3.6, fixing high-severity dev-server path traversal
      and arbitrary file read advisories (GHSA-v2wj-q39q-566r, GHSA-p9ff-h696-f583)
    • add pnpm.overrides forcing patched versions of transitive deps flagged
      by pnpm audit: undici, lodash, postcss, fast-uri, qs, esbuild,
      brace-expansion, js-yaml, @babel/core and
      @babel/plugin-transform-modules-systemjs
    • bump direct deps lodash-es and tmp to their patched releases in
      builder/config packages
    • drop unused crypto-browserify polyfill dependency from unenv-preset
    • replace ip-cidr with ipaddr.js for CIDR matching in the network-list
      polyfill
    • replace @fastly/http-compute-js with fetch-to-node (same API, zero
      dependencies) in the Next.js 12.3.x custom server preset, removing
      @fastly/js-compute and the unfixed decompress vulnerability pulled in
      transitively via @bytecodealliance/weval
  • Updated dependencies [e238045]:

    • @aziontech/unenv-preset@1.0.2
    • @aziontech/config@1.0.2

@aziontech/unenv-preset@1.0.2

Patch Changes

  • #457 e238045 Thanks @jcbsfilho! - security(deps): remediate pnpm audit vulnerabilities
    • bump vite to ^7.3.6, fixing high-severity dev-server path traversal
      and arbitrary file read advisories (GHSA-v2wj-q39q-566r, GHSA-p9ff-h696-f583)
    • add pnpm.overrides forcing patched versions of transitive deps flagged
      by pnpm audit: undici, lodash, postcss, fast-uri, qs, esbuild,
      brace-expansion, js-yaml, @babel/core and
      @babel/plugin-transform-modules-systemjs
    • bump direct deps lodash-es and tmp to their patched releases in
      builder/config packages
    • drop unused crypto-browserify polyfill dependency from unenv-preset
    • replace ip-cidr with ipaddr.js for CIDR matching in the network-list
      polyfill
    • replace @fastly/http-compute-js with fetch-to-node (same API, zero
      dependencies) in the Next.js 12.3.x custom server preset, removing
      @fastly/js-compute and the unfixed decompress vulnerability pulled in
      transitively via @bytecodealliance/weval

@pablodiehl
pablodiehl requested review from a team and jcbsfilho as code owners July 8, 2026 13:48
@github-actions

github-actions Bot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

SCC Complexity Analysis

  • Title: Version Packages
  • Author: pablodiehl
Metric Source Branch (changeset-release/main) Target Branch (main) Difference
Complexity 2452 2452 0
Code 50654 50597 57

@jcbsfilho
jcbsfilho merged commit abd7939 into main Jul 8, 2026
10 checks passed
@jcbsfilho
jcbsfilho deleted the changeset-release/main branch July 8, 2026 13:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

4 participants