You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Fixed bun install recursing without bound when the custom Angular
builders had not been compiled yet. The postinstall step ran a nested bun install for the builders, which re-entered the root install and
its postinstall. The builders are a workspace of the root package, so
the root install already covers them and only the compile remains.
These CommonJS build scripts are now named .cjs permanently. They
used to be renamed to .cjs and back on every run, so an interrupted
build or install left the tracked files deleted and untracked copies
in their place:
dev-setup
clean-symlinks
store-git-metadata
Escape now closes these popups and returns focus to the button that
opened them:
the row-actions menu in lists
the options list of the console's dropdown selects
Both announced themselves as popups to assistive technology but
ignored Escape, so a keyboard user could not close them. Inside a
dialog, one Escape closes only the menu or list, not the dialog
behind it.
Maintainability
Moved the devkit's build tooling to 22.2.0 and removed the npm
overrides in its manifest. The overrides were added to force patched
versions past dependency alerts, but the tooling had since moved
beyond them, so they were forcing older releases onto it:
Package
Forced by the overrides
Declared by the tooling
vite
7
8
Babel
7
8
webpack-dev-server
5
6
The vite pin also kept a vulnerable esbuild in the devkit lockfile
(GHSA-g7r4-m6w7-qqqr, low). Without the overrides the devkit resolves
the versions its tooling declares, and npm audit reports no
vulnerabilities.
Jetstream no longer depends on govau/cf-common, unmaintained since
2020, through which it read every configuration setting. The small
part it used now lives in the repository as api/env, with tests.
This also removes the stale go-cfenv 1.19.0 that four backend
modules inherited from it; go-cfenv is now 1.24.3 throughout.
Removed six root dependencies that nothing in the repository imports
or runs:
Package
State upstream
q
archived and deprecated
delete
no change since 2017
ps-node
no change since 2021
npm-run-all
no change since 2024; no script used it
mappy-breakpoints
no change since 2023
kind-of
2020 security pin, no longer needed
kind-of stays at the patched 6.0.3 through clone-deep, which now
requires it on its own. The lockfile loses 125 package versions and
gains none.
Chores
Angular dependency updates:
Component
From
To
Angular framework
22.1.7
22.2.0
Angular CLI and build tooling
22.1.8
22.2.0
Analog Vitest plugin
2.7.2
2.7.5
Analog 2.7.2 failed on Angular 22.2 with cache.has is not a function
(analogjs/analog#2575), because 22.2 changed the internal cache the
plugin relies on. 2.7.3 carries the fix, and 2.7.5 stops starting idle
Angular worker threads up front (analogjs/analog#2581), so unit tests
and production builds share a single @angular/build 22.2.0.
Added scripts/lockdiff.mjs, which explains a lockfile change by
package instead of by line. For bun.lock and npm package-lock.json
it reports:
packages added, removed, re-versioned or only moved in the tree
which changed package brought each one in
docs/build-and-packaging.md describes the stepwise update procedure
it supports, which keeps lockfile regeneration as a last resort.
Dependency updates: typescript-eslint from 8.70.0 to 8.70.1.
The lint configuration uses only the typescript-eslint package,
which brings its parser and plugin, so the root manifest no longer
declares them separately. The separate pins kept an older copy of the
whole family in the lockfile whenever typescript-eslint moved on its
own:
@typescript-eslint/eslint-plugin
@typescript-eslint/parser
The Stratos Theme Builder's CI job installs from tools/stb/bun.lock
with bun install --frozen-lockfile instead of npm install, which
ignored the lockfile and resolved every dependency fresh. The
lockfile also drops stale nested CodeMirror copies that failed
typecheck when installed as locked.
These targets generate build-info.ts when it is missing, as CI
already does before its tests:
make check gate
make check tests
make check coverage
In a fresh clone or worktree the unit tests previously failed to
resolve it. An existing file is left untouched.
they state the current Angular (22) and Go (1.27) versions
the README's application screenshot and Browserstack logo render
again
most markdownlint findings in the two files are cleared
Both images had pointed into the website/ tree the Docusaurus
rewrite replaced; the logo now lives in docs/images/.
Dependency updates: the Monaco editor from 0.56.0 to 0.57.0, which
updates the editor core and its bundled DOMPurify (3.4.8 to 3.4.15).
The manifest range moves to ^0.57.0, since a caret range on a 0.x
version does not take a new minor.
Backend toolchain and dependency updates:
Component
From
To
Go (backend modules)
1.27.0
1.27.1
Go (CI tools image)
1.26.5
1.27.1
capi (CF API client)
fork of 3.229.1
3.229.2
go-sqlite3
0.35.4
0.35.6
Helm
3.21.4
3.22.0
Kubernetes client libraries
0.37.0
0.37.1
AWS SDK for Go v2
1.46.0
1.47.1
code.cloudfoundry.org/clock
1.87.0
1.89.0
capi now comes from its upstream release instead of a fork. The fork
carried the "create a role by username and origin" change ahead of
its release; 3.229.2 includes it.
Sixteen replace directives that no longer affected the build were
removed from the backend modules.
Dependabot runs from one configuration file again. The repository had
both .github/dependabot.yml and .github/dependabot.yaml, and only
the first was in effect, so these were lost:
version updates for the backend Go modules
version updates for the website
the pinned chore(deps) commit prefix the release notes rely on
The merged file restores them and adds a weekly grouped update across
all seven Go modules.
Unit-test tooling updates, moved together because Vitest 5 requires
its plugins at exactly its own version:
Package
From
To
vitest
5.0.1
5.0.2
@vitest/coverage-v8
5.0.1
5.0.2
@vitest/ui
5.0.1
5.0.2
Dependabot now groups the Vitest packages, so it no longer proposes
a Vitest bump that leaves the plugins behind.
Removed ANGULAR-21-UPGRADE-STATUS.md from the repository root. It
was a work-in-progress note from an abandoned Angular 21 upgrade
attempt; the test failure it describes no longer occurs, and the
branches and versions it names are out of date. The current
dependency-update procedure is in docs/build-and-packaging.md.
Frontend dependency updates:
Package
From
To
marked
18.0.12
18.0.14
ng-packagr
22.1.1
22.2.1
jsdom
30.0.1
30.1.1
happy-dom
20.14.0
20.14.5
sass
1.104.0
1.105.0
@oxc-project/runtime
0.121.0
0.151.0
@types/node
26.4.1
26.6.3
fs-extra
11.4.0
11.4.1
browserstack-local
1.5.14
1.5.15
baseline-browser-mapping
2.11.25
2.11.26
The marked pin in src/frontend/packages/core/package.json moved
with the root, as the nested manifest pin check requires.
Website dependency updates:
Package
From
To
react, react-dom
19.2.8
19.3.0
lucide-react
1.28.0
1.48.0
tailwind-merge
3.6.0
3.7.0
postcss
8.5.25
8.5.28
prettier
3.9.6
3.9.9
caniuse-lite
1.0.30001806
1.0.30001812
baseline-browser-mapping
2.11.10
2.11.26
Frontend dependency updates:
Package
From
To
Angular framework and @angular/cdk
22.2.0
22.2.1
ng2-charts
10.0.0
11.0.0
ng-packagr
22.2.1
22.2.3
vitest, @vitest/coverage-v8, @vitest/ui
5.0.2
5.0.3
typescript-eslint
8.70.1
8.71.0
sass
1.105.0
1.105.1
@oxc-project/runtime
0.151.0
0.152.0
ng2-charts 11 only raises its Angular peer floor from 21 to 22; the
chart directive's behavior is unchanged.
The Angular pins in the nested src/frontend/packages/*/package.json
manifests moved with the root, as the nested manifest pin check
requires.
Frontend dependency updates:
Package
From
To
@angular/build, @angular/cli, @schematics/angular
22.2.0
22.2.1
@angular-devkit/build-angular, core, schematics
22.2.0
22.2.1
@angular-devkit/architect
0.2202.0
0.2202.1
ng-packagr
22.2.3
22.2.4
baseline-browser-mapping
2.11.26
2.11.27
The Angular build tooling now matches the 22.2.1 framework, in the
root and devkit manifests alike.
rollup leaves the root lockfile. Nothing depended on it; the
toolchain builds with rolldown.
Analog 2.8.0 carries the plugin fixes for the Angular 22.2 transformer
and source caches; it is tested against the 22.2.1 build tooling. The
Analog pins in src/frontend/packages/store/package.json moved with
the root, as the nested manifest pin check requires.
release-notes.sh check (also run by make changelog and make stamp tag) now notes each bumped package that no fragment names. A later
dependency fragment no longer hides an earlier bump it never described.
Frontend dependency updates from 09-24 that no other fragment covers:
Package
From
To
eslint
10.10.0
10.11.0
browserstack-local
1.5.13
1.5.14
baseline-browser-mapping
2.11.21
2.11.25
browserstack-local and baseline-browser-mapping moved again later in
the release; the rows above are their first steps.
Security Updates
Echo, Jetstream's HTTP framework, moved from 5.3.1 to 5.4.0 in every
backend module. It fixes seven advisories:
Static files were served for paths with . or .. segments
The stricter handling does not change how Jetstream behaves: HSTS and
the Cloud Foundry HTTPS redirect do not depend on Echo's scheme
detection, and the UI's static files never use // or dot segments.
fast-uri moved to 3.1.8: from 3.1.5 in the root and website manifests,
and from 3.1.7 in the devkit. It reaches the UI through ajv, which the
schema widget uses to validate JSON schemas. 3.1.5 was affected by all
three advisories: