Skip to content

fix(ci): correct Craft version tag (no v prefix) - #34

Merged
BYK merged 2 commits into
mainfrom
fix/craft-version-tag
Jan 22, 2026
Merged

fix(ci): correct Craft version tag (no v prefix)#34
BYK merged 2 commits into
mainfrom
fix/craft-version-tag

Conversation

@BYK

@BYK BYK commented Jan 22, 2026

Copy link
Copy Markdown
Member

Craft tags don't use the v prefix - should be 2.19.0 not v2.19.0.

@github-actions

github-actions Bot commented Jan 22, 2026

Copy link
Copy Markdown
Contributor

Semver Impact of This PR

🟢 Patch (bug fixes)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


Bug Fixes 🐛

  • (ci) Correct Craft version tag (no v prefix) by BYK in #34

🤖 This preview updates automatically when you update the PR.

Comment thread .github/workflows/release.yml Outdated
@BYK
BYK merged commit 758ea59 into main Jan 22, 2026
4 checks passed
@BYK
BYK deleted the fix/craft-version-tag branch January 22, 2026 01:30
BYK added a commit that referenced this pull request Aug 1, 2026
…s lockfile (#1332)

## Summary

Fixes all 13 open Dependabot alerts. No GitHub security advisories are
open.

Bumps the published package minimum to **Node.js 20+** (from 18+) so the
declared `engines.node` matches what the new transitive overrides
(`@hono/node-server@2.0.12`, `brace-expansion@5.0.9`) actually install.

## Background

Post-merge of PR #1254 ("chore: pre-shape repo into pnpm-workspace
monorepo layout"), the docs workspace moved from `docs/` to
`apps/cli-docs/`. The old `docs/package.json` was deleted, but
`docs/pnpm-lock.yaml` was left tracked — referencing the obsolete Astro
6.x / Starlight 0.39 layout. This stale lockfile is the source of 9 of
the 13 open alerts.

The remaining 4 alerts are transitive vulnerabilities in the active root
`pnpm-lock.yaml`:
- `shell-quote@1.8.4` via `react-devtools-core`
- `@hono/node-server@1.19.17` via `@modelcontextprotocol/sdk@1.29.0` →
`@hono/mcp` → `@mastra/client-js`
- `fast-uri@3.1.3` via `ajv` → MCP SDK chain
- `brace-expansion@5.0.7` via `minimatch` → `glob` (via ultracite and
@sentry/bundler-plugins)

## Changes

1. **Delete `docs/pnpm-lock.yaml`** — orphaned lockfile from
pre-monorepo layout; closes alerts #25, #27, #29, #31, #33, #34, #35,
#41, #54.

2. **`pnpm.overrides` in root `package.json`** for the 4 transitive
alerts:

```diff
-"shell-quote@<1.8.4": "1.8.4",
+"shell-quote@<1.9.0": "1.9.0",
 `qs@>=6.11.1 <=6.15.1`: "6.15.2",
 `form-data@<4.0.6`: "4.0.6",
 `vite@>=8.0.0 <8.0.16`: "8.0.16`,
+"@hono/node-server@<2.0.5": "2.0.12",
+"fast-uri@<=3.1.3": "3.1.5",
+"brace-expansion@<5.0.8": "5.0.9"
```

The previous `shell-quote@<1.8.4 → 1.8.4` override was itself vulnerable
(alert #36: `shell-quote <= 1.8.4` is the vulnerable range, patched in
1.9.0), so it is bumped to `<1.9.0 → 1.9.0`.

3. **`engines.node` bump 18 → 20** in root `package.json` and
`packages/cli/package.json`, plus doc updates in:
   - `apps/cli-docs/src/content/docs/library-usage.md`
   - `apps/cli-docs/src/content/docs/migrating-from-v3.md`
- `packages/cli/README.md` (the auto-generated `library-prereq` block
reads from `engines.node` via `generateLibraryPrereq()` in
`generate-docs-sections.ts`, so it picked up the new floor
automatically).

The dev floor (`devEngines.runtime >=22.15`) is unchanged — Node 22.15+
remains the development minimum. The standalone binary continues to
bundle its own Node 22.15+ runtime.

## Verification

- `pnpm audit --prod` → no known vulnerabilities
- `pnpm run check:deps` ✓
- `pnpm run lint` ✓ (951 files)
- `pnpm run typecheck` ✓
- `pnpm test:unit` → 416 files, 8760 tests passing, 13 skipped
- Resolved versions match or exceed each patched minimum:
  - shell-quote 1.9.0 (patched 1.9.0)
  - @hono/node-server 2.0.12 (patched 2.0.5)
  - fast-uri 3.1.5 (patched 3.1.4)
  - brace-expansion 5.0.9 (patched 5.0.8)

## Reviewer notes

**Pin rationale for `@hono/node-server@2.0.12`** — the patched minimum
is 2.0.5, but `packages/cli/package.json` already declares
`"@hono/node-server": "^2.0.6"` as a direct devDependency. Pinning to
2.0.12 (the latest 2.x available at PR time) keeps the override and the
direct declaration in the same major line and avoids a near-term minor
bump. `2.0.5–2.0.11` had no further advisories at the time of writing.

**Lockfile dedupe side effect** — `shell-quote@1.10.0` (already
non-vulnerable, used by `launch-editor`) is consolidated to `1.9.0`
because the override forces single-version resolution. No security
regression; `launch-editor` does not pin a shell-quote range narrower
than what 1.9.0 satisfies.

**Node 18 deprecation** — addresses the F1 SHOULD-FIX from the initial
review. The `>=18.0` floor had become inconsistent with the lockfile
once the overrides pulled in `@hono/node-server@2.0.12` (engines `>=20`)
and `brace-expansion@5.0.9` (engines `20 || >=22`). Both packages are
dev-only transitive deps, so the only users impacted are source-install
users who run the CLI via `node` instead of the standalone binary.
`devEngines.runtime` already required `>=22.15`, so development
environments are unaffected.

## Note

`pnpm audit` (non-prod-only) flags one additional low-severity advisory
— `@ai-sdk/provider-utils@2.2.8` (GHSA-866g-f22w-33x8, CVE-2026-8769,
via @mastra/client-js) — that is not yet in Dependabot. Addressing it
requires bumping @mastra/client-js to a newer major; left out of this PR
to keep scope focused on the explicit GitHub security report.

<sub>Comment `@sentry <feedback>` on this PR to have Autofix iterate on
the changes.</sub>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant