Repository navigation
Releases: jaypetez/stride
Release list
v0.2.12 — dependency maintenance
A dependency maintenance release. Per-package details are in each package's CHANGELOG.md.
Changed
- Runtime deps:
@anthropic-ai/sdk0.127.0 → 0.128.0,@modelcontextprotocol/sdk1.30.0 → 1.30.1. - CI:
github/codeql-action(init/analyze/upload-sarif) 4.38.1 → 4.38.2, all three pinned to the same SHA. - Dev tooling:
vite8.3.0 → 8.3.1,vitestand@vitest/coverage-v85.0.1 → 5.0.2,turbo2.11.1 → 2.11.5,lint-staged17.5.1 → 17.6.0.
Security
esbuild0.27.7 → 0.28.2 (transitive viatsup), fixing a low-severity advisory (GHSA-g7r4-m6w7-qqqr, patched in 0.28.1) with apnpm.overridesentry.
Full changelog: v0.2.11...v0.2.12
v0.2.11 — dependency maintenance
A dependency maintenance release. Per-package details are in each package's CHANGELOG.md.
Changed
- Runtime deps:
hono4.13.7 → 4.13.8,@tanstack/react-query5.102.8 → 5.103.1,dotenv17.4.2 → 18.0.1 (major; every call site already passes{ quiet: true }, so the MCP stdout wire stays clean, and no code changes were needed). - CI:
github/codeql-action(init/analyze/upload-sarif) 4.38.0 → 4.38.1, all three pinned to the same SHA. - Dev tooling:
@commitlint/cliand@commitlint/config-conventional21.2.2 → 21.2.3,@types/node26.5.0 → 26.6.2,tsx4.23.13 → 4.23.15.
Security
ip-address10.3.1 → 10.7.2 (transitive via@modelcontextprotocol/sdk→express-rate-limit), fixing a moderate advisory (GHSA-2vr4-cq9g-pvrc, patched in 10.5.1) with a lockfile-only update.
Full changelog: v0.2.10...v0.2.11
v0.2.10 — vitest 5.0.1 fix
Completes the dependency maintenance batch from 0.2.9: vitest/@vitest/coverage-v8 5.0.0 → 5.0.1, held back at the time after CI showed apps/web typecheck failures.
Changed
-
Dev tooling:
vitest/@vitest/coverage-v85.0.0 → 5.0.1.The earlier failure was not a vitest regression —
@vitest/expect'sAssertiontype declaration is byte-identical between 5.0.0 and 5.0.1 (diffed the packed npm tarballs directly). The real cause: Dependabot's frozen lockfile snapshot resolved two different@types/nodeversions across the two peer-qualifiedvitest@5.0.1variants in the workspace, so@testing-library/jest-dom's vitest type augmentation landed on a different physical vitest instance than the oneapps/web's test files actually imported. Re-resolving the lockfile converges both variants onto a single@types/nodeand fixes it, with no version pin changes beyond the intended bump.
Full changelog: v0.2.9...v0.2.10
v0.2.9 — dependency maintenance batch
Dependency maintenance batch. No runtime behaviour changed outside routine patch/minor bumps to third-party libraries.
Changed
-
Runtime deps:
zod4.5.4 → 4.6.5,@anthropic-ai/sdk0.124.0 → 0.127.0,@clack/prompts1.8.0 → 1.8.1,react/react-dom/@types/react/@types/react-dom19.2.x → 19.3.0. (#107, #109, #106, #104, #105)The
react/react-dompair and the@anthropic-ai/sdkbump each needed a Dependabot rebase to land: React refuses to boot whenreactandreact-domresolve to different versions ("Incompatible React versions"), so the two PRs had to merge back-to-back rather than independently. -
CI:
github/codeql-action(init/analyze/upload-sarif) 4.37.9 → 4.38.0. (#101, #103, #108)initandanalyzepin the same SHA incodeql.yml, so Dependabot's split PRs each showed a version mismatch and failed their ownAnalyzecheck in isolation — same shape as the React pairing above, resolved by merging both. -
Dev tooling:
@biomejs/biome2.5.12 → 2.5.14,@changesets/cli3.0.2 → 3.0.3,lint-staged17.5.0 → 17.5.1,turbo2.10.12 → 2.11.2,happy-dom20.14.0 → 20.14.5,vite8.2.2 → 8.3.0. (#111)vitest/@vitest/coverage-v8are deliberately held at 5.0.0 (Dependabot proposed 5.0.1): bumping them makes@testing-library/jest-dom@7.0.1's vitest module augmentation resolve against the 5.0.1 peer variant, and every jest-dom matcher (toBeInTheDocument, etc.) disappears from theAssertiontype, breakingapps/web's typecheck. Revisit once jest-dom ships a vitest 5.0.1-compatible release.
Full changelog: v0.2.8...v0.2.9
v0.2.8 — js-yaml security patch + CI maintenance
Security and CI maintenance release. No runtime behaviour changed — every change is confined to the dev toolchain and the workflow pins.
Fixed
-
js-yamladvisory GHSA-2883-xcg3-v3hh (high). Thejs-yaml@4override pinned^4.3.1and the lockfile resolved to exactly 4.3.1 — inside the vulnerable range (>=4.0.0 <4.3.2). Both override lines now pin the patched versions (js-yaml@4→^4.3.2,js-yaml@3→^3.15.2).js-yamlreaches the tree transitively via@commitlint/cli > @commitlint/load > cosmiconfig, and Dependabot's security-update job runs withupdate-subdependencies: false, so Dependabot could not fix this itself — its run errored out and the override had to be bumped by hand.The advisory was failing the
auditjob, which fails the aggregatebuildgate — the single required check onmain— and so had the entire Dependabot queue blocked. (#98)
Changed
- CI actions:
pnpm/action-setup6.0.10 → 6.1.0 (#96) andchangesets/action2.1.1 → 2.1.2 (#97). The latter is patch-only (no input renames), so the pin's documented lockstep with@changesets/cliv3 still holds.
Full changelog: v0.2.7...v0.2.8
v0.2.7 — dependency maintenance + vitest 5
A dependency-maintenance release rolling up the ten pending updates, including
the vitest 4 → 5 major. No runtime behaviour changed.
Changed
- Runtime dependencies:
hono4.13.5 → 4.13.7 (api, web),
@anthropic-ai/sdk0.122.0 → 0.124.0 (core),@hono/zod-validator0.9.0 →
0.9.1 (api), and@clack/prompts1.7.0 → 1.8.0 (cli). - Dev tooling:
vitestand@vitest/coverage-v84.1.11 → 5.0.0,
@types/node26.2.0 → 26.5.0,@playwright/test1.62.1 → 1.63.0,
@changesets/cli3.0.1 → 3.0.2, andlint-staged17.4.1 → 17.5.0. - Vitest 5 needed no config migration — no
vitest.config.*/
vite.config.*changes and no test changes. Verified across the full CI
matrix (Ubuntu/macOS/Windows × Node 22/24). (#94)
Fixed
stride profilestopped type-checking under@clack/prompts1.8.0. That
release pulls@clack/core1.5.0, which retypesisCancelfrom
(value) => value is symbolto(value) => value is typeof CANCEL_SYMBOL.
The old signature narrowed away all symbols, collapsing aboolean | symbol
union tobooleanafter the guard; the new one narrows only that unique
symbol, and subtracting it from the broadsymbolstill leavessymbol. The
PAR-Q screening loop therefore needed an explicitbooleanassertion at one
call site — sound, becauseisCancelguards with an early return immediately
above and the cancel symbol is the only symbolconfirm()can resolve to.
Type-level only.
Still open
esbuild 0.27.7
(GHSA-g7r4-m6w7-qqqr, low,
dev scope) remains deferred, unchanged from 0.2.6: tsup@8.5.1 pins
esbuild: ^0.27.0, and the vulnerable path is esbuild's own development server,
which tsup never starts.
Full changelog: v0.2.6...v0.2.7
v0.2.6 — qs security patch
A security-patch release. It moves the qs transitive dependency to 6.16.0,
clearing two moderate advisories from the runtime dependency tree. No runtime
behaviour changed.
Security
qs6.15.3 → 6.16.0, clearing two moderate advisories:
GHSA-4mjr-xmp4-gh2g
(denial of service via attacker-controlledisBuffer) and
GHSA-x5fp-wj9c-mxmx
(array-limit bypass via bracket-key comma parsing). Both alerts were
runtime scope —qsis reached through
@stride/mcp > @modelcontextprotocol/sdk > express > body-parser.
body-parser@2.3.0declaresqs: ^6.15.2andexpress@5.2.1declares
^6.14.0, so 6.16.0 satisfies both parents and needs nopnpm.overrides
pin — only the lockfile was holding the stale resolution. (#92)
Knowingly deferred
esbuild 0.27.7
(GHSA-g7r4-m6w7-qqqr,
low, dev scope) is left in place. tsup@8.5.1 — the current latest — pins
esbuild: ^0.27.0, so 0.28.1+ cannot be reached without forcing an override
against its declared range, and the vulnerable path is esbuild's own
development server, which tsup never starts. vite@8.2.2 already resolves
esbuild 0.28.2 independently. To be revisited when tsup widens its range.
Full changelog: v0.2.5...v0.2.6
v0.2.5 — dependency maintenance + Changesets v3
A dependency-maintenance release: every open Dependabot update has landed, three high-severity advisories reachable through dev tooling are patched, and the release pipeline is migrated to Changesets v3. No runtime behaviour changed. All @stride/* packages move 0.2.4 → 0.2.5 in lockstep; per-package details are in each package's CHANGELOG.md.
The ten open Dependabot PRs (#68, #79, #82–#89) were consolidated into #90 so pnpm-lock.yaml was regenerated once, rather than serially rebasing every PR under the strict up-to-date-branch policy.
Changed
- Runtime dependencies:
hono4.12.34 → 4.13.5 (api, web, #86),@hono/node-server2.1.0 → 2.1.1 (api, #68),@anthropic-ai/sdk0.116.0 → 0.122.0 (core, #84),@tanstack/react-query5.101.4 → 5.102.8 (web, #83), andzod4.4.3 → 4.5.4 (catalog, #82). - Dev tooling (#89):
@biomejs/biome2.5.7 → 2.5.11,@changesets/cli2.31.1 → 3.0.1,@commitlint/cli21.2.1 → 21.2.2,@commitlint/config-conventional21.2.0 → 21.2.2,vitestand@vitest/coverage-v84.1.10 → 4.1.11,lint-staged17.3.0 → 17.4.1,tsx4.23.12 → 4.23.13,turbo2.10.9 → 2.10.12,@testing-library/react16.3.2 → 16.3.3,@types/react-dom19.2.4 → 19.2.5,@vitejs/plugin-react6.0.5 → 6.1.1,happy-dom20.11.2 → 20.12.0, andvite8.2.1 → 8.2.2. - CI actions:
github/codeql-action(init/analyze/upload-sarif) v4.37.6 → v4.37.9 (#85, #87, #88 — bumped together so theAnalyzejob stays version consistent), andchangesets/actionv1.9.0 → v2.1.1 (#79). - Release pipeline: migrated to Changesets v3. The action's v2 requires CLI v3 and renamed every input the release job passes (
version→version-script,publish→publish-script,commit→commit-message,title→pr-title), dropping theGITHUB_TOKENenv var in favour of agithub-tokeninput; the CLI renamedchangeset tagtochangeset git-tag.
Fixed
- Changesets silently skipped every package under CLI v3:
@changesets/configv4 flips the default ofprivatePackages.versionfromtruetofalse. Every workspace package here is private, sochangeset versionmatched nothing — no version bump, no changelog entries, and the changeset left unconsumed, all while the release job still reported success..changeset/config.jsonnow setsprivatePackagesexplicitly.
Security
fast-uri: theoverridespin moves ^3.1.5 → ^3.1.6 (resolving to 3.1.7), patching GHSA-f65p-4m7j-42xc (SSRF via repeated hostname percent-decoding), GHSA-fph4-wmhf-6fwf, and GHSA-jqff-g426-hqxp (host confusion via percent-encoded scheme normalization). As in 0.2.3, the pin added to close the previous advisory was itself holding a now-vulnerable version in place, failing the requiredauditgate on every open dependency PR. Reached only through dev tooling (@commitlint/cli→@commitlint/load→@commitlint/config-validator→ajv).hono4.13.5 additionally carries upstream fixes for query-parser fragment handling,toSSGpath traversal, and aparseBody({ dot: true })DoS. None are reachable from this codebase's routes, but the bump takes them anyway.
pnpm audit --audit-level=high is clean. No runtime behaviour changed.
All @stride/* packages are versioned in lockstep at 0.2.5. Packages are private, so nothing is published to npm.
Full changelog: v0.2.4...v0.2.5
v0.2.4 — dependency maintenance
A dependency-maintenance release rolling up the three open Dependabot updates. No runtime behaviour changed. All @stride/* packages move 0.2.3 → 0.2.4 in lockstep; per-package details are in each package's CHANGELOG.md.
Changed
- Runtime dependencies:
@anthropic-ai/sdk0.115.0 → 0.116.0 (core, #64) and@hono/node-server2.0.12 → 2.1.0 (api, #63). - Dev tooling (#62):
@types/node26.1.2 → 26.2.0,tsx4.23.5 → 4.23.12,turbo2.10.8 → 2.10.9,@testing-library/jest-dom7.0.0 → 7.0.1,happy-dom20.11.1 → 20.11.2, andvite8.2.0 → 8.2.1.
Full changelog: v0.2.3...v0.2.4
v0.2.3 — dependency maintenance + security patches
A dependency-maintenance release: every open Dependabot update has landed, and three high-severity advisories reachable through dev tooling are patched.
Changed
- Runtime dependencies:
hono4.12.32 → 4.12.34. - Dev tooling:
@biomejs/biome2.5.6 → 2.5.7,lint-staged17.1.1 → 17.3.0,tsx4.23.1 → 4.23.5,turbo2.10.7 → 2.10.8,@playwright/test1.62.0 → 1.62.1,@types/react19.2.17 → 19.2.18,@types/react-dom19.2.3 → 19.2.4,@vitejs/plugin-react6.0.4 → 6.0.5, andvite8.1.5 → 8.2.0. - CI actions:
github/codeql-action(init/analyze/upload-sarif) v4.37.3 → v4.37.6, andpnpm/action-setup6.0.9 → 6.0.10.
Security
fast-uri: theoverridespin moves ^3.1.4 → ^3.1.5, patching GHSA-7p8r-x3mc-p8w7 (host confusion via backslash). The pin added in 0.2.2 to close GHSA-v2hh-gcrm-f6hx was itself holding the vulnerable version in place, which had been failing the requiredauditgate on every open dependency PR.js-yaml: newoverridesentries pin the 3.x line to ^3.15.1 and the 4.x line to ^4.3.1, patching GHSA-5p4m-2wfm-xmqj (CVE-2026-59870, quadratic CPU consumption in!!omapresolution). Both are reached through@changesets/cli; because the two consumers sit on different majors, each line is pinned separately rather than forced onto one.
pnpm audit --audit-level=high is clean. No runtime behaviour changed.
All @stride/* packages are versioned in lockstep at 0.2.3. Packages are private, so nothing is published to npm.