Skip to content

Releases: jaypetez/stride

v0.2.12 — dependency maintenance

Choose a tag to compare

@jaypetez jaypetez released this 03 Oct 02:52
913746d

A dependency maintenance release. Per-package details are in each package's CHANGELOG.md.

Changed

  • Runtime deps: @anthropic-ai/sdk 0.127.0 → 0.128.0, @modelcontextprotocol/sdk 1.30.0 → 1.30.1.
  • CI: github/codeql-action (init/analyze/upload-sarif) 4.38.1 → 4.38.2, all three pinned to the same SHA.
  • Dev tooling: vite 8.3.0 → 8.3.1, vitest and @vitest/coverage-v8 5.0.1 → 5.0.2, turbo 2.11.1 → 2.11.5, lint-staged 17.5.1 → 17.6.0.

Security

  • esbuild 0.27.7 → 0.28.2 (transitive via tsup), fixing a low-severity advisory (GHSA-g7r4-m6w7-qqqr, patched in 0.28.1) with a pnpm.overrides entry.

Full changelog: v0.2.11...v0.2.12

v0.2.11 — dependency maintenance

Choose a tag to compare

@jaypetez jaypetez released this 29 Sep 22:07
9d35184

A dependency maintenance release. Per-package details are in each package's CHANGELOG.md.

Changed

  • Runtime deps: hono 4.13.7 → 4.13.8, @tanstack/react-query 5.102.8 → 5.103.1, dotenv 17.4.2 → 18.0.1 (major; every call site already passes { quiet: true }, so the MCP stdout wire stays clean, and no code changes were needed).
  • CI: github/codeql-action (init/analyze/upload-sarif) 4.38.0 → 4.38.1, all three pinned to the same SHA.
  • Dev tooling: @commitlint/cli and @commitlint/config-conventional 21.2.2 → 21.2.3, @types/node 26.5.0 → 26.6.2, tsx 4.23.13 → 4.23.15.

Security

  • ip-address 10.3.1 → 10.7.2 (transitive via @modelcontextprotocol/sdk → express-rate-limit), fixing a moderate advisory (GHSA-2vr4-cq9g-pvrc, patched in 10.5.1) with a lockfile-only update.

Full changelog: v0.2.10...v0.2.11

v0.2.10 — vitest 5.0.1 fix

Choose a tag to compare

@jaypetez jaypetez released this 21 Sep 21:36
7a6b765

Completes the dependency maintenance batch from 0.2.9: vitest/@vitest/coverage-v8 5.0.0 → 5.0.1, held back at the time after CI showed apps/web typecheck failures.

Changed

  • Dev tooling: vitest/@vitest/coverage-v8 5.0.0 → 5.0.1.

    The earlier failure was not a vitest regression — @vitest/expect's Assertion type declaration is byte-identical between 5.0.0 and 5.0.1 (diffed the packed npm tarballs directly). The real cause: Dependabot's frozen lockfile snapshot resolved two different @types/node versions across the two peer-qualified vitest@5.0.1 variants in the workspace, so @testing-library/jest-dom's vitest type augmentation landed on a different physical vitest instance than the one apps/web's test files actually imported. Re-resolving the lockfile converges both variants onto a single @types/node and fixes it, with no version pin changes beyond the intended bump.

Full changelog: v0.2.9...v0.2.10

v0.2.9 — dependency maintenance batch

Choose a tag to compare

@jaypetez jaypetez released this 21 Sep 21:17
ee147fe

Dependency maintenance batch. No runtime behaviour changed outside routine patch/minor bumps to third-party libraries.

Changed

  • Runtime deps: zod 4.5.4 → 4.6.5, @anthropic-ai/sdk 0.124.0 → 0.127.0, @clack/prompts 1.8.0 → 1.8.1, react/react-dom/@types/react/@types/react-dom 19.2.x → 19.3.0. (#107, #109, #106, #104, #105)

    The react/react-dom pair and the @anthropic-ai/sdk bump each needed a Dependabot rebase to land: React refuses to boot when react and react-dom resolve to different versions ("Incompatible React versions"), so the two PRs had to merge back-to-back rather than independently.

  • CI: github/codeql-action (init/analyze/upload-sarif) 4.37.9 → 4.38.0. (#101, #103, #108)

    init and analyze pin the same SHA in codeql.yml, so Dependabot's split PRs each showed a version mismatch and failed their own Analyze check in isolation — same shape as the React pairing above, resolved by merging both.

  • Dev tooling: @biomejs/biome 2.5.12 → 2.5.14, @changesets/cli 3.0.2 → 3.0.3, lint-staged 17.5.0 → 17.5.1, turbo 2.10.12 → 2.11.2, happy-dom 20.14.0 → 20.14.5, vite 8.2.2 → 8.3.0. (#111)

    vitest/@vitest/coverage-v8 are deliberately held at 5.0.0 (Dependabot proposed 5.0.1): bumping them makes @testing-library/jest-dom@7.0.1's vitest module augmentation resolve against the 5.0.1 peer variant, and every jest-dom matcher (toBeInTheDocument, etc.) disappears from the Assertion type, breaking apps/web's typecheck. Revisit once jest-dom ships a vitest 5.0.1-compatible release.

Full changelog: v0.2.8...v0.2.9

v0.2.8 — js-yaml security patch + CI maintenance

Choose a tag to compare

@jaypetez jaypetez released this 14 Sep 04:57
7a09a93

Security and CI maintenance release. No runtime behaviour changed — every change is confined to the dev toolchain and the workflow pins.

Fixed

  • js-yaml advisory GHSA-2883-xcg3-v3hh (high). The js-yaml@4 override pinned ^4.3.1 and the lockfile resolved to exactly 4.3.1 — inside the vulnerable range (>=4.0.0 <4.3.2). Both override lines now pin the patched versions (js-yaml@4 → ^4.3.2, js-yaml@3 → ^3.15.2).

    js-yaml reaches the tree transitively via @commitlint/cli > @commitlint/load > cosmiconfig, and Dependabot's security-update job runs with update-subdependencies: false, so Dependabot could not fix this itself — its run errored out and the override had to be bumped by hand.

    The advisory was failing the audit job, which fails the aggregate build gate — the single required check on main — and so had the entire Dependabot queue blocked. (#98)

Changed

  • CI actions: pnpm/action-setup 6.0.10 → 6.1.0 (#96) and changesets/action 2.1.1 → 2.1.2 (#97). The latter is patch-only (no input renames), so the pin's documented lockstep with @changesets/cli v3 still holds.

Full changelog: v0.2.7...v0.2.8

v0.2.7 — dependency maintenance + vitest 5

Choose a tag to compare

@jaypetez jaypetez released this 08 Sep 17:24
ec81cd9

A dependency-maintenance release rolling up the ten pending updates, including
the vitest 4 → 5 major. No runtime behaviour changed.

Changed

  • Runtime dependencies: hono 4.13.5 → 4.13.7 (api, web),
    @anthropic-ai/sdk 0.122.0 → 0.124.0 (core), @hono/zod-validator 0.9.0 →
    0.9.1 (api), and @clack/prompts 1.7.0 → 1.8.0 (cli).
  • Dev tooling: vitest and @vitest/coverage-v8 4.1.11 → 5.0.0,
    @types/node 26.2.0 → 26.5.0, @playwright/test 1.62.1 → 1.63.0,
    @changesets/cli 3.0.1 → 3.0.2, and lint-staged 17.4.1 → 17.5.0.
  • Vitest 5 needed no config migration — no vitest.config.* /
    vite.config.* changes and no test changes. Verified across the full CI
    matrix (Ubuntu/macOS/Windows × Node 22/24). (#94)

Fixed

  • stride profile stopped type-checking under @clack/prompts 1.8.0. That
    release pulls @clack/core 1.5.0, which retypes isCancel from
    (value) => value is symbol to (value) => value is typeof CANCEL_SYMBOL.
    The old signature narrowed away all symbols, collapsing a boolean | symbol
    union to boolean after the guard; the new one narrows only that unique
    symbol, and subtracting it from the broad symbol still leaves symbol. The
    PAR-Q screening loop therefore needed an explicit boolean assertion at one
    call site — sound, because isCancel guards with an early return immediately
    above and the cancel symbol is the only symbol confirm() can resolve to.
    Type-level only.

Still open

esbuild 0.27.7
(GHSA-g7r4-m6w7-qqqr, low,
dev scope) remains deferred, unchanged from 0.2.6: tsup@8.5.1 pins
esbuild: ^0.27.0, and the vulnerable path is esbuild's own development server,
which tsup never starts.

Full changelog: v0.2.6...v0.2.7

v0.2.6 — qs security patch

Choose a tag to compare

@jaypetez jaypetez released this 08 Sep 17:09
3cb1405

A security-patch release. It moves the qs transitive dependency to 6.16.0,
clearing two moderate advisories from the runtime dependency tree. No runtime
behaviour changed.

Security

  • qs 6.15.3 → 6.16.0, clearing two moderate advisories:
    GHSA-4mjr-xmp4-gh2g
    (denial of service via attacker-controlled isBuffer) and
    GHSA-x5fp-wj9c-mxmx
    (array-limit bypass via bracket-key comma parsing). Both alerts were
    runtime scope — qs is reached through
    @stride/mcp > @modelcontextprotocol/sdk > express > body-parser.
    body-parser@2.3.0 declares qs: ^6.15.2 and express@5.2.1 declares
    ^6.14.0, so 6.16.0 satisfies both parents and needs no pnpm.overrides
    pin — only the lockfile was holding the stale resolution. (#92)

Knowingly deferred

esbuild 0.27.7
(GHSA-g7r4-m6w7-qqqr,
low, dev scope) is left in place. tsup@8.5.1 — the current latest — pins
esbuild: ^0.27.0, so 0.28.1+ cannot be reached without forcing an override
against its declared range, and the vulnerable path is esbuild's own
development server, which tsup never starts. vite@8.2.2 already resolves
esbuild 0.28.2 independently. To be revisited when tsup widens its range.

Full changelog: v0.2.5...v0.2.6

v0.2.5 — dependency maintenance + Changesets v3

Choose a tag to compare

@jaypetez jaypetez released this 03 Sep 23:14
4fa3aff

A dependency-maintenance release: every open Dependabot update has landed, three high-severity advisories reachable through dev tooling are patched, and the release pipeline is migrated to Changesets v3. No runtime behaviour changed. All @stride/* packages move 0.2.4 → 0.2.5 in lockstep; per-package details are in each package's CHANGELOG.md.

The ten open Dependabot PRs (#68, #79, #82–#89) were consolidated into #90 so pnpm-lock.yaml was regenerated once, rather than serially rebasing every PR under the strict up-to-date-branch policy.

Changed

  • Runtime dependencies: hono 4.12.34 → 4.13.5 (api, web, #86), @hono/node-server 2.1.0 → 2.1.1 (api, #68), @anthropic-ai/sdk 0.116.0 → 0.122.0 (core, #84), @tanstack/react-query 5.101.4 → 5.102.8 (web, #83), and zod 4.4.3 → 4.5.4 (catalog, #82).
  • Dev tooling (#89): @biomejs/biome 2.5.7 → 2.5.11, @changesets/cli 2.31.1 → 3.0.1, @commitlint/cli 21.2.1 → 21.2.2, @commitlint/config-conventional 21.2.0 → 21.2.2, vitest and @vitest/coverage-v8 4.1.10 → 4.1.11, lint-staged 17.3.0 → 17.4.1, tsx 4.23.12 → 4.23.13, turbo 2.10.9 → 2.10.12, @testing-library/react 16.3.2 → 16.3.3, @types/react-dom 19.2.4 → 19.2.5, @vitejs/plugin-react 6.0.5 → 6.1.1, happy-dom 20.11.2 → 20.12.0, and vite 8.2.1 → 8.2.2.
  • CI actions: github/codeql-action (init/analyze/upload-sarif) v4.37.6 → v4.37.9 (#85, #87, #88 — bumped together so the Analyze job stays version consistent), and changesets/action v1.9.0 → v2.1.1 (#79).
  • Release pipeline: migrated to Changesets v3. The action's v2 requires CLI v3 and renamed every input the release job passes (version → version-script, publish → publish-script, commit → commit-message, title → pr-title), dropping the GITHUB_TOKEN env var in favour of a github-token input; the CLI renamed changeset tag to changeset git-tag.

Fixed

  • Changesets silently skipped every package under CLI v3: @changesets/config v4 flips the default of privatePackages.version from true to false. Every workspace package here is private, so changeset version matched nothing — no version bump, no changelog entries, and the changeset left unconsumed, all while the release job still reported success. .changeset/config.json now sets privatePackages explicitly.

Security

  • fast-uri: the overrides pin moves ^3.1.5 → ^3.1.6 (resolving to 3.1.7), patching GHSA-f65p-4m7j-42xc (SSRF via repeated hostname percent-decoding), GHSA-fph4-wmhf-6fwf, and GHSA-jqff-g426-hqxp (host confusion via percent-encoded scheme normalization). As in 0.2.3, the pin added to close the previous advisory was itself holding a now-vulnerable version in place, failing the required audit gate on every open dependency PR. Reached only through dev tooling (@commitlint/cli → @commitlint/load → @commitlint/config-validator → ajv).
  • hono 4.13.5 additionally carries upstream fixes for query-parser fragment handling, toSSG path traversal, and a parseBody({ dot: true }) DoS. None are reachable from this codebase's routes, but the bump takes them anyway.

pnpm audit --audit-level=high is clean. No runtime behaviour changed.

All @stride/* packages are versioned in lockstep at 0.2.5. Packages are private, so nothing is published to npm.

Full changelog: v0.2.4...v0.2.5

v0.2.4 — dependency maintenance

Choose a tag to compare

@jaypetez jaypetez released this 14 Aug 06:51
1780544

A dependency-maintenance release rolling up the three open Dependabot updates. No runtime behaviour changed. All @stride/* packages move 0.2.3 → 0.2.4 in lockstep; per-package details are in each package's CHANGELOG.md.

Changed

  • Runtime dependencies: @anthropic-ai/sdk 0.115.0 → 0.116.0 (core, #64) and @hono/node-server 2.0.12 → 2.1.0 (api, #63).
  • Dev tooling (#62): @types/node 26.1.2 → 26.2.0, tsx 4.23.5 → 4.23.12, turbo 2.10.8 → 2.10.9, @testing-library/jest-dom 7.0.0 → 7.0.1, happy-dom 20.11.1 → 20.11.2, and vite 8.2.0 → 8.2.1.

Full changelog: v0.2.3...v0.2.4

v0.2.3 — dependency maintenance + security patches

Choose a tag to compare

@jaypetez jaypetez released this 07 Aug 17:28
9dcfc58

A dependency-maintenance release: every open Dependabot update has landed, and three high-severity advisories reachable through dev tooling are patched.

Changed

  • Runtime dependencies: hono 4.12.32 → 4.12.34.
  • Dev tooling: @biomejs/biome 2.5.6 → 2.5.7, lint-staged 17.1.1 → 17.3.0, tsx 4.23.1 → 4.23.5, turbo 2.10.7 → 2.10.8, @playwright/test 1.62.0 → 1.62.1, @types/react 19.2.17 → 19.2.18, @types/react-dom 19.2.3 → 19.2.4, @vitejs/plugin-react 6.0.4 → 6.0.5, and vite 8.1.5 → 8.2.0.
  • CI actions: github/codeql-action (init/analyze/upload-sarif) v4.37.3 → v4.37.6, and pnpm/action-setup 6.0.9 → 6.0.10.

Security

  • fast-uri: the overrides pin moves ^3.1.4 → ^3.1.5, patching GHSA-7p8r-x3mc-p8w7 (host confusion via backslash). The pin added in 0.2.2 to close GHSA-v2hh-gcrm-f6hx was itself holding the vulnerable version in place, which had been failing the required audit gate on every open dependency PR.
  • js-yaml: new overrides entries pin the 3.x line to ^3.15.1 and the 4.x line to ^4.3.1, patching GHSA-5p4m-2wfm-xmqj (CVE-2026-59870, quadratic CPU consumption in !!omap resolution). Both are reached through @changesets/cli; because the two consumers sit on different majors, each line is pinned separately rather than forced onto one.

pnpm audit --audit-level=high is clean. No runtime behaviour changed.

All @stride/* packages are versioned in lockstep at 0.2.3. Packages are private, so nothing is published to npm.