Repository navigation
v0.2.3 — dependency maintenance + security patches
A dependency-maintenance release: every open Dependabot update has landed, and three high-severity advisories reachable through dev tooling are patched.
Changed
- Runtime dependencies:
hono4.12.32 → 4.12.34. - Dev tooling:
@biomejs/biome2.5.6 → 2.5.7,lint-staged17.1.1 → 17.3.0,tsx4.23.1 → 4.23.5,turbo2.10.7 → 2.10.8,@playwright/test1.62.0 → 1.62.1,@types/react19.2.17 → 19.2.18,@types/react-dom19.2.3 → 19.2.4,@vitejs/plugin-react6.0.4 → 6.0.5, andvite8.1.5 → 8.2.0. - CI actions:
github/codeql-action(init/analyze/upload-sarif) v4.37.3 → v4.37.6, andpnpm/action-setup6.0.9 → 6.0.10.
Security
fast-uri: theoverridespin moves ^3.1.4 → ^3.1.5, patching GHSA-7p8r-x3mc-p8w7 (host confusion via backslash). The pin added in 0.2.2 to close GHSA-v2hh-gcrm-f6hx was itself holding the vulnerable version in place, which had been failing the requiredauditgate on every open dependency PR.js-yaml: newoverridesentries pin the 3.x line to ^3.15.1 and the 4.x line to ^4.3.1, patching GHSA-5p4m-2wfm-xmqj (CVE-2026-59870, quadratic CPU consumption in!!omapresolution). Both are reached through@changesets/cli; because the two consumers sit on different majors, each line is pinned separately rather than forced onto one.
pnpm audit --audit-level=high is clean. No runtime behaviour changed.
All @stride/* packages are versioned in lockstep at 0.2.3. Packages are private, so nothing is published to npm.