Skip to content

v0.2.3 — dependency maintenance + security patches

Choose a tag to compare

@jaypetez jaypetez released this 07 Aug 17:28
9dcfc58

A dependency-maintenance release: every open Dependabot update has landed, and three high-severity advisories reachable through dev tooling are patched.

Changed

  • Runtime dependencies: hono 4.12.32 → 4.12.34.
  • Dev tooling: @biomejs/biome 2.5.6 → 2.5.7, lint-staged 17.1.1 → 17.3.0, tsx 4.23.1 → 4.23.5, turbo 2.10.7 → 2.10.8, @playwright/test 1.62.0 → 1.62.1, @types/react 19.2.17 → 19.2.18, @types/react-dom 19.2.3 → 19.2.4, @vitejs/plugin-react 6.0.4 → 6.0.5, and vite 8.1.5 → 8.2.0.
  • CI actions: github/codeql-action (init/analyze/upload-sarif) v4.37.3 → v4.37.6, and pnpm/action-setup 6.0.9 → 6.0.10.

Security

  • fast-uri: the overrides pin moves ^3.1.4 → ^3.1.5, patching GHSA-7p8r-x3mc-p8w7 (host confusion via backslash). The pin added in 0.2.2 to close GHSA-v2hh-gcrm-f6hx was itself holding the vulnerable version in place, which had been failing the required audit gate on every open dependency PR.
  • js-yaml: new overrides entries pin the 3.x line to ^3.15.1 and the 4.x line to ^4.3.1, patching GHSA-5p4m-2wfm-xmqj (CVE-2026-59870, quadratic CPU consumption in !!omap resolution). Both are reached through @changesets/cli; because the two consumers sit on different majors, each line is pinned separately rather than forced onto one.

pnpm audit --audit-level=high is clean. No runtime behaviour changed.

All @stride/* packages are versioned in lockstep at 0.2.3. Packages are private, so nothing is published to npm.