Skip to content

v0.2.5 — dependency maintenance + Changesets v3

Choose a tag to compare

@jaypetez jaypetez released this 03 Sep 23:14
4fa3aff

A dependency-maintenance release: every open Dependabot update has landed, three high-severity advisories reachable through dev tooling are patched, and the release pipeline is migrated to Changesets v3. No runtime behaviour changed. All @stride/* packages move 0.2.4 → 0.2.5 in lockstep; per-package details are in each package's CHANGELOG.md.

The ten open Dependabot PRs (#68, #79, #82–#89) were consolidated into #90 so pnpm-lock.yaml was regenerated once, rather than serially rebasing every PR under the strict up-to-date-branch policy.

Changed

  • Runtime dependencies: hono 4.12.34 → 4.13.5 (api, web, #86), @hono/node-server 2.1.0 → 2.1.1 (api, #68), @anthropic-ai/sdk 0.116.0 → 0.122.0 (core, #84), @tanstack/react-query 5.101.4 → 5.102.8 (web, #83), and zod 4.4.3 → 4.5.4 (catalog, #82).
  • Dev tooling (#89): @biomejs/biome 2.5.7 → 2.5.11, @changesets/cli 2.31.1 → 3.0.1, @commitlint/cli 21.2.1 → 21.2.2, @commitlint/config-conventional 21.2.0 → 21.2.2, vitest and @vitest/coverage-v8 4.1.10 → 4.1.11, lint-staged 17.3.0 → 17.4.1, tsx 4.23.12 → 4.23.13, turbo 2.10.9 → 2.10.12, @testing-library/react 16.3.2 → 16.3.3, @types/react-dom 19.2.4 → 19.2.5, @vitejs/plugin-react 6.0.5 → 6.1.1, happy-dom 20.11.2 → 20.12.0, and vite 8.2.1 → 8.2.2.
  • CI actions: github/codeql-action (init/analyze/upload-sarif) v4.37.6 → v4.37.9 (#85, #87, #88 — bumped together so the Analyze job stays version consistent), and changesets/action v1.9.0 → v2.1.1 (#79).
  • Release pipeline: migrated to Changesets v3. The action's v2 requires CLI v3 and renamed every input the release job passes (version → version-script, publish → publish-script, commit → commit-message, title → pr-title), dropping the GITHUB_TOKEN env var in favour of a github-token input; the CLI renamed changeset tag to changeset git-tag.

Fixed

  • Changesets silently skipped every package under CLI v3: @changesets/config v4 flips the default of privatePackages.version from true to false. Every workspace package here is private, so changeset version matched nothing — no version bump, no changelog entries, and the changeset left unconsumed, all while the release job still reported success. .changeset/config.json now sets privatePackages explicitly.

Security

  • fast-uri: the overrides pin moves ^3.1.5 → ^3.1.6 (resolving to 3.1.7), patching GHSA-f65p-4m7j-42xc (SSRF via repeated hostname percent-decoding), GHSA-fph4-wmhf-6fwf, and GHSA-jqff-g426-hqxp (host confusion via percent-encoded scheme normalization). As in 0.2.3, the pin added to close the previous advisory was itself holding a now-vulnerable version in place, failing the required audit gate on every open dependency PR. Reached only through dev tooling (@commitlint/cli → @commitlint/load → @commitlint/config-validator → ajv).
  • hono 4.13.5 additionally carries upstream fixes for query-parser fragment handling, toSSG path traversal, and a parseBody({ dot: true }) DoS. None are reachable from this codebase's routes, but the bump takes them anyway.

pnpm audit --audit-level=high is clean. No runtime behaviour changed.

All @stride/* packages are versioned in lockstep at 0.2.5. Packages are private, so nothing is published to npm.

Full changelog: v0.2.4...v0.2.5