Repository navigation
v0.2.5 — dependency maintenance + Changesets v3
A dependency-maintenance release: every open Dependabot update has landed, three high-severity advisories reachable through dev tooling are patched, and the release pipeline is migrated to Changesets v3. No runtime behaviour changed. All @stride/* packages move 0.2.4 → 0.2.5 in lockstep; per-package details are in each package's CHANGELOG.md.
The ten open Dependabot PRs (#68, #79, #82–#89) were consolidated into #90 so pnpm-lock.yaml was regenerated once, rather than serially rebasing every PR under the strict up-to-date-branch policy.
Changed
- Runtime dependencies:
hono4.12.34 → 4.13.5 (api, web, #86),@hono/node-server2.1.0 → 2.1.1 (api, #68),@anthropic-ai/sdk0.116.0 → 0.122.0 (core, #84),@tanstack/react-query5.101.4 → 5.102.8 (web, #83), andzod4.4.3 → 4.5.4 (catalog, #82). - Dev tooling (#89):
@biomejs/biome2.5.7 → 2.5.11,@changesets/cli2.31.1 → 3.0.1,@commitlint/cli21.2.1 → 21.2.2,@commitlint/config-conventional21.2.0 → 21.2.2,vitestand@vitest/coverage-v84.1.10 → 4.1.11,lint-staged17.3.0 → 17.4.1,tsx4.23.12 → 4.23.13,turbo2.10.9 → 2.10.12,@testing-library/react16.3.2 → 16.3.3,@types/react-dom19.2.4 → 19.2.5,@vitejs/plugin-react6.0.5 → 6.1.1,happy-dom20.11.2 → 20.12.0, andvite8.2.1 → 8.2.2. - CI actions:
github/codeql-action(init/analyze/upload-sarif) v4.37.6 → v4.37.9 (#85, #87, #88 — bumped together so theAnalyzejob stays version consistent), andchangesets/actionv1.9.0 → v2.1.1 (#79). - Release pipeline: migrated to Changesets v3. The action's v2 requires CLI v3 and renamed every input the release job passes (
version→version-script,publish→publish-script,commit→commit-message,title→pr-title), dropping theGITHUB_TOKENenv var in favour of agithub-tokeninput; the CLI renamedchangeset tagtochangeset git-tag.
Fixed
- Changesets silently skipped every package under CLI v3:
@changesets/configv4 flips the default ofprivatePackages.versionfromtruetofalse. Every workspace package here is private, sochangeset versionmatched nothing — no version bump, no changelog entries, and the changeset left unconsumed, all while the release job still reported success..changeset/config.jsonnow setsprivatePackagesexplicitly.
Security
fast-uri: theoverridespin moves ^3.1.5 → ^3.1.6 (resolving to 3.1.7), patching GHSA-f65p-4m7j-42xc (SSRF via repeated hostname percent-decoding), GHSA-fph4-wmhf-6fwf, and GHSA-jqff-g426-hqxp (host confusion via percent-encoded scheme normalization). As in 0.2.3, the pin added to close the previous advisory was itself holding a now-vulnerable version in place, failing the requiredauditgate on every open dependency PR. Reached only through dev tooling (@commitlint/cli→@commitlint/load→@commitlint/config-validator→ajv).hono4.13.5 additionally carries upstream fixes for query-parser fragment handling,toSSGpath traversal, and aparseBody({ dot: true })DoS. None are reachable from this codebase's routes, but the bump takes them anyway.
pnpm audit --audit-level=high is clean. No runtime behaviour changed.
All @stride/* packages are versioned in lockstep at 0.2.5. Packages are private, so nothing is published to npm.
Full changelog: v0.2.4...v0.2.5