Repository navigation
v0.2.7 — dependency maintenance + vitest 5
A dependency-maintenance release rolling up the ten pending updates, including
the vitest 4 → 5 major. No runtime behaviour changed.
Changed
- Runtime dependencies:
hono4.13.5 → 4.13.7 (api, web),
@anthropic-ai/sdk0.122.0 → 0.124.0 (core),@hono/zod-validator0.9.0 →
0.9.1 (api), and@clack/prompts1.7.0 → 1.8.0 (cli). - Dev tooling:
vitestand@vitest/coverage-v84.1.11 → 5.0.0,
@types/node26.2.0 → 26.5.0,@playwright/test1.62.1 → 1.63.0,
@changesets/cli3.0.1 → 3.0.2, andlint-staged17.4.1 → 17.5.0. - Vitest 5 needed no config migration — no
vitest.config.*/
vite.config.*changes and no test changes. Verified across the full CI
matrix (Ubuntu/macOS/Windows × Node 22/24). (#94)
Fixed
stride profilestopped type-checking under@clack/prompts1.8.0. That
release pulls@clack/core1.5.0, which retypesisCancelfrom
(value) => value is symbolto(value) => value is typeof CANCEL_SYMBOL.
The old signature narrowed away all symbols, collapsing aboolean | symbol
union tobooleanafter the guard; the new one narrows only that unique
symbol, and subtracting it from the broadsymbolstill leavessymbol. The
PAR-Q screening loop therefore needed an explicitbooleanassertion at one
call site — sound, becauseisCancelguards with an early return immediately
above and the cancel symbol is the only symbolconfirm()can resolve to.
Type-level only.
Still open
esbuild 0.27.7
(GHSA-g7r4-m6w7-qqqr, low,
dev scope) remains deferred, unchanged from 0.2.6: tsup@8.5.1 pins
esbuild: ^0.27.0, and the vulnerable path is esbuild's own development server,
which tsup never starts.
Full changelog: v0.2.6...v0.2.7