Repository navigation
chore: bump v1 package versions and management sdk to 1.31.2 - #2733
Merged
Merged
Conversation
chore: version bump
Patch-bump cli-auth, cli-command, cli-config and cli-utilities, update every workspace reference to the new versions, move cli-utilities to @contentstack/management ~1.31.2 (resolves security vulnerabilities in its dependencies) and raise the picomatch override to ^4.0.7. pnpm-lock.yaml re-resolved with pnpm install --lockfile-only. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
🔒 Security Scan Results
⏱️ SLA Breach Summary
ℹ️ Vulnerabilities Without Available Fixes (Informational Only)The following vulnerabilities were detected but do not have fixes available (no upgrade or patch). These are excluded from failure thresholds:
Consider reviewing these vulnerabilities when fixes become available. |
reeshika-h
approved these changes
Oct 6, 2026
amit-kanswal-cs
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The v1 release branch
DX-23-09-2026-Releaseis behindv1-legacy— the version bumps merged there in #2732 are not on it yet — and the v1 packages still resolve@contentstack/management1.31.1, which carries dependency vulnerabilities fixed upstream in 1.31.2.Fix
v1-legacyinto the release branch (brings chore: version bump #2732chore: version bump, the launch version bump and the.talismanrccleanup).cli-auth1.8.8 → 1.8.9,cli-command1.8.8 → 1.8.9,cli-config1.21.3 → 1.21.4,cli-utilities1.20.0 → 1.20.1. The rootcontentstackpackage stays at 1.68.0 and now depends on the bumped versions.cli-utilitiesmoves@contentstack/managementto~1.31.2(upstream changelog: resolved security vulnerabilities in dependencies).picomatchoverride raised to^4.0.7.pnpm-lock.yamlre-resolved withpnpm install --lockfile-only(pnpm 10.28.0):@contentstack/management1.31.2 andpicomatch4.0.7 are locked; workspace links are unchanged.Verification
pnpm install --lockfile-onlyresolves cleanly against the registry, and no workspace package still references the old~1.8.8/~1.20.0/~1.21.3versions.