Skip to content

chore: bump v1 package versions and management sdk to 1.31.2 - #2733

Merged
cs-raj merged 5 commits into
DX-23-09-2026-Releasefrom
fix/version-bump
Oct 6, 2026
Merged

cs-raj merged 5 commits into
DX-23-09-2026-Releasefrom
fix/version-bump

Conversation

@cs-raj

@cs-raj cs-raj commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Problem

The v1 release branch DX-23-09-2026-Release is behind v1-legacy — the version bumps merged there in #2732 are not on it yet — and the v1 packages still resolve @contentstack/management 1.31.1, which carries dependency vulnerabilities fixed upstream in 1.31.2.

Fix

  • Merge v1-legacy into the release branch (brings chore: version bump #2732 chore: version bump, the launch version bump and the .talismanrc cleanup).
  • Patch-bump the v1 packages and every workspace reference to them: cli-auth 1.8.8 → 1.8.9, cli-command 1.8.8 → 1.8.9, cli-config 1.21.3 → 1.21.4, cli-utilities 1.20.0 → 1.20.1. The root contentstack package stays at 1.68.0 and now depends on the bumped versions.
  • cli-utilities moves @contentstack/management to ~1.31.2 (upstream changelog: resolved security vulnerabilities in dependencies).
  • Root picomatch override raised to ^4.0.7.
  • pnpm-lock.yaml re-resolved with pnpm install --lockfile-only (pnpm 10.28.0): @contentstack/management 1.31.2 and picomatch 4.0.7 are locked; workspace links are unchanged.

Verification

pnpm install --lockfile-only resolves cleanly against the registry, and no workspace package still references the old ~1.8.8 / ~1.20.0 / ~1.21.3 versions.

cs-raj and others added 5 commits September 29, 2026 14:57
Patch-bump cli-auth, cli-command, cli-config and cli-utilities, update every
workspace reference to the new versions, move cli-utilities to
@contentstack/management ~1.31.2 (resolves security vulnerabilities in its
dependencies) and raise the picomatch override to ^4.0.7. pnpm-lock.yaml
re-resolved with pnpm install --lockfile-only.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@cs-raj cs-raj self-assigned this Oct 6, 2026
@snyk-io

snyk-io Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 0 0 10 ✅ Passed
🟠 High Severity 0 7 25 ✅ Passed
🟡 Medium Severity 1 45 500 ✅ Passed
🔵 Low Severity 0 0 1000 ✅ Passed

⏱️ SLA Breach Summary

⚠️ Warning: The following vulnerabilities have exceeded their SLA thresholds (days since publication).

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 0 0 15 / 30 days ✅ Passed
🟠 High 0 0 30 / 120 days ✅ Passed
🟡 Medium 0 1 90 / 365 days ⚠️ Warning
🔵 Low 0 0 180 / 365 days ✅ Passed

ℹ️ Vulnerabilities Without Available Fixes (Informational Only)

The following vulnerabilities were detected but do not have fixes available (no upgrade or patch). These are excluded from failure thresholds:

  • Critical without fixes: 0
  • High without fixes: 7
  • Medium without fixes: 45
  • Low without fixes: 0

⚠️ BUILD PASSED WITH WARNINGS - SLA breaches detected for issues without available fixes

Consider reviewing these vulnerabilities when fixes become available.

@cs-raj
cs-raj merged commit f30eb61 into DX-23-09-2026-Release Oct 6, 2026
11 checks passed
@cs-raj
cs-raj deleted the fix/version-bump branch October 6, 2026 06:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants