Repository navigation
fix(deps): bump @contentstack/management to ~1.31.2 and overrides - #2734
Conversation
Move cli and cli-utilities to @contentstack/management ~1.31.2 (resolves security vulnerabilities in its dependencies) and raise the workspace overrides js-yaml 5.4.2 -> 5.4.3 and fast-uri 4.1.5 -> 4.2.1. pnpm-lock.yaml is re-resolved accordingly; no package versions change. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
🔒 Security Scan Results
⏱️ SLA Breach Summary
ℹ️ Vulnerabilities Without Available Fixes (Informational Only)The following vulnerabilities were detected but do not have fixes available (no upgrade or patch). These are excluded from failure thresholds:
Consider reviewing these vulnerabilities when fixes become available. |
1 similar comment
🔒 Security Scan Results
⏱️ SLA Breach Summary
ℹ️ Vulnerabilities Without Available Fixes (Informational Only)The following vulnerabilities were detected but do not have fixes available (no upgrade or patch). These are excluded from failure thresholds:
Consider reviewing these vulnerabilities when fixes become available. |
Problem
@contentstack/cliand@contentstack/cli-utilitiesondevelopmentstill resolve@contentstack/management1.31.1, which carries dependency vulnerabilities fixed upstream in 1.31.2, and the workspace overrides forjs-yamlandfast-uriare behind their patched releases.Fix
@contentstack/management~1.31.1→~1.31.2inpackages/contentstackandpackages/contentstack-utilities(upstream changelog: resolved security vulnerabilities in dependencies).js-yaml5.4.2 → 5.4.3,fast-uri4.1.5 → 4.2.1.pnpm-lock.yamlre-resolved to match:@contentstack/management1.31.2,js-yaml5.4.3,fast-uri4.2.1. No package versions change in this PR.Verification
@contentstack/management1.31.2 is on npm, andpnpm install --lockfile-only --frozen-lockfile(pnpm 10.28.0) confirms the lockfile matches the manifests. The.talismanrcchecksum forpnpm-lock.yamlis refreshed (Talisman flags its sha512 integrity hashes on every lockfile change).