Repository navigation
DX | 29-09-2026 | Release - #375
Conversation
The asset UID swap in lookupAssets regex-escaped the UID and then handed it to String.split, which matches literally. A UID holding a regex metacharacter never matched the serialized entry, so the source UID survived the swap and the CMA rejected the entry with "Asset(s) does not exists" - a message that points at the export rather than at the failed rewrite. Escaping now matches the encoding the search actually runs against (JSON), so UIDs with a backslash or a quote work as well, and a swap that changes nothing is recorded as unmatched rather than matched, which keeps a silent failure out of matched-asset-uids.json. updateUids carried the same escape-then-literal-split mismatch for entry UIDs in HTML RTE. It now builds a single alternation from every matching UID, longest first, so a UID that is a prefix of another cannot clobber it and a replacement value cannot be re-scanned by a later pass. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Fifteen packages here required modules at runtime that they never
declared in dependencies, so the published tarballs are only
installable on a package manager that flattens node_modules.
tslib (15 packages). Every TypeScript package compiles with
importHelpers: true, so tsc emits require("tslib") into lib/. Twelve of
them emit helpers and declared nothing; bulk-operations and apps-cli had
tslib in devDependencies, which does not ship. cm-seed, cm-bootstrap and
cli-tsgen emit no helpers today but set importHelpers: true too, so they
are one interop import away from the same break -- declared as well so
the rule stays uniform and checkable.
Four other undeclared runtime imports:
bulk-operations chalk lib/core/rate-limiter.js
cm-export-to-csv lodash require("lodash/find")
migration lodash require("lodash/isEmpty")
content-type diff lib/core/content-type/compare.js
Version ranges follow what the repo already declares elsewhere, so no
new convention is introduced. diff is the one judgement call: it is
undeclared today and resolves transitively via diff2html, which asks for
^8.0.3. Latest diff is 9.x, so ^8.0.3 declares what the code already
runs against rather than taking a silent major bump.
Not touched: cm-regex-validate and cm-export-query already declare
tslib; variants and cm-migrate-rte do not set importHelpers.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
fix(deps): declare tslib, chalk, lodash and diff at runtime
fix(import): remap asset and entry UIDs containing regex metacharacters
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |
fix for reference
🔒 Security Scan Results
⏱️ SLA Breach Summary
ℹ️ Vulnerabilities Without Available Fixes (Informational Only)The following vulnerabilities were detected but do not have fixes available (no upgrade or patch). These are excluded from failure thresholds:
✅ BUILD PASSED - All security checks passed |
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |
No description provided.