Skip to content

chore: bump v1 plugin versions for the release - #377

Merged
cs-raj merged 4 commits into
DX-23-09-2026-Releasefrom
fix/version-bump
Oct 6, 2026
Merged

cs-raj merged 4 commits into
DX-23-09-2026-Releasefrom
fix/version-bump

Conversation

@cs-raj

@cs-raj cs-raj commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Problem

The v1 plugins on the release branch still depend on the previous core packages (cli-command ~1.8.7, cli-utilities ~1.19.2, cli-config ~1.21.2, cli-auth ~1.8.7) and on @contentstack/management ^1.31.1 / @contentstack/delivery-sdk ^5.6.0, and their own versions have not been bumped for the fixes already merged on this branch (tslib runtime dependency, audit skipConfirm).

Fix

  • Bump every v1 plugin for the release:
    • @contentstack/apps-cli 1.7.5 → 1.7.6
    • @contentstack/cli-audit 1.21.1 → 1.22.0
    • @contentstack/cli-cm-bootstrap 1.19.10 → 1.19.11
    • @contentstack/cli-cm-branches 1.8.6 → 1.8.7
    • @contentstack/cli-bulk-operations 1.2.5 → 1.2.6
    • @contentstack/cli-cm-bulk-publish 1.13.1 → 1.13.2
    • @contentstack/cli-cm-regex-validate 1.0.4 → 1.0.5
    • contentstack-cli-tsgen 4.10.4 → 4.10.5
    • @contentstack/cli-cm-clone 1.21.12 → 1.21.13
    • contentstack-cli-content-type 1.5.5 → 1.5.6
    • @contentstack/cli-cm-export-to-csv 1.12.9 → 1.12.10
    • @contentstack/cli-cm-export 1.27.1 → 1.27.2
    • @contentstack/cli-external-migrate 1.0.0-alpha.8 → 1.0.0-alpha.9
    • @contentstack/cli-cm-import-setup 1.8.9 → 1.8.10
    • @contentstack/cli-cm-import 1.35.1 → 1.35.2
    • @contentstack/cli-cm-migrate-rte 1.7.5 → 1.7.6
    • @contentstack/cli-migration 1.12.7 → 1.12.8
    • @contentstack/cli-cm-export-query 1.0.8 → 1.0.9
    • @contentstack/cli-cm-seed 1.15.11 → 1.15.12
    • @contentstack/cli-variants 1.6.3 → 1.6.4
  • Point them at the released core packages: cli-command ~1.8.9, cli-utilities ~1.20.1, cli-config ~1.21.4, cli-auth ~1.8.9.
  • SDK bumps where used: @contentstack/management ^1.31.2 (cli-bulk-operations, cli-cm-regex-validate), @contentstack/delivery-sdk ^5.6.1 (cli-bulk-operations), @contentstack/types-generator ^3.10.5 (contentstack-cli-tsgen).
  • Cross-plugin references updated to the bumped versions (cli-cm-export / cli-cm-import in clone, export-query and seed; cli-audit and cli-variants in import, export and export-query; cli-cm-seed in bootstrap).

Verification

Every bumped external version is on npm (the four core packages, @contentstack/management 1.31.2, @contentstack/delivery-sdk 5.6.1, @contentstack/types-generator 3.10.5), and pnpm-lock.yaml was re-resolved with pnpm install --lockfile-only (pnpm 10.28.0) — it now pins exactly those versions; workspace links are unchanged. .talismanrc now ignores the content detectors for pnpm-lock.yaml (Talisman flags its sha512 integrity hashes as base64 secrets on every lockfile change).

Bump all 20 v1 plugins (cli-audit takes a minor, 1.21.1 -> 1.22.0; the rest
a patch) and point them at the released core packages (cli-command ~1.8.9,
cli-utilities ~1.20.1, cli-config ~1.21.4, cli-auth ~1.8.9),
@contentstack/management ^1.31.2, @contentstack/delivery-sdk ^5.6.1 and
@contentstack/types-generator ^3.10.5. Cross-plugin references (export,
import, seed, audit, variants) follow the bumped versions, and pnpm-lock.yaml
is re-resolved against the published versions.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@snyk-io

snyk-io Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 0 1 10 ✅ Passed
🟠 High Severity 0 10 25 ✅ Passed
🟡 Medium Severity 0 57 500 ✅ Passed
🔵 Low Severity 0 0 1000 ✅ Passed

⏱️ SLA Breach Summary

✅ No SLA breaches detected. All vulnerabilities are within acceptable time thresholds.

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 0 0 15 / 30 days ✅ Passed
🟠 High 0 0 30 / 120 days ✅ Passed
🟡 Medium 0 0 90 / 365 days ✅ Passed
🔵 Low 0 0 180 / 365 days ✅ Passed

ℹ️ Vulnerabilities Without Available Fixes (Informational Only)

The following vulnerabilities were detected but do not have fixes available (no upgrade or patch). These are excluded from failure thresholds:

  • Critical without fixes: 1
  • High without fixes: 10
  • Medium without fixes: 57
  • Low without fixes: 0

✅ BUILD PASSED - All security checks passed

@cs-raj cs-raj self-assigned this Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 0 1 10 ✅ Passed
🟠 High Severity 0 10 25 ✅ Passed
🟡 Medium Severity 0 57 500 ✅ Passed
🔵 Low Severity 0 0 1000 ✅ Passed

⏱️ SLA Breach Summary

✅ No SLA breaches detected. All vulnerabilities are within acceptable time thresholds.

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 0 0 15 / 30 days ✅ Passed
🟠 High 0 0 30 / 120 days ✅ Passed
🟡 Medium 0 0 90 / 365 days ✅ Passed
🔵 Low 0 0 180 / 365 days ✅ Passed

ℹ️ Vulnerabilities Without Available Fixes (Informational Only)

The following vulnerabilities were detected but do not have fixes available (no upgrade or patch). These are excluded from failure thresholds:

  • Critical without fixes: 1
  • High without fixes: 10
  • Medium without fixes: 57
  • Low without fixes: 0

✅ BUILD PASSED - All security checks passed

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 0 0 10 ✅ Passed
🟠 High Severity 0 4 25 ✅ Passed
🟡 Medium Severity 0 56 500 ✅ Passed
🔵 Low Severity 0 0 1000 ✅ Passed

⏱️ SLA Breach Summary

✅ No SLA breaches detected. All vulnerabilities are within acceptable time thresholds.

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 0 0 15 / 30 days ✅ Passed
🟠 High 0 0 30 / 120 days ✅ Passed
🟡 Medium 0 0 90 / 365 days ✅ Passed
🔵 Low 0 0 180 / 365 days ✅ Passed

ℹ️ Vulnerabilities Without Available Fixes (Informational Only)

The following vulnerabilities were detected but do not have fixes available (no upgrade or patch). These are excluded from failure thresholds:

  • Critical without fixes: 0
  • High without fixes: 4
  • Medium without fixes: 56
  • Low without fixes: 0

✅ BUILD PASSED - All security checks passed

@amit-kanswal-cs amit-kanswal-cs left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@cs-raj
cs-raj merged commit e863cbe into DX-23-09-2026-Release Oct 6, 2026
12 checks passed
@cs-raj
cs-raj deleted the fix/version-bump branch October 6, 2026 08:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants