Skip to content

DX | 29-09-2026 | v1 | Release - #2728

Open
cs-raj wants to merge 6 commits into
v1-legacyfrom
DX-23-09-2026-Release
Open

cs-raj wants to merge 6 commits into
v1-legacyfrom
DX-23-09-2026-Release

Conversation

@cs-raj

@cs-raj cs-raj commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bug fixes

  • @contentstack/cli and @contentstack/cli-utilities now declare tslib as a runtime dependency. Installs that don't hoist dependencies, such as pnpm add -g @contentstack/cli, no longer fail with "Cannot find module 'tslib'".
  • When a request still gets a 401 after the access token is refreshed, the CLI now retries the refresh once and then stops with "Authentication failed after token refresh". Before, it looped and kept calling the token refresh endpoint.

Security

  • Upgraded @contentstack/cli-utilities dependencies: @contentstack/management ~1.31.1, @contentstack/marketplace-sdk ^1.5.4, axios ^1.20.0, js-yaml ^4.3.2 and picomatch ^4.0.7.
  • Upgraded the workspace overrides: uuid 14.0.2, brace-expansion 5.0.12, js-yaml 5.4.2 and fast-uri 4.2.1. Snyk reports no vulnerable paths after the upgrade.

cs-raj and others added 6 commits September 21, 2026 13:32
@contentstack/cli and @contentstack/cli-utilities compile with
importHelpers: true, so their emitted output requires tslib at runtime.
tslib was listed under devDependencies (cli) or not at all (cli-utilities),
so consumers never receive it and a global install fails with
"Cannot find module 'tslib'".

Verified against the published v1-x tarballs: @contentstack/cli 1.68.0 has
3 files requiring tslib, @contentstack/cli-utilities 1.19.2 has 26, neither
declaring it. cli-auth, cli-command and cli-config emit zero tslib requires
and are deliberately left unchanged.

Mirrors PR #2722, which fixed the same defect on the v2 line.

Also switches the .talismanrc pnpm-lock.yaml entry from a checksum pin to
ignore_detectors, so lockfile regeneration no longer invalidates it.

Refs: #2629

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Upgrades @contentstack/cli-utilities dependencies and the workspace-level
pnpm overrides.

packages/contentstack-utilities:

  @contentstack/management      ~1.30.1 -> ~1.31.1
  @contentstack/marketplace-sdk  ^1.5.1 -> ^1.5.4
  axios                         ^1.19.0 -> ^1.20.0
  js-yaml                        ^4.3.1 -> ^4.3.2
  picomatch (@oclif/core override) ^4.0.4 -> ^4.0.7

pnpm-workspace.yaml overrides:

  uuid             14.0.1 -> 14.0.2
  brace-expansion   5.0.9 -> 5.0.12
  js-yaml           5.2.3 -> 5.4.2
  fast-uri          4.1.2 -> 4.2.1

snyk test --all-projects --fail-on=all reports 6 projects with no vulnerable
paths. pnpm install --frozen-lockfile and pnpm build both pass, and the tslib
runtime dependency added in the preceding commit is unaffected.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The 401 branch recursed with the same stale error object and an
unincremented counter, so a token refresh that succeeded without clearing
the 401 looped forever, issuing a real refresh-endpoint call each pass.
The maxRetryCount cap existed only on the 429/408 branch.

Apply the same guard: attempt one refresh, then print a clear error and
exit if the 401 persists. The cap is 2 rather than the 429/408 branch's 3
because a single refresh is enough to establish that the token is dead.

This brings v1-legacy in line with the v2 fix, which was never backported.
The resulting file is byte-identical to the one on main.

Reachability note: the callers in @contentstack/cli-variants pass an
HttpResponse, whose `response` field is TypeScript-private but a real
property at runtime, so `error.response.status` resolves and the branch is
genuinely reachable.

Adds test/unit/authentication-handler.test.ts, the first coverage for this
file in either branch. Eight cases across the 401 and 429/408 paths,
including a regression guard that hangs indefinitely without this fix.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
fix(auth): cap 401 retry count in refreshAccessToken
fix(deps): declare tslib as a runtime dependency
@cs-raj cs-raj self-assigned this Sep 28, 2026
@snyk-io

snyk-io Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@github-actions

Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 0 0 10 ✅ Passed
🟠 High Severity 0 0 25 ✅ Passed
🟡 Medium Severity 0 0 0 ✅ Passed
🔵 Low Severity 0 0 0 ✅ Passed

⏱️ SLA Breach Summary

✅ No SLA breaches detected. All vulnerabilities are within acceptable time thresholds.

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 0 0 15 / 30 days ✅ Passed
🟠 High 0 0 30 / 120 days ✅ Passed
🟡 Medium 0 0 90 / 365 days ✅ Passed
🔵 Low 0 0 180 / 365 days ✅ Passed

✅ BUILD PASSED - All security checks passed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant