Bug Fixes
- Fixed
bun installrecursing without bound when the custom Angular
builders had not been compiled yet. The postinstall step ran a nested
bun installfor the builders, which re-entered the root install and
its postinstall. The builders are a workspace of the root package, so
the root install already covers them and only the compile remains. - These CommonJS build scripts are now named
.cjspermanently. They
used to be renamed to.cjsand back on every run, so an interrupted
build or install left the tracked files deleted and untracked copies
in their place:dev-setupclean-symlinksstore-git-metadata
- Escape now closes these popups and returns focus to the button that
opened them:- the row-actions menu in lists
- the options list of the console's dropdown selects
- Both announced themselves as popups to assistive technology but
ignored Escape, so a keyboard user could not close them. Inside a
dialog, one Escape closes only the menu or list, not the dialog
behind it.
Maintainability
- Moved the devkit's build tooling to 22.2.0 and removed the npm
overrides in its manifest. The overrides were added to force patched
versions past dependency alerts, but the tooling had since moved
beyond them, so they were forcing older releases onto it:
| Package | Forced by the overrides | Declared by the tooling |
|---|---|---|
| vite | 7 | 8 |
| Babel | 7 | 8 |
| webpack-dev-server | 5 | 6 |
- The vite pin also kept a vulnerable esbuild in the devkit lockfile
(GHSA-g7r4-m6w7-qqqr, low). Without the overrides the devkit resolves
the versions its tooling declares, and npm audit reports no
vulnerabilities. - Jetstream no longer depends on
govau/cf-common, unmaintained since
2020, through which it read every configuration setting. The small
part it used now lives in the repository asapi/env, with tests.
This also removes the stalego-cfenv1.19.0 that four backend
modules inherited from it;go-cfenvis now 1.24.3 throughout. - Removed six root dependencies that nothing in the repository imports
or runs:
| Package | State upstream |
|---|---|
q
| archived and deprecated |
delete
| no change since 2017 |
ps-node
| no change since 2021 |
npm-run-all
| no change since 2024; no script used it |
mappy-breakpoints
| no change since 2023 |
kind-of
| 2020 security pin, no longer needed |
kind-ofstays at the patched 6.0.3 throughclone-deep, which now
requires it on its own. The lockfile loses 125 package versions and
gains none.
Chores
- Angular dependency updates:
| Component | From | To |
|---|---|---|
| Angular framework | 22.1.7 | 22.2.0 |
| Angular CLI and build tooling | 22.1.8 | 22.2.0 |
| Analog Vitest plugin | 2.7.2 | 2.7.5 |
- Analog 2.7.2 failed on Angular 22.2 with
cache.has is not a function
(analogjs/analog#2575), because 22.2 changed the internal cache the
plugin relies on. 2.7.3 carries the fix, and 2.7.5 stops starting idle
Angular worker threads up front (analogjs/analog#2581), so unit tests
and production builds share a single@angular/build22.2.0. - Added
scripts/lockdiff.mjs, which explains a lockfile change by
package instead of by line. Forbun.lockand npmpackage-lock.json
it reports:- packages added, removed, re-versioned or only moved in the tree
- which changed package brought each one in
docs/build-and-packaging.mddescribes the stepwise update procedure
it supports, which keeps lockfile regeneration as a last resort.- Dependency updates:
typescript-eslintfrom 8.70.0 to 8.70.1. - The lint configuration uses only the
typescript-eslintpackage,
which brings its parser and plugin, so the root manifest no longer
declares them separately. The separate pins kept an older copy of the
whole family in the lockfile whenevertypescript-eslintmoved on its
own:@typescript-eslint/eslint-plugin@typescript-eslint/parser
- The Stratos Theme Builder's CI job installs from
tools/stb/bun.lock
withbun install --frozen-lockfileinstead ofnpm install, which
ignored the lockfile and resolved every dependency fresh. The
lockfile also drops stale nested CodeMirror copies that failed
typecheck when installed as locked. - These targets generate
build-info.tswhen it is missing, as CI
already does before its tests:make check gatemake check testsmake check coverage
- In a fresh clone or worktree the unit tests previously failed to
resolve it. An existing file is left untouched. README.mdandCONTRIBUTING.mdfixes (#5960):- they state the current Angular (22) and Go (1.27) versions
- the README's application screenshot and Browserstack logo render
again - most markdownlint findings in the two files are cleared
- Both images had pointed into the
website/tree the Docusaurus
rewrite replaced; the logo now lives indocs/images/. - Dependency updates: the Monaco editor from 0.56.0 to 0.57.0, which
updates the editor core and its bundled DOMPurify (3.4.8 to 3.4.15).
The manifest range moves to^0.57.0, since a caret range on a 0.x
version does not take a new minor. - Backend toolchain and dependency updates:
| Component | From | To |
|---|---|---|
| Go (backend modules) | 1.27.0 | 1.27.1 |
| Go (CI tools image) | 1.26.5 | 1.27.1 |
| capi (CF API client) | fork of 3.229.1 | 3.229.2 |
| go-sqlite3 | 0.35.4 | 0.35.6 |
| Helm | 3.21.4 | 3.22.0 |
| Kubernetes client libraries | 0.37.0 | 0.37.1 |
| AWS SDK for Go v2 | 1.46.0 | 1.47.1 |
code.cloudfoundry.org/clock
| 1.87.0 | 1.89.0 |
- capi now comes from its upstream release instead of a fork. The fork
carried the "create a role by username and origin" change ahead of
its release; 3.229.2 includes it. - Sixteen
replacedirectives that no longer affected the build were
removed from the backend modules. - Dependabot runs from one configuration file again. The repository had
both.github/dependabot.ymland.github/dependabot.yaml, and only
the first was in effect, so these were lost:- version updates for the backend Go modules
- version updates for the website
- the pinned
chore(deps)commit prefix the release notes rely on
- The merged file restores them and adds a weekly grouped update across
all seven Go modules. - Unit-test tooling updates, moved together because Vitest 5 requires
its plugins at exactly its own version:
| Package | From | To |
|---|---|---|
vitest
| 5.0.1 | 5.0.2 |
@vitest/coverage-v8
| 5.0.1 | 5.0.2 |
@vitest/ui
| 5.0.1 | 5.0.2 |
- Dependabot now groups the Vitest packages, so it no longer proposes
a Vitest bump that leaves the plugins behind. - Removed
ANGULAR-21-UPGRADE-STATUS.mdfrom the repository root. It
was a work-in-progress note from an abandoned Angular 21 upgrade
attempt; the test failure it describes no longer occurs, and the
branches and versions it names are out of date. The current
dependency-update procedure is indocs/build-and-packaging.md. - Frontend dependency updates:
| Package | From | To |
|---|---|---|
marked
| 18.0.12 | 18.0.14 |
ng-packagr
| 22.1.1 | 22.2.1 |
jsdom
| 30.0.1 | 30.1.1 |
happy-dom
| 20.14.0 | 20.14.5 |
sass
| 1.104.0 | 1.105.0 |
@oxc-project/runtime
| 0.121.0 | 0.151.0 |
@types/node
| 26.4.1 | 26.6.3 |
fs-extra
| 11.4.0 | 11.4.1 |
browserstack-local
| 1.5.14 | 1.5.15 |
baseline-browser-mapping
| 2.11.25 | 2.11.26 |
- The
markedpin insrc/frontend/packages/core/package.jsonmoved
with the root, as the nested manifest pin check requires. - Website dependency updates:
| Package | From | To |
|---|---|---|
react, react-dom
| 19.2.8 | 19.3.0 |
lucide-react
| 1.28.0 | 1.48.0 |
tailwind-merge
| 3.6.0 | 3.7.0 |
postcss
| 8.5.25 | 8.5.28 |
prettier
| 3.9.6 | 3.9.9 |
caniuse-lite
| 1.0.30001806 | 1.0.30001812 |
baseline-browser-mapping
| 2.11.10 | 2.11.26 |
- Frontend dependency updates:
| Package | From | To |
|---|---|---|
Angular framework and @angular/cdk
| 22.2.0 | 22.2.1 |
ng2-charts
| 10.0.0 | 11.0.0 |
ng-packagr
| 22.2.1 | 22.2.3 |
vitest, @vitest/coverage-v8, @vitest/ui
| 5.0.2 | 5.0.3 |
typescript-eslint
| 8.70.1 | 8.71.0 |
sass
| 1.105.0 | 1.105.1 |
@oxc-project/runtime
| 0.151.0 | 0.152.0 |
ng2-charts11 only raises its Angular peer floor from 21 to 22; the
chart directive's behavior is unchanged.- The Angular pins in the nested
src/frontend/packages/*/package.json
manifests moved with the root, as the nested manifest pin check
requires. - Frontend dependency updates:
| Package | From | To |
|---|---|---|
@angular/build, @angular/cli, @schematics/angular
| 22.2.0 | 22.2.1 |
@angular-devkit/build-angular, core, schematics
| 22.2.0 | 22.2.1 |
@angular-devkit/architect
| 0.2202.0 | 0.2202.1 |
ng-packagr
| 22.2.3 | 22.2.4 |
baseline-browser-mapping
| 2.11.26 | 2.11.27 |
- The Angular build tooling now matches the 22.2.1 framework, in the
root and devkit manifests alike. rollupleaves the root lockfile. Nothing depended on it; the
toolchain builds withrolldown.- Frontend dependency updates:
| Package | From | To |
|---|---|---|
@analogjs/vite-plugin-angular, @analogjs/vitest-angular
| 2.7.5 | 2.8.0 |
- Analog 2.8.0 carries the plugin fixes for the Angular 22.2 transformer
and source caches; it is tested against the 22.2.1 build tooling. The
Analog pins insrc/frontend/packages/store/package.jsonmoved with
the root, as the nested manifest pin check requires. release-notes.sh check(also run bymake changelogandmake stamp tag) now notes each bumped package that no fragment names. A later
dependency fragment no longer hides an earlier bump it never described.- Frontend dependency updates from 09-24 that no other fragment covers:
| Package | From | To |
|---|---|---|
eslint
| 10.10.0 | 10.11.0 |
browserstack-local
| 1.5.13 | 1.5.14 |
baseline-browser-mapping
| 2.11.21 | 2.11.25 |
browserstack-localandbaseline-browser-mappingmoved again later in
the release; the rows above are their first steps.
Security Updates
- Echo, Jetstream's HTTP framework, moved from 5.3.1 to 5.4.0 in every
backend module. It fixes seven advisories:
| Advisory | What it fixes |
|---|---|
| GHSA-2ffq-g2xg-c22p | Any client could set the forwarded-scheme headers |
| GHSA-99jh-6h7p-pp36 | The proxy middleware passed on a spoofed X-Real-IP
|
| GHSA-h9g5-28mm-hx3g | JSONP accepted any callback name |
| GHSA-r7w9-592q-9vg4 | Method override could turn a POST into a GET and skip CSRF checks |
| GHSA-v753-g4cw-jm48 | Control characters in a redirect path could redirect off-site |
| GHSA-375p-5qhx-8wq4 | An encoded static-file path could bypass a guarded route |
| GHSA-3pmx-cf9f-34xr | Static files were served for paths with . or .. segments
|
- The stricter handling does not change how Jetstream behaves: HSTS and
the Cloud Foundry HTTPS redirect do not depend on Echo's scheme
detection, and the UI's static files never use//or dot segments. - fast-uri moved to 3.1.8: from 3.1.5 in the root and website manifests,
and from 3.1.7 in the devkit. It reaches the UI through ajv, which the
schema widget uses to validate JSON schemas. 3.1.5 was affected by all
three advisories:
| Advisory | Severity | What it fixes |
|---|---|---|
| GHSA-5jgf-p345-68v8 | High | Host confusion via skipped IDN canonicalization on scheme-relative references |
| GHSA-qw65-cvwx-89v3 | High | Authority injection through an unvalidated port when serializing |
| GHSA-hrr3-gc8f-f4qj | Medium | Inconsistent host case normalization via percent-encoded octets |