github cloudfoundry/stratos v5.5.5
Stratos v5.5.5

2 hours ago

Bug Fixes

  • Fixed bun install recursing without bound when the custom Angular
    builders had not been compiled yet. The postinstall step ran a nested
    bun install for the builders, which re-entered the root install and
    its postinstall. The builders are a workspace of the root package, so
    the root install already covers them and only the compile remains.
  • These CommonJS build scripts are now named .cjs permanently. They
    used to be renamed to .cjs and back on every run, so an interrupted
    build or install left the tracked files deleted and untracked copies
    in their place:
    • dev-setup
    • clean-symlinks
    • store-git-metadata
  • Escape now closes these popups and returns focus to the button that
    opened them:
    • the row-actions menu in lists
    • the options list of the console's dropdown selects
  • Both announced themselves as popups to assistive technology but
    ignored Escape, so a keyboard user could not close them. Inside a
    dialog, one Escape closes only the menu or list, not the dialog
    behind it.

Maintainability

  • Moved the devkit's build tooling to 22.2.0 and removed the npm
    overrides in its manifest. The overrides were added to force patched
    versions past dependency alerts, but the tooling had since moved
    beyond them, so they were forcing older releases onto it:
Package Forced by the overrides Declared by the tooling
vite 7 8
Babel 7 8
webpack-dev-server 5 6
  • The vite pin also kept a vulnerable esbuild in the devkit lockfile
    (GHSA-g7r4-m6w7-qqqr, low). Without the overrides the devkit resolves
    the versions its tooling declares, and npm audit reports no
    vulnerabilities.
  • Jetstream no longer depends on govau/cf-common, unmaintained since
    2020, through which it read every configuration setting. The small
    part it used now lives in the repository as api/env, with tests.
    This also removes the stale go-cfenv 1.19.0 that four backend
    modules inherited from it; go-cfenv is now 1.24.3 throughout.
  • Removed six root dependencies that nothing in the repository imports
    or runs:
Package State upstream
q archived and deprecated
delete no change since 2017
ps-node no change since 2021
npm-run-all no change since 2024; no script used it
mappy-breakpoints no change since 2023
kind-of 2020 security pin, no longer needed
  • kind-of stays at the patched 6.0.3 through clone-deep, which now
    requires it on its own. The lockfile loses 125 package versions and
    gains none.

Chores

  • Angular dependency updates:
Component From To
Angular framework 22.1.7 22.2.0
Angular CLI and build tooling 22.1.8 22.2.0
Analog Vitest plugin 2.7.2 2.7.5
  • Analog 2.7.2 failed on Angular 22.2 with cache.has is not a function
    (analogjs/analog#2575), because 22.2 changed the internal cache the
    plugin relies on. 2.7.3 carries the fix, and 2.7.5 stops starting idle
    Angular worker threads up front (analogjs/analog#2581), so unit tests
    and production builds share a single @angular/build 22.2.0.
  • Added scripts/lockdiff.mjs, which explains a lockfile change by
    package instead of by line. For bun.lock and npm package-lock.json
    it reports:
    • packages added, removed, re-versioned or only moved in the tree
    • which changed package brought each one in
  • docs/build-and-packaging.md describes the stepwise update procedure
    it supports, which keeps lockfile regeneration as a last resort.
  • Dependency updates: typescript-eslint from 8.70.0 to 8.70.1.
  • The lint configuration uses only the typescript-eslint package,
    which brings its parser and plugin, so the root manifest no longer
    declares them separately. The separate pins kept an older copy of the
    whole family in the lockfile whenever typescript-eslint moved on its
    own:
    • @typescript-eslint/eslint-plugin
    • @typescript-eslint/parser
  • The Stratos Theme Builder's CI job installs from tools/stb/bun.lock
    with bun install --frozen-lockfile instead of npm install, which
    ignored the lockfile and resolved every dependency fresh. The
    lockfile also drops stale nested CodeMirror copies that failed
    typecheck when installed as locked.
  • These targets generate build-info.ts when it is missing, as CI
    already does before its tests:
    • make check gate
    • make check tests
    • make check coverage
  • In a fresh clone or worktree the unit tests previously failed to
    resolve it. An existing file is left untouched.
  • README.md and CONTRIBUTING.md fixes (#5960):
    • they state the current Angular (22) and Go (1.27) versions
    • the README's application screenshot and Browserstack logo render
      again
    • most markdownlint findings in the two files are cleared
  • Both images had pointed into the website/ tree the Docusaurus
    rewrite replaced; the logo now lives in docs/images/.
  • Dependency updates: the Monaco editor from 0.56.0 to 0.57.0, which
    updates the editor core and its bundled DOMPurify (3.4.8 to 3.4.15).
    The manifest range moves to ^0.57.0, since a caret range on a 0.x
    version does not take a new minor.
  • Backend toolchain and dependency updates:
Component From To
Go (backend modules) 1.27.0 1.27.1
Go (CI tools image) 1.26.5 1.27.1
capi (CF API client) fork of 3.229.1 3.229.2
go-sqlite3 0.35.4 0.35.6
Helm 3.21.4 3.22.0
Kubernetes client libraries 0.37.0 0.37.1
AWS SDK for Go v2 1.46.0 1.47.1
code.cloudfoundry.org/clock 1.87.0 1.89.0
  • capi now comes from its upstream release instead of a fork. The fork
    carried the "create a role by username and origin" change ahead of
    its release; 3.229.2 includes it.
  • Sixteen replace directives that no longer affected the build were
    removed from the backend modules.
  • Dependabot runs from one configuration file again. The repository had
    both .github/dependabot.yml and .github/dependabot.yaml, and only
    the first was in effect, so these were lost:
    • version updates for the backend Go modules
    • version updates for the website
    • the pinned chore(deps) commit prefix the release notes rely on
  • The merged file restores them and adds a weekly grouped update across
    all seven Go modules.
  • Unit-test tooling updates, moved together because Vitest 5 requires
    its plugins at exactly its own version:
Package From To
vitest 5.0.1 5.0.2
@vitest/coverage-v8 5.0.1 5.0.2
@vitest/ui 5.0.1 5.0.2
  • Dependabot now groups the Vitest packages, so it no longer proposes
    a Vitest bump that leaves the plugins behind.
  • Removed ANGULAR-21-UPGRADE-STATUS.md from the repository root. It
    was a work-in-progress note from an abandoned Angular 21 upgrade
    attempt; the test failure it describes no longer occurs, and the
    branches and versions it names are out of date. The current
    dependency-update procedure is in docs/build-and-packaging.md.
  • Frontend dependency updates:
Package From To
marked 18.0.12 18.0.14
ng-packagr 22.1.1 22.2.1
jsdom 30.0.1 30.1.1
happy-dom 20.14.0 20.14.5
sass 1.104.0 1.105.0
@oxc-project/runtime 0.121.0 0.151.0
@types/node 26.4.1 26.6.3
fs-extra 11.4.0 11.4.1
browserstack-local 1.5.14 1.5.15
baseline-browser-mapping 2.11.25 2.11.26
  • The marked pin in src/frontend/packages/core/package.json moved
    with the root, as the nested manifest pin check requires.
  • Website dependency updates:
Package From To
react, react-dom 19.2.8 19.3.0
lucide-react 1.28.0 1.48.0
tailwind-merge 3.6.0 3.7.0
postcss 8.5.25 8.5.28
prettier 3.9.6 3.9.9
caniuse-lite 1.0.30001806 1.0.30001812
baseline-browser-mapping 2.11.10 2.11.26
  • Frontend dependency updates:
Package From To
Angular framework and @angular/cdk 22.2.0 22.2.1
ng2-charts 10.0.0 11.0.0
ng-packagr 22.2.1 22.2.3
vitest, @vitest/coverage-v8, @vitest/ui 5.0.2 5.0.3
typescript-eslint 8.70.1 8.71.0
sass 1.105.0 1.105.1
@oxc-project/runtime 0.151.0 0.152.0
  • ng2-charts 11 only raises its Angular peer floor from 21 to 22; the
    chart directive's behavior is unchanged.
  • The Angular pins in the nested src/frontend/packages/*/package.json
    manifests moved with the root, as the nested manifest pin check
    requires.
  • Frontend dependency updates:
Package From To
@angular/build, @angular/cli, @schematics/angular 22.2.0 22.2.1
@angular-devkit/build-angular, core, schematics 22.2.0 22.2.1
@angular-devkit/architect 0.2202.0 0.2202.1
ng-packagr 22.2.3 22.2.4
baseline-browser-mapping 2.11.26 2.11.27
  • The Angular build tooling now matches the 22.2.1 framework, in the
    root and devkit manifests alike.
  • rollup leaves the root lockfile. Nothing depended on it; the
    toolchain builds with rolldown.
  • Frontend dependency updates:
Package From To
@analogjs/vite-plugin-angular, @analogjs/vitest-angular 2.7.5 2.8.0
  • Analog 2.8.0 carries the plugin fixes for the Angular 22.2 transformer
    and source caches; it is tested against the 22.2.1 build tooling. The
    Analog pins in src/frontend/packages/store/package.json moved with
    the root, as the nested manifest pin check requires.
  • release-notes.sh check (also run by make changelog and make stamp tag) now notes each bumped package that no fragment names. A later
    dependency fragment no longer hides an earlier bump it never described.
  • Frontend dependency updates from 09-24 that no other fragment covers:
Package From To
eslint 10.10.0 10.11.0
browserstack-local 1.5.13 1.5.14
baseline-browser-mapping 2.11.21 2.11.25
  • browserstack-local and baseline-browser-mapping moved again later in
    the release; the rows above are their first steps.

Security Updates

  • Echo, Jetstream's HTTP framework, moved from 5.3.1 to 5.4.0 in every
    backend module. It fixes seven advisories:
Advisory What it fixes
GHSA-2ffq-g2xg-c22p Any client could set the forwarded-scheme headers
GHSA-99jh-6h7p-pp36 The proxy middleware passed on a spoofed X-Real-IP
GHSA-h9g5-28mm-hx3g JSONP accepted any callback name
GHSA-r7w9-592q-9vg4 Method override could turn a POST into a GET and skip CSRF checks
GHSA-v753-g4cw-jm48 Control characters in a redirect path could redirect off-site
GHSA-375p-5qhx-8wq4 An encoded static-file path could bypass a guarded route
GHSA-3pmx-cf9f-34xr Static files were served for paths with . or .. segments
  • The stricter handling does not change how Jetstream behaves: HSTS and
    the Cloud Foundry HTTPS redirect do not depend on Echo's scheme
    detection, and the UI's static files never use // or dot segments.
  • fast-uri moved to 3.1.8: from 3.1.5 in the root and website manifests,
    and from 3.1.7 in the devkit. It reaches the UI through ajv, which the
    schema widget uses to validate JSON schemas. 3.1.5 was affected by all
    three advisories:
Advisory Severity What it fixes
GHSA-5jgf-p345-68v8 High Host confusion via skipped IDN canonicalization on scheme-relative references
GHSA-qw65-cvwx-89v3 High Authority injection through an unvalidated port when serializing
GHSA-hrr3-gc8f-f4qj Medium Inconsistent host case normalization via percent-encoded octets

Don't miss a new stratos release

NewReleases is sending notifications on new releases.