Skip to content

chore(release): v2.1.1 hotfix and security patches#27

Merged
night-slayer18 merged 10 commits intomainfrom
develop
Mar 21, 2026
Merged

chore(release): v2.1.1 hotfix and security patches#27
night-slayer18 merged 10 commits intomainfrom
develop

Conversation

@night-slayer18
Copy link
Copy Markdown
Member

This PR merges develop into main for the v2.1.1 hotfix release.

Changes included:

  • Patched 6 vulnerabilities in transitive dependencies (minimatch, rollup, undici, qs, ajv, flatted) via npm overrides
  • Bumped root workspace and internal package versions to 2.1.1

dependabot Bot and others added 10 commits February 13, 2026 11:09
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) from 0.33.1 to 0.34.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](aquasecurity/trivy-action@0.33.1...0.34.0)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-version: 0.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…velop/aquasecurity/trivy-action-0.34.0

chore(deps): bump aquasecurity/trivy-action from 0.33.1 to 0.34.0
Bumps the production-dependencies group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [glob](https://github.com/isaacs/node-glob) | `13.0.1` | `13.0.3` |
| [inquirer](https://github.com/SBoudrias/Inquirer.js) | `13.2.2` | `13.2.4` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `0.563.0` | `0.564.0` |
| [tailwind-merge](https://github.com/dcastil/tailwind-merge) | `3.4.0` | `3.4.1` |
| [marked](https://github.com/markedjs/marked) | `17.0.1` | `17.0.2` |


Updates `glob` from 13.0.1 to 13.0.3
- [Changelog](https://github.com/isaacs/node-glob/blob/main/changelog.md)
- [Commits](isaacs/node-glob@v13.0.1...v13.0.3)

Updates `inquirer` from 13.2.2 to 13.2.4
- [Release notes](https://github.com/SBoudrias/Inquirer.js/releases)
- [Commits](https://github.com/SBoudrias/Inquirer.js/compare/inquirer@13.2.2...inquirer@13.2.4)

Updates `lucide-react` from 0.563.0 to 0.564.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/0.564.0/packages/lucide-react)

Updates `tailwind-merge` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/dcastil/tailwind-merge/releases)
- [Commits](dcastil/tailwind-merge@v3.4.0...v3.4.1)

Updates `marked` from 17.0.1 to 17.0.2
- [Release notes](https://github.com/markedjs/marked/releases)
- [Commits](markedjs/marked@v17.0.1...v17.0.2)

---
updated-dependencies:
- dependency-name: glob
  dependency-version: 13.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: inquirer
  dependency-version: 13.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: lucide-react
  dependency-version: 0.564.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: tailwind-merge
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: marked
  dependency-version: 17.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
…lop/production-dependencies-23f0036a23

chore(deps): bump the production-dependencies group with 5 updates
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) from 0.34.0 to 0.35.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](aquasecurity/trivy-action@0.34.0...0.35.0)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-version: 0.35.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…velop/aquasecurity/trivy-action-0.35.0

chore(deps): bump aquasecurity/trivy-action from 0.34.0 to 0.35.0
…errides

Signed-off-by: night-slayer18 <samanuaia257@gmail.com>
- ajv limited to >=6.14.0 <7 to maintain compatibility with eslint which
  relies on the ajv@6 API (ajv@8 removed defaultMeta).
- All other overrides from previous commit retained.

Signed-off-by: night-slayer18 <samanuaia257@gmail.com>
Signed-off-by: night-slayer18 <samanuaia257@gmail.com>
@netlify
Copy link
Copy Markdown

netlify Bot commented Mar 21, 2026

Deploy Preview for autodocshq ready!

Name Link
🔨 Latest commit d12d658
🔍 Latest deploy log https://app.netlify.com/projects/autodocshq/deploys/69be9246c9ed2500087506ab
😎 Deploy Preview https://deploy-preview-27--autodocshq.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions
Copy link
Copy Markdown

🚀 Deployed on https://pr-27--autodocshq.netlify.app

@github-actions github-actions Bot temporarily deployed to pull request March 21, 2026 12:43 Inactive
@github-actions
Copy link
Copy Markdown

Preview Deployment

Your preview is ready.

URL: https://pr-27--autodocshq.netlify.app


Deployed from commit d738346

@codecov
Copy link
Copy Markdown

codecov Bot commented Mar 21, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@night-slayer18 night-slayer18 merged commit badeef7 into main Mar 21, 2026
39 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant