Skip to content

fix(deps): release patched transitive dev-dep versions - #90

Merged
ClaudiaFang merged 1 commit into
mainfrom
claude/release-security-patch
Jul 31, 2026
Merged

ClaudiaFang merged 1 commit into
mainfrom
claude/release-security-patch

Conversation

@ClaudiaFang

Copy link
Copy Markdown
Member

Summary

  • Empty commit, no source changes.
  • The actual dependency patch already landed on main in chore(deps): patch transitive dev-dep vulnerabilities #87 as chore(deps): ..., which semantic-release intentionally excludes from triggering a release.
  • This adds a fix(deps): commit so semantic-release cuts a patch release (1.5.1), making the Dependabot security fix (brace-expansion, fast-uri, postcss) traceable to a published version.

Test plan

  • npx eslint . / build ran via pre-commit hook, no source changed
  • N/A — no functional change, purely a release trigger

🤖 Generated with Claude Code

No source changes — marks the security dependency bump from PR #87
(brace-expansion, fast-uri, postcss) as a fix so semantic-release cuts
a patch version, since GHSA fixes should be traceable to a release.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@sonarqubecloud

Copy link
Copy Markdown

@ClaudiaFang
ClaudiaFang merged commit 94cac72 into main Jul 31, 2026
16 checks passed
@ClaudiaFang
ClaudiaFang deleted the claude/release-security-patch branch July 31, 2026 17:50
@ClaudiaFang

Copy link
Copy Markdown
Member Author

🎉 This PR is included in version 1.5.1 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

ClaudiaFang added a commit that referenced this pull request Aug 7, 2026
fix(deps): release patched transitive dev-dep versions
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant