Skip to content

chore(release): v2.1.1 hotfix and security patches - #27

Merged
night-slayer18 merged 10 commits into
mainfrom
develop
Mar 21, 2026
Merged

chore(release): v2.1.1 hotfix and security patches#27
night-slayer18 merged 10 commits into
mainfrom
develop

Conversation

@night-slayer18

Copy link
Copy Markdown
Member

This PR merges develop into main for the v2.1.1 hotfix release.

Changes included:

  • Patched 6 vulnerabilities in transitive dependencies (minimatch, rollup, undici, qs, ajv, flatted) via npm overrides
  • Bumped root workspace and internal package versions to 2.1.1

dependabot Bot and others added 10 commits February 13, 2026 11:09
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) from 0.33.1 to 0.34.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](aquasecurity/trivy-action@0.33.1...0.34.0)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-version: 0.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…velop/aquasecurity/trivy-action-0.34.0

chore(deps): bump aquasecurity/trivy-action from 0.33.1 to 0.34.0
Bumps the production-dependencies group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [glob](https://github.com/isaacs/node-glob) | `13.0.1` | `13.0.3` |
| [inquirer](https://github.com/SBoudrias/Inquirer.js) | `13.2.2` | `13.2.4` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `0.563.0` | `0.564.0` |
| [tailwind-merge](https://github.com/dcastil/tailwind-merge) | `3.4.0` | `3.4.1` |
| [marked](https://github.com/markedjs/marked) | `17.0.1` | `17.0.2` |


Updates `glob` from 13.0.1 to 13.0.3
- [Changelog](https://github.com/isaacs/node-glob/blob/main/changelog.md)
- [Commits](isaacs/node-glob@v13.0.1...v13.0.3)

Updates `inquirer` from 13.2.2 to 13.2.4
- [Release notes](https://github.com/SBoudrias/Inquirer.js/releases)
- [Commits](https://github.com/SBoudrias/Inquirer.js/compare/inquirer@13.2.2...inquirer@13.2.4)

Updates `lucide-react` from 0.563.0 to 0.564.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/0.564.0/packages/lucide-react)

Updates `tailwind-merge` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/dcastil/tailwind-merge/releases)
- [Commits](dcastil/tailwind-merge@v3.4.0...v3.4.1)

Updates `marked` from 17.0.1 to 17.0.2
- [Release notes](https://github.com/markedjs/marked/releases)
- [Commits](markedjs/marked@v17.0.1...v17.0.2)

---
updated-dependencies:
- dependency-name: glob
  dependency-version: 13.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: inquirer
  dependency-version: 13.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: lucide-react
  dependency-version: 0.564.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: tailwind-merge
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: marked
  dependency-version: 17.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
…lop/production-dependencies-23f0036a23

chore(deps): bump the production-dependencies group with 5 updates
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) from 0.34.0 to 0.35.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](aquasecurity/trivy-action@0.34.0...0.35.0)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-version: 0.35.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…velop/aquasecurity/trivy-action-0.35.0

chore(deps): bump aquasecurity/trivy-action from 0.34.0 to 0.35.0
…errides

Signed-off-by: night-slayer18 <samanuaia257@gmail.com>
- ajv limited to >=6.14.0 <7 to maintain compatibility with eslint which
  relies on the ajv@6 API (ajv@8 removed defaultMeta).
- All other overrides from previous commit retained.

Signed-off-by: night-slayer18 <samanuaia257@gmail.com>
Signed-off-by: night-slayer18 <samanuaia257@gmail.com>
@netlify

netlify Bot commented Mar 21, 2026

Copy link
Copy Markdown

Deploy Preview for autodocshq ready!

Name Link
🔨 Latest commit d12d658
🔍 Latest deploy log https://app.netlify.com/projects/autodocshq/deploys/69be9246c9ed2500087506ab
😎 Deploy Preview https://deploy-preview-27--autodocshq.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@github-actions

Copy link
Copy Markdown

🚀 Deployed on https://pr-27--autodocshq.netlify.app

@github-actions
github-actions Bot temporarily deployed to pull request March 21, 2026 12:43 Inactive
@github-actions

Copy link
Copy Markdown

Preview Deployment

Your preview is ready.

URL: https://pr-27--autodocshq.netlify.app


Deployed from commit d738346

@codecov

codecov Bot commented Mar 21, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@night-slayer18
night-slayer18 merged commit badeef7 into main Mar 21, 2026
39 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant