Skip to content

fix(deps): bump @contentstack/core to ^1.5.3, release 5.6.1 - #401

Merged
cs-raj merged 1 commit into
developmentfrom
fix/deps-update-2026-10-06
Oct 6, 2026
Merged

cs-raj merged 1 commit into
developmentfrom
fix/deps-update-2026-10-06

Conversation

@cs-raj

@cs-raj cs-raj commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Problem

@contentstack/delivery-sdk 5.6.0 resolves @contentstack/core 1.5.2, whose dependency tree carries a known security vulnerability in qs (fixed in qs 6.16.0). The follow-redirects override and the TypeScript toolchain were also behind their current patch releases.

Fix

  • Bump @contentstack/core to ^1.5.3 (lockfile 1.5.3), which moves qs to 6.16.0 — the qs and @contentstack/core advisories no longer appear in npm audit; the remaining advisories are all in the jest dev toolchain and were already present.
  • Raise the follow-redirects override to ^1.16.1 (lockfile 1.16.1).
  • Update typescript to ~5.9.3 (dev dependency; build and declaration output unchanged).
  • Transitive lockfile refresh pulled in by the above: handlebars 4.7.10, acorn 8.19.0, @types/node 26.6.4, @types/ws 8.18.2, browserslist/caniuse data.
  • Version 5.6.1 with the CHANGELOG entry.

Verification

Node 23 / npm 10.9: npm ci, npm run build (rollup + types) and npm run test:unit (36 suites, 720 tests) all pass. npm audit --package-lock-only drops from 40 to 38 advisories, the two removed being qs and @contentstack/core.

Resolve security vulnerabilities in dependencies: @contentstack/core 1.5.3
moves qs to 6.16.0, and the follow-redirects override is raised to ^1.16.1.
TypeScript updated to ~5.9.3 for the build toolchain.

Co-Authored-By: Claude Fable 5.1 <[email protected]>
@cs-raj cs-raj self-assigned this Oct 6, 2026
@cs-raj
cs-raj requested a review from a team as a code owner October 6, 2026 06:16
@snyk-io

snyk-io Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

🔒 Security Scan Results

ℹ️ Note: Only vulnerabilities with available fixes (upgrades or patches) are counted toward thresholds.

Check Type Count (with fixes) Without fixes Threshold Result
🔴 Critical Severity 0 0 10 ✅ Passed
🟠 High Severity 0 0 25 ✅ Passed
🟡 Medium Severity 0 0 500 ✅ Passed
🔵 Low Severity 0 0 1000 ✅ Passed

⏱️ SLA Breach Summary

✅ No SLA breaches detected. All vulnerabilities are within acceptable time thresholds.

Severity Breaches (with fixes) Breaches (no fixes) SLA Threshold (with/no fixes) Status
🔴 Critical 0 0 15 / 30 days ✅ Passed
🟠 High 0 0 30 / 120 days ✅ Passed
🟡 Medium 0 0 90 / 365 days ✅ Passed
🔵 Low 0 0 180 / 365 days ✅ Passed

✅ BUILD PASSED - All security checks passed

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Coverage report

St.❔
Category Percentage Covered / Total
🟢 Statements 98.9% 993/1004
🟢 Branches 96.52% 305/316
🟢 Functions 97.79% 221/226
🟢 Lines 99.37% 945/951

Test suite run success

720 tests passing in 36 suites.

Report generated by 🧪jest coverage report action from 50ca418

@cs-raj
cs-raj merged commit 8a862db into development Oct 6, 2026
11 checks passed
@cs-raj
cs-raj deleted the fix/deps-update-2026-10-06 branch October 6, 2026 06:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants