From 5c8252f83b8fd3764cb5e80bcf909c8d56ec2a65 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Thu, 24 Sep 2026 15:42:28 +0000 Subject: [PATCH] ci(changesets): version packages --- .changeset/pin-platform-sdk-range.md | 9 --------- .changeset/upgrade-jsondiffpatch.md | 9 --------- packages/sync-actions/CHANGELOG.md | 18 ++++++++++++++++++ packages/sync-actions/package.json | 2 +- 4 files changed, 19 insertions(+), 19 deletions(-) delete mode 100644 .changeset/pin-platform-sdk-range.md delete mode 100644 .changeset/upgrade-jsondiffpatch.md diff --git a/.changeset/pin-platform-sdk-range.md b/.changeset/pin-platform-sdk-range.md deleted file mode 100644 index 5ba6b4c..0000000 --- a/.changeset/pin-platform-sdk-range.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -'@commercetools/sync-actions': patch ---- - -Replace the `latest` version range for `@commercetools/platform-sdk` with `^9.4.0`. - -The `latest` descriptor re-resolved on every lockfile refresh and crossed major boundaries without review, which is how the 8.x to 9.x upgrade landed unannounced. A caret range matches the other packages in this repository and routes future updates through reviewable dependency PRs, with major upgrades gated behind explicit approval. - -This is a dependency-declaration change only. The public API and observable behavior of `@commercetools/sync-actions` are unchanged. diff --git a/.changeset/upgrade-jsondiffpatch.md b/.changeset/upgrade-jsondiffpatch.md deleted file mode 100644 index 1244aba..0000000 --- a/.changeset/upgrade-jsondiffpatch.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -'@commercetools/sync-actions': minor ---- - -Upgrade the `jsondiffpatch` dependency from `0.5.0` to `^0.7.6`, moving off an unmaintained release onto the current maintained version. - -A customer security report referenced `jsonpath-plus` (which is not, and never was, a dependency of this package). The reported version facts — pinned `0.5.0`, fixed in `0.7.6`, not backwards compatible — instead correspond to `jsondiffpatch`, a direct dependency used by the diff/patch utility behind update-action generation. This change adopts `jsondiffpatch@0.7.6`. - -The public API and observable behavior of `@commercetools/sync-actions` are unchanged. Internally: `jsondiffpatch` 0.7 is ESM-only, so imports were updated to the package root and the dependency is bundled into the published CommonJS, ESM, and UMD artifacts (CommonJS consumers are unaffected). Fine-grained text diffing remains disabled, so a changed string is still reported as a whole-value replacement. diff --git a/packages/sync-actions/CHANGELOG.md b/packages/sync-actions/CHANGELOG.md index b269d91..45b9fe1 100644 --- a/packages/sync-actions/CHANGELOG.md +++ b/packages/sync-actions/CHANGELOG.md @@ -1,5 +1,23 @@ # @commercetools/sync-actions +## 8.4.0 + +### Minor Changes + +- [#60](https://github.com/commercetools/typescript-dev-utilities/pull/60) [`a4edf89`](https://github.com/commercetools/typescript-dev-utilities/commit/a4edf89bcc79fb156a8c3ce635025d8338dad8b7) Thanks [@marcelogpinheiro](https://github.com/marcelogpinheiro)! - Upgrade the `jsondiffpatch` dependency from `0.5.0` to `^0.7.6`, moving off an unmaintained release onto the current maintained version. + + A customer security report referenced `jsonpath-plus` (which is not, and never was, a dependency of this package). The reported version facts — pinned `0.5.0`, fixed in `0.7.6`, not backwards compatible — instead correspond to `jsondiffpatch`, a direct dependency used by the diff/patch utility behind update-action generation. This change adopts `jsondiffpatch@0.7.6`. + + The public API and observable behavior of `@commercetools/sync-actions` are unchanged. Internally: `jsondiffpatch` 0.7 is ESM-only, so imports were updated to the package root and the dependency is bundled into the published CommonJS, ESM, and UMD artifacts (CommonJS consumers are unaffected). Fine-grained text diffing remains disabled, so a changed string is still reported as a whole-value replacement. + +### Patch Changes + +- [#62](https://github.com/commercetools/typescript-dev-utilities/pull/62) [`ba27b2a`](https://github.com/commercetools/typescript-dev-utilities/commit/ba27b2af071db480b31eace6d31b6b137a7e4f0c) Thanks [@ajimae](https://github.com/ajimae)! - Replace the `latest` version range for `@commercetools/platform-sdk` with `^9.4.0`. + + The `latest` descriptor re-resolved on every lockfile refresh and crossed major boundaries without review, which is how the 8.x to 9.x upgrade landed unannounced. A caret range matches the other packages in this repository and routes future updates through reviewable dependency PRs, with major upgrades gated behind explicit approval. + + This is a dependency-declaration change only. The public API and observable behavior of `@commercetools/sync-actions` are unchanged. + ## 8.3.0 ### Minor Changes diff --git a/packages/sync-actions/package.json b/packages/sync-actions/package.json index b873c68..1a54ad9 100644 --- a/packages/sync-actions/package.json +++ b/packages/sync-actions/package.json @@ -1,6 +1,6 @@ { "name": "@commercetools/sync-actions", - "version": "8.3.0", + "version": "8.4.0", "publishConfig": { "access": "public" },