Skip to content

chore(release): bump version to 0.2.0 - #46

Open
bpedro wants to merge 27 commits into
mainfrom
develop
Open

bpedro wants to merge 27 commits into
mainfrom
develop

Conversation

@bpedro

@bpedro bpedro commented Oct 9, 2026

Copy link
Copy Markdown
Member

Summary

Apply multiple dependency fixes and improvements.

Checklist

  • Commits are signed (git commit -S)
  • Commit messages follow Conventional Commits

ivanasabi and others added 27 commits September 3, 2026 10:09
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* chore(ci-governance): synchronize Node profile

Governance-Provenance: hmac-sha256:0837805e11b99a61122d875508937baaf8f6e7ea3020166fd7d18275ddf05021

* chore(ci-governance): synchronize Node profile

Governance-Provenance: hmac-sha256:9f99e6a9dcda0869e8a2b16e662ab3934595ca748bc2a31590f6fe405a176c10

* chore(ci-governance): synchronize Node profile

Governance-Provenance: hmac-sha256:6349bde86c5f9ca562cdc9e04317b9a0ed7997de24d1e0a58023f15bb0840ea7

---------

Co-authored-by: inditextechci-sync[bot] <312492039+inditextechci-sync[bot]@users.noreply.github.com>
Governance-Provenance: hmac-sha256:a1b6e524ca9f6ce4c32b3a48b2236f856760e1ffb52ab1bf1040104860858f6c

Co-authored-by: inditextechci-sync[bot] <312492039+inditextechci-sync[bot]@users.noreply.github.com>
* chore(ci-governance): synchronize Node profile

Governance-Provenance: hmac-sha256:438b9a2ed034fe83792f50e2f24b554dc25b549c0dccd10f000b52b7b0dc9b18

* chore(ci-governance): synchronize Node profile

Governance-Provenance: hmac-sha256:e52a0fa7ce2702b06cd4f63f609b437a645287cc40fd2a5d71256de0739ccf4b

---------

Co-authored-by: inditextechci-sync[bot] <312492039+inditextechci-sync[bot]@users.noreply.github.com>
* docs: remove empty Development section in CONTRIBUTING

* docs: fix 'recommend to use' -> 'recommend using' in CONTRIBUTING
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Governance-Provenance: hmac-sha256:2a1a3c9bcc9eed2eb78db0630a7376b920c120c3a50ff7caf64cb499c1b9b6f8
Governance-Provenance: hmac-sha256:27a539fd921b3dc485736c72e0b990f4e80e9f9eadd0a39b53c0dc1078cf0511
Governance-Provenance: hmac-sha256:7c5063e572e2a745640531909b4f8037bc5a8463cc324f907f3aa300aef7a2b2
chore(ci-governance): synchronize Node profile
Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.11 to 5.0.1.
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.1/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 5.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
Bumps [swagger-ui-react](https://github.com/swagger-api/swagger-ui) from 5.32.14 to 5.33.0.
- [Release notes](https://github.com/swagger-api/swagger-ui/releases)
- [Commits](swagger-api/swagger-ui@v5.32.14...v5.33.0)

---
updated-dependencies:
- dependency-name: swagger-ui-react
  dependency-version: 5.33.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
Bumps [prettier](https://github.com/prettier/prettier) from 3.9.6 to 3.9.8.
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.9.6...3.9.8)

---
updated-dependencies:
- dependency-name: prettier
  dependency-version: 3.9.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
* chore(ci-governance): synchronize Node profile

Governance-Provenance: hmac-sha256:cea719fa0a94c0a129876ddf39623a83de6718bd0610c8ee1bb52e9f830799b5

* chore(ci-governance): synchronize Node profile

Governance-Provenance: hmac-sha256:a0d13af33b94dac8034b6e3da720b99fd295355064354e48808ff7425af9f79d

* chore(ci-governance): synchronize Node profile

Governance-Provenance: hmac-sha256:27c98b36663866b3da69897d84ed0996e4b697df4291d336f20ff3f0c4030a13

---------

Co-authored-by: inditextechci-sync[bot] <312492039+inditextechci-sync[bot]@users.noreply.github.com>
Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
Bumps [undici](https://github.com/nodejs/undici) from 7.29.0 to 7.30.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.29.0...v7.30.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 7.30.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.14 to 3.4.16.
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.14...3.4.16)

---
updated-dependencies:
- dependency-name: dompurify
  dependency-version: 3.4.16
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
…rsions (#42)

Resolves the 8 open Dependabot alerts:

- undici 7.29.0 -> 7.30.0 (transitive of jsdom, dev, root lockfile):
  GHSA-3wwx-pv8p-q78v, GHSA-pmjh-fq2x-6v4x, GHSA-r53p-7pc4-xj5r
- dompurify 3.4.14 -> 3.4.16 (root dev + example runtime, both via
  swagger-ui-react): GHSA-p98j-92pf-mc4p
- brace-expansion 1.1.18 -> 1.21, 5.0.9 -> 5.0.12 (root, dev):
  GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p, GHSA-q2hr-2g5m-vwhr

npm audit reports 0 vulnerabilities in both lockfiles; npm run verify
(lint, prettier, 21 vitest tests, build) passes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2.
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

---
updated-dependencies:
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.18 to 1.1.21.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v1.1.18...v1.1.21)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Bruno Pedro <brunolgp@inditex.com>
@bpedro
bpedro requested a review from a team as a code owner October 9, 2026 12:29
@bpedro bpedro added the release-type/minor Publish the next minor release. label Oct 9, 2026
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Comment on lines +661 to +741
run: |
set -euo pipefail

case ",$RELEASE_LABELS," in
*",release-type/major,"*) release_bump="major" ;;
*",release-type/minor,"*) release_bump="minor" ;;
*",release-type/hotfix,"*|*",release-type/multi-hotfix,"*|*",release-type/patch,"*)
release_bump="patch"
;;
*)
if [[ "$DEVELOPMENT_FLOW" == "trunk-based-development" ]]; then
release_bump="minor"
else
echo "::error title=Missing release type::git-flow releases require a release-type label."
exit 1
fi
;;
esac
export RELEASE_BUMP="$release_bump"

git tag | sort > "$RUNNER_TEMP/tags-before.txt"

case "${PACKAGE_MANAGER:-npm}" in
npm) npm run release:prepare ;;
pnpm) corepack enable; pnpm run release:prepare ;;
*) echo "::error title=Invalid package manager::PACKAGE_MANAGER must be npm or pnpm."; exit 1 ;;
esac

git tag | sort > "$RUNNER_TEMP/tags-after.txt"
new_tags=()
while IFS= read -r tag; do
new_tags+=("$tag")
done < <(comm -13 "$RUNNER_TEMP/tags-before.txt" "$RUNNER_TEMP/tags-after.txt")
if [[ ${#new_tags[@]} -eq 0 ]]; then
echo "::error title=No release cut::release:prepare produced no new tags."
exit 1
fi

records_file="$RUNNER_TEMP/node-release-records.jsonl"
: > "$records_file"
for tag in "${new_tags[@]}"; do
tag_target="$(git rev-parse "${tag}^{commit}")"
if [[ "$tag" =~ ([0-9]+\.[0-9]+\.[0-9]+([-+.][0-9A-Za-z.-]+)?)$ ]]; then
version="${BASH_REMATCH[1]}"
else
version="$tag"
fi
jq -cn \
--arg tag "$tag" \
--arg tag_target "$tag_target" \
--arg version "$version" \
--arg bump "$release_bump" \
'{packages: [], version: $version, tag: $tag, tag_target: $tag_target, next_dev: "", release_bump: $bump}' \
>> "$records_file"
done
releases="$(jq -cs . "$records_file")"
primary_version="$(jq -r '.[0].version' <<< "$releases")"

changelog_pending="false"
if [[ -f CHANGELOG.md ]] \
&& awk '/^## \[?[Uu]nreleased\]?/{f=1;next} /^## /{f=0} f && NF {print; exit}' CHANGELOG.md | grep -q .; then
changelog_pending="true"
fi

echo "RELEASE_BUMP=$release_bump" >> "$GITHUB_ENV"
echo "RELEASE_VERSION=$primary_version" >> "$GITHUB_ENV"
# CHANGELOG links must name real tags: independent workspaces tag
# <member>-<version>, so the prefix is the primary tag minus its
# version (empty for single and locked-step releases).
primary_tag="$(jq -r '.[0].tag' <<< "$releases")"
echo "CHANGELOG_TAG_PREFIX=${primary_tag%"$primary_version"}" >> "$GITHUB_ENV"

{
echo "expected_ref=refs/heads/$BASELINE_BRANCH"
echo "source_commit=$RELEASE_SOURCE_COMMIT"
echo "primary_version=$primary_version"
echo "changelog_pending=$changelog_pending"
echo "releases_intermediate<<EOF"
printf '%s\n' "$releases"
echo "EOF"
} >> "$GITHUB_OUTPUT"
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

❌ No changes in CHANGELOG.md

Update the ## [Unreleased] section listing the changes for this release before merging.

This branch was successfully deployed

1 active deployment
npm-snapshot — ad9ae951 Deployed Oct 9, 2026 by bpedro via Publish snapshot #54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release-type/minor Publish the next minor release.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants