Skip to content

chore: cli 5.7.1 - #216

Merged
finalerock44 merged 7 commits into
productionfrom
promote/cli-5.7.1
Oct 7, 2026
Merged

finalerock44 merged 7 commits into
productionfrom
promote/cli-5.7.1

Conversation

@finalerock44

Copy link
Copy Markdown
Contributor

What & why

Type of change

  • fix — bug fix
  • feat — new feature
  • perf — performance improvement
  • refactor — code change that's neither a fix nor a feature
  • docs — documentation only
  • chore / ci / build / test — tooling, no user-facing change
  • Breaking change (title has ! or PR notes a BREAKING CHANGE:)

Checklist

  • PR title follows the Conventional Commits format (see comment above)
  • pnpm lint passes
  • pnpm typecheck passes
  • pnpm build passes
  • I have not bumped the version or edited CHANGELOG.md (release-please handles this)
  • I have signed the CLA (the bot will prompt on first contribution)
  • Docs / README.md / STYLE_GUIDE.md updated if behaviour or output changed

How to test

finalerock44 and others added 6 commits October 2, 2026 18:05
node-apk pulled in node-forge, which has an unpatched high-severity
advisory (GHSA-86w9-cpqp-85rv, RSA PKCS#1 v1.5 signature forgery) that
fails `pnpm audit` on every PR. node-forge 1.4.0 is the latest release
and the upstream fix (digitalbazaar/forge#1152) is unmerged a month on;
node-apk itself hasn't been released since 2023.

The CLI only ever needed the package name, so read it straight out of
AndroidManifest.xml: node-stream-zip (already a dependency) extracts the
entry and a small Android binary XML reader takes the root <manifest>'s
package attribute.

Checked against aapt2 and node-apk on 54 real APKs (fixtures, emulator
overlays, customer reproduction binaries), all identical. Those all use
UTF-16 string pools, so unit tests build UTF-8 and UTF-16 manifests by
hand (both verified readable by aapt and aapt2) and cover the error
paths.

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The release workflow's back-merge PR is opened by the release-please
GitHub App, and claude-code-action refuses non-human actors, so the
required claude-review check fails and blocks the merge (#197, #209).
The PR only carries production code already reviewed through dev, so
skip it like the release-please release PRs.
* chore: pin the 5.7.0 promotion

Release-As: 5.7.0

* chore(production): release 5.7.0

---------

Co-authored-by: finalerock44 <ethan@devicecloud.dev>
Co-authored-by: finalerock44 <77282157+finalerock44@users.noreply.github.com>
Co-authored-by: dcd-cli-release-please[bot] <296541543+dcd-cli-release-please[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Three high advisories now fail `pnpm audit --audit-level moderate` on
dev, so every PR, the release PR included, goes red at the audit step:

- @modelcontextprotocol/sdk <1.31.0 (GHSA-6qxp-vccf-f47h). A runtime
  dependency that ships in dcd-mcp. Raise the floor to ^1.31.0 (resolves
  1.32.1). dcd-mcp only uses the stdio server, so the 1.31/1.32 client
  OAuth and redirect changes don't touch it.
- source-map-js <1.2.2 (GHSA-68fv-2mgg-jv7q). Dev only, via
  eslint-plugin-unicorn > @eslint/css-tree. Override to 1.2.2.
- braces <=3.0.3 (GHSA-vfj7-8cjw-p6xm). Dev only, via shx > shelljs >
  fast-glob > micromatch, which the build script runs on fixed paths.
  No patched release exists, so ignore it in auditConfig. Drop the
  ignore once braces ships a fix, or drop shx.
#215)

Bumps the minor-and-patch group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [chalk](https://github.com/chalk/chalk) | `6.0.0` | `6.0.1` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.3` | `26.6.4` |
| [chai](https://github.com/chaijs/chai) | `6.2.2` | `6.3.0` |
| [eslint](https://github.com/eslint/eslint) | `10.11.0` | `10.12.0` |
| [mocha](https://github.com/mochajs/mocha) | `12.0.2` | `12.0.3` |
| [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint) | `8.70.1` | `8.71.0` |



Updates `chalk` from 6.0.0 to 6.0.1
- [Release notes](https://github.com/chalk/chalk/releases)
- [Commits](chalk/chalk@v6.0.0...v6.0.1)

Updates `@types/node` from 26.6.3 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `chai` from 6.2.2 to 6.3.0
- [Release notes](https://github.com/chaijs/chai/releases)
- [Changelog](https://github.com/chaijs/chai/blob/main/History.md)
- [Commits](chaijs/chai@v6.2.2...v6.3.0)

Updates `eslint` from 10.11.0 to 10.12.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.11.0...v10.12.0)

Updates `mocha` from 12.0.2 to 12.0.3
- [Release notes](https://github.com/mochajs/mocha/releases)
- [Changelog](https://github.com/mochajs/mocha/blob/main/CHANGELOG.md)
- [Commits](mochajs/mocha@v12.0.2...v12.0.3)

Updates `typescript-eslint` from 8.70.1 to 8.71.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.71.0/packages/typescript-eslint)

---
updated-dependencies:
- dependency-name: chalk
  dependency-version: 6.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: chai
  dependency-version: 6.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: eslint
  dependency-version: 10.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: mocha
  dependency-version: 12.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: typescript-eslint
  dependency-version: 8.71.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@finalerock44 finalerock44 self-assigned this Oct 7, 2026
@claude

claude Bot commented Oct 7, 2026

Copy link
Copy Markdown

Code review

No issues found. Checked for bugs and CLAUDE.md compliance.

@finalerock44 finalerock44 changed the title promote: cli 5.7.1 chore: cli 5.7.1 Oct 7, 2026
@finalerock44
finalerock44 merged commit d0c32ac into production Oct 7, 2026
6 checks passed
@finalerock44
finalerock44 deleted the promote/cli-5.7.1 branch October 7, 2026 13:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant