From 5a42c6234491bce0a9fe9a3d94cc6544ee86cfc8 Mon Sep 17 00:00:00 2001 From: Claude Date: Tue, 29 Sep 2026 15:54:05 +0000 Subject: [PATCH 1/2] chore(changeset): upgrade note and the changes 17.5.0 shipped without notes (#20622) --- ...aftercare-upgrade-and-unannounced-notes.md | 32 +++++++++++++++++++ 1 file changed, 32 insertions(+) create mode 100644 .changeset/20622-release-aftercare-upgrade-and-unannounced-notes.md diff --git a/.changeset/20622-release-aftercare-upgrade-and-unannounced-notes.md b/.changeset/20622-release-aftercare-upgrade-and-unannounced-notes.md new file mode 100644 index 0000000000..f71da0df46 --- /dev/null +++ b/.changeset/20622-release-aftercare-upgrade-and-unannounced-notes.md @@ -0,0 +1,32 @@ +--- +'@objectstack/cli': patch +--- + +Upgrade note for a lockfile-preserving upgrade, and the changes 17.5.0 shipped without release notes (#20622) + +Clause-②: no + +**Upgrading with a scanner.** The raised dependency floors (`hono ^4.13.5` in `@objectstack/plugin-hono-server`) cover the `hono` that objectstack loads. A lockfile-preserving upgrade can keep an older `hono` copy under `@modelcontextprotocol/sdk` (reached through `@objectstack/cli` → `@objectstack/mcp`). objectstack never loads that copy: `@objectstack/mcp` imports only the SDK's `server/mcp`, `server/stdio`, `server/webStandardStreamableHttp` and `types` modules, none of which imports `hono`. A scanner still reports it. Run `pnpm update hono` (or your package manager's equivalent) to move it to the patched line. + +**Shipped in 17.5.0 without notes.** 17.5.0 was published from a commit later than its version commit, so the changesets below shipped inside 17.5.0 but were not consumed by it. Their notes appear in this release for the first time. Breaking entries come first. + +Breaking: + +- #20458 feat(spec)!: retire the inner name on cube measures and dimensions — the record key is the member's name +- #20504 fix(spec,driver-turso)!: refuse a forced mode replica with no syncUrl at authoring and at construction +- #20567 feat(spec)!: RealtimeEventType names the emitted data.record.* / data.records.* vocabulary (carries two changesets) + +Also shipped: + +- #20568 fix(spec): os migrate meta guidance for fourteen more migration-entry families states each lesson in words, not tracker numbers (stage 7) +- #20572 refactor(spec): step 18 rationale as key-sorted fragments, conversionIds derived, so two retirements merge clean +- #20576 docs(spec): re-anchor the dead tracker citations in ui/ and two freed sites to the commits that decided them (stage 5) +- #20577 fix(spec,objectql): name the aggregated column at `having`, PostgreSQL only at `where` +- #20579 fix(spec,cli): os validate / os build read the ADR-0087 conversions defineStack applied — --json conversions and --strict see the producer's record +- #20582 feat(sdui-parser): the manifest marks the html tier's intrinsic tags `tier: 'html'`, ported from objectui's lockstep copy +- #20584 fix(plugin-security): an organization-less permission-set read resolves organization-less rows only +- #20585 fix(service-automation,metadata-protocol,metadata,runtime): withhold a flow's inbound-hook secret from every served definition, and keep it on a round trip +- #20591 fix(spec): nextUtcCalendarDay and utcInstantMs read years 0001..0099 as written, not as 1900..1999 +- #20598 fix(plugin-security): security/explain answers enforcement's refusal for a row-level policy comparing two fields of no shared comparison class +- #20605 fix(plugin-audit): describe sys_comment reactions and mentions by the shape they store +- #20606 docs(spec): re-anchor the dead tracker citations in the packages/spec/src remainder to the commits and ADRs that decided them (stage 6) From 5cbc928cf1057a97b804a33055f5fb32976867d7 Mon Sep 17 00:00:00 2001 From: Claude Date: Tue, 29 Sep 2026 16:03:46 +0000 Subject: [PATCH 2/2] chore(changeset): state the unconsumed-changeset cause in words true for all 16 entries (#20622) --- .../20622-release-aftercare-upgrade-and-unannounced-notes.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.changeset/20622-release-aftercare-upgrade-and-unannounced-notes.md b/.changeset/20622-release-aftercare-upgrade-and-unannounced-notes.md index f71da0df46..8e45ebfd0e 100644 --- a/.changeset/20622-release-aftercare-upgrade-and-unannounced-notes.md +++ b/.changeset/20622-release-aftercare-upgrade-and-unannounced-notes.md @@ -8,7 +8,7 @@ Clause-②: no **Upgrading with a scanner.** The raised dependency floors (`hono ^4.13.5` in `@objectstack/plugin-hono-server`) cover the `hono` that objectstack loads. A lockfile-preserving upgrade can keep an older `hono` copy under `@modelcontextprotocol/sdk` (reached through `@objectstack/cli` → `@objectstack/mcp`). objectstack never loads that copy: `@objectstack/mcp` imports only the SDK's `server/mcp`, `server/stdio`, `server/webStandardStreamableHttp` and `types` modules, none of which imports `hono`. A scanner still reports it. Run `pnpm update hono` (or your package manager's equivalent) to move it to the patched line. -**Shipped in 17.5.0 without notes.** 17.5.0 was published from a commit later than its version commit, so the changesets below shipped inside 17.5.0 but were not consumed by it. Their notes appear in this release for the first time. Breaking entries come first. +**Shipped in 17.5.0 without notes.** The changesets below were in the tree 17.5.0 was published from, but its version commit did not consume them, so they shipped inside 17.5.0 without release notes. Their notes appear in this release for the first time. Breaking entries come first. Breaking: