CHANGELOG promotion was a manual operator step that was never run, so 463 fragments for work already shipped in <=1.3.1 accumulated in .changeset/. Their notes were already hand-curated into the dated [1.2.0]/[1.3.0]/[1.3.1] CHANGELOG sections (#690 backfill, PR #694). Rendering them now would duplicate and mis-attribute shipped work. Move them to .changeset/archived/ (read non-recursively by all changeset tooling, so never rendered), keeping only the 3 genuinely-unreleased fragments at the top level. Prep for wiring `render` into the release finalize job (#690 follow-up). Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
427 B
427 B
type, pr
| type | pr |
|---|---|
| Security | 3588 |
npm audit --omit=dev is clean — bumped lockfile-pinned transitive versions of fast-uri, @anthropic-ai/sdk, hono, ip-address, and express-rate-limit (pulled in through @anthropic-ai/claude-agent-sdk and @modelcontextprotocol/sdk) to patched releases. Same pass applied to sdk/package-lock.json (was clean for production already; the test now locks it in). Resolves #3588.