Skip to content

[Snyk] Security upgrade @changesets/cli from 2.31.1 to 3.0.0 - #1196

Open
steveukx wants to merge 1 commit into
mainfrom
snyk-fix-7611222c92a9488bc74b14117f2d3dc2
Open

steveukx wants to merge 1 commit into
mainfrom
snyk-fix-7611222c92a9488bc74b14117f2d3dc2

Conversation

@steveukx

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

  • package.json

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning
Failed to update the yarn.lock, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Uncontrolled Recursion
SNYK-JS-BRACES-19963945
  721  

Breaking Change Risk

Merge Risk: High

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Uncontrolled Recursion

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-BRACES-19963945
@steveukx

Copy link
Copy Markdown
Owner Author

Merge Risk: High

The upgrade to @changesets/cli v3.0.0 is a major version with significant breaking changes that require developer action.

Key Breaking Changes:

  • Node.js and Module System: All Changesets packages are now ESM-only and require Node.js version ^22.11 || ^24 || >=26. Any scripts using CommonJS (require) to interact with Changesets packages must be updated.

  • Command Renames: Several core commands have been renamed, which will break CI/CD pipelines and local scripts.

    • changeset bump is now changeset version
    • changeset release is now changeset publish
    • changeset tag is now changeset git-tag
  • Peer Dependency Bumping: The default behavior for peer dependency bumps has changed. Previously, a minor bump would trigger a major version increase for dependents; now it triggers a patch bump. This may affect your versioning strategy.

  • Configuration and API:

    • The commit option in the configuration file is no longer supported.
    • The data passed to custom changelog generation functions has changed. For example, release.version is now release.newVersion.

Recommendation:
This upgrade requires careful migration. Before merging, you must:

  1. Ensure your development and CI environments use a compatible Node.js version (22.11+).
  2. Update all CI/CD scripts and local commands to use the new command names (version, publish).
  3. Review any custom scripts that interact with Changesets packages to ensure they are compatible with ESM.
  4. Consult the official migration guide for a complete list of changes.

Source: Announcing Changesets v3, GitHub Changelog

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@changeset-bot

changeset-bot Bot commented Sep 23, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 8fd0048

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants