Skip to content

chore(release): version packages — security updates for lodash and NestJS#1231

Merged
underfisk merged 1 commit into
masterfrom
copilot/create-release-based-on-prs
May 20, 2026
Merged

chore(release): version packages — security updates for lodash and NestJS#1231
underfisk merged 1 commit into
masterfrom
copilot/create-release-based-on-prs

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented May 20, 2026

Summary

Release based on recent merged PRs. Bumps patch versions for packages affected by security dependency updates.

Packages bumped

Package From To Reason
@golevelup/nestjs-common 6.0.0 6.0.1 lodash security update
@golevelup/nestjs-discovery 7.0.0 7.0.1 lodash + @nestjs/core security updates
@golevelup/nestjs-modules 2.0.0 2.0.1 lodash security update
@golevelup/nestjs-rabbitmq 9.0.1 9.0.2 lodash + @nestjs/core security updates

PRs included since last release

  • #1230 — chore(deps): update dependency lodash to v4.18.1 [security]
  • #1228 — chore(deps): update dependency @nestjs/core to v11.1.18 [security] (consolidated to v11.1.21 via chore(deps): consolidate dependency and toolchain upgrades #1225)
  • #1229 — chore(deps): update dependency vite to v8.0.5 [security] (dev-only, no package bump)
  • #1212 — chore(deps): update vitest monorepo to v4.1.7 (dev-only, no package bump)
  • #1213 — chore(deps): update dependency @aws-sdk/client-s3 to v3.1050.0 (not in published packages)
  • #1225 — chore(deps): consolidate dependency and toolchain upgrades (dev-only toolchain)

Notes

  • vite, vitest, and @aws-sdk/client-s3 are dev-only dependencies and do not affect published packages — no version bump needed for those.
  • Changesets were generated and changeset version was run to produce the updated package.json and CHANGELOG.md files.

@underfisk underfisk marked this pull request as ready for review May 20, 2026 15:24
Copilot AI review requested due to automatic review settings May 20, 2026 15:24
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR performs a patch release across affected @golevelup/* packages to publish recent security dependency updates (lodash and NestJS peer dependency ranges), aligning package versions and changelogs for the monorepo release workflow.

Changes:

  • Bump patch versions for common, discovery, modules, and rabbitmq.
  • Add corresponding changelog entries documenting the security-related dependency updates.
  • Record the nestjs-discovery@7.0.1 bump as an updated dependency for nestjs-rabbitmq.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated no comments.

Show a summary per file
File Description
packages/rabbitmq/package.json Patch version bump to 9.0.2 for the RabbitMQ package release.
packages/rabbitmq/CHANGELOG.md Adds 9.0.2 entry documenting lodash/NestJS security updates and updated dependency.
packages/modules/package.json Patch version bump to 2.0.1 for the modules package release.
packages/modules/CHANGELOG.md Adds 2.0.1 entry documenting lodash security update.
packages/discovery/package.json Patch version bump to 7.0.1 for the discovery package release.
packages/discovery/CHANGELOG.md Adds 7.0.1 entry documenting lodash/NestJS security updates.
packages/common/package.json Patch version bump to 6.0.1 for the common package release.
packages/common/CHANGELOG.md Adds 6.0.1 entry documenting lodash security update.

@underfisk underfisk merged commit 719ffc5 into master May 20, 2026
6 checks passed
@underfisk underfisk deleted the copilot/create-release-based-on-prs branch May 20, 2026 15:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants