Repository navigation
Releases: lingodotdev/lingo.dev
Release list
lingo.dev@0.138.10
Patch Changes
-
#2235
077c680Thanks @AndreyHirsa! - Bumpfigletfrom 1.9.4 to 1.11.4. -
#2230
2893846Thanks @AndreyHirsa! - Bump@markdoc/markdocfrom 0.5.4 to 0.5.10 andcsv-stringifyfrom 6.6.0 to 6.9.0.
lingo.dev@0.138.9
Patch Changes
- #2220
81525d1Thanks @moygospadin! - Pass the working directory togit config safe.directoryas an argument instead of interpolating it into a shell command
@lingo.dev/compiler@0.4.14
@lingo.dev/_react@0.7.12
@lingo.dev/_compiler@0.12.15
lingo.dev@0.138.8
Patch Changes
-
#2208
8dfdf49Thanks @cherkanovart! - Clear twonpm auditadvisories that surfaced through transitive dependencies.csv-parsemoves from 5.6.0 to 7.0.2, which patches GHSA-8cw4-87c7-c6xx (prototype replacement reachable through thecolumnsoption). None of the options renamed in csv-parse 6.0.0 were in use, so the CSV loaders are unchanged.The AI SDK packages move to the latest release of the major they were already on, so that
@ai-sdk/provider-utilsresolves at or above 4.0.33 and clears GHSA-866g-f22w-33x8 (uncontrolled resource consumption). The SDK packages pin@ai-sdk/provider-utilsto an exact version, so bumping them is the only way to reach it:aigoes to 6.0.280 and@ai-sdk/anthropic,@ai-sdk/google,@ai-sdk/groq,@ai-sdk/mistraland@ai-sdk/openaifollow on their 3.x line.The system prompt moves from a
{ role: "system" }entry inmessagesto thesystemoption ongenerateText. Sinceai6.0.170 the former makes the SDK print a prompt-injection warning on every BYOK run.The basic translator also stops wrapping its system prompt in a serialized
{ role, content }envelope before handing it over, so the provider now receives the prompt text on its own rather than a line of JSON quoting it. This is the one change here that alters what reaches the model.
@lingo.dev/compiler@0.4.13
Patch Changes
-
#2208
8dfdf49Thanks @cherkanovart! - Clear twonpm auditadvisories that surfaced through transitive dependencies.csv-parsemoves from 5.6.0 to 7.0.2, which patches GHSA-8cw4-87c7-c6xx (prototype replacement reachable through thecolumnsoption). None of the options renamed in csv-parse 6.0.0 were in use, so the CSV loaders are unchanged.The AI SDK packages move to the latest release of the major they were already on, so that
@ai-sdk/provider-utilsresolves at or above 4.0.33 and clears GHSA-866g-f22w-33x8 (uncontrolled resource consumption). The SDK packages pin@ai-sdk/provider-utilsto an exact version, so bumping them is the only way to reach it:aigoes to 6.0.280 and@ai-sdk/anthropic,@ai-sdk/google,@ai-sdk/groq,@ai-sdk/mistraland@ai-sdk/openaifollow on their 3.x line.The system prompt moves from a
{ role: "system" }entry inmessagesto thesystemoption ongenerateText. Sinceai6.0.170 the former makes the SDK print a prompt-injection warning on every BYOK run.The basic translator also stops wrapping its system prompt in a serialized
{ role, content }envelope before handing it over, so the provider now receives the prompt text on its own rather than a line of JSON quoting it. This is the one change here that alters what reaches the model. -
Updated dependencies [
8dfdf49]:- lingo.dev@0.138.8
@lingo.dev/_compiler@0.12.14
Patch Changes
-
#2208
8dfdf49Thanks @cherkanovart! - Clear twonpm auditadvisories that surfaced through transitive dependencies.csv-parsemoves from 5.6.0 to 7.0.2, which patches GHSA-8cw4-87c7-c6xx (prototype replacement reachable through thecolumnsoption). None of the options renamed in csv-parse 6.0.0 were in use, so the CSV loaders are unchanged.The AI SDK packages move to the latest release of the major they were already on, so that
@ai-sdk/provider-utilsresolves at or above 4.0.33 and clears GHSA-866g-f22w-33x8 (uncontrolled resource consumption). The SDK packages pin@ai-sdk/provider-utilsto an exact version, so bumping them is the only way to reach it:aigoes to 6.0.280 and@ai-sdk/anthropic,@ai-sdk/google,@ai-sdk/groq,@ai-sdk/mistraland@ai-sdk/openaifollow on their 3.x line.The system prompt moves from a
{ role: "system" }entry inmessagesto thesystemoption ongenerateText. Sinceai6.0.170 the former makes the SDK print a prompt-injection warning on every BYOK run.The basic translator also stops wrapping its system prompt in a serialized
{ role, content }envelope before handing it over, so the provider now receives the prompt text on its own rather than a line of JSON quoting it. This is the one change here that alters what reaches the model.
lingo.dev@0.138.7
Patch Changes
- #2204
ee3fa2eThanks @AndreyHirsa! - Remove the unusedremark-mdx-frontmatterimport and dependency from the mdx loader.
lingo.dev@0.138.6
Patch Changes
-
#2197
9db8613Thanks @cherkanovart! - Fixrun --key, which matched nothing and could overwrite unrelated lockfile entries.--keyfiltered with a raw glob match, but flat buckets join nesting with/, so a prefix likeauth/loginmatched no key at all and the run reported everything as cached. It now matches on exact key, on a prefix that ends at a/, or on a glob.auth/loginselectsauth/login/titleand leavesauth/login_urlandsign-in-erroralone.A
--keyrun also wrote checksums for every source key, not just the translated subset, which marked untouched keys as translated ini18n.lock.--keynow suppresses the checksum write, as--target-localealready did, and no longer computes the discarded checksums at all.The help text for
--keydocumented dot-separated paths and anauth.loginexample, neither of which matched real keys. It now states the/separator, that a prefix must end at one, and that a glob does not cross one.The
--frozenfailure message told the user to runlingo.dev lockfile, which does nothing once the lockfile section is populated. It now points atlingo.dev run, which localizes what is pending and updates the lockfile.