Sitelet https://github.com/lingodotdev/lingo.dev/releases
Skip to content

Releases: lingodotdev/lingo.dev

lingo.dev@0.138.10

Choose a tag to compare

@github-actions github-actions released this 07 Oct 10:57
cb06644

Patch Changes

lingo.dev@0.138.9

Choose a tag to compare

@github-actions github-actions released this 05 Oct 13:13

Patch Changes

  • #2220 81525d1 Thanks @moygospadin! - Pass the working directory to git config safe.directory as an argument instead of interpolating it into a shell command

@lingo.dev/compiler@0.4.14

Choose a tag to compare

@github-actions github-actions released this 14 Sep 09:37
78fca71

Patch Changes

  • #2213 d664a88 Thanks @ohmoses! - Updated dependency overrides to patch critical and high severity vulnerabilities.

@lingo.dev/_react@0.7.12

Choose a tag to compare

@github-actions github-actions released this 14 Sep 09:37
78fca71

Patch Changes

  • #2213 d664a88 Thanks @ohmoses! - Updated dependency overrides to patch critical and high severity vulnerabilities.

@lingo.dev/_compiler@0.12.15

Choose a tag to compare

@github-actions github-actions released this 14 Sep 09:37
78fca71

Patch Changes

  • #2213 d664a88 Thanks @ohmoses! - Updated dependency overrides to patch critical and high severity vulnerabilities.

lingo.dev@0.138.8

Choose a tag to compare

@github-actions github-actions released this 11 Sep 12:43
3a68459

Patch Changes

  • #2208 8dfdf49 Thanks @cherkanovart! - Clear two npm audit advisories that surfaced through transitive dependencies.

    csv-parse moves from 5.6.0 to 7.0.2, which patches GHSA-8cw4-87c7-c6xx (prototype replacement reachable through the columns option). None of the options renamed in csv-parse 6.0.0 were in use, so the CSV loaders are unchanged.

    The AI SDK packages move to the latest release of the major they were already on, so that @ai-sdk/provider-utils resolves at or above 4.0.33 and clears GHSA-866g-f22w-33x8 (uncontrolled resource consumption). The SDK packages pin @ai-sdk/provider-utils to an exact version, so bumping them is the only way to reach it: ai goes to 6.0.280 and @ai-sdk/anthropic, @ai-sdk/google, @ai-sdk/groq, @ai-sdk/mistral and @ai-sdk/openai follow on their 3.x line.

    The system prompt moves from a { role: "system" } entry in messages to the system option on generateText. Since ai 6.0.170 the former makes the SDK print a prompt-injection warning on every BYOK run.

    The basic translator also stops wrapping its system prompt in a serialized { role, content } envelope before handing it over, so the provider now receives the prompt text on its own rather than a line of JSON quoting it. This is the one change here that alters what reaches the model.

@lingo.dev/compiler@0.4.13

Choose a tag to compare

@github-actions github-actions released this 11 Sep 12:43
3a68459

Patch Changes

  • #2208 8dfdf49 Thanks @cherkanovart! - Clear two npm audit advisories that surfaced through transitive dependencies.

    csv-parse moves from 5.6.0 to 7.0.2, which patches GHSA-8cw4-87c7-c6xx (prototype replacement reachable through the columns option). None of the options renamed in csv-parse 6.0.0 were in use, so the CSV loaders are unchanged.

    The AI SDK packages move to the latest release of the major they were already on, so that @ai-sdk/provider-utils resolves at or above 4.0.33 and clears GHSA-866g-f22w-33x8 (uncontrolled resource consumption). The SDK packages pin @ai-sdk/provider-utils to an exact version, so bumping them is the only way to reach it: ai goes to 6.0.280 and @ai-sdk/anthropic, @ai-sdk/google, @ai-sdk/groq, @ai-sdk/mistral and @ai-sdk/openai follow on their 3.x line.

    The system prompt moves from a { role: "system" } entry in messages to the system option on generateText. Since ai 6.0.170 the former makes the SDK print a prompt-injection warning on every BYOK run.

    The basic translator also stops wrapping its system prompt in a serialized { role, content } envelope before handing it over, so the provider now receives the prompt text on its own rather than a line of JSON quoting it. This is the one change here that alters what reaches the model.

  • Updated dependencies [8dfdf49]:

    • lingo.dev@0.138.8

@lingo.dev/_compiler@0.12.14

Choose a tag to compare

@github-actions github-actions released this 11 Sep 12:43
3a68459

Patch Changes

  • #2208 8dfdf49 Thanks @cherkanovart! - Clear two npm audit advisories that surfaced through transitive dependencies.

    csv-parse moves from 5.6.0 to 7.0.2, which patches GHSA-8cw4-87c7-c6xx (prototype replacement reachable through the columns option). None of the options renamed in csv-parse 6.0.0 were in use, so the CSV loaders are unchanged.

    The AI SDK packages move to the latest release of the major they were already on, so that @ai-sdk/provider-utils resolves at or above 4.0.33 and clears GHSA-866g-f22w-33x8 (uncontrolled resource consumption). The SDK packages pin @ai-sdk/provider-utils to an exact version, so bumping them is the only way to reach it: ai goes to 6.0.280 and @ai-sdk/anthropic, @ai-sdk/google, @ai-sdk/groq, @ai-sdk/mistral and @ai-sdk/openai follow on their 3.x line.

    The system prompt moves from a { role: "system" } entry in messages to the system option on generateText. Since ai 6.0.170 the former makes the SDK print a prompt-injection warning on every BYOK run.

    The basic translator also stops wrapping its system prompt in a serialized { role, content } envelope before handing it over, so the provider now receives the prompt text on its own rather than a line of JSON quoting it. This is the one change here that alters what reaches the model.

lingo.dev@0.138.7

Choose a tag to compare

@github-actions github-actions released this 04 Sep 13:28
c43aa97

Patch Changes

  • #2204 ee3fa2e Thanks @AndreyHirsa! - Remove the unused remark-mdx-frontmatter import and dependency from the mdx loader.

lingo.dev@0.138.6

Choose a tag to compare

@github-actions github-actions released this 20 Aug 18:59
b1258a5

Patch Changes

  • #2197 9db8613 Thanks @cherkanovart! - Fix run --key, which matched nothing and could overwrite unrelated lockfile entries.

    --key filtered with a raw glob match, but flat buckets join nesting with /, so a prefix like auth/login matched no key at all and the run reported everything as cached. It now matches on exact key, on a prefix that ends at a /, or on a glob. auth/login selects auth/login/title and leaves auth/login_url and sign-in-error alone.

    A --key run also wrote checksums for every source key, not just the translated subset, which marked untouched keys as translated in i18n.lock. --key now suppresses the checksum write, as --target-locale already did, and no longer computes the discarded checksums at all.

    The help text for --key documented dot-separated paths and an auth.login example, neither of which matched real keys. It now states the / separator, that a prefix must end at one, and that a glob does not cross one.

    The --frozen failure message told the user to run lingo.dev lockfile, which does nothing once the lockfile section is populated. It now points at lingo.dev run, which localizes what is pending and updates the lockfile.