Repository navigation
DX | 29-09-2026 | Release - #399
Conversation
embedded_metadata and ai_generated_metadata are not supported on dev11 CDA — API returns HTTP 422. Restrict assetFields() calls to the two supported values (user_defined_fields, visual_markups) in asset.spec.ts, asset-query.spec.ts, entries.spec.ts, and entry.spec.ts. Generated by Claude Code
fix: remove unsupported asset_fields params from CDA API tests
Fix back merge
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
🔒 Security Scan Results
⏱️ SLA Breach Summary
ℹ️ Vulnerabilities Without Available Fixes (Informational Only)The following vulnerabilities were detected but do not have fixes available (no upgrade or patch). These are excluded from failure thresholds:
✅ BUILD PASSED - All security checks passed |
Coverage report
Test suite run success720 tests passing in 36 suites. Report generated by 🧪jest coverage report action from 3984a7e |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Documented asset-field options lose their only live CDA coverage across four API paths.
Review effort: Balanced
Findings: 4
Open (4)
What changed in this PR
Updates release dependencies and narrows API tests for asset-field parameters.
Changes:
- Upgrades Axios and Playwright.
- Refreshes transitive dependency locks.
- Removes two documented asset-field values from API tests.
| File | Description |
|---|---|
test/api/entry.spec.ts |
Narrows entry asset-field coverage. |
test/api/entries.spec.ts |
Narrows entries asset-field coverage. |
test/api/asset.spec.ts |
Narrows asset fetch coverage. |
test/api/asset-query.spec.ts |
Narrows asset query coverage. |
package.json |
Upgrades Axios and Playwright. |
package-lock.json |
Locks updated dependency graph. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Publish on release:published from release.yml so the npm trusted publisher can be keyed on the filename, drop NODE_AUTH_TOKEN in favour of id-token: write (OIDC), run on Node 24 with npm@latest (trusted publishing needs npm >= 11.5.1), check out the release tag without persisted credentials. GitHub pre-releases go to the beta dist-tag. The GitHub Packages job gains the packages: write permission it was missing and publishes with the job's own token instead of a personal token. package.json gains the repository field that provenance validation requires. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
chore(release): publish to npm with trusted publishing
🔒 Security Scan Results
⏱️ SLA Breach Summary
ℹ️ Vulnerabilities Without Available Fixes (Informational Only)The following vulnerabilities were detected but do not have fixes available (no upgrade or patch). These are excluded from failure thresholds:
✅ BUILD PASSED - All security checks passed |


No description provided.