Skip to content

chore(main): release 27.12.0 - #8575

Merged
sarahetter merged 1 commit into
mainfrom
release-please--branches--main--components--netlify-cli
Oct 8, 2026
Merged

sarahetter merged 1 commit into
mainfrom
release-please--branches--main--components--netlify-cli

Conversation

@token-generator-app

@token-generator-app token-generator-app Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

🤖 I have created a release beep boop

27.12.0 (2026-10-08)

Features

  • init: install Netlify agent skills by default (#8555) (f3d7e82)
  • init: sync installed skills with the manifest (#8556) (332666c)

Bug Fixes

  • deps: batch low-risk dependency updates (#8585) (edd9f44)
  • deps: update content-type to v3 and read the header string directly (#8572) (969145c)
  • dev: use URL separators for static file paths (#8593) (626224b)
  • init: report skill sync outcomes accurately on the first run (#8580) (0f2b082)

This PR was generated with Release Please. See documentation.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 3d592a04-a5ea-456e-8023-4daffe6e908c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/netlify-cli@8575

commit: b75c3a3

@token-generator-app token-generator-app Bot changed the title chore(main): release 27.11.3 chore(main): release 27.12.0 Oct 6, 2026
@token-generator-app
token-generator-app Bot force-pushed the release-please--branches--main--components--netlify-cli branch 3 times, most recently from 4f6779d to af3be42 Compare October 7, 2026 16:14
@token-generator-app
token-generator-app Bot force-pushed the release-please--branches--main--components--netlify-cli branch 2 times, most recently from bd5b1fe to 728b9f8 Compare October 8, 2026 16:23
domitriusclark added a commit that referenced this pull request Oct 8, 2026
## Problem

`netlify dev` returns 403 on Windows for static files that need a
redirect
shadow check, such as paths with spaces or brackets. `getStatic` builds
the
URL forwarded to the static server with `path.relative`, which yields
backslashes on Windows, so the static server receives
`/files%5Cfile%20with%20spaces.html`.

This has been latent since 2020. `@fastify/static` 10.1.4
(GHSA-r799-r9gc-m956)
added a path spelling guard that splits on `/`, stats the joined path,
finds
the file under a different spelling, and rejects it. Earlier versions
served
the file.

Surfaced by the Windows integration shard on #8575, which fails
`should not shadow an existing file that has unsafe URL characters` on
every
attempt. The previous five release PRs passed it.

## Approach

Split the relative path on `path.sep` and join with `/`, so the URL
always
uses forward slashes. Only OS separators are rewritten; a literal
backslash in
a POSIX filename is preserved.

## Tests

- `npm run typecheck`, `npx eslint src/utils/proxy.ts`, `npm run build`:
clean
- `npm exec vitest -- run tests/integration/commands/dev/dev.test.ts`
with
  `@fastify/static` 10.1.5 installed: 27 passed

Verified on macOS only, where `path.relative` already returns forward
slashes,
so this run cannot reproduce the bug. PRs do not run Windows integration
tests. The proof is the Windows shard on the regenerated release PR
after
this merges.

## Risk

Low. One-line change on the path the proxy already controls. No behavior
change on POSIX, where `path.sep` is already `/`.

## Rollback

Revert this commit.
@token-generator-app
token-generator-app Bot force-pushed the release-please--branches--main--components--netlify-cli branch from 728b9f8 to b75c3a3 Compare October 8, 2026 17:21
@sarahetter
sarahetter enabled auto-merge (squash) October 8, 2026 18:23
@sarahetter
sarahetter merged commit e137887 into main Oct 8, 2026
64 of 66 checks passed
@sarahetter
sarahetter deleted the release-please--branches--main--components--netlify-cli branch October 8, 2026 18:34
@token-generator-app

Copy link
Copy Markdown
Contributor Author

🤖 Created releases:

🌻

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant