Skip to content

Deploy - #17517

Open
artsyit wants to merge 7 commits into
releasefrom
staging
Open

Deploy#17517
artsyit wants to merge 7 commits into
releasefrom
staging

Conversation

@artsyit

@artsyit artsyit commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

This is an automatically generated release PR!

leamotta and others added 6 commits July 27, 2026 12:53
* feat(tracking): impression tracking for home sections

* feat(tracking): add home artwork item impression events (NWFY and artwork recs)

* feat(tracking): fire home railViewed once per page view across tab switches

Rails inside Palette Tabs remount when returning to a previously viewed
tab, which refired railViewed. Add a page-view-scoped dedupe provider on
HomeApp so each rail fires at most once per visit; navigating away and
back resets the scope and tracks again.

Assisted-by: Claude Code <noreply@anthropic.com>

* feat(tracking): dedupe home itemViewed per page view across tab switches

Assisted-by: Claude Code <noreply@anthropic.com>
The Hammer Price game (PR #17494) shipped prematurely from a hackathon
project.

This PR removes the self-contained Games app, unmounts its routes.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
)

Resolves GHSA-23hp-3jrh-7fpw (node-tar DoS via unlimited input,
critical). tar was pulled transitively only through build/install
tooling:

- node-gyp@11 → tar@7.4.3
- unleash-client@6 → make-fetch-happen@13 → cacache@18 → tar@6.2.1

Added two resolutions:
- tar@npm:^7.4.3 → 7.5.20 (patched, ≥7.5.19; 7.5.21+ still under the
  10-day npmMinimalAgeGate quarantine)
- make-fetch-happen@npm:^13.0.1 → ^14.0.3, which pulls cacache@19
  (tar 7) and drops the unpatched tar@6.2.1 line entirely

`yarn npm audit --severity critical --recursive` is now clean.

Assisted-by: Claude <noreply@anthropic.com>
)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…e; (#17521)

bump cohesion

Autosuggest already fires this event; the full-page /search results
view (ZeroState) didn't, leaving no-results searches invisible in
analytics.

Assisted-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants