Skip to content

develop into master for new release - #672

Merged
ajolipa merged 22 commits into
masterfrom
develop
Aug 27, 2026
Merged

develop into master for new release#672
ajolipa merged 22 commits into
masterfrom
develop

Conversation

@ajolipa

@ajolipa ajolipa commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

In this PR

Release candidate. Includes the following PRs:

See PR #649 for notes on some environment variable tweaks that are needed to go along with updating the main domain to be on Performant Studio. I believe each of these features has been tested individually but we may want to do a bit of tire-kicking on staging to make sure things are playing nicely together? I'm also not sure if there's anything to be considered about updating the domain in other apps that reference it, or whether the app.coredata.cloud domain will still work fine for now.

camdendotlol and others added 22 commits July 24, 2026 14:30
* WIP

* project audit log

* table updates

* cleanup

* modal

* UX improvements

* exclude outline class from Tailwind due to Semantic UI conflict

* fix styling inconsistency

* update label

* update gem
…ents

Bump connector and triple-eye-effable (#647)
* add primary domain redirect middleware

* more info in example env
Allow paginated and whitespace-tokenized keyword search queries in relational dropdowns (#644)
…-token

Bump core-data-connector to v0.2.3
* feedback WIP

* fix edit button condition

* update CDC
* move gems over

* copy files

* config
Remove unwanted fields from AtoM identifier modal
…-record-names

Autofocusing on record name dropdown in related record modals
* WIP published toggle

* publish button

* default published state for projects

* testing SSH key fix again lol

* restrict public endpoints to published records

* Typesense and UI tweaks

* fix unpublished records appearing in relationship fields
…nship-import

Fix `result` field on merged relationship data to avoid import bug
@ajolipa
ajolipa requested review from blms and camdendotlol August 26, 2026 19:47
@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm gl-matrix is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: client/yarn.locknpm/@performant-software/geospatial@3.1.29npm/gl-matrix@3.4.4

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/gl-matrix@3.4.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm robust-predicates is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: client/yarn.locknpm/@performant-software/geospatial@3.1.29npm/robust-predicates@3.0.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/robust-predicates@3.0.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@blms blms left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agree some smoke testing is a good idea!

@camdendotlol camdendotlol left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tomorrow morning would be good for a production release. There are some manual steps involved for the domain change but it shouldn't be too substantial.

The app will still be served on app.coredata.cloud with middleware that redirects all requests to the new domain while preserving the path. So e.g. the FairData Sites sites that pull data from the public endpoints will still work.

@ajolipa
ajolipa merged commit 788bdfe into master Aug 27, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants