Development - #335
Conversation
feat: add asset scanning support in import
…Each Assets loaded from --data-dir backup may not have a publish_details field if they were never published. The optional chain only guarded `asset`, not `publish_details`, causing a TypeError in displayAssetsDetails().
…sets.js setConfig() assigned to `config` at module scope but the variable was never declared, causing a ReferenceError on any cm:assets:publish run that goes through the data-dir flow.
…portCommand for asset publishing
…nd update related logic
fix: Update flags in AssetsPublishCommand and add user reminder in ImportCommand for asset publishing
publish() flattened each asset's publish_details into independent environments[] and locales[] arrays, so the CMA republished the cartesian product. For a ragged publish state (different locales on different environments) this over-published to env-locale pairs that never existed on the source stack. Add buildPublishGroups: group publish_details by environment, coalesce environments with an identical locale set, and emit one publish call per group so each call is a single rectangle the CMA reproduces exactly. A rectangular asset still collapses to one call (unchanged behavior). The DX-1656 invalid-environment guard is preserved (envs absent from the destination are still skipped). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Bumps [adm-zip](https://github.com/cthackers/adm-zip) from 0.5.18 to 0.6.0. - [Release notes](https://github.com/cthackers/adm-zip/releases) - [Changelog](https://github.com/cthackers/adm-zip/blob/master/history.md) - [Commits](cthackers/adm-zip@v0.5.18...v0.6.0) --- updated-dependencies: - dependency-name: adm-zip dependency-version: 0.6.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
back merge
git-diff@2.0.7 is unmaintained (last published 2018) and pulls in chalk@2, diff@3, loglevel, shelljs and shelljs.exec. Snyk flagged the only vulnerable path in the monorepo through that tree: Missing Release of Resource after Effective Lifetime [Medium] SNYK-JS-INFLIGHT-6095116 git-diff@2.0.7 > shelljs@0.8.5 > glob@7.2.3 > inflight@1.0.6 Snyk reports no direct upgrade or patch, since git-diff is abandoned. Replace it with diff@^9 (jsdiff): zero runtime dependencies, bundled TypeScript types, dual CJS/ESM. It also removes the dependency on a `git` binary and the temp-file/subprocess round trip git-diff used to shell out through shelljs. buildDiffString now calls createTwoFilesPatch, which emits the `---` and `+++` file headers itself, so the hand-rolled header concatenation is gone. Output was verified equivalent: both patch strings were run through Diff2html.parse and compared on file names, added/deleted line counts, hunk headers and every line type plus content - identical. Identical inputs are also handled better. git-diff returned undefined when both sides matched, which interpolated the literal string "undefined" into the patch; createTwoFilesPatch returns a well-formed patch with no hunks. Drop @types/git-diff, since diff ships its own types. Tests: the existing spec mocked diff2html, so the generated patch was never asserted. Add two cases covering the string handed to Diff2html.parse - one for headers, hunk and changed lines, one for the identical-input case. Both were mutation-checked against a corrupted buildDiffString. Suite: 78 passed, 16 suites, tsc clean, Snyk reports no vulnerable paths across the monorepo. Bump the pinned pnpm-lock.yaml checksum in .talismanrc, which the lockfile change invalidates. The finding is the usual sha512 integrity hashes, not a secret. Note: this commit also carries a pre-existing, uncommitted version bump to 1.5.4 that was already present in package.json. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
added audit check and fix for assets in pending or quarantined state
handled assets in pending or quarantine states export failure
There was a problem hiding this comment.
Pull request overview
This PR updates multiple CLI plugins to better support Contentstack “asset scanning” workflows by (a) propagating asset scan status through export/audit, (b) preventing unsafe downloads/publishes while scans are pending/quarantined, and (c) adding a post-import publish flow that can run after scanning completes.
Changes:
- Export now requests and stores
_asset_scan_status, skips downloading assets in configured blocking statuses, and reports what was skipped. - Import now performs deferred plan checks, can auto-skip asset publish when
assetsScanis enabled, and preserves env↔locale pairing in asset publish payloads. - Bulk publish adds scan-status gating (with retry handling) and a
--backup-dirmode to publish imported assets to their original env/locale targets.
Reviewed changes
Copilot reviewed 42 out of 44 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
| pnpm-workspace.yaml | Bumps pnpm overrides for several transitive deps. |
| packages/contentstack-query-export/package.json | Formatting-only adjustment. |
| packages/contentstack-import/test/unit/import/modules/assets.test.ts | Updates/adds tests for new asset publish grouping behavior. |
| packages/contentstack-import/src/utils/import-config-handler.ts | Adds deferred plan checks and scanning-driven import flags. |
| packages/contentstack-import/src/types/import-config.ts | Adds planStatus and assetScanningEnabled to config typing. |
| packages/contentstack-import/src/import/modules/assets.ts | Preserves env↔locale pairing and adds scanning/publish messaging. |
| packages/contentstack-import/src/commands/cm/stacks/import.ts | Passes command context into config setup; adds end-of-run reminder. |
| packages/contentstack-import/package.json | Declares plan-protected feature assetsScan. |
| packages/contentstack-external-migrate/tsconfig.tsbuildinfo | Adds a TS build info artifact file. |
| packages/contentstack-export/test/unit/export/modules/stack.test.ts | Updates test config to include blocking scan statuses. |
| packages/contentstack-export/test/unit/export/modules/base-class.test.ts | Updates test config to include blocking scan statuses. |
| packages/contentstack-export/test/unit/export/modules/assets.test.ts | Adds tests validating scan-status download skipping behavior. |
| packages/contentstack-export/src/utils/export-config-handler.ts | Adds deferred plan checks and exports planStatus into config. |
| packages/contentstack-export/src/types/export-config.ts | Adds planStatus typing. |
| packages/contentstack-export/src/types/default-config.ts | Adds blockingScanStatuses typing under assets config. |
| packages/contentstack-export/src/export/modules/base-class.ts | Adds rejection logging and guards resolve/reject callbacks. |
| packages/contentstack-export/src/export/modules/assets.ts | Requests scan status and skips downloads for blocking statuses. |
| packages/contentstack-export/src/config/index.ts | Adds default blockingScanStatuses. |
| packages/contentstack-export/src/commands/cm/stacks/export.ts | Passes command context into config setup. |
| packages/contentstack-export/package.json | Declares plan-protected feature assetsScan. |
| packages/contentstack-export/messages/index.json | Adds messages for scan-status skip logs/summaries. |
| packages/contentstack-content-type/tests/core/content-type/compare.test.ts | Adds tests for unified patch formatting passed to diff2html. |
| packages/contentstack-content-type/src/core/content-type/compare.ts | Switches diff generation from git-diff to diff. |
| packages/contentstack-content-type/skills/contentstack-cli-content-type/SKILL.md | Updates docs to reflect diff library change. |
| packages/contentstack-content-type/skills/code-review/SKILL.md | Updates dependency-audit list (git-diff → diff). |
| packages/contentstack-content-type/package.json | Bumps version; adds diff and adjusts typings deps. |
| packages/contentstack-bulk-publish/test/unit/util/asset-scan.test.js | Adds unit tests for asset scan retry/status helpers. |
| packages/contentstack-bulk-publish/src/util/asset-scan.js | Introduces scan status helpers and retry/backoff logic. |
| packages/contentstack-bulk-publish/src/producer/publish-assets.js | Adds scan gating, pending retry processing, and --backup-dir publish mode. |
| packages/contentstack-bulk-publish/src/consumer/publish.js | Makes publish_details iteration null-safe. |
| packages/contentstack-bulk-publish/src/commands/cm/assets/publish.js | Adds --backup-dir flag and validation changes. |
| packages/contentstack-bulk-publish/.mocharc.json | Adds new util test file to Mocha run list. |
| packages/contentstack-audit/test/unit/modules/entries.test.ts | Adds tests for asset metadata indexing and entry file-field validation/fix. |
| packages/contentstack-audit/test/unit/modules/assets.test.ts | Adds tests for scan-status validation/fix in assets module. |
| packages/contentstack-audit/test/unit/mock/contents/assets/chunk1-assets.json | Adds mock asset scan status fixtures. |
| packages/contentstack-audit/test/unit/mock/contents/assets/assets.json | Adds mock assets index fixture. |
| packages/contentstack-audit/src/types/content-types.ts | Adds output columns for scan_status and mandatory. |
| packages/contentstack-audit/src/modules/entries.ts | Adds asset metadata indexing and file-field scan-status validation/fix. |
| packages/contentstack-audit/src/modules/assets.ts | Adds scan-status blocking/fix behavior for assets audit. |
| packages/contentstack-audit/src/messages/index.ts | Adds messages for scan-status-related warnings/fixes. |
| packages/contentstack-audit/src/config/index.ts | Adds blocking scan statuses and new report module keys. |
| packages/contentstack-audit/src/audit-base-command.ts | Adds new report modules to display/report gating. |
| .talismanrc | Updates pnpm-lock checksum entry formatting/values. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
…ull-guard fix(bulk-publish): add null guard on asset.publish_details before forEach
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |
…-zip-0.6.0 chore(deps): bump adm-zip from 0.5.18 to 0.6.0
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |
bumped versions
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |
…o updated-lock-file
…ns into updated-lock-file
updated lock file
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |
No description provided.