apos createis now an interactive guided installer (it delegates tocreate-apostrophe). The<shortname>positional argument and the--starterand--mongodb-urioptions have been removed - project name, starter kit, and database are now chosen through prompts. For scripted installs, usenpm create apostrophe@latest -- --unattendedinstead.
- Bump and clean up dependencies. This closes vulnerabilities in
uuidandfast-xml-parseralthough they were not used in a sensitive or vulnerable way within ApostropheCMS. This also closes a vulnerability inshelljswhich ould only be exploited if the developer could be convinced to enter malicious commands as part of their CLI input. - Passwords and starter kit URLs containing intentionally malicious punctuation cannot be used to run arbitrary shell commands. Because the CLI is only used by developers, this would always have been an "own goal" situation, however this does make the CLI more robust for scripted use. Thanks to Nitro13urn for reporting the issue.
-
Adds support for hybrid ApostropheCMS + Astro projects in the
createcommand. Projects with abackend/directory are automatically detected and handled appropriately.-
Updated the default Astro starter example in the README to use
astro-public-demo. -
The
addcommand now displays an error when run inside a hybrid Astro project, as it is not currently supported in that context. -
The default starter kit is now
public-demo
-
-
Validates the
shortNameargument in thecreatecommand to only allow letters, numbers, hyphens, and underscores, preventing potential command injection.
add widget,add pieceandadd moduleare compatible with our new ESM-based starter kits. commonjs starter kits can still be used.
- Fully compatible with the new major version of Apostrophe (
4.0.0). - Slight improvements to messaging and documentation.
- Removed vestigial support for Apostrophe 2.x, which has passed its end of life date and should not be used, therefore its removal is not considered a major version change in the CLI. Of course, those who need to create new 2.x projects can fork existing projects without the use of the CLI.
- Adds the
--mongodb-uriflag to pass a MongoDB server connection string allowing for initial user addition during project creation when a host server is being used.
- Adds additional options to the
--starterflag to make use of the starter kits easier. Also adds fallbacks for obtaining templates from other repositories. - Changes the
config.jsfile to reflect the new name for the olda3-boilerplatetemplate repo,starter-kit-essentials
- Fixes apostrophe 3 paths in console output.
- Fixed typo in CLI help to clarify install options.
- Pinned
package.jsonto version1.4.0of thecolorsmodule to ensure the liberty bug does not corrupt the display. This should not be possible when installing normally with-gsince we were already shipping apackage-lock.jsonthat contains 1.4.0, however the bug did occur if a user cloned the repo and rannpm update, so in an abundance of caution we are making sure it is not possible even when doing so.
- Adds a spinner indicator during package install to avoid the impression that the process is failing.
- Updates ESLint to v7 to meet the eslint-config-apostrophe peer dependency requirement.
- The initial build of the overhauled ApostropheCMS CLI. Uses the
3.0.0major version number as this is very much an advanced version of theapostrophe-clipackage (currently at 2.x.x), but moved to a new package name for logistical reasons.