release: v3.12.8 - #314
Conversation
Picks up the CLNP-8740 / SBISSUE-21844 thread collection fixes: - loadNext set isFetching.prev instead of .next, which left loadPrevious blocked for good — older replies stopped paginating once newer ones had been loaded - a stale onMessagesDeleted for an already-succeeded echo removed the message occupying the shared reqId slot - local send/resend is now scoped to the parent message, and a succeeded message is removed locally when the delete call succeeds The pinned dependency is what consumers install, so the fixes cannot reach them without this bump. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
| CVE | Package | Version | Fix |
|---|---|---|---|
| CVE-2026-33896 | node-forge |
1.3.1 |
1.4.0 |
| CVE-2026-1525 | undici |
6.22.0 |
6.24.0 |
🔶 High · 24 findings
| CVE | Package | Version | Fix |
|---|---|---|---|
| CVE-2026-41673 | @xmldom/xmldom |
0.7.13 |
0.8.13 |
| CVE-2026-1526 | undici |
6.22.0 |
6.24.0 |
| CVE-2026-34601 | @xmldom/xmldom |
0.7.13 |
0.8.12 |
| CVE-2026-41907 | uuid |
7.0.3 |
11.1.1 |
| CVE-2026-45623 | postcss |
8.4.49 |
8.5.12 |
| CVE-2026-22036 | undici |
6.22.0 |
6.23.0 |
| CVE-2025-12816 | node-forge |
1.3.1 |
1.3.2 |
| CVE-2026-12151 | undici |
6.22.0 |
6.27.0 |
| CVE-2026-41673 | @xmldom/xmldom |
0.8.11 |
0.8.13 |
| CVE-2026-33894 | node-forge |
1.3.1 |
1.4.0 |
| CVE-2026-33891 | node-forge |
1.3.1 |
1.4.0 |
| CVE-2026-2391 | qs |
6.13.0 |
6.14.2 |
| CVE-2026-41672 | @xmldom/xmldom |
0.7.13 |
0.8.13 |
| CVE-2026-1528 | undici |
6.22.0 |
6.24.0 |
| CVE-2026-33895 | node-forge |
1.3.1 |
1.4.0 |
| CVE-2026-34601 | @xmldom/xmldom |
0.8.11 |
0.8.12 |
| CVE-2026-41907 | uuid |
3.4.0 |
11.1.1 |
| CVE-2026-41672 | @xmldom/xmldom |
0.8.11 |
0.8.13 |
| CVE-2026-41674 | @xmldom/xmldom |
0.7.13 |
0.8.13 |
| CVE-2025-66031 | node-forge |
1.3.1 |
1.3.2 |
| CVE-2026-41675 | @xmldom/xmldom |
0.7.13 |
0.8.13 |
| CVE-2026-41675 | @xmldom/xmldom |
0.8.11 |
0.8.13 |
| CVE-2026-2229 | undici |
6.22.0 |
6.24.0 |
| CVE-2026-41674 | @xmldom/xmldom |
0.8.11 |
0.8.13 |
🟡 Medium · 10 findings
| CVE | Package | Version | Fix |
|---|---|---|---|
| CVE-2026-9679 | undici |
6.22.0 |
6.27.0 |
| CVE-2026-53632 | launch-editor |
2.12.0 |
2.14.1 |
| CVE-2023-0842 | xml2js |
0.4.23 |
0.5.0 |
| CVE-2026-41650 | fast-xml-parser |
4.5.6 |
5.7.0 |
| CVE-2026-8723 | qs |
6.13.0 |
6.15.2 |
| CVE-2026-1527 | undici |
6.22.0 |
6.24.0 |
| CVE-2025-66030 | node-forge |
1.3.1 |
1.3.2 |
| CVE-2026-41305 | postcss |
8.4.49 |
8.5.10 |
| CVE-2026-48038 | joi |
17.13.3 |
17.13.4 |
| CVE-2026-12590 | body-parser |
1.20.3 |
1.20.6 |
🟢 Low · 3 findings
| CVE | Package | Version | Fix |
|---|---|---|---|
| CVE-2026-6733 | undici |
6.22.0 |
6.27.0 |
| CVE-2026-11525 | undici |
6.22.0 |
6.27.0 |
| CVE-2025-15284 | qs |
6.13.0 |
6.14.1 |
View full analysis in Upwind Console
Scan completed in 17s
Scan history (2 scans)
| Commit | Scanned at | New | Resolved | Net |
|---|---|---|---|---|
8940146 |
2026-08-03 00:54 UTC | — | — | — |
8940146 < |
2026-08-03 00:54 UTC | +39 | 0 | +39 |
Last scanned: 8940146 · 2026-08-03 00:54 UTC
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #314 +/- ##
========================================
Coverage 11.34% 11.34%
========================================
Files 361 361
Lines 9105 9105
Branches 2449 2585 +136
========================================
Hits 1033 1033
+ Misses 8071 7996 -75
- Partials 1 76 +75 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
/bot create tocket |
|
/bot create ticket |
|
[Creating Ticket] Preparing https://github.com/sendbird/sendbird-uikit-react-native/actions/runs/30775721192 |
|
[Creating Ticket] In progress https://github.com/sendbird/sdk-deployment/actions/workflows/create-ticket.yml |
|
[Creating Ticket] 🔖 Creating https://sendbird.atlassian.net/browse/SDKRLSD-2234 |
Release v3.12.8
[3.12.8]
Bug Fixes
Notes for the release announcement
ModalSafeAreais newly exported from@sendbird/uikit-react-native-foundation.@sendbird/uikit-toolsmoves from0.0.15to0.1.5. It is a pinned hard dependency, so the thread fixes cannot reach apps without this bump.Verification
yarn install --frozen-lockfile,yarn lint,yarn test(34 suites / 190 tests) andyarn build(5 projects) pass on this branch.react-nativefield resolves@sendbird/uikit-toolsto its ESM build, which bundles cleanly.loadNext.Checklist
publish-packageworkflowNext Steps
/bot create ticketcomment to create a ticketpublish-packageworkflow in GitHub Actions🤖 Generated with Claude Code