Skip to content

Release JavaScript SDK v17.4.1#997

Open
stas-schaller wants to merge 10 commits intomasterfrom
release/sdk/javascript/core/v17.4.1
Open

Release JavaScript SDK v17.4.1#997
stas-schaller wants to merge 10 commits intomasterfrom
release/sdk/javascript/core/v17.4.1

Conversation

@stas-schaller
Copy link
Copy Markdown
Contributor

@stas-schaller stas-schaller commented Apr 14, 2026

Summary

Release branch for JavaScript SDK v17.4.1 — patch release adding IL5 (DoD Impact Level 5) region support, a rollup build toolchain fix, and a security bump for rollup itself.

Changes

New Features

  • IL5 region mapping (KSM-901): adds `IL5` token prefix → `il5.keepersecurity.us` hostname, consistent with Python SDK (KSM-900) and Java SDK (KSM-902) implementations

Maintenance

  • Rollup sourcemaps (KSM-758): replaces deprecated `rollup-plugin-sourcemaps@0.6.3` with `rollup-plugin-sourcemaps2@0.5.4` — resolves peer dependency warnings with Rollup 4.x

Security

  • rollup devDependency bump: `^4.52.3` → `^4.60.1` — fixes HIGH severity arbitrary file write via path traversal affecting Rollup 4.0.0–4.58.0; build-only, not shipped in the published package

Breaking Changes

None.

Related Issues

@stas-schaller stas-schaller changed the title feat(sdk/javascript): release JavaScript SDK v17.4.1 Release JavaScript SDK v17.4.1 Apr 14, 2026
KSM-901: add IL5 region mapping (il5.keepersecurity.us)
…7-4-1

KSM-758: replace rollup-plugin-sourcemaps with rollup-plugin-sourcemaps2
@socket-security
Copy link
Copy Markdown

socket-security bot commented Apr 14, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​rollup-plugin-sourcemaps2@​0.5.4971008084100
Updatednpm/​rollup@​4.52.3 ⏵ 4.60.188100 +1610098 -1100

View full report

@stas-schaller stas-schaller marked this pull request as ready for review April 15, 2026 21:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant