Skip to content

chore(deps): bump @objectstack/formula from 17.0.0-rc.6 to 17.0.0 - #4955

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/objectstack/formula-17.0.0
Aug 17, 2026
Merged

chore(deps): bump @objectstack/formula from 17.0.0-rc.6 to 17.0.0#4955
github-actions[bot] merged 1 commit into
mainfrom
dependabot/npm_and_yarn/objectstack/formula-17.0.0

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 17, 2026

Copy link
Copy Markdown
Contributor

Bumps @objectstack/formula from 17.0.0-rc.6 to 17.0.0.

Release notes

Sourced from @​objectstack/formula's releases.

@​objectstack/formula@​17.0.0

Minor Changes

  • f6cd635: fix(formula): the CEL pushdown compiler parses through the canonical front end, so DEFAULT_LIMITS finally apply to RLS/sharing predicates (#6132)

    cel-to-filter.ts — the ONE canonical CEL → FilterCondition pushdown compiler (ADR-0058 D1/D2/D6), consumed by the RLS path (plugin-security's RLSCompiler), the sharing seeder (plugin-sharing), and the analytics SQL backend — kept a private, limitless parse environment of its own:

    newEnvironment({unlistedVariablesAreDyn: true,enableOptionalTypes: true});

    no limits, no stdlib, no rewriteNullableTernary. That made the pushdown path the one place on the platform that answered a different question from celEngine.compile() about what parses. Measured: a 300-term addition, a 60-level parenthesis nest and a 200-element list literal all parsed there while the interpreter refused each one outright (Exceeded maxAstNodes (256) / maxDepth (32) / maxListElements (64)). Escalated: an 80-term conjunction, a 40-level nest and a 200-element $in all reached real pushdown SQL, silently — and isSupportedRlsExpression, the ADR-0056 D4 authoring gate, was a thin wrapper over the same limitless environment, so it was no independent check either.

    It now parses through parseCelToAstWithReason#4812's canonical entry, with DEFAULT_LIMITS, the stdlib and the #3306 null-guard rewrite. "What parses" has one answer again.

    Within the limits nothing moves, and that is measured, not asserted. Across the 710 sources of the pushdown corpus that both front ends accept, the only AST difference is rewriteNullableTernary's dyn(…) wrap on the three null-guard ternaries — and a ternary faults on its own ?: node before the lowerer descends into a branch, so verdict and detail come out byte-identical. Pinned in cel-to-filter-parse-convergence.test.ts, which rebuilds the old environment to compare against.

    Over the limits, behaviour changes — in two dated steps.

    • Now, during 17.0.0-rc.x (rc-grace): an over-limit predicate still compiles — nothing that enforces today stops enforcing on this upgrade — and emits one WARN per predicate naming the bound that was exceeded (maxAstNodes / maxDepth / maxListElements / …), the platform's value for it, and what the predicate itself measures (cel-js's own accounting: the smallest bound it parses under), plus what will happen at GA.
    • At v17.0.0 GA (fail-closed): the same predicate is refused{ ok: false, reason: 'parse-error', detail: 'Exceeded maxAstNodes (256)' } — and the RLS path turns that into RLS_DENY_FILTER, i.e. zero rows, fail closed. A sharing rule with such a condition is not seeded.

... (truncated)

Changelog

Sourced from @​objectstack/formula's changelog.

17.0.0

Minor Changes

  • f6cd635: fix(formula): the CEL pushdown compiler parses through the canonical front end, so DEFAULT_LIMITS finally apply to RLS/sharing predicates (#6132)

    cel-to-filter.ts — the ONE canonical CEL → FilterCondition pushdown compiler (ADR-0058 D1/D2/D6), consumed by the RLS path (plugin-security's RLSCompiler), the sharing seeder (plugin-sharing), and the analytics SQL backend — kept a private, limitless parse environment of its own:

    newEnvironment({unlistedVariablesAreDyn: true,enableOptionalTypes: true});

    no limits, no stdlib, no rewriteNullableTernary. That made the pushdown path the one place on the platform that answered a different question from celEngine.compile() about what parses. Measured: a 300-term addition, a 60-level parenthesis nest and a 200-element list literal all parsed there while the interpreter refused each one outright (Exceeded maxAstNodes (256) / maxDepth (32) / maxListElements (64)). Escalated: an 80-term conjunction, a 40-level nest and a 200-element $in all reached real pushdown SQL, silently — and isSupportedRlsExpression, the ADR-0056 D4 authoring gate, was a thin wrapper over the same limitless environment, so it was no independent check either.

    It now parses through parseCelToAstWithReason#4812's canonical entry, with DEFAULT_LIMITS, the stdlib and the #3306 null-guard rewrite. "What parses" has one answer again.

    Within the limits nothing moves, and that is measured, not asserted. Across the 710 sources of the pushdown corpus that both front ends accept, the only AST difference is rewriteNullableTernary's dyn(…) wrap on the three null-guard ternaries — and a ternary faults on its own ?: node before the lowerer descends into a branch, so verdict and detail come out byte-identical. Pinned in cel-to-filter-parse-convergence.test.ts, which rebuilds the old environment to compare against.

    Over the limits, behaviour changes — in two dated steps.

    • Now, during 17.0.0-rc.x (rc-grace): an over-limit predicate still compiles — nothing that enforces today stops enforcing on this upgrade — and emits one WARN per predicate naming the bound that was exceeded (maxAstNodes / maxDepth / maxListElements / …), the platform's value for it, and what the predicate itself measures (cel-js's own accounting: the smallest bound it parses under), plus what will happen at GA.
    • At v17.0.0 GA (fail-closed): the same predicate is refused{ ok: false, reason: 'parse-error', detail: 'Exceeded maxAstNodes (256)' } — and the RLS path turns that into RLS_DENY_FILTER, i.e. zero rows, fail closed. A sharing rule with such a condition is not seeded.

... (truncated)

Commits
  • 24c1b91 chore: version packages (#6208)
  • 078e28b fix(formula): cover a Date-valued binding in the temporal-equality rewrite (#...
  • d063a96 fix(spec): stop folding like/ilike onto $contains at the wire (#7536) (#7593)
  • See full diff in compare view

@dependabotdependabotBot added automated Opened or maintained by automation (Dependabot, release bot) dependencies labels Aug 17, 2026
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/objectstack/formula-17.0.0 branch from 23f3576 to 1c905ceCompareAugust 17, 2026 08:08
@github-actions
github-actionsBot added this pull request to the merge queueAug 17, 2026
@github-merge-queue
github-merge-queueBot removed this pull request from the merge queue due to a conflict with the base branch Aug 17, 2026
Bumps [@objectstack/formula](https://github.com/objectstack-ai/objectstack/tree/HEAD/packages/formula) from 17.0.0-rc.6 to 17.0.0.
- [Release notes](https://github.com/objectstack-ai/objectstack/releases)
- [Changelog](https://github.com/objectstack-ai/objectstack/blob/main/packages/formula/CHANGELOG.md)
- [Commits](https://github.com/objectstack-ai/objectstack/commits/@objectstack/formula@17.0.0/packages/formula)
---
updated-dependencies:
- dependency-name: "@objectstack/formula"
dependency-version: 17.0.0
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/objectstack/formula-17.0.0 branch from 1c905ce to f2b68b7CompareAugust 17, 2026 08:12
@github-actions
github-actionsBot added this pull request to the merge queueAug 17, 2026
Merged via the queue into main with commit 080fa91Aug 17, 2026
19 of 20 checks passed
@dependabot
dependabotBot deleted the dependabot/npm_and_yarn/objectstack/formula-17.0.0 branch August 17, 2026 08:12
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)24.7 KB350 KB
Entry fileindex-Blnxv6I6.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)9.56KB3.59KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)8.92KB3.41KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)25.13KB5.40KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.13KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.64KB2.21KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.79KB
auth (createAuthenticatedFetch.js)6.34KB2.43KB
auth (index.js)2.71KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.88KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)26.07KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.65KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)498.79KB111.24KB
core (index.js)4.06KB1.61KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)157.40KB43.42KB
fields (index.js)233.27KB58.22KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.35KB1.38KB
i18n (pickLocalized.js)3.69KB1.73KB
i18n (provider.js)23.12KB7.62KB
i18n (useDisplayLocale.js)2.84KB1.45KB
i18n (useObjectLabel.js)27.59KB6.63KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)39.16KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.35KB3.31KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.42KB1.42KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.81KB0.83KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.75KB18.37KB
plugin-chatbot (index.js)181.21KB43.14KB
plugin-dashboard (index.js)127.85KB32.73KB
plugin-designer (index.js)212.39KB42.83KB
plugin-detail (index.js)239.90KB60.01KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)120.42KB29.03KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)197.58KB53.00KB
plugin-kanban (index.js)52.72KB14.54KB
plugin-list (index.js)111.23KB26.97KB
plugin-map (index.js)17.91KB5.72KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)41.97KB11.33KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)83.81KB20.49KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)27.53KB9.41KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.28KB0.68KB
react (schema-input.js)1.45KB0.83KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)4.55KB2.07KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.05KB1.52KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automatedOpened or maintained by automation (Dependabot, release bot)dependenciespackage: core

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants