Skip to content

release: v3.12.9 - #320

Merged
OnestarLee merged 2 commits into
mainfrom
release/3.12.9
Sep 16, 2026
Merged

OnestarLee merged 2 commits into
mainfrom
release/3.12.9

Conversation

@OnestarLee

@OnestarLee OnestarLee commented Sep 14, 2026 •

Copy link
Copy Markdown
Collaborator

Release v3.12.9

[3.12.9]

Bug Fixes

  • avoid a crash when leaving a channel or list screen in apps that replace the global Promise, such as APM agents
  • resume a partially played voice message instead of restarting it, when using expo-audio
  • show the correct remaining time while playing a voice message, when using expo-audio
  • upgrade vulnerable build dependencies (js-yaml, nx)

Included changes

Commit Summary Ref
c2e27ee fix: stop relying on instanceof Promise for async effect and voice service results #315
d3e8758 fix: use seekTo and millisecond units in the expo-audio player adapter SBISSUE-22082
fc28410 fix: upgrade vulnerable build dependencies (js-yaml 3.15.1/4.3.1, Nx 22.7.7) SECURE-4411, SECURE-4450
5e3ce6c fix: upgrade js-yaml to patched 3.15.2 / 4.3.2 SECURE-4677

Note: CHANGELOG_DRAFT.md on main still held the already-released v3.12.8 entries — the v3.12.9 draft written in d3e8758 was reverted by 0574cc7. This PR restores it.

Checklist

  • CHANGELOG_DRAFT.md is complete
  • All tests pass (yarn test: 36 suites / 205 tests, yarn lint: clean)
  • Ready for publish-package workflow

Next Steps

  1. Add /bot create ticket comment to create a ticket
  2. Run the publish-package workflow in GitHub Actions

🤖 Generated with Claude Code

@upwind-code-us

upwind-code-us Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Upwind Upwind Code Scan - ⚠️ Warn

87 newly introduced vulnerabilities · 0 resolved · 87 total in this PR vs main

Total breakdown: 🔴 6 Critical | 🔶 48 High | 🟡 27 Medium | 🟢 6 Low


🔴 Critical · 6 findings
CVE Package Version Fix
CVE-2026-1525 undici 6.22.0 6.24.0
CVE-2026-54906 concurrent-ruby 1.3.3 1.3.7
CVE-2026-45363 jwt 2.10.2 2.10.3
CVE-2026-45623 postcss 8.4.49 8.5.12
CVE-2026-33210 json 2.16.0 2.17.1.2
CVE-2026-33896 node-forge 1.3.1 1.4.0

🔶 High · 48 findings
CVE Package Version Fix
CVE-2026-83616 @xmldom/xmldom 0.8.11 0.8.15
CVE-2026-41675 @xmldom/xmldom 0.8.11 0.8.13
CVE-2026-54297 faraday 1.10.4 1.10.6
CVE-2026-35611 addressable 2.8.7 2.9.0
CVE-2026-41907 uuid 7.0.3 11.1.1
CVE-2026-83619 @xmldom/xmldom 0.8.11 0.8.15
CVE-2026-83605 @xmldom/xmldom 0.7.13 0.8.14
CVE-2026-2229 undici 6.22.0 6.24.0
CVE-2026-83605 @xmldom/xmldom 0.8.11 0.8.14
CVE-2026-33176 activesupport 7.2.3 7.2.3.1
CVE-2026-41672 @xmldom/xmldom 0.8.11 0.8.13
CVE-2025-66031 node-forge 1.3.1 1.3.2
CVE-2026-22036 undici 6.22.0 6.23.0
CVE-2026-83607 @xmldom/xmldom 0.8.11 0.8.14
CVE-2026-83616 @xmldom/xmldom 0.7.13 0.8.15
CVE-2026-33894 node-forge 1.3.1 1.4.0
CVE-2026-54904 concurrent-ruby 1.3.3 1.3.7
CVE-2026-1528 undici 6.22.0 6.24.0
CVE-2026-33891 node-forge 1.3.1 1.4.0
CVE-2026-34601 @xmldom/xmldom 0.8.11 0.8.12
CVE-2026-83615 @xmldom/xmldom 0.8.11 0.8.15
CVE-2026-1526 undici 6.22.0 6.24.0
CVE-2026-41907 uuid 3.4.0 11.1.1
CVE-2026-83607 @xmldom/xmldom 0.7.13 0.8.14
CVE-2026-73646 postcss 8.4.49 8.5.18
CVE-2026-83613 @xmldom/xmldom 0.7.13 0.8.15
CVE-2026-41675 @xmldom/xmldom 0.7.13 0.8.13
CVE-2026-67214 nanoid 3.3.11 3.3.16
CVE-2026-41673 @xmldom/xmldom 0.7.13 0.8.13
CVE-2026-83614 @xmldom/xmldom 0.7.13 0.8.15
CVE-2026-67213 nanoid 3.3.11 3.3.18
CVE-2026-2391 qs 6.13.0 6.14.2
CVE-2026-41674 @xmldom/xmldom 0.8.11 0.8.13
CVE-2026-73231 @faker-js/faker 7.6.0 10.5.0
CVE-2026-12151 undici 6.22.0 6.27.0
CVE-2026-83608 @xmldom/xmldom 0.7.13 0.8.15
CVE-2026-33895 node-forge 1.3.1 1.4.0
CVE-2026-41674 @xmldom/xmldom 0.7.13 0.8.13
CVE-2026-73086 nanoid 3.3.11 3.3.12
CVE-2026-41673 @xmldom/xmldom 0.8.11 0.8.13
CVE-2026-83614 @xmldom/xmldom 0.8.11 0.8.15
CVE-2026-83608 @xmldom/xmldom 0.8.11 0.8.15
CVE-2025-12816 node-forge 1.3.1 1.3.2
CVE-2026-83615 @xmldom/xmldom 0.7.13 0.8.15
CVE-2026-41672 @xmldom/xmldom 0.7.13 0.8.13
CVE-2026-34601 @xmldom/xmldom 0.7.13 0.8.12
CVE-2026-83613 @xmldom/xmldom 0.8.11 0.8.15
CVE-2026-83619 @xmldom/xmldom 0.7.13 0.8.15

🟡 Medium · 27 findings
CVE Package Version Fix
CVE-2026-48038 joi 17.13.3 17.13.4
CVE-2023-0842 xml2js 0.4.23 0.5.0
CVE-2026-8723 qs 6.13.0 6.15.2
CVE-2025-66030 node-forge 1.3.1 1.3.2
CVE-2026-82417 qs 6.13.0 6.16.0
CVE-2026-45822 decode-uri-component 0.2.2 0.5.0
CVE-2026-41305 postcss 8.4.49 8.5.10
CVE-2026-16728 undici 6.22.0 6.28.0
CVE-2026-9679 undici 6.22.0 6.27.0
CVE-2026-41650 fast-xml-parser 4.5.6 5.7.0
CVE-2026-33170 activesupport 7.2.3 7.2.3.1
CVE-2026-1527 undici 6.22.0 6.24.0
CVE-2026-83610 @xmldom/xmldom 0.7.13 0.8.15
CVE-2026-54905 concurrent-ruby 1.3.3 1.3.7
CVE-2025-14762 aws-sdk-s3 1.203.1 1.208.0
CVE-2026-33169 activesupport 7.2.3 7.2.3.1
CVE-2026-15157 undici 6.22.0 6.28.0
CVE-2026-54171 excon 0.112.0 1.5.0
CVE-2026-83610 @xmldom/xmldom 0.8.11 0.8.15
CVE-2026-47751 anthropics/claude-code-action v1 1.0.74
CVE-2026-25765 faraday 1.10.4 1.10.5
CVE-2026-83611 @xmldom/xmldom 0.8.11 0.8.15
CVE-2026-53632 launch-editor 2.12.0 2.14.1
CVE-2026-69153 postcss 8.4.49 8.5.23
CVE-2026-12590 body-parser 1.20.3 1.20.6
CVE-2026-16729 undici 6.22.0 6.28.0
CVE-2026-83611 @xmldom/xmldom 0.7.13 0.8.15

🟢 Low · 6 findings
CVE Package Version Fix
CVE-2026-84367 joi 17.13.3 17.13.5
CVE-2026-11525 undici 6.22.0 6.27.0
CVE-2026-6733 undici 6.22.0 6.27.0
CVE-2026-84368 joi 17.13.3 17.13.6
CVE-2026-54696 json 2.16.0 2.19.9
CVE-2025-15284 qs 6.13.0 6.14.1

View full analysis in Upwind Console

Scan completed in 7s

Scan history (2 scans)
Commit Scanned at New Resolved Net
f1bdb7d 2026-09-14 10:42 UTC +87 0 +87
38e067d < 2026-09-15 02:35 UTC +87 0 +87

Last scanned: 38e067d · 2026-09-15 02:35 UTC

@upwind-code-us

upwind-code-us Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Upwind Upwind IaC Scan - ✅ Passed

0 newly introduced misconfigurations · 0 resolved · 0 total in this PR vs main

View full analysis in Upwind Console →

Scan completed in 4s

Scan history (2 scans)
Commit Scanned at New Resolved Net
f1bdb7d 2026-09-14 10:42 UTC 0 0 0
38e067d < 2026-09-15 02:35 UTC 0 0 0

Last scanned: 38e067d · 2026-09-15 02:35 UTC

@codecov-commenter

codecov-commenter commented Sep 14, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 12.31%. Comparing base (3f9a9ae) to head (b0bb4e4).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #320   +/-   ##
=======================================
  Coverage   12.31%   12.31%           
=======================================
  Files         361      361           
  Lines        9108     9108           
  Branches     2563     2563           
=======================================
  Hits         1122     1122           
  Misses       7985     7985           
  Partials        1        1           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@OnestarLee

Copy link
Copy Markdown
Collaborator Author

/bot create ticket

@sendbird-sdk-deployment

Copy link
Copy Markdown
Collaborator

@sendbird-sdk-deployment

Copy link
Copy Markdown
Collaborator

@sendbird-sdk-deployment

Copy link
Copy Markdown
Collaborator

[Creating Ticket] 🔖 Creating https://sendbird.atlassian.net/browse/SDKRLSD-2276

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

approved by automation

@OnestarLee
OnestarLee added this pull request to the merge queue Sep 16, 2026
Merged via the queue into main with commit 3d26ccf Sep 16, 2026
9 checks passed
@OnestarLee
OnestarLee deleted the release/3.12.9 branch September 16, 2026 01:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants