| Metadata | Value |
|---|---|
| Status | Completed |
| Version | 1.2.0 |
| Last Updated | 2026-07-09 |
| Author | Sangeetha Grantha Team |
Batch 1 — Security patch + low-risk drop-in dependency upgrades (June 2026). These are patch/minor bumps with no expected API breakage. Verify compile/build/test across all three layers before committing.
42.7.10 → 42.7.11 — fixes CVE-2026-42198 (SCRAM PBKDF2 iteration DoS). Drop-in.gradle/libs.versions.toml)3.4.0 → 3.5.0 (minor — digest auth, session cookies)4.1.1 → 4.2.1 (minor — Ktor 3.4 DI bridge)12.8.1 → 12.9.0 (minor — also sync compose.yaml image tag)1.5.32 → 1.5.34 (patch)modules/frontend/sangita-admin-web/package.json)19.2.4 → 19.2.7 / 19.2.6 (patch)5.90.21 → 5.101.1 (minor)4.2.1 → 4.3.1 (minor)7.13.1 → latest 7.x (stay on 7 line)4.0.18 → 4.1.9 (minor — adds Vite 8 support)1.40.0 → 1.61.0 (21 minors behind — run full E2E suite after)tools/krithi-extract-enrich-worker/pyproject.toml + uv.lock)2.12.5 → 2.13.4 (minor)3.3.2 → 3.3.4 (patch)1.27.1 → 1.27.2.3 (patch)gradle/libs.versions.toml; sync Flyway tag in compose.yaml. Run ./gradlew :modules:backend:api:build + make test.package.json; bun install; bun run build + bun run test; run Playwright E2E suite.pyproject.toml; uv lock; run worker pytest.current-versions.md, tech-stack.md, getting-started.md (per CLAUDE.md Critical Rule 5).Ref: line + this track).1.0.0 and MockK 1.14.9 are already current — no action.All bumps landed as commit 7bf3443 (2026-06-24) and are on origin/main. Verified: gradle/libs.versions.toml shows Ktor 3.5.0 / Koin 4.2.1 / Flyway 12.9.0 / Logback 1.5.34 / PostgreSQL JDBC 42.7.11; package.json shows React 19.2.7 / TanStack Query 5.101.1 / Tailwind 4.3.1 / React Router 7.18.0 / Playwright 1.61.x. Version docs (current-versions.md) synced in the same change, including the Python worker bumps (pydantic 2.13.4, psycopg 3.3.4, PyMuPDF 1.27.2.3). Note: Vitest subsequently moved to 4.1.10 via TRACK-121.