Skip to content

Document allowed version values in fern.config.json - #7233

Open
devin-ai-integration[bot] wants to merge 1 commit into
mainfrom
devin/1790960968-fern-config-version-values
Open

devin-ai-integration[bot] wants to merge 1 commit into
mainfrom
devin/1790960968-fern-config-version-values

Conversation

@devin-ai-integration

Copy link
Copy Markdown
Contributor

Summary

The Fern CLI now accepts only an exact semver version, "latest", or "*" for version in fern.config.json. It used to accept any string. This change matters for security, because the CLI installs and runs whatever version that field names. Customers who pin the CLI version can now see which values are valid, so a v-prefixed version or a range like ^5.40.0 won't surprise them with a validation error.

Implements docs for: fix(cli): reject non-semver versions in fern.config.json (fern-api/fern#17945)

Pages changed

  • fern/products/docs/pages/getting-started/project-structure.mdx and fern/products/sdks/project-structure.mdx (both have the same fern.config.json section): added one paragraph covering:
    • accepted values: exact semver (prereleases allowed), "latest", "*"
    • rejected forms: v prefix, ranges, dist-tags, surrounding whitespace, and file:/npm:/git/URL specs
  • fern/products/cli-api-reference/pages/general-commands.mdx: one sentence each under fern upgrade --version and fern downgrade. Both commands now check the version the same way before they write fern.config.json (isValidProjectConfigVersion).

fern check --warnings reports 0 errors. The only Vale error is at sdks/project-structure.mdx:51 ("that is"). It's in an unchanged line and was already there.

Link to Devin session: https://app.devin.ai/sessions/76bd1188a1734b9fac32e42fd2efeec8
Open in Devin Desktop: https://app.devin.ai/desktop/session/76bd1188a1734b9fac32e42fd2efeec8?variant=devin

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants