Repository navigation
Port missing 2.1 features + security dep bumps to master (#474, #480) - #522
Merged
navneetkumar-pim-webkul merged 3 commits intoJun 26, 2026
Merged
Conversation
…ges from 2.1 (#474) Backport of 2.1 PR #474 onto master: - Help & Resources admin page: sidebar menu, ACL entry, reusable card component - Promo banner (cloud-hosting + upgrade-available) with per-admin dismissal (new admin_promo_dismissals table + model/proxy/contract/repository) - Installer optional-packages selector + cloud-hosting banner - Translations for all 33 locales Drops the unrelated dead-file/upgrade-script deletions bundled in the original PR; keeps master docs and VERSION. Admin + installer assets rebuilt. (cherry picked from 9177845 on origin/2.1)
* fix: make promo banner sticky to remove empty gap on scroll Promo banner used position:relative, so it scrolled out of view while the layout already offsets the header by 3rem (its height). When the banner scrolled away the sticky header stayed pinned at top:48px, leaving a 48px empty gap above it. Make the banner sticky (top-0, z above header) so it stays pinned and the header sits flush below it. * fix: drop promo bar z-index to avoid modal overlay collision Addresses review feedback: z-[10002] tied modal overlays (confirm/history/ bulk-edit all use z-[10002]) and, being rendered later in the DOM, painted above them — leaving the banner visible/clickable over an open modal. The banner only needs to stay above scrolling page content (which it does via position:sticky alone, as a positioned element) and below modal overlays. Removing the explicit z-index achieves both. Also avoids relying on a new arbitrary Tailwind value (z-[10000]) that the committed build CSS does not contain (CI does not rebuild assets). * fix: give promo bar z-[9999] to sit above transform-stacked charts Dashboard chart SVGs use CSS transform, so each creates its own stacking context. With the banner at z-index:auto, those contexts painted at the same level and (being later in the DOM) bled over the sticky banner on scroll — e.g. completeness donut charts appeared inside the banner. A positive z-index is required to beat transform stacking contexts. z-[9999] sits above all page content (<=1000) while staying below the header/modal/drawer overlays (10001/10002), so modals and drawers still cover the banner correctly. z-[9999] already exists in the committed build CSS (CI does not rebuild assets), so no asset rebuild is needed. (cherry picked from commit e6e35fb)
Sync dependency versions toward 2.1 and resolve outstanding composer audit advisories: - phpseclib/phpseclib 3.0.52 -> 3.0.55 - guzzlehttp/psr7 2.10.2 -> 2.12.3 - laravel/framework 12.61.0 -> 12.62.0 - phpoffice/phpspreadsheet 1.30.4 -> 1.30.5 (CVE-2026-45034, parity with 2.1 #487) - mtdowling/jmespath.php 2.8.0 -> 2.9.1 (CVE-2026-54133) composer audit now reports no advisories. Only composer.lock changed; composer.json constraints untouched.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Backports the features present in 2.1 but missing from master, and closes outstanding dependency CVEs. All 2.1 security fixes were already in master (via #497 + individual twins) — this PR fills the remaining feature gap and clears
composer audit.Commits
b513a795admin_promo_dismissalstable + model/proxy/contract/repository) + installer optional-packages selector + cloud-hosting banner + translations for all 33 locales2784385bz-[9999]fix (no scroll gap, sits below modal/drawer overlays) + rebuilt CSS086b91b9Dependency bumps (
086b91b9)3.0.52 → 3.0.552.10.2 → 2.12.312.61.0 → 12.62.01.30.4 → 1.30.5— CVE-2026-45034 (parity with 2.1 Chore(deps): Bump phpoffice/phpspreadsheet from 1.30.4 to 1.30.5 #487)2.8.0 → 2.9.1— CVE-2026-54133composer audit→ no advisories. Onlycomposer.lockchanged;composer.jsonconstraints untouched.Scope notes
upgrade_*.shdeletions — dropped here. Master docs andCore::VERSIONpreserved.Verification
unopim:translations:check— 100% / all 33 locales$confidentialnamed param mismatch — not introduced here)composer audit: no advisories · Laravel 12.62.0 boots · Core unit suite 48 pass