Milestone 0: import zappier billing, Verae middleware, and Zapier research

Compose-ready workspace: packages/zappier (rate card, portal, Stripe),
packages/verae-zapier-middleware (timestamp + NATS), packages/verae-zapier
(CLI app), vendor/zapier-platform, and research/zapier vendor corpus.

Gate 0 structure checks pass. Product code and research are not yet wired.
This commit is contained in:
George Lambert 2026-09-09 02:37:36 -04:00
commit b4150c8250
1364 changed files with 6814366 additions and 0 deletions

View file

@ -0,0 +1,167 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# Platform News in 2025
<Card title="What's changed in v18.0.6" icon="newspaper" href="/integrations/news/2025/v18.0.6" horizontal>
Package manager detection from `zapier build`
*Released: 2025-12-24*
</Card>
<Card title="What's changed in v18.0.5" icon="newspaper" href="/integrations/news/2025/v18.0.5" horizontal>
A security fix on the CLI.
*Released: 2025-12-10*
</Card>
<Card title="Incident: Unauthorized Access to Zapier NPM Packages" icon="newspaper" href="/integrations/news/2025/npm-package-sec-inc" horizontal>
Please review the enclosed list of packages and recommendations for Zapier developers.
*Released: 2025-11-24*
</Card>
<Card title="What's changed in v18.0.1" icon="newspaper" href="/integrations/news/2025/v18.0.1" horizontal>
Bug fixes for npx resolution and TypeScript typing for line items.
*Released: 2025-11-05*
</Card>
<Card title="What's changed in v18.0.0" icon="newspaper" href="/integrations/news/2025/v18.0.0" horizontal>
Node.js 22 support, new throttling middleware, and a new CLI executable name `zapier-platform`.
*Released: 2025-10-30*
</Card>
<Card title="What's changed in v17.9.1" icon="newspaper" href="/integrations/news/2025/v17.9.1" horizontal>
Bug fix for zapier push and dependency updates.
*Released: 2025-10-28*
</Card>
<Card title="Self-serve static IP for private integrations" icon="newspaper" href="/integrations/news/2025/static-ip-self-serve" horizontal>
Developers can now enable static IP addresses for private integrations directly in Platform UI without contacting support.
*Released: 2025-10-21*
</Card>
<Card title="Labeled Versions now available in CLI and Platform UI" icon="newspaper" href="/integrations/news/2025/labeled-versions" horizontal>
Integration version numbers can now include a label, to enable you to develop and test changes without committing to a [semantic version number](/integrations/manage/versions#version-numbering) until you're ready.
*Released: 2025-10-21*
</Card>
<Card title="What's changed in v17.9.0" icon="newspaper" href="/integrations/news/2025/v17.9.0" horizontal>
Bugfix for snapshot flag, improvements for `zapier env`.
*Released: 2025-10-20*
</Card>
<Card title="What's changed in v17.8.0" icon="newspaper" href="/integrations/news/2025/v17.8.0" horizontal>
Added flexibility for Search Pagination and cleaning up some dependencies. Zapier push now supports snapshot publishing.
*Released: 2025-10-07*
</Card>
<Card title="Migration UI now supports individual and organization-level migrations" icon="newspaper" href="/integrations/news/2025/organization-user-migration-in-ui" horizontal>
Enhanced migration UI with granular control options for individual and organization-level migrations.
*Released: 2025-10-02*
</Card>
<Card title="What's changed in v17.7.2" icon="newspaper" href="/integrations/news/2025/v17.7.2" horizontal>
Fixed issues with typing and semver restriction.
*Released: 2025-09-17*
</Card>
<Card title="What's changed in v17.7.1" icon="newspaper" href="/integrations/news/2025/v17.7.1" horizontal>
Improved `zapier scaffold`, `zapier init`, `zapier validate`, and `zapier invoke auth`. Also fixed issues with uncensored sensitive information and field grouping schema.
*Released: 2025-09-10*
</Card>
<Card title="No more manual handling of 4xx errors in refreshAccessToken" icon="lightbulb-on" href="/integrations/news/2025/4xx-errors-refreshAccessToken" horizontal>
We now automatically handle 4xx error responses when refreshing OAuth2 access tokens.
*Effective: 2025-09-08*
</Card>
<Card title="What's changed in v17.7.0" icon="newspaper" href="/integrations/news/2025/v17.7.0" horizontal>
This update lays groundwork for Search Pagination, which will allow Search steps to paginate through results so that the most relevant results can be returned. However, this is not yet supported by any Zapier products.
*Released: 2025-08-22*
</Card>
<Card title="What's changed in v17.6.0" icon="newspaper" href="/integrations/news/2025/v17.6.0" horizontal>
Global `console` object and account filtering for `zapier canary`.
*Released: 2025-08-11*
</Card>
<Card title="What's changed in v17.5.0" icon="newspaper" href="/integrations/news/2025/v17.5.0" horizontal>
Global `errors`, bug fixes with `zapier build` and auth field types.
*Released: 2025-07-30*
</Card>
<Card title="What's changed in v17.4.0" icon="newspaper" href="/integrations/news/2025/v17.4.0" horizontal>
Regression bug fixes with `zapier build`, support for compression of large input bundles.
*Released: 2025-07-23*
</Card>
<Card title="What's changed in v17.3.1" icon="newspaper" href="/integrations/news/2025/v17.3.1" horizontal>
Regression bug fixes with `zapier build`.
*Released: 2025-07-17*
</Card>
<Card title="What's changed in v17.3.0" icon="newspaper" href="/integrations/news/2025/v17.3.0" horizontal>
Revamped `zapier build` and input field grouping.
*Released: 2025-07-01*
</Card>
<Card title="What's changed in v17.2.0" icon="newspaper" href="/integrations/news/2025/v17.2.0" horizontal>
Improved large bundle handling.
*Released: 2025-06-11*
</Card>
<Card title="What's changed in v17.1.0" icon="newspaper" href="/integrations/news/2025/v17.1.0" horizontal>
Improved `zapier convert` and `zapier deprecate`.
*Released: 2025-06-10*
</Card>
<Card title="What's changed in v17.0.4" icon="newspaper" href="/integrations/news/2025/v17.0.4" horizontal>
Fixed a bug in `zapier build`.
*Released: 2025-06-03*
</Card>
<Card title="What's changed in v17.0.3" icon="newspaper" href="/integrations/news/2025/v17.0.3" horizontal>
Bug fixes on `zapier build`, `{{curlies}}` replacement, and more.
*Released: 2025-05-30*
</Card>
<Card title="What's changed in v17.0.2" icon="newspaper" href="/integrations/news/2025/v17.0.2" horizontal>
Windows and ESM bugs.
*Released: 2025-05-19*
</Card>
<Card title="What's changed in v17.0.1" icon="newspaper" href="/integrations/news/2025/v17.0.1" horizontal>
Fixed a regression bug on `zapier build` and the oauth2 template in `zapier init`.
*Released: 2025-05-14*
</Card>
<Card title="What's changed in v17.0.0" icon="newspaper" href="/integrations/news/2025/v17.0.0" horizontal>
ES module support, more complete typing, no more `{{curlies}}` in shorthand requests.
*Released: 2025-05-12*
</Card>

View file

@ -0,0 +1,86 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# No more manual handling of 4xx errors in refreshAccessToken
> We now automatically handle 4xx error responses when refreshing OAuth2 access tokens.
*Effective: 2025-09-08*
We made a change to how we handle error responses when refreshing OAuth2 access tokens.
## Old behavior
When an app gives an error response (status code 4xx or 5xx) while refreshing the OAuth2 access token, Zapier keeps retrying the Zap step indefinitely or until it hits a certain limit, depending on the user's settings.
## New behavior
When an app encounter a 4xx error response (except for the ones listed below) while refreshing the access token, Zapier will mark the connect as stale, and send an email telling the user to reconnect.
Exceptions: The following 4xx errors often indicate a temporary issue so they still have the same behavior as before:
* 408 (Request Timeout)
* 409 (Conflict)
* 423 (Locked)
* 425 (Too Early)
* 429 (Too Many Requests)
This is how Zapier handles a stale connection:
* If the stale connection is used by a trigger step, the trigger polling system will skip polling when the scheduled time comes.
* If the stale connection is used by an action step, the Zap run will be put on hold until the user reconnects and replays the run.
## What does it mean to you?
You don't need to handle 4xx error responses in `refreshAccessToken` anymore. For example, you might have been catching 4xx errors in `refreshAccessToken` by enabling `skipThrowForStatus` and throwing `ExpiredAuthError`:
```js theme={null}
const refreshAccessToken = async (z, bundle) => {
const response = await z.request({
url: "https://example.com/token/refresh",
method: "POST",
body: {
refresh_token: bundle.authData.refresh_token,
client_id: process.env.CLIENT_ID,
client_secret: process.env.CLIENT_SECRET,
grant_type: "refresh_token",
},
headers: {
"Content-Type": "application/x-www-form-urlencoded",
},
skipThrowForStatus: true,
});
if (response.status >= 400 && response.status < 500) {
throw new z.errors.ExpiredAuthError(
"Authentication issue. Please reconnect.",
);
}
return response.data;
};
```
This is no longer necessary. Now you can simplify your code as follows and let the platform handle it:
```js theme={null}
const refreshAccessToken = async (z, bundle) => {
const response = await z.request({
url: "https://example.com/token/refresh",
method: "POST",
body: {
refresh_token: bundle.authData.refresh_token,
client_id: process.env.CLIENT_ID,
client_secret: process.env.CLIENT_SECRET,
grant_type: "refresh_token",
},
headers: {
"Content-Type": "application/x-www-form-urlencoded",
},
});
return response.data;
};
```
No need to upgrade zapier-platform-core; this change is implemented in the Zapier backend.

View file

@ -0,0 +1,167 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# Platform News in 2025
<Card title="What's changed in v18.0.6" icon="newspaper" href="/integrations/news/2025/v18.0.6" horizontal>
Package manager detection from `zapier build`
*Released: 2025-12-24*
</Card>
<Card title="What's changed in v18.0.5" icon="newspaper" href="/integrations/news/2025/v18.0.5" horizontal>
A security fix on the CLI.
*Released: 2025-12-10*
</Card>
<Card title="Incident: Unauthorized Access to Zapier NPM Packages" icon="newspaper" href="/integrations/news/2025/npm-package-sec-inc" horizontal>
Please review the enclosed list of packages and recommendations for Zapier developers.
*Released: 2025-11-24*
</Card>
<Card title="What's changed in v18.0.1" icon="newspaper" href="/integrations/news/2025/v18.0.1" horizontal>
Bug fixes for npx resolution and TypeScript typing for line items.
*Released: 2025-11-05*
</Card>
<Card title="What's changed in v18.0.0" icon="newspaper" href="/integrations/news/2025/v18.0.0" horizontal>
Node.js 22 support, new throttling middleware, and a new CLI executable name `zapier-platform`.
*Released: 2025-10-30*
</Card>
<Card title="What's changed in v17.9.1" icon="newspaper" href="/integrations/news/2025/v17.9.1" horizontal>
Bug fix for zapier push and dependency updates.
*Released: 2025-10-28*
</Card>
<Card title="Self-serve static IP for private integrations" icon="newspaper" href="/integrations/news/2025/static-ip-self-serve" horizontal>
Developers can now enable static IP addresses for private integrations directly in Platform UI without contacting support.
*Released: 2025-10-21*
</Card>
<Card title="Labeled Versions now available in CLI and Platform UI" icon="newspaper" href="/integrations/news/2025/labeled-versions" horizontal>
Integration version numbers can now include a label, to enable you to develop and test changes without committing to a [semantic version number](/integrations/manage/versions#version-numbering) until you're ready.
*Released: 2025-10-21*
</Card>
<Card title="What's changed in v17.9.0" icon="newspaper" href="/integrations/news/2025/v17.9.0" horizontal>
Bugfix for snapshot flag, improvements for `zapier env`.
*Released: 2025-10-20*
</Card>
<Card title="What's changed in v17.8.0" icon="newspaper" href="/integrations/news/2025/v17.8.0" horizontal>
Added flexibility for Search Pagination and cleaning up some dependencies. Zapier push now supports snapshot publishing.
*Released: 2025-10-07*
</Card>
<Card title="Migration UI now supports individual and organization-level migrations" icon="newspaper" href="/integrations/news/2025/organization-user-migration-in-ui" horizontal>
Enhanced migration UI with granular control options for individual and organization-level migrations.
*Released: 2025-10-02*
</Card>
<Card title="What's changed in v17.7.2" icon="newspaper" href="/integrations/news/2025/v17.7.2" horizontal>
Fixed issues with typing and semver restriction.
*Released: 2025-09-17*
</Card>
<Card title="What's changed in v17.7.1" icon="newspaper" href="/integrations/news/2025/v17.7.1" horizontal>
Improved `zapier scaffold`, `zapier init`, `zapier validate`, and `zapier invoke auth`. Also fixed issues with uncensored sensitive information and field grouping schema.
*Released: 2025-09-10*
</Card>
<Card title="No more manual handling of 4xx errors in refreshAccessToken" icon="lightbulb-on" href="/integrations/news/2025/4xx-errors-refreshAccessToken" horizontal>
We now automatically handle 4xx error responses when refreshing OAuth2 access tokens.
*Effective: 2025-09-08*
</Card>
<Card title="What's changed in v17.7.0" icon="newspaper" href="/integrations/news/2025/v17.7.0" horizontal>
This update lays groundwork for Search Pagination, which will allow Search steps to paginate through results so that the most relevant results can be returned. However, this is not yet supported by any Zapier products.
*Released: 2025-08-22*
</Card>
<Card title="What's changed in v17.6.0" icon="newspaper" href="/integrations/news/2025/v17.6.0" horizontal>
Global `console` object and account filtering for `zapier canary`.
*Released: 2025-08-11*
</Card>
<Card title="What's changed in v17.5.0" icon="newspaper" href="/integrations/news/2025/v17.5.0" horizontal>
Global `errors`, bug fixes with `zapier build` and auth field types.
*Released: 2025-07-30*
</Card>
<Card title="What's changed in v17.4.0" icon="newspaper" href="/integrations/news/2025/v17.4.0" horizontal>
Regression bug fixes with `zapier build`, support for compression of large input bundles.
*Released: 2025-07-23*
</Card>
<Card title="What's changed in v17.3.1" icon="newspaper" href="/integrations/news/2025/v17.3.1" horizontal>
Regression bug fixes with `zapier build`.
*Released: 2025-07-17*
</Card>
<Card title="What's changed in v17.3.0" icon="newspaper" href="/integrations/news/2025/v17.3.0" horizontal>
Revamped `zapier build` and input field grouping.
*Released: 2025-07-01*
</Card>
<Card title="What's changed in v17.2.0" icon="newspaper" href="/integrations/news/2025/v17.2.0" horizontal>
Improved large bundle handling.
*Released: 2025-06-11*
</Card>
<Card title="What's changed in v17.1.0" icon="newspaper" href="/integrations/news/2025/v17.1.0" horizontal>
Improved `zapier convert` and `zapier deprecate`.
*Released: 2025-06-10*
</Card>
<Card title="What's changed in v17.0.4" icon="newspaper" href="/integrations/news/2025/v17.0.4" horizontal>
Fixed a bug in `zapier build`.
*Released: 2025-06-03*
</Card>
<Card title="What's changed in v17.0.3" icon="newspaper" href="/integrations/news/2025/v17.0.3" horizontal>
Bug fixes on `zapier build`, `{{curlies}}` replacement, and more.
*Released: 2025-05-30*
</Card>
<Card title="What's changed in v17.0.2" icon="newspaper" href="/integrations/news/2025/v17.0.2" horizontal>
Windows and ESM bugs.
*Released: 2025-05-19*
</Card>
<Card title="What's changed in v17.0.1" icon="newspaper" href="/integrations/news/2025/v17.0.1" horizontal>
Fixed a regression bug on `zapier build` and the oauth2 template in `zapier init`.
*Released: 2025-05-14*
</Card>
<Card title="What's changed in v17.0.0" icon="newspaper" href="/integrations/news/2025/v17.0.0" horizontal>
ES module support, more complete typing, no more `{{curlies}}` in shorthand requests.
*Released: 2025-05-12*
</Card>

View file

@ -0,0 +1,15 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# Labeled Versions now available in CLI and Platform UI
> Integration version numbers can now include a label, to enable you to develop and test changes without committing to a [semantic version number](/integrations/manage/versions#version-numbering) until you're ready.
*Released: 2025-10-21*
## Labeled Versions
* 🎉 [Labeled Versions](https://docs.zapier.com/integrations/manage/labeled-versions) are now publicly available!
* Versions like `2.0.0-beta` can be used for testing and avoiding version collisions during parallel development
* More flexible "snapshot" versions like `0.0.0-my-feature` can be used to push integration updates without committing to a semantic version number

View file

@ -0,0 +1,17 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# Incident: Unauthorized Access to Zapier NPM Packages
> Please review the enclosed list of packages and recommendations for Zapier developers.
*Released: 2025-11-24*
## Unauthorized Access to Zapier npm Packages
**Note: No action is needed from Zapier users**, only from Zapier developers using one of the NPM package versions listed [on this page](/integrations/build-cli/inc-547). See that link for detailed mitigation recommendations.
All Zapier products are operating as expected and there is no indication of data loss or leak.
Please [see this link](https://status.zapier.com/incidents/01KAV9DDHMYT7R6MFHSB8C09E3#updates) for the most up-to-date information.

View file

@ -0,0 +1,15 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# Migration UI now supports individual and organization-level migrations
> Enhanced migration UI with granular control options for individual and organization-level migrations.
*Released: 2025-10-02*
## Migration via the Platform UI
* 🎉 [Email-based migration](https://docs.zapier.com/integrations/manage/migrate#migrate-users-to-new-version-with-platform-ui) now supports two scopes:
* **Individual**: Migrates only private Zap workflows under the user's individual account (equivalent to the `--user` flag of the `zapier migrate` CLI command)
* **Organization**: Migrates all Zap workflows including shared resources across organization accounts (equivalent to the `--account` flag of the `zapier migrate` CLI command)

View file

@ -0,0 +1,15 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# Self-serve static IP for private integrations
> Developers can now enable static IP addresses for private integrations directly in Platform UI without contacting support.
*Released: 2025-10-21*
## Self-serve static IP for private integrations
* 🎉 [Static IP](https://docs.zapier.com/integrations/build/static-ip) can now be enabled by team members for private integrations:
* **Platform UI toggle**: Navigate to the Settings tab on the Advanced page to enable static IP addresses for your private integration without contacting support.
* **Published integrations**: Continue to contact Zapier Support to enable static IP for published integrations.

View file

@ -0,0 +1,124 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.0.0
> ES module support, more complete typing, no more `{{curlies}}` in shorthand requests.
*Released: 2025-05-12*
Version 17.0.0 is a **BREAKING CHANGE** release that contains several important upgrades and changes. Here is a brief breakdown of the main breaking changes (**❗ denotes a breaking change**):
## ES Module Support
You can now build integrations using modern ES Module syntax. This means you can use `import ... from ...` instead of `require(...)`, and use newer npm packages that support only ESM.
To start using ESM for your integration project:
* Set `"type": "module"` in your `package.json`
* Replace `main` with `exports` in your `package.json`
For a complete example, check out [minimal-esm](https://github.com/zapier/zapier-platform/tree/82b11aef29a4e7cb576431dba24cba0066c5057b/example-apps/minimal-esm) or [typescript-esm](https://github.com/zapier/zapier-platform/tree/82b11aef29a4e7cb576431dba24cba0066c5057b/example-apps/typescript-esm) (both can be initialized using [`zapier init`](https://github.com/zapier/zapier-platform/blob/82b11aef29a4e7cb576431dba24cba0066c5057b/packages/cli/docs/cli.md#init) with the `-m esm` flag).
Additionally, this update means it's no longer required for every integration's entry point to be `index.js` at the root directory. Instead, the entry point can be defined in `package.json`.
* For example, see the Typescript ESM example integration [at this link](https://github.com/zapier/zapier-platform/tree/main/example-apps/typescript-esm) - it no longer contains an `index.js` file at the root directory, rather the entry point is defined via `"exports": "./dist/index.js"` in the integration's [package.json](https://github.com/zapier/zapier-platform/blob/main/example-apps/typescript-esm/package.json#L20)
## Typing Improvements
We've improved the typing system, making the TypeScript dev experience more enjoyable. The new typing system includes:
* Bundle `inputData` types is now inferred from input fields.
* New helper functions to help with typing:
* `defineApp`, `defineTrigger`, `defineCreate`, `defineSearch`, `defineInputFields`
* These are now recommended over the equivalent `satisfies Xyz` statements
* `satisfies` is still used for `perform` functions, with `InferInputData`, and for other features without `define` helpers. For example, `export default { ... } satisfies Authentication` is still expected.
Check out the [typescript-esm](https://github.com/zapier/zapier-platform/tree/82b11aef29a4e7cb576431dba24cba0066c5057b/example-apps/typescript-esm) example project for a full example.
## ❗ No More `{{curly brackets}}` Outside of Shorthand Requests
Calling `z.request()` with `{{bundle.*}}` or `{{process.env.*}}` will now result in an error. For example:
```js theme={null}
const perform = async (z, bundle) => {
const response = await z.request({
url: "https://{{bundle.authData.subdomain}}.example.com",
});
return response.data;
};
```
This will result in an error in v17. Instead, you must use [template literals](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Template_literals) i.e. `${var}`:
```js theme={null}
const perform = async (z, bundle) => {
const response = await z.request({
url: `https://${bundle.authData.subdomain}.example.com`,
});
return response.data;
};
```
However, `{{curly backets}}` are still (and have to be) allowed in other places, including `operation.lock.key`. They are also allowed (actually required) in usage of shorthand requests:
```js theme={null}
{
operation: {
perform: {
url: 'https://{{bundle.authData.subdomain}}.example.com',
method: 'GET',
}
}
}
```
### ❗ Schema Changes
We have split authentication fields, input fields, and output fields into their own respective schemas, to allow for stricter schema checks and to prepare for future platform updates. Along with this, we have removed irrelevant or incompatible field types and properties from certain schemas.
Note that a descriptive error will be thrown on `zapier validate` if your integration attempts to use an unsupported type or property to prompt you to change it; no need to manually check these. The updated schema are as follows:
* `AuthenticationSchema.fields`:
* The following **types** are no longer supported: `code`, `file`, `integer`, `text`
* The following **properties** are no longer supported: `altersDynamicFields`, `dynamic`, `meta`, `primary`, `search`, `steadyState`
* `BasicActionOperationSchema.inputFields`:
* All **types** remain the same.
* The following **properties** are no longer supported: `primary`, `steadyState`
* `BasicActionOperationSchema.outputFields`:
* The following **types** are no longer supported: `text`, `copy`, `code`
* The following **properties** are no longer supported: `altersDynamicFields`, `choices`, `computed`, `dynamic`, `helpText`, `inputFormat`, `meta`, `placeholder`, `search`
***
Apart from these major changes, here are the detailed release notes for this release (**note that ❗ denotes a breaking change**):
## cli
* 🎉 ESM support added to `zapier init` command via the `--module` flag - supports Minimal and Typescript templates ([#976](https://github.com/zapier/zapier-platform/pull/976))
* 🔨 `zapier build` now uses `esbuild` instead of `browserify` to detect dependencies, for a faster experience building, and to better support ESM ([#946](https://github.com/zapier/zapier-platform/pull/946))
* 🔨 Update `gulp-prettier` dependency from 4.0.0 to 5.0.0
## core
* ❗ Stop replacing `{{curlies}}` unless it's a shorthand request ([#1001](https://github.com/zapier/zapier-platform/pull/1001))
* 🎉 ESM Support: Two versions of `zapierwrapper.js`, one CJS and one ESM, loaded dynamically depending on the app type ([#965](https://github.com/zapier/zapier-platform/pull/965))
* 🐛 Not every `{{curlies}}` in the request object need to be recursively replaced ([#1001](https://github.com/zapier/zapier-platform/pull/1001))
* 🐛 HTTP 500 along with status codes >500 are caught in RPC client ([#974](https://github.com/zapier/zapier-platform/pull/974))
* 🔨 Remove Bluebird library, replace with native promises ([#980](https://github.com/zapier/zapier-platform/pull/980))
* 🔨 Refactor middleware and lambda handler logic to use async/await instead of Promise chaining ([#980](https://github.com/zapier/zapier-platform/pull/980))
* 🔨 Trim newline and whitespaces from request headers ([#1000](https://github.com/zapier/zapier-platform/pull/1000))
## schema
* ❗ Remove deprecated shouldLock property in the schema ([#988](https://github.com/zapier/zapier-platform/pull/988))
* 🔨 FieldSchema has been split into separate schemas and renamed for clarity ([#957](https://github.com/zapier/zapier-platform/pull/957), [#998](https://github.com/zapier/zapier-platform/pull/998)). Changes include:
* Input Fields (`PlainInputFieldSchema` and `InputFieldsSchema`)
* Output Fields (`PlainOutputFieldSchema` and `OutputFieldsSchema`)
* Authentication Fields (`AuthFieldSchema` and `AuthFieldsSchema`)
* 🔨 A dedicated `BasicSearchOperationSchema` has been added ([#998](https://github.com/zapier/zapier-platform/pull/998))
## misc
* 🔨 Dependency updates - full list in the PR ([#1010](https://github.com/zapier/zapier-platform/pull/1010))

View file

@ -0,0 +1,22 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.0.1
> Fixed a regression bug on `zapier build` and the oauth2 template in `zapier init`.
*Released: 2025-05-14*
## cli
* 🐛 `zapier init` Typescript template OAuth2 implementation doesn't work out of the box ([#1022](https://github.com/zapier/zapier-platform/pull/1022))
* 🐛 `version-store.js` is updated to show the Node and NPM versions for v17 ([#1020](https://github.com/zapier/zapier-platform/pull/1020))
## core
* 🐛 `zapier build` (and therefore also `zapier push`) hangs on the `Building app definition.json` step when it's run on an integration with a Core dependency of v17, and run via CLI with a version less than v17 ([#1020](https://github.com/zapier/zapier-platform/pull/1020))
## schema
None!

View file

@ -0,0 +1,22 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.0.2
> Windows and ESM bugs.
*Released: 2025-05-19*
## cli
* 🐛 Fix crashing issues on Windows ([#1024](https://github.com/zapier/zapier-platform/pull/1024))
* 💅 Default to ESM for `zapier init` if template supports it ([#1026](https://github.com/zapier/zapier-platform/pull/1026))
## core
* 🐛 ESM apps can't import `define` helpers from `zapier-platform-core` ([#1018](https://github.com/zapier/zapier-platform/pull/1018))
## schema
None!

View file

@ -0,0 +1,28 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.0.3
> Bug fixes on `zapier build`, `{{curlies}}` replacement, and more.
*Released: 2025-05-30*
## cli
* 🐛 Fix "Cannot find base config file" tsconfig warning on `zapier build` ([#1033](https://github.com/zapier/zapier-platform/pull/1033))
## core
* 🐛 Fix various bugs with `{{curlies}}` replacement ([#1032](https://github.com/zapier/zapier-platform/pull/1032))
* 🐛 Remove request body fields with undefined `{{curlies}}` when the content-type is `application/x-www-form-urlencoded` ([#1044](https://github.com/zapier/zapier-platform/pull/1044))
* 🐛 `{{curlies}}` in `requestTemplate` aren't properly replaced ([#1034](https://github.com/zapier/zapier-platform/pull/1034))
* 🐛 Fix unexpected line breaks in logged response content ([#1042](https://github.com/zapier/zapier-platform/pull/1042))
## schema
None!
## misc
* 📜 Update example apps: [oauth2](https://github.com/zapier/zapier-platform/tree/8fcadb7d8eaa10d4eb99b84ec8df70a0bb9b8e16/example-apps/oauth2), [typescript](https://github.com/zapier/zapier-platform/tree/8fcadb7d8eaa10d4eb99b84ec8df70a0bb9b8e16/example-apps/typescript), [typescript-esm](https://github.com/zapier/zapier-platform/tree/8fcadb7d8eaa10d4eb99b84ec8df70a0bb9b8e16/example-apps/typescript-esm) ([#1036](https://github.com/zapier/zapier-platform/pull/1036))

View file

@ -0,0 +1,21 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.0.4
> Fixed a bug in `zapier build`.
*Released: 2025-06-03*
## cli
* 🐛 Fix "Cannot find module..." error after running `zapier build` on a CJS integration using hybrid packages([#1046](https://github.com/zapier/zapier-platform/pull/1046))
## core
None!
## schema
None!

View file

@ -0,0 +1,22 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.1.0
> Improved `zapier convert` and `zapier deprecate`.
*Released: 2025-06-10*
## cli
* 🎉 `zapier convert` now accepts an app definition via the `--json` flag ([#1048](https://github.com/zapier/zapier-platform/pull/1048))
* 💅 `zapier deprecate` now prompts for deprecation reason ([#1045](https://github.com/zapier/zapier-platform/pull/1045))
## core
None!
## schema
None!

View file

@ -0,0 +1,21 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.2.0
> Improved large bundle handling.
*Released: 2025-06-11*
## cli
None!
## core
* 🎉 Add before middleware to fetch stashed bundles for improved large payload handling ([#1050](https://github.com/zapier/zapier-platform/pull/1050))
## schema
None!

View file

@ -0,0 +1,39 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.3.0
> Revamped `zapier build` and input field grouping.
*Released: 2025-07-01*
This release introduces two major improvements: `zapier build` and input field grouping.
The `zapier build` command has been revamped to:
* Better support npm/yarn/pnpm workspaces
* Run faster when the `--skip-npm-install` flag is enabled
* Test the build.zip file to verify all load-time dependencies are included (not applicable on Windows)
Input Field Grouping:
* Grouping support, intended for visual purpose in products, has been added to the input fields.
## cli
* 💅 `zapier build` supports npm/yarn/pnpm workspaces and runs faster ([#1052](https://github.com/zapier/zapier-platform/pull/1052))
* 🐛 Fix a bug where `zapier build` can select the wrong entry point of a dependency ([#1052](https://github.com/zapier/zapier-platform/pull/1052) - [c004298](https://github.com/zapier/zapier-platform/pull/1052/commits/c004298a1b61b7de777f3c8222949c7d38d8826f))
* 📜 Update docs for new days before deprecation and sending emails ([#1056](https://github.com/zapier/zapier-platform/pull/1056))
## core
* 🐛 Fix a bug where Fetch logger crashes when response doesn't have content-type ([#1062](https://github.com/zapier/zapier-platform/pull/1062))
* 🐛 Fix a bug where `text/xml` response content should be logged ([#1058](https://github.com/zapier/zapier-platform/pull/1058))
* 💅 Typing update: allow overriding `id` requirement in polling triggers ([#1059](https://github.com/zapier/zapier-platform/pull/1059))
* 💅 Typing update: allow test bundles to be recursively partial ([#1057](https://github.com/zapier/zapier-platform/pull/1057))
* 🔨 Bump fernet from 0.4.0 to 0.3.3 (latest) ([#1055](https://github.com/zapier/zapier-platform/pull/1055))
## schema
* 🎉 Input fields now support visual grouping through the "group" property of the `/PlainInputFieldSchema` and the new `/InputFieldGroupsSchema` ([#1061](https://github.com/zapier/zapier-platform/pull/1061))

View file

@ -0,0 +1,24 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.3.1
> Regression bug fixes with `zapier build`.
*Released: 2025-07-17*
## cli
* 🐛 Fix regression bugs with `zapier build --skip-npm-install`, where:
* it can miss local packages files when building in a Lerna monorepo ([#1068](https://github.com/zapier/zapier-platform/pull/1068))
* it can fail with "Configuration property ... is not defined" when [config](https://www.npmjs.com/package/config) package is used ([#1071](https://github.com/zapier/zapier-platform/pull/1071))
* 💅 Improve some error messages in `zapier build` ([#1070](https://github.com/zapier/zapier-platform/pull/1070))
## core
* 💅 Improve the error message when the app module fails to import ([#1070](https://github.com/zapier/zapier-platform/pull/1070))
## schema
None!

View file

@ -0,0 +1,24 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.4.0
> Regression bug fixes with `zapier build`, support for compression of large input bundles.
*Released: 2025-07-23*
## cli
* 🐛 Fix regression bugs with `zapier build`, where it can fail with "'The "path" argument must be of type string'" when [dirent.parentPath](https://nodejs.org/docs/latest/api/fs.html#direntparentpath) property is missing ([#1087](https://github.com/zapier/zapier-platform/pull/1087))
* 🐛 Fixes a regression where `zapier build --skip-npm-install` fails when an app has a linked dependencies in its `node_modules` ([#1089](https://github.com/zapier/zapier-platform/pull/1089))
* 🐛 Remove empty array at the end of `zapier versions -f json` ([#1086](https://github.com/zapier/zapier-platform/pull/1086))
* 💅 Add additional Typescript auth options to `zapier init` ([#1067](https://github.com/zapier/zapier-platform/pull/1067))
## core
* 💅 Support compression when stashing large input bundles ([#1085](https://github.com/zapier/zapier-platform/pull/1085))
## schema
None!

View file

@ -0,0 +1,26 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.5.0
> Global `errors`, bug fixes with `zapier build` and auth field types.
*Released: 2025-07-30*
## cli
* 🐛 Fix missing `bundle.inputDataRaw` in invoke command ([#1072](https://github.com/zapier/zapier-platform/pull/1072))
* 🐛 Fix error `'No loader is configured for ".node" files'` on `zapier build` ([#1094](https://github.com/zapier/zapier-platform/pull/1094))
* 🔨 Refactor `zapier init` to move auth befores/afters into `middleware.js` instead of `authentication.js` ([#1073](https://github.com/zapier/zapier-platform/pull/1073))
## core
* 💅 Export errors from `zapier-platform-core` ([#1075](https://github.com/zapier/zapier-platform/pull/1075))
* 🔨 Update `form-data` from `4.0.1` to `4.0.4` ([#1096](https://github.com/zapier/zapier-platform/pull/1096))
## schema
* 💅 Expanded `AuthFieldSchema` with additional field types:
* Added support for the `integer` type ([#1095](https://github.com/zapier/zapier-platform/pull/1095)).
* Added support for the `text` type ([#1098](https://github.com/zapier/zapier-platform/pull/1098)).

View file

@ -0,0 +1,22 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.6.0
> Global `console` object and account filtering for `zapier canary`.
*Released: 2025-08-11*
## cli
* 💅 Add user and account filters to canary ([#1066](https://github.com/zapier/zapier-platform/pull/1066))
## core
* 💅 Export `console` from zapier-platform-core ([#1077](https://github.com/zapier/zapier-platform/pull/1077), [#1102](https://github.com/zapier/zapier-platform/pull/1102))
* 🐛 Allow safe `authData` keys to be logged uncensored ([#1097](https://github.com/zapier/zapier-platform/pull/1097))
## schema
None!

View file

@ -0,0 +1,31 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.7.0
> This update lays groundwork for Search Pagination, which will allow Search steps to paginate through results so that the most relevant results can be returned. However, this is not yet supported by any Zapier products.
*Released: 2025-08-22*
## cli
* 🐛 Fix `zapier pull` error "listFiles is not a function" ([#1113](https://github.com/zapier/zapier-platform/pull/1113))
* 🐛 Fix `zapier invoke auth` writing object values to `.env` as `[object Object]` ([#1107](https://github.com/zapier/zapier-platform/pull/1107))
* 💅 Add logic to `zapier build` to handle the case where the app directory has symlinks to files on a different drive ([#1106](https://github.com/zapier/zapier-platform/pull/1106))
* 🎉 `zapier invoke` supports testing Search Pagination with a `paging_token` flag ([#1082](https://github.com/zapier/zapier-platform/pull/1082))
## core
* 🎉 Foundational support for Search Pagination ([#1082](https://github.com/zapier/zapier-platform/pull/1082))
## schema
* 🎉 Schema support for Search Pagination ([#1082](https://github.com/zapier/zapier-platform/pull/1082))
## misc
* 💅 Enable Windows in Github Actions CI ([#1106](https://github.com/zapier/zapier-platform/pull/1106))
* 💅 Add Claude, Copilot, and Cursor instructions/rules ([#1107](https://github.com/zapier/zapier-platform/pull/1107))
* 🔨 Bump `tmp` from 0.2.3 to 0.2.4 ([#1100](https://github.com/zapier/zapier-platform/pull/1100))
* 🔨 Bump `sha.js` from 2.4.11 to 2.4.12 ([#1116](https://github.com/zapier/zapier-platform/pull/1116))

View file

@ -0,0 +1,29 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.7.1
> Improved `zapier scaffold`, `zapier init`, `zapier validate`, and `zapier invoke auth`. Also fixed issues with uncensored sensitive information and field grouping schema.
*Released: 2025-09-10*
## cli
* 🐛 Fix `zapier scaffold` failing when app object contains spread elements ([#1115](https://github.com/zapier/zapier-platform/pull/1115))
* 🐛 Fix `zapier invoke auth` may append to last line without a newline ([#1138](https://github.com/zapier/zapier-platform/pull/1138))
* 🐛 Fix `zapier scaffold` to use `.js` extension for TS imports ([#1123](https://github.com/zapier/zapier-platform/pull/1123))
* 🐛 Fix `zapier scaffold` to handle shorthand property syntax ([#1125](https://github.com/zapier/zapier-platform/pull/1125))
* 💅 `zapier validate` now runs `_zapier-build` before validation by default ([#1130](https://github.com/zapier/zapier-platform/pull/1130))
* 💅 Add `dev` script to `package.json` of typescript templates generated by `zapier init` ([#1128](https://github.com/zapier/zapier-platform/pull/1128))
* 💅 Improve `zapier init` to list only templates that support selected module and language ([#1146](https://github.com/zapier/zapier-platform/pull/1146))
## core
* 🐛 Censor sensitive info in `ResponseError` ([#1147](https://github.com/zapier/zapier-platform/pull/1147))
## schema
* 🐛 Fix `InputFieldGroupsSchema` to have its properties displayed ([#1143](https://github.com/zapier/zapier-platform/pull/1143))
* 🧪 Allow to skip cleaning arrays in `inputData` via `skipCleanArrayInputData` ([#1153](https://github.com/zapier/zapier-platform/pull/1153))
* 🔨 Support version with label (ongoing work) ([#1093](https://github.com/zapier/zapier-platform/pull/1093))

View file

@ -0,0 +1,23 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.7.2
> Fixed issues with typing and semver restriction.
*Released: 2025-09-17*
## cli
* 🐛 Allows deleting old non-semver versions and blocks pushes to non-semver versions ([#1160](https://github.com/zapier/zapier-platform/pull/1160))
* 🐛 Integration check displays failure icon if errors are present ([#1159](https://github.com/zapier/zapier-platform/pull/1159))
## core
* 🐛 Adds paging\_token to bundle.meta types ([#1157](https://github.com/zapier/zapier-platform/pull/1157))
## misc
* 🔨 Bump vite from 6.3.5 to 6.3.6 ([#1156](https://github.com/zapier/zapier-platform/pull/1156))
* 🔨 Improve types ([#1162](https://github.com/zapier/zapier-platform/pull/1162), [#1164](https://github.com/zapier/zapier-platform/pull/1164), [#1165](https://github.com/zapier/zapier-platform/pull/1165))

View file

@ -0,0 +1,26 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.8.0
> Added flexibility for Search Pagination and cleaning up some dependencies. Zapier push now supports snapshot publishing.
*Released: 2025-10-07*
Aside from some clean up work, this release adds support for natural snapshots to `zapier push`. This is currently only supported internally but look out for a public release soon!
## cli
* 💅 `zapier push` supports natural snapshots ([#1172](https://github.com/zapier/zapier-platform/pull/1172))
* 🐛 Address `punycode` deprecation warning by removing `node-fetch` ([#1171](https://github.com/zapier/zapier-platform/pull/1171))
* 📜 Fix incorrect docs in `zapier migrate` ([#1169](https://github.com/zapier/zapier-platform/pull/1169))
## core
* 🐛 Allow null and undefined values for `page_token` in `SearchResult` ([#1168](https://github.com/zapier/zapier-platform/pull/1168))
* 🐛 Allow undefined value for `paging_token` ([#1166](https://github.com/zapier/zapier-platform/pull/1166))
## misc
* 📜 Direct developers to Platform News ([#1174](https://github.com/zapier/zapier-platform/pull/1174))

View file

@ -0,0 +1,24 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.9.0
> Bugfix for snapshot flag, improvements for `zapier env`.
*Released: 2025-10-20*
This release fixes an issue with validation for labeled versions, and improves failures on `zapier env:set`.
## cli
* 🐛 Validate snapshot labels for 12 chars instead of 18 ([#1182](https://github.com/zapier/zapier-platform/pull/1182))
* 💅 Display failure reasons for env:set ([#1180](https://github.com/zapier/zapier-platform/pull/1180))
## core
None!
## schema
None!

View file

@ -0,0 +1,27 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v17.9.1
> Bug fix for zapier push and dependency updates.
*Released: 2025-10-28*
This release addresses a bug in the `zapier push` command and includes dependency updates.
## cli
* 🐛 Fix issue where zapier push fail if the app wasn't built already (may have affected ESM builds) ([#1187](https://github.com/zapier/zapier-platform/pull/1187))
## core
None!
## schema
None!
## misc
* 🔨 Bump vite from 6.3.6 to 6.4.1 ([#1185](https://github.com/zapier/zapier-platform/pull/1185))

View file

@ -0,0 +1,56 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v18.0.0
> Node.js 22 support, new throttling middleware, and a new CLI executable name `zapier-platform`.
*Released: 2025-10-30*
Version 18.0.0 is a **BREAKING CHANGE** release that contains several important upgrades and changes. Here is a brief breakdown of the main changes (**❗ denotes a breaking change**):
## ❗ Node.js 22 Support
Zapier Platform v18 runs on Node.js 22 runtime. This is a breaking change as it may affect compatibility with older Node.js versions and dependencies.
## ❗ Schema Changes
The `skipCleanArrayInputData` experimental flag has been replaced with `cleanInputData`. This provides more consistent data cleaning behavior across the platform. This change is breaking **only if** you're using `skipCleanArrayInputData`.
See [cleanInputData flag documentation](/integrations/build-cli/empty-values-in-input-data) for more details on how to configure this behavior.
## ❗ New Throttling Middleware
A new `throwForThrottling` middleware has been added to prevent `afterResponse` middleware from suppressing 429 (throttling) responses. This ensures proper handling of rate limiting scenarios. This change is breaking **if** you want to handle 429 responses in your `afterResponse`. See [v18.x and above: the built-in `throwForThrottling` middleware](/integrations/build-cli/making-http-requests#v18-x-and-above%3A-the-built-in-throwforthrottling-middleware) for how to handle 429s yourself.
## New Executable Name `zapier-platform`
The CLI now includes a new executable name `zapier-platform` while deprecating the old `zapier` command. Both will work for now, but `zapier-platform` is the recommended command going forward.
***
Apart from these major changes, here are the detailed release notes for this release (**note that ❗ denotes a breaking change**):
## cli
* 🎉 Add executable name `zapier-platform` and deprecate `zapier` ([#1181](https://github.com/zapier/zapier-platform/pull/1181))
* 🔨 Update outdated dependencies with security vulnerabilities ([#1111](https://github.com/zapier/zapier-platform/pull/1111))
* 🔨 Apply prettier formatting to generated auth files since gen.fs.write bypasses transform streams
* 🔨 Add ESM wrapper improvements for better module support
## core
* ❗ Add Node.js 22 support ([#1078](https://github.com/zapier/zapier-platform/pull/1078))
* 🎉 Add `throwForThrottling` middleware with backward-compatible default behavior ([#1151](https://github.com/zapier/zapier-platform/pull/1151))
* 🐛 Add better error message for 413 responses ([#1110](https://github.com/zapier/zapier-platform/pull/1110))
## schema
* ❗ Replace `skipCleanArrayInputData` with `cleanInputData` ([#1183](https://github.com/zapier/zapier-platform/pull/1183))
* 🔨 Add global `cleanInputData` flag for consistent data cleaning behavior
## misc
* ❗ Major dependency updates across all packages ([#1079](https://github.com/zapier/zapier-platform/pull/1079))
* 🔨 Update CI configuration for Node.js 22 support
* 🔨 Pin exact xmldom version for security

View file

@ -0,0 +1,27 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v18.0.1
> Bug fixes for npx resolution and TypeScript typing for line items.
*Released: 2025-11-05*
This release addresses an npx resolution issue introduced in v18.0.0 and fixes TypeScript typing for nested input fields when working with line items.
## cli
* 🐛 Fix npx resolution issue with dual binary entries ([#1191](https://github.com/zapier/zapier-platform/pull/1191))
## core
* 🐛 Fix children input types when line items are present ([#1188](https://github.com/zapier/zapier-platform/pull/1188))
## schema
None!
## misc
None!

View file

@ -0,0 +1,33 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v18.0.5
> A security fix on the CLI.
*Released: 2025-12-10*
<Info>
We're releasing v18.0.5, skipping comprimised versions v18.0.2, v18.0.3, and
v18.0.4, due to the prior [security
incident](/integrations/news/2025/npm-package-sec-inc).
</Info>
This release fixes a potential security vulnerability in the `build` command related to zip file decompression.
## cli
* 🐛 Remove problematic decompress-tar dependency ([#1202](https://github.com/zapier/zapier-platform/pull/1202))
## core
None!
## schema
None!
## misc
* 🔨 Switch to pnpm as package manager and task runner ([#1204](https://github.com/zapier/zapier-platform/pull/1204))

View file

@ -0,0 +1,31 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v18.0.6
> Package manager detection from `zapier build`
*Released: 2025-12-24*
The `zapier build` command was harcoded to use `npm install`. As alternate package managers gain adoption, the `zapier build` command will respect your app's package manager of choice.
It does this by checking the `packageManager` on the package.json file. If it is not defined, it will look for any relevant lock files. If still, none is defined, then will fallback to `npm`.
If you are familiar with using `zapier build` with the flag `--skip-npm-install`, this flag has been renamed to `--skip-dep-install`, but will continue to still work as an alias. In the future, we will remove the `--skip-npm-install` flag.
## cli
* 💅 CLI build respects the integration's package manager ([#1216](https://github.com/zapier/zapier-platform/pull/1216))
## core
None!
## schema
None!
## misc
* 🔨 Bump tmp from 0.2.4 to 0.2.5 ([#1207](https://github.com/zapier/zapier-platform/pull/1207))
* 🔨 Bump form-data from 4.0.4 to 4.0.5 ([#1208](https://github.com/zapier/zapier-platform/pull/1208))

View file

@ -0,0 +1,107 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# Platform News in 2026
<Card title="What's changed in v19.1.0" icon="newspaper" href="/integrations/news/2026/v19.1.0" horizontal>
Auth template rendering can honor the real outbound request and custom request properties, plus a fix for the `appTester` type signature
*Released: 2026-07-30*
</Card>
<Card title="What's changed in v19.0.0" icon="newspaper" href="/integrations/news/2026/v19.0.0" horizontal>
The `zapier` CLI binary has been removed. Use `zapier-platform` instead.
*Released: 2026-05-18*
</Card>
<Card title="New platform guardrails for safer integration versioning" icon="newspaper" href="/integrations/news/2026/version-promotion-guardrails" horizontal>
The platform now checks for breaking changes during promotion and guides you toward the correct semantic version, helping protect your users from unexpected disruptions.
*Effective: 2026-05-12*
</Card>
<Card title="What's changed in v18.6.0" icon="newspaper" href="/integrations/news/2026/v18.6.0" horizontal>
New `invoke auth template` and `invoke auth render` commands for inspecting an app's auth request shape
*Released: 2026-05-05*
</Card>
<Card title="What's changed in v18.5.1" icon="newspaper" href="/integrations/news/2026/v18.5.1" horizontal>
Actionable error when app definition fails to load, `platformData` removed from bundle, docs and `help` updated to use `zapier-platform` binary name
*Released: 2026-04-30*
</Card>
<Card title="What's changed in v18.5.0" icon="newspaper" href="/integrations/news/2026/v18.5.0" horizontal>
Line item support in `invoke`, falsy value fixes, new `line-items` project template
*Released: 2026-04-16*
</Card>
<Card title="What's changed in v18.4.0" icon="newspaper" href="/integrations/news/2026/v18.4.0" horizontal>
JSON input field type, `versions` command improvements, function-based dynamic dropdown fix
*Released: 2026-04-06*
</Card>
<Card title="What's changed in v18.3.0" icon="newspaper" href="/integrations/news/2026/v18.3.0" horizontal>
Bug fixes and improvements
*Released: 2026-03-12*
</Card>
<Card title="What's changed in v18.2.3" icon="newspaper" href="/integrations/news/2026/v18.2.3" horizontal>
Bug fixes and improvements
*Released: 2026-03-04*
</Card>
<Card title="What's changed in v18.2.2" icon="newspaper" href="/integrations/news/2026/v18.2.2" horizontal>
Bug fix for legacy-scripting-runner module loading
*Released: 2026-02-26*
</Card>
<Card title="User migrations must stay within the same major version" icon="newspaper" href="/integrations/news/2026/migrations-same-major-version" horizontal>
The Platform UI and CLI now block migrating users when the source and target integration versions differ in their [semantic major version](/integrations/manage/versions#version-numbering)—for example, you cannot migrate from `1.x.x` to `2.x.x`.
*Effective: 2026-02-26*
</Card>
<Card title="What's changed in v18.2.1" icon="newspaper" href="/integrations/news/2026/v18.2.1" horizontal>
Bug fix for build command with symlink-based package managers
*Released: 2026-02-23*
</Card>
<Card title="Pushing unlabelled semantic versions must be sequential" icon="newspaper" href="/integrations/news/2026/no-skip-or-intermediate-versions" horizontal>
Unlabelled integration versions must be published in order via `zapier-platform push`.
*Effective: 2026-02-23*
</Card>
<Card title="What's changed in v18.2.0" icon="newspaper" href="/integrations/news/2026/v18.2.0" horizontal>
invoke command supports function-based choices, stashing returns a better error message
*Released: 2026-02-18*
</Card>
<Card title="What's changed in v18.1.1" icon="newspaper" href="/integrations/news/2026/v18.1.1" horizontal>
Bug fix for missing HTTP error logs and security updates.
*Released: 2026-01-29*
</Card>
<Card title="What's changed in v18.1.0" icon="newspaper" href="/integrations/news/2026/v18.1.0" horizontal>
New `invoke --remote` flag and a fix on package manager detection.
*Released: 2026-01-19*
</Card>
<Card title="What's changed in v18.0.7" icon="newspaper" href="/integrations/news/2026/v18.0.7" horizontal>
Publishing process improvements, refactoring, and `sample` field added to dynamic `outputFields`.
*Released: 2026-01-07*
</Card>

View file

@ -0,0 +1,107 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# Platform News in 2026
<Card title="What's changed in v19.1.0" icon="newspaper" href="/integrations/news/2026/v19.1.0" horizontal>
Auth template rendering can honor the real outbound request and custom request properties, plus a fix for the `appTester` type signature
*Released: 2026-07-30*
</Card>
<Card title="What's changed in v19.0.0" icon="newspaper" href="/integrations/news/2026/v19.0.0" horizontal>
The `zapier` CLI binary has been removed. Use `zapier-platform` instead.
*Released: 2026-05-18*
</Card>
<Card title="New platform guardrails for safer integration versioning" icon="newspaper" href="/integrations/news/2026/version-promotion-guardrails" horizontal>
The platform now checks for breaking changes during promotion and guides you toward the correct semantic version, helping protect your users from unexpected disruptions.
*Effective: 2026-05-12*
</Card>
<Card title="What's changed in v18.6.0" icon="newspaper" href="/integrations/news/2026/v18.6.0" horizontal>
New `invoke auth template` and `invoke auth render` commands for inspecting an app's auth request shape
*Released: 2026-05-05*
</Card>
<Card title="What's changed in v18.5.1" icon="newspaper" href="/integrations/news/2026/v18.5.1" horizontal>
Actionable error when app definition fails to load, `platformData` removed from bundle, docs and `help` updated to use `zapier-platform` binary name
*Released: 2026-04-30*
</Card>
<Card title="What's changed in v18.5.0" icon="newspaper" href="/integrations/news/2026/v18.5.0" horizontal>
Line item support in `invoke`, falsy value fixes, new `line-items` project template
*Released: 2026-04-16*
</Card>
<Card title="What's changed in v18.4.0" icon="newspaper" href="/integrations/news/2026/v18.4.0" horizontal>
JSON input field type, `versions` command improvements, function-based dynamic dropdown fix
*Released: 2026-04-06*
</Card>
<Card title="What's changed in v18.3.0" icon="newspaper" href="/integrations/news/2026/v18.3.0" horizontal>
Bug fixes and improvements
*Released: 2026-03-12*
</Card>
<Card title="What's changed in v18.2.3" icon="newspaper" href="/integrations/news/2026/v18.2.3" horizontal>
Bug fixes and improvements
*Released: 2026-03-04*
</Card>
<Card title="What's changed in v18.2.2" icon="newspaper" href="/integrations/news/2026/v18.2.2" horizontal>
Bug fix for legacy-scripting-runner module loading
*Released: 2026-02-26*
</Card>
<Card title="User migrations must stay within the same major version" icon="newspaper" href="/integrations/news/2026/migrations-same-major-version" horizontal>
The Platform UI and CLI now block migrating users when the source and target integration versions differ in their [semantic major version](/integrations/manage/versions#version-numbering)—for example, you cannot migrate from `1.x.x` to `2.x.x`.
*Effective: 2026-02-26*
</Card>
<Card title="What's changed in v18.2.1" icon="newspaper" href="/integrations/news/2026/v18.2.1" horizontal>
Bug fix for build command with symlink-based package managers
*Released: 2026-02-23*
</Card>
<Card title="Pushing unlabelled semantic versions must be sequential" icon="newspaper" href="/integrations/news/2026/no-skip-or-intermediate-versions" horizontal>
Unlabelled integration versions must be published in order via `zapier-platform push`.
*Effective: 2026-02-23*
</Card>
<Card title="What's changed in v18.2.0" icon="newspaper" href="/integrations/news/2026/v18.2.0" horizontal>
invoke command supports function-based choices, stashing returns a better error message
*Released: 2026-02-18*
</Card>
<Card title="What's changed in v18.1.1" icon="newspaper" href="/integrations/news/2026/v18.1.1" horizontal>
Bug fix for missing HTTP error logs and security updates.
*Released: 2026-01-29*
</Card>
<Card title="What's changed in v18.1.0" icon="newspaper" href="/integrations/news/2026/v18.1.0" horizontal>
New `invoke --remote` flag and a fix on package manager detection.
*Released: 2026-01-19*
</Card>
<Card title="What's changed in v18.0.7" icon="newspaper" href="/integrations/news/2026/v18.0.7" horizontal>
Publishing process improvements, refactoring, and `sample` field added to dynamic `outputFields`.
*Released: 2026-01-07*
</Card>

View file

@ -0,0 +1,15 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# User migrations must stay within the same major version
> The Platform UI and CLI now block migrating users when the source and target integration versions differ in their [semantic major version](/integrations/manage/versions#version-numbering)—for example, you cannot migrate from `1.x.x` to `2.x.x`.
*Effective: 2026-02-26*
## Same-major-version migrations only
* Migrations are only allowed when the **from** and **to** versions share the same major number (e.g. `1.0.0``1.0.1`, or `2.1.0``2.2.0`).
* Cross-major moves (e.g. `1.5.0``2.0.0`) are blocked in both the [Platform UI](https://zapier.com/app/developer) and via [`zapier-platform migrate`](https://github.com/zapier/zapier-platform/blob/main/packages/cli/docs/cli.md#migrate). This aligns with long-standing guidance; major releases include [breaking changes](/integrations/manage/planning-changes), so users should [update Zap workflows manually](https://help.zapier.com/hc/en-us/articles/18755649454989-App-versions-in-Zapier) or you should use [deprecation](/integrations/manage/versions#deprecating-versions) instead of migration.
* Details and workflow are in [Migrate users to a new version](/integrations/manage/migrate).

View file

@ -0,0 +1,42 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# Pushing unlabelled semantic versions must be sequential
> Unlabelled integration versions must be published in order via `zapier-platform push`.
*Effective: 2026-02-23*
## What changed
These rules apply to **unlabelled** [semantic versions](/integrations/manage/versions#version-numbering) only (for example `1.2.3`). **[Labelled versions](/integrations/manage/labeled-versions)** (such as `1.2.3-beta` or `0.0.0-my-feature`) are not part of these checks.
When you push a new unlabelled version, the platform validates **two** things in addition to existing format checks.
### 1. You cannot skip a required predecessor
The API must see the right **previous** unlabelled release before it accepts the new one:
* **Patch bump** (`1.2.3`): the exact unlabelled `1.2.2` must already exist.
* **Minor bump** (`1.3.0`): at least one unlabelled `1.2.x` must exist.
* **Major bump** (`2.0.0` when coming from `1.x`): at least one unlabelled `1.x.x` must exist.
`1.0.0` is unchanged: there is no prior semver to require.
If the predecessor is missing, push fails with **403** and guidance like: *Version X requires Y to exist. Push version Y, then try again.*
### 2. You cannot insert an “intermediate” version behind a newer line
You also cannot push a version if a **newer** unlabelled version already exists in the segment that would make yours a backward insert:
* **`1.2.3`**: blocked if any unlabelled **`1.2.4` or higher** on the same `1.2.*` line already exists. Pushing **`1.3.0`** is still allowed when only `1.3.x` or `2.x.x` exists—those are not on the `1.2.*` patch line.
* **`1.3.0`**: blocked if any unlabelled **`1.4.x` or higher** on the same major (`1.*`) already exists. **`2.0.0`** is still allowed when only `2.x.x` exists.
* **`2.0.0`**: blocked if any unlabelled **`3.x.x` or higher** already exists.
If that applies, push fails with **403** and a message that an existing version would make this an intermediate release, which is not allowed.
## What this means for you
* Plan **patch → patch → minor → major** (or the minimal chain your history needs) using **unlabelled** semver when you are ready to record real releases; use **labelled** snapshots while iterating.
* If you are stuck because old versions were removed, you may still use **[deprecation](/integrations/manage/versions#deprecating-versions)** and, when appropriate, **[delete a deprecated version](/integrations/manage/deprecate#deleting-deprecated-versions)** so your remaining unlabelled history matches what you want to push next.

View file

@ -0,0 +1,27 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v18.0.7
> Publishing process improvements, refactoring, and `sample` field added to dynamic `outputFields`.
*Released: 2026-01-07*
In response to the previous [Shai-Hulud incident](/integrations/build-cli/inc-547), we're changing our package publishing process to improve security. This release also includes a schema extension that allows `outputFields` to have a `sample` field. Lastly, we've refactored the `invoke` command to make upcoming enhancements easier.
## cli
* 🔨 Refactor `invoke` command ([#1217](https://github.com/zapier/zapier-platform/pull/1217))
## core
None!
## schema
* 🎉 Allow a `sample` field to be provided for dynamic `outputFields` ([#1211](https://github.com/zapier/zapier-platform/pull/1211))
## misc
* 🔨 Add publish job in CI ([#1212](https://github.com/zapier/zapier-platform/pull/1212), [#1223](https://github.com/zapier/zapier-platform/pull/1223))

View file

@ -0,0 +1,42 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v18.1.0
> New `invoke --remote` flag and a fix on package manager detection.
*Released: 2026-01-19*
The `zapier-platform invoke` command now supports a **remote mode**. By adding a `--remote` (`-r` for short) flag to the `invoke` command, such as:
```
zapier-platform invoke -r
```
... all invocations, including trigger/action invocation itself, input field definitions, and dynamic dropdown choices, will be executed remotely by the Zapier production environment. This means:
* The integration version you want to test has to be deployed first.
* The invocation results and the bundle payload passed to your integration code will match what you see in live production, which is great for testing.
* Remote mode is slower than local mode (without the `-r` flag).
Read more about the three different modes in the [`zapier-platform invoke --help`](https://github.com/zapier/zapier-platform/blob/main/packages/cli/docs/cli.md#invoke) documentation.
We also fixed an issue where the `build` and `test` commands were not correctly detecting package managers (like npm, yarn, pnpm, or bun) when your integration was part of a monorepo. Now, the CLI doesn't just look in the current directory for package manager indicators (like `package-lock.json` for npm), but also checks parent directories up to four levels up.
## cli
* 🎉 Add `--remote` flag to `invoke` command ([#1220](https://github.com/zapier/zapier-platform/pull/1220))
* 🐛 Fix package manager detection in `build` and `test` commands to include parent directories ([#1225](https://github.com/zapier/zapier-platform/pull/1225))
## core
None!
## schema
None!
## misc
* 📜 Improve internal development docs ([#1221](https://github.com/zapier/zapier-platform/pull/1221))

View file

@ -0,0 +1,27 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v18.1.1
> Bug fix for missing HTTP error logs and security updates.
*Released: 2026-01-29*
Main change introduced here is fixing missing HTTP error logs that were prematurely lost during a Lambda invocation.
## cli
None!
## core
* 🐛 Restore missing HTTP error logs ([#1227](https://github.com/zapier/zapier-platform/pull/1227))
## schema
None!
## misc
* 🔨 Bump lodash from 4.17.21 to 4.17.23 across the board ([#1228](https://github.com/zapier/zapier-platform/pull/1228), [#1229](https://github.com/zapier/zapier-platform/pull/1229), [#1230](https://github.com/zapier/zapier-platform/pull/1230), [#1231](https://github.com/zapier/zapier-platform/pull/1231), [#1233](https://github.com/zapier/zapier-platform/pull/1233), [#1234](https://github.com/zapier/zapier-platform/pull/1234), [#1235](https://github.com/zapier/zapier-platform/pull/1235))

View file

@ -0,0 +1,29 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v18.2.0
> invoke command supports function-based choices, stashing returns a better error message
*Released: 2026-02-18*
The main change in this release is to support function-based choices in the `invoke` command, which will allow developers to test perform-based dynamic dropdowns.
## cli
* 🎉 `zapier-platform invoke` now supports function-based choices ([#1237](https://github.com/zapier/zapier-platform/pull/1237))
## core
* 🐛 If we attempt to stash a large response but it's bigger than the max limit, throw a descriptive error with the actual size and the limit ([#1238](https://github.com/zapier/zapier-platform/pull/1238))
* 🔨 Add an environment variable to allow suppressing cleaning up env vars ([#1242](https://github.com/zapier/zapier-platform/pull/1242))
## schema
None!
## misc
* 🔨 CI: Use `environment` to publish ([#1239](https://github.com/zapier/zapier-platform/pull/1239))
* 🔨 CI: Automate the boilerplate upload ([#1240](https://github.com/zapier/zapier-platform/pull/1240))

View file

@ -0,0 +1,23 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v18.2.1
> Bug fix for build command with symlink-based package managers
*Released: 2026-02-23*
Resolved a bug in the CLI that caused the `build` command to fail when using a symlink-based package manager (like pnpm).
## cli
* 🐛 `zapier-platform build` no longer raises `EEXIST` when using a symlink-based package manager ([#1244](https://github.com/zapier/zapier-platform/pull/1244))
## core
None!
## schema
None!

View file

@ -0,0 +1,28 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v18.2.2
> Bug fix for legacy-scripting-runner module loading
*Released: 2026-02-26*
Improved error handling when loading the legacy-scripting-runner module in core. The runtime now logs a warning with the actual error message when the module is installed but fails to load, making it easier to diagnose issues like missing transitive dependencies.
## cli
None!
## core
* 🐛 Log a warning when `zapier-platform-legacy-scripting-runner` is installed but fails to load, instead of silently returning null ([#1247](https://github.com/zapier/zapier-platform/pull/1247))
## schema
None!
## misc
* 🔨 Fix publishing workflow to run on pushes to `main` ([#1243](https://github.com/zapier/zapier-platform/pull/1243))
* 🔨 Add non-interactive mode to bump script ([#1249](https://github.com/zapier/zapier-platform/pull/1249))

View file

@ -0,0 +1,23 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v18.2.3
> Bug fixes and improvements
*Released: 2026-03-04*
Bug fixes for the CLI build command and pnpm compatibility.
## cli
* 🐛 Surface package manager errors in `build` command ([#1254](https://github.com/zapier/zapier-platform/pull/1254))
## core
* 🐛 Declare `zapier-platform-legacy-scripting-runner` as an optional peer dep to fix pnpm strict module resolution ([#1255](https://github.com/zapier/zapier-platform/pull/1255))
## schema
None!

View file

@ -0,0 +1,23 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v18.3.0
> Bug fixes and improvements
*Released: 2026-03-12*
Add support for function-based dynamic dropdowns
## cli
* 🎉 Add support for function-based dynamic dropdown to the invoke command ([#1206](https://github.com/zapier/zapier-platform/pull/1206))
## core
None!
## schema
* 🎉 Add FieldDynamicChoicesSchema for function-based dynamic dropdowns ([#1206](https://github.com/zapier/zapier-platform/pull/1206))

View file

@ -0,0 +1,72 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v18.4.0
> JSON input field type, `versions` command improvements, function-based dynamic dropdown fix
*Released: 2026-04-06*
This release introduces the new `json` input field type, improved `zapier versions` output, and a schema validation fix.
You can now accept structured JSON input from users with the new [`json` field type](/integrations/build-cli/input-fields#json-fields). Optionally provide a `schema` to validate and describe the expected shape:
```javascript theme={null}
{
key: 'product',
type: 'json',
label: 'Product',
helpText: 'Enter a JSON object',
schema: {
type: 'object',
properties: {
name: { type: 'string' },
price: { type: 'integer' },
},
required: ['name'],
},
}
```
We also fixed a bug where pushing code with [function-based dynamic dropdowns](/integrations/build-cli/dynamic-dropdowns#function-based-dynamic-dropdowns-perform) caused an unexpected validation error on the server. If you want to use function-based dynamic dropdowns, upgrade to 18.4.0 or later:
```javascript theme={null}
{
key: 'project_id',
label: 'Project',
type: 'string',
required: true,
choices: {
perform: async (z, bundle) => {
const response = await z.request('https://api.example.com/projects');
return {
results: response.data.map((project) => ({
id: project.id,
label: project.name,
})),
paging_token: null,
};
},
},
}
```
## cli
* 💅 Clarify `zapier-platform versions` timestamps with separate "Created at" and "Updated at" columns ([#1275](https://github.com/zapier/zapier-platform/pull/1275))
## core
* 🎉 Add JSON field type handling with schema-aware TypeScript inference ([#1273](https://github.com/zapier/zapier-platform/pull/1273))
## schema
* 🎉 Add JSON input field type with optional `schema` property for structured data ([#1265](https://github.com/zapier/zapier-platform/pull/1265))
* 🎉 Validate `schema` property on JSON fields against JSON Schema meta-schema ([#1267](https://github.com/zapier/zapier-platform/pull/1267))
* 🐛 Fix oneOf ambiguity in FieldChoicesSchema that caused server-side validation errors for function-based dynamic dropdowns ([#1268](https://github.com/zapier/zapier-platform/pull/1268))
* 📜 Update `skipThrowForStatus` documentation to note 401 errors are not subject to the flag ([#1270](https://github.com/zapier/zapier-platform/pull/1270))
## misc
* 🔨 Improve publish workflow with path filters and boilerplate build fixes ([#1264](https://github.com/zapier/zapier-platform/pull/1264), [#1266](https://github.com/zapier/zapier-platform/pull/1266))

View file

@ -0,0 +1,39 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v18.5.0
> Line item support in `invoke`, falsy value fixes, new `line-items` project template
*Released: 2026-04-16*
This release adds line item support to the `zapier-platform invoke` command and bumps `lodash` across all packages to address a security vulnerability.
[Line items](/integrations/build-cli/input-fields#line-items) are fields with a `children` property that represent structured, repeating data — like rows in a spreadsheet or items in an order. The `invoke` command now supports them in both interactive and non-interactive modes:
```bash theme={null}
# Non-interactive: pass line items as JSON
zapier-platform invoke create order --non-interactive \
-i '{"name": "My Order", "line_items": [{"product_name": "Pens", "quantity": "12", "price": "1.50"}]}'
# Interactive: use the line item editing UI
zapier-platform invoke create order -i '{"name": "My Order"}'
```
In interactive mode, a sub-menu lets you add, edit, and delete items with per-field editing and required field validation.
## cli
* 🎉 Add line item support to `invoke` command with interactive editing UI ([#1272](https://github.com/zapier/zapier-platform/pull/1272))
* 🎉 Add `line-items` project template for `zapier-platform init` ([#1272](https://github.com/zapier/zapier-platform/pull/1272))
* 🐛 Fix `invoke` bugs: auto-detect auth ID for no-auth apps in remote mode, falsy value handling (`0`, `false`) causing infinite dropdown re-prompting, and more ([#1272](https://github.com/zapier/zapier-platform/pull/1272))
* 🔨 Bump `lodash` from 4.17.23 to 4.18.1 ([#1274](https://github.com/zapier/zapier-platform/pull/1274))
## core
* 🔨 Bump `lodash` from 4.17.23 to 4.18.1 ([#1274](https://github.com/zapier/zapier-platform/pull/1274))
## schema
* 🔨 Bump `lodash` from 4.17.23 to 4.18.1 ([#1274](https://github.com/zapier/zapier-platform/pull/1274))

View file

@ -0,0 +1,26 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v18.5.1
> Actionable error when app definition fails to load, `platformData` removed from bundle, docs and `help` updated to use `zapier-platform` binary name
*Released: 2026-04-30*
This patch release improves the error message you get when an app definition fails to load, removes `platformData` from the bundle, and finishes the rename of the CLI binary from `zapier` to `zapier-platform` across docs and the `help` command.
We're renaming `zapier` to `zapier-platform` because the `zapier` binary name will be allocated to the [Zapier SDK](https://docs.zapier.com/sdk). The `zapier` binary still works in v18, but in the next major release (v19), we'll officially remove it — you'll need to use `zapier-platform` instead. If `zapier-platform` is too long to type, you can set up a shell alias like `alias zp=zapier-platform`.
## cli
* 📜 Rename binary name from `zapier` to `zapier-platform` in docs, source, and `help` command ([#1291](https://github.com/zapier/zapier-platform/pull/1291), [#1292](https://github.com/zapier/zapier-platform/pull/1292), [#1293](https://github.com/zapier/zapier-platform/pull/1293))
## core
* 🐛 Throw actionable error when app definition fails to load ([#1288](https://github.com/zapier/zapier-platform/pull/1288))
* 🐛 Remove `platformData` from bundle logging ([#1289](https://github.com/zapier/zapier-platform/pull/1289))
## schema
None!

View file

@ -0,0 +1,25 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v18.6.0
> New `invoke auth template` and `invoke auth render` commands for inspecting an app's auth request shape
*Released: 2026-05-05*
This release adds two new commands that let you inspect and render the authentication request your app produces. They run your app's middleware (`beforeRequest`, `getAccessToken`, etc.) with placeholder credentials and capture the resulting auth request shape (headers, query params, and body) without making a real network call.
`zapier-platform invoke auth template` returns the static template (with `{{placeholders}}` for auth fields). `zapier-platform invoke auth render` substitutes real auth data from .env into that template and returns the final request.
## cli
* 🎉 Add `invoke auth template` and `invoke auth render` commands ([#1282](https://github.com/zapier/zapier-platform/pull/1282))
## core
* 🎉 Add `getAuthTemplate` and `renderAuthTemplate` Lambda commands ([#1282](https://github.com/zapier/zapier-platform/pull/1282))
## schema
None!

View file

@ -0,0 +1,31 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v19.0.0
> The `zapier` CLI binary has been removed. Use `zapier-platform` instead.
*Released: 2026-05-18*
Version 19.0.0 is a **BREAKING CHANGE** release. Here is a brief breakdown of the main change (**❗ denotes a breaking change**):
## ❗ The `zapier` binary has been removed
The `zapier` command was deprecated in v18.0.0 in favor of `zapier-platform`. v19 completes that transition by removing the old binary entirely.
***
Apart from this major change, here are the detailed release notes for this release (**note that ❗ denotes a breaking change**):
## cli
* ❗ Remove the `zapier` executable; the CLI now ships only `zapier-platform` ([#1299](https://github.com/zapier/zapier-platform/pull/1299))
## core
None!
## schema
None!

View file

@ -0,0 +1,27 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# What's changed in v19.1.0
> Auth template rendering can honor the real outbound request and custom request properties, plus a fix for the `appTester` type signature
*Released: 2026-07-30*
This release improves auth template extraction and rendering: templates can now honor the real outbound request and integration-specific custom request properties when selecting credentials, non-auth request bodies are kept out of extracted templates, and `z.request(url, options)` calls are handled correctly during extraction. It also fixes the `appTester` TypeScript signature to accept request templates.
## cli
None!
## core
* Thread `targetRequest` through `renderAuthTemplate` so rendering can honor the real outbound request ([#1298](https://github.com/zapier/zapier-platform/pull/1298))
* Support `customRequestProperties` in the `renderAuthTemplate` bundle, letting integration middleware select the right credential during rendering ([#1322](https://github.com/zapier/zapier-platform/pull/1322))
* Drop non-auth request bodies from extracted auth templates ([#1323](https://github.com/zapier/zapier-platform/pull/1323))
* Preserve `z.request(url, options)` options in auth-template request stubs, and honor `customRequestProperties` during template extraction ([#1324](https://github.com/zapier/zapier-platform/pull/1324))
* Support request templates in the `appTester` type signature ([#1302](https://github.com/zapier/zapier-platform/pull/1302))
## schema
None!

View file

@ -0,0 +1,43 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# New platform guardrails for safer integration versioning
> The platform now checks for breaking changes during promotion and guides you toward the correct semantic version, helping protect your users from unexpected disruptions.
*Effective: 2026-05-12*
## What's new
The platform now automatically checks for breaking changes when you [promote](/integrations/manage/promote) a new integration version. If breaking changes are found and the version doesn't increment the major number, promotion is paused with a clear explanation of what was detected and which version number to use instead.
This helps you catch issues **before** they reach users — no more accidentally shipping a removal or auth change under a patch bump.
## What gets checked
When you promote, the platform compares the new version against the current public version at the **schema level** — looking at the structure of your triggers, actions, searches, and authentication. The following schema-level breaking changes are detected automatically:
* **Removed triggers, actions, or searches** — a key present in the current public version is missing in the new version
* **Authentication type change** — the auth type (e.g., `oauth2`, `apiKey`, `session`) differs between versions
* **Trigger type change** — a trigger switched between polling and hook type
* **Removed searchOrCreate keys** — a searchOrCreate present in the current version is missing
* **Removed input field keys** — an input field key on an existing trigger/action was removed
* **Optional input field made required without a default** — an existing optional field is now required but has no default value
* **Authentication field changes** — removing an auth field, adding a new required auth field, or changing an auth field's type
* **Input field type changes** — changing the type of an input field (e.g., `string``list`)
* **Incompatible JSON field schema changes** — backward-incompatible changes to `json`-type input field schemas
If any of these are detected, you'll see a message explaining the specific changes found and the minimum major version required.
<Note>
These checks cover **schema-level** changes only. Some breaking changes happen outside the schema — for example, removing or renaming output field keys, changing the behavior of a perform function, or altering response structures. These are still your responsibility to catch. Review the full [versioning matrix](/integrations/manage/planning-changes) before promoting.
</Note>
## What this means for you
* **If you're already following semver**, nothing changes. You're good.
* **If a promotion is paused**, read the message — it tells you exactly which changes triggered the check and what version number to use. Bump the major version and promote again.
* **If you need to phase out a trigger, action, or search without a major bump**, [hide it](/integrations/manage/versions#what-counts-as-a-breaking-change) instead of removing it. Hidden items continue to work for existing Zap workflows but are no longer available to new users.
For the full list of what gets detected and how to choose the right version number, see [Version numbering](/integrations/manage/versions#version-numbering).

View file

@ -0,0 +1,572 @@
> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zapier.com/llms.txt
> Use this file to discover all available pages before exploring further.
# Platform News (Single Page)
> Recent changelogs and tips on a single page
## What's changed in v19.1.0
*Released: 2026-07-30*
This release improves auth template extraction and rendering: templates can now honor the real outbound request and integration-specific custom request properties when selecting credentials, non-auth request bodies are kept out of extracted templates, and `z.request(url, options)` calls are handled correctly during extraction. It also fixes the `appTester` TypeScript signature to accept request templates.
**cli**
None!
**core**
* Thread `targetRequest` through `renderAuthTemplate` so rendering can honor the real outbound request ([#1298](https://github.com/zapier/zapier-platform/pull/1298))
* Support `customRequestProperties` in the `renderAuthTemplate` bundle, letting integration middleware select the right credential during rendering ([#1322](https://github.com/zapier/zapier-platform/pull/1322))
* Drop non-auth request bodies from extracted auth templates ([#1323](https://github.com/zapier/zapier-platform/pull/1323))
* Preserve `z.request(url, options)` options in auth-template request stubs, and honor `customRequestProperties` during template extraction ([#1324](https://github.com/zapier/zapier-platform/pull/1324))
* Support request templates in the `appTester` type signature ([#1302](https://github.com/zapier/zapier-platform/pull/1302))
**schema**
None!
***
## What's changed in v19.0.0
*Released: 2026-05-18*
Version 19.0.0 is a **BREAKING CHANGE** release. Here is a brief breakdown of the main change (**❗ denotes a breaking change**):
**❗ The `zapier` binary has been removed**
The `zapier` command was deprecated in v18.0.0 in favor of `zapier-platform`. v19 completes that transition by removing the old binary entirely.
***
Apart from this major change, here are the detailed release notes for this release (**note that ❗ denotes a breaking change**):
**cli**
* ❗ Remove the `zapier` executable; the CLI now ships only `zapier-platform` ([#1299](https://github.com/zapier/zapier-platform/pull/1299))
**core**
None!
**schema**
None!
***
## New platform guardrails for safer integration versioning
*Effective: 2026-05-12*
**What's new**
The platform now automatically checks for breaking changes when you [promote](/integrations/manage/promote) a new integration version. If breaking changes are found and the version doesn't increment the major number, promotion is paused with a clear explanation of what was detected and which version number to use instead.
This helps you catch issues **before** they reach users — no more accidentally shipping a removal or auth change under a patch bump.
**What gets checked**
When you promote, the platform compares the new version against the current public version at the **schema level** — looking at the structure of your triggers, actions, searches, and authentication. The following schema-level breaking changes are detected automatically:
* **Removed triggers, actions, or searches** — a key present in the current public version is missing in the new version
* **Authentication type change** — the auth type (e.g., `oauth2`, `apiKey`, `session`) differs between versions
* **Trigger type change** — a trigger switched between polling and hook type
* **Removed searchOrCreate keys** — a searchOrCreate present in the current version is missing
* **Removed input field keys** — an input field key on an existing trigger/action was removed
* **Optional input field made required without a default** — an existing optional field is now required but has no default value
* **Authentication field changes** — removing an auth field, adding a new required auth field, or changing an auth field's type
* **Input field type changes** — changing the type of an input field (e.g., `string``list`)
* **Incompatible JSON field schema changes** — backward-incompatible changes to `json`-type input field schemas
If any of these are detected, you'll see a message explaining the specific changes found and the minimum major version required.
<Note>
These checks cover **schema-level** changes only. Some breaking changes happen outside the schema — for example, removing or renaming output field keys, changing the behavior of a perform function, or altering response structures. These are still your responsibility to catch. Review the full [versioning matrix](/integrations/manage/planning-changes) before promoting.
</Note>
**What this means for you**
* **If you're already following semver**, nothing changes. You're good.
* **If a promotion is paused**, read the message — it tells you exactly which changes triggered the check and what version number to use. Bump the major version and promote again.
* **If you need to phase out a trigger, action, or search without a major bump**, [hide it](/integrations/manage/versions#what-counts-as-a-breaking-change) instead of removing it. Hidden items continue to work for existing Zap workflows but are no longer available to new users.
For the full list of what gets detected and how to choose the right version number, see [Version numbering](/integrations/manage/versions#version-numbering).
***
## What's changed in v18.6.0
*Released: 2026-05-05*
This release adds two new commands that let you inspect and render the authentication request your app produces. They run your app's middleware (`beforeRequest`, `getAccessToken`, etc.) with placeholder credentials and capture the resulting auth request shape (headers, query params, and body) without making a real network call.
`zapier-platform invoke auth template` returns the static template (with `{{placeholders}}` for auth fields). `zapier-platform invoke auth render` substitutes real auth data from .env into that template and returns the final request.
**cli**
* 🎉 Add `invoke auth template` and `invoke auth render` commands ([#1282](https://github.com/zapier/zapier-platform/pull/1282))
**core**
* 🎉 Add `getAuthTemplate` and `renderAuthTemplate` Lambda commands ([#1282](https://github.com/zapier/zapier-platform/pull/1282))
**schema**
None!
***
## What's changed in v18.5.1
*Released: 2026-04-30*
This patch release improves the error message you get when an app definition fails to load, removes `platformData` from the bundle, and finishes the rename of the CLI binary from `zapier` to `zapier-platform` across docs and the `help` command.
We're renaming `zapier` to `zapier-platform` because the `zapier` binary name will be allocated to the [Zapier SDK](https://docs.zapier.com/sdk). The `zapier` binary still works in v18, but in the next major release (v19), we'll officially remove it — you'll need to use `zapier-platform` instead. If `zapier-platform` is too long to type, you can set up a shell alias like `alias zp=zapier-platform`.
**cli**
* 📜 Rename binary name from `zapier` to `zapier-platform` in docs, source, and `help` command ([#1291](https://github.com/zapier/zapier-platform/pull/1291), [#1292](https://github.com/zapier/zapier-platform/pull/1292), [#1293](https://github.com/zapier/zapier-platform/pull/1293))
**core**
* 🐛 Throw actionable error when app definition fails to load ([#1288](https://github.com/zapier/zapier-platform/pull/1288))
* 🐛 Remove `platformData` from bundle logging ([#1289](https://github.com/zapier/zapier-platform/pull/1289))
**schema**
None!
***
## What's changed in v18.5.0
*Released: 2026-04-16*
This release adds line item support to the `zapier-platform invoke` command and bumps `lodash` across all packages to address a security vulnerability.
[Line items](/integrations/build-cli/input-fields#line-items) are fields with a `children` property that represent structured, repeating data — like rows in a spreadsheet or items in an order. The `invoke` command now supports them in both interactive and non-interactive modes:
```bash theme={null}
**Non-interactive: pass line items as JSON**
zapier-platform invoke create order --non-interactive \
-i '{"name": "My Order", "line_items": [{"product_name": "Pens", "quantity": "12", "price": "1.50"}]}'
**Interactive: use the line item editing UI**
zapier-platform invoke create order -i '{"name": "My Order"}'
```
In interactive mode, a sub-menu lets you add, edit, and delete items with per-field editing and required field validation.
**cli**
* 🎉 Add line item support to `invoke` command with interactive editing UI ([#1272](https://github.com/zapier/zapier-platform/pull/1272))
* 🎉 Add `line-items` project template for `zapier-platform init` ([#1272](https://github.com/zapier/zapier-platform/pull/1272))
* 🐛 Fix `invoke` bugs: auto-detect auth ID for no-auth apps in remote mode, falsy value handling (`0`, `false`) causing infinite dropdown re-prompting, and more ([#1272](https://github.com/zapier/zapier-platform/pull/1272))
* 🔨 Bump `lodash` from 4.17.23 to 4.18.1 ([#1274](https://github.com/zapier/zapier-platform/pull/1274))
**core**
* 🔨 Bump `lodash` from 4.17.23 to 4.18.1 ([#1274](https://github.com/zapier/zapier-platform/pull/1274))
**schema**
* 🔨 Bump `lodash` from 4.17.23 to 4.18.1 ([#1274](https://github.com/zapier/zapier-platform/pull/1274))
***
## What's changed in v18.4.0
*Released: 2026-04-06*
This release introduces the new `json` input field type, improved `zapier versions` output, and a schema validation fix.
You can now accept structured JSON input from users with the new [`json` field type](/integrations/build-cli/input-fields#json-fields). Optionally provide a `schema` to validate and describe the expected shape:
```javascript theme={null}
{
key: 'product',
type: 'json',
label: 'Product',
helpText: 'Enter a JSON object',
schema: {
type: 'object',
properties: {
name: { type: 'string' },
price: { type: 'integer' },
},
required: ['name'],
},
}
```
We also fixed a bug where pushing code with [function-based dynamic dropdowns](/integrations/build-cli/dynamic-dropdowns#function-based-dynamic-dropdowns-perform) caused an unexpected validation error on the server. If you want to use function-based dynamic dropdowns, upgrade to 18.4.0 or later:
```javascript theme={null}
{
key: 'project_id',
label: 'Project',
type: 'string',
required: true,
choices: {
perform: async (z, bundle) => {
const response = await z.request('https://api.example.com/projects');
return {
results: response.data.map((project) => ({
id: project.id,
label: project.name,
})),
paging_token: null,
};
},
},
}
```
**cli**
* 💅 Clarify `zapier-platform versions` timestamps with separate "Created at" and "Updated at" columns ([#1275](https://github.com/zapier/zapier-platform/pull/1275))
**core**
* 🎉 Add JSON field type handling with schema-aware TypeScript inference ([#1273](https://github.com/zapier/zapier-platform/pull/1273))
**schema**
* 🎉 Add JSON input field type with optional `schema` property for structured data ([#1265](https://github.com/zapier/zapier-platform/pull/1265))
* 🎉 Validate `schema` property on JSON fields against JSON Schema meta-schema ([#1267](https://github.com/zapier/zapier-platform/pull/1267))
* 🐛 Fix oneOf ambiguity in FieldChoicesSchema that caused server-side validation errors for function-based dynamic dropdowns ([#1268](https://github.com/zapier/zapier-platform/pull/1268))
* 📜 Update `skipThrowForStatus` documentation to note 401 errors are not subject to the flag ([#1270](https://github.com/zapier/zapier-platform/pull/1270))
**misc**
* 🔨 Improve publish workflow with path filters and boilerplate build fixes ([#1264](https://github.com/zapier/zapier-platform/pull/1264), [#1266](https://github.com/zapier/zapier-platform/pull/1266))
***
## What's changed in v18.3.0
*Released: 2026-03-12*
Add support for function-based dynamic dropdowns
**cli**
* 🎉 Add support for function-based dynamic dropdown to the invoke command ([#1206](https://github.com/zapier/zapier-platform/pull/1206))
**core**
None!
**schema**
* 🎉 Add FieldDynamicChoicesSchema for function-based dynamic dropdowns ([#1206](https://github.com/zapier/zapier-platform/pull/1206))
***
## What's changed in v18.2.3
*Released: 2026-03-04*
Bug fixes for the CLI build command and pnpm compatibility.
**cli**
* 🐛 Surface package manager errors in `build` command ([#1254](https://github.com/zapier/zapier-platform/pull/1254))
**core**
* 🐛 Declare `zapier-platform-legacy-scripting-runner` as an optional peer dep to fix pnpm strict module resolution ([#1255](https://github.com/zapier/zapier-platform/pull/1255))
**schema**
None!
***
## What's changed in v18.2.2
*Released: 2026-02-26*
Improved error handling when loading the legacy-scripting-runner module in core. The runtime now logs a warning with the actual error message when the module is installed but fails to load, making it easier to diagnose issues like missing transitive dependencies.
**cli**
None!
**core**
* 🐛 Log a warning when `zapier-platform-legacy-scripting-runner` is installed but fails to load, instead of silently returning null ([#1247](https://github.com/zapier/zapier-platform/pull/1247))
**schema**
None!
**misc**
* 🔨 Fix publishing workflow to run on pushes to `main` ([#1243](https://github.com/zapier/zapier-platform/pull/1243))
* 🔨 Add non-interactive mode to bump script ([#1249](https://github.com/zapier/zapier-platform/pull/1249))
***
## User migrations must stay within the same major version
*Effective: 2026-02-26*
**Same-major-version migrations only**
* Migrations are only allowed when the **from** and **to** versions share the same major number (e.g. `1.0.0``1.0.1`, or `2.1.0``2.2.0`).
* Cross-major moves (e.g. `1.5.0``2.0.0`) are blocked in both the [Platform UI](https://zapier.com/app/developer) and via [`zapier-platform migrate`](https://github.com/zapier/zapier-platform/blob/main/packages/cli/docs/cli.md#migrate). This aligns with long-standing guidance; major releases include [breaking changes](/integrations/manage/planning-changes), so users should [update Zap workflows manually](https://help.zapier.com/hc/en-us/articles/18755649454989-App-versions-in-Zapier) or you should use [deprecation](/integrations/manage/versions#deprecating-versions) instead of migration.
* Details and workflow are in [Migrate users to a new version](/integrations/manage/migrate).
***
## What's changed in v18.2.1
*Released: 2026-02-23*
Resolved a bug in the CLI that caused the `build` command to fail when using a symlink-based package manager (like pnpm).
**cli**
* 🐛 `zapier-platform build` no longer raises `EEXIST` when using a symlink-based package manager ([#1244](https://github.com/zapier/zapier-platform/pull/1244))
**core**
None!
**schema**
None!
***
## Pushing unlabelled semantic versions must be sequential
*Effective: 2026-02-23*
**What changed**
These rules apply to **unlabelled** [semantic versions](/integrations/manage/versions#version-numbering) only (for example `1.2.3`). **[Labelled versions](/integrations/manage/labeled-versions)** (such as `1.2.3-beta` or `0.0.0-my-feature`) are not part of these checks.
When you push a new unlabelled version, the platform validates **two** things in addition to existing format checks.
**1. You cannot skip a required predecessor**
The API must see the right **previous** unlabelled release before it accepts the new one:
* **Patch bump** (`1.2.3`): the exact unlabelled `1.2.2` must already exist.
* **Minor bump** (`1.3.0`): at least one unlabelled `1.2.x` must exist.
* **Major bump** (`2.0.0` when coming from `1.x`): at least one unlabelled `1.x.x` must exist.
`1.0.0` is unchanged: there is no prior semver to require.
If the predecessor is missing, push fails with **403** and guidance like: *Version X requires Y to exist. Push version Y, then try again.*
**2. You cannot insert an “intermediate” version behind a newer line**
You also cannot push a version if a **newer** unlabelled version already exists in the segment that would make yours a backward insert:
* **`1.2.3`**: blocked if any unlabelled **`1.2.4` or higher** on the same `1.2.*` line already exists. Pushing **`1.3.0`** is still allowed when only `1.3.x` or `2.x.x` exists—those are not on the `1.2.*` patch line.
* **`1.3.0`**: blocked if any unlabelled **`1.4.x` or higher** on the same major (`1.*`) already exists. **`2.0.0`** is still allowed when only `2.x.x` exists.
* **`2.0.0`**: blocked if any unlabelled **`3.x.x` or higher** already exists.
If that applies, push fails with **403** and a message that an existing version would make this an intermediate release, which is not allowed.
**What this means for you**
* Plan **patch → patch → minor → major** (or the minimal chain your history needs) using **unlabelled** semver when you are ready to record real releases; use **labelled** snapshots while iterating.
* If you are stuck because old versions were removed, you may still use **[deprecation](/integrations/manage/versions#deprecating-versions)** and, when appropriate, **[delete a deprecated version](/integrations/manage/deprecate#deleting-deprecated-versions)** so your remaining unlabelled history matches what you want to push next.
***
## What's changed in v18.2.0
*Released: 2026-02-18*
The main change in this release is to support function-based choices in the `invoke` command, which will allow developers to test perform-based dynamic dropdowns.
**cli**
* 🎉 `zapier-platform invoke` now supports function-based choices ([#1237](https://github.com/zapier/zapier-platform/pull/1237))
**core**
* 🐛 If we attempt to stash a large response but it's bigger than the max limit, throw a descriptive error with the actual size and the limit ([#1238](https://github.com/zapier/zapier-platform/pull/1238))
* 🔨 Add an environment variable to allow suppressing cleaning up env vars ([#1242](https://github.com/zapier/zapier-platform/pull/1242))
**schema**
None!
**misc**
* 🔨 CI: Use `environment` to publish ([#1239](https://github.com/zapier/zapier-platform/pull/1239))
* 🔨 CI: Automate the boilerplate upload ([#1240](https://github.com/zapier/zapier-platform/pull/1240))
***
## What's changed in v18.1.1
*Released: 2026-01-29*
Main change introduced here is fixing missing HTTP error logs that were prematurely lost during a Lambda invocation.
**cli**
None!
**core**
* 🐛 Restore missing HTTP error logs ([#1227](https://github.com/zapier/zapier-platform/pull/1227))
**schema**
None!
**misc**
* 🔨 Bump lodash from 4.17.21 to 4.17.23 across the board ([#1228](https://github.com/zapier/zapier-platform/pull/1228), [#1229](https://github.com/zapier/zapier-platform/pull/1229), [#1230](https://github.com/zapier/zapier-platform/pull/1230), [#1231](https://github.com/zapier/zapier-platform/pull/1231), [#1233](https://github.com/zapier/zapier-platform/pull/1233), [#1234](https://github.com/zapier/zapier-platform/pull/1234), [#1235](https://github.com/zapier/zapier-platform/pull/1235))
***
## What's changed in v18.1.0
*Released: 2026-01-19*
The `zapier-platform invoke` command now supports a **remote mode**. By adding a `--remote` (`-r` for short) flag to the `invoke` command, such as:
```
zapier-platform invoke -r
```
... all invocations, including trigger/action invocation itself, input field definitions, and dynamic dropdown choices, will be executed remotely by the Zapier production environment. This means:
* The integration version you want to test has to be deployed first.
* The invocation results and the bundle payload passed to your integration code will match what you see in live production, which is great for testing.
* Remote mode is slower than local mode (without the `-r` flag).
Read more about the three different modes in the [`zapier-platform invoke --help`](https://github.com/zapier/zapier-platform/blob/main/packages/cli/docs/cli.md#invoke) documentation.
We also fixed an issue where the `build` and `test` commands were not correctly detecting package managers (like npm, yarn, pnpm, or bun) when your integration was part of a monorepo. Now, the CLI doesn't just look in the current directory for package manager indicators (like `package-lock.json` for npm), but also checks parent directories up to four levels up.
**cli**
* 🎉 Add `--remote` flag to `invoke` command ([#1220](https://github.com/zapier/zapier-platform/pull/1220))
* 🐛 Fix package manager detection in `build` and `test` commands to include parent directories ([#1225](https://github.com/zapier/zapier-platform/pull/1225))
**core**
None!
**schema**
None!
**misc**
* 📜 Improve internal development docs ([#1221](https://github.com/zapier/zapier-platform/pull/1221))
***
## What's changed in v18.0.7
*Released: 2026-01-07*
In response to the previous [Shai-Hulud incident](/integrations/build-cli/inc-547), we're changing our package publishing process to improve security. This release also includes a schema extension that allows `outputFields` to have a `sample` field. Lastly, we've refactored the `invoke` command to make upcoming enhancements easier.
**cli**
* 🔨 Refactor `invoke` command ([#1217](https://github.com/zapier/zapier-platform/pull/1217))
**core**
None!
**schema**
* 🎉 Allow a `sample` field to be provided for dynamic `outputFields` ([#1211](https://github.com/zapier/zapier-platform/pull/1211))
**misc**
* 🔨 Add publish job in CI ([#1212](https://github.com/zapier/zapier-platform/pull/1212), [#1223](https://github.com/zapier/zapier-platform/pull/1223))
***
## What's changed in v18.0.6
*Released: 2025-12-24*
The `zapier build` command was harcoded to use `npm install`. As alternate package managers gain adoption, the `zapier build` command will respect your app's package manager of choice.
It does this by checking the `packageManager` on the package.json file. If it is not defined, it will look for any relevant lock files. If still, none is defined, then will fallback to `npm`.
If you are familiar with using `zapier build` with the flag `--skip-npm-install`, this flag has been renamed to `--skip-dep-install`, but will continue to still work as an alias. In the future, we will remove the `--skip-npm-install` flag.
**cli**
* 💅 CLI build respects the integration's package manager ([#1216](https://github.com/zapier/zapier-platform/pull/1216))
**core**
None!
**schema**
None!
**misc**
* 🔨 Bump tmp from 0.2.4 to 0.2.5 ([#1207](https://github.com/zapier/zapier-platform/pull/1207))
* 🔨 Bump form-data from 4.0.4 to 4.0.5 ([#1208](https://github.com/zapier/zapier-platform/pull/1208))
***
## What's changed in v18.0.5
*Released: 2025-12-10*
<Info>
We're releasing v18.0.5, skipping comprimised versions v18.0.2, v18.0.3, and
v18.0.4, due to the prior [security
incident](/integrations/news/2025/npm-package-sec-inc).
</Info>
This release fixes a potential security vulnerability in the `build` command related to zip file decompression.
**cli**
* 🐛 Remove problematic decompress-tar dependency ([#1202](https://github.com/zapier/zapier-platform/pull/1202))
**core**
None!
**schema**
None!
**misc**
* 🔨 Switch to pnpm as package manager and task runner ([#1204](https://github.com/zapier/zapier-platform/pull/1204))
***
## Incident: Unauthorized Access to Zapier NPM Packages
*Released: 2025-11-24*
**Unauthorized Access to Zapier npm Packages**
**Note: No action is needed from Zapier users**, only from Zapier developers using one of the NPM package versions listed [on this page](/integrations/build-cli/inc-547). See that link for detailed mitigation recommendations.
All Zapier products are operating as expected and there is no indication of data loss or leak.
Please [see this link](https://status.zapier.com/incidents/01KAV9DDHMYT7R6MFHSB8C09E3#updates) for the most up-to-date information.
***
Looking for older news? [2026](/integrations/news/2026), [2025](/integrations/news/2025), and [old changelogs prior to v17](https://github.com/zapier/zapier-platform/tree/main/changelog)