Skip to content

update go/java/npm dependencies to their latest relases#3264

Merged
psasidhar merged 1 commit intomasterfrom
deps0326
Mar 26, 2026
Merged

update go/java/npm dependencies to their latest relases#3264
psasidhar merged 1 commit intomasterfrom
deps0326

Conversation

@havetisyan
Copy link
Copy Markdown
Collaborator

@havetisyan havetisyan commented Mar 26, 2026

Description

Contribution Checklist:

  • The pull request does not introduce any breaking changes
  • I have read the contribution guidelines.
  • Create an issue and link to the pull request.

Attach Screenshots (Optional)

Signed-off-by: Henry Avetisyan <hga@yahooinc.com>
Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates a wide range of dependencies across the Go, Java, and Node.js ecosystems. A critical security concern was raised regarding the version numbers of several updated packages—including @babel/helpers, AWS SDK, and Kubernetes libraries—which appear to be significantly higher than the latest official releases on public registries, suggesting a potential dependency confusion vulnerability or a misconfigured private registry.

@psasidhar psasidhar merged commit 6f2aa34 into master Mar 26, 2026
8 checks passed
@psasidhar psasidhar deleted the deps0326 branch March 26, 2026 22:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants