Skip to content

Update vulnerable dependencies#12899

Merged
steven-sheehy merged 2 commits intomainfrom
vulnerable-dependencies
Feb 5, 2026
Merged

Update vulnerable dependencies#12899
steven-sheehy merged 2 commits intomainfrom
vulnerable-dependencies

Conversation

@steven-sheehy
Copy link
Contributor

@steven-sheehy steven-sheehy commented Feb 4, 2026

Description:

  • Bump Assertj from 3.27.6 to 3.27.7
  • Bump bats image from 1.11.1 to 1.13.0
  • Bump @aws-sdk/client-s3 from 3.980.0 to 3.983.0 to fix vulnerable fast-xml-parser
  • Bump send from 0.18.0 to 0.19.2
  • Exclude swagger-parser-v2-converter due to vulnerable rhino dependency
  • Exclude vertx everywhere except monitor where it's required for tests
  • Fix Redis warning ERR wrong number of arguments for 'mset' command

Related issue(s):

Notes for reviewer:

Checklist

  • Documented (Code comments, README, etc.)
  • Tested (unit, integration, etc.)

Signed-off-by: Steven Sheehy <steven.sheehy@swirldslabs.com>
@steven-sheehy steven-sheehy added this to the 0.148.0 milestone Feb 4, 2026
@steven-sheehy steven-sheehy self-assigned this Feb 4, 2026
@steven-sheehy steven-sheehy added security dependencies Type: Pull requests that update a dependency file labels Feb 4, 2026
@lfdt-bot
Copy link

lfdt-bot commented Feb 4, 2026

Snyk checks have passed. No issues have been found so far.

Status Scanner Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Signed-off-by: Steven Sheehy <steven.sheehy@swirldslabs.com>
@steven-sheehy steven-sheehy marked this pull request as ready for review February 4, 2026 23:31
@steven-sheehy steven-sheehy requested a review from a team as a code owner February 4, 2026 23:31
@codacy-production
Copy link

codacy-production bot commented Feb 4, 2026

Coverage summary from Codacy

See diff coverage on Codacy

Coverage variation Diff coverage
-39.25% (target: -1.00%) 100.00%
Coverage variation details
Coverable lines Covered lines Coverage
Common ancestor commit (549fea3) 27271 25605 93.89%
Head commit (406576a) 52794 (+25523) 28848 (+3243) 54.64% (-39.25%)

Coverage variation is the difference between the coverage for the head and common ancestor commits of the pull request branch: <coverage of head commit> - <coverage of common ancestor commit>

Diff coverage details
Coverable lines Covered lines Diff coverage
Pull request (#12899) 2 2 100.00%

Diff coverage is the percentage of lines that are covered by tests out of the coverable lines that the pull request added or modified: <covered lines added or modified>/<coverable lines added or modified> * 100%

See your quality gate settings    Change summary preferences

@steven-sheehy steven-sheehy merged commit 6340293 into main Feb 5, 2026
37 of 39 checks passed
@steven-sheehy steven-sheehy deleted the vulnerable-dependencies branch February 5, 2026 00:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Type: Pull requests that update a dependency file security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants