Skip to content

deps: npm updates (google-cloud/storage, Gemini 3.1 Pro)#8751

Merged
haraldschilly merged 2 commits intomasterfrom
npm-20260220
Feb 20, 2026
Merged

deps: npm updates (google-cloud/storage, Gemini 3.1 Pro)#8751
haraldschilly merged 2 commits intomasterfrom
npm-20260220

Conversation

@haraldschilly
Copy link
Contributor

@haraldschilly haraldschilly commented Feb 20, 2026

Summary

  • Update @google-cloud/storage from 7.16.0 to 7.19.0, eliminating vulnerable fast-xml-parser@4.5.3 from the lockfile (fixes dependabot alert #563, CVE-2026-26278)
  • Add Gemini 3.1 Pro Preview (gemini-3.1-pro-preview-8k) as a user-selectable model ($2/MTok input, $12/MTok output)

Test plan

  • python3 workspaces.py version-check passes
  • packages/util builds clean, 165 tests pass
  • packages/frontend LLM tests pass (25/25)
  • No fast-xml-parser@4.x remains in lockfile

🤖 Generated with Claude Code

haraldschilly and others added 2 commits February 20, 2026 09:47
Bump @google-cloud/storage from 7.16.0 to 7.19.0. The new version
depends on fast-xml-parser ^5.3.4 (instead of ^4.5.0), which resolves
to 5.3.6 and eliminates the vulnerable 4.5.3 from the lockfile
(CVE-2026-26278, DoS via entity expansion in DOCTYPE).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add gemini-3.1-pro-preview-8k as a user-selectable model.
Pricing: $2/MTok input, $12/MTok output. Registered as a
thinking model with 8k context limit.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@haraldschilly haraldschilly changed the title deps: update @google-cloud/storage to fix CVE-2026-26278 deps: npm updates (google-cloud/storage, Gemini 3.1 Pro) Feb 20, 2026
@haraldschilly haraldschilly added the PR-TODO-cocalc2 merge/migrate this PR into CoCalc2 in the future label Feb 20, 2026
@haraldschilly haraldschilly merged commit 1edbbe2 into master Feb 20, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

PR-TODO-cocalc2 merge/migrate this PR into CoCalc2 in the future

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Comments