Skip to content

Bump transitive dependencies to clear npm audit findings - #2430

Open
MarceloRGonc wants to merge 6 commits into
mainfrom
dependabot/audit
Open

Bump transitive dependencies to clear npm audit findings#2430
MarceloRGonc wants to merge 6 commits into
mainfrom
dependabot/audit

Conversation

@MarceloRGonc

@MarceloRGonc MarceloRGonc commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Fixes OPS-4714.

Copilot AI lite review requested due to automatic review settings August 10, 2026 13:25

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates transitive npm dependencies (Dependabot/audit-style lockfile refresh) and bumps the pinned commit SHA for the automated PR reviewer GitHub Action, keeping the repo’s dependency tree and CI automation up to date.

Changes:

  • Bump @ai-sdk/* / ai transitive versions under @assistant-ui/react-ai-sdk, introducing undici as a new transitive dependency.
  • Refresh multiple transitive packages to patched versions (e.g., brace-expansion, js-yaml, @fastify/static).
  • Update .github/workflows/pr-reviewer.yml to use a newer pinned commit of anthropics/claude-code-action (still pinned by SHA).

Blocking

None

Non-blocking

None

Merge recommendation

Ready to merge

Reviewed changes

Copilot reviewed 2 out of 3 changed files in this pull request and generated no comments.

File Description
package-lock.json Updates locked dependency versions for security/patch refreshes (including new transitive undici).
.github/workflows/pr-reviewer.yml Updates the pinned commit SHA for the PR reviewer action execution.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@linear

linear Bot commented Aug 10, 2026

Copy link
Copy Markdown

OPS-4714

@MarceloRGonc MarceloRGonc changed the title Dependabot/audit Bump transitive dependencies to clear npm audit findings Aug 10, 2026
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants