Skip to content

Conversation

@RomneyDa
Copy link
Collaborator

@RomneyDa RomneyDa commented Nov 21, 2025

Description


Summary by cubic

Update vulnerable dependencies flagged by Snyk in the VS Code extension and GUI to address security issues. No functional changes.

  • Dependencies
    • VS Code extension: systeminformation → ^5.27.11, google-auth-library → ^10.4.1, puppeteer → ^24.15.0, zod → ^3.25.76.
    • GUI: @tiptap/core/document/dropcursor → ^2.27.0, posthog-js → ^1.281.x, yaml → ^2.8.x, plus matching google-auth-library, puppeteer, and zod bumps.
    • Lockfiles updated accordingly; no migration steps.

Written for commit 8b5802d. Summary will update automatically on new commits.

@RomneyDa RomneyDa requested a review from a team as a code owner November 21, 2025 21:09
@RomneyDa RomneyDa requested review from Patrick-Erichsen and removed request for a team November 21, 2025 21:09
@dosubot dosubot bot added the size:S This PR changes 10-29 lines, ignoring generated files. label Nov 21, 2025
@github-actions
Copy link

github-actions bot commented Nov 21, 2025

✅ Review Complete

Code Review Summary

⚠️ Continue configuration error. Please verify that the assistant exists in Continue Hub.


Copy link
Contributor

@cubic-dev-ai cubic-dev-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 4 files

@github-project-automation github-project-automation bot moved this from Todo to In Progress in Issues and PRs Nov 21, 2025
@dosubot dosubot bot added the lgtm This PR has been approved by a maintainer label Nov 21, 2025
@RomneyDa RomneyDa merged commit 159eaea into main Nov 22, 2025
58 of 60 checks passed
@RomneyDa RomneyDa deleted the dallin/package-bumps-snyk-2 branch November 22, 2025 00:25
@github-project-automation github-project-automation bot moved this from In Progress to Done in Issues and PRs Nov 22, 2025
@github-actions github-actions bot locked and limited conversation to collaborators Nov 22, 2025
@sestinj
Copy link
Contributor

sestinj commented Nov 25, 2025

🎉 This PR is included in version 1.6.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@sestinj
Copy link
Contributor

sestinj commented Nov 26, 2025

🎉 This PR is included in version 1.36.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@sestinj
Copy link
Contributor

sestinj commented Dec 4, 2025

🎉 This PR is included in version 1.7.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

lgtm This PR has been approved by a maintainer released size:S This PR changes 10-29 lines, ignoring generated files.

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

4 participants