Skip to content

chore(deps): bump undici and brace-expansion to clear Dependabot alerts - #53

Merged
JosephSamirL merged 1 commit into
mainfrom
feat/ruby-sdk-dependabot-alerts
Oct 1, 2026
Merged

JosephSamirL merged 1 commit into
mainfrom
feat/ruby-sdk-dependabot-alerts

Conversation

@abbaseya

Copy link
Copy Markdown
Collaborator

Clears all 8 open Dependabot alerts. All 8 are transitive dev dependencies in yarn.lock, used only by the release tooling. The published gem keeps zero runtime dependencies.

lockfile entry before after alerts
undici@npm:^6.23.0, undici@npm:^6.25.0 6.28.0 6.29.0 #30
undici@npm:^7.0.0 7.29.0 7.30.0 #23, #24 (high), #25, #26, #31, #32
brace-expansion@npm:^5.0.8 5.0.9 5.0.12 #35

How

yarn up -R undici brace-expansion, as in #47. Each patched version is inside a range the lockfile already declares. So there is no resolutions override, and package.json and .yarnrc.yml are unchanged. All three versions are older than the npmMinimalAgeGate of 3 days.

This supersedes #52, which bumps only the undici 6.x line.

Verified locally at a971ad3

Check Result
yarn install --immutable (the release.yml install step) passes
yarn release:dry-run loads every plugin, then stops off main as expected
RuboCop 103 files, no offenses
rbs validate + steep check clean
Full RSpec suite 1477 examples, 0 failures, line coverage 98.11%
Cross-SDK parity (spec/cross_sdk) 274 examples, 0 failures
Full-chain release gate 9 examples, 0 failures
gem build / install / require require OK

🤖 Generated with Claude Code

Lockfile-only bump with `yarn up -R`. Every patched version is inside a
range the lockfile already declares, so no `resolutions` override is needed.

- undici 6.28.0 -> 6.29.0 (alert #30)
- undici 7.29.0 -> 7.30.0 (alerts #23, #24, #25, #26, #31, #32)
- brace-expansion 5.0.9 -> 5.0.12 (alert #35)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@JosephSamirL JosephSamirL left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved via /approve. An independent code review ran through /review, and this issues the B-G4 human marker at a971ad3.

@JosephSamirL
JosephSamirL merged commit f421a19 into main Oct 1, 2026
18 checks passed
@JosephSamirL
JosephSamirL deleted the feat/ruby-sdk-dependabot-alerts branch October 1, 2026 10:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants