chore: resolve open dependabot security alerts - #1450
Conversation
…g-library peers Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
93ccb16 to
10a3576
Compare
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
Dependabot Alerts Resolved
esbuildng-packagr21.2.5 -> 21.2.7 (lockfile-only, within existing^21.0.0range), which dedupesesbuildto 0.28.1Not resolved
uuid(transitive, dev-only)jest-cucumber@4.5.0(latest) pins@cucumber/gherkin@^28.0.0, whose accepted@cucumber/messagesrange (<=28) tops out at@cucumber/messages@28.1.0, which itself pins an exactuuid@11.1.0(one patch short of the fixed11.1.1).jest-cucumberalso directly pinsuuid@^10.0.0. No newerjest-cucumberrelease exists. Per repo policy this SDK does not useoverrides/resolutions. The advisory (GHSA-w5hq-g745-h8pq) only applies when callers pass an external output buffer touuidv3/v5/v6, which is not how it is used here (dev/test-only, transitive). Left open pending ajest-cucumberupstream update.