Skip to content

chore(deps): security bumps + in-range lockfile refresh - #704

Merged
B4nan merged 1 commit into
masterfrom
chore/deps-sweep
Sep 7, 2026
Merged

B4nan merged 1 commit into
masterfrom
chore/deps-sweep

Conversation

@apify-deps

@apify-deps apify-deps Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Summary

Dependency sweep — security bumps + in-range freshening (all within existing ranges):

  • fast-uri → 3.1.7 (high) — fixes 4 alerts, all ranges collapsing to the same patched floor
  • postcss-selector-parser → 7.1.6 (low)
  • zod ^4.0.0 → ^4.5.4 (direct dep range bump in input_secrets/validations, expected side effect of the in-range refresh)

🚩 Flagged — needs review

  • Existing overrides esbuild: ^0.28.1, tar: ^7.5.16, js-yaml@4: ^4.2.0 in pnpm-workspace.yaml — audited for staleness. None are no-ops: removing any of them lets an older (but not currently alerted, and no historical alert found either) version back in for a specific consumer (tsx``'s esbuild@0.27.7, an npm-tooling dep's tar@7.5.11vialerna, and lerna's own js-yaml@4.1.1`). Since there's no open or past Dependabot alert to confirm these floors are security-motivated, I couldn't confidently call dropping them safe — left all three in place pending a human check of why they were added.

🤖 Generated with Claude Code

@apify-deps apify-deps Bot added the adhoc Ad-hoc unplanned task added during the sprint. label Sep 7, 2026
@apify-deps
apify-deps Bot requested a review from B4nan September 7, 2026 01:17
@B4nan
B4nan merged commit e471394 into master Sep 7, 2026
9 checks passed
@B4nan
B4nan deleted the chore/deps-sweep branch September 7, 2026 09:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

adhoc Ad-hoc unplanned task added during the sprint.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants