Skip to content

chore: resolve open dependabot security alerts#180

Draft
jonathannorris wants to merge 1 commit into
mainfrom
chore/dependabot-alerts
Draft

chore: resolve open dependabot security alerts#180
jonathannorris wants to merge 1 commit into
mainfrom
chore/dependabot-alerts

Conversation

@jonathannorris
Copy link
Copy Markdown
Member

Summary

  • Resolved 6 open Dependabot security alerts by bumping vulnerable dependencies across affected provider lockfiles.

Dependabot Alerts Resolved

Alert Package Manifest Severity Fix
#41 faraday providers/openfeature-go-feature-flag-provider/Gemfile.lock low Bumped 2.14.1 to 2.14.2
#40 faraday providers/openfeature-ofrep-provider/Gemfile.lock low Bumped 2.14.1 to 2.14.2
#39 faraday providers/openfeature-flagsmith-provider/Gemfile.lock low Bumped 2.14.1 to 2.14.2
#35 addressable providers/openfeature-flagsmith-provider/Gemfile.lock high Bumped 2.8.9 to 2.9.0
#34 addressable providers/openfeature-go-feature-flag-provider/Gemfile.lock high Bumped 2.8.7 to 2.9.0
#29 json providers/openfeature-meta_provider/Gemfile.lock high Bumped 2.19.0 to 2.19.7

Verification

  • bundle exec rake (lint + RSpec) passes on each affected provider: go-feature-flag (82 examples), ofrep (44 examples), flagsmith (89 examples), meta_provider (58 examples).

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates several dependency versions across multiple Gemfile.lock files for various OpenFeature providers, including openfeature-flagsmith-provider, openfeature-go-feature-flag-provider, openfeature-meta_provider, and openfeature-ofrep-provider. Specifically, it bumps versions for dependencies such as addressable, faraday, faraday-net_http, json, and public_suffix. There are no review comments, and I have no feedback to provide.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants