Skip to content

CDP-5757: Bump third-party dependencies#181

Merged
richdawe-cio merged 6 commits into
mainfrom
cdp-5757-bump-some-deps
May 14, 2026
Merged

CDP-5757: Bump third-party dependencies#181
richdawe-cio merged 6 commits into
mainfrom
cdp-5757-bump-some-deps

Conversation

@richdawe-cio
Copy link
Copy Markdown
Contributor

@richdawe-cio richdawe-cio commented May 13, 2026

Bump the following third-party dependencies that we use for development. This updates a number of dependencies to resolve known security issues.

  • ava
  • nyc
  • pretty-quick
  • sinon
  • @types/sinon

Also:

  • Add a mise configuration to help with local development.
  • Update examples/getCustomerByEmail.js to print the search results.

Note

Low Risk
Low risk: adds local toolchain config and adjusts an example script to log async results, with no production/library logic changes.

Overview
Adds .mise.toml to standardize local tooling (enables mise experimental mode and pins Node to 22.22.0).

Updates examples/getCustomerByEmail.js to use consistent quoting/semicolons and to handle the getCustomersByEmail promise by logging the returned result.

Reviewed by Cursor Bugbot for commit 685fa07. Bugbot is set up for automated code reviews on this repo. Configure here.

@socket-security
Copy link
Copy Markdown

socket-security Bot commented May 13, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedsinon@​14.0.0 ⏵ 17.0.2100 +110098 -250100
Updated@​types/​sinon@​10.0.11 ⏵ 17.0.4100 +11007684100
Updatednyc@​15.1.0 ⏵ 18.0.097 +110010084100
Updatedpretty-quick@​3.1.3 ⏵ 3.3.199 +1100100 +186100
Updatedava@​5.0.1 ⏵ 5.3.198 +110010088 -1100

View full report

@richdawe-cio richdawe-cio merged commit 09c1592 into main May 14, 2026
9 checks passed
@richdawe-cio richdawe-cio deleted the cdp-5757-bump-some-deps branch May 14, 2026 12:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants