Skip to content

chore: update dependency#207

Merged
beeme1mr merged 1 commit into
open-feature:mainfrom
Arhell:dep
Aug 17, 2023
Merged

chore: update dependency#207
beeme1mr merged 1 commit into
open-feature:mainfrom
Arhell:dep

Conversation

@Arhell
Copy link
Copy Markdown
Member

@Arhell Arhell commented Aug 16, 2023

This PR

  • adds this new feature

Related Issues

Fixes #205

Notes

Follow-up Tasks

How to test

Signed-off-by: Arhell <arhell333@gmail.com>
@netlify
Copy link
Copy Markdown

netlify Bot commented Aug 16, 2023

Deploy Preview for openfeature ready!

Name Link
🔨 Latest commit e27e338
🔍 Latest deploy log https://app.netlify.com/sites/openfeature/deploys/64dd416289e14d000886b6e9
😎 Deploy Preview https://deploy-preview-207--openfeature.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

@beeme1mr beeme1mr merged commit a9544a1 into open-feature:main Aug 17, 2023
@Arhell Arhell deleted the dep branch August 17, 2023 18:08
jonathannorris added a commit that referenced this pull request May 11, 2026
- fast-uri >=3.1.2 via resolution (high, alerts #206 and #207)
- @babel/plugin-transform-modules-systemjs >=7.29.4 via resolution (high, alert #208)

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
jonathannorris added a commit that referenced this pull request May 12, 2026
- fast-uri >=3.1.2 via resolution (high, alerts #206 and #207)
- @babel/plugin-transform-modules-systemjs >=7.29.4 via resolution (high, alert #208)

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
pull Bot pushed a commit to ClariNerd617/openfeature.dev that referenced this pull request May 13, 2026
## Summary

- Resolved open Dependabot security alerts by updating the direct
`postcss` dependency and adding resolutions to pin transitive
dependencies to patched versions.

Note: alert open-feature#80 (`tsup` DOM clobbering, low) has no patched version
available and is skipped. Alerts open-feature#108 and open-feature#104 (mermaid) are already
fixed by the direct `mermaid@11.10.0` dependency. Alerts open-feature#204 and open-feature#205
(fast-xml-builder) are already fixed by the `fast-xml-parser: ^5.7.0`
resolution pulling in `fast-xml-builder@1.2.0`.

## Dependabot Alerts Resolved

| Alert | Package | Severity | Fix |
|-------|---------|----------|-----|
| open-feature#208 | `@babel/plugin-transform-modules-systemjs` | **high** | Pinned
to >=7.29.4 via resolutions |
| open-feature#207 | `fast-uri` | **high** | Pinned to >=3.1.2 via resolutions |
| open-feature#206 | `fast-uri` | **high** | Pinned to >=3.1.2 via resolutions |
| open-feature#205 | `fast-xml-builder` | **high** | Already fixed via
`fast-xml-parser: ^5.7.0` resolution |
| open-feature#204 | `fast-xml-builder` | **medium** | Already fixed via
`fast-xml-parser: ^5.7.0` resolution |
| open-feature#203 | `ip-address` | **medium** | Pinned to >=10.1.1 via resolutions
|
| open-feature#202 | `postcss` | **medium** | Bumped direct dep to ^8.5.10; forced
via resolutions |
| open-feature#131 | `webpack` | **low** | Pinned to 5.99.9 via resolutions |
| open-feature#130 | `webpack` | **low** | Pinned to 5.99.9 via resolutions |
| open-feature#113 | `js-yaml` | **medium** | Scoped to markdownlint-cli2/js-yaml:
>=4.1.1 via resolutions |

---------

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

update dependency

2 participants