Skip to content

chore: update dependency#208

Merged
beeme1mr merged 5 commits into
open-feature:mainfrom
Arhell:dep
Sep 5, 2023
Merged

chore: update dependency#208
beeme1mr merged 5 commits into
open-feature:mainfrom
Arhell:dep

Conversation

@Arhell
Copy link
Copy Markdown
Member

@Arhell Arhell commented Aug 17, 2023

This PR

  • adds this new feature

Related Issues

Fixes #1234523

Notes

Follow-up Tasks

How to test

Signed-off-by: Arhell <arhell333@gmail.com>
@netlify
Copy link
Copy Markdown

netlify Bot commented Aug 17, 2023

Deploy Preview for openfeature ready!

Name Link
🔨 Latest commit 89d14a1
🔍 Latest deploy log https://app.netlify.com/sites/openfeature/deploys/64f7680941c39e0008ff2737
😎 Deploy Preview https://deploy-preview-208--openfeature.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

Copy link
Copy Markdown
Member Author

@Arhell Arhell left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

beeme1mr and others added 4 commits August 23, 2023 14:07
Signed-off-by: Arhell <arhell333@gmail.com>
Signed-off-by: Arhell <arhell333@gmail.com>
@beeme1mr beeme1mr merged commit 0421fb0 into open-feature:main Sep 5, 2023
@Arhell Arhell deleted the dep branch September 5, 2023 18:03
jonathannorris added a commit that referenced this pull request May 11, 2026
- fast-uri >=3.1.2 via resolution (high, alerts #206 and #207)
- @babel/plugin-transform-modules-systemjs >=7.29.4 via resolution (high, alert #208)

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
jonathannorris added a commit that referenced this pull request May 12, 2026
- fast-uri >=3.1.2 via resolution (high, alerts #206 and #207)
- @babel/plugin-transform-modules-systemjs >=7.29.4 via resolution (high, alert #208)

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
pull Bot pushed a commit to ClariNerd617/openfeature.dev that referenced this pull request May 13, 2026
## Summary

- Resolved open Dependabot security alerts by updating the direct
`postcss` dependency and adding resolutions to pin transitive
dependencies to patched versions.

Note: alert open-feature#80 (`tsup` DOM clobbering, low) has no patched version
available and is skipped. Alerts open-feature#108 and open-feature#104 (mermaid) are already
fixed by the direct `mermaid@11.10.0` dependency. Alerts open-feature#204 and open-feature#205
(fast-xml-builder) are already fixed by the `fast-xml-parser: ^5.7.0`
resolution pulling in `fast-xml-builder@1.2.0`.

## Dependabot Alerts Resolved

| Alert | Package | Severity | Fix |
|-------|---------|----------|-----|
| open-feature#208 | `@babel/plugin-transform-modules-systemjs` | **high** | Pinned
to >=7.29.4 via resolutions |
| open-feature#207 | `fast-uri` | **high** | Pinned to >=3.1.2 via resolutions |
| open-feature#206 | `fast-uri` | **high** | Pinned to >=3.1.2 via resolutions |
| open-feature#205 | `fast-xml-builder` | **high** | Already fixed via
`fast-xml-parser: ^5.7.0` resolution |
| open-feature#204 | `fast-xml-builder` | **medium** | Already fixed via
`fast-xml-parser: ^5.7.0` resolution |
| open-feature#203 | `ip-address` | **medium** | Pinned to >=10.1.1 via resolutions
|
| open-feature#202 | `postcss` | **medium** | Bumped direct dep to ^8.5.10; forced
via resolutions |
| open-feature#131 | `webpack` | **low** | Pinned to 5.99.9 via resolutions |
| open-feature#130 | `webpack` | **low** | Pinned to 5.99.9 via resolutions |
| open-feature#113 | `js-yaml` | **medium** | Scoped to markdownlint-cli2/js-yaml:
>=4.1.1 via resolutions |

---------

Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants