fix: bump anyio, js-yaml, multer, sharp, smol-toml, hono, morgan, react-router and vitest for security advisories - #757
Open
devin-ai-integration[bot] wants to merge 6 commits into
Open
devin-ai-integration[bot] wants to merge 6 commits into
devin-ai-integration[bot] wants to merge 6 commits into
Conversation
…visories Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Contributor
Author
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
Contributor
☂️ Python Coverage
Overall Coverage
New FilesNo new covered files... Modified FilesNo covered modified files...
|
osm6495
approved these changes
Sep 10, 2026
…manfs/node for security advisories Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Dependency-only security remediation from the automated Wiz + Dependabot reconciliation run (2026-09-21), continuing the 2026-09-07/09-14 runs on this branch.
anyio4.9.0 → 4.14.2 in all three Poetry locks (e2e/python,sdk/@launchdarkly/observability-python,sdk/highlight-py).resolutions:js-yaml3.15.2 / 4.3.2,multer2.4.0,sharp0.35.4,smol-toml1.8.0 (plus the earlierpacote,browserslist,fast-uri,@xmldom/xmldom,qs,fflate,@humanfs/nodebumps).hono4.13.7,morgan1.12.1,react-router/react-router-dom6.30.6,vitest+@vitest/mocker4.1.11.e2e/react-nativehas its own npm lockfile, sojs-yamlis pinned there viaoverridesand the lock regenerated.grpc1.83.1 from the previous run.Implementation details
Dependency vulnerability fixes (automated)
Generated by the dependency-vuln-remediation run on 2026-09-21.
Change type: Minor/patch version bumps only — manifest and lockfile changes, no source edits.
Findings addressed (this run)
Carried from the previous runs on this branch:
google.golang.org/grpc1.83.1 across six Go modules,pacote21.5.1,qs6.16.0,fast-uri3.1.7,@xmldom/xmldom0.8.15,browserslist4.28.9,fflate0.4.9/0.6.11/0.8.3,@humanfs/node0.16.8, Django 5.2.17 / 6.1.1.Already satisfied on this branch (stale alerts, no change needed):
baseline-browser-mapping(2.11.21 ≥ 2.11.0),viteinsdk/highlight-run(^6.4.3),uuid11.1.1.Not addressed here
<= 0.6.0Moderate has no fix.nuget.orgblocked in this environment; Dependabot PRs #513/#509/#496 already covere2e/dotnet4/cs/packages.config.go 1.26.0, which would rewrite every module'sgodirective and the CI toolchain.rubygems.orgis not on the network allowlist, so the twoGemfile.locks cannot be regenerated here.Verification
PUPPETEER_SKIP_DOWNLOAD=1 YARN_NPM_REGISTRY_SERVER=https://registry.npmjs.org node .yarn/releases/yarn-4.13.0.cjs install(with--mode=skip-build; Playwright/Chrome CDN downloads forrrvideo/puppeteerare blocked in this environment — cosmetic, resolution and lockfile writing succeed)yarn dedupe --checkyarn build:sdk20/20 packagesyarn lint49/49 packagesangular.io-example#buildfailure in this environment is caused byfonts.googleapis.combeing blocked, unrelated to these bumpslock-versionunchanged (2.1); onlyanyioandtyping-extensionsmoved.e2e/pythonpoetry check --lockreports a pre-existing missingREADME.md.grpcalready at 1.83.1 on this branch)Note: the
Require additional human oversight on bot PRscheck isaction_requiredby design on bot-authored PRs in this repo and needs a human approval; the long-runningiOS build (legacy arch, RN 0.78)job routinely exceeds 90 minutes.Link to Devin session: https://app.devin.ai/sessions/e51e4f8c5e3a47a494306ec7418b4ae2
Open in Devin Desktop: https://app.devin.ai/desktop/session/e51e4f8c5e3a47a494306ec7418b4ae2?variant=devin