chore: resolve open dependabot security alerts - #2028
Conversation
✅ Deploy Preview for polite-licorice-3db33c canceled.
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
Included review availability: Your plan includes up to 4 reviews per rolling hour; 3 remain after this review. 📝 WalkthroughWalkthroughThe playground application updates its ChangesPlayground dependency update
Estimated code review effort: 1 (Trivial) | ~2 minutes Merge Risk: ⚪ Minimal · up to This PR makes a localized dependency update to address a security alert, with no actionable merge-blocking risk remaining beyond normal checks and review. Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
closed/opened to try to fix seemingly stuck checks... |
- js-yaml 4.3.0 -> 4.3.1 (high, alert #275) in playground-app Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
fd5e02f to
b15633f
Compare
|



Summary
js-yamlto 4.3.1 inplayground-appto resolve a high-severity quadratic CPU consumption vulnerability (alert fix(deps): update module google.golang.org/grpc to v1.52.0 - autoclosed #275)Dependabot Alerts Resolved
js-yamlUnresolvable (no compatible patched version)
The following alerts affect
github.com/docker/dockerintest/integration/go.mod, pulled in transitively viatestcontainers-go,docker/buildx, anddocker/compose/v5. Upstream moved the fixed releases (v29.x+) to a new module path (github.com/moby/moby/v2), which is not yet consumed by these dependency chains in a compatible way. Attempting to force the upgrade cascades into an unrelated, very large dependency tree (containerd v2, sigstore, vault, opa, etc.) and a Go toolchain bump, which is too invasive/risky for a routine security fix. No safe non-breaking patched version is currently available.github.com/docker/dockergithub.com/docker/dockergithub.com/docker/dockergithub.com/docker/dockergithub.com/docker/docker