Skip to content

Bump Snyk-flagged dependencies#28

Merged
bruce-y merged 2 commits intomainfrom
bump-snyk-dependencies
Mar 26, 2026
Merged

Bump Snyk-flagged dependencies#28
bruce-y merged 2 commits intomainfrom
bump-snyk-dependencies

Conversation

@bruce-y
Copy link
Copy Markdown

@bruce-y bruce-y commented Mar 26, 2026

Consolidates 5 open Snyk upgrade PRs (#16, #17, #18, #19, #20) into a single PR by bumping the minimum versions in package.json.

How it works:

  • @actions/core ^1.10.1 → ^1.11.1
  • @actions/github ^6.0.0 → ^6.0.1
  • @actions/tool-cache ^2.0.1 → ^2.0.2
  • @vercel/ncc ^0.38.0 → ^0.38.3
  • yaml ^2.2.1 → ^2.8.0

The three @actions/cache Snyk PRs (#15, #21, #23) were intentionally excluded — they would replace the @useblacksmith/cache fork with the official @actions/cache, breaking the Blacksmith integration. The lockfile and dist/ will be regenerated in CI once the BUF_TOKEN is available for the private registry.


View Codesmith session

Co-authored-by: Codesmith <codesmith@blacksmith.sh>
Copy link
Copy Markdown

@cursor cursor bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Co-authored-by: Codesmith <codesmith@blacksmith.sh>
@bruce-y bruce-y merged commit 3328c92 into main Mar 26, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant