chore: resolve open dependabot security alerts - #407
Conversation
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #407 +/- ##
==========================================
+ Coverage 95.64% 96.28% +0.63%
==========================================
Files 24 47 +23
Lines 1057 1778 +721
==========================================
+ Hits 1011 1712 +701
- Misses 46 66 +20 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Summary
uv.lock.aiohttpto 3.14.3 (resolves 3 alerts, ci: add generated protobuf files to sdist and wheel #46-TypeError when using flagd provider #48).cryptographyto 50.0.0 (resolves 1 high-severity alert, docs: update OpenTelemetry hook README #49).Both are transitive dependencies pulled in via the
openfeature-provider-aws-ssmprovider's async extras/dev group (aiobotocore/moto). Relocked withuv lock --upgrade-package aiohttp --upgrade-package cryptography. Verifieduv build,poe mypy, andpoe covpass for the affected package (aws-ssm).Dependabot Alerts Resolved
aiohttpaiohttpaiohttpcryptography