fix(deps): bump transitive brace-expansion, fast-uri and moment past bun audit advisories - #2473
Merged
Merged
Conversation
…bun audit advisories bun audit fails every PR on ten advisories against brace-expansion 1.1.18 / 5.0.9, fast-uri 4.1.4 / 3.1.7 and moment 2.30.1, all transitive. This is the lockfile-only result of `bun audit fix`: 1.1.21 / 5.0.12, 4.1.5 / 3.1.8 and 2.31.0, all within their declared ranges.
Contributor
There was a problem hiding this comment.
AgentCore Harness Review
Verdict: Looks good
This PR is a routine bun.lock refresh containing only patch/minor version bumps of transitive dependencies (brace-expansion, fast-uri, moment, and nested variants). None are declared in package.json, no source or test files are touched, and the version bumps are all backwards-compatible within their semver ranges. Nothing requiring changes here — safe to merge assuming CI is green.
Contributor
|
Claude Security Review: no high-confidence findings. (run) |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## refactor #2473 +/- ##
=========================================
Coverage 97.33% 97.33%
=========================================
Files 627 627
Lines 45030 45030
=========================================
Hits 43832 43832
Misses 1198 1198 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
nborges-aws
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
bun auditin the Linux verify job fails every PR opened since new advisories were published (e.g. #2472, #2456), on ten advisories against transitive dependencies: brace-expansion 1.1.18 / 5.0.9, fast-uri 4.1.4 / 3.1.7, and moment 2.30.1.This is the lockfile-only result of
bun audit fix: brace-expansion → 1.1.21 / 5.0.12, fast-uri → 4.1.5 / 3.1.8, moment → 2.31.0, all within their declared ranges.bun auditis clean afterwards. Same shape as #2445.Related Issue
Closes #
Documentation PR
Not applicable.
Type of Change
Testing
How have you tested the change?
bun test(subset: wizard + policy screens, 87 pass; lockfile-only change)bun run test:e2e, or explained why they are not applicable — dependency bump within ranges, no code changebun run typecheckbun run lint:checkbun run format:checkbun run buildsrc/assets/, I updated affected snapshots withbun test <test-file> --update-snapshotsand committed themChecklist
By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.