Skip to content

fix(deps): bump transitive brace-expansion, fast-uri and moment past bun audit advisories - #2473

Merged
notgitika merged 1 commit into
aws:refactorfrom
notgitika:fix/audit-transitive-bumps
Sep 30, 2026
Merged

notgitika merged 1 commit into
aws:refactorfrom
notgitika:fix/audit-transitive-bumps

Conversation

@notgitika

Copy link
Copy Markdown
Contributor

Description

bun audit in the Linux verify job fails every PR opened since new advisories were published (e.g. #2472, #2456), on ten advisories against transitive dependencies: brace-expansion 1.1.18 / 5.0.9, fast-uri 4.1.4 / 3.1.7, and moment 2.30.1.

This is the lockfile-only result of bun audit fix: brace-expansion → 1.1.21 / 5.0.12, fast-uri → 4.1.5 / 3.1.8, moment → 2.31.0, all within their declared ranges. bun audit is clean afterwards. Same shape as #2445.

Related Issue

Closes #

Documentation PR

Not applicable.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran bun test (subset: wizard + policy screens, 87 pass; lockfile-only change)
  • I ran the relevant end-to-end tests with bun run test:e2e, or explained why they are not applicable — dependency bump within ranges, no code change
  • I ran bun run typecheck
  • I ran bun run lint:check
  • I ran bun run format:check
  • I ran bun run build
  • If I modified src/assets/, I updated affected snapshots with bun test <test-file> --update-snapshots and committed them

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

…bun audit advisories

bun audit fails every PR on ten advisories against brace-expansion 1.1.18 /
5.0.9, fast-uri 4.1.4 / 3.1.7 and moment 2.30.1, all transitive. This is the
lockfile-only result of `bun audit fix`: 1.1.21 / 5.0.12, 4.1.5 / 3.1.8 and
2.31.0, all within their declared ranges.
@github-actions github-actions Bot added the size/xs PR size: XS label Sep 30, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Sep 30, 2026

@agentcore-devx-automation agentcore-devx-automation Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

This PR is a routine bun.lock refresh containing only patch/minor version bumps of transitive dependencies (brace-expansion, fast-uri, moment, and nested variants). None are declared in package.json, no source or test files are touched, and the version bumps are all backwards-compatible within their semver ranges. Nothing requiring changes here — safe to merge assuming CI is green.

@agentcore-devx-automation agentcore-devx-automation Bot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Sep 30, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Sep 30, 2026
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.33%. Comparing base (d1eed2f) to head (c2de00b).

Additional details and impacted files
@@            Coverage Diff            @@
##           refactor    #2473   +/-   ##
=========================================
  Coverage     97.33%   97.33%           
=========================================
  Files           627      627           
  Lines         45030    45030           
=========================================
  Hits          43832    43832           
  Misses         1198     1198           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@notgitika
notgitika merged commit 1b8b52d into aws:refactor Sep 30, 2026
18 of 22 checks passed
@notgitika
notgitika deleted the fix/audit-transitive-bumps branch September 30, 2026 13:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xs PR size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants