Skip to content

chore(deps): integrate dependency upgrades on patched backend stack - #259

Merged
DavidHLP merged 14 commits into
codex/security-source-map-jsfrom
codex/dependency-integration
Oct 11, 2026
Merged

DavidHLP merged 14 commits into
codex/security-source-map-jsfrom
codex/dependency-integration

Conversation

@DavidHLP

Copy link
Copy Markdown
Owner

Dependency candidates were still built on the older Boot3/SpringMVC6.2.19 stack, which failed image scans for CVE-2026-47884 and CVE-2026-47890. This branch integrates their Actions SHA updates, frontend dependency/type fixes and dotenv18 onto the already patched backend stack, without repeating the backend migration or weakening any gate.

Head: 6186e58. Baseline: b987619.

Actions merge is conflict-free. Frontend lock conflicts remove obsolete intlify11.4.10 snapshots; dotenv lock conflicts preserve newer Vite, Node types, Vue language core and coverage peers. The final dotenv merge changes only its own root version/importer/package/snapshot. The two management source changes preserve writable computed types and template event typing. No backend, documentation, corpus, or security policy changed.

Both final static review axes APPROVE this head. Remote supply-chain-contract.sh original handle4653 completed0: digest-only promotion, all-service evidence, negative/dry-run/idempotency/partial-failure cases, immutable images and deploy policy PASS.

Normal CI https://github.com/DavidHLP/UltiCode/actions/runs/38062115205 completed SUCCESS on exact6186e58f4f0d9191031d6b4a26ed5b14f25de56a:all32jobsSUCCESS,0failed. Both frontend type checks/tests/lint, shared auth tests, Agent unit tests, backend build, default/features-off/features-on tests, migrations/dynamic architecture contracts, contract compatibility, secret scan and all nine Docker images passed. Current result was read through normal remote-dev gh run view (original75409 completed0), after local observation43465 hung. No workflow restart was dispatched. Remote AST graph update original84713 completed0:34224nodes116040edges810communities; SQL122 files omitted due missing tree_sitter_sql. graph.json built_at_commit confirmed6186e58f4f0d9191031d6b4a26ed5b14f25de56a.

Historical intermediate28passed observation is superseded by current32SUCCESS. Original43465 was an observation handle only; its timeout never established CI failure.

No new paid model calls. Original28 unfinished task scope and formal acceptance constraints remain unchanged. This is a reviewable candidate body, not a claim of PR creation or merge. Current Linear project read again returned UNAUTHORIZED / reauthentication required.

dependabot Bot and others added 14 commits October 10, 2026 08:04
Bumps the all-actions group with 4 updates: [actions/setup-node](https://github.com/actions/setup-node), [actions/upload-artifact](https://github.com/actions/upload-artifact), [jdx/mise-action](https://github.com/jdx/mise-action) and [actions/download-artifact](https://github.com/actions/download-artifact).


Updates `actions/setup-node` from 7.0.0 to 7.1.0
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@8207627...949feb2)

Updates `actions/upload-artifact` from 7.0.1 to 7.0.2
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@043fb46...cf430e0)

Updates `jdx/mise-action` from 5.0.1 to 5.1.1
- [Release notes](https://github.com/jdx/mise-action/releases)
- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md)
- [Commits](jdx/mise-action@7a4e45a...2d8d4ca)

Updates `actions/download-artifact` from 7.0.0 to 8.0.2
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@37930b1...9000827)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: 7.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-actions
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-actions
- dependency-name: jdx/mise-action
  dependency-version: 5.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-actions
- dependency-name: actions/download-artifact
  dependency-version: 8.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps the development group with 11 updates:

| Package | From | To |
| --- | --- | --- |
| [jsdom](https://github.com/jsdom/jsdom) | `30.1.1` | `30.1.2` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `5.0.2` | `5.0.3` |
| [@iconify-json/lucide](https://github.com/iconify/icon-sets) | `1.2.137` | `1.2.140` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.6.3` | `26.6.4` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `5.0.2` | `5.0.3` |
| [eslint](https://github.com/eslint/eslint) | `10.11.0` | `10.12.0` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.38.0` | `6.40.0` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.3.1` | `8.3.3` |
| [vite-plugin-pwa](https://github.com/vite-pwa/vite-plugin-pwa) | `1.3.0` | `2.0.0` |
| [vue-tsc](https://github.com/vuejs/language-tools/tree/HEAD/packages/tsc) | `3.3.11` | `3.3.12` |
| [@vitest/ui](https://github.com/vitest-dev/vitest/tree/HEAD/packages/ui) | `5.0.2` | `5.0.3` |


Updates `jsdom` from 30.1.1 to 30.1.2
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v30.1.1...v30.1.2)

Updates `vitest` from 5.0.2 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

Updates `@iconify-json/lucide` from 1.2.137 to 1.2.140
- [Commits](https://github.com/iconify/icon-sets/commits)

Updates `@types/node` from 26.6.3 to 26.6.4
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@vitest/coverage-v8` from 5.0.2 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/coverage-v8)

Updates `eslint` from 10.11.0 to 10.12.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.11.0...v10.12.0)

Updates `knip` from 6.38.0 to 6.40.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.40.0/packages/knip)

Updates `vite` from 8.3.1 to 8.3.3
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.3.3/packages/vite)

Updates `vite-plugin-pwa` from 1.3.0 to 2.0.0
- [Release notes](https://github.com/vite-pwa/vite-plugin-pwa/releases)
- [Commits](vite-pwa/vite-plugin-pwa@v1.3.0...v2.0.0)

Updates `vue-tsc` from 3.3.11 to 3.3.12
- [Release notes](https://github.com/vuejs/language-tools/releases)
- [Changelog](https://github.com/vuejs/language-tools/blob/master/CHANGELOG.md)
- [Commits](https://github.com/vuejs/language-tools/commits/v3.3.12/packages/tsc)

Updates `@vitest/ui` from 5.0.2 to 5.0.3
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/ui)

---
updated-dependencies:
- dependency-name: jsdom
  dependency-version: 30.1.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
- dependency-name: vitest
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
- dependency-name: "@iconify-json/lucide"
  dependency-version: 1.2.140
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
- dependency-name: "@types/node"
  dependency-version: 26.6.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
- dependency-name: "@vitest/coverage-v8"
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
- dependency-name: eslint
  dependency-version: 10.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development
- dependency-name: knip
  dependency-version: 6.40.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: development
- dependency-name: vite
  dependency-version: 8.3.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
- dependency-name: vite-plugin-pwa
  dependency-version: 2.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: development
- dependency-name: vue-tsc
  dependency-version: 3.3.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
- dependency-name: "@vitest/ui"
  dependency-version: 5.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [dotenv](https://github.com/motdotla/dotenv) from 17.4.2 to 18.0.6.
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](motdotla/dotenv@v17.4.2...v18.0.6)

---
updated-dependencies:
- dependency-name: dotenv
  dependency-version: 18.0.6
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-11T02:55:47.955173Z 6186e58 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@DavidHLP
DavidHLP merged commit 9c16b47 into codex/security-source-map-js Oct 11, 2026
32 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant