Skip to content

chore: resolve open dependabot security alerts#180

Open
jonathannorris wants to merge 1 commit into
mainfrom
chore/dependabot-alerts
Open

chore: resolve open dependabot security alerts#180
jonathannorris wants to merge 1 commit into
mainfrom
chore/dependabot-alerts

Conversation

@jonathannorris
Copy link
Copy Markdown
Member

Summary

  • Resolved 6 open Dependabot security alerts by bumping vulnerable dependencies across affected provider lockfiles.

Dependabot Alerts Resolved

Alert Package Manifest Severity Fix
#41 faraday providers/openfeature-go-feature-flag-provider/Gemfile.lock low Bumped 2.14.1 to 2.14.2
#40 faraday providers/openfeature-ofrep-provider/Gemfile.lock low Bumped 2.14.1 to 2.14.2
#39 faraday providers/openfeature-flagsmith-provider/Gemfile.lock low Bumped 2.14.1 to 2.14.2
#35 addressable providers/openfeature-flagsmith-provider/Gemfile.lock high Bumped 2.8.9 to 2.9.0
#34 addressable providers/openfeature-go-feature-flag-provider/Gemfile.lock high Bumped 2.8.7 to 2.9.0
#29 json providers/openfeature-meta_provider/Gemfile.lock high Bumped 2.19.0 to 2.19.7

Verification

  • bundle exec rake (lint + RSpec) passes on each affected provider: go-feature-flag (82 examples), ofrep (44 examples), flagsmith (89 examples), meta_provider (58 examples).

Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates several dependency versions across multiple Gemfile.lock files for various OpenFeature providers, including openfeature-flagsmith-provider, openfeature-go-feature-flag-provider, openfeature-meta_provider, and openfeature-ofrep-provider. Specifically, it bumps versions for dependencies such as addressable, faraday, faraday-net_http, json, and public_suffix. There are no review comments, and I have no feedback to provide.

@jonathannorris jonathannorris force-pushed the chore/dependabot-alerts branch from 2731d8d to 05604d0 Compare June 2, 2026 14:59
@jonathannorris jonathannorris marked this pull request as ready for review June 2, 2026 17:51
@jonathannorris jonathannorris requested review from askpt and toddbaert June 2, 2026 17:54
Signed-off-by: Jonathan Norris <jonathan.norris@dynatrace.com>
@jonathannorris jonathannorris force-pushed the chore/dependabot-alerts branch from 05604d0 to 7d0904b Compare June 5, 2026 19:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants