Skip to content

bump deps#99

Merged
malewis5 merged 4 commits intomasterfrom
bump-deps
Apr 7, 2026
Merged

bump deps#99
malewis5 merged 4 commits intomasterfrom
bump-deps

Conversation

@malewis5
Copy link
Copy Markdown
Collaborator

@malewis5 malewis5 commented Apr 7, 2026

This pull request focuses on updating dependencies in the @vercel/slack-bolt package and addressing a security concern by overriding the vite version. It also includes minor improvements to test formatting for readability.

Dependency and security updates:

  • Bumped several dev dependencies in packages/slack-bolt/package.json, including @biomejs/biome, @types/node, @vitest/coverage-v8, and vitest, to their latest patch versions.
  • Added a pnpm.overrides section in the root package.json to force the vite version to 7.3.2, mitigating a vulnerability in the version range required by vitest.
  • Added a changeset file documenting the dependency bumps and the vite override due to the security issue.

Test code improvements:

  • Reformatted parameterized test definitions in packages/slack-bolt/src/internal/slack/index.test.ts for better readability and maintainability. [1] [2]

@vercel
Copy link
Copy Markdown
Contributor

vercel Bot commented Apr 7, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
slack-bolt-nextjs Ready Ready Preview, Comment Apr 7, 2026 1:56pm

@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedvitest@​4.1.2 ⏵ 4.1.398 +210079 +198100
Updated@​vitest/​coverage-v8@​4.1.2 ⏵ 4.1.3991007999 +2100
Updated@​types/​node@​20.19.35 ⏵ 20.19.39100 +110081 +196100
Updatedturbo@​2.9.2 ⏵ 2.9.41001008598100
Added@​slack/​bolt@​4.7.09910010091100

View full report

@malewis5 malewis5 merged commit 44c8df6 into master Apr 7, 2026
4 checks passed
@malewis5 malewis5 deleted the bump-deps branch April 7, 2026 13:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant