Skip to content

Bumping deps to avoid CVE (15/01/2026)#9378

Merged
liranmauda merged 1 commit into
noobaa:masterfrom
liranmauda:liran-bump-deps
Jan 15, 2026
Merged

Bumping deps to avoid CVE (15/01/2026)#9378
liranmauda merged 1 commit into
noobaa:masterfrom
liranmauda:liran-bump-deps

Conversation

@liranmauda

@liranmauda liranmauda commented Jan 15, 2026

Copy link
Copy Markdown
Contributor

Explain the Changes

  • Bumping deps to avoid CVE (15/01/2026)

Summary by CodeRabbit

  • Chores
    • Bumped AWS SDK v3 packages to latest patch release (3.969.0)
    • Updated PostgreSQL driver to 8.17.1
    • Updated YAML package to 2.8.2
    • No changes to public/exported APIs; dependency version updates only

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitai Bot commented Jan 15, 2026

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

Bumped dependency versions in package.json: AWS SDK v3 clients/libs moved from 3.968.0 → 3.969.0, pg updated to 8.17.1, and yaml updated to 2.8.2. No public API changes.

Changes

Cohort / File(s) Summary
Dependencies (package.json)
package.json
Updated @aws-sdk/client-s3, @aws-sdk/client-sts, @aws-sdk/credential-providers, @aws-sdk/lib-storage, @aws-sdk/s3-request-presigner from 3.968.03.969.0; devDependency @aws-sdk/client-iam 3.968.03.969.0; pg 8.16.38.17.1; yaml 2.8.12.8.2. No code/API changes.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

Suggested labels

size/M

Suggested reviewers

  • nimrod-becker
  • dannyzaken
  • jackyalbo
🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly communicates the primary change: bumping dependencies to address CVE vulnerabilities, which aligns with the changeset containing only dependency version updates.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.



📜 Recent review details

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between 4522c86 and 6c4aeb5.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (1)
  • package.json
🚧 Files skipped from review as they are similar to previous changes (1)
  • package.json
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: Build Noobaa Image
  • GitHub Check: run-package-lock-validation
  • GitHub Check: run-jest-unit-tests

✏️ Tip: You can disable this entire section by setting review_details to false in your review settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

- Bumping deps to avoid CVE (15/01/2026)

Signed-off-by: liranmauda <liran.mauda@gmail.com>
@liranmauda liranmauda merged commit 72c66a7 into noobaa:master Jan 15, 2026
18 of 19 checks passed
nadavMiz pushed a commit to nadavMiz/noobaa-core that referenced this pull request Jan 19, 2026
Bumping deps to avoid CVE (15/01/2026)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant