chore: resolve open dependabot security alerts#399
Conversation
There was a problem hiding this comment.
Code Review
This pull request updates dependencies in the uv.lock file, upgrading aiohttp from 3.13.5 to 3.14.1 along with its corresponding wheels and a conditional dependency on typing-extensions. Additionally, openfeature-provider-flagd is upgraded from 0.4.1 to 0.5.0. As there are no review comments, no further feedback is provided.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
There was a problem hiding this comment.
Copilot wasn't able to review any files in this pull request.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #399 +/- ##
==========================================
+ Coverage 95.62% 96.28% +0.65%
==========================================
Files 24 47 +23
Lines 1029 1750 +721
==========================================
+ Hits 984 1685 +701
- Misses 45 65 +20 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Summary
aiohttp3.13.5 -> 3.14.1 inuv.lockto resolve two medium-severity Dependabot alerts (chore: add CODEOWNERS #34, chore: reorganize repo for multiple packages #35).Dependabot Alerts Resolved
aiohttpaiohttpaiohttpis a transitive dependency (viaopenfeature-provider-aws-ssm[async]); the lockfile was regenerated withuv lock --upgrade-package aiohttp. Verified build, mypy, and the aws-ssm test suite (174 passed) on the patched version.