Skip to content

Update all dependencies and fix security vulnerabilities - #8

Merged
silvexis merged 8 commits into
mainfrom
claude/code-review-template-01UXFbM5TpFwUntpvX5dxSxg
Sep 12, 2026
Merged

silvexis merged 8 commits into
mainfrom
claude/code-review-template-01UXFbM5TpFwUntpvX5dxSxg

Conversation

@silvexis

@silvexis silvexis commented Mar 14, 2026 •

Copy link
Copy Markdown
Member

Summary

Refresh of this consolidation PR to current (September 2026) stable versions, plus a full template content/docs pass and Docs CI (markdownlint + lychee).

Updates all GitHub Actions, Python (uv), and JavaScript dependencies, including the remaining Dependabot majors that landed after the March 2026 tip (f2acdaf). Then brings READMEs, contributing/security text, GitHub templates, Dependabot, CODEOWNERS notes, Docker examples, and license year current.

Security

JavaScript: npm audit reports 0 vulnerabilities after the refresh.

Python: pip-audit reports no known vulnerabilities in the locked template extras.

Changes beyond f2acdaf (March 2026)

GitHub Actions

  • actions/checkout: v6 → v7
  • actions/setup-node: v6 → v7
  • actions/github-script: v8 → v9 (script does not use require('@actions/github'), so the v9 ESM breaking change does not apply)
  • codecov/codecov-action: v5 → v7 (file → files per the v7 migration; path is python/coverage.xml)
  • astral-sh/setup-uv: v7 → v10.1.0 (pinned to the immutable release; this action no longer publishes floating @v10 major tags)
  • github/codeql-action: remains v4 (latest major; current tag v4.38.0)
  • New Docs CI: DavidAnson/markdownlint-cli2-action@v24 and lycheeverse/lychee-action@v2 (fail: true)

Node.js support

  • engines.node remains >=20.0.0
  • CI matrix: 22 / 24 / 26
    • Node 20 reached EOL on 2026-04-30 (same rationale as dropping Node 18)
    • Node 24 is Active LTS; Node 22 is Maintenance LTS; Node 26 is Current (LTS planned 2026-10-28)

Python (still 3.11–3.13)

Floors in pyproject.toml / lock via uv lock --upgrade:

  • ruff: >=0.14.0 → >=0.16.0 (locked 0.16.7)
  • pytest: >=9.0 → >=9.1 (locked 9.1.1)
  • pytest-cov: >=4.1 → >=7.1 (locked 7.1.0)
  • polars: >=1.36.0 → >=1.44.0 (locked 1.44.2)
  • pydantic: >=2.12.0 → >=2.13.0 (locked 2.13.5)
  • aws-lambda-powertools: >=3.24.0 → >=3.34.0 (locked 3.34.0)
  • httpx: remains >=0.28.0 (locked 0.28.1, still latest)
  • Dev installs now use uv [dependency-groups] (uv sync --extra dev --group dev)

JavaScript

  • @eslint/js: ^9.39.1 → ^10.0.1 (installed 10.0.1)
  • eslint: ^9.0.0 → ^10.10.0 (installed 10.10.0)
  • @types/node: ^22.0.0 → ^24.13.4 (aligned with Active LTS)
  • @typescript-eslint/* / typescript-eslint: ^8.53.0 → ^8.70.0
  • eslint-plugin-jest: ^29.2.1 → ^29.16.6
  • globals: ^16.5.0 → ^17.12.0
  • jest: ^30.2.0 → ^30.5.1
  • prettier: ^3.2.0 → ^3.9.6
  • ts-jest: ^29.4.6 → ^29.4.12
  • typescript: stays on 5.9.3 — TypeScript 7.0.2 is latest npm latest, but typescript-eslint@8.70 requires <6.1.0 and ts-jest@29 requires <7
  • CI now runs Prettier, ESLint, tsc --noEmit, and Jest
  • Repository URL uses https:// (not deprecated git://)

Intentionally not taken

  • TypeScript 7 (toolchain peer-dep ceiling)
  • Prettier 4 (still alpha)
  • Python 3.14 (this PR keeps the 3.11–3.13 matrix)
  • Contributor Covenant 3.0 (2.1 remains; a CoC version bump is a policy decision)

Template content and config pass (tip 8fd1dab)

Stale or incorrect items that were fixed:

  • Node 18 language in CONTRIBUTING (now 20+, with CI 22/24/26)
  • NOTICE copyright year → 2026
  • Dependabot pip + / missed python/uv.lock; now uv ecosystem on /python, plus docker for the example Dockerfile
  • SECURITY.md now prefers GitHub private vulnerability reporting, with email fallback; docs URL is the current GitHub how-to
  • OpenSSF criteria link (old ossf/best-practices-badge path 404s; now coreinfrastructure/best-practices-badge)
  • Issue/PR templates: relative CoC links, security guidance, YAML forms, PR heading structure
  • Makefile ran uv from the repo root (no root pyproject.toml); Python targets now cd python. docker compose replaces docker-compose
  • Dockerfile copies python/, uses a named AS builder stage, Python 3.13
  • Source headers aligned to Apache SPDX (FILE-HEADER style)
  • CODEOWNERS comments explain rulesets vs inventing extra teams
  • Mozilla CoC attribution URL (diversity → inclusion)
  • Ruff lint set expanded with SIM, PIE, PT, RUF
  • Codecov upload path corrected to python/coverage.xml

New CI jobs

Job Tool Scope
Markdown lint markdownlint-cli2 (DavidAnson/markdownlint-cli2-action@v24) all *.md (ignores node_modules, coverage, venvs)
Link check lychee (lycheeverse/lychee-action@v2, fail: true) all *.md; allowlist is only localhost, example.com, placeholder GitHub paths, mailto, and npmjs.com (403 to bots)

JavaScript and Python CI already ran format + lint + tests; JS also type-checks. Workflows now set permissions: contents: read, fail-fast: false, and cancel outdated PR runs.

Consolidates open Dependabot PRs

This tip covers the intent of:

No conflicts with the Node ≥20 / Jest 30 direction. Those Dependabot PRs target main and can be closed after this merges.

Breaking changes

  • Node 20 dropped from CI (EOL). Minimum engines.node is still >=20.0.0.
  • ESLint 10 (flat config already in use; Node 20.19+ / 22.13+ / 24+ required to run ESLint itself)
  • Jest 30 / eslint-plugin-jest 29 / @types/jest 30 (already introduced earlier in this PR)
  • codecov-action v7 input rename file → files

Testing

  • npx markdownlint-cli2 → 0 issues (14 Markdown files)
  • lychee --config lychee.toml './**/*.md' → 0 errors
  • npm ci / Prettier / ESLint / tsc --noEmit / Jest (local)
  • npm audit → 0 vulnerabilities
  • uv sync --extra dev --group dev / ruff format+check / pytest (local)
  • GitHub Actions CI green on tip 8fd1dab (JS 22/24/26, Python 3.11/3.12/3.13, Docs Markdown lint + Link check)
  • Custom codeql.yml workflow is disabled_inactivity on this repo; GitHub default CodeQL setup remains active

Checklist

  • Documentation of versions in this PR body matches the lockfiles
  • All active GitHub checks for tests, formatting, and security are passing
  • Base branch is main

This commit updates all GitHub Actions, Python, and JavaScript dependencies
to their latest stable versions as of January 2025.

GitHub Actions Updates:
- actions/checkout: v4 → v6
- astral-sh/setup-uv: v3 → v7
- codecov/codecov-action: v4 → v5
- github/codeql-action: v3 → v4
- actions/setup-node: v4 → v6
- actions/github-script: v7 → v8

Python Dependencies Updates:
- ruff: >=0.3.0 → >=0.14.0
- pytest: >=8.0 → >=9.0
- polars: >=0.20.0 → >=1.36.0
- httpx: >=0.27.0 → >=0.28.0
- pydantic: >=2.0 → >=2.12.0
- aws-lambda-powertools: >=2.0 → >=3.24.0

JavaScript Dependencies Updates:
- @types/node: ^20.0.0 → ^25.0.0
- typescript: ^5.4.0 → ^5.9.0
- @typescript-eslint/eslint-plugin: ^8.0.0 → ^8.53.0
- @typescript-eslint/parser: ^8.0.0 → ^8.53.0
- typescript-eslint: ^8.47.0 → ^8.53.0
Merged updates from Dependabot PRs into this branch:
- eslint-config-prettier: ^9.0.0 → ^10.1.8
- eslint-plugin-jest: ^28.0.0 → ^29.2.1 (major version bump)
- jest: ^29.7.0 → ^30.2.0 (major version bump)
- @types/jest: ^29.5.0 → ^30.0.0 (major version bump)
- ts-jest: ^29.1.0 → ^29.4.6

Combined with manual updates from previous commit:
- @types/node: ^20.0.0 → ^25.0.0
- typescript: ^5.4.0 → ^5.9.0
- @typescript-eslint/eslint-plugin: ^8.0.0 → ^8.53.0
- @typescript-eslint/parser: ^8.0.0 → ^8.53.0
- typescript-eslint: ^8.47.0 → ^8.53.0

https://claude.ai/code/session_01UXFbM5TpFwUntpvX5dxSxg
Regenerated lock files after dependency updates to resolve security issues:

JavaScript (npm audit):
- Fixed ajv ReDoS vulnerability (moderate severity)
- Fixed flatted unbounded recursion DoS (high severity)
- Fixed multiple minimatch ReDoS vulnerabilities (high severity)
- Result: 0 vulnerabilities found

Python (pip-audit):
- Updated uv.lock with latest dependency versions
- Result: No known vulnerabilities found

All security issues from GitHub's Dependabot alerts are now resolved.

https://claude.ai/code/session_01UXFbM5TpFwUntpvX5dxSxg
@silvexis
silvexis requested a review from a team as a code owner March 14, 2026 15:31
@greptile-apps

greptile-apps Bot commented Mar 14, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR refreshes the Python, JavaScript, and GitHub Actions dependency sets while substantially modernizing the repository template’s CI, documentation, automation, and local-development assets.

  • Updates locked Python and JavaScript development dependencies.
  • Moves CI to current runtime matrices and adds TypeScript and documentation checks.
  • Refreshes Dependabot, CodeQL, Codecov, container, Makefile, and contributor workflows.
  • Reworks the starter source, tests, documentation, and publishing exclusions.

Confidence Score: 5/5

The PR appears safe to merge, with one non-blocking local documentation-lint issue; the existing Node engine/tooling mismatch also remains non-blocking.

The new Make target does not pass Markdown files to markdownlint-cli2, so local documentation linting does not match CI. The previous Node engine finding remains outstanding because javascript/package.json still advertises Node >=20.0.0 while ESLint 10 requires newer Node 20 patch releases, but both outstanding concerns are non-blocking quality issues. The earlier trailing-newline thread was manually resolved without explanation and does not affect merge safety.

Files Needing Attention: Makefile, javascript/package.json

Important Files Changed

Filename Overview
javascript/package.json Updates the JavaScript quality toolchain and scripts, while the previously reported Node engine/tooling mismatch remains outstanding.
python/pyproject.toml Updates Python dependency floors and adopts the standardized uv development dependency group.
.github/workflows/ci-python.yml Updates actions, installs both uv development sets, and corrects the workspace-relative Codecov report path.
.github/workflows/ci-javascript.yml Updates the Node matrix and adds TypeScript checking to CI.
.github/workflows/ci-docs.yml Adds Markdown linting and link checking with explicit repository-wide file patterns.
Makefile Modernizes local Python, JavaScript, documentation, and container targets, but the Markdown lint target omits its input glob.
Dockerfile Reworks the Python template into a root-context multi-stage image with a documented placeholder entry point.
.github/dependabot.yaml Adds grouped uv, npm, GitHub Actions, and Docker dependency updates at their correct project locations.

Fix all with Greploop Fix All in Claude Code

Prompt To Fix All With AI
### Issue 1
Makefile:52-53
**Markdown lint skips files**

The new `lint-md` target invokes `markdownlint-cli2` without a file glob, so it displays help instead of linting the repository. Contributors can therefore get a false local pass even though Docs CI explicitly checks `**/*.md`. Pass the same glob here and in the documented command so local checks reproduce CI.

```suggestion
lint-md:
	npx --yes markdownlint-cli2 '**/*.md'
```

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Reviews (3): Last reviewed commit: "Modernize template docs and add Markdown..." | Re-trigger Greptile

Comment thread python/pyproject.toml Outdated
@silvexis silvexis changed the title Claude/code review template 01 ux fb m5 tp fw untpv x5dx sxg Update all dependencies and fix security vulnerabilities Mar 14, 2026
@silvexis
silvexis requested a review from Copilot March 14, 2026 16:33
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR consolidates dependency upgrades across GitHub Actions workflows, the Python (uv/pyproject) toolchain, and the JavaScript toolchain, aiming to bring the template up to date and address reported dependency vulnerabilities.

Changes:

  • Bumped GitHub Actions used in CI/security workflows (checkout/setup-node/setup-uv/codecov/codeql/github-script).
  • Updated Python optional dependencies and refreshed uv.lock to newer resolved versions.
  • Updated JavaScript dev dependencies (TypeScript/ESLint/Jest ecosystem) and refreshed package-lock.json.

Reviewed changes

Copilot reviewed 6 out of 8 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
.github/workflows/ci-python.yml Updates CI Actions used for Python pipeline (checkout/setup-uv/codecov).
.github/workflows/ci-javascript.yml Updates CI Actions for JS pipeline (checkout/setup-node).
.github/workflows/codeql.yml Updates CodeQL Actions versions used for security scanning.
.github/workflows/dependabot-auto-merge.yml Updates actions/github-script used for Dependabot auto-merge logic.
python/pyproject.toml Raises minimum versions for optional/dev/test/lint dependencies.
python/uv.lock Refreshes resolved Python dependency set to newer versions.
javascript/package.json Raises JS dev dependency versions (Jest/ESLint/TS tooling).
javascript/package-lock.json Refreshes resolved JS dependency graph to match updated devDependencies.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

You can also share your feedback on Copilot code review. Take the survey.

Comment thread .github/workflows/ci-javascript.yml Outdated
Comment thread javascript/package.json Outdated
Comment thread javascript/package.json Outdated
- Drop Node 18 from CI matrix (EOL), add Node 24
- Update engines.node to >=20.0.0
- Align @types/node with highest LTS runtime (^22.0.0)
- Add trailing newline to pyproject.toml
- Remove duplicate ruff entry in dev-dependencies

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the template’s GitHub Actions and Python/JavaScript dependencies, aiming to consolidate Dependabot updates and address reported security vulnerabilities.

Changes:

  • Bumped multiple GitHub Actions versions in CI, CodeQL, and Dependabot auto-merge workflows.
  • Updated Python dependency constraints (pyproject) and regenerated uv.lock.
  • Updated JavaScript devDependencies (notably Jest/ESLint/tooling) and regenerated package-lock.json.

Reviewed changes

Copilot reviewed 6 out of 8 changed files in this pull request and generated 4 comments.

Show a summary per file
File Description
.github/workflows/ci-python.yml Updates checkout/uv/codecov actions used by Python CI.
.github/workflows/ci-javascript.yml Updates checkout/setup-node actions and adjusts Node test matrix.
.github/workflows/codeql.yml Updates checkout and CodeQL action versions for security scanning.
.github/workflows/dependabot-auto-merge.yml Updates actions/github-script used for Dependabot label check.
python/pyproject.toml Raises Python optional/development dependency minimum versions.
python/uv.lock Regenerates the Python lockfile to reflect updated dependencies.
javascript/package.json Updates Node engine and JS tooling dependencies (Jest/TS/ESLint stack).
javascript/package-lock.json Regenerates npm lockfile after dependency updates.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

You can also share your feedback on Copilot code review. Take the survey.

Comment thread .github/workflows/ci-javascript.yml Outdated
Comment thread javascript/package.json Outdated
Comment thread javascript/package.json
Comment thread javascript/package.json Outdated
@silvexis
silvexis enabled auto-merge March 14, 2026 17:19
cursoragent and others added 2 commits September 12, 2026 18:10
Bump remaining Actions majors past the March tip, drop EOL Node 20 from
CI in favor of 22/24/26, and lock current stable JS/Python versions.
Keep TypeScript on 5.9 because typescript-eslint and ts-jest do not
support TypeScript 7 yet.

Co-authored-by: Erik Peterson <me@erikpeterson.com>
astral-sh/setup-uv stopped publishing floating major/minor tags in v8
(immutable releases). @v10 does not resolve on GitHub Actions.

Co-authored-by: Erik Peterson <me@erikpeterson.com>
Comment thread javascript/package.json
"main": "index.js",
"engines": {
"node": ">=18.0.0",
"node": ">=20.0.0",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Node engine range mismatch

The package advertises Node.js >=20.0.0, but the upgraded ESLint 10 toolchain requires Node.js ^20.19.0 || ^22.13.0 || >=24. Contributors using Node 20.0–20.18 therefore meet the declared engine requirement but cannot reliably run the provided lint scripts. CI now tests only Node 22, 24, and 26, so it will not catch this mismatch. Please raise the declared minimum to Node 20.19 or otherwise align the toolchain and CI with the supported range.

Suggested change
"node": ">=20.0.0",
"node": ">=20.19.0",

Knowledge Base Used:

Prompt To Fix With AI
This is a comment left during a code review.
Path: javascript/package.json
Line: 20

Comment:
**Node engine range mismatch**

The package advertises Node.js `>=20.0.0`, but the upgraded ESLint 10 toolchain requires Node.js `^20.19.0 || ^22.13.0 || >=24`. Contributors using Node 20.0–20.18 therefore meet the declared engine requirement but cannot reliably run the provided lint scripts. CI now tests only Node 22, 24, and 26, so it will not catch this mismatch. Please raise the declared minimum to Node 20.19 or otherwise align the toolchain and CI with the supported range.

```suggestion
    "node": ">=20.19.0",
```

**Knowledge Base Used:**
- [JavaScript project template](https://app.greptile.com/cloudzero/-/custom-context/knowledge-base/cloudzero/template-cloudzero-open-source/-/docs/javascript-project-template.md)
- [CI and security workflows](https://app.greptile.com/cloudzero/-/custom-context/knowledge-base/cloudzero/template-cloudzero-open-source/-/docs/ci-and-security-workflows.md)

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Claude Code

Bring README, contributing, security, and GitHub templates current
for September 2026. Add markdownlint-cli2 and lychee to Docs CI,
expand Python/JS lint coverage, and point Dependabot at uv.

Co-authored-by: Erik Peterson <me@erikpeterson.com>
Comment thread Makefile
Comment on lines +52 to +53
lint-md:
npx --yes markdownlint-cli2

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Markdown lint skips files

The new lint-md target invokes markdownlint-cli2 without a file glob, so it displays help instead of linting the repository. Contributors can therefore get a false local pass even though Docs CI explicitly checks **/*.md. Pass the same glob here and in the documented command so local checks reproduce CI.

Suggested change
lint-md:
npx --yes markdownlint-cli2
lint-md:
npx --yes markdownlint-cli2 '**/*.md'

Knowledge Base Used:

Prompt To Fix With AI
This is a comment left during a code review.
Path: Makefile
Line: 52-53

Comment:
**Markdown lint skips files**

The new `lint-md` target invokes `markdownlint-cli2` without a file glob, so it displays help instead of linting the repository. Contributors can therefore get a false local pass even though Docs CI explicitly checks `**/*.md`. Pass the same glob here and in the documented command so local checks reproduce CI.

```suggestion
lint-md:
	npx --yes markdownlint-cli2 '**/*.md'
```

**Knowledge Base Used:**
- [Local development and containers](https://app.greptile.com/cloudzero/-/custom-context/knowledge-base/cloudzero/template-cloudzero-open-source/-/docs/local-development-and-containers.md)
- [CI and security workflows](https://app.greptile.com/cloudzero/-/custom-context/knowledge-base/cloudzero/template-cloudzero-open-source/-/docs/ci-and-security-workflows.md)

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants