Update all dependencies and fix security vulnerabilities - #8
Conversation
This commit updates all GitHub Actions, Python, and JavaScript dependencies to their latest stable versions as of January 2025. GitHub Actions Updates: - actions/checkout: v4 → v6 - astral-sh/setup-uv: v3 → v7 - codecov/codecov-action: v4 → v5 - github/codeql-action: v3 → v4 - actions/setup-node: v4 → v6 - actions/github-script: v7 → v8 Python Dependencies Updates: - ruff: >=0.3.0 → >=0.14.0 - pytest: >=8.0 → >=9.0 - polars: >=0.20.0 → >=1.36.0 - httpx: >=0.27.0 → >=0.28.0 - pydantic: >=2.0 → >=2.12.0 - aws-lambda-powertools: >=2.0 → >=3.24.0 JavaScript Dependencies Updates: - @types/node: ^20.0.0 → ^25.0.0 - typescript: ^5.4.0 → ^5.9.0 - @typescript-eslint/eslint-plugin: ^8.0.0 → ^8.53.0 - @typescript-eslint/parser: ^8.0.0 → ^8.53.0 - typescript-eslint: ^8.47.0 → ^8.53.0
Merged updates from Dependabot PRs into this branch: - eslint-config-prettier: ^9.0.0 → ^10.1.8 - eslint-plugin-jest: ^28.0.0 → ^29.2.1 (major version bump) - jest: ^29.7.0 → ^30.2.0 (major version bump) - @types/jest: ^29.5.0 → ^30.0.0 (major version bump) - ts-jest: ^29.1.0 → ^29.4.6 Combined with manual updates from previous commit: - @types/node: ^20.0.0 → ^25.0.0 - typescript: ^5.4.0 → ^5.9.0 - @typescript-eslint/eslint-plugin: ^8.0.0 → ^8.53.0 - @typescript-eslint/parser: ^8.0.0 → ^8.53.0 - typescript-eslint: ^8.47.0 → ^8.53.0 https://claude.ai/code/session_01UXFbM5TpFwUntpvX5dxSxg
Regenerated lock files after dependency updates to resolve security issues: JavaScript (npm audit): - Fixed ajv ReDoS vulnerability (moderate severity) - Fixed flatted unbounded recursion DoS (high severity) - Fixed multiple minimatch ReDoS vulnerabilities (high severity) - Result: 0 vulnerabilities found Python (pip-audit): - Updated uv.lock with latest dependency versions - Result: No known vulnerabilities found All security issues from GitHub's Dependabot alerts are now resolved. https://claude.ai/code/session_01UXFbM5TpFwUntpvX5dxSxg
Greptile SummaryThis PR refreshes the Python, JavaScript, and GitHub Actions dependency sets while substantially modernizing the repository template’s CI, documentation, automation, and local-development assets.
Confidence Score: 5/5The PR appears safe to merge, with one non-blocking local documentation-lint issue; the existing Node engine/tooling mismatch also remains non-blocking. The new Make target does not pass Markdown files to markdownlint-cli2, so local documentation linting does not match CI. The previous Node engine finding remains outstanding because Files Needing Attention: Makefile, javascript/package.json Important Files Changed
Prompt To Fix All With AI### Issue 1
Makefile:52-53
**Markdown lint skips files**
The new `lint-md` target invokes `markdownlint-cli2` without a file glob, so it displays help instead of linting the repository. Contributors can therefore get a false local pass even though Docs CI explicitly checks `**/*.md`. Pass the same glob here and in the documented command so local checks reproduce CI.
```suggestion
lint-md:
npx --yes markdownlint-cli2 '**/*.md'
```
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.Reviews (3): Last reviewed commit: "Modernize template docs and add Markdown..." | Re-trigger Greptile |
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
This PR consolidates dependency upgrades across GitHub Actions workflows, the Python (uv/pyproject) toolchain, and the JavaScript toolchain, aiming to bring the template up to date and address reported dependency vulnerabilities.
Changes:
- Bumped GitHub Actions used in CI/security workflows (checkout/setup-node/setup-uv/codecov/codeql/github-script).
- Updated Python optional dependencies and refreshed
uv.lockto newer resolved versions. - Updated JavaScript dev dependencies (TypeScript/ESLint/Jest ecosystem) and refreshed
package-lock.json.
Reviewed changes
Copilot reviewed 6 out of 8 changed files in this pull request and generated 3 comments.
Show a summary per file
| File | Description |
|---|---|
.github/workflows/ci-python.yml |
Updates CI Actions used for Python pipeline (checkout/setup-uv/codecov). |
.github/workflows/ci-javascript.yml |
Updates CI Actions for JS pipeline (checkout/setup-node). |
.github/workflows/codeql.yml |
Updates CodeQL Actions versions used for security scanning. |
.github/workflows/dependabot-auto-merge.yml |
Updates actions/github-script used for Dependabot auto-merge logic. |
python/pyproject.toml |
Raises minimum versions for optional/dev/test/lint dependencies. |
python/uv.lock |
Refreshes resolved Python dependency set to newer versions. |
javascript/package.json |
Raises JS dev dependency versions (Jest/ESLint/TS tooling). |
javascript/package-lock.json |
Refreshes resolved JS dependency graph to match updated devDependencies. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
You can also share your feedback on Copilot code review. Take the survey.
- Drop Node 18 from CI matrix (EOL), add Node 24 - Update engines.node to >=20.0.0 - Align @types/node with highest LTS runtime (^22.0.0) - Add trailing newline to pyproject.toml - Remove duplicate ruff entry in dev-dependencies
There was a problem hiding this comment.
Pull request overview
This PR updates the template’s GitHub Actions and Python/JavaScript dependencies, aiming to consolidate Dependabot updates and address reported security vulnerabilities.
Changes:
- Bumped multiple GitHub Actions versions in CI, CodeQL, and Dependabot auto-merge workflows.
- Updated Python dependency constraints (pyproject) and regenerated
uv.lock. - Updated JavaScript devDependencies (notably Jest/ESLint/tooling) and regenerated
package-lock.json.
Reviewed changes
Copilot reviewed 6 out of 8 changed files in this pull request and generated 4 comments.
Show a summary per file
| File | Description |
|---|---|
.github/workflows/ci-python.yml |
Updates checkout/uv/codecov actions used by Python CI. |
.github/workflows/ci-javascript.yml |
Updates checkout/setup-node actions and adjusts Node test matrix. |
.github/workflows/codeql.yml |
Updates checkout and CodeQL action versions for security scanning. |
.github/workflows/dependabot-auto-merge.yml |
Updates actions/github-script used for Dependabot label check. |
python/pyproject.toml |
Raises Python optional/development dependency minimum versions. |
python/uv.lock |
Regenerates the Python lockfile to reflect updated dependencies. |
javascript/package.json |
Updates Node engine and JS tooling dependencies (Jest/TS/ESLint stack). |
javascript/package-lock.json |
Regenerates npm lockfile after dependency updates. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
You can also share your feedback on Copilot code review. Take the survey.
Bump remaining Actions majors past the March tip, drop EOL Node 20 from CI in favor of 22/24/26, and lock current stable JS/Python versions. Keep TypeScript on 5.9 because typescript-eslint and ts-jest do not support TypeScript 7 yet. Co-authored-by: Erik Peterson <me@erikpeterson.com>
astral-sh/setup-uv stopped publishing floating major/minor tags in v8 (immutable releases). @v10 does not resolve on GitHub Actions. Co-authored-by: Erik Peterson <me@erikpeterson.com>
| "main": "index.js", | ||
| "engines": { | ||
| "node": ">=18.0.0", | ||
| "node": ">=20.0.0", |
There was a problem hiding this comment.
The package advertises Node.js >=20.0.0, but the upgraded ESLint 10 toolchain requires Node.js ^20.19.0 || ^22.13.0 || >=24. Contributors using Node 20.0–20.18 therefore meet the declared engine requirement but cannot reliably run the provided lint scripts. CI now tests only Node 22, 24, and 26, so it will not catch this mismatch. Please raise the declared minimum to Node 20.19 or otherwise align the toolchain and CI with the supported range.
| "node": ">=20.0.0", | |
| "node": ">=20.19.0", |
Knowledge Base Used:
Prompt To Fix With AI
This is a comment left during a code review.
Path: javascript/package.json
Line: 20
Comment:
**Node engine range mismatch**
The package advertises Node.js `>=20.0.0`, but the upgraded ESLint 10 toolchain requires Node.js `^20.19.0 || ^22.13.0 || >=24`. Contributors using Node 20.0–20.18 therefore meet the declared engine requirement but cannot reliably run the provided lint scripts. CI now tests only Node 22, 24, and 26, so it will not catch this mismatch. Please raise the declared minimum to Node 20.19 or otherwise align the toolchain and CI with the supported range.
```suggestion
"node": ">=20.19.0",
```
**Knowledge Base Used:**
- [JavaScript project template](https://app.greptile.com/cloudzero/-/custom-context/knowledge-base/cloudzero/template-cloudzero-open-source/-/docs/javascript-project-template.md)
- [CI and security workflows](https://app.greptile.com/cloudzero/-/custom-context/knowledge-base/cloudzero/template-cloudzero-open-source/-/docs/ci-and-security-workflows.md)
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.Bring README, contributing, security, and GitHub templates current for September 2026. Add markdownlint-cli2 and lychee to Docs CI, expand Python/JS lint coverage, and point Dependabot at uv. Co-authored-by: Erik Peterson <me@erikpeterson.com>
| lint-md: | ||
| npx --yes markdownlint-cli2 |
There was a problem hiding this comment.
The new lint-md target invokes markdownlint-cli2 without a file glob, so it displays help instead of linting the repository. Contributors can therefore get a false local pass even though Docs CI explicitly checks **/*.md. Pass the same glob here and in the documented command so local checks reproduce CI.
| lint-md: | |
| npx --yes markdownlint-cli2 | |
| lint-md: | |
| npx --yes markdownlint-cli2 '**/*.md' |
Knowledge Base Used:
Prompt To Fix With AI
This is a comment left during a code review.
Path: Makefile
Line: 52-53
Comment:
**Markdown lint skips files**
The new `lint-md` target invokes `markdownlint-cli2` without a file glob, so it displays help instead of linting the repository. Contributors can therefore get a false local pass even though Docs CI explicitly checks `**/*.md`. Pass the same glob here and in the documented command so local checks reproduce CI.
```suggestion
lint-md:
npx --yes markdownlint-cli2 '**/*.md'
```
**Knowledge Base Used:**
- [Local development and containers](https://app.greptile.com/cloudzero/-/custom-context/knowledge-base/cloudzero/template-cloudzero-open-source/-/docs/local-development-and-containers.md)
- [CI and security workflows](https://app.greptile.com/cloudzero/-/custom-context/knowledge-base/cloudzero/template-cloudzero-open-source/-/docs/ci-and-security-workflows.md)
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.
Summary
Refresh of this consolidation PR to current (September 2026) stable versions, plus a full template content/docs pass and Docs CI (markdownlint + lychee).
Updates all GitHub Actions, Python (uv), and JavaScript dependencies, including the remaining Dependabot majors that landed after the March 2026 tip (
f2acdaf). Then brings READMEs, contributing/security text, GitHub templates, Dependabot, CODEOWNERS notes, Docker examples, and license year current.Security
JavaScript:
npm auditreports 0 vulnerabilities after the refresh.Python:
pip-auditreports no known vulnerabilities in the locked template extras.Changes beyond
f2acdaf(March 2026)GitHub Actions
actions/checkout: v6 → v7actions/setup-node: v6 → v7actions/github-script: v8 → v9 (script does not userequire('@actions/github'), so the v9 ESM breaking change does not apply)codecov/codecov-action: v5 → v7 (file→filesper the v7 migration; path ispython/coverage.xml)astral-sh/setup-uv: v7 → v10.1.0 (pinned to the immutable release; this action no longer publishes floating@v10major tags)github/codeql-action: remains v4 (latest major; current tagv4.38.0)DavidAnson/markdownlint-cli2-action@v24andlycheeverse/lychee-action@v2(fail: true)Node.js support
engines.noderemains>=20.0.0Python (still 3.11–3.13)
Floors in
pyproject.toml/ lock viauv lock --upgrade:>=0.14.0→>=0.16.0(locked 0.16.7)>=9.0→>=9.1(locked 9.1.1)>=4.1→>=7.1(locked 7.1.0)>=1.36.0→>=1.44.0(locked 1.44.2)>=2.12.0→>=2.13.0(locked 2.13.5)>=3.24.0→>=3.34.0(locked 3.34.0)>=0.28.0(locked 0.28.1, still latest)[dependency-groups](uv sync --extra dev --group dev)JavaScript
@eslint/js:^9.39.1→^10.0.1(installed 10.0.1)eslint:^9.0.0→^10.10.0(installed 10.10.0)@types/node:^22.0.0→^24.13.4(aligned with Active LTS)@typescript-eslint/*/typescript-eslint:^8.53.0→^8.70.0eslint-plugin-jest:^29.2.1→^29.16.6globals:^16.5.0→^17.12.0jest:^30.2.0→^30.5.1prettier:^3.2.0→^3.9.6ts-jest:^29.4.6→^29.4.12typescript: stays on 5.9.3 — TypeScript 7.0.2 is latest npmlatest, buttypescript-eslint@8.70requires<6.1.0andts-jest@29requires<7tsc --noEmit, and Jesthttps://(not deprecatedgit://)Intentionally not taken
Template content and config pass (tip
8fd1dab)Stale or incorrect items that were fixed:
pip+/missedpython/uv.lock; nowuvecosystem on/python, plusdockerfor the example Dockerfileossf/best-practices-badgepath 404s; nowcoreinfrastructure/best-practices-badge)uvfrom the repo root (no rootpyproject.toml); Python targets nowcd python.docker composereplacesdocker-composepython/, uses a namedAS builderstage, Python 3.13FILE-HEADERstyle)diversity→inclusion)python/coverage.xmlNew CI jobs
DavidAnson/markdownlint-cli2-action@v24)*.md(ignoresnode_modules, coverage, venvs)lycheeverse/lychee-action@v2,fail: true)*.md; allowlist is only localhost, example.com, placeholder GitHub paths, mailto, and npmjs.com (403 to bots)JavaScript and Python CI already ran format + lint + tests; JS also type-checks. Workflows now set
permissions: contents: read,fail-fast: false, and cancel outdated PR runs.Consolidates open Dependabot PRs
This tip covers the intent of:
npm_and_yarngroup (transitive security bumps; refreshed via a new lockfile)github/codeql-action3 → 4 (already in this PR)actions/github-script7 → 9astral-sh/setup-uv3 → 7 (this PR goes further to v10.1.0)codecov/codecov-action4 → 7actions/checkout4 → 7jest/@types/jest(Jest 30.5.1)globals16.5.0 → 17.12.0@typescript-eslint/parser→ 8.69.0 (this PR uses 8.70.0)prettier3.6.2 → 3.9.6No conflicts with the Node ≥20 / Jest 30 direction. Those Dependabot PRs target
mainand can be closed after this merges.Breaking changes
engines.nodeis still>=20.0.0.file→filesTesting
npx markdownlint-cli2→ 0 issues (14 Markdown files)lychee --config lychee.toml './**/*.md'→ 0 errorsnpm ci/ Prettier / ESLint /tsc --noEmit/ Jest (local)npm audit→ 0 vulnerabilitiesuv sync --extra dev --group dev/ ruff format+check / pytest (local)8fd1dab(JS 22/24/26, Python 3.11/3.12/3.13, Docs Markdown lint + Link check)codeql.ymlworkflow isdisabled_inactivityon this repo; GitHub default CodeQL setup remains activeChecklist
main