Skip to content

chore(sync): main → develop tras el barrido de dependabot - #688

Merged
beyondnetPeru merged 22 commits into
developfrom
main
Sep 5, 2026
Merged

chore(sync): main → develop tras el barrido de dependabot#688
beyondnetPeru merged 22 commits into
developfrom
main

Conversation

@beyondnetPeru

Copy link
Copy Markdown
Contributor

Sincroniza main en develop tras mergear el barrido de dependabot.

Lo que arrastra (8 bumps, todos ya en main):

  • Acciones: github/codeql-action 4.37.3→4.37.9, codeql-action/upload-sarif, actions/setup-node 4→7, softprops/action-gh-release 1→3.
  • npm: @nestjs/cli 11.0.24, @commitlint/cli 21.2.2, @typescript-eslint/eslint-plugin 8.67.0, @opentelemetry/auto-instrumentations-node 0.79.0.

Cada uno se mergeó con los 9 checks requeridos en verde. Los rojos que se ven en esos PRs (Security Audit, Governance guards, build-and-test, Trivy) no son requeridos y son previos a los bumps: Security Audit viene rojo en main desde b84523b4 (02-sep) por GHSA-jqff-g426-hqxp en fast-uri, que va en su propio PR.

Queda fuera #668 (source-map-support), en conflicto de package-lock.json tras estos merges.

🤖 Generated with Claude Code

dependabot Bot and others added 20 commits August 26, 2026 17:05
Bumps [@nestjs/cli](https://github.com/nestjs/nest-cli) from 11.0.23 to 11.0.24.
- [Release notes](https://github.com/nestjs/nest-cli/releases)
- [Commits](nestjs/nest-cli@11.0.23...11.0.24)

---
updated-dependencies:
- dependency-name: "@nestjs/cli"
  dependency-version: 11.0.24
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) from 8.62.0 to 8.67.0.
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.67.0/packages/eslint-plugin)

---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.67.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@commitlint/cli](https://github.com/conventional-changelog/commitlint/tree/HEAD/@commitlint/cli) from 20.5.3 to 21.2.2.
- [Release notes](https://github.com/conventional-changelog/commitlint/releases)
- [Changelog](https://github.com/conventional-changelog/commitlint/blob/master/@commitlint/cli/CHANGELOG.md)
- [Commits](https://github.com/conventional-changelog/commitlint/commits/v21.2.2/@commitlint/cli)

---
updated-dependencies:
- dependency-name: "@commitlint/cli"
  dependency-version: 21.2.2
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [@opentelemetry/auto-instrumentations-node](https://github.com/open-telemetry/opentelemetry-js-contrib/tree/HEAD/packages/auto-instrumentations-node) from 0.78.0 to 0.79.0.
- [Release notes](https://github.com/open-telemetry/opentelemetry-js-contrib/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-js-contrib/blob/main/packages/auto-instrumentations-node/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-js-contrib/commits/auto-instrumentations-node-v0.79.0/packages/auto-instrumentations-node)

---
updated-dependencies:
- dependency-name: "@opentelemetry/auto-instrumentations-node"
  dependency-version: 0.79.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 4.37.3 to 4.37.9.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@e4fba86...cdf488f)

---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.37.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 1 to 3.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@v1...v3)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v4...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.37.3 to 4.37.9.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v4.37.3...v4.37.9)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.37.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
…github/codeql-action-4.37.9

chore(deps): bump github/codeql-action from 4.37.3 to 4.37.9
…github/codeql-action/upload-sarif-4.37.9

chore(deps): bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.9
…actions/setup-node-7

chore(deps): bump actions/setup-node from 4 to 7
…softprops/action-gh-release-3

chore(deps): bump softprops/action-gh-release from 1 to 3
…stjs/cli-11.0.24

chore(deps-dev): bump @nestjs/cli from 11.0.23 to 11.0.24
…mmitlint/cli-21.2.2

chore(deps-dev): bump @commitlint/cli from 20.5.3 to 21.2.2
…pescript-eslint/eslint-plugin-8.67.0

chore(deps-dev): bump @typescript-eslint/eslint-plugin from 8.62.0 to 8.67.0
…entelemetry/auto-instrumentations-node-0.79.0

chore(deps): bump @opentelemetry/auto-instrumentations-node from 0.78.0 to 0.79.0
@beyondnetPeru
beyondnetPeru requested a review from a team as a code owner September 5, 2026 23:32
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown

📊 Bilingual Coverage Impact

PR Changes

  • Paired EN/ES files modified: 0
  • New EN files needing ES translation: 0

Repository Coverage

Metric Value
Total EN files 527
Total ES files 497
Paired files 0
Coverage 0%

Good: All EN changes have ES counterparts.


Generated by GitHub Actions

beyondnetPeru and others added 2 commits September 5, 2026 18:35
… del arreglo

`Security Audit` lleva rojo en `main` desde `b84523b4` (2026-09-02). La causa
no es una dependencia sin arreglo: son dos pins propios que se quedaron por
debajo de la version parcheada, y el gate los reporta como advisories ajenas.

`overrides.fast-uri` estaba fijado en `3.1.5` — exactamente la ultima version
vulnerable de la rama 3.x. GHSA-jqff-g426-hqxp parchea en `3.1.6`, dentro del
`^3.0.1` que declara `ajv@8.20.0`, asi que el arreglo cabia en el pin que ya
existia. Medido con el propio gate y no inferido del changelog: las cuatro
advisories de `fast-uri` y las cinco filas de la cadena `ajv`/`commitlint`
que llegaban *via* `fast-uri` desaparecen — 9 de las 11 filas bloqueantes.

Las dos restantes eran `browserslist`, tambien un transitivo solo-dev
(`ts-jest`→`@babel/core` y `@nestjs/cli`→`webpack`) con arreglo publicado en
`4.28.7`; se pinea `4.28.9` con la misma forma de override que el propio
workflow prescribe para este caso.

Verificado con `63-validate-npm-audit-gate.mjs`, el mismo guard que corre CI,
sobre este arbol: de 11 filas bloqueantes / 7 altas a **0 bloqueantes, 0
altas**. La moderada de `qs` sobrevive a proposito: el gate no bloquea por
debajo de HIGH.

Lo que merece llevarse no es la CVE sino el modo de fallo: un `overrides`
puesto para cerrar un advisory se convierte en el techo que impide cerrarlo
la siguiente vez, y nadie lo revisa porque parece configuracion resuelta.
Mismo patron que GT-691, donde la vigilancia estaba atada a un major que no
habia salido.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…6-hqxp

fix(deps): que el pin de un override no se quede un parche por debajo del arreglo
@beyondnetPeru
beyondnetPeru merged commit 5e1fa83 into develop Sep 5, 2026
93 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant