Skip to content

chore(deps): resolve pending Dependabot updates - #14

Merged
jmgilman merged 5 commits into
masterfrom
chore/dependabot-updates
Sep 11, 2026
Merged

jmgilman merged 5 commits into
masterfrom
chore/dependabot-updates

Conversation

@jmgilman

@jmgilman jmgilman commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Updates

Consolidates Dependabot #3 and #5–#10:

  • Proxy Testify 1.12.1.
  • Material for MkDocs 9.7.7, fixing a DOM-based XSS vulnerability in search suggestions.
  • CodeQL upload-sarif 4.37.9; attest and attest-build-provenance 4.2.2; deploy-pages 5.0.1; download-syft 0.24.2.

All action pins were verified against upstream tags, and their used inputs, outputs, runtime requirements, and existing permissions remain compatible. download-syft now defaults to Syft1.51.1; SPDX JSON remains2.3.

SDK proposal #4

Keep the isolated proxy on SDK1.6.1, with the reason documented in its README. SDK1.7 deprecates the MCP logging API and removes logging/setLevel from protocol2026-07-28. Preserving the current logging contract would require deprecated API use under strict SA1019 checks; dropping forwarding or disabling lint is not an acceptable dependency-only change. Production remains on SDK1.7. The exploratory migration was not included.

Verification

  • Complete moon run root:check passes: root/proxy builds, strict lint, formatting, race tests, documentation build, and real MCP smoke.
  • Real SDK1.7 client verified proxy discovery, deterministic composition, invalid arguments, cancellation, recovery, in-flight hot reload, and replacement capability execution on the same session.
  • Require green CI and explicitly dispatched binary/container release rehearsal before merge.

After merge, close the seven superseded Dependabot PRs and close #4 with the compatibility explanation. Do not merge or publish the pending release PR.

Final verification

Linux CI exposed an existing logging-test race: the fixture acknowledged logging/setLevel before the SDK applied it. The fixture now signals only after successful application; the logging passthrough test passed 100 race-detector repetitions. Production logging code is unchanged.

All PR checks and binary/container release rehearsal passed at commit 2c2bd18651ef5c1676d692c0e1f1bfbea829c405.

Apply the five open Dependabot GitHub Actions proposals in one change:

- github/codeql-action/upload-sarif 4.36.2 -> 4.37.9 (PR #6)
- actions/attest-build-provenance 4.1.1 -> 4.2.2 (PR #7)
- actions/attest 4.1.0 -> 4.2.2 (PR #8)
- actions/deploy-pages 5.0.0 -> 5.0.1 (PR #9)
- anchore/sbom-action/download-syft 0.24.0 -> 0.24.2 (PR #10)

Every SHA was verified against the upstream tag object, and the inputs
used here (sarif_file/category, subject-checksums, subject-name/digest,
push-to-registry) plus the deploy-pages page_url output are unchanged in
the new revisions. download-syft now installs Syft v1.51.1 instead of
v1.42.3; SPDX JSON still defaults to 2.3, so the goreleaser and apko SBOM
paths keep producing what actions/attest-sbom consumes.
Acknowledge logging/setLevel only after the SDK handler succeeds so the passthrough test cannot emit its message before logging is enabled.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant