Skip to content

chore(deps): Bump @spinframework/wasi-http-proxy from 1.0.1 to 2.0.0 in /experiments/003_wasm_compile/js-spin - #46

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/experiments/003_wasm_compile/js-spin/spinframework/wasi-http-proxy-2.0.0
Open

chore(deps): Bump @spinframework/wasi-http-proxy from 1.0.1 to 2.0.0 in /experiments/003_wasm_compile/js-spin#46
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/experiments/003_wasm_compile/js-spin/spinframework/wasi-http-proxy-2.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 31, 2026

Copy link
Copy Markdown
Contributor

Bumps @spinframework/wasi-http-proxy from 1.0.1 to 2.0.0.

Release notes

Sourced from @​spinframework/wasi-http-proxy's releases.

build-tools-v2.0.0

Release v2.0.0 for build-tools published to npm.

spin-postgres-v2.0.0

Release v2.0.0 for spin-postgres published to npm.

wasi-http-proxy-v2.0.0

Release v2.0.0 for wasi-http-proxy published to npm.

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​spinframework/wasi-http-proxy since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@spinframework/wasi-http-proxy](https://github.com/spinframework/spin-js-sdk/tree/HEAD/packages/http-trigger) from 1.0.1 to 2.0.0.
- [Release notes](https://github.com/spinframework/spin-js-sdk/releases)
- [Commits](https://github.com/spinframework/spin-js-sdk/commits/spin/templates/v2.0/packages/http-trigger)

---
updated-dependencies:
- dependency-name: "@spinframework/wasi-http-proxy"
  dependency-version: 2.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 31, 2026
@iheitlager

Copy link
Copy Markdown
Member

Review: holding, not merging yet — see #42

Tested together with #42 (same `@spinframework` v1→v2 release train, same `js-spin/package.json` — merging one without the other leaves a half-upgraded package set). Full findings posted on #42: bumping both introduces a transitive critical vulnerability (`decompress` Zip Slip, GHSA-mp2f-45pm-3cg9) via `build-tools@2.x` → `componentize-js` → `weval` → `decompress`, that isn't present at the current pinned versions. `npm audit`'s own fix suggestion is to downgrade `build-tools` back to 1.0.7.

Not merging either PR until that's resolved (upstream fix, or an `overrides` pin on `decompress`).


🤖 Analysis by Claude

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant