Skip to content

chore(deps): Consolidated dependency updates#2582

Merged
cmgrote merged 1 commit into
mainfrom
dependencies
Jun 22, 2026
Merged

chore(deps): Consolidated dependency updates#2582
cmgrote merged 1 commit into
mainfrom
dependencies

Conversation

@cmgrote

@cmgrote cmgrote commented Jun 22, 2026

Copy link
Copy Markdown
Collaborator

Summary

Consolidates 3 dependency PRs into a single update.

Updates

Dependency Version Change Original PR
awssdk 2.46.13 → 2.46.15 #2581
io.opentelemetry:opentelemetry-bom 1.62.0 → 1.63.0 #2555
io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha 2.28.1-alpha → 2.29.0-alpha #2578

Original PRs

The following PRs are consolidated in this update:

Not included: #2580 (gradle-wrapper 8.14.3 → 9.6.0, excluded per request)


Generated by /consolidate-deps skill

Consolidates updates from the following dependency PRs:
- #2581: chore(deps): Bump awssdk from 2.46.13 to 2.46.15
- #2555: chore(deps): Bump io.opentelemetry:opentelemetry-bom from 1.62.0 to 1.63.0
- #2578: chore(deps): Bump io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha from 2.28.1-alpha to 2.29.0-alpha

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Chris (He/Him) <cgrote@gmail.com>
@cmgrote cmgrote added the dependencies Pull requests that update a dependency file label Jun 22, 2026
@cmgrote cmgrote enabled auto-merge (squash) June 22, 2026 08:26
@socket-security

Copy link
Copy Markdown

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: maven org.apache.httpcomponents.core5:httpcore5 is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?maven/co.elastic.clients/elasticsearch-java@9.4.2maven/org.apache.httpcomponents.core5/httpcore5@5.4

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/org.apache.httpcomponents.core5/httpcore5@5.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@cmgrote cmgrote merged commit cac42d7 into main Jun 22, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant