Skip to content

Add Renovate ownership of MessagePack pinned transitive dependency#6471

Merged
trmartin4 merged 1 commit intomainfrom
platform/add-messagepack
Mar 5, 2026
Merged

Add Renovate ownership of MessagePack pinned transitive dependency#6471
trmartin4 merged 1 commit intomainfrom
platform/add-messagepack

Conversation

@trmartin4
Copy link
Member

@trmartin4 trmartin4 commented Oct 20, 2025

🎟️ Tracking

#5745

📔 Objective

We pin the MessagePack transitive dependency.

This PR assigns ownership of those updates to Platform. As you can see in #5745, they currently do not have an owner.

⏰ Reminders before review

  • Contributor guidelines followed
  • All formatters and local linters executed and passed
  • Written new unit and / or integration tests where applicable
  • Protected functional changes with optionality (feature flags)
  • Used internationalization (i18n) for all UI strings
  • CI builds passed
  • Communicated to DevOps any deployment requirements
  • Updated any necessary documentation (Confluence, contributing docs) or informed the documentation team

🦮 Reviewer guidelines

  • 👍 (:+1:) or similar for great changes
  • 📝 (:memo:) or ℹ️ (:information_source:) for notes or general info
  • ❓ (:question:) for questions
  • 🤔 (:thinking:) or 💭 (:thought_balloon:) for more open inquiry that's not quite a confirmed issue and could potentially benefit from discussion
  • 🎨 (:art:) for suggestions / improvements
  • ❌ (:x:) or ⚠️ (:warning:) for more significant problems or concerns needing attention
  • 🌱 (:seedling:) or ♻️ (:recycle:) for future improvements or indications of technical debt
  • ⛏ (:pick:) for minor or nitpick changes

@trmartin4 trmartin4 changed the title Added Renovate ownership of MessagePack pinned transitive dependency Add Renovate ownership of MessagePack pinned transitive dependency Oct 20, 2025
@trmartin4 trmartin4 marked this pull request as ready for review October 20, 2025 16:10
@trmartin4
Copy link
Member Author

Tagged you @justindbaur to make sure this was the intended result (or at least an acceptable side-effect) of pinning this transitive dependency.

@github-actions
Copy link
Contributor

Logo
Checkmarx One – Scan Summary & Details3567c7ff-e3b7-48b7-88c7-b93c7c95f5d2

Fixed Issues (100)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
CRITICAL Stored_XSS /src/SharedWeb/Health/HealthCheckServiceExtensions.cs: 61
CRITICAL Stored_XSS /util/Server/Startup.cs: 57
MEDIUM CSRF /src/Api/Billing/Controllers/VNext/OrganizationBillingVNextController.cs: 108
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1432
MEDIUM CSRF /src/Api/Dirt/Controllers/OrganizationReportsController.cs: 264
MEDIUM CSRF /src/Api/Dirt/Controllers/OrganizationReportsController.cs: 213
MEDIUM CSRF /src/Api/Dirt/Controllers/OrganizationReportsController.cs: 169
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1432
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1432
MEDIUM CSRF /src/Api/AdminConsole/Controllers/GroupsController.cs: 289
MEDIUM CSRF /src/Api/Controllers/CollectionsController.cs: 176
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1407
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1526
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1459
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: 266
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1315
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: 346
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: 337
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: 337
MEDIUM CSRF /src/Api/Billing/Controllers/VNext/OrganizationBillingVNextController.cs: 96
MEDIUM CSRF /src/Api/Billing/Controllers/VNext/ProviderBillingVNextController.cs: 82
MEDIUM CSRF /src/Api/Billing/Controllers/VNext/AccountBillingVNextController.cs: 60
MEDIUM CSRF /src/Api/Billing/Controllers/VNext/OrganizationBillingVNextController.cs: 50
MEDIUM CSRF /src/Api/Billing/Controllers/VNext/ProviderBillingVNextController.cs: 40
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1250
MEDIUM CSRF /src/Api/KeyManagement/Controllers/AccountsKeyManagementController.cs: 137
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: 477
MEDIUM CSRF /src/Api/KeyManagement/Controllers/AccountsKeyManagementController.cs: 97
MEDIUM CSRF /src/Api/Vault/Controllers/SecurityTaskController.cs: 66
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: 675
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: 207
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: 360
MEDIUM CSRF /src/Api/Auth/Controllers/EmergencyAccessController.cs: 173
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: 387
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: 182
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: 116
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: 618
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: 595
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 857
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 857
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 857
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 857
MEDIUM CSRF /src/Api/NotificationCenter/Controllers/NotificationsController.cs: 67
MEDIUM CSRF /src/Api/NotificationCenter/Controllers/NotificationsController.cs: 61
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1459
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 817
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 817
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 785
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 785
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 817
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 817
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 785
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 785
MEDIUM CSRF /src/Api/AdminConsole/Controllers/GroupsController.cs: 138
MEDIUM CSRF /src/Api/AdminConsole/Controllers/GroupsController.cs: 166
MEDIUM CSRF /src/Api/AdminConsole/Controllers/GroupsController.cs: 166
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: 366
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: 366
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: 512
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1459
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: 279
MEDIUM CSRF /src/Api/AdminConsole/Controllers/OrganizationUsersController.cs: 279
MEDIUM CSRF /bitwarden_license/src/Scim/Controllers/v2/GroupsController.cs: 99
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1050
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1154
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/GroupsController.cs: 136
MEDIUM CSRF /bitwarden_license/src/Scim/Controllers/v2/GroupsController.cs: 89
MEDIUM CSRF /src/Api/Controllers/CollectionsController.cs: 208
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 222
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1407
MEDIUM CSRF /src/Api/AdminConsole/Controllers/ProviderUsersController.cs: 183
MEDIUM CSRF /src/Api/AdminConsole/Controllers/ProviderUsersController.cs: 202
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 299
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 714
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1507
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/MembersController.cs: 217
MEDIUM CSRF /src/Api/Auth/Controllers/AccountsController.cs: 536
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/GroupsController.cs: 164
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 299
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 197
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 714
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/MembersController.cs: 180
MEDIUM CSRF /src/Api/AdminConsole/Public/Controllers/MembersController.cs: 180
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 167
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 251
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1088
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 1017
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 737
MEDIUM CSRF /src/Api/Vault/Controllers/CiphersController.cs: 737
MEDIUM CSRF /src/Api/Auth/Controllers/WebAuthnController.cs: 153
MEDIUM SSL_Verification_Bypass /src/Core/Services/Implementations/MailKitSmtpMailDeliveryService.cs: 84
MEDIUM Use_Of_Hardcoded_Password /src/Identity/IdentityServer/RequestValidators/SendAccess/SendAccessConstants.cs: 115
MEDIUM Use_Of_Hardcoded_Password /src/Core/Constants.cs: 199
MEDIUM Use_Of_Hardcoded_Password /src/Identity/IdentityServer/RequestValidators/SendAccess/SendAccessConstants.cs: 62
MEDIUM Use_Of_Hardcoded_Password /src/Identity/IdentityServer/RequestValidators/SendAccess/SendAccessConstants.cs: 58
MEDIUM Use_Of_Hardcoded_Password /src/Identity/IdentityServer/RequestValidators/SendAccess/SendAccessConstants.cs: 26
MEDIUM Use_Of_Hardcoded_Password /src/Identity/IdentityServer/RequestValidators/DeviceValidator.cs: 43
MEDIUM Use_Of_Hardcoded_Password /src/Core/KeyManagement/Sends/SendPasswordHasherServiceCollectionExtensions.cs: 14
MEDIUM Use_Of_Hardcoded_Password /src/Core/Constants.cs: 227
MEDIUM Use_Of_Hardcoded_Password /util/Seeder/Factories/UserSeeder.cs: 14

@codecov
Copy link

codecov bot commented Oct 20, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 50.99%. Comparing base (629672c) to head (89f4eea).
⚠️ Report is 541 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #6471   +/-   ##
=======================================
  Coverage   50.99%   50.99%           
=======================================
  Files        1885     1885           
  Lines       83248    83248           
  Branches     7359     7359           
=======================================
  Hits        42450    42450           
  Misses      39186    39186           
  Partials     1612     1612           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@trmartin4 trmartin4 merged commit fa5fde5 into main Mar 5, 2026
37 of 39 checks passed
@trmartin4 trmartin4 deleted the platform/add-messagepack branch March 5, 2026 18:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants