Skip to content

chore: upgrade observability-kit to 25.4-SNAPSHOT - #9523

Merged
ZheSun88 merged 2 commits into
mainfrom
chore/observability-kit-25.4-snapshot
Sep 28, 2026
Merged

ZheSun88 merged 2 commits into
mainfrom
chore/observability-kit-25.4-snapshot

Conversation

@totally-not-ai

@totally-not-ai totally-not-ai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

This change moves the Observability Kit starter from version 5.0.0 to 25.4-SNAPSHOT. The new version matches the platform's version numbering.

What changed

  • In versions.json, observability-kit-starter now points to 25.4-SNAPSHOT instead of 5.0.0.
  • Behavior change: Apps that use the Observability Kit starter through the platform now get a SNAPSHOT (pre-release) build. This build can change until a final release replaces it. Apps that don't use Observability Kit are not affected.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Artur-
Artur- marked this pull request as ready for review September 28, 2026 12:24
@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Dependencies Report

  • 🟠 Known Vulnerabilities:

    • Vulnerabilities in: pkg:npm/%40apidevtools/json-schema-ref-parser@11.7.2 [CVE-2026-15195] (oss-bomber)
      👌 The cve carries a git only range with no version mapping. The affected releases are 15.3.0 to 15.3.5, fixed in 15.3.6, while 11.7.2 predates that line by 17 months. It arrives through swagger-parser 10.1.1, which pins it exactly.
      ·
    • Vulnerabilities in: pkg:npm/source-map-js@1.2.1 [CVE-2026-93749] (oss-bomber)
      👌 Build-time only: source-map-js is a dev dependency of postcss used by Vite during build/dev and is not shipped in production bundles. Exploitation requires feeding a crafted indexed source map into the developer's own build (event-loop DoS only). No fixed version is published on npm yet (1.2.1 is latest); upgrade once available.
      ·
    • Vulnerabilities in: pkg:maven/me.friwi/jcef-api@jcef-ca49ada%2Bcef-135.0.20%2Bge7de5c3%2Bchromium-135.0.7049.85 [CVE-2024-21639, CVE-2024-21640, CVE-2024-9410] (owasp)
      👌 Wait for the update from the jcefmaven community. Meanwhile the swing-kit is supposed to be used with fixed websites and not to browse the internet, we have a check for that, so the only possible attacker would be the same person that created the swing application, aka our customer devs. so this vulnerability is not classified by us as critical issue
      · cpe:2.3:a:chromiumembedded:chromium_embedded_framework::::::::
      · cpe:2.3:a:ada:ada::::::::
    • Vulnerabilities in: pkg:maven/io.opentelemetry/opentelemetry-api@1.65.0 [CVE-2026-54285] (owasp)
      👌 False positive: the advisory is for opentelemetry-js (@opentelemetry/core W3CBaggagePropagator.extract(), fixed in JS 2.8.0) and its only CPE targets node.js. io.opentelemetry is opentelemetry-java, an unrelated codebase on its own 1.x line, so the version range matches only by CPE collision; osv-scanner and ossindex report nothing for this coordinate. It reaches the sbom transitively through selenium-remote-driver under vaadin-testbench, a test only dependency.
      · cpe:2.3:a:opentelemetry:opentelemetry::::::node.js::*
    • Vulnerabilities in: pkg:maven/com.vaadin/vaadin-swing-kit-flow@3.0.1 [CVE-2021-33604] (owasp)
      👌 false report: this CVE is targeting Vaadin version prior 20, swing-kit-flow is using vaadin 24+ version, the related issue has been fixed.
      · cpe:2.3:a:vaadin:flow-server::::::::
      · cpe:2.3:a:vaadin:vaadin::::::::
  • 📔 No Core License Issues

  • 📔 No License Issues

  • 🟠 Changes in 25.4-SNAPSHOT since V25.3.0-rc1

    • 6 packages added (6 external, 0 vaadin)
    • 246 packages modified (20 external, 226 vaadin)
    • 402 packages same (386 external, 16 vaadin)

[Click for more Details]

source-map-js is a build-time dev dependency of postcss (via Vite) and is
not shipped in production bundles. No fixed version is published on npm.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ZheSun88
ZheSun88 enabled auto-merge (squash) September 28, 2026 13:38
@ZheSun88
ZheSun88 merged commit d9bcfc5 into main Sep 28, 2026
4 checks passed
@ZheSun88
ZheSun88 deleted the chore/observability-kit-25.4-snapshot branch September 28, 2026 13:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant