fix(deps): keep compatibility builds secure - #10
Conversation
yordis
commented
Sep 13, 2026
- Client compatibility must reject vulnerable build dependencies without disabling repository-wide security enforcement.
- Release artifacts need current source-link tooling so downstream compatibility gates remain trustworthy.
Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>
PR SummaryLow Risk Overview This aligns release artifacts with newer Source Link tooling, which supports keeping dependency/security compatibility checks trustworthy without turning off repo-wide enforcement on vulnerable build dependencies. Reviewed by Cursor Bugbot for commit 5620a29. Bugbot is set up for automated code reviews on this repo. Configure here. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. WalkthroughThe build configuration updates ChangesSourceLink package update
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other Merge Risk: ⚪ Minimal · up to This updates SourceLink tooling without an identified build, packaging, or security regression. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the build file bright Comment |