Skip to content

Refresh Graphify and Highlight.js dependencies - #114

Merged
bifrost0x merged 1 commit into
mainfrom
dev/dependency-refresh-august
Aug 17, 2026
Merged

Refresh Graphify and Highlight.js dependencies#114
bifrost0x merged 1 commit into
mainfrom
dev/dependency-refresh-august

Conversation

@bifrost0x

Copy link
Copy Markdown
Owner

Summary

  • update Graphify from 0.9.39 to 0.9.42 and regenerate the hash-locked graph requirements
  • update Highlight.js assets from 11.11.2 to 11.12.0 and refresh the committed vendor bundle
  • fix the privileged Dependabot vendor workflow so it checks out the validated PR head before generation and verifies trusted helper-script checksums before execution
  • apply available Debian security updates in both container stages so the current pinned base image no longer ships the fixable util-linux CVE-2026-53615

This consolidates the dependency changes from #112 and #113.

Verification

  • scripts/lock_requirements.ps1 -Check
  • pytest tests -q - 1,587 passed, 33 skipped
  • focused dependency and supply-chain policy tests - 62 passed
  • npm run vendor:check
  • npm run lint:js
  • npm run test:js - 200 passed
  • npm run test:e2e - 65 passed, one unrelated one-off failure; the failed case passed on an isolated rerun
  • git diff --check

Container build and multi-architecture Trivy results are left to the pull request workflows because the local Docker engine is unavailable.

@bifrost0x
bifrost0x marked this pull request as ready for review August 17, 2026 11:18
@bifrost0x
bifrost0x merged commit e0da8f1 into main Aug 17, 2026
15 of 16 checks passed
@bifrost0x
bifrost0x deleted the dev/dependency-refresh-august branch August 17, 2026 11:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant