Skip to content

[Snyk] Security upgrade @vscode/extension-telemetry from 0.8.5 to 0.9.0#14376

Merged
austin3dickey merged 1 commit into
mainfrom
snyk-fix-c37197ebb90c1f892613be706166e505
Jun 22, 2026
Merged

[Snyk] Security upgrade @vscode/extension-telemetry from 0.8.5 to 0.9.0#14376
austin3dickey merged 1 commit into
mainfrom
snyk-fix-c37197ebb90c1f892613be706166e505

Conversation

@posit-snyk-bot

Copy link
Copy Markdown
Contributor

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • extensions/positron-python/package.json
  • extensions/positron-python/package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-OPENTELEMETRYCORE-17373280
  111  

Breaking Change Risk

Merge Risk: Low

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Allocation of Resources Without Limits or Throttling

…thon/package-lock.json to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-OPENTELEMETRYCORE-17373280
@posit-snyk-bot

Copy link
Copy Markdown
Contributor Author

Merge Risk: Low

This is a minor version upgrade. The release notes for version 0.9.0 indicate that the changes are limited to internal dependency updates and a migration of the project's linting configuration. There are no documented API changes or breaking changes for consumers of the package.

Changes in v0.9.0:

  • Updates to direct dependencies.
  • Bumps of brace-expansion, flatted, and minimatch.
  • Migration to ESLint 9.

Source: GitHub Releases

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@github-actions

Copy link
Copy Markdown

E2E Tests 🚀
This PR will run tests tagged with: @:critical

readme  valid tags

@juliasilge

Copy link
Copy Markdown
Member

@austin3dickey can you evaluate if we should take this bump? We turn off all the Microsoft telemetry but having the version that triggers security checks is not good for us.

@juliasilge juliasilge requested a review from austin3dickey June 22, 2026 13:16
@austin3dickey

Copy link
Copy Markdown
Contributor

The upstream change that bumps this is microsoft/vscode-python#26007, which bumps the major version. But this minor version bump should be fine in the meantime while we wait for that to be merged.

@austin3dickey austin3dickey merged commit f0698b3 into main Jun 22, 2026
48 checks passed
@austin3dickey austin3dickey deleted the snyk-fix-c37197ebb90c1f892613be706166e505 branch June 22, 2026 17:00
@github-actions github-actions Bot locked and limited conversation to collaborators Jun 22, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants