Fix dependabot alerts / dependencies vulnerabilities [October 5th 2026] - #1849
Merged
Merged
Conversation
rwood-moz
approved these changes
Oct 5, 2026
rwood-moz
left a comment
Contributor
There was a problem hiding this comment.
LGTM and I see all the checks passed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed?
Bump version to 1.8.1 and updating dependencies flagged by dependabot where applicable (and there's a new package version for us to update).
pnpm audit)pnpm audit)pnpm audit)Wrote the table with the help of Claude code, otherwise vulnerabilities were found / patched by pnpm audit.
Why?
New day, new dependabot alerts for vulnerabilities.
Limitations and Notes
There's a major bump in
oauthlibbut the breaking changes listed in the repo doesn't affect us and we don't event import it directly anywhere. The paths that would be affected would be the ZoomClient and GoogleClient and both seem to work as expected.Note that I've had to narrowly-er specify the
sqlalchemypinned version inrequirements.txtto be2.0.*instead of2.*since there was a breaking change (ScalarAttributeImpl) from2.1.*and a fresh install of all the packages would fail to build and run the backend container.Also, there are some vulnerabilities that are not yet patched:
Applicable Issues
N/A
QA Log
Manually ran the project locally and went through FTUE + created a booking through a Google Calendar integration.
Screenshots
N/A