Skip to content

chore(deps-dev): bump @smithy/signature-v4 from 5.7.2 to 5.7.3 - #2679

Merged
HAYDEN-OAI merged 1 commit into
mainfrom
dependabot/npm_and_yarn/smithy/signature-v4-5.7.3
Sep 7, 2026
Merged

chore(deps-dev): bump @smithy/signature-v4 from 5.7.2 to 5.7.3#2679
HAYDEN-OAI merged 1 commit into
mainfrom
dependabot/npm_and_yarn/smithy/signature-v4-5.7.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor

Bumps @smithy/signature-v4 from 5.7.2 to 5.7.3.

Changelog

Sourced from @​smithy/signature-v4's changelog.

5.7.3

Patch Changes

  • a825452: switch for-in loops to guarded
  • Updated dependencies [e82a22b]
  • Updated dependencies [a825452]
    • @​smithy/core@​3.33.3
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@smithy/signature-v4](https://github.com/smithy-lang/smithy-typescript/tree/HEAD/packages/signature-v4) from 5.7.2 to 5.7.3.
- [Release notes](https://github.com/smithy-lang/smithy-typescript/releases)
- [Changelog](https://github.com/smithy-lang/smithy-typescript/blob/main/packages/signature-v4/CHANGELOG.md)
- [Commits](https://github.com/smithy-lang/smithy-typescript/commits/@smithy/signature-v4@5.7.3/packages/signature-v4)

---
updated-dependencies:
- dependency-name: "@smithy/signature-v4"
  dependency-version: 5.7.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 7, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 7, 2026 15:16
@dependabot dependabot Bot added the javascript Pull requests that update javascript code label Sep 7, 2026
@openai-sdks

openai-sdks Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

OkTest Summary

236/236 SDK tests passed in 11.724s for Node SDK PR #2679.

Test results — 42 files
Test Result Time
tests/chat-completions-complex-body.test.ts ✅ Passed 157ms
tests/chat-completions-create.test.ts ✅ Passed 282ms
tests/chat-completions-stream.test.ts ✅ Passed 203ms
tests/files-content-binary.test.ts ✅ Passed 254ms
tests/files-create-multipart.test.ts ✅ Passed 345ms
tests/files-list-pagination.test.ts ✅ Passed 218ms
tests/initialize-config.test.ts ✅ Passed 224ms
tests/instance-isolation.test.ts ✅ Passed 211ms
tests/models-list.test.ts ✅ Passed 305ms
tests/responses-background-lifecycle.test.ts ✅ Passed 367ms
tests/responses-body-method-errors.test.ts ✅ Passed 316ms
tests/responses-cancel-timeout.test.ts ✅ Passed 198ms
tests/responses-cancel.test.ts ✅ Passed 316ms
tests/responses-compact-retries.test.ts ✅ Passed 349ms
tests/responses-compact.test.ts ✅ Passed 338ms
tests/responses-create-advanced-stream.test.ts ✅ Passed 116ms
tests/responses-create-advanced.test.ts ✅ Passed 250ms
tests/responses-create-disconnect.test.ts ✅ Passed 1.168s
tests/responses-create-errors.test.ts ✅ Passed 219ms
tests/responses-create-malformed-api-responses.test.ts ✅ Passed 312ms
tests/responses-create-retries.test.ts ✅ Passed 280ms
tests/responses-create-stream-failures.test.ts ✅ Passed 196ms
tests/responses-create-stream-timeout.test.ts ✅ Passed 2.173s
tests/responses-create-stream-wire.test.ts ✅ Passed 2.712s
tests/responses-create-stream.test.ts ✅ Passed 100ms
tests/responses-create-terminal-states.test.ts ✅ Passed 258ms
tests/responses-create-timeout.test.ts ✅ Passed 202ms
tests/responses-create.test.ts ✅ Passed 296ms
tests/responses-delete.test.ts ✅ Passed 257ms
tests/responses-input-items-errors.test.ts ✅ Passed 216ms
tests/responses-input-items-list.test.ts ✅ Passed 195ms
tests/responses-input-items-options.test.ts ✅ Passed 264ms
tests/responses-input-tokens-count-timeout.test.ts ✅ Passed 222ms
tests/responses-input-tokens-count.test.ts ✅ Passed 306ms
tests/responses-malformed-inputs.test.ts ✅ Passed 2.304s
tests/responses-not-found-errors.test.ts ✅ Passed 298ms
tests/responses-parse.test.ts ✅ Passed 304ms
tests/responses-retrieve-retries.test.ts ✅ Passed 293ms
tests/responses-retrieve.test.ts ✅ Passed 299ms
tests/responses-stored-method-errors.test.ts ✅ Passed 711ms
tests/retry-behavior.test.ts ✅ Passed 3.1s
tests/sdk-error-shape.test.ts ✅ Passed 290ms

View OkTest run #34137466694

SDK merge (e19ee6be9b78) · head (559fcfe888e4) · base (fdb038e21509) · OkTest (08ec4299e769)

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Castiron custom code

✅ No new custom-code files detected.

32 mixed files remain; 0 existing customizations changed.

Compared fdb038e21509559fcfe888e4. Generated baselines verified.

32 existing customizations unchanged
  • api.md
  • scripts/castiron/README.md
  • scripts/castiron/custom_code_report.py
  • scripts/castiron/test_custom_code_report.py
  • src/client.ts
  • src/resources/audio/transcriptions.ts
  • src/resources/audio/translations.ts
  • src/resources/beta/assistants.ts
  • src/resources/beta/beta.ts
  • src/resources/beta/index.ts
  • src/resources/beta/responses/internal-base.ts
  • src/resources/beta/responses/responses.ts
  • src/resources/beta/threads/index.ts
  • src/resources/beta/threads/runs/index.ts
  • src/resources/beta/threads/runs/runs.ts
  • src/resources/beta/threads/threads.ts
  • src/resources/chat/completions/completions.ts
  • src/resources/chat/completions/index.ts
  • src/resources/conversations/index.ts
  • src/resources/embeddings.ts
  • src/resources/files.ts
  • src/resources/fine-tuning/checkpoints/permissions.ts
  • src/resources/images.ts
  • src/resources/responses/internal-base.ts
  • src/resources/responses/responses.ts
  • src/resources/skills/skills.ts
  • src/resources/skills/versions/versions.ts
  • src/resources/vector-stores/file-batches.ts
  • src/resources/vector-stores/files.ts
  • src/resources/webhooks/index.ts
  • src/resources/webhooks/webhooks.ts
  • tests/lib/data-residency.test.ts

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 34137508094 --repo openai/openai-node \
  --name castiron-custom-code-34137508094-1 --dir /tmp/castiron-custom-code-34137508094-1
git apply --stat /tmp/castiron-custom-code-34137508094-1/custom-code.patch
cat /tmp/castiron-custom-code-34137508094-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin fdb038e21509264bcdf81741a40988dd694188b1 559fcfe888e4b8f27dfeb1cf16f41563661b2d58
python3 scripts/castiron/custom_code_report.py report \
  --base fdb038e21509264bcdf81741a40988dd694188b1 \
  --head 559fcfe888e4b8f27dfeb1cf16f41563661b2d58 --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-559fcfe888e4
cat /tmp/castiron-custom-code-559fcfe888e4/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 559fcfe888

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread pnpm-lock.yaml
dependencies:
lightningcss: 1.33.0
picomatch: 4.0.5
picomatch: 4.0.7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Restore Vite's unrelated picomatch resolution

For this targeted @smithy/signature-v4 bump, changing Vite's independent picomatch dependency from 4.0.5 to 4.0.7 adds unrelated toolchain behavior and review surface; the lock graph shows that the updated Smithy package instead depends only on @smithy/core, @smithy/types, and tslib. Restore this edge to 4.0.5 so the lockfile contains only the requested package and its dependency closure.

AGENTS.md reference: AGENTS.md:L150-L153

Useful? React with 👍 / 👎.

@HAYDEN-OAI HAYDEN-OAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed at 559fcfe. No blocking correctness or Node-version-policy findings. The Smithy Node >=18 requirement remains below the SDK's >=22.0.0 floor; CJS/ESM support and optional-peer isolation are preserved.

Validation: current-head CI passed, including supported-line packed-package and TypeScript 4.9/6 checks. Locally, the exact head passed frozen installation with existing supply-chain policies, a Node 24 build, and 192 focused Bedrock tests. Real credential-chain and SigV4 smoke tests passed through the public CJS/ESM entrypoints on exact Node 22.0.0, including service scopes and payload hashes.

Nonblocking scope note: the lockfile also updates Vite's picomatch edge from 4.0.5 to 4.0.7. Reviewed that development-only change; no resulting defect found.

@HAYDEN-OAI
HAYDEN-OAI added this pull request to the merge queue Sep 7, 2026
Merged via the queue into main with commit 41ca20d Sep 7, 2026
33 checks passed
@HAYDEN-OAI
HAYDEN-OAI deleted the dependabot/npm_and_yarn/smithy/signature-v4-5.7.3 branch September 7, 2026 17:24
@openai-sdks openai-sdks Bot mentioned this pull request Sep 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant