chore(deps): update dependency openai to v6.35.0#3807
chore(deps): update dependency openai to v6.35.0#3807renovate[bot] wants to merge 1 commit intodevelopfrom
Conversation
There was a problem hiding this comment.
Stale comment
Security review (automation): PR #3807
Outcome: No medium, high, or critical findings. The diff only updates
web/package-lock.jsonfor the dev dependencyopenai(6.34.0 → 6.35.0): resolved URL and integrity hash. No application or build script changes.Scope checked: Compared merge base
2b99a7a0to head288b4e1d. No new attack surface in repo code from this PR. Existinggulp-gpt-translate.jsusage is unchanged by this bump.Supply chain: Same registry (
registry.npmjs.org), official package tarball; Snyk’s npmopenaiadvisory data shows no direct CVEs for recent 6.x lines (not a guarantee, but no known disclosed issue tied to this bump).
Slack summary (copy/paste):
PR #3807 (chore(deps): update dependency openai to v6.35.0) — security pass. Lockfile-only bump for devopenai6.34→6.35; no code changes; no medium+ issues identified.Sent by Cursor Automation: Find vulnerabilities
288b4e1 to
c44ac44
Compare
There was a problem hiding this comment.
Security review (automation)
Scope: Diff is limited to web/package-lock.json: openai 6.34.0 → 6.35.0 (same registry URL, updated tarball integrity).
Findings: No medium / high / critical issues introduced by this change with high confidence.
- Application code: No modified source; runtime usage (e.g. dev-time
gulp-gpt-translate/OpenAIclient) is unchanged by this PR. - Supply chain: Official
registry.npmjs.orgartifact with lockfile integrity pinning; no new dependency graph entries beyond the version bump. - Known advisories: No credible public advisory identified tying 6.35.0 to a exploitable vulnerability in this repo’s usage pattern.
Prior automation threads: Resolved via cleanup so this assessment is the active one.
Sent by Cursor Automation: Find vulnerabilities


This PR contains the following updates:
6.34.0→6.35.0Release Notes
openai/openai-node (openai)
v6.35.0Compare Source
Full Changelog: v6.34.0...v6.35.0
Features
Bug Fixes
oidcdir (cf860f6)Chores
Documentation
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.