Skip to content

chore(deps): bump actions/setup-node from 4 to 6#3

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/actions/setup-node-6
Open

chore(deps): bump actions/setup-node from 4 to 6#3
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/actions/setup-node-6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 15, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/setup-node from 4 to 6.

Release notes

Sourced from actions/setup-node's releases.

v6.0.0

What's Changed

Breaking Changes

Dependency Upgrades

Full Changelog: actions/setup-node@v5...v6.0.0

v5.0.0

What's Changed

Breaking Changes

This update, introduces automatic caching when a valid packageManager field is present in your package.json. This aims to improve workflow performance and make dependency management more seamless. To disable this automatic caching, set package-manager-cache: false

steps:
- uses: actions/checkout@v5
- uses: actions/setup-node@v5
  with:
    package-manager-cache: false

Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. See Release Notes

Dependency Upgrades

New Contributors

Full Changelog: actions/setup-node@v4...v5.0.0

v4.4.0

... (truncated)

Commits

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 6.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v4...v6)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels May 15, 2026

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This repository is configured for manual code reviews. Comment @claude review to trigger a review and subscribe this PR to future pushes, or @claude review once for a one-time review.

Tip: disable this comment in your organization's Code Review settings.

cortexuvula added a commit that referenced this pull request Jun 16, 2026
…a256, SSE logging, fsync, identifier validation)

Addresses CODE_REVIEW_REPORT.md findings #1, #2, #3, #4/#11, #6, #9.
Verified each against the actual code; skipped #5/#7/#8/#10/#12-15 with
documented rationale (low threat model, intentional design, YAGNI).
cortexuvula added a commit that referenced this pull request Jun 20, 2026
…y, lock scoping)

Addresses 9 findings from the codebase bug audit:

Critical:
- #1 Onboarding bypass: gate on a separate onboarding_started sentinel
  (written by the wizard on first save) instead of inferring from
  app_config row existence. An interrupted wizard now reappears on next
  launch instead of being silently auto-marked complete. Adds
  set_onboarding_started command + API wrapper.
- #2 Ollama/LM Studio deadlock: current_base_url cloned the endpoint out
  of the read guard and dropped it before locking the url_cache, fixing
  the AB-BA lock-ordering inversion with set_endpoint.

PHI leaks (AGENTS.md line 6):
- #3 vocabulary.rs: drop find_text from the 'entry added' log.
- #4 whisper_supervisor: allowlist stderr to known-safe diagnostic
  prefixes; drop arbitrary lines (whisper.cpp can emit recognized text).
- #6 peer_discussion.rs: drop physician_name/specialty from the log.

Security:
- #5 Endpoint-policy: validate_local_endpoint at the top of every
  test/probe command (probe_endpoint_reachable, test_lmstudio_connection,
  test_stt_remote_connection, test_ollama_connection) so a crafted
  payload can't reach a public host.

Robustness:
- #7 start_with_gate: separate 'starting' guard so status()/watcher
  don't freeze during the multi-second gate; clean up the whisper child
  on any error path after it started; stop() clears starting too.
- #8 start_sharing_inner: bind ports + start whisper BEFORE taking the
  sharing write lock; only hold the lock for the assignment; stop the
  service on any error after start.
- #9 SSE malformed-event: propagate as a stream error instead of silent
  drop, so a truncated SOAP note surfaces visibly.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants