Skip to content

Resolve performance harness dependency alerts - #1

Closed
JacksonWeber wants to merge 1 commit into
mainfrom
jacksonweber-microsoft-resolve-performance-dependency-alerts
Closed

Resolve performance harness dependency alerts#1
JacksonWeber wants to merge 1 commit into
mainfrom
jacksonweber-microsoft-resolve-performance-dependency-alerts

Conversation

@JacksonWeber

Copy link
Copy Markdown
Owner

Summary

  • update the performance harness OpenTelemetry logging and tracing dependencies
  • adapt SimpleLogRecordProcessor construction for the OpenTelemetry 0.220 API
  • refresh the performance harness lockfile to clear 42 npm advisories (1 critical, 10 high, 31 moderate)

Validation

  • npm ci --ignore-scripts --prefix .\test\performanceTests
  • npm run build --prefix .\test\performanceTests
  • npm audit --json --package-lock-only --prefix .\test\performanceTests (0 vulnerabilities)
  • compatibility-test lockfiles audit at 0 vulnerabilities

The repository root lockfile still reports pre-existing advisories and is intentionally unchanged by this narrowly scoped remediation.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@JacksonWeber

Copy link
Copy Markdown
Owner Author

Closing in favor of the upstream pull request: microsoft#1529

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant