chore: Bump @google/adk from 1.4.0 to 1.5.0 - #1065
Open
dependabot[bot] wants to merge 1 commit into
Open
StepSecurity Actions Security / StepSecurity Required Checks
succeeded
Aug 3, 2026 in 0s
StepSecurity Required Checks
Finished StepSecurity Required Checks
- Pwn Request Vulnerabilities Check - Checks for Pwn Request vulnerabilities in the PR via risky triggers
- Script Injection Check - Checks for script injection vulnerabilities in the PR
- NPM Compromised Packages Check - Checks for compromised npm package versions in the PR
- NPM Package Cooldown Check - Fails if any package version in the PR was released within the configured cooldown period, helping to avoid brand-new (and potentially unreviewed or malicious) releases
Details
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR (showing first 10 of 19 packages)
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| @google/adk | 1.4.0 | 1.5.0 | packages/adk/package.json | 2026-07-30T21:10:54Z |
| brace-expansion | 5.0.9 | pnpm-lock.yaml | 2026-07-30T10:00:32Z | |
| gaxios | 7.1.4 | 7.3.0 | pnpm-lock.yaml | 2026-07-23T19:45:45Z |
| color-name | 2.1.0 | 2.1.1 | pnpm-lock.yaml | 2026-07-22T15:38:35Z |
| body-parser | 1.20.6 | 2.3.0 | pnpm-lock.yaml | 2026-06-15T10:46:12Z |
| hasown | 2.0.2: | 2.0.4 | pnpm-lock.yaml | 2026-05-28T18:11:39Z |
| eventsource-parser | 3.0.6 | 3.1.0 | pnpm-lock.yaml | 2026-05-27T20:55:51Z |
| es-object-atoms | 1.1.1 | 1.1.2 | pnpm-lock.yaml | 2026-05-22T14:40:03Z |
| balanced-match | 4.0.4 | pnpm-lock.yaml | 2026-02-22T11:38:25Z | |
| long | 5.3.2 | pnpm-lock.yaml | 2025-04-17T17:32:06Z |
Loading