voyagi/bumpwarden-demo-app / cookie-parser
cookie-parser 1.4.6 to 1.4.7
Scored 8 of 100, which is clear. Every factor below is computed from a source you can open, and the sum decides the band. Nothing here is a judgement call.
Where this sits
The same axis as the queue, so this bump's place in the run is legible.
Machine explanation, not verdict
Update cookie-parser to 1.4.7
cookie-parser has been updated from 1.4.6 to 1.4.7. This patch release updates the internal cookie dependency to version 0.7.2. It also includes CI and build configuration updates, such as adding support for OSSF scorecard reporting, fixing CI pipeline errors for Node.js 8 and 9, and migrating to GITHUB_OUTPUT environment variables. No usage sites of cookie-parser were detected in this repository.
Confidence high. Model gemini-3.5-flash. It named no call site in this repository.
Provenance
- Run
- run-20260830T180003072Z-scheduled
- First seen
- 2026-08-29 06:53:40 UTC
- Last scored
- 2026-08-30 18:00:03 UTC
- Rubric
- v1.0.0
- Bump key
- voyagi/bumpwarden-demo-app#cookie-parser@1.4.7
How 8 was reached
What was done
Rule GRN-PR-1 Open a pull request with the bump and the brief. If Dependabot or Renovate already opened one for the same bump, comment there instead of duplicating it.