Skip to content

upgrading coana to version 15.3.6#1328

Merged
Martin Torp (mtorp) merged 2 commits into
v1.xfrom
coana-15.3.6
May 22, 2026
Merged

upgrading coana to version 15.3.6#1328
Martin Torp (mtorp) merged 2 commits into
v1.xfrom
coana-15.3.6

Conversation

@mtorp
Copy link
Copy Markdown
Contributor

@mtorp Martin Torp (mtorp) commented May 22, 2026

Summary

  • Upgrades @coana-tech/cli from 15.3.4 to 15.3.6

Coana Changelog

For details on what's included in this Coana release, see the Coana Changelogs.


Note

Low Risk
Low risk dependency/version bump with no application logic changes; main impact is behavioral changes coming from the updated external @coana-tech/cli tool.

Overview
Bumps the CLI release to 1.1.101 and upgrades the bundled @coana-tech/cli dependency from 15.3.4 to 15.3.6 (including lockfile updates).

Updates CHANGELOG.md with a new 1.1.101 entry documenting the Coana upgrade.

Reviewed by Cursor Bugbot for commit f899361. Configure here.

@socket-security-staging
Copy link
Copy Markdown

socket-security-staging Bot commented May 22, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​@​coana-tech/​cli@​15.3.6471008098100

View full report

@mtorp Martin Torp (mtorp) enabled auto-merge (squash) May 22, 2026 09:50
@socket-security-staging
Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @coana-tech/cli is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/@coana-tech/[email protected]

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@coana-tech/[email protected]. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @coana-tech/cli is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/@coana-tech/[email protected]

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@coana-tech/[email protected]. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @coana-tech/cli is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/@coana-tech/[email protected]

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@coana-tech/[email protected]. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @coana-tech/cli is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/@coana-tech/[email protected]

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@coana-tech/[email protected]. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @coana-tech/cli is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/@coana-tech/[email protected]

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@coana-tech/[email protected]. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @coana-tech/cli is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/@coana-tech/[email protected]

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@coana-tech/[email protected]. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@mtorp Martin Torp (mtorp) merged commit 2c4618f into v1.x May 22, 2026
12 checks passed
@mtorp Martin Torp (mtorp) deleted the coana-15.3.6 branch May 22, 2026 10:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants