Skip to content

build(deps): bump @slack/web-api to v8 and @slack/webhook to v8 - #154

Merged
MarshallOfSound merged 1 commit into
mainfrom
bump-slack-axios-free
Oct 10, 2026
Merged

MarshallOfSound merged 1 commit into
mainfrom
bump-slack-axios-free

Conversation

@claude

@claude claude Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Requested by David Babenko-Sanders · Slack thread

This bumps @slack/web-api from ^6.8.0 to ^8.2.0 and @slack/webhook from ^7.0.0 to ^8.0.2, and declares @slack/types ^3.2.0 as a direct dependency because MessageBuilder imports KnownBlock from it. The new versions use the built-in fetch instead of axios, so axios is no longer in the lockfile. One code change was needed: @slack/types v3 requires image_url on image accessories, so the user section block in MessageBuilder now only adds the avatar accessory when avatar_url is set.

🤖 Generated with Claude Code

https://claude.ai/code/session_01JNyjV4J2pgJaC2WfJpGfCb


Generated by Claude Code

Bumps @slack/web-api from ^6.8.0 to ^8.2.0 and @slack/webhook from
^7.0.0 to ^8.0.2. Both now use the built-in fetch instead of axios, so
axios is no longer in the lockfile. Also declares @slack/types ^3.2.0
as a direct dependency, since MessageBuilder imports KnownBlock from it.

@slack/types v3 requires image_url on image accessories, so the user
section block now only includes the avatar accessory when avatar_url
is set.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JNyjV4J2pgJaC2WfJpGfCb
@claude
claude Bot requested a review from a team as a code owner October 10, 2026 00:07
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​slack/​types@​2.10.0 ⏵ 3.2.0100 +110083 +293 -1100
Updated@​slack/​web-api@​6.10.0 ⏵ 8.2.099 +1100100 +198 +1100
Updated@​slack/​webhook@​7.0.1 ⏵ 8.0.29910010098 +8100

View full report

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — straightforward Slack SDK major-version bump with a small, correct accompanying code fix.

What was reviewed: the package.json/yarn.lock version bumps for @ slack/web-api, @ slack/webhook, and new @ slack/types dependency; the MessageBuilder.ts change that now only adds the avatar "accessory" image block when user.avatar_url is truthy (avatar_url is optional on MinimalUserInfo, so this avoids emitting an image block with an undefined image_url, matching the stricter @ slack/types v3 typing); and the untouched src/permissions/plugins/slack/index.ts WebClient usage, which doesn't rely on anything removed by the v8 bump (e.g., axios internals).

Extended reasoning...

The change is a mechanical major-version dependency bump (Slack SDK v6/v7 to v8) across package.json/yarn.lock plus one small, well-justified code fix in src/MessageBuilder.ts that conditionally includes the avatar image accessory only when avatar_url is set, matching the now-stricter @ slack/types v3 ImageElement typing. No auth, crypto, or data-exposure surface is touched; the only other Slack SDK consumer (src/permissions/plugins/slack/index.ts) is unmodified and uses APIs unaffected by the bump. The diff is small, self-contained, and the PR's own description accurately matches what the code does.

@MarshallOfSound
MarshallOfSound enabled auto-merge (squash) October 10, 2026 10:36
@MarshallOfSound
MarshallOfSound merged commit c4bc646 into main Oct 10, 2026
7 checks passed
@MarshallOfSound
MarshallOfSound deleted the bump-slack-axios-free branch October 10, 2026 10:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants