Skip to content

Conversation

kibanamachine
Copy link
Contributor

Backport

This will backport the following commits from main to 9.0:

Questions ?

Please refer to the Backport tool documentation

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [@slack/webhook](https://tools.slack.dev/node-slack-sdk/webhook)
([source](https://redirect.github.com/slackapi/node-slack-sdk)) |
dependencies | patch | [`^7.0.1` ->
`^7.0.6`](https://renovatebot.com/diffs/npm/@slack%2fwebhook/7.0.1/7.0.6)
|

---

### Release Notes

<details>
<summary>slackapi/node-slack-sdk (@&elastic#8203;slack/webhook)</summary>

###
[`v7.0.6`](https://redirect.github.com/slackapi/node-slack-sdk/releases/tag/%40slack/webhook%407.0.6)

[Compare
Source](https://redirect.github.com/slackapi/node-slack-sdk/compare/@slack/webhook@7.0.5...@slack/webhook@7.0.6)

#### What's Changed

This release includes a security patch to internal dependencies. 🔏 ✨

##### 📚 Documentation

- docs: update links, copy edit, apply style guide in
[#&elastic#8203;2294](https://redirect.github.com/slackapi/node-slack-sdk/issues/2294)
- Thanks [@&elastic#8203;haleychaas](https://redirect.github.com/haleychaas)!
- docs: autogenerated typedoc reference in
[#&elastic#8203;2308](https://redirect.github.com/slackapi/node-slack-sdk/issues/2308)
- Thanks
[@&elastic#8203;lukegalbraithrussell](https://redirect.github.com/lukegalbraithrussell)!

##### 🤖 Dependencies

- chore(deps): bump axios from ^1.8.3 to ^1.11.0 in
[@&elastic#8203;slack/webhook](https://redirect.github.com/slack/webhook) in
[#&elastic#8203;2335](https://redirect.github.com/slackapi/node-slack-sdk/issues/2335)
- Thanks [@&elastic#8203;mwbrooks](https://redirect.github.com/mwbrooks)!
- chore(deps-dev): bump
[@&elastic#8203;biomejs/biome](https://redirect.github.com/biomejs/biome) to v2
for all packages in
[#&elastic#8203;2281](https://redirect.github.com/slackapi/node-slack-sdk/issues/2281)
- Thanks [@&elastic#8203;mwbrooks](https://redirect.github.com/mwbrooks)!
- chore(deps-dev): bump mocha from 10.8.2 to 11.7.1 in /packages/webhook
in the dev-mocha group in
[#&elastic#8203;2305](https://redirect.github.com/slackapi/node-slack-sdk/issues/2305)
- Thanks [@&elastic#8203;dependabot](https://redirect.github.com/dependabot)!
- chore(deps-dev): bump nock from 13.5.6 to 14.0.6 in /packages/webhook
in
[#&elastic#8203;2306](https://redirect.github.com/slackapi/node-slack-sdk/issues/2306)
- Thanks [@&elastic#8203;dependabot](https://redirect.github.com/dependabot)!
- chore(deps-dev): bump typescript from 4.9.5 to 5.8.3 in
/packages/webhook in
[#&elastic#8203;2309](https://redirect.github.com/slackapi/node-slack-sdk/issues/2309)
- Thanks [@&elastic#8203;dependabot](https://redirect.github.com/dependabot)!
- chore(deps-dev): bump ts-node from 8.10.2 to 10.9.2 in
/packages/webhook in
[#&elastic#8203;2310](https://redirect.github.com/slackapi/node-slack-sdk/issues/2310)
- Thanks [@&elastic#8203;dependabot](https://redirect.github.com/dependabot)!
- chore(deps-dev): bump shx from 0.3.4 to 0.4.0 in /packages/webhook in
[#&elastic#8203;2311](https://redirect.github.com/slackapi/node-slack-sdk/issues/2311)
- Thanks [@&elastic#8203;dependabot](https://redirect.github.com/dependabot)!
- chore(deps-dev): bump c8 from 9.1.0 to 10.1.3 in /packages/webhook in
[#&elastic#8203;2312](https://redirect.github.com/slackapi/node-slack-sdk/issues/2312)
- Thanks [@&elastic#8203;dependabot](https://redirect.github.com/dependabot)!

##### 🧰 Maintenance

- test: upload individual test results to codecov to gather stats in
[#&elastic#8203;2178](https://redirect.github.com/slackapi/node-slack-sdk/issues/2178)
- Thanks [@&elastic#8203;zimeg](https://redirect.github.com/zimeg)!
- chore(webhook): release
[@&elastic#8203;slack/webhook](https://redirect.github.com/slack/webhook)[@&#8203;7](https://redirect.github.com/7).0.6
in
[#&elastic#8203;2338](https://redirect.github.com/slackapi/node-slack-sdk/issues/2338)
- Thanks [@&elastic#8203;zimeg](https://redirect.github.com/zimeg)!

**Package**: https://www.npmjs.com/package/@&#8203;slack/webhook/v/7.0.6
**Full Changelog**:
https://github.com/slackapi/node-slack-sdk/compare/[@&#8203;slack/webhook](https://redirect.github.com/slack/webhook)[@&#8203;7](https://redirect.github.com/7).0.5...[@&#8203;slack/webhook](https://redirect.github.com/slack/webhook)[@&#8203;7](https://redirect.github.com/7).0.6
**Milestone**:
https://github.com/slackapi/node-slack-sdk/milestone/140?closed=1

###
[`v7.0.5`](https://redirect.github.com/slackapi/node-slack-sdk/releases/tag/%40slack/webhook%407.0.5)

[Compare
Source](https://redirect.github.com/slackapi/node-slack-sdk/compare/@slack/webhook@7.0.4...@slack/webhook@7.0.5)

#### What's Changed

This patch release updates the `axios` dependency used to send webhooks
with internal bug fixes.

- fix(webhook): bump axios to 1.8.3 to address CVE-2025-27152 by
[@&elastic#8203;zimeg](https://redirect.github.com/zimeg) in
[https://github.com/slackapi/node-slack-sdk/pull/2173](https://redirect.github.com/slackapi/node-slack-sdk/pull/2173)

**Full Changelog**:
https://github.com/slackapi/node-slack-sdk/compare/[@&#8203;slack/webhook](https://redirect.github.com/slack/webhook)[@&#8203;7](https://redirect.github.com/7).0.4..[@&#8203;slack/webhook](https://redirect.github.com/slack/webhook)[@&#8203;7](https://redirect.github.com/7).0.5
**Milestone**: https://github.com/slackapi/node-slack-sdk/milestone/130

###
[`v7.0.4`](https://redirect.github.com/slackapi/node-slack-sdk/releases/tag/%40slack/webhook%407.0.4)

[Compare
Source](https://redirect.github.com/slackapi/node-slack-sdk/compare/@slack/webhook@7.0.3...@slack/webhook@7.0.4)

#### What's Changed

- chore(deps): bump minimum axios version for web-api and webhook to
avoid security vuln by
[@&elastic#8203;hello-ashleyintech](https://redirect.github.com/hello-ashleyintech)
in
[https://github.com/slackapi/node-slack-sdk/pull/2116](https://redirect.github.com/slackapi/node-slack-sdk/pull/2116)
- ci: check for changes to lints separate from writing changes by
[@&elastic#8203;zimeg](https://redirect.github.com/zimeg) in
[https://github.com/slackapi/node-slack-sdk/pull/2117](https://redirect.github.com/slackapi/node-slack-sdk/pull/2117)
- chore: tsconfig skiplibcheck:true - dont typecheck dependency d.ts
files
[https://github.com/slackapi/node-slack-sdk/pull/1913](https://redirect.github.com/slackapi/node-slack-sdk/pull/1913)
- thanks [@&elastic#8203;filmaj](https://redirect.github.com/filmaj)!
- chore: remove eslint, use biome instead in
[https://github.com/slackapi/node-slack-sdk/pull/2006](https://redirect.github.com/slackapi/node-slack-sdk/pull/2006)
- thanks [@&elastic#8203;filmaj](https://redirect.github.com/filmaj)!
- Release:
[@&elastic#8203;slack/webhook](https://redirect.github.com/slack/webhook)[@&#8203;7](https://redirect.github.com/7).0.4,
[@&elastic#8203;slack/web-api](https://redirect.github.com/slack/web-api)[@&#8203;7](https://redirect.github.com/7).8.0
by
[@&elastic#8203;hello-ashleyintech](https://redirect.github.com/hello-ashleyintech)
in
[https://github.com/slackapi/node-slack-sdk/pull/2118](https://redirect.github.com/slackapi/node-slack-sdk/pull/2118)

**Full Changelog**:
https://github.com/slackapi/node-slack-sdk/compare/[@&#8203;slack/cli-hooks](https://redirect.github.com/slack/cli-hooks)[@&#8203;1](https://redirect.github.com/1).1.2...[@&#8203;slack/webhook](https://redirect.github.com/slack/webhook)[@&#8203;7](https://redirect.github.com/7).0.4

###
[`v7.0.3`](https://redirect.github.com/slackapi/node-slack-sdk/releases/tag/%40slack/webhook%407.0.3)

[Compare
Source](https://redirect.github.com/slackapi/node-slack-sdk/compare/@slack/webhook@7.0.2...@slack/webhook@7.0.3)

#### What's Changed

This patch release bumps the minimum version of axios to 1.7.4 to
address a CVE - see [Axios 1.7.4 release
notes](https://redirect.github.com/axios/axios/releases/tag/v1.7.4) for
more information.

##### Changelog

- webhook(chore): bump axios to 1.7.4 to address CVE-2024-39338 - Thanks
[@&elastic#8203;zimeg](https://redirect.github.com/zimeg)!
[https://github.com/slackapi/node-slack-sdk/pull/1879](https://redirect.github.com/slackapi/node-slack-sdk/pull/1879)

**Full Changelog**:
https://github.com/slackapi/node-slack-sdk/compare/[@&#8203;slack/web-api](https://redirect.github.com/slack/web-api)[@&#8203;7](https://redirect.github.com/7).0.2...[@&#8203;slack/webhook](https://redirect.github.com/slack/webhook)[@&#8203;7](https://redirect.github.com/7).0.3

###
[`v7.0.2`](https://redirect.github.com/slackapi/node-slack-sdk/releases/tag/%40slack/webhook%407.0.2)

[Compare
Source](https://redirect.github.com/slackapi/node-slack-sdk/compare/@slack/webhook@7.0.1...@slack/webhook@7.0.2)

Bumps axios to 1.6.3 to address a security vulnerability.

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS4xMDcuMCIsInVwZGF0ZWRJblZlciI6IjM5LjEwNy4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJiYWNrcG9ydDphbGwtb3BlbiIsInJlbGVhc2Vfbm90ZTpza2lwIl19-->

Co-authored-by: elastic-renovate-prod[bot] <174716857+elastic-renovate-prod[bot]@users.noreply.github.com>
(cherry picked from commit 91d0978)
@kibanamachine kibanamachine added the backport This PR is a backport of another PR label Sep 19, 2025
@kibanamachine kibanamachine enabled auto-merge (squash) September 19, 2025 07:24
@kibanamachine kibanamachine merged commit 8fa240b into elastic:9.0 Sep 19, 2025
12 checks passed
@elasticmachine
Copy link
Contributor

💚 Build Succeeded

Metrics [docs]

✅ unchanged

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport This PR is a backport of another PR
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants